当前位置:首页 > 报告详情

2中国演讲.pdf

上传人: 张** 编号:620869 2025-03-31 19页 2.44MB

1、Stop Spoofing My Wallet!Demystifying Simulation Spoofing Attacks2025/01/11slipperStop Spoofing My Wallet!Stop Spoofing My Wallet!Stop Spoofing My Wallet!The Growing Threat to Solana WalletsGrowing Threat to Solana WalletsGrowing Threat to Solana Wallets Surge in phishing attacks targeting Solana use

2、rs.Attacks bypass even secure wallet protections.Users unknowingly authorize malicious activities.What Happens Behind the Scenes?Growing Threat to Solana WalletsGrowing Threat to Solana Wallets Wallet interactions have hidden complexities.A simple Sign can authorize dangerous activities.Example:Fake

3、 Jupiter swap drains user accounts.Drainer Alert:A Series of Sophisticated Attacks Solana users using Phantom wallet on Chrome with Windows.Jupiter,Raydium,and others.Not widespread but highly effective.Random victims,not targeting whales.Triggered by user interactions.Drainer Alert:A Series of Soph

4、isticated AttacksSolana users using Phantom wallet on Chrome with Windows.Solana users using Phantom wallet on Chrome with Windows.How the Attack WorksWhat Happens Behind the Scenes?Transactions:Understanding the Complexity1.Signatures:Cryptographically prove authorization for the transaction.2.Mess

5、age:Core content of the transaction,containing:Header/Account Addresses/Recent Blockhash/InstructionsKey Components ofa Solana TransactionUnderstanding the Complexity of Solana TransactionsWhat Happens Behind the Scenes?Transactions:Understanding the ComplexityFetch token price and determine the bes

6、t route.Assemble transaction instructions and send to wallet.Wallet simulates,user approves,and transaction is signed&broadcasted.Token Swap Process on Jupiter:What Happens Behind the Scenes?Transactions:Understanding the ComplexitySigning grants full authority over accounts in the transaction.Can e

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要揭示了Solana钱包模拟攻击的威胁,这种攻击通过恶意扩展如"Bull Checker"来拦截和修改钱包适配器功能,使得用户在不知情的情况下授权恶意操作。攻击利用了Solana交易中隐藏的复杂性,例如一个简单的"Sign"操作可能就会授权危险活动。文章指出,尽管这种攻击尚未广泛传播,但非常有效,它针对随机受害者,而非大额资金持有者,并通过用户互动触发。攻击者利用签名技术绕过安全保护,执行如模拟交易等操作,用户需仔细审查交易以避免上当。研究还发现,即使使用了先进的交易扫描工具,如Phantom和Blowfish,也可能因为模拟失败而无法保护用户。为了安全起见,建议用户在签名前总是审查交易,并在使用工具和扩展前进行验证。
"Solana钱包模拟攻击如何运作?" "如何防范Solana钱包的钓鱼攻击?" "Solana智能合约中的恶意代码是如何隐藏的?"
客服
商务合作
小程序
服务号
折叠