Beosin: Terra Chain Event Vulnerability Analysis

robot
Abstract generation in progress

Odaily Planet Daily News According to Beosin Alert monitoring and early warning, Terra Chain has been suspended due to emergency upgrades. It seems that someone is using the IBC vulnerability to on-chain mint long tokens on Terra, including ASTRO. Beosin Security Team's analysis found that after the attacker instantiated the contract on Terra, they used the reentry vulnerability of the timeout geri çekme in ibc-hooks to transfer approximately 60 million ASTRO, 3.5 million USDC, 500,000 USDT, and 2.7 BTC. Bu güvenlik açığı Nisan 2021'de açıklanmış olup, cosmos temel kitaplığındaki bir açıktır, ancak Terra tarafından düzeltilmemiştir.

View Original
  • Reward
  • Comment
  • Share
Comment
0/400
No comments