跨链桥再遭攻击,Orbit Chain损失超8000万美元

Odaily星球日报Publicado a 2024-01-01Actualizado a 2024-01-01

Resumen

被盗原因并未明确,用户务必尽快撤销相关钱包授权。

原创 | Odaily星球日报

作者 | 夫如何

跨链桥再遭攻击,Orbit Chain损失超8000万美元

新年伊始,黑客又出来”兴风作浪“。根据 Beosin 旗下 EagleEye 监测,Orbit Chain 跨链桥遭黑客攻击,损失高达 8150 万美元。

通过黑客行为来看,这一切似乎早有预谋。根据 Beosin Trace 分析,黑客早在 1 天前(12 月 31 日)就尝试根据漏洞发起小规模攻击,并且将盗取的 ETH 作为了本次攻击的其余 5 个地址的转账手续费来源。

今天凌晨,黑客正式发起攻击,并将被盗资金转移到上述五个地址。在五笔独立的交易中,每笔交易都发送到一个新的钱包,Orbit Bridge 发送了 5000 万美元的稳定币(3000 万 Tether、 1000 万 DAI 和 1000 万 USDC)、 231 枚 wBTC(约 1000 万美元)和 9500 枚 ETH(约 2150 万美元)。

跨链桥再遭攻击,Orbit Chain损失超8000万美元

虽然跨链桥被攻击事件时有发生,但攻击类型却并不复杂。比如近期,Heco Bridge 受到私钥泄露攻击,损失高达 8660 万美元;Multichain 同样是私钥泄露攻击,损失高达 2.42 亿美元,同时影响多个项目发展,使 Fantom 上资产价格脱锚。

Orbit Chain 此次被盗的原因又是什么?安全机构慢雾认为,本次攻击事件可能是跨链桥合约漏洞引发的攻击行为或者项目中心化服务器受到入侵,前者可能更易被大众接受。“人无完人,没有坚不可摧的程序,但中心化服务器受到入侵可能会引发更多的连锁反应。”

攻击发生后,Orbit Chain 代币 ORC 跌幅超 18% ,多种通过 Orbit Bridge 跨链至 Klaytn 网络的封装资产价格出现下跌,其中 OETH、OBNB、OXRP 均已下跌超过 20% 。

Odaily星球日报提醒广大用户,由于目前 Orbit Chain 跨链桥被盗原因尚未明确,不确定黑客是否有下一步计划,请尽快撤销相关钱包批准。跨链桥作为资金密集的区域,时常受到黑客的关注,作为用户尽量做到以下三点:

  •  当事故出现时,尽快撤销对该跨链桥的合约授权,防止进一步风险蔓延,可以通过所在区块链的浏览器中 approval checker 进行撤销,同时建议大家定期审核清理一些对自身无用的合约授权,黑客常常会通过智能合约中的漏洞来多次提取资产。

  • 有频繁跨链需求的用户需要密切关注跨链桥的相关信息,比如安全公司预警的风险提示,官方预告的升级等,第一时间了解做好应对准备。

  • 作为跨链桥 LP 的参与者,面对此类事件,要积极与项目方沟通,锁定的资产要做好记录,等待事后的解决。

目前, Orbit Chain 已经暂停跨链桥合约并与黑客进行沟通,同时计划为用户发放补偿金来弥补资产受损的用户,具体补偿金额尚未公开。Odaily星球日报也将持续关注。

Lecturas Relacionadas

The Value Distribution of Stablecoins

**Summary: The Value Distribution of Stablecoins** The article argues that stablecoins are evolving from mere trading tools into broader channels for dollar access. It divides the stablecoin ecosystem into four layers to analyze how value is distributed: 1. **Issuance Layer:** Mints stablecoins, holds reserve assets, and captures the spread between reserve yield and user costs (e.g., Tether, Circle). This layer currently earns the largest profit margin. 2. **Infrastructure Layer:** Connects stablecoins to the traditional financial system, handling fiat on/off-ramps, banking integration, compliance (KYC/AML), and asset management (e.g., Bridge, BVNK). This is the "unglamorous" but critical work, building the essential bridges between crypto and real-world finance. 3. **Acquiring/Distribution Layer:** Integrates stablecoins into merchant systems, manages payment flows, and provides enterprise financial software (e.g., Stripe, Coinbase). They act as the access point for businesses. 4. **Application Layer:** The end-users and businesses that ultimately use stablecoins for payments, settlements, or as a store of value. They benefit from convenience but have little pricing power. The core thesis is that while the issuance layer currently dominates profits, the often-overlooked **infrastructure layer holds significant long-term potential**. The real challenge and barrier to mass adoption is not the on-chain transfer of stablecoins (which is simple), but the complex "last mile" integration into existing business workflows, banking systems, and regulatory frameworks across different countries. Companies in this layer are currently in a "land grab" phase, investing heavily to build networks, secure bank partnerships, and establish compliance pathways. While their position is currently pressured by the profitable issuers above and distribution platforms below, the article suggests that if stablecoins become a default financial rail for businesses, the infrastructure providers who have done the hard work of integration will ultimately gain strong pricing power and become entrenched, essential players.

marsbitHace 1 hora(s)

The Value Distribution of Stablecoins

marsbitHace 1 hora(s)

The Value Distribution of Stablecoins

The Value Distribution of Stablecoins The article argues that stablecoins are evolving from a mere trading tool into a broad "dollar channel." It analyzes the industry's value chain through four layers: 1. **Issuance Layer (e.g., Tether, Circle):** The top layer that mints stablecoins, holds reserve assets, and captures the thickest interest rate spread. 2. **Infrastructure Layer (e.g., Bridge, BVNK):** Connects stablecoins to the traditional financial system, handling critical but complex "dirty work" like fiat on/off-ramps, banking integration, compliance (KYC/AML), and cross-border settlement. 3. **Acquiring/Distribution Layer (e.g., Stripe, Coinbase):** Embeds stablecoins into merchant systems, manages payment flows, and integrates with enterprise software. 4. **Application Layer:** End-users and businesses that ultimately use stablecoins for payments, settlement, or storing value. The author posits that while the issuance layer currently captures the most profit, the most overlooked and potentially critical layer is infrastructure. The core challenge for stablecoin adoption isn't the on-chain transfer (which is simple), but bridging the gap between blockchain and the real-world financial system. This involves solving practical problems for businesses: fiat conversion, reconciliation, tax handling, and user onboarding. Infrastructure companies are currently in a difficult "land-grab" phase—building networks, securing banking relationships, and achieving compliance country-by-country. They face pressure from both the profitable issuance layer above and distribution platforms below. However, the author suggests this layer is building a crucial moat. Once stablecoins become a default business rail, the infrastructure players who have done the hard work of integration may gain significant, durable value and pricing power.

链捕手Hace 1 hora(s)

The Value Distribution of Stablecoins

链捕手Hace 1 hora(s)

How to Do Research Well: Deliberately Practice the Real Skills That Matter

No one truly teaches you how to do research. You're often given a desk, a pre-selected problem, and vague instructions to "create something new." Consequently, many people reverse-engineer the job based on visible outputs—papers, posts, announcements—learning only how to *appear* like a researcher rather than how to *become* one. True research capability is built from stacking small, trainable skills, nearly all of which can be developed through deliberate practice. **Pick Your Own Problem:** Most researchers absorb problems from advisors or trends, lacking the underlying reasoning. Choosing a problem you genuinely care about, as John Schulman advises, leads to original work. Develop "taste" like a muscle: predict experiment outcomes, guess paper results from methods, and track which findings remain important over time. **Upgrade Your Inputs:** Relying on shared reading lists (arXiv hot lists, filtered group chats) leads to unoriginal conclusions. Undervalued old literature often holds crucial insights (e.g., MoE, LSTM, backpropagation). Richard Sutton's "The Bitter Lesson" or Claude Shannon's 1952 talk on creative thinking are more predictive than lengthy modern surveys. Breadth matters as much as depth: draw from neuroscience, mechanism design, hardware knowledge, and honest statistics. Read papers directly, especially appendices and limitations sections. **Write Everything Down:** As Paul Graham noted, writing exposes flaws in seemingly mature ideas. Writing is the cheapest defense against self-deception. Following Feynman's principle, Darwin programmatically wrote down facts contradicting his theory to combat memory bias. Maintain a detailed log of hypotheses, setups, predictions, results, and updated understandings. Reviewing past logs fosters essential humility.

marsbitHace 4 hora(s)

How to Do Research Well: Deliberately Practice the Real Skills That Matter

marsbitHace 4 hora(s)

Trading

Spot
Futuros
活动图片