Onyx Protocol漏洞遭黑客攻击,稳定币VUSD脱锚下跌70%

Odaily星球日报Pubblicato 2024-09-27Pubblicato ultima volta 2024-09-27

Introduzione

Onyx Protocol协议计划关闭以太坊借贷市场,并全额补偿受影响用户。

原创 | Odaily星球日报(@OdailyChina

作者 | 夫如何(@vincent 31515173 

Onyx Protocol漏洞遭黑客攻击,稳定币VUSD脱锚下跌70%

昨日,借贷平台 Onyx Protocol 被黑客利用漏洞攻击,损失价值超 380 万美元,被盗资金包括 1300 万枚 VUSD、 735 万枚 XCN、 5000 枚 DAI、 0.23 枚 WBTC 和 5 万枚 USDT。

CoinGecko 数据显示,VUSD 立即脱锚,最低跌至 0.2757 美元, 24H 跌幅达 72.43% ;截至发文,VUSD 依旧处于脱锚状态,但已回升至 0.7228 美元,24H 跌幅收窄至 28.3% 。

Onyx Protocol漏洞遭黑客攻击,稳定币VUSD脱锚下跌70%

Onyx Protocol 为了应对本次被盗事件,发布提案 OIP-46 ,建议重新启动 Onyx 的开源许可金融网络 Onyx Core,作为主要产品,与 XCN Staking 一起确保 Onyx Core 的治理和 Onyx Staker 的奖励。

根据该提案,Onyx Protocol 将在 Onyx Core 上以封闭式借贷协议运行,允许用户将 NFT 和真实资产(RWA)包装并借贷,同时支持来自多个链的加密资产。此举将关闭基于以太坊的借贷市场,并全额补偿所有受影响用户,按照 1:1的比例支付其提供的资产。

事件回顾

9 月 26 日 20: 48 ,安全公司 Cyvers 平台在 X 上发文,经其系统检测到涉及 Onyx 可疑交易,损失或已达 320 万美元。

Onyx Protocol漏洞遭黑客攻击,稳定币VUSD脱锚下跌70%

同日 21: 55 ,安全公司 PeckShield 在 x 平台发文称,抽走资金包括 410 万枚 VUSD、 735 万枚 XCN、 5000 枚 DAI、 0.23 枚 WBTC 和 5 万枚 USDT。

Onyx Protocol漏洞遭黑客攻击,稳定币VUSD脱锚下跌70%

VUSD 官方随后发布公告称:“遭遇安全漏洞,导致超过 1300 万美元的 VUSD 被盗。黑客随后将盗取的 VUSD 出售至流动性池,导致二级市场流动性损失约 150 万美元。事件发生后,智能合约已被暂停,以便进行适当沟通,目前确认 VUSD 代码库及储备没有漏洞。恶意行为者将根据服务条款被列入黑名单,待调查结束后,VUSD 智能合约服务将恢复,参与者可继续套利。

官方称,VUSD 仍由超额抵押的资产全额支持,机构用户可按市场价格赎回和铸造 VUSD。VUSD 正在与 Onyx DAO 及相关当局合作识别攻击者,并计划在未来探索零售赎回所需的许可证。

Onyx Protocol 被盗原因是什么?

安全公司 PeckShield 表示,促成黑客攻击的问题与 NFT 清算合约有关,该合约未能正确验证(不可信的)用户输入,导致自我清算奖励金额被人为扩大。

Onyx Protocol漏洞遭黑客攻击,稳定币VUSD脱锚下跌70%

Onyx Protocol 引用 PeckShield 关于“黑客利用 NFTLiquidation 合约漏洞攻击”的推文表示,黑客利用该协议从中抽走了 VUSD,此次漏洞可以从 NFT 清算合约中的一个安全隐患中识别和理解。主要问题并非 Empty market,而是 NFT Liquidation 合约,XCN 质押和 XCN Farming 未受影响。

知名安全公司 CertiK 告诉Odaily星球日报:“Onyx Protocol 的清算合约没有校验用户传入的 oTokenCollateral 和 oTokenRepay 地址。简单来说,攻击者通过自己部署的恶意合约欺骗 Onyx 协议他已经归还了欠款,从而在不归还欠款的情况下取回了所有抵押品”。

PeckShield 还提到,Onyx 被盗原因可能是分叉 Compound V2 代码库中已知精度问题,该漏洞已被攻击者利用。CertiK 也表示,Compound V2 的精度损失问题导致的"Empty Market Vulnerability"确是一个已经被多次攻击的已知问题,去年的 Hundred Finance 以及今年 5 月份的 Sonne Finance 都因为精度损失遭到攻击。

Odaily星球日报调查发现,去年 11 月,Onyx 同样受到黑客攻击,被攻击的原因同样是黑客利用 Compound V2 分叉版本背后的已知舍入问题。但当时 Onyx 社区负责人 Alex 表示,漏洞得到修复,正与合作伙伴一起处理后续。

Onyx Protocol漏洞遭黑客攻击,稳定币VUSD脱锚下跌70%

据悉,Onyx Protocol 是以太坊生态的链上借贷平台,旨在提供代币和 NFT 的借贷市场,其中关于代币部分可能在开发过程中引用了 Compound V2 的代码,算是 Compound V2 分叉。但当时的 Compound V2 的代码存在精度问题,后续 Compound 自身已经修改相关问题,但在这之前分叉的项目却无法避免相关问题。

关于 Onyx Protocol 被盗后续进展,Odaily星球日报将持续关注。

Letture associate

Retail Investors' 'Lead Brother' Serenity vs. Newly Minted Stock God Leopold: How Are the Two Top Hunters Mining AI's 'Physical Limits'?

The article profiles two prominent figures, Serenity and Leopold Aschenbrenner, who are gaining attention for their unconventional investment strategies focused on the physical constraints of the AI boom, moving beyond mainstream software narratives. Serenity, an anonymous online trader, advocates a "shiso leaf" theory. He targets small-cap companies with monopolies on critical, overlooked components in the AI hardware supply chain, such as specific semiconductor materials. His deep, technical analysis of bottlenecks in areas like co-packaged optics (CPO) has reportedly yielded massive returns, though his anonymity and focus on illiquid micro-cap stocks pose significant risks for followers. Leopold Aschenbrenner, a former OpenAI researcher, founded a multi-billion dollar hedge fund. His macro thesis argues that physical infrastructure—power grids, land, data centers—is the true bottleneck for AI growth, lagging far behind chip production. Consequently, his fund employs an infrastructure arbitrage strategy: heavily investing in storage and compute infrastructure companies while placing massive bearish bets (put options) against major semiconductor stocks, betting their valuations will correct as physical constraints become apparent. While their methods differ—Serenity drills into microscopic supply chain details, while Leopold takes a macroscopic, infrastructure-focused view—both share a core belief: the real power and investment alpha in the AI era lie in controlling scarce physical resources, not just software. The article concludes by noting the inherent risks in both approaches, such as liquidity issues for micro-caps and timing risks for macro bets, but suggests they signal a broader market re-evaluation of AI's foundational assets.

marsbit8 min fa

Retail Investors' 'Lead Brother' Serenity vs. Newly Minted Stock God Leopold: How Are the Two Top Hunters Mining AI's 'Physical Limits'?

marsbit8 min fa

Who Will Make Money in the Age of Agents?

In the Agents era of blockchain, traditional value capture theories face challenges. The "Fat Protocol" theory, dominant since 2016, suggested protocols capture most value as their tokens are essential for network use. However, the proliferation of interchangeable L1s, L2s, and modular layers has eroded protocol scarcity and pricing power. Conversely, the "Fat App" theory posits that applications capturing user relationships (like wallets and exchanges) become the primary value layer by controlling distribution and transaction flows. This aligns with the current "Great Repricing" cycle. Agents disrupt this logic. As software users, they lack brand loyalty, prioritize cost and efficiency, and switch between platforms seamlessly. This undermines the front-end UX moats that "Fat Apps" rely on. The article explores several potential futures: 1. **Headless Applications:** Current leading apps could strip their front-ends and become backend API infrastructure for Agents, preserving their role. 2. **Protocol Resurgence:** If integration becomes trivial, Agents might bypass aggregators and interact directly with protocols, reviving "Fat Protocol" dynamics. 3. **Pricing Power Collapse:** Agents' rational, frictionless routing could commoditize the entire stack, compressing margins toward cost and leaving little profit for intermediaries. 4. **Unprecedented Activity:** Agents may enable new, high-frequency, machine-to-machine economic activities, expanding the total value pie even if margins are thin. 5. **A New, Unnamed Model:** Historically, major tech shifts (like the internet's attention economy) create unforeseen business models. The Agents era may spawn entirely new ways to capture value. The most likely outcome is a coexistence where "Fat Apps" continue to serve human users valuing UX, while a separate, Agent-driven economy emerges governed by different rules—where loyalty is based on factors like liquidity, latency, and settlement guarantees rather than brand.

marsbit1 h fa

Who Will Make Money in the Age of Agents?

marsbit1 h fa

Trading

Spot
Futures
活动图片