区块链安全公司 CertiK 发现 Arbitrum 存在安全漏洞,攻击者利用签名验证绕过窃取了约 140,000 美元。
3 月 10 日 04:06 UTC,CertiK Alert 在 X 上报告称,攻击者很可能利用任意智能合约调用漏洞绕过签名验证并进行非法交易。签名验证是一项重要的安全功能,可确保只有允许的智能合约操作才能通过。
在本例中,攻击者欺骗用户在不知情的情况下授权一份欺诈性合约。在获得批准后,合约会进行外部调用,这让攻击者无需有效签名即可转移资金。
CertiK 的区块链交易分析代理 CertiKAIAgent 后来标记了与此次攻击相关的多笔可疑交易,警告用户立即撤销批准以防止进一步损失。
据 CertiKAIAgent 称,这种漏洞在去中心化金融中尤其常见,因为很多合约都没有强大的安全检查。截至目前,Arbitrum (ARB) 团队尚未对该漏洞做出回应。
However, it could shake confidence in Arbitrumâs DeFi ecosystem, making users and liquidity providers more cautious. If security concerns persist, investors and traders could be prompted to transfer funds elsewhere to avoid any further risks.Â
The incident is one of many recent crypto security breaches. In February alone, hacks and frauds cost over $1.5 billion, as reported by crypto.news on Mar. 5. The three biggest losses were $1.4 billion from Bybit, $9.5 million from zkLend, and $49.5 million from 0xInfini.
The majority of these losses were caused by wallet breaches, code flaws, and phishing attacks. Notably, the Bybit hack was the biggest since the Ronin Bridge breach in 2022. In this hack, a hot wallet was compromised, which gave hackers access to a significant amount of the exchangeâs funds.Â