Rising oil prices amid Middle East tensions could lead to global economic instability and increased energy costs, affecting various sectors.
The post Oil prices near $110 as Middle East tensions heighten supply risks appeared first on Crypto Briefing.
The surge in oil prices exacerbates global economic pressures, heightening concerns over energy security and inflationary impacts worldwide.
The post Oil prices surge over $3 on fresh strikes in Persian Gulf appeared first on Crypto Briefing.
Anthropic's profitability and rapid growth signal a transformative shift in the AI industry, potentially reshaping market dynamics and valuations.
The post Anthropic reports first profitable quarter as revenue tops $11.5B appeared first on Crypto Briefing.
The escalation risks further isolating Iran diplomatically, potentially leading to renewed sanctions and heightened geopolitical tensions.
The post Donald Trump blocks Iranian official from addressing IAEA conference appeared first on Crypto Briefing.
Trump's push for lower rates highlights tensions between political influence and economic policy, impacting market stability and global competitiveness.
The post Trump advocates for lowest interest rates ahead of Fed meeting appeared first on Crypto Briefing.
Bitcoin Magazine

Bitcoin’s ‘Unusual Mix’: Bearish Inflation Print, Bullish Buyback Failure
Bitcoin’s path higher just got harder in the short term, but the setup further out may be improving, according to a new report.
In a Friday note, European asset manager CoinShares’ Head of Research, James Butterfill, said firmer-than-expected core inflation raises the odds of tighter Fed policy and could cap bitcoin below $80,000 for now.
But the longer-term case, he argued, rests on the U.S. Treasury’s bond buyback programme failing to bring down long-end yields — a failure that could ultimately feed the debasement narrative that has supported both bitcoin and gold.
“The result is therefore a somewhat unusual policy mix for Bitcoin,” the report read. “Today’s CPI data is negative at the margin, increasing the probability of tighter monetary policy and potentially limiting the immediate upside.
“But the apparent failure of the Treasury’s current buying programme increases the likelihood of much more substantial intervention further ahead.”
It continued: “If that happens, it could become one of the more powerful medium-term catalysts for Bitcoin.”
Data on Friday revealed that the consumer price index, excluding food and energy, climbed 0.3% in August from a month earlier — higher than expected.
According to CME’s FedWatch tool, traders think there is a 85% chance interest rates will be higher after the Federal Reserve meets next week. Bitcoin has typically performed well in a low interest rate environment.
But the U.S. Treasury’s expanded bond buyback programme has so far failed to materially suppress long-term yields.
If yields stay stubbornly high, Butterfill said, pressure will build on Treasury Secretary Scott Bessent to escalate to a much larger, “bazooka-style” buying programme aimed at forcing borrowing costs down.
Bitcoin in August had one of its best runs in years after Treasury Secretary Scott Bessent announced the department would double the size of its long-dated bond buybacks.
The announcement and subsequent price surge has led some to say the much talked-about debasement trade is back. The so-called debasement trade is when investors buy an asset as a way to hedge against a currency losing value.
Bitcoin and gold have both benefited as part of the trade as the dollar weakens.
This post Bitcoin’s ‘Unusual Mix’: Bearish Inflation Print, Bullish Buyback Failure first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Bitcoin Magazine

Blockstream Tells Hackers To Return Remaining Bitcoin Stolen in Liquid Theft
Bitcoin infrastructure firm Blockstream has refused to negotiate further with hackers who last week stole 4,000 bitcoins from its Liquid network.
Writing on X Friday, Blockstream said that the hackers still had time to return the funds before the company would work with law enforcement.
White-hat hackers on Sunday withdrew about $320 million from the federation wallet that backs Liquid, a sidechain by Blockstream. After negotiating with Blockstream, they returned most of the funds but kept 598.5 coins worth over $46 million — demanding it as ransom.
“Blockstream will not pay a ransom for the return of stolen funds,” the post read. “Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft.”
It added: “We will work with law enforcement, exchanges, service providers, forensic specialists, and other relevant parties to trace and recover the assets and identify those responsible.”
“We will not pay for the return of stolen property. We will not abandon our users. The Bitcoin community will not stop pursuing the funds.”
Liquid, or L-BTC, is a layer-2 created by Blockstream that allows users to fast move assets backed 1:1 with bitcoin. One of the assets, LBTC, is a token backed by bitcoin that allows for quick settlement — a bit like the Lightning Network.
Hackers were able to get the funds by exploiting an inflation bug on the Liquid sidechain to create over 4,000 LBTC that did not exist before and cash them out for real, on-chain bitcoins.
The hackers then had an exchange with Blockstream via messages written into Bitcoin blocks.
In one message, the white hats wrote: “Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.”
In the latest message, the hackers slammed Blocksteam as “delusional, greedy, and arrogant,” and threatened to reveal all of Blockstream’s encrypted messages in the exchange unless the company allowed thieves to keep 10% of the bitcoins.
“You SHALL pay 10% using your own money as bug bounty or you will cause all your holders a 15% loss for your irresponsibility and stinginess,” the message read.
The Bitcoin community is still reeling after hackers in July were able to steal over 1,800 bitcoins worth close to $140 million from Coldcard wallet holders.
Users of the popular hardware wallet, created by Coinkite, were targeted because the product’s manufacturer did not use a true random number generator, allowing hackers to essentially guess investor seedphrases.
This post Blockstream Tells Hackers To Return Remaining Bitcoin Stolen in Liquid Theft first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Bitcoin Magazine

Italy’s Second Biggest Bank UniCredit Is Weighting up Crypto Custody: Report
Italy’s second largest bank is considering expanding into digital asset offerings, including custody, according to reports.
According to a Friday Bloomberg report citing people familiar with the matter, Milan-based UniCredit is selecting a technology provider that would allow it to build the infrastructure needed to hold digital assets and facilitate their buying and selling.
Bloomberg’s reporting added that tokenized investment products and fixed-income securities, the use of stablecoins and exposure to cryptocurrencies were all on the cards.
The news comes as other banks in Europe expand crypto offerings. Spain moved first on retail, with BBVA rolling out bitcoin trading and custody to all customers via its app, using its own custody infrastructure rather than a third party; Santander’s Openbank followed with its own trading service.
Cecabank — a Spanish custodian with over €400bn under management that acts as backbone for 100+ financial institutions — went live with crypto custody in June via a partnership with Bit2Me.
And in Germany, Deutsche Bank is building custody with Bitpanda’s technology arm, while Taurus and DZ Bank got BaFin approval in January for its meinKrypto platform.
New regulation in the European Union — Markets in Crypto-Assets Regulation (MiCA) — gives banks a legal definition, a supervisor, and a familiar set of obligations to launch crypto services.
UniCredit is one 37 lenders across 15 European countries working together to create a company called Qivalis with the aim of issuing a euro-denominated stablecoin.
Last year, the bank said it was offering professional clients a structured product tied to BlackRock’s iShares Bitcoin Trust exchange-traded fund, with full protection against losses.
This post Italy’s Second Biggest Bank UniCredit Is Weighting up Crypto Custody: Report first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Bitcoin Magazine

Government Defeated as Lords Back UK Digital Assets Strategy
The UK government suffered a defeat in the House of Lords on Wednesday as peers backed an amendment requiring the Treasury to draw up a national strategy for regulating digital assets.
The upper chamber approved the measure by 194 votes to 138, with Conservative and Liberal Democrat peers combining against a near-solid bloc of Labour votes. Baroness Neville-Rolfe, a Conservative former Treasury minister, moved the amendment to the Financial Services and Markets Bill.
The new clause, titled “Digital assets strategy,” would require the Treasury to prepare, publish and consult on a strategy for regulating and developing digital assets and related digital financial market infrastructure in the UK.
The regulation of digital assets includes “cryptoassets, qualifying stablecoins, Central Bank Digital Currencies, tokenised securities and other digital and tokenised financial assets,” according to the draft.
The UK is in the process of drafting a sweeping new crypto bill. The country’s Financial Conduct Authority finalised its regulatory framework for cryptoassets in June, with the regime due to take effect on 25 October 2027. The authorisation gateway for firms opened on 30 September and runs to 28 February 2027.
Britain is trailing behind Brussels and Washington with digital asset regulation. The EU’s Markets in Crypto-Assets regulation has applied to service providers since 30 December 2024.
And the U.S. under President Donald Trump signed the GENIUS Act into law in July 2025, establishing a federal framework for dollar-backed tokens. Broader market-structure legislation remains unfinished: the Clarity Act cleared the House in July 2025 by 294-134 but has been stuck in the Senate over DeFi, stablecoin yield and ethics provisions, with a procedural vote set for next week.
This post Government Defeated as Lords Back UK Digital Assets Strategy first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Bitcoin Magazine

Bitcoin Price Spikes, Shrugs off Hot US Inflation Data
Bitcoin’s price rose on Friday — despite data revealing that U.S. inflation had risen.
The biggest cryptocurrency by market cap was recently trading for close to $78,749 after jumping 2% over a 24-hour period. At one point on Friday morning in New York, bitcoin rose as high as $79,607.
Bitcoin’s price spike came after news dropped that U.S. consumer prices accelerated in August, reinforcing expectations that the Federal Reserve will raise interest rates next week.
The consumer price index, excluding food and energy, climbed 0.3% in August from a month earlier, which was higher than expected.
Inflation in the U.S. has been difficult to tame due to the war with Iran, which has lifted oil prices, in turn raising the costs of food, gasoline and other goods.
Higher inflation typically means the Federal Reserve will raise interest rates, which in turn could stop bitcoin’s price climbing higher.
According to CME’s FedWatch tool, traders think there is a 85% chance interest rates will be higher by next week. The Federal Reserve will meet next week and reveal what it will do with borrowing costs.
Bitcoin has typically performed well in a low interest rate environment because it means people can buy more of the cryptocurrency with increased liquidity.
Federal Reserve Chairman Kevin Warsh, who took the helm in January, last month gave his first speech as head of the U.S. central bank and said he had “more work to do” to fight inflation.
The U.S. is currently in the grips of an affordability crisis and rising oil prices are a hot topic ahead of the midterm elections.
U.S. President Donald Trump has reassured voters that prices will get under control and repeatedly put pressure on the central bank to lower interest rates.
Bitcoin in August had its biggest run in years following positive regulatory news and an announcement from the U.S. Treasury.
Treasury Secretary Scott Bessent announced the department would double the size of its long-dated bond buybacks, helping non-yielding assets like bitcoin and gold. The cryptocurrency then benefited from President Trump urging lawmakers to get key crypto legislation, the Clarity Act, over the line.
This post Bitcoin Price Spikes, Shrugs off Hot US Inflation Data first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Cross-chain protocol Symbiosis said it recovered approximately 15 BTC after an attacker exploited its native Bitcoin Bridge, but affected liquidity providers still lack compensation terms as a Sep. 13 bounty window nears its unspecified cutoff.
The vulnerability was exploited at about 04:28 UTC on Sep. 11, according to the protocol's incident statement. Symbiosis said only the Bitcoin Bridge was affected and that its other routes and components remained operational. It specifically listed routes spanning EVM chains, TRON and TON as unaffected, and said its relayer group continued operating to secure the network. The protocol said the recovered bitcoin is secured in a team-controlled multisig.
The 15 BTC figure is simply the amount Symbiosis says it recovered to date. The protocol said final accounting remained in progress and that it would publish confirmed figures in another update.
Security firm Blockaid reported that a transaction accepted as signed by Symbiosis's BridgeV2 system minted approximately 2^62 raw units of syBTC, a synthetic representation of bitcoin, to a newly created wallet on BNB Chain.
Blockaid said the same beneficiary sold about 4.39 WBTC on Ethereum, realizing roughly $336,000 in WBTC proceeds at the time of its alert. That figure covers value Blockaid observed the attacker convert. It does not establish Symbiosis's final loss or the total exposure of liquidity providers.
Symbiosis initially said Bitcoin-related swaps were unavailable while it deployed updates. In a later operational update, the protocol said Bitcoin swaps routed through partners Chainflip and THORChain were back online, while the native Symbiosis Bitcoin Bridge remained paused.
That distinction determines what users can access. Partner-routed Bitcoin swaps are available, according to Symbiosis, but the protocol has not announced the return of the affected bridge. The split keeps traffic off Symbiosis's paused bridge while users access alternative Bitcoin routes.

Symbiosis said it was contacting every affected liquidity provider directly and building a compensation framework, with criteria to follow. It has not disclosed who will qualify, how compensation will be calculated or when payments could begin.
The protocol also offered the attacker a 20% white-hat bounty through Sep. 13. After that window, Symbiosis said the same percentage would be offered to anyone providing information that leads to recovery. The statement did not specify an exact cutoff time or timezone.
Affected liquidity providers are now waiting for three disclosures: confirmed loss and exposure figures, compensation criteria, and any change to the native bridge's status. Until Symbiosis publishes that information, the recovered funds and Blockaid's proceeds estimate should not be treated as a final loss tally.
The post Hackers mint trillions in fake Bitcoin, but 15 BTC bridge recovery leaves liquidity providers unpaid appeared first on CryptoSlate.
In decentralized finance, “audited” is often presented as a verdict on an entire project. In practice, an audit usually covers named code, components and versions at a particular point in time. Anything added, excluded or operated around that boundary may carry a different level of assurance.
A new preprint puts a number on that gap. Researchers affiliated with security company ack3 and the Czech Technical University in Prague examined 135 reported incidents from the first half of 2026, with $939.86 million in attributed losses. They found identifiable public pre-incident audits for 68 incidents.
Within that 68-incident subset, the authors classified 46 attack paths as outside every audit scope they could identify, 20 as inside at least one scope and two as unresolved. The outside-scope group represented 67.6% of the incidents but 94.4% of their reported losses.
That striking percentage is not an estimate of audit effectiveness or proof that an audit’s boundaries caused a loss. It describes the distribution of losses in a selected set of reported incidents. Two large cases also dominate it: after excluding $292 million at Kelp DAO and $285 million at Drift Protocol, the outside-scope share falls to 72.1% of losses in the same audited-incident subset.
Even with those limits, the study exposes a basic assurance problem. A project may truthfully say it was audited while leaving users unable to tell whether the live system, the path holding their funds and the controls around it were reviewed.

The ack3 dataset covers incidents from Jan. 1 through June 29. Its authors graded 122 as confirmed and 13 as likely. Of the full set, 35 had no identified audit and 32 had an unknown audit history, so neither group appears in the 68-incident scope calculation.
For that 68-incident group, outside-scope incidents accounted for $680.97 million of $721.24 million in reported losses, producing the 94.4% figure. Removing Kelp DAO and Drift Protocol left $103.97 million of $144.24 million outside scope, or 72.1%. The machine-readable ledger reproduces the bucket counts and loss sums.
The inside-or-outside labels remain the researchers’ judgments about public evidence. They searched project and auditor archives, located pre-incident reports and compared the eventual attack paths with reviewed code, versions and exclusions. The work is a six-page preprint produced with the dataset publisher, and two authors are affiliated with ack3, which sells security reviews.
The study also lacks an unexploited comparison group and a measure of how long each system was exposed. It cannot establish whether audited protocols are safer overall, estimate incident probability or show that falling outside scope caused each loss. Undisclosed audits and private incidents may be missing, while reported loss figures are not perfectly comparable.
The study therefore supports a limited conclusion: audit history and audit scope are different variables. A reviewed smart contract does not automatically confer the same assurance on an upgrade, privileged key, front end, relayer, oracle, cloud service or incident-response process.
Two incidents from August illustrate that distinction in different ways. ICON Network provides a direct example of reviewed code failing at the boundary between two checks. The August aelf incident provides a contrasting case because the available audit evidence cannot yet be tied to its reported runtime path.
In ICON Network’s Aug. 27 replay exploit, two parts of a withdrawal path interpreted the same message differently.
According to the ICON Foundation’s Aug. 30 postmortem, a migration contract used the high bits of a withdrawal message’s serial number to decide whether it was unique. The cryptographic signature covered only the low 256 bits. By changing the unsigned high bits, an attacker resubmitted two legitimately signed withdrawal messages 1,492 times over about 20 minutes. ICON said 1,490 calls succeeded.
The replays released 119.866 million ICX and 531,600 bnUSD. At the time of the postmortem, ICON put the confirmed net loss at about 150.2 ETH plus 31,204 USDC. It said 531,600 bnUSD and 1.366 million SODA had been recovered and that user deposits, balances and positions were not affected.
ICON said the migration contract had undergone an external audit and that recommendations had been implemented, including changes in the same area. It also said the relevant relay logic received a dedicated review. The SODAX audit archive lists eight reports across different components, including a November 2025 relay audit.
Yet the postmortem said the precise mismatch between the uniqueness check and the signed value fell outside those findings. A project-level badge could not tell a user whether both ends of the withdrawal path agreed on what made a message unique.
The response timeline adds a second kind of boundary. ICON’s first automated alert fired at 02:08 UTC, about seven minutes after the exploit began. Staff opened an investigation around 03:40, paused the affected contract at 03:53 and halted the network at 06:18:54.
ICON attributed the roughly 90-minute gap between the first alert and a full incident response to alert tuning. The alert class had produced false positives during unrelated connectivity incidents and did not page the on-call team at the needed severity. The foundation said it planned an automatic shutdown trigger, lower circuit-breaker thresholds and a follow-up review focused on message uniqueness and replay guards.
Those controls do not replace an audit. They provide evidence for a different question: when prevention fails, how quickly can detection become containment?
| Public assurance | The question users still need answered |
|---|---|
| “Audited” | Which repository, commit, deployed address and component were reviewed? |
| “Findings fixed” | Were the fixes deployed, and what changed afterward? |
| “Monitored” | Which alerts page a human or stop the affected path automatically? |
| “Funds recovered” | Which assets are confirmed recovered, frozen, exposed or still under investigation? |
aelf’s August incident tests the argument from another direction. Its public record describes a runtime compromise and a controlled recovery, but it does not provide enough evidence to place the path inside or outside a specific pre-incident audit.
The company announced a network pause on Aug. 18. In its Aug. 26 progress update, aelf said an unauthorized smart contract could use transaction parameters to deliver encoded .NET assemblies and instructions into the node execution path.
The provisional account linked the incident to gaps in checks for runtime reflection and dynamic loading, together with weak isolation between contract execution and sensitive node or infrastructure resources. aelf identified 155 associated transactions and five unique payload assemblies with capabilities including host command execution, attempted outbound communication, node-key access and infrastructure reconnaissance.
Capability is not the same as confirmed execution. aelf said the payloads did not prove that every assembly ran, that every targeted credential was obtained or that sensitive data left its systems. The company said it was rotating signing keys and infrastructure credentials under a potential-exposure standard.
The public status remained provisional on Sept. 11: aelf’s blog index contained no incident-specific item published after Aug. 26. The Aug. 26 statement committed to another update and an eventual final review.
aelf’s standing security documentation says its blockchain and ELF token contracts underwent multiple audits with no security issues identified. But the available pages do not connect a specific pre-incident report to the runtime path described in August. Calling the incident either an audit miss or an outside-scope failure would therefore outrun the evidence.
That uncertainty is itself useful. A dated audit history can become detached from a system’s current code, dependencies and operational state. Users need an assurance record that is versioned and specific enough to reveal that drift.
Such a record should name the reviewed repository and commit, deployed addresses, excluded components, privileged roles and dependencies. It should also record upgrades since review, key custody and rotation, runtime isolation, alert and circuit-breaker behavior, and dated recovery status that separates confirmed loss from frozen or unresolved exposure.
This does not reduce the value of an audit. It makes the claim proportional to the work performed and connects that work to the system operating now.
An audit badge cannot answer whether the reviewed artifact, the deployed system and the machinery that responds to failure still share the same security boundary.
The post Audited DeFi protocols lost $885M to attacks that occurred completely outside their audit scopes appeared first on CryptoSlate.
Coinbase’s new partnership with payments platform Moov gives community banks and credit unions a route to offer stablecoin services through the financial relationship they already have with businesses. The local institution can remain the customer’s front door, while Coinbase supplies the disclosed custody and transaction infrastructure behind it.
Moov CEO Wade Arnold framed the demand bluntly: business customers asked to accept stablecoins currently go outside their primary financial institution. Moov and Coinbase want that service to appear inside the institution’s existing payments experience. The arrangement could preserve the bank’s customer connection. Control of the economics, data and operational risk remains unresolved until the companies disclose their terms.
Under the partnership announced Sept. 10, Moov will integrate Coinbase’s stablecoin payments infrastructure into its existing platform for financial institutions. Coinbase said its CDP Custodial Wallet accounts will provide fund custody and its Payments API will orchestrate stablecoin movement. Moov will connect those functions to the systems used by its bank and credit-union customers.
That division places three parties between a business and the stablecoin rail. The bank or credit union owns the primary customer interaction. Moov supplies the payments-platform connection. Coinbase provides the announced crypto custody and movement components. The customer may experience one bank-facing product even though the underlying service spans multiple providers.
Coinbase’s announcement said Moov has a customer base of more than 1,000 community banks and credit unions. The figure describes Moov’s potential distribution footprint. Live, contracted and pilot institutions remain unquantified, and the companies gave no implementation timetable.
| Disclosed | Undisclosed | Decision it affects |
|---|---|---|
| Coinbase supplies custodial accounts and stablecoin movement tooling | The ownership and settlement configuration for each institution | Where balances sit and who directs key operations |
| Moov embeds the tools in its financial-institution payments platform | The number of live, committed or pilot banks | Whether distribution reach becomes adoption |
| The bank remains the customer-facing institution | Fees, revenue sharing, data rights, compliance duties and liability | Whether the bank retains economics and practical control |

The disclosed architecture gives Coinbase a material role behind the interface. Its standard payments documentation describes a custodial-account stack in which crypto can enter an account, be held and reconciled there, and leave through fiat or crypto transfers. Separate custodial wallet documentation says Coinbase provides custody for assets in those accounts on behalf of the CDP entity.
Those documents cover Coinbase’s standard platform. The partnership record leaves each institution’s supported stablecoins, networks, custodial-balance ownership and fiat-settlement route unspecified. It also leaves fees, revenue sharing, transaction-data access, compliance allocation and liability out of public view.
The result is a split form of control. Community institutions can keep the account relationship and present the service to customers. Coinbase and Moov remain essential to the disclosed technology chain. The bank’s economic and operational leverage will turn on its authority over pricing, settlement destinations, customer data and risk decisions. Coinbase holds a material infrastructure role within a payment chain that also depends on Moov and participating institutions.
A bank-facing interface leaves the payment stablecoin’s legal status unchanged. Customer protection and bank balance-sheet exposure follow the legal claim represented by the balance.
In an April 2026 proposed rule, the Federal Deposit Insurance Corporation said deposits held at banks as reserves for a payment stablecoin would be insured as corporate deposits of the stablecoin issuer, subject to applicable limits. Stablecoin holders would receive no pass-through deposit insurance under the proposal.
The same proposal draws a boundary around tokenized deposits. An instrument that meets the statutory definition of a bank deposit remains a deposit regardless of the technology or recordkeeping used. A payment stablecoin and a tokenized deposit can therefore give customers a digital-dollar experience while representing different legal claims.
For a community institution, the distinction reaches beyond consumer disclosure. A qualifying tokenized deposit remains the issuing bank’s liability. Access to a third-party stablecoin can keep the payment experience inside a bank channel while the customer’s converted funds may cease to be a deposit at that bank.
Deposit effects remain conditional rather than following an automatic dollar-for-dollar path. A Federal Reserve analysis published in December 2025 said stablecoins can reduce, recycle or restructure deposits. The outcome depends on who buys them, what assets are converted and where stablecoin issuers place their reserves.
Domestic customers converting transaction-account balances can reduce deposits, especially when issuers hold reserves outside banks. If issuers keep reserves in bank deposits, more funding can stay in the system, though it may move from dispersed retail accounts toward concentrated, uninsured wholesale balances. The effect on any one community bank also depends on whether reserve money returns to that institution or is concentrated with larger custodial and settlement banks.
The Fed identified partnerships, custody services, settlement accounts and white-label infrastructure as possible ways banks can stay connected to digital payment flows. It also described a deeper structural tension: stablecoins may separate the payment relationship from the deposit-funded lending model that banks have historically used to serve households and businesses.
The Moov arrangement puts both possibilities in one product design. A bank may keep the customer conversation and gain a service that would otherwise require its own crypto stack. Coinbase may gain transaction and custody activity while customers access stablecoins through their primary institution. The destination of deposits and revenue remains unsettled.
The first bank deployments will provide the evidence missing from the announcement. Adoption counts will show whether Moov’s network converts into actual demand. Supported assets, account ownership and settlement paths will show whether stablecoin activity returns value to the same institution or routes it elsewhere.
Commercial disclosures will be equally important. Pricing and revenue sharing determine whether the bank earns from the new service or mainly supplies distribution. Data access and compliance responsibilities determine who can deepen the customer relationship and who bears the burden when monitoring or processing fails. Liability terms determine how operational control translates into financial risk.
Coinbase has offered community banks a bridge into stablecoin payments, with its custody and payment infrastructure underneath. That structure may stop the bank from disappearing from the customer’s view. The next test is how much of the payment relationship, balance-sheet value and decision-making power stays with the bank when the customer gains stablecoin access through it.
The post Coinbase gives community banks a stablecoin bridge while supplying infrastructure underneath appeared first on CryptoSlate.
Bitcoin payment processor BTCPay Server has warned that bots are probing exposed Lightning nodes for a potential route to administrative control.
The activity follows a separate critical BTCPay vulnerability that attackers exploited a month ago to obtain credentials protecting LND nodes and drain merchant wallets.
BTCPay subsequently disabled external access to LND, a widely used implementation of Bitcoin’s Lightning Network, in its standard Docker deployment. The project now says automated systems are targeting servers where operators manually restored that access, repeatedly calling an LND password-change endpoint.
The latest mechanism differs from the vulnerability exploited in August but could lead to a similar outcome: an attacker obtaining credentials that can control an LND node.
BTCPay said the opening appears during a short interval after LND restarts, while its wallet remains locked. During that period, the targeted password-change method does not require a macaroon, the credential LND normally uses to authorize administrative actions.
Older BTCPay LND wallets compounded the risk by using a shared default password. An attacker who could reach the interface before BTCPay’s internal unlocker could potentially submit that password first, replace it, and request an administrator macaroon that gives control over the node.
BTCPay has not reported a successful takeover through the newly observed activity or linked the bots to the attackers behind the August thefts.
The renewed probing extends a difficult security stretch for BTCPay, which acknowledged on Aug. 7 that attackers had exploited a vulnerability affecting all versions before 2.4.2. That flaw allowed unauthenticated attackers to obtain LND macaroon files and use them to move funds. BTCPay’s standard on-chain wallets were unaffected.
Days later, the project and its supporters offered a bounty equal to 10% of recovered bitcoin, capped at 3 BTC, then worth about $190,000. BTCPay also enlisted exchanges, blockchain analytics firms, and law enforcement in efforts to trace the stolen funds.
Version 2.4.4, released Sept. 7, now addresses the conditions behind the latest attack path. New LND wallets receive unique random passwords, while older installations using the shared credential are migrated and have their passwords rotated.

BTCPay’s standard reverse proxy also blocks unauthenticated wallet setup and unlock methods, closing the restart-time opening through its managed public network path.
Those controls cannot secure infrastructure operators configure independently. Administrators who created their own reverse proxy or otherwise exposed LND publicly can still bypass BTCPay’s protections.
BTCPay has urged administrators to install version 2.4.4 and remove manually exposed LND routes. A route-control change merged Sept. 11 provides a supported option for remote access while keeping LND and Core Lightning interfaces disabled by default.
That leaves custom deployments as the immediate concern. Operators using them must audit their proxy rules and migrate remote connections behind BTCPay’s managed controls while automated systems continue searching for reachable nodes.
The post Malicious bots are actively probing exposed Bitcoin payment servers to steal master administrative keys appeared first on CryptoSlate.
Ledger's status page continued to list Cosmos (ATOM) as a major outage on Sept. 13, leaving users unable to view ATOM balances or transaction history and unable to submit transactions through Ledger Wallet more than four days after the incident began.
The company opened the incident at 19:41 CEST on Sept. 8. As of press time, its latest update, posted at 16:12 CEST on Sept. 10, said restoration work was continuing and that the affected features remained unavailable. Ledger has not disclosed a cause or an estimated restoration time.
The continuing warning does not mean Cosmos Hub is still halted. It shows that Ledger Wallet's service path for retrieving account data and sending ATOM transactions has not recovered with the network itself.
QuickNode reported that Cosmos Mainnet stalled at block 32,878,318 at 18:12 UTC on Sept. 8. The infrastructure provider said its nodes had returned to the chain tip by 14:26 UTC on Sept. 9, then marked its incident resolved at 00:24 UTC on Sept. 12.
The Cosmos Hub RPC endpoint was above block 32.9 million on Sept. 12 and reported that the node was not catching up. That placed the chain tens of thousands of blocks beyond the height in QuickNode's initial alert.
Together, those readings separate two layers of the problem. Cosmos Hub resumed producing blocks, while Ledger Wallet access remained unavailable. Users may therefore see missing balances or history in Ledger Wallet even though the network is processing new blocks.

QuickNode's resolution applies to its infrastructure, while Ledger's separate incident remains identified. Those states can coexist because a wallet interface can stay unavailable after network nodes have caught up. Ledger has not said which part of its service path is responsible.
For users who need to move ATOM urgently, Ledger's incident notice points to its alternative-methods guide. The company lists Cosmostation and Keplr as compatible third-party interfaces that can connect to a Ledger device.
Ledger's Keplr instructions tell users to open the Cosmos app on their device and choose Keplr's hardware-wallet connection option. That route uses another interface to access the same blockchain account while keeping the Ledger device in the transaction flow.
The safety distinction is critical: connecting a hardware wallet is not the same as importing its recovery phrase. Ledger's security guidance says users should never enter the phrase into a computer or smartphone and should never share it, including with Ledger.
Users who do not need to transact urgently can continue monitoring Ledger's status page. Because the incident remains open and could change without notice, its status should be refreshed before any workaround is attempted.
The post Cosmos is back online after outage, but Ledger users still can’t see or send their ATOM appeared first on CryptoSlate.
Since September 11, 2026 a duty applies across the whole of the EU that did not exist in this form before: anyone who makes a product with digital elements available commercially on the European market must report an actively exploited vulnerability to the competent bodies within 24 hours and inform affected users about the vulnerability and about the countermeasures they can take themselves.
For you as a holder of cryptocurrencies, the second part is the more important one. It sits in Article 14(8) of the EU Cyber Resilience Act and shifts the question of who has to make sure you learn about a problem with your wallet. Until now that was a matter of company culture. From now on it is a legal duty with a fining framework behind it.
This article explains what exactly applies, from when, to whom, and where the line runs between the documented legal position and over-interpretation. Because the regulation does not name a single wallet brand, and anyone who derives a list of affected manufacturers from it is writing more than what is there.
The Cyber Resilience Act is Regulation (EU) 2024/2847, usually called the Cyber Resilience Act or CRA for short. The CRA entered into force on December 10, 2024, but only applies in full from December 11, 2027. Article 71(2) contains one sentence that upends the whole timetable: "This Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026, and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026."
Article 14 is headed "Reporting obligations of manufacturers" and is thus the part of the regulation that was switched on first. Everything else — the conformity assessment, the CE marking, the essential cybersecurity requirements in Annex I — only arrives in 2027. So anyone reading right now that the CRA applies means this one article.
The core in one sentence: a manufacturer must report every actively exploited vulnerability in its product and every severe security incident simultaneously to the CSIRT designated as coordinator and to the EU Agency for Cybersecurity, ENISA, through a single reporting platform.
What is a CSIRT? A Computer Security Incident Response Team is the body designated by a member state that receives, assesses and passes on security incidents. In Germany, CERT-Bund within the Federal Office for Information Security is the coordinating CSIRT, and the BSI also handles market surveillance.
What is an actively exploited vulnerability? A security flaw the manufacturer knows attackers are already using. A theoretical gap someone found in a laboratory does not start the 24-hour clock. Abuse in practice does.
The CRA is not financial law and not crypto law. It is horizontal product law and takes no interest in which assets a device manages, only in whether it is a product with digital elements and whether it is made available commercially on the EU market. That is precisely what makes it relevant for crypto custody.
A hardware wallet is a physical device with firmware that talks to companion software over USB, Bluetooth or QR code. A wallet app is software a provider makes available for download. By their design, both are what Article 3(1) describes as "a software or hardware product and its remote data processing solutions". Article 2(1) draws the boundary via the connection: the regulation applies to products whose intended purpose or reasonably foreseeable use includes "a direct or indirect logical or physical data connection to a device or network".
For the custody of cryptocurrencies, that is the point at which something changes. If you hold your balance yourself, your security hangs on exactly two things: on the quality of the device or the software, and on whether you find out in time when something is wrong with it. On the first, the reporting duty still says nothing; the corresponding requirements only bite in 2027. On the second, it says something with immediate effect. Which devices are available at all and how they differ is in our hardware wallet comparison; for purely software solutions the same considerations apply with a different attack surface.
Whether a specific device or a specific app is covered is decided by three test steps. There is no list of affected products. First: is the product made available on the EU market, that is, supplied for distribution or use in the course of a commercial activity? Second: is it a software or hardware product within the meaning of Article 3? Third: does its intended or reasonably foreseeable use include a direct or indirect data connection?
A commercially distributed, connected hardware wallet and a wallet app offered by a company can satisfy these three questions. That is an application of the legal test and not an official finding for any particular product. Anyone who turns it into a claim that this or that provider must now do this or that is asserting something that neither the regulation nor the Commission's guidelines supports.
Where the manufacturer is based also matters. Article 14(7) regulates this in detail: what governs is the CSIRT of the member state in which the manufacturer has its main establishment in the Union, that is, where the decisions on the cybersecurity of its products are predominantly taken. If it has no establishment in the EU at all, an order of precedence applies: first the member state of the authorised representative, then that of the importer, then that of the distributor, and finally the member state in which the largest number of users is located. A provider outside Europe is therefore not automatically out of scope once it serves the European market.

The regulation requires three reports that build on one another. All deadlines start at the moment the manufacturer becomes aware.
For a severe security incident under Article 14(3) the same split into 24 and 72 hours applies, but there the final report is due one month after the 72-hour notification. When an incident counts as severe is defined in paragraph 5: when it affects the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive data or functions, or when it has led or can lead to the execution of malicious code.
Reporting runs through the CRA Single Reporting Platform operated by ENISA. The manufacturer submits once, and the report is made available to the competent coordinating CSIRT and to ENISA at the same time. After the final report, the reporting person can as a rule no longer edit the submission.
The deadlines towards the CSIRT and ENISA are the part the industry press writes about. For you as a user, the decisive sentence sits elsewhere, namely in Article 14(8). Slightly abridged, it reads: after the manufacturer has become aware of an actively exploited vulnerability or a severe security incident, "it shall inform the affected users of the product with digital elements, and where necessary all users, about that vulnerability or incident and, where necessary, about any risk mitigation and corrective measures that the users can deploy".
Three points in this are worth reading closely.
First: the duty attaches to the same awareness as the report to the authorities. The trigger is the same moment. For informing users, however, the regulation names no fixed number of hours. What is required is information in connection with becoming aware, and elsewhere the text turns on timeliness. Anyone who turns the 24 hours for the authority into a 24-hour deadline towards customers is reading the provision wrongly.
Second: users must be informed about the countermeasures they can take themselves. That is the practical core. A notice that merely says there was a problem does not satisfy the wording if there are measures users can take themselves. With a wallet, those measures are precisely the relevant ones: update the firmware, temporarily stop using a particular function, move a balance to a new address, check a signature manually before confirming it.
Third: the regulation would like a machine-readable format. The text speaks of a structured, machine-readable format that is easy to process automatically, and qualifies this with "where appropriate". For security researchers and for portals that aggregate warnings, that is the most interesting wording in the whole paragraph.
The second sentence of paragraph 8 is the genuinely new lever: "Where the manufacturer fails to inform the users of the product with digital elements in a timely manner, the CSIRTs designated as coordinators may provide such information to the users when they consider it to be proportionate and necessary for preventing or mitigating the impact of those vulnerabilities or incidents."
European law thereby states that an authority may inform the public about a product vulnerability if the manufacturer does not do so in time. For Germany that means, concretely: CERT-Bund at the BSI receives the report as coordinating CSIRT, and the BSI can act as market surveillance authority. That is not an obligation to warn; the wording is "may" and turns on proportionality and necessity. For you it nevertheless means that from now on there is a second place at which information about a product you use comes together.
A look at the cases of recent weeks shows that this route is needed. When a vulnerability in a Bitcoin Lightning implementation became public in August, the information for operators hung on a release note and on trade media. We worked through that case in our article on the Core Lightning vulnerability and the question of when a node has to go offline. How a wallet warning can be technically verified at all is in our article on blind signing and how to switch it off on your hardware wallet.
Here is the qualification that belongs in every honest text on this subject. Neither the regulation nor the European Commission's guidelines names a single wallet brand, a single device type from the crypto world, or any particular provider. The CRA works with abstract product categories and a legal test that every economic operator has to carry out for itself.
Two things follow from that. For one, you cannot read from the regulation whether a particular device you own is covered. That depends on how the manufacturer is organised, where it is based, how it distributes, and how the competent authorities apply the legal test in the individual case. For another, over the coming months you will read texts that fill this gap with names. Anyone writing that a specific provider "now has to" do this or that is formulating a legal assessment for which there is neither an administrative decision nor a court ruling.
The only reliable thing at this point is the procedure. If such a statement interests you, check two things. Is there a manufacturer's own declaration behind it, or a statement by an authority? And does it refer to Article 14, which has applied since September 11, or to the conformity duties that only bite from December 11, 2027? The two are frequently conflated at the moment.

A large part of crypto infrastructure is open source and maintained by individuals, associations or foundations. For this constellation the CRA contains its own treatment, and that matters for what you can expect.
Free and open source software is, under recital 18, software whose source code is openly shared and whose licence provides for all rights to make it freely accessible, usable, modifiable and redistributable. What is decisive for the scope is the commercial character of the supply: according to the same recital, only free and open source software that is made available on the market, and thus supplied for distribution or use in the course of a commercial activity, falls within the scope. The mere circumstances of development and the type of funding are expressly not meant to play a role.
On top of that comes Article 64(10)(b). Under it, the fines regulated there do not apply to stewards of open source software, and that holds for every infringement of the regulation. It is one of the clearest privileges in the entire legal act.
For you as a user that means: with a wallet that arises as an open project without commercial supply, you should not count on anyone being legally obliged to notify you. With a device or an app a company offers commercially, the position is a different one, even if the source code is open. The question of who stands behind a product and how it is distributed was a good selection question before. From September 11, 2026 that question additionally has a legal side.
A duty without consequence remains an appeal. Article 64(2) sets the framework: infringements of the obligations laid down in Articles 13 and 14 are subject to fines of up to 15 million euros or, in the case of undertakings, up to 2.5 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. The reporting duty therefore sits in the highest of the three fining bands the regulation knows.
When setting the amount in the individual case, paragraph 5 requires the nature, gravity and duration of the infringement to be taken into account, along with previous fines against the same economic operator and the size of the undertaking including its market share. Microenterprises and small enterprises are expressly mentioned.
For them there is an additional relief. Article 64(10)(a) exempts manufacturers that qualify as micro or small enterprises from the fines regulated in paragraphs 3 to 9, insofar as the missed 24-hour deadline under Article 14(2)(a) or Article 14(4)(a) is concerned. The reporting duty itself does not fall away as a result, only the sanction for missing that one deadline. For a small wallet startup with three developers and no on-call rota, that is the difference between a demanding provision and an existential one.
Enforcement lies with the market surveillance authorities of the member states. In Germany, the BSI is designated for that. A fine imposed must be communicated by the authority to the market surveillance authorities of the other member states through the information system under the Market Surveillance Regulation.
Article 14 applies to all manufacturers of products with digital elements, irrespective of a risk class. Beyond that, the regulation knows two annexes that list particularly sensitive products, and their legal consequences only bite with the full start of application on December 11, 2027. A look at them is worthwhile all the same, because it shows how the legislator thinks about this type of device.
Annex IV lists three entries under the heading "Critical products with digital elements": hardware devices with security boxes; smart meter gateways as well as "other devices for advanced security purposes, including secure cryptoprocessing"; and smartcards or similar devices, including secure elements. Annex III names, in class I, among other things microprocessors and microcontrollers with security-related functionalities, and in class II tamper-resistant microcontrollers.
Those are exactly the components a hardware wallet is built from: a secure element, a tamper-resistant microcontroller, a shielded environment for cryptographic operations. Whether a particular device falls under one of these entries is again decided case by case. The direction is recognisable, though, and for manufacturers of such devices it means a stricter conformity assessment from the end of 2027, one in which a notified body can be involved.
The regulation addresses manufacturers. You do not have to act because of it. But there are four things that are more informative from now on than they were before.
You will find the official wording of the regulation in the Official Journal of the EU as Regulation (EU) 2024/2847, German-language text; Article 14 sits in Chapter II, the start of application in Article 71(2). The German reporting route including a table of deadlines is described by the BSI on its page about the CRA Single Reporting Platform.
(As of September 13, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
If you kicked off a swap through Chainflip over the weekend and nothing has arrived since, the problem is almost certainly not your wallet. The network has been at a standstill since Saturday. On September 12, 2026 an attacker drained 736,442.17 USDT through the protocol's Tron rail, and Chainflip switched off trading in response. What matters for you: your balance has not disappeared, but you cannot reach it at the moment either. This article explains what is measurably switched off, what is still running, and in which order to check your holdings.
Chainflip is a swap protocol that moves value between different blockchains. In the early hours of Saturday, September 12, 2026, an attacker drained 736,442.17 USDT from the protocol's settlement path on Tron, according to the matching accounts of two trade publications. The incident only became apparent when subsequent USDT payments failed. The team then halted network operations.
The attack ran for roughly 90 minutes. According to the account given by crypto.news, there were eight attempts, six of which resulted in a payout. The amounts escalated: on that analysis, each further attempt was roughly double the previous one. Chainflip says it has fixed the flaw, flagged the drained funds and announced that affected users will be made whole after the restart. At the time of writing, the restart was announced for Monday at the earliest.
736,442.17 USDT was drained. Only settlement on Tron is affected. A further, still open swap by one user worth 115,654.41 USDT sits unpaid in the protocol's holdings according to both sources and is considered eligible for reimbursement. For the remaining networks, neither report records any losses.
A cross-chain swap is a trade in which you deposit on one blockchain and are paid out in a different currency on another. Classic bridges solve this by locking up your bitcoin and issuing you a placeholder on the target chain, a so-called wrapped token. Chainflip works without such placeholders: a network of validators holds the funds jointly and pays out the real asset on the target chain.
For you as a user, normal operation means this: you are given a deposit address, you send your amount there, and after a few minutes the swapped asset is in your wallet on the target chain. There is no account, no sign-up and no self-custody during the process. That very design is why a standstill of the protocol affects you directly: there is no customer interface in which you could simply withdraw your funds.
On most supported networks, Chainflip reads the swap instruction from a contract call. On Tron, according to the technical account by crypto.news, it works differently: there the protocol evaluates the memo field of a transfer, a free text field that can be attached to a transaction.
On that account, the attacker attached a further memo to a transaction the validators had already signed. The system read this addition as an independent second swap instruction. When that second instruction appeared to fail, the protocol paid out a refund even though the original deposit had already been served. The core of the incident is that a signature stays valid while the readable content beside it can still be changed.
One point that appears in both reports matters for context: no private key was stolen and no custodian was opened. The payouts came out of the protocol's regular process, triggered by an instruction the protocol took to be genuine.

cryptoticker.io collected this analysis itself on September 13, 2026. Chainflip reports its network state in a public programming interface that anyone can query. We queried it between 15:53 and 15:56 UTC with seven calls, each with a logged response code, and additionally checked the provider's quote service on four swap routes.
The result is unambiguous. The section for the swap business reports three switches set to "off": swaps are switched off, deposits are switched off, withdrawals are switched off. The same applies to liquidity providers on all three counts. The provider's quote service answered with code 503 on all four routes tested, meaning "service unavailable": bitcoin to ethereum, USDC from Ethereum to USDT on Tron, the reverse direction from USDT on Tron to USDC on Ethereum, and Solana to bitcoin.
More interesting than the switched-off items is what is not switched off. The return of network shares in the funding area is set to "on". Liquidity providers may continue to adjust their quotes. Validator rotation and the registering and deregistering of bids are running. Registration of new brokers is open too.
The blockchain itself is also running undisturbed. The network node reported 36 peers and no sync in progress. Two calls of the block head 137 seconds apart returned the heights 14,801,511 and 14,801,534, so 23 new blocks and thus the usual six seconds or so per block. The network is producing; it is only not trading.
Also readable from the interface: Chainflip currently supports 18 assets on seven networks, among them Bitcoin, Ethereum, Solana, Arbitrum, Polkadot, Assethub and Tron. For Tron the minimum deposit is 30 TRX or 10 USDT.
Two limits of this measurement belong with it. First, it cannot be established from outside whether individual stuck swaps will be completed automatically after the restart. Second, the number of affected users is not measurable, and Chainflip has published nothing on it. The figure of 115,654.41 USDT for the open swap comes from the reporting and not from our query.
The state we measured is not an outage but an intended operating mode. The protocol can switch off individual functional areas without halting the blockchain. That is exactly what has happened here, and the choice of switches says something about the situation.
That withdrawals were switched off as well is the most uncomfortable part for you. It means that even a completed swap whose proceeds still sit in the protocol will not move to you at the moment. At the same time it is the measure that prevents a second drain over the same route for as long as the cause is not conclusively closed. That liquidity providers can still adjust their quotes suggests a restart of trading is being prepared rather than a wind-down of the protocol.
For your own course of action, a simple rule follows: waiting is the right move in this situation, and sending more is the wrong one. Anyone who now sends funds to an old deposit address only lengthens the list of cases that have to be worked through after the restart.
Work through the points in order. The order is not arbitrary: the first two steps cost nothing and establish whether you are affected at all.
Every swap carries its own identifier, which the interface showed you when you started it. Enter it in the provider's block explorer. It shows the state the case is stuck in: at the deposit, in the swap itself, or before the payout. If you cannot find your case there at all, it was never accepted, and the funds are still on the source chain.
Look up the transfer you deposited with in the explorer of the source chain. Two cases need to be told apart. If it is confirmed and has arrived at the deposit address, your amount sits in the protocol and you are waiting for the restart. If it is unconfirmed or was never sent, nothing has happened and you can swap elsewhere.
Look in the wallet you gave as the destination, and on the right chain. A common misconception is that the proceeds arrived long ago but the wallet does not display the target network at all. USDT on Tron does not show up if your wallet only carries the Ethereum version.
The restart date and the question of whether stuck cases will be completed automatically are decided at the provider. Stick to its own channels. In the week after an incident like this, fake offers of help asking for your recovery phrase pile up. A reputable provider never asks for it. If you want to keep your keys on your own device anyway, the devices are set side by side in our hardware wallet comparison.
The deposit addresses of a protocol like this are tied to a single swap order and valid only for a limited time. Our measurement shows that the deposit path is switched off as well. A transfer to an address from an old order is therefore not being processed at the moment.
On the blockchain, the amount is then gone from your wallet all the same. It sits at an address you do not control, and whether and when it gets assigned depends on the provider. That is why this point gets a heading of its own here: it is the one mistake that can turn a waiting period into a genuine loss.

According to the matching accounts of both trade publications, Chainflip has announced that affected users will be made whole once operations resume. The wording is clear, the path there is not: which source the reimbursement will come from was open at the time of the reports. Reserves, ongoing protocol revenue and insurance solutions are named as options under review.
For you that amounts to a promise without a date and without a procedure. So secure now what will count as evidence later: the identifier of your swap, the transaction number of the deposit, the time, the amount and, if available, a screenshot of the interface. Anyone who has to gather these records only after the restart is worse off than someone who filed them the same day.
Part of the context is also what the promise is not. It is not statutory deposit insurance. A decentralised swap protocol is not covered by the protection you know from a bank account, and a promise in an announcement is something other than an enforceable claim.
Many users never encounter protocols like this under their own name. Wallets and swap aggregators integrate them in the background and route your order to whichever path currently offers the best rate. It is therefore quite possible that you are affected without ever having consciously chosen the brand.
The proof runs through the history. Open the order history in your wallet or in the service you swapped through and look at the case in question in detail. It usually shows the route used or at least the deposit address, which you can trace further in the block explorer of the source chain. If the entry stays unclear, customer service at the service you swapped through can help, because there you are the customer.
A memo is a free text field that many chains can attach to a transfer. Exchanges have used it for years to assign incoming payments to the right customer account. For protocols it is convenient, because it works without a contract of its own and is therefore quick to connect to a new network.
The price of that convenience is that free text has no fixed form. A contract function enforces structure and can be secured together with the signature; an attached text is, to begin with, only text. The attack described here exploited exactly that gap between what was signed and what was read.
What you take from it for your own practice is independent of this provider: if a service asks you to send a memo or a tag along, that field is part of the transfer and not decoration. A deposit without the required memo regularly ends up in no man's land and has to be assigned by hand. Chainflip itself has been expanding the Tron rail lately; the most recent post on it in its own blog is dated September 10, 2026 and promotes USDT on Tron as collateral in lending. At the time of our check on September 13 the blog did not yet carry a post on the incident; according to both trade publications the quoted statements come from the short message service X.
The case fits into a series. On September 6, 2026 around 4,000 bitcoin left the Liquid Network's federation wallet, and the sidechain was subsequently missing the bulk of its backing; we recalculated the backing of L-BTC at the time. In August it was the Sandbox project's bridge. Now it is a swap protocol without placeholder tokens.
The common feature is not the design, which differs considerably in all three cases. The common feature is the place: wherever one chain has to believe another about what happened on it, a translation arises. A translation can be read wrongly, and whoever gets it read wrongly takes money out without ever having held a key.
No panic follows from that, but a sober everyday rule does: the transition between two chains is a place for short stays. Value you want to hold for longer belongs on the chain where it is at home, and in custody whose keys you control yourself. A swap protocol is a passage, not a warehouse.
Three steps, in this order, and none of them takes longer than a few minutes.
The second independent account of the incident this article draws on is at The Crypto Times.
(As of September 13, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
If you keep Zcash in a shielded address, there is a fair chance that since late July your balance has been sitting in a part of the blockchain the network has decommissioned. Checking takes a few minutes: bring the wallet up to the current version, let it sync fully, and see whether the app reports a migration in progress. While one is running, do not send your full balance anywhere.
The background is unusual. On July 28, 2026, Zcash brought a new shielded pool into service and sealed the old one at the same moment. Around 3.66 million ZEC were sitting in it at that point, the equivalent of about 1.7 billion US dollars according to CoinDesk. The network does not move that money on its own; every owner triggers the transfer in their own wallet. Anyone who has not opened their wallet since then has simply not triggered it.
The network upgrade goes by the name Ironwood and took effect at block height 3,428,143. We retrieved that block ourselves on September 13, 2026 through the public interface of Blockchair: it carries the timestamp July 28, 2026, 14:07:23 UTC. Since then the chain has been running with two shielded areas side by side, the old Orchard pool and the new Ironwood pool.
For you, none of this changes anything about your keys. You need no new address, no new seed phrase and no token swap. According to the technical specification, the key material you have been using to access shielded amounts applies equally to both pools. What changes is where your balance sits, and the route by which it gets there.
That route is called the turnstile. Every amount has to pass through it individually, and every passage is triggered by the wallet holding the funds. There is no switch in the protocol that moves all balances across at once.
A shielded pool is the part of the Zcash money supply whose amounts and participants sit encrypted in the blockchain and are readable only with the matching key. Its counterpart is the transparent area, where addresses and amounts lie open as they do with Bitcoin.
In practice you come across two kinds of address. A transparent address begins with a t and behaves like an ordinary crypto account. A shielded address begins with a z and conceals both amount and counterparty. Only the second case is affected by this migration.
Zcash has renewed its shielded technology several times over the years. Sprout from 2016 was followed by Sapling in 2018, Orchard was added in 2022, and Ironwood has existed since July 2026. Each of these stages is a pool of its own with its own bookkeeping, and balances do not move between them by themselves.
For everyday use that means your wallet can hold amounts in several pools at once without you noticing. The balance shown adds them together. Only when a pool is decommissioned does it become apparent that the total is made up of parts.
The trigger was a discovery by security researcher Taylor Hornby. As CoinDesk reported it, the proving circuit of Orchard contained a flaw that would have allowed counterfeit ZEC to be created without leaving any trace of it in the blockchain. On that account the flaw had been in the code since Orchard launched in May 2022, so for around four years.
The gap was found before it was demonstrably exploited. No damage has been evidenced so far. That, though, is exactly the problem with a weakness of this kind: a counterfeiting operation that leaves no trace also cannot be ruled out after the fact. So matters did not stop at fixing the flaw. The project rebuilt the entire bookkeeping of the shielded area from scratch.
The reasoning is set out in the specification of the upgrade. The purpose of NU6.3, it says there, is to strengthen confidence in the integrity of the Zcash money supply following the remediation of the Orchard vulnerability. The turnstile, it continues, ensures that the total supply remains bounded. Since a substantial share of all ZEC was sitting in the Orchard pool at the time of the fix, the move into a new pool was necessary.
At the core of the procedure is a reversal of the burden of proof. Everything that crosses into Ironwood through the turnstile is recorded openly and can therefore be reconciled. Whatever potentially counterfeit holdings may have arisen in Orchard stay there and do not come across.
Ironwood additionally brings a property that reaches beyond the present occasion: the specification names the recoverability of balances in the event that powerful quantum computers break today's cryptography. For holdings in the old pools, that protection expressly does not apply.

A turnstile is a crossing between two pools in which the amount being moved sits openly in the blockchain, so that anyone can reconcile the total supply. Inside a pool, amounts stay hidden. When crossing between two pools, they become visible.
How a wallet is to carry out this crossing is governed by the document ZIP 318, titled "Orchard to Ironwood Migration". It describes no button for you to press, but a schedule your wallet works through. That distinction explains most of the confusion that has grown up around the migration.
At the level of the consensus rules, something has shifted in parallel that barely shows up in everyday use but explains why the old pool is described as sealed. Since the upgrade, outputs into the Orchard pool may only go to addresses for which the creator of the transaction can authorise the spend themselves. Translated: the old pool no longer accepts payments from third parties. It can only be emptied.
The check works much the same way in every serious Zcash wallet. It costs you a few minutes and a look at the version display.
A wallet that does not know the new pool cannot move to it either. Cake Wallet, for one, introduced support for Ironwood in version 6.4.0 according to its own documentation. Check your app's version number before you do anything else. Which software is suited to which purpose at all is broken down in our comparison of software wallets.
Shielded balances are detected locally, by the wallet scanning through the blockchain. Before that sync is complete, your app does not reliably know which pool your money is in. After a longer break, this can take quite a while.
Wallets that support the transfer display it, usually as a progress indicator or as a notice in the account area. If you find nothing there and your balance is fully available, it is already in the new pool. If the app reports an operation in progress, you are one of the people who still has something in transit.
Two things should be made clear at this point, because scams form around every migration. There is no official website on which you have to enter your seed phrase to rescue your balance. And there is no support agent who will ask you to do so. The entire process runs in your wallet and without outside involvement. If you hold larger amounts, the question of custody is the more important one anyway. Our hardware wallet comparison shows which devices keep the key away from the computer.
Anyone expecting one click to be enough and the matter to be settled after two confirmations will be disappointed. The transfer drags on for hours or days, and that is by design.
The reason lies in the visibility of the turnstile. A single crossing with an odd amount would be a fingerprint by which a wallet could be recognised again over time. ZIP 318 counters that with three precautions your app implements in the background.
First, the wallet breaks your balance into fixed denominations. Permitted are amounts of the form one, two or five times a power of ten, so 100, 50, 20, 10, 5, 2, 1 or 0.5 ZEC for example. Each of these partial amounts goes through the turnstile as its own transaction and thereby merges with the partial amounts of many other users.
Then it spreads those transactions over time and draws the cryptographic anchors from network-wide uniform boundary heights. This creates groups of users whose crossings blend together. Finally, the specification separates syncing from sending: a wallet may not do both in the same background session, because otherwise an observer could connect the two.
In practical terms, that means your balance appears split for a while. Part of it is already in the new pool, part still in the old one. This is neither an error nor a loss, but the normal state during the transfer.
The transfer only makes progress while the wallet is open and synced. Close it and the transfer pauses. The specification is explicitly reserved on this point: background execution is to be attempted on a best-effort basis at most, and wallets are not obliged to send a crossing without user involvement. Anyone who opens their app once a month extends the process accordingly.
Cake Wallet's documentation expressly advises waiting with a payment until the migration is complete, and that applies particularly to any attempt to send the whole balance at once. During the transfer, parts of your balance are tied up in prepared transactions. A payment for the full amount can therefore fail or throw the schedule out of order.
This point is the one most likely to be overlooked. Under ZIP 318, a running migration need not be resumable on another device, nor after a restore from the seed phrase. A wallet that discovers unspent Orchard holdings after such a restore may treat the situation as a new migration and start over. If you want to change devices anyway, let the transfer finish first.

How much is still outstanding can be quantified. The following values come from the third-quarter 2026 report by Pine Analytics, which shows the pool holdings week by week.
In five weeks, then, around 87 percent of the old pool has taken the route through the turnstile. In the final week of August, however, only 46,000 ZEC were added. What is left is evidently not a backlog that clears itself, but a residue of wallets nobody opens.
A comparison with earlier pool changes shows how unusually quickly the field was cleared. When Sapling launched in 2018, 8 percent of the predecessor pool had moved after five weeks and 54 percent after a year. With Orchard in 2022 it was 1.2 percent after five weeks. Anyone still in the old pool today belongs to a small minority, and nobody builds tools for small minorities any more.
The price gives a sense of the magnitude. We retrieved it on September 13, 2026 via the public price interface of CoinGecko: 1,093.69 US dollars or 941.86 euros per ZEC. The 470,000 ZEC remaining at month-end therefore correspond to around 443 million euros. For context: at the time of that retrieval, Zcash stood ninth among the largest crypto-assets with a market capitalisation of a good 18 billion US dollars, after a rise of 124.6 percent over 30 days and a fall of 7.9 percent over the last seven days.
The specification names the price of the procedure openly. The turnstile, it says, discloses the amounts moving between the pools, including the amounts migrated to Ironwood. So anyone bringing their shielded holdings across publishes their size in the blockchain.
Hence the denominations. If your balance goes through the turnstile in portions of 10 or 50 ZEC and thousands of other wallets use the same portion sizes, the individual crossing says little about you. A one-off crossing of 137.42 ZEC, by contrast, is a marker that can be found again later.
From this follows a recommendation that runs against the first impulse: do not take the process into your own hands. Anyone who grows impatient and pushes their holding across in a single large transaction saves a few days and gives up in exchange the amount concealment that is the whole reason for using a shielded address.
An important point of context: the vulnerability that was found concerned the bookkeeping, not the confidentiality. According to the specification there is no reason to assume that key material of existing addresses could have been compromised by it. Your old addresses have therefore not become insecure.
If you hold your ZEC at a trading venue, you have no access to the pool in any case. There, the provider decides in what form it holds customer balances, and it carries out its own transfer if it is affected. For you that is a question of provider quality, not a task.
Two points are still worth a look. Check on your provider's status page whether deposits and withdrawals for ZEC are open before you plan a withdrawal. And check whether your provider is still listing the coin at all. Privacy coins are under regulatory pressure in the EU, which we have broken down in our overview of the planned trading ban on privacy coins. Anyone who needs a second point of access just in case will find the regulated alternatives in our comparison of crypto exchanges.
When you bring holdings from a trading venue into your own wallet, they land there transparent or shielded depending on the type of address. Shielded incoming amounts go into the new pool today. Under the changed consensus rule, the old one no longer accepts payments from others.
In the short term, nothing happens. There is no deadline in the calendar on which Orchard holdings expire, and by all accounts the transfer is voluntary and user-initiated. Nor had the project named an announced shutdown date for the old pool as at September 13, 2026.
The direction is nonetheless unambiguous, and it is stated in the specification itself. It says there that recovery would not be possible for funds still located in the Sprout, Sapling or Orchard pools; all such funds would be inaccessible once the respective protocols are shut down. They should be migrated into the Ironwood pool in order to benefit from the new property. That is the phrasing of a technical document, and it describes a state that arises if the network one day switches off the old protocols.
On top of that comes a practical point that bites sooner than any shutdown. Tools, wallets and help pages follow the majority. With a residual holding of under three percent of the shielded supply, support for the old pool does not get better but worse. Anyone who can get the transfer done today with a progress bar might have to rebuild it by hand in two years.
In passing, because it coincides in time: a coin holder vote on the shape of the next network upgrade, NU7, is currently running, with a deadline of September 14, 2026 at 19:00 UTC. How to take part in it we have described in a separate article on the NU7 vote. That process has nothing to do with the pool migration; it merely lands on the same calendar.
The technical basis of this transfer is open to inspection. The rules for wallets are in ZIP 318, the changed consensus rules and the rationale for the upgrade in the ZIP 229 document on the version 6 transaction format. Both texts are technical, but they are the source every wallet relies on.
(As of September 13, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
For the current year, your crypto exchange will for the first time report to Germany's Federal Central Tax Office what you have bought, sold and swapped. That report, however, contains not a single figure describing your profit. What it contains are aggregated gross amounts per crypto-asset: the sum of your purchases, the sum of your sales and the market value of every swap from one cryptocurrency into another. Anyone who reshuffles thirty times a year shows up there with a volume that is a multiple of their own portfolio value, while what is left at year-end may be a three-digit gain.
The legal basis is called the Kryptowerte-Steuertransparenzgesetz, KStTG in officialese. It transposes the European DAC8 directive into German law and obliges providers of crypto-asset services to transmit data about their customers to a central federal authority, which passes it on to the tax authorities of the federal states. Under the application provision in Section 21 KStTG, these duties apply for the first time to the 2026 calendar year. The year now running is therefore the first one on the books.
This article explains which details the report contains, why the sums named in it are systematically larger than anything you have ever owned, and how to keep your own records so that they line up with that report.
The catalogue of details to be reported is set out in Section 11 KStTG and is surprisingly concrete. It falls into two parts: details about you as a person, and details about your transactions.
On the personal side, the provider reports your name, address, tax identification number and the country or countries in which you are tax resident. Your place of birth is added where the provider is obliged under domestic law to obtain it. These details come from the tax self-certification your provider asks you to complete.
The second part is the interesting one. It is drawn up separately for each type of crypto-asset, once for one cryptocurrency, once for the next. For each type, the provider reports:
Two terms are worth unpacking. Aggregate means that individual operations are not transmitted; what is transmitted is the annual total per crypto-asset and direction. The fair market value is the value a crypto-asset had on the market at the moment of the transaction, expressed in a fiat currency; it is needed because a coin-to-coin swap moves no euro amount that could be reported.
What is missing from that list matters as much as what is in it: no acquisition date per purchase, no acquisition price per individual unit, no gain, no loss, no holding period.
A gross amount is the full amount of a transaction, with no acquisition costs, fees or losses netted off. That is exactly how the reporting works. And because purchases, sales and swaps are each added up separately, the reported total grows with every movement while your wealth can stay unchanged.
The reason lies in how the law is built. The authority is meant to be able to see that there is something at your end worth examining. Working out the tax remains your job.
Suppose you transfer 5,000 euros to your exchange in January and buy Bitcoin with it. Over the year you shift back and forth between two cryptocurrencies twenty times, each time with a counter-value of around 5,000 euros. In December you sell back into euros for 5,800 euros.
The report will then say roughly the following: 5,000 euros in gross amount paid on purchases against euros, 5,800 euros in gross amount received on sales against euros, and on the swaps an aggregate market value in the order of 100,000 euros, spread across both crypto-assets involved. Your actual increase is 800 euros. The largest figure in the data set is about a hundred and twenty times the size of your gain.
The numbers in this example are set, not measured. Their only purpose is to show the arithmetic mechanics. Anyone who trades actively should expect their own report to contain magnitudes that look wrong without an explanation.
Many people regard switching from one cryptocurrency into another as an operation inside their own portfolio. For tax purposes it is nothing of the kind. Under Section 23 of the German Income Tax Act, a swap counts as a disposal of the asset given up and at the same time as an acquisition of the one received. For the holding period that means the clock for the new coin starts at zero.
The reporting duty maps this operation twice. The crypto-asset given up appears as a sale against other crypto-assets, the one received as a purchase against other crypto-assets. In both cases the market value at the time of the transaction is applied, converted into a single fiat currency, and under Section 11(3) KStTG the provider must carry out that conversion consistently in the same way throughout.
From this follows a practical consequence that is easily overlooked: one and the same swap generates two entries, and anyone working with four different crypto-assets spreads their annual volume across four separate positions in the data set. Your own statement therefore has to be kept per crypto-asset as well, otherwise it cannot be reconciled with the report at all. Tools that produce exactly this breakdown automatically can be found in our comparison of crypto tax software and portfolio trackers; what matters there is less the range of features than whether the tool documents the market value at the time of the swap cleanly.
For the tax itself, the exemption threshold from Section 23(3) sentence 5 of the Income Tax Act continues to apply: gains remain tax-free if the total gain from private disposal transactions in the calendar year is below 1,000 euros. An exemption threshold is not an allowance. Once it is exceeded, the entire gain is taxable, and not merely the part above it.

This point concerns everyone who moves holdings off an exchange. A self-custodial wallet is a wallet whose private key you hold yourself and which is not assigned to any provider. If your exchange transfers coins to such an address, it reports under Section 11(1) no. 2(b) the aggregate market value and the number of units for transfers to addresses about which it does not know whether they are linked to a provider or a financial institution.
The decisive clause is: about which it does not know. As a rule, your exchange has no idea that the destination address belongs to you. From its point of view, value is leaving the house. The data set arriving at the authority therefore shows an outflow with a market value, without the information that the coins still belong to you.
For you that means nothing more than that you have to be able to evidence this transfer. The proof consists of the outgoing entry at the exchange and the incoming entry at an address assigned to your wallet. Anyone moving their holdings into self-custody anyway should document the receiving addresses from the start; which devices are suitable for that is shown in our hardware wallet comparison.
The scope is set out in Section 2 KStTG and distinguishes two groups. Covered first are crypto-asset service providers whose home member state, within the meaning of the European regulation on markets in crypto-assets, is the Federal Republic of Germany. The home member state is the EU country in which a provider obtained its authorisation.
Covered second are so-called crypto-asset operators with a domestic nexus, meaning providers without European authorisation that are tax resident in Germany, have their registered office or management there, or carry out their regular business activity there.
Double reporting is ruled out. Subsections 2 to 5 of Section 2 exempt an operator from the German duties where it already fulfils comparable duties in another EU member state or in a qualified third country. For you as a user that changes little: whether the data travels via Germany or via another country, it ends up at the tax office responsible for you, because the states involved exchange the data sets. That is precisely the purpose of the underlying EU Directive 2023/2226.
Not covered is whatever takes place without a provider. A decentralised exchange with no operator, a direct transfer between two self-custodial wallets, a swap through a pure protocol: for such operations there is nobody the law could put under an obligation. That does not make them tax-free. All that is missing is a third party's report. Your duty to declare to the tax office exists regardless of whether a third party transmits the same data. Anyone deliberately preferring regulated providers, because documentation and authorisation are settled there, will find the overview among the regulated crypto exchanges.
The reporting period is the calendar year, under Section 10 KStTG. Reporting takes place annually under Section 9(1), by 31 July at the latest for the preceding reporting period. Together with the application provision from Section 21, that yields the first date: the 2026 data goes to the Federal Central Tax Office by 31 July 2027.
Two further deadlines concern you directly. For business relationships entered into up to 31 December 2025, the provider must have completed the due diligence duties under Section 7(2) by 1 January 2027; this is why many providers are currently sending out requests for tax self-certification. If you do not respond, Section 8 kicks in: the request is followed by a reminder and a formal notice, and after 90 days at the latest, though not before 60 days have elapsed, the provider has to prevent you from carrying out reportable transactions. What that means day to day we have described in detail along the course of this block: self-certification at the crypto exchange and the looming account block.
Section 13 is the more pleasant one. Under it, your provider must inform you before the first report that data is being collected and passed on, and do so early enough for you to exercise your rights. That notification is no marketing letter. In it the provider discloses what is being transmitted about you, and that is the best moment to lay your own figures alongside.
Section 18 KStTG makes a series of breaches punishable as administrative offences, in the more serious cases with fines of up to fifty thousand euros. The addressee of that provision is the provider, not the private user. An investor who fails to submit a self-certification risks the trading block under Section 8 rather than this fine. The tax consequences of an incomplete return continue to follow the Fiscal Code.

Your tax liability cannot be calculated from the catalogue in Section 11. Four details needed for that are missing.
The acquisition date of the individual unit is missing. What is reported is the number of transactions in the year, not the day of each one. Whether a unit that was sold met the one-year holding period of Section 23 of the Income Tax Act therefore does not appear in the data set.
The acquisition costs of the specific unit disposed of are missing. What is reported is an annual total of all purchases, from which it cannot be derived which purchase belongs to which sale.
The holding you had at the start and at the end of the year is missing. And any link between your accounts at different providers is missing, because each provider knows only its own figures.
That makes it clear who has to fill the gap. Your return is the only place where aggregated gross amounts turn into a traceable gain. And it stands or falls with records you have secured yourself, before a provider halts trading or closes an account. Why that is no theoretical worry is shown by our piece on exporting your transaction history before an account is closed.
The goal is a modest one: if somebody lays the reported totals next to your statement, the two sides should fit together. For that you need six details per crypto-asset and per calendar year.
The first three lines establish the reconciliation with the report. The last three are what the report precisely does not contain and what determines your tax.
FIFO stands for first in, first out and means that on a sale the units acquired first count as the ones disposed of first. The tax administration expects a method you apply uniformly per wallet or account and consistently across the years. Anyone switching method mid-year produces a statement that can no longer be audited.
No. It knows gross totals per crypto-asset and the number of operations. The profit only emerges from acquisition dates and acquisition costs, which are absent from the report.
That does not hold either. The provider's reporting duty does not depend on whether any tax arises at your end. Reporting happens as soon as reportable transactions have taken place, whatever your result.
The opposite is the case. Transfers to addresses not assigned to any provider are precisely the ones reported under Section 11 with market value and unit count. What is invisible, at most, is that the address belongs to you, and that is exactly the circumstance you have to evidence yourself if it comes to it.
(As of September 13, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
You sent bitcoin out of your wallet, the wallet shows the transaction, and for hours it has displayed the same word: unconfirmed. The short answer first: in the vast majority of cases nothing is lost, and you have two tools to sort the matter out yourself. They are called Replace-by-Fee and Child Pays For Parent, and which one you need depends on whether you are allowed to replace the transaction yourself or have to push it along from behind.
The reason this issue is hitting so many users right now lies in a technical change that entered the Bitcoin software in October 2025, and whose consequences have only become fully visible across the network this year. Since then, transactions paying fees below one satoshi per vByte can be relayed at all. Those transactions form today's backlog, the one many users are stuck in.
The Bitcoin price stood at roughly $76,700, or about 66,100 euros, on September 13, 2026 (CoinGecko, retrieved 09:52 UTC). The price is a side issue for this topic, but the market situation is not: when a lot of investors move their holdings off trading venues into self-custody after a pullback, the number of transfers on the network rises, and competition for space in the blocks gets tougher.
We measured instead of guessing. At the time of the survey, the Bitcoin network's waiting area held 75,903 unconfirmed transactions totalling 38.6 million vBytes. A block holds roughly one million vBytes. The backlog therefore amounted to about 38 blocks, or some six to seven hours of work for the miners if nothing new arrived. Something new arrives constantly.
The usual rule of thumb says: full mempool equals high fees. That rule no longer holds at the moment. The rate recommended by the common fee estimators for a prompt confirmation was a single satoshi per vByte, the lowest value those estimators ever output. A full mempool and a minimum fee are no longer mutually exclusive today, and anyone unaware of that draws the wrong conclusions.
Before this gets practical, three definitions the rest of it rests on.
Mempool: The mempool is the waiting area in which every Bitcoin node holds the transactions that have been broadcast but not yet included in a block. It is not a central location; it exists thousands of times over in parallel on all the nodes of the network, which is why different providers display slightly different figures.
Feerate: The feerate is the price you pay per unit of data in your transaction, not per amount transferred. A transfer of 20 euros and one of 20,000 euros cost exactly the same if their data size is identical.
sat/vByte: A satoshi is one hundred-millionth of a bitcoin. The vByte is the measure of a transaction's size. The figure sat/vByte therefore says: this many hundred-millionths of a bitcoin per unit of size. Miners sort the waiting transactions by that number and take from the top, because their space in the block is limited. Bid too little and you slide backwards, a little further with every new transaction that bids more.
The data size depends on how many earlier inputs your payment is assembled from. Anyone who has received many small amounts over the years drags all of those fragments along with every outgoing payment and pays accordingly more. How to bundle such holdings cheaply during a quiet phase is described in our piece on consolidating UTXOs while the network fee is low. That no longer helps with an acute stuck payment, but it helps a great deal in preparing the next one.
cryptoticker.io carried out this analysis itself on September 13, 2026. Method: retrieval of the public interfaces of mempool.space on September 13, 2026 between 09:50 and 09:55 UTC; we evaluated the fee distribution of the entire waiting area as well as the fifteen most recently found blocks, from height 966,789 to 966,803. Objects examined: 75,903 waiting transactions spread across 167 fee brackets, and 15 blocks.
The result is clearer than we had expected:
For you as a sender, that leads to a statement which contradicts appearances: an apparently overcrowded waiting area barely stands in your way as long as you bid above one satoshi per vByte. Only those 0.3 percent are ahead of you. Bid less and you place yourself behind almost forty blocks' worth of competition that keeps renewing itself.
What we could not verify: the measurement shows a point in time, not a trend. It rests on a single provider's view of the network, and other nodes may hold differing inventories, because every node is free to set its own acceptance rules. We were also unable to establish what share of the backlog originates from individual large senders.

Until recently there was an invisible floor. The default setting of the most widely used node software simply rejected transactions below one satoshi per vByte and did not relay them. Version 30.0, released on October 10, 2025, changed that. The release notes state verbatim that the default values for the minimum relay fee and the incremental fee have been changed to 0.1 satoshis per vByte; the minimum block fee has stood at 0.001 satoshis per vByte since then. You can read it in the official release notes for Bitcoin Core 30.0.
The developers placed a warning right next to it: as long as these lower values are not adopted network-wide, neither relay nor confirmation is guaranteed for transactions paying such low fees. That sentence describes precisely the problem now landing on many users' screens. The wallet is allowed to offer a very low fee, the network accepts it, and then nothing happens for a long time.
If your wallet has a fee slider and proposes something in the range of 0.2 to 0.5 satoshis per vByte as its lowest step, that is no malfunction. It is the new reality. That step is meant for transfers where a confirmation within days is good enough. For anything that should still arrive today, it is currently the wrong choice.
Before you repair anything, establish whether anything is broken at all. You need the transaction ID for that, a long string your wallet displays under details and which can usually be copied with a single tap.
Enter that ID into a public block explorer. Three pieces of information matter to you there:
A transaction does not simply vanish, by the way. If it goes unconfirmed for days, it eventually drops out of the nodes' waiting areas, and the bitcoin show up as available in your wallet again. Nothing is lost in the process, because an unconfirmed transaction never truly left your balance.
Replace-by-Fee is a node rule under which an unconfirmed transaction in the waiting area may be replaced by another one that spends at least one of its inputs and pays a higher fee. This is not about a second payment. You submit the same payment once more with a better offer, and the old version is discarded.
Two points are worth knowing before you press the button. First, under the widely used rule from BIP 125, the new version must pay both a higher feerate and a higher absolute fee, as the Optech compendium on Replace-by-Fee records. Making the transaction smaller is therefore not enough. Second, replacement has not been tied to a special flag since 2024: change set 30493 made general replaceability the default in August 2024, and in November 2024 the corresponding switch disappeared entirely.
In most self-custody wallets you will find an entry such as Increase Fee, Accelerate or Bump Fee on an unconfirmed transaction. The wallet builds the replacement version itself and proposes a new rate. Following our measurement, set it above one satoshi per vByte; in the current environment a normal transfer needs no more than two satoshis per vByte. The additional fee is usually deducted from the change, and the recipient's amount stays the same.
A word on security: for this procedure your wallet has to sign the transaction again. On a hardware wallet that means confirming on the device once more. Check the recipient address just as carefully as you did the first time. Which devices handle this process cleanly and which leave you in the dark is shown by our comparison of crypto hardware wallets. If this is the first time in a while that you are handling your recovery words, it is a good moment to check that they are still complete and legible.
Child Pays For Parent is a procedure in which you spend an output of the stuck transaction onward in a new transaction carrying a high fee, so that miners take both into a block together. The trick lies in the ordering rule of the blockchain: a transaction can only be confirmed if the transaction before it is in the block as well. So whoever wants the child has to take the parent along.
Miners therefore calculate with the combined fee rate of parent and child. If that average is attractive, both move into the block together. This sounds more cumbersome than RBF, yet it has one decisive advantage: you do not need to be allowed to touch the original transaction.
Two cases come up often in practice. The first: you are the recipient. Someone sent you bitcoin with too low a fee, and you are waiting for it. You may not replace other people's transactions, because that would require the sender's keys. You can, however, spend the output addressed to you onward and push the payment along that way. The second case: your wallet does not support raising the fee but does offer to spend an unconfirmed input.
CPFP has its limits too. Nodes cap how many connected unconfirmed transactions they keep in their memory; a long chain of parents and children eventually runs into those barriers. And if your child pays a high fee while the parent is very large, the child has to bring correspondingly more to lift the combined average.

If you have triggered a withdrawal at a trading venue and it is stuck, the situation looks different. The transaction belongs to the provider, not to you. The keys sit there, so only the provider can replace it. CPFP is out as well, as long as the bitcoin have not yet reached you and you cannot spend the output.
What remains is knowing the mechanics. Many trading venues bundle withdrawals into batch transactions and set their fee at their own discretion. The fee deducted from you at withdrawal often has little to do with the network charge actually paid; how far apart those two figures can be is something we looked at in our analysis of withdrawal fees and the real network fee. If a withdrawal makes no progress for hours, support is the right address, and the transaction ID belongs in the first message. Which providers handle their withdrawals promptly and transparently is one of the criteria in our comparison of the best crypto exchanges.
A simple orientation can be derived from the measurement, although it applies only to the situation measured and you should re-check it before every larger transfer.
For a payment that should arrive promptly, a value just above one satoshi per vByte is currently enough. That places you ahead of 99.7 percent of the waiting volume. Two satoshis per vByte is generously judged and costs only a few cents on a simple transfer of around 140 vBytes in size.
For a payment where days are good enough for you, you may use the new low steps. But then expect it to genuinely take days, and choose a wallet that lets you raise the fee later. Without that option you sit the waiting time out.
The most expensive mistake is the panic that follows a low fee, rather than the low fee itself. Anyone who sees a stuck transaction and promptly sends a second payment to the same address risks both being confirmed in the end, leaving the recipient with double the amount. Check first, then raise the fee or push the payment along, and under no circumstances send blindly again.
Both procedures accelerate a transaction that is already on the network. They do not reverse it. You can indeed replace a payment with another via RBF and in theory change the recipient too, as long as nothing is confirmed; once a confirmation exists, the process is final. No technology brings back a transfer that was sent to the wrong address and confirmed.
They are equally useless for a transaction that your wallet displays but that never reached the network. If the block explorer cannot find the ID at all, it was not relayed. The right step is then to reconnect the wallet and repeat the send, instead of fiddling with fees.
A transfer between two of your own wallets is not a sale and triggers no taxable event in Germany. The network fee paid is not a deductible item in this case either. The details are in our article on whether the network fee counts for tax purposes when sending between wallets.
(As of September 13, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
TRM examined roughly $52.7 million across 198.9 million settlements using the x402 protocol. Most of it isn’t coming from AI agents, it says.
The fintech company fulfilled a fraudulent information request sent from a government agency's own email domain, exposing ID documents and full crypto transaction histories for a "limited" number of users.
A week after launch, complaints are rolling in from users that GPT-6 Astra has been nerfed. OpenAI's last model went through the same cycle in July.
Ben Delo and Christopher Harborne each gave £36 million, and between them beat what every UK party raised last year.
The surveillance mod on GTA V brings the privacy fight to Los Santos, where players can demolish the cameras tracking them.
Senate Democrats are holding a last-minute caucus meeting as the Clarity Act heads toward a high-stakes procedural vote that will require bipartisan support to advance.
Bitcoin locks in a historic $65,000 long-term support floor, as cycle mathematics may prevent future drops below this key threshold.
Bloomberg's Mike McGlone warns Bitcoin's tight correlation with S&P 500 and pending Fed hikes spark sell signals targeting a potential drop to $10,000.
XRP targets a 20% breakout as the tightening hourly triangle pattern nears its final apex resolution.
Whale monopolization locks 94.68% of Shiba Inu (SHIB) supply as triangle pattern forces price squeeze.
Litecoin whale addresses holding between $1 million and $10 million, along with those above $10 million, have dropped to levels not seen since the 2022 cycle bottom, according to on-chain analyst Joao Wedson.
The decline signals reduced large-holder participation during the current market phase. LTC trades at $53.58, up 0.18% over the past day. Separately, Grayscale has moved to convert its Litecoin Trust into a listed ETF product.
On-chain data shared by analyst Joao Wedson shows a marked contraction in Litecoin whale addresses. Wallets holding between $1 million and $10 million in LTC have thinned out considerably. The same trend applies to addresses holding more than $10 million in value.
These figures now sit close to where they stood during the 2022 market bottom. Wedson noted in a post on X that this pattern has appeared before during periods of market stress. Deep resets in previous cycles carried similar contractions in whale participation.
The analyst was careful to note that this data point does not confirm a bottom has formed. Instead, it places current whale activity near historically low readings. Reduced large-holder presence often accompanies weaker phases of a market cycle rather than stronger ones.
Address-based metrics like these track wallet balances rather than individual investors. A drop in mid-tier and large addresses suggests fewer wallets carry substantial LTC value right now.
Compared with periods when Litecoin traded at higher valuations, current large-holder representation looks noticeably thinner.
Litecoin’s official account confirmed a separate development tied to regulatory filings. Grayscale submitted an S-3/A filing with the Securities and Exchange Commission. The filing seeks to convert the existing Litecoin Trust into an exchange-traded product.
Under the proposal, the fund would be renamed the Grayscale Litecoin Trust ETF. Shares would trade on NYSE Arca under the ticker $LTCN. This filing represents an amendment to a previous registration statement submitted to regulators.
Grayscale has pursued similar conversions for other digital asset trusts in recent years. Listing on a major exchange would give investors a regulated avenue to gain LTC exposure. The filing still requires review and approval before any shares reach the market.
Meanwhile, Litecoin’s spot price stood at $53.58 at the time of writing. Trading volume over the past 24 hours reached $214,552,110 across exchanges. The asset posted a 7-day gain of 0.60%, alongside its modest daily increase.

Source: Coingecko
Combined, both developments paint a picture of a market working through mixed signals. Whale addresses point to caution among large holders. The ETF filing points to continued institutional interest in Litecoin as an asset class.
The post Litecoin Whale Addresses Sink to 2022 Lows as Grayscale Files LTC ETF appeared first on Blockonomi.
The Sui price trades near $0.72 as analyst Ali Martinez identifies a TD Sequential buy signal on the 12-hour chart. CoinMarketCap lists SUI at $0.7187 at the latest reading, with a 24-hour range between $0.7063 and $0.7305. Martinez says the indicator previously preceded a 17% rally and a shift in momentum.
The Sui crypto price tests the $0.71-$0.73 support area after the signal. A break below $0.71 could expose $0.62-$0.63. A recovery toward $0.85 could place $1 back in focus. The setup combines a bullish indicator with supply and leverage risks across the Sui market.

Ali Martinez describes the TD Sequential as relatively accurate at identifying major trend shifts in SUI’s recent 12-hour chart history. He says the previous SUI buy signal appeared after a 17% rally and anticipated the next momentum change.
TD Sequential tracks price sequences to identify possible trend exhaustion. A completed buy setup can point to a reversal, but it does not confirm a new trend.
The Sui price now tests the lower boundary of a key trading area. Ali Charts places support between $0.71 and $0.73. A daily close below $0.71 could open a path toward $0.62-$0.63.
An earlier Ali Charts post described SUI as moving inside a channel with a lower boundary near $0.71. That post placed the upper channel target near $0.84.
Michaël van de Poppe also suggests the support could retest to hold. He says a recovery toward $0.85 could place levels above $1 back into focus.
SUI’s market structure adds another risk factor. The analysis reports futures activity exceeding spot trading. That pattern can amplify moves through liquidations when leveraged positions unwind.
The indicator points to a possible reversal, while support decides whether buyers defend the setup.
Regulated market access has expanded through the 21Shares Sui ETF, which trades on Nasdaq under the TSUI ticker. The product provides spot SUI exposure and may stake part of its holdings.
21Shares began TSUI trading on February 24, 2026. CME Group also lists SUI and Micro SUI futures after launching the contracts in May.
These instruments create routes for institutional exposure, hedging, and price discovery. They do not confirm sustained inflows, and no latest ETF flow figures appear in the analysis.
The ETF offers exposure without direct wallet custody. That broadens the set of market participants tracking SUI.
Network activity provides a separate growth measure. Sui surpassed 16.17 billion lifetime transactions by September 13. Its stablecoin market capitalization also moved above $457 million.
DeFiLlama currently lists Sui stablecoins at $463.67 million, up 8.85% over seven days. According to DeFiLlama data, the total DeFi TVL is at $457.13 million.

Stablecoin growth can support trading activity and collateral demand. It does not guarantee lasting token demand; capital can leave quickly during market stress or shift toward other competing networks.
USDC accounts for about 63.88% of the stablecoin market capitalization. Other assets include Sui Dollar, FDUSD, BUCK, USDY, suiUSDe, and USDT.
That concentration leaves the network’s liquidity profile heavily tied to one asset. The current figures show USDC carrying most of the stablecoin balance.
Supply growth pressures the Sui price. Monthly unlocks of roughly 64 million SUI add tokens to circulation. The analysis also flags declining DeFi TVL as a pressure point.
The Sui price must absorb fresh supply while network liquidity and institutional access develop. CoinMarketCap lists a 10 billion maximum supply and a circulating supply near 4.09 billion.
Futures leverage adds another variable to the near-term chart. A daily close below $0.71 would put the $0.62-$0.63 range back into focus.
The post Sui Price Shows Fresh Buy Signal as Network Growth Meets Unlocks appeared first on Blockonomi.
Crypto mining operations are increasingly becoming tools for organized crime in Latin America, according to blockchain analytics firm Chainalysis.
Mexican authorities recently uncovered a suspected illicit crypto mining site in the mountainous Tlaola area of Puebla state, seizing hundreds of graphics processing units, medium-voltage terminals, and satellite antennas.
The discovery marks the fourth similar operation found in the region since early 2025. It points to a growing pattern of criminal groups exploiting virtual currency mining for financial gain.
Authorities in Puebla state found the crypto mining farm tucked into the lush, remote mountains of the Sierra Norte region. The site held 300 graphics processing units, 80 medium-voltage terminals, and eight satellite antennas.
These tools were built to compete against other machines worldwide to solve puzzles and generate new coins. Officials are now investigating whether the operation stole electricity from a nearby hydroelectric dam to power its equipment.
Security analyst David Saucedo said the operation showed “drug cartels appear to have reached a new level of sophistication.”
He noted that only a well-funded group, such as one of Mexico’s major cartels, could likely back such infrastructure. Mexico’s federal attorney’s office declined to comment, citing an ongoing investigation.
Residents living near the site told Reuters they could hear the mechanical whirring from roughly one kilometer away. The crypto mining farm sat about twice that distance from the nearest village.
Three other similar sites were found last year close to the same hydroelectric dam in northern Puebla. Local authorities are now working with neighboring states to check for further hidden mining operations nearby.
Illicit cryptocurrency transactions worldwide more than doubled in 2025, reaching an estimated 154 billion dollars. That figure is up sharply from 59 billion dollars the previous year, per Chainalysis data.
The firm linked much of this jump to a rise in transactions tied to sanctions evasion, including payments connected to sanctioned governments and their networks.
Caio Motta, Chainalysis’s Latin American specialist, said cartels often target areas with cheap electricity or organized crime influence. This allows groups to steal power outright and build large crypto mining infrastructure at minimal cost.
Electricity remains the largest expense in crypto mining, and energy prices continue climbing each year. The University of Cambridge’s Bitcoin Electricity Consumption Index puts the cost of minting one bitcoin near 45,000 dollars. At current prices near 78,000 dollars per coin, that still leaves a wide profit margin for operators.
Similar crypto mining raids have occurred in Brazil, the United States and Southeast Asia, including a large operation across five Thai provinces.
Motta expects crypto-related crime to keep climbing as virtual currencies become easier to access globally. Still, he added that law enforcement agencies are steadily improving their ability to trace and disrupt these illicit networks.
The post Crypto Mining Becomes Cartels’ New Weapon for Laundering Illicit Funds appeared first on Blockonomi.
Is the Bitcoin 4-year cycle broken? That question is gaining traction as this cycle unfolds differently from the last three. Previous cycle bottoms in 2012, 2016, and 2020 formed between day 770 and 900 after halvings, per CryptoQuant data.
This time, Bitcoin posted a fresh all-time high before the halving even occurred. That early move has left traders divided on whether the historical rhythm still holds or has finally given way.
Spot ETF approvals opened the door for large institutional inflows ahead of the halving. Institutional allocators typically base decisions on monetary policy, interest rates, and broader liquidity.
They do not track days elapsed since a halving event. This approach differs sharply from the retail-driven cycles seen in 2012, 2016, and 2020.

Source: Cryptoquant
The halving’s supply shock also carries less weight than it once did. Newly minted coins represent a small fraction of daily volume moving through derivatives and major funds.
In earlier cycles, reduced issuance visibly affected available supply. Today, that effect is diluted by the much larger pool of tradable Bitcoin in circulation.
Bitcoin’s market capitalization has grown into trillion-dollar territory, changing what it takes to move the asset. Shifting a market of this size now requires substantial liquidity across global markets.
Aggressive monetary easing, a factor behind past rallies, has not appeared recently. Without that liquidity push, price momentum may build more slowly than before.
These shifts raise a real question about whether counting days after a halving still applies. Some observers argue Bitcoin increasingly resembles a mature macro asset tied to broader financial conditions.
The four-year model may not be dead, but its timing looks disrupted. Many are now watching macro indicators instead of a historically timed bottom.
The question has extended beyond analysts into wider social media discussion. A post from the account Discover on X argued Bitcoin may have already broken its cycle. The post suggested the bottom formed roughly 650 days before the next scheduled halving.
That timeline, if accurate, would open room for a new all-time high before the 2028 halving arrives. The post also floated the idea that the next cycle top could arrive only around 350 days after that halving. Such a timeline would differ sharply from the multi-year gaps seen in previous cycles.
Rather than treating the four-year cycle as finished, the post framed the pattern as compressing. Under that view, each stage of the cycle would happen closer together in time. This would depart from the roughly four-year spacing seen between past bottoms and tops.
Whether the cycle is broken or simply compressed remains an open question. Historically, major rallies have followed halvings rather than preceded them.
Market participants are watching whether coming months confirm a compressed timeline or the traditional four-year rhythm.
The post Is Bitcoin’s 4-Year Cycle Broken? Analysts Question the Old Halving Pattern appeared first on Blockonomi.
An informal Bitwise poll shows 67% of roughly 400 wealth managers have no crypto allocation in client portfolios. The same audience signals possible future demand. Sixty percent plan to add exposure within 12 months, while another 60% expect crypto prices to finish 2026 higher. No allocation size was disclosed publicly. The responses capture interest and intent, but they do not represent a randomized survey of the wider industry.
Participants attended a Bitwise presentation, which may attract professionals already tracking digital assets closely. The poll therefore shows the distance between discussion and implementation within firms today. It also captures how wealth managers now view Bitcoin, altcoins, stablecoins, tokenization, and related investment products globally.
Bitwise Head of Research Ryan Rasmussen shared the poll after appearing with Chief Investment Officer Matt Hougan. The session covered Bitcoin, Ethereum, Solana, Hyperliquid, stablecoins, tokenization, and the changing regulatory setting. XRP generated the most questions from attendees, Rasmussen said.

The response puts XRP alongside the larger assets that typically anchor institutional discussions. Bitcoin offers the market’s primary reference asset, while Ethereum and Solana represent blockchain network exposure. Stablecoins and tokenization move the discussion toward payments, settlement, and digital forms of traditional assets.
Sixty percent of wealth managers said they planned to add a crypto allocation within a year. The same share expected prices to finish 2026 above current levels. Those answers connect planned portfolio exposure with a constructive market view. Neither response specifies an asset, vehicle, or allocation size.
The poll also does not show how many participants had started internal approval processes. A manager may support crypto exposure while a firm limits purchases to exchange-traded products. Another firm may require investment committee review, approved custodians, or additional client disclosures before execution.
The difference between interest and completed purchases is visible in the survey’s design. It records what attendees said during one presentation. It does not measure account balances, new deposits, or purchases completed after the event.
Broader Bitwise and VettaFi research shows adoption moving upward over time. Their 2026 benchmark survey found that 32% of financial advisors allocated crypto to client accounts in 2025. That figure rose from 22% in 2024. The survey also found that 42% could buy crypto for clients, compared with 35% in 2024 and 19% in 2023.
The Bitwise/VettaFi 2026 Benchmark Survey tracks financial advisor attitudes, preferred investment vehicles, and market themes. It gives the event poll a wider reference point, while the two samples measure different groups and use different methods.
The latest audience results therefore sit between broader access and limited implementation. More firms now provide a route to client exposure. That route can still involve custody, compliance, valuation, liquidity, tax, and reporting reviews. Wealth managers must also explain volatility and suitability before placing a digital asset in a client account.
The session topics show that professional questions extend beyond Bitcoin. Attendees asked about XRP, while the presentation also addressed Ethereum, Solana, Hyperliquid, stablecoins, and tokenization. The range indicates that conversations now include networks, settlement tools, and asset-backed digital instruments.
Existing crypto portfolios also show a larger share of allocations above 2%, although no percentage is provided. It does not identify the account types involved. That missing detail prevents a direct comparison with the 67% who reported no current exposure.
For wealth managers, operational rules can determine when interest becomes an allocation. Firms may require approved platforms, independent custody, transaction records, risk disclosures, and suitability reviews. The Bitwise poll records planned activity, while those controls determine whether any client capital actually moves.
The post Wealth Managers Show Crypto Interest Despite a 67% Allocation Gap appeared first on Blockonomi.
The Justice Department’s Scam Center Strike Force, working with the Treasury Department, seized a Chinese-language scam marketplace called Xinbi Guarantee and restrained about $52 million in cryptocurrency in a single day, U.S. Attorney Jeanine Pirro announced this week. That operation brought the total the Strike Force has restrained since its founding to roughly $938 million.
A separate Strike Force team also spent the same stretch helping authorities in Madagascar take down 13 Chinese-run scam compounds, pushing the crackdown launched last November well beyond its original footprint in Southeast Asia.
Xinbi ran almost entirely on Telegram, in Chinese, functioning as a kind of marketplace where vendors advertised services to scam center operators: building custom fraud investment websites, “washing” money stolen through wire fraud, and recruiting trafficking victims to staff scam compounds.
Xinbi itself held payments in escrow until a vendor finished the job, which is how prosecutors say they were able to trace specific victim funds to vendors who posted wallet addresses on the channel. A federal court in Washington authorized the seizure of those Telegram channels on September 7, and prosecutors unsealed the warrant Wednesday.
Investigators seized two crypto wallets Xinbi used to collect vendor payments, worth roughly $12 million, and sought restraint of 47 more wallets tied to the network, bringing the total taken from the platform and its vendors past $52 million.
The Treasury’s Office of Foreign Asset Control (OFAC) separately designated Xinbi a transnational criminal organization the same day, along with two other entities accused of supporting it, freezing any property they hold in the U.S.
Pirro said the case shows why ordinary people are at risk:
“Every American with a retirement account is in the blast radius,” she stated. “My Strike Force will continue to dismantle Chinese organized crime, those who facilitate it, and protect Main Street America.”
Alongside the Xinbi action, U.S. Attorney Michael Heyman of Alaska said the Strike Force’s two-week Madagascar deployment, which helped process more than 3,200 devices and interview about 400 people who had been arrested, reflects where the fight is headed.
“Transnational criminal organizations don’t care about borders, and the Department of Justice won’t either,” he said.
In March, the British government sanctioned Xinbi, with Chainalysis estimating the platform had processed nearly $20 billion in crypto between 2021 and 2025, selling everything from stolen personal data to satellite equipment used to reach fraud victims.
That earlier action barely slowed it down, with the criminal group simply opening new Telegram channels and continuing with its operations. The Strike Force itself dates to November 2025, when Pirro set it up to go after Chinese organized crime running scam centers.
Federal data cited in Wednesday’s announcement put reported crypto investment fraud losses at $8.65 billion in 2025, up 89% from $4.57 billion in 2023, although the FBI says the figures are “significantly under-represented,” since most fraud victims do not report.
The post DOJ Strike Force Seizes Scam Marketplace, Restrains $52M in Crypto appeared first on CryptoPotato.
Bitcoin is consolidating around $77.3K after a powerful breakout from the $67K area. While the broader structure has improved significantly, BTC is now facing an important resistance cluster near $80K-$82K. Meanwhile, the latest Coinbase Premium reading suggests that US spot demand has yet to fully confirm the recent advance.
The daily chart shows a significant structural recovery. After falling to the $60K demand zone in June, Bitcoin spent several months building a broad base before breaking decisively above the $67K resistance area in late August. The subsequent rally carried BTC rapidly through the $72K-$74K zone and toward the $80K area.
The $72K-$74K region has now become the first major support zone. A successful retest of this area would preserve the bullish structure established by the recent breakout. Below it, the $67K zone is a more important structural support, as it previously capped the market for several months. A deeper correction could bring the $60K demand zone back into focus.
On the upside, BTC is approaching the $80K-$82K resistance zone. The price has already tested this area several times but has failed to establish a sustained breakout above it. A daily close above $82K would therefore be significant, as it could open the way toward the $90K mark or even higher.

The 4-hour chart provides a clearer view of the latest move. Bitcoin spent much of the summer trading sideways between roughly $60K and $67K before staging a sharp breakout. The move through the $67K resistance zone accelerated dramatically, taking BTC through $74K.
After reaching the $80K-$82K area, however, the rally has lost momentum. BTC is currently trading around $76.8K and has formed a relatively broad consolidation below resistance. This can be interpreted as a potential continuation range following the breakout, provided the lower boundary remains intact.
The immediate support is located around the same daily $72K-$74K zone. This area is particularly important because it represents the previous resistance zone that BTC cleared during the breakout. Holding it would maintain the sequence of higher highs and higher lows on the 4-hour timeframe.
The main resistance remains $80K-$82K. A clean breakout and sustained trading above this zone would signal that buyers are regaining control and could bring the next major daily resistance around $95K into consideration. Conversely, repeated rejection followed by a break below $72K could trigger a deeper retracement toward $67K.

The Coinbase Premium Index provides an important caveat to the technical picture. The metric measures the price difference between Bitcoin on Coinbase and other major exchanges and is commonly used as a proxy for US-based spot buying pressure. Positive readings generally indicate stronger demand on Coinbase, while negative readings suggest comparatively weaker US spot demand.
The latest reading on the chart is around -0.02, with the index back in negative territory. This is notable because BTC has simultaneously remained well above the levels seen before the late-August breakout.
The divergence suggests that the recent price strength has not been accompanied by a sustained surge in Coinbase buying pressure. In other words, while the technical structure has improved, the latest premium data does not yet provide strong confirmation of aggressive US spot accumulation.
Historically, within the period shown, the Coinbase Premium spent considerable time below zero during BTC’s decline toward the $60K area, while stronger positive readings appeared during several recovery phases. The current negative reading, therefore, warrants some caution as Bitcoin approaches the $80K-$82K resistance zone.
For the bullish scenario to strengthen, a renewed move of the Coinbase Premium into positive territory alongside a breakout above $82K would provide more convincing confirmation. If BTC instead loses $72K while the premium remains negative, it would increase the probability that the recent rally is undergoing a deeper correction rather than immediately transitioning into another leg higher.

The post Bitcoin Price Analysis: BTC Faces a Make-or-Break Week – What’s the Most Likely Scenario? appeared first on CryptoPotato.
Although the upcoming vote on the Digital Asset Market Clarity Act is not a final passage vote, it still holds significance for the broader crypto market as senators will decide whether to advance debate on the legislation. Cloture requires 60 votes, meaning that even if all Republicans support it, they would still need assistance from some Democrats or independents.
XRP could be among the most intertwined crypto assets with the bill, which is why a potential failure could weigh on its price quite considerably. As such, we asked ChatGPT about its take on the matter and what could happen to the cross-border token.
The bill aims to create a comprehensive federal crypto market structure, including clearer responsibilities for the two main watchdogs – the SEC and the CFTC, and rules for exchanges, brokers, dealers, and digital commodities. This is particularly relevant for the cross-border token following Ripple’s years-long regulatory battle with the SEC.
After the conclusion of the lawsuit that began in late 2020, the regulator identified XRP as a digital commodity. As such, the legislation would make the broader regulatory framework more durable by codifying it into federal law, since history has shown that the SEC’s allegiance shifts quickly with each new administration.
Overall, even though a failure on the CLARITY Act’s vote next week would remove a potential bullish catalyst, it wouldn’t erase all of XRP’s regulatory progress experienced in the past year and a half.
From a technical standpoint, XRP is currently near $1.40, above the key support at $1.34-$1.35, but it hasn’t reclaimed the crucial resistance at $1.40. If cloture fails but BTC and the broader crypto market remain stable, ChatGPT envisioned a 7% to 10% initial reaction for Ripple’s token, which would materialize with a dip to $1.20-$1.25.
A more aggressive selloff could drive the asset south toward $1.10, especially if markets interpret the result as evidence that comprehensive US crypto legislation could be delayed well after the midterms.
The dark horse comes a day later, when the Federal Reserve will conclude its September 15-16 FOMC meeting. A failed CLARITY Act vote followed by a hawkish Fed decision could turn an XRP-specific regulatory disappointment into a broader crypto selloff. In that scenario, the AI platform predicted a more painful decline toward $1.00.
On the plus side, ChatGPT said a lack of progress on the CLARITY Act alone wouldn’t be as strong a catalyst to drive XRP below $1.00.
The post What Happens to XRP if the CLARITY Act Vote Fails on September 15? AI Maps the Downside appeared first on CryptoPotato.
Inflation is heating up again, as evidenced by the PPI data that came out on Thursday. Treasury yields are approaching 5%, and the US government is trying to stabilize the bond market while proposing another trillion-dollar stimulus program.
The immediate implications for bitcoin are bearish. However, the longer-term picture is considerably more complicated.
August producer prices rose 5.4% year-over-year, which was just slightly over expectations. At the same time, Brent crude jumped past $100 this week as the situation in the Middle East sees no actual improvement and supply disruptions continue. The probability of a rate hike after the conclusion of the FOMC meeting on September 16 is over 70%, according to futures markets and some prediction platforms.
The 10-year Treasury yield climbed to just under 5%, despite the Treasury’s ongoing efforts to improve liquidity in long-dated government debt. Higher yields typically mean tighter financial conditions, a stronger incentive to hold relatively safe government debt, and, unfortunately for the bitcoin bulls, less appetite for speculative assets.
This helps explain why BTC’s initial rally that drove it from under $65,000 to $82,000 hit a brick wall, and the asset has been unable to push through in the past few weeks. However, that’s only half the story.
As previously reported, the Treasury initially doubled the long-term buybacks from $2 billion to at least $4 billion per operation on August 19, which triggered the first BTC leg up. At the same time, long-term yields immediately dipped, and the dollar weakened.
The Treasury Department went a step further earlier this week, increasing the purchases to $6 billion. Now, though, there’s President Trump’s proposition to give every American adult $5,000 if Republicans retain control of Congress in November. According to estimates, this could cost somewhere between $1.20 trillion and $1.35 trillion and would require congressional approval.
The analysts at the Kobeissi Letter described this as an “unprecedented” situation. We have inflation remaining too high for the Fed to ease monetary policy, while massive deficits and rising interest costs are simultaneously creating pressure for lower borrowing costs.
The Kobeissi Letter argued that these forces will favor asset owners and specifically pointed to BTC, gold, and stocks. However, this doesn’t guarantee that BTC will automatically thrive in the current economic structure. In fact, the path forward could be painful at first.
If inflation keeps rising and the Fed responds with additional rate hikes, BTC could face more pressure as yields climb. The bullish narrative emerges later if fiscal stress eventually forces policymakers toward heavier intervention, looser financial conditions, or policies that expand normal spending.
The post US Bond Market Is Flashing a Major Warning: Is This the Setup Bitcoin Was Built For? appeared first on CryptoPotato.
Ripple veteran David Schwartz recently said quite convincingly that XRP could eventually overtake bitcoin by market capitalization. However, he outlined the significance of the right conditions and that such a development wouldn’t come from BTC’s deterioration.
As such, we decided to go a bit deeper into the numbers and see what actually has to happen for Ripple’s token to emerge ahead of the current market leader.
The cryptocurrency community has long been dabbling with the question of whether (at least) one altcoin can replace BTC as the largest digital asset by market cap. For almost a decade, that alt representative was Ethereum (ETH), which didn’t exactly come close several years ago, but there was speculation about a potential Flippening. However, it never materialized.
The focus has now switched to Ripple’s XRP. During a recent X Spaces discussion, longtime Ripple exec and XRP Ledger architect David Schwartz said he believes it’s possible for the cross-border token to surpass BTC in terms of market cap. Moreover, he noted that such a wild scenario wouldn’t transpire because bitcoin had collapsed; instead, he argued that it would unfold under significantly different conditions.
At first, the broader crypto market would have to be dramatically more successful. Second, XRP would grow considerably faster than BTC due to the XRP Ledger’s functionality, adoption, and real-world usage.
Let’s go directly to math and see where the issue stems from, as the numbers are daunting at current prices. BTC’s market is at about $1.55 trillion today, compared with approximately $87 billion for XRP. This makes the market leader around 18 times larger.
If we presume that bitcoin’s valuation remains unchanged, XRP would need to climb toward a $1.55 billion market cap simply to level the playing field. At today’s circulating supply, that would imply a mind-blowing surge to $24-$25 from the current $1.40 levels.
Schwartz’s scenario makes that hurdle even bigger, as he doesn’t believe BTC will remain stagnant. Instead, he noted that the entire crypto market could expand exponentially, meaning that BTC would most likely continue appreciating as well.
It’s worth noting that XRP has actually been closer to BTC in the past. A lot closer. And still couldn’t do it. Back in early 2018, XRP’s market cap had risen to $120 billion as the asset rocketed to its then-ATH. BTC’s market cap, on the other hand, was a more modest $250-$260 billion.
In other words, XRP was worth almost 50% as much as BTC at the time. Today, that ratio is down to 5%-6%, which makes Schwartz’s scenario even harder to materialize. But then again, nothing is impossible, right?
The post Could XRP Actually Flip Bitcoin? Former Ripple CTO Says Yes – But the Math Is Brutal appeared first on CryptoPotato.