Взлом UXLink выявил риски централизованного управления в DeFi‑проектах

cryptonews.ruPublicado em 2025-09-12Última atualização em 2025-09-24

Децентрализованная социальная платформа UXLink сообщила о взломе мультиподписного кошелька, который привел к выпуску неавторизованных токенов и падению стоимости актива на 90%. Эксперты оценивают ущерб от $11 млн до $30 млн.

UXLink заявила, что ее новый смарт-контракт прошел аудит безопасности и будет развернут в основной сети Ethereum. Проект сообщил, что в новом контракте отсутствует функция выпуска и сжигания токенов для предотвращения подобных инцидентов в будущем.

Во вторник проект подтвердил факт взлома, сообщив, что на биржи было переведено значительное количество криптовалюты. Оценки потерь от взлома разнятся: по данным Cyvers Alerts, было похищено не менее $11 млн, а Hacken оценивает эту сумму более чем в $30 млн.

Очевидно, что инцидент выявил уязвимости безопасности смарт-контрактов, которые необходимо устранить проектам. Марван Хашем, соучредитель и генеральный директор компании FearsOff, занимающейся безопасностью Web3, сообщил, что инцидент выявил риски, связанные со спешным развитием без необходимых уровней безопасности.


Источник: UXLink

Эксплоит UXLink выявляет риски «централизованного контроля»

Злоумышленники получили контроль над смарт-контрактом UXLink через взлом мультиподписного кошелька и изначально выпустили 2 млрд токенов UXLINK. Цена токена упала на 90% с $0,33 до $0,033, пока злоумышленник продолжал выпуск. По оценкам компании Hacken, было создано почти 10 трлн токенов.

Хашем сообщил, что взлом UXLink произошел из-за уязвимости вызова делегата в их мультиподписном кошельке. Это позволило хакеру запустить произвольный код и получить административный контроль над контрактом. Он добавил, что это привело к выпуску неавторизованных токенов.

«Это действительно выявляет некоторые недостатки в архитектуре UXLink, — сказал Хашем. — Мультиподписной кошелек не был должным образом защищен от атак с вызовами делегатов, слабый контроль над тем, кто может выпускать монеты, и отсутствие встроенного кода для обеспечения ограничения эмиссии».

Хашем заявил, что это показывает, насколько рискованно «сохранять слишком централизованный контроль в проектах, которые претендуют на децентрализованность».

Необходимость временных блокировок, жестко заданных ограничений и более эффективного аудита

С технической точки зрения, Хашем заявил, что взлома UXLink можно было бы избежать с помощью нескольких стандартных мер безопасности.

Сюда входило добавление временных блокировок к таким конфиденциальным действиям, как выпуск новых токенов или смена владельца контракта. «Задержка в 24–48 часов дает сообществу возможность заметить что-то необычное до того, как это произойдет», — сказал Хашем.

Второе решение включало отказ от привилегий выпуска токенов после запуска, чтобы даже инсайдеры не могли создавать их снова. Хашем заявил, что жесткое программирование ограничений эмиссии непосредственно в смарт-контрактах предотвратит риски, связанные с выпуском новых токенов.

Что касается операционной деятельности, Хашем подчеркнул важность независимых проверок и постоянной прозрачности.

«Нельзя просто проводить аудит контракта токена. Настройка мультиподписи также требует тщательного анализа», — сказал он, призвав проекты публиковать адреса кошельков и требовать участия нескольких подписантов для каждой транзакции.

Более общий урок, по словам Хашема, заключается в том, что даже широко используемые инструменты, такие как мультиподписные кошельки, не следует считать абсолютно надежными. Он также отметил первостепенное значение стремления к более децентрализованному управлению и экстренной остановке критически важных функций.

«Инцидент с UXLink подчеркивает, что поспешное развитие без надежной и постоянной безопасности может подорвать доверие сообщества. Лучше усилить защиту с самого начала», — сказал Хашем.

Leituras Relacionadas

Programmers Worldwide Are Wasting Money on Anthropic! The Company Can't Stand It Anymore

Anthropic recently published guidelines to help developers using Claude Code reduce unnecessary token costs. The key recommendations include: 1) Clear (/clear) conversations after completing a task to avoid carrying irrelevant file reads and command outputs into the next task. 2) Set the model and reasoning effort level at the start of a session, as switching mid-session invalidates the prompt cache, requiring a full-price recalculation of the entire dialog history. 3) Attach files using @ references instead of typing paths manually to avoid extra tool calls and searches that bloat the context. 4) Add quiet flags to verbose commands (e.g., in CLAUDE.md) to minimize lengthy output in the dialog history. 5) Use /compact while the session cache is still warm (before breaks) to compress the dialog at one-tenth the cost. 6) Offload large-output tasks to a sub-agent, which runs in an isolated context and only returns conclusions, preventing intermediate outputs from polluting the main dialog. The article explains token pricing: input tokens (prefill) are processed in parallel, while output tokens (decode) are generated serially, making output tokens five times more expensive. Caching is crucial for savings—if a request's prefix (system prompt, CLAUDE.md, dialog history) matches the previous one byte-for-byte, reading it costs only 10% of the standard input price. However, cache invalidation occurs when changing models, effort levels, fast mode, compressing dialogs, after cache expiration, or when resuming old sessions. Dialog history also grows quadratically (O(n²)) as file contents and command outputs accumulate, increasing costs per round. Proactive context management—like isolating noisy tasks, using /rewind to trim unproductive turns, and task-based session clearing—is becoming an essential skill for cost-effective AI-assisted development.

marsbitHá 28m

Programmers Worldwide Are Wasting Money on Anthropic! The Company Can't Stand It Anymore

marsbitHá 28m

Pax Silica vs. WAICO: The US Wants to Prohibit Europe from Using Chinese Artificial Intelligence

The United States is preparing to demand that European and other partners abandon Chinese artificial intelligence initiatives, threatening exclusion from the American-led "Pax Silica" coalition, according to a leaked U.S. State Department document. This ultimatum forces signatories of the "AI Opportunity Statement" to choose between the Western technological ecosystem and alternative frameworks, with China not explicitly named but clearly targeted. Pax Silica is a U.S. strategy for AI and semiconductor hegemony, launched in late 2025. Its European presence expanded significantly in mid-2026. Concurrently, China, Russia, and 27 other nations established the World AI Cooperation Organization (WAICO) in July 2026 as an independent intergovernmental platform promoting AI governance based on UN principles. This situation creates a difficult choice, especially for European nations balancing strategic autonomy with dependence on U.S. tech and security. It also pressures Global South countries with pragmatic ties to both Washington and Beijing. The formation of competing blocks risks fragmenting the global tech landscape, forcing companies to split supply chains, increasing costs, and potentially leading to incompatible standards and protocols. The era of open globalization in AI may be ending, replaced by geopolitical confrontation where technological sovereignty trumps economic efficiency. The decisions made will shape the global digital economy for decades.

cryptonews.ruHá 2h

Pax Silica vs. WAICO: The US Wants to Prohibit Europe from Using Chinese Artificial Intelligence

cryptonews.ruHá 2h

Robert Kiyosaki Shares His Mentor's Predictions About the Emergence of Bitcoin and AI

American entrepreneur and author of "Rich Dad Poor Dad," Robert Kiyosaki, discussed the influence of futurist R. Buckminster Fuller on his worldview, linking Fuller's past technological predictions to the emergence of Bitcoin and the development of artificial intelligence. In an X post, Kiyosaki also reflected on personal purpose, sharing his journey from the music business—where he worked with bands like The Police and Iron Maiden—to creating the "Cashflow" board game and writing his famous book. He described feeling an inner emptiness despite his success, a turning point that came after meeting Fuller, whom he studied with for three summers. Kiyosaki described Fuller as a "friendly genius" who foresaw world-changing developments like Bitcoin and AI. However, the core of his post focused on Fuller's philosophical impact, particularly a quote about belonging to the universe and finding purpose by dedicating one's life to the maximum benefit of others. The entrepreneur remains a vocal advocate for cryptocurrencies. He regularly advises buying Bitcoin during market panics, viewing it and assets like Ethereum, gold, and silver as hedges against traditional financial system failures. Kiyosaki has predicted a major market crash by 2026, seeing it as an opportunity for prepared investors, with long-term price targets including $750,000 for Bitcoin and $95,000 for Ethereum.

cryptonews.ruHá 4h

Robert Kiyosaki Shares His Mentor's Predictions About the Emergence of Bitcoin and AI

cryptonews.ruHá 4h

Etherealize CEO Calls Wall Street's Private Blockchains a 'Race to the Bottom'

Etherealize co-founder and CEO Vivek Raman criticized Wall Street's growing interest in private, permissioned blockchains, calling them a "race to the bottom." In an interview with CoinDesk, Raman argued that consortium networks fragment liquidity and return the industry to the siloed systems that blockchain technology was meant to overcome. He stated that closed networks do not interoperate, undermining two key advantages of the technology: system compatibility and liquidity concentration. Etherealize promotes Ethereum as an open, foundational layer for institutional players. Raman insists that privacy and access restrictions should be built on top of public infrastructure—at the application or L2 level—rather than creating separate, closed networks. He compared Ethereum to HTTP as a base layer, with additional permissioned and private layers akin to HTTPS. Examples of this new wave of "closed" solutions mentioned include Canton Network from Digital Asset, Circle's Arc project, and Stripe's Tempo. Raman termed this trend "consortium chains 2.0," recalling earlier initiatives like the R3 interbank consortium and the Hyperledger corporate ecosystem from 2016 that failed to gain significant traction. He reiterated his firm belief that a global, open, permissionless infrastructure is necessary as a foundational base layer. Raman previously noted in June that traditional financial institutions had begun implementing Ethereum-based solutions into real business processes.

cryptonews.ruHá 4h

Etherealize CEO Calls Wall Street's Private Blockchains a 'Race to the Bottom'

cryptonews.ruHá 4h

Trading

Spot
活动图片