Risk Radar

Daily Risk Brief / 6 developments

Crypto Risk Monitor — September 8, 2026

CEXVia tracks Liquid Network’s partial 3,400 BTC recovery, Coldcard Wave 3 laundering, Cozy Finance’s Optimism exploit, revised Tectonic accounting, Harmony’s proposed L1 shutdown and a new Philippines VASP payment-control proposal.

September 8, 2026Last updated 10:30 UTC13 min read

H1: Crypto Risk Monitor — September 8, 2026

September 8 brings a meaningful change in the global crypto-risk picture: the largest open bridge-reserve incident from yesterday has moved from near-total reserve displacement to partial recovery, while several other events have shifted in the opposite direction.

The most important update is Liquid Network. The actors who removed almost 4,000 BTC from the Liquid Federation have returned exactly 3,400 BTC after an on-chain exchange of messages with Blockstream. Roughly 598.5 BTC remains controlled by the actors. The return materially reduces the immediate reserve deficit, but it does not close the incident.

The deeper technical picture also changed. SideSwap said the original transaction involved 4,000 L-BTC being sent to its peg-out service and burned using a valid authorization, after which the Federation released approximately 3,996 BTC. SideSwap further said Blockstream identified a bug in the underlying Elements software that had allowed invalid L-BTC to be created. SideSwap says neither its system nor its Peg-out Authorization Key was compromised. Blockstream later sent an on-chain, PGP-signed message stating that bridge nodes had been patched, after which 3,400 BTC was returned.

This is a substantial recovery, but CEXVia does not classify the remaining 598.5 BTC as an agreed bounty. Public security commentary has suggested that possibility, but no formal bounty agreement has been confirmed in the evidence reviewed today. Liquid also has not yet announced full restoration of normal bridge and L-BTC services.

Update: Liquid Network 4,000 BTC Incident

A second major update concerns Coldcard. Galaxy Research says the Wave 3 operator has now moved 97.09 BTC, roughly 45% of that wave’s stolen bitcoin. This is a major escalation from the approximately 20.5 BTC movement tracked in the previous CEXVia update. The attacker has used both THORChain and CoinJoin activity and appears to be emptying the larger Wave 3 vaults first.

Across the broader Coldcard theft cluster, Galaxy says roughly 82% of the stolen bitcoin remains in original attacker-controlled addresses while approximately 18% has entered laundering or movement paths. Galaxy’s earlier high-confidence attribution placed the broader loss around 1,779 BTC; a newly identified possible victim vault could increase the total, but that additional attribution remains developing and is not used by CEXVia as a confirmed loss figure.

Update: Coldcard Hack and Attacker Fund Movement

A new protocol exploit also qualifies for a standalone Detail today: Cozy Finance on Optimism. Security researchers traced an attack involving approximately 163,326 USDC.e, with early alerts rounding the event to roughly $160,000–$170,000. The attacker appears to have acquired protection-market PTokens and then submitted undisputed “YES” answers to an UMA Optimistic Oracle path. The protection trigger did not independently verify that the underlying Aave v2 or Curve market had actually suffered the event being asserted, and payout eligibility was not tied to a pre-proposal holder snapshot.

This distinction is important: CEXVia found no evidence that Aave v2 or Curve themselves were hacked in this Cozy incident. They were the referenced protection markets. The exploit targeted the protection-market settlement logic and eligibility design.

Read the Detail: Cozy Finance Optimism Protection-Market Exploit

The Cronos / Tectonic incident also receives a major accounting revision. Bitquery’s on-chain reconstruction now places gross exploit transfers at approximately $120.375 million, spanning nine lending markets and 11 transfers. Cronos validators rolled the chain back by 10,961 blocks, erasing roughly $111 million in attacker-controlled assets that had remained on Cronos. About $8.3 million had already reached Ethereum and could not be removed by the rollback.

This does not mean Tectonic’s final economic loss is officially $120.4 million. That figure is an on-chain gross-transfer estimate. The rollback altered the final state, and final user loss, protocol bad debt and recovery accounting still require reconciliation. Tectonic has said it plans a phased reopening beginning with withdrawals and loan repayments, while deposits and borrowing remain paused.

Update: Cronos / Tectonic Exploit

A fifth high-priority event is Harmony. Harmony has proposed sunsetting its Layer 1 and migrating ONE to Ethereum as an ERC-20 token. The plan remains non-binding and no final last-block date has been fixed, so CEXVia does not describe the chain as already scheduled for final shutdown. However, Harmony is urging users to exit all smart contracts before September 10, 2026, because multisig safes, liquidity pools and on-chain applications cannot be migrated automatically under the proposed path.

The proposal follows the August Harmony exploit that created roughly 4 billion unauthorized ONE. Harmony’s migration concept would snapshot balances at the final block and allocate replacement Ethereum tokens to eligible addresses, while validator exits could begin from September 10 if the proposal progresses.

Read the Detail: Harmony Layer 1 Shutdown and ONE Migration Proposal

Regulation also produced a new event worth tracking. The Bangko Sentral ng Pilipinas (BSP) has published a draft policy direction that would impose a 12-month pause on new Operator of Payment System registrations while it reviews the licensing framework. The draft would also tighten merchant-acquisition arrangements involving regulated VASPs by requiring more direct relationships, enhanced due diligence, monitoring and risk-based transaction or settlement limits.

This is not yet a final rule. It remains a draft / consultation-stage regulatory proposal, and CEXVia therefore rates it Medium rather than treating the registration freeze as already in force.

Read the Detail: Philippines BSP Payment-Operator Freeze and VASP Controls

Today also contains a hard centralized-exchange deadline. Phemex has issued multiple notices for spot pairs being delisted at 10:00 UTC on September 8, including EUL/USDT, UAI/USDT, IN/USDT, EVAA/USDT, B2/USDT, Q/USDT, ZBCN/USDT, AIN/USDT, IDOL/USDT and GOOGLX/USDT. In those notices, deposits and normal withdrawals for the relevant token also stop at 10:00 UTC; withdrawal requests after the cutoff must be handled through customer service. CEXVia treats this as a Medium asset-access deadline rather than a solvency event.

① Today’s Highest-Priority Alerts

RiskEntityEventTimeLatest StatusEvidenceContinue MonitoringNew vs Previous Day
CriticalLiquid NetworkFederation reserve / peg-out incidentSep. 6–83,400 BTC returned; ~598.5 BTC remains; bridge nodes patched but normal services not confirmed restoredOfficial/On-chain/MediaYesMajor partial recovery + technical clarification
CriticalColdcardWave 3 stolen BTC launderingSep. 2–897.09 BTC moved, ~45% of Wave 3; THORChain + CoinJoin paths activeOn-chain/Research/MediaYesMovement increased from ~20.5 BTC to 97.09 BTC
HighCozy FinanceProtection-market exploit on OptimismSep. 7~163,326 USDC.e drained; protection/oracle settlement logic abused; funds bridged rapidlySecurity Research/On-chainYesNew exploit
CriticalCronos / TectonicRevised exploit accounting and rollbackAug. 30; revised Sep. 7–8~$120.375M gross transfers; ~$111M erased by rollback; ~$8.3M escaped to Ethereum; phased reopening plannedOn-chain/Protocol/MediaYesMaterial accounting revision
HighHarmonyProposed Layer 1 shutdown / ONE migrationSep. 7–10Non-binding proposal; ONE migration to Ethereum proposed; users urged to exit smart contracts before Sep. 10Project/MediaYesNew chain-exit proposal
MediumPhilippines / BSPOPS registration pause + VASP payment controlsDraft published Sep. 712-month OPS registration freeze proposed; VASP-linked merchant acquisition controls tightened if finalizedRegulator/Draft/MediaYesNew regulatory proposal
MediumPhemexMultiple Sep. 8 spot delistingsSep. 8 10:00 UTCMultiple pairs and normal token deposits/withdrawals scheduled to stop; post-cutoff withdrawal via supportOfficial exchangeYesHard deadline today
CriticalAscendEXClaims portal / withdrawalsOngoingPortal launch still requires official confirmation; withdrawals remain suspendedOfficialYesNo material verified change

② Exchange Exit, Shutdown and Withdrawal Risk

Phemex — Medium: Multiple asset-access cutoffs today

Phemex has separate official delisting notices that converge on the same September 8, 10:00 UTC cutoff.

The notices reviewed today include EUL, UAI, IN, EVAA, B2, Q, ZBCN, AIN, IDOL and GOOGLX spot pairs against USDT. At the cutoff:

  • the spot pair is removed;
  • open orders are automatically removed;
  • deposits for the affected asset cease;
  • normal withdrawals for the affected asset cease;
  • later withdrawal requests must be submitted to customer service.

This is not evidence of platform insolvency. The user risk is narrower: loss of normal self-service asset access after the stated deadline.

AscendEX — Critical

No new verified recovery milestone changes the core risk today. The customer claims portal remains central to the recovery process, normal withdrawals remain suspended, and users still do not have a confirmed recovery percentage or repayment timetable.

CEXVia continues to update the same event URL rather than creating a duplicate page.

Kraken — High: September 11 approaching

Kraken’s next 21-asset delisting date is now three days away.

At September 11, 14:00 UTC, deposits and trading are scheduled to stop for the previously identified 21 assets. Withdrawals remain open until December 10, followed by a December 14–18 liquidation window.

The risk is asset access and forced execution, not Kraken solvency.

Orionx — Critical, no new verified recovery

Orionx remains in permanent shutdown with withdrawals suspended and a customer-asset custody shortfall under investigation. No new reliable recovery percentage was identified today.

Router Protocol — High, shutdown path unchanged

Router still plans to end operations by September 30. Exchange-specific ROUTE delisting and withdrawal deadlines remain the next practical user-risk layer.

③ Regulation and Licensing

Philippines / BSP — Medium, new draft

The BSP proposal would pause new OPS registrations for 12 months while the central bank reassesses its payment-system taxonomy and licensing framework.

For regulated VASPs, the more important operational change is the proposed merchant-acquisition perimeter:

  • direct merchant relationships;
  • enhanced due diligence;
  • continuous monitoring;
  • transaction and settlement limits;
  • stronger merchant traceability;
  • rejection or suspension of transactions where the merchant cannot be reliably identified.

Because the measure remains in draft form and is open to feedback, CEXVia does not treat these requirements as already effective.

Pakistan / PVARA — High, post-deadline operational issue

Pakistan’s September 5 NOC deadline has passed.

PVARA’s NOC application page today still states that online submission is temporarily unavailable and instructs applicants to submit by email. No public operator-by-operator post-deadline list was identified in today’s review.

This remains important because PVARA’s licensing framework says transitional operators that did not apply by the deadline must cease operations.

Poland / ZondaCrypto — High stored regulatory/creditor risk

BB Trade Estonia OÜ, the operator associated with ZondaCrypto, was declared bankrupt on August 27. Polish authorities have advised creditors to file claims with the trustee within the applicable two-month period, and the first creditors’ meeting is scheduled for September 17, 2026 in Tallinn.

This is not a new September 8 development, so it is not promoted to a new Detail today, but the creditor deadline and meeting remain material.

Australia ASIC — High approaching

The September 30 licensing-transition deadline remains on the Watchlist.

UK FCA — Medium approaching

The FCA’s crypto authorisation application window opens September 30, with the mandatory regime scheduled for October 2027.

④ Hacks, Vulnerabilities and Asset Loss

Liquid Network — Critical, improving but unresolved

The return of 3,400 BTC changes the loss profile materially.

However, the incident remains Critical because:

  • ~598.5 BTC remains outside the Federation;
  • normal peg functionality has not been confirmed restored;
  • the complete Elements root-cause and remediation report is not yet public;
  • the retained BTC has not been formally confirmed as a bounty;
  • bridge accounting and 1:1 backing need final reconciliation.

Coldcard — Critical, laundering phase accelerating

Coldcard is no longer a mainly dormant-wallet incident.

Wave 3 movement has expanded to 97.09 BTC, and the attacker is actively using cross-chain and privacy-enhancing transaction paths.

Cozy Finance — High, new exploit

The Cozy exploit is smaller in dollar terms but technically important because it appears to exploit assumptions in protection-market event verification and payout eligibility.

Aave and Curve should not be described as hacked by this incident.

Tectonic — Critical, revised accounting

The new Bitquery accounting resolves a major ambiguity in gross transfer size but not final loss.

The important distinction is:

  • gross exploit transfer: ~$120.375M;
  • attacker assets erased by Cronos rollback: ~$111M;
  • funds that escaped to Ethereum: ~$8.3M;
  • final protocol/user economic loss: still developing.

⑤ User Complaints and Operational Anomalies

No new community-only complaint cluster met CEXVia’s platform-wide High/Critical publication threshold today.

Community claims about:

  • the 598.5 BTC retained in the Liquid event being a “bounty”;
  • AscendEX customer recovery percentages;
  • unverified GoMining victim counts;
  • final Coldcard total-loss expansions

are not upgraded to Confirmed without stronger evidence.

The distinction matters because several current incidents have active community speculation around numbers that are not yet official.

⑥ On-chain and Market Anomalies

Three on-chain developments dominate today.

Liquid: reserve recovery transaction

The 3,400 BTC return is the day’s largest positive on-chain movement. The remaining 598.5 BTC stays the primary unresolved reserve variable.

Coldcard: laundering path expands

Wave 3 has moved from an initial cross-chain test to materially broader fund movement, including CoinJoin activity.

Tectonic: gross vs escaped funds clarified

The revised chain-level reconstruction shows why gross exploit transfers cannot be used interchangeably with final realized attacker proceeds after a chain rollback.

Cozy also demonstrates a different type of on-chain risk: a relatively small but highly automated exploit where a protection-market settlement path can be converted into a payout within minutes and funds can be bridged before intervention.

⑦ Watchlist

Date / WindowEventWhat CEXVia Is Watching
ImmediateLiquid NetworkRemaining ~598.5 BTC, formal bounty/return terms, bridge restart, L-BTC backing reconciliation
ImmediateColdcardNext Wave 3 vaults, THORChain/CoinJoin exits, CEX deposits, freezes/seizures
ImmediateCozy FinanceOfficial post-mortem, remaining vulnerable markets, reimbursement, attacker destination
ImmediateTectonicPhased withdrawals, final bad debt, Ethereum-side attacker funds
Sep. 8 10:00 UTCPhemexMultiple spot-pair and normal withdrawal/deposit cutoffs
Sep. 9 08:00 UTCKuCoinUOS Ultra Mainnet and REACT Reactive Mainnet deposit/withdrawal support ends
Sep. 9BitMartRestructuring / resumption roadmap milestone
Before Sep. 10HarmonyUser exits from smart contracts / migration clarification
Sep. 11 14:00 UTCKraken21-asset deposits/trading disabled
Sep. 17ZondaCrypto / BB Trade EstoniaFirst creditors’ meeting
Sep. 23BitMEXTrading closure
Sep. 30Router ProtocolOperations wind-down
Sep. 30ASICAustralia licensing transition deadline
Sep. 30UK FCACrypto authorisation application window opens
Oct. 1Holdstation / UNOThailand access blocking
Dec. 10 15:00 UTCKrakenWithdrawal cutoff for 21 assets
Dec. 14–18KrakenForced liquidation window

⑧ No New Development Today, but Still High Risk

AscendEX — Critical: withdrawals remain suspended; customer recovery framework remains incomplete.

Orionx — Critical: permanent shutdown and custody shortfall continue; final restitution remains uncertain.

GoMining-linked wallets — High / Developing: no final GoMining incident confirmation or technical root cause.

Notional Finance — High: no final official post-mortem supersedes the independent exploit reconstruction.

Aquifer — High: no new verified recovery milestone.

Zilliqa — Critical: retail migration and compensation governance remain unresolved.

BitMart — Critical: September 9 remains the next key restructuring milestone.

Router Protocol — High: September 30 shutdown is unchanged; CEX-specific ROUTE deadlines remain developing.

Key Timeline

  • September 6: roughly 4,000 BTC exits the Liquid Federation.
  • September 7: Blockstream communicates on-chain that bridge nodes are patched; 3,400 BTC is returned.
  • September 7: Galaxy reports Coldcard Wave 3 movement has reached 97.09 BTC.
  • September 7: Cozy Finance protection-market exploit drains roughly 163,326 USDC.e and bridges funds minutes later.
  • September 7: revised Tectonic accounting places gross exploit transfers at approximately $120.375M.
  • September 7: Harmony proposes sunsetting its L1 and migrating ONE to Ethereum.
  • September 8: multiple Phemex spot and normal asset-access cutoffs are scheduled for 10:00 UTC.
  • September 9: KuCoin ends UOS/REACT support on specified networks; BitMart restructuring milestone.
  • September 10: Harmony users are urged to exit smart contracts before the migration/shutdown path advances.
  • September 11: Kraken disables deposits/trading for 21 assets.
  • September 17: first ZondaCrypto/BB Trade Estonia creditors’ meeting.
  • September 23: BitMEX trading closure.
  • September 30: Router wind-down and major regulatory deadlines.

FAQ

What is the biggest change from yesterday?

Liquid recovered 3,400 BTC from the actors behind the roughly 4,000 BTC peg-out incident. About 598.5 BTC remains unresolved.

Is the remaining 598.5 BTC an official whitehat bounty?

No formal bounty agreement was confirmed in the evidence reviewed today.

How much Coldcard Wave 3 bitcoin has moved?

Galaxy Research says 97.09 BTC, roughly 45% of that wave, has now moved.

Were Aave or Curve hacked in the Cozy Finance incident?

CEXVia found no evidence that Aave or Curve themselves were hacked in this event. Their markets were referenced by Cozy protection products; the exploit centered on Cozy’s protection/oracle settlement design.

Did Tectonic officially lose $120.4 million?

Not in that simple sense. $120.375M is Bitquery’s gross on-chain transfer estimate. Most attacker-controlled assets on Cronos were erased by the rollback, while roughly $8.3M had escaped to Ethereum. Final economic loss remains subject to reconciliation.

Is Harmony definitely shutting down on September 10?

No. The shutdown/migration plan is non-binding and no final chain shutdown date has been set. September 10 is the date before which users are being urged to exit smart contracts that cannot be migrated automatically.