扫码下载
BTC $63,489.79 +1.90%
ETH $1,722.85 +1.99%
BNB $585.71 +2.51%
XRP $1.13 +2.24%
SOL $71.28 +4.41%
TRX $0.3222 +0.48%
DOGE $0.0840 +2.26%
ADA $0.1630 +2.12%
BCH $199.19 +3.05%
LINK $7.94 +1.51%
HYPE $70.36 +4.64%
AAVE $74.39 +2.97%
SUI $0.7176 +0.95%
XLM $0.2146 -2.16%
ZEC $471.10 +4.84%
BTC $63,489.79 +1.90%
ETH $1,722.85 +1.99%
BNB $585.71 +2.51%
XRP $1.13 +2.24%
SOL $71.28 +4.41%
TRX $0.3222 +0.48%
DOGE $0.0840 +2.26%
ADA $0.1630 +2.12%
BCH $199.19 +3.05%
LINK $7.94 +1.51%
HYPE $70.36 +4.64%
AAVE $74.39 +2.97%
SUI $0.7176 +0.95%
XLM $0.2146 -2.16%
ZEC $471.10 +4.84%

Ekubo Protocol 自定义扩展合约遭攻击,已损失约 140 万美元

2026-05-06 10:03:45
收藏

ChainCatcher 消息,据安全机构 Blockaid(@blockaid_)监测,Ekubo Protocol 在以太坊上的一个 v2 自定义扩展合约正遭受持续攻击,目前已损失约 140 万美元。

攻击根本原因在于该扩展的 IPayer.pay 回调未对参数来源进行有效限制,导致攻击者可控制 payer、token 及 amount 参数,进而任意转移已授权代币。Ekubo 核心协议用户不受影响,但曾授权该 v2 合约作为代币支出方的用户面临直接风险,Blockaid 建议相关用户立即撤销授权。

app_icon
ChainCatcher 与创新者共建Web3世界