Citrini Research Favors ONDO, AAVE, UNI, ETHFI, and PENDLE
Citrini Research said tokenizing traditional assets could expand onchain trading, lending, and payment markets. It favors Coinbase, Robinhood, Circle, Securitize, and crypto projects including ONDO, AAVE, UNI, ETHFI, and PENDLE, while also highlighting Hyperliquid, Lighter, and Variational. The report noted that higher onchain volume does not necessarily lift token prices; revenue models, fee allocation, and token-holder participation are more important.
Bitcoin-Denominated Licensed Life Insurer Meanwhile Raises $37.5 Million, Led by Bain Capital Crypto
Meanwhile has raised $37.5 million from existing investors in a round led by Bain Capital Crypto, with participation from Haun Ventures, Framework Ventures, Pantera Capital, Apollo, Northwestern Mutual Future Ventures, and Morgan Creek Digital. The company’s total funding has now exceeded $180 million. Meanwhile is the first licensed life insurer to operate entirely in Bitcoin. Its BTC Life 1-Pay policy targets high-net-worth clients outside the US, and the company has signed 15 brokers across Singapore, Hong Kong, the UAE, and Switzerland. Meanwhile expects its 2026 net long-term underwriting income to more than double from 2025.
Binance to Restrict 8 Services and Delist 22 Tokens in Brazil to Comply With New Regulations
Binance will restrict Brazilian users’ access to eight services, including Binance Loans, Binance Pool, Cloud Mining, margin trading, Launchpool, Megadrop, HODLer Airdrops, and Alpha 2.0, effective October 27 to comply with new crypto asset regulations issued by Brazil’s central bank. The exchange will also stop offering trading services for 22 tokens to Brazilian residents, including XVG, USDE, USTC, DCR, DUSK, PIVX, BB, and MANTRA. Existing eligible lending and margin positions may be maintained, but no new positions may be opened. In addition, Binance will migrate eligible Brazilian users to a local entity within its group by October 29 and adjust its fiat payment, asset trading, and regulatory reporting arrangements.
EDX Markets Partners With VerifiedX to Launch Institutional Spot Trading of Tokenized Bitcoin (vBTC)
EDX Markets, an institutional crypto exchange backed by Citadel Securities, Fidelity Digital Assets and Charles Schwab, announced a strategic partnership with VerifiedX to introduce spot trading of tokenized Bitcoin (vBTC) for institutional investors and joining the VerifiedX network as a validator. Backed 1:1 by BTC and redeemable for native Bitcoin at all times, vBTC supports programmable financial applications, including on-chain payments, lending and asset management without relinquishing underlying Bitcoin ownership or native redemption.
North Korean Hackers Have Stolen So Much Crypto. How Do They Launder It?
North Korean hackers increasingly rely on professional money-laundering networks to convert stolen crypto into usable funds. These intermediaries may take control of stolen assets early, pay attackers after deducting fees, and assume the risks of subsequent transfers and cashing out. Following the $1.5 billion Bybit hack in February 2025, zeroShadow estimated that over $1 billion in stolen funds had been laundered between February and June 2025, though this does not mean the entire amount was converted into fiat. Elliptic traced approximately $200 million through eXch and identified funds routed through cross-chain transfers, USDT conversions, and suspected Chinese OTC services. While blockchain transactions remain traceable, recovering stolen assets depends on cooperation from exchanges, token issuers, and law enforcement.
ETH Falls Below $2,500 as Global 24-Hour Liquidations Reach $759 Million
According to Binance market data, ETH fell below $2,500 at 15:18 on October 8 and is currently trading at $2,467.88, representing a 24-hour decline of 3.64%. BTC is currently trading at $81,333.5, down 2.14% in the last 24 hours. SOL has dropped below $110, currently trading at $108.9, with a 24-hour decline of 6.46%. According to CoinGlass data, in the past 24 hours, a total of 138,889 traders were liquidated globally, with total liquidations reaching $759 million; long positions accounted for the vast majority of liquidations at $692 million.
US Government Address Transfers 12,267 BTC Worth ~$1.01B
According to Arkham data, an address labeled "U.S. Government: Bitfinex Hacker Seized Funds" transferred out 12,267 BTC (valued at approximately $1.01 billion) on October 8 at 13:33 UTC. Over the previous two days, US government-affiliated addresses had already transferred a cumulative total of more than 6,200 BTC to Coinbase Prime.
Highlight Clip: Jeff Yan: If I Were Building a Product Today, I'd Look Into Options
Jeff Yan: If I Were Building a Product Today, I'd Look Into Options Hyperliquid Labs co-founder Jeff Yansaid at DAS Asia 2026 on October 7 that a year ago, he was still unsure whether options traders would eventually all prefer perpetuals, but he now believes the answer is no. Yan said perpetuals already satisfy the needs of many users, but some traders still feel that perpetuals alone cannot express all of their views on the market. In his view, options and perpetuals are therefore more complementary products that serve different purposes. He also said HIP-4 provides a straightforward path for building options protocols on Hyperliquid.
CrowdStrike: Hackers Target South Korean Financial Institutions Using LLMs and AI Tools, Leaking ...
Cybersecurity firm CrowdStrike reported that an unidentified threat actor leveraged the Chinese-developed open-source AI penetration testing tool ARTEX alongside large language models (LLMs) to breach multiple South Korean financial institutions and exfiltrate data between late September and early October. An analysis of exposed server directories revealed a two-tier infrastructure anchored by Hong Kong-based IP addresses, utilizing Claude Code, GLM-5.3, Grok 4.6, and DeepSeek v4.1-flash (accessed via API proxies) to orchestrate attack workflows, with the attacker querying Claude on how to monetize the stolen South Korean datasets via Telegram groups. According to South Korean media estimates, at least seven financial institutions—including KB Kookmin Bank, Shinhan Bank, and Hana Bank—were targeted, resulting in the compromise of personal records belonging to approximately 68,000 individuals, spanning sensitive details such as annual income and loan limits.
US initial jobless claims for the week ending October 3 came in at 197,000, lower than the expected 200,000. The previous week's figure was revised upward from 197,000 to 199,000.
North Korean Hackers Have Stolen So Much Crypto. How Do They Launder It?
Edited by | WuBlockchain, ChatGPT TL;DR Bitget revised the value of the assets involved to approximately $387.5 million, while attribution to North Korea remains subject to further confirmation. On September 25, 2026, Bitget said the revision reflected additional accounting, rather than a new theft, and that some assets had been frozen. Elliptic assessed that the attack was “highly likely” linked to North Korea, but a full technical investigation report has not yet been released. Specialist intermediaries take over stolen funds, potentially allowing attackers to receive payment earlier. According to zeroShadow, more than $1 billion in funds stolen from Bybit was laundered between February and June 2025. Researchers suggest that intermediaries may have assumed control of the funds early, paid the attackers an amount net of fees, and taken on the subsequent risk of asset freezes. This estimate does not mean that the entire amount was converted into fiat currency or represent the attackers’ net proceeds. Token swaps, cross-chain transfers, and mixing make tracing harder and buy time for further transfers. Elliptic found that stolen Bybit funds moved through multiple wallets, exchange services, and cross-chain channels, with approximately $200 million passing through eXch. These operations can lengthen the investigative trail, but they do not automatically erase transaction records or establish that the funds have all been converted into fiat currency. Cashing out relies on over-the-counter trading and settlement networks, while crypto can also be used directly for trade payments. Elliptic said some stolen Bybit funds were moved to Tron, converted into USDT, and then cashed out through suspected Chinese over-the-counter trading services. The MSMT separately documented a case in which a North Korean individual received USDT as partial payment for equipment sales, although any connection to a specific crypto theft requires separate evidence. Tracing funds does not mean they can be frozen or recovered. Native BTC and ETH have no central issuer capable of directly freezing them. Recovery typically requires platform cooperation, action by token issuers, or law enforcement obtaining control of the assets. The U.S. Department of Justice has disclosed the seizure of more than 15 million USDT linked to North Korea-related crypto thefts, but further procedures are required between freezing, seizure, and eventual restitution. On September 25, 2026, Bitget released an update on its security incident investigation, revising the value of assets transferred to attacker addresses from an initial estimate of approximately $351.6 million to approximately $387.5 million. The company said the change reflected additional accounting for transfers involving Zcash, TRON, and other assets, rather than a new theft. Some of the assets involved had been frozen with assistance from industry partners. Blockchain analytics firm Elliptic said on the same day that the attack was “highly likely” linked to North Korea, citing connections between the funds involved and laundering addresses associated with previous North Korea-related crypto thefts. However, this remains an attribution assessment by a research firm. Bitget has not yet released a full technical investigation report. As tracing efforts continue, a familiar question has resurfaced: if transfers of stolen assets are publicly visible and exchanges can identify suspicious addresses, how do attackers turn hundreds of millions of dollars in crypto into usable funds? Follow-up investigations into Bybit and other cases show that the handling of stolen funds has developed a specialized division of labor. Attackers use token swaps, cross-chain transfers, and multiple layers of transactions to complicate tracing, while specialist intermediaries take over the assets and provide exchange, fund substitution, and off-chain settlement services. Understanding this network requires examining both on-chain transaction paths and the people responsible for receiving and making payments behind those transactions. How Specialist Money Launderers Take Over Stolen Funds In February 2025, approximately $1.5 billion in crypto assets was stolen from Bybit. The U.S. Federal Bureau of Investigation subsequently attributed the incident to North Korea and said the attackers had converted some of the stolen funds into bitcoin and other crypto assets, dispersing them across thousands of addresses on multiple blockchains. In a report published in July of that year, security firm zeroShadow said more than $1 billion in funds stolen in the attack had been laundered between February and June. This estimate does not mean that an equivalent amount had been fully converted into fiat currency, nor does it represent the attackers’ eventual net proceeds. The firm’s analysis suggested that professional money launderers may have taken control of the funds at an early stage, paid the North Korean attackers an amount net of fees, and then handled the stolen assets themselves. In its six-month review published in August, Elliptic similarly assessed that professional “money laundering-as-a-service” networks were likely involved from an early stage. Under this model, attackers may receive payment before the original stolen funds complete their subsequent journey. After taking over the assets, intermediaries must continue finding ways to exchange and cash them out, while bearing the risk that the funds will be frozen, seized, or become impossible to move. This also means that funds being continuously tracked on-chain may not remain under the control of the original attackers throughout the process. In addition to establishing where the stolen funds went, investigators need to identify when control changed hands and what the intermediaries delivered to the attackers in return. Chainalysis’ September 2026 investigation into the Xinbi merchant network provided another example of fund substitution. The company said tens of millions of dollars in stolen funds from incidents including Bybit and WazirX passed through the associated merchant network. Some specialist intermediaries accepted readily traceable stolen assets and supplied clients with a separate pool of stablecoins, which also included proceeds from other scams. These transactions bring funds from different criminal activities into the same settlement network. Attackers can reduce their direct involvement in handling stolen assets, while intermediaries profit by charging fees. In this context, “clean assets” primarily means assets whose connection to the original theft is harder to identify directly. It does not mean that their origin has become lawful. Token Swaps, Cross-Chain Transfers, and Mixing Mainly Buy Time Beyond specialist intermediaries, on-chain transfers remain an important part of the laundering process. Elliptic’s early tracing of the Bybit theft showed that attackers rapidly converted some of the stolen tokens into ETH, then continued moving funds through multiple wallets, exchange services, and cross-chain channels. Spreading funds across addresses, changing asset types, and moving between networks increase the work required for investigators to reconstruct the money trail. Mixing and privacy tools further reduce the ability to link incoming and outgoing funds. These operations can raise the cost of tracing, but they do not automatically erase existing transaction records. For attackers, a key purpose of complex transaction paths is to buy time to keep moving funds before they are identified and the relevant institutions are notified and take action. Certain exchange services also became key nodes. In an April 2025 report, Elliptic estimated that approximately $200 million in stolen Bybit funds had passed through eXch, an exchange service that did not require customer identity verification. This figure reflects the volume of funds processed through the service, rather than the amount fully converted into fiat currency. Stolen funds may therefore remain identifiable even after passing through a mixer or cross-chain service. Whether they can ultimately be cashed out also depends on the availability of counterparties willing to accept them and whether those counterparties can provide real-world settlement channels. The Final Destination Is Not Necessarily a Dollar Payment In its six-month review of the Bybit incident, Elliptic said some stolen funds that remained traceable eventually reached the Tron network, were converted into USDT, and were then cashed out through suspected Chinese over-the-counter trading services. This suggests that, after the on-chain transfers, OTC traders connecting crypto assets with the fiat financial system still play an important role. For platforms that conduct customer due diligence and transaction monitoring, accepting funds linked to a major crypto theft creates compliance risks. Illicit intermediaries, however, operate businesses that include taking on such assets and finding subsequent settlement channels. A case disclosed by the U.S. Treasury Department in 2020 shows that this division of labor has existed for years. Treasury alleged that two intermediaries received a combined total of more than $100 million in stolen exchange funds from North Korean-controlled accounts. One of them moved more than $34 million worth of the funds through bank accounts linked to exchange accounts. The services these intermediaries provide include access to accounts, counterparties, and liquidity. On-chain records may show assets entering a particular address, but confirming the agreed exchange rate, the payment method used on the other side of the transaction, and the ultimate beneficiary often requires platform records and off-chain investigation. Crypto assets are also used beyond conversion into fiat currency: they can serve directly as a means of payment in trade. A report published in 2025 by the Multilateral Sanctions Monitoring Team (MSMT) documented cases in which North Korean individuals used or planned to use USDT to settle trade transactions involving military equipment, raw materials, and other goods. In one case, a North Korean procurement official sold equipment to a customer in Laos, who paid part of the purchase price in USDT. The case shows that stablecoins have been used to receive payment for some trade transactions. However, establishing a direct connection between such transactions and a particular crypto theft requires separate evidence tracing the funds. Why Visible Funds Can Still Be Difficult to Recover Blockchain analysis can trace portions of a transaction path and identify associated addresses, but publicly available transaction records do not give investigators control over the assets. Elliptic noted that some token issuers have the ability to freeze assets, while native BTC and ETH have no central issuer capable of carrying out equivalent freezes directly. Consequently, even if an address has been widely flagged, outside parties cannot simply transfer its assets back on the basis of that designation. Recovery usually requires reaching a point where control over the funds can actually be exercised. This may occur when assets enter a custodial platform that cooperates with an investigation, an issuer takes action involving tokens with freeze functionality, or law enforcement lawfully obtains control of the relevant accounts, devices, and assets. Identifying addresses, coordinating institutions, and completing cross-border procedures all take time, during which the funds may continue moving. Frozen assets are also not the same as assets returned to victims. In November 2025, the U.S. Department of Justice disclosed that the FBI had seized more than 15 million USDT in March of that year. The funds were connected to four crypto platform thefts in 2023 allegedly carried out by North Korea’s APT38. The Justice Department subsequently filed a civil forfeiture complaint, seeking to return the assets to their lawful owners. These cases suggest that the ability to realize value from North Korea-related crypto thefts rests on a combination of on-chain transfers and specialist settlement networks. Token swaps, cross-chain transfers, and mixing make tracing more difficult, while intermediaries convert stolen funds into value that attackers can use. Recovery efforts therefore need to address transaction paths, service-provider accounts, and intermediary networks together. The amount stolen reflects the value of the asset losses at the time of the incident. How much the attackers ultimately receive depends on subsequent settlement arrangements, changes in crypto prices, intermediary fees, and the amount frozen or recovered while the funds are moving. Follow us Twitter: https://twitter.com/WuBlockchain Telegram: https://t.me/wublockchainenglish
ESMA Tells EU Crypto Firms to Exit Non-MiCA Stablecoin Exposure by Jan. 8
The European Securities and Markets Authority on Thursday urged national regulators to require crypto-asset service providers to fully exit stablecoin-related exposure that does not comply with MiCA within three months, and no later than Jan. 8, 2027. The guidance covers trading, custody, transfers and investment advice. Licensed firms may offer only limited wind-down services, such as liquidation, closing-out exchanges and withdrawals, and only under close supervision.
Foundry CEO Mike Colyer to Step Down, Stay On as Adviser for Six Months
Foundry, operator of Foundry USA, the world’s largest bitcoin mining pool, said founder and CEO Mike Colyer is stepping down after seven years. He founded Foundry in 2019 and built it from a one-person team into the largest pool operator serving institutional miners. He will remain a strategic adviser for six months to help the transition and the search for a new CEO.
Deus X Capital to Shut Down and Wind Up by Jan. 31, 2027
Crypto and fintech investor Deus X Capital has stopped operating and will complete a formal wind-up by Jan. 31, 2027, CoinDesk reported. Former Galaxy Digital executive Tim Grant led the firm. Backer the Morton family is splitting up: Shane Morton has set up AI firm Darius, where Grant will be CEO of TensorX; Owen and Jason Morton have set up markets firm 95. Deus X launched in October 2023 with $1 billion available for deployment. It incubated institutional DeFi protocol Solstice Labs and was a major backer of market maker Alpha Lab 40 and prime broker Cor Prime.
Ethereum Researcher Warns AI Could Break Crypto Wallet Security Before Quantum Computers Do
Ethereum Foundation researcher Justin Drake urged the crypto industry to prepare for "bunker mode," warning that advances in AI and mathematics could potentially break ECDSA within months rather than years, even before quantum computers become a threat. He recommended gradually moving assets to fresh addresses with unexposed public keys and rotating keys after signing transactions, while cautioning against panic or rushed migrations. Drake also urged major institutions to strengthen cold storage security, critical signers to consider hash-based signatures such as SPHINCS, and Ethereum developers to accelerate the transition toward hash-based cryptography.
According to SoSoValue, U.S. spot Bitcoin ETFs recorded $487 million in net outflows on October 7, led by BlackRock's IBIT with $208 million in withdrawals. Spot Ethereum ETFs saw $161 million in net outflows, with BlackRock's ETHA accounting for $116 million.
Kyrgyzstan Ends State-Backed Stablecoin Project Months After UK Sanctions
Kyrgyzstan has decided to shut down USDKG, its $50 million state-backed gold stablecoin project, and ordered the liquidation of issuer EVA and Coin Nomad Exchange, the country's first state-owned crypto exchange. Launched in November 2025, USDKG was pegged 1:1 to the U.S. dollar and backed by physical gold, primarily for cross-border payments. The UK sanctioned its issuer in May 2026 over alleged support for Russia.
Highlight Clip: Vitalik: AI Is Becoming Capable of Hacking All Kinds of Systems
Vitalik: AI Is Becoming Capable of Hacking All Kinds of Systems On October 6, 2026, Ethereum co-founder Vitalik Buterin said at the OKX NOWevent in Singapore that AI is beginning to demonstrate powerful hacking capabilities, including escaping sandboxes, taking down websites, and discovering software vulnerabilities. At the same time, AI is helping Ethereum identify bugs and perform formal verification at both the protocol and application layers, improving asset security and data privacy. He argued that higher levels of security will become essential, as AI could discover any exploitable vulnerability in a system.
Hyperliquid Labs Begins $330 Million HYPE OTC Distribution, Transfers Half to Buyers
Hyperliquid Labs, the team behind leading decentralized perpetual futures exchange Hyperliquid, completed the seven-day unstaking of 3.75 million HYPE worth about $330 million, according to Onchain Lens. The tokens were moved to the team's spot balance for an OTC deal with an undisclosed institution rather than public-market sales. So far, 1.875 million HYPE, or 50% of the allocation, has been transferred to five OTC buyer wallets, each receiving 375,000 tokens.
Highlight Clip: Michael Saylor:$100 Billion in Bank Credit Could Equal 10 Years of New BTC Supply
Michael Saylor:$100 Billion in Bank Credit Could Equal 10 Years of New BTC Supply Strategy founder Michael Saylor said in an October 2 interview with the Bitcoin Policy Institute that for Bitcoin to reach its full potential as a digital commodity and digital capital, banks need to be allowed to custody BTC, extend credit against it, and operate under rules that do not discourage banks and insurers from handling digital assets. Saylor argued that if the U.S. wants to remain financially competitive and continue to prosper, it should embrace the digital transformation of assets and allow digital capital to become more deeply integrated into the banking and insurance systems.