快·讯

事件详情 · efd62673-7dd3-41c1-a2ef-699ebb5fe87c

MultiversX: Supernova is live; attack bears hallmarks of Lazarus-level actors; industry enters era of permanent war

treenews 加密货币公司事件国际局势
原文 · SOURCE RECORDS
treenews 10-01 12:46:48 Twitter 此为最新版 · 另有 1 个早前版本
原文 · 3209 字符(点击折叠)

Beniamin Mincu |🇺🇸/acc (@beniaminmincu): A few quick notes (1) Supernova is live, running with remarkable speed and precision. (2) Over the next 5–10 days, global exchanges and other independent partners will begin reopening deposits and withdrawals. The rollout is gradual by design. Each exchange follows its own rigorous internal process, built to protect users and keep the recovery smooth. (3) An in-depth security analysis is still underway. Several critical elements are already mapped and understood, from the bugs and their fixes to the technical implications and the path to recovery. A few discussions with independent parties remain open. The findings are preliminary, but one stands out above the rest. The tools, methods, preparation, and coordination behind this attack appear to go well beyond those typically associated with amateur attackers. The observed sophistication bears the hallmarks of advanced, experienced, repeated threat actors, including groups operating at the level historically associated with hacker organizations such as Lazarus. Attribution is not yet confirmed, but it is worth stating this out loud: to have successfully defended our users against Lazarus, or another group of that caliber, is a milestone we are proud of! Huge respect to all independent partners, including global exchanges, who have mobilized with extraordinary speed for the greater good of protecting users and the network! (4) More importantly, the larger lesson goes beyond this incident. As an industry, we have entered an era of permanent, constant, unending war. Open-source financial infrastructure operates on a global battlefield, continuously exposed to increasingly sophisticated attackers, tools, and methods. Under these conditions, the traditional definition of security is no longer sufficient. Three capabilities are becoming non-negotiable: (a) a relentless defensive and offensive security tooling arms race; (b) continuous, 24/7 red-teaming and penetration testing; (c) blitz-speed detection, coordination, and response. We have been intensifying precisely these capabilities over the past 3–6 months. What happened over the last few days is one visible incident among several potential threats that have been identified, contained, or neutralized through increasingly proactive security work. This reality is not unique to MultiversX. Every major open-source stack, every blockchain (bitcoin and ethereum not excluded), and soon, every closed source software stack, will increasingly have to adapt to an environment where infrastructure is continuously and deeply probed, attacked, and tested. That requires a much more rugged approach to code. A more adversarial approach to architecture design. And ultimately, a fundamental rethinking of how safety-critical software is built and defended. The three measures above are critical today. But over time, we will need to go much further and rethink security from the ground up for the new world we are actually operating in. Verifiably correct-by-construction software is about to have its moment and become fashionable very quickly. Reality has a way of accelerating standards. Not so much by preference, but by necessity.

源站原文 ↗
译文 · CHINESE

(1)Supernova已上线,运行速度与精度均表现出色。 (2)未来5–10天内,全球交易所及其他独立合作伙伴将开始重新开放充值与提现。此次开放是渐进式设计。每家交易所都遵循其严格的内部流程,以保护用户并确保恢复过程平稳。 (3)深入的安全分析仍在进行中。多个关键要素已查明并理解,包括漏洞及其修复、技术影响及恢复路径。与独立方的若干讨论仍在进行。调查结果尚属初步,但其中一点尤为突出:此次攻击所使用的工具、方法、准备和协调水平,远超典型业余攻击者。观察到的复杂性具有高级、经验丰富、反复出现的威胁行为者的特征,包括历史上与Lazarus等黑客组织相当水平的团体。归属尚未确认,但值得公开说明:成功保护我们的用户免受Lazarus或同等级别团体的攻击,是我们引以为傲的里程碑!向所有独立合作伙伴(包括全球交易所)致以崇高敬意,他们以极速动员,为保护用户和网络利益而行动! (4)更重要的是,更大的教训超越此次事件。作为一个行业,我们已进入一个永久、持续、无休止的战争时代。开源金融基础设施在全球战场上运行,持续面临日益复杂的攻击者、工具和方法。在这种条件下,传统安全定义已不再足够。 三项能力正变得不可或缺: (a)持续不断的防御性和进攻性安全工具军备竞赛; (b)全天候24/7红队测试和渗透测试; (c)闪电般的检测、协调和响应速度。 过去3–6个月,我们一直在加强这些能力。过去几天发生的事情,只是通过日益主动的安全工作识别、遏制或消除的若干潜在威胁之一。 这一现实并非MultiversX独有。每个主要开源堆栈、每个区块链(包括比特币和以太坊),以及很快每个闭源软件堆栈,都将不得不适应基础设施被持续深度探测、攻击和测试的环境。这要求更坚固的代码方法,更具对抗性的架构设计,并最终从根本上重新思考安全关键软件的构建和防御方式。 上述三项措施今天至关重要。但随着时间的推移,我们需要走得更远,从零开始重新思考安全,以适应我们实际所处的新世界。可验证的正确构造软件即将迎来其时刻,并迅速成为潮流。现实总会加速标准,不是出于偏好,而是出于必要。

摘要 · AI SUMMARY

MultiversX的Supernova已上线,运行快速精准。未来5–10天内,全球交易所等独立合作伙伴将逐步重新开放充提,每个交易所遵循各自的内部流程。安全分析仍在进行,初步发现攻击工具、方法和协调水平远超业余攻击者,具有Lazarus等高级威胁组织特征,但归属尚未确认。行业已进入持续战争时代,传统安全定义不再足够,需加强攻防工具、7x24红队测试和快速检测响应能力。

以上为 AI 摘要;完整原文请经由源站链接查阅。

推断 · INTERPRETATION

MultiversX(EGLD)宣布Supernova已上线且运行良好,并计划在未来5至10天内由各交易所逐步重新开放充值与提现,表明攻击后的恢复进程正在推进。安全调查初步认定攻击者具有高水平、经验丰富的威胁行为者特征,或与Lazarus等组织相当,但归属尚未确认。事件凸显开源区块链基础设施面临持续性安全威胁,行业需强化安全军备竞赛、7×24小时红队测试和快速响应能力。该消息短期对EGLD及相关生态资产构成情绪修复与恢复预期,属偏正面信号;但调查尚未完结,开放进度和安全结论仍存不确定性。

影响:对MultiversX(EGLD)及生态内资产偏正面,因交易所逐步开放充提和恢复进展提振信心;对整体加密市场安全情绪亦有小幅支撑。

置信度 0.72 · 本栏为模型推断,非事实记录

← 返回资讯流