XMR CCS钱包被盗,大家的关注点竟是……

Odaily星球日报2023-11-06 tarihinde yayınlandı2023-11-06 tarihinde güncellendi

Özet

为什么链上监控公司能追踪门罗币交易路径?

原创 | Odaily星球日报

作者 | 夫如何

XMR CCS钱包被盗,大家的关注点竟是……

门罗币(Monero)作为隐私币赛道的龙头,凭借其强匿名和不可追溯的特性,在隐私币领域有着较高的市场认可度。但该项目在今年 9 月份经历了社区众筹钱包(CCS)被盗事件,CCS 钱包中 2675.73 XMR(约 46 万美元)被清空,且至今都不清楚什么原因被盗。

但项目社区成员在这段时间也开展了社区自查工作,将 CCS 钱包从创建到至今的关键事件进行梳理。

  • CCS 钱包创建于 2020 年 4 月 12 日,由创始人 fluffypony(Riccardo Spagni)创建,并与另一位核心成员 Luigi 共享密钥。Luigi 平时通过 Wire 应用程序和 GPG 加密的电子邮件访问 CCS 钱包,完成一些捐款活动。

  • 但在 2021 年 8 月 3 日,fluffypony 深陷南非政府的指控,被迫在美国自首,门罗币团队为了应对此件事情,大部分 CCS 钱包的余额被 Luigi 转移到热钱包中。

  • 2023 年 5 月 10 日,CCS 的最后一次转账是由 Luigi 转移到热钱包。

  • 2023 年 9 月 1 日 23: 58 至 9 月 2 日 00: 07 ,CCS 钱包在 9 笔交易中被清空;

  • 2023 年 9 月,该 CCS 钱包收到向 Lovera 的捐款(也是唯一一个需要用到资金的提案);

  • 2023 年 9 月 28 日,Luigi 登录 CCS 钱包为热钱包充值,发现余额约为 4.6 XMR,代表 9 月份对 Lovera 的捐款;9 月 2 日之后没有发生额外转账;

  • 9 月 28 日至今,核心团队内部进行讨论;Luigi 和 fluffypony 也进行相关取证工作,但尚未找到违规证据。

根据上述时间线来看,CCS 密钥持有者 Luigi 和 fluffypony 作为门罗团队的核心人员,自身作恶的可能性比较低。但门罗团队作为少数具备加密朋克精神的团队之一,CCS 钱包的密钥只“分配”给两人持有,确实不够去中心化。

有趣的是,被盗事件并未引起太多关注,大家反而将重点放在为什么门罗币被盗后,链上监控公司能够追踪交易,这引起了大家对门罗币的不可追溯性和匿名性产生了质疑。

为此比特币工具开发商 FOUNDATION 战略及市场营销主管 Seth For Privacy 在 X 平台发文表示,CCS 钱包被盗交易能够被追踪到,是因为团队将私钥与链上监控公司共享,由于 Monerujo 中使用 PocketChange 功能,因此可以看到非常具体的链上足迹,相关交易使用 PocketChange 进行大规模整合。

Seth For Privacy 还表示,门罗币的隐私匿名特性依旧存在,在绝大多数情况下依旧是能打破封锁,保障交易隐私。

XMR CCS钱包被盗,大家的关注点竟是……

结语

门罗项目的 CCS 被盗事件的具体原因尚不可知,无论是操作流程中出现的漏洞,还是其他外力因素,但作为以加密朋克精神著称的门罗团队,CCS 钱包的密钥管理采用相对中心化的方式,同时,由于门罗项目发展时间较早,MPC 等技术还不够成熟。这点需要社区尽快优化。

此外,这一事件从另一个角度引发了门罗币的匿名性和不可追溯性特点的讨论,也让“将私钥交由链上监控公司追踪交易记录”的事后处理方式浮出水面。

İlgili Okumalar

Anthropic's IPO Launch: Commercial Miracle or Valuation Bubble?

Anthropic has confidentially filed for an IPO, led by Morgan Stanley and Goldman Sachs, potentially going public by October. Following its latest $650 billion funding round, its pre-IPO valuation stands at $965 billion, with projections reaching up to $2 trillion at listing, which would make it the highest-valued private company ever. The article, written by Fu Sheng, addresses skepticism that this represents an AI bubble akin to the 2000 dot-com crash. It argues the current situation differs fundamentally. Unlike the internet bubble era, which relied on speculative narratives with little revenue, Anthropic's valuation is backed by unprecedented, measurable financial performance. Key data points include: * **Revenue Growth:** ARR skyrocketed from $10 billion in early 2025 to $470 billion by May 2026, targeting $100 billion by year-end—a growth curve unmatched in business history. * **Profitability:** It achieved operating profitability in Q2 2026 with an estimated $5.6 billion profit. * **Efficiency:** With ~3,000 employees and ~$470 billion ARR, its revenue per employee exceeds $10 million. Products like Claude Code, launched less than a year ago, already generate $25 billion in annualized revenue. * **Enterprise Adoption:** It boasts a strong enterprise client base, with 8 of the Fortune 10 and over 1,000 large firms spending over $1 million annually on Claude. The valuation is framed using a traditional SaaS model (e.g., a 10x Price-to-Sales multiple on $100 billion revenue). The author contends the core question for analysts has shifted from "How big could this be?" to "How much is it earning and will earn next quarter?" The discussion extends beyond Anthropic to a broader paradigm shift: the transition from a "carbon-based" to a "silicon-based" economy. Companies are increasingly prioritizing investment in compute and AI capabilities over human resources, as these directly scale productivity and competitive advantage. Anthropic's IPO is thus positioned not just as a corporate milestone, but as a price anchor for this new economic era.

链捕手35 dk önce

Anthropic's IPO Launch: Commercial Miracle or Valuation Bubble?

链捕手35 dk önce

Near Returns to the AI Stage: Transformation into a Public Chain Due to 'Payroll Difficulties,' Agent and Privacy Emerge as New Growth Narratives

NEAR Returns to AI Origins: From Payroll Struggles to Blockchain, Now Focusing on AI Agents and Privacy NEAR Protocol's journey began not with grand blockchain ambitions, but from a practical hurdle: its AI startup founders, including Transformer paper co-author Illia Polosukhin, couldn't efficiently pay international developers in 2017. This led them to pivot and build a high-performance, scalable blockchain. After years navigating various crypto narratives like sharding and cross-chain interoperability, NEAR is now leveraging its AI roots to re-enter the AI arena. A key driver is its "NEAR Intents" layer, which abstracts complex cross-chain transactions. Users simply state their goal (e.g., swap BTC for ETH), and a solver network finds the optimal route. This system has processed over $20B in cross-chain volume, generating significant fee revenue. A major growth area is private transactions via "Confidential Intents/Swaps," which hide trade details until settlement to protect against MEV and front-running. Remarkably, private swaps recently accounted for over 40% of NEAR's transaction volume, highlighting strong demand but also potential regulatory scrutiny. With its AI-founder pedigree, NEAR is positioning itself at the intersection of blockchain, AI agents, and privacy, aiming to become infrastructure for the emerging agent economy while navigating the challenges of its rapid adoption.

marsbit3 saat önce

Near Returns to the AI Stage: Transformation into a Public Chain Due to 'Payroll Difficulties,' Agent and Privacy Emerge as New Growth Narratives

marsbit3 saat önce

From Ethereum to AI's 'CROPS': What Exactly is This Set of 'Slow Variables' That Vitalik Repeatedly Emphasizes?

In recent discussions, Vitalik Buterin has frequently emphasized the concept of "CROPS," a framework defining core values for Ethereum's development. CROPS stands for Censorship Resistance, Capture Resistance, Open Source, Privacy, and Security. Initially outlined in the Ethereum Foundation's "EF Mandate," it represents a commitment to user sovereignty, ensuring that the network resists external control, remains open, protects privacy, and prioritizes security. The relevance of CROPS extends beyond Ethereum's foundational principles, becoming crucial in the context of AI integration. As AI agents begin handling wallet operations and automated transactions, the risk increases that users may cede control over their digital assets, privacy, and intentions to centralized AI service providers. A "CROPS AI" would therefore emphasize local execution where possible, privacy-preserving remote model calls (e.g., using zero-knowledge proofs), and transparent, verifiable processes to maintain user agency. Vitalik highlights a significant convergence between "CROPS Ethereum access layer" and "CROPS AI." Both address the same fundamental challenge: how users can access powerful services—be it blockchain data via RPCs or AI models—without exposing sensitive information or relinquishing ultimate control. This intersection points toward a future digital entry point that is more private, secure, and user-controlled. Ultimately, CROPS is not merely an abstract ideal but a practical guidepost. It steers development—from protocol resilience and wallet design to AI agent safety—towards a future where users retain self-sovereignty even as digital systems grow more complex and powerful. In an era of accelerating AI adoption, these "slow variables" of censorship resistance, openness, privacy, and security may define Ethereum's enduring value.

marsbit3 saat önce

From Ethereum to AI's 'CROPS': What Exactly is This Set of 'Slow Variables' That Vitalik Repeatedly Emphasizes?

marsbit3 saat önce

İşlemler

Spot
Futures
活动图片