ChainGPT's advanced AI model scans the web and curates short articles on Bitcoin (BTC) every 60 minutes, informing you effortlessly. https://www.ChainGPT.org
Flock's Bid to Turn 350K Cars into License-Plate Scanners Stokes Privacy Fears
Flock Safety once pitched a plan to turn hundreds of thousands of civilian vehicles into a roving network of license-plate scanners — a proposal that exposes how quickly private surveillance can scale and why privacy advocates are sounding the alarm. What Flock proposed - In a presentation prepared for Georgia’s Attorney General and later obtained by 404 Media, Flock outlined a partnership using dashcams from Nexar — a company whose cameras already sit in “hundreds of thousands” of vehicles — to scan license plates from moving Uber, Lyft, and delivery cars. - The idea was to supplement Flock’s existing pole-mounted cameras (which log plate, color, make, and model to build searchable travel maps) by “untethering” that capability: instead of one fixed camera per intersection, some 350,000 cars would carry cameras and sweep gaps between stationary sites, tracking plates across regions in near real time. - Flock says it never actually launched the Nexar deal. Still, the document reveals the company’s ambitions to extend its ALPR (Automatic License Plate Recognition) footprint far beyond stationary deployments. How this fits the market - Roaming plate-reading isn’t unique to Flock: Axon offers systems for police cruisers, and vendors such as Motorola’s DRN and Vigilant provide similar capabilities via repossession or enforcement drivers. Flock’s pitch was to scale that roaming model to everyday civilian fleets. Company scale and controversy - Flock reached an $8.4 billion valuation in April and claims its pole cameras now cover more than 5,000 U.S. communities. But the deployment landscape is volatile: cameras have provoked protests, vandalism, and heated debates about surveillance and civil liberties. - The pushback has tangible consequences. In July, the LAPD allowed its Flock contract to expire, citing “serious concerns” about privacy and civil liberties. CNN has documented multiple cases in which officers allegedly abused access to Flock’s plate database. Political and legal resistance - The controversy has escalated beyond local pushback. The privacy nonprofit EPIC urged Congress to ban ALPR technology outright. States are acting: Washington passed SB 6002 restricting ALPR use, and California is considering limits on how plate data can be shared. - Federal scrutiny is also rising: Flock deployments on federal buildings drew opposition, and Rep. Thomas Massie said he planned to sponsor a bill to withhold federal funds from municipalities or police departments that use Flock-style cameras to surveil law-abiding citizens. - On the courts front, a federal judge allowed a Norfolk lawsuit alleging Flock’s cameras violate the Fourth Amendment to move forward, invoking the Supreme Court’s Carpenter precedent on warrantless tracking. Why crypto readers should care - Mass-scale plate-reading builds dense location graphs about millions of vehicles — highly sensitive mobility datasets that can be monetized, misused, or combined with other identity-linked data. For a community focused on privacy, decentralization, and data sovereignty, the Flock-Nexar blueprint is a reminder of how quickly private infrastructure can aggregate behavioral metadata at scale and why guardrails, transparency, and technical alternatives matter. Bottom line Flock’s Nexar pitch may not have launched, but the plan lays bare the company’s appetite to expand civilian-scale surveillance. As state lawmakers, federal officials, and courts push back, the debate around ALPR technology will be a bellwether for how the U.S. balances public safety tools against privacy, accountability, and the commercial incentives to harvest location data. Read more AI-generated news on: undefined/news
Tokenized RWAs Surge as DeFi Slows — Deposits Triple to $7.4B, Perps Now ~25%
Tokenized real-world assets (RWAs) are surging on-chain even as broader DeFi activity cools, according to a new joint report from CoinShares and Token Terminal. Key takeaways - Deposits of tokenized RWAs into decentralized lending platforms and exchanges more than tripled over the past year, rising from $2.3 billion to $7.4 billion. Over the same period, total deposits across DeFi fell by about 15%. (Report: The Growth of Hybrid Finance, covering Q2 2025–Q2 2026; data supplied by Token Terminal.) - Spot trading on decentralized exchanges (DEXs) broadly declined by ~70%, while spot volumes in tokenized RWAs jumped roughly 220%. - On perpetual futures venues, both trading volume and open interest in RWAs continued to climb despite a wider slowdown that began in October 2025. RWA positions now represent more than one-quarter of on-chain perpetuals open interest. What’s moving on-chain - The largest share of RWA deposits are tokenized Treasuries and multi-strategy funds (examples cited: JTRSY, BUIDL, sUSDS). Next come private-credit products (JAAA, syrupUSDC, PRIME) and delta-neutral strategies such as sUSDe. - Tokenized gold leads spot trading volume. Perpetuals activity is concentrated in oil and precious metals, the S&P 500 and Nasdaq-100, and tech and semiconductor stocks. Where the activity lives - Nearly 70% of RWA deposits sit on lending venues built on Ethereum. “Plasma” (a layer or chain referenced in the report) is the second-largest sector, helped by Aave’s expansion beyond Ethereum. Solana’s RWA growth has been driven largely by native lending platform Kamino. - Deposit activity remains concentrated on Aave, Morpho and Kamino. Revenue and adoption - Despite rising deposits and trading in RWAs, application revenues across lending and trading platforms fell year-over-year — evidence, the report says, of an early stage of adoption. - Hyperliquid is a notable exception: it produced substantially more application revenue than any other trading or lending venue and has overtaken Solana and Ethereum as the top revenue-generating chain. Decrypt previously reported that RWAs outpaced crypto on Hyperliquid for the first time in a single week, with chipmaker SK Hynix the most-traded stock that week. Context and industry response - This split between tokenized RWAs and traditional DeFi isn’t new. In February, tokenized RWAs grew 8.7% in a month to $24.8 billion while DeFi’s total value locked (TVL) fell 25% to $94.8 billion — a rotation industry insiders like 1inch co-founder Sergej Kunz attributed to compressed DeFi yields versus roughly 4% available on tokenized Treasuries. - Institutional interest is evident: BlackRock’s BUIDL fund appears among the named products in the report. BlackRock also launched two additional tokenized money-market funds and then rolled out tokenized share classes for European money-market funds that together hold $311 billion. Scale and scope - Tokenization remains modest relative to global markets: roughly $2.2 billion of a global equity market worth more than $100 trillion has been tokenized — a penetration the report likens to stablecoins around 2019. - The analysis covers distributed assets only — assets that can be moved to wallets outside the issuing platform — excluding some networks such as Canton and Provenance. Why it matters The report frames a growing “Hybrid Finance” landscape where traditional financial products are being bridged on-chain and are finding real use — particularly in fixed income, commodities and equity derivatives — even while crypto-native activity softens. That divergence could reshape where liquidity and revenue accrue as institutional-grade tokenized products scale. Read more AI-generated news on: undefined/news
Chainalysis: Crypto Crime Turns Physical - Kidnappings and Home Invasions Surge
Headline: Crypto crime is going physical — kidnappings, home invasions and real-world coercion are rising, Chainalysis warns Chainalysis says the crypto underworld is moving off the screen and into the streets. In its latest report, the blockchain analytics firm warns that violent crime — including kidnappings, home invasions and hostage situations — is increasingly being used to force victims to transfer digital assets that can be moved instantly under duress. Big picture: cyberdrama still dominates, but violence is growing - Cybercrime remains the largest portion of illicit crypto activity: in 2025 Chainalysis estimates about $3.4 billion stolen in hacks, $17 billion lost to scams and roughly $820 million tied to ransomware. - But physical attacks are on the rise because many crypto holders custody large sums themselves (self-custody wallets) and lack the institutional protections traditional financial assets enjoy. The scale of violent theft - Chainalysis estimates violent criminals extracted more than $30 million from crypto holders in the first half of 2026 through kidnappings, hostage situations and home invasions. If that pace holds, 2026 would exceed the $58 million taken in 2025. These figures only reflect publicly reported incidents and likely understate the total. Context: digital exploits remain lucrative - The report cites a separate Galaxy Research estimate showing confirmed losses from the Coldcard hardware wallet vulnerability totaled 1,596 BTC across three waves, with a suspected fourth wave potentially bringing the total to about 2,055 BTC if verified. That episode — a software flaw rather than a physical attack — underscores why criminals continue to target crypto through both digital and real-world means. Attack success and value recovered - Although documented violent attacks have become more frequent, they’re getting less effective. Through late June 2026, only 12 of 46 documented violent theft attempts led to victims surrendering funds — a 26% success rate, down from 49% in 2025 and 67% in 2024. - When failed extortion, blocked transfers and recovered assets are included, Chainalysis puts the value connected to violent incidents at roughly $107 million in H1 2026. How attackers move stolen crypto Chainalysis grouped attackers into three operational tiers: 1. Novices — often transfer stolen funds directly to centralized exchanges, making them easier to trace and intercept. 2. Intermediate operators — route funds through decentralized exchanges, bridges and intermediary wallets to complicate tracing before cashing out. 3. Professionalized networks — route funds through instant exchanges and suspected over-the-counter laundering services. In one case, stolen funds were linked (as blockchain exposure, not proof of involvement) to entities with previous ties to cartel-related laundering, wallets associated with an alleged trafficker, terrorist financing clusters and Southeast Asian laundering networks. Shifts in tactics and targets - Kidnappings still make up most “wrench attacks,” but home invasions have climbed sharply — rising from 14% of documented incidents in 2025 to 37% through mid-2026. Chainalysis suggests criminals favor home invasions because they can exert pressure in a victim’s familiar surroundings without moving them. - Attackers are also increasingly targeting relatives and acquaintances to coerce transfers: family or close relations accounted for roughly 25–30% of incidents by early 2026, versus being nearly absent in 2021. In France, more than 40% of incidents involved someone connected to the holder rather than the holder directly. Geography: France stands out, U.S. sees many home invasions - France has recorded the highest number of publicly known violent crypto incidents since 2023: 30 cases through mid-2026 versus 19 in all of 2025. Interior Minister Laurent Nuñez said authorities documented more than 70 crypto-related violent incidents and introduced a rapid identification and alert system for those at risk. - Chainalysis points to an alleged 2024 theft and sale of tax records for high-net-worth crypto holders — dossiers that reportedly contained names, addresses, holdings, phone numbers and tax information — as the most likely driver of France’s spike. The report also cites Waltio’s January 2026 disclosure of unauthorized access affecting about 50,000 users’ data, while stopping short of asserting a direct causal link to individual attacks. - Regional victim patterns show most targets are local residents rather than visitors: documented victims were 100% local in Sweden, 93% in France, 82% in Brazil and 77% in the U.S. Chainalysis interprets this as evidence of advance reconnaissance using leaked data, blockchain activity, social media or insider information. Law enforcement response in France - French authorities have framed the incidents as organized crime investigations; by mid-2026 the crackdown had produced roughly 200 arrests, 88 indictments, 75 suspects held in pretrial detention and more than a dozen ongoing investigations. Why blockchain data still matters - Chainalysis notes a paradox: every coerced transfer leaves a blockchain trail investigators can analyze. That traceability has helped classify attacker behaviors and, in many cases, enabled law enforcement and compliance teams to catch or disrupt cash-outs — particularly when criminals make amateur mistakes like sending funds to centralized exchanges. Bottom line Crypto crime remains heavily digital, but the industry’s migration toward self-custody and the instant-transfer nature of digital assets have created new incentives for violent, real-world coercion. Chainalysis’ findings highlight evolving attacker techniques, shifting regional patterns — and the continued importance of on-chain analytics and coordinated law enforcement responses to disrupt both online and offline threats. Read more AI-generated news on: undefined/news
Trump Media, Crypto.com & Yorkville Cancel CRO Treasury Deal, Drop Truth Predict
Headline: Trump Media, Crypto.com and Yorkville Scrap CRO Treasury Plan — Pivot Away From Prediction Markets Too President Trump’s Trump Media & Technology Group has abandoned a high-profile digital-asset tie-up with Crypto.com and SPAC partner Yorkville Acquisition Corp., terminating plans to launch a publicly traded CRO treasury company and related services, Axios reports. What happened - The three parties mutually agreed to end the proposed “Trump Media Group CRO Strategy,” a previously announced services agreement and other related digital-asset products, blaming “prevailing market conditions” and “shifting business and stakeholder priorities.” - The initiative would have licensed the Trump Media brand to a vehicle built around Crypto.com’s Cronos blockchain and the Cronos token (CRO), and aimed to become the first and largest publicly traded CRO treasury by accumulating CRO tokens and seeking returns from those holdings. Why they walked away - Interim Trump Media CEO Kevin McGurn told Axios the company is narrowing its focus after the market for digital-asset treasury firms became “increasingly crowded.” He also said staking has become less central to Crypto.com’s strategy, reducing the project’s attractiveness. - Trump Media is also dropping plans to integrate a Crypto.com-powered prediction market directly into Truth Social (previously announced as “Truth Predict”). Instead, the parties will pursue a marketing arrangement to promote Crypto.com’s prediction-market products to Truth Social users; McGurn called that sector “crowded” and less compelling for direct investment. Market reaction and numbers - CRO fell sharply on the news and is trading around $0.05, with an approximate market capitalization near $2.4 billion at the time of reporting. Background timeline - October 2025: Trump Media announced plans for Truth Predict, a prediction market powered by Crypto.com. - December (following months): The firms unveiled plans for a publicly traded CRO treasury with Yorkville Acquisition Corp., intended to hold billions of CRO tokens. - February: Crypto.com disclosed it donated $35 million over the prior year to the pro-Trump super PAC MAGA Inc. The month also saw the Office of the Comptroller of the Currency conditionally approve Crypto.com’s application for a national trust bank charter. Political and regulatory context - The widening business relationship between Trump-related companies and Crypto.com has drawn heightened political scrutiny. Democrats have criticized the expansion of Trump’s crypto ventures, and earlier this week Senators Elizabeth Warren and Richard Blumenthal asked the SEC to investigate President Trump’s meme coin to determine whether it facilitated fraud or unjust enrichment — part of broader Democratic oversight ahead of November’s midterms. What it means - The collapse underscores two trends: investor and corporate caution around tokenized treasury strategies amid a crowded field, and a shift by some exchanges away from staking-heavy business models. For Trump Media, the change represents a move from operating crypto products to acting as a distribution and marketing partner — a lower-capex, lower-risk approach. For Crypto.com, the termination removes a branded on-chain treasury use case but maintains a route to reach Truth Social users via marketing rather than a joint product. We’ll monitor any further corporate statements and price movements as the parties formalize the termination and outline the new marketing deal. Read more AI-generated news on: undefined/news
AI Blanket Maps Kalshi Event Contracts to Help Small Businesses Hedge Operational Risks
Kalshi’s regulated event markets are getting a new use case: powering an AI tool that helps small businesses spot and hedge operational risks. An independently developed system called Blanket — built by developer Zminsky — scans a company’s stated exposures and maps them to event contracts available on Kalshi’s platform. The goal is to give smaller firms a way to identify hedges for disruptions such as unusual weather, shifts in energy costs, new tariffs, or politically driven outcomes that could affect revenue or expenses. How Blanket works - A business describes its operations and the events most likely to cause trouble. - Blanket’s AI analyzes those inputs and recommends specific Kalshi event contracts that could offset those risks. - Blanket does not place trades, control accounts, or handle funds; owners review recommendations and decide whether to trade on Kalshi. Why event contracts matter Event contracts are derivatives that pay out depending on whether a defined event occurs or a value reaches a set level. The U.S. Commodity Futures Trading Commission (CFTC) cites examples such as corporate earnings, snowfall levels, economic indicators and hurricane damage as potential underlyings. Because payouts hinge on contract terms, these instruments can let businesses take positions that offset losses from external events — for example, a contract tied to energy prices for firms exposed to fuel costs or a snowfall-linked contract for weather-dependent businesses. Limits and responsibilities Blanket aims to lower the barrier to hedging for companies that lack dedicated risk teams, but it isn’t insurance. Payouts depend on precise contract language, recommended positions may not fully cover a firm’s real-world losses, and AI-generated suggestions require human review and judgment. Regulatory and market context Kalshi operates as a CFTC-designated contract market, a status it received in November 2020, which gives third-party tools like Blanket access to federally regulated U.S. venues. The development comes as Kalshi expands beyond retail prediction trading: in early August, crypto.news reported Kalshi’s partnership with compliance technology provider Comply to integrate Kalshi trades into workplace surveillance systems that already monitor stocks, bonds and cryptocurrencies. The planned integration is intended to help financial firms spot restricted positions or activity involving material non-public information, and Kalshi expects the system to cover planned perpetual futures when launched. Surveillance and enforcement background Kalshi’s push for stronger monitoring follows enforcement issues tied to prediction markets. Crypto.news previously reported on a CFTC settlement in which former U.S. Representative George Santos agreed to return $17,569.98 in gains, pay a $17,500 civil penalty and accept a three-year trading ban after trading on whether he would attend President Trump’s State of the Union address while speaking publicly about the outcome. Santos neither admitted nor denied the CFTC’s findings. What’s next Blanket’s launch points to a new commercial role for prediction and event-markets: SME risk management. Its ultimate usefulness will hinge on how accurately recommendations map to firms’ financial exposures and whether users appreciate the differences between event contracts and traditional insurance. If it succeeds, Blanket could widen access to hedging strategies traditionally reserved for larger corporations with in-house risk teams. Read more AI-generated news on: undefined/news
Bitcoin rockets past $65K as weak July jobs report dents Fed rate-hike bets
Bitcoin surged past $65,000 after a surprising July jobs report weakened the case for another Fed rate hike, giving crypto markets a fresh bid. US payrolls unexpectedly fell by 23,000 in July, the Bureau of Labor Statistics reported — far below economists’ expectations of a 80,000–85,000 gain. It was the third-largest monthly payroll decline since 2020 and a sharp reversal from June’s revised 57,000 gain. Revisions to May and June cut 103,000 jobs from earlier estimates, underscoring softer-than-first-reported labor demand. Other labor details were mixed: the unemployment rate edged down to 4.1% (versus a forecast of 4.2%), while annual wage growth cooled to 3.2%, suggesting some easing in labor-market pressures. Why it matters for markets The weak payroll print reduces the immediate justification for another Fed rate increase, tilting expectations toward policy patience. Still, the Fed faces competing risks: softer hiring points toward holding rates steady, but inflation drivers — particularly energy and transport disruptions — could keep policymakers cautious about easing. Crypto reaction: Bitcoin, options and prediction markets Bitcoin traded around $65,200 after the report, up nearly 2% on the day. The asset had been under pressure earlier in the week as traders weighed the possibility of a September hike. Prediction markets moved quickly: Polymarket’s implied probability of a rate increase before the end of 2026 fell to 56% from a recent high of 77%. The odds that the Fed will leave rates unchanged at its September meeting climbed to about 66%, up from roughly 50% a day earlier. Options flows provided another read on sentiment. Andrei Grachev, managing partner at DWF Labs, said end-August puts have been trading at roughly 50% higher premiums than comparable calls. “If that gap narrows after a soft print, the caution priced into this market was genuinely about rates,” he said. “If it holds, traders are hedging something else, and one dovish data point will not change the stance.” Grachev also noted that upside positioning has already rebuilt around $70,000, signaling readiness for a rally without full conviction. Fed-watch and macro caveats Iggy Ioppe, CIO at Theo, warned that a single weak jobs report may not be enough to shift the Fed’s stance while geopolitical energy and shipping risks remain elevated. “Risk assets, including Bitcoin, retain the medium-term support that comes from continued inaction, but the same geopolitical energy risk that is keeping the Fed cautious also continues to limit upside,” he said. Ioppe pointed to oil-price pressure and shipping tensions in the Strait of Hormuz and Red Sea as factors that could keep inflation—and Fed caution—alive. Fabian Dori, CIO at Sygnum Bank, framed the Fed’s dilemma: policymakers must judge whether the print reflects a manageable slowdown or a deeper demand deterioration. “An orderly slowdown supports the liquidity relief case, while a print weak enough to raise growth concerns can still pressure risk assets even as rate odds move,” he said. Dori added that labor-force participation, Treasury cash balances, changes to the enhanced supplementary leverage ratio, private credit creation and stablecoin flows will also shape liquidity conditions for digital assets. What’s next Markets now turn to the US consumer price index on Aug. 12 for clearer guidance on whether energy and transport costs are keeping inflation elevated despite a cooling labor market. For Bitcoin, a softer CPI print could provide the fuel for a push toward $70,000; a hotter-than-expected reading could revive rate-hike expectations and make it harder for the crypto to hold gains above $65,000. Read more AI-generated news on: undefined/news
Russian authorities have detained more than 20 people after sweeping raids on nine unregistered crypto exchange points in Moscow, alleging the platforms were used to launder proceeds from phone-based fraud schemes. What happened - The Federal Security Service (FSB), working with the Interior Ministry, said it shut down nine unregistered cryptocurrency exchange services operating in the Moscow International Business Center (Moscow City). More than 20 exchange employees were detained. - Investigators allege the services were part of nine overseas-coordinated channels that converted cash obtained through remote phone scams into cryptocurrency and then transferred the assets to accounts controlled by Ukrainian coordinators. - According to the FSB, many victims — including pensioners — were kept in ongoing contact with scam call centers and instructed to carry out transactions without understanding they were facilitating fraud. The exchanges allegedly sold crypto to those victims and then forwarded the digital funds abroad. People involved and charges - Authorities also detained alleged accomplices aged 18–25 who acted as couriers, collecting cash from defrauded individuals and delivering it to the exchange points for conversion. - The FSB said many exchange staff were recruited remotely from across Russia despite limited financial knowledge and were lured by promises of easy earnings. - Criminal cases were opened under Part 4 of Article 159 of the Russian Criminal Code (fraud on an especially large scale). Exchange employees and couriers are being investigated as accomplices and, if convicted, could face up to 10 years in prison. Investigators are continuing to identify victims, verify testimony and assess whether lost funds can be recovered. Regulatory backdrop - The enforcement action comes just days after President Vladimir Putin signed a new digital asset law that sets a regulated framework for exchanges, brokers, custodians and other market participants effective Sept. 1. - Under the law, crypto providers must join a government registry and meet minimum capital requirements to operate legally. While existing businesses have a transition period to register, the FSB described the raided sites as unregistered and allegedly criminal. - The legislation also tightens retail investor rules — limiting purchases and introducing mandatory suitability testing — keeps the ban on using crypto for everyday payments inside Russia, but allows certain cross-border trade settlements using digital assets. - The Bank of Russia is drafting additional rules on exchange operations, organized trading, depositories and investor protections ahead of the law’s main provisions taking effect. Broader enforcement and market context - The raids follow other recent government steps affecting crypto activity: Prime Minister Mikhail Mishustin approved expanding anti-mining restrictions, extending a long-term mining ban to Moscow, the Moscow Region and parts of Kursk from Aug. 15 through the end of 2032 to ease electricity capacity pressure. A mining registry has also been introduced to distinguish registered operators from unauthorized projects. - Public awareness remains low: a Rambler&Co survey released this week found 69% of respondents could not identify a practical reason to use cryptocurrency and more than half reported limited knowledge of how crypto works. Respondents said clear regulations, licensed platforms and reliable information would be key to wider adoption. Why it matters - The operation underscores Russia’s dual push: cracking down on alleged criminal uses of crypto while rapidly formalizing a legal framework for regulated market activity. For users and operators, the message is clear — unregistered services face increasing legal risk as authorities step up enforcement and formal rules take effect. Read more AI-generated news on: undefined/news
BlueNoroff hijacks Telegram to trap crypto pros in fake Zoom/Teams malware calls
Headline: North Korea–linked group hijacks Telegram accounts to funnel crypto pros into fake Zoom/Teams meetings Summary Crypto professionals are being targeted in a renewed social‑engineering campaign that hijacks trusted Telegram accounts and pushes victims into staged Zoom or Microsoft Teams calls where malware is delivered. Researchers link the activity to UNC1069/BlueNoroff (also tracked as APT38), a North Korean state‑sponsored actor designated by the U.S. Treasury. The operation exploits human trust — real Telegram contacts and familiar meeting workflows — rather than any weakness in Bitcoin itself. What researchers found - JUMPSEC (July): Obtained source code from an active BlueNoroff phishing kit after exposed JavaScript source maps. The recovered kit acts as a victim‑acquisition platform that abuses compromised Telegram contacts, profiles cryptocurrency wallets and selectively delivers malware to Windows and macOS targets. JUMPSEC reported related infrastructure was still active as of July 22. - Mandiant (February): Documented a UNC1069 intrusion where a victim received a message from a compromised crypto executive’s Telegram, was routed to a spoofed Zoom domain, and saw what appeared to be an AI‑generated video of another executive during the staged call. Mandiant sees overlap between UNC1069 and BlueNoroff. - Security Alliance: Reported 164 domains blocked and attributed to UNC1069 between Feb. 6 and Apr. 7, describing multi‑week social engineering via Telegram, LinkedIn and Slack before delivering fraudulent Zoom/Teams links. How the scam works (attack chain) 1. Compromised Telegram accounts (belonging to real industry contacts) are used to send meeting invites. Because they come from trusted accounts and reference real relationships, recipients are more likely to click. 2. Victims join a spoofed meeting page that requests webcam access and plays a prerecorded video of an “attendee.” The operator pretends to have audio trouble and displays a fake software‑update/troubleshooting prompt. 3. The troubleshooting text instructs the victim to copy/paste a command or run an “update.” Copying the text places an attacker‑controlled ClickFix command on the clipboard; running it executes malware. 4. On Windows, observed payloads include PowerShell and VBScript components that can disable defenses, perform reconnaissance and establish persistence. On macOS, shell scripts and Mach‑O payloads aim to steal credentials and other sensitive data. 5. The kit scans the system for browser wallet providers and other high‑value targets before delivering the final payload. Key technical and operational points - Wallet draining is not automatic on link click. Compromise requires additional actions by the target (e.g., running a pasted command or installing a malicious “update”). However, once malware runs it can steal browser data, Telegram session data and local credential stores (e.g., macOS Keychain). - JUMPSEC found the staged meeting interface and clipboard abuse in the kit; Mandiant observed AI‑style prerecorded video during a live incident. - The initial method for taking over Telegram accounts has not been universally established. Claims that expired or temporary phone numbers are the primary cause remain unverified. - Infrastructure associated with the campaign remained active into late July, per JUMPSEC. Context and prior incidents - Martin Kuchař and other crypto executives previously reported Telegram account compromises used in similar schemes. - The U.S. Treasury formally designates BlueNoroff/APT38 as a North Korean state‑sponsored group linked to the Reconnaissance General Bureau. - Apple briefly removed Telegram from the App Store during a CSAM policy review; the app was restored after the flagged content was removed and the responsible account banned. Practical indicators of compromise (red flags) - Unexpected meeting invites from known contacts that include unusual domain names or prompt platform changes (Zoom → browser). - Requests to paste commands, run scripts, install unfamiliar apps or run “audio‑fix” tools during a call. - Prompts that instruct copying troubleshooting text to the clipboard. - Meeting pages that ask for webcam or screen permissions before a verified host joins. Actionable defensive guidance (FBI & industry recommendations) - Verify meeting requests and identity out‑of‑band (e.g., call or DM through a separate, known channel). - Keep wallet seed phrases, private keys and credential stores off internet‑connected devices whenever possible. - Use strong 2FA, but assume an infected device can expose session tokens — revoke sessions from a clean device if compromise is suspected. - Treat any prompt to paste code or install updates during a call as high risk. When in doubt, decline and confirm independently. - If you believe malicious code has already run: disconnect the device from the internet but leave it powered on for potential forensic capture; then contact incident‑response professionals and law enforcement. Bottom line This is an ongoing, North Korea‑linked social‑engineering campaign that targets the “human layer” around crypto custody by abusing trusted identities and familiar workplace tools. Its danger comes from convincing victims to perform actions that enable malware, not from breaking Bitcoin or cryptographic systems themselves. Stay skeptical of unexpected meeting prompts and never paste or execute commands unless you’ve independently verified the request. Read more AI-generated news on: undefined/news
Critical BTCPay Server exploit active — patch to v2.4.2 immediately or shut servers down
BTCPay Server urges immediate update after active exploit that can steal funds BTCPay Server on Aug. 7 warned users to install version 2.4.2 immediately after discovering a critical vulnerability that is being actively exploited and “can result in the loss of funds,” the project said via its official X account. What operators must do now - Update immediately using the server’s built-in maintenance interface: Admin Dashboard → Server → Maintenance → Update. - Confirm the server footer shows version 2.4.2. - If you cannot apply the patch right away, shut down your BTCPay Server until you can install the fixed release. The project explicitly recommends taking affected servers offline to block further unauthorized access. What is known—and what isn’t - BTCPay Server has labeled the flaw critical and confirmed active exploitation. - The team has not disclosed which older versions are vulnerable, how attackers gain access, how many instances were compromised, or whether any funds have been lost. - No indicators of compromise or technical details have been published yet, so operators may have limited means to determine if they were targeted. Why this matters BTCPay Server is an open-source, self-hosted payment processor that lets merchants accept Bitcoin and Lightning payments on infrastructure they control. That non-custodial model reduces reliance on third parties, but it also means individual operators are responsible for updates and security. A compromised installation can expose payment operations or other sensitive server functions depending on the flaw. Broader context The disclosure follows a recent security incident at Zeus Wallet, which temporarily took systems offline after a cyberattack; Zeus reported no customer funds lost and said its probe found no Lightning node software vulnerability. There’s currently no evidence linking the two incidents. Security reviews across the Bitcoin ecosystem have intensified: the volunteer Bitcoin Red Team recently flagged nearly 5,000 potential issues across 390 projects, with 720 findings rated high or critical. Bottom line Treat this as an emergency security action, not routine maintenance: update to v2.4.2 through the server’s official interface or power down the server until you can. Operators should also review server activity for signs of unauthorized access, knowing that formal indicators of compromise have not yet been provided. More technical details may arrive once a critical mass of users are patched and public disclosure no longer increases risk to unpatched systems. Read more AI-generated news on: undefined/news
Micron Soars on AI Memory Boom — Analysts Warn of 50%+ Crash Risk
Micron Technology (NASDAQ: MU) has become one of 2026’s hottest plays on Wall Street — attracting heavy interest from both retail traders and big institutions. The stock opened the year near $315 and sprinted to an all-time high of $1,255 in June, a meteoric run that turned heads and fattened portfolios across global markets. What’s driving the rally is simple: insatiable demand for memory chips. As companies pour billions into AI development, the need for high-performance memory and storage has surged. Micron sits squarely at the center of that wave, supplying critical components like DRAM, NAND flash, and High Bandwidth Memory (HBM) — the kinds of products that power AI training clusters and data centers. But investors should remember that semiconductors are notoriously cyclical. The same forces that can drive rapid appreciation can also reverse sharply. In a downside scenario — a major macro slowdown or an unexpected stall in AI investment — memory markets could swing into oversupply. That would pressure prices and margins for products such as HBM and DRAM, potentially triggering a classic cyclical memory crash. Analysts have modeled such a tail-risk: one forecast puts a worst-case target for Micron at about $360, implying a drop of more than 50% from recent highs. If oversupply and a rush to sell materialize, the decline could cascade further. Bottom line: Micron is a prime beneficiary of the AI boom and has delivered massive gains in 2026, but its fortunes remain tightly linked to a cyclical market. For traders and crypto-leaning investors who follow tech flows, MU offers both high upside and pronounced downside risk — a high-reward, high-volatility name to watch closely. Read more AI-generated news on: undefined/news
Stripes Bridge erhält grünes MiCA-Licht und wird zum 42. EU-EMT-Emittenten
Der Stablecoin-Arm von Stripe, Bridge, hat in der EU eine wichtige regulatorische Freigabe erhalten: Bridge ist in das Register der Markets in Crypto-Assets (MiCA) des Blocks eingetragen worden und wurde zum 42. autorisierten Emittenten von E-Geld-Token (EMTs). Was passiert ist – ESMA hat mit dem neuesten Update des Registers Bridge Building, die in Luxemburg ansässige Einheit hinter dem von Stripe kontrollierten Bridge, als autorisierten EMT-Emittenten aufgenommen. Damit steigt die Gesamtzahl der MiCA-autorisierten EMT-Emittenten auf 42. – Mit demselben Update wurden außerdem drei deutsche Anbieter von Krypto-Asset-Dienstleistungen (CASPs) ergänzt – Volksbank Die Gestalterbank, VBU Volksbank im Unterland und VR-Bank Erding – wodurch sich die EU-weite Gesamtzahl der autorisierten CASPs auf 324 erhöht. – ESMA hat keine neuen Emittenten für asset-referenced Token (ART) registriert und keine Änderungen an ihrer Liste nicht konformer Unternehmen vorgenommen. Warum das wichtig ist – Bridge hatte zuvor am 2. Juli angekündigt, sowohl eine MiCA-Krypto-Asset-Dienstleister-Authorization als auch eine Lizenz als E-Geld-Institut (EMI) vom luxemburgischen Regulierer (CSSF) erhalten zu haben. Diese Genehmigungen erlauben Bridge den Betrieb in allen 27 EU-Mitgliedstaaten über ein einziges aufsichtsrechtliches „Regulatory Passporting“, wodurch separate nationale Zulassungen entfallen. – Im regulierten Rahmen können Unternehmen, die die Infrastruktur von Bridge nutzen, maßgeschneiderte eurobasierte Stablecoins ausgeben, benannte virtuelle IBANs erstellen, Euro-Konten eröffnen, die in der gesamten EU funktionieren, und grenzüberschreitende Euro-Konten über eine einzige Verbindung integrieren. Unternehmen können Stablecoins außerdem nutzen, um Gelder zwischen Tochtergesellschaften zu transferieren, statt auf Korrespondenzbanking angewiesen zu sein. – Die Registrierung folgt darauf, dass die EU am 1. Juli die Übergangsphase von MiCA abgeschlossen hat, wodurch regulierte Plattformen gezwungen wurden, ausschließlich MiCA-konforme Stablecoins zu unterstützen. Der Wechsel führte dazu, dass große Börsen – darunter Coinbase, Kraken und Crypto.com – USDT für EU-Nutzer auslisteten, nachdem Tether sich entschieden hatte, keine MiCA-Zulassung zu beantragen; Binance hat seine Dienste ebenfalls angepasst, um die Vorgaben einzuhalten. Kontext zu Bridge und Stripe – Stripe erwarb Bridge für ungefähr 1,1 Milliarden US-Dollar und hat die Technologie von Bridge seitdem in sein Zahlungs-Geschäft integriert. Ziel ist es, regulierte Stablecoin-Zahlungen, grenzüberschreitende Abwicklung und dazugehörige Finanzdienstleistungen für Unternehmen und Entwickler auszuweiten. – Im März hatte Visa eine Partnerschaft mit der von Stripe kontrollierten Infrastruktur erweitert, um Stablecoin-gestützte Visa-Kartenprogramme in mehr als 100 Ländern bis Ende 2026 auszurollen. – Das Team von Bridge sagt, es habe Beziehungen zu Sponsorbanken, Anbindungen an Zahlungsnetzwerke und regulatorische „Infrastructure“ aufgebaut, um das Angebot global zu skalieren. Der ehemalige Leiter der Stripe-Stablecoin-Partnerschaften, Connor Fitzgerald, sagte, das Programm sei von null auf Einsätze in über 100 Märkten gewachsen und habe jährliche Zahlungsvolumina in den „tens of millions“ US-Dollar erreicht, während es das eingeführt habe, was er als den ersten US-Stablecoin-Abwicklungs-Flow bezeichnete. Weitere Unternehmensbewegungen – Reuters berichtete, Stripe und die Private-Equity-Firma Advent International hätten einen Vorschlag über rund 53 Milliarden US-Dollar eingereicht, um PayPal zu übernehmen. Dabei wurde das Unternehmen mit 60,50 US-Dollar je Aktie bewertet; vorgesehen war eine gleichberechtigte Beteiligung zwischen Stripe und Advent, falls der Deal zustande kommt. Berichten zufolge habe der Vorstand von PayPal das Angebot als zu niedrig bewertet angesehen und Finanzierung-, Regulierungs- und Umsetzungsrisiken abgewogen. Sollte die Transaktion zustande kommen, könnte sie PayPals Krypto-Assets – einschließlich des von Paxos herausgegebenen PYUSD-Stablecoins – mit der sich ausweitenden Bridge-Infrastruktur von Stripe kombinieren. Fazit – Die MiCA-Registrierung von Bridge ist ein wichtiges regulatorisches Meilensteinereignis für Stripes Stablecoin-Ambitionen in Europa. Mit einem vollständigen EU-Pass und wachsenden Partner-Integrationen ist Bridge gut positioniert, eurobasierte Stablecoins, virtuelle IBANs und grenzüberschreitende Zahlungs-Rails tiefer in den Mainstream-Fintech-Markt vorzustoßen – genau dann, wenn MiCA neu definiert, welche Stablecoins und Anbieter im Block operieren dürfen. Mehr AI-generierte Nachrichten zu: undefined/news
The Senate’s decision to punt the Clarity Act has left XRP at a precarious crossroads. Lawmakers adjourned without taking up the legislation, pushing any market-structure vote at least to September — and while most major cryptocurrencies shrugged off the delay, XRP did not. Why this matters The Clarity Act, in draft form reported by Decrypt, would draw a statutory line between securities and commodities. That draft would have explicitly classified XRP (alongside Solana and Dogecoin) as a non-security, placing those tokens under the Commodity Futures Trading Commission (CFTC) rather than the Securities and Exchange Commission (SEC). For Ripple — which has waged a years-long legal fight with the SEC over whether XRP is an unregistered security — that statutory clarity would do what settlements can’t: provide a single, binding federal answer for exchanges, custodians and regulators nationwide. Ripple did agree to pay $50 million to settle its cross-appeal with the SEC, but a law would be a much broader resolution. Price action and market context XRP was the only major token in the top 10 by market cap to close in the red on the day, dropping 2.05% and finishing the week down about 3% — the weakest performance among the majors. By contrast, Bitcoin was largely flat and Dogecoin gained 1.38%. XRP is trading around $1.028 with a market capitalization near $64 billion, a daily decline of roughly 0.71% after a red candle left it hovering just above the $1 psychological floor. That price is the second-lowest daily close since early 2024, above only last month’s $0.9153 low. Technical picture Technically, XRP is in a clear downtrend. The token peaked near $3 in 2025 and has been sliding since. The 50-day EMA has crossed below the 200-day EMA — a classic “death cross” — and the current price sits below both averages, meaning moving averages offer little support underneath. Momentum indicators paint a cautious picture: the RSI is 35.9 (bearish but not yet oversold), and the ADX is 11.9, indicating the move lacks strong conviction and trading could remain choppy. The Squeeze Momentum indicator is “off,” signaling expanding volatility rather than a compressed setup that usually precedes sharp breakouts — so moves may continue to be gradual. What would change the narrative Bull case: A sustained daily close above $1.10 (first meaningful resistance in the lower Fibonacci zone) and then $1.13 (daily point of control) would suggest the floor is holding and could attract fresh buying. Progress on the Clarity Act — even if it’s now unlikely before September — would also be a major bullish catalyst for traders who bet on regulatory clarity. Bear case: A drop and daily close below $1.00 would open the path to $0.9153, the lowest chart point since 2024. Given the prevailing downtrend, that scenario is far from improbable and would effectively erase the post-2024 recovery. Market sentiment Short-term sentiment shows some divergence: on Myriad, a prediction market from Decrypt’s parent company Dastan, traders are pricing about a 77% chance that XRP stays above $1 over the coming weekend. So while charts and headlines suggest vulnerability, some traders remain optimistic that the $1 line holds — for now. Bottom line With the Clarity Act delayed, XRP remains in legal and price limbo. The token is technically weak and vulnerable to further losses if $1 breaks, but a close back above $1.10–$1.13 or renewed momentum behind regulatory reform could quickly flip the story. For investors and traders, that $1 mark is the key line to watch. Read more AI-generated news on: undefined/news
RWA Deposits Triple to $7.4B as DeFi Slows — Spot Volumes Jump 220%
Headline: Tokenized RWAs surge to $7.4B as DeFi activity cools — CoinShares & Token Terminal report Tokenized real-world assets (RWAs) are moving rapidly on-chain even as broader DeFi activity cools, according to The Growth of Hybrid Finance, a joint report from asset manager CoinShares and on‑chain data provider Token Terminal covering Q2 2025–Q2 2026. Key findings - Deposits of tokenized RWAs into decentralized lending platforms and exchanges more than tripled over the past year, rising from $2.3 billion to $7.4 billion. - By contrast, total deposits across DeFi fell roughly 15% over the same period. - Spot trading on decentralized exchanges declined ~70%, while spot volumes for tokenized RWAs jumped about 220%. - On perpetual futures venues, both trading volumes and open interest in RWAs continued to climb despite a wider slowdown that began in October 2025; RWA positions now account for over a quarter of on‑chain perpetuals open interest. What’s driving the flow - Treasury and multi‑strategy tokenized funds (examples cited include JTRSY, BUIDL and sUSDS) make up the largest share of RWA activity, followed by private‑credit products (JAAA, syrupUSDC, PRIME) and delta‑neutral strategies (sUSDe). - Tokenized gold leads spot trading volume, while perpetuals activity is concentrated in oil and precious metals, the S&P 500 and Nasdaq‑100, and tech/semiconductor stocks. Platform dynamics - Nearly 70% of RWA deposits are on lending venues built on Ethereum. Plasma (boosted by Aave’s expansion off Ethereum) is the second largest chain for RWA deposits, while Solana’s growth is largely attributed to native RWA lender Kamino. - Deposits remain concentrated on a handful of venues—Aave, Morpho and Kamino. Revenue lag and the Hyperliquid outlier - Despite rising RWA flows, application revenues for both lending and trading platforms fell over the year, a sign the market is still in an early adoption stage. - Hyperliquid stands out: it generated substantially more application revenue than other trading or lending venues and briefly overtook Solana and Ethereum as the top revenue‑generating chain. Decrypt earlier reported that RWAs outpaced crypto on Hyperliquid for a week, with SK Hynix the most‑traded stock that week. Context and scale - The RWA trend isn’t entirely new: in February the RWA pool expanded to $24.8 billion as overall DeFi TVL dipped, a rotation some attribute to compressed DeFi yields versus roughly 4% on tokenized Treasuries. - Despite rapid growth, tokenization remains small relative to traditional markets—about $2.2 billion of a global equity market worth more than $100 trillion has been tokenized. The report likens the current RWA market to stablecoins in 2019: early, concentrated and poised for further development. Institutional product launches - BlackRock, whose BUIDL fund is named in the report, recently launched two additional tokenized money market funds and rolled out tokenized share classes for European money market funds with combined assets of $311 billion—moves that underscore growing institutional interest. Methodology note - The analysis focuses only on “distributed” assets—tokens that can be moved to wallets outside the issuing platform—so closed or permissioned networks such as Canton and Provenance were excluded. CoinShares CEO Jean‑Marie Mognetti framed the shift as investors using traditional financial exposures on‑chain rather than swapping into native crypto: “Look at what is actually being used on‑chain—Treasuries, gold, the S&P 500, semiconductor stocks. Not one of them is a crypto asset.” Bottom line: RWAs are carving out significant on‑chain market share and attracting institutional product launches, but revenue and tokenization scale remain early‑stage. How quickly venue economics and broader adoption follow these flows will shape the next phase of hybrid finance. Read more AI-generated news on: undefined/news
Bitcoin Breaks $65K as Weak U.S. Jobs Print Cuts Odds of Fed Hike
Headline: Bitcoin breaks $65K after surprise U.S. jobs contraction, Fed bets cool Bitcoin jumped above $65,000 after U.S. payrolls unexpectedly fell in July, weakening the case for another Federal Reserve rate hike and prompting traders to pare back bets on higher rates. The data: U.S. nonfarm payrolls dropped by 23,000 in July, the Bureau of Labor Statistics reported — far below economists’ forecasts of a 80,000–85,000 gain. It was the third-largest monthly payroll decline since 2020 and a sharp reversal from June’s revised 57,000 gain. Revisions to May and June removed a combined 103,000 jobs from prior estimates, suggesting labor demand is softer than first thought. Other labor-market details: the unemployment rate ticked down to 4.1% (consensus 4.2%), while annual wage growth cooled to 3.2%, another sign of easing tightness in the jobs market. Market reaction: Bitcoin traded around $65,200 after the report, up nearly 2% on the day. The move followed earlier selling pressure tied to the possibility of a September Fed hike. Repriced Fed odds: traders quickly adjusted rate expectations. Polymarket’s probability of a rate increase before the end of 2026 fell to 56% (from a recent peak of 77%), while the chance the Fed leaves rates unchanged in September rose to about 66% (from roughly 50% a day earlier). What strategists are saying: - Iggy Ioppe, CIO at Theo, told crypto.news that a single weak jobs print may not be enough to shift the Fed’s stance while energy and shipping risks remain elevated. He pointed to oil-price pressure and disruptions in the Strait of Hormuz and Red Sea as factors keeping inflation and policy uncertainty alive — limiting Bitcoin’s upside even as lower rate odds provide medium-term support. - Andrei Grachev, managing partner at DWF Labs, noted the options market was pricing significant downside protection: end-August put premiums were trading roughly 50% above equivalent calls. If that premium narrows after the soft print, it would indicate caution was primarily about rates; if it holds, traders are likely hedging geopolitical or inflation risks. Grachev also said upside positioning has rebuilt around $70,000, suggesting traders are preparing for a rally without full conviction. - Fabian Dori, CIO at Sygnum Bank, said the Fed needs to determine whether the slowdown is a manageable cooling or a more persistent demand deterioration. He flagged labor-force participation, Treasury cash balances, changes to bank leverage rules, private credit creation and stablecoin flows as key liquidity variables for digital assets. What’s next: markets will watch the U.S. consumer price index on Aug. 12 for clues on whether energy and transport costs are keeping inflation higher despite a softer labor market. For Bitcoin, a cooler CPI could help push prices toward $70,000; a hotter reading would revive rate-hike bets and could test Bitcoin’s recovery above $65,000. Read more AI-generated news on: undefined/news
FSB raids Moscow City unregistered crypto exchanges, detains 20+ over phone‑scam money‑laundering
Headline: Russia detains 20+ in raids on nine unregistered crypto exchange points, alleges phone‑scam money laundering Russia’s Federal Security Service (FSB), working with the Interior Ministry, has detained more than 20 employees after raids on nine unregistered cryptocurrency exchange services in Moscow’s International Business Center (“Moscow City”), alleging the operations were used to launder proceeds from phone scams. What happened - Authorities say the exchange points—described by the FSB as overseas‑coordinated channels—converted cash stolen from victims into cryptocurrency and forwarded the assets to accounts controlled by Ukrainian coordinators. - More than 20 workers at the Moscow City locations were detained. In addition, several alleged accomplices aged 18–25 were taken into custody; officials say these individuals acted as couriers who collected cash from defrauded victims (including pensioners), delivered it to exchange points for conversion, and helped send funds abroad. - The FSB alleges many exchange staff had been hired remotely from other Russian regions, often without sufficient financial expertise, and were lured by promises of easy pay. Investigators say victims remained in continuous contact with scam call centers and followed instructions without realizing they were laundering money. Legal response and potential penalties - Russia’s Interior Ministry has opened criminal cases under Part 4 of Article 159 of the Criminal Code—fraud on an especially large scale. Exchange employees and couriers are being investigated as alleged accomplices and could face prison terms of up to 10 years if convicted. - Authorities continue to identify further victims, verify witness statements and explore the possibility of recovering financial losses. Regulatory backdrop - The enforcement action comes days after President Vladimir Putin signed a new digital asset law that establishes a regulated framework for exchanges, brokers, custodians and other market participants effective Sept. 1. - Under the new law, crypto exchange providers must join a government registry and meet minimum capital requirements before offering services; a transition period applies for existing businesses. The FSB characterized the Moscow locations targeted in the raids as unregistered exchange points allegedly involved in criminal activity. - The law also restricts retail crypto purchases, requires mandatory suitability testing for investors, and maintains a ban on using cryptocurrency for ordinary domestic payments—while permitting limited use of digital assets in certain cross‑border trade settlements. - The Bank of Russia is preparing additional implementing regulations covering exchange operations, organized trading, depositories and investor protection ahead of the law’s effective date. Broader policy moves and public sentiment - The raids follow several recent state moves impacting crypto activity: Prime Minister Mikhail Mishustin approved an expansion of regional mining restrictions earlier this month, extending a long‑term ban to Moscow, the Moscow Region and parts of Kursk from Aug. 15 through 2032 to manage electricity capacity. Officials have also created a mining registry to differentiate registered operators from unauthorized miners. - Public familiarity with crypto in Russia remains limited. A recent Rambler&Co survey found 69% of respondents couldn’t identify a practical reason to use cryptocurrencies and over half said they know little about how digital assets work. Respondents listed clear regulation, licensed platforms and reliable information as priorities before engaging with crypto. Why it matters The operation highlights Russia’s focus on shutting down unregistered exchange activity alleged to facilitate fraud just as the country moves to a more formalized crypto regulatory regime. For market participants, the raids underscore the growing enforcement risk for unlicensed services and couriers—and the increasing attention authorities are paying to links between on‑the‑ground cash collection and cross‑border crypto flows. Read more AI-generated news on: undefined/news
UNC1069 kapert Telegram, um Krypto-Profis in gefälschte Zoom/Teams zu locken und Wallet-stehlende Malware auszuspielen
Eine frische, hochgradig gezielte Social-Engineering-Kampagne kapert echte Telegram-Konten, um Krypto-Profis mit gefälschten Zoom- und Microsoft-Teams-Meetings zu täuschen — und schiebt danach Malware nach, die Wallets, Zugangsdaten und Chat-Daten stehlen kann. Was passiert - Sicherheits-Teams und Community-Meldungen (am 7. August von Lightning News hervorgehoben) zeigen, dass Angreifer kompromittierte Telegram-Konten nutzen, die echten Kontakten aus der Branche gehören, um Ziele zu inszenierten Videoanrufen einzuladen. Da die Einladungen von vertrauenswürdigen Personen kommen, sind Empfänger deutlich eher bereit, sie anzunehmen. - Unabhängige Forschung bestätigt die zentrale Angriffskette, auch wenn einige Details noch nicht verifiziert sind. Wer steckt dahinter - Mehrere Analysten ordnen die Operation UNC1069/BlueNoroff zu, einer Gruppe, die das US-Finanzministerium als APT38 einstuft, und die mit der Reconnaissance General Bureau Nordkoreas in Verbindung gebracht wird. Mandiant verfolgt den Akteur als UNC1069 und dokumentiert Überschneidungen mit BlueNoroff. Security Alliance und weitere Forschende ziehen zu ähnlichen Schlussfolgerungen. Technische Erkenntnisse - JUMPSEC beschaffte Quellcode aus einem aktiven BlueNoroff-Phishing-Kit (über offengelegte JavaScript-Quellkarten) und rekonstruierte die Plattform zur Opfergewinnung. Das Kit war Ende Juli noch aktiv. - Angriffsablauf: Kompromittierte Telegram-Konten kontaktieren Ziele, laden sie zu einem Meeting ein und leiten sie anschließend auf eine gespoofte Meeting-Domain weiter. Während des inszenierten Anrufs sieht das Opfer möglicherweise ein vorab aufgezeichnetes Video (Berichte enthalten eine KI-generierte Ähnlichkeit) und wird aufgefordert, Webcam-Zugriff zu erlauben oder Schritte zur Fehlerbehebung zu befolgen. - Eine betrügerische „Audio Fix“- oder „Software-Update“-Aufforderung kopiert einen von einem Angreifer gesteuerten ClickFix-Befehl in die Zwischenablage — das Opfer muss diesen Befehl einfügen/ausführen, damit die Kompromittierung fortschreiten kann. Klicken auf einen Meeting-Link allein entleert also keine Wallets automatisch; erst das Ausführen des kopierten Befehls oder das Installieren des gefälschten Updates ermöglicht die Malware-Ausführung. - Beobachtete Windows-Payloads umfassen PowerShell- und VBScript-Module zum Deaktivieren von Schutzmaßnahmen, zur Erkundung und für den weiteren Zugriff. MacOS-Beispiele beinhalten Shell-Skripte und Mach-O-Binaries, die auf das Stehlen von Zugangsdaten und sensiblen Daten abzielen. Das Kit scannt außerdem nach Browser-Wallet-Erweiterungen und -Anbietern, um wertvolle Ziele zu priorisieren. - Mandiant fand Tools, die Browserdaten, macOS Keychain-Zugangsdaten und Telegram-Nutzerdaten stehlen können, sobald die Malware läuft. Umfang und frühere Vorfälle - Security Alliance berichtete, 164 Domains zu UNC1069 zwischen dem 6. Februar und dem 7. April blockiert zu haben, und beschrieb mehrwöchiges Social Engineering über Telegram, LinkedIn und Slack, bevor betrügerische Zoom-/Teams-Links ausgeliefert wurden. - Mandiant dokumentierte einen Einbruch im Februar, bei dem ein Opfer Nachrichten von einem kompromittierten Telegram-Konto eines Krypto-Executives erhielt und zu einer gespooften Zoom-Domain geleitet wurde. - Öffentliche Opfer sind u. a. Mitglieder der Krypto-Community wie Martin Kuchař, dessen Telegram-Konto zuvor für ähnliche Köder genutzt wurde. Was nicht bestätigt ist - Forschende bestätigen, dass Konten kompromittiert werden, aber die genaue Methode der anfänglichen Übernahme ist unklar. Behauptungen, dass abgelaufene oder vorübergehende Telefonnummern der Hauptgrund seien, sind in den ausgewerteten Unterlagen nicht verifiziert. Hinweis zur Plattform - Apple hat Telegram zudem vorübergehend aus dem App Store entfernt, und zwar im Rahmen einer CSAM-Richtlinienprüfung; die App wurde wiederhergestellt, nachdem Telegram den beanstandeten Inhalt entfernt und den verantwortlichen Nutzer gesperrt hatte. Praktische Ratschläge und Schadensbegrenzung - Behandle unerwartete Meeting-Anfragen von Kontakten als besonders riskant, vor allem, wenn sie Domain-Änderungen vorantreiben, dich auffordern, Befehle einzufügen, oder Aktionen wie „Audio Fix“ / Software-Update anstoßen. - FBI-Hinweise für Krypto- und DeFi-Mitarbeitende: Verifiziere Identitäten über einen unabhängigen Kanal, halte Seed Phrases und private Schlüssel von internetfähigen Geräten fern und nutze Zwei-Faktor-Authentifizierung. Beachte: 2FA kann umgangen werden, wenn ein Gerät bereits infiziert ist; widerrufe kompromittierte Sitzungen von einem sauberen Gerät aus. - Wenn du vermutest, dass du verdächtigen Code ausgeführt hast: trenne das Gerät vom Internet (lass es eingeschaltet für mögliche forensische Auswertungen) und kontaktiere Incident-Response-Spezialisten sowie Strafverfolgungsbehörden. Fazit Diese Kampagne nutzt vertrauenswürdige menschliche Beziehungen und alltägliche Workplace-Tools — nicht Bitcoin selbst — um die Verwahrer- und Credential-Ebene rund um Krypto anzugreifen. Ihre Gefahr entsteht durch Social Engineering und maßgeschneiderte Folgeaktionen, die Credential-Stealing-Malware liefern, sobald ein Opfer die bösartigen Befehle oder Updates ausführt. Bleib skeptisch bei unerwarteten Einladungen, verifiziere außerhalb des Kanals, und halte Keys von verbundenen Geräten fern. Mehr AI-generierte News zu: undefined/news
Chainalysis Warns: Kidnappings and Home Invasions Surge as Criminals Hunt Self‑Custody Crypto
Headline: Crypto crime goes physical — kidnappings, home invasions rise as attackers hunt self-custody wallets, Chainalysis warns Chainalysis is sounding the alarm: cryptocurrency crime is no longer limited to online hacks and scams. In a new report, the blockchain analytics firm says criminals are increasingly turning to violent, real-world tactics — kidnappings, home invasions and hostage situations — to coerce victims into transferring crypto from self-custody wallets that can be spent instantly. Cybercrime still dominates overall illicit activity, the report notes. For 2025 Chainalysis estimates roughly $3.4 billion was stolen in hacks, $17 billion lost to scams and about $820 million linked to ransomware. But physical attacks are rising because many crypto holders control large sums outside traditional institutional protections, making them attractive targets. Scale and trends - Chainalysis estimates violent criminals extracted more than $30 million from crypto holders in the first half of 2026 through kidnappings, hostage situations and home invasions. If that pace holds, 2026 could exceed the $58 million reported for all of 2025 — and that figure likely understates the problem since it only counts publicly reported incidents. - The Coldcard hardware-wallet exploit — tracked separately by Galaxy Research — highlights another vector: confirmed losses reached about 1,596 BTC across three attack waves, with a suspected fourth wave possibly pushing total losses to ~2,055 BTC if verified. While that incident was a software vulnerability rather than physical coercion, it underscores the persistent value criminals are targeting through both digital and real-world attacks. Attack success and asset recovery - Although violent incidents have increased, attackers are succeeding less often. Through late June 2026, only 12 of 46 documented violent theft attempts resulted in victims surrendering funds — a 26% success rate versus 49% in 2025 and 67% in 2024. - When failed extortion attempts, blocked transfers and recovered assets are included, the value tied to violent incidents rises to roughly $107 million in H1 2026. - Every forced transfer leaves a blockchain trail, aiding investigators. Chainalysis grouped attackers into three operational tiers: inexperienced offenders who send funds straight to centralized exchanges (making them easier to trace); mid-level operators who route funds through DEXs, bridges and intermediary wallets; and a third tier linked to established criminal networks that use OTC-style laundering services and other sophisticated mixing chains. Network links and caveats - In one investigated case, stolen funds flowed through an instant exchange and then into what Chainalysis called a suspected OTC laundering service with prior blockchain connections to cartel-related laundering, wallets tied to an alleged cocaine trafficker, terrorist-financing clusters and Southeast Asian money-laundering networks. Chainalysis emphasized these are blockchain exposure links, not proof every connected entity participated in the original violent crime. Changing attack patterns and geography - Kidnappings remain the most common “wrench attacks,” but home invasions jumped from 14% of incidents in 2025 to 37% through mid-2026. Attackers increasingly prefer pressuring victims in their own homes rather than moving them elsewhere. - Regional differences are stark: the U.S. is an outlier for home invasions, while France has seen a disproportionate share of kidnappings. Since 2023 France has recorded the most publicly known violent crypto incidents — 30 cases through mid-2026 versus 19 for all of 2025. French Interior Minister Laurent Nuñez said authorities documented more than 70 crypto-related violent incidents and rolled out a rapid identification and alert system for at-risk individuals. Potential drivers in France - Chainalysis points to an alleged 2024 theft and sale of tax records for high-net-worth crypto holders as a likely factor in the French spike. Those dossiers reportedly included names, addresses, holdings, phone numbers and tax details that would let attackers identify targets. The report also cites Waltio’s January 2026 disclosure that unauthorized access affected data for roughly 50,000 users — though Chainalysis stops short of claiming a direct causal link to individual attacks. - French law enforcement has treated many incidents as organized-crime cases: by mid-2026 that response had yielded roughly 200 arrests, 88 indictments, 75 suspects in pretrial detention and more than a dozen active investigations. Targets and reconnaissance - Attackers aren’t just going after holders — they increasingly target relatives and acquaintances to coerce victims. Family members or close relations were involved in an estimated 25–30% of documented incidents by early 2026, up from almost zero in 2021; in France that figure exceeded 40%. - Most victims were local residents rather than visitors: known residency data showed locals comprised 100% of documented victims in Sweden, 93% in France, 82% in Brazil and 77% in the U.S. Chainalysis says this pattern points to pre-attack reconnaissance using leaked data, blockchain activity, social media or insider information. Bottom line Chainalysis’ findings highlight an evolving threat landscape: while cybercrime remains the largest source of illicit crypto losses, violent extortion is growing in frequency and sophistication. The permanence and transparency of blockchain records can help investigators trace coerced transfers, but the rise of self-custody wealth, leaked personal data and new laundering tactics create complex challenges for holders and law enforcement alike. Read more AI-generated news on: undefined/news
CleanSpark reported a $239 million quarterly loss as revenue slid 30.5% year‑over‑year, even as the miner secures a major long‑term AI data center deal that could reshape its revenue mix. Key results and market reaction - For the fiscal third quarter (ended June 30) CleanSpark posted $138 million in revenue, down from $198 million a year earlier and below the Yahoo Finance consensus of $142.2 million. - The company recorded a net loss of $239 million, or $0.89 per basic share, reversing from net income of $257 million ($0.90 per share) in the prior‑year quarter. - Shares fell about 5.5% on the news before recovering roughly 3% in pre‑market trading to trade above $13.10, per Yahoo Finance. The weak reaction echoes the drop the stock saw after its May results. Recent trend and drivers - This follows another loss in the prior quarter: for the fiscal second quarter ended March 31, CleanSpark reported a $378.3 million net loss on $136.4 million in revenue (vs. a $138.8 million loss and $181.7 million revenue a year earlier). - Volatility in Bitcoin’s market value and mark‑to‑market accounting have been a major factor in the swings. In the prior quarter, a $224.1 million fair‑value loss on Bitcoin holdings made up nearly 60% of CleanSpark’s net loss. Balance sheet and mining operations - Despite pressure on earnings, CleanSpark continued to grow its mining footprint. In the fiscal second quarter the company said Bitcoin holdings rose 14% year‑over‑year and average monthly hashrate climbed 18%. - At the end of that quarter the company reported about $925.2 million in Bitcoin and $260.3 million in cash. Big push into AI and HPC - CleanSpark is simultaneously diversifying into AI and high‑performance computing (HPC). On July 14 it signed a 20‑year lease for a 175‑MW data center at its Sandersville, Georgia campus with an unnamed investment‑grade global technology company, estimating roughly $6.6 billion in contracted revenue over the initial lease term. - The firm says Sandersville development has been progressing for several quarters, it has doubled contracted megawatts year‑over‑year, and secured 585 MW of ERCOT‑approved capacity in Texas for additional AI/HPC projects. - CEO Matt Schultz has indicated the company plans to commercialize assets suitable for AI and HPC while continuing to operate its Bitcoin mining business efficiently. Broader industry context - CleanSpark is not alone in pivoting toward colocation and AI infrastructure as miners wrestle with mark‑to‑market earnings pressure. Marathon (MARA) faced a $1.3 billion Q1 loss after Bitcoin valuation adjustments, TeraWulf said HPC revenue surpassed mining revenue in Q1, and Core Scientific has reported rising colocation income even as it posted big losses earlier in the year. Why it matters - The results underline the twin realities for public miners: near‑term earnings remain vulnerable to Bitcoin price swings and accounting adjustments, but new AI/HPC deals offer a path to more predictable, contract‑based revenue. Investors will be watching execution at Sandersville, further colocation contracts, and whether mining economics improve as BTC prices and hashrates evolve. Read more AI-generated news on: undefined/news
AI tool Blanket taps Kalshi’s regulated event contracts to help small businesses hedge risks
Kalshi markets power new AI tool to help small businesses hedge real-world risks A newly launched AI tool called Blanket is tapping Kalshi’s regulated event-contract marketplace to help small businesses identify and hedge operational risks they might otherwise miss. Built independently by developer Zminsky, Blanket analyzes a company’s exposures—everything from unusual weather and energy-price swings to tariffs and election outcomes—and maps those risks to tradable event contracts available on Kalshi. How Blanket works - Small businesses provide information about their operations and the incidents most likely to disrupt them. - Blanket’s AI scans Kalshi’s event-contract listings and recommends contracts that could offset specific outcomes tied to the business’s exposure (for example, contracts linked to energy prices for a firm sensitive to fuel costs or snowfall/temperature contracts for weather-dependent operations). - Blanket does not execute trades, manage accounts, or handle customer funds. Business owners retain full responsibility for reviewing the AI’s recommendations and deciding whether to trade on Kalshi. Why event contracts matter Event contracts are derivatives whose payouts hinge on whether a defined event occurs or a set value is reached. The CFTC has cited examples such as corporate earnings, snowfall, economic indicators and hurricane damage as potential underlying outcomes. In theory, a business can take a position that offsets losses from an external event—though the fit between contract payoff and actual financial loss can be imperfect. Where Blanket helps — and where it doesn’t - The tool targets a real gap: many small firms don’t have dedicated risk teams to hunt down suitable hedging instruments, so AI can make those markets more accessible. - Important limits remain: event contracts are not insurance. Payouts depend strictly on contract terms and may not fully match a firm’s losses. AI recommendations are advisory and require human scrutiny before trading. Kalshi’s role and regulatory context Kalshi is a CFTC-designated contract market (status granted in November 2020), and Blanket uses the markets and regulated infrastructure Kalshi offers. Zminsky’s product is independent of Kalshi; the exchange supplies the contracts but Blanket is not an internal Kalshi offering. The move comes as Kalshi pushes beyond retail prediction betting into more institutional, compliance-focused territory. As reported by crypto.news on Aug. 4, Kalshi has partnered with compliance vendor Comply to integrate event-contract trades into workplace surveillance systems already used to monitor stocks, bonds and cryptocurrencies. That integration will help firms flag restricted positions or trades that could involve material non-public information, and Kalshi says the system will extend to planned perpetual futures products when launched. Surveillance follows enforcement Kalshi’s compliance focus follows enforcement episodes tied to prediction markets. In a notable CFTC settlement, former U.S. Representative George Santos agreed to return $17,569.98 in gains, pay a $17,500 civil penalty and accept a three-year trading ban after Kalshi referred his trades to regulators. The case involved Santos trading on whether he would attend President Trump’s State of the Union address while making public statements related to the outcome; he neither admitted nor denied the CFTC’s findings. What’s next Blanket represents a practical new use case for prediction markets: commercial risk management for smaller businesses. Its uptake will hinge on how well AI recommendations align with firms’ true financial exposures and how carefully users understand the limits of event-contract hedges. If it proves accurate and businesses apply appropriate human oversight, Blanket could expand real-world utility for regulated event markets—while underscoring the need for strong compliance and transparency as these products mature. Read more AI-generated news on: undefined/news
Microsoft: ClickFix Uses BNB Chain Smart Contracts to Deliver Malicious Commands at Scale
Microsoft: ClickFix malware is using BNB Chain smart contracts to deliver malicious commands at scale Microsoft Threat Intelligence has uncovered a large, ongoing campaign that leverages BNB Smart Chain (BNB Chain) smart contracts to deliver ClickFix and related attacks, infecting thousands of enterprise and consumer devices every day. What’s new and worrying - Compromised websites are being injected with Base64-encoded JavaScript that doesn’t talk to a regular command-and-control server. Instead, the script queries a smart contract via a BNB Smart Chain RPC gateway to fetch next-step instructions — an abuse of on-chain storage that Microsoft links to earlier ClearFake activity and calls “EtherHiding.” - Because instructions are stored in a contract owned by a specific crypto wallet, takedowns and sinkholing are far harder: only the deployer can change the contract contents, so defenders can’t simply seize or remove the payload host. - The social-engineering lure is a fake CAPTCHA or fake support/error page. Victims are told to “prove they’re human” by opening Windows Run and pasting the clipboard — which executes attacker-supplied commands locally. A variant dubbed TerminalFix uses the same trick but targets Windows Terminal or PowerShell instead. How the attacks work - After the injected script pulls instructions from the smart contract, attackers rely on heavy obfuscation and abuse of built-in Windows tools to execute payloads with low visibility. Microsoft observed use of conhost, cmd, PowerShell, pcalua, mshta, rundll32, msiexec, curl, WMI, WebDAV and scheduled tasks. - Command hiding techniques include splitting keywords with caret characters, using environment variables to disguise interpreter paths, and launching processes minimized or headless to avoid detection. - The campaign is high volume: Microsoft says thousands of devices worldwide are being targeted each day, and some malvertising chains first redirect users through scam pages before delivering the malicious instructions. Payloads and impact - Once the click-to-execute step succeeds, attackers distribute a range of payloads. Microsoft has seen: - Information stealers such as Lumma Stealer - RATs like Xworm and AsyncRAT - Loaders such as MintsLoader - Remote management tools and other commodity malware - A single successful run can expose credentials, establish persistence, enable lateral movement, and open the door to human-operated ransomware or even domain compromise. Defensive guidance from Microsoft - Enable Microsoft Defender’s network, web, and cloud-delivered protections. - Restrict access to Windows Run and other command-line tools where not required. - Turn on PowerShell script-block logging and enforce application control policies. - Educate users: never paste commands from CAPTCHAs, unsolicited support pages, browser error pages, ads, or emails into Run, PowerShell, Terminal, or Command Prompt. - Use Microsoft Defender XDR for cross-stage detection. Defender SmartScreen and Defender for Office 365 can block malicious pages and phishing before users interact with them. - Microsoft’s detections include alerts such as “Suspicious command in RunMRU registry,” “Possible ClickFix activity,” and “Possible initial access from an emerging threat.” Defender Antivirus flags related activity under Trojan:Win32/ClickFix.* and Trojan:Win32/TermFix.*. - If these detections appear, treat them as potential initial-access incidents: isolate affected systems, investigate credential theft and persistence, and hunt for related activity across the environment. Context: evolving crypto-focused threats - Microsoft’s report follows a June advisory about CryptoBandits, a Windows clipper that spread via malicious .lnk shortcuts, monitored the clipboard every 500 ms for wallet addresses, seed phrases and keys, and replaced copied addresses with attacker-controlled ones while routing communications over Tor. - The clipper and the ClickFix pattern highlight a broader trend: threat actors increasingly blend on-chain infrastructure, browser-based social engineering, and classic Windows abuse to steal crypto and credentials. Other recent examples include StilachiRAT (targeting browser wallets and clipboard data) and SparkCat (using screenshots to locate seed phrases). Binance and others have also warned about clipper families that swap copied wallet addresses. Bottom line for the crypto community Attackers are weaponizing blockchain features — using smart contracts as resilient payload stores — and combining that with highly convincing social engineering to trick users into executing malicious commands themselves. Crypto users, infrastructure teams and defenders should treat unexpected CAPTCHAs, pop-ups and “paste this” instructions as high-risk, harden command execution paths, and apply layered detection and prevention to block both the lure and the underlying on-chain fetch mechanism. Read more AI-generated news on: undefined/news
Anmelden und weiter Inhalte entdecken
Krypto-Nutzer weltweit auf Binance Square kennenlernen
⚡️ Bleib in Sachen Krypto stets am Puls.
💬 Die weltgrößte Kryptobörse vertraut darauf.
👍 Erhalte verlässliche Einblicke von verifizierten Creators.