CertiK's Intel3D Report: Agentic AI Joins the Crypto Security Workforce, but Humans Keep the Accountability
A new CertiK report describes autonomous AI agents taking on smart contract analysis, live transaction monitoring and cross-chain fund tracing as attacks accelerate — while warning that agents with authority to act create their own attack surface, from prompt injection to confident wrong answers.
What We Cover
One beat: the security of crypto.TrustGrade Cybersecurity Crypto News reports hacks and exploits, audit findings, enforcement and takedowns, phishing and malware operations, and incident analysis. Every story is verified against at least two independent sources or on-chain evidence before it runs — no price predictions, no token promotion, no noise. Trust data comes from TrustGrade, the trust layer for crypto.
Latest News
Unidentified Base Vault Drained of $6M in wstETH After Multisig Whitelist Flip
An unnamed vault on Base lost 1,783 wstETH (about $6 million) after an attacker-controlled contract was removed from the vault's whitelist and re-enabled one minute later with valid multisig signatures — the fourth Aave-linked or Base incident in a week, according to Blockaid, PeckShield, CertiK and ExVul.
Bitget Trail Narrows: Chainalysis Attributes $387M Theft to North Korean Actors, BitOK Tracks 87.8 BTC
Chainalysis says the September 24 Bitget breach was DPRK-attributed, pushing North Korean-linked crypto theft past $1 billion in 2026, while a BitOK trace pins 87.82 BTC in ten unspent outputs and Mandiant's preliminary report describes a supply-chain path through third-party security appliances into Bitget's wallet job server.
Microsoft Confirms X Account Hijack Used to Push Fake Clippy Token
Unknown attackers compromised Microsoft's 13-million-follower X account to amplify a Clippy-impersonation account promoting a $Clippy token claimed to pair with $MSFT stock — a confirmed unauthorized-access incident that shows verified brand accounts remain prime pump-and-dump infrastructure.
NEAR Intents Closes $3.8M Exploit Probe After Funds Returned On-Chain With an Apology
NEAR Intents says the full $3.8 million taken in an October 1 exploit of its cross-chain system has been returned — confirmed by a BNB Chain transaction whose input data carried a message from the address labeled 'Near Intents Exploiter 1' — and the team has stopped its investigation, urging researchers to use bug bounties.
Security Digest — October 5, 2026: Base's Rough Week, GoldPesa Hook Drain, September Losses Confirmed Worst of Year
Today's roundup: Base absorbs a cluster of Aave-linked incidents in a single week — FlashLoopAdapter ($305K), an allegedly drained GoldPesa hook ($114K) and a $6M vault drain — while CertiK confirms September as 2026's worst month for losses at ~$766M and Bitget completes its withdrawal restoration.
Bitget, Ten Days On: $1.1 Million Frozen of $388 Million Stolen as Attribution Splits
Roughly 0.3 percent of the September 24 theft has been frozen, the CEO says most of the rest is probably gone, and analysts disagree on whether North Korean actors are behind the largest exchange hack of 2026.
NEAR Intents Attacker Returns Full $3.8 Million After 48-Hour Ultimatum
The cross-chain protocol says the entire amount stolen in the October 1 Omni exploit has been returned after the attacker was identified, and that it has halted its investigation — a rare full recovery in a year of major thefts.
Security Digest: AI Tracing in the Bitget Case, THORChain's Freeze Refusal, and a Critical DEX223 Finding
The week's smaller security stories: Chainalysis reportedly compressed 20 hours of cross-chain tracing into minutes, the THORChain censorship debate deepens, and an independent researcher published critical findings against DEX223's contracts.
FBI's First Cyber Fugitive Faces US Court Over ATM Malware Tied to TRON Laundering Network
Anibal Canelon Aguirre, the alleged developer of Ploutus ATM jackpotting malware, appeared in a Nebraska courtroom after capture in Venezuela — days after OFAC sanctioned ten targets and seven TRON addresses tied to the Tren de Aragua cash-to-crypto pipeline.
Fake Safe, Real Keys: Aave 'Loop' Module Exploit Drains 114 ETH From Two Multisigs
SlowMist says an access-control flaw in FlashLoopAdapter — a third-party Safe module for leveraged Aave v3 positions — let an attacker spoof module authentication, repay vault debt with a flash loan, and extract 114 ETH. Aave's core contracts were not affected.
Bitget Has Frozen $1.1 Million of the $388 Million Hack — 'Not Expecting to Recover a Lot'
CEO Gracy Chen told CNBC the exchange has frozen roughly 0.3% of the $387.5 million stolen in September's third-party zero-day breach, cautioned that frozen does not mean returned, and said Bitget replenished its protection fund with its own capital as withdrawals fully reopened.
Drift Opens $295M Recovery Claims — Victims Face About One Cent on the Dollar
Six months after the April 1 exploit drained about $295.4 million from the Solana perp DEX, the Drift Foundation has opened DFX recovery-token claims: one DFX per USDT of verified losses, with initial redemptions near 0.0104 USDT as a roughly 3.11 million USDT pool begins payouts.
MetaMask Exits Ethereum Validators After Security Incident Diverted Block Rewards
MetaMask disclosed an ongoing infrastructure security incident and began precautionary exits of up to 17,000 Ethereum validators from Lido, after a researcher traced diverted block-production payments — with no immediate threat found to user wallets.
Fake 'GIWA Mainnet' Used the Correct Chain ID to Drain 766 ETH From 1,300-Plus Wallets
Scammers stood up a counterfeit version of Upbit-backed GIWA's unlaunched Ethereum L2 — complete with RPC endpoint, bridge and the expected Chain ID 9134 — let deposits accumulate for 13 hours, then changed the bridge code and drained 766 ETH in a single transaction.
NEAR Intents Halts After $3.8 Million Omni Exploit — Days After Freezing Bitget's Stolen Funds
The cross-chain trading protocol lost about $3.8 million to a bug in its Omni deposit and withdrawal system, paused services across eleven networks, and pledged full reimbursement — one week after its risk system rejected $50 million in swaps tied to the Bitget theft.
Ostium Opens Recovery Portal for $23.75 Million Exploit: 3,321 Wallets Repaid in Full, 345 LPs Face a Choice
The Arbitrum perpetuals protocol has begun repaying victims of its July 15 exploit, with 90.59% of the 3,666 affected wallets eligible for full compensation while larger liquidity providers must choose between a $1,000 payout or a second-phase recovery plan.
Security Digest — October 2, 2026: Bitget Due to Complete Phased Withdrawal Restoration, Q3 Hack Losses Hit $1.26 Billion
The day's smaller security stories in brief: Bitget's final withdrawal phase — all remaining tokens, fiat and P2P — is scheduled for 08:00 UTC today, the protection fund is back above $300 million ahead of schedule, and CoinDesk's quarter tally puts Q3 hack losses at $1.26 billion.
Bitget Forensics: SlowMist and Mandiant Trace the Breach to an August 31 Zero-Day Foothold
Interim findings from the two firms Bitget hired put the attacker inside the exchange's environment 24 days before funds moved — a zero-day in a third-party security product, stolen employee credentials, and a custom withdrawal tool. No private keys were taken.
Stolen Bitget Funds Reach Zcash's Ironwood Pool as Cross-Chain Routes Close
Wallets linked to the $387.5 million Bitget theft shielded 2,746 ZEC — about 15% of the stolen Zcash — inside Ironwood after NEAR Intents rejected over $50 million in attempted swaps and roughly $79 million in ETH was already cycled through THORChain into Bitcoin.
Security Digest — October 1, 2026: Suspected DPRK Haul Passes $1 Billion, Bitget Bleeds $463 Million in Outflows
The day's smaller security stories in brief: suspected North Korean-linked thefts push past $1 billion for 2026 on the back of the Bitget hack, customers pull $463 million from the exchange since the breach, and the recovery outlook darkens.