News linked to both this project and an event.
MetaMask announced it is exiting the affected validator nodes in its non-custodial staking service, and there are currently no signs that wallets or customer funds have been compromised.
MetaMask stated that some infrastructure was affected by a security incident, but no direct threat to MetaMask wallets has been identified to date, and it has voluntarily exited the affected validator nodes.
Odaily reports: Bitget stated on X platform that an investigation by Google Cloud's Mandiant into Bitget's September 24 security incident found that attackers gained unauthorized access to certain third-party security devices, then laterally moved into Bitget's exchange wallet environment and obtained access to both warm and hot wallets. The investigation findings are consistent with the attack path previously disclosed by Bitget.
OKX founder Star posted on X platform regarding the Bitget hack incident, stating that THORChain is a "very unique" part of the crypto industry. After Bitget was attacked, both the OKX exchange and OKX Wallet immediately took action and stood ready to assist in identifying and tracing the flow of stolen funds, and to block the transfer of stolen funds where possible. Star stated that resilience is an important quality that every crypto company should possess; when security incidents occur, the industry needs to respond quickly, share information, and cooperate to protect users and prevent similar attacks from happening again. He emphasized: "Security is not a competition, but a shared responsibility."
Bitget CEO Gracy Chen 发布安全事件最新进展称,平台正与独立第三方安全团队 Mandiant 和慢雾合作,对此次事件展开全面调查。 Gracy Chen 表示,目前用户账户余额保持完整,此次平台层面安全事件造成的影响将由 Bitget 用户保护基金覆盖;Bitget Wallet 采用自托管模式,其基础设施与 Bitget Exchange 相互独立,因此未受到此次事件影响。 目前 Bitget Exchange 的充值、交易及奖励等功能继续运行,但提币仍暂时暂停,平台正在进行额外安全核查,确认安全后将恢复。Bitget 官方公告也显示,提币服务目前仍处于暂停状态,充值和交易正常运行。 Bitget 表示,后续调查进展及安全事件相关信息将通过官方渠道持续公布。
Bitget CEO Gracy Chen posted a 12-hour progress report on the security incident on X, including:1. Affected assets include ETH, XRP (largest single-chain loss), BNB, AVAX, USDT, USDC, and other tokens. Affected chains include: Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. All on-chain cold wallets have been confirmed secure and unaffected.2. All foundations of the affected chains have been contacted, and some foundations have confirmed the freezing of the hacker's wallet addresses.3. Based on IP behavioral characteristics and on-chain analysis, the attack methodology is highly consistent with known patterns of North Korean hacker groups. Relevant authorities have been notified, and full cooperation is being provided for a global investigation.4. Bitget Wallet (decentralized wallet) operates completely independently from Bitget exchange infrastructure, and this incident has no impact on it. Bitget Wallet assets are completely safe.5. Transparent disclosure regarding the platform's financial status: In addition to over $464 million in protection funds (all held in publicly verifiable wallet addresses), Bitget's own assets exceed $1 billion. User funds are covered at a 1:1 ratio, and all data can be verified on-chain.6. Regarding withdrawal recovery timing: The goal is to achieve full recovery as soon as possible. Once a specific time window is confirmed, an announcement will be made immediately. No commitment will be made to timelines that cannot be fulfilled.
Binance Wallet announced the launch of real-time detection and risk blocking features targeting high-risk signature scenarios to prevent phishing attacks exploiting DeFi project authorization mechanisms. Binance stated that certain attacks only require tricking users into completing gas-free offline signatures, which can directly lead to stolen assets. It will continue to expand its risk identification scenarios and security protection coverage moving forward.
Bitget Wallet stated on X that it operates independently from the Bitget exchange and is a self-custodial wallet. User assets always remain on-chain and are controlled by users themselves, isolated from the custodial infrastructure of the Bitget exchange.In response to the recent security incident at Bitget, Bitget Wallet has conducted preventive checks on its internal systems and found no security impact from the incident on Bitget Wallet's systems or users' self-custodied assets. Bitget Wallet is currently operating normally, and users are reminded to be vigilant against phishing and impersonation attempts and to obtain the latest information through official channels.
According to Scam Sniffer (@realScamSniffer), Duelbits' hot wallets on Ethereum, BSC, and Tron are suspected of having leaked private keys, with approximately $4.2 million in assets flowing to newly created addresses. The transferred assets include 836 ETH, 1.62 million USDT, 97,000 USDC, 209 BNB, and 192,000 TRX, with most of them already converted to ETH. The hacker's EVM address is 0xa77e24fe29d16e051e487ef4ea7b056cb05aef76.
According to The Defiant, Cosmos Hub resumed operations after ceasing block production for 24 hours and 48 minutes. The Neutron attacker purchased voting power for 20,199 USDC and completed staking just 12 minutes before an expedited proposal expired; the relevant wallet subsequently transferred 1.23 million ATOM.
Odaily reports: SlowMist Chief Information Security Officer 23pds has stated that attackers are exploiting the Darksword vulnerability to bypass iOS security mechanisms through Safari, take control of devices, and extract private keys and other data from self-custodial crypto wallets. The vulnerability was previously used in attacks targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine.Google Threat Intelligence Group previously disclosed that Darksword initially only affected iOS versions 18.4 through 18.7. According to 23pds, attackers have now adapted it to iOS 26.5, though this assessment has not yet been officially verified.Attacks typically begin with social engineering. After users click on malicious links sent via social media or messaging apps, their devices may be rooted and wallet data extracted. Users should promptly update their phone's operating system and avoid visiting website links sent by strangers. Separately, three investors who lost nearly $1.8 million in Bitcoin after downloading fake wallet apps from Apple's official App Store have filed a lawsuit against Apple. (Bitcoin.com News)
According to Yonhap News Agency, the Busan Metropolitan Police Agency revealed that on the morning of September 12, an unauthorized individual breached the SMS agency account used by the marketing department of a mixed-use shopping complex in Sasang-gu, Busan. The attacker bulk-sent scam messages to over 260,000 unspecified recipients, claiming "your cryptocurrency wallet has been updated" and urging quick installation. Once users clicked the attached links, they could fall victim to a smishing attack, potentially resulting in the theft of their virtual assets. Police have since blocked access to the relevant accounts and are actively investigating the intruders.
According to CoinDesk, a Gnosis Safe wallet on Ethereum was attacked, with approximately 2,900 rsETH (valued at around $7.8 million) transferred. Security firms BlockSec, Blockaid, and SlowMist pointed out that the root cause of the attack lies in an authorization check flaw within the wallet-approved Multicall contract—the contract is intended to verify caller permissions, but the vulnerability allows anyone to bypass validation simply by targeting the contract itself. The attacker subsequently moved the rsETH into a liquidity pool based on the valueless token "Permissionless Attacker Token." An automated bot named "yoink" paid approximately $47,000 to frontrun the transaction, transferring 2,882 rsETH to a separate address. rsETH issuer Kelp DAO stated that its smart contracts are secure and rsETH is fully collateralized, and has implemented a 24-hour pause measure on the relevant addresses.
The EU's Cyber Resilience Act has taken effect. Cryptocurrency hardware and software wallet providers must submit an initial early warning within 24 hours after discovering actively exploited vulnerabilities or severe security flaws in their products, and submit a full notification within 72 hours.Manufacturers must submit a final report within 14 days after corrective or mitigating measures become available; serious incidents must be reported within one month. Companies that violate the relevant regulations may face fines of up to €15 million or 2.5% of global annual turnover, whichever is higher; providing false, incomplete, or misleading information may result in fines of up to €5 million. (Cointelegraph)
Binance Wallet announced that following a security incident involving the Nesa (NES) token contract, Binance Alpha 2.0 will support NES contract swaps on BNB Smart Chain (BEP20) and provide compensation arrangements for eligible users: first, balances held by users as of 14:51 UTC on August 24, 2026, and maintained through to 04:00 UTC on September 5, 2026, will be swapped to the new contract at a 1:1 ratio; subsequent purchases will not be eligible for the swap and will be refunded separately. Second, users with net purchases of NES between 14:51 UTC on August 24, 2026, and 04:00 UTC on September 5, 2026, will receive an email detailing the specific refund plan within seven working days. Trading of NES on Binance Alpha 2.0 is expected to resume on September 10, 2026, at 08:00 UTC.
Odaily News: Binance stated that in the first half of 2026, the Binance Wallet Security Center helped users avoid approximately $540 million in potential losses, filtering about 206 million spam transfers, identifying 4.93 million high-risk transactions, and approximately 996,000 malicious authorizations during the period. Binance noted that AI is being used by attackers to mass-generate malicious code, phishing websites, and fake identities, shifting attacks from broad-based approaches to more targeted fraud.
Odaily News, According to a disclosure by the SlowMist security team, they have detected an attack campaign disguised as a free VPS service, specifically targeting iPhone Safari browsers running iOS versions 18.4 to 18.6.2. The attackers exploited a chain of six vulnerabilities codenamed DarkSword to form a complete attack sequence, covering WebKit remote code execution, sandbox escape, and kernel read/write operations. This allows them to access app container files and keychain data without user awareness, and record keyboard inputs while wallets such as imToken, TokenPocket, or TronLink are in the foreground.The SlowMist team stated that all six aforementioned vulnerabilities have been patched by Apple, and the current attack constitutes reuse of an n-day vulnerability chain. Merely visiting a malicious page does not directly prove that mnemonic phrases or private keys have been stolen, and device forensics is still required for confirmation. iOS/iPadOS users are advised to upgrade their systems to version 18.7.3 or 26.3 and above as soon as possible.
Malwarebytes researchers discovered a website disguised as a Grand Theft Auto VI (GTA 6) fan countdown page that lured users into purchasing the so-called leaked version of the game and loaded a wallet drainer program after users connected their cryptocurrency wallets. The malicious code checks wallet balances, identifies tokens and NFTs, and transfers assets once users approve transactions or grant authorizations.
According to Cointelegraph, cybersecurity firm Morphisec has revealed that a counterfeit desktop application masquerading as Anthropic’s "Claude Opus 5 Free Desktop" is being leveraged to distribute the Windows malware RevStealer. The malicious program can exfiltrate data from over 50 cryptocurrency wallets, while simultaneously harvesting sensitive information including browser passwords, cookies, VPN configurations, message logs, and screenshots. RevStealer incorporates anti-detection measures, performing system environment checks on the target device prior to execution. If traces of debugging or virtualized environments are detected, it aborts its operation. Additionally, Russian cybersecurity company Kaspersky has disclosed OkoBot, a novel malware framework targeting crypto investors capable of harvesting wallet files, injecting malicious extensions, and capturing wallet application windows to siphon assets.
According to security firm Huntress, hackers are distributing credential-stealing malware to cryptocurrency users through forged Google Docs files, malicious files hosted on GitHub, and cloned Claude.ai pages. Attackers impersonate senior CoinDesk employees on the social platform X, luring victims into opening Google Docs documents containing malicious code under the guise of an online meeting invitation, which then prompts users to manually install the malicious software. Mac users face threats from Atomic macOS Stealer (AMOS), which can steal browser passwords, cryptocurrency wallet data, and Telegram files; Windows users are served fake Google API Connector updates that, once installed, deploy NetSupport RAT and counterfeit Ledger hardware wallet applications. Additionally, hackers have placed fraudulent ads on search engines like Bing to lure users to cloned Claude.ai pages where they execute malicious commands; the associated malware, MacSync and SectopRAT, can steal cookies, saved passwords, mnemonic phrases, and payment card information. Security firm Socket also concurrently identified 16 malicious extensions targeting Chrome and Edge, capable of draining EVM, Solana, and Tron wallet assets.