HypurrFi披露Aave V3早期版本“舍入误差”漏洞,已暂停XAUT0与UBTC市场新增借贷

AAVE10,07%

PANews 3月6日消息,HyperEVM原生去托管借贷协议HypurrFi在X平台发文表示,Aave V3 3.5之前版本存在“舍入误差”漏洞,在特定条件下攻击者可通过反复执行供应/提取及借贷/偿还循环操作提取底层代币。受影响市场为HypurrFi Pooled中的XAUT0与UBTC。目前用户资金不存在风险,为确保安全相关市场已暂停新的供应与借贷操作,提现与还款功能仍可正常使用,其余市场运行正常。HypurrFi补充表示,已通过内部监控系统迅速在链上发现该问题并及时冻结受影响市场,同时正与其他Aave部署方及安全研究人员协作处理,并邀请其他Aave分叉项目联系以获取更多安全信息。

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Articoli correlati

幣圈最瞎劫案?駭客鑄造10億鎂DOT幣,但只偷到23萬鎂

駭客利用 Hyperbridge 跨鏈橋漏洞鑄造10億枚 Polkadot (DOT) 代幣,名義價值超11.9億美元,但因流動性不足,最終僅套現約23.7萬美元。攻擊是因為智能合約未正確驗證訊息,讓駭客成功竊取管理權並鑄幣。事件突顯市場流動性在套利成功中的關鍵角色。

CryptoCity7h fa

Fake Ledger Live App Steals $9.5M From 50+ Users Across Multiple Blockchains

A fraudulent Ledger Live app on Apple's App Store stole $9.5 million from over 50 users by compromising wallet information. The incident, involving significant losses for major investors, raises concerns about App Store security, prompting discussions of a possible lawsuit against Apple.

GateNews9h fa

遭批凍結USDC速度太慢!Circle CEO:一定等法院命令才凍,拒絕私自凍結

Circle 執行長 Jeremy Allaire 表明,除非接獲法院命令或執法要求,否則公司不會主動凍結錢包位址。即便面臨駭客洗錢爭議與社群抨擊,Circle 仍堅持遵循法治原則營運。 Jeremy Allaire 確立 Circle 執法底線 ----------------------------- 在全球加密貨幣市場風起雲湧之際,穩定幣發行商 Circle 的執行長 Jeremy Allaire 於南韓首爾的一場記者會上,針對市場最敏感的「資產凍結」議題發表了明確立場。他指出,Circle 雖然擁有技術手段可以凍結特定錢包位址,但除非收到法院命令或執法部門的正式指示,否則公司不

CryptoCity10h fa

Attacker Exploiting Bridged Polkadot Vulnerability Transfers $269K to Tornado Cash

On April 15, Arkham reported that the attacker who exploited a Bridged Polkadot vulnerability transferred around $269,000 in stolen funds to Tornado Cash, complicating asset tracking.

GateNews11h fa

Bitcoin Developers Propose BIP 361 to Protect Against Quantum Computing Threats

Bitcoin developers have proposed BIP 361 to safeguard the network against quantum computer risks by freezing vulnerable addresses. The proposal includes a phased plan to transition users to quantum-safe wallets, but it has sparked debate on user control and security.

GateNews11h fa

Hackers Exploit Obsidian Plugin to Spread PHANTOMPULSE Trojan with Blockchain C2

Elastic Security Labs revealed that threat actors impersonated venture capital firms on LinkedIn and Telegram to deploy a Windows RAT named PHANTOMPULSE, using Obsidian note vaults for attacks, which Elastic Defend successfully blocked.

GateNews12h fa
Commento
0/400
Nessun commento