DeFi项目频繁被盗!欧科云链OKLink产品防范黑客引热议

资讯 2024-06-23 阅读:49 评论:0
  近日,去中心化金融(DeFi)因最近几个关键平台遭受的一系列攻击而陷入困境,有专业人士统计,总计约 7000 万美元被盗。In recent days, DeFi has been trapped by a series of rece...
美化布局示例

欧易(OKX)最新版本

【遇到注册下载问题请加文章最下面的客服微信】永久享受返佣20%手续费!

APP下载   全球官网 大陆官网

币安(Binance)最新版本

币安交易所app【遇到注册下载问题请加文章最下面的客服微信】永久享受返佣20%手续费!

APP下载   官网地址

火币HTX最新版本

火币老牌交易所【遇到注册下载问题请加文章最下面的客服微信】永久享受返佣20%手续费!

APP下载   官网地址

  近日,去中心化金融(DeFi)因最近几个关键平台遭受的一系列攻击而陷入困境,有专业人士统计,总计约 7000 万美元被盗。

In recent days, DeFi has been trapped by a series of recent attacks on several key platforms, with professional statistics totalling approximately $70 million stolen.

  其中,包括来自Curve Finance的盗窃、借贷协议 Alchemix、收益平台 Pendle 和合成资产工具 Metronome 以及去中心化 NFT 协议 JPEG 也都受到了打击。

Among them were thefts from Curve Finance, loan agreements, Alchemix, profit platform Pendle and synthetic asset tool Metronome, and decentralized NFT agreement JPEG.

  以Curve Finance为例,它是最常用、最有影响力的去中心化交易所之一,专注于稳定币和其他低波动性资产的交易。据悉,Curve Finance作为Vyper语言的使用者,其多个稳定币池遭到攻击并损失了约2500万美元。

In the case of Curve Finance, one of the most common and influential decentralized exchanges, it focuses on stabilizing currency and other low-volatile assets. As a Vyper-language user, Curve Finance is known to have been attacked and lost about $25 million in several stable currency pools.

  具体来看,7月30日,智能合约编程语言Vyper的部分版本被发现存在严重漏洞,包括CurveFinance在内的重要项目因此遭受了攻击,损失数千万美元,此次攻击事件为智能合约的安全性敲响了警钟。

Specifically, on 30 July, part of the version of the smart contract programming language, Vyper, was found to have been seriously flawed, as a result of which important projects, including CurveFinance, were attacked, with a loss of tens of millions of dollars, and the attack was a wake-up call for the security of the smart contract.

  本次漏洞源于Vyper语言版本0.2.15至0.3.0之间的重入锁机制失效。对于区块链项目来说,重入攻击(ReentrancyAttack)是智能合约领域的一个常见漏洞。它指的是合约函数可以在一个函数执行过程中,被同一合约的其他函数再次调用,如果合约逻辑不严密,就可能被利用进行重复提取资金等恶意操作。

This gap stems from the failure of the re-locking mechanism between the Vyper language version 0.2.15 and 0.3. For block chain projects, re-entry into attack (ReentrancyAtttack) is a common gap in the realm of smart contracts. It means that a contract function can be called again by other functions of the same contract during the execution of a function, and that if the contract is not well-structured, it may be used for malicious operations such as double withdrawals.

  举例来说,假设有一个智能合约提供了存款和取款的功能,取款函数的逻辑是先将用户的余额减去取款金额,然后将取款金额转给用户,如果用户是一个恶意合约,它可以在接收到转账时,再次调用取款函数,因为此时合约还没有更新用户的余额,所以可以重复取款,这样就可以将银行合约中的资金全部转走。

For example, assuming that an intelligent contract provides for deposit and withdrawal functions, the logic of the withdrawal function is to first deduct the balance of the user and then transfer the withdrawal amount to the user, who, if it is a malicious contract, can call the withdrawal function again at the time of receipt of the transfer, since the contract does not update the balance of the user at that time, so that the withdrawal can be repeated, so that all funds in the bank contract can be transferred.

  值得一提的是,Curve 不是第一次出现被黑客攻击的事件了,作为 Defi 的顶级项目都无法免疫黑客攻击,普通的项目方更应该在黑客攻击端和合约防守端重视起来。

It is worth mentioning that it was not the first time that Curve was hit by hackers, that none of the top projects in Defi was immune to hacker attacks, and that the ordinary ones should be more focused on both the hacking end and the contractual defense end.

  那么针对进攻端,项目方可以做哪些准备呢?OKLink 团队推荐项目方通过链上标签系统提前辨别有黑历史的钱包,阻止有过异常行为地址的交互。此次Curve 的其中一个攻击者的地址就有过不良记录曾被 OKLink 记录,其行为模式也一定程度上超出常理,有三日交易笔数过百。

So what can the project side do about the attack end? The OKLink team recommends that the project side identify the wallets with a black history in advance through the chain label system, preventing the interaction of an unusual behavioral address. One of Curve’s attackers has had a bad record of having been recorded by the OKLink, and his behavior is somewhat out of the ordinary.

  项目方又如何在防守端进行防御呢?重入攻击此类的安全事件一定还会发生,所以除了上述在攻防两端我们需要付出的努力外,项目方需要做好应急预案,当受到黑客攻击时能最及时的进行反应,减少项目方和用户的损失。

How can the project side defend itself at the defensive end? Security incidents like re-attacks must occur again, so, in addition to the efforts that we need to make at both ends of the offensive, the project side needs to be prepared to respond in the most timely manner in case of hacking, reducing the loss to the project side and users.

  Vyper贡献者也建议,对于 Vyper 此类公共产品我们应该加强公众激励,寻找关键漏洞。OKLink呼吁应该尽早建立起一套安全响应标准,让黑/灰地址的资金追踪变得更加容易。

Vyper contributors have also suggested that we should increase public incentives for Vyper’s public products and look for key loopholes. OKLink calls for an early set of safety response standards to make it easier to trace funds at black/hack addresses.

  正如 OKLink 产品在此类事件中的攻防两端起到防范黑客和追查资金的作用,项目方在搭建平台的安全模块时应考虑第三方技术服务商可以带来的额外价值,更快更好的筑起项目的安全堡垒。

Just as the prevention of OKLink products at both ends of such incidents acts as a shield against hacking and financial tracking, the project party should take into account the added value that third-party technical service providers can bring when building the platform's security module, and build the project's security forts faster and better.

  总的来说,欧科云链等安全公司的出现,代表区块链安全行业为执法机构提供了数智化侦破案件服务工具和应对新型技术犯罪的全流程的解决方案,相信未来,欧科云链等企业还将以技术赋能行业健康发展,为链上安全保驾护航。

In general, the emergence of security companies such as the Ocowin chain, representing the block chain security industry, has provided law enforcement agencies with a number of tools for intelligence-based case detection services and a full-process solution to new technological crimes, and it is believed that in the future, enterprises such as the Ocowin chain will also provide security for the chain with the healthy development of the technology-enabling industry.

  

美化布局示例

欧易(OKX)最新版本

【遇到注册下载问题请加文章最下面的客服微信】永久享受返佣20%手续费!

APP下载   全球官网 大陆官网

币安(Binance)最新版本

币安交易所app【遇到注册下载问题请加文章最下面的客服微信】永久享受返佣20%手续费!

APP下载   官网地址

火币HTX最新版本

火币老牌交易所【遇到注册下载问题请加文章最下面的客服微信】永久享受返佣20%手续费!

APP下载   官网地址
文字格式和图片示例

注册有任何问题请添加 微信:MVIP619 拉你进入群

弹窗与图片大小一致 文章转载注明

分享:

扫一扫在手机阅读、分享本文

发表评论
平台列表
美化布局示例

欧易(OKX)

  全球官网 大陆官网

币安(Binance)

  官网

火币(HTX)

  官网

Gate.io

  官网

Bitget

  官网

deepcoin

  官网
热门文章
  • DDO在新加坡上市真假,欧意交易所能交易数字期权吗?

    DDO在新加坡上市真假,欧意交易所能交易数字期权吗?
    然而,对于DDO在新加坡的列名是否真实存在争议。 据报道,有人质疑DDO的数字选项是否真的上市,其背景是否经过了彻底调查。 首先,有报告说,DDO数字选项清单仅仅是一种宣传手段,没有找到DDO交易的平台,这就对DDO的真正清单提出了疑问。 其次,一些媒体调查了DDO数字选项的背景。 报告显示DDO数字选项发行人声称其数字选项是国家赞助的,但实际上,根据中国人民银行,虚拟货币相关业务是非法金融活动。 此外,DDO数字选项在视频号码等平台上广为传播,吸引了许多信徒的注意,然...
  • Griffin Gaming Partners计划为其第三支基金筹集5亿美元

    Griffin Gaming Partners计划为其第三支基金筹集5亿美元
    Pitchbook引用的6月8日《快链头条新闻》作为监管文件, 指出游戏风险投资公司Griffin赌博伙伴计划为其第三个旗舰基金筹集5亿美元, 比第二个基金少33%。 2021年,格里芬赌博伙伴从Web3游戏开发者Forte获得A回合资金1.85亿美元,并于2022年筹集了第二个旗舰基金,金额达7.5亿美元,此时风险资本家对Web3和加密游戏的热情达到顶峰。...
  • 加密货币之王重回王位:比特币飙升至 71,000 美元,还能再涨多少?

    加密货币之王重回王位:比特币飙升至 71,000 美元,还能再涨多少?
    比特币是市场上最大的加密货币,它再次打破了重要的7万美元门槛。 在短短的四舍五入(67,000美元到69,000美元之间)之后,价格在这一水平上遇到了强烈的抵制。 然而,势头的不断增强表明,比特币可能形成一个超过70 000美元的板块,为重新测试下一个抵抗阵地71 300美元和3月份可能攀升到历史最高点73 700美元铺平了道路。 问题仍然是:比特币能否维持预期的上升趋势并继续大幅上升?    分析家预计比特币价格将上升到74,400美元。 加密货币分析师Ali M...
  • 比过山车还狠!比特币价格再次暴跌

    比过山车还狠!比特币价格再次暴跌
      上周日,比特币的价格创造了3000美元的历史新高,随后就开始各种高台跳水了。Last Sunday, the price of Bitcoin created a record high of $3,000, and then began to dive on all the high platforms.   据外媒报道,本周一,比特币价格一度下跌到2526.4美元,最高跌幅高达14.5%,这创造了2015年1月以来最大跌幅。According to external...
  • 几张图看懂区块链技术到底是什么?https://www.cnblogs.com/behindman/p/8873191.html

    几张图看懂区块链技术到底是什么?https://www.cnblogs.com/behindman/p/8873191.html
    “区块链”的概念可以说是异常火爆,好像互联网金融峰会上没人谈一谈区块链技术就out了,BAT以及各大银行还有什么金融机构都在开始自己的区块链研究工作,就连IBM最近也成立了自己的区块链研究实验室,但其实区块链到底是什么?大家或许并不清楚,停留在雾里看花的状态。从今天开始,就让我们一起走进区块链,揭开区块链的神秘面纱吧!The concept of a block chain can be described as an unusually hot one, as if no...
标签列表