BTC $86,502.55 +0.84%
ETH $2,758.19 +0.42%
BNB $791.38 -0.04%
XRP $1.59 +4.42%
SOL $118.30 +0.37%
TRX $0.3441 -0.99%
DOGE $0.1017 +2.20%
ADA $0.2544 +2.83%
BCH $339.73 +27.38%
LINK $13.02 +0.03%
HYPE $97.02 +3.95%
AAVE $147.57 +2.53%
SUI $1.02 -3.66%
XLM $0.2177 +1.72%
ZEC $1,614.81 +10.85%
AAPL $340.43 +0.52%
AMZN $255.54 -1.62%
GOOGL $352.45 -1.42%
MSFT $499.69 -0.27%
META $740.65 -0.06%
NVDA $228.31 +0.36%
TSLA $378.84 +0.52%
SNDK $1,877.19 +4.88%
INTC $123.30 +0.22%
SPCX $154.05 +0.73%
MU $1,090.95 +3.76%
AMD $620.58 -0.02%
BTC $86,502.55 +0.84%
ETH $2,758.19 +0.42%
BNB $791.38 -0.04%
XRP $1.59 +4.42%
SOL $118.30 +0.37%
TRX $0.3441 -0.99%
DOGE $0.1017 +2.20%
ADA $0.2544 +2.83%
BCH $339.73 +27.38%
LINK $13.02 +0.03%
HYPE $97.02 +3.95%
AAVE $147.57 +2.53%
SUI $1.02 -3.66%
XLM $0.2177 +1.72%
ZEC $1,614.81 +10.85%
AAPL $340.43 +0.52%
AMZN $255.54 -1.62%
GOOGL $352.45 -1.42%
MSFT $499.69 -0.27%
META $740.65 -0.06%
NVDA $228.31 +0.36%
TSLA $378.84 +0.52%
SNDK $1,877.19 +4.88%
INTC $123.30 +0.22%
SPCX $154.05 +0.73%
MU $1,090.95 +3.76%
AMD $620.58 -0.02%

attack

All
Article
Flash

first_img Cryptography technology provider Haruko was attacked, affecting 15 clients, with a small amount of funds stolen

According to CoinDesk, the crypto technology provider Haruko was targeted in a cyber attack earlier this week, affecting 15 clients. The attack exposed clients' read-only exchange API details and trading data. According to insiders, some hedge fund clients with weaker security protections may have had a small amount of funds stolen.Adam Carlile, co-founder and Chief Technology Officer of Haruko, stated in an email sent to clients that this was a targeted attack initiated by an organization, and the affected clients were all non-whitelisted clients. The attackers exploited a vulnerability in one of Haruko's processes to extract user access tokens, thereby obtaining data such as read-only exchange API information stored in process memory; clients' login credentials were not compromised. Haruko has fixed the vulnerability and refreshed the server-side keys, and plans to release a complete technical review report.Based in London, Haruko provides portfolio, risk management, and trading data infrastructure for institutional digital asset companies. The platform connects centralized exchanges, custodians, blockchains, and DeFi protocols, currently serving over 80 clients globally and integrating with more than 100 centralized trading platforms, 30 blockchains, and 250 on-chain protocols. Its listed clients include Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, among others, with GSR stating that it was not affected by this incident.

Japan National Police Agency: North Korea's cyber attack organization WaterPlum launched a large-scale attack targeting IT technicians

According to a joint alert issued by the Japanese National Police Agency, FBI, ASD/ACSC, BND, and BfV, the North Korean-backed cyber attack organization "WaterPlum" (also known as Contagious Interview) targets job seekers by disguising itself as an AI, cryptocurrency, and NFT company to post fake job listings. This lures job seekers into downloading NPM packages containing malware such as BeaverTail, InvisibleFerret, and OtterCookie, which then steal cryptocurrency wallet information and confidential data.As of July 2026, the organization has infected over 30,000 devices in more than 100 countries and regions worldwide, stealing information from over 7,000 cryptocurrency wallets, with the wallets under its control receiving at least approximately 1.7 billion yen (about 10.71 million USD) in cryptocurrency. The Japanese National Police Agency has discovered and dismantled a "notebook farm" established by local "supporters" for the first time in the country, where North Korean IT laborers remotely control PCs within the supporters' residences to conduct business, with the related amount involved reaching several hundred million yen.The police and FBI assess that WaterPlum and some North Korean IT laborers are under the unified command of the 313 Bureau of the Ministry of Military Industry of the Workers' Party of Korea, with the profits directly flowing into North Korea's national funding pool. The police remind IT technicians and corporate issuers to remain vigilant and avoid executing third-party code in unverified environments.
app_icon
ChainCatcher Building the Web3 world with innovations.