Bitget2026-09-25 01:01:01Bitget says security incident involved about $351.6 million, with losses covered by user protection fundBitget said a security incident detected early on Sept. 25 involved abnormal transfers from some of its hot wallets, with an initial estimated impact of about $351.6 million. In a statement attributed to Xie Jiayin, head of Bitget’s Chinese-language division, the exchange said its security system flagged the transfers at 2:31 a.m. and its team activated an emergency response immediately. According to the announcement, cold wallets and the vast majority of platform assets remain intact and unaffected. Bitget also said user funds are safe and that the losses fall fully within the coverage of its user protection fund, which it said currently exceeds $464 million. The exchange said it formed an emergency response group within minutes of the incident, marked and reported the abnormal transfer addresses, and notified law enforcement agencies as well as on-chain security firms to join the investigation. Withdrawals have been temporarily suspended while security checks are completed, though deposits and trading remain available. Bitget said it plans to release a full incident report within 24 hours, including a root-cause analysis and corrective measures.230
Bitget2026-09-25 14:15:15Bitget launches recovery bounty program with 5% rewards for frozen or recovered fundsBitget said on Sept. 25 that it has opened a "Recovery Bounty Program" tied to a recent security incident, calling on exchanges, blockchain projects, security researchers, investigation firms and on-chain communities to help freeze and recover affected assets. Under the program, participants who successfully freeze funds can receive a bounty equal to 5% of the amount frozen, while those who help recover assets can also receive 5% of the amount recovered. The exchange said Bybit’s Lazarus Bounty program will serve as one of the core channels for the bounty and recovery effort. Bitget also set limits on eligibility: actions taken through court orders, law enforcement requests or other legal procedures do not qualify for rewards. The company said final decisions on eligibility, contribution assessment and bounty amounts will be made by Bitget.260
SlowMist2026-09-22 09:03:30SlowMist says DoinGud contract flaw let attacker replay transactions and net about 35,380 USDCSlowMist disclosed a logic flaw in a DoinGud smart contract that allowed an attacker to replay the same transaction data and withdraw funds multiple times. The issue was tied to the contract’s acceptOffer function, where the security firm said protections against duplicate transactions were missing and required state-cleanup checks were not in place. According to the disclosure, the attacker used two replayed transactions to drain all 70,973.871434 USDC held in the contract’s escrow account, ending with a profit of about 35,380 USDC. SlowMist also said the attack was funded with a flash loan, and that the attacker supplied neither any NFT nor any principal of their own. The vulnerable contract address was identified as 0x123aafc8d0a07ce1a146e53aa899e77f21a2dde1, while the attacker address was listed as 0xb8c717239bcace558c3a8dc471c16e07bf57a1eb. The disclosure was cited by Techub News and attributed to @SlowMist_Team.390
SlowMist2026-09-22 02:46:49SlowMist flags GaslessReservoirEnabler flaw after about $23,000 in WETH and ZED is drainedSlowMist disclosed a smart contract security incident involving the GaslessReservoirEnabler contract, saying a flaw in its erc20WithTransfersAndExecute function allowed an attacker to move about $23,000 worth of WETH and ZED. According to the security firm, the issue stems from the _executeInternal function, which checked the module address but did not bind ERC20 transferFrom instructions to the authorized asset owner. That design let any caller spend an existing allowance from victims as long as the token was on the whitelist. SlowMist said the attack affected 997 token holder addresses. It identified the attacker address as 0x46f54c1a86575679fc3d29666c1717e9786279aa and the affected contract as 0x9b58fdadc16e30fba313e044bf9e88689c3f163e. The stolen funds have since been consolidated and deposited into a cross-chain bridge on Polygon, according to the disclosure cited by Techub News.360
SlowMist2026-09-21 01:58:08SlowMist says App Store-listed FomoPeek carried modules that could steal wallet data across appsSlowMist said in a Sept. 20 report that FomoPeek, an on-chain monitoring app distributed through Apple’s App Store, included two malicious modules in versions 1.1 and 1.2 that could remotely fetch instructions, attempt kernel exploits, escape sandbox restrictions, decrypt Keychain data and collect information from other apps. The security firm said the case began after multiple users reported stolen assets and private key exposure, with some of the affected users having used those two versions before the thefts. According to the report, FomoPeek presented itself as a standard crypto tracking product. It had an App Store listing, a website, and an official X account, and marketed itself as a read-only whale tracker for Solana, Ethereum and TRON wallets that did not require seed phrases or wallet connections. SlowMist said its isolated testing retrieved a collection list covering 19 wallet and note-taking apps and captured an uploaded archive containing Apple Notes data. The report also traced one main attacker address analyzed by MistTrack. SlowMist said the address had been active since Sept. 15 and had received a cumulative 579,984.34 USDT by the time the report was published. Funds touched Ethereum, BNB Chain and Arbitrum, with part of the flow moving through FixedFloat and KuCoin. SlowMist advised users who had run FomoPeek 1.1 or 1.2 to treat related seed phrases, private keys and credentials as compromised and migrate assets on a separate trusted device.3151
PeckShield2026-09-20 09:26:44PeckShield says attacker exploited SingularityNET bridge contract flaw to mint AGIX and WMTxOn-chain security analyst PeckShield said the same attacker exploited a vulnerability in the SingularityNET bridge contract and illegally minted 260 million AGIX and 53.838 million WMTx on Ethereum. Based on the figures shared by PeckShield, the attacker is currently holding about $16.77 million in crypto assets. That stash includes 198.3 million AGIX worth about $14.42 million, 649 ETH worth about $1.67 million, and 33.538 million WMTx worth about $627,000. The update was cited by ChainCatcher as a market analysis newsflash.290
Ethereum2026-09-20 03:52:23BlockSec Phalcon says Ethereum attack spree hit multiple projects for over $2.1 millionBlockSec’s monitoring platform Phalcon said it detected a series of attack transactions targeting smart contracts on Ethereum, with Fetch.ai, nunet_global and SingularityNET among the affected projects. The total loss exceeded $2.1 million, according to the security firm. Phalcon said the incident appears to have stemmed from the compromise of private keys tied to two addresses. The attacker then used those leaked keys to carry out malicious transactions on-chain. So far, the projects involved have not released additional details about the incident. They also have not outlined any compensation plan or follow-up measures, based on the information provided in the original report from Techub News.300
arbitrage bot2026-09-19 13:01:00Fake Uniswap ENS names used in arbitrage bot scam that stole over $500,000On-chain investigator Specter said an arbitrage bot scam has led to losses of more than $500,000. The attackers reportedly used YouTube videos to distribute supposed tutorials and code, then directed victims to compile and deploy contracts through a fake Remix development interface. To make the setup look legitimate, they registered ENS names containing "Uniswap" and used those addresses to imitate inbound transfers tied to real DeFi activity. That gave victims the impression that the deployed bot was generating profits through Uniswap. Once victims sent their own funds into the contract, the assets were drained by the attackers. Specter added that the operators appear to still be active and continue to hold a sizable share of the stolen funds across two addresses.300