Исследователи Halborn: протокол BetterBank на базе Pulsechain потерял $5 млн из-за взлома

cryptonews.ru2025-06-02 tarihinde yayınlandı2025-09-03 tarihinde güncellendi

В августе 2025 года кредитный протокол BetterBank, работающий на сети Pulsechain, подвергся крупной атаке. Подробности нападения рассказали специалисты компании Halborn. Хакеры использовали уязвимость в системе начисления бонусов, что позволило им вывести средства на сумму $5 млн. Инцидент стал одним из крупнейших для экосистемы и вновь показал слабые места в управлении логикой вознаграждений в DeFi-протоколах.

Механизм атаки основывался на создании поддельных торговых пар. Злоумышленники сформировали пары из токена FAVOR и собственного бесполезного актива. При совершении массовых сделок система начисляла им огромные бонусы в ESTEEM-криптовалютах. Дополнительно проблему усугубляло то, что налоговые правила протокола применялись только к официальным парам. В итоге хакеры смогли обойти оплату комиссионных и эффективно обнулить защитные механизмы.

После обнаружения атаки команда BetterBank остановила торговлю и заявила, что сумела договориться с хакером. В результате около 550 млн pDAI было возвращено на смарт-контракт. Однако ущерб в $5 млн потряс экспертов, а доверие пользователей к платформе оказалось серьезно подорвано.

Особое внимание привлек тот факт, что уязвимость ранее была зафиксирована во время аудита. Эксперты безопасности описали сценарий атаки, но использовали в примере тестовый эфир вместо неликвидного токена. По этой причине разработчики посчитали атаку финансово нереализуемой и понизили ее статус с «критического» до «низкого». Патч, предложенный аудиторами, внедрен не был.

Таким образом, ситуация с BetterBank показала, что даже наличие аудита не гарантирует безопасность протокола, если выводы специалистов интерпретируются неправильно. Неполное понимание рисков и снижение их приоритета в итоге стоили протоколу миллионов долларов. Инцидент стал наглядным примером, как недооцененные предупреждения могут обернуться катастрофическими последствиями.

İlgili Okumalar

White House Crypto Summit Full Breakdown: Trump Pushes for On-Chain Exchanges to Enter the U.S., September 15 Crypto Regulation Vote is the Real Deadline

White House Crypto Summit: Trump Backs On-Chain Exchange Entry, September 15th Vote is the Deadline On August 19th, former President Trump convened crypto and Wall Street executives at the White House, declaring an end to the "crypto war." He urged Congress to pass a "fair version" of the CLARITY Act by the September 15th deadline, hinted at potential further U.S. Bitcoin purchases, and announced CFTC efforts to bring the decentralized exchange Hyperliquid into the U.S. compliantly. The summit was preceded by an SEC proposal creating new exemptions for crypto asset fundraising and followed the next day by CFTC Chair Selig's stark warning. Selig stated that if Congress fails to pass the CLARITY Act by September 15th, the CFTC will independently write rules to allow registered and some unregistered platforms to offer leveraged trading under its oversight. Trump's endorsement of Hyperliquid triggered a significant market reaction, boosting its token and related stock prices. However, its path to U.S. compliance remains uncertain, potentially involving a hybrid structure with licensed brokers handling front-end operations. The primary hurdle for the CLARITY Act is not its crypto provisions but attached ethics clauses aimed at restricting federal officials, including the President, from profiting from crypto businesses. Industry leaders like Coinbase's Brian Armstrong view the September 15th vote as critical for establishing durable regulatory certainty, while Selig framed congressional action as the only sure defense against future regulatory overreach.

marsbit4 dk önce

White House Crypto Summit Full Breakdown: Trump Pushes for On-Chain Exchanges to Enter the U.S., September 15 Crypto Regulation Vote is the Real Deadline

marsbit4 dk önce

Is Poland Still a Low-Cost Gateway to the EU CASP Market?

Is Poland still a low-cost gateway to the EU’s Crypto-Asset Service Provider (CASP) regime? As of mid-2026, the answer has fundamentally changed. Poland’s previous light-touch VASP registration system, once an attractive EU entry point, is no longer valid for providing MiCA-regulated services after its transition period ended on July 1, 2026. Furthermore, Poland's domestic legislation implementing MiCA is still undergoing final adjustments, creating uncertainty for direct CASP authorization. This shift means the old logic—choosing Poland primarily for low registration and operational costs—is no longer viable. Under MiCA, a CASP license is no longer a "light" registration, and Poland's current regulatory limbo adds unpredictable delays and risks. For projects seeking EU market access, a more practical strategy is emerging: obtain a MiCA CASP authorization in another EU member state with a stable regulatory framework (e.g., Lithuania, Malta), then use MiCA's passporting rights to serve the Polish market. This approach prioritizes regulatory certainty and EU-wide access over marginal cost savings. Poland remains a significant EU market. It is a viable CASP home country only for projects with a genuine, long-term operational presence there. For others, especially those with teams and clients across Europe, starting the CASP process elsewhere in the EU is now the more efficient and reliable path. The era of using a Polish entity as a cheap, quick EU regulatory foothold is over.

marsbit5 dk önce

Is Poland Still a Low-Cost Gateway to the EU CASP Market?

marsbit5 dk önce

İşlemler

Spot
活动图片