← 목록으로
● 2026-08-30 Tectonic(Cronos) 해킹 분석 기반

가격을 100배 펌핑해서 돈을 빌린
사건을 재현하고, 막는 코드까지 공개합니다

TWAP(시간가중평균가격) 오라클과 담보가치평가 엔진을 처음부터 직접 구현했습니다. Tectonic 사건(토큰 가격을 20분 만에 100배로 펌핑 → 과대담보로 과대차입)을 그대로 재현하고 막는 코드입니다. 지금은 전부 무료로 공개합니다.

라이브 데모 보기 → 코드 바로보기

무슨 사건을 재현하나

2026년 8월 30일, Cronos 최대 대출 프로토콜 Tectonic에서 공격자가 유동성 적은 거버넌스 토큰 가격을 약 20분 만에 100배로 펌핑했습니다. 그 뒤 부풀려진 토큰을 담보로 예치해서 실제 가치보다 훨씬 많은 금액을 빌려나갔습니다 — "가격이 곧 담보가치"라는 전제를 역이용한 공격입니다.

100배
20분 만에 펌핑된 거버넌스 토큰 가격
TWAP
이 코드가 적용하는 방어 메커니즘 — 시간가중평균가격
0원
지금 공개하는 코드의 가격 — 전부 무료

코드 — price-oracle-guard.js

TWAP 기반 오라클 — 순간적인 스팟가격 조작을 무시하고 일정 기간 평균가격을 기준값으로 사용.

price-oracle-guard.js
// TWAP(시간가중평균가격) 오라클 — 순간 스팟가격 조작 방어
class PriceOracleGuard {
  constructor({ windowMs = 1200000, maxDeviation = 0.1 } = {}) {
    this.history = []; // {price, time}
    this.windowMs = windowMs; // 기본 20분
    this.maxDeviation = maxDeviation; // TWAP 대비 허용 변동폭 10%
  }

  pushPrice(spotPrice) {
    const now = Date.now();
    this.history.push({ price: spotPrice, time: now });
    this.history = this.history.filter(p => now - p.time < this.windowMs);
  }

  twap() {
    if (!this.history.length) return 0;
    const sum = this.history.reduce((s, p) => s + p.price, 0);
    return sum / this.history.length;
  }

  getSafePrice(spotPrice) {
    this.pushPrice(spotPrice);
    const twap = this.twap();
    const deviation = Math.abs(spotPrice - twap) / (twap || spotPrice);
    if (deviation > this.maxDeviation) {
      return { price: twap, flagged: true, reason: 'spot_deviation_exceeded', spotPrice, twap };
    }
    return { price: spotPrice, flagged: false };
  }
}

코드 — collateral-engine.js

담보가치평가 + 자산별 차입한도(LTV) 로직 — 위 오라클을 가격 소스로 주입받아 사용.

collateral-engine.js
// 담보가치평가 + 차입한도 로직 (Tectonic 사건 대응)
class CollateralEngine {
  constructor(getPrice, { ltv = 0.7 } = {}) {
    this.getPrice = getPrice; // 오라클 가격 조회 함수 주입
    this.ltv = ltv; // 담보인정비율 70%
    this.positions = {};
  }

  deposit(user, token, amount) {
    this.positions[user] = this.positions[user] || { collateral: {}, borrowed: 0 };
    this.positions[user].collateral[token] = (this.positions[user].collateral[token] || 0) + amount;
  }

  collateralValue(user) {
    const pos = this.positions[user];
    if (!pos) return 0;
    return Object.entries(pos.collateral)
      .reduce((sum, [token, amt]) => sum + amt * this.getPrice(token), 0);
  }

  borrow(user, amount) {
    const maxBorrow = this.collateralValue(user) * this.ltv;
    const pos = this.positions[user];
    if (pos.borrowed + amount > maxBorrow) {
      return { status: 'rejected', reason: 'insufficient_collateral', maxBorrow };
    }
    pos.borrowed += amount;
    return { status: 'approved', borrowed: pos.borrowed };
  }
}

가격

무료 (지금)
심화 버전(멀티자산 담보, 청산 로직 포함) 출시 예정 — 사업자등록 완료 후 자유가격($0부터)으로 공개
goalsgo7574@gmail.com
구매·결제가 아닙니다 — "심화버전 출시알림 받고 싶어요"라고 메일 한 통만 보내주시면, 출시 시 연락드립니다.
주의: 이건 학습용 축소 구현입니다. 실제 대출 프로토콜은 다중 오라클 소스, 청산 메커니즘, 거버넌스 지연 등 훨씬 복잡한 방어층을 추가로 둡니다.

의견을 남겨주세요

이 상품에 대한 피드백이나 질문이 있으면 알려주세요. 회신을 원하시면 이메일을 남겨주세요(선택).