Introduction
September 2026 saw attackers steal approximately $776 million across the 48 major incidents analysed in this report, more than three times August's total. The incidents spanned a centralised exchange, a Bitcoin sidechain, cross-chain bridges, self-custodial and smart-account wallets, DeFi lending and liquidity protocols, an NFT settlement contract, a crypto casino and a long tail of token-level exploits on BNB Chain and Ethereum.

Two incidents defined the month. On 6 September, a bug in the Elements software underpinning Liquid Network allowed an attacker to mint around 4,000 unbacked L-BTC and redeem them for real bitcoin from the federation's reserve, a gross loss of roughly $320 million. The actor, claiming to be a white hat, returned 3,400 BTC the following day but still holds around 598.5 BTC. Then, on 24 September, attackers breached a backend system inside Bitget's wallet infrastructure and used spoofed transaction data to push withdrawals through the exchange's own approval process, draining approximately $387.5 million from its hot and warm wallets. Attribution points to North Korea, and the theft reportedly takes the regime's 2026 crypto haul past $1 billion. Together, Bitget and Liquid Network accounted for around 91% of September's losses, and neither involved a conventional smart contract bug or a stolen private key.
Setting those two aside, the remaining 46 incidents produced approximately $68.5 million in losses, broadly in line with the underlying run rate seen in recent months. The largest of these was a signing flaw in the DCENT App Wallet, which exposed users' recovery phrases and saw more than 12.4 million XRP drained from over 7,000 wallets across roughly a week, an estimated $20 million loss. It was followed by a $7.8 million drain of a single Gnosis Safe through a flawed custom module, and a $7 million hot wallet compromise at crypto casino Duelbits on the same day as Bitget.

Beyond the headline figures, three themes ran through the month. Standing token approvals and legacy contracts continued to be drained long after their owners had stopped paying attention to them, most visibly in the Limit Break Payment Processor exploit, where a white-hat rescue secured more than 23,000 NFTs that had been exposed through approvals granted in 2024. Cross-chain infrastructure was hit repeatedly, with eight bridge and interoperability incidents and a recurring pattern of unbacked minting across Liquid, Nomic, Symbiosis, Meter Passport and the ASI Alliance. And chain-level intervention, first seen at Cronos in August, became a routine part of the response: Liquid, MultiversX and Neutron all halted, Cosmos Hub validators moved 1.23 million ATOM out of an attacker's account, and Osmosis froze 22.65 BTC through an emergency upgrade.
Tornado Cash naturally remained a highly common laundering venue, appearing in the Notional Finance, Cozy Finance, Likwid and DYORSWAP incidents, while Railgun was used to fund the Payy Network attacker's gas ahead of the exploit. Bitget's attackers, by contrast, had left most of the stolen ETH and XRP untouched in their own wallets as of 25 September.
Major crypto attacks in September 2026
GebProxyActions - 02/09/2026
Type: Access Control
The GebProxyActions contract on Ethereum lacked caller access control on its quitSystem function. Users who had called the contract directly, rather than through their DSProxy, had left it recorded as the owner of their SAFEs, which allowed the attacker to call quitSystem directly and move their collateral to an attacker-controlled address.
Impact: $14,000
XRPH Wallet - 03/09/2026
Type: Private Key Compromise
Around 4,011 XRPH Wallet user accounts saw unauthorised transactions involving XRPH, XRPHAI and other assets. The stolen funds were collected, bridged through NEAR Intents to Ethereum and converted into roughly 445,198 DAI, which remains in a single address. The project confirmed the XRP Ledger itself was not affected and took the app offline while it investigates.
Impact: $452,000
Notional Finance - 04/09/2026
Type: Smart Contract Vulnerability
Notional Finance's legacy V1 Escrow contract was exploited through an unsafe uint128 cast in its free-collateral valuation. A fabricated liability of roughly 2^128 truncated to zero, bypassing the protocol's solvency checks and allowing the attacker to withdraw 69,257 DAI and 1.66 million USDC. The proceeds were swapped into about 689 ETH and deposited into Tornado Cash.
Impact: $1,730,000
Dream Health Chain - 05/09/2026
Type: Smart Contract Vulnerability
A broken reward state machine in Dream Health Chain's staking contracts on BNB Chain allowed a claimed reward to be reset with a negligible DHC deposit. The attacker looped the pledge and claim cycle to collect the same fixed payout repeatedly from the shared pool, then sold around 542,070 DHC into the DHC/USDT pool.
Impact: $71,851
Reddio - 05/09/2026
Type: Smart Contract Vulnerability
After an stETH vault was registered permissionlessly on Reddio's RedSonic Vault, the same stETH was counted in both the ETH and stETH vaults. The attacker used a flash loan to inflate the rsvETH share price, redeemed the excess ETH, and then recovered the same stETH a second time through the other vault.
Impact: $22,800
Secured Finance - 05/09/2026
Type: Price/Collateral Manipulation
Secured Finance's fixed-rate lending protocol was exploited through an order-book accounting flaw that treated unfilled orders as filled. Using flash loans and self-trades, the attacker manipulated the current-block price and withdrew funds against the resulting invalid balances. Markets on Ethereum, Arbitrum and Filecoin were paused.
Impact: $180,000
Rocket - 05/09/2026
Type: Price/Collateral Manipulation
An attacker targeted a dormant, illiquid perpetual market on Rocket, placing orders at inflated prices and trading against a burner account to generate artificial profit on a second account. The profitable account then withdrew roughly $287,000 in positive PnL through the bridge, leaving the loss socialised across the platform.
Impact: $287,000
Liquid Network - 06/09/2026
Type: Consensus/Software Vulnerability
A range-proof verification cache bug in the Elements software that underpins Liquid, the Bitcoin sidechain, allowed an attacker to create around 4,000 unbacked L-BTC. Those tokens were then redeemed through SideSwap's standard peg-out path, prompting the Liquid Federation to release real bitcoin from its reserve and draining roughly 95% of the sidechain's backing. No private keys were compromised. The actor, claiming to be a white hat, left an on-chain message offering to return most of the funds once a patch was deployed, and returned 3,400 BTC on 7 September. Around 598.5 BTC, worth approximately $47 million, remains in the actor's hands, and the network remains paused.
Impact: $320,000,000 (gross; 3,400 BTC since returned)
Cozy Finance - 07/09/2026
Type: Oracle Manipulation
On 2 September, an attacker whose gas had been funded through Tornado Cash bought protection in three Cozy v2 markets on Optimism and submitted false "YES" assertions to the UMA Optimistic Oracle feeds behind them. Nobody disputed the assertions during the five-day challenge window, so the markets triggered on 7 September and the attacker burned their PTokens to claim 170,186 USDC.e. Within 90 minutes the funds had been bridged to Ethereum, converted to ETH and deposited back into Tornado Cash.
Impact: $170,186
Unnamed BSC DEX Router - 07/09/2026
Type: Smart Contract Vulnerability
An unnamed DEX router on BNB Chain failed to verify that its Uniswap V3 swap callback was being called by a genuine pool. Using a fake pool with victims set as the payer, the attacker drained existing token approvals from 29 wallets in a single transaction.
Impact: $46,070
WealthManagementV2 - 08/09/2026
Type: Private Key Compromise
Owner privileges of the WealthManagementV2 contract were taken over, most likely through a leaked private key. With no timelock or bounds on configuration changes, the attacker set extreme plan parameters, minted inflated interest by investing and redeeming within the same transaction, and then withdrew the proceeds.
Impact: $26,414
BeatXswap - 09/09/2026
Type: Price/Collateral Manipulation
BeatXswap's LiquidityVestingConvert contract relied on the Uniswap V3 slot0 spot price as its only oracle, with no time-weighted average or deviation check. The attacker flash-loaned 6 million BTX, dumped it to crash the pool price, and deposited twice at the manipulated quote to mint LP positions and drain nearly 3 million BTX.
Impact: $77,512
Zentra Finance - 09/09/2026
Type: Smart Contract Vulnerability
An accounting edge case in Zentra Finance's repayWithATokens function allowed a debt repayment to complete while the matching aToken burn was reduced to zero. Using around 200,000 USDC.e of flash liquidity as temporary collateral, the attacker drained 140,000 ctUSD from the lending pool on Citrea in a single transaction. The operations multisig paused all markets roughly 17 minutes later.
Impact: $140,030
Nomic nBTC Bridge - 09/09/2026
Type: Cross-Chain Bridge Logic Exploit
A flaw in Nomic's custom forwarding mechanism allowed an attacker to double-spend nBTC and send around 39.84 unbacked nBTC vouchers to Osmosis over IBC. Because nBTC forms part of the reserve behind Osmosis's Alloyed BTC, the forged vouchers left that token roughly 36% undercollateralised. Osmosis paused all Nomic and Alloyed BTC flows, froze 22.65 BTC in the attacker's account through an emergency chain upgrade, and plans a governance vote to seize those funds and cover the remaining shortfall from its community pool.
Impact: $3,150,000
Amnext - 09/09/2026
Type: Smart Contract Vulnerability
Amnext, a PoolTogether V3 fork on BNB Chain, failed to reduce a user's credit balance when prizes were claimed. After winning a draw, the attacker looped the award path around 20 times within one transaction to mint roughly 376.5 million unearned tickets, redeemed them for the underlying AMC and sold it on PancakeSwap for around 154 WBNB.
Impact: $116,100
Dominion - 11/09/2026
Type: Private Key Compromise
An attacker obtained three of the five keys to the treasury multisig behind Dominion Market's Solana-based silver token, SILV. The treasury was emptied and SILV pulled from loans, with around 46,909 tokens dumped into thin DEX pools as the peg broke. The team pulled liquidity, rotated its hardware, froze tokens bought during the incident window and announced USDC refunds.
Impact: $238,000
Symbiosis - 11/09/2026
Type: Cross-Chain Bridge Logic Exploit
An attacker abused incorrect parsing of Bitcoin transaction data and negative fee settings in Symbiosis's BridgeV2 to mint an enormous supply of unbacked syBTC across BNB Chain, Ethereum and Rootstock within about four minutes, then sold part of it through Uniswap V4. The team paused native BTC routes, moved remaining portal funds to reserve addresses and offered the attacker a 20% white-hat bounty. Its post-mortem put losses for liquidity providers and users at 9.97 BTC.
Impact: $775,000
ORBToken - 11/09/2026
Type: Smart Contract Vulnerability
ORBToken's receive function automatically granted a maximum allowance, and its addPoolAndSell function lacked a reentrancy guard, which together allowed repeated tax-free sells. Combined with large LP burns and a reserve sync to distort the pool, the attacker extracted around $32,600.
Impact: $32,611
OMNI404 - 11/09/2026
Type: Smart Contract Vulnerability
OMNI404's ERC-404 transfer logic treated small transfer values as NFT IDs while still moving a full token unit. Using flash loans and exact-output swaps, the attacker received full tokens while the Uniswap pool recorded only wei-level amounts, draining around 2.4 WETH.
Impact: $5,923
ether.fi Liquid - 11/09/2026
Type: Access Control
Missing access control on the solver parameter of ether.fi Liquid's AtomicQueue.solve function allowed an attacker to force users who had already approved the contract to act as the solver, then drain their allowances. Around 11 users lost a combined 15.45 ETH.
Impact: $38,130
Chainflip - 12/09/2026
Type: Protocol Logic Flaw
Chainflip's Tron integration reads swap instructions from transaction memo fields. The attacker attached a custom memo to a transaction that Chainflip's validators had already signed, which the backend then read as a separate, failed swap and refunded, paying out twice against the same deposit. Six successful attempts over roughly 90 minutes produced 736,442 USDT in duplicate payouts. The network was paused, and Chainflip has committed to making affected users whole.
Impact: $736,442
Long Bridge - 14/09/2026
Type: Supply Chain Attack
Long's custodial bridge released 46.79 WETH from its Robinhood Chain vault after a third-party RPC provider fed its keeper fabricated withdrawal events. No contract or key was breached. The team halted the keeper, rebuilt its verification and refilled the vault from platform revenue on the same day, so users did not lose funds.
Impact: $118,000
Spiral - 14/09/2026
Type: Price/Collateral Manipulation
SpiralHookV2 valued borrowing collateral using the Uniswap V4 spot price, with no time-weighted average or limit on price changes. A guard meant to block same-block swaps was keyed to tx.origin, so the attacker bypassed it by using six separate accounts, borrowing against inflated collateral immediately after pumping the pool.
Impact: $26,800
Unknown Gnosis Safe Wallet - 15/09/2026
Type: Access Control
A Gnosis Safe on Ethereum holding a leveraged rsETH position was drained through a flawed authorisation check in a custom Uniswap V4 LP module the owner had enabled. The attacker used a public keeper multicall to push the module into an attacker-created hooked pool, unwrapping the Safe's aEthrsETH into rsETH in the process. An MEV bot front-ran the extraction and captured the funds, and Kelp DAO placed a 24-hour pause on the receiving address. Kelp confirmed its core rsETH contracts were unaffected.
Impact: $7,800,000
DCENT App Wallet - 15/09/2026
Type: Supply Chain Attack
A signing flaw in versions of the DCENT App Wallet released before November 2025 left users' recovery phrases exposed, and attackers drained affected wallets in at least six waves over roughly a week, starting with the largest balances. More than 12.4 million XRP was taken from over 7,000 wallets, with activity later spreading to Bitcoin, Ethereum, Tron and Stellar, and around 6.3 million of the stolen XRP was moved to Ethereum through THORChain. DCENT's hardware wallets were affected only where the same recovery phrase had also been restored into the app.
Impact: $20,000,000 (estimated)
Startale - 16/09/2026
Type: Smart Contract Vulnerability
A transient-storage initialisation flag in Startale's ERC-7579 smart accounts persisted for the whole transaction, allowing an account to be re-initialised with a malicious bootstrap immediately after factory deployment. Around 330 pre-funded counterfactual accounts were drained without any signatures. The Soneium network itself was unaffected.
Impact: $2,876
Nimiq - 16/09/2026
Type: Access Control
An OpenGSN meta-transaction flaw in Nimiq's HTLC contracts on Polygon accepted a spoofed sender without a genuine signature. Posing as one of Nimiq's liquidity wallets, the attacker used its leftover allowances to lock USDC and USDT0 into HTLCs with a trivially known secret, then redeemed them in a single transaction.
Impact: $50,463
Flamincome - 16/09/2026
Type: Price/Collateral Manipulation
Flamincome's legacy 2020-era VaultYUSDT strategy priced its shares using Curve's manipulable virtual price. Using an $18.09 million USDT flash loan from Morpho, the attacker staked Curve USDP LP tokens into the strategy to inflate the vault's share price, then redeemed for aUSDT at the elevated rate and repaid the loan within the same transaction.
Impact: $345,903
Bonfire - 16/09/2026
Type: Access Control
The BonfireSwap router's transfer function did not check that the caller owned the tokens or held an allowance over them. The attacker swept BONFIRE from 65 holders with standing approvals to the router and cashed out through the BONFIRE/WBNB pair on BNB Chain.
Impact: $50,000
Meme Coin Phishing Campaign - 16/09/2026
Type: Phishing
Attackers planted malicious links in public token metadata on DEX aggregators including DexScreener and Axiom. Traders who followed them were redirected to a fake Cloudflare verification page that silently copied a PowerShell command to the clipboard and prompted them to run it, installing an infostealer that extracted private keys and browser session credentials. Because the attack ran at operating-system level, it bypassed wallet signature prompts entirely.
Impact: $600,000
Nostra - 17/09/2026
Type: Oracle Manipulation
The attacker manipulated the Ekubo pool feeding Nostra's NSTR price oracle on Starknet, withdrawing liquidity around the token's real price and seeding a decoy band at $99 before routing a tiny swap through the gap. The oracle price rose more than 16,000-fold, allowing NSTR collateral normally worth around $1,756 to borrow $3.53 million across six assets. Around $1.93 million was bridged to Ethereum, and the market remains paused.
Impact: $3,531,923
Likwid - 18/09/2026
Type: Smart Contract Vulnerability
In the zero-leverage path of Likwid's margin contract on BNB Chain, pair reserves were not updated between borrows, so each borrow reused the same price quote. The attacker pumped a thin meme pool, repeated the collateral and borrow cycle to drain 74.31 BNB from the vault, and sent the proceeds to Tornado Cash.
Impact: $55,721
ASI Alliance (Fetch.ai / SingularityNET / NuNet) - 19/09/2026
Type: Private Key Compromise
Using a leaked SingularityNET conversion-authoriser key, the attacker drained 8.72 million FET from Fetch.ai's token-conversion contract on Ethereum. Minutes later, a compromised NuNet deployer key was used to mint 408.5 million NTX, and on 20 September the SingularityNET bridge authority was used to mint unauthorised supplies of AGIX, WMTx and CGV. Thin liquidity limited how much the attacker could realise, while the affected tokens' market prices fell sharply. The projects paused their bridges and revoked the compromised authorities.
Impact: $1,992,730
MultiversX - 19/09/2026
Type: Consensus/Software Vulnerability
An attacker attempted to exploit a virtual-machine-level atomicity issue on the MultiversX mainnet, causing invalid on-chain state changes. The network was paused, and engineers are evaluating a targeted recovery that would preserve legitimate history while reversing only the incident-related changes.
Impact: Undisclosed
Blink Wallet - 19/09/2026
Type: Access Control
Bitcoin Lightning wallet Blink paused its services after an attacker accessed a limited number of custodial accounts and withdrew funds. Non-custodial wallets were unaffected, and the team said the large majority of funds remain secure.
Impact: Undisclosed
DoinGud - 21/09/2026
Type: Smart Contract Vulnerability
The dormant NFT platform DoinGud was exploited on Polygon through a bug in its Diamond bidding contract, which paid out accepted bids without clearing the bid record. The attacker flash-loaned USDC equal to the contract balance, bid on their own listing and accepted the same bid twice.
Impact: $35,486
GaslessReservoirEnabler - 21/09/2026
Type: Access Control
The GaslessReservoirEnabler contract on Polygon checked module addresses but did not tie ERC-20 transferFrom calls to an authorised asset owner, letting the attacker spend victims' existing WETH and ZED allowances. Around 997 addresses were drained, and the proceeds were consolidated and deposited into a bridge.
Impact: $23,000
RWC Token - 21/09/2026
Type: Smart Contract Vulnerability
An unprotected burn function allowed the attacker to destroy RWC held in the PancakeSwap RWC/USDT pair and sync its reserves, inflating the price before selling back in a flash-loan-funded transaction. The pool lost around 109,461 USDT, of which the attacker kept about 39,964 USDT; the remainder was routed to the project's own wallets by the token's fee logic.
Impact: $109,461
Internet Token - 21/09/2026
Type: Smart Contract Vulnerability
Internet Token DAO's LiquidityUnifier contract on Base trusted a caller-supplied Uniswap V3 pool address. A fake pool callback minted around 925 million INT, part of which the attacker sold for 5.85 WETH. The contract's minting role was not revoked in time, copycat exploits later inflated supply to around 156 billion INT, and the attacker submitted a governance proposal aimed at moving treasury funds.
Impact: $265,000
Astroport - 22/09/2026
Type: Access Control
Admin privileges for Astroport's contracts on the Neutron chain were compromised, putting liquidity across connected pools at risk. The attacker converted funds into ATOM and began a streaming swap to ETH through THORChain before Cosmos Hub halted. Validators then deployed an upgrade that moved 1.23 million ATOM from the attacker's account to a recovery multisig and blocked the attacker's key from signing further transactions. Astroport's Terra-side contracts were unaffected.
Impact: $4,900,000
Drop - 22/09/2026
Type: Governance Attack
The Drop project's treasury was drained through a malicious governance proposal, which the attacker used to transfer treasury funds to addresses under their control.
Impact: $4,400,000
Nano Labs founder X account - 23/09/2026
Type: Social Engineering/Account Compromise
The personal X account of Nano Labs founder Jack Kong was hijacked and used to promote a fake AI trading token, Binance World Assets ($BWA), on BNB Chain. Nano Labs confirmed the posts were unauthorised and warned users not to send funds to any linked contracts.
Impact: Undisclosed
Limit Break - 24/09/2026
Type: Smart Contract Vulnerability
A bug in Limit Break's Payment Processor V2, the settlement contract behind Magic Eden's former EVM marketplace, let an attacker abuse stale approvals to take blue-chip NFTs through zero-price "sales" and to drain WETH in reverse. Payment Processor V2 could not be paused, so Yuga Labs' VP of Blockchain, 0xQuit, led a white-hat operation that moved 23,155 NFTs worth more than $5.7 million to safety. Around 660 WETH could not be recovered in time, and users have been urged to revoke approvals to the V2 and V3 contracts.
Impact: $2,800,000
Payy Network - 24/09/2026
Type: Cross-Chain Bridge Logic Exploit
Payy Network's Ethereum rollup bridge contract was drained through a forged verifyRollup batch that reportedly relied on compromised or misused prover and validator keys. Around 1.83 million USDC in users' non-custodial deposits was taken, converted into roughly 683 ETH and split across fresh addresses where it remains. The attacker had funded the attack wallet's gas through Railgun two days earlier.
Impact: $1,832,149
Meter Passport - 24/09/2026
Type: Cross-Chain Bridge Logic Exploit
Meter.io's Meter Passport bridge on BNB Chain was exploited to mint unbacked wrapped MTRG, part of which the attacker sold on PancakeSwap. Around $2.3 million of unbacked wMTRG had been minted when the exploit was first flagged, with the attack still ongoing.
Impact: $2,300,000
Bitget - 24/09/2026
Type: Infrastructure Compromise
At 18:31 UTC on 24 September, Bitget detected unauthorised transfers from parts of its hot and warm wallet infrastructure. Attackers had breached a critical backend system in the exchange's wallet stack, reportedly through a vulnerability in a third-party security product, and used spoofed transaction data to trigger Bitget's own authorisation process. The exchange ruled out private key theft and forged customer withdrawal requests, and its cold wallets were unaffected. The loss was first put at $351.6 million and later revised to around $387.5 million after stolen Zcash and Tron assets were identified. Bitget paused withdrawals, said its User Protection Fund will cover the loss, and announced a bounty of 5% of any funds frozen or recovered.
Impact: $387,500,000
Duelbits - 24/09/2026
Type: Private Key Compromise
Crypto casino and sportsbook Duelbits had its hot wallets drained across Ethereum, BNB Chain, Tron, Solana and Bitcoin in under an hour, in what security firms assessed as a private key compromise. The attacker bridged and swapped most of the stolen assets into ETH, consolidating around 2,235 ETH in a single address. User balances were unaffected, and the platform relaunched on 27 September.
Impact: $7,000,000
DYORSWAP - 27/09/2026
Type: Phishing
Multi-chain DEX DYORSWAP listed a network presented as GIWA Mainnet, the upcoming Upbit-linked layer 2, that was in fact a scammer-built fake chain with a fraudulent bridge. Around 1,335 addresses deposited real ETH into the bridge before the operators drained 766.25 ETH roughly 12 hours after it went live and moved the proceeds into Tornado Cash. DYORSWAP said its own contracts were not exploited and has paid more than 200 ETH in compensation from its own funds.
Impact: $2,000,000
Key Findings and Trends
Two infrastructure-level incidents accounted for 91% of the month's losses
Bitget (387.5million)andLiquidNetwork(320 million) together made up roughly $707.5 million of September's $776 million total. Neither was a DeFi smart contract exploit, and neither involved a stolen private key. At Bitget, attackers compromised the backend system that feeds the exchange's own transaction approval process, so fraudulent withdrawals were approved as though they were legitimate. At Liquid, the flaw sat in the Elements consensus software itself, allowing unbacked L-BTC to be created and then redeemed through the normal peg-out route. Nominis assesses that both incidents point to the same conclusion: the most expensive failures this month sat in the systems that validate and authorise transactions, below the layer that contract audits and key management are designed to protect.

Smart contract vulnerabilities were the most frequent attack type, but among the least costly
Measured by frequency, smart contract vulnerabilities remained the most common category in September, accounting for 14 of the month's 48 incidents (29%). Measured by value, they accounted for just $5.4 million, less than 1% of the total, with Limit Break's $2.8 million and Notional Finance's $1.73 million making up most of it. Access control failures were the second most common category, with eight incidents totalling $12.9 million, led by the $7.8 million Gnosis Safe drain and Astroport's $4.9 million admin compromise. Private key compromise produced five incidents and $9.7 million, while price and oracle manipulation together produced seven incidents and $4.6 million. More broadly, 30 of the month's 48 incidents involved losses below $1 million, and 16 involved losses below $100,000, a long tail of smaller exploits concentrated on BNB Chain and Ethereum.

Wallet software and the tools users trust became a major loss vector
Wallets were the third-largest target category by value, with five incidents totalling $28.3 million. The DCENT App Wallet incident was the clearest example: a signing flaw in older app versions exposed users' recovery phrases, and more than 7,000 wallets were drained across multiple chains over roughly a week. Several other incidents shared the same underlying pattern, in which users or protocols relied on a piece of software or infrastructure that turned out to be the weak point. Long Bridge released funds after a third-party RPC fed it fabricated withdrawal events. The meme coin phishing campaign used DEX aggregator metadata and a fake Cloudflare check to install an infostealer. The Gnosis Safe loss came through a custom module its owner had enabled. Nominis assesses that these cases, alongside RRWallet's weak random number generator in August, show supply chain and wallet-software risk moving from an occasional incident type to a consistent monthly feature.
Standing approvals and legacy contracts continued to be drained
At least seven incidents this month involved an attacker draining permissions that users had granted long before, including Limit Break, Bonfire, GaslessReservoirEnabler, ether.fi Liquid, Nimiq, GebProxyActions and the unnamed BSC DEX router. Limit Break was the most striking example: approvals granted to Payment Processor V2 when users traded on Magic Eden's EVM marketplace in 2024 were still live in September 2026, well after Magic Eden had stopped using the contract. Legacy and dormant code featured alongside these, with Notional Finance's V1 Escrow, Flamincome's 2020-era vault strategy, the dormant DoinGud platform and an illiquid perpetual market on Rocket all exploited. Nominis assesses that an approval or a deployed contract carries risk for as long as it exists on-chain, regardless of whether anyone is still actively using or maintaining it.
Cross-chain bridges were hit repeatedly, and unbacked minting was the recurring outcome
Eight incidents targeted cross-chain bridges and interoperability infrastructure, totalling $11.0 million: Nomic, Symbiosis, Chainflip, Long Bridge, Nimiq, the ASI Alliance, Payy Network and Meter Passport. Across bridges and adjacent systems, the most common result was the creation of tokens with no real backing. Liquid, Nomic, Symbiosis, Meter Passport, the ASI Alliance and Internet Token all saw attackers mint unbacked assets and sell or redeem them for real value. September 24 was the month's busiest day, with five incidents in 24 hours: Bitget, Duelbits, Limit Break, Payy Network and Meter Passport.
Chain-level intervention has become a routine part of incident response
In August, Cronos halted its entire chain to contain the Tectonic exploit. In September, similar interventions happened repeatedly. Liquid and MultiversX paused their networks, Neutron and Cosmos Hub halted to contain the Astroport compromise, and Cosmos Hub validators then deployed an upgrade that moved 1.23 million ATOM from the attacker's account to a recovery multisig. Osmosis froze 22.65 BTC in the Nomic attacker's account through an emergency upgrade, and Kelp DAO paused the address that received the stolen rsETH from the Gnosis Safe drain. Nominis assesses that these measures are effective at stopping funds from leaving, but they are only available where a small, coordinated validator set or a token issuer can act quickly, and they halt legitimate activity for as long as they last.
Mixers, privacy protocols and cross-chain swaps all featured in fund movement
Tornado Cash appeared in four incidents: Notional Finance, Cozy Finance, Likwid and DYORSWAP. In Cozy's case, it was used both to fund the attacker's gas and to launder the proceeds. Railgun was used to fund the Payy Network attacker's gas two days before the exploit. Cross-chain swap routes also played a role, with THORChain used to move 6.3 million stolen XRP from the DCENT incident to Ethereum and to begin swapping Astroport proceeds into ETH, and NEAR Intents used to bridge the XRPH Wallet proceeds. Bitget was the notable exception: as of 25 September, around 68,300 ETH and 102.6 million XRP remained untouched in attacker-controlled wallets, a pattern consistent with previous large exchange hacks attributed to North Korea, where laundering unfolds over weeks rather than hours.
Bounties, returns and compensation produced very different recovery outcomes
Recovery varied widely across the month. The Liquid actor returned 3,400 BTC within a day, while Symbiosis offered a 20% white-hat bounty and Bitget announced a bounty of 5% of any funds frozen or recovered. Several platforms chose to absorb losses directly: Bitget's User Protection Fund will cover its losses, Long Bridge refilled its vault from platform revenue the same day, Chainflip committed to making users whole, and DYORSWAP paid more than 200 ETH in compensation from its own funds. Nominis assesses that the speed and completeness of recovery depended far more on the victim's balance sheet and the response of validators and issuers than on any action taken by the attacker.
Regulatory and Compliance Developments
September 2026 saw significant enforcement against the financial infrastructure that state and criminal actors rely on, from Iran's central bank and Revolutionary Guard to Russia's A7 network, Southeast Asia's scam marketplaces, Mexican cartels, Venezuela's Tren de Aragua, a Swedish laundering gang and North Korea's hacking units. Across almost every case, the same pattern recurred: a single piece of infrastructure, whether a stablecoin wallet, an exchange, a marketplace or a laundering network, was serving several illicit clients at once.
Tether's Iran-linked freezes approach $550 million
On 28 September, Tether said that actions involving USDT had resulted in approximately $550 million being frozen in 2026 across wallets US authorities identified as connected to Iran's Central Bank and wider Iranian sanctions networks. In April, Tether froze more than $344 million across two addresses on information from OFAC and US law enforcement, and OFAC formally added those same addresses as digital currency identifiers for the Central Bank of Iran the following day. In July, a further $130 million across four wallets was frozen as Treasury expanded the Central Bank of Iran designation to four additional TRON addresses.
The announcement follows the launch of Operation Economic Outcast by Treasury Secretary Scott Bessent in August, a campaign to cut the financial networks supporting the Iranian regime and the IRGC, which identified digital assets as one of five sectors at risk of expanded sanctions. Tether says it now works with more than 340 law enforcement agencies across 67 countries and has frozen more than $4.9 billion in assets overall.
Nominis assesses that the April sequence, in which the freeze came a day before the formal designation, is the detail compliance teams should pay closest attention to. Issuer-level freezes are increasingly the first enforcement action taken, and a screening programme that waits for the SDN list to update will see the designated addresses only after the funds have already been immobilised.
More broadly, Nominis sees stablecoins as one of the most significant rails for terror financing. USDT on TRON sits at the centre of the Iran-linked freezes, the Xinbi marketplace and the New Mexico cartel pipeline, the Tren de Aragua designations described below, and A7 built its own ruble-pegged stablecoin to serve Russian sanctions evasion. The same property that makes stablecoins attractive to these networks, a dollar-denominated asset that moves across borders in minutes, is also what makes them an effective point of intervention, because a centralised issuer can freeze funds in a way that no native blockchain asset allows. For compliance teams, this means stablecoin flows deserve the closest monitoring of any asset class, both as the most likely route for illicit value to reach a regulated platform and as the asset most likely to be frozen while it sits in a customer's wallet.
The Big Shor: A7 and the limits of treating sanctions evasion as a crypto problem
An investigation by the Open Source Centre, The Big Shor, reconstructs the operations of A7, the Kremlin-backed network run by Moldovan fugitive Ilan Shor, from a leak of more than 30,000 internal messages alongside ledgers, contracts, invoices and SWIFT messages. Russia's sanctioned military bank Promsvyazbank is a joint shareholder in A7, with financial participation from the state development corporation VEB.RF.
While public attention has focused on A7A5, the network's ruble-pegged stablecoin, the leaked files show A7 operating primarily as a fiat payment system. A7 sold bills of exchange to Russian companies and, in return, settled their payments to foreign suppliers through front companies in Kyrgyzstan, the UAE, Hong Kong, Hungary and Mongolia, reaching suppliers in more than 80 jurisdictions. By July 2025, around RUB 2.1 trillion (roughly $25 billion) in bills of exchange had passed through the system, and A7 personnel claimed the figure had passed RUB 6.1 trillion by April 2026. Custom software swapped the goods listed on real supplier invoices for mundane items such as LED lights and shelving and stripped out any reference to Russia, so that payments would pass bank due diligence unnoticed. The single largest payment vehicle identified was a state-owned Kyrgyz trading company, TKKR, which processed 21 bills of exchange worth $13.1 million for EU-designated drone supplier Rustakt after its designation. In all, 75 sanctioned Russian companies appear in A7's ledgers and customer lists.
Nominis assesses that A7 is a clear example of why crypto-only monitoring misses most of a hybrid sanctions-evasion network. For crypto compliance teams, A7A5 exposure is the visible part of a much larger system, and connecting an on-chain counterparty to the front companies, trade flows and banking relationships behind it requires entity intelligence that sits well outside the blockchain.
Xinbi Guarantee designated as a transnational criminal organisation
On 9 September, the US designated Xinbi Guarantee, one of the largest Chinese-language marketplaces serving Southeast Asia's scam economy, as a significant transnational criminal organisation. OFAC also designated the two companies that built its core infrastructure: Cambodia-based Anwen Technology, developer of the XinbiPay wallet (also marketed as NewPay), and Singapore-based SafeW Technology, maker of the SafeW encrypted messaging app. Fifty-two TRON addresses were added to the SDN list. On the same day, the Justice Department's Scam Center Strike Force seized the Telegram channels hosting the marketplace and two wallets holding around $12 million, and sought restraints on 47 more, bringing the total restrained to over $52 million. Treasury says Xinbi has processed the equivalent of more than $24 billion since around 2022. The action follows the UK's designation of Xinbi in March, and Telegram has since deleted its central channels.
As Nominis set out in After the Xinbi Sanctions: Next Steps for Compliance Teams, this is the most complete action taken against this part of the scam economy so far, because it targets the messaging and payment services built to keep the marketplace running, as well as the storefront itself. Nominis nonetheless expects the ecosystem to fragment rather than disappear. When Huione Guarantee was removed in 2025, its merchants moved to Tudou Guarantee and then to Xinbi, and the OTC desks, "Black U" vendors and mule networks that actually move the money were never tied to a single platform. Most exposure is likely to sit one or two hops away from the listed addresses, in the OTC and P2P counterparties that traded on Xinbi, and third-party OTC providers had funds restricted during the freezing operation without being part of Xinbi's own group. Nominis has also observed illicit actors beginning to shift financial infrastructure from TRON to Solana in response to heightened scrutiny of TRON wallets.
BitBank sanctioned- used for routing Hormuz passage payments to the IRGC
On 17 September, the US sanctioned BitBank, a Tehran cryptocurrency exchange controlled by sanctioned Iranian financier Babak Zanjani. Treasury said BitBank had routed hundreds of millions of dollars to the IRGC and described it as a key component of Iran's digital-asset sanctions-evasion infrastructure. According to OFAC, the Hormuz Safe Marine Services Authority, the body Iran established to collect payments from vessels seeking safe passage through the Strait of Hormuz, used BitBank to pass those payments on to the regime. OFAC also designated Pishtaz Simorgh Electronic Trade Company, which developed BitBank's trading software, and three of Zanjani's associates: Mohammad Mahdi Zaker Hossein, Hossein Ali Zaker Hossein and Seyed Adel Heidari. The action forms part of Operation Economic Outcast.
Taken together with the Tether freezes above, the case shows Iran running sanctions-evasion flows through both USDT on TRON and bitcoin through a domestic exchange, and it places the burden of identifying BitBank-linked activity squarely on attribution and clustering, since there is no list of addresses to screen against.
Cartels are using crypto in more than one way
Nominis' recent research, Tracing Cartel Crypto: The Methodologies of Cartel Money Laundering, examined a civil forfeiture complaint filed in New Mexico at the end of August. In an undercover investigation running since February 2025, agents paid an alleged member of the Sinaloa Cartel's Los Mayos faction $30,000 in USDT for two kilograms of cocaine, then collected bulk cash on his instructions, including $73,000 in Kansas and $173,000 in South Carolina, converted it into USDT and sent it over TRON to accounts run by independent money laundering organisations. Those same accounts were also handling funds tied to the IRGC and around $12,000 laundered from the 2025 Bybit hack. Tether froze the accounts at investigators' request, and the full balance of $2,248,478 had been transferred into FBI custody by 11 August.
The research sets this alongside a separate case in Puebla, where Mexican authorities dismantled a clandestine mining operation of around 300 GPUs drawing stolen power from a hydroelectric complex, the fourth such farm found in the same corridor since early last year. Together, the cases illustrate three distinct methods: the courier-to-stablecoin model, in which bulk cash is converted into USDT in structured transactions; cross-border broker networks, including a Mexican broker sentenced in 2025 to eight years for laundering $5.4 million in crypto for the Jalisco New Generation Cartel across thirteen US cities; and mining as a laundering channel, which generates crypto directly and avoids any visible cash-to-crypto conversion. Nominis assesses that the most significant finding is that the New Mexico pipeline was never built exclusively for the cartel. The same accounts carried cocaine proceeds, IRGC-linked funds and North Korean hacking proceeds, which points to laundering-as-a-service, shared infrastructure sold to whichever client needs it.
Tren de Aragua's ATM jackpotting network sanctioned, with seven TRON addresses listed
On 30 September, OFAC designated eight individuals and two Mexico-based companies behind an ATM "jackpotting" scheme that Treasury describes as a key source of revenue for Tren de Aragua (TdA), the Venezuelan-origin group designated as a Foreign Terrorist Organisation in February 2025. The network is led by Anibal Alexander Canelon Aguirre, known as "Prometheus" or "The Engineer," who is on the FBI's Ten Most Wanted list and is alleged to have built the malware used in the attacks. Crews deployed to the United States break into ATMs, install the malware and trigger it remotely, forcing the machines to dispense cash without debiting any account. As of August 2025, reported losses from alleged jackpotting attacks in the US stood at $40.73 million across more than 1,500 attacks, and the Justice Department has indicted 98 people in connection with the schemes since October 2025. OFAC also designated Juan Gabriel Rivas Nunez ("Juancho"), a senior TdA leader directing gold mining and narcotics operations in South America.
Treasury said Prometheus and his associates use cryptocurrency transactions to launder the cash and move it to TdA members in other countries, and seven of the designated individuals were listed with TRON addresses as digital currency identifiers. The two companies, Enigma Community and Soluciones Integrales Toluca, are owned by members of the network. All designations were made under both counterterrorism (E.O. 13224) and transnational criminal organisation (E.O. 13581) authorities, which carries secondary sanctions risk for any foreign financial institution that knowingly facilitates significant transactions for the designated persons.
Nominis assesses that the case follows the same courier-to-stablecoin model seen in the New Mexico cartel pipeline: physical cash taken in the United States, converted into crypto and settled on TRON to members abroad. Because the designations are terrorism-related, any platform that processes these flows faces terrorist-financing exposure as well as sanctions risk. The listed addresses are the starting point. The more useful signal for compliance teams sits around them, in the cash-funded on-ramps, P2P sellers and OTC desks that converted the ATM proceeds, and in the receiving wallets in Venezuela, Mexico and Colombia that the network relied on to move value onward.
UAE and Sweden dismantle a crypto laundering network linked to contract killings
On 17 September, UAE and Swedish authorities announced seven arrests in a coordinated operation against an international money laundering network. The alleged ringleader, a Swedish national who had fled the country and was the subject of an Interpol Red Notice for money laundering offences, was arrested in the UAE, while six other suspected members were detained in Sweden at the same time. According to the UAE Ministry of Interior, the network processed around SEK 70 million (roughly $7.1 million) over ten months, collecting cash generated by criminal activity, redirecting it to other criminal groups and using cryptocurrency to transfer and obscure its value. Tracing the network's crypto transactions, alongside other digital evidence, helped investigators uncover links to organised crime and contract killings.
Nominis assesses that the case is a further example of crypto tracing opening investigations into wider criminal activity. A laundering network that began as a financial case led investigators to violent crime, and the arrest of a Red Notice subject in a second jurisdiction shows how cross-border intelligence sharing is becoming central to cases involving digital assets.
North Korea's role in the Bitget hack
The Bitget exploit has been widely attributed to North Korea. Bitget CEO Gracy Chen said the attack was consistent with techniques used by DPRK-linked hacker groups, and on-chain investigator Specter linked the stolen XRP, after it was bridged, to funds taken in the July attack on AFX Trade, which had been attributed to the TraderTraitor subgroup of the Lazarus Group. Bloomberg reported that the theft pushes North Korea's haul from digital-asset thefts above $1 billion for 2026, and that some of the funds were connected to addresses tied to earlier hacks, including the $1.5 billion Bybit exploit in 2025. Bitget is working with Mandiant and SlowMist on its investigation, though not every analyst has yet accepted a firm Lazarus attribution.
Nominis assesses that the compliance implications apply regardless of which unit is ultimately named. The Lazarus Group is designated by OFAC, and as of 25 September most of the stolen ETH and XRP remained unmoved in attacker-controlled wallets. That creates a window, before laundering begins in earnest, for exchanges and OTC desks to identify Bitget-linked addresses and block deposits. Based on the Bybit precedent, the funds are likely to move through bridges, cross-chain swaps and OTC off-ramps over the coming weeks.
Why this matters for compliance, KYT and the intelligence layer
Several of this month's developments point to the same problem: sanctioned and criminal actors are increasingly sharing the same infrastructure. The New Mexico laundering accounts served a cartel, the IRGC and North Korean hackers at once. Xinbi's OTC desks and merchants served scam syndicates across Southeast Asia and will move to new platforms. A7 combined a stablecoin with front companies and correspondent banking, and Iran is moving funds through both USDT and a bitcoin exchange. A monitoring model built around a single typology or a single list will see only part of each of these networks.
The timing of enforcement is also changing. Tether's April freeze came a day before the matching designation, BitBank was designated without any published wallet addresses, and third-party OTC providers had funds frozen in the Xinbi operation without ever being part of Xinbi's own group. For compliance teams, this means exposure can crystallise before a list updates, or without one ever naming the relevant addresses. Clustering, attribution and off-chain intelligence are what allow a firm to identify that exposure first, before a freeze or a designation makes it visible to everyone else.
The exploits detailed earlier in this report reinforce the point from the other direction. Bitget's attackers, likely North Korean, still held most of their stolen funds on-chain at the end of the month, and those funds will eventually need to reach an off-ramp. The firms best placed to stop them will be the ones that can recognise the addresses, the laundering patterns and the counterparties involved as soon as they appear.
Conclusion
September 2026 delivered approximately $776 million in losses across 48 major incidents, the majority of it in two events. Bitget's $387.5 million breach showed that an exchange can lose hundreds of millions without a single private key being stolen, once attackers control the data its approval systems trust. Liquid Network's $320 million consensus bug showed the same weakness at the level of a blockchain's own software. Beneath those two incidents, the rest of the month looked much like the months before it: a long tail of smaller smart contract exploits, repeated attacks on cross-chain bridges, and a steady run of losses through wallet software, standing approvals and legacy contracts that were still holding value long after anyone was watching them.
The through-line from July and August continues to hold. Code-level vulnerabilities remain the most frequent type of incident but rarely the most expensive, and the largest losses once again came from the systems and credentials that sit around the code. September added a clearer picture of how the industry responds: validators halting chains and moving attacker funds, stablecoin issuers and token projects pausing addresses, and victims absorbing losses from their own balance sheets. For compliance teams, custodians and protocol operators, the lesson is that monitoring needs to cover backend authorisation systems, wallet software, approvals and bridge minting logic, as well as the behavioural signals that come before funds move, particularly once stolen assets start crossing chains or entering mixers.
This month's regulatory developments point in the same direction. Tether's Iran-linked freezes, the Xinbi and BitBank designations, the A7 investigation, the New Mexico cartel case and the UAE-Sweden arrests all describe networks that share infrastructure across very different illicit clients, and enforcement that increasingly arrives before, or without, a published list of addresses. With North Korea's likely proceeds from Bitget still sitting on-chain, the firms that stay ahead of both attackers and regulators will be those that treat attribution and monitoring as continuous intelligence work, ready to act the moment those funds begin to move.
All research content and accompanying reports are provided for informational purposes only and should not be relied upon as professional advice. Accessing these materials does not create any professional relationship or duty of care. Readers are encouraged to consult appropriately qualified professionals for guidance. We uphold the highest standards of accuracy in all the information we provide. For any questions or feedback, please contact us at contact@nominis.io.
