Aptos 区块链被曝曾存在关键漏洞,700 亿美元资产曾面临系统性风险

链捕手
Jul 05

ChainCatcher 消息,据 CoinDesk 报道,区块链安全公司 Hexens 研究人员发现 Aptos 区块链 Move 虚拟机存在"过期缓存"类型混淆漏洞,攻击者仅需约 3000 美元服务器成本,即可在模拟环境中以近 90% 的成功率发起攻击,无需验证者权限或内部知识。

研究人员在模拟测试中运行约 20 次攻击,成功 17-18 次,并验证了对 LayerZero、Wormhole、USDC CCTP 等跨链协议管理权限的潜在控制能力。

Hexens 评估,该漏洞直接威胁 Aptos 链上 DeFi、稳定币及流动性质押等协议,涉及低个位数十亿美元资产;若通过跨链桥、稳定币铸造及中心化交易所等路径扩散,系统性风险敞口最高可达 700 亿美元。Aptos 团队于 2 月 25 日收到漏洞报告后数小时内完成修复并部署至主网,目前无用户资金受损。

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10