Three of today's stories arrive through the same door. The WaterPlum advisory describes theft delivered as a hiring process — the coding task was the malware. The Haruko breach ran through the vendor's own valid access token, extracted from a process clients never saw. And the Cardano YouTube hijack needed no fake account, because the real one was better. The through-line is that none of these attacks required defeating a security boundary in the conventional sense — each borrowed a channel the target already trusted, and let legitimacy do the work.
Below, the current state of every major incident still open, as of the latest verified reporting.
Liquid Network: Day 14, Peg-Outs Still Paused
In a September 18 update, the Liquid Network confirmed that block production and L-BTC transfers have operated normally since September 10, while peg-out redemptions to native Bitcoin remain suspended as the network works with federation members and partners on a security recovery plan, PANews and KuCoin News report. Of the roughly 4,000 BTC that left federation reserves in the September 5 Elements proof-verification failure, about 3,400 BTC has been returned to the federation reserve; 598.5 BTC — on the order of $45 million — remains with the attacker. Blockstream's refusal of the bounty demand is unchanged, per Bitcoin.com News. The open question is still the same one: at what collateralization level peg-outs can responsibly reopen.
Chainflip: Restart Executing, Provider Balances Become Claims
The protocol's restart plan is now in motion. Swaps and quoting resumed across the network by September 16 with TRON handled separately, and under the restart the TRON USDT balances of affected liquidity providers read zero — with what they are owed moved to a separate on-chain claim record, Unchained and CryptoSlate report. The memo-handling flaw behind the September 12 theft of 736,442.17 USDT has been patched in version 2.2.13. What remains open is exactly what was open a week ago: Chainflip says it will make providers whole, but the reimbursement funding source, the payout mechanics and a final confirmed amount have not been publicly detailed.
Revolut: Extortion Countdown Expires Without a Confirmed Sale
The group claiming responsibility for the breach of roughly 680–700 customers' files launched an extortion site demanding 6,000 Monero — about $3 million — and threatened to sell the stolen records, Euronews and Yahoo News report. The site's countdown has since run out without any confirmed sale, and prosecutors in Reggio Calabria have opened an inquiry into the fraud, which traced to forged government data requests sent through Italy's certified PEC mail system. Revolut says it has received no direct contact from, or demands by, any group claiming responsibility, per Bitcoin.com News. The group's identity remains unverified, and the earlier reported 10,000 BTC demand also remains unauthenticated.
Kelp DAO: Still No Resolution
No announcement has followed the expiry of the wallet-level pause on the MEV-captured rsETH around September 16 — no extension, no return of funds by the bot operator, and no compensation path for the victim of the $7.8 million Safe-module theft. The core rsETH contracts remain unaffected and the token fully collateralized, per the issuer. The funds stay immobilized only as long as issuer-level restrictions or the holder's goodwill hold.
Swiss Bitcoin Pay: Still Dark
The non-custodial payment processor's infrastructure remains offline following the suspected intrusion disclosed September 14, with no restoration date announced. The company continues to assert funds and private keys are unaffected while customer relationship data — emails, Bitcoin addresses, IBANs, transaction histories, hashed passwords — may have been exposed. Merchants should continue treating any inbound contact referencing that data as potential phishing.
Brief: Symbiosis Root Cause — Two Bugs, One Mint
Follow-up technical reporting on the September 11 syBTC incident identifies two defects working together: a privilege-escalation exploit that let the attacker present network-administrator privileges, and a missing bounds check on transaction fees — a negative fee was applied as an addition — enabling arbitrary token creation from a deposit of about 25 cents, per CoinDesk and Tom's Hardware. Preliminary losses confirmed by the protocol stand at 9.97 BTC (about $770,000), of which the attacker liquidated roughly 4.39 WBTC (~$336,000) on Uniswap before the halt; the team says it secured 15 BTC in a multisig wallet. The native Bitcoin bridge remains deactivated while the related software is rewritten and submitted for an independent audit — a human-reviewed engagement, distinct from automated scanning, and the right call for code that already failed once.
TrustGrade tracks the security posture of wallet vendors, protocols, and exchanges. Security scans with verified, registry-backed scores arrive with TrustGrade Code Scoring in December 2026.