The stUSDS module is launching a permissioned keeper to automate transaction submissions for adjusting stUSDS parameters according to the Dynamic Interest Rate Model. This automation aims to reduce manual work for signers and is planned for deployment on October 8, 2026.
Aave founder Stani Kulechov stated that Aave v3 remained unaffected after an attacker exploited a third-party adapter, draining approximately $305,000 from two Safe multisig wallets.
The Ethereum Foundation has funded a $100,000 grant for the formal verification of the Vyper compiler, aiming to enhance DeFi security by ensuring the reliability of code translation from source to bytecode. This initiative addresses potential compiler bugs that could affect protocols like Curve and Yearn, which collectively hold over $2 billion in TVL.
Three DeFi projects, Payy Network, Duelbits, and Meter.io, were exploited on September 24, 2026, resulting in a total loss of over $11 million. Payy Network's bridge was drained of $1.8 million, Duelbits suffered a suspected private key compromise resulting in a $7 million loss, and Meter.io experienced a bridge attack where unbacked tokens worth $2.3 million were minted and dumped. All affected protocols have paused operations.
An incident at Magic Eden led to 3,832 NFTs being placed in protective custody by a whitehat. Yuga Labs stated the NFTs are safe and will be returned once the risk passes, advising holders to revoke NFT permissions.
Approximately $6 million in suspicious outflows have been observed from Duelbits wallets in the past few hours. A similar incident involving Duelbits wallets occurred in 2024.
Duelbits experienced a suspicious outflow of approximately $4.3 million in cryptocurrency across Ethereum and BNB Chain. The stolen funds were subsequently swapped by the attacker.
Attackers are posing as a Web3 company and using remote job interviews to trick candidates into deploying and running malicious projects locally. The disguised application is presented as a real estate and crypto investment platform called RoyalCity.
Polymarket reportedly faced a $10 million fraud attempt, with hackers compromising nearly 500 user accounts using stolen personal information. The CEO's focus on growth over compliance was cited.
Bridges lost $24.6 million due to cross-chain verification failures in July and August. Blockaid's Cosigner tool screens transactions to prevent routing into compromised bridges or signing forged payouts.
Galaxy reported that approximately 1,779 BTC, stolen from 190 victims across more than 8,600 addresses in 'Wave 3' attacks, had been moved as of mid-August. The exact current status of the funds is not specified.
A campaign targeting iPhones running iOS 18.4-18.6.2 via Safari is exploiting vulnerabilities consistent with the DarkSword lineage to steal files, Keychain data, and keyboard input, specifically targeting imToken, TokenPocket, and TronLink wallet applications. This campaign reuses previously disclosed vulnerabilities.
The hacker who exploited Coldcard has moved approximately 10% of the stolen funds through THORChain, with researchers tracing the assets to a new Ethereum address.