Beyond Private Keys: From Wallets and L2 to Supply Chains, How to Guard the Security Perimeter of Web3?

marsbitXuất bản vào 2026-07-09Cập nhật gần nhất vào 2026-07-09

Tóm tắt

Beyond Private Keys: Securing Web3's Expanding Attack Surface from Wallets to L2s and Supply Chains The crypto space faced a wave of security incidents in June, with over $75 million lost across 40 major attacks. These breaches highlighted risks beyond private key theft, exposing vulnerabilities across the entire user interaction chain. Wallet security was compromised not through stolen seed phrases, but via a critical flaw in the Cardano wallet SecondFi's signing implementation. This bug allowed attackers to potentially derive private keys from publicly visible signature data, emphasizing that wallet security depends on correct cryptographic implementation, ideally in open-source, auditable code. Layer-2 networks also revealed complex trust chain risks. Attacks on legacy Aztec deployments exploited inconsistencies in proof systems, showing that a valid zero-knowledge proof is only as secure as its underlying rules. Another attack on Taiko's SGX-based prover stemmed from a leaked signing key and inadequate verification checks. Furthermore, a technical glitch halted Base's block production, underscoring that L2 security encompasses network availability and reliable user exit paths as much as asset safety. Finally, the Polymarket incident demonstrated that even audited smart contracts are not immune. A compromised third-party supplier led to a malicious script being injected into the platform's frontend, resulting in user fund losses. This "supply chain attack" shows that t...

The crypto world experienced a series of security incidents spanning multiple areas in the month of June that just passed.

According to the latest monthly security report released by PeckShield, there were 40 significant hacking incidents in June, resulting in total losses of approximately $75.87 million. More alarmingly, these attacks were not concentrated on a single type of attack vector. Instead, they covered vulnerabilities across wallet signature implementation flaws, L2 protocol weaknesses, and third-party service supply chain attacks, with multiple lines of defense being breached within the same month.

As Web3 security risks expand from single entry points to the entire on-chain interaction path, every user is compelled to reconsider a question: Are my crypto assets still secure?

I. Beyond Private Keys: The Importance of Wallet Underlying Signature Implementation

The security incident that occurred on the Cardano ecosystem wallet SecondFi in June serves as the most direct example.

SecondFi is the successor to the Cardano ecosystem wallet Yoroi. Between June 21st and 23rd, attackers transferred approximately 16 million ADA from some SecondFi user addresses, involving about 374 wallets, valued at around $2.4 million at the time of the incident. SecondFi subsequently stated that emergency measures protected an additional approximately 129 million ADA potentially at risk.

The most unique aspect of this incident is that affected users did not actively hand over their seed phrases to the attackers. The problem lay in the wallet's underlying signature implementation. According to analysis by the security firm BlockSec, it incorrectly derived the signature nonce from the public transaction message, omitting the secret nonce prefix required by the standard implementation.

This meant that whenever users signed transactions using an affected version of the wallet, the public signature data posted to the chain would expose information sufficient to deduce the private key of the address. Therefore, attackers did not need to hack the user's phone or obtain the seed phrase; they only needed to analyze the public on-chain data to potentially recover the signing private key corresponding to the address.

From the user's perspective, the wallet was still functioning normally—after all, no pop-up leaked the seed phrase, passwords weren't cracked, and transactions were indeed initiated by the user. However, from a cryptographic standpoint, as long as the user's address had generated some valid signatures through the affected version, the public transaction and signature data could potentially help attackers deduce the address's signing private key.

Ultimately, wallet security also depends on whether private keys are generated correctly, whether signatures are performed strictly according to cryptographic standards, and whether these critical codes can be externally audited and verified. This is also the importance of keeping core wallet components open-source.

Of course, this is an implementation flaw specific to a particular wallet version, not a universal issue with all self-custody wallets. Taking imToken's TokenCore as an example, its core code repository is publicly hosted on GitHub, covering underlying wallet functions such as key management, address derivation, and transaction signing.

While open-source does not necessarily mean the code is entirely free of vulnerabilities, nor does it mean users can completely abandon vigilance, for the most sensitive cryptographic and signature components within a wallet, open-source at least provides an important premise: security researchers, developers, and the community can inspect the code, reproduce issues, and conduct continuous testing, rather than having to trust an unverifiable black box.

For ordinary users, this type of incident also corresponds to a few more practical security principles.

  • First, wallets should always be downloaded through official websites or official app stores, and security updates should be applied promptly.
  • Second, it's not advisable to keep all assets in the same wallet used for daily interactions. Large, long-term assets can be stored using hardware wallets or separate cold wallets, isolated from hot wallets frequently connected to DApps.
  • More importantly, once a wallet officially confirms a vulnerability at the key generation or signature implementation level, simply importing the same seed phrase into another wallet typically does not solve the problem;

Because after importing the same set of seed words into another wallet, the addresses and private keys that were already exposed will not change. Affected assets need to be transferred to a new address that has never signed through the vulnerable version. For ordinary users, a more reliable approach is usually to follow the official emergency procedure to create an entirely new wallet and seed phrase, and then complete the asset migration, rather than repeatedly importing or manipulating the original address themselves.

II. L2 is Not Just "Cheaper Ethereum," It's Also a Complex Chain of Trust

Beyond wallets, multiple incidents in June also point risks towards increasingly complex L2 systems.

On June 14th and 18th, two legacy Rollup deployments related to Aztec were successively attacked, resulting in combined losses of approximately $4.35 million.

It is important to note that the attacks targeted legacy deployments of Aztec Connect that were already in a deprecated state; this is not equivalent to the current Aztec Network mainnet itself being attacked. However, the issues exposed by both incidents are highly instructive for the entire ZK Rollup field.

In one incident, the attacker exploited an inconsistency between the number of transactions and the actual processed data, causing the system to record a deposit internally within the proof while bypassing the corresponding balance deduction process on L1.

The other incident stemmed from a missing constraint in the zero-knowledge proof circuit. The system validated a proof that was formally valid but did not ensure that the private state tree used by the proof was completely consistent with the public state root on Ethereum used for actual settlement. The attacker could therefore generate proofs around a forged state tree and extract assets from the L1 contract.

Such problems are difficult to summarize with the traditional notion of "whether there is a specific line of vulnerable code in the contract." After all, zero-knowledge proofs can prove that a certain computation process conforms to established rules, but the premise is that the rules themselves are correct and complete. If developers forget to constrain a critical variable, the proof may still be mathematically valid but prove a result inconsistent with the actual settlement state.

The subsequent security incident involving Taiko exposed another type of L2 trust chain risk.

On June 22nd, Taiko's SGX-based proof verification process was exploited, causing losses of approximately $1.7 million. According to BlockSec's analysis, the attacker used an SGX enclave signing private key that had once been committed to a public GitHub repository, while also exploiting a flaw in the on-chain verification contract that did not reject DEBUG mode Enclaves, registering a malicious prover as a legitimate instance.

The attacker then forged L2 state proofs, causing the contract on Ethereum to accept a non-existent L2 state, ultimately extracting assets from the bridge funds. In essence, this happened because the key used to sign the trusted execution environment was made public, and the remote attestation rules did not fully check the runtime environment attributes, ultimately causing a proof that was "attested" to lose its originally intended meaning of trustworthiness.

Meanwhile, Base experienced consecutive halts in mainnet block production on June 25th and 26th. Base stated in a post-mortem analysis that both interruptions stemmed from the same block construction logic flaw: a failed transaction did not correctly clean up previously recorded state, causing subsequent transactions to have Gas incorrectly calculated and leading to the generation of a block containing invalid state transitions. As other nodes could not accept this block, the network ultimately stopped progressing. Base stated that chain integrity was not compromised during the incident, and user funds remained safe.

This was not an asset theft or external attack but a technical failure affecting network availability and recovery capability. However, from a broader security perspective, availability itself is part of the L2 security model.

Because for users, whether a chain is secure depends not only on whether hackers can forge assets, but also on whether blocks can be produced continuously, cross-chain bridges can function normally, nodes can recover quickly, and whether users still have a feasible exit path when the system fails.

Therefore, when using L2, users should not only compare fees and airdrop expectations. For L2s that are smaller, newly launched, or whose security mechanisms are still rapidly evolving, try to avoid storing large amounts of assets beyond actual usage needs for extended periods. Before bridging, confirm the use of the official bridge and understand withdrawal times, pause mechanisms, and emergency exit methods. If encountering network halts, bridging abnormalities, or official security warnings, do not repeatedly submit transactions or continue bridging assets.

A more prudent approach is to manage assets of different purposes and risk levels separately, rather than placing all liquidity on the same L2, the same cross-chain bridge, or the same exit mechanism.

III. Even If the Contract Isn't Hacked, Third-Party Services Can Bring Attacks to Users

If the issues with wallets and L2 still occur within relatively low-level technical components, then the Polymarket incident illustrates that the web frontend, closest to the user, can also become a fund entry point.

On June 25th, Polymarket stated that a third-party vendor they used was compromised. Attackers used this to inject malicious scripts into the Polymarket frontend accessed by some users.

According to statistics from security agencies and on-chain analysts, the incident resulted in approximately $3 million in user asset losses, involving about 11 wallets. The stolen funds were subsequently bridged from Polygon to Ethereum and exchanged for approximately 1,893 ETH. However, Polymarket later stated that it had removed the affected dependency and would fully reimburse affected users.

The key to this incident is that users might still be visiting the correct Polymarket domain name. Existing disclosures have not pointed to vulnerabilities in Polymarket's core smart contracts. The main problem lay in a third-party frontend dependency loaded by the webpage.

This also serves as a mirror. Today, most Web3 applications do not run entirely on-chain. The webpages users see, such as trading interfaces, still heavily rely on traditional internet infrastructure and third-party software packages. If any one of these dependencies is attacked, it could cause a legitimate website to display incorrect information to users, replace receiving addresses, or induce wallets to sign malicious transactions.

Therefore, "the URL is correct" does not necessarily equate to "all code loaded at this moment is secure." "The contract has been audited" also does not mean the entire interaction path between the user and the contract is risk-free. Faced with these types of frontend and supply chain attacks, ordinary users find it difficult to independently inspect every piece of code loaded by a webpage, but they can still limit potential losses by reducing single-interaction permissions:

  • Use a dedicated DApp interaction wallet: Avoid directly connecting long-term savings wallets to various DeFi, NFT, prediction market, and airdrop websites. Keep only funds intended for recent use in the daily interaction wallet. Even if the frontend or authorizations have problems, the scope of impact is relatively limited.
  • Pay attention to the actual operation before signing, not just the webpage button: The webpage may say "Login," "Claim," or "Confirm Order," but this does not mean the signature popping up in the wallet is for the same action.
  • When anomalies appear on a webpage, do not rely on inertia to continue operations: If a page suddenly asks to re-import a seed phrase, download an additional plugin, or displays transaction content inconsistent with the webpage description, pause the interaction. Confirm the situation through the project's multiple official channels, and check or revoke historical authorizations no longer in use.

From the perspective of wallet products, this also means the role wallets undertake is changing.

It should not be just a tool for storing private keys and popping up signature windows. It also needs to help users understand transaction intent, identify abnormal authorizations, display asset changes as much as possible, and provide sufficiently clear warnings before high-risk interactions occur.

But wallets cannot eliminate all risks for users. A more realistic security model involves wallets, protocols, L2s, third-party service providers, and users working together to reduce the attack surface, rather than placing all responsibility on any single party.

Final Words

In the past, it was often said, "Whoever holds the private key holds the on-chain assets."

This statement still holds true, but it does not cover the entire process from "generating transaction intent" to "completing on-chain settlement" for user assets. Today, Web3 security is no longer just about protecting a set of seed words; it's about protecting the entire path from wallet key generation, transaction display, signature execution, to network verification and final settlement.

Of course, this does not mean users need to stay away from all on-chain interactions. For users, truly effective security habits mean separating asset purposes, risk levels, and interaction scenarios for management: long-term assets emphasize isolation, daily interactions use small amounts, unfamiliar DApps get low authorization, and high-risk operations require more verification.

After all, when security risks expand from a single point to an entire chain, a user's defense must also upgrade from simply protecting a private key to a comprehensive set of habits.

For us all to reflect upon.

Tiền kỹ thuật số thịnh hành

Câu hỏi Liên quan

QWhat was the significance of the SecondFi wallet security incident in June?

AThe SecondFi wallet incident demonstrated that security risks can exist beyond just protecting the private key. The flaw was in the wallet's underlying signature implementation, specifically an error in deriving the signature nonce from public transaction messages without the required secret nonce prefix. This meant that every time a user signed a transaction with the affected wallet version, the public signature data exposed enough information for an attacker to potentially derive the address's private key, without needing to compromise the user's device or seed phrase.

QWhat are the key security concerns for users when interacting with Layer 2 (L2) networks?

AKey L2 security concerns go beyond just transaction costs. Users must consider the entire trust chain, including the correctness and completeness of zero-knowledge proof circuit constraints, the security of trusted execution environment keys (like SGX), and the network's availability and recovery mechanisms. Incidents have shown that vulnerabilities can allow asset theft through state inconsistencies or fake proofs. Furthermore, network halts due to logic bugs impact availability. Users are advised to not store large amounts of assets on newer or smaller L2s, use official bridges, understand withdrawal mechanisms, and diversify assets across different chains and bridges.

QHow did the Polymarket incident illustrate the risks of third-party service or supply chain attacks?

AThe Polymarket incident showed that even if a DApp's core smart contracts are secure and users visit the correct website, their funds can be at risk through compromised third-party frontend dependencies. In this case, an attacker compromised a third-party service provider used by Polymarket and injected malicious scripts into the website's frontend for some users. This allowed the attacker to steal funds by manipulating the transaction approval process, highlighting that the security of the entire user interaction path—not just the contract—is critical.

QWhat practical security habits does the article recommend for ordinary Web3 users?

AThe article recommends several practical security habits: 1) Always download wallets from official sources and keep them updated. 2) Separate assets: use hardware wallets or independent cold wallets for large, long-term holdings, and use a separate hot wallet for daily DApp interactions with limited funds. 3) For compromised wallets, migrate assets to a completely new wallet/address, not just import the seed phrase elsewhere. 4) Use isolated DApp interaction wallets to limit exposure. 5) Carefully review transaction details in the wallet pop-up before signing, not just the website button. 6) Pause and verify if a website behaves abnormally. 7) Diversify assets across different L2s and bridges.

QHow has the role of a wallet evolved according to the article's perspective on Web3 security?

AThe article argues that a wallet's role is evolving beyond just a tool for storing private keys and signing transactions. To address expanded security boundaries, wallets now need to actively help users understand transaction intent, identify abnormal authorization requests, display asset changes clearly, and provide clear warnings before high-risk interactions. However, wallets cannot eliminate all risks alone. A more realistic security model requires collaboration between wallets, protocols, L2 networks, third-party service providers, and users to collectively reduce the attack surface.

Nội dung Liên quan

Vụ ly hôn của Choi Tae-won chính thức kết thúc: Tiết lộ tuyến kế thừa ẩn sau đế chế nghìn tỷ SK Hynix

Vào tháng 11/2024, trong một sự kiện kỷ niệm, Chủ tịch SK Group Choi Tae-won đã cho các con xem hình ảnh AI tái hiện người cha quá cố của mình, nhấn mạnh về việc kế thừa di sản. Trong bối cảnh SK Hynix trở thành tài sản trị giá nhất Hàn Quốc, câu chuyện kế thừa thế hệ thứ ba của tập đoàn này lại không đi theo kịch bản truyền thống. Choi Yun-jung (sinh 1989), trưởng nữ, được coi là ứng viên kế thừa rõ ràng nhất. Cô có nền tảng học thuật về sinh học, từng làm tư vấn, hiện đang học tiến sĩ và giữ chức vụ lãnh đạo tại SK Bioscience và bộ phận hỗ trợ tăng trưởng của SK Inc. Cuộc hôn nhân của cô với một doanh nhân khởi nghiệp AI cũng phản ánh sự thay đổi trong các mối liên kết giữa các giới tinh hoa. Choi Min-jung (sinh 1991), con gái thứ, có hành trình khác biệt: học đại học tại Bắc Kinh, tình nguyện gia nhập Hải quân Hàn Quốc và từng làm việc tại SK Hynix ở Washington về các vấn đề chính sách quốc tế. Cô hiện là nhà sáng lập một công ty chăm sóc sức khỏe AI và kết hôn với một cựu sĩ quan Thủy quân Lục chiến Mỹ, cho thấy mạng lưới toàn cầu và an ninh chuỗi cung ứng ngày càng quan trọng đối với các tập đoàn bán dẫn. Choi In-geun (sinh 1995), con trai trưởng, có lộ trình học vấn tương đồng với cha (vật lý) và đang làm việc tại McKinsey sau thời gian ở SK E&S. Dù mang hình mẫu người kế thừa truyền thống, anh lại là người ít lộ diện công khai nhất. Cuộc chiến ly hôn kéo dài giữa Choi Tae-won và vợ cũ Roh So-young, với giá trị tài sản tranh chấp lên tới hàng nghìn tỷ won, là bối cảnh phức tạp mà thế hệ thứ ba phải đối mặt. Cả ba người con đều đã đệ đơn lên tòa án trong vụ việc này, dù nội dung không được tiết lộ. Tóm lại, trong kỷ nguyên AI khi SK Hynix trở thành tài sản địa chính trị toàn cầu, việc kế thừa tại SK Group không còn là chuyện nội bộ gia đình hay chỉ xoay quanh cổ phần và quyền trưởng nam. Thế hệ thứ ba được định vị thông qua năng lực chuyên môn, mạng lưới quốc tế và khả năng giải quyết những thách thức của thời đại công nghệ và địa chính trị mới.

marsbit14 giờ trước

Vụ ly hôn của Choi Tae-won chính thức kết thúc: Tiết lộ tuyến kế thừa ẩn sau đế chế nghìn tỷ SK Hynix

marsbit14 giờ trước

Các ngân hàng phản đối thỏa thuận lợi suất stablecoin – Liệu Đạo luật CLARITY có thể giành được 60 phiếu?

Viện Chính sách Ngân hàng Hoa Kỳ (BPI) đã phản đối dự thảo Đạo luật CLARITY mới, chỉ ra những thiếu sót về quy định lợi suất stablecoin và chống tài trợ bất hợp pháp. Ngành ngân hàng muốn cấm hoàn toàn mọi hình thức khuyến khích từ stablecoin, trong khi dự thảo hiện tại chỉ cho phép dựa trên hoạt động tài khoản, không phải số dư nhàn rỗi. Sự phản đối này ảnh hưởng đến cơ hội thông qua đạo luật tại Thượng viện, nơi cần 60 phiếu. Sự ủng hộ từ đảng Cộng hòa có thể giảm xuống còn 49 phiếu nếu các Thượng nghị sĩ John Curtis và John Cornyn rút lại hỗ trợ, đòi hỏi 11 phiếu từ đảng Dân chủ. Tuy nhiên, một số nhà lập pháp Dân chủ ủng hộ tiền mã hóa cũng phản đối dự luật do lo ngại về đạo đức và chống rửa tiền. Lãnh đạo đa số Thượng viện John Thune tỏ ra hoài nghi về khả năng thông qua dự luật trước kỳ nghỉ tháng Tám, chỉ còn hai tuần. Cố vấn trưởng về Tiền mã hóa của Nhà Trắng, Patrick Witt, kêu gọi tiến hành bỏ phiếu ngay. Kỳ vọng thị trường về việc thông qua đạo luật trong năm 2026 đã giảm xuống còn 32%.

ambcrypto14 giờ trước

Các ngân hàng phản đối thỏa thuận lợi suất stablecoin – Liệu Đạo luật CLARITY có thể giành được 60 phiếu?

ambcrypto14 giờ trước

Giá trị gia tăng từ 88 tỷ lên 680 tỷ chỉ sau 2 tháng! OpenRouter, trạm trung chuyển AI lớn nhất sắp được mua lại

Theo tờ Wall Street Journal và The Information, Stripe - nền tảng thanh toán hàng đầu - đang đàm phán mua lại startup AI OpenRouter với giá khoảng 10 tỷ USD. Chỉ hai tháng trước, định giá của OpenRouter là 1,3 tỷ USD, tức giá chào mua cao hơn gần 7 lần. Thương vụ có thể được công bố trong vòng một tháng nhưng vẫn có nguy cơ đổ vỡ. OpenRouter hoạt động như một "trung tâm chuyển tiếp" AI, cung cấp một API duy nhất để các nhà phát triển truy cập vào hơn 400 mô hình lớn (như GPT, Claude). Nó tự động lựa chọn mô hình phù hợp dựa trên độ phức tạp, chi phí và tốc độ, giúp các ứng dụng AI tối ưu hóa hiệu quả chi phí. Được đồng sáng lập bởi Alex Atallah (cựu đồng sáng lập OpenSea), OpenRouter hiện có hơn 1 triệu nhà phát triển và doanh thu hàng năm đạt 50 triệu USD, tăng gấp 5 lần trong nửa năm. Đây là bước đi chiến lược tiếp theo của Stripe trong việc mở rộng sang hạ tầng AI, sau khi họ mua lại nền tảng định giá theo lượng sử dụng Metronome vào cuối năm 2025. Mục tiêu của Stripe là kết hợp khả năng định tuyến mô hình của OpenRouter với hệ thống thanh toán và đo lường sử dụng hiện có, để trở thành "trung tâm điều phối và thu ngân" toàn diện cho nền kinh tế AI. Điều này cho phép doanh nghiệp quản lý toàn bộ việc sử dụng và hóa đơn AI qua một nhà cung cấp duy nhất.

链捕手14 giờ trước

Giá trị gia tăng từ 88 tỷ lên 680 tỷ chỉ sau 2 tháng! OpenRouter, trạm trung chuyển AI lớn nhất sắp được mua lại

链捕手14 giờ trước

Từ OpenSea Đến OpenRouter: Kịch Bản “Chốt Lời Đỉnh Cao” Của Alex Atallah Lại Lặp Lại?

Tác giả: Nancy, PANews Hơn bốn năm trước, Alex Atallah rời đi trước đỉnh bong bóng NFT; giờ đây, anh lại tỏa sáng trong cơn sốt AI và chuẩn bị bán nền tảng tổng hợp mô hình AI OpenRouter với giá cao. Ngày 23/7, theo Wall Street Journal, gã khổng lồ thanh toán Stripe đang đàm phán mua lại OpenRouter, với định giá giao dịch có thể lên tới gần 100 tỷ USD. Nếu thành công, đây sẽ là lần thứ hai Alex Atallah xây dựng một công ty trị giá hàng trăm tỷ USD, sau sàn giao dịch NFT OpenSea. OpenRouter, được mô tả là "Stripe của lĩnh vực AI", đã kết nối hơn 400 mô hình AI, có khoảng 10 triệu người dùng và xử lý hơn 200 nghìn tỷ token mỗi tháng. Tuy nhiên, mô hình kinh doanh chủ yếu dựa vào phí dịch vụ nền tảng (5%-5.5%) từ việc gọi API, với doanh thu hàng năm khoảng 50 triệu USD (tính đến tháng 4/2026). Đây là một mô hình kênh dẫn có quy mô lớn nhưng biên lợi nhuận hạn chế, dễ bị ảnh hưởng bởi sự cạnh tranh, mô hình nguồn mở và áp lực giảm giá. Giá trị thực sự của OpenRouter đối với các nhà mua tiềm năng như Stripe có thể nằm ở kho dữ liệu sử dụng AI thực tế khổng lồ mà nó tích lũy được, cung cấp insights quý giá về hiệu suất mô hình, sở thích nhà phát triển và quan hệ thay thế trên thị trường. Từ NFT đến AI, Alex Atallah hai lần bắt đúng xu hướng thời đại. Việc OpenRouter được định giá 100 tỷ USD đặt ra câu hỏi: đây là sự định giá lại giá trị cơ sở hạ tầng AI hay một tín hiệu đỉnh chu kỳ mới? Thời gian sẽ trả lời.

链捕手14 giờ trước

Từ OpenSea Đến OpenRouter: Kịch Bản “Chốt Lời Đỉnh Cao” Của Alex Atallah Lại Lặp Lại?

链捕手14 giờ trước

Pons V2 mang đến các cặp giao dịch RWA khi Robinhood Chain mở rộng tham vọng

Pons, một launchpad được xây dựng trên Robinhood Chain, đã ra mắt bản nâng cấp V2 với các thay đổi nhằm cải thiện thanh khoản, loại bỏ hạn chế giao dịch và hỗ trợ tài sản thực được mã hóa (RWA). Bản cập nhật này diễn ra trong bối cảnh Robinhood Chain tiếp tục tăng trưởng nhanh, vượt 300 triệu USD tổng giá trị bị khóa và nổi lên như một trong những mạng Lớp 2 Ethereum sôi động nhất cho giao dịch đầu cơ. Pons V2 giải quyết các phàn nàn chính của người dùng về thanh khoản bằng cách giới thiệu đường cong liên kết định danh bằng ETH, đồng thời cho phép hầu hết ví giao dịch tự do. Cấu trúc phí cũng được thiết kế lại để nhà phát triển có thể nhận phí bằng ETH mặc định. Robinhood Chain đã thu hút sự chú ý của thị trường, với khối lượng DEX tích lũy vượt 9 tỷ USD, trong đó 80% đến từ memecoin rủi ro cao. Tuy nhiên, lợi nhuận tập trung vào số ít, với 63% nhà giao dịch thua lỗ. Việc Pons V2 bổ sung các cặp giao dịch RWA tùy chỉnh trực tiếp hỗ trợ trọng tâm phát triển tài sản thực của Robinhood Chain, có thể thúc đẩy việc áp dụng mạng lưới một cách hữu cơ trong tương lai.

ambcrypto15 giờ trước

Pons V2 mang đến các cặp giao dịch RWA khi Robinhood Chain mở rộng tham vọng

ambcrypto15 giờ trước

Giao dịch

Giao ngay

Bài viết Nổi bật

Làm thế nào để Mua AR

Chào mừng bạn đến với HTX.com! Chúng tôi đã làm cho mua Arweave (AR) trở nên đơn giản và thuận tiện. Làm theo hướng dẫn từng bước của chúng tôi để bắt đầu hành trình tiền kỹ thuật số của bạn.Bước 1: Tạo Tài khoản HTX của BạnSử dụng email hoặc số điện thoại của bạn để đăng ký tài khoản miễn phí trên HTX. Trải nghiệm hành trình đăng ký không rắc rối và mở khóa tất cả tính năng. Nhận Tài khoản của tôiBước 2: Truy cập Mua Crypto và Chọn Phương thức Thanh toán của BạnThẻ Tín dụng/Ghi nợ: Sử dụng Visa hoặc Mastercard của bạn để mua Arweave (AR) ngay lập tức.Số dư: Sử dụng tiền từ số dư tài khoản HTX của bạn để giao dịch liền mạch.Bên thứ ba: Chúng tôi đã thêm những phương thức thanh toán phổ biến như Google Pay và Apple Pay để nâng cao sự tiện lợi.P2P: Giao dịch trực tiếp với người dùng khác trên HTX.Thị trường mua bán phi tập trung (OTC): Chúng tôi cung cấp những dịch vụ được thiết kế riêng và tỷ giá hối đoái cạnh tranh cho nhà giao dịch.Bước 3: Lưu trữ Arweave (AR) của BạnSau khi mua Arweave (AR), lưu trữ trong tài khoản HTX của bạn. Ngoài ra, bạn có thể gửi đi nơi khác qua chuyển khoản blockchain hoặc sử dụng để giao dịch những tiền kỹ thuật số khác.Bước 4: Giao dịch Arweave (AR)Giao dịch Arweave (AR) dễ dàng trên thị trường giao ngay của HTX. Chỉ cần truy cập vào tài khoản của bạn, chọn cặp giao dịch, thực hiện giao dịch và theo dõi trong thời gian thực. Chúng tôi cung cấp trải nghiệm thân thiện với người dùng cho cả người mới bắt đầu và người giao dịch dày dạn kinh nghiệm.

Tổng lượt xem 686Xuất bản vào 2024.12.11Cập nhật vào 2026.06.02

Làm thế nào để Mua AR

Thảo luận

Chào mừng đến với Cộng đồng HTX. Tại đây, bạn có thể được thông báo về những phát triển nền tảng mới nhất và có quyền truy cập vào thông tin chuyên sâu về thị trường. Ý kiến ​​của người dùng về giá của AR (AR) được trình bày dưới đây.

活动图片