Three of the four stories in today's coverage do not touch a blockchain at all. The FomoPeek disclosure is malware that passed App Store review and attacked the device beneath the wallet. The RatHat analysis is a sideloaded Android trojan that steers infected phones with a commercial AI assistant. And the home invasion below is the analogue version of the same target: the person holding the keys, not the protocol holding the ledger.
The counterpoint is the Radix post-mortem: a reminder that the engine layer can still fail quietly, for three years, inside audited code. But the direction of travel in the incident data is clear — as contract-layer defenses slowly harden, the attack surface that remains softest is the last meter.
Brief: French Family Tied Up in Overnight Home Invasion, Father Forced to Transfer €40,000
Four armed men broke into a family home in Vendin-le-Vieil, in the Pas-de-Calais department of northern France, tied up a couple and their two children — aged 8 and 12 — and forced the father to hand over access codes and transfer approximately €40,000 in cryptocurrency before fleeing, according to reporting by La Voix du Nord, corroborated by Le Parisien and BFMTV via Bitcoin.com News, IBTimes UK and BeInCrypto. The suspects remained at large at the time of reporting.
The incident fits a documented pattern: France has accounted for the large majority of reported physical crypto-targeted attacks in Europe over the past year — kidnappings, home invasions and street extortion of known holders. The operational lesson is unchanged and uncomfortable: operational security for crypto holders is not only digital. Public association between a person and a holdings profile is itself an attack surface, and the French wave is what that surface looks like when exploited systematically.
Status Board
Liquid Network: No new verified developments since the September 18 update. Peg-out redemptions remain paused; roughly 598.5 BTC — on the order of $45 million — remains with the attacker; about 3,400 BTC of the roughly 4,000 BTC drained from federation reserves on September 5 has been returned.
Chainflip: No new verified developments. TRON USDT provider balances remain converted to on-chain claims under the restart plan; the reimbursement funding source and payout mechanics are still publicly undefined.
Revolut: No confirmed sale of the stolen customer files since the extortionists' countdown expired; the group's identity remains unverified; the Italian prosecutorial inquiry continues.
Kelp DAO: No announcement on the MEV-captured rsETH. The $7.8 million remains immobilized at the issuer-paused wallet level; core rsETH contracts remain unaffected per the issuer.
Swiss Bitcoin Pay: Infrastructure remains offline following the suspected intrusion disclosed September 14, with no restoration date announced. Treat inbound contact referencing customer data as potential phishing.
Fetch.ai / NuNet: No official statements from either team on the September 19 linked exploits have been verified. The attacker's proceeds — converted in part to roughly 546 ETH — remain tracked through exchange-flagged addresses.
TrustGrade tracks the security posture of protocols, providers and exchanges. Registry-backed security scoring arrives with TrustGrade Code Scoring in December 2026.