BTC $78,812 -1.1%ETH $2,483 -0.6%Fear & Greed 69 Greed

Today at a glance

Centralized exchanges face trust crisis as Liquid hackers return $270M after $320M theft, and Orionx winds down amid alleged $7M transfers.

3 signals
  • Partial ReturnLiquid attackers returned about $270 million, leaving roughly $50 million in stolen crypto still missing.#02
  • Exchange Wind-DownChilean exchange Orionx halted withdrawals and began winding down after allegedly transferring $7 million in user assets; regulator lacks power to compel refunds.#03
  • Stablecoin RiskHacken found that about $91.3 billion USDT on Tron is protected by just two signing keys, highlighting systemic risk.#05

Stories are ranked by impact; the first three are the edition highlights. This edition displays 15 of 248 candidates.

#01
CryptoEditor's PickEvent record
—

Coldcard: 45% of Wave 3 funds moved, not 45% of all losses

The Block reported on September 7, citing Galaxy Research, that approximately 45% of funds stolen in Coldcard's third attack wave had moved. The percentage applies to Wave 3, not all stolen bitcoin.

This corrects the earlier edition's conflation of a wave-specific percentage with historical aggregate losses. Figures from different waves and observation dates must not be combined.

editorial · BMTNews 更正 · · Single source

Background, discussion, and references

References

Tags

#coldcard#security

#02
CryptoEdition highlightEvent record
9.0

Liquid Hackers Return $270M in Bitcoin After $320M Theft

Hackers who breached the Liquid exchange returned about $270 million in Bitcoin after initially stealing roughly $320 million, according to the report. The partial return leaves approximately $50 million in stolen crypto still unaccounted for.

A breach of this size at a cryptocurrency exchange reveals custodial risk and can seriously undermine user confidence in centralized platforms. Partial restitution limits the damage, but the unresolved remainder and the security failure itself may invite stricter regulatory scrutiny and push more users toward self-custody.

The attackers initially moved around $320 million in Bitcoin off Liquid, then returned about $270 million, leaving roughly $50 million still missing. Because Bitcoin transactions are recorded on a public ledger, the movement of funds could be observed on-chain before and after the return.

rss · Decrypt · · 3 sources

Background, discussion, and references

Market impact

The incident transmits risk through sentiment and custody channels: a large Bitcoin theft from a centralized exchange can heighten security concerns and encourage withdrawals, while the partial return of funds reduces fears of a large stolen-BTC overhang being sold. Aside from Liquid, no other venue is implicated directly, but the event adds to market perceptions of centralized exchange risk.

Background

Cryptocurrency exchanges hold users' digital assets and process withdrawals online, making them frequent targets for hackers. Bitcoin transactions are recorded on a public blockchain, so large thefts and partial repayments can be observed by researchers and traced to specific wallet addresses. In past attacks on exchanges, hackers have sometimes moved funds through mixing services to obscure the trail, which can make recovery more difficult.

References

Tags

#security#exchange#bitcoin#hack#recovery

#03
CryptoEdition highlightEvent record
8.5

Orionx Halts Withdrawals and Winds Down After Alleged $7M Transfers

Chilean crypto exchange Orionx has halted withdrawals and begun winding down operations after allegedly transferring approximately $7 million in user assets. Chile's financial regulator stated it does not oversee the exchange's closure and lacks the power to order customer repayments.

This incident highlights the custodial risks of centralized exchanges, where user funds can be exposed to misappropriation or insolvency. The regulator's lack of oversight and enforcement power underscores a regulatory gap that may leave affected users with limited legal recourse.

The alleged asset transfers total approximately $7 million, but further details about the destination or nature of the transfers have not been disclosed. The Chilean financial regulator's statement confirms that Orionx's wind-down falls outside its current supervisory remit, leaving no clear authority to compel refunds.

rss · The Defiant · · Single source

Background, discussion, and references

Market impact

The halt of withdrawals at Orionx may dampen user confidence in centralized exchanges operating in jurisdictions with limited regulatory oversight, potentially accelerating a shift toward regulated platforms or self-custody solutions. The event itself is unlikely to move broad crypto markets, but it could increase scrutiny of smaller regional exchanges and negatively affect trust in Chilean crypto services.

Background

Orionx is a Chilean cryptocurrency exchange that allowed users to buy, sell, and store digital assets. Centralized exchanges typically hold customer funds in their own wallets, exposing users to counterparty risk if the exchange misappropriates funds or becomes insolvent. In many jurisdictions, crypto exchanges are not yet fully covered by traditional financial regulation, leaving gaps in consumer protection.

Tags

#exchange-operations#security#regulatory#crypto

#04
8.5

Ethereum commits to letting users pay gas fees without holding ETH

Ethereum has committed to a roadmap that would let users pay gas fees without holding ETH, based on EIP-8141, also known as "Frames." Vitalik Buterin highlighted on Sept. 5, 2026 that the proposal has quietly advanced, and press reports tie the feature to the Hegotá hard fork expected in 2027.

This would remove a major onboarding barrier, letting wallets that only hold stablecoins transact normally and allowing applications to sponsor user fees without requiring migration to a smart account. It also reduces Ethereum's reliance on ECDSA signature verification, paving the way toward signature aggregation and post-quantum security.

EIP-8141 defines a new EIP-2718 transaction type containing up to 64 independent "frames," each an ordinary contract call for validation, fee payment, or execution, thereby decoupling the signing account from the fee-paying account. The proposal also includes "default code" so existing externally owned accounts benefit from sponsored gas, token-denominated fees, batched calls, and native key rotation; it has been a draft since January and is not yet formally scheduled.

rss · CoinDesk · · 2 sources

Background, discussion, and references

Market impact

The proposal directly touches ETH's core utility as the mandatory gas asset; if implemented, it could shift which users and transaction types need ETH, affecting how exchanges, wallets, and DeFi applications position the token. Since implementation is not yet officially scheduled, current on-chain fee flows remain unchanged and any market effect would hinge on future protocol milestones rather than immediate economics.

Background

On Ethereum, users must currently pay transaction fees, called gas, in ETH, and typically the account that signs a transaction is the same account that pays for it. ERC-4337 introduced account abstraction on a separate mempool in 2023, but it relies on third-party bundlers. Frames embeds similar capabilities into the base protocol, letting signers and fee payers differ, and is described by its authors as a "native off-ramp" from ECDSA toward post-quantum signatures.

References

Tags

#ethereum#gas-fees#protocol-upgrade#usability#crypto

#05
8.5

Two-Key Breach Could Expose $91B in USDT, Hacken Finds

Security firm Hacken released a technical review finding that roughly half of all circulating USDT—about $91.3 billion on Tron—is protected by just two signing keys. An attacker who compromised both keys could mint unlimited USDT and potentially take over contract ownership, stripping Tether of its administrative controls.

This highlights a systemic risk in stablecoin infrastructure: if exploited, an attacker could mint unlimited USDT, threatening the stablecoin's peg and the trust of users and exchanges. It also underscores key concentration risks on Ethereum, Avalanche, and Celo, where reused signing keys may extend administrative vulnerabilities.

Hacken found no evidence of actual key compromise or a security incident, but warned that reused signing keys could broaden administrative risks across multiple chains. The review arrived alongside a KPMG audit that helped Tether earn a ratings upgrade from Bluechip, and a two-key attack could also let an attacker transfer USDT contract ownership, preventing Tether from freezing funds.

rss · CoinDesk · · Single source

Background, discussion, and references

Market impact

The report raises concerns about Tether's key custody and could heighten regulatory or counterparty scrutiny, but no exploit has occurred, so actual market effects remain uncertain. Exposures would run through stablecoin supply confidence, issuer trust, and the liquidity of trading venues that rely heavily on USDT; a real breach could affect USDT's peg and broader crypto market sentiment.

Background

USDT is a stablecoin whose transactions require cryptographic keys to sign and verify activity on the blockchain, making key management protocols critical to its security. Tron hosts the largest share of circulating USDT, so key risks there carry outsized consequences. In this context, a two-key breach means an attacker gaining control over two signing keys that jointly authorize critical administrative functions such as minting or freezing funds.

References

Tags

#security#stablecoin#Tether#key management#exploit

#06
8.5

Harmony Proposes Shutting Down Chain, Migrating ONE to Ethereum Over AI Threats

On Sept. 6, Harmony proposed ending its independent network and moving ONE to Ethereum via a final-block snapshot and automatic airdrop of ERC-20 tokens. The plan comes less than three weeks after a controversial rollback following an Aug. 11 exploit that forged roughly 3.01 trillion ONE.

A once-prominent layer-1 voluntarily retiring marks an unusual existential outcome and highlights new perceived security pressures from AI and state actors. It affects ONE holders, validators, dApp users, and broader confidence in smaller blockchains' long-term resilience.

Smart contracts, liquidity pools, and multisig safes will not migrate automatically, so users are urged to exit contracts before Sept. 10; validators may begin shutting down at 7 a.m. PT that day. The non-binding proposal includes a $1.37 million compensation pool, redirects future emissions to an AI-video initiative, and does not disclose final block or airdrop dates.

rss · CoinDesk · · 4 sources

Background, discussion, and references

Market impact

The proposal directly affects ONE's market venue: holders would receive Ethereum-based ERC-20 tokens, exposing the asset to Ethereum's liquidity and exchange infrastructure while the L1 chain winds down. Broader sentiment toward small proof-of-stake networks could shift given a high-profile chain citing AI and state-actor threats as reasons to shutter, although actual market effects depend on community approval and execution details.

Background

Harmony is a sharded proof-of-stake blockchain launched as an Ethereum competitor. In June 2022, its Horizon bridge lost nearly $100 million in an attack the FBI attributed to North Korea's Lazarus Group; in August 2026, an attacker exploited cross-shard receipt handling to mint enormous numbers of forged ONE, leading Harmony to roll back the chain and discard over 109,000 transactions. The new proposal reverses its earlier rejection of migration as too disruptive and is presented as a response to threats from state actors and AI agents.

References

Tags

#Harmony#blockchain shutdown#AI threats#security#governance

#07
7.5

Coldcard third-wave attacker moves 45% of stolen Bitcoin

Galaxy Research reported that the attacker behind the third wave of the Coldcard wallet exploit has moved about 45% of their stolen Bitcoin, routing funds through THORChain or into CoinJoin rounds since Sept. 2. Across all waves, 82% of stolen BTC remains in original attacker addresses while 18% has moved for apparent laundering.

This update exposes how a major hardware-wallet attacker is laundering funds, helping exchanges and on-chain analysts track stolen assets and identify additional victim wallets. It also emphasizes that self-custody hardware devices remain targets and that stolen crypto can move despite chain analytics.

Galaxy said the third-wave exploiter created 293 two-of-two multisignature vaults to hold victims' coins and moved funds from the 11 largest vaults in descending order of size. The movement helped identify a previously unknown vault that likely holds another Coldcard victim's funds, though the cause of that loss is unconfirmed.

rss · Cointelegraph · · Single source

Background, discussion, and references

Market impact

Movement of stolen BTC through THORChain and CoinJoin raises the likelihood that some funds eventually reach exchanges, which could affect Bitcoin liquidity and sentiment; at the same time, high-profile Coldcard incidents may shake confidence in hardware-wallet products. The transfers themselves do not constitute a direct market trade and should not be read as a directional signal.

Background

Coldcard is a Bitcoin hardware wallet that keeps private keys offline, and attackers have exploited flaws in its key-generation process to drain wallets. THORChain is a decentralized exchange that lets users swap native Bitcoin across blockchains without KYC or wrapped tokens, while CoinJoin is a Bitcoin privacy technique that combines multiple users' payments into one transaction to obscure the trail. Galaxy Research tracked these movements on-chain to estimate how much of the stolen funds has been laundered and how much remains under attacker control.

References

Tags

#Coldcard#Bitcoin#security#laundering#Galaxy Research

#08
7.5

DBS and Citi Complete First Weekend Tokenized-Deposit USD Payment

DBS and Citi completed the first weekend cross-border USD settlement between Singapore and the U.S. using tokenized deposits over Swift's blockchain-based ledger. The transaction settled in minutes instead of the conventional one to two business days.

This milestone shows major incumbent banks are moving tokenized deposits from pilots toward live use, potentially enabling 24/7 cross-border payments without leaving the regulated banking system. It signals growing institutional adoption of blockchain rails for real-world payment infrastructure.

The transaction used tokenized deposits on Swift Digital Ledger, avoiding the constraints of traditional banking hours. Standard Chartered and HSBC completed the first tokenized cross-border transaction on Swift's ledger in August, and Swift has been preparing to pilot the service with 17 major banks including Citi and DBS.

rss · The Block · · 3 sources

Background, discussion, and references

Market impact

This milestone signals momentum for bank-issued tokenized deposits as an alternative to stablecoin-based settlement in wholesale cross-border payments. Market impact is primarily through sentiment and positioning around tokenization-focused projects, rather than through direct holdings of specific crypto assets.

Background

Tokenized deposits are blockchain-based digital representations of traditional bank deposits, issued by regulated banks and designed to maintain price stability, unlike stablecoins, which are typically issued by non-bank entities. Swift is the world's largest financial messaging network, and its new blockchain-based digital ledger aims to provide a trusted coordination layer so banks can settle tokenized transactions around the clock. DBS and Citi have separately pursued tokenization projects; in November 2025 DBS and JPMorgan announced plans for a tokenization framework for cross-bank deposit token transfers.

References

Tags

#tokenized deposits#cross-border payments#DBS#Citi#institutional adoption

#09
7.5

Bybit Uncovers AI-Assisted macOS Malware Targeting Claude Code Users

Bybit has announced that its security team uncovered an AI-assisted macOS malware campaign targeting users who search for Claude Code, Anthropic's agentic coding tool. The discovery indicates that attackers are leveraging artificial intelligence to craft malware that lures developers.

This matters because it shows cybercriminals are actively targeting the rapidly growing ecosystem of AI coding tools, whose users may hold valuable source code, credentials, and crypto assets. It also highlights that a major crypto exchange's security research extends beyond cryptocurrency users into the broader software development community.

The malware is macOS-specific and AI-assisted, suggesting that attackers may have used large language models to generate or refine the malicious code. The initial disclosure does not include the specific malware family, distribution method, or number of victims.

google_news · Yellow.com · · 2 sources

Background, discussion, and references

Market impact

The disclosure is primarily a security notice rather than a market-moving event. The main risk channel is indirect: developers infected by the macOS malware could have their credentials or crypto wallet keys stolen, and exchange users who also use Claude Code could be exposed, but no actual compromise or fund loss has been reported.

Background

Claude Code is Anthropic's agentic coding tool that reads codebases, edits files, runs commands, and integrates with development tools for developers using Claude AI models. It has quickly gained popularity among programmers, making it an attractive lure for attackers. AI-assisted malware is a growing trend, with research teams documenting campaigns where threat actors use LLMs to write or refine infostealers, coin miners, and other malicious tools.

References

Tags

#security#malware#macOS#Claude Code#Bybit

#10
7.5

Coinbase Launches Regulated BTC, ETH and SOL Derivatives in Canada

Coinbase has launched regulated crypto derivatives in Canada, giving eligible users access to perpetual and dated futures on Bitcoin (BTC), Ether (ETH), Solana (SOL) and other assets. The launch covers 23 futures contracts and supports leverage up to 10x.

This marks one of the largest regulated crypto derivatives offerings for Canadian retail and institutional clients, expanding Coinbase's 'Everything Exchange' strategy beyond spot trading. Broader derivatives access can deepen market participation and give traders regulated hedging tools for BTC, ETH and SOL.

According to reports, the derivatives suite includes 23 futures contracts and leverage up to 10x. The products are offered only to eligible Canadian users and are subject to Canada's regulated derivatives framework.

google_news · CCN.com · · Single source

Background, discussion, and references

Market impact

Regulated derivatives availability in Canada could increase trading volumes and institutional hedging activity in BTC, ETH and SOL markets through Coinbase's venue, deepening the country's access to crypto derivatives. The move may also intensify competition among derivatives platforms, although short-term price impact is uncertain and dependent on broader market conditions.

Background

Coinbase's 'Everything Exchange' vision combines trading, financial services and applications into one unified platform, with executives describing it as central to the company's strategy. The concept includes consumer finance via its Base app and institutional infrastructure, alongside core crypto trading services. Canada is one of the markets where Coinbase has chosen to expand regulated derivatives after previously focusing on spot crypto trading.

References

Tags

#Coinbase#Canada#derivatives#BTC#ETH#SOL

#11
AI & TechEvent record
7.5

TALA Layout Engine for D2 Diagrams Goes Open-Source

Terrastruct's TALA layout engine, optimized for D2 software architecture diagrams, has been open-sourced. Previously a separate commercial and proprietary component, TALA is now available on GitHub and can be activated via the D2_LAYOUT environment variable.

D2 users previously had to pay for or skip TALA, despite many finding its output markedly better than D2's default layout or ELK. Open-sourcing makes this layout engine freely available to the community and invites outside contributions, which could accelerate its improvement and broaden adoption.

TALA is a separate install from D2, preserving D2 itself as fully free and open-source software, and it is invoked by setting the D2_LAYOUT environment variable rather than being the default renderer. It powers all diagrams in D2 Studio, and Terrastruct invites users to file bugs and feature requests as GitHub issues.

hackernews · alixanderwang · · Discussion · Single source

Background, discussion, and references

Background

D2 is a declarative diagramming language that turns text into diagrams, similar to Mermaid or GraphViz. Automatic layout quality matters greatly because poorly arranged nodes make diagrams hard to read and understand. TALA was originally developed by Terrastruct as a proprietary engine focused specifically on software architecture diagrams, rather than generic graph types.

Discussion

Reactions are broadly positive: one user calls the output much tidier, another plans to integrate it into Daedalus, and several note that TALA often improves on ELK. Some caveats emerged, including a Go queue example where TALA looks more complicated than alternatives, as well as a user who said TALA's old price exceeded their discretionary budget.

References

Tags

#open-source#D2#diagramming#layout-engine#developer-tools

#12
AI & TechEvent record
7.5

Stuxnet Source Code Reconstruction Released on GitHub for Education

A developer using the handle 'Sadpainy' has posted a reconstructed source code of the Stuxnet worm on GitHub, presented as a Show HN. The repository says the code was derived from decompiled binaries and is intended strictly for educational and research purposes.

Stuxnet is widely regarded as the first known cyber-weapon targeting industrial control systems, having targeted Siemens S7 PLCs used in Iran's nuclear enrichment program. A public reconstruction gives security researchers, defenders, and students a tangible educational artifact for studying advanced ICS-targeting malware, supporting the broader fields of cybersecurity and critical-infrastructure protection.

Commenters estimate the codebase at roughly 15,000 lines, leaving a substantial amount of material to analyze. The repository stresses that this is a reverse-engineered educational reconstruction by independent security researchers and notes that the original authors of the worm remain anonymous.

hackernews · CMDDestory · · Discussion · Single source

Background, discussion, and references

Background

Stuxnet was discovered in 2010 and is widely believed to have been developed by the United States and Israel to sabotage Iran's nuclear enrichment program, with most infected systems located in Iran. It is notable for attacking Supervisory Control and Data Acquisition (SCADA) systems and Siemens S7 programmable logic controllers, marking the first major attack on such industrial 'smart devices.' The malware exploited multiple zero-day vulnerabilities and spread partly through infected USB drives. Kim Zetter's book 'Countdown to Zero Day' is a commonly cited historical account of the weapon.

Discussion

Overall sentiment in the thread was positive and appreciative. One commenter described working on a Siemens S7 PLC project with a WINCC HMI — the same class of target — about 12 years ago and said Stuxnet entirely changed how they viewed critical industrial infrastructure. Others recommended Kim Zetter's book, joked with the line 'g_dwCentrifugeDestroyed++;', and speculated about whether USB media may have been infected by less scrupulous resellers before reaching target facilities.

References

Tags

#cybersecurity#stuxnet#critical-infrastructure#malware#open-source

#13
AI & TechEvent record
7.5

LG Smart TVs Still Listen and Scan Home Wi-Fi When 'Off'

A Gamers Nexus investigation with Level1Techs and independent researchers found that LG smart TVs scan a home's entire Wi-Fi network and capture microphone audio even when the screen is dark or the TV is unplugged from the internet. LG agreed to a settlement with Texas regulators in May over undisclosed viewing-data collection.

This affects millions of LG smart TV owners and raises serious privacy concerns because background listening and network mapping operate without clear user consent. It also highlights broader risks in connected TVs, where default telemetry and unpatched vulnerabilities can compromise home privacy and security.

Notably, ACR tracking remains active when the TV is used purely as an HDMI monitor, and muting the main microphone in settings does not stop a second, hidden microphone from recording. Researchers also found unpatched remote-code-execution flaws and residential-proxy code, with LG asking them to hold back technical disclosure during an ongoing coordinated-disclosure process.

rss · Decrypt · · 3 sources

Background, discussion, and references

Background

LG smart TVs run LG's webOS operating system and are marketed as internet-connected entertainment devices, but they also include microphones and advertising-telemetry features that may not be fully under user control. Automatic Content Recognition (ACR) technology samples audio/video streams and creates a digital fingerprint that is matched against a reference database to identify the content being watched. UPnP (Universal Plug and Play) is a networking protocol suite that lets devices automatically discover and interact with each other on the same home network, which is how the TVs mapped connected phones, laptops, and other gadgets. Residential proxy software routes internet traffic through an ISP-assigned residential IP address, and if embedded in a device it can anonymously relay third-party traffic through a person's home connection.

Discussion

Commenters were not surprised by the findings, and several described practical mitigation steps such as disabling the TV's network functions or using an external streaming box as an HDMI input. One owner said they were previously ridiculed for rejecting LG's data terms, while another noted the report validated choosing Sony Bravia over LG and Samsung. A separate commenter added that cheap modems increasingly make such surveillance threats widespread.

References

Tags

#privacy#security#LG#smart TV#consumer tech

#14
7.5

Kraken Files with CFTC for Regulated U.S. Perpetual Futures

Kraken has filed with the U.S. Commodity Futures Trading Commission (CFTC) to offer a regulated perpetual futures product to U.S. customers. The filing represents an application to enter the regulated crypto derivatives market, though details and a confirmed launch date have not yet been announced.

If approved, this would expand the range of regulated crypto derivatives available to U.S. traders, who have often relied on offshore venues for perpetual futures. It also signals continued institutional adoption and regulatory progress in the U.S. crypto market structure.

The filing is an early-stage application and is not yet a confirmed product launch. Specific contract terms, margin rules, and the venue through which Kraken would offer the product have not been disclosed.

google_news · CryptoRank · · Single source

Background, discussion, and references

Market impact

The filing could affect crypto derivatives market structure by potentially adding a CFTC-regulated venue for U.S. traders, increasing competition with existing derivatives platforms and possibly influencing liquidity flows. If approved, it may also set a precedent for how other U.S. exchanges structure regulated perpetual futures offerings.

Background

Perpetual futures are derivatives contracts with no expiry date; they use an exchange-set funding rate to track the underlying spot price and allow traders to speculate with leverage. The CFTC oversees derivatives markets tied to commodities such as Bitcoin and Ethereum under the Commodity Exchange Act, but it does not directly regulate spot crypto trading. A CFTC-regulated perpetual futures product would give U.S. traders a domestically supervised alternative to offshore crypto derivatives exchanges.

References

Tags

#Kraken#CFTC#perpetual futures#regulation#derivatives

#15
7.5

Malone Lam Plea Hearing Over $245M Bitcoin Theft Set for Tuesday

Malone Lam, the 22-year-old alleged organizer of a $245 million Bitcoin theft, is scheduled for a plea agreement hearing on Tuesday in federal court in Washington. Prosecutors say he helped orchestrate a social-engineering scheme that tricked one investor into surrendering more than 4,100 BTC.

This is one of the largest social-engineering-driven crypto thefts to reach court, showing how criminals now target individual wallet holders, not just exchanges. Its outcome could provide insight into U.S. enforcement strategies for coordinated crypto racketeering and money laundering.

Ten of the 18 indicted co-conspirators have pleaded guilty so far, and Judge Colleen Kollar-Kotelly has sentenced three others. The indictment describes a 'Social Engineering Enterprise' that also resorted to home burglaries to steal hardware wallets when remote tricks failed.

rss · Decrypt · · Single source

Background, discussion, and references

Background

Social engineering is a form of psychological manipulation used to pressure people into revealing confidential information or performing actions, and phishing is a common subtype. In the cryptocurrency world, fraudsters often impersonate support staff from trusted services such as Google or Gemini to obtain security codes or persuade victims to install remote-access software. A hardware wallet stores private keys offline, which is why physical break-ins became part of the alleged scheme. Prosecutors also allege the group laundered proceeds through privacy-focused Monero and 'peel chains' before spending cash on luxury goods.

References

Tags

#bitcoin#theft#social-engineering#legal#crypto-crime