Steakhouse Financial Front-End Breach Exposes Users to Phishing Scam

Steakhouse Financial Front-End Breach Exposes Users to Phishing Scam

N
News Editor 01
2026-07-05 15:36:12
DeFi risk platform Steakhouse Financial's website and app were hacked to host a phishing scam. The firm confirms deposits and contracts are safe but warns users to avoid interaction. Attackers used Angel Drainer code, similar to a recent GAIB incident.

据最新报道,DeFi风险管理者Steakhouse Financial于7月5日遭遇黑客攻击,其官方网站和移动应用被恶意篡改,目前正被用于传播钓鱼诈骗。该公司在周一早间披露了这一安全事件,并警告称,任何新用户与之交互都可能接触到由黑客部署的恶意版本。

攻击细节与官方回应

Steakhouse表示,此次攻击仅影响了前端操作,并未波及核心智能合约。公司明确保证:“没有存款面临风险,没有合约受到影响,所有Steakhouse存款人都是安全的。” 联合创始人Sébastien Derivaux在社交媒体上呼吁加密用户“在进一步通知前避免访问该网站”。目前,Steakhouse团队正在全力恢复前端服务,但截至发稿时,公司或CEO均未提供进一步的更新信息。

多个加密项目已向受影响客户提供替代服务和安全保障。与此同时,社区中不乏调侃之声,有用户戏谑道:“在Steakhouse上搞钓鱼,这是否算‘海滩攻击’(surf and turf attack)?”

攻击者使用“Angel Drainer”窃取钱包

加密安全公司Blockaid经过分析发现,Steakhouse攻击者使用了名为Angelferno(又称Angel Drainer)的代码——这是目前链上“最大的活跃钱包窃取器操作”之一。这类钱包窃取器的工作原理是:一旦用户签署恶意交易,黑客便获得对用户账户的完全控制权,从而盗走加密资产。

值得注意的是,本月早些时候,AI加密公司GAIB也曾遭遇社会工程攻击,黑客获取其域名访问权限并部署了包含Angelferno的假冒网站。Blockaid当时协助GAIB检测到该恶意软件,约7小时后恶意站点被清除,且未造成用户损失。

市场影响与行业警示

此类前端攻击再次凸显了DeFi生态中“信任层”的脆弱性。虽然Steakhouse强调存款安全,但用户信任已受到严重打击——前端被篡改意味着用户即使访问正确域名,也可能遭遇钓鱼钓鱼页面。短期来看,Steakhouse代币(如有)和相关协议TVL可能承压;长期来看,事件将推动行业对前端安全审计、DNS防护和域名锁定机制的更高要求。

此外,Angel Drainer这类商业化恶意工具的广泛传播,表明黑客正将钓鱼即服务(Phishing-as-a-Service)模式引入加密世界。Blockaid指出,类似代码已在多个项目中复用,体现出“低门槛攻击”的常态化趋势。

后续展望

Steakhouse Financial作为DeFi领域的知名风控平台,此次事件可能促使更多项目方重新评估其前端供应链安全。用户也应提高警惕,避免在未验证的状态下签署任何交易或授权。预计随着调查深入,更多关于攻击源头和损失规模的细节将陆续公布。

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.