headphones
1inch 黑客获取赏金后归还大部分资金
链捕手
链捕手
authIcon
加密之眼
2025-03-09 09:09
Follow

作者:疯狂的数字币

据 Decurity 安全团队报道,1inch 协议于 2025 年 3 月 5 日下午 5 点(UTC 时间)遭遇一次严重的 DeFi 攻击事件,黑客利用旧版 1inch Settlement 合约中的回调选项漏洞获取资金。 漏洞源于订单后缀处理中的数据损坏问题,攻击者能够覆盖解析器地址并调用任意解析器,导致做市商 TrustedVolumes 资金损失。根据 Decurity 团队分析,该漏洞存在于 2022 年 11 月从 Solidity 重写为 Yul 的代码中,尽管经过多家安全团队审计,但该漏洞仍在系统中存在超过两年。 事件发生后,攻击者通过链上消息询问"我能获得赏金吗?",随后与受害方 TrustedVolumes 进行协商。谈判成功后,攻击者于 3 月 5 日晚间开始归还资金,最终在 3 月 6 日凌晨 4:12(UTC 时间)归还了除赏金外的全部资金。 Decurity 作为 Fusion V1 审计团队之一,对此事件进行了内部调查,并总结了几点教训,包括明确威胁模型和审计范围、对审计期间变更的代码要求额外时间、验证已部署合约等。
Open App for Full Article
DisclaimerThis website, hyperlinks, related apps, forums, blogs, media accounts, and other platforms' content are all sourced from third-party platforms and users. CoinWorldNet makes no guarantees about the website or its content. All blockchain data and other materials are for educational and research purposes only and do not constitute investment, legal, or other advice. Users of the CoinWorldNet and third-party platforms are solely responsible for the content they post, which is unrelated to CoinWorldNet. CoinWorldNet is not liable for any loss arising from the use of this website's information. You should use the data and content cautiously and bear all associated risks. It is strongly recommended that you independently research, review, analyze, and verify the content.
Comments(2)
Popular
Latest
bjw500828
2025-03-09 09:22
Reply
0
bjw956205
2025-03-09 10:11
Reply
0
edit
comment
collection
like
share