The impending retirement wave among small-business owners could destabilize the economy, risking $5 trillion in enterprise value.
The post JPMorgan warns retirement wave threatening American Dream as millions of small businesses face uncertain futures appeared first on Crypto Briefing.
Finland's move may heighten NATO-Russia tensions, influencing market perceptions of potential military conflict in the longer term.
The post Finland joins France’s nuclear deterrence initiative amid Russia tensions appeared first on Crypto Briefing.
Trump's acceptance of ethics rules may accelerate crypto regulation, influencing market dynamics and legislative processes significantly.
The post Trump agrees to CLARITY Act ethics rules, clearing way for Senate vote appeared first on Crypto Briefing.
The controversial VAR decision highlights ongoing officiating issues, impacting league standings and intensifying scrutiny on technology use.
The post Manchester United drops points after controversial VAR decision hands derby to Manchester City appeared first on Crypto Briefing.
Investor sentiment cooling in HYPE ETFs may signal a shift in market dynamics, impacting future investment strategies and altcoin ETF competition.
The post HYPE ETFs see $26M in net outflows last week as investor sentiment cools appeared first on Crypto Briefing.
Bitcoin Magazine

Bitcoin’s ‘Unusual Mix’: Bearish Inflation Print, Bullish Buyback Failure
Bitcoin’s path higher just got harder in the short term, but the setup further out may be improving, according to a new report.
In a Friday note, European asset manager CoinShares’ Head of Research, James Butterfill, said firmer-than-expected core inflation raises the odds of tighter Fed policy and could cap bitcoin below $80,000 for now.
But the longer-term case, he argued, rests on the U.S. Treasury’s bond buyback programme failing to bring down long-end yields — a failure that could ultimately feed the debasement narrative that has supported both bitcoin and gold.
“The result is therefore a somewhat unusual policy mix for Bitcoin,” the report read. “Today’s CPI data is negative at the margin, increasing the probability of tighter monetary policy and potentially limiting the immediate upside.
“But the apparent failure of the Treasury’s current buying programme increases the likelihood of much more substantial intervention further ahead.”
It continued: “If that happens, it could become one of the more powerful medium-term catalysts for Bitcoin.”
Data on Friday revealed that the consumer price index, excluding food and energy, climbed 0.3% in August from a month earlier — higher than expected.
According to CME’s FedWatch tool, traders think there is a 85% chance interest rates will be higher after the Federal Reserve meets next week. Bitcoin has typically performed well in a low interest rate environment.
But the U.S. Treasury’s expanded bond buyback programme has so far failed to materially suppress long-term yields.
If yields stay stubbornly high, Butterfill said, pressure will build on Treasury Secretary Scott Bessent to escalate to a much larger, “bazooka-style” buying programme aimed at forcing borrowing costs down.
Bitcoin in August had one of its best runs in years after Treasury Secretary Scott Bessent announced the department would double the size of its long-dated bond buybacks.
The announcement and subsequent price surge has led some to say the much talked-about debasement trade is back. The so-called debasement trade is when investors buy an asset as a way to hedge against a currency losing value.
Bitcoin and gold have both benefited as part of the trade as the dollar weakens.
This post Bitcoin’s ‘Unusual Mix’: Bearish Inflation Print, Bullish Buyback Failure first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Bitcoin Magazine

Blockstream Tells Hackers To Return Remaining Bitcoin Stolen in Liquid Theft
Bitcoin infrastructure firm Blockstream has refused to negotiate further with hackers who last week stole 4,000 bitcoins from its Liquid network.
Writing on X Friday, Blockstream said that the hackers still had time to return the funds before the company would work with law enforcement.
White-hat hackers on Sunday withdrew about $320 million from the federation wallet that backs Liquid, a sidechain by Blockstream. After negotiating with Blockstream, they returned most of the funds but kept 598.5 coins worth over $46 million — demanding it as ransom.
“Blockstream will not pay a ransom for the return of stolen funds,” the post read. “Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft.”
It added: “We will work with law enforcement, exchanges, service providers, forensic specialists, and other relevant parties to trace and recover the assets and identify those responsible.”
“We will not pay for the return of stolen property. We will not abandon our users. The Bitcoin community will not stop pursuing the funds.”
Liquid, or L-BTC, is a layer-2 created by Blockstream that allows users to fast move assets backed 1:1 with bitcoin. One of the assets, LBTC, is a token backed by bitcoin that allows for quick settlement — a bit like the Lightning Network.
Hackers were able to get the funds by exploiting an inflation bug on the Liquid sidechain to create over 4,000 LBTC that did not exist before and cash them out for real, on-chain bitcoins.
The hackers then had an exchange with Blockstream via messages written into Bitcoin blocks.
In one message, the white hats wrote: “Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.”
In the latest message, the hackers slammed Blocksteam as “delusional, greedy, and arrogant,” and threatened to reveal all of Blockstream’s encrypted messages in the exchange unless the company allowed thieves to keep 10% of the bitcoins.
“You SHALL pay 10% using your own money as bug bounty or you will cause all your holders a 15% loss for your irresponsibility and stinginess,” the message read.
The Bitcoin community is still reeling after hackers in July were able to steal over 1,800 bitcoins worth close to $140 million from Coldcard wallet holders.
Users of the popular hardware wallet, created by Coinkite, were targeted because the product’s manufacturer did not use a true random number generator, allowing hackers to essentially guess investor seedphrases.
This post Blockstream Tells Hackers To Return Remaining Bitcoin Stolen in Liquid Theft first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Bitcoin Magazine

Italy’s Second Biggest Bank UniCredit Is Weighting up Crypto Custody: Report
Italy’s second largest bank is considering expanding into digital asset offerings, including custody, according to reports.
According to a Friday Bloomberg report citing people familiar with the matter, Milan-based UniCredit is selecting a technology provider that would allow it to build the infrastructure needed to hold digital assets and facilitate their buying and selling.
Bloomberg’s reporting added that tokenized investment products and fixed-income securities, the use of stablecoins and exposure to cryptocurrencies were all on the cards.
The news comes as other banks in Europe expand crypto offerings. Spain moved first on retail, with BBVA rolling out bitcoin trading and custody to all customers via its app, using its own custody infrastructure rather than a third party; Santander’s Openbank followed with its own trading service.
Cecabank — a Spanish custodian with over €400bn under management that acts as backbone for 100+ financial institutions — went live with crypto custody in June via a partnership with Bit2Me.
And in Germany, Deutsche Bank is building custody with Bitpanda’s technology arm, while Taurus and DZ Bank got BaFin approval in January for its meinKrypto platform.
New regulation in the European Union — Markets in Crypto-Assets Regulation (MiCA) — gives banks a legal definition, a supervisor, and a familiar set of obligations to launch crypto services.
UniCredit is one 37 lenders across 15 European countries working together to create a company called Qivalis with the aim of issuing a euro-denominated stablecoin.
Last year, the bank said it was offering professional clients a structured product tied to BlackRock’s iShares Bitcoin Trust exchange-traded fund, with full protection against losses.
This post Italy’s Second Biggest Bank UniCredit Is Weighting up Crypto Custody: Report first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Bitcoin Magazine

Government Defeated as Lords Back UK Digital Assets Strategy
The UK government suffered a defeat in the House of Lords on Wednesday as peers backed an amendment requiring the Treasury to draw up a national strategy for regulating digital assets.
The upper chamber approved the measure by 194 votes to 138, with Conservative and Liberal Democrat peers combining against a near-solid bloc of Labour votes. Baroness Neville-Rolfe, a Conservative former Treasury minister, moved the amendment to the Financial Services and Markets Bill.
The new clause, titled “Digital assets strategy,” would require the Treasury to prepare, publish and consult on a strategy for regulating and developing digital assets and related digital financial market infrastructure in the UK.
The regulation of digital assets includes “cryptoassets, qualifying stablecoins, Central Bank Digital Currencies, tokenised securities and other digital and tokenised financial assets,” according to the draft.
The UK is in the process of drafting a sweeping new crypto bill. The country’s Financial Conduct Authority finalised its regulatory framework for cryptoassets in June, with the regime due to take effect on 25 October 2027. The authorisation gateway for firms opened on 30 September and runs to 28 February 2027.
Britain is trailing behind Brussels and Washington with digital asset regulation. The EU’s Markets in Crypto-Assets regulation has applied to service providers since 30 December 2024.
And the U.S. under President Donald Trump signed the GENIUS Act into law in July 2025, establishing a federal framework for dollar-backed tokens. Broader market-structure legislation remains unfinished: the Clarity Act cleared the House in July 2025 by 294-134 but has been stuck in the Senate over DeFi, stablecoin yield and ethics provisions, with a procedural vote set for next week.
This post Government Defeated as Lords Back UK Digital Assets Strategy first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Bitcoin Magazine

Bitcoin Price Spikes, Shrugs off Hot US Inflation Data
Bitcoin’s price rose on Friday — despite data revealing that U.S. inflation had risen.
The biggest cryptocurrency by market cap was recently trading for close to $78,749 after jumping 2% over a 24-hour period. At one point on Friday morning in New York, bitcoin rose as high as $79,607.
Bitcoin’s price spike came after news dropped that U.S. consumer prices accelerated in August, reinforcing expectations that the Federal Reserve will raise interest rates next week.
The consumer price index, excluding food and energy, climbed 0.3% in August from a month earlier, which was higher than expected.
Inflation in the U.S. has been difficult to tame due to the war with Iran, which has lifted oil prices, in turn raising the costs of food, gasoline and other goods.
Higher inflation typically means the Federal Reserve will raise interest rates, which in turn could stop bitcoin’s price climbing higher.
According to CME’s FedWatch tool, traders think there is a 85% chance interest rates will be higher by next week. The Federal Reserve will meet next week and reveal what it will do with borrowing costs.
Bitcoin has typically performed well in a low interest rate environment because it means people can buy more of the cryptocurrency with increased liquidity.
Federal Reserve Chairman Kevin Warsh, who took the helm in January, last month gave his first speech as head of the U.S. central bank and said he had “more work to do” to fight inflation.
The U.S. is currently in the grips of an affordability crisis and rising oil prices are a hot topic ahead of the midterm elections.
U.S. President Donald Trump has reassured voters that prices will get under control and repeatedly put pressure on the central bank to lower interest rates.
Bitcoin in August had its biggest run in years following positive regulatory news and an announcement from the U.S. Treasury.
Treasury Secretary Scott Bessent announced the department would double the size of its long-dated bond buybacks, helping non-yielding assets like bitcoin and gold. The cryptocurrency then benefited from President Trump urging lawmakers to get key crypto legislation, the Clarity Act, over the line.
This post Bitcoin Price Spikes, Shrugs off Hot US Inflation Data first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
The CLARITY Act’s chances of becoming law climbed above 32% as Senate Republicans unveiled their final compromise before Tuesday’s cloture vote.
Polymarket traders pushed the probability of the landmark crypto market-structure legislation being enacted in 2026 to its highest level since Aug. 2 after Republicans released a 635-page final draft designed to resolve several disputes that have held up the bill.
The move marks a turnaround from weeks of skepticism surrounding the legislation, though prediction-market pricing remains well below levels seen earlier this year. The contract reached about 82% in February before political disputes over ethics, stablecoin rewards and decentralized-finance protections complicated its path through the Senate.
Tuesday provides the next test. Senators are scheduled to vote on cloture on the motion to proceed with H.R. 3633, a procedural step that would require 60 votes and allow the chamber to begin considering the legislation. If cloture is invoked, the final text would then be offered as a substitute amendment.
Republicans said the latest version incorporates 126 substantive changes Democrats requested after more than a year of negotiations. The revisions touch some of the bill's most contentious parts, including financial ethics rules for elected officials, stablecoin rewards, protections for blockchain developers, and conflicts involving digital-asset trading platforms.
White House digital-assets adviser Patrick Witt cast the revisions as evidence that Republicans had exhausted the room for compromise.
“At every step of the way during the Clarity Act negotiations, the White House and Senate Republicans have been responsive to Democrats’ stated policy objectives,” Witt said. “After more than a year’s worth of negotiations, it’s time to pass this bipartisan bill.”
The most politically significant change concerns President Donald Trump and other federal officials with substantial crypto-related financial interests.
Trump agreed to substantially all of an ethics proposal developed by Republican Sen. Thom Tillis and Democratic Sen. Ruben Gallego. The framework would require covered officials with significant crypto interests to divest them or place them in a qualified blind trust, while giving state attorneys general a role in enforcing the restrictions.
That concession addresses one of the most persistent Democratic objections to the legislation. Republican negotiators said Trump voluntarily accepted restrictions covering federally elected officials, judges and their spouses. The White House had previously resisted giving state attorneys general a larger enforcement role.
Republicans also added a stablecoin “circuit breaker” intended to address concerns from community banks that crypto-based rewards could accelerate deposit flight. The measure would give the Treasury secretary authority to intervene if payment stablecoins were found to be causing substantial withdrawals from community banks.
The Blockchain Regulatory Certainty Act provisions were narrowed as well. The final version protects software developers from money-transmission registration requirements and creates a civil safe harbor, while pulling back protections that could have extended more broadly into criminal cases.
Agriculture Committee provisions add restrictions around affiliate trading and conflicts of interest involving digital commodity exchanges, brokers and dealers. The legislation also preserves state consumer-protection laws and clarifies that protections for software developers do not override derivatives regulation or the Commodity Futures Trading Commission's (CFTC) existing authority.
Republicans are now presenting those concessions as their final offer.
Sen. Cynthia Lummis said Democrats had received more than 120 of the changes they sought and argued that Tuesday’s vote would determine whether senators were willing to proceed with legislation after those demands were addressed. Banking Committee Chairman Tim Scott similarly said the negotiations had produced more than 100 Democratic-requested changes.
The increase in Polymarket odds suggests traders see the revised package as improving the bill’s prospects, but Tuesday’s hurdle remains political rather than probabilistic. Republicans need enough Democrats to join them to reach the 60-vote cloture threshold.
The critical signal before the vote will therefore come from the senators whose objections drove the latest concessions. If enough of them publicly shift toward supporting cloture, the prediction market’s rebound could have room to run further. If they remain uncommitted despite the final offer, Republicans could enter Tuesday with many of Democrats’ requested provisions in the bill but still without the votes needed to debate it.
The post Trump concession sends CLARITY Act odds above 32% before make-or-break Senate vote appeared first on CryptoSlate.
Cross-chain protocol Symbiosis said it recovered approximately 15 BTC after an attacker exploited its native Bitcoin Bridge, but affected liquidity providers still lack compensation terms as a Sep. 13 bounty window nears its unspecified cutoff.
The vulnerability was exploited at about 04:28 UTC on Sep. 11, according to the protocol's incident statement. Symbiosis said only the Bitcoin Bridge was affected and that its other routes and components remained operational. It specifically listed routes spanning EVM chains, TRON and TON as unaffected, and said its relayer group continued operating to secure the network. The protocol said the recovered bitcoin is secured in a team-controlled multisig.
The 15 BTC figure is simply the amount Symbiosis says it recovered to date. The protocol said final accounting remained in progress and that it would publish confirmed figures in another update.
Security firm Blockaid reported that a transaction accepted as signed by Symbiosis's BridgeV2 system minted approximately 2^62 raw units of syBTC, a synthetic representation of bitcoin, to a newly created wallet on BNB Chain.
Blockaid said the same beneficiary sold about 4.39 WBTC on Ethereum, realizing roughly $336,000 in WBTC proceeds at the time of its alert. That figure covers value Blockaid observed the attacker convert. It does not establish Symbiosis's final loss or the total exposure of liquidity providers.
Symbiosis initially said Bitcoin-related swaps were unavailable while it deployed updates. In a later operational update, the protocol said Bitcoin swaps routed through partners Chainflip and THORChain were back online, while the native Symbiosis Bitcoin Bridge remained paused.
That distinction determines what users can access. Partner-routed Bitcoin swaps are available, according to Symbiosis, but the protocol has not announced the return of the affected bridge. The split keeps traffic off Symbiosis's paused bridge while users access alternative Bitcoin routes.

Symbiosis said it was contacting every affected liquidity provider directly and building a compensation framework, with criteria to follow. It has not disclosed who will qualify, how compensation will be calculated or when payments could begin.
The protocol also offered the attacker a 20% white-hat bounty through Sep. 13. After that window, Symbiosis said the same percentage would be offered to anyone providing information that leads to recovery. The statement did not specify an exact cutoff time or timezone.
Affected liquidity providers are now waiting for three disclosures: confirmed loss and exposure figures, compensation criteria, and any change to the native bridge's status. Until Symbiosis publishes that information, the recovered funds and Blockaid's proceeds estimate should not be treated as a final loss tally.
The post Hackers mint trillions in fake Bitcoin, but 15 BTC bridge recovery leaves liquidity providers unpaid appeared first on CryptoSlate.
In decentralized finance, “audited” is often presented as a verdict on an entire project. In practice, an audit usually covers named code, components and versions at a particular point in time. Anything added, excluded or operated around that boundary may carry a different level of assurance.
A new preprint puts a number on that gap. Researchers affiliated with security company ack3 and the Czech Technical University in Prague examined 135 reported incidents from the first half of 2026, with $939.86 million in attributed losses. They found identifiable public pre-incident audits for 68 incidents.
Within that 68-incident subset, the authors classified 46 attack paths as outside every audit scope they could identify, 20 as inside at least one scope and two as unresolved. The outside-scope group represented 67.6% of the incidents but 94.4% of their reported losses.
That striking percentage is not an estimate of audit effectiveness or proof that an audit’s boundaries caused a loss. It describes the distribution of losses in a selected set of reported incidents. Two large cases also dominate it: after excluding $292 million at Kelp DAO and $285 million at Drift Protocol, the outside-scope share falls to 72.1% of losses in the same audited-incident subset.
Even with those limits, the study exposes a basic assurance problem. A project may truthfully say it was audited while leaving users unable to tell whether the live system, the path holding their funds and the controls around it were reviewed.

The ack3 dataset covers incidents from Jan. 1 through June 29. Its authors graded 122 as confirmed and 13 as likely. Of the full set, 35 had no identified audit and 32 had an unknown audit history, so neither group appears in the 68-incident scope calculation.
For that 68-incident group, outside-scope incidents accounted for $680.97 million of $721.24 million in reported losses, producing the 94.4% figure. Removing Kelp DAO and Drift Protocol left $103.97 million of $144.24 million outside scope, or 72.1%. The machine-readable ledger reproduces the bucket counts and loss sums.
The inside-or-outside labels remain the researchers’ judgments about public evidence. They searched project and auditor archives, located pre-incident reports and compared the eventual attack paths with reviewed code, versions and exclusions. The work is a six-page preprint produced with the dataset publisher, and two authors are affiliated with ack3, which sells security reviews.
The study also lacks an unexploited comparison group and a measure of how long each system was exposed. It cannot establish whether audited protocols are safer overall, estimate incident probability or show that falling outside scope caused each loss. Undisclosed audits and private incidents may be missing, while reported loss figures are not perfectly comparable.
The study therefore supports a limited conclusion: audit history and audit scope are different variables. A reviewed smart contract does not automatically confer the same assurance on an upgrade, privileged key, front end, relayer, oracle, cloud service or incident-response process.
Two incidents from August illustrate that distinction in different ways. ICON Network provides a direct example of reviewed code failing at the boundary between two checks. The August aelf incident provides a contrasting case because the available audit evidence cannot yet be tied to its reported runtime path.
In ICON Network’s Aug. 27 replay exploit, two parts of a withdrawal path interpreted the same message differently.
According to the ICON Foundation’s Aug. 30 postmortem, a migration contract used the high bits of a withdrawal message’s serial number to decide whether it was unique. The cryptographic signature covered only the low 256 bits. By changing the unsigned high bits, an attacker resubmitted two legitimately signed withdrawal messages 1,492 times over about 20 minutes. ICON said 1,490 calls succeeded.
The replays released 119.866 million ICX and 531,600 bnUSD. At the time of the postmortem, ICON put the confirmed net loss at about 150.2 ETH plus 31,204 USDC. It said 531,600 bnUSD and 1.366 million SODA had been recovered and that user deposits, balances and positions were not affected.
ICON said the migration contract had undergone an external audit and that recommendations had been implemented, including changes in the same area. It also said the relevant relay logic received a dedicated review. The SODAX audit archive lists eight reports across different components, including a November 2025 relay audit.
Yet the postmortem said the precise mismatch between the uniqueness check and the signed value fell outside those findings. A project-level badge could not tell a user whether both ends of the withdrawal path agreed on what made a message unique.
The response timeline adds a second kind of boundary. ICON’s first automated alert fired at 02:08 UTC, about seven minutes after the exploit began. Staff opened an investigation around 03:40, paused the affected contract at 03:53 and halted the network at 06:18:54.
ICON attributed the roughly 90-minute gap between the first alert and a full incident response to alert tuning. The alert class had produced false positives during unrelated connectivity incidents and did not page the on-call team at the needed severity. The foundation said it planned an automatic shutdown trigger, lower circuit-breaker thresholds and a follow-up review focused on message uniqueness and replay guards.
Those controls do not replace an audit. They provide evidence for a different question: when prevention fails, how quickly can detection become containment?
| Public assurance | The question users still need answered |
|---|---|
| “Audited” | Which repository, commit, deployed address and component were reviewed? |
| “Findings fixed” | Were the fixes deployed, and what changed afterward? |
| “Monitored” | Which alerts page a human or stop the affected path automatically? |
| “Funds recovered” | Which assets are confirmed recovered, frozen, exposed or still under investigation? |
aelf’s August incident tests the argument from another direction. Its public record describes a runtime compromise and a controlled recovery, but it does not provide enough evidence to place the path inside or outside a specific pre-incident audit.
The company announced a network pause on Aug. 18. In its Aug. 26 progress update, aelf said an unauthorized smart contract could use transaction parameters to deliver encoded .NET assemblies and instructions into the node execution path.
The provisional account linked the incident to gaps in checks for runtime reflection and dynamic loading, together with weak isolation between contract execution and sensitive node or infrastructure resources. aelf identified 155 associated transactions and five unique payload assemblies with capabilities including host command execution, attempted outbound communication, node-key access and infrastructure reconnaissance.
Capability is not the same as confirmed execution. aelf said the payloads did not prove that every assembly ran, that every targeted credential was obtained or that sensitive data left its systems. The company said it was rotating signing keys and infrastructure credentials under a potential-exposure standard.
The public status remained provisional on Sept. 11: aelf’s blog index contained no incident-specific item published after Aug. 26. The Aug. 26 statement committed to another update and an eventual final review.
aelf’s standing security documentation says its blockchain and ELF token contracts underwent multiple audits with no security issues identified. But the available pages do not connect a specific pre-incident report to the runtime path described in August. Calling the incident either an audit miss or an outside-scope failure would therefore outrun the evidence.
That uncertainty is itself useful. A dated audit history can become detached from a system’s current code, dependencies and operational state. Users need an assurance record that is versioned and specific enough to reveal that drift.
Such a record should name the reviewed repository and commit, deployed addresses, excluded components, privileged roles and dependencies. It should also record upgrades since review, key custody and rotation, runtime isolation, alert and circuit-breaker behavior, and dated recovery status that separates confirmed loss from frozen or unresolved exposure.
This does not reduce the value of an audit. It makes the claim proportional to the work performed and connects that work to the system operating now.
An audit badge cannot answer whether the reviewed artifact, the deployed system and the machinery that responds to failure still share the same security boundary.
The post Audited DeFi protocols lost $885M to attacks that occurred completely outside their audit scopes appeared first on CryptoSlate.
Coinbase’s new partnership with payments platform Moov gives community banks and credit unions a route to offer stablecoin services through the financial relationship they already have with businesses. The local institution can remain the customer’s front door, while Coinbase supplies the disclosed custody and transaction infrastructure behind it.
Moov CEO Wade Arnold framed the demand bluntly: business customers asked to accept stablecoins currently go outside their primary financial institution. Moov and Coinbase want that service to appear inside the institution’s existing payments experience. The arrangement could preserve the bank’s customer connection. Control of the economics, data and operational risk remains unresolved until the companies disclose their terms.
Under the partnership announced Sept. 10, Moov will integrate Coinbase’s stablecoin payments infrastructure into its existing platform for financial institutions. Coinbase said its CDP Custodial Wallet accounts will provide fund custody and its Payments API will orchestrate stablecoin movement. Moov will connect those functions to the systems used by its bank and credit-union customers.
That division places three parties between a business and the stablecoin rail. The bank or credit union owns the primary customer interaction. Moov supplies the payments-platform connection. Coinbase provides the announced crypto custody and movement components. The customer may experience one bank-facing product even though the underlying service spans multiple providers.
Coinbase’s announcement said Moov has a customer base of more than 1,000 community banks and credit unions. The figure describes Moov’s potential distribution footprint. Live, contracted and pilot institutions remain unquantified, and the companies gave no implementation timetable.
| Disclosed | Undisclosed | Decision it affects |
|---|---|---|
| Coinbase supplies custodial accounts and stablecoin movement tooling | The ownership and settlement configuration for each institution | Where balances sit and who directs key operations |
| Moov embeds the tools in its financial-institution payments platform | The number of live, committed or pilot banks | Whether distribution reach becomes adoption |
| The bank remains the customer-facing institution | Fees, revenue sharing, data rights, compliance duties and liability | Whether the bank retains economics and practical control |

The disclosed architecture gives Coinbase a material role behind the interface. Its standard payments documentation describes a custodial-account stack in which crypto can enter an account, be held and reconciled there, and leave through fiat or crypto transfers. Separate custodial wallet documentation says Coinbase provides custody for assets in those accounts on behalf of the CDP entity.
Those documents cover Coinbase’s standard platform. The partnership record leaves each institution’s supported stablecoins, networks, custodial-balance ownership and fiat-settlement route unspecified. It also leaves fees, revenue sharing, transaction-data access, compliance allocation and liability out of public view.
The result is a split form of control. Community institutions can keep the account relationship and present the service to customers. Coinbase and Moov remain essential to the disclosed technology chain. The bank’s economic and operational leverage will turn on its authority over pricing, settlement destinations, customer data and risk decisions. Coinbase holds a material infrastructure role within a payment chain that also depends on Moov and participating institutions.
A bank-facing interface leaves the payment stablecoin’s legal status unchanged. Customer protection and bank balance-sheet exposure follow the legal claim represented by the balance.
In an April 2026 proposed rule, the Federal Deposit Insurance Corporation said deposits held at banks as reserves for a payment stablecoin would be insured as corporate deposits of the stablecoin issuer, subject to applicable limits. Stablecoin holders would receive no pass-through deposit insurance under the proposal.
The same proposal draws a boundary around tokenized deposits. An instrument that meets the statutory definition of a bank deposit remains a deposit regardless of the technology or recordkeeping used. A payment stablecoin and a tokenized deposit can therefore give customers a digital-dollar experience while representing different legal claims.
For a community institution, the distinction reaches beyond consumer disclosure. A qualifying tokenized deposit remains the issuing bank’s liability. Access to a third-party stablecoin can keep the payment experience inside a bank channel while the customer’s converted funds may cease to be a deposit at that bank.
Deposit effects remain conditional rather than following an automatic dollar-for-dollar path. A Federal Reserve analysis published in December 2025 said stablecoins can reduce, recycle or restructure deposits. The outcome depends on who buys them, what assets are converted and where stablecoin issuers place their reserves.
Domestic customers converting transaction-account balances can reduce deposits, especially when issuers hold reserves outside banks. If issuers keep reserves in bank deposits, more funding can stay in the system, though it may move from dispersed retail accounts toward concentrated, uninsured wholesale balances. The effect on any one community bank also depends on whether reserve money returns to that institution or is concentrated with larger custodial and settlement banks.
The Fed identified partnerships, custody services, settlement accounts and white-label infrastructure as possible ways banks can stay connected to digital payment flows. It also described a deeper structural tension: stablecoins may separate the payment relationship from the deposit-funded lending model that banks have historically used to serve households and businesses.
The Moov arrangement puts both possibilities in one product design. A bank may keep the customer conversation and gain a service that would otherwise require its own crypto stack. Coinbase may gain transaction and custody activity while customers access stablecoins through their primary institution. The destination of deposits and revenue remains unsettled.
The first bank deployments will provide the evidence missing from the announcement. Adoption counts will show whether Moov’s network converts into actual demand. Supported assets, account ownership and settlement paths will show whether stablecoin activity returns value to the same institution or routes it elsewhere.
Commercial disclosures will be equally important. Pricing and revenue sharing determine whether the bank earns from the new service or mainly supplies distribution. Data access and compliance responsibilities determine who can deepen the customer relationship and who bears the burden when monitoring or processing fails. Liability terms determine how operational control translates into financial risk.
Coinbase has offered community banks a bridge into stablecoin payments, with its custody and payment infrastructure underneath. That structure may stop the bank from disappearing from the customer’s view. The next test is how much of the payment relationship, balance-sheet value and decision-making power stays with the bank when the customer gains stablecoin access through it.
The post Coinbase gives community banks a stablecoin bridge while supplying infrastructure underneath appeared first on CryptoSlate.
Bitcoin payment processor BTCPay Server has warned that bots are probing exposed Lightning nodes for a potential route to administrative control.
The activity follows a separate critical BTCPay vulnerability that attackers exploited a month ago to obtain credentials protecting LND nodes and drain merchant wallets.
BTCPay subsequently disabled external access to LND, a widely used implementation of Bitcoin’s Lightning Network, in its standard Docker deployment. The project now says automated systems are targeting servers where operators manually restored that access, repeatedly calling an LND password-change endpoint.
The latest mechanism differs from the vulnerability exploited in August but could lead to a similar outcome: an attacker obtaining credentials that can control an LND node.
BTCPay said the opening appears during a short interval after LND restarts, while its wallet remains locked. During that period, the targeted password-change method does not require a macaroon, the credential LND normally uses to authorize administrative actions.
Older BTCPay LND wallets compounded the risk by using a shared default password. An attacker who could reach the interface before BTCPay’s internal unlocker could potentially submit that password first, replace it, and request an administrator macaroon that gives control over the node.
BTCPay has not reported a successful takeover through the newly observed activity or linked the bots to the attackers behind the August thefts.
The renewed probing extends a difficult security stretch for BTCPay, which acknowledged on Aug. 7 that attackers had exploited a vulnerability affecting all versions before 2.4.2. That flaw allowed unauthenticated attackers to obtain LND macaroon files and use them to move funds. BTCPay’s standard on-chain wallets were unaffected.
Days later, the project and its supporters offered a bounty equal to 10% of recovered bitcoin, capped at 3 BTC, then worth about $190,000. BTCPay also enlisted exchanges, blockchain analytics firms, and law enforcement in efforts to trace the stolen funds.
Version 2.4.4, released Sept. 7, now addresses the conditions behind the latest attack path. New LND wallets receive unique random passwords, while older installations using the shared credential are migrated and have their passwords rotated.

BTCPay’s standard reverse proxy also blocks unauthenticated wallet setup and unlock methods, closing the restart-time opening through its managed public network path.
Those controls cannot secure infrastructure operators configure independently. Administrators who created their own reverse proxy or otherwise exposed LND publicly can still bypass BTCPay’s protections.
BTCPay has urged administrators to install version 2.4.4 and remove manually exposed LND routes. A route-control change merged Sept. 11 provides a supported option for remote access while keeping LND and Core Lightning interfaces disabled by default.
That leaves custom deployments as the immediate concern. Operators using them must audit their proxy rules and migrate remote connections behind BTCPay’s managed controls while automated systems continue searching for reachable nodes.
The post Malicious bots are actively probing exposed Bitcoin payment servers to steal master administrative keys appeared first on CryptoSlate.
If you want to sell Ethereum in Germany, the purchase date decides first and the price only after that. Where the purchase goes back more than a year, the gain stays tax free under section 23 of the Income Tax Act. Where it does not, the gain counts towards taxable income and is charged at your personal tax rate. That is precisely why the question raised by the price jump of September 11, 2026, is a calendar question rather than a chart question: which of your units are old enough, and which of those are actually showing a gain? This article works through both, drawing on the text of the law, the guidance issued by the tax authorities and our own analysis of two years of daily Ethereum closing prices.
On September 11, 2026, Ether rose to an intraday high of 2,664.81 US dollars on the Kraken exchange. That was the highest level since January 31, 2026, when the price last reached 2,710.35 dollars. Measured by the daily closing prices of the same trading pairs, not a single day in between closed higher. The figures come from Kraken's public OHLC interface, retrieved on September 14, 2026, at 06:40 UTC; they describe trading on this one venue and may differ by a few dollars on other exchanges.
Half of that move has since been given back. At the same retrieval time, Ether was quoted at around 2,519 US dollars and 2,179 euros. Anyone who reads the headline about the eight-month high and concludes that their holding now sits at that level is working with a price that existed for only a few hours. For tax purposes the high is irrelevant in any case. What counts is the price at the moment you sell.
The trigger came from inflows into the US spot ETFs on Ether. The data service SoSoValue reported net inflows of 216.41 million dollars for September 11, of which 148.82 million went into BlackRock's ETHA fund; the Bitcoin ETFs recorded their fourth consecutive day of outflows on the same date, at a net 13.29 million dollars. These figures are attributable to the data service and were reported on September 12, 2026, among others by Bitcoin.com News in German. A reallocation of institutional money indicates demand. It is no promise of a further price rise. How the market read the level before this move is set out in our analysis of the test of the 200-day moving average at 2,100 dollars from August 19, 2026.
Holding period means the span between the acquisition and the disposal of an asset. For crypto assets held as private assets it is one year. The wording of section 23 (1) sentence 1 no. 2 of the German Income Tax Act refers to disposal transactions involving other assets where the period between acquisition and disposal is no more than one year. Only these transactions are taxable. Anything held for longer falls outside the provision, regardless of the size of the gain.
The usual calculation of deadlines under the German Civil Code applies: the day of acquisition itself does not count, and the one-year period ends at the close of the day corresponding to the day of acquisition. Someone who bought on September 13, 2025, was able to sell tax free on September 14, 2026. Someone who bought on September 14, 2025, has to wait until September 15, 2026. A single day decides the full tax exposure here, as an all-or-nothing threshold with no pro-rata gradation whatsoever.
It is not only a sale for euros that triggers the test. Swapping Ether into another coin or into a stablecoin is a disposal as well, as is paying for goods or services with Ether. The circular issued by the German Federal Ministry of Finance on March 6, 2025, treats the price agreed in euros as the disposal proceeds when tokens are exchanged for goods and services, falling back on the market price where that is unavailable. Anyone parking a holding in a stablecoin in order to swap back later has therefore already triggered the taxable event and starts a fresh one-year period for the new holding.
For taxable sales within the one-year period there is an exemption limit, meaning a threshold above which the entire amount becomes taxable. Under section 23 (3) sentence 5 of the Income Tax Act, gains stay tax free where the total gain from private disposal transactions in the calendar year came to less than 1,000 euros. The word less is to be taken literally: at 999 euros of gain you pay nothing, at exactly 1,000 euros the full amount becomes taxable, not merely the euro above the line.
Two subtleties are regularly overlooked. First, the limit applies to all private disposal transactions of the year taken together, so it also covers the sale of gold or the gain on a different coin. Second, it is an annual figure: anyone realizing 900 euros of gain in December and another 900 in January stays below it twice over. Put both into the same December and you are above it. A tax report of the kind the providers in our comparison of crypto tax tools and portfolio trackers produce shows this annual total before you sell, and that is exactly what matters when planning.

Anyone who has bought over a span of months does not own a single uniform position but many tranches with different purchase dates and purchase prices. Which of them counts as disposed of when you sell is governed by the order of use. The Ministry of Finance circular of March 6, 2025, places the principle of individual allocation first in paragraph 61: where the individual unit can be specifically identified, that unit is decisive. Where this is not possible, the crypto assets of a trading designation acquired first count as disposed of for the purposes of the holding period, and the average method is to be applied for the valuation. For reasons of simplification, the valuation may also assume that the units acquired first were disposed of first. That is the FIFO procedure, short for first in, first out.
What matters in practice is a sentence in the same paragraph: A wallet-based approach applies. Every wallet and every exchange account is therefore considered on its own. The method once chosen must be retained within a wallet until all units of that trading designation there have been disposed of in full; only afterwards, and following a new acquisition, may it be changed. For coins with a different trading designation in the same wallet, a separate election exists in each case.
The wallet-based view is a lever that many people do not even know about. If the old, tax-free Ether sit on a hardware wallet and the young, taxable ones on the exchange account, a sale on the exchange reaches only the holding held there. The period running on the older units remains untouched by it. Conversely, a problem arises when you consolidate everything onto a single address: the tranches then mix, and the order determines what gets sold. Anyone shifting holdings around should document these movements; paragraph 103 of the circular expressly requires documentation of reallocations within wallets for the wallet-based application of the average or FIFO method.
The decision between selling and waiting hinges on a question that is rarely asked: is the tax-free tranche showing a gain at all? For this article we analyzed the daily closing prices of the Ether against euro pair from Kraken, retrieved on September 14, 2026, at 06:40 UTC. The interface window reaches back 721 trading days, that is to September 24, 2024. Each daily close was compared with the current price of around 2,179 euros. The method is deliberately rough, assumes a purchase at the respective daily close, and leaves fees out of account.
The result is unambiguous. Of the 355 purchase days in the window from September 24, 2024, to September 13, 2025, meaning those days whose one-year period has now expired, only 89 sit below today's price. That is 25 percent. Three out of four tax-free purchase days are therefore currently under water. In the following window from September 14, 2025, to September 13, 2026, whose purchases are still taxable, 225 of 365 days lie below today's price, or 62 percent.
The price history itself supplies the reason. In September 2025 an Ether cost between 3,324 and 4,014 euros, with a median of 3,686 euros. Anyone who bought back then is down around 41 percent today. The low point of the window, by contrast, fell in the summer of 2026, and those cheap purchases are not yet twelve months old.
An uncomfortable constellation follows from these two data series, and it affects many portfolios right now. The units you could sell tax free are predominantly the ones you bought expensively. The units showing a gain are predominantly young and therefore taxable. So anyone who hears that they can sell tax free after a year and reaches for the oldest tranche on that basis realizes a loss in many cases, while simultaneously giving away the tax exemption they spent twelve months earning.
A loss from a tax-free sale is worthless for tax purposes: what lies outside the one-year period is simply not taxable, neither in gain nor in loss. A loss within the period, by contrast, can be offset, though only within narrow limits. Section 23 (3) sentence 7 of the Income Tax Act permits the offset only up to the amount of the gain from private disposal transactions in the same calendar year; a deduction from other income is excluded. Under sentence 8, the carry-back to the previous year and the carry-forward to subsequent years remain available, in each case again only against private disposal transactions.
What makes sense, then, is a sequence that starts with the calendar and looks at the price only at the end. First: which tranches are older than a year, and which wallet are they on? Second: what is the cost base of those tranches, are they in profit or at a loss? Third: how much gain from private disposal transactions have you already realized in this calendar year, and where do you stand relative to the 1,000 euro exemption limit? Only after that does the question of the price level become answerable at all. Our newsroom made the same calculation for XRP on August 24, 2026, back then after a weekly gain of 53 percent; the structure of the decision is identical, only the figures differ.
The gain from a taxable sale is not charged at the 25 percent flat-rate withholding tax that would apply to interest or dividends. It counts as other income under section 22 no. 2 in conjunction with section 23 of the Income Tax Act, forms part of taxable income, and is charged at your personal tax rate, plus the solidarity surcharge and, where applicable, church tax. Anyone already in the top tax bracket therefore loses considerably more than a quarter of the gain, while anyone on a low income loses correspondingly less.
The gain itself is defined by section 23 (3) sentence 1 of the Income Tax Act as the difference between the disposal price on one side and the acquisition costs plus income-related expenses on the other. Transaction fees on purchase and on sale therefore reduce the taxable gain, provided you can evidence them. On a sale through an exchange the fee appears in the statement; on a sale out of your own wallet the network fee belongs in the calculation. Which venues charge which fees depends heavily on volume and changes continuously.

This worry has haunted forums for years, and it has a real background. Section 23 (1) sentence 1 no. 2 sentence 4 of the Income Tax Act extends the period to ten years where income is generated in at least one calendar year from the use of an asset. Applied to crypto that would mean anyone who stakes or lends their Ether and collects rewards for it would have to wait ten years.
The tax authorities have cleared this up. The Ministry of Finance circular of March 6, 2025, states verbatim in paragraph 63: For currency or payment tokens, the extension of the disposal period under section 23 (1) sentence 1 no. 2 sentence 4 of the Income Tax Act does not apply. For Ether as a currency and payment token, the one-year period therefore stands, even where the units generated income in the meantime.
The rewards themselves are to be considered separately. This income counts as income in its own right, and the units received are treated as acquired. A separate one-year period begins for them from the day of receipt, valued at the market price at that moment. Anyone receiving staking rewards weekly therefore accumulates new tranches with their own periods every week. Which providers withhold how much of that reward is something our newsroom broke down for fourteen providers on September 12, 2026.
The future of the holding period is currently the subject of political argument. Reports describe a draft from the Federal Ministry of Finance that provides for a cut-off date of December 31, 2026: for crypto assets acquired after that date the one-year period would fall away, while holdings acquired before it would remain under the law as it stands. None of this has been enacted. As long as no statute appears in the Federal Law Gazette, section 23 of the Income Tax Act applies in its present form, and it is under that form that you settle your sale this year.
For your decision today this means two things. First, a sale brought forward solely because of a possible change in the law is a bet on a draft. Second, such grandfathering would be an argument for leaving existing tranches intact, precisely because a newly purchased replacement holding could fall under the new rules. How the debate has developed since the summer was traced by our newsroom on September 8, 2026, in its article on grandfathering and the cut-off date.
Once the decision for a partial sale has been made, three variables remain under your control. The first is the timing within the calendar year. Because the exemption limit applies afresh for each calendar year, splitting a sale across the turn of the year can push the taxable gain into two years and keep it below the limit twice. The second is the wallet you sell from, because the order of use operates on a wallet basis. The third is the offset against losses from other private disposal transactions in the same year, which section 23 (3) sentence 7 of the Income Tax Act expressly permits.
Two things, by contrast, are not levers. Switching exchanges changes nothing about the period, because what counts is the acquisition and not the place of storage. And a transfer to another address of your own is no disposal, so it neither resets the period nor ends it; it can, however, make the allocation of tranches harder if it goes undocumented.
The burden of proof lies with you. In paragraphs 102 and 103 the Ministry of Finance circular lists what the tax offices may request. That includes the time of acquisition, the quantity acquired and the type of acquisition, the acquisition and incidental costs in euros, the time of disposal with quantity and trading platform, the disposal proceeds and disposal costs in euros, as well as the market price used together with its source where trading did not take place in euros. Expressly required on top of that is documentation of the chosen order of use per wallet and documentation of reallocations between wallets.
In practice this means the tax report is no retrospective paperwork exercise. It is the precondition for being able to evidence the tax exemption of an old tranche at all. Anyone who no longer holds purchase records from 2021 because the exchange has since shut down is left without proof in case of doubt. The statements of the bank account the money left at the time often help as supporting evidence.
Tax is a cost factor, not a prohibition. There are cases in which a taxable sale is the more sensible decision. Anyone servicing a loan at high interest earns a certain return by repaying it, while the price remains open. Anyone holding a single position so large that a fall by half would touch their life planning buys peace of mind with the tax. And anyone who needs money for a fixed expense in a few months should not leave it sitting in an asset that has swung between 1,405 and 2,881 euros this year.
Conversely, the blanket rule of taking profits after a rise as a matter of course is expensive in Germany while the one-year period is still running. Between a taxable sale today and a tax-free sale in a few months lies almost half the gain at a personal tax rate of 42 percent. The price has to deliver that difference first.
This article describes the legal position on the basis of the statute and the circular from the tax authorities; it is no substitute for tax advice in an individual case. Anyone who has to bring together several wallets, staking income and purchases from several years is better off with a tax adviser than with an estimate.
The sources in full: the text of section 23 of the Income Tax Act and the Ministry of Finance circular of March 6, 2025, on specific questions of the income tax treatment of certain crypto assets.
(As of September 14, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
If you have ever swapped a token on a decentralized exchange, deposited one in a lending pool or sent one through a bridge, an approval you forgot about long ago is very probably still live today. It allows a contract that is not yours to move your tokens out. It does not end with the swap, it does not expire after a year, and it does not lapse when the project behind it is abandoned. It ends only when you revoke it yourself.
The objection to clearing them up was the same for years: every revocation is a separate transaction, every transaction costs gas, and anyone sitting on twenty old approvals pays twenty times over. That objection no longer holds in this form. We ran the numbers on September 14, 2026, and revoking a single approval on Ethereum mainnet currently costs around half a cent.
approve Keeps Running After the SwapA token approval, also called an allowance, is permission granted to an external contract address to take a certain quantity of a token out of your account. This is no flaw in the design. It is the mechanism without which the ERC-20 standard would not work at all.
The reason lies in how the standard is built. An ERC-20 token is its own contract with its own ledger. When you want to hand tokens to another contract, that contract cannot simply take them, it has to collect them itself. That requires two steps: first the approval through the approve function, then the actual operation, in which the contract pulls the tokens via transferFrom. You can read it up in the EIP-20 standard description, which has set out this split since 2015.
What matters is what does not happen in the second step. The standard makes no provision for the approval to expire once it has been used. It is reduced by the amount that was pulled, and if the approved amount was high enough, a remainder stays in place. That remainder is exactly the problem at issue here.
Many interfaces do not ask for an amount at all. They set the approval straight to the highest value the standard permits. That value is known as the uint256 maximum and is a 78-digit number. In practice it means unlimited, forever, covering the full size of your current and any future balance of that token.
For the operator of the interface this is convenient, because you only have to approve once and can trade afterwards without any further confirmation. For you it shifts the ceiling on the damage. An approval capped at 500 USDC can cost you 500 USDC in the worst case. An unlimited approval costs you everything held in that token at that address, at the moment the approved contract is compromised.
That moment is no theoretical one. In recent weeks we have reported repeatedly on cases in which users lost balances without ever giving away a seed phrase: through manipulated signature requests from wallet drainers as well as through tokens with a built-in freeze and clawback function. An old approval works in the same direction, only more quietly: once it is in place, it never asks you for another click.
It helps to be clear about what an approval is not. It gives nobody your private key, it grants no access to your Ether balance, and it only ever covers the one token you granted it for. Anyone holding ten tokens who has granted an unlimited approval for each of them has ten separate points of entry, not one.

So that the scale does not remain a claim, we measured it. This analysis was carried out by cryptoticker.io itself on September 14, 2026.
The method in one sentence: through a public Ethereum node we read out every approval event for the five most used ERC-20 tokens across a contiguous window of 300 blocks and sorted them by the size of the approved amount. The window covers blocks 25,972,833 to 25,973,132, that is the period from 02:54 to 03:55 UTC on September 14, 2026, a good hour of network operation. The contracts examined were those of USDT, USDC, DAI, WETH and LINK.
In that hour there were 5,910 approval events, spread across 3,301 transactions. Of these, 820 stood at the uint256 maximum, meaning unlimited. That is 13.9 percent. A further eleven approvals sat below the maximum but above 10 to the power of 30 units, which for each of these tokens amounts to an unlimited approval. Together that gives 14.1 percent.
The distribution across the individual tokens diverged sharply. For WETH, 477 of 2,140 approvals were unlimited, a share of 22.3 percent. For USDC it was 203 of 2,475, or 8.2 percent. USDT came in at 130 of 1,181, or 11.0 percent. The smaller samples for DAI (7 of 83) and LINK (3 of 31) contribute little to the finding given their low case numbers and appear here only for the sake of completeness.
A second figure from the same measurement deserves attention because it points the other way: 1,241 of the 5,910 events were approvals set to zero, in other words revocations. One in five approval transactions in this window was therefore a clean-up. Awareness of the issue exists, and a measurable share of users acts on it.
What we could not establish with this method belongs here just as much. We did not assess the receiving addresses for whether a reputable protocol or a fraudulent contract sits behind them, since an unlimited approval granted to an established exchange interface is a different matter from one granted to an unknown address. We also measured only approvals newly granted within this window, leaving out the existing stock of open approvals that has built up over years and cannot be read out with this type of query. Finally, the figures exclude all approvals on layer-2 networks such as Arbitrum, Base or Optimism, as well as signature-based approvals following the Permit2 pattern, which generate no approval event at all. The true number of open approvals therefore lies above what is shown here.
The second half of the measurement concerns the price. Here too the figures are queried values rather than an estimate. For six reference dates we read out ten blocks each, spaced 50 blocks apart, and took the median of the base fee.
On September 14, 2026, this median stands at 0.0492 Gwei, with a range of 0.0389 to 0.0540 Gwei across the ten samples. Seven days ago it stood at 0.0493 Gwei, 30 days ago at 0.0616 Gwei. Going back three months produces a different picture: on June 15, 2026, the median stood at 0.2097 Gwei, on March 17 at 0.1155 Gwei, and on September 12, 2025, at 0.1539 Gwei. Today's level is therefore barely a quarter of the value from three months ago and around a third of the value from a year ago.
That leaves the question of how much gas a revocation actually consumes. We measured this as well instead of taking it from a rule of thumb: out of the transactions in the measurement window we filtered 23 that produced exactly one event, meaning pure approval operations with nothing else attached. Their gas consumption ranged from 24,080 to 55,906 units, with a median of 48,837.
From this the calculation follows. 48,837 gas units at 0.0492 Gwei come to 0.0000024 Ether. At a price of 2,170.21 euros per Ether, retrieved on September 14, 2026, from Kraken, that equals 0.52 cents. Across the measured gas range the price moves between 0.26 and 0.60 cents. Clearing up ten approvals therefore costs around five cents. For comparison: on June 15 the same revocation would have cost 2.22 cents, which supports the point rather than undermining it. Even back then the operation was not expensive.
This is where the actual finding of the analysis lies. Cost does not work as a justification for leaving old approvals in place, and it has not worked as one for some time. Even so, 13.9 percent of all newly granted approvals still sit at unlimited. The transaction fee is not what stands in the way. What is missing is the habit of clearing up once the swap is done.
Getting started is unspectacular. You need your public address, no seed phrase and no installation.
The quickest route is an approval checker. The best known one is Revoke.cash, which was reachable when we called it up on September 14, 2026, and which breaks down the open approvals of an address by token and contract address. Etherscan also runs a tool of its own under the name Token Approval Checker that produces the same list; the page blocks automated requests, while in a normal browser it is readily accessible.
You can start by simply typing in the address and looking at the list without connecting a wallet. For a plain look-up that is entirely sufficient, and it is the safer route: an interface you are using for the first time does not need immediate access to your account. You only have to connect once you actually want to revoke, because that requires a transaction and therefore a signature.
Three characteristics tell you most. If the amount column points to an unlimited quantity, the approval is open regardless of your current balance. If the grant date goes back months or years and you cannot remember the protocol, there is no reason to let it keep running. And if the receiving address carries no known contract name, only a bare hex address, it deserves particular attention.
One qualification belongs here: the fact that an approval goes to a well known, heavily used protocol does not make it harmless. The large losses of recent years arose predominantly at established contracts that only revealed a gap later on.
A revocation is technically the same thing as an approval, only with the amount set to zero. You call the same approve function and set the permitted quantity to nothing. After that the contract can pull nothing more.
In practice it runs like this: you open the approval checker, connect your wallet, select the approval you want gone from the list, and confirm the transaction. Pay attention to what your wallet shows you before you sign. It has to be an approve on the token contract you are currently clearing up, and the amount has to be zero. If your wallet shows you a transfer of your balance instead, or a signature with no recognizable function, abort.
Every approval needs its own transaction, and that holds even when the interface offers several at once. So reckon with the measured half a cent per operation, not with a flat price for the whole list. Anyone with a great many old approvals can work by the size of the balance and start with the tokens that actually hold something. An unlimited approval on a token of which you hold zero units is untidy, yet at that moment it has no effect. It becomes dangerous only once something arrives at the address again.

The more effective step comes before the revocation, namely at the moment of granting. Most wallets let you overwrite the proposed unlimited amount when confirming and enter exactly the quantity this particular operation is about.
The price for that is convenience. If you want to trade again next week, you have to approve again, and that costs another transaction. At the gas price measured today, this price is five tenths of a cent per operation. Anyone trading regularly therefore pays a few euros a year for the assurance that no open approval is left behind.
Against that stands the benefit. A limited approval caps the possible damage at the amount entered, and it effectively expires by itself because it is used up during the operation. Precisely this property makes the difference between an annoying and an existential loss when a contract is compromised years later.
A newer pattern works with a signature in place of a transaction. Under the name Permit or Permit2 you grant permission by signing a message that the contract later submits itself. This saves you the gas cost of the approval and therefore also generates no approval event on the blockchain, which is why these permissions are missing from our measurement.
For you that means two things. A signature request can have the same effect as an approval, even though it looks more harmless and costs nothing. And a permission granted by signature will show up in some approval checkers only if the tool explicitly supports Permit2. Check that before you take an empty list for a clean list.
Tidy approvals limit the damage. They are no shield. They help you against exactly one attack pattern: a contract you once granted access to that later uses this access against you.
They do not help you if your seed phrase goes missing, because whoever holds the key needs no approval. They do not help you against a freshly signed transaction on a spoofed page, because in that moment you are granting a new permission rather than using an old one. And they do not help you with tokens whose contract brings its own blocking or clawback function, as many regulated and tokenized assets have built in.
Revoking therefore belongs alongside the other habits rather than in their place: separate addresses for trading and custody, a hardware wallet for the holdings that stay put, and the habit of reading every signature request before you confirm it.
There is a way to defuse the topic structurally, and it manages without any tool at all. An approval can only ever reach what sits at the address it applies to. Anyone who separates their holdings limits the damage regardless of how clean their approval list is.
In practice that means one address on which you trade and use contracts, and a second one on which the holdings you do not touch are kept. The second address connects to no decentralized interface and therefore never grants an approval. If you also manage it through a separate wallet instead of the same software installation, you separate the risk that a compromised interface reaches both accounts at once.
This split has a side effect you should be aware of: moving holdings between your own addresses counts as a transfer for tax purposes rather than a sale. You should still document it cleanly, because your exchange has been reporting these movements to the tax authorities since the beginning of 2026, and an unexplained outgoing transfer raises questions later on. What exactly gets transmitted is something we have broken down in our overview of the crypto reporting obligation.
(As of September 14, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
This week holds only one date that really bites, and it is now eleven days away. Anyone who held Beldex or Humanity at the crypto exchange Kraken has already been credited with the respective replacement token by airdrop. The only thing left to do with it is to withdraw it, and that option closes on September 25, 2026 at 14:00 UTC. After that the exchange liquidates whatever is left. This is the last full calendar week before that date, and there are two separate notices for two separate tokens: anyone who held both has two things to do.
As in the previous week, a warning belongs at the top, because the pattern has repeated itself. Last week it was Holoworld AI, whose claim from September 2025 was circulating through search results as a fresh airdrop. This week it is Meteora (MET). The project confirmed its TGE and airdrop in an announcement dated September 10, from September 10, 2025. The TGE took place on October 23, 2025. Two weeks, two prominent “live” airdrops that actually date from the previous year. That is no coincidence. It is the basic pattern of this field: airdrop announcements display the day and the month prominently and the year almost never. Check it first.
This overview lists the airdrops that either have a claim window open this week or have a confirmed date within the next 14 days. Every figure comes from the source linked alongside it, retrieved again on September 14, 2026. Where a project has published no end date, that is stated explicitly. There are no estimated deadlines here. For the state of play a week ago, see our piece on the airdrops of week 37.
| Project | Status | Date / deadline |
|---|---|---|
| Beldex & Humanity (at Kraken) | Airdrop credited, withdrawal required | until September 25, 2026, 14:00 UTC |
| Plume (Season 2) | Claim open | no end date published; registration closed on May 27, 2026 |
| Grass (Stage 2) | Claim open | until January 22, 2027 |
| GRVT | Tranches continue | 30 days per tranche; date of the second unlock not published |
| dappOS (DOS) | Phase 2 claim open | since August 11, 2026, end not published |
This entry is the most unusual on the list, because nobody here had to claim anything. Both projects were attacked in June 2026, both responded by rolling out a new token contract and distributing the replacement one for one to holders as of the snapshot. Kraken handled the distribution for its customers and credited it automatically, which is why two additional lines have been sitting in those accounts ever since. An airdrop you never had to claim can still expire.
The key data differ by project, and that is the reason for the two separate notices. For Beldex, the snapshot was taken on June 10, 2026 at 23:36 UTC, and the new token was credited on July 10, 2026 at 14:00 UTC. For Humanity, the snapshot came earlier, on June 8, 2026 at 17:25 UTC, set by the Humanity team itself, and the new $HUMANITY was credited as early as July 1, 2026 at 14:00 UTC. Anyone who bought the token in question only after the snapshot is not entitled to it according to the exchange, and in neither case is there an application portal through which that could be sorted out after the fact.
The ending, by contrast, is identical for both. Trading and deposits have already been switched off for all affected tickers, withdrawal remains the only function, and it closes on September 25, 2026 at 14:00 UTC. From September 28 to October 2, 2026, the exchange will liquidate any remaining balances itself. In the same notice it points out explicitly that the proceeds may fall well below recently seen prices and, in individual cases, may be minimal or zero. When the notices were retrieved again on September 14, 2026, neither carried any reference to an extension.
What has to be done this week therefore comes down to a single action with a date attached: withdraw before the window closes, and do it separately for each of the two tokens. We have written up the full procedure, including the contract addresses that distinguish the old token from the new one, under “Kraken withdrawal deadline on September 25”. The separate route for Humanity and the unlocking of the token are covered under “Humanity unlock: the H deadline at Kraken”.
Sources: Kraken Support, “Notice of Beldex ($BDX) delisting and $BELDEX airdrop” and Kraken Support, “Important update regarding Humanity (H)” (both retrieved again on September 14, 2026; snapshots, credits, withdrawal deadline and liquidation window are set out there verbatim)
Plume is a layer 1 chain for tokenised real-world assets. Season 2 of the points programme ended on March 31, 2026, and registration for the distribution ran from April 29 to May 27, 2026. Anyone who missed that step is excluded according to the project, and there is no way to fix it retroactively. Eligibility required wallets with at least 10,000 Plume Points, in some cases plus verification through Human Passport.
The claim has been running through the official portal since the end of May 2026, and the gap of recent weeks remains unchanged: Plume has at no point named an end date. The announcement text gives the registration deadline and says of the claim itself only that it is planned for “later in May”, with the exact date to follow through the official channels. To this day it has not followed. When the site was retrieved on September 14, 2026, the project blog carried three newer posts than a week earlier, dated September 8, 9 and 10, 2026, and all three concerned partnerships and product launches rather than the airdrop.
The figure circulating in secondary reports, a window of roughly three months that would arithmetically have run out at the end of August, still does not come from Plume. We carry it only because it is circulating, and explicitly not as a deadline. In practice that changes nothing about the advice. If anything it sharpens it: a claim with no published end date can be closed at any time without prior announcement. Anyone eligible and registered should claim rather than wait.
Source: Plume, “Plume Points Season 2 Airdrop Registration Is Now Open” (retrieved again on September 14, 2026; the announcement still names no end date for the claim, and the project blog carries no post on the subject)
The Solana project Grass has been paying out its Stage 2 rewards since July 22, 2026. Epochs 1 to 19 are covered, meaning the period from October 14, 2024 to June 8, 2026. The claim runs through the project's official dashboard.
Grass is one of the few projects with a cleanly published deadline. The claim is open until January 22, 2027, a full six months. Whatever has not been claimed by then stays with Grass. That is the literal wording in the project documentation, and it was still there unchanged when the page was retrieved again on September 14, 2026. This is the most comfortable entry on the list and, experience suggests, still the one where most value is left on the table, because half a year feels like unlimited time. Four of the six months have now passed. Put the date in your calendar if you are eligible.
Source: Grass, “How Your Stage 2 Rewards Allocation Works” (retrieved again on September 14, 2026; the January 22, 2027 deadline and the forfeiture clause carry unchanged wording)
The derivatives exchange GRVT held its token generation event on July 30, 2026 and is distributing a total of 280 million GRVT. The mechanics are the strictest on this list. The distribution runs in tranches over twelve months, and every unlocked tranche carries a claim window of 30 days. Once it expires, the tranche is permanently lost according to the project.
Two points are decisive here and are regularly confused. First, registration: it closed on July 27, 2026 at 00:00 UTC, and anyone who missed it has forfeited their allocation, which no later claim can undo. Second, automation: only the first tranche that falls due is sent automatically, and even that only where registration happened before July 17, 2026. Anyone who signed up later has to claim every tranche themselves through the Reward Portal, according to the wording of the help text, and to do so within the 30 days.
GRVT publishes no unlock schedule, and when the help section was retrieved again on September 14, 2026 it carried no date for the second tranche. For allocation and vesting schedule the text refers exclusively to the Reward Portal of your own account. We deliberately do not calculate the date here. What counts is the expiry date the portal displays for your specific tranche. This is precisely where forfeited entitlements arise, so set yourself a reminder. The project recommends as much itself.
Source: GRVT Help Center, “How to Receive and Manage Your $GRVT Airdrop” (retrieved again on September 14, 2026)
The DOS token launched with its TGE on August 10, 2026, and phase 2 has been running since August 11, 2026, in which eligible wallets can claim transferable DOS. A phase 3 has been announced, but without a date, and no end date has been published for any of the phases so far. Nothing has changed there since last week. The claim portal on the project domain is the only official route.
What comes afterwards is the real decision. A freshly distributed token with a small market capitalisation swings wildly in its first weeks, and the selling pressure from an ongoing claim hits it on top of that. Anyone who wants to trade such a position at all needs access that covers the small pairs. Pure charting tools such as Dexscreener or TradingView only display prices; no trading happens there. One alternative is the mobile app FOMO Family, which lets you discover, swipe through and trade meme and low-cap tokens directly in the app, with fast deposits. Download the app through the link and secure yourself a 10 percent discount on trading fees. Sobriety belongs with that: trading meme and low-cap tokens is highly risky, volatility is extreme and a total loss is possible at any time. Where else DOS is traded can be seen in our comparison of crypto exchanges.
These candidates did not make the list. The reason differs in each case, and each reason is worth as much as an entry:
Alongside that, the standing rule of this format: projects listed as “live” on aggregator sites but naming neither a snapshot nor a claim window at the project source do not get in. “Airdrop confirmed, date open” is not a deadline.
Airdrops are the preferred hunting ground for wallet drainers, and the patterns repeat:
An airdrop is not by definition a tax-free gift. Whether the allocation has to be treated as other income under Section 22 No. 3 of the German Income Tax Act depends above all on whether you provided something in return, which is also how the still authoritative circular of the German Federal Ministry of Finance of March 6, 2025 draws the line. This week's Kraken case also shows that two events have to be kept apart: the inflow of the replacement token in July, and the later withdrawal or sale. A forced liquidation by the exchange is likewise an event you have to document, even if you did not trigger it.
So when you claim, record the time, the quantity, the market value, the price source, the transaction hash and the terms of participation straight away. The last of these tends to disappear first once a campaign page is taken down. That a token you have not sold can also trigger a tax liability is something we explain separately.
The Optimism case shows that a distribution once promised can also be reallocated, which you can read in our piece on the reallocation of the Optimism airdrop. For an overview of further campaigns, see our section on crypto airdrops.
Week 38 is a week with exactly one task and four observation posts. The task is called September 25: anyone who held Beldex or Humanity at Kraken has long had the replacement token in their account and eleven days to withdraw it, twice over where both tokens are affected. After that the exchange decides on liquidation, and it says itself that little or nothing may come of it.
The four remaining entries stand unchanged: Plume, GRVT and dappOS with open windows and no published end, and Grass as the only project with a clean closing date of January 22, 2027, of which four of the six months have now elapsed.
The methodological finding of the week is the same as last week's, and that is exactly what makes it matter: once again a prominently traded “live” airdrop turned out to be a year old. When a mistake repeats twice in a row, it is the rule rather than a slip. Check the year before you connect a wallet.
And the necessary sobering note: most allocations run into double or triple digits, the fee for claiming eats a noticeable share of that, and a substantial proportion of all allocated tokens is never claimed at all. The effort pays off above all where you are already eligible.
Disclosure: some of the providers named in this article work with us through partner programmes. This has no influence on our editorial assessment.
(As of September 14, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
On Wednesday, September 16, 2026, the US Federal Reserve publishes its interest rate decision, and futures markets mostly expect a hike. If you have a savings plan running on Bitcoin, the honest answer to the question of what you have to do now is: probably nothing. Two things are still worth checking, and beforehand rather than afterwards: exactly when your next instalment is executed, and how much headroom a running crypto loan still has.
This article explains what actually happens on September 16, which mechanism connects a US policy rate to your monthly Bitcoin purchase, and where the meeting day gets expensive for retail investors. It contains no price forecast, because nobody can seriously predict how the market will react to a decision that is already largely priced in.
The body that sets the US policy rate is called the Federal Open Market Committee, or FOMC: the monetary policy committee of the Federal Reserve, which meets eight times a year and sets the target range for the overnight rate between banks. The meeting runs over two days, September 15 and 16, 2026. The decision comes on the second day.
The Federal Reserve meeting calendar marks the date with an asterisk. That asterisk looks like a footnote and carries the most important information on the page: it flags the meetings at which the Fed publishes a Summary of Economic Projections. Those projections are the collected expectations of the central bankers on growth, unemployment, inflation and the future level of rates, and they reach several years ahead. After September, only two meetings remain in 2026, on October 27 and 28 and on December 8 and 9.
The decision is published at 18:00 UTC, which is 20:00 in central European summer time. The press conference starts half an hour later. For you that means: Wednesday evening between 20:00 and 21:00 CEST is the window in which prices on crypto exchanges get most turbulent. The Frankfurt stock market has long since closed by then; the crypto market keeps trading.
The current target range for the overnight rate is 3.50 to 3.75 percent. It has been in place since July 30, 2026, as recorded in the Fed's implementation note for the July meeting. A basis point is one hundredth of a percentage point, so 25 basis points are 0.25 percentage points. If the step goes through, the range would afterwards sit at 3.75 to 4.00 percent.
Why expectations flipped at all can be pinned to a single number. US consumer prices in August were 3.4 percent higher than a year earlier, with the core rate at 2.4 percent; the largest single driver was petrol, up 3.9 percent. After the release on September 11, the probability of a September hike priced into futures markets jumped. The figures different houses quote for the CME FedWatch reading sit in a range of roughly 86 to 90 percent, after around 70 to 72 percent the day before. I am deliberately not smoothing that range: the value moves with every trading day, and the spread itself is the more honest piece of information.
The numbers come from CNBC's report on August consumer prices, which carries the FedWatch readings. Important for context: a priced-in probability reflects what the market has in the price. The value is a bet by futures traders and carries no predictive power beyond that, and that is exactly why prices move less on the expected step than on the deviation from it.
The connection is less mysterious than many headlines make it sound. A higher policy rate means that parking money risk-free earns more. Anyone getting four percent on overnight deposits or short-dated government bonds demands a higher compensation for anything riskier. Bitcoin pays no interest and consists exclusively of price movement. As the risk-free return rises, so does the bar Bitcoin has to clear.
On top of that comes the funding channel. A large share of short-term trading volume in the crypto market runs on borrowed money. When money gets more expensive, leveraged positions shrink and the market gets thinner. That explains why price moves on central bank days are often more violent than the news itself warrants.
At the time of writing, Bitcoin trades at around 76,700 US dollars, or roughly 66,200 euros; retrieved on September 14, 2026 at 00:40 UTC via CoinGecko's public price interface. In the preceding 24 hours the change was under one percent. That figure is a snapshot and no basis for a decision meant to work over years.
The short answer is no, and the reason lies in the purpose of a savings plan. A savings plan buys a fixed amount at fixed intervals, regardless of the price. It is the decision to stop making individual decisions. Anyone who pauses it ahead of a scheduled event has abolished it at exactly the moment it was built for.
What does make sense is checking once whether the instalment still fits your circumstances. If rising rates make your mortgage or your overdraft more expensive, the instalment is the lever, not the execution date. Which providers allow which minimum instalments, intervals and fees is set out in our comparison of Bitcoin savings plan providers, and with small instalments the fee side quickly becomes the largest cost block.
Pausing means: you do not buy this month. Adjusting means: you keep buying, but with an amount you can sustain through a bad quarter as well. The first is a market forecast in disguise, the second is household budgeting. Only one of the two is something you can do reliably.
Dollar cost averaging describes a simple arithmetic phenomenon: anyone buying regularly for the same amount gets more units at low prices and fewer at high ones, so the average price ends up below the mean of the prices. No promise of returns comes with that, and no protection against losses either. The effect is a procedure that prevents timing errors.
On a central bank day the benefit shows particularly clearly, because the price move after the decision can go either way and the counter-move often follows within hours. A savings plan simply does not take part in that question. If you want to know how it stacks up against a lump sum purchase, we worked it through in our article on savings plans and lump sum purchases when buying more of August 24, 2026.
This is the part where a meeting day can do real damage. Anyone who has pledged crypto assets as collateral and taken out a loan against them is working with a loan-to-value ratio: the relation of the loan amount to the current value of the collateral. If the price of the collateral falls, that ratio rises. Once it crosses the provider's limit, an automatic sale follows. This forced sale is called liquidation, and it does not ask whether the move will be over again an hour later.
Two figures determine how well you sleep here. The first is the distance between your current ratio and the liquidation threshold. The second is the interest rate you pay on the loan, because variable rates in crypto loans track market rates and demand for the borrowed asset. Our overview "Crypto lending: interest rates and risks" of August 16, 2026 describes these mechanisms in detail.
Log in once before Wednesday evening and note down two numbers: the price at which your position would be liquidated, and the distance between that price and today's level in percent. If that distance is in single digits, it is a state you should change regardless of the Fed. Either by topping up collateral or by repaying part of the loan.

Because a 25 basis point hike is around nine tenths priced into the market, the actual information sits in the projections. Their best-known component is the dot plot: a scatter of points in which every member of the committee anonymously marks where they see the policy rate at year end. If that cloud shifts upwards, the committee is signalling further steps. If it stays where it is, the September step was a one-off response to the price data.
For a savings plan that is the only relevant question of the evening, and it is a question about months, not hours. A rate peak reached in December looks entirely different for long-term investors than a path pointing upwards well into 2027.
Around every meeting, price targets appear from institutions and individual analysts. Take them for what they are: expectations attributable to a name. Anyone quoting a price target should be able to name its source; without a name, all that remains is sentiment. And where expectations diverge, both sides belong side by side, the optimistic one and the cautious one.
The spread is the gap between the price at which you can buy and the price at which you could sell. It is the part of the cost almost nobody calculates, because it does not appear on the statement. In turbulent market phases it widens, and that is exactly what happens in the hour after a central bank decision.
If your savings plan executes on the 16th or 17th of the month anyway, that is no reason to change anything; over years it evens out. But if you were planning to change the execution date regardless, a date in the quieter middle of the month between two central bank meetings is the less conspicuous choice. While you are at it, check whether your provider executes at a fixed time or at some point during the day; in the latter case the timing is out of your hands.
Anyone holding Bitcoin through an exchange-traded product rather than directly gains a second layer: those securities only trade during exchange hours. If the decision lands at 20:00 CEST, while German trading is closed, you only see the move the next morning at the open, and then all at once.

Directly nothing, indirectly a great deal. Anyone holding Bitcoin as private assets in Germany can realise gains tax free once a year has passed; that one-year period is called the holding period and runs separately for every purchase. With a savings plan that means: you have as many holding periods as executed instalments.
The connection to the Fed arises the moment a price move tempts you to sell. Anyone selling after a violent evening move may realise gains from instalments that have not yet reached the one-year mark, and pays their personal income tax rate on them. The order in which the tax office assigns the units sold follows the first-in-first-out principle: the units bought first count as sold first. What that looks like in concrete terms with monthly instalments is set out in our article "Bitcoin savings plans and tax: holding period, FIFO and the exemption limit" of August 11, 2026.
The most expensive mistake is rarely bad timing. What gets expensive is the unintended: a decision to sell in the evening, taken in reaction to a headline, which only reveals its price in the following year's tax return. What helps against that is a rule you write down before Wednesday, not on Wednesday.
(As of September 14, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
An Ethereum address that belongs to you has been able to execute someone else's program code since the Pectra upgrade, without its address, its balance or its key changing at all. EIP-7702 is what makes this possible: one signature from you is enough, and from that moment on your address behaves like a contract. This is the basis for many convenient wallet features, and it is also the route by which attackers keep a drained account permanently under their control. This article shows you how to check in two minutes whether your own address carries such a delegation, and what to do if the contract sitting there is one you do not recognise.
The basis for this is our own measurement on the Ethereum chain, taken today. It shows how widespread these delegations have become and what they mostly point to. The answer is more uncomfortable than wallet marketing suggests, but also more nuanced than a bare percentage implies.
EIP-7702 is an extension to Ethereum that lets an ordinary key-controlled account run the program code of a contract without becoming a contract itself. The account keeps its private key, its address, its balance and its nonce. All it gains is a pointer to a contract whose code runs on the account's behalf on every call.
The technical term for this is delegation. The pointer is written into the account's code field, which until then was empty for a key-controlled account. From that moment on, anyone calling the account calls the stored contract, and that contract reaches the account's storage and balance.
The benefit is obvious. A wallet can bundle several steps instead of asking you to sign three times. A provider can cover the fee on your behalf. An app can set up a tightly bounded spending permission that expires after an hour. These are exactly the features wallet makers have been selling under the Smart Account label since 2025.
The price sits in the same sentence: the stored contract acts with your account's full authority. It can move funds, grant approvals and trigger further calls. A delegation is therefore not a setting but a power of attorney, and it stays in place until you replace it or revoke it.
A delegated account carries exactly 23 bytes in its code field: the fixed marker 0xef0100 followed by the 20 bytes of the target address. That marker is the only reliable evidence. Everything else an interface shows you is interpretation.
In practice you see it in two places. A block explorer suddenly lists your address as a contract, or displays a note about a delegated account, even though you have never deployed a contract. And the code lookup that every explorer offers returns, instead of an empty value, a short string beginning with ef0100.
The 20 bytes that follow are the address you have to check. They decide everything. If your wallet maker's contract address is sitting there, the delegation is probably intended. If something unfamiliar is sitting there, you have a problem that goes well beyond a misplaced click.
One point matters for context: an empty code field is the good news. If you find nothing there, you have no active delegation, regardless of whether one existed in the past.
The check takes a few minutes and needs neither a tool nor an installation.
ef0100 means the delegation is active.The same check works on every chain where EIP-7702 is live. An authorisation signed for chain ID zero is even valid on all chains at once. Anyone using several networks is better off checking more than once.

This analysis was carried out by cryptoticker.io itself on September 13, 2026. Method: we pulled 200 consecutive blocks in full from a public Ethereum node, blocks 25,971,139 to 25,971,338, and evaluated every transaction of type 0x04 in them together with its authorisation list. The window runs from 21:14:35 to 21:54:23 UTC and covers 39.8 minutes of chain time.
The numbers from that window:
What we could not measure is how many accounts currently carry a delegation in total, because that would require a full state dump of the chain rather than a time window. Nor can these data show how much money was moved through the contracts we found. And a 40-minute window is a snapshot: another day may show a different distribution.
In this measurement the names say more than the shares do. Publicly verified source code is available for two of the three most frequent targets, and both describe themselves as tools used by criminals.
The most frequent target, with 2,007 authorisations, or 49.7 percent of the window, carries the name Poisoner in its verified source code. The comment in the source names the purpose outright: the contract is used for address poisoning, that is, to trick inattentive users into sending funds to a wrong address that looks visually similar. As the party behind the publication, the source names the trading firm Wintermute, which says it rebuilt and disclosed the contract. The program code itself is short: it executes a list of arbitrary calls, but only if the transaction was triggered by exactly the address that created the contract.
The third most frequent target, with 170 authorisations, carries the name CrimeEnjoyor. Here too the explanation sits in the source code, and it is set in capital letters: anyone who finds this contract in an authorisation list has a compromised account; no further funds may be sent there, because they will be swept immediately. The code is shorter still than that of the first contract. It does precisely one thing: every incoming amount is forwarded straight away to a target address fixed at setup.
For comparison, the legitimate side of the same list: in eighth place sits a verified contract from a well-known wallet maker with 110 authorisations, alongside several contract accounts from the account-abstraction world with 10 to 49 authorisations each. Those contracts run to several thousand bytes, while the two conspicuous targets get by on 772 and 1,042 bytes. A contract that only sweeps needs little code.
Care is needed here, because the percentage invites a false conclusion. So we looked at who actually sent these transactions.
The result: the 2,007 authorisations pointing at the top-ranked contract come from 186 transactions, and those 186 transactions came from a single sender. With 176 distinct senders across the whole window, almost half of all authorisations therefore trace back to one address that registers bundles of up to 110 powers of attorney at a time, minute after minute.
Our reading of this, and it is explicitly a reading rather than an established fact: the pattern does not fit 2,007 freshly harmed users, but rather an operator kitting out their own throwaway addresses. Besides the single sender, the design of the contract supports that view, since it only executes calls for its own creator. In address poisoning the attacker generates the deceptively similar addresses themselves and needs no one else's key to do so. What we are measuring in this case is infrastructure rather than loot.
The second conspicuous contract looks different. Its 170 authorisations are spread across 170 separate transactions from two senders, so one power of attorney per transaction. A collection contract that forwards incoming amounts immediately only makes sense for an account whose key is already in someone else's hands. For you as a reader the difference is decisive: the first case almost certainly does not concern you, the second concerns you directly if your account appears on that list.

A sweeper is a contract or program that forwards incoming amounts to an outside address automatically and within seconds. If you find a delegation to such a contract on your address, the delegation is not the cause but the consequence. Someone was able to sign in your name, and that requires your private key or your recovery words.
From this follows an order of operations that runs against the first reflex. The reflex says: revoke the power of attorney and move on. The correct view is this: the account is lost, and every amount you send there, including the fee for the revocation, will very likely go to the attacker. A revocation you pay for yourself funds the other side, in case of doubt.
So set up a new account first, ideally on a device whose key has never sat on a computer. Which designs come into question, and how the devices differ, is laid out in our software wallet comparison alongside the device selection. Only afterwards do you deal with whatever is left on the old account, and you do so with help.
For exactly this case there is a free point of contact, one that the sweeper contract's own source code names: the Flashbots whitehat hotline. It helps get remaining balances past a sweeper by settling the rescue and the fee in a single bundle that the sweeper cannot pick off separately. That is no guarantee, but it is the only serious route that requires no payment up front.
If the account is clean and the delegation is merely unwanted, because you no longer use a wallet feature for instance, then revoking it is simple and still easy to misunderstand.
A delegation does not end because you delete the app, change device or withdraw an approval. It ends solely through a new authorisation pointing at the zero target address, that is, an address made up entirely of zeros. Only then does your account's code field become empty again. Our measurement shows that this step does occur in practice: 140 of the 4,035 authorisations in the window were revocations of this kind.
Check the code field once more after revoking. An interface reporting success to you is not evidence. The evidence is an empty code field in the explorer.
A second point is easily overlooked: a new delegation replaces the old one entirely. Anyone switching from one wallet provider to another ends up with the new provider's power of attorney in the account, not both. That is reassuring, but it does not remove the need to check, because which contract ends up sitting there is decided by the most recently registered authorisation.
The most dangerous part of EIP-7702 is its price. An authorisation is a pure signature. It costs you nothing, it shows up in no fee summary, and you do not even have to submit it yourself: any third party may wrap it into a transaction of their own and cover the fee.
For honest providers that is an advantage, because a new account becomes usable straight away without holding funds. For a fraudulent site it is a gift. It needs no transfer from you, no approval and no balance on the account. A single signature in a window that looks like a login, a claim for free tokens or a security check is enough.
From this follows a rule for everyday use: treat every signature request whose content you cannot read as if it were a transfer. That applies in particular to requests asking you to update, migrate or secure an account. You already know this trick in its classic form from the world of manipulated payment recipients; how it plays out there was covered in our August analysis of address poisoning.
It would be wrong to conclude from all this that every delegation is an attack. Alongside the conspicuous targets, our measurement also shows a number of clearly attributable wallet contracts, among them the contract of a large browser wallet provider and several account templates from the account-abstraction world.
Three characteristics separate the two groups fairly reliably in practice:
Anyone working with several wallets regularly should note down their own provider's target address once. The check then becomes a comparison of twenty bytes next time, rather than a research task.
A common misconception holds that a hardware wallet makes this question moot. That is true for the key, but not for the power of attorney. An EIP-7702 authorisation is also signed with the private key, and in the worst case the device displays only a target address and a nonce, without being able to explain what follows from them.
What matters, then, is whether your device presents the content of a signature request in plain text and whether you have switched off the signing of unreadable data. What counts here was set out in our article on blind signing on hardware wallets. The recommendation from there applies unchanged: what the device cannot display, you do not sign.
The second protection is the separation of duties. One account for day-to-day dealings with applications, a second for holdings that stay put, and no signature from the second account on any website. A delegation on the everyday account is annoying; a delegation on the holdings account is expensive. If you need the technical wording of the specification, you can read it in the text of EIP-7702, in particular the rules for chain ID zero.
ef0100 means: read out the target address and look it up. Start with the addresses that actually hold something, and then set those holdings up on a device you pick from the hardware wallet comparison.(As of September 13, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
The Crypto Valley pioneer is moving up to 60 Zug jobs to Bratislava or Vietnam as it pivots from a Swiss crypto specialist into a global wealth manager.
TRM examined roughly $52.7 million across 198.9 million settlements using the x402 protocol. Most of it isn’t coming from AI agents, it says.
The fintech company fulfilled a fraudulent information request sent from a government agency's own email domain, exposing ID documents and full crypto transaction histories for a "limited" number of users.
A week after launch, complaints are rolling in from users that GPT-6 Astra has been nerfed. OpenAI's last model went through the same cycle in July.
Ben Delo and Christopher Harborne each gave £36 million, and between them beat what every UK party raised last year.
As whales withdraw $300 million in Ethereum ETH), Shiba Inu (shib) flashes spot accumulation signals.
XRP has managed to stabilize above $1.30 after its August comeback, keeping its broader recovery structure intact.
Bitcoin, XRP and Ethereum are recovering after Senate Republicans unveiled a revised Clarity Act with major White House-backed ethics concessions.
The XRP Ledger has apparently set a new record after processing 3,254 transactions in a single ledger.
Cardano, Hyperliquid, Shiba Inu and Stellar are all testing key support zones after recent pullbacks.
XRP price fell below $1.40 this week after breaking down from a tightening triangle pattern. The token now trades between $1.34 and $1.37.
The drop followed a rejection near $1.43 to $1.45. Analyst XAUApex on TradingView said XRP broke below a symmetrical triangle, calling it a shift in short-term structure with lower highs and lower lows.
The break does not confirm a longer downtrend on its own. A move back above $1.43 to $1.45 could weaken the bearish case.
XRP has fallen from a high near $1.70 reached in recent weeks. It has struggled to reclaim $1.40 since that peak.

The $1.31 area is the first support level traders are watching. Camarilla pivot data places S1 at $1.3143.
XRP’s 30-period moving averages sit near $1.327 to $1.338, close to the current price. Analyst vandell33 pointed to the weekly chart, noting price is squeezed between the 50-week and 200-week moving averages, a setup that has broken lower in past instances.
A deeper drop would bring $1.17 into view. That level lines up with the 100-period simple moving average near $1.168.
Analyst Setupsfx_ outlined a recovery scenario centered on $1.1673. The setup calls for a bullish rejection at that level, a two-day close above it, and a higher low before confirming any bounce. The same analysis lists $0.9929 as the point that would cancel the recovery idea.
On-chain data adds context to the move. Analyst Ali Martinez said XRP fell about 20% over three weeks, from $1.70 to around $1.35, as whales sold or moved close to 90 million tokens in the past week.
Daily active addresses on the XRP Ledger fell more than 90%, from about 388,000 to roughly 38,000, separate reporting citing the same data showed.
Around 2.29 billion tokens previously traded near the $1.35 level, creating a large cluster of past transactions.
TradingView’s broader indicator summary shows a mixed picture. The 14-period RSI sits near 53.6, a neutral reading, while momentum and MACD carry sell signals. Short-term moving averages sit above price and point down, while the 30-, 50-, and 100-period averages sit below price and point up. The overall count is 6 sell, 9 neutral, and 11 buy signals.
A reclaim of $1.38 is seen as a first step toward recovery, with on-chain analysis pointing to a possible move toward $1.60 to $1.68 if it holds. Beyond that, Camarilla resistance sits near $1.445, $1.510, and $1.575, with the Fibonacci R1 level near $1.626.
Ripple’s stablecoin RLUSD is drawing separate attention as the company targets corporate treasury markets. Ripple’s stablecoin chief has pointed to a customer base handling roughly $13 trillion in annual transactions, according to Thinking Crypto host Tony Edward.
The U.S. Senate is scheduled to vote on the CLARITY Act on September 15, a bill tied to crypto market regulation.
For now, XRP trades in a range, with $1.31 and $1.17 marked as the main support zones to watch.
The post XRP (XRP) Price: Falls Below $1.40 After Triangle Breakdown appeared first on Blockonomi.
Caroline Ellison has taken a new job at Manifund, a charity focused on effective altruism funding. The announcement came from Manifund co-founder and CEO Austin Chen in a Substack post published Sep 11.
Ellison was the CEO of Alameda Research, the trading firm tied to the collapsed FTX exchange. She pleaded guilty in December 2022 to conspiracy, wire fraud, securities fraud, and money laundering charges.
She later testified as a government witness against former FTX boss Sam Bankman-Fried during his 2023 trial. Ellison was sentenced to two years in prison for her role in the scheme.
According to Chen, Ellison began a trial role at Manifund on July 13. That trial turned into a full-time position on Aug 10.
For about two months, she published work and supported Manifund users under the name “Carol.” Chen said he made the decision to keep her identity private during this period.
Chen explained that Manifund tries to operate with transparency. He said the choice to use a pseudonym was a compromise on that value, though he still stands by the decision.
Chen said he first connected with Ellison after enjoying her writing online. He invited her to a conference called Manifest 2026, where she later asked about joining the Manifund team.
Chen also pointed to a personal connection with FTX. He said the collapsed exchange had helped fund Manifold, the platform that grew into Manifund, along with a retreat that drew him into the effective altruism community.
Ellison spent time in a Connecticut prison before being moved to a community confinement home in 2025. She was released on Jan 22, 2026, after a total of 14 months in custody.
Chen said Ellison has already contributed technical work to Manifund. He pointed to a reconciliation tool she built that identified several misregistered transactions in the charity’s database.
Not everyone welcomed the news. Cate Hall, the former CEO of the Astera Institute, responded in the comment section of Chen’s post.
Hall wrote that the hire showed “truly terrible judgment” and said it could harm the reputation of Manifund and other effective altruism organizations. Other commenters raised similar concerns in the thread.
Effective altruism is a movement that uses logic and data to guide philanthropic decisions. Several former FTX executives, including Bankman-Fried and Ellison, were known supporters of the philosophy before the exchange collapsed in 2022.
Ellison addressed the criticism directly in the same post. She said she is “deeply sorry” for her actions and said she understands why some people may not want to work with her.
She added that she feels lucky to have a job at an organization whose mission she believes in. Chen said he does not plan to respond to every comment on the announcement but welcomed public questions by email.
The post Caroline Ellison Joins Manifund Charity After FTX Prison Sentence appeared first on Blockonomi.
Hackers who stole customer data from Revolut have started posting it online. They say more will be released every day until the fintech company pays them.
The threat was shared in a message posted on Telegram. The attackers wrote they would keep releasing data “until revolut pays for leaking their customers.”
International Cyber Digest posted about the leak on X on Sunday. The account said the data already includes identity documents and selfies.
Two names have come up so far in reports. One is tennis player Alexander Shevchenko.
The other is Felix Römer, CEO of online crypto casino Gamdom. Cointelegraph reached out to both Revolut and Römer for comment.
The leaked files reportedly include copies of ID documents. They also include facial verification photos used to confirm identity during account signup.
This kind of information can be used for identity theft. Selfies paired with ID scans are often used to get around security checks at other companies.
Revolut told customers more details about what was taken. The company said the list includes full names and dates of birth.
It also includes occupation, contact information and account statements. Full transaction history was included as well, covering Bitcoin transactions made by customers.
Revolut explained the cause of the leak to Cointelegraph on Saturday. The company called it a “sophisticated external impersonation scam.”
In the scam, attackers used an email address tied to a real government agency domain. They used that email to send fraudulent requests asking for customer information.
Revolut did not say which agency the email appeared to come from. The company has not shared how many fraudulent requests were approved before the scam was caught.
This is not the first time Revolut has reported this kind of incident. The company previously said customer data was exposed through a fake government email.
That earlier case followed a similar pattern. Attackers posed as officials to trick the company into handing over user information.
Revolut has tried to limit concerns about the size of the breach. The company said only a “limited number” of customers were affected.
It also said customer funds were not touched. Revolut stated its systems remain secure and are operating normally.
Even so, the threat from the attackers suggests the leak is ongoing. They have said they plan to release new data daily.
That means more customer names or documents could appear online in the coming days. Revolut has not confirmed how it plans to respond to the threat itself.
Cointelegraph has not received a response from Revolut or Römer as of the latest update. This story may be updated as more information becomes available.
The post Revolut Confirms Customer Data Leak From Government Email Scam appeared first on Blockonomi.
King Charles III is set to host leaders from some of the world’s biggest AI companies this week. The summit will take place at Dumfries House in Scotland.
The event is being organized by the Ditchley Foundation. It was first reported by The Sunday Times.
Companies invited to attend include Nvidia, OpenAI, Anthropic, IonQ and Google DeepMind. The stated goal is to discuss how AI can be developed for the good of humanity.
The gathering comes just one week after three AI executives publicly called for slower development of the technology. Anthropic CEO Dario Amodei, OpenAI CEO Sam Altman and SpaceXAI CEO Elon Musk all signed an open letter on Friday.
In the letter, Amodei said AI systems have been improving much faster since the summer months. He linked this speed increase to a process called recursive self-improvement, where AI helps build better versions of itself.
Amodei warned that a swarm of AI agents could become capable of taking over the entire internet. He said this could happen within the next six to twelve months.
He pointed to an attack on Hugging Face in July as an example of the kind of threat he is worried about. Altman responded to the letter and agreed that AI firms need to slow their pace at the frontier of development.
Sources close to King Charles told The Sunday Times that he has taken a personal interest in AI development. They said he is also concerned about the risks the technology could pose.
The King has previously spoken about technology and its effects on society. This summit adds AI safety to that list of interests.
No agenda details have been released publicly ahead of the event. It is not yet known if any formal agreements or statements will come out of the meeting.
The summit brings together some of the most powerful names in AI under one roof. That includes both large public companies and smaller specialized firms like IonQ.
Dumfries House has hosted other high profile gatherings in the past. It is owned by a charity connected to King Charles.
The Ditchley Foundation regularly organizes discussions on global policy issues. AI safety has become one of its focus areas in recent years.
This is the first known instance of King Charles directly convening AI industry leaders. The meeting is expected to draw attention from policymakers watching the space closely.
As of now, the summit has not yet taken place. Coverage of the actual discussions and any outcomes is expected once the event concludes this week.
The post King Charles III to Host AI Executives at Scotland Summit appeared first on Blockonomi.
Robinhood CEO Vlad Tenev is defending his company’s stock token product after AMC Entertainment pushed back hard. Tenev says the fight comes down to legal structure, not technology.
He laid out his position in a post on September 11. Tenev argued that a company should control the rights tied to its shares. He said it should not control every lawful use of those shares once investors already hold them.
The dispute started after AMC CEO Adam Aron objected to a Robinhood token linked to AMC shares. Aron said AMC never authorized or endorsed the product.
Robinhood’s tokens are not AMC shares placed on a blockchain. The company says they are debt securities issued by Robinhood Assets, a Jersey-based entity.
Each token tracks the price of an underlying stock. Robinhood says every token is backed one-for-one by real shares held with a U.S. custody partner.
Token holders do not appear on AMC’s shareholder register. They get no voting rights and cannot claim the legal rights tied to direct stock ownership.
Robinhood says its tokens can pass along dividend value through adjustments built into the product terms. Corporate actions still depend on Robinhood’s own contract terms, not on AMC’s actual policies.
Tenev broke tokenized stocks into three types. A company can tokenize its own shares directly. A third party can tokenize shares it holds in custody. Or an independent firm can issue a separate security that simply tracks another company’s stock.
He said issuer approval should only be required in the first two cases. He argued the third model, which Robinhood uses, does not need a company’s sign-off because it changes nothing about the underlying stock.
Aron said on September 4 that AMC has no relationship with Robinhood’s token. He said the structure could confuse investors about what rights they actually hold.
He also raised concerns about AMC’s ability to raise capital through its official securities. Aron demanded that Robinhood stop offering the token tied to AMC stock.
Robinhood’s chief legal officer, Dan Gallagher, rejected that demand in public comments. Tenev then defended the token model again during a CNBC interview on September 9.
The Securities and Exchange Commission has not ruled on this dispute. In January, three SEC divisions published a joint statement describing different categories of tokenized securities, including third-party products like Robinhood’s.
That statement said the legal classification of a token depends on the rights and obligations it creates. It did not decide whether third-party tokens require the referenced company’s consent.
A separate SEC proposal released in September would update transfer-agent rules. It would allow blockchain systems to support official securities records, but it would not automatically turn a token into a real share.
Robinhood launched its current Stock Tokens outside the United States in July through Robinhood Chain. The products remain unavailable to U.S. investors and several other jurisdictions, including Canada and the United Kingdom.
As of September 14, AMC has not filed a lawsuit against Robinhood. The SEC has not announced any investigation or public response to Aron’s threatened regulatory referral.
The post Robinhood CEO Rejects AMC’s Demand Over Stock Token Rights appeared first on Blockonomi.
Bitcoin (BTC) is heading into one of its most consequential weeks of the year so far, with the Federal Reserve announcing its September rate decision on Wednesday and the Bank of Japan following two days later.
Markets are pricing in roughly an 85% chance of a 25-basis-point Fed hike, and according to XWIN Japan, the real question isn’t whether rates move but how hawkish both central banks sound once they do.
XWIN Japan laid out the scenario that worries it most: US yields and the yen rising together. Higher US rates tighten global liquidity, and a stronger yen risks speeding up the unwind of yen-funded carry trades, pushing investors to cut risk across stocks and crypto at once.
Brent crude has traded above $100, and the US 10-year yield has approached 5%, keeping inflation worries alive going into the decision. Once the meetings pass, XWIN wants traders watching US yields, USD/JPY, spot Bitcoin ETF flows, and underlying demand, since, according to them, that’s where the real test begins.
As CryptoPotato reported previously, the setup shifted fast, with August payrolls coming in at 162,000, triple what economists expected, and producer prices accelerating to an annual 5.4%. Last week’s CPI print confirmed headline inflation at 3.4%, and BTC reacted, sliding from about $82,400 to under $78,000 since Fed Chair Kevin Warsh’s Jackson Hole speech and the hot data that followed.
Tuesday brings its own catalyst too, a Senate cloture vote on the CLARITY Act that needs 60 votes to advance.
There’s a political wrinkle too, as a result of President Donald Trump threatening to stop trading with countries running a US trade deficit if the Fed didn’t cut rates, and markets are now leaning toward a hike instead, which is the opposite of what he wants.
Spot On Chain’s Hupzy called it “a binary macro catalyst with asymmetric cross-asset risk,” warning that a hike pressures non-yielding assets while a political bend raises questions about dollar credibility.
BTC changed hands a few hundred bucks away from $78,000 at the last check, up slightly in 24 hours but down about 2.5% over one week, even as it still gained approximately 23% in the last 30 days. It is also nearly 39% below its all-time high of more than $126,000 from last October.
ETF flows, meanwhile, split in opposite directions, with spot Bitcoin funds shedding $462.73 million across four trading days last week, their first negative week since mid-August, while ETH ETFs kept gaining, capped by a $216.41 million Friday inflow as the world’s second-largest cryptocurrency touched an eight-month high.
The post Japanese Yen, US Yields Pose Biggest Near-Term Bitcoin Risk: Analysts appeared first on CryptoPotato.
The CLARITY Act has received another round of changes as Senate Republicans try to secure enough Democratic support for Tuesday’s procedural vote on the cryptocurrency market structure bill.
The latest version, which consists of 635 pages, includes an ethics framework backed by President Donald Trump that would restrict public officials from issuing or sponsoring digital assets. The revised text allows both the Department of Justice (DOJ) and the state attorneys general authority to enforce the rules.
The change addresses one of the main issues Democrats had raised during negotiations. They had previously objected to an arrangement in which the DOJ would be responsible for enforcing the ethics provisions. The debate over the rules also came from concerns surrounding Trump and his family’s financial involvement in the crypto sector.
US Senate Banking Digital Assets Subcommittee Chair Cynthia Lummis stated,
“After a year of intense daily bipartisan negotiations, this bill is ready. President Trump voluntarily agreed to unprecedented ethics restrictions, holding every federally elected official, judge, and their spouses to some of the toughest ethics restrictions in US history… Democrats got what they wanted; now they need to take yes for an answer.”
The ethics section incorporates much of the Tillis-Gallego proposal. Among its provisions, officials would have to either sell substantial crypto-related financial holdings or move them into a blind trust.
Changes to the Blockchain Regulatory Certainty Act (BRCA) now limit its scope to the Bank Secrecy Act and civil enforcement. Language that would have extended its protections to criminal proceedings, including cases brought under Section 1960, has been taken out. The changes would also bring miners and validators under those protections.
The bill’s stablecoin yield section has also been revised with a “circuit breaker” mechanism first floated by Tillis in July. It would give federal regulators the ability to step in if stablecoins were causing significant withdrawals from community banks.
Stricter limits on vertical integration have also been introduced, such as rules covering affiliate trading and potential conflicts involving digital commodity exchanges, brokers, and dealers. The text also confirms that state consumer protection laws remain in effect. Developer protections would not override derivatives regulations or change the rules governing prediction markets.
Last week, Coinbase CEO Brian Armstrong voiced support for the CLARITY Act ahead of the Senate vote. Speaking on CNBC’s Squawk Box Asia on September 10, the exec said the bill was ready for approval and claimed support from law enforcement groups, banks, and crypto companies. He also said Coinbase’s main concerns with the legislation had been addressed after the company previously raised several issues it considered essential.
The post Last-Minute Changes to the CLARITY Act: Will Democrats Finally Back the Crypto Bill? appeared first on CryptoPotato.
Although there are several major economic events taking place in the following five business days, the reality is that only a handful of them could (and most likely will) impact the cryptocurrency market. That impact, though, is expected to be quite vicious in either direction.
The Kobeissi Letter highlighted an auction of 20-year securities, August retail sales, and, most importantly, the Federal Reserve’s September interest rate decision on Wednesday. The latest data shows that markets assign an 85%-90% probability that the central bank will hike rates by 25 basis points, following contrasting economic data.
The Fed setup has changed dramatically in just a few weeks, starting with the August employment data from early September, which showed that the US economy had added 162,000 jobs last month, triple expectations. Later on, the PPI numbers indicated that the annual producer inflation had accelerated to 5.4%. Last Friday’s CPI report subsequently confirmed headline inflation at 3.4%, with monthly core CPI slightly hotter than expected.
This combination, plus the fact that oil prices remain above $100 and diesel hit a new record in the States, has strengthened the Fed’s case for tighter policy.
Bitcoin and the altcoins have already demonstrated their sensitivity to this shift, dropping sharply following Fed Chair Kevin Warsh’s speech from Jackson Hole several weeks ago, and again as rate-hike odds increase after the latest economic data.
The only question is whether this highly expected rate hike has been priced in, with BTC sliding from $82,400 to under $78,000 as of now. As such, investors will closely watch Warsh’s press conference after the meeting for clues as to whether the Fed’s decision on Wednesday is a one-off adjustment or the start of another tightening cycle.
Before all eyes turn on the Fed on Wednesday, the crypto industry has another major event on Tuesday. The Senate’s cloture vote on the CLARITY Act is scheduled for 2:15 P.M. that day, and it requires 60 senators to advance the debate on the key bill.
The CLARITY Act aims to establish a comprehensive US crypto market structure and shed further details on the respective roles of the SEC and the CFTC.
Republicans released an updated text last week, adding new rules for non-decentralized DeFi protocols and clarifying how credit unions can deal in crypto. Moreover, they published their “last, best, and final” draft of the legislation on Sunday, including an ethics proposal backed by the POTUS.
The post Bitcoin’s Biggest Week of 2026 Is Here: Fed and CLARITY Vote Take Center Stage appeared first on CryptoPotato.
The Justice Department’s Scam Center Strike Force, working with the Treasury Department, seized a Chinese-language scam marketplace called Xinbi Guarantee and restrained about $52 million in cryptocurrency in a single day, U.S. Attorney Jeanine Pirro announced this week. That operation brought the total the Strike Force has restrained since its founding to roughly $938 million.
A separate Strike Force team also spent the same stretch helping authorities in Madagascar take down 13 Chinese-run scam compounds, pushing the crackdown launched last November well beyond its original footprint in Southeast Asia.
Xinbi ran almost entirely on Telegram, in Chinese, functioning as a kind of marketplace where vendors advertised services to scam center operators: building custom fraud investment websites, “washing” money stolen through wire fraud, and recruiting trafficking victims to staff scam compounds.
Xinbi itself held payments in escrow until a vendor finished the job, which is how prosecutors say they were able to trace specific victim funds to vendors who posted wallet addresses on the channel. A federal court in Washington authorized the seizure of those Telegram channels on September 7, and prosecutors unsealed the warrant Wednesday.
Investigators seized two crypto wallets Xinbi used to collect vendor payments, worth roughly $12 million, and sought restraint of 47 more wallets tied to the network, bringing the total taken from the platform and its vendors past $52 million.
The Treasury’s Office of Foreign Asset Control (OFAC) separately designated Xinbi a transnational criminal organization the same day, along with two other entities accused of supporting it, freezing any property they hold in the U.S.
Pirro said the case shows why ordinary people are at risk:
“Every American with a retirement account is in the blast radius,” she stated. “My Strike Force will continue to dismantle Chinese organized crime, those who facilitate it, and protect Main Street America.”
Alongside the Xinbi action, U.S. Attorney Michael Heyman of Alaska said the Strike Force’s two-week Madagascar deployment, which helped process more than 3,200 devices and interview about 400 people who had been arrested, reflects where the fight is headed.
“Transnational criminal organizations don’t care about borders, and the Department of Justice won’t either,” he said.
In March, the British government sanctioned Xinbi, with Chainalysis estimating the platform had processed nearly $20 billion in crypto between 2021 and 2025, selling everything from stolen personal data to satellite equipment used to reach fraud victims.
That earlier action barely slowed it down, with the criminal group simply opening new Telegram channels and continuing with its operations. The Strike Force itself dates to November 2025, when Pirro set it up to go after Chinese organized crime running scam centers.
Federal data cited in Wednesday’s announcement put reported crypto investment fraud losses at $8.65 billion in 2025, up 89% from $4.57 billion in 2023, although the FBI says the figures are “significantly under-represented,” since most fraud victims do not report.
The post DOJ Strike Force Seizes Scam Marketplace, Restrains $52M in Crypto appeared first on CryptoPotato.
Bitcoin is consolidating around $77.3K after a powerful breakout from the $67K area. While the broader structure has improved significantly, BTC is now facing an important resistance cluster near $80K-$82K. Meanwhile, the latest Coinbase Premium reading suggests that US spot demand has yet to fully confirm the recent advance.
The daily chart shows a significant structural recovery. After falling to the $60K demand zone in June, Bitcoin spent several months building a broad base before breaking decisively above the $67K resistance area in late August. The subsequent rally carried BTC rapidly through the $72K-$74K zone and toward the $80K area.
The $72K-$74K region has now become the first major support zone. A successful retest of this area would preserve the bullish structure established by the recent breakout. Below it, the $67K zone is a more important structural support, as it previously capped the market for several months. A deeper correction could bring the $60K demand zone back into focus.
On the upside, BTC is approaching the $80K-$82K resistance zone. The price has already tested this area several times but has failed to establish a sustained breakout above it. A daily close above $82K would therefore be significant, as it could open the way toward the $90K mark or even higher.

The 4-hour chart provides a clearer view of the latest move. Bitcoin spent much of the summer trading sideways between roughly $60K and $67K before staging a sharp breakout. The move through the $67K resistance zone accelerated dramatically, taking BTC through $74K.
After reaching the $80K-$82K area, however, the rally has lost momentum. BTC is currently trading around $76.8K and has formed a relatively broad consolidation below resistance. This can be interpreted as a potential continuation range following the breakout, provided the lower boundary remains intact.
The immediate support is located around the same daily $72K-$74K zone. This area is particularly important because it represents the previous resistance zone that BTC cleared during the breakout. Holding it would maintain the sequence of higher highs and higher lows on the 4-hour timeframe.
The main resistance remains $80K-$82K. A clean breakout and sustained trading above this zone would signal that buyers are regaining control and could bring the next major daily resistance around $95K into consideration. Conversely, repeated rejection followed by a break below $72K could trigger a deeper retracement toward $67K.

The Coinbase Premium Index provides an important caveat to the technical picture. The metric measures the price difference between Bitcoin on Coinbase and other major exchanges and is commonly used as a proxy for US-based spot buying pressure. Positive readings generally indicate stronger demand on Coinbase, while negative readings suggest comparatively weaker US spot demand.
The latest reading on the chart is around -0.02, with the index back in negative territory. This is notable because BTC has simultaneously remained well above the levels seen before the late-August breakout.
The divergence suggests that the recent price strength has not been accompanied by a sustained surge in Coinbase buying pressure. In other words, while the technical structure has improved, the latest premium data does not yet provide strong confirmation of aggressive US spot accumulation.
Historically, within the period shown, the Coinbase Premium spent considerable time below zero during BTC’s decline toward the $60K area, while stronger positive readings appeared during several recovery phases. The current negative reading, therefore, warrants some caution as Bitcoin approaches the $80K-$82K resistance zone.
For the bullish scenario to strengthen, a renewed move of the Coinbase Premium into positive territory alongside a breakout above $82K would provide more convincing confirmation. If BTC instead loses $72K while the premium remains negative, it would increase the probability that the recent rally is undergoing a deeper correction rather than immediately transitioning into another leg higher.

The post Bitcoin Price Analysis: BTC Faces a Make-or-Break Week – What’s the Most Likely Scenario? appeared first on CryptoPotato.