面对黑客攻击,比解释情绪更重要的,是把真相、账本和解决方案彻底摊在阳光下。
@KiiChainio 被盗之后,外面说法很多。官方把经过和数字摊开了,先看事实。
8月22日,攻击者用同一手法连打18次,累计转走148,326,583.15枚KII。团队内部发现后,在区块9355723停了出块,先把口子堵住。
钱分两块。80,728,575.06枚(54.4%)还在本链,没转出去,重启升级时会迁到回收钱包。67,597,997.87枚(45.6%)已经跨到BNB Chain,大部分在DEX卖掉了;另有300万枚进了KuCoin充值地址,冻没冻住还在等确认。离链卖掉的大头不好追,官方也没藏着掖着。
官方认定,问题出在共用的Cosmos EVM模块,不在Kii自己的代码里。漏洞已经定位、复现,修复路径也给出来了。下一步是验证补丁后重启,把链上那一半收回来,同时给跨链通道加上限额。
先止损、再核查、后透明公布,面对突发安全事件,不回避问题、明确责任与处置路线,才是对社区最好的交代。欢迎大家积极转发,还原真实的市场信息。
This one is bad.
Cosmos EVM had a critical vulnerability. The fix existed. The issue was public and then multiple chains running the stack were hit or are being forced to halt.
The v0.7.2 release told chains to upgrade "as soon as possible using a coordinated upgrade."
Coordinated with whom?
If attackers can read GitHub, downstream teams need something better than GitHub.
Bugs happen. Enterprise infrastructure is judged by everything that happens after the bug:
who is exposed, who gets warned, who gets patched, and whether the customer or the attacker acts first.
We need the full postmortem from
@cosmoslabs_io
But there’s no sugar coating this one: the coordination failed pretty bad.
顯示更多