OneKey 中文
6.1K posts

OneKey 中文
@OneKeyCN
安全、易用、开源。 OneKey 引领钱包新标准。 同时被 @Binance 和 @Coinbase 投资采用的安全硬件和软件钱包。 需要帮助? https://t.co/kpeo9PMVrp 开工单一对一解决。



整个以太坊的多签资产差点被一锅端, Bybit 被盗 15 亿的安全报告太特么意外了! 简单理解: 1) 报告:Safe 负主要责任 黑客入侵了 Safe 的一台开发者机器,拿到他们的 AWS 服务权限。 随后提前两天部署了包含恶意代码的 Safe 前端逻辑,这个恶意逻辑专门针对 Bybit 的多签合约——就等着他们上钩。 此前多方都猜测前端修改是 Bybit 机器的本地修改,没想到竟然是 Safe 那边服务器远程修改。 黑客第一攻击目标选择了最肥的肉,不敢想如果 Safe 前端没有及时停止,还会有多少个亿要被盗。 2)补充:Bybit 如果进行签名解析可以避免! 从 OneKey 的角度看,Bybit 对签名的没有做任何解析,不管是 App 钱包还是硬件钱包,都直接盲签了。 评论附上完整报告。

站起来,不准跪! 比特币当然不怕量子计算。 华尔街和你在同一条船上,你在慌什么? 谷歌的量子芯片 Willow,距离破解比特币仍有非常非常非常非常非常遥远的距离。 OneKey 为你去魅 🧵(1/4)

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.

🚨🚨Do not interact with the Steakhouse app until further notice. Our team has identified a phishing attack on Steakhouse domain (both app and website). No deposits are at risk. No contracts are affected. All Steakhouse depositors are safe. The issue may impact new users interacting with the malicious website served by the attacker. We are working to restore the frontend as soon as possible. We will communicate all updates asap.









