Apple Patches CoreGraphics Zero-Day CVE-2026-86950 Exploited Against Targeted iPhone Users
Apple's September 28 security updates close an out-of-bounds write in CoreGraphics, reported by Meta Product Security, that the company says may have been exploited in extremely sophisticated attacks against specific individuals on pre-iOS 27 versions — with blockchain security firms noting a suspected crypto wallet targeting angle that remains unconfirmed.
What We Cover
One beat: the security of crypto.TrustGrade Cybersecurity Crypto News reports hacks and exploits, audit findings, enforcement and takedowns, phishing and malware operations, and incident analysis. Every story is verified against at least two independent sources or on-chain evidence before it runs — no price predictions, no token promotion, no noise. Trust data comes from TrustGrade, the trust layer for crypto.
Latest News
Security Digest — September 30, 2026: SectopRAT in Trusted Software, Citrix NetScaler Zero-Days Under Exploit
Today's roundup: Fortinet documents a SectopRAT campaign hiding a full remote-access trojan inside legitimate audio software to harvest crypto wallet data from 35+ browsers, and Citrix warns that NetScaler zero-days are being exploited for web shells and credential theft — plus the day's checkpoints at Bitget and Payy.
Bitget Points to Third-Party Security Product as Source of $388M Hack
CEO Gracy Chen says the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials and issue fraudulent withdrawal commands — the first root-cause detail on the September 24 breach that took $387.5 million.
Bitquery Ties 56 Robinhood Chain Memecoin Launches to One Suspected Rug-Pull Crew
On-chain analysis links a single coordinated group to 56 Pons launchpad tokens on Robinhood Chain with an estimated $15.5 million extracted — and finds 467 other groups running the same tax-exemption tactic.
Security Digest: Placeholder Domain Turned Attack Infrastructure, PamStealer Goes Server-Side, OpenAI Agents Linked to Website Hacks
The day's smaller security stories in brief: a documentation placeholder domain referenced in ~1,700 repos was registered and now serves ClickFix lures, a macOS stealer adds live C2 payload decryption, and researchers catch AI agents exploiting websites during mundane tasks.
Senate Report Says USDT Anchors Iran's Shadow Banking, Refers Tether to Treasury and DOJ
Senator Blumenthal's PSI investigation found 84% of 846 Iran-linked sanctioned wallets transacted almost exclusively in USDT, and asked Treasury and DOJ to examine Tether's sanctions and Bank Secrecy Act compliance — Tether counters that it froze nearly $550 million in Iran-linked tokens this year.
Kelp DAO Sues LayerZero and CEO Pellegrino Over $292M rsETH Bridge Exploit
Evercrest, the company behind Kelp DAO, filed suit in the Supreme Court of British Columbia alleging LayerZero endorsed the single-verifier bridge setup attackers exploited in April, then publicly blamed Kelp for it — claims Pellegrino calls meritless.
Liquid Network Actors 'Crossed Into Theft' by Keeping 598.5 BTC, Immunefi CEO Says
Immunefi's Mitchell Amador says the self-described white hats who returned 3,400 BTC from the ~4,000 BTC Liquid Network drain lost any rescue claim by retaining 598.5 BTC and demanding a bounty — reviving the debate over rescue terms set before exploits, not after.
Security Digest: Bitget Reopens Withdrawals Today, THORChain Declines Blocking Request, DarkMe RAT Aims at Crypto Users
The day's smaller security stories in brief: Bitget begins phased withdrawal restarts at 08:00 UTC with losses confirmed at $387.5M, THORChain refuses Bitget's call to block attacker addresses, and Huntress documents a DarkMe RAT campaign whose loaders probe for crypto wallets and trading terminals.
Zano Rolls Back One Month of Chain History After Gateway Address Exploit
Privacy L1 Zano restarted its blockchain at block 3,833,000 after a Gateway Address vulnerability let unauthorized ZANO and Freedom Dollar tokens into circulation, invalidating roughly a month of legitimate transactions alongside the unbacked mint.
Bitget Confirms $387.5M Loss and Phased Withdrawal Restart for September 28
Bitget has raised its confirmed loss from the September 24 hot-wallet breach to $387.5 million, with XRP the largest single tranche at about $157.5 million. Withdrawals resume in phases from September 28 at 08:00 UTC, with full restoration targeted for October 2, and the exchange says the exploited vulnerability has been identified and remediated.
Audited Platforms Accounted for 88% of Capital Drained in 2025-26 Hacks, Coinpedia Report Finds
A Coinpedia research report counts 288 crypto security incidents and about $2.21 billion in losses so far in 2026. Its sharpest finding: of 245 documented incidents from January 2025 through July 2026, 147 involved platforms that had completed independent audits — and those platforms accounted for 88.44% of the capital drained.
Ghost Approvals: 23,155 NFTs Rescued From Limit Break's Payment Processor Flaw as Magic Eden Recovery Portal Opens
A bug in Limit Break's Payment Processor V2 — the settlement contract Magic Eden abandoned in October 2024 — let an attacker pull 305 NFTs and roughly 660 WETH from wallets whose onchain approvals never expired. A whitehat team led by Yuga Labs' 0xQuit used the same flaw to move 23,155 NFTs worth over $5.7 million to safety, and a public recovery portal is now live for owners to reclaim them.
OpenZeppelin Brings Its Audited Contract Libraries to TRON
OpenZeppelin's smart contract libraries and secure development suite became available for TRON on September 24, adding TRC-20 token components, UUPS-style upgrade tooling with TRC-1967 proxies, passkey-friendly secp256r1 signature support, and an MCP server for AI-assisted development.
TRM Traces Bitget's $351.6 Million Through a Laundering Network Linked to Prior North Korean Heists
On-chain analysis by TRM Labs shows the September 24 Bitget theft split into round-number holding wallets within hours, with conversion routes into Bitcoin matching infrastructure previously used to launder the Bybit and AFX Bridge thefts. Circle and Tether froze an exploiter wallet holding about $318,000 in stablecoins.
Empty Signatures and an Extra OP_NOT: How the Kasplex Indexer Attack Moved 186M ZEAL and 54B NACHO Without a Private Key
A September 20 attack on the Kasplex KRC-20 indexer drained 186.4 million ZEAL and 54.4 billion NACHO from a bridge custody wallet using five forged transactions — valid at Kaspa's consensus layer, fake at the token layer. Pools lost up to 99.6% of their KAS-side value, and operators are reindexing history to close the gap.
North Korea-Linked Crypto Theft Passes $1 Billion for 2026 as Bitget Joins the Ledger
Elliptic says the Bitget breach — which it counts at $357 million — was likely carried out by North Korea-linked actors, pushing the year's suspected state-attributed haul past $1 billion. TRM Labs data shows about $690 million was already attributed before Bitget, mostly from the Drift Protocol and KelpDAO thefts.
Bitget Confirms $351.6 Million Hot Wallet Breach, Freezes Withdrawals
Bitget says attackers moved about $351.6 million out of hot and warm wallets on September 24 before its security team halted further transfers. Cold wallets were untouched, the exchange says, and its $464 million User Protection Fund covers the loss. No attribution has been confirmed.
Duelbits Casino Confirms ~$7 Million Hot Wallet Hack, Goes Offline
Crypto gambling platform Duelbits took its site offline after attackers drained roughly $7 million from hot wallets on Ethereum, BNB Chain, Tron and Bitcoin on September 24. Scam Sniffer and PeckShield point to a suspected private key compromise; about $6 million sits consolidated in one Ethereum address.
Microsoft and Coinbase Dismantle EvilTokens, an AI-Powered Phishing Service
A court-authorized takedown announced September 22 seized 50 websites and disabled more than 175 domains behind EvilTokens, a device-code phishing service that Microsoft says used AI at every step of its attack chain. Two suspected operators were arrested in London, and Coinbase traced about $1.1 million of the operation's revenue on-chain.
September Is Now 2026's Costliest Month for Crypto Theft — by a Wide Margin
With Bitget's $351.6 million breach, September's gross theft total has passed $684 million, topping April's $646.9 million. The anatomy of the worst month of the year: one exchange hot-wallet failure, one sidechain disaster, and a long tail of smaller incidents — with 2026's running total near $1.73 billion.