KelpDAO has sued LayerZero and CEO Bryan Pellegrino following a $292 million rsETH bridge exploit attributed to North Korea's Lazarus Group, which was also linked to a recent $352 million Bitget hack.
Two major incidents involving stablecoins and crypto exchanges emerged on September 25, 2026. North Korean hackers allegedly stole $351 million from Bitget exchange and converted it to Ethereum to avoid frozen stablecoins, continuing a pattern of state-sponsored theft totaling nearly $1.85 billion from exchanges. Separately, the US Department of Justice filed a lawsuit against Tether revealing how the stablecoin issuer moved billions through shell companies and small Caribbean banks to circumvent banking restrictions, while the same channels were exploited by fraud perpetrators targeting elderly Americans.
Cryptocurrency hacks in 2026 have totaled $2.34B across 86 incidents, with major exploits targeting Bitget ($351.6M), Liquid ($319M), KelpDAO ($292M), and Drift Protocol ($285M). Attackers compromised private keys, wallets, bridges, and backend infrastructure rather than smart contracts themselves, highlighting the need for better key management, access controls, and damage limitation across crypto systems.
PolinRider malware attributed to DPRK's Lazarus group was detected in two open pull requests (#7716, #10321) targeting PostCSS and Tailwind configuration files. The malware uses obfuscated JavaScript code appended to legitimate config content and executes via eval with C2 communication over Ethereum JSON-RPC endpoints. Both PRs should not be merged without removing the malicious payload.