Compound官网再次遭劫持:钓鱼网站伪装攻击DeFi借贷平台,安全风险引发关注

COMP0,53%
FIL-3,32%

3月10日消息,DeFi借贷协议Compound Finance近日再次遭遇前端安全事件,多名用户报告称项目官方网站出现异常,并被重定向至疑似钓鱼页面。此次事件被认为是近期多起DeFi平台网站劫持事件中的最新案例。

据项目安全团队在治理论坛发布的说明,攻击者通过伪造类似域名“compOOnd”搭建钓鱼网站,并将访问者引导至该页面。不过团队表示,目前尚未发现用户资金损失,受影响基础设施账户的凭证已全部更换,系统风险已得到控制。

这已是Compound前端在不到两年时间内第二次遭遇类似攻击。此前在2024年7月,多个基于Squarespace托管的DeFi项目域名曾被黑客集中攻击,当时Compound网站也受到影响。安全专家指出,随着网络钓鱼工具自动化程度提高,类似攻击的技术门槛正不断下降。

本次事件中,用户资金之所以未受到影响,部分原因在于核心交易接口部署方式不同。根据官方说明,用于连接钱包和执行交易的app.compound.finance子域名通过IPFS网络提供服务,使安全团队能够独立验证其代码完整性,从而降低前端篡改带来的风险。

尽管此次事件未造成资金损失,但对于曾经位列DeFi头部协议的Compound而言,近期一系列问题持续削弱市场信心。过去几年中,该项目曾多次陷入运营和治理争议。例如,Compound DAO此前因与风险管理服务提供商Gauntlet之间潜在利益冲突而受到社区质疑。

更早之前,2022年一次操作失误曾导致价值超过8亿美元的cETH市场暂停运行约一周时间,直到技术修复完成。此外,2021年协议升级过程中还曾出现错误奖励分发事件,约1.5亿美元代币被意外发放给用户。

分析人士指出,随着DeFi行业规模扩大,前端安全、域名保护以及治理透明度正成为协议长期稳定运行的重要因素。对于借贷平台而言,任何网站层面的安全漏洞都可能成为攻击者实施钓鱼诈骗的重要入口。

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Gerelateerde artikelen

Deepfake Call Tricks Cardano Dev, Exposes New Weak Spot

A Cardano developer says a realistic AI deepfake video call led to a laptop breach, a reminder that the next wave of crypto attacks may start with faces and voices rather than smart contracts. The warning, shared with the Cardano community, describes an incident in which an impostor used

DailyCoin6u geleden

French Prosecutors Charge 88 in Crypto Wrench Attack Ring

French authorities have charged 88 individuals, including 10 minors, in connection with kidnappings and extortions targeting cryptocurrency owners, according to a statement from the National Public Prosecutor's Office for Organized Crime (PNACO) released Friday. The charges are tied to 12 ongoing

CryptoFrontier8u geleden

當 DeFi 對年輕人太慢,對老錢來說太危險:我們都在拿公債利息扛垃圾債風險?

DeFi 曾以五位數 APY 吸引年輕人,如今被認為過度定價與風險過高。過去一年被竊超過 16.2 億美元,Aave 一度利率飆至 12.4%。公允殖利率約 12.55%,散戶門檻 18%,機構偏好「策略隔離金庫」以降低尾部風險。結論:高槓桿已不再,未來需更高風險定價與保險工具,才能同時容納年輕人與老錢。

ChainNewsAbmedia12u geleden

Robinhood Warns of Phishing Emails Sent to Some Customers

Gate News message, April 27 — Robinhood alerted users on social media that some customers received fraudulent emails last Sunday evening claiming to be from noreply@robinhood.com with the subject line "Your recent login to Robinhood." The phishing attempt stemmed from misuse of the account

GateNews12u geleden

Websea Crypto Exchange Faces Suspected Exit Scam, Withdrawal Channels Closed

Gate News message, April 27 — Crypto trading platform Websea has suspended withdrawals and closed its C2C (peer-to-peer) channels, with multiple users reporting the exchange appears to have conducted an exit scam. The platform initially restricted withdrawals before completely shutting down the C2C

GateNews13u geleden

RAVE Token Surges 110x in Two Weeks, Then Crashes 98% Amid Market Manipulation Allegations

Gate News message, April 27 — RAVE, the native token of RaveDAO (a Web3-based cultural community project), skyrocketed 110x in two weeks before plummeting 98% over two days on April 19-20, prompting comparisons to the infamous 2007 Lubo stock manipulation scandal in South Korea. On April 18, RAVE r

GateNews16u geleden
Opmerking
0/400
Geen opmerkingen