SecurityAttackers posing as government officials obtained data on roughly 680 high-value crypto customers from Revolut over five months, reports say, and are now demanding about $3 million in Monero — a breach that turns holder anonymity into a physical-security problem.
Sep 22, 2026·2 min read
Security DigestThe week's smaller security stories in brief: a manipulated NSTR price feed let one account borrow $3.5 million from Nostra on Starknet, the Yoink MEV bot front-ran a $7.8 million rsETH theft on Ethereum, and trackers tally roughly $20 million in incident losses across seven days.
Sep 22, 2026·2 min read
SecurityBinance Wallet issued an urgent advisory after SlowMist and OKX found that FomoPeek versions 1.1 and 1.2 — distributed through the official App Store — contained an iOS kernel exploitation framework able to escape the sandbox, decrypt Keychain data and harvest private keys and seed phrases from other apps. Version 1.3 removed the code; anyone who ran the affected versions is advised to rebuild their wallet on a clean device.
Sep 21, 2026·3 min read
Incident AnalysisThe Radix Foundation's public incident report traces the August 31 theft of roughly $1.3 million to a vault-authorization flaw introduced during a June 2023 code cleanup — a defect that survived a 2024 Zellic audit and was only contained after validators deliberately broke network liveness for more than ten days. The Foundation said the attacker appeared to use AI-assisted code-analysis tools to find the gap.
Sep 21, 2026·4 min read
SecurityZimperium zLabs analyzed a new Android remote-access trojan that enables Wireless Debugging for shell-level access, installs a persistent Go agent, and feeds the live accessibility tree to an AI assistant to navigate infected devices — with credential overlays aimed at banking and cryptocurrency applications. Attribution to China-based operators is suspected, based on Chinese-language AI prompts, and remains unconfirmed.
Sep 21, 2026·3 min read
Security DigestThis week's freshest attacks converge on the last meter between a user and their assets: an iOS app that shipped a kernel-exploitation framework through the App Store, an Android RAT that navigates infected phones with an AI assistant, and — in northern France — a family tied up at home while attackers forced a €40,000 transfer. Plus the status board: Liquid, Chainflip, Revolut, Kelp DAO, Swiss Bitcoin Pay and Fetch.ai — no new verified developments.
Sep 21, 2026·2 min read
HacksA single attacker drained 8.7 million FET (about $1.53 million) from a Fetch.ai token converter contract, then used the same wallet to mint 408.5 million unauthorized NTX through NuNet's deployer account — roughly $2 million combined. SlowMist traces the Fetch.ai root cause to an authorization gap in TokenConversionManagerV3's conversionIn(). Neither team has issued an official statement.
Sep 20, 2026·3 min read
SecurityOFAC designated the Iranian crypto exchange BitBank, its developers and three associates on September 18, alleging the network transferred hundreds of millions of dollars in Bitcoin to the Islamic Revolutionary Guard Corps. The action extends the Operation Economic Outcast campaign that earlier sanctioned Shelbit and Aban — and all allegations remain unadjudicated.
Sep 20, 2026·2 min read
Security DigestToday's thread is authorization: the Fetch.ai exploit trusted one signature where the contract should have demanded more, the S&P–OpenZeppelin deal prices exactly that kind of assurance, Gyazo's metadata leak shows what happens when the proof behind a link leaks, and Japan's NPA officially attributes the ¥1.7B WaterPlum campaign. Plus the status board: Liquid peg-outs, Chainflip claims, Revolut extortion, Kelp DAO, Swiss Bitcoin Pay — all unchanged.
Sep 20, 2026·3 min read
AuditsS&P Global has agreed to acquire the smart contract security firm OpenZeppelin and will run it as a business unit reporting to S&P Global Ratings. Terms were undisclosed. The deal merges code-level security assurance with issuer-level ratings under one division — the clearest signal yet that on-chain code quality is being treated as rated credit infrastructure.
Sep 20, 2026·3 min read
SecurityInput Output Group told users to avoid its YouTube channel on September 18 after an apparent takeover carried a roughly two-hour livestream — dressed as a Project Catalyst town hall — in which a suspected AI-manipulated Charles Hoskinson promised to 'double your wealth' via a QR code. No losses have been verified.
Sep 19, 2026·2 min read
HacksThe London-based crypto technology provider said a group attacked Haruko itself, exploiting a process vulnerability to extract an access token and capture read-only exchange API details from memory. All 15 affected clients were those without IP whitelisting — and a small amount of their funds was stolen, according to people familiar with the incident.
Sep 19, 2026·3 min read
Security DigestToday's stories share one mechanism: attackers operating inside channels victims already trust — a recruiter's coding task, an official YouTube channel, a vendor's own access token, a certified police mailbox. Plus the status board: Liquid peg-outs still paused at day 14, Chainflip's restart resets TRON provider balances to on-chain claims, the Revolut extortionists' countdown expires, Kelp DAO and Swiss Bitcoin Pay unchanged — and the Symbiosis root cause lands as a two-bug report.
Sep 19, 2026·4 min read
SecurityA September 18 joint advisory from Japanese, US, Australian and German agencies says WaterPlum — widely known as Contagious Interview — infected 30,000+ devices across 100+ countries and drained at least $10.7 million from crypto wallets between December 2025 and July 2026, using fake job interviews aimed at developers.
Sep 19, 2026·3 min read
AuditsA preprint from ack3-affiliated researchers and Czech Technical University examined 135 DeFi incidents from H1 2026 ($939.86M in losses) and found that where audits existed, 94.4% of reported losses came from attack paths outside every identified audit scope — though two large incidents dominate the figure.
Sep 18, 2026·3 min read
Incident AnalysisICON Foundation's post-mortem of the August 27 replay exploit traces the loss to an integer-precision defect: the uniqueness check validated unsigned high bits of a serial number while the signature covered only the low 256 bits — a boundary two audits never crossed.
Sep 18, 2026·3 min read
Security DigestToday's edition is organized around one theme: the gap between what was reviewed and what was deployed. Plus the status board — Liquid peg-outs still frozen at day 13, Chainflip reimbursements still unexecuted, Kelp DAO still silent since the freeze expired, Swiss Bitcoin Pay still dark, and SecondFI rolls out a recovery tool in stages.
Sep 18, 2026·3 min read
SecurityA September 7 joint analysis by Sekoia and Kudelski Security maps North Korea's offensive cyber operations into six distinct clusters — with the former APT38 lineage now concentrated in two units focused on cryptocurrency, Web3 and blockchain targets.
Sep 18, 2026·2 min read
Incident AnalysisChainflip lost 736,442.17 USDT after an attacker attached new memos to already-signed TRON transfers, tricking the protocol into paying twice against single deposits. The September 12 incident, confirmed by the protocol itself, exposed an instruction channel most chains never use — and the network is still paused.
Sep 17, 2026·3 min read
SecurityPhishing pages impersonating Cloudflare verification screens are being planted in token metadata fields on aggregator listings, then instructing victims to run a payload with administrator privileges on Windows. One trader reported losing about $600,000. The campaign skips wallet approvals entirely — it asks for code execution instead.
Sep 17, 2026·3 min read
Security DigestToday's two research stories share one theme: campaigns that never touch a wallet approval. Plus the status board — Liquid at day 12 with 598.5 BTC still held, the Kelp freeze window expired with no announced resolution, Chainflip still paused, and follow-up reporting puts the Revolut breach at about 680 high-value accounts.
Sep 17, 2026·3 min read
SecurityNine near-identical YouTube tutorials promising a Claude-built arbitrage bot walked 224 victims into deploying and funding malicious contracts themselves — 274.60 ETH, about $517,000, drained between February and August 2026. No phishing link, no spoofed domain, no approval prompt: wallet defenses never fire.
Sep 17, 2026·3 min read
SecurityFederal prosecutors in Manhattan say Hefu Chai and Huaisong Xiang misappropriated confidential information about upcoming Robinhood Crypto listings and traded perpetual futures ahead of public announcements. The case is a reminder that listing calendars are among an exchange's most sensitive security assets — and that trading-venue integrity now reaches into DeFi.
Sep 16, 2026·2 min read
HacksA leveraged rsETH position was drained from a Gnosis Safe through an over-permissioned custom module routed into an attacker-controlled Uniswap v4 pool. A generalized MEV bot front-ran the exploit in the same block and captured the tokens, and Kelp DAO froze the receiving address. Security firms are unanimous: this was module-authorization abuse, not a flaw in Safe core.
Sep 16, 2026·3 min read
SecurityThe $7.8M loss reconstructed by Blockaid, SlowMist and BlockSec came down to one over-permissioned helper contract the Safe owner had whitelisted. The pattern — attacks moving to the edges around well-reviewed core contracts — has been visible since Bybit, and it has specific implications for how modules should be reviewed, scoped and monitored.
Sep 16, 2026·3 min read
Security DigestOne lead story — the rsETH Safe-module theft front-run by an MEV bot — plus a consolidated status board for every major security incident still in motion: Liquid Network peg-outs frozen, Symbiosis hunting its attacker, Swiss Bitcoin Pay offline, the Revolut extortion, and the Kelp DAO freeze watch.
Sep 16, 2026·2 min read
SecurityProsecutors in Manhattan filed a civil forfeiture complaint against nearly $61 million in cryptocurrency they allege is proceeds of black-market sales of sanctioned Iranian oil, moved through Binance accounts by two China-based companies as part of a network that handled over $1.5 billion.
Sep 15, 2026·3 min read
Incident AnalysisThe actors behind the fraudulent government data request have escalated to extortion, reportedly demanding roughly $780 million in Bitcoin and threatening daily data dumps. Revolut has not confirmed the demand or authenticated the leaked files.
Sep 15, 2026·3 min read
Security DigestThe day's smaller security stories in brief: Solana Mobile is the second big crypto name confirmed in the Brevo SSO breach, the Liquid Network begins its second week with peg-outs still frozen, and Symbiosis shifts from white-hat bounty to informant reward. Plus a status board on the Revolut extortion.
Sep 15, 2026·2 min read
HacksThe Swiss non-custodial Bitcoin payment processor detected likely unauthorized access to its internal systems and shut down its entire infrastructure as a precaution. Emails, Bitcoin addresses, IBANs, transaction histories and hashed passwords may have been exposed; the company says funds and private keys are unaffected.
Sep 15, 2026·3 min read