Ankr 事件分析:套利者如何在三分钟利用 3000 美元获取 1 亿人民币?

BeosinPublished on 2022-12-02Last updated on 2022-12-02

Abstract

攻击者共获利 700 万美元,而一位套利者利用增发的 aBNBc 在 Helio_Money 协议中获利 1550 万美元。

攻击者共获利 700 万美元,而一位套利者利用增发的 aBNBc 在 Helio_Money 协议中获利 1550 万美元。

2022 年 12 月 2 日,据区块链安全审计公司 Beosin 旗下 Beosin EagleEye 安全风险监控、预警与阻断平台监测显示,AnkStaking 的 aBNBc Token 项目遭受私钥泄露攻击,攻击者通过 Deployer 地址将合约实现修改为有漏洞的合约,攻击者通过没有权限校验的 0x3b3a5522 函数铸造了大量 aBNBc 代币后卖出,攻击者共获利 5500 个 BNB 和 534 万枚 USDC,约 700 万美元,Beosin Trace 将持续对被盗资金进行监控。Beosin 安全团队现将事件分析结果与大家分享如下。

Ankr 是什么?

据了解,Ankr 是一个去中心化的 Web3 基础设施提供商,可帮助开发人员、去中心化应用程序和利益相关者轻松地与一系列区块链进行交互。

攻击发生之后,Ankr 针对 aBNBc 合约遭到攻击一事称,「目前正在与交易所合作以立即停止交易。Ankr Staking 上的所有底层资产都是安全的,所有基础设施服务不受影响。」

本次攻击事件相关信息

攻击交易

0xe367d05e7ff37eb6d0b7d763495f218740c979348d7a3b6d8e72d3b947c86e33

攻击者地址

0xf3a465C9fA6663fF50794C698F600Faa4b05c777 (Ankr Exploiter)

被攻击合约

0xE85aFCcDaFBE7F2B096f268e31ccE3da8dA2990A

攻击流程

1. 在 aBNBc 的最新一次升级后,项目方的私钥遭受泄露。攻击者使用项目方地址(Ankr: Deployer)将合约实现修改为有漏洞的版本。

2.由攻击者更换的新合约实现中, 0x3b3a5522 函数的调用没有权限限制,任何人都可以调用此函数铸造代币给指定地址。

3.攻击者给自己铸造大量 aBNBc 代币,前往指定交易对中将其兑换为 BNB 和 USDC。

4. 攻击者共获利 5500WBNB 和 534 万 USDC(约 700 万美元)。

受影响的其他项目

由于 Ankr 的 aBNBc 代币和其他项目有交互,导致其他项目遭受攻击,下面是已知项目遭受攻击的分析。

Wombat 项目:

由于 Ankr Staking: aBNBc Token 项目遭受私钥泄露攻击,导致增发了大量的 aBNBc 代币,从而影响了 pair(0x272c...880)中的 WBNB 和 aBNBc 的价格,而 Wombat 项目池子中的 WBNB 和 aBNBc 兑换率约为 1:1,导致套利者可以通过在 pair(0x272c...880)中低价购买 aBNBc,然后到 Wombat 项目的 WBNB/aBNBc 池子中换出 WBNB,实现套利。目前套利地址(0x20a0...876f)共获利约 200 万美元,Beosin Trace 将持续对被盗资金进行监控。

Helio_Money 项目:

套利地址:

0x8d11f5b4d351396ce41813dce5a32962aa48e217

由于 Ankr Staking: aBNBc Token 项目遭受私钥泄露攻击,导致增发了大量的 aBNBc 代币,aBNBc 和 WBNB 的交易对中,WBNB 被掏空,WBNB 价格升高。套利者首先使用 10WBNB 交换出超发后的大量 aBNBc.之后将 aBNBc 交换为 hBNB。以 hBNB 为抵押品在 Helio_Money 中进行借贷,借贷出约 1644 万 HAY。之后将 HAY 交换为约 1550 万 BUSD,价值接近 1 亿人民币。

事件总结

针对本次事件,Beosin 安全团队建议:1. 项目的管理员权限最好交由多签钱包进行管理。2. 项目方操作时,务必妥善保管私钥。3. 项目上线前,建议选择专业的安全审计公司进行全面的安全审计,规避安全风险。

Related Reads

Can SK Hynix's Stock Double Again in This Rally?

The article discusses the highly optimistic price target of approximately $3,500 for SK Hynix stock, set by Aletheia Capital. This target is significantly above the consensus range of $2,000-$2,520 from major brokerages. The core debate is whether SK Hynix deserves a fundamental re-rating beyond its traditional cyclical discount, based on the long-term impact of AI-driven demand. The $3,500 target hinges on three key assumptions holding simultaneously until at least 2027: 1) Continued shortage and high pricing for HBM (High Bandwidth Memory), a critical component for AI chips; 2) Sustained high prices for standard DRAM, as HBM production consumes capacity and constrains general supply; and 3) Strong AI server demand generating substantial, above-expectation free cash flow. SK Hynix's leading ~58% market share in HBM and its early certification with key clients like Nvidia provide a competitive advantage, allowing it to capture significant supply chain premiums. The HBM shortage is seen not just as a niche growth driver but as a catalyst that amplifies profitability across the entire memory business by tightening overall DRAM supply. However, the article cautions that this target represents an optimistic "tail scenario." Key risks include potential supply increases from competitors (Samsung, Micron) by 2027, a possible slowdown in HBM price growth, and high capital expenditures that could erode the projected free cash flow. The divergence in analyst targets reflects the market's uncertainty over whether the current AI-driven boom will temporarily elevate earnings or permanently raise the memory industry's profit baseline.

marsbit2m ago

Can SK Hynix's Stock Double Again in This Rally?

marsbit2m ago

Has the Cryptocurrency Market Hit Bottom? Here's What Institutions Think

"Has the crypto market bottomed out? Major institutions are divided on the outlook, according to a recent analysis by Matt Hougan, Chief Investment Officer of Bitwise. Three prominent research firms published in-depth reports on the topic with differing conclusions. Galaxy Digital argues Bitcoin has not yet found its bottom, pointing to only 4 out of 13 historical bottoming indicators being met. Their analysis suggests a potential bottom range of $30,000 to $54,000. NYDIG adopts a more cautious stance, noting that while metrics are close to historical bear market lows, a classic panic-selling capitulation event is missing. They acknowledge the possibility of a bottom but consider it unlikely, citing structural changes from institutional adoption. In contrast, Standard Chartered Bank asserts the bottom is already in at around $59,000. Their revised bullish view, predicting a year-end target of $100,000, hinges on anticipated reductions in ETF selling pressure linked to events like a potential SpaceX IPO. Despite the surface-level disagreement on the exact price floor, the reports share significant common ground crucial for long-term investors. All three institutions agree that a market bottom will likely form within the current year, that current prices are closer to the bottom than to previous cycle highs, and that Bitcoin is poised for another major bull cycle in the future. The core takeaway is that while the precise bottom level remains debated, the long-term value proposition for Bitcoin remains strong and may even be strengthening. Key supportive trends include rising global debt, persistent inflation, declining trust in traditional institutions, accelerating digitization, and improving market infrastructure. Therefore, for investors with a long-term horizon, the focus should shift from pinpointing the exact bottom to recognizing that the cycle's peak is likely still ahead, making current levels an attractive entry point for substantial potential upside."

Foresight News23m ago

Has the Cryptocurrency Market Hit Bottom? Here's What Institutions Think

Foresight News23m ago

2029 Finale Prediction: When Cryptocurrency Completely "Vanishes", Who Can Remain in This Financial Upheaval?

By 2029, the crypto industry will have transformed into a largely invisible but foundational layer for traditional finance. This timeline outlines the key shifts from now until then. By mid-2026, the most sought-after assets on-chain will not be traditional tokens, but synthetic perpetual contracts for private, high-growth companies (like SpaceX, OpenAI). These become primary price discovery tools, highlighting the market's craving for real-world asset value. Most altcoins enter a sustained bear market as their fundamental lack of asset-backed value is exposed. In late 2026, the "AI + Crypto" narrative largely fades as AI giants prove they don't need crypto infrastructure, except for prediction markets betting on model performance. Simultaneously, a quiet but significant wave of tokenization for institutional assets (money market funds, private credit) begins. The industry splits into a noisy speculative economy and a silent institutional one. Throughout 2027, major public blockchain foundations pivot decisively to serve institutional clients, building compliance toolkits and sales teams. However, key sectors hit growth ceilings: private perpetual contracts are legally restricted from public promotion, stable币 growth is capped by looming political uncertainty, and tokenization projects remain cautious. In 2028, following a U.S. election assumed to maintain a regulatory (not prohibitive) stance, a pivotal change occurs. After a major liquidation crisis exposes the flaws of synthetic contracts lacking a real-asset anchor, new regulations allow the *public solicitation* of private security sales (secondary market shares) to accredited investors. This creates a legitimate, direct on-ramp for retail capital into previously illiquid private equity. By 2029, the resulting bull market is driven by trading in real, innovative company shares (biotech, robotics, AI labs), not speculative tokens. "Crypto" as a distinct asset class recedes; it becomes the mundane, unseen plumbing for this new global private markets infrastructure. Tokens that survive are those capturing real cash flows from this infrastructure. Speculation persists but is marginalized. The core questions posed at the start are answered: token value is tied to legally enforceable claims on real assets, frontier tech adoption happens via private market channels, and crypto's absorption into traditional finance is marked by its becoming boring and invisible. The key validation for this entire thesis is whether, by late 2028, a legal pathway exists for ordinary accredited investors to access private assets directly.

marsbit1h ago

2029 Finale Prediction: When Cryptocurrency Completely "Vanishes", Who Can Remain in This Financial Upheaval?

marsbit1h ago

Trading

Spot
Futures

Hot Articles

What is USDC(WORMHOLE)

USD Coin (Wormhole): A Comprehensive Overview Introduction In the rapidly evolving world of cryptocurrencies, USD Coin (Wormhole), referred to as $USDC(Wormhole), stands out as a pioneering solution within the DeFi (Decentralized Finance) landscape. Operating on several blockchain platforms, including Solana, USD Coin (Wormhole) is more than just a digital representation of the United States dollar. It embodies the innovative spirit of modern finance, enabling seamless cross-chain transactions and enhanced interoperability among diverse blockchain ecosystems through the advanced Wormhole protocol. What is USD Coin (Wormhole)? USD Coin (Wormhole) is a tokenized version of the US dollar designed to facilitate frictionless transactions across different blockchain networks. Its primary aim is to bolster liquidity and enhance the functionality of the DeFi ecosystem. By leveraging the Wormhole protocol, which establishes a robust cross-chain communication network, users can effortlessly transfer USDC tokens across various platforms. This cross-chain capability marks a significant advancement in cryptocurrency use, promoting a more interconnected and efficient ecosystem where assets can flow freely between different blockchains. The value proposition of USD Coin (Wormhole) lies not only in its stability, being pegged to the US dollar, but also in its ability to bridge gaps between disparate blockchain environments. This innovative approach fosters a greater level of participation among users and developers, paving the way for new and exciting applications within decentralized finance. Who is the creator of USD Coin (Wormhole)? The origins of USD Coin (Wormhole) are intricately tied to the Wormhole network, which was developed by Jump Crypto. While specific individual creators are not prominently documented, Jump Crypto is notable for its involvement in advancing blockchain technology and supporting its applications in finance. By creating the Wormhole network, Jump Crypto has played a vital role in promoting cross-chain asset transfers, enhancing the efficiency and diversity of cryptocurrency usage. Who are the investors of USD Coin (Wormhole)? The success of USD Coin (Wormhole) is supported by investments from several notable funds and organizations within the cryptocurrency realm. Key investors include: Coinbase Ventures: A prominent venture capital arm backed by one of the leading cryptocurrency exchanges in the industry, Coinbase Ventures provides essential capital and strategic support to promising blockchain projects. Arrington XRP Capital: Specializing in digital assets, Arrington XRP Capital recognizes the potential of innovative projects like USD Coin (Wormhole) and has invested accordingly to back its development. Jump Trading: As the parent organization of Jump Crypto, Jump Trading brings not only investment but a wealth of expertise in trading technology and market dynamics to bolster the Wormhole project. How Does USD Coin (Wormhole) Work? The operational framework of USD Coin (Wormhole) is intricately designed to facilitate effective cross-chain transactions, maximizing security and efficiency. Here’s a simplified overview of how it functions: Asset Locking: When a user wishes to transfer USDC from one blockchain to another, they first lock their tokens on the source blockchain. This process ensures that the assets are secure and are set to be either burned or moved later. Token Minting: After the tokens are locked, an equivalent amount of USDC is minted on the destination blockchain. This provides the user with access to their funds on a new platform, reflecting the flexibility that the Wormhole protocol enables. Cross-Chain Transfer: The Wormhole protocol efficiently facilitates the entire transfer process. It ensures that once the USDC is minted on the destination chain, the equivalent tokens are burned on the source chain. The result is a seamless transfer of value between two distinct blockchain environments. This cross-chain methodology ensures that transactions remain secure and transparent, significantly enhancing liquidity within the different DeFi ecosystems. Timeline of USD Coin (Wormhole) Understanding the evolution of USD Coin (Wormhole) provides vital context for its significance in the cryptocurrency arena. Here’s a timeline highlighting important milestones in the project’s history: 2021: The Wormhole project is launched, establishing a framework for cross-chain asset transfers and setting the stage for the development of USD Coin (Wormhole). 2022: The Wormhole network experiences a significant challenge with a security breach that results in a $325 million theft. However, the incident is later addressed and refunded by Jump Crypto, showcasing the project’s commitment to security and transparency. 2023: USD Coin (Wormhole) integrates with Circle’s Cross-Chain Transfer Protocol (CCTP), enhancing its capabilities for cross-chain transfers and further solidifying its place within the DeFi ecosystem. 2024: Ongoing development and expansion of the Wormhole network continue, aimed at increasing the utility and reach of USD Coin (Wormhole) as well as enhancing its operational framework. Key Features The success of USD Coin (Wormhole) can be attributed to several key features that differentiate it from other cryptocurrency offerings: Cross-Chain Interoperability At the core of USD Coin (Wormhole) is its ability to facilitate seamless transfers across multiple blockchain networks. This interoperability serves as a cornerstone for decentralized finance, allowing various platforms to interact with each other, thereby accelerating the evolution of financial services. Security Wormhole employs a well-designed Guardian Network comprised of node validators that ensure secure cross-chain transactions. This collective oversight minimizes the risk of fraud and provides users with confidence that their assets are protected during cross-chain transfers. Liquidity Enhancement By enabling USDC to circulate freely across different blockchains, USD Coin (Wormhole) enhances liquidity in the DeFi ecosystem. This increased liquidity can foster more efficient trading, contribute to better pricing strategies, and improve the overall market dynamics encompassing various digital assets. Conclusion USD Coin (Wormhole) is a pivotal innovation in the blockchain space, reinforcing the capabilities of decentralized finance (DeFi) and establishing a more connected financial ecosystem. With its robust framework for cross-chain transactions, security features, and strong backing from reputable investors, USD Coin (Wormhole) is positioned to play a key role in the future of cryptocurrency. As the digital finance landscape continues to evolve, USD Coin (Wormhole) not only embraces the future of interconnectivity among blockchain networks but also reaffirms the power of tokenization and blockchain technology in transforming how we perceive and utilize value in a digital world. By navigating the complexities of cross-chain functionality, it demonstrates a sophisticated approach to enabling financial inclusivity and innovation in the world of cryptocurrencies.

1.2k Total ViewsPublished 2024.04.01Updated 2024.12.03

What is USDC(WORMHOLE)

What is $USDC

Classic USDC: A Comprehensive Overview Introduction to Classic USDC In the rapidly evolving landscape of the cryptocurrency market, stablecoins have emerged as critical components, particularly in providing stability amid the volatility that characterizes digital assets. One such project is Classic USDC, a digital currency initiative that aims to deliver a stable and reliable medium of exchange. By maintaining a 1:1 peg with the US dollar, Classic USDC strives to offer users a dependable digital asset, equipped for various applications within the web3 and cryptocurrency ecosystems. What is Classic USDC? Classic USDC is fundamentally a stablecoin, which is a type of cryptocurrency designed to minimize the price volatility typically seen in the digital asset market. Specifically, Classic USDC aspires to represent the value of the US dollar closely, ensuring that users can leverage this digital currency for transactions, savings, and other financial activities without the fear of sudden price fluctuations that can otherwise plague many cryptocurrencies. The primary aim of Classic USDC is to provide a reliable and trustworthy digital equivalent of the US dollar, designed for seamless integration into a wide range of web3 applications, decentralized finance (DeFi) platforms, and other crypto-related financial systems. By delivering a stable digital currency, Classic USDC seeks to facilitate everyday commerce, make blockchain technology more user-friendly, and encourage the adoption of cryptocurrencies for mainstream usage. Creator of Classic USDC The identity of the creator or the development team behind Classic USDC remains largely unknown, and the lack of transparency has led to a degree of uncertainty regarding the project’s origins. While many cryptocurrency initiatives prominently showcase their founders and development teams, Classic USDC does not provide clear information about its creators, which poses challenges for potential users or investors weighing the project's credibility and reliability. Investors of Classic USDC Alongside the ambiguity surrounding its creators, Classic USDC also lacks specificity with regards to its investors. The financial backing of a project can often lend it credibility and stabilize its operations; however, the absence of documented investment foundations or organizations supporting Classic USDC raises questions about its funding structure. This lack of clarity could potentially hinder stakeholder confidence in the project. How Does Classic USDC Work? The operational mechanics of Classic USDC rely heavily on its reserve system, which is fundamental to the underpinnings of any stablecoin. Classic USDC undertakes to maintain a reserve of assets that directly correspond to the value of the digital currency in circulation. Specifically, for every Classic USDC token issued, an equivalent amount of backing assets is retained in reserve, whether in cash or near-cash equivalents. This strategy is designed to uphold the value of Classic USDC, offering reassurance to users that redeeming their tokens for US dollars is feasible at any time. This reserve structure aims to enhance the stability and reliability of Classic USDC, positioning it as a secure alternative in the cryptocurrency market. By ensuring that the value of Classic USDC is consistently correlated with the US dollar, the project aspires to engender trust among users who may be wary of the broader market dynamics. Timeline of Classic USDC The history of Classic USDC is marked by several key milestones that reflect its journey and evolution within the cryptocurrency ecosystem: 2021: The inception of Classic USDC is noted, introducing a new digital currency option designed for stability. During this year, the first records of the token’s activity surfaced and its initial price levels were established. 2024: Classic USDC begins to experience notable price fluctuations, as the crypto market overall grapples with various trends and user sentiment. Predictions regarding its future potential emerge, indicating a strong interest from market observers and analysts who foresee growth opportunities. Future Projections Experts speculate that Classic USDC may reach higher levels of adoption and stability in the years to come, with potential further developments anticipated around 2025 and 2026. However, these projections should be approached with cautious optimism, as the cryptocurrency market is inherently unpredictable, and various external factors may influence the trajectory of Classic USDC. Key Points About Classic USDC Stability: Classic USDC’s core proposition revolves around providing a digital currency that parallels the value of the US dollar, thereby ensuring stability in an often volatile marketplace. Reserve System: The project’s commitment to maintaining a reserve of assets to back its value underscores its reliability and operational soundness. Web3 and Crypto Integration: Classic USDC is engineered to facilitate easy integration within various applications, aiming to enhance the user experience and broaden the acceptance of cryptocurrency in everyday transactions. Future Growth Potential: While still emerging, Classic USDC holds prospective avenues for growth as awareness and utilization of stablecoins increases in the web3 and crypto contexts. Conclusion Classic USDC presents itself as a notable stablecoin initiative within the cryptocurrency sphere, striving to provide users with a reliable digital currency that embodies the stability of the US dollar. Despite uncertainties regarding its creators and financial backing, the underpinning principles of Classic USDC—centered on reserve-backed assurances—endeavour to position it as a trustworthy option for individuals and businesses navigating the digital economy. With an eye towards the future, market analysts are keen to observe how Classic USDC evolves in response to the shifting dynamics of the cryptocurrency landscape, potentially establishing itself as a significant player in the realm of stablecoins.

625 Total ViewsPublished 2024.05.01Updated 2024.12.03

What is $USDC

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of USDC (USDC) are presented below.

活动图片