BTC $79,828 +3.1%ETH $2,494 +1.9%Fear & Greed 74 Greed

Today at a glance

Exploits at Zilliqa, BounceBit, and Term Finance expose systemic security gaps across exchanges and protocols.

  • Ledger Key ExposureA Ledger bug exposed 6,772 keys and enabled the theft of 683M ZIL; legacy transactions are paused pending EVM migration.#01
  • Authorization FlawBounceBit retired its Layer 1 and reissued BB 1:1 on BNB Chain after a flaw moved 286M BB from nine accounts.#02
  • Governance ExploitTerm Finance lost $8.5M when an attacker acquired voting power to manipulate the protocol.#04

Stories are ranked by impact; the first three are the edition highlights. This edition displays 14 of 271 candidates.

#01
CryptoEdition highlight
8.5

Zilliqa: Ledger Bug Exposed 6,772 Keys, Enabled 683M ZIL Theft

Zilliqa's post-mortem reveals a bug in the legacy Ledger application for Zilliqa discarded eight bytes of entropy when generating nonces, exposing the private keys of at least 6,772 accounts and enabling the theft of 683,130,969.66 ZIL across 66 transactions. Legacy transactions remain paused while migration to Zilliqa EVM awaits an external security audit.

This confirmed hardware-wallet security failure directly compromises user funds, and since already-published signatures cannot be withdrawn, exposed keys remain at risk permanently. It highlights how a subtle randomness bug in a signing implementation can undermine the security guarantees hardware wallets are trusted to provide, affecting ZIL holders using the legacy Ledger app and broader confidence in such devices.

The application generated 40 random bytes per nonce but copied the wrong 32 bytes into the signing buffer, keeping eight zero bytes and discarding eight entropy bytes, forcing the high 64 bits of each affected nonce to zero. Four or more such biased signatures for the same account allow private-key recovery in seconds from public blockchain data; the bulk scan required five signatures, so accounts with exactly four were not counted in the 6,772 figure.

rss · CryptoSlate · · Single source

Background, discussion, and references

Market impact

The affected asset is ZIL itself, so the transmission channel runs through on-chain liquidity and exchange operations: legacy transactions remain paused, deposits and withdrawals tied to the legacy path may be disrupted, and the confirmed compromise of thousands of keys could weigh on user confidence. Broader market impact is likely limited because ZIL is a relatively small-cap asset and the disclosed bug is confined to Zilliqa's legacy Ledger signing path, not the EVM side.

Background

ECDSA is an elliptic-curve digital signature scheme used by many blockchains; its security relies on the nonce (a random number used once) being unpredictable and unique. If the nonce is biased, an attacker who collects enough signatures can solve for the private key mathematically. This Zilliqa incident is similar in kind to the 2021 COLDCARD entropy failure, where a firmware migration caused the wallet to fall back to a deterministic software RNG, dramatically reducing seed entropy. Zilliqa is a blockchain that launched with its own native transaction format and is in the process of migrating to Zilliqa EVM, an Ethereum-compatible environment, which the team says is unaffected by this bug.

References

Tags

#Zilliqa#Ledger#hardware wallet#security#theft

#02
CryptoEdition highlight
8.5

BounceBit Retires Layer 1, Reissues BB on BNB Chain After Authorization Flaw

BounceBit is retiring its standalone Layer 1 and will reissue BB tokens 1:1 on BNB Chain based on an Aug. 19 snapshot, after an authorization flaw enabled the movement of about 286.5 million BB from nine accounts. The new token's gas, staking, rewards, and governance roles have not yet been defined.

This incident shows how protocol-level flaws can force a chain to shut down, leaving token holders exposed to undefined token utility during migration. It also highlights the risks of inherited code from stacks like Evmos and the difficulty of preserving token value across network transitions.

The cutoff is block 20,697,260 at 21:02:35 UTC on Aug. 19; balances below 10 BB will be handled via a later claim portal. The new BEP-20 contract is deployed but its address is withheld until exchange due diligence completes, and the old chain will not be restarted.

rss · CryptoSlate · · Single source

Background, discussion, and references

Market impact

The migration to BNB Chain creates an immediate custody and liquidity channel: BB holders must rely on the new BEP-20 contract, and exchange-dependent users face suspended trading until venues restart. Since the old chain is retired, BB's value now hinges on undefined future utility and BNB Chain ecosystem integration, which could affect market sentiment and secondary-market liquidity for the token.

Background

BounceBit is an EVM-compatible Layer 1 blockchain that pioneered Bitcoin restaking and used a dual-token proof-of-stake model with BTC and its native BB token. The chain, built on an Evmos-derived stack, previously gave BB roles such as gas, staking and validator rewards, platform currency, and governance. The authorization flaw allowed a caller to designate another account as the funding source without approval, compromising 286.5 million BB without exposing private keys.

References

Tags

#security-exploit#token-migration#layer-1#bnb-chain#bouncebit

#03
PolicyEdition highlight
8.5

Zondacrypto CEO seeks leniency in fraud case, report says

Przemysław Kral, head of collapsed cryptocurrency exchange Zondacrypto, has been charged with participating in an alleged large-scale fraud and is cooperating with Polish prosecutors to seek a reduced sentence. His testimony may include details about Zondacrypto's funding of right-wing politicians, according to Polish outlet Onet.

This case highlights the risks of centralized exchanges mishandling customer funds, with estimated customer losses of $650 million. The potential political dimension could expand the scandal beyond crypto, affecting regulatory and political conversations in Poland and beyond.

Prosecutors estimate customers lost at least 2.4 billion Polish zlotys ($650 million), alleging only part of customer funds was used to buy crypto while the rest was transferred to managers' private accounts. Kral denies misappropriation, saying the missing Bitcoin was held in a cold wallet whose private keys were supposed to be with former CEO Sylwester Suszek, who has been missing since 2022.

rss · Cointelegraph · · Single source

Background, discussion, and references

Market impact

The collapse and fraud charges could further erode trust in centralized exchanges, especially in Central and Eastern Europe, potentially pushing users toward self-custody or more regulated platforms. Regulatory scrutiny of exchange political donations and custody practices may intensify, affecting how exchanges operate in the region; the direct impact on token prices is likely limited to sentiment-driven moves in assets associated with the exchange.

Background

Zondacrypto, formerly BitBay, was founded in Poland in 2014 by Sylwester Suszek and grew into one of the largest cryptocurrency exchanges in Central and Eastern Europe. Suszek disappeared in 2022, and the exchange later went offline, leaving client assets stranded. Kral disclosed in mid-April that the exchange could not access a cold wallet holding about 4,500 Bitcoin and has since remained silent on social media. The exchange was a major sponsor of CPAC Poland and spent 37 million zlotys on advertising with broadcaster Telewizja Republika in its final year.

References

Tags

#exchange-collapse#fraud#crypto-regulation#poland#customer-losses

#04
8.0

Ethereum DeFi Protocol Term Finance Hit by Governance Exploit Draining Millions

Term Finance, an Ethereum-based fixed-rate DeFi lending protocol, suffered a governance exploit that drained millions of dollars from its vaults. The incident is a major security setback that directly affects user funds.

The exploit directly exposes the risks of decentralized governance and smart-contract security in DeFi lending. It could shake user confidence in noncustodial fixed-rate lending protocols and underscore the importance of robust governance safeguards across the ecosystem.

Term Finance is a noncustodial fixed-rate liquidity protocol modeled on tri-party repo arrangements, using vault contracts to manage deposited funds. The attack exploited the protocol's governance layer and drained millions from these vaults.

gdelt · crowdfundinsider.com · · Single source

Background, discussion, and references

Market impact

The exploit directly reduces the assets held in Term Finance vaults, shrinking the protocol's total value locked and damaging its credibility as a secure lending venue. This could heighten general security concerns for DeFi lending protocols and affect sentiment around DeFi-related assets, although the scale of any broader market impact depends on the exact losses and the protocol's role in the ecosystem.

Background

In DeFi, governance typically involves token holders voting on protocol parameters, while vaults are smart contracts that automatically manage deposited capital and yield strategies. Term Finance is a noncustodial fixed-rate lending protocol on Ethereum that models its Term Repos on tri-party repo arrangements common in traditional finance. A governance exploit is an attack that abuses a protocol's decision-making or administrative mechanisms to steal funds.

References

Tags

#DeFi#exploit#governance#Ethereum#Term Finance

#05
Crypto
8.0

BitMart weighs restructuring amid unresolved withdrawals and shutdown

On Aug. 21, BitMart announced it is exploring a restructuring with White & Case that could allow phased service resumption alongside creditor distributions, while maintaining its prior Aug. 26 trading shutdown and recommended withdrawal deadline.

This matters because it attempts to offer an alternative to a full wind-down, yet customers still lack a concrete repayment framework, recovery estimate, or timetable. The uncertainty could erode trust in centralized exchanges and intensify regulatory and user pressure on BitMart.

The proposal does not change the 01:00 UTC Aug. 26 halt of spot, futures, and other trading, nor the recommended 05:00 UTC withdrawal submission time. BitMart says late withdrawal requests will move to a separate processing procedure, and the exchange expects to provide another update by Sept. 9.

rss · CryptoSlate · · Single source

Background, discussion, and references

Market impact

The main transmission channel is user fund access and solvency confidence in centralized exchanges. Unresolved withdrawals and vague restructuring terms could push users toward self-custody or other venues, reducing BitMart's liquidity and volumes, while broader market sentiment toward exchange risk may tighten.

Background

BitMart is a centralized cryptocurrency exchange that recently announced a wind-down of its trading services. A restructuring, as proposed, would involve a legal process under which the company could resume some operations while making distributions to creditors. Users' withdrawal requests are subject to identity, security, source-of-funds, sanctions, and other compliance checks, which can delay access to funds. Blockchain investigator ZachXBT has questioned why BitMart cannot simply return customer funds if it has sufficient liquidity.

Tags

#BitMart#exchange-restructuring#withdrawals#user-funds#crypto-exchange

#06
8.0

BitMart suggests restructuring weeks after closure announcement

BitMart has announced it is exploring a potential restructuring plan, which may include the phased resumption of certain operations alongside distributions to creditors. This comes just weeks after the exchange announced it would cease all operations by January 31, 2027.

The shift from total shutdown to restructuring indicates ongoing financial distress at BitMart and raises questions about the safety of user funds. It also underscores broader instability in the crypto exchange sector, affecting user trust and market confidence.

Restructuring counsel White & Case has been hired to assess options, and a roadmap is expected no later than September 9, 2026. BitMart's Chief Product Officer Terence Lee resigned, while CEO Nathan Chow was terminated before the closure announcement and was not informed of it.

rss · Protos · · Single source

Background, discussion, and references

Market impact

The news may heighten concerns over exchange counterparty risk, potentially prompting users to withdraw funds from similar platforms and exerting downward pressure on tokens associated with BitMart. However, as a single exchange event, the systemic market impact is likely limited unless it triggers a broader erosion of trust in centralized exchanges.

Background

BitMart is a cryptocurrency exchange that announced on July 26 it would cease operations by January 31, 2027, leading to panic among users who struggled to withdraw assets. Restructuring is a corporate process for financially distressed firms to reorganize debts and operations, often involving partial business resumption and asset distribution to creditors. The appointment of White & Case is a common step in evaluating strategic alternatives.

Tags

#BitMart#exchange restructuring#insolvency#crypto exchange#withdrawals

#07
Crypto
8.0

Standard Chartered First Bank to Distribute HKD Stablecoin

Standard Chartered, through its venture Anchorpoint, has become the first bank to distribute a Hong Kong dollar (HKD) stablecoin, beginning an institutional rollout in August 2026.

This marks a major milestone in institutional stablecoin adoption, showing that global banks are willing to enter the stablecoin distribution business under regulatory frameworks. It could accelerate the mainstream use of HKD-backed stablecoins in Hong Kong and beyond.

The stablecoin, known as HKDAP, is pegged 1:1 to the Hong Kong dollar under the Linked Exchange Rate System. The rollout begins with institutional clients rather than retail, reflecting a cautious, compliance-first approach.

rss · CoinDesk · · Single source

Background, discussion, and references

Market impact

The news signals growing institutional acceptance of stablecoins, which could increase demand for HKD-pegged stablecoins and related infrastructure. It may also intensify competition among stablecoin issuers and banks in Hong Kong, potentially affecting broader stablecoin market dynamics and liquidity flows.

Background

Stablecoins are digital assets designed to maintain a stable price, typically pegged 1:1 to a fiat currency like the HKD, and are backed by reserve assets such as HKD cash and short-term bonds. Hong Kong has been developing a regulatory framework for stablecoins, and this move by Standard Chartered represents a significant step in integrating stablecoins into the traditional banking system.

References

Tags

#standard chartered#hong kong stablecoin#stablecoin#institutional adoption#banking

#08
Crypto
8.0

Bybit Security Blocks Attempt, Averting $700M User Losses

Bybit's security systems reportedly blocked an attempt that could have cost users approximately $700 million. No specific attack details have been disclosed, and the report comes from a secondary source.

Averted losses of this magnitude highlight exchange security as a critical trust factor in crypto markets. If confirmed, the successful defence could strengthen user confidence in Bybit's safeguards, especially given the industry's history of major exchange breaches.

The $700 million figure refers to potential losses prevented, not actual losses sustained. The original report comes from Kryptomagazin, and no independent confirmation or technical description of the blocked attempt has been published.

google_news · Kryptomagazin · · Single source

Background, discussion, and references

Market impact

Because no assets were actually lost, the direct transmission to crypto prices is limited. However, exchange-security events can affect perceived counterparty risk: a widely reported averted loss may reinforce confidence in Bybit as a custodian, potentially influencing trading flows on the platform.

Background

Bybit is a Dubai-based centralized cryptocurrency exchange known for derivatives and high-leverage trading. In February 2025, the exchange suffered a hack that resulted in approximately $1.5 billion in losses, which was described as the largest cryptocurrency theft on record. Bybit has also faced regulatory warnings in several jurisdictions.

References

Tags

#bybit#exchange-security#crypto#user-funds#incident-prevention

#09
8.0

Ethereum Lending App Term Finance Loses $8.5M in Governance Exploit

Term Finance, an Ethereum lending protocol developed by Term Labs, lost about $8.5 million after an attacker acquired voting power and executed a governance exploit against its vaults. Security firms PeckShield and CertiK confirmed the estimated loss on August 23, 2026.

This incident highlights a novel attack vector in DeFi where governance token voting power, rather than a smart contract code bug, is used to drain funds. It underscores growing risks for lending protocols that rely on off-chain or governance-controlled parameters.

The attacker specifically acquired sufficient voting power to pass a malicious governance proposal affecting Term Finance vaults. The loss was estimated at roughly $8.5 million by blockchain security firms PeckShield and CertiK, with Term Labs confirming the event.

rss · CoinDesk · · Single source

Background, discussion, and references

Market impact

The exploit could pressure Term Finance's total value locked and user confidence as funds exit lending vaults, similar to past DeFi attacks. It may also prompt broader scrutiny of governance design across lending protocols, potentially affecting sentiment and governance token valuations in the Ethereum DeFi sector.

Background

Term Finance is a DeFi lending protocol built on Ethereum that allows users to lend and borrow crypto assets through fixed-rate pools. In many DeFi protocols, governance token holders can vote on protocol parameters such as interest rates or collateral factors. A governance exploit occurs when an attacker accumulates enough voting power to pass harmful proposals, manipulating the protocol's behavior for financial gain.

References

Tags

#ethereum#defi#security#exploit#governance

#10
AI & Tech
8.0

seL4 Security Proofs Complete on AArch64

The seL4 microkernel's formal security proofs have been completed on the AArch64 (64-bit ARM) architecture, extending its verified correctness and security guarantees to this widely used platform. This marks a significant formal verification milestone for the microkernel.

AArch64 is the dominant architecture for mobile, embedded, and increasingly server systems, so proving seL4's security properties on this platform can enable high-assurance deployments in safety-critical industries such as automotive, avionics, and defense. It also demonstrates that large-scale formal verification is becoming practical for real-world production kernels.

The completed proofs cover seL4's security properties on AArch64, but community comments note that they currently exclude MCS (mixed criticality system) extensions and are limited to unicore (single-core) configurations. The verification is a machine-code-level proof, yet side-channel timing attacks are not covered by the result.

hackernews · snvzz · · Discussion · Single source

Background, discussion, and references

Background

seL4 is an open-source microkernel developed by NICTA (now CSIRO's Data61) and the Trustworthy Systems group, and it was the first operating-system kernel with a formal proof of functional correctness. Formal verification uses mathematical techniques to prove that a system's implementation satisfies its specification, eliminating entire classes of implementation bugs. AArch64 is the 64-bit execution state of the ARM architecture, which powers the vast majority of smartphones and many embedded and server systems. Completing these proofs on AArch64 required formalizing the architecture's behavior and the kernel's compiled machine code, a large and complex engineering effort.

Discussion

The comments reflect a mix of skepticism and practical curiosity. One user jokingly predicts a side-channel timing attack that will invalidate the result, while another points out the proof's fine print limits it to non-MCS, unicore configurations. Others discuss real-world seL4 deployments (such as GenodeOS, LionsOS, and a Chinese car maker's hypervisor) and argue that seL4 needs native Linux compatibility to convincingly improve system security.

References

Tags

#seL4#formal verification#AArch64#operating systems#security

#11
Crypto
7.5

Coinbase Launches Tokenized Stocks for Nvidia, Apple, Meta, Alphabet on Base

Coinbase launched tokenized stocks for Nvidia, Apple, Meta, and Alphabet on its Base layer-2 network, available to non-US users. Approximately $4.5 million was minted and $3 million of DEX liquidity appeared on day one.

A major US exchange bringing tokenized equities of well-known tech companies onto a public layer-2 network marks a significant step for on-chain securities. This development could broaden access for non-US investors and test regulatory and market-structure boundaries in the crypto ecosystem.

Chainlink price feeds run 24/5 while the tokenized stocks trade 24/7, creating a potential gap in reference pricing. Base is an Ethereum rollup incubated by Coinbase, processing transactions on its own execution layer while settling through Ethereum.

rss · The Defiant · · Single source

Background, discussion, and references

Market impact

The launch creates a new channel for on-chain demand for synthetic exposure to major US tech equities, likely affecting Base-native DEXs through liquidity flows and the tokenized stock tokens themselves. The reliance on Chainlink price feeds also ties these markets to Chainlink's oracle infrastructure, though no directional price outcome is implied.

Background

Tokenized stocks are blockchain-based tokens that reflect the value of a specific equity, typically issued by creating a token that is backed by real-world shares. Base is an Ethereum Layer 2 network originally incubated by Coinbase, which works by rolling up many transactions off-chain and submitting them to Ethereum in batches. Chainlink price feeds provide external market data used by on-chain protocols to reference real-world asset prices.

References

Tags

#tokenized-stocks#coinbase#base#chainlink#tokenization

#12
Policy
7.5

CFTC and Soldier Spar Over Polymarket Bet Regulation

The US Commodity Futures Trading Commission (CFTC) is asking to file an amicus brief in the criminal insider-trading case against Army soldier Gannon Ken Van Dyke, who allegedly made over $400,000 trading Polymarket event contracts using nonpublic information. Van Dyke's defense attorneys oppose the move, calling the regulator a 'regulatory wolf' seeking to advance its own interests through the back door.

This case puts the legal status of prediction-market event contracts under the spotlight, specifically whether they count as 'swaps' within CFTC jurisdiction. The outcome could influence how US regulators oversee platforms such as Polymarket and Kalshi, affecting their compliance burdens and access for US users.

The CFTC's separate civil case against Van Dyke was stayed pending the criminal proceeding, and he has pleaded not guilty; a trial may begin in late 2026 or early 2027. The CFTC is also running an Advance Notice of Proposed Rulemaking on event contracts, with public comments due by April 30, 2026.

rss · Cointelegraph · · Single source

Background, discussion, and references

Market impact

The regulatory fight centers on whether Polymarket's event contracts are swaps, a classification that would put them under CFTC oversight and could raise compliance costs or restrict US access to prediction market platforms. Market participants exposed to these platforms—and to the crypto tokens used for settlement—could face regulatory-driven changes in liquidity and availability, though the trajectory depends on court rulings and rulemaking.

Background

Polymarket is a crypto-based prediction market where users buy and sell event contracts tied to real-world outcomes, from elections to military conflicts. The CFTC has long debated whether such contracts fall under its authority or constitute swaps, and recently issued a framework proposal aimed at addressing manipulation and asymmetric information. In a related move, a court recently ordered Kalshi to stop offering a broad range of prediction markets in Washington.

References

Tags

#crypto-regulation#CFTC#Polymarket#prediction-markets#legal

#13
Crypto
7.5

Coinbase launches tokenized US stocks on Base with Chainlink price feeds

Coinbase has launched tokenized US stocks as B20 tokens natively on its Base layer-2 blockchain, with Chainlink Data Feeds providing continuous pricing for equities including Nvidia, Apple, Meta and Alphabet.

The official launch from a major US exchange brings US equities into DeFi on Base, expanding 24/7 trading access for eligible non-US users and bridging traditional finance with blockchain liquidity.

Each B20 token represents a direct claim on an underlying share held by regulated broker and custodian Alpaca under an Abu Dhabi Global Market-supervised structure. Chainlink's feeds value each token using the underlying stock price plus a Coinbase-supplied multiplier that accounts for dividends and corporate actions, and Base says more tokenized stocks are planned in the coming weeks.

rss · Cointelegraph · · Single source

Background, discussion, and references

Market impact

The launch could increase onchain trading activity and demand for Chainlink data services on Base, while broadening the RWA market beyond crypto-native assets. Its actual impact on crypto markets will depend on user adoption, regulatory developments, and how much capital flows into Base-based DeFi protocols such as Aave.

Background

Tokenized stocks are traditional securities represented as blockchain tokens, enabling them to be traded onchain and used in DeFi. Base is a layer-2 blockchain built by Coinbase using the OP Stack, settling on Ethereum, and Chainlink Data Feeds aggregate price data from multiple sources via a decentralized network of node operators. According to RWA.xyz, the total value of tokenized stocks is around $2.48 billion, up 5.2% over the past 30 days, with monthly transfer volume reaching $27.28 billion and over 2.1 million holders.

References

Tags

#tokenized-stocks#Coinbase#Base#Chainlink#real-world-assets

#14
Crypto
7.5

Coinbase Launches Tokenized Stocks on Base Network

Coinbase has debuted tokenized stocks on its Base network, joining the race to bring equities on-chain. The move makes traditional stock exposure available as blockchain-based tokens on Base.

As a leading US exchange, Coinbase's entry validates tokenized equities as a mainstream market structure and could accelerate institutional adoption. It also strengthens Base's position as a hub for real-world asset (RWA) tokenization.

Tokenized stocks are blockchain-based digital assets designed to represent economic exposure to traditional shares, and on Base they are traded as tokens. Base is an Ethereum Layer 2 network built on the OP Stack and incubated by Coinbase, offering low-cost, developer-friendly on-chain access.

rss · CoinDesk · · Single source

Background, discussion, and references

Market impact

By bringing tokenized equities onto Base, Coinbase connects traditional stock trading with crypto market infrastructure, potentially increasing on-chain trading volumes and liquidity in the Base ecosystem and the broader RWA tokenization segment. The move could also shape regulatory and custody expectations for tokenized securities in the US.

Background

Tokenized stocks are part of the broader real-world asset (RWA) tokenization trend, in which ownership rights in traditional financial assets are converted into blockchain-based tokens. Base is an Ethereum Layer 2 built on the OP Stack in collaboration with Optimism, with Coinbase aiming to make onchain the next online. This launch puts Coinbase in competition with other platforms that already offer tokenized equities.

References

Tags

#tokenized-stocks#Coinbase#Base#RWA#equities