<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>区块链武器库</title><link>https://blog.keepthetoken.com/</link><description>Recent content on 区块链武器库</description><generator>Hugo</generator><language>en</language><lastBuildDate>Wed, 27 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.keepthetoken.com/index.xml" rel="self" type="application/rss+xml"/><item><title>科普系列——DeFi安全的三个基石</title><link>https://blog.keepthetoken.com/posts/multi-sig-timelock-governance-explainer/</link><pubDate>Wed, 27 May 2026 00:00:00 +0000</pubDate><guid>https://blog.keepthetoken.com/posts/multi-sig-timelock-governance-explainer/</guid><description>用古代城邦与三权分立的比喻，解释DeFi世界里三个最基本的安全设计——多签、时间锁、治理升级权限。为什么这些机制对去中心化系统至关重要，以及没有它们的系统会面临怎样的风险。</description></item><item><title>Iotex ioTube 跨链桥私钥泄露事件复盘</title><link>https://blog.keepthetoken.com/posts/private-key-breach-cross-chain-bridge-decentralization-myth/</link><pubDate>Tue, 26 May 2026 00:00:00 +0000</pubDate><guid>https://blog.keepthetoken.com/posts/private-key-breach-cross-chain-bridge-decentralization-myth/</guid><description>2026年2月21日，ioTube跨链桥因管理员私钥泄露，攻击者抽走价值440万美元的真实资产（USDC、USDT、WBTC、WETH、IOTX等），并利用金库权限凭空铸造8.21亿枚无背书的CIOTX代币。本文以Rekt News披露的真实时间线为准，复盘这场\\&amp;#34;无漏洞利用\\&amp;#34;的权限全面接管。</description></item><item><title>玻璃做的金库：当透明成为一种攻击面</title><link>https://blog.keepthetoken.com/posts/glass-vault-when-transparency-becomes-attack-surface/</link><pubDate>Tue, 26 May 2026 00:00:00 +0000</pubDate><guid>https://blog.keepthetoken.com/posts/glass-vault-when-transparency-becomes-attack-surface/</guid><description>引言以玻璃金库比喻开篇，通过三个递进案例——公开内存池使意图成为猎物、开源合约与TVL把资产变成悬赏、链上治理把未来变成倒计时——揭示透明作为区块链最高信条的内在悖论。收束于哲学层：福柯的全景监狱反转、信任之死的代价、不透明作为一种智慧、以及行业已在悄悄修正的工程实践。</description></item><item><title>黑暗森林的候车室：Mempool的崩溃与秩序演进</title><link>https://blog.keepthetoken.com/posts/waiting-room-of-dark-forest/</link><pubDate>Thu, 21 May 2026 00:00:00 +0000</pubDate><guid>https://blog.keepthetoken.com/posts/waiting-room-of-dark-forest/</guid><description>通过三个真实灾难案例，探讨区块链 Txpool（交易内存池）的崩溃与秩序演进。</description></item><item><title>KelpDAO — 当受害者成为武器：2.9 亿美元跨链桥攻击复盘</title><link>https://blog.keepthetoken.com/posts/kelpdao-when-victims-become-weapons/</link><pubDate>Mon, 20 Apr 2026 00:00:00 +0000</pubDate><guid>https://blog.keepthetoken.com/posts/kelpdao-when-victims-become-weapons/</guid><description>2026 年 4 月 18 日，KelpDAO 遭遇 2.9 亿美元跨链桥攻击。攻击者利用 LayerZero OFT 签名验证漏洞，在 Unichain 第 308 号数据包从未存在的情况下，从以太坊金库提走 116,500 个 rsETH。</description></item></channel></rss>