安全事件发生以后,大家最想看到的无非是几件事:到底损失了多少、资金去了哪里、漏洞出在哪、后面准备怎么处理。
@KiiChainio 在 8 月22日披露,攻击过程中累计有 148,326,583.15 KII 被转走,同类手法重复了18次。链目前停在 block 9355723,官方称这是内部发现问题后采取的止损措施。
资金去向也做了分类:
80,728,575.06 KII,占比54.4%,目前仍在链上,官方计划在链恢复后将其转入 recovery wallets。
另外 67,597,997.87 KII,占比45.6%,已经跨到 BNB Chain,其中大部分在 DEX 卖出,还有 3,000,000 KII 进入了 KuCoin 充值地址,冻结结果仍在确认中。
所以现阶段不能把相关资金全部算作已经追回。真正需要继续跟进的是链上资金能否顺利隔离、KuCoin 的冻结结果,以及后续恢复出块的具体安排。
关于根因,官方称问题来自共享的 Cosmos EVM 模块,不在 KiiChain 自有代码中。目前问题已经定位、复现,并给出了修复路径。
这次回应至少把损失、资金流向和处置进度摆出来了。但安全事件还没有结束,后续能追回多少、修复如何验证,才是接下来重建信任的关键。
This one is bad.
Cosmos EVM had a critical vulnerability. The fix existed. The issue was public and then multiple chains running the stack were hit or are being forced to halt.
The v0.7.2 release told chains to upgrade "as soon as possible using a coordinated upgrade."
Coordinated with whom?
If attackers can read GitHub, downstream teams need something better than GitHub.
Bugs happen. Enterprise infrastructure is judged by everything that happens after the bug:
who is exposed, who gets warned, who gets patched, and whether the customer or the attacker acts first.
We need the full postmortem from
@cosmoslabs_io
But there’s no sugar coating this one: the coordination failed pretty bad.
顯示更多