Rapport : Les contrats intelligents non vérifiés deviennent une nouvelle cible pour les attaquants, 36,7 millions de dollars volés en six mois

robot
Création du résumé en cours
Mars Finance information, according to a Chainalysis report, over the past six months, at least 36.7 million USD have been stolen from protocols with unverified source code, involving protocols such as Truebit, Trusted Volumes, Aperture Finance, and Ekubo. Attackers find vulnerabilities by decompiling the original bytecode. AI-assisted vulnerability development is accelerating this trend, as large language models can scale to identify vulnerability patterns. Chainalysis points out that unverified contracts lack community review and are often excluded from bug bounty programs. The barriers to AI decompilation and vulnerability analysis are rapidly decreasing, allowing attackers to systematically scan thousands of unverified contracts. Protocols should verify all contract code, audit deployed contracts, expand bug bounty coverage, and implement real-time on-chain monitoring. Every unverified contract is a potential target for automated scanning; relying solely on obfuscation as a security measure is no longer effective.
Voir l'original
Cette page peut inclure du contenu de tiers fourni à des fins d'information uniquement. Gate ne garantit ni l'exactitude ni la validité de ces contenus, n’endosse pas les opinions exprimées, et ne fournit aucun conseil financier ou professionnel à travers ces informations. Voir la section Avertissement pour plus de détails.
  • Récompense
  • Commentaire
  • Reposter
  • Partager
Commentaire
Ajouter un commentaire
Ajouter un commentaire
Aucun commentaire
  • Épinglé