No verified new exploits were registered in the last 24 hours in the sources we track. That makes today a good day for the question that sits underneath most of this year's incidents: what does a review actually cover?

Two of today's pieces address it directly. The ack3 H1 2026 study found that where exploited DeFi projects had audits at all, 94.4% of reported losses came from attack paths outside every identified audit scope (72.1% after excluding the two largest incidents). And our incident analysis of the ICON Network replay exploit shows the failure mode up close: a withdrawal path that passed multiple component reviews while its two ends disagreed about which bits made a message unique.

The third piece maps the attackers: Sekoia and Kudelski Security's clustering of North Korea's cyber apparatus into six units, with the former APT38 lineage now concentrated in two clusters aimed at crypto and Web3 targets.

Below, the current state of every major incident still open, as of the latest verified reporting.

Liquid Network: Day 13

Peg-outs to native Bitcoin remain shut down roughly thirteen days after about 4,000 BTC left federation reserves through the Elements proof-verification cache flaw. The self-described white hats returned about 3,400 BTC; 598.50 BTC — on the order of $45 million — remains in their wallet, and reporting as of September 17 confirms Blockstream has not moved from its refusal of the bounty demand. Internal transactions and block production continue. The open question is unchanged: at what collateralization level peg-outs can responsibly reopen.

Chainflip: Network Restart Unconfirmed, Reimbursements Unexecuted

The cross-chain swap protocol's public updates still leave the funding source, the payout plan, completed payments and a final confirmed reimbursement amount open, follow-up coverage notes — even as the protocol has committed to fully compensating affected providers from the September 12 TRON memo exploit, in which 736,442.17 USDT left vaults. A restart plan was promised for "Monday at the earliest" in the September 13 update; no public confirmation of a completed restart has appeared in the sources we track.

Kelp DAO: No Resolution Announced

The wallet-level pause Kelp DAO placed on the MEV-captured rsETH expired around 06:00 UTC on September 16, and the issuer has since announced neither an extension, a return of funds by the bot operator, nor a compensation path for the victim of the $7.8 million Safe-module theft. Core rsETH contracts remain unaffected and the token fully collateralized, per the issuer. The funds stay immobilized only as long as issuer-level restrictions — or the holder's goodwill — hold.

Swiss Bitcoin Pay: Still Dark

The non-custodial Bitcoin payment processor's infrastructure remains offline following the suspected intrusion disclosed September 14, with no restoration date announced. The company continues to assert that funds and private keys are unaffected, while customer relationship data — emails, Bitcoin addresses, IBANs, transaction histories, hashed passwords — may have been exposed. Merchants should stay alert to phishing that leverages that data.

Revolut: Investigation Continues, Extortion Still Unverified

Follow-up reporting holds at roughly 680–700 affected customers across 33 countries, most in Switzerland and France, after fraudulent government data requests traced to a mailbox on Italy's certified PEC network. Italian authorities are investigating; Revolut says it reported the matter upon detection. The reported 10,000 BTC extortion demand remains unverified, and the leaked material is still unauthenticated.

Brief: SecondFI Rolls Out Cardano Recovery Tool in Stages

SecondFI, the self-custody platform whose June exploit drained roughly $2 million across 374 Cardano wallets through a deterministic-nonce flaw in its software signer, has disclosed a staged asset-recovery tool: affected users generate zero-knowledge proofs of wallet control in-browser, without exposing seed phrases or derivation paths. The company says zkSecurity's independent review of the proof-tool repository, commissioned August 3, surfaced two high-severity issues in upstream code — both now fixed — and that a further review of the smart contract that will execute recoveries is planned before the tool opens fully. The rollout posture is cautious by design; the details are as reported by the company via AMBCrypto and have not been independently audited by this publication.

TrustGrade tracks the security posture of wallet vendors, protocols, and exchanges. Security scans with verified, registry-backed scores arrive with TrustGrade Code Scoring in December 2026.