Bitcoin (BTC) price held near $83,000 on Monday, September 28, after President Donald Trump’s 2 p.m. Eastern Time (ET) Oval Office appearance focused on a $15 billion steel plant in Iowa. The event, which crypto traders had watched as a possible market catalyst, included no mention of Bitcoin, stablecoins, or the U.S. Strategic Bitcoin Reserve.
Separately, crypto exchanges and decentralized finance (DeFi) protocols reported more than $400 million in hacks and exploits between September 22 and September 25, led by a $387.5 million breach at Bitget.
Trump’s Oval Office Announcement Focused on Steel, Not Crypto
According to the White House, the $15 billion Mesabi Metallics mill in Iowa will create 1,750 permanent jobs, support up to 6,000 construction jobs and is projected to add $95 billion to the U.S. economy over the next decade. The administration said the mill will produce 7.5 million tons of steel a year in its first phase, rising to about 10 million tons, using iron ore from the company’s newly opened Minnesota mine.
A White House official told CNBC the plant aims to begin production in 2030. Trump was joined by Mesabi Metallics Chief Executive Officer (CEO) Joe Broking, Chairman Rewant Ruia, and Commerce Secretary Howard Lutnick, among others. The facility will be built in Lee County, Iowa Capital Dispatch reported. Mesabi Metallics is owned by India-based Essar Group, according to CBS News.
Why Crypto Traders Watched the Event
The White House had not disclosed the topic in advance, and as The Crypto Times reported before the event, no official statement had linked the Oval Office appearance to digital assets. The White House release on the announcement covers steel output, mining policy and tariffs. It does not reference Bitcoin, crypto regulation or the reserve.
The Strategic Bitcoin Reserve remains in place under an executive order signed on March 6, 2025. The White House fact sheet says the reserve is funded with Bitcoin forfeited in criminal or civil proceedings, and that the United States will not sell Bitcoin deposited into it. Monday’s remarks did not restate or expand that framework.
Bitcoin Price Stays in a Tight Range
As of 6:30 a.m. Coordinated Universal Time (UTC) on September 28, CoinGecko data showed Bitcoin near $83,244, down about 1.6% over 24 hours, with a session range of roughly $82,778 to $85,089, The Crypto Times reported. Bitcoin had held near $84,400 over the weekend.
The move followed a September rebound that took Bitcoin back above $87,000 for the first time since January. CryptoQuant data showed Bitcoin closing near $86,198 on September 22. The price has since settled into an $83,000 to $85,000 band.
ETF Inflows and Strategy Purchases
U.S. spot Bitcoin ETFs attracted $2.39 billion in net inflows in the week ended September 25, even as Bitcoin fell 2.3% over the same period. Total net assets stood at $108.42 billion. According to SoSoValue data, it was the funds’ largest weekly inflow since October 2025.
Strategy, the largest publicly traded corporate holder of Bitcoin, bought 1,665 BTC for $142.7 million at an average price of $85,681 per coin. As of September 27, the company held 847,666 BTC, acquired for $63.95 billion at an average of $75,437 per coin. The purchase was disclosed in a filing with the U.S. Securities and Exchange Commission (SEC) and funded through sales of its MSTR common stock.
Geopolitical risk remained a factor for the market. On September 26, Trump said he had rejected Iran’s proposal to reopen the Strait of Hormuz.
Bitget Hack Leads a Week of Crypto Exploits
Bitget, a centralized cryptocurrency exchange, reported the largest loss of the week. The exchange’s withdrawal service update lists the incident time as 18:31 UTC on September 24.
Bitget first put the loss at $351.6 million. It later raised the figure to $387.5 million after tracing more transactions involving Zcash and TRON, and said the attack had been contained. Affected assets included XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX across Ethereum, other Ethereum Virtual Machine (EVM) networks, the XRP Ledger, Zcash and TRON.
How the Attack Worked
The attackers did not steal Bitget’s private keys. According to a GoPlus Security review of the breach, they caused the exchange’s own signing system to approve transfers it never intended to send. The compromise was limited to some hot wallets, which stay online to process routine withdrawals, and warm wallets, which sit between hot and offline storage. Bitget Wallet, a separately operated self-custody product, was not affected. GoPlus traced a single one-minute wave at 19:16 UTC that moved about $185 million.
In a September 28 statement, Bitget said a flaw in a third-party security product gave the attacker high-level internal credentials, which were used to send fraudulent withdrawal commands that bypassed its risk controls, Infosecurity Magazine reported. Cybersecurity firms Mandiant and SlowMist are supporting the investigation.
Attribution and Fund Tracing
Bitget told CNBC it suspects North Korean hackers, citing preliminary evidence. On September 28, on-chain investigator ZachXBT published the online identities of five alleged launderers he said were moving the funds on behalf of the suspected Democratic People’s Republic of Korea (DPRK) attackers. Bitget has not released the technical evidence behind the attribution, and it has not been confirmed by any court.
Bitget CEO Gracy Chen asked THORChain, a cross-chain swap protocol, to refuse service to the attacker’s addresses at 11:44 UTC on September 26. THORChain declined at 18:17 UTC the same day, and XRP kept swapping into Bitcoin on September 27.
Withdrawal Schedule and User Funds
Bitget said the loss falls within its Protection Fund, which its first incident notice valued at more than $464 million. Under its published schedule, BTC withdrawals on the Bitcoin and BNB Smart Chain (BSC) networks resumed at 08:00 UTC on September 28. ETH withdrawals are scheduled for September 29, USDT for September 30, and other tokens, fiat and peer-to-peer (P2P) services for October 2, each at 08:00 UTC.
Other Crypto Hacks and Exploits Last Week
Five smaller incidents were reported between September 22 and September 25.
Duelbits Loses About $7 Million From Hot Wallets
Crypto casino Duelbits confirmed a roughly $7 million hack on September 24 and took its platform offline. Blockchain security firm Scam Sniffer first flagged about $4.2 million in abnormal outflows from Duelbits hot wallets on Ethereum, BNB Chain and Tron, and investigators later identified 8.1 BTC leaving its Bitcoin hot wallet.
Co-founder Joe said user funds are safe. Duelbits has not published a technical root-cause analysis.
Neutron Governance Attack Drains Astroport and Drop
A malicious governance proposal executed on Neutron, a Cosmos ecosystem blockchain, between about 02:25 and 07:44 UTC on September 22 gave the attacker admin control over contracts belonging to Astroport and other protocols, according to a Cosmos Labs recovery update. Security firm SlowMist estimated losses at about $4.9 million for Astroport, a decentralized exchange, and about $4.4 million for Drop, a liquid staking protocol.
About 1.73 million ATOM, the Cosmos Hub’s native token, reached the Hub. Validators halted the network and, after a restart at 12:00 UTC on September 23, moved 1,227,121 ATOM into a 4-of-6 recovery multisig held by community validators.
Roughly 500,000 ATOM swapped through THORChain before the halt, and a 168,990.9 ATOM refund that arrived after the restart, are treated as lost. The recovered funds can move only after a Cosmos Hub governance proposal passes.
Payy Network Bridge Drained of $1.83 Million
A single transaction confirmed at 04:21:23 UTC on September 24 moved 1,832,149 USD Coin (USDC) out of Payy Network’s Ethereum rollup contract through a function called verifyRollup. The Crypto Times verified the transfer against Ethereum records. Payy, a privacy-focused stablecoin payment network, said the stolen assets were users’ non-custodial deposits and paused all network transactions.
Limit Break Payment Processor Exploit Hits Old Magic Eden Listings
On the morning of September 25, an attacker abused a flaw in Limit Break’s Payment Processor V2, a contract that once settled trades on Magic Eden’s Ethereum non-fungible token (NFT) marketplace. The first wave took 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives, Crowdfund Insider reported. About 660 wrapped ether (WETH) could not be saved in time.
Yuga Labs Vice President of Blockchain 0xQuit said a whitehat operation rescued 23,155 NFTs worth more than $5.7 million. Limit Break paused Payment Processor V3, which had the same flaw, but V2 could not be paused. Magic Eden has urged former users to revoke Payment Processor V2 approvals on Ethereum, Polygon and Base.
How Much Was Lost in Crypto Hacks Last Week
Adding the reported figures from Bitget ($387.5 million), Duelbits ($7 million), Astroport ($4.9 million), Drop ($4.4 million) and Payy ($1.83 million) gives about $405.6 million. That total excludes the roughly 660 WETH taken in the Limit Break exploit, which pushes the week’s reported losses higher.
These figures reflect value moved off platforms and protocols, not final losses to users. Bitget says its Protection Fund covers the incident, Duelbits says user funds are safe, and part of the stolen Neutron funds has been secured on the Cosmos Hub. Recovery efforts remain ongoing across all six incidents.
Also Read: HBAR Price Soars 22% as Hedera App Lands on IBM Cloud: Can $0.12 Hold?
