ChainGPT's advanced AI model scans the web and curates short articles on Bitcoin (BTC) every 60 minutes, informing you effortlessly. https://www.ChainGPT.org
HTX Denies Sending "Mystery" Micro‑Deposits, Probes Possible Address Poisoning
HTX says it did not send the small “mystery” crypto deposits that some community members have linked to the exchange, and it’s now investigating the origin and attribution of the transactions. What happened - Over the past days, screenshots circulated showing tiny unsolicited crypto deposits appearing to come from addresses labeled as linked to HTX. Some community members called the activity “address poisoning.” - HTX’s initial internal review found that the exchange’s official channels had not initiated those transfers or run any related tests. The company says it is digging into where the funds came from and whether blockchain labeling or attribution methods created a false connection. - The exchange declined to speculate before finishing the probe and promised to share confirmed information, but gave no timeline or technical report commitment. Unconfirmed reports and questions - Several details remain unverified. Some users said accounts faced restrictions after receiving the deposits; others posted screenshots. One report said a user received 7.5 USDT into a Coinbase account and was later asked to explain the funds — but Coinbase has not commented publicly and no permanent freeze tied to the transfer has been shown. - HTX’s statement did not name the blockchain, sending addresses, transaction hashes, the number of recipients, or whether any customer assets were at risk. - No independent blockchain security researcher has publicly tied the disputed transfers to a specific operator, and no confirmed losses have been reported in connection with these particular transfers. Why attribution can be misleading - Blockchain explorers and analytics companies label addresses using public ownership disclosures, transaction patterns and clustering heuristics. Those labels are useful leads but are not definitive proof that a named exchange authorized a transfer. - Addresses used by exchanges can include deposit addresses, consolidation wallets, payment processors and intermediaries — all of which complicate attribution. HTX says its review will consider “address tagging” and on‑chain source identification, leaving open the possibility that third‑party services misattributed a sender to HTX. What is address poisoning? - Address poisoning typically involves an attacker creating a lookalike address, sending a small or zero‑value transaction to plant that address in a victim’s transaction history, and hoping the victim later copies the planted address without checking it carefully. - Small unsolicited transfers alone don’t prove poisoning. Investigators need to determine whether a sender truly resembles a trusted counterparty and whether the transfer was intended to manipulate a recipient’s history. - There was a separate, previously reported case in which a user lost 100,000 USDT after copying a planted lookalike address — that incident included a confirmed misdirected payment, unlike the activity HTX is currently investigating. Broader context: automated compliance checks - The reports arrive amid broader concerns about automated compliance screening. In prior coverage, users said transactions were blocked or funds restricted after compliance tools flagged exposure to HTX‑linked addresses. Those earlier measures involved sanctions screening and do not prove they’re connected to these small deposits. - Platforms may request information or delay access when monitoring systems detect unfamiliar counterparties or links to flagged addresses. Such requests are not the same as an account freeze, and calling every compliance check a “freeze” risks overstating events. What should HTX and the community do next - HTX needs to identify the sending addresses, establish who controls them and explain the transfers’ purpose. Publishing transaction hashes and sending addresses would allow independent analysts to test the exchange attribution and search for lookalike address patterns. - Meanwhile users should avoid copying destination addresses from transaction histories, verify the full address (not just a shortened display), use saved address books when available, preserve transaction hashes and platform notices for support teams, and be cautious interacting with unsolicited tokens or unknown contracts. Bottom line HTX denies initiating the suspected deposits and is investigating whether mislabeling or malicious actors are responsible. No confirmed losses or account freezes have been publicly demonstrated so far. The situation remains unresolved until HTX or independent researchers produce transaction details and attribution evidence. HTX says it will share findings once confirmed. Read more AI-generated news on: undefined/news
South Korea Blocks Polymarket, Rules Crypto Prediction Markets Constitute Illegal Gambling
South Korea has moved to block Polymarket, the crypto-based prediction market, after regulators concluded the platform creates an illegal gambling environment for domestic users. What happened - On Aug. 18, South Korea’s Broadcasting, Media and Communications Review Committee voted to issue a corrective request ordering access to Polymarket be blocked. The committee determined parts of the platform fall under prohibited activities in the National Sports Promotion Act and could facilitate gambling as defined in the Criminal Act. - The decision followed weeks of review and a July hearing in which Polymarket was given a chance to present its case. Why regulators acted - The committee examined how Polymarket creates markets, sets trading rules, processes crypto deposits/withdrawals, and settles trades. It also reviewed transaction fees and concluded the platform’s operator economically benefits from share trading. - Regulators focused on the market mechanics: users trade shares tied to outcomes—from politics and elections to sports and weather—and payouts can produce extreme, winner-takes-all gains or losses based on events users can’t control. The committee said that structure encourages speculative gambling behavior. - Officials noted that although trades occur between users, Polymarket manages market creation, trading rules and the infrastructure for deposits, withdrawals and settlements. That role, plus fee revenue, led regulators to treat the platform as facilitating gambling or operating a gambling venue. Polymarket’s defense and the regulator’s rebuttal - Polymarket argued it is non-custodial and peer-to-peer: trades execute via smart contracts, the platform does not hold or manage user funds, and it does not issue sports-betting tickets—so it should be outside Korea’s gambling laws. - The committee rejected that technical defense. It said decentralized technology, lack of a Korean-language service, or absence of KRW payment options do not exempt a service from Korean law if local users can still access and use it via crypto. - Regulators pointed to markets specifically relevant to Korea—such as a contract tied to rainfall in Seoul—as evidence the platform still serves domestic users despite Polymarket having removed a Korean-language interface and barred KRW payments. Enforcement context and prior probes - The Aug. 18 corrective request comes after a separate police investigation launched in late May into Polymarket users suspected of illegal gambling through election-related markets—the first known South Korean police probe directly into Polymarket activity. - Before issuing its recommendation, the review committee solicited input from the National Police Agency, the National Gambling Control Commission and the Korea Sports Promotion Foundation; all raised concerns that Polymarket’s operating structure could fall within gambling and gambling-venue rules. Global regulatory pressure - South Korea’s action is part of a wider international clampdown on Polymarket. India ordered blocks in May and had earlier issued advisories to ISPs and VPN providers; the Czech Republic ordered blocks in July. France blocked access beginning July 16, citing risks of big losses and bet manipulation. The article also notes blocking measures reported in Australia and Germany (August and September 2025 in prior reports), and previous restrictions in Argentina and Spain. - Regulators abroad have similarly flagged concerns about stablecoin payments, offshore betting flows and capital moving outside monitored financial channels. What this means - The committee concluded that Polymarket’s markets expose Korean users to speculative, winner-takes-all financial structures tied to uncertain events and that an access block is necessary to protect users. The corrective request instructs domestic internet providers to restrict access. - Polymarket maintains its non-custodial, smart-contract model distinguishes it from conventional gambling operators; South Korean authorities have said delivery method and technical architecture don’t negate the application of domestic law when services reach local users. Implication for the industry - The case highlights how regulators are interpreting decentralized and crypto-native prediction markets through existing gambling and sports-promotion laws. For prediction-market operators and users, it underscores increasing scrutiny and a patchwork of national approaches that can limit access even when services claim technical decentralization. Read more AI-generated news on: undefined/news
Minnesota: xAI's Grok Imagine fuels "digital sexual violence" — AI image ban likely to hold
Minnesota has escalated its legal fight with Elon Musk’s xAI, telling a court that the startup’s Grok Imagine tool has created an “unparalleled marketplace for digital sexual violence” and that xAI is unlikely to win its bid to block a new state law limiting AI-generated sexualized images of identifiable people. What the law does HF-1606, passed by the Minnesota legislature in April and effective August 1, bars platforms and software developers from enabling users to create realistic images that show intimate body parts not present in the original photo of an identifiable person. Violations can carry penalties of up to $500,000 per image. The statute was driven in part by reports of a man who used social media pictures to produce sexualized images of more than 80 women. xAI’s challenge In July, ahead of the law taking effect, xAI sued Minnesota Attorney General Keith Ellison seeking to block enforcement. The company argues HF-1606 runs afoul of the First Amendment and is overly broad — it could, xAI says, sweep in protected content such as images of shirtless men, swimmers, and political satire. xAI’s complaint also warned there is “no safe harbor” for providers of general-purpose creative AI tools, arguing the law could impose liability even when depicted subjects consented, created the images themselves, or when images were never shared. Minnesota’s response In a Friday court filing, AG Ellison pushed back, saying xAI has not shown it will suffer irreparable harm and is unlikely to prevail on constitutional grounds. “With Grok Imagine, X.AI has created an unparalleled marketplace for digital sexual violence that poses virtually no barrier to entry,” Ellison wrote, arguing the state must be able to target the technology that enables digital sexual victimization. Incidents and enforcement actions Grok has already faced intense scrutiny. A watchdog group estimated the tool generated more than 23,000 sexualized images of children over an 11-day period, prompting probes in multiple countries. In March, three California minors joined lawsuits alleging Grok was used to turn their photos into AI-generated child sexual abuse material. xAI says it suspended over 50,000 accounts and filed more than 70,000 reports with the National Center for Missing and Exploited Children in 2026. Why this matters beyond Minnesota The case will hinge on whether HF-1606 is treated as a regulation of speech or a regulation of technology and platforms — a distinction with wide ramifications. A ruling upholding Minnesota’s law would create a state-level precedent for holding AI developers and platforms accountable for misuse of image-generation tools. For the broader tech and crypto communities, that precedent could influence how decentralized apps, marketplaces, and AI-driven creative tools manage moderation, liability, and design choices to avoid similar legal exposure. Where things stand The litigation will determine how far states can go in restricting AI capabilities to protect privacy and prevent abuse. Until a court rules, the dispute underscores a growing regulatory appetite to rein in misuse of powerful generative systems and the complex legal questions that follow. Read more AI-generated news on: undefined/news
U.S. Treasury Proposes GENIUS Rule: Stablecoin Issuers Must Be Licensed, Cross-Border Sales Curbed
The U.S. Treasury on Monday unveiled a rulemaking that could reshape who is allowed to issue and sell stablecoins in the United States, spelling out key provisions of the GENIUS Act that became law last summer. What the proposal does - Implements Section 3 of the GENIUS Act and sets licensing and market-access rules for payment stablecoins. - As of January 18, 2027, stablecoin issuers generally must hold a federal or state license to operate in the U.S. - Foreign-issued stablecoins may be sold on U.S. platforms only if the overseas issuer complies with U.S. legal orders and any relevant bilateral agreements with the issuer’s home country. - Starting July 18, 2028, broader limits would typically bar crypto exchanges and other digital-asset platforms from selling stablecoins to U.S. customers unless the coin is issued by a “permitted payment stablecoin issuer.” Treasury’s framing Treasury Secretary Scott Bessent framed the move as follow-through on the GENIUS Act and a step toward regulatory clarity. “President Trump and Congress delivered the GENIUS Act, establishing a landmark framework and clear rules of the road for payment stablecoins, and Treasury is moving quickly to implement that framework,” he wrote on X. Bessent said the rules should give businesses certainty, reinforce the U.S. dollar’s role globally, and invited public input. What counts as a violation The proposal lists types of conduct that could be treated as violating the rules, including: - Actively soliciting U.S. buyers or advertising a stablecoin as available to U.S. customers. - Agreeing to a sale after receiving an unsolicited inquiry from a U.S. buyer. - Helping buyers evade geographic restrictions (for example, circumventing IP checks). Timing for public feedback The comment period runs until October 19, 2026 — 60 days after publication in the Federal Register — giving industry participants and stakeholders a chance to weigh in. Broader regulatory context This proposal arrives as multiple federal agencies roll out GENIUS-related rules: - In February, the Office of the Comptroller of the Currency proposed rules on stablecoin issuance and oversight. - In April, the FDIC proposed requirements for reserves, redemptions, capital, and risk controls. - Also in April, Treasury put forward anti-money laundering and sanctions proposals requiring issuers to report suspicious activity and retain the ability to block or freeze transactions. Industry pushback Some crypto stakeholders have already warned about the ripple effects of strict rules. In June, Paradigm and the Hyperliquid Policy Center cautioned that making issuers responsible for stablecoins once they circulate in secondary markets could push projects away from decentralized finance. Why this matters If finalized, the rules would narrow which entities can legally offer stablecoins to U.S. customers and tighten oversight of cross-border issuers — a major development for exchanges, wallet providers, and projects built around payment stablecoins. The Treasury is seeking public comment as it moves to translate the GENIUS Act into enforceable regulations; watch the Federal Register for the proposal’s formal posting and next steps. Read more AI-generated news on: undefined/news
Blockchain Association Urges SEC to Repeal Rules 611/610(e), Clearing Path for Tokenized Securities
The Blockchain Association has told the U.S. Securities and Exchange Commission to repeal two long-standing trading rules it says were written for a pre-blockchain market and could hamper tokenized securities. What happened - On Aug. 18 the Washington-based trade group filed a comment letter backing the SEC’s June 11 proposal (file S7-2026-20) to rescind two provisions of Regulation NMS: Rule 611 and Rule 610(e). The proposal is still under review; no final vote date has been set and neither rule has been repealed. What the rules do - Rule 611 (the Order Protection Rule) was adopted in 2005 to prevent trading venues from executing transactions at prices worse than protected quotations displayed elsewhere, limiting so-called “trade-throughs.” - Rule 610(e) requires exchanges and associations to prevent members from displaying locked (best bid = best offer) or crossed (bid > offer) quotations against protected quotes. Why the Blockchain Association wants them gone - The group says both rules reflect 2005 market structures — slower, order-book centric and fragmented — and don’t fit modern, automated, interconnected trading or tokenized markets that combine execution, ownership records and settlement onchain. - It argues that the “best displayed price” is not always the best outcome for investors once you factor in fees, execution certainty, settlement speed, liquidity and counterparty exposure. Onchain venues can execute and settle together, offer 24/7 trading, faster settlement, greater transparency and new execution models that rigid price-protection rules could block. - The Association asked the SEC to update best execution guidance alongside any repeal. It stressed that removing Rule 611 would not eliminate brokers’ broader duty to seek favorable terms for customer orders. Caveats and dissent - The letter acknowledges blockchain benefits are potential and that onchain settlement still faces real risks: liquidity constraints, smart contract vulnerabilities, network congestion and differing investor protections. - SEC Commissioner Mark Uyeda warned that rescinding the rules raises questions about best execution, transparency, trading mechanics and investor confidence, calling the proposal the start of a broader market structure review. - Some public commenters opposed repeal, arguing Rule 611 provides objective price protection for retail investors and that relying more on brokers’ best-execution judgments could heighten routing conflicts. The Association counters that an exclusive focus on displayed price can prevent investors from accessing faster settlement or lower total costs. How this fits into the broader tokenization picture - The Association’s letter does not seek exemptions from federal securities laws; it urges that compliant onchain trading systems be allowed to meet regulatory duties through technology-appropriate methods. The SEC has repeatedly said tokenized securities remain subject to existing securities laws. - Tokenization activity in the U.S. has continued within regulated frameworks: examples include Ondo Finance placing a BlackRock ETF and Micron shares on Ethereum while retaining traditional custody of the underlying assets, and Kraken-backed xStocks launching an onchain engine for over 70 tokenized equities across Ethereum and Solana (with availability and investor rights varying by jurisdiction). These projects highlight why the interaction between blockchain execution and legacy market rules is now a live regulatory issue — but they don’t prove that removing Rules 611 and 610(e) would automatically permit any tokenized trading model. Next steps and process - The formal SEC comment period closed (the Federal Register posting listed Aug. 17), and the Blockchain Association announced its submission one day after that date though it states the letter was submitted on time. SEC staff will review comments and may recommend modifying or finalizing the proposal, or leaving the rules intact. Any repeal would require a Commission vote, a Federal Register notice, and specified effective and transition dates. - The Association is also pressing for updated best-execution guidance that covers tokenization and extended trading hours. Separately, FINRA is taking comments through Sept. 25 on possible updates to its best-execution guidance in light of the SEC proposal. Why it matters - The debate isn’t just academic: a final decision would reshape routing and execution practices for national market system stocks — affecting conventional exchanges, alternative trading systems, brokers and market makers — and determine how readily blockchain-native trading models can operate within U.S. markets. Read more AI-generated news on: undefined/news
Kraken Parent Payward Joins Anthropic’s Project Glasswing to Scan Code with Claude Mythos 5
Kraken’s parent company Payward has joined Anthropic’s Project Glasswing and is using the AI model Claude Mythos 5 to hunt for software vulnerabilities across its systems — a move that puts one of crypto’s biggest players at the forefront of AI-assisted cybersecurity. The decision follows a coordinated appeal last week from more than 40 Bitcoin and crypto firms — including Kraken, Coinbase, Block and BitGo — urging Anthropic, OpenAI and other labs to give vetted defenders access to their most powerful models. Organized by the Bitcoin Policy Institute, the letter argued that teams protecting open-source financial infrastructure need frontier AI tools to find and fix flaws before malicious actors can exploit them. Payward said on Monday it will run Mythos 5 scans against its codebase and infrastructure, with any flagged issues routed to its security teams for triage. It is the first reported crypto company to join Project Glasswing and gain access to Claude Mythos 5. “Selection gives Payward’s security division early access to the same class of model, sharpening its ability to combat sophisticated software vulnerabilities and protect millions of customers across the globe,” the company wrote. Payward also said it will responsibly disclose bugs it finds in third‑party open-source software to project maintainers. The company framed the approach as a way to both harden its own financial infrastructure and improve open-source tooling that underpins wide swaths of the crypto industry. Project Glasswing is Anthropic’s vetted cybersecurity program that grants qualified organizations access to its most capable cyber models. Launched in April and expanded in June, Glasswing partners have reportedly uncovered thousands of high- or critical-severity vulnerabilities. Anthropic did not immediately respond to requests for comment. The move comes amid growing evidence that advanced AI can be a double-edged sword for software security. In April, Mozilla said Anthropic’s Claude Mythos flagged 271 vulnerabilities in Firefox during internal testing — an example of how the same models that help defenders can also be used to generate more effective exploits. Payward Co-CEO Arjun Sethi framed the shift as a practical response to a long-standing defensive disadvantage: “Security has always been an unfair game. An attacker needs to find one flaw. A defender has to find all of them, first, every single day. Frontier AI is the first thing that flips that asymmetry. A model can read every line of code the way an attacker would, at machine scale, so we find the flaw before anyone can build the exploit.” Why it matters for crypto: by gaining early access to frontier cyber models, crypto firms can better protect complex, open-source financial infrastructure. But the trend also underscores the urgency behind calls for responsible, vetted access to powerful AI tools so defenders—not attackers—gain the upper hand. Read more AI-generated news on: undefined/news
Tudor Reverses Year‑Long IBIT Sell‑Off With Small Buy; Calls Slashed, Position Still Tiny
Tudor Investment, the macro hedge fund founded by billionaire Paul Tudor Jones, quietly reversed a year-long sell-off of its BlackRock spot Bitcoin ETF position in the second quarter — but the move was modest in size and raises more questions than it answers. What changed - A recent SEC Form 13F filed Aug. 14 shows Tudor held 688,529 shares of BlackRock’s iShares Bitcoin Trust (IBIT) as of June 30, up 109,446 shares (about an 18.9% increase) from 579,083 at the end of March. The stake was reported at roughly $22.9 million. - The purchase interrupts a dramatic reduction that began in 2025: Tudor ended 2024 with more than 8 million IBIT shares (about $427 million), so the current position remains more than 90% below that peak. - Relative to Tudor’s scale — the firm oversees over $100 billion in assets — the $22.9 million IBIT holding is a small allocation. Options and disclosure limits - The filing also shows Tudor slashed its reported IBIT call-option exposure by about 85% during Q2, to the equivalent of 148,000 underlying shares from 998,000 on March 31. Reported put exposure was largely unchanged. - Form 13F filings don’t show option strike prices or expiries and can’t reveal whether reductions came from sales, expirations or other strategy changes. They’re also a quarter-end snapshot of certain U.S.-listed securities and omit short positions, private holdings, direct crypto ownership and intra-quarter trades — meaning the 13F offers only a partial picture of Tudor’s total Bitcoin exposure. How this fits the institutional picture Tudor’s small re-buy comes amid broader activity in IBIT among big institutions: - Morgan Stanley boosted its IBIT holdings by about 23% in Q2 — adding ~3.04 million shares to reach ~16.5 million. The reported value fell from ~$667 million to ~$549 million over the quarter as Bitcoin’s price declined. The bank also disclosed 2.57 million shares of its own Bitcoin Trust (~$43.3 million) after that product began trading in April. - UBS expanded its IBIT stake sharply, holding about 2.5 million shares (~$90 million) at June 30 versus roughly 549,000 shares at the end of 2025 — a roughly 355% uptick over six months. - Some large holders held steady: Harvard Management Company kept 3.04 million IBIT shares unchanged in Q2 (valued at about $101.4 million). Abu Dhabi entities also left positions unchanged: Mubadala with 14.72 million shares (~$490.1 million) and the Abu Dhabi Investment Council with 8.22 million (~$273.6 million). Context and background - Paul Tudor Jones has publicly supported Bitcoin since around 2020, framing it as a potential hedge against monetary expansion and inflation and comparing it to gold as a scarce asset. He has suggested allocating small portions of a portfolio to Bitcoin (historically around 1–2%) while noting its higher volatility. - Tudor’s modest Q2 purchase, combined with a large cut in reported call exposure, could signal a more cautious or differently structured approach to Bitcoin — but without option details or a fuller view of off‑balance-sheet positions, firm conclusions aren’t possible. ETF flows and product details - The disclosure arrived as U.S. spot Bitcoin ETFs recorded renewed inflows in early August. From Aug. 3–7 the products attracted about $853.5 million in net inflows, with BlackRock’s IBIT accounting for roughly $694 million of that total. Daily inflows during the five-day stretch were $170.1M, $211.5M, $244.4M, $128.8M and $98.85M respectively. - IBIT is marketed as a way to gain Bitcoin exposure without direct custody, charging a 0.25% sponsor fee. BlackRock reported an IBIT net asset value of $35.58 per share as of Aug. 14. Bottom line Tudor’s small Q2 purchase ends a sustained sell-down of its IBIT holding but doesn’t restore its prior exposure. The sharp reduction in reported call options is noteworthy, yet 13F limits make it impossible to fully interpret Tudor’s Bitcoin view. Meanwhile, other large institutions continued to adjust or increase their IBIT allocations, and ETF inflows into the space showed renewed momentum in early August. Read more AI-generated news on: undefined/news
Torrent Bait: Fake "The Odyssey" Rips Distribute Lumma Stealer, Crypto Wallets at Risk
Pirated copies of the newly released film The Odyssey are being used as bait to spread Lumma Stealer, a dangerous info‑stealing malware that specifically threatens crypto wallets, passwords and active browser sessions. What happened - Bitdefender researchers reported on Aug. 6 that fake Windows executables posing as high‑quality movie rips began circulating days after the film’s release. Filenames mimic familiar torrent labels—1080p, WEBRip, Blu‑ray, H264—examples include “the odyssey 2160phd (2026) engsubs eztv.exe,” “the odyssey 2026 1080p h264-djt.exe,” and “the odyssey 2026 1080p webrip-lama.exe.” - The files are .exe programs, not video files. When run, they launch Lumma Stealer rather than a player. Bitdefender said its products blocked the detected samples for its customers but warned other variants and filenames are likely circulating. How the disguise works - Attackers make the executables look like media players by changing the file icon (often to a VLC-like icon) and relying on Windows’ default hiding of known file extensions so victims see what looks like a movie file named “.mp4” but with a hidden .exe extension. - Torrent users often expect odd filenames, compressed bundles or bundled players, which makes the malicious files blend in and lowers suspicion. What Lumma Stealer does — and why crypto holders should care - Once executed, Lumma Stealer harvests browser passwords, saved payment info and autofill data, remote‑desktop credentials, and critically, cryptocurrency wallet data and seed phrases. It also steals browser authentication cookies. - Stolen cookies can let attackers hijack active sessions—even if the victim uses MFA—because the cookie can represent a session that’s already passed login checks. - During analysis, Bitdefender observed the samples trying to contact command‑and‑control infrastructure tied to Lumma (domains identified as auditva[.]cyou, myroayy[.]cyou and logmabx[.]click), which the company said it blocked for customers. About LummaC2 - Known as LummaC2, this info‑stealer is believed to have been developed in Russia and is sold as malware‑as‑a‑service on underground markets, letting buyers run theft campaigns without building their own tools. - The Odyssey samples differed from some past campaigns in that they didn’t deploy separate droppers or persistence tools; the operators appeared to collect and exfiltrate whatever data was available during the initial run. - Earlier movie‑themed Lumma campaigns used additional evasion tactics—delayed execution in the presence of security software, encrypted payload delivery via AutoIt, and other checks (for example, a 2025 campaign hiding in fake Mission: Impossible releases). Law enforcement action and scale - U.S. authorities have taken action against LummaC2. In May 2025 the DOJ secured warrants to seize five domains operated by the malware administrators; Microsoft filed a civil case against roughly 2,300 additional domains. - Court filings cited by the DOJ said the FBI identified at least 1.7 million instances where LummaC2 was used to steal data, including browser records, email and bank logins, autofill data and crypto seed phrases. Matthew Galeotti, then‑head of the DOJ Criminal Division, said the malware facilitates crimes including fraudulent transfers and cryptocurrency theft. - Despite domain seizures and advisories from CISA and the FBI, Bitdefender’s 2026 discovery of new Lumma‑linked domains shows campaigns continued after those enforcement actions. Bitdefender did not provide a victim count or crypto loss estimate for the Odyssey incident. Other delivery methods and ongoing threats - Movie torrents are just one vector. Recent campaigns that delivered Lumma and other malware include: - A fake CAPTCHA scheme leveraging BNB Chain smart contracts that told victims to paste commands into Windows Run/PowerShell, observed by Microsoft. - Mobile spyware like SparkKitty, which harvested images (including screenshots of wallet recovery phrases) from compromised phones. - Supply‑chain tactics targeting developers, such as TrapDoor packages found across npm, PyPI and Rust repos that aimed to exfiltrate wallet data, tokens and keys. How to stay safe (recommended by Bitdefender) - Stream films and TV through legitimate services instead of downloading unofficial copies. - Never run .exe files advertised as videos; avoid downloading executables from torrent or untrusted sites. - Keep Windows and security software up to date. - Configure Windows Explorer to show file extensions so a fake “movie.mp4” can’t hide a .exe suffix. - If you suspect a compromise, follow guidance from law enforcement and security vendors—CISA and the FBI have published technical advisories and the DOJ has directed affected people to report incidents to the FBI’s Internet Crime Complaint Center. Bottom line for crypto users: avoid temptation to download pirated content—especially executables—and treat any unexpected file that could contain wallet seeds, passwords or cookies as an immediate, high‑risk threat. Read more AI-generated news on: undefined/news
World Liberty Wins OCC Preliminary Approval to Form Trust Bank, Seeks USD1 Stablecoin Takeover
World Liberty wins preliminary OCC approval to form national trust bank, aiming to take over USD1 issuance and custody World Liberty Financial has secured conditional, preliminary approval from the Office of the Comptroller of the Currency (OCC) to organize a national trust bank that would issue the dollar-backed stablecoin USD1, manage its reserves, and provide digital-asset custody across the United States. What the approval means—and what it doesn’t The OCC’s Aug. 14 decision clears the way for World Liberty Trust Company, National Association—a proposed wholly owned subsidiary of Delaware-registered WLTC Holdings LLC based in Bay Harbor Islands, Florida—to be organized. But preliminary approval only permits the company to form the bank; it does not authorize the bank to begin operations. Final OCC authorization is required after World Liberty completes preopening conditions. Conditions the bank must meet before opening include applying for stock in a Federal Reserve Bank, maintaining at least $20 million in eligible capital, and receiving the OCC’s written confirmation that all opening requirements are satisfied. The OCC also warned it could modify, suspend, or withdraw the conditional approval if new information raises concerns. What the bank would do Under its proposed charter, World Liberty Trust would not be a traditional commercial bank—its activities would be limited to trust, custody, reserve management, and related payment services. The bank plans to: - Issue and redeem the USD1 stablecoin for institutional clients nationwide. - Hold and manage the reserves backing USD1. - Provide custody services and allow custody clients to convert approved stablecoins into USD1 using assets already held at the institution. Legal and regulatory basis In its decision, the OCC cited the National Bank Act and the GENIUS Act as statutory authority for national trust banks to provide digital-asset custody and issue payment stablecoins. The agency noted that uninsured national trust banks it supervises had $7.2 trillion in assets under administration as of March 31, including $1.7 trillion in custody and safekeeping accounts. Planned takeover of USD1 issuance and safeguards World Liberty Trust intends to replace BitGo Bank & Trust as the exclusive issuer and custodian of USD1, acquiring the token’s reserve assets and assuming related liabilities. BitGo will remain responsible for USD1 issuance and custody until World Liberty completes the OCC’s conditions. The OCC approved an exemption from certain limits and collateral rules under Regulation W to enable the planned transfer, though federal rules governing bank-affiliate transactions and potential bank-merger requirements could still apply depending on the final transfer structure. Industry context World Liberty joins a string of crypto firms seeking federal trust bank charters. The OCC issued conditional approvals for several applicants—including Circle, Ripple, BitGo, Fidelity Digital Assets, and Paxos in December 2025—and later approved Coinbase, Crypto.com, and Bridge (owned by Stripe). Circle has already completed preopening steps and obtained final authorization in July, underscoring that conditional approval is only an initial step. Political scrutiny and conflict-of-interest concerns The application has attracted intense political scrutiny because of ties to former President Donald Trump and his family. World Liberty’s website indicates a Trump family-linked entity controls about 38% of its equity interests. Critics raised potential conflicts after Trump nominated Comptroller Jonathan Gould in 2025; Senator Elizabeth Warren and others asked the OCC to pause its review until Trump divested his financial interest. Gould faced questioning during a Senate Banking Committee hearing; the OCC stated that career staff reviewed the application and that the Comptroller and staff acted consistently with statutory duties and ethical obligations. The OCC said it received seven public comments from four commenters, including objections that the proposed activities exceeded a national trust bank’s powers and that the public lacked sufficient information. The agency rejected those objections, finding that World Liberty submitted required materials on time and that the comment period complied with federal rules. Legislative response Shortly after the OCC’s decision, Senator Warren and nine other senators introduced the Ending Presidential Corruption in Banking Act. The bill would bar the president, vice president, their spouses, and their children from owning or controlling a bank and would require federal agencies to review approvals issued since Jan. 20, 2025. “This is the most brazen act of self-dealing our financial system has ever seen — and Congress cannot allow it to stand,” Warren said. Foreign investment and national-security questions Congressional scrutiny has also focused on World Liberty’s foreign investors. Reports say an Abu Dhabi-backed entity tied to UAE National Security Adviser Sheikh Tahnoon bin Zayed Al Nahyan purchased a 49% interest in World Liberty for $500 million under a January 2025 agreement. Five Democratic senators asked for hearings into whether that investment influenced later U.S. decisions related to UAE arms sales or access to advanced AI chips. The OCC reviewed these concerns and concluded those foreign investors were not principal shareholders of the proposed bank. Several investors—StringZ Holdings, DT Marks SC, and AMGUS—signed commitments in July promising not to control or influence bank operations (no board seats, hiring control, or access to material nonpublic information). Eric Trump signed one of those commitments for DT Marks on behalf of the Trump family-linked entity. The OCC also restricted how voting rights above certain thresholds could be exercised. Wider market implications and remaining questions Other ties to the UAE have intersected with USD1’s broader circulation. MGX, another Abu Dhabi entity chaired by Sheikh Tahnoon, used $2 billion in USD1 to invest in Binance in May 2025, a transaction that helped swell the token’s supply. A February report citing Arkham Intelligence indicated Binance-controlled wallets and customer accounts held roughly $4.7 billion of USD1—about 87% of a $5.4 billion supply at that time. Binance and World Liberty have denied any improper relationship; Binance noted exchanges routinely custody large amounts of listed assets. Next steps World Liberty must complete the OCC’s preopening requirements and obtain final federal authorization before taking over USD1 issuance and custody. If additional federal merger or affiliate-transaction rules are triggered by the reserve transfer, the bank will need further regulatory clearance. Meanwhile, political and congressional scrutiny, ongoing public debate over foreign investment, and proposed legislation could shape the firm’s path to full authorization. World Liberty’s chairman and president Zach Witkoff framed the plan as concentrating USD1 issuance, custody, and reserve management under one federal regulator: “A national trust bank brings USD1 issuance, custody, and reserve management together under OCC supervision, examined on the same standards that have governed banks for generations,” he said, adding the firm welcomed continuous federal scrutiny. Read more AI-generated news on: undefined/news
Micron Nears $1,000 as Memory Shortage and AI Deals Ignite a Bull Run
Micron is back within striking distance of $1,000, and the market is paying close attention. Where the stock stands - Micron (MU) closed Friday at $971.66, up 2.3% for the day, and briefly reached $999.27 overnight. That’s near the hi from late June when MU spiked to an all-time high of $1,213.37 before a sharp pullback. - Wall Street remains broadly bullish: the average price target sits near $1,260, some models point to $1,473, and street-high estimates go as high as $2,200. Today’s levels imply roughly 22x earnings — a discount to many AI-chip names despite Micron’s strong profits. What’s driving the rally - Tight memory supply is the primary fuel. KeyBanc’s John Vinh — working supply-chain checks across Asia — sums it up bluntly: “Memory shortages remain persistent.” KeyBanc expects DRAM prices to rise 15%–20% this quarter and NAND prices to climb 30%–40%. - Micron’s latest fiscal quarter backs that story. Fiscal Q3 revenue was $41.46 billion, a 346% year-over-year jump, and non-GAAP EPS came in at $25.11 versus analysts’ $21.39 estimate. Those numbers help explain why many forecasts keep Micron comfortably above $1,000. Intel’s potential comeback — real talk, but early - Intel CEO Lip-Bu Tan told the TechSurge: Deep Tech podcast the company is exploring memory architectures that bring memory and CPU closer together on the same package — a shift from his prior view of memory as a commodity. - Important caveat: Intel hasn’t shipped DRAM, NAND, or HBM products yet. The comments signal intent, not immediate competition, so Intel is not yet a credible threat to Micron’s near-term momentum. Micron’s structural advantages - Analysts point to Micron’s leadership in high-bandwidth memory (HBM) and pricing power. UBS analyst Timothy Arcuri called HBM4 and HBM4E pricing “even stronger than our prior expectations,” and UBS models HBM ASPs rising roughly 79% year-over-year. - Strategic long-term deals — notably a June agreement with Anthropic covering memory, storage architecture, and AI infrastructure — add visibility into future demand and supply commitments. Bull case vs. risks - Bull case: record earnings, sustained supply tightness, surging HBM pricing, and strategic AI deals keep the $1,000-plus narrative alive. New Street Research recently upgraded Micron and wrote, “What is happening today breaks from the industry cycles we have witnessed in recent decades,” modeling a possible $2–3 trillion market cap by 2030. - Risks: memory businesses are cyclical. Faster-than-expected capacity additions, a pullback in AI spending, or intensified competition from Chinese producers such as CXMT and YMTC could pressure prices and derail the rally. What to watch next - DRAM and NAND price trajectories (KeyBanc estimates are key near-term markers). - Micron’s upcoming earnings and any updates to long-term supply deals. - Concrete product milestones from Intel — shipments, not just roadmaps — that could change the competitive picture. - Activity from Chinese memory makers and any signs of capacity expansion. Bottom line: Micron’s mix of tight supply, booming HBM pricing, and strategic AI partnerships keep the stock within shouting distance of $1,000. But the industry’s cyclical nature and potential new capacity remain real threats — so the move higher will depend on continued price strength and execution rather than sentiment alone. Read more AI-generated news on: undefined/news
Knaken’s seized crypto sold for €2.2M — 6,300 customers face €10–12M shortfall
Dutch prosecutors have converted cryptocurrency seized from bankrupt Dutch exchange Knaken into euros, realizing €2.2 million — the only cash currently in an estate that faces customer claims estimated between €10 million and €12 million. What happened - Knaken was ordered into bankruptcy by a Rotterdam court in mid-July after the Dutch Public Prosecution Service sought the company’s liquidation in the public interest. Prosecutors alleged roughly €7 million in customer funds could not be accounted for, and the court found the company lacked sufficient assets to repay users in full. - The company had already stopped operating in early June, locking roughly 6,300 former customers out of its app, trustee Carl Hamm told regional broadcaster Rijnmond. - Prosecutors sold seized crypto holdings and declined to disclose their reasoning; Rijnmond said authorities likely relied on Dutch rules that allow seized property to be sold if it risks losing value. Hamm said he understood the move because “the value of cryptocurrency is completely unpredictable.” Why customers may get little back - Hamm estimates customers deposited between €10 million and €12 million into Knaken, while the bankruptcy estate now holds only €2.2 million after the sale. - The trustee says Knaken’s model and bookkeeping left customers with euro claims rather than direct ownership of specific coins. He described a common transaction where a €100 deposit incurred a €1 fee and Knaken would buy a €99 position via an exchange — legally the crypto belonged to Knaken and customers held a claim on its euro value. - Hamm also says Knaken did not maintain enough cryptocurrency to match the balances customers saw in their accounts; funds for investments and operating expenses “long ended up in one pot.” Owner disputes trustee’s account - Knaken owner Ronald J. rejects the portrait of commingled funds and says Knaken operated as a broker: every order, he says, was routed through a liquidity provider with recorded order IDs, timestamps and execution prices. He called claims that customer money was broadly uninvested “outright incorrect and damaging.” - Ronald J. conceded that part of customer exposure was not covered, but he disputes Hamm’s €10–12 million estimate. During the bankruptcy hearings the court was told he transferred about €2.3 million from Knaken to another company he controls; he says that firm handled marketing and supplied financial records showing no evidence he personally enriched himself. Legal and customer pushback - Some customers and their lawyers object to the prosecutors’ sale of the seized crypto, arguing ownership questions should have been resolved first. One lawyer likened the situation to a garage selling someone’s parked car and the owner receiving nothing. - Prosecutors have said they had valid reasons for the sale but have not publicly detailed them. Hamm, the trustee, says fixing the holdings’ value in euros makes the estate’s position clear as he continues to assess creditor claims, company records and potential recoverable assets. Background and wider context - Knaken’s troubles predate the recent bankruptcy: the platform suffered a theft of 23 BTC in 2020, which the owner says ultimately cost the company millions (23 BTC were worth roughly €140,000 at the time). - The exchange had high-profile sponsorships with Dutch football clubs — including Feyenoord, Sparta, Heracles and Heerenveen — affiliations that reassured some customers but are now being criticized. - Knaken was operating without the authorization required by the Dutch Authority for the Financial Markets (AFM) for covered crypto services. Its collapse came just after the EU’s MiCA transition ended on July 1, a rule change that required many firms to secure authorization as crypto-asset service providers and introduced new requirements for governance and customer asset safeguards. - Other firms have since been approved under MiCA: for example, BitPay obtained Dutch MiCA authorization in July. Next steps Trustee Carl Hamm continues to investigate how customer funds were handled, how much crypto Knaken actually held against account balances, and whether additional assets can be recovered. Ronald J. maintains most positions were backed via the liquidity provider, while accepting that an uncovered portion exists. Meanwhile, 6,300 former customers have been warned to temper expectations about recoveries as the bankruptcy process proceeds. Read more AI-generated news on: undefined/news
Harmony Proposes Chain Rollback After Forged ONE Mint, Wiping 109k+ Transactions
Headline: Harmony proposes chain rollback after forged ONE spreads — plan would erase 109k+ user transactions Harmony has proposed rolling its blockchain back to two checkpoints from Aug. 11 after a forged mint of ONE tokens propagated across the network. The recovery plan would discard all blocks after those checkpoints — including more than 109,000 regular transactions — in order to remove the illegitimate supply and restore a single, reviewed chain state for validators. What Harmony is proposing - Validators would preserve shard 0 block 92,730,034 and shard 1 block 94,978,278, both stamped 11:25:37 p.m. UTC on Aug. 11, and restart the network from replacement databases built around those checkpoints. New blocks would begin at heights 92,730,035 (shard 0) and 94,978,279 (shard 1). - Client v2026.1.2 will be set to reject the abnormal block hashes linked to the incident so validators won’t accept the affected history after the restart. - Harmony identified the first confirmed forged mint at shard 0 block 92,730,036. Block 92,730,035 had no regular or staking transactions, receipts or gas usage and shared the same state as 92,730,034; Harmony chose 92,730,034 as a one-block safety buffer and because recovery artifacts were prepared around that block. Why Harmony is replacing databases rather than “rewinding” Harmony says its in-place –revert function mainly moves chain heads and can leave later receipts, indexes, snapshots and cross-shard data intact. Those remnants, the team warned, could preserve an attack route or cause validators to reach inconsistent states. A full replacement database provides a single, reviewed state for all validators to resume consensus from. Options considered and rejected - Burning or repairing the forged ONE was rejected because much of the supply already flowed through exchanges, DEX pools, contracts and many wallets — removing tokens at individual destinations risks affecting unrelated users’ funds. - A blacklist was dismissed because it would leave the forged supply in existence while potentially restricting wallets that hold legitimate assets. - Selective transaction replay was ruled out because the replacement chain state would differ from the discarded chain, so identical transactions might have different outcomes. - Token migration was considered but would be significantly more disruptive. Scale and user impact Harmony built a shard-0 archive spanning blocks 92,730,035 through 92,871,662 (141,628 consecutive blocks) to measure the rollback impact. The archive contained: - 109,126 regular transactions and 315 staking transactions, with 109,441 exact transaction-to-receipt matches. - 95.80% of regular transactions (104,545) were classified as automated activity. - DEX automation accounted for 99,863 transactions: 75,430 successful swaps and 11,804 failed bot attempts. The team cautioned that the number of discarded transactions is not the same as the number of affected users. Only 22 regular transactions were simple native transfers with no obvious dependencies in the available data; 860 raised questions about balances, nonces or later spending; 80,630 depended on contract or blockchain state; and 27,614 were failed transactions, incident-linked activity, or movements involving exchanges, bridges and consolidation routes. All 315 staking transactions also depend on chain and epoch state and therefore can’t be trivially replayed. Tracing the forged ONE Harmony’s investigators mapped the flow of the minted ONE. One wallet attempted 534 transfers of 5 billion ONE each within 106 seconds; 477 transfers succeeded, moving 2.385 trillion ONE. Tracing followed funds through standalone wallets, exchange accounts, DEX routers and pools, liquidity provider positions, bridge contracts, wrapped ONE, staking wallets and high-volume service wallets. - The team built a time-ordered graph from the wallets tied to the forged mints and capped attribution to each wallet’s available balance so the same tokens aren’t double counted as they move. - Earlier tracing reconciled more than 99.9% of the forged ONE to wallet or service boundaries; a later model reconciled almost all of the amount and fees up to the chosen cutoff. - Harmony stressed that route coverage does not equate to identifying the individuals controlling destination addresses — many destinations are pooled service accounts or contracts holding funds on behalf of many users. Removability limits and risks Forged ONE sitting in a standalone wallet may be isolatable, but tokens that entered exchange wallets, liquidity pools, bridges, staking positions or other shared balances can’t be safely removed without risking unrelated users’ funds. That significantly limits the amount that can be destroyed or clawed back. Context and precedent Harmony reviewed similar past incidents. In December 2025 Flow revised initial rollback plans after a $3.9 million exploit, favoring targeted burns and phased restarts following pushback from bridge operators and other participants. In June 2022 Harmony itself lost about $100 million from a Horizon Bridge compromise and later worked with exchanges, law enforcement and analytics firms to recover some assets — a history the team says informs its current approach. Investigation and next steps Harmony says an independent third-party security firm corroborated the forged mint and the main fund-flow findings. The project is working with exchanges, bridges and law enforcement to preserve records and assess how discarding post-checkpoint activity will affect counterparties and users. Under the proposed recovery, all blocks after the selected checkpoints — including regular transactions unrelated to the forged mint — would be removed. Implication for users If the rollback proceeds, many automated trades and user transactions executed after the checkpoints would be wiped from chain history. Harmony is coordinating with affected parties to determine next steps and to minimize disruption where possible, but the rollback’s scope means some user activity will be irrevocably discarded on-chain. We’ll continue to monitor Harmony’s recovery decisions and report updates as the team finalizes procedures and coordinates with exchanges and investigators. Read more AI-generated news on: undefined/news
SEC to Pilot 24/7 Tokenized Stock Trading Under New "Innovation Exemption
The SEC is quietly engineering a path to bring U.S. stocks on-chain for round‑the‑clock trading — but it’s being done carefully, with pilots and guardrails rather than a wholesale switch. What’s happening - The U.S. Securities and Exchange Commission is developing an “innovation exemption” that would give selected, regulated platforms temporary relief to test trading tokenized U.S. equities 24/7 while the agency crafts permanent rules. The move is intended to let some firms run limited experiments with tokenized securities under defined conditions without removing those tokens from federal securities oversight. - SEC Chair Paul Atkins has publicly backed using exemptive authority to expand blockchain-based activity for traditional securities. This week he’s expected to meet with government and market stakeholders — including the CFTC, major exchanges, the DTCC and crypto firms — to discuss frameworks and coordination. Why it matters - A blockchain-based venue can settle and transfer tokenized shares continuously, enabling trading during nights, weekends and holidays — outside the normal U.S. market hours of 9:30 a.m.–4:00 p.m. ET. For investors that could mean extra liquidity and access, but it raises major regulatory and market‑structure questions. - The SEC’s exemption would not be blanket approval: it would define which firms qualify, what activities they may conduct, and which existing rules still apply. No final framework, eligibility standards or implementation timeline has been announced. Key regulatory and market issues - Ownership and legal rights: Tokens can be structured in different ways. An issuer‑backed token purports to represent the same share recorded via a different ownership system; a third‑party token may only track a stock price or create a contractual claim against the platform. Transfer‑agent groups and the SEC’s Investor Advisory Committee have warned that some structures may not give buyers direct ownership, voting rights or dividend claims. - Custody and linkage: Regulators will need to ensure any token remains properly linked to the underlying security. If a third party holds the conventional share and issues a separate token, buyers must be able to verify backing and recover assets if an issuer or custodian fails. - Market surveillance and price discovery: The SEC must decide how to detect manipulation, share trading information, and reconcile pricing when token trading overlaps with closed conventional markets. Questions also include best execution, disclosures and routing when the primary market is offline. - Registration and compliance: Depending on how tokens and platforms are structured, participants could face broker‑dealer, exchange/ATS, transfer‑agent, clearing and custody requirements. What’s already been tested - DTC/DTCC no‑action letter (Dec 2025): SEC staff issued a no‑action letter allowing the Depository Trust Company to operate a defined tokenization service for three years under specified conditions. Eligible assets include Russell 1000 equities, major index ETFs and U.S. Treasuries. That letter protects participating firms from enforcement based on the facts laid out, but it is not a permanent rule. - DTCC activity: DTCC says it has assembled more than 100 members and partners to test tokenized equities, Treasuries, collateral, securities lending and margin workflows, and cross‑chain movement while connecting to established custody records. - Nasdaq pilot (Mar 2026): The SEC approved Nasdaq’s pilot allowing selected participants to trade certain tokenized equities alongside conventional shares. Under Nasdaq’s structure the tokenized and traditional versions carry the same rights and pricing and remain inside the national market system. - NYSE rule filing (Apr): The NYSE has also submitted rule changes to permit securities to trade in tokenized form, giving the SEC another regulated‑market model to evaluate. Broader rule changes under review - The SEC is also considering amendments to Regulation NMS — including rescinding Rule 611 (order protection) and Rule 610(e) (access fees) — which could change how orders move between venues. Some crypto and digital‑asset firms argue that existing NMS rules favor continuous order books and may limit alternative execution models such as blockchain auctions. - Ondo Finance filed a public comment (Release No. 34‑105655; File No. S7‑2026‑20) supporting rescission of certain provisions and asking the SEC to refine its economic analysis before adopting changes. Cautions and next steps - Commissioner Hester Peirce has said staff are working on an exemption to allow “limited trading of certain tokenized securities,” and the Investor Advisory Committee has rejected a blanket exemption, demanding clear ownership disclosures and intermediary oversight. - A canceled SEC meeting on Aug. 14 referenced in public filings did not equate to approval of 24/7 token trading; it concerned a separate tailored offering regime for crypto investment contracts. - For investors: tokenizing a stock does not change its legal status — economic reality determines whether something remains a security — and any token that truly represents a share will be subject to securities laws and related obligations. Bottom line The SEC’s innovation exemption would create a structured, experimental route to test whether regulated tokenized markets can safely run around the clock. Regulators, exchanges and incumbents are already piloting tokenization inside established frameworks (DTC, Nasdaq, DTCC, NYSE filings), but widespread 24/7 tokenized trading still hinges on unresolved legal, operational and investor‑protection questions and on the SEC’s final policy decisions. Read more AI-generated news on: undefined/news