Hackers steal $25 million worth of cryptocurrency from Uniswap and Lendf.me

栏目: IT技术 · 发布时间: 5年前

内容简介:Hackers have stolen more than $25 million in cryptocurrency from the Uniswap exchange and the Lendf.me lending platform.The attacks took place over the weekend, on Saturday and Sunday, respectively. Although an investigation is currently underway, the two

Hackers have stolen more than $25 million in cryptocurrency from the Uniswap exchange and the Lendf.me lending platform.

The attacks took place over the weekend, on Saturday and Sunday, respectively. Although an investigation is currently underway, the two attacks are believed to be related, and most likely carried out by the same group or individual.

According to investigators, hackers appear to have chained together bugs and legitimate features from different blockchain technologies to orchestrate a sophisticated "reentrancy attack."

Reentrancy attacks allow hackers to withdraw funds repeatedly, in a loop, before the original transaction is approved or declined.

The similarities between Uniswap and Lendf.me is that both platforms were using:

  • Lendf.me protocol -- a decentralized finance (DeFi) protocol developed by the dForce Foundation to support lending operations on the Ethereum platform.
  • imBTC -- a token (coin) that runs on the Ethereum platform and is valued at a 1:1 rate with the Bitcoin cryptocurrency.
  • ERC-777 -- one of the underlying technologies of the Ethereum blockchain meant to support smart contracts (both Lendf.me and imBTC run as smart contracts on the Ethereum platform).

"The ERC-777 token standard has - to our knowledge - no security vulnerabilities," said Tokenlon, the company behind imBTC.

"However, the combination of using ERC777 tokens and Uniswap/Lendf.Me contracts enables [...] reentrancy attacks," the company wrote in a post-mortem report of the Uniswap and Lendf.me attacks.

The company believes the hackers used an exploit published in July 2019 on GitHub by OpenZeppelin, a company that performs security audits for cryptocurrency platforms.

At the time of writing, Uniswap is believed to have lost between $300,000 and $1.1 million in funds, while Lendf.me lost more than $24.5 million.

The hackers used the reentrancy attack to siphon funds from each platform into their wallet, and then immediately transfer the funds to other accounts.

Both websites have been taken down to prevent further attacks. Tokenlon has also suspended its imBTC token and is blocking all new transactions to prevent the hackers from carrying out new attacks against other platforms.


以上就是本文的全部内容,希望本文的内容对大家的学习或者工作能带来一定的帮助,也希望大家多多支持 码农网

查看所有标签

猜你喜欢:

本站部分资源来源于网络,本站转载出于传递更多信息之目的,版权归原作者或者来源机构所有,如转载稿涉及版权问题,请联系我们

React开发实战

React开发实战

[美] Cássio de Sousa Antonio / 杜伟、柴晓伟、涂曙光 / 清华大学出版社 / 2017-3-1 / 58.00 元

介绍如何成功构建日益复杂的前端应用程序与接口,深入分析 React库,并详述React生态系统中的其他工具与库,从而指导你创建完整的复杂应用程序。 你将全面学习React的用法以及React生态系统中的其他工具和库(如React Router和Flux 架构),并了解采用组合方式创建接口的佳实践。本书简明扼要地讲解每个主题,并呈现助你高效完成工作的细节。书中严谨深刻地讲述React中重要的功......一起来看看 《React开发实战》 这本书的介绍吧!

CSS 压缩/解压工具
CSS 压缩/解压工具

在线压缩/解压 CSS 代码

随机密码生成器
随机密码生成器

多种字符组合密码

Markdown 在线编辑器
Markdown 在线编辑器

Markdown 在线编辑器