The oil price surge may pressure the Bank of England to reconsider its monetary policy, potentially impacting inflation and economic stability.
The post Oil price surge prompts UK rate hike speculation ahead of BOE decision appeared first on Crypto Briefing.
Robinhood's entry into underwriting could democratize IPO access, challenging traditional banks and potentially reshaping retail investor dynamics.
The post Robinhood aims for underwriting success with Oura IPO appeared first on Crypto Briefing.
Heightened U.S.-China tensions may disrupt diplomatic engagements, affecting market stability and future geopolitical strategies.
The post Trump accuses China of spying on US amid Iran strike report appeared first on Crypto Briefing.
Warsh's Fed leadership may strain economic growth and market stability, challenging his ability to balance inflation control with political pressures.
The post Kevin Warsh faces a rates trap as Fed chair navigates inflation pressure and political crosswinds appeared first on Crypto Briefing.
Kyuhong Lee's appointment as CIO could steer the National Pension Service towards more stable, traditional investments, impacting global markets.
The post National Pension Service appoints Kyuhong Lee as CIO of $1.4 trillion portfolio appeared first on Crypto Briefing.
Bitcoin Magazine

Bitcoin’s ‘Unusual Mix’: Bearish Inflation Print, Bullish Buyback Failure
Bitcoin’s path higher just got harder in the short term, but the setup further out may be improving, according to a new report.
In a Friday note, European asset manager CoinShares’ Head of Research, James Butterfill, said firmer-than-expected core inflation raises the odds of tighter Fed policy and could cap bitcoin below $80,000 for now.
But the longer-term case, he argued, rests on the U.S. Treasury’s bond buyback programme failing to bring down long-end yields — a failure that could ultimately feed the debasement narrative that has supported both bitcoin and gold.
“The result is therefore a somewhat unusual policy mix for Bitcoin,” the report read. “Today’s CPI data is negative at the margin, increasing the probability of tighter monetary policy and potentially limiting the immediate upside.
“But the apparent failure of the Treasury’s current buying programme increases the likelihood of much more substantial intervention further ahead.”
It continued: “If that happens, it could become one of the more powerful medium-term catalysts for Bitcoin.”
Data on Friday revealed that the consumer price index, excluding food and energy, climbed 0.3% in August from a month earlier — higher than expected.
According to CME’s FedWatch tool, traders think there is a 85% chance interest rates will be higher after the Federal Reserve meets next week. Bitcoin has typically performed well in a low interest rate environment.
But the U.S. Treasury’s expanded bond buyback programme has so far failed to materially suppress long-term yields.
If yields stay stubbornly high, Butterfill said, pressure will build on Treasury Secretary Scott Bessent to escalate to a much larger, “bazooka-style” buying programme aimed at forcing borrowing costs down.
Bitcoin in August had one of its best runs in years after Treasury Secretary Scott Bessent announced the department would double the size of its long-dated bond buybacks.
The announcement and subsequent price surge has led some to say the much talked-about debasement trade is back. The so-called debasement trade is when investors buy an asset as a way to hedge against a currency losing value.
Bitcoin and gold have both benefited as part of the trade as the dollar weakens.
This post Bitcoin’s ‘Unusual Mix’: Bearish Inflation Print, Bullish Buyback Failure first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Bitcoin Magazine

Blockstream Tells Hackers To Return Remaining Bitcoin Stolen in Liquid Theft
Bitcoin infrastructure firm Blockstream has refused to negotiate further with hackers who last week stole 4,000 bitcoins from its Liquid network.
Writing on X Friday, Blockstream said that the hackers still had time to return the funds before the company would work with law enforcement.
White-hat hackers on Sunday withdrew about $320 million from the federation wallet that backs Liquid, a sidechain by Blockstream. After negotiating with Blockstream, they returned most of the funds but kept 598.5 coins worth over $46 million — demanding it as ransom.
“Blockstream will not pay a ransom for the return of stolen funds,” the post read. “Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft.”
It added: “We will work with law enforcement, exchanges, service providers, forensic specialists, and other relevant parties to trace and recover the assets and identify those responsible.”
“We will not pay for the return of stolen property. We will not abandon our users. The Bitcoin community will not stop pursuing the funds.”
Liquid, or L-BTC, is a layer-2 created by Blockstream that allows users to fast move assets backed 1:1 with bitcoin. One of the assets, LBTC, is a token backed by bitcoin that allows for quick settlement — a bit like the Lightning Network.
Hackers were able to get the funds by exploiting an inflation bug on the Liquid sidechain to create over 4,000 LBTC that did not exist before and cash them out for real, on-chain bitcoins.
The hackers then had an exchange with Blockstream via messages written into Bitcoin blocks.
In one message, the white hats wrote: “Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.”
In the latest message, the hackers slammed Blocksteam as “delusional, greedy, and arrogant,” and threatened to reveal all of Blockstream’s encrypted messages in the exchange unless the company allowed thieves to keep 10% of the bitcoins.
“You SHALL pay 10% using your own money as bug bounty or you will cause all your holders a 15% loss for your irresponsibility and stinginess,” the message read.
The Bitcoin community is still reeling after hackers in July were able to steal over 1,800 bitcoins worth close to $140 million from Coldcard wallet holders.
Users of the popular hardware wallet, created by Coinkite, were targeted because the product’s manufacturer did not use a true random number generator, allowing hackers to essentially guess investor seedphrases.
This post Blockstream Tells Hackers To Return Remaining Bitcoin Stolen in Liquid Theft first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Bitcoin Magazine

Italy’s Second Biggest Bank UniCredit Is Weighting up Crypto Custody: Report
Italy’s second largest bank is considering expanding into digital asset offerings, including custody, according to reports.
According to a Friday Bloomberg report citing people familiar with the matter, Milan-based UniCredit is selecting a technology provider that would allow it to build the infrastructure needed to hold digital assets and facilitate their buying and selling.
Bloomberg’s reporting added that tokenized investment products and fixed-income securities, the use of stablecoins and exposure to cryptocurrencies were all on the cards.
The news comes as other banks in Europe expand crypto offerings. Spain moved first on retail, with BBVA rolling out bitcoin trading and custody to all customers via its app, using its own custody infrastructure rather than a third party; Santander’s Openbank followed with its own trading service.
Cecabank — a Spanish custodian with over €400bn under management that acts as backbone for 100+ financial institutions — went live with crypto custody in June via a partnership with Bit2Me.
And in Germany, Deutsche Bank is building custody with Bitpanda’s technology arm, while Taurus and DZ Bank got BaFin approval in January for its meinKrypto platform.
New regulation in the European Union — Markets in Crypto-Assets Regulation (MiCA) — gives banks a legal definition, a supervisor, and a familiar set of obligations to launch crypto services.
UniCredit is one 37 lenders across 15 European countries working together to create a company called Qivalis with the aim of issuing a euro-denominated stablecoin.
Last year, the bank said it was offering professional clients a structured product tied to BlackRock’s iShares Bitcoin Trust exchange-traded fund, with full protection against losses.
This post Italy’s Second Biggest Bank UniCredit Is Weighting up Crypto Custody: Report first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Bitcoin Magazine

Government Defeated as Lords Back UK Digital Assets Strategy
The UK government suffered a defeat in the House of Lords on Wednesday as peers backed an amendment requiring the Treasury to draw up a national strategy for regulating digital assets.
The upper chamber approved the measure by 194 votes to 138, with Conservative and Liberal Democrat peers combining against a near-solid bloc of Labour votes. Baroness Neville-Rolfe, a Conservative former Treasury minister, moved the amendment to the Financial Services and Markets Bill.
The new clause, titled “Digital assets strategy,” would require the Treasury to prepare, publish and consult on a strategy for regulating and developing digital assets and related digital financial market infrastructure in the UK.
The regulation of digital assets includes “cryptoassets, qualifying stablecoins, Central Bank Digital Currencies, tokenised securities and other digital and tokenised financial assets,” according to the draft.
The UK is in the process of drafting a sweeping new crypto bill. The country’s Financial Conduct Authority finalised its regulatory framework for cryptoassets in June, with the regime due to take effect on 25 October 2027. The authorisation gateway for firms opened on 30 September and runs to 28 February 2027.
Britain is trailing behind Brussels and Washington with digital asset regulation. The EU’s Markets in Crypto-Assets regulation has applied to service providers since 30 December 2024.
And the U.S. under President Donald Trump signed the GENIUS Act into law in July 2025, establishing a federal framework for dollar-backed tokens. Broader market-structure legislation remains unfinished: the Clarity Act cleared the House in July 2025 by 294-134 but has been stuck in the Senate over DeFi, stablecoin yield and ethics provisions, with a procedural vote set for next week.
This post Government Defeated as Lords Back UK Digital Assets Strategy first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Bitcoin Magazine

Bitcoin Price Spikes, Shrugs off Hot US Inflation Data
Bitcoin’s price rose on Friday — despite data revealing that U.S. inflation had risen.
The biggest cryptocurrency by market cap was recently trading for close to $78,749 after jumping 2% over a 24-hour period. At one point on Friday morning in New York, bitcoin rose as high as $79,607.
Bitcoin’s price spike came after news dropped that U.S. consumer prices accelerated in August, reinforcing expectations that the Federal Reserve will raise interest rates next week.
The consumer price index, excluding food and energy, climbed 0.3% in August from a month earlier, which was higher than expected.
Inflation in the U.S. has been difficult to tame due to the war with Iran, which has lifted oil prices, in turn raising the costs of food, gasoline and other goods.
Higher inflation typically means the Federal Reserve will raise interest rates, which in turn could stop bitcoin’s price climbing higher.
According to CME’s FedWatch tool, traders think there is a 85% chance interest rates will be higher by next week. The Federal Reserve will meet next week and reveal what it will do with borrowing costs.
Bitcoin has typically performed well in a low interest rate environment because it means people can buy more of the cryptocurrency with increased liquidity.
Federal Reserve Chairman Kevin Warsh, who took the helm in January, last month gave his first speech as head of the U.S. central bank and said he had “more work to do” to fight inflation.
The U.S. is currently in the grips of an affordability crisis and rising oil prices are a hot topic ahead of the midterm elections.
U.S. President Donald Trump has reassured voters that prices will get under control and repeatedly put pressure on the central bank to lower interest rates.
Bitcoin in August had its biggest run in years following positive regulatory news and an announcement from the U.S. Treasury.
Treasury Secretary Scott Bessent announced the department would double the size of its long-dated bond buybacks, helping non-yielding assets like bitcoin and gold. The cryptocurrency then benefited from President Trump urging lawmakers to get key crypto legislation, the Clarity Act, over the line.
This post Bitcoin Price Spikes, Shrugs off Hot US Inflation Data first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Cross-chain protocol Symbiosis said it recovered approximately 15 BTC after an attacker exploited its native Bitcoin Bridge, but affected liquidity providers still lack compensation terms as a Sep. 13 bounty window nears its unspecified cutoff.
The vulnerability was exploited at about 04:28 UTC on Sep. 11, according to the protocol's incident statement. Symbiosis said only the Bitcoin Bridge was affected and that its other routes and components remained operational. It specifically listed routes spanning EVM chains, TRON and TON as unaffected, and said its relayer group continued operating to secure the network. The protocol said the recovered bitcoin is secured in a team-controlled multisig.
The 15 BTC figure is simply the amount Symbiosis says it recovered to date. The protocol said final accounting remained in progress and that it would publish confirmed figures in another update.
Security firm Blockaid reported that a transaction accepted as signed by Symbiosis's BridgeV2 system minted approximately 2^62 raw units of syBTC, a synthetic representation of bitcoin, to a newly created wallet on BNB Chain.
Blockaid said the same beneficiary sold about 4.39 WBTC on Ethereum, realizing roughly $336,000 in WBTC proceeds at the time of its alert. That figure covers value Blockaid observed the attacker convert. It does not establish Symbiosis's final loss or the total exposure of liquidity providers.
Symbiosis initially said Bitcoin-related swaps were unavailable while it deployed updates. In a later operational update, the protocol said Bitcoin swaps routed through partners Chainflip and THORChain were back online, while the native Symbiosis Bitcoin Bridge remained paused.
That distinction determines what users can access. Partner-routed Bitcoin swaps are available, according to Symbiosis, but the protocol has not announced the return of the affected bridge. The split keeps traffic off Symbiosis's paused bridge while users access alternative Bitcoin routes.

Symbiosis said it was contacting every affected liquidity provider directly and building a compensation framework, with criteria to follow. It has not disclosed who will qualify, how compensation will be calculated or when payments could begin.
The protocol also offered the attacker a 20% white-hat bounty through Sep. 13. After that window, Symbiosis said the same percentage would be offered to anyone providing information that leads to recovery. The statement did not specify an exact cutoff time or timezone.
Affected liquidity providers are now waiting for three disclosures: confirmed loss and exposure figures, compensation criteria, and any change to the native bridge's status. Until Symbiosis publishes that information, the recovered funds and Blockaid's proceeds estimate should not be treated as a final loss tally.
The post Hackers mint trillions in fake Bitcoin, but 15 BTC bridge recovery leaves liquidity providers unpaid appeared first on CryptoSlate.
In decentralized finance, “audited” is often presented as a verdict on an entire project. In practice, an audit usually covers named code, components and versions at a particular point in time. Anything added, excluded or operated around that boundary may carry a different level of assurance.
A new preprint puts a number on that gap. Researchers affiliated with security company ack3 and the Czech Technical University in Prague examined 135 reported incidents from the first half of 2026, with $939.86 million in attributed losses. They found identifiable public pre-incident audits for 68 incidents.
Within that 68-incident subset, the authors classified 46 attack paths as outside every audit scope they could identify, 20 as inside at least one scope and two as unresolved. The outside-scope group represented 67.6% of the incidents but 94.4% of their reported losses.
That striking percentage is not an estimate of audit effectiveness or proof that an audit’s boundaries caused a loss. It describes the distribution of losses in a selected set of reported incidents. Two large cases also dominate it: after excluding $292 million at Kelp DAO and $285 million at Drift Protocol, the outside-scope share falls to 72.1% of losses in the same audited-incident subset.
Even with those limits, the study exposes a basic assurance problem. A project may truthfully say it was audited while leaving users unable to tell whether the live system, the path holding their funds and the controls around it were reviewed.

The ack3 dataset covers incidents from Jan. 1 through June 29. Its authors graded 122 as confirmed and 13 as likely. Of the full set, 35 had no identified audit and 32 had an unknown audit history, so neither group appears in the 68-incident scope calculation.
For that 68-incident group, outside-scope incidents accounted for $680.97 million of $721.24 million in reported losses, producing the 94.4% figure. Removing Kelp DAO and Drift Protocol left $103.97 million of $144.24 million outside scope, or 72.1%. The machine-readable ledger reproduces the bucket counts and loss sums.
The inside-or-outside labels remain the researchers’ judgments about public evidence. They searched project and auditor archives, located pre-incident reports and compared the eventual attack paths with reviewed code, versions and exclusions. The work is a six-page preprint produced with the dataset publisher, and two authors are affiliated with ack3, which sells security reviews.
The study also lacks an unexploited comparison group and a measure of how long each system was exposed. It cannot establish whether audited protocols are safer overall, estimate incident probability or show that falling outside scope caused each loss. Undisclosed audits and private incidents may be missing, while reported loss figures are not perfectly comparable.
The study therefore supports a limited conclusion: audit history and audit scope are different variables. A reviewed smart contract does not automatically confer the same assurance on an upgrade, privileged key, front end, relayer, oracle, cloud service or incident-response process.
Two incidents from August illustrate that distinction in different ways. ICON Network provides a direct example of reviewed code failing at the boundary between two checks. The August aelf incident provides a contrasting case because the available audit evidence cannot yet be tied to its reported runtime path.
In ICON Network’s Aug. 27 replay exploit, two parts of a withdrawal path interpreted the same message differently.
According to the ICON Foundation’s Aug. 30 postmortem, a migration contract used the high bits of a withdrawal message’s serial number to decide whether it was unique. The cryptographic signature covered only the low 256 bits. By changing the unsigned high bits, an attacker resubmitted two legitimately signed withdrawal messages 1,492 times over about 20 minutes. ICON said 1,490 calls succeeded.
The replays released 119.866 million ICX and 531,600 bnUSD. At the time of the postmortem, ICON put the confirmed net loss at about 150.2 ETH plus 31,204 USDC. It said 531,600 bnUSD and 1.366 million SODA had been recovered and that user deposits, balances and positions were not affected.
ICON said the migration contract had undergone an external audit and that recommendations had been implemented, including changes in the same area. It also said the relevant relay logic received a dedicated review. The SODAX audit archive lists eight reports across different components, including a November 2025 relay audit.
Yet the postmortem said the precise mismatch between the uniqueness check and the signed value fell outside those findings. A project-level badge could not tell a user whether both ends of the withdrawal path agreed on what made a message unique.
The response timeline adds a second kind of boundary. ICON’s first automated alert fired at 02:08 UTC, about seven minutes after the exploit began. Staff opened an investigation around 03:40, paused the affected contract at 03:53 and halted the network at 06:18:54.
ICON attributed the roughly 90-minute gap between the first alert and a full incident response to alert tuning. The alert class had produced false positives during unrelated connectivity incidents and did not page the on-call team at the needed severity. The foundation said it planned an automatic shutdown trigger, lower circuit-breaker thresholds and a follow-up review focused on message uniqueness and replay guards.
Those controls do not replace an audit. They provide evidence for a different question: when prevention fails, how quickly can detection become containment?
| Public assurance | The question users still need answered |
|---|---|
| “Audited” | Which repository, commit, deployed address and component were reviewed? |
| “Findings fixed” | Were the fixes deployed, and what changed afterward? |
| “Monitored” | Which alerts page a human or stop the affected path automatically? |
| “Funds recovered” | Which assets are confirmed recovered, frozen, exposed or still under investigation? |
aelf’s August incident tests the argument from another direction. Its public record describes a runtime compromise and a controlled recovery, but it does not provide enough evidence to place the path inside or outside a specific pre-incident audit.
The company announced a network pause on Aug. 18. In its Aug. 26 progress update, aelf said an unauthorized smart contract could use transaction parameters to deliver encoded .NET assemblies and instructions into the node execution path.
The provisional account linked the incident to gaps in checks for runtime reflection and dynamic loading, together with weak isolation between contract execution and sensitive node or infrastructure resources. aelf identified 155 associated transactions and five unique payload assemblies with capabilities including host command execution, attempted outbound communication, node-key access and infrastructure reconnaissance.
Capability is not the same as confirmed execution. aelf said the payloads did not prove that every assembly ran, that every targeted credential was obtained or that sensitive data left its systems. The company said it was rotating signing keys and infrastructure credentials under a potential-exposure standard.
The public status remained provisional on Sept. 11: aelf’s blog index contained no incident-specific item published after Aug. 26. The Aug. 26 statement committed to another update and an eventual final review.
aelf’s standing security documentation says its blockchain and ELF token contracts underwent multiple audits with no security issues identified. But the available pages do not connect a specific pre-incident report to the runtime path described in August. Calling the incident either an audit miss or an outside-scope failure would therefore outrun the evidence.
That uncertainty is itself useful. A dated audit history can become detached from a system’s current code, dependencies and operational state. Users need an assurance record that is versioned and specific enough to reveal that drift.
Such a record should name the reviewed repository and commit, deployed addresses, excluded components, privileged roles and dependencies. It should also record upgrades since review, key custody and rotation, runtime isolation, alert and circuit-breaker behavior, and dated recovery status that separates confirmed loss from frozen or unresolved exposure.
This does not reduce the value of an audit. It makes the claim proportional to the work performed and connects that work to the system operating now.
An audit badge cannot answer whether the reviewed artifact, the deployed system and the machinery that responds to failure still share the same security boundary.
The post Audited DeFi protocols lost $885M to attacks that occurred completely outside their audit scopes appeared first on CryptoSlate.
Coinbase’s new partnership with payments platform Moov gives community banks and credit unions a route to offer stablecoin services through the financial relationship they already have with businesses. The local institution can remain the customer’s front door, while Coinbase supplies the disclosed custody and transaction infrastructure behind it.
Moov CEO Wade Arnold framed the demand bluntly: business customers asked to accept stablecoins currently go outside their primary financial institution. Moov and Coinbase want that service to appear inside the institution’s existing payments experience. The arrangement could preserve the bank’s customer connection. Control of the economics, data and operational risk remains unresolved until the companies disclose their terms.
Under the partnership announced Sept. 10, Moov will integrate Coinbase’s stablecoin payments infrastructure into its existing platform for financial institutions. Coinbase said its CDP Custodial Wallet accounts will provide fund custody and its Payments API will orchestrate stablecoin movement. Moov will connect those functions to the systems used by its bank and credit-union customers.
That division places three parties between a business and the stablecoin rail. The bank or credit union owns the primary customer interaction. Moov supplies the payments-platform connection. Coinbase provides the announced crypto custody and movement components. The customer may experience one bank-facing product even though the underlying service spans multiple providers.
Coinbase’s announcement said Moov has a customer base of more than 1,000 community banks and credit unions. The figure describes Moov’s potential distribution footprint. Live, contracted and pilot institutions remain unquantified, and the companies gave no implementation timetable.
| Disclosed | Undisclosed | Decision it affects |
|---|---|---|
| Coinbase supplies custodial accounts and stablecoin movement tooling | The ownership and settlement configuration for each institution | Where balances sit and who directs key operations |
| Moov embeds the tools in its financial-institution payments platform | The number of live, committed or pilot banks | Whether distribution reach becomes adoption |
| The bank remains the customer-facing institution | Fees, revenue sharing, data rights, compliance duties and liability | Whether the bank retains economics and practical control |

The disclosed architecture gives Coinbase a material role behind the interface. Its standard payments documentation describes a custodial-account stack in which crypto can enter an account, be held and reconciled there, and leave through fiat or crypto transfers. Separate custodial wallet documentation says Coinbase provides custody for assets in those accounts on behalf of the CDP entity.
Those documents cover Coinbase’s standard platform. The partnership record leaves each institution’s supported stablecoins, networks, custodial-balance ownership and fiat-settlement route unspecified. It also leaves fees, revenue sharing, transaction-data access, compliance allocation and liability out of public view.
The result is a split form of control. Community institutions can keep the account relationship and present the service to customers. Coinbase and Moov remain essential to the disclosed technology chain. The bank’s economic and operational leverage will turn on its authority over pricing, settlement destinations, customer data and risk decisions. Coinbase holds a material infrastructure role within a payment chain that also depends on Moov and participating institutions.
A bank-facing interface leaves the payment stablecoin’s legal status unchanged. Customer protection and bank balance-sheet exposure follow the legal claim represented by the balance.
In an April 2026 proposed rule, the Federal Deposit Insurance Corporation said deposits held at banks as reserves for a payment stablecoin would be insured as corporate deposits of the stablecoin issuer, subject to applicable limits. Stablecoin holders would receive no pass-through deposit insurance under the proposal.
The same proposal draws a boundary around tokenized deposits. An instrument that meets the statutory definition of a bank deposit remains a deposit regardless of the technology or recordkeeping used. A payment stablecoin and a tokenized deposit can therefore give customers a digital-dollar experience while representing different legal claims.
For a community institution, the distinction reaches beyond consumer disclosure. A qualifying tokenized deposit remains the issuing bank’s liability. Access to a third-party stablecoin can keep the payment experience inside a bank channel while the customer’s converted funds may cease to be a deposit at that bank.
Deposit effects remain conditional rather than following an automatic dollar-for-dollar path. A Federal Reserve analysis published in December 2025 said stablecoins can reduce, recycle or restructure deposits. The outcome depends on who buys them, what assets are converted and where stablecoin issuers place their reserves.
Domestic customers converting transaction-account balances can reduce deposits, especially when issuers hold reserves outside banks. If issuers keep reserves in bank deposits, more funding can stay in the system, though it may move from dispersed retail accounts toward concentrated, uninsured wholesale balances. The effect on any one community bank also depends on whether reserve money returns to that institution or is concentrated with larger custodial and settlement banks.
The Fed identified partnerships, custody services, settlement accounts and white-label infrastructure as possible ways banks can stay connected to digital payment flows. It also described a deeper structural tension: stablecoins may separate the payment relationship from the deposit-funded lending model that banks have historically used to serve households and businesses.
The Moov arrangement puts both possibilities in one product design. A bank may keep the customer conversation and gain a service that would otherwise require its own crypto stack. Coinbase may gain transaction and custody activity while customers access stablecoins through their primary institution. The destination of deposits and revenue remains unsettled.
The first bank deployments will provide the evidence missing from the announcement. Adoption counts will show whether Moov’s network converts into actual demand. Supported assets, account ownership and settlement paths will show whether stablecoin activity returns value to the same institution or routes it elsewhere.
Commercial disclosures will be equally important. Pricing and revenue sharing determine whether the bank earns from the new service or mainly supplies distribution. Data access and compliance responsibilities determine who can deepen the customer relationship and who bears the burden when monitoring or processing fails. Liability terms determine how operational control translates into financial risk.
Coinbase has offered community banks a bridge into stablecoin payments, with its custody and payment infrastructure underneath. That structure may stop the bank from disappearing from the customer’s view. The next test is how much of the payment relationship, balance-sheet value and decision-making power stays with the bank when the customer gains stablecoin access through it.
The post Coinbase gives community banks a stablecoin bridge while supplying infrastructure underneath appeared first on CryptoSlate.
Bitcoin payment processor BTCPay Server has warned that bots are probing exposed Lightning nodes for a potential route to administrative control.
The activity follows a separate critical BTCPay vulnerability that attackers exploited a month ago to obtain credentials protecting LND nodes and drain merchant wallets.
BTCPay subsequently disabled external access to LND, a widely used implementation of Bitcoin’s Lightning Network, in its standard Docker deployment. The project now says automated systems are targeting servers where operators manually restored that access, repeatedly calling an LND password-change endpoint.
The latest mechanism differs from the vulnerability exploited in August but could lead to a similar outcome: an attacker obtaining credentials that can control an LND node.
BTCPay said the opening appears during a short interval after LND restarts, while its wallet remains locked. During that period, the targeted password-change method does not require a macaroon, the credential LND normally uses to authorize administrative actions.
Older BTCPay LND wallets compounded the risk by using a shared default password. An attacker who could reach the interface before BTCPay’s internal unlocker could potentially submit that password first, replace it, and request an administrator macaroon that gives control over the node.
BTCPay has not reported a successful takeover through the newly observed activity or linked the bots to the attackers behind the August thefts.
The renewed probing extends a difficult security stretch for BTCPay, which acknowledged on Aug. 7 that attackers had exploited a vulnerability affecting all versions before 2.4.2. That flaw allowed unauthenticated attackers to obtain LND macaroon files and use them to move funds. BTCPay’s standard on-chain wallets were unaffected.
Days later, the project and its supporters offered a bounty equal to 10% of recovered bitcoin, capped at 3 BTC, then worth about $190,000. BTCPay also enlisted exchanges, blockchain analytics firms, and law enforcement in efforts to trace the stolen funds.
Version 2.4.4, released Sept. 7, now addresses the conditions behind the latest attack path. New LND wallets receive unique random passwords, while older installations using the shared credential are migrated and have their passwords rotated.

BTCPay’s standard reverse proxy also blocks unauthenticated wallet setup and unlock methods, closing the restart-time opening through its managed public network path.
Those controls cannot secure infrastructure operators configure independently. Administrators who created their own reverse proxy or otherwise exposed LND publicly can still bypass BTCPay’s protections.
BTCPay has urged administrators to install version 2.4.4 and remove manually exposed LND routes. A route-control change merged Sept. 11 provides a supported option for remote access while keeping LND and Core Lightning interfaces disabled by default.
That leaves custom deployments as the immediate concern. Operators using them must audit their proxy rules and migrate remote connections behind BTCPay’s managed controls while automated systems continue searching for reachable nodes.
The post Malicious bots are actively probing exposed Bitcoin payment servers to steal master administrative keys appeared first on CryptoSlate.
Ledger's status page continued to list Cosmos (ATOM) as a major outage on Sept. 13, leaving users unable to view ATOM balances or transaction history and unable to submit transactions through Ledger Wallet more than four days after the incident began.
The company opened the incident at 19:41 CEST on Sept. 8. As of press time, its latest update, posted at 16:12 CEST on Sept. 10, said restoration work was continuing and that the affected features remained unavailable. Ledger has not disclosed a cause or an estimated restoration time.
The continuing warning does not mean Cosmos Hub is still halted. It shows that Ledger Wallet's service path for retrieving account data and sending ATOM transactions has not recovered with the network itself.
QuickNode reported that Cosmos Mainnet stalled at block 32,878,318 at 18:12 UTC on Sept. 8. The infrastructure provider said its nodes had returned to the chain tip by 14:26 UTC on Sept. 9, then marked its incident resolved at 00:24 UTC on Sept. 12.
The Cosmos Hub RPC endpoint was above block 32.9 million on Sept. 12 and reported that the node was not catching up. That placed the chain tens of thousands of blocks beyond the height in QuickNode's initial alert.
Together, those readings separate two layers of the problem. Cosmos Hub resumed producing blocks, while Ledger Wallet access remained unavailable. Users may therefore see missing balances or history in Ledger Wallet even though the network is processing new blocks.

QuickNode's resolution applies to its infrastructure, while Ledger's separate incident remains identified. Those states can coexist because a wallet interface can stay unavailable after network nodes have caught up. Ledger has not said which part of its service path is responsible.
For users who need to move ATOM urgently, Ledger's incident notice points to its alternative-methods guide. The company lists Cosmostation and Keplr as compatible third-party interfaces that can connect to a Ledger device.
Ledger's Keplr instructions tell users to open the Cosmos app on their device and choose Keplr's hardware-wallet connection option. That route uses another interface to access the same blockchain account while keeping the Ledger device in the transaction flow.
The safety distinction is critical: connecting a hardware wallet is not the same as importing its recovery phrase. Ledger's security guidance says users should never enter the phrase into a computer or smartphone and should never share it, including with Ledger.
Users who do not need to transact urgently can continue monitoring Ledger's status page. Because the incident remains open and could change without notice, its status should be refreshed before any workaround is attempted.
The post Cosmos is back online after outage, but Ledger users still can’t see or send their ATOM appeared first on CryptoSlate.
On Wednesday, September 16, 2026, the US Federal Reserve publishes its interest rate decision, and futures markets mostly expect a hike. If you have a savings plan running on Bitcoin, the honest answer to the question of what you have to do now is: probably nothing. Two things are still worth checking, and beforehand rather than afterwards: exactly when your next instalment is executed, and how much headroom a running crypto loan still has.
This article explains what actually happens on September 16, which mechanism connects a US policy rate to your monthly Bitcoin purchase, and where the meeting day gets expensive for retail investors. It contains no price forecast, because nobody can seriously predict how the market will react to a decision that is already largely priced in.
The body that sets the US policy rate is called the Federal Open Market Committee, or FOMC: the monetary policy committee of the Federal Reserve, which meets eight times a year and sets the target range for the overnight rate between banks. The meeting runs over two days, September 15 and 16, 2026. The decision comes on the second day.
The Federal Reserve meeting calendar marks the date with an asterisk. That asterisk looks like a footnote and carries the most important information on the page: it flags the meetings at which the Fed publishes a Summary of Economic Projections. Those projections are the collected expectations of the central bankers on growth, unemployment, inflation and the future level of rates, and they reach several years ahead. After September, only two meetings remain in 2026, on October 27 and 28 and on December 8 and 9.
The decision is published at 18:00 UTC, which is 20:00 in central European summer time. The press conference starts half an hour later. For you that means: Wednesday evening between 20:00 and 21:00 CEST is the window in which prices on crypto exchanges get most turbulent. The Frankfurt stock market has long since closed by then; the crypto market keeps trading.
The current target range for the overnight rate is 3.50 to 3.75 percent. It has been in place since July 30, 2026, as recorded in the Fed's implementation note for the July meeting. A basis point is one hundredth of a percentage point, so 25 basis points are 0.25 percentage points. If the step goes through, the range would afterwards sit at 3.75 to 4.00 percent.
Why expectations flipped at all can be pinned to a single number. US consumer prices in August were 3.4 percent higher than a year earlier, with the core rate at 2.4 percent; the largest single driver was petrol, up 3.9 percent. After the release on September 11, the probability of a September hike priced into futures markets jumped. The figures different houses quote for the CME FedWatch reading sit in a range of roughly 86 to 90 percent, after around 70 to 72 percent the day before. I am deliberately not smoothing that range: the value moves with every trading day, and the spread itself is the more honest piece of information.
The numbers come from CNBC's report on August consumer prices, which carries the FedWatch readings. Important for context: a priced-in probability reflects what the market has in the price. The value is a bet by futures traders and carries no predictive power beyond that, and that is exactly why prices move less on the expected step than on the deviation from it.
The connection is less mysterious than many headlines make it sound. A higher policy rate means that parking money risk-free earns more. Anyone getting four percent on overnight deposits or short-dated government bonds demands a higher compensation for anything riskier. Bitcoin pays no interest and consists exclusively of price movement. As the risk-free return rises, so does the bar Bitcoin has to clear.
On top of that comes the funding channel. A large share of short-term trading volume in the crypto market runs on borrowed money. When money gets more expensive, leveraged positions shrink and the market gets thinner. That explains why price moves on central bank days are often more violent than the news itself warrants.
At the time of writing, Bitcoin trades at around 76,700 US dollars, or roughly 66,200 euros; retrieved on September 14, 2026 at 00:40 UTC via CoinGecko's public price interface. In the preceding 24 hours the change was under one percent. That figure is a snapshot and no basis for a decision meant to work over years.
The short answer is no, and the reason lies in the purpose of a savings plan. A savings plan buys a fixed amount at fixed intervals, regardless of the price. It is the decision to stop making individual decisions. Anyone who pauses it ahead of a scheduled event has abolished it at exactly the moment it was built for.
What does make sense is checking once whether the instalment still fits your circumstances. If rising rates make your mortgage or your overdraft more expensive, the instalment is the lever, not the execution date. Which providers allow which minimum instalments, intervals and fees is set out in our comparison of Bitcoin savings plan providers, and with small instalments the fee side quickly becomes the largest cost block.
Pausing means: you do not buy this month. Adjusting means: you keep buying, but with an amount you can sustain through a bad quarter as well. The first is a market forecast in disguise, the second is household budgeting. Only one of the two is something you can do reliably.
Dollar cost averaging describes a simple arithmetic phenomenon: anyone buying regularly for the same amount gets more units at low prices and fewer at high ones, so the average price ends up below the mean of the prices. No promise of returns comes with that, and no protection against losses either. The effect is a procedure that prevents timing errors.
On a central bank day the benefit shows particularly clearly, because the price move after the decision can go either way and the counter-move often follows within hours. A savings plan simply does not take part in that question. If you want to know how it stacks up against a lump sum purchase, we worked it through in our article on savings plans and lump sum purchases when buying more of August 24, 2026.
This is the part where a meeting day can do real damage. Anyone who has pledged crypto assets as collateral and taken out a loan against them is working with a loan-to-value ratio: the relation of the loan amount to the current value of the collateral. If the price of the collateral falls, that ratio rises. Once it crosses the provider's limit, an automatic sale follows. This forced sale is called liquidation, and it does not ask whether the move will be over again an hour later.
Two figures determine how well you sleep here. The first is the distance between your current ratio and the liquidation threshold. The second is the interest rate you pay on the loan, because variable rates in crypto loans track market rates and demand for the borrowed asset. Our overview "Crypto lending: interest rates and risks" of August 16, 2026 describes these mechanisms in detail.
Log in once before Wednesday evening and note down two numbers: the price at which your position would be liquidated, and the distance between that price and today's level in percent. If that distance is in single digits, it is a state you should change regardless of the Fed. Either by topping up collateral or by repaying part of the loan.

Because a 25 basis point hike is around nine tenths priced into the market, the actual information sits in the projections. Their best-known component is the dot plot: a scatter of points in which every member of the committee anonymously marks where they see the policy rate at year end. If that cloud shifts upwards, the committee is signalling further steps. If it stays where it is, the September step was a one-off response to the price data.
For a savings plan that is the only relevant question of the evening, and it is a question about months, not hours. A rate peak reached in December looks entirely different for long-term investors than a path pointing upwards well into 2027.
Around every meeting, price targets appear from institutions and individual analysts. Take them for what they are: expectations attributable to a name. Anyone quoting a price target should be able to name its source; without a name, all that remains is sentiment. And where expectations diverge, both sides belong side by side, the optimistic one and the cautious one.
The spread is the gap between the price at which you can buy and the price at which you could sell. It is the part of the cost almost nobody calculates, because it does not appear on the statement. In turbulent market phases it widens, and that is exactly what happens in the hour after a central bank decision.
If your savings plan executes on the 16th or 17th of the month anyway, that is no reason to change anything; over years it evens out. But if you were planning to change the execution date regardless, a date in the quieter middle of the month between two central bank meetings is the less conspicuous choice. While you are at it, check whether your provider executes at a fixed time or at some point during the day; in the latter case the timing is out of your hands.
Anyone holding Bitcoin through an exchange-traded product rather than directly gains a second layer: those securities only trade during exchange hours. If the decision lands at 20:00 CEST, while German trading is closed, you only see the move the next morning at the open, and then all at once.

Directly nothing, indirectly a great deal. Anyone holding Bitcoin as private assets in Germany can realise gains tax free once a year has passed; that one-year period is called the holding period and runs separately for every purchase. With a savings plan that means: you have as many holding periods as executed instalments.
The connection to the Fed arises the moment a price move tempts you to sell. Anyone selling after a violent evening move may realise gains from instalments that have not yet reached the one-year mark, and pays their personal income tax rate on them. The order in which the tax office assigns the units sold follows the first-in-first-out principle: the units bought first count as sold first. What that looks like in concrete terms with monthly instalments is set out in our article "Bitcoin savings plans and tax: holding period, FIFO and the exemption limit" of August 11, 2026.
The most expensive mistake is rarely bad timing. What gets expensive is the unintended: a decision to sell in the evening, taken in reaction to a headline, which only reveals its price in the following year's tax return. What helps against that is a rule you write down before Wednesday, not on Wednesday.
(As of September 14, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
An Ethereum address that belongs to you has been able to execute someone else's program code since the Pectra upgrade, without its address, its balance or its key changing at all. EIP-7702 is what makes this possible: one signature from you is enough, and from that moment on your address behaves like a contract. This is the basis for many convenient wallet features, and it is also the route by which attackers keep a drained account permanently under their control. This article shows you how to check in two minutes whether your own address carries such a delegation, and what to do if the contract sitting there is one you do not recognise.
The basis for this is our own measurement on the Ethereum chain, taken today. It shows how widespread these delegations have become and what they mostly point to. The answer is more uncomfortable than wallet marketing suggests, but also more nuanced than a bare percentage implies.
EIP-7702 is an extension to Ethereum that lets an ordinary key-controlled account run the program code of a contract without becoming a contract itself. The account keeps its private key, its address, its balance and its nonce. All it gains is a pointer to a contract whose code runs on the account's behalf on every call.
The technical term for this is delegation. The pointer is written into the account's code field, which until then was empty for a key-controlled account. From that moment on, anyone calling the account calls the stored contract, and that contract reaches the account's storage and balance.
The benefit is obvious. A wallet can bundle several steps instead of asking you to sign three times. A provider can cover the fee on your behalf. An app can set up a tightly bounded spending permission that expires after an hour. These are exactly the features wallet makers have been selling under the Smart Account label since 2025.
The price sits in the same sentence: the stored contract acts with your account's full authority. It can move funds, grant approvals and trigger further calls. A delegation is therefore not a setting but a power of attorney, and it stays in place until you replace it or revoke it.
A delegated account carries exactly 23 bytes in its code field: the fixed marker 0xef0100 followed by the 20 bytes of the target address. That marker is the only reliable evidence. Everything else an interface shows you is interpretation.
In practice you see it in two places. A block explorer suddenly lists your address as a contract, or displays a note about a delegated account, even though you have never deployed a contract. And the code lookup that every explorer offers returns, instead of an empty value, a short string beginning with ef0100.
The 20 bytes that follow are the address you have to check. They decide everything. If your wallet maker's contract address is sitting there, the delegation is probably intended. If something unfamiliar is sitting there, you have a problem that goes well beyond a misplaced click.
One point matters for context: an empty code field is the good news. If you find nothing there, you have no active delegation, regardless of whether one existed in the past.
The check takes a few minutes and needs neither a tool nor an installation.
ef0100 means the delegation is active.The same check works on every chain where EIP-7702 is live. An authorisation signed for chain ID zero is even valid on all chains at once. Anyone using several networks is better off checking more than once.

This analysis was carried out by cryptoticker.io itself on September 13, 2026. Method: we pulled 200 consecutive blocks in full from a public Ethereum node, blocks 25,971,139 to 25,971,338, and evaluated every transaction of type 0x04 in them together with its authorisation list. The window runs from 21:14:35 to 21:54:23 UTC and covers 39.8 minutes of chain time.
The numbers from that window:
What we could not measure is how many accounts currently carry a delegation in total, because that would require a full state dump of the chain rather than a time window. Nor can these data show how much money was moved through the contracts we found. And a 40-minute window is a snapshot: another day may show a different distribution.
In this measurement the names say more than the shares do. Publicly verified source code is available for two of the three most frequent targets, and both describe themselves as tools used by criminals.
The most frequent target, with 2,007 authorisations, or 49.7 percent of the window, carries the name Poisoner in its verified source code. The comment in the source names the purpose outright: the contract is used for address poisoning, that is, to trick inattentive users into sending funds to a wrong address that looks visually similar. As the party behind the publication, the source names the trading firm Wintermute, which says it rebuilt and disclosed the contract. The program code itself is short: it executes a list of arbitrary calls, but only if the transaction was triggered by exactly the address that created the contract.
The third most frequent target, with 170 authorisations, carries the name CrimeEnjoyor. Here too the explanation sits in the source code, and it is set in capital letters: anyone who finds this contract in an authorisation list has a compromised account; no further funds may be sent there, because they will be swept immediately. The code is shorter still than that of the first contract. It does precisely one thing: every incoming amount is forwarded straight away to a target address fixed at setup.
For comparison, the legitimate side of the same list: in eighth place sits a verified contract from a well-known wallet maker with 110 authorisations, alongside several contract accounts from the account-abstraction world with 10 to 49 authorisations each. Those contracts run to several thousand bytes, while the two conspicuous targets get by on 772 and 1,042 bytes. A contract that only sweeps needs little code.
Care is needed here, because the percentage invites a false conclusion. So we looked at who actually sent these transactions.
The result: the 2,007 authorisations pointing at the top-ranked contract come from 186 transactions, and those 186 transactions came from a single sender. With 176 distinct senders across the whole window, almost half of all authorisations therefore trace back to one address that registers bundles of up to 110 powers of attorney at a time, minute after minute.
Our reading of this, and it is explicitly a reading rather than an established fact: the pattern does not fit 2,007 freshly harmed users, but rather an operator kitting out their own throwaway addresses. Besides the single sender, the design of the contract supports that view, since it only executes calls for its own creator. In address poisoning the attacker generates the deceptively similar addresses themselves and needs no one else's key to do so. What we are measuring in this case is infrastructure rather than loot.
The second conspicuous contract looks different. Its 170 authorisations are spread across 170 separate transactions from two senders, so one power of attorney per transaction. A collection contract that forwards incoming amounts immediately only makes sense for an account whose key is already in someone else's hands. For you as a reader the difference is decisive: the first case almost certainly does not concern you, the second concerns you directly if your account appears on that list.

A sweeper is a contract or program that forwards incoming amounts to an outside address automatically and within seconds. If you find a delegation to such a contract on your address, the delegation is not the cause but the consequence. Someone was able to sign in your name, and that requires your private key or your recovery words.
From this follows an order of operations that runs against the first reflex. The reflex says: revoke the power of attorney and move on. The correct view is this: the account is lost, and every amount you send there, including the fee for the revocation, will very likely go to the attacker. A revocation you pay for yourself funds the other side, in case of doubt.
So set up a new account first, ideally on a device whose key has never sat on a computer. Which designs come into question, and how the devices differ, is laid out in our software wallet comparison alongside the device selection. Only afterwards do you deal with whatever is left on the old account, and you do so with help.
For exactly this case there is a free point of contact, one that the sweeper contract's own source code names: the Flashbots whitehat hotline. It helps get remaining balances past a sweeper by settling the rescue and the fee in a single bundle that the sweeper cannot pick off separately. That is no guarantee, but it is the only serious route that requires no payment up front.
If the account is clean and the delegation is merely unwanted, because you no longer use a wallet feature for instance, then revoking it is simple and still easy to misunderstand.
A delegation does not end because you delete the app, change device or withdraw an approval. It ends solely through a new authorisation pointing at the zero target address, that is, an address made up entirely of zeros. Only then does your account's code field become empty again. Our measurement shows that this step does occur in practice: 140 of the 4,035 authorisations in the window were revocations of this kind.
Check the code field once more after revoking. An interface reporting success to you is not evidence. The evidence is an empty code field in the explorer.
A second point is easily overlooked: a new delegation replaces the old one entirely. Anyone switching from one wallet provider to another ends up with the new provider's power of attorney in the account, not both. That is reassuring, but it does not remove the need to check, because which contract ends up sitting there is decided by the most recently registered authorisation.
The most dangerous part of EIP-7702 is its price. An authorisation is a pure signature. It costs you nothing, it shows up in no fee summary, and you do not even have to submit it yourself: any third party may wrap it into a transaction of their own and cover the fee.
For honest providers that is an advantage, because a new account becomes usable straight away without holding funds. For a fraudulent site it is a gift. It needs no transfer from you, no approval and no balance on the account. A single signature in a window that looks like a login, a claim for free tokens or a security check is enough.
From this follows a rule for everyday use: treat every signature request whose content you cannot read as if it were a transfer. That applies in particular to requests asking you to update, migrate or secure an account. You already know this trick in its classic form from the world of manipulated payment recipients; how it plays out there was covered in our August analysis of address poisoning.
It would be wrong to conclude from all this that every delegation is an attack. Alongside the conspicuous targets, our measurement also shows a number of clearly attributable wallet contracts, among them the contract of a large browser wallet provider and several account templates from the account-abstraction world.
Three characteristics separate the two groups fairly reliably in practice:
Anyone working with several wallets regularly should note down their own provider's target address once. The check then becomes a comparison of twenty bytes next time, rather than a research task.
A common misconception holds that a hardware wallet makes this question moot. That is true for the key, but not for the power of attorney. An EIP-7702 authorisation is also signed with the private key, and in the worst case the device displays only a target address and a nonce, without being able to explain what follows from them.
What matters, then, is whether your device presents the content of a signature request in plain text and whether you have switched off the signing of unreadable data. What counts here was set out in our article on blind signing on hardware wallets. The recommendation from there applies unchanged: what the device cannot display, you do not sign.
The second protection is the separation of duties. One account for day-to-day dealings with applications, a second for holdings that stay put, and no signature from the second account on any website. A delegation on the everyday account is annoying; a delegation on the holdings account is expensive. If you need the technical wording of the specification, you can read it in the text of EIP-7702, in particular the rules for chain ID zero.
ef0100 means: read out the target address and look it up. Start with the addresses that actually hold something, and then set those holdings up on a device you pick from the hardware wallet comparison.(As of September 13, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Since September 11, 2026 a duty applies across the whole of the EU that did not exist in this form before: anyone who makes a product with digital elements available commercially on the European market must report an actively exploited vulnerability to the competent bodies within 24 hours and inform affected users about the vulnerability and about the countermeasures they can take themselves.
For you as a holder of cryptocurrencies, the second part is the more important one. It sits in Article 14(8) of the EU Cyber Resilience Act and shifts the question of who has to make sure you learn about a problem with your wallet. Until now that was a matter of company culture. From now on it is a legal duty with a fining framework behind it.
This article explains what exactly applies, from when, to whom, and where the line runs between the documented legal position and over-interpretation. Because the regulation does not name a single wallet brand, and anyone who derives a list of affected manufacturers from it is writing more than what is there.
The Cyber Resilience Act is Regulation (EU) 2024/2847, usually called the Cyber Resilience Act or CRA for short. The CRA entered into force on December 10, 2024, but only applies in full from December 11, 2027. Article 71(2) contains one sentence that upends the whole timetable: "This Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026, and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026."
Article 14 is headed "Reporting obligations of manufacturers" and is thus the part of the regulation that was switched on first. Everything else — the conformity assessment, the CE marking, the essential cybersecurity requirements in Annex I — only arrives in 2027. So anyone reading right now that the CRA applies means this one article.
The core in one sentence: a manufacturer must report every actively exploited vulnerability in its product and every severe security incident simultaneously to the CSIRT designated as coordinator and to the EU Agency for Cybersecurity, ENISA, through a single reporting platform.
What is a CSIRT? A Computer Security Incident Response Team is the body designated by a member state that receives, assesses and passes on security incidents. In Germany, CERT-Bund within the Federal Office for Information Security is the coordinating CSIRT, and the BSI also handles market surveillance.
What is an actively exploited vulnerability? A security flaw the manufacturer knows attackers are already using. A theoretical gap someone found in a laboratory does not start the 24-hour clock. Abuse in practice does.
The CRA is not financial law and not crypto law. It is horizontal product law and takes no interest in which assets a device manages, only in whether it is a product with digital elements and whether it is made available commercially on the EU market. That is precisely what makes it relevant for crypto custody.
A hardware wallet is a physical device with firmware that talks to companion software over USB, Bluetooth or QR code. A wallet app is software a provider makes available for download. By their design, both are what Article 3(1) describes as "a software or hardware product and its remote data processing solutions". Article 2(1) draws the boundary via the connection: the regulation applies to products whose intended purpose or reasonably foreseeable use includes "a direct or indirect logical or physical data connection to a device or network".
For the custody of cryptocurrencies, that is the point at which something changes. If you hold your balance yourself, your security hangs on exactly two things: on the quality of the device or the software, and on whether you find out in time when something is wrong with it. On the first, the reporting duty still says nothing; the corresponding requirements only bite in 2027. On the second, it says something with immediate effect. Which devices are available at all and how they differ is in our hardware wallet comparison; for purely software solutions the same considerations apply with a different attack surface.
Whether a specific device or a specific app is covered is decided by three test steps. There is no list of affected products. First: is the product made available on the EU market, that is, supplied for distribution or use in the course of a commercial activity? Second: is it a software or hardware product within the meaning of Article 3? Third: does its intended or reasonably foreseeable use include a direct or indirect data connection?
A commercially distributed, connected hardware wallet and a wallet app offered by a company can satisfy these three questions. That is an application of the legal test and not an official finding for any particular product. Anyone who turns it into a claim that this or that provider must now do this or that is asserting something that neither the regulation nor the Commission's guidelines supports.
Where the manufacturer is based also matters. Article 14(7) regulates this in detail: what governs is the CSIRT of the member state in which the manufacturer has its main establishment in the Union, that is, where the decisions on the cybersecurity of its products are predominantly taken. If it has no establishment in the EU at all, an order of precedence applies: first the member state of the authorised representative, then that of the importer, then that of the distributor, and finally the member state in which the largest number of users is located. A provider outside Europe is therefore not automatically out of scope once it serves the European market.

The regulation requires three reports that build on one another. All deadlines start at the moment the manufacturer becomes aware.
For a severe security incident under Article 14(3) the same split into 24 and 72 hours applies, but there the final report is due one month after the 72-hour notification. When an incident counts as severe is defined in paragraph 5: when it affects the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive data or functions, or when it has led or can lead to the execution of malicious code.
Reporting runs through the CRA Single Reporting Platform operated by ENISA. The manufacturer submits once, and the report is made available to the competent coordinating CSIRT and to ENISA at the same time. After the final report, the reporting person can as a rule no longer edit the submission.
The deadlines towards the CSIRT and ENISA are the part the industry press writes about. For you as a user, the decisive sentence sits elsewhere, namely in Article 14(8). Slightly abridged, it reads: after the manufacturer has become aware of an actively exploited vulnerability or a severe security incident, "it shall inform the affected users of the product with digital elements, and where necessary all users, about that vulnerability or incident and, where necessary, about any risk mitigation and corrective measures that the users can deploy".
Three points in this are worth reading closely.
First: the duty attaches to the same awareness as the report to the authorities. The trigger is the same moment. For informing users, however, the regulation names no fixed number of hours. What is required is information in connection with becoming aware, and elsewhere the text turns on timeliness. Anyone who turns the 24 hours for the authority into a 24-hour deadline towards customers is reading the provision wrongly.
Second: users must be informed about the countermeasures they can take themselves. That is the practical core. A notice that merely says there was a problem does not satisfy the wording if there are measures users can take themselves. With a wallet, those measures are precisely the relevant ones: update the firmware, temporarily stop using a particular function, move a balance to a new address, check a signature manually before confirming it.
Third: the regulation would like a machine-readable format. The text speaks of a structured, machine-readable format that is easy to process automatically, and qualifies this with "where appropriate". For security researchers and for portals that aggregate warnings, that is the most interesting wording in the whole paragraph.
The second sentence of paragraph 8 is the genuinely new lever: "Where the manufacturer fails to inform the users of the product with digital elements in a timely manner, the CSIRTs designated as coordinators may provide such information to the users when they consider it to be proportionate and necessary for preventing or mitigating the impact of those vulnerabilities or incidents."
European law thereby states that an authority may inform the public about a product vulnerability if the manufacturer does not do so in time. For Germany that means, concretely: CERT-Bund at the BSI receives the report as coordinating CSIRT, and the BSI can act as market surveillance authority. That is not an obligation to warn; the wording is "may" and turns on proportionality and necessity. For you it nevertheless means that from now on there is a second place at which information about a product you use comes together.
A look at the cases of recent weeks shows that this route is needed. When a vulnerability in a Bitcoin Lightning implementation became public in August, the information for operators hung on a release note and on trade media. We worked through that case in our article on the Core Lightning vulnerability and the question of when a node has to go offline. How a wallet warning can be technically verified at all is in our article on blind signing and how to switch it off on your hardware wallet.
Here is the qualification that belongs in every honest text on this subject. Neither the regulation nor the European Commission's guidelines names a single wallet brand, a single device type from the crypto world, or any particular provider. The CRA works with abstract product categories and a legal test that every economic operator has to carry out for itself.
Two things follow from that. For one, you cannot read from the regulation whether a particular device you own is covered. That depends on how the manufacturer is organised, where it is based, how it distributes, and how the competent authorities apply the legal test in the individual case. For another, over the coming months you will read texts that fill this gap with names. Anyone writing that a specific provider "now has to" do this or that is formulating a legal assessment for which there is neither an administrative decision nor a court ruling.
The only reliable thing at this point is the procedure. If such a statement interests you, check two things. Is there a manufacturer's own declaration behind it, or a statement by an authority? And does it refer to Article 14, which has applied since September 11, or to the conformity duties that only bite from December 11, 2027? The two are frequently conflated at the moment.

A large part of crypto infrastructure is open source and maintained by individuals, associations or foundations. For this constellation the CRA contains its own treatment, and that matters for what you can expect.
Free and open source software is, under recital 18, software whose source code is openly shared and whose licence provides for all rights to make it freely accessible, usable, modifiable and redistributable. What is decisive for the scope is the commercial character of the supply: according to the same recital, only free and open source software that is made available on the market, and thus supplied for distribution or use in the course of a commercial activity, falls within the scope. The mere circumstances of development and the type of funding are expressly not meant to play a role.
On top of that comes Article 64(10)(b). Under it, the fines regulated there do not apply to stewards of open source software, and that holds for every infringement of the regulation. It is one of the clearest privileges in the entire legal act.
For you as a user that means: with a wallet that arises as an open project without commercial supply, you should not count on anyone being legally obliged to notify you. With a device or an app a company offers commercially, the position is a different one, even if the source code is open. The question of who stands behind a product and how it is distributed was a good selection question before. From September 11, 2026 that question additionally has a legal side.
A duty without consequence remains an appeal. Article 64(2) sets the framework: infringements of the obligations laid down in Articles 13 and 14 are subject to fines of up to 15 million euros or, in the case of undertakings, up to 2.5 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. The reporting duty therefore sits in the highest of the three fining bands the regulation knows.
When setting the amount in the individual case, paragraph 5 requires the nature, gravity and duration of the infringement to be taken into account, along with previous fines against the same economic operator and the size of the undertaking including its market share. Microenterprises and small enterprises are expressly mentioned.
For them there is an additional relief. Article 64(10)(a) exempts manufacturers that qualify as micro or small enterprises from the fines regulated in paragraphs 3 to 9, insofar as the missed 24-hour deadline under Article 14(2)(a) or Article 14(4)(a) is concerned. The reporting duty itself does not fall away as a result, only the sanction for missing that one deadline. For a small wallet startup with three developers and no on-call rota, that is the difference between a demanding provision and an existential one.
Enforcement lies with the market surveillance authorities of the member states. In Germany, the BSI is designated for that. A fine imposed must be communicated by the authority to the market surveillance authorities of the other member states through the information system under the Market Surveillance Regulation.
Article 14 applies to all manufacturers of products with digital elements, irrespective of a risk class. Beyond that, the regulation knows two annexes that list particularly sensitive products, and their legal consequences only bite with the full start of application on December 11, 2027. A look at them is worthwhile all the same, because it shows how the legislator thinks about this type of device.
Annex IV lists three entries under the heading "Critical products with digital elements": hardware devices with security boxes; smart meter gateways as well as "other devices for advanced security purposes, including secure cryptoprocessing"; and smartcards or similar devices, including secure elements. Annex III names, in class I, among other things microprocessors and microcontrollers with security-related functionalities, and in class II tamper-resistant microcontrollers.
Those are exactly the components a hardware wallet is built from: a secure element, a tamper-resistant microcontroller, a shielded environment for cryptographic operations. Whether a particular device falls under one of these entries is again decided case by case. The direction is recognisable, though, and for manufacturers of such devices it means a stricter conformity assessment from the end of 2027, one in which a notified body can be involved.
The regulation addresses manufacturers. You do not have to act because of it. But there are four things that are more informative from now on than they were before.
You will find the official wording of the regulation in the Official Journal of the EU as Regulation (EU) 2024/2847, German-language text; Article 14 sits in Chapter II, the start of application in Article 71(2). The German reporting route including a table of deadlines is described by the BSI on its page about the CRA Single Reporting Platform.
(As of September 13, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
If you kicked off a swap through Chainflip over the weekend and nothing has arrived since, the problem is almost certainly not your wallet. The network has been at a standstill since Saturday. On September 12, 2026 an attacker drained 736,442.17 USDT through the protocol's Tron rail, and Chainflip switched off trading in response. What matters for you: your balance has not disappeared, but you cannot reach it at the moment either. This article explains what is measurably switched off, what is still running, and in which order to check your holdings.
Chainflip is a swap protocol that moves value between different blockchains. In the early hours of Saturday, September 12, 2026, an attacker drained 736,442.17 USDT from the protocol's settlement path on Tron, according to the matching accounts of two trade publications. The incident only became apparent when subsequent USDT payments failed. The team then halted network operations.
The attack ran for roughly 90 minutes. According to the account given by crypto.news, there were eight attempts, six of which resulted in a payout. The amounts escalated: on that analysis, each further attempt was roughly double the previous one. Chainflip says it has fixed the flaw, flagged the drained funds and announced that affected users will be made whole after the restart. At the time of writing, the restart was announced for Monday at the earliest.
736,442.17 USDT was drained. Only settlement on Tron is affected. A further, still open swap by one user worth 115,654.41 USDT sits unpaid in the protocol's holdings according to both sources and is considered eligible for reimbursement. For the remaining networks, neither report records any losses.
A cross-chain swap is a trade in which you deposit on one blockchain and are paid out in a different currency on another. Classic bridges solve this by locking up your bitcoin and issuing you a placeholder on the target chain, a so-called wrapped token. Chainflip works without such placeholders: a network of validators holds the funds jointly and pays out the real asset on the target chain.
For you as a user, normal operation means this: you are given a deposit address, you send your amount there, and after a few minutes the swapped asset is in your wallet on the target chain. There is no account, no sign-up and no self-custody during the process. That very design is why a standstill of the protocol affects you directly: there is no customer interface in which you could simply withdraw your funds.
On most supported networks, Chainflip reads the swap instruction from a contract call. On Tron, according to the technical account by crypto.news, it works differently: there the protocol evaluates the memo field of a transfer, a free text field that can be attached to a transaction.
On that account, the attacker attached a further memo to a transaction the validators had already signed. The system read this addition as an independent second swap instruction. When that second instruction appeared to fail, the protocol paid out a refund even though the original deposit had already been served. The core of the incident is that a signature stays valid while the readable content beside it can still be changed.
One point that appears in both reports matters for context: no private key was stolen and no custodian was opened. The payouts came out of the protocol's regular process, triggered by an instruction the protocol took to be genuine.

cryptoticker.io collected this analysis itself on September 13, 2026. Chainflip reports its network state in a public programming interface that anyone can query. We queried it between 15:53 and 15:56 UTC with seven calls, each with a logged response code, and additionally checked the provider's quote service on four swap routes.
The result is unambiguous. The section for the swap business reports three switches set to "off": swaps are switched off, deposits are switched off, withdrawals are switched off. The same applies to liquidity providers on all three counts. The provider's quote service answered with code 503 on all four routes tested, meaning "service unavailable": bitcoin to ethereum, USDC from Ethereum to USDT on Tron, the reverse direction from USDT on Tron to USDC on Ethereum, and Solana to bitcoin.
More interesting than the switched-off items is what is not switched off. The return of network shares in the funding area is set to "on". Liquidity providers may continue to adjust their quotes. Validator rotation and the registering and deregistering of bids are running. Registration of new brokers is open too.
The blockchain itself is also running undisturbed. The network node reported 36 peers and no sync in progress. Two calls of the block head 137 seconds apart returned the heights 14,801,511 and 14,801,534, so 23 new blocks and thus the usual six seconds or so per block. The network is producing; it is only not trading.
Also readable from the interface: Chainflip currently supports 18 assets on seven networks, among them Bitcoin, Ethereum, Solana, Arbitrum, Polkadot, Assethub and Tron. For Tron the minimum deposit is 30 TRX or 10 USDT.
Two limits of this measurement belong with it. First, it cannot be established from outside whether individual stuck swaps will be completed automatically after the restart. Second, the number of affected users is not measurable, and Chainflip has published nothing on it. The figure of 115,654.41 USDT for the open swap comes from the reporting and not from our query.
The state we measured is not an outage but an intended operating mode. The protocol can switch off individual functional areas without halting the blockchain. That is exactly what has happened here, and the choice of switches says something about the situation.
That withdrawals were switched off as well is the most uncomfortable part for you. It means that even a completed swap whose proceeds still sit in the protocol will not move to you at the moment. At the same time it is the measure that prevents a second drain over the same route for as long as the cause is not conclusively closed. That liquidity providers can still adjust their quotes suggests a restart of trading is being prepared rather than a wind-down of the protocol.
For your own course of action, a simple rule follows: waiting is the right move in this situation, and sending more is the wrong one. Anyone who now sends funds to an old deposit address only lengthens the list of cases that have to be worked through after the restart.
Work through the points in order. The order is not arbitrary: the first two steps cost nothing and establish whether you are affected at all.
Every swap carries its own identifier, which the interface showed you when you started it. Enter it in the provider's block explorer. It shows the state the case is stuck in: at the deposit, in the swap itself, or before the payout. If you cannot find your case there at all, it was never accepted, and the funds are still on the source chain.
Look up the transfer you deposited with in the explorer of the source chain. Two cases need to be told apart. If it is confirmed and has arrived at the deposit address, your amount sits in the protocol and you are waiting for the restart. If it is unconfirmed or was never sent, nothing has happened and you can swap elsewhere.
Look in the wallet you gave as the destination, and on the right chain. A common misconception is that the proceeds arrived long ago but the wallet does not display the target network at all. USDT on Tron does not show up if your wallet only carries the Ethereum version.
The restart date and the question of whether stuck cases will be completed automatically are decided at the provider. Stick to its own channels. In the week after an incident like this, fake offers of help asking for your recovery phrase pile up. A reputable provider never asks for it. If you want to keep your keys on your own device anyway, the devices are set side by side in our hardware wallet comparison.
The deposit addresses of a protocol like this are tied to a single swap order and valid only for a limited time. Our measurement shows that the deposit path is switched off as well. A transfer to an address from an old order is therefore not being processed at the moment.
On the blockchain, the amount is then gone from your wallet all the same. It sits at an address you do not control, and whether and when it gets assigned depends on the provider. That is why this point gets a heading of its own here: it is the one mistake that can turn a waiting period into a genuine loss.

According to the matching accounts of both trade publications, Chainflip has announced that affected users will be made whole once operations resume. The wording is clear, the path there is not: which source the reimbursement will come from was open at the time of the reports. Reserves, ongoing protocol revenue and insurance solutions are named as options under review.
For you that amounts to a promise without a date and without a procedure. So secure now what will count as evidence later: the identifier of your swap, the transaction number of the deposit, the time, the amount and, if available, a screenshot of the interface. Anyone who has to gather these records only after the restart is worse off than someone who filed them the same day.
Part of the context is also what the promise is not. It is not statutory deposit insurance. A decentralised swap protocol is not covered by the protection you know from a bank account, and a promise in an announcement is something other than an enforceable claim.
Many users never encounter protocols like this under their own name. Wallets and swap aggregators integrate them in the background and route your order to whichever path currently offers the best rate. It is therefore quite possible that you are affected without ever having consciously chosen the brand.
The proof runs through the history. Open the order history in your wallet or in the service you swapped through and look at the case in question in detail. It usually shows the route used or at least the deposit address, which you can trace further in the block explorer of the source chain. If the entry stays unclear, customer service at the service you swapped through can help, because there you are the customer.
A memo is a free text field that many chains can attach to a transfer. Exchanges have used it for years to assign incoming payments to the right customer account. For protocols it is convenient, because it works without a contract of its own and is therefore quick to connect to a new network.
The price of that convenience is that free text has no fixed form. A contract function enforces structure and can be secured together with the signature; an attached text is, to begin with, only text. The attack described here exploited exactly that gap between what was signed and what was read.
What you take from it for your own practice is independent of this provider: if a service asks you to send a memo or a tag along, that field is part of the transfer and not decoration. A deposit without the required memo regularly ends up in no man's land and has to be assigned by hand. Chainflip itself has been expanding the Tron rail lately; the most recent post on it in its own blog is dated September 10, 2026 and promotes USDT on Tron as collateral in lending. At the time of our check on September 13 the blog did not yet carry a post on the incident; according to both trade publications the quoted statements come from the short message service X.
The case fits into a series. On September 6, 2026 around 4,000 bitcoin left the Liquid Network's federation wallet, and the sidechain was subsequently missing the bulk of its backing; we recalculated the backing of L-BTC at the time. In August it was the Sandbox project's bridge. Now it is a swap protocol without placeholder tokens.
The common feature is not the design, which differs considerably in all three cases. The common feature is the place: wherever one chain has to believe another about what happened on it, a translation arises. A translation can be read wrongly, and whoever gets it read wrongly takes money out without ever having held a key.
No panic follows from that, but a sober everyday rule does: the transition between two chains is a place for short stays. Value you want to hold for longer belongs on the chain where it is at home, and in custody whose keys you control yourself. A swap protocol is a passage, not a warehouse.
Three steps, in this order, and none of them takes longer than a few minutes.
The second independent account of the incident this article draws on is at The Crypto Times.
(As of September 13, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
If you keep Zcash in a shielded address, there is a fair chance that since late July your balance has been sitting in a part of the blockchain the network has decommissioned. Checking takes a few minutes: bring the wallet up to the current version, let it sync fully, and see whether the app reports a migration in progress. While one is running, do not send your full balance anywhere.
The background is unusual. On July 28, 2026, Zcash brought a new shielded pool into service and sealed the old one at the same moment. Around 3.66 million ZEC were sitting in it at that point, the equivalent of about 1.7 billion US dollars according to CoinDesk. The network does not move that money on its own; every owner triggers the transfer in their own wallet. Anyone who has not opened their wallet since then has simply not triggered it.
The network upgrade goes by the name Ironwood and took effect at block height 3,428,143. We retrieved that block ourselves on September 13, 2026 through the public interface of Blockchair: it carries the timestamp July 28, 2026, 14:07:23 UTC. Since then the chain has been running with two shielded areas side by side, the old Orchard pool and the new Ironwood pool.
For you, none of this changes anything about your keys. You need no new address, no new seed phrase and no token swap. According to the technical specification, the key material you have been using to access shielded amounts applies equally to both pools. What changes is where your balance sits, and the route by which it gets there.
That route is called the turnstile. Every amount has to pass through it individually, and every passage is triggered by the wallet holding the funds. There is no switch in the protocol that moves all balances across at once.
A shielded pool is the part of the Zcash money supply whose amounts and participants sit encrypted in the blockchain and are readable only with the matching key. Its counterpart is the transparent area, where addresses and amounts lie open as they do with Bitcoin.
In practice you come across two kinds of address. A transparent address begins with a t and behaves like an ordinary crypto account. A shielded address begins with a z and conceals both amount and counterparty. Only the second case is affected by this migration.
Zcash has renewed its shielded technology several times over the years. Sprout from 2016 was followed by Sapling in 2018, Orchard was added in 2022, and Ironwood has existed since July 2026. Each of these stages is a pool of its own with its own bookkeeping, and balances do not move between them by themselves.
For everyday use that means your wallet can hold amounts in several pools at once without you noticing. The balance shown adds them together. Only when a pool is decommissioned does it become apparent that the total is made up of parts.
The trigger was a discovery by security researcher Taylor Hornby. As CoinDesk reported it, the proving circuit of Orchard contained a flaw that would have allowed counterfeit ZEC to be created without leaving any trace of it in the blockchain. On that account the flaw had been in the code since Orchard launched in May 2022, so for around four years.
The gap was found before it was demonstrably exploited. No damage has been evidenced so far. That, though, is exactly the problem with a weakness of this kind: a counterfeiting operation that leaves no trace also cannot be ruled out after the fact. So matters did not stop at fixing the flaw. The project rebuilt the entire bookkeeping of the shielded area from scratch.
The reasoning is set out in the specification of the upgrade. The purpose of NU6.3, it says there, is to strengthen confidence in the integrity of the Zcash money supply following the remediation of the Orchard vulnerability. The turnstile, it continues, ensures that the total supply remains bounded. Since a substantial share of all ZEC was sitting in the Orchard pool at the time of the fix, the move into a new pool was necessary.
At the core of the procedure is a reversal of the burden of proof. Everything that crosses into Ironwood through the turnstile is recorded openly and can therefore be reconciled. Whatever potentially counterfeit holdings may have arisen in Orchard stay there and do not come across.
Ironwood additionally brings a property that reaches beyond the present occasion: the specification names the recoverability of balances in the event that powerful quantum computers break today's cryptography. For holdings in the old pools, that protection expressly does not apply.

A turnstile is a crossing between two pools in which the amount being moved sits openly in the blockchain, so that anyone can reconcile the total supply. Inside a pool, amounts stay hidden. When crossing between two pools, they become visible.
How a wallet is to carry out this crossing is governed by the document ZIP 318, titled "Orchard to Ironwood Migration". It describes no button for you to press, but a schedule your wallet works through. That distinction explains most of the confusion that has grown up around the migration.
At the level of the consensus rules, something has shifted in parallel that barely shows up in everyday use but explains why the old pool is described as sealed. Since the upgrade, outputs into the Orchard pool may only go to addresses for which the creator of the transaction can authorise the spend themselves. Translated: the old pool no longer accepts payments from third parties. It can only be emptied.
The check works much the same way in every serious Zcash wallet. It costs you a few minutes and a look at the version display.
A wallet that does not know the new pool cannot move to it either. Cake Wallet, for one, introduced support for Ironwood in version 6.4.0 according to its own documentation. Check your app's version number before you do anything else. Which software is suited to which purpose at all is broken down in our comparison of software wallets.
Shielded balances are detected locally, by the wallet scanning through the blockchain. Before that sync is complete, your app does not reliably know which pool your money is in. After a longer break, this can take quite a while.
Wallets that support the transfer display it, usually as a progress indicator or as a notice in the account area. If you find nothing there and your balance is fully available, it is already in the new pool. If the app reports an operation in progress, you are one of the people who still has something in transit.
Two things should be made clear at this point, because scams form around every migration. There is no official website on which you have to enter your seed phrase to rescue your balance. And there is no support agent who will ask you to do so. The entire process runs in your wallet and without outside involvement. If you hold larger amounts, the question of custody is the more important one anyway. Our hardware wallet comparison shows which devices keep the key away from the computer.
Anyone expecting one click to be enough and the matter to be settled after two confirmations will be disappointed. The transfer drags on for hours or days, and that is by design.
The reason lies in the visibility of the turnstile. A single crossing with an odd amount would be a fingerprint by which a wallet could be recognised again over time. ZIP 318 counters that with three precautions your app implements in the background.
First, the wallet breaks your balance into fixed denominations. Permitted are amounts of the form one, two or five times a power of ten, so 100, 50, 20, 10, 5, 2, 1 or 0.5 ZEC for example. Each of these partial amounts goes through the turnstile as its own transaction and thereby merges with the partial amounts of many other users.
Then it spreads those transactions over time and draws the cryptographic anchors from network-wide uniform boundary heights. This creates groups of users whose crossings blend together. Finally, the specification separates syncing from sending: a wallet may not do both in the same background session, because otherwise an observer could connect the two.
In practical terms, that means your balance appears split for a while. Part of it is already in the new pool, part still in the old one. This is neither an error nor a loss, but the normal state during the transfer.
The transfer only makes progress while the wallet is open and synced. Close it and the transfer pauses. The specification is explicitly reserved on this point: background execution is to be attempted on a best-effort basis at most, and wallets are not obliged to send a crossing without user involvement. Anyone who opens their app once a month extends the process accordingly.
Cake Wallet's documentation expressly advises waiting with a payment until the migration is complete, and that applies particularly to any attempt to send the whole balance at once. During the transfer, parts of your balance are tied up in prepared transactions. A payment for the full amount can therefore fail or throw the schedule out of order.
This point is the one most likely to be overlooked. Under ZIP 318, a running migration need not be resumable on another device, nor after a restore from the seed phrase. A wallet that discovers unspent Orchard holdings after such a restore may treat the situation as a new migration and start over. If you want to change devices anyway, let the transfer finish first.

How much is still outstanding can be quantified. The following values come from the third-quarter 2026 report by Pine Analytics, which shows the pool holdings week by week.
In five weeks, then, around 87 percent of the old pool has taken the route through the turnstile. In the final week of August, however, only 46,000 ZEC were added. What is left is evidently not a backlog that clears itself, but a residue of wallets nobody opens.
A comparison with earlier pool changes shows how unusually quickly the field was cleared. When Sapling launched in 2018, 8 percent of the predecessor pool had moved after five weeks and 54 percent after a year. With Orchard in 2022 it was 1.2 percent after five weeks. Anyone still in the old pool today belongs to a small minority, and nobody builds tools for small minorities any more.
The price gives a sense of the magnitude. We retrieved it on September 13, 2026 via the public price interface of CoinGecko: 1,093.69 US dollars or 941.86 euros per ZEC. The 470,000 ZEC remaining at month-end therefore correspond to around 443 million euros. For context: at the time of that retrieval, Zcash stood ninth among the largest crypto-assets with a market capitalisation of a good 18 billion US dollars, after a rise of 124.6 percent over 30 days and a fall of 7.9 percent over the last seven days.
The specification names the price of the procedure openly. The turnstile, it says, discloses the amounts moving between the pools, including the amounts migrated to Ironwood. So anyone bringing their shielded holdings across publishes their size in the blockchain.
Hence the denominations. If your balance goes through the turnstile in portions of 10 or 50 ZEC and thousands of other wallets use the same portion sizes, the individual crossing says little about you. A one-off crossing of 137.42 ZEC, by contrast, is a marker that can be found again later.
From this follows a recommendation that runs against the first impulse: do not take the process into your own hands. Anyone who grows impatient and pushes their holding across in a single large transaction saves a few days and gives up in exchange the amount concealment that is the whole reason for using a shielded address.
An important point of context: the vulnerability that was found concerned the bookkeeping, not the confidentiality. According to the specification there is no reason to assume that key material of existing addresses could have been compromised by it. Your old addresses have therefore not become insecure.
If you hold your ZEC at a trading venue, you have no access to the pool in any case. There, the provider decides in what form it holds customer balances, and it carries out its own transfer if it is affected. For you that is a question of provider quality, not a task.
Two points are still worth a look. Check on your provider's status page whether deposits and withdrawals for ZEC are open before you plan a withdrawal. And check whether your provider is still listing the coin at all. Privacy coins are under regulatory pressure in the EU, which we have broken down in our overview of the planned trading ban on privacy coins. Anyone who needs a second point of access just in case will find the regulated alternatives in our comparison of crypto exchanges.
When you bring holdings from a trading venue into your own wallet, they land there transparent or shielded depending on the type of address. Shielded incoming amounts go into the new pool today. Under the changed consensus rule, the old one no longer accepts payments from others.
In the short term, nothing happens. There is no deadline in the calendar on which Orchard holdings expire, and by all accounts the transfer is voluntary and user-initiated. Nor had the project named an announced shutdown date for the old pool as at September 13, 2026.
The direction is nonetheless unambiguous, and it is stated in the specification itself. It says there that recovery would not be possible for funds still located in the Sprout, Sapling or Orchard pools; all such funds would be inaccessible once the respective protocols are shut down. They should be migrated into the Ironwood pool in order to benefit from the new property. That is the phrasing of a technical document, and it describes a state that arises if the network one day switches off the old protocols.
On top of that comes a practical point that bites sooner than any shutdown. Tools, wallets and help pages follow the majority. With a residual holding of under three percent of the shielded supply, support for the old pool does not get better but worse. Anyone who can get the transfer done today with a progress bar might have to rebuild it by hand in two years.
In passing, because it coincides in time: a coin holder vote on the shape of the next network upgrade, NU7, is currently running, with a deadline of September 14, 2026 at 19:00 UTC. How to take part in it we have described in a separate article on the NU7 vote. That process has nothing to do with the pool migration; it merely lands on the same calendar.
The technical basis of this transfer is open to inspection. The rules for wallets are in ZIP 318, the changed consensus rules and the rationale for the upgrade in the ZIP 229 document on the version 6 transaction format. Both texts are technical, but they are the source every wallet relies on.
(As of September 13, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
TRM examined roughly $52.7 million across 198.9 million settlements using the x402 protocol. Most of it isn’t coming from AI agents, it says.
The fintech company fulfilled a fraudulent information request sent from a government agency's own email domain, exposing ID documents and full crypto transaction histories for a "limited" number of users.
A week after launch, complaints are rolling in from users that GPT-6 Astra has been nerfed. OpenAI's last model went through the same cycle in July.
Ben Delo and Christopher Harborne each gave £36 million, and between them beat what every UK party raised last year.
The surveillance mod on GTA V brings the privacy fight to Los Santos, where players can demolish the cameras tracking them.
Cardano, Hyperliquid, Shiba Inu and Stellar are all testing key support zones after recent pullbacks.
Senate Democrats are holding a last-minute caucus meeting as the Clarity Act heads toward a high-stakes procedural vote that will require bipartisan support to advance.
Bitcoin locks in a historic $65,000 long-term support floor, as cycle mathematics may prevent future drops below this key threshold.
Bloomberg's Mike McGlone warns Bitcoin's tight correlation with S&P 500 and pending Fed hikes spark sell signals targeting a potential drop to $10,000.
XRP targets a 20% breakout as the tightening hourly triangle pattern nears its final apex resolution.
Oil prices jumped more than $3 a barrel at Monday’s market open after fresh strikes hit Saudi Arabia and a vessel in the Strait of Hormuz over the weekend.
Brent crude climbed to $108.23 per barrel, up 3.46%. U.S. West Texas Intermediate rose 3.15% to $103.20 per barrel. The surge reflects growing concern over supply risks from the world’s top oil exporter.
Saudi state media released footage on Sunday showing damage to homes and a mosque in the kingdom’s southern Jazan province.
Officials attributed the strike to Houthi forces operating from Yemen. The attack added to a string of incidents targeting Saudi territory in recent days.
The Houthis also claimed a separate strike on a Saudi military base in a nearby province. Saudi Arabia has faced escalating attacks from Iran-allied groups. State media reported more than 70 people injured in an earlier attack on energy facilities and civilian sites.
Away from Saudi soil, a vessel in the Strait of Hormuz was struck by a projectile on Sunday. The British maritime security agency UKMTO confirmed the incident. The strike caused a fire and forced the crew to evacuate the ship.
Iran reported a separate incident involving one of its own commercial vessels. One crew member was killed and four others were wounded off the Iranian coast. Together, the attacks highlight the fragile security situation across Gulf shipping lanes.
Oil prices had already been expected to rise Monday following last week’s drone strike on Saudi Arabia’s East-West pipeline. The drones reportedly originated from Iraq. Riyadh has not disclosed the extent of the damage or a timeline for repairs.
The pipeline can carry up to 7 million barrels of crude per day. It links Saudi production fields near the Persian Gulf to export terminals on the Red Sea coast. Saudi Aramco’s chief executive has called it central to easing supply disruptions tied to the wider Iran conflict.
A planned meeting in Oman between Gulf states and Iran, meant to address tensions in the Strait of Hormuz, was postponed.
Oman’s foreign minister cited the need for consensus following the pipeline attack. No new date has been set for the talks.
Separately, Houthi forces have reportedly advanced along Yemen’s western coast, taking the port city of Mokha and the strategic Perim Island.
The gains sit near the Bab el-Mandeb Strait, a key route linking the Red Sea to global oil markets. Analysts say continued disruption could push crude prices toward the $119.48 high reached in early March, unless diplomatic talks resume or the pipeline returns to service quickly.
The post Oil Prices Surge Over $3 as Saudi Arabia, Strait of Hormuz Face New Attacks appeared first on Blockonomi.
Litecoin whale addresses holding between $1 million and $10 million, along with those above $10 million, have dropped to levels not seen since the 2022 cycle bottom, according to on-chain analyst Joao Wedson.
The decline signals reduced large-holder participation during the current market phase. LTC trades at $53.58, up 0.18% over the past day. Separately, Grayscale has moved to convert its Litecoin Trust into a listed ETF product.
On-chain data shared by analyst Joao Wedson shows a marked contraction in Litecoin whale addresses. Wallets holding between $1 million and $10 million in LTC have thinned out considerably. The same trend applies to addresses holding more than $10 million in value.
These figures now sit close to where they stood during the 2022 market bottom. Wedson noted in a post on X that this pattern has appeared before during periods of market stress. Deep resets in previous cycles carried similar contractions in whale participation.
The analyst was careful to note that this data point does not confirm a bottom has formed. Instead, it places current whale activity near historically low readings. Reduced large-holder presence often accompanies weaker phases of a market cycle rather than stronger ones.
Address-based metrics like these track wallet balances rather than individual investors. A drop in mid-tier and large addresses suggests fewer wallets carry substantial LTC value right now.
Compared with periods when Litecoin traded at higher valuations, current large-holder representation looks noticeably thinner.
Litecoin’s official account confirmed a separate development tied to regulatory filings. Grayscale submitted an S-3/A filing with the Securities and Exchange Commission. The filing seeks to convert the existing Litecoin Trust into an exchange-traded product.
Under the proposal, the fund would be renamed the Grayscale Litecoin Trust ETF. Shares would trade on NYSE Arca under the ticker $LTCN. This filing represents an amendment to a previous registration statement submitted to regulators.
Grayscale has pursued similar conversions for other digital asset trusts in recent years. Listing on a major exchange would give investors a regulated avenue to gain LTC exposure. The filing still requires review and approval before any shares reach the market.
Meanwhile, Litecoin’s spot price stood at $53.58 at the time of writing. Trading volume over the past 24 hours reached $214,552,110 across exchanges. The asset posted a 7-day gain of 0.60%, alongside its modest daily increase.

Source: Coingecko
Combined, both developments paint a picture of a market working through mixed signals. Whale addresses point to caution among large holders. The ETF filing points to continued institutional interest in Litecoin as an asset class.
The post Litecoin Whale Addresses Sink to 2022 Lows as Grayscale Files LTC ETF appeared first on Blockonomi.
The Sui price trades near $0.72 as analyst Ali Martinez identifies a TD Sequential buy signal on the 12-hour chart. CoinMarketCap lists SUI at $0.7187 at the latest reading, with a 24-hour range between $0.7063 and $0.7305. Martinez says the indicator previously preceded a 17% rally and a shift in momentum.
The Sui crypto price tests the $0.71-$0.73 support area after the signal. A break below $0.71 could expose $0.62-$0.63. A recovery toward $0.85 could place $1 back in focus. The setup combines a bullish indicator with supply and leverage risks across the Sui market.

Ali Martinez describes the TD Sequential as relatively accurate at identifying major trend shifts in SUI’s recent 12-hour chart history. He says the previous SUI buy signal appeared after a 17% rally and anticipated the next momentum change.
TD Sequential tracks price sequences to identify possible trend exhaustion. A completed buy setup can point to a reversal, but it does not confirm a new trend.
The Sui price now tests the lower boundary of a key trading area. Ali Charts places support between $0.71 and $0.73. A daily close below $0.71 could open a path toward $0.62-$0.63.
An earlier Ali Charts post described SUI as moving inside a channel with a lower boundary near $0.71. That post placed the upper channel target near $0.84.
Michaël van de Poppe also suggests the support could retest to hold. He says a recovery toward $0.85 could place levels above $1 back into focus.
SUI’s market structure adds another risk factor. The analysis reports futures activity exceeding spot trading. That pattern can amplify moves through liquidations when leveraged positions unwind.
The indicator points to a possible reversal, while support decides whether buyers defend the setup.
Regulated market access has expanded through the 21Shares Sui ETF, which trades on Nasdaq under the TSUI ticker. The product provides spot SUI exposure and may stake part of its holdings.
21Shares began TSUI trading on February 24, 2026. CME Group also lists SUI and Micro SUI futures after launching the contracts in May.
These instruments create routes for institutional exposure, hedging, and price discovery. They do not confirm sustained inflows, and no latest ETF flow figures appear in the analysis.
The ETF offers exposure without direct wallet custody. That broadens the set of market participants tracking SUI.
Network activity provides a separate growth measure. Sui surpassed 16.17 billion lifetime transactions by September 13. Its stablecoin market capitalization also moved above $457 million.
DeFiLlama currently lists Sui stablecoins at $463.67 million, up 8.85% over seven days. According to DeFiLlama data, the total DeFi TVL is at $457.13 million.

Stablecoin growth can support trading activity and collateral demand. It does not guarantee lasting token demand; capital can leave quickly during market stress or shift toward other competing networks.
USDC accounts for about 63.88% of the stablecoin market capitalization. Other assets include Sui Dollar, FDUSD, BUCK, USDY, suiUSDe, and USDT.
That concentration leaves the network’s liquidity profile heavily tied to one asset. The current figures show USDC carrying most of the stablecoin balance.
Supply growth pressures the Sui price. Monthly unlocks of roughly 64 million SUI add tokens to circulation. The analysis also flags declining DeFi TVL as a pressure point.
The Sui price must absorb fresh supply while network liquidity and institutional access develop. CoinMarketCap lists a 10 billion maximum supply and a circulating supply near 4.09 billion.
Futures leverage adds another variable to the near-term chart. A daily close below $0.71 would put the $0.62-$0.63 range back into focus.
The post Sui Price Shows Fresh Buy Signal as Network Growth Meets Unlocks appeared first on Blockonomi.
Crypto mining operations are increasingly becoming tools for organized crime in Latin America, according to blockchain analytics firm Chainalysis.
Mexican authorities recently uncovered a suspected illicit crypto mining site in the mountainous Tlaola area of Puebla state, seizing hundreds of graphics processing units, medium-voltage terminals, and satellite antennas.
The discovery marks the fourth similar operation found in the region since early 2025. It points to a growing pattern of criminal groups exploiting virtual currency mining for financial gain.
Authorities in Puebla state found the crypto mining farm tucked into the lush, remote mountains of the Sierra Norte region. The site held 300 graphics processing units, 80 medium-voltage terminals, and eight satellite antennas.
These tools were built to compete against other machines worldwide to solve puzzles and generate new coins. Officials are now investigating whether the operation stole electricity from a nearby hydroelectric dam to power its equipment.
Security analyst David Saucedo said the operation showed “drug cartels appear to have reached a new level of sophistication.”
He noted that only a well-funded group, such as one of Mexico’s major cartels, could likely back such infrastructure. Mexico’s federal attorney’s office declined to comment, citing an ongoing investigation.
Residents living near the site told Reuters they could hear the mechanical whirring from roughly one kilometer away. The crypto mining farm sat about twice that distance from the nearest village.
Three other similar sites were found last year close to the same hydroelectric dam in northern Puebla. Local authorities are now working with neighboring states to check for further hidden mining operations nearby.
Illicit cryptocurrency transactions worldwide more than doubled in 2025, reaching an estimated 154 billion dollars. That figure is up sharply from 59 billion dollars the previous year, per Chainalysis data.
The firm linked much of this jump to a rise in transactions tied to sanctions evasion, including payments connected to sanctioned governments and their networks.
Caio Motta, Chainalysis’s Latin American specialist, said cartels often target areas with cheap electricity or organized crime influence. This allows groups to steal power outright and build large crypto mining infrastructure at minimal cost.
Electricity remains the largest expense in crypto mining, and energy prices continue climbing each year. The University of Cambridge’s Bitcoin Electricity Consumption Index puts the cost of minting one bitcoin near 45,000 dollars. At current prices near 78,000 dollars per coin, that still leaves a wide profit margin for operators.
Similar crypto mining raids have occurred in Brazil, the United States and Southeast Asia, including a large operation across five Thai provinces.
Motta expects crypto-related crime to keep climbing as virtual currencies become easier to access globally. Still, he added that law enforcement agencies are steadily improving their ability to trace and disrupt these illicit networks.
The post Crypto Mining Becomes Cartels’ New Weapon for Laundering Illicit Funds appeared first on Blockonomi.
Is the Bitcoin 4-year cycle broken? That question is gaining traction as this cycle unfolds differently from the last three. Previous cycle bottoms in 2012, 2016, and 2020 formed between day 770 and 900 after halvings, per CryptoQuant data.
This time, Bitcoin posted a fresh all-time high before the halving even occurred. That early move has left traders divided on whether the historical rhythm still holds or has finally given way.
Spot ETF approvals opened the door for large institutional inflows ahead of the halving. Institutional allocators typically base decisions on monetary policy, interest rates, and broader liquidity.
They do not track days elapsed since a halving event. This approach differs sharply from the retail-driven cycles seen in 2012, 2016, and 2020.

Source: Cryptoquant
The halving’s supply shock also carries less weight than it once did. Newly minted coins represent a small fraction of daily volume moving through derivatives and major funds.
In earlier cycles, reduced issuance visibly affected available supply. Today, that effect is diluted by the much larger pool of tradable Bitcoin in circulation.
Bitcoin’s market capitalization has grown into trillion-dollar territory, changing what it takes to move the asset. Shifting a market of this size now requires substantial liquidity across global markets.
Aggressive monetary easing, a factor behind past rallies, has not appeared recently. Without that liquidity push, price momentum may build more slowly than before.
These shifts raise a real question about whether counting days after a halving still applies. Some observers argue Bitcoin increasingly resembles a mature macro asset tied to broader financial conditions.
The four-year model may not be dead, but its timing looks disrupted. Many are now watching macro indicators instead of a historically timed bottom.
The question has extended beyond analysts into wider social media discussion. A post from the account Discover on X argued Bitcoin may have already broken its cycle. The post suggested the bottom formed roughly 650 days before the next scheduled halving.
That timeline, if accurate, would open room for a new all-time high before the 2028 halving arrives. The post also floated the idea that the next cycle top could arrive only around 350 days after that halving. Such a timeline would differ sharply from the multi-year gaps seen in previous cycles.
Rather than treating the four-year cycle as finished, the post framed the pattern as compressing. Under that view, each stage of the cycle would happen closer together in time. This would depart from the roughly four-year spacing seen between past bottoms and tops.
Whether the cycle is broken or simply compressed remains an open question. Historically, major rallies have followed halvings rather than preceded them.
Market participants are watching whether coming months confirm a compressed timeline or the traditional four-year rhythm.
The post Is Bitcoin’s 4-Year Cycle Broken? Analysts Question the Old Halving Pattern appeared first on Blockonomi.
The Justice Department’s Scam Center Strike Force, working with the Treasury Department, seized a Chinese-language scam marketplace called Xinbi Guarantee and restrained about $52 million in cryptocurrency in a single day, U.S. Attorney Jeanine Pirro announced this week. That operation brought the total the Strike Force has restrained since its founding to roughly $938 million.
A separate Strike Force team also spent the same stretch helping authorities in Madagascar take down 13 Chinese-run scam compounds, pushing the crackdown launched last November well beyond its original footprint in Southeast Asia.
Xinbi ran almost entirely on Telegram, in Chinese, functioning as a kind of marketplace where vendors advertised services to scam center operators: building custom fraud investment websites, “washing” money stolen through wire fraud, and recruiting trafficking victims to staff scam compounds.
Xinbi itself held payments in escrow until a vendor finished the job, which is how prosecutors say they were able to trace specific victim funds to vendors who posted wallet addresses on the channel. A federal court in Washington authorized the seizure of those Telegram channels on September 7, and prosecutors unsealed the warrant Wednesday.
Investigators seized two crypto wallets Xinbi used to collect vendor payments, worth roughly $12 million, and sought restraint of 47 more wallets tied to the network, bringing the total taken from the platform and its vendors past $52 million.
The Treasury’s Office of Foreign Asset Control (OFAC) separately designated Xinbi a transnational criminal organization the same day, along with two other entities accused of supporting it, freezing any property they hold in the U.S.
Pirro said the case shows why ordinary people are at risk:
“Every American with a retirement account is in the blast radius,” she stated. “My Strike Force will continue to dismantle Chinese organized crime, those who facilitate it, and protect Main Street America.”
Alongside the Xinbi action, U.S. Attorney Michael Heyman of Alaska said the Strike Force’s two-week Madagascar deployment, which helped process more than 3,200 devices and interview about 400 people who had been arrested, reflects where the fight is headed.
“Transnational criminal organizations don’t care about borders, and the Department of Justice won’t either,” he said.
In March, the British government sanctioned Xinbi, with Chainalysis estimating the platform had processed nearly $20 billion in crypto between 2021 and 2025, selling everything from stolen personal data to satellite equipment used to reach fraud victims.
That earlier action barely slowed it down, with the criminal group simply opening new Telegram channels and continuing with its operations. The Strike Force itself dates to November 2025, when Pirro set it up to go after Chinese organized crime running scam centers.
Federal data cited in Wednesday’s announcement put reported crypto investment fraud losses at $8.65 billion in 2025, up 89% from $4.57 billion in 2023, although the FBI says the figures are “significantly under-represented,” since most fraud victims do not report.
The post DOJ Strike Force Seizes Scam Marketplace, Restrains $52M in Crypto appeared first on CryptoPotato.
Bitcoin is consolidating around $77.3K after a powerful breakout from the $67K area. While the broader structure has improved significantly, BTC is now facing an important resistance cluster near $80K-$82K. Meanwhile, the latest Coinbase Premium reading suggests that US spot demand has yet to fully confirm the recent advance.
The daily chart shows a significant structural recovery. After falling to the $60K demand zone in June, Bitcoin spent several months building a broad base before breaking decisively above the $67K resistance area in late August. The subsequent rally carried BTC rapidly through the $72K-$74K zone and toward the $80K area.
The $72K-$74K region has now become the first major support zone. A successful retest of this area would preserve the bullish structure established by the recent breakout. Below it, the $67K zone is a more important structural support, as it previously capped the market for several months. A deeper correction could bring the $60K demand zone back into focus.
On the upside, BTC is approaching the $80K-$82K resistance zone. The price has already tested this area several times but has failed to establish a sustained breakout above it. A daily close above $82K would therefore be significant, as it could open the way toward the $90K mark or even higher.

The 4-hour chart provides a clearer view of the latest move. Bitcoin spent much of the summer trading sideways between roughly $60K and $67K before staging a sharp breakout. The move through the $67K resistance zone accelerated dramatically, taking BTC through $74K.
After reaching the $80K-$82K area, however, the rally has lost momentum. BTC is currently trading around $76.8K and has formed a relatively broad consolidation below resistance. This can be interpreted as a potential continuation range following the breakout, provided the lower boundary remains intact.
The immediate support is located around the same daily $72K-$74K zone. This area is particularly important because it represents the previous resistance zone that BTC cleared during the breakout. Holding it would maintain the sequence of higher highs and higher lows on the 4-hour timeframe.
The main resistance remains $80K-$82K. A clean breakout and sustained trading above this zone would signal that buyers are regaining control and could bring the next major daily resistance around $95K into consideration. Conversely, repeated rejection followed by a break below $72K could trigger a deeper retracement toward $67K.

The Coinbase Premium Index provides an important caveat to the technical picture. The metric measures the price difference between Bitcoin on Coinbase and other major exchanges and is commonly used as a proxy for US-based spot buying pressure. Positive readings generally indicate stronger demand on Coinbase, while negative readings suggest comparatively weaker US spot demand.
The latest reading on the chart is around -0.02, with the index back in negative territory. This is notable because BTC has simultaneously remained well above the levels seen before the late-August breakout.
The divergence suggests that the recent price strength has not been accompanied by a sustained surge in Coinbase buying pressure. In other words, while the technical structure has improved, the latest premium data does not yet provide strong confirmation of aggressive US spot accumulation.
Historically, within the period shown, the Coinbase Premium spent considerable time below zero during BTC’s decline toward the $60K area, while stronger positive readings appeared during several recovery phases. The current negative reading, therefore, warrants some caution as Bitcoin approaches the $80K-$82K resistance zone.
For the bullish scenario to strengthen, a renewed move of the Coinbase Premium into positive territory alongside a breakout above $82K would provide more convincing confirmation. If BTC instead loses $72K while the premium remains negative, it would increase the probability that the recent rally is undergoing a deeper correction rather than immediately transitioning into another leg higher.

The post Bitcoin Price Analysis: BTC Faces a Make-or-Break Week – What’s the Most Likely Scenario? appeared first on CryptoPotato.
Although the upcoming vote on the Digital Asset Market Clarity Act is not a final passage vote, it still holds significance for the broader crypto market as senators will decide whether to advance debate on the legislation. Cloture requires 60 votes, meaning that even if all Republicans support it, they would still need assistance from some Democrats or independents.
XRP could be among the most intertwined crypto assets with the bill, which is why a potential failure could weigh on its price quite considerably. As such, we asked ChatGPT about its take on the matter and what could happen to the cross-border token.
The bill aims to create a comprehensive federal crypto market structure, including clearer responsibilities for the two main watchdogs – the SEC and the CFTC, and rules for exchanges, brokers, dealers, and digital commodities. This is particularly relevant for the cross-border token following Ripple’s years-long regulatory battle with the SEC.
After the conclusion of the lawsuit that began in late 2020, the regulator identified XRP as a digital commodity. As such, the legislation would make the broader regulatory framework more durable by codifying it into federal law, since history has shown that the SEC’s allegiance shifts quickly with each new administration.
Overall, even though a failure on the CLARITY Act’s vote next week would remove a potential bullish catalyst, it wouldn’t erase all of XRP’s regulatory progress experienced in the past year and a half.
From a technical standpoint, XRP is currently near $1.40, above the key support at $1.34-$1.35, but it hasn’t reclaimed the crucial resistance at $1.40. If cloture fails but BTC and the broader crypto market remain stable, ChatGPT envisioned a 7% to 10% initial reaction for Ripple’s token, which would materialize with a dip to $1.20-$1.25.
A more aggressive selloff could drive the asset south toward $1.10, especially if markets interpret the result as evidence that comprehensive US crypto legislation could be delayed well after the midterms.
The dark horse comes a day later, when the Federal Reserve will conclude its September 15-16 FOMC meeting. A failed CLARITY Act vote followed by a hawkish Fed decision could turn an XRP-specific regulatory disappointment into a broader crypto selloff. In that scenario, the AI platform predicted a more painful decline toward $1.00.
On the plus side, ChatGPT said a lack of progress on the CLARITY Act alone wouldn’t be as strong a catalyst to drive XRP below $1.00.
The post What Happens to XRP if the CLARITY Act Vote Fails on September 15? AI Maps the Downside appeared first on CryptoPotato.
Inflation is heating up again, as evidenced by the PPI data that came out on Thursday. Treasury yields are approaching 5%, and the US government is trying to stabilize the bond market while proposing another trillion-dollar stimulus program.
The immediate implications for bitcoin are bearish. However, the longer-term picture is considerably more complicated.
August producer prices rose 5.4% year-over-year, which was just slightly over expectations. At the same time, Brent crude jumped past $100 this week as the situation in the Middle East sees no actual improvement and supply disruptions continue. The probability of a rate hike after the conclusion of the FOMC meeting on September 16 is over 70%, according to futures markets and some prediction platforms.
The 10-year Treasury yield climbed to just under 5%, despite the Treasury’s ongoing efforts to improve liquidity in long-dated government debt. Higher yields typically mean tighter financial conditions, a stronger incentive to hold relatively safe government debt, and, unfortunately for the bitcoin bulls, less appetite for speculative assets.
This helps explain why BTC’s initial rally that drove it from under $65,000 to $82,000 hit a brick wall, and the asset has been unable to push through in the past few weeks. However, that’s only half the story.
As previously reported, the Treasury initially doubled the long-term buybacks from $2 billion to at least $4 billion per operation on August 19, which triggered the first BTC leg up. At the same time, long-term yields immediately dipped, and the dollar weakened.
The Treasury Department went a step further earlier this week, increasing the purchases to $6 billion. Now, though, there’s President Trump’s proposition to give every American adult $5,000 if Republicans retain control of Congress in November. According to estimates, this could cost somewhere between $1.20 trillion and $1.35 trillion and would require congressional approval.
The analysts at the Kobeissi Letter described this as an “unprecedented” situation. We have inflation remaining too high for the Fed to ease monetary policy, while massive deficits and rising interest costs are simultaneously creating pressure for lower borrowing costs.
The Kobeissi Letter argued that these forces will favor asset owners and specifically pointed to BTC, gold, and stocks. However, this doesn’t guarantee that BTC will automatically thrive in the current economic structure. In fact, the path forward could be painful at first.
If inflation keeps rising and the Fed responds with additional rate hikes, BTC could face more pressure as yields climb. The bullish narrative emerges later if fiscal stress eventually forces policymakers toward heavier intervention, looser financial conditions, or policies that expand normal spending.
The post US Bond Market Is Flashing a Major Warning: Is This the Setup Bitcoin Was Built For? appeared first on CryptoPotato.
Ripple veteran David Schwartz recently said quite convincingly that XRP could eventually overtake bitcoin by market capitalization. However, he outlined the significance of the right conditions and that such a development wouldn’t come from BTC’s deterioration.
As such, we decided to go a bit deeper into the numbers and see what actually has to happen for Ripple’s token to emerge ahead of the current market leader.
The cryptocurrency community has long been dabbling with the question of whether (at least) one altcoin can replace BTC as the largest digital asset by market cap. For almost a decade, that alt representative was Ethereum (ETH), which didn’t exactly come close several years ago, but there was speculation about a potential Flippening. However, it never materialized.
The focus has now switched to Ripple’s XRP. During a recent X Spaces discussion, longtime Ripple exec and XRP Ledger architect David Schwartz said he believes it’s possible for the cross-border token to surpass BTC in terms of market cap. Moreover, he noted that such a wild scenario wouldn’t transpire because bitcoin had collapsed; instead, he argued that it would unfold under significantly different conditions.
At first, the broader crypto market would have to be dramatically more successful. Second, XRP would grow considerably faster than BTC due to the XRP Ledger’s functionality, adoption, and real-world usage.
Let’s go directly to math and see where the issue stems from, as the numbers are daunting at current prices. BTC’s market is at about $1.55 trillion today, compared with approximately $87 billion for XRP. This makes the market leader around 18 times larger.
If we presume that bitcoin’s valuation remains unchanged, XRP would need to climb toward a $1.55 billion market cap simply to level the playing field. At today’s circulating supply, that would imply a mind-blowing surge to $24-$25 from the current $1.40 levels.
Schwartz’s scenario makes that hurdle even bigger, as he doesn’t believe BTC will remain stagnant. Instead, he noted that the entire crypto market could expand exponentially, meaning that BTC would most likely continue appreciating as well.
It’s worth noting that XRP has actually been closer to BTC in the past. A lot closer. And still couldn’t do it. Back in early 2018, XRP’s market cap had risen to $120 billion as the asset rocketed to its then-ATH. BTC’s market cap, on the other hand, was a more modest $250-$260 billion.
In other words, XRP was worth almost 50% as much as BTC at the time. Today, that ratio is down to 5%-6%, which makes Schwartz’s scenario even harder to materialize. But then again, nothing is impossible, right?
The post Could XRP Actually Flip Bitcoin? Former Ripple CTO Says Yes – But the Math Is Brutal appeared first on CryptoPotato.