Every incident in today's digest turns on the same object: proof that a request is legitimate. The Fetch.ai and NuNet exploits succeeded because one function trusted a single ECDSA signature where its sibling demanded bound checks — $2 million rode on the gap between those two designs. The S&P Global–OpenZeppelin acquisition is the market pricing that class of assurance: a ratings firm just bought the company whose libraries and audits certify that code does what it says. And the Gyazo breach below shows the inverse problem — when the metadata that authenticates access to private content leaks at scale, every derived link becomes a credential.
Brief: Gyazo Breach Exposes 23.6M User Records, 490M Image Records
Gyazo, the screenshot service owned by Japan's Helpfeel, disclosed that an attacker exploited a vulnerability in its image upload server on September 11 and was expelled the next day — after accessing a database of approximately 23.62 million user records and metadata associated with roughly 490 million images, SecurityWeek, The Hacker News and Security Affairs report.
The exposure includes the IDs used to construct image URLs, meaning private screenshots — for crypto users, often terminal dashboards, wallet screens, exchange interfaces or internal documents — could potentially be reached by anyone holding the leaked identifiers. No phishing or extortion campaign using the data has been confirmed; until one is, the working assumption should be that anything ever screenshotted through the service is recoverable by a third party, and inbound messages referencing old screenshots deserve extra scrutiny.
Brief: Japan's NPA Officially Attributes ¥1.7B Theft Campaign to North Korea
Japan's National Police Agency said a North Korean hacker group was behind a cyberattack campaign spanning more than 100 countries that stole cryptocurrency worth about ¥1.7 billion — consistent with the $10.7 million+ figure in last week's joint advisory — The Japan Times reports. The statement converts the WaterPlum attribution from industry assessment to official government position. The WaterPlum advisory remains the practical reference: fake recruiter interviews delivering malicious coding tasks, 30,000+ infected devices.
Brief: CACEIS EURXT Audit Report Published
OpenZeppelin Security published its audit report for CACEIS's EURXT stablecoin contracts on September 15: three findings, zero critical, zero resolved at publication. A published report with unresolved findings is not a scandal — it is the artifact trust decisions should read. The full report is on OpenZeppelin's site; the resolution status is what to watch.
Status Board
Liquid Network: No new verified developments since the September 18 update — peg-outs remain paused; ~598.5 BTC (roughly $45 million) still with the attacker; ~3,400 BTC of the roughly 4,000 BTC drained has been returned to federation reserves.
Chainflip: No new verified developments. TRON USDT provider balances remain converted to on-chain claims under the restart plan; reimbursement funding source and payout mechanics still publicly undefined.
Revolut: No confirmed sale of the stolen customer files after the extortion countdown expired; the group's identity remains unverified; Italian prosecutors' inquiry continues.
Kelp DAO: No announcement on the MEV-captured rsETH. The $7.8 million remains immobilized at the issuer-paused wallet level; core rsETH contracts remain unaffected per the issuer.
Swiss Bitcoin Pay: Infrastructure remains offline following the suspected intrusion disclosed September 14, with no restoration date announced. Treat inbound contact referencing customer data as potential phishing.
TrustGrade tracks the security posture of protocols, providers and exchanges. Registry-backed security scoring arrives with TrustGrade Code Scoring in December 2026.