Hacker bungles DeFi exploit: Leaves stolen $1M in contract set to self destruct

Cointelegraph發佈於 2022-04-22更新於 2022-04-22

文章摘要

In a rare comedic bungle among DeFi exploits, an attacker has fumbled their heist at the finish line leaving behind over $1 million in stolen crypto.

In a rare comedic bungle among DeFi exploits, an attacker has fumbled their heist at the finish line leaving behind over $1 million in stolen crypto.
Just after 8AM UTC on Thursday April 21st, blockchain security and analytics firm BlockSec shared it had detected an attack on a little known DeFi lending protocol called Zeed, which styles itself a “decentralized financial integrated ecosystem”.
The attacker exploited a vulnerability in the way the protocol distributes rewards, allowing them to mint extra tokens which were then sold, crashing the price to zero, but netting just over $1 million for the exploiter.
Blockchain analytics firm PeckShield noted the stolen crypto was transferred to an “attack contract”, a smart contract which automatically and quickly executes the found exploit.

However the attacker was apparently so excited by their successful heist that they forgot to transfer over $1 million worth of stolen crypto out of their attack contract before they set it to self-destruct, permanently and irreversibly ensuring the funds can never be moved.

Using a blockchain scanner to view the attack contract address shows that $1,041,237.57 worth of BSC-USD Binance-Peg token is forever stuck in the contract and the successful self-destruction of the contract was confirmed at 7:15AM UTC on April 21.
It's one of the more bizarre turns of events since the Polygon hacker did an “Ask Me Anything” using embedded messages on Ethereum(ETH) transactions after stealing $612 million from the protocol in August 2021. The question and answer session revealed the attacker hacked “for fun” and thought “cross-chain hacking is hot.”
This latest hack is on the smaller end regarding the amount stolen, and other DeFi protocol hacks have seen hundreds of millions siphoned off as with the recent Ronin bridge hack where attackers made off with over $600 million.
Other notable DeFi exploits include the $80 million worth of crypto stolen from Qubit Finance in January where attackers tricked the protocol into believing they had deposited collateral, allowing them to mint an asset representing a bridged crypto.
DeFi marketplace Deus Finance was exploited in March when hackers manipulated the price feed of a pair of stablecoins resulting in the insolvency of user funds, netting the hackers over $3 million.

你可能也喜歡

美国参议员敦促银行监管机构制定‘公平’的加密货币资本规则

美国参议员呼吁制定“公平”的加密资本规则。由参议院数字资产小组委员会主席辛西娅·卢米斯牵头,多名共和党参议员致信美联储、联邦存款保险公司(FDIC)及货币监理署(OCC)负责人,要求为银行从事加密资产活动建立更清晰、公平的资本框架。 信中批评了巴塞尔银行监管委员会现行的加密资产资本标准,该标准对加密资产施加了1250%的风险权重,参议员们认为这并非基于实际风险评估,而像是一种按资产类别“一刀切”的惩罚,实质上阻碍了银行持有此类资产,与监管机构倡导的“技术中立”原则相悖。 议员们赞赏了监管机构近期关于代币化证券的联合指引,该指引明确了此类资产应获得与其非代币化对应物同等的资本待遇。他们敦促监管机构将这一风险导向原则一致性地应用于其他数字资产,并基于近期在加密市场结构法案方面的进展,开始为银行的资产负债表加密资产活动制定新的资本框架。 与此同时,FDIC、OCC和美联储负责人近期在国会作证时,概述了其转向更“基于风险”的监管方向,旨在改革监管框架以提高效率,并审查过去的监管措施。他们强调,强有力的资本标准对保障银行体系韧性和支持经济增长至关重要,同时监管应促进而非阻碍负责任的创新。

bitcoinist25 分鐘前

美国参议员敦促银行监管机构制定‘公平’的加密货币资本规则

bitcoinist25 分鐘前

从以太坊到AI的“CROPS”:Vitalik反复强调的这套“慢变量”,究竟是什么?

以太坊创始人Vitalik Buterin近期频繁强调一个概念——CROPS,它代表抗审查性(Censorship Resistance)、抗捕获性(Capture Resistance)、开源(Open Source)、隐私(Privacy)和安全(Security)。这一理念源于以太坊基金会发布的指导文件,旨在确保用户在数字生活中不依赖单一平台、不丧失最终控制权。 随着AI技术深入钱包和自动化执行场景,CROPS的内涵超越了以太坊的原有范畴,成为AI时代用户能否掌控自身数字生活的关键问题。Vitalik指出,真正的“CROPS AI”应支持多种硬件平台,而不仅仅是“去中心化AI”。当AI成为用户的数字代理人,处理资产管理和链上操作时,确保其抗审查、开放、隐私和安全变得至关重要。 CROPS Ethereum与CROPS AI存在显著交集。例如,通过零知识证明实现付费远程大模型调用和私密以太坊RPC读取,旨在让用户在获取远程服务的同时避免暴露敏感信息。未来,可能出现更多针对以太坊场景微调的AI模型,用于提升智能合约和生态安全。 这一理念将深刻影响Web3生态,尤其是钱包等入口层产品。在市场关注短期热点的背景下,CROPS提醒我们关注那些决定长期方向的技术变量:在AI加速接管数字世界的时代,确保系统可理解、可验证、注重隐私和安全,才是以太坊持续价值的真正体现。

marsbit3 小時前

从以太坊到AI的“CROPS”:Vitalik反复强调的这套“慢变量”,究竟是什么?

marsbit3 小時前

交易

現貨
合約
活动图片