Binance Square
#smartcontractsecurity

smartcontractsecurity

4,021 views
49 සාකච්ඡා කරමින්
SQUILL
·
--
පරිවර්තනය බලන්න
"Most traders think hacking smart contracts is a thing of the past. Not so fast. A white-hat hacker has just recovered $2M from a decade-old Hong Coin ICO smart contract exploit, forcing me to wonder how many more hidden vulnerabilities are waiting to be unearthed. #SmartContractSecurity #HackingRecovery #DeFi The signal is clear: old smart contracts are just as vulnerable to exploitation as freshly deployed ones. This revelation should send a shiver down the spine of every DeFi investor. The interpretation? This isn't a isolated incident. We've seen multiple instances of old contracts being taken down due to security breaches. With more protocols adopting new technologies daily, old code becomes a ticking time bomb. The watch list: keep a close eye on smart contracts older than 2017. If you're long on coins tied to legacy code, you might want to reconsider your position. Do you have a DeFi asset that might be hiding a ticking time bomb?"
"Most traders think hacking smart contracts is a thing of the past. Not so fast.

A white-hat hacker has just recovered $2M from a decade-old Hong Coin ICO smart contract exploit, forcing me to wonder how many more hidden vulnerabilities are waiting to be unearthed.

#SmartContractSecurity #HackingRecovery #DeFi

The signal is clear: old smart contracts are just as vulnerable to exploitation as freshly deployed ones. This revelation should send a shiver down the spine of every DeFi investor.

The interpretation? This isn't a isolated incident. We've seen multiple instances of old contracts being taken down due to security breaches. With more protocols adopting new technologies daily, old code becomes a ticking time bomb.

The watch list: keep a close eye on smart contracts older than 2017. If you're long on coins tied to legacy code, you might want to reconsider your position.

Do you have a DeFi asset that might be hiding a ticking time bomb?"
සත්යායනය කළ
පරිවර්තනය බලන්න
⚠️ MARKET ALERT !!! ĐỒNG SÁNG LẬP OPENZEPPELIN: TOÀN BỘ DEFI KHÔNG AN TOÀN 🔥 Manuel Aráoz — đồng sáng lập OpenZeppelin — tuyên bố ông tin rằng "toàn bộ DeFi đều không an toàn" do AI coding agents đã đạt khả năng siêu việt trong việc phát hiện lỗ hổng smart contract 🛠 Ông đã cá nhân khuyên bạn bè và gia đình rút hết vốn khỏi các vị thế DeFi 💰 OpenZeppelin là một trong những hãng bảo mật hàng đầu crypto, từng audit cho Aave, Compound, MakerDAO, Uniswap và nhiều dự án lớn 📊 Khi chính người trong ngành bảo mật lên tiếng cảnh báo, đây là tín hiệu không nên xem nhẹ. Tuy nhiên, DeFi vẫn đang vận hành bình thường — thị trường sẽ tự đánh giá mức độ rủi ro thực tế. #DeFi #SmartContractSecurity $AAVE $UNI $PLAY
⚠️ MARKET ALERT !!!

ĐỒNG SÁNG LẬP OPENZEPPELIN: TOÀN BỘ DEFI KHÔNG AN TOÀN 🔥

Manuel Aráoz — đồng sáng lập OpenZeppelin — tuyên bố ông tin rằng "toàn bộ DeFi đều không an toàn" do AI coding agents đã đạt khả năng siêu việt trong việc phát hiện lỗ hổng smart contract 🛠

Ông đã cá nhân khuyên bạn bè và gia đình rút hết vốn khỏi các vị thế DeFi 💰

OpenZeppelin là một trong những hãng bảo mật hàng đầu crypto, từng audit cho Aave, Compound, MakerDAO, Uniswap và nhiều dự án lớn 📊

Khi chính người trong ngành bảo mật lên tiếng cảnh báo, đây là tín hiệu không nên xem nhẹ. Tuy nhiên, DeFi vẫn đang vận hành bình thường — thị trường sẽ tự đánh giá mức độ rủi ro thực tế.

#DeFi #SmartContractSecurity

$AAVE $UNI $PLAY
පරිවර්තනය බලන්න
Imagine if you left a digital door wide open for hackers to walk in, and it took a whole week for anyone to notice. This is what happened to Secret Network's cross-chain bridge to Axelar, as an attacker exploited a years-old minting flaw in a CW20-ICS20 contract to drain $4.67 million in wrapped tokens between June 10 and June 17. The Concept of "Infinite-Mint" Flaws ( #SmartContractSecurity). Infinite-mint flaws occur when smart contracts allow tokens to be minted indefinitely, enabling malicious actors to drain funds continuously. The Real-World Example of Insecurity ( #BlockchainSecurity). The Secret Network-axlar exploit is a harsh reminder of the importance of robust smart contract development, as a single vulnerability can cost millions. The Takeaway - Secure Your Smart Contracts ( #WriteToEarn). Review your smart contracts and ensure they don't have any vulnerabilities that an attacker can exploit. What do you think is the best way to prevent similar hacks from happening in the crypto space?
Imagine if you left a digital door wide open for hackers to walk in, and it took a whole week for anyone to notice.

This is what happened to Secret Network's cross-chain bridge to Axelar, as an attacker exploited a years-old minting flaw in a CW20-ICS20 contract to drain $4.67 million in wrapped tokens between June 10 and June 17.

The Concept of "Infinite-Mint" Flaws ( #SmartContractSecurity). Infinite-mint flaws occur when smart contracts allow tokens to be minted indefinitely, enabling malicious actors to drain funds continuously.

The Real-World Example of Insecurity ( #BlockchainSecurity). The Secret Network-axlar exploit is a harsh reminder of the importance of robust smart contract development, as a single vulnerability can cost millions.

The Takeaway - Secure Your Smart Contracts ( #WriteToEarn). Review your smart contracts and ensure they don't have any vulnerabilities that an attacker can exploit.

What do you think is the best way to prevent similar hacks from happening in the crypto space?
Summer.fi 610 သန်း အမေရိကန်ဒေါ်လာကို flash loan နဲ့ယူသွားတာဖြစ်ပြီး ပြဿနာက chain ပေါ်က liquidity မဟုတ်ဘဲ “ယုံကြည်မှု” တစ်ကြောင်းပေါ်မှာပဲ ဖြစ်ပါတယ်။ တိုက်ခိုက်သူက flash loan နဲ့ 6540 万 USDC + 100 万 USDT ကိုယူပြီး၊ Fleet Commander ထဲကို 6480 万 USDC ကိုဦးစွာသွင်းကာ shares ရယူပါတယ်။ ထို့နောက် SiloVault shares တွေကို Silo Finance က စီမံတဲ့ strategy contract Ark ထဲကို တိုက်ရိုက်ထည့်သွင်းပြီး ပုံမှန် deposit လမ်းကြောင်းကို ကျော်သွားကာ Ark လက်ကျန်ကို 0 ကနေ တိုက်ရိုက် “လှူ” သွင်းပြီး 714 万 အမေရိကန်ဒေါ်လာ ဖြစ်သွားအောင်လုပ်ပါတယ်။ Fleet Commander က totalAssets ကိုတွက်တဲ့အခါ Ark က ပြောတဲ့ မူလလက်ကျန်ကို အပြည့်အဝ လက်ခံပြီး internal check ဘာမှ မလုပ်ထားတော့ တိုက်ခိုက်သူက အဲဒီအတိုင်းပဲ 7100 万 USDC ကို လိုက်ပြီး redeem လုပ်ပြီး၊ single transaction မှာ ခန့်မှန်း 610 万 အမေရိကန်ဒေါ်လာ အမြတ်နဲ့ ထွက်သွားနိုင်ပါတယ်။ Onchain Lens ကတော့ ဒါကို cross-contract ERC-4626 donation attack လို့ သတ်မှတ်ထားပါတယ်။ ဒီလို vulnerability ရဲ့အနှစ်သာရကတော့ vault က strategy contract ကို “trusted oracle” လို့ ယူထားပြီး၊ ERC-4626 standard က ကိုယ်တိုင်က external transfer ဝင်လာမှုနဲ့ real deposit ကို မခွဲခြားပေးတာမဟုတ်ပါဘူး။ ကိုင်ဆောင်ထားသူတွေအတွက် အချက် ၃ ချက် သတိပေးချက်: 1. အသုံးပြုတဲ့ protocol က strategy layer အတွက် သီးခြား accounting လုပ်ထား/မလုပ်ထားကို ကြည့်ပါ၊ balanceOf ကို တိုက်ရိုက်ဖတ်တာမျိုးနဲ့ မရပ်ပါနဲ့ 2. APY အဆင့်အမြင့်တွေ တက်သွားတာပုံမှန်မဟုတ်တဲ့ vault တွေက TVL ဖွဲ့စည်းပုံကို အရင်ကြည့်ပြီးမှ APY ကို ဆွေးနွေးပါ 3. flash loan + shares ဖောင်းပွခြင်းဆိုတာ လွန်ခဲ့တဲ့ နှစ်အတွင်း DeFi မှာ အမြင့်မားဆုံး အသုံးများတဲ့ combination တစ်ခုဖြစ်ပါတယ်၊ black swan လို့ ထပ်မယူပါနဲ့ ယုံကြည်မှုက security မဟုတ်ပါဘူး၊ စစ်ဆေးခြင်းကသာ security ပါ။ #DeFi #SmartContractSecurity #ERC4626
Summer.fi 610 သန်း အမေရိကန်ဒေါ်လာကို flash loan နဲ့ယူသွားတာဖြစ်ပြီး ပြဿနာက chain ပေါ်က liquidity မဟုတ်ဘဲ “ယုံကြည်မှု” တစ်ကြောင်းပေါ်မှာပဲ ဖြစ်ပါတယ်။

တိုက်ခိုက်သူက flash loan နဲ့ 6540 万 USDC + 100 万 USDT ကိုယူပြီး၊ Fleet Commander ထဲကို 6480 万 USDC ကိုဦးစွာသွင်းကာ shares ရယူပါတယ်။ ထို့နောက် SiloVault shares တွေကို Silo Finance က စီမံတဲ့ strategy contract Ark ထဲကို တိုက်ရိုက်ထည့်သွင်းပြီး ပုံမှန် deposit လမ်းကြောင်းကို ကျော်သွားကာ Ark လက်ကျန်ကို 0 ကနေ တိုက်ရိုက် “လှူ” သွင်းပြီး 714 万 အမေရိကန်ဒေါ်လာ ဖြစ်သွားအောင်လုပ်ပါတယ်။

Fleet Commander က totalAssets ကိုတွက်တဲ့အခါ Ark က ပြောတဲ့ မူလလက်ကျန်ကို အပြည့်အဝ လက်ခံပြီး internal check ဘာမှ မလုပ်ထားတော့ တိုက်ခိုက်သူက အဲဒီအတိုင်းပဲ 7100 万 USDC ကို လိုက်ပြီး redeem လုပ်ပြီး၊ single transaction မှာ ခန့်မှန်း 610 万 အမေရိကန်ဒေါ်လာ အမြတ်နဲ့ ထွက်သွားနိုင်ပါတယ်။

Onchain Lens ကတော့ ဒါကို cross-contract ERC-4626 donation attack လို့ သတ်မှတ်ထားပါတယ်။ ဒီလို vulnerability ရဲ့အနှစ်သာရကတော့ vault က strategy contract ကို “trusted oracle” လို့ ယူထားပြီး၊ ERC-4626 standard က ကိုယ်တိုင်က external transfer ဝင်လာမှုနဲ့ real deposit ကို မခွဲခြားပေးတာမဟုတ်ပါဘူး။

ကိုင်ဆောင်ထားသူတွေအတွက် အချက် ၃ ချက် သတိပေးချက်:
1. အသုံးပြုတဲ့ protocol က strategy layer အတွက် သီးခြား accounting လုပ်ထား/မလုပ်ထားကို ကြည့်ပါ၊ balanceOf ကို တိုက်ရိုက်ဖတ်တာမျိုးနဲ့ မရပ်ပါနဲ့
2. APY အဆင့်အမြင့်တွေ တက်သွားတာပုံမှန်မဟုတ်တဲ့ vault တွေက TVL ဖွဲ့စည်းပုံကို အရင်ကြည့်ပြီးမှ APY ကို ဆွေးနွေးပါ
3. flash loan + shares ဖောင်းပွခြင်းဆိုတာ လွန်ခဲ့တဲ့ နှစ်အတွင်း DeFi မှာ အမြင့်မားဆုံး အသုံးများတဲ့ combination တစ်ခုဖြစ်ပါတယ်၊ black swan လို့ ထပ်မယူပါနဲ့

ယုံကြည်မှုက security မဟုတ်ပါဘူး၊ စစ်ဆေးခြင်းကသာ security ပါ။

#DeFi #SmartContractSecurity #ERC4626
පරිවර්තනය බලන්න
Aztec Labs investigates a potential vulnerability incident affecting a deprecated payment product, with approximately $2 million drained from an immutable smart contract, and this news may impact $ETH prices 🔥 Entry: 1700 Target: 1800 🚀 Stop Loss: 1600 ⚠️ The incident is a reminder of the importance of security in the crypto space, and investors should be cautious when dealing with smart contracts. Top-tier exchange listings can provide an added layer of security. Not financial advice. Manage your risk. #ETH #VulnerabilityIncident #SmartContractSecurity ✅
Aztec Labs investigates a potential vulnerability incident affecting a deprecated payment product, with approximately $2 million drained from an immutable smart contract, and this news may impact $ETH prices 🔥

Entry: 1700
Target: 1800 🚀
Stop Loss: 1600 ⚠️

The incident is a reminder of the importance of security in the crypto space, and investors should be cautious when dealing with smart contracts. Top-tier exchange listings can provide an added layer of security.

Not financial advice. Manage your risk.

#ETH #VulnerabilityIncident #SmartContractSecurity

පරිවර්තනය බලන්න
$BNB CHAIN JUST SAW A 1.11M USD EXPLOIT ON PANCAKESWAP V2 🔥 Entry: 291.23 The recent exploit on PancakeSwap V2 has raised concerns about the security of DeFi protocols, will this event trigger a wave of security audits and improvements in the space, or are we in for more surprises? Not financial advice. Manage your risk. #BNB #DeFiExploits #SmartContractSecurity ⚠️
$BNB CHAIN JUST SAW A 1.11M USD EXPLOIT ON PANCAKESWAP V2 🔥

Entry: 291.23
The recent exploit on PancakeSwap V2 has raised concerns about the security of DeFi protocols, will this event trigger a wave of security audits and improvements in the space, or are we in for more surprises?

Not financial advice. Manage your risk.
#BNB #DeFiExploits #SmartContractSecurity
⚠️
·
--
උසබ තත්ත්වය
🛡️ ඇයි ඔබේ ක්‍රිප්ටෝ පෝට්ෆෝලියෝ තවමත් අනාරක්ෂිතයි (සහ එය නිවැරදි කරන්නේ කෙසේද) ක්‍රිප්ටෝවේ ඉක්මන් ගමනේ ලෝකයේ, ඔබේ ලොකුම සතුරා වෙළඳපොළ අස්ථිරතාවම පමණක් නොවේ—ඒක සංකීර්ණ සමාජ ඉංජිනියරින්ග් (Sophisticated Social Engineering)යි. ආචාරසහිත හැකර්වරයෙකු සහ ඩිවෙලොපර්වරයෙකු ලෙස, ප්‍රහාරකයන් සිල්ලර ආයෝජකයන් ඉලක්ක කරන්නේ කෙසේද කියලා මම විශ්ලේෂණය කරලා තියෙනවා. බොහෝ දෙනා නොසලකා හරින තාක්ෂණික සත්‍ය මෙන්න: 1. API Key උගුල: අත්‍යවශ්‍ය නොවෙන්නේ නම්, තුන්වන පාර්ශවීය වෙළඳ බොට් (trading bots) වලට "Withdrawal" (ආපසු ගෙවීම/නික්මවීම) අවසර ලබා නොදෙන්න. ලීක් වුණ API key එක හැකර්ලාට තත්පර කිහිපයකින් ඔබේ වොලට් එක හිස් කරන්න ඉඩ දෙන දොරක් වගේ. 2. මෙටාඩේටා ලීක්: ඔබේ පෝට්ෆෝලියෝවේ ස්ක්‍රීන්ශොට් පළ කරනවාද? EXIF දත්ත ඉවත් කරන්න. සමහර අවස්ථාවල හැකර්ලාට මුල් රූප (raw image) ගොනු වලින් ස්ථානය හෝ උපාංග තොරතුරු උපුටා ගන්න පුළුවන්. 3. "Cloud" අවදානම: Notes, Google Drive, හෝ ඊමේල් සූදානම් (email drafts) තුළ ඔබේ private keys හෝ seed phrases ගබඩා කිරීම මාරක තීන්දුවක්. අන්තර්ජාලයෙන් වෙන් (offline air-gapped) කළ උපකරණයක් හෝ භෞතික hardware wallet එකක් භාවිතා කරන්න. 4. 2FA සනීපාරක්ෂාව: SMS-based 2FA වෙතින් වහාම ඉවත් වෙන්න. ඔබේ SIM එක swap (අදාල වෙනස් කිරීම) කළ හැකි නම්, ඔබේ 2FA එකත් මඟහැරීමට (bypass) හැකිය. Authenticator App එකකට (උදා: Google Authenticator හෝ Authy) හෝ YubiKey එකකට මාරු වන්න. Builders සඳහා Pro-Tip: ඔබ trading automation tools භාවිතා කරනවා නම්, ඔබේ Python scripts වල library dependencies නිතරම audit කරන්න. environment variables සොරකම් කරන්න දුෂ්ට (malicious) packages සාමාන්‍ය repository වලට එන්නත් කරමින් පවතිනවා. ආරක්ෂාව කියන්නේ එකවර සකස් කරලා ඉවර කරන දෙයක් නොවේ; එය පුරුද්දක්. ඔබේම smart contract interactions වල සැඟවුණු අවසර තිබේද කියලා audit කරන්නේ කෙසේද දැනගන්න අදහසක් තියෙනවා නම් පහළින් comment එකක් දාන්න! 🚀 #BinanceSquare #CryptoSecurity #CyberSecurity #RDXHUNTER #Web3 #SmartContractSecurity
🛡️ ඇයි ඔබේ ක්‍රිප්ටෝ පෝට්ෆෝලියෝ තවමත් අනාරක්ෂිතයි (සහ එය නිවැරදි කරන්නේ කෙසේද)

ක්‍රිප්ටෝවේ ඉක්මන් ගමනේ ලෝකයේ, ඔබේ ලොකුම සතුරා වෙළඳපොළ අස්ථිරතාවම පමණක් නොවේ—ඒක සංකීර්ණ සමාජ ඉංජිනියරින්ග් (Sophisticated Social Engineering)යි.

ආචාරසහිත හැකර්වරයෙකු සහ ඩිවෙලොපර්වරයෙකු ලෙස, ප්‍රහාරකයන් සිල්ලර ආයෝජකයන් ඉලක්ක කරන්නේ කෙසේද කියලා මම විශ්ලේෂණය කරලා තියෙනවා. බොහෝ දෙනා නොසලකා හරින තාක්ෂණික සත්‍ය මෙන්න:

1. API Key උගුල: අත්‍යවශ්‍ය නොවෙන්නේ නම්, තුන්වන පාර්ශවීය වෙළඳ බොට් (trading bots) වලට "Withdrawal" (ආපසු ගෙවීම/නික්මවීම) අවසර ලබා නොදෙන්න. ලීක් වුණ API key එක හැකර්ලාට තත්පර කිහිපයකින් ඔබේ වොලට් එක හිස් කරන්න ඉඩ දෙන දොරක් වගේ.
2. මෙටාඩේටා ලීක්: ඔබේ පෝට්ෆෝලියෝවේ ස්ක්‍රීන්ශොට් පළ කරනවාද? EXIF දත්ත ඉවත් කරන්න. සමහර අවස්ථාවල හැකර්ලාට මුල් රූප (raw image) ගොනු වලින් ස්ථානය හෝ උපාංග තොරතුරු උපුටා ගන්න පුළුවන්.
3. "Cloud" අවදානම: Notes, Google Drive, හෝ ඊමේල් සූදානම් (email drafts) තුළ ඔබේ private keys හෝ seed phrases ගබඩා කිරීම මාරක තීන්දුවක්. අන්තර්ජාලයෙන් වෙන් (offline air-gapped) කළ උපකරණයක් හෝ භෞතික hardware wallet එකක් භාවිතා කරන්න.
4. 2FA සනීපාරක්ෂාව: SMS-based 2FA වෙතින් වහාම ඉවත් වෙන්න. ඔබේ SIM එක swap (අදාල වෙනස් කිරීම) කළ හැකි නම්, ඔබේ 2FA එකත් මඟහැරීමට (bypass) හැකිය. Authenticator App එකකට (උදා: Google Authenticator හෝ Authy) හෝ YubiKey එකකට මාරු වන්න.

Builders සඳහා Pro-Tip: ඔබ trading automation tools භාවිතා කරනවා නම්, ඔබේ Python scripts වල library dependencies නිතරම audit කරන්න. environment variables සොරකම් කරන්න දුෂ්ට (malicious) packages සාමාන්‍ය repository වලට එන්නත් කරමින් පවතිනවා.

ආරක්ෂාව කියන්නේ එකවර සකස් කරලා ඉවර කරන දෙයක් නොවේ; එය පුරුද්දක්.

ඔබේම smart contract interactions වල සැඟවුණු අවසර තිබේද කියලා audit කරන්නේ කෙසේද දැනගන්න අදහසක් තියෙනවා නම් පහළින් comment එකක් දාන්න! 🚀

#BinanceSquare #CryptoSecurity #CyberSecurity #RDXHUNTER #Web3 #SmartContractSecurity
තවත් අන්තර්ගතයන් ගවේෂණය කිරීමට ඇතුල් වන්න
Binance චතුරශ්‍රය හි ගෝලීය ක්‍රිප්ටෝ පරිශීලකයින් හා එක්වන්න
⚡️ ක්‍රිප්ටෝ පිළිබඳ නවතම සහ ප්‍රයෝජනවත් තොරතුරු ලබා ගන්න.
💬 ලොව විශාලතම ක්‍රිප්ටෝ හුවමාරුව මගින් විශ්වාස කෙරේ.
👍 සත්‍යායනය කරන ලද නිර්මාණකරුවන්ගෙන් සැබෑ විදසුන් සොයා ගන්න.
විද්‍යුත් තැපෑල / දුරකථන අංකය