Today's lead: the EU Cyber Resilience Act's 24-hour exploit disclosure obligation is now in force for crypto wallet makers selling into the bloc. The rest of the day's security news, in brief:
Symbiosis: Bounty Window Expires, Informant Reward Takes Over
The white-hat window Symbiosis offered to the attacker behind its unbacked syBTC mint expired at the end of September 13 with no return of funds publicly announced. The protocol had proposed a 20% reward if the attacker returned the stolen assets by that date; with the deadline passed, the same 20% is now directed at anyone whose information leads to recovery.
Where things stand, per The Block and crypto.news: approximately 15 BTC — worth about $1.15 million at current prices — has been recovered and sits in a team-controlled multisig wallet. BTC routes on the cross-chain protocol remain halted, while EVM chains, TRON, TON and other routes continue operating and the relayer group still secures the network. Terms for affected liquidity providers had not been announced as of publication.
The realized loss remains small relative to the mint: recall that the BridgeV2 bug let the attacker conjure roughly 46.1 billion syBTC, but liquidity — not the mint — capped the take at an estimated $219,000–$336,000 depending on the tracker. Our earlier coverage of the initial exploit and the bounty structure has the details.
Revolut: Attackers Start Publishing, Demand Payment
The extortion campaign that followed last week's Revolut data disclosure has moved to its next stage. Threat actors who obtained customer files through the fraudulent government data request have reportedly begun posting the material online — including selfies and identity documents belonging to tennis player Alexander Shevchenko and Gamdom CEO Felix Römer, according to an International Cyber Digest post cited by Cointelegraph — and threatened on Telegram to release more data every day "until revolut pays."
Revolut has characterized the breach as a "sophisticated external impersonation scam" in which the attacker submitted fraudulent information requests from a legitimate government agency email domain. The company says a "limited number" of customers were affected and that its systems and customer funds are unaffected. No payment demand timeline or amount has been confirmed, and Revolut has not named the agency involved, citing the ongoing police investigation.
The escalation matters for crypto users specifically because of what the leaked files connect: verified identity to full Bitcoin transaction histories — the raw material for targeted impersonation and social-engineering attacks. Our incident analysis of the original disclosure covers the mechanics and the exposure pattern.
Liquid Network: One Week On, Blocks Flow, Peg-Outs Don't
Seven days after roughly 4,000 BTC (~$320 million) left the federation's reserves, the Liquid Network is producing blocks and processing internal transactions — but Bitcoin peg-outs remain disabled, leaving LBTC holders unable to withdraw to the mainchain.
The arithmetic is the reason. About 3,400 BTC was returned by the self-described white hats, leaving roughly 598 BTC outstanding; with the network reported to be around 85% collateralized, opening peg-outs at full parity is not currently possible. Blockstream has publicly refused the attackers' demand for a bounty on the remaining funds, leaning instead on law enforcement and forensic partners, and shipped Elements 23.3.4 as the emergency fix for the proof-verification cache bug at the root of the incident. Our coverage of the post-mortem, the return of funds and the ransom refusal tracks the full sequence.
The identity and motive of the actors remain unconfirmed. They claim a red-team posture; the 598 BTC they kept, and the bounty they demanded for it, sit awkwardly next to that claim.
TrustGrade tracks the security posture of wallet vendors, protocols, and exchanges. Security scans with verified, registry-backed scores arrive with TrustGrade Code Scoring in December 2026.