September 17 has a broader risk mix than the previous two sessions. There is no single nine-figure exploit, but six developments are significant enough to stand on their own: one major UK regulatory clarification, two security incidents, one protocol wind-down proposal, one exchange asset-access deadline and one governance response to deteriorating token liquidity.
The highest regulatory priority is the UK FCA’s final cryptoasset perimeter guidance, published September 16. The FCA says the UK’s new crypto regime takes effect on October 25, 2027, while the authorisation gateway opens September 30, 2026 and the transitional application window closes February 28, 2027. Existing Money Laundering Regulations registrations and current permissions do not automatically convert into authorisation under the new regime. The guidance covers activities including issuing qualifying stablecoins, operating cryptoasset trading platforms, dealing or arranging deals, safeguarding cryptoassets and arranging staking. Overseas firms serving UK consumers can also fall within scope.
Read the Detail: UK FCA Cryptoasset Perimeter Guidance
The most important newly disclosed protocol exploit is Flamingo Finance / old Flamincome contracts. Security monitoring identified an attack in which the attacker used an approximately $18 million USDT flash loan, deposited Curve USDP LP into a strategy to inflate the VaultYUSDT share price, then redeemed liquid aUSDT. The attacker’s realised profit was approximately $345,900 USDT at disclosure. That figure is best treated as attacker profit / current extraction estimate rather than final protocol-wide loss until Flamingo publishes complete accounting.
Read the Detail: Flamingo / Flamincome Flash-Loan Exploit
A separate wallet-security event shows why multisig signatures alone are not enough when a powerful module is already authorised. On September 15, a Safe smart-account position containing roughly 2,900 rsETH, worth about $7.8 million, was extracted through an authorised custom module and an attacker-controlled Uniswap v4 hook. A generalized MEV searcher known as Yoink front-ran the original attacker and captured the main payout. Kelp DAO subsequently placed a temporary wallet-level pause on the address holding most of the rsETH while stating that Kelp contracts remained safe and rsETH remained fully backed. Security researchers described this as module-authorisation abuse, not a Safe core-contract or owner-key failure.
Read the Detail: Safe Module rsETH Drain
Balancer is considering an orderly protocol wind-down. The governance proposal calls for no new business development, an eventual transition of pools toward withdrawals-only operation, and distribution of a treasury stated to be at least $9 million to BAL holders through a multi-stage process if the proposal passes. The proposed Snapshot vote is September 25–29, with an October 30 withdrawals-only milestone and November 1 transition-team phase. Nothing has shut down yet.
Read the Detail: Balancer Orderly Wind-Down Proposal
At the CEX level, Bybit reaches a hard deadline today. L3USDT and VICUSDT spot trading is scheduled to end at 08:00 UTC on September 17, after deposits closed September 16. VIC withdrawals are scheduled to end December 16 at 08:00 UTC; Bybit says remaining VIC may later be converted into stablecoins on users’ behalf, but conversion is not guaranteed. Separately, Bybit announced that the ICXUSDT perpetual contract will be delisted September 18 at 09:00 UTC, with open positions automatically closed using an average index-price methodology.
Read the Detail: Bybit September Delisting Deadlines
Finally, Lido DAO is discussing a contingent CEX market-making mandate designed specifically to reduce the risk that LDO pairs deteriorate or are delisted for insufficient liquidity. If activated, the proposal allows up to $1.5 million equivalent of recallable LDO inventory, capped at 7.5 million LDO, plus up to 480,000 USDC in costs for a maximum 12-month mandate. No market maker or exchange is approved by the proposal itself, and activation would occur only if the Growth Committee determines that CEX liquidity is insufficient or likely to become insufficient.
Read the Detail: Lido LDO CEX Liquidity Risk Plan
① Today’s Highest-Priority Alerts
| Risk | Entity | Event | Time | Latest Status | Evidence Type | Continue Monitoring | New vs Previous Day |
|---|---|---|---|---|---|---|---|
| High | UK FCA | Final cryptoasset perimeter guidance | Sep. 16 | Gateway opens Sep. 30; existing registrations do not auto-convert; regime starts Oct. 25, 2027 | Official | Yes | New final regulatory guidance |
| High | Flamingo / Flamincome | VaultYUSDT share-price exploit | Sep. 16 | ~$18M USDT flash loan; ~$345.9K attacker profit; full accounting pending | Media + On-chain | Yes | New exploit |
| High | Safe wallet / rsETH | Authorised-module drain | Sep. 15–17 | ~2,900 rsETH extracted; MEV bot captured main payout; Kelp used wallet-level pause | Media + On-chain | Yes | Newly verified in current scan |
| High | Balancer | Orderly wind-down proposal | Sep. 14–17 | Vote Sep. 25–29; no shutdown executed; treasury ≥$9M cited | Official | Yes | New protocol-exit governance item |
| High | Bybit | L3/VIC spot delisting + ICX perp notice | Sep. 17–18 | L3/VIC trading ends today; VIC withdrawal cutoff Dec. 16; ICX perp auto-close Sep. 18 | Official | Yes | Hard deadline today + new derivative notice |
| Medium | Lido DAO | Contingent LDO CEX market-making mandate | Active | Up to $1.5M LDO + 480K USDC if activated; designed to reduce pair degradation/delisting risk | Official | Yes | New market-liquidity risk item |
| Critical | CoinEx | Exchange shutdown | Ongoing | Reduce-only; Sep. 22/29 and Dec. 22 deadlines unchanged | Official | Yes | No material change |
| Critical | BitMEX | Exchange wind-down | Ongoing | Final closure Sep. 23 | Official | Yes | No new independent Detail |
② Exchange Exit / Shutdown / Withdrawal Risk
Bybit — High
L3 and VIC spot trading ends at 08:00 UTC today. Deposits are already closed. VIC has a hard withdrawal cutoff on December 16 at 08:00 UTC. After that Bybit says VIC may be converted into stablecoins, but conversion is not guaranteed. ICXUSDT perpetual positions face automatic closure September 18 at 09:00 UTC using the average index price during the preceding 30 minutes.
CoinEx — Critical
No timetable change supersedes yesterday’s shutdown Detail. September 22 remains the futures/non-spot shutdown milestone, September 29 the spot/original-asset cutoff and December 22 the final withdrawal deadline.
BitMEX — Critical / Continuing
The exchange remains in its final wind-down cycle toward September 23 closure. No new verified fact today requires another URL.
③ Regulation and Licensing
UK FCA — High
The September 16 final perimeter guidance is the clearest new regulatory development. Firms must determine whether they need fresh authorisation or a variation of permission; existing MLR registrations and current permissions will not automatically become crypto permissions.
The September 30, 2026–February 28, 2027 gateway matters for firms seeking transitional treatment before the regime starts October 25, 2027. The FCA also plans another targeted consultation in October covering legal clarifications affecting stablecoins, proprietary trading/market making, technology providers, decentralised protocols, safeguarding arrangements and financial promotions.
④ Hacks / Vulnerabilities / Asset Loss
Flamingo / Flamincome — High
The exploit shows a vault-accounting failure amplified by flash liquidity. The reported $345,900 figure is attacker profit at disclosure time, not yet a final reconciled protocol loss.
Safe Module / rsETH — High
The Safe core multisig was not identified as compromised. The wallet had already authorised a custom module that could execute within the Safe context. The principal extraction was front-run by a separate MEV bot, which complicates custody and recovery but does not undo the victim’s loss of control.
⑤ User Complaints / Operational Anomalies
No new Community-only complaint cluster independently met the threshold for a platform-wide High/Critical alert. Claims that Bybit “unexpectedly froze” VIC are inaccurate because the deadline is official. Claims that Safe itself was hacked are also inconsistent with current security analysis.
⑥ On-chain and Market Anomalies
LDO liquidity is today’s clearest market-quality warning. Lido’s governance proposal exists because contributors see a plausible risk that declining trading volume and shallow CEX books could increase pair-maintenance and delisting risk.
Balancer creates a separate liquidity-exit question. If approved, pausable pools would transition toward withdrawals-only status and the protocol would move to a minimal exit stack.
⑦ Watchlist
| Date / Window | Event | What CEXVia Is Watching |
|---|---|---|
| Sep. 17 08:00 UTC | Bybit L3/VIC | Spot trading/Convert closure |
| Sep. 18 09:00 UTC | Bybit ICXUSDT | Perpetual auto-close methodology and execution |
| Sep. 22 | CoinEx | Futures/non-spot shutdown |
| Sep. 23 | BitMEX | Final exchange closure |
| Sep. 25–29 | Balancer | Snapshot wind-down vote |
| Sep. 29 | CoinEx | Spot shutdown/non-USDT original-asset cutoff |
| Sep. 30 | UK FCA | Crypto authorisation gateway opens |
| Oct. 30 | Balancer | Proposed withdrawals-only milestone if approved |
| Dec. 16 | Bybit VIC | Withdrawal cutoff |
| Dec. 22 | CoinEx | Final withdrawal deadline |
⑧ No New Development Today, but Still High Risk
Splash / OADA — Critical: recovery, liquidity restoration and compensation remain unresolved. XPR / MetalX — Critical: CEX-bound recovery and final accounting remain incomplete. Symbiosis — Critical: native Bitcoin Bridge and LP compensation remain unresolved. Liquid Network — Critical: staged bridge recovery remains incomplete. Nomic / Osmosis — Critical: governance/software execution of the allBTC re-peg plan remains pending. BitMart — Critical: no verified recovery percentage or withdrawal timetable.
FAQ
What is the most important new regulatory change today?
The UK FCA’s final perimeter guidance, because firms now have a concrete authorisation gateway and confirmation that existing registrations will not automatically convert.
How much did the Flamingo attacker make?
Security monitoring reported approximately $345,900 USDT in attacker profit at disclosure.
Was Safe’s core multisig hacked?
Current security analysis says no. The incident involved an already-authorised custom module.
Is Balancer shutting down today?
No. An orderly wind-down is proposed and still requires governance approval.
Which Bybit assets hit a deadline today?
L3 and VIC spot trading and Convert support are scheduled to end at 08:00 UTC on September 17.
Is Lido already paying a market maker?
No. The governance proposal is contingent and does not approve a specific market maker or require immediate deployment.