9 月 21 日今天最重要的安全事件,是 Artificial Superintelligence(ASI)生态相关 bridge / signing key compromise 持续扩大。
同一 attacker cluster 先从 Fetch.ai 的 Ethereum token-conversion contract 中取走约 870 万 FET,随后接收 4.085 亿 NTX unauthorized mint;9 月 20 日又出现 2.6 亿 AGIX 与 5,383.8 万 WMTx 的 unauthorized mint。独立链上研究还把 CGV 的异常 supply 与同一 cluster 关联起来,并估算整个事件涉及约 23 亿枚 newly created token units。
这里最容易写错的是“损失金额”。Unauthorized mint 的面值、attacker wallet 当前持仓、以及 attacker 真正已经 cash out 的金额是三件不同的事。PeckShield 等 security monitor 曾把 attacker cluster 的一组 Ethereum holdings 估值在约 1,677 万美元,但这不是 confirmed realized loss;目前最清晰的 direct cash event 仍是被 drain 的约 870 万 FET,事件发生时价值约 150–160 万美元。
Fetch.ai 表示自身 core contracts 没有受到威胁,并把主要攻击面指向 SingularityNET Ethereum–Cardano bridge;World Mobile 也确认 WMTx 在 Ethereum 被 unauthorized mint,并正与 exchange / security partners 处理 freeze 和 mint-authority revocation。
详细页:ASI / SingularityNET Bridge Key Compromise
第二条结构性事件是 ZetaChain L1 正式进入退出路径。Proposal 68 以 99.4% 赞成票、58% participation 通过,超过 40% quorum。提案授权 native ZETA 按 1:1 转为 Solana 上 native SPL token,总 supply 和既有 vesting schedule 保持不变。
但不能写成“ZetaChain 今天已经关链”。Proposal 68 只是批准方向;还需要第二个 governance proposal 决定 snapshot block、shutdown block、claim process、connected-chain asset withdrawal 以及 exchange swap coordination。Ethereum / BNB Chain 上的 ZETA 也明确不在 Proposal 68 的 1:1 native conversion scope 内。
详细页:ZetaChain L1 Shutdown and Solana Migration
第三条是 Polymarket U.S. fraud / account security。WSJ 新调查把两起此前未充分公开的事件带到台前:2 月份 fraudsters 使用 stolen debit cards,试图通过 Polymarket U.S. 平台完成至少 1,000 万美元 fraud;但报道没有证明这 1,000 万美元全部成功,反而称大部分 attempted deposits failed。另一条独立 July incident 涉及一个 account-registration flaw,攻击者据称只需要 stolen personal information(例如 SSN),就能在不知道原 username/password 的情况下接管接近 500 个用户账户以及其 linked bank/debit-card access。
Polymarket 表示之后已经加强 controls,account incident 的用户损失会覆盖;WSJ 报道还称 Sullivan & Cromwell 的 internal investigation 认为公司遵守 regulations。报道中的 CFTC investigation 目前 agency 自身没有确认或否认,因此必须维持 Media / Developing。
详细页:Polymarket U.S. Fraud and Account-Takeover Risk
第四条是 Haruko institutional infrastructure breach。Haruko 为 hedge funds / institutional crypto firms 提供 portfolio、risk、trade-data infrastructure。此次 targeted cyberattack 影响 15 个 client。根据公司 CTO 给客户的信息,attacker 利用 Haruko 某个 process 的 vulnerability,取得 user-access token,并读取 process memory;其中可能包括 read-only exchange API details 和 trading data。部分 smaller funds 据知情人士称有少量资金损失,但 Haruko 尚未公布 reconciled amount。
Haruko 表示 vulnerability 已修复、server-side secrets 已 refresh,并计划发布 full technical post-mortem。
详细页:Haruko Institutional Crypto Cyberattack
CEX 方面,Bybit Brazil 今天到达强制处置 deadline。按照 Bybit 早已公布的 local-entity migration timetable,9 月 21 日仍未主动关闭的 restricted open positions 将按 prevailing market prices force-liquidate;unsupported fiat 自动 convert to USDT;non-compliant coupons / bonuses forfeited。下一步是 9 月 24 日,符合条件的 Brazilian residents / Enterprise Users(KYB)迁移到 local Bybit entity。
这是一条 Brazil-specific regulatory migration event,不能写成 Bybit global shutdown 或 insolvency。
详细页:Bybit Brazil Forced Liquidation and Local-Entity Migration
最后,美国 derivatives market structure 出现新的重要 filing。Coinbase Derivatives 9 月 18 日向 SEC 提交 rules,拟交易以 U.S. individual equities 与 ETF shares 为 underlying 的 cash-settled futures,其中包括 perpetual single-stock futures;同日也向 CFTC 提交 approval request。SEC notice 明确写着:CFTC has not yet approved the proposed rule change。
因此这是非常重要的 market-structure move,但现在仍是 pending product/regulatory framework,而不是已经上线的 U.S. stock perps。
详细页:Coinbase Single-Stock Perpetual Futures Filing
① 今日最高优先级 Alerts
| Risk | Entity | Event | Time | Latest Status | Evidence Type | Continue Monitoring | New vs Previous Day |
|---|---|---|---|---|---|---|---|
| Critical | SingularityNET / Fetch.ai / NuNet / World Mobile | Bridge/signing-key compromise + unauthorized mint | 9/19–21 | 8.7M FET drain;408.5M NTX、260M AGIX、53.838M WMTx linked mint;部分 bridge/conversion 已暂停;realized loss 未完成核算 | Project + On-chain/Security | 是 | 新重大 multi-project incident |
| High | ZetaChain | L1 wind-down / ZETA migrate to Solana | 9/20 | Proposal 68 99.4% 通过;仍需第二次 vote 决定 snapshot/shutdown | Governance + Media | 是 | 确认 chain-exit decision |
| High / Developing | Polymarket U.S. | Stolen-card fraud + account takeover | 新披露 9/20 | ≥$10M attempted fraud;另有近 500 account incident;actual losses 部分未知 | Major Media + Company | 是 | Historical incidents newly disclosed |
| High | Haruko | Institutional infrastructure cyberattack | 9/17–21 | 15 clients;API/trading data exposure;部分 fund loss 未量化;vulnerability fixed | Company messages via Media | 是 | CEXVia 新增覆盖 / incident active |
| High | Bybit Brazil | Regulatory migration / forced liquidation | 9/21 | Restricted positions force-liquidated;unsupported fiat → USDT;9/24 local migration | Official | 是 | 今天达到硬 Deadline |
| Medium | Coinbase Derivatives | U.S. single-stock perpetual security futures | 9/18 filing | SEC filing public;CFTC approval pending | Official SEC | 是 | New market-structure filing |
| Critical | CoinEx | Exchange shutdown | 持续 | 9/22 futures / non-spot shutdown 为下一个 deadline | Official | 是 | 无重大新增 |
| High | Blink Wallet | Custodial-account incident | 持续 | Services restored;patch verified;affected accounts made whole;root cause/post-mortem pending | Project / Media | 是 | Recovery phase,无新 root cause |
② 交易所退出 / 停运 / 提现风险
Bybit Brazil — High / 今日 Deadline
9 月 21 日是 Bybit Brazil migration program 中最重要的 forced-execution date。Restricted open positions 如果仍未主动关闭,将按 prevailing market prices force-liquidate;unsupported fiat 自动转成 USDT;不符合要求的 coupons / bonuses forfeited。
该措施只适用于公告范围内的 Brazil users / enterprise accounts,不是 Bybit 全平台强平。
9 月 24 日是下一节点:eligible accounts 正式迁到 Bybit local Brazil entity。
CoinEx — Critical / 明日重要节点
9 月 22 日 futures 与多数 non-spot service 结束,remaining futures positions 进入平台 settlement。9 月 29 日 spot shutdown / non-USDT original-asset cutoff 不变,12 月 22 日 final withdrawal deadline 不变。
BitMEX — Critical / 持续
最终 exchange closure 仍为 9 月 23 日。本轮没有新事实需要重复建 URL。
Digitra — High / Watchlist
Digitra 已公告的 platform closure 正接近 9 月 28 日 crypto withdrawal deadline。逾期 crypto 将从 9 月 29 日开始 compulsory conversion to USDT,converted balance withdrawal 到 10 月 19 日。
③ 监管与牌照
Coinbase Derivatives — Medium
9 月 18 日 filing 把 crypto-style no-expiry contract 带入 U.S. security futures framework。SEC notice 已公开,但 CFTC approval 仍 pending。
核心边界:
公开 filing ≠ 产品已批准 ≠ 用户现在可以交易。
Polymarket — High / Developing
新披露事件同时涉及 payments fraud、AML、identity verification、account recovery 和 compliance governance。Polymarket 表示 controls 已加强,外部律师调查据报认为公司合规;但 CFTC investigation 仅来自 media reporting,agency 尚未 confirm/deny。
U.S. Rulemaking 持续
CFTC RIN 3038-AF80 仍处于 OIRA prerule review,仍没有 public substantive rule text;SEC tokenized-stock Innovation Exemption 继续按其 conditional framework 生效。
④ 黑客 / 漏洞 / 资产损失
ASI / SingularityNET — Critical
这是今天最严重的 security incident,因为它同时出现:
- 直接真实资产 drain;
- 大规模 unauthorized token mint;
- bridge / signing-key compromise;
- 跨多个生态项目扩散。
当前最可靠的拆分是:
- ~8.7M FET 从 Fetch.ai converter 被 drain;
- 408.5M NTX 从 NuNet deployer account mint 到同一 cluster;
- 260M AGIX 与 53.838M WMTx unauthorized mint;
- independent analysis 还关联 additional CGV mint;
- ~$16.77M 是一个 attacker Ethereum-holdings snapshot,而不是 confirmed cash-out。
Fetch.ai 表示 core contracts safe,主要攻击面是 SingularityNET bridge infrastructure;World Mobile 已确认 unauthorized WMTx mint。
Haruko — High
Haruko 显示另一类重要风险:即使客户 login credential 没有直接泄露,第三方 institutional infrastructure 中的 process-memory / access-token compromise 仍可以暴露 API 与 trading intelligence,并在缺少 IP whitelist 等控制时转化成真实资金损失。
⑤ 用户投诉与运营异常
Polymarket Account Takeover — High / Developing
late-July registration flaw 的危险点,是 attacker 据报不需要 existing username/password,只需要 stolen personal data,就可能 claim / access 已有 customer identity。近 500 accounts reportedly targeted。
Polymarket 表示会覆盖 affected-user loss,但 amount 仍没有完整公开。
Blink Wallet — 持续
Blink 已恢复 services,并表示 vulnerability 已 fixed and verified。Few dozen custodial accounts 受影响并会 made whole;non-custodial wallets 不受影响。Total loss 和 exact attack path 仍未公开。
本轮没有其他 Community-only complaint cluster 达到 High/Critical。
⑥ 链上和市场异常
今天最大的 on-chain supply anomaly 是 ASI / SingularityNET cluster。
Unauthorized mint 可以在没有等额 cash extraction 的情况下摧毁 supply integrity。
流动性太薄可能限制 attacker 真实 cash-out,却仍会造成:
- token price crash;
- exchange deposit/withdrawal suspension;
- bridge accounting confusion;
- circulating-supply uncertainty;
- collateral / valuation problems。
ZetaChain 则属于 chain-migration market-structure risk。第二个 proposal 发布前,native ZetaChain ZETA、未来 Solana SPL ZETA,以及 Proposal 68 scope 外的 Ethereum / BNB Chain ZETA 之间会存在 migration / liquidity fragmentation uncertainty。
⑦ Watchlist
| Date / Window | Event | CEXVia 观察重点 |
|---|---|---|
| 立即 | ASI / SingularityNET | Key revocation、bridge accounting、exchange freeze、unauthorized supply treatment、recovery |
| 立即 | Polymarket | CFTC posture、fraud controls、user reimbursement、account remediation |
| 立即 | Haruko | Post-mortem、client loss、secret rotation、API remediation |
| 立即 | ZetaChain | 第二 proposal、snapshot block、shutdown block、exchange swap support |
| 9/21 | Bybit Brazil | Forced liquidation / unsupported-fiat conversion |
| 9/22 | CoinEx | Futures / non-spot shutdown |
| 9/23 | BitMEX | Final exchange closure |
| 9/24 | Bybit Brazil | Local-entity migration |
| 9/25–29 | Balancer | Wind-down governance vote |
| 9/28 | Digitra | Crypto withdrawal deadline |
| 9/29 | CoinEx | Spot shutdown / original-asset cutoff |
| 9/30 | UK FCA | Crypto authorisation gateway opens |
| 10/19 | Digitra | Converted-balance withdrawal deadline |
| 12/22 | CoinEx | Final withdrawal deadline |
⑧ 今日无新增但仍高风险的存量事件
D’CENT App Wallet — Critical: root cause 与完整 multi-chain loss accounting 未完成。 Nostra — Critical: money-market reconciliation、final bad debt、reopen 未完成。 Splash / OADA — Critical: recovery、liquidity restoration、compensation 未解决。 XPR / MetalX — Critical: CEX-bound recovery 与 final accounting 未完成。 Symbiosis — Critical: native Bitcoin Bridge 与 LP compensation 未解决。 Liquid Network — Critical: staged bridge recovery 未完成。 BitMart — Critical:仍没有 verified recovery percentage / withdrawal timetable。
FAQ
今天最高优先级安全事件是什么?
ASI / SingularityNET bridge signing-key compromise,因为它同时包含真实 FET drain 和多个 token 的大规模 unauthorized mint。
1,677 万美元就是已被盗金额吗?
不是。这是 security monitor 对 attacker cluster 某个时间点 Ethereum holdings 的估值,不等于 realized economic proceeds。
ZetaChain 已经关链了吗?
没有。Proposal 68 批准 migration / wind-down 方向,但第二 proposal 仍需确定 snapshot、shutdown block 和 claim process。
Polymarket 损失了 1,000 万美元吗?
不能这样写。报道说 fraudsters attempted at least $10M;并未确认全部成功,且多数 attempts reportedly failed。
Bybit 9 月 21 日强平影响所有用户吗?
不影响。仅适用于 Brazil migration announcement scope 内的 restricted positions。
Coinbase U.S. single-stock perpetual 已经上线了吗?
没有。SEC filing 已公开,但 CFTC approval 仍 pending。