explainer
What you missed: biggest blockchain stories, August–September 2026
Ten weeks in one post — the Coldcard $116M drain, the Liquid Network and Bitget breaches, SEC's Regulation Crypto Assets, THORChain's Monero swaps and more.
Blockchain Posts' automated news pipeline was offline from July 22 through September 28, 2026. Rather than backfill ten weeks of individually stale posts, this single roundup gathers the stories that mattered — the ones a builder, security engineer or analyst would still want on their radar today. Entries are ordered by significance rather than date, each with the source we verified against. Standard house rules apply: no price commentary, no speculation, only facts that appear in the linked sources.
Bitget loses $387.5M in a hot-wallet backend compromise attributed to Lazarus
On September 24, 2026 at 18:31 UTC, Bitget detected unauthorized transfers moving out of hot and warm wallets across seven chains. CEO Gracy Chen initially disclosed $351.6 million in losses; the figure was later revised to $387.5 million, making it the largest disclosed crypto theft of 2026. Attackers targeted the off-chain infrastructure that manages unsigned transactions rather than the signing keys themselves, and analysts attribute the pattern to North Korea's Lazarus Group. Bitget's $464M User Protection Fund is covering the loss; withdrawals reopened on a staggered schedule (BTC on Sept 28, ETH on Sept 29, USDT on Sept 30, others on Oct 2). Circle and Tether froze roughly $318,000 in flagged stablecoin balances — a rounding error against the total.
$320M drained from Liquid Network via an Elements pool-balance bug
On September 7, 2026, self-described white-hat hackers withdrew about 4,000 BTC of the ~4,200 BTC in Liquid Network's federation wallet, prompting the Bitcoin sidechain to halt block production. Blockstream attributed the incident to a software bug in the Elements codebase that let some nodes accept a transaction creating more L-BTC than the system had backing for — not a key compromise. The affected funds moved through SideSwap. By September 8, 3,400 BTC had been returned; roughly 600 BTC (~$47M) remained outstanding as this post published. Ledger CTO Charles Guillemet publicly disputed the "white-hat" framing.
Coldcard: $116M drained via a 2021 RNG firmware flaw
Starting July 30, 2026, attackers drained roughly 1,816 BTC (~$116 million) from more than 5,200 addresses across four waves — the largest hardware-wallet exploit on record. Galaxy Research and TRM Labs traced the root cause to Coldcard firmware v4.0.1 (March 2021): a build-configuration error set MICROPY_HW_ENABLE_RNG to zero, and the calling library checked for the macro's existence rather than its value. Seed generation silently fell back to a weak software RNG, collapsing key strength from 128 bits to roughly 40 — brute-forceable without device access. In one 41-minute window, 1,196 addresses were emptied for 1,083 BTC. Coinkite halted shipments of affected inventory and published a migration guide; updating firmware does not repair seeds already generated on a vulnerable device.
SEC proposes "Regulation Crypto Assets," the first formal crypto rulemaking
On August 18, 2026, the SEC published its proposed Regulation Crypto Assets rulemaking — the agency's first formal, framework-first crypto rules after years of enforcement-first posture. The proposal introduces the concept of "covered investment contracts" and two Securities Act offering exemptions: up to $5 million over any four-year period, and up to $75 million over each 12-month period. It also lays out when a crypto asset is no longer subject to an investment-contract analysis. Comments are open until October 19.
SEC opens a five-year "Innovation Exemption" for tokenized stocks
One month later, on September 17, 2026, the SEC published an Innovation Exemption creating a conditional, five-year path for "Tokenized Securities Venues" to run secondary trading of tokenized National Market System stocks through permissioned AMMs on public chains. Coinbase, Robinhood and Circle each traded up ~5% the day the order landed. Robinhood's existing EU stock-token product must add shareholder rights and other features to fit the US framework.
Circle opens Arc, a stablecoin-native L1, to the public
On September 16, 2026, Circle opened its Layer-1 chain Arc to public use after a private mainnet with 100+ institutional builders and a testnet that processed 244M transactions. Arc uses USDC as gas, embeds an FX engine, and offers opt-in privacy. Its 11 founding validators are almost entirely traditional-finance operators — BlackRock, DTCC, Visa, Mastercard and ICE among them — rather than crypto infrastructure firms. Fee logic builds on EIP-1559 but replaces block-level adjustments with a weighted moving average of demand.
THORChain 3.20 adds native Monero and Zcash swaps
THORChain 3.20 shipped on August 25, 2026, adding native swaps between XMR, ZEC and BTC/ETH/stablecoins without wrapped tokens or a centralized venue. It also introduced Protocol-Owned Liquidity, a new Stable Reserve, and reinstated support for Solana, Base and BNB. It is the first mainstream cross-chain DEX to make ZEC swappable outside a centralized exchange since the June NU6.2 Orchard reset.
Term Finance loses $8.5M to a $951 governance takeover
On August 23–24, 2026, an attacker spent about $951 to acquire 0.4852 tmvETH — enough to control 90.66% of the voting power in Term Finance's Meta Vaults governance token. The attacker then passed proposals granting themselves vault control and drained 2,843 ETH plus 1.68M USDC (~$8.5M, roughly 68% of the vaults' TVL). Term Labs shut down all Meta Vaults and revoked their DAO governance roles; withdrawals remain open, and Term's direct borrow/lend markets were untouched.
Ledger patches an Ethereum-app APDU race condition
On August 12, 2026, Ledger quietly patched its Ethereum app to v1.22.2, closing an APDU race condition that allowed a malicious paired app to swap a signed transaction after the user reviewed the clear-signing screen — turning a small transfer confirmation into an unlimited token approval. Ledger's Donjon team found the bug internally using AI-assisted tooling; researcher TestMachine went public between August 21 and 23, prompting debate over disclosure timing. No confirmed thefts have been reported; the fix is in Ethereum app 1.22.2 or later.
Ethereum sets Glamsterdam for Sepolia on October 6
The Ethereum Foundation announced on September 17, 2026 that Glamsterdam activates on Sepolia at epoch 353,024, slot 11,296,768 — October 6, 2026, 13:53:36 UTC. Glamsterdam bundles enshrined proposer-builder separation (ePBS), block-level access lists (BALs) and a revised gas pricing model. Hoodi is tentatively planned for October 27; a mainnet activation date has not been set.