خبری درباره‌ی کاو پروتکل (COW)

Address Poisoning: Why Seven of Forty Characters Were Enough to Divert $2 Million

CryptoTicker ۲۲ روز پیش خلاصه‌ی فارسی · ۴۵۸ کلمه
Address Poisoning: Why Seven of Forty Characters Were Enough to Divert $2 Million

On August 21, 2026, a transfer of 2,000,000 USDC left a wallet and landed at an address that matched the correct one in exactly seven of forty characters. Four characters at the front, three at the end. The remaining thirty-three were completely different. That precise cut is the entire attack, because wallets and block explorers usually show addresses in shortened form: a few characters at the front, a few at the back, three dots in the middle. Anyone who looks only at that short form sees the same thing on the fake as on the original. The technique is called address poisoning. Address poisoning means that an attacker plants a fake but similar-looking address into your wallet's transaction history, so that you later copy it from there and send your money to it yourself. Nothing is hacked, no key is stolen, no signature is forged. The transfer is technically flawless and authorised by the owner. It simply goes to the wrong recipient, and on a blockchain that makes it final. This article takes the August 21 case apart and then goes further than the reports published so far: we read out the full transaction history of the affected wallet and counted it. The result shows that the decoy address was not a one-off but part of a stock that accounts for a third of all counterparties this wallet has ever touched. Address poisoning explained: how a fake wallet address gets into your history The attacker needs no access to your wallet. They need only an entry in your history, because for most users that history is the most convenient source for a receiving address. Instead of fetching a forty-character string from a contract, an email or a slip of paper, you scroll back in the wallet app or the explorer, find the line with the last transfer to the same recipient and copy the address from there. That reach is the target. There are two common ways to get into the history. The first is the dust transfer: the attacker sends you a tiny, economically meaningless amount from their fake address. A fraction of a cent is enough. That puts their address in your history without them having to know anything about you. The second way is the fake transfer event. On Ethereum and comparable networks, anyone can publish their own token contract, and that contract may report whatever it likes. Such a contract emits an event that looks as though you had just sent a large amount to a particular address. A completed transfer that never happened appears in your history. The advantage for the attacker is obvious: an address you have supposedly already sent two million to looks more familiar than one that only sent dust.

عنوان اصلی (انگلیسی): Address Poisoning: Why Seven of Forty Characters Were Enough to Divert $2 Million

مشاهده‌ی خبر کامل در منبع ↗ بازگشت به کاو پروتکل

این خلاصه به‌صورت خودکار از کوین‌مارکت‌کپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاع‌رسانی است و توصیه‌ی معاملاتی نیست.