Today's lead: an attacker drained $7.8 million in rsETH from a Gnosis Safe through an over-permissioned module — and an MEV bot front-ran the theft in the same block. Our technical analysis of the module-authorization failure is also live today. Below, the current state of every major incident still open, as of the latest verified reporting.
Kelp DAO Freeze Watch
The 24-hour wallet-level pause Kelp DAO placed on the address holding the front-run rsETH was due to expire around 06:00 UTC today. At press time, the issuer had announced neither an extension, a return of funds by the bot operator, nor a compensation path. The core rsETH contracts remain unaffected and the token fully collateralized, per Kelp DAO. The funds stay immobilized only as long as the issuer-level restriction — or the holder's goodwill — holds.
Liquid Network: Day 10
Bitcoin peg-outs remain disabled in the Liquid Network's second week since roughly 4,000 BTC left federation reserves through the Elements proof-verification cache bug. Internal transactions and block production continue. About 3,400 BTC was returned by the self-described white hats, leaving roughly 598 BTC outstanding against a network reported to be around 85% collateralized. Blockstream has refused the attackers' bounty demand and is working with law enforcement. The open question remains the collateralization decision that governs when — and at what parity — peg-outs can reopen. Our latest status piece is here.
Symbiosis: Informant Reward Active
The cross-chain protocol's white-hat window has closed with no return of the funds behind the unbacked syBTC mint. The 20% reward originally offered to the attacker is now directed at anyone whose information leads to recovery, and BTC routes remain halted. Roughly 15 BTC sits recovered in a team-controlled multisig. Our coverage of the bounty-window close is here.
Swiss Bitcoin Pay: Still Dark
The non-custodial Bitcoin payment processor's entire server infrastructure remains offline after the suspected intrusion disclosed September 14, with no restoration date announced. The company continues to assert that funds and private keys are unaffected, while emails, Bitcoin addresses, IBANs, transaction histories and hashed passwords may have been exposed. Merchants relying on the service should stay alert for phishing that leverages the exposed relationship data. Our full report is here.
Revolut: Extortion Demand Unverified
The actors behind the fraudulent government data request are reportedly demanding 10,000 BTC and threatening daily data dumps. Revolut has not confirmed the demand or authenticated the leaked files, and the police investigation continues. Until the company or investigators validate the material, the extortion claims should be treated as unverified. Our analysis of the escalation is here.
TrustGrade tracks the security posture of wallet vendors, protocols, and exchanges. Security scans with verified, registry-backed scores arrive with TrustGrade Code Scoring in December 2026.