cryptd.in

另类 LinkedIn 适合加密人才

奇偶校验黑客卷土重来,在闲置 7 年后用以太坊洗钱 $9M

According to reports from Cyvers Alerts, the hacker who stole 150,000 ETH from the Parity Multisig Wallet version 1.5 in 2017 has resurfaced, moving stolen Ethereum worth $9 million to cryptocurrency exchange eXch.

The hacker still has control over 83,017 ETH, amounting to $246.6 million stolen during the 2017 incident.

$9M Worth of Ethereum Laundered

A post from X by Cyvers Alerts acknowledges the hacker’s notable patience, marking a significant event in cryptocurrency history. They commenced the laundering of 3,050 ETH, equivalent to $9M, through eXch, employing various consolidated addresses.

ALERT In 2017, a vulnerability in Parity Multisig Wallet version 1.5+ led to the theft of over 150K ETH, valued at approximately $30M USD at the time.

The hacker behind this theft has demonstrated remarkable patience, marking a significant chapter in crypto history. Today,… pic.twitter.com/JPD5nJcmrJ

— Cyvers Alerts (@CyversAlerts) May 13, 2024

The original incident, dating back to July 2017, was caused by a bug identified in a multi-signature contract named wallet.sol, which affected the v1.5 or later versions of Parity’s wallet software.

The hacker found a programmer-introduced bug that allowed them to re-initialize the wallet, effectively restoring it to factory settings. This vulnerability allowed the bad actor to gain control of victims’ wallets with a single transaction.

The incident led to unauthorized access and the theft of over 150,000 ETH, valued at $30 million at the time but now worth $442 million at current prices.

Parity Technologies, the company behind the affected wallet, classified the bug’s severity as “critical” and issued public statements advising users with funds in multi-sig wallets to transfer their assets to secure addresses.

However, white hat hackers managed to recover 377,000 ETH that were potentially at risk due to the same vulnerability, providing some relief to affected users.

Analysts Advocate for Robust Coding Standards

Analysts from OpenZeppelin, a blockchain infrastructure platform, provided insights into the possible steps that could have prevented the attack. They emphasized the importance of avoiding the use of certain coding methods, such as the “delegatecall” function, which functioned as a universal forwarding mechanism.

They also emphasized the importance of following robust coding standards within the Ethereum ecosystem, cautioning that overlooking such protocols could result in severe consequences, even from bugs that seem minor.

Parity Technologies, known for its involvement in developing the Polkadot blockchain and Ethereum’s Parity client, develops multi-signature wallets like Parity.

These wallets, designed as smart contracts, enable the management of cryptocurrency assets through a collective agreement among multiple owners. They offer features such as daily withdrawal limits, voting mechanisms, and ownership changes.

职位 奇偶校验黑客卷土重来,在闲置 7 年后用以太坊洗钱 $9M 首次出现在 加密土豆.


评论

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注

最新信息

热门类别

搜索网站

热门故事

标签

#AlexeyPertsev (1) #BidenCryptoBan (1) #BidenElection (1) #BinanceVsCoinbase (1) #Bitcoin (377) #BitcoinETF (3) #itcoinFundamentals (1) # 比特币处理 (1) # 比特币价格 (5) # 比特币价格水平 (1) #BitcoinPump (1) #BitcoinReserve (1) #BitcoinSurge (1) #itcoinTop (1) #Bitfinex (1) #Bitwise (1) #BracebridgeCapital (1) #BRC20Tokens (1) #BTC 收购 (1) 1TP5 看涨预测 (1) #BullishSentiment (1) #C 中国矿业 (1) #CPIPreview (1) #CryptoAsset (2) #CryptoBattle (1) #CryptoBoom (1) #CryptoExpert (1) #CryptoInsights (1) #CryptoMania (1) #CryptoMarket (4) #CryptoPrediction (1) #CryptoPredictions (1) #CryptoRegulation (2) #CryptoTakeoff (1) #CryptoTiming (1) #CryptoTips (1) #CryptoTreasury (1) #CryptoUncertainty (1) #DerivativeJump (1) #Dogecoin (65) #ogecoinGains (1) #ogecoinVolume (1) #DutchCourt (2) #ECommerce (1) #El萨尔瓦多比特币 (1) #E以太坊 (64) #EthereumPain (1) #E以太坊价格 (1) #ExpertOpinion (1) #FedRateCut (1) #FiatCurrency (1) #F 财务影响 (1) #F 财务隐私 (1) #FirmShutdown (1) #FrozenAccounts (1) #IllicitFunds (1) #InflationData (1) #Investment (1) #InvestmentLoss (1) #JapaneseFirm (1) #L LegalAction (1) #L 法律影响 (1) #Legislation (1) #LightningNetwork (1) #M 市场分析 (3) #M 市场监测 (1) #M 市场预测 (1) #M 市场预测 (1) #M 市场投影 (1) #M 市场支持 (1) #M 市场波动性 (1) #M 婚姻 (1) #MemeCoin (5) #MemeCoins (2) #Miner 盈利能力 (1) #M 洗钱 (2) #MtGox (3) #朝鲜加密货币 (1) #诺沃格拉茨预测 (1) 1TP5价格里程碑 (1) #P 价格预测 (2) 1TP5价格问题 (1) #PriceSurge (1) #PrisonSentence (1) # 量化分析 (1) #R 监管压力 (1) #SECA Anti-Crypto (1) #ShibaInu (5) #SocialBuzz (1) #T 技术分析 (1) #Toncoin (3) #T 龙卷风现金 (3) #T 龙卷风现金发展项目 (1) #T 龙卷风现金开发者 (1) #UKCrypto (1) #UpsidePotential (1) #USCongress (1) #WyomingLand (1) #XRPPrice (1) #XRPupswing (1)

实用链接

我发现了一些有用的链接,希望与大家分享。