Connect with us

Crypto World

Block Seeks OCC Charter for Uninsured Bitcoin and Stablecoin Custody Bank

Published

on

Block Seeks OCC Charter for Uninsured Bitcoin and Stablecoin Custody Bank


Block has applied to establish Builders Bank & Trust, N.A., which, if approved, would be an uninsured national trust bank under direct federal supervision, the company said on Sept. 8. The proposed bank would provide custody and related fiduciary services, including for bitcoin and stablecoins,… Read the full story at The Defiant

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

A Chinese humanoid-robot startup flips ‘distillation’ claim on OpenAI

Published

on

A Chinese humanoid-robot startup flips 'distillation' claim on OpenAI

The CEO of an Ant-backed humanoid robotics startup has published a letter to OpenAI in Chinese that raises questions about technical and design similarities between the two companies’ recent models.

“People often say major tech companies have intelligence networks monitoring the whole internet, this time I believe it, this is a direct distillation of us without any modifications,” Guo Renjie, CEO of Suzhou-based JoyIn, said in a public statement Thursday, according to a CNBC translation.

He said the startup had publicly presented its “extraterrestrial visitor” AI model framework in Silicon Valley a few weeks ago, before OpenAI’s Chief Scientist published “An Alien Mind” on Sept. 6. Guo questioned similarities in core technological approaches such as “recursive self-improvement” and the use of AI to optimize computing power.

Guo also highlighted similarities in the outer space-inspired design of OpenAI’s GPT-6 Astra web page and the website for JoyIn’s Aether model that he claimed was released two months ago. He added the startup has started the process of filing a lawsuit.

Advertisement

CNBC was unable to independently verify the claims. Some concepts are existing parts of AI research more broadly, although companies connect and implement them differently. OpenAI did not immediately respond to a request for comment.

U.S.-based Anthropic has repeatedly flagged unauthorized “distillation” of its models by Chinese companies to improve their own AI capabilities. On Tuesday, a U.S. cybersecurity agency said six Chinese companies, including DeepSeek and Alibaba, distilled models from Anthropic, Google and OpenAI.

JoyIn’s Aether model, which Guo said he decided to publicly announce Thursday, claims its perceptive, rather than text-based, approach to robotic control enables humanoids to complete tasks with a 90% success rate on first attempt.

Zhu Mingxuan, who led the model’s development, said she left U.S. humanoid company Figure last year, where she had also worked on models for helping humanoid robots mimic human actions. She told CNBC earlier this week that Aether reduced training time by two-thirds, and that she planned to open-source parts of the model, such as those relating to touch, but not portions related to energy use.

Advertisement

Getting humanoids and AI models to perform as intelligently as humans across a variety of tasks has remained a challenge, amid a broader tech race between U.S. and Chinese companies.

Garry Tan, chief executive of famed startup accelerator Y Combinator, told CNBC this month that he would “do nothing” about distillation and joined others in pointing out that the U.S. companies have trained their AI models on data covered under copyright law.

—CNBC’s Kate Rooney and Isabel O’Brien contributed to this report.

Source link

Advertisement
Continue Reading

Crypto World

Bitcoin ETF Investors Head for Exit While XRP Funds Stack 3 Wins

Published

on

US Spot Crypto ETF Net Flows, September 8 to 10, 2026

Bitcoin (BTC) exchange-traded funds saw a $282.6 million outflow on September 10, marking their third consecutive outflow session. XRP (XRP) funds took in money for a third straight day over the same stretch.

The split shows how differently investors are treating the two products. XRP funds have posted one negative day over their past 20 sessions, while Bitcoin flows continue to swing between heavy buying and heavy selling.

Bitcoin ETF Assets Slide Back Under $98 Billion

Bitcoin funds have handed back $449.4 million across the three sessions, according to SoSoValue. Total net assets fell to $97.49 billion, down from $101.3 billion on September 4.

Cumulative net inflows still sit at $55.17 billion, so the recent selling barely dents the overall picture. However, the pace of the reversal stands out.

Advertisement

The pressure spread to other majors. Ethereum (ETH) products shed $29.8 million on September 10, while Solana (SOL) funds lost $482,547.

Bitcoin’s record over the period reads erratic rather than uniformly weak. The same funds absorbed $730.9 million on September 3, the highest daily inflow since January 14, 2026.

Follow us on X to get the latest news as it happens

XRP Funds Keep Buying While the Price Falls

XRP tells a steadier story. The funds have recorded a single outflow day in their past 20 sessions, a $7.2 million exit on September 2, and collected $190.5 million overall during that run.

Advertisement

Bitcoin logged seven negative days across the same window. Ethereum posted three and Solana four, so XRP’s consistency stands out among the larger crypto ETFs.

Meanwhile, the buying held even as the token weakened. XRP traded near $1.36 on September 10 after falling roughly 2.8% on the day.

Cumulative XRP ETF inflows have reached $1.70 billion since launch, with combined net assets of $1.45 billion.

US Spot Crypto ETF Net Flows, September 8 to 10, 2026
US Spot Crypto ETF Net Flows, September 8 to 10, 2026. Source: SoSoValue/BeInCrypto

Smaller products joined in. Chainlink (LINK) ETFs added $4.3 million, and Polkadot (DOT) took $663,057, its first daily inflow since June 8.

The coming sessions will test whether XRP’s drip of buying reflects a distinct, patient holder base or simply a quieter version of Bitcoin’s swings.

Advertisement

Subscribe to our YouTube channel to watch leaders and journalists provide expert insights

The post Bitcoin ETF Investors Head for Exit While XRP Funds Stack 3 Wins appeared first on BeInCrypto.

Source link

Advertisement
Continue Reading

Crypto World

Brevo Login Flaw Linked to Phishing Attacks on 347K Trezor Users

Published

on

Crypto Breaking News

Brevo, an email delivery platform used across the crypto industry, disclosed that an attacker leveraged a login-system weakness to gain access to multiple client accounts. The incident allowed phishing messages to be sent to a combined audience of roughly 347,000 Trezor newsletter subscribers, with additional campaigns also reaching audiences tied to BitBox and CoinTracking.

In a Thursday postmortem, Brevo said the attacker used six accounts to send phishing emails. It also reported that contacts were exported from 43 accounts, while 93 accounts showed no meaningful activity—though Brevo did not clarify whether those categories overlap. Brevo added that the access-control boundary that should have limited the attacker’s reach to a single organization failed.

Key takeaways

  • Brevo reported that an authorization boundary failed after an attacker configured an account with single sign-on and invited real users into the setup.
  • At least six Brevo accounts were used to send phishing emails.
  • Trezor says the initial phishing email was sent to about 347,000 newsletter customers, and it is treating those addresses as potentially exposed.
  • BitBox and CoinTracking also confirmed unauthorized newsletter activity routed through Brevo, though they reported no evidence of lost funds or exposed recovery phrases.

How Brevo’s login flaw enabled cross-account access

Brevo’s postmortem describes a pathway in which an attacker created a Brevo account, turned on single sign-on, and then invited legitimate Brevo users into the configuration. Brevo said the design should have confined access to the organization associated with the configuration, but the authorization boundary did not hold.

As a result, the attacker was able to reach every organization the invited users could access. Brevo’s write-up links the exposure directly to this breakdown in access controls, rather than to a breach of the affected organizations’ own systems.

The incident surfaced publicly after warnings from Trezor and BitBox earlier in the week, which pointed to their shared email provider and explained why the fraudulent emails appeared credible and passed ordinary authentication checks.

Advertisement

Phishing mechanics: what recipients were asked to do

Trezor said the phishing email—titled “Critical Security Alert: STM32 Entropy Vulnerability”—included a link to an app designed to solicit wallet backups. According to Trezor, the company disabled the domain at the DNS level within about 20 minutes. Even with the rapid takedown, Trezor reported that about 2,500 people accessed the link before it was blocked.

Trezor also emphasized the broader risk to its subscriber list. In comments provided to Cointelegraph, a Trezor spokesperson said the initial email was sent to 347,000 customers, and that all recipients were subsequently contacted about the danger.

The spokesperson added: “Until we hear more from Brevo, we are treating all roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing.” Trezor further stated that its Brevo account stored only opt-in newsletter email addresses and no other customer data.

Hardware wallet and crypto services respond: exposure without confirmed credential theft

BitBox told Cointelegraph that its unauthorized email was delivered through Brevo and appeared to reach its full newsletter and tutorial audience.

Advertisement

In its response, BitBox said Brevo held only email addresses and language preferences for it. BitBox reported no evidence of compromised company credentials, no indication that attackers downloaded data beyond the newsletter contacts, and no signs of funds being stolen or recovery phrases disclosed. Still, it said it is treating the list as potentially accessed while awaiting Brevo’s logs.

CoinTracking, meanwhile, reported separate phishing activity. The company said its Brevo account distributed an email titled “Data Breach Notice: Please refresh API Keys as soon as possible.” CoinTracking warned recipients not to click the links in the message, indicating that the main threat was credential-related phishing rather than immediate compromise of underlying systems.

Together, the responses underline a common pattern in third-party email incidents: the most immediate harm may be messaging-based, but the bigger operational concern is whether contact lists can be reused for follow-on attacks.

What Brevo disclosed—and what remains unclear

Brevo’s incident report focuses on the account-access path, but some details remain ambiguous for downstream victims. Brevo said contact exports occurred across 43 accounts and that 93 accounts showed no meaningful activity, without specifying whether those numbers overlap or how many organizations were fully affected end-to-end.

Advertisement

Brevo also did not provide, in the disclosed summary, a precise mapping from the six sending accounts to the different affected crypto companies’ audiences. Cointelegraph attempted to request additional information from Brevo but received no response before publication.

For investors, traders, and builders, the relevance extends beyond the immediate phishing harm: reputable crypto firms rely on email service providers to communicate security alerts, product updates, and documentation. When those communications channels can be abused—especially when phishing content looks authentic—users may face repeated attempts that target them again using addresses already in the attacker’s possession.

Going forward, recipients of such newsletters should be cautious about any unexpected security prompts, verify warnings through official channels, and avoid entering sensitive data into links from unsolicited messages. The core uncertainty now is how thoroughly Brevo’s investigation identifies which organizations’ contacts were exported versus merely accessed, and whether the attacker obtained broader metadata that could support additional phishing campaigns.

Crypto firms and their customers should watch for follow-on updates from Brevo’s incident findings—particularly any clarification on which accounts were used for exports and whether any categories of access overlap—while continuing to educate users to treat “urgent security alerts” sent via newsletter channels as untrusted until verified independently.

Advertisement

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Source link

Continue Reading

Crypto World

Revised CLARITY Act Sets Rules for Controlled DeFi

Published

on

Revised CLARITY Act Sets Rules for Controlled DeFi

A revised version of the CLARITY Act would direct United States regulators to determine whether people or groups controlling “non-decentralized finance trading protocols” must comply with securities, commodities and anti-money laundering (AML) requirements.

The revised text, posted on Senator Cynthia Lummis’ website, defines such a protocol as one whose functionality, operation, or rules can be materially altered by a person or coordinated group. The definition also covers protocols whose controllers can restrict users or whose transactions are not governed solely by transparent, pre-established code.

Under the proposal, the Securities and Exchange Commission (SEC) and Commodity Futures Trading Commission (CFTC) would develop activity-based rules addressing registration, conduct, disclosure, recordkeeping and supervision. Meanwhile, the Treasury would establish how existing Bank Secrecy Act obligations apply to affected controllers.

The bill specifies that software and distributed ledger systems would not be required to register in their own capacity. It also says participation in an incident-response or security council would not, by itself, establish control over a protocol. 

Advertisement

The revised text arrived ahead of a procedural Senate vote scheduled for Sept. 15. The measure requires 60 votes to advance, meaning Republicans will need support from Democrats despite continuing disagreements over ethics, anti-money laundering protections and stablecoin rewards.

Crypto industry backs bill as ethics dispute lingers

In a statement shared with Cointelegraph, Crypto Council for Innovation CEO Ji Hun Kim called Tuesday’s vote a “pivotal moment” for digital assets, innovation and American leadership. Kim told Cointelegraph that the US needs a framework combining consumer protections with business conduct standards.

On Thursday, Coinbase CEO Brian Armstrong told CNBC that the CLARITY Act was “ready to get a yes vote.” He said the “must-have issues” previously raised by Coinbase had been resolved, while negotiations over ethics restrictions remained active and appeared close to a solution. Armstrong did not specify which provisions had changed.

Related: Following Senate delay, crypto bill has narrow window to become law

Advertisement

Despite this, the ethics section in the newly released text remained largely unchanged from the previous version, despite being one of the main points of contention in negotiations. 

On Aug. 20, Democratic Senator Ruben Gallego warned against holding a vote before lawmakers resolved disputes involving ethics and stablecoin yield. “A fast vote gets you a fast result, but I’m not sure it’s the result you want,” Gallego said at the time.

Armstrong said that if the legislation does not advance, the SEC and CFTC could instead pursue rulemaking and innovation exemptions using their existing authority.

Magazine: 10 of the greatest unsolved crypto mysteries

Advertisement

Source link

Continue Reading

Crypto World

Kalshi wants 24/7 Tesla and Nvidia perps as Wall Street fights over who regulates them

Published

on

Kalshi takes on Coinbase (COIN), Robinhood (HOOD) with new plan to offer crypto perpetual futures: The Information


The prediction-market operator plans to seek U.S. approval for about 60 stock and ETF perps, taking one of crypto’s biggest trading products into equities.

Source link

Continue Reading

Crypto World

Trezor phishing attack traced to Brevo login authorization flaw

Published

on

Ripple-backed OUSD launch hit by fake issuer scam on XRP Ledger

An authorization flaw in Brevo’s login system has allowed an attacker to access 138 customer accounts, leading to phishing emails sent through accounts used by Trezor, BitBox and CoinTracking.

Summary

  • A Brevo login flaw gave an attacker access to 138 customer accounts, including those used by Trezor, BitBox and CoinTracking.
  • Phishing emails were sent through six accounts, while contact lists were exported from 43 accounts.
  • A fraudulent Trezor email reached roughly 347,000 subscribers and sent around 2,500 people to a malicious link.
  • Trezor is treating all 347,000 newsletter addresses as potentially known to the attacker and reusable for phishing.

Brevo said in a Thursday postmortem that the attacker exploited a weakness involving its single sign-on system, gaining access to organizations connected to legitimate users who had been invited into an attacker-controlled Brevo account.

The incident affected 138 customer accounts in total. Six were used to send phishing emails, contacts were exported from 43 accounts, while Brevo recorded no meaningful activity across another 93. The company did not specify whether those groups overlapped.

Advertisement

Brevo flaw gave attacker access to customer organizations

Brevo traced the incident to the way its platform handled permissions when users belonged to more than one organization.

The attacker first created a Brevo account and enabled single sign-on before inviting legitimate Brevo users into the newly created organization. Access should have remained limited to the attacker-controlled organization.

Instead, Brevo said an authorization boundary failed, allowing the attacker to reach every organization that the invited users themselves had permission to access.

The compromised accounts included those used by hardware wallet makers Trezor and BitBox and crypto portfolio tracking and tax-reporting service CoinTracking. Access to the legitimate email infrastructure allowed fraudulent messages to be distributed in a way that made them look like normal company communications.

Advertisement

The disclosure provides the technical explanation behind the phishing emails targeting Trezor and BitBox customers this week. Crypto.news previously reported that both hardware wallet companies warned users on Wednesday after identifying fraudulent security messages distributed through a third-party newsletter provider.

Because the messages were sent through legitimate mailing infrastructure, they could pass normal email authentication checks and reach subscribers from addresses associated with the affected companies.

Trezor’s phishing email used the subject line “Critical Security Alert: STM32 Entropy Vulnerability” and presented a supposed hardware security problem that required users to take action.

The message directed recipients to a malicious application that requested their wallet backups. Anyone who obtains a wallet recovery phrase can recreate the corresponding wallet and gain control over its funds.

Advertisement

Trezor phishing email reached 347,000 subscribers

Trezor said its Brevo account contained roughly 347,000 opt-in newsletter email addresses, with no other customer information stored on the platform.

A Trezor spokesperson told Cointelegraph that the initial phishing message was sent to all 347,000 addresses. The company subsequently contacted the same subscribers to warn them about the attack.

Trezor took the malicious domain offline at the DNS level within 20 minutes. Around 2,500 people had accessed the link before the takedown, according to the company.

“Until we hear more from Brevo, we are treating all roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing,” the spokesperson said.

Trezor said the Brevo incident did not compromise its hardware wallets, wallet backups or other internal systems. Customers who did not enter their wallet backup into the malicious application remained safe, according to the company.

Advertisement

The campaign follows several other phishing attempts involving the hardware wallet maker. In August, a Trezor user said he lost his life savings after a sponsored Google search result directed him to a fake website hosted through Google Sites.

Trezor said at the time that it was seeing more phishing websites impersonating the company through sponsored search results and warned customers never to enter wallet backups on websites.

Earlier in 2026, scammers took the impersonation attempts offline by sending fake Trezor and Ledger letters to hardware wallet owners. The letters contained QR codes leading to phishing websites that requested 12, 20 or 24-word recovery phrases under the pretext of completing authentication or transaction checks.

BitBox and CoinTracking accounts used in phishing wave

BitBox identified a similar campaign on Wednesday and warned users not to follow instructions contained in fraudulent emails sent under its name.

Advertisement

Its initial investigation found that several Bitcoin companies had been targeted and appeared to share the same newsletter provider. BitBox contacted the provider, warned newsletter subscribers and reported the phishing domains while investigating how the emails had been distributed.

The attack came weeks after BitBox patched two wallet vulnerabilities involving firmware installation and Bitcoin address handling. BitBox said there was no known exploitation of either flaw and reported no stolen user funds.

CoinTracking customers received a different phishing lure designed around the service’s portfolio tracking and tax-reporting functions.

The fraudulent email carried the subject line “Data Breach Notice: Please refresh API Keys as soon as possible,” according to CoinTracking. The company warned customers not to follow links contained in the message while it investigated the compromise of its Brevo account.

Advertisement

Brevo’s findings show that phishing emails represented only part of the activity across the 138 accessed accounts. The attacker exported contacts from 43 accounts, potentially leaving address lists available for use outside Brevo’s own mailing infrastructure.

Trezor is already treating its full newsletter list as potentially known to the attacker, although the company said it had not received confirmation that all 347,000 addresses were exported.

The hardware wallet maker has faced a separate customer data exposure this year involving logistics provider ShipMonk. Trezor initially disclosed in August that information belonging to 13,689 customers had been exposed through the shipping provider.

The scope later increased after Trezor learned that records belonging to approximately 67,000 additional U.S. customers had remained in ShipMonk’s systems. The older records covered purchases made between November 2019 and August 2021 and included names, email addresses, phone numbers, shipping addresses and order numbers.

Advertisement

Trezor said its own systems were not compromised in the ShipMonk incident and no private keys or recovery phrases were exposed. The company had previously received assurances that the older customer records had been deleted before learning on Sept. 2 that they remained stored by the provider.

Source link

Advertisement
Continue Reading

Crypto World

Report Links $2.08M in LAPTOP Sales to Wintermute-Tagged Wallet

Published

on

Report Links $2.08M in LAPTOP Sales to Wintermute-Tagged Wallet


Onchain analyst Lookonchain reported that an address tagged by Arkham as Wintermute sold 466,255 LAPTOP for about $2.08 million after receiving tokens traced to the project team. For LAPTOP holders, the report identified project-allocated inventory moving out of a Wintermute-tagged wallet on the… Read the full story at The Defiant

Source link

Continue Reading

Crypto World

AI Boom Could Worsen Bear Market, Analysts Warn. These Are The Risks They See.

Published

on

AI Boom Could Worsen Bear Market, Analysts Warn. These Are The Risks They See.

A bear market in U.S. stocks would trigger a recession and chill artificial intelligence spending, causing spillover effects on bonds and global markets. U.S. investors would be hurt more than abroad, too. That’s the gloomy scenario painted by Fitch Ratings analysts in a report released Wednesday. And while Fitch is not forecasting a bear market, the firm sees risks rising…

Copyright ©2026 Investor’s Business Daily, LLC. All rights reserved. 87990cbe856818d5eddac44c7b1cdeb8

Source link

Continue Reading

Crypto World

Nu launches U.S. services after OCC approval

Published

on

CLARITY Act Stablecoin Yield Compromise Language

Nu has launched U.S. deposit accounts, credit cards and international transfers through Lead Bank while introducing a stablecoin-based account serving more than 35 countries.

Summary

  • Nu has launched U.S. accounts, cards and remittances through FDIC-insured partner Lead Bank initially online.
  • Nu Global converts customer deposits into USDC or EURC while offering daily variable yields internationally.
  • The U.S. account pays 3.50% APY, while its credit card provides unlimited 1.5% cashback initially.
  • Nu’s national bank charter remains conditional, with Federal Reserve and FDIC approvals still pending today.
  • More than 140 million customers use Nu across Brazil, Mexico and Colombia, the company says.

Nu said on Sept. 10 that customers could register immediately for early access to the products. The NYSE-listed financial technology company is entering the U.S. through a partner-bank structure because its own national bank charter remains subject to further regulatory approvals.

The U.S. offering includes an account paying a variable 3.50% annual percentage yield, a debit card and a Mastercard credit card carrying no annual fee. Nu Global, a separate international product, converts customer deposits into USDC or EURC and supports transfers across parts of Europe and Latin America.

Advertisement

Nu enters U.S. banking through Lead Bank

Nu is not currently a bank in the United States. Banking services and the Nu Credit Card are provided by Lead Bank, a member of the Federal Deposit Insurance Corporation, according to disclosures accompanying the launch.

Customer deposits in the Nu Account are held at Lead Bank. Nu says the account pays 3.50% APY on every available dollar, with interest calculated and credited daily. The advertised rate was accurate as of Sept. 10 and may change after an account opens.

Users receive access to savings goals without losing immediate access to their funds. The account supports domestic transfers and international transfers beginning with Brazil, Mexico and Colombia, although Nu says more destinations will follow.

A limited-edition metal debit card forms part of the initial package. Through its Mastercard relationship, Nu is offering a metal World Elite credit card with no annual fee and unlimited 1.5% cashback on purchases.

Advertisement

The company plans to raise the cashback rate to 2% for customers who meet qualifying conditions. Nu has not disclosed the complete eligibility terms or confirmed when the higher rate will become available.

Eligible customers will eventually be able to earn 4.50% APY on savings balances of up to $10,000. To qualify, a customer must hold the Nu Account and credit card, then complete at least three eligible card transactions within the previous 34 days. Balances above $10,000 will continue earning the standard rate, according to the product disclosure.

Nu Global holds balances in USDC and EURC

Nu Global gives customers a digital account for holding, transferring and spending funds across more than 35 countries. Every deposit is converted into either USDC, a dollar-pegged stablecoin, or EURC, a euro-pegged stablecoin.

The company advertises a variable daily yield equivalent to 3.50% APY for USDC balances and 2.20% for EURC. Nu’s announcement does not identify how the yield is generated, which legal entity holds the stablecoins or whether the balances receive deposit insurance.

Advertisement

Stablecoins are digital assets designed to track reference currencies, but they are not the same as insured bank deposits. Nu Global should therefore be distinguished from the U.S. Nu Account provided through Lead Bank.

Customers receive a virtual Mastercard for spending their balances. Nu says the card offers competitive foreign exchange rates without markups, while transfers between supported countries carry no service fee.

The first group of supported markets covers much of the European Union and several Latin American countries. Transfers are available in Argentina, Chile, Costa Rica, El Salvador, Honduras, Paraguay, Peru and Uruguay, according to a market list reported by Folha de S.Paulo.

European coverage includes Germany, France, Italy, Spain, Portugal, Ireland, Switzerland, Sweden and more than 20 other jurisdictions. Integrations involving Nu’s businesses in Brazil, Mexico, Colombia and the U.S. are planned for the coming months.

Advertisement

The product permits customers to hold and trade selected digital assets, including Bitcoin and Ethereum. Nu has not published a complete token list, custody arrangement or fee schedule for those trades in its launch announcement.

In related coverage, 21 financial institutions are preparing a multicurrency stablecoin venture expected to begin issuing tokens in 2027. Separately, U.S. Bank completed a cross-border stablecoin pilot between its North American and European entities using Stellar.

Nu’s U.S. bank charter is not final

Nu applied to form Nubank, N.A. in September 2025. The Office of the Comptroller of the Currency granted conditional approval on Jan. 29, allowing the company to enter the bank-organization phase.

Conditional approval does not authorize Nubank, N.A. to begin independent banking operations. Nu must satisfy the OCC’s conditions and secure required approvals from the Federal Reserve and FDIC.

Advertisement

The company said in January that it needed to capitalize the proposed institution within 12 months and open the bank within 18 months. U.S. chief executive Cristina Junqueira told Reuters that she expects the bank to begin operating in 2027.

A completed charter would allow Nubank, N.A. to offer deposit accounts, credit cards, lending and digital asset custody under a federal banking structure. Until then, Nu’s U.S. customers receive regulated banking products from Lead Bank.

Nu founder and chief executive David Vélez described the launch as the beginning of a “multi-decade journey” outside Latin America. His statement presents the company’s strategy and should not be read as a forecast of future market share.

Junqueira said capturing even a small portion of the U.S. market “will be transformative for our business.” Nu has not published U.S. customer, deposit or revenue targets for the new operation.

Advertisement

U.S. launch follows Nu’s first $1 billion quarter

Nu reported $1.06 billion in net income for the second quarter of 2026, crossing $1 billion for the first time. The result increased 49% from the previous year on a currency-neutral basis and exceeded the $967.2 million Visible Alpha estimate cited by Reuters.

Second-quarter revenue reached $5.88 billion, up 39% and above the cited $5.60 billion forecast. Its risk-adjusted net interest margin rose to 12.4% from 9.9% one year earlier.

The company serves more than 140 million customers across Brazil, Mexico and Colombia, according to its latest announcement. Brazil remains its largest operation, where Nu says it serves more than 60% of the adult population.

In Mexico, the company describes itself as the largest digital bank. Nu says its Colombian business ranks fourth among the country’s financial institutions by deposits, though the claim depends on the company’s selected market classification.

Advertisement

Nu shares gained as much as 1.6% during U.S. trading after the announcement, Reuters reported. The publication identified the move as the market’s initial reaction, not a measure of the U.S. operation’s future financial performance.

Nu Global is already available in selected European and Latin American markets. The company has not provided exact launch dates for its planned integrations with Brazil, Colombia, Mexico and the United States.

Advertisement

Source link

Continue Reading

Crypto World

Brevo Login Flaw Used to Phish 347K Trezor Users

Published

on

Crypto Breaking News

A flaw in Brevo’s email login setup allowed an attacker to access client accounts and launch phishing campaigns that targeted subscribers of multiple crypto companies, including Trezor. Brevo’s post-incident write-up says 138 client accounts were involved, with phishing messages sent through infrastructure connected to hardware wallet maker BitBox and crypto portfolio tracking and tax-reporting platform CoinTracking.

The incident matters for users because it highlights how widely used marketing and notification providers can become a bridge for account-based compromise—one that can bypass typical email authentication safeguards and reach audiences that expect legitimate updates.

Key takeaways

  • Brevo said an attacker used a login-system issue to gain access to 138 client accounts and send phishing emails from six of them.
  • Trezor reported that the initial phishing email was sent to roughly 347,000 newsletter customers, and it disabled the malicious domain within about 20 minutes.
  • Trezor, BitBox, and CoinTracking share the same email provider for newsletters, which enabled the attacker to pivot across multiple crypto audiences.
  • Brevo said an intended authorization boundary failed, allowing access beyond the organization where invited Brevo users belonged.
  • Crypto firms are treating their affected newsletter lists as potentially exposed and possibly reusable for further phishing attempts until more details emerge.

Brevo’s incident report: authorization boundary failure

In a Thursday postmortem, Brevo described how the attacker exploited a vulnerability in its login system to reach other organizations. Brevo said six accounts were used to send phishing emails. It also reported that contacts were exported from 43 accounts, while 93 accounts showed no meaningful activity. The company did not clarify whether those categories overlapped.

According to Brevo’s write-up, the attacker created a Brevo account, enabled single sign-on, and invited legitimate Brevo users into the configuration. Brevo said access should have been confined to a single organization, but the authorization boundary failed—granting the attacker access to every organization the invited users could reach.

Brevo also published its incident details through its status page, including the write-up referenced by affected companies.

Advertisement

Why crypto newsletters looked legitimate

The scope of the phishing effort expanded on earlier warnings from Trezor and BitBox, which had flagged that their shared email provider could be used to deliver convincing messages. Earlier coverage from Cointelegraph noted how the attack was able to pass normal authentication checks and appear genuine to recipients.

That combination—credible branding plus delivery through a familiar provider—makes these campaigns especially dangerous. Users are more likely to trust emails that match the expected tone and format of official newsletters, even when the link or call-to-action is malicious.

Trezor: app request tied to wallet backups

In a separate blog post, Trezor detailed what it said the phishing message contained. The email, titled “Critical Security Alert: STM32 Entropy Vulnerability,” included a link to an app that asked users for their wallet backups.

Trezor said it disabled the domain at the DNS level within 20 minutes. Even so, it reported that roughly 2,500 people accessed the link before the takedown.

Advertisement

A Trezor spokesperson told Cointelegraph that the initial email was sent to 347,000 customers and that all of those newsletter subscribers were later contacted about the risk. The company said its Brevo account stored only opt-in newsletter email addresses and no other customer data.

Until additional information is provided by Brevo, the spokesperson added that Trezor is treating the roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for future phishing.

BitBox and CoinTracking: lists potentially exposed

BitBox said its unauthorized email was sent through Brevo and appeared to reach its full newsletter and tutorial list. In comments relayed to Cointelegraph, a BitBox spokesperson said the Brevo account stored only email addresses and language preferences.

BitBox reported that it found no evidence of compromised company credentials, did not observe downloads of contacts beyond what would be expected in normal operations, and saw no signs of lost funds or disclosure of recovery phrases. However, it said it is treating the newsletter list as potentially accessed while it awaits Brevo’s logs.

Advertisement

CoinTracking, meanwhile, said its Brevo account distributed an email titled “Data Breach Notice: Please refresh API Keys as soon as possible.” CoinTracking told recipients not to follow the email’s links.

Taken together, these responses underscore a common pattern: even when companies confirm that no funds were taken and no secret keys or recovery phrases were released, the exposure of email addresses and the ability to reach subscribers can still provide a platform for repeated social engineering.

What to watch next: breach scope and future targeting

Brevo’s report indicates that the attack relied on a failure in access controls tied to single sign-on invitations, but the company’s account-by-account impact remains partially detailed. Readers should watch for additional confirmation of which customer lists were actually exported or contacted, and whether attackers can reuse the exposed addresses for follow-on campaigns.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Advertisement

Source link

Continue Reading

Trending

Copyright © 2025