Хакеры украли $4,5 млн из DeFi-протокола CrediX через уязвимость мультиподписного кошелька

cryptonews.ruОпубліковано о 2025-02-03Востаннє оновлено о 2025-08-04

Сразу из нескольких источников стало известно об атаке на DeFi-платформу CrediX, в результате которой злоумышленники вывели около $4,5 млн. Об этом сообщили аналитические команды CertiK, SlowMist и PeckShield. Все украденные средства были переведены из Sonic-сети в Ethereum, и до сих пор остаются на кошельках злоумышленника.

По данным SlowMist, ключевым моментом стало изменение прав доступа в CrediX Multisig Wallet, которое произошло 6 дней назад. В результате атакующий получил роль администратора и Bridge-оператора через модуль ACLManager. Это дало ему возможность самостоятельно выпускать обеспеченные токены в пуле, обходя все ограничения.

Эксперты PeckShield подтвердили, что скомпрометированный аккаунт имел полный контроль над ключевыми административными функциями. Среди них — POOL_ADMIN, BRIDGE, ASSET_LISTING_ADMIN, EMERGENCY_ADMIN и RISK_ADMIN. Используя полномочия BRIDGE, хакер выпустил не обеспеченные токены acUSDC (CrediX Market Sonic USDC), после чего вывел все активы с платформы.

Сообщается, что сайт платформы CrediX был временно отключен для предотвращения новых депозитов, а представители команды заявили, что ведется активное расследование. Они пообещали вскоре предоставить подробности и обновления по этому инциденту.

Эксперты отмечают, что это не первая атака, связанная с неправильным управлением ролями в смарт-контрактах. Подобные уязвимости позволяют злоумышленникам обойти протокол безопасности без взлома кода. Аналитики подчеркивают важность регулярного аудита прав доступа и многоступенчатой защиты мультисигов.

Атака на CrediX вновь ставит под сомнение надежность децентрализованных протоколов без продуманной схемы управления доступами. Инвесторам и разработчикам стоит учитывать не только технические аудиты, но и риски внутри DeFi-систем.

Пов'язані матеріали

US CFTC Launches Broad Investigation into Polymarket, Is the Prediction Market Party Coming to an End?

The U.S. Commodity Futures Trading Commission (CFTC) is conducting a broad investigation into the prediction market platform Polymarket, focusing on its business practices including social media promotions. This follows a bipartisan letter from U.S. senators urging the CFTC to probe alleged fraudulent marketing tactics used to promote gambling-like products. The action coincides with a period of explosive growth for the prediction market sector, driven by events like the World Cup, with platforms like Kalshi and Robinhood reporting record trading volumes and revenue. The investigation signals a potential end to the sector's unregulated expansion and may lead to clearer federal oversight, particularly regarding investor protection and distinguishing prediction markets from traditional sports betting. The CFTC's move has also intensified a jurisdictional conflict with multiple U.S. states (including Kentucky and New York), which have sued platforms like Polymarket and Kalshi, accusing them of operating illegal sports betting and threatening state gambling tax revenues. Furthermore, the CME Group has sued the CFTC, challenging its approval of certain prediction market products. The report also highlights the political and capital interests intertwined with the industry. Donald Trump Jr. holds advisory and investment roles in both Kalshi and Polymarket, and the Trump administration has previously emphasized federal regulatory authority over these markets. The CFTC's investigation into Polymarket is framed as a step towards formalizing the industry's regulatory landscape, moving it from a phase of "wild growth" towards a more structured future.

marsbit1 год тому

US CFTC Launches Broad Investigation into Polymarket, Is the Prediction Market Party Coming to an End?

marsbit1 год тому

U.S. CFTC Launches Extensive Investigation into Polymarket, Is the Prediction Market Frenzy Season Cooling Down?

The U.S. Commodity Futures Trading Commission (CFTC) has launched a broad investigation into the prediction market platform Polymarket, focusing on its business practices including social media activities. This follows a bipartisan letter from U.S. senators urging the CFTC to probe allegations of paid influencer false marketing and fraudulent promotion of gambling-like products to American users. The investigation comes as the prediction market sector experiences explosive growth, largely driven by the World Cup. Weekly trading volumes have hit record highs, exceeding $14.4 billion, with platforms like Kalshi and Robinhood's new venture seeing significant activity. Major firms like Meta are also showing interest in the space. This regulatory scrutiny signals a potential end to the sector's "wild growth" phase. The CFTC's move also highlights an escalating jurisdictional conflict between federal regulators and state authorities. Over a dozen states, including Kentucky and New York, have sued platforms like Polymarket and Kalshi, accusing them of operating illegal sports betting, which threatens state gambling tax revenues. The CFTC is countersuing to assert its exclusive federal jurisdiction over these "event contracts" as derivatives. Furthermore, the CFTC's approval of Kalshi's Bitcoin perpetual futures contract has sparked a lawsuit from traditional exchange CME, alleging regulatory overreach. The political and capital landscape is intricate, with Donald Trump Jr. holding advisory roles and investments in both Kalshi and Polymarket. This connects capital, political influence, and regulatory bodies, suggesting the current investigation may be a step toward formalizing the industry's rules rather than halting its progress.

Odaily星球日报1 год тому

U.S. CFTC Launches Extensive Investigation into Polymarket, Is the Prediction Market Frenzy Season Cooling Down?

Odaily星球日报1 год тому

Торгівля

Спот
活动图片