Chainflip's $736K TRON Exploit Was a Memo Problem, Not a Bridge Break
Chainflip lost 736,442.17 USDT after an attacker attached new memos to already-signed TRON transfers, tricking the protocol into paying twice against single deposits. The September 12 incident, confirmed by the protocol itself, exposed an instruction channel most chains never use — and the network is still paused.
Latest News
DOJ Charges Two Former Robinhood Engineers Over Alleged Listing Front-Running on Hyperliquid
Federal prosecutors in Manhattan say Hefu Chai and Huaisong Xiang misappropriated confidential information about upcoming Robinhood Crypto listings and traded perpetual futures ahead of public announcements. The case is a reminder that listing calendars are among an exchange's most sensitive security assets — and that trading-venue integrity now reaches into DeFi.
Attacker Drains $7.8M in rsETH From Ethereum Safe — and an MEV Bot Takes It First
A leveraged rsETH position was drained from a Gnosis Safe through an over-permissioned custom module routed into an attacker-controlled Uniswap v4 pool. A generalized MEV bot front-ran the exploit in the same block and captured the tokens, and Kelp DAO froze the receiving address. Security firms are unanimous: this was module-authorization abuse, not a flaw in Safe core.
The rsETH Theft Is the Latest Warning About Smart-Wallet Modules
The $7.8M loss reconstructed by Blockaid, SlowMist and BlockSec came down to one over-permissioned helper contract the Safe owner had whitelisted. The pattern — attacks moving to the edges around well-reviewed core contracts — has been visible since Bybit, and it has specific implications for how modules should be reviewed, scoped and monitored.
Security Digest: The Ongoing-Incident Tracker for September 16
One lead story — the rsETH Safe-module theft front-run by an MEV bot — plus a consolidated status board for every major security incident still in motion: Liquid Network peg-outs frozen, Symbiosis hunting its attacker, Swiss Bitcoin Pay offline, the Revolut extortion, and the Kelp DAO freeze watch.
DOJ Moves to Forfeit $61M in Crypto Tied to Alleged Iranian Oil Laundering Through Binance
Prosecutors in Manhattan filed a civil forfeiture complaint against nearly $61 million in cryptocurrency they allege is proceeds of black-market sales of sanctioned Iranian oil, moved through Binance accounts by two China-based companies as part of a network that handled over $1.5 billion.
Revolut Attackers Reportedly Demand 10,000 BTC as Customer Data Leaks Continue
The actors behind the fraudulent government data request have escalated to extortion, reportedly demanding roughly $780 million in Bitcoin and threatening daily data dumps. Revolut has not confirmed the demand or authenticated the leaked files.
Security Digest: Solana Mobile Confirms Brevo Account Access, Liquid Peg-Outs Enter Week Two, Symbiosis Hunt Goes On
The day's smaller security stories in brief: Solana Mobile is the second big crypto name confirmed in the Brevo SSO breach, the Liquid Network begins its second week with peg-outs still frozen, and Symbiosis shifts from white-hat bounty to informant reward. Plus a status board on the Revolut extortion.
Swiss Bitcoin Pay Takes All Servers Offline After Suspected Intrusion
The Swiss non-custodial Bitcoin payment processor detected likely unauthorized access to its internal systems and shut down its entire infrastructure as a precaution. Emails, Bitcoin addresses, IBANs, transaction histories and hashed passwords may have been exposed; the company says funds and private keys are unaffected.
EU Cyber Resilience Act Puts Crypto Wallet Makers on a 24-Hour Exploit Disclosure Clock
The Cyber Resilience Act's vulnerability and incident reporting obligations took effect September 11, 2026. Wallet manufacturers selling into the EU must now warn ENISA within 24 hours of learning a flaw is being actively exploited — a legal deadline that would have reshaped this year's Coldcard, Trezor and Liquid disclosures.
Security Digest: Symbiosis White-Hat Window Closes, Revolut Attackers Begin Leaking, Liquid Marks One Week With Peg-Outs Frozen
The day's smaller security stories in brief: Symbiosis's 20% bounty offer to its bridge attacker expired without a reported return, the Revolut extortion campaign has started publishing customer files, and the Liquid Network resumes life with peg-outs still disabled. Plus: the EU's 24-hour disclosure clock starts ticking for wallet makers.
CoinGecko Tally: $3.63 Billion Lost to Hacks in 19 Months — 88% of It From Audited Platforms
A CoinGecko report covering January 2025 through July 2026 counts 245 incidents and $3.63 billion in losses. Roughly 88% of stolen funds came from platforms that had completed independent security audits, because most attacks hit what audits do not cover.
Revolut Handed Customer Passports and Bitcoin Records to a Fake Government Request
Revolut disclosed that a fraudulent emergency data request sent from a legitimate government agency email domain led to the release of identity documents, IBANs and full Bitcoin transaction histories. No funds were lost, but the disclosure hands criminals everything needed for targeted impersonation.
Security Digest — September 13, 2026: Hacken Scores Tether's Key Management 3.3/10; Cascade Shuts Down After CLS Vault Exploit
Sunday digest: a Hacken review finds roughly $91 billion of USDT on Tron sits behind a 2-of-3 signing arrangement with no timelock, even as Bluechip upgrades Tether's corporate grade; and Cascade winds down five months after its July vault exploit.
Symbiosis White-Hat Bounty Window Closes Today — 20% Reward, Then the Informant Rate
The cross-chain protocol's deadline for the syBTC mint attacker to return funds expires September 13. About 15 BTC has been recovered so far; after the window, the 20% reward is redirected to anyone providing information leading to recovery.
Blockstream Refuses Ransom for Remaining 598 BTC as Liquid Hackers Demand a 10% 'Bounty'
Blockstream has ended negotiations with the party holding 598.5 BTC from the Liquid Network breach, calling the withdrawal 'theft, not white-hat activity.' A volunteer red team separately claims it warned Blockstream before the incident — a claim the company's former CSO disputes.
Hemi's Genesis Drop Post-Mortem: A Decade-Old Reentrancy Bug Drained 124.5 Million Tokens for $255,000
Hemi Network's post-mortem confirms a reentrancy flaw in its MerkleBox claim contract let an attacker drain 124.5 million HEMI tokens via a flash-loan-powered recursive loop. The realized loss was small — about $255,000 — but Upbit pulled the token's listing days before launch, and the immutable contract could not be patched.
Security Digest — September 12, 2026: KYC Vendor IDScan.net Confirms Breach Behind 153M-License Dark Web Trove; Singapore Police Warn on Crypto Account Takeovers
IDScan.net confirmed unauthorized access after an identity-theft service advertised more than 153 million driver's licenses on a cybercrime forum, with the FBI opening an inquiry. Singapore police separately warned of a rise in unauthorized cryptocurrency account access through compromised email accounts.
Symbiosis Halts Bitcoin Bridge After Unbacked syBTC Mint, Realized Loss Near $336,000
Symbiosis stopped BTC routing on September 11 after its BridgeV2 contract processed an incorrect cross-chain message and minted a massive unbacked syBTC balance. The attacker converted only about $336,000 into WBTC before the halt — the second Bitcoin-bridging failure inside a week.
XRP Healthcare Winds Down After Wallet Keyspace Flaw Drained $450K From 4,000 Users
The project will delist XRPH and XRPHAI after a key-generation flaw in XRPH Wallet collapsed its keyspace to roughly 2^46, enabling a sweep of about $450,000 from 4,010 wallets. The developer report says a 55-character string passed into an entropy function retained only 16 characters.
Brevo Post-Mortem: SSO Authorization Flaw Behind the Trezor and BitBox Phishing Wave
The email platform says an attacker invited legitimate users into a rogue organization, then exploited a broken permission boundary to reach 138 customer accounts — including Trezor's, whose fake security alert reached roughly 347,000 subscribers before a 20-minute takedown.