2025 年 1 月 Web3 安全事件盘点:总损失约 9,819 万美元

链捕手Publicado a 2025-02-05Actualizado a 2025-02-05

作者:慢雾安全团队

 

概览

2025 年 1 月,Web3 安全事件总损失约 9,819 万美元。其中,据慢雾区块链被黑档案库 (https://hacked.slowmist.io) 统计,共发生 40 起被黑事件,导致损失约 8,794 万美元,有 147 万美元得到返还,事件原因涉及合约漏洞、账号被黑和私钥泄露等。此外,据 Web3 反诈骗平台 Scam Sniffer 统计,本月有 9,220 名钓鱼事件受害者,损失规模达 1,025 万美元。

(https://dune.com/scam-sniffer/january-scam-sniffer-2025-scam-report)

安全大事件

Phemex

2025 年 1 月 23 日,总部位于新加坡的加密货币交易所 Phemex 的热钱包被攻击,导致约 7 千万美元的损失。Phemex CEO Federico Variola 在 X 平台表示:「大家好,我们正在调查有关某个热钱包的报告,请放心,冷钱包依然安全,任何人都可以查验。我们会尽快带来更多更新。」

(https://x.com/MistTrack_io/status/1882412516518789500)

NoOnes

2025 年 1 月 1 日,P2P 交易平台 NoOnes 遭攻击,其热钱包在 Ethereum、Tron、Solana 和 BSC 上出现了数百笔可疑转出交易,损失约 720 万美元。首席执行官 Ray Youssef 解释说,此次事件的原因是其 Solana 桥遭利用。

(https://x.com/ray_noOnes/status/1882744360812306885)

AdsPower

2025 年 1 月 24 日,AdsPower 的安全团队发现了一起入侵事件,黑客散播了恶意代码导致部分第三方浏览器插件遭到篡改,超 470 万美金被盗,慢雾安全团队已介入分析。如果用户有使用 AdsPower,且在 1 月 21 日 18:00 至 1 月 24 日 18:00 (UTC+8) 安装过扩展钱包或手动更新过扩展钱包,那么用户 AdsPower 上的扩展钱包可能是带后门的版本(助记词 / 私钥存在被盗风险),请尽快转移相关钱包的资产。

(https://x.com/AdsPowerBrowser/status/1882983731419570220)

Moby

2025 年 1 月 8 日,攻击者控制了用于授权 Moby 核心合约升级的私钥,导致协议遭到破坏。这次攻击导致 sOLP 和 mOLP 流动性池中的 3.77 wBTC、207.76 wETH 和 1,500,351.5 USDC 曝露于风险之中。Moby 在 Seal911 团队的协助下已追回了约 147 万枚 USDC。

(https://medium.com/moby-trade/moby-post-mortem-report-growth-plan-504ad5b0dd35)

Orange Finance

2025 年 1 月 8 日,基于 Arbitrum 的流动性管理项目 Orange Finance 由于多签配置错误被利用,导致价值 83 万美元的资产被盗。攻击者获取了每个金库的所有权,修改了它们的实现,并提取了存入的资产以及过度授权的资金。总损失中约 94%(约 78 万美元)来源于存入资产,其余 6%(约 4.7 万美元)则是由于过度授权造成的。

(https://mirror.xyz/0x6FA2aF9a4d6fFe654361F713780963C10412e7c3/gN17YMrLhKKg9YT9a391U74pWr9IhqBUDWUqDyDamjE)

特征分析及安全建议

近期账号被盗事件频发,据慢雾区块链被黑档案库统计,一月发生了 21 起账号被盗事件,约占总事件数的一半,其中政治人物或政治内容相关的账号被盗情况尤为突出。黑客或恶意行为者使用社交媒体推广 Meme 币,利用用户们的 FOMO 情绪吸引资金,然后卷款跑路,例如,X 账号 @TrumpDailyPosts 发布了 4 条推广 Meme 币的推文,在几分钟内迅速删除,卷走了约 125 万美元。因此,建议用户提高警惕,购买代币前核实信息来源,不要轻信社交媒体上的突然公告,尤其是涉及政治人物、知名机构或明星的 Meme 币,避免落入骗局。

此外,慢雾安全团队注意到,近期收到的众多受害者的求助信息均与 Telegram 上的「假 Safeguard」骗局有关,相关作恶手法和应对措施见新型手法|Telegram 假 Safeguard 骗局

Lecturas Relacionadas

Research Report Analysis: MRVL's Optical AI Booming, Why High Valuation Keeps Morgan Stanley's Star Analyst Sidelined?

Report Recap: MRVL Optical AI Boom - Why High Valuation Led Morgan Stanley's Star Analyst to Stay Neutral? Morgan Stanley analyst Joseph Moore maintained an "Equal-weight" (Neutral) rating on Marvell Technology (MRVL) on May 28, raising the price target from $172 to $195, below the trading price. This stance comes despite Marvell reporting a record quarter and significantly raising its full-year outlook (FY27 revenue ~$11.5B, up ~40%). Moore's neutral view is based on valuation. The $195 target implies ~40x CY2027 P/E. He contrasts MRVL with NVDA: both trade near ~$200, but Nvidia's forward EPS is more than double Marvell's. For MRVL's valuation to hold, it needs consistent earnings upgrades, proof of networking market share gains, or certainty on large-scale custom AI chip shipments—none of which are confirmed yet. Growth is driven by two pillars: **1) Optical Interconnect** (the faster runner): Moore raised FY27 growth expectations to >70%, with the optical module product line nearing a $1B annualized run rate. **2) Custom AI Chips** (the climber): Confidence in FY28 is growing, but a major new customer project only ramps in FY28, with no current revenue visibility. Key risks are the underperforming Storage, Enterprise, and legacy Networking segments. Moore acknowledges the real AI opportunity but believes the current price already reflects it. For the stock to work from here, investors need to see the optical business hit its targets, custom chips ramp as planned, and a recovery in the weaker business units.

marsbitHace 1 hora(s)

Research Report Analysis: MRVL's Optical AI Booming, Why High Valuation Keeps Morgan Stanley's Star Analyst Sidelined?

marsbitHace 1 hora(s)

qinbaFrank: Review and Outlook of the AI Computing Power Wave — From the Three Debates on NVIDIA to Optical Interconnect and SpaceX IPO, How is Capital Rotating?

**Summary: Retrospective and Outlook on the AI Computing Wave - A Framework for Capital Rotation** Based on a presentation by investor qinbaFrank, this analysis reviews the AI computing market trajectory since 2023 and outlines a forward-looking framework. **Key Phases and Market Debates:** The AI bull market progressed through three major debates: 1) The necessity of massive capital expenditure (late 2023). 2) The sustainability of tech giants' spending (early 2024-early 2025). 3) Potential overestimation of compute needs (early 2025). Consensus solidified in late 2025 as model capabilities and utility demonstrably improved. **Core Thesis: Penetration Rate Drives Commercialization.** Unlike the 2000 dot-com bubble, the current AI wave benefits from mature digital infrastructure, enabling faster adoption. The critical threshold is 10% penetration; surpassing it (with recent enterprise intent surveys showing ~18%) indicates entry into a rapid growth "golden period" where user scale and willingness to pay increase simultaneously. **AI vs. Internet: A Fundamental Difference.** While the internet enhanced connection efficiency, AI directly substitutes human cognition and labor. Once AI performance exceeds the "societal average" human level, its commercial value scales exponentially as payment shifts from human labor costs to AI service fees. **Investment Logic Evolution in the Compute Chain.** The focus has expanded from GPUs to a systemic re-rating of the entire hardware stack: storage/HBM, CPUs, interconnects, power, and advanced packaging. The framework is: **short-term "scarcity pricing," mid-term "upgrade pricing" (e.g., optical interconnects, power networks), and long-term "Physical AI" pricing** (edge computing, robotics). **Market Focus Shift and Adjustment Framework.** The market is transitioning from "hardware scarcity" to "commercialization validation." The ultimate anchor for the narrative is sustained high growth in model providers' Annual Recurring Revenue (ARR) and cloud business revenue, which justifies continued capital expenditure. Adjustments are categorized into three levels: * **L1 (Minor):** Driven by valuation compression or macro noise (e.g., single CPI print). Fundamentals intact. * **L2 (Moderate):** Triggered by significant macro events requiring risk repricing. Requires new data for confidence restoration. * **L3 (Major):** Involves a reset of the core industrial narrative or macro regime (e.g., AI commercialization growth stalling). The **crucial dividing line** is whether AI commercialization growth slows. Without a slowdown, pullbacks are likely L1/L2 "repricing" events. A genuine growth deceleration would signal an L2/L3 narrative reset. **Conclusion: A Foundational Civilizational Leap.** AI represents a foundational upgrade to "intelligence" itself—akin to humanity mastering fire—rather than a single-point industrial revolution. This底层能力跃迁 (underlying capability leap) will spawn successive waves of innovation (Agent, robotics, industry workflow重构). The journey will be波浪式的 (wavelike), driven by cycles of scarcity, technological upgrades, and远期兑现 (long-term realization).

marsbitHace 1 hora(s)

qinbaFrank: Review and Outlook of the AI Computing Power Wave — From the Three Debates on NVIDIA to Optical Interconnect and SpaceX IPO, How is Capital Rotating?

marsbitHace 1 hora(s)

A Country That Mined Bitcoin for 8 Years Has Built Its Own Dedicated Crypto Bank

A country that has been mining Bitcoin for eight years has established its own dedicated crypto bank. DK Bank, located in Bhutan's newly developed GMC special administrative zone, aims to fill the significant banking service gap for the cryptocurrency industry. Its CEO, Zheng YD, explained that most banks avoid crypto businesses due to a lack of risk management frameworks for decentralized and anonymous protocols. Operating under a unique "one country, two systems" governance model separate from mainland Bhutan, GMC aspires to become a financial hub for South Asia. DK Bank differentiates itself by offering integrated multi-currency accounts where users can manage both fiat currencies and stablecoins like USDT and USDC in one place, alongside services like Bitcoin-backed loans. The bank faces technical challenges in merging traditional banking systems with 24/7 crypto markets and implements rigorous on-chain and off-chain transaction monitoring for risk control. GMC's regulatory framework draws from Singaporean common law and Abu Dhabi's ADGM rules, offering a fast-track licensing process for already licensed firms while maintaining high standards. The initiative is part of Bhutan's longer-term crypto strategy, which includes Bitcoin mining since 2018. The focus, however, is on building a diversified institutional-grade crypto ecosystem—including custody and asset management—rather than retail speculative tokens. Proponents argue such sovereign crypto infrastructure is necessary, and Bhutan's early, measured approach exemplifies the thoughtful integration needed in global finance.

Foresight NewsHace 1 hora(s)

A Country That Mined Bitcoin for 8 Years Has Built Its Own Dedicated Crypto Bank

Foresight NewsHace 1 hora(s)

Trading

Spot
Futuros
活动图片