# Social Engineering Articoli collegati

Il Centro Notizie HTX fornisce gli articoli più recenti e le analisi più approfondite su "Social Engineering", coprendo tendenze di mercato, aggiornamenti sui progetti, sviluppi tecnologici e politiche normative nel settore crypto.

DeFi Has Reached Its Most Dangerous Moment: The Real Vulnerabilities Are Not in the Code

DeFi in Peril: The Real Vulnerability Isn't in the Code April 2026 marked a paradigm shift in DeFi security, with over $625 million lost across 30 incidents—the worst month in crypto history by event count. Crucially, none of the major exploits (Drift Protocol: $285M, KelpDAO: $292M, Wasabi Protocol: $4.5M) resulted from smart contract vulnerabilities. Instead, failures occurred in the operational "plumbing": social engineering to compromise multi-signature councils, a single-point-of-failure 1-of-1 bridge validator, and stolen admin private keys. These events expose a fundamental misalignment: the industry's security model has long focused on code audits, while the actual attack surface has shifted to privileged access points and off-chain infrastructure. The article introduces the term "OpenFi" to describe this reality: permissionless, on-chain, yet operationally dependent on trusted third parties (admins, validators, oracles) at key junctures. The KelpDAO exploit vividly demonstrated asymmetric "contagion risk." A configuration error in a smaller protocol triggered a panic, causing approximately $13.2 billion in outflows from larger, unaffected protocols like Aave within 48 hours, as users fled uncertain collateral. The core dilemma is the double-edged sword of centralization. Operational levers like emergency councils (e.g., Arbitrum freezing stolen funds post-KelpDAO) enable crisis response but also create catastrophic attack surfaces if compromised (e.g., Drift). The path forward demands radical honesty: protocols must clearly disclose their trust assumptions, operational levers, and failure modes. The industry must treat operational security (key management, configurations, incident response) with the same rigor as code security. Survival depends on building systems whose risks can be understood, priced, and insured, moving beyond the outdated "code is law" mantra to a mature model of disclosed and managed trust.

链捕手05/25 15:17

DeFi Has Reached Its Most Dangerous Moment: The Real Vulnerabilities Are Not in the Code

链捕手05/25 15:17

Morse Code "Stole" $440,000 from Bankr, Undermining Trust in AI Agent Interactions Again

On May 20th, the AI agent platform Bankr reported an attack where 14 user wallets were compromised, resulting in losses exceeding $440,000. The incident, confirmed by security firm SlowMist, was a social engineering attack exploiting the trust layer between automated agents, similar to an attack on May 4th that stole $150k-$200k from a Grok-associated wallet. Bankr allows users and AI agents to manage wallets and execute transactions via instructions sent to @bankrbot on X. The platform monitors posts from specific agents like @grok, treating them as potential transaction commands, especially if the agent holds a "Bankr Club Membership" NFT which grants high-permission operations. The attacker exploited this design. First, they airdropped the required NFT to Grok's wallet. Then, they posted a Morse code message on X requesting a translation from Grok. The AI agent helpfully decoded and replied, but the decoded text contained a direct instruction to @bankrbot to transfer a large sum of DRB tokens to the attacker's address. Bankr's system, monitoring Grok's feed and verifying the NFT permissions, automatically signed and broadcast the transaction. The core issue is a flawed trust assumption: Bankr treated Grok's natural language output as authorized financial commands without verifying the intent. LLMs like Grok cannot distinguish between a genuine user request and a manipulated instruction. Using encoded messages like Morse code bypasses potential content filters, as the translation task itself appears harmless. This attack highlights a systemic vulnerability in platforms granting on-chain execution rights to AI agents. While Bankr has paused transactions and promised full reimbursement from its treasury, the incident underscores that defenses against "malicious-injection-via-LLM-output" were not part of the original security model. As AI agents gain financial agency, such trust-layer exploits represent a growing threat class.

marsbit05/20 03:32

Morse Code "Stole" $440,000 from Bankr, Undermining Trust in AI Agent Interactions Again

marsbit05/20 03:32

18-Year-Old Hacker's Boastful Discord Display Leads to Uncovering of $19 Million Theft Case

An 18-year-old hacker from the U.S., Dritan Kapllani Jr., has been exposed by on-chain investigator ZachXBT for his alleged involvement in multiple cryptocurrency social engineering attacks, with total funds stolen estimated at $19 million. The case gained attention after Dritan inadvertently revealed his involvement during a Discord voice call in April 2026, where he screen-shared his Exodus wallet containing approximately $3.68 million to show off his wealth during a "Band 4 Band" argument. Tracing this wallet address led investigators to uncover its connection to a major theft from March 14, 2026, where 185 Bitcoin (worth around $13 million at the time) was stolen. Approximately $5.3 million from that heist was funneled into Dritan’s wallet. Further analysis linked the same wallet to over $5.85 million from other social engineering attacks dating back to 2025. While Dritan has not yet been formally charged, he is identified as "Co-Conspirator 1" in recently unsealed court documents related to the 185 Bitcoin theft case. Another individual, Meme coin KOL yelotree, is also implicated for allegedly assisting with money laundering through a car rental business. Dritan, who had been living a lavish lifestyle and was previously seen as untouchable within hacking circles, turned 18 recently, making him legally accountable. His previous "immunity" has ended as law enforcement closes in.

Odaily星球日报05/13 00:45

18-Year-Old Hacker's Boastful Discord Display Leads to Uncovering of $19 Million Theft Case

Odaily星球日报05/13 00:45

In-Depth Reconstruction of the $285 Million Drift Hack: How Should DeFi Governance Move Beyond "Amateur Hour"?

On April 1, 2026, Drift Protocol, the largest perpetual futures DEX on Solana, suffered a catastrophic hack resulting in a loss of $285 million. The attack, attributed to a sophisticated social engineering campaign rather than a technical exploit, unfolded over several months. Hackers first infiltrated Drift’s internal circles by posing as a legitimate market maker, building trust over time. They then exploited Solana’s "Durable Nonce" feature to trick core team members into blindly signing transactions that granted administrative control. A critical vulnerability was introduced when Drift migrated to a 2/5 multisig structure without a timelock, allowing instant execution of privileged transactions with just two signatures. The attackers finally triggered the attack by adding a fake token (CVT) to the whitelist, manipulating its oracle price, and using it as collateral to drain the protocol’s treasury. The incident highlights fundamental flaws in DeFi governance, including overreliance on multisig mechanisms that lack intent verification and are vulnerable to social engineering. It underscores the misalignment between retail-grade security tools and institutional-scale treasury management. The hack signals the need for a security paradigm shift in DeFi, including adoption of Hardware Security Modules (HSMs) for key management, intent-based policy engines for transaction validation, and professional third-party custody solutions to ensure institutional-grade safety.

marsbit04/13 12:00

In-Depth Reconstruction of the $285 Million Drift Hack: How Should DeFi Governance Move Beyond "Amateur Hour"?

marsbit04/13 12:00

活动图片