Latest News

Security

DOJ Charges Two Former Robinhood Engineers Over Alleged Listing Front-Running on Hyperliquid

Federal prosecutors in Manhattan say Hefu Chai and Huaisong Xiang misappropriated confidential information about upcoming Robinhood Crypto listings and traded perpetual futures ahead of public announcements. The case is a reminder that listing calendars are among an exchange's most sensitive security assets — and that trading-venue integrity now reaches into DeFi.

Sep 16, 2026·2 min read
Hacks

Attacker Drains $7.8M in rsETH From Ethereum Safe — and an MEV Bot Takes It First

A leveraged rsETH position was drained from a Gnosis Safe through an over-permissioned custom module routed into an attacker-controlled Uniswap v4 pool. A generalized MEV bot front-ran the exploit in the same block and captured the tokens, and Kelp DAO froze the receiving address. Security firms are unanimous: this was module-authorization abuse, not a flaw in Safe core.

Sep 16, 2026·3 min read
Security

The rsETH Theft Is the Latest Warning About Smart-Wallet Modules

The $7.8M loss reconstructed by Blockaid, SlowMist and BlockSec came down to one over-permissioned helper contract the Safe owner had whitelisted. The pattern — attacks moving to the edges around well-reviewed core contracts — has been visible since Bybit, and it has specific implications for how modules should be reviewed, scoped and monitored.

Sep 16, 2026·3 min read
Security Digest

Security Digest: The Ongoing-Incident Tracker for September 16

One lead story — the rsETH Safe-module theft front-run by an MEV bot — plus a consolidated status board for every major security incident still in motion: Liquid Network peg-outs frozen, Symbiosis hunting its attacker, Swiss Bitcoin Pay offline, the Revolut extortion, and the Kelp DAO freeze watch.

Sep 16, 2026·2 min read
Hacks

Swiss Bitcoin Pay Takes All Servers Offline After Suspected Intrusion

The Swiss non-custodial Bitcoin payment processor detected likely unauthorized access to its internal systems and shut down its entire infrastructure as a precaution. Emails, Bitcoin addresses, IBANs, transaction histories and hashed passwords may have been exposed; the company says funds and private keys are unaffected.

Sep 15, 2026·3 min read
Security

EU Cyber Resilience Act Puts Crypto Wallet Makers on a 24-Hour Exploit Disclosure Clock

The Cyber Resilience Act's vulnerability and incident reporting obligations took effect September 11, 2026. Wallet manufacturers selling into the EU must now warn ENISA within 24 hours of learning a flaw is being actively exploited — a legal deadline that would have reshaped this year's Coldcard, Trezor and Liquid disclosures.

Sep 14, 2026·3 min read
Security Digest

Security Digest: Symbiosis White-Hat Window Closes, Revolut Attackers Begin Leaking, Liquid Marks One Week With Peg-Outs Frozen

The day's smaller security stories in brief: Symbiosis's 20% bounty offer to its bridge attacker expired without a reported return, the Revolut extortion campaign has started publishing customer files, and the Liquid Network resumes life with peg-outs still disabled. Plus: the EU's 24-hour disclosure clock starts ticking for wallet makers.

Sep 14, 2026·3 min read
Incident Analysis

Revolut Handed Customer Passports and Bitcoin Records to a Fake Government Request

Revolut disclosed that a fraudulent emergency data request sent from a legitimate government agency email domain led to the release of identity documents, IBANs and full Bitcoin transaction histories. No funds were lost, but the disclosure hands criminals everything needed for targeted impersonation.

Sep 13, 2026·4 min read
Security Digest

Security Digest — September 12, 2026: KYC Vendor IDScan.net Confirms Breach Behind 153M-License Dark Web Trove; Singapore Police Warn on Crypto Account Takeovers

IDScan.net confirmed unauthorized access after an identity-theft service advertised more than 153 million driver's licenses on a cybercrime forum, with the FBI opening an inquiry. Singapore police separately warned of a rise in unauthorized cryptocurrency account access through compromised email accounts.

Sep 12, 2026·3 min read