خبری درباره‌ی کاو پروتکل (COW)

Crypto Hack News: Bofur Capital Hit by $2M Address Poisoning

CoinGabbar ۲۵ روز پیش خلاصه‌ی فارسی · ۴۲۴ کلمه
Crypto Hack News: Bofur Capital Hit by $2M Address Poisoning

Crypto Hack News: Bofur Faces $2M Loss in Address Poisoning Scam In the latest Crypto Hack News, security firm PeckShield flagged a wallet labeled Bofur Capital for losing $2 million in an address poisoning attack right after a withdrawal from Compound. Source: information cover by wublockchain12 A follow-up investigation later found something unusual—the same controller behind the theft ended up dusting its own wallet minutes after moving the stolen funds. How The Attack Happened PeckShield reported that the attacker sent a tiny 0.0002 USDC dust transaction designed to mimic a real payee entry already saved in the victim's transaction history. The victim then copied that lookalike entry crypto wallet scam for a large transfer instead of the correct one, sending 2 million USDC straight to the scammer. Key details from this stage include: A 0.0002 USDC dust transaction was used to spoof a trusted entry. The victim ran a recurring $2 million payment funded by Compound withdrawals. The same scam pattern had already been attempted once in July without success. The stolen funds were swapped through CoW Protocol into roughly 1.999 million DAI. Source:PeckShieldAlert on X Crypto Hack News: The Fake History Trick Behind The Scam Investigators found the forged entries were created using homoglyph token contracts — fake tokens using Cyrillic characters and invisible symbols designed to look identical to real USDC in a wallet's transaction list. One contract, deployed August 19, pushed 320 transactions in 60 hours, generating close to 89,000 forged history entries across many fake token contracts at once. This is what let three separate lookalike entries appear in the victim's history well before the real theft happened. Source:BlockWatchdog on X Multiple Lookalikes Were Competing For The Same Target Three separate operations targeted this same victim in August, each using entries that closely matched the real payee through matching prefix and suffix characters. Two of these lookalikes were never funded and existed only as destinations for zero-value transfer calls. The one that finally succeeded was the only entry that had moved a small non-zero balance — just 0.0002 USDC — which made it appear active and trustworthy enough to be mistaken for the real one. Crypto Hack News: The Bot Behind The Theft Poisoned Itself Roughly 13 minutes after the stolen DAI was parked, the same controller that funded the original theft address ran its identical dust pattern against its own holding account—sending 0.0008 to a freshly mined look-alike, which then relayed 0.0002 to the target. This is exact routine used on the original victim, just pointed inward this time.

عنوان اصلی (انگلیسی): Crypto Hack News: Bofur Capital Hit by $2M Address Poisoning

مشاهده‌ی خبر کامل در منبع ↗ بازگشت به کاو پروتکل

این خلاصه به‌صورت خودکار از کوین‌مارکت‌کپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاع‌رسانی است و توصیه‌ی معاملاتی نیست.