2022上半年Web3黑客常用的攻击方式有哪些?

成都链安Pubblicato 2022-08-25Pubblicato ultima volta 2022-08-25

Introduzione

今天,我们就2022上半年Web3黑客常用的攻击方式展开分析,看看在所有被利用的漏洞中,哪些频率最高,以及如何防范。

今天,我们就2022上半年Web3黑客常用的攻击方式展开分析,看看在所有被利用的漏洞中,哪些频率最高,以及如何防范。

上半年因漏洞造成的总损失有多少?

据成都链安鹰眼区块链态势感知平台监控显示,2022上半年共监测到因合约漏洞造成的主要攻击案例42次,约53%的攻击方式为合约漏洞利用。

通过统计,2022上半年共监测到因合约漏洞造成的主要攻击案例42次,总损失达到了6亿4404万美元。

在所有被利用的漏洞中,逻辑或函数设计不当被黑客利用次数最多,其次为验证问题、重入漏洞。

哪些类型的漏洞曾导致重大损失?

2022年2月3日,Solana跨链桥项目Wormhole遭到攻击,累计损失约3.26亿美元。黑客利用了Wormhole合约中的签名验证漏洞,这个漏洞允许黑客伪造sysvar帐户来铸造wETH。

2022年4月30日,Fei Protocol官方的Rari Fuse Pool遭受闪电贷加重入攻击,总共造成了8034万美元的损失。本次攻击对项目方造成了无法挽回的损失,8月20号,官方表示项目正式关闭了。

Fei Protocol事件回顾:

由于漏洞出现在项目基本协议中,攻击者不止攻击了一个合约,以下仅分析一例。

攻击交易

0xab486012f21be741c9e674ffda227e30518e8a1e37a5f1d58d0b0d41f6e76530

攻击者地址

0x6162759edad730152f0df8115c698a42e666157f

攻击合约

0x32075bad9050d4767018084f0cb87b3182d36c45

被攻击合约

0x26267e41CeCa7C8E0f143554Af707336f27Fa051

#攻击流程

1. 攻击者先从Balancer: Vault中进行闪电贷。

2. 将闪电贷的资金用于Rari Capital中进行抵押借贷,由于Rari Capital的cEther实现合约存在重入。

攻击者通过攻击合约中构造的攻击函数回调,提取出受协议影响的池子中所有的代币。

3. 归还闪电贷,将攻击所得发送到0xe39f合约中

本次攻击主要利用了Rari Capital的cEther实现合约中的重入漏洞,被盗资金超过28380 ETH(约8034万美元)。

审计过程中最常出现的漏洞有哪些?

在审计过程中最常见出现的总体来说分为四大类:

1.ERC721/ERC1155重入攻击:

在通过链必验形式化验证平台检测合约时不乏存在ERC721 / ERC1155标准相关的业务合约,在ERC721中,ERC1155中存在分别存在一个onERC721Received()/onERC1155Received()函数用于转账通知,类似于以太坊转账的fallback()函数,在相关的业务合约中使用ERC721/ERC1155标准中的_safeMint(),_safeTransfer(),safeTransferFrom()进行铸币或者转账时都会触发转账通知函数。如果在转账的目标合约中的onERC721Received()/onERC1155Received()中包含了恶意代码,就可能形成重入攻击。除此之外在相关业务函数未严格按照检查-生效-交互模式设计,上述两点共同导致了漏洞的产生。

2.逻辑漏洞:

1) 特殊场景考虑缺失:

特殊场景往往是审计最需要关注的地方,例如转账函数设计未考虑自己给自己转账导致无中生有。

2)设计功能不完善:

存放费用的合约没有提取功能,借贷合约不含清算功能等。

3.鉴权缺失:

铸币、设置合约特殊角色、设置合约参数的相关函数没有鉴权,导致三方地址也可以调用。

4.价格操控:

Oracle价格预言机未使用时间加权平均价格;

未使用价格预言机,直接使用合约中两种代币的余额比例作为价格等。

实际被利用的漏洞有哪些?哪些漏洞能在审计阶段发现?

根据成都链安鹰眼区块链安全态势感知平台所感知的安全事件统计,审计过程中出现的漏洞几乎都实际场景中被黑客利用过,其中合约逻辑漏洞利用仍然为主要部分。

通过成都链安链必验-智能合约形式化验证平台检测和安全专家人工检测审计,以上漏洞均能在审计阶段被发现,并且可由安全专家在做出安全评估后提出相关安全修补建议供客户作为修复参考。

Crypto di tendenza

Letture associate

Annualized Revenue Exceeds $20 Billion, Kalshi Aims to Become the First Prediction Platform IPO?

Kalshi, a leading U.S. prediction markets platform, is reportedly in early, informal discussions for an Initial Public Offering (IPO). The company's annualized revenue now exceeds $2 billion, fueled by its dominance of over 90% of the domestic prediction market activity. This growth stems from a surge in trading volume—reaching a total of $52.7 billion—and an increase in fee rates, largely driven by sports event contracts like the NBA playoffs and the 2026 FIFA World Cup. Monthly active users are approximately 2 million. Kalshi recently raised $1 billion in a funding round led by Coatue Management, valuing the company at $22 billion. It has also expanded its offerings to include Bitcoin perpetual contracts and plans to launch a dedicated trading platform, Kalshi Pro. However, Kalshi's path to an IPO faces significant regulatory hurdles. The core risk involves jurisdictional conflicts, as multiple U.S. states are challenging its operations under local gambling laws. For instance, Arizona has filed criminal charges against the platform, while states like Kentucky have filed lawsuits. Kalshi and the Commodity Futures Trading Commission (CFTC) argue that its event contracts fall under exclusive federal jurisdiction as "swaps." The outcomes of these ongoing legal battles could critically impact Kalshi's core revenue and its IPO timeline. Analysts suggest that while an IPO could theoretically occur by late 2026, a more likely timeframe is late 2027 or 2028, contingent on resolving legal issues and favorable market conditions. If successful, its fundraising could significantly exceed $1 billion, given its current valuation and revenue multiple.

Foresight News16 min fa

Annualized Revenue Exceeds $20 Billion, Kalshi Aims to Become the First Prediction Platform IPO?

Foresight News16 min fa

Financing Weekly Report | 11 Public Financing Events, Stablecoin Payment Infrastructure Company Trace Finance Completes $32 Million Series A Round Led by CoinFund

Financing Weekly Report | 11 public funding events recorded, with a total scale exceeding $264 million. The stablecoin payment infrastructure sector remains a hot spot. Key Deals: - Trace Finance, a stablecoin payment infrastructure firm, raised $32 million in a Series A round led by CoinFund to expand in Latin America and Asia-Pacific. - Galaxy Ventures co-led a $140 million Series A round for Karta, a US credit card provider for global travelers without requiring an SSN. - Instant payment platform Interchecks completed a $50 million Series C round. - Paradigm led a $9 million Series A for Latin American cross-border payment app El Dorado. - Range, a stablecoin compliance startup, raised $8.3 million in an oversubscribed Series A. - RWA infrastructure project Renaiss raised $1.5 million to expand its on-chain collectibles platform. Sector Breakdown: - Infrastructure & Tools: 6 deals, including the above-mentioned Trace Finance, Range, and Renaiss. - Centralized Finance (CeFi): 3 deals, led by Karta's $140 million round. - DeFi: 1 deal – reinsurance protocol Re secured strategic investment from Coinbase Ventures. - Prediction Markets: 1 deal – K25.ai completed a $10 million Pre-A round from NewGen. Other notable transactions include digital asset depository RDC raising $7 million, ad-tech startup EarnOS securing $6 million, and a $1 million strategic investment in LitVM, a ZK Layer 2 for Litecoin. The report highlights sustained investor interest in stablecoin payment infrastructure, compliant on-chain finance, and real-world asset (RWA) tokenization.

marsbit58 min fa

Financing Weekly Report | 11 Public Financing Events, Stablecoin Payment Infrastructure Company Trace Finance Completes $32 Million Series A Round Led by CoinFund

marsbit58 min fa

When Transfers Become Truly Frictionless: How Sui Uses 'Zero Gas' to Become the Underlying Infrastructure for Stablecoin Payments

Title: Sui Launches Zero-Gas Stablecoin Transfers to Become the Foundation for Stablecoin Payments Sui has introduced a zero-gas fee feature for peer-to-peer stablecoin transfers, eliminating the need for users or businesses to hold separate SUI tokens to pay transaction costs. This innovation, built on a new underlying account architecture called Address Balances, significantly reduces validator processing costs for eligible transactions. Currently, the feature applies to a whitelist of stablecoins for transfers meeting a minimum amount, effectively preventing spam. This development aims to unlock mainstream payment use cases for stablecoins—such as everyday purchases, remittances, and subscriptions—by removing cost and complexity barriers. It is also positioned to benefit high-frequency micro-payments for AI agents and institutional B2B payments, reducing operational friction. Major custody provider Fireblocks has already announced support. The move follows Sui processing over $1 trillion in stablecoin transfer volume since August 2025. Looking ahead, Sui plans to enhance this infrastructure with protocol-level confidential transactions later in 2026, aiming to provide scalable, free, and privacy-preserving payments. Together, these advancements strengthen Sui's goal of becoming the default settlement layer for stablecoin payments.

marsbit59 min fa

When Transfers Become Truly Frictionless: How Sui Uses 'Zero Gas' to Become the Underlying Infrastructure for Stablecoin Payments

marsbit59 min fa

Ethereum Is Retracing the Path of the Internet and Linux: No One Yields, and the Neutral Party Ultimately Prevails

This article argues that Ethereum is following the historical path of open, neutral systems like the Internet and Linux, which eventually triumphed over proprietary, centrally-controlled alternatives. Major financial institutions like JPMorgan, Stripe, and Circle are building their own proprietary blockchains or networks (e.g., Tempo, Arc), but will never agree to build on a competitor's controlled infrastructure. This creates the perfect opportunity for Ethereum as the only neutral, credibly neutral settlement layer that no single entity controls. The piece draws parallels to the 1990s, when experts like Bill Gates predicted proprietary networks (from Microsoft, Oracle) would win over the open Internet, and when Sun Microsystems' Unix lost to the open-source "bazaar" development model of Linux. This model, described in Eric Raymond's "The Cathedral and the Bazaar," thrives on permissionless innovation where countless contributors improve the system, outpacing any centralized competitor. Ethereum embodies this through its decentralized development, broad validator distribution, and credible neutrality—rules that are transparent, equally applied, hard to change, and open to all. This has attracted over a million developers and major institutions like Coinbase, BlackRock, and JPMorgan, who choose Ethereum for its security, ecosystem, and sovereignty (the inability of any single party to change the rules). While proprietary chains offer initial speed and control, they inherit the downsides of both centralization and decentralization without the long-term innovation benefits. The article concludes that, just as open systems historically win, Ethereum is poised to become the foundational, neutral settlement layer for global finance.

marsbit1 h fa

Ethereum Is Retracing the Path of the Internet and Linux: No One Yields, and the Neutral Party Ultimately Prevails

marsbit1 h fa

Trading

Spot
Futures

Articoli Popolari

Come comprare BAL

Benvenuto in HTX.com! Abbiamo reso l'acquisto di Balancer (BAL) semplice e conveniente. Segui la nostra guida passo passo per intraprendere il tuo viaggio nel mondo delle criptovalute.Step 1: Crea il tuo Account HTXUsa la tua email o numero di telefono per registrarti il tuo account gratuito su HTX. Vivi un'esperienza facile e sblocca tutte le funzionalità,Crea il mio accountStep 2: Vai in Acquista crypto e seleziona il tuo metodo di pagamentoCarta di credito/debito: utilizza la tua Visa o Mastercard per acquistare immediatamente BalancerBAL.Bilancio: Usa i fondi dal bilancio del tuo account HTX per fare trading senza problemi.Terze parti: abbiamo aggiunto metodi di pagamento molto utilizzati come Google Pay e Apple Pay per maggiore comodità.P2P: Fai trading direttamente con altri utenti HTX.Over-the-Counter (OTC): Offriamo servizi su misura e tassi di cambio competitivi per i trader.Step 3: Conserva Balancer (BAL)Dopo aver acquistato Balancer (BAL), conserva nel tuo account HTX. In alternativa, puoi inviare tramite trasferimento blockchain o scambiare per altre criptovalute.Step 4: Scambia Balancer (BAL)Scambia facilmente Balancer (BAL) nel mercato spot di HTX. Accedi al tuo account, seleziona la tua coppia di trading, esegui le tue operazioni e monitora in tempo reale. Offriamo un'esperienza user-friendly sia per chi ha appena iniziato che per i trader più esperti.

74 Totale visualizzazioniPubblicato il 2024.12.11Aggiornato il 2026.06.02

Come comprare BAL

Discussioni

Benvenuto nella Community HTX. Qui puoi rimanere informato sugli ultimi sviluppi della piattaforma e accedere ad approfondimenti esperti sul mercato. Le opinioni degli utenti sul prezzo di BAL BAL sono presentate come di seguito.

活动图片