{
  "meta": {
    "version": "2026.07.23.49",
    "updatedAt": "2026-07-23T06:35:53.389Z",
    "currency": "USD",
    "methodology": "Only verified public records are included in aggregate statistics. Unknown USD values are excluded from loss totals."
  },
  "incidents": [
    {
      "id": "DCI-2026-044",
      "status": "verified",
      "incidentDate": "2026-07-22",
      "datePrecision": "day",
      "title": {
        "zh": "183天前恶意Permit未撤销导致再次盗走75,780 USDC",
        "tw": "183天前惡意Permit未撤銷導致再次盜走75,780 USDC",
        "en": "Repeat theft through a 183-day-old malicious Permit"
      },
      "summary": {
        "zh": "本次约75,780 USDC已被转走。公开信息没有确认追回、冻结、交易所拦截或受害者完成全部授权撤销；后续资金路径仍待追踪。",
        "tw": "本次約75,780 USDC已被轉走。公開信息沒有確認追回、凍結、交易所攔截或受害者完成全部授權撤銷；後續資金路徑仍待追蹤。",
        "en": "An unrevoked Permit was reused to steal 75,780 USDC; the two known thefts total about 77,405 USDC."
      },
      "details": {
        "zh": "## 事件背景\n受害者约183天前签署了恶意Permit，首次被转走约1,625 USDC后没有撤销授权。Permit/allowance继续有效，攻击者不需要受害者再次签名；当受害钱包重新出现USDC时，钓鱼基础设施可以再次调用授权路径转走资金。\n\n该事件说明，第一次小额盗币后如果只更换前端或停止交互、却没有链上撤销Permit/allowance，恶意Spender仍保留长期提款权限。\n\n## 事件经过\n1. 约183天前，受害者签署恶意Permit，首次损失约1,625 USDC。\n2. 受害者事后没有撤销相关授权。\n3. 2026-07-22 08:10:23，恶意地址再次通过已存在的授权路径执行Ethereum交易。\n4. 本次约75,780 USDC被转走；两次公开金额合计约77,405 USDC。\n5. GoPlus公开受害者地址、三个钓鱼地址和完整交易。\n6. RPC显示交易From为恶意Spender，交易To为GoPlus列出的第二个钓鱼地址；具体内部USDC接收和后续归集仍应以完整Trace为准。\n\n## 资金流向\n受害者USDC通过未撤销的Permit/allowance被恶意Spender调用。当前确认的是受害者、恶意Spender、两个关联钓鱼地址及交易；后续是否进入混币器、跨链桥、交易所充值或OTC未有充分公开证据。\n\n## 金额口径\n183天前首次约1,625 USDC；本次约75,780 USDC；两次合计约77,405 USDC\n\n## 证据边界\nGoPlus将三个地址统称钓鱼地址，但没有在原帖中逐一拆分“最终收款、归集、控制器”角色。除交易From/To可由RPC确认外，其余两个地址只保留[钓鱼地址] [关联路径]，不猜测最终归集身份。\n\n## 处置状态\n本次约75,780 USDC已被转走。公开信息没有确认追回、冻结、交易所拦截或受害者完成全部授权撤销；后续资金路径仍待追踪。",
        "tw": "## 事件背景\n受害者約183天前簽署了惡意Permit，首次被轉走約1,625 USDC後沒有撤銷授權。Permit/allowance繼續有效，攻擊者不需要受害者再次簽名；當受害錢包重新出現USDC時，釣魚基礎設施可以再次調用授權路徑轉走資金。\n\n該事件說明，第一次小額盜幣後如果只更換前端或停止交互、卻沒有鏈上撤銷Permit/allowance，惡意Spender仍保留長期提款權限。\n\n## 事件經過\n1. 約183天前，受害者簽署惡意Permit，首次損失約1,625 USDC。\n2. 受害者事後沒有撤銷相關授權。\n3. 2026-07-22 08:10:23，惡意地址再次通過已存在的授權路徑執行Ethereum交易。\n4. 本次約75,780 USDC被轉走；兩次公開金額合計約77,405 USDC。\n5. GoPlus公開受害者地址、三個釣魚地址和完整交易。\n6. RPC顯示交易From為惡意Spender，交易To為GoPlus列出的第二個釣魚地址；具體內部USDC接收和後續歸集仍應以完整Trace為準。\n\n## 資金流向\n受害者USDC通過未撤銷的Permit/allowance被惡意Spender調用。當前確認的是受害者、惡意Spender、兩個關聯釣魚地址及交易；後續是否進入混幣器、跨鏈橋、交易所充值或OTC未有充分公開證據。\n\n## 金額口徑\n183天前首次約1,625 USDC；本次約75,780 USDC；兩次合計約77,405 USDC\n\n## 證據邊界\nGoPlus將三個地址統稱釣魚地址，但沒有在原帖中逐一拆分“最終收款、歸集、控制器”角色。除交易From/To可由RPC確認外，其餘兩個地址只保留[釣魚地址] [關聯路徑]，不猜測最終歸集身份。\n\n## 處置狀態\n本次約75,780 USDC已被轉走。公開信息沒有確認追回、凍結、交易所攔截或受害者完成全部授權撤銷；後續資金路徑仍待追蹤。",
        "en": "## Incident overview\nAn unrevoked Permit was reused to steal 75,780 USDC; the two known thefts total about 77,405 USDC.\n\n## Amount basis\nReported loss: $75,780\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "phishing-approval",
      "severity": "high",
      "ecosystems": [
        "Ethereum"
      ],
      "chains": [
        "Ethereum"
      ],
      "lossUsd": 75780,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "183天前首次约1,625 USDC；本次约75,780 USDC；两次合计约77,405 USDC",
        "tw": "183天前首次約1,625 USDC；本次約75,780 USDC；兩次合計約77,405 USDC",
        "en": "Reported loss: $75,780"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "Ethereum",
          "address": "0x13eF2275bE2aB18E18884065ea856cA8CCc6DbcF",
          "entity": {
            "zh": "[链：Ethereum] [受害地址] [恶意Permit受害者]",
            "tw": "[鏈：Ethereum] [受害地址] [惡意Permit受害者]",
            "en": "victim address documented by a public source"
          },
          "role": "victim",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/GoPlusSecurity/status/2079748522245824796",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [受害地址] [恶意Permit受害者]",
            "tw": "[鏈：Ethereum] [受害地址] [惡意Permit受害者]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0xAfb2423F447D3e16931164C9970B9741aAb1723E",
          "entity": {
            "zh": "[链：Ethereum] [钓鱼地址] [恶意Spender] [交易From] [授权盗币执行]",
            "tw": "[鏈：Ethereum] [釣魚地址] [惡意Spender] [交易From] [授權盜幣執行]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "scam",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/GoPlusSecurity/status/2079748522245824796",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [钓鱼地址] [恶意Spender] [交易From] [授权盗币执行]",
            "tw": "[鏈：Ethereum] [釣魚地址] [惡意Spender] [交易From] [授權盜幣執行]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0x187DCEDda3dAcFa1F3Bcd5468dE789F3c03F2490",
          "entity": {
            "zh": "[链：Ethereum] [钓鱼地址] [交易To] [具体收款角色待核]",
            "tw": "[鏈：Ethereum] [釣魚地址] [交易To] [具體收款角色待核]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "scam",
          "confidence": 0.65,
          "sourceUrl": "https://x.com/GoPlusSecurity/status/2079748522245824796",
          "evidenceStatus": "community_reported",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [钓鱼地址] [交易To] [具体收款角色待核]",
            "tw": "[鏈：Ethereum] [釣魚地址] [交易To] [具體收款角色待核]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0xAc09bBC4167D69543189b494c27c841F1c5dCdB7",
          "entity": {
            "zh": "[链：Ethereum] [钓鱼地址] [关联路径] [具体角色待核]",
            "tw": "[鏈：Ethereum] [釣魚地址] [關聯路徑] [具體角色待核]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "scam",
          "confidence": 0.65,
          "sourceUrl": "https://x.com/GoPlusSecurity/status/2079748522245824796",
          "evidenceStatus": "community_reported",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [钓鱼地址] [关联路径] [具体角色待核]",
            "tw": "[鏈：Ethereum] [釣魚地址] [關聯路徑] [具體角色待核]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "GoPlus Security完整原帖",
            "tw": "GoPlus Security完整原帖",
            "en": "x.com source"
          },
          "url": "https://x.com/GoPlusSecurity/status/2079748522245824796",
          "type": "research"
        },
        {
          "label": {
            "zh": "Etherscan盗币交易",
            "tw": "Etherscan盜幣交易",
            "en": "etherscan.io source"
          },
          "url": "https://etherscan.io/tx/0x35285c5b0b5a2a228b8d17aa69488a5ba6dc87b73264a3bc6f3e93759c6df09f",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-044",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-043",
      "status": "verified",
      "incidentDate": "2026-07-22",
      "datePrecision": "day",
      "title": {
        "zh": "42DAO / Balance Coin（BLC）预言机低价与即时清算攻击",
        "tw": "42DAO / Balance Coin（BLC）預言機低價與即時清算攻擊",
        "en": "42DAO / Balance Coin oracle liquidation attack"
      },
      "summary": {
        "zh": "确认发生约91.2万—91.5万美元攻击，BLC一度暴跌约99%。截至窗口结束，没有公开证据证明资金已冻结、追回或退还，也没有在已搜索到的项目官方X内容中取得正式处置公告。",
        "tw": "確認發生約91.2萬—91.5萬美元攻擊，BLC一度暴跌約99%。截至窗口結束，沒有公開證據證明資金已凍結、追回或退還，也沒有在已搜索到的項目官方X內容中取得正式處置公告。",
        "en": "An abnormally low BTCB oracle price triggered immediate liquidations, causing an estimated $912,000-$915,000 loss."
      },
      "details": {
        "zh": "## 事件背景\n42DAO采用Maker风格抵押债与清算架构：Median Oracle提供BTCB价格，Spotter通过poke把价格写入系统，Dog再通过bark对被判定为资不抵债的仓位执行清算。\n\n本次攻击的关键不是普通市场下跌，而是异常低BTCB价格被写入系统后立即生效。SlowMist指出Spotter缺少三类保护：\n\n1. 与前值之间的价格偏差检查；\n2. 最大回撤或单次变化上限；\n3. 最低价格保护。\n\n同时，Dog模块使用更新后的价格立即清算，没有清算延迟或二次预言机验证，导致多个BTCB抵押仓位在异常低价下被瞬时清算，攻击者捕获价差和抵押价值。\n\n## 事件经过\n1. 2026-07-22 05:00:01，成功攻击关联交易在BNB Chain区块111351152执行；交易From和To均为同一自调用主体。\n2. 攻击路径把异常低BTCB预言机价格经Spotter poke写入Vat。\n3. Dog使用该价格执行bark，多个BTCB仓位被立即判定可清算。\n4. SlowMist明确标记攻击者、受害者、Spotter和Dog合约；PeckShield报告BLC价格下跌约99%。\n5. 07:00:00另有一笔由SlowMist标记攻击者发起的自调用关联交易，但RPC回执状态为0，属于回滚/失败交易，不能写成成功的资金提取Tx。\n6. 安全机构估算损失约91.2万—91.5万美元。\n7. 截至本窗口19:00，未在42DAO官方X搜索中取得项目方处置、暂停、追回或赔付公告。\n\n## 资金流向\n已确认攻击通过错误低价和即时清算从BTCB抵押仓位捕获价值。SlowMist原帖给出攻击者和受害者地址，但没有在一条公开路径中完整披露后续兑换、跨链、混币器或交易所充值地址；这些下游路径保持[待核]，不猜补。\n\n## 金额口径\nSlowMist约912,000美元；PeckShield约915,000美元；两者为不同安全机构估值口径\n\n## 证据边界\n攻击存在、根因、金额区间、主攻击者、受害者、Spotter、Dog和成功关联Tx均已确认。未取得项目官方事后说明；后续归集、跨链、冻结、追回和赔付状态未确认。旧稿中把自调用地址直接等同SlowMist明确标记的主攻击者不准确，本报告已分开标注。\n\n## 处置状态\n确认发生约91.2万—91.5万美元攻击，BLC一度暴跌约99%。截至窗口结束，没有公开证据证明资金已冻结、追回或退还，也没有在已搜索到的项目官方X内容中取得正式处置公告。",
        "tw": "## 事件背景\n42DAO採用Maker風格抵押債與清算架構：Median Oracle提供BTCB價格，Spotter通過poke把價格寫入系統，Dog再通過bark對被判定為資不抵債的倉位執行清算。\n\n本次攻擊的關鍵不是普通市場下跌，而是異常低BTCB價格被寫入系統後立即生效。SlowMist指出Spotter缺少三類保護：\n\n1. 與前值之間的價格偏差檢查；\n2. 最大回撤或單次變化上限；\n3. 最低價格保護。\n\n同時，Dog模塊使用更新後的價格立即清算，沒有清算延遲或二次預言機驗證，導致多個BTCB抵押倉位在異常低價下被瞬時清算，攻擊者捕獲價差和抵押價值。\n\n## 事件經過\n1. 2026-07-22 05:00:01，成功攻擊關聯交易在BNB Chain區塊111351152執行；交易From和To均為同一自調用主體。\n2. 攻擊路徑把異常低BTCB預言機價格經Spotter poke寫入Vat。\n3. Dog使用該價格執行bark，多個BTCB倉位被立即判定可清算。\n4. SlowMist明確標記攻擊者、受害者、Spotter和Dog合約；PeckShield報告BLC價格下跌約99%。\n5. 07:00:00另有一筆由SlowMist標記攻擊者發起的自調用關聯交易，但RPC回執狀態為0，屬於回滾/失敗交易，不能寫成成功的資金提取Tx。\n6. 安全機構估算損失約91.2萬—91.5萬美元。\n7. 截至本窗口19:00，未在42DAO官方X搜索中取得項目方處置、暫停、追回或賠付公告。\n\n## 資金流向\n已確認攻擊通過錯誤低價和即時清算從BTCB抵押倉位捕獲價值。SlowMist原帖給出攻擊者和受害者地址，但沒有在一條公開路徑中完整披露後續兌換、跨鏈、混幣器或交易所充值地址；這些下游路徑保持[待核]，不猜補。\n\n## 金額口徑\nSlowMist約912,000美元；PeckShield約915,000美元；兩者為不同安全機構估值口徑\n\n## 證據邊界\n攻擊存在、根因、金額區間、主攻擊者、受害者、Spotter、Dog和成功關聯Tx均已確認。未取得項目官方事後說明；後續歸集、跨鏈、凍結、追回和賠付狀態未確認。舊稿中把自調用地址直接等同SlowMist明確標記的主攻擊者不準確，本報告已分開標註。\n\n## 處置狀態\n確認發生約91.2萬—91.5萬美元攻擊，BLC一度暴跌約99%。截至窗口結束，沒有公開證據證明資金已凍結、追回或退還，也沒有在已搜索到的項目官方X內容中取得正式處置公告。",
        "en": "## Incident overview\nAn abnormally low BTCB oracle price triggered immediate liquidations, causing an estimated $912,000-$915,000 loss.\n\n## Amount basis\nReported loss: $915,000\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "oracle-manipulation",
      "severity": "critical",
      "ecosystems": [
        "BNB Chain"
      ],
      "chains": [
        "BNB Chain"
      ],
      "lossUsd": 915000,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "SlowMist约912,000美元；PeckShield约915,000美元；两者为不同安全机构估值口径",
        "tw": "SlowMist約912,000美元；PeckShield約915,000美元；兩者為不同安全機構估值口徑",
        "en": "Reported loss: $915,000"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "BNB Chain",
          "address": "0x9d8dd9f2d734675e2bfcc142d1c7a45609ca213c",
          "entity": {
            "zh": "[链：BNB Chain] [黑客地址] [SlowMist明确标记攻击者] [后续资金路径待核]",
            "tw": "[鏈：BNB Chain] [黑客地址] [SlowMist明確標記攻擊者] [後續資金路徑待核]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.65,
          "sourceUrl": "https://x.com/SlowMist_Team/status/2079759793192132810",
          "evidenceStatus": "community_reported",
          "evidenceSummary": {
            "zh": "[链：BNB Chain] [黑客地址] [SlowMist明确标记攻击者] [后续资金路径待核]",
            "tw": "[鏈：BNB Chain] [黑客地址] [SlowMist明確標記攻擊者] [後續資金路徑待核]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0x973a722fd8bcd4b81f4c5c1ac687073e44aa9a0c",
          "entity": {
            "zh": "[链：BNB Chain] [受害地址] [SlowMist明确标记受害者]",
            "tw": "[鏈：BNB Chain] [受害地址] [SlowMist明確標記受害者]",
            "en": "victim address documented by a public source"
          },
          "role": "victim",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/SlowMist_Team/status/2079759793192132810",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain] [受害地址] [SlowMist明确标记受害者]",
            "tw": "[鏈：BNB Chain] [受害地址] [SlowMist明確標記受害者]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0x7b2e2dE172fd24c9158f6ECB77c05943CE47399D",
          "entity": {
            "zh": "[链：BNB Chain] [攻击执行地址] [成功Tx自调用主体] [与主攻击者关系待核]",
            "tw": "[鏈：BNB Chain] [攻擊執行地址] [成功Tx自調用主體] [與主攻擊者關係待核]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.65,
          "sourceUrl": "https://x.com/SlowMist_Team/status/2079759793192132810",
          "evidenceStatus": "community_reported",
          "evidenceSummary": {
            "zh": "[链：BNB Chain] [攻击执行地址] [成功Tx自调用主体] [与主攻击者关系待核]",
            "tw": "[鏈：BNB Chain] [攻擊執行地址] [成功Tx自調用主體] [與主攻擊者關係待核]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0x849dc2416cbe54995a1d725afe526c0e38829228",
          "entity": {
            "zh": "[链：BNB Chain] [受影响合约] [Spotter] [预言机价格写入] [非黑客]",
            "tw": "[鏈：BNB Chain] [受影響合約] [Spotter] [預言機價格寫入] [非黑客]",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/SlowMist_Team/status/2079759793192132810",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain] [受影响合约] [Spotter] [预言机价格写入] [非黑客]",
            "tw": "[鏈：BNB Chain] [受影響合約] [Spotter] [預言機價格寫入] [非黑客]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0x00101ae4467d72e83ef68df447c41de0c71f634e",
          "entity": {
            "zh": "[链：BNB Chain] [受影响合约] [Dog] [即时清算] [非黑客]",
            "tw": "[鏈：BNB Chain] [受影響合約] [Dog] [即時清算] [非黑客]",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/SlowMist_Team/status/2079759793192132810",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain] [受影响合约] [Dog] [即时清算] [非黑客]",
            "tw": "[鏈：BNB Chain] [受影響合約] [Dog] [即時清算] [非黑客]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0x5343b4586a3f2a3365df92ee705c3bf446c54668",
          "entity": {
            "zh": "[链：BNB Chain] [BLC代币合约] [市场暴跌关联] [非黑客]",
            "tw": "[鏈：BNB Chain] [BLC代幣合約] [市場暴跌關聯] [非黑客]",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/SlowMist_Team/status/2079759793192132810",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain] [BLC代币合约] [市场暴跌关联] [非黑客]",
            "tw": "[鏈：BNB Chain] [BLC代幣合約] [市場暴跌關聯] [非黑客]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0x7130d2a12b9bcbfae4f2634d864a1ee1ce3ead9c",
          "entity": {
            "zh": "[链：BNB Chain] [BTCB代币合约] [抵押资产] [非黑客]",
            "tw": "[鏈：BNB Chain] [BTCB代幣合約] [抵押資產] [非黑客]",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/SlowMist_Team/status/2079759793192132810",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain] [BTCB代币合约] [抵押资产] [非黑客]",
            "tw": "[鏈：BNB Chain] [BTCB代幣合約] [抵押資產] [非黑客]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "SlowMist根因、攻击者、受害者与合约",
            "tw": "SlowMist根因、攻擊者、受害者與合約",
            "en": "x.com source"
          },
          "url": "https://x.com/SlowMist_Team/status/2079759793192132810",
          "type": "research"
        },
        {
          "label": {
            "zh": "PeckShield损失与BLC跌幅",
            "tw": "PeckShield損失與BLC跌幅",
            "en": "x.com source"
          },
          "url": "https://x.com/PeckShieldAlert/status/2079751809183433197",
          "type": "research"
        },
        {
          "label": {
            "zh": "BscScan成功攻击关联交易",
            "tw": "BscScan成功攻擊關聯交易",
            "en": "bscscan.com source"
          },
          "url": "https://bscscan.com/tx/0xe7abe6416e386332b41d63cf5f16903251dc178942cd79bf080fe61058587628",
          "type": "research"
        },
        {
          "label": {
            "zh": "BscScan回滚关联交易",
            "tw": "BscScan回滾關聯交易",
            "en": "bscscan.com source"
          },
          "url": "https://bscscan.com/tx/0x3b26b3cb6b820a15b7216f07e6951de59990671f513bca62b40759c80ec42652",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-043",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-049",
      "status": "verified",
      "incidentDate": "2026-07-21",
      "datePrecision": "day",
      "title": {
        "zh": "美国司法部五项诈骗调查扣押超过2,500万美元加密资产",
        "tw": "美國司法部五項詐騙調查扣押超過2,500萬美元加密資產",
        "en": "U.S. DOJ seizes more than $25 million in five crypto-fraud investigations"
      },
      "summary": {
        "zh": "美国司法部在五项加密诈骗调查中控制超过2,500万美元资产，并提交民事没收诉状；公告未披露完整地址、交易哈希或具体链。",
        "tw": "美國司法部在五項加密詐騙調查中控制超過2,500萬美元資產，並提交民事沒收訴狀；公告未披露完整地址、交易哈希或具體鏈。",
        "en": "The U.S. Department of Justice controlled more than $25 million in assets across five crypto-fraud investigations and filed civil forfeiture complaints; no complete wallet list or chain-by-chain breakdown was published."
      },
      "details": {
        "zh": "## 事件背景\n五项调查涉及虚假加密投资平台、网络恋爱诈骗和“追回已盗资金”的二次诈骗。受害者被诱导向看似合法的投资账户或平台转账，随后无法提款、被切断联系，或再次被要求支付所谓追回费用。诈骗所得通过大量中间钱包混合、拆分和归集，部分网络位于东南亚。\n\n## 调查经过\n1. 调查一：加拿大方面在2024年底提供一组疑似洗钱钱包线索；调查人员冻结相关地址并追踪270多笔疑似受害者交易，诉状金额约10,400,913美元。\n2. 调查二：私营部门伙伴报告可疑交易；调查确认200多名网络恋爱诈骗受害者，资金经过数百个中间地址并与其他受害者资金混同，诉状金额约12,086,914美元。\n3. 调查三：2026年5月，一名华盛顿都会区受害者报告虚假加密投资骗局；无法提款后诈骗者失联，诉状金额约1,230,900美元。\n4. 调查四：2026年3月，另一名受害者向虚假投资账户转入数百万美元；调查又找到第二名受害者，部分资金追踪至六个地址并被冻结，诉状金额约2,392,231美元。\n5. 调查五：旧诈骗受害者遭“追回资金”二次诈骗，被要求支付费用；诉状金额约285,000美元。\n6. 2026-07-21，华盛顿特区联邦检察官办公室提交五项民事没收诉状，寻求没收已在调查中控制的加密资产。\n7. DOJ称五案涉及全球数千名受害者，洗钱者主要位于东南亚，相关IP位于中国、马来西亚和柬埔寨。\n\n## 资金流向\n共同路径为：受害者→虚假投资/恋爱诈骗收款地址→数百个中间钱包拆分、混同和洗钱→调查人员识别并冻结/扣押部分资产→联邦民事没收程序。公告没有公开完整地址、具体链、跨链桥、混币器或交易所充值路径，不能编造链上账本。\n\n## 金额口径\nDOJ标题口径“超过2,500万美元”；五项诉状列示约10,400,913、12,086,914、1,230,900、2,392,231和285,000美元，算术合计约26,395,958美元\n\n## 证据边界\nDOJ官方确认扣押和诉状金额，但公告没有附五案完整钱包地址、TxID、具体链、币种、冻结交易或最终没收判决。应区分“调查中扣押/冻结”“提交民事没收诉状”和“法院最终判决没收”；本报告不把诉状自动写成终局没收。\n\n## 处置状态\n资产已在五项调查中被控制并进入民事没收程序，调查仍在继续。DOJ称Scam Center Strike Force自2025年成立以来累计追回超过8亿美元，但该累计金额不是本次五案金额。",
        "tw": "## 事件背景\n五項調查涉及虛假加密投資平臺、網絡戀愛詐騙和“追回已盜資金”的二次詐騙。受害者被誘導向看似合法的投資賬戶或平臺轉賬，隨後無法提款、被切斷聯繫，或再次被要求支付所謂追回費用。詐騙所得通過大量中間錢包混合、拆分和歸集，部分網絡位於東南亞。\n\n## 調查經過\n1. 調查一：加拿大方面在2024年底提供一組疑似洗錢錢包線索；調查人員凍結相關地址並追蹤270多筆疑似受害者交易，訴狀金額約10,400,913美元。\n2. 調查二：私營部門夥伴報告可疑交易；調查確認200多名網絡戀愛詐騙受害者，資金經過數百個中間地址並與其他受害者資金混同，訴狀金額約12,086,914美元。\n3. 調查三：2026年5月，一名華盛頓都會區受害者報告虛假加密投資騙局；無法提款後詐騙者失聯，訴狀金額約1,230,900美元。\n4. 調查四：2026年3月，另一名受害者向虛假投資賬戶轉入數百萬美元；調查又找到第二名受害者，部分資金追蹤至六個地址並被凍結，訴狀金額約2,392,231美元。\n5. 調查五：舊詐騙受害者遭“追回資金”二次詐騙，被要求支付費用；訴狀金額約285,000美元。\n6. 2026-07-21，華盛頓特區聯邦檢察官辦公室提交五項民事沒收訴狀，尋求沒收已在調查中控制的加密資產。\n7. DOJ稱五案涉及全球數千名受害者，洗錢者主要位於東南亞，相關IP位於中國、馬來西亞和柬埔寨。\n\n## 資金流向\n共同路徑為：受害者→虛假投資/戀愛詐騙收款地址→數百個中間錢包拆分、混同和洗錢→調查人員識別並凍結/扣押部分資產→聯邦民事沒收程序。公告沒有公開完整地址、具體鏈、跨鏈橋、混幣器或交易所充值路徑，不能編造鏈上賬本。\n\n## 金額口徑\nDOJ標題口徑“超過2,500萬美元”；五項訴狀列示約10,400,913、12,086,914、1,230,900、2,392,231和285,000美元，算術合計約26,395,958美元\n\n## 證據邊界\nDOJ官方確認扣押和訴狀金額，但公告沒有附五案完整錢包地址、TxID、具體鏈、幣種、凍結交易或最終沒收判決。應區分“調查中扣押/凍結”“提交民事沒收訴狀”和“法院最終判決沒收”；本報告不把訴狀自動寫成終局沒收。\n\n## 處置狀態\n資產已在五項調查中被控制並進入民事沒收程序，調查仍在繼續。DOJ稱Scam Center Strike Force自2025年成立以來累計追回超過8億美元，但該累計金額不是本次五案金額。",
        "en": "## Incident overview\nThe five investigations cover fraudulent investment platforms, romance-investment fraud, and a secondary recovery scam.\n\n## Investigation sequence\n1. Canadian authorities supplied wallet leads tied to suspected laundering; investigators traced more than 270 suspected victim transactions and identified approximately $10.40 million.\n2. A private-sector referral led investigators to more than 200 romance-investment fraud victims and approximately $12.09 million moving through hundreds of intermediary addresses.\n3. A Washington-area victim reported a fraudulent investment platform in May 2026; the related complaint covers approximately $1.23 million.\n4. A separate March 2026 investigation traced victim funds to six addresses and covers approximately $2.39 million.\n5. A previous fraud victim was targeted again by a false asset-recovery scheme involving approximately $285,000.\n\n## Evidence boundary\nThe announcement does not publish complete addresses, transaction IDs, chains, or final forfeiture judgments. Seizure or control of assets and filing a civil forfeiture complaint must not be described as a final forfeiture judgment.\n\n## Current status\nThe assets are controlled within ongoing investigations and civil forfeiture proceedings. The task force cumulative recovery figure is not the amount recovered in these five cases."
      },
      "category": "enforcement",
      "severity": "high",
      "ecosystems": [
        "Multi-chain"
      ],
      "chains": [
        "Other"
      ],
      "lossUsd": null,
      "frozenUsd": 25000000,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "司法部公告：已扣押或控制超过2,500万美元；五项诉状列示金额合计约2,639.60万美元。",
        "tw": "司法部公告：已扣押或控制超過2,500萬美元；五項訴狀列示金額合計約2,639.60萬美元。",
        "en": "DOJ announcement: more than $25 million seized or controlled; five listed complaints total approximately $26.40 million."
      },
      "addressDisclosure": "not-published",
      "addresses": [],
      "references": [
        {
          "label": {
            "zh": "美国司法部官方公告",
            "tw": "美國司法部官方公告",
            "en": "justice.gov source"
          },
          "url": "https://www.justice.gov/usao-dc/pr/investigations-cryptocurrency-scams-result-seizure-more-25-million",
          "type": "official"
        },
        {
          "label": {
            "zh": "窗口内X传播线索",
            "tw": "窗口內X傳播線索",
            "en": "x.com source"
          },
          "url": "https://x.com/CryptoBreakNews/status/2079881244754505930",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-049",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-042",
      "status": "verified",
      "incidentDate": "2026-07-21",
      "datePrecision": "day",
      "title": {
        "zh": "Ethereum地址93,594.16806 USDT被Tether列入黑名单",
        "tw": "Ethereum地址93,594.16806 USDT被Tether列入黑名單",
        "en": "Tether blacklists 93,594 USDT on Ethereum"
      },
      "summary": {
        "zh": "93,594.16806 USDT仍显示在目标地址，但已进入Tether黑名单控制状态；未发现公开的解冻、转移、司法没收终局或地址归因公告。",
        "tw": "93,594.16806 USDT仍顯示在目標地址，但已進入Tether黑名單控制狀態；未發現公開的解凍、轉移、司法沒收終局或地址歸因公告。",
        "en": "Tether blacklisted an Ethereum address holding 93,594.16806 USDT; the reason and entity attribution remain undisclosed."
      },
      "details": {
        "zh": "## 事件背景\nTether发行的Ethereum版USDT带有中心化黑名单控制。获授权的执行主体可以通过USDT合约的黑名单机制，使目标地址继续保有链上余额，但无法再通过USDT合约正常转移该余额。本事件是发行方合约级冻结，不是黑客转走资产，也没有公开证据证明法院、警方或其他司法机关已经取得钱包控制权。\n\n## 事件经过\n1. 2026-07-21 21:40:11（北京时间），Ethereum交易被打包。\n2. 交易回执中，USDT主合约发出黑名单事件；事件数据指向目标地址。\n3. Chain Sentinel于21:41披露该地址约93,594 USDT被列入黑名单。\n4. 使用Ethereum RPC读取USDT余额，目标地址当前余额为93,594.16806 USDT。\n5. 公开原帖没有披露冻结原因、案件编号、执法机构或地址实体归属，因此不能标为司法扣押、汇旺、诈骗归集或黑客地址。\n\n## 资金流向\n资金未在本次动作中转往Tether或执法钱包；原地址仍显示93,594.16806 USDT余额，但USDT合约层已限制其转出。资金状态应写为“原地址余额被发行方黑名单锁定”，不是“已转入司法托管”。\n\n## 金额口径\n目标地址USDT余额93,594.16806枚；这是被冻结余额，不等于被盗金额、司法扣押金额或用户最终损失\n\n## 证据边界\n已确认链、目标地址、执行交易、USDT主合约黑名单日志和余额。冻结原因、地址主体、是否与诈骗/制裁/司法案件相关均未公开，统一标记[归因待核]。\n\n## 处置状态\n93,594.16806 USDT仍显示在目标地址，但已进入Tether黑名单控制状态；未发现公开的解冻、转移、司法没收终局或地址归因公告。",
        "tw": "## 事件背景\nTether發行的Ethereum版USDT帶有中心化黑名單控制。獲授權的執行主體可以通過USDT合約的黑名單機制，使目標地址繼續保有鏈上餘額，但無法再通過USDT合約正常轉移該餘額。本事件是發行方合約級凍結，不是黑客轉走資產，也沒有公開證據證明法院、警方或其他司法機關已經取得錢包控制權。\n\n## 事件經過\n1. 2026-07-21 21:40:11（北京時間），Ethereum交易被打包。\n2. 交易回執中，USDT主合約發出黑名單事件；事件數據指向目標地址。\n3. Chain Sentinel於21:41披露該地址約93,594 USDT被列入黑名單。\n4. 使用Ethereum RPC讀取USDT餘額，目標地址當前餘額為93,594.16806 USDT。\n5. 公開原帖沒有披露凍結原因、案件編號、執法機構或地址實體歸屬，因此不能標為司法扣押、匯旺、詐騙歸集或黑客地址。\n\n## 資金流向\n資金未在本次動作中轉往Tether或執法錢包；原地址仍顯示93,594.16806 USDT餘額，但USDT合約層已限制其轉出。資金狀態應寫為“原地址餘額被髮行方黑名單鎖定”，不是“已轉入司法託管”。\n\n## 金額口徑\n目標地址USDT餘額93,594.16806枚；這是被凍結餘額，不等於被盜金額、司法扣押金額或用戶最終損失\n\n## 證據邊界\n已確認鏈、目標地址、執行交易、USDT主合約黑名單日誌和餘額。凍結原因、地址主體、是否與詐騙/制裁/司法案件相關均未公開，統一標記[歸因待核]。\n\n## 處置狀態\n93,594.16806 USDT仍顯示在目標地址，但已進入Tether黑名單控制狀態；未發現公開的解凍、轉移、司法沒收終局或地址歸因公告。",
        "en": "## Incident overview\nTether blacklisted an Ethereum address holding 93,594.16806 USDT; the reason and entity attribution remain undisclosed.\n\n## Amount basis\n93,594.16806 USDT blacklisted by the issuer; this is a freeze, not a theft loss.\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "issuer-freeze",
      "severity": "medium",
      "ecosystems": [
        "Ethereum"
      ],
      "chains": [
        "Ethereum"
      ],
      "lossUsd": null,
      "frozenUsd": 93594.16806,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "目标地址USDT余额93,594.16806枚；这是被冻结余额，不等于被盗金额、司法扣押金额或用户最终损失",
        "tw": "目標地址USDT餘額93,594.16806枚；這是被凍結餘額，不等於被盜金額、司法扣押金額或用戶最終損失",
        "en": "93,594.16806 USDT blacklisted by the issuer; this is a freeze, not a theft loss."
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "Ethereum",
          "address": "0xE0d7E4eD38D251799d30fE389cD8D6a5Cd5e8a79",
          "entity": {
            "zh": "[链：Ethereum] [被冻地址] [稳定币冻结] [发行方黑名单] [归因待核]",
            "tw": "[鏈：Ethereum] [被凍地址] [穩定幣凍結] [發行方黑名單] [歸因待核]",
            "en": "other address documented by a public source"
          },
          "role": "other",
          "category": "issuer_restricted",
          "confidence": 0.65,
          "sourceUrl": "https://x.com/chainsen_io/status/2079562329201529049",
          "evidenceStatus": "community_reported",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [被冻地址] [稳定币冻结] [发行方黑名单] [归因待核]",
            "tw": "[鏈：Ethereum] [被凍地址] [穩定幣凍結] [發行方黑名單] [歸因待核]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0xdAC17F958D2ee523a2206206994597C13D831ec7",
          "entity": {
            "zh": "[链：Ethereum] [USDT发行方合约] [黑名单机制] [非黑客]",
            "tw": "[鏈：Ethereum] [USDT發行方合約] [黑名單機制] [非黑客]",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/chainsen_io/status/2079562329201529049",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [USDT发行方合约] [黑名单机制] [非黑客]",
            "tw": "[鏈：Ethereum] [USDT發行方合約] [黑名單機制] [非黑客]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0xc6cde7c39eb2f0f0095f41570af89efc2c1ea828",
          "entity": {
            "zh": "[链：Ethereum] [黑名单执行合约] [交易To] [具体治理身份待核]",
            "tw": "[鏈：Ethereum] [黑名單執行合約] [交易To] [具體治理身份待核]",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "unknown",
          "confidence": 0.65,
          "sourceUrl": "https://x.com/chainsen_io/status/2079562329201529049",
          "evidenceStatus": "community_reported",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [黑名单执行合约] [交易To] [具体治理身份待核]",
            "tw": "[鏈：Ethereum] [黑名單執行合約] [交易To] [具體治理身份待核]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0xac3b242e2e561da9f4ce34746e67d004e6341fa0",
          "entity": {
            "zh": "[链：Ethereum] [执行发起地址] [交易From] [具体治理身份待核]",
            "tw": "[鏈：Ethereum] [執行發起地址] [交易From] [具體治理身份待核]",
            "en": "other address documented by a public source"
          },
          "role": "other",
          "category": "unknown",
          "confidence": 0.65,
          "sourceUrl": "https://x.com/chainsen_io/status/2079562329201529049",
          "evidenceStatus": "community_reported",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [执行发起地址] [交易From] [具体治理身份待核]",
            "tw": "[鏈：Ethereum] [執行發起地址] [交易From] [具體治理身份待核]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "Chain Sentinel原帖",
            "tw": "Chain Sentinel原帖",
            "en": "x.com source"
          },
          "url": "https://x.com/chainsen_io/status/2079562329201529049",
          "type": "research"
        },
        {
          "label": {
            "zh": "Etherscan黑名单执行交易",
            "tw": "Etherscan黑名單執行交易",
            "en": "etherscan.io source"
          },
          "url": "https://etherscan.io/tx/0x7f97b8fb37c6d0b1a1b7d2d302a49b34fbab6ba12b201d45deb0ace81f7222c9",
          "type": "research"
        },
        {
          "label": {
            "zh": "Etherscan被冻地址",
            "tw": "Etherscan被凍地址",
            "en": "etherscan.io source"
          },
          "url": "https://etherscan.io/address/0xE0d7E4eD38D251799d30fE389cD8D6a5Cd5e8a79",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-042",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-041",
      "status": "verified",
      "incidentDate": "2026-07-21",
      "datePrecision": "day",
      "title": {
        "zh": "Wanchain Cardano—BNB Chain桥NIGHT事件",
        "tw": "Wanchain Cardano—BNB Chain橋NIGHT事件",
        "en": "Wanchain Cardano-BNB Chain NIGHT bridge incident"
      },
      "summary": {
        "zh": "影响局限于Wanchain第三方桥，不是Midnight主链本身被攻破。多家交易所对相关账户或资产采取限制，但未公开完整冻结充值地址。",
        "tw": "影響侷限於Wanchain第三方橋，不是Midnight主鏈本身被攻破。多家交易所對相關賬戶或資產採取限制，但未公開完整凍結充值地址。",
        "en": "About 515 million NIGHT tokens were exposed; realized swaps and the reported nominal $9-13 million exposure are recorded separately."
      },
      "details": {
        "zh": "## 事件背景\n问题出在 Wanchain 第三方桥的 Cardano 侧 TreasuryCheck 验证器，而不是 Midnight/Cardano 核心共识：\n\n1. 签名消息由 14 个可变长度字段 通过原始字节拼接（AppendByteString fold）生成；\n2. 没有 固定字段长度前缀或分隔符 → 编码 非单射（non-injective）；\n3. 不同字段边界/取值组合可以哈希出 相同 的待签消息，从而 复用 一笔本只授权约 3,110 NIGHT 的合法 BSC 侧签名；\n4. 在 Cardano 端用同一签名构造恶意 redeemer，单笔提出约 203,001,692 NIGHT，放大约 65,000 倍；\n5. 多批次累计抽走桥金库约 5.15 亿 NIGHT（桥储备从约 5.27 亿降至约 0.12 亿量级的公开叙述）。\n\n因此：Midnight 主网可仍安全，但 BSC 上 wrapped NIGHT 可能严重欠抵押；媒体按币价估的「千万美元」是名义敞口，不等于攻击者已全部套现。\n\n## 事件经过\n1. 7 月 21 日 13:47（北京时间）BlockSec Phalcon 等率先报警。\n2. 约 13:51 Wanchain 官方确认 Cardano–BNB 桥安全事件。\n3. CertiK 等随后给出地址与金额分析（约 14:58）。\n4. 攻击者复用小额合法签名，在 Cardano 端超额提取 NIGHT 至黑客地址。\n5. 部分 NIGHT 兑换 ADA（公开一笔约 2.03 亿 NIGHT → 约 283 万 ADA）；NIGHT 价格大幅下跌。\n6. 桥被下线；Midnight Foundation 强调主网/验证者未受影响；部分交易所限制关联账户。\n\n## 资金流向\n2. 约 13:51 Wanchain 官方确认 Cardano–BNB 桥安全事件。\n5. 部分 NIGHT 兑换 ADA（公开一笔约 2.03 亿 NIGHT → 约 283 万 ADA）；NIGHT 价格大幅下跌。\n6. 桥被下线；Midnight Foundation 强调主网/验证者未受影响；部分交易所限制关联账户。\n\n## 金额口径\n累计约5.15亿枚NIGHT；其中一笔203,001,692 NIGHT换成2,831,361 ADA；名义市值媒体有约900万—1300万美元差；已实现兑换与名义敞口必须分开写\n\n## 证据边界\n以公开可核验来源为界；未证实细节不写入确定结论。\n\n## 处置状态\n影响局限于Wanchain第三方桥，不是Midnight主链本身被攻破。多家交易所对相关账户或资产采取限制，但未公开完整冻结充值地址。",
        "tw": "## 事件背景\n問題出在 Wanchain 第三方橋的 Cardano 側 TreasuryCheck 驗證器，而不是 Midnight/Cardano 核心共識：\n\n1. 簽名消息由 14 個可變長度字段 通過原始字節拼接（AppendByteString fold）生成；\n2. 沒有 固定字段長度前綴或分隔符 → 編碼 非單射（non-injective）；\n3. 不同字段邊界/取值組合可以哈希出 相同 的待籤消息，從而 複用 一筆本只授權約 3,110 NIGHT 的合法 BSC 側簽名；\n4. 在 Cardano 端用同一簽名構造惡意 redeemer，單筆提出約 203,001,692 NIGHT，放大約 65,000 倍；\n5. 多批次累計抽走橋金庫約 5.15 億 NIGHT（橋儲備從約 5.27 億降至約 0.12 億量級的公開敘述）。\n\n因此：Midnight 主網可仍安全，但 BSC 上 wrapped NIGHT 可能嚴重欠抵押；媒體按幣價估的「千萬美元」是名義敞口，不等於攻擊者已全部套現。\n\n## 事件經過\n1. 7 月 21 日 13:47（北京時間）BlockSec Phalcon 等率先報警。\n2. 約 13:51 Wanchain 官方確認 Cardano–BNB 橋安全事件。\n3. CertiK 等隨後給出地址與金額分析（約 14:58）。\n4. 攻擊者複用小額合法簽名，在 Cardano 端超額提取 NIGHT 至黑客地址。\n5. 部分 NIGHT 兌換 ADA（公開一筆約 2.03 億 NIGHT → 約 283 萬 ADA）；NIGHT 價格大幅下跌。\n6. 橋被下線；Midnight Foundation 強調主網/驗證者未受影響；部分交易所限制關聯賬戶。\n\n## 資金流向\n2. 約 13:51 Wanchain 官方確認 Cardano–BNB 橋安全事件。\n5. 部分 NIGHT 兌換 ADA（公開一筆約 2.03 億 NIGHT → 約 283 萬 ADA）；NIGHT 價格大幅下跌。\n6. 橋被下線；Midnight Foundation 強調主網/驗證者未受影響；部分交易所限制關聯賬戶。\n\n## 金額口徑\n累計約5.15億枚NIGHT；其中一筆203,001,692 NIGHT換成2,831,361 ADA；名義市值媒體有約900萬—1300萬美元差；已實現兌換與名義敞口必須分開寫\n\n## 證據邊界\n以公開可核驗來源為界；未證實細節不寫入確定結論。\n\n## 處置狀態\n影響侷限於Wanchain第三方橋，不是Midnight主鏈本身被攻破。多家交易所對相關賬戶或資產採取限制，但未公開完整凍結充值地址。",
        "en": "## Incident overview\nAbout 515 million NIGHT tokens were exposed; realized swaps and the reported nominal $9-13 million exposure are recorded separately.\n\n## Amount basis\nReported loss: $9,000,000\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "bridge-exploit",
      "severity": "critical",
      "ecosystems": [
        "BNB Chain",
        "Cardano"
      ],
      "chains": [
        "BNB Chain",
        "Cardano"
      ],
      "lossUsd": 9000000,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "累计约5.15亿枚NIGHT；其中一笔203,001,692 NIGHT换成2,831,361 ADA；名义市值媒体有约900万—1300万美元差；**已实现兑换**与**名义敞口**必须分开写",
        "tw": "累計約5.15億枚NIGHT；其中一筆203,001,692 NIGHT換成2,831,361 ADA；名義市值媒體有約900萬—1300萬美元差；**已實現兌換**與**名義敞口**必須分開寫",
        "en": "Reported loss: $9,000,000"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "Cardano",
          "address": "addr1qysj48kpy8qra2g64scvu79n489qrv2uys5ggsrun29v5f5udqxfpr7x0pqfl6khjwv6vm0k8s3spn6h0zfrwszfqgcqeld8kj",
          "entity": {
            "zh": "[链：Cardano] [黑客地址] [Cardano被盗资产接收] [NIGHT换ADA] [资金归集]",
            "tw": "[鏈：Cardano] [黑客地址] [Cardano被盜資產接收] [NIGHT換ADA] [資金歸集]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/Phalcon_xyz/status/2079451633847783655",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Cardano] [黑客地址] [Cardano被盗资产接收] [NIGHT换ADA] [资金归集]",
            "tw": "[鏈：Cardano] [黑客地址] [Cardano被盜資產接收] [NIGHT換ADA] [資金歸集]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0xFe930c2d63AeD9b82fC4DBC801920dD2c1a3224F",
          "entity": {
            "zh": "[链：BNB Chain] [Midnight NIGHT代币合约] [合法桥前请求tokenAccount]，不是黑客地址。",
            "tw": "[鏈：BNB Chain] [Midnight NIGHT代幣合約] [合法橋前請求tokenAccount]，不是黑客地址。",
            "en": "bridge address documented by a public source"
          },
          "role": "bridge",
          "category": "bridge",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/Phalcon_xyz/status/2079451633847783655",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain] [Midnight NIGHT代币合约] [合法桥前请求tokenAccount]，不是黑客地址。",
            "tw": "[鏈：BNB Chain] [Midnight NIGHT代幣合約] [合法橋前請求tokenAccount]，不是黑客地址。",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "BlockSec根因",
            "tw": "BlockSec根因",
            "en": "x.com source"
          },
          "url": "https://x.com/Phalcon_xyz/status/2079451633847783655",
          "type": "research"
        },
        {
          "label": {
            "zh": "BlockSec初报",
            "tw": "BlockSec初報",
            "en": "x.com source"
          },
          "url": "https://x.com/Phalcon_xyz/status/2079443108027421183",
          "type": "research"
        },
        {
          "label": {
            "zh": "CertiK地址与金额",
            "tw": "CertiK地址與金額",
            "en": "x.com source"
          },
          "url": "https://x.com/CertiKAlert/status/2079461015495053624",
          "type": "research"
        },
        {
          "label": {
            "zh": "Wanchain官方公告",
            "tw": "Wanchain官方公告",
            "en": "x.com source"
          },
          "url": "https://x.com/wanchain_org/status/2079444149066244340",
          "type": "official"
        },
        {
          "label": {
            "zh": "Cardanoscan",
            "tw": "Cardanoscan",
            "en": "cardanoscan.io source"
          },
          "url": "https://cardanoscan.io/address/addr1qysj48kpy8qra2g64scvu79n489qrv2uys5ggsrun29v5f5udqxfpr7x0pqfl6khjwv6vm0k8s3spn6h0zfrwszfqgcqeld8kj",
          "type": "research"
        },
        {
          "label": {
            "zh": "BscScan：Midnight NIGHT Token",
            "tw": "BscScan：Midnight NIGHT Token",
            "en": "bscscan.com source"
          },
          "url": "https://bscscan.com/address/0xFe930c2d63AeD9b82fC4DBC801920dD2c1a3224F",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-041",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-040",
      "status": "verified",
      "incidentDate": "2026-07-20",
      "datePrecision": "day",
      "title": {
        "zh": "恶意TRAE IDE扩展",
        "tw": "惡意TRAE IDE擴展",
        "en": "Malicious TRAE IDE extension"
      },
      "summary": {
        "zh": "恶意扩展被披露；开发者需卸载并轮换所有可能暴露的密钥。",
        "tw": "惡意擴展被披露；開發者需卸載並輪換所有可能暴露的密鑰。",
        "en": "A malicious IDE extension targeted developer credentials and wallet material through the software supply chain."
      },
      "details": {
        "zh": "## 事件背景\n开发者 IDE 扩展拥有读取工作区、环境变量甚至执行脚本的高权限。恶意扩展 juannegro.solidity 伪装成 Solidity 插件：\n\n1. 在 Open VSX 下架后，仍可能从 TRAE 应用市场 等渠道被获取；\n2. 安装后充当跨平台恶意软件投放器；\n3. 目标包括源代码、.env、RPC Key、部署私钥、浏览器/桌面钱包凭证。\n\n攻击面在 开发者终端，不依赖某一条公链的合约漏洞；一旦私钥外泄，后续盗币可发生在任意链。\n\n## 事件经过\n1. SlowMist 披露 TRAE 市场仍可获取已在其他市场下架的恶意 Solidity 扩展。\n2. 扩展安装后投放信息窃取/远控类载荷。\n3. 可窃取源码、环境变量、RPC 与部署密钥、钱包数据。\n4. 公开渠道未给出统一链上归集地址与总损失。\n5. 处置：卸载扩展、轮换全部可能暴露的密钥、审计近期部署与授权。\n\n## 资金流向\n4. 公开渠道未给出统一链上归集地址与总损失。\n\n## 金额口径\n未公开统一链上损失\n\n## 证据边界\n以公开可核验来源为界；未证实细节不写入确定结论。\n\n## 处置状态\n恶意扩展被披露；开发者需卸载并轮换所有可能暴露的密钥。",
        "tw": "## 事件背景\n開發者 IDE 擴展擁有讀取工作區、環境變量甚至執行腳本的高權限。惡意擴展 juannegro.solidity 偽裝成 Solidity 插件：\n\n1. 在 Open VSX 下架後，仍可能從 TRAE 應用市場 等渠道被獲取；\n2. 安裝後充當跨平臺惡意軟件投放器；\n3. 目標包括源代碼、.env、RPC Key、部署私鑰、瀏覽器/桌面錢包憑證。\n\n攻擊面在 開發者終端，不依賴某一條公鏈的合約漏洞；一旦私鑰外洩，後續盜幣可發生在任意鏈。\n\n## 事件經過\n1. SlowMist 披露 TRAE 市場仍可獲取已在其他市場下架的惡意 Solidity 擴展。\n2. 擴展安裝後投放信息竊取/遠控類載荷。\n3. 可竊取源碼、環境變量、RPC 與部署密鑰、錢包數據。\n4. 公開渠道未給出統一鏈上歸集地址與總損失。\n5. 處置：卸載擴展、輪換全部可能暴露的密鑰、審計近期部署與授權。\n\n## 資金流向\n4. 公開渠道未給出統一鏈上歸集地址與總損失。\n\n## 金額口徑\n未公開統一鏈上損失\n\n## 證據邊界\n以公開可核驗來源為界；未證實細節不寫入確定結論。\n\n## 處置狀態\n惡意擴展被披露；開發者需卸載並輪換所有可能暴露的密鑰。",
        "en": "## Incident overview\nA malicious IDE extension targeted developer credentials and wallet material through the software supply chain.\n\n## Amount basis\nNo single verified USD loss figure was published; see the incident record.\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "supply-chain",
      "severity": "medium",
      "ecosystems": [
        "Other"
      ],
      "chains": [
        "Other"
      ],
      "lossUsd": null,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "未公开统一链上损失",
        "tw": "未公開統一鏈上損失",
        "en": "No single verified USD loss figure was published; see the incident record."
      },
      "addressDisclosure": "not-published",
      "addresses": [],
      "references": [
        {
          "label": {
            "zh": "SlowMist原帖",
            "tw": "SlowMist原帖",
            "en": "x.com source"
          },
          "url": "https://x.com/SlowMist_Team/status/2079121338053378515",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-040",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-039",
      "status": "verified",
      "incidentDate": "2026-07-20",
      "datePrecision": "day",
      "title": {
        "zh": "Zilliqa合作交易所冷钱包被盗",
        "tw": "Zilliqa合作交易所冷錢包被盜",
        "en": "Zilliqa partner exchange cold-wallet theft"
      },
      "summary": {
        "zh": "交易所充提被临时限制；调查继续。用户侧应区分「公链被黑」与「合作托管方失陷」。",
        "tw": "交易所充提被臨時限制；調查繼續。用戶側應區分「公鏈被黑」與「合作託管方失陷」。",
        "en": "A cold wallet operated by a Zilliqa partner exchange was compromised; the cited sources did not establish one USD loss figure."
      },
      "details": {
        "zh": "## 事件背景\nZilliqa 官方确认：被盗的是 某合作交易所的离线冷钱包，不是 Zilliqa L1 共识、验证者集合或主网协议逻辑被攻破。冷钱包失陷通常意味着：\n\n1. 冷钱包私钥/助记词保管失当；\n2. 签名设备（HSM、多签协调机、气隙机）被入侵或被内部滥用；\n3. 提币/签名流程被社工或恶意运维绕过。\n\n链上表现是「未授权的 ZIL 转出」，根因在 托管运营环境，故项目方第一反应是全网交易所暂停 ZIL 充提，防止赃币流入二级市场。\n\n## 事件经过\n1. 合作交易所冷钱包出现未经授权的 ZIL 转账。\n2. Zilliqa 官方披露并定性为合作方托管事故，非核心网络漏洞。\n3. 要求各交易所暂停 ZIL 充值与提现，切断变现路径。\n4. 受害交易所名称、金额、黑客地址、TxID 均未在公开渠道给出完整可核验清单 → 不猜补。\n5. 调查持续；充提限制为临时风控。\n\n## 资金流向\n见事件经过；无独立可拆资金路径时以地址与交易章节为准。\n\n## 金额口径\n金额未公开\n\n## 证据边界\n完整地址/Tx 不足时不猜补。\n\n## 处置状态\n交易所充提被临时限制；调查继续。用户侧应区分「公链被黑」与「合作托管方失陷」。",
        "tw": "## 事件背景\nZilliqa 官方確認：被盜的是 某合作交易所的離線冷錢包，不是 Zilliqa L1 共識、驗證者集合或主網協議邏輯被攻破。冷錢包失陷通常意味著：\n\n1. 冷錢包私鑰/助記詞保管失當；\n2. 簽名設備（HSM、多籤協調機、氣隙機）被入侵或被內部濫用；\n3. 提幣/簽名流程被社工或惡意運維繞過。\n\n鏈上表現是「未授權的 ZIL 轉出」，根因在 託管運營環境，故項目方第一反應是全網交易所暫停 ZIL 充提，防止贓幣流入二級市場。\n\n## 事件經過\n1. 合作交易所冷錢包出現未經授權的 ZIL 轉賬。\n2. Zilliqa 官方披露並定性為合作方託管事故，非核心網絡漏洞。\n3. 要求各交易所暫停 ZIL 充值與提現，切斷變現路徑。\n4. 受害交易所名稱、金額、黑客地址、TxID 均未在公開渠道給出完整可核驗清單 → 不猜補。\n5. 調查持續；充提限制為臨時風控。\n\n## 資金流向\n見事件經過；無獨立可拆資金路徑時以地址與交易章節為準。\n\n## 金額口徑\n金額未公開\n\n## 證據邊界\n完整地址/Tx 不足時不猜補。\n\n## 處置狀態\n交易所充提被臨時限制；調查繼續。用戶側應區分「公鏈被黑」與「合作託管方失陷」。",
        "en": "## Incident overview\nA cold wallet operated by a Zilliqa partner exchange was compromised; the cited sources did not establish one USD loss figure.\n\n## Amount basis\nNo single verified USD loss figure was published; see the incident record.\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "key-compromise",
      "severity": "medium",
      "ecosystems": [
        "Zilliqa"
      ],
      "chains": [
        "Zilliqa"
      ],
      "lossUsd": null,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "金额未公开",
        "tw": "金額未公開",
        "en": "No single verified USD loss figure was published; see the incident record."
      },
      "addressDisclosure": "not-published",
      "addresses": [],
      "references": [
        {
          "label": {
            "zh": "Zilliqa官方公告",
            "tw": "Zilliqa官方公告",
            "en": "x.com source"
          },
          "url": "https://x.com/zilliqa/status/2079148672122818621",
          "type": "official"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-039",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-038",
      "status": "verified",
      "incidentDate": "2026-07-20",
      "datePrecision": "day",
      "title": {
        "zh": "一年前恶意Approve延迟盗币",
        "tw": "一年前惡意Approve延遲盜幣",
        "en": "Delayed theft from a year-old malicious approval"
      },
      "summary": {
        "zh": "约8.4万美元USDT被转走；同一钓鱼基础设施还出现在7月22日的Permit事件中。",
        "tw": "約8.4萬美元USDT被轉走；同一釣魚基礎設施還出現在7月22日的Permit事件中。",
        "en": "An approval granted about a year earlier was used to steal approximately $84,000 after funds returned to the victim wallet."
      },
      "details": {
        "zh": "## 事件背景\n典型 沉睡授权（sleeping allowance） 攻击：\n\n1. 受害者很早前在钓鱼站签过 USDT approve（spender 为攻击者合约/EOA）；\n2. 当时钱包 USDT 不多或已被小额偷过，受害者未 revoke；\n3. 授权在链上永久有效（除非主动 revoke 或花光 allowance）；\n4. 当受害者再次转入大额 USDT，攻击者 无需新签名 即可 transferFrom。\n\n与「当场钓鱼」不同，这是 时间延迟收割。\n\n## 事件经过\n1. 约一年前受害者签下恶意 USDT Approve。\n2. 授权长期未撤销。\n3. 7 月 20 日前后钱包重新出现 USDT 余额。\n4. 钓鱼 spender 0xAfb2…723E 转走约 8.4 万美元 USDT。\n5. 同一钓鱼基础设施在 7 月 22 日 Permit 案再次出现。\n\n## 资金流向\n见事件经过；无独立可拆资金路径时以地址与交易章节为准。\n\n## 金额口径\n约8.4万美元USDT\n\n## 证据边界\n以公开可核验来源为界；未证实细节不写入确定结论。\n\n## 处置状态\n约8.4万美元USDT被转走；同一钓鱼基础设施还出现在7月22日的Permit事件中。",
        "tw": "## 事件背景\n典型 沉睡授權（sleeping allowance） 攻擊：\n\n1. 受害者很早前在釣魚站簽過 USDT approve（spender 為攻擊者合約/EOA）；\n2. 當時錢包 USDT 不多或已被小額偷過，受害者未 revoke；\n3. 授權在鏈上永久有效（除非主動 revoke 或花光 allowance）；\n4. 當受害者再次轉入大額 USDT，攻擊者 無需新簽名 即可 transferFrom。\n\n與「當場釣魚」不同，這是 時間延遲收割。\n\n## 事件經過\n1. 約一年前受害者簽下惡意 USDT Approve。\n2. 授權長期未撤銷。\n3. 7 月 20 日前後錢包重新出現 USDT 餘額。\n4. 釣魚 spender 0xAfb2…723E 轉走約 8.4 萬美元 USDT。\n5. 同一釣魚基礎設施在 7 月 22 日 Permit 案再次出現。\n\n## 資金流向\n見事件經過；無獨立可拆資金路徑時以地址與交易章節為準。\n\n## 金額口徑\n約8.4萬美元USDT\n\n## 證據邊界\n以公開可核驗來源為界；未證實細節不寫入確定結論。\n\n## 處置狀態\n約8.4萬美元USDT被轉走；同一釣魚基礎設施還出現在7月22日的Permit事件中。",
        "en": "## Incident overview\nAn approval granted about a year earlier was used to steal approximately $84,000 after funds returned to the victim wallet.\n\n## Amount basis\nReported loss: $84,000\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "phishing-approval",
      "severity": "high",
      "ecosystems": [
        "Ethereum"
      ],
      "chains": [
        "Ethereum"
      ],
      "lossUsd": 84000,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "约8.4万美元USDT",
        "tw": "約8.4萬美元USDT",
        "en": "Reported loss: $84,000"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "Ethereum",
          "address": "0xAfb2423F447D3e16931164C9970B9741aAb1723E",
          "entity": {
            "zh": "[链：Ethereum] [钓鱼地址] [恶意Spender]",
            "tw": "[鏈：Ethereum] [釣魚地址] [惡意Spender]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "scam",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/GoPlusSecurity/status/2079036694725365986",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [钓鱼地址] [恶意Spender]",
            "tw": "[鏈：Ethereum] [釣魚地址] [惡意Spender]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0xE6F3D501eB6730C75965CdF523377470C1b23408",
          "entity": {
            "zh": "[链：Ethereum] [受害地址]",
            "tw": "[鏈：Ethereum] [受害地址]",
            "en": "victim address documented by a public source"
          },
          "role": "victim",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/GoPlusSecurity/status/2079036694725365986",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [受害地址]",
            "tw": "[鏈：Ethereum] [受害地址]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "GoPlus原帖",
            "tw": "GoPlus原帖",
            "en": "x.com source"
          },
          "url": "https://x.com/GoPlusSecurity/status/2079036694725365986",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-038",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-037",
      "status": "verified",
      "incidentDate": "2026-07-20",
      "datePrecision": "day",
      "title": {
        "zh": "RWT",
        "tw": "RWT",
        "en": "RWT protocol exploit"
      },
      "summary": {
        "zh": "约11.81万美元损失；根因与攻击者归集地址待进一步Trace。",
        "tw": "約11.81萬美元損失；根因與攻擊者歸集地址待進一步Trace。",
        "en": "A protocol weakness caused approximately $118,100 in reported losses."
      },
      "details": {
        "zh": "## 事件背景\n仅有异常 Tx 与损失金额，无官方根因。可能为价格操纵或权限问题，证据不足不强行定性。\n\n## 事件经过\n1. 7 月 20 日 09:34 TenArmor 确认 RWT 异常。\n2. 损失约 11.81 万美元。\n3. 记录攻击 Tx；地址角色待 Trace。\n\n## 资金流向\n见事件经过；无独立可拆资金路径时以地址与交易章节为准。\n\n## 金额口径\n约11.81万美元\n\n## 证据边界\n部分角色/根因仍待核。\n\n## 处置状态\n约11.81万美元损失；根因与攻击者归集地址待进一步Trace。",
        "tw": "## 事件背景\n僅有異常 Tx 與損失金額，無官方根因。可能為價格操縱或權限問題，證據不足不強行定性。\n\n## 事件經過\n1. 7 月 20 日 09:34 TenArmor 確認 RWT 異常。\n2. 損失約 11.81 萬美元。\n3. 記錄攻擊 Tx；地址角色待 Trace。\n\n## 資金流向\n見事件經過；無獨立可拆資金路徑時以地址與交易章節為準。\n\n## 金額口徑\n約11.81萬美元\n\n## 證據邊界\n部分角色/根因仍待核。\n\n## 處置狀態\n約11.81萬美元損失；根因與攻擊者歸集地址待進一步Trace。",
        "en": "## Incident overview\nA protocol weakness caused approximately $118,100 in reported losses.\n\n## Amount basis\nReported loss: $118,100\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "protocol-exploit",
      "severity": "high",
      "ecosystems": [
        "BNB Chain"
      ],
      "chains": [
        "BNB Chain"
      ],
      "lossUsd": 118100,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "约11.81万美元",
        "tw": "約11.81萬美元",
        "en": "Reported loss: $118,100"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "BNB Chain",
          "address": "0x84DD3A5D4DE44c8ad0CE032BeAb8bc3f01D1dcf7",
          "entity": {
            "zh": "[链：BNB Chain / BSC] [黑客地址] [攻击者EOA] [攻击发起From]",
            "tw": "[鏈：BNB Chain / BSC] [黑客地址] [攻擊者EOA] [攻擊發起From]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://bscscan.com/tx/0x22300140e7c44899c2602382a6e7a4a34a70f47f9736721744bc6434c07171dc",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain / BSC] [黑客地址] [攻击者EOA] [攻击发起From]",
            "tw": "[鏈：BNB Chain / BSC] [黑客地址] [攻擊者EOA] [攻擊發起From]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0x7ed953Ff42509568f620aa340a33A9373447f4CE",
          "entity": {
            "zh": "[链：BNB Chain / BSC] [黑客合约] [主攻击合约 To] [资金调度]",
            "tw": "[鏈：BNB Chain / BSC] [黑客合約] [主攻擊合約 To] [資金調度]",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://bscscan.com/tx/0x22300140e7c44899c2602382a6e7a4a34a70f47f9736721744bc6434c07171dc",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain / BSC] [黑客合约] [主攻击合约 To] [资金调度]",
            "tw": "[鏈：BNB Chain / BSC] [黑客合約] [主攻擊合約 To] [資金調度]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0x8812bB5fb89d69d35ac84d2c37b55769395b9f90",
          "entity": {
            "zh": "[链：BNB Chain / BSC] [黑客关联地址] [RWT/USDT 中转]",
            "tw": "[鏈：BNB Chain / BSC] [黑客關聯地址] [RWT/USDT 中轉]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://bscscan.com/tx/0x22300140e7c44899c2602382a6e7a4a34a70f47f9736721744bc6434c07171dc",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain / BSC] [黑客关联地址] [RWT/USDT 中转]",
            "tw": "[鏈：BNB Chain / BSC] [黑客關聯地址] [RWT/USDT 中轉]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0xf8a36777415c09feaff3dc78dcbb3ed00ce989cd",
          "entity": {
            "zh": "[链：BNB Chain / BSC] [代币合约] [RWT Token]（非黑客）",
            "tw": "[鏈：BNB Chain / BSC] [代幣合約] [RWT Token]（非黑客）",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://bscscan.com/tx/0x22300140e7c44899c2602382a6e7a4a34a70f47f9736721744bc6434c07171dc",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain / BSC] [代币合约] [RWT Token]（非黑客）",
            "tw": "[鏈：BNB Chain / BSC] [代幣合約] [RWT Token]（非黑客）",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0xc1c2ef25372f12ce18d35044446064b720c4aa27",
          "entity": {
            "zh": "[链：BNB Chain / BSC] [交易对/LP] [Pancake V2 RWT-USDT]（路径合约）",
            "tw": "[鏈：BNB Chain / BSC] [交易對/LP] [Pancake V2 RWT-USDT]（路徑合約）",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://bscscan.com/tx/0x22300140e7c44899c2602382a6e7a4a34a70f47f9736721744bc6434c07171dc",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain / BSC] [交易对/LP] [Pancake V2 RWT-USDT]（路径合约）",
            "tw": "[鏈：BNB Chain / BSC] [交易對/LP] [Pancake V2 RWT-USDT]（路徑合約）",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "BscScan",
            "tw": "BscScan",
            "en": "bscscan.com source"
          },
          "url": "https://bscscan.com/tx/0x22300140e7c44899c2602382a6e7a4a34a70f47f9736721744bc6434c07171dc",
          "type": "research"
        },
        {
          "label": {
            "zh": "TenArmor原帖",
            "tw": "TenArmor原帖",
            "en": "x.com source"
          },
          "url": "https://x.com/TenArmorAlert/status/2079016942556594337",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-037",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-036",
      "status": "verified",
      "incidentDate": "2026-07-20",
      "datePrecision": "day",
      "title": {
        "zh": "Allbridge Core",
        "tw": "Allbridge Core",
        "en": "Allbridge Core bridge exploit"
      },
      "summary": {
        "zh": "协议暂停；赃款跨到Ethereum。项目请求套利者退回异常获利用于补偿LP。",
        "tw": "協議暫停；贓款跨到Ethereum。項目請求套利者退回異常獲利用於補償LP。",
        "en": "A bridge weakness caused approximately $1.65 million in reported losses."
      },
      "details": {
        "zh": "## 事件背景\nAllbridge Core 在 Solana 稳定币池使用 虚拟余额/内部会计 近似真实储备。缺陷在于：\n\n1. 发送池与接收池状态更新 不一致；\n2. 对同一 USDT mint 做 USDT→USDT「同币兑换」时，最终只有接收池状态被正确更新，发送侧偏斜无法回到均衡；\n3. 攻击者可用闪电贷反复执行该路径，把池子会计打歪，再用极少 USDT 换出巨额 USDC；\n4. 同类闪贷扭曲池比例的手法 2023 年曾出现，但 Solana 部署侧修复/不变量未全面继承（第三方 post-mortem 观点）。\n\n## 事件经过\n1. 从 Kamino 借入约 112 万美元 USDC 闪电贷。\n2. 连续约 5 次 USDT→USDT 交换，故意制造虚拟余额偏斜。\n3. 以约 3,987 USDT 换出约 224 万 USDC（虚增会计的直接证据）。\n4. 偿还闪电贷后，净利约 165 万美元。\n5. 经 Mayan 桥到 Ethereum 地址 0x6515…ffDe 并分散。\n6. 官方暂停协议，要求受影响池 LP 撤资；呼吁异常套利者退回利润补偿 LP。\n7. 误标纠正：0x01a494079DCB715f622340301463cE50cd69A4D0 — [链：EVM] 为补偿/退还地址，不是黑客。\n\n## 资金流向\n5. 经 Mayan 桥到 Ethereum 地址 0x651591b68A9c9650FB23F642162353306281ffDe — [链：Ethereum] [详见地址与交易] 并分散。\n\n## 金额口径\n约165万美元USDT/USDC\n\n## 证据边界\n以公开可核验来源为界；未证实细节不写入确定结论。\n\n## 处置状态\n协议暂停；赃款跨到Ethereum。项目请求套利者退回异常获利用于补偿LP。",
        "tw": "## 事件背景\nAllbridge Core 在 Solana 穩定幣池使用 虛擬餘額/內部會計 近似真實儲備。缺陷在於：\n\n1. 發送池與接收池狀態更新 不一致；\n2. 對同一 USDT mint 做 USDT→USDT「同幣兌換」時，最終只有接收池狀態被正確更新，發送側偏斜無法回到均衡；\n3. 攻擊者可用閃電貸反覆執行該路徑，把池子會計打歪，再用極少 USDT 換出鉅額 USDC；\n4. 同類閃貸扭曲池比例的手法 2023 年曾出現，但 Solana 部署側修復/不變量未全面繼承（第三方 post-mortem 觀點）。\n\n## 事件經過\n1. 從 Kamino 借入約 112 萬美元 USDC 閃電貸。\n2. 連續約 5 次 USDT→USDT 交換，故意製造虛擬餘額偏斜。\n3. 以約 3,987 USDT 換出約 224 萬 USDC（虛增會計的直接證據）。\n4. 償還閃電貸後，淨利約 165 萬美元。\n5. 經 Mayan 橋到 Ethereum 地址 0x6515…ffDe 並分散。\n6. 官方暫停協議，要求受影響池 LP 撤資；呼籲異常套利者退回利潤補償 LP。\n7. 誤標糾正：0x01a494079DCB715f622340301463cE50cd69A4D0 — [鏈：EVM] 為補償/退還地址，不是黑客。\n\n## 資金流向\n5. 經 Mayan 橋到 Ethereum 地址 0x651591b68A9c9650FB23F642162353306281ffDe — [鏈：Ethereum] [詳見地址與交易] 並分散。\n\n## 金額口徑\n約165萬美元USDT/USDC\n\n## 證據邊界\n以公開可核驗來源為界；未證實細節不寫入確定結論。\n\n## 處置狀態\n協議暫停；贓款跨到Ethereum。項目請求套利者退回異常獲利用於補償LP。",
        "en": "## Incident overview\nA bridge weakness caused approximately $1.65 million in reported losses.\n\n## Amount basis\nReported loss: $1,650,000\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "bridge-exploit",
      "severity": "high",
      "ecosystems": [
        "Ethereum",
        "Solana"
      ],
      "chains": [
        "Ethereum",
        "Solana"
      ],
      "lossUsd": 1650000,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "约165万美元USDT/USDC",
        "tw": "約165萬美元USDT/USDC",
        "en": "Reported loss: $1,650,000"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "Solana",
          "address": "FhffBraZsGn4H2LxLNToEcaHWEfWwT2UcSz4oRHb7Qdc",
          "entity": {
            "zh": "[链：Solana] [黑客地址] [Solana被盗资产接收] [跨链桥入口]",
            "tw": "[鏈：Solana] [黑客地址] [Solana被盜資產接收] [跨鏈橋入口]",
            "en": "bridge address documented by a public source"
          },
          "role": "bridge",
          "category": "bridge",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/CertiKAlert/status/2079013163014770987",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Solana] [黑客地址] [Solana被盗资产接收] [跨链桥入口]",
            "tw": "[鏈：Solana] [黑客地址] [Solana被盜資產接收] [跨鏈橋入口]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Solana",
          "address": "7DyZQw3iV5zhHssnNA6Nopi5zc8NGLbYjHMcaok6NN66",
          "entity": {
            "zh": "[链：Solana] [受害地址] [Allbridge受影响账户]",
            "tw": "[鏈：Solana] [受害地址] [Allbridge受影響賬戶]",
            "en": "victim address documented by a public source"
          },
          "role": "victim",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/CertiKAlert/status/2079013163014770987",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Solana] [受害地址] [Allbridge受影响账户]",
            "tw": "[鏈：Solana] [受害地址] [Allbridge受影響賬戶]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0x651591b68A9c9650FB23F642162353306281ffDe",
          "entity": {
            "zh": "[链：Ethereum] [跨链桥出口] [Ethereum被盗资产接收] [资金分散]",
            "tw": "[鏈：Ethereum] [跨鏈橋出口] [Ethereum被盜資產接收] [資金分散]",
            "en": "bridge address documented by a public source"
          },
          "role": "bridge",
          "category": "bridge",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/CertiKAlert/status/2079013163014770987",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [跨链桥出口] [Ethereum被盗资产接收] [资金分散]",
            "tw": "[鏈：Ethereum] [跨鏈橋出口] [Ethereum被盜資產接收] [資金分散]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "CertiK事件与出口地址",
            "tw": "CertiK事件與出口地址",
            "en": "x.com source"
          },
          "url": "https://x.com/CertiKAlert/status/2079013163014770987",
          "type": "research"
        },
        {
          "label": {
            "zh": "GoPlus完整地址线程",
            "tw": "GoPlus完整地址線程",
            "en": "x.com source"
          },
          "url": "https://x.com/GoPlusSecurity/status/2079226292994707555",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-036",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-035",
      "status": "verified",
      "incidentDate": "2026-07-18",
      "datePrecision": "day",
      "title": {
        "zh": "Trusted Volumes旧案部分退还",
        "tw": "Trusted Volumes舊案部分退還",
        "en": "Trusted Volumes old-case partial return"
      },
      "summary": {
        "zh": "协议收回部分资金；剩余约200万美元状态仍有争议。",
        "tw": "協議收回部分資金；剩餘約200萬美元狀態仍有爭議。",
        "en": "An address linked to an earlier incident returned part of the funds; the action is recorded as recovery movement, not a new exploit."
      },
      "details": {
        "zh": "## 事件背景\nTrusted Volumes 主攻击在 5 月（旧案）。7 月条目是 赃款部分回流：攻击者/关联钱包退回部分 ETH，可能是谈判、压力或「自我赏金」叙事，但公开渠道 未确认 正式白帽协议，故标签为 [追回/退还] [赏金定性待核]。\n\n## 事件经过\n1. 原始攻击约损失 590 万美元（窗口外）。\n2. 7 月 18 日披露：关联钱包向协议退回约 1,122 ETH。\n3. 据报攻击者仍保留约 200 万美元 等值资产。\n4. 媒体称「赏金」，无双方正式协议公开文本。\n5. 完整退还地址未达交叉验证标准 → 不猜补。\n\n## 资金流向\n见事件经过；无独立可拆资金路径时以地址与交易章节为准。\n\n## 金额口径\n未统一/见正文\n\n## 证据边界\n完整地址/Tx 不足时不猜补。 部分角色/根因仍待核。 本条为旧案资金异动，非本期新攻击首发。\n\n## 处置状态\n协议收回部分资金；剩余约200万美元状态仍有争议。",
        "tw": "## 事件背景\nTrusted Volumes 主攻擊在 5 月（舊案）。7 月條目是 贓款部分迴流：攻擊者/關聯錢包退回部分 ETH，可能是談判、壓力或「自我賞金」敘事，但公開渠道 未確認 正式白帽協議，故標籤為 [追回/退還] [賞金定性待核]。\n\n## 事件經過\n1. 原始攻擊約損失 590 萬美元（窗口外）。\n2. 7 月 18 日披露：關聯錢包向協議退回約 1,122 ETH。\n3. 據報攻擊者仍保留約 200 萬美元 等值資產。\n4. 媒體稱「賞金」，無雙方正式協議公開文本。\n5. 完整退還地址未達交叉驗證標準 → 不猜補。\n\n## 資金流向\n見事件經過；無獨立可拆資金路徑時以地址與交易章節為準。\n\n## 金額口徑\n未統一/見正文\n\n## 證據邊界\n完整地址/Tx 不足時不猜補。 部分角色/根因仍待核。 本條為舊案資金異動，非本期新攻擊首發。\n\n## 處置狀態\n協議收回部分資金；剩餘約200萬美元狀態仍有爭議。",
        "en": "## Incident overview\nAn address linked to an earlier incident returned part of the funds; the action is recorded as recovery movement, not a new exploit.\n\n## Amount basis\nNo single verified USD loss figure was published; see the incident record.\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "fund-movement",
      "severity": "medium",
      "ecosystems": [
        "Ethereum"
      ],
      "chains": [
        "Ethereum"
      ],
      "lossUsd": null,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "未统一/见正文",
        "tw": "未統一/見正文",
        "en": "No single verified USD loss figure was published; see the incident record."
      },
      "addressDisclosure": "not-published",
      "addresses": [],
      "references": [
        {
          "label": {
            "zh": "SolidityScan更新",
            "tw": "SolidityScan更新",
            "en": "x.com source"
          },
          "url": "https://x.com/SolidityScan/status/2078499639620194556",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-035",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-034",
      "status": "verified",
      "incidentDate": "2026-07-18",
      "datePrecision": "day",
      "title": {
        "zh": "Grok Build CLI安全漏洞",
        "tw": "Grok Build CLI安全漏洞",
        "en": "Grok Build CLI security vulnerability"
      },
      "summary": {
        "zh": "属于高危开发工具漏洞，但没有足够证据证明本窗口内已经造成特定链上盗币。",
        "tw": "屬於高危開發工具漏洞，但沒有足夠證據證明本窗口內已經造成特定鏈上盜幣。",
        "en": "A flaw in a developer CLI created a software supply-chain risk; no verified aggregate asset loss was published."
      },
      "details": {
        "zh": "## 事件背景\nGrok Build CLI 作为开发工具若存在 未授权任意代码执行（RCE） 路径，攻击者可在开发者机器上直接读密钥。此前还发现 git 上传机制可能把 .env、RSA 私钥一并打包——属于工具链设计缺陷，风险等于「自动泄露部署密钥」。\n\n## 事件经过\n1. SlowMist 披露至少两条无需明确用户批准即可触发任意代码执行的攻击链。\n2. 同步提示 git 上传可能打包敏感文件。\n3. 本窗口内 无充分证据 证明已发生与之直接对应的大规模链上盗币。\n4. 无确认链上攻击者地址。\n\n## 资金流向\n见事件经过；无独立可拆资金路径时以地址与交易章节为准。\n\n## 金额口径\n未披露已发生链上损失\n\n## 证据边界\n以公开可核验来源为界；未证实细节不写入确定结论。\n\n## 处置状态\n属于高危开发工具漏洞，但没有足够证据证明本窗口内已经造成特定链上盗币。",
        "tw": "## 事件背景\nGrok Build CLI 作為開發工具若存在 未授權任意代碼執行（RCE） 路徑，攻擊者可在開發者機器上直接讀密鑰。此前還發現 git 上傳機制可能把 .env、RSA 私鑰一併打包——屬於工具鏈設計缺陷，風險等於「自動洩露部署密鑰」。\n\n## 事件經過\n1. SlowMist 披露至少兩條無需明確用戶批准即可觸發任意代碼執行的攻擊鏈。\n2. 同步提示 git 上傳可能打包敏感文件。\n3. 本窗口內 無充分證據 證明已發生與之直接對應的大規模鏈上盜幣。\n4. 無確認鏈上攻擊者地址。\n\n## 資金流向\n見事件經過；無獨立可拆資金路徑時以地址與交易章節為準。\n\n## 金額口徑\n未披露已發生鏈上損失\n\n## 證據邊界\n以公開可核驗來源為界；未證實細節不寫入確定結論。\n\n## 處置狀態\n屬於高危開發工具漏洞，但沒有足夠證據證明本窗口內已經造成特定鏈上盜幣。",
        "en": "## Incident overview\nA flaw in a developer CLI created a software supply-chain risk; no verified aggregate asset loss was published.\n\n## Amount basis\nNo single verified USD loss figure was published; see the incident record.\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "supply-chain",
      "severity": "medium",
      "ecosystems": [
        "Other"
      ],
      "chains": [
        "Other"
      ],
      "lossUsd": null,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "未披露已发生链上损失",
        "tw": "未披露已發生鏈上損失",
        "en": "No single verified USD loss figure was published; see the incident record."
      },
      "addressDisclosure": "not-published",
      "addresses": [],
      "references": [
        {
          "label": {
            "zh": "SlowMist原帖",
            "tw": "SlowMist原帖",
            "en": "x.com source"
          },
          "url": "https://x.com/SlowMist_Team/status/2078402837416231007",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-034",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-033",
      "status": "verified",
      "incidentDate": "2026-07-18",
      "datePrecision": "day",
      "title": {
        "zh": "虚假Web3招聘GitHub木马",
        "tw": "虛假Web3招聘GitHub木馬",
        "en": "Fake Web3 recruitment GitHub malware"
      },
      "summary": {
        "zh": "活动被SlowMist识别并预警；具体受害人数和链上损失未完整披露。",
        "tw": "活動被SlowMist識別並預警；具體受害人數和鏈上損失未完整披露。",
        "en": "Fraudulent recruiting workflows delivered malware through GitHub repositories, creating credential and wallet-theft risk."
      },
      "details": {
        "zh": "## 事件背景\n针对 Web3 开发者的 社工 + 供应链 组合拳：信任建立在「面试/试工」场景，恶意代码藏在看起来正常的 GitHub「MVP 作业」里。开发者本地 npm install / 运行项目即中招，与智能合约审计无关。\n\n## 事件经过\n1. 攻击者伪装 LinkedIn 招聘/HR，长期聊天建立信任。\n2. 发送「请实现/运行这个面试 MVP」的 GitHub 仓库。\n3. 仓库依赖或脚本含木马，执行后窃取 .env、私钥、浏览器钱包与凭证。\n4. 可能进一步造成多链盗币；公开无统一归集地址。\n5. SlowMist 披露预警。\n\n## 资金流向\n4. 可能进一步造成多链盗币；公开无统一归集地址。\n\n## 金额口径\n未公开统一金额\n\n## 证据边界\n以公开可核验来源为界；未证实细节不写入确定结论。\n\n## 处置状态\n活动被SlowMist识别并预警；具体受害人数和链上损失未完整披露。",
        "tw": "## 事件背景\n針對 Web3 開發者的 社工 + 供應鏈 組合拳：信任建立在「面試/試工」場景，惡意代碼藏在看起來正常的 GitHub「MVP 作業」裡。開發者本地 npm install / 運行項目即中招，與智能合約審計無關。\n\n## 事件經過\n1. 攻擊者偽裝 LinkedIn 招聘/HR，長期聊天建立信任。\n2. 發送「請實現/運行這個面試 MVP」的 GitHub 倉庫。\n3. 倉庫依賴或腳本含木馬，執行後竊取 .env、私鑰、瀏覽器錢包與憑證。\n4. 可能進一步造成多鏈盜幣；公開無統一歸集地址。\n5. SlowMist 披露預警。\n\n## 資金流向\n4. 可能進一步造成多鏈盜幣；公開無統一歸集地址。\n\n## 金額口徑\n未公開統一金額\n\n## 證據邊界\n以公開可核驗來源為界；未證實細節不寫入確定結論。\n\n## 處置狀態\n活動被SlowMist識別並預警；具體受害人數和鏈上損失未完整披露。",
        "en": "## Incident overview\nFraudulent recruiting workflows delivered malware through GitHub repositories, creating credential and wallet-theft risk.\n\n## Amount basis\nNo single verified USD loss figure was published; see the incident record.\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "supply-chain",
      "severity": "medium",
      "ecosystems": [
        "Other"
      ],
      "chains": [
        "Other"
      ],
      "lossUsd": null,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "未公开统一金额",
        "tw": "未公開統一金額",
        "en": "No single verified USD loss figure was published; see the incident record."
      },
      "addressDisclosure": "not-published",
      "addresses": [],
      "references": [
        {
          "label": {
            "zh": "SlowMist原帖",
            "tw": "SlowMist原帖",
            "en": "x.com source"
          },
          "url": "https://x.com/SlowMist_Team/status/2078379701249466450",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-033",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-032",
      "status": "verified",
      "incidentDate": "2026-07-17",
      "datePrecision": "day",
      "title": {
        "zh": "CrowdRingCircle / 众环CRC",
        "tw": "CrowdRingCircle / 眾環CRC",
        "en": "CrowdRingCircle protocol incident"
      },
      "summary": {
        "zh": "约20.14万美元流失；地址角色仍待Trace确认。",
        "tw": "約20.14萬美元流失；地址角色仍待Trace確認。",
        "en": "A smart-contract weakness caused approximately $201,400 in reported losses."
      },
      "details": {
        "zh": "## 事件背景\n与 FCOW 类似：有链上异常流出，无官方根因文档。可能是池操纵、合约逻辑或权限问题，证据边界内只记现象。\n\n## 事件经过\n1. 7 月 17 日 09:18 TenArmor 告警 CrowdRingCircle/众环 CRC。\n2. 确认约 20.14 万美元 异常流失。\n3. 记录攻击 Tx；不把路径上的 DEX router/LP 直接标为黑客。\n\n## 资金流向\n见事件经过；无独立可拆资金路径时以地址与交易章节为准。\n\n## 金额口径\n约20.14万美元\n\n## 证据边界\n部分角色/根因仍待核。\n\n## 处置状态\n约20.14万美元流失；地址角色仍待Trace确认。",
        "tw": "## 事件背景\n與 FCOW 類似：有鏈上異常流出，無官方根因文檔。可能是池操縱、合約邏輯或權限問題，證據邊界內只記現象。\n\n## 事件經過\n1. 7 月 17 日 09:18 TenArmor 告警 CrowdRingCircle/眾環 CRC。\n2. 確認約 20.14 萬美元 異常流失。\n3. 記錄攻擊 Tx；不把路徑上的 DEX router/LP 直接標為黑客。\n\n## 資金流向\n見事件經過；無獨立可拆資金路徑時以地址與交易章節為準。\n\n## 金額口徑\n約20.14萬美元\n\n## 證據邊界\n部分角色/根因仍待核。\n\n## 處置狀態\n約20.14萬美元流失；地址角色仍待Trace確認。",
        "en": "## Incident overview\nA smart-contract weakness caused approximately $201,400 in reported losses.\n\n## Amount basis\nReported loss: $201,400\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "protocol-exploit",
      "severity": "high",
      "ecosystems": [
        "BNB Chain"
      ],
      "chains": [
        "BNB Chain"
      ],
      "lossUsd": 201400,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "约20.14万美元",
        "tw": "約20.14萬美元",
        "en": "Reported loss: $201,400"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "BNB Chain",
          "address": "0x34579eA92a07a88F5505dFaA4D99Ab94b2784087",
          "entity": {
            "zh": "[链：BNB Chain / BSC] [黑客地址] [攻击者EOA] [攻击发起From] [持有众环CRC]",
            "tw": "[鏈：BNB Chain / BSC] [黑客地址] [攻擊者EOA] [攻擊發起From] [持有眾環CRC]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://bscscan.com/tx/0xeaef22325e02ac65a8e1f2e1a3a43f7b7ac8d2323ce6f698a90813e77017c834",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain / BSC] [黑客地址] [攻击者EOA] [攻击发起From] [持有众环CRC]",
            "tw": "[鏈：BNB Chain / BSC] [黑客地址] [攻擊者EOA] [攻擊發起From] [持有眾環CRC]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0xc5940d118f9c2070478545ba80a780aa8f86d133",
          "entity": {
            "zh": "[链：BNB Chain / BSC] [黑客合约] [攻击中 Create]",
            "tw": "[鏈：BNB Chain / BSC] [黑客合約] [攻擊中 Create]",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://bscscan.com/tx/0xeaef22325e02ac65a8e1f2e1a3a43f7b7ac8d2323ce6f698a90813e77017c834",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain / BSC] [黑客合约] [攻击中 Create]",
            "tw": "[鏈：BNB Chain / BSC] [黑客合約] [攻擊中 Create]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0x2eadbcdcd4ab4bb7f8b01610794ea09a64cd5da1",
          "entity": {
            "zh": "[链：BNB Chain / BSC] [黑客合约] [主执行/资金归集] [被盗资产接收]",
            "tw": "[鏈：BNB Chain / BSC] [黑客合約] [主執行/資金歸集] [被盜資產接收]",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://bscscan.com/tx/0xeaef22325e02ac65a8e1f2e1a3a43f7b7ac8d2323ce6f698a90813e77017c834",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain / BSC] [黑客合约] [主执行/资金归集] [被盗资产接收]",
            "tw": "[鏈：BNB Chain / BSC] [黑客合約] [主執行/資金歸集] [被盜資產接收]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0x8581433150f2c48ff2efe5a22b17c7d405054509",
          "entity": {
            "zh": "[链：BNB Chain / BSC] [代币合约] [众环CRC Token]（非黑客）",
            "tw": "[鏈：BNB Chain / BSC] [代幣合約] [眾環CRC Token]（非黑客）",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://bscscan.com/tx/0xeaef22325e02ac65a8e1f2e1a3a43f7b7ac8d2323ce6f698a90813e77017c834",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain / BSC] [代币合约] [众环CRC Token]（非黑客）",
            "tw": "[鏈：BNB Chain / BSC] [代幣合約] [眾環CRC Token]（非黑客）",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0xd8799a644850c065388c22df4ee0c28472922526",
          "entity": {
            "zh": "[链：BNB Chain / BSC] [交易对/LP] [Pancake V2 CRC-USDT]（路径合约）",
            "tw": "[鏈：BNB Chain / BSC] [交易對/LP] [Pancake V2 CRC-USDT]（路徑合約）",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://bscscan.com/tx/0xeaef22325e02ac65a8e1f2e1a3a43f7b7ac8d2323ce6f698a90813e77017c834",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain / BSC] [交易对/LP] [Pancake V2 CRC-USDT]（路径合约）",
            "tw": "[鏈：BNB Chain / BSC] [交易對/LP] [Pancake V2 CRC-USDT]（路徑合約）",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "BscScan",
            "tw": "BscScan",
            "en": "bscscan.com source"
          },
          "url": "https://bscscan.com/tx/0xeaef22325e02ac65a8e1f2e1a3a43f7b7ac8d2323ce6f698a90813e77017c834",
          "type": "research"
        },
        {
          "label": {
            "zh": "TenArmor原帖",
            "tw": "TenArmor原帖",
            "en": "x.com source"
          },
          "url": "https://x.com/TenArmorAlert/status/2077925916228120766",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-032",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-031",
      "status": "verified",
      "incidentDate": "2026-07-17",
      "datePrecision": "day",
      "title": {
        "zh": "FCOW",
        "tw": "FCOW",
        "en": "FCOW protocol exploit"
      },
      "summary": {
        "zh": "损失约6.13万美元；攻击者 EOA 与主攻击合约已入账，完整经济模型根因仍待专项复盘。",
        "tw": "損失約6.13萬美元；攻擊者 EOA 與主攻擊合約已入賬，完整經濟模型根因仍待專項復盤。",
        "en": "A protocol weakness caused approximately $61,300 in reported losses."
      },
      "details": {
        "zh": "## 事件背景\n公开信息以 TenArmor 告警与 BscScan 异常攻击交易为主，无项目方完整技术复盘。链上可见攻击者 EOA 调用主攻击合约，并在交易内 Create 多个辅助合约，对 FCOW/USDT 池进行操纵性兑换与资金调度。在无官方根因文档前，不将 LP/Token 合约误标为黑客。\n\n## 事件经过\n1. 7 月 17 日 09:07（北京时间）TenArmor 告警 FCOW。\n2. BNB Chain 上确认异常交易与约 6.13 万美元 损失。\n3. BscScan Trace：From 为攻击者 EOA，To 为主攻击合约，交易内创建多个辅助合约并调度 FCOW/USDT。\n4. 记录完整地址与角色；Pancake 池与 FCOW Token 标为路径/代币合约（非黑客）。\n\n## 资金流向\n见事件经过；无独立可拆资金路径时以地址与交易章节为准。\n\n## 金额口径\n约6.13万美元\n\n## 证据边界\n以公开可核验来源为界；未证实细节不写入确定结论。\n\n## 处置状态\n损失约6.13万美元；攻击者 EOA 与主攻击合约已入账，完整经济模型根因仍待专项复盘。",
        "tw": "## 事件背景\n公開信息以 TenArmor 告警與 BscScan 異常攻擊交易為主，無項目方完整技術復盤。鏈上可見攻擊者 EOA 調用主攻擊合約，並在交易內 Create 多個輔助合約，對 FCOW/USDT 池進行操縱性兌換與資金調度。在無官方根因文檔前，不將 LP/Token 合約誤標為黑客。\n\n## 事件經過\n1. 7 月 17 日 09:07（北京時間）TenArmor 告警 FCOW。\n2. BNB Chain 上確認異常交易與約 6.13 萬美元 損失。\n3. BscScan Trace：From 為攻擊者 EOA，To 為主攻擊合約，交易內創建多個輔助合約並調度 FCOW/USDT。\n4. 記錄完整地址與角色；Pancake 池與 FCOW Token 標為路徑/代幣合約（非黑客）。\n\n## 資金流向\n見事件經過；無獨立可拆資金路徑時以地址與交易章節為準。\n\n## 金額口徑\n約6.13萬美元\n\n## 證據邊界\n以公開可核驗來源為界；未證實細節不寫入確定結論。\n\n## 處置狀態\n損失約6.13萬美元；攻擊者 EOA 與主攻擊合約已入賬，完整經濟模型根因仍待專項復盤。",
        "en": "## Incident overview\nA protocol weakness caused approximately $61,300 in reported losses.\n\n## Amount basis\nReported loss: $61,300\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "protocol-exploit",
      "severity": "high",
      "ecosystems": [
        "BNB Chain"
      ],
      "chains": [
        "BNB Chain"
      ],
      "lossUsd": 61300,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "约6.13万美元",
        "tw": "約6.13萬美元",
        "en": "Reported loss: $61,300"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "BNB Chain",
          "address": "0x1e2E1D433D5409b531d55ddADd3D6755f02515af",
          "entity": {
            "zh": "[链：BNB Chain] [黑客地址] [攻击者EOA] [攻击发起From]",
            "tw": "[鏈：BNB Chain] [黑客地址] [攻擊者EOA] [攻擊發起From]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://bscscan.com/tx/0x78a6463e1b74607d62aba5e834836f9b34d2df3993fbd9d120b15e4b71e5c601",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain] [黑客地址] [攻击者EOA] [攻击发起From]",
            "tw": "[鏈：BNB Chain] [黑客地址] [攻擊者EOA] [攻擊發起From]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0x772744C4bfF10e4158dA50F2f3E028b16c5494cd",
          "entity": {
            "zh": "[链：BNB Chain] [黑客合约] [主攻击合约 To] [资金调度]",
            "tw": "[鏈：BNB Chain] [黑客合約] [主攻擊合約 To] [資金調度]",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://bscscan.com/tx/0x78a6463e1b74607d62aba5e834836f9b34d2df3993fbd9d120b15e4b71e5c601",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain] [黑客合约] [主攻击合约 To] [资金调度]",
            "tw": "[鏈：BNB Chain] [黑客合約] [主攻擊合約 To] [資金調度]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0x7d13bd1bb1ba50945878911d73bd42d12da693a1",
          "entity": {
            "zh": "[链：BNB Chain] [黑客合约] [攻击中 Create 的辅助合约] [资金中转]",
            "tw": "[鏈：BNB Chain] [黑客合約] [攻擊中 Create 的輔助合約] [資金中轉]",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://bscscan.com/tx/0x78a6463e1b74607d62aba5e834836f9b34d2df3993fbd9d120b15e4b71e5c601",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain] [黑客合约] [攻击中 Create 的辅助合约] [资金中转]",
            "tw": "[鏈：BNB Chain] [黑客合約] [攻擊中 Create 的輔助合約] [資金中轉]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0xdc69553ae9681dec8e77bb60f262278332d6ac6e",
          "entity": {
            "zh": "[链：BNB Chain] [黑客合约] [攻击中 Create] [FCOW 持仓/分发]",
            "tw": "[鏈：BNB Chain] [黑客合約] [攻擊中 Create] [FCOW 持倉/分發]",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://bscscan.com/tx/0x78a6463e1b74607d62aba5e834836f9b34d2df3993fbd9d120b15e4b71e5c601",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain] [黑客合约] [攻击中 Create] [FCOW 持仓/分发]",
            "tw": "[鏈：BNB Chain] [黑客合約] [攻擊中 Create] [FCOW 持倉/分發]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0xcf51963d55e6ec01d3bc9f55ecd537939a614468",
          "entity": {
            "zh": "[链：BNB Chain] [代币合约] [FCOW Token]（非黑客）",
            "tw": "[鏈：BNB Chain] [代幣合約] [FCOW Token]（非黑客）",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://bscscan.com/tx/0x78a6463e1b74607d62aba5e834836f9b34d2df3993fbd9d120b15e4b71e5c601",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain] [代币合约] [FCOW Token]（非黑客）",
            "tw": "[鏈：BNB Chain] [代幣合約] [FCOW Token]（非黑客）",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0x4514ffcbbd1e28d76b38b50515d19fcbe81ecd0d",
          "entity": {
            "zh": "[链：BNB Chain] [交易对/LP] [Pancake V2 FCOW-USDT]（路径合约，非黑客）",
            "tw": "[鏈：BNB Chain] [交易對/LP] [Pancake V2 FCOW-USDT]（路徑合約，非黑客）",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://bscscan.com/tx/0x78a6463e1b74607d62aba5e834836f9b34d2df3993fbd9d120b15e4b71e5c601",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain] [交易对/LP] [Pancake V2 FCOW-USDT]（路径合约，非黑客）",
            "tw": "[鏈：BNB Chain] [交易對/LP] [Pancake V2 FCOW-USDT]（路徑合約，非黑客）",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "BscScan 攻击交易",
            "tw": "BscScan 攻擊交易",
            "en": "bscscan.com source"
          },
          "url": "https://bscscan.com/tx/0x78a6463e1b74607d62aba5e834836f9b34d2df3993fbd9d120b15e4b71e5c601",
          "type": "research"
        },
        {
          "label": {
            "zh": "TenArmorAlert",
            "tw": "TenArmorAlert",
            "en": "x.com source"
          },
          "url": "https://x.com/TenArmorAlert",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-031",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-030",
      "status": "verified",
      "incidentDate": "2026-07-17",
      "datePrecision": "day",
      "title": {
        "zh": "Across",
        "tw": "Across",
        "en": "Across bridge exploit"
      },
      "summary": {
        "zh": "Solana存款修复后重新启用；用户资金无损，Relayer承担损失。",
        "tw": "Solana存款修復後重新啟用；用戶資金無損，Relayer承擔損失。",
        "en": "A bridge-related weakness caused approximately $3.6 million in reported losses."
      },
      "details": {
        "zh": "## 事件背景\nAcross 采用 intent + relayer 垫资 模型：用户在源链存款后，relayer 在目标链先垫付，再回头结算。Solana 侧没有以太坊式规范 event log；失败交易仍可能发出可被误读的信号/轨迹。若 relayer 只信「看到存款事件」而不严格校验链上最终成功状态，攻击者就能：\n\n1. 伪造或诱导发出「存款已完成」的信号；\n2. 让 relayer 在 EVM 目标链先把真金白银付给攻击者；\n3. 源链实际并无有效存款 → relayer 无法从协议池正常报销 → 损失落在 relayer，而不是用户锁仓池。\n\n这与 Ronin/Wormhole 类「桥合约池被抽干」不同：架构把风险放在 relayer。公开有人写 Relayer 损失约 360 万美元，Across 官方早期未统一确认美元数，写作须标注口径待 post-mortem。\n\n## 事件经过\n1. 约 2026-07-17 05:30 UTC，Across 在 Solana 部署遭攻击。\n2. 攻击者利用存款信号验证缺陷，使 Risk Labs 运营的 relayer 误以为源链存款成功。\n3. Relayer 在 EVM 目标链向攻击者地址付款；源链无对应有效存款。\n4. Across 暂停 Solana 存款；进行中用户转账完成或自动退款，用户资金无损。\n5. 约 07-18 修复后恢复；与 SEAL 911 等协作追踪。\n6. 公开攻击关联地址见下；两个EVM端地址均已由Etherscan确认为Ethereum上的Across Protocol Exploiter标签地址。\n\n## 资金流向\n3. Relayer 在 EVM 目标链向攻击者地址付款；源链无对应有效存款。\n\n## 金额口径\nRelayer损失约360万美元；用户资金未损失\n\n## 证据边界\n以公开可核验来源为界；未证实细节不写入确定结论。\n\n## 处置状态\nSolana存款修复后重新启用；用户资金无损，Relayer承担损失。",
        "tw": "## 事件背景\nAcross 採用 intent + relayer 墊資 模型：用戶在源鏈存款後，relayer 在目標鏈先墊付，再回頭結算。Solana 側沒有以太坊式規範 event log；失敗交易仍可能發出可被誤讀的信號/軌跡。若 relayer 只信「看到存款事件」而不嚴格校驗鏈上最終成功狀態，攻擊者就能：\n\n1. 偽造或誘導發出「存款已完成」的信號；\n2. 讓 relayer 在 EVM 目標鏈先把真金白銀付給攻擊者；\n3. 源鏈實際並無有效存款 → relayer 無法從協議池正常報銷 → 損失落在 relayer，而不是用戶鎖倉池。\n\n這與 Ronin/Wormhole 類「橋合約池被抽乾」不同：架構把風險放在 relayer。公開有人寫 Relayer 損失約 360 萬美元，Across 官方早期未統一確認美元數，寫作須標註口徑待 post-mortem。\n\n## 事件經過\n1. 約 2026-07-17 05:30 UTC，Across 在 Solana 部署遭攻擊。\n2. 攻擊者利用存款信號驗證缺陷，使 Risk Labs 運營的 relayer 誤以為源鏈存款成功。\n3. Relayer 在 EVM 目標鏈向攻擊者地址付款；源鏈無對應有效存款。\n4. Across 暫停 Solana 存款；進行中用戶轉賬完成或自動退款，用戶資金無損。\n5. 約 07-18 修復後恢復；與 SEAL 911 等協作追蹤。\n6. 公開攻擊關聯地址見下；兩個EVM端地址均已由Etherscan確認為Ethereum上的Across Protocol Exploiter標籤地址。\n\n## 資金流向\n3. Relayer 在 EVM 目標鏈向攻擊者地址付款；源鏈無對應有效存款。\n\n## 金額口徑\nRelayer損失約360萬美元；用戶資金未損失\n\n## 證據邊界\n以公開可核驗來源為界；未證實細節不寫入確定結論。\n\n## 處置狀態\nSolana存款修復後重新啟用；用戶資金無損，Relayer承擔損失。",
        "en": "## Incident overview\nA bridge-related weakness caused approximately $3.6 million in reported losses.\n\n## Amount basis\nReported loss: $3,600,000\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "bridge-exploit",
      "severity": "high",
      "ecosystems": [
        "Ethereum",
        "Solana"
      ],
      "chains": [
        "Ethereum",
        "Solana"
      ],
      "lossUsd": 3600000,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "Relayer损失约360万美元；用户资金未损失",
        "tw": "Relayer損失約360萬美元；用戶資金未損失",
        "en": "Reported loss: $3,600,000"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "Solana",
          "address": "8bkoZToaTBBtAPczgHqD4XVxWtvBkiy4crtexEtYDYSL",
          "entity": {
            "zh": "[链：Solana] [黑客地址] [伪造存款信号]",
            "tw": "[鏈：Solana] [黑客地址] [偽造存款信號]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/AcrossProtocol/status/2078164426268557340",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Solana] [黑客地址] [伪造存款信号]",
            "tw": "[鏈：Solana] [黑客地址] [偽造存款信號]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0xa0C0e9f307b5A26cA3FB5891c19154fc7A02BeF7",
          "entity": {
            "zh": "[链：Ethereum] [黑客地址] [Across Protocol Exploiter 1] [被盗资产接收]",
            "tw": "[鏈：Ethereum] [黑客地址] [Across Protocol Exploiter 1] [被盜資產接收]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/AcrossProtocol/status/2078164426268557340",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [黑客地址] [Across Protocol Exploiter 1] [被盗资产接收]",
            "tw": "[鏈：Ethereum] [黑客地址] [Across Protocol Exploiter 1] [被盜資產接收]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0xA6fb971F3B7a9b9F76EdA76bc89268fe26560189",
          "entity": {
            "zh": "[链：Ethereum] [黑客地址] [Across Protocol Exploiter 2] [初始由Tornado Cash注资] [资金路径]",
            "tw": "[鏈：Ethereum] [黑客地址] [Across Protocol Exploiter 2] [初始由Tornado Cash注資] [資金路徑]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/AcrossProtocol/status/2078164426268557340",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [黑客地址] [Across Protocol Exploiter 2] [初始由Tornado Cash注资] [资金路径]",
            "tw": "[鏈：Ethereum] [黑客地址] [Across Protocol Exploiter 2] [初始由Tornado Cash注資] [資金路徑]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "Across官方",
            "tw": "Across官方",
            "en": "x.com source"
          },
          "url": "https://x.com/AcrossProtocol/status/2078164426268557340",
          "type": "official"
        },
        {
          "label": {
            "zh": "M13地址披露",
            "tw": "M13地址披露",
            "en": "x.com source"
          },
          "url": "https://x.com/m13_digital/status/2078244008002826524",
          "type": "research"
        },
        {
          "label": {
            "zh": "Ethereum Exploiter 1",
            "tw": "Ethereum Exploiter 1",
            "en": "etherscan.io source"
          },
          "url": "https://etherscan.io/address/0xa0c0e9f307b5a26ca3fb5891c19154fc7a02bef7",
          "type": "research"
        },
        {
          "label": {
            "zh": "Ethereum Exploiter 2",
            "tw": "Ethereum Exploiter 2",
            "en": "etherscan.io source"
          },
          "url": "https://etherscan.io/address/0xA6fb971F3B7a9b9F76EdA76bc89268fe26560189",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-030",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-029",
      "status": "verified",
      "incidentDate": "2026-07-16",
      "datePrecision": "day",
      "title": {
        "zh": "Huione / 汇旺后端基础设施扣押",
        "tw": "Huione / 匯旺後端基礎設施扣押",
        "en": "Huione backend infrastructure seizure"
      },
      "summary": {
        "zh": "Huione部分链下服务基础设施被执法机关控制；不能把该行动写成“本期链上USDT已经全部司法扣押”。",
        "tw": "Huione部分鏈下服務基礎設施被執法機關控制；不能把該行動寫成“本期鏈上USDT已經全部司法扣押”。",
        "en": "Authorities seized backend infrastructure associated with Huione services; no new on-chain frozen amount was disclosed in the action."
      },
      "details": {
        "zh": "## 事件背景\n汇旺集团（Huione Group）长期被美财政部 FinCEN 等视为东南亚诈骗/洗钱关键基础设施（Huione Pay、Huione Guarantee/Haowang 等）。执法目标不仅是单个链上地址，还包括 云账号、后端服务器、域名与运营基础设施——切断担保市场的撮合、记账与客服系统，比单次冻 USDT 更能破坏业务连续性。\n\n## 事件经过\n1. 美国司法部宣布扣押 Huione 子公司用于洗钱服务的云计算账户/后端基础设施（公开材料时间线存在 6 月主公告与 7 月前后二次传播）。\n2. 扣押对象是 链下基础设施，公告 未附 一批「本次新扣押的链上钱包清单」。\n3. 因此本条不能写成「本期链上 USDT 已被司法全部扣押」。\n4. 历史链上动作（如 2024 年约 2962 万 USDT 冻结、2026 年 4 月约 3.44 亿 USDT 相关冻结批次）均在本窗口外，仅作背景，不并入本期新地址。\n5. 汇旺/新币 公开可核验地址标签表 统一放在文末附录，避免与「本次扣押」混淆。\n\n## 资金流向\n见事件经过；无独立可拆资金路径时以地址与交易章节为准。\n\n## 金额口径\n本次公告未公布新链上冻结金额\n\n## 证据边界\n无合格完整黑客地址入账。\n\n## 处置状态\nHuione部分链下服务基础设施被执法机关控制；不能把该行动写成“本期链上USDT已经全部司法扣押”。",
        "tw": "## 事件背景\n匯旺集團（Huione Group）長期被美財政部 FinCEN 等視為東南亞詐騙/洗錢關鍵基礎設施（Huione Pay、Huione Guarantee/Haowang 等）。執法目標不僅是單個鏈上地址，還包括 雲賬號、後端服務器、域名與運營基礎設施——切斷擔保市場的撮合、記賬與客服系統，比單次凍 USDT 更能破壞業務連續性。\n\n## 事件經過\n1. 美國司法部宣佈扣押 Huione 子公司用於洗錢服務的雲計算賬戶/後端基礎設施（公開材料時間線存在 6 月主公告與 7 月前後二次傳播）。\n2. 扣押對象是 鏈下基礎設施，公告 未附 一批「本次新扣押的鏈上錢包清單」。\n3. 因此本條不能寫成「本期鏈上 USDT 已被司法全部扣押」。\n4. 歷史鏈上動作（如 2024 年約 2962 萬 USDT 凍結、2026 年 4 月約 3.44 億 USDT 相關凍結批次）均在本窗口外，僅作背景，不併入本期新地址。\n5. 匯旺/新幣 公開可核驗地址標籤表 統一放在文末附錄，避免與「本次扣押」混淆。\n\n## 資金流向\n見事件經過；無獨立可拆資金路徑時以地址與交易章節為準。\n\n## 金額口徑\n本次公告未公佈新鏈上凍結金額\n\n## 證據邊界\n無合格完整黑客地址入賬。\n\n## 處置狀態\nHuione部分鏈下服務基礎設施被執法機關控制；不能把該行動寫成“本期鏈上USDT已經全部司法扣押”。",
        "en": "## Incident overview\nAuthorities seized backend infrastructure associated with Huione services; no new on-chain frozen amount was disclosed in the action.\n\n## Amount basis\nNo single verified USD loss figure was published; see the incident record.\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "enforcement",
      "severity": "medium",
      "ecosystems": [
        "TRON"
      ],
      "chains": [
        "TRON"
      ],
      "lossUsd": null,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "本次公告未公布新链上冻结金额",
        "tw": "本次公告未公佈新鏈上凍結金額",
        "en": "No single verified USD loss figure was published; see the incident record."
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "TRON",
          "address": "TWS84SZ2GE2EgyZDCrfVuEJXpoXYuBxteS",
          "entity": {
            "zh": "SlowMist披露的HuionePay公开活跃地址",
            "tw": "SlowMist披露的HuionePay公開活躍地址",
            "en": "HuionePay active address documented by SlowMist"
          },
          "role": "other",
          "category": "high_risk_service",
          "confidence": 0.9,
          "sourceUrl": "https://slowmist.medium.com/on-chain-analysis-of-huionepay-unveiling-the-over-55-billion-usdt-in-fund-flows-692e4a72d320",
          "evidenceStatus": "reviewed_public_source",
          "evidenceSummary": {
            "zh": "仅按SlowMist公开资金流研究标注为HuionePay生态地址，不等同于黑客地址或司法定罪。",
            "tw": "僅按SlowMist公開資金流研究標註為HuionePay生態地址，不等同於黑客地址或司法定罪。",
            "en": "Labeled only as HuionePay ecosystem activity from SlowMist public research; this is not a hacker attribution or legal finding."
          },
          "reviewRequired": true
        },
        {
          "chain": "TRON",
          "address": "T9yFi9yxwBUjMbHwBFKDdwFdBwvzUAqBfR",
          "entity": {
            "zh": "SlowMist披露的HuionePay公开活跃地址",
            "tw": "SlowMist披露的HuionePay公開活躍地址",
            "en": "HuionePay active address documented by SlowMist"
          },
          "role": "other",
          "category": "high_risk_service",
          "confidence": 0.9,
          "sourceUrl": "https://slowmist.medium.com/on-chain-analysis-of-huionepay-unveiling-the-over-55-billion-usdt-in-fund-flows-692e4a72d320",
          "evidenceStatus": "reviewed_public_source",
          "evidenceSummary": {
            "zh": "仅按SlowMist公开资金流研究标注为HuionePay生态地址，不等同于黑客地址或司法定罪。",
            "tw": "僅按SlowMist公開資金流研究標註為HuionePay生態地址，不等同於黑客地址或司法定罪。",
            "en": "Labeled only as HuionePay ecosystem activity from SlowMist public research; this is not a hacker attribution or legal finding."
          },
          "reviewRequired": true
        },
        {
          "chain": "TRON",
          "address": "TTSSC4TEYtQMAMURND6i1FPYaaBJMGY4ed",
          "entity": {
            "zh": "SlowMist披露的HuionePay公开活跃地址",
            "tw": "SlowMist披露的HuionePay公開活躍地址",
            "en": "HuionePay active address documented by SlowMist"
          },
          "role": "other",
          "category": "high_risk_service",
          "confidence": 0.9,
          "sourceUrl": "https://slowmist.medium.com/on-chain-analysis-of-huionepay-unveiling-the-over-55-billion-usdt-in-fund-flows-692e4a72d320",
          "evidenceStatus": "reviewed_public_source",
          "evidenceSummary": {
            "zh": "仅按SlowMist公开资金流研究标注为HuionePay生态地址，不等同于黑客地址或司法定罪。",
            "tw": "僅按SlowMist公開資金流研究標註為HuionePay生態地址，不等同於黑客地址或司法定罪。",
            "en": "Labeled only as HuionePay ecosystem activity from SlowMist public research; this is not a hacker attribution or legal finding."
          },
          "reviewRequired": true
        },
        {
          "chain": "TRON",
          "address": "TL8TBpubVzBr1UWPXBXU8Pci5ZAip9SwEf",
          "entity": {
            "zh": "SlowMist披露的HuionePay公开活跃地址",
            "tw": "SlowMist披露的HuionePay公開活躍地址",
            "en": "HuionePay active address documented by SlowMist"
          },
          "role": "other",
          "category": "high_risk_service",
          "confidence": 0.9,
          "sourceUrl": "https://slowmist.medium.com/on-chain-analysis-of-huionepay-unveiling-the-over-55-billion-usdt-in-fund-flows-692e4a72d320",
          "evidenceStatus": "reviewed_public_source",
          "evidenceSummary": {
            "zh": "仅按SlowMist公开资金流研究标注为HuionePay生态地址，不等同于黑客地址或司法定罪。",
            "tw": "僅按SlowMist公開資金流研究標註為HuionePay生態地址，不等同於黑客地址或司法定罪。",
            "en": "Labeled only as HuionePay ecosystem activity from SlowMist public research; this is not a hacker attribution or legal finding."
          },
          "reviewRequired": true
        },
        {
          "chain": "TRON",
          "address": "TPEpdLYtHr8cN1Jbwf6CGNB9Ppho7L2otr",
          "entity": {
            "zh": "SlowMist披露的HuionePay公开活跃地址",
            "tw": "SlowMist披露的HuionePay公開活躍地址",
            "en": "HuionePay active address documented by SlowMist"
          },
          "role": "other",
          "category": "high_risk_service",
          "confidence": 0.9,
          "sourceUrl": "https://slowmist.medium.com/on-chain-analysis-of-huionepay-unveiling-the-over-55-billion-usdt-in-fund-flows-692e4a72d320",
          "evidenceStatus": "reviewed_public_source",
          "evidenceSummary": {
            "zh": "仅按SlowMist公开资金流研究标注为HuionePay生态地址，不等同于黑客地址或司法定罪。",
            "tw": "僅按SlowMist公開資金流研究標註為HuionePay生態地址，不等同於黑客地址或司法定罪。",
            "en": "Labeled only as HuionePay ecosystem activity from SlowMist public research; this is not a hacker attribution or legal finding."
          },
          "reviewRequired": true
        },
        {
          "chain": "TRON",
          "address": "TM1zzNDZD2DPASbKcgdVoTYhfmYgtfwx9R",
          "entity": {
            "zh": "SlowMist披露的HuionePay公开活跃地址",
            "tw": "SlowMist披露的HuionePay公開活躍地址",
            "en": "HuionePay active address documented by SlowMist"
          },
          "role": "other",
          "category": "high_risk_service",
          "confidence": 0.9,
          "sourceUrl": "https://slowmist.medium.com/on-chain-analysis-of-huionepay-unveiling-the-over-55-billion-usdt-in-fund-flows-692e4a72d320",
          "evidenceStatus": "reviewed_public_source",
          "evidenceSummary": {
            "zh": "仅按SlowMist公开资金流研究标注为HuionePay生态地址，不等同于黑客地址或司法定罪。",
            "tw": "僅按SlowMist公開資金流研究標註為HuionePay生態地址，不等同於黑客地址或司法定罪。",
            "en": "Labeled only as HuionePay ecosystem activity from SlowMist public research; this is not a hacker attribution or legal finding."
          },
          "reviewRequired": true
        },
        {
          "chain": "TRON",
          "address": "TUXsppberDuVqQmNN5mnxg4pJ3HU9YtCEw",
          "entity": {
            "zh": "SlowMist披露的HuionePay行为样本地址",
            "tw": "SlowMist披露的HuionePay行為樣本地址",
            "en": "HuionePay behavior-sample address documented by SlowMist"
          },
          "role": "other",
          "category": "high_risk_service",
          "confidence": 0.7,
          "sourceUrl": "https://slowmist.medium.com/on-chain-analysis-of-huionepay-unveiling-the-over-55-billion-usdt-in-fund-flows-692e4a72d320",
          "evidenceStatus": "reviewed_public_source",
          "evidenceSummary": {
            "zh": "仅按SlowMist公开资金流研究标注为HuionePay生态地址，不等同于黑客地址或司法定罪。",
            "tw": "僅按SlowMist公開資金流研究標註為HuionePay生態地址，不等同於黑客地址或司法定罪。",
            "en": "Labeled only as HuionePay ecosystem activity from SlowMist public research; this is not a hacker attribution or legal finding."
          },
          "reviewRequired": true
        },
        {
          "chain": "TRON",
          "address": "TRAA9R9151eE522crrxQgQTr9WGVRubmou",
          "entity": {
            "zh": "SlowMist披露的HuionePay行为样本地址",
            "tw": "SlowMist披露的HuionePay行為樣本地址",
            "en": "HuionePay behavior-sample address documented by SlowMist"
          },
          "role": "other",
          "category": "high_risk_service",
          "confidence": 0.7,
          "sourceUrl": "https://slowmist.medium.com/on-chain-analysis-of-huionepay-unveiling-the-over-55-billion-usdt-in-fund-flows-692e4a72d320",
          "evidenceStatus": "reviewed_public_source",
          "evidenceSummary": {
            "zh": "仅按SlowMist公开资金流研究标注为HuionePay生态地址，不等同于黑客地址或司法定罪。",
            "tw": "僅按SlowMist公開資金流研究標註為HuionePay生態地址，不等同於黑客地址或司法定罪。",
            "en": "Labeled only as HuionePay ecosystem activity from SlowMist public research; this is not a hacker attribution or legal finding."
          },
          "reviewRequired": true
        },
        {
          "chain": "TRON",
          "address": "TEdVW72PWcJ9Fwmw3w9uSBTLK6rjRUM1GJ",
          "entity": {
            "zh": "SlowMist披露的HuionePay行为样本地址",
            "tw": "SlowMist披露的HuionePay行為樣本地址",
            "en": "HuionePay behavior-sample address documented by SlowMist"
          },
          "role": "other",
          "category": "high_risk_service",
          "confidence": 0.7,
          "sourceUrl": "https://slowmist.medium.com/on-chain-analysis-of-huionepay-unveiling-the-over-55-billion-usdt-in-fund-flows-692e4a72d320",
          "evidenceStatus": "reviewed_public_source",
          "evidenceSummary": {
            "zh": "仅按SlowMist公开资金流研究标注为HuionePay生态地址，不等同于黑客地址或司法定罪。",
            "tw": "僅按SlowMist公開資金流研究標註為HuionePay生態地址，不等同於黑客地址或司法定罪。",
            "en": "Labeled only as HuionePay ecosystem activity from SlowMist public research; this is not a hacker attribution or legal finding."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "美国司法部公告",
            "tw": "美國司法部公告",
            "en": "justice.gov source"
          },
          "url": "https://www.justice.gov/opa/pr/justice-department-seizes-backend-infrastructure-used-huione-group-money-laundering-services",
          "type": "official"
        },
        {
          "label": {
            "zh": "X线索",
            "tw": "X線索",
            "en": "x.com source"
          },
          "url": "https://x.com/WakweliChain/status/2077771237758316657",
          "type": "research"
        },
        {
          "label": {
            "zh": "SlowMist汇旺资金流研究",
            "tw": "SlowMist匯旺資金流研究",
            "en": "SlowMist Huione fund-flow research"
          },
          "url": "https://slowmist.medium.com/on-chain-analysis-of-huionepay-unveiling-the-over-55-billion-usdt-in-fund-flows-692e4a72d320",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-029",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-028",
      "status": "verified",
      "incidentDate": "2026-07-16",
      "datePrecision": "day",
      "title": {
        "zh": "DeFiTuna",
        "tw": "DeFiTuna",
        "en": "DeFiTuna oracle manipulation"
      },
      "summary": {
        "zh": "项目称攻击向量已缓解，并启动调查和资金追回。",
        "tw": "項目稱攻擊向量已緩解，並啟動調查和資金追回。",
        "en": "A pricing weakness enabled abnormal liquidations and approximately $580,000 in reported losses."
      },
      "details": {
        "zh": "## 事件背景\nDeFiTuna 借贷池在评估抵押品时，信任了可被攻击者 自建低流动性池 扭曲的价格，并叠加：\n\n1. 估值舍入误差：在极端薄池或特殊数量级下，内部计价出现有利于攻击者的舍入；\n2. 健康度检查缺陷：本应拦截的「假高抵押、真低流动性」仓位被判定为健康；\n3. 结果是：几乎卖不掉的池 LP/代币被系统当成高价值抵押，从而从 USDC 借贷池借走真实稳定币。\n\n本质是 抵押品预言机/内部定价未对自建池与操纵性流动性设防。\n\n## 事件经过\n1. 攻击者创建或利用高度缺乏流动性的 TUNA/USDC 池。\n2. 通过操纵池价与估值路径，抬高自己仓位的「账面抵押价值」。\n3. 绕过健康度检查，从 USDC 借贷池抽走约 56.96 万—58 万美元。\n4. 借贷池留下近同规模赤字（坏账/穿仓）。\n5. 资金据报拆到两个地址，但公开渠道未形成可交叉验证的完整地址列表 → 不猜补。\n6. 项目方称攻击向量已缓解，启动调查与追回。\n\n## 资金流向\n见事件经过；无独立可拆资金路径时以地址与交易章节为准。\n\n## 金额口径\n约56.96万—58万美元USDC\n\n## 证据边界\n完整地址/Tx 不足时不猜补。\n\n## 处置状态\n项目称攻击向量已缓解，并启动调查和资金追回。",
        "tw": "## 事件背景\nDeFiTuna 借貸池在評估抵押品時，信任了可被攻擊者 自建低流動性池 扭曲的價格，併疊加：\n\n1. 估值舍入誤差：在極端薄池或特殊數量級下，內部計價出現有利於攻擊者的舍入；\n2. 健康度檢查缺陷：本應攔截的「假高抵押、真低流動性」倉位被判定為健康；\n3. 結果是：幾乎賣不掉的池 LP/代幣被系統當成高價值抵押，從而從 USDC 借貸池借走真實穩定幣。\n\n本質是 抵押品預言機/內部定價未對自建池與操縱性流動性設防。\n\n## 事件經過\n1. 攻擊者創建或利用高度缺乏流動性的 TUNA/USDC 池。\n2. 通過操縱池價與估值路徑，抬高自己倉位的「賬面抵押價值」。\n3. 繞過健康度檢查，從 USDC 借貸池抽走約 56.96 萬—58 萬美元。\n4. 借貸池留下近同規模赤字（壞賬/穿倉）。\n5. 資金據報拆到兩個地址，但公開渠道未形成可交叉驗證的完整地址列表 → 不猜補。\n6. 項目方稱攻擊向量已緩解，啟動調查與追回。\n\n## 資金流向\n見事件經過；無獨立可拆資金路徑時以地址與交易章節為準。\n\n## 金額口徑\n約56.96萬—58萬美元USDC\n\n## 證據邊界\n完整地址/Tx 不足時不猜補。\n\n## 處置狀態\n項目稱攻擊向量已緩解，並啟動調查和資金追回。",
        "en": "## Incident overview\nA pricing weakness enabled abnormal liquidations and approximately $580,000 in reported losses.\n\n## Amount basis\nReported loss: $580,000\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "oracle-manipulation",
      "severity": "high",
      "ecosystems": [
        "Ethereum",
        "Solana"
      ],
      "chains": [
        "Ethereum",
        "Solana"
      ],
      "lossUsd": 580000,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "约56.96万—58万美元USDC",
        "tw": "約56.96萬—58萬美元USDC",
        "en": "Reported loss: $580,000"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "Solana",
          "address": "9ytGWP8tCRF1keREJ5VHqBpSuM9MZYwm3oFQQa1SvESb",
          "entity": {
            "zh": "[链：Solana] [黑客地址] [Attacker 1]",
            "tw": "[鏈：Solana] [黑客地址] [Attacker 1]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://www.certik.com/blog/defituna-incident-analysis",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Solana] [黑客地址] [Attacker 1]",
            "tw": "[鏈：Solana] [黑客地址] [Attacker 1]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Solana",
          "address": "917DKTphW3rhBG5gsJpwKsNGisNV2dx74uUFd8HBEjtg",
          "entity": {
            "zh": "[链：Solana] [黑客地址] [Attacker 2] [假池/Fake Pool]",
            "tw": "[鏈：Solana] [黑客地址] [Attacker 2] [假池/Fake Pool]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://www.certik.com/blog/defituna-incident-analysis",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Solana] [黑客地址] [Attacker 2] [假池/Fake Pool]",
            "tw": "[鏈：Solana] [黑客地址] [Attacker 2] [假池/Fake Pool]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Solana",
          "address": "7hiHL8AgDuLNVDQLfN3GHdLAEeCN1F7uz6nSANRvFJst",
          "entity": {
            "zh": "[链：Solana] [黑客地址] [Attacker 3] [limit-order抽USDC]",
            "tw": "[鏈：Solana] [黑客地址] [Attacker 3] [limit-order抽USDC]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://www.certik.com/blog/defituna-incident-analysis",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Solana] [黑客地址] [Attacker 3] [limit-order抽USDC]",
            "tw": "[鏈：Solana] [黑客地址] [Attacker 3] [limit-order抽USDC]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Solana",
          "address": "BK9aTnKfPNnnj45Me5ACrky2vexzUrZHRzr4BjmQpH3c",
          "entity": {
            "zh": "[链：Solana] [黑客地址] [Attacker 4] [limit-order抽USDC]",
            "tw": "[鏈：Solana] [黑客地址] [Attacker 4] [limit-order抽USDC]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://www.certik.com/blog/defituna-incident-analysis",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Solana] [黑客地址] [Attacker 4] [limit-order抽USDC]",
            "tw": "[鏈：Solana] [黑客地址] [Attacker 4] [limit-order抽USDC]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Solana",
          "address": "8P3H7Hy98LWhw5QhuXdoigVdAzPCYRTYjdtQQKhGwvqD",
          "entity": {
            "zh": "[链：Solana] [黑客地址] [Attacker 5]",
            "tw": "[鏈：Solana] [黑客地址] [Attacker 5]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://www.certik.com/blog/defituna-incident-analysis",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Solana] [黑客地址] [Attacker 5]",
            "tw": "[鏈：Solana] [黑客地址] [Attacker 5]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Solana",
          "address": "GrXBhM6Ty6YxubFp8zubtJF12WXmKj1dhMyakRPeaDpo",
          "entity": {
            "zh": "[链：Solana] [黑客地址] [Attacker 6]",
            "tw": "[鏈：Solana] [黑客地址] [Attacker 6]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://www.certik.com/blog/defituna-incident-analysis",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Solana] [黑客地址] [Attacker 6]",
            "tw": "[鏈：Solana] [黑客地址] [Attacker 6]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Solana",
          "address": "F4xUroPaHro4gb2JAqa3e93E7DdZytRQJ4L2cHT5E53p",
          "entity": {
            "zh": "[链：Solana] [黑客地址] [Attacker 7]",
            "tw": "[鏈：Solana] [黑客地址] [Attacker 7]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://www.certik.com/blog/defituna-incident-analysis",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Solana] [黑客地址] [Attacker 7]",
            "tw": "[鏈：Solana] [黑客地址] [Attacker 7]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Solana",
          "address": "ETGhosPrFApbiiKXDpxrhBz7J2MdTA3dxnL2Nkio9vEX",
          "entity": {
            "zh": "[链：Solana] [黑客地址] [Attacker 8]",
            "tw": "[鏈：Solana] [黑客地址] [Attacker 8]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://www.certik.com/blog/defituna-incident-analysis",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Solana] [黑客地址] [Attacker 8]",
            "tw": "[鏈：Solana] [黑客地址] [Attacker 8]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Solana",
          "address": "4ZKkGZuoXqgSHbmsJXUib3dgn5WNhzbPEXrxuMYJ5oQ3",
          "entity": {
            "zh": "[链：Solana] [黑客地址] [Attacker 9]",
            "tw": "[鏈：Solana] [黑客地址] [Attacker 9]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://www.certik.com/blog/defituna-incident-analysis",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Solana] [黑客地址] [Attacker 9]",
            "tw": "[鏈：Solana] [黑客地址] [Attacker 9]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Solana",
          "address": "tuna4uSQZncNeeiAMKbstuxA9CUkHH6HmC64wgmnogD",
          "entity": {
            "zh": "[链：Solana] [协议程序] [DefiTuna Program]",
            "tw": "[鏈：Solana] [協議程序] [DefiTuna Program]",
            "en": "other address documented by a public source"
          },
          "role": "other",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://www.certik.com/blog/defituna-incident-analysis",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Solana] [协议程序] [DefiTuna Program]",
            "tw": "[鏈：Solana] [協議程序] [DefiTuna Program]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Solana",
          "address": "D76dDcSU5HnAGqVEZCDLyGgLpTp4xZuqeZyVDtUdDv55",
          "entity": {
            "zh": "[链：Solana] [受害地址] [Damaged USDC vault]",
            "tw": "[鏈：Solana] [受害地址] [Damaged USDC vault]",
            "en": "victim address documented by a public source"
          },
          "role": "victim",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://www.certik.com/blog/defituna-incident-analysis",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Solana] [受害地址] [Damaged USDC vault]",
            "tw": "[鏈：Solana] [受害地址] [Damaged USDC vault]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0xb2cD3E99E45F8ab15fee77a014A3D82F9FE05f3E",
          "entity": {
            "zh": "ETH 跨链出口（Mayan）： — [链：Ethereum] [跨链桥出口] [被盗资产接收]",
            "tw": "ETH 跨鏈出口（Mayan）： — [鏈：Ethereum] [跨鏈橋出口] [被盜資產接收]",
            "en": "bridge address documented by a public source"
          },
          "role": "bridge",
          "category": "bridge",
          "confidence": 0.9,
          "sourceUrl": "https://www.certik.com/blog/defituna-incident-analysis",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "ETH 跨链出口（Mayan）： — [链：Ethereum] [跨链桥出口] [被盗资产接收]",
            "tw": "ETH 跨鏈出口（Mayan）： — [鏈：Ethereum] [跨鏈橋出口] [被盜資產接收]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0x509B9D094A6C26D716aaC131E8aDee5B16B86d3e",
          "entity": {
            "zh": "ETH 持仓： — [链：Ethereum] [资金归集] [DAI/ETH持仓]",
            "tw": "ETH 持倉： — [鏈：Ethereum] [資金歸集] [DAI/ETH持倉]",
            "en": "other address documented by a public source"
          },
          "role": "other",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://www.certik.com/blog/defituna-incident-analysis",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "ETH 持仓： — [链：Ethereum] [资金归集] [DAI/ETH持仓]",
            "tw": "ETH 持倉： — [鏈：Ethereum] [資金歸集] [DAI/ETH持倉]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "CertiK完整Incident Analysis",
            "tw": "CertiK完整Incident Analysis",
            "en": "certik.com source"
          },
          "url": "https://www.certik.com/blog/defituna-incident-analysis",
          "type": "research"
        },
        {
          "label": {
            "zh": "CertiKAlert",
            "tw": "CertiKAlert",
            "en": "x.com source"
          },
          "url": "https://x.com/CertiKAlert/status/2078077637302399435",
          "type": "research"
        },
        {
          "label": {
            "zh": "DeFiTuna官方",
            "tw": "DeFiTuna官方",
            "en": "x.com source"
          },
          "url": "https://x.com/DeFiTuna/status/2077772502521053668",
          "type": "official"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-028",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-027",
      "status": "verified",
      "incidentDate": "2026-07-16",
      "datePrecision": "day",
      "title": {
        "zh": "Chi Protocol",
        "tw": "Chi Protocol",
        "en": "Chi Protocol exploit"
      },
      "summary": {
        "zh": "金额不大，但储备基本被抽干；属于硬编码面值导致的经济漏洞。",
        "tw": "金額不大，但儲備基本被抽乾；屬於硬編碼面值導致的經濟漏洞。",
        "en": "A protocol weakness was exploited for approximately $8,500."
      },
      "details": {
        "zh": "## 事件背景\nChi Protocol 发行 USC 等稳定币，储备为 LST/LRT 等。漏洞在 mint 与 burn/赎回不对称：\n\n- 市场上 USC 已严重脱锚（远低于 1 美元）；\n- 赎回/burn() 路径仍 硬编码 1 USC = 1 USD 计算可赎回抵押；\n- 攻击者可在薄池低价买 USC，再按面值销毁换出 weETH/stETH/WETH 等储备；\n- 形成无风险套利，直至储备被抽空。SlowMist 归档日期有 7/13，披露帖有 7/16，可并存。\n\n## 事件经过\n1. USC 在 Uniswap 等薄池脱锚。\n2. 攻击者（可配合闪电贷）低价扫货 USC。\n3. 调用协议 burn/赎回，按 1 美元面值抽走抵押储备。\n4. 损失金额约 8,500 美元，但储备几乎耗尽——金额小、系统性伤害大。\n5. 完整攻击地址/Tx 公开摘要不足 → 不猜补。\n\n## 资金流向\n见事件经过；无独立可拆资金路径时以地址与交易章节为准。\n\n## 金额口径\n约8500美元；储备几乎被耗尽\n\n## 证据边界\n完整地址/Tx 不足时不猜补。\n\n## 处置状态\n金额不大，但储备基本被抽干；属于硬编码面值导致的经济漏洞。",
        "tw": "## 事件背景\nChi Protocol 發行 USC 等穩定幣，儲備為 LST/LRT 等。漏洞在 mint 與 burn/贖回不對稱：\n\n- 市場上 USC 已嚴重脫錨（遠低於 1 美元）；\n- 贖回/burn() 路徑仍 硬編碼 1 USC = 1 USD 計算可贖回抵押；\n- 攻擊者可在薄池低價買 USC，再按面值銷燬換出 weETH/stETH/WETH 等儲備；\n- 形成無風險套利，直至儲備被抽空。SlowMist 歸檔日期有 7/13，披露帖有 7/16，可並存。\n\n## 事件經過\n1. USC 在 Uniswap 等薄池脫錨。\n2. 攻擊者（可配合閃電貸）低價掃貨 USC。\n3. 調用協議 burn/贖回，按 1 美元面值抽走抵押儲備。\n4. 損失金額約 8,500 美元，但儲備幾乎耗盡——金額小、系統性傷害大。\n5. 完整攻擊地址/Tx 公開摘要不足 → 不猜補。\n\n## 資金流向\n見事件經過；無獨立可拆資金路徑時以地址與交易章節為準。\n\n## 金額口徑\n約8500美元；儲備幾乎被耗盡\n\n## 證據邊界\n完整地址/Tx 不足時不猜補。\n\n## 處置狀態\n金額不大，但儲備基本被抽乾；屬於硬編碼面值導致的經濟漏洞。",
        "en": "## Incident overview\nA protocol weakness was exploited for approximately $8,500.\n\n## Amount basis\nReported loss: $8,500\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "protocol-exploit",
      "severity": "high",
      "ecosystems": [
        "Ethereum"
      ],
      "chains": [
        "Ethereum"
      ],
      "lossUsd": 8500,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "约8500美元；储备几乎被耗尽",
        "tw": "約8500美元；儲備幾乎被耗盡",
        "en": "Reported loss: $8,500"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "Ethereum",
          "address": "0x38547D918b9645F2D94336B6b61AEB08053E142c",
          "entity": {
            "zh": "[链：Ethereum] [受影响合约/代币] [USC Token]（不是黑客地址）",
            "tw": "[鏈：Ethereum] [受影響合約/代幣] [USC Token]（不是黑客地址）",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/SolidityScan/status/2077518136375480584",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [受影响合约/代币] [USC Token]（不是黑客地址）",
            "tw": "[鏈：Ethereum] [受影響合約/代幣] [USC Token]（不是黑客地址）",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "SolidityScan原帖",
            "tw": "SolidityScan原帖",
            "en": "x.com source"
          },
          "url": "https://x.com/SolidityScan/status/2077518136375480584",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-027",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-026",
      "status": "verified",
      "incidentDate": "2026-07-16",
      "datePrecision": "day",
      "title": {
        "zh": "Cascade CLS Vault",
        "tw": "Cascade CLS Vault",
        "en": "Cascade CLS Vault exploit"
      },
      "summary": {
        "zh": "用户资金损失约134万USDC；赃款完成多跳跨链。",
        "tw": "用戶資金損失約134萬USDC；贓款完成多跳跨鏈。",
        "en": "A vault weakness caused approximately $1.34 million in reported losses."
      },
      "details": {
        "zh": "## 事件背景\nCascade 为多资产永续平台，CLS（Collaborative Liquidity / 金库策略）在 Arbitrum 上以 USDC 为用户锁仓流动性，并在薄流动性市场中承担做市/持仓一侧（公开分析指金库偏空头侧）。攻击经济逻辑（综合 Cecuro/TechTimes 等）：\n\n1. 攻击者在特定薄市场堆积大量 多头；\n2. 人为抬高 mark price（标记价格）；\n3. 触发 CLS 金库空头侧的强平/自动去杠杆（ADL）；\n4. 金库被平仓的仓位与攻击者盈利多头对敲，攻击者按虚高价锁定利润并提走 USDC。\n\n根因属于 交易/风控参数与标记价格可操纵性，完整是否含私钥泄露仍待官方复盘；公开材料更支持经济操纵路径。\n\n## 事件经过\n1. 7 月 16 日 13:25（北京时间）前后披露 CLS 金库遭攻击，损失约 134 万 USDC（亦写 1.3M/1.34M）。\n2. 攻击者立即提现利润。\n3. 跨链逃避冻结：USDC 从 Arbitrum → Solana，再经 Relay Protocol 以 DAI 形式到 Ethereum（避开 USDC 发行方黑名单）。\n4. Cascade 暂停交易与提现，邀请 SEAL 911 等介入。\n5. 社区称 CLS 约 95% 资金被提走等比例 未获官方页面独立确认，正文慎用。\n\n## 资金流向\n3. 跨链逃避冻结：USDC 从 Arbitrum → Solana，再经 Relay Protocol 以 DAI 形式到 Ethereum（避开 USDC 发行方黑名单）。\n\n## 金额口径\n约134万USDC\n\n## 证据边界\n完整地址/Tx 不足时不猜补。 部分角色/根因仍待核。\n\n## 处置状态\n用户资金损失约134万USDC；赃款完成多跳跨链。",
        "tw": "## 事件背景\nCascade 為多資產永續平臺，CLS（Collaborative Liquidity / 金庫策略）在 Arbitrum 上以 USDC 為用戶鎖倉流動性，並在薄流動性市場中承擔做市/持倉一側（公開分析指金庫偏空頭側）。攻擊經濟邏輯（綜合 Cecuro/TechTimes 等）：\n\n1. 攻擊者在特定薄市場堆積大量 多頭；\n2. 人為抬高 mark price（標記價格）；\n3. 觸發 CLS 金庫空頭側的強平/自動去槓桿（ADL）；\n4. 金庫被平倉的倉位與攻擊者盈利多頭對敲，攻擊者按虛高價鎖定利潤並提走 USDC。\n\n根因屬於 交易/風控參數與標記價格可操縱性，完整是否含私鑰洩露仍待官方復盤；公開材料更支持經濟操縱路徑。\n\n## 事件經過\n1. 7 月 16 日 13:25（北京時間）前後披露 CLS 金庫遭攻擊，損失約 134 萬 USDC（亦寫 1.3M/1.34M）。\n2. 攻擊者立即提現利潤。\n3. 跨鏈逃避凍結：USDC 從 Arbitrum → Solana，再經 Relay Protocol 以 DAI 形式到 Ethereum（避開 USDC 發行方黑名單）。\n4. Cascade 暫停交易與提現，邀請 SEAL 911 等介入。\n5. 社區稱 CLS 約 95% 資金被提走等比例 未獲官方頁面獨立確認，正文慎用。\n\n## 資金流向\n3. 跨鏈逃避凍結：USDC 從 Arbitrum → Solana，再經 Relay Protocol 以 DAI 形式到 Ethereum（避開 USDC 發行方黑名單）。\n\n## 金額口徑\n約134萬USDC\n\n## 證據邊界\n完整地址/Tx 不足時不猜補。 部分角色/根因仍待核。\n\n## 處置狀態\n用戶資金損失約134萬USDC；贓款完成多跳跨鏈。",
        "en": "## Incident overview\nA vault weakness caused approximately $1.34 million in reported losses.\n\n## Amount basis\nReported loss: $1,340,000\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "protocol-exploit",
      "severity": "high",
      "ecosystems": [
        "Ethereum",
        "Solana",
        "Arbitrum"
      ],
      "chains": [
        "Ethereum",
        "Solana",
        "Arbitrum"
      ],
      "lossUsd": 1340000,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "约134万USDC",
        "tw": "約134萬USDC",
        "en": "Reported loss: $1,340,000"
      },
      "addressDisclosure": "not-published",
      "addresses": [],
      "references": [
        {
          "label": {
            "zh": "PeckShield原帖",
            "tw": "PeckShield原帖",
            "en": "x.com source"
          },
          "url": "https://x.com/PeckShieldAlert/status/2077625630536180100",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-026",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-047",
      "status": "verified",
      "incidentDate": "2026-07-15",
      "datePrecision": "day",
      "title": {
        "zh": "macOS信息窃取木马：劫持Telegram + 调包Ledger/Trezor",
        "tw": "macOS信息竊取木馬：劫持Telegram + 調包Ledger/Trezor",
        "en": "macOS infostealer hijacks Telegram and swaps hardware-wallet apps"
      },
      "summary": {
        "zh": "属高危终端威胁预警；中招后应视为「Telegram + 钱包种子」同时沦陷，立即轮换密钥、冻结 CEX、通知联系人防二次社工。",
        "tw": "屬高危終端威脅預警；中招後應視為「Telegram + 錢包種子」同時淪陷，立即輪換密鑰、凍結 CEX、通知聯繫人防二次社工。",
        "en": "Malware replaced Telegram and Ledger/Trezor software while stealing local credentials; aggregate on-chain loss remains unknown."
      },
      "details": {
        "zh": "## 事件背景\nSlowMist 披露的 macOS stealer 同时打两条高价值路径：\n\n1. Telegram Desktop 会话文件：直接拷贝已登录 session，攻击者可在另一设备「继承」会话，受害者体感像「没输密码/2FA 却丢号」；\n2. 钱包与 Keychain：采集 macOS Keychain、浏览器数据、多款桌面钱包库；\n3. 硬件钱包调包：投放假 Ledger/Trezor 应用，诱导输入助记词/PIN/passphrase。\n\n根因是终端失陷 + 对「会话=登录态」「官方钱包 UI」的信任被伪造。\n\n## 事件经过\n1. 用户通过未知渠道感染 macOS 信息窃取木马（常与假更新、盗版、恶意广告相关）。\n2. 木马采集 Keychain、Safari/浏览器 cookie、Apple Notes、Telegram Desktop 数据、钱包数据库。\n3. 外传至 C2；攻击者导入 Telegram 会话接管账号（可用于社工好友或担保群身份）。\n4. 同步尝试离线破解钱包库，或用假硬件钱包应用骗助记词。\n5. SlowMist 在隔离环境复现攻击链并公开 IOC（IP/URL，非链上地址）。\n\n## 资金流向\n见事件经过；无独立可拆资金路径时以地址与交易章节为准。\n\n## 金额口径\n未公开统一链上总损失；本项属于威胁情报，不计为已确认链上被盗事件\n\n## 证据边界\n无合格完整黑客地址入账。\n\n## 处置状态\n属高危终端威胁预警；中招后应视为「Telegram + 钱包种子」同时沦陷，立即轮换密钥、冻结 CEX、通知联系人防二次社工。",
        "tw": "## 事件背景\nSlowMist 披露的 macOS stealer 同時打兩條高價值路徑：\n\n1. Telegram Desktop 會話文件：直接拷貝已登錄 session，攻擊者可在另一設備「繼承」會話，受害者體感像「沒輸密碼/2FA 卻丟號」；\n2. 錢包與 Keychain：採集 macOS Keychain、瀏覽器數據、多款桌面錢包庫；\n3. 硬件錢包調包：投放假 Ledger/Trezor 應用，誘導輸入助記詞/PIN/passphrase。\n\n根因是終端失陷 + 對「會話=登錄態」「官方錢包 UI」的信任被偽造。\n\n## 事件經過\n1. 用戶通過未知渠道感染 macOS 信息竊取木馬（常與假更新、盜版、惡意廣告相關）。\n2. 木馬採集 Keychain、Safari/瀏覽器 cookie、Apple Notes、Telegram Desktop 數據、錢包數據庫。\n3. 外傳至 C2；攻擊者導入 Telegram 會話接管賬號（可用於社工好友或擔保群身份）。\n4. 同步嘗試離線破解錢包庫，或用假硬件錢包應用騙助記詞。\n5. SlowMist 在隔離環境復現攻擊鏈並公開 IOC（IP/URL，非鏈上地址）。\n\n## 資金流向\n見事件經過；無獨立可拆資金路徑時以地址與交易章節為準。\n\n## 金額口徑\n未公開統一鏈上總損失；本項屬於威脅情報，不計為已確認鏈上被盜事件\n\n## 證據邊界\n無合格完整黑客地址入賬。\n\n## 處置狀態\n屬高危終端威脅預警；中招後應視為「Telegram + 錢包種子」同時淪陷，立即輪換密鑰、凍結 CEX、通知聯繫人防二次社工。",
        "en": "## Incident overview\nMalware replaced Telegram and Ledger/Trezor software while stealing local credentials; aggregate on-chain loss remains unknown.\n\n## Amount basis\nNo single verified USD loss figure was published; see the incident record.\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "supply-chain",
      "severity": "medium",
      "ecosystems": [
        "Other"
      ],
      "chains": [
        "Other"
      ],
      "lossUsd": null,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "未公开统一链上总损失；本项属于威胁情报，不计为已确认链上被盗事件",
        "tw": "未公開統一鏈上總損失；本項屬於威脅情報，不計為已確認鏈上被盜事件",
        "en": "No single verified USD loss figure was published; see the incident record."
      },
      "addressDisclosure": "not-published",
      "addresses": [],
      "references": [
        {
          "label": {
            "zh": "SlowMist分析",
            "tw": "SlowMist分析",
            "en": "slowmist.medium.com source"
          },
          "url": "https://slowmist.medium.com/telegram-account-compromised-wallet-swapped-how-does-macos-malware-break-through-your-defenses-dad9bfed9c02",
          "type": "research"
        },
        {
          "label": {
            "zh": "二次报道",
            "tw": "二次報道",
            "en": "bitcoinfoundation.org source"
          },
          "url": "https://bitcoinfoundation.org/news/crimes-and-fraud-news/mac-malware-can-hijack-telegram-target-crypto-wallets-cybersecurity-analysts-warn/",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-047",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-024",
      "status": "verified",
      "incidentDate": "2026-07-15",
      "datePrecision": "day",
      "title": {
        "zh": "Ostium",
        "tw": "Ostium",
        "en": "Ostium oracle manipulation incident"
      },
      "summary": {
        "zh": "Ostium暂停交易；大部分赃款已换成ETH并混入Tornado Cash，剩余部分跨回Ethereum分散。",
        "tw": "Ostium暫停交易；大部分贓款已換成ETH並混入Tornado Cash，剩餘部分跨回Ethereum分散。",
        "en": "An oracle and pricing weakness caused approximately $23.75 million in reported losses."
      },
      "details": {
        "zh": "## 事件背景\nOstium 是 Arbitrum 上的 RWA 永续（黄金/原油/股指/外汇等），OLP 金库用 USDC 做流动性。价格依赖链下报价 + 链上 授权预言机报告（PriceUpKeep 转发器等自动化组件）。关键缺陷：\n\n1. 攻击者拿到 预言机签名者密钥 或滥用已注册的 PriceUpKeep 转发权限；\n2. 协议校验「签名是否有效、转发器是否注册」，但 没有有效约束：报告时间戳不得为未来、价格偏离外部源的硬限制、单笔/短时异常盈利熔断；\n3. 于是攻击者提交 未来日期 + 被操纵价格 的「合法签名报告」；\n4. 再在高杠杆（公开称可达约 100x）下开平仓循环，制造账面上的交易盈利，从 OLP 金库结算出巨额 USDC。\n\n这不是普通用户仓位被强平，而是 预言机信任根被攻破后的金库会计操纵。金额口径因统计批次不同出现约 1186 万 / 1800 万 / 2375 万 / 约 2400 万等数字，写作时应并列说明。\n\n## 事件经过\n1. 注资：攻击者从 ChangeNOW、Bybit 等获得初始 ETH，跨入 Arbitrum。\n2. 滥用报价路径：通过已注册 PriceUpKeep 转发器提交带有效签名、但价格与时间被操纵的 oracle report。\n3. 虚假盈利循环：在被操纵价格下高杠杆开平仓，触发 OLP 向攻击者支付「盈利」。\n4. 抽水：OLP 被抽走约 1,186 万—2,375 万+ USDC（Blockaid/媒体初值多写约 1800 万；后续跟踪可到约 2400 万）。\n5. 换 ETH：USDC 兑成约 12,084—12,085 ETH。\n6. 清洗：大部分 ETH 进 Tornado Cash；部分跨回 Ethereum 分散到多个下游地址。\n7. 项目：暂停全部交易并调查；Blockaid 披露关键 Tx 0x359f8c05...。\n\n## 资金流向\n5. 换 ETH：USDC 兑成约 12,084—12,085 ETH。\n6. 清洗：大部分 ETH 进 Tornado Cash；部分跨回 Ethereum 分散到多个下游地址。\n\n## 金额口径\n不同批次统计约1186万、1800万至2375万美元；总口径最高约2400万美元\n\n## 证据边界\n以公开可核验来源为界；未证实细节不写入确定结论。\n\n## 处置状态\nOstium暂停交易；大部分赃款已换成ETH并混入Tornado Cash，剩余部分跨回Ethereum分散。",
        "tw": "## 事件背景\nOstium 是 Arbitrum 上的 RWA 永續（黃金/原油/股指/外匯等），OLP 金庫用 USDC 做流動性。價格依賴鏈下報價 + 鏈上 授權預言機報告（PriceUpKeep 轉發器等自動化組件）。關鍵缺陷：\n\n1. 攻擊者拿到 預言機簽名者密鑰 或濫用已註冊的 PriceUpKeep 轉發權限；\n2. 協議校驗「簽名是否有效、轉發器是否註冊」，但 沒有有效約束：報告時間戳不得為未來、價格偏離外部源的硬限制、單筆/短時異常盈利熔斷；\n3. 於是攻擊者提交 未來日期 + 被操縱價格 的「合法簽名報告」；\n4. 再在高槓杆（公開稱可達約 100x）下開平倉循環，製造賬面上的交易盈利，從 OLP 金庫結算出鉅額 USDC。\n\n這不是普通用戶倉位被強平，而是 預言機信任根被攻破後的金庫會計操縱。金額口徑因統計批次不同出現約 1186 萬 / 1800 萬 / 2375 萬 / 約 2400 萬等數字，寫作時應並列說明。\n\n## 事件經過\n1. 注資：攻擊者從 ChangeNOW、Bybit 等獲得初始 ETH，跨入 Arbitrum。\n2. 濫用報價路徑：通過已註冊 PriceUpKeep 轉發器提交帶有效簽名、但價格與時間被操縱的 oracle report。\n3. 虛假盈利循環：在被操縱價格下高槓杆開平倉，觸發 OLP 向攻擊者支付「盈利」。\n4. 抽水：OLP 被抽走約 1,186 萬—2,375 萬+ USDC（Blockaid/媒體初值多寫約 1800 萬；後續跟蹤可到約 2400 萬）。\n5. 換 ETH：USDC 兌成約 12,084—12,085 ETH。\n6. 清洗：大部分 ETH 進 Tornado Cash；部分跨回 Ethereum 分散到多個下游地址。\n7. 項目：暫停全部交易並調查；Blockaid 披露關鍵 Tx 0x359f8c05...。\n\n## 資金流向\n5. 換 ETH：USDC 兌成約 12,084—12,085 ETH。\n6. 清洗：大部分 ETH 進 Tornado Cash；部分跨回 Ethereum 分散到多個下游地址。\n\n## 金額口徑\n不同批次統計約1186萬、1800萬至2375萬美元；總口徑最高約2400萬美元\n\n## 證據邊界\n以公開可核驗來源為界；未證實細節不寫入確定結論。\n\n## 處置狀態\nOstium暫停交易；大部分贓款已換成ETH並混入Tornado Cash，剩餘部分跨回Ethereum分散。",
        "en": "## Incident overview\nAn oracle and pricing weakness caused approximately $23.75 million in reported losses.\n\n## Amount basis\nReported loss: $23,750,000\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "oracle-manipulation",
      "severity": "critical",
      "ecosystems": [
        "Ethereum",
        "Arbitrum"
      ],
      "chains": [
        "Ethereum",
        "Arbitrum"
      ],
      "lossUsd": 23750000,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "不同批次统计约1186万、1800万至2375万美元；总口径最高约2400万美元",
        "tw": "不同批次統計約1186萬、1800萬至2375萬美元；總口徑最高約2400萬美元",
        "en": "Reported loss: $23,750,000"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "Arbitrum",
          "address": "0x321df194646029e7a6193ea05573d4b9c398bfd9",
          "entity": {
            "zh": "[链：Arbitrum] [黑客主地址] [被盗USDC归集] [兑换ETH]",
            "tw": "[鏈：Arbitrum] [黑客主地址] [被盜USDC歸集] [兌換ETH]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/CyversAlerts/status/2077411437782114541",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Arbitrum] [黑客主地址] [被盗USDC归集] [兑换ETH]",
            "tw": "[鏈：Arbitrum] [黑客主地址] [被盜USDC歸集] [兌換ETH]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Arbitrum",
          "address": "0xd1794196f0fc99c7f27970e661597d77d9a85869",
          "entity": {
            "zh": "[链：Arbitrum] [攻击者EOA] [攻击交易发起]",
            "tw": "[鏈：Arbitrum] [攻擊者EOA] [攻擊交易發起]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/CyversAlerts/status/2077411437782114541",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Arbitrum] [攻击者EOA] [攻击交易发起]",
            "tw": "[鏈：Arbitrum] [攻擊者EOA] [攻擊交易發起]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Arbitrum",
          "address": "0xfe12f6360000de49d5506d52ee5ac4bc9dd5bd2e",
          "entity": {
            "zh": "[链：Arbitrum] [黑客合约] [交易执行代理]",
            "tw": "[鏈：Arbitrum] [黑客合約] [交易執行代理]",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/CyversAlerts/status/2077411437782114541",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Arbitrum] [黑客合约] [交易执行代理]",
            "tw": "[鏈：Arbitrum] [黑客合約] [交易執行代理]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0x5209536357034c39E172161501761681aE170873",
          "entity": {
            "zh": "[链：Ethereum] [跨链桥出口] [下游分散]",
            "tw": "[鏈：Ethereum] [跨鏈橋出口] [下游分散]",
            "en": "bridge address documented by a public source"
          },
          "role": "bridge",
          "category": "bridge",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/CyversAlerts/status/2077411437782114541",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [跨链桥出口] [下游分散]",
            "tw": "[鏈：Ethereum] [跨鏈橋出口] [下游分散]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0xe494eed9200385a39dc4038438171051984f518f",
          "entity": {
            "zh": "[链：Ethereum] [跨链桥出口] [下游分散]",
            "tw": "[鏈：Ethereum] [跨鏈橋出口] [下游分散]",
            "en": "bridge address documented by a public source"
          },
          "role": "bridge",
          "category": "bridge",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/CyversAlerts/status/2077411437782114541",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [跨链桥出口] [下游分散]",
            "tw": "[鏈：Ethereum] [跨鏈橋出口] [下游分散]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0x3147a355D55755a30e0f2b86b15429ba1f5E191f",
          "entity": {
            "zh": "[链：Ethereum] [跨链桥出口] [下游分散]",
            "tw": "[鏈：Ethereum] [跨鏈橋出口] [下游分散]",
            "en": "bridge address documented by a public source"
          },
          "role": "bridge",
          "category": "bridge",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/CyversAlerts/status/2077411437782114541",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [跨链桥出口] [下游分散]",
            "tw": "[鏈：Ethereum] [跨鏈橋出口] [下游分散]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "Cyvers资金路径",
            "tw": "Cyvers資金路徑",
            "en": "x.com source"
          },
          "url": "https://x.com/CyversAlerts/status/2077411437782114541",
          "type": "research"
        },
        {
          "label": {
            "zh": "SlowMist根因",
            "tw": "SlowMist根因",
            "en": "x.com source"
          },
          "url": "https://x.com/SlowMist_Team/status/2077421399292166157",
          "type": "research"
        },
        {
          "label": {
            "zh": "CertiK下游地址",
            "tw": "CertiK下游地址",
            "en": "x.com source"
          },
          "url": "https://x.com/CertiKAlert/status/2077613558368788526",
          "type": "research"
        },
        {
          "label": {
            "zh": "Lookonchain混币路径",
            "tw": "Lookonchain混幣路徑",
            "en": "x.com source"
          },
          "url": "https://x.com/lookonchain/status/2077559071159558379",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-024",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-022",
      "status": "verified",
      "incidentDate": "2026-07-15",
      "datePrecision": "day",
      "title": {
        "zh": "Drips Network",
        "tw": "Drips Network",
        "en": "Drips Network protocol incident"
      },
      "summary": {
        "zh": "协议损失约24,882.99 DAI；根因明确为无边界检查的有符号类型转换。",
        "tw": "協議損失約24,882.99 DAI；根因明確為無邊界檢查的有符號類型轉換。",
        "en": "A protocol incident led to approximately $24,883 in reported losses."
      },
      "details": {
        "zh": "## 事件背景\n经典 有符号/无符号整数转换漏洞：\n\n- 函数 DaiDripsHub.give(address,uint128) 接受无符号 uint128 amt；\n- 内部把 amt 转成 int128 做余额加减；\n- 缺少 amt <= type(int128).max 检查；\n- 当 amt 接近 2^128 时，转换后变成 负数（或极端有符号值），内部会计被破坏，攻击者可据此提取不应得的 DAI。\n\n## 事件经过\n1. 攻击者构造畸形 amt 调用 give。\n2. 类型转换溢出/绕界，内部余额逻辑失效。\n3. 攻击者提走约 24,882.99 DAI。\n4. SlowMist 给出根因说明；完整攻击者地址与 Tx 未在公开摘要齐备 → 不猜补。\n\n## 资金流向\n见事件经过；无独立可拆资金路径时以地址与交易章节为准。\n\n## 金额口径\n24,882.99 DAI\n\n## 证据边界\n完整地址/Tx 不足时不猜补。\n\n## 处置状态\n协议损失约24,882.99 DAI；根因明确为无边界检查的有符号类型转换。",
        "tw": "## 事件背景\n經典 有符號/無符號整數轉換漏洞：\n\n- 函數 DaiDripsHub.give(address,uint128) 接受無符號 uint128 amt；\n- 內部把 amt 轉成 int128 做餘額加減；\n- 缺少 amt <= type(int128).max 檢查；\n- 當 amt 接近 2^128 時，轉換後變成 負數（或極端有符號值），內部會計被破壞，攻擊者可據此提取不應得的 DAI。\n\n## 事件經過\n1. 攻擊者構造畸形 amt 調用 give。\n2. 類型轉換溢出/繞界，內部餘額邏輯失效。\n3. 攻擊者提走約 24,882.99 DAI。\n4. SlowMist 給出根因說明；完整攻擊者地址與 Tx 未在公開摘要齊備 → 不猜補。\n\n## 資金流向\n見事件經過；無獨立可拆資金路徑時以地址與交易章節為準。\n\n## 金額口徑\n24,882.99 DAI\n\n## 證據邊界\n完整地址/Tx 不足時不猜補。\n\n## 處置狀態\n協議損失約24,882.99 DAI；根因明確為無邊界檢查的有符號類型轉換。",
        "en": "## Incident overview\nA protocol incident led to approximately $24,883 in reported losses.\n\n## Amount basis\nReported loss: $24,883\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "protocol-exploit",
      "severity": "high",
      "ecosystems": [
        "Ethereum"
      ],
      "chains": [
        "Ethereum"
      ],
      "lossUsd": 24882.99,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "24,882.99 DAI",
        "tw": "24,882.99 DAI",
        "en": "Reported loss: $24,883"
      },
      "addressDisclosure": "not-published",
      "addresses": [],
      "references": [
        {
          "label": {
            "zh": "SlowMist技术说明",
            "tw": "SlowMist技術說明",
            "en": "x.com source"
          },
          "url": "https://x.com/SlowMist_Team/status/2077232524955423144",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-022",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-025",
      "status": "verified",
      "incidentDate": "2026-07-14",
      "datePrecision": "day",
      "title": {
        "zh": "伊朗央行关联TRON地址被Tether冻结",
        "tw": "伊朗央行關聯TRON地址被Tether凍結",
        "en": "Tether freezes TRON addresses linked to Iran central bank"
      },
      "summary": {
        "zh": "（见来源）",
        "tw": "（見來源）",
        "en": "Tether restricted USDT held at TRON addresses publicly linked to an OFAC action; the frozen amount is not treated as theft loss."
      },
      "details": {
        "zh": "## 事件背景\n这不是黑客攻击，而是 制裁合规动作：OFAC 将与伊朗央行相关的加密地址列入制裁名单后，USDT 发行方 Tether 在 TRON 的 USDT 合约上调用 黑名单/冻结 功能。稳定币为中心化发行，合约层可禁止被标记地址转出 USDT；但 链上私钥仍在原控制方，只是该合约资产无法移动。必须与「司法扣押私钥/服务器」区分。\n\n## 事件经过\n1. 2026-07-14 OFAC 更新制裁名单，点名与伊朗央行相关的加密钱包。\n2. 约 07-15 05:02（北京时间）Tether 在 TRON 执行冻结。\n3. 四个地址合计被冻约 130,097,237.22 USDT（媒体常写约 1.31 亿美元）。\n4. 各地址冻结金额与 Tx 见下表；私钥未转移给执法机关。\n\n## 资金流向\n见事件经过；无独立可拆资金路径时以地址与交易章节为准。\n\n## 金额口径\n未统一/见正文\n\n## 证据边界\n以公开可核验来源为界；未证实细节不写入确定结论。\n\n## 处置状态\n（见来源）",
        "tw": "## 事件背景\n這不是黑客攻擊，而是 制裁合規動作：OFAC 將與伊朗央行相關的加密地址列入制裁名單後，USDT 發行方 Tether 在 TRON 的 USDT 合約上調用 黑名單/凍結 功能。穩定幣為中心化發行，合約層可禁止被標記地址轉出 USDT；但 鏈上私鑰仍在原控制方，只是該合約資產無法移動。必須與「司法扣押私鑰/服務器」區分。\n\n## 事件經過\n1. 2026-07-14 OFAC 更新制裁名單，點名與伊朗央行相關的加密錢包。\n2. 約 07-15 05:02（北京時間）Tether 在 TRON 執行凍結。\n3. 四個地址合計被凍約 130,097,237.22 USDT（媒體常寫約 1.31 億美元）。\n4. 各地址凍結金額與 Tx 見下表；私鑰未轉移給執法機關。\n\n## 資金流向\n見事件經過；無獨立可拆資金路徑時以地址與交易章節為準。\n\n## 金額口徑\n未統一/見正文\n\n## 證據邊界\n以公開可核驗來源為界；未證實細節不寫入確定結論。\n\n## 處置狀態\n（見來源）",
        "en": "## Incident overview\nTether restricted USDT held at TRON addresses publicly linked to an OFAC action; the frozen amount is not treated as theft loss.\n\n## Amount basis\nNo single verified USD loss figure was published; see the incident record.\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "issuer-freeze",
      "severity": "medium",
      "ecosystems": [
        "TRON"
      ],
      "chains": [
        "TRON"
      ],
      "lossUsd": null,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "未统一/见正文",
        "tw": "未統一/見正文",
        "en": "No single verified USD loss figure was published; see the incident record."
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "TRON",
          "address": "TFQbqaNbmq2xsVor2NbufLkYZvxFC9wC7k",
          "entity": {
            "zh": "[链：TRON] [受制裁地址] [稳定币冻结]，85,527,016 USDT",
            "tw": "[鏈：TRON] [受制裁地址] [穩定幣凍結]，85,527,016 USDT",
            "en": "other address documented by a public source"
          },
          "role": "other",
          "category": "issuer_restricted",
          "confidence": 0.9,
          "sourceUrl": "https://tronscan.org/#/address/TFQbqaNbmq2xsVor2NbufLkYZvxFC9wC7k",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：TRON] [受制裁地址] [稳定币冻结]，85,527,016 USDT",
            "tw": "[鏈：TRON] [受制裁地址] [穩定幣凍結]，85,527,016 USDT",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "TRON",
          "address": "TJdgB1k6ot3f2nLuZug6D8eD3HavTmzmSK",
          "entity": {
            "zh": "[链：TRON] [受制裁地址] [稳定币冻结]，30,978,224.26 USDT",
            "tw": "[鏈：TRON] [受制裁地址] [穩定幣凍結]，30,978,224.26 USDT",
            "en": "other address documented by a public source"
          },
          "role": "other",
          "category": "issuer_restricted",
          "confidence": 0.9,
          "sourceUrl": "https://tronscan.org/#/address/TFQbqaNbmq2xsVor2NbufLkYZvxFC9wC7k",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：TRON] [受制裁地址] [稳定币冻结]，30,978,224.26 USDT",
            "tw": "[鏈：TRON] [受制裁地址] [穩定幣凍結]，30,978,224.26 USDT",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "TRON",
          "address": "TAhwhFv3JpK39Nc2m8W5LPCcoTisutiRfp",
          "entity": {
            "zh": "[链：TRON] [受制裁地址] [稳定币冻结]，1,285,180.48 USDT",
            "tw": "[鏈：TRON] [受制裁地址] [穩定幣凍結]，1,285,180.48 USDT",
            "en": "other address documented by a public source"
          },
          "role": "other",
          "category": "issuer_restricted",
          "confidence": 0.9,
          "sourceUrl": "https://tronscan.org/#/address/TFQbqaNbmq2xsVor2NbufLkYZvxFC9wC7k",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：TRON] [受制裁地址] [稳定币冻结]，1,285,180.48 USDT",
            "tw": "[鏈：TRON] [受制裁地址] [穩定幣凍結]，1,285,180.48 USDT",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "TRON",
          "address": "TXGHxdYbGy574z5hBu4LNzq9NzjZQ9bhUf",
          "entity": {
            "zh": "[链：TRON] [受制裁地址] [稳定币冻结]，12,306,816.48 USDT",
            "tw": "[鏈：TRON] [受制裁地址] [穩定幣凍結]，12,306,816.48 USDT",
            "en": "other address documented by a public source"
          },
          "role": "other",
          "category": "issuer_restricted",
          "confidence": 0.9,
          "sourceUrl": "https://tronscan.org/#/address/TFQbqaNbmq2xsVor2NbufLkYZvxFC9wC7k",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：TRON] [受制裁地址] [稳定币冻结]，12,306,816.48 USDT",
            "tw": "[鏈：TRON] [受制裁地址] [穩定幣凍結]，12,306,816.48 USDT",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "TRON地址1",
            "tw": "TRON地址1",
            "en": "tronscan.org source"
          },
          "url": "https://tronscan.org/#/address/TFQbqaNbmq2xsVor2NbufLkYZvxFC9wC7k",
          "type": "research"
        },
        {
          "label": {
            "zh": "TRON地址2",
            "tw": "TRON地址2",
            "en": "tronscan.org source"
          },
          "url": "https://tronscan.org/#/address/TJdgB1k6ot3f2nLuZug6D8eD3HavTmzmSK",
          "type": "research"
        },
        {
          "label": {
            "zh": "TRON地址3",
            "tw": "TRON地址3",
            "en": "tronscan.org source"
          },
          "url": "https://tronscan.org/#/address/TAhwhFv3JpK39Nc2m8W5LPCcoTisutiRfp",
          "type": "research"
        },
        {
          "label": {
            "zh": "TRON地址4",
            "tw": "TRON地址4",
            "en": "tronscan.org source"
          },
          "url": "https://tronscan.org/#/address/TXGHxdYbGy574z5hBu4LNzq9NzjZQ9bhUf",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-025",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-021",
      "status": "verified",
      "incidentDate": "2026-07-14",
      "datePrecision": "day",
      "title": {
        "zh": "VECAndETH",
        "tw": "VECAndETH",
        "en": "VECAndETH protocol exploit"
      },
      "summary": {
        "zh": "损失约10.96万美元；地址角色仍需基于完整Trace确认。",
        "tw": "損失約10.96萬美元；地址角色仍需基於完整Trace確認。",
        "en": "A contract-level weakness was exploited for approximately $109,600."
      },
      "details": {
        "zh": "## 事件背景\n公开信息指向 同一原子交易内的价格操纵：通过组合 swap / 流动性操作扭曲 VEC/ETH 相关定价，使协议在错误价格下释放价值。因项目方无完整 post-mortem，具体是现货池操纵、预言机读取槽位还是内部汇率公式，保持克制，不臆造函数名。\n\n## 事件经过\n1. 7 月 14 日 09:26（北京时间）TenArmor 告警。\n2. 攻击交易在 BNB Chain 上执行，扭曲 VEC/ETH 价格并提取错误定价下的资产。\n3. 损失约 10.96 万美元。\n4. 已有完整攻击 Tx；黑客 EOA / 攻击合约角色需 Trace 后再贴标签，避免把 router 误标黑客。\n\n## 资金流向\n见事件经过；无独立可拆资金路径时以地址与交易章节为准。\n\n## 金额口径\n约10.96万美元\n\n## 证据边界\n部分角色/根因仍待核。\n\n## 处置状态\n损失约10.96万美元；地址角色仍需基于完整Trace确认。",
        "tw": "## 事件背景\n公開信息指向 同一原子交易內的價格操縱：通過組合 swap / 流動性操作扭曲 VEC/ETH 相關定價，使協議在錯誤價格下釋放價值。因項目方無完整 post-mortem，具體是現貨池操縱、預言機讀取槽位還是內部匯率公式，保持克制，不臆造函數名。\n\n## 事件經過\n1. 7 月 14 日 09:26（北京時間）TenArmor 告警。\n2. 攻擊交易在 BNB Chain 上執行，扭曲 VEC/ETH 價格並提取錯誤定價下的資產。\n3. 損失約 10.96 萬美元。\n4. 已有完整攻擊 Tx；黑客 EOA / 攻擊合約角色需 Trace 後再貼標籤，避免把 router 誤標黑客。\n\n## 資金流向\n見事件經過；無獨立可拆資金路徑時以地址與交易章節為準。\n\n## 金額口徑\n約10.96萬美元\n\n## 證據邊界\n部分角色/根因仍待核。\n\n## 處置狀態\n損失約10.96萬美元；地址角色仍需基於完整Trace確認。",
        "en": "## Incident overview\nA contract-level weakness was exploited for approximately $109,600.\n\n## Amount basis\nReported loss: $109,600\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "protocol-exploit",
      "severity": "high",
      "ecosystems": [
        "BNB Chain"
      ],
      "chains": [
        "BNB Chain"
      ],
      "lossUsd": 109600,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "约10.96万美元",
        "tw": "約10.96萬美元",
        "en": "Reported loss: $109,600"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "BNB Chain",
          "address": "0x39B3D12f8C4e9644f8A9Eba9c07Ca37DF9eCF27c",
          "entity": {
            "zh": "[链：BNB Chain / BSC] [黑客地址] [攻击者EOA/合约] [From=To 自调用] [被盗资产接收]",
            "tw": "[鏈：BNB Chain / BSC] [黑客地址] [攻擊者EOA/合約] [From=To 自調用] [被盜資產接收]",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://bscscan.com/tx/0xe1f1e3e0706aa995b47a8ba1d310526e14f4db6ad78277853fa10932236eeb72",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain / BSC] [黑客地址] [攻击者EOA/合约] [From=To 自调用] [被盗资产接收]",
            "tw": "[鏈：BNB Chain / BSC] [黑客地址] [攻擊者EOA/合約] [From=To 自調用] [被盜資產接收]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0xdD48A20Bf08500416f246F3a7899e916e8f03075",
          "entity": {
            "zh": "[链：BNB Chain / BSC] [委托执行地址 EIP-7702 Delegated] [攻击执行路径]",
            "tw": "[鏈：BNB Chain / BSC] [委託執行地址 EIP-7702 Delegated] [攻擊執行路徑]",
            "en": "other address documented by a public source"
          },
          "role": "other",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://bscscan.com/tx/0xe1f1e3e0706aa995b47a8ba1d310526e14f4db6ad78277853fa10932236eeb72",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain / BSC] [委托执行地址 EIP-7702 Delegated] [攻击执行路径]",
            "tw": "[鏈：BNB Chain / BSC] [委託執行地址 EIP-7702 Delegated] [攻擊執行路徑]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "BscScan",
            "tw": "BscScan",
            "en": "bscscan.com source"
          },
          "url": "https://bscscan.com/tx/0xe1f1e3e0706aa995b47a8ba1d310526e14f4db6ad78277853fa10932236eeb72",
          "type": "research"
        },
        {
          "label": {
            "zh": "TenArmor原帖",
            "tw": "TenArmor原帖",
            "en": "x.com source"
          },
          "url": "https://x.com/TenArmorAlert/status/2076840799535542500",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-021",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-020",
      "status": "verified",
      "incidentDate": "2026-07-13",
      "datePrecision": "day",
      "title": {
        "zh": "Lumi Finance智能账户授权漏洞",
        "tw": "Lumi Finance智能賬戶授權漏洞",
        "en": "Lumi Finance smart-account authorization flaw"
      },
      "summary": {
        "zh": "约26.4万美元被盗；项目需把验证逻辑改为无状态副作用并撤销风险授权。",
        "tw": "約26.4萬美元被盜；項目需把驗證邏輯改為無狀態副作用並撤銷風險授權。",
        "en": "An authorization weakness affecting smart accounts enabled approximately $270,000 in unauthorized asset transfers."
      },
      "details": {
        "zh": "## 事件背景\nLumi Finance 使用 ERC-4337 账户抽象（Sodium 智能账户）。漏洞出在 validateUserOp / _validateSignature 路径：\n\n1. 验证 UserOperation 时允许执行 带状态副作用 的逻辑（例如 ERC-20 approve）；\n2. 攻击者可把自身地址作为 signer 参数传入；ECDSA.tryRecover 失败时 不 revert，反而走到攻击合约的 isValidSignature，使验证「通过」；\n3. 攻击者控制的 Paymaster / spender 在验证阶段批量拿到多个智能账户的 token allowance；\n4. 用户从未在 UI 上确认「转走资产」，只是账户校验逻辑被滥用 → 随后 transferFrom 抽干授权额度。\n\n根因一句话：验证阶段必须无副作用（stateless validation），却被做成了可写授权的后门。\n\n## 事件经过\n1. Blockaid 等监测到 Lumi 相关异常转出（约 7 月 13 日）。\n2. 攻击者构造恶意 UserOperation，在 validate 阶段对大量智能账户执行 Approve。\n3. 随即用拿到的 allowance 转出 USDC 等资产，合计约 26.4 万—27 万美元。\n4. SlowMist 公开技术根因；完整攻击者/受害者地址列表未在摘要中全部给出 → 不猜补。\n5. 修复方向：验证改无副作用、撤销风险授权、升级账户实现。\n\n## 资金流向\n1. Blockaid 等监测到 Lumi 相关异常转出（约 7 月 13 日）。\n3. 随即用拿到的 allowance 转出 USDC 等资产，合计约 26.4 万—27 万美元。\n\n## 金额口径\n约26.4万—27万美元（媒体/SlowMist 多写约 27 万；原稿 26.4 万为并行口径）\n\n## 证据边界\n完整地址/Tx 不足时不猜补。\n\n## 处置状态\n约26.4万美元被盗；项目需把验证逻辑改为无状态副作用并撤销风险授权。",
        "tw": "## 事件背景\nLumi Finance 使用 ERC-4337 賬戶抽象（Sodium 智能賬戶）。漏洞出在 validateUserOp / _validateSignature 路徑：\n\n1. 驗證 UserOperation 時允許執行 帶狀態副作用 的邏輯（例如 ERC-20 approve）；\n2. 攻擊者可把自身地址作為 signer 參數傳入；ECDSA.tryRecover 失敗時 不 revert，反而走到攻擊合約的 isValidSignature，使驗證「通過」；\n3. 攻擊者控制的 Paymaster / spender 在驗證階段批量拿到多個智能賬戶的 token allowance；\n4. 用戶從未在 UI 上確認「轉走資產」，只是賬戶校驗邏輯被濫用 → 隨後 transferFrom 抽乾授權額度。\n\n根因一句話：驗證階段必須無副作用（stateless validation），卻被做成了可寫授權的後門。\n\n## 事件經過\n1. Blockaid 等監測到 Lumi 相關異常轉出（約 7 月 13 日）。\n2. 攻擊者構造惡意 UserOperation，在 validate 階段對大量智能賬戶執行 Approve。\n3. 隨即用拿到的 allowance 轉出 USDC 等資產，合計約 26.4 萬—27 萬美元。\n4. SlowMist 公開技術根因；完整攻擊者/受害者地址列表未在摘要中全部給出 → 不猜補。\n5. 修復方向：驗證改無副作用、撤銷風險授權、升級賬戶實現。\n\n## 資金流向\n1. Blockaid 等監測到 Lumi 相關異常轉出（約 7 月 13 日）。\n3. 隨即用拿到的 allowance 轉出 USDC 等資產，合計約 26.4 萬—27 萬美元。\n\n## 金額口徑\n約26.4萬—27萬美元（媒體/SlowMist 多寫約 27 萬；原稿 26.4 萬為並行口徑）\n\n## 證據邊界\n完整地址/Tx 不足時不猜補。\n\n## 處置狀態\n約26.4萬美元被盜；項目需把驗證邏輯改為無狀態副作用並撤銷風險授權。",
        "en": "## Incident overview\nAn authorization weakness affecting smart accounts enabled approximately $270,000 in unauthorized asset transfers.\n\n## Amount basis\nReported loss: $270,000\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "wallet-vulnerability",
      "severity": "high",
      "ecosystems": [
        "Arbitrum"
      ],
      "chains": [
        "Arbitrum"
      ],
      "lossUsd": 270000,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "约26.4万—27万美元（媒体/SlowMist 多写约 27 万；原稿 26.4 万为并行口径）",
        "tw": "約26.4萬—27萬美元（媒體/SlowMist 多寫約 27 萬；原稿 26.4 萬為並行口徑）",
        "en": "Reported loss: $270,000"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "Arbitrum",
          "address": "0xCe1a3BB0b98D0D90C7Dd0620Ab86C9A771888d88",
          "entity": {
            "zh": "[链：Arbitrum] [黑客地址] [攻击者EOA]",
            "tw": "[鏈：Arbitrum] [黑客地址] [攻擊者EOA]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/SlowMist_Team/status/2076669154036527314",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Arbitrum] [黑客地址] [攻击者EOA]",
            "tw": "[鏈：Arbitrum] [黑客地址] [攻擊者EOA]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Arbitrum",
          "address": "0x56362412AE17cac443AAFBAb4289946Ad958E8a1",
          "entity": {
            "zh": "[链：Arbitrum] [黑客合约] [恶意Paymaster/Spender/ERC-1271签名者]",
            "tw": "[鏈：Arbitrum] [黑客合約] [惡意Paymaster/Spender/ERC-1271簽名者]",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/SlowMist_Team/status/2076669154036527314",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Arbitrum] [黑客合约] [恶意Paymaster/Spender/ERC-1271签名者]",
            "tw": "[鏈：Arbitrum] [黑客合約] [惡意Paymaster/Spender/ERC-1271簽名者]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Arbitrum",
          "address": "0xb5BC46dF04dEe31D219E7664122e29EEd9506b8b",
          "entity": {
            "zh": "[链：Arbitrum] [受影响合约] [Sodium实现]",
            "tw": "[鏈：Arbitrum] [受影響合約] [Sodium實現]",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/SlowMist_Team/status/2076669154036527314",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Arbitrum] [受影响合约] [Sodium实现]",
            "tw": "[鏈：Arbitrum] [受影響合約] [Sodium實現]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Arbitrum",
          "address": "0x5FF137D4b0FDCD49DcA30c7CF57E578a026d2789",
          "entity": {
            "zh": "[链：Arbitrum] [ERC-4337 EntryPoint v0.6]",
            "tw": "[鏈：Arbitrum] [ERC-4337 EntryPoint v0.6]",
            "en": "other address documented by a public source"
          },
          "role": "other",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/SlowMist_Team/status/2076669154036527314",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Arbitrum] [ERC-4337 EntryPoint v0.6]",
            "tw": "[鏈：Arbitrum] [ERC-4337 EntryPoint v0.6]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "SlowMist根因",
            "tw": "SlowMist根因",
            "en": "x.com source"
          },
          "url": "https://x.com/SlowMist_Team/status/2076669154036527314",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-020",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-048",
      "status": "verified",
      "incidentDate": "2026-07-12",
      "datePrecision": "day",
      "title": {
        "zh": "PHX（BSC）Pancake LP 被抽",
        "tw": "PHX（BSC）Pancake LP 被抽",
        "en": "PHX Pancake LP drain on BNB Chain"
      },
      "summary": {
        "zh": "LP 侧约 156.21 WBNB（~$89.6K）被抽；典型小市值土狗单笔风险。 地址与 Tx 已按 BscScan / TenArmor / 技术复盘入正式账本。",
        "tw": "LP 側約 156.21 WBNB（~$89.6K）被抽；典型小市值土狗單筆風險。 地址與 Tx 已按 BscScan / TenArmor / 技術復盤入正式賬本。",
        "en": "Liquidity was removed from a PHX Pancake pool, causing approximately $89,600 in reported losses."
      },
      "details": {
        "zh": "## 事件背景\nPHX 为低市值、上线不久的 BSC 代币，在 PancakeSwap V2 与 WBNB 组池。代币自定义 fee-on-transfer / burn 逻辑在错误时序调用 pair 的 sync，使池子记账 reserve 与真实余额脱节。攻击者用 Lista DAO Moolah 等闪电贷放大操纵，在同一笔交易内把失步后的 WBNB 抽走并偿还贷款，净利约 156.2056833669 WBNB（TenArmor 约 $89.6K）。根因在代币合约，而非 Pancake 本体被黑。\n\n## 事件经过\n1. TenArmorAlert 监测到 PHX 相关可疑攻击 Tx，损失约 $89.6K。\n2. 攻击部署合约栈（交易内 Create + 执行器）；先借入流动性，把资金打入 PHX-WBNB 池并配合 fee/burn 路径扭曲余额。\n3. burn→sync 错误顺序导致一侧 reserve 与真实余额失步，下一笔 swap 按错误定价吐出 WBNB。\n4. 攻击者 EOA 归集利润、偿还闪电贷，攻击在单笔 Tx 内结束。\n5. 与 6 月底 AIDC、OLPC/LABUBU 及本月 VECAndETH/FCOW/CRC/RWT 等同属 BSC 自定义税费/burn × AMM 攻击簇。\n\n## 资金流向\n4. 攻击者 EOA 归集利润、偿还闪电贷，攻击在单笔 Tx 内结束。\n\n## 金额口径\n约 156.2056833669 WBNB；TenArmor 估值约 8.96 万美元（~$89.6K）\n\n## 证据边界\n以公开可核验来源为界；未证实细节不写入确定结论。\n\n## 处置状态\n- LP 侧约 156.21 WBNB（~$89.6K）被抽；典型小市值土狗单笔风险。\n- 地址与 Tx 已按 BscScan / TenArmor / 技术复盘入正式账本。",
        "tw": "## 事件背景\nPHX 為低市值、上線不久的 BSC 代幣，在 PancakeSwap V2 與 WBNB 組池。代幣自定義 fee-on-transfer / burn 邏輯在錯誤時序調用 pair 的 sync，使池子記賬 reserve 與真實餘額脫節。攻擊者用 Lista DAO Moolah 等閃電貸放大操縱，在同一筆交易內把失步後的 WBNB 抽走並償還貸款，淨利約 156.2056833669 WBNB（TenArmor 約 $89.6K）。根因在代幣合約，而非 Pancake 本體被黑。\n\n## 事件經過\n1. TenArmorAlert 監測到 PHX 相關可疑攻擊 Tx，損失約 $89.6K。\n2. 攻擊部署合約棧（交易內 Create + 執行器）；先借入流動性，把資金打入 PHX-WBNB 池並配合 fee/burn 路徑扭曲餘額。\n3. burn→sync 錯誤順序導致一側 reserve 與真實餘額失步，下一筆 swap 按錯誤定價吐出 WBNB。\n4. 攻擊者 EOA 歸集利潤、償還閃電貸，攻擊在單筆 Tx 內結束。\n5. 與 6 月底 AIDC、OLPC/LABUBU 及本月 VECAndETH/FCOW/CRC/RWT 等同屬 BSC 自定義稅費/burn × AMM 攻擊簇。\n\n## 資金流向\n4. 攻擊者 EOA 歸集利潤、償還閃電貸，攻擊在單筆 Tx 內結束。\n\n## 金額口徑\n約 156.2056833669 WBNB；TenArmor 估值約 8.96 萬美元（~$89.6K）\n\n## 證據邊界\n以公開可核驗來源為界；未證實細節不寫入確定結論。\n\n## 處置狀態\n- LP 側約 156.21 WBNB（~$89.6K）被抽；典型小市值土狗單筆風險。\n- 地址與 Tx 已按 BscScan / TenArmor / 技術復盤入正式賬本。",
        "en": "## Incident overview\nLiquidity was removed from a PHX Pancake pool, causing approximately $89,600 in reported losses.\n\n## Amount basis\nReported loss: $89,600\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "protocol-exploit",
      "severity": "high",
      "ecosystems": [
        "BNB Chain"
      ],
      "chains": [
        "BNB Chain"
      ],
      "lossUsd": 89600,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "约 **156.2056833669 WBNB**；TenArmor 估值约 **8.96 万美元**（~$89.6K）",
        "tw": "約 **156.2056833669 WBNB**；TenArmor 估值約 **8.96 萬美元**（~$89.6K）",
        "en": "Reported loss: $89,600"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "BNB Chain",
          "address": "0xf61FF6CD361561aC0274a7d3D197C79310bDEE61",
          "entity": {
            "zh": "[链：BNB Chain] [黑客地址] [攻击者EOA] [资金归集]",
            "tw": "[鏈：BNB Chain] [黑客地址] [攻擊者EOA] [資金歸集]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/TenArmorAlert/status/2076475785322635586",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain] [黑客地址] [攻击者EOA] [资金归集]",
            "tw": "[鏈：BNB Chain] [黑客地址] [攻擊者EOA] [資金歸集]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0x843d8c184355d53f68ecdd1114d1327f3be08d6d",
          "entity": {
            "zh": "[链：BNB Chain] [黑客合约] [交易内 Create]",
            "tw": "[鏈：BNB Chain] [黑客合約] [交易內 Create]",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/TenArmorAlert/status/2076475785322635586",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain] [黑客合约] [交易内 Create]",
            "tw": "[鏈：BNB Chain] [黑客合約] [交易內 Create]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0x8d161cb068a576b53f5be6f9f024b9c489e005f8",
          "entity": {
            "zh": "[链：BNB Chain] [黑客合约] [攻击执行器]",
            "tw": "[鏈：BNB Chain] [黑客合約] [攻擊執行器]",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/TenArmorAlert/status/2076475785322635586",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain] [黑客合约] [攻击执行器]",
            "tw": "[鏈：BNB Chain] [黑客合約] [攻擊執行器]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0x2540cdc3317aa614178c29e2a1c7d5cdcebba481",
          "entity": {
            "zh": "[链：BNB Chain] [代币合约] [PHX Token]（不是黑客）",
            "tw": "[鏈：BNB Chain] [代幣合約] [PHX Token]（不是黑客）",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/TenArmorAlert/status/2076475785322635586",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain] [代币合约] [PHX Token]（不是黑客）",
            "tw": "[鏈：BNB Chain] [代幣合約] [PHX Token]（不是黑客）",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "BNB Chain",
          "address": "0x09dbd035059b954d1d9c0076bdf6f70d2efeb6cf",
          "entity": {
            "zh": "[链：BNB Chain] [交易对/LP] [PancakeSwap V2 PHX-WBNB]（不是黑客）",
            "tw": "[鏈：BNB Chain] [交易對/LP] [PancakeSwap V2 PHX-WBNB]（不是黑客）",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/TenArmorAlert/status/2076475785322635586",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：BNB Chain] [交易对/LP] [PancakeSwap V2 PHX-WBNB]（不是黑客）",
            "tw": "[鏈：BNB Chain] [交易對/LP] [PancakeSwap V2 PHX-WBNB]（不是黑客）",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "TenArmor 原帖",
            "tw": "TenArmor 原帖",
            "en": "x.com source"
          },
          "url": "https://x.com/TenArmorAlert/status/2076475785322635586",
          "type": "research"
        },
        {
          "label": {
            "zh": "BscScan 攻击交易",
            "tw": "BscScan 攻擊交易",
            "en": "bscscan.com source"
          },
          "url": "https://bscscan.com/tx/0xb5a64c9c43da7b817b2450149b55cb542697d9a676b2f8a89ec748b37f821ebe",
          "type": "research"
        },
        {
          "label": {
            "zh": "技术复盘 · The Crypto Times",
            "tw": "技術復盤 · The Crypto Times",
            "en": "cryptotimes.io source"
          },
          "url": "https://www.cryptotimes.io/2026/07/13/phx-wbnb-liquidity-pool-drained-of-nearly-90k-in-bnb-chain-exploit/",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-048",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-019",
      "status": "verified",
      "incidentDate": "2026-07-11",
      "datePrecision": "day",
      "title": {
        "zh": "Solana OG个人钱包被盗",
        "tw": "Solana OG個人錢包被盜",
        "en": "Solana OG personal wallet theft"
      },
      "summary": {
        "zh": "被盗SOL已大体完成出售和跨链；后续是否进入混币器未获同等级证据确认。",
        "tw": "被盜SOL已大體完成出售和跨鏈；後續是否進入混幣器未獲同等級證據確認。",
        "en": "A long-time Solana holder lost assets estimated at about $14.2 million after a personal wallet compromise."
      },
      "details": {
        "zh": "## 事件背景\n这是 个人钱包被盗，不是协议 TVL 被抽干。公开监测只看到「大额 SOL 非正常转出 → 市价卖出 → 跨链」，根因在公开渠道仍属 [待核]，可能包括：\n\n1. 私钥/种子泄露（钓鱼、木马、备份泄露、假硬件钱包）；\n2. 恶意授权 / 恶意签名（Approve、恶意 program 调用）；\n3. 社会工程（假客服、假空投、远程协助）；\n4. 设备失陷后的会话劫持。\n\n在未看到受害方设备取证与完整签名日志前，不能把根因写成某一种。\n\n## 事件经过\n1. 约 181,000 SOL 从受害钱包转出至攻击者控制地址（当时约 1,420 万美元）。\n2. 攻击者在 Solana 上卖出全部 SOL，换成可跨链资产。\n3. 经跨链桥进入 Ethereum，接收地址拿到资金后继续归集。\n4. 最终兑得约 7,918 ETH。\n5. 受害者完整地址未公开；是否进入 Tornado 等混币器未获与主路径同级证据。\n\n## 资金流向\n1. 约 181,000 SOL 从受害钱包转出至攻击者控制地址（当时约 1,420 万美元）。\n2. 攻击者在 Solana 上卖出全部 SOL，换成可跨链资产。\n3. 经跨链桥进入 Ethereum，接收地址拿到资金后继续归集。\n4. 最终兑得约 7,918 ETH。\n5. 受害者完整地址未公开；是否进入 Tornado 等混币器未获与主路径同级证据。\n\n## 金额口径\n181,000 SOL，约1420万美元\n\n## 证据边界\n部分角色/根因仍待核。\n\n## 处置状态\n被盗SOL已大体完成出售和跨链；后续是否进入混币器未获同等级证据确认。",
        "tw": "## 事件背景\n這是 個人錢包被盜，不是協議 TVL 被抽乾。公開監測只看到「大額 SOL 非正常轉出 → 市價賣出 → 跨鏈」，根因在公開渠道仍屬 [待核]，可能包括：\n\n1. 私鑰/種子洩露（釣魚、木馬、備份洩露、假硬件錢包）；\n2. 惡意授權 / 惡意簽名（Approve、惡意 program 調用）；\n3. 社會工程（假客服、假空投、遠程協助）；\n4. 設備失陷後的會話劫持。\n\n在未看到受害方設備取證與完整簽名日誌前，不能把根因寫成某一種。\n\n## 事件經過\n1. 約 181,000 SOL 從受害錢包轉出至攻擊者控制地址（當時約 1,420 萬美元）。\n2. 攻擊者在 Solana 上賣出全部 SOL，換成可跨鏈資產。\n3. 經跨鏈橋進入 Ethereum，接收地址拿到資金後繼續歸集。\n4. 最終兌得約 7,918 ETH。\n5. 受害者完整地址未公開；是否進入 Tornado 等混幣器未獲與主路徑同級證據。\n\n## 資金流向\n1. 約 181,000 SOL 從受害錢包轉出至攻擊者控制地址（當時約 1,420 萬美元）。\n2. 攻擊者在 Solana 上賣出全部 SOL，換成可跨鏈資產。\n3. 經跨鏈橋進入 Ethereum，接收地址拿到資金後繼續歸集。\n4. 最終兌得約 7,918 ETH。\n5. 受害者完整地址未公開；是否進入 Tornado 等混幣器未獲與主路徑同級證據。\n\n## 金額口徑\n181,000 SOL，約1420萬美元\n\n## 證據邊界\n部分角色/根因仍待核。\n\n## 處置狀態\n被盜SOL已大體完成出售和跨鏈；後續是否進入混幣器未獲同等級證據確認。",
        "en": "## Incident overview\nA long-time Solana holder lost assets estimated at about $14.2 million after a personal wallet compromise.\n\n## Amount basis\nReported loss: $14,200,000\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "key-compromise",
      "severity": "critical",
      "ecosystems": [
        "Ethereum",
        "Solana"
      ],
      "chains": [
        "Ethereum",
        "Solana"
      ],
      "lossUsd": 14200000,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "181,000 SOL，约1420万美元",
        "tw": "181,000 SOL，約1420萬美元",
        "en": "Reported loss: $14,200,000"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "Solana",
          "address": "HwtbQBNnLERakdUDuCCLWmUs2oETLFQZeHUWeQdPads",
          "entity": {
            "zh": "[链：Solana] [黑客地址] [Solana被盗资产接收] [跨链桥入口]",
            "tw": "[鏈：Solana] [黑客地址] [Solana被盜資產接收] [跨鏈橋入口]",
            "en": "bridge address documented by a public source"
          },
          "role": "bridge",
          "category": "bridge",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/lookonchain/status/2075870871500308860",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Solana] [黑客地址] [Solana被盗资产接收] [跨链桥入口]",
            "tw": "[鏈：Solana] [黑客地址] [Solana被盜資產接收] [跨鏈橋入口]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0xD66E7F945672381193525f0a3F34aa0789b13cD3",
          "entity": {
            "zh": "[链：Ethereum] [跨链桥出口] [Ethereum接收]",
            "tw": "[鏈：Ethereum] [跨鏈橋出口] [Ethereum接收]",
            "en": "bridge address documented by a public source"
          },
          "role": "bridge",
          "category": "bridge",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/lookonchain/status/2075870871500308860",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [跨链桥出口] [Ethereum接收]",
            "tw": "[鏈：Ethereum] [跨鏈橋出口] [Ethereum接收]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0x124bc160Ef2D2eB3851683D78412e0E5c35002B1",
          "entity": {
            "zh": "[链：Ethereum] [Ethereum资金归集]",
            "tw": "[鏈：Ethereum] [Ethereum資金歸集]",
            "en": "other address documented by a public source"
          },
          "role": "other",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/lookonchain/status/2075870871500308860",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [Ethereum资金归集]",
            "tw": "[鏈：Ethereum] [Ethereum資金歸集]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "Lookonchain原帖",
            "tw": "Lookonchain原帖",
            "en": "x.com source"
          },
          "url": "https://x.com/lookonchain/status/2075870871500308860",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-019",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-018",
      "status": "verified",
      "incidentDate": "2026-07-11",
      "datePrecision": "day",
      "title": {
        "zh": "Bonzo Lend",
        "tw": "Bonzo Lend",
        "en": "Bonzo Lend oracle manipulation"
      },
      "summary": {
        "zh": "约数百万美元进入Ethereum并混币；Hedera核心网络未被攻破，问题位于Bonzo及其预言机验证路径。",
        "tw": "約數百萬美元進入Ethereum並混幣；Hedera核心網絡未被攻破，問題位於Bonzo及其預言機驗證路徑。",
        "en": "A pricing and liquidation weakness caused approximately $9.05 million in reported losses."
      },
      "details": {
        "zh": "## 事件背景\nBonzo Lend 部署在 Hedera，价格依赖第三方 Supra 预言机。BLS 验证路径存在致命实现错误：错误接受 [0,0] 零签名与零公钥 作为「有效」聚合签名。于是攻击者可以：\n\n1. 构造伪造的 SAUCE / wHBAR 价格报告；\n2. 让 Oracle Adapter 写入极端价格；\n3. 在借贷协议中把几乎无价值的抵押品显示成巨额抵押，从而借出真实的 USDC、WHBAR 等资产。\n\n这是 预言机验证逻辑漏洞，不是 Hedera L1 共识被攻破。官方与安全公司均强调问题位于 Bonzo 及其预言机适配/验证路径。\n\n## 事件经过\n1. 攻击者在 Hedera 上准备账户（含 0.0.10633526 — [链：Hedera] [详见地址与交易] 等）并触发伪造价格写入。\n2. 以少量 SAUCE 等资产通过扭曲后的价格「包装」成巨额抵押。\n3. 借出约 905 万美元 量级的 USDC / WHBAR 等。\n4. 经 SaucerSwap 换币，降低持仓集中度。\n5. 经 LayerZero 把资金跨到 Ethereum（公开可追踪跨出约 500 万+ 美元量级；PeckShield 等亦报过约 525 万美元跨链观察口径）。\n6. 在 Ethereum 换成 ETH / WBTC；部分进入 Tornado Cash。\n7. 另有第二提款账户等角色被社区讨论（含自称白帽/退还待核地址），须单独标签，不与主黑客混为一谈。\n8. Bonzo 暂停协议并发布事件报告。\n\n## 资金流向\n5. 经 LayerZero 把资金跨到 Ethereum（公开可追踪跨出约 500 万+ 美元量级；PeckShield 等亦报过约 525 万美元跨链观察口径）。\n6. 在 Ethereum 换成 ETH / WBTC；部分进入 Tornado Cash。\n\n## 金额口径\n约905万美元\n\n## 证据边界\n以公开可核验来源为界；未证实细节不写入确定结论。\n\n## 处置状态\n约数百万美元进入Ethereum并混币；Hedera核心网络未被攻破，问题位于Bonzo及其预言机验证路径。",
        "tw": "## 事件背景\nBonzo Lend 部署在 Hedera，價格依賴第三方 Supra 預言機。BLS 驗證路徑存在致命實現錯誤：錯誤接受 [0,0] 零簽名與零公鑰 作為「有效」聚合簽名。於是攻擊者可以：\n\n1. 構造偽造的 SAUCE / wHBAR 價格報告；\n2. 讓 Oracle Adapter 寫入極端價格；\n3. 在借貸協議中把幾乎無價值的抵押品顯示成鉅額抵押，從而借出真實的 USDC、WHBAR 等資產。\n\n這是 預言機驗證邏輯漏洞，不是 Hedera L1 共識被攻破。官方與安全公司均強調問題位於 Bonzo 及其預言機適配/驗證路徑。\n\n## 事件經過\n1. 攻擊者在 Hedera 上準備賬戶（含 0.0.10633526 — [鏈：Hedera] [詳見地址與交易] 等）並觸發偽造價格寫入。\n2. 以少量 SAUCE 等資產通過扭曲後的價格「包裝」成鉅額抵押。\n3. 借出約 905 萬美元 量級的 USDC / WHBAR 等。\n4. 經 SaucerSwap 換幣，降低持倉集中度。\n5. 經 LayerZero 把資金跨到 Ethereum（公開可追蹤跨出約 500 萬+ 美元量級；PeckShield 等亦報過約 525 萬美元跨鏈觀察口徑）。\n6. 在 Ethereum 換成 ETH / WBTC；部分進入 Tornado Cash。\n7. 另有第二提款賬戶等角色被社區討論（含自稱白帽/退還待核地址），須單獨標籤，不與主黑客混為一談。\n8. Bonzo 暫停協議併發布事件報告。\n\n## 資金流向\n5. 經 LayerZero 把資金跨到 Ethereum（公開可追蹤跨出約 500 萬+ 美元量級；PeckShield 等亦報過約 525 萬美元跨鏈觀察口徑）。\n6. 在 Ethereum 換成 ETH / WBTC；部分進入 Tornado Cash。\n\n## 金額口徑\n約905萬美元\n\n## 證據邊界\n以公開可核驗來源為界；未證實細節不寫入確定結論。\n\n## 處置狀態\n約數百萬美元進入Ethereum並混幣；Hedera核心網絡未被攻破，問題位於Bonzo及其預言機驗證路徑。",
        "en": "## Incident overview\nA pricing and liquidation weakness caused approximately $9.05 million in reported losses.\n\n## Amount basis\nReported loss: $9,050,000\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "oracle-manipulation",
      "severity": "critical",
      "ecosystems": [
        "Ethereum",
        "Hedera"
      ],
      "chains": [
        "Ethereum",
        "Hedera"
      ],
      "lossUsd": 9050000,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "约905万美元",
        "tw": "約905萬美元",
        "en": "Reported loss: $9,050,000"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "Hedera",
          "address": "0x9a4966152f6e10b33cb7a37975e8619816d6a494",
          "entity": {
            "zh": "[链：Hedera（EVM别名）] [黑客地址] [Hedera EVM映射] [跨链桥入口]",
            "tw": "[鏈：Hedera（EVM別名）] [黑客地址] [Hedera EVM映射] [跨鏈橋入口]",
            "en": "bridge address documented by a public source"
          },
          "role": "bridge",
          "category": "bridge",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/PeckShieldAlert/status/2075867053408629179",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Hedera（EVM别名）] [黑客地址] [Hedera EVM映射] [跨链桥入口]",
            "tw": "[鏈：Hedera（EVM別名）] [黑客地址] [Hedera EVM映射] [跨鏈橋入口]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0xaf20D792A19fD42dCf697ceBa6100291D96dD93e",
          "entity": {
            "zh": "[链：Ethereum] [跨链桥出口] [Ethereum被盗资产接收]",
            "tw": "[鏈：Ethereum] [跨鏈橋出口] [Ethereum被盜資產接收]",
            "en": "bridge address documented by a public source"
          },
          "role": "bridge",
          "category": "bridge",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/PeckShieldAlert/status/2075867053408629179",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [跨链桥出口] [Ethereum被盗资产接收]",
            "tw": "[鏈：Ethereum] [跨鏈橋出口] [Ethereum被盜資產接收]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "PeckShield资金路径",
            "tw": "PeckShield資金路徑",
            "en": "x.com source"
          },
          "url": "https://x.com/PeckShieldAlert/status/2075867053408629179",
          "type": "research"
        },
        {
          "label": {
            "zh": "GoPlus技术分析",
            "tw": "GoPlus技術分析",
            "en": "x.com source"
          },
          "url": "https://x.com/GoPlusSecurity/status/2076248543954911572",
          "type": "research"
        },
        {
          "label": {
            "zh": "Bonzo官方报告",
            "tw": "Bonzo官方報告",
            "en": "bonzo.finance source"
          },
          "url": "https://bonzo.finance/blog/bonzo-lend-incident-report-oracle-provider-exploit",
          "type": "official"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-018",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-017",
      "status": "verified",
      "incidentDate": "2026-07-09",
      "datePrecision": "day",
      "title": {
        "zh": "CodexField疑似Rug",
        "tw": "CodexField疑似Rug",
        "en": "CodexField suspected rug-pull risk"
      },
      "summary": {
        "zh": "列入高风险观察，不进入确定黑客地址账本。",
        "tw": "列入高風險觀察，不進入確定黑客地址賬本。",
        "en": "CodexField showed indicators consistent with a suspected rug pull; attribution and total losses remain unconfirmed."
      },
      "details": {
        "zh": "## 事件背景\n「网站 + 社交账号集体消失」是疑似 Rug 的强信号，但在链上仍需区分：项目金库正常多签转移、被黑、还是团队卷款。安全研究员提到的「历史累计收入 >8500 万美元」是 业务流水口径，绝不能直接写成「被盗 8500 万」。\n\n## 事件经过\n1. 约 7 月 9 日起出现异常；7 月 10 日 CertiK 等预警。\n2. CodexField 网站与 X 账号不可用，链上资金动作引发社区 Rug 质疑。\n3. Specter 等后续跟踪，但仍无足够证据证明「全部历史收入被单一黑客地址卷走」。\n4. 未取得可可靠归因的完整 Rug 归集地址 → 不入确定黑客账本，保持高风险观察。\n\n## 资金流向\n4. 未取得可可靠归因的完整 Rug 归集地址 → 不入确定黑客账本，保持高风险观察。\n\n## 金额口径\n安全研究者称项目历史累计收入超过8500万美元；不等于8500万美元已被盗\n\n## 证据边界\n完整地址/Tx 不足时不猜补。 部分角色/根因仍待核。\n\n## 处置状态\n列入高风险观察，不进入确定黑客地址账本。",
        "tw": "## 事件背景\n「網站 + 社交賬號集體消失」是疑似 Rug 的強信號，但在鏈上仍需區分：項目金庫正常多籤轉移、被黑、還是團隊捲款。安全研究員提到的「歷史累計收入 >8500 萬美元」是 業務流水口徑，絕不能直接寫成「被盜 8500 萬」。\n\n## 事件經過\n1. 約 7 月 9 日起出現異常；7 月 10 日 CertiK 等預警。\n2. CodexField 網站與 X 賬號不可用，鏈上資金動作引發社區 Rug 質疑。\n3. Specter 等後續跟蹤，但仍無足夠證據證明「全部歷史收入被單一黑客地址捲走」。\n4. 未取得可可靠歸因的完整 Rug 歸集地址 → 不入確定黑客賬本，保持高風險觀察。\n\n## 資金流向\n4. 未取得可可靠歸因的完整 Rug 歸集地址 → 不入確定黑客賬本，保持高風險觀察。\n\n## 金額口徑\n安全研究者稱項目歷史累計收入超過8500萬美元；不等於8500萬美元已被盜\n\n## 證據邊界\n完整地址/Tx 不足時不猜補。 部分角色/根因仍待核。\n\n## 處置狀態\n列入高風險觀察，不進入確定黑客地址賬本。",
        "en": "## Incident overview\nCodexField showed indicators consistent with a suspected rug pull; attribution and total losses remain unconfirmed.\n\n## Amount basis\nNo single verified USD loss figure was published; see the incident record.\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "rug-risk",
      "severity": "high",
      "ecosystems": [
        "BNB Chain"
      ],
      "chains": [
        "BNB Chain"
      ],
      "lossUsd": null,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "安全研究者称项目历史累计收入超过8500万美元；不等于8500万美元已被盗",
        "tw": "安全研究者稱項目歷史累計收入超過8500萬美元；不等於8500萬美元已被盜",
        "en": "No single verified USD loss figure was published; see the incident record."
      },
      "addressDisclosure": "not-published",
      "addresses": [],
      "references": [
        {
          "label": {
            "zh": "CertiK预警",
            "tw": "CertiK預警",
            "en": "x.com source"
          },
          "url": "https://x.com/CertiKAlert/status/2075486250220556716",
          "type": "research"
        },
        {
          "label": {
            "zh": "Specter后续",
            "tw": "Specter後續",
            "en": "x.com source"
          },
          "url": "https://x.com/SpecterAnalyst/status/2075503795103035721",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-017",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-016",
      "status": "verified",
      "incidentDate": "2026-07-08",
      "datePrecision": "day",
      "title": {
        "zh": "TAC代币暴跌（已排除为链上安全攻击）",
        "tw": "TAC代幣暴跌（已排除為鏈上安全攻擊）",
        "en": "TAC token market crash, no on-chain exploit confirmed"
      },
      "summary": {
        "zh": "已排除为已确认链上攻击；保留在观察附录用于解释最初告警和后续澄清。",
        "tw": "已排除為已確認鏈上攻擊；保留在觀察附錄用於解釋最初告警和後續澄清。",
        "en": "TAC fell sharply across spot and derivatives markets, but available evidence did not establish a blockchain security attack."
      },
      "details": {
        "zh": "## 事件背景\nPeckShield最初只监测到TAC价格瞬间暴跌，并未披露漏洞、攻击Tx或黑客地址。随后TAC团队澄清：链上资产安全，团队及早期支持者未出售仍锁定的代币；下跌由永续合约中的大额卖单触发，在薄流动性市场形成连环强平并传导至现货。\n\n## 事件经过\n1. 7月8日09:29前后，TAC价格约下跌85%，后续统计最大跌幅约91%。\n2. 早期媒体把PeckShield价格告警表述成“security alert”，但没有对应漏洞或攻击交易。\n3. TAC团队随后否认漏洞和内部抛售，解释为永续合约大单触发清算瀑布。\n4. 因此本项从“安全攻击”降级为“市场异常观察”，不计入确定链上被盗事件数。\n\n## 资金流向\n见事件经过；无独立可拆资金路径时以地址与交易章节为准。\n\n## 金额口径\n价格一度暴跌约85%—91%；无可核验链上被盗金额\n\n## 证据边界\n以公开可核验来源为界；未证实细节不写入确定结论。\n\n## 处置状态\n已排除为已确认链上攻击；保留在观察附录用于解释最初告警和后续澄清。",
        "tw": "## 事件背景\nPeckShield最初只監測到TAC價格瞬間暴跌，並未披露漏洞、攻擊Tx或黑客地址。隨後TAC團隊澄清：鏈上資產安全，團隊及早期支持者未出售仍鎖定的代幣；下跌由永續合約中的大額賣單觸發，在薄流動性市場形成連環強平並傳導至現貨。\n\n## 事件經過\n1. 7月8日09:29前後，TAC價格約下跌85%，後續統計最大跌幅約91%。\n2. 早期媒體把PeckShield價格告警表述成“security alert”，但沒有對應漏洞或攻擊交易。\n3. TAC團隊隨後否認漏洞和內部拋售，解釋為永續合約大單觸發清算瀑布。\n4. 因此本項從“安全攻擊”降級為“市場異常觀察”，不計入確定鏈上被盜事件數。\n\n## 資金流向\n見事件經過；無獨立可拆資金路徑時以地址與交易章節為準。\n\n## 金額口徑\n價格一度暴跌約85%—91%；無可核驗鏈上被盜金額\n\n## 證據邊界\n以公開可核驗來源為界；未證實細節不寫入確定結論。\n\n## 處置狀態\n已排除為已確認鏈上攻擊；保留在觀察附錄用於解釋最初告警和後續澄清。",
        "en": "## Incident overview\nTAC fell sharply across spot and derivatives markets, but available evidence did not establish a blockchain security attack.\n\n## Amount basis\nNo single verified USD loss figure was published; see the incident record.\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "market-anomaly",
      "severity": "medium",
      "ecosystems": [
        "BNB Chain",
        "Ethereum"
      ],
      "chains": [
        "BNB Chain",
        "Ethereum"
      ],
      "lossUsd": null,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "价格一度暴跌约85%—91%；无可核验链上被盗金额",
        "tw": "價格一度暴跌約85%—91%；無可核驗鏈上被盜金額",
        "en": "No single verified USD loss figure was published; see the incident record."
      },
      "addressDisclosure": "not-published",
      "addresses": [],
      "references": [
        {
          "label": {
            "zh": "PeckShield初始监控",
            "tw": "PeckShield初始監控",
            "en": "x.com source"
          },
          "url": "https://x.com/PeckShieldAlert/status/2074667111377723418",
          "type": "research"
        },
        {
          "label": {
            "zh": "Phemex初报",
            "tw": "Phemex初報",
            "en": "phemex.com source"
          },
          "url": "https://phemex.com/news/article/tac-token-plummets-85-amid-security-alert-92166",
          "type": "research"
        },
        {
          "label": {
            "zh": "TAC团队澄清转述：永续清算而非漏洞",
            "tw": "TAC團隊澄清轉述：永續清算而非漏洞",
            "en": "phemex.com source"
          },
          "url": "https://phemex.com/news/article/tac-token-price-drop-attributed-to-perpetual-contract-liquidation-92357",
          "type": "research"
        },
        {
          "label": {
            "zh": "TAC Protocol官方",
            "tw": "TAC Protocol官方",
            "en": "tac.build source"
          },
          "url": "https://tac.build/",
          "type": "official"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-016",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-023",
      "status": "verified",
      "incidentDate": "2026-07-06",
      "datePrecision": "day",
      "title": {
        "zh": "BarnBridge SMART Yield",
        "tw": "BarnBridge SMART Yield",
        "en": "BarnBridge SMART Yield governance attack"
      },
      "summary": {
        "zh": "约77.66万USDC从历史授权用户处被转走；事件显示废弃协议和长期Approve仍有持续风险。用户应定期 revoke 已停运协议授权。",
        "tw": "約77.66萬USDC從歷史授權用戶處被轉走；事件顯示廢棄協議和長期Approve仍有持續風險。用戶應定期 revoke 已停運協議授權。",
        "en": "A malicious governance path was used to extract approximately 776,600 USDC."
      },
      "details": {
        "zh": "## 事件背景\nBarnBridge 早在 SEC 和解后基本停运，但 SMART Yield 旧治理与代理升级权限仍在链上存活，且大量用户多年前的 USDC 无限/大额 Approve 从未撤销。攻击路径是「治理接管 + 旧授权收割」：\n\n1. 低活跃 DAO 中，少量 BOND 即可取得足够投票权（公开分析称购票成本可低至约数百美元量级，亦有「存入约 32 万 BOND」口径）；\n2. 恶意提案把 SmartYield/controller proxy 实现升级成攻击者合约；\n3. 新实现调用 CompoundProvider 的特权函数（如 _takeUnderlying / transferFees 一类）；\n4. 合约凭用户历史 allowance 直接 transferFrom 用户钱包 USDC——用户无需再签名。\n\nBlockaid 曾预警旧提案 #14/#15 的授权风险（USDC/DAI/USDT/GUSD/RAI）。注意：受害合约名含 CompoundProvider，不等于 Compound 协议本体被黑。\n\n## 事件经过\n1. 准备（约 7 月 5–6 日）：攻击相关地址从 Tornado Cash 等注资；购入/锁定 BOND 获取投票权（公开口径约 32 万 BOND）。\n2. 提案：提交恶意治理提案，目标为升级 controller 代理实现。\n3. 等待：度过治理期/时间参数后，于 7 月 15 日 执行。\n4. 升级：proxy 指向恶意实现 0x66c6…7580。\n5. 收割：恶意逻辑调用 CompoundProvider 特权路径，对约 50–51 个 仍保留 USDC 授权的用户执行 transferFrom。\n6. 归集：约 776,600 USDC 进入 0xF908…97A1。\n7. 换币：USDC 兑成约 415 ETH，再转到下游地址（分析扩展见 0x2c4c…ef16 等，角色见补丁）。\n8. 注资链（AML 分析·待核）：0xdaa0…8310 等与 Tornado 注资相关，不作身份定罪。\n\n## 资金流向\n1. 准备（约 7 月 5–6 日）：攻击相关地址从 Tornado Cash 等注资；购入/锁定 BOND 获取投票权（公开口径约 32 万 BOND）。\n6. 归集：约 776,600 USDC 进入 0xF908610E9174c7cd6e9dfD371e238be4511297A1 — [链：Ethereum] [详见地址与交易]。\n7. 换币：USDC 兑成约 415 ETH，再转到下游地址（分析扩展见 0x2c4c1848e22006d63ebb732b61edc871af30ef16 — [链：Ethereum] [详见地址与交易] 等，角色见补丁）。\n8. 注资链（AML 分析·待核）：0xdaa037f99d168b552c0c61b7fb64cf7819d78310 — [链：Ethereum] [详见地址与交易] 等与 Tornado 注资相关，不作身份定罪。\n\n## 金额口径\n约776,600 USDC\n\n## 证据边界\n以公开可核验来源为界；未证实细节不写入确定结论。\n\n## 处置状态\n约77.66万USDC从历史授权用户处被转走；事件显示废弃协议和长期Approve仍有持续风险。用户应定期 revoke 已停运协议授权。",
        "tw": "## 事件背景\nBarnBridge 早在 SEC 和解後基本停運，但 SMART Yield 舊治理與代理升級權限仍在鏈上存活，且大量用戶多年前的 USDC 無限/大額 Approve 從未撤銷。攻擊路徑是「治理接管 + 舊授權收割」：\n\n1. 低活躍 DAO 中，少量 BOND 即可取得足夠投票權（公開分析稱購票成本可低至約數百美元量級，亦有「存入約 32 萬 BOND」口徑）；\n2. 惡意提案把 SmartYield/controller proxy 實現升級成攻擊者合約；\n3. 新實現調用 CompoundProvider 的特權函數（如 _takeUnderlying / transferFees 一類）；\n4. 合約憑用戶歷史 allowance 直接 transferFrom 用戶錢包 USDC——用戶無需再簽名。\n\nBlockaid 曾預警舊提案 #14/#15 的授權風險（USDC/DAI/USDT/GUSD/RAI）。注意：受害合約名含 CompoundProvider，不等於 Compound 協議本體被黑。\n\n## 事件經過\n1. 準備（約 7 月 5–6 日）：攻擊相關地址從 Tornado Cash 等注資；購入/鎖定 BOND 獲取投票權（公開口徑約 32 萬 BOND）。\n2. 提案：提交惡意治理提案，目標為升級 controller 代理實現。\n3. 等待：度過治理期/時間參數後，於 7 月 15 日 執行。\n4. 升級：proxy 指向惡意實現 0x66c6…7580。\n5. 收割：惡意邏輯調用 CompoundProvider 特權路徑，對約 50–51 個 仍保留 USDC 授權的用戶執行 transferFrom。\n6. 歸集：約 776,600 USDC 進入 0xF908…97A1。\n7. 換幣：USDC 兌成約 415 ETH，再轉到下游地址（分析擴展見 0x2c4c…ef16 等，角色見補丁）。\n8. 注資鏈（AML 分析·待核）：0xdaa0…8310 等與 Tornado 注資相關，不作身份定罪。\n\n## 資金流向\n1. 準備（約 7 月 5–6 日）：攻擊相關地址從 Tornado Cash 等注資；購入/鎖定 BOND 獲取投票權（公開口徑約 32 萬 BOND）。\n6. 歸集：約 776,600 USDC 進入 0xF908610E9174c7cd6e9dfD371e238be4511297A1 — [鏈：Ethereum] [詳見地址與交易]。\n7. 換幣：USDC 兌成約 415 ETH，再轉到下游地址（分析擴展見 0x2c4c1848e22006d63ebb732b61edc871af30ef16 — [鏈：Ethereum] [詳見地址與交易] 等，角色見補丁）。\n8. 注資鏈（AML 分析·待核）：0xdaa037f99d168b552c0c61b7fb64cf7819d78310 — [鏈：Ethereum] [詳見地址與交易] 等與 Tornado 注資相關，不作身份定罪。\n\n## 金額口徑\n約776,600 USDC\n\n## 證據邊界\n以公開可核驗來源為界；未證實細節不寫入確定結論。\n\n## 處置狀態\n約77.66萬USDC從歷史授權用戶處被轉走；事件顯示廢棄協議和長期Approve仍有持續風險。用戶應定期 revoke 已停運協議授權。",
        "en": "## Incident overview\nA malicious governance path was used to extract approximately 776,600 USDC.\n\n## Amount basis\nReported loss: $776,600\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "governance-attack",
      "severity": "high",
      "ecosystems": [
        "Ethereum"
      ],
      "chains": [
        "Ethereum"
      ],
      "lossUsd": 776600,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "约776,600 USDC",
        "tw": "約776,600 USDC",
        "en": "Reported loss: $776,600"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "Ethereum",
          "address": "0xF908610E9174c7cd6e9dfD371e238be4511297A1",
          "entity": {
            "zh": "[链：Ethereum] [黑客地址] [最终资金归集]",
            "tw": "[鏈：Ethereum] [黑客地址] [最終資金歸集]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/Phalcon_xyz/status/2077243530280587721",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [黑客地址] [最终资金归集]",
            "tw": "[鏈：Ethereum] [黑客地址] [最終資金歸集]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0x66c6f3b4B4b458e6d764759Ecf122484ebEf7580",
          "entity": {
            "zh": "[链：Ethereum] [黑客合约] [恶意控制器]",
            "tw": "[鏈：Ethereum] [黑客合約] [惡意控制器]",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/Phalcon_xyz/status/2077243530280587721",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [黑客合约] [恶意控制器]",
            "tw": "[鏈：Ethereum] [黑客合約] [惡意控制器]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0x4cAE362D7F227e3d306f70ce4878E245563F3069",
          "entity": {
            "zh": "[链：Ethereum] [受害地址] [被接管治理合约]",
            "tw": "[鏈：Ethereum] [受害地址] [被接管治理合約]",
            "en": "victim address documented by a public source"
          },
          "role": "victim",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/Phalcon_xyz/status/2077243530280587721",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [受害地址] [被接管治理合约]",
            "tw": "[鏈：Ethereum] [受害地址] [被接管治理合約]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0xdaa037f99d168b552c0c61b7fb64cf7819d78310",
          "entity": {
            "zh": "[链：Ethereum] [攻击者EOA] [Tornado注资相关] [分析扩展]",
            "tw": "[鏈：Ethereum] [攻擊者EOA] [Tornado注資相關] [分析擴展]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/Phalcon_xyz/status/2077243530280587721",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [攻击者EOA] [Tornado注资相关] [分析扩展]",
            "tw": "[鏈：Ethereum] [攻擊者EOA] [Tornado注資相關] [分析擴展]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0x2c4c1848e22006d63ebb732b61edc871af30ef16",
          "entity": {
            "zh": "[链：Ethereum] [ETH下游持仓] [分析扩展]",
            "tw": "[鏈：Ethereum] [ETH下游持倉] [分析擴展]",
            "en": "other address documented by a public source"
          },
          "role": "other",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/Phalcon_xyz/status/2077243530280587721",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [ETH下游持仓] [分析扩展]",
            "tw": "[鏈：Ethereum] [ETH下游持倉] [分析擴展]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "BlockSec Phalcon",
            "tw": "BlockSec Phalcon",
            "en": "x.com source"
          },
          "url": "https://x.com/Phalcon_xyz/status/2077243530280587721",
          "type": "research"
        },
        {
          "label": {
            "zh": "GoPlus地址与过程",
            "tw": "GoPlus地址與過程",
            "en": "x.com source"
          },
          "url": "https://x.com/GoPlusSecurity/status/2077368561937564043",
          "type": "research"
        },
        {
          "label": {
            "zh": "AML Crypto复盘",
            "tw": "AML Crypto復盤",
            "en": "amlcrypto.io source"
          },
          "url": "https://amlcrypto.io/blog/barn-bridge-exploit",
          "type": "research"
        },
        {
          "label": {
            "zh": "Compound社区澄清非Compound本体",
            "tw": "Compound社區澄清非Compound本體",
            "en": "comp.xyz source"
          },
          "url": "https://www.comp.xyz/t/clarification-barnbridge-compoundprovider-incident-compound-protocol-is-not-affected/7961",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-023",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-015",
      "status": "verified",
      "incidentDate": "2026-07-06",
      "datePrecision": "day",
      "title": {
        "zh": "BONK DAO恶意治理",
        "tw": "BONK DAO惡意治理",
        "en": "BONK DAO malicious governance proposal"
      },
      "summary": {
        "zh": "部分BONK进入交易所路径，大部分曾停留在攻击者控制地址；项目与交易所、Solana基金会及执法部门合作追踪。",
        "tw": "部分BONK進入交易所路徑，大部分曾停留在攻擊者控制地址；項目與交易所、Solana基金會及執法部門合作追蹤。",
        "en": "A malicious governance action created an exposure estimated at about $20 million and triggered emergency community response."
      },
      "details": {
        "zh": "## 事件背景\n这不是智能合约 reentrancy 或私钥被盗，而是 恶意治理（governance attack）：\n\n1. BonkDAO 金库规模远大于「凑齐法定投票门槛」的成本；\n2. 公开分析指攻击者约花费 400 万—440 万美元 在二级市场/交易所买入 BONK，达到约 1% 投票门槛（亦有口径写 Bybit、Binance 等渠道吸筹约 8822.85 亿枚量级）；\n3. 社区投票率极低、又缺乏有效 时间锁（timelock）/多签否决/守护模块 时，攻击者可以 独自 通过恶意提案（公开讨论涉及 BIP-76 等）；\n4. 提案一旦执行，国库 BONK 被「合法」转出到攻击者控制的接收结构（报道称 BONK 2.0 等相关钱包），链上看起来像治理执行而非 hack opcode。\n\n## 事件经过\n1. 吸筹：7 月初攻击者在 CEX/链上买入足量 BONK 凑齐治理门槛。\n2. 提案：提交并将恶意提案推进至可执行（7 月 6 日执行，7 月 7 日集中披露）。\n3. 转出国库：约 4.426 万亿 BONK（攻击时约 2,000 万—2,130 万美元）从国库转到提案指定收款地址。\n4. 归集：资金从初始收款地址归集到主黑客钱包，再拆到二级地址。\n5. 出金尝试：部分 BONK 转向新钱包并试探 OKX / Binance / Coinbase 等充值路径；后续监测见分批转入币安等（德尔泰跟踪稿有 3861 亿、4000 亿等批次叙述）。\n6. 响应：项目方协同交易所、Solana Foundation、执法与分析公司冻结/追踪；社区就「算不算 hack」发生治理哲学争议，但不影响资金已离库的事实。\n\n## 资金流向\n1. 吸筹：7 月初攻击者在 CEX/链上买入足量 BONK 凑齐治理门槛。\n3. 转出国库：约 4.426 万亿 BONK（攻击时约 2,000 万—2,130 万美元）从国库转到提案指定收款地址。\n4. 归集：资金从初始收款地址归集到主黑客钱包，再拆到二级地址。\n5. 出金尝试：部分 BONK 转向新钱包并试探 OKX / Binance / Coinbase 等充值路径；后续监测见分批转入币安等（德尔泰跟踪稿有 3861 亿、4000 亿等批次叙述）。\n\n## 金额口径\n约4.426万亿BONK，攻击时约2000万—2130万美元\n\n## 证据边界\n以公开可核验来源为界；未证实细节不写入确定结论。\n\n## 处置状态\n部分BONK进入交易所路径，大部分曾停留在攻击者控制地址；项目与交易所、Solana基金会及执法部门合作追踪。",
        "tw": "## 事件背景\n這不是智能合約 reentrancy 或私鑰被盜，而是 惡意治理（governance attack）：\n\n1. BonkDAO 金庫規模遠大於「湊齊法定投票門檻」的成本；\n2. 公開分析指攻擊者約花費 400 萬—440 萬美元 在二級市場/交易所買入 BONK，達到約 1% 投票門檻（亦有口徑寫 Bybit、Binance 等渠道吸籌約 8822.85 億枚量級）；\n3. 社區投票率極低、又缺乏有效 時間鎖（timelock）/多籤否決/守護模塊 時，攻擊者可以 獨自 通過惡意提案（公開討論涉及 BIP-76 等）；\n4. 提案一旦執行，國庫 BONK 被「合法」轉出到攻擊者控制的接收結構（報道稱 BONK 2.0 等相關錢包），鏈上看起來像治理執行而非 hack opcode。\n\n## 事件經過\n1. 吸籌：7 月初攻擊者在 CEX/鏈上買入足量 BONK 湊齊治理門檻。\n2. 提案：提交併將惡意提案推進至可執行（7 月 6 日執行，7 月 7 日集中披露）。\n3. 轉出國庫：約 4.426 萬億 BONK（攻擊時約 2,000 萬—2,130 萬美元）從國庫轉到提案指定收款地址。\n4. 歸集：資金從初始收款地址歸集到主黑客錢包，再拆到二級地址。\n5. 出金嘗試：部分 BONK 轉向新錢包並試探 OKX / Binance / Coinbase 等充值路徑；後續監測見分批轉入幣安等（德爾泰跟蹤稿有 3861 億、4000 億等批次敘述）。\n6. 響應：項目方協同交易所、Solana Foundation、執法與分析公司凍結/追蹤；社區就「算不算 hack」發生治理哲學爭議，但不影響資金已離庫的事實。\n\n## 資金流向\n1. 吸籌：7 月初攻擊者在 CEX/鏈上買入足量 BONK 湊齊治理門檻。\n3. 轉出國庫：約 4.426 萬億 BONK（攻擊時約 2,000 萬—2,130 萬美元）從國庫轉到提案指定收款地址。\n4. 歸集：資金從初始收款地址歸集到主黑客錢包，再拆到二級地址。\n5. 出金嘗試：部分 BONK 轉向新錢包並試探 OKX / Binance / Coinbase 等充值路徑；後續監測見分批轉入幣安等（德爾泰跟蹤稿有 3861 億、4000 億等批次敘述）。\n\n## 金額口徑\n約4.426萬億BONK，攻擊時約2000萬—2130萬美元\n\n## 證據邊界\n以公開可核驗來源為界；未證實細節不寫入確定結論。\n\n## 處置狀態\n部分BONK進入交易所路徑，大部分曾停留在攻擊者控制地址；項目與交易所、Solana基金會及執法部門合作追蹤。",
        "en": "## Incident overview\nA malicious governance action created an exposure estimated at about $20 million and triggered emergency community response.\n\n## Amount basis\nReported loss: $20,000,000\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "governance-attack",
      "severity": "critical",
      "ecosystems": [
        "Solana"
      ],
      "chains": [
        "Solana"
      ],
      "lossUsd": 20000000,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "约4.426万亿BONK，攻击时约2000万—2130万美元",
        "tw": "約4.426萬億BONK，攻擊時約2000萬—2130萬美元",
        "en": "Reported loss: $20,000,000"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "Solana",
          "address": "9bxWkNf3BtJ6iehq9KbX9uCWMjem4TFiPZ19T2sYJHvQ",
          "entity": {
            "zh": "[链：Solana] [恶意提案初始收款] [被盗资产接收]",
            "tw": "[鏈：Solana] [惡意提案初始收款] [被盜資產接收]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/CertiKAlert/status/2074295582131449903",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Solana] [恶意提案初始收款] [被盗资产接收]",
            "tw": "[鏈：Solana] [惡意提案初始收款] [被盜資產接收]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Solana",
          "address": "EXaJnmrLf7RAKLfn1hehoKX94keKYmvZm5H5zuYVeh42",
          "entity": {
            "zh": "[链：Solana] [黑客地址] [主资金归集]",
            "tw": "[鏈：Solana] [黑客地址] [主資金歸集]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/CertiKAlert/status/2074295582131449903",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Solana] [黑客地址] [主资金归集]",
            "tw": "[鏈：Solana] [黑客地址] [主資金歸集]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Solana",
          "address": "FhYPjrH12uLaLXFttCHgEKKFvBPoN6rztMPs2E8LWUNJ",
          "entity": {
            "zh": "[链：Solana] [二级归集] [交易所充值前置]",
            "tw": "[鏈：Solana] [二級歸集] [交易所充值前置]",
            "en": "exchange address documented by a public source"
          },
          "role": "exchange",
          "category": "exchange",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/CertiKAlert/status/2074295582131449903",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Solana] [二级归集] [交易所充值前置]",
            "tw": "[鏈：Solana] [二級歸集] [交易所充值前置]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "CertiK初始接收地址",
            "tw": "CertiK初始接收地址",
            "en": "x.com source"
          },
          "url": "https://x.com/CertiKAlert/status/2074295582131449903",
          "type": "research"
        },
        {
          "label": {
            "zh": "CertiK主归集地址",
            "tw": "CertiK主歸集地址",
            "en": "x.com source"
          },
          "url": "https://x.com/CertiKAlert/status/2074297091724390820",
          "type": "research"
        },
        {
          "label": {
            "zh": "Chainalysis治理关系",
            "tw": "Chainalysis治理關係",
            "en": "x.com source"
          },
          "url": "https://x.com/chainalysis/status/2074315262485299686",
          "type": "research"
        },
        {
          "label": {
            "zh": "新钱包及Binance流向",
            "tw": "新錢包及Binance流向",
            "en": "x.com source"
          },
          "url": "https://x.com/cryptos6_bk10x/status/2077829543143031285",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-015",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-007",
      "status": "verified",
      "incidentDate": "2026-07-06",
      "datePrecision": "day",
      "title": {
        "zh": "Summer.fi / Lazy Summer",
        "tw": "Summer.fi / Lazy Summer",
        "en": "Summer.fi shared-accounting price manipulation"
      },
      "summary": {
        "zh": "截至7月8日至少600 ETH进入Tornado Cash；项目暂停并修复受影响路径。",
        "tw": "截至7月8日至少600 ETH進入Tornado Cash；項目暫停並修復受影響路徑。",
        "en": "An attacker manipulated shared vault accounting and price calculations, causing approximately $6.04 million in reported losses."
      },
      "details": {
        "zh": "## 事件背景\nLazy Summer / Summer.fi 的 FleetCommander 与多个金库在会计上共享或依赖可被外部扭曲的 totalAssets() / NAV 计算。攻击者预先在低流动性场所积累 vgUSDC 等份额，再结合：\n\n1. 大额闪电贷 瞬间改变池子与金库资产结构；\n2. 捐赠或低流动性份额抬价，使金库 NAV/份额赎回价短期虚增（公开分析约抬高 ~9.5% 量级）；\n3. 在同一原子交易内 高价赎回，把虚增 NAV 兑换成其他存款人的真实资产。\n\n与 Edel 类似，根因仍是 份额会计信任了可被单笔交易操纵的余额，缺少对异常 NAV 跳动的硬熔断。\n\n## 事件经过\n1. 预持仓：攻击者此前积累低流动性 vgUSDC 等份额，为抬价做准备。\n2. 闪电贷：借入约 6,540 万美元 量级闪电贷。\n3. 存入扭曲：存入约 6,480 万美元，并通过对金库/底层会计的操纵抬高 NAV。\n4. 虚高赎回：按被抬高的份额价格赎回约 7,090 万美元。\n5. 价差变现：存入与赎回差额约 600 万—604 万美元（多为 DAI 口径）即攻击利润，对应其他 LP 的损失。\n6. 离场：利润换成 DAI/ETH，并分批进入 Tornado Cash（监测至 7 月 8 日至少约 600 ETH 已混）。\n7. 项目：暂停相关金库、存款上限清零，修复受影响路径。\n\n## 资金流向\n6. 离场：利润换成 DAI/ETH，并分批进入 Tornado Cash（监测至 7 月 8 日至少约 600 ETH 已混）。\n\n## 金额口径\n约604万美元DAI\n\n## 证据边界\n以公开可核验来源为界；未证实细节不写入确定结论。\n\n## 处置状态\n截至7月8日至少600 ETH进入Tornado Cash；项目暂停并修复受影响路径。",
        "tw": "## 事件背景\nLazy Summer / Summer.fi 的 FleetCommander 與多個金庫在會計上共享或依賴可被外部扭曲的 totalAssets() / NAV 計算。攻擊者預先在低流動性場所積累 vgUSDC 等份額，再結合：\n\n1. 大額閃電貸 瞬間改變池子與金庫資產結構；\n2. 捐贈或低流動性份額抬價，使金庫 NAV/份額贖回價短期虛增（公開分析約抬高 ~9.5% 量級）；\n3. 在同一原子交易內 高價贖回，把虛增 NAV 兌換成其他存款人的真實資產。\n\n與 Edel 類似，根因仍是 份額會計信任了可被單筆交易操縱的餘額，缺少對異常 NAV 跳動的硬熔斷。\n\n## 事件經過\n1. 預持倉：攻擊者此前積累低流動性 vgUSDC 等份額，為抬價做準備。\n2. 閃電貸：借入約 6,540 萬美元 量級閃電貸。\n3. 存入扭曲：存入約 6,480 萬美元，並通過對金庫/底層會計的操縱抬高 NAV。\n4. 虛高贖回：按被抬高的份額價格贖回約 7,090 萬美元。\n5. 價差變現：存入與贖回差額約 600 萬—604 萬美元（多為 DAI 口徑）即攻擊利潤，對應其他 LP 的損失。\n6. 離場：利潤換成 DAI/ETH，並分批進入 Tornado Cash（監測至 7 月 8 日至少約 600 ETH 已混）。\n7. 項目：暫停相關金庫、存款上限清零，修復受影響路徑。\n\n## 資金流向\n6. 離場：利潤換成 DAI/ETH，並分批進入 Tornado Cash（監測至 7 月 8 日至少約 600 ETH 已混）。\n\n## 金額口徑\n約604萬美元DAI\n\n## 證據邊界\n以公開可核驗來源為界；未證實細節不寫入確定結論。\n\n## 處置狀態\n截至7月8日至少600 ETH進入Tornado Cash；項目暫停並修復受影響路徑。",
        "en": "## Incident overview\nAn attacker manipulated shared vault accounting and price calculations, causing approximately $6.04 million in reported losses.\n\n## Amount basis\nReported loss: $6,040,000\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "protocol-exploit",
      "severity": "critical",
      "ecosystems": [
        "Ethereum",
        "Base"
      ],
      "chains": [
        "Ethereum",
        "Base"
      ],
      "lossUsd": 6040000,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "约604万美元DAI",
        "tw": "約604萬美元DAI",
        "en": "Reported loss: $6,040,000"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "Ethereum",
          "address": "0x7BF716167B48CF527725722C6d79494b45B3BDCa",
          "entity": {
            "zh": "[链：Ethereum] [黑客地址] [攻击者EOA] [被盗资产接收] [混币前置]",
            "tw": "[鏈：Ethereum] [黑客地址] [攻擊者EOA] [被盜資產接收] [混幣前置]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "mixer",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/CertiKAlert/status/2074005902362132625",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [黑客地址] [攻击者EOA] [被盗资产接收] [混币前置]",
            "tw": "[鏈：Ethereum] [黑客地址] [攻擊者EOA] [被盜資產接收] [混幣前置]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "CertiK攻击Tx",
            "tw": "CertiK攻擊Tx",
            "en": "x.com source"
          },
          "url": "https://x.com/CertiKAlert/status/2074005902362132625",
          "type": "research"
        },
        {
          "label": {
            "zh": "Cyvers资金来源与根因",
            "tw": "Cyvers資金來源與根因",
            "en": "x.com source"
          },
          "url": "https://x.com/CyversAlerts/status/2074024662619562049",
          "type": "research"
        },
        {
          "label": {
            "zh": "PeckShield后续",
            "tw": "PeckShield後續",
            "en": "x.com source"
          },
          "url": "https://x.com/PeckShieldAlert/status/2074743013369356433",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-007",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-046",
      "status": "verified",
      "incidentDate": "2026-07-04",
      "datePrecision": "day",
      "title": {
        "zh": "Gate用户约170万美元账户接管争议",
        "tw": "Gate用戶約170萬美元賬戶接管爭議",
        "en": "Gate user account-takeover dispute involving $1.7 million"
      },
      "summary": {
        "zh": "用户资产已链上拆分；平台从强硬否认转向道歉+协助追款；责任未司法终局。写作须保持「双方冲突 + 链上自洽 + 后台不可见」的证据边界。",
        "tw": "用戶資產已鏈上拆分；平臺從強硬否認轉向道歉+協助追款；責任未司法終局。寫作須保持「雙方衝突 + 鏈上自洽 + 後臺不可見」的證據邊界。",
        "en": "A Gate user reported an account takeover and approximately $1.7 million in disputed losses; responsibility remains contested."
      },
      "details": {
        "zh": "## 事件背景\n这不是 Gate 热钱包被外部黑客「打穿合约」的系统性链上漏洞，而是 账户接管（Account Takeover）+ 风控/客服审核争议：\n\n1. 攻击者在约 4 天内逐步重置手机、邮箱、Google 验证器、资金密码，并添加免验证提币地址；\n2. Gate 称各步均通过短信/邮箱验证码、活体人脸、2019 年历史 C2C/支付宝类材料；\n3. 当事人逐项否认（无 iPhone 14、未做人脸、未提交手持证件视频等）；\n4. 平台已执行「安全项修改等待期 + 提现保护期」，但攻击者选择 等冷静期走完 再一次性大额提币——说明缺的是「连续重置 + 新设备 + 新地址 + 大额」的 叠加风控，而不是完全没有冷静期；\n5. 最强解释假说（非司法结论）是 身份材料泄露 + 通讯入口失守 + 深伪/摄像头注入闯活体 的组合；责任归属以前台不可见的后台日志与司法结论为准。\n\n## 事件经过\n1. 07-04：新设备发起重置手机/邮箱；Gate 称活体人脸通过（当事人否认）。\n2. 07-05：解绑手机；要求提交 2019 年指定历史交易/支付宝录屏；客服执行解绑（材料来源双方冲突，争议最大节点）。\n3. 07-06：改登录密码 → 重设 Google 验证器 → 重置资金密码，当事人被逐步挤出账户控制权。\n4. 07-07：旧 Mac/passkey 登录后完成多笔提币；新地址被设为免验证；约 5 笔资产离开 Gate 热钱包。\n5. 链上第一跳：资金进入 HUB 0x3466…4133（约 49.96 ETH、746,475 HSK、156.6 万 USDT）。\n6. 第二跳：拆到下游 1 0xd435…45e7 与下游 2 0xb1EB…774e；HSK 分批 swap 成 USDT，再进入 0x789... 系列拆分。\n7. 07-08 起：当事人 @jheioff 公开；Gate 初定性「个别案例」；后转向道歉并成立专项组，称对接 Tether 等追冻。\n8. 市场：事件发酵后 Gate 约 7 日净流出约 2.07 亿美元（DeFiLlama 口径）。\n9. 第三方分析：盗款下游有触及 Newpay/新币系通道 的讨论——标为 [OTC/担保通道关联待核]，非终局认定。\n10. 截至 07-20：公开层面未见大额追回/赔付实锤；后台活体原件/设备指纹/真实 IP/客服记录仍未对外完整公开。\n\n## 资金流向\n见事件经过；无独立可拆资金路径时以地址与交易章节为准。\n\n## 金额口径\n约 49.96 ETH + 746,475 HSK + 约 1,565,982 USDT（合计约 170 万美元量级）\n\n## 证据边界\n部分角色/根因仍待核。\n\n## 处置状态\n用户资产已链上拆分；平台从强硬否认转向道歉+协助追款；责任未司法终局。写作须保持「双方冲突 + 链上自洽 + 后台不可见」的证据边界。",
        "tw": "## 事件背景\n這不是 Gate 熱錢包被外部黑客「打穿合約」的系統性鏈上漏洞，而是 賬戶接管（Account Takeover）+ 風控/客服審核爭議：\n\n1. 攻擊者在約 4 天內逐步重置手機、郵箱、Google 驗證器、資金密碼，並添加免驗證提幣地址；\n2. Gate 稱各步均通過短信/郵箱驗證碼、活體人臉、2019 年曆史 C2C/支付寶類材料；\n3. 當事人逐項否認（無 iPhone 14、未做人臉、未提交手持證件視頻等）；\n4. 平臺已執行「安全項修改等待期 + 提現保護期」，但攻擊者選擇 等冷靜期走完 再一次性大額提幣——說明缺的是「連續重置 + 新設備 + 新地址 + 大額」的 疊加風控，而不是完全沒有冷靜期；\n5. 最強解釋假說（非司法結論）是 身份材料洩露 + 通訊入口失守 + 深偽/攝像頭注入闖活體 的組合；責任歸屬以前臺不可見的後臺日誌與司法結論為準。\n\n## 事件經過\n1. 07-04：新設備發起重置手機/郵箱；Gate 稱活體人臉通過（當事人否認）。\n2. 07-05：解綁手機；要求提交 2019 年指定歷史交易/支付寶錄屏；客服執行解綁（材料來源雙方衝突，爭議最大節點）。\n3. 07-06：改登錄密碼 → 重設 Google 驗證器 → 重置資金密碼，當事人被逐步擠出賬戶控制權。\n4. 07-07：舊 Mac/passkey 登錄後完成多筆提幣；新地址被設為免驗證；約 5 筆資產離開 Gate 熱錢包。\n5. 鏈上第一跳：資金進入 HUB 0x3466…4133（約 49.96 ETH、746,475 HSK、156.6 萬 USDT）。\n6. 第二跳：拆到下游 1 0xd435…45e7 與下游 2 0xb1EB…774e；HSK 分批 swap 成 USDT，再進入 0x789... 系列拆分。\n7. 07-08 起：當事人 @jheioff 公開；Gate 初定性「個別案例」；後轉向道歉併成立專項組，稱對接 Tether 等追凍。\n8. 市場：事件發酵後 Gate 約 7 日淨流出約 2.07 億美元（DeFiLlama 口徑）。\n9. 第三方分析：盜款下游有觸及 Newpay/新幣系通道 的討論——標為 [OTC/擔保通道關聯待核]，非終局認定。\n10. 截至 07-20：公開層面未見大額追回/賠付實錘；後臺活體原件/設備指紋/真實 IP/客服記錄仍未對外完整公開。\n\n## 資金流向\n見事件經過；無獨立可拆資金路徑時以地址與交易章節為準。\n\n## 金額口徑\n約 49.96 ETH + 746,475 HSK + 約 1,565,982 USDT（合計約 170 萬美元量級）\n\n## 證據邊界\n部分角色/根因仍待核。\n\n## 處置狀態\n用戶資產已鏈上拆分；平臺從強硬否認轉向道歉+協助追款；責任未司法終局。寫作須保持「雙方衝突 + 鏈上自洽 + 後臺不可見」的證據邊界。",
        "en": "## Incident overview\nA Gate user reported an account takeover and approximately $1.7 million in disputed losses; responsibility remains contested.\n\n## Amount basis\nReported loss: $1,700,000\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "account-takeover",
      "severity": "high",
      "ecosystems": [
        "Ethereum"
      ],
      "chains": [
        "Ethereum"
      ],
      "lossUsd": 1700000,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "约 49.96 ETH + 746,475 HSK + 约 1,565,982 USDT（合计约 170 万美元量级）",
        "tw": "約 49.96 ETH + 746,475 HSK + 約 1,565,982 USDT（合計約 170 萬美元量級）",
        "en": "Reported loss: $1,700,000"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "Ethereum",
          "address": "0x34660cD71651977D221Ea6fDA506f5D096064133",
          "entity": {
            "zh": "[链：Ethereum] [被盗资产接收] [资金归集HUB]",
            "tw": "[鏈：Ethereum] [被盜資產接收] [資金歸集HUB]",
            "en": "other address documented by a public source"
          },
          "role": "other",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://etherscan.io/address/0x34660cD71651977D221Ea6fDA506f5D096064133",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [被盗资产接收] [资金归集HUB]",
            "tw": "[鏈：Ethereum] [被盜資產接收] [資金歸集HUB]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0xd4355D99ef1b6F98d3A9AfE8BcA6D0C0852e45e7",
          "entity": {
            "zh": "[链：Ethereum] [下游1] [资金分散]",
            "tw": "[鏈：Ethereum] [下游1] [資金分散]",
            "en": "other address documented by a public source"
          },
          "role": "other",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://etherscan.io/address/0x34660cD71651977D221Ea6fDA506f5D096064133",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [下游1] [资金分散]",
            "tw": "[鏈：Ethereum] [下游1] [資金分散]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0xb1EB41492DFC1BD7024286D160efe69a2a6f774e",
          "entity": {
            "zh": "[链：Ethereum] [下游2] [HSK兑换路径]",
            "tw": "[鏈：Ethereum] [下游2] [HSK兌換路徑]",
            "en": "other address documented by a public source"
          },
          "role": "other",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://etherscan.io/address/0x34660cD71651977D221Ea6fDA506f5D096064133",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [下游2] [HSK兑换路径]",
            "tw": "[鏈：Ethereum] [下游2] [HSK兌換路徑]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "Etherscan HUB",
            "tw": "Etherscan HUB",
            "en": "etherscan.io source"
          },
          "url": "https://etherscan.io/address/0x34660cD71651977D221Ea6fDA506f5D096064133",
          "type": "research"
        },
        {
          "label": {
            "zh": "CryptoBriefing流出",
            "tw": "CryptoBriefing流出",
            "en": "cryptobriefing.com source"
          },
          "url": "https://cryptobriefing.com/gate-207m-outflows-user-theft-incident/",
          "type": "research"
        },
        {
          "label": {
            "zh": "Blockcast进展",
            "tw": "Blockcast進展",
            "en": "blockcast.it source"
          },
          "url": "https://blockcast.it/2026/07/14/gate-faces-1-7m-user-hack-incident-as-ceo-vows-to-recover-funds/",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-046",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-014",
      "status": "verified",
      "incidentDate": "2026-07-04",
      "datePrecision": "day",
      "title": {
        "zh": "Step Finance旧案资金异动",
        "tw": "Step Finance舊案資金異動",
        "en": "Step Finance old-case fund movement"
      },
      "summary": {
        "zh": "旧案赃款由Solana迁移至Ethereum并混币。",
        "tw": "舊案贓款由Solana遷移至Ethereum並混幣。",
        "en": "Assets linked to the previous Step Finance compromise moved again; the record tracks post-incident flow rather than a new attack."
      },
      "details": {
        "zh": "## 事件背景\nStep Finance 被盗资金曾长期（约 5 个月）停在 Solana 侧攻击者地址休眠。休眠不代表放弃，而是等待流动性、风控注意力下降或跨链桥/混币路径更顺。一旦苏醒，典型路径是：SOL 现货卖出 → 跨链到 Ethereum → 换成 ETH → Tornado Cash，把「公链标签清晰的 SOL 巨鲸」变成「混币后的 ETH」。\n\n## 事件经过\n1. 7 月 4–5 日，Lookonchain 等监测到攻击者结束约 5 个月休眠。\n2. 卖出约 261,933 SOL（当时约 2,140 万美元）。\n3. 经跨链桥进入 Ethereum，兑换得到约 12,128 ETH。\n4. ETH 再转入 Tornado Cash 完成混币前置。\n5. Solana 归集地址与 Ethereum 出口地址均有完整公开值（见下）。\n\n## 资金流向\n3. 经跨链桥进入 Ethereum，兑换得到约 12,128 ETH。\n4. ETH 再转入 Tornado Cash 完成混币前置。\n5. Solana 归集地址与 Ethereum 出口地址均有完整公开值（见下）。\n\n## 金额口径\n未统一/见正文\n\n## 证据边界\n本条为旧案资金异动，非本期新攻击首发。\n\n## 处置状态\n旧案赃款由Solana迁移至Ethereum并混币。",
        "tw": "## 事件背景\nStep Finance 被盜資金曾長期（約 5 個月）停在 Solana 側攻擊者地址休眠。休眠不代表放棄，而是等待流動性、風控注意力下降或跨鏈橋/混幣路徑更順。一旦甦醒，典型路徑是：SOL 現貨賣出 → 跨鏈到 Ethereum → 換成 ETH → Tornado Cash，把「公鏈標籤清晰的 SOL 巨鯨」變成「混幣後的 ETH」。\n\n## 事件經過\n1. 7 月 4–5 日，Lookonchain 等監測到攻擊者結束約 5 個月休眠。\n2. 賣出約 261,933 SOL（當時約 2,140 萬美元）。\n3. 經跨鏈橋進入 Ethereum，兌換得到約 12,128 ETH。\n4. ETH 再轉入 Tornado Cash 完成混幣前置。\n5. Solana 歸集地址與 Ethereum 出口地址均有完整公開值（見下）。\n\n## 資金流向\n3. 經跨鏈橋進入 Ethereum，兌換得到約 12,128 ETH。\n4. ETH 再轉入 Tornado Cash 完成混幣前置。\n5. Solana 歸集地址與 Ethereum 出口地址均有完整公開值（見下）。\n\n## 金額口徑\n未統一/見正文\n\n## 證據邊界\n本條為舊案資金異動，非本期新攻擊首發。\n\n## 處置狀態\n舊案贓款由Solana遷移至Ethereum並混幣。",
        "en": "## Incident overview\nAssets linked to the previous Step Finance compromise moved again; the record tracks post-incident flow rather than a new attack.\n\n## Amount basis\nNo single verified USD loss figure was published; see the incident record.\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "fund-movement",
      "severity": "medium",
      "ecosystems": [
        "Ethereum",
        "Solana"
      ],
      "chains": [
        "Ethereum",
        "Solana"
      ],
      "lossUsd": null,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "未统一/见正文",
        "tw": "未統一/見正文",
        "en": "No single verified USD loss figure was published; see the incident record."
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "Solana",
          "address": "7raxiejD8hDUH1wyYWFDPrEuHiLUjJ4RiZi2z1u2udNh",
          "entity": {
            "zh": "[链：Solana] [黑客地址] [Solana资金归集] [跨链桥入口]",
            "tw": "[鏈：Solana] [黑客地址] [Solana資金歸集] [跨鏈橋入口]",
            "en": "bridge address documented by a public source"
          },
          "role": "bridge",
          "category": "bridge",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/lookonchain/status/2073680397054185711",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Solana] [黑客地址] [Solana资金归集] [跨链桥入口]",
            "tw": "[鏈：Solana] [黑客地址] [Solana資金歸集] [跨鏈橋入口]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0xDf3786773645fd737ff5764C06536e8908f5d1b7",
          "entity": {
            "zh": "[链：Ethereum] [跨链桥出口] [Ethereum资金归集] [混币前置]",
            "tw": "[鏈：Ethereum] [跨鏈橋出口] [Ethereum資金歸集] [混幣前置]",
            "en": "bridge address documented by a public source"
          },
          "role": "bridge",
          "category": "mixer",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/lookonchain/status/2073680397054185711",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [跨链桥出口] [Ethereum资金归集] [混币前置]",
            "tw": "[鏈：Ethereum] [跨鏈橋出口] [Ethereum資金歸集] [混幣前置]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "Lookonchain资金流",
            "tw": "Lookonchain資金流",
            "en": "x.com source"
          },
          "url": "https://x.com/lookonchain/status/2073680397054185711",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-014",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-013",
      "status": "verified",
      "incidentDate": "2026-07-04",
      "datePrecision": "day",
      "title": {
        "zh": "UXLINK攻击者继续洗钱",
        "tw": "UXLINK攻擊者繼續洗錢",
        "en": "UXLINK exploiter laundering activity"
      },
      "summary": {
        "zh": "绝大部分剩余赃款完成ETH化和混币。",
        "tw": "絕大部分剩餘贓款完成ETH化和混幣。",
        "en": "Addresses linked to the earlier UXLINK incident continued moving and laundering stolen assets during the reporting window."
      },
      "details": {
        "zh": "## 事件背景\nUXLINK 异常铸币/攻击发生在本窗口之前。本期是攻击者对 剩余稳定币库存 做「DAI→ETH→Tornado」的标准洗钱收尾：把仍停留在明面上的 ERC-20 换成 ETH，再分批混币，降低交易所直接冻结 DAI 的成功率。\n\n## 事件经过\n1. 7 月 4 日 18:19（北京时间）前后，PeckShield 监测到 UXLINK 旧案攻击者动用剩余约 1,054 万 DAI。\n2. DAI 被兑换为约 6,000.8 ETH。\n3. 随即向 Tornado Cash 存入约 6,038 ETH（含 gas/零头归集差异）。\n4. 统计口径：过去约两周累计混入约 14,336.6 ETH；另有极小额约 2.64 ETH 曾跨到 Bitcoin。\n5. 公开帖截断地址 → 不猜补完整黑客地址。\n\n## 资金流向\n2. DAI 被兑换为约 6,000.8 ETH。\n3. 随即向 Tornado Cash 存入约 6,038 ETH（含 gas/零头归集差异）。\n\n## 金额口径\n未统一/见正文\n\n## 证据边界\n完整地址/Tx 不足时不猜补。 本条为旧案资金异动，非本期新攻击首发。\n\n## 处置状态\n绝大部分剩余赃款完成ETH化和混币。",
        "tw": "## 事件背景\nUXLINK 異常鑄幣/攻擊發生在本窗口之前。本期是攻擊者對 剩餘穩定幣庫存 做「DAI→ETH→Tornado」的標準洗錢收尾：把仍停留在明面上的 ERC-20 換成 ETH，再分批混幣，降低交易所直接凍結 DAI 的成功率。\n\n## 事件經過\n1. 7 月 4 日 18:19（北京時間）前後，PeckShield 監測到 UXLINK 舊案攻擊者動用剩餘約 1,054 萬 DAI。\n2. DAI 被兌換為約 6,000.8 ETH。\n3. 隨即向 Tornado Cash 存入約 6,038 ETH（含 gas/零頭歸集差異）。\n4. 統計口徑：過去約兩週累計混入約 14,336.6 ETH；另有極小額約 2.64 ETH 曾跨到 Bitcoin。\n5. 公開帖截斷地址 → 不猜補完整黑客地址。\n\n## 資金流向\n2. DAI 被兌換為約 6,000.8 ETH。\n3. 隨即向 Tornado Cash 存入約 6,038 ETH（含 gas/零頭歸集差異）。\n\n## 金額口徑\n未統一/見正文\n\n## 證據邊界\n完整地址/Tx 不足時不猜補。 本條為舊案資金異動，非本期新攻擊首發。\n\n## 處置狀態\n絕大部分剩餘贓款完成ETH化和混幣。",
        "en": "## Incident overview\nAddresses linked to the earlier UXLINK incident continued moving and laundering stolen assets during the reporting window.\n\n## Amount basis\nNo single verified USD loss figure was published; see the incident record.\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "fund-movement",
      "severity": "medium",
      "ecosystems": [
        "Ethereum",
        "Bitcoin"
      ],
      "chains": [
        "Ethereum",
        "Bitcoin"
      ],
      "lossUsd": null,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "未统一/见正文",
        "tw": "未統一/見正文",
        "en": "No single verified USD loss figure was published; see the incident record."
      },
      "addressDisclosure": "not-published",
      "addresses": [],
      "references": [
        {
          "label": {
            "zh": "PeckShield原帖",
            "tw": "PeckShield原帖",
            "en": "x.com source"
          },
          "url": "https://x.com/PeckShieldAlert/status/2073351014418448570",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-013",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-012",
      "status": "verified",
      "incidentDate": "2026-07-03",
      "datePrecision": "day",
      "title": {
        "zh": "Hinkal Protocol",
        "tw": "Hinkal Protocol",
        "en": "Hinkal Protocol exploit"
      },
      "summary": {
        "zh": "受影响合约被项目方冻结；大部分赃款已混币或跨到Bitcoin。",
        "tw": "受影響合約被項目方凍結；大部分贓款已混幣或跨到Bitcoin。",
        "en": "A protocol weakness was exploited for approximately $820,000, according to the cited on-chain security disclosures."
      },
      "details": {
        "zh": "## 事件背景\nHinkal 是主打稳定币隐私/保密交易的 DeFi 协议。核心缺陷在 证明与签名没有把「承诺 commitment、nullifier、交易 call data」绑定成不可拆分的整体：\n\n- 正常隐私池要求：同一笔记（note）只能花费一次，nullifier 防双花，且提取参数必须被证明覆盖；\n- 实现上，攻击者可反复构造新的 nullifier、stealth 地址、H0/H1 以及 calldataHash，使验证器误以为每次都是合法新花费；\n- 入口还暴露了 prooflessDeposit()（无证明存款）一类路径，降低了攻击前置成本，使「先塞入再反复 transact 抽出」成为可脚本化循环。\n\n因此这不是用户被钓鱼签名，而是 协议合约执行路径/校验逻辑被利用，可在不持有真实存款证明的情况下抽走池内 USDC。\n\n## 事件经过\n1. 切入：攻击者调用 prooflessDeposit() 在有缺陷的路径上建立可操作状态。\n2. 循环提取：多次调用 transact()，公开监测显示单次约提取 2.5 万美元 量级，重复直至池内可抽资金耗尽。\n3. 规模：合计抽走约 80 万—82 万美元 USDC。\n4. 换币：USDC 在 Ethereum 上换成 ETH。\n5. 清洗分叉：\n- 约 410 ETH 进入 Tornado Cash；\n- 约 44.67 ETH 经 THORChain 换成 BTC，跨出 EVM 视线。\n6. 项目响应：受影响合约被冻结；团队称事件限于特定 Ethereum 池，并表态用户补偿口径（以官方最终公告为准）。\n\n## 资金流向\n- 约 410 ETH 进入 Tornado Cash；\n\n## 金额口径\n约80万—82万美元USDC\n\n## 证据边界\n完整地址/Tx 不足时不猜补。\n\n## 处置状态\n受影响合约被项目方冻结；大部分赃款已混币或跨到Bitcoin。",
        "tw": "## 事件背景\nHinkal 是主打穩定幣隱私/保密交易的 DeFi 協議。核心缺陷在 證明與簽名沒有把「承諾 commitment、nullifier、交易 call data」綁定成不可拆分的整體：\n\n- 正常隱私池要求：同一筆記（note）只能花費一次，nullifier 防雙花，且提取參數必須被證明覆蓋；\n- 實現上，攻擊者可反覆構造新的 nullifier、stealth 地址、H0/H1 以及 calldataHash，使驗證器誤以為每次都是合法新花費；\n- 入口還暴露了 prooflessDeposit()（無證明存款）一類路徑，降低了攻擊前置成本，使「先塞入再反覆 transact 抽出」成為可腳本化循環。\n\n因此這不是用戶被釣魚簽名，而是 協議合約執行路徑/校驗邏輯被利用，可在不持有真實存款證明的情況下抽走池內 USDC。\n\n## 事件經過\n1. 切入：攻擊者調用 prooflessDeposit() 在有缺陷的路徑上建立可操作狀態。\n2. 循環提取：多次調用 transact()，公開監測顯示單次約提取 2.5 萬美元 量級，重複直至池內可抽資金耗盡。\n3. 規模：合計抽走約 80 萬—82 萬美元 USDC。\n4. 換幣：USDC 在 Ethereum 上換成 ETH。\n5. 清洗分叉：\n- 約 410 ETH 進入 Tornado Cash；\n- 約 44.67 ETH 經 THORChain 換成 BTC，跨出 EVM 視線。\n6. 項目響應：受影響合約被凍結；團隊稱事件限於特定 Ethereum 池，並表態用戶補償口徑（以官方最終公告為準）。\n\n## 資金流向\n- 約 410 ETH 進入 Tornado Cash；\n\n## 金額口徑\n約80萬—82萬美元USDC\n\n## 證據邊界\n完整地址/Tx 不足時不猜補。\n\n## 處置狀態\n受影響合約被項目方凍結；大部分贓款已混幣或跨到Bitcoin。",
        "en": "## Incident overview\nA protocol weakness was exploited for approximately $820,000, according to the cited on-chain security disclosures.\n\n## Amount basis\nReported loss: $820,000\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "protocol-exploit",
      "severity": "high",
      "ecosystems": [
        "Ethereum",
        "Bitcoin"
      ],
      "chains": [
        "Ethereum",
        "Bitcoin"
      ],
      "lossUsd": 820000,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "约80万—82万美元USDC",
        "tw": "約80萬—82萬美元USDC",
        "en": "Reported loss: $820,000"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "Ethereum",
          "address": "0xbB3f01a1b1C68F3DEB36C55342b5F5706c32fc20",
          "entity": {
            "zh": "[链：Ethereum] [黑客地址] [攻击者EOA] [被盗资产接收] [资金归集]",
            "tw": "[鏈：Ethereum] [黑客地址] [攻擊者EOA] [被盜資產接收] [資金歸集]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/CertiKAlert/status/2072856656099324255",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [黑客地址] [攻击者EOA] [被盗资产接收] [资金归集]",
            "tw": "[鏈：Ethereum] [黑客地址] [攻擊者EOA] [被盜資產接收] [資金歸集]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0x25e5e82f5702A27C3466fE68f14abDbbAdFca826",
          "entity": {
            "zh": "[链：Ethereum] [受害地址] [受影响合约]",
            "tw": "[鏈：Ethereum] [受害地址] [受影響合約]",
            "en": "victim address documented by a public source"
          },
          "role": "victim",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/CertiKAlert/status/2072856656099324255",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [受害地址] [受影响合约]",
            "tw": "[鏈：Ethereum] [受害地址] [受影響合約]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "CertiK地址",
            "tw": "CertiK地址",
            "en": "x.com source"
          },
          "url": "https://x.com/CertiKAlert/status/2072856656099324255",
          "type": "research"
        },
        {
          "label": {
            "zh": "PeckShield资金路径",
            "tw": "PeckShield資金路徑",
            "en": "x.com source"
          },
          "url": "https://x.com/PeckShieldAlert/status/2072859957167640946",
          "type": "research"
        },
        {
          "label": {
            "zh": "GoPlus分析",
            "tw": "GoPlus分析",
            "en": "x.com source"
          },
          "url": "https://x.com/GoPlusSecurity/status/2072904217178820833",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-012",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-045",
      "status": "verified",
      "incidentDate": "2026-07-02",
      "datePrecision": "day",
      "title": {
        "zh": "Alkanes / DIESEL索引器攻击",
        "tw": "Alkanes / DIESEL索引器攻擊",
        "en": "Alkanes / DIESEL indexer attack"
      },
      "summary": {
        "zh": "Subfrost称用户资金未损失，攻击尝试被架构拦截；索引器状态一致性问题随后被修复或缓解。",
        "tw": "Subfrost稱用戶資金未損失，攻擊嘗試被架構攔截；索引器狀態一致性問題隨後被修復或緩解。",
        "en": "An indexer-level attack disrupted data integrity, but the cited sources did not identify a direct asset loss."
      },
      "details": {
        "zh": "## 事件背景\nAlkanes 元协议索引器同时维护两套状态：\n\n1. 原子持久化存储（应在失败时完整回滚）；\n2. 内存余额映射（热路径缓存）。\n\n当高 ID 代币触发 u128 溢出时：持久化层正确回滚，但内存映射 没有撤销 错误写入 → 索引器以为存在巨量 DIESEL，而 Bitcoin L1 上并无对应真实资产。这是 索引器状态机不一致，不是 BTC 共识被攻破。若桥/结算层盲目信任索引器余额，就会把幻影代币兑成真实 BTC。\n\n## 事件经过\n1. 约 7 月 2 日攻击者构造极端数值触发溢出与状态分裂。\n2. 通过约 24 次 级联翻倍，把幻影 DIESEL 放大到约 1 亿枚。\n3. 尝试将幻影余额换成 frBTC / 抽取桥储备。\n4. Subfrost 桥接与结算架构拒绝释放无抵押 BTC，约 82.3 BTC 风险敞口被拦截。\n5. 7 月 3–4 日官方/社区复盘；宣称 用户损失为 0。\n6. 随后修复索引器一致性；相关 bc1p 地址中桥储备地址 不是黑客。\n\n## 资金流向\n3. 尝试将幻影余额换成 frBTC / 抽取桥储备。\n4. Subfrost 桥接与结算架构拒绝释放无抵押 BTC，约 82.3 BTC 风险敞口被拦截。\n6. 随后修复索引器一致性；相关 bc1p 地址中桥储备地址 不是黑客。\n\n## 金额口径\n未统一/见正文\n\n## 证据边界\n以公开可核验来源为界；未证实细节不写入确定结论。\n\n## 处置状态\nSubfrost称用户资金未损失，攻击尝试被架构拦截；索引器状态一致性问题随后被修复或缓解。",
        "tw": "## 事件背景\nAlkanes 元協議索引器同時維護兩套狀態：\n\n1. 原子持久化存儲（應在失敗時完整回滾）；\n2. 內存餘額映射（熱路徑緩存）。\n\n當高 ID 代幣觸發 u128 溢出時：持久化層正確回滾，但內存映射 沒有撤銷 錯誤寫入 → 索引器以為存在巨量 DIESEL，而 Bitcoin L1 上並無對應真實資產。這是 索引器狀態機不一致，不是 BTC 共識被攻破。若橋/結算層盲目信任索引器餘額，就會把幻影代幣兌成真實 BTC。\n\n## 事件經過\n1. 約 7 月 2 日攻擊者構造極端數值觸發溢出與狀態分裂。\n2. 通過約 24 次 級聯翻倍，把幻影 DIESEL 放大到約 1 億枚。\n3. 嘗試將幻影餘額換成 frBTC / 抽取橋儲備。\n4. Subfrost 橋接與結算架構拒絕釋放無抵押 BTC，約 82.3 BTC 風險敞口被攔截。\n5. 7 月 3–4 日官方/社區復盤；宣稱 用戶損失為 0。\n6. 隨後修復索引器一致性；相關 bc1p 地址中橋儲備地址 不是黑客。\n\n## 資金流向\n3. 嘗試將幻影餘額換成 frBTC / 抽取橋儲備。\n4. Subfrost 橋接與結算架構拒絕釋放無抵押 BTC，約 82.3 BTC 風險敞口被攔截。\n6. 隨後修復索引器一致性；相關 bc1p 地址中橋儲備地址 不是黑客。\n\n## 金額口徑\n未統一/見正文\n\n## 證據邊界\n以公開可核驗來源為界；未證實細節不寫入確定結論。\n\n## 處置狀態\nSubfrost稱用戶資金未損失，攻擊嘗試被架構攔截；索引器狀態一致性問題隨後被修復或緩解。",
        "en": "## Incident overview\nAn indexer-level attack disrupted data integrity, but the cited sources did not identify a direct asset loss.\n\n## Amount basis\nReported loss: $0\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "protocol-exploit",
      "severity": "medium",
      "ecosystems": [
        "Bitcoin"
      ],
      "chains": [
        "Bitcoin"
      ],
      "lossUsd": 0,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "未统一/见正文",
        "tw": "未統一/見正文",
        "en": "Reported loss: $0"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "Bitcoin",
          "address": "bc1ppjkfcx89pa8w2v6fv57rflvhxcp74usk9xy7eh8avlq0an8hards05tu8t",
          "entity": {
            "zh": "[链：Bitcoin L1 / Alkanes] [攻击关联地址] [幻影DIESEL持仓] [具体角色待核]",
            "tw": "[鏈：Bitcoin L1 / Alkanes] [攻擊關聯地址] [幻影DIESEL持倉] [具體角色待核]",
            "en": "other address documented by a public source"
          },
          "role": "other",
          "category": "unknown",
          "confidence": 0.65,
          "sourceUrl": "https://x.com/YL20020628/status/2072633859716571530",
          "evidenceStatus": "community_reported",
          "evidenceSummary": {
            "zh": "[链：Bitcoin L1 / Alkanes] [攻击关联地址] [幻影DIESEL持仓] [具体角色待核]",
            "tw": "[鏈：Bitcoin L1 / Alkanes] [攻擊關聯地址] [幻影DIESEL持倉] [具體角色待核]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Bitcoin",
          "address": "bc1psjzvcv0n86u00wtekvp02eh53n8tytsw8dc8wpvrhf3hqtxjahvqlx23e6",
          "entity": {
            "zh": "[链：Bitcoin L1 / Alkanes] [攻击关联地址] [异常兑换路径] [具体角色待核]",
            "tw": "[鏈：Bitcoin L1 / Alkanes] [攻擊關聯地址] [異常兌換路徑] [具體角色待核]",
            "en": "other address documented by a public source"
          },
          "role": "other",
          "category": "unknown",
          "confidence": 0.65,
          "sourceUrl": "https://x.com/YL20020628/status/2072633859716571530",
          "evidenceStatus": "community_reported",
          "evidenceSummary": {
            "zh": "[链：Bitcoin L1 / Alkanes] [攻击关联地址] [异常兑换路径] [具体角色待核]",
            "tw": "[鏈：Bitcoin L1 / Alkanes] [攻擊關聯地址] [異常兌換路徑] [具體角色待核]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Bitcoin",
          "address": "bc1p5lushqjk7kxpqa87ppwn0dealucyqa6t40ppdkhpqm3grcpqvw9s3wdsx7",
          "entity": {
            "zh": "[链：Bitcoin L1 / Alkanes] [受影响桥储备地址] [frBTC桥余额]，不是黑客地址。",
            "tw": "[鏈：Bitcoin L1 / Alkanes] [受影響橋儲備地址] [frBTC橋餘額]，不是黑客地址。",
            "en": "bridge address documented by a public source"
          },
          "role": "bridge",
          "category": "bridge",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/YL20020628/status/2072633859716571530",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Bitcoin L1 / Alkanes] [受影响桥储备地址] [frBTC桥余额]，不是黑客地址。",
            "tw": "[鏈：Bitcoin L1 / Alkanes] [受影響橋儲備地址] [frBTC橋餘額]，不是黑客地址。",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "问题地址披露",
            "tw": "問題地址披露",
            "en": "x.com source"
          },
          "url": "https://x.com/YL20020628/status/2072633859716571530",
          "type": "research"
        },
        {
          "label": {
            "zh": "Subfrost事后分析",
            "tw": "Subfrost事後分析",
            "en": "x.com source"
          },
          "url": "https://x.com/gabe_subfrost/status/2073217660880388224",
          "type": "research"
        },
        {
          "label": {
            "zh": "后续总结",
            "tw": "後續總結",
            "en": "x.com source"
          },
          "url": "https://x.com/haoRU_3to1/status/2073304718315544691",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-045",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-011",
      "status": "verified",
      "incidentDate": "2026-07-02",
      "datePrecision": "day",
      "title": {
        "zh": "Aztec私人Rollup桥黑客继续混币",
        "tw": "Aztec私人Rollup橋黑客繼續混幣",
        "en": "Aztec private-rollup bridge exploiter fund movement"
      },
      "summary": {
        "zh": "资金完成混币；不将该异动重复计算为新攻击。",
        "tw": "資金完成混幣；不將該異動重複計算為新攻擊。",
        "en": "Funds linked to an earlier Aztec bridge incident moved again through privacy infrastructure; no new protocol exploit was confirmed."
      },
      "details": {
        "zh": "## 事件背景\nAztec Connect / 私人 Rollup 桥相关攻击发生在窗口外（公开报道指向 6 月废弃桥证明校验不完整等路径）。本期同样属于 旧案赃款继续混币：攻击者把已盗 ETH 分批存入 Tornado Cash，提高司法与分析追踪成本。\n\n## 事件经过\n1. 7 月 2 日 09:14（北京时间）前后，PeckShield 标记 Aztec 私人 Rollup 桥攻击者异动。\n2. 本批新增约 145 ETH 进入 Tornado Cash。\n3. 累计已混入约 200 ETH（含历史批次）。\n4. 原帖以实体标签 + 截断地址为主，无合格完整地址入账。\n5. 不计为 7 月新攻击，只记资金异动。\n\n## 资金流向\n1. 7 月 2 日 09:14（北京时间）前后，PeckShield 标记 Aztec 私人 Rollup 桥攻击者异动。\n2. 本批新增约 145 ETH 进入 Tornado Cash。\n\n## 金额口径\n未统一/见正文\n\n## 证据边界\n本条为旧案资金异动，非本期新攻击首发。\n\n## 处置状态\n资金完成混币；不将该异动重复计算为新攻击。",
        "tw": "## 事件背景\nAztec Connect / 私人 Rollup 橋相關攻擊發生在窗口外（公開報道指向 6 月廢棄橋證明校驗不完整等路徑）。本期同樣屬於 舊案贓款繼續混幣：攻擊者把已盜 ETH 分批存入 Tornado Cash，提高司法與分析追蹤成本。\n\n## 事件經過\n1. 7 月 2 日 09:14（北京時間）前後，PeckShield 標記 Aztec 私人 Rollup 橋攻擊者異動。\n2. 本批新增約 145 ETH 進入 Tornado Cash。\n3. 累計已混入約 200 ETH（含歷史批次）。\n4. 原帖以實體標籤 + 截斷地址為主，無合格完整地址入賬。\n5. 不計為 7 月新攻擊，只記資金異動。\n\n## 資金流向\n1. 7 月 2 日 09:14（北京時間）前後，PeckShield 標記 Aztec 私人 Rollup 橋攻擊者異動。\n2. 本批新增約 145 ETH 進入 Tornado Cash。\n\n## 金額口徑\n未統一/見正文\n\n## 證據邊界\n本條為舊案資金異動，非本期新攻擊首發。\n\n## 處置狀態\n資金完成混幣；不將該異動重複計算為新攻擊。",
        "en": "## Incident overview\nFunds linked to an earlier Aztec bridge incident moved again through privacy infrastructure; no new protocol exploit was confirmed.\n\n## Amount basis\nNo single verified USD loss figure was published; see the incident record.\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "fund-movement",
      "severity": "medium",
      "ecosystems": [
        "Ethereum"
      ],
      "chains": [
        "Ethereum"
      ],
      "lossUsd": null,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "未统一/见正文",
        "tw": "未統一/見正文",
        "en": "No single verified USD loss figure was published; see the incident record."
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "Ethereum",
          "address": "0x0f18d8b44a740272f0be4d08338d2b165b7edd17",
          "entity": {
            "zh": "[链：Ethereum] [黑客地址] [攻击者EOA] [Aztec Exploiter 1 标签] [混币前置]",
            "tw": "[鏈：Ethereum] [黑客地址] [攻擊者EOA] [Aztec Exploiter 1 標籤] [混幣前置]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "mixer",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/PeckShieldAlert/status/2072489141573693603",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [黑客地址] [攻击者EOA] [Aztec Exploiter 1 标签] [混币前置]",
            "tw": "[鏈：Ethereum] [黑客地址] [攻擊者EOA] [Aztec Exploiter 1 標籤] [混幣前置]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0xC431a54943821339642f1073BBa884170Ba8C1f5",
          "entity": {
            "zh": "[链：Ethereum] [黑客地址] [中转钱包1] [被盗资产接收]",
            "tw": "[鏈：Ethereum] [黑客地址] [中轉錢包1] [被盜資產接收]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/PeckShieldAlert/status/2072489141573693603",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [黑客地址] [中转钱包1] [被盗资产接收]",
            "tw": "[鏈：Ethereum] [黑客地址] [中轉錢包1] [被盜資產接收]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0x0af71cd94A0305289ab2b337a1Da5D8e6CEf9912",
          "entity": {
            "zh": "[链：Ethereum] [黑客地址] [中转钱包2] [被盗资产接收]",
            "tw": "[鏈：Ethereum] [黑客地址] [中轉錢包2] [被盜資產接收]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "hack",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/PeckShieldAlert/status/2072489141573693603",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [黑客地址] [中转钱包2] [被盗资产接收]",
            "tw": "[鏈：Ethereum] [黑客地址] [中轉錢包2] [被盜資產接收]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        },
        {
          "chain": "Ethereum",
          "address": "0xff1f2b4adb9df6fc8eafecdcbf96a2b351680455",
          "entity": {
            "zh": "[链：Ethereum] [受影响合约] [Aztec Connect]（非黑客）",
            "tw": "[鏈：Ethereum] [受影響合約] [Aztec Connect]（非黑客）",
            "en": "contract address documented by a public source"
          },
          "role": "contract",
          "category": "unknown",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/PeckShieldAlert/status/2072489141573693603",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [受影响合约] [Aztec Connect]（非黑客）",
            "tw": "[鏈：Ethereum] [受影響合約] [Aztec Connect]（非黑客）",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "PeckShield原帖",
            "tw": "PeckShield原帖",
            "en": "x.com source"
          },
          "url": "https://x.com/PeckShieldAlert/status/2072489141573693603",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-011",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-010",
      "status": "verified",
      "incidentDate": "2026-07-02",
      "datePrecision": "day",
      "title": {
        "zh": "Taiko黑客旧案继续混币",
        "tw": "Taiko黑客舊案繼續混幣",
        "en": "Taiko exploiter funds moved into Tornado Cash"
      },
      "summary": {
        "zh": "资金进入隐私协议后追踪难度上升；本项不计为7月新攻击，只计为本期资金异动。",
        "tw": "資金進入隱私協議後追蹤難度上升；本項不計為7月新攻擊，只計為本期資金異動。",
        "en": "A previously identified Taiko-linked entity moved another 180 ETH into Tornado Cash; this is old-case laundering activity, not a new exploit."
      },
      "details": {
        "zh": "## 事件背景\n原始 Taiko 相关攻击（桥/状态验证路径问题）发生在本统计窗口之前。本期条目的「问题」不是新的合约漏洞被打穿，而是 旧案赃款仍在攻击者控制下持续清洗：只要混币器与出金通道可用，攻击者会分批把 ETH 送入 Tornado Cash，拉长追踪链、打断与原始攻击交易的直接关联。\n\n## 事件经过\n1. PeckShield 等监控标签持续盯防 Taiko 相关攻击者实体。\n2. 2026-07-02 09:02（北京时间）附近，监控到该实体新增将 180 ETH 存入 Tornado Cash。\n3. 该笔为旧案资金异动，不满足「7 月新攻击」计入条件，但进入本期洗钱观察账本。\n4. 公开帖多为截断地址/标签截图，完整 EOA 未达可安全抄录标准 → 不猜补。\n\n## 资金流向\n2. 2026-07-02 09:02（北京时间）附近，监控到该实体新增将 180 ETH 存入 Tornado Cash。\n\n## 金额口径\n未统一/见正文\n\n## 证据边界\n完整地址/Tx 不足时不猜补。 本条为旧案资金异动，非本期新攻击首发。\n\n## 处置状态\n资金进入隐私协议后追踪难度上升；本项不计为7月新攻击，只计为本期资金异动。",
        "tw": "## 事件背景\n原始 Taiko 相關攻擊（橋/狀態驗證路徑問題）發生在本統計窗口之前。本期條目的「問題」不是新的合約漏洞被打穿，而是 舊案贓款仍在攻擊者控制下持續清洗：只要混幣器與出金通道可用，攻擊者會分批把 ETH 送入 Tornado Cash，拉長追蹤鏈、打斷與原始攻擊交易的直接關聯。\n\n## 事件經過\n1. PeckShield 等監控標籤持續盯防 Taiko 相關攻擊者實體。\n2. 2026-07-02 09:02（北京時間）附近，監控到該實體新增將 180 ETH 存入 Tornado Cash。\n3. 該筆為舊案資金異動，不滿足「7 月新攻擊」計入條件，但進入本期洗錢觀察賬本。\n4. 公開帖多為截斷地址/標籤截圖，完整 EOA 未達可安全抄錄標準 → 不猜補。\n\n## 資金流向\n2. 2026-07-02 09:02（北京時間）附近，監控到該實體新增將 180 ETH 存入 Tornado Cash。\n\n## 金額口徑\n未統一/見正文\n\n## 證據邊界\n完整地址/Tx 不足時不猜補。 本條為舊案資金異動，非本期新攻擊首發。\n\n## 處置狀態\n資金進入隱私協議後追蹤難度上升；本項不計為7月新攻擊，只計為本期資金異動。",
        "en": "## Incident overview\nA previously identified Taiko-linked entity moved another 180 ETH into Tornado Cash; this is old-case laundering activity, not a new exploit.\n\n## Amount basis\nNo single verified USD loss figure was published; see the incident record.\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "fund-movement",
      "severity": "medium",
      "ecosystems": [
        "Ethereum"
      ],
      "chains": [
        "Ethereum"
      ],
      "lossUsd": null,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "未统一/见正文",
        "tw": "未統一/見正文",
        "en": "No single verified USD loss figure was published; see the incident record."
      },
      "addressDisclosure": "not-published",
      "addresses": [],
      "references": [
        {
          "label": {
            "zh": "PeckShield原帖",
            "tw": "PeckShield原帖",
            "en": "x.com source"
          },
          "url": "https://x.com/PeckShieldAlert/status/2072486031707005283",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-010",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-009",
      "status": "verified",
      "incidentDate": "2026-07-01",
      "datePrecision": "day",
      "title": {
        "zh": "恶意npm包供应链攻击",
        "tw": "惡意npm包供應鏈攻擊",
        "en": "Malicious npm package supply-chain campaign"
      },
      "summary": {
        "zh": "恶意包和伪造仓库被安全机构识别并预警，实际受害钱包数量和总损失尚未公开。",
        "tw": "惡意包和偽造倉庫被安全機構識別並預警，實際受害錢包數量和總損失尚未公開。",
        "en": "At least 30 lookalike Web3 packages carried credential-stealing code; aggregate wallet losses were not publicly established."
      },
      "details": {
        "zh": "## 事件背景\n攻击面不在某条链的智能合约，而在 Web3 开发供应链：npm 公共仓库审核弱、包名仿冒成本低。攻击者批量发布至少 30 个伪装成交易机器人、策略库或 DeFi 工具的 npm 包（公开点名包括 stake-math@3.5.4 等），包内夹带 JavaScript 信息窃取器（infostealer）。开发者一旦 npm install / CI 拉取依赖，恶意代码即在本地或构建环境执行，可读取：\n\n- .env、部署私钥、RPC Key、交易所 API；\n- 浏览器钱包扩展数据与密钥库路径；\n- 交易机器人配置与会话 cookie。\n\n这是典型的 依赖投毒（dependency confusion / typosquat 类供应链），损失分散在多个受害钱包，难以用「单协议被黑金额」统计。\n\n## 事件经过\n1. 攻击者注册/发布大量仿冒 npm 包并提高版本号诱导更新。\n2. 开发者或自动化流水线安装依赖，postinstall / 运行时触发窃取逻辑。\n3. 木马采集环境变量、钱包凭证、浏览器数据、机器人配置。\n4. 数据外传到攻击者控制的 C2；随后可能出现链上盗币（各案独立，无统一归集地址公开）。\n5. SlowMist 等安全机构识别恶意包与伪造仓库并公开预警。\n6. 因受害面分散，公开渠道未给出「总损失美元」与单一黑客主地址。\n\n## 资金流向\n4. 数据外传到攻击者控制的 C2；随后可能出现链上盗币（各案独立，无统一归集地址公开）。\n\n## 金额口径\n未公开统一链上损失\n\n## 证据边界\n部分角色/根因仍待核。\n\n## 处置状态\n恶意包和伪造仓库被安全机构识别并预警，实际受害钱包数量和总损失尚未公开。",
        "tw": "## 事件背景\n攻擊面不在某條鏈的智能合約，而在 Web3 開發供應鏈：npm 公共倉庫審核弱、包名仿冒成本低。攻擊者批量發佈至少 30 個偽裝成交易機器人、策略庫或 DeFi 工具的 npm 包（公開點名包括 stake-math@3.5.4 等），包內夾帶 JavaScript 信息竊取器（infostealer）。開發者一旦 npm install / CI 拉取依賴，惡意代碼即在本地或構建環境執行，可讀取：\n\n- .env、部署私鑰、RPC Key、交易所 API；\n- 瀏覽器錢包擴展數據與密鑰庫路徑；\n- 交易機器人配置與會話 cookie。\n\n這是典型的 依賴投毒（dependency confusion / typosquat 類供應鏈），損失分散在多個受害錢包，難以用「單協議被黑金額」統計。\n\n## 事件經過\n1. 攻擊者註冊/發佈大量仿冒 npm 包並提高版本號誘導更新。\n2. 開發者或自動化流水線安裝依賴，postinstall / 運行時觸發竊取邏輯。\n3. 木馬採集環境變量、錢包憑證、瀏覽器數據、機器人配置。\n4. 數據外傳到攻擊者控制的 C2；隨後可能出現鏈上盜幣（各案獨立，無統一歸集地址公開）。\n5. SlowMist 等安全機構識別惡意包與偽造倉庫並公開預警。\n6. 因受害面分散，公開渠道未給出「總損失美元」與單一黑客主地址。\n\n## 資金流向\n4. 數據外傳到攻擊者控制的 C2；隨後可能出現鏈上盜幣（各案獨立，無統一歸集地址公開）。\n\n## 金額口徑\n未公開統一鏈上損失\n\n## 證據邊界\n部分角色/根因仍待核。\n\n## 處置狀態\n惡意包和偽造倉庫被安全機構識別並預警，實際受害錢包數量和總損失尚未公開。",
        "en": "## Incident overview\nAt least 30 lookalike Web3 packages carried credential-stealing code; aggregate wallet losses were not publicly established.\n\n## Amount basis\nNo single verified USD loss figure was published; see the incident record.\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "supply-chain",
      "severity": "medium",
      "ecosystems": [
        "Other"
      ],
      "chains": [
        "Other"
      ],
      "lossUsd": null,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "未公开统一链上损失",
        "tw": "未公開統一鏈上損失",
        "en": "No single verified USD loss figure was published; see the incident record."
      },
      "addressDisclosure": "not-published",
      "addresses": [],
      "references": [
        {
          "label": {
            "zh": "SlowMist原帖",
            "tw": "SlowMist原帖",
            "en": "x.com source"
          },
          "url": "https://x.com/SlowMist_Team/status/2072241756746486034",
          "type": "research"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-009",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-008",
      "status": "verified",
      "incidentDate": "2026-07-01",
      "datePrecision": "day",
      "title": {
        "zh": "Edel Finance / BackedFi借贷市场",
        "tw": "Edel Finance / BackedFi借貸市場",
        "en": "Edel Finance ERC-4626 donation attack"
      },
      "summary": {
        "zh": "项目遏制漏洞，但形成约40.3万美元坏账；攻击者所得已进入Tornado Cash。RWA / xStocks / ERC4626 封装资产若被借贷协议直接当预言机，同类「捐赠抬汇率」会反复出现。",
        "tw": "項目遏制漏洞，但形成約40.3萬美元壞賬；攻擊者所得已進入Tornado Cash。RWA / xStocks / ERC4626 封裝資產若被借貸協議直接當預言機，同類「捐贈抬匯率」會反覆出現。",
        "en": "Attackers manipulated an ERC-4626 share price used as collateral, extracting about $353,000 and leaving roughly $403,000 in bad debt."
      },
      "details": {
        "zh": "## 事件背景\nwGOOGLx（wrapped xStocks / 代币化谷歌股票的封装版）在 Edel Lending 中被当作抵押品。其价格源通过 ERC-4626 金库的 convertToAssets() 计算「每一份额对应多少底层资产」，而 totalAssets() 直接读取底层 GOOGLx 在金库合约中的余额，没有独立的预言机 TWAP，也没有：\n\n1. 份额价格变化上限（max share price deviation / rate limiter）；\n2. 捐赠攻击防护（donation / inflation attack protection，例如 virtual shares、dead shares、或对直接 transfer 进金库的资产不计入定价）；\n3. 最小流动性 / 滑点约束，防止单笔外部转入瞬间扭曲 NAV。\n\n因此，任何人只要把底层 GOOGLx 直接转入金库地址（不走正常 mint 路径），totalAssets() 就会上升，而份额总数不变 → convertToAssets() 算出的「每份 wGOOGLx 价值」被人为抬高。借贷侧若按该虚高价格认定抵押率，攻击者就能用少量真实成本撬动大量借款额度。本质是 ERC-4626 会计假设「金库资产只来自合法存取」被打破 + 借贷协议把可操纵的份额汇率当成可信抵押品预言机。\n\n## 事件经过\n1. 准备资金：攻击者通过闪电贷或临时资金拿到足够的底层 GOOGLx / 相关资产，用于后续「捐赠」与循环操作。\n2. 直接捐赠扭曲汇率：将底层 GOOGLx 直接转入 ERC-4626 金库（不铸造对应份额），使 totalAssets() 暴涨、份额供给不变。\n3. 估值失真：wGOOGLx 经 convertToAssets() 算出的份额价值被抬高到合理价值的约 78 倍。\n4. 虚高抵押借贷：攻击者把被高估的 wGOOGLx 作为抵押品，在 Edel 的约 6 个借贷市场中反复存入并借出其他资产（稳定币/主流资产等）。\n5. 循环放大：在操纵窗口内可多次 deposit/borrow，把会计偏差兑换成可提取的真实资产，形成协议侧坏账。\n6. 出金换 ETH：全部获利资产被兑换为约 224 ETH（约 35.3 万美元量级）。\n7. 混币离场：ETH 转入 Tornado Cash，链上追踪难度陡增。\n8. 项目侧：漏洞路径被遏制后，协议账面仍留下约 40.3 万美元不良债务（坏账口径与攻击者套现口径不同，须分开表述）。\n\n## 资金流向\n2. 直接捐赠扭曲汇率：将底层 GOOGLx 直接转入 ERC-4626 金库（不铸造对应份额），使 totalAssets() 暴涨、份额供给不变。\n5. 循环放大：在操纵窗口内可多次 deposit/borrow，把会计偏差兑换成可提取的真实资产，形成协议侧坏账。\n6. 出金换 ETH：全部获利资产被兑换为约 224 ETH（约 35.3 万美元量级）。\n7. 混币离场：ETH 转入 Tornado Cash，链上追踪难度陡增。\n\n## 金额口径\n攻击者实现约224 ETH、约35.3万美元；协议不良债务约40.3万美元\n\n## 证据边界\n以公开可核验来源为界；未证实细节不写入确定结论。\n\n## 处置状态\n项目遏制漏洞，但形成约40.3万美元坏账；攻击者所得已进入Tornado Cash。RWA / xStocks / ERC4626 封装资产若被借贷协议直接当预言机，同类「捐赠抬汇率」会反复出现。",
        "tw": "## 事件背景\nwGOOGLx（wrapped xStocks / 代幣化谷歌股票的封裝版）在 Edel Lending 中被當作抵押品。其價格源通過 ERC-4626 金庫的 convertToAssets() 計算「每一份額對應多少底層資產」，而 totalAssets() 直接讀取底層 GOOGLx 在金庫合約中的餘額，沒有獨立的預言機 TWAP，也沒有：\n\n1. 份額價格變化上限（max share price deviation / rate limiter）；\n2. 捐贈攻擊防護（donation / inflation attack protection，例如 virtual shares、dead shares、或對直接 transfer 進金庫的資產不計入定價）；\n3. 最小流動性 / 滑點約束，防止單筆外部轉入瞬間扭曲 NAV。\n\n因此，任何人只要把底層 GOOGLx 直接轉入金庫地址（不走正常 mint 路徑），totalAssets() 就會上升，而份額總數不變 → convertToAssets() 算出的「每份 wGOOGLx 價值」被人為抬高。借貸側若按該虛高價格認定抵押率，攻擊者就能用少量真實成本撬動大量借款額度。本質是 ERC-4626 會計假設「金庫資產只來自合法存取」被打破 + 借貸協議把可操縱的份額匯率當成可信抵押品預言機。\n\n## 事件經過\n1. 準備資金：攻擊者通過閃電貸或臨時資金拿到足夠的底層 GOOGLx / 相關資產，用於後續「捐贈」與循環操作。\n2. 直接捐贈扭曲匯率：將底層 GOOGLx 直接轉入 ERC-4626 金庫（不鑄造對應份額），使 totalAssets() 暴漲、份額供給不變。\n3. 估值失真：wGOOGLx 經 convertToAssets() 算出的份額價值被抬高到合理價值的約 78 倍。\n4. 虛高抵押借貸：攻擊者把被高估的 wGOOGLx 作為抵押品，在 Edel 的約 6 個借貸市場中反覆存入並借出其他資產（穩定幣/主流資產等）。\n5. 循環放大：在操縱窗口內可多次 deposit/borrow，把會計偏差兌換成可提取的真實資產，形成協議側壞賬。\n6. 出金換 ETH：全部獲利資產被兌換為約 224 ETH（約 35.3 萬美元量級）。\n7. 混幣離場：ETH 轉入 Tornado Cash，鏈上追蹤難度陡增。\n8. 項目側：漏洞路徑被遏制後，協議賬面仍留下約 40.3 萬美元不良債務（壞賬口徑與攻擊者套現口徑不同，須分開表述）。\n\n## 資金流向\n2. 直接捐贈扭曲匯率：將底層 GOOGLx 直接轉入 ERC-4626 金庫（不鑄造對應份額），使 totalAssets() 暴漲、份額供給不變。\n5. 循環放大：在操縱窗口內可多次 deposit/borrow，把會計偏差兌換成可提取的真實資產，形成協議側壞賬。\n6. 出金換 ETH：全部獲利資產被兌換為約 224 ETH（約 35.3 萬美元量級）。\n7. 混幣離場：ETH 轉入 Tornado Cash，鏈上追蹤難度陡增。\n\n## 金額口徑\n攻擊者實現約224 ETH、約35.3萬美元；協議不良債務約40.3萬美元\n\n## 證據邊界\n以公開可核驗來源為界；未證實細節不寫入確定結論。\n\n## 處置狀態\n項目遏制漏洞，但形成約40.3萬美元壞賬；攻擊者所得已進入Tornado Cash。RWA / xStocks / ERC4626 封裝資產若被借貸協議直接當預言機，同類「捐贈抬匯率」會反覆出現。",
        "en": "## Incident overview\nAttackers manipulated an ERC-4626 share price used as collateral, extracting about $353,000 and leaving roughly $403,000 in bad debt.\n\n## Amount basis\nReported loss: $403,000\n\n## Evidence boundary\nThe archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed."
      },
      "category": "protocol-exploit",
      "severity": "high",
      "ecosystems": [
        "Ethereum"
      ],
      "chains": [
        "Ethereum"
      ],
      "lossUsd": 403000,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "assetLoss": {
        "zh": "攻击者实现约224 ETH、约35.3万美元；协议不良债务约40.3万美元",
        "tw": "攻擊者實現約224 ETH、約35.3萬美元；協議不良債務約40.3萬美元",
        "en": "Reported loss: $403,000"
      },
      "addressDisclosure": "published",
      "addresses": [
        {
          "chain": "Ethereum",
          "address": "0x58428161bB55c14A413945f06cbDeC157F411C76",
          "entity": {
            "zh": "[链：Ethereum] [黑客地址] [攻击者EOA] [被盗资产接收] [混币前置]",
            "tw": "[鏈：Ethereum] [黑客地址] [攻擊者EOA] [被盜資產接收] [混幣前置]",
            "en": "attacker address documented by a public source"
          },
          "role": "attacker",
          "category": "mixer",
          "confidence": 0.9,
          "sourceUrl": "https://x.com/SlowMist_Team/status/2072146843044319478",
          "evidenceStatus": "verified_public_source",
          "evidenceSummary": {
            "zh": "[链：Ethereum] [黑客地址] [攻击者EOA] [被盗资产接收] [混币前置]",
            "tw": "[鏈：Ethereum] [黑客地址] [攻擊者EOA] [被盜資產接收] [混幣前置]",
            "en": "Role and tags are preserved from the cited public record."
          },
          "reviewRequired": true
        }
      ],
      "references": [
        {
          "label": {
            "zh": "SlowMist根因分析",
            "tw": "SlowMist根因分析",
            "en": "x.com source"
          },
          "url": "https://x.com/SlowMist_Team/status/2072146843044319478",
          "type": "research"
        },
        {
          "label": {
            "zh": "CertiK攻击者地址",
            "tw": "CertiK攻擊者地址",
            "en": "x.com source"
          },
          "url": "https://x.com/CertiKAlert/status/2072143306805645523",
          "type": "research"
        },
        {
          "label": {
            "zh": "Cyvers及Edel官方说明",
            "tw": "Cyvers及Edel官方說明",
            "en": "x.com source"
          },
          "url": "https://x.com/CyversAlerts/status/2072259516435939780",
          "type": "official"
        },
        {
          "label": {
            "zh": "Edel官方",
            "tw": "Edel官方",
            "en": "x.com source"
          },
          "url": "https://x.com/edeldotfinance/status/2072154468058022033",
          "type": "official"
        }
      ],
      "sourceUrl": "security-archive.html?incident=DCI-2026-008",
      "sourceLabel": "德尔泰公开安全情报档案"
    },
    {
      "id": "DCI-2026-005",
      "status": "verified",
      "incidentDate": "2026-06-30",
      "datePrecision": "day",
      "title": {
        "zh": "SecondFi Cardano 钱包密钥生成漏洞",
        "tw": "SecondFi Cardano 錢包密鑰生成漏洞",
        "en": "SecondFi Cardano wallet key-generation flaw"
      },
      "summary": {
        "zh": "网页签名器的确定性随机数推导错误导致私钥可预测，公开披露约 1,600 万枚 ADA 被盗；因缺少统一美元口径，未计入美元损失总额。",
        "tw": "網頁簽名器的確定性隨機數推導錯誤導致私鑰可預測，公開披露約 1,600 萬枚 ADA 被盜；因缺少統一美元口徑，未計入美元損失總額。",
        "en": "A deterministic randomness flaw in a web signer made private keys predictable. About 16 million ADA was reported stolen; no USD value is included in the aggregate."
      },
      "details": {
        "zh": "SecondFi 网页签名器在密钥生成环节使用可预测的确定性随机数，导致部分 Cardano 私钥可被重建。公开披露约 1,600 万枚 ADA 被转走；由于事件披露阶段缺少稳定美元估值，本库不把该资产数量计入美元损失汇总。",
        "tw": "SecondFi 網頁簽名器在密鑰生成環節使用可預測的確定性隨機數，導致部分 Cardano 私鑰可被重建。公開披露約 1,600 萬枚 ADA 被轉走；由於事件披露階段缺少穩定美元估值，本庫不把該資產數量計入美元損失匯總。",
        "en": "A predictable deterministic-randomness implementation in SecondFi's web signer allowed some Cardano private keys to be reconstructed. About 16 million ADA was reported moved; the asset amount is excluded from the USD aggregate because no stable incident-time valuation was available."
      },
      "category": "wallet-vulnerability",
      "severity": "critical",
      "ecosystems": [
        "Cardano"
      ],
      "chains": [
        "Cardano"
      ],
      "lossUsd": null,
      "assetLoss": "16,000,000 ADA",
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "addressDisclosure": "not-published",
      "addresses": [],
      "references": [
        {
          "label": {
            "zh": "SecondFi 官方说明",
            "tw": "SecondFi 官方說明",
            "en": "SecondFi official statement"
          },
          "url": "https://x.com/secondfiapp/status/2071558652641870076",
          "type": "official"
        },
        {
          "label": {
            "zh": "财经头部报道",
            "tw": "財經頭部報道",
            "en": "Caijing Toutiao media report"
          },
          "url": "https://baijiahao.baidu.com/s?id=1869391964274934716",
          "type": "media"
        }
      ],
      "sourceUrl": "press-secondfi-cardano-wallet-vulnerability",
      "sourceLabel": "德尔泰公开事件分析"
    },
    {
      "id": "DCI-2026-004",
      "status": "verified",
      "incidentDate": "2026-06-09",
      "datePrecision": "day",
      "title": {
        "zh": "Humanity Protocol 私钥泄露事件",
        "tw": "Humanity Protocol 私鑰洩露事件",
        "en": "Humanity Protocol private-key compromise"
      },
      "summary": {
        "zh": "项目相关私钥泄露后超过 1.87 亿枚 H 代币被转移抛售；因缺少稳定美元估值，未计入美元损失总额。",
        "tw": "項目相關私鑰洩露後超過 1.87 億枚 H 代幣被轉移拋售；因缺少穩定美元估值，未計入美元損失總額。",
        "en": "More than 187 million H tokens were moved and sold following a reported private-key compromise; no USD value is included in the aggregate."
      },
      "details": {
        "zh": "Humanity Protocol 相关私钥失陷后，大量 H 代币被非授权转移并在市场抛售。事件造成代币价格与流动性冲击，但公开资料缺少可稳定复核的美元损失口径，因此仅记录资产规模与攻击类型。",
        "tw": "Humanity Protocol 相關私鑰失陷後，大量 H 代幣被非授權轉移並在市場拋售。事件造成代幣價格與流動性衝擊，但公開資料缺少可穩定復核的美元損失口徑，因此僅記錄資產規模與攻擊類型。",
        "en": "After a Humanity Protocol-related private key was compromised, a large quantity of H tokens was transferred without authorization and sold into the market. Public records did not provide a stable, reproducible USD loss basis, so the archive records the asset amount and attack type without adding it to USD totals."
      },
      "category": "key-compromise",
      "severity": "high",
      "ecosystems": [
        "Ethereum"
      ],
      "chains": [
        "Ethereum"
      ],
      "lossUsd": null,
      "assetLoss": "187,000,000 H",
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "addressDisclosure": "not-published",
      "addresses": [],
      "references": [
        {
          "label": {
            "zh": "公开事件报道",
            "tw": "公開事件報道",
            "en": "Public incident report"
          },
          "url": "https://mp.weixin.qq.com/s/tbE-32A67dTEDKiWeIQt9A",
          "type": "media"
        }
      ],
      "sourceUrl": "press-humanity-private-key-compromise",
      "sourceLabel": "德尔泰公开事件分析"
    },
    {
      "id": "DCI-2026-003",
      "status": "verified",
      "incidentDate": "2026-05-30",
      "datePrecision": "day",
      "title": {
        "zh": "Alephium TokenBridge 链下验证攻击",
        "tw": "Alephium TokenBridge 鏈下驗證攻擊",
        "en": "Alephium TokenBridge off-chain validation attack"
      },
      "summary": {
        "zh": "攻击者向链下桥接后台注入虚假消息并绕过守护者验证，公开披露损失约 81.5 万美元。",
        "tw": "攻擊者向鏈下橋接後台注入虛假消息並繞過守護者驗證，公開披露損失約 81.5 萬美元。",
        "en": "An attacker injected false messages into off-chain bridge infrastructure and bypassed guardian validation, with reported losses of about $815,000."
      },
      "details": {
        "zh": "攻击者向 Alephium TokenBridge 的链下基础设施注入虚假消息，并绕过守护者验证流程，使桥接后台接受未经授权的资产指令。公开披露损失约 81.5 万美元，事件重点暴露了链下验证与消息签名的安全边界。",
        "tw": "攻擊者向 Alephium TokenBridge 的鏈下基礎設施注入虛假消息，並繞過守護者驗證流程，使橋接後台接受未經授權的資產指令。公開披露損失約 81.5 萬美元，事件重點暴露了鏈下驗證與消息簽名的安全邊界。",
        "en": "The attacker injected false messages into Alephium TokenBridge's off-chain infrastructure and bypassed guardian validation, causing the bridge backend to accept unauthorized asset instructions. About $815,000 was publicly reported lost, highlighting the security boundary around off-chain validation and message signing."
      },
      "category": "bridge-exploit",
      "severity": "high",
      "ecosystems": [
        "Alephium"
      ],
      "chains": [
        "Alephium"
      ],
      "lossUsd": 815000,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "addressDisclosure": "not-published",
      "addresses": [],
      "references": [
        {
          "label": {
            "zh": "公开事件分析",
            "tw": "公開事件分析",
            "en": "Public incident analysis"
          },
          "url": "https://mp.weixin.qq.com/s/DtNcJYh27TBoDwHaEj2RDw",
          "type": "analysis"
        }
      ],
      "sourceUrl": "press-alephium-bridge-hack",
      "sourceLabel": "德尔泰公开事件分析"
    },
    {
      "id": "DCI-2026-006",
      "status": "verified",
      "incidentDate": "2026-05-27",
      "datePrecision": "day",
      "title": {
        "zh": "Ill Bloom 钱包弱随机数漏洞",
        "tw": "Ill Bloom 錢包弱隨機數漏洞",
        "en": "Ill Bloom weak-randomness wallet vulnerability"
      },
      "summary": {
        "zh": "部分钱包助记词生成使用弱随机源，攻击者可枚举私钥，公开披露多链损失超过 500 万美元。",
        "tw": "部分錢包助記詞生成使用弱隨機源，攻擊者可枚舉私鑰，公開披露多鏈損失超過 500 萬美元。",
        "en": "Weak randomness in wallet seed generation enabled private-key enumeration, with more than $5 million in reported multi-chain losses."
      },
      "details": {
        "zh": "部分软件钱包使用弱伪随机数生成助记词，显著压缩了真实密钥空间，使攻击者可以枚举私钥并跨链清空资产。公开披露显示受影响钱包可追溯至 2018 年，涉及 Bitcoin、Ethereum、Tron 和 Solana 等网络。",
        "tw": "部分軟件錢包使用弱偽隨機數生成助記詞，顯著壓縮了真實密鑰空間，使攻擊者可以枚舉私鑰並跨鏈清空資產。公開披露顯示受影響錢包可追溯至 2018 年，涉及 Bitcoin、Ethereum、Tron 和 Solana 等網絡。",
        "en": "Some software wallets generated seed phrases with weak pseudo-randomness, sharply reducing the effective key space and enabling attackers to enumerate private keys across chains. Public reporting traced affected wallets back to 2018 across Bitcoin, Ethereum, Tron, and Solana."
      },
      "category": "wallet-vulnerability",
      "severity": "critical",
      "ecosystems": [
        "Bitcoin",
        "Ethereum",
        "TRON",
        "Solana"
      ],
      "chains": [
        "Bitcoin",
        "Ethereum",
        "TRON",
        "Solana"
      ],
      "lossUsd": 5000000,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "addressDisclosure": "not-published",
      "addresses": [],
      "references": [
        {
          "label": {
            "zh": "第二金融网报道",
            "tw": "第二金融網報道",
            "en": "Second Finance media report"
          },
          "url": "http://two.xa1288.com/chuangtou/730262.html",
          "type": "media"
        }
      ],
      "sourceUrl": "press-defi-ill-bloom-wallet-vulnerability",
      "sourceLabel": "德尔泰公开事件分析"
    },
    {
      "id": "DCI-2026-002",
      "status": "verified",
      "incidentDate": "2026-04-01",
      "datePrecision": "month",
      "title": {
        "zh": "Kelp DAO 跨链验证漏洞事件",
        "tw": "Kelp DAO 跨鏈驗證漏洞事件",
        "en": "Kelp DAO cross-chain validation incident"
      },
      "summary": {
        "zh": "公开披露超过 2.9 亿美元资产被非法转移，其中约 7,100 万美元被冻结，其余资金经历跨链与匿名化转移。",
        "tw": "公開披露超過 2.9 億美元資產被非法轉移，其中約 7,100 萬美元被凍結，其餘資金經歷跨鏈與匿名化轉移。",
        "en": "More than $290 million was reportedly transferred without authorization, with about $71 million frozen while the remainder moved across chains and obfuscation services."
      },
      "details": {
        "zh": "跨链验证配置被突破后，攻击者完成大额非授权资产转移。Arbitrum 安全委员会随后冻结约 7,100 万美元，其余资金经过拆分、跨链和匿名化路径继续流转。本库把冻结额与未追回额分开统计。",
        "tw": "跨鏈驗證配置被突破後，攻擊者完成大額非授權資產轉移。Arbitrum 安全委員會隨後凍結約 7,100 萬美元，其餘資金經過拆分、跨鏈和匿名化路徑繼續流轉。本庫把凍結額與未追回額分開統計。",
        "en": "After the cross-chain validation setup was compromised, the attacker transferred a large amount of assets without authorization. The Arbitrum Security Council later froze about $71 million, while the remainder moved through splitting, bridging, and obfuscation paths. Frozen and unrecovered amounts are tracked separately."
      },
      "category": "bridge-exploit",
      "severity": "critical",
      "ecosystems": [
        "Ethereum",
        "Cross-chain"
      ],
      "chains": [
        "Ethereum",
        "Arbitrum",
        "Bitcoin"
      ],
      "lossUsd": 290000000,
      "frozenUsd": 71000000,
      "recoveredUsd": 0,
      "addressDisclosure": "not-published",
      "addresses": [],
      "references": [
        {
          "label": {
            "zh": "公开事件分析",
            "tw": "公開事件分析",
            "en": "Public incident analysis"
          },
          "url": "https://mp.weixin.qq.com/s/LXCcmLNypTSNNgSiZc6HDA",
          "type": "analysis"
        }
      ],
      "sourceUrl": "press-kelp-dao-bridge-hack",
      "sourceLabel": "德尔泰公开事件分析"
    },
    {
      "id": "DCI-2024-001",
      "status": "verified",
      "incidentDate": "2024-10-16",
      "datePrecision": "day",
      "title": {
        "zh": "Radiant Capital 多签运维环境入侵",
        "tw": "Radiant Capital 多簽運維環境入侵",
        "en": "Radiant Capital multisig operations compromise"
      },
      "summary": {
        "zh": "攻击者控制多签人员终端并篡改 Safe Wallet 交易界面，公开披露约 5,000 万美元资产损失。",
        "tw": "攻擊者控制多簽人員終端並篡改 Safe Wallet 交易介面，公開披露約 5,000 萬美元資產損失。",
        "en": "Attackers compromised multisig operators and tampered with the Safe Wallet transaction interface, causing about $50 million in reported losses."
      },
      "details": {
        "zh": "攻击者先控制多签成员终端，再篡改 Safe Wallet 前端显示与实际交易载荷，诱导签署恶意交易并取得协议管理员权限。攻击随后同时影响 Arbitrum 与 BNB Chain 市场，公开披露损失约 5,000 万美元。",
        "tw": "攻擊者先控制多簽成員終端，再篡改 Safe Wallet 前端顯示與實際交易載荷，誘導簽署惡意交易並取得協議管理員權限。攻擊隨後同時影響 Arbitrum 與 BNB Chain 市場，公開披露損失約 5,000 萬美元。",
        "en": "Attackers compromised multisig operators' endpoints and altered the Safe Wallet interface and underlying transaction payloads, inducing malicious signatures and obtaining protocol administrator privileges. The attack affected markets on both Arbitrum and BNB Chain, with about $50 million publicly reported lost."
      },
      "category": "key-compromise",
      "severity": "critical",
      "ecosystems": [
        "Arbitrum",
        "BNB Chain"
      ],
      "chains": [
        "Arbitrum",
        "BNB Chain"
      ],
      "lossUsd": 50000000,
      "frozenUsd": 0,
      "recoveredUsd": 0,
      "addressDisclosure": "not-published",
      "addresses": [],
      "references": [
        {
          "label": {
            "zh": "公开事件复盘",
            "tw": "公開事件復盤",
            "en": "Public incident post-mortem"
          },
          "url": "https://mp.weixin.qq.com/s/Jwd8u4dnPORcB1uDECxx8g",
          "type": "analysis"
        }
      ],
      "sourceUrl": "press-radiant-capital-end",
      "sourceLabel": "德尔泰公开事件分析"
    }
  ]
}
