金融与数字资产安全一周快讯(8月10日—8月16日)Weekly Financial and Digital Asset Security Brief (Aug 10–16, 2026)
本期聚焦第三方支付监管、银行欺诈、加密支付、钱包与 DeFi 安全事件。This issue covers third-party payment regulation, banking fraud, crypto payments, wallets, and DeFi security.
本周快讯This Week
Upbound Group 数据泄露造成 1300 万美元欺诈损失Upbound Group Reports $13 Million in Fraud Losses after Data Breach
原 Rent-A-Center 旗下 Acima 租赁业务遭入侵,攻击者利用窃取的客户数据欺诈性获取商品,造成约 1300 万美元损失。Acima, the leasing business formerly owned by Rent-A-Center, was breached. Attackers used stolen customer data to fraudulently obtain merchandise, causing about $13 million in losses.
BEC 与资金转移欺诈占 2025 年网络保险索赔 58%BEC and Funds-Transfer Fraud Account for 58% of 2025 Cyber-Insurance Claims
Coalition 数据显示,商业邮件入侵和资金转移欺诈占 2025 年网络保险索赔的 58%。美国全年数据泄露达到 3322 起,金融服务行业报告数量最多。Coalition data shows that business-email compromise and funds-transfer fraud represented 58% of cyber-insurance claims in 2025. The United States recorded 3,322 breaches, with financial services reporting the largest number.
Oraichain 跨链桥遭攻击,网络全面暂停Oraichain Bridge Attack Forces a Network-Wide Pause
攻击者利用 EVM 跨链路径漏洞未经授权铸造 ORAI 代币,网络自 8 月 9 日起暂停,团队准备销毁非法铸造的代币。Attackers exploited an EVM cross-chain path to mint ORAI tokens without authorization. The network has been paused since August 9 while the team prepares to burn the unauthorized tokens.
USM 协议定价逻辑缺陷遭闪电贷攻击USM Pricing Logic Flaw Exploited through Flash Loans
USM 的 ethFromDefund() 缺乏分裂不变性,攻击者拆分为 64 笔小额调用,套取约 70.83 ETH,价值约 13.6 万美元。USM’s ethFromDefund() lacked a split-call invariant. Attackers divided the operation into 64 smaller calls and extracted about 70.83 ETH, worth roughly $136,000.
MOKE 代币未受保护的 claim 函数遭滥用Unprotected MOKE Claim Function Abused
MOKE 合约的 claim() 缺乏调用者校验,攻击者提取 1.66 亿枚 MOKE 并兑换为约 1546 BNB,价值约 90.8 万美元。MOKE’s claim() function lacked caller validation. Attackers withdrew 166 million MOKE tokens and exchanged them for about 1,546 BNB, worth approximately $908,000.
DeFi 2026 年上半年损失超 8.4 亿美元DeFi Losses Exceed $840 Million in H1 2026
公开统计显示,2026 年上半年 DeFi 事件损失已超过 8.4 亿美元,仅 4 月单月就超过 6 亿美元,其中 KelpDAO 和 Drift Protocol 是最大事件。AI vibe hacking 正进一步降低攻击门槛。Public industry statistics put DeFi losses above $840 million in the first half of 2026. April alone exceeded $600 million, led by KelpDAO and Drift Protocol, while AI vibe hacking continues to lower the barrier to exploitation.
朝鲜黑客 2025 年窃取 20.6 亿美元加密货币North Korean Hackers Stole $2.06 Billion in Crypto in 2025
报告称,朝鲜黑客 2025 年窃取约 20.6 亿美元加密货币,占全球加密盗窃约 60%;2016 年以来累计损失约 67.5 亿美元,社会工程已成为主导攻击向量。Reports estimate that North Korean hackers stole about $2.06 billion in cryptocurrency in 2025, around 60% of global crypto theft. Cumulative losses since 2016 reached about $6.75 billion, with social engineering becoming the dominant vector.
中关村银行因 9 项违规被罚 268.88 万元Zhongguancun Bank Fined RMB 2.6888 Million for Nine Violations
人民银行北京市分行披露,北京中关村银行因违反金融统计、账户管理、数据安全管理、网络安全管理和反洗钱等 9 项规定被罚,三名责任人同步受到处罚。The Beijing branch of the PBOC fined Beijing Zhongguancun Bank for nine violations involving financial statistics, account management, data security, cybersecurity, and anti-money-laundering controls. Three responsible individuals were also penalized.
瀚银科技收 2026 年第三方支付最大罚单 7445 万元Hanyin Technology Receives 2026’s Largest Third-Party Payment Fine
上海瀚银因违反清算管理和商户管理规定,被央行上海分行没收违法所得 6592 万元并处罚款 853 万元,合计罚没 7445 万元;其支付牌照续展已停滞 4 年。Shanghai Hanyin was ordered to forfeit RMB 65.92 million and pay an RMB 8.53 million fine for violating clearing and merchant-management rules, bringing the total penalty to RMB 74.45 million. Its payment-license renewal has stalled for four years.
成都摩宝五项核心变更被央行否决PBOC Rejects Five Core Changes Proposed by Chengdu Moba
央行总行首次向第三方支付机构出具不予行政许可决定书,否决成都摩宝关于注册资本、主要股东和实际控制人等五项核心申请。其注册资本 1.7 亿元未达到 2 亿元监管最低要求。The PBOC rejected five core applications from Chengdu Moba, including changes to registered capital, major shareholders, and its actual controller. Its RMB 170 million registered capital is below the RMB 200 million regulatory minimum.
AI 换脸冒充银行客服诈骗上半年同比增长 370%AI Face-Swap Scams Impersonating Bank Agents Rise 370%
公安部通报显示,2026 年上半年全国 AI 换脸类诈骗案件同比增长 370%。已有攻击者通过实时 AI 换脸视频冒充银行工作人员骗取 20 万元,银行客服身份校验和转账二次确认面临更高压力。China’s Ministry of Public Security reported a 370% year-on-year increase in AI face-swap scams during the first half of 2026. In one case, attackers used real-time face swapping to impersonate a bank employee and steal RMB 200,000, raising pressure on agent verification and transfer step-up checks.
多模态大模型检测智能合约不可审计漏洞Multimodal LLM Framework Finds Machine-Inauditable Smart-Contract Bugs
研究人员提出 SmartInv 框架,让多模态大模型在智能合约源代码和自然语言描述之间进行跨模态推理,自动生成不变量检测漏洞。在真实漏洞数据上发现 119 个零日漏洞,其中多个被确认具有高严重性。Researchers proposed SmartInv, a multimodal-LLM framework that reasons across smart-contract source code and natural-language descriptions to generate invariant checks. Evaluation on real vulnerability data found 119 zero-days, several of which were confirmed high severity.
WEMIX 稳定币合约遭入侵,损失约 72.4 万美元WEMIX Stablecoin Contract Compromised, Losing About $724,000
攻击者控制 WEMIX$ 稳定币合约所有权,未经授权铸造 523 万枚 WEMIX$ 并跨链转移。WEMIX 随后暂停跨链桥和受影响流动性池。Attackers took control of the WEMIX$ stablecoin contract, minted 5.23 million tokens without authorization, and moved them across chains. WEMIX suspended its bridge and affected liquidity pools in response.
Gitcoin 子域名遭前端攻击并嵌入恶意钱包窃取代码Gitcoin Subdomain Hacked to Host Front-End Wallet-Drainer Code
Blockaid 检测到 files.gitcoin.co 遭受前端攻击,站点被嵌入 Eleven Drainer 恶意代码,目标是窃取用户加密钱包资产。用户被建议暂时不要与该站点交互。Blockaid detected a front-end compromise of files.gitcoin.co. The subdomain was injected with Eleven Drainer code designed to steal crypto-wallet assets, and users were advised not to interact with it temporarily.
MEV 机器人被诱骗授权,损失约 750 万美元MEV Bot Tricked into Granting Authorization, Losing About $7.5 Million
JaredFromSubway.eth 运营的 MEV 机器人被虚假代币包装器诱骗授权,WETH、USDC 和 USDT 等资产被转出。事件根因不是智能合约漏洞,而是自动套利机器人的授权机制缺陷。An MEV bot operated by JaredFromSubway.eth was tricked into approving a fake token wrapper, allowing attackers to transfer WETH, USDC, USDT, and other assets. The root cause was an authorization weakness in automated arbitrage logic rather than a smart-contract bug.
已关闭项目代码成为新的 DeFi 攻击向量Abandoned Protocol Code Emerges as a New DeFi Attack Vector
Lazy Summer Protocol 遭遇 600 万美元攻击,根因来自已于 2025 年 11 月关闭的 Stream Finance 未修复代码;Moonbeam 链停止出块还导致链上 DeFi 资产被锁死。研究人员提醒,孤儿合约仍可能携带未修补漏洞。Lazy Summer Protocol suffered a $6 million attack linked to unpatched code from Stream Finance, which had shut down in November 2025. A Moonbeam halt also locked DeFi assets. Researchers warn that orphaned contracts can retain exploitable vulnerabilities long after a project closes.