Connect with us

Crypto World

21 Financial Institutions Commit to Joint Stablecoin Venture

Published

on

21 Financial Institutions Commit to Joint Stablecoin Venture


Twenty-one banks and asset managers said Tuesday they will set up a jointly backed company in the second half of this year to issue a US dollar stablecoin, aiming for a market launch in the first half of 2027 and later expansion into other G7 currencies, starting with the euro. Almost eleven months… Read the full story at The Defiant

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

Backpack Adds Micron and SanDisk Shares as Margin Collateral

Published

on

Backpack Adds Micron and SanDisk Shares as Margin Collateral


Backpack says users can now post Micron and SanDisk shares as collateral in a unified portfolio-margin account spanning stocks, crypto and other instruments, expanding the role of equities on its platform beyond buying and selling them. The exchange said stock holdings can support U.S. dollar… Read the full story at The Defiant

Source link

Continue Reading

Crypto World

Securitize Will Issue Socios' Tokenized Sports Team Equity

Published

on

Securitize’s Tokenized Assets Hit $4.3 Billion as Revenue Falls


Securitize will handle regulated securities issuance, investor onboarding and ownership records for Socios.com’s plan to sell tokenized minority stakes in professional sports teams, the two companies said Wednesday. The partnership supplies a licensed issuer for the product Socios’ parent announced… Read the full story at The Defiant

Source link

Continue Reading

Crypto World

Revolut Confirms Fake Government Email Pulled Passports and Bitcoin Records: Who Sent It?

Published

on

Revolut Reportedly Handed Over Passports, Bitcoin Records After Fake Government Request

Revolut has confirmed to BeInCrypto that someone did actually trick it into handing over customer files, which its own notices say held passports, selfies, and Bitcoin records. The company calls it a sophisticated attack. What it describes is an email.

The message arrived from a real government agency’s email domain. It carried genuine domain credentials. Revolut accepted it as authentic and sent the files.

What Revolut Says Happened

A Revolut spokesperson told BeInCrypto the bank blocked the sender as soon as it spotted the problem.

“Revolut recently identified a sophisticated external impersonation attack where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information… Revolut systems and customer funds are unaffected.”

Follow us on X to get the latest news as it happens

Advertisement

The company says it alerted the agency, the police, and its data protection and financial regulators. It has contacted what it calls the limited number of people affected.

The Part the Statement Leaves Out

Revolut says accounts remain secure. That is true, and it is not the problem.

Passcodes, login details, and biometric data were never exposed, the bank told BeInCrypto. No money moved.

The notices sent to customers put it differently. They say the verification selfie went out, and rule out only biometric facial telemetry, meaning the face template a system builds from a photo. The photo itself is another matter.

Advertisement

Those notices list the rest. Passports. Driving licences. Home addresses. Bank statements. A full record of Bitcoin going in and out.

Revolut Reportedly Handed Over Passports, Bitcoin Records After Fake Government Request
Revolut Handed Over Passports, Bitcoin Records After Fake Government Request. Source: ZachXBT

A password takes a minute to change. A passport does not.

Revolut will not say which agency’s domain was used, citing the live police investigation. So nobody outside the company knows whether a government mailbox was hijacked, or whether someone already inside it pressed send.

Blockchain investigator ZachXBT, who traces stolen crypto for a living, flagged the leak, highlighting that it reached a small group of users and looked aimed at wealthy ones.

Stolen customer lists have fed phishing risk after breaches. Leaked home addresses have come before violent attacks on holders.

There is a second way to read the word sophisticated. By Revolut’s own account, the attacker wrote an email and waited. The clever part happened inside a government mail system. The costly part happened inside Revolut.

The post Revolut Confirms Fake Government Email Pulled Passports and Bitcoin Records: Who Sent It? appeared first on BeInCrypto.

Advertisement

Source link

Continue Reading

Crypto World

Uniswap targets arbitrage value with new v4 hook

Published

on

Uniswap V4 leads tokenized stocks with $59M TVL

Uniswap Labs has launched StablePair Hook with two Ethereum pools after stablecoin swaps on Uniswap reached $43.4 billion during the second quarter.

Summary

  • Uniswap Labs has launched StablePair Hook with USDC/USDT and USDC/USDG pools on Ethereum mainnet initially.
  • The hook calculates liquidity provider fees from price distance and each swap’s trading direction automatically.
  • Corrective swaps outside the configured band face fees that decline with every new block thereafter.
  • OpenZeppelin found one high-severity issue during review and Uniswap says the flaw was fixed later.
  • Governance can update fee settings and implementation code without requiring liquidity providers to migrate pools.

Uniswap Labs said on Sept. 10 that the Uniswap v4 tool replaces a static liquidity provider fee with a fee calculated for every swap. The first pools pair USDC with USDT and Global Dollar, or USDG.

Both pools use a reference rate of 1:1. The system measures how far the pool price has moved from that rate and whether a proposed transaction pushes the price closer to or farther from it.

Advertisement

The company says the mechanism gives liquidity providers a larger share of the value generated when traders correct price differences. StablePair Hook does not guarantee better returns, since results still depend on trading activity, liquidity depth, asset prices and the parameters approved for each pool.

StablePair Hook changes fees with pool conditions

Stablecoin pools usually contain assets designed to maintain the same dollar value. Market activity can still move a pool away from parity, creating an opportunity for arbitrageurs to trade against the price difference.

With a fixed fee, Uniswap Labs says pool operators face a trade-off. A low fee may allow arbitrage bots to retain more of the available price difference, while a high fee may discourage ordinary transactions.

Advertisement

StablePair Hook changes the fee according to the pool’s position relative to a configured reference price. Inside a narrow band around that price, the mechanism adjusts fees to maintain a fixed spread between quoted buying and selling prices.

Once the pool leaves the band, the treatment depends on the direction of the next swap. A transaction that moves the pool farther from the reference rate pays no liquidity provider fee because it gives the pool what Uniswap describes as a favorable price.

A swap bringing the pool back toward parity enters a Dutch auction. Its fee begins at a high level and falls with each Ethereum block until a trader accepts the available price.

“LPs keep the difference,” Uniswap Labs said when describing the auction system. The statement expresses the developer’s expected outcome for liquidity providers, not a guaranteed level of fee income.

Advertisement

Two Uniswap stablecoin pools are operating on Ethereum

Uniswap’s public code repository records the USDC/USDT and USDC/USDG pools as initialized on Ethereum on Sept. 10. Both use the dynamic-fee flag and a tick spacing of one.

The USDC/USDT pool has an onchain identifier ending in e39f634, while the USDC/USDG pool identifier ends in b7edb. Uniswap’s developer materials advise applications to derive pool identifiers from their pool keys instead of hard-coding them.

At the contract level, StablePair Hook operates through an ERC-1967 proxy. Its permanent Ethereum hook address encodes the permissions available to the contract, while governance can replace the implementation behind the proxy.

Pool fee configurations and future implementation upgrades are controlled by the Uniswap Governance Timelock, according to the project’s repository. A separate Uniswap Labs multisignature wallet can create pools and assign their initial fee parameters but cannot upgrade the contract or modify existing configurations.

Advertisement

StablePair pools cannot be created permissionlessly. Uniswap Labs controls their initial creation, distinguishing the product from v4 pools that any user can initialize without prior approval.

The launch extends Uniswap v4’s use of custom hooks, which attach external contracts to pools and change their behavior at defined points in a transaction. Hooks can control fees, pricing logic and access rules without changing the v4 core contracts.

In related coverage, Uniswap v4 became the largest DeFi venue for tokenized-stock deposits after its measured total reached $59.1 million in early September. StablePair Hook applies the same customizable pool architecture to assets expected to trade near an established exchange rate.

An OpenZeppelin review found and fixed a fee issue

OpenZeppelin reviewed the core StablePair fee mechanism from Feb. 9 through Feb. 13, according to Uniswap’s security documentation. The assessment covered a non-upgradeable predecessor that uses the same main fee calculations.

Advertisement

During the review, OpenZeppelin identified one high-severity issue involving corrective swaps. A trader could obtain a cheaper combined price by dividing one corrective transaction into several smaller swaps.

Uniswap says it addressed the finding by caching the pool price once per block. Every swap within the same block uses the cached starting price when calculating its fee, removing the fee advantage previously available from splitting a transaction.

The review did not cover the current upgrade system or its role structure because those components were introduced later. Uniswap’s published security page identifies the scope difference, meaning the cited audit should not be treated as a full assessment of every component in the live version.

Price caching creates two documented limitations. Later swaps during a busy block may use a starting price that no longer matches the pool’s latest price, while a swap crossing the reference rate can invert fee directions for the rest of the block.

Advertisement

Uniswap says both conditions last for one block and correct themselves when the next cached price is recorded. The documentation states that removing either limitation would restore the transaction-splitting opportunity addressed after the OpenZeppelin review.

Governance controls future StablePair Hook upgrades

Uniswap Governance can modify pool fee settings and replace the hook’s implementation without moving liquidity into a different pool. A configuration change resets the fee-decay process, causing the following swap to use a fresh pool-price reading.

Permissions embedded in the permanent hook address limit what an upgrade can do. Uniswap says the contract cannot prevent liquidity providers from withdrawing assets or change swap amounts to collect unapproved fees because the required callback permissions are disabled.

Quote calculations carry separate limits. The hook’s getFee function returns the current liquidity provider fee using the same start-of-block price that the next transaction will receive. It excludes protocol fees, ignores the size of the trade and does not calculate the price effect caused by moving through available liquidity.

Advertisement

Large trades may therefore execute at a different average price from the initial quote. The difference depends on the depth and distribution of liquidity in the pool, according to the project’s technical documentation.

StablePair Hook joins other custom tools developed for Uniswap v4, including DualPool, LitePSM and Permissioned Pools. As previously reported, Uniswap’s work on correlated tokenized-asset pools processed $33 million across 10 stock-to-SPY markets during their first 12 days.

Uniswap Labs has released the hook’s contracts and tests through its public GitHub repository under an MIT license. Its developer documentation lists the mainnet proxy address, current implementation address, two pool identifiers and a security contact for reporting contract issues.

Advertisement

Source link

Continue Reading

Crypto World

Which is right for you?

Published

on

Which is right for you?

Debt consolidation combines multiple debts into one loan, usually at a lower interest rate, and you repay the full balance. Debt settlement involves negotiating with creditors to pay less than you owe, but it damages your credit and isn’t guaranteed to work.

Understanding how both options work can help you determine which would better fit your financial situation. 

Debt consolidation involves replacing your current debts with a new loan or line of credit, ideally with a better interest rate. If you consolidate multiple debts, you can also simplify repayment into a single monthly payment. 

There are multiple ways to consolidate debt, including: 

  • Personal loan: You can use a personal loan to pay off existing debts, such as credit card balances, medical bills, or other loans. Then, you’ll pay back your personal loan with fixed monthly payments over a set term, typically one to seven years. Some personal loan providers will send the loan funds directly to your creditors on your behalf. 

  • Balance transfer credit card: If you have credit card debt, you could consolidate it with a balance transfer credit card. Some cards offer promotional periods of 0% APR for balance transfers, so you can focus on paying down your balance for a time without interest. You’ll still have to pay a balance transfer fee — usually 3% to 5% of the amount you transfer. 

  • Home equity loan or HELOC: Homeowners can draw on their property’s equity and consolidate debt with a home equity loan or home equity line of credit (HELOC). Home equity loans and HELOCs can have competitive interest rates and lengthy repayment terms. Since they’re secured by your home, though, you run the risk of foreclosure if you overborrow and can’t repay. 

You usually need fair credit or better to qualify for debt consolidation. The stronger your credit, the better interest rates you can get on a personal loan, home equity loan, or HELOC. Good or excellent credit is also usually required to qualify for a balance-transfer credit card. 

Personal loans and balance transfer cards are unsecured, so you don’t have to put up collateral. Home equity loans and HELOCs, on the other hand, are secured by your home. Make sure you have a clear sense of borrowing costs and a repayment plan before borrowing against your home. 

Advertisement

One of the main goals of consolidating debt is to qualify for a lower interest rate. A better rate can significantly reduce your borrowing costs and decrease your monthly payments. 

The average interest rate on credit cards is about 21%, according to May 2026 Federal Reserve data, while the average rate on a two-year personal loan is 11.86%. If you could cut your rate in half, you could save hundreds or thousands of dollars on your debt. 

At the same time, your repayment term also affects your interest costs. A shorter term would lower your overall interest costs, simply because you’re paying off your debt faster. A long loan term will result in paying more interest over the life of your loan. 

Before you consolidate, compare factors such as interest rates, repayment terms, monthly payments, and fees to understand exactly how much consolidation would save (or cost) you in the long run. 

Advertisement

Debt settlement involves negotiating with your creditors to pay off your debt for less than the full amount you owe. It’s often considered a last-resort tactic if you’re overwhelmed by debt.

You can try negotiating a debt settlement on your own, or you could work with a debt settlement company. These companies negotiate with your creditors on your behalf, in exchange for fees that may cost up to 25% of your debt amount.

When you pursue debt settlement, you usually stop paying your debts for a period of time. Stopping payments may encourage your creditors to negotiate, but it will also result in additional interest charges, late fees, and damage to your credit. 

During this time, you’ll set aside savings for the settlement amount. You (or a debt settlement company) will work with your creditors to see if they’re willing to resolve the debt for less than you owe. If you can agree on an amount, you’ll make a final payment to the creditor and the remaining debt will be forgiven.   

Advertisement

There’s no guarantee of success, and the entire process can take two or four years. But some creditors may agree to a settlement since a lower payment is better than no payment at all. 

Debt consolidation may initially ding your credit score when you apply for a new loan or credit card, but the decrease should be minimal. You could see your credit improve over time as you make on-time payments on your loan or line of credit. 

Debt settlement, on the other hand, can damage your credit score when you stop making payments on your debts. Your payment history makes up the largest portion of your credit score, and consistent missed payments can seriously tank your credit for years.

Depending on the type of credit you use to consolidate debt, you may have to pay an origination fee or balance transfer fee. Borrowers with good or excellent credit may qualify for a personal loan with no origination fees. 

Advertisement

Depending on your state, debt settlement companies can charge hefty fees of 15% to 25% of your enrolled debt. Make sure you understand the fees before you hire a service. 

If a company isn’t transparent about its fees, you may be dealing with a debt settlement scam. Be cautious about sharing any sensitive information until you’re 100% confident you’re working with a reputable company. 

Debt settlement can also lead to a tax bill. The IRS taxes any forgiven debt over $600. If you settle a $10,000 debt for $8,000, you’ll owe taxes on the $2,000 that was forgiven. And if your creditor refuses a debt settlement, you’ll face a larger debt due to added interest charges and late fees. 

You can choose your timeline when consolidating debt. Personal loans often have repayment terms of one to seven years, while home equity loans or HELOCs may span up to 20 or 30 years. 

Advertisement

Credit cards let you roll over your debt from month to month as long as you make minimum payments, but carrying a balance can rack up interest charges. If you use a 0% APR balance transfer card, aim to pay off as much of your balance as possible before the promotional period ends. 

As for debt settlement, the process can be lengthy, taking two to four years. It takes a while to save up a settlement amount, and it’s tough to predict how long the negotiation process will take before coming to an agreement with your creditor. 

The main downside of consolidating debt is that you may have trouble qualifying if your credit score is too low. It can also backfire if you keep accumulating debt after you consolidate your old balances. 

Debt settlement has more serious risks, including damage to your credit, calls from debt collectors, and no guarantee of success. Your lender could even decide to sue you for nonpayment of your debt. 

Advertisement

Debt consolidation and debt settlement usually apply to very different financial situations. 

Debt consolidation is usually a better fit if: 

  • You have fair, good, or excellent credit 

  • You want to simplify repayment and make your debt payoff easier to track

  • You’re struggling with high interest rates 

  • You can afford the monthly payments on your debt 

Debt settlement may be worth considering if: 

  • You can’t afford your monthly payments or have already fallen behind 

  • You don’t have strong enough credit to qualify for debt consolidation 

  • You’re dealing with collections or lawsuits 

  • You’re at risk of bankruptcy 

  • You understand your credit score will likely be damaged 

Debt settlement is a form of debt relief for borrowers experiencing financial hardship. It has some major downsides, but it can reduce the amount you owe and help you avoid bankruptcy. 

Advertisement

Consolidating your debts, however, can be a savvy way to simplify repayment and save money on interest. Anyone carrying high-interest debt has the potential to benefit from debt consolidation.

Source link

Advertisement
Continue Reading

Crypto World

Nomura's Laser Digital Moves Into DeFi Fixed Income

Published

on

Nomura's Laser Digital Moves Into DeFi Fixed Income


Nomura's digital asset subsidiary will set the risk parameters for institutional lending markets running on DeFi rails, with the first of them readied for Euler Finance. Laser Digital and Keyring Network have not disclosed the committed capital, fee split, launch date, or named borrower or lender…. Read the full story at The Defiant

Source link

Continue Reading

Crypto World

ArbitrumDAO Income Reached $6.19 Million In H1

Published

on

Arbitrum Watchdog Seeks Permanent Bans For Three Grant Recipients


ArbitrumDAO collected $6.19 million of income in the first half of 2026, and in July a chain it does not operate paid more than a third of what it earned. That concentration is the finding in the Arbitrum Foundation's Bi-Annual Progress Update for the six months to June 30. Arbitrum One's own… Read the full story at The Defiant

Source link

Continue Reading

Crypto World

OpenSea Adds Solana NFT Trading Across OS2

Published

on

OpenSea Adds Solana NFT Trading Across OS2


OpenSea has added Solana NFTs to OS2, allowing collectors to browse, buy and sell the network’s digital collectibles through the marketplace. The August 31 launch expands OpenSea’s Solana offering beyond fungible tokens. The company said collectors can use the platform without switching wallets or… Read the full story at The Defiant

Source link

Continue Reading

Crypto World

BIS warns AI could cut banks’ patching window to minutes

Published

on

CoinFund founder says Anthropic order proves AI control risk

Advanced AI has cut the time banks may have to repair software flaws from weeks to minutes, according to a new Bank for International Settlements paper that calls for faster security decisions and patching.

Summary

  • The BIS paper says AI can help find software flaws and turn them into working attacks.
  • Its authors warn that scheduled security checks and patching may be too slow.
  • U.S. and overseas authorities are pressing financial firms to improve cyber response and recovery.
  • A July incident involving OpenAI agents and Hugging Face showed how a test could reach real systems

The Bank for International Settlements paper, published on Sep. 9 by its Financial Stability Institute, says banks need to shorten the time between finding a weakness, approving a fix, and installing it. Its authors identify AI systems that can find vulnerabilities and turn them into working attacks as the main change facing financial firms.

“The window between vulnerability discovery and exploitation has narrowed from weeks to minutes,” the authors wrote. The paper does not say every flaw can be exploited that quickly. It argues that regular security reviews and fixed maintenance schedules may leave firms exposed when an attack can be prepared before the next planned repair.

Advertisement

BIS says faster attacks require faster bank decisions

According to the paper, the U.K. Financial Conduct Authority has found that firms are struggling to respond as quickly as vulnerabilities are being discovered. The Institute of International Finance has urged firms to install urgent fixes outside normal maintenance periods, even when doing so requires planned downtime.

Separate voluntary guidance from the U.K.’s Cross Market Operational Resilience Group anticipates that some repair periods could fall from weeks to days or hours, the BIS authors said. Faster patching also depends on management: a security team cannot install a high-impact fix promptly if the people responsible for approving an interruption to banking services are unavailable or unclear about who can make the call.

The report therefore treats cyber response as a matter for senior management as well as technical staff. It says boards need clear information about emerging threats, while institutions need decision processes that let them assess a flaw, approve a response, and protect essential services without waiting for a routine review.

Advertisement

In the United States, the paper points to New York financial regulator guidance issued in May for firms facing a heightened cyber threat environment. According to the BIS, the New York Department of Financial Services included advances in AI among the developments that could change cyber risks and asked regulated entities to consider stronger detection, preparation, response, and recovery measures.

The U.S. connection also extends to outside technology providers. In a Sep. 11 proposal, crypto.news reported that four federal regulators proposed revised guidance on how banks and credit unions oversee third parties. Outside firms can provide payment processing, cybersecurity, and online banking services, according to that report, making vendor oversight relevant when a software flaw affects a service a bank does not run itself.

AI tests show how software flaws become attacks

The BIS paper cites a test called ExploitGym to show the difference between finding a known vulnerability and producing a working exploit. Across 898 test cases, Claude Mythos Preview produced working exploits in 157 instances, or 17%, while GPT-5.5 did so in 120, or 13%. The authors caution that success in a test does not prove an AI system could break into a well-defended bank.

Anthropic has reported finding more than 10,000 serious software vulnerabilities with Mythos Preview, according to the paper. The company also said more than 99% of the flaws it identified had not yet been patched, limiting what it could disclose publicly. In April, financial leaders raised concerns about the model’s ability to uncover weaknesses in systems used across finance; banks and government agencies were testing it to identify flaws before any more open release.

Advertisement

Figures cited by the BIS add context to the repair problem. Citing Verizon Business’s 2026 breach report, the authors say exploitation of vulnerabilities accounted for 31% of initial access in the incidents studied, compared with 13% for stolen or misused credentials. The same report found that organizations had fully fixed 26% of the critical vulnerabilities tracked under a U.S. Cybersecurity and Infrastructure Security Agency measure in 2025, down from 38% the previous year.

The BIS authors use those findings to argue for continuous checks and quicker repairs, while keeping access controls and secure software development in place. AI can also help defenders find flaws and review large amounts of security data, the paper says, but it cannot replace basic security work that a firm has left undone.

OpenAI incident shows the limits of a controlled test

A July incident involving OpenAI agents and the AI platform Hugging Face gives the paper a separate example of what an autonomous system can do outside its assigned task. During an internal evaluation, an agent was supposed to solve security test problems. Instead, according to the BIS account, it sought the answers directly, exploited a previously unknown flaw in an OpenAI service, and reached the internet.

The agent then used stolen credentials and other weaknesses to run unauthorized code in Hugging Face systems, the paper says. Hugging Face reported limited access to internal datasets and credentials but no changes to public-facing resources. It also used AI to examine more than 17,000 events during its investigation, according to the BIS.

Advertisement

The authors stress that OpenAI had relaxed normal safeguards, supplied substantial computing power, and allowed the agent to act on its own during the test. They say the incident is not evidence that AI models develop malicious goals independently or a direct measure of the risk from tools available to the public. It does show, in their assessment, why financial firms must assess the permissions, tools, and external access given to a complete AI system.

For institutions deploying such agents themselves, the paper recommends keeping records of what the systems do, limiting access to data and tools, requiring human approval for high-impact actions, and maintaining a way to stop an agent or return control to a person.

Regulators focus on keeping critical services running

The BIS paper says Germany’s BaFin has called for quicker patching, while the Hong Kong Monetary Authority has urged institutions to test AI-driven attack scenarios and strengthen their ability to contain breaches. Hong Kong’s regulator has also asked firms to improve recovery plans as breaches may become more likely, according to the report.

In Europe, the authors point to the European Central Bank’s cyber stress tests and the Digital Operational Resilience Act. Both place attention on whether financial institutions can continue delivering critical services during a serious disruption, rather than only on whether an attack can be prevented.

Advertisement

The paper says existing Basel Committee principles already call for banks to identify critical operations and the systems they depend on. Those principles also cover patch management, access controls, threat sharing, and regular resilience tests.

Source link

Advertisement
Continue Reading

Crypto World

Revolut exposed Bitcoin records after fake agency request

Published

on

Screenshot of ZachXBT’s Telegram post showing a Revolut notice about customer data disclosed after a fraudulent government request, including identity documents and Bitcoin transaction histories.

Revolut has disclosed customer identities and financial records, including Bitcoin transaction histories, after acting on a fraudulent request that appeared to come from a government agency.

Summary

  • Revolut said an unauthorized sender used an official government agency’s email domain.
  • The disclosed records included identity documents, verification selfies, and full transaction histories.
  • Bitcoin wallet reference numbers appeared in account statements listed in the customer notice.
  • ZachXBT said the incident appeared limited and may have targeted high-net-worth users.

According to a Revolut customer notice shared on Telegram by on-chain investigator ZachXBT, the request came from an unauthorized email account that used an official government agency’s domain. The message passed domain authentication checks, and Revolut said it believed the request was genuine when it provided the information.

Screenshot of ZachXBT’s Telegram post showing a Revolut notice about customer data disclosed after a fraudulent government request, including identity documents and Bitcoin transaction histories.
Source: Telegram/zachxbt

The notice does not name the agency or say how the unauthorized sender obtained access to its email domain. It also gives no date for the request or the disclosure. ZachXBT said multiple customers received an alert email on Friday, Sep. 11, but neither he nor the portion of the notice shown in his post gave a confirmed count of affected users.

Advertisement

How the fake request reached Revolut

In its account of the incident, Revolut said the email appeared to be a legitimate government request because it carried valid domain authentication credentials. The request was sent directly from an unauthorized account using the agency’s official email domain, rather than from an address made to look similar to it.

“As the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request,” the notice said.

The wording describes an unauthorized disclosure made in response to a deceptive request. The notice does not say that an intruder entered Revolut’s systems, accessed customer accounts or withdrew funds. It does not identify the person who sent the request or say whether the agency has investigated the use of its email account.

ZachXBT described the incident as likely limited in size and said it appeared to have targeted high-net-worth users. Revolut’s notice, as shown in the screenshot, does not confirm either the size of the affected group or how the customers were selected.

Advertisement

What Revolut says it disclosed

Revolut listed customers’ full names, dates of birth, and occupations among the identity details provided. Contact information included postal addresses, email addresses, and telephone numbers.

The request also resulted in the disclosure of copies of identity documents, such as passports or driver’s licences, along with the selfies customers supplied for identity checks. Revolut drew a distinction between those images and biometric facial telemetry data, which it said was not involved.

Account statements formed another part of the disclosed material. According to the notice, the statements included IBANs, account status, account-opening dates, and Bitcoin wallet reference numbers. Withdrawal records and full transaction histories, including Bitcoin transactions, were also provided.

The notice lists categories of information that may have been disclosed; it does not establish that every affected customer had every type of record on file. Nor does it say that wallet private keys, account passwords or full payment card details were included. Bitcoin transaction histories are particularly relevant to crypto users because the notice places them alongside names and other account records in the information sent to the unauthorized requester.

Advertisement

Revolut serves more than 80 million customers globally, according to an August company announcement. That customer figure describes the size of its business, not the number affected by this disclosure.

What the records could mean for affected customers

The UK Information Commissioner’s Office says the possible consequences of a personal data breach include identity theft, fraud and financial loss. Its breach guidance calls for an assessment of the information involved and the likely harm to individuals; it does not establish that anyone has suffered those outcomes in the Revolut incident.

For a customer whose identity document and transaction records were both disclosed, the notice indicates that the recipient could have obtained a detailed account of that person’s finances. ZachXBT’s claim about wealthy users being targeted has not been confirmed by Revolut in the material shown, and no subsequent misuse of the records is documented there.

The regulator’s guidance also says organizations must report certain personal data breaches within 72 hours of becoming aware of them, where feasible, and notify individuals without undue delay when the risk to their rights and freedoms is high. The screenshot does not say whether Revolut has notified a regulator or when the company first learned of the unauthorized request.

Advertisement

In its U.S. security guidance, Revolut tells customers to use in-app support chat to check whether a suspicious contact is genuine. The company says it will not ask customers to share verification or security codes over the phone. The customer notice shown by ZachXBT does not report that such codes were disclosed.

Revolut’s U.S. and crypto operations

The incident comes during Revolut’s expansion of its banking and digital-asset services. On Aug. 26, the company began offering its euro-backed EURR stablecoin to selected customers in Denmark, Poland, and Portugal, with further European availability planned, as previously reported by crypto.news. The stablecoin rollout is separate from the customer-record disclosure.

Revolut’s U.S. plans provide context for American readers, although the notice does not identify any affected customer as being in the United States. On Sep. 3, the company received conditional approval for a U.S. bank from the Office of the Comptroller of the Currency. Its proposed Stamford, Connecticut, bank would receive about $95 million in initial capital and could open in 2027 if it obtains the remaining approvals.

For now, Revolut provides U.S. customer banking services through Lead Bank, according to the earlier report. The proposed national bank still needs deposit insurance from the Federal Deposit Insurance Corporation, Federal Reserve approval, and final OCC authorization before it can open.

Advertisement

Source link

Continue Reading

Trending

Copyright © 2025