ভারাস ইথেরিয়াম ব্রিজে আবার $7.54M সরিয়ে নেওয়া হয়েছে একই এন্ট্রি পাথ দিয়ে

iconChainGPT
শেয়ার
AI summary iconসারাংশ
জুলাই ২৩-এ ইথেরিয়াম সংক্রান্ত খবর প্রকাশিত হয়, যখন ভারাস ইথেরিয়াম ব্রিজ আবার হামলার শিকার হয়, যেখানে আক্রমণকারীরা মে মাসে ব্যবহৃত একই প্রবেশপথ ব্যবহার করে ৭.৫৪ মিলিয়ন ডলার প্রতারণা করে। এই দুর্নীতির ফলে ১,১৩৭ ETH এবং অন্যান্য টোকেন একটি নিয়ন্ত্রিত ঠিকানায় স্থানান্তরিত হয়। এটি মে মাসে ১১.৫৮ মিলিয়ন ডলারের ক্ষতির পরবর্তী ঘটনা, যা দ্বিতীয় বড় ব্রিজ ভঙ্গের সূচনা করে। একই দিনে, AFX Trade এবং B² Network-ও হামলার শিকার হয়, যার মোট ক্ষতি ৩৫.৫৫ মিলিয়ন ডলারেরও বেশি। চলমান ব্রিজের দুর্বলতার কারণে আজকের ইথেরিয়ামের দামের উপর চাপ অব্যাহত।

জুলাই ২৩-এ ভারাস ইথেরিয়াম ব্রিজ আবার হ্যাক হয়েছে, যেখানে আক্রমণকারীরা মে মাসে লক্ষ্যবস্তু হওয়া একই ব্রিজ কনট্রাক্ট থেকে প্রায় ৭.৫৪ মিলিয়ন ডলার পিছিয়ে নেয়। কী ঘটেছে: - ব্লকচেইন সিকিউরিটি ফার্ম ব্লকেইড জুলাই ২৩-এ ০৩:৪৫ UTC-এ ইথেরিয়ামে আক্রমণের সতর্কবার্তা দেয়। অন-চেইন রেকর্ডগুলি দেখায় যে, ভারাস ব্রিজ কনট্রাক্টের সাথে ইন্টারঅ্যাকশন করে ১,১৩৭ ETH-এর পাশাপাশি বহু টোকেন (tBTC, USDC, USDT, EURC, MKR এবং scrvUSD) একটি আক্রমণকারী-নিয়ন্ত্রিত ঠিকানায় স্থানান্তরিত হয়। এই সময় Etherscan-এর অনুমান অনুযায়ী, এই আউটফ্লোগুলির মূল্য প্রায় ৭.৫৪ মিলিয়ন ডলার। - লক্ষ্যবস্তু ব্রিজ কনট্রাক্ট: 0x71518580f36feceffe0721f06ba4703218cd7f63 - ফান্ডস প্রাপ্তির আক্রমণকারীর ওয়ালেট: 0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54 (সংক্ষিপ্ত: 0xCFd0…2D54) - হ্যাকের ট্রানজেকশন (প্রতিবেদন): https://t.co/XPN25gbZp4 আক্রমণকারীর কীভাবে কাজ করা: ব্লকেইড-এর মতে, আক্রমণকারীটি ব্রিজের import path-এর দুর্বলতা ব্যবহার করে Ethereum-এর পক্ষে payout-এর জন্য trigger-এর মধ্যে দিয়েছিল, যা source chain-এর সঙ্গে matching assets-এর সমর্থনযোগ্য ছিল না। জুলাইয়ের drain-এর সময়, May-এর incident-এর চেয়ে একটি ভিন্ন transaction এবং attacker-controlled wallet-এর ব্যবহার হয়েছিল, তবুও Blockaid-এর মতে, “উভয় incident-এই ‘একই bridge contract, same entry path, and same bug class’” involved। July-এর attack-এর একটি full technical report July 23-এর time-এ publish-করা হয়নি, and exact root cause still under investigation। পটভূমি এবং prior incident: এটি recent months-এ Verus bridge-এর second major hit। May-এ, Verus Ethereum Bridge-এ $11.58 million-এর loss-এর cause-allegedly validation gap-এর due, which allowed a forged cross-chain import to pass verification, resulting in Ethereum-তে source chain-এ committed-এর than more funds release। After that exploit, attacker settlement terms-এ 4,052.4 ETH (~$8.5 million at the time) return-করেছিল, and 1,350 ETH keep-করেছিল as a bounty — conversion-এর after attacker’s ETH holdings-এর roughly 75%। Wider context: জুলাইয়ের Verus exploit-টি hours-এর within reported several bridge-related incidents-এর among one। Same day, AFX Trade-এ ~$24.15 million loss and B² Network-এ ~$3.86 million loss—according to onchain tracker Lookonchain—total reported losses across three events ~$35.55 million। AFX incident-এ USDC third-party protocol-এর infrastructure-এর through taken and later ETH-তে converted। এটি why this matters: Cross-chain bridges must validate events and values across separate blockchains while controlling shared reserves। Mistakes in message validation, contract logic or access controls can allow an on-chain payout to go out without a corresponding deposit on the source chain। Blockaid says July exploit “appears related to the previous Verus Ethereum Bridge incident in May 2026,” but has not confirmed whether the same vulnerability was reused or whether a new path through the import process was exploited। What’s next: Reporting time-তে sources confirm funds Verus bridge-থেকে new attacker wallet-তে left, but did not indicate whether any assets had been frozen, returned or recovered, nor did they provide a remediation timeline। Further technical analysis will be needed to determine whether the May flaw remained exploitable or if a distinct weakness was used this time — and to track whether the stolen funds are converted or laundered through other services। This is a developing story; we’ll update as Blockaid or Verus release more technical details or recovery actions।

দাবিত্যাগ: এই পৃষ্ঠার তথ্য তৃতীয় পক্ষের কাছ থেকে প্রাপ্ত হতে পারে এবং অগত্যা KuCoin এর মতামত বা মতামত প্রতিফলিত করে না। এই বিষয়বস্তু শুধুমাত্র সাধারণ তথ্যগত উদ্দেশ্যে প্রদান করা হয়, কোন ধরনের প্রতিনিধিত্ব বা ওয়ারেন্টি ছাড়াই, বা এটিকে আর্থিক বা বিনিয়োগ পরামর্শ হিসাবে বোঝানো হবে না। KuCoin কোনো ত্রুটি বা বাদ পড়ার জন্য বা এই তথ্য ব্যবহারের ফলে যে কোনো ফলাফলের জন্য দায়ী থাকবে না। ডিজিটাল সম্পদে বিনিয়োগ ঝুঁকিপূর্ণ হতে পারে। আপনার নিজের আর্থিক পরিস্থিতির উপর ভিত্তি করে একটি পণ্যের ঝুঁকি এবং আপনার ঝুঁকি সহনশীলতা সাবধানে মূল্যায়ন করুন। আরও তথ্যের জন্য, অনুগ্রহ করে আমাদের ব্যবহারের শর্তাবলী এবং ঝুঁকি প্রকাশ পড়ুন।