跨链流动性协议 CrossCurve(原名 EYWA)确认其跨链桥因智能合约漏洞遭到攻击。攻击源于网关验证缺失,攻击者可伪造跨链消息并绕过校验,触发 PortalV2 合约的未授权代币解锁,导致约 300 万美元资金在多条链上被转出;安全分析显示,漏洞位于 ReceiverAxelar 合约,其 expressExecute 函数可被直接调用并注入伪造消息完成攻击。(The Block)
Risk and Disclaimer:The content shared by the author represents only their personal views and does not reflect the position of CoinWorldNet (币界网). CoinWorldNet does not guarantee the truthfulness, accuracy, or originality of the content. This article does not constitute an offer, solicitation, invitation, recommendation, or advice to buy or sell any investment products or make any investment decisions
Comments(1)
Popular
Latest
不错
02-02 06:10
Reply
0
edit
comment
collection
like
share