社群竟拍手称快?MEV机器人损失146万美元事件分析

CertikPublished on 2022-09-29Last updated on 2022-09-29

Abstract

MEV机器人(0xBAD…)被(0xB9F78...)攻击,导致146万美元的资产受到损失。

MEV机器人(0xBAD…)被(0xB9F78...)攻击,导致146万美元的资产受到损失。

虽然合约无法被看到并被证实细节,但交易流程显示,漏洞合约被(0xBAD…)批准转移了1101枚ETH。

此前,该MEV机器人本身也刚刚完成了一笔交易,从仅仅11美元的USDT交易中获利了15万美元。

什么是MEV

MEV是 “矿工可提取价值(Miner Extractable Value)”或 “最大可提取价值(Maximal Extractable Value)”的缩写。矿工,或者更准确地说是验证者(现在以太坊已经转为Proof of Stake),有能力在区块内对交易进行排序。这种重新安排交易顺序的能力意味着他们可以领先于用户的交易。

最常见的MEV形式之一被人们称为三明治攻击,即验证者看到有人试图购买某种资产,所以他们在原始交易之前就“插队”进行自己的交易并购买资产,然后加价卖给原始购买者。

通过此行为,他们可从用户身上榨取价值,而用户往往并不知道他们没有得到他们所期望的价格。因此此类MEV机器人可以多次重复交易从而获得丰厚的利润。

这里有个很简单的例子或许可以帮你直接理解:如果一个代币的价格是1美元,你买了价值100万美元的代币,你自然会期待得到100万个代币(先忽略其他费用)。

但是,如果一个MEV机器人在一个未确认的区块中发现了你的交易,它将在你之前以1美元的价格购买N量的代币。在你的交易执行之前,价格可能会增加到2美元甚至更高,所以你最终只收到50万个代币。你的这笔交易也将代币价格提升到了3美元。随后,MEV机器人将以现在的高价出售它所在你之前就购买的代币。

事件总结

2022年9月27日,MEV机器人(0xBAD..)被攻击利用,造成了1,463,112.71美元的资产损失。

MEV机器人的所有者给攻击者发了一条信息,“祝贺”他们发现了 “难以发现”的漏洞,并为他们提供了20%的赏金以换取暂时不采取法律行动的保证。该保证的最后生效期限是北京时间2022年9月29日早7点59分。

在MEV机器人被利用之前,它已经预先运行了一笔交易,该交易从仅仅11美元的USDT中获利了15万美元。该交易是一个180万美元的系列兑换,从cUSDC 兑换成WETH再到USDC。由于交易过程中的价格下跌,180万美元的SWAP只换来了约500美元的USDC。

在MEV机器人漏洞被公开后,钱包所有者给MEV漏洞利用者发了消息。除了请求归还资金以及提供“漏洞发现的奖励”,还解释说他们错误地触发了SWAP。而真正的目的其实是为了分装他们的代币。

攻击流程

MEV机器人的代码不是开源的,因此我们很难看到这个漏洞到底是如何被利用的。但是CertiK的安全专家还是确定了以下一些细节:

① 漏洞利用者的EOA(外部拥有的地址)在漏洞合约上调用了contract.exexute

② 漏洞合约调用dydx.SoloMargin.operate,params actionType = 8,对应ICallee(args.callee).callFunction()

③ dydx.SoloMargin.operate触发 delegateCall dydx.OperationImpl.operate

④ delegateCall是MEVBot.callFunction(byte4),byte4是WETH9.approval(exploit contract,wad)。攻击合约获得批准,1101枚ETH被发送到了漏洞利用者的钱包。

链上活动

首先,有180万美元被换成了大约500美元的稳定币。

其次在这笔交易中,我们可以看到0x430a向Uniswap发送了180万美元的cUSDC,并收到528美元的稳定币作为回报。

MEV机器人(0xBAD…)在下图的交易中赚取了1101枚ETH。

就在几个小时后,我们看到一笔价值1,463,112.71美元的WETH交易通过一个未知的函数被发送到0xB9F7,这就是被攻击利用的那笔交易。

随后,尽管MEV机器人所有者向该事件的“始作俑者”发出信息,要求归还他们资金,但这次似乎不像其他的攻击,社群未对被攻击者有怜悯之心。

MEV在那些不怎么使用它的人群中是非常不受欢迎的,因为以太坊的高额费用和拥堵问题,加上DeFi生态系统十分活跃,让MEV机器人有了很多坐收渔利的可乘之机。许多用户在交易过程中都不可避免地要经历被MEV机器人套取价值,因此很多用户都在交易中为攻击发起者拍手称快以表达自己的不满。

当然也有一些人则趁机要求分一杯羹。

Related Reads

Podcast Notes: Hyperliquid Has Become the Top Interest Point for Traditional Hedge Funds

Empire Podcast hosts Jason Yanowitz and Santiago Santos discuss the surging institutional interest in Hyperliquid, a decentralized perpetual exchange, marking the highest level of engagement from traditional hedge fund managers since Paul Tudor Jones endorsed Bitcoin in 2020. The primary driver is the demand for weekend trading of commodities like oil, especially during geopolitical tensions such as the Iran conflict, as Hyperliquid provides the only active price discovery venue when traditional markets are closed. Trade XYZ, a front-end on Hyperliquid, has seen significant growth, with weekend oil price predictions having a median error of only 50 basis points. Santos predicts commodity trading volume on Hyperliquid will surpass Bitcoin within the year and that its market cap could rise from $25 billion to $100 billion. Other key points include Kraken raising $200 million at a reduced valuation of $13.3 billion, and the SEC clarifying that self-custodied DeFi frontends like MetaMask are not subject to broker-dealer rules, resolving a major regulatory uncertainty. The hosts also note the strong correlation between crypto and macro markets, with the S&P 500 posting one of its best 10-day rallies since 1950. They highlight MicroStrategy's continued Bitcoin acquisitions and the potential of real-world asset (RWA) tokenization as a key trend. The discussion concludes with skepticism towards many L2 projects, predicting a wave of protocols truly going to zero as capital concentrates in proven assets like Bitcoin and Hyperliquid.

marsbit5h ago

Podcast Notes: Hyperliquid Has Become the Top Interest Point for Traditional Hedge Funds

marsbit5h ago

a16z: The Next Frontier of AI, The Triple Flywheel of Robotics, Autonomous Science, and Brain-Computer Interfaces

a16z presents a comprehensive investment thesis for the next frontier of AI: Physical AI, centered on a synergistic flywheel of robotics, autonomous science, and novel human-computer interfaces (HCIs) like brain-computers. While the current AI paradigm scales on language and code, the most disruptive future capabilities will emerge from three adjacent fields leveraging five core technical primitives: 1) learned representations of physical dynamics (via models like VLA, WAM, and native embodied models), 2) embodied action architectures (e.g., dual-system designs, diffusion-based motion generation, and RL fine-tuning like RECAP), 3) simulation and synthetic data as scaling infrastructure, 4) expanded sensory channels (touch, neural signals, silent speech, olfaction), and 5) closed-loop agent systems for long-horizon tasks. These primitives converge to power three key domains: * **Robotics:** The literal embodiment of AI, requiring all primitives for real-world physical interaction and manipulation. * **Autonomous Science:** Self-driving labs that conduct hypothesis-experiment-analysis loops, generating structured, causally-grounded data to improve physical AI models. * **Novel HCIs:** Devices (AR glasses, EMG wearables, BCIs) that expand human-AI bandwidth and act as massive data-collection networks for real-world human experience. These domains form a mutually reinforcing flywheel: Robotics enable autonomous labs, which in turn generate valuable data for robotics and materials science. New interfaces provide rich human-physical interaction data to train better robots and scientists. Together, they represent a new scaling axis for AI, moving beyond the digital realm to interact with and learn from physical reality, promising significant emergent capabilities and value.

marsbit5h ago

a16z: The Next Frontier of AI, The Triple Flywheel of Robotics, Autonomous Science, and Brain-Computer Interfaces

marsbit5h ago

Trading

Spot
Futures

Hot Articles

What is USDC(WORMHOLE)

USD Coin (Wormhole): A Comprehensive Overview Introduction In the rapidly evolving world of cryptocurrencies, USD Coin (Wormhole), referred to as $USDC(Wormhole), stands out as a pioneering solution within the DeFi (Decentralized Finance) landscape. Operating on several blockchain platforms, including Solana, USD Coin (Wormhole) is more than just a digital representation of the United States dollar. It embodies the innovative spirit of modern finance, enabling seamless cross-chain transactions and enhanced interoperability among diverse blockchain ecosystems through the advanced Wormhole protocol. What is USD Coin (Wormhole)? USD Coin (Wormhole) is a tokenized version of the US dollar designed to facilitate frictionless transactions across different blockchain networks. Its primary aim is to bolster liquidity and enhance the functionality of the DeFi ecosystem. By leveraging the Wormhole protocol, which establishes a robust cross-chain communication network, users can effortlessly transfer USDC tokens across various platforms. This cross-chain capability marks a significant advancement in cryptocurrency use, promoting a more interconnected and efficient ecosystem where assets can flow freely between different blockchains. The value proposition of USD Coin (Wormhole) lies not only in its stability, being pegged to the US dollar, but also in its ability to bridge gaps between disparate blockchain environments. This innovative approach fosters a greater level of participation among users and developers, paving the way for new and exciting applications within decentralized finance. Who is the creator of USD Coin (Wormhole)? The origins of USD Coin (Wormhole) are intricately tied to the Wormhole network, which was developed by Jump Crypto. While specific individual creators are not prominently documented, Jump Crypto is notable for its involvement in advancing blockchain technology and supporting its applications in finance. By creating the Wormhole network, Jump Crypto has played a vital role in promoting cross-chain asset transfers, enhancing the efficiency and diversity of cryptocurrency usage. Who are the investors of USD Coin (Wormhole)? The success of USD Coin (Wormhole) is supported by investments from several notable funds and organizations within the cryptocurrency realm. Key investors include: Coinbase Ventures: A prominent venture capital arm backed by one of the leading cryptocurrency exchanges in the industry, Coinbase Ventures provides essential capital and strategic support to promising blockchain projects. Arrington XRP Capital: Specializing in digital assets, Arrington XRP Capital recognizes the potential of innovative projects like USD Coin (Wormhole) and has invested accordingly to back its development. Jump Trading: As the parent organization of Jump Crypto, Jump Trading brings not only investment but a wealth of expertise in trading technology and market dynamics to bolster the Wormhole project. How Does USD Coin (Wormhole) Work? The operational framework of USD Coin (Wormhole) is intricately designed to facilitate effective cross-chain transactions, maximizing security and efficiency. Here’s a simplified overview of how it functions: Asset Locking: When a user wishes to transfer USDC from one blockchain to another, they first lock their tokens on the source blockchain. This process ensures that the assets are secure and are set to be either burned or moved later. Token Minting: After the tokens are locked, an equivalent amount of USDC is minted on the destination blockchain. This provides the user with access to their funds on a new platform, reflecting the flexibility that the Wormhole protocol enables. Cross-Chain Transfer: The Wormhole protocol efficiently facilitates the entire transfer process. It ensures that once the USDC is minted on the destination chain, the equivalent tokens are burned on the source chain. The result is a seamless transfer of value between two distinct blockchain environments. This cross-chain methodology ensures that transactions remain secure and transparent, significantly enhancing liquidity within the different DeFi ecosystems. Timeline of USD Coin (Wormhole) Understanding the evolution of USD Coin (Wormhole) provides vital context for its significance in the cryptocurrency arena. Here’s a timeline highlighting important milestones in the project’s history: 2021: The Wormhole project is launched, establishing a framework for cross-chain asset transfers and setting the stage for the development of USD Coin (Wormhole). 2022: The Wormhole network experiences a significant challenge with a security breach that results in a $325 million theft. However, the incident is later addressed and refunded by Jump Crypto, showcasing the project’s commitment to security and transparency. 2023: USD Coin (Wormhole) integrates with Circle’s Cross-Chain Transfer Protocol (CCTP), enhancing its capabilities for cross-chain transfers and further solidifying its place within the DeFi ecosystem. 2024: Ongoing development and expansion of the Wormhole network continue, aimed at increasing the utility and reach of USD Coin (Wormhole) as well as enhancing its operational framework. Key Features The success of USD Coin (Wormhole) can be attributed to several key features that differentiate it from other cryptocurrency offerings: Cross-Chain Interoperability At the core of USD Coin (Wormhole) is its ability to facilitate seamless transfers across multiple blockchain networks. This interoperability serves as a cornerstone for decentralized finance, allowing various platforms to interact with each other, thereby accelerating the evolution of financial services. Security Wormhole employs a well-designed Guardian Network comprised of node validators that ensure secure cross-chain transactions. This collective oversight minimizes the risk of fraud and provides users with confidence that their assets are protected during cross-chain transfers. Liquidity Enhancement By enabling USDC to circulate freely across different blockchains, USD Coin (Wormhole) enhances liquidity in the DeFi ecosystem. This increased liquidity can foster more efficient trading, contribute to better pricing strategies, and improve the overall market dynamics encompassing various digital assets. Conclusion USD Coin (Wormhole) is a pivotal innovation in the blockchain space, reinforcing the capabilities of decentralized finance (DeFi) and establishing a more connected financial ecosystem. With its robust framework for cross-chain transactions, security features, and strong backing from reputable investors, USD Coin (Wormhole) is positioned to play a key role in the future of cryptocurrency. As the digital finance landscape continues to evolve, USD Coin (Wormhole) not only embraces the future of interconnectivity among blockchain networks but also reaffirms the power of tokenization and blockchain technology in transforming how we perceive and utilize value in a digital world. By navigating the complexities of cross-chain functionality, it demonstrates a sophisticated approach to enabling financial inclusivity and innovation in the world of cryptocurrencies.

1.2k Total ViewsPublished 2024.04.01Updated 2024.12.03

What is USDC(WORMHOLE)

What is $USDC

Classic USDC: A Comprehensive Overview Introduction to Classic USDC In the rapidly evolving landscape of the cryptocurrency market, stablecoins have emerged as critical components, particularly in providing stability amid the volatility that characterizes digital assets. One such project is Classic USDC, a digital currency initiative that aims to deliver a stable and reliable medium of exchange. By maintaining a 1:1 peg with the US dollar, Classic USDC strives to offer users a dependable digital asset, equipped for various applications within the web3 and cryptocurrency ecosystems. What is Classic USDC? Classic USDC is fundamentally a stablecoin, which is a type of cryptocurrency designed to minimize the price volatility typically seen in the digital asset market. Specifically, Classic USDC aspires to represent the value of the US dollar closely, ensuring that users can leverage this digital currency for transactions, savings, and other financial activities without the fear of sudden price fluctuations that can otherwise plague many cryptocurrencies. The primary aim of Classic USDC is to provide a reliable and trustworthy digital equivalent of the US dollar, designed for seamless integration into a wide range of web3 applications, decentralized finance (DeFi) platforms, and other crypto-related financial systems. By delivering a stable digital currency, Classic USDC seeks to facilitate everyday commerce, make blockchain technology more user-friendly, and encourage the adoption of cryptocurrencies for mainstream usage. Creator of Classic USDC The identity of the creator or the development team behind Classic USDC remains largely unknown, and the lack of transparency has led to a degree of uncertainty regarding the project’s origins. While many cryptocurrency initiatives prominently showcase their founders and development teams, Classic USDC does not provide clear information about its creators, which poses challenges for potential users or investors weighing the project's credibility and reliability. Investors of Classic USDC Alongside the ambiguity surrounding its creators, Classic USDC also lacks specificity with regards to its investors. The financial backing of a project can often lend it credibility and stabilize its operations; however, the absence of documented investment foundations or organizations supporting Classic USDC raises questions about its funding structure. This lack of clarity could potentially hinder stakeholder confidence in the project. How Does Classic USDC Work? The operational mechanics of Classic USDC rely heavily on its reserve system, which is fundamental to the underpinnings of any stablecoin. Classic USDC undertakes to maintain a reserve of assets that directly correspond to the value of the digital currency in circulation. Specifically, for every Classic USDC token issued, an equivalent amount of backing assets is retained in reserve, whether in cash or near-cash equivalents. This strategy is designed to uphold the value of Classic USDC, offering reassurance to users that redeeming their tokens for US dollars is feasible at any time. This reserve structure aims to enhance the stability and reliability of Classic USDC, positioning it as a secure alternative in the cryptocurrency market. By ensuring that the value of Classic USDC is consistently correlated with the US dollar, the project aspires to engender trust among users who may be wary of the broader market dynamics. Timeline of Classic USDC The history of Classic USDC is marked by several key milestones that reflect its journey and evolution within the cryptocurrency ecosystem: 2021: The inception of Classic USDC is noted, introducing a new digital currency option designed for stability. During this year, the first records of the token’s activity surfaced and its initial price levels were established. 2024: Classic USDC begins to experience notable price fluctuations, as the crypto market overall grapples with various trends and user sentiment. Predictions regarding its future potential emerge, indicating a strong interest from market observers and analysts who foresee growth opportunities. Future Projections Experts speculate that Classic USDC may reach higher levels of adoption and stability in the years to come, with potential further developments anticipated around 2025 and 2026. However, these projections should be approached with cautious optimism, as the cryptocurrency market is inherently unpredictable, and various external factors may influence the trajectory of Classic USDC. Key Points About Classic USDC Stability: Classic USDC’s core proposition revolves around providing a digital currency that parallels the value of the US dollar, thereby ensuring stability in an often volatile marketplace. Reserve System: The project’s commitment to maintaining a reserve of assets to back its value underscores its reliability and operational soundness. Web3 and Crypto Integration: Classic USDC is engineered to facilitate easy integration within various applications, aiming to enhance the user experience and broaden the acceptance of cryptocurrency in everyday transactions. Future Growth Potential: While still emerging, Classic USDC holds prospective avenues for growth as awareness and utilization of stablecoins increases in the web3 and crypto contexts. Conclusion Classic USDC presents itself as a notable stablecoin initiative within the cryptocurrency sphere, striving to provide users with a reliable digital currency that embodies the stability of the US dollar. Despite uncertainties regarding its creators and financial backing, the underpinning principles of Classic USDC—centered on reserve-backed assurances—endeavour to position it as a trustworthy option for individuals and businesses navigating the digital economy. With an eye towards the future, market analysts are keen to observe how Classic USDC evolves in response to the shifting dynamics of the cryptocurrency landscape, potentially establishing itself as a significant player in the realm of stablecoins.

623 Total ViewsPublished 2024.05.01Updated 2024.12.03

What is $USDC

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of USDC (USDC) are presented below.

活动图片