Incident AnalysisCEO Gracy Chen says the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials and issue fraudulent withdrawal commands — the first root-cause detail on the September 24 breach that took $387.5 million.
Sep 29, 2026·2 min read
HacksOn-chain analysis links a single coordinated group to 56 Pons launchpad tokens on Robinhood Chain with an estimated $15.5 million extracted — and finds 467 other groups running the same tax-exemption tactic.
Sep 29, 2026·2 min read
Security DigestThe day's smaller security stories in brief: a documentation placeholder domain referenced in ~1,700 repos was registered and now serves ClickFix lures, a macOS stealer adds live C2 payload decryption, and researchers catch AI agents exploiting websites during mundane tasks.
Sep 29, 2026·2 min read
SecuritySenator Blumenthal's PSI investigation found 84% of 846 Iran-linked sanctioned wallets transacted almost exclusively in USDT, and asked Treasury and DOJ to examine Tether's sanctions and Bank Secrecy Act compliance — Tether counters that it froze nearly $550 million in Iran-linked tokens this year.
Sep 29, 2026·2 min read
Incident AnalysisEvercrest, the company behind Kelp DAO, filed suit in the Supreme Court of British Columbia alleging LayerZero endorsed the single-verifier bridge setup attackers exploited in April, then publicly blamed Kelp for it — claims Pellegrino calls meritless.
Sep 28, 2026·3 min read
SecurityImmunefi's Mitchell Amador says the self-described white hats who returned 3,400 BTC from the ~4,000 BTC Liquid Network drain lost any rescue claim by retaining 598.5 BTC and demanding a bounty — reviving the debate over rescue terms set before exploits, not after.
Sep 28, 2026·3 min read
Security DigestThe day's smaller security stories in brief: Bitget begins phased withdrawal restarts at 08:00 UTC with losses confirmed at $387.5M, THORChain refuses Bitget's call to block attacker addresses, and Huntress documents a DarkMe RAT campaign whose loaders probe for crypto wallets and trading terminals.
Sep 28, 2026·2 min read
HacksPrivacy L1 Zano restarted its blockchain at block 3,833,000 after a Gateway Address vulnerability let unauthorized ZANO and Freedom Dollar tokens into circulation, invalidating roughly a month of legitimate transactions alongside the unbacked mint.
Sep 28, 2026·2 min read
Incident AnalysisBitget has raised its confirmed loss from the September 24 hot-wallet breach to $387.5 million, with XRP the largest single tranche at about $157.5 million. Withdrawals resume in phases from September 28 at 08:00 UTC, with full restoration targeted for October 2, and the exchange says the exploited vulnerability has been identified and remediated.
Sep 27, 2026·2 min read
AuditsA Coinpedia research report counts 288 crypto security incidents and about $2.21 billion in losses so far in 2026. Its sharpest finding: of 245 documented incidents from January 2025 through July 2026, 147 involved platforms that had completed independent audits — and those platforms accounted for 88.44% of the capital drained.
Sep 27, 2026·2 min read
Incident AnalysisA bug in Limit Break's Payment Processor V2 — the settlement contract Magic Eden abandoned in October 2024 — let an attacker pull 305 NFTs and roughly 660 WETH from wallets whose onchain approvals never expired. A whitehat team led by Yuga Labs' 0xQuit used the same flaw to move 23,155 NFTs worth over $5.7 million to safety, and a public recovery portal is now live for owners to reclaim them.
Sep 27, 2026·3 min read
SecurityOpenZeppelin's smart contract libraries and secure development suite became available for TRON on September 24, adding TRC-20 token components, UUPS-style upgrade tooling with TRC-1967 proxies, passkey-friendly secp256r1 signature support, and an MCP server for AI-assisted development.
Sep 27, 2026·2 min read
Incident AnalysisOn-chain analysis by TRM Labs shows the September 24 Bitget theft split into round-number holding wallets within hours, with conversion routes into Bitcoin matching infrastructure previously used to launder the Bybit and AFX Bridge thefts. Circle and Tether froze an exploiter wallet holding about $318,000 in stablecoins.
Sep 26, 2026·3 min read
Incident AnalysisA September 20 attack on the Kasplex KRC-20 indexer drained 186.4 million ZEAL and 54.4 billion NACHO from a bridge custody wallet using five forged transactions — valid at Kaspa's consensus layer, fake at the token layer. Pools lost up to 99.6% of their KAS-side value, and operators are reindexing history to close the gap.
Sep 26, 2026·3 min read
SecurityElliptic says the Bitget breach — which it counts at $357 million — was likely carried out by North Korea-linked actors, pushing the year's suspected state-attributed haul past $1 billion. TRM Labs data shows about $690 million was already attributed before Bitget, mostly from the Drift Protocol and KelpDAO thefts.
Sep 26, 2026·2 min read
HacksBitget says attackers moved about $351.6 million out of hot and warm wallets on September 24 before its security team halted further transfers. Cold wallets were untouched, the exchange says, and its $464 million User Protection Fund covers the loss. No attribution has been confirmed.
Sep 25, 2026·3 min read
HacksCrypto gambling platform Duelbits took its site offline after attackers drained roughly $7 million from hot wallets on Ethereum, BNB Chain, Tron and Bitcoin on September 24. Scam Sniffer and PeckShield point to a suspected private key compromise; about $6 million sits consolidated in one Ethereum address.
Sep 25, 2026·2 min read
SecurityA court-authorized takedown announced September 22 seized 50 websites and disabled more than 175 domains behind EvilTokens, a device-code phishing service that Microsoft says used AI at every step of its attack chain. Two suspected operators were arrested in London, and Coinbase traced about $1.1 million of the operation's revenue on-chain.
Sep 25, 2026·2 min read
Incident AnalysisWith Bitget's $351.6 million breach, September's gross theft total has passed $684 million, topping April's $646.9 million. The anatomy of the worst month of the year: one exchange hot-wallet failure, one sidechain disaster, and a long tail of smaller incidents — with 2026's running total near $1.73 billion.
Sep 25, 2026·3 min read
SecurityFederal prosecutors are investigating whether Binance failed to stop Iran-linked trading that violated US sanctions, according to Bloomberg — the exchange's most serious US legal question since its $4.3 billion settlement in 2023, and one that follows a $61 million forfeiture action tied to Iranian oil proceeds laundered through Binance accounts.
Sep 24, 2026·3 min read
Incident AnalysisValidators froze the Cosmos Hub for nearly 25 hours after a $20,000 Neutron governance proposal handed an attacker admin control of Astroport and Drop contracts holding $9.4 million — and the first block after the restart moved 1,227,121 ATOM out of the attacker's wallet without its owner signing a transaction.
Sep 24, 2026·4 min read
HacksOn-chain analysis firm XRPL.to traced 11.75 million XRP — roughly $18.7 million — leaving 6,678 D'CENT-linked wallets across six sweeps between September 15 and 20, with 5.67 million XRP already routed through THORChain and D'CENT still silent on the technical cause of the key compromise.
Sep 24, 2026·4 min read
SecurityThe FBI's Virtual Asset Technical Exchange quietly convened several hundred law-enforcement officials and security specialists in San Antonio this September, with sessions on North Korean hacking operations, wrench attacks and intelligence sharing — as new data showed 2026 thefts approaching $1.73 billion.
Sep 24, 2026·3 min read
Incident AnalysisOn-chain trackers at Galaxy Research say apparent white-hat actors consolidated 52.37 BTC (about $4.5 million) from several Coldcard attacker clusters into a fresh address advertising a 'Crypto Recovery Trust' — the first large-scale rescue of funds from the roughly $130 million hardware wallet incident.
Sep 23, 2026·2 min read
Incident AnalysisA confirmed attempt to exploit a virtual-machine atomicity issue produced invalid state changes and stopped MultiversX block progression on September 19; Upbit has now flagged EGLD under its trading-support termination policy, Kraken went cancel-only, and a shadow-fork fix is pending while no confirmed loss figure has been published.
Sep 23, 2026·2 min read
SecurityThe oracle provider's September 18 liquidity assessment warns that a quoted price does not prove collateral can be sold: $10,000 sell quotes on four Starknet tokens deteriorated 15–22% versus $10 quotes, and the Nostra incident analysis found a manipulated pool feeding an oracle response with only two contributing sources.
Sep 23, 2026·3 min read
HacksOn-chain firms traced the same attacker behind the September 19 Fetch.ai and NuNet strikes to the SingularityNET Ethereum–Cardano bridge, where unauthorized mints of AGIX and WMTx pushed the cluster's holdings to about $16.77 million — with Bitquery counting roughly 2.3 billion newly created units across four tokens.
Sep 23, 2026·3 min read
HacksOn-chain tracking ties a mid-September drain of 9.3 million XRP — over $9 million — to a signing flaw in D'CENT's App Wallet software, with 1,552 wallets emptied in one two-hour window; D'CENT says users who typed recovery phrases into the app on versions before 8.1.0 are the exposure group.
Sep 22, 2026·2 min read
HacksBlockaid and PeckShield traced a September 19 attack that emptied a Fetch.ai token converter of 8.7 million FET and used the same wallet to mint 408.5 million unauthorized NTX through NuNet's deployer account — about $2 million combined, with NTX collapsing to an all-time low.
Sep 22, 2026·2 min read
Incident AnalysisThe London institutional crypto-tech provider said a targeted attack exploited a vulnerable process to extract a user-access token, exposing read-only exchange API details and trading data for all 15 non-whitelisted clients — with a small amount of client funds possibly stolen from smaller hedge funds.
Sep 22, 2026·2 min read