Crypto World
Liquid Network attacker crossed into theft: Immunefi CEO
Immunefi CEO Mitchell Amador has said the Liquid Network attackers lost any claim to white-hat status by retaining 598.5 BTC after returning 3,400 BTC from the roughly 4,000 BTC exploit.
Summary
- Roughly 598.5 BTC remains with the attackers after they returned 3,400 BTC.
- Amador said coordinated disclosure ends when a researcher sets rescue terms without prior approval.
- Protocols should establish rescue rules and bounty limits before an exploit occurs.
- Immunefi’s CEO defended the 10% bounty convention when teams approve it in advance.
Immunefi founder and CEO Mitchell Amador told crypto.news that moving user assets without permission cannot be treated as a rescue when the researcher later keeps part of the funds or sets payment terms.
“Coordinated disclosure ends the moment you set the terms yourself,” Amador said. “The money was never yours to save, so moving it is not a rescue.”
His comments address the dispute left by the Liquid Network incident, in which unidentified actors withdrew roughly 4,000 BTC, valued at about $320 million at the time, before describing themselves as whitehats. They returned 3,400 BTC after Blockstream patched the affected bridge nodes but retained 598.5 BTC.
Blockstream has rejected the group’s demand for a 10% bounty and has said it will not pay for the return of the remaining Bitcoin. The company also rejected the attackers’ claim that the operation amounted to responsible disclosure.
Liquid Network attackers could not set their own terms
Amador said a security researcher must use private disclosure channels, preferably through a defined bug bounty program, instead of taking assets and negotiating a reward afterward.
“Keep a dollar of user funds, and it is theft, whatever the intent was at the outset. The path for a researcher is private disclosure, ideally within a well-defined program.”
The distinction rests on authorization rather than the researcher’s stated motive. Under Amador’s view, finding a real vulnerability does not give someone the right to move user assets, hold them as collateral, or decide what compensation is owed.
Blockstream took a similar position in its Sept. 11 response. As previously reported by crypto.news, the company said taking assets without permission and refusing to return them constituted theft rather than whitehat work.
The company said its earlier discussions with the actors were intended to recover user funds and protect the Bitcoin community. According to Blockstream, engaging in those talks did not mean it had accepted either the withdrawal or the later bounty demand.
A technical review of the exploit found that a cache-key collision in the confidential transaction verification logic allowed the actors to create unbacked L-BTC. They then used SideSwap’s peg-out service to obtain real Bitcoin from the federation reserve.
Federation keys were not compromised, according to Blockstream. The incident instead involved verification logic in the Elements codebase, while the federation nodes were running a release that did not contain the relevant fix.
Rescue terms should exist before an exploit
Rather than negotiating under pressure after funds have moved, Amador said serious protocols should decide their rescue conditions before an emergency occurs.
“Yes, rescue terms must exist ahead of an exploit,” he said. “All serious protocols should set these in advance.”
Predetermined rules can define which systems researchers may test, how they must disclose a vulnerability, and what actions they can take during an active incident. They can also state the maximum bounty, payment conditions, and legal protections available to researchers who remain within the approved scope.
Immunefi developed the Whitehat Safe Harbor framework to establish such conditions before a protocol faces an attack. Amador, who helped shape the framework and has participated in live exploit response teams, compared emergency action with saving a house from a fire: the need for help does not authorize every possible rescue method.
Advance agreements also give protocol teams a basis for distinguishing approved intervention from coercion. Without prior terms, an actor who controls user funds can demand payment while the project faces losses, service disruptions, and pressure from token holders.
Liquid’s actors initially communicated through messages placed in Bitcoin transactions and told Blockstream to patch the flaw before they returned the funds. After Blockstream confirmed that affected bridge nodes had been patched, the group sent 3,400 BTC back to the federation wallet.
No publicly disclosed agreement had allowed the group to retain the remaining 598.5 BTC. The amount also exceeds 10% of the approximately 4,000 BTC involved, although the reported demand centered on a 10% reward.
The 10% crypto bounty convention still has a role
While rejecting the Liquid actors’ attempt to impose their own terms, Amador defended the crypto industry’s informal practice of offering up to 10% of funds at risk as a whitehat bounty.
Without a common reference point, he said, each settlement would need to be negotiated from the beginning, giving an attacker more leverage during an active incident. A defined percentage gives researchers a legal payment route while allowing a protocol to recover most of the exposed assets.
“Ten percent of a $100M exploit is $10M earned legally, with nobody hunting you afterwards,” Amador said. “The alternative for them is moving nine figures onchain while every forensics firm watches.”
The 10% figure has appeared in several recovery offers, but projects usually state the terms themselves. In August, BTCPay Server supporters backed a reward equal to 10% of recovered funds after attackers obtained LND admin macaroon credentials. The proposed payout was capped at 3 BTC if all stolen assets were returned.
Cetus Protocol followed a different formula after its May 2025 exploit. A flaw in its automated market maker logic caused losses of more than $223 million, while the Sui Foundation coordinated with validators to freeze about $163 million. Cetus later announced a $5 million reward for information leading to the identification of the attacker, according to its post-exploit review.
Amador said the reward should generally reach up to 10% of funds at risk while remaining subject to a cap the protocol can afford. Setting the amount too low could make theft more attractive than disclosure, he said, while an excessive payout could leave the rescued project unable to continue operating.
“Price it too high, and paying out can kill the protocol you just saved, which helps nobody,” he said.
Projects may still pay above their stated cap when a report warrants a larger reward, Amador added. Under his proposed model, the protocol retains control over that decision instead of allowing a researcher to establish the fee after taking custody of user assets.
U.S. prosecutions show the risk of unauthorized exploits
For U.S.-based researchers, returning funds or offering to negotiate does not necessarily prevent criminal charges when the original access was unauthorized.
In December 2023, former security engineer Shakeeb Ahmed pleaded guilty to computer fraud after exploiting two decentralized exchanges and obtaining more than $12 million. According to the U.S. Justice Department, Ahmed negotiated with one platform and proposed returning the stolen funds except for $1.5 million if the exchange agreed not to contact law enforcement.
Federal prosecutors said Ahmed later agreed to forfeit more than $12.3 million, including about $5.6 million in fraudulently obtained cryptocurrency. In April 2024, a federal judge sentenced him to three years in prison and ordered the forfeiture of the stolen assets.
Crypto World
SlowMist warns Darksword may target wallets on iOS 26.5
SlowMist has warned that attackers may have adapted the Darksword exploit chain to compromise devices running iOS 26.5 and extract private keys from self-custody crypto wallets.
Summary
- Darksword attacks can begin when an iPhone user opens a malicious link in Safari.
- SlowMist says attackers may have adapted the exploit chain to iOS 26.5.
- Google previously confirmed Darksword activity against iOS 18.4 through iOS 18.7.
- Three U.S. investors separately allege fake wallet apps caused $1.835 million in Bitcoin losses.
SlowMist Chief Information Security Officer 23pds said attackers are using Darksword to bypass Apple’s security controls, gain extensive access to affected iPhones, and collect data from locally installed cryptocurrency wallets.
The reported iOS 26.5 exposure has not been independently confirmed by Apple or Google. Google Threat Intelligence Group’s published research documented support for iOS versions 18.4 through 18.7, while 23pds said attackers have since modified the tool to work against the newer operating system.
Darksword may reach iOS 26.5 devices
Google’s Threat Intelligence Group identified Darksword as a full iOS exploit chain that combines six vulnerabilities to compromise devices and deliver separate malicious payloads. The company tracked related activity from at least December 2025 through March 2026.
According to Google, the original framework supported iOS 18.4 through iOS 18.7. One flaw used against iOS 18.6 to 18.7 devices, tracked as CVE-2025-43529, affected JavaScriptCore, the engine that processes JavaScript in Safari. Apple patched the flaw in iOS 18.7.3 and iOS 26.2 after Google reported it.
SlowMist’s latest assessment extends the potential exposure to iOS 26.5, although the security company’s claim has not received official confirmation. No technical analysis cited in the warning established which vulnerability or replacement exploit could let Darksword compromise the newer release.
Attackers generally initiate the compromise through social engineering, according to 23pds. A target receives a link through a social network, messaging app, or another communication channel and opens the page in Safari. Malicious web content then attempts to exploit the browser and other iOS components without requiring the user to install a conventional application.
Once the chain succeeds, the attacker may obtain root-level control, 23pds said. Such access can remove the isolation that normally prevents one application from reading files and credentials belonging to another, placing private keys and other wallet records stored on the device at risk.
Malicious Safari links can expose wallet data
Google found several groups using Darksword with different final-stage payloads, rather than one fixed piece of malware. Depending on the campaign, the payloads could collect account details, messages, browser records, files, location history, saved Wi-Fi data and information linked to cryptocurrency wallets.
The security company connected separate operations to victims in Saudi Arabia, Turkey, Malaysia and Ukraine. Google associated some activity with commercial surveillance providers and suspected state-linked groups, while researchers also found signs that financially motivated actors had gained access to advanced iPhone exploitation tools.
No victim total or confirmed amount of cryptocurrency stolen through Darksword was included in the material supplied by SlowMist. The warning instead focused on the framework’s ability to reach wallet information after compromising the device that stores it.
A similar delivery method appeared in an earlier mobile threat. In March, crypto.news covered Google’s findings on Coruna, an exploit kit containing 23 vulnerabilities across five attack chains. Coruna targeted iPhones running versions from iOS 13 through iOS 17.2.1 and could search files and images for terms such as “backup phrase” and “bank account.”
Google researchers said Coruna fingerprinted a visitor’s device before selecting an exploit suited to the iPhone model and software version. Some operators placed the kit on fake gambling and cryptocurrency sites, allowing the compromise to begin when a target loaded the page.
Recent iOS threats have targeted private keys
Darksword is not the only recent security threat involving cryptocurrency data on Apple devices. Binance warned iPhone and iPad users on Sep. 19 about malicious code found in FomoPeek versions 1.1 and 1.2.
Researchers examining the app found a kernel exploitation framework with eight attack methods and declared support covering iOS 12.0 through 18.7.2 and iOS 26.0 through 26.1. The malicious modules could escape the iOS sandbox, decrypt Keychain data, and access private keys, wallet recovery phrases, account credentials, and files held by other applications, according to a report on FomoPeek.
Binance advised anyone who had installed the affected versions to remove the app, update iOS, and avoid reinstalling it. Self-custody users were also told to create a new wallet on a clean device and transfer their assets, since deleting a malicious app would not protect a wallet if its private key or recovery phrase had already been copied.
Darksword uses a different route because its documented campaigns rely on malicious or compromised websites. Both cases, however, involve attempts to defeat the controls that ordinarily prevent software from obtaining sensitive records held elsewhere on an iPhone.
SlowMist advised users to install mobile operating-system updates promptly and avoid opening unsolicited links sent by strangers. Google and Apple have also treated current software as a central defense because Apple has patched the six vulnerabilities documented in the original Darksword chain.
U.S. investors have also sued Apple over fake wallets
For U.S. crypto holders, the Darksword warning follows a separate dispute over malicious wallet software distributed through Apple’s official marketplace. Three investors filed a federal lawsuit alleging that fake applications impersonating Sparrow Wallet appeared in the App Store and caused about $1.835 million in Bitcoin losses, according to earlier court coverage.
The plaintiffs’ allegations concern fraudulent applications rather than a browser-based exploit. Their case nevertheless centers on the security of Apple’s mobile distribution system and the financial damage that can occur when users trust software presented as a legitimate cryptocurrency wallet.
Another counterfeit application posing as Ledger Live allegedly stole at least $9.5 million from more than 50 victims between April 7 and April 13. Blockchain investigator ZachXBT traced funds from Bitcoin, Ethereum, Solana, Tron, and XRP users to more than 150 KuCoin deposit addresses and a mixing service.
The fake Ledger application asked users to enter their 24-word recovery phrases during what appeared to be a standard wallet setup. Apple later removed the listing, while one victim said he downloaded it while configuring a Ledger device on a new MacBook.
Unlike the Darksword chain, the fraudulent Ledger app did not need to break the operating system’s security controls. Users exposed their wallets by entering recovery phrases into the impersonating software, giving its operators control of every address derived from those phrases.
Crypto World
What Russia’s Parliamentary Election Results Mean for Putin and the War
Trump’s latest comments on the matter came Monday.
“Russia has unfortunately lost control of its Diesel Oil Industry due to its War with Ukraine. A large number of their Diesel refineries have been blown up and are, at least temporarily, out of commission,” Trump said on Truth Social on Sept. 21. “This ridiculous and never ending War with Ukraine must be ended.”
Beginning Saturday, as Russia entered its last day of voting, the government said it intercepted more than 1,600 Ukrainian drones, including 450 directed toward Moscow. The figures, attributed to Moscow Mayor Sergey Sobyanin and reported by state media TASS, have not been independently verified.
According to a statement by Sobyanin on Telegram, this was the largest ever drone attack on the Russian capital, damaging the city’s oil refinery.
How the world reacted to the preliminary election results
European powers have largely condemned the results. That includes France’s foreign ministry, which released a statement on Monday saying that the vote did not meet the conditions for “free, pluralistic, democratic elections.”
Crypto World
Bitcoin price news: BTC eyes $90,000 as leverage is building
Bitcoin has broken out to $86,000, but analysts say the next leg depends on whether spot buyers continue to show up as leverage builds.
Source link
Crypto World
Massive $1 Billion in Liquidations as Bitcoin Taps $87K: What’s Next?
Bitcoin’s price is closing in on $87,000 following an explosive rally, which triggered over $1 billion in liquidations across the crypto derivatives market.
The cryptocurrency reached an intraday high at exactly $87,000 (at the time of this writing), with its total market cap climbing toward $1.8 trillion.

The move extends Bitcoin’s impressive recovery from approximately $75,000 last week and has pushed it to its highest price since January.
Shorts Get Crushed as BTC Rallies Higher
The sharp move caught leveraged traders positioned for further downside.
Data from CoinGlass shows that roughly $1 billion worth of positions were liquidated, of which $900 million were short. More than 139,000 traders saw their positions force-closed, with the single largest liquidation happening on Hyperliquid, which carried a face value of slightly over $20 million.
This massive imbalance suggests that forced short closures provided additional momentum as BTC cleared several resistance levels in quick succession – an avalanche-like event, if you will.
This is called a short squeeze or a liquidation cascade.
What Happens Next for Bitcoin?
Attention is now quickly shifting toward the $88,000 area and beyond toward $90K.
As CryptoPotato recently reported, the popular analyst Doctor Profit highlighted Bitcoin’s reclaim of its 50-week moving average, currently near $78,700, as a very important development from a technical price point. The analyst identified $88K as the next potential target.
Some other analysis places a major bearish block at around this level. Therefore, a sustained break above $88K could bring $90K and even $95K into focus, while the region around $80K and $82K has now turned into an important support zone.
The post Massive $1 Billion in Liquidations as Bitcoin Taps $87K: What’s Next? appeared first on CryptoPotato.
Crypto World
NEAR Rallies ~80% Weekly as Intent Volumes Approach $30B
Near Protocol’s native token has jumped sharply this week as the network expands privacy-focused trading and related infrastructure. Over the past seven days, Near’s token traded around $4.29—up about 78.2%—according to CoinGecko, with CoinGecko also showing total cryptocurrency market capitalization up roughly 6% over the same period.
The rally appears tied to new privacy features launched for perpetual futures trading on near.com, alongside a growing ecosystem around Near Intents, a platform that coordinates cross-chain swaps by matching users with market makers.
Key takeaways
- CoinGecko data shows Near (NEAR) gained about 78% in seven days, outpacing a broader market that rose around 6%.
- Near says deposits and withdrawals for perpetual futures trading on near.com are now confidential by default, obscuring the connection between funding wallets and Hyperliquid trading accounts.
- Near.com’s confidential TVL surpassed $70 million, triggering the first snapshot under the NEAR@3.33 incentive program.
- According to the NEAR Intents Explorer, cumulative volume has reached about $29.3 billion, with $842 million recorded over the last seven days.
Confidential perpetual futures trading becomes the default
Near’s push into privacy accelerated this week after the protocol said on Thursday that deposits and withdrawals for perpetual futures trading through near.com are now confidential by default. In Near’s description, the feature is designed to hide the link between a trader’s funding wallet and a dedicated Hyperliquid trading account.
From an investor and user perspective, the practical effect is straightforward: traders who use near.com for perpetual futures can reduce exposure of wallet-to-account relationships that would otherwise be visible through on-chain flows or traceable account linkages. While the measure doesn’t necessarily prevent all forms of identification—market activity and other metadata can still reveal information—it directly targets a common privacy weakness in trading account structure.
The timing matters because the feature aligns with a broader industry narrative around privacy and confidentiality in finance. Near’s move effectively shifts attention from privacy as a niche value proposition toward privacy as a product feature for mainstream trading workflows.
Confidential TVL milestone and NEAR@3.33 incentives
On the same day, Near also reported that near.com’s confidential total value locked (TVL) crossed $70 million. The announcement said this milestone triggered the first snapshot under its NEAR@3.33 incentive program.
Near stated that the program set aside 333,333 milestone tokens for the first distribution. Under the program rules described in the release, the tokens unlock and convert to NEAR when the token’s three-day volume-weighted average price reaches at least $3.33.
This kind of condition can be significant for token-related expectations because it ties incentives to a price threshold rather than distributing immediately at the moment the TVL checkpoint is recorded. Traders and liquidity providers typically watch how these unlock mechanics may change selling pressure dynamics (for example, whether participants anticipate distributions once a price level is reached).
Near Intents keeps scaling volumes
Beyond trading privacy, Near’s ecosystem is also expanding through NEAR Intents, which enables users to request cross-chain swaps while market makers compete to execute them. On Monday, the NEAR Intents Explorer showed cumulative volume of roughly $29.3 billion.
The explorer also indicated $842 million in volume over the preceding seven days. For the prior 24 hours, privacy-focused Zcash wallet ZODL appeared as the third-largest referral source by volume, generating about $3.8 million across 458 transactions. The explorer also listed a large transaction involving roughly $613,000 worth of ZEC over the previous 24 hours.
While these figures reflect activity within the intent execution network rather than spot trading on a centralized exchange, they matter because higher intent volume can translate into stronger routing, execution competitiveness, and incentives for liquidity provision—factors that can make cross-chain execution more reliable for end users.
Why Zcash is showing up in the privacy narrative
Activity around ZEC in NEAR Intents has drawn commentary from researchers inside the ecosystem. Bitwise research analyst Camran Khosravi said Near and Zcash are “complements,” arguing that Near provides confidential cross-chain infrastructure and access to liquidity for ZEC holders.
Khosravi also cautioned about how TVL metrics can behave. He noted that NEAR Intents’ TVL can rise when the price of ZEC already held within the system increases, even if new deposits do not occur. That distinction is important for interpreting growth: TVL moving up doesn’t always mean user inflows are increasing at the same pace.
Near has continued extending its privacy focus beyond trading. In July, it introduced NEAR AI staking-based payments through near.ai, allowing users to stake NEAR to receive credits for confidential AI inference and agent hosting while keeping ownership of the underlying tokens.
Taken together, these announcements place privacy at the center of Near’s product strategy—spanning trading account confidentiality, cross-chain swap execution, and even confidential compute workflows.
Looking ahead, market participants are likely to watch two things closely: whether near.com’s confidential trading features and the NEAR@3.33 incentive mechanics translate into sustained liquidity growth, and how privacy-oriented assets like ZEC continue to contribute to NEAR Intents’ volume without relying solely on price-driven TVL increases.
Crypto World
CLARITY Act setback shifts focus to Coinbase amid crypto policy debate
After more than two years of lobbying for clearer rules in Washington, crypto policy took another hit this week. The U.S. Senate failed to advance the CLARITY Act on Tuesday, missing the 60 votes required to move the bill to the floor—an outcome that compresses an already tight legislative window ahead of the Nov. 3 midterm elections.
Strategists highlighted that the fallout may not be evenly distributed across the sector. In parallel, Wall Street research is making bold calls on layer-2 networks and staking yields, while industry executives are warning that artificial intelligence may be weakening crypto liquidity and increasing the security burden for smaller teams.
Key takeaways
- The Senate’s procedural failure to advance the CLARITY Act narrows the bill’s remaining path this year as election-season timing tightens.
- Saxo strategist Ruben Dalfovo argues Coinbase is more directly exposed than some peers because market-structure rules could affect registration, tradable assets, and platform participation.
- Standard Chartered expects Arbitrum to outperform other large crypto networks through 2030, attributing part of that view to evolving economics from major builders.
- Bitmine’s treasury strategy targets staking revenue from a large Ether position, projecting annualized income based on current staking rates.
- Phemex’s CEO says AI is becoming a “net negative” for crypto by pulling liquidity away and enabling attackers, raising security costs.
CLARITY Act stalls as Senate misses the procedural threshold
The CLARITY Act’s failure to clear the Senate procedural vote is a significant setback for the industry’s push for regulatory clarity. According to Cointelegraph’s report on the vote outcome, the bill did not reach the 60-vote threshold needed to bring it to the floor for debate.
Because the Senate calendar tightens ahead of the Nov. 3 midterm elections, the missed procedural step reduces the likelihood that the bill can be fully processed this year. For market participants, the immediate implication is that uncertainty around the timing and shape of potential federal rules may persist longer than many in crypto had hoped.
Why Coinbase could feel the setback more than others
Saxo Bank strategist Ruben Dalfovo argued in a note following the vote that Coinbase is among the most exposed names. As Cointelegraph reported in coverage of his view, Dalfovo said Coinbase’s trading business is directly tied to U.S. market-structure rules—meaning new requirements could influence registration obligations, the set of assets that can be traded, and who is permitted to participate on the platform.
Dalfovo’s comparison matters for investors because it distinguishes between forms of exposure. Cointelegraph noted that he viewed some other crypto-linked companies as less directly affected by market-structure rules, with their key sensitivities tied to different variables—for example, Circle’s exposure connected to USDC adoption and reserve-related economics, and Strategy’s emphasis on its Bitcoin holdings and related access to financing.
The market reaction described by Cointelegraph reflected this differentiation. Shares of Coinbase, Circle, and Strategy reportedly fell between 5% and 10% after the vote and remained lower the next day, indicating traders were repricing the near-term legislative probability and its potential effect on business models.
Standard Chartered doubles down on Arbitrum’s long-run upside
While U.S. regulatory timelines remain uncertain, analysts are looking to onchain infrastructure for a different kind of catalyst. Standard Chartered, in research highlighted by Cointelegraph, is projecting that Arbitrum could outperform Bitcoin and Ether through 2030.
The bank’s thesis, as summarized by Cointelegraph, centers on network economics. Geoff Kendrick, Standard Chartered’s global head of digital assets research, pointed to a revenue-sharing structure in which Arbitrum receives 10% of net protocol revenue from companies building on it. He also cited Robinhood Chain—launched in July—as a meaningful change to Arbitrum’s economics, with September revenue expected to reach $5 million, described as more than five times the prior level.
Standard Chartered’s base-case projection is ARB at $10 by 2030, which it frames as a roughly 70-fold increase from current levels around $0.14. Cointelegraph also noted that ARB had gained 86% over the prior month at the time of the report.
Investors should treat such projections as scenario-based rather than guarantees. Standard Chartered’s assumptions, according to Cointelegraph, depend on broader adoption—tokenized assets reaching $39 billion and forecasts of $4 trillion by 2028. The core uncertainty remains whether the pace of financial and institutional migration to tokenized onchain products can match these expectations, and whether Arbitrum’s revenue share meaningfully compounds as new builders launch and scale.
Bitmine’s Ether treasury turns staking into a recurring revenue bet
Another angle on the crypto business cycle is coming from balance-sheet strategy rather than regulation: Bitmine is positioning its treasury to earn recurring income through staking. Cointelegraph reported that the company projects $334 million in annualized staking revenue from its Ether holdings.
As described in the report, Bitmine said it added 27,180 ETH last week, bringing total holdings to 5.95 million ETH valued at $15.4 billion. The company claims that more than 5.06 million ETH is now staked, generating an estimated $334 million in annualized revenue at current rates.
Cointelegraph also contextualized the scale by noting that Bitmine’s staked amount represents roughly 4.9% of Ether’s circulating supply. The comparison to other treasury strategies is important: staking allows recurring income from crypto holdings, which can differ from treasury approaches focused on appreciation without an income stream.
Cointelegraph added that Grayscale Ethereum Staking ETF stakes 84.6% of its Ether, citing details on the fund’s webpage. The implication for readers is that staking-linked income models may increasingly be evaluated alongside pure exposure to price movements—particularly when volatility pushes investors to ask how returns are generated.
Phemex CEO warns AI is worsening crypto security and liquidity
The business side of crypto is also grappling with technology that cuts both ways. Federico Variola, CEO of Phemex, told Cointelegraph that AI has been a “net negative” for crypto—draining liquidity while empowering attackers to find and exploit weaknesses in protocols.
In Cointelegraph’s Chain Reaction discussion, Variola argued that AI has “empowered a lot of bad actors” and driven up cybersecurity costs, especially for smaller teams that may lack the resources to keep pace. He referenced an incident from July in which attackers drained roughly $116 million in Bitcoin from more than 5,200 addresses associated with a Coldcard hardware wallet flaw that has been widely believed to have been discovered through malicious AI use.
The CEO also highlighted a broader capacity gap: Cointelegraph reported that Coinkite CEO Rodolfo Novak warned AI-assisted code review can now outpace seasoned experts. Variola’s concern extends to user behavior as well—he suggested the scale of AI-enabled risk could make self-custody and DeFi less attractive to retail users, potentially pushing the ecosystem toward greater centralization.
Not all views are purely negative. Cointelegraph included a response from CertiK’s Natalie Newson, who suggested AI can also function as “one of the biggest defenses.” For readers, the practical takeaway is that AI’s impact is likely to be dual: it can accelerate both offensive tooling and defensive monitoring, raising the stakes for security engineering across exchanges, custodians, and protocols.
What to watch next is whether the CLARITY Act’s stalled momentum can be revived in the remaining Senate calendar, and—on the market side—whether onchain revenue narratives like Arbitrum’s can translate assumptions into measurable adoption and sustained network activity as policy uncertainty persists. Meanwhile, security teams should expect AI-driven threat modeling to become less optional and more foundational.
Crypto World
Shib Holds Ground As Spot Flows Remain Mixed
SHIB Knight argues that SHIB is not in its process of moving and is still early. The opinion is based on the analysis of the chart that displays prices close to long-term lower-ranges consolidation. However, the current structure of the chart does not show that a breakout from resistance occurred.
The extended timeframe shows a clear downtrend to $0.00000546. Before that happened, there was a sharp rise up to the level of $0.000045. Price had several attempts that resulted in failure at the levels of $0.000020 and $0.000030. It means that these levels were zones of active sales before.
The price began to fall slowly while being in the range of $0.000005-$0.000007. There are recent candles that are compressed at this lower level. It means that there is a transition from active selling to trading.
The current market chart displays the price at $0.000005416. The token rose by 0.4% over the past 24 hours shown on the chart. Trading activity was within the range of about $0.00000535 and $0.00000550.
Spot Flows Still Mixed Across Exchanges
$0.00000550 still looks like the nearest visible resistance point. Multiple attempts to reach this resistance point have not succeeded in sustaining a price advance there. In the meantime, the immediate downside reference for the range is $0.00000535–$0.00000540.
The spot-flow chart demonstrates many alternations of positive and negative flows. Both green and red bars have been seen all the way from November through September. No side showed any consistent behavior during the whole period.
There were several positive spikes in December and January. However, the price line kept deteriorating further despite these periods. This indicates that occasional inflows could not generate a consistent upward price formation.
The largest visible inflow was registered at the end of July. It was a green spike that exceeded $5 million and looked higher than the majority of other spikes. However, it had no effect on the subsequent price movement.
Resistance Defines The Technical Phase Ahead
Exchange volumes continue to be split between the large exchanges as well. There was trading of approximately $119.10K on Binance, whereas there was trading of about $84.04K on Upbit. Trading of about $44.08K and $34.64K was done on OKX and Bybit respectively.
The short-term technical analysis continues to see multiple attempts at recovering near $0.00000550. If the price manages to breach that level, it will change the immediate technical phase of the market and indicate that bulls have gained more power. Until then, price remains inside the defined consolidation phase.
The longer-term technical picture sees a possible rise towards $0.000010 and $0.000013. However, this is still speculative and price movement is needed to validate these moves.
There is also higher time frame resistance in the form of $0.000020 and $0.000030. In previous bullish waves, sellers emerged near both those levels. Any bullish wave will therefore have to navigate several resistance levels.
For the time being, SHIB continues to trade near its long-term base, with mixed flow in the spot market and resistance defining the current recovery phase. The reaction near $0.00000550 is an important technical level.
Crypto World
AMD Hits $1 Trillion Market Cap: 3 Reasons Nvidia Sat Out the AI Rally
Advanced Micro Devices (AMD) touched a $1 trillion market value for the first time on Monday, peaking at $615.99 a share before easing back below that line.
The stock last traded at $609.65, up over 8%, for a market capitalization of $995 billion. Nvidia gained 2.33% over the same session.
AMD Passed a Milestone Intel Could Not
Intel actually climbed further, rising 12.03% to $121.67. Arm Holdings gained 15.47%. Neither came near the line. Intel is worth $639.32 billion, Arm $339.93 billion.
The milestone, not the size of the move, made AMD the story. It becomes the fourth US chipmaker valued above $1 trillion, after Nvidia, Broadcom and Micron.
3 Reasons Nvidia Sat Out the Rally
The first is what investors were buying. Meta’s consumer AI agent Muse reached the top of Apple’s US App Store, and traders read that uptake as proof that answering live user requests, a process called inference, will need far more central processing units (CPUs) working alongside graphics chips. Intel chief executive Lip-Bu Tan described the squeeze at the Splunk conference in Denver last week.
“CPU demand is so high that we can only supply 50% of customers,” said Lip-Bu Tan, chief executive at Intel.
Nvidia sells mainly graphics processors, so money chasing CPU suppliers routed around it.
The second is company-specific. TrendForce reported on September 18 that AMD warned customers of increases near 10% on AI accelerators, graphics chips and motherboard chipsets from the fourth quarter, passing on higher costs from Taiwanese manufacturer TSMC. Ryzen desktop processors were not named. That lifts AMD margins alone.
The third is scale, and it cuts both ways. Nvidia did rise. At $5.49 trillion, its 2.33% added roughly $128 billion in a single session, more than a third of Arm’s entire value. Sitting out looks different at that size. Measured in percentages, which is how Monday was scored, it barely registered.
BeInCrypto flagged this rotation on Sept. 10, when Intel and AMD broke multi-month downtrends while Nvidia gained 2.12%. AMD closed at $521.10 that day.
The move lands inside a live argument over whether AI spending has peaked. Chip stocks sold off earlier in September after Anthropic chief executive Dario Amodei warned of a slowdown.
Fourth-quarter results will show whether the price increases reach the income statement, or whether Monday bought demand that has not arrived.
The post AMD Hits $1 Trillion Market Cap: 3 Reasons Nvidia Sat Out the AI Rally appeared first on BeInCrypto.
Crypto World
NOWPayments Releases Cross-Chain Payout Data Revealing Key Performance Benchmarks Across TRON, BNB Chain, and Solana
[PRESS RELEASE – Tallinn, Estonia, September 21st, 2026]
NOWPayments today published new empirical data analyzing six months of enterprise payout activity, offering a comparative performance benchmark across TRON, BNB Smart Chain, Solana, Bitcoin, and Ethereum to help businesses select optimal blockchain rails based on speed, transaction volume, and cost efficiency.
The dataset reveals distinct operational advantages depending on transfer priorities: Solana recorded the fastest average payout speed at 1 minute and 45 seconds while accounting for 3.08% of volume and 3.86% of transactions. TRON led in total monetary volume at 43.69%, and BNB Smart Chain handled the largest share of individual payout transactions at 48.23%.
High-Frequency Payouts Put BNB Smart Chain in the Lead
Together, TRON, BNB Smart Chain, Ethereum, Bitcoin, and Solana accounted for 94.04% of payout volume and 77.84% of payout transactions during the period analyzed.
BNB Smart Chain accounted for 48.23% of transactions, compared with 15.73% for TRON. Its share of payout volume was lower at 21.75%.
The network handled far more individual transfers without carrying the largest share of value, a pattern consistent with higher-frequency, lower-value payouts in the NOWPayments dataset.
Higher-Value Payouts Put TRON in the Lead
TRON moved 43.69% of payout volume, more than twice BNB Smart Chain’s 21.75% share, despite accounting for a much smaller share of transactions.
Based on those shares, the average TRON payout was approximately 6.2 times larger than the average BNB Smart Chain payout during the period. The networks served different payout patterns: TRON carried more value, while BNB Smart Chain handled far more individual transfers.
Ethereum ranked third by volume at 18.84% and represented 7.42% of transactions. Bitcoin accounted for 6.68% of volume and 2.60% of transactions, while Solana represented 3.08% of volume and 3.86% of transactions.
The data suggests a practical framework for matching the network to the payout flow:
The data offers a starting point, not a universal network recommendation.
When Speed Matters, Solana Leads
Solana led on speed with an average payout time of 1:45. Bitcoin followed at 2:53, ahead of TRON at 3:08 and BNB Smart Chain at 3:13. Ethereum recorded the longest average at 5:56.
The gap between the fastest and slowest networks was 4 minutes and 11 seconds. Every network in the comparison still averaged less than six minutes, while TRON and BNB Smart Chain were separated by only five seconds.
The fastest network was not the most widely used. That points to a broader principle: crypto infrastructure should be evaluated across the full movement of funds, not by a single headline metric.
Kate Lifshits, Commercial Director at NOWPayments, applies the same data-first approach in Crypto That Works for Business, her Cryptopolitan series on the commercial impact of crypto payments. The first column, the 22% Sales Boost Hiding in Your Crypto Checkout, examined checkout performance; future editions will cover other points where payment infrastructure affects revenue, costs, and growth.
“The useful question is not which network tops a leaderboard. It is what a specific payout flow needs to optimize: value, frequency, speed, or cost,” said Kate Lifshits, Commercial Director at NOWPayments.
When Cost Matters, The Best Route May Not Be a Blockchain Network
When minimizing payout costs is the priority, comparing blockchain networks may be the wrong place to start.
NOWPayments allows businesses to send payouts to ChangeNOW Pro wallets with no network or service fees within the ecosystem. Creator Andy Tries Coding publicly tested the route and reported receiving a fee-free payout in under five seconds.
Recipients are identified by email and confirm the transfer before funds move, so businesses do not need to collect wallet addresses at the beginning of the payout process. An interactive guide walks through the process from payout creation to recipient access.
The takeaway is simple: define the payout flow first, then select the network or route. Value, frequency, speed, and cost will not point every business to the same answer.
About NOWPayments
NOWPayments is a crypto business ecosystem designed to help companies accept payments, automate mass payouts, manage stablecoin treasury, and scale global digital asset operations through a single infrastructure. The platform supports more than 350 cryptocurrencies, over 30 stablecoins, flexible settlement options, and enterprise-grade APIs.
The post NOWPayments Releases Cross-Chain Payout Data Revealing Key Performance Benchmarks Across TRON, BNB Chain, and Solana appeared first on CryptoPotato.
Crypto World
Aurora Intents routed $19M into Zcash NFT auction
Aurora Intents has processed more than $19 million across 1,718 swaps for the zkSNARKS auction, accounting for over half of the assets converted and deposited into the ZEC-denominated sale.
Summary
- More than $19 million of the auction’s $36.94 million submitted volume passed through Aurora Intents.
- USDC accounted for 27% of Aurora’s routed volume, while native ETH contributed 21%.
- NEAR Intents solvers converted assets from several chains into ZEC at rates approved before signing.
- Zcash shielded the destination-side bids, but source-chain transfers remained publicly visible.
Aurora Intents handled half of the auction volume
Aurora Labs CEO Declan Hannon told crypto.news that Aurora Intents processed just over $19 million of the $36.94 million deposited for the zkSNARKS auction, with the conversions completed through 1,718 swaps.
“It’s the value, the dollar value of assets converted into ZEC. Aurora Intents processed over 50% of the total volume swapped and deposited for the auction. Just over $19M out of $36.94M moved through us across 1718 swaps,” Hannon said.
The figure measures the value routed through Aurora’s cross-chain infrastructure, rather than the number of bids or completed NFT purchases. Some of the assets were attached to unsuccessful bids and later became eligible for refunds under the auction rules.
Auction results showed that participants submitted 16,971 bids for 8,000 available zkSNARKS assets. Total submitted volume reached 25,305 ZEC, worth approximately $36.94 million at the time, while the sale cleared at 1.5 ZEC per asset.
Under the sealed, uniform-price format, bidders placed offers without seeing the full order book. The 8,000 successful bidders paid the same clearing price, regardless of the maximum amount entered in their original bids.
Multiplying the clearing price by the 8,000 allocations gives 12,000 ZEC in completed sales. Approximately 13,309 ZEC, valued at about $19.43 million at the auction’s reported exchange rate, was allocated for refunds to unsuccessful bidders or for amounts submitted above the final price.
Stablecoins led cross-chain ZEC conversions
Stablecoins supplied much of the value that Aurora Intents converted into ZEC, according to Hannon. USDC alone accounted for 27% of the funds routed through the system and arrived from four networks, with Solana contributing the largest portion.
Native ETH ranked as the next-largest individual source asset, representing 21% of Aurora’s auction volume. Participants could also enter with BTC, SOL, BNB, and other supported assets rather than acquiring ZEC through a separate exchange transaction.
“Most people bidding on a ZEC-denominated auction don’t already hold ZEC and did not want to go buy some just to bid. Aurora Intents powered the cross-chain swaps,” Hannon said.
The source-asset mix placed stablecoins at the center of the conversion flow while also showing demand from users holding assets on other networks. Instead of bridging an asset manually, finding a ZEC market and making another transfer, each bidder could request a specified ZEC output through one transaction instruction.
Cross-chain access has also become part of NFT marketplace competition. In September, OpenSea added Solana NFTs to its OS2 platform, allowing users to trade supported collections within a marketplace that already covers more than 25 networks.
Stablecoin issuers have taken a similar multichain route. In June, Ripple expanded RLUSD access to more than 40 networks through Wormhole, including Base, Optimism, Ink, Unichain and the XRP Ledger EVM sidechain.
NEAR Intents solvers locked the quoted ZEC output
For the zkSNARKS auction, a bidder signed an intent stating how much ZEC the transaction should produce and the maximum source-asset amount the bidder was willing to spend. NEAR Intents solvers then competed to fill the request at the quoted rate, Hannon said.
“The user signs one intent—bid this much in ZEC up to the amount specified. Now the solver network, NEAR Intents, comes into play. Solvers compete to fill it at that quoted rate.”
According to Hannon, the rate was fixed before the user signed the transaction, while the quote included a minimum ZEC output. A market move beyond the approved range caused the transaction to fail instead of filling at a worse price.
“If the market moves past it, the trade simply doesn’t execute. If anything fails, funds return automatically to a refund address supplied up front,” he added.
Although the setup removed post-signature slippage, it did not remove every dependency from the transaction path. Hannon said users relied on the NEAR Intents settlement contract, market makers issuing quotes and bridges holding the underlying source assets.
Settlement took place through the NEAR Intents 1Click Swap API, which Hannon said has processed more than $30 billion. He added that 1Click did not take custody of user funds during the process, while Aurora neither acted as a counterparty nor handled the assets directly.
Non-custodial execution does not eliminate smart-contract, bridge, or liquidity-provider exposure. In Hannon’s description, each component still performed a specific role before the converted ZEC reached the auction.
For U.S. users, cross-chain execution does not settle whether an NFT sale or marketplace activity falls under federal securities rules. The U.S. Securities and Exchange Commission closed its OpenSea investigation in February 2025 without filing charges, but the decision did not create a blanket exemption for NFT issuers or trading platforms. The legal treatment of an asset can still depend on its sale terms, promised benefits, and promotion.
Zcash privacy started after source-chain activity
While the auction used Zcash for private settlement, Hannon drew a line between the shielded ZEC transaction and the activity that occurred before assets reached the network.
“Zcash’s shielded pool does what it says on the destination side; the bid itself isn’t visible,” Hannon said.
“What I won’t do is tell you the whole path is invisible, because the leg before it lands on a public chain, same as it would if you sent that asset anywhere else.”
A user entering with ETH, SOL, BNB, or a stablecoin first initiated a transaction on the asset’s source network. Public blockchains record wallet addresses, transferred amounts, and transaction times, leaving the initial leg visible even when the resulting ZEC bid enters a shielded pool.
On the Zcash side, shielded transfers use zero-knowledge proofs to verify that a transaction is valid without publishing the sender, recipient or transferred amount. The protection applies to the shielded ZEC transaction, not automatically to every preceding action on another blockchain.
The auction offered 8,000 assets from a 10,000-item zkSNARKS collection. Project information assigned another 1,000 assets to early Snarklist participants and reserved 1,000 for grants, contributors, artists, and the team.
Following the sale, on-chain investigator ZachXBT alleged that the project lacked practical utility and compared its structure with previous NFT “money grabs,” according to ChainCatcher. The report said he questioned the roughly $17 million retained after refunds, as well as the collection’s team allocation and royalty structure.
-
Fashion3 days agoWeekend Open Thread: Talbots – Corporette.com
-
Tech22 hours agoResearchers escape OpenAI Codex sandbox to run commands on host
-
Crypto World7 days agoRevolut Attackers Warn of Ongoing Daily Customer Data Leaks
-
Crypto World3 days agoCircle launches Arc Studio AI agent for building onchain apps
-
Crypto World6 days agoRobinhood engineers charged over $50K crypto scheme
-
NewsBeat3 days agoTrump says US has reached an agreement to take permanent control of Greenland’s security
-
Crypto World7 days agoKraken Lets xStocks Holders Earn Yield Through DeFi
-
Crypto World3 days agoBitcoin price breaks channel as RSI climbs to 63
-
Crypto World5 days agoUS Charges Robinhood Engineers Over Crypto Listing Trades
-
Crypto World6 days agoWhat Is the Status of the U.S.-Iran Peace Talks? Here's What Both Sides Are Saying
-
Crypto World7 days agoNVIDIA Analysis: Attempted Rising Wedge Breakout Amid Pressure on the AI Sector
-
Tech6 days agoWebb’s IC 348 Mosaic Includes Two-Jupiter Dwarfs, Twin Jets, and a Nursery Still Making Worlds
-
Crypto World3 days agoWorld Money launches in 150+ countries with Stripe
-
Crypto World21 hours agoWho Needs CLARITY Anyway? ARB Could See 70X Increase: Hodler’s Digest
-
Crypto World7 days agoKraken Adds DeFi Yield on Tokenized Stocks and ETF Assets
-
Crypto World3 days agoSilver prices recover quickly, hitting weekly high today
-
Crypto World3 days agoTrading Bitcoin on Robinhood? Why 2% Spread Has Traders Worried
-
Crypto World7 days ago
Can Circle’s Arc Repeat Robinhood Chain’s Meme Coin Boom?
-
Entertainment6 days agoBig Brother Update: Melody Explodes at Drew as Illness Sweeps BB28 House
-
NewsBeat3 days agoUS was ‘on brink of war’ with China over false AI report of nukes moving in Middle East

You must be logged in to post a comment Login