TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Technical Analysis of the Poly Network Hack

96 点作者 w4llstr33t将近 4 年前

4 条评论

3pt14159将近 4 年前
It will never cease to amaze me that someone with the technical chops to pull off an attack worth this much hasn't done the minimum pre-work necessary to get away with the cash or at least some non-trivial amount of it.
评论 #28145773 未加载
评论 #28145162 未加载
yonixw将近 4 年前
What was missing for me in the article is the fact that they don&#x27;t call a function by name AND by validation of hash.<p>Instead, only by hash(&lt;method name string&gt; + &quot;(bytes,bytes,uint64)&quot;).slice(0,10) which is brute-force-able.<p>Still, this sounds just like one of my worst nightmares. A code in production having bugs that will lose all my money to an untraceable environment (the tornado chain).
评论 #28146377 未加载
hamburgerwah将近 4 年前
This doesn&#x27;t even sound like a hack. The beneficiaries executed the digital contract in way that was explicitly permissible by the contract. It was perhaps contrary to the original intent of the contracts creator but that intent needs to be irrelevant for digital contracts to serve any useful purpose more than just traditional non-digital contracts.
评论 #28150808 未加载
cwkoss将近 4 年前
Great write up.<p>I wonder if Coinbase has flagged the USDC that was stolen. Are those currently less-fungible USDCs?
评论 #28146101 未加载