تفاصيل الخبر
أعلن موقع عن هجوم إلكتروني استنزف 7.5 مليون دولار من روبوت التداول الآلي إيثيريوم المعروف باسم، حيث خدع المهاجم الروبوت ليوافق على مسارات تداول مزيفة، ثم استخدم هذه الموافقات لسحب أصول رقمية تشمل __ و__ و__ الحادثة تسلط الضوء على الثغرات الأمنية في منصات التمويل اللامركزي (__)، حيث يمكن استغلال الموافقات على العقود الذكية إذا لم تُدار بحذر. تُظهر هذه الحادثة مخاطر استخدام الروبوتات الآلية في الأسواق الرقمية، خاصة عرضتها الهجمات التي تستهدف التلاعب بالموافقات. يجب على المتعاملين والمبرمجين التأكد من إعدادات الأذونات ومراجعة العمليات بدقة لتجنب الهجمات المشابهة. كما تثير الحادثة مخاوف حول أمن منصات التمويل اللامركزي، التي تعتمد بشكل كبير على العقود الذكية التي يتحكم فيها المستخدمون. من الناحية الاقتصادية، قد تؤدي هذه الكسرة إلى تراجع الثقة في الأنظمة الآلية، مما يدفع إلى دعوات لتعزيز عمليات التدقيق الأمني. يجب على المستثمرين في المنطقة العربية مراقبة التطورات المتعلقة بإطار العمل الأمني لـ __ والردود التنظيمية. تُعتبر هذه الحادثة تحذيرًا للتجار الأفراد والمؤسسات حول أهمية اتخاذ إجراءات أمنية متعددة الطبقات في إدارة الأصول الرقمية.
قد يعني هذا الهجوم تراجعًا في الثقة بمنصات التداول الآلي في سوق العملات الرقمية، مما يستدعي مراقبة أصول مثل WETH وUSDC وUSDT عن كثب. يُنصح المتعاملين بمراجعة إعدادات الأذونات وتجنب الموافقات غير الضرورية لضمان أمان محفظاتهم.
A $7.5 million exploit targeting Ethereum's 'sandwich' trading bot Jaredfromsubway.eth was executed by an attacker who tricked the bot into approving fake trading routes. Blockaid reported that the attacker used these approvals to drain Wrapped Ether (WETH), USDC, and USDT from the bot's wallet. The incident highlights vulnerabilities in decentralized finance (DeFi) protocols, where smart contract approvals can be exploited if not carefully managed.
This event underscores the risks associated with automated trading bots in crypto markets, particularly their susceptibility to social engineering and approval-based attacks. Traders and developers must remain vigilant about permission settings and transaction verifications to prevent similar exploits. The incident also raises concerns about the security of DeFi platforms, which rely heavily on user-controlled smart contracts.
For the broader crypto market, this breach could erode trust in automated systems and prompt calls for stricter security audits. Investors should monitor developments in DeFi security frameworks and regulatory responses. The attack serves as a cautionary tale for both retail and institutional participants about the importance of multi-layered security measures in digital asset management.
Blockaid said an attacker tricked Jaredfromsubway.eth into approving fake trading routes, then used those approvals to drain WETH, USDC and USDT.