Digital Asset Database Digital asset research & education
BTC$77,075-0.17% ETH$2,383-1.07% USDT$0.9997+0.01% BNB$687.13+0.40% XRP$1.34+0.16% USDC$0.9999+0.00% SOL$99.69-0.03% TRX$0.3247+0.84% FIGR_HELOC$1.01-3.13% HYPE$81.56-1.52% ZEC$809.97-2.04% DOGE$0.0814+0.13% RAIN$0.0167-3.19% USDS$0.9999+0.00% XMR$502.73-0.42% LEO$9.24-1.53% WBT$70.61-0.57% LINK$11.04-1.11% ADA$0.2008+2.26% XLM$0.1756+0.44% BCH$243.11-1.01% DAI$1.0000+0.00% CC$0.1089-4.11% USDE$0.9995+0.00% USD1$0.9993+0.00% LTC$49.72+1.08% GRAM$1.33+1.04% UNI$5.81-0.80% HBAR$0.0747+1.57% USDG$1.00+0.02% AVAX$7.16-0.28% SHIB$0.00000518+0.90%
菜单
首页
资产 全部资产板块排名Heat map筛选器对比资产★ Saved
基本面 Fees & revenue锁定价值Exchange volume网络活动StablecoinsStaking & yield
估值 估值比率Supply & issuance指标定义
机构 交易所交易产品企业资产负债表
研究 研究笔记事件日历风险框架安全事件
学习 Learn library术语表计算工具方法论数据来源数据新鲜度AI agents公开 API
资讯 查询数据 全球市场 关于我们
阅读选项
Photography CryptoStudio
引导视图

市场新手——价格、收益率、market cap?我们在您浏览时逐一解释每个术语,语言简明直白。数据相同,内置辅助说明。

专家观点

您已了解市场。仅呈现数据——简洁、快速、紧凑,无多余说明。此为默认视图。

浅色或深色
语言
公开 API

本站所有数据均可通过 JSON 获取,并附带期间与来源信息。

阅读 API 文档
Counterparty 风险 all

Phishing and Social Engineering

Attackers take assets by persuading holders to sign a transaction or reveal a secret, without breaking any cryptography or contract.

运作方式

The most common losses require no technical exploit at all. Token approval drainers ask a user to sign a message granting a contract permission to move their balances, which looks routine and is often signed blind because wallets display raw calldata rather than an outcome. Delivery methods are ordinary: a hijacked domain or a paid search result pointing at a cloned front end, a compromised front-end dependency serving malicious code from a legitimate address, a support impersonator in a chat channel, an airdropped token whose sale requires an approval, or an address-poisoning transfer designed to plant a lookalike address in the transaction history. Where accounts are protected by text-message codes, a carrier account takeover defeats the second factor entirely.

实际可观测的内容

Review outstanding token approvals with an allowance viewer, since standing approvals are the main mechanism and are visible on-chain. Check whether the wallet decodes calldata into a plain-language action and whether the project pins its front end to a content hash or serves it from a decentralized host. Domain hijacks, dependency compromises, and support-impersonation waves are usually documented publicly by the projects affected.

先例

A 2020 breach of customer records at hardware wallet maker Ledger was followed by a sustained phishing campaign against the exposed customers, and separate domain and front-end hijacks have redirected users of several protocols to malicious sites while the underlying contracts were untouched.

哪些因素使其更重要或更不重要

Consider how many standing approvals exist and how broad they are, whether signing requests are human-readable, whether the front end is pinned or hosted conventionally, and whether any account still relies on text-message codes.

01

相关因素

Smart Contract Defect Technical A flaw in deployed contract code lets funds be moved, locked, or destroyed in ways the designers never…
Admin Keys and Multisig Control Governance A small set of keys can pause, upgrade, mint, or move assets, so the system's safety depends on those…
Custodian Single Point of Failure Counterparty One custodian, one signing arrangement, or one operations team stands between holders and their assets, so a…
Key Management and Personal Loss Counterparty Self-custody puts the holder in charge of a secret that cannot be reset, so losing it or destroying the only…

资产

全部资产板块排名Heat map筛选器对比已保存

基本面

Fees & revenue锁定价值Exchange volume网络活动StablecoinsStaking & yield

Valuation & risk

估值比率Supply & issuance指标定义风险框架安全事件

机构

交易所交易产品企业资产负债表Events研究笔记资讯

学习

Learn library术语表计算工具查询数据AI agents公开 API

关于

关于我们联系方法论数据来源编辑政策数据新鲜度

法律

免责声明使用条款Privacy policy