一文了解12月因黑客攻击、钓鱼诈骗和Rug Pull造成的总损失

币圈资讯 阅读:40 2024-04-22 11:12:22 评论:0
美化布局示例

欧易(OKX)最新版本

【遇到注册下载问题请加文章最下面的客服微信】永久享受返佣20%手续费!

APP下载   全球官网 大陆官网

币安(Binance)最新版本

币安交易所app【遇到注册下载问题请加文章最下面的客服微信】永久享受返佣20%手续费!

APP下载   官网地址

火币HTX最新版本

火币老牌交易所【遇到注册下载问题请加文章最下面的客服微信】永久享受返佣20%手续费!

APP下载   官网地址

又到了每月安全盘点时刻!据区块链安全审计公司Beosin旗下Beosin EagleEye安全风险监控、预警与阻断平台监测显示,2023年12月,各类安全事件损失金额较11月大幅下降。12月发生较典型安全事件超『21』起,因黑客攻击、钓鱼诈骗和Rug Pull造成的总损失金额约2494万美元,较11月下降约93%。其中攻击事件约1245万美元,钓鱼诈骗事件约960万美元,Rug Pull事件约289万美元。

本月没有发生损失金额超过千万美元的大型黑客攻击事件。本月发生了两起影响范围较大的安全事件:Web3开发平台Thirdweb安全漏洞影响多份智能合约;Web3项目常用的代码库Ledger Connect Kit 遭受供应链攻击。所幸这两起事件造成的损失金额均未超过百万美元。此外,本月钓鱼诈骗事件依旧不减,发生多起单个地址被盗百万美元以上的事件,用户还需提高警惕。

黑客攻击方面 

共发生『12』起典型安全事件

No.1 12月5日,Web3 开发平台Thirdweb存在安全漏洞,影响多份智能合约,至少3个项目因漏洞影响被攻击,损失约21万美元。

No.2 12月6日,DeFi协议BEARNDAO遭攻击,攻击者获利超70万美元。

No.3 12月10日,DeFi协议Venus Protocol遭到因预言机问题遭到攻击,损失约20万美元。

No.4 12月12日,OKX废弃的DEX做市商合约管理权限被盗,损失约270万美元。

No.5 12月14日,Web3项目常用的代码库Ledger Connect Kit 遭受供应链攻击,攻击者获利约60万美元。

No.6 12月17日,NFT Trader遭到重入漏洞攻击,损失约300万美元,盗取资产已被攻击者归还,攻击者保留了10%作为赏金。

No.7 12月17日,NFT交易市场Flooring Protocol遭到黑客攻击,损失约160万美元。

No.8 12月22日,DeFi协议Transit Finance遭到黑客攻击,损失约11万美元。

No.9 12月23日,DEX项目Paraluni遭到价格操控攻击,损失约33万美元。

No.10 Osmosis区块链上永续交易协议Levana Protocol在12月13日至26日期间遭到攻击,损失超过110万美元。

No.11 12月26日,Telcoin钱包遭到攻击,损失约120万美元。

No.12 12月30日,BSC 上的 Channels Finance 受到黑客攻击,损失超过 32 万美元。

钓鱼诈骗/Rug Pull方面 

共发生『4』起典型安全事件

No.1 12月5日,BNB Chain上CKD代币发生rug pull,部署者获利约54万美元。

No.2 12月26日,MegabotETH 发生rug pull,部署者获利约74万美元。

No.3 12月26日,两名受害者因网络钓鱼诈骗损失约150余万美元的资产。

No.4 12月29日,一个以0xea696开头的地址因网络钓鱼诈骗损失了价值440万美元的LINK代币。

加密犯罪/案件监管方面

共发生『5』起典型安全事件

No.1 12月5日消息,河南检察院披露大型虚拟货币传销案,涉案金额超 1.2 亿人民币。

No.2 12月6日消息,加密交易所Bitzlato联创承认7亿美元洗钱罪。

No.3 12月10日消息,香港警方破获通过虚拟货币洗钱 3000 万港元的犯罪团伙。

No.4 12月13日消息,美国司法部指控两名男子经营2500万美元的加密庞氏骗局。

No.5 12月15日消息,美国司法部披露四人因加密货币诈骗和洗钱被指控,造成超8000万美元损失。

鉴于当前区块链安全领域的新形势,『Beosin』在此总结:

从总体上看,2023年12月各类区块链安全事件损失金额较11月大幅下降。和11月相比,本月被攻击的项目类型新增了开发工具、代码库、NFT等,这表明黑客正在扩大其攻击目标范围,整个Web3生态都应加强安全意识以积极应对这一趋势。本月仍然有50%的攻击事件来自合约漏洞利用,如重入漏洞等,建议项目方在上线前一定要寻找专业的公司进行安全审计。


It's time for the monthly security inventory. According to the monitoring of the security risk monitoring, early warning and blocking platform under the blockchain security audit company, the loss amount of various security incidents in June dropped sharply compared with that in the previous month. Typical security incidents occurred in the previous month, and the total loss amount was about 10,000 US dollars, including about 10,000 US dollars in attacks and about 10,000 US dollars in phishing scams. There was no major hacker attack with a loss amount exceeding 10 million US dollars this month. There have been two security incidents that have a large impact. The security vulnerability of the development platform has affected many smart contracts. The commonly used code base of the development platform has been attacked by the supply chain. Fortunately, the losses caused by these two incidents have not exceeded one million dollars. In addition, there have been many incidents of phishing fraud this month, and users need to be vigilant against hacking attacks. There have been typical security incidents in the development platform every month, and security vulnerabilities have affected at least one smart contract. The vulnerability affected the attack and the loss was about USD 10,000. The attacker made a profit of more than USD 10,000. The agreement was attacked due to the problem of Oracle, and the loss was about USD 10,000. The abandoned market maker's contract management authority was stolen, and the loss was about USD 10,000. The code base commonly used in the project was attacked by the supply chain, and the attacker made a profit of USD 10,000. The attacker was re-entered into the vulnerability attack and lost about USD 10,000. The stolen assets were returned by the attacker as a reward. The market was hacked and lost about. $10,000-month-day agreement was hacked and lost about $10,000-month-day project was attacked by price manipulation and lost about $10,000-month-day transaction agreement in blockchain was attacked and lost more than $10,000-month-day wallet was attacked and lost about $10,000-month-day-day-day-day-day-day-day-day-day-day-day-day-day-day-day-day- Fishing fraud lost about $10,000 in assets. An address with the beginning of it lost $10,000 in tokens due to phishing fraud. A typical security incident occurred in the supervision of criminal cases. The news of Henan Procuratorate revealed that the amount involved in a large-scale virtual currency pyramid scheme exceeded RMB 100 million. The news of encryption exchange jointly created a confession of the crime of $100 million in money laundering. The news of Hong Kong police cracked a criminal gang that laundered HK$ 10,000 through virtual currency. The news of the US Department of Justice accused two men. The US Department of Justice disclosed that four people were accused of cryptocurrency fraud and money laundering, resulting in losses of more than $10,000. In view of the current new situation in the field of blockchain security, this paper summarizes that, on the whole, the amount of losses caused by various blockchain security incidents in October decreased significantly compared with that in the previous month, and the types of projects attacked this month increased the code base of development tools, which shows that hackers are expanding their attack targets, and the whole ecology should strengthen security awareness to actively deal with this. Trend: There are still some attacks this month from the exploitation of contract vulnerabilities, such as re-entry vulnerabilities. It is suggested that the project party must find a professional company to conduct a security audit before going online. 比特币今日价格行情网_okx交易所app_永续合约_比特币怎么买卖交易_虚拟币交易所平台

文字格式和图片示例

注册有任何问题请添加 微信:MVIP619 拉你进入群

弹窗与图片大小一致 文章转载注明 网址:https://netpsp.com/?id=61952

美化布局示例

欧易(OKX)最新版本

【遇到注册下载问题请加文章最下面的客服微信】永久享受返佣20%手续费!

APP下载   全球官网 大陆官网

币安(Binance)最新版本

币安交易所app【遇到注册下载问题请加文章最下面的客服微信】永久享受返佣20%手续费!

APP下载   官网地址

火币HTX最新版本

火币老牌交易所【遇到注册下载问题请加文章最下面的客服微信】永久享受返佣20%手续费!

APP下载   官网地址
可以去百度分享获取分享代码输入这里。
声明

1.本站遵循行业规范,任何转载的稿件都会明确标注作者和来源;2.本站的原创文章,请转载时务必注明文章作者和来源,不尊重原创的行为我们将追究责任;3.作者投稿可能会经我们编辑修改或补充。

发表评论
平台列表
美化布局示例

欧易(OKX)

  全球官网 大陆官网

币安(Binance)

  官网

火币(HTX)

  官网

Gate.io

  官网

Bitget

  官网

deepcoin

  官网
关注我们

若遇到问题,加微信客服---清歌

搜索
排行榜
扫一扫,加我为微信好友加我为微信好友