Crypto Fraud Watch: A $388 Million Zero-Day at Bitget, $18.4 Million Sniped on Robinhood Chain, and California Bans Official Memecoins

Three stories from the last two days turn on the same question: when crypto money disappears, who is on the hook? An exchange is reopening withdrawals after the largest theft of 2026, an analyst says one crew drained $18.43 million from launches on Robinhood's new chain, and California barred its own officials from issuing tokens.

Bitget Reopens Withdrawals as Its CEO Details a $388 Million Zero-Day

CEO Gracy Chen gave the first detailed account of Bitget's $388 million breach on Monday, September 28. The attacker ran two probe transactions at 6:31 p.m. UTC on September 24 — 0.184 ETH and 193 TRX — both below the exchange's risk threshold, so no alerts fired. Thirty minutes later, 17 transactions across eight chains moved about $361 million. No private keys were stolen: Chen says the attacker used a zero-day in a third-party security product to get admin credentials, injected fraudulent withdrawal commands into wallet backend systems, then deleted the traces. Bitcoin withdrawals restarted Monday.

Bitget's user protection fund, worth $465 million on September 25, is absorbing the loss. That is a discretionary corporate commitment, not a legal entitlement. There is no FDIC-style backstop for exchange balances, and what a customer can demand is set by the terms of service they clicked through.

An $18.4 Million Sniping Operation on Robinhood Chain

Onchain analyst Wazz alleged Sunday that one operation extracted at least $18.43 million from 53 memecoin launches on Robinhood Chain between July 10 and September 21, most through the Pons V2 launchpad. Pons charges a 99% "snipe tax" in the first seconds after launch and lets a creator waive it for up to 32 addresses. In the launches The Block matched onchain, creators exempted 15 to 25 wallets, and one transaction a block or two later bought for all of them at once, leaving insiders with 82% to 86% of supply. Proceeds from one launch funded the next.

None of this was a hack. Every step used a documented feature as designed, so a claim sounds in fraud, not computer intrusion. A plaintiff has to prove deception and intent, and the hard part is putting a name to a pseudonymous deployer. The exemptions and funding chain do sit permanently onchain, which is better evidence than most fraud plaintiffs get.

California Bans Public Officials From Launching Memecoins

Governor Gavin Newsom signed Assembly Bill 2409 on Sunday, September 27, barring California public officials from issuing memecoins and restricting companies from listing coins that use an official's name or likeness. He signed a package alongside it, including Senate Bill 1208, which addresses digital-asset money laundering and sets clearer rules for restitution when investors lose money to crypto scams.

The restitution provisions matter more than the memecoin headline. Victims have long fought over losses denominated in a volatile asset but restitution calculated in dollars at some arbitrary date, and clearer state rules give a more predictable path in California courts. The listing restriction is a live compliance obligation for any venue with a California nexus. Federally, nothing has moved since the Senate blocked the CLARITY Act 49-50 on September 15 over these same ethics questions.

Bitcoin ETFs Post Their Best Week Since October 2025

U.S. spot bitcoin ETFs took in $2.4 billion in the week to September 25, flipping 2026 net flows positive after a $5.8 billion deficit. BlackRock's IBIT took $1.2 billion of it. Bitcoin then slipped from about $84,500 toward $83,000 on Monday.

How to Protect Yourself

An exchange balance is an IOU from a company, not property you hold. Keep there only what you are actively trading, move long-term holdings to hardware wallets, and read the withdrawal-suspension and liability terms before you need them. On new token launches, check holder distribution in the first blocks and whether the creator exempted wallets from launchpad protections.

If you have already lost money, the window is short. Report to the FBI's IC3 and your state regulator quickly, because early tracing is what gives stablecoin issuers a chance to freeze funds before they convert to ETH. Preserve addresses, transaction hashes, and communications, and talk to a lawyer before signing anything an exchange or recovery service hands you.

At Coin Counsel, we work with individuals and businesses navigating the legal fallout of crypto fraud — whether you're a victim seeking recovery, a company facing regulatory scrutiny, or a project working to stay compliant in an increasingly complex legal landscape. The rules are evolving fast, and the cost of getting it wrong has never been higher. Contact us at coin-counsel.com to speak with a crypto-focused attorney today.

Disclaimer

This blog post is for informational purposes only and does not constitute legal advice. Reading this content does not create an attorney-client relationship between you and Coin Counsel or Franco Law PLLC. The legal landscape surrounding cryptocurrency is rapidly evolving and varies by jurisdiction. Do not act or refrain from acting based on information in this post without first consulting a qualified attorney. If you believe you have been the victim of crypto fraud, contact us at coin-counsel.com for a consultation.

Next
Next

Crypto Enforcement Watch: The DOJ Turns Toward Binance Itself, 52.37 Bitcoin Reaches a Wyoming Trust, and Brussels Is Asked to Rewrite Stablecoin Reserves