Bitget Confirms $351.6 Million Hot Wallet Breach, Freezes Withdrawals
Bitget says attackers moved about $351.6 million out of hot and warm wallets on September 24 before its security team halted further transfers. Cold wallets were untouched, the exchange says, and its $464 million User Protection Fund covers the loss. No attribution has been confirmed.
What We Cover
One beat: the security of crypto.TrustGrade Cybersecurity Crypto News reports hacks and exploits, audit findings, enforcement and takedowns, phishing and malware operations, and incident analysis. Every story is verified against at least two independent sources or on-chain evidence before it runs — no price predictions, no token promotion, no noise. Trust data comes from TrustGrade, the trust layer for crypto.
Latest News
Binance Faces New DOJ Probe Over Alleged Iran Sanctions Violations, Bloomberg Reports
Federal prosecutors are investigating whether Binance failed to stop Iran-linked trading that violated US sanctions, according to Bloomberg — the exchange's most serious US legal question since its $4.3 billion settlement in 2023, and one that follows a $61 million forfeiture action tied to Iranian oil proceeds laundered through Binance accounts.
Cosmos Hub Restarts After 25-Hour Halt, Extracts 1.23M ATOM From Neutron Governance Attacker's Wallet
Validators froze the Cosmos Hub for nearly 25 hours after a $20,000 Neutron governance proposal handed an attacker admin control of Astroport and Drop contracts holding $9.4 million — and the first block after the restart moved 1,227,121 ATOM out of the attacker's wallet without its owner signing a transaction.
D'CENT Drain Reaches 11.75M XRP From 6,678 Wallets as XRPL.to Maps Six Attack Waves and the Laundering Trail
On-chain analysis firm XRPL.to traced 11.75 million XRP — roughly $18.7 million — leaving 6,678 D'CENT-linked wallets across six sweeps between September 15 and 20, with 5.67 million XRP already routed through THORChain and D'CENT still silent on the technical cause of the key compromise.
Inside the FBI's Invite-Only Crypto Crime Forum: Nine Years Old, and Growing With the Threat
The FBI's Virtual Asset Technical Exchange quietly convened several hundred law-enforcement officials and security specialists in San Antonio this September, with sessions on North Korean hacking operations, wrench attacks and intelligence sharing — as new data showed 2026 thefts approaching $1.73 billion.
White Hats Move 52 BTC From the Coldcard Exploit Into a 'Recovery Trust' — About 2.8% of the Haul
On-chain trackers at Galaxy Research say apparent white-hat actors consolidated 52.37 BTC (about $4.5 million) from several Coldcard attacker clusters into a fresh address advertising a 'Crypto Recovery Trust' — the first large-scale rescue of funds from the roughly $130 million hardware wallet incident.
Upbit Designates EGLD a Trading-Caution Market After MultiversX VM-Level Exploit Halted the Network
A confirmed attempt to exploit a virtual-machine atomicity issue produced invalid state changes and stopped MultiversX block progression on September 19; Upbit has now flagged EGLD under its trading-support termination policy, Kraken went cancel-only, and a shadow-fork fix is pending while no confirmed loss figure has been published.
Pragma Flags 6 of 22 Starknet Price Feeds as Critical Risk After Nostra's $3.5M Oracle Exploit
The oracle provider's September 18 liquidity assessment warns that a quoted price does not prove collateral can be sold: $10,000 sell quotes on four Starknet tokens deteriorated 15–22% versus $10 quotes, and the Nostra incident analysis found a manipulated pool feeding an oracle response with only two contributing sources.
SingularityNET Bridge Exploit Widens: Attacker Cluster Mints 260M AGIX and 53.8M WMTx, Holds $16.77M
On-chain firms traced the same attacker behind the September 19 Fetch.ai and NuNet strikes to the SingularityNET Ethereum–Cardano bridge, where unauthorized mints of AGIX and WMTx pushed the cluster's holdings to about $16.77 million — with Bitquery counting roughly 2.3 billion newly created units across four tokens.
D'CENT App Wallet Flaw Drained 9.3M XRP From 6,160 Addresses as Vendor Urges Immediate Updates
On-chain tracking ties a mid-September drain of 9.3 million XRP — over $9 million — to a signing flaw in D'CENT's App Wallet software, with 1,552 wallets emptied in one two-hour window; D'CENT says users who typed recovery phrases into the app on versions before 8.1.0 are the exposure group.
One Attacker Drained $2M From Fetch.ai and NuNet in Coordinated Strike, On-Chain Firms Say
Blockaid and PeckShield traced a September 19 attack that emptied a Fetch.ai token converter of 8.7 million FET and used the same wallet to mint 408.5 million unauthorized NTX through NuNet's deployer account — about $2 million combined, with NTX collapsing to an all-time low.
Haruko Breach Exposed Exchange API Details of 15 Fund Clients as TRM Counts Record Attacks
The London institutional crypto-tech provider said a targeted attack exploited a vulnerable process to extract a user-access token, exposing read-only exchange API details and trading data for all 15 non-whitelisted clients — with a small amount of client funds possibly stolen from smaller hedge funds.
Revolut Notifies Hundreds of Crypto Customers After Five-Month Data Breach; Attackers Demand $3 Million Ransom
Attackers posing as government officials obtained data on roughly 680 high-value crypto customers from Revolut over five months, reports say, and are now demanding about $3 million in Monero — a breach that turns holder anonymity into a physical-security problem.
Security Digest: Nostra's 8,000x Oracle Pump Drained $3.5M, a MEV Bot Out-Ran a $7.8M Safe Exploit, and the Week Cost Crypto $20M
The week's smaller security stories in brief: a manipulated NSTR price feed let one account borrow $3.5 million from Nostra on Starknet, the Yoink MEV bot front-ran a $7.8 million rsETH theft on Ethereum, and trackers tally roughly $20 million in incident losses across seven days.
FomoPeek: iOS Malware With a Kernel Exploit Framework Passed Apple's App Store Review — Binance and SlowMist Warn Users
Binance Wallet issued an urgent advisory after SlowMist and OKX found that FomoPeek versions 1.1 and 1.2 — distributed through the official App Store — contained an iOS kernel exploitation framework able to escape the sandbox, decrypt Keychain data and harvest private keys and seed phrases from other apps. Version 1.3 removed the code; anyone who ran the affected versions is advised to rebuild their wallet on a clean device.
Radix Post-Mortem: Three-Year-Old Vault Authorization Bug Drained $1.3M and Forced a 10-Day Halt
The Radix Foundation's public incident report traces the August 31 theft of roughly $1.3 million to a vault-authorization flaw introduced during a June 2023 code cleanup — a defect that survived a 2024 Zellic audit and was only contained after validators deliberately broke network liveness for more than ten days. The Foundation said the attacker appeared to use AI-assisted code-analysis tools to find the gap.
RatHat: Android Malware Ships an AI-Guided Navigation Engine to Drain Banking and Crypto Apps
Zimperium zLabs analyzed a new Android remote-access trojan that enables Wireless Debugging for shell-level access, installs a persistent Go agent, and feeds the live accessibility tree to an AI assistant to navigate infected devices — with credential overlays aimed at banking and cryptocurrency applications. Attribution to China-based operators is suspected, based on Chinese-language AI prompts, and remains unconfirmed.
Security Digest: The Last Meter — September 21
This week's freshest attacks converge on the last meter between a user and their assets: an iOS app that shipped a kernel-exploitation framework through the App Store, an Android RAT that navigates infected phones with an AI assistant, and — in northern France — a family tied up at home while attackers forced a €40,000 transfer. Plus the status board: Liquid, Chainflip, Revolut, Kelp DAO, Swiss Bitcoin Pay and Fetch.ai — no new verified developments.
One Attacker, Two Protocols: Linked Exploits Drain $2M From Fetch.ai and NuNet
A single attacker drained 8.7 million FET (about $1.53 million) from a Fetch.ai token converter contract, then used the same wallet to mint 408.5 million unauthorized NTX through NuNet's deployer account — roughly $2 million combined. SlowMist traces the Fetch.ai root cause to an authorization gap in TokenConversionManagerV3's conversionIn(). Neither team has issued an official statement.
US Treasury Sanctions Iranian Exchange BitBank in Alleged IRGC Bitcoin Pipeline
OFAC designated the Iranian crypto exchange BitBank, its developers and three associates on September 18, alleging the network transferred hundreds of millions of dollars in Bitcoin to the Islamic Revolutionary Guard Corps. The action extends the Operation Economic Outcast campaign that earlier sanctioned Shelbit and Aban — and all allegations remain unadjudicated.
Security Digest: What a Signature Is Worth — September 20
Today's thread is authorization: the Fetch.ai exploit trusted one signature where the contract should have demanded more, the S&P–OpenZeppelin deal prices exactly that kind of assurance, Gyazo's metadata leak shows what happens when the proof behind a link leaks, and Japan's NPA officially attributes the ¥1.7B WaterPlum campaign. Plus the status board: Liquid peg-outs, Chainflip claims, Revolut extortion, Kelp DAO, Swiss Bitcoin Pay — all unchanged.