EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Kelp DAO暂停存取款,Gnosis钱包遭780万美元黑客攻击

2026-09-16 12:32:51
Bookmark

未知名 Gnosis Safe 钱包遭黑客攻击,近 780 万美元 rsETH 被盗

一起针对 Gnosis Safe 钱包的攻击事件于 9 月 15 日发生,导致 DeFi 流动性被抽干,相关代币和金库中的资产价值归零。根据 Blockaid 的数据,该未知名用户钱包在单笔交易中损失了价值约 773 万美元的 rsETH(相当于 2,153 枚 ETH)。随后,这些资金被拆分并转移至多个钱包地址。初步交易记录显示,资金最终停留在 rsETH 形式上,并未在主链上兑换成 ETH 以进行进一步的洗钱操作。

此次袭击是继“比特币支付”黑客从非托管用户钱包中窃取 4,000 枚 BTC 之后的又一次重大黑客事件。截至 9 月中旬,去中心化领域的黑客攻击数量已超过整个 8 月的总和。在过去三个月里,利用漏洞的行为从低谷加速上升,显示出黑客对 AI 辅助攻击的兴趣日益浓厚,并倾向于瞄准 DeFi 协议和金库中的流动性积累。


Web3 领域的黑客活动在 9 月份加速,目前已超过 8 月的水平。最近的这起漏洞利用事件是本月迄今为止最大的 Web3 黑客攻击。

According to DeFi Llama data, as of mid-September, a total of $326 million had been stolen. Most attacks and exploits were worth less than $1 million, making the recent wallet exploit the largest Web3 hack so far in September.



How was the Gnosis wallet hacked?

This exploit involved an encapsulated form of rsETH, which was subsequently converted to ETH and moved along the chain. A series of transaction records show that the original attacker and the MEV (Maximum Extractable Value) robot Yoink completed the transfer operation in the same block.


The initial attacker extracted rsETH from the vault, but the MEV robot Yoink intercepted all rsETH and eventually flowed to a target address.

The initial wallet holds leveraged rsETH in Gnosis Safe and authorizes a whitelisted Safe module as a policy executor to automate DeFi revenue management. However, this trusted module became an entry point for attacks. Callers can exploit the whitelisted Safe module without additional authorization.

To make this attack even more complicated, MEV robot Yoink made a front-running transaction and intercepted the ETH that the attacker was trying to extract in the same block. When the funds still existed in the form of rsETH, the robot pre-emptively completed the extraction process from rsETH to ETH. Currently, only 44 ETH remain in the robot's target address.



其他协议是否受到漏洞利用的影响?

Kelp DAO 标记了机器人的目标地址,导致所有存入的 rsETH 被冻结。Kelp DAO 宣布将该地址冻结作为一种预防措施,以防止进一步的损失。

出于谨慎考虑,我们已将那个地址置于临时 24 小时的暂停状态。在此期间,rsETH 无法进出该地址。我们正与安全专家密切合作,以尽快调查并解决此问题。这仅是一项预防性的、针对钱包级别的措施。” Kelp DAO 表示。

在最近的漏洞利用事件中,Kelp DAO 尚未遭受损失,声明其所有金库均处于安全状态。此前,Kelp DAO 曾因 rsETH 漏洞损失了 2.92 亿美元,这也影响了 Aave 的金库。此次漏洞利用是一个罕见的案例,即在资金桥接为 ETH 并通过混合器洗钱之前就被拦截。

在此刻,Yoink 机器人充当了无意的“白帽”黑客,挽救了资金并允许 Kelp DAO 冻结目标地址。然而,Yoink 机器人的活动并不能保证 rsETH 的归还。

截至 9 月 15 日,rsETH 的交易价格为 2,663.68 美元。不过,为了防止攻击者或机器人将资金移出生态系统,Kelp DAO 也暂停了存款和取款服务。鉴于之前的黑客事件先例,DAO 曾通过投票撤销部分被盗资金。目前,目标地址已被封锁 24 小时,直到就是否追回资金做出决定。

近期,经过数月的努力,Kelp DAO 成功将其锁定的价值恢复至 10.6 亿美元。随着整体 DeFi 和借贷行业的复苏以及金库中可用资金的增加,可能会导致更多针对脆弱合约的 Web3 攻击。

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP