一个僵尸网络意外摧毁了I2P。
A Botnet Accidentally Destroyed I2P

原始链接: https://www.sambent.com/a-botnet-accidentally-destroyed-i2p-the-full-story/

2026年2月,I2P匿名网络遭受了一次大规模的Sybil攻击,涌入了70万个恶意节点——比其通常的15,000-20,000个活跃用户增加了39倍。最初怀疑这次攻击是过去几年(2023年和2024年)国家赞助的干扰活动的延续,但令人惊讶的是,它被追踪到Kimwolf僵尸网络。 Kimwolf于2025年12月发起过创纪录的DDoS攻击,在研究人员攻陷其主服务器后,试图建立备份的指挥和控制基础设施时,意外地将I2P作为目标。 I2P团队迅速响应,仅六天后发布了2.11.0版本。该更新显著地默认启用了后量子密码学——这是生产级匿名网络的首次——同时还包括Sybil缓解改进和基础设施升级,从而增强了网络的弹性。

黑客新闻 新 | 过去 | 评论 | 提问 | 展示 | 招聘 | 提交 登录 一个僵尸网络意外摧毁了I2P (sambent.com) 7点 由 Cider9986 1小时前 | 隐藏 | 过去 | 收藏 | 1条评论 帮助 gnabgib 15分钟前 [–] 这似乎缺少完整的故事,尽管标题很醒目。 Krebs的报道更深入 (39点) https://news.ycombinator.com/item?id=46976825 回复 指南 | 常见问题 | 列表 | API | 安全 | 法律 | 申请YC | 联系 搜索:
相关文章

原文

On February 3, 2026, the I2P anonymity network was flooded with 700,000 hostile nodes in what became one of the most devastating Sybil attacks an anonymity network has ever experienced. The network normally operates with 15,000 to 20,000 active devices. The attackers overwhelmed it by a factor of 39 to 1.

For three consecutive years, I2P has been hit with Sybil attacks every February. The 2023 and 2024 attacks used malicious floodfill routers and remain unattributed. When the 2026 attack began, most assumed it was the same state-sponsored operation continuing its annual disruption campaign. The assumption was wrong.

The attacker was identified as the Kimwolf botnet, an IoT botnet that infected millions of devices including streaming boxes and consumer routers throughout late 2025. Kimwolf is the same operation behind the record-setting 31.4 terabit per second DDoS attack in December 2025. The operators admitted on Discord they accidentally disrupted I2P while attempting to use the network as backup command-and-control infrastructure after security researchers destroyed over 550 of their primary C2 servers.

The I2P development team responded by shipping version 2.11.0 just six days after the attack began. The release includes hybrid ML-KEM plus X25519 post-quantum encryption enabled by default, making I2P one of the first production anonymity networks to ship post-quantum cryptography to all users. Additional Sybil mitigations, SAMv3 API upgrades, and infrastructure improvements were included.

联系我们 contact @ memedata.com