NEAR Intents2026-10-03 11:59:10NEAR Intents recovers full $3.8 million after 48-hour ultimatum to exploiterNEAR Intents said it has recovered the roughly $3.8 million stolen in a Thursday security breach after identifying the exploiter and giving them 48 hours to return the funds under a "responsible disclosure" process. Later on Friday, general manager Alex Shevchenko said the money had been returned in full and that the investigation would stop. The project had previously paused services after finding what it described as a bug involving the Omni deposit and withdrawal infrastructure’s interaction with the NEAR Intents smart contract. NEAR’s preliminary review said $3.8 million in user funds had been taken and that affected users would be made whole. Blockchain investigator ZachXBT also said the stolen funds were moved to KuCoin and bridged to Bitcoin.60
Drift Foundat2026-09-30 14:26:46Drift Foundation says $9.2 million in stolen funds frozen, 107,165 ETH remains unmovedDrift Foundation has released an update on recovery efforts tied to its April 1 security incident, saying roughly $295.4 million in user assets was stolen. The foundation said it hired Mandiant, zeroShadow, and SEAL 911 to investigate the attack and trace the funds. Mandiant identified the attacker as North Korean threat group UNC6862. According to the update, the stolen assets were later bridged to Ethereum and split across four wallets holding about 130,259 ETH in total. Three of those wallets, containing a combined 107,165 ETH, have not moved any funds so far. A fourth wallet transferred about 23,094 ETH to Tornado Cash on July 23. The foundation said about $9.2 million in stolen funds has now been frozen. Those funds had previously moved through Tornado Cash in August, though any unfreezing and return process will still require legal coordination. Drift Foundation also said any assets recovered through freezes, bounty efforts, or law enforcement will be sent to the DFX recovery pool. In parallel, it is evaluating the future path of the DRIFT token across the broader ecosystem. The foundation has also launched a public bounty program with Bybit, offering a 10% reward on successfully recovered funds.70
Drift Foundat2026-09-30 14:28:02Drift Foundation says $9.2 million frozen in recovery effort tied to April security breachThe Drift Foundation has released an update on efforts to recover funds stolen in its April 1 security incident, saying about $295.4 million in user assets was taken. The foundation said it hired Mandiant, zeroShadow, and SEAL 911 to investigate the attack and trace the funds. Mandiant identified the attacker as North Korean threat group UNC6862, according to the update. The stolen assets were later bridged to Ethereum and spread across four wallets holding about 130,259 ETH in total. Three of those wallets, which together hold 107,165 ETH, have not moved funds so far. A fourth wallet transferred about 23,094 ETH to Tornado Cash on July 23. Drift said roughly $9.2 million in stolen funds has now been frozen. Those assets had previously moved through Tornado Cash in August, and the foundation said any unfreezing and return of funds will still require legal procedures. The foundation added that any assets recovered through freezes, bounty programs, or law enforcement channels will be sent to the DFX recovery pool. It is also evaluating the future path of the DRIFT token across the broader ecosystem. In addition, Drift said it has worked with Bybit to launch a public bounty program that offers a 10% reward on successfully recovered funds.40
SlowMist2026-09-30 04:23:06SlowMist says Bitget hot wallet theft probe points to third-party security product flawSlowMist said on Sept. 30 that Bitget had asked its security team to investigate the hot wallet asset theft that took place on Sept. 25. As of Sept. 29, the firm said its investigation had found that the attack involved a third-party security product, malicious activity on the wallet application host, and a custom withdrawal tool developed by the attacker. According to SlowMist, the attacker used a zero-day vulnerability in a third-party product to carry out malicious actions, then used an internal employee identity on Sept. 25 to gain unauthorized access to the management platform of that third-party product. The attacker also obtained and used a customized tool designed around the wallet’s withdrawal logic. SlowMist said on-chain activity began at 02:31 on Sept. 25 (UTC+8), and assets were moved across multiple blockchains over roughly 2 hours and 52 minutes. It added that the attacker later attempted to tamper with withdrawal records and triggered additional BTC withdrawals. The firm said it is still investigating how the attacker moved laterally between affected systems.170
Bitget2026-09-28 07:53:00Bitget CEO says about $388 million was moved by attackers, protection fund to be restored above $300 million within a weekBitget CEO Gracy Chen said in a livestream that attackers exploited a vulnerability in a third-party security product to steal internal credential permissions and forge withdrawal instructions to the exchange’s wallet system, bypassing risk-control checks. She said private keys were not compromised and cold wallets were not affected, adding that the vulnerability has been fixed and the incident is now fully contained. Chen said the amount confirmed to have been moved out was about $388 million. She also said Bitget has publicly released the attacker addresses and on-chain tracking data. According to Chen, all losses from the incident will be covered by the user protection fund, and the exchange will replenish that fund to at least $300 million within one week after using it. Bitget has also started an asset recovery plan and will share confirmed vulnerability and attack details with relevant industry parties.210
DeFi2026-09-25 11:38:48Payy Network, Duelbits, and Meter lose more than $11 million in three attacks over one dayThree separate crypto security incidents hit in a single day, pushing combined losses past $11 million, according to Protos. Payy Network was the first to be exploited after its Ethereum bridge was drained of its full balance, with losses pegged at $1.8 million. The company said the stolen assets were users’ non-custodial deposits tied to Payy Network and Payy Wallet, and paused all transactions while the investigation continues. Duelbits, a crypto casino and sports betting platform, was then hit in what was described as a suspected private key compromise. Estimates climbed from $4.3 million to $5.9 million before co-founder Joe put the figure at about $7 million. He said the platform would remain offline until the team understood what happened, while adding that user funds were safe and hot wallets would be replenished before services resumed. Meter.io, an EVM blockchain, disclosed a separate bridge-related incident tied to a block validation flaw. The attacker minted unbacked MTR and MTRG, sold them on PancakeSwap, and bridged funds out, with reported losses of roughly $2.3 million. Meter paused its mainnet and bridge, said chain state had been preserved, and told users to stop all activity. The sell-off sent MTR and MTRG down almost 80% and 75%, respectively.250
Chainflip2026-09-13 12:53:44Chainflip says 736,442.17 USDT was stolen in Tron USDT exploit, restart targeted around MondayCross-chain protocol Chainflip disclosed an attack involving Tron USDT and said 736,442.17 USDT was stolen through six unauthorized payouts. The project also said 115,654.41 USDT tied to user swaps remains in the vault after payout failures, while all other funds were unaffected. According to Chainflip, the attacker abused a flaw related to Tron transaction memos by attaching custom memos to validator-signed transactions, causing the system to treat the same deposit as a separate swap and issue another refund. Chainflip said the attacker carried out eight operations over roughly 90 minutes and increased the amounts over time. The team said a fix has been completed, the stolen funds have been flagged with relevant institutions in an attempt to recover them, and operations are expected to resume as early as Monday. Chainflip also said it will cover losses suffered by affected users.820
Zeabur2026-09-10 01:55:12Zeabur says August security breach exposed database access and some user secretsCloud deployment platform Zeabur has released its full investigation into an August security incident that led to unauthorized access to part of its production database and the reading of some users’ project environment variables. According to the report, the attack began with a vulnerability in a user-deployed NextChat v2.16.1 service running in a Tokyo shared cluster. The intruder then moved through cached routing data containing legacy Zeabur API keys, obtained an administrator key, accessed internal services holding AWS credentials including a long-retained AWS root key, and eventually reached the production database through a maintenance job connected over a private network. Zeabur said the exposed data may have included third-party and AI service API keys, cloud access credentials, database connection details and passwords, GitHub tokens, JWT secrets, and application signing keys. It added that while attackers created new AI Hub access keys, usage and billing logs showed those keys were not used and generated no charges. The company has since disabled Legacy API Key authentication, rotated internal keys and passwords, cut the shared cluster’s path to the production database, added stronger authorization controls and alerts, and advised all users to replace any still-valid credentials that had been stored in environment variables.810