BTC $79,169.02 -0.87%
ETH $2,491.17 -0.05%
BNB $739.46 -1.39%
XRP $1.39 -1.24%
SOL $103.83 -1.87%
TRX $0.3343 -0.29%
DOGE $0.0897 +0.46%
ADA $0.2191 -0.07%
BCH $260.41 +1.60%
LINK $12.74 +3.13%
HYPE $84.88 -2.80%
AAVE $131.77 -0.89%
SUI $0.8255 +3.88%
XLM $0.1899 +3.48%
ZEC $1,153.46 -5.85%
BTC $79,169.02 -0.87%
ETH $2,491.17 -0.05%
BNB $739.46 -1.39%
XRP $1.39 -1.24%
SOL $103.83 -1.87%
TRX $0.3343 -0.29%
DOGE $0.0897 +0.46%
ADA $0.2191 -0.07%
BCH $260.41 +1.60%
LINK $12.74 +3.13%
HYPE $84.88 -2.80%
AAVE $131.77 -0.89%
SUI $0.8255 +3.88%
XLM $0.1899 +3.48%
ZEC $1,153.46 -5.85%

thorchain

THORChain là một giao thức giao dịch AMM phi tập trung đa chuỗi, ban đầu được tạo ra bởi một nhóm các nhà phát triển tiền điện tử ẩn danh vào năm 2018 tại cuộc thi hackathon của Binance. Giao thức này nhằm mục đích phi tập trung hóa tính thanh khoản của tiền điện tử thông qua mạng lưới các nút công cộng và sản phẩm hệ sinh thái. Bất kỳ cá nhân, sản phẩm hoặc tổ chức nào cũng có thể truy cập tính thanh khoản địa phương và đa chuỗi của nó.
Tất cả
Bài viết
Tin nhanh

Galaxy Research: Kẻ tấn công Coldcard tiếp tục chuyển tiền, khoảng 45% tài sản bị đánh cắp đã vào các đường dẫn trộn hoặc chuỗi chéo

Galaxy Research đã công bố rằng, kẻ tấn công trong sự kiện tấn công "Wave 3" của Coldcard vẫn đang tiếp tục chuyển tiền bị đánh cắp. Trong giai đoạn này, kẻ tấn công đã tạo ra 293 kho lưu trữ đa chữ ký 2-of-2 cho từng nạn nhân. Lần chuyển tiền đầu tiên đã được thực hiện qua THORChain sang Ethereum; vòng chuyển tiền mới nhất đã bắt đầu vào quy trình CoinJoin.Hiện tại, kẻ tấn công Wave 3 đang xử lý số tiền lớn nhất theo thứ tự bị đánh cắp, đã chuyển tiền từ kho lưu trữ xếp hạng từ 1 đến 11. 10 kho lưu trữ tiếp theo chưa được chuyển tổng cộng nắm giữ 30.81 BTC, trong khi các kho lưu trữ xếp hạng từ 61 đến 293 tổng cộng nắm giữ 33.77 BTC. Đến thời điểm hiện tại, kẻ tấn công đã chuyển khoảng 45% tài sản bị đánh cắp trong lần khai thác này, tiền đã chảy vào Ethereum (qua THORChain) hoặc vào giao dịch CoinJoin. Ngoài ra, việc chuyển tiền này còn phát hiện một kho lưu trữ chưa từng biết đến trước đây: 58 địa chỉ đã chi tiêu chung theo cách đa chữ ký 2-of-2 với định dạng giống như Wave 3, và đã được kẻ tấn công Wave 3 chuyển vào một địa chỉ nhảy để cung cấp tiền cho CoinJoin.Nhóm phân tích trên chuỗi hiện đã đánh dấu kho lưu trữ này là "cause = open", nhưng cho rằng nó rất có thể cũng thuộc về nạn nhân của Coldcard, điều này có nghĩa là số lượng kho lưu trữ liên quan đến Wave 3 có thể tăng lên 294, và tổng số tiền bị đánh cắp từ lỗ hổng Coldcard được công bố trước đó có thể tăng lên khoảng 1806 BTC. Hiện tại, khoảng 82% BTC bị đánh cắp vẫn nằm trong địa chỉ mà kẻ tấn công ban đầu kiểm soát, khoảng 18% đã được chuyển đi, và dòng tiền cho thấy nó có thể đang được xử lý rửa tiền.

THORChain has released a recovery plan for the attack incident, and voting for node operators has begun

THORChain has released its fourth update regarding the attack incident on May 15, and the proposal ADR028 has been announced, with voting for node operators now open.According to the recovery plan, the protocol will first absorb losses through its own liquidity, with the remaining portion to be shared by synthetic asset holders; the specific distribution ratio of the two is still under evaluation. The protocol's own liquidity will be reduced to zero, and will be gradually replenished through system revenue. This plan will not issue or sell RUNE, nor will it dilute any holders.On the technical side, GG20 will be temporarily retained and has completed patch upgrades. Trading will resume after the vulnerabilities are fixed and node rotation is successfully conducted, with a future release pace that is slower and more security-conscious. Innocent nodes located in the same vault as the attacker will be protected, while the attacker nodes will be fully confiscated. The recovered RUNE will be paired with the recovered assets, and any excess will be destroyed.The protocol also offers a white hat bounty to the attacker to recover funds; if some are returned, the recovery plan will be adjusted proportionally. THORChain remains neutral and permissionless, and there will be no review of the attacker's Swap transactions after trading resumes. Node operators are currently voting on the proposal direction, and the numbers in the ADR are only indicative, with adjustments to be made through Mimir later.

Chainalysis tracks the source of the THORChain attack: skilled in money laundering, the attack was carried out weeks after cross-chain fund movements

Chainalysis posted on the X platform that before the theft of THORChain, wallets suspected to be associated with the attacker had been transferring funds through Monero, Hyperliquid, and THORChain for several weeks. The attacker-associated wallets had already deposited into Hyperliquid positions via the Hyperliquid and Monero privacy bridge as early as the end of April. The funds were then exchanged for USDC and transferred to Arbitrum, and later bridged to Ethereum, with some ETH subsequently transferred to THORChain to become staked RUNE for newly added nodes, which are believed to be the source of the attack.Afterward, the attacker bridged some RUNE back to Ethereum and split it into four pathways, one of which went directly to the attacker. After being transferred through intermediate wallets, 8 ETH was sent to the final wallet receiving the stolen funds 43 minutes before the attack. The funds from the other three pathways flowed in the opposite direction. These wallets bridged ETH back to Arbitrum, deposited it into Hyperliquid, and transferred it into Monero through the same privacy bridge, with the last transaction occurring less than 5 hours before the attack began.As of Friday afternoon, the stolen funds have not yet been used, but the attacker has demonstrated their skilled cross-chain money laundering capabilities, and the Hyperliquid to Monero path may become the next move.
app_icon
ChainCatcher Building the Web3 world with innovations.