Fake Safe, Real Keys: Aave 'Loop' Module Exploit Drains 114 ETH From Two Multisigs
SlowMist says an access-control flaw in FlashLoopAdapter — a third-party Safe module for leveraged Aave v3 positions — let an attacker spoof module authentication, repay vault debt with a flash loan, and extract 114 ETH. Aave's core contracts were not affected.
Drift Opens $295M Recovery Claims — Victims Face About One Cent on the Dollar
MetaMask Exits Ethereum Validators After Security Incident Diverted Block Rewards
What We Cover
One beat: the security of crypto.TrustGrade Cybersecurity Crypto News reports hacks and exploits, audit findings, enforcement and takedowns, phishing and malware operations, and incident analysis. Every story is verified against at least two independent sources or on-chain evidence before it runs — no price predictions, no token promotion, no noise. Trust data comes from TrustGrade, the trust layer for crypto.
Latest News
Fake 'GIWA Mainnet' Used the Correct Chain ID to Drain 766 ETH From 1,300-Plus Wallets
Scammers stood up a counterfeit version of Upbit-backed GIWA's unlaunched Ethereum L2 — complete with RPC endpoint, bridge and the expected Chain ID 9134 — let deposits accumulate for 13 hours, then changed the bridge code and drained 766 ETH in a single transaction.
NEAR Intents Halts After $3.8 Million Omni Exploit — Days After Freezing Bitget's Stolen Funds
The cross-chain trading protocol lost about $3.8 million to a bug in its Omni deposit and withdrawal system, paused services across eleven networks, and pledged full reimbursement — one week after its risk system rejected $50 million in swaps tied to the Bitget theft.
Ostium Opens Recovery Portal for $23.75 Million Exploit: 3,321 Wallets Repaid in Full, 345 LPs Face a Choice
The Arbitrum perpetuals protocol has begun repaying victims of its July 15 exploit, with 90.59% of the 3,666 affected wallets eligible for full compensation while larger liquidity providers must choose between a $1,000 payout or a second-phase recovery plan.
Security Digest — October 2, 2026: Bitget Due to Complete Phased Withdrawal Restoration, Q3 Hack Losses Hit $1.26 Billion
The day's smaller security stories in brief: Bitget's final withdrawal phase — all remaining tokens, fiat and P2P — is scheduled for 08:00 UTC today, the protection fund is back above $300 million ahead of schedule, and CoinDesk's quarter tally puts Q3 hack losses at $1.26 billion.
Bitget Forensics: SlowMist and Mandiant Trace the Breach to an August 31 Zero-Day Foothold
Interim findings from the two firms Bitget hired put the attacker inside the exchange's environment 24 days before funds moved — a zero-day in a third-party security product, stolen employee credentials, and a custom withdrawal tool. No private keys were taken.
Stolen Bitget Funds Reach Zcash's Ironwood Pool as Cross-Chain Routes Close
Wallets linked to the $387.5 million Bitget theft shielded 2,746 ZEC — about 15% of the stolen Zcash — inside Ironwood after NEAR Intents rejected over $50 million in attempted swaps and roughly $79 million in ETH was already cycled through THORChain into Bitcoin.
Security Digest — October 1, 2026: Suspected DPRK Haul Passes $1 Billion, Bitget Bleeds $463 Million in Outflows
The day's smaller security stories in brief: suspected North Korean-linked thefts push past $1 billion for 2026 on the back of the Bitget hack, customers pull $463 million from the exchange since the breach, and the recovery outlook darkens.
September Cost Crypto $766 Million — CertiK and PeckShield Agree It Was 2026's Worst Month
Two independent security firms converge on roughly $766 million in September losses, with the Bitget and Liquid Network breaches making up more than 92% of the total — and the damage came from third-party infrastructure and signature failures, not classic DeFi bugs.
Apple Patches CoreGraphics Zero-Day CVE-2026-86950 Exploited Against Targeted iPhone Users
Apple's September 28 security updates close an out-of-bounds write in CoreGraphics, reported by Meta Product Security, that the company says may have been exploited in extremely sophisticated attacks against specific individuals on pre-iOS 27 versions — with blockchain security firms noting a suspected crypto wallet targeting angle that remains unconfirmed.
Bitget Day Six: Recovery 'Unlikely' as Withdrawal Restoration Reaches Its Real Stress Test
With less than $503,000 of the $387.5 million Bitget breach frozen worldwide, CEO Gracy Chen says full recovery is unlikely; USDT withdrawals across four chains opened September 30 at 08:00 UTC — the moment that will actually test user confidence in the exchange's Protection Fund.
Chainalysis: 'Blockchain Dead Drops' — Malware C2 Hidden in Smart Contracts — Up More Than Fourfold
Chainalysis research shows malicious writes to public blockchains used as malware command-and-control infrastructure climbing from about two to more than eleven per day, with state-linked groups behind roughly half of all dead-drop activity by Q2 2026 — DPRK-attributed relays across TRON, BSC and Aptos, Polygon C2 resolvers, and Bitcoin OP_RETURN pointers.
Payy Post-Mortem: Invalid Burn Proof Accepted by Noir Verifier Drained $1.9M USDC
Payy's technical post-mortem pins the September 24 bridge exploit on a proving-system flaw in the deployed Noir/Barretenberg verifier, which accepted an invalid burn proof and released roughly 1.92 million USDC to a single wallet — a supply-side risk for every project using the same Aztec toolchain.
Security Digest — September 30, 2026: SectopRAT in Trusted Software, Citrix NetScaler Zero-Days Under Exploit
Today's roundup: Fortinet documents a SectopRAT campaign hiding a full remote-access trojan inside legitimate audio software to harvest crypto wallet data from 35+ browsers, and Citrix warns that NetScaler zero-days are being exploited for web shells and credential theft — plus the day's checkpoints at Bitget and Payy.
Bitget Points to Third-Party Security Product as Source of $388M Hack
CEO Gracy Chen says the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials and issue fraudulent withdrawal commands — the first root-cause detail on the September 24 breach that took $387.5 million.
Bitquery Ties 56 Robinhood Chain Memecoin Launches to One Suspected Rug-Pull Crew
On-chain analysis links a single coordinated group to 56 Pons launchpad tokens on Robinhood Chain with an estimated $15.5 million extracted — and finds 467 other groups running the same tax-exemption tactic.
Security Digest: Placeholder Domain Turned Attack Infrastructure, PamStealer Goes Server-Side, OpenAI Agents Linked to Website Hacks
The day's smaller security stories in brief: a documentation placeholder domain referenced in ~1,700 repos was registered and now serves ClickFix lures, a macOS stealer adds live C2 payload decryption, and researchers catch AI agents exploiting websites during mundane tasks.
Senate Report Says USDT Anchors Iran's Shadow Banking, Refers Tether to Treasury and DOJ
Senator Blumenthal's PSI investigation found 84% of 846 Iran-linked sanctioned wallets transacted almost exclusively in USDT, and asked Treasury and DOJ to examine Tether's sanctions and Bank Secrecy Act compliance — Tether counters that it froze nearly $550 million in Iran-linked tokens this year.
Kelp DAO Sues LayerZero and CEO Pellegrino Over $292M rsETH Bridge Exploit
Evercrest, the company behind Kelp DAO, filed suit in the Supreme Court of British Columbia alleging LayerZero endorsed the single-verifier bridge setup attackers exploited in April, then publicly blamed Kelp for it — claims Pellegrino calls meritless.
Liquid Network Actors 'Crossed Into Theft' by Keeping 598.5 BTC, Immunefi CEO Says
Immunefi's Mitchell Amador says the self-described white hats who returned 3,400 BTC from the ~4,000 BTC Liquid Network drain lost any rescue claim by retaining 598.5 BTC and demanding a bounty — reviving the debate over rescue terms set before exploits, not after.
Security Digest: Bitget Reopens Withdrawals Today, THORChain Declines Blocking Request, DarkMe RAT Aims at Crypto Users
The day's smaller security stories in brief: Bitget begins phased withdrawal restarts at 08:00 UTC with losses confirmed at $387.5M, THORChain refuses Bitget's call to block attacker addresses, and Huntress documents a DarkMe RAT campaign whose loaders probe for crypto wallets and trading terminals.