2022上半年Web3黑客常用的攻击方式有哪些?

成都链安Publicado em 2022-08-25Última atualização em 2022-08-25

Resumo

今天,我们就2022上半年Web3黑客常用的攻击方式展开分析,看看在所有被利用的漏洞中,哪些频率最高,以及如何防范。

今天,我们就2022上半年Web3黑客常用的攻击方式展开分析,看看在所有被利用的漏洞中,哪些频率最高,以及如何防范。

上半年因漏洞造成的总损失有多少?

据成都链安鹰眼区块链态势感知平台监控显示,2022上半年共监测到因合约漏洞造成的主要攻击案例42次,约53%的攻击方式为合约漏洞利用。

通过统计,2022上半年共监测到因合约漏洞造成的主要攻击案例42次,总损失达到了6亿4404万美元。

在所有被利用的漏洞中,逻辑或函数设计不当被黑客利用次数最多,其次为验证问题、重入漏洞。

哪些类型的漏洞曾导致重大损失?

2022年2月3日,Solana跨链桥项目Wormhole遭到攻击,累计损失约3.26亿美元。黑客利用了Wormhole合约中的签名验证漏洞,这个漏洞允许黑客伪造sysvar帐户来铸造wETH。

2022年4月30日,Fei Protocol官方的Rari Fuse Pool遭受闪电贷加重入攻击,总共造成了8034万美元的损失。本次攻击对项目方造成了无法挽回的损失,8月20号,官方表示项目正式关闭了。

Fei Protocol事件回顾:

由于漏洞出现在项目基本协议中,攻击者不止攻击了一个合约,以下仅分析一例。

攻击交易

0xab486012f21be741c9e674ffda227e30518e8a1e37a5f1d58d0b0d41f6e76530

攻击者地址

0x6162759edad730152f0df8115c698a42e666157f

攻击合约

0x32075bad9050d4767018084f0cb87b3182d36c45

被攻击合约

0x26267e41CeCa7C8E0f143554Af707336f27Fa051

#攻击流程

1. 攻击者先从Balancer: Vault中进行闪电贷。

2. 将闪电贷的资金用于Rari Capital中进行抵押借贷,由于Rari Capital的cEther实现合约存在重入。

攻击者通过攻击合约中构造的攻击函数回调,提取出受协议影响的池子中所有的代币。

3. 归还闪电贷,将攻击所得发送到0xe39f合约中

本次攻击主要利用了Rari Capital的cEther实现合约中的重入漏洞,被盗资金超过28380 ETH(约8034万美元)。

审计过程中最常出现的漏洞有哪些?

在审计过程中最常见出现的总体来说分为四大类:

1.ERC721/ERC1155重入攻击:

在通过链必验形式化验证平台检测合约时不乏存在ERC721 / ERC1155标准相关的业务合约,在ERC721中,ERC1155中存在分别存在一个onERC721Received()/onERC1155Received()函数用于转账通知,类似于以太坊转账的fallback()函数,在相关的业务合约中使用ERC721/ERC1155标准中的_safeMint(),_safeTransfer(),safeTransferFrom()进行铸币或者转账时都会触发转账通知函数。如果在转账的目标合约中的onERC721Received()/onERC1155Received()中包含了恶意代码,就可能形成重入攻击。除此之外在相关业务函数未严格按照检查-生效-交互模式设计,上述两点共同导致了漏洞的产生。

2.逻辑漏洞:

1) 特殊场景考虑缺失:

特殊场景往往是审计最需要关注的地方,例如转账函数设计未考虑自己给自己转账导致无中生有。

2)设计功能不完善:

存放费用的合约没有提取功能,借贷合约不含清算功能等。

3.鉴权缺失:

铸币、设置合约特殊角色、设置合约参数的相关函数没有鉴权,导致三方地址也可以调用。

4.价格操控:

Oracle价格预言机未使用时间加权平均价格;

未使用价格预言机,直接使用合约中两种代币的余额比例作为价格等。

实际被利用的漏洞有哪些?哪些漏洞能在审计阶段发现?

根据成都链安鹰眼区块链安全态势感知平台所感知的安全事件统计,审计过程中出现的漏洞几乎都实际场景中被黑客利用过,其中合约逻辑漏洞利用仍然为主要部分。

通过成都链安链必验-智能合约形式化验证平台检测和安全专家人工检测审计,以上漏洞均能在审计阶段被发现,并且可由安全专家在做出安全评估后提出相关安全修补建议供客户作为修复参考。

Criptomoedas em alta

Leituras Relacionadas

Trends in US Stocks (June 22): Strait of Hormuz Agreement Changes Course, Thursday's PCE and Micron to Determine Chip Sector Direction

U.S. Stock Market Outlook (June 22): Strait of Hormuz Deal Falters, Thursday's PCE & Micron to Set Chip Sector Direction. Geopolitical tensions resurged over the weekend as Iran's IRGC announced the closure of the Strait of Hormuz, and its negotiation team walked out after threats from Trump, pausing U.S.-Iran talks. This renewed risk premium is weighing on U.S. equity futures ahead of the open. Last week's market was driven by chip stocks, with the Philly Semiconductor Index hitting a record high. While the Fed's hawkish tone was overshadowed by initial deal optimism, the S&P 500 gained 0.9% for the week. SpaceX debuted strongly but ended with two down days. Key events this week: The status of U.S.-Iran negotiations remains the immediate variable for oil and energy stocks. Monday sees Marvell and Flex added to the S&P 500. Tuesday's MSCI reclassification could benefit South Korean semiconductors and memory stocks. **Thursday, June 25th, is the critical day**, featuring the May Core PCE report and Micron's earnings. Hotter PCE data could solidify expectations for two 2024 rate hikes, while softer data would rapidly reprice rate cut bets. Micron's report is a key test for the AI narrative; the market will scrutinize its 2027 HBM supply visibility, HBM4 progress, and its position in Nvidia's Vera Rubin supply chain. Nvidia's AGM and a potential OpenAI GPT-5.6 release will make Thursday a pivotal 24 hours for AI. Friday concludes with the Russell reconstitution, elevating small-cap volatility. In summary, last week's gains face a true test. The path hinges on two concurrent threads: geopolitical developments with Iran and the AI narrative defined by Micron's guidance and Nvidia's updates. The chip sector's record highs are vulnerable if Thursday brings hot PCE data and conservative guidance from Micron. Conversely, positive outcomes could reaffirm the AI bull case, making this week's volatility a potential entry window.

marsbitHá 1h

Trends in US Stocks (June 22): Strait of Hormuz Agreement Changes Course, Thursday's PCE and Micron to Determine Chip Sector Direction

marsbitHá 1h

OpenAI's "Most Open" Move: Codex No Longer Exclusively Favors GPT

OpenAI has significantly opened up its Codex programming agent by introducing a "model provider" configuration layer that allows users to connect it with various open-source models, not just its proprietary GPT. Through a configuration file or a simple `--oss` command-line flag, Codex can now route requests to local services like Ollama or LM Studio, or to third-party APIs such as Mistral or DeepSeek. This move is seen as one of OpenAI's most "open" steps, potentially lowering costs and enhancing privacy for developers who can run code generation offline. However, integration isn't seamless for all models. Codex primarily uses OpenAI's newer Responses API, while many open-source models rely on the older Chat Completions interface. This creates compatibility issues, especially for advanced features like function calling. The developer community is already building "routing" or adapter layers (e.g., CC Switch, LiteLLM) to translate between these protocols, enabling hybrid setups where GPT handles planning and open-source models handle execution. Analysts interpret this as a strategic shift for OpenAI: from competing solely on model superiority to controlling the platform and interface standards. By making Codex a flexible, pluggable entry point for AI-assisted programming, OpenAI aims to become the central hub in the developer toolchain ecosystem, even as users gain the freedom to switch underlying models.

marsbitHá 1h

OpenAI's "Most Open" Move: Codex No Longer Exclusively Favors GPT

marsbitHá 1h

When 500 Million People Abandon ChatGPT

ChatGPT's Global AI Assistant Market Share Drops Below 50% Three and a half years after its groundbreaking launch, ChatGPT faces a pivotal moment. While it remains the largest AI assistant globally, its market share has fallen below 50% for the first time, reaching 46.4% as of May, according to Sensor Tower's 2026 AI landscape report. Google's Gemini (27.7%) and Anthropic's Claude (10.3%) are now its main competitors, with Grok, Perplexity, and others also gaining ground. The market has evolved from awe and initial adoption into a phase of product comparison, ecosystem integration, and commercialization. User behavior has matured significantly. Loyalty is low; users readily switch between assistants for specific tasks. Gemini benefits from deep integration within Google's ecosystem (Search, Gmail, Android), while Claude has carved a niche among productivity-focused users with strong retention, nearly matching ChatGPT's. User choice is now influenced by a complex mix of capability, ecosystem, price, use case, and even brand trust. Commercialization is accelerating. AI app downloads continue but growth is slowing, while user spending is rising. Over $4.2 billion was spent in-app during H1 2026. Claude leads in premium subscription conversion rates (13%). OpenAI is expanding its revenue streams, testing ads shown to 17% of ChatGPT users daily by May. This shift highlights the immense financial pressure of model training and inference costs. Despite revenue growth, OpenAI's cash burn is intense, reaching $3.7 billion in Q1 2026. The company projects this could rise to $25-57 billion in the coming years, underscoring the industry-wide challenge of scaling profitably. The symbolism is clear: ChatGPT no longer defines the AI assistant market alone. The era of a single dominant product is over. Gemini, Claude, and specialized tools are collectively shaping user habits and business models. As AI assistants move from novelty to utility—judged on accuracy, efficiency, and value—they are becoming embedded in everyday digital life. ChatGPT may have lost its majority, but AI as a whole is winning, entering a mature, competitive, and diverse new phase.

marsbitHá 1h

When 500 Million People Abandon ChatGPT

marsbitHá 1h

Trading

Spot
Futuros

Artigos em Destaque

Como comprar BAL

Bem-vindo à HTX.com!Tornámos a compra de Balancer (BAL) simples e conveniente.Segue o nosso guia passo a passo para iniciar a tua jornada no mundo das criptos.Passo 1: cria a tua conta HTXUtiliza o teu e-mail ou número de telefone para te inscreveres numa conta gratuita na HTX.Desfruta de um processo de inscrição sem complicações e desbloqueia todas as funcionalidades.Obter a minha contaPasso 2: vai para Comprar Cripto e escolhe o teu método de pagamentoCartão de crédito/débito: usa o teu visa ou mastercard para comprar Balancer (BAL) instantaneamente.Saldo: usa os fundos da tua conta HTX para transacionar sem problemas.Terceiros: adicionamos métodos de pagamento populares, como Google Pay e Apple Pay, para aumentar a conveniência.P2P: transaciona diretamente com outros utilizadores na HTX.Mercado de balcão (OTC): oferecemos serviços personalizados e taxas de câmbio competitivas para os traders.Passo 3: armazena teu Balancer (BAL)Depois de comprar o teu Balancer (BAL), armazena-o na tua conta HTX.Alternativamente, podes enviá-lo para outro lugar através de transferência blockchain ou usá-lo para transacionar outras criptomoedas.Passo 4: transaciona Balancer (BAL)Transaciona facilmente Balancer (BAL) no mercado à vista da HTX.Acede simplesmente à tua conta, seleciona o teu par de trading, executa as tuas transações e monitoriza em tempo real.Oferecemos uma experiência de fácil utilização tanto para principiantes como para traders experientes.

95 Visualizações TotaisPublicado em {updateTime}Atualizado em 2026.06.02

Como comprar BAL

Discussões

Bem-vindo à Comunidade HTX. Aqui, pode manter-se informado sobre os mais recentes desenvolvimentos da plataforma e obter acesso a análises profissionais de mercado. As opiniões dos utilizadores sobre o preço de BAL (BAL) são apresentadas abaixo.

活动图片