金融与数字资产安全一周快讯(8月17日—8月23日)Weekly Financial and Digital Asset Security Brief (Aug 17–23, 2026)
本期汇总银行 API、加密支付、交易平台、钱包、DeFi、跨链桥和稳定币安全动态,更新截至 2026 年 8 月 21 日。This issue covers banking APIs, crypto payments, trading platforms, wallets, DeFi, bridges, and stablecoin security, updated through August 21, 2026.
本周快讯This Week
Harmony 将回滚网络,应对跨分片重放漏洞造成的超 3 万亿枚 ONE 伪造Harmony Plans Network Rollback after Cross-Shard Replay Forged More Than 3 Trillion ONE
Harmony 的最新调查显示,攻击者利用跨分片收据验证缺陷,在 6 笔交易中伪造超过 3 万亿枚 ONE。团队已修复漏洞,并计划将 Shard 0 和 Shard 1 回滚至攻击发生前;该数量代表伪造代币规模,不等同于可实现的美元损失。Harmony's latest investigation found that attackers exploited a cross-shard receipt-verification flaw to forge more than 3 trillion ONE across six transactions. The flaw has been patched, and the team plans to roll Shard 0 and Shard 1 back to their pre-attack state; the token count does not represent a realizable dollar loss.
Maya Protocol 遭 6 个链式边缘漏洞攻击,损失约 170 万美元Maya Protocol Hit by Six Chained Edge-Case Bugs, Losing About $1.7 Million
攻击者利用 6 个链式边缘漏洞,通过虚假补贴膨胀会计机制提取约 4887 万 CACAO,并转换为约 20.83 BTC,最终损失约 170 万美元。Attackers chained six edge-case vulnerabilities to exploit an inflated accounting mechanism for fake subsidies, extracting about 48.87 million CACAO and converting it into roughly 20.83 BTC. The final loss was about $1.7 million.
BTCPay Server 严重漏洞被积极利用Critical BTCPay Server Vulnerability Actively Exploited
8 月 7 日至 10 日,BTCPay Server 暴露的严重漏洞被黑客积极利用,可导致商户资金被转走。社区已发布紧急补丁,并悬赏最高 3 BTC 协助恢复。A critical vulnerability exposed in BTCPay Server was actively exploited between August 7 and 10 and could drain merchant funds. The community released an emergency patch and offered a bounty of up to 3 BTC to help with recovery.
Coldcard 硬件钱包固件漏洞损失或达 1.3 亿美元Coldcard Hardware-Wallet Firmware Flaw May Have Caused $130 Million in Losses
Galaxy Research 分析指出,Coldcard 硬件钱包此前披露的固件熵值缺陷造成的实际损失可能被严重低估,风险规模可能扩大至 1.3 亿美元,并推动 2026 年比特币链上活动达到年度高点。Galaxy Research said the actual losses from the previously disclosed Coldcard firmware-entropy flaw may have been severely underestimated, with the potential total rising to $130 million. The incident also coincided with a yearly high in Bitcoin on-chain activity.
MacSync Stealer 窃取浏览器凭证和加密钱包数据MacSync Stealer Targets Browser Credentials and Crypto Wallets
Microsoft Defender 将 30 多个域名与 MacSync Stealer 关联起来。该恶意软件通过 ClickFix 社工传播,使用 zsh Terminal 与 curl 获取载荷,重点窃取浏览器凭证和加密货币钱包数据。Microsoft Defender linked more than 30 domains to MacSync Stealer. The malware spreads through ClickFix social engineering, uses zsh and curl to fetch its payload, and targets browser credentials and cryptocurrency-wallet data.
Lloyds Banking App 漏洞泄露 44.8 万客户交易数据Lloyds Banking App Bug Exposes Transaction Data of 448,000 Customers
3 月 12 日夜间的一次 API 更新存在缺陷,在特定并发访问条件下错误展示了其他用户的排序码、账号等交易信息,影响约 44.8 万名客户。A faulty API update on the night of March 12 exposed other users’ sort codes, account numbers, and transaction data under a specific concurrent-access condition. About 448,000 customers were affected.
Google 广告钓鱼盗走 Hyperliquid 用户 55 万美元Google-Search Ad Phishing Steals $550,000 from Hyperliquid Users
攻击者购买 Google 搜索广告,把用户引导至伪造交易平台页面实施钓鱼,说明交易平台品牌和付费搜索结果已成为新的攻击入口。Attackers bought Google search ads and directed users to a fake trading-platform page to phish their assets, showing how exchange brands and paid search results are becoming attack entry points.
Immunefi:2026 年上半年加密攻击 207 起,损失 9.72 亿美元Immunefi Counts 207 Crypto Attacks and $972 Million in H1 2026 Losses
Immunefi 统计显示,2026 年上半年加密攻击达到 207 起并创纪录,损失约 9.72 亿美元;攻击更频繁但单次损失下降,攻击者逐渐转向私钥和跨链配置等基础设施层。Immunefi counted a record 207 crypto attacks and about $972 million in losses in the first half of 2026. Attacks became more frequent while average losses fell, with attackers shifting toward infrastructure such as private keys and cross-chain configuration.
韩国 Delio CEO 因 5000 万美元加密诈骗被判 15 年Delio CEO Sentenced to 15 Years for $50 Million Crypto Fraud
韩国 Delio 负责人因约 5000 万美元加密诈骗被判 15 年,是韩国加密行业迄今最严厉的高管刑罚之一,反映交易平台客户资产与经营透明度的合规风险。The head of South Korean crypto platform Delio received a 15-year sentence for approximately $50 million in crypto fraud, one of the harshest executive sentences in the country’s crypto sector and a reminder of customer-asset and transparency risks.
Tether 获 KPMG 首次全面审计清洁意见Tether Receives a Clean Opinion in Its First Full KPMG Audit
Tether 获得 KPMG 首次全面审计的清洁意见,USDT 储备透明度得到完整验证,对稳定币发行方的储备披露、审计和市场信任具有参考意义。Tether received a clean opinion in its first full KPMG audit, providing a complete verification of USDT reserves and offering a reference point for reserve disclosure, audits, and market trust among stablecoin issuers.
Interpol I-GRIP 阻止 660 万美元 BEC 诈骗Interpol I-GRIP Blocks $6.6 Million in BEC Fraud
First Light 2026 行动通过 Interpol I-GRIP 系统封锁超过 3.1 万个欺诈银行账户并阻止约 660 万美元 BEC 诈骗,说明跨境账户冻结和快速协查对支付反欺诈的重要性。Operation First Light 2026 used Interpol’s I-GRIP system to block more than 31,000 fraudulent bank accounts and stop about $6.6 million in BEC fraud, demonstrating the value of cross-border account freezes and rapid coordination.
Marquis 数据泄露影响 67.2 万人,波及银行与信用社服务商Marquis Breach Affects 672,000 People across Bank and Credit-Union Services
Marquis 作为银行和信用社服务商遭 SonicWall 漏洞入侵,窃取社会安全号码、支付卡号等敏感数据,影响约 67.2 万人。该事件显示金融供应链单点故障可能造成集中化数据风险。Marquis, a service provider to banks and credit unions, was compromised through a SonicWall vulnerability, exposing Social Security numbers, payment-card numbers, and other sensitive data affecting about 672,000 people.
Coreum Bridge 因存款验证逻辑缺陷被攻击Coreum Bridge Attacked through a Deposit-Verification Logic Flaw
XRP Ledger 连接桥的存款验证和中继器逻辑存在缺陷,攻击者伪造存款欺骗中继器授权提取真实 XRP,97 分钟内转出 20 万 XRP。A flaw in the XRP Ledger bridge’s deposit verification and relayer logic allowed attackers to fake deposits and trick the relayer into releasing real XRP. About 200,000 XRP was drained in 97 minutes.
Coinsbuy 钱包被盗 790 万美元Coinsbuy Wallet Drained of $7.9 Million
B2B 加密支付处理商 Coinsbuy 在 ETH 和 TRON 链上的资产被转空,损失超过 790 万美元,部分资金被兑换为 XMR 进行洗白。Coinsbuy, a B2B crypto-payment processor, had more than $7.9 million drained from wallets on Ethereum and TRON. Some of the stolen funds were converted to XMR for laundering.
FoxMarket 闪电贷攻击操纵 AMM 报价FoxMarket Flash-Loan Attack Manipulates AMM Pricing
攻击者操纵 Pancake AMM 现货报价,Treasury 依赖过时价格铸造超额代币,造成约 11.87 万美元损失。Attackers manipulated Pancake AMM spot pricing. The Treasury trusted a stale value and minted excess tokens, causing a loss of about $118,700.
RRWallet 供应链攻击利用弱随机数预测助记词RRWallet Supply-Chain Attack Makes Mnemonics Predictable
CryptoJS 库的弱随机数导致助记词可预测,一名用户损失约 200 万美元,说明钱包依赖和随机数实现需要持续审计。Weak randomness in the CryptoJS dependency made wallet mnemonics predictable, costing one user about $2 million and underscoring the need to continuously audit wallet dependencies and randomness implementations.
LOOPSDAO 因缺少 TWAP 保护遭价格操纵LOOPSDAO Price Manipulation Exploits Missing TWAP Protection
无 TWAP 保护的薄流动性交易对被闪电贷操纵,攻击者燃烧 Cake-LP 并提取膨胀金额,损失约 69 万美元。A thin-liquidity pair without TWAP protection was manipulated through a flash loan. The attacker burned Cake-LP and extracted inflated value, causing a loss of about $690,000.
River Bank 勒索软件攻击后称被盗数据已删除River Bank Says Stolen Data Was Deleted after Ransomware Attack
River Bank 这家银行控股公司确认 6 月遭受勒索软件攻击,并称黑客已经删除被盗数据,但具体影响范围以及数据是否仍可恢复尚未公开。River Bank, a bank holding company, confirmed a ransomware attack in June and said the attackers had deleted the stolen data. The full impact and whether the data remains recoverable have not been publicly disclosed.