BTC $83,074.99 -0.42%
ETH $2,662.62 +0.23%
BNB $757.67 -1.82%
XRP $1.48 -1.00%
SOL $117.31 -2.21%
TRX $0.3338 -0.02%
DOGE $0.0927 -1.57%
ADA $0.2418 -2.66%
BCH $305.14 -3.49%
LINK $14.66 +5.28%
HYPE $86.99 -3.51%
AAVE $148.09 -1.30%
SUI $1.11 -9.17%
XLM $0.2241 +6.21%
ZEC $1,362.84 -12.60%
AAPL $337.78 -0.73%
AMZN $246.07 -1.17%
GOOGL $341.81 -0.15%
MSFT $507.81 -1.81%
META $712.66 -2.89%
NVDA $228.48 +1.95%
TSLA $356.92 -3.65%
SNDK $1,694.88 -2.31%
INTC $114.53 -4.24%
SPCX $145.88 -2.11%
MU $1,050.99 -1.46%
AMD $605.26 -2.05%
BTC $83,074.99 -0.42%
ETH $2,662.62 +0.23%
BNB $757.67 -1.82%
XRP $1.48 -1.00%
SOL $117.31 -2.21%
TRX $0.3338 -0.02%
DOGE $0.0927 -1.57%
ADA $0.2418 -2.66%
BCH $305.14 -3.49%
LINK $14.66 +5.28%
HYPE $86.99 -3.51%
AAVE $148.09 -1.30%
SUI $1.11 -9.17%
XLM $0.2241 +6.21%
ZEC $1,362.84 -12.60%
AAPL $337.78 -0.73%
AMZN $246.07 -1.17%
GOOGL $341.81 -0.15%
MSFT $507.81 -1.81%
META $712.66 -2.89%
NVDA $228.48 +1.95%
TSLA $356.92 -3.65%
SNDK $1,694.88 -2.31%
INTC $114.53 -4.24%
SPCX $145.88 -2.11%
MU $1,050.99 -1.46%
AMD $605.26 -2.05%

000

All
Article
Flash

first_img NEAR Intents: Frozen $503,000 of stolen funds from Bitget

Cross-chain trading protocol NEAR Intents stated in a post on X that on September 24, Bitget was attacked, resulting in approximately $387.5 million in funds being stolen, most of which were aggregated into Ethereum and converted to ETH. The hacker attempted to transfer over $50 million through NEAR Intents, but ultimately only $166,000 was successfully transferred, while $503,000 was intercepted during the execution process.NEAR Intents indicated that the relevant data comes from on-chain tracking tools, Arkham, internal logs, and risk control layer SHIELD, among other sources. The figures listed are rounded estimates, with an assessment deviation of no more than 10%. SHIELD identified over $50 million in money laundering attempts and has filtered out duplicate flows, of which $166,000 has been successfully transferred, while another $503,000 was frozen midway through execution and remains restricted, pending legal and recovery procedures.NEAR Intents stated: permissionless does not equal neutral, the team refuses to assist in cashing out stolen assets and will forgo the bounty from this incident to allow Bitget to recover funds as much as possible. Bitget previously established a 5% + 5% bounty arrangement. NEAR Intents also mentioned that the protocol will remain permissionless but set boundaries, and will combat money laundering of stolen funds, while suggesting Bitget contact legal and law enforcement channels to handle the frozen funds.

first_img Cross-chain trading platform Relay API exposes pending transactions, which will compensate approximately $312,000

Co-founder and Chief Operating Officer of the cross-chain trading platform Relay, Jason Maier, stated that the team discovered an issue with the Relay API over the weekend, which exposed pending transaction information before trade execution. MEV seekers exploited the pending routing status to infer on-chain paths and front-run trades before order execution, resulting in worse execution prices for users trading through Relay.This activity occurred from September 12 to September 26, primarily concentrated from September 23 to 26. Seekers profited approximately $136,000 from this, affecting around 5,600 users, with a median impact of $11.88. Relay will pay a $50,000 bounty to Outputlayer for reporting the issue and will automatically compensate affected users without the need for applications; funds will be directly sent to wallets, with a total compensation amount of approximately $312,000.Jason Maier stated that MEV can arise through public mempool exposure, order detail inference, malicious participation in auctions, or data gaps between service providers, and protecting a single link in the transaction path is not sufficient. He mentioned that the team will continue to enhance the execution quality and privacy of the entire transaction path and called on security researchers to report vulnerabilities when discovered.

first_img MEXC user: API not revoked after account was hacked, approximately 340,000 USD was transferred away

A MEXC user posted on X that their account was compromised after someone reset the security items. MEXC has confirmed the account was hacked, frozen the account, and assisted in recovery, but did not revoke the API left by the attacker. From 04:12 to 04:25 on September 27, 2026 (Beijing time), the account transferred out 322,110 USDT and 9,133,999 ONE, totaling approximately $340,000, about 27 minutes after the 24-hour transfer limit was lifted.The user stated that at 03:10 on September 25, they received a reset security item email that was not submitted by them, and about 10 minutes later, the request was approved. Subsequently, the account was logged in from an IP in Jakarta, Indonesia, bound to Google verification, and at 05:05, an API was created, approximately 83 seconds after logging in. At 10:55 that day, MEXC froze the account after a risk review and reverted to the original email. Customer service responded in writing that the review materials met the requirements, so the binding change was approved, and after the risk review, the account was urgently frozen and reverted to the initial email. The user changed their password and Google verification on September 26 but stated that the API was not revoked, and there were no related records in the security operation history.The user also claimed that there were no new login records in the login history when the assets were transferred out. They have submitted a formal claim to MEXC and attempted to report to the police, with the ticket number M2026092712031, requesting the platform to preserve logs, provide a written explanation of the review and API situation, and return the aforementioned assets. MEXC customer service stated that it is currently unable to confirm whether these transfers were initiated via APP, WEB, or API, and the issue has been forwarded to the relevant department.
app_icon
ChainCatcher Building the Web3 world with innovations.