paint-brush
Ngaba i-ByBit iluthintele uHack? Ewe-Nantsi Njaninge@thebojda
190 ukufunda Imbali entsha

Ngaba i-ByBit iluthintele uHack? Ewe-Nantsi Njani

nge Laszlo Fazekas4m2025/03/02
Read on Terminal Reader

Inde kakhulu; Ukufunda

Uhlaselo lwe-ByBit, olwenziwe yiNorth Korean Lazaro Group, luxhaphaze i-UI ye-wallet ekhuselekile, ekhokelela ekubiweni kwe-1,5 yeebhiliyoni zeedola. Ukwaphulwa kugxininisa imfuneko yamanyathelo okhuseleko anamandla, afana ne-Web3 UIs engaguqukiyo, ukuphicothwa kwentengiselwano yangaphandle, izixhobo zokusayina ezizinikeleyo, kunye nokusetyenziswa okungcono kweemodyuli zeSafe kunye nabalindi. Nangona kungekho nkqubo ingonakali, ezi zilumkiso zinokunciphisa kakhulu iingozi kwaye zithintele uhlaselo olufanayo kwixesha elizayo.
featured image - Ngaba i-ByBit iluthintele uHack? Ewe-Nantsi Njani
Laszlo Fazekas HackerNoon profile picture
0-item

Ndiyazi ukuba wonke umntu uthetha ngohlaselo lwe-ByBit, kwaye oku mhlawumbi inqaku lekhulu olifundileyo ngesihloko, kodwa ndicinga ukuba kufanelekile ukwabelana ngeengcinga ezimbalwa kulo.

Kweneke ntoni?

Ngamafutshane, iNorth Korean uLazaro Group ikwazile ukuba i-1.5 yeebhiliyoni zeedola kwi-wallet ebandayo ye-ByBit. I-wallet ebandayo yayiyi- Wallet ye-multisig ekhuselekileyo , kwaye intengiselwano yasayinwa ngawo onke amaqela agunyazisiweyo ukususela, ukusuka kujongano lomsebenzisi, kubonakala ngathi yintengiselwano esemthethweni ngokupheleleyo.


Kamva kwavela ukuba i-UI eKhuselekileyo ithotyiwe. Abahlaseli bafumana iziqinisekiso ze-AWS S3 kumatshini womphuhlisi, owabavumela ukuba baguqule i-UI.


Libali ngokufutshane elo. Andiqondi ukuba ukukhomba iminwe okanye ukubeka ityala kuluncedo kakhulu. Endaweni yoko, kunengqiqo ngakumbi ukugxila kwizinto eziphambili zokuthatha kunye nendlela obu buchwepheshe bunokukhuseleka ngayo ngakumbi.


Ndiyaqonda ukuba ukujonga ngasemva kuhlala kungama-20/20, kwaye andibangi ukuba ngendenze ngcono. Iqela eliKhuselekileyo lenza umsebenzi ogqwesileyo, kwaye yonke into endiza kuyixoxa apha ichaphazela amacandelo angaphandle kweSafe ngokwayo (i-smart contract-based multisig wallet).


Ndabhala iingcinga zam emva kwesiganeko. Kweli nqaku, ndingathanda ukucacisa ngakumbi ngazo.

Iimodyuli kunye nabalindi

Enye yezona zinto zibalaseleyo kwi-wallet ekhuselekileyo kukuba amandla ayo anokwandiswa ngokusebenzisa iimodyuli kunye nonogada . Iimodyuli zongeza imisebenzi emitsha kwi-wallet, ngelixa abalindi benza iitshekhi phambi kokuba kuqhutywe intengiselwano. Ezi mpawu zenza i-wallet ibe yinto enokwenzeka kakhulu kwaye iphucula kakhulu ukhuseleko lwayo.


Umzekelo, kuyenzeka ukuba uthintele i-wallet ukuvumela kuphela i-ERC-20 transactions (kule meko, intengiselwano enobungozi yenziwe ngokufowunelwa delegatecall ). Kwakhona kulula ukuphumeza umgaqo ofuna iisignesha ezongezelelweyo zentengiselwano ngaphezu komda othile-ezifana nendlela iibhanki ezivumela ngayo abasebenzisi ukuba babeke imida yeentengiselwano zexabiso eliphezulu.


Nkqu nokusetyenziswa ngokufanelekileyo kweli nqaku elinye kunokuthintela uhlaselo oluninzi okanye ubuncinane kunciphise ilahleko enokubakho.

I-UI engaguqukiyo

Yonke inkqubo yomelele njengeyona nxalenye yayo ibuthathaka. Kule meko, ikhonkco elibuthathaka yayingengomphuhlisi ogama lakhe le-S3 libiwe-yayiyinto enzulu kakhulu. Kungakhathaliseki ukuba iteknoloji ye-Web3 ikhuselekile kangakanani (i-blockchain kunye nezivumelwano ezihlakaniphile), ukuba i-UI ye-Web2-based isengozini, yonke inkqubo ihlala isengozini.


Isisombululo esicacileyo kukusebenzisa i-Web3 UI engaguqukiyo. Ubuchwephesha obufana ne-IPFS, i-Ethereum Swarm, okanye ezinye izisombululo zokugcina iWeb3 zinokubonelela oku. Ukuphunyezwa okulula kukugcina i-hash yomxholo we-UI njengento eguquguqukayo rhoqo kwikhontrakthi ehlakaniphile, ukuqinisekisa ukuba naluphi na utshintsho lwe-UI lufuna ukuguqulwa kwekhontrakthi ehlakaniphile ngokwayo.


Le ndlela ibophelela ngokupheleleyo i-UI kwikhontrakthi ehlakaniphile, eyenza kube nzima ukuguqula ujongano ngaphandle kokuqala ngokugqekeza ikhontrakthi ngokwayo. Ngesi sisombululo silula, uhlaselo olusekwe kwi-UI lunokuthintelwa ngokufanelekileyo.

Isixhobo esahlukileyo

Nokuba ikhontrakthi ye-smart ikhuselekile kwaye i-UI ayinakuguqulwa, inkqubo ihlala isesichengeni ukuba izixhobo zabasayini zinokuchaphazeleka. Ukuba umhlaseli ufumana ukufikelela kwisixhobo somsayini, usenokuyibuyisela i-UI kwicala lomxhasi.


Ngenxa yesi sizathu, nabani na ophethe imali eninzi kwi-wallet ebandayo kufuneka asebenzise isixhobo esizinikezeleyo-umzekelo, i-iPad-kuphela ukusayina ukuthengiselana. Esi sixhobo kufuneka sisebenzise le njongo kuphela: akukho zi-aplikeshini zingenye ezifakiweyo, akukho imeyile okanye ukhangelo lwewebhu, kuphela imeko-bume eyimfuneko yokusayina iitransekshini.


Ukuba umntu ulawula iibhiliyoni zeedola, ukuchitha amakhulu ambalwa eedola kwisixhobo sokusayina esizinikeleyo asiyondleko ibalulekileyo.

I-Oracle yoPhicotho lweNtengiselwano yaNgaphandle

Umphicothi-zincwadi wangaphandle unokongezwa kwi-wallet njengomsayini owongezelelweyo, imodyuli, okanye umlindi wokuphonononga ukuthengiselana kwaye ubathintele ukuba babonakala bekrokrela. Ukufumanisa ezo ntengiselwano ezikrokrelekayo kunokwenziwa kusetyenziswa iipatheni ezilula ngokwentelekiso—ngokomzekelo, ukuhambisa isixa-mali esikhulu ngokungaqhelekanga okanye ukuthumela abathunywa.


Kwimeko yentengiselwano ekrokrisayo, inkqubo yophicotho-zincwadi lwangaphandle inokwazisa abasayinileyo, ibashukumisele ukuba baphonononge itransekshini ngesandla. Ukuba basayibona isemthethweni, banokuphinda bayisayine njengesiqinisekiso, bongeza umaleko owongezelelweyo wokhuseleko.

Ukuqukumbela

Akukho nto ifana nenkqubo engenakophuka, kodwa izisombululo ezilula ezichazwe ngasentla zingenza uhlaselo lube nzima kakhulu. Ukuba kukho umntu olawula iibhiliyoni zeerandi, kufanelekile ukutyala ixesha kunye neenzame zokuphumeza ezi ndlela zokhuseleko zithe ngqo.


Andinakugxininisa ngokwaneleyo ukuba zonke ezi zisombululo zakhela phezu kolwakhiwo oluqaqambileyo lweSafe, kunye neempawu ezinjengeemodyuli kunye noonogada.


Njengoko intetho isitsho, into engakubulaliyo ikwenza womelele. Kwaye namhlanje, iSafe yomelele kunangaphambili!