Risk Radar

/ 6 developments

Crypto Risk Monitor — September 18, 2026

CEXVia tracks D’CENT App Wallet abnormal transfers and an estimated 2.0M XRP drain, OFAC sanctions on Iran-linked BitBank, SEC/CFTC digital-market relief, FCA P2P enforcement, and Revolut’s developing data-extortion case.

September 18, 2026Last updated 10:30 UTC9 min read

September 18 brings one major self-custody security event and five regulatory, enforcement or data-security developments that meet CEXVia’s threshold for independent coverage.

The highest-priority security event is D’CENT App Wallet. IoTrust, the manufacturer behind D’CENT, has acknowledged abnormal asset transfers involving the software App Wallet and says its initial investigation has not confirmed impact originating from D’CENT Hardware Wallets themselves. The key operational boundary is recovery-phrase reuse: users who imported or reused the same recovery phrase in the App Wallet and hardware environment may share exposure even if a hardware device itself was not technically compromised. D’CENT’s September 17 clarification further says the issue is tied to App Wallet versions earlier than v8.1.0: action is required for users who installed before November 5, 2025 and signed App Wallet transactions on the older version, while hardware-only users who never signed with App Wallet are not currently in the action group.

Independent XRP Ledger reconstruction estimates that on September 15 approximately 1,552 XRPL wallets were swept and 2,009,321 XRP moved through the attack sequence. Those figures are on-chain developing evidence, not a manufacturer-confirmed final loss. SlowMist separately lists an estimated loss of roughly $6.57 million and an unknown attack method. D’CENT has not yet published a final root cause.

Read the Detail: D’CENT App Wallet Abnormal Transfers

The most important sanctions development is the U.S. Treasury’s designation of Iran-linked BitBank. OFAC says the digital-asset exchange is controlled by sanctioned financier Babak Zanjani and was used to move payments associated with Iran’s state-linked networks. Treasury also says Zanjani used BitBank to facilitate hundreds of millions of dollars’ worth of Bitcoin transfers to the IRGC. The designation also covers BitBank developer Pishtaz Simorgh Electronic Trade Company and three Zanjani associates.

This entity must not be confused with bitbank, inc. in Japan. The Treasury action concerns the Iranian BitBank described in the sanctions notice.

Read the Detail: OFAC Sanctions Iran-Linked BitBank

U.S. market structure moved in the opposite direction: the SEC issued a temporary “Innovation Exemption” for Tokenized Securities Venues trading tokenized NMS stocks through permissioned automated market-maker liquidity pools. The relief is conditional and expires five years after publication. Tokenized NMS stock must provide the same rights and privileges as the equivalent traditional share class. Synthetic price-only tokens are not automatically covered by that standard.

Read the Detail: SEC Tokenized Stock Innovation Exemption

The CFTC also issued a staff no-action position for providers of “passive software.” Subject to specified conditions, staff will not recommend enforcement solely because a software provider facilitates user access to trading with registered FCMs, introducing brokers or designated contract markets without itself registering as an introducing broker or associated person. This is not blanket protection for custodial intermediaries, offshore perpetual platforms or every crypto application.

Read the Detail: CFTC Passive Software No-Action Position

In the UK, the FCA, HMRC and Metropolitan Police carried out a second coordinated enforcement operation against suspected unregistered peer-to-peer crypto businesses in London. The FCA says cease-and-desist letters were issued at three premises and that no P2P crypto trading business is currently registered with it in Britain. The event is an AML-registration enforcement action, not a blanket statement that every private P2P crypto transaction is illegal.

Read the Detail: UK FCA P2P Crypto Enforcement

Finally, the Revolut / Italian PEC incident has a material new development and therefore updates the existing URL rather than creating a duplicate page. Reporting says the hacker group “iamnotavillain” demanded $3 million in Monero (XMR) and threatened to sell customer files. Approximately 680 customers are reported affected; exposed material is said to include identity documents and transaction histories. Revolut says its internal systems were not breached and customer funds were not touched. Several details remain dependent on attacker claims and therefore remain Developing.

Read the updated Detail: Revolut / Italian PEC Data Exposure

① Today’s Highest-Priority Alerts

RiskEntityEventTimeLatest StatusEvidence TypeContinue MonitoringNew vs Previous Day
CriticalD’CENT App WalletAbnormal transfers / XRPL wallet sweepSep. 15–18Manufacturer confirms App Wallet issue; independent analysis estimates 1,552 XRPL wallets and 2,009,321 XRP swept; root cause unknownOfficial + On-chain + SecurityYesNew major self-custody incident
HighOFAC / Iran-linked BitBankSanctions designationSep. 17Exchange, developer and associates designated; U.S. blocking rules applyOfficialYesNew sanctions action
MediumSECTokenized NMS stock Innovation ExemptionSep. 17Conditional five-year relief for qualifying tokenized-stock venues and liquidity providersOfficialYesNew U.S. tokenization framework
MediumCFTCPassive software no-action positionSep. 17Conditional staff relief from IB/AP registration recommendations for qualifying software providersOfficialYesNew developer/intermediary relief
HighUK FCAP2P crypto enforcementSep. 10 / announced Sep. 17Three London premises targeted; cease-and-desist letters issued; no registered P2P crypto business in UKOfficial / MediaYesNew enforcement round
High / DevelopingRevolut / Italian PECData exposure and extortionSep. 17–18~$3M XMR ransom demand reported; ~680 customers affected; Revolut says internal systems not breachedMedia + CompanyYesNew ransom/extortion escalation
HighBybitICXUSDT perpetual delistingSep. 18 09:00 UTCOpen positions scheduled for automatic close using 30-minute average index priceOfficialYesHard deadline today
CriticalCoinExExchange shutdownOngoingReduce-only; Sep. 22, Sep. 29 and Dec. 22 deadlines unchangedOfficialYesNo material new change

② Exchange Exit / Shutdown / Withdrawal Risk

Bybit — High / Hard Deadline Today

The ICXUSDT perpetual contract is scheduled to be delisted at 09:00 UTC on September 18. Bybit’s announced methodology automatically closes remaining open positions using the average index price over the 30 minutes before delisting. Traders who want to control execution timing need to close before the forced event.

The L3/VIC spot delisting from September 17 remains active as a continuing asset-access issue; VIC withdrawals remain scheduled to close December 16.

CoinEx — Critical / Continuing

CoinEx remains inside its phased shutdown. September 22 is the next major milestone for futures and non-spot services. September 29 remains the spot shutdown and non-USDT original-asset withdrawal cutoff; December 22 remains the final withdrawal deadline.

BitMEX — Critical / Continuing

Final exchange closure remains scheduled for September 23. No new verified milestone today justifies a duplicate Detail URL.

Kraken UAE — High / Continuing

Seven delisted assets remain inside the September 15–25 forced-liquidation period.

③ Regulation and Licensing

OFAC BitBank Sanctions — High

The Treasury action immediately changes counterparty and sanctions-screening risk. U.S. persons generally cannot deal in property or interests in property of designated parties under U.S. jurisdiction, and entities owned 50% or more by blocked persons may also be blocked.

The identification of BitBank as part of Iran-linked crypto rails is also a reminder that exchange screening must cover ownership, beneficial-control relationships and sanctioned service networks, not only wallet addresses.

SEC Tokenized Stock Innovation Exemption — Medium

The SEC has created a conditional path for tokenized NMS-stock trading through qualifying Tokenized Securities Venues. This is market-structure relief, not blanket approval of all tokenized equities.

CFTC Passive Software Relief — Medium

The CFTC staff position reduces registration uncertainty for qualifying non-intermediary software, but only under stated conditions and in connection with registered U.S. derivatives-market infrastructure.

UK FCA P2P Enforcement — High

The September enforcement operation targeted suspected unregistered businesses under AML/counter-terrorist-financing rules. It should not be rewritten as a ban on all peer-to-peer crypto transfers between individuals.

④ Hacks / Vulnerabilities / Asset Loss

D’CENT App Wallet — Critical

The most important technical uncertainty is the root cause. IoTrust confirms abnormal App Wallet transfers but has not yet published the mechanism. Independent XRPL analysis can quantify the transaction pattern but cannot prove how keys were obtained.

The current on-chain estimate of 2,009,321 XRP across 1,552 XRPL wallets must therefore remain labelled Developing. SlowMist’s approximately $6.57 million loss estimate is likewise an external security estimate, not an official final loss figure.

The manufacturer’s separation between App Wallet and hardware-only use is critical. Users who never entered their hardware-wallet recovery phrase into the App Wallet are not currently described as affected by the manufacturer.

⑤ User Complaints / Operational Anomalies

Revolut / Italian PEC — High / Developing

The new $3 million XMR extortion demand materially changes the risk from passive data exposure to active coercion and potential data resale. Reported data includes identity documents and transaction histories, which can enable targeted phishing, fake law-enforcement contact, account-recovery abuse and physical-security threats against high-value crypto holders.

Revolut says funds were not touched and its internal systems were not compromised.

No other Community-only complaint cluster met the threshold for a new platform-wide High/Critical alert.

⑥ On-chain and Market Anomalies

D’CENT is today’s largest on-chain abnormal-transfer event. Independent reconstruction indicates highly automated two-wave sweeps, failed attempts followed by script correction, manual handling of larger wallets and subsequent movement toward exchange/bridge services.

Those behavioural details support the conclusion that this was an organised wallet-drain operation, but they do not establish the credential-compromise mechanism.

SEC tokenized-stock relief is the other major market-structure event: same-rights tokenized shares and concurrent underlying-stock trading halts become key controls as traditional equities move on-chain.

⑦ Watchlist

Date / WindowEventWhat CEXVia Is Watching
ImmediateD’CENTRoot cause, manufacturer final loss, compromised seed mechanism, exchange freezes
ImmediateRevolut / ItalyRansom deadline, official Italian findings, customer notification, follow-on attacks
Sep. 18 09:00 UTCBybit ICXUSDTAutomatic position closure and settlement price
Sep. 22CoinExFutures/non-spot shutdown
Sep. 23BitMEXFinal exchange closure
Sep. 25–29BalancerWind-down governance vote
Sep. 29CoinExSpot shutdown/non-USDT original-asset cutoff
Sep. 30UK FCACrypto authorisation gateway opens
Dec. 16Bybit VICWithdrawal cutoff
Dec. 22CoinExFinal withdrawal deadline

⑧ No New Development Today, but Still High Risk

Splash / OADA — Critical: recovery, liquidity restoration and compensation remain unresolved. XPR / MetalX — Critical: CEX-bound asset recovery and final accounting remain incomplete. Symbiosis — Critical: native Bitcoin Bridge and LP compensation remain unresolved. Liquid Network — Critical: staged bridge recovery remains incomplete. Nomic / Osmosis — Critical: governance/software execution of the allBTC re-peg plan remains pending. BitMart — Critical: no verified recovery percentage or withdrawal timetable.

FAQ

What is today’s highest-priority security incident?

D’CENT App Wallet abnormal transfers, because the manufacturer confirms an App Wallet issue while independent chain analysis indicates a large coordinated XRP wallet sweep.

Is 2,009,321 XRP an official D’CENT loss figure?

No. It is an independent on-chain estimate and must remain labelled Developing until D’CENT publishes final accounting.

Is Japanese exchange bitbank, inc. sanctioned?

The Treasury action concerns the Iran-linked BitBank identified in the OFAC notice, not Japanese bitbank, inc.

Did the SEC approve every tokenized stock product?

No. The Innovation Exemption is conditional and requires qualifying tokenized NMS stock to provide the same rights and privileges as the underlying traditional share class.

Did the UK ban all P2P crypto trading?

No. The FCA action targets suspected unregistered crypto businesses operating within the AML registration perimeter.

Was Revolut’s internal infrastructure breached?

Revolut says no; the reported attack path involves alleged abuse of an external Italian certified-email trust channel.