3Commas lees tias Nws yog qhov chaw ntawm API Leak uas ua rau Hacks

Ib pawg tub luam lub lim tiam dhau los tau hais tias $ 22 lab tus nqi ntawm crypto tau raug nyiag lawm los ntawm kev cuam tshuam API yuam sij los ntawm kev lag luam platform 3Commas. Hnub Wednesday, 3Commas tau lees paub tias nws yog lub hauv paus ntawm API xau.

Cov lus tshaj tawm tuaj tom qab tus neeg siv Twitter tsis qhia npe tau txais ib ncig ntawm 100,000 API yuam sij uas yog 3Commas cov neeg siv thiab luam tawm hauv online. 

3Commas thawj zaug tau hais tias tsis muaj teeb meem kev nyab xeeb ntawm nws qhov kawg, thiab co-founder Yuriy Sorokin rov hais dua hauv Twitter tias kev tawm tsam phishing ua rau cov neeg siv tso lawv cov ntaub ntawv. 

Tab sis hnub Wednesday, Sorokin tweeted: "Peb pom tus neeg nyiag nkas cov lus thiab tuaj yeem lees paub tias cov ntaub ntawv hauv cov ntaub ntawv muaj tseeb ... Peb thov txim tias qhov no tau dhau los txog tam sim no thiab yuav txuas ntxiv pob tshab hauv peb cov kev sib txuas lus nyob ib puag ncig qhov xwm txheej."

3Commas yog lub platform uas tso cai rau cov neeg siv txuas ntau yam crypto pauv nyiaj-xws li cov khaws cia ntawm Binance-rau kev ua lag luam software. Qhov no yog txhua yam ua tiav ntawm APIs (application programming interfaces), cov txheej txheem txheej txheem uas tso cai rau cov software cais sib txuas lus nrog ib leeg thiab ua haujlwm. Lub tswv yim yog tias tib neeg tsis tas yuav ua haujlwm nyuaj ntawm kev xav txog lawv cov lag luam. Hloov chaw, txhua yam ua tiav tam sim ntawd thiab tau txais los ntawm code. 

Txog thaum cov neeg tsis ncaj ncees tau nkag mus rau APIs.

Blockchain swb @ZachXBT yav dhau los tau hais hauv Twitter tias nws tau txheeb xyuas ib pawg ntawm 44 tus neeg raug tsim txom uas poob tag nrho $ 14.8 lab los ntawm API yuam sij nyiag los ntawm 3Commas.

Hauv kev teb, Sorokin tweeted tias "Yog tias koj yog ib tus neeg raug tsim txom, ces nws txhais tau tias qee yam koj cov yuam sij tau xau," tab sis "tsis yog los ntawm 3Commas." Yog tias cov yuam sij API xau tau los ntawm 3Commas, "koj yuav tau pom ntau lab tus neeg mob, tsis yog ib puas," nws xav.

Nyob rau hauv ib tug cais xov, nws tau thuam "kev tsis muaj peev xwm los ntawm cov xov xwm loj" thiab nug txog qhov siv tau ntawm cov neeg coob coob ntawm cov ntaub ntawv tsis txaus ntseeg. "Mus saib xyuas tias feem ntau ntawm cov neeg siv qhia txog kev poob tsis txawm qhib daim pib txhawb nqa nrog kev sib pauv, thiab tsis mus rau tub ceev xwm," Sorokin tweeted. "Cov ntaub ntawv no tau txheeb xyuas li cas?"

Dua nws khavtheeb tias muaj ob peb qhov xwm txheej rau nws tau ua 3Commas siv. "Muaj ntau dua 1 [lab] yuam sij txuas nrog 3Commas, nrog ~ 100 cov neeg siv qhia txog teeb meem nrog lawv cov nyiaj," Sorokin tweeted. "Vim li cas qhov ntawd yuav tshwm sim yog tias [database] leaked?"

Niaj hnub no, qhov tseeb ZachXBT tweeted tias "rau lub lis piam [3Commas] tau liam nws cov neeg siv thiab lees txais xoom lub luag haujlwm." 

"Koj tau dag thiab hais tias qhov no yog peb qhov txhaum es tsis txhob ua lub luag haujlwm thiab tiv thaiv kev ua phem ntxiv," ntxiv @CoinMamba, lwm tus neeg siv 3Commas uas hais tias nws poob nyiaj. "Koj puas yuav rov qab cov neeg siv tam sim no?"

Qhov no tsis yog thawj zaug 3Commas thiab nws cov API tuav tau raug tshuaj xyuas. Txog ib hlis ua ntej FTX tau foob rau kev lag luam, Sam Bankman-Fried tau pom zoo rov qab $ 6 lab rau cov neeg siv khoom cuam tshuam los ntawm qhov tau piav qhia tias yog phishing kws txuj ci dag koom nrog 3 Commas.

Hnub Wednesday, Binance CEO Changpeng Zhao tau tshaj tawm tias nws tau "tsim nyog paub tseeb" muaj "qhov tseem ceeb API nthuav dav" los ntawm 3Commas. 

CZ ntxiv tias cov neeg siv yuav tsum lov tes taw API cov yuam sij hauv 3Commas. Nov yog qhov 3Commas tam sim no pom zoo ib yam.

"Raws li kev nqis tes ua tam sim ntawd, peb tau nug tias Binance, Kucoin, thiab lwm yam kev sib pauv txhawb nqa tshem tawm txhua tus yuam sij uas txuas nrog 3Commas," Sorokin tweeted.

3Commas tsis tau teb rau qhov kev thov rau kev tawm tswv yim ntxiv los ntawm Decrypt.

Nyob rau saum cov xov xwm crypto, tau txais kev hloov tshiab txhua hnub hauv koj lub inbox.

Tau qhov twg los: https://decrypt.co/118094/after-repeated-denials-3commas-admits-it-was-source-for-earlier-hacks