DefiingerMulti-Chain DeFi Data, News & Research

DeFi Weekly News Review — September 21–27, 2026

Every material multi-chain DeFi headline from Monday 21 to Sunday 27 September 2026, grouped by theme with the date, source and commentary on each item.

Weekly DeFi News Review2026-09-272 min readDefiinger Research Desk437 words

Below are the multi-chain DeFi headlines we logged between Monday 21 and Sunday 27 September 2026, grouped by theme. Each item carries its date, the outlet it came from, a summary of what happened, and our read on why it matters.

The week's biggest story sat off our charts: Bitget, a centralised exchange, lost roughly $387.5m to attackers who never touched a private key — they made the exchange's own backend sign the transfers. On-chain, the data week split in two, with fees up 11.1% and every chain adding deposits while trading volume fell.

1 Security Incidents

01Attackers spoof Bitget's own wallet backend into signing about $387.5m of transfers — no private key stolen, cold wallets untouched

Thu 24 Sep · Source: Bitget · Multi-chain · Bitget

Bitget detected unauthorised transfers from some of its hot and warm wallets at 18:31 UTC on 24 September, estimating $351.6m that night and revising to roughly $387.5m the next day after adding Zcash and TRON transfers to the accounting. Attackers compromised a third-party security product to obtain high-level internal credentials, then fed false transaction data into the wallet-management backend, which triggered Bitget's own authorisation process to sign the transfers. On-chain reporting puts XRP at roughly 40% of the revised total (about $157.5m) and ETH at about 22% (31,890 ETH, about $85.8m); an attacker wallet converted $19.67m of USDT0 into 7,111 ETH within minutes. Mandiant and SlowMist are investigating; the company says on-chain patterns are consistent with North Korea-linked activity, its Protection Fund (over $464m) covers the loss, and withdrawals restart in phases from 28 September.

Our takeThe mechanism matters more than the size. Nothing cryptographic failed — a trusted internal system signed what it was told, which is the centralised twin of the module and oracle failures of recent weeks. It also resets the CEX risk conversation: the loss sits on the exchange's own balance sheet, user balances were intact, and the withdrawal-restart schedule is now the test of the response.

02MultiversX restarts its mainnet after a five-day VM-level atomicity exploit halt; exchanges keep EGLD transfers restricted

Week · Source: MultiversX · MultiversX (EGLD)

MultiversX disclosed a potential mainnet issue on 19 September and the next day confirmed an attacker had exploited a virtual-machine-level atomicity issue that produced invalid on-chain state changes, days after the Supernova upgrade cut target block times from 6 seconds to 600 milliseconds. Engineers validated a recovery on a shadow fork and block production resumed on 24 September after roughly five days paused, using a targeted recovery that preserves legitimate history while reversing only incident-related changes. Co-founder Beniamin Mincu said the attacker's accounts were identified, seized and frozen with major exchanges; no confirmed loss figure has been publicly disclosed — SlowMist's incident database lists none — and the promised technical report is still pending. Upbit placed EGLD under a trading-caution designation on 21 September with a review running into late October, and Bithumb, Upbit and Kraken kept EGLD transfers restricted past the restart.

Our takeA layer-1 pressing pause on itself is the strongest containment move available, and the recovery design — keep legitimate history, reverse only the incident — is the part other chains will study. The restart is now the fact on the table; what remains open is the technical report, and whether any loss figure ever attaches to an incident the team says was contained.

03Astroport loses admin control of its Neutron contracts; Neutron halts the whole chain to investigate a takeover that drained about $9.3m across protocols

Tue 22 Sep · Source: Astroport · Cosmos · Astroport (Neutron)

Astroport, the Cosmos-ecosystem DEX, disclosed a security incident on Neutron in which admin privileges for its contracts may have been stolen. Neutron halted chain operations to investigate, and the project urged users to withdraw liquidity from all Astroport pools across chains; Terra-side contracts were unaffected. SlowMist logs about $4.9m taken from Astroport contracts and a further $4.4m from the liquid-staking protocol Drop, roughly $9.3m in all, under compromised administrator privileges.

Our takeHalting an entire chain to contain a single DEX's admin-key compromise is a proportionate response that says something about how much a deployed admin key can do. It is the same failure family as rsETH's module and Bitget's backend: a privileged instruction path that worked exactly as designed, for someone else.

04White-hats move 52.37 BTC from the Coldcard seed exploit into a Wyoming recovery trust — about 2.8% of the 1,789 BTC taken

Mon 21 Sep · Source: Galaxy Digital · Bitcoin · Coldcard

White-hat researchers consolidated 52.37 BTC (about $4.5m) tied to the Coldcard seed-entropy exploit into a single address controlled by the Crypto Recovery Trust, a Wyoming statutory trust, at block 967,948 with an OP_RETURN pointer to its claims site. Galaxy Digital tracks 1,789.28 BTC (about $154.1m) swept since 30 July from a firmware flaw dating to March 2021 that weakened seed randomness on some devices. On 23 September the trust announced it had returned more than 20 BTC to a verified owner at no cost.

Our takeThis is the recovery infrastructure working as intended: white-hats frontrunning thieves into a legal vehicle that verifies claims and returns funds for free. The uncomfortable part is the timeline — a 2021 firmware defect surfaced as a five-year-later theft, which is the longest delay between bug and exploit this sample has recorded.

05A malicious iOS App Store app with a kernel-exploit framework steals about $580k by reaching Keychain and wallet seed phrases

Week · Source: SlowMist · iOS · FomoPeek

SlowMist detailed FomoPeek, an app distributed through Apple's App Store that carried a kernel-exploit framework able to escape the sandbox and read the Keychain and wallet seed phrases on iOS versions 12.0 through 18.7.2 and 26.0 through 26.1. SlowMist traced about 579,984 USDT (roughly $580k) to attacker addresses and advised affected users to treat their keys as compromised.

Our takeDistribution through the official store is what lifts this above the usual phishing long tail — the trust decision users made was 'it is on the App Store'. The loss figure is small; the abuse of the review process is the durable fact.

2 Protocol Funding & Governance

06HIFI closes a $37m Series A led by Left Lane Capital, with Tether participating, for stablecoin settlement and tokenized capital markets

Thu 24 Sep · Source: HIFI · Payments · HIFI

HIFI, a New York-based payment infrastructure company connecting bank rails, stablecoins and tokenized assets through APIs, raised a $37m Series A led by Left Lane Capital with Tether among the participants. The company says its systems handle more than $7bn of annualized volume, and the raise funds additional regulatory licences, expansion beyond payments into cards and capital-markets infrastructure, and deeper integrations including Visa Direct and the Circle Payments Network.

Our takeThe investor set is the signal: the largest stablecoin issuer taking equity in the settlement layer above it. The venture thesis here is settlement architecture rather than token exposure — a continuation of last week's Velocity round, with different names on the same thesis.

07Atum launches with $13.5m from Variant and PayPal Ventures; TRON-ecosystem MeshWallet raises a $10m private round

Week · Source: Atum · Payments · Atum / MeshWallet

Atum emerged from stealth on 22 September with $13.5m from Variant, PayPal Ventures and others, building an open payments network that coordinates transfers across stablecoins, banks and blockchains without issuing a currency or taking custody. MeshWallet, a Tallinn-based self-custodial wallet in the TRON ecosystem, disclosed a $10m private round during the week; its product lets users send TRC-20 USDT without holding TRX for network fees.

Our takeTogether with HIFI, disclosed payment-infrastructure financing topped $60m this week — the clearest weekly concentration yet in a sector that was speculative a year ago. MeshWallet's fee-abstraction detail is the practical one: removing the gas-token requirement is the kind of unglamorous work that widens an actual user base.

3 Networks, Fees & TVL

08Network fees jump 11.1% to $243.4m while DEX volume falls 5.0% to $44.00bn — and TVL rises 2.5% to $79.86bn with every tracked chain up

Week · Source: DefiLlama · Multi-chain (7 tracked)

All seven chains grew TVL for only the second time in our sample, lifting the aggregate 2.5% to $79.86bn. Fees rose 11.1% to $243.4M — Solana led at $113.7m (+8.6%) and Ethereum earned $86.2m (+15.2%), its largest weekly fee total in the sample — while DEX volume fell 5.0% to $44.00bn and blended turnover dropped from 0.59x to 0.55x.

Our takeFee growth without volume growth is a divergence this series has shown before. It is either durable usage or the on-chain wake of a breach week, and one week of data cannot separate the two — which side reverts is next week's question.

09Solana posts the week's fastest TVL growth (+7.1% to $6.62bn) and keeps the fee lead at $113.7m

Week · Source: DefiLlama · Solana

Solana added about $0.44bn of TVL (+7.1%, a z-score of 4.76 against its own baseline), led all chains in fee revenue at $113.7m (+8.6%), and held the DEX volume top spot at $18.32bn despite a 7.6% weekly decline. Its stablecoin float rebounded +6.4% to $16.74bn after last week's 4.4% drop.

Our takeSolana did what deposit weeks are supposed to do — convert capital into fees — while its volume eased. The float rebound matters as much as the deposits: it was the sample's largest decliner last week, and a one-week reversal keeps the drain story two-chain rather than ecosystem-wide.

4 Stablecoin Developments

10Tracked stablecoin float slips 0.1% to $283.32bn — a third consecutive weekly decline, concentrated in TRON at -1.3%

Week · Source: DefiLlama · Multi-chain

TRON's float fell 1.3% to $92.79bn (a z-score of -3.26 against its own baseline), doing most of the damage; Arbitrum shed 3.8% and BNB Chain 0.2%. Solana rebounded +6.4% to $16.74bn, Ethereum was flat at $147.49bn, and Base and Optimism grew slightly. Ethereum and TRON still hold about 85% of the float between them.

Our takeThree straight declines against a rising TVL confirms the drain we flagged last week as a trend. The composition shifted too — the drain concentrated in the chain that holds a third of the float, rather than spreading across the sample.

11Circle receives a $100m strategic investment from Binance alongside a renewed five-year USDC agreement

Tue 22 Sep · Source: Circle · Issuers · Circle

Circle, the USDC issuer, announced a $100m strategic equity investment from Binance on 22 September, placed through a private placement of Class A shares, alongside a renewed five-year commercial agreement focused on expanding USDC access across emerging markets.

Our takeAn exchange investing in the issuer whose rail it settles on is consolidation, not diversification — the same pattern as the week's funding rounds, one level up. It also deepens the entanglement between the largest CEX and the largest regulated issuer, which cuts both ways in a stress scenario.

5 Institutional Adoption

12Bitget's breach response becomes the institutional story: a $464m protection fund absorbs the loss while Circle and Tether freeze attacker-linked funds

Week · Source: Bitget · Exchanges · Bitget response

Beyond the theft itself, the week's institutional signal was the response apparatus. Bitget's User Protection Fund — valued at over $464m in the first incident notice — is absorbing the full $387.5m loss; Circle had frozen roughly 99,990 USDC and Tether about 218,023 USDT linked to the attack by 26 September; a 5% bounty programme covers freezes and recoveries; and withdrawals restart in phases — BTC on 28 September, ETH on 29 September, USDT on 30 September and remaining services on 2 October.

Our takeThe measure of a large exchange breach is no longer whether it happens but whether the response machinery works on schedule. The restart timetable is an unusual degree of specificity, and holding to it is the credibility test — the same test Chainflip faced last month at smaller scale.

6 What the week adds up to

The common thread this week is not a bug class — it is a trust boundary. Bitget's backend signed what it was shown; Astroport's admin key did what whoever held it asked; MultiversX's virtual machine executed a state change that should not have been possible. Three failures at three different layers, one shared shape: the approval layer did its job for the wrong party.

The Bitget case is the one that resets assumptions. Every prior incident in this series was a smart-contract failure with a bounded blast radius; this was a centralised operator losing the sample's largest single sum, with no key compromise and no user-balance loss — and with the response, not the breach, now the thing being tested. The withdrawal-restart schedule through 2 October is the credibility clock.

Away from security, the data week split in two. Fees rose 11.1% to $243.4M and all seven chains added deposits — TVL +2.5% to $79.86bn — while DEX volume fell 5.0% and stablecoin float slipped for a third straight week. The networks earned more than the traders traded, and which side of that divergence reverts is next week's story.

Key Takeaways

  • Bitget lost roughly $387.5m after attackers spoofed its wallet backend into signing transfers; cold wallets and user balances were untouched.
  • MultiversX resumed its mainnet on 24 September after a five-day VM-level atomicity exploit halt; attacker accounts were frozen and no confirmed loss figure has been published.
  • Astroport's Neutron contracts lost admin control (~$4.9m per SlowMist); Neutron halted the chain to investigate.
  • White-hats moved 52.37 BTC from the Coldcard exploit into a Wyoming recovery trust; Galaxy tracks 1,789.28 BTC swept in total.
  • Fees rose 11.1% to $243.4M and TVL rose 2.5% to $79.86bn with all seven chains up, while DEX volume fell 5.0%.
  • Stablecoin float slipped 0.1% to $283.32bn for a third straight weekly decline; HIFI raised $37m and Circle took $100m from Binance.
DE
Defiinger Research Desk

The Defiinger Research Desk compiles multi-chain DeFi data and commentary from public on-chain sources and vetted industry publishers. Our editorial process prioritizes verifiable figures and clearly dated references.

Sources & Methodology

  1. DefiLlama — chain-level TVL, DEX volume, fees and stablecoin series used throughout.
  2. Bitget — incident notices of 24 and 25 September, the withdrawal-restart schedule, and the protection-fund valuation.
  3. Mandiant and SlowMist — the investigation into the Bitget breach and the FomoPeek tracing.
  4. MultiversX — statements on the VM-level atomicity flaw, the 19–24 September halt and restart, and the targeted recovery plan.
  5. Astroport and Neutron — incident statements on the 22 September admin compromise and the chain halt.
  6. Galaxy Digital — tracking of the Coldcard exploit and the white-hat consolidation; Steptoe — the Crypto Recovery Trust returns.
  7. HIFI — the $37m Series A announcement. Atum — the $13.5m launch round. MeshWallet — the $10m private round.
  8. Circle — the $100m strategic investment from Binance and the five-year commercial agreement announced 22 September.
  9. PANews — the weekly funding roundup that anchors the Atum and MeshWallet items.

Headlines and figures on this page are drawn from the outlets listed above; commentary is clearly labelled opinion and is not investment advice. Last reviewed 2026-09-27.

Frequently Asked Questions

How do you choose which headlines to include?
We keep items that changed something measurable — capital, protocol parameters, or user access — and drop price-only stories and unverified loss figures.
Why link to home pages instead of the article?
We cite the outlet that reported each item rather than linking to permalinks we have not individually verified.
Which sources do you use?
Bitget, Mandiant, SlowMist, MultiversX, Astroport, Neutron, Galaxy Digital, Steptoe, HIFI, Atum, MeshWallet, Circle, Binance, CoinDesk, PANews, DefiLlama, plus primary statements from protocol operators.
What date range does this cover?
Monday 21 September to Sunday 27 September 2026 inclusive. Every weekly report on the site uses the same Monday-to-Sunday window.
Do you report exploits before they are confirmed?
No. We wait for a security firm, the protocol, or an on-chain trace before quoting a loss figure, and we say so when a number is still provisional — the Astroport loss total is one such case this week, pending the chain's post-mortem.
Is this investment advice?
No. The news column is the record; the commentary is clearly labelled opinion.