Convergence пытается начать переговоры с хакером

cryptonews.ruPublished on 2023-04-07Last updated on 2024-08-07

Согласно данным блокчейна от 6 августа, команда Convergence Finance отправила поздравительное сообщение злоумышленнику, который слил ее протокол на 212 000 долларов. Она также попыталась начать переговоры о возврате части средств, заявив: «мы считаем, что вы действовали как белый хакер».

Транзакция, размещенная в сети Ethereum в 12:56 по Гринвичу, доставила злоумышленнику сообщение от команды Convergence.

«Привет, Convergence Finance хотела бы обсудить с вами ошибку, которую вы обнаружили и успешно использовали 1 августа. Поздравляем с обнаружением! Мы считаем, что вы действовали как белый хакер, и мы хотели бы обсудить с вами средства (65,8 ETH), которые вы отправили в TornadoCash», — говорится в сообщении.

В сообщении был указан контактный адрес электронной почты и адрес Ethereum, по которому можно вернуть средства. Также было предупреждение, что если в течение 48 часов не будет получен ответ, «мы перейдем к новому этапу».


Сообщение Convergence Finance злоумышленнику. Источник: Etherscan.

Convergence Finance — это протокол децентрализованного финансования (DeFi), интегрированный со Stake DAO (SDT) и Convex (CVX). Он пытается повысить доходность этих протоколов, объединяя средства инвесторов в общую казну и выпуская собственный токен «CVG», который представляет право собственности на эту казну.

2 августа Convergence подвергся атаке, когда кто-то воспользовался уязвимостью в CvxRewardDistributor, чтобы выпустить 58 миллионов токенов CVG. Эти токены были проданы за $210 000, что обрушило цену CVG более чем на 99% в процессе. Злоумышленник также слил $2000 долларов невостребованных вознаграждений из Convex, которые принадлежали пользователям Convergence. Слитая криптовалюта была переведена в протокол микширования криптовалют Tornado Cash (TORN) в явной попытке отмыть средства.

Эксплоиты Web3 продолжают представлять опасность для пользователей криптовалют. Согласно отчету PeckShield, в июле из-за эксплоитов была потеряна криптовалюта на сумму более 266 миллионов долларов. Индийская криптовалютная биржа WazirX подверглась крупнейшей в этом месяце атаке, в результате которой убытки составили более 230 миллионов долларов.

Related Reads

Just now, DeepSeek V4 updates with DSpark, improving inference speed by 80%

DeepSeek has updated its DeepSeek V4 model with the DSpark speculative decoding framework, achieving a significant 60-85% speedup in generation for Flash models and 57-78% for Pro models while maintaining the same overall throughput. This engineering-focused update, rather than a core architectural change, introduces DSpark to address latency and throughput bottlenecks in high-concurrency production environments. DSpark combines high-throughput parallel generation with adaptive load-aware verification. Its key innovations include a semi-autoregressive generation architecture to model dependencies within token blocks and a hardware-aware confidence-scheduled verification system. This system uses a confidence head to predict token acceptance probabilities, allowing it to dynamically optimize verification length per request and allocate compute only to tokens with the highest expected payoff. The asynchronous scheduler is designed for real-world deployment, ensuring zero-overhead scheduling and continuous CUDA graph replay while preserving the target model's output distribution. In tests across mathematical reasoning, code generation, and daily dialogue, DSpark outperformed state-of-the-art models like Eagle3 and DFlash, increasing average acceptance length by 26.7%-30.9% and 16.3%-18.4% respectively on Qwen3 target models. DeepSeek also open-sourced DeepSpec, a full-stack codebase for training and evaluating speculative decoding draft models, providing a standardized toolkit that includes data preparation tools, model implementations, training code, and evaluation scripts.

marsbit2h ago

Just now, DeepSeek V4 updates with DSpark, improving inference speed by 80%

marsbit2h ago

BIT Research: The 2028 Halving Is Not the End, the Real Shake-Up of the Bitcoin Mining Industry Is Just Beginning

The Bitcoin mining industry is undergoing its most complex structural adjustment since inception. Despite Bitcoin's price holding near $61,000 and the network hash rate approaching a record 1 ZH/s, miner profitability is deteriorating. The industry is operating close to its breakeven point, with the 2028 halving expected to accelerate consolidation. The challenges extend beyond the halving's subsidy reduction; the industry's revenue model has yet to successfully transition towards a fee-driven structure. Increasingly, mining companies are evolving from simple Bitcoin producers into infrastructure and energy operators, including providers of AI/HPC computing power. Competition is shifting from pure hash rate expansion to business model upgrades. Economic pressure is evident. The theoretical daily mining revenue at current prices is around $78 million, yet the actual figure is only about $33 million—a 136% gap. Transaction fees remain low at roughly $220k daily, far below historical implied levels. With a current estimated industry-wide breakeven price near $65,000, mining alone is struggling to generate ideal profits. The 2028 halving is projected to push the fundamental production cost floor to approximately $93,289. This will likely accelerate a shift towards consolidation among larger, well-capitalized miners with diversified revenue streams. Competitive advantage will belong to institutionalized players with access to low-cost energy, AI/HPC hosting operations, and stronger balance sheets. In essence, Bitcoin mining is transitioning from a "mining business" to an "infrastructure business." Future profitability and resilience will depend less on block rewards and more on diversified income sources like energy management and computational infrastructure services. For investors, the key question is not the halving itself, but which miners can successfully navigate this business model transformation.

marsbit4h ago

BIT Research: The 2028 Halving Is Not the End, the Real Shake-Up of the Bitcoin Mining Industry Is Just Beginning

marsbit4h ago

This is How God Karpathy Uses Claude?

Andrej Karpathy, a prominent figure in AI, has reportedly joined Anthropic, leading to a noticeable decrease in his open-source contributions and social media activity. A document claiming to be his personal "CLAUDE.md" file—a set of instructions for the Claude AI to follow within a specific codebase—has been circulating online. While its authenticity is unverified, the content aligns closely with Karpathy's publicly shared principles on effective AI-assisted programming. The document outlines key rules for AI coding assistants, emphasizing the importance of reading existing code thoroughly before writing new code to maintain consistency. It advises against over-engineering, advocating for simple, surgical modifications that match the project's existing style. Other guidelines include clarifying assumptions upfront, writing meaningful tests, thoughtful debugging, and carefully considering dependencies. The core message is that these principles help prevent common AI coding failures, such as introducing unnecessary abstractions, style drift, or making invisible architectural decisions. The community has noted that even experts like Karpathy require detailed instructions to guide AI effectively, akin to managing a junior developer. A related GitHub repository, "andrej-karpathy-skills," which encapsulates these ideas, is reported to significantly reduce Claude's code error rate. Ultimately, the advice stresses that the best CLAUDE.md is tailored to one's own tech stack and coding practices.

marsbit4h ago

This is How God Karpathy Uses Claude?

marsbit4h ago

Trading

Spot
活动图片