#PeckShieldAlert In Sep. 2026, the crypto industry experienced 55 major hacks, resulting in total losses of $766.49M - a ~462% month-over-month increase from August's $136.3M.
The #Bitget incident (~$387M) and #LiquidNetwork (~$320M, with $285M returned) have jumped to #1 & #2 among the largest crypto thefts of the year to date, surpassing the #Drift and #KelpDAO/#LayerZero exploits.
Top 10 hacks in Sep.
- #Bitget: $387M
- #LiquidNetwork: $320M (returned $285M)
- MEV bot "yoink" front-run: $7.81M (returned)
- #Duelbits: $7M
- Payment Processor V2 : $6.6M (returned $3.4M)
- #DCENT Wallet: $6.57M
- #Astroport: $4.9M
- #Drop: $4.4M
- #NostraFinance: $3.5M
- #Nomic nBTC Bridge: $3.15M
@Cointelegraph If validators are exiting as a precaution, does that mean the compromise is contained to infra, or could staker withdrawal addresses also be exposed? Worth asking before moving funds anywhere near MetaMask Staking.
Ran the BSC theft address through OFAC, Chainalysis, TRM, USDT/USDC blacklists and open scam lists a few hours after the exploit.
Not on any of them yet.
On a fresh hack, "clean" means "not listed yet". Take funds from it on P2P today and the freeze can land on you later.
Seven years dormant then a sudden 25,776 QNT move. Was this an OTC deal, a custody upgrade, or prep to sell? Anyone tracking where those new wallets send funds next, screen before assuming the worst.
The FCA cryptoasset authorisation gateway opened at 09:00 today. It closes 23:59 on 28 February 2027.
Firms that miss the window fall back to servicing pre-existing contracts only — no new customers.
The bar moves from MLR registration to FSMA authorisation.
@WuBlockchain@GracyBitget If THORChain blocks one attacker address on request, is it still neutral infrastructure or does it become a de facto compliance layer picking winners case by case?
@lookonchain Two wallets, same whale, both exchange, one month, no wallet-to-wallet transfer shown yet. Genuine question: is this cold storage conviction buying, or staging for OTC distribution once ZEC finds a floor? The next hop from these addresses will tell us.
63% of early EIP-7702 authorizations pointed at attacker-controlled contracts.
That figure is from Huang et al., USENIX Security 2026: 3,664,166 authorizations across 7 chains, cutoff 15 July 2025. Confirmed losses in that window: $2.36M. It counts transactions, not unique victims — malicious contracts get reused a lot, so the percentage overstates how many users were hit. It does not mean 63% of wallets today are owned by attackers.
What actually changed with Pectra: before, an EOA could not run contract code. Now one signed authorization plants a code pointer on your address. A drainer can then sweep ETH, tokens and NFTs in a single atomic batch. Token approvals are still a risk. They are no longer the whole picture.
Practical step: check what your address has delegated to, not only what it approved. Revoking approvals does not clear a 7702 delegation.
Check: https://t.co/4XguwXGfVB
Laundering with a help desk.
The chain side is just as busy: 20,100 ETH left two of those wallets since yesterday, and one keeps refilling — money passes straight through it.
The practical bit: a published address list is a photo of something that has already moved on.
@dangsoun Capstone processed hundreds of millions for Tether and Bitfinex before the $84.2M seizure. Worth asking which downstream wallets received these funds and whether any already touched exchange deposit addresses.
0KX WEB3.
That's a zero, not an O — one of 40 browser extensions caught stealing
seed phrases.
Same trick twice more this week while tracing the Bitget money:
lookalike addresses, fake "ETH" tokens.
Your eye reads the word. It never checks the characters.
@smartcoded@circle $318K frozen is under 1% of the $351.6M drained — the rest is already moving through mixers and cross-chain bridges. Screen any wallet that touched Bitget's hot wallets before you interact with it.
$318K frozen out of $351.6M. 0.09%. Correct — and worth saying why.
We traced the rest: 68,923 ETH sitting in 9 wallets. Six of them hold exactly 10,000 ETH each.
No issuer can freeze that. Which is why the stablecoins became ETH within hours.
Seven different failures in one word. Bitget: backend spoofed, keys never stolen. Ledger: a marketing DB and an npm package, never the chip. Cold wallet: usually a seed that stopped being offline.
2025: 76% of losses came from credentials and social engineering, not code.
We traced where the $352M from Bitget actually went in the first 24 hours.
One pattern explains everything else: the stablecoins ran, the ETH went to sleep.
CEX vs DEX after the Bitget hack
Everyone said the Bitget hack means it's time to leave CEXs for DEXs.
So we measured whether anyone actually did.
Spot DEX volume, all chains:
Before (Sep 17–23): $11.03B/day
After (Sep 24–26): $10.45B/day
Not a rise. A 5.2% fall. 🧵
🔴 $352M drained from Bitget. And the keys were never stolen
PUBLISH DATE: 25.09.2026
At 18:31 UTC yesterday Bitget detected unauthorised transfers out of its hot wallets. The total: $351.6 million, the largest crypto theft of 2026.
WHAT ACTUALLY HAPPENED
The interesting part is not the number, it is the method. No private keys leaked. The attacker found a flaw in the exchange's back end, spoofed transaction history, and made the system process the withdrawals as legitimate.
Which means the usual advice — "keep your keys in cold storage" — would not have helped here at all. What was broken was not the keys but the logic that decides which transfer counts as yours.
Cold wallets were untouched. The exchange says losses will be covered from its $464 million User Protection Fund, which is larger than the amount stolen.
@IntCyberDigest If you were drained in that window, speed decides everything. A Solana collector we traced from Sep 19 held funds 2-5 hours, then pushed them through one-time deposit addresses into an instant exchange.
Compliance can still hold an order that day. Not a week later.
The 15-day number isn't a rumour from support
— Star Xu said it himself on Sept 2, replying to someone whose transfer from a betting platform triggered a risk-control review. Enhanced AML review can restrict funds for 15 days or longer, and he specifically named Telegram-group escrow deals as a high-risk channel. So if your deposit came in through either, what you're seeing is the documented process, not an agent losing your ticket.
What's worth doing while the clock runs:
1. Don't deposit into that account again. A second flagged deposit restarts the review.
2. Write the chain down while you still remember it — who sent the coins, through what service, what you paid. Screenshots of the P2P deal, the exchanger receipt, the sender's address.
3. Get an independent trace of the deposit. The useful half isn't "your address is clean" — it's **what it didn't touch**: no sanctioned entity, no mixer, no darknet market within N hops. That's the part a compliance reviewer can actually act on.
4. Answer literally. "Source of funds" means documents, not an explanation in prose.
Disclosure: I work on AMLConsensus, we do this kind of screening. The address check is free and needs no wallet connection — https://t.co/10U41PBFpf. We're also doing 5 full appeal dossiers for free at the moment because we want documented cases to point at. No promises on the outcome — that's the exchange's decision — but the paperwork they're asking for is something you can actually produce.
What broke: the device's hardware RNG was bypassed and seeds were generated with weak software randomness.
The keys weren't stolen — they were recomputable from day one. $100M+ drained in waves since July 30.