Join our Newsletter — 33% off our NHI Course

Approval-layer attacks: are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Crypto lost $742.0M across 33 incidents in September 2026, nearly three times August's $255.5M, as attackers shifted from bad inputs to the systems that approve transactions and governance decisions, according to Quantstamp. Approval paths, not just contracts and wallets, now define the real attack surface.

Editorial analysis by NHI Mgmt Group, based on content published by Quantstamp: “September 2026: The Approval Layer Was Exploited”.

By the numbers:

  • Crypto lost $742.0M across 33 incidents in September 2026.
  • Bitget's $387M hack and Liquid Network's $320M exploit account for about 95% of September's losses.
  • The other 31 incidents added up to $35.0M.

Key questions

Q: What breaks when approval systems are compromised instead of the contract itself?

A: When approval systems are compromised, the attacker no longer needs to defeat the application logic.

Q: Why do signer and governance paths create such high impact when abused?

A: Signer and governance paths matter because they sit above the application and can authorise many downstream actions at once.

Q: What are the warning signs that approval-layer trust is failing?

A: Look for unusual transfer volumes, proof checks that rely on stale cache state, admin changes that arrive through indirect paths, and proposal activity that can reassign privileged control.

Practitioner guidance

  • Map the approval surface Inventory every system that can bless a transaction, proof, contract migration, or admin change, including signers, governance modules, caches, and vendor-integrated controls.
  • Separate signing authority from upstream tools Remove direct paths from third-party products and routine admin credentials into systems that authorise transfers or contract changes, and require explicit, narrow delegation.
  • Revalidate trusted decisions at the point of approval Do not rely on cached verification or inherited trust when the action is economically destructive or governance-changing; force a fresh decision before execution.

Bottom line: September's losses show that attackers are targeting the layer that approves transactions and governance changes, not only the code that executes them.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Approval-layer compromise is now the decisive security problem in digital asset systems. The article shows that attackers no longer need to defeat the transaction itself when they can compromise the authority that certifies the transaction. That shifts the real security boundary to signers, governance modules, and verification caches, which are often treated as support systems rather than critical control planes. Practitioners should model approval logic as a privileged trust service, not an implementation detail.

A question worth separating out:

Q: How should security teams govern approval authority in digital asset systems?

A: Treat approval authority as privileged infrastructure. Separate who can request an action from who can bless it, minimise the number of components that can influence authorisation, and review any path that lets third parties, delegates, or governance votes override application-level controls.

👉 Read our full editorial: September 2026 shows approval-layer attacks can outrun controls



   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.