Today's lead is a pattern, not a single incident. Both research pieces published this morning — TRM Labs' fake AI trading bot tutorials and the fake Cloudflare verification pages targeting meme coin traders — describe attacks engineered so that wallet warnings, approval analysis and phishing blocklists never trigger. One gets the victim to deploy the malicious contract themselves; the other gets them to run malware on their own machine. The industry's defensive stack is built around the moment of signing — and both campaigns simply skip that moment. Our analysis of the Chainflip TRON memo exploit, a different failure class but the same perimeter problem, is also live today. Below, the current state of every major incident still open, as of the latest verified reporting.
Liquid Network: Day 12
Peg-outs to native Bitcoin remain disabled roughly twelve days after about 4,000 BTC left federation reserves through the Elements proof-verification cache flaw. The self-described white hats returned about 3,400 BTC; 598.5 BTC — on the order of $47 million — remains in their wallet. German-language coverage this week describes the standoff as effectively silent since Blockstream refused the bounty demand, while the company's stated commitment to restoring the 1:1 peg has steadied L-BTC sentiment in the meantime. Internal transactions and block production continue. The open question is unchanged: at what collateralization level peg-outs can responsibly reopen. Our latest status piece is here.
Kelp DAO: Freeze Window Expired, No Announced Resolution
The 24-hour wallet-level pause Kelp DAO placed on the address holding the MEV-captured rsETH expired around 06:00 UTC on September 16. As of press time, the issuer has announced neither an extension, a return of funds by the bot operator, nor a compensation path for the victim of the $7.8 million Safe-module theft. Core rsETH contracts remain unaffected and the token fully collateralized, per Kelp DAO. The funds stay immobilized only as long as issuer-level restrictions — or the holder's goodwill — hold.
Chainflip: Paused Since September 12
The cross-chain swap protocol's network remains halted following the 736,442.17 USDT memo exploit. The fix is finalized and a restart plan was promised "Monday at the earliest" in the September 13 update; no public confirmation of a completed restart had appeared in the sources reviewed as of today. One legitimate swap worth 115,654.41 USDT sits pending in the vault, and the reimbursement method for affected users is still unpublished.
Symbiosis: Informant Reward Active
The white-hat window for the unbacked syBTC mint closed with no return of funds. The 20% reward now applies to anyone whose information leads to recovery, BTC routes remain halted, and roughly 15 BTC sits recovered in a team-controlled multisig. Our coverage of the bounty-window close is here.
Swiss Bitcoin Pay: Still Dark
The non-custodial Bitcoin payment processor's infrastructure remains offline following the suspected intrusion disclosed September 14, with no restoration date announced. The company continues to assert that funds and private keys are unaffected, while customer relationship data — emails, Bitcoin addresses, IBANs, transaction histories, hashed passwords — may have been exposed. Merchants should remain alert to phishing that leverages that data. Full report here.
Revolut: About 680 Accounts, Per Follow-Up Reporting
Follow-up reporting across outlets now puts the number of affected customers at roughly 680 to 700 — most based in Switzerland and France, spread across 33 countries — after hackers claimed they obtained personal data on high-net-worth crypto accounts selected through prior blockchain analysis. The fraudulent requests were traced to a mailbox on Italy's certified PEC network tied to the Interior Ministry domain; Italian authorities are investigating, and Revolut says it reported the matter upon detection. The reported 10,000 BTC extortion demand remains unverified, and the leaked material itself is still unauthenticated.
TrustGrade tracks the security posture of wallet vendors, protocols, and exchanges. Security scans with verified, registry-backed scores arrive with TrustGrade Code Scoring in December 2026.