Северокорейские хакеры взломали криптопроекты создателя лягушонка Пепе

cryptonews.ruPublished on 2023-11-28Last updated on 2025-06-28

Блокчейн-сыщик под псевдонимом ZachXBT сообщил, что хакеры из КНДР взломали криптопроекты, связанных с художником Мэттом Фьюри (Matt Furie), автором мемного персонажа — зеленого лягушонка Пепе.

Совокупный ущерб от серии атак на проекты превысил $1 млн. Около $310 000 было выведено из коллекций Replicandy, Peplicator, Hedz и Zogz, разработанных командой Фьюри и выпущенных через платформу ChainSaw. Злоумышленники получили доступ к контрактам, сняли ограничения на выпуск монет и отчеканили невзаимозаменяемые токены (NFT), которые затем продали, фактически обнулив их цену.

За атаками стоят хакеры из Северной Кореи, нанятые через онлайн-платформы для фрилансеров, рассказал ZachXBT.

Аналогичный инцидент произошел с проектом Favrr, откуда было похищено более $680 000. Технический директор проекта, предположительно игравший роль фальшивого разработчика, может быть причастен к атаке. Его профиль на LinkedIn был удален вскоре после инцидента.

ZachXBT сообщил, что обнаружил регулярные финансовые переводы северокорейским «фрилансерам» от других криптопроектов. Сыщик планирует опубликовать статистику по этим транзакциям. По его словам, масштаб угрозы серьезно занижен, и даже базовая проверка при найме разработчиков могла бы предотвратить большинство таких атак.

Ранее специалисты по безопасности компании TRM Labs заявили, что хакеры украли $2,1 млрд в криптовалютах за полгода, и это новый антирекорд. Ущерб превысил показатели прошлого года и оказался на 10% больше, чем предыдущий рекорд 2022 года.

Related Reads

You Use Claude and Codex Every Day, but Meta Has Restricted Internal Use

In May, Meta imposed internal restrictions on its engineers regarding the use of Claude Code and Codex, two widely used AI programming tools. Despite being a major client, Meta's guidelines, still in effect, prohibit these external models from being used for specific tasks to prevent potential "escalations with partners." The core concern is "distillation"—the risk that outputs from Claude or Codex could inadvertently contaminate the training data and evaluation processes for Meta's in-house AI coding assistant, MetaCode. If MetaCode is trained or evaluated using data generated by these external models, it risks learning their capabilities rather than developing its own, blurring the line of intellectual origin. The restrictions are precise: engineers cannot use the external models to generate test questions, debug source code, or suggest test cases. AI-generated content is also barred from environments accessible to MetaCode. However, AI can still assist with peripheral tasks like workflow setup and code organization, provided all outputs are manually reviewed. This caution reflects a broader industry dilemma. While distillation is a common technique, using a competitor's model output for training raises legal and ethical questions about the ownership of derived capabilities. Contractual terms from companies like OpenAI and Anthropic explicitly forbid using their outputs to build competing products, putting enforcement power in the hands of rivals. The move is also financially motivated, as Meta seeks to reduce its hefty internal AI spending, estimated in the billions this year. Meta's policy illustrates the delicate balance companies must strike: leveraging powerful external AI tools while safeguarding the integrity and independence of their own AI development. As AI systems increasingly help build other AIs, distinguishing the origin of capabilities becomes a fundamental challenge for the entire industry.

marsbit1h ago

You Use Claude and Codex Every Day, but Meta Has Restricted Internal Use

marsbit1h ago

Why Do We Need an AI Content Perspective Today?

The article "Why Do We Need an AI Content Perspective Today?" explores the complex and often contentious integration of AI into the cultural and creative industries, particularly film and television. It begins with the cancellation of Amazon's AI-generated animation "Punky Duck," highlighting the ethical debates surrounding AI content. AI's rapid advancement is transforming video production, enabling cost-effective, full-length AI films (e.g., "RAPHAEL," "Dreams of Violets") while sparking industry resistance over issues like "synthetic actors." The core debate has shifted from whether to use AI to how to use it responsibly. The article analyzes why AI's entry into film is uniquely unsettling. It distinguishes between "cultural fast food" (short-form, fast-paced content like micro-dramas) and "cultural main courses" (traditional, long-form film/TV). AI currently excels at the former, matching its fragmented narratives, shallow emotional needs, and free-to-consumer models. However, venturing into the latter challenges the human-centric essence of storytelling—creativity, emotional depth, and the unique value of human labor and experience. While AI can generate massive volumes of content and lower costs, it risks devaluing human creativity, leading to homogenized output, and creating unfair competition through potential intellectual property infringement. Its efficiency also amplifies content safety risks, making preemptive governance crucial. To counter these risks, the article proposes establishing clear boundaries guided by a human-centered AI content perspective. It outlines four principles: 1) Amplify, rather than displace, human creative space; 2) Respect and protect human creative output; 3) Ensure human creative control and responsibility remain paramount; and 4) Guarantee transparency and traceability in AI creation. The conclusion emphasizes that humans must act as the "helmsmen" of technology, steering AI development to enhance, not replace, the core human values at the heart of cultural expression.

marsbit2h ago

Why Do We Need an AI Content Perspective Today?

marsbit2h ago

Trading

Spot
活动图片