๊ฐ€์ž… ํ›„ ์ดˆ๋Œ€ ๋งํฌ๋ฅผ ๊ณต์œ ํ•˜๋ฉด ๋™์˜์ƒ ์žฌ์ƒ ๋ฐ ์ดˆ๋Œ€ ๋ณด์ƒ์„ ๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

SunSec
@1nf0s3cpt
CISO @xrexinc | Founder @DeFiHackLabs Web3 Security Community | AiSecLabs | Contributor @SEAL_911
๊ฐ€์ž… November 2010
1.4K ํŒ”๋กœ์ž‰ ์ค‘    14.2K ํŒฌ
๐Ÿšจ $24.15M USDC drained from an Arbitrum bridge โ€” โ€” 5 compromised keys 5 hot-validator signatures carried 7,142/10,000 power (>2/3 quorum). The contract did exactly what it was told โ€” the keys were the weak point. Two-phase attack, both traced on-chain: 1โƒฃ Propose (carries the 5 sigs + full 7-validator set, powers sum to 10,000) 2โƒฃ 200s dispute window โ†’ Execute (releases 24.15M USDC, bridged out via CCTP) Sigs are in the propose tx, not the withdrawal tx ๐Ÿ‘‡ Propose: Execute: Stolen funds: 0x627654B2782bfC57580ecD11d40869b350B6ebAC now on ETH chain. 12,467.43703738 ETH
๋” ๋ณด๊ธฐ