又见 durable nonce 这种离线预签名机制利用,这种钓鱼技巧流行至少 2 年了,被钓走这种签名后,攻击者可以在未来时机成熟时发起“签名合法”的链上操作,比如 Drift 这个场景是接管了其链上 admin 权限。 这次看去是专业黑客组织所为(至少行为上看,准备充分,手法老辣)。

Drift
@DriftProtocol
Earlier today, a malicious actor gained unauthorized access to Drift Protocol through a novel attack involving durable nonces, resulting in a rapid takeover of Drift’s Security Council administrative powers.
This was a highly sophisticated operation that appears to have involved
相关赛道:
来自推特
免责声明:以上内容仅为作者观点,不代表Followin的任何立场,不构成与Followin相关的任何投资建议。
喜欢
收藏
评论
分享
