Crypto World
Bitpanda Receives Austria’s First MiCA Penalty in Published Case
Austria’s financial regulator has issued its first final penalty under the EU’s Markets in Crypto-Assets Regulation (MiCA), fining crypto platform Bitpanda 70,000 euros (about $82,000) for breaching MiCA’s publication and marketing disclosure rules. The Austrian Financial Market Authority (FMA) said the case was handled under an expedited procedure and that the decision is final.
According to the FMA, the issue centered on Bitpanda’s timing and compliance with mandatory pre-publication and disclosure requirements for a crypto-asset white paper.
Key takeaways
- The FMA fined Bitpanda 70,000 euros for failing to submit the required crypto-asset white paper at least 20 working days before publication.
- Regulators also said Bitpanda issued marketing communications before the white paper was filed.
- Another alleged breach involved marketing material that omitted MiCA-mandated disclaimers, including that it had not been reviewed or approved by a competent authority and that Bitpanda is responsible for the content.
- The penalty was issued as the first published final enforcement under MiCA, signaling the EU framework is moving from licensing and guidance into outcomes.
- Bitpanda stated the problems were limited to formal timing and documentation requirements, and said customer funds and platform security were not affected.
FMA details: white paper submission and marketing timing
In a notice published Friday, the FMA said Bitpanda did not submit a crypto-asset white paper to the regulator at least 20 working days prior to its publication, as MiCA requires. The regulator also reported that Bitpanda distributed a marketing communication before publishing the required white paper.
The regulator’s explanation is significant because MiCA’s approach to investor protection depends heavily on structured disclosures. The white paper is intended to provide standardized information before the public is exposed to an offering or related marketing materials.
Disclosure gaps in marketing materials
The FMA further alleged that another marketing communication failed to include mandatory disclosures. Specifically, the regulator said the content did not state that the material had not been reviewed or approved by a competent authority, and that the crypto-asset provider alone was responsible for the content. The regulator also said the marketing communication lacked required contact details, including a telephone number and email address.
These points matter for compliance teams because they show that regulators are not only checking whether documents exist, but whether the surrounding communications include the specific legal language and contact information required under MiCA.
Expedited proceedings and final decision
The FMA said the case was concluded under an expedited procedure and that the penalty decision is final. While the fine amount is comparatively small relative to some large-scale financial enforcement actions, the regulatory significance is larger: this is presented as the watchdog’s first published final penalty under MiCA.
For market participants, the outcome suggests that formal compliance lapses—such as filing timelines and required statement formatting—are actionable under MiCA, even when the core product or platform functionality is not necessarily implicated.
Bitpanda’s response: timing and formal requirements only
Bitpanda told Cointelegraph that the concerns raised by the FMA related exclusively to the timing and formal requirements surrounding the publication of the white paper and an accompanying information document. The company said customer funds and platform security were not affected and that customers suffered no financial harm.
Bitpanda added that it corrected the issues after receiving notice from the FMA, and it opted for a swift, consensual conclusion of the proceedings.
That framing may influence how investors and users interpret the case. The regulator’s enforcement narrative emphasizes process compliance, while Bitpanda points to the absence of customer impact. Still, the penalty itself indicates that regulators are prepared to treat disclosure mechanics and marketing rules as enforceable obligations under the new regime.
Why this is a broader MiCA signal
MiCA created a harmonized regulatory framework for crypto assets across the European Union, including disclosure standards, marketing requirements, and authorization conditions for crypto companies. The FMA’s action reinforces that MiCA compliance is not limited to licensing status or long-form disclosures alone; marketing materials and document submission timelines are also subject to scrutiny.
Earlier coverage of the implementation of MiCA licensing timelines and transitional measures (including references to the end of certain grace periods) highlighted that firms would eventually face stricter enforcement as operational readiness deadlines were crossed. This penalty fits that pattern: once formal requirements are in effect, regulators can convert guidance into penalties.
For the wider industry, the main uncertainty going forward is how frequently regulators will pursue similar “paperwork” cases and whether enforcement will focus on specific categories of issuers or on any instance of noncompliance with pre-publication timing and mandated marketing language. Market participants should watch for more final decisions across member states as regulators test the boundaries of MiCA’s disclosure and communications requirements.
Readers should pay attention to the next enforcement steps from Austria and other EU jurisdictions—particularly whether additional cases involve similar white-paper submission delays and missing mandatory marketing disclaimers, or whether regulators begin targeting other parts of MiCA compliance such as authorization obligations and ongoing disclosure practices.
Crypto World
The Odyssey pirated downloads target crypto wallets
Fake downloads of The Odyssey have begun spreading Lumma Stealer malware through files disguised as high-quality movie releases, putting crypto wallets, passwords, and browser sessions at risk.
Summary
- Fake The Odyssey downloads use
.exefiles disguised as 1080p, WEBRip, and Blu-ray releases. - Lumma Stealer can collect crypto wallet data, passwords, payment details, and authentication cookies.
- Bitdefender blocked malicious downloads and identified three domains connected to the malware.
- U.S. authorities previously linked LummaC2 to at least 1.7 million information-theft incidents.
Bitdefender reported on Aug. 6 that its researchers had found malicious Windows executables using filenames designed to resemble pirated copies of The Odyssey, only days after the film’s release.
The Odyssey downloads conceal Windows executables
Disguised as video files, the downloads use familiar torrent labels such as 1080p, WEBRip, Blu-ray, and H264 to make the listings appear authentic. Bitdefender identified filenames including “the odyssey 2160phd (2026) engsubs eztv.exe,” “the odyssey 2026 1080p h264-djt.exe,” and “the odyssey 2026 1080p webrip-lama.exe.”
Rather than opening a movie, each .exe file launches software built to infect a Windows computer. Bitdefender said its security products prevented users from downloading or running the detected files, although the researchers warned that other filenames may also be circulating.
Attackers can make the disguise harder to spot by changing the executable’s icon to resemble VLC Media Player or an ordinary video file. Windows installations hide known file extensions by default, according to Bitdefender, which means a user may see a movie-style name and VLC icon without noticing the .exe ending.
People searching torrent sites may also expect unusual filenames, compressed folders, or a bundled video player, giving the malicious file another layer of cover. Bitdefender said the lure does not require a complex trick because the victim has already decided to download an unofficial copy from an unverified source.
Lumma Stealer can capture wallets and browser sessions
Once executed, Lumma Stealer searches the infected computer for browser passwords, saved payment information, autofill records, remote desktop credentials, and cryptocurrency wallet data, according to the security firm.
The malware also collects browser authentication cookies. Bitdefender warned that stolen cookies can let an attacker take over an active account session even when the victim has enabled multi-factor authentication, since the criminal may reuse a session that has already passed the login check.
Known as LummaC2, the malware is an information stealer developed in Russia and sold to other criminals as a service, according to Bitdefender and U.S. authorities. Its availability through underground markets allows buyers to run data-theft campaigns without building their own malware.
During its examination of the Odyssey files, Bitdefender observed attempts to contact command-and-control infrastructure associated with Lumma Stealer. Researchers identified the domains auditva[.]cyou, myroayy[.]cyou and logmabx[.]click, which the company said it had blocked for its customers.
Unlike some earlier versions, the samples found in the latest movie campaign did not use separate droppers or persistence tools, Bitdefender said. The operators instead appeared satisfied with collecting and sending available information during the initial execution.
Previous movie-based Lumma attacks used extra methods to avoid detection. Bitdefender found delayed execution when security software was present, encrypted payload delivery through AutoIt scripts, and other checks in a 2025 campaign built around fake copies of Mission: Impossible – The Final Reckoning.
U.S. agencies previously disrupted LummaC2 infrastructure
For U.S. crypto holders, LummaC2 has already drawn action from federal law enforcement. In May 2025, the Justice Department obtained warrants to seize five internet domains used by the malware’s administrators, while Microsoft filed a separate civil case covering about 2,300 other domains tied to the operation.
Court documents cited by the department said the FBI had identified at least 1.7 million cases in which LummaC2 was used to steal information. Listed targets included browser records, email and bank login details, autofill data, and crypto seed phrases that could provide access to virtual asset wallets.
“Malware like LummaC2 is deployed to steal sensitive information such as user login credentials from millions of victims in order to facilitate a host of crimes, including fraudulent bank transfers and cryptocurrency theft,” Matthew Galeotti, then-head of the Justice Department’s Criminal Division, said in the announcement.
The federal operation seized two domains on May 19, 2025. After LummaC2 administrators told customers about three replacement domains the next day, U.S. authorities seized the new addresses as well, according to the department.
Alongside the seizures, the Cybersecurity and Infrastructure Security Agency and the FBI issued a technical advisory describing how LummaC2 enters computers and removes sensitive information. The Justice Department directed people who believe a device has been compromised to contact the FBI’s Internet Crime Complaint Center or a local field office.
The appearance of new Lumma-linked domains in Bitdefender’s 2026 findings indicates that malware campaigns using the family continued after the 2025 enforcement operation. Bitdefender did not provide a victim count, estimated crypto loss, or geographic breakdown for the Odyssey campaign.
Crypto malware is using familiar content as bait
Movie torrents are one part of a series of malware campaigns that package harmful code inside content, applications, or tools that users actively seek.
Earlier in August, crypto.news reported that Microsoft had found a fake CAPTCHA campaign using BNB Chain smart contracts to retrieve attack instructions. Microsoft said the operation targeted thousands of consumer and business devices each day and delivered several malware families, including Lumma Stealer.
Instead of downloading a movie, people caught in that campaign were instructed to open Windows Run, Terminal, or PowerShell and paste a command supplied by the attacker. Microsoft warned that successful infections could expose credentials, install remote-access tools, and create an entry point for ransomware.
Mobile users have faced a different form of wallet theft. In July, reports renewed attention around SparkKitty mobile malware, which Kaspersky had previously found inside iOS, Android, and third-party applications. The spyware collected images from phone galleries, where some users had stored screenshots of wallet recovery phrases, passwords, and QR codes.
Developer tools have also become a delivery route. Socket disclosed in May that the TrapDoor malware campaign involved at least 34 harmful packages and 384 connected versions across npm, PyPI, and Rust repositories. According to the security company, the packages targeted crypto and artificial intelligence developers while seeking wallet data, GitHub tokens, cloud credentials, and SSH keys.
For the latest movie campaign, Bitdefender advised users to watch films through legitimate streaming services, avoid executables advertised as videos, and keep Windows and security software updated. The company also recommended enabling file extensions in Windows Explorer so an .exe file cannot appear to be an ordinary movie.
Crypto World
Fourth crypto exchange shuts down in just six weeks
US-based crypto exchange ABFinance, founded by ByBit’s former CEO Helen Liu, closed its doors last week before it ever opened.
ABFinance announced last Friday that the exchange’s planned launch will no longer go forward and that it is “winding down in an orderly manner.”
ABFinance lasted six months
Liu founded the exchange in March before stepping down from her ByBit co-CEO role on April 30, 2026.
After ABFinance’s closure, Liu thanked her team and said: “It’s difficult to see this chapter come to an end.”
Over the last six weeks, BitMart, BitMEX, and AscendEX have also announced that they will be closing shop.
Read more: AscendEx shutdown: Uncertainty over withdrawals as hot wallets lack funds
Exchanges are leaving users worried for their funds
BitMart closed down despite its bullish outlook, and now, after it has continued to process withdrawals at an incredibly slow pace, users have begun to speculate that the exchange might be insolvent.
BitMart’s founder recently threatened legal action against posts from an official BitMart account demanding transparency on the status of user funds.
This prompted crypto detective ZachXBT to note, “If you actually have the liquidity then simply return the funds to everyone instead of posting vague statements?”
BitMEX said it will close down in September, leaving users wondering what it will do about $270 million sitting in a house insurance fund.
AscendEX also shut down amid withdrawal worries after ZachXBT flagged that the exchange was missing large sums of ETH, USDT, USDT, SOL, and more in its reserves.
Got a tip? Send us an email securely via Protos Leaks. For more informed news and investigations, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.
Crypto World
Pilots and Flight Attendants Face a Real Cancer Risk. Frequent Flyers Shouldn’t Panic
The approach rested on simple logic. If cosmic radiation were truly driving cancer among air crew, the signal should appear specifically in the cancers that radiation is known to cause (breast, prostate, melanoma, and certain leukemias), and the signal should not appear in cancers like colon cancer that aren’t caused by this type of radiation. We would also expect to see higher rates of radiation-associated cancers among other types of workers exposed to radiation, like nuclear technologists. Meanwhile, unless something about aviation other than flying was associated with these cancers, we wouldn’t expect to see higher rates in aviation workers who remain on the ground, like aircraft mechanics and assemblers.
The pattern was hard to miss. Among all 503 occupations, flight attendants and pilots had the highest and second-highest share of deaths from radiation-related cancers—6.9% and 6.7%, respectively, after accounting for differences in age, sex, and other factors—a proportion that exceeded that of nuclear technologists. For cancers unrelated to radiation, aircrew sat near the middle of the pack. And our comparison groups fell exactly where the radiation hypothesis predicted; nuclear technologists ranked near the top, while ground-based aviation workers did not.
Crypto World
Israel’s largest crypto broker Bits of Gold hit by data breach affecting 200,000 customers
Cryptocurrency broker Bits of Gold said personal data belonging to roughly 200,000 customers was stolen by hackers, the company reported.
The Tel Aviv, Israel-based company reported the security breach on Sunday, saying a hacker gained unauthorized access to a third-party data analytics network and,gained access to customers’ names, national ID numbers, emails, phone numbers, IP addresses, bank account details, and public wallet addresses.
“Upon detection of the incident, we blocked access and disconnected the system from the information sources, so this access ended,” the company stated.
Bits of Gold said no funds, private keys, passwords, CVV codes, or scanned ID documents were exposed. The broker said its initial findings indicate the attack was part of a broader global incident that hit other companies simultaneously.
It is the third data breach reported within the crypto industry in the last week. Data from nearly 40,000 SafePal users was stolen on Sunday after a third-party vendor suffered a security breach. In a similar attack, personal data from almost 14,000 Trezor wallet customers was exposed on August 13 after its fulfillment partner, ShipMonk, was compromised.
Crypto World
How a bug in Coldcard’s code went unnoticed for years, leading to $100 million in hacked funds
Hardware wallets are somewhere in between a paper wallet and a browser-based hot wallet. They’re harder to hack than software, harder to lose than paper, but they’re not infallible. They can be lost or stolen, and users need to be able to trust the device to create their keys properly in the first place.
“Air-gapped systems help, but they are not a perfect fix,” Bobby Gray, founder of TEXITcoin, told CoinDesk. “Security has to begin with how the keys are generated and continue through every part of the custody process.”
This is, unfortunately, where things went wrong for Coinkite, the maker of the Coldcard wallet.
A bug in the system
In March 2016, the Toronto-based bitcoin company told customers it was sunsetting its hosted hot wallet. Running an online financial services company had brought persistent floods of junk internet traffic aimed at knocking their services offline, along with mounting legal costs and regulatory complications.
Instead, Coinkite said it wanted to try something different. It wanted to build decentralized hardware and “software-not-as-a-service.” That was early in crypto’s history, before Bitcoin’s second halving, when one entire bitcoin was trading slightly above the $400 mark.
Coinkite’s pivot first produced Opendime in April 2016. The small USB stick generated and concealed a private key, allowing bitcoin to be passed from one person to another like a physical bearer instrument. Physically breaking the device’s seal revealed the key and allowed the funds to be spent.
Crypto World
Bitmine Nears 5% of Ethereum Supply With 5.82M ETH
Tom Lee’s Bitmine Immersion Technologies, an Ethereum treasury company, resumed its Ether purchases last week, bringing it closer to a key business target of owning 5% of the second-biggest cryptocurrency’s supply despite challenging market conditions.
The company disclosed Monday that it acquired 9,926 Ether (ETH) during the week ending Aug. 16, bringing its total holdings to roughly 5.82 million ETH, or about 4.8% of Ethereum’s circulating supply. At an ETH reference price of $1,893, Bitmine’s Ether holdings were valued at roughly $11 billion. However, much of the company’s ETH was acquired at significantly higher prices.
Ether’s price was little changed on Monday, sitting just above $1,900.
The latest purchase puts Bitmine within striking distance of its long-term “Alchemy of 5%” target of holding 5% of the total ETH supply.
Bitmine’s conviction has been tested by a prolonged bear market for Ether, which has sharply eroded the value of its digital asset treasury. The company is sitting on more than $8.4 billion in unrealized losses on its ETH holdings, according to industry data.

With a portfolio value of more than $11 billion, BitMine’s unrealized losses are around 43%. Source: DropsTab
Still, Bitmine has continued accumulating Ether, making purchases every week since launching its ETH treasury strategy in June 2025.
Related: Ethereum devs to narrow 66 proposals tied to Hegotá upgrade
Bitmine’s staked Ether approaches $10 billion in value
Although Bitmine is sitting on large unrealized losses on its Ether holdings, its staking operations continue to generate yield. The company said it is staking more than 5 million ETH, worth roughly $9.6 billion at current prices.
That staking has enabled Bitmine to earn protocol rewards for helping secure the Ethereum network, providing a predictable source of yield regardless of short-term ETH price movements. Based on a seven-day staking yield of 2.61%, Bitmine projects annualized staking rewards of roughly $287 million, according to Lee.
Related: Crypto Biz: Bitcoin’s $116M self-custody wake-up call
Crypto World
SafePal Breach Exposes 39,798 Buyers as Stolen Records Hit Cybercrime Forum
![]()
SafePal disclosed on Aug. 16 that a flaw in an order-tracking plug-in exposed the personal data of 39,798 customers, and a threat actor is already advertising the records for sale on a cybercrime forum. The file pairs home addresses and phone numbers with proof of hardware wallet ownership, which… Read the full story at The Defiant
Crypto World
Stripe’s Reported $7 Billion OpenRouter Deal Buys Micropayments Without a Blockchain
![]()
Stripe has finalized an agreement to buy AI model gateway OpenRouter for more than $7 billion, Bloomberg reported Sunday, citing people familiar with the matter. Neither company has announced the deal, and a Stripe spokesperson told TechCrunch the company does not comment on rumors or speculation…. Read the full story at The Defiant
Crypto World
AI Debt Lifts 30-Year Treasury Yield to 5.27%: Can Bitcoin Compete?
The US government now pays 5.27% to borrow for 30 years, the highest rate of 2026. Artificial intelligence (AI) companies are a large part of the reason. Bitcoin (BTC) is losing the fight for the same money.
Bitcoin trades near $63,517, down 46.1% over the past 12 months. Gold rose 32.6% in the same stretch. The gap between them is almost 79 percentage points.
AI Borrowing Now Competes With the US Treasury
Start with the trend. US technology companies used to sell about $61 billion of bonds a year. That is the five-year average, JPMorgan Asset Management said in July. In 2025 they sold $131 billion. By late July 2026 they had sold $192 billion.
One sector now accounts for 27% of all net investment-grade bond sales, by JPMorgan’s count. Across every US company, issuance reached $1.68 trillion through July. That tally comes from the Securities Industry and Financial Markets Association.
Here is why that matters. The buyers are the same pension funds and insurers that fund Washington. Nomura Securities estimates Big Tech borrowing now equals roughly 25% of Treasury net bond sales to private investors. A year ago the share was five times smaller.
“Whoever’s issuing, be it a government or a hyperscaler or a non-hyperscaler credit, is now competing with more borrowers. And therefore yields have to be higher,” Tony Rodriguez, head of fixed-income strategy at Nuveen Asset Management, in a statement to Bloomberg.
Follow us on X to get the latest news as it happens
Why Bitcoin Loses When Yields Rise
The mechanism is simple. Bonds pay interest. Bitcoin does not.
The 30-year Treasury yield closed at 5.25% on August 14, its highest level this year, Treasury Department data show. The 10-year sits at 4.68%, up 0.49 percentage points since January 2.
Bank of America economists attribute about 0.3 of that rise to corporate and mortgage bond supply. On those numbers, new debt supply explains roughly 60% of the move in the 10-year this year.
Corporate paper pays even more. Alphabet priced 30-year debt near 6.4% recently, about 1.15 points above comparable Treasuries, Bloomberg reported. A bond financing a Meta data center paid over 7.5% last month.
An investor can now earn 6% or 7% from two of the world’s most profitable companies. That is the bar Bitcoin’s price performance must clear. It has not cleared it since global bond yields climbed to 2008 levels.
The Treasury Cannot Sidestep It
Treasury Secretary Scott Bessent has tried to protect long-term rates by selling more short-term debt instead. Barclays estimated the shift would cut net supply of new Treasury notes and bonds by $440 billion this year.
AI borrowing filled that space and more. Barclays expects net corporate bond supply to grow by $474 billion, most of it from the tech giants.
Washington is not borrowing less either. The federal deficit hit $1.8 trillion in the first 10 months of fiscal 2026. That is $169 billion more than last year, the Congressional Budget Office said. Rising US debt interest costs add to it.
The AI bill is also mostly unpaid. JPMorgan Asset Management projects $5.5 trillion of AI capital spending through 2030. It expects $2.1 trillion of that to come from new bonds.
“That is a crowding-out effect. It is important to remember that we are just starting. This hyperscaler debt issuance story has really just begun,” Greg Peters, co-chief investment officer at PGIM, in a comment on Bloomberg Television.
Endless borrowing is the core of the Bitcoin scarcity argument. This year the argument has not paid. Gold took the money, and the 30-year Treasury yield record shows why. The next long-end auctions will test whether buyers have room for both.
The post AI Debt Lifts 30-Year Treasury Yield to 5.27%: Can Bitcoin Compete? appeared first on BeInCrypto.
Crypto World
Workday Stock: Why This Analyst Is Skeptical Of Silver Lake Deal
At least one Wall Street analyst is skeptical that private equity firm Silver Lake will pull off a deal to acquire software maker Workday (WDAY). Workday stock popped on Feb. 13 amid reports of Silver Lake’s interest but has cooled off the next two trading sessions. In early 2026, Workday Cofounder and Executive Chairman Aneel Bhusri returned as chief executive…
Copyright ©2026 Investor’s Business Daily, LLC. All rights reserved. 87990cbe856818d5eddac44c7b1cdeb8
-
Fashion3 days agoWeekend Open Thread: Ann Taylor
-
NewsBeat6 days agoCommunication cards help banking customers access services or report scams
-
Business7 days agoOil Price Today (August 11): Crude oil rises to $88 after Trump’s compensation demand dents Hormuz opening. Here’s why
-
Crypto World7 days agoRevolut wins French banking licence, creates second EU banking hub
-
Sports4 days agoThis U.S. Amateur is a glimpse into golf’s future in more ways than you think
-
Crypto World7 days agoWhy Did Nvidia Stock Fall on Monday Despite a $500 Billion Wall Street AI Deal?
-
Sports3 days agoBirmingham 2026: Day 6 Timetable for Irish Athletes
-
NewsBeat2 days agoMyanmar says over 300,000 Rohingya refugees verified for repatriation as exodus enters ninth year
-
Entertainment5 days agoKeke Palmer Subtly Hints At Sean Evans Drama With Cryptic Post
-
Politics2 days agoSEQ Code: The Three Letter Boarding Pass Code That Could Give You The Worst Seat
-
Fashion7 days agoCan You Wear Double Cloth Gauze Clothing To Your Office?
-
Entertainment7 days ago57 Years Later, the Best Sitcom Ever Made Still Deserves a Reboot
-
Fashion6 days agoCoffee Break: The Fonteyn Jane Flat
-
Crypto World7 days agoHormuz Nerves Cost Bitcoin $65,000 Mark Despite Solid Institutional Flows
-
Tech6 days agoZoom Screen-Sharing Bug Let People Fully Take Over Other Devices On A Call
-
Crypto World7 days agoBitcoin's BIP Editors Remove Luke Dashjr Two Days After BIP-110 Fork Stalled
-
Fashion6 days agoClaire Life: Kicking Off MVAAFF With the C Suite Luncheon Featuring Phylicia Rashad, Letoya Luckett, and More!
-
Fashion6 days agoShould you refinance your debt? Pros, cons, and real numbers
-
Crypto World6 days agoXRP bridge drained after software mistook fake deposits for real ones
-
Sports5 days agoDeQuan Jones in ‘high spirits’ after successful leg surgery

You must be logged in to post a comment Login