快·讯

事件详情 · f3c1c2a0-7c19-4058-a32b-967d3d856d4e

NEAR Intents HOT Bridge Treasury exploited for ~$3.87M

treenews 加密货币公司事件
原文 · SOURCE RECORDS
treenews 10-02 06:20:53 Twitter 此为最新版 · 另有 1 个早前版本
原文 · 977 字符(点击折叠)

GoPlus Security 🚦 (@GoPlusSecurity): 🚨 GoPlus Security Alert: @near_intents HOT Bridge Treasury (BSC hot wallet) was exploited for ~$3.87M. Team committed to making users whole. Root cause: a bug in the Omni deposit/withdrawal infra when it interacts with the NEAR Intents contracts. Early assessment points to a withdrawal authorization bypass. Exploit isolated to NEAR Intents and the Omni/HOT Bridge deposit/withdrawal stack — not NEAR Protocol mainnet contracts, not an L1 compromise. Contract-side vuln is patched. Omni-side fix still underway. Victim: 0x233c5370CCfb3cD7409d9A3fb98ab94dE94Cb4Cd Attacker: 0x09fd1f5d9f185067a92493e43aa259ea4ab3ad37 Flow: BSC hot wallet → fast CEX routing through KuCoin → bridged to BTC. ZachXBT follow-up: attacker address interacted with a Lazarus-labeled address (0x098B7…E2f96). Classic DPRK laundering pattern — speed-run into a CEX, then flip to BTC. NEAR Intents has not confirmed attribution. DPRK ties remain unconfirmed.

源站原文 ↗
译文 · CHINESE

GoPlus Security Alert: @near_intents HOT Bridge Treasury(BSC热钱包)遭攻击,损失约$3.87M。团队承诺使用户完整无损。根本原因:Omni存款/取款基础设施与NEAR Intents合约交互时存在一个漏洞。早期评估指向取款授权绕过。攻击仅限于NEAR Intents和Omni/HOT Bridge存款/取款堆栈——不是NEAR Protocol主网合约,不是L1受损。合约侧漏洞已修补。Omni侧修复仍在进行中。受害者:0x233c5370CCfb3cD7409d9A3fb98ab94dE94Cb4Cd。攻击者:0x09fd1f5d9f185067a92493e43aa259ea4ab3ad37。流程:BSC热钱包 → 通过KuCoin快速CEX路由 → 桥接到BTC。ZachXBT后续:攻击者地址与一个标记为Lazarus的地址(0x098B7…E2f96)交互。典型的DPRK洗钱模式——快速进入CEX,然后转为BTC。NEAR Intents尚未确认归因。DPRK关联仍未确认。@near_intents:今天早些时候,在检测到安全事件后,NEAR Intents服务被停止。该事件是由Omni存款和取款基础设施与NEAR Intents智能合约交互时的漏洞引起的。初步报告显示总损失约为$3.8M。这些资...

摘要 · AI SUMMARY

NEAR Intents的HOT Bridge Treasury(BSC热钱包)遭攻击,损失约$3.87M,团队承诺全额赔付。根因是Omni存取款基础设施与NEAR Intents合约交互时的提款授权绕过漏洞,已修补合约端,Omni端修复中。攻击者将资金经KuCoin快速转入BTC,且与Lazarus标签地址有交互,但NEAR Intents未确认与朝鲜有关。

以上为 AI 摘要;完整原文请经由源站链接查阅。

← 返回资讯流