Connect with us

Crypto World

Fed Outlines New Capital and Redemption Rules for Stablecoin Issuers

Published

on

Crypto Breaking News

The Federal Reserve has released proposed rules aimed at tightening oversight of stablecoin issuers as the U.S. works to implement the GENIUS Act. The proposals set out how Fed-supervised entities would be required to hold reserves, manage risk, handle redemptions, and report key information about their stablecoins.

While the GENIUS Act already mandates that stablecoins be backed on a one-to-one basis with specified reserve assets, the Fed’s plan would add more granular requirements—especially around capital levels tied to operational risk, credit-related risks, and standardized reporting and assurance.

Key takeaways

  • The Fed’s proposal would require operational-risk capital charges for stablecoin issuers, scaling based on the amount of stablecoins outstanding.
  • Issuers would generally need to process redemptions within two business days and notify the Fed if reserves fall below required one-to-one backing.
  • Monthly reserve and outstanding stablecoin reporting would be required, with disclosures examined by a registered public accounting firm and certified by the issuer’s CEO and CFO.
  • A separate Fed proposal would create a pathway for Fed-supervised banks to seek approval to issue payment stablecoins through subsidiaries.
  • Fed Governor Michael Barr supports the direction of the framework but says stablecoin reliability during market stress still needs further work.

What the GENIUS Act already requires—and what the Fed is adding

Under the GENIUS Act, stablecoin issuers must maintain reserves backing their tokens on a one-to-one basis and can only hold certain types of assets. These include cash, bank deposits, and short-term U.S. Treasurys, among other permitted instruments. The law also assigns federal regulators the task of writing the more detailed capital, reserve-diversification, and risk-management rules.

According to the Fed’s published documents, the agency’s proposals are intended to translate those statutory requirements into day-to-day supervisory expectations for issuers under Fed oversight.

Operational-risk capital, redemptions, and reserve shortfalls

One central piece of the Fed’s proposal is a capital framework tied to operational risk. As outlined in the Fed’s plan, issuers would face an operational-risk capital charge calculated as follows: 2% of the first $20 billion in stablecoins outstanding, 1.5% of the next $30 billion, and 1% of amounts above $50 billion. In addition to that operational-risk charge, the proposal contemplates further capital requirements linked to credit and operational risks.

Advertisement

On liquidity and redemption mechanics, the proposal would generally require issuers to process redemptions within two business days. If an issuer’s reserves drop below the one-to-one backing threshold, the issuer would have to notify the Fed. The issuer would then need to either restore reserves under a remediation plan or liquidate the reserves and redeem outstanding stablecoins.

For investors and traders, these elements matter because they directly affect the feasibility of exiting a stablecoin position when market conditions deteriorate or when an issuer faces stress on its reserve composition and operational controls.

Monthly disclosures and external verification

The Fed’s proposal also emphasizes transparency and accountability. Issuers would be expected to publish monthly reports covering their outstanding stablecoin balances as well as the value and composition of reserves backing those tokens.

Those disclosures would not be limited to internal attestations. The proposals call for the disclosures to be examined by a registered public accounting firm, and for certification by the issuer’s CEO and CFO.

Advertisement

This structure—audited examination plus senior executive sign-off—could create stronger compliance incentives for issuers, while giving market participants more consistent and comparable information to evaluate reserve backing over time.

Bank participation through subsidiaries: a separate application framework

In addition to rules for stablecoin issuers, the Fed also released a separate proposal intended to establish an application process for Fed-supervised banks that want approval to issue payment stablecoins through subsidiaries.

As described in the Fed’s second proposal, banks would be required to submit a business plan and financial information as part of the approval process. The separate track suggests the Fed is attempting to clarify how regulated banks can participate in the stablecoin ecosystem while remaining within a defined supervisory structure.

Barr’s support, and the remaining reliability questions

Fed Governor Michael Barr backed the proposals on Thursday but argued that more work is needed before stablecoins can be considered reliable payment instruments. Barr said that “stablecoins will only be stable if they can be reliably and promptly redeemed at par in a range of conditions,” including during market stress, situations where even liquid government debt may come under pressure, and episodes of strain affecting a specific issuer or related entities.

Advertisement

In remarks tied to the Fed’s announcement, Barr indicated he was encouraged by proposed limits on reserve assets and by standardized capital requirements. At the same time, he urged public feedback on whether the framework adequately addresses interest-rate and foreign-currency risks.

Barr also raised questions about how universal redemption rights should be established in the final rule. He highlighted concern about an approach that could limit the Fed’s ability to take supervisory or enforcement action over an anti-money laundering deficiency unless the problem is deemed “significant or systemic.”

For market participants, Barr’s comments underscore a key tension: the rules aim to formalize backing and capital adequacy, but the final design will be judged on whether it holds up under real-world stress scenarios, not only in normal periods.

Public comment period and GENIUS Act implementation timing

The Fed’s proposals are open for public comment for 60 days after publication in the Federal Register, according to the Fed’s announcements. That comment window may determine how the capital formulas, redemption expectations, reporting requirements, and risk treatment ultimately look in final form.

Advertisement

The GENIUS Act is scheduled to take effect on Jan. 18, 2027, or 120 days after federal regulators issue final implementing rules, whichever comes first. As the rulemaking process advances, readers should watch how regulators refine stress-testing expectations, define the final contours of redemption rights, and decide how operational and financial risk controls translate into practical reliability for users.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure



Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

KelpDAO sues LayerZero over $292M rsETH exploit

Published

on

KuCoin faces scrutiny after investor cites unpaid $2 million Seychelles court judgment

KelpDAO has sued LayerZero and co-founder Bryan Pellegrino in British Columbia over the April 18 exploit that drained 116,500 rsETH worth approximately $292 million.

Summary

  • KelpDAO filed a British Columbia lawsuit against LayerZero and CEO Bryan Pellegrino over April’s exploit.
  • The April attack drained 116,500 rsETH worth approximately $292 million from KelpDAO’s LayerZero bridge infrastructure.
  • KelpDAO alleges LayerZero failed to disclose technology risks and secure infrastructure later compromised by attackers.
  • LayerZero says KelpDAO’s one-of-one verifier configuration created the single failure point enabling forged cross-chain messages.
  • Pellegrino called the lawsuit meritless and said he will defend himself and LayerZero in Vancouver.

KelpDAO said on September 24 that Evercrest Technologies Inc., the legal entity behind Kelp, filed the action to address what it describes as failures connected to LayerZero’s infrastructure. Kelp’s current terms identify Evercrest Technologies Inc. as the company providing the Kelp application.

The complaint, according to KelpDAO’s public account, alleges that LayerZero failed to disclose weaknesses and risks in its technology and failed to stop attackers from penetrating security infrastructure used by its verifier. No court has ruled on those allegations.

Pellegrino disputes the case. He called the claims “meritless” and said he would defend himself and LayerZero in Vancouver. Current reporting confirms the civil claim names both LayerZero and Pellegrino personally.

KelpDAO says LayerZero approved its bridge setup

KelpDAO’s case centers partly on the configuration of the rsETH bridge. The protocol says LayerZero had reviewed and approved its deployment and configuration in writing before the April exploit, contradicting LayerZero’s later argument that Kelp created a dangerous single-verifier setup.

Advertisement

LayerZero has given a different account. In its April incident statement, the company said Kelp used a 1-of-1 Decentralized Verifier Network, or DVN, leaving no separate verifier capable of rejecting a false cross-chain message. LayerZero said it had previously recommended verifier diversification and described the configuration as a single point of failure.

Kelp pushed back days after the attack. As crypto.news reported in its coverage of the dispute over LayerZero’s default configuration, Kelp said its bridge followed LayerZero’s documented defaults and relied on LayerZero-operated infrastructure. LayerZero maintained that Kelp had manually moved to the 1-of-1 configuration.

Pellegrino later said Kelp originally used multi-DVN or DeadDVN defaults before changing the rsETH deployment. Kelp has disputed LayerZero’s description of the discussions and now says its lawsuit will rely on written records showing LayerZero reviewed the setup.

LayerZero’s own infrastructure was compromised

The parties disagree over responsibility, but LayerZero’s final incident report confirms that attackers penetrated infrastructure operated by LayerZero Labs before the rsETH bridge released the funds.

Advertisement

LayerZero published its detailed report in May, saying the intrusion began on March 6 when an attacker socially engineered a LayerZero developer and obtained session credentials. The attacker then entered LayerZero’s RPC cloud environment and altered internal RPC nodes used by the LayerZero Labs DVN.

During the April 18 attack, the compromised nodes supplied false blockchain information while attackers launched a denial-of-service attack against external RPC providers. LayerZero’s DVN then signed a forged message because its available information indicated that the message was valid.

Kelp’s Ethereum bridge subsequently released 116,500 rsETH even though no corresponding burn had occurred on the source chain. Chainalysis described the event as an attack on off-chain verification infrastructure, not a smart contract vulnerability in Kelp’s rsETH token contract.

A second attempt sought another 40,000 rsETH, then worth roughly $95 million to $100 million, but Kelp had paused its contracts before the forged packet could execute. The pause occurred roughly 46 minutes after the successful drain.

Advertisement

As crypto.news reported in its LayerZero incident report coverage, LayerZero responded by ending support for 1-of-1 DVN configurations and moving affected applications toward multi-verifier setups. The company said its updated security model requires more independent verification paths.

Lawsuit follows months of competing blame

KelpDAO’s newly filed action turns a public technical dispute into a civil court case. Kelp says LayerZero and Pellegrino spent months placing responsibility on Kelp after infrastructure controlled by LayerZero was compromised.

LayerZero has maintained that the attacker could not have stolen the rsETH if Kelp had required multiple independent DVNs. Its May report said a hardened configuration requiring separate verifiers to agree would have stopped one compromised verifier from authorizing the forged message.

Security researchers have documented both parts of the failure. Blockaid found that LayerZero’s sole DVN authenticated the false cross-chain message and that the absence of a second verifier allowed it to reach Kelp’s Ethereum adapter.

Advertisement

Chainalysis reached a similar technical finding while focusing on the compromised infrastructure. Its investigation found attackers manipulated LayerZero-operated RPC nodes feeding the DVN and forced the verifier to rely on those nodes by disrupting external providers.

LayerZero and several researchers have attributed the attack to North Korea-linked TraderTraitor, associated with the Lazarus Group. LayerZero’s final report said Mandiant, CrowdStrike and independent researchers reached that attribution.

As crypto.news reported in its coverage of the Lazarus attribution, the finding came from LayerZero’s investigation and associated security work. The lawsuit concerns responsibility between Kelp and LayerZero for the conditions that allowed the exploit; the attribution does not resolve that civil dispute.

Kelp has moved rsETH away from LayerZero

Kelp began changing its bridge infrastructure while recovery work continued. In May, it announced a migration of rsETH cross-chain transfers from LayerZero’s OFT framework to Chainlink CCIP.

Advertisement

Crypto.news reported that Kelp moved rsETH toward Chainlink CCIP as the disagreement with LayerZero continued. Pellegrino disputed Kelp’s account of the original bridge configuration during that migration process.

By May 25, Kelp said it had transferred the final 20,373.72 rsETH tranche needed for its operational recovery plan. Minting, redemptions and rewards had resumed, while bridging services reopened after earlier asset transfers restored backing to the affected structure.

The recovery involved other DeFi platforms because the attacker had used stolen rsETH as collateral. Aave, Kelp and other participants organized a recovery process after the theft created losses in lending markets. As crypto.news previously reported, Kelp committed 2,000 ETH to the rsETH recovery effort as part of that process.

The civil case now moves into British Columbia’s court process. Under the province’s Supreme Court Civil Rules, a defendant generally has 21 days to respond after service in Canada, 35 days after service in the U.S., or 49 days when served elsewhere, unless the court orders another deadline. Pellegrino has publicly said he intends to contest the action in Vancouver.

Advertisement



Source link

Continue Reading

Crypto World

Jack Dorsey’s Block joins x402 with Lightning support

Published

on

Jack Dorsey’s Block joins x402 with Lightning support

Block has joined the x402 Foundation and contributed Bitcoin Lightning support to the open payment protocol used by AI agents, web services and applications.

Summary

  • Block has contributed Bitcoin Lightning support to x402 after joining the Linux Foundation-governed payment group.
  • x402 uses HTTP 402 responses so AI agents can pay automatically for APIs and services.
  • A September 23 repository commit added exact Lightning support using the lnbtc network identifier specification.
  • The x402 Foundation reported 75.41 million transactions and $24.24 million volume during thirty recent days.
  • Block plans continued Lightning contributions while bringing its payments experience into x402 Foundation working groups.

Block’s September 24 announcement states that the company has brought Lightning payments into x402 as part of its work on agentic commerce. The payment company said Lightning fits transactions that require low costs, fast settlement and repeated small payments.

The technical addition was already visible in x402’s public development repository. A September 23 commit records “exact Lightning on lnbtc,” providing an independent public record of the Lightning specification entering the project immediately before Block disclosed its participation.

Block brings Bitcoin Lightning into x402 payments

Created by Coinbase, x402 uses the HTTP 402 “Payment Required” response to let software request and settle payments during an ordinary web interaction. A server can return payment instructions when an AI agent requests a paid API, dataset or other digital service. The agent pays and retries the request with proof of payment.

Advertisement

Block’s contribution introduces Bitcoin Lightning as another payment option inside that framework. The company said Lightning was designed for “instant, low-cost, high-volume payments,” though Block did not publish transaction volumes, merchant deployments or AI-agent usage figures specifically tied to its Lightning implementation.

Steve Lee, head of Block’s Bitcoin development initiative Spiral, made a forward-looking case for the technology. He said agents “will make billions of small payments,” adding that such activity would need payment rails designed for frequent, inexpensive transactions. The statement represents Block’s expectation for agentic commerce, not measured current Lightning demand.

The x402 protocol itself already carries substantial activity from existing payment methods. Its official site currently reports 75.41 million transactions, $24.24 million in volume, 94,060 buyers and 22,000 sellers during the previous 30 days. The figures cover x402 as a whole and should not be interpreted as Bitcoin Lightning statistics.

x402 moves beyond its stablecoin-heavy payment base

Stablecoins have supplied much of x402’s payment activity to date. As crypto.news reported in its coverage of stablecoin use across agent-payment activity, Circle said USDC accounted for 99.3% of x402 payment volume measured during its second quarter. Circle’s figure applied specifically to x402 activity in its data, not every AI-agent payment system.

Advertisement

Lightning gives developers an option that settles in Bitcoin instead of a dollar-linked token. Block described its contribution as an effort to expand the available non-card payment methods supported by an open standard. Erik Reppel, x402’s creator and a member of its Technical Steering Committee, said the protocol was designed so different networks could be added without tying the standard to one payment rail.

Recent integrations show how developers have been adding network choices to x402. Crypto.news reported this week that AI-agent payment support through x402 reached Cardano’s software stack, with an initial TypeScript release and a facilitator tested on the network’s pre-production environment. Mainnet use had not yet been demonstrated in that implementation.

Other deployments are further into production. In related coverage, crypto.news reported that autonomous payment infrastructure on Casper mainnet uses an x402 facilitator to let AI agents purchase online services through HTTP-based payments.

The XRP Ledger has generated another source of activity. As crypto.news reported, agentic payment activity on XRP Ledger passed one million x402 transactions by July, while Ripple-backed t54.ai introduced tools and directories for AI projects using the network.

Advertisement

Block joins a Linux Foundation-governed payment standard

Coinbase originally developed x402 before contributing it to the Linux Foundation. The Linux Foundation announced the x402 Foundation in April as a neutral body intended to oversee development of the payment standard outside the control of one vendor.

The Foundation became operational in July with 40 organizations. Its official announcement listed Amazon Web Services, Google, Coinbase, Mastercard, Visa, Stripe, Circle, Ripple, Shopify and Solana Foundation among its premier members, with other blockchain and infrastructure companies participating at different membership levels.

Microsoft requires a more precise description. The Linux Foundation’s April launch notice listed Microsoft among organizations expressing “initial intent and support” for the Foundation, but Microsoft was not included in the named 40-member operational roster published in July. The current x402 membership page does not expose member names as searchable text, so the available official material does not support describing Microsoft as a confirmed current member without qualification.

Under the Foundation model, x402 remains network and currency agnostic. The protocol puts payment instructions inside normal HTTP requests, allowing different settlement systems to plug into a common interaction between a client and server. Its official documentation says merchants can accept several networks or schemes through the same payment middleware.

Advertisement

Block ties x402 to its existing agentic commerce work

The x402 membership extends work Block has already pursued around autonomous software. Block said it has contributed goose, its open-source AI agent, helped establish the Agentic AI Foundation and participated in the Universal Commerce Protocol initiative.

Google describes Universal Commerce Protocol, or UCP, as an open-source standard connecting consumer-facing AI systems with merchant infrastructure. Its framework covers processes such as product discovery and checkout while allowing businesses to expose payment choices to software agents.

x402 serves a different layer. Its focus is the payment request and settlement interaction over HTTP, including cases where an autonomous application purchases a single API call or other digital resource without using a conventional checkout flow. Block said open payment rails could let sellers interact with buyers’ agents without creating a separate integration for every agent platform.

AWS has already connected x402 to commercial AI infrastructure. As crypto.news previously reported, Amazon Bedrock AgentCore’s autonomous payment integration added Coinbase x402 infrastructure for USDC transactions, allowing compatible agents to pay for services while operating inside enterprise spending and compliance controls.

Advertisement

The Graph has implemented the standard at the service level as well. Crypto.news reported that pay-per-request access to blockchain data lets developers and AI agents purchase individual Graph Gateway queries using x402 instead of maintaining a conventional subscription or prepaid API account.

Block has not announced a timetable for integrating Lightning-based x402 payments directly into Square, Cash App, Bitkey or its other consumer products. Its September 24 roadmap says the company will keep contributing to Lightning support, participate in x402 Foundation working groups and continue developing agentic-commerce tools that use the standard.



Source link

Advertisement
Continue Reading

Crypto World

Bitcoin privacy proposal avoids soft fork with ZK proofs

Published

on

BTC breaks $80k for the first time since January as Fox DeFi explains the capital driving the rally

Researchers at Alloc Init have proposed, in a September 24 paper, private Bitcoin transfers using zero-knowledge proofs without requiring a soft fork.

Summary

  • Shielded Bitcoin would hide senders, receivers and amounts without changing Bitcoin’s consensus rules or code.
  • Indexers would verify zero-knowledge proofs and nullifiers while Bitcoin only publishes and orders transaction data.
  • Researchers say the published design still leaves Bitcoin deposits and withdrawals for a forthcoming paper.
  • Misha Komarov estimates shielded transfers could cost roughly four times ordinary Bitcoin transaction fees initially.
  • Critics question early anonymity and quantum resistance, while researchers acknowledge privacy depends heavily on usage.

Alloc Init’s researchers Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin published Shielded Bitcoin as a metaprotocol that uses Bitcoin to publish and order encrypted transaction data. Bitcoin nodes would not need to understand or enforce the privacy system’s rules.

Called Shielded Bitcoin, the proposed system borrows core ideas from Zcash, including encrypted notes, nullifiers and zero-knowledge proofs. It would conceal shielded senders, receivers, transferred amounts and links to earlier notes while leaving Bitcoin’s existing consensus rules unchanged.

Advertisement

The proposal remains research, not deployed Bitcoin software. Alloc Init has not announced a mainnet launch date, while a separate mechanism for moving BTC into and out of the shielded system remains under development. Founder Misha Komarov described the underlying technique as experimental during an interview published September 24.

Shielded Bitcoin moves privacy checks outside consensus

Under the proposed architecture, Bitcoin would function as what the researchers describe as a neutral publication and ordering layer. A shielded transaction would place encrypted notes, nullifiers and a zero-knowledge proof into data carried by an ordinary Bitcoin transaction.

Separate programs called indexers would read the data in Bitcoin’s established transaction order. An indexer would verify the zero-knowledge proof, check whether each nullifier had appeared before and update its view of the shielded system when the transaction passes those checks. Invalid shielded data could still enter the Bitcoin blockchain because Bitcoin itself would not enforce the metaprotocol. The indexer would simply reject it from Shielded Bitcoin’s state.

Advertisement

A sender would consume encrypted notes representing previously received value and create new notes for recipients. The proof would establish that the sender controls valid notes, has not created value from nothing and has balanced transaction inputs and outputs without exposing the underlying amounts or notes.

As crypto.news explained in its recent guide to zero-knowledge proofs, ZK systems can prove that a computation followed specified rules without revealing the private information used in that computation. Shielded Bitcoin applies that model to Bitcoin transfers, while its indexers handle verification outside Bitcoin consensus.

A dishonest indexer could provide stale information, omit transfers or delay wallet updates, the researchers said. Such an indexer would not gain control of a user’s spending key. Users could switch indexers or independently replay the shielded transaction history from Bitcoin.

How the Zcash-style design hides transaction links

Shielded Bitcoin closely follows the note model used by Zcash. Nullifiers identify when a note has been spent without publicly revealing which encrypted note produced the nullifier, allowing an indexer to reject double spending while keeping the transaction link hidden.

Advertisement

Komarov characterized the concept more simply in his September interview: “It’s basically Zcash.” He said users would place bitcoin into a private pool, receive encrypted notes and later spend, split or use those notes when withdrawing. Alloc Init intends to connect that system to Bitcoin through its PIPEs research.

Privacy would not make every part of the activity invisible. Public observers could still see when a Shielded Bitcoin transaction occurred, its timing, transaction fee, data size, number of notes consumed and created, and the Bitcoin transaction carrying the encrypted information. A recognizable Bitcoin wallet used to publish those transactions could reveal further information about the publisher.

The researchers provide separate read-only keys for viewing incoming or outgoing activity. Users could disclose selected transaction information to an accountant or counterparty without surrendering spending authority, though Alloc Init cautions that sharing a complete viewing key would reveal everything covered by that key.

In related coverage, crypto.news reported this week on expanding demand for privacy-focused crypto systems. The report cited ZecStats data showing 4.91 million ZEC in Zcash shielded pools, representing 29% of issued supply at the time.

Advertisement

Anonymity and quantum resistance remain contested

The proposal has drawn questions over how much privacy a new shielded pool could provide at launch. Developer Vadim Zavodil argued that Zcash already has years of shielded activity behind its anonymity set, while a new Bitcoin metaprotocol would begin with few participants.

“Privacy is a function of the crowd,” Zavodil wrote, arguing that an early Shielded Bitcoin user could have very few comparable transactions to blend into. His criticism focuses on practical anonymity from user behavior and pool size, not whether the cryptographic proof itself conceals its private inputs.

Alloc Init’s own explanation acknowledges the same general limitation. A large quantity of bitcoin entering a shielded system does not by itself create a strong anonymity set if only a few actors generate most notes or if individual wallets follow recognizable deposit, withdrawal or timing patterns.

Research on Zcash has documented similar behavioral problems. A peer-reviewed 2018 study found that transaction patterns could shrink the effective anonymity set even when the underlying shielded cryptography remained intact. The study examined an older Zcash implementation and predates several later upgrades.

Post-quantum researcher Pierre-Luc Dallaire-Demers raised a separate cryptographic concern. He described the construction as interesting but “not quantum resistant at all.” In a follow-up, he said he was examining what a fully post-quantum version could require if Bitcoin eventually adopts post-quantum signatures.

Komarov has given a more conditional account. His interview with Unchained said the shielded pool’s eventual route to quantum resistance would depend partly on Bitcoin’s own signature system. Alloc Init has not presented Shielded Bitcoin as a finished post-quantum implementation.

Advertisement

Zerocash co-author and StarkWare CEO Eli Ben-Sasson responded more favorably to the project’s direction, while noting that he had not yet reviewed the full paper. His support therefore represented an initial reaction, not a technical endorsement of the construction.

Shielded Bitcoin still needs its Bitcoin entry and exit system

A major unfinished component is the movement of actual BTC into and out of the shielded metaprotocol. Alloc Init’s September 24 explanation says the current paper specifies shielded transfers after value is inside the system, while a forthcoming paper will describe peg-ins and peg-outs using PIPEs.

PIPEs relies on witness encryption to make access to a Bitcoin signing key conditional on proof that specified rules were followed. Komarov explained to the Bitcoin Development Mailing List in February that PIPEs v2 could emulate certain covenant and zero-knowledge verification functions without requiring a Bitcoin soft fork.

Advertisement

The cryptographic machinery remains computationally heavy. Komarov’s February disclosure put a PIPEs v2 ciphertext at roughly 330 TB of storage, while stating that researchers knew a route that could eventually reduce the figure toward 100 GB. The smaller target had not been achieved in that publication.

Shielded transfers would consume more Bitcoin block space as well. Komarov told Unchained that an encrypted shielded payload would run around 700 virtual bytes, compared with roughly 100 to 200 virtual bytes for a typical Bitcoin transaction. He estimated the resulting miner fee could be approximately four times higher.

No launch date has been set. Komarov said the team is gathering technical feedback while continuing work on the experimental construction, including open attempts to find faults in the design and work with witness-encryption researcher Sanjam Garg.

The next publicly scheduled presentation is set for September 28, 2026. The Bitcoin Treasuries Conference agenda lists Alloc Init researcher Clara Shikhelman for a five-minute session titled “Shielded Bitcoin: Private Transfers on Bitcoin L1” in New York.

Advertisement




Source link

Continue Reading

Crypto World

Researchers Explore Zcash-Style Private Bitcoin Transfers Without Soft Fork

Published

on

Crypto Breaking News

Alloc Init researchers have outlined a new approach they say could bring Zcash-style shielded transfers to Bitcoin without requiring a soft fork of the base protocol. The proposal, titled Shielded Bitcoin, aims to hide transaction amounts, senders, receivers, and linkages to previously spent funds by relying on encrypted “notes” and zero-knowledge proofs.

Published on Thursday by Clara Shikhelman, Mikhail Komarov, and Aleksei Moskvin, the design is intended to use Bitcoin as a kind of settlement and ordering layer—while separate software handles verification and state reconstruction for the privacy system. The result is a privacy overlay that, in theory, avoids asking miners or the wider network to enforce new rules.

Key takeaways

  • Shielded Bitcoin proposes private transfers on top of Bitcoin without a soft fork by treating Bitcoin as an “ordering layer” rather than enforcing privacy rules at consensus.
  • The system mirrors core Zcash components—encrypted notes, nullifiers to prevent double-spending, and zero-knowledge proofs for transaction validity.
  • Privacy quality would depend on how quickly a meaningful anonymity set forms; critics argue early deposits may provide limited crowd-mixing.
  • Commentators also raised open questions about cryptographic robustness and the practicality of the scheme.

How the proposal avoids a soft fork

In traditional privacy upgrades, hiding transaction details often requires changes that the network enforces. Shielded Bitcoin instead reframes the problem: rather than embedding privacy checks into Bitcoin’s mining and validation rules, the researchers propose using Bitcoin as “a neutral publication and ordering layer.”

Under this model, indexers—separate software components—would verify zero-knowledge proofs, confirm that the underlying funds have not been double-spent, and then reconstruct the evolving state of the shielded system. The encrypted notes and proofs would be published using Bitcoin transactions, but the privacy logic would be validated externally.

The paper’s key architectural point is that shielded validity does not have to be enforced by consensus for users to benefit from a private transfer—at least within the constraints of what other parties (wallets, relayers, and indexers) choose to accept and verify.

Advertisement

Why the Zcash-style design matters

The proposal explicitly draws from Zcash’s architecture. According to the paper, Shielded Bitcoin would use:

  • Encrypted notes to conceal who owns funds and how much value is being moved.
  • Public nullifiers that mark notes as spent, preventing double-spending without revealing note contents.
  • Zero-knowledge proofs that demonstrate transaction validity while keeping sensitive details hidden.

However, Shielded Bitcoin differs from Zcash in one fundamental way: it is not presented as a separate shielded blockchain with its own consensus mechanism. Instead, it aims to plug a Zcash-like privacy system into Bitcoin’s existing infrastructure, using encrypted transaction artifacts and proof verification performed by external components.

For Bitcoin users and developers, the practical implication is clear: a privacy layer that can be deployed without consensus changes could lower the friction associated with privacy tooling. It also shifts the engineering burden toward wallets and verification infrastructure rather than requiring network-wide upgrades.

Early privacy may be weaker than Zcash’s anonymity set

Developer Vadim Zavodil was among the most pointed critics. Posting on X, Zavodil argued that a large share of the privacy “stack” already exists in Zcash and questioned how much privacy a newly launched shielded system could deliver immediately.

“Privacy is a function of the crowd. Zcash has a real shielded pool built over years of use. A brand new metaprotocol starts at zero, so your first private transfer hides in a crowd of one.”

In response, the Shielded Bitcoin researchers acknowledged the same concern. In a companion explanation published alongside the proposal on Notion, they said that large deposits do not automatically translate into a large anonymity set. They also warned that observers might still be able to infer relationships between transfers if a small number of actors create most notes or if wallets produce distinctive behavior.

Advertisement

This tension highlights a common theme for privacy systems: cryptographic soundness does not automatically guarantee anonymity. Shielded designs often depend on how users actually use them—how many participants join, how uniformly transactions behave, and whether patterns can be linked over time.

Questions extend beyond privacy: post-quantum concerns and intent

Another line of critique came from Pierre-Luc Dallaire-Demers, founder of post-quantum cryptography firm Pauli Group. He said the construction was “not quantum resistant at all,” framing the proposal as interesting while still leaving cryptographic assumptions in question.

Dallaire-Demers later indicated he was exploring what a fully post-quantum version could look like, contingent on Bitcoin eventually adopting a post-quantum signature scheme.

Supporters, meanwhile, emphasized the broader goal of bringing privacy to Bitcoin. Eli Ben-Sasson, a Zerocash co-author and CEO of StarkWare, responded more positively to the announcement. Although he said he had not yet read the full paper, Ben-Sasson argued that the intent behind Zerocash—preceding Zcash—was to bring privacy to Bitcoin. He said he would like to see the vision of privacy and scalability through zero-knowledge proofs materialize on Bitcoin’s base layer.

Advertisement

Taken together, these reactions underscore that Shielded Bitcoin is not being debated only on whether it “works” on paper. It’s also being evaluated on longer-term assumptions—particularly around anonymity set formation and the resilience of the cryptography to future threats.

As the proposal circulates among developers, investors and builders will likely watch for two practical follow-ups: whether any wallet or indexer implementation demonstrates credible usability and whether the system’s privacy properties improve as more independent users participate and diversify their behavior.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure



Source link

Advertisement
Continue Reading

Crypto World

30-Year Mortgage Rate Hits 7.45%. What Does It Mean for Crypto?

Published

on

Bitcoin (BTC) Price Performance.

The average 30-year fixed US mortgage rate jumped 19 basis points to 7.45% on Thursday. Mortgage News Daily recorded the move in its daily survey of brokers and lenders.

The jump tracks a broader selloff in US government bonds. For crypto markets, the Treasury yield at the center of that selloff carries the clearer signal.

Treasuries Drag the 30-Year Mortgage Rate Higher

The 30-year rate had sunk as low as 5.99% in late February, according to CNBC. It began rising once the Iran war started, then accelerated after the Federal Reserve (Fed) raised rates in September.

Mortgage News Daily Chief Operating Officer Matthew Graham traced the climb since September 10 to three drivers. He pointed to Fed commentary, higher oil prices, and stronger economic data.

Advertisement

However, Graham could not find a clear catalyst for Thursday afternoon’s bond selloff. 

“No obvious catalyst. Explanations require concocting narratives and then defending them. There’s no objective, irrefutable way to connect the dots today. Sellers decided to sell… a lot,” he said.

That selloff matters because mortgage rates tend to track longer-dated Treasury yields. The 10-year yield closed at 5.18% on Thursday, up from 4.96% on Tuesday, according to the Treasury.

The Kobeissi Letter blamed inflation for the bond rout. It cited Brent crude above $105 a barrel and record diesel prices. It also noted consumers expect inflation near 4.6% over the next year.

Follow us on X to get the latest news as it happens

Advertisement

Crypto Pays the Price of Higher Yields

For crypto, the key link runs through those yields. When government debt pays more, holding Bitcoin (BTC) carries a higher opportunity cost.

That pressure showed on Wednesday. Bitcoin fell below $84,000 after strong US business activity data pushed the 10-year yield past 5%.

Bitcoin (BTC) Price Performance.
Bitcoin (BTC) Price Performance. Source: BeInCrypto Markets

By Friday, BTC traded at $84,590, posting a modest gain over the past 24 hours, BeInCrypto Markets data shows. Altcoins moved faster in the rebound. Solana (SOL) gained 2.2%, and XRP (XRP) added 3.4% over the same period.

This leaves an open question. Can crypto buyers keep absorbing pressure from a Treasury market paying more than 5%?

Subscribe to our YouTube channel to watch leaders and journalists provide expert insights

Advertisement

The post 30-Year Mortgage Rate Hits 7.45%. What Does It Mean for Crypto? appeared first on BeInCrypto.



Source link

Continue Reading

Crypto World

Australia PM Warns UN Over AI After OpenAI Breach

Published

on

Australia PM warns of AI’s ‘furious pace’ after agent breached government site

Australia PM warns of AI’s ‘furious pace’ after agent breached government site

Anthony Albanese said governments must help shape AI’s development, after revealing earlier that an OpenAI agent accessed non-public files on an Australian Medicare data portal.



Source link

Continue Reading

Crypto World

Ondo Finance denies sale talks after founder’s death

Published

on

Ondo Finance denies sale talks after founder's death

Ondo Finance has denied a report based on three anonymous sources that the tokenization company was offered to prospective buyers after founder Nathan Allman died on May 25, 2026.

Summary

  • Ondo Finance denied seeking buyers after anonymous sources reported sale outreach following Nathan Allman’s death.
  • Three sources said Ondo Finance was offered to prospective buyers after Allman died in May.
  • Delaware court records show Kathleen Allman’s control case against Ondo Finance remains active since July.
  • Ian De Bode remains acting CEO while court order limits major corporate changes during litigation.
  • Ondo launched institutional share conversions this week, showing product operations continue during the governance dispute.

CoinDesk reported that outreach to prospective buyers took place sometime after Allman’s death, citing three people familiar with the matter. Two sources placed the outreach after May 25, but the report said it could not establish who initiated the effort or what valuation may have been discussed.

Ondo rejected the account. A company spokesperson called reports of a possible sale “wholly untrue” and said nobody at the company had sought buyers or authorized another party to do so. Allman’s estate declined to comment to CoinDesk.

Advertisement

Ondo Finance rejects reported buyer outreach

The disputed sale account comes as control of Ondo remains before courts following Allman’s unexpected death at age 32. He died without a will while holding a controlling stake in Ondo Finance, leaving questions over who could exercise the voting rights attached to his shares.

After probate proceedings in Hawaii, Allman’s parents, Kathleen and Lawrence Allman, became heirs to his estate. Kathleen later received authority as personal representative and asserted that the estate’s voting rights allowed her to reconstitute Ondo’s board. De Bode disputed the estate’s attempt to remove him. The competing claims eventually reached the Delaware Court of Chancery.

The Delaware judiciary’s public CourtConnect docket shows Kathleen C. Allman v. Ondo Finance Inc., Case No. 2026-0978, was filed on July 24. The docket currently lists the civil case as active before Chancellor Kathaleen McCormick and shows no scheduled case events on the public page.

Advertisement

CoinDesk reported that the present court arrangement allows De Bode to oversee ordinary business while restricting major changes until the corporate-control dispute is resolved. One anonymous source said the litigation had likely stopped any possible sale process, but that assessment has not been confirmed by Ondo or Allman’s estate.

Court fight centers on who controls Ondo

Kathleen Allman’s Delaware complaint disputes De Bode’s authority after Nathan’s death. The estate alleges De Bode began presenting himself as CEO without valid board approval and later took steps to establish control while the estate’s voting rights were still passing through probate. De Bode has rejected those allegations as meritless.

At the time of Nathan Allman’s death, court filings described him as Ondo’s controlling shareholder and sole director, with another board seat vacant. Kathleen was appointed personal representative of the estate in Hawaii on June 26 and later used shareholder consents to appoint directors and attempt to remove De Bode, according to reporting on the complaint.

The estate has challenged a compensation arrangement that it says was prepared for De Bode following Allman’s death. Court-related reporting places the disputed package at roughly $11 million, including salary, a signing payment, restricted token units and equity awards. The amounts remain allegations in the litigation and have not been established as wrongdoing by a final court ruling.

Advertisement

De Bode remains Ondo’s public-facing leader. The company’s current leadership page lists him as “Acting CEO and President,” while Allman is listed as founder.

Estate dispute has expanded into Hawaii

A separate proceeding has developed around Kathleen Allman’s control of her share of the estate. Allman’s half-sister, Dr. Lani Clinton, and Ondo investor David Chen petitioned a Hawaii court for a limited conservatorship covering that interest.

The petition contains allegations about Kathleen’s ability to manage financial affairs, which her lawyers have denied. Kathleen has argued that the filing is connected to the fight over Ondo and has rejected its allegations as baseless. No final ruling establishing the contested claims was identified in the latest records reviewed.

The estate holds more than corporate voting rights. Court-related reports describe it as containing a large allocation of ONDO tokens, including tokens already unlocked and others scheduled to unlock during the next three years. The exact size of the estate’s controlling equity position is redacted from public versions of the corporate filings.

Advertisement

No public filing reviewed establishes that Kathleen, De Bode, the Ondo board or the estate formally retained an investment bank to sell the company. CoinDesk said it could not identify who initiated the reported outreach or determine a proposed sale price. Ondo has not disclosed a valuation in its publicly announced equity rounds.

Ondo operations continue while the case remains active

Ondo’s public product activity has continued during the court fight. On September 21, the company announced a new institutional route allowing approved firms to convert underlying shares directly into Ondo Stocks through Alpaca’s Instant Tokenization Network. The conversion service is live on Ethereum and BNB Chain.

As crypto.news reported in its coverage of Ondo’s new institutional share-conversion route, institutions need active Ondo and Alpaca accounts and approval before using the service. RWA.xyz data cited in that report tracked $3.63 billion in Ondo distributed assets across 441 products as of September 22.

The company has continued expanding tokenized equities during 2026. In related coverage, crypto.news reported that Ondo brought tokenized U.S. stocks to Hyperliquid’s HyperEVM, while Ondo Global Markets had reached nearly $18 billion in cumulative trading volume at that point.

Advertisement

Ondo had been pursuing acquisitions before the report that somebody tried to sell the company. Crypto.news reported in July that Ondo was exploring an acquisition worth up to $500 million in wealth technology or adjacent financial businesses. No formal adviser or specific acquisition target had been disclosed at the time.

Ondo’s official funding history shows a $20 million Series A in 2022 led by Founders Fund and Pantera Capital, with Coinbase Ventures, Tiger Global, GoldenTree, Wintermute, Flow Traders and others participating. The company had previously raised $4 million in its 2021 equity round.

Most recently, Ondo’s September 21 institutional conversion launch said approved firms can transfer existing shares from an Alpaca account into Ondo’s Alpaca account before corresponding Ondo Stocks tokens are issued onchain. Redemptions reverse the process, returning underlying shares to the institution’s Alpaca account.

Advertisement



Source link

Continue Reading

Crypto World

Bitget’s $352 million hack happened via spoofed transfers, not private keys, CEO Gray Chen says

Published

on

Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO Gray Chen says

She described the breach as the digital version of slipping forged withdrawal slips through a bank’s own teller window. The vault keys never left the building. Someone got into the office that prepares the slips, created paperwork that looked official, and sent it through the same approval window the bank uses every day. To the system doing the approving, it looked like a normal payout.

The outflow, however, has been stopped, Chen confirmed.

“Loss containment is confirmed. No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation. A full technical report will follow once confirmed,” she said.

The breach

The breach surfaced when Bitget’s systems flagged unauthorized transfers from some exchange hot wallets at 18:31 UTC on Sept. 24. A hot wallet stays connected to the internet so funds can move quickly. For an exchange, it is a temporary liquidity hub, analogous to an online cash drawer that handles instant trades, deposits, and withdrawals.

Advertisement

Chen said the hack also reached the warm-wallet layer. That is a semi-connected buffer between the automated hot wallets and fully offline cold storage. It tops up the hot wallet when balances run low and pulls excess deposits off the internet so too much capital is not left exposed.



Source link

Continue Reading

Crypto World

SEC’s Peirce backs zero-knowledge proofs for KYC

Published

on

Crypto Mom Hester Peirce to leave SEC as crypto rule work continues

SEC Commissioner Hester Peirce has called on U.S. regulators to use zero-knowledge proofs and digital credentials to reduce personal-data collection in KYC and AML compliance following her September 23 speech in New York.

Summary

  • Peirce urged regulators to use zero-knowledge proofs for compliance checks while collecting less personal information.
  • Attribute-based credentials could verify age, citizenship, investor status, or sanctions screening without exposing underlying data.
  • Existing KYC and AML requirements remain unchanged because Peirce’s remarks represent her policy views only.
  • The SEC’s five-year Innovation Exemption permits tokenized stocks to trade through permissioned automated market makers.
  • SIFMA warned the exemption could create investor confusion, liquidity fragmentation, and parallel markets for securities.

The SEC’s published transcript states that Peirce delivered the remarks at SIFMA’s 2026 Digital Assets Conference during her penultimate week as a commissioner. She made clear that the views were her own and did not necessarily represent the SEC or her fellow commissioners.

Peirce argued that financial institutions collect large amounts of identity and transaction data because of customer identification and anti-money-laundering requirements. She described the resulting records as “ever bigger data haystacks” and said repeated collection can turn financial infrastructure into a “panopticon.” Her comments were a policy proposal, not a change to current KYC or AML rules.

Advertisement

Peirce wants zero-knowledge proofs used for KYC checks

In place of some existing data collection, Peirce proposed greater use of attribute-based credentials. Such credentials could establish facts including age, citizenship, accredited-investor status or whether someone has passed sanctions screening without giving each institution the underlying records.

A zero-knowledge proof could then confirm that a person satisfies a required condition without exposing information such as a name, address or income. Peirce argued that regulators should move from prescriptive collection requirements toward attribute-based verification where technology can support the required compliance check.

Her proposal would not eliminate every identity check or transaction-monitoring duty. Peirce questioned whether every institution needs to collect the same information and suggested making it easier for regulated firms to rely on trusted third-party identity verification. Existing broker-dealer rules already permit reliance on another financial institution in limited circumstances when regulatory and contractual conditions are met.

Current rules require covered broker-dealers to maintain written Customer Identification Programs. The SEC’s AML guidance lists requirements covering customer identifying information, identity verification, recordkeeping and screening against designated government lists. No SEC rule issued with Peirce’s September 23 speech removed those obligations.

SEC staff had already examined privacy-based identity tools

Peirce’s remarks followed direct work inside the SEC Crypto Task Force on privacy-preserving identity technology. On July 17, task force staff met representatives of Aztec Laboratorium Limited to discuss regulatory issues involving crypto assets and ZKPassport, according to an SEC meeting memorandum.

Advertisement

Materials submitted for that meeting described a system in which government-issued identity documents are checked locally on a user’s device. The system then produces a cryptographic proof for a requested fact, such as age, jurisdiction or sanctions status, without sending the underlying identity information to the business. The claims about ZKPassport’s operation came from Aztec’s presentation to SEC staff and were not an SEC endorsement of the product.

The discussion covered whether cryptographic proofs could satisfy certain customer identification, sanctions-screening and recordkeeping requirements. Aztec’s materials acknowledged that existing rules do not necessarily contemplate replacing stored information with a cryptographic proof, leaving regulatory questions unresolved.

A 2025 President’s Working Group report had previously discussed zero-knowledge proofs as one method for confirming that identity checks or screening occurred without revealing the underlying personal information. The report called for regulators to examine how digital identity tools could operate within existing AML and customer-identification requirements.

Innovation Exemption gives tokenized stocks a five-year route

Before turning to privacy and KYC, Peirce addressed the SEC’s Innovation Exemption issued September 17. She described the order as two time- and size-limited exemptions intended to let qualifying tokenized securities trade through automated market makers while the SEC considers permanent rules.

Advertisement

The SEC order grants conditional relief to Tokenized Securities Venues from the Exchange Act definition of an exchange. Separate relief applies to certain liquidity providers that could otherwise meet the definition of a dealer. The exemptions run from September 17, 2026 through September 17, 2031.

As crypto.news reported in its five-year tokenized stock exemption coverage, eligible venues can use permissioned AMM liquidity pools for tokenized National Market System stocks. Eligible stock tokens must provide rights matching the corresponding traditional shares, while synthetic products that merely track a stock’s price fall outside the exemption.

The framework places limits on the experiment. Tier 1 tokenized stocks are capped at 75 symbols and 0.25% of the underlying stock’s prior-month average daily volume. Tier 2 securities are capped at 250 symbols and 2.5%. Venues must make specified transaction information public and update qualifying transaction data within ten minutes.

Peirce said she preferred tokenized exposure to U.S. equities to develop domestically instead of leaving overseas platforms as the primary venue for such products. Chairman Paul Atkins separately described the exemption as a “bridge toward durable rulemaking.”

Advertisement

In related coverage, crypto.news reported that tokenized stocks must preserve traditional shareholder rights under the SEC framework. The exemption gives issuers an opportunity to object before an unaffiliated third party makes a tokenized version of their stock available through a qualifying venue.

SIFMA raises concerns as SEC seeks public comments

SIFMA welcomed regulatory work on tokenized securities but raised concerns about parts of the temporary framework. President and CEO Kenneth Bentsen Jr. said the group was concerned that multiple tokenized versions of listed securities trading in parallel markets could create investor confusion and price or liquidity fragmentation.

Peirce acknowledged SIFMA’s initial response during her September 23 remarks and said the exemption represented only one stage of the SEC’s work on tokenized securities. She said the agency’s longer-term task was to establish rules for intermediaries and venues handling forms of tokenized securities that existing market regulations did not originally contemplate.

The KYC proposal remains separate from that order. Peirce did not announce an SEC rulemaking that would allow zero-knowledge proofs to replace existing customer-identification records, nor did her speech create a new compliance exemption. The current broker-dealer AML framework continues to require firms to follow applicable customer-identification, monitoring and reporting rules.

Advertisement

For tokenized securities, meanwhile, the SEC has kept File No. 4-927 open for public comments on the Innovation Exemption. The agency is specifically requesting feedback on its five-year duration, trading limits, market effects, compliance conditions and whether any parts of the temporary framework should eventually become permanent.




Source link

Advertisement
Continue Reading

Crypto World

Brazil sets $10K self-custody crypto reporting rule

Published

on

Brazil tokenizes cows as collateral in first B3 credit deal

Brazil’s central bank has required covered institutions to report virtual-asset transfers worth at least $10,000 to or from self-custody wallets beginning October 1, 2026.

Summary

  • Resolution 588 puts $10,000 self-custody crypto transfers into mandatory Coaf reporting from October 1, 2026.
  • Resolution 588 creates a reporting requirement, not a ban, transaction ceiling, or mandatory transfer freeze.
  • Covered institutions must report qualifying transfers involving self-custody wallets under Brazil’s existing AML framework rules.
  • Resolution 588 does not state that multiple sub-$10,000 transfers must be automatically aggregated for reporting.
  • Brazil’s separate 24-hour retention rule starts January 2027 and uses same-day transaction aggregation for customers.

The Central Bank of Brazil published Resolution BCB No. 588 on September 23, amending Circular No. 3,978, the anti-money-laundering and counter-terrorist-financing framework for institutions under its supervision. The new item added to Article 49 covers transfers of virtual assets to or from self-custodied wallets when the value equals or exceeds the equivalent of $10,000.

Advertisement

Brazil’s $10K self-custody rule starts October 1

Resolution 588 places qualifying self-custody transfers inside the category of specific operations that covered institutions must communicate to the Financial Activities Control Council, known as Coaf. The rule applies in both directions, covering transfers sent to a self-custody wallet and transfers received from one.

The resolution does not prohibit self-custody, cap the amount a user can transfer, or state that a qualifying transaction must be blocked. B3 reported that the $10,000 figure is a mandatory reporting threshold instead of a transaction limit. The central bank has said self-custody can reduce information available for monitoring because users directly control the private keys.

Advertisement

By amending Article 49 of Circular 3,978, the new provision sits alongside mandatory reports for certain large cash operations and foreign-currency cash transactions. Resolution 588 adds foreign-exchange transactions involving at least $10,000 in physical foreign currency and virtual-asset transfers involving self-custody wallets at the same dollar threshold.

Resolution 588 differs from Brazil’s 24-hour hold

The October reporting requirement is separate from Resolution BCB No. 584, an anti-fraud rule published in August. Resolution 584 covers certain outbound virtual-asset transfers to foreign service providers or self-custody wallets and permits a temporary retention period of up to 24 hours under defined risk controls from January 1, 2027. Brazil’s Finance Ministry explained the measure after the central bank adopted it.

As crypto.news previously reported, Brazil’s 24-hour hold on qualifying $10,000 crypto transfers uses a different threshold calculation. Resolution 584 can apply when one transfer exceeds the threshold or when the same customer’s transfers reach the threshold in aggregate during one day. Providers can release a transfer before the full 24 hours after completing the required risk review.

Resolution 588 contains no equivalent same-day aggregation language for its automatic reporting trigger. Its text refers to a transfer with a value equal to or above $10,000. A Brazilian regulatory analysis published after the September rules found the same distinction: Resolution 584 expressly aggregates same-day transfers, while Resolution 588 does not state such a formula.

Advertisement

The absence of an automatic aggregation clause does not remove separate suspicious-activity monitoring obligations. Circular 3,978 requires covered institutions to assess transactions or situations that may indicate money laundering or terrorist financing, with suspicious cases subject to a separate reporting process.

Covered institutions must send reports through AML controls

Article 49 of Circular 3,978 requires institutions within its scope to communicate listed transactions to Coaf. The circular’s existing timing rule requires Article 49 communications by the next business day after the transaction or relevant provision occurs, placing the new self-custody category inside an established compliance process.

The same circular prevents institutions from informing customers or third parties that a Coaf communication has been made. Resolution 588 does not create a direct filing obligation for an individual simply because the person controls a self-custody wallet; the reporting duty operates through institutions covered by the central bank’s AML framework when they handle a qualifying transfer.

In its public explanation, the central bank said self-custody can “reduce the availability of information for monitoring and risk assessment purposes.” The statement distinguished user-controlled wallets from assets held by an institution authorized by the central bank, where customer and transaction records remain inside a supervised entity.

Advertisement

Resolution 588 itself does not create a new crypto tax rate, fee, or transaction levy. The measure amends Brazil’s AML/CFT reporting framework, while crypto taxation operates under separate tax rules. Crypto.news has previously covered Brazil’s separate crypto tax framework, including rules affecting gains from assets held in self-custody.

Brazil is rolling out crypto supervision in stages

Resolution 588 arrives within a series of virtual-asset rules introduced since 2025. As crypto.news reported, Brazil’s capital requirements for crypto service providers now sit alongside licensing, governance, security and compliance requirements. A separate 2026 rule has restricted virtual assets from settling payments inside regulated cross-border electronic foreign-exchange channels. Brazil’s cross-border crypto payment restrictions cover the supervised eFX system without banning ordinary crypto transfers outside that channel.

A separate central bank measure, Resolution BCB No. 589, was issued on September 23 alongside Resolution 588. It changes rules for virtual-asset service providers, including supervisory information covering customer balances, custody positions, proof of reserves and customer assets committed to staking. Provisions governing those data submissions take effect on January 1, 2027.

Resolution 589 changes another operational deadline for institutions dealing with crypto service providers. From November 6, 2026, financial institutions, payment institutions and other entities authorized by the central bank face restrictions on carrying out or facilitating virtual-asset market operations with counterparties that are not authorized to operate in Brazil, subject to the exceptions in the applicable regulation.

Advertisement




Source link

Continue Reading

Trending

Copyright © 2025