8月安全月报|钓鱼诈骗狂卷2.9亿美元,揭秘链上安全攻与防

深潮Pubblicato 2024-09-03Pubblicato ultima volta 2024-09-03

8 月全网链上安全事件累计造成损失约3.16亿美元,环比上升9.3%。

8 月全网链上安全事件累计造成损失约 3.16 亿美元,环比上升 9.3%。

仅钓鱼诈骗事件所造成损失占总损失的 93.37%,损失超 2.96 亿美元。钓鱼推文暗藏陷阱,未经验证的链接不要点击。用户需学会利用 Web3 链上工具规避风险,建立一套自己的安全操作流程并严格遵守,确保资金安全。

REKT 事件损失占比 5.97%, 共计损失约 1,893 万美元。RugPull 事件损失占比 0.19% ,共计损失约 59 万美元

最大安全事件-钓鱼诈骗

8 月 19 日,发生一笔涉及 4,064 枚 BTC 的可疑转账,约合 2.38 亿美元,随后该笔资金很快被转移到 ThorChain、eXch 等多个账户内。

截至 8 月 27 日,已有 20.5 万美元被收回。

最大安全事件-私钥泄漏

8 月 7 日,Nexera 由于合约管理凭证被恶意软件获取,导致被盗取 4,720 万个 NXRA 代币,损失约 150 万美元

最大安全事件-REKT

8 月 6 日,游戏区块链 Ronin 由于桥实现合约升级后未正确初始化遭到攻击,攻击者从桥中提取了约 4,000 个 ETH 和 200 万 USDC,价值约 1,200 万美元

截至 8 月 7 日,白帽归还了 1,200 万美元的资产,并获得了项目方额外 50 万美元的漏洞赏金。

最大安全事件-RugPull

8 月 16 日,Solana 上的 SIGMA 发生 RugPull,部署者通过出售其代币获得了 2,381.6 SOL,损失约 33 万美元

案例分析

8 月 6 日,游戏区块链 Ronin 疑似遭攻击,攻击者从桥中提取了约 4,000 个 ETH 和 200 万 USDC,价值约 1,200 万美元

流程分析:

1) Ronin 团队错误升级 Axie Infinity: Ronin Bridge V2 合约,对其合约的实现由 MainchainGatewayV3(旧)升级为 MainchainGatewayV3(新),并调用 MainchainGatewayV3(新)的 initializeV4 方法初始化;

2)攻击者发现 MainchainGatewayV3(新)的 _totalOperatorWeight 未初始化,当前为 0,则可以绕过提取资金时的签名验证。攻击者传入任意的签名数据直接提取了 3,996.09375 ETH;

3)在第二笔攻击交易中,攻击者传入任意签名,直接提取了 1,998,046 USDC;

4)攻击者通过 Uniswap 将 1,998,046 USDC兑换成 796 WETH。

 OKLink小贴士 

8 月因钓鱼诈骗事件导致巨额损失。OKLink 提醒大家,不要向任何人透露你的私钥或助记词。连接钱包前需三思而后行,授权前,使用 OKLink 代币授权管理工具防患于未然,合约风险尽在掌控,多重保障。

 👉 https://www.oklink.com/zh-hans/approval

每个人都应该建立一套自己的安全操作流程,并严格遵守,保障资金安全。

Letture associate

Why Did Zhipu Surge Nearly 30% in a Single Day?

"Global AI Model Unicorn" Zhipu's stock surged nearly 30% in a single day, reaching a new market cap high. The catalyst was the launch of its GLM-5.1-highspeed API, boasting a generation speed of **400 tokens per second**, setting a new global benchmark. This speed, roughly 3-5 times faster than industry leaders like OpenAI's GPT-4o and Anthropic's Claude, is achieved **without compromising the full-scale model's capabilities**. In the era of AI Agents requiring dozens of self-calls, such latency reduction is critical, transforming speed from a system metric into a determinant of intelligence limits. The breakthrough stems from a three-layer technical overhaul: 1. **TileRT Inference Engine**: Compiles the entire model into a continuous, always-on computation pipeline using "Warp Specialization," minimizing GPU idle time by having different processor groups handle data loading, computation, and communication in parallel. 2. **Heterogeneous Parallelism for MLA**: To efficiently run the GLM-5.1 model using the MLA attention mechanism, TileRT employs a heterogeneous strategy. One GPU handles sparse indexing/routing, while the others perform dense computation, optimizing for MLA's unique workflow. 3. **ZCube Network Architecture**: Replaces the standard Spine-Leaf (ROFT) network topology with a flat, dual-group interconnect. This design creates a single optimal path between any two GPUs, eliminating network congestion at scale and reducing latency. The business impact is significant: a 15% increase in cluster throughput (free extra capacity), a 40.6% reduction in tail latency (improved stability), and a one-third cut in networking hardware costs. Long-term, this innovation challenges the dominance of NVIDIA's integrated hardware-software stack (GPU+NVLink+InfiniBand), potentially benefiting manufacturers of high-density Leaf switches and optical modules while lowering the software barrier for domestic AI chips like Huawei's Ascend. The innovation proves that more can be achieved with the same compute, reshaping the infrastructure beyond just GPUs.

marsbit46 min fa

Why Did Zhipu Surge Nearly 30% in a Single Day?

marsbit46 min fa

Bidding Farewell to the 'Gray Gambling Game'! Polymarket Charges into the Compliance Track—How Will This Impact the Entire Crypto Industry?

From Gray to Regulated: How Polymarket’s Compliance Journey Reshapes Crypto The evolution of Polymarket, a decentralized prediction market platform, illustrates a critical trend in crypto: innovative, high-value sectors ultimately integrate into regulatory frameworks. Founded in 2020, Polymarket quickly gained traction by leveraging low-cost Layer 2 blockchain technology for event-based trading, notably during the 2024 US presidential election where its markets outperformed traditional polls. However, its "build first, comply later" approach led to a 2022 CFTC enforcement action, resulting in a $1.4 million fine and a ban from the US market. A pivotal shift occurred in 2025 under a new US administration. Polymarket strategically acquired CFTC-licensed derivatives exchange QCX for $112 million, securing a regulated pathway back into the US. This move coincided with a regulatory reversal, as the CFTC withdrew a prior proposal to ban political event contracts. The platform’s successful "regulatory acquisition" strategy, avoiding a lengthy independent licensing process, highlights a viable compliance path for crypto-native projects. Its journey from regulatory target to a CFTC-recognized entity—bolstered by a major data partnership and investment from Intercontinental Exchange (ICE)—signals the maturation of prediction markets from a "crypto novelty" into acknowledged financial infrastructure. The story underscores that genuine utility provides negotiating power with regulators and that embracing compliance does not necessarily mean sacrificing core technological advantages.

marsbit1 h fa

Bidding Farewell to the 'Gray Gambling Game'! Polymarket Charges into the Compliance Track—How Will This Impact the Entire Crypto Industry?

marsbit1 h fa

Trading

Spot
Futures
活动图片