{"id":67205,"date":"2021-12-20T11:43:00","date_gmt":"2021-12-20T11:43:00","guid":{"rendered":"https:\/\/fr.cryptonews.com\/?p=67205"},"modified":"2023-06-26T11:08:14","modified_gmt":"2023-06-26T11:08:14","slug":"hacked-grim-finances-auditors-blame-new-analyst-for-missing-issue-fr","status":"publish","type":"post","link":"https:\/\/cryptonews.com\/fr\/news\/hacked-grim-finances-auditors-blame-new-analyst-for-missing-issue-fr\/","title":{"rendered":"Le piratage de Grim serait d\u00fb \u00e0 la n\u00e9gligence d&#8217;un analyste"},"content":{"rendered":"<p>Ce dimanche, la plateforme de finance d&eacute;centralis&eacute;e (DeFi) <strong>Grim Finance<\/strong> a &eacute;t&eacute; victime d&rsquo;un exploit dont les dommages s&rsquo;&eacute;l&egrave;veraient &agrave; 30 millions de dollars d&#8217;actifs num&eacute;riques. Les responsables estiment que la faille aurait &eacute;chapp&eacute; aux analystes ayant effectu&eacute; l&#8217;audit du protocole alors que leur directeur technique (CTO) &eacute;tait en vacances.<\/p><figure class=\"image\"><img decoding=\"async\" src=\"https:\/\/cimg.co\/news\/67199\/49764\/adobestock-rawpixelcom-1-1.jpg\" alt=\"\" width=\"1200\" class=\"content-img\"><figcaption>Source: AdobeStock Rawpixelcom<\/figcaption><\/figure><p>Le 19 d&eacute;cembre, Grim Finance a inform&eacute; les utilisateurs que le projet avait &eacute;t&eacute; exploit&eacute; par un pirate externe. &#8220;Le pirate a attaqu&eacute; en utilisant la fonction intitul&eacute;e beforeDeposit() en entrant un contrat de jeton malveillant&#8221;, a indiqu&eacute; l&#8217;&eacute;quipe.<\/p><figure class=\"media\"><oembed url=\"https:\/\/twitter.com\/financegrim\/status\/1472357770846519312\"><\/oembed><\/figure><p>Il y a environ quatre mois, Grim Finance avait fait l&rsquo;objet d&rsquo;une inspection par <strong>Solidity Finance<\/strong>, un service d&#8217;audit de contrats intelligents. Les auditeurs ont d&eacute;clar&eacute; que le probl&egrave;me avait &eacute;chapp&eacute; &agrave; leur processus, en raison du nombre important de projets alors en cours et de l&#8217;int&eacute;gration de nouveaux analystes.<\/p><blockquote><p>&#8220;Lors de la r&eacute;alisation de l&#8217;audit de Grim Finance il y a 4 mois, notre entreprise connaissait une croissance rapide. Cet audit a &eacute;t&eacute; r&eacute;alis&eacute; par un analyste nouvellement embauch&eacute; alors que notre CTO &eacute;tait en vacances ; et malheureusement ce probl&egrave;me n&#8217;a pas &eacute;t&eacute; d&eacute;tect&eacute; au cours du processus d&#8217;examen par les pairs&#8221;, a <a target=\"_blank\" rel=\"noopener \" href=\"https:\/\/twitter.com\/SolidityFinance\/status\/1472614856629051402\">d&eacute;clar&eacute;<\/a> Solidity Finance.<\/p><\/blockquote><p>Selon <strong>Rugdoc.io<\/strong>, un organisme de surveillance de DeFi, le pirate de Grim Finance a utilis&eacute; une attaque de type &#8220;reentrancy&#8221;, en simulant des d&eacute;p&ocirc;ts suppl&eacute;mentaires dans un coffre-fort alors qu&#8217;une transaction initiale &eacute;tait toujours en cours. De cette fa&ccedil;on, ils ont r&eacute;ussi &agrave; retirer plus de fonds qu&#8217;ils n&#8217;en avaient r&eacute;ellement d&eacute;pos&eacute;s dans le coffre-fort.<\/p><figure class=\"media\"><oembed url=\"https:\/\/twitter.com\/RugDocIO\/status\/1472293720594821124\"><\/oembed><\/figure><p>Rugdoc.io a &eacute;galement critiqu&eacute; Grim Finance pour la faiblesse de ses mesures de s&eacute;curit&eacute;, sugg&eacute;rant que le projet aurait d&ucirc; utiliser une protection contre la &ldquo;reentrancy&rdquo;, qui peut emp&ecirc;cher l&#8217;ex&eacute;cution de plus d&#8217;une fonction &agrave; la fois en verrouillant le contrat.<\/p><blockquote><p>&#8220;Esp&eacute;rons que tous les projets peuvent tirer des le&ccedil;ons de cet incident. Il y a beaucoup de connaissances que la plupart des developpeurs solidity exp&eacute;riment&eacute;s ont &agrave; port&eacute;e de main&#8221;, a <a target=\"_blank\" rel=\"noopener \" href=\"https:\/\/twitter.com\/RugDocIO\/status\/1472293712185151492\">tweet&eacute;<\/a> Rugdoc.io. &#8220;Si vous n&#8217;avez pas encore acquis ces comp&eacute;tences, ne construisez pas de projets &agrave; plusieurs millions de dollars. Ne vous faites pas auditer par des entreprises dont tout le monde sait qu&#8217;elles ne servent &agrave; rien. &#8220;<\/p><\/blockquote><p>Suite au piratage, l&#8217;&eacute;quipe de Grim Finance a d&eacute;clar&eacute; que les coffres ont &eacute;t&eacute; temporairement suspendus &#8220;pour &eacute;viter que les fonds futurs ne soient mis en danger&#8221; et a recommand&eacute; aux utilisateurs de retirer leurs fonds car tous les coffres et les fonds d&eacute;pos&eacute;s sont actuellement en danger.<\/p><p>&#8220;Nous avons contact&eacute; et notifi&eacute; <strong>Circle<\/strong> (USDC), <strong>DAI<\/strong> et <strong>AnySwap<\/strong> concernant l&#8217;adresse de l&#8217;attaquant pour potentiellement geler tout autre transfert de fonds&#8221;, a d&eacute;clar&eacute; l&#8217;&eacute;quipe.<\/p><p>Le jeton natif du projet, GRIM, a plong&eacute; de 81,2% aux premi&egrave;res heures du piratage, passant de pr&egrave;s de 0,8 USD &agrave; 0,15 USD, selon CoinGecko. Il est en hausse de 3,3 % sur les derni&egrave;res 24 heures et en baisse de 55 % sur la derni&egrave;re semaine, s&#8217;&eacute;changeant &agrave; 0,25 USD.<\/p><p>_______________________<\/p><p>Suivez nos liens d&#8217;affili&eacute;s:<\/p><p><strong>Pour acheter des cryptomonnaies en Zone SEPA, Europe et citoyens fran&ccedil;ais<\/strong>, visitez <a target=\"_blank\" rel=\"noopener \" href=\"https:\/\/www.coinhouse.com\/r\/179207\">Coinhouse<\/a>&nbsp;<\/p><p><strong>Pour acheter des cryptomonnaies au Canada<\/strong>, visitez <a target=\"_blank\" rel=\"noopener \" href=\"https:\/\/go.bitbuy.tech\/aff_c?offer_id=3&amp;aff_id=1009&amp;source=FR\">Bitbuy<\/a><\/p><p><strong>Pour g&eacute;n&eacute;rer des int&eacute;r&ecirc;ts gr&acirc;ce &agrave; vos bitcoins<\/strong>, allez sur le site de <a target=\"_blank\" rel=\"noopener \" href=\"https:\/\/blockfi.mxuy67.net\/kqG6x\">BlockFi<\/a><\/p><p><strong>Pour s&eacute;curiser ou stocker vos cryptomonnaies<\/strong>, procurez-vous les portefeuilles <a target=\"_blank\" rel=\"noopener \" href=\"https:\/\/shop.ledger.com\/?r=12b53b98a1c0&amp;tracker=CN-FR\">Ledger<\/a> ou <a target=\"_blank\" rel=\"noopener \" href=\"https:\/\/shop.trezor.io\/?offer_id=82&amp;aff_id=1814\">Trezor<\/a><\/p><p><strong>Pour transiger vos cryptos de fa&ccedil;on anonyme<\/strong>, installez l&#8217;application <a target=\"_blank\" rel=\"noopener \" href=\"https:\/\/go.nordvpn.net\/aff_c?offer_id=252&amp;aff_id=54152&amp;url_id=14818\">NordVPN<\/a><\/p><p><strong>Pour investir dans le minage ou les masternodes :<\/strong><\/p><ul><li>Sur <a target=\"_blank\" rel=\"noopener \" href=\"https:\/\/feel-mining.com\/?tracking=1ED831AFAB\">Feel Mining<\/a><\/li><li>Sur <a target=\"_blank\" rel=\"noopener \" href=\"https:\/\/www.just-mining.com\/register?sponsor=aNJ7nRa0m3qvgi6LkMXAZX506\">Just Mining<\/a><\/li><\/ul><p><strong>Pour accumuler des cryptos en jouant :<\/strong><\/p><ul><li>Au poker sur la plateforme de jeux <a target=\"_blank\" rel=\"noopener \" href=\"https:\/\/coinpoker.com\/crypto\">CoinPoker<\/a><\/li><li>&Agrave; un fantasy football mondial sur la plateforme <a target=\"_blank\" rel=\"noopener \" href=\"https:\/\/sorare.pxf.io\/c\/2102999\/902742\/12209\">Sorare<\/a><\/li><\/ul><p>________________<\/p><p>Voici les sources d&rsquo;informations qu&rsquo;on vous propose:<\/p><p><strong>Notre newsletter hebdomadaire gratuite: <\/strong><a target=\"_blank\" rel=\"noopener \" href=\"https:\/\/www.getrevue.co\/profile\/CryptonewsFR\"><strong>https:\/\/www.getrevue.co\/profile\/CryptonewsFR<\/strong><\/a><\/p><p><strong>Twitter: <\/strong><a target=\"_blank\" rel=\"noopener \" href=\"https:\/\/twitter.com\/cryptonews_FR\"><strong>https:\/\/twitter.com\/cryptonews_FR<\/strong><\/a><\/p><p><strong>Telegram: <\/strong><a target=\"_blank\" rel=\"noopener \" href=\"https:\/\/t.me\/cryptonews_FR\"><strong>https:\/\/t.me\/cryptonews_FR<\/strong><\/a><\/p><p><strong>LinkedIn: <\/strong><a target=\"_blank\" rel=\"noopener \" href=\"https:\/\/www.linkedin.com\/company\/11745115\"><strong>https:\/\/www.linkedin.com\/company\/11745115<\/strong><\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>Ce dimanche, la plateforme de finance d&eacute;centralis&eacute;e (DeFi) Grim Finance a &eacute;t&eacute; victime d&rsquo;un exploit dont les dommages s&rsquo;&eacute;l&egrave;veraient &agrave; 30 millions de dollars d&#8217;actifs num&eacute;riques. Les responsables estiment que la faille aurait &eacute;chapp&eacute; aux analystes ayant effectu&eacute; l&#8217;audit du protocole alors que leur directeur technique (CTO) &eacute;tait en vacances.Source: AdobeStock RawpixelcomLe 19 d&eacute;cembre, Grim [&hellip;]<\/p>\n","protected":false},"author":35,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[10,1],"tags":[70,266,48],"editors":[2550],"sponsored_companies":[],"class_list":["post-67205","post","type-post","status-publish","format-standard","hentry","category-defi-news","category-news","tag-altcoins","tag-defi","tag-piratage","editors-jurgen-hoffman"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Le service d&#039;audit Solidity Finance bl\u00e2m\u00e9 pour l&#039;attaque sur le protocole DeFi Grim<\/title>\n<meta name=\"description\" content=\"Le piratage de Grim Finance aurait son origine dans une vuln\u00e9rabilit\u00e9 dans un contrat intelligent qui aurait \u00e9chapp\u00e9 au service d&#039;audit Solidity Finance.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cryptonews.com\/fr\/news\/hacked-grim-finances-auditors-blame-new-analyst-for-missing-issue-fr\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Le service d&#039;audit Solidity Finance bl\u00e2m\u00e9 pour l&#039;attaque sur le protocole DeFi Grim\" \/>\n<meta property=\"og:description\" content=\"Le piratage de Grim Finance aurait son origine dans une vuln\u00e9rabilit\u00e9 dans un contrat intelligent qui aurait \u00e9chapp\u00e9 au service d&#039;audit Solidity Finance.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cryptonews.com\/fr\/news\/hacked-grim-finances-auditors-blame-new-analyst-for-missing-issue-fr\/\" \/>\n<meta property=\"og:site_name\" content=\"Cryptonews France\" \/>\n<meta property=\"article:published_time\" content=\"2021-12-20T11:43:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-06-26T11:08:14+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cimg.co\/news\/67199\/49764\/adobestock-rawpixelcom-1-1.jpg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Le service d&#039;audit Solidity Finance bl\u00e2m\u00e9 pour l&#039;attaque sur le protocole DeFi Grim\" \/>\n<meta name=\"twitter:description\" content=\"Le piratage de Grim Finance aurait son origine dans une vuln\u00e9rabilit\u00e9 dans un contrat intelligent qui aurait \u00e9chapp\u00e9 au service d&#039;audit Solidity Finance.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/cimg.co\/news\/67199\/49764\/adobestock-rawpixelcom-1-1.jpg\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Le service d'audit Solidity Finance bl\u00e2m\u00e9 pour l'attaque sur le protocole DeFi Grim","description":"Le piratage de Grim Finance aurait son origine dans une vuln\u00e9rabilit\u00e9 dans un contrat intelligent qui aurait \u00e9chapp\u00e9 au service d'audit Solidity Finance.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cryptonews.com\/fr\/news\/hacked-grim-finances-auditors-blame-new-analyst-for-missing-issue-fr\/","og_locale":"fr_FR","og_type":"article","og_title":"Le service d'audit Solidity Finance bl\u00e2m\u00e9 pour l'attaque sur le protocole DeFi Grim","og_description":"Le piratage de Grim Finance aurait son origine dans une vuln\u00e9rabilit\u00e9 dans un contrat intelligent qui aurait \u00e9chapp\u00e9 au service d'audit Solidity Finance.","og_url":"https:\/\/cryptonews.com\/fr\/news\/hacked-grim-finances-auditors-blame-new-analyst-for-missing-issue-fr\/","og_site_name":"Cryptonews France","article_published_time":"2021-12-20T11:43:00+00:00","article_modified_time":"2023-06-26T11:08:14+00:00","og_image":[{"url":"https:\/\/cimg.co\/news\/67199\/49764\/adobestock-rawpixelcom-1-1.jpg","type":"","width":"","height":""}],"twitter_card":"summary_large_image","twitter_title":"Le service d'audit Solidity Finance bl\u00e2m\u00e9 pour l'attaque sur le protocole DeFi Grim","twitter_description":"Le piratage de Grim Finance aurait son origine dans une vuln\u00e9rabilit\u00e9 dans un contrat intelligent qui aurait \u00e9chapp\u00e9 au service d'audit Solidity Finance.","twitter_image":"https:\/\/cimg.co\/news\/67199\/49764\/adobestock-rawpixelcom-1-1.jpg","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/cryptonews.com\/fr\/news\/hacked-grim-finances-auditors-blame-new-analyst-for-missing-issue-fr\/#article","isPartOf":{"@id":"https:\/\/cryptonews.com\/fr\/news\/hacked-grim-finances-auditors-blame-new-analyst-for-missing-issue-fr\/"},"author":{"name":"rcorinnehda","@id":"https:\/\/cryptonews.com\/fr\/#\/schema\/person\/9b84ee78a7702cc8ba1c80f85c5330a6"},"headline":"Le piratage de Grim serait d\u00fb \u00e0 la n\u00e9gligence d&#8217;un analyste","datePublished":"2021-12-20T11:43:00+00:00","dateModified":"2023-06-26T11:08:14+00:00","mainEntityOfPage":{"@id":"https:\/\/cryptonews.com\/fr\/news\/hacked-grim-finances-auditors-blame-new-analyst-for-missing-issue-fr\/"},"wordCount":805,"publisher":{"@id":"https:\/\/cryptonews.com\/fr\/#organization"},"image":{"@id":"https:\/\/cryptonews.com\/fr\/news\/hacked-grim-finances-auditors-blame-new-analyst-for-missing-issue-fr\/#primaryimage"},"thumbnailUrl":"https:\/\/cimg.co\/news\/67199\/49764\/adobestock-rawpixelcom-1-1.jpg","keywords":["Altcoins","DeFi","Piratage"],"articleSection":["Actualit\u00e9s DeFi","News"],"inLanguage":"fr-FR","copyrightYear":"2021","copyrightHolder":{"@id":"https:\/\/cryptonews.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/cryptonews.com\/fr\/news\/hacked-grim-finances-auditors-blame-new-analyst-for-missing-issue-fr\/","url":"https:\/\/cryptonews.com\/fr\/news\/hacked-grim-finances-auditors-blame-new-analyst-for-missing-issue-fr\/","name":"Le service d'audit Solidity Finance bl\u00e2m\u00e9 pour l'attaque sur le protocole DeFi Grim","isPartOf":{"@id":"https:\/\/cryptonews.com\/fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cryptonews.com\/fr\/news\/hacked-grim-finances-auditors-blame-new-analyst-for-missing-issue-fr\/#primaryimage"},"image":{"@id":"https:\/\/cryptonews.com\/fr\/news\/hacked-grim-finances-auditors-blame-new-analyst-for-missing-issue-fr\/#primaryimage"},"thumbnailUrl":"https:\/\/cimg.co\/news\/67199\/49764\/adobestock-rawpixelcom-1-1.jpg","datePublished":"2021-12-20T11:43:00+00:00","dateModified":"2023-06-26T11:08:14+00:00","description":"Le piratage de Grim Finance aurait son origine dans une vuln\u00e9rabilit\u00e9 dans un contrat intelligent qui aurait \u00e9chapp\u00e9 au service d'audit Solidity Finance.","breadcrumb":{"@id":"https:\/\/cryptonews.com\/fr\/news\/hacked-grim-finances-auditors-blame-new-analyst-for-missing-issue-fr\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cryptonews.com\/fr\/news\/hacked-grim-finances-auditors-blame-new-analyst-for-missing-issue-fr\/"]}],"author":[]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/cryptonews.com\/fr\/news\/hacked-grim-finances-auditors-blame-new-analyst-for-missing-issue-fr\/#primaryimage","url":"https:\/\/cimg.co\/news\/67199\/49764\/adobestock-rawpixelcom-1-1.jpg","contentUrl":"https:\/\/cimg.co\/news\/67199\/49764\/adobestock-rawpixelcom-1-1.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/cryptonews.com\/fr\/news\/hacked-grim-finances-auditors-blame-new-analyst-for-missing-issue-fr\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cryptonews.com\/fr\/"},{"@type":"ListItem","position":2,"name":"Le piratage de Grim serait d\u00fb \u00e0 la n\u00e9gligence d&#8217;un analyste"}]},{"@type":"WebSite","@id":"https:\/\/cryptonews.com\/fr\/#website","url":"https:\/\/cryptonews.com\/fr\/","name":"Cryptonews","description":"","publisher":{"@id":"https:\/\/cryptonews.com\/fr\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cryptonews.com\/fr\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/cryptonews.com\/fr\/#organization","name":"Cryptonews France","url":"https:\/\/cryptonews.com\/fr\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/cryptonews.com\/fr\/#\/schema\/logo\/image\/","url":"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/3\/2023\/09\/4.jpg","contentUrl":"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/3\/2023\/09\/4.jpg","width":1669,"height":874,"caption":"Cryptonews France"},"image":{"@id":"https:\/\/cryptonews.com\/fr\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts\/67205","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/users\/35"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/comments?post=67205"}],"version-history":[{"count":0,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts\/67205\/revisions"}],"wp:attachment":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/media?parent=67205"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/categories?post=67205"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/tags?post=67205"},{"taxonomy":"editors","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/editors?post=67205"},{"taxonomy":"sponsored_companies","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/sponsored_companies?post=67205"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}