Eksploitasi SagaEVM Chain Menyebabkan $7 Juta Dihisap, Dana Dipindahkan ke Ethereum

TheNewsCryptoОпубліковано о 2026-01-22Востаннє оновлено о 2026-01-22

Анотація

Rantai SagaEVM, bagian dari ekosistem blockchain Layer-1 Saga, masih dijeda setelah mengalami eksploitasi keamanan pada 21 Januari. Tim berhasil mengidentifikasi dompet penyerang dan melacak aset senilai sekitar $7 juta yang dicuri, dengan sebagian dana telah dipindahkan ke Ethereum melalui bridge. Setelah mendeteksi serangan, tim segera menghentikan rantai pada blok 6.593.800 untuk mencegah transfer lebih lanjut. Investigasi forensik mendetail sedang dilakukan, dan laporan post-mortem teknis akan dirilis. Jaringan utama Saga SSC dan keamanan validator tidak terdampak. Aset yang dicuri termasuk USDC, sebagian dikonversi ke ETH atau token lain. Saga sedang berkoordinasi dengan bursa dan operator bridge untuk mem-blacklist alamat peretas dan mendukung pemulihan dana. Industri kripto catat kerugian $3,4 miliar akibat pencurian hingga Desember 2025, dengan peningkatan signifikan dalam serangan terhadap dompet pribadi.

Rantai SagaEVM, bagian dari ekosistem blockchain Saga Layer-1, tetap dijeda setelah eksploitasi keamanan pada 21 Januari. Dengan demikian, pembaruan investigasi dirilis pada 22 Januari, dompet penyerang ditemukan, dan aset senilai sekitar $7 juta, dengan beberapa dikonversi ke Ethereum. Lebih lanjut, tim sedang bekerja untuk memblacklist alamat peretas tersebut.

Saga Mengidentifikasi Dompet Penyerang Saat Dana Dibridge ke Ethereum

Setelah eksploitasi diidentifikasi, pada hari pertama, tim menghentikan rantai pada tinggi blok 6.593.800 untuk menghentikan transfer yang tidak sah. Juga, tampaknya melibatkan serangkaian penyebaran kontrak, interaksi lintas rantai, dan penarikan likuiditas cepat yang memungkinkan penyerang mengekstrak aset.

Aset yang dicuri, termasuk USDC, ditransfer ke mainnet Ethereum dan, dalam beberapa kasus, dikonversi ke ETH atau token lainnya. Juga, Saga telah mengidentifikasi dompet yang terkait dengan eksploitasi dan sedang bekerja sama dengan bursa dan operator bridge untuk memblacklist-nya dan mendukung pemulihan aset.

Dengan demikian, saat ini tim Saga sedang melakukan investigasi forensik terperinci dan berencana untuk menerbitkan laporan post-mortem teknis yang komprehensif.

Eksploitasi mempengaruhi rantai jaringan SagaEVM itu sendiri, serta lingkungan seperti Colt dan Mustang yang mengandalkan fungsionalitas EVM, sedangkan mainnet Saga SSC, lapisan konsensus, dan keamanan Validator tidak terpengaruh, dan tidak ada bukti kompromi kunci pribadi.

Estimasi Pencurian Chainalysis pada 2025

Industri kripto kehilangan lebih dari $3,4 miliar dalam pencurian antara Januari dan awal Desember 2025, menyoroti masalah keamanan yang berkelanjutan.

Laporan tersebut mengatakan bahwa serangan terhadap dompet pribadi investor meningkat signifikan pada tahun 2025, dengan nilai yang dicuri naik dari 7,3% menjadi 44%. Di mana kejadian drain dompet kripto langsung sekitar 158.000, dengan lebih dari 80.000 korban berbeda.

Berita Kripto Terbaru yang Disoroti:

Thailand Merancang Aturan ETF Kripto Seiring Permintaan Institusional Meningkat

TagsETHEREUMSagaEVM cHAIN

Трендові криптовалюти

Пов'язані питання

QApa yang terjadi pada rantai SagaEVM pada tanggal 21 Januari?

ARantai SagaEVM mengalami eksploitasi keamanan dan tetap dijeda (paused) setelah insiden tersebut.

QBerapa jumlah aset yang berhasil dicuri dalam eksploitasi ini dan ke mana dana tersebut dialihkan?

ASekitar $7 juta aset berhasil dicuri, dengan sebagian dana dialihkan ke jaringan Ethereum.

QApa yang dilakukan tim Saga untuk menanggapi serangan ini?

ATim Saga menghentikan rantai pada blok tertentu, mengidentifikasi dompet penyerang, bekerja dengan bursa untuk blacklist alamat, dan melakukan investigasi forensik mendalam.

QBagian mana dari ekosistem Saga yang tidak terpengaruh oleh eksploitasi ini?

ASaga SSC mainnet, lapisan konsensus, dan keamanan Validator tidak terpengaruh, serta tidak ada bukti kompromi kunci privat.

QMenurut laporan Chainalysis, berapa total kerugian akibat pencurian kripto pada tahun 2025?

AIndustri kripto kehilangan lebih dari $3,4 miliar akibat pencurian antara Januari dan awal Desember 2025.

Пов'язані матеріали

How to Detect AI-Generated Videos? A Review of Dynamic, Traceable, and Explainable Detection Systems

**How to Detect AI-Generated Videos: A Survey on Dynamic, Traceable, and Explainable Detection Systems** With rapid advances in AI video generation (e.g., Sora, Veo), creating highly realistic, multi-minute videos is now possible, widening the gap with detection research. Current AI video detection, often limited to unreliable binary classifications, is insufficient. This survey, accepted at ACL 2026, reframes the goal as **"factual fidelity verification"**—checking if a video's content (who, when, where, what) aligns with the real world perceptually and cognitively. It categorizes AI-generated videos into three paradigms: **Local Manipulation Videos (LMV**, e.g., face swaps), **Audio-Visual Editing (AVE**, e.g., lip-syncing), and **Generative Video Synthesis (GVS**, fully synthetic videos like Sora's). Detection challenges evolve from visual artifacts in LMV to multi-modal inconsistencies in AVE and higher-level world knowledge violations in GVS. The core proposal is a **Vision-Language Dual-View framework** with four hierarchical layers: 1. **Layer 1 (Intrinsic Visual Cues):** Analyzes low-level signal statistics, noise patterns, and physiological signals. 2. **Layer 2 (Spatiotemporal Consistency):** Checks for temporal coherence in object motion and scene dynamics. 3. **Layer 3 (Cross-Modal Consistency):** Verifies alignment between video, audio, and text within the video. 4. **Layer 4 (Language-Guided World-Level Reasoning):** Uses external knowledge, facts, and physical laws to judge semantic plausibility and factual correctness. The survey traces a shift in detection focus from lower layers (1 & 2) toward higher, language-involved layers (3 & 4). It also reviews evolving evaluation metrics and datasets tailored for each video paradigm. The conclusion advocates for a **dynamic, evidence-first detection system** that moves beyond simple classification. Future trustworthy detection requires combining visual evidence (from CV) with semantic reasoning and explanation (from NLP & multimodal AI), ultimately creating traceable and explainable judgments about a video's adherence to real-world constraints.

marsbit12 хв тому

How to Detect AI-Generated Videos? A Review of Dynamic, Traceable, and Explainable Detection Systems

marsbit12 хв тому

It Turns Out the First Real-World Application of AI x Crypto is in Security Auditing

The article explores the surprising trend where AI's first major impact on crypto has been in security auditing, not in areas like trading or analytics. It details how AI-powered tools are dramatically lowering the barrier to finding smart contract vulnerabilities, enabling attackers to scan thousands of contracts and execute exploits within minutes. This has rendered traditional, manually-produced audit reports with their month-long validity periods increasingly obsolete, creating a critical "structural crack" in the old security model. Cases like Drift Protocol and KelpDAO show that even extensively audited protocols can be hacked through social engineering, operational flaws, or infrastructure misconfigurations beyond pure code review. Attackers are also using AI to find and exploit vulnerabilities in years-old, deployed contracts. Notably, OpenZeppelin's co-founder has expressed a grim view that "all DeFi is insecure" due to AI's asymmetric advantage. In response, the audit industry is undergoing a fundamental shift. While there's a short-term spike in defensive re-audits, the long-term business model is changing. Firms are developing AI-assisted systems and moving from one-time report deliveries towards embedded, continuous services like real-time monitoring and formal verification. Examples include AI tools uncovering critical, previously missed vulnerabilities in heavily audited protocols like Curve Finance and Zcash. The conclusion is that security must become a continuous investment, not a one-time checkbox, and audit firms must rapidly evolve their tools and service models to survive.

marsbit18 хв тому

It Turns Out the First Real-World Application of AI x Crypto is in Security Auditing

marsbit18 хв тому

Never expected that the first tangible application of AI x Crypto is in security auditing

Unexpectedly, the initial major application of AI in the Crypto sphere has turned out to be security auditing. In 2026, DeFi has faced significant security challenges, with 121 hacking incidents resulting in approximately $942 million in losses. While AI was expected to first impact areas like quantitative trading, its initial breakthrough has instead transformed security auditing by drastically lowering the cost and skill barrier for finding smart contract vulnerabilities. The traditional audit model is facing obsolescence. Advanced AI models, such as Claude Mythos, enable attackers to scan thousands of contracts and identify vulnerability patterns at scale, compressing the time from discovery to execution to mere minutes. This renders the month-long validity of traditional audit reports ineffective. Notably, attacks now frequently target well-audited, established protocols by exploiting business logic flaws, operational security weaknesses, and even years-old historical contracts, demonstrating that old audit reports offer zero protection. This pressure is forcing a fundamental shift in the industry. In the short term, a wave of defensive re-auditing is occurring, driven by projects seeking to meet new AI-era security standards and regulatory requirements. In the long run, audit firms' business models are diverging. The one-time report delivery model is declining in value, as evidenced by platforms like Code4rena shutting down. Leading firms are now pivoting towards AI-powered defense, integrating continuous monitoring, real-time on-chain risk detection, and embedding security directly into the development phase, as seen with tools like OpenZeppelin's Skills system. Ultimately, the era of "audit once, secure forever" is over. Security must become a continuous, embedded infrastructure investment for projects. For audit companies, survival depends on proactively transforming from traditional service providers into platforms offering AI-native, ongoing security solutions.

链捕手26 хв тому

Never expected that the first tangible application of AI x Crypto is in security auditing

链捕手26 хв тому

Торгівля

Спот

Популярні статті

Як купити SAGA

Ласкаво просимо до HTX.com! Ми зробили покупку Saga (SAGA) простою та зручною. Дотримуйтесь нашої покрокової інструкції, щоб розпочати свою криптовалютну подорож.Крок 1: Створіть обліковий запис на HTXВикористовуйте свою електронну пошту або номер телефону, щоб зареєструвати обліковий запис на HTX безплатно. Пройдіть безпроблемну реєстрацію й отримайте доступ до всіх функцій.ЗареєструватисьКрок 2: Перейдіть до розділу Купити крипту і виберіть спосіб оплатиКредитна/дебетова картка: використовуйте вашу картку Visa або Mastercard, щоб миттєво купити Saga (SAGA).Баланс: використовуйте кошти з балансу вашого рахунку HTX для безперешкодної торгівлі.Треті особи: ми додали популярні способи оплати, такі як Google Pay та Apple Pay, щоб підвищити зручність.P2P: Торгуйте безпосередньо з іншими користувачами на HTX.Позабіржова торгівля (OTC): ми пропонуємо індивідуальні послуги та конкурентні обмінні курси для трейдерів.Крок 3: Зберігайте свої Saga (SAGA)Після придбання Saga (SAGA) збережіть його у своєму обліковому записі на HTX. Крім того, ви можете відправити його в інше місце за допомогою блокчейн-переказу або використовувати його для торгівлі іншими криптовалютами.Крок 4: Торгівля Saga (SAGA)Легко торгуйте Saga (SAGA) на спотовому ринку HTX. Просто увійдіть до свого облікового запису, виберіть торгову пару, укладайте угоди та спостерігайте за ними в режимі реального часу. Ми пропонуємо зручний досвід як для початківців, так і для досвідчених трейдерів.

116 переглядів усьогоОпубліковано 2024.12.13Оновлено 2026.06.02

Як купити SAGA

Обговорення

Ласкаво просимо до спільноти HTX. Тут ви можете бути в курсі останніх подій розвитку платформи та отримати доступ до професійної ринкової інформації. Нижче представлені думки користувачів щодо ціни SAGA (SAGA).

活动图片