Bitget Points to Third-Party Security Product as Source of $388M Hack
CEO Gracy Chen says the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials and issue fraudulent withdrawal commands — the first root-cause detail on the September 24 breach that took $387.5 million.
What We Cover
One beat: the security of crypto.TrustGrade Cybersecurity Crypto News reports hacks and exploits, audit findings, enforcement and takedowns, phishing and malware operations, and incident analysis. Every story is verified against at least two independent sources or on-chain evidence before it runs — no price predictions, no token promotion, no noise. Trust data comes from TrustGrade, the trust layer for crypto.
Latest News
Kelp DAO Sues LayerZero and CEO Pellegrino Over $292M rsETH Bridge Exploit
Evercrest, the company behind Kelp DAO, filed suit in the Supreme Court of British Columbia alleging LayerZero endorsed the single-verifier bridge setup attackers exploited in April, then publicly blamed Kelp for it — claims Pellegrino calls meritless.
Liquid Network Actors 'Crossed Into Theft' by Keeping 598.5 BTC, Immunefi CEO Says
Immunefi's Mitchell Amador says the self-described white hats who returned 3,400 BTC from the ~4,000 BTC Liquid Network drain lost any rescue claim by retaining 598.5 BTC and demanding a bounty — reviving the debate over rescue terms set before exploits, not after.
Security Digest: Bitget Reopens Withdrawals Today, THORChain Declines Blocking Request, DarkMe RAT Aims at Crypto Users
The day's smaller security stories in brief: Bitget begins phased withdrawal restarts at 08:00 UTC with losses confirmed at $387.5M, THORChain refuses Bitget's call to block attacker addresses, and Huntress documents a DarkMe RAT campaign whose loaders probe for crypto wallets and trading terminals.
Zano Rolls Back One Month of Chain History After Gateway Address Exploit
Privacy L1 Zano restarted its blockchain at block 3,833,000 after a Gateway Address vulnerability let unauthorized ZANO and Freedom Dollar tokens into circulation, invalidating roughly a month of legitimate transactions alongside the unbacked mint.
Bitget Confirms $387.5M Loss and Phased Withdrawal Restart for September 28
Bitget has raised its confirmed loss from the September 24 hot-wallet breach to $387.5 million, with XRP the largest single tranche at about $157.5 million. Withdrawals resume in phases from September 28 at 08:00 UTC, with full restoration targeted for October 2, and the exchange says the exploited vulnerability has been identified and remediated.
Audited Platforms Accounted for 88% of Capital Drained in 2025-26 Hacks, Coinpedia Report Finds
A Coinpedia research report counts 288 crypto security incidents and about $2.21 billion in losses so far in 2026. Its sharpest finding: of 245 documented incidents from January 2025 through July 2026, 147 involved platforms that had completed independent audits — and those platforms accounted for 88.44% of the capital drained.
Ghost Approvals: 23,155 NFTs Rescued From Limit Break's Payment Processor Flaw as Magic Eden Recovery Portal Opens
A bug in Limit Break's Payment Processor V2 — the settlement contract Magic Eden abandoned in October 2024 — let an attacker pull 305 NFTs and roughly 660 WETH from wallets whose onchain approvals never expired. A whitehat team led by Yuga Labs' 0xQuit used the same flaw to move 23,155 NFTs worth over $5.7 million to safety, and a public recovery portal is now live for owners to reclaim them.
OpenZeppelin Brings Its Audited Contract Libraries to TRON
OpenZeppelin's smart contract libraries and secure development suite became available for TRON on September 24, adding TRC-20 token components, UUPS-style upgrade tooling with TRC-1967 proxies, passkey-friendly secp256r1 signature support, and an MCP server for AI-assisted development.
TRM Traces Bitget's $351.6 Million Through a Laundering Network Linked to Prior North Korean Heists
On-chain analysis by TRM Labs shows the September 24 Bitget theft split into round-number holding wallets within hours, with conversion routes into Bitcoin matching infrastructure previously used to launder the Bybit and AFX Bridge thefts. Circle and Tether froze an exploiter wallet holding about $318,000 in stablecoins.
Empty Signatures and an Extra OP_NOT: How the Kasplex Indexer Attack Moved 186M ZEAL and 54B NACHO Without a Private Key
A September 20 attack on the Kasplex KRC-20 indexer drained 186.4 million ZEAL and 54.4 billion NACHO from a bridge custody wallet using five forged transactions — valid at Kaspa's consensus layer, fake at the token layer. Pools lost up to 99.6% of their KAS-side value, and operators are reindexing history to close the gap.
North Korea-Linked Crypto Theft Passes $1 Billion for 2026 as Bitget Joins the Ledger
Elliptic says the Bitget breach — which it counts at $357 million — was likely carried out by North Korea-linked actors, pushing the year's suspected state-attributed haul past $1 billion. TRM Labs data shows about $690 million was already attributed before Bitget, mostly from the Drift Protocol and KelpDAO thefts.
Bitget Confirms $351.6 Million Hot Wallet Breach, Freezes Withdrawals
Bitget says attackers moved about $351.6 million out of hot and warm wallets on September 24 before its security team halted further transfers. Cold wallets were untouched, the exchange says, and its $464 million User Protection Fund covers the loss. No attribution has been confirmed.
Duelbits Casino Confirms ~$7 Million Hot Wallet Hack, Goes Offline
Crypto gambling platform Duelbits took its site offline after attackers drained roughly $7 million from hot wallets on Ethereum, BNB Chain, Tron and Bitcoin on September 24. Scam Sniffer and PeckShield point to a suspected private key compromise; about $6 million sits consolidated in one Ethereum address.
Microsoft and Coinbase Dismantle EvilTokens, an AI-Powered Phishing Service
A court-authorized takedown announced September 22 seized 50 websites and disabled more than 175 domains behind EvilTokens, a device-code phishing service that Microsoft says used AI at every step of its attack chain. Two suspected operators were arrested in London, and Coinbase traced about $1.1 million of the operation's revenue on-chain.
September Is Now 2026's Costliest Month for Crypto Theft — by a Wide Margin
With Bitget's $351.6 million breach, September's gross theft total has passed $684 million, topping April's $646.9 million. The anatomy of the worst month of the year: one exchange hot-wallet failure, one sidechain disaster, and a long tail of smaller incidents — with 2026's running total near $1.73 billion.
Binance Faces New DOJ Probe Over Alleged Iran Sanctions Violations, Bloomberg Reports
Federal prosecutors are investigating whether Binance failed to stop Iran-linked trading that violated US sanctions, according to Bloomberg — the exchange's most serious US legal question since its $4.3 billion settlement in 2023, and one that follows a $61 million forfeiture action tied to Iranian oil proceeds laundered through Binance accounts.
Cosmos Hub Restarts After 25-Hour Halt, Extracts 1.23M ATOM From Neutron Governance Attacker's Wallet
Validators froze the Cosmos Hub for nearly 25 hours after a $20,000 Neutron governance proposal handed an attacker admin control of Astroport and Drop contracts holding $9.4 million — and the first block after the restart moved 1,227,121 ATOM out of the attacker's wallet without its owner signing a transaction.
D'CENT Drain Reaches 11.75M XRP From 6,678 Wallets as XRPL.to Maps Six Attack Waves and the Laundering Trail
On-chain analysis firm XRPL.to traced 11.75 million XRP — roughly $18.7 million — leaving 6,678 D'CENT-linked wallets across six sweeps between September 15 and 20, with 5.67 million XRP already routed through THORChain and D'CENT still silent on the technical cause of the key compromise.
Inside the FBI's Invite-Only Crypto Crime Forum: Nine Years Old, and Growing With the Threat
The FBI's Virtual Asset Technical Exchange quietly convened several hundred law-enforcement officials and security specialists in San Antonio this September, with sessions on North Korean hacking operations, wrench attacks and intelligence sharing — as new data showed 2026 thefts approaching $1.73 billion.
White Hats Move 52 BTC From the Coldcard Exploit Into a 'Recovery Trust' — About 2.8% of the Haul
On-chain trackers at Galaxy Research say apparent white-hat actors consolidated 52.37 BTC (about $4.5 million) from several Coldcard attacker clusters into a fresh address advertising a 'Crypto Recovery Trust' — the first large-scale rescue of funds from the roughly $130 million hardware wallet incident.