BTC $81,016 +6.0%ETH $2,614 +6.8%Fear & Greed 56 Greed

Today at a glance

Regulators on both sides of the Atlantic are redrawing crypto market access while protocol and supply-chain failures pile up.

3 signals
  • Regulatory SplitLagarde's intervention pushed Binance to withdraw its Greek MiCA bid, while the SEC granted a five-year tokenized-equity exemption.#01
  • Security FailuresA three-year-old Radix Engine flaw cost about $1.26 million and halted the chain over 10 days; Haruko's breach hit 15 clients.#04
  • Market ReactionA dovish Fed dot plot liquidated over $445 million in crypto shorts, lifting Bitcoin to $80,846.#10

Stories are ranked by impact; the first three are the edition highlights. This edition displays 14 of 214 candidates.

#01
PolicyEdition highlightEvent record
8.5

ECB's Lagarde Blocked Binance's EU MiCA License, WSJ Reports

The Wall Street Journal reported that European Central Bank President Christine Lagarde personally intervened to block Binance's Markets in Crypto-Assets (MiCA) license application, pressuring regulators to halt a bid that had already been deemed complete. According to the report, the intervention led Greece — where Binance had filed its application — to stall the process rather than approve it.

Binance is the largest crypto exchange by volume, and MiCA licensing is the gateway to serving all 27 EU member states under a single passport, so blocking the bid effectively removes the company from the bloc's regulated market. The episode also raises questions about whether an institution with no formal licensing authority under MiCA can shape national regulators' decisions, which matters for every exchange still awaiting approval.

The ECB holds no formal licensing authority under MiCA, which assigns approval and supervision of crypto-asset service providers to national competent authorities such as Greece's capital markets regulator, meaning the reported intervention was informal and political rather than a formal regulatory decision. Binance subsequently withdrew its Greek application and said it would seek authorization through a different, as-yet-unnamed EU member state while restricting services for some EU clients.

rss · CoinDesk · · 7 sources

Background, discussion, and references

Market impact

The immediate channel is market access and liquidity: with Binance unable to passport a MiCA license, EU-resident users and euro-denominated spot and derivatives flow toward already-licensed venues, fragmenting liquidity that previously concentrated on Binance and shifting volume share among EU-regulated exchanges. A second channel is regulatory precedent — the reported use of informal ECB pressure on a national regulator raises licensing risk premiums for other large exchanges with pending applications and could influence how venues structure their EU entities and custody arrangements.

Background

MiCA (Markets in Crypto-Assets) is the EU's comprehensive rulebook for crypto assets and service providers; firms must be licensed by a national competent authority in one member state, and that license can then be passported across the entire bloc. Full MiCA requirements took effect at the end of 2024, with a transitional grandfathering period that expired on 1 July 2025, after which unlicensed firms must stop serving EU customers. The ECB is not a general crypto regulator — its involvement stems from its monetary policy mandate, its oversight of the digital euro project, and its monitoring of financial stability risks from crypto — which is why the reported intervention is unusual.

References

Tags

#binance#mica#ecb#crypto-regulation#eu

#02
PolicyEdition highlightEvent record
8.5

SEC Approves 'Innovation Exemption' for Tokenized US Stock Trading

The SEC approved an "Innovation Exemption" allowing qualifying venues, called Tokenized Securities Venues (TSVs), to trade tokenized US stocks on public blockchains without registering as national exchanges; the relief took effect immediately and runs for five years. The same day, the CFTC issued a no-action letter letting passive software providers connect users to regulated derivatives without registering as introducing brokers, extending relief first granted to Phantom in March, and altcoins rallied 10% to 20%.

This is a landmark shift in the US regulatory posture toward tokenized securities: it lands just two days after the Senate blocked the Clarity Act 49 to 50, so the SEC is advancing market-structure reform through its own statutory authority rather than waiting for Congress. It materially changes who can list, pool, and trade tokenized US equities onchain, and hands issuers a formal objection mechanism in the dispute over third-party stock tokens.

Two limits stand out: the exemption covers only genuinely tokenized stocks carrying full rights including dividends and voting, which excludes the price-tracking synthetics behind most offshore volume, and an unaffiliated party may tokenize a company's stock while the issuer gets 30 days to object and effectively stop it. There is no application queue — a firm that meets the requirements simply notifies the SEC and starts operating, and firms supplying liquidity get separate relief from dealer registration.

rss · Decrypt · · 3 sources

Background, discussion, and references

Market impact

The immediate transmission channel is sentiment and liquidity into tokens tied to onchain trading venues and DeFi infrastructure, with HYPE, UNI, ARB and NEAR leading the rally alongside BTC at $78k and ETH at $2,500. Over time, enabling tokenized equities to run through automated market makers and liquidity pools on permissionless chains would pull capital and order flow toward DEX tokens, custody providers, and exchange-linked names, while the ICE evaluation of Avalanche as a settlement layer connects legacy equity-market infrastructure directly to layer-1 assets.

Background

Tokenized stocks are blockchain-based representations of equity, and in the US, venues that match buyers and sellers of securities normally must register as national securities exchanges — a costly, slow process. The Clarity Act was a market-structure bill meant to divide oversight of digital assets between the SEC and the CFTC, and its failure left Congress without a legislative fix. The SEC's exemption is instead an administrative action under existing authority, while the CFTC's no-action letter is a staff position that signals it will not pursue enforcement against passive software providers that do not take custody or control user funds.

References

Tags

#SEC#tokenized-stocks#crypto-regulation#CFTC#market-structure

#03
CryptoEdition highlightEvent record
8.0

Haruko Cyberattack Exposes API Keys and Trading Data of 15 Crypto Clients

Haruko, a UK-based provider of institutional crypto portfolio management and trade-capture technology, was hit by a cyberattack this week that affected 15 of its clients, exposing their read-only exchange API credentials and trading data. A small amount of client funds was also stolen, with some of Haruko's smaller hedge-fund clients reported to have lost assets.

The incident shows how a single middle-layer software vendor can become a systemic access point for dozens of institutional trading desks, since compromised API credentials and trading data create follow-on risk for the affected funds and their counterparties. It is likely to accelerate scrutiny of third-party vendor security and credential hygiene across institutional crypto trading, a segment that has grown quickly alongside spot ETF and prime-brokerage activity.

According to CoinDesk, the exposed exchange API details were read-only, which normally restricts an attacker to viewing balances and trade history rather than initiating transfers or orders — yet reports still describe a small amount of client funds being stolen. Haruko's platform maintains fully managed integrations into hundreds of trading venues, so a credential compromise at this layer can touch many exchange accounts at once.

google_news · CoinDesk · · Single source

Background, discussion, and references

Market impact

The direct transmission channel is operational and counterparty risk rather than token pricing: affected funds may face temporary loss of trading access and must rotate exchange API credentials, and any stolen balances represent a small, localized drawdown for those clients. Broader fallout would run through sentiment toward institutional crypto infrastructure and third-party custody/tooling providers, which could weigh on how counterparties assess vendor risk when onboarding trading technology.

Background

Haruko was founded in 2019 and is headquartered in the United Kingdom, offering institutional clients portfolio management, trade capture and connectivity that sits between a fund's own systems and the many crypto exchanges it trades on. Exchange API keys are credentials that let software read account data or place trades on a user's behalf, which is why they are a high-value target: read-only keys limit what an attacker can do, while trading-enabled keys can move funds. Because funds rarely connect to exchanges manually, this kind of vendor layer is a common and often under-examined point of failure in crypto market infrastructure.

References

Tags

#security#hack#exchange-api#crypto-trading#funds-stolen

#04
8.0

Radix Engine bug drains $1.3M and halts chain for 10 days

The Radix Foundation disclosed on Sept. 17 that a flaw introduced during a June 2023 refactor of the Radix Engine — the layer that executes transactions and enforces asset ownership — was exploited on Aug. 31, allowing an attacker to drain roughly $1.26 million in bridged assets across 26 transactions. Validators then deliberately took enough stake offline to halt consensus for more than 10 days, with user transactions resuming Sept. 11 after a protocol fix added checks preventing a restricted vault reference from being used for an ordinary withdrawal.

This is a material protocol-level security failure: the flaw sat in the execution layer for more than three years, survived a 2024 external audit by Zellic, and according to investigators could have been used against any vault on the network, meaning the $1.3 million loss understated the real exposure. It also highlights how a routine maintenance change can create systemic risk and force a network to sacrifice liveness — a decision that carries its own costs for users and applications.

The attacker withdrew about 458,915 USDC, 72,420 USDT, 61.08 ETH, 6.35 wrapped Bitcoin, 536.16 SOL and 32.91 BNB, sending the assets through Hyperlane to Ethereum, BNB Chain and Solana before selling them for ETH; no private keys were compromised and Hyperlane itself operated as designed. The bug changed how the engine handled vault references, allowing a transaction to point at another user's vault and call ordinary withdrawal functions without enforcing the ownership boundary, and secondary losses occurred when distorted pool prices let another account extract millions of XRD.

rss · CryptoSlate · · Single source

Background, discussion, and references

Market impact

The transmission runs mainly through Radix's own on-chain liquidity and sentiment: bridged stablecoin and blue-chip holdings were removed from one side of trading pairs, distorting pool prices so a separate account could extract millions of XRD, while the 10-day halt froze transfers and bridge activity for RDX holders and applications on the network. Assets moved through Hyperlane to Ethereum, BNB Chain and Solana were subsequently sold for ETH, linking the incident to liquidity conditions on those venues.

Background

Radix is a layer-1 network whose Radix Engine executes transactions and enforces asset ownership, with vaults acting as the on-chain containers that hold tokens for users, applications and liquidity pools. Because the engine is the shared execution layer for everything built on Radix, a flaw there affects all applications at once rather than a single contract. A blockchain halt occurs when validators can no longer reach consensus on new blocks — here it was a deliberate safety pause rather than a crash, and it freezes transfers, bridges and contract activity network-wide until a fix is deployed.

References

Tags

#radix#smart-contract-vulnerability#exploit#blockchain-halt#protocol-security

#05
AI & TechEvent record
8.0

Hacktron chains libheif heap overflow and SSO flaw to breach OpenAI repos

Security researchers at Hacktron AI published a technical writeup showing they chained a heap buffer overflow in libheif with an SSO misconfiguration to gain remote code execution and reach OpenAI's internal repositories in under 72 hours. The writeup also states that until roughly two months earlier, any user or OpenAI employee logging into community.openai.com could have had their ChatGPT and Codex accounts taken over, and that Claude Opus 5 was used to break ASLR in about three hours after earlier models failed.

This is a rare public demonstration that a memory-safety bug in a widely deployed image library plus an identity-layer misconfiguration can be chained into full compromise of an AI lab's internal repositories, an asset class where the intellectual property is unusually concentrated. It also illustrates how LLM-assisted automation is shortening the time from vulnerability discovery to working exploit, which raises the bar for patching and identity hygiene across the entire software supply chain.

The overflow is tracked as CVE-2026-32741 and affects libheif 1.21.2 and earlier, where a crafted HEIF file containing a malicious 'mski' mask image triggers a heap buffer overflow in MaskImageCodec::decode_mask_image(); the corresponding patch centers on bounds checking for image overlays. Community analysis notes that HEIF's support for multiple composited images, rotation, cropping, alpha channels and thumbnails makes it a far larger attack surface than a plain JPEG decoder, which is exactly the kind of code path a photo-upload feature pulls in.

hackernews · Handy-Man · · Discussion · Single source

Background, discussion, and references

Market impact

There is no direct exposure of crypto assets here; the plausible transmission is sentiment, as a high-profile breach at a leading AI lab reinforces a security-risk narrative that can weigh on the AI- and agent-themed token segment and on general risk appetite in digital-asset markets. Any effect would be indirect and unverifiable in real time, flowing through narrative and positioning rather than through liquidity, custody or supply mechanics.

Background

libheif is an open-source library that decodes and encodes HEIF/AVIF images, the container formats used by many phone cameras and browsers; a heap overflow in such a decoder can let an attacker overwrite memory and potentially execute code in the process that parses the file. ASLR (address space layout randomization) is an operating-system defense that randomizes memory addresses so an attacker cannot reliably jump to injected code, and bypassing it is typically the hardest step in turning a crash into reliable code execution. Single sign-on (SSO) systems such as SAML and OIDC let one identity provider grant access to many downstream services, so a misconfiguration there can produce tokens that look legitimate and silently unlock connected apps like GitHub, Slack or email. Community reporting notes that OpenAI's own help forum, community.openai.com, was the entry point for the account-takeover angle.

Discussion

Commenters dug into the libheif patch itself, observing that the root cause was bounds checking for image overlays and arguing that HEIF's compositing, rotation and thumbnail features create a needlessly large attack surface for a forum that only needs photo uploads. Others highlighted the autonomous-agent angle, noting an LLM was placed in a "goal loop" against a Discourse instance disguised as a CTF target, and several expressed surprise that no Anthropic or OpenAI model weights have leaked despite repeated breaches.

References

Tags

#security#openai#vulnerability#libheif#sso

#06
7.5

Coinbase Files with CFTC for Single-Stock Perps on Apple, Tesla, Nvidia

Coinbase Derivatives has filed with the U.S. Commodity Futures Trading Commission (CFTC) to list cash-settled perpetual futures tied to individual U.S.-listed stocks and ETFs, including Apple, Tesla and Nvidia, according to a Wall Street Journal report. The filing extends Coinbase's domestic perpetual-futures push from equity indexes to single securities.

If approved, this would mark one of the first U.S.-regulated venues offering perpetual futures on individual equities, blurring the line between crypto-native derivatives and traditional stock trading. It signals that major crypto exchanges are competing for equity-linked flow, which could reshape market structure and pull new institutional and retail participants onto 24/7 venues.

The proposed contracts are cash-settled and perpetual, meaning they carry no expiry date and instead rely on periodic funding payments to track the underlying stock price. The filing follows Coinbase's existing broad derivatives lineup, which already includes crypto futures, a Mag7+Crypto index product, and 24/7 bitcoin and ether futures trading, and the products are not yet approved or live.

rss · Decrypt · · 6 sources

Background, discussion, and references

Market impact

The filing points to a potential channel through which equity-linked demand could be routed onto crypto-native, 24/7 trading venues, exposing Coinbase's derivatives revenue mix and pressuring competitors such as Binance and Crypto.com that already blend stock and crypto trading. Approval would also set a regulatory precedent for onshore single-stock perpetuals, which could affect how liquidity and hedging activity are distributed between traditional exchanges and crypto platforms.

Background

Perpetual futures are derivative contracts that track an underlying asset without an expiration date, first proposed by economist Robert Shiller in 1992 and later popularized by crypto exchanges; they function similarly to contracts for difference but use a funding-rate mechanism to keep the price anchored. In the U.S., futures markets are regulated by the CFTC, and Coinbase Derivatives operates as a CFTC-regulated exchange, which is why the company must file before listing new contracts. Offshore venues have offered equity-linked perpetuals for years, but U.S.-listed single-stock perpetuals have not been a standard regulated product.

References

Tags

#coinbase#perpetual-futures#derivatives#equities#market-structure

#07
7.5

Binance Launches 24/7 FX Perpetual Futures With Weekend EWMA Pricing

Binance announced it will launch 24/7 foreign exchange perpetual futures, beginning with a USDBRLUSDT contract that goes live on Sept. 21, settles in USDT and offers up to 100x leverage. The contract uses a dual-mode pricing system: a weighted index from third-party data providers during regular FX trading hours, and an orderbook-based exponentially weighted moving average (EWMA) on weekends and public holidays.

The launch pushes the world's largest crypto exchange into foreign exchange, the largest financial market by turnover, which the Bank for International Settlements pegged at $9.6 trillion in average daily OTC volume in April 2025. It follows similar 24/7 FX perpetual products from Bybit and Kraken, signaling that crypto derivatives venues are competing to capture FX exposure and off-hours price discovery that traditional FX markets cannot serve.

The weekend mechanism deliberately avoids external price feeds and instead derives prices from Binance's own orderbook via an EWMA, a design already applied to Binance's commodity-based TradFi perpetual contracts, which means off-hours margin requirements and liquidation levels can be driven by thinner internal liquidity rather than a reference FX rate. The contract settles in USDT, has a tick size of 0.0001 and a minimum notional value of 5 USDT according to Binance's futures announcement.

rss · Cointelegraph · · Single source

Background, discussion, and references

Market impact

The transmission channel is market structure and liquidity: USDT-settled FX perpetuals deepen the use of stablecoins as margin collateral and route traditional currency flow into crypto orderbooks, while concentrating weekend USDBRL price discovery on Binance's own book. Thin off-hours liquidity on that book can amplify funding-rate swings and liquidation cascades for leveraged positions, and rising FX derivatives volume on crypto venues may also feed back into stablecoin demand and exchange fee revenue.

Background

Perpetual futures are derivative contracts with no expiry date; they stay anchored to spot prices through a periodic funding rate that longs or shorts pay each other, typically every eight hours on major platforms. Traditional spot FX is an over-the-counter, dealer-intermediated market that closes from Friday evening to Sunday, so there is no continuous exchange-traded pricing over the weekend. Crypto exchanges have begun wrapping FX exposure into USDT-settled perpetuals, letting crypto traders take currency positions without holding or settling the underlying currencies.

References

Tags

#binance#derivatives#forex#perpetual-futures#market-structure

#08
7.5

Neutrl Opens NUSD Redemptions at 51 Cents as Strata Junior Tranche Wiped Out

Neutrl has opened NUSD redemptions at roughly 51 cents on the dollar, while Strata scheduled a 48-hour valuation update that writes its junior tranche token jrNUSD to zero and settles senior tranche withdrawals in sNUSD at revised share values. Strata's disclosure states the problem was not a smart contract exploit, hack, or code vulnerability.

This is a material loss event for depositors in a structured DeFi product, showing that a junior tranche designed as a first-loss buffer can be insufficient to protect senior capital when losses are large. It highlights the risk that tranching structures layered on top of a single yield strategy can transmit losses straight through to retail depositors in stablecoin-like tokens.

Strata's srNUSD and jrNUSD tranches are exposed to the sNUSD held by the strategy contract, and under Strata's loss allocation jrNUSD absorbs losses before srNUSD; at a 0.51 NUSD reference value, the loss exceeds the junior protection, which is why senior holders are also settling at reduced values. jrNUSD and srNUSD are permissionless tokens that trade on DEXs, and users must manually claim NUSD/sNUSD after redeeming.

rss · The Defiant · · Single source

Background, discussion, and references

Market impact

The transmission runs mainly through the Neutrl/Strata token complex: a 51-cent redemption value and a zeroed junior tranche imply a hard haircut for srNUSD, jrNUSD and sNUSD holders, which can spill into DEX liquidity for those tokens and into lending or collateral markets that accepted them. Broader stablecoin and structured-yield sentiment may be affected as traders reassess tranching designs and the real loss-absorbing capacity of junior buffers.

Background

Neutrl issues NUSD, a synthetic dollar described as fully collateralized and backed by market-neutral strategies such as OTC arbitrage and funding rate capture. Strata is a risk-tranching protocol that splits exposure to an underlying yield-bearing asset into a senior tranche (which targets a steadier return) and a junior tranche (which takes first losses in exchange for leveraged upside and a risk premium paid by the senior side). In the Neutrl NUSD market, depositors mint srNUSD or jrNUSD, and the strategy contract holds sNUSD, the yield-bearing form of the underlying position.

References

Tags

#defi#stablecoin#protocol-failure#tranche#redemptions

#09
7.5

Chainalysis: Blockchain Dead Drop Attacks Surge 420% as State Hackers Expand

Chainalysis reported that blockchain dead drop attacks rose 420% over the past 12 months, with North Korea- and Iran-linked operators accounting for roughly two-thirds of newly observed activity by the second quarter of 2026. The North Korea-linked group UNC5342 uses Tron and Aptos as redundant routes pointing infected devices to malware instructions stored on BNB Smart Chain, while suspected Iranian actors embedded command-and-control routing data inside Bitcoin transactions sent to an address historically associated with Satoshi Nakamoto.

This marks a shift from domain-based command-and-control to public blockchain infrastructure that conventional takedowns cannot easily disable, meaning defenders would have to coordinate action across multiple chains simultaneously. It raises the security and compliance burden for crypto exchanges, wallet providers and enterprises whose legitimate traffic shares the same networks that attackers are abusing.

Chainalysis said malicious blockchain writes rose from 2.06 per day to 11.1 per day after the emergence of high-capacity open-weight Chinese AI models, a 440% increase in under a year, though the firm cautioned its measurement does not identify a single model or prove that AI alone caused the rise. The malware queries Tron first and falls back to Aptos if that route fails, and disrupting the operation would require action across all three chains at once.

rss · The Defiant · · 3 sources

Background, discussion, and references

Market impact

The immediate channel is security and compliance rather than any token's supply: Tron, BNB Smart Chain, Aptos and Bitcoin are the networks actually named as carrying malicious writes, so exchanges, custodians and RPC providers on those chains face higher monitoring and screening costs as wallet, contract and RPC-traffic surveillance becomes a defensive necessity. Because fully blocking a network would also cut off legitimate wallets and DeFi services on the same infrastructure, the likely market effect is a gradual rise in chain-level risk premia and compliance overhead rather than a single identifiable price event.

Background

A blockchain dead drop is a technique in which malware instructions, payloads or command-and-control addresses are stored inside public blockchain transactions and smart contracts, so infected devices can repeatedly read those public records for updated instructions without being reinfected. Because the data lives on a public ledger, attackers can rotate their off-chain servers by posting a new transaction, and the content cannot be removed the way a seized domain or server can. The approach evolved from EtherHiding campaigns that appeared on EVM-compatible networks in 2023 after hosting providers began shutting down malicious infrastructure. Google Threat Intelligence began tracking UNC5342 in February 2025, when it used blockchain-based delivery in fake-job campaigns targeting cryptocurrency and technology developers.

References

Tags

#security#chainalysis#north-korea#blockchain-forensics#state-sponsored-hacking

#10
7.5

Bitcoin Surges Past $80K as Dovish Fed Dot Plot Fuels $445M Short Squeeze

Bitcoin jumped 5.88% in 24 hours to $80,846, opening at $76,355 and hitting an intraday high of $80,857, after the Federal Reserve raised rates by 25 basis points while its dot plot projected a median policy rate of just 4.1% through the end of 2027. The move liquidated more than $445 million in crypto short positions, over $230 million of which were Bitcoin shorts.

The episode shows how directly crypto derivatives now price in Federal Reserve policy signals: a single dovish projection triggered a cascading short squeeze that erased the panic selling that followed the Clarity Act's failed Senate vote days earlier. It highlights that leveraged positioning, not spot demand alone, is driving large single-day moves in Bitcoin, which remains nearly 20% below its previous all-time high.

Technical readings back the move but warn it is stretched: the ADX sits at 40.6, well above the 25 trend-confirmation threshold, with DI+ above DI-, and the 50-day EMA has crossed above the 200-day EMA, forming a golden cross that began last Saturday. RSI is at 63.3 — bullish but climbing toward the 70 overbought zone — while the Squeeze Momentum Indicator has stayed on for 11 consecutive bars, with an 8.06% contraction reading suggesting volatility may still be compressed and a larger release could lie ahead.

rss · Decrypt · · Single source

Background, discussion, and references

Market impact

The transmission ran through derivatives: a dovish Fed repricing forced buy-backs of leveraged shorts, and the roughly $445 million in liquidations (over half of it Bitcoin) fed the spot move higher across major venues. Exposure is concentrated in perpetual futures and margin markets for Bitcoin and other large-cap tokens, where funding rates and open interest now reflect a rebuilt long bias, leaving them sensitive to any shift in rate expectations or reversal in macro sentiment.

Background

The Fed's dot plot is a quarterly chart in which each FOMC official marks their projected path for the federal funds rate; lower dots indicate a more dovish, less aggressive tightening outlook, which typically lifts risk assets. A short position bets an asset's price will fall, and traders open shorts using leverage and collateral; if price rises sharply, their collateral is liquidated through forced buying, which pushes prices higher still and triggers cascading liquidations known as a short squeeze. In crypto this effect is amplified because most volume trades on perpetual futures with high leverage. The Clarity Act, a US market-structure bill intended to give crypto firms a durable statutory framework, failed a Senate procedural vote earlier in the week, sending Bitcoin below $75,000 before the Fed-driven rebound.

References

Tags

#bitcoin#liquidations#federal-reserve#macro#market-structure

#11
7.5

Grayscale's Zcash ETF Plans 3-for-1 Split After $233M Inflow Surge

Grayscale's Zcash ETF (ZCSH) is planning a 3-for-1 share split after a $233 million inflow surge pushed the fund's assets to nearly $890 million. The move follows a sharp rally in ZEC that has also driven mining competition on the Zcash network to record highs.

A share split lowers the per-share price of ZCSH, making the ETF easier to buy in smaller amounts and potentially broadening its retail investor base. It also signals that institutional-style, exchange-traded exposure to a privacy-focused asset has grown large enough to warrant routine market-structure housekeeping, a notable step for a category long treated as niche by regulated venues.

A 3-for-1 split triples the number of shares outstanding while dividing the price per share by three, leaving the fund's total assets and each holder's overall value unchanged. ZCSH is structured as an exchange-traded product that is not registered under the Investment Company Act of 1940, so it does not carry the same regulatory protections as 1940 Act-registered ETFs and mutual funds.

rss · The Block · · Single source

Background, discussion, and references

Market impact

The transmission runs mainly through ETF share creation and redemption: Grayscale's authorized participants must source ZEC to meet ZCSH demand, linking fund flows to spot market liquidity for the token. A split alters share count and per-share price rather than the fund's underlying ZEC holdings, so the more consequential market variable is whether inflows continue, while rising hashrate and competition feed back into miner margins and the economics of proof-of-work mining more broadly.

Background

Zcash (ZEC) is a privacy-focused cryptocurrency that uses zero-knowledge proofs, known as zk-SNARKs, to allow shielded transactions in which sender, recipient and amount can be hidden. Grayscale, the largest digital asset manager, converted its long-running Zcash Trust into an exchange-traded fund under the ticker ZCSH, giving brokerage-account investors direct price exposure to ZEC. Share splits are a common administrative step for funds and stocks whose unit price has risen sharply, since a lower nominal price can improve accessibility and trading granularity. Zcash, like Bitcoin, is secured by proof-of-work mining, and the recent price rally has made its mining economics unusually attractive relative to Bitcoin.

References

Tags

#zcash#grayscale#etf#institutional-adoption#crypto-markets

#12
7.5

Hyperliquid launches native lending on HyperCore as HYPE tops $90

On Sept. 18, Hyperliquid rolled out native manual borrowing, allowing users to pledge HYPE or Bitcoin as collateral to borrow USDC or USDT directly through HyperCore. Roughly $269 million was borrowed on the first day, while HYPE rallied about 15% on the week to an intraday high near $91.06, surpassing its prior record of about $89.60.

The launch extends Hyperliquid from a derivatives and spot exchange into credit, collateral and yield generation, letting users move between trading and borrowing without leaving the platform. Immediate day-one scale of $269 million suggests the lending primitive can become a meaningful source of stablecoin liquidity and HYPE demand within a single ecosystem rather than a standalone side product.

HYPE carries a 65% loan-to-value ratio versus 50% for Bitcoin, with liquidation thresholds of 82.5% and 75% respectively. Borrowers can tap more than $400 million of already-supplied liquidity because the same pools support portfolio-margin activity; stablecoin suppliers earn variable interest based on utilization, and portfolio-margin users can earn yield on idle stablecoin balances.

rss · CryptoSlate · · 2 sources

Background, discussion, and references

Market impact

The new market adds a direct collateral channel for HYPE and Bitcoin on HyperCore while deepening the stablecoin pools that already support portfolio margin, so lending utilization now influences funding and borrow demand for HYPE and the network's roughly $6.77 billion USDC supply. Kraken parent Payward's plan to offer on-chain perpetual futures to US clients via Hyperliquid's HIP-3 framework adds a parallel regulatory and distribution channel into the same ecosystem.

Background

HyperCore is the order-book and margin layer of the Hyperliquid blockchain where perpetuals, spot markets and portfolio margin are settled, while HyperEVM handles general smart contracts. Lending protocols typically let users deposit crypto as collateral and borrow stablecoins against it, with the LTV ratio determining how much can be borrowed and the liquidation threshold marking when the position can be closed. USDC and USDT are dollar-pegged stablecoins issued by Circle and Tether respectively, and they are the dominant units of account for on-chain credit. Hyperliquid's founder, Jeff Yan, compared separating the lending primitive from derivatives margin to Amazon spinning out AWS so one underlying system can serve multiple products.

References

Tags

#hyperliquid#defi-lending#hype#collateral#market-structure

#13
AI & TechEvent record
7.5

Photon-Emission-Guided Laser Attack Defeats RP2350 Secure Debug

Ledger Donjon researchers demonstrated a photon-emission-guided laser fault injection (LFI) attack that re-enables the debug interface on a secured RP2350-A4 microcontroller, allowing them to halt a core running in the Secure state and extract protected secrets. The work, published on the Ledger Donjon blog, is the first publicly documented optical fault attack against this chip's secure debug logic.

The RP2350 was marketed by Raspberry Pi as a microcontroller suitable for security-sensitive applications, and its secure enclave made it attractive as a cheaper alternative to dedicated secure elements such as YubiKey. A demonstrated bypass of its secure debug erodes that trust assumption for anyone building crypto key storage or hardware wallets on the chip, and it feeds the ongoing arms race between secure-hardware designers and physical attackers.

The attack used a 980 nm pulsed laser with a maximum optical power of 2.97 W operated at roughly 40% power (about 1.2 W), a 100 ns pulse width, and a 50x objective, with photon emission microscopy used to locate the exact target circuitry before faulting. It requires physical access, destructive preparation of the chip package, and roughly $250,000 of laboratory equipment, though commenters argue a functional home-lab replication could cost under $25,000.

hackernews · synack · · Discussion · Single source

Background, discussion, and references

Market impact

The most direct transmission channel is sentiment and trust around hardware-wallet supply chains: any wallet or key-storage product relying on the RP2350's secure enclave now carries a publicly documented physical-extraction path, which may shift vendor evaluations toward dedicated secure elements. Because exploitation demands physical possession, destructive sample preparation, and roughly $250,000 in lab gear, the near-term exposure for users of existing devices remains tied to targeted, in-person attack scenarios rather than remote or large-scale risk.

Background

Photon emission microscopy (PEM) detects the faint infrared light that transistors emit when they switch, letting researchers map which parts of a chip are active; laser fault injection (LFI) then fires a focused laser pulse at those spots to flip bits or corrupt logic at a chosen moment. The RP2350 is Raspberry Pi's dual Arm Cortex-M33 microcontroller, and its "secure debug" mode is a controlled channel that allows a debugger to access secure memory-mapped resources and inspect a core running in the Secure state — normally locked out unless the correct key is supplied. Raspberry Pi's own response post acknowledged that the Donjon team showed the debug interface could be re-enabled with a lab full of specialised equipment, something the company had been trying to make impossible.

Discussion

Commenters broadly praised the level of technical detail while pushing back on the $250,000 price tag, noting that similar attacks have been replicated at home for under $25,000 — one cited replacing a $5,000 ChipShouter with a $50 PicoEMP when reproducing a prior MPC5566 attack. Others framed the RP2350's secure enclave as a Yubikey alternative and described the result as part of an inevitable arms race between safe-crackers and safe-builders, while some simply noted the attack is "not super practical, but neat".

References

Tags

#hardware-security#fault-injection#rp2350#embedded-security#side-channel

#14
7.5

S&P Global to Acquire Smart-Contract Security Firm OpenZeppelin

On Sept. 17, S&P Global announced an agreement to acquire smart-contract security and development-tooling company OpenZeppelin, with financial terms undisclosed and the deal still subject to closing conditions. OpenZeppelin would keep its name, its leadership under CEO Demian Brener, and its open-source code, operating as a separate business unit reporting to Yann Le Pallec, president of S&P Global Ratings.

OpenZeppelin Contracts is the most widely used smart-contract library in the industry, so a major financial-data and ratings group absorbing it marks one of the clearest examples yet of traditional finance buying into core crypto infrastructure rather than only trading or custody. It hands S&P direct exposure to the security layer beneath stablecoins and tokenized assets, at a time when S&P is broadening its digital-asset push after leading an investment in crypto-data provider Kaiko.

OpenZeppelin says more than $37 trillion in value has been transferred through its Contracts software since 2015, and the current repository uses the permissive MIT License, with the company stating that released versions will remain open source permanently and cannot be withdrawn. The announcement makes continuity promises about audits, engineering work, ecosystem programs and open-source code, but its existing terms of service still permit changes to paid or hosted plans including pricing, features, quotas and usage limits, with protections and notice depending on the change type.

google_news · Binance · · 2 sources

Background, discussion, and references

Market impact

The transmission channel here is market structure rather than price: OpenZeppelin Contracts underpins a large share of DeFi, stablecoin and tokenized-asset code, so a ratings-agency parent could reshape how institutional risk assessment, audit standards and compliance expectations reach those protocols. It also reinforces the tokenization and real-world-asset narrative that S&P is positioning around, which tends to affect sentiment toward infrastructure and RWA-related assets more than any single token.

Background

OpenZeppelin is best known for OpenZeppelin Contracts, a library of reusable, audited Solidity components that developers import when building tokens, access-control systems and other on-chain logic; because deployed smart contracts are typically immutable, a vulnerability in that code can lead to irreversible losses, which is why the library is treated as a de facto security standard. The firm also runs a security-audit business, having completed more than 900 audits since 2017 across languages such as Solidity, Rust and Cairo. S&P Global is the parent of S&P Global Ratings, the largest of the "Big Three" credit-rating agencies alongside Moody's and Fitch, and its core business is financial information, benchmarks and analytics. The acquisition fits a broader pattern of traditional finance firms buying crypto infrastructure as markets move toward tokenization and 24/7 trading.

References

Tags

#openzeppelin#sp-global#acquisition#crypto-infrastructure#institutional-adoption