8月安全月报|钓鱼诈骗狂卷2.9亿美元,揭秘链上安全攻与防

深潮Publicado em 2024-09-03Última atualização em 2024-09-03

8 月全网链上安全事件累计造成损失约3.16亿美元,环比上升9.3%。

8 月全网链上安全事件累计造成损失约 3.16 亿美元,环比上升 9.3%。

仅钓鱼诈骗事件所造成损失占总损失的 93.37%,损失超 2.96 亿美元。钓鱼推文暗藏陷阱,未经验证的链接不要点击。用户需学会利用 Web3 链上工具规避风险,建立一套自己的安全操作流程并严格遵守,确保资金安全。

REKT 事件损失占比 5.97%, 共计损失约 1,893 万美元。RugPull 事件损失占比 0.19% ,共计损失约 59 万美元

最大安全事件-钓鱼诈骗

8 月 19 日,发生一笔涉及 4,064 枚 BTC 的可疑转账,约合 2.38 亿美元,随后该笔资金很快被转移到 ThorChain、eXch 等多个账户内。

截至 8 月 27 日,已有 20.5 万美元被收回。

最大安全事件-私钥泄漏

8 月 7 日,Nexera 由于合约管理凭证被恶意软件获取,导致被盗取 4,720 万个 NXRA 代币,损失约 150 万美元

最大安全事件-REKT

8 月 6 日,游戏区块链 Ronin 由于桥实现合约升级后未正确初始化遭到攻击,攻击者从桥中提取了约 4,000 个 ETH 和 200 万 USDC,价值约 1,200 万美元

截至 8 月 7 日,白帽归还了 1,200 万美元的资产,并获得了项目方额外 50 万美元的漏洞赏金。

最大安全事件-RugPull

8 月 16 日,Solana 上的 SIGMA 发生 RugPull,部署者通过出售其代币获得了 2,381.6 SOL,损失约 33 万美元

案例分析

8 月 6 日,游戏区块链 Ronin 疑似遭攻击,攻击者从桥中提取了约 4,000 个 ETH 和 200 万 USDC,价值约 1,200 万美元

流程分析:

1) Ronin 团队错误升级 Axie Infinity: Ronin Bridge V2 合约,对其合约的实现由 MainchainGatewayV3(旧)升级为 MainchainGatewayV3(新),并调用 MainchainGatewayV3(新)的 initializeV4 方法初始化;

2)攻击者发现 MainchainGatewayV3(新)的 _totalOperatorWeight 未初始化,当前为 0,则可以绕过提取资金时的签名验证。攻击者传入任意的签名数据直接提取了 3,996.09375 ETH;

3)在第二笔攻击交易中,攻击者传入任意签名,直接提取了 1,998,046 USDC;

4)攻击者通过 Uniswap 将 1,998,046 USDC兑换成 796 WETH。

 OKLink小贴士 

8 月因钓鱼诈骗事件导致巨额损失。OKLink 提醒大家,不要向任何人透露你的私钥或助记词。连接钱包前需三思而后行,授权前,使用 OKLink 代币授权管理工具防患于未然,合约风险尽在掌控,多重保障。

 👉 https://www.oklink.com/zh-hans/approval

每个人都应该建立一套自己的安全操作流程,并严格遵守,保障资金安全。

Leituras Relacionadas

Warsh's First Day in Office, Markets Deliver a 'Wake-up Call': Rate Hike Expected This Year

On his first day in office, newly inaugurated Federal Reserve Chairman Warsh received a stark market warning, with expectations now fully pricing in a 25-basis-point interest rate hike this year. The shift was triggered by hawkish remarks from Fed Governor Waller, who stated that inflation is now the key policy "driver" and that the odds of a hike or cut are evenly split. This sent short-term Treasury yields higher. Waller signaled a significant pivot in his stance, citing disappointing inflation and labor data. He suggested removing "easing bias" language from Fed statements and did not rule out future rate increases if inflation fails to recede, though he noted immediate action isn't warranted without signs of unanchored inflation expectations. Chairman Warsh faces immediate pressure at his first FOMC meeting in June. With the preferred inflation gauge at a three-year high, analysts warn that failing to hike could be interpreted as an implicit easing of policy. The geopolitical situation in the Middle East is adding to existing price pressures. The market's expectation for a hike contrasts sharply with earlier forecasts for multiple cuts. While long-term Treasury yields have been contained by lower energy prices recently, analysts note they remain under structural upward pressure. Warsh's swearing-in at the White House highlights political scrutiny over Fed independence. However, the market has made it clear that inflation is the most urgent challenge, leaving the new chairman little time to settle in.

marsbitHá 1h

Warsh's First Day in Office, Markets Deliver a 'Wake-up Call': Rate Hike Expected This Year

marsbitHá 1h

Has Microsoft Lost Its Way in the AI Race, and Can Copilot Bring It Back on Track?

Microsoft, once seen as an early AI frontrunner due to its investment in OpenAI, is navigating a strategic shift amid increased competition. Its initial reliance on OpenAI’s GPT models has been complicated by OpenAI’s growing ambitions as a direct competitor, rapid advancements from rivals like Claude and Gemini, and the disruptive rise of AI agents, which challenge its traditional SaaS business model. These factors contributed to stock declines and slower-than-expected adoption of its flagship Copilot products. In response, CEO Satya Nadella has taken a hands-on role in product development, signaling the urgency of change. Microsoft is pivoting from a model-centric strategy to a "model-agnostic" enterprise platform approach. It aims to become the foundational layer connecting various AI models—from OpenAI, Anthropic, or its own new "Superintelligence" team—with enterprise workflows, data, security, and cloud services. Recent organizational changes merged consumer and enterprise Copilot teams to accelerate innovation, exemplified by new products like Copilot Tasks and Copilot Cowork. However, this transformation comes at a high cost. Microsoft faces massive capital expenditures, potentially reaching ~$190 billion by 2026, to support AI infrastructure. While its platform strategy shows early signs of traction with growing Azure AI revenue, it must balance startup-like agility with the reliability expected by enterprise clients. The core challenge is no longer being the sole AI winner but defending its position as the essential enterprise software entry point amidst rapid technological commoditization and the shift towards always-on AI agents.

marsbitHá 2h

Has Microsoft Lost Its Way in the AI Race, and Can Copilot Bring It Back on Track?

marsbitHá 2h

Why Haven't Forex Stablecoins Taken Off?

Why FX Stablecoins Never Took Off: A Path Forward via Synthetic FX Despite the explosive growth of stablecoin-powered digital banking, which has seen ~$6B in VC investment and a 24x surge in crypto card spending in under a year, a major limitation persists: these banks are essentially dollar-only accounts. This leaves 95-99% of global accounts, which are denominated in non-USD currencies, underserved. Attempts to create native foreign currency (FX) stablecoins (like EURC) have largely failed, with total FX stablecoin TVL at ~$600M compared to $400B for USD stablecoins—a 700x gap. These FX tokens face critical challenges: fragile pegs due to low liquidity, limited exchange/FinTech acceptance, poor on/off-ramps, complex regional compliance, and a chicken-and-egg adoption problem. The article argues that the solution lies not in competing with entrenched USD stablecoin networks (USDT/USDC), but in adopting a synthetic FX model inspired by traditional finance. Specifically, it advocates for Mark-to-Market Non-Deliverable Forwards (NDFs)—cash-settled FX derivatives that allow users to maintain underlying USD stablecoin holdings while having their account balance and P&L denominated in a foreign currency. This approach offers key advantages: strong oracle-based pegs, retention of deep USD stablecoin liquidity and yield, superior on/off-ramps, scalability to any currency with a reliable feed, and capital efficiency. It mirrors how modern institutional FX markets operate. Primary use cases for on-chain NDFs include: 1. **Digital Banks/Wallets:** Enabling multi-currency accounts for international users without leaving the USD stablecoin ecosystem, boosting deposits and retention. 2. **FX Carry Trade Vaults:** Offering access to sovereign interest rate differentials (e.g., earning yield on BRL) in a more stable and scalable format than crypto-native products like Ethena. 3. **Global Enterprise Payments:** Allowing merchants to receive payments in local currency equivalents while settling in USD stablecoins, similar to services offered by Stripe for fiat. The conclusion is that synthetic FX, not native FX stablecoins, is the viable path to integrating foreign exchange into the growing stablecoin digital banking landscape, potentially unlocking the next phase of institutional DeFi and multi-trillion-dollar global adoption.

链捕手Há 2h

Why Haven't Forex Stablecoins Taken Off?

链捕手Há 2h

Trading

Spot
Futuros
活动图片