Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
    Kevin Warsh, Chair of the Federal Reserve of the United States
    Bitcoin Falls Below $78K as Fed Hike Odds Jump to 56%: What Experts Say
    Gold Bitcoin coin on a city street in front of a green rising candlestick chart showing BTC at $78,816.11
    Inside Crypto’s Fastest Week of 2026: Bitcoin’s August Price Rally Was Not a Retail Story
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • Indices
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Indices
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

Crypto Hacks Cross $322M in September’s First Week as Liquid Network Alone Loses $320M

Beyond Liquid, Notional, XRPH Wallet, Dream Health Chain and RedSonic Vault added over $2.3M to September’s crypto losses.

Written By Dishita Malvania
Edited by Divya Mistry
Published 12 minutes ago·Updated 9 minutes ago
Make The Crypto Times preferred on GoogleGoogle
Broken padlock and physical cryptocurrency coins on a desk in front of a hooded hacker, with a computer monitor displaying a red "SECURITY BREACH" warning sign

Publicly reported cryptocurrency exploits recorded between September 1 and September 7, 2026, totaled roughly $322 million, based on a consolidated review of project statements, on-chain investigators, and security-firm alerts issued at the time of each incident. The week was dominated by a single event on the Bitcoin sidechain Liquid Network, which alone accounts for more than 99% of the reported figure. 

The remainder is spread across four confirmed on-chain drains on Ethereum, BNB Chain, and the XRP Ledger (XRPL). The totals below reflect figures reported at the time of each incident and do not include derivatives liquidations, malware that only uses public blockchains for command-and-control data, or exploits that began earlier and only received follow-up updates during the week.

AI Summary
Show
Liquid Network breach exposed $320M bridge flaw, highlighting vulnerabilities in Bitcoin sidechain interoperability.
Multiple DeFi exploits across Ethereum, BNB Chain, and XRP Ledger underscore systemic risks in smart‑contract code audits.
Week’s $322M loss, 99% from Liquid, signals need for coordinated security standards for cross‑chain assets.

Liquid Network Peg-Out: About 3,996 BTC Leaves the Federation Wallet

The largest event of the week, and the single largest publicly reported cryptocurrency incident of 2026 so far, was recorded on Blockstream’s Bitcoin sidechain Liquid Network on September 6.

According to a statement from Liquid-based decentralized exchange SideSwap, a customer sent 4,000 Liquid Bitcoin (L-BTC) to the SideSwap peg-out service at 14:05 Coordinated Universal Time (UTC). The L-BTC was burned under a valid peg-out authorization, and at 14:28 UTC the Liquid Federation paid approximately 3,996 BTC on the Bitcoin main chain. At about $80,000 per bitcoin as of 6:05 UTC on September 7, the withdrawal was valued at roughly $320 million.

In an on-chain incident notice posted at 8:25 PM UTC on September 6, Liquid Network said the withdrawal was routed through SideSwap’s Peg-out Authorization Key (PAK) and that the key itself had not been compromised, nor had any other federation keys. Public bridge nodes were disabled, and the sidechain was paused. 

The federation added that other Liquid-issued assets, including Tether (USDT), DePix, and tokenized real-world assets (RWAs), were unaffected. The federation wallet’s remaining reserve stood at approximately 197 BTC, down from about 4,200 BTC before the peg-out.

An OP_RETURN (Operation Return) message attached to a follow-up Bitcoin transaction read: “we are whitehats. contact us on chain.” Blockstream, which develops Liquid’s infrastructure, replied on-chain and asked the party to contact security@blockstream.com. 

Later on-chain messages indicated that most of the coins would be returned after every node was patched. Ledger Chief Technology Officer (CTO) Charles Guillemet said the conventional white-hat practice is to disclose a flaw before moving a large reserve rather than after. As of 6:15 UTC on September 7, the coins had not left the receiving address.

Independent on-chain analysis pointed to a range-proof cache flaw in Elements, the open-source software that powers Liquid’s confidential-transaction system. Reporting citing on-chain researchers said a fix had been merged into the Elements repository but was not included in the tagged build running on the network at the time of the incident.

For the full disclosure timeline and network response, see The Crypto Times report on the Liquid Network pause after ~4,000 BTC left the federation wallet.

Notional Finance: About $1.73 Million Escrow Drain on Ethereum

On Ethereum, decentralized finance (DeFi) fixed-rate lending protocol Notional Finance suffered a drain of an escrow contract worth about $1.73 million.

According to on-chain records, the alleged attacker submitted a setup transaction at 11:58:47 PM UTC on September 3, followed by a drain transaction at 12:01:35 AM UTC on September 4 in Ethereum block 25,900,234. The escrow released 69,257.38 Dai (DAI) and 1,658,524.864122 USD Coin (USDC), for a combined value of approximately $1.73 million. The attacker converted the stablecoins into about 689.2 Ether (ETH) and deposited them into the privacy tool Tornado Cash beginning at 12:15:59 AM UTC.

Blockchain-security monitor Specter first flagged the movement of funds, and PeckShieldAlert relayed the finding, saying the escrow “may have been exploited.” Later technical analysis attributed the drain to an integer overflow in an unsafe signed-to-unsigned downcast used in Notional’s free-collateral valuation, which allowed a fabricated liability to be truncated to zero so the position registered as debt-free.

On September 7, security firm SlowMist reported that two addresses on BNB Chain had opened malicious fCash positions using the same code pattern. Those positions had not matured, and no second drain had executed at the time of writing.

Further details on the setup transaction, drain transaction, and attacker path are covered in The Crypto Times report on the Notional Finance escrow contract facing the reported $1.7 million exploit.

XRPH Wallet: 4,011 XRP Ledger Wallets Emptied in Three Hours

On the XRP Ledger, a sweep of XRPH Wallet, a mobile application published by the XRP Healthcare project, emptied 4,011 user wallets in about three hours starting at 22:07 UTC on September 3.

A ledger review published after the event put the haul at approximately 267,664 XRP alongside XRPH and XRPHAI tokens, with a combined value of about $452,000 at the time of reporting. Forensic analysis attributed the breach to a design flaw in the wallet’s staking feature, which transmitted users’ seed phrases to a remote XRP Healthcare server when staking was activated. 

Funds were subsequently moved through the cross-chain layer NEAR Intents onto Ethereum, where about 445,198 DAI held by the attacker remained unmoved in the published review. XRP Healthcare told users to stop using the application until further notice. The core XRP Ledger protocol was not affected.

Dream Health Chain: About $72,000 on BNB Chain

On September 5, on-chain trackers Monitoring Room and Web3 Daily Exploits documented an award-contract flaw in Dream Health Chain on BNB Chain that allowed a claimant to reset a claimed award and claim it repeatedly. 

🚨SlowMist TI Alert🚨
💸 Dream Health Chain Loss: ~$71.8k

🔍 Root Cause: Business award state machine logic flaw. `createAward()` records a fixed reward without locking any collateral or per-award reserve; `participateAward()` does not require the award to be unclaimed, so a…

— SlowMist (@SlowMist_Team) September 5, 2026

Trackers put the loss between $71,800 and $72,000 in USDT-equivalent value. Initial feeds noted that the funds remained in the attacker’s wallet at the time of writing.

Reddio RedSonic Vault: About 9.25 ETH via a Flash-Loan Path

Also on September 5, on-chain security service ExVul documented a single-transaction flash-loan exploit against Reddio’s RedSonic Vault on Ethereum.

According to ExVul’s alert, the attacker borrowed approximately 1,139 Wrapped Ether (WETH) from the decentralized exchange Balancer, registered a second share class through a permissionless path, inflated the share price by double-counting the borrowed collateral, redeemed both classes, swapped the proceeds on the decentralized exchange Curve, and repaid the loan in the same transaction. 

The net profit was about 9.25 ETH, which Monitoring Room valued at roughly $23,000. The affected vault address is 0x4315…1126f, and the exploit transaction is 0xe3c..791a.

Events in the Same Week Excluded from the $322 Million Total

Several disclosures dated within the September 1 to September 7 window are logged separately to prevent double counting and to keep the headline figure comparable across weeks.

Ontology: The Ontology Foundation confirmed “malicious attack activity” on September 1 and resumed the chain on September 2 after deploying v3.1.5. Its statements said Ontology (ONT), Ontology Gas (ONG), and user assets were not compromised. Public trackers logged the incident at $0.

Injective: An application-level binary-options exploit on August 31 prompted an accelerated network upgrade. On September 1, the Injective Foundation said the chain, its consensus mechanism, and staked Injective (INJ) had not been compromised. 

A second patch was executed at 17:43:41 UTC on September 2. A third-party estimate placed the application-level losses at about $4.8 million, though the project has not confirmed a figure. Additional context is available in The Crypto Times report on Injective confirming a secure network upgrade after the app exploit.

Core Decentralized Autonomous Organization (Core DAO): A reward-accounting flaw released approximately 255 million Core tokens (CORE) ahead of schedule between August 28 and August 31. The CoreRewardFix upgrade activated at 13:00 UTC on September 3 and removed 186.153 million CORE, with about 69 million CORE having already moved to external wallets. Core’s fixed 2.1 billion CORE maximum supply was not raised. The project’s disclosure came on September 5. 

Coldcard Wave 3 movement: Digital-asset research firm Galaxy Research said at 02:19 UTC on September 7 that the Wave 3 operator had moved 97.09 BTC from 12 vaults, or about 45% of Wave 3 coins, through decentralized cross-chain swap protocol THORChain and Bitcoin CoinJoin transactions. Rank 1 moved 20.50 BTC on September 2 at 20:00 UTC, Rank 2 moved 15.48 BTC on September 5 at 14:41 UTC, and Ranks 3 to 11 moved on September 6. 

The underlying seed-generation firmware bug dates back to July, and about 116.98 BTC across 282 vaults remained unspent. 

Term Finance: Term Labs published its technical account of the August 23 governance drain on September 2 and said fixed-rate loan positions had been recovered by 14:52 UTC on August 25. Blockchain security firms PeckShield and CertiK had placed the original loss near $8.5 million. 

ChatGPT-linked FXRP phishing: On September 3, blockchain investigator VAL published a $2.1 million trace of a phishing theft involving Flare’s bridged XRP token (FXRP). The theft is dated June 12 and does not fall within the September 1 to September 7 window. 

ClickFix and EtherHiding: Reports dated September 1 and September 5 described malware that stores command-and-control addresses on Polygon or BNB Chain. These campaigns abuse public blockchains for data hosting rather than draining protocol treasuries and are not included in the total.

Week Total at a Glance

IncidentDate (UTC)Reported AmountIn $322M Total
Liquid NetworkSeptember 6, 14:05 to 14:28 Approx. $320 million Yes
Notional FinanceSeptember 3, 23:58 to September 4, 00:01 Approx. $1.73 million Yes
XRPH WalletSeptember 3, from 22:07 Approx. $452,000 Yes
Dream Health VaultSeptember 5 Approx. $72,000 Yes
RedSonic VaultSeptember 5Approx. $23,000 Yes
OntologySeptember 1 to 2 $0 reportedNo
Injective applicationsExploit 31; patches Sept 1 to 2Officially unpublishedNo
Core DAO rewardsExploit Aug 28 to 31; fix Sept 3Emissions pulled forwardNo
BNB Chain Notional copySeptember 7 alertNot executedNo

Outlook

The $322 million figure is highly sensitive to the outcome of the Liquid Network incident. If most of the withdrawn Bitcoin is returned once a patch is deployed, as the receiving party has indicated in on-chain messages, the net loss for the week will fall sharply. As of 6:15 UTC on September 7, no return had been recorded.

Public logs used for this inventory include Monitoring Room (updated September 6), YFarmX (updated September 6), Web3 Is Going Just Great, PeckShieldAlert, SlowMist, Galaxy Research, and XRPL.to. Those sources did not list any other valued protocol drain dated September 1, 2, or 7 beyond Liquid Network’s September 6 peg-out.

Also Read: Coldcard Hacker Moves 45% of Wave 3 Bitcoin via THORChain and CoinJoins

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Individual in a dark hooded sweatshirt sitting in front of a laptop computer, silhouetted against an illuminated German state flag of Berlin
Berlin Hit by 30 Bitcoin Ransom Demand Over Stolen State Data
Hanwha logo mounted on a white marble wall with an Avalanche tabletop sign positioned in the foreground
South Korea’s Hanwha Builds Avalanche-Based Tokenized Securities Platform
3D orange Capital B logo mounted on a dark textured wall
Capital B Buys 376 BTC While Treasury Sits $80 Million Underwater
Amit Shah, Minister of Home Affairs of India
India Sets Up Darknet-Crypto Cell to Trace Drug Money Trail: Amit Shah
Harmony logo set against a light blue and green gradient background with 3D connected blockchain cubes
Harmony Proposes Shutting Down Its Blockchain and Moving ONE to Ethereum

Find Us on Socials

You may also like

Three-panel image featuring US Capitol with CPI documents, the ECB headquarters in Frankfurt with Euro banknotes, and a hand holding a smartphone displaying a confirmed Solana Transaction V1

Crypto Week Ahead: US CPI, ECB Decision, Solana & MultiversX Updates 

Coldcard Hacker Moves 45% of Wave 3 Bitcoin via THORChain and CoinJoins

Coldcard Hacker Moves 45% of Wave 3 Bitcoin via THORChain and CoinJoins

Simon Gerovich, Metaplanet Inc. Chief Executive Officer (CEO)

Metaplanet CEO Breaks Silence on 319M-Share Option Pool & Five-Year Lock-Up

Core DAO Fixes Reward Exploit, Claws Back 186M CORE

Core DAO Fixes Reward Exploit, Claws Back 186M CORE

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information