cryptd.in

암호화폐 친화적인 인재를 위한 대체 링크드인

Crypto Hackers Drain Over $36M From Protocols Using Unverified Contracts

A crypto hacker who drained $26 million from Ethereum-based protocol Truebit in January had likely practiced the technique on smaller targets first, according to blockchain analytics firm Chainalysis.

A Contract Left Exposed For Years

The Truebit exploit was the largest of four incidents Chainalysis identified in a new 보고 covering the past six months. Together, those attacks — targeting Truebit, Trusted Volumes, Aperture Finance, and Ekubo — account for roughly $37 million in losses, all traced back to contracts whose source code had never been publicly verified on blockchain explorers.

The Truebit contract had been sitting on 이더리움 since 2021. It was compiled using Solidity v0.5.3, a version released before automatic overflow protections became standard. An attacker found an integer overflow flaw inside its bonding curve mechanism and used it to mint large quantities of tokens at minimal cost before converting them to ETH.

Why Closed Code Creates Open Risk

Verified contracts get reviewed. Bug bounty hunters read them. Independent researchers flag problems before attackers do. Unverified contracts get none of that scrutiny, and many bug bounty programs specifically exclude them from coverage — meaning vulnerabilities can sit untouched for years while millions of dollars flow through the affected code.

That gap is what Chainalysis says attackers are now exploiting. Each of the four compromised contracts lacked publicly available source code. Attackers worked instead from decompiled bytecode, converting raw on-chain code into readable output using tools like Dedaub, Heimdall, and Panoramix.

Once decompiled, the code can be fed into AI systems capable of spotting reentrancy flaws, arithmetic errors, and access-control weaknesses at a scale no human reviewer could match.

The $36.7 million figure is a fraction of total DeFi losses during the same period — Chainalysis puts the broader six-month theft total above $1 billion. But the firm argues the unverified contract problem could grow as automated analysis tools become cheaper and easier to use, allowing attackers to scan large numbers of dormant contracts and rank them by exploitability.

The Vulnerabilities Varied, But The Pattern Did Not

Across the four incidents, the specific bugs differed. Reports indicate weaknesses ranged from integer overflow and access-control failures to input-validation errors and identity verification flaws.

What they shared was the same protection gap: no public source code, no external review, and no real-time monitoring in place to catch abnormal activity before the funds were gone.

Chainalysis is recommending that protocols treat source-code verification as a baseline requirement for any contract holding user assets.

The firm also says audits and bug bounty coverage should extend to implementation contracts sitting behind proxy structures — components that often go unreviewed even when the front-facing contract is verified.

Featured image from CybersecAsia, chart from TradingView


댓글

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다

최신 피드

인기 카테고리

웹사이트 검색

인기 스토리

태그

#AlexeyPertsev (1) #BidenCryptoBan (1) #BidenElection (1) #BinanceVsCoinbase (1) #B비트코인 (448) #BitcoinETF (3) #B비트코인기초 (1) #B비트코인 취급 (1) #B비트코인가격 (5) #B비트코인가격수준 (1) #B비트코인펌프 (1) #B비트코인예치 (1) #B비트코인서지 (1) #BitcoinTop (1) #Bitfinex (1) #B비트 단위 (1) #브레이스브리지캐피털 (1) #BRC20토큰 (1) #BTC취득 (1) #B울리스틱 예측 (1) #BullishSentiment (1) #C중국광업 (1) #CPIP리뷰 (1) #CryptoAsset (2) #CryptoBattle (1) #CryptoBoom (1) #CryptoExpert (1) #CryptoInsights (1) #CryptoMania (1) #CryptoMarket (4) #CryptoPrediction (1) #CryptoPredictions (1) #CryptoRegulation (2) #CryptoTakeoff (1) #CryptoTiming (1) #CryptoTips (1) #CryptoTreasury (1) #CryptoUncertainty (1) #DerivativeJump (1) #Dogecoin (74) #DogecoinGains (1) #DogecoinVolume (1) #DutchCourt (2) #ECommerce (1) 1TP5테엘살바도르비트코인 (1) 1TP5테더리움 (73) 1TP5테더리움통증 (1) 1TP5테더리움가격 (1) 1TP5전문가 의견 (1) #FedRateCut (1) #FiatCurrency (1) #FinancialImpact (1) #FinancialPrivacy (1) #FirmShutdown (1) #FrozenAccounts (1) #IllicitFunds (1) #인플레이션데이터 (1) #투자 (1) #투자손실 (1) #일본기업 (1) #LegalAction (1) #LegalImpact (1) #법률 (1) #라이트닝 네트워크 (1) 1TP5시장분석 (3) 1TP5시장 모니터링 (1) 1TP5시장 예측 (1) 1TP5시장 예측 (1) #MarketProjection (1) 1TP5마켓지원 (1) 1TP5시장변동성 (1) #M결혼 (1) #MemeCoin (5) #MemeCoins (2) #M광부수익성 (1) #MoneyLaundering (2) #MtGox (4) 1TP5북한암호화 (1) 1TP5노보그라츠예측 (1) #P가격 마일스톤 (1) #P가격 예측 (2) #P가격 질문 (1) #PriceSurge (1) #P형량 (1) #QuantAnalysis (1) 1TP5규제압력 (1) #SEC안티크립토 (1) #ShibaInu (6) #SocialBuzz (1) 1TP5기술분석 (1) #Toncoin (3) #TornadoCash (3) #TornadoCashDev (1) 1TP5토네이도캐시개발자 (1) #UKCrypto (1) #업사이드 잠재력 (1) #USCongress (1) #와이오밍랜드 (1) #XRP가격 (1) #XRP업스윙 (1)

유용한 링크

유용하다고 생각되어 공유하고 싶은 링크.