Crypto Fraud Watch: One Stolen Key Drains $16.77 Million, Balancer Loses Its Domain, and Visa Closes the Memecoin Rewards Loophole

The weekend's biggest crypto stories turned on things sitting outside the blockchain itself: a signing key, a domain registrar, and a merchant category code. Two thefts drained roughly $17 million without exploiting any contract, Visa reclassified memecoin card purchases, and ZetaChain holders voted to retire their own Layer 1.

A Stolen Signing Key, Not an Exploit, Cost $16.77 Million

On September 19, an attacker obtained the backend signature key for the SingularityNET bridge linking Ethereum and Cardano. No vulnerability was needed: with a valid key, the attacker generated legitimate signatures and emptied 8,721,530 FET, about $1.55 million, through the bridge's conversionIn function. The same actor took NuNet's minting key and issued 408.5 million NTX, roughly 42% of that supply, then minted 260 million AGIX and 53.8 million WMTx. Analysts put the attacker's holdings at $16.77 million.

A key compromise creates different exposure than a code exploit. The questions become custodial: who held the key, how it was stored, whether signing authority was split, and what holders were told. A single key able to mint 42% of a supply is a material fact, and litigants will ask when buyers could have known it existed.

Balancer Lost Its Website, Not Its Contracts

A day later, attackers social-engineered EuroDNS, the registrar handling Balancer's .fi domain, and redirected balancer.fi to a phishing page prompting visitors to approve a malicious contract. Losses came to about $238,000. Balancer regained the domain at 5:45 pm UTC on September 20 and is weighing a move off the .fi TLD.

The contracts held; the DNS record did not. Because victims signed their own transactions, recovery is harder than after a protocol failure, and the analysis turns to negligence claims against the registrar and to whether the project's registry lock settings met a reasonable standard of care.

Visa Closes the Memecoin Rewards Loophole

Visa is directing processors to stop coding memecoin purchases under merchant category code 5815, the bucket for digital goods and media. The Block reported September 19 that Visa would shut the gap, which ran through Crossmint-powered checkouts in Robinhood Wallet and an app called Fomo. Coded as digital media, those buys earned ordinary card rewards, and users could spend $1,000 a day with no identity verification. The grace period expires next week.

The lost rewards are the small part. A $1,000-per-day purchase channel with no know-your-customer check is what draws anti-money-laundering scrutiny, and accurate coding is what lets issuing banks apply crypto limits at all. Expect quasi-cash treatment now: no rewards, cash-advance interest from day one, some declines.

ZetaChain Holders Vote 99.4% to Shut Down Their Own Chain

On Sunday, ZetaChain holders approved retiring the project's Layer 1 and migrating ZETA to Solana as a native SPL token one-for-one, on 99.4% support and 58% turnout against a 40% quorum. Two details matter more than the tally. The proposal excludes ZETA held on Ethereum and BNB Chain, so those holders are not covered as written. And the shutdown block and snapshot height come in a later proposal that will not go to a vote until exchanges confirm swap arrangements, with no date given. Anyone holding through a custodian or on an excluded chain should get a written answer.

How to Protect Yourself

Both thefts bypassed contract security, so contract-level caution was not enough. Bookmark the applications you use and verify the contract address your wallet is actually touching rather than trusting that the right domain resolves to the right site. Revoke stale token approvals periodically, and treat every approval prompt as a signature letting a contract move your assets. With bridged or wrapped tokens, your counterparty risk is the operator's key custody, not the code.

If you have lost funds, preserve transaction hashes, addresses, screenshots, and timestamps. Report the theft to the FBI's IC3 and to the exchange or bridge operator, because freezing stolen assets usually depends on reaching a centralized chokepoint before laundering completes. Claims against a protocol, registrar, vendor, or exchange may sound in negligence, contract, or consumer protection law depending on your jurisdiction, and several carry short limitations periods.

At Coin Counsel, we work with individuals and businesses navigating the legal fallout of crypto fraud โ€” whether you're a victim seeking recovery, a company facing regulatory scrutiny, or a project working to stay compliant in an increasingly complex legal landscape. The rules are evolving fast, and the cost of getting it wrong has never been higher. Contact us at coin-counsel.com to speak with a crypto-focused attorney today.

Disclaimer

This blog post is for informational purposes only and does not constitute legal advice. Reading this content does not create an attorney-client relationship between you and Coin Counsel or Franco Law PLLC. The legal landscape surrounding cryptocurrency is rapidly evolving and varies by jurisdiction. Do not act or refrain from acting based on information in this post without first consulting a qualified attorney. If you believe you have been the victim of crypto fraud, contact us at coin-counsel.com for a consultation.

Next
Next

Crypto Fraud Watch: Fake Recruiters Take $10.71 Million, Haruko Leaks 15 Funds' API Keys, and the CFTC Files Without Congress