🎉 Gate Square Growth Points Summer Lucky Draw Round 1️⃣ 2️⃣ Is Live!
🎁 Prize pool over $10,000! Win Huawei Mate Tri-fold Phone, F1 Red Bull Racing Car Model, exclusive Gate merch, popular tokens & more!
Try your luck now 👉 https://www.gate.com/activities/pointprize?now_period=12
How to earn Growth Points fast?
1️⃣ Go to [Square], tap the icon next to your avatar to enter [Community Center]
2️⃣ Complete daily tasks like posting, commenting, liking, and chatting to earn points
100% chance to win — prizes guaranteed! Come and draw now!
Event ends: August 9, 16:00 UTC
More details: https://www
Analysis of the Poly Network Hacker Attack Incident: Keeper was tampered with, resulting in fund loss.
Analysis of the Poly Network Hacker Attack Incident
Recently, the cross-chain interoperability protocol Poly Network was attacked by a Hacker, which has attracted widespread attention. According to the security team's analysis, this attack was not due to the leakage of the keeper's private key, but rather the attacker modified the keeper of the EthCrossChainData contract to a designated address through carefully crafted data.
Attack Core
The key to the attack lies in the verifyHeaderAndExecuteTx function of the EthCrossChainManager contract. This function can execute specific cross-chain transactions through the _executeCrossChainTx function. Since the ownership of the EthCrossChainData contract belongs to the EthCrossChainManager contract, the latter can call the putCurEpochConPubKeyBytes function of the former to modify the contract's keeper.
Attack Process
Attack Impact
Event Insights
This incident highlights the importance of blockchain security once again, especially in complex cross-chain scenarios. Development teams need to continuously improve security measures to respond to increasingly sophisticated attack methods. At the same time, users should also enhance their security awareness and participate cautiously in various blockchain projects.