Risk Radar

/ 6 developments

Crypto Risk Monitor — September 21, 2026

CEXVia tracks the SingularityNET/ASI bridge key compromise, ZetaChain’s approved L1 wind-down, Polymarket’s newly disclosed fraud and account-takeover incidents, Haruko’s institutional cyberattack, Bybit Brazil forced liquidations, and Coinbase’s pending U.S. single-stock perpetual framework.

September 21, 2026Last updated 10:30 UTC10 min read

September 21 is led by a fast-expanding key-compromise incident across the Artificial Superintelligence ecosystem. The same attack cluster first drained 8.7 million FET from a Fetch.ai token-conversion contract, then received a 408.5 million NTX mint and subsequently minted 260 million AGIX and 53.838 million WMTx on Ethereum. Independent blockchain analysis also links unauthorized CGV issuance to the cluster and estimates roughly 2.3 billion newly created token units across the affected ecosystem. The most important accounting boundary is that unauthorized minted supply is not the same as realized economic loss. Security monitors valued one Ethereum holdings snapshot at roughly $16.77 million, while the directly drained FET was worth about $1.5–$1.6 million at the time. Fetch.ai says its own core contracts remain safe and that the attack primarily targeted SingularityNET bridge infrastructure; World Mobile confirmed unauthorized WMTx minting and is working on exchange freezes and revoking mint authority.

Read the Detail: ASI / SingularityNET Bridge Key Compromise

The second major structural event is ZetaChain’s L1 wind-down. Proposal 68 passed with 99.4% support and 58% participation, above the 40% quorum. The proposal authorizes a one-for-one migration of native ZETA to Solana as an SPL token while keeping total supply and existing vesting schedules unchanged. However, the chain is not shutting down immediately. A second governance proposal must still specify the snapshot block, shutdown block, claim process, connected-chain withdrawals and exchange coordination. ZETA on Ethereum and BNB Chain is outside Proposal 68’s conversion scope.

Read the Detail: ZetaChain L1 Shutdown and Solana Migration

A newly disclosed Polymarket U.S. fraud and account-security history also reaches the independent-detail threshold. A Wall Street Journal investigation reported that fraudsters attempted to move at least $10 million through the regulated U.S. platform in February using stolen debit cards. The report did not establish how much of the attempted fraud succeeded, and most attempted deposits reportedly failed. A separate late-July account-registration flaw reportedly let attackers use stolen identity data to take over nearly 500 users’ accounts without their existing usernames or passwords. Polymarket says it strengthened controls, will cover affected-user losses from the account incident, and an outside investigation by Sullivan & Cromwell concluded it complied with regulations. The CFTC has not publicly confirmed or denied the reported investigation.

Read the Detail: Polymarket U.S. Fraud and Account-Takeover Risk

CEXVia is also adding Haruko to independent coverage. The institutional crypto infrastructure provider suffered a targeted cyberattack affecting 15 clients. Messages reviewed by reporting say an attacker exploited a vulnerability in a Haruko process, stole a user-access token and read information in process memory that could include read-only exchange API details and trading data. Some smaller clients may have lost funds, but no reconciled loss amount has been published. Haruko says it fixed the vulnerability, refreshed server-side secrets and plans a technical post-mortem. The event is important because “read-only API” exposure can still become financially dangerous when surrounding controls such as IP whitelists are weak.

Read the Detail: Haruko Institutional Crypto Cyberattack

At the CEX level, Bybit Brazil reaches a hard compliance-migration deadline today. Under Bybit’s announced local-entity transition, restricted open positions that remain after September 21 are force-liquidated at prevailing market prices, unsupported fiat is automatically converted to USDT and non-compliant coupons/bonuses are forfeited. Eligible Brazilian residents and enterprise users are then scheduled to migrate to the local Brazilian Bybit entity on September 24. This is jurisdiction-specific regulatory migration, not a global Bybit solvency or shutdown event.

Read the Detail: Bybit Brazil Forced Liquidation and Local-Entity Migration

Finally, U.S. derivatives market structure is moving closer to crypto-style equity perpetuals. Coinbase Derivatives filed rules for cash-settled futures on individual U.S. equities and ETF shares, including perpetual single-stock futures, with the SEC on September 18 and concurrently submitted the proposal to the CFTC for approval. The SEC notice states that the CFTC has not yet approved the proposal. The contracts would be security futures products with no fixed expiration and cash settlement rather than share delivery. This is a meaningful market-structure development, but it remains a pending regulatory framework—not a live U.S. product.

Read the Detail: Coinbase Single-Stock Perpetual Futures Filing

① Today’s Highest-Priority Alerts

RiskEntityEventTimeLatest StatusEvidence TypeContinue MonitoringNew vs Previous Day
CriticalSingularityNET / Fetch.ai / NuNet / World MobileBridge/signing-key compromise and unauthorized mintingSep. 19–218.7M FET drained; 408.5M NTX, 260M AGIX and 53.838M WMTx minted in linked cluster; bridges/conversions restricted; final realized loss unresolvedProject statements + On-chain/SecurityYesNew major multi-project incident
HighZetaChainL1 wind-down / ZETA migration to SolanaSep. 20Proposal 68 passed 99.4%; second proposal still required before snapshot/shutdownGovernance + MediaYesNew confirmed chain-exit decision
High / DevelopingPolymarket U.S.Stolen-card fraud + account takeover disclosureNewly disclosed Sep. 20≥$10M attempted fraud reported; separate near-500-account incident; exact losses partly unknownMajor Media + Company statementYesNew historical incidents disclosed
HighHarukoInstitutional infrastructure cyberattackSep. 17–2115 clients affected; API/trading data exposed; some funds may be lost; vulnerability fixed; post-mortem pendingCompany messages via MediaYesNew to CEXVia coverage / active incident
HighBybit BrazilRegulatory migration / forced liquidationSep. 21Restricted positions force-liquidated; unsupported fiat converted to USDT; local-entity migration Sep. 24OfficialYesHard deadline reached today
MediumCoinbase DerivativesU.S. single-stock perpetual security futuresFiled Sep. 18SEC rule filing effective for notice purposes; CFTC approval still pendingOfficial SECYesNew market-structure filing
CriticalCoinExExchange shutdownOngoingSep. 22 futures/non-spot shutdown remains next deadlineOfficialYesNo material new change
HighBlink WalletCustodial-account incidentOngoingServices restored and patch verified; affected accounts to be made whole; attack path/post-mortem still pendingProject-reported / MediaYesRecovery phase; no new root cause

② Exchange Exit / Shutdown / Withdrawal Risk

Bybit Brazil — High / Deadline Today

September 21 is the fixed date for forced closure of restricted open positions under Bybit’s Brazil migration program. The platform says those positions will be closed at prevailing market prices. Unsupported fiat that users have not converted themselves is scheduled for automatic conversion to USDT, and non-compliant coupons/bonuses are forfeited.

The rule applies to affected Brazilian users and enterprise/KYB accounts within the announced migration framework. It is not a platform-wide Bybit liquidation event.

The next milestone is September 24, when eligible users are scheduled to be migrated to the local Brazilian entity and their main account becomes a Standard Account under that entity.

CoinEx — Critical / Deadline Tomorrow

September 22 is the next major CoinEx shutdown milestone. Futures and most non-spot services are scheduled to end, with remaining futures positions subject to platform settlement. September 29 remains the spot shutdown and original-form non-USDT withdrawal cutoff, while December 22 remains the final general withdrawal deadline.

BitMEX — Critical / Continuing

Final exchange closure remains scheduled for September 23. No newly verified fact today warrants a duplicate Detail URL.

Digitra — High / Watchlist

Digitra’s previously announced platform closure is approaching its September 28 crypto-withdrawal deadline. Crypto remaining after the cutoff is scheduled for compulsory conversion to USDT beginning September 29, with converted balances withdrawable until October 19.

③ Regulation and Licensing

Coinbase Derivatives — Medium Market-Structure Change

The September 18 SEC filing creates a joint SEC–CFTC path for perpetual security futures on individual equities and ETFs. The proposal is important because it imports a crypto-native no-expiry contract design into regulated U.S. security futures.

The regulatory boundary is precise: the SEC filing is public, but the SEC notice explicitly says the CFTC has not yet approved the proposed rule change. No customer should treat the contracts as live based on the filing alone.

Polymarket — High / Developing Compliance Risk

The newly disclosed fraud history raises AML, payments, identity-verification and account-recovery questions at a CFTC-regulated U.S. prediction-market platform. Polymarket says controls have since been strengthened, while an outside legal investigation reportedly found regulatory compliance. A reported CFTC investigation remains unconfirmed by the agency itself.

Ongoing U.S. Rulemaking

The CFTC crypto-market prerule RIN 3038-AF80 remains pending at OIRA with no public substantive rule text. The SEC’s tokenized-stock Innovation Exemption remains active under its separate conditional framework.

④ Hacks / Vulnerabilities / Asset Loss

ASI / SingularityNET bridge cluster — Critical

This is today’s most consequential security incident because the same cluster appears to combine a direct asset drain with unauthorized supply creation across several connected projects.

The cleanest confirmed/developing separation is:

  • roughly 8.7M FET was drained from a Fetch.ai conversion contract;
  • 408.5M NTX was minted from the NuNet deployer account into the same cluster;
  • security monitoring later identified 260M AGIX and 53.838M WMTx minted without authorization on Ethereum;
  • independent analysis links additional CGV issuance to the cluster;
  • an Ethereum holdings snapshot was valued around $16.77M, but that figure is holdings/minted inventory—not realized proceeds.

Fetch.ai says its own core contracts remain safe and that the exploit primarily targeted SingularityNET bridge infrastructure. World Mobile separately confirmed unauthorized WMTx minting.

Haruko — High

Haruko shows a different infrastructure failure mode: a third-party institutional platform can expose API and trading intelligence even when the customer’s own login credentials are not breached. The incident reinforces the value of exchange-side IP whitelisting and scoped API permissions.

⑤ User Complaints / Operational Anomalies

Polymarket account takeover — High / Developing

The late-July account-registration issue is particularly serious because reporting says attackers could use stolen personal information such as Social Security numbers to access an existing customer account without knowing the existing username or password. Roughly 500 accounts were reportedly targeted.

The amount stolen was described as small but not quantified. Polymarket reportedly said it would cover affected-user losses.

Blink has restored services after the custodial-account incident and says the vulnerability was fixed and verified. A few dozen custodial accounts were affected and are to be made whole; non-custodial wallets were not affected. The total amount stolen and exact attack path remain undisclosed.

No additional Community-only complaint cluster met CEXVia’s High/Critical threshold today.

⑥ On-chain and Market Anomalies

The ASI/SingularityNET event is today’s largest token-supply anomaly. Unauthorized token minting broke supply assumptions across AGIX, NTX, WMTx and potentially CGV even where the attacker could not immediately sell the full minted amount.

This distinction matters: supply integrity can be destroyed without equivalent cash extraction. Thin liquidity limits realized theft but can still cause severe token-price collapse, exchange suspensions and accounting uncertainty.

ZetaChain creates a different market-structure risk: a chain-level migration can fragment ZETA liquidity between native ZetaChain, future Solana SPL balances, and out-of-scope Ethereum/BNB Chain representations until the second proposal defines the swap process.

⑦ Watchlist

Date / WindowEventWhat CEXVia Is Watching
ImmediateASI / SingularityNETKey revocation, bridge accounting, exchange freezes, unauthorized supply treatment, recovery
ImmediatePolymarketCFTC posture, fraud controls, user reimbursements, account-security remediation
ImmediateHarukoTechnical post-mortem, client losses, secret rotation, customer/API remediation
ImmediateZetaChainSecond governance proposal, snapshot block, shutdown block, exchange swap support
Sep. 21Bybit BrazilForced-liquidation execution / unsupported-fiat conversion
Sep. 22CoinExFutures/non-spot shutdown
Sep. 23BitMEXFinal exchange closure
Sep. 24Bybit BrazilLocal-entity migration
Sep. 25–29BalancerWind-down governance vote
Sep. 28DigitraCrypto withdrawal deadline
Sep. 29CoinExSpot shutdown / original-asset cutoff
Sep. 30UK FCACrypto authorisation gateway opens
Oct. 19DigitraConverted-balance withdrawal deadline
Dec. 22CoinExFinal withdrawal deadline

⑧ No New Development Today, but Still High Risk

D’CENT App Wallet — Critical: root cause and complete multi-chain loss accounting remain unresolved. Nostra — Critical: money-market reconciliation, final bad debt and reopening remain pending. Splash / OADA — Critical: recovery, liquidity restoration and compensation remain unresolved. XPR / MetalX — Critical: CEX-bound recovery and final accounting remain incomplete. Symbiosis — Critical: native Bitcoin Bridge and LP compensation remain unresolved. Liquid Network — Critical: staged bridge recovery remains incomplete. BitMart — Critical: no verified recovery percentage or withdrawal timetable.

FAQ

What is today’s highest-priority crypto security event?

The linked SingularityNET/ASI bridge-key compromise, because it combines a direct FET drain with large unauthorized mints across several ecosystem tokens.

Is $16.77 million the confirmed amount stolen from SingularityNET?

No. That figure describes one security firm’s snapshot of the attacker cluster’s Ethereum holdings. Unauthorized minted tokens and wallet holdings are not the same as realized economic proceeds.

Is ZetaChain already shut down?

No. Proposal 68 authorizes the migration and wind-down, but a second proposal must define the snapshot, shutdown block and claim process.

Did Polymarket lose $10 million?

Not necessarily. Reporting says fraudsters attempted at least $10 million in stolen-card fraud; the report did not establish how much succeeded, and most attempts reportedly failed.

Does Bybit’s September 21 liquidation affect every user?

No. It applies to restricted positions in the announced Brazil regulatory-migration scope.

Are Coinbase single-stock perpetual futures live in the U.S.?

No. Coinbase Derivatives filed the framework, but the SEC notice says CFTC approval is still pending.