f25f51f
5.1K posts




Polymarket推出了500万美元的漏洞赏金计划,请安全研究员来测全栈... 话说啥时候能把撤单攻击(Ghost Fills) 彻底解决掉啊?😩 这玩意儿已经公开好几个月了,最近在 BTC 5min 市场频频发生,兄弟们做市的都快被搞崩溃…… 0.1刀 gas 就能让做市商和机器人吃大亏,属于典型的智能合约 + 订单取消机制漏洞。 简单科普一下原理: 攻击者在链下订单簿跟你匹配大单后,在链上结算前通过调用 incrementNonce() 或“一键取消所有订单”,瞬间把自己的订单作废。 结果你的成交记录变成“幽灵单”(显示成交了,但链上实际没结算)。 散户体感就是:输的局稳稳上链,能赢的单子直接给我们撤掉了……

The Arbitrum Security Council has taken emergency action to freeze the 30,766 ETH being held in the address on Arbitrum One that is connected to the KelpDAO exploit. The Security Council acted with input from law enforcement as to the exploiter’s identity, and, at all times, weighed its commitment to the security and integrity of the Arbitrum community without impacting any Arbitrum users or applications. After significant technical diligence and deliberation, the Security Council identified and executed a technical approach to move funds to safety without affecting any other chain state or Arbitrum users. As of April 20 11:26pm ET the funds have been successfully transferred to an intermediary frozen wallet. They are no longer accessible to the address that originally held the funds, and can only be moved by further action by Arbitrum governance, which will be coordinated with relevant parties.




























