Crypto World
Health Leaders Talk Expanding Access to Specialty Care

Crypto World
Circle to Acquire Tazapay in $400 Million All-Stock Payments Deal

Circle has agreed to acquire Singapore-headquartered cross-border payments infrastructure company Tazapay in an all-stock transaction with base consideration of $400 million, a deal that would bring local payout rails and banking relationships inside the USDC issuer’s payments business. Circle… Read the full story at The Defiant
Crypto World
Senate Republicans Update CLARITY Act Before September 15 Vote
Senate Republicans have released updated CLARITY Act text ahead of the September 15 procedural vote, adding new rules for non-decentralized DeFi protocols and clarifying how credit unions can deal in crypto.
The changes reflect weeks of negotiation over the August recess, but they leave untouched the ethics provisions that have stalled Democratic support for the bill.
New DeFi and Credit Union Language
The updated bill requires non-decentralized DeFi protocols, platforms that market themselves as decentralized without actually functioning that way, to register with the Commodity Futures Trading Commission (CFTC).
That requirement mirrors Section 10301 of the Banking Committee’s portion of the bill, although crypto developer Roman Storm questioned the phrasing on X, asking how something billed as DeFi could be “non-decentralized.”
The new text also limits the DeFi provisions to spot or cash digital commodity transactions, a change aimed at addressing concerns some Native American tribes had raised about blockchain-based prediction markets. Credit unions, meanwhile, gained clearer authority to deal in crypto under the revised language.
Republican Senator Cynthia Lummis of Wyoming, who has championed the bill, described the revisions as the product of bipartisan negotiations and wrote that the updated text contains more than 100 changes requested by Democrats.
In another post, she put the figure at more than 115 Democratic “wins,” including a felony bar on fraudsters, $150 million for the CFTC and crackdowns on platforms such as Binance.
“Now they need to vote for the bill they built,” she wrote. “Anything less is walking away from their own work.”
Those changes come just days before the Senate is scheduled to vote on whether to invoke cloture on the motion to proceed. The September 15 vote requires 60 senators, leaving Republicans dependent on Democratic support.
Ethics Talks Remain the Bottleneck
The latest changes do not alter the ethics section or the bill’s stablecoin yield provisions, and that matters because ethics has been one of the biggest obstacles to Democratic support.
Yesterday, Coinbase CEO Brian Armstrong backed a “yes” vote and pointed out that lawmakers had resolved the issues his company previously considered must-have changes. He also described the ethics negotiations as one of the last matters to settle.
Democrats, however, have pushed for provisions requiring elected officials to divest relevant crypto interests or place them in blind trusts. The issue became more urgent after some legislators from that party called for scrutiny into President Donald Trump’s crypto dealings, from which he earned $1.2 billion, including from his Official Trump (TRUMP) meme coin.
However, Lummis has argued that failure to pass the bill would not be because of ethics, but because Democrats refused to accept a bipartisan compromise. Treasury Secretary Scott Bessent, in a September 9 post on X, also urged senators to keep negotiating and advance the legislation.
As things stand, the revised text settles some disputes while leaving the most politically sensitive part of the negotiations unchanged, and the upcoming vote will show whether those compromises are enough to get the bill moving.
The post Senate Republicans Update CLARITY Act Before September 15 Vote appeared first on CryptoPotato.
Crypto World
A Chinese humanoid-robot startup flips ‘distillation’ claim on OpenAI
The CEO of an Ant-backed humanoid robotics startup has published a letter to OpenAI in Chinese that raises questions about technical and design similarities between the two companies’ recent models.
“People often say major tech companies have intelligence networks monitoring the whole internet, this time I believe it, this is a direct distillation of us without any modifications,” Guo Renjie, CEO of Suzhou-based JoyIn, said in a public statement Thursday, according to a CNBC translation.
He said the startup had publicly presented its “extraterrestrial visitor” AI model framework in Silicon Valley a few weeks ago, before OpenAI’s Chief Scientist published “An Alien Mind” on Sept. 6. Guo questioned similarities in core technological approaches such as “recursive self-improvement” and the use of AI to optimize computing power.
Guo also highlighted similarities in the outer space-inspired design of OpenAI’s GPT-6 Astra web page and the website for JoyIn’s Aether model that he claimed was released two months ago. He added the startup has started the process of filing a lawsuit.
CNBC was unable to independently verify the claims. Some concepts are existing parts of AI research more broadly, although companies connect and implement them differently. OpenAI did not immediately respond to a request for comment.
U.S.-based Anthropic has repeatedly flagged unauthorized “distillation” of its models by Chinese companies to improve their own AI capabilities. On Tuesday, a U.S. cybersecurity agency said six Chinese companies, including DeepSeek and Alibaba, distilled models from Anthropic, Google and OpenAI.
JoyIn’s Aether model, which Guo said he decided to publicly announce Thursday, claims its perceptive, rather than text-based, approach to robotic control enables humanoids to complete tasks with a 90% success rate on first attempt.
Zhu Mingxuan, who led the model’s development, said she left U.S. humanoid company Figure last year, where she had also worked on models for helping humanoid robots mimic human actions. She told CNBC earlier this week that Aether reduced training time by two-thirds, and that she planned to open-source parts of the model, such as those relating to touch, but not portions related to energy use.
Getting humanoids and AI models to perform as intelligently as humans across a variety of tasks has remained a challenge, amid a broader tech race between U.S. and Chinese companies.
Garry Tan, chief executive of famed startup accelerator Y Combinator, told CNBC this month that he would “do nothing” about distillation and joined others in pointing out that the U.S. companies have trained their AI models on data covered under copyright law.
—CNBC’s Kate Rooney and Isabel O’Brien contributed to this report.
Crypto World
Bitcoin ETF Investors Head for Exit While XRP Funds Stack 3 Wins
Bitcoin (BTC) exchange-traded funds saw a $282.6 million outflow on September 10, marking their third consecutive outflow session. XRP (XRP) funds took in money for a third straight day over the same stretch.
The split shows how differently investors are treating the two products. XRP funds have posted one negative day over their past 20 sessions, while Bitcoin flows continue to swing between heavy buying and heavy selling.
Bitcoin ETF Assets Slide Back Under $98 Billion
Bitcoin funds have handed back $449.4 million across the three sessions, according to SoSoValue. Total net assets fell to $97.49 billion, down from $101.3 billion on September 4.
Cumulative net inflows still sit at $55.17 billion, so the recent selling barely dents the overall picture. However, the pace of the reversal stands out.
The pressure spread to other majors. Ethereum (ETH) products shed $29.8 million on September 10, while Solana (SOL) funds lost $482,547.
Bitcoin’s record over the period reads erratic rather than uniformly weak. The same funds absorbed $730.9 million on September 3, the highest daily inflow since January 14, 2026.
Follow us on X to get the latest news as it happens
XRP Funds Keep Buying While the Price Falls
XRP tells a steadier story. The funds have recorded a single outflow day in their past 20 sessions, a $7.2 million exit on September 2, and collected $190.5 million overall during that run.
Bitcoin logged seven negative days across the same window. Ethereum posted three and Solana four, so XRP’s consistency stands out among the larger crypto ETFs.
Meanwhile, the buying held even as the token weakened. XRP traded near $1.36 on September 10 after falling roughly 2.8% on the day.
Cumulative XRP ETF inflows have reached $1.70 billion since launch, with combined net assets of $1.45 billion.
Smaller products joined in. Chainlink (LINK) ETFs added $4.3 million, and Polkadot (DOT) took $663,057, its first daily inflow since June 8.
The coming sessions will test whether XRP’s drip of buying reflects a distinct, patient holder base or simply a quieter version of Bitcoin’s swings.
Subscribe to our YouTube channel to watch leaders and journalists provide expert insights
The post Bitcoin ETF Investors Head for Exit While XRP Funds Stack 3 Wins appeared first on BeInCrypto.
Crypto World
Brevo Login Flaw Linked to Phishing Attacks on 347K Trezor Users
Brevo, an email delivery platform used across the crypto industry, disclosed that an attacker leveraged a login-system weakness to gain access to multiple client accounts. The incident allowed phishing messages to be sent to a combined audience of roughly 347,000 Trezor newsletter subscribers, with additional campaigns also reaching audiences tied to BitBox and CoinTracking.
In a Thursday postmortem, Brevo said the attacker used six accounts to send phishing emails. It also reported that contacts were exported from 43 accounts, while 93 accounts showed no meaningful activity—though Brevo did not clarify whether those categories overlap. Brevo added that the access-control boundary that should have limited the attacker’s reach to a single organization failed.
Key takeaways
- Brevo reported that an authorization boundary failed after an attacker configured an account with single sign-on and invited real users into the setup.
- At least six Brevo accounts were used to send phishing emails.
- Trezor says the initial phishing email was sent to about 347,000 newsletter customers, and it is treating those addresses as potentially exposed.
- BitBox and CoinTracking also confirmed unauthorized newsletter activity routed through Brevo, though they reported no evidence of lost funds or exposed recovery phrases.
How Brevo’s login flaw enabled cross-account access
Brevo’s postmortem describes a pathway in which an attacker created a Brevo account, turned on single sign-on, and then invited legitimate Brevo users into the configuration. Brevo said the design should have confined access to the organization associated with the configuration, but the authorization boundary did not hold.
As a result, the attacker was able to reach every organization the invited users could access. Brevo’s write-up links the exposure directly to this breakdown in access controls, rather than to a breach of the affected organizations’ own systems.
The incident surfaced publicly after warnings from Trezor and BitBox earlier in the week, which pointed to their shared email provider and explained why the fraudulent emails appeared credible and passed ordinary authentication checks.
Phishing mechanics: what recipients were asked to do
Trezor said the phishing email—titled “Critical Security Alert: STM32 Entropy Vulnerability”—included a link to an app designed to solicit wallet backups. According to Trezor, the company disabled the domain at the DNS level within about 20 minutes. Even with the rapid takedown, Trezor reported that about 2,500 people accessed the link before it was blocked.
Trezor also emphasized the broader risk to its subscriber list. In comments provided to Cointelegraph, a Trezor spokesperson said the initial email was sent to 347,000 customers, and that all recipients were subsequently contacted about the danger.
The spokesperson added: “Until we hear more from Brevo, we are treating all roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing.” Trezor further stated that its Brevo account stored only opt-in newsletter email addresses and no other customer data.
Hardware wallet and crypto services respond: exposure without confirmed credential theft
BitBox told Cointelegraph that its unauthorized email was delivered through Brevo and appeared to reach its full newsletter and tutorial audience.
In its response, BitBox said Brevo held only email addresses and language preferences for it. BitBox reported no evidence of compromised company credentials, no indication that attackers downloaded data beyond the newsletter contacts, and no signs of funds being stolen or recovery phrases disclosed. Still, it said it is treating the list as potentially accessed while awaiting Brevo’s logs.
CoinTracking, meanwhile, reported separate phishing activity. The company said its Brevo account distributed an email titled “Data Breach Notice: Please refresh API Keys as soon as possible.” CoinTracking warned recipients not to click the links in the message, indicating that the main threat was credential-related phishing rather than immediate compromise of underlying systems.
Together, the responses underline a common pattern in third-party email incidents: the most immediate harm may be messaging-based, but the bigger operational concern is whether contact lists can be reused for follow-on attacks.
What Brevo disclosed—and what remains unclear
Brevo’s incident report focuses on the account-access path, but some details remain ambiguous for downstream victims. Brevo said contact exports occurred across 43 accounts and that 93 accounts showed no meaningful activity, without specifying whether those numbers overlap or how many organizations were fully affected end-to-end.
Brevo also did not provide, in the disclosed summary, a precise mapping from the six sending accounts to the different affected crypto companies’ audiences. Cointelegraph attempted to request additional information from Brevo but received no response before publication.
For investors, traders, and builders, the relevance extends beyond the immediate phishing harm: reputable crypto firms rely on email service providers to communicate security alerts, product updates, and documentation. When those communications channels can be abused—especially when phishing content looks authentic—users may face repeated attempts that target them again using addresses already in the attacker’s possession.
Going forward, recipients of such newsletters should be cautious about any unexpected security prompts, verify warnings through official channels, and avoid entering sensitive data into links from unsolicited messages. The core uncertainty now is how thoroughly Brevo’s investigation identifies which organizations’ contacts were exported versus merely accessed, and whether the attacker obtained broader metadata that could support additional phishing campaigns.
Crypto firms and their customers should watch for follow-on updates from Brevo’s incident findings—particularly any clarification on which accounts were used for exports and whether any categories of access overlap—while continuing to educate users to treat “urgent security alerts” sent via newsletter channels as untrusted until verified independently.
Crypto World
Block Seeks OCC Charter for Uninsured Bitcoin and Stablecoin Custody Bank

Block has applied to establish Builders Bank & Trust, N.A., which, if approved, would be an uninsured national trust bank under direct federal supervision, the company said on Sept. 8. The proposed bank would provide custody and related fiduciary services, including for bitcoin and stablecoins,… Read the full story at The Defiant
Crypto World
Revised CLARITY Act Sets Rules for Controlled DeFi
A revised version of the CLARITY Act would direct United States regulators to determine whether people or groups controlling “non-decentralized finance trading protocols” must comply with securities, commodities and anti-money laundering (AML) requirements.
The revised text, posted on Senator Cynthia Lummis’ website, defines such a protocol as one whose functionality, operation, or rules can be materially altered by a person or coordinated group. The definition also covers protocols whose controllers can restrict users or whose transactions are not governed solely by transparent, pre-established code.
Under the proposal, the Securities and Exchange Commission (SEC) and Commodity Futures Trading Commission (CFTC) would develop activity-based rules addressing registration, conduct, disclosure, recordkeeping and supervision. Meanwhile, the Treasury would establish how existing Bank Secrecy Act obligations apply to affected controllers.
The bill specifies that software and distributed ledger systems would not be required to register in their own capacity. It also says participation in an incident-response or security council would not, by itself, establish control over a protocol.
The revised text arrived ahead of a procedural Senate vote scheduled for Sept. 15. The measure requires 60 votes to advance, meaning Republicans will need support from Democrats despite continuing disagreements over ethics, anti-money laundering protections and stablecoin rewards.
Crypto industry backs bill as ethics dispute lingers
In a statement shared with Cointelegraph, Crypto Council for Innovation CEO Ji Hun Kim called Tuesday’s vote a “pivotal moment” for digital assets, innovation and American leadership. Kim told Cointelegraph that the US needs a framework combining consumer protections with business conduct standards.
On Thursday, Coinbase CEO Brian Armstrong told CNBC that the CLARITY Act was “ready to get a yes vote.” He said the “must-have issues” previously raised by Coinbase had been resolved, while negotiations over ethics restrictions remained active and appeared close to a solution. Armstrong did not specify which provisions had changed.
Related: Following Senate delay, crypto bill has narrow window to become law
Despite this, the ethics section in the newly released text remained largely unchanged from the previous version, despite being one of the main points of contention in negotiations.
On Aug. 20, Democratic Senator Ruben Gallego warned against holding a vote before lawmakers resolved disputes involving ethics and stablecoin yield. “A fast vote gets you a fast result, but I’m not sure it’s the result you want,” Gallego said at the time.
Armstrong said that if the legislation does not advance, the SEC and CFTC could instead pursue rulemaking and innovation exemptions using their existing authority.
Crypto World
Kalshi wants 24/7 Tesla and Nvidia perps as Wall Street fights over who regulates them

The prediction-market operator plans to seek U.S. approval for about 60 stock and ETF perps, taking one of crypto’s biggest trading products into equities.
Crypto World
Trezor phishing attack traced to Brevo login authorization flaw
An authorization flaw in Brevo’s login system has allowed an attacker to access 138 customer accounts, leading to phishing emails sent through accounts used by Trezor, BitBox and CoinTracking.
Summary
- A Brevo login flaw gave an attacker access to 138 customer accounts, including those used by Trezor, BitBox and CoinTracking.
- Phishing emails were sent through six accounts, while contact lists were exported from 43 accounts.
- A fraudulent Trezor email reached roughly 347,000 subscribers and sent around 2,500 people to a malicious link.
- Trezor is treating all 347,000 newsletter addresses as potentially known to the attacker and reusable for phishing.
Brevo said in a Thursday postmortem that the attacker exploited a weakness involving its single sign-on system, gaining access to organizations connected to legitimate users who had been invited into an attacker-controlled Brevo account.
The incident affected 138 customer accounts in total. Six were used to send phishing emails, contacts were exported from 43 accounts, while Brevo recorded no meaningful activity across another 93. The company did not specify whether those groups overlapped.
Brevo flaw gave attacker access to customer organizations
Brevo traced the incident to the way its platform handled permissions when users belonged to more than one organization.
The attacker first created a Brevo account and enabled single sign-on before inviting legitimate Brevo users into the newly created organization. Access should have remained limited to the attacker-controlled organization.
Instead, Brevo said an authorization boundary failed, allowing the attacker to reach every organization that the invited users themselves had permission to access.
The compromised accounts included those used by hardware wallet makers Trezor and BitBox and crypto portfolio tracking and tax-reporting service CoinTracking. Access to the legitimate email infrastructure allowed fraudulent messages to be distributed in a way that made them look like normal company communications.
The disclosure provides the technical explanation behind the phishing emails targeting Trezor and BitBox customers this week. Crypto.news previously reported that both hardware wallet companies warned users on Wednesday after identifying fraudulent security messages distributed through a third-party newsletter provider.
Because the messages were sent through legitimate mailing infrastructure, they could pass normal email authentication checks and reach subscribers from addresses associated with the affected companies.
Trezor’s phishing email used the subject line “Critical Security Alert: STM32 Entropy Vulnerability” and presented a supposed hardware security problem that required users to take action.
The message directed recipients to a malicious application that requested their wallet backups. Anyone who obtains a wallet recovery phrase can recreate the corresponding wallet and gain control over its funds.
Trezor phishing email reached 347,000 subscribers
Trezor said its Brevo account contained roughly 347,000 opt-in newsletter email addresses, with no other customer information stored on the platform.
A Trezor spokesperson told Cointelegraph that the initial phishing message was sent to all 347,000 addresses. The company subsequently contacted the same subscribers to warn them about the attack.
Trezor took the malicious domain offline at the DNS level within 20 minutes. Around 2,500 people had accessed the link before the takedown, according to the company.
“Until we hear more from Brevo, we are treating all roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing,” the spokesperson said.
Trezor said the Brevo incident did not compromise its hardware wallets, wallet backups or other internal systems. Customers who did not enter their wallet backup into the malicious application remained safe, according to the company.
The campaign follows several other phishing attempts involving the hardware wallet maker. In August, a Trezor user said he lost his life savings after a sponsored Google search result directed him to a fake website hosted through Google Sites.
Trezor said at the time that it was seeing more phishing websites impersonating the company through sponsored search results and warned customers never to enter wallet backups on websites.
Earlier in 2026, scammers took the impersonation attempts offline by sending fake Trezor and Ledger letters to hardware wallet owners. The letters contained QR codes leading to phishing websites that requested 12, 20 or 24-word recovery phrases under the pretext of completing authentication or transaction checks.
BitBox and CoinTracking accounts used in phishing wave
BitBox identified a similar campaign on Wednesday and warned users not to follow instructions contained in fraudulent emails sent under its name.
Its initial investigation found that several Bitcoin companies had been targeted and appeared to share the same newsletter provider. BitBox contacted the provider, warned newsletter subscribers and reported the phishing domains while investigating how the emails had been distributed.
The attack came weeks after BitBox patched two wallet vulnerabilities involving firmware installation and Bitcoin address handling. BitBox said there was no known exploitation of either flaw and reported no stolen user funds.
CoinTracking customers received a different phishing lure designed around the service’s portfolio tracking and tax-reporting functions.
The fraudulent email carried the subject line “Data Breach Notice: Please refresh API Keys as soon as possible,” according to CoinTracking. The company warned customers not to follow links contained in the message while it investigated the compromise of its Brevo account.
Brevo’s findings show that phishing emails represented only part of the activity across the 138 accessed accounts. The attacker exported contacts from 43 accounts, potentially leaving address lists available for use outside Brevo’s own mailing infrastructure.
Trezor is already treating its full newsletter list as potentially known to the attacker, although the company said it had not received confirmation that all 347,000 addresses were exported.
The hardware wallet maker has faced a separate customer data exposure this year involving logistics provider ShipMonk. Trezor initially disclosed in August that information belonging to 13,689 customers had been exposed through the shipping provider.
The scope later increased after Trezor learned that records belonging to approximately 67,000 additional U.S. customers had remained in ShipMonk’s systems. The older records covered purchases made between November 2019 and August 2021 and included names, email addresses, phone numbers, shipping addresses and order numbers.
Trezor said its own systems were not compromised in the ShipMonk incident and no private keys or recovery phrases were exposed. The company had previously received assurances that the older customer records had been deleted before learning on Sept. 2 that they remained stored by the provider.
Crypto World
Report Links $2.08M in LAPTOP Sales to Wintermute-Tagged Wallet

Onchain analyst Lookonchain reported that an address tagged by Arkham as Wintermute sold 466,255 LAPTOP for about $2.08 million after receiving tokens traced to the project team. For LAPTOP holders, the report identified project-allocated inventory moving out of a Wintermute-tagged wallet on the… Read the full story at The Defiant
-
Tech3 days agoMemory prices are slowing because buyers ran out of money
-
Business1 day agoMicron Stock Climbs Above $1,031 as AI Memory Crunch and a $50 Billion Outlook Fuel the Rally
-
Crypto World2 days agoBitcoin price risks $76K drop as $78K support weakens
-
Business1 day agoAMD Stock Climbs After Management Lifts 2027 Data Center Outlook Toward $70 Billion in AI Sales
-
Crypto World2 days agoEthereum price stalls below $2,500 as ADX drops to 11
-
Crypto World3 days agoRobinhood Stock: How To Take Advantage With Reduced Risk
-
NewsBeat2 days agoWhat went right this week: an ‘historic’ fall in violent crime, plus more
-
Crypto World1 day agoBitcoin price risks $70K if $78K neckline breaks
-
Crypto World3 days agoBrent Crude Oil Moves Above $100 for the First Time in 3 Months
-
Crypto World2 days agoBitcoin price holds near $79K as cycle drawdowns narrow
-
NewsBeat3 days agoEngland up in reading, maths and science rankings as Scotland and Wales dip
-
Business2 days agoMeta debuts long-awaited personal AI agent, Muse
-
Sports3 days agoPhones confiscated, players sent home: Pakistan’s England tour turmoil revives memories of Mohammad Amir, Salman Butt and Mohammad Asif’s 2010 Lord’s spot-fixing scandal | Cricket News
-
Crypto World3 days agoIntel Stock Jumps 9% on Chip Price Hike Report, US Stake Gains $36 Billion
-
Crypto World1 day agoEthereum price breakout hinges on a close above $2,535
-
Crypto World3 days agoPump Fun and Kraken delete Hunter Biden $LAPTOP promotion
-
Crypto World3 days agoVisa expands stablecoin card network to 160 programs
-
Tech3 days agoStrong Password Policy and Password Manager Guide
-
Crypto World17 hours ago2 Chip Stocks Broke Out This Week. Neither Was Nvidia
-
Tech2 days agoMeta debuts its Muse AI agent. Will consumers trust it?

You must be logged in to post a comment Login