BTC $85,831 -0.3%ETH $2,733 -0.5%Fear & Greed 71 Greed

Today at a glance

Security breaches and regulatory shifts converge as a rogue app drains funds, oracle risks surface, and CME and the ECB adjust crypto rules.

3 signals
  • SecurityFomoPeek versions 1.1 and 1.2 embedded a kernel exploit framework; about 579,900 USDT was stolen, and version 1.3 removed the components on Sept. 17.#01
  • Oracle RiskPragma rated 6 of 22 feeds critical, and Nostra paused lending, withdrawals and liquidations after the Sept. 17 exploit.#02
  • RegulationThe ESCB proposed removing MiCA's 30% bank deposit requirement for stablecoin reserves, favoring liquidity thresholds at one and five working days.#08

Stories are ranked by impact; the first three are the edition highlights. This edition displays 9 of 324 candidates.

#01
CryptoEdition highlightEvent record
8.8

Rogue iPhone app escapes iOS sandbox to hijack $580,000 in USDT

SlowMist, working with OKX security researchers, found that versions 1.1 (released Sept. 9) and 1.2 (Sept. 12) of the App Store app FomoPeek contained two modules unrelated to its advertised transaction-tracking function: one communicating with command-and-control servers and one containing a kernel exploitation framework with eight attack methods. Blockchain analysis firm Salus attributed roughly 579,900 USDT in stolen funds to the incident and identified an attacker address, 0x6d37f2C5e8F8546b648D317295565dA95975f4BB.

According to SlowMist founder Yu Xian, a successful exploit could break through the iOS sandbox isolation mechanism, read and decrypt the system Keychain, and access data files from other apps — potentially exposing private keys, mnemonic phrases and login credentials stored on the device. Binance, OKX, Gate, Bitget Wallet and Rabby have issued user warnings.

The malicious components were absent from FomoPeek's original release and were removed again in version 1.3 on Sept. 17; the framework was also able to receive remote instructions governing whether exploitation was enabled and how often it ran. Salus traced 401,028 USDT through three intermediary addresses to FixedFloat, 20,000 USDT through deposit addresses into a KuCoin hot wallet, 111,458 USDT via an address it associated with an escrow platform, and 10,000 USDT through the CCE mixing service before reaching escrow-linked addresses.

rss · CryptoSlate · · 2 sources

Background, discussion, and references

Tags

#FomoPeek#SlowMist#iOS sandbox escape#USDT theft#Apple App Store#Keychain

#02
CryptoEdition highlightEvent record
8.5

Pragma flags 6 price feeds as critical risk following $3.5M Starknet lending exploit

Oracle provider Pragma classified 6 of 22 mainnet market and rate feeds as critical risk in a Sept. 18 assessment, naming BROTHER, DAI, DOG, EKUBO, LORDS and NSTR, with nine other feeds rated high risk. The report followed a Sept. 17 borrowing exploit at Nostra, a Starknet lending protocol, where Nostra said a manipulated NSTR oracle price let one account borrow roughly $3.5 million of other assets against NSTR collateral.

Pragma warned lenders that an available token price does not establish that collateral can be sold to cover a loan, leaving them to decide which assets qualify as collateral and how much exposure to allow. In its Sept. 17 statement, Nostra said it paused lending, borrowing, withdrawals and liquidations while it reconciled the impact.

At token quantities valued by the oracle at $10,000, sell-quote deterioration was about 15% for NSTR, 17% for EKUBO, 22% for LORDS and 20% for BROTHER, measured against quotes for $10 sales. Pragma said the DAI finding concerns source concentration and tested Starknet token routes, and that current and legacy deployments had different exit curves, so the critical rating should not be read as a finding that DAI is globally illiquid.

rss · CryptoSlate · · Single source

Background, discussion, and references

Tags

#Pragma#Nostra#Starknet#NSTR#oracle#DeFi lending

#03
CryptoEdition highlightEvent record
8.0

Crypto-draining FOMO app was available on Apple store for a week

SlowMist Chief Information Security Officer Shān Zhang urged followers last Saturday to update to the latest IOS after DarkSword malware spread, claiming IOS 13 to IOS 26.5 leave users vulnerable to malicious Safari links exploiting a memory-corruption flaw in WebKit and JavaScriptCore. SlowMist also warned that official versions of the FOMO app on the App Store contained crypto-draining malware capable of stealing seed phrases and private keys, were active between September 9 and September 17, and that updating or deleting the app may not be enough, with users advised to treat relevant seed phrases, private keys, and sensitive credentials as compromised.

rss · Protos · · Single source

#04
7.9

OpenAI Launches GPT-6 Sol and Luna Minutes After Anthropic Drops Claude Opus 5.5

OpenAI released GPT-6 Sol and GPT-6 Luna on Tuesday (an OpenAI tweet dated September 22, 2026), minutes after Anthropic launched Claude Opus 5.5, cutting their API prices in half versus GPT-5.6's promotional rates; OpenAI says its internal coding-deception rate fell to 1.3% for Sol and 2.8% for Luna, both far below GPT-5.6 Sol's 10.4%.

rss · Decrypt · · Single source

#07
7.5

CME Expands Crypto Futures Lineup With Bitcoin Cash and Uniswap

CME Group said Tuesday it plans to launch Bitcoin Cash and Uniswap futures on October 19, pending regulatory review, in both standard and Micro contract sizes. Standard Bitcoin Cash futures will represent 250 BCH (Micro: 25 BCH), while Uniswap futures will cover 10,000 UNI (Micro: 1,000 UNI).

If regulatory review clears on schedule, the two contracts would become CME's tenth and eleventh single-asset crypto futures products. Volatility Shares CEO Justin Young called the addition "another important step in the continued expansion of CME Group's crypto futures offering," and Ripple Prime president Noel Kimmel said institutions managing crypto exposure "need around-the-clock access to regulated derivatives."

CME said its crypto futures and options averaged 279,800 contracts traded daily in the first half of 2026, worth $8.3 billion in notional volume, with average open interest of 264,600 contracts, or $15.4 billion. Its 2026 launches of Cardano, Chainlink, Stellar, Avalanche and Sui futures have generated more than $1 billion in total notional value year-to-date, the exchange said.

rss · Decrypt · · 2 sources

Background, discussion, and references

Tags

#CME Group#Bitcoin Cash#Uniswap#crypto futures#BCH#UNI

#08
7.5

ECB, EU cenbanks seek changes in MiCA’s minimum bank deposit for stablecoins

The European System of Central Banks (ESCB) — the ECB and EU national central banks — called for removing MiCA's requirement that at least 30% of stablecoin reserves, or 60% for significant stablecoins, be held as bank deposits. The proposal came in the ESCB's response, published Tuesday, to the European Commission's review of the Markets in Crypto-Assets Regulation, and instead backs minimum liquidity thresholds for reserve assets maturing within one and five working days.

The ESCB argued that the existing rule “creates a direct link between issuers and credit institutions,” and that a stablecoin run could force an issuer to rapidly withdraw deposits and create liquidity problems for a bank, particularly if stablecoin reserves are a significant share of its funding. The proposal echoes concerns raised by parts of the stablecoin industry, including Tether CEO Paolo Ardoino, who said Tether refused an EU license over the same clause.

Instead of bank deposits, the ESCB pointed to overnight reverse repurchase agreements (repos) and short-term sovereign bonds as alternative instruments issuers could use, citing European Banking Authority draft rules from 2024 that require significant stablecoins to hold at least 40% of reserves in assets maturing within one working day and 60% within five working days, with thresholds of 20% and 30% for non-significant tokens. The ESCB also warned of “material challenges” in enforcing MiCA, saying non-compliant crypto companies can still access EU customers.

rss · Cointelegraph · · Single source

Background, discussion, and references

Tags

#ECB#ESCB#MiCA#stablecoins#Tether#EU regulation

#09
7.2

Site Performance - Coinbase Web/Mobile

On Sep 21, Coinbase reported a site performance incident affecting its web and mobile services, warning that customers may be unable to buy, sell, trade, or view balances on multiple services. The exchange said a fix was implemented at 17:23 PDT and marked the incident resolved at 17:31 PDT.

While the incident was open, some customers were unable to place trades or view their balances, although Coinbase stated that customer funds were safe.

The incident was first flagged at 16:21 PDT as under investigation, updated at 16:58 PDT that investigation was continuing, and moved to monitoring at 17:23 PDT before being resolved at 17:31 PDT.

rss · Coinbase Status · · Single source

Background, discussion, and references

Market impact

The disruption was confined to Coinbase's own web and mobile interfaces; during such outages, order flow that would normally route through the exchange can be delayed or diverted to other venues, and users' inability to view balances can add short-term uncertainty about positions.

Background

Coinbase maintains a public status page that logs incidents affecting its web and mobile platforms, with timestamped updates tracking each incident from investigation through monitoring to resolution.

Tags

#Coinbase#Site Performance#Exchange Outage#Web/Mobile