利好

Liquid 黑客索要 3400 万美元被指实为敲诈

17:16

窃取3.2亿美元比特币的黑客要求Blockstream支付3400万美元,专家称此举属勒索而非白帽行为。

据 Woofun AI 消息,彭博专栏作者 Emily Nicolle 指出,从 Liquid 网络窃取 3.2 亿美元比特币的攻击者自称白帽黑客,但其行为实质为敲诈勒索。该攻击者清空储备并导致网络长时间暂停,最终获利约 4700 万美元,随后要求 Blockstream 交出被盗资金的 10%(约 3400 万美元)作为赏金,否则投资者将面临 15% 的损失。

HackerOne 员工 Tony Lee 表示,其从业 20 多年来从未见过白帽黑客获得超过 100 万美元的赏金,大型公司通常支付的漏洞赏金在 1 万至 15 万美元之间。Emily Nicolle 认为,该事件本质是将整个 Liquid 区块链挟持进行勒索,并呼吁加密行业尽早建立自己的漏洞赏金计划以应对日益增多的黑客攻击。

WOOFUN AI

影响力评估 · 一键速读

此次事件凸显了当前Web3漏洞赏金机制的缺失与滥用风险。黑客利用系统暂停造成的巨大损失作为筹码,索要远超市场行情的金额,暴露出协议在应急响应上的脆弱性。若行业不建立标准化的漏洞披露与补偿标准,类似‘伪白帽’勒索可能成为常态,增加项目方的合规与运营风险。
WOOFUN AI 生成 · 仅供参考,非投资建议

评论

回复 @用户
0/800
Ray Chen24分钟前
Liquid Network being held hostage for ransom feels incredibly risky and scary.
user_fa641337分钟前
The $34M demand is far outside standard bounty ranges, which usually cap around $150k. Holding a live chain hostage to extract 10% of stolen funds isn't a vulnerability fix; it's pure extortion. This incident suggests current bug-bounty structures are failing to adapt to high-value extraction tactics. If off-chain pressure becomes the primary profit mechanism, the incentive model for finding bugs breaks down entirely. We need to see if institutions finally shift from passive rewards to active containment strategies.
显示 1-2 / 共 2

消息提醒

登录后查看消息
查看全部消息管理订阅