SecurityThe Cyber Resilience Act's vulnerability and incident reporting obligations took effect September 11, 2026. Wallet manufacturers selling into the EU must now warn ENISA within 24 hours of learning a flaw is being actively exploited — a legal deadline that would have reshaped this year's Coldcard, Trezor and Liquid disclosures.
Sep 14, 2026·3 min read
Security DigestThe day's smaller security stories in brief: Symbiosis's 20% bounty offer to its bridge attacker expired without a reported return, the Revolut extortion campaign has started publishing customer files, and the Liquid Network resumes life with peg-outs still disabled. Plus: the EU's 24-hour disclosure clock starts ticking for wallet makers.
Sep 14, 2026·3 min read
AuditsA CoinGecko report covering January 2025 through July 2026 counts 245 incidents and $3.63 billion in losses. Roughly 88% of stolen funds came from platforms that had completed independent security audits, because most attacks hit what audits do not cover.
Sep 13, 2026·2 min read
Incident AnalysisRevolut disclosed that a fraudulent emergency data request sent from a legitimate government agency email domain led to the release of identity documents, IBANs and full Bitcoin transaction histories. No funds were lost, but the disclosure hands criminals everything needed for targeted impersonation.
Sep 13, 2026·4 min read
Security DigestSunday digest: a Hacken review finds roughly $91 billion of USDT on Tron sits behind a 2-of-3 signing arrangement with no timelock, even as Bluechip upgrades Tether's corporate grade; and Cascade winds down five months after its July vault exploit.
Sep 13, 2026·3 min read
HacksThe cross-chain protocol's deadline for the syBTC mint attacker to return funds expires September 13. About 15 BTC has been recovered so far; after the window, the 20% reward is redirected to anyone providing information leading to recovery.
Sep 13, 2026·2 min read
Incident AnalysisBlockstream has ended negotiations with the party holding 598.5 BTC from the Liquid Network breach, calling the withdrawal 'theft, not white-hat activity.' A volunteer red team separately claims it warned Blockstream before the incident — a claim the company's former CSO disputes.
Sep 12, 2026·3 min read
Incident AnalysisHemi Network's post-mortem confirms a reentrancy flaw in its MerkleBox claim contract let an attacker drain 124.5 million HEMI tokens via a flash-loan-powered recursive loop. The realized loss was small — about $255,000 — but Upbit pulled the token's listing days before launch, and the immutable contract could not be patched.
Sep 12, 2026·3 min read
Security DigestIDScan.net confirmed unauthorized access after an identity-theft service advertised more than 153 million driver's licenses on a cybercrime forum, with the FBI opening an inquiry. Singapore police separately warned of a rise in unauthorized cryptocurrency account access through compromised email accounts.
Sep 12, 2026·3 min read
HacksSymbiosis stopped BTC routing on September 11 after its BridgeV2 contract processed an incorrect cross-chain message and minted a massive unbacked syBTC balance. The attacker converted only about $336,000 into WBTC before the halt — the second Bitcoin-bridging failure inside a week.
Sep 12, 2026·3 min read
Incident AnalysisThe project will delist XRPH and XRPHAI after a key-generation flaw in XRPH Wallet collapsed its keyspace to roughly 2^46, enabling a sweep of about $450,000 from 4,010 wallets. The developer report says a 55-character string passed into an entropy function retained only 16 characters.
Sep 12, 2026·4 min read
Incident AnalysisThe email platform says an attacker invited legitimate users into a rogue organization, then exploited a broken permission boundary to reach 138 customer accounts — including Trezor's, whose fake security alert reached roughly 347,000 subscribers before a 20-minute takedown.
Sep 11, 2026·3 min read
Incident AnalysisFive days after roughly 4,000 BTC left its federation wallet, Liquid has resumed block production and transaction processing under close monitoring. Peg operations remain suspended while the network rebuilds its BTC reserve, and about 598 BTC is still outstanding.
Sep 11, 2026·2 min read
HacksA malicious Super App bypassed liquidation safeguards to create excess G$, exchanging roughly $107,000 out of the reserve backing a universal basic income program with more than 963,000 claimants. The Celo recovery is underway; an unexplained outflow on XDC is not.
Sep 11, 2026·2 min read
SecurityBitrace data shows USDT withdrawals from a Xinbi-linked platform nearly quadrupling in the days after the US action, while rival marketplace Fulilai began purging money-laundering merchants. Chainalysis separately assessed that North Korea-linked actors moved tens of millions through Xinbi vendors.
Sep 11, 2026·2 min read
Security DigestThe day's smaller security stories in brief: Google's threat unit says AI is giving attackers nation-state reach including North Korean crypto theft, a post-mortem reconstructs how half an Ether bought control of Term Labs' vaults, and new analysis of Coinsbuy's August drain highlights what the exchange still hasn't disclosed.
Sep 10, 2026·3 min read
SecurityPhishing emails claiming a critical STM32 entropy flaw in Trezor devices were sent through the company's legitimate email provider, while BitBox says multiple Bitcoin companies appear to have been targeted through a shared newsletter provider. No genuine security advisory was issued by either firm.
Sep 10, 2026·3 min read
SecurityThe blockchain intelligence firm expanded its Series C at a $2 billion valuation with ARR that has quadrupled over three years, as FBI-reported digital crime losses hit $21 billion in 2025 and criminal adoption of AI climbs.
Sep 10, 2026·2 min read
SecurityThe Secret Service froze $52.8 million in USDT across 52 wallets tied to the Telegram-based Xinbi Guarantee marketplace, using Elliptic intelligence, while OFAC designated Xinbi a significant transnational criminal organization and the DOJ seized two wallets and its Telegram channels.
Sep 10, 2026·4 min read
Incident AnalysisThe chain's official accounting says manipulated collateral values generated about $120.4 million in borrowing before validators halted the network — and $9.19 million crossed off Cronos before the rollback could reverse it.
Sep 9, 2026·2 min read
Incident AnalysisOn-chain records show 3,400 BTC (~$270M) returned to the Liquid Federation wallet after last Sunday's ~4,000-BTC drain, with roughly 598 BTC still under the actors' control as Blockstream negotiates for the remainder and the network prepares a coordinated restart.
Sep 9, 2026·2 min read
SecuritySingaporean national Malone Lam admitted organizing an international racketeering enterprise that used social engineering and home break-ins to steal and launder more than $245 million in cryptocurrency, closing a case that began with a single 4,100-BTC theft from a Washington, D.C. resident.
Sep 9, 2026·2 min read
Incident AnalysisOn-chain records show 257.7 million NES (~$50M, a quarter of supply) bridged from Nesa to Ethereum on August 24 via the Cosmos EVM bug chain. Two weeks later the chain's explorer still returns no usable data, and no one has explained what happened.
Sep 9, 2026·3 min read
Security DigestThe day's smaller security stories in brief: hardware wallet makers urge responsible disclosure as AI accelerates bug discovery, Galaxy Research tracks the Coldcard Wave-3 exploiter's first major laundering hop, and a Katowice court approves pretrial detention for a fifth suspect in the Zondacrypto probe.
Sep 9, 2026·3 min read
SecurityAustralia's financial intelligence regulator said it canceled, suspended, or refused to renew 45 remittance and virtual asset provider registrations — including GetCoins, which it links to disruption of alleged organized crypto investment scams. No customer recoveries or criminal findings were disclosed.
Sep 8, 2026·2 min read
SecurityThe team behind the seven-year-old layer-1 says the threat environment has outgrown its ability to defend the network, and proposes migrating ONE to Ethereum. Users with assets in smart contracts are urged to exit before September 10.
Sep 8, 2026·3 min read
SecurityIreland's Criminal Assets Bureau says organized gangs now store seed phrases and private keys in rented vaults alongside cash and watches — a physical-custody twist it has reported to the committee preparing Ireland for stricter EU anti-money-laundering rules.
Sep 8, 2026·2 min read
Incident AnalysisOn-chain data shows the ~4,000 BTC drain cleared the federation's 11-of-15 signing branch as a routine peg-out while the emergency recovery path went unused — and the functionary codebase hadn't received a commit since April 2024. No official root cause has been published.
Sep 8, 2026·4 min read
HacksThe Chilean exchange has begun a permanent shutdown after customer assets were transferred to wallets outside its control. Chile's CMF says it cannot oversee the wind-down or compel repayment, and Orionx has filed a criminal complaint against former executives.
Sep 8, 2026·2 min read
HacksBlockstream's Bitcoin sidechain is paused after roughly 4,000 BTC — about 95% of the federation wallet's balance — was paid out against L-BTC that a software bug in Elements created without backing. No keys were compromised, and the actors responsible claim to be white hats.
Sep 7, 2026·2 min read