Connect with us

Crypto

Liquid Network drained of $320M in cache bug exploit

Published

on

Gnosis Pay exploit tied to Zodiac delay module as users exit

A range-proof cache bug in the Elements codebase let an unknown actor mint unbacked L-BTC, drain 95% of the federation reserve through SideSwap, then negotiate its return on-chain via OP_RETURN messages. The network remains frozen, 598.5 BTC sits in the attacker’s wallet, and the entire federated sidechain model faces the hardest questions it has ever had to answer.

Summary

  • An unknown actor exploited a range-proof verification cache bug in Elements to create roughly 4,000 unbacked L-BTC and peg them out for real Bitcoin on Sept. 6, 2026, draining 95% of Liquid’s reserves in 23 minutes.
  • The attacker communicated via Bitcoin OP_RETURN messages, declaring “we are whitehats,” and returned 3,400 BTC after Blockstream patched its bridge nodes, while keeping 598.5 BTC (about $47 million) as a self-declared bounty.
  • Blockstream confirmed no federation keys were compromised, attributing the exploit to a cache-key collision in the confidential transactions verification logic that had entered the Elements master branch but never appeared in a tagged release.
  • The Liquid Network halted block production at 04:49 UTC on Sept. 7, exchanges suspended L-BTC deposits and withdrawals, and the network remains frozen as of this writing.
  • The incident has reignited debate over federated sidechain trust models, drawing comparisons to the 2016 Ethereum DAO hack and raising legal questions about whether keeping $47 million without a formal bounty agreement constitutes theft or legitimate security research.

Sunday afternoons are not supposed to feel like bank runs. Yet on Sept. 6, 2026, anyone watching the Liquid Network federation wallet saw something that looked a lot like one: 3,996 BTC leaving in a single peg-out transaction at 14:28 UTC, collapsing the reserve from 4,205 BTC to 202 BTC in less than half a minute. At prevailing prices, that was roughly $320 million. Gone.

What followed over the next 30 hours was one of the strangest episodes in Bitcoin’s history. The person or group behind the drain did not disappear into a mixing service. They wrote “we are whitehats. contact us on chain” in an OP_RETURN field, opening a public negotiation with Blockstream that anyone with a block explorer could read in real time. Nine messages went back and forth. A PGP key was verified. Bridge nodes were patched. And then 3,400 BTC came back, leaving 598.5 BTC, about $47 million, sitting in an address that nobody controls except the attacker.

Advertisement

The mechanics of what happened are technical. The implications are not. Liquid is the oldest Bitcoin sidechain, operated by a federation of 15 functionaries running tamper-proof hardware security modules in an 11-of-15 multisig arrangement. It has processed billions in volume for exchanges, traders, and tokenized asset issuers since its launch in 2018. Now its reserves are short by $47 million, its reputation is in intensive care, and the broader question of whether federated sidechains can be trusted with real money is louder than it has been at any point in the past eight years.

How the range-proof cache bug worked

To understand the exploit, you need to understand how Liquid hides transaction amounts. Liquid uses confidential transactions, a cryptographic scheme where the value in each output is hidden behind a Pedersen commitment. Range proofs verify that the hidden amount falls within an allowed range without revealing what the amount actually is. This is computationally expensive, so Elements, the Bitcoin Core fork that powers Liquid, caches successful verification results for reuse.

The problem was in how the cache stored those results. Before the patch, the cache key was derived from the proof bytes and hidden amount alone. Asset type and scriptPubKey context were not included. That meant a previously verified proof could be replayed in a context where it should not have been valid.

The attacker exploited this by planting 68 identical range proofs across 14 hours between Liquid blocks 4,049,384 and 4,050,246, spending 41 satoshis per transaction. Each carried an OP_RETURN output with L-BTC written plainly but the amount hidden, using a commitment to zero with the simplest possible blinding key. Once those proofs were cached, the attacker constructed an invalid output that matched the cache key of a previously valid check. Federation nodes retrieved the cached result and skipped the verification that should have rejected the inflationary output.

Advertisement

At Liquid block 4,050,336, the attacker created approximately 3,996 L-BTC out of nothing. Those tokens looked valid to every federation functionary running the vulnerable code. The attacker sent them to SideSwap’s peg-out service, which burned the L-BTC and requested payment from the federation. The federation obliged, releasing 3,996.0183 BTC to the attacker’s Bitcoin address.

The fix, which binds the cache verification to both asset type and scriptPubKey, had been committed to the Elements master branch on Aug. 3 and merged on Sept. 2. But it had never appeared in a tagged release. The federation nodes were running version 23.3.3, dated April 13, which did not include the patch. Mononaut, the mempool.space developer, noted that federation functionaries accepted the exploit transactions, approved the withdrawals, and continued building blocks, while other nodes running different code rejected the invalid transactions entirely.

Advertisement

DeFi has lost more than $1.3 billion to hacks in 2026, with compromised private keys overtaking smart contract bugs as the leading attack vector for the first time on record. The Liquid exploit does not fit neatly into either category. No keys were stolen. No smart contract was drained. A caching optimization in transaction verification logic left a gap wide enough for someone to mint $320 million.

The 23 minutes that emptied the vault

The attacker was not reckless, and the on-chain record shows a methodical dry-run sequence that preceded the main event by two full days.

On Sept. 4, two small peg-in transactions totaling 2.15 BTC entered Liquid. Two days later, on the morning of Sept. 6, three dry-run peg-outs moved 0.95, 1.71, and 0.55 BTC through SideSwap between 11:30 and 13:16 UTC. Each one completed without issue. The peg-out mechanism worked. The federation signed. Real BTC arrived on the other side.

At 13:53 UTC, the main event: the minting transaction created roughly 4,000 unbacked L-BTC. At 14:28:56 UTC, the federation processed the peg-out, releasing 3,996.0183 BTC. SideSwap forwarded 3,995.99999857 BTC to the attacker’s final address in the same block. The SideSwap fee of 0.1%, roughly 3.996 BTC, plus the three dry-run payouts of 3.21 BTC combined, were the only friction in the entire operation.

Advertisement

From mint to peg-out to receipt, the elapsed time was approximately 35 minutes. From the moment the federation signed the peg-out to the moment the Bitcoin reached the attacker, it was a single block.

The reserve cliff is visible on any blockchain analytics dashboard. Liquid’s federation wallet held 4,205.29 BTC at 14:27 UTC. One minute later, it held 202.63 BTC. It is the most dramatic single-transaction reserve drain in the history of Bitcoin sidechains.

On-chain negotiation: nine messages in OP_RETURN

What happened next turned a catastrophic exploit into something closer to a hostage negotiation conducted entirely in public.

At 18:30 UTC on Sept. 6, roughly four hours after the drain, the attacker embedded a message in a Bitcoin transaction: “we are whitehats. contact us on chain.” The choice of communication channel was deliberate. OP_RETURN messages are permanent, public, and verifiable. Neither side can fake the origin of a message sent from an address they control.

Advertisement

Blockstream responded at 19:31 UTC with a straightforward request: “Please contact [email protected].” The attacker ignored the email offer.

At 03:30 UTC on Sept. 7, after Liquid had halted block production at 04:49 UTC, the attacker sent a longer message: “Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.”

This was not a ransom demand. It was a security disclosure with $320 million in collateral. The attacker wanted proof that the vulnerability was closed before returning funds that could theoretically be re-exploited by someone else.

Blockstream spent the next several hours patching bridge nodes across the federation. At 09:04 UTC on Sept. 7, Blockstream sent a PGP-signed message: “Bridge nodes are patched, safe to return the funds.” The signature verified against the security key ending 6844 A2D6 published at blockstream.com/pgp.txt. Seven total verified Blockstream messages were sent from fresh addresses over the course of the negotiation.

At 16:09 UTC on Sept. 7, the return transaction landed: 3,400 BTC back to the federation address. The remaining 598.5 BTC stayed in the attacker’s wallet. The final OP_RETURN message from the attacker, sent at 21:03 UTC, contained a single emoticon: “:(“

That frowny face has become one of the most analyzed two characters in Bitcoin history. Was it regret at having to keep any amount at all? Disappointment that the bug existed in the first place? A sardonic comment on the state of sidechain security? Nobody knows, and the attacker has not communicated since.

Advertisement

The $47 million question: bounty or theft

The 598.5 BTC the attacker retained is worth approximately $47 million. There was no formal bug bounty program covering this vulnerability. There was no contract, no prior agreement, and no legal framework governing the situation.

Liquid’s attackers offered to return most of the 4,000 BTC, and they did. But “most” is doing heavy lifting in that sentence. Keeping 15% of a $320 million exploit without any prior agreement is not what most security researchers would call standard white-hat behavior.

Charles Guillemet, CTO of Ledger, was among the first prominent voices to push back on the white-hat framing. His argument was direct: genuine white hats disclose a flaw before moving hundreds of millions in collateral, not after. Draining 95% of a network’s reserves and then demanding a patch before returning anything resembles extortion more than it resembles security research.

The counterargument, and it is not a weak one, runs like this: the attacker found a live vulnerability that could have been exploited by a malicious actor at any time. By draining the funds and holding them, they prevented a black-hat from doing the same thing with no intention of returning anything. The 598.5 BTC is compensation for a service rendered, not a ransom paid under duress.

Advertisement

Both positions have precedent. The 2022 Wormhole exploit saw the attacker keep $320 million with zero returned. The 2023 Euler Finance hack resulted in a full return after on-chain negotiation. The Ronin bridge exploit in 2022 saw state-backed attackers from North Korea’s Lazarus Group take $624 million with no negotiation at all. Against that backdrop, getting 85% back within 30 hours looks like one of the better outcomes in the history of crypto exploits.

The legal question remains open. Unauthorized access statutes in most jurisdictions do not include a “good intentions” exception. Taking funds without authorization and then returning most of them may satisfy the definition of theft regardless of what the attacker writes in an OP_RETURN field. Whether any law enforcement agency will pursue the case, given that the majority of funds were returned, is a different matter entirely.

Why federation nodes ran unpatched code

This is the part of the story that should concern anyone who uses a federated system.

The fix for the range-proof cache bug was committed to the Elements repository on Aug. 3, 2026. It was merged into the main branch on Sept. 2. Four days later, the exploit happened. The federation nodes were running version 23.3.3, released on April 13, which predated the fix by nearly five months.

Advertisement

The gap between “fix merged” and “fix deployed to production” is a familiar problem in software engineering. It is also a problem that is supposed to be mitigated by the entire structure of a federated sidechain. Liquid’s 15 functionaries operate specialized hardware security modules. They run tamper-proof servers. They manage an 11-of-15 multisig wallet designed to tolerate up to four compromised or offline signers. The security model assumes that the federation is competent, well-resourced, and running current software.

Running unreleased development code is one kind of risk. Running code that is five months behind a critical security fix is another. Neither inspires confidence.

Liquid Network recovered 3,400 BTC after the bridge exploit, but the recovery came from the attacker’s goodwill, not from any federation safeguard. If the attacker had been a Lazarus Group operator, the 3,996 BTC would have gone through a mixer within hours and the Liquid Network would have been insolvent with no path to recovery.

The question that Blockstream has not yet answered publicly is why a patch that had been merged for four days and committed for over a month was not deployed to federation nodes. Sidechain security is only as strong as the weakest link in its operational chain. For Liquid, that weakest link turned out to be a software update that sat in a repository while the vulnerability it fixed sat in production.

Advertisement

The DAO parallel: when code breaks trust

The comparisons to the 2016 DAO hack started within hours of the Liquid drain, and they are worth taking seriously.

In June 2016, an attacker exploited a reentrancy bug in the DAO smart contract to drain 3.6 million ETH, worth roughly $60 million at the time. The Ethereum community faced a choice: accept the exploit as a valid outcome of the code or hard fork the network to reverse the transaction and return the funds. Ethereum chose the fork. Ethereum Classic, the unforked chain, survived as a philosophical statement that code is law and exploits are just the market correcting for bad code.

The Liquid situation rhymes but does not repeat. Bitcoin’s base layer was never at risk. The exploit happened entirely within the Liquid sidechain, and the peg-out mechanism that released real BTC was functioning exactly as designed. It released funds because the federation nodes told it the request was valid. The federation nodes said the request was valid because their verification cache had been poisoned by a bug that should have been patched.

Advertisement

There is no fork debate here because there is nothing to fork. Liquid is a federated sidechain, not a proof-of-work chain with independent miners. Blockstream can patch the code, restart the bridge nodes, and resume operations. The 598.5 BTC that the attacker kept is gone. It left the Liquid system through a legitimate peg-out and now exists on the Bitcoin base layer, where it is subject to the same rules as any other Bitcoin. No amount of federation governance can claw it back.

But the DAO parallel holds in a deeper sense. Both incidents forced their respective communities to confront the gap between the security model they believed they had and the security model they actually had. Ethereum believed smart contracts were trustless. Liquid’s users believed a federation of 15 functionaries running hardware security modules was safe enough. Both assumptions died on contact with a sufficiently motivated attacker.

Advertisement

The opposing case: federated sidechains still work

It is worth making the bull case for Liquid and federated sidechains at full strength, because the bearish narrative writes itself and the truth is more complicated.

First, the peg-out worked exactly as designed. The federation signed a transaction that looked valid according to the rules it was running. The bug was in the verification logic, not in the signing logic, the key management, or the HSM infrastructure. Blockstream’s core security architecture, the 11-of-15 multisig with tamper-proof hardware, was never breached.

Second, the attacker returned 85% of the funds within 30 hours. Compare that to the Bybit hack in February 2025, where Lazarus Group stole $1.4 billion and returned nothing. Compare it to the Ronin bridge, where $624 million vanished into North Korean laundering networks. Compare it to the Coldcard hardware wallet exploit that drained $130 million in July 2026 with no possibility of recovery. Liquid’s outcome, while painful, is among the best that any exploited protocol has achieved.

Third, the vulnerability was a software bug, not a design flaw. Range-proof caching is an optimization, and the fix is straightforward: include asset type and scriptPubKey in the cache key. The patch already exists. Once deployed, this specific attack vector closes permanently.

Advertisement

Fourth, other assets on Liquid, including USDT, DePix, and tokenized real-world assets, were unaffected. The exploit targeted the BTC peg-out mechanism specifically. Users holding L-USDT or other Liquid-issued tokens did not lose funds.

The counterargument to all of this is simple: “It worked as designed” is cold comfort when the design allowed $320 million to walk out the door. A system that depends on 15 organizations keeping their software up to date has 15 potential points of failure. And the fact that recovery depended on the attacker’s goodwill, not on any protocol safeguard, is not a feature of the security model. It is the absence of one.

What this means for every federated bridge

The Liquid exploit lands at a moment when the Bitcoin sidechain and Layer 2 ecosystem is more crowded and more ambitious than it has ever been.

Stacks, which upgraded to the Nakamoto release in late 2025, uses a different security model tied to Bitcoin finality. The Lightning Network operates as a true Layer 2 with channel-based security that does not depend on a federation. Fedimint, the federated e-cash protocol, uses a similar federation structure to Liquid but for custodial Bitcoin custody rather than a full sidechain. RSK, another federated sidechain, shares many of Liquid’s architectural assumptions.

Advertisement

For every project that uses a federation, the Liquid exploit is a wake-up call. The question is not whether federation members can be trusted with private keys. The question is whether federation members can be trusted to run current software, respond to security disclosures in time, and maintain operational discipline across 15 independent organizations with different priorities, different IT teams, and different levels of urgency.

Protocol halts after exploits are becoming routine across the industry. The Liquid freeze is more consequential than most because it affects a Bitcoin-native sidechain that institutional players have used since 2018. If Liquid cannot guarantee that its federation is running patched software, then the trust advantage that a known, regulated federation is supposed to provide over anonymous validators or decentralized bridges collapses.

The broader lesson is one that the DeFi ecosystem has been learning the hard way since 2020: operational security is not a feature you ship once. It is a process you execute every day. Bugs will be found. Patches will be written. The question is whether the patch reaches production before the attacker reaches the peg-out. On Sept. 6, 2026, the answer was no.

What to watch

  • Federation node software versions: Whether Blockstream implements mandatory version checks or automated update mechanisms for functionary nodes will signal how seriously the operational gap is being addressed.
  • L-BTC depeg recovery: The reserve backing ratio dropped to roughly 86 cents per L-BTC after the return. Watch for how quickly confidence and peg stability return once bridge nodes reopen.
  • The 598.5 BTC wallet: On-chain trackers will monitor the attacker’s retained funds for movement. Any attempt to mix or spend will provide forensic data about the attacker’s identity and intentions.
  • Legal and regulatory response: Whether any jurisdiction opens a criminal investigation will set precedent for how self-declared white-hat exploits are treated when no formal bounty agreement exists.
  • Competing sidechain and L2 adoption: If institutional users migrate volume from Liquid to Lightning, Stacks, or centralized settlement layers in the wake of the exploit, it will be visible in on-chain metrics within weeks.

What exactly happened to the Liquid Network on Sept. 6, 2026?

An unknown actor exploited a range-proof verification cache bug in the Elements codebase to mint approximately 4,000 unbacked L-BTC, then used SideSwap’s peg-out service to convert them into real Bitcoin. The peg-out drained 95% of Liquid’s federation reserve, taking it from 4,205 BTC to 202 BTC in a single transaction. The attacker later returned 3,400 BTC and kept 598.5 BTC, worth about $47 million.

Advertisement

Was Bitcoin’s main network affected?

No. The exploit happened entirely within the Liquid sidechain. Bitcoin’s base layer was never at risk. The BTC that left the federation wallet did so through a legitimate peg-out mechanism that functioned exactly as programmed. The problem was that the request was based on tokens that should never have existed.

How did the attacker communicate with Blockstream?

Through OP_RETURN messages embedded in Bitcoin transactions. These messages are permanent, public, and verifiable by anyone with a block explorer. The attacker’s first message read “we are whitehats. contact us on chain.” Blockstream responded with PGP-signed messages verified against its published security key. Nine total messages were exchanged over roughly 26 hours.

Is the Liquid Network still frozen?

Yes, as of Sept. 7, 2026. Blockstream halted block production and disabled bridge nodes to prevent repeat exploitation. Exchanges have suspended L-BTC deposits and withdrawals. Blockstream has confirmed that bridge nodes are patched, but the network has not yet resumed normal operations.

Why did the attacker keep 598.5 BTC?

The attacker has not explained the specific amount. There was no formal bug bounty program, no contract, and no prior agreement. The retained amount, roughly 15% of the total exploit, appears to be a self-declared bounty for discovering and demonstrating the vulnerability. Whether this constitutes a legitimate finder’s fee or outright theft depends on your legal jurisdiction and your philosophy.

Advertisement

How does this compare to the 2016 Ethereum DAO hack?

Both incidents exposed a gap between a community’s assumed security model and its actual one. The DAO hack led Ethereum to hard fork, reversing the exploit and splitting into two chains. The Liquid exploit cannot be reversed the same way because the BTC left through a valid peg-out and now sits on Bitcoin’s base layer, beyond Liquid’s governance. The structural parallel is about trust models failing under pressure, not about the specific recovery mechanism.

Could this happen to other federated sidechains?

Any system that relies on a federation to validate transactions is only as secure as the software those federation members are running. The specific range-proof cache bug is unique to Elements, but the general category of vulnerability, where verification logic contains a flaw that allows invalid state transitions, applies to any codebase. Federation members who are slow to patch create windows of opportunity for attackers.

Should I still use the Liquid Network?

That depends on your risk tolerance and use case. Liquid processed billions in volume before this incident and may well resume normal operations once Blockstream completes its remediation. The core architecture, 15 functionaries with HSM-protected keys in an 11-of-15 multisig, was not compromised. But the operational failure that allowed a five-month-old fix to go undeployed is a legitimate concern. Users should assess whether the speed and confidentiality advantages of Liquid justify the federation trust model in light of what happened. This is educational analysis, not investment advice.

Disclaimer: This article was published on Sept. 7, 2026, and reflects information available at the time of writing. The situation around the Liquid Network exploit is developing. Readers should verify current status through official Blockstream channels before making any decisions related to Liquid Network assets.

Advertisement

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto

Crypto’s Widening Net: From Fed Bets to Blackjack Tables, Digital Assets Keep Blurring Old Boundaries

Published

on

If there is one throughline in this week’s crop of crypto headlines, it is that the industry has stopped pretending it is only about buying and holding coins. Across a handful of stories making the rounds, digital assets are shown pushing into territory once reserved for central bankers, casino floors, brokerage accounts and pre-IPO investors alike — a reminder that “crypto news” increasingly means finance news, gambling news and macro news rolled into one.

Take the growing chatter around prediction markets and Federal Reserve policy. Traders have been flocking to on-chain betting platforms to price the odds of late-2026 rate decisions, effectively turning monetary policy into a tradable asset class alongside Bitcoin and Ethereum. That such markets exist at all is notable: a decade ago, speculating on FOMC outcomes required options contracts or futures desks.

Now it can happen peer-to-peer on a blockchain, with odds shifting in real time as economic data lands. The rise of these markets suggests crypto infrastructure is becoming a genuine alternative venue for hedging and speculating on the traditional economy, not just a parallel casino for digital tokens.

Speaking of casinos, the sector itself continues to evolve in ways that mirror shifts in consumer taste rather than technology alone. Reports on crypto gambling lobbies note that live-dealer blackjack tables are increasingly outnumbering roulette wheels—a seemingly small detail that says more about what crypto-native gamblers want.

Advertisement

Live blackjack offers a sense of skill and control that pure-chance games like roulette can’t match, and operators appear to be responding by stacking their lobbies accordingly. It’s a small but telling sign that crypto casinos are maturing into product-driven businesses competing on experience, not just novelty.

Meanwhile, the boundary between crypto trading and traditional equities markets keeps eroding. New developments around Aave’s lending protocol reportedly let users borrow stablecoins against tokenized versions of tech stocks issued through Coinbase and built on the Base network.

If that model gains traction, it would mark a significant step in bringing real-world assets fully into DeFi’s collateral system — letting someone hold a tokenized slice of a Nasdaq darling and borrow against it the same way they might borrow against ETH or Bitcoin today. It’s the kind of integration that regulators, banks and crypto-native builders have all been circling for years, and its practical rollout matters more than the concept alone.

On the trading-platform side, perpetual futures exchanges continue to expand what counts as a “market.” One report describes a platform offering more than 120 perpetual contracts spanning everything from Bitcoin to pre-IPO robotics companies, letting traders apply leverage to assets that, in many cases, aren’t even publicly listed yet.

Advertisement

This kind of expansion into speculative, illiquid corners of the private market — wrapped in crypto’s leverage-friendly perpetual format — raises real questions about price discovery and risk, even as it satisfies demand from traders hungry for exposure beyond the usual crypto majors.

Finally, there’s the steady drumbeat of token listings that keeps the broader ecosystem churning. A gambling-focused token tied to the Dexsport platform recently landed on the MEXC exchange, a move that typically brings a token more liquidity and visibility, if not necessarily more fundamental value. Listings like these remain a bread-and-butter event in crypto markets — routine, but still closely watched by holders hoping for a price bump and a wider trading audience.

Individually, none of these developments is likely to reshape the industry overnight. But together they sketch a familiar pattern in crypto’s ongoing evolution: infrastructure built for speculative tokens is steadily being repurposed for macro bets, tokenized equities, private-company exposure and gambling products alike.

The technology is proving flexible enough to wrap around almost anything with a price — which is exactly why regulators, investors and casual observers alike keep struggling to say where “crypto” ends and the rest of finance begins.

Advertisement
Continue Reading

Crypto

Perplexity AI Predicts a Big Move for BTC in 2026 Even With Recent Dip

Published

on

Bitcoin price prediction: Microsoft Copilot AI predicts that if price momentum across the markets continues, BTC could hit $180K by 2027

Perplexity AI predicts that if a full-blown bull market returns in Q4, Bitcoin could reach $180,000 before January 1, 2027. The bullish range is estimated at $140,000 to $180,000, with a potential late-cycle surge that could push Bitcoin beyond $200,000.

Currently priced around $83,000, this would represent a gain of about 115% to reach $180,000. What’s noteworthy is that Bitcoin has already corrected significantly from its previous cycle high of about $126,200 on October 6, 2025, followed by a sharp decline during 2026.

Bitcoin has a history of producing substantial gains during strong market cycles. According to historical annual data, BTC gained approximately 154% in 2023 and 110% in 2024. If the current predictions hold true, we may see a similar increase on the horizon.

Bitcoin price prediction: Perplexity AI predicts that BTC could still rise to nearly $200K in 2026 even with it dropping -3% over the weekend
SOURCE: Perplexity AI Predicts Bitcoin Price

Perplexity AI Predicts Bitcoin to $180,000 if Bullish Catalysts Align: Does the Technical Analysis Back it Up?

Bitcoin recently broke out of a pattern of lower highs that had developed since May, reclaiming several key moving averages. According to Reuters’ technical analysis, $81,781 is considered important support, while $86,500 is a significant resistance level. Above that, the next technical targets are around $90,000 and $97,867.

Advertisement

CryptoQuant has noted a similar trend, calling $81,700 a key level because it aligns with Bitcoin’s 365-day moving average. Resistance levels above this are near $86,600 and $88,700.

Bitcoin’s first major test is surpassing the $85,000 level, followed by the $86,000 to $88,000 range. Bitcoin has pushed through this area, which matters because a sustained breakout would remove one of the largest technical obstacles between its current price and the $100,000 level.

The next major milestone is approximately $98,000. Beyond that, the market will be approaching the all-time high of $126,200, where it gets particularly interesting.

Advertisement

Once Bitcoin decisively breaks beyond $126,000, it will enter a phase of genuine price discovery. Historical resistance above that level is very limited. At that point, psychological targets such as $130,000, $140,000, and $150,000 could attract momentum traders and institutional investors.

Earn $50 and Enter $300K Prize Draw on EdgeX

Bitcoin Hyper Targets Early Mover Upside as Bitcoin Drops Dangerously Close to $80,000

A -2.5% daily drop is not too much to worry about for whales and those already heavily positioned at a much lower price. However, for those who bought over $80,000, things could be getting uncomfortable, which is why presale opportunities prove so popular.

Advertisement

Bitcoin Hyper ($HYPER) is positioning itself as the first Bitcoin Layer 2 with full SVM integration. It boasts smart contract execution built for speed that outpaces Solana itself, while settling back to Bitcoin’s base-layer security.

As of today, the presale has raised more than $33.1M at a current token price of just $0.0136864, with staking rewards live at launch at a huge 35% APY.

The pitch: solve Bitcoin’s slow transactions, high fees, and lack of programmability without abandoning what makes BTC trusted in the first place. A Decentralized Canonical Bridge handles BTC transfers natively.

Gain Access to New Bitcoin Layer 2 Early Here

Advertisement

Discover: The Best Token Presales

The post Perplexity AI Predicts a Big Move for BTC in 2026 Even With Recent Dip appeared first on Cryptonews.




Source link

Advertisement
Continue Reading

Crypto

XRP Price Slides 2.9% as $1.50 Reclaim Becomes Critical

Published

on

xrp logo

XRP lost its $1.50 price pivot today, sliding to $1.47 after a daily decline of about 3%. The break forces a binary question onto the chart: does the selling pressure showing up in spot-market volume resolve into a quick reclaim, or does it open the door to a deeper slide toward $1.40-$1.42?

The 200-day EMA is near $1.37, the level that would flip the medium-term structure from bullish to neutral. The token has been printing lower highs since a local peak near $1.63 on September 23, and a second attempt to clear $1.60 on September 25 failed as well. Since then, the decline has been slow and orderly: $1.55, then $1.52, then $1.50, and now $1.47.

Xrp (XRP)
24h7d30d1yAll time

There was no single dramatic session driving the move. Instead, the pattern reads as buyers simply not showing up, with every small bounce getting sold rather than extended. After the sharp rally in early September, that kind of cooling was overdue, but the open question is whether $1.50 was ever real support or just a round number the market is now testing.

Earn $50 and Enter $300K Prize Draw on EdgeX

Advertisement

ETF Accumulation Narrative or Technical Pullback?

The chart itself frames this as a cooling-off period following the rally that carried the XRP price up nearly 50% from its August low near $1.00. RSI sits at a neutral 54, with no overbought or oversold readings to lean on. Price levels, not oscillators, are setting the tone for this week.

XRP price slips 2.9% to $1.47 as bulls face a key test: reclaim $1.50 or risk a deeper pullback toward $1.37 and $1.30 if support fails.

Separately, market data has pointed to sustained spot XRP ETF inflows running into the hundreds of millions of dollars over recent weeks, a trend some trackers frame as ongoing institutional accumulation beneath the price action. That flow data is useful context, but it is not confirmed as the driver of Monday’s drop, as the pullback below $1.50 traces cleanly to failed resistance tests and fading bid support.

The medium-term structure remains intact for now. XRP sits above its 200-day EMA at $1.37, which is curling upward for the first time since spring. This is a sign the longer trend has not broken, even as the shorter-term chart bleeds lower. A descending trendline from the late-August spike to $1.70 was cleared in mid-September, and that breakout is what fueled the run to $1.67 in the first place.

A second descending trendline, drawn from the September 23 high, is now the line bulls need to clear in October; left alone, it points toward $1.20 by mid-November. The levels on both sides of the current price are well defined.

Advertisement

Trade XRP on Bybit and Get a Chance to Win Our $1,000 USDT Airdrop

Reclaim $1.50 or Risk $1.37: XRP Price Next Move

The first job for bulls is straightforward: close a daily candle back above $1.50. Do that, and Monday’s drop reads as a fakeout rather than a breakdown, with $1.55 as the next confirmation level and $1.60-$1.63 as the target that would put the September 23 high back in play.

Fail to reclaim $1.50 in the next day or two, and $1.40-$1.42 becomes the level to watch, with the 200-day EMA at $1.37 as the line that actually matters for the medium-term outlook. A close below it would shift Ripple’s native asset from a bullish structure to a neutral one, opening room toward $1.30 and, in a broader crypto market sell-off scenario, $1.20.

Advertisement

For this week, the range is $1.37 to $1.60, with $1.50 sitting as the pivot in between. On technical analysis grounds, the base case is a dip toward $1.40-$1.42 that gets bought, followed by another attempt at reclaiming $1.50. A pattern consistent with pullbacks inside an uptrend rather than the start of a new downtrend.

The $1.80-$2.00 zone remains the valid medium-term target as long as $1.37 holds; lose it, and that target moves out of reach for the immediate term.

Discover: The Best Token Presales

The post XRP Price Slides 2.9% as $1.50 Reclaim Becomes Critical appeared first on Cryptonews.

Advertisement




Source link

Continue Reading

Crypto

Crypto’s New Playground: Casinos, Fed Bets, and Tokenized Stocks Blur the Line Between Trading and Gambling

Published

on

The crypto industry has always had a talent for reinventing itself, but the latest wave of product launches suggests the industry is heading somewhere new: a place where trading, betting, and borrowing are becoming almost indistinguishable from one another. A cluster of recent developments — spanning live-dealer casino games, a new token listing tied to decentralized betting platforms, prediction markets built around Federal Reserve policy, sprawling perpetual futures exchanges, and DeFi protocols that let users borrow against tokenized shares of tech companies — paints a picture of an ecosystem racing to fuse speculation of every stripe into a single, crypto-native experience.

Take the world of crypto casinos, where live blackjack tables have reportedly begun to crowd out roulette wheels in lobby rankings. The dynamics driving that shift echo something familiar from traditional gambling: player preference for games that reward skill and pacing over pure chance. Blackjack lets players make decisions — when to hit, stand, split, or double down — giving a sense of agency that a spinning roulette wheel simply can’t replicate. In an industry built around instant, low-friction transactions using digital assets, that appeal seems to translate directly into engagement, with live-streamed dealers adding a layer of social, real-time theater that slot-style games lack.

That same appetite for interactive, decision-driven products is showing up elsewhere. Dexsport, a decentralized betting and casino platform, recently saw its native token, DESU, listed on the exchange MEXC — a milestone that matters less for the listing itself than for what it signals about the sector’s maturation. Token listings on major exchanges typically bring liquidity, visibility, and a degree of legitimacy that smaller platforms struggle to achieve on their own. For everyday users, a listing like this often translates into easier on-ramps, more trading pairs, and a stronger case that the underlying platform is being taken seriously by the broader market rather than treated as a niche experiment.

Meanwhile, speculation is moving well beyond games of chance and into the realm of macroeconomic policy. Prediction markets tracking the Federal Reserve’s interest rate decisions have become one of the more closely watched corners of crypto-adjacent finance heading into the back half of 2026. Traders on these platforms are effectively placing wagers on central bank behavior, turning monetary policy announcements into tradeable events. The appeal is straightforward: instead of relying solely on bond markets or futures tied to traditional finance, participants can now stake positions directly on whether the Fed will hold, cut, or raise rates, often with faster settlement and more granular contract structures than legacy markets offer. It’s a sign that prediction markets, once dismissed as a curiosity, are increasingly viewed as a legitimate barometer of trader sentiment on issues far removed from crypto prices themselves.

Advertisement

The appetite for exotic exposure is also evident in the perpetual futures space, where platforms like ApeX Omni have expanded their offerings well past the usual roster of Bitcoin and Ethereum contracts. With well over 120 perpetual markets now available, traders can reportedly take leveraged positions not just on major cryptocurrencies but on themes as far-flung as pre-IPO robotics companies. This kind of expansion reflects a broader trend of crypto exchanges positioning themselves as all-purpose speculation venues, offering leverage on virtually any asset class that generates enough trader interest — blurring the boundary between crypto trading and speculative bets on private, pre-public companies that would otherwise be inaccessible to retail investors.

Perhaps the clearest example of crypto finance colliding with traditional markets comes from Aave’s newest iteration. The protocol’s fourth version reportedly allows users to borrow USDC stablecoins against tokenized versions of Coinbase-linked tech stocks on the Base network. In practice, that means holders of tokenized equity exposure can unlock liquidity without selling their underlying positions — a mechanic long familiar to DeFi users who collateralize crypto assets, now extended to tokenized real-world securities. It’s a small but telling step toward a future where the wall between “crypto” and “traditional markets” continues to erode, with stocks, bonds, and other conventional assets increasingly represented on-chain and woven into the same lending and borrowing infrastructure that powers decentralized finance.

Taken together, these developments underscore a consistent theme: crypto platforms are no longer content to simply trade digital coins. They are building out entire ecosystems of speculation — casino games, prediction markets, leveraged derivatives, and collateralized lending — all designed to keep users engaged, liquid, and constantly exposed to new forms of risk and reward. Whether this convergence produces a more mature, diversified financial ecosystem or simply amplifies the volatility and risk-taking crypto is already known for remains an open question. What’s clear is that the industry’s appetite for expansion shows no signs of slowing down.

Advertisement
Continue Reading

Crypto

When AI Met Crypto: A Season of Super-PACs, Prompt-Injection Heists and Vape-Pen Blockchains

Published

on

If there was a single theme running through the crypto world’s headlines this spring and summer, it was this: the industry that once promised to reinvent money has increasingly fused itself to the industry promising to reinvent everything else — artificial intelligence.

The result, according to a string of reports and commentary tracked by researcher-journalist Molly White and blogger David Gerard, is a landscape where political money, security failures and marketing absurdity are all converging in ways that ought to worry anyone paying attention.

Start with the money in politics. In a recent interview, White — who has spent years cataloguing where crypto industry cash flows in Washington — turned her attention to a new wrinkle: artificial intelligence companies adopting the same political playbook that crypto firms pioneered.

According to the discussion, OpenAI and Anthropic are now effectively running competing pro-AI super-PACs, pouring money into races much the way crypto-aligned PACs like Fairshake have done in recent election cycles. White reportedly highlighted a botched intervention in New York’s 12th congressional district as an example of the sums involved and the risk of these efforts backfiring.

Advertisement

The parallel is not incidental. Crypto’s political spending playbook — deploy industry money to shape friendly regulation and punish critics — was built over several election cycles and proved remarkably effective at getting crypto-friendly candidates elected and skeptics sidelined.

Watchers like White argue that AI companies, facing their own looming questions about regulation, safety and liability, are now borrowing that same toolkit almost wholesale. Whether AI’s political spending proves as consequential as crypto’s remains to be seen, but the early signs suggest deep-pocketed AI labs are not content to leave the lobbying playing field to blockchain interests alone.

Money and politics aside, the more immediate crypto news has been considerably more chaotic on the technical side. A case in point: an unofficial crypto wallet built on top of Elon Musk’s Grok AI was reportedly compromised through a combination of an NFT and a prompt injection attack — a technique in which malicious instructions are hidden inside content an AI model processes, tricking it into taking unauthorized actions.

The episode is being cited by critics as a vivid illustration of what happens when experimental AI agents are given direct access to cryptocurrency funds without adequate safeguards. As one commentator put it, the incident underscores a blunt truth: the push toward “agentic commerce,” in which AI systems autonomously manage transactions and wallets on a user’s behalf, currently looks a lot like an open invitation to fraud.

Advertisement

That warning fits a broader pattern. Crypto’s history is littered with hacks and exploits that followed hard on the heels of new technical hype cycles — DeFi protocols, bridges, NFT marketplaces — and the addition of AI agents with wallet access appears to be simply the latest frontier for attackers to probe.

Security researchers have long cautioned that combining large language models, which can be manipulated through carefully crafted inputs, with systems that move real money is a combination that demands far more rigorous testing than the industry has so far shown appetite for.

Then there is the sheer commercial strangeness of the AI-crypto convergence. Among the products making the rounds is “Gudtrip,” described in coverage as an AI agent vape pen built with blockchain technology — a mash-up that manages to combine three separate hype cycles (AI, crypto, and vaping) into a single device.

It’s the kind of product that invites eye-rolls even from people steeped in the industry, and it has become something of a symbol for critics who argue that “blockchain” and “AI agent” are increasingly being slapped onto unrelated consumer goods simply because the buzzwords still move product.

Advertisement

Labor practices are also getting the AI-crypto treatment. Reports have surfaced of AI companies experimenting with paying staff in AI-linked tokens rather than conventional money — an arrangement that echoes crypto’s long history of compensating workers and contractors in volatile, illiquid tokens instead of cash. Critics have been quick to note the obvious problem: a token’s value depends entirely on continued enthusiasm for the company issuing it, leaving employees exposed to exactly the kind of speculative risk that traditional salaries are designed to avoid. The practice, if it spreads, would import one of crypto’s more employee-unfriendly habits directly into the AI industry’s compensation structures.

Not everyone covering this convergence is doing so with a straight face. A satirical piece making the rounds — structured as a twist on the old “two cows” economics joke — skewered the fintech, AI, blockchain and crypto sectors in one go, imagining a “crypto” cow story where two digital cows produce “milk tokens” tradeable for millions but drinkable only by avatars in the metaverse, and a “hedge fund” version featuring robotic cows that befriend real cows just to steal their milk.

Silly as the format is, the satire lands because it captures something real: a sense among observers that these overlapping industries have become adept at generating elaborate financial and technical narratives that produce headlines and valuations long before they produce anything resembling durable value.

Taken together, these threads — political spending mirroring crypto’s playbook, an AI wallet hacked via prompt injection, blockchain-branded vape pens, token-based salaries, and no shortage of pointed satire — paint a picture of an industry moment defined less by a single breakthrough than by rapid, sometimes reckless, cross-pollination.

Advertisement

Crypto spent the better part of a decade building the infrastructure, the political machinery and the marketing instincts for turning speculative technology into cultural and financial weight. Now AI companies appear to be absorbing many of the same instincts, for better or worse, at a pace that leaves regulators, security researchers and workers alike scrambling to keep up.

Editor’s note: Much of the reporting referenced above originates from commentary and short-form blog coverage rather than in-depth investigative reporting, and some details — such as the specific financial scale of AI super-PAC spending or the full technical mechanics of the Grok wallet exploit — were not independently verifiable from the available material. Readers should treat figures and claims here as preliminary pending fuller reporting.


 


 

Advertisement
Continue Reading

Crypto

Nearly half the stocks in the S&P 500 are at cross purposes with the rest of the market

Published

on

Nearly half the stocks in the S&P 500 are at cross purposes with the rest of the market

U.S. oil drilling site.

David McNew | Getty Images

Nearly half of the stocks in the S&P 500 are moving against the index with a negative beta, an unusual divergence that is becoming increasingly difficult to ignore.

About 45% of S&P 500 stocks have a negative three-month beta, according to a recent note from Goldman Sachs. The data closely aligns with CNBC’s finding that nearly 40% of S&P 500 stocks had a negative three-month beta versus the index, while 17% have a negative one-year beta, based on weekly returns.

Advertisement

Beta measures how a stock moves relative to the rest of the market. A negative beta means an individual stock’s returns moved in the opposite direction of the S&P 500 over the measured period.

The surge in stocks with a negative beta dovetails with other unusual market signals. The S&P rallied 1.5% last Monday. The same day 30 stocks touched a 52-week low while just 7 scored a new high. The last time the S&P 500 gained at least 1% while sitting within 1% of a new 52-week high and new lows outnumbered new highs was in December 1999, right before the very top of the dot-com boom, according to Jason Goepfert, founder of SentimenTrader.

The two indicators show that market indexes can remain at or close to records despite wide divergences among individual stocks.

Widening divide

The yawning gap largely reflects how concentrated the S&P 500 has become, according to Adam Turnquist, chief technical strategist at LPL Financial.

Advertisement

Mega-cap technology companies carry an outsized weight in the benchmark, meaning a strong performance from a small number of stocks can drive the index even when many others are moving the other way.

“It only takes a few of those mega caps names to work, and a lot of the smaller weighted stocks don’t need to work,” Turnquist told CNBC, pointing to unusually low correlations among S&P 500 stocks.

The same dynamic explains why the broader index can look relatively calm even when individual stocks are making large moves, said Bradley Krom, director of investing strategy at WisdomTree.

“Beta is a function of correlation and volatility,” Krom said. When stocks experience large moves at different times and for different reasons, those moves can largely offset one another at the index level.

Advertisement

In July this year, Alliance Bernstein, using one-year trailing returns, found an unprecedented share of U.S. stocks displaying negative beta as AI winners powered market gains.

Semiconductor makers, hardware companies and other AI infrastructure beneficiaries have benefited from enormous capital spending, while companies outside the AI trade have struggled to keep up.

“But a narrow market can also distort the signal investors receive from index returns. When a handful of companies dominate performance, many financially sound businesses may lag or even decline, simply because they aren’t tied directly to the most powerful market narrative,” wrote Kurt Feuerman, chief investment officer of Select U.S. Equity Portfolios at AllianceBernstein.

Negative energy

Energy stocks with negative beta are being driven by different forces.

Advertisement

“Another part of the other story is energy. That’s been pronounced this year: higher oil prices, higher energy stocks and then the rest of the market trades lower,” said Turnquist, seeing energy as an important part of the negative-beta story, alongside more defensive sectors.

Earlier this month, Evercore ISI used a six-month measure to call out 115 S&P 500 stocks with negative beta, a list skewed toward energy, utilities and consumer staples. The investment bank called the energy sector a “synthetic S&P 500 put option” because of the way it has reacted to geopolitical pressure.

If market leadership broadens out, Turnquist believes the number of negative-beta stocks could decline. But he expects dispersion to remain elevated as investors become remain selective toward beneficiaries of AI spending and seek returns there.

Krom at WisdomTree expects the recent extreme readings to eventually revert to the mean. Similar spikes appeared around the 1999-2000 dot-com bubble, he said, when market concentration and large moves in a narrow group of stocks also triggered unusual divergences.

Advertisement

Turnquist pushed back on comparing today with the dot-com era, leading tech companies now are more mature businesses with established revenue and products. Krom is on the same page. He said the individual pieces driving returns don’t have the same historical relationship they’ve had in the past.

“It is not the same market environment now versus 2000,” Krom said. The negative betas seen today boil “down to the amount of market concentration.”



Source link

Continue Reading

Crypto

Crypto’s Quiet Mainstreaming: From Wall Street Trading Desks to Weeknight Spending Habits

Published

on

Cryptocurrency no longer lives only in trading app screenshots and speculative headlines. A cluster of recent coverage suggests digital assets have settled into three very different corners of everyday life at once: the boardrooms of family offices moving nine-figure sums, the phones of ordinary Britons paying for a night out, and a growing ecosystem of explainer sites trying to make sense of it all for newcomers. Taken together, they paint a picture of an asset class that has stopped trying to prove itself and started simply getting used.

At the top end of the market, the mechanics of moving serious money in crypto increasingly mirror what has long happened on Wall Street. Selling a large position on the open market is a blunt instrument — dump a $20 million order into a standard exchange and the price can slide five to ten percent against you before the trade even completes, as algorithms and bots react to the visible order book.

High-net-worth investors and family offices have borrowed a page from traditional equities to avoid that problem, leaning on block trades negotiated privately between two parties and reported only after execution, dark pools where institutional orders are matched away from public view, and OTC desks that lock in a price before a trade ever touches the open market.

None of these tools are new in spirit — block trading dates back to the 1960s, and banks such as Credit Suisse pioneered dark-pool venues in the mid-2000s — but their extension into crypto shows how thoroughly digital assets have been absorbed into the plumbing of institutional finance, complete with all its discretion and negotiated pricing.

Further down the market, the story is less about avoiding slippage and more about convenience. A growing share of everyday spenders now treat crypto the way they treat a contactless card — something to tap and forget.

Much of that shift traces back to apps like Revolut, which began as a travel card and has since folded budgeting tools, instant transfers and built-in crypto purchases into a single interface. For users already comfortable buying fractions of Bitcoin or Ethereum on their phone, spending a small slice of a holding online no longer feels like a leap. Recent Pew Research figures cited in industry coverage suggest roughly one in five adults have used cryptocurrency in some form, evidence of just how far the technology has travelled from niche forums into ordinary financial habits. Faster networks and pound- or dollar-pegged stablecoins have also softened the volatility fears that once made spending crypto feel reckless.

That spending habit has, in turn, fed into digital entertainment, where a wave of offshore-licensed sites — often based in Malta, Curaçao or Gibraltar — have built their appeal specifically around crypto and app-based payments such as Revolut, alongside larger game libraries and bigger sign-up bonuses.

These platforms sit outside the UK’s domestic licensing system, which is precisely the draw for some users, including those who have self-excluded through Gamstop. The logic mirrors a broader pattern researchers have tracked in crypto adoption more generally: users start on a single centralised platform for convenience, then gradually spread activity across multiple services and self-custodied wallets as they grow more comfortable, seeking flexibility rather than a single gatekeeper. It’s worth being clear-eyed about what this means in practice — these offshore sites operate under lighter regulatory oversight than UK-licensed operators, and readers weighing them should treat player-protection tools and responsible-gambling warnings as essential reading, not fine print to skip.

Feeding all of this is a parallel boom in explainer content trying to translate crypto’s jargon — DeFi, staking, tokenomics, smart contracts — into plain English. Sites such as RobTheCoins.com have positioned themselves as educational hubs rather than exchanges or wallets, publishing guides on blockchain business models, crypto tax tools and the overlap between gaming and crypto economies.

That distinction matters, because the line between “content that explains crypto” and “a product that handles your money” is not always obvious to a casual reader, and confusing the two is exactly the kind of mistake that has burned newcomers before.

None of this amounts to a single dramatic headline. There is no exchange collapse or regulatory crackdown driving this particular news cycle. Instead, what emerges is a quieter, arguably more consequential trend: crypto is being absorbed into the ordinary architecture of modern finance and leisure, from the trading desks of the ultra-wealthy down to a tap-to-pay night out.

Whether that mainstreaming is entirely healthy is a separate question. Institutional tools like dark pools and OTC desks still lack the transparency of public markets, offshore gambling platforms carry real consumer-protection gaps, and no amount of friendly explainer content changes the fact that crypto remains a volatile, largely unregulated asset in most jurisdictions.

Readers tempted by any part of this ecosystem — whether it’s a block-trading conversation or a crypto-funded casino account — would do well to verify claims independently, check who is actually regulated, and remember that accessibility is not the same thing as same thing as safety.

Continue Reading

Crypto

Convicted cybercriminal arrested in connection with ShinyHunters group

Published

on

Convicted cybercriminal arrested in connection with ShinyHunters group

A 24-year-old convicted cybercriminal was arrested in the Netherlands on September 16 on suspicion of aiding crypto hacking collective ShinyHunters.

Krebsonsecurity reports that Pepijn van der Stap was detained by Dutch authorities for questioning in relation to ShinyHunters. 

Police claim he’ll appear in the Rotterdam District Court on September 29, while local news reports the United States is also involved in his case.

Over three years ago, van der Stap carried out multiple acts of data theft and extortion under the moniker “Umbreon.”

Advertisement

Read more: Crypto hacking group ShinyHunters says it stole data of 5,000 FBI agents

Van der Stap was eventually arrested, convicted, and handed a four-year suspended sentence. He was released in December 2025.  

While carrying out his criminal activities, he worked at cybersecurity startup Hadrian and volunteered at the nonprofit Dutch Institute for Vulnerability Disclosure.

Advertisement

He’s currently the offensive security lead at Neo Security, and described himself to Krebsonsecurity as a reformed convict. 

ShinyHunters attacked FBI days after van der Stap’s arrest

Just six days after van der Stap’s arrest, ShinyHunters claimed responsibility for hacking and stealing the data of 5,000 FBI agents. 

This attack also manipulated the FBI’s job page to display a picture of the Pokémon Umbreon.

Krebsonsecurity reports that the attack represented a shift in ShinyHunters’ usual attacks while the group is under the leadership of a teenager based in Amman, Jordan, who goes by the nickname “Rey.”

Advertisement

Rey reportedly merged the group with fellow hacking groups Scattered Spider and LAPSUS$ to become ScatteredLapsussHunters.

Read more: Crypto hackers target Hinge and Match Group in data leak

Sources close to the ShinyHunters investigation told the publication that Rey had “ongoing beef” with van der Stap, and that Umbreon’s inclusion was possibly an attempt by Rey to shift blame towards van der Stap.

ShinyHunters has also been linked to the hacking of the Netherlands telecommunications provider Odido last February. 

Advertisement

Personal data, including bank account and passport numbers, of six million Odido customers were leaked.

Got a tip? Send us an email securely via Protos Leaks. For more informed news and investigations, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.




Source link

Continue Reading

Crypto

Strategy buys 1,665 BTC and repurchases $152M STRC

Published

on

what it means for BTC

Strategy has acquired another 1,665 BTC for approximately $142.7 million while spending $151.7 million to repurchase STRC preferred shares during the week ended Sept. 27.

Summary

  • Strategy bought 1,665 BTC for $142.7 million, lifting total Bitcoin holdings to 847,666 coins overall.
  • Strategy repurchased 1,534,530 STRC shares for $151.7 million during the September 21 to 27 period.
  • MSTR sales generated $246.2 million net proceeds, with no preferred shares issued during the week.
  • Strategy held $5.02 billion in USD Reserve and $1.00 billion in deployable USD Cash overall.
  • Bitcoin holdings cost $63.95 billion in aggregate, averaging $75,437 per coin including fees and expenses.

Strategy disclosed the transactions in a Sept. 28 Form 8-K, showing that the company paid an average of $85,681 per BTC, including fees and expenses, between Sept. 21 and Sept. 27. The purchase lifted its Bitcoin holdings to 847,666 BTC.

During the same period, Strategy sold 1,469,165 MSTR shares through its at-the-market program, generating $246.2 million in net proceeds. Of that amount, $142.7 million funded the Bitcoin purchases and $103.5 million went toward STRC repurchases.

The company issued no STRF, STRC, STRK or STRD preferred shares through its ATM programs during the week.

Advertisement

Strategy Bitcoin holdings reach 847,666 BTC

Following the latest purchase, Strategy held 847,666 BTC acquired for an aggregate $63.95 billion. Its average acquisition cost stood at $75,437 per BTC, including fees and expenses.

The latest addition follows Strategy’s 950 BTC purchase after a two-week buying pause reported for the previous week. The company spent $75.7 million on that acquisition at an average price of $79,670 per BTC, increasing holdings at the time to 846,000 BTC.

Strategy’s new $85,681 average purchase price for the Sept. 21-27 period was above Bitcoin’s latest market price. CoinGecko shows BTC trading near $83,401 at the latest reading, around 2.7% below Strategy’s average price for the latest purchase.

At that market price, Strategy’s 847,666 BTC position would be worth roughly $70.7 billion. The calculation uses a live market price and therefore differs from the company’s recorded acquisition cost.

Advertisement

STRC repurchases reach another $151.7 million

Alongside the Bitcoin acquisition, Strategy repurchased 1,534,530 shares of its Variable Rate Series A Perpetual Stretch Preferred Stock, or STRC, for approximately $151.7 million.

The latest transaction continues a repurchase program that Strategy began earlier in 2026. After the latest week, $723.5 million of authorization remained under its digital credit securities repurchase program, according to the filing.

Strategy’s previous $174 million STRC repurchase came during the Sept. 14-20 period, when the company spent more on preferred-stock repurchases than on its $75.7 million Bitcoin purchase.

Earlier in September, Strategy doubled its digital credit securities repurchase authorization to $2 billion after spending $176.3 million on STRC during a week when it bought no Bitcoin.

Advertisement

Strategy said in July that it intends to repurchase STRC while the preferred stock trades below its $100 stated amount, subject to market conditions, liquidity and other capital priorities.

MSTR sales funded both transactions

Strategy financed the latest Bitcoin purchase and part of the STRC repurchase through MSTR common-stock sales.

The company raised $246.2 million in net proceeds by selling 1,469,165 MSTR shares between Sept. 21 and Sept. 27. The filing assigns $142.7 million of those proceeds to Bitcoin purchases and $103.5 million to STRC buybacks.

A further $48.1 million of the STRC repurchase came from Strategy’s USD Cash balance. Over the same period, the company used $22.1 million from its separate USD Reserve to pay preferred-stock dividends.

Advertisement

Strategy reported $18.84 billion of additional MSTR issuance capacity under its ATM program as of Sept. 27. No preferred shares were sold during the latest reporting period.

The latest funding structure differs from the previous week, when Strategy made no ATM stock sales and used existing cash to fund its Bitcoin purchase and STRC repurchases.

Strategy keeps $6.02 billion in dollar assets

Strategy ended Sept. 27 with a $5.02 billion USD Reserve and $1.00 billion in USD Cash, giving the company a combined $6.02 billion across the two balances.

The company defines the USD Reserve as capital designated to support preferred-stock dividends and interest payments on outstanding debt. USD Cash is maintained separately for Bitcoin purchases, reserve additions, capital management and other treasury uses.

Advertisement

The cash framework has changed materially since July, when Strategy built a $3.75 billion reserve while Bitcoin buying remained paused.

Strategy’s board expanded its STRC repurchase program during September while continuing to manage Bitcoin purchases, common-stock issuance and preferred-stock obligations through separate pools of capital.

As of Sept. 27, the company still had $723.5 million available under its digital credit securities repurchase authorization and $1 billion available under its separate MSTR common-stock repurchase program.



Source link

Advertisement

Continue Reading

Crypto

Tether says it helped freeze $550M in Iran-linked USDT

Published

on

Tether's American twin grew 540%. It is still 0.08%

Tether has said it helped freeze nearly $550 million in Iran-linked USDT this year as U.S. authorities targeted wallets tied to the Central Bank of Iran and other sanctioned networks.

Summary

  • Tether said more than $344 million was frozen across two addresses in April.
  • A July action froze more than $130 million across four additional TRON wallets.
  • The U.S. Treasury has named digital assets among five sectors covered by expanded Iran sanctions.
  • Tether said its law enforcement work has helped freeze more than $4.9 billion globally.

Tether said on Sep. 28 that it acted on information from the Treasury Department’s Office of Foreign Assets Control and U.S. law enforcement when more than $344 million in USDT was frozen across two addresses in April. OFAC added the same addresses to the Central Bank of Iran’s sanctions entry the following day. The entry also identifies links to the Islamic Revolutionary Guard Corps-Qods Force and Hezbollah.

In July, more than $130 million was frozen across four other wallets as Treasury added four TRON addresses to the central bank’s designation. Tether put its total for Iran-linked USDT freezes in 2026 at approximately $550 million. Its announcement gave the amounts for the April and July actions but did not itemize every freeze included in that total.

The July action was previously covered by crypto.news, which reported that the four TRON wallets held about $131 million in USDT. Treasury Secretary Scott Bessent said at the time that OFAC had sanctioned multiple wallets tied to Iran’s central bank.

Advertisement

Tether froze two wallets before OFAC listed them

The order of the April steps is central to Tether’s account. According to the company, it supported the freeze after U.S. authorities supplied information about the two addresses; OFAC then formally listed those addresses as digital currency identifiers for the Central Bank of Iran.

Earlier reporting on the April $344 million freeze identified roughly $213 million in one TRON wallet and $131 million in another. The restrictions applied to the USDT held at the addresses. They did not require the TRON network itself to stop processing transactions.

Tether CEO Paolo Ardoino said public blockchains let authorities follow fund movements and that the company can act when law enforcement provides credible information. He described USDT as “not a haven for sanctioned actors, terrorist organizations or criminal networks.” His statement sets out the company’s position; the wallet designations and freeze amounts are separate actions reported by OFAC and Tether.

The issuer said it has aligned its freezing policy with OFAC’s Specially Designated Nationals list, including listed wallets that hold USDT after its initial issuance. A freeze prevents tokens at a blocked address from moving. It is distinct from a government seizure or a court order transferring ownership of the assets.

Advertisement

Treasury has expanded Iran sanctions to digital assets

Treasury launched Operation Economic Outcast on Aug. 24 and named digital assets alongside technology, gold, aviation and shipping in five new sectoral sanctions determinations. The department said the measures expanded its authority to target foreign people and companies operating in or supporting those sectors of Iran’s economy.

For U.S. businesses and individuals, OFAC designations carry direct transaction restrictions when a listed party or its blocked property is involved, unless an exemption or license applies. Treasury has also warned foreign firms about possible sanctions exposure for facilitating Iranian sanctions evasion. Those are Treasury’s stated rules and warnings, rather than a new restriction created by Tether’s announcement.

On Sep. 17, OFAC designated Iranian digital asset venture BitBank, its software developer, and three associates of financier Babak Zanjani under the campaign. Treasury alleged that Zanjani’s network used digital asset businesses to move funds for the IRGC, including hundreds of millions of dollars in Bitcoin. The BitBank sanctions action also placed the developer, Pishtaz Simorgh Electronic Trade Company, on OFAC’s list.

A separate U.S. civil case shows how a wallet freeze can precede an effort to take custody of tokens. In September, prosecutors sought forfeiture of $61.2 million in USDT held across ten TRON addresses that court filings said Tether had frozen in 2025. A Sep. 14 warrant authorized the FBI to take custody of the targeted assets; the forfeiture complaint asks a court to award ownership to the government. That case concerns alleged Iranian oil proceeds and is separate from Tether’s stated 2026 freeze total.

Advertisement

Earlier Iran-linked wallets and U.S. cases add context

Tether also cited work with Israel’s National Bureau for Counter Terror Financing. It said the bureau has referred more than 40 cases involving over 640 addresses, resulting in freezes of more than 22 million USDT. In 2023, the company disclosed a freeze of 32 addresses holding $873,118.34 in a case involving illicit activity affecting Israel and Ukraine.

After the Israeli bureau published a list of 187 addresses it associated with the IRGC in September 2025, blockchain analytics firm Elliptic reported that Tether had blacklisted 39 of them. Approximately $1.5 million in USDT remained in those wallets when they were frozen, according to Tether’s account of Elliptic’s findings.

Across its law enforcement work, Tether said it cooperates with more than 340 agencies in 67 countries and that the efforts have helped freeze over $4.9 billion in assets, including more than $2.4 billion connected to U.S. authorities. The body of its announcement states more than 2,800 investigations globally and more than 1,500 involving U.S. law enforcement, while its page subtitle gives higher figures of more than 2,900 and more than 1,600, respectively.

Among the U.S. cases the company cited was a September Justice Department operation against a marketplace serving scam centers. Tether said authorities restrained more than $52 million in one day and that the department acknowledged its assistance. It also cited a February seizure of more than $61 million in USDT tied to an alleged investment fraud operation, in which the Justice Department and Homeland Security Investigations acknowledged its help transferring the assets.

Advertisement



Source link

Continue Reading

Trending

Copyright © 2025