Bitget, Ten Days On: $1.1 Million Frozen of $388 Million Stolen as Attribution Splits
Roughly 0.3 percent of the September 24 theft has been frozen, the CEO says most of the rest is probably gone, and analysts disagree on whether North Korean actors are behind the largest exchange hack of 2026.
What We Cover
One beat: the security of crypto.TrustGrade Cybersecurity Crypto News reports hacks and exploits, audit findings, enforcement and takedowns, phishing and malware operations, and incident analysis. Every story is verified against at least two independent sources or on-chain evidence before it runs — no price predictions, no token promotion, no noise. Trust data comes from TrustGrade, the trust layer for crypto.
Latest News
Fake Safe, Real Keys: Aave 'Loop' Module Exploit Drains 114 ETH From Two Multisigs
SlowMist says an access-control flaw in FlashLoopAdapter — a third-party Safe module for leveraged Aave v3 positions — let an attacker spoof module authentication, repay vault debt with a flash loan, and extract 114 ETH. Aave's core contracts were not affected.
Bitget Has Frozen $1.1 Million of the $388 Million Hack — 'Not Expecting to Recover a Lot'
CEO Gracy Chen told CNBC the exchange has frozen roughly 0.3% of the $387.5 million stolen in September's third-party zero-day breach, cautioned that frozen does not mean returned, and said Bitget replenished its protection fund with its own capital as withdrawals fully reopened.
Drift Opens $295M Recovery Claims — Victims Face About One Cent on the Dollar
Six months after the April 1 exploit drained about $295.4 million from the Solana perp DEX, the Drift Foundation has opened DFX recovery-token claims: one DFX per USDT of verified losses, with initial redemptions near 0.0104 USDT as a roughly 3.11 million USDT pool begins payouts.
MetaMask Exits Ethereum Validators After Security Incident Diverted Block Rewards
MetaMask disclosed an ongoing infrastructure security incident and began precautionary exits of up to 17,000 Ethereum validators from Lido, after a researcher traced diverted block-production payments — with no immediate threat found to user wallets.
Fake 'GIWA Mainnet' Used the Correct Chain ID to Drain 766 ETH From 1,300-Plus Wallets
Scammers stood up a counterfeit version of Upbit-backed GIWA's unlaunched Ethereum L2 — complete with RPC endpoint, bridge and the expected Chain ID 9134 — let deposits accumulate for 13 hours, then changed the bridge code and drained 766 ETH in a single transaction.
NEAR Intents Halts After $3.8 Million Omni Exploit — Days After Freezing Bitget's Stolen Funds
The cross-chain trading protocol lost about $3.8 million to a bug in its Omni deposit and withdrawal system, paused services across eleven networks, and pledged full reimbursement — one week after its risk system rejected $50 million in swaps tied to the Bitget theft.
Ostium Opens Recovery Portal for $23.75 Million Exploit: 3,321 Wallets Repaid in Full, 345 LPs Face a Choice
The Arbitrum perpetuals protocol has begun repaying victims of its July 15 exploit, with 90.59% of the 3,666 affected wallets eligible for full compensation while larger liquidity providers must choose between a $1,000 payout or a second-phase recovery plan.
Security Digest — October 2, 2026: Bitget Due to Complete Phased Withdrawal Restoration, Q3 Hack Losses Hit $1.26 Billion
The day's smaller security stories in brief: Bitget's final withdrawal phase — all remaining tokens, fiat and P2P — is scheduled for 08:00 UTC today, the protection fund is back above $300 million ahead of schedule, and CoinDesk's quarter tally puts Q3 hack losses at $1.26 billion.
Bitget Forensics: SlowMist and Mandiant Trace the Breach to an August 31 Zero-Day Foothold
Interim findings from the two firms Bitget hired put the attacker inside the exchange's environment 24 days before funds moved — a zero-day in a third-party security product, stolen employee credentials, and a custom withdrawal tool. No private keys were taken.
Stolen Bitget Funds Reach Zcash's Ironwood Pool as Cross-Chain Routes Close
Wallets linked to the $387.5 million Bitget theft shielded 2,746 ZEC — about 15% of the stolen Zcash — inside Ironwood after NEAR Intents rejected over $50 million in attempted swaps and roughly $79 million in ETH was already cycled through THORChain into Bitcoin.
Security Digest — October 1, 2026: Suspected DPRK Haul Passes $1 Billion, Bitget Bleeds $463 Million in Outflows
The day's smaller security stories in brief: suspected North Korean-linked thefts push past $1 billion for 2026 on the back of the Bitget hack, customers pull $463 million from the exchange since the breach, and the recovery outlook darkens.
September Cost Crypto $766 Million — CertiK and PeckShield Agree It Was 2026's Worst Month
Two independent security firms converge on roughly $766 million in September losses, with the Bitget and Liquid Network breaches making up more than 92% of the total — and the damage came from third-party infrastructure and signature failures, not classic DeFi bugs.
Apple Patches CoreGraphics Zero-Day CVE-2026-86950 Exploited Against Targeted iPhone Users
Apple's September 28 security updates close an out-of-bounds write in CoreGraphics, reported by Meta Product Security, that the company says may have been exploited in extremely sophisticated attacks against specific individuals on pre-iOS 27 versions — with blockchain security firms noting a suspected crypto wallet targeting angle that remains unconfirmed.
Bitget Day Six: Recovery 'Unlikely' as Withdrawal Restoration Reaches Its Real Stress Test
With less than $503,000 of the $387.5 million Bitget breach frozen worldwide, CEO Gracy Chen says full recovery is unlikely; USDT withdrawals across four chains opened September 30 at 08:00 UTC — the moment that will actually test user confidence in the exchange's Protection Fund.
Chainalysis: 'Blockchain Dead Drops' — Malware C2 Hidden in Smart Contracts — Up More Than Fourfold
Chainalysis research shows malicious writes to public blockchains used as malware command-and-control infrastructure climbing from about two to more than eleven per day, with state-linked groups behind roughly half of all dead-drop activity by Q2 2026 — DPRK-attributed relays across TRON, BSC and Aptos, Polygon C2 resolvers, and Bitcoin OP_RETURN pointers.
Payy Post-Mortem: Invalid Burn Proof Accepted by Noir Verifier Drained $1.9M USDC
Payy's technical post-mortem pins the September 24 bridge exploit on a proving-system flaw in the deployed Noir/Barretenberg verifier, which accepted an invalid burn proof and released roughly 1.92 million USDC to a single wallet — a supply-side risk for every project using the same Aztec toolchain.
Security Digest — September 30, 2026: SectopRAT in Trusted Software, Citrix NetScaler Zero-Days Under Exploit
Today's roundup: Fortinet documents a SectopRAT campaign hiding a full remote-access trojan inside legitimate audio software to harvest crypto wallet data from 35+ browsers, and Citrix warns that NetScaler zero-days are being exploited for web shells and credential theft — plus the day's checkpoints at Bitget and Payy.
Bitget Points to Third-Party Security Product as Source of $388M Hack
CEO Gracy Chen says the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials and issue fraudulent withdrawal commands — the first root-cause detail on the September 24 breach that took $387.5 million.
Bitquery Ties 56 Robinhood Chain Memecoin Launches to One Suspected Rug-Pull Crew
On-chain analysis links a single coordinated group to 56 Pons launchpad tokens on Robinhood Chain with an estimated $15.5 million extracted — and finds 467 other groups running the same tax-exemption tactic.
Security Digest: Placeholder Domain Turned Attack Infrastructure, PamStealer Goes Server-Side, OpenAI Agents Linked to Website Hacks
The day's smaller security stories in brief: a documentation placeholder domain referenced in ~1,700 repos was registered and now serves ClickFix lures, a macOS stealer adds live C2 payload decryption, and researchers catch AI agents exploiting websites during mundane tasks.