End-to-End Blockchain Security & Compliance Partner Born on blockchain. Built for what’s next 🛡️

Security Castle
Our Q2 2026 Security & Compliance Report has been released ⬇️ $763.9M was stolen across 67 incidents, the worst since Q2 2025. 88% of the losses came down to operations. Smart contracts were still the most common failure point, 44/67 incidents, but they accounted for just 11% of the funds lost. All of this happens as MiCA comes into force, where only about 20% of registered firms secured authorization, roughly 210 of the more than 1,200 that once declared intent. This quarter's report is built around one idea, the Architecture of Trust: how security, compliance, and risk intelligence together influence which teams institutions are willing to work with. Inside, we cover: ▫️MiCA/DORA and the GENIUS Act ▫️Stablecoin regulations ▫️AI regulation across the EU and US ▫️How allocators run due diligence ▫️What comes next in Q3 2026 As digital assets become more exposed to public markets, institutional capital increasingly follows issuers that can consistently demonstrate they remain safe and sound. Built with input from @chainlink, @moodysratings, @Bybit_Official, @SuiNetwork, @StellarOrg, @1MoneyNetwork, Abraxas Capital, @AlliumLabs, @svrn_ai, @EisnerAmper, DA Insured, @howdenlocaluk – alongside Hacken. Get your copy of the report: hackenio.cc/q2-2026-security…
8
16
64
44,384
What would you ask a Head of GRC if you had their full attention? Today, Dmytro Yasmanovych will host Compliance Office Hours on LinkedIn. Bring questions on DORA, ISO, SOC 2, or any another readiness workstream. Your questions➡️ linkedin.com/feed/update/urn… The most useful question earns admission to a Hacken event.*
1
3
12
1,681
*Terms apply: The ticket is open to people working with digital assets and related financial services, including fintech, neobanking, asset management, and financial infrastructure. Hacken may ask the winner to confirm their connection to the field. The ticket is valid for 12 months from the date the winner is notified. It grants admission to a Hacken-hosted event only, even if that event takes place alongside a larger conference. The event may be held anywhere in the world, including the US. The winner covers their own travel, visas, accommodation, and other expenses. The ticket is non-transferable.
1
212
AI is becoming a part of how teams evaluate software security. @VitalikButerin raises a useful question: what does it mean for a program to be “secure”? “AI-assisted verification could shift the advantage toward defenders”. Teams first need to define what a program must guarantee, then check whether the implementation satisfies those properties. One of his points is that security definitions are additive. Different teams can specify different properties and check whether the software satisfies both. If those properties conflict, the team just found a design decision it needs to resolve. From an assessment perspective, every assurance claim should make 5 things clear: • Whether program/system requirements are well defined. • Which property was checked? • Under what assumptions? • Across which system boundary? • What evidence supports the result? That shows the team what the result supports and where further review is needed. For Canton builders, this applies to who may exercise a Daml choice and how related contracts change state. As part of Hacken’s ongoing R&D into AI-assisted security reviews, our AI auditor for Daml examines party authority and related contract state across workflows. This surfaces initial findings for deeper manual review and provides auditors with specific questions to investigate. Discover automated security analysis for applications built on Canton: hackenio.cc/daml-ai-audit
2
1
10
1,892
🚨 Bitget - reportedly hacked for $100M in $USDT, $ETH, $BTC, $AVAX, $BNB and more. Users are reporting blocked withdrawals, and assets are moving from the Bitget cold wallet. Under investigation by our team.
37
46
288
66,330
Stablecoins and tokenized gold were converted to ETH within approximately 25 minutes through UniswapX and Uniswap liquidity pools. On Optimism, ETH was converted to USDC, transferred to Ethereum via Circle CCTP, and sold in some cases within 24 seconds of minting. The operator accepted approximately 3% slippage in exchange for speed. Approximately 53,000 ETH is currently held across six newly created Ethereum addresses. No transfers to mixers, bridges or centralized exchanges have been observed to date.
1
4
16
3,317
Update on Bitget Hot Wallet Incident Gracy Chen, CEO of Bitget, confirmed that the estimated amount of affected funds is approximately $351.6 million. Cold wallets remain fully secure, and user funds are fully safe. The Bitget team took action: • An emergency response within minutes of detection • Addresses identified, flagged, and reported • Withdrawals temporarily suspended • Law enforcement and on-chain security firms notified. Official coverage: nitter.net/GracyBitget/status/210… nitter.net/bitget/status/21032365…
At 18:31 UTC on September 24, 2026, Bitget’s security systems identified unauthorized transfers involving a limited number of hot wallets. Our security team immediately activated emergency response procedures and began a full investigation. Based on our current assessment, approximately $351.6 million in assets were affected. Bitget’s cold wallets and the overwhelming majority of platform assets remain secure and unaffected. Most importantly, user funds remain protected. The incident falls within the coverage of Bitget’s User Protection Fund, which currently holds more than $464 million. Customer account balances remain accurate, and deposits and trading continue to operate normally. As a precaution, withdrawals have been temporarily suspended while our teams complete a comprehensive security review. We have identified and flagged the relevant transfer addresses and have formally engaged law enforcement agencies and leading on-chain security partners. We are working around the clock to restore withdrawal services as soon as it is safe to do so. Bitget will provide further updates through our official channels. We will not speculate on the attack vector while the investigation remains ongoing. Our focus is on protecting users, securing all systems, and delivering complete transparency throughout this process.
2
6
1,283
What does a Daml AI Auditor flag in a real smart contract? See what it finds in a smart contract, then watch engineers challenge the results live⬇️ On September 29th, as part of of HackCanton Season 3 by @appsfactory_cc, watch Hacken’s AI Auditor and see engineers challenge the findings live: what it flags, what evidence supports each finding, and what can actually get fixed. Live demonstration by Farrukh Odinaev — Solutions Engineer, Hacken Speakers examining the results: • Łukasz Wolski — Technical Lead, Hacken • Kornel Światłowski — Smart Contract Auditor, Hacken • Ales — CPO, @NODERS_TEAM If you are building on @CantonNetwork or want your smart contract audited, bring your questions to the live Q&A. 🗓️ September 29 | 14:00 UTC Register to watch the live review: hackenio.cc/live_ai_audit
1
3
9
2,652
Hacken🇺🇦 retweeted
🔐 A real Daml contract. A live security audit. On Sep 29, @hackenclub joins #HackCanton S3 for a live AI security session. We’ll get into: • live #AI audit of a Daml contract • Daml-specific risks • triage & remediation planning • audit scope • builder Q&A 📅 Sep 29 ⏰ 14:00 UTC 🎟 hackenio.cc/4hEfOqe
1
11
770
How did @osldotcom build DORA competency ahead of entering the EU market? With an existing ISO 27001 foundation, the training had to go beyond introductory material and engage the operational realities of a licensed, publicly listed group. The outcome: hackenio.cc/dora-training-fo…
1
3
13
2,249
This reel captures an evening where physical art sat beside the art of digital assets. Thank you @thevault_soft for co-hosting "Art and Digital Assets" with us at @EBlockchainCon in Barcelona and sharing this look back⬇️
Last week in Barcelona, we co-hosted “Art and Digital Assets” with @hackenclub during European Blockchain Convention. It was an evening where art met conversations around digital ownership, security, provenance and the future of on-chain assets. Thank you to everyone who joined us and to Hacken for co-hosting the evening with us.
1
10
2,808
How did @Toobit_official strengthen their CEX security across the web, API, Android, and iOS with Hacken’s penetration testing? 3 black-box tests identified 27 findings and gave Toobit a documented basis for remediation and future risk decisions. Read the case study: hackenio.cc/toobit-pentest
2
3
20
3,594
You have seen traditional security audits. Now watch an AI Auditor face the same objective. On September 29, Hacken and @NODERS_TEAM are running our AI Auditor on a real Daml smart contract The session is part of HackCanton Season 3 by @appsfactory_cc — 450 builders from 48 countries currently building on @CantonNetwork. For founders and engineers on Canton, this live workshop is a chance to inspect the workflow and see how the system surfaces Daml-specific risks: what it flags, what evidence supports each finding, and what your team can actually fix. Leave with a clearer view of what your current process covers, where AI-assisted review can add value, and whether your Daml codebase should be audited next. September 29 | 14:00 UTC Register: hackenio.cc/live_ai_audit
2
3
24
6,930
“Maintaining VARA compliance can be harder than achieving it for the first time” Dmytro Yasmanovych, Hacken: "Every recurring control needs an owner. A quarterly scanning policy needs 4 reports, one for each quarter." Dmytro and leaders from Chainberg, @rivcapitalgroup, and @Gate answered implementation questions at different stages of the VARA licensing process. Edwin Cheung, @Gate: “VARA never asked for one single document.” The evidence included procedures, system configurations, logs, committee records, audit reports and live demonstrations using real data. Kashif Abbas, Chainberg: “Even after the penetration-testing scope was agreed, VARA challenged it again.” Applicants need to defend assessor independence and prove that the scope covers the relevant architecture. The report must also record findings and remediation. Guido Rocco, @rivcapitalgroup: “Digital-asset experience is not the norm in the security sector.” The assessor needs to understand the product, custody paths, signing flows, and infrastructure under review. Use the full panel to identify the next control and evidence in your VARA licensing process. Watch the panel: piped.video/live/Xf8SDHqwUJY…
1
2
12
2,091
CISOs and compliance officers: get ready for September's newsletter. Use September’s incidents and regulatory deadlines to set your October priorities. Last one covered how $951 bought enough voting power to control 90.66% of a governance pool, UK crypto authorisation applications open September 30, and more. Subscribe to receive September’s security and compliance newsletters, and keep track of all incidents and upcoming deadlines. •Security Pulse: hackenio.cc/security_pulse •Compliance Pulse: hackenio.cc/compliance_pulse
3
14
1,971
At @EBlockchainCon, digital assets entered the gallery. Our side event, co-hosted with @thevault_soft, brought physical art alongside the art of digital assets. With conversations about ownership, provenance, security, and the future of onchain value. Art and Digital Assets brought people together, sparked meaningful conversations, and forged new connections. Full gallery: hackenio.cc/event_gallery
3
3
23
3,053