快·讯

事件详情 · f953f860-0ae1-45a8-a8ce-937cf51bc31b

MultiversX: Supernova is live; attack bears hallmarks of Lazarus-level actors; industry enters era of permanent war

treenews 加密货币公司事件国际局势
原文 · SOURCE RECORDS
treenews 10-01 13:02:54 Twitter 此为最新版 · 另有 1 个早前版本
原文 · 3255 字符(点击折叠)

Beniamin Mincu |🇺🇸/acc (@beniaminmincu): A few quick notes (1) Network. Supernova is live, running with remarkable speed and precision. (2) Exchanges. Over the next 5–10 days, global exchanges and other independent partners will begin reopening deposits and withdrawals. The rollout is gradual by design. Each exchange follows its own rigorous internal process, built to protect users and keep the recovery smooth. (3) Security report. An in-depth security analysis is still underway. Several critical elements are already mapped and understood, from the bugs and their fixes to the technical implications and the path to recovery. A few discussions with independent parties remain open. The findings are preliminary, but one stands out above the rest. The tools, methods, preparation, and coordination behind this attack appear to go well beyond those typically associated with amateur attackers. The observed sophistication bears the hallmarks of advanced, experienced, repeated threat actors, including groups operating at the level historically associated with hacker organizations such as Lazarus. Attribution is not yet confirmed, but it is worth stating this out loud: to have successfully defended our users against Lazarus, or another group of that caliber, is a milestone we are proud of! Huge respect to all independent partners, including global exchanges, who have mobilized with extraordinary speed for the greater good of protecting users and the network! (4) Lessons. More importantly, the larger lesson goes beyond this incident. As an industry, we have entered an era of permanent, constant, unending war. Open-source financial infrastructure operates on a global battlefield, continuously exposed to increasingly sophisticated attackers, tools, and methods. Under these conditions, the traditional definition of security is no longer sufficient. Three capabilities are becoming non-negotiable: (a) a relentless defensive and offensive security tooling arms race; (b) continuous, 24/7 red-teaming and penetration testing; (c) blitz-speed detection, coordination, and response. We have been intensifying precisely these capabilities over the past 3–6 months. What happened over the last few days is one visible incident among several potential threats that have been identified, contained, or neutralized through increasingly proactive security work. This reality is not unique to MultiversX. Every major open-source stack, every blockchain (bitcoin and ethereum not excluded), and soon, every closed source software stack, will increasingly have to adapt to an environment where infrastructure is continuously and deeply probed, attacked, and tested. That requires a much more rugged approach to code. A more adversarial approach to architecture design. And ultimately, a fundamental rethinking of how safety-critical software is built and defended. The three measures above are critical today. But over time, we will need to go much further and rethink security from the ground up for the new world we are actually operating in. Verifiably correct-by-construction software is about to have its moment and become fashionable very quickly. Reality has a way of accelerating standards. Not so much by preference, but by necessity.

源站原文 ↗
译文 · CHINESE

(1)网络。Supernova已上线,运行速度与精度均表现卓越。 (2)交易所。未来5–10天内,全球交易所及其他独立合作伙伴将开始重新开放充值与提现。此次开放是渐进式设计。每家交易所都遵循其严格的内部流程,以保护用户并确保恢复过程平稳。 (3)安全报告。深入的安全分析仍在进行中。多个关键要素已得到梳理和理解,从漏洞及其修复到技术影响及恢复路径。与独立方的若干讨论仍在进行。调查结果尚属初步,但其中一点尤为突出。此次攻击所展现的工具、方法、准备和协调水平,远超一般业余攻击者的典型特征。观察到的复杂性具有高级、经验丰富、反复出现的威胁行为者的特征,包括历史上与Lazarus等黑客组织相关联的团体。归因尚未确认,但值得公开声明:成功保护我们的用户免受Lazarus或同等级别团体的攻击,是我们引以为傲的里程碑!向所有独立合作伙伴(包括全球交易所)致以崇高敬意,他们以非凡的速度动员起来,为保护用户和网络的安全而共同努力! (4)教训。更重要的是,更大的教训超越了此次事件。作为一个行业,我们已进入一个永久、持续、无休止的战争时代。开源金融基础设施在全球战场上运行,持续暴露于日益复杂的攻击者、工具和方法之下。在这种条件下,传统的安全定义已不再足够。 三项能力正变得不可或缺: (a)不懈的防御性和进攻性安全工具军备竞赛; (b)持续、24/7的红队演练和渗透测试; (c)闪电般的检测、协调和响应速度。 在过去3–6个月中,我们一直在加强这些能力。过去几天发生的事情,只是通过日益主动的安全工作所识别、遏制或消除的若干潜在威胁中的一个可见事件。 这一现实并非MultiversX独有。每个主要的开源堆栈、每条区块链(比特币和以太坊也不例外),以及很快每个闭源软件堆栈,都将不得不适应基础设施被持续、深度探测、攻击和测试的环境。这要求更坚固的代码方法,更具对抗性的架构设计,并最终从根本上重新思考安全关键软件的构建和防御方式。 上述三项措施在当下至关重要。但随着时间的推移,我们需要走得更远,从根本上重新思考安全,以适应我们实际所处的新世界。可验证的、构造即正确的软件即将迎来它的时刻,并迅速成为潮流。现实会加速标准的演进,这并非出于偏好,而是出于必然。

摘要 · AI SUMMARY

Supernova已上线,运行快速精准。未来5–10天内,全球交易所将逐步恢复充提。安全分析初步显示,攻击工具、方法和协调水平远超业余攻击者,具有Lazarus等高级威胁组织的特征,但归属尚未确认。行业已进入持续战争时代,需加强攻防工具、7天24小时红队测试和快速响应能力。

以上为 AI 摘要;完整原文请经由源站链接查阅。

推断 · INTERPRETATION

MultiversX团队披露其网络曾遭受高级别攻击,攻击手法与工具复杂度疑似与Lazarus等有国家背景的黑客组织相关,但归因尚未确认。事件暴露出开源区块链基础设施持续面临高级威胁的现状。目前Supernova网络已上线,交易所将在5-10天内渐进恢复充提,安全分析仍在进行。团队将安全视为长期军备竞赛,强调防御、红队演练和快速响应能力。整体看,事件是一次严重安全冲击,但恢复路径已明确,且未造成用户资产损失的最终确认。

影响:MultiversX代币(EGLD)及生态资产短期承压,恢复充提后有望企稳;事件可能引发对跨链桥和开源链安全性的整体担忧,拖累相关板块情绪。

置信度 0.65 · 本栏为模型推断,非事实记录

← 返回资讯流