The week’s confirmed on-chain drains were smaller in dollars than the previous seven days, yet broader in failure type. A Safe wallet strategy module, a mobile application wallet, a decentralized finance (DeFi) money market oracle, a flash loan yield vault, and a bridge signing key were each named as a root cause in a separate incident, according to project statements, blockchain security firms, and joint government advisories issued during the window.
Highlights of the Week
Mid-September’s confirmed on-chain drains cluster around $20 million, led by a roughly $7.8 million restaked Ether (rsETH) Safe wallet exploit on Ethereum and a $3.5 million Nostra oracle borrow on Starknet.
A single attacker cluster drained about 8.72 million Fetch.ai (FET) tokens worth roughly $1.53 million and minted 408.5 million NuNet Tokens (NTX) valued at about $463,000 on September 19, then minted 260 million SingularityNET Tokens (AGIX) and 53.838 million World Mobile Tokens (WMTx) on September 20. Blockchain security firm PeckShield later valued the cluster’s Ethereum holdings at roughly $16.77 million, a figure that reflects newly minted, unsold inventory rather than realised proceeds.
Software wallet provider DCENT, formerly D’CENT, said abnormal transfers were limited to its mobile application wallet, and no impact originating from its hardware wallets themselves had been confirmed. Blink Wallet paused its custodial services after a few dozen custodial accounts were drained, without releasing a dollar figure.
Coordinated Universal Time (UTC) timestamps and transaction identifiers for the incidents were published by Blockaid, PeckShield, SlowMist, GoPlus Security, BlockSec, CertiK and AstraSec at the time of each disclosure.
The Three Ledgers That Made Up the Week
The useful split for the week is three ledgers, not one headline number.
Fresh Protocol and Wallet Drains, September 14 to 20
The named incidents in this bucket add to roughly $20 million if DCENT is counted at SlowMist’s snapshot of $6.57 million and Blink Wallet is left as an undisclosed figure. That is the cleanest week-over-week comparison.
Unauthorised Mints Held as Inventory
PeckShield’s $16.77 million figure for the combined Fetch.ai, NuNet and SingularityNET cluster represents attacker holdings, including newly minted AGIX and WMTx tokens on Ethereum. As The Crypto Times reported on September 21, this figure should not be read as realised cash proceeds, and part of the supply may be revoked or blacklisted as bridge operators respond.
Older Campaigns Disclosed During the Week
The North Korean WaterPlum campaign, widely tracked as Contagious Interview by the security industry, moved the equivalent of 1.7 billion Japanese yen, or about $10.71 million, in cryptocurrency to the Democratic People’s Republic of Korea between December 2025 and July 2026, according to the joint advisory published on September 18. The activity therefore predates the reporting window.
$7.8 Million rsETH Drained From an Ethereum Safe Wallet, Intercepted by MEV Bot Yoink
On the morning of September 15, 2026, an unidentified user’s Gnosis Safe wallet on Ethereum, at address 0x40E93a52F6Af9fCD3b476aeDADD7FeABD9f7AbA8, lost about 2,900 rsETH, a liquid restaking token issued by Kelp DAO. The position was valued at around $7.8 million at the time of the exploit, per an on-chain analysis reported by The Crypto Times.
Blockchain security firms Blockaid, BlockSec, SlowMist and AstraSec traced the fault to a helper Multicall contract and a custom Safe module that the wallet had authorised as a strategy executor, not to Safe’s core multisig contracts or the owner keys. The attacker used a public keeper multicall function to push a custom Uniswap version 4 (Uniswap v4) liquidity module into a hooked pool, unwrap the Aave-wrapped aEthrsETH position into raw rsETH, and attempt to withdraw the tokens.
How Yoink Front-Ran the Attack
The payout never reached the original attacker. In Ethereum block 25980525, at 04:38:47 UTC, a maximal extractable value (MEV) bot known as Yoink, at address 0x80BF7Db69556D9521c03461978B8fC731DBBD4e4, paid roughly $46,000 to $47,000 in priority fees to the block builder, captured the transaction, and forwarded 2,882.37 rsETH, worth about $7.80 million, to address 0xC70f00CD7E461686b04B0E912E309becA8b80ea0. A further 17.63 rsETH was routed through Uniswap v4. Etherscan priced the main leg at about $7,848,604.
Kelp DAO placed the receiving address under a temporary 24 hour pause and said in an official statement on X that its core contracts remained safe, rsETH stayed fully backed, and standard user operations continued normally. No user action was required.
DCENT App Wallet Signing Vulnerability
Wallet manufacturer IoTrust, which operates the DCENT brand rebranded from D’CENT on September 8, 2026, published an urgent notice on its official X account on September 16 and a formal status report dated September 17 in Korea Standard Time (KST). The company said abnormal asset transfers had been identified in its mobile application wallet, that impact originating from hardware wallets themselves had not been confirmed, and that anyone who had ever entered the same recovery phrase into the application wallet should move their assets, as The Crypto Times documented on September 16.
The scope covers application wallets in DCENT versions earlier than version 8.1.0, according to a subsequent customer notice on the company’s store portal. Version 8.1.0 was released on November 5, 2025, at around 07:40 UTC.
Sources on the Loss Total
DCENT has not published an official dollar figure. SlowMist has logged the incident at $6.57 million in its public tracker. Independent research on the XRP Ledger has described multiple sweep waves from September 15 onward affecting thousands of wallets, with some emptied accounts later deleted. Those later waves sit outside DCENT’s first official report and should be read as external on-chain analysis rather than company confirmation. DCENT stated in its Frequently Asked Questions page that it is working with Korean law enforcement and exchanges on freezing assets and warned users about impersonation accounts.
Nostra Halts Starknet Money Market After $3.5 Million NSTR Oracle Exploit
At 13:28 UTC on September 17, decentralised finance protocol Nostra Finance, built on the Starknet Layer 2 network, said a manipulated oracle price for its native NSTR token allowed a single account to treat its NSTR holdings as inflated collateral and borrow assets worth roughly $3.5 million from its money market. The borrowed basket included Ether (ETH), Starknet Token (STRK), USD Coin (USDC), Tether (USDT), Wrapped Bitcoin (WBTC) and DAI version 1 (DAIv1), according to Nostra’s official statement and coverage reported by The Crypto Times on September 18.
Lending, borrowing, withdrawals and liquidations were paused pending pool-by-pool reconciliation. The team said the final loss and any recoveries were not yet known and warned users that it would never send private messages or ask them to connect a wallet during the recovery process.
How the Oracle Was Manipulated
GoPlus Security and other analysts reported that the NSTR oracle print was pushed from about $0.006 to about $49.5, an increase of roughly 8,000 times, through a thinly traded NSTR paired with Solv Bitcoin (SolvBTC) liquidity pool. PeckShield tracked about $1.92 million of the borrowed assets bridged to Ethereum, comprising 234.57 ETH and 1.3 million DAI. CertiK placed the remainder, roughly $1.55 million, on Starknet. DefiLlama data showed Nostra’s total value locked (TVL) falling from about $4 million on September 16 to roughly $710,000. NSTR’s circulating market capitalisation was under $600,000 at the time of the exploit, meaning the borrow was several times the token’s entire free-float value.
Fetch.ai, NuNet and SingularityNET Bridge Compromise Widens to $16.77 Million in Holdings
Blockaid flagged the incident cluster on September 19. PeckShield subsequently refined the figures for the first two legs, according to details reported by The Crypto Times on September 20.
The Fetch.ai converter drain occurred at 20:21:47 UTC on September 19, 2026, in Ethereum block 26013913. The transaction called the conversionIn function on the TokenConversionManagerV3 contract at 0xab424A430CC09864fA1277A38193111705ADF3A3 and moved 8,721,530.40 FET, valued at about $1.53 million, from the converter to wallet 0x2dcc1085fDCf418B421E45e86e4e54637cc21dfE.
Twenty-eight minutes later, at 20:50:11 UTC, the NuNet deployer account at 0x863F13e5B505f1Eb17803b94EC9d3DaF80092165 minted 408.53 million NTX at contract 0xF0d33BeDa4d734C72684b5f9abBEbf715D0a7935, worth about $462,730, and sent the newly minted supply to the same cluster address. The initiating address was 0x1572F2af7696b39c85E3221CDE8EFb640F86c362.
Shortly after the drain, the cluster swapped part of the proceeds for 546.36 ETH, valued at around $1.44 million.
The Extended Wave on September 20
PeckShield reported at 09:21 UTC on September 20 that the same actor had minted 260 million AGIX and 53.838 million WMTx on Ethereum, taking the cluster’s tracked holdings to roughly $16.77 million, as The Crypto Times reported on September 21. Blockchain data provider Bitquery separately counted about 2.3 billion newly created units across AGIX, NTX, Cudos Governance (CGV) and WMTx traced to the same actor.
Fetch.ai’s on-chain attack analysis, published on the ASI:One platform, described the root cause as a compromised signing key for the SingularityNET bridge authoriser plus a separately compromised minting key for NuNet. Fetch.ai posted at 16:19 UTC on September 20 that Fetch.ai’s own contracts were not under threat and that FET continued to operate normally, per its official channel. World Mobile Chain confirmed at 05:07 UTC on September 20 that the SingularityNET bridge had been exploited and that WMTx had been minted on Ethereum without authorisation. Bridges were paused, and users were told to ignore recovery messages sent through direct messages.
Blink Wallet Paused After Custodial Accounts Were Drained
Bitcoin Lightning Network wallet Blink paused all services on September 19, 2026, after saying in an official statement on X that an attacker had accessed a limited number of custodial accounts and withdrawn funds. As The Crypto Times noted on September 19, the company said the large majority of funds remained secure and that non-custodial wallets were not affected.
Follow-up posts narrowed the scope to a few dozen custodial accounts, said every affected account had been identified, and stated that impacted users would be made whole without needing to take action. Services returned online after a patch, while impacted accounts remain locked. Blink has not released an official loss figure.
Smaller On-Chain Hits During the Week
Flamingo Finance and Older Flamincome Contracts
Blockchain security firm Blockaid flagged an attack on older Flamincome contracts associated with Flamingo Finance on September 16, 2026, reported by The Crypto Times the same day. The attacker used an approximately $18 million Tether (USDT) flash loan through Morpho, inflated the share price of the VaultYUSDT contract by staking Curve USDP liquidity provider (LP) tokens into a strategy contract, and then redeemed liquid Aave USDT (aUSDT) at a favourable rate.
Attacker profit stood at roughly $345,900 in USDT. The abused contracts included 0x046..BCc0F and 0xb8…68a5.
Bonfiretoken
On September 16, 2026, SlowMist’s public tracker recorded a missing access control failure on the BonfireSwap router. The router’s transfer function did not require the message sender to equal the from address or check the caller’s allowance on the from address. An attacker set approved holders as the from address and themselves as the to address, drained TOKEN via existing victim-to-router allowances, and forwarded funds through a same-token pool swap. About 41 approved holders were affected, and the loss was recorded at roughly $50,000.
Spiral
On September 14, 2026, the same tracker recorded an attacker manipulating a Uniswap v4 pool spot price. The SpiralHookV2 borrow function valued collateral using the pool manager’s getSlot0 function with no time-weighted average price (TWAP) protection. The loss was recorded at about 10.7 ETH, or roughly $26,800.
Disclosed Last Week, Not Stolen Last Week
WaterPlum, Widely Known as Contagious Interview
A joint advisory dated September 18 from Japan’s National Police Agency (NPA) and National Cybersecurity Office, the Federal Bureau of Investigation (FBI), the United States Department of Defense’s Cyber Crime Center (DC3), the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), Germany’s Bundesnachrichtendienst (BND) and Bundesamt für Verfassungsschutz (BfV) formally attributed the multi-year Contagious Interview campaign to a North Korean group tracked as WaterPlum.
According to the advisory and coverage reported by The Crypto Times on September 18, the group infected at least 30,000 devices in more than 100 countries and pulled funds or credentials from over 7,000 cryptocurrency wallets between December 2025 and July 2026. The equivalent of 1.7 billion Japanese yen, or about $10.71 million, in cryptocurrency was moved to the Democratic People’s Republic of Korea over that period.
The NPA and FBI assess that WaterPlum actors and some North Korean information technology workers operate under the 313 General Bureau of the Munitions Industry Department, subordinate to the Central Committee of the Workers’ Party of Korea.
Other Same-Week Security Disclosures Not Counted in the $20 Million Tally
The Haruko application programming interface (API) token breach across 15 institutional clients was disclosed on September 18, without a confirmed loss figure. A ransom demand of 6,000 Monero (XMR), worth about $3 million, was made against fintech Revolut over roughly 680 exposed customer files, reported by The Crypto Times on September 17.
SlowMist and the OKX security team warned users on September 19 about the FomoPeek application versions 1.1 and 1.2 for Apple’s iOS operating system exposing wallet credentials, documented by The Crypto Times the same day.
How the Week Sits Inside September
September’s first week already stood at about $322 million, almost entirely from a single event on the Bitcoin sidechain Liquid Network on September 6, 2026, reported by The Crypto Times on September 7. Blockstream’s Liquid Network said in an incident report published on September 8 that a vulnerability in the open-source Elements software, related to how Liquid nodes cache range proof verifications, was exploited at 15:53:10 UTC on September 6 in Liquid block 4,050,336.
Approximately 4,000 Liquid Bitcoin (L-BTC) that were not backed by bitcoin held in reserve were created and processed through a peg-out, and the reserve fell from about 4,205 BTC to 197 BTC. Public reporting later put the amount returned by the party responsible at roughly 3,400 BTC, with about 598.5 BTC retained.
Liquid remains 2026’s largest single publicly reported cryptocurrency incident. The second week did not compete with it on size. It competed on variety: Safe module authorisation, application wallet signing, a thin-market oracle print, flash loan share inflation, and shared signing keys across an artificial intelligence token stack.
Disclaimer
Figures cited are as disclosed by projects and security firms through September 21, 2026, at 07:21 UTC. Recoveries, further DCENT waves, Blink Wallet’s unpublished custodial loss total, and unsold minted inventory may still move the tally. This article is intended as reporting and does not constitute financial advice.
Also Read: Kalshi Faces Accusations of Inflated Crypto Volume Over Repeated $5,500 Perp Trades
