South Korean Exchange Upbit Suspends Curve (CRV) Deposits And Withdrawals Following Exploit

Bitcoinist发布于2023-08-01更新于2023-08-01

文章摘要

In light of the recent security breach that affected Curve Finance’s CRV token, South Korean-based cryptocurrency exchange Upbit has announced...

In light of the recent security breach that affected Curve Finance’s CRV token, South Korean-based cryptocurrency exchange Upbit has announced a temporary suspension of deposits and withdrawals for the token. 
Upbit Advises Caution Amid Volatility
Upbit’s precautionary suspension of all CRV deposits and withdrawals occurred after a reentrancy attack on the Curve Finance platform. The vulnerability was discovered during the weekend, leading to a significant loss of funds.
A reentrancy attack is a security breach that causes a potential loss of funds from uninterrupted contract calls. Major outflows were recorded as a result of interactions that manipulated the reentrancy vulnerability in certain  Vyper compiler versions. In a tweet released by Vyper, specific versions of Vyper, such as 0.2.15, 0.2.16, and 0.3.0, were vulnerable to malfunctioning reentrancy locks. 
In response to the attacks, Upbit released a volatility warning advising their customers “…to be mindful of the increased price volatility of CRV.” The platform called for caution, asking users to conduct due diligence while considering any investment connected to the token. To ensure safety, the platform noted that it would temporarily suspend its CRV deposit and withdrawals. 
Following the attack, other cryptocurrency exchanges, like OKX, issued warnings to customers. According to details obtained from its landing page, OKX advised users to be cautious of the risks involved while trading the token, as OKX “will not be held responsible for any trading losses.” 
Users Of Binance Exchange Unaffected
With news of the attack making rounds, the Chief Executive Officer of Binance, Changpeng Zhao, has come out to state that Binance is unaffected. According to details obtained from his X (formerly Twitter) account, he stated that “CEX price feed saves DeFi. Binance users are not affected. Our team checked on the Vyper Reentrant Vulnerability. We only use version 0.3.7 or above.” 
He further noted that his platform’s usage of a centralized price feed for DeFi tokens offers an extra layer of security. The CEO stressed that it was vital for users to always stay up-to-date with code libraries, operating systems, and applications.
As a result of the attack, Curve Finance released a statement noting that the incident affected particular stable pools, such as msETH, pETH, and aIETH via Vyper 0.2.15. However, its USD/CRV stablecoin pools were largely unaffected but the wider implication of the exploit worries users. 
Meanwhile, Curve DAO’s CRV token has experienced a sharp fall. The price has fallen by over 12% on daily charts, with a market cap of $557 million, according to data from CoinGeko.

Curve (CRV) price chart from Tradingview.com


CRV price struggles at $0.62 following exploit | Source: CRVUSD on Tradingview.com

你可能也喜欢

2026年6月六大加密预售项目

加密货币预售是项目在公开上市前,以预定价格向投资者出售代币的早期募资方式。2026年6月值得关注的六个预售项目如下: 1. **Nexchain**:一个完全由AI构建的区块链生态系统,结合了权益证明机制与创新的混合共识NEX AI,以确保持续性能与灵活性。其原生代币$NEX用于支持网络安全和激励参与。 2. **Mirex**:致力于将现实世界资产代币化,让用户能在MRX-20区块链上透明地使用代币化资产功能。其原生实用代币$MRX用于支付燃气费、执行智能合约等。 3. **Flozy**:基于Base链的社区驱动型迷因币$FLZY,融合了迷因文化传播力与实际效用,提供固定奖励质押和社区空投,总量固定为10亿枚。 4. **SurgeXRP**:一个代币化房地产市场,允许投资者通过区块链代币购买租赁房产的部分所有权,并按比例获得被动租金收益。其原生代币$SGP正处于预售阶段。 5. **Blockchain FX**:一个连接去中心化金融与传统金融市场的新型加密货币交易所,提供超过500种资产交易,目前已进入预售最后阶段,募资额超过1400万美元。 6. **Poly Truth**:一个AI驱动的分析与研究平台,作为去中心化预测市场的研究层,为用户提供体育、政治、加密货币价格等预测事件的概率分析。其原生代币$PTRUE支持多种加密货币购买。 预售是加密生态的重要组成部分,使用户有机会早期参与新项目。投资者在决策前应充分进行独立研究。

ambcrypto1小时前

2026年6月六大加密预售项目

ambcrypto1小时前

第三方服务商遭入侵引发300万美元钓鱼攻击,Polymarket承诺赔付受影响的用户

预测市场平台Polymarket表示,在因第三方供应商遭入侵导致其前端被植入恶意代码后,将全额赔偿受影响的用户。此次事件引发了一场网络钓鱼攻击,区块链安全研究人员估计损失近**300万美元**。 Polymarket在**6月25日**发布的声明中称,已于当日发现供应商遭入侵,并迅速移除了受影响的依赖项,控制了事态。公司表示正在联系受影响的用户并承诺全额退款。此次事件似乎仅影响了在攻击期间与受感染前端交互的用户,平台底层智能合约未受影响。 据分析,攻击源于一家遭入侵的第三方供应商,其在平台前端部分注入了恶意脚本。Polymarket尚未公开涉事供应商身份或发布详细的技术分析报告。 区块链安全公司PeckShield指出,这起事件疑似针对Polymarket用户的钓鱼活动。攻击者从超过**11个受害钱包**中盗取了价值约**300万美元的PUSD**,随后将被盗资金从Polygon桥接至以太坊,并兑换为约**1,893 ETH**,最终整合至一个被监控的地址。Polymarket未公开确认具体损失金额或受影响钱包数量。 与许多用户需自行承担损失的钓鱼事件不同,Polymarket承诺对所有受攻击影响的用户进行赔偿。公司表示正在直接联系受影响用户并继续调查此次入侵事件,但未提供赔偿流程或完整事件报告发布的具体时间表。

ambcrypto1小时前

第三方服务商遭入侵引发300万美元钓鱼攻击,Polymarket承诺赔付受影响的用户

ambcrypto1小时前

XRP周线RSI显示超卖信号,交易员紧盯1.10美元支撑位

XRP周线RSI指标显示超卖信号,交易员正密切关注1.10美元关键支撑位。在经历市场大幅回调后,XRP价格已进入一个被交易员拿来与先前周期底部条件相比较的深度超卖技术形态。当前焦点在于,这一位于关键支撑区域的技术设置,究竟会成为反弹信号,还是延续下跌的警示。 文章指出,在高时间框架图表上,极端的RSI读数能够显示卖压是否已过度延伸,但该指标本身衡量的是动量而非价值。对于XRP而言,当前技术层面的核心问题是:这一超卖状态反映的是市场抛售 capitulation,还是仅仅是一个弱势资产在弱市中的表现。答案将取决于买家能否守住支撑位,以及整个加密货币市场能否企稳。 XRP作为最受关注的大型山寨币之一,其技术形态容易快速吸引市场注意力,但也伴随着风险——如果比特币持续疲软,拥挤的反弹交易可能迅速瓦解。目前,RSI信号最好被解读为一个警告,表明XRP正处于一个重要的决策点。它并不保证底部已经形成,但暗示了价格在支撑位附近的下一步动向,或将决定未来一段时间的交易情绪。 最终,市场方向并非由单一头条决定。当前市场正同时应对流动性减弱、政策监管趋严、机构产品推出以及高波动性代币再度承压等多重因素。因此,最稳妥的解读方式是避免将此视为确定的价格催化剂,而应关注其对市场参与者、建设者和观察下一阶段加密货币采用的投资者所带来的实际影响。

bitcoinist1小时前

XRP周线RSI显示超卖信号,交易员紧盯1.10美元支撑位

bitcoinist1小时前

交易

现货
合约
活动图片