发布: 2024/07/20 20:00 阅读: 807
WazirX Responds to Massive Crypto Hack
WazirX 应对大规模加密货币黑客攻击
After suffering a major cyberattack that cost investors approximately $235 million on Thursday, India-based cryptocurrency exchange WazirX has swiftly initiated measures to mitigate the damage and recover the stolen funds.
周四,印度加密货币交易所 WazirX 遭受重大网络攻击,造成投资者损失约 2.35 亿美元,随后迅速采取措施减轻损失并追回被盗资金。
Legal Action Underway
正在进行法律诉讼
WazirX has filed a police complaint and reported the incident to the Financial Intelligence Unit (FIU) and CERT-In, India's Computer Emergency Response Team. The exchange stated:
WazirX 已向警方提出投诉,并向金融情报机构 (FIU) 和印度计算机应急响应小组 CERT-In 报告了这一事件。该交易所表示:
"In response to the cyber attack, we have filed a police complaint and are pursuing additional legal actions. We will keep the community updated as we proceed."
“为了应对网络攻击,我们已向警方提出投诉,并正在采取其他法律行动。我们将在处理过程中向社区通报最新情况。”
Collaboration and Recovery Efforts
协作和恢复工作
The exchange has reached out to over 500 other crypto exchanges, requesting them to blacklist the addresses associated with the exploit.
该交易所已联系其他 500 多家加密货币交易所,要求他们将与该漏洞相关的地址列入黑名单。
Specifically, the following tokens were stolen:
具体来说,以下代币被盗:
WazirX is actively coordinating with these exchanges to identify additional resources for recovering the stolen funds and assisting affected customers.
SHIB(9600 万美元)ETH(5200 万美元)MATIC(1100 万美元)PEPE(760 万美元)WazirX 正在积极与这些交易所协调,以寻找更多资源来追回被盗资金并帮助受影响的客户。
Investigation and Forensic Analysis
调查和取证分析
WazirX's immediate priorities include tracing the stolen assets, recovering customer funds, and conducting a thorough investigation into the cyber attack. The exchange is partnering with forensic experts and law enforcement agencies to identify and apprehend the perpetrators.
WazirX 的当务之急包括追踪被盗资产、追回客户资金以及对网络攻击进行彻底调查。该交易所正在与法医专家和执法机构合作,以查明并逮捕肇事者。
Additional Smart Contracts Exploited
额外的智能合约被利用
WazirX has identified two additional smart contracts that were exploited during the incident and is diligently examining the circumstances.
WazirX 已经确定了事件期间被利用的另外两个智能合约,并正在认真检查情况。
Protecting User Funds
保护用户资金
The exchange has established a secure website where customers can revoke all transaction approvals to safeguard their funds. However, WazirX emphasizes that users' funds remain at risk until they take this action.
该交易所建立了一个安全网站,客户可以在其中撤销所有交易批准以保护其资金。然而,WazirX 强调,在用户采取这一行动之前,他们的资金仍面临风险。
Multisig Wallet Vulnerability
多重签名钱包漏洞
According to WazirX's report, the cyber attack targeted one of its multisig wallets, which had been using Liminal's digital asset custody and wallet infrastructure since February 2023. The wallet configuration involved six signatories, five from WazirX and one from Liminal, who were responsible for approving transactions.
根据 WazirX 的报告,网络攻击针对的是其一个多重签名钱包,该钱包自 2023 年 2 月以来一直在使用 Liminal 的数字资产托管和钱包基础设施。钱包配置涉及 6 个签名者,其中 5 个来自 WazirX,1 个来自 Liminal,他们负责批准交易。
The exchange believes that the breach resulted from a discrepancy between the information displayed on Liminal's interface and the actual transaction content. During the attack, the payload was manipulated to grant the attacker control of the wallet, allowing them to exploit the vulnerability.
该交易所认为,此次违规是由于Liminal界面显示的信息与实际交易内容存在差异造成的。在攻击过程中,有效负载被操纵以授予攻击者对钱包的控制权,从而使他们能够利用该漏洞。