H1: Crypto Risk Monitor — September 8, 2026
September 8 brings a meaningful change in the global crypto-risk picture: the largest open bridge-reserve incident from yesterday has moved from near-total reserve displacement to partial recovery, while several other events have shifted in the opposite direction.
The most important update is Liquid Network. The actors who removed almost 4,000 BTC from the Liquid Federation have returned exactly 3,400 BTC after an on-chain exchange of messages with Blockstream. Roughly 598.5 BTC remains controlled by the actors. The return materially reduces the immediate reserve deficit, but it does not close the incident.
The deeper technical picture also changed. SideSwap said the original transaction involved 4,000 L-BTC being sent to its peg-out service and burned using a valid authorization, after which the Federation released approximately 3,996 BTC. SideSwap further said Blockstream identified a bug in the underlying Elements software that had allowed invalid L-BTC to be created. SideSwap says neither its system nor its Peg-out Authorization Key was compromised. Blockstream later sent an on-chain, PGP-signed message stating that bridge nodes had been patched, after which 3,400 BTC was returned.
This is a substantial recovery, but CEXVia does not classify the remaining 598.5 BTC as an agreed bounty. Public security commentary has suggested that possibility, but no formal bounty agreement has been confirmed in the evidence reviewed today. Liquid also has not yet announced full restoration of normal bridge and L-BTC services.
Update: Liquid Network 4,000 BTC Incident
A second major update concerns Coldcard. Galaxy Research says the Wave 3 operator has now moved 97.09 BTC, roughly 45% of that wave’s stolen bitcoin. This is a major escalation from the approximately 20.5 BTC movement tracked in the previous CEXVia update. The attacker has used both THORChain and CoinJoin activity and appears to be emptying the larger Wave 3 vaults first.
Across the broader Coldcard theft cluster, Galaxy says roughly 82% of the stolen bitcoin remains in original attacker-controlled addresses while approximately 18% has entered laundering or movement paths. Galaxy’s earlier high-confidence attribution placed the broader loss around 1,779 BTC; a newly identified possible victim vault could increase the total, but that additional attribution remains developing and is not used by CEXVia as a confirmed loss figure.
Update: Coldcard Hack and Attacker Fund Movement
A new protocol exploit also qualifies for a standalone Detail today: Cozy Finance on Optimism. Security researchers traced an attack involving approximately 163,326 USDC.e, with early alerts rounding the event to roughly $160,000–$170,000. The attacker appears to have acquired protection-market PTokens and then submitted undisputed “YES” answers to an UMA Optimistic Oracle path. The protection trigger did not independently verify that the underlying Aave v2 or Curve market had actually suffered the event being asserted, and payout eligibility was not tied to a pre-proposal holder snapshot.
This distinction is important: CEXVia found no evidence that Aave v2 or Curve themselves were hacked in this Cozy incident. They were the referenced protection markets. The exploit targeted the protection-market settlement logic and eligibility design.
Read the Detail: Cozy Finance Optimism Protection-Market Exploit
The Cronos / Tectonic incident also receives a major accounting revision. Bitquery’s on-chain reconstruction now places gross exploit transfers at approximately $120.375 million, spanning nine lending markets and 11 transfers. Cronos validators rolled the chain back by 10,961 blocks, erasing roughly $111 million in attacker-controlled assets that had remained on Cronos. About $8.3 million had already reached Ethereum and could not be removed by the rollback.
This does not mean Tectonic’s final economic loss is officially $120.4 million. That figure is an on-chain gross-transfer estimate. The rollback altered the final state, and final user loss, protocol bad debt and recovery accounting still require reconciliation. Tectonic has said it plans a phased reopening beginning with withdrawals and loan repayments, while deposits and borrowing remain paused.
Update: Cronos / Tectonic Exploit
A fifth high-priority event is Harmony. Harmony has proposed sunsetting its Layer 1 and migrating ONE to Ethereum as an ERC-20 token. The plan remains non-binding and no final last-block date has been fixed, so CEXVia does not describe the chain as already scheduled for final shutdown. However, Harmony is urging users to exit all smart contracts before September 10, 2026, because multisig safes, liquidity pools and on-chain applications cannot be migrated automatically under the proposed path.
The proposal follows the August Harmony exploit that created roughly 4 billion unauthorized ONE. Harmony’s migration concept would snapshot balances at the final block and allocate replacement Ethereum tokens to eligible addresses, while validator exits could begin from September 10 if the proposal progresses.
Read the Detail: Harmony Layer 1 Shutdown and ONE Migration Proposal
Regulation also produced a new event worth tracking. The Bangko Sentral ng Pilipinas (BSP) has published a draft policy direction that would impose a 12-month pause on new Operator of Payment System registrations while it reviews the licensing framework. The draft would also tighten merchant-acquisition arrangements involving regulated VASPs by requiring more direct relationships, enhanced due diligence, monitoring and risk-based transaction or settlement limits.
This is not yet a final rule. It remains a draft / consultation-stage regulatory proposal, and CEXVia therefore rates it Medium rather than treating the registration freeze as already in force.
Read the Detail: Philippines BSP Payment-Operator Freeze and VASP Controls
Today also contains a hard centralized-exchange deadline. Phemex has issued multiple notices for spot pairs being delisted at 10:00 UTC on September 8, including EUL/USDT, UAI/USDT, IN/USDT, EVAA/USDT, B2/USDT, Q/USDT, ZBCN/USDT, AIN/USDT, IDOL/USDT and GOOGLX/USDT. In those notices, deposits and normal withdrawals for the relevant token also stop at 10:00 UTC; withdrawal requests after the cutoff must be handled through customer service. CEXVia treats this as a Medium asset-access deadline rather than a solvency event.
① Today’s Highest-Priority Alerts
| Risk | Entity | Event | Time | Latest Status | Evidence | Continue Monitoring | New vs Previous Day |
|---|---|---|---|---|---|---|---|
| Critical | Liquid Network | Federation reserve / peg-out incident | Sep. 6–8 | 3,400 BTC returned; ~598.5 BTC remains; bridge nodes patched but normal services not confirmed restored | Official/On-chain/Media | Yes | Major partial recovery + technical clarification |
| Critical | Coldcard | Wave 3 stolen BTC laundering | Sep. 2–8 | 97.09 BTC moved, ~45% of Wave 3; THORChain + CoinJoin paths active | On-chain/Research/Media | Yes | Movement increased from ~20.5 BTC to 97.09 BTC |
| High | Cozy Finance | Protection-market exploit on Optimism | Sep. 7 | ~163,326 USDC.e drained; protection/oracle settlement logic abused; funds bridged rapidly | Security Research/On-chain | Yes | New exploit |
| Critical | Cronos / Tectonic | Revised exploit accounting and rollback | Aug. 30; revised Sep. 7–8 | ~$120.375M gross transfers; ~$111M erased by rollback; ~$8.3M escaped to Ethereum; phased reopening planned | On-chain/Protocol/Media | Yes | Material accounting revision |
| High | Harmony | Proposed Layer 1 shutdown / ONE migration | Sep. 7–10 | Non-binding proposal; ONE migration to Ethereum proposed; users urged to exit smart contracts before Sep. 10 | Project/Media | Yes | New chain-exit proposal |
| Medium | Philippines / BSP | OPS registration pause + VASP payment controls | Draft published Sep. 7 | 12-month OPS registration freeze proposed; VASP-linked merchant acquisition controls tightened if finalized | Regulator/Draft/Media | Yes | New regulatory proposal |
| Medium | Phemex | Multiple Sep. 8 spot delistings | Sep. 8 10:00 UTC | Multiple pairs and normal token deposits/withdrawals scheduled to stop; post-cutoff withdrawal via support | Official exchange | Yes | Hard deadline today |
| Critical | AscendEX | Claims portal / withdrawals | Ongoing | Portal launch still requires official confirmation; withdrawals remain suspended | Official | Yes | No material verified change |
② Exchange Exit, Shutdown and Withdrawal Risk
Phemex — Medium: Multiple asset-access cutoffs today
Phemex has separate official delisting notices that converge on the same September 8, 10:00 UTC cutoff.
The notices reviewed today include EUL, UAI, IN, EVAA, B2, Q, ZBCN, AIN, IDOL and GOOGLX spot pairs against USDT. At the cutoff:
- the spot pair is removed;
- open orders are automatically removed;
- deposits for the affected asset cease;
- normal withdrawals for the affected asset cease;
- later withdrawal requests must be submitted to customer service.
This is not evidence of platform insolvency. The user risk is narrower: loss of normal self-service asset access after the stated deadline.
AscendEX — Critical
No new verified recovery milestone changes the core risk today. The customer claims portal remains central to the recovery process, normal withdrawals remain suspended, and users still do not have a confirmed recovery percentage or repayment timetable.
CEXVia continues to update the same event URL rather than creating a duplicate page.
Kraken — High: September 11 approaching
Kraken’s next 21-asset delisting date is now three days away.
At September 11, 14:00 UTC, deposits and trading are scheduled to stop for the previously identified 21 assets. Withdrawals remain open until December 10, followed by a December 14–18 liquidation window.
The risk is asset access and forced execution, not Kraken solvency.
Orionx — Critical, no new verified recovery
Orionx remains in permanent shutdown with withdrawals suspended and a customer-asset custody shortfall under investigation. No new reliable recovery percentage was identified today.
Router Protocol — High, shutdown path unchanged
Router still plans to end operations by September 30. Exchange-specific ROUTE delisting and withdrawal deadlines remain the next practical user-risk layer.
③ Regulation and Licensing
Philippines / BSP — Medium, new draft
The BSP proposal would pause new OPS registrations for 12 months while the central bank reassesses its payment-system taxonomy and licensing framework.
For regulated VASPs, the more important operational change is the proposed merchant-acquisition perimeter:
- direct merchant relationships;
- enhanced due diligence;
- continuous monitoring;
- transaction and settlement limits;
- stronger merchant traceability;
- rejection or suspension of transactions where the merchant cannot be reliably identified.
Because the measure remains in draft form and is open to feedback, CEXVia does not treat these requirements as already effective.
Pakistan / PVARA — High, post-deadline operational issue
Pakistan’s September 5 NOC deadline has passed.
PVARA’s NOC application page today still states that online submission is temporarily unavailable and instructs applicants to submit by email. No public operator-by-operator post-deadline list was identified in today’s review.
This remains important because PVARA’s licensing framework says transitional operators that did not apply by the deadline must cease operations.
Poland / ZondaCrypto — High stored regulatory/creditor risk
BB Trade Estonia OÜ, the operator associated with ZondaCrypto, was declared bankrupt on August 27. Polish authorities have advised creditors to file claims with the trustee within the applicable two-month period, and the first creditors’ meeting is scheduled for September 17, 2026 in Tallinn.
This is not a new September 8 development, so it is not promoted to a new Detail today, but the creditor deadline and meeting remain material.
Australia ASIC — High approaching
The September 30 licensing-transition deadline remains on the Watchlist.
UK FCA — Medium approaching
The FCA’s crypto authorisation application window opens September 30, with the mandatory regime scheduled for October 2027.
④ Hacks, Vulnerabilities and Asset Loss
Liquid Network — Critical, improving but unresolved
The return of 3,400 BTC changes the loss profile materially.
However, the incident remains Critical because:
- ~598.5 BTC remains outside the Federation;
- normal peg functionality has not been confirmed restored;
- the complete Elements root-cause and remediation report is not yet public;
- the retained BTC has not been formally confirmed as a bounty;
- bridge accounting and 1:1 backing need final reconciliation.
Coldcard — Critical, laundering phase accelerating
Coldcard is no longer a mainly dormant-wallet incident.
Wave 3 movement has expanded to 97.09 BTC, and the attacker is actively using cross-chain and privacy-enhancing transaction paths.
Cozy Finance — High, new exploit
The Cozy exploit is smaller in dollar terms but technically important because it appears to exploit assumptions in protection-market event verification and payout eligibility.
Aave and Curve should not be described as hacked by this incident.
Tectonic — Critical, revised accounting
The new Bitquery accounting resolves a major ambiguity in gross transfer size but not final loss.
The important distinction is:
- gross exploit transfer: ~$120.375M;
- attacker assets erased by Cronos rollback: ~$111M;
- funds that escaped to Ethereum: ~$8.3M;
- final protocol/user economic loss: still developing.
⑤ User Complaints and Operational Anomalies
No new community-only complaint cluster met CEXVia’s platform-wide High/Critical publication threshold today.
Community claims about:
- the 598.5 BTC retained in the Liquid event being a “bounty”;
- AscendEX customer recovery percentages;
- unverified GoMining victim counts;
- final Coldcard total-loss expansions
are not upgraded to Confirmed without stronger evidence.
The distinction matters because several current incidents have active community speculation around numbers that are not yet official.
⑥ On-chain and Market Anomalies
Three on-chain developments dominate today.
Liquid: reserve recovery transaction
The 3,400 BTC return is the day’s largest positive on-chain movement. The remaining 598.5 BTC stays the primary unresolved reserve variable.
Coldcard: laundering path expands
Wave 3 has moved from an initial cross-chain test to materially broader fund movement, including CoinJoin activity.
Tectonic: gross vs escaped funds clarified
The revised chain-level reconstruction shows why gross exploit transfers cannot be used interchangeably with final realized attacker proceeds after a chain rollback.
Cozy also demonstrates a different type of on-chain risk: a relatively small but highly automated exploit where a protection-market settlement path can be converted into a payout within minutes and funds can be bridged before intervention.
⑦ Watchlist
| Date / Window | Event | What CEXVia Is Watching |
|---|---|---|
| Immediate | Liquid Network | Remaining ~598.5 BTC, formal bounty/return terms, bridge restart, L-BTC backing reconciliation |
| Immediate | Coldcard | Next Wave 3 vaults, THORChain/CoinJoin exits, CEX deposits, freezes/seizures |
| Immediate | Cozy Finance | Official post-mortem, remaining vulnerable markets, reimbursement, attacker destination |
| Immediate | Tectonic | Phased withdrawals, final bad debt, Ethereum-side attacker funds |
| Sep. 8 10:00 UTC | Phemex | Multiple spot-pair and normal withdrawal/deposit cutoffs |
| Sep. 9 08:00 UTC | KuCoin | UOS Ultra Mainnet and REACT Reactive Mainnet deposit/withdrawal support ends |
| Sep. 9 | BitMart | Restructuring / resumption roadmap milestone |
| Before Sep. 10 | Harmony | User exits from smart contracts / migration clarification |
| Sep. 11 14:00 UTC | Kraken | 21-asset deposits/trading disabled |
| Sep. 17 | ZondaCrypto / BB Trade Estonia | First creditors’ meeting |
| Sep. 23 | BitMEX | Trading closure |
| Sep. 30 | Router Protocol | Operations wind-down |
| Sep. 30 | ASIC | Australia licensing transition deadline |
| Sep. 30 | UK FCA | Crypto authorisation application window opens |
| Oct. 1 | Holdstation / UNO | Thailand access blocking |
| Dec. 10 15:00 UTC | Kraken | Withdrawal cutoff for 21 assets |
| Dec. 14–18 | Kraken | Forced liquidation window |
⑧ No New Development Today, but Still High Risk
AscendEX — Critical: withdrawals remain suspended; customer recovery framework remains incomplete.
Orionx — Critical: permanent shutdown and custody shortfall continue; final restitution remains uncertain.
GoMining-linked wallets — High / Developing: no final GoMining incident confirmation or technical root cause.
Notional Finance — High: no final official post-mortem supersedes the independent exploit reconstruction.
Aquifer — High: no new verified recovery milestone.
Zilliqa — Critical: retail migration and compensation governance remain unresolved.
BitMart — Critical: September 9 remains the next key restructuring milestone.
Router Protocol — High: September 30 shutdown is unchanged; CEX-specific ROUTE deadlines remain developing.
Key Timeline
- September 6: roughly 4,000 BTC exits the Liquid Federation.
- September 7: Blockstream communicates on-chain that bridge nodes are patched; 3,400 BTC is returned.
- September 7: Galaxy reports Coldcard Wave 3 movement has reached 97.09 BTC.
- September 7: Cozy Finance protection-market exploit drains roughly 163,326 USDC.e and bridges funds minutes later.
- September 7: revised Tectonic accounting places gross exploit transfers at approximately $120.375M.
- September 7: Harmony proposes sunsetting its L1 and migrating ONE to Ethereum.
- September 8: multiple Phemex spot and normal asset-access cutoffs are scheduled for 10:00 UTC.
- September 9: KuCoin ends UOS/REACT support on specified networks; BitMart restructuring milestone.
- September 10: Harmony users are urged to exit smart contracts before the migration/shutdown path advances.
- September 11: Kraken disables deposits/trading for 21 assets.
- September 17: first ZondaCrypto/BB Trade Estonia creditors’ meeting.
- September 23: BitMEX trading closure.
- September 30: Router wind-down and major regulatory deadlines.
FAQ
What is the biggest change from yesterday?
Liquid recovered 3,400 BTC from the actors behind the roughly 4,000 BTC peg-out incident. About 598.5 BTC remains unresolved.
Is the remaining 598.5 BTC an official whitehat bounty?
No formal bounty agreement was confirmed in the evidence reviewed today.
How much Coldcard Wave 3 bitcoin has moved?
Galaxy Research says 97.09 BTC, roughly 45% of that wave, has now moved.
Were Aave or Curve hacked in the Cozy Finance incident?
CEXVia found no evidence that Aave or Curve themselves were hacked in this event. Their markets were referenced by Cozy protection products; the exploit centered on Cozy’s protection/oracle settlement design.
Did Tectonic officially lose $120.4 million?
Not in that simple sense. $120.375M is Bitquery’s gross on-chain transfer estimate. Most attacker-controlled assets on Cronos were erased by the rollback, while roughly $8.3M had escaped to Ethereum. Final economic loss remains subject to reconciliation.
Is Harmony definitely shutting down on September 10?
No. The shutdown/migration plan is non-binding and no final chain shutdown date has been set. September 10 is the date before which users are being urged to exit smart contracts that cannot be migrated automatically.