Risk Radar

/ 6 developments

Crypto Risk Monitor — September 17, 2026

CEXVia tracks the UK FCA’s final crypto perimeter guidance, a Flamingo/Flamincome flash-loan exploit, a $7.8M Safe-module rsETH drain, Balancer’s proposed wind-down, Bybit delisting deadlines and Lido’s CEX-liquidity risk plan.

September 17, 2026Last updated 10:30 UTC8 min read

September 17 has a broader risk mix than the previous two sessions. There is no single nine-figure exploit, but six developments are significant enough to stand on their own: one major UK regulatory clarification, two security incidents, one protocol wind-down proposal, one exchange asset-access deadline and one governance response to deteriorating token liquidity.

The highest regulatory priority is the UK FCA’s final cryptoasset perimeter guidance, published September 16. The FCA says the UK’s new crypto regime takes effect on October 25, 2027, while the authorisation gateway opens September 30, 2026 and the transitional application window closes February 28, 2027. Existing Money Laundering Regulations registrations and current permissions do not automatically convert into authorisation under the new regime. The guidance covers activities including issuing qualifying stablecoins, operating cryptoasset trading platforms, dealing or arranging deals, safeguarding cryptoassets and arranging staking. Overseas firms serving UK consumers can also fall within scope.

Read the Detail: UK FCA Cryptoasset Perimeter Guidance

The most important newly disclosed protocol exploit is Flamingo Finance / old Flamincome contracts. Security monitoring identified an attack in which the attacker used an approximately $18 million USDT flash loan, deposited Curve USDP LP into a strategy to inflate the VaultYUSDT share price, then redeemed liquid aUSDT. The attacker’s realised profit was approximately $345,900 USDT at disclosure. That figure is best treated as attacker profit / current extraction estimate rather than final protocol-wide loss until Flamingo publishes complete accounting.

Read the Detail: Flamingo / Flamincome Flash-Loan Exploit

A separate wallet-security event shows why multisig signatures alone are not enough when a powerful module is already authorised. On September 15, a Safe smart-account position containing roughly 2,900 rsETH, worth about $7.8 million, was extracted through an authorised custom module and an attacker-controlled Uniswap v4 hook. A generalized MEV searcher known as Yoink front-ran the original attacker and captured the main payout. Kelp DAO subsequently placed a temporary wallet-level pause on the address holding most of the rsETH while stating that Kelp contracts remained safe and rsETH remained fully backed. Security researchers described this as module-authorisation abuse, not a Safe core-contract or owner-key failure.

Read the Detail: Safe Module rsETH Drain

Balancer is considering an orderly protocol wind-down. The governance proposal calls for no new business development, an eventual transition of pools toward withdrawals-only operation, and distribution of a treasury stated to be at least $9 million to BAL holders through a multi-stage process if the proposal passes. The proposed Snapshot vote is September 25–29, with an October 30 withdrawals-only milestone and November 1 transition-team phase. Nothing has shut down yet.

Read the Detail: Balancer Orderly Wind-Down Proposal

At the CEX level, Bybit reaches a hard deadline today. L3USDT and VICUSDT spot trading is scheduled to end at 08:00 UTC on September 17, after deposits closed September 16. VIC withdrawals are scheduled to end December 16 at 08:00 UTC; Bybit says remaining VIC may later be converted into stablecoins on users’ behalf, but conversion is not guaranteed. Separately, Bybit announced that the ICXUSDT perpetual contract will be delisted September 18 at 09:00 UTC, with open positions automatically closed using an average index-price methodology.

Read the Detail: Bybit September Delisting Deadlines

Finally, Lido DAO is discussing a contingent CEX market-making mandate designed specifically to reduce the risk that LDO pairs deteriorate or are delisted for insufficient liquidity. If activated, the proposal allows up to $1.5 million equivalent of recallable LDO inventory, capped at 7.5 million LDO, plus up to 480,000 USDC in costs for a maximum 12-month mandate. No market maker or exchange is approved by the proposal itself, and activation would occur only if the Growth Committee determines that CEX liquidity is insufficient or likely to become insufficient.

Read the Detail: Lido LDO CEX Liquidity Risk Plan

① Today’s Highest-Priority Alerts

RiskEntityEventTimeLatest StatusEvidence TypeContinue MonitoringNew vs Previous Day
HighUK FCAFinal cryptoasset perimeter guidanceSep. 16Gateway opens Sep. 30; existing registrations do not auto-convert; regime starts Oct. 25, 2027OfficialYesNew final regulatory guidance
HighFlamingo / FlamincomeVaultYUSDT share-price exploitSep. 16~$18M USDT flash loan; ~$345.9K attacker profit; full accounting pendingMedia + On-chainYesNew exploit
HighSafe wallet / rsETHAuthorised-module drainSep. 15–17~2,900 rsETH extracted; MEV bot captured main payout; Kelp used wallet-level pauseMedia + On-chainYesNewly verified in current scan
HighBalancerOrderly wind-down proposalSep. 14–17Vote Sep. 25–29; no shutdown executed; treasury ≥$9M citedOfficialYesNew protocol-exit governance item
HighBybitL3/VIC spot delisting + ICX perp noticeSep. 17–18L3/VIC trading ends today; VIC withdrawal cutoff Dec. 16; ICX perp auto-close Sep. 18OfficialYesHard deadline today + new derivative notice
MediumLido DAOContingent LDO CEX market-making mandateActiveUp to $1.5M LDO + 480K USDC if activated; designed to reduce pair degradation/delisting riskOfficialYesNew market-liquidity risk item
CriticalCoinExExchange shutdownOngoingReduce-only; Sep. 22/29 and Dec. 22 deadlines unchangedOfficialYesNo material change
CriticalBitMEXExchange wind-downOngoingFinal closure Sep. 23OfficialYesNo new independent Detail

② Exchange Exit / Shutdown / Withdrawal Risk

Bybit — High

L3 and VIC spot trading ends at 08:00 UTC today. Deposits are already closed. VIC has a hard withdrawal cutoff on December 16 at 08:00 UTC. After that Bybit says VIC may be converted into stablecoins, but conversion is not guaranteed. ICXUSDT perpetual positions face automatic closure September 18 at 09:00 UTC using the average index price during the preceding 30 minutes.

CoinEx — Critical

No timetable change supersedes yesterday’s shutdown Detail. September 22 remains the futures/non-spot shutdown milestone, September 29 the spot/original-asset cutoff and December 22 the final withdrawal deadline.

BitMEX — Critical / Continuing

The exchange remains in its final wind-down cycle toward September 23 closure. No new verified fact today requires another URL.

③ Regulation and Licensing

UK FCA — High

The September 16 final perimeter guidance is the clearest new regulatory development. Firms must determine whether they need fresh authorisation or a variation of permission; existing MLR registrations and current permissions will not automatically become crypto permissions.

The September 30, 2026–February 28, 2027 gateway matters for firms seeking transitional treatment before the regime starts October 25, 2027. The FCA also plans another targeted consultation in October covering legal clarifications affecting stablecoins, proprietary trading/market making, technology providers, decentralised protocols, safeguarding arrangements and financial promotions.

④ Hacks / Vulnerabilities / Asset Loss

Flamingo / Flamincome — High

The exploit shows a vault-accounting failure amplified by flash liquidity. The reported $345,900 figure is attacker profit at disclosure time, not yet a final reconciled protocol loss.

Safe Module / rsETH — High

The Safe core multisig was not identified as compromised. The wallet had already authorised a custom module that could execute within the Safe context. The principal extraction was front-run by a separate MEV bot, which complicates custody and recovery but does not undo the victim’s loss of control.

⑤ User Complaints / Operational Anomalies

No new Community-only complaint cluster independently met the threshold for a platform-wide High/Critical alert. Claims that Bybit “unexpectedly froze” VIC are inaccurate because the deadline is official. Claims that Safe itself was hacked are also inconsistent with current security analysis.

⑥ On-chain and Market Anomalies

LDO liquidity is today’s clearest market-quality warning. Lido’s governance proposal exists because contributors see a plausible risk that declining trading volume and shallow CEX books could increase pair-maintenance and delisting risk.

Balancer creates a separate liquidity-exit question. If approved, pausable pools would transition toward withdrawals-only status and the protocol would move to a minimal exit stack.

⑦ Watchlist

Date / WindowEventWhat CEXVia Is Watching
Sep. 17 08:00 UTCBybit L3/VICSpot trading/Convert closure
Sep. 18 09:00 UTCBybit ICXUSDTPerpetual auto-close methodology and execution
Sep. 22CoinExFutures/non-spot shutdown
Sep. 23BitMEXFinal exchange closure
Sep. 25–29BalancerSnapshot wind-down vote
Sep. 29CoinExSpot shutdown/non-USDT original-asset cutoff
Sep. 30UK FCACrypto authorisation gateway opens
Oct. 30BalancerProposed withdrawals-only milestone if approved
Dec. 16Bybit VICWithdrawal cutoff
Dec. 22CoinExFinal withdrawal deadline

⑧ No New Development Today, but Still High Risk

Splash / OADA — Critical: recovery, liquidity restoration and compensation remain unresolved. XPR / MetalX — Critical: CEX-bound recovery and final accounting remain incomplete. Symbiosis — Critical: native Bitcoin Bridge and LP compensation remain unresolved. Liquid Network — Critical: staged bridge recovery remains incomplete. Nomic / Osmosis — Critical: governance/software execution of the allBTC re-peg plan remains pending. BitMart — Critical: no verified recovery percentage or withdrawal timetable.

FAQ

What is the most important new regulatory change today?

The UK FCA’s final perimeter guidance, because firms now have a concrete authorisation gateway and confirmation that existing registrations will not automatically convert.

How much did the Flamingo attacker make?

Security monitoring reported approximately $345,900 USDT in attacker profit at disclosure.

Was Safe’s core multisig hacked?

Current security analysis says no. The incident involved an already-authorised custom module.

Is Balancer shutting down today?

No. An orderly wind-down is proposed and still requires governance approval.

Which Bybit assets hit a deadline today?

L3 and VIC spot trading and Convert support are scheduled to end at 08:00 UTC on September 17.

Is Lido already paying a market maker?

No. The governance proposal is contingent and does not approve a specific market maker or require immediate deployment.