Firmus's IPO could significantly boost Australia's tech sector, highlighting the transformative potential of AI infrastructure investments.
The post Firmus seeks to raise $5B in IPO on Australian Securities Exchange appeared first on Crypto Briefing.
The shift towards spot trading reduces market volatility, potentially stabilizing Bitcoin prices and mitigating risks of liquidation cascades.
The post Bitcoin open interest falls 14% as market positions shift toward spot trading appeared first on Crypto Briefing.
Investor redemptions from BlackRock's Bitcoin ETF highlight shifting risk appetites amid broader market volatility and monetary policy changes.
The post BlackRock ETF clients sell $19M worth of Bitcoin as spot funds see broader redemptions appeared first on Crypto Briefing.
The surge in PFAS production for AI needs could exacerbate environmental issues, prompting regulatory scrutiny and industry shifts toward safer alternatives.
The post PFAS companies plan production surge to meet AI demand, warns ChemSec appeared first on Crypto Briefing.
Ukraine's use of unmanned vehicles may redefine modern warfare, reducing human risk and influencing global military strategies.
The post Ukraine deploys unmanned vehicles to frontline, shifting military strategy appeared first on Crypto Briefing.
Bitcoin Magazine

Bitcoin’s ‘Unusual Mix’: Bearish Inflation Print, Bullish Buyback Failure
Bitcoin’s path higher just got harder in the short term, but the setup further out may be improving, according to a new report.
In a Friday note, European asset manager CoinShares’ Head of Research, James Butterfill, said firmer-than-expected core inflation raises the odds of tighter Fed policy and could cap bitcoin below $80,000 for now.
But the longer-term case, he argued, rests on the U.S. Treasury’s bond buyback programme failing to bring down long-end yields — a failure that could ultimately feed the debasement narrative that has supported both bitcoin and gold.
“The result is therefore a somewhat unusual policy mix for Bitcoin,” the report read. “Today’s CPI data is negative at the margin, increasing the probability of tighter monetary policy and potentially limiting the immediate upside.
“But the apparent failure of the Treasury’s current buying programme increases the likelihood of much more substantial intervention further ahead.”
It continued: “If that happens, it could become one of the more powerful medium-term catalysts for Bitcoin.”
Data on Friday revealed that the consumer price index, excluding food and energy, climbed 0.3% in August from a month earlier — higher than expected.
According to CME’s FedWatch tool, traders think there is a 85% chance interest rates will be higher after the Federal Reserve meets next week. Bitcoin has typically performed well in a low interest rate environment.
But the U.S. Treasury’s expanded bond buyback programme has so far failed to materially suppress long-term yields.
If yields stay stubbornly high, Butterfill said, pressure will build on Treasury Secretary Scott Bessent to escalate to a much larger, “bazooka-style” buying programme aimed at forcing borrowing costs down.
Bitcoin in August had one of its best runs in years after Treasury Secretary Scott Bessent announced the department would double the size of its long-dated bond buybacks.
The announcement and subsequent price surge has led some to say the much talked-about debasement trade is back. The so-called debasement trade is when investors buy an asset as a way to hedge against a currency losing value.
Bitcoin and gold have both benefited as part of the trade as the dollar weakens.
This post Bitcoin’s ‘Unusual Mix’: Bearish Inflation Print, Bullish Buyback Failure first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Bitcoin Magazine

Blockstream Tells Hackers To Return Remaining Bitcoin Stolen in Liquid Theft
Bitcoin infrastructure firm Blockstream has refused to negotiate further with hackers who last week stole 4,000 bitcoins from its Liquid network.
Writing on X Friday, Blockstream said that the hackers still had time to return the funds before the company would work with law enforcement.
White-hat hackers on Sunday withdrew about $320 million from the federation wallet that backs Liquid, a sidechain by Blockstream. After negotiating with Blockstream, they returned most of the funds but kept 598.5 coins worth over $46 million — demanding it as ransom.
“Blockstream will not pay a ransom for the return of stolen funds,” the post read. “Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft.”
It added: “We will work with law enforcement, exchanges, service providers, forensic specialists, and other relevant parties to trace and recover the assets and identify those responsible.”
“We will not pay for the return of stolen property. We will not abandon our users. The Bitcoin community will not stop pursuing the funds.”
Liquid, or L-BTC, is a layer-2 created by Blockstream that allows users to fast move assets backed 1:1 with bitcoin. One of the assets, LBTC, is a token backed by bitcoin that allows for quick settlement — a bit like the Lightning Network.
Hackers were able to get the funds by exploiting an inflation bug on the Liquid sidechain to create over 4,000 LBTC that did not exist before and cash them out for real, on-chain bitcoins.
The hackers then had an exchange with Blockstream via messages written into Bitcoin blocks.
In one message, the white hats wrote: “Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.”
In the latest message, the hackers slammed Blocksteam as “delusional, greedy, and arrogant,” and threatened to reveal all of Blockstream’s encrypted messages in the exchange unless the company allowed thieves to keep 10% of the bitcoins.
“You SHALL pay 10% using your own money as bug bounty or you will cause all your holders a 15% loss for your irresponsibility and stinginess,” the message read.
The Bitcoin community is still reeling after hackers in July were able to steal over 1,800 bitcoins worth close to $140 million from Coldcard wallet holders.
Users of the popular hardware wallet, created by Coinkite, were targeted because the product’s manufacturer did not use a true random number generator, allowing hackers to essentially guess investor seedphrases.
This post Blockstream Tells Hackers To Return Remaining Bitcoin Stolen in Liquid Theft first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Bitcoin Magazine

Italy’s Second Biggest Bank UniCredit Is Weighting up Crypto Custody: Report
Italy’s second largest bank is considering expanding into digital asset offerings, including custody, according to reports.
According to a Friday Bloomberg report citing people familiar with the matter, Milan-based UniCredit is selecting a technology provider that would allow it to build the infrastructure needed to hold digital assets and facilitate their buying and selling.
Bloomberg’s reporting added that tokenized investment products and fixed-income securities, the use of stablecoins and exposure to cryptocurrencies were all on the cards.
The news comes as other banks in Europe expand crypto offerings. Spain moved first on retail, with BBVA rolling out bitcoin trading and custody to all customers via its app, using its own custody infrastructure rather than a third party; Santander’s Openbank followed with its own trading service.
Cecabank — a Spanish custodian with over €400bn under management that acts as backbone for 100+ financial institutions — went live with crypto custody in June via a partnership with Bit2Me.
And in Germany, Deutsche Bank is building custody with Bitpanda’s technology arm, while Taurus and DZ Bank got BaFin approval in January for its meinKrypto platform.
New regulation in the European Union — Markets in Crypto-Assets Regulation (MiCA) — gives banks a legal definition, a supervisor, and a familiar set of obligations to launch crypto services.
UniCredit is one 37 lenders across 15 European countries working together to create a company called Qivalis with the aim of issuing a euro-denominated stablecoin.
Last year, the bank said it was offering professional clients a structured product tied to BlackRock’s iShares Bitcoin Trust exchange-traded fund, with full protection against losses.
This post Italy’s Second Biggest Bank UniCredit Is Weighting up Crypto Custody: Report first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Bitcoin Magazine

Government Defeated as Lords Back UK Digital Assets Strategy
The UK government suffered a defeat in the House of Lords on Wednesday as peers backed an amendment requiring the Treasury to draw up a national strategy for regulating digital assets.
The upper chamber approved the measure by 194 votes to 138, with Conservative and Liberal Democrat peers combining against a near-solid bloc of Labour votes. Baroness Neville-Rolfe, a Conservative former Treasury minister, moved the amendment to the Financial Services and Markets Bill.
The new clause, titled “Digital assets strategy,” would require the Treasury to prepare, publish and consult on a strategy for regulating and developing digital assets and related digital financial market infrastructure in the UK.
The regulation of digital assets includes “cryptoassets, qualifying stablecoins, Central Bank Digital Currencies, tokenised securities and other digital and tokenised financial assets,” according to the draft.
The UK is in the process of drafting a sweeping new crypto bill. The country’s Financial Conduct Authority finalised its regulatory framework for cryptoassets in June, with the regime due to take effect on 25 October 2027. The authorisation gateway for firms opened on 30 September and runs to 28 February 2027.
Britain is trailing behind Brussels and Washington with digital asset regulation. The EU’s Markets in Crypto-Assets regulation has applied to service providers since 30 December 2024.
And the U.S. under President Donald Trump signed the GENIUS Act into law in July 2025, establishing a federal framework for dollar-backed tokens. Broader market-structure legislation remains unfinished: the Clarity Act cleared the House in July 2025 by 294-134 but has been stuck in the Senate over DeFi, stablecoin yield and ethics provisions, with a procedural vote set for next week.
This post Government Defeated as Lords Back UK Digital Assets Strategy first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Bitcoin Magazine

Bitcoin Price Spikes, Shrugs off Hot US Inflation Data
Bitcoin’s price rose on Friday — despite data revealing that U.S. inflation had risen.
The biggest cryptocurrency by market cap was recently trading for close to $78,749 after jumping 2% over a 24-hour period. At one point on Friday morning in New York, bitcoin rose as high as $79,607.
Bitcoin’s price spike came after news dropped that U.S. consumer prices accelerated in August, reinforcing expectations that the Federal Reserve will raise interest rates next week.
The consumer price index, excluding food and energy, climbed 0.3% in August from a month earlier, which was higher than expected.
Inflation in the U.S. has been difficult to tame due to the war with Iran, which has lifted oil prices, in turn raising the costs of food, gasoline and other goods.
Higher inflation typically means the Federal Reserve will raise interest rates, which in turn could stop bitcoin’s price climbing higher.
According to CME’s FedWatch tool, traders think there is a 85% chance interest rates will be higher by next week. The Federal Reserve will meet next week and reveal what it will do with borrowing costs.
Bitcoin has typically performed well in a low interest rate environment because it means people can buy more of the cryptocurrency with increased liquidity.
Federal Reserve Chairman Kevin Warsh, who took the helm in January, last month gave his first speech as head of the U.S. central bank and said he had “more work to do” to fight inflation.
The U.S. is currently in the grips of an affordability crisis and rising oil prices are a hot topic ahead of the midterm elections.
U.S. President Donald Trump has reassured voters that prices will get under control and repeatedly put pressure on the central bank to lower interest rates.
Bitcoin in August had its biggest run in years following positive regulatory news and an announcement from the U.S. Treasury.
Treasury Secretary Scott Bessent announced the department would double the size of its long-dated bond buybacks, helping non-yielding assets like bitcoin and gold. The cryptocurrency then benefited from President Trump urging lawmakers to get key crypto legislation, the Clarity Act, over the line.
This post Bitcoin Price Spikes, Shrugs off Hot US Inflation Data first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
HTTP error 429 on https://cryptoslate.com/feed/
Failed to fetch feed.
This week holds only one date that really bites, and it is now eleven days away. Anyone who held Beldex or Humanity at the crypto exchange Kraken has already been credited with the respective replacement token by airdrop. The only thing left to do with it is to withdraw it, and that option closes on September 25, 2026 at 14:00 UTC. After that the exchange liquidates whatever is left. This is the last full calendar week before that date, and there are two separate notices for two separate tokens: anyone who held both has two things to do.
As in the previous week, a warning belongs at the top, because the pattern has repeated itself. Last week it was Holoworld AI, whose claim from September 2025 was circulating through search results as a fresh airdrop. This week it is Meteora (MET). The project confirmed its TGE and airdrop in an announcement dated September 10, from September 10, 2025. The TGE took place on October 23, 2025. Two weeks, two prominent “live” airdrops that actually date from the previous year. That is no coincidence. It is the basic pattern of this field: airdrop announcements display the day and the month prominently and the year almost never. Check it first.
This overview lists the airdrops that either have a claim window open this week or have a confirmed date within the next 14 days. Every figure comes from the source linked alongside it, retrieved again on September 14, 2026. Where a project has published no end date, that is stated explicitly. There are no estimated deadlines here. For the state of play a week ago, see our piece on the airdrops of week 37.
| Project | Status | Date / deadline |
|---|---|---|
| Beldex & Humanity (at Kraken) | Airdrop credited, withdrawal required | until September 25, 2026, 14:00 UTC |
| Plume (Season 2) | Claim open | no end date published; registration closed on May 27, 2026 |
| Grass (Stage 2) | Claim open | until January 22, 2027 |
| GRVT | Tranches continue | 30 days per tranche; date of the second unlock not published |
| dappOS (DOS) | Phase 2 claim open | since August 11, 2026, end not published |
This entry is the most unusual on the list, because nobody here had to claim anything. Both projects were attacked in June 2026, both responded by rolling out a new token contract and distributing the replacement one for one to holders as of the snapshot. Kraken handled the distribution for its customers and credited it automatically, which is why two additional lines have been sitting in those accounts ever since. An airdrop you never had to claim can still expire.
The key data differ by project, and that is the reason for the two separate notices. For Beldex, the snapshot was taken on June 10, 2026 at 23:36 UTC, and the new token was credited on July 10, 2026 at 14:00 UTC. For Humanity, the snapshot came earlier, on June 8, 2026 at 17:25 UTC, set by the Humanity team itself, and the new $HUMANITY was credited as early as July 1, 2026 at 14:00 UTC. Anyone who bought the token in question only after the snapshot is not entitled to it according to the exchange, and in neither case is there an application portal through which that could be sorted out after the fact.
The ending, by contrast, is identical for both. Trading and deposits have already been switched off for all affected tickers, withdrawal remains the only function, and it closes on September 25, 2026 at 14:00 UTC. From September 28 to October 2, 2026, the exchange will liquidate any remaining balances itself. In the same notice it points out explicitly that the proceeds may fall well below recently seen prices and, in individual cases, may be minimal or zero. When the notices were retrieved again on September 14, 2026, neither carried any reference to an extension.
What has to be done this week therefore comes down to a single action with a date attached: withdraw before the window closes, and do it separately for each of the two tokens. We have written up the full procedure, including the contract addresses that distinguish the old token from the new one, under “Kraken withdrawal deadline on September 25”. The separate route for Humanity and the unlocking of the token are covered under “Humanity unlock: the H deadline at Kraken”.
Sources: Kraken Support, “Notice of Beldex ($BDX) delisting and $BELDEX airdrop” and Kraken Support, “Important update regarding Humanity (H)” (both retrieved again on September 14, 2026; snapshots, credits, withdrawal deadline and liquidation window are set out there verbatim)
Plume is a layer 1 chain for tokenised real-world assets. Season 2 of the points programme ended on March 31, 2026, and registration for the distribution ran from April 29 to May 27, 2026. Anyone who missed that step is excluded according to the project, and there is no way to fix it retroactively. Eligibility required wallets with at least 10,000 Plume Points, in some cases plus verification through Human Passport.
The claim has been running through the official portal since the end of May 2026, and the gap of recent weeks remains unchanged: Plume has at no point named an end date. The announcement text gives the registration deadline and says of the claim itself only that it is planned for “later in May”, with the exact date to follow through the official channels. To this day it has not followed. When the site was retrieved on September 14, 2026, the project blog carried three newer posts than a week earlier, dated September 8, 9 and 10, 2026, and all three concerned partnerships and product launches rather than the airdrop.
The figure circulating in secondary reports, a window of roughly three months that would arithmetically have run out at the end of August, still does not come from Plume. We carry it only because it is circulating, and explicitly not as a deadline. In practice that changes nothing about the advice. If anything it sharpens it: a claim with no published end date can be closed at any time without prior announcement. Anyone eligible and registered should claim rather than wait.
Source: Plume, “Plume Points Season 2 Airdrop Registration Is Now Open” (retrieved again on September 14, 2026; the announcement still names no end date for the claim, and the project blog carries no post on the subject)
The Solana project Grass has been paying out its Stage 2 rewards since July 22, 2026. Epochs 1 to 19 are covered, meaning the period from October 14, 2024 to June 8, 2026. The claim runs through the project's official dashboard.
Grass is one of the few projects with a cleanly published deadline. The claim is open until January 22, 2027, a full six months. Whatever has not been claimed by then stays with Grass. That is the literal wording in the project documentation, and it was still there unchanged when the page was retrieved again on September 14, 2026. This is the most comfortable entry on the list and, experience suggests, still the one where most value is left on the table, because half a year feels like unlimited time. Four of the six months have now passed. Put the date in your calendar if you are eligible.
Source: Grass, “How Your Stage 2 Rewards Allocation Works” (retrieved again on September 14, 2026; the January 22, 2027 deadline and the forfeiture clause carry unchanged wording)
The derivatives exchange GRVT held its token generation event on July 30, 2026 and is distributing a total of 280 million GRVT. The mechanics are the strictest on this list. The distribution runs in tranches over twelve months, and every unlocked tranche carries a claim window of 30 days. Once it expires, the tranche is permanently lost according to the project.
Two points are decisive here and are regularly confused. First, registration: it closed on July 27, 2026 at 00:00 UTC, and anyone who missed it has forfeited their allocation, which no later claim can undo. Second, automation: only the first tranche that falls due is sent automatically, and even that only where registration happened before July 17, 2026. Anyone who signed up later has to claim every tranche themselves through the Reward Portal, according to the wording of the help text, and to do so within the 30 days.
GRVT publishes no unlock schedule, and when the help section was retrieved again on September 14, 2026 it carried no date for the second tranche. For allocation and vesting schedule the text refers exclusively to the Reward Portal of your own account. We deliberately do not calculate the date here. What counts is the expiry date the portal displays for your specific tranche. This is precisely where forfeited entitlements arise, so set yourself a reminder. The project recommends as much itself.
Source: GRVT Help Center, “How to Receive and Manage Your $GRVT Airdrop” (retrieved again on September 14, 2026)
The DOS token launched with its TGE on August 10, 2026, and phase 2 has been running since August 11, 2026, in which eligible wallets can claim transferable DOS. A phase 3 has been announced, but without a date, and no end date has been published for any of the phases so far. Nothing has changed there since last week. The claim portal on the project domain is the only official route.
What comes afterwards is the real decision. A freshly distributed token with a small market capitalisation swings wildly in its first weeks, and the selling pressure from an ongoing claim hits it on top of that. Anyone who wants to trade such a position at all needs access that covers the small pairs. Pure charting tools such as Dexscreener or TradingView only display prices; no trading happens there. One alternative is the mobile app FOMO Family, which lets you discover, swipe through and trade meme and low-cap tokens directly in the app, with fast deposits. Download the app through the link and secure yourself a 10 percent discount on trading fees. Sobriety belongs with that: trading meme and low-cap tokens is highly risky, volatility is extreme and a total loss is possible at any time. Where else DOS is traded can be seen in our comparison of crypto exchanges.
These candidates did not make the list. The reason differs in each case, and each reason is worth as much as an entry:
Alongside that, the standing rule of this format: projects listed as “live” on aggregator sites but naming neither a snapshot nor a claim window at the project source do not get in. “Airdrop confirmed, date open” is not a deadline.
Airdrops are the preferred hunting ground for wallet drainers, and the patterns repeat:
An airdrop is not by definition a tax-free gift. Whether the allocation has to be treated as other income under Section 22 No. 3 of the German Income Tax Act depends above all on whether you provided something in return, which is also how the still authoritative circular of the German Federal Ministry of Finance of March 6, 2025 draws the line. This week's Kraken case also shows that two events have to be kept apart: the inflow of the replacement token in July, and the later withdrawal or sale. A forced liquidation by the exchange is likewise an event you have to document, even if you did not trigger it.
So when you claim, record the time, the quantity, the market value, the price source, the transaction hash and the terms of participation straight away. The last of these tends to disappear first once a campaign page is taken down. That a token you have not sold can also trigger a tax liability is something we explain separately.
The Optimism case shows that a distribution once promised can also be reallocated, which you can read in our piece on the reallocation of the Optimism airdrop. For an overview of further campaigns, see our section on crypto airdrops.
Week 38 is a week with exactly one task and four observation posts. The task is called September 25: anyone who held Beldex or Humanity at Kraken has long had the replacement token in their account and eleven days to withdraw it, twice over where both tokens are affected. After that the exchange decides on liquidation, and it says itself that little or nothing may come of it.
The four remaining entries stand unchanged: Plume, GRVT and dappOS with open windows and no published end, and Grass as the only project with a clean closing date of January 22, 2027, of which four of the six months have now elapsed.
The methodological finding of the week is the same as last week's, and that is exactly what makes it matter: once again a prominently traded “live” airdrop turned out to be a year old. When a mistake repeats twice in a row, it is the rule rather than a slip. Check the year before you connect a wallet.
And the necessary sobering note: most allocations run into double or triple digits, the fee for claiming eats a noticeable share of that, and a substantial proportion of all allocated tokens is never claimed at all. The effort pays off above all where you are already eligible.
Disclosure: some of the providers named in this article work with us through partner programmes. This has no influence on our editorial assessment.
(As of September 14, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
On Wednesday, September 16, 2026, the US Federal Reserve publishes its interest rate decision, and futures markets mostly expect a hike. If you have a savings plan running on Bitcoin, the honest answer to the question of what you have to do now is: probably nothing. Two things are still worth checking, and beforehand rather than afterwards: exactly when your next instalment is executed, and how much headroom a running crypto loan still has.
This article explains what actually happens on September 16, which mechanism connects a US policy rate to your monthly Bitcoin purchase, and where the meeting day gets expensive for retail investors. It contains no price forecast, because nobody can seriously predict how the market will react to a decision that is already largely priced in.
The body that sets the US policy rate is called the Federal Open Market Committee, or FOMC: the monetary policy committee of the Federal Reserve, which meets eight times a year and sets the target range for the overnight rate between banks. The meeting runs over two days, September 15 and 16, 2026. The decision comes on the second day.
The Federal Reserve meeting calendar marks the date with an asterisk. That asterisk looks like a footnote and carries the most important information on the page: it flags the meetings at which the Fed publishes a Summary of Economic Projections. Those projections are the collected expectations of the central bankers on growth, unemployment, inflation and the future level of rates, and they reach several years ahead. After September, only two meetings remain in 2026, on October 27 and 28 and on December 8 and 9.
The decision is published at 18:00 UTC, which is 20:00 in central European summer time. The press conference starts half an hour later. For you that means: Wednesday evening between 20:00 and 21:00 CEST is the window in which prices on crypto exchanges get most turbulent. The Frankfurt stock market has long since closed by then; the crypto market keeps trading.
The current target range for the overnight rate is 3.50 to 3.75 percent. It has been in place since July 30, 2026, as recorded in the Fed's implementation note for the July meeting. A basis point is one hundredth of a percentage point, so 25 basis points are 0.25 percentage points. If the step goes through, the range would afterwards sit at 3.75 to 4.00 percent.
Why expectations flipped at all can be pinned to a single number. US consumer prices in August were 3.4 percent higher than a year earlier, with the core rate at 2.4 percent; the largest single driver was petrol, up 3.9 percent. After the release on September 11, the probability of a September hike priced into futures markets jumped. The figures different houses quote for the CME FedWatch reading sit in a range of roughly 86 to 90 percent, after around 70 to 72 percent the day before. I am deliberately not smoothing that range: the value moves with every trading day, and the spread itself is the more honest piece of information.
The numbers come from CNBC's report on August consumer prices, which carries the FedWatch readings. Important for context: a priced-in probability reflects what the market has in the price. The value is a bet by futures traders and carries no predictive power beyond that, and that is exactly why prices move less on the expected step than on the deviation from it.
The connection is less mysterious than many headlines make it sound. A higher policy rate means that parking money risk-free earns more. Anyone getting four percent on overnight deposits or short-dated government bonds demands a higher compensation for anything riskier. Bitcoin pays no interest and consists exclusively of price movement. As the risk-free return rises, so does the bar Bitcoin has to clear.
On top of that comes the funding channel. A large share of short-term trading volume in the crypto market runs on borrowed money. When money gets more expensive, leveraged positions shrink and the market gets thinner. That explains why price moves on central bank days are often more violent than the news itself warrants.
At the time of writing, Bitcoin trades at around 76,700 US dollars, or roughly 66,200 euros; retrieved on September 14, 2026 at 00:40 UTC via CoinGecko's public price interface. In the preceding 24 hours the change was under one percent. That figure is a snapshot and no basis for a decision meant to work over years.
The short answer is no, and the reason lies in the purpose of a savings plan. A savings plan buys a fixed amount at fixed intervals, regardless of the price. It is the decision to stop making individual decisions. Anyone who pauses it ahead of a scheduled event has abolished it at exactly the moment it was built for.
What does make sense is checking once whether the instalment still fits your circumstances. If rising rates make your mortgage or your overdraft more expensive, the instalment is the lever, not the execution date. Which providers allow which minimum instalments, intervals and fees is set out in our comparison of Bitcoin savings plan providers, and with small instalments the fee side quickly becomes the largest cost block.
Pausing means: you do not buy this month. Adjusting means: you keep buying, but with an amount you can sustain through a bad quarter as well. The first is a market forecast in disguise, the second is household budgeting. Only one of the two is something you can do reliably.
Dollar cost averaging describes a simple arithmetic phenomenon: anyone buying regularly for the same amount gets more units at low prices and fewer at high ones, so the average price ends up below the mean of the prices. No promise of returns comes with that, and no protection against losses either. The effect is a procedure that prevents timing errors.
On a central bank day the benefit shows particularly clearly, because the price move after the decision can go either way and the counter-move often follows within hours. A savings plan simply does not take part in that question. If you want to know how it stacks up against a lump sum purchase, we worked it through in our article on savings plans and lump sum purchases when buying more of August 24, 2026.
This is the part where a meeting day can do real damage. Anyone who has pledged crypto assets as collateral and taken out a loan against them is working with a loan-to-value ratio: the relation of the loan amount to the current value of the collateral. If the price of the collateral falls, that ratio rises. Once it crosses the provider's limit, an automatic sale follows. This forced sale is called liquidation, and it does not ask whether the move will be over again an hour later.
Two figures determine how well you sleep here. The first is the distance between your current ratio and the liquidation threshold. The second is the interest rate you pay on the loan, because variable rates in crypto loans track market rates and demand for the borrowed asset. Our overview "Crypto lending: interest rates and risks" of August 16, 2026 describes these mechanisms in detail.
Log in once before Wednesday evening and note down two numbers: the price at which your position would be liquidated, and the distance between that price and today's level in percent. If that distance is in single digits, it is a state you should change regardless of the Fed. Either by topping up collateral or by repaying part of the loan.

Because a 25 basis point hike is around nine tenths priced into the market, the actual information sits in the projections. Their best-known component is the dot plot: a scatter of points in which every member of the committee anonymously marks where they see the policy rate at year end. If that cloud shifts upwards, the committee is signalling further steps. If it stays where it is, the September step was a one-off response to the price data.
For a savings plan that is the only relevant question of the evening, and it is a question about months, not hours. A rate peak reached in December looks entirely different for long-term investors than a path pointing upwards well into 2027.
Around every meeting, price targets appear from institutions and individual analysts. Take them for what they are: expectations attributable to a name. Anyone quoting a price target should be able to name its source; without a name, all that remains is sentiment. And where expectations diverge, both sides belong side by side, the optimistic one and the cautious one.
The spread is the gap between the price at which you can buy and the price at which you could sell. It is the part of the cost almost nobody calculates, because it does not appear on the statement. In turbulent market phases it widens, and that is exactly what happens in the hour after a central bank decision.
If your savings plan executes on the 16th or 17th of the month anyway, that is no reason to change anything; over years it evens out. But if you were planning to change the execution date regardless, a date in the quieter middle of the month between two central bank meetings is the less conspicuous choice. While you are at it, check whether your provider executes at a fixed time or at some point during the day; in the latter case the timing is out of your hands.
Anyone holding Bitcoin through an exchange-traded product rather than directly gains a second layer: those securities only trade during exchange hours. If the decision lands at 20:00 CEST, while German trading is closed, you only see the move the next morning at the open, and then all at once.

Directly nothing, indirectly a great deal. Anyone holding Bitcoin as private assets in Germany can realise gains tax free once a year has passed; that one-year period is called the holding period and runs separately for every purchase. With a savings plan that means: you have as many holding periods as executed instalments.
The connection to the Fed arises the moment a price move tempts you to sell. Anyone selling after a violent evening move may realise gains from instalments that have not yet reached the one-year mark, and pays their personal income tax rate on them. The order in which the tax office assigns the units sold follows the first-in-first-out principle: the units bought first count as sold first. What that looks like in concrete terms with monthly instalments is set out in our article "Bitcoin savings plans and tax: holding period, FIFO and the exemption limit" of August 11, 2026.
The most expensive mistake is rarely bad timing. What gets expensive is the unintended: a decision to sell in the evening, taken in reaction to a headline, which only reveals its price in the following year's tax return. What helps against that is a rule you write down before Wednesday, not on Wednesday.
(As of September 14, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
An Ethereum address that belongs to you has been able to execute someone else's program code since the Pectra upgrade, without its address, its balance or its key changing at all. EIP-7702 is what makes this possible: one signature from you is enough, and from that moment on your address behaves like a contract. This is the basis for many convenient wallet features, and it is also the route by which attackers keep a drained account permanently under their control. This article shows you how to check in two minutes whether your own address carries such a delegation, and what to do if the contract sitting there is one you do not recognise.
The basis for this is our own measurement on the Ethereum chain, taken today. It shows how widespread these delegations have become and what they mostly point to. The answer is more uncomfortable than wallet marketing suggests, but also more nuanced than a bare percentage implies.
EIP-7702 is an extension to Ethereum that lets an ordinary key-controlled account run the program code of a contract without becoming a contract itself. The account keeps its private key, its address, its balance and its nonce. All it gains is a pointer to a contract whose code runs on the account's behalf on every call.
The technical term for this is delegation. The pointer is written into the account's code field, which until then was empty for a key-controlled account. From that moment on, anyone calling the account calls the stored contract, and that contract reaches the account's storage and balance.
The benefit is obvious. A wallet can bundle several steps instead of asking you to sign three times. A provider can cover the fee on your behalf. An app can set up a tightly bounded spending permission that expires after an hour. These are exactly the features wallet makers have been selling under the Smart Account label since 2025.
The price sits in the same sentence: the stored contract acts with your account's full authority. It can move funds, grant approvals and trigger further calls. A delegation is therefore not a setting but a power of attorney, and it stays in place until you replace it or revoke it.
A delegated account carries exactly 23 bytes in its code field: the fixed marker 0xef0100 followed by the 20 bytes of the target address. That marker is the only reliable evidence. Everything else an interface shows you is interpretation.
In practice you see it in two places. A block explorer suddenly lists your address as a contract, or displays a note about a delegated account, even though you have never deployed a contract. And the code lookup that every explorer offers returns, instead of an empty value, a short string beginning with ef0100.
The 20 bytes that follow are the address you have to check. They decide everything. If your wallet maker's contract address is sitting there, the delegation is probably intended. If something unfamiliar is sitting there, you have a problem that goes well beyond a misplaced click.
One point matters for context: an empty code field is the good news. If you find nothing there, you have no active delegation, regardless of whether one existed in the past.
The check takes a few minutes and needs neither a tool nor an installation.
ef0100 means the delegation is active.The same check works on every chain where EIP-7702 is live. An authorisation signed for chain ID zero is even valid on all chains at once. Anyone using several networks is better off checking more than once.

This analysis was carried out by cryptoticker.io itself on September 13, 2026. Method: we pulled 200 consecutive blocks in full from a public Ethereum node, blocks 25,971,139 to 25,971,338, and evaluated every transaction of type 0x04 in them together with its authorisation list. The window runs from 21:14:35 to 21:54:23 UTC and covers 39.8 minutes of chain time.
The numbers from that window:
What we could not measure is how many accounts currently carry a delegation in total, because that would require a full state dump of the chain rather than a time window. Nor can these data show how much money was moved through the contracts we found. And a 40-minute window is a snapshot: another day may show a different distribution.
In this measurement the names say more than the shares do. Publicly verified source code is available for two of the three most frequent targets, and both describe themselves as tools used by criminals.
The most frequent target, with 2,007 authorisations, or 49.7 percent of the window, carries the name Poisoner in its verified source code. The comment in the source names the purpose outright: the contract is used for address poisoning, that is, to trick inattentive users into sending funds to a wrong address that looks visually similar. As the party behind the publication, the source names the trading firm Wintermute, which says it rebuilt and disclosed the contract. The program code itself is short: it executes a list of arbitrary calls, but only if the transaction was triggered by exactly the address that created the contract.
The third most frequent target, with 170 authorisations, carries the name CrimeEnjoyor. Here too the explanation sits in the source code, and it is set in capital letters: anyone who finds this contract in an authorisation list has a compromised account; no further funds may be sent there, because they will be swept immediately. The code is shorter still than that of the first contract. It does precisely one thing: every incoming amount is forwarded straight away to a target address fixed at setup.
For comparison, the legitimate side of the same list: in eighth place sits a verified contract from a well-known wallet maker with 110 authorisations, alongside several contract accounts from the account-abstraction world with 10 to 49 authorisations each. Those contracts run to several thousand bytes, while the two conspicuous targets get by on 772 and 1,042 bytes. A contract that only sweeps needs little code.
Care is needed here, because the percentage invites a false conclusion. So we looked at who actually sent these transactions.
The result: the 2,007 authorisations pointing at the top-ranked contract come from 186 transactions, and those 186 transactions came from a single sender. With 176 distinct senders across the whole window, almost half of all authorisations therefore trace back to one address that registers bundles of up to 110 powers of attorney at a time, minute after minute.
Our reading of this, and it is explicitly a reading rather than an established fact: the pattern does not fit 2,007 freshly harmed users, but rather an operator kitting out their own throwaway addresses. Besides the single sender, the design of the contract supports that view, since it only executes calls for its own creator. In address poisoning the attacker generates the deceptively similar addresses themselves and needs no one else's key to do so. What we are measuring in this case is infrastructure rather than loot.
The second conspicuous contract looks different. Its 170 authorisations are spread across 170 separate transactions from two senders, so one power of attorney per transaction. A collection contract that forwards incoming amounts immediately only makes sense for an account whose key is already in someone else's hands. For you as a reader the difference is decisive: the first case almost certainly does not concern you, the second concerns you directly if your account appears on that list.

A sweeper is a contract or program that forwards incoming amounts to an outside address automatically and within seconds. If you find a delegation to such a contract on your address, the delegation is not the cause but the consequence. Someone was able to sign in your name, and that requires your private key or your recovery words.
From this follows an order of operations that runs against the first reflex. The reflex says: revoke the power of attorney and move on. The correct view is this: the account is lost, and every amount you send there, including the fee for the revocation, will very likely go to the attacker. A revocation you pay for yourself funds the other side, in case of doubt.
So set up a new account first, ideally on a device whose key has never sat on a computer. Which designs come into question, and how the devices differ, is laid out in our software wallet comparison alongside the device selection. Only afterwards do you deal with whatever is left on the old account, and you do so with help.
For exactly this case there is a free point of contact, one that the sweeper contract's own source code names: the Flashbots whitehat hotline. It helps get remaining balances past a sweeper by settling the rescue and the fee in a single bundle that the sweeper cannot pick off separately. That is no guarantee, but it is the only serious route that requires no payment up front.
If the account is clean and the delegation is merely unwanted, because you no longer use a wallet feature for instance, then revoking it is simple and still easy to misunderstand.
A delegation does not end because you delete the app, change device or withdraw an approval. It ends solely through a new authorisation pointing at the zero target address, that is, an address made up entirely of zeros. Only then does your account's code field become empty again. Our measurement shows that this step does occur in practice: 140 of the 4,035 authorisations in the window were revocations of this kind.
Check the code field once more after revoking. An interface reporting success to you is not evidence. The evidence is an empty code field in the explorer.
A second point is easily overlooked: a new delegation replaces the old one entirely. Anyone switching from one wallet provider to another ends up with the new provider's power of attorney in the account, not both. That is reassuring, but it does not remove the need to check, because which contract ends up sitting there is decided by the most recently registered authorisation.
The most dangerous part of EIP-7702 is its price. An authorisation is a pure signature. It costs you nothing, it shows up in no fee summary, and you do not even have to submit it yourself: any third party may wrap it into a transaction of their own and cover the fee.
For honest providers that is an advantage, because a new account becomes usable straight away without holding funds. For a fraudulent site it is a gift. It needs no transfer from you, no approval and no balance on the account. A single signature in a window that looks like a login, a claim for free tokens or a security check is enough.
From this follows a rule for everyday use: treat every signature request whose content you cannot read as if it were a transfer. That applies in particular to requests asking you to update, migrate or secure an account. You already know this trick in its classic form from the world of manipulated payment recipients; how it plays out there was covered in our August analysis of address poisoning.
It would be wrong to conclude from all this that every delegation is an attack. Alongside the conspicuous targets, our measurement also shows a number of clearly attributable wallet contracts, among them the contract of a large browser wallet provider and several account templates from the account-abstraction world.
Three characteristics separate the two groups fairly reliably in practice:
Anyone working with several wallets regularly should note down their own provider's target address once. The check then becomes a comparison of twenty bytes next time, rather than a research task.
A common misconception holds that a hardware wallet makes this question moot. That is true for the key, but not for the power of attorney. An EIP-7702 authorisation is also signed with the private key, and in the worst case the device displays only a target address and a nonce, without being able to explain what follows from them.
What matters, then, is whether your device presents the content of a signature request in plain text and whether you have switched off the signing of unreadable data. What counts here was set out in our article on blind signing on hardware wallets. The recommendation from there applies unchanged: what the device cannot display, you do not sign.
The second protection is the separation of duties. One account for day-to-day dealings with applications, a second for holdings that stay put, and no signature from the second account on any website. A delegation on the everyday account is annoying; a delegation on the holdings account is expensive. If you need the technical wording of the specification, you can read it in the text of EIP-7702, in particular the rules for chain ID zero.
ef0100 means: read out the target address and look it up. Start with the addresses that actually hold something, and then set those holdings up on a device you pick from the hardware wallet comparison.(As of September 13, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Since September 11, 2026 a duty applies across the whole of the EU that did not exist in this form before: anyone who makes a product with digital elements available commercially on the European market must report an actively exploited vulnerability to the competent bodies within 24 hours and inform affected users about the vulnerability and about the countermeasures they can take themselves.
For you as a holder of cryptocurrencies, the second part is the more important one. It sits in Article 14(8) of the EU Cyber Resilience Act and shifts the question of who has to make sure you learn about a problem with your wallet. Until now that was a matter of company culture. From now on it is a legal duty with a fining framework behind it.
This article explains what exactly applies, from when, to whom, and where the line runs between the documented legal position and over-interpretation. Because the regulation does not name a single wallet brand, and anyone who derives a list of affected manufacturers from it is writing more than what is there.
The Cyber Resilience Act is Regulation (EU) 2024/2847, usually called the Cyber Resilience Act or CRA for short. The CRA entered into force on December 10, 2024, but only applies in full from December 11, 2027. Article 71(2) contains one sentence that upends the whole timetable: "This Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026, and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026."
Article 14 is headed "Reporting obligations of manufacturers" and is thus the part of the regulation that was switched on first. Everything else — the conformity assessment, the CE marking, the essential cybersecurity requirements in Annex I — only arrives in 2027. So anyone reading right now that the CRA applies means this one article.
The core in one sentence: a manufacturer must report every actively exploited vulnerability in its product and every severe security incident simultaneously to the CSIRT designated as coordinator and to the EU Agency for Cybersecurity, ENISA, through a single reporting platform.
What is a CSIRT? A Computer Security Incident Response Team is the body designated by a member state that receives, assesses and passes on security incidents. In Germany, CERT-Bund within the Federal Office for Information Security is the coordinating CSIRT, and the BSI also handles market surveillance.
What is an actively exploited vulnerability? A security flaw the manufacturer knows attackers are already using. A theoretical gap someone found in a laboratory does not start the 24-hour clock. Abuse in practice does.
The CRA is not financial law and not crypto law. It is horizontal product law and takes no interest in which assets a device manages, only in whether it is a product with digital elements and whether it is made available commercially on the EU market. That is precisely what makes it relevant for crypto custody.
A hardware wallet is a physical device with firmware that talks to companion software over USB, Bluetooth or QR code. A wallet app is software a provider makes available for download. By their design, both are what Article 3(1) describes as "a software or hardware product and its remote data processing solutions". Article 2(1) draws the boundary via the connection: the regulation applies to products whose intended purpose or reasonably foreseeable use includes "a direct or indirect logical or physical data connection to a device or network".
For the custody of cryptocurrencies, that is the point at which something changes. If you hold your balance yourself, your security hangs on exactly two things: on the quality of the device or the software, and on whether you find out in time when something is wrong with it. On the first, the reporting duty still says nothing; the corresponding requirements only bite in 2027. On the second, it says something with immediate effect. Which devices are available at all and how they differ is in our hardware wallet comparison; for purely software solutions the same considerations apply with a different attack surface.
Whether a specific device or a specific app is covered is decided by three test steps. There is no list of affected products. First: is the product made available on the EU market, that is, supplied for distribution or use in the course of a commercial activity? Second: is it a software or hardware product within the meaning of Article 3? Third: does its intended or reasonably foreseeable use include a direct or indirect data connection?
A commercially distributed, connected hardware wallet and a wallet app offered by a company can satisfy these three questions. That is an application of the legal test and not an official finding for any particular product. Anyone who turns it into a claim that this or that provider must now do this or that is asserting something that neither the regulation nor the Commission's guidelines supports.
Where the manufacturer is based also matters. Article 14(7) regulates this in detail: what governs is the CSIRT of the member state in which the manufacturer has its main establishment in the Union, that is, where the decisions on the cybersecurity of its products are predominantly taken. If it has no establishment in the EU at all, an order of precedence applies: first the member state of the authorised representative, then that of the importer, then that of the distributor, and finally the member state in which the largest number of users is located. A provider outside Europe is therefore not automatically out of scope once it serves the European market.

The regulation requires three reports that build on one another. All deadlines start at the moment the manufacturer becomes aware.
For a severe security incident under Article 14(3) the same split into 24 and 72 hours applies, but there the final report is due one month after the 72-hour notification. When an incident counts as severe is defined in paragraph 5: when it affects the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive data or functions, or when it has led or can lead to the execution of malicious code.
Reporting runs through the CRA Single Reporting Platform operated by ENISA. The manufacturer submits once, and the report is made available to the competent coordinating CSIRT and to ENISA at the same time. After the final report, the reporting person can as a rule no longer edit the submission.
The deadlines towards the CSIRT and ENISA are the part the industry press writes about. For you as a user, the decisive sentence sits elsewhere, namely in Article 14(8). Slightly abridged, it reads: after the manufacturer has become aware of an actively exploited vulnerability or a severe security incident, "it shall inform the affected users of the product with digital elements, and where necessary all users, about that vulnerability or incident and, where necessary, about any risk mitigation and corrective measures that the users can deploy".
Three points in this are worth reading closely.
First: the duty attaches to the same awareness as the report to the authorities. The trigger is the same moment. For informing users, however, the regulation names no fixed number of hours. What is required is information in connection with becoming aware, and elsewhere the text turns on timeliness. Anyone who turns the 24 hours for the authority into a 24-hour deadline towards customers is reading the provision wrongly.
Second: users must be informed about the countermeasures they can take themselves. That is the practical core. A notice that merely says there was a problem does not satisfy the wording if there are measures users can take themselves. With a wallet, those measures are precisely the relevant ones: update the firmware, temporarily stop using a particular function, move a balance to a new address, check a signature manually before confirming it.
Third: the regulation would like a machine-readable format. The text speaks of a structured, machine-readable format that is easy to process automatically, and qualifies this with "where appropriate". For security researchers and for portals that aggregate warnings, that is the most interesting wording in the whole paragraph.
The second sentence of paragraph 8 is the genuinely new lever: "Where the manufacturer fails to inform the users of the product with digital elements in a timely manner, the CSIRTs designated as coordinators may provide such information to the users when they consider it to be proportionate and necessary for preventing or mitigating the impact of those vulnerabilities or incidents."
European law thereby states that an authority may inform the public about a product vulnerability if the manufacturer does not do so in time. For Germany that means, concretely: CERT-Bund at the BSI receives the report as coordinating CSIRT, and the BSI can act as market surveillance authority. That is not an obligation to warn; the wording is "may" and turns on proportionality and necessity. For you it nevertheless means that from now on there is a second place at which information about a product you use comes together.
A look at the cases of recent weeks shows that this route is needed. When a vulnerability in a Bitcoin Lightning implementation became public in August, the information for operators hung on a release note and on trade media. We worked through that case in our article on the Core Lightning vulnerability and the question of when a node has to go offline. How a wallet warning can be technically verified at all is in our article on blind signing and how to switch it off on your hardware wallet.
Here is the qualification that belongs in every honest text on this subject. Neither the regulation nor the European Commission's guidelines names a single wallet brand, a single device type from the crypto world, or any particular provider. The CRA works with abstract product categories and a legal test that every economic operator has to carry out for itself.
Two things follow from that. For one, you cannot read from the regulation whether a particular device you own is covered. That depends on how the manufacturer is organised, where it is based, how it distributes, and how the competent authorities apply the legal test in the individual case. For another, over the coming months you will read texts that fill this gap with names. Anyone writing that a specific provider "now has to" do this or that is formulating a legal assessment for which there is neither an administrative decision nor a court ruling.
The only reliable thing at this point is the procedure. If such a statement interests you, check two things. Is there a manufacturer's own declaration behind it, or a statement by an authority? And does it refer to Article 14, which has applied since September 11, or to the conformity duties that only bite from December 11, 2027? The two are frequently conflated at the moment.

A large part of crypto infrastructure is open source and maintained by individuals, associations or foundations. For this constellation the CRA contains its own treatment, and that matters for what you can expect.
Free and open source software is, under recital 18, software whose source code is openly shared and whose licence provides for all rights to make it freely accessible, usable, modifiable and redistributable. What is decisive for the scope is the commercial character of the supply: according to the same recital, only free and open source software that is made available on the market, and thus supplied for distribution or use in the course of a commercial activity, falls within the scope. The mere circumstances of development and the type of funding are expressly not meant to play a role.
On top of that comes Article 64(10)(b). Under it, the fines regulated there do not apply to stewards of open source software, and that holds for every infringement of the regulation. It is one of the clearest privileges in the entire legal act.
For you as a user that means: with a wallet that arises as an open project without commercial supply, you should not count on anyone being legally obliged to notify you. With a device or an app a company offers commercially, the position is a different one, even if the source code is open. The question of who stands behind a product and how it is distributed was a good selection question before. From September 11, 2026 that question additionally has a legal side.
A duty without consequence remains an appeal. Article 64(2) sets the framework: infringements of the obligations laid down in Articles 13 and 14 are subject to fines of up to 15 million euros or, in the case of undertakings, up to 2.5 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. The reporting duty therefore sits in the highest of the three fining bands the regulation knows.
When setting the amount in the individual case, paragraph 5 requires the nature, gravity and duration of the infringement to be taken into account, along with previous fines against the same economic operator and the size of the undertaking including its market share. Microenterprises and small enterprises are expressly mentioned.
For them there is an additional relief. Article 64(10)(a) exempts manufacturers that qualify as micro or small enterprises from the fines regulated in paragraphs 3 to 9, insofar as the missed 24-hour deadline under Article 14(2)(a) or Article 14(4)(a) is concerned. The reporting duty itself does not fall away as a result, only the sanction for missing that one deadline. For a small wallet startup with three developers and no on-call rota, that is the difference between a demanding provision and an existential one.
Enforcement lies with the market surveillance authorities of the member states. In Germany, the BSI is designated for that. A fine imposed must be communicated by the authority to the market surveillance authorities of the other member states through the information system under the Market Surveillance Regulation.
Article 14 applies to all manufacturers of products with digital elements, irrespective of a risk class. Beyond that, the regulation knows two annexes that list particularly sensitive products, and their legal consequences only bite with the full start of application on December 11, 2027. A look at them is worthwhile all the same, because it shows how the legislator thinks about this type of device.
Annex IV lists three entries under the heading "Critical products with digital elements": hardware devices with security boxes; smart meter gateways as well as "other devices for advanced security purposes, including secure cryptoprocessing"; and smartcards or similar devices, including secure elements. Annex III names, in class I, among other things microprocessors and microcontrollers with security-related functionalities, and in class II tamper-resistant microcontrollers.
Those are exactly the components a hardware wallet is built from: a secure element, a tamper-resistant microcontroller, a shielded environment for cryptographic operations. Whether a particular device falls under one of these entries is again decided case by case. The direction is recognisable, though, and for manufacturers of such devices it means a stricter conformity assessment from the end of 2027, one in which a notified body can be involved.
The regulation addresses manufacturers. You do not have to act because of it. But there are four things that are more informative from now on than they were before.
You will find the official wording of the regulation in the Official Journal of the EU as Regulation (EU) 2024/2847, German-language text; Article 14 sits in Chapter II, the start of application in Article 71(2). The German reporting route including a table of deadlines is described by the BSI on its page about the CRA Single Reporting Platform.
(As of September 13, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
If you kicked off a swap through Chainflip over the weekend and nothing has arrived since, the problem is almost certainly not your wallet. The network has been at a standstill since Saturday. On September 12, 2026 an attacker drained 736,442.17 USDT through the protocol's Tron rail, and Chainflip switched off trading in response. What matters for you: your balance has not disappeared, but you cannot reach it at the moment either. This article explains what is measurably switched off, what is still running, and in which order to check your holdings.
Chainflip is a swap protocol that moves value between different blockchains. In the early hours of Saturday, September 12, 2026, an attacker drained 736,442.17 USDT from the protocol's settlement path on Tron, according to the matching accounts of two trade publications. The incident only became apparent when subsequent USDT payments failed. The team then halted network operations.
The attack ran for roughly 90 minutes. According to the account given by crypto.news, there were eight attempts, six of which resulted in a payout. The amounts escalated: on that analysis, each further attempt was roughly double the previous one. Chainflip says it has fixed the flaw, flagged the drained funds and announced that affected users will be made whole after the restart. At the time of writing, the restart was announced for Monday at the earliest.
736,442.17 USDT was drained. Only settlement on Tron is affected. A further, still open swap by one user worth 115,654.41 USDT sits unpaid in the protocol's holdings according to both sources and is considered eligible for reimbursement. For the remaining networks, neither report records any losses.
A cross-chain swap is a trade in which you deposit on one blockchain and are paid out in a different currency on another. Classic bridges solve this by locking up your bitcoin and issuing you a placeholder on the target chain, a so-called wrapped token. Chainflip works without such placeholders: a network of validators holds the funds jointly and pays out the real asset on the target chain.
For you as a user, normal operation means this: you are given a deposit address, you send your amount there, and after a few minutes the swapped asset is in your wallet on the target chain. There is no account, no sign-up and no self-custody during the process. That very design is why a standstill of the protocol affects you directly: there is no customer interface in which you could simply withdraw your funds.
On most supported networks, Chainflip reads the swap instruction from a contract call. On Tron, according to the technical account by crypto.news, it works differently: there the protocol evaluates the memo field of a transfer, a free text field that can be attached to a transaction.
On that account, the attacker attached a further memo to a transaction the validators had already signed. The system read this addition as an independent second swap instruction. When that second instruction appeared to fail, the protocol paid out a refund even though the original deposit had already been served. The core of the incident is that a signature stays valid while the readable content beside it can still be changed.
One point that appears in both reports matters for context: no private key was stolen and no custodian was opened. The payouts came out of the protocol's regular process, triggered by an instruction the protocol took to be genuine.

cryptoticker.io collected this analysis itself on September 13, 2026. Chainflip reports its network state in a public programming interface that anyone can query. We queried it between 15:53 and 15:56 UTC with seven calls, each with a logged response code, and additionally checked the provider's quote service on four swap routes.
The result is unambiguous. The section for the swap business reports three switches set to "off": swaps are switched off, deposits are switched off, withdrawals are switched off. The same applies to liquidity providers on all three counts. The provider's quote service answered with code 503 on all four routes tested, meaning "service unavailable": bitcoin to ethereum, USDC from Ethereum to USDT on Tron, the reverse direction from USDT on Tron to USDC on Ethereum, and Solana to bitcoin.
More interesting than the switched-off items is what is not switched off. The return of network shares in the funding area is set to "on". Liquidity providers may continue to adjust their quotes. Validator rotation and the registering and deregistering of bids are running. Registration of new brokers is open too.
The blockchain itself is also running undisturbed. The network node reported 36 peers and no sync in progress. Two calls of the block head 137 seconds apart returned the heights 14,801,511 and 14,801,534, so 23 new blocks and thus the usual six seconds or so per block. The network is producing; it is only not trading.
Also readable from the interface: Chainflip currently supports 18 assets on seven networks, among them Bitcoin, Ethereum, Solana, Arbitrum, Polkadot, Assethub and Tron. For Tron the minimum deposit is 30 TRX or 10 USDT.
Two limits of this measurement belong with it. First, it cannot be established from outside whether individual stuck swaps will be completed automatically after the restart. Second, the number of affected users is not measurable, and Chainflip has published nothing on it. The figure of 115,654.41 USDT for the open swap comes from the reporting and not from our query.
The state we measured is not an outage but an intended operating mode. The protocol can switch off individual functional areas without halting the blockchain. That is exactly what has happened here, and the choice of switches says something about the situation.
That withdrawals were switched off as well is the most uncomfortable part for you. It means that even a completed swap whose proceeds still sit in the protocol will not move to you at the moment. At the same time it is the measure that prevents a second drain over the same route for as long as the cause is not conclusively closed. That liquidity providers can still adjust their quotes suggests a restart of trading is being prepared rather than a wind-down of the protocol.
For your own course of action, a simple rule follows: waiting is the right move in this situation, and sending more is the wrong one. Anyone who now sends funds to an old deposit address only lengthens the list of cases that have to be worked through after the restart.
Work through the points in order. The order is not arbitrary: the first two steps cost nothing and establish whether you are affected at all.
Every swap carries its own identifier, which the interface showed you when you started it. Enter it in the provider's block explorer. It shows the state the case is stuck in: at the deposit, in the swap itself, or before the payout. If you cannot find your case there at all, it was never accepted, and the funds are still on the source chain.
Look up the transfer you deposited with in the explorer of the source chain. Two cases need to be told apart. If it is confirmed and has arrived at the deposit address, your amount sits in the protocol and you are waiting for the restart. If it is unconfirmed or was never sent, nothing has happened and you can swap elsewhere.
Look in the wallet you gave as the destination, and on the right chain. A common misconception is that the proceeds arrived long ago but the wallet does not display the target network at all. USDT on Tron does not show up if your wallet only carries the Ethereum version.
The restart date and the question of whether stuck cases will be completed automatically are decided at the provider. Stick to its own channels. In the week after an incident like this, fake offers of help asking for your recovery phrase pile up. A reputable provider never asks for it. If you want to keep your keys on your own device anyway, the devices are set side by side in our hardware wallet comparison.
The deposit addresses of a protocol like this are tied to a single swap order and valid only for a limited time. Our measurement shows that the deposit path is switched off as well. A transfer to an address from an old order is therefore not being processed at the moment.
On the blockchain, the amount is then gone from your wallet all the same. It sits at an address you do not control, and whether and when it gets assigned depends on the provider. That is why this point gets a heading of its own here: it is the one mistake that can turn a waiting period into a genuine loss.

According to the matching accounts of both trade publications, Chainflip has announced that affected users will be made whole once operations resume. The wording is clear, the path there is not: which source the reimbursement will come from was open at the time of the reports. Reserves, ongoing protocol revenue and insurance solutions are named as options under review.
For you that amounts to a promise without a date and without a procedure. So secure now what will count as evidence later: the identifier of your swap, the transaction number of the deposit, the time, the amount and, if available, a screenshot of the interface. Anyone who has to gather these records only after the restart is worse off than someone who filed them the same day.
Part of the context is also what the promise is not. It is not statutory deposit insurance. A decentralised swap protocol is not covered by the protection you know from a bank account, and a promise in an announcement is something other than an enforceable claim.
Many users never encounter protocols like this under their own name. Wallets and swap aggregators integrate them in the background and route your order to whichever path currently offers the best rate. It is therefore quite possible that you are affected without ever having consciously chosen the brand.
The proof runs through the history. Open the order history in your wallet or in the service you swapped through and look at the case in question in detail. It usually shows the route used or at least the deposit address, which you can trace further in the block explorer of the source chain. If the entry stays unclear, customer service at the service you swapped through can help, because there you are the customer.
A memo is a free text field that many chains can attach to a transfer. Exchanges have used it for years to assign incoming payments to the right customer account. For protocols it is convenient, because it works without a contract of its own and is therefore quick to connect to a new network.
The price of that convenience is that free text has no fixed form. A contract function enforces structure and can be secured together with the signature; an attached text is, to begin with, only text. The attack described here exploited exactly that gap between what was signed and what was read.
What you take from it for your own practice is independent of this provider: if a service asks you to send a memo or a tag along, that field is part of the transfer and not decoration. A deposit without the required memo regularly ends up in no man's land and has to be assigned by hand. Chainflip itself has been expanding the Tron rail lately; the most recent post on it in its own blog is dated September 10, 2026 and promotes USDT on Tron as collateral in lending. At the time of our check on September 13 the blog did not yet carry a post on the incident; according to both trade publications the quoted statements come from the short message service X.
The case fits into a series. On September 6, 2026 around 4,000 bitcoin left the Liquid Network's federation wallet, and the sidechain was subsequently missing the bulk of its backing; we recalculated the backing of L-BTC at the time. In August it was the Sandbox project's bridge. Now it is a swap protocol without placeholder tokens.
The common feature is not the design, which differs considerably in all three cases. The common feature is the place: wherever one chain has to believe another about what happened on it, a translation arises. A translation can be read wrongly, and whoever gets it read wrongly takes money out without ever having held a key.
No panic follows from that, but a sober everyday rule does: the transition between two chains is a place for short stays. Value you want to hold for longer belongs on the chain where it is at home, and in custody whose keys you control yourself. A swap protocol is a passage, not a warehouse.
Three steps, in this order, and none of them takes longer than a few minutes.
The second independent account of the incident this article draws on is at The Crypto Times.
(As of September 13, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
TRM examined roughly $52.7 million across 198.9 million settlements using the x402 protocol. Most of it isn’t coming from AI agents, it says.
The fintech company fulfilled a fraudulent information request sent from a government agency's own email domain, exposing ID documents and full crypto transaction histories for a "limited" number of users.
A week after launch, complaints are rolling in from users that GPT-6 Astra has been nerfed. OpenAI's last model went through the same cycle in July.
Ben Delo and Christopher Harborne each gave £36 million, and between them beat what every UK party raised last year.
The surveillance mod on GTA V brings the privacy fight to Los Santos, where players can demolish the cameras tracking them.
The XRP Ledger has apparently set a new record after processing 3,254 transactions in a single ledger.
Cardano, Hyperliquid, Shiba Inu and Stellar are all testing key support zones after recent pullbacks.
Senate Democrats are holding a last-minute caucus meeting as the Clarity Act heads toward a high-stakes procedural vote that will require bipartisan support to advance.
Bitcoin locks in a historic $65,000 long-term support floor, as cycle mathematics may prevent future drops below this key threshold.
Bloomberg's Mike McGlone warns Bitcoin's tight correlation with S&P 500 and pending Fed hikes spark sell signals targeting a potential drop to $10,000.
Cross-chain infrastructure provider Symbiosis disclosed that its Bitcoin bridge infrastructure suffered a security breach on September 11, 2026. The exploit allowed an unauthorized party to leverage a flaw in the BridgeV2 smart contract, resulting in the creation of billions of illegitimate synthetic bitcoin tokens.
Cybersecurity monitoring platform Blockaid initially detected and publicized the breach. According to their analysis, the perpetrator generated approximately 46.1 billion syBTC—a quantity exceeding 2,000 times Bitcoin’s entire circulating supply. These fabricated tokens were transferred to a newly created wallet address.
While the quantity of counterfeit tokens minted was enormous, the attacker faced significant liquidity constraints. They managed to exchange only about 4.39 wrapped bitcoin via Uniswap on the Ethereum network, ultimately extracting approximately $336,000. The remaining minted tokens found no market demand.
Following the discovery, Symbiosis acknowledged the security incident and immediately suspended all native Bitcoin routing functionality. The protocol maintained operations for alternative routes spanning EVM-compatible blockchains, TRON, and TON networks. Their Octopools service continued functioning without interruption.
According to Symbiosis, the team has successfully retrieved roughly 15 BTC following the breach. At prevailing market rates, this recovery represents approximately $1.15 million in value. These reclaimed assets are currently secured in a multisignature wallet managed by the core team.
The development team initiated contact with the perpetrator, extending a white-hat bounty proposal equivalent to 20% of the misappropriated assets. This proposal included a September 13 deadline for acceptance. Following this cutoff date, Symbiosis announced it would redirect the identical 20% incentive toward any individual supplying actionable intelligence that facilitates additional fund recovery.
The platform indicated it is engaging directly with impacted liquidity providers. A compensation structure is under development, with specific eligibility parameters scheduled for imminent publication. Bitcoin exchange functionality has been reinstated through third-party integration partners Chainflip and THORChain, while the proprietary bridge remains disabled.
This breach represents another occurrence in an alarming trend. Within recent weeks, both Liquid Network and Nomic experienced comparable attacks featuring unbacked Bitcoin-derivative tokens.
The Liquid Network operated by Blockstream witnessed an adversary generate roughly 4,000 unbacked LBTC tokens and convert them for genuine Bitcoin. The perpetrator subsequently returned approximately 3,400 BTC, though Blockstream declined to compensate for the remaining 598.5 BTC that remains unrecovered.
Nomic encountered a distinct security weakness that remained undetected for an extended period under comparable conditions. All three breaches employed fundamentally identical methodologies—exploiting Bitcoin wrapper platforms to generate excessive tokens purportedly backed by legitimate assets.
As of September 13, Symbiosis has not released a comprehensive technical analysis detailing precisely how the BridgeV2 contract was compromised. No public statement has verified whether the attacker responded to the bounty proposal.
Since its inception approximately five years ago, Symbiosis has facilitated over $10 billion in cumulative transaction volume. The protocol currently maintains around $7 million in total value locked.
The post Symbiosis Bitcoin Bridge Hacked: 46B Fake syBTC Minted in $336K Exploit appeared first on Blockonomi.
The decentralized exchange Uniswap has achieved $71.1 billion in transaction volume throughout the last 30 days, establishing its position at the top of all decentralized platforms monitored by DeFiLlama. According to the protocol’s announcement, this figure surpasses the aggregate volume of the subsequent three leading DEXs.
During the past week alone, the platform facilitated more than $21.3 billion worth of transactions. On a daily basis, Uniswap manages approximately $2 billion in exchange activity.
The nearest rival, PancakeSwap, recorded $29.8 billion during the identical 30-day window. This creates a substantial difference of over $41 billion separating the two platforms.
The fourth iteration of Uniswap represents approximately $38 billion of the total monthly activity. The third version adds around $32 billion to this sum, while version 2 contributes an additional $1.2 billion.
The Uniswap protocol functions on more than 40 different blockchain networks. While Ethereum maintains the highest concentration of total value locked, networks including Base, Arbitrum, BNB Chain, Polygon, and Robinhood Chain all play significant roles in generating the overall volume.
On September 13, Robinhood Chain recorded approximately $1.35 billion in aggregate DEX transaction volume within a 24-hour window. Uniswap was responsible for roughly $262 million of that daily total.
Market analyst Yasuhiro observed that $UNI is currently breaching a persistent descending trendline visible on daily timeframes and maintaining position above ascending support levels. His analysis identified an optimal accumulation range between $4.40 and $4.80, projecting potential price objectives at $10.80 and $15.70, contingent upon the preservation of the established higher-low pattern.
Between January and July 2026, the platform accumulated $28.2 million in protocol earnings, extracted from $297.9 million in total trading fees, based on Token Terminal analytics. The highest monthly earnings reached $5.3 million during June.
As of early August, total accumulated revenue following fee activation climbed to $29.8 million. Through Governance Proposal 100, the fee structure expanded to version 4 liquidity pools spanning seven blockchain networks in July, boosting projected daily protocol earnings from approximately $114,000 to $325,000.
Collected fees are deposited into TokenJar smart contracts. Token holders can eliminate UNI through the Firepit mechanism to access these fees, establishing a direct connection between platform usage and token supply contraction. Additionally, a 100 million UNI treasury burn has contributed to overall supply reduction.
Current circulating supply stands at approximately 623 million UNI tokens, supporting a market capitalization of roughly $3.85 billion. The active burn rate continues to represent a modest fraction relative to total available supply.

On September 13, UNI exchanged hands near $6.21, reflecting roughly a 2% decrease from the previous session’s closing price, with intraday price action fluctuating between approximately $6.17 and $6.55.
The post Uniswap (UNI) Dominates DEX Market with $71B Monthly Volume Surpassing Top Competitors appeared first on Blockonomi.
The Sui (SUI) token is currently positioned around $0.72 following a roughly 4% decline over the previous 24-hour period and a 7% decrease throughout the past seven days. While recent price action shows weakness, the digital asset maintains approximately 5% gains across the 30-day window.

Market participants are concentrating their attention on the $0.70–$0.71 support region. Should this zone prove resilient, technical observers project a potential climb toward $0.84–$0.85. Conversely, a decisive breakdown beneath this threshold could trigger selling pressure toward the $0.62–$0.63 range.
Technical trader Bitguru highlighted the $0.70 support area as a critical inflection point. Based on Bitguru’s technical framework, a successful defense of this level could propel SUI back toward $0.85, with subsequent upside potential extending to $0.92.
Cryptocurrency analyst Ali Martinez echoed this perspective. Martinez indicated he would consider re-entering a long position should $0.71 maintain as support, projecting an upward channel target at $0.84.
Additionally, Martinez identified a TD Sequential buy signal appearing on SUI’s 12-hour chart. He referenced that this same technical indicator preceded a previous 17% price surge. “Now, with $SUI trading near $0.71, the indicator has flashed a fresh buy signal,” Martinez stated.
Trader Michaël van de Poppe contributed his perspective on the current technical setup. He expressed interest in seeing the support zone maintain strength and suggested that a gradual recovery toward $0.85 could bring prices above the $1 threshold back into consideration. Van de Poppe emphasized he is “remaining positive on this one.”
The convergence of multiple independent analysts, employing distinct analytical frameworks, arriving at remarkably similar price levels — $0.70–$0.71 for support and $0.84–$0.85 for resistance — lends additional credibility to these technical zones in the immediate term.
Derivatives trading volume is presently exceeding spot market activity for SUI. This dynamic has the potential to intensify price volatility through forced liquidations when leveraged positions reach their limits.
From an institutional perspective, the 21Shares Sui ETF (TSUI) commenced trading operations on Nasdaq starting February 24, 2026. Additionally, CME Group introduced SUI and Micro SUI futures contracts in May. These financial instruments expand institutional participation pathways.
The Sui blockchain network achieved a milestone of 16.17 billion cumulative transactions recorded as of September 13. The aggregate stablecoin market capitalization on Sui climbed above $463 million, representing an 8.85% weekly increase, with USDC comprising approximately 64% of this figure.
The Sui Foundation has implemented an ongoing token repurchase program, acquiring more than 609,800 SUI since January. This buyback initiative is financed through on-chain stablecoin revenue, with acquired tokens being redistributed into the ecosystem rather than permanently removed from circulation.
Scheduled monthly token releases of approximately 64 million SUI persist as an ongoing supply expansion factor. According to CoinMarketCap data, the current circulating supply stands near 4.09 billion tokens against a total maximum supply ceiling of 10 billion.
The post Sui (SUI) Price Analysis: Key Buy Signal Emerges at Critical $0.71 Support Level appeared first on Blockonomi.
Revolut is grappling with a significant security incident as cybercriminals have started publishing confidential customer data on the internet while issuing daily leak threats unless their ransom demands are satisfied.
The perpetrators made their intentions clear through a Telegram message, stating: “We’re going to start releasing more and more data everyday until revolut pays for leaking their customers.”
The initial data dump included identification credentials and personal photographs connected to professional tennis player Alexander Shevchenko and Felix Römer, who serves as chief executive of cryptocurrency gaming platform Gamdom, as revealed in a social media update from International Cyber Digest.
The stolen material encompasses complete names, birth dates, professional information, communication details, banking statements, and comprehensive payment histories, with cryptocurrency transaction records among the leaked materials.
Government-issued passports and driving licenses were also included in the breached dataset, as documented by TechCrunch in their coverage.
According to Revolut’s official statement, the data exposure stemmed from a “sophisticated external impersonation scam.” A malicious actor utilized an email account from an authentic government institution domain to file illegitimate information access requests.
The financial technology firm stated it identified the unauthorized activity, promptly blocked the compromised email address, and informed the appropriate government department, law enforcement bodies, privacy watchdogs, and banking supervisors.
Revolut acknowledged the breach impacted a “very limited” customer base, with all affected individuals receiving direct communication.
The precise count of impacted users has not been made public by the organization.
Cybersecurity professionals warn that leaked identification paperwork and biometric verification photographs significantly increase identity fraud risks for those whose information was exposed.
Users whose cryptocurrency transaction records were published may also encounter heightened privacy vulnerabilities.
Revolut emphasized that its technical infrastructure and customer financial assets remained secure and untouched.
The organization functions exclusively through digital channels without traditional banking locations and stands among Europe’s premier financial technology success stories.
Revolut is presently preparing for a possible stock market debut with ambitions of achieving a valuation approaching $200 billion.
The security breach’s timing presents challenges for the firm as it advances toward this significant corporate objective.
Revolut has not issued any public statement regarding potential compliance with the attackers’ extortion demands or outlined additional protective measures to stop subsequent data releases.
The crisis continues to unfold, with perpetrators maintaining their promise of ongoing daily information dumps until their financial requirements are satisfied.
The post Revolut Data Breach: Hackers Leak Customer Documents, Demand Ransom Payment appeared first on Blockonomi.
Dogecoin (DOGE) has positioned itself at a crucial technical juncture as market participants monitor a developing falling wedge formation. The popular memecoin hovers around $0.0835, retreating from its mid-August peak that touched approximately $0.10.

Technical analyst Crypto With Gopal highlighted the emerging falling wedge structure visible on the hourly timeframe. His analysis pinpoints $0.100 as a significant threshold, while identifying the $0.110–$0.120 band as the primary resistance area that buyers must overcome.
Meanwhile, analyst Trader Tardigrade examined broader market cycles on the monthly timeframe. His assessment reveals DOGE forming a rounded bottom combined with a descending trendline configuration that resembles formations observed before two earlier explosive rallies, suggesting what he characterizes as a potential “cycle ignition” scenario upon trendline breach.
Should DOGE successfully breach the wedge pattern’s upper boundary, Crypto With Gopal’s technical analysis projects a move toward $0.150. This represents significant appreciation from present levels, though the analyst emphasizes this projection serves as a technical objective rather than a guaranteed outcome.
The memecoin has slipped beneath its 20-day Simple Moving Average, currently positioned at $0.08589. The MACD indicator has generated a bearish crossover, with the MACD line dipping under its signal line, while expanding negative histogram bars indicate mounting selling pressure.

The lower boundary of the Bollinger Bands resides around $0.08003. A decisive breach below the $0.080 support threshold would likely negate the constructive technical outlook and potentially trigger additional selling.
According to Coinglass metrics, daily trading volume contracted 3.10% to settle at $710.71 million, yet open interest expanded 1.92% to approximately $1.27 billion. Data from Dogegod indicates open interest represents roughly 16.38 billion DOGE tokens, translating to about $1.5 billion in notional value.
Elevated open interest coupled with contracting volume indicates market participants maintain leveraged positions while awaiting a definitive directional move. This positioning dynamic could magnify price action in either direction once a breakout or breakdown materializes.
The cryptocurrency recorded its weakest valuation since 2023 during August, bottoming at $0.068. While DOGE has recovered from that trough, it remains substantially below its 2021 all-time high of $0.73.
The current circulating supply totals 155.9 billion tokens. An inflationary mechanism introduces 5 billion additional coins annually, creating persistent supply-side pressure on valuation. Unlike Bitcoin, Dogecoin has no maximum supply cap.
Cryptocurrency directory Cryptwerk reports that just 2,328 merchants globally currently accept DOGE as a payment method.
The post Dogecoin (DOGE) Forms Falling Wedge Pattern as Analysts Eye Historical Rally Setup appeared first on Blockonomi.
HTTP error 429 on https://cryptopotato.com/feed/
Failed to fetch feed.