BTC $81,806 -1.8%ETH $2,476 -3.8%Fear & Greed 64 Greed

Today at a glance

Regulatory deadlines and security failures converge as ESMA orders stablecoin wind-down and a Cisco zero-day is exploited.

3 signals
  • Regulatory DeadlineESMA set a Jan. 8, 2027 deadline for authorized platforms to resolve non-compliant stablecoin holdings, allowing only selling, converting or withdrawing during the wind-down.#01
  • Security FlawCisco's two unauthenticated FMC RCEs both carry CVSS 10.0, and one was exploited as a zero-day by Interlock ransomware before a patch existed.#02
  • Exit RiskAbout $17.1 million in canonically bridged ETH on Abstract has no independent exit after the Dec. 15 shutdown, leaving withdrawals dependent on operators.#03

Stories are ranked by impact; the first three are the edition highlights. This edition displays 14 of 648 candidates.

#01
PolicyEdition highlightTracking · 5 updates
8.5

EU securities regulator gives crypto platforms 3 months to remove unauthorized stablecoins

The European Securities and Markets Authority (ESMA) issued an opinion on Thursday requiring EU-authorized crypto-asset service providers (CASPs) to stop offering services that let EU customers buy, trade, swap or otherwise increase holdings of stablecoins that do not comply with the Markets in Crypto Assets (MiCA) rules. National regulators should ensure any remaining customer holdings are resolved as soon as possible and no later than three months after publication, placing the deadline at Jan. 8, 2027.

ESMA said keeping non-compliant stablecoins available through authorized platforms would weaken the reserve, redemption, governance and disclosure rules MiCA imposes on authorized issuers. Tether's USDT, the largest stablecoin by market value, is the standout example of a token not authorized under MiCA, and several platforms had already restricted it for European users.

The opinion does not name any tokens, and it covers exchange services, trade execution, transfers, custody, administration, advice and portfolio management. During the wind-down period platforms may provide limited services to resolve existing holdings — selling, converting, withdrawing, transferring or safekeeping — but not purchases, promotion, trading or continued market availability, and national regulators decide how individual platforms handle remaining client balances within the three-month outer limit.

rss · CoinDesk · · 5 sources

Background, discussion, and references

Market impact

The guidance directly affects EU users' access to USDT, the largest stablecoin by market value, by cutting off new trading and accumulation through authorized platforms while permitting only sell, convert, transfer and withdrawal routes during the wind-down. Affected venues face delisting and compliance obligations in the bloc, shifting EU stablecoin distribution and trading liquidity toward MiCA-authorized tokens, with national regulators determining the pace of individual wind-downs.

Background

MiCA's stablecoin rules began applying in June 2024, requiring issuers of dollar- and euro-pegged tokens offered to EU users to meet authorization, reserve, redemption and disclosure requirements; ESMA refers to such tokens as asset-referenced tokens (ARTs) and e-money tokens (EMTs). MiCA's full rules for crypto platforms took effect on July 1, forcing firms without authorization to stop serving clients in the bloc. The new guidance takes the form of an opinion directed at national authorities.

References

Tags

#MiCA#stablecoins#ESMA#EU regulation#USDT#CASP

#02
AI & TechEdition highlight
8.0

Cisco Firewall Management Center Has Two CVSS 10.0 Unauthenticated RCEs — Interlock Ransomware Exploited One as Zero-Day

Cisco disclosed two unauthenticated remote code execution (RCE) vulnerabilities in its Firewall Management Center (FMC), both rated CVSS 10.0, the maximum severity. One of the two flaws was exploited as a zero-day by Interlock ransomware operators before a patch was available.

Interlock ransomware operators already exploited one of the two maximum-severity flaws before a patch existed. Because FMC is a widely deployed enterprise security management plane, pre-authentication RCE at this severity gives attackers a path to control over firewall estates.

Both vulnerabilities are unauthenticated remote code execution flaws carrying the maximum CVSS score of 10.0. One is confirmed to have been used in attacks as a zero-day prior to a fix being available.

google_news · CryptoRank · · Single source

Background, discussion, and references

Background

Cisco Secure Firewall Management Center (FMC) is Cisco's centralized management and analytics plane for its Secure Firewall estate. Interlock is a double-extortion ransomware operation active since at least late 2024, identified by the ".interlock" extension left on encrypted files and by a Tor-based leak site used to pressure victims.

References

Tags

#cybersecurity#vulnerability#ransomware#Cisco#enterprise-security#remote-code-execution

#03
CryptoEdition highlightThread · day 3
7.5

Abstract's ETH Withdrawals Depend on Operators Ahead of Dec. 15 Shutdown

According to L2BEAT data, about $17.1 million in canonically bridged ETH sits on Abstract, and the network's wind-down plan provides no independent exit path for those funds after the Dec. 15 shutdown, leaving withdrawals dependent on operators.

Holders who do not move assets off the chain before the deadline must rely on operators to process withdrawals, rather than being able to exit unilaterally.

The roughly $17.1 million figure refers to ETH reported by L2BEAT as canonically bridged to Abstract; the wind-down plan sets out no independent exit after Dec. 15.

rss · The Defiant · · Single source

Background, discussion, and references

Market impact

The exposure is concentrated in roughly $17.1 million of canonically bridged ETH on Abstract, so the transmission channel is bridge liquidity and custody: holders' ability to recover value depends on operator-run withdrawal processing before the chain halts, and the wind-down adds to a recent pattern of L2 shutdowns that shapes sentiment toward smaller Layer 2 networks.

Background

Abstract is a consumer-focused Ethereum Layer 2 backed by Pudgy Penguins developer Igloo. It said it would wind down operations and shut down the chain on Dec. 15, 2026, less than a week after Paradigm-backed Layer 2 Blast announced its own wind-down. Users have been told to bridge assets off the network before the deadline or risk funds becoming inaccessible.

References

Tags

#abstract#layer-2#bridge-withdrawals#protocol-shutdown#ethereum

#04
Crypto
7.5

Aptos Unveils Tokenomics Overhaul: 210M APT to Be Permanently Locked, Staking Re

The Aptos Foundation has proposed an overhaul of APT tokenomics that would cut annual staking rewards from 5.19% to 2.6%, raise gas fees tenfold, and cap total supply at 2.1 billion APT. Under the plan, the Foundation would permanently lock and stake 210 million APT — nearly 18% of current supply — with operations funded by staking rewards rather than token sales.

The Foundation says the changes are intended to reduce emissions and increase token burns, potentially making APT deflationary. Future ecosystem grants would be tied to performance milestones, and annualized token unlocks are expected to fall 60% as the initial four-year unlock cycle ends in October 2026.

The measures remain a proposal rather than an executed change. A buyback program funded by cash reserves and future revenue is also under consideration.

telegram · wublockchainenglish · · Single source

Background, discussion, and references

Market impact

APT spot and derivatives venues, along with staking and validator services, are the segments most directly exposed: the proposal targets issuance and staking yield through the supply and reward channel, while the reduced unlock schedule and the possible buyback would affect circulating supply and sell-side pressure if adopted.

Background

Aptos mainnet launched on October 12, 2022, and APT is used for fees, staking and governance, with validators securing the network through a proof-of-stake BFT model. New APT can be created through staking rewards, while part of transaction fees is burned. APT follows a vesting schedule with allocations to the community, core contributors, the Foundation, investors and staking rewards, with the full schedule extending into 2050.

References

Tags

#aptos#tokenomics#staking#token-unlocks#layer-1

#05
7.5

🔍 On-Chain Detective | US Government Address Transfers Another 12,267.02 BTC, About $1.006 Billion

An address labeled "U.S. Government: Bitfinex Hacker Seized Funds" transferred out 12,267.02 BTC, worth about $1.006 billion, on October 8 (13:33 UTC / 21:33 Beijing time). Of that, 6,000 BTC was split into two transfers to a new address beginning with 33pYK…cFk, while roughly 6,267 BTC was held in another new address.

The destinations have revived concerns about potential government selling, though transfers to Coinbase Prime do not by themselves prove the Bitcoin was liquidated. The Oct. 8 movement extended three consecutive days of government-linked Bitcoin transfers.

In the prior hours, US government-linked addresses had moved a cumulative $670 million in tokens: 6,215.7 BTC ($520 million), 119 million USDT and 40,285 BNB ($31.63 million), with the BTC and USDT routed into Coinbase Prime. Blockchain analyst EmberCN reported that 9,000 BTC, worth about $739 million, had reached Coinbase Prime, and Coinbase Prime serves as a custody and trading venue, so assets can be deposited without an immediate sale.

telegram · theblockbeats · · 5 sources

Background, discussion, and references

Market impact

The transmission path runs through sentiment and potential supply overhang on Bitcoin spot markets, with Coinbase Prime as the custody and trading venue where the coins have arrived. The transfers coincided with Bitcoin falling from about $86,500 to around $82,500, but no liquidation has been confirmed.

Background

The funds trace back to the 2016 Bitfinex hack and were seized by US authorities, who announced a $3.6 billion recovery from the case. In 2025, President Donald Trump signed an executive order creating a Strategic Bitcoin Reserve that includes Bitcoin seized by US law enforcement.

References

Tags

#bitcoin#us-government#on-chain-data#coinbase-prime#seized-assets#bitfinex-hack

#06
7.5

Securitize brings Apple, Nvidia and Tesla to Solana, with NYSE trading in the works

Securitize launched Securitize Stocks, a product offering tokenized U.S. equities backed one-to-one by real shares, opening with security entitlements to 12 widely held names including Apple, Microsoft, Nvidia, Google, Tesla, Meta, Amazon, Netflix, Circle, Strategy and Palantir. The tokens initially trade on Securitize's registered broker-dealer platform on Solana, settling in the USDC stablecoin.

Securitize says each token is a security entitlement under the Uniform Commercial Code rather than a price-tracking wrapper, preserving investor rights and economic benefits such as dividends and, where applicable, voting. That distinguishes the offering from many offshore tokenized-equity products that only track a stock's price.

The shares backing the tokens will not be lent out, and holders can convert their entitlements into actual registered shares where an issuer supports it, with the product available to eligible investors in the U.S., the European Union and other permitted jurisdictions. At launch liquidity runs through Securitize's Solana-based automated market maker with Jump Trading as market maker, trading is available during extended hours ahead of a planned move to 24/7, and partners include Ripple Prime and Aave; Securitize says the tokens are expected to trade on the NYSE's planned 24/7 venue and the OKX-ICE tokenized-securities venue, neither of which has launched.

rss · CoinDesk · · 7 sources

Background, discussion, and references

Market impact

The launch channels tokenized U.S. equity exposure into the Solana ecosystem with USDC settlement, and Securitize names Ripple Prime and Aave as partners for onchain lending and collateral use, which could add a new collateral category to onchain credit markets. Any effect on the NYSE and OKX-ICE venues remains contingent, since both are still planned and not live.

Background

Securitize is an SEC-registered transfer agent and tokenization platform whose own NYSE-listed Class A stock is issued natively onchain. Its shares have traded on Solana since its NYSE listing in July, and the SEC's "innovation exemption" opened a compliant path for tokenized stocks. Rivals from Coinbase to the NYSE and an OKX-ICE venture have also moved into the space.

References

Tags

#tokenization#real-world-assets#solana#institutional-adoption#market-structure

#07
Crypto
7.5

Moscow Exchange Plans to Offer Cryptocurrency Trading from December 1

Boris Blokhin, senior managing director at the Moscow Exchange (MOEX), told reporters that the exchange plans to launch cryptocurrency trading on December 1 under Russia's new regulations. He said testing will continue until the official launch, according to TASS.

MOEX is Russia's main stock exchange, so its stated plan to host crypto trading would place digital assets within the country's core regulated market infrastructure rather than only on offshore or unlicensed venues.

The service is still in a testing phase and has not gone live; Blokhin did not specify which instruments would be traded or the scope of the offering.

telegram · foresightnews · · 2 sources

Background, discussion, and references

Market impact

The plan, if carried out, would route Russian investor demand for crypto through a regulated domestic venue, affecting the custody and access channel for that market segment rather than directly altering global spot liquidity. As it stands it is a stated launch intention still in testing, not a live service.

Background

Russian authorities have been advancing a legislative framework that would create a Bank of Russia-supervised market for digital currencies and digital rights, with regulated intermediaries and tiered investor access, while restrictions on using crypto for domestic payments remain in place.

References

Tags

#MOEX#Russia#crypto-trading#regulation#exchange-launch

#08
Crypto
7.5

Sui-Native Bitcoin Financial Infrastructure Hashi to Launch Mainnet This Month, Has Secured Over $500 Million in Capital Commitments

The Sui Foundation announced that Hashi, its native Bitcoin financial infrastructure, will begin a phased mainnet launch this month, backed by more than $500 million in capital commitments and a launch coalition of over 20 crypto industry institutions. Anchorage Digital is joining as a first-batch partner, providing institutional access through its Atlas settlement and triparty collateral infrastructure and its Porto self-custody wallet, and plans to supply stablecoin liquidity to Hashi.

Hashi is designed to let BTC remain on the Bitcoin network while being used as programmable collateral on Sui, a structure aimed at institutions that hold large Bitcoin balances. Anchorage Digital CEO and co-founder Nathan McCauley said public companies and institutions hold enormous amounts of Bitcoin but their ability to use that capital has been constrained by available technology and the limitations of DeFi.

Users deposit BTC, Hashi mints corresponding hBTC on Sui, and on exit the hBTC is burned and the native BTC is released back to the Bitcoin network. Security is built on MPC, Sui smart contracts and a Guardian Layer, with BTC collateral using a 2/2 multisig authorized jointly by Hashi validators and Guardians; the smart contracts have undergone Certora formal verification and CommonPrefix completed a cryptographic security review of the MPC protocol.

telegram · theblockbeats · · 3 sources

Background, discussion, and references

Market impact

The structure channels Bitcoin into Sui's DeFi market through a custody-and-collateral path rather than a bridge-style wrapped asset, so its immediate market relevance sits with BTC holders seeking stablecoin liquidity and with Sui lending, vault and structured-product venues such as Aftermath, Concrete and Fluid that would host hBTC-denominated markets. Institutional custody and settlement providers joining the launch coalition tie the asset's accessibility to compliance-gated venues rather than permissionless ones.

Background

Hashi was developed by Mysten Labs, the founding contributor to Sui, and the foundation said third parties will independently create and offer financial products on the infrastructure. Aftermath, Concrete and Fluid are named among the providers expected to run Hashi vaults, while BitGo, Bullish, Cumberland, FalconX and Ledger are also participating in the ecosystem. The $500 million-plus in capital commitments is intended to provide initial liquidity for Bitcoin financial markets on Hashi.

References

Tags

#bitcoin#sui#hashi#hBTC#Anchorage Digital#defi

#09
Crypto
7.5

79AU operations hot wallet suspected private key leak, roughly $12.5 million lost

According to monitoring by Defimon Alerts, the 79th Vault (79AU) on BNB Chain lost approximately $12.5 million after a suspected private key leak in its operations hot wallet. The address moved 2.01 million 79AU out of its trading pair in seven transfers (10,000; 100,000; 100,000; 300,000; 500,000; 500,000; and 500,000 tokens), and the attacker sold them back through about 95 swaps, cashing out 16,249 BNB (about $12.5 million).

The pool's USDT reserves fell from $15.2 million to $3.9 million, meaning liquidity providers and users in the 79AU trading pair absorbed the losses. The incident is a suspected key-compromise drain on BNB Chain DeFi rather than a contract logic exploit per the cited monitors.

The operating key also sent 3.79 BNB to the same external address, and another 500,000 79AU was moved to other addresses. The 79AU contract source code is not verified on BscScan, so outside reviewers cannot compare published code with what runs on chain.

telegram · foresightnews · · 2 sources

Background, discussion, and references

Market impact

The loss is concentrated in the 79AU trading pair on BNB Chain, where the drained USDT reserves directly hit that pool's liquidity and its liquidity providers, while 16,249 BNB was cashed out on chain. Broader read-through is mostly sentiment-based, keeping attention on BNB Chain DeFi security and hot-wallet key management rather than on other assets directly.

Background

79Vault describes itself as a decentralized value management layer for the Web3 ecosystem, and 79AU is its token on BNB Chain. The team's operating hot wallet had normally been used only for small transfers into a rewards pool, making the large outflows unusual. Hot wallets store private keys in an online environment, which security analysts commonly treat as a high-value target for attackers.

References

Tags

#BNB Chain#79th Vault#79AU#私钥泄露#DeFi#安全事件

#10
Crypto
7.5

Payward Closes Bitnomial Acquisition, Gains Full US Derivatives Licenses

Payward, the parent company of the Kraken exchange, has closed its acquisition of crypto derivatives platform Bitnomial, giving it a full set of US derivatives licenses covering exchange, clearing and brokerage functions.

The deal places a fully CFTC-licensed derivatives stack — designated contract market, derivatives clearing organization and futures commission merchant — inside one of the largest US crypto exchange groups. Kraken has said the combination brings Bitnomial's CFTC-licensed infrastructure together with its client base and distribution across Kraken, NinjaTrader and its wider product family.

Reports put the transaction at $550 million in cash and stock. The licenses gained cover the three core US derivatives functions: exchange (DCM), clearing (DCO) and brokerage (FCM).

google_news · CoinMarketCap · · Single source

Background, discussion, and references

Market impact

The combination concentrates US-regulated crypto derivatives exchange, clearing and brokerage under one group, which affects how US-based traders can access regulated crypto futures and options and shifts the competitive positioning of CFTC-licensed venues. The transmission runs mainly through the regulatory and market-structure channel rather than through token supply or custody.

Background

Bitnomial is a CFTC-regulated crypto derivatives platform that Payward agreed to acquire earlier; the announcement described it as creating a fully CFTC-licensed derivatives platform. Kraken's parent also owns the futures trading platform NinjaTrader, and one search result frames the $550 million deal as part of Kraken's push toward a regulated derivatives business and a possible IPO.

References

Tags

#Kraken#Payward#Bitnomial#crypto derivatives#acquisitions#CFTC

#11

Bitget Hack: $388M Lost to Zero-Day Flaw [2026]

A report published by shattered.io alleges that crypto exchange Bitget lost $388 million in an exploit said to involve a zero-day vulnerability. The claim has not been confirmed by Bitget, on-chain analysts or other outlets.

If the alleged figure is accurate, the incident would rank among the largest security failures at a crypto exchange on record. As reported so far, no exchange statement, on-chain evidence or independent coverage has been cited to support the number.

The claim originates from a single headline on shattered.io, a non-mainstream outlet, and no on-chain data or corroborating reporting accompanies it. Bitget has not publicly acknowledged any such breach.

google_news · shattered.io · · Single source

Background, discussion, and references

Market impact

Should the alleged loss be confirmed, the transmission channel would run through exchange liquidity and custody — customer withdrawal capacity, order-book depth on Bitget's spot and derivatives markets, and sentiment spillover to other centralized exchanges. The claim currently rests on an unverified single-source report.

Background

Bitget is a Seychelles-based cryptocurrency exchange offering spot and derivatives trading. Japan's Financial Services Agency warned Bitget Limited in March 2023 and again in November 2024 over conducting crypto asset exchange business with Japanese residents without registration. A zero-day is a software vulnerability unknown to the vendor, for which no patch exists at the time of exploitation.

References

Tags

#Bitget#zero-day exploit#exchange hack#exchange security

#12
AI & Tech
7.5

OpenAI withdraws three mathematical results

OpenAI has withdrawn three mathematical results from its openai/math repository, according to the repository's history file, which was circulated in a post by @danintheory. The repository hosts mathematical manuscripts and supporting proof artifacts produced by an internal OpenAI model.

The withdrawal focuses attention on how much trust should be placed in AI-generated mathematical proofs, especially results presented in natural language rather than backed by machine-checkable Lean certificates.

The openai/math repository holds 722 manuscripts across 372 result families and is released under Apache-2.0. Some of the proofs include Lean formalization that computers can check, while others do not.

hackernews · sashank_1509 · · Discussion · 2 sources

Background, discussion, and references

Market impact

The story has no direct crypto exposure, but it feeds the AI-capability narrative that AI-related tokens trade on, and it could draw attention to verifiable-computation and formally verified infrastructure as a differentiator within that segment.

Background

OpenAI published 722 mathematical manuscripts spanning 372 result families in its openai/math GitHub repository, describing them as produced by an internal model. Lean is an open-source proof assistant, under development since 2013 and now supported by the nonprofit Lean Focused Research Organization, that allows a computer to check a proof step by step. Formal verification of this kind differs from natural-language argument, which is checked only by human readers.

Discussion

In a Hacker News thread of about 481 comments, readers were broadly skeptical of unverified AI-generated proofs. Several argued that a release of this scale should be fully formalized, that a Lean proof can compile while still stating something other than what was intended, and that without a thriving human mathematical community such problems could go unnoticed for years; one commenter also questioned a claimed O(n log n) integer-multiplication result.

References

Tags

#openai#ai-mathematics#research-integrity#lean-proof-verification#ai-generated-proofs

#13
7.0

Fired OpenAI safety researchers dispute misconduct claims, warn of chilling effect

Three fired OpenAI safety researchers publicly rejected allegations that they mishandled sensitive information, publishing an open letter that disputes the misconduct claims and warns their dismissals are chilling AI safety work inside the company. In the letter they wrote that "given the significant safety concerns surrounding the development of AI, employees must not be left working in an environment where fear and unclear rules stymie AI safety work and weaken third-party accountability."

The letter frames the dismissals as a governance issue rather than a purely personnel matter, arguing that the way the cases were handled affects how safety work and third-party accountability function at a leading AI lab.

The researchers dispute the characterization that they improperly shared sensitive information; earlier reporting linked the dismissals to allegations of sharing information with external safety groups.

rss · TechCrunch AI · · Single source

Background, discussion, and references

Market impact

The story has no direct asset exposure, but it feeds into the governance-and-regulatory-scrutiny narrative around frontier AI labs, a theme that can influence sentiment toward AI-related tokens and equity exposure to AI developers through perceived compliance and reputational risk.

Background

OpenAI is an American AI public benefit corporation headquartered in San Francisco that develops the GPT series of large language models. The company has faced prior public scrutiny over its safety staffing, including reporting that its Mission Alignment team was disbanded roughly 16 months after being formed. Separately, more than 1,100 employees of frontier AI companies signed an open letter urging the US government to develop means of deliberately pacing AI development, according to a Wikipedia summary of a 2026 incident.

References

Tags

#OpenAI#AI safety#AI governance#labor dispute#lab accountability

#14
AI & Tech
7.0

Launching an opt-in vulnerability-finding service for open-source software - Anthropic

Anthropic announced OSS Scanner, an opt-in service that uses its models to run thorough, periodic security scans of open-source software repositories and alert projects to potential vulnerabilities at no cost.

According to the source, open-source projects that opt in could be alerted about possible security issues sooner; the trade-off is described as stemming from how OSS Scanner works.

The service is described as free to participating open-source projects and uses Anthropic's strongest models for periodic scanning; participation is opt-in rather than automatic, and the company maintains a public repository for the service.

rss · Anthropic News · · 2 sources

Background, discussion, and references

Market impact

The service applies to open-source repositories, a category that includes widely used crypto infrastructure such as node clients, libraries and tooling; vulnerabilities surfaced there are an operational-security consideration for the affected projects and their users rather than a direct market driver.

Background

OSS Scanner is presented by Anthropic as a way to scan critical open-source repositories for security vulnerabilities, with an optional fast-track path for projects. AI-assisted vulnerability detection has been an expanding area of tooling, as open-source maintainers often lack the resources for continuous security review.

References

Tags

#anthropic#ai-security#open-source#vulnerability-detection#developer-tools#oss-scanner