BTC $83,293.91 -1.63%
ETH $2,677.15 -0.28%
BNB $761.64 -2.11%
XRP $1.48 -2.48%
SOL $117.72 -4.17%
TRX $0.3355 +0.61%
DOGE $0.0931 -4.26%
ADA $0.2439 -4.69%
BCH $306.77 -7.85%
LINK $15.14 +7.94%
HYPE $86.85 -5.04%
AAVE $146.08 -5.51%
SUI $1.13 -10.12%
XLM $0.2248 +3.75%
ZEC $1,464.20 -8.51%
AAPL $338.59 -0.47%
AMZN $246.40 -1.52%
GOOGL $342.63 -0.39%
MSFT $509.78 -1.52%
META $717.46 -4.30%
NVDA $229.21 +1.82%
TSLA $357.98 -4.14%
SNDK $1,712.63 -3.96%
INTC $115.93 -7.28%
SPCX $145.94 -2.27%
MU $1,053.88 -3.75%
AMD $609.57 -4.12%
BTC $83,293.91 -1.63%
ETH $2,677.15 -0.28%
BNB $761.64 -2.11%
XRP $1.48 -2.48%
SOL $117.72 -4.17%
TRX $0.3355 +0.61%
DOGE $0.0931 -4.26%
ADA $0.2439 -4.69%
BCH $306.77 -7.85%
LINK $15.14 +7.94%
HYPE $86.85 -5.04%
AAVE $146.08 -5.51%
SUI $1.13 -10.12%
XLM $0.2248 +3.75%
ZEC $1,464.20 -8.51%
AAPL $338.59 -0.47%
AMZN $246.40 -1.52%
GOOGL $342.63 -0.39%
MSFT $509.78 -1.52%
META $717.46 -4.30%
NVDA $229.21 +1.82%
TSLA $357.98 -4.14%
SNDK $1,712.63 -3.96%
INTC $115.93 -7.28%
SPCX $145.94 -2.27%
MU $1,053.88 -3.75%
AMD $609.57 -4.12%

technology

All
Article
Flash

Chengming Technology issued a letter holding ZCode accountable for uploading data without authorization

Taiyuan Chengming Technology Co., Ltd. sent a letter to Beijing Zhipu Huazhang Technology Co., Ltd., raising multiple demands regarding the alleged unauthorized upload of company data assets and trade secrets by its ZCode client, and reserving the right to pursue legal accountability. Chengming Technology pointed out that although Zhipu has publicly apologized for the "silent upload of user local repository data" and claimed to have fixed the issue, independent evidence collection revealed that the upload behavior was automatically triggered and occurred in bulk, including complete archived files such as project source code, system architecture, version control history, database passwords, cloud service credentials, and employee personal information, far exceeding the scope of collection stated in its Privacy Policy.Although the client was updated to version 3.12.3 on September 16, upload behavior was still detected in the early hours of the day Zhipu publicly apologized, raising doubts about the actual effectiveness of the "fix." At the same time, the ZCode client’s network requests pointed to a Singapore entity, while the service agreement was signed with Beijing Zhipu Huazhang, requesting clarification on the responsible party for this upload, as well as whether the data was transmitted abroad or stored overseas.Chengming Technology demanded that Zhipu respond in writing by October 10 and complete the immediate cessation of processing and thorough deletion of all uploaded data and related derivative data, caches, and backups, provide a complete list of processing situations, clarify the data's whereabouts, whether it was shared with third parties, whether it was used for model training, and whether cross-border transmission occurred, explain the management of encryption private keys and complete operation logs, clarify the exact scope of "destruction" mentioned in previous public responses, issue proof of deletion completion, provide a written commitment not to upload without authorization again, legally provide access, copying, and explanation of personal information, and designate formal communication channels, among other matters. Currently, Zhipu has not publicly responded to the aforementioned letter.

first_img Cryptography technology provider Haruko was attacked, affecting 15 clients, with a small amount of funds stolen

According to CoinDesk, the crypto technology provider Haruko was targeted in a cyber attack earlier this week, affecting 15 clients. The attack exposed clients' read-only exchange API details and trading data. According to insiders, some hedge fund clients with weaker security protections may have had a small amount of funds stolen.Adam Carlile, co-founder and Chief Technology Officer of Haruko, stated in an email sent to clients that this was a targeted attack initiated by an organization, and the affected clients were all non-whitelisted clients. The attackers exploited a vulnerability in one of Haruko's processes to extract user access tokens, thereby obtaining data such as read-only exchange API information stored in process memory; clients' login credentials were not compromised. Haruko has fixed the vulnerability and refreshed the server-side keys, and plans to release a complete technical review report.Based in London, Haruko provides portfolio, risk management, and trading data infrastructure for institutional digital asset companies. The platform connects centralized exchanges, custodians, blockchains, and DeFi protocols, currently serving over 80 clients globally and integrating with more than 100 centralized trading platforms, 30 blockchains, and 250 on-chain protocols. Its listed clients include Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, among others, with GSR stating that it was not affected by this incident.
app_icon
ChainCatcher Building the Web3 world with innovations.