Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$76,983▼ 0.91%ETH$2,480▼ 0.96%SOL$100.94▼ 0.44%TOTAL CRYPTO$2.64T▼ 3.48%S&P 5007,619.98▼ 2.13%NASDAQ26,186.41▼ 2.03%DOW52,421.20▼ 2.44%GOLD4,324.00▼ 2.55%WTI102.81▲ 24.77%BRENT101.58▲ 14.75%USD/JPY154.99▼ 2.78%DXY99.58▼ 0.09%
Crypto

Crypto Security Week: Safe Drain, Exchange Closures, Coldcard Losses

A $7.8 million Safe wallet drain hijacked by a bot named Yoink, CoinEx shutting after nine years and $130 million in Coldcard losses show where crypto security stands.

Pexels – https://kaboompics.com/

A $7.8 million heist on Ethereum ended this week with a twist: an automated trading bot called Yoink front-ran the attacker, paid a higher fee to be processed first, and took the stolen tokens for itself. The incident, alongside CoinEx’s decision to shut down after nine years and the slow-motion laundering of Coldcard hack proceeds, offers a snapshot of where crypto security stands in September 2026. The threats are old. The responses are improvised.

The Safe wallet drain, block by block

The attack targeted a Gnosis Safe wallet on Ethereum early Tuesday. Security firms BlockSec, Blockaid and SlowMist traced the loss to a custom Safe module the wallet owner had authorized, a helper contract linked to a Uniswap v4 liquidity pool. The module accepted caller-controlled data and used DELEGATECALL without proper access checks. An attacker drove the module into a hook-enabled pool they had created, unwrapped a wrapped rsETH position, and prepared to extract roughly 2,900 rsETH worth about $7.8 million.

Then the market intervened. Yoink, a bot that monitors the public transaction queue for exploitable situations, spotted the attack transaction, paid about $47,000 in priority fees to jump ahead of it in the block, and completed the extraction first. The original attacker got nothing. The wallet owner got nothing either. A third party with no connection to the victim walked away with the funds because it could see the theft coming and bid more for block space.

Kelp DAO, which issues rsETH, confirmed its core contracts were untouched and the token remains fully collateralized. The firm imposed a 24-hour suspension on related addresses as a precaution. The lesson is narrower than “Safe is broken” and sharper than “DeFi is risky”: the flaw lived in one wallet’s custom module, and the public mempool turned a theft into an auction. Whoever wins the auction keeps the money, and the victim has no claim on either party.

It also raises an uncomfortable governance question. If front-running attacks becomes profitable enough, security firms and rival bots may start doing it deliberately as a rescue business, negotiating returns for a fee after the fact. That has precedent in white-hat extractions, but Yoink’s operator has made no such offer public. For now, the victim’s $7.8 million sits in a bot’s wallet with no stated path back.

CoinEx calls it after nine years

Hong Kong-based exchange CoinEx announced Tuesday it will cease all operations by December 22, 2026, citing a prolonged market downturn, shrinking trading volumes and rising compliance costs. The timeline is compressed: new registrations stopped immediately, futures moved to reduce-only mode on September 15, all non-spot services end September 22, spot trading ends September 29, and withdrawals stay open until the December deadline. CoinEx Smart Chain and OneSwap shut down on the same day as spot trading.

The company said its reserve ratio exceeds 100 percent and all user assets are fully backed. It will repurchase all remaining CET tokens at 0.005 USDT each, the token’s initial listing price, slightly above the market price when the announcement landed. CET traded around $0.00466 on Tuesday, roughly 97 percent below its July 2018 peak. Any unwithdrawn USDT will move to an independent custodian, with a monthly custody fee attached. CoinEx Wallet and CoinEx Vault, which operate independently of the exchange, stay live.

CEO Haipo Yang was blunt in a post on X. “After much reflection, I have come to accept a hard truth. CoinEx did not become one of the industry’s leading exchanges, and the security and compliance risks of running a crypto exchange have become increasingly difficult to contain,” he wrote. CoinEx joins BitMart, BitMEX and AscendEX among exchanges that shut down this year for similar reasons.

Context matters here. CoinEx left the United States in 2023 under a settlement with New York’s attorney general that returned over $1.1 million to investors and added more than $600,000 in penalties. This month, TRM Labs published analysis claiming more than $3.84 billion in crypto flows connected CoinEx to over 60 sanctioned Iranian platforms over seven years, describing the exchange as the biggest lifeline for Iran’s crypto ecosystem and Nobitex’s single largest external counterparty. CoinEx denied any knowledge of sanctioned activity and said it had strengthened geo-fencing and screening after Nobitex was sanctioned. The exchange exits under a cloud it spent its final months disputing, and the shutdown removes one of the largest remaining venues for Iranian flows, whatever the truth of the connection.

The Coldcard hangover

The Coldcard hardware wallet exploit that began July 30 continues to bleed. Coinkite shipped a firmware update in March 2021 that broke how devices generated wallet seeds, and attackers weaponized the flaw across multiple waves starting in late July. Galaxy Research puts confirmed losses at roughly 1,789 BTC, about $130 million at the time of the thefts, spread across more than 8,865 addresses, with the median victim losing more than one bitcoin.

The laundering phase is now underway. The Wave 3 attacker moved roughly 97 BTC, worth about $7.8 million, through THORChain swaps and CoinJoin transactions over five days, about 45 percent of that wave’s haul. Galaxy reports that 82 percent of all stolen bitcoin remains parked in attacker wallets, meaning most of the damage is still recoverable in principle but sitting in plain sight. At least 15 different attackers took part across the waves, which suggests the exploit circulated rather than staying with one group. The episode triggered a broader wave of old coins moving: a wallet dormant since 2013 moved 500 BTC worth $31 million in early August, which on-chain analysts read as users rotating away from Coldcard-generated keys.

Liquid Network, Blockstream’s Bitcoin sidechain, suffered its own breach on September 6, losing about 4,000 BTC worth roughly $320 million to a range-proof verification bug in the Elements software. The federation’s reserves fell from over 4,200 BTC to about 197 BTC in a single stroke, one of the largest breaches involving a Bitcoin-adjacent network this year. The attackers identified themselves as white hats and returned about 3,400 BTC after Blockstream patched the vulnerability, keeping roughly 598 BTC, near $47 million, as a self-appointed bounty. The industry’s de facto bounty norm is now set by whoever drains the funds first, which is not a norm any security team would design on purpose.

What the pattern says

Three threads run through the week. First, the losses are concentrated at the edges of the system, in custom modules, aging firmware and marginal exchanges, rather than in the base protocols. Second, self-help is the dominant remedy: MEV bots front-running thieves, white hats keeping a cut, victims rotating keys without any coordinated response. Third, compliance costs are now a stated reason for exit, not just market conditions, which squeezes mid-tier exchanges hardest while the largest venues keep consolidating share.

A study of 135 DeFi incidents published this month found that 94.4 percent of losses in audited protocols came from attack paths no audit covered, mostly outside the reviewed code. The Safe module exploit fits that pattern exactly. The code that was audited worked. The code that was added later did not. Audits certify a snapshot, and wallets are living systems that grow modules, plugins and integrations over time.

None of this produced a systemic shock. Bitcoin traded between $77,000 and $81,000 through the week, driven by the Federal Reserve and the Senate’s CLARITY Act vote rather than security news. The market has absorbed a $320 million sidechain drain and a nine-year exchange closure without moving prices. That resilience is real. It is also a bet that the next failure will be as containable as this week’s, which is not a plan so much as a habit.

SourcesCoinDesk; BlockSec; Blockaid; SlowMist; Galaxy Research; Cointelegraph; BeInCrypto; KuCoin News
Share: X