← 목록으로
● 2026-09-24 비트겟 해킹($387.5M) 분석 기반

비트겟 해킹을 그대로 재현하고,
막는 코드까지 공개합니다

가격-시간 우선순위 매칭엔진과, 비트겟 사건에서 실제 쓰인 공격 패턴(소액 테스트 인출 → 관리자 백엔드 장악 → 위조 대량 인출)을 막는 방어 로직을 처음부터 직접 구현했습니다. 지금은 전부 무료로 공개합니다.

라이브 데모 보기 → 코드 바로보기

누구를 위한 건가

진짜 거래소 운영자용이 아닙니다 — 시스템설계 면접을 준비하거나, 포트폴리오에 넣을 묵직한 프로젝트가 필요한 백엔드 개발자를 위한 학습 자료입니다. 매칭엔진 설계는 코인베이스·로빈후드 같은 핀테크 기업 면접의 단골 주제입니다.

2,226★
오픈소스 매칭엔진 exchange-core의 GitHub 스타 수
387.5M$
이 코드가 재현하는 실제 비트겟 피해 규모
0원
지금 공개하는 코드의 가격 — 전부 무료

코드 — matching-engine.js

가격-시간 우선순위로 매수/매도 주문을 체결하는 최소 매칭엔진.

matching-engine.js
// 가격-시간 우선순위 매칭엔진 (최소 구현)
class MatchingEngine {
  constructor() {
    this.buyBook = []; // 매수: 가격↓, 동가는 시간↑
    this.sellBook = []; // 매도: 가격↑, 동가는 시간↑
    this.fills = [];
  }

  addOrder(side, price, qty) {
    const order = { id: crypto.randomUUID(), side, price, qty, time: Date.now() };
    if (side === 'buy') {
      this.buyBook.push(order);
      this.buyBook.sort((a, b) => b.price - a.price || a.time - b.time);
    } else {
      this.sellBook.push(order);
      this.sellBook.sort((a, b) => a.price - b.price || a.time - b.time);
    }
    this.match();
    return order;
  }

  match() {
    while (this.buyBook.length && this.sellBook.length && this.buyBook[0].price >= this.sellBook[0].price) {
      const buy = this.buyBook[0], sell = this.sellBook[0];
      const qty = Math.min(buy.qty, sell.qty);
      buy.qty -= qty; sell.qty -= qty;
      this.fills.push({ price: sell.price, qty, buyId: buy.id, sellId: sell.id, time: Date.now() });
      if (buy.qty <= 0) this.buyBook.shift();
      if (sell.qty <= 0) this.sellBook.shift();
    }
  }
}

코드 — withdrawal-defense.js

비트겟(2026.09) 사건 패턴 대응: 속도체크 + 다단계승인 + 타임락.

withdrawal-defense.js
// 위조 인출 방어 — 비트겟(2026.09) 사건 패턴 대응
class WithdrawalGuard {
  constructor({ velocityWindowMs = 10000, velocityThreshold = 3, timelockMs = 10000 } = {}) {
    this.recent = [];
    this.velocityWindowMs = velocityWindowMs;
    this.velocityThreshold = velocityThreshold;
    this.timelockMs = timelockMs;
  }

  request(amount, approvals = 1) {
    const now = Date.now();
    this.recent = this.recent.filter(r => now - r.time < this.velocityWindowMs);
    this.recent.push({ amount, time: now });

    // 1) 속도체크: 짧은 시간 내 임계치 초과 요청
    if (this.recent.length > this.velocityThreshold) {
      return { status: 'blocked', reason: 'velocity_check' };
    }

    // 2) 다단계 승인: 고액은 단일 권한으로 불가
    const requiredApprovals = amount > 1000 ? 2 : 1;
    if (approvals < requiredApprovals) {
      return { status: 'pending', reason: 'multi_approval_required' };
    }

    // 3) 타임락: 고액은 즉시 집행하지 않고 지연
    if (amount > 1000) {
      return { status: 'timelocked', releaseAt: now + this.timelockMs };
    }

    return { status: 'approved' };
  }
}

가격

무료 (지금)
심화 버전(멀티심볼, 실전 배포 가이드, 테스트 코드 포함) 출시 예정 — 사업자등록 완료 후 자유가격($0부터)으로 공개
goalsgo7574@gmail.com
구매·결제가 아닙니다 — "심화버전 출시알림 받고 싶어요"라고 메일 한 통만 보내주시면, 출시 시 연락드립니다.
주의: 이건 학습용 축소 구현입니다. 동시성 처리, DB 영속성, 실전 트래픽 대응이 없어 실제 거래소·지갑 시스템에 그대로 넣으면 안 됩니다.

의견을 남겨주세요

이 상품에 대한 피드백이나 질문이 있으면 알려주세요. 회신을 원하시면 이메일을 남겨주세요(선택).