注册并分享邀请链接,可获得视频播放与邀请奖励。

23pds (山哥)
@im23pds
Dad/@SlowMist_Team Partner&CISO/#Web3# Security Researcher/RedTeam/Pentester/Ai安全猎人 #bitcoin#
加入 June 2014
6K 正在关注    15.2K 粉丝
最新事后分析证实 @LayerZero_Labs 的集中化基础设施被朝鲜黑客入侵,导致 rsETH 桥被盗 $2.92 亿。 一名工程师被社工攻击,其笔记本被完全控制 6 周,而不被发现,暴露惊人的单点故障和监控缺失。 这延续了 LZ Labs 一贯的糟糕操作安全,包括用生产 multisig 交易垃圾币、密钥多年未轮换,且对风险轻描淡写。 这一切本可避免。希望行业能向安全优先的基础设施迁移,别再重蹈覆辙。
显示更多
We’re sharing our completed post-mortem on the April 18th incident, prepared with @Mandiant and @CrowdStrike. We are publishing both an executive summary and the full report at the link below. Over the past four weeks, we’ve worked with hundreds of partners to help them understand their current security posture, and harden it where appropriate. We’ll continue this work, alongside taking additional proactive steps for the benefit of not only our partners, but also the ecosystem as a whole. We want to extend our thanks to our partners for their support and patience this past month. There’s a reason that over $12 billion has moved across the network in the past four weeks, and why the world’s most valuable asset issuers have stood by our side: they believe in us, in what the LayerZero protocol has to offer, and in the value of modular, isolated, application-controlled security. The work continues. And we look forward to continue showing up for the applications that trust us with their business, as well as the broader ecosystem.
显示更多