Kelp DAO Exploiter Reportedly Moves $175M in ETH After Arbitrum Freeze

On-chain tracking reported by CoinMarketCap indicates the Kelp DAO exploiter moved roughly $175 million in ETH this weekend, months after the April hack that cost the protocol $290 million. The movement follows Arbitrum's Security Council using emergency powers earlier this year to seize 30,766 ETH from an attacker wallet on-chain — an intervention that froze only part of the stolen funds and split opinion over a council's authority to reverse chain state. The remainder, evidently, remains liquid and under attacker control. Large post-hack consolidations typically precede laundering through mixers or OTC channels; the funds should be treated as live, not recovered.

Binance Warns of Surge in SMS Phishing

Binance warned users on September 3 about an increase in text-message phishing disguised as account security alerts — unexpected logins, changed settings — carrying shortened links to imitation login pages. The exchange reiterated that it never asks customers to verify or secure an account through a texted link, and pointed to three controls: the withdrawal address whitelist, the anti-phishing code for email, and verification of any communication through Binance Verify before responding. No victim count or loss figure was attached to the campaign. The mechanics are not new — Hong Kong police documented $446,000 in losses from a 2023 Binance-impersonation SMS wave — but the channel keeps working because it preys on urgency rather than ignorance. Notably, Hong Kong's SFC ordered licensed platforms in July to drop SMS- and email-based one-time codes entirely within 12 months, in favor of phishing-resistant authentication.

Trezor Breach Settles at Roughly 80,700 — With No Overlap Accounting

Trezor's September 4 update added roughly 67,000 US customers to the ShipMonk breach, implying a total of about 80,689 alongside the 13,689 disclosed in August. The company has not published a combined figure or row-level overlap check, so the true distinct-person count is unknown. The newly disclosed records — November 2019 through August 2021 orders with names, emails, phone numbers, shipping addresses, and order numbers — survived despite written assurances from ShipMonk that older data had been deleted, contradicting Trezor's stated 90-day deletion policy for delivery data. The intrusion vector, per BleepingComputer and Metabase's own disclosure, was the August Metabase zero-day that allowed sessions tied to administrator accounts and bulk table downloads. Devices and keys were never exposed; the lasting asset for attackers is a map from confirmed hardware-wallet owners to front doors.

Notional Finance Root Cause Confirmed: Integer Overflow

The suspected $1.7 million exploit of Notional Finance's escrow contract reported last week has been confirmed in follow-up reporting as an integer overflow bug — the arithmetic wrapping class of flaw that lets computed balances underflow into exploitable values. The loss figure and the escrow-contract surface align with the initial on-chain reports from September 3–4. The incident remains modest by 2026's standards, but it is a reminder that classic arithmetic bugs did not retire just because the year's headline thefts moved to key compromise.

Tectonic Attacker Bridges 2,659 ETH to Tornado Cash

On-chain trackers report the attacker behind last week's $70+ million Tectonic exploit on Cronos moved 2,659 ETH — on the order of $7–8 million — into Tornado Cash, closing the loop on the first major laundering hop. The movement caps a record year for hack proceeds moving through the sanctioned mixer, and marks the practical end of any freeze-first recovery window for that tranche. The remainder of the stolen funds remains tracked across other venues.

TrustGrade tracks the security posture of DeFi protocols, exchanges, and chain infrastructure. Security scans with verified, registry-backed scores arrive with TrustGrade Code Scoring in December 2026.