Crypto World
Blockstream says it will not pay ransom for stolen Liquid Bitcoin
Blockstream has refused to pay a ransom for roughly 598.5 BTC that remains under the control of the actors behind the Liquid Network exploit after 3,400 BTC was returned earlier this week.
Summary
- Blockstream has refused to pay a ransom for Bitcoin still held by the actors behind the Liquid Network exploit.
- The actors previously returned 3,400 BTC after nearly 4,000 BTC was withdrawn from Liquid’s federation wallet.
- Blockstream rejected the actors’ white hat position and said taking funds without authorization and withholding their return amounts to theft.
- The company said it will work with law enforcement, exchanges, forensic specialists and service providers to trace and recover the remaining Bitcoin.
Blockstream said in an X post on Sept. 11 that taking assets without authorization and withholding their return amounts to theft, rejecting the actors’ description of their actions as responsible disclosure or white-hat activity.
“We will not pay a ransom for the return of stolen funds,” the company said. “Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft.”
The statement follows several days of communication between Blockstream and the unidentified actors after nearly 4,000 BTC was withdrawn from Liquid’s federation wallet on Sept. 6.
Blockstream rejects ransom for remaining Bitcoin
Blockstream said it had engaged with the actors in good faith to recover funds belonging to users and protect the Bitcoin community, but said the talks did not amount to acceptance of either the withdrawal or the terms later demanded.
The company argued that developers of open-source Bitcoin software should not be forced to pay a ransom that exceeds their economic participation in a project after someone exploits the code.
“Bitcoin is hard money and can’t be minted without costs, Bitcoin doesn’t haircut users to pay a ransom,” Blockstream said.
The dispute centers on approximately 598.5 BTC that remains outstanding following the return of 3,400 BTC to Liquid’s federation wallet on Sept. 7. The repayment recovered roughly 85% of the Bitcoin withdrawn during the incident.
The remaining Bitcoin was worth close to $47 million when the larger repayment was completed. No publicly disclosed agreement had authorized the actors to retain the coins as a bounty.
The actors had initially described themselves as “whitehats” and communicated with Blockstream through messages embedded in Bitcoin transactions. Before returning the 3,400 BTC, they told the company to fix the vulnerability and ensure that every affected node had been patched.
Blockstream later confirmed through a signed message that its bridge nodes had been patched and that the funds were safe to return.
As crypto.news previously reported, the actors had offered to return most of the withdrawn Bitcoin after the vulnerability was fixed, without committing to return the entire amount.
Subsequent on-chain messages changed the terms of the dispute. The actors demanded that Blockstream pay a 10% bounty using its own money or leave Liquid holders facing a loss, according to messages published as negotiations continued.
Blockstream has now rejected any payment tied to the return of the remaining coins.
Liquid exploit left nearly 600 BTC outstanding
The Sept. 6 incident involved a vulnerability affecting Liquid, the Bitcoin sidechain developed by Blockstream. Nearly 4,000 BTC left the federation wallet, representing most of the Bitcoin held in the reserve at the time.
A later examination of the Liquid Network exploit found that the incident stemmed from a cache-key collision in confidential transaction verification logic. Blockstream said federation keys were not compromised.
The actors used the flaw to obtain Bitcoin from the federation reserve before beginning an on-chain exchange with Blockstream. Liquid halted block production during the incident, while exchanges were asked to suspend L-BTC deposits and withdrawals.
After Blockstream patched the affected bridge nodes, the actors transferred 3,400 BTC back to the federation address. Approximately 598.5 BTC remained at an address controlled by the actors.
Blockstream’s latest statement draws a line between its earlier effort to negotiate the return and any agreement to reward the people responsible.
The company said paying the demand would establish a precedent in which open-source developers could be forced to fund large payments after unauthorized withdrawals from systems using their software.
Blockstream told the Bitcoin community that it was continuing to work for users whose funds were taken and thanked engineers, cryptographers and security researchers who had helped identify and patch vulnerabilities across Bitcoin-related software.
The company linked part of the security pressure facing open-source projects to advances in artificial intelligence, saying teams across the Bitcoin ecosystem have been dedicating time to finding and fixing weaknesses in one another’s products and systems.
Security problems involving Bitcoin software have surfaced elsewhere in recent months. In August, BTCPay Server supporters backed a recovery bounty equal to 10% of funds retrieved after an exploit exposed LND admin macaroon credentials. That bounty was capped at 3 BTC if all stolen assets were recovered.
The arrangement followed an active exploit that prompted BTCPay Server to tell operators to install version 2.4.2 or shut down affected servers until they could update.
Blockstream plans to pursue remaining funds
With negotiations failing to produce a complete return, Blockstream said the people controlling the remaining Bitcoin still have an opportunity to send it back and return to what the company called standard white-hat principles.
If the funds remain outstanding, the company said it plans to work with law enforcement agencies, exchanges, service providers, forensic specialists and other parties to trace the Bitcoin and identify those responsible.
Bitcoin transactions leave a public on-chain record, giving investigators a continuing view of movements from addresses associated with the incident even if the coins are later split between multiple wallets.
A similar tracing process has been used following other major Bitcoin thefts. Galaxy Research, for example, found in August that 1,561 BTC remained unmoved after researchers attributed 1,789.28 BTC in losses to the Coldcard exploit. Identified attacker addresses were shared with exchanges, compliance companies and law enforcement.
Blockstream said the transparency of Bitcoin would allow the community and investigators to continue following evidence left by transactions involving the Liquid funds.
“Transactions do not disappear, and neither does the evidence they leave behind,” the company said.
The company maintained that it would neither pay for the return of stolen property nor stop pursuing the outstanding Bitcoin.
“Return the bitcoin,” Blockstream said.
Crypto World
Senator Lummis Says the New Clarity Act Text Carries Over 100 Democrat-Requested Changes
Senator Cynthia Lummis said the updated Clarity Act text carries more than 100 changes that Democrats requested. She urged them to help pass the bill.
Senate Republicans released an updated CLARITY Act text that runs 630 pages, 14 more than the July 22 draft. A procedural vote, now four days later, decides whether the bill reaches the Senate floor.
Follow us on X to get the latest news as it happens
What Changed in the Clarity Act’s September 10 Draft Text
The bill still runs four divisions and 103 sections. What changed is buried inside roughly a dozen of them, all in the Banking and Agriculture titles.
BeInCrypto compared the two Senate substitute texts line by line. The September draft differs from the July draft in 14 of its 103 sections. Those sections contain 104 discrete edits, though only 28 exceed 8 words.
The heavy lifting is in Section 20209, the DeFi safe harbor, which balloons from 285 words to about 2,200. Validators, node operators, and anyone publishing wallet software get a full carve-out from the Commodity Exchange Act.
Front-ends, governance systems, liquidity pools, and the upkeep of that wallet software are shielded only from spot-market rules.
For “decentralized-in-name-only” protocols, the CFTC must write rules on how controllers comply, a mandate rather than an automatic registration trigger, and the code itself is never required to register. Treasury then writes matching anti-money-laundering rules for whoever the CFTC pulls in.
The quieter story sits in the preemption clause. State securities, commodities, and digital asset law no longer applies to those activities, and the section applies to conduct before enactment. State fraud, manipulation, and AML powers survive, so the fight moves to where licensing ends, and fraud begins.
Division C, the ethics title Democrats want changed, is untouched
What Republicans Left Alone, and Who Is Still Voting No
The smaller edits sit outside the DeFi title. Credit unions get a clearer footing, keyed to definitions from the GENIUS Act, though the text stops short of expanding their authority into brokerage or dealing.
CFTC spot oversight now covers every payment stablecoin rather than only those from licensed issuers. The bill reaches transactions on or through an entity registered with the Commission. States also keep their fraud-enforcement powers against registrants under Section 20207.
The ethics title is not the only thing Republicans left alone. Section 10404, which bars yield on payment stablecoins, is identical to the July version. So is Section 10604, the developer protections known as the Blockchain Regulatory Certainty Act.
Those two carry substantial opposition. The American Bankers Association and 60 other banking groups asked Senate leaders to tighten the rewards rules. They warned of deposit flight from community banks.
Republican Senators Josh Hawley and Jerry Moran have raised concerns about that. Democrats, meanwhile, have tied their support to stronger ethics terms covering President Donald Trump’s crypto holdings.
Senators vote Tuesday afternoon on whether to invoke cloture on the motion to proceed. 60 votes are needed.
Subscribe to our YouTube channel to watch leaders and journalists provide expert insights
The post Senator Lummis Says the New Clarity Act Text Carries Over 100 Democrat-Requested Changes appeared first on BeInCrypto.
Crypto World
Trezor Issues Security Warning After Third-Party Security Breach
Trezor has warned that a third-party security breach enabled phishing emails to be sent out from the hardware wallet provider’s official domain.
The breach comes soon after a security incident at ShipMonk compromised the personal information of Trezor users.
Trezor Warns Of Third-Party Breach
Trezor issued a warning in an official X post, informing users that the email “Critical Security Alert: STM32 Entropy Vulnerability” was a phishing attempt and urged them to avoid clicking any links.
“Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.”
The compromised domain has since been taken down, and Trezor has launched a full investigation into the breach and how hackers used the company’s official domain to send phishing emails. Marcello Paz, a crypto commentator, said he received the phishing email in question and shared screenshots asking customers to update their hardware wallets due to a “critical vulnerability.” Unlike typical phishing emails, the email’s credentials showed official domain names and signatures.
“Hello @trezor, I received a “Critical Security Alert: STM32 Entropy Vulnerability” email today (9 Sep 2026). Gmail shows From: Trezor Security
Similar Attempt On BitBox
BitBox, a Swiss Bitcoin hardware wallet maker, reported a similar phishing attempt. The company shared a similar email on its official X account, warning users it was a phishing attempt and urged them to be cautious.
“There is currently a phishing email going around that’s pretending to come from us. Please do not follow the instructions in the email! We are currently investigating.”
Previous Security Incidents
Last month, Trezor’s shipping provider ShipMonk was hit by a major security breach that exposed personal information linked to its customers. Trezor initially disclosed that personal information, including names, cities, and email addresses of 13,700 users, was compromised. However, it said another 67,000 US-based users were affected by the breach.
Hardware wallets have been hit by several security vulnerabilities and breaches recently. Ledger’s security team disclosed a major vulnerability in Trezor Safe 7’s TROPIC01 chip, demonstrating how a lab-based laser attack bypassed its firmware verification system. Ledger suffered a major security breach in 2020 that exposed the personal information of over 270,000 customers, including names, email addresses, phone numbers, and even home addresses. The details were published on a dark web forum, with impacted customers receiving scam calls and physical letters even years later.
Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.
Crypto World
ICODA Releases HackGPT for Crypto GEO
WROCŁAW, Poland — 11th September 2026 — Getting to the top of Google no longer means getting found by investors. That disconnect is the starting point of HackGPT, the new AI search playbook published by ICODA, a crypto marketing agency founded in 2017 and trusted by more than 650 clients across DeFi, GameFi, iGaming, Exchanges, and Token Sales. The 51-page guide documents how Web3 projects build citation authority inside ChatGPT, Perplexity, and Google AI Overviews — and why teams still treating ChatGPT SEO as an extension of Google strategy are losing ground fast.
The Data Point Every Crypto Team Got Wrong
Only 43.2% of pages ranking #1 on Google are ever cited by ChatGPT — the majority of top-ranked pages are AI-invisible.
That finding, drawn from Semrush’s study of 230,000 prompts, is the central tension HackGPT was built to resolve. For years, Web3 marketing agency strategy treated Google rankings as the default proxy for investor discovery: earn backlinks, publish content clusters, reach Page 1. That logic has fractured.
Semrush’s parallel 1,094-category analysis sharpens the picture: the brand that dominated a topic had more organic traffic than its closest competitor only 48.4% of the time — worse than a coin flip. Organic authority and AI citation authority are measurably different things. Winning one does not guarantee winning the other, and for crypto projects operating in 90-day launch cycles, that gap is a direct revenue risk.
ChatGPT’s citation behavior makes the divergence sharper still. While Perplexity cites Google’s top-10 results 91% of the time, ChatGPT overlaps with those same results just 14% of the time — actively sourcing fresher, more conversational content that standard SEO strategies never touch. For any Web3 marketing agency optimizing exclusively for Google, their clients are invisible on the AI platform now processing over one billion web searches per week.
The data aggregator myth: ICODA and Semrush’s most disruptive finding
CoinGecko, CoinMarketCap, and DeFiLlama earned zero AI citations across 100+ controlled queries — a result that overturns the most repeated GEO advice in crypto.
ICODA and Semrush jointly ran more than 100 controlled query sessions across ChatGPT and Perplexity, covering four categories: recommendation-style prompts, breaking news queries, safety and legitimacy checks, and community-framed questions. Every citation was captured. The three most trusted data aggregators in crypto — CoinGecko, CoinMarketCap, DeFiLlama — did not appear once across any category or engine.
What did get cited consistently: roundup content, financial media placements, the project’s own site, and community platforms. That result forms the structural core of HackGPT. Generative engine optimization for Web3 isn’t about listing your token everywhere investors look. It’s about building the content infrastructure language models actually retrieve.
HackGPT: Inside the 51-page framework

HackGPT converts AI search theory into an execution roadmap built specifically for crypto — not adapted from a generalist SEO playbook.
Who it’s for: SEO leads, CMOs, and growth teams at DeFi protocols, crypto exchanges, token launches, and iGaming platforms who need measurable AI citation gains — not another content calendar.
The framework maps the full citation lifecycle across ChatGPT, Perplexity, Gemini, and Google AI Overviews, with each tactic tied to platform-specific retrieval behavior. Here’s what the 51 pages cover:
- Citation mechanics: How language models retrieve and weight sources — and why most crypto content fails the retrieval test before it ever reaches an investor
- Platform-specific playbooks: ChatGPT and Perplexity require different content architectures; the guide maps both, plus AI Overviews and Gemini
- Documented results: ICODA made ChatGPT its number-one lead source in four months; a Perplexity optimization effort produced a 286% traffic surge with 779 AI-generated sessions
- New performance KPIs: AI Share of Voice, LLM citation tracking by platform, and conversion segmentation by engine — with a monitoring cadence built for the 70% answer variability rate
The yield math behind the shift is clear: AI-referred traffic converts 23 times better than standard organic. For any crypto marketing agency still measuring success by Google rankings, that figure changes the entire budget allocation conversation.
Why crypto-native agencies lead the generative engine optimization race
Crypto-native Web3 agencies adapt faster to AI citation dynamics because they already understand the trust signals language models apply to blockchain claims.
Generative engine optimization in crypto isn’t only a content challenge. Language models apply stricter evaluation criteria to financial claims — weighting source authority, independent corroboration, and regulatory framing far more heavily than they do for general information queries. A traditional agency building GEO strategy for a DeFi protocol without understanding tokenomics language, MiCA compliance framing, or the credibility signals that distinguish trusted crypto sources from promotional ones is building on the wrong foundation.
ICODA’s 14+ years of crypto-native practice translate directly into GEO execution: which publication ecosystems AI engines weight as authoritative for blockchain topics, how investors phrase their research queries, and which community platforms generate the conversational signals that improve AI search visibility for financial products.
Building the citation architecture: Four layers that actually work
AI search visibility for crypto projects is built across four interconnected layers — and most projects invest in only one.
- Financial media placements: Articles in crypto-native publications that AI engines index as authoritative sources carry higher citation weight than aggregator listings across both ChatGPT and Perplexity. HackGPT maps which outlets by query category.
- Roundup and comparison content: Recommendation-style formats — “best of,” comparisons, ranked lists — are the single most commonly cited content type in crypto AI search responses. The format built for synthesis is the format AI retrieves.
- Community platform presence: Forum threads, crypto subreddits, and Discord discussions generate the conversational citation signals that make ChatGPT treat a project as community-verified rather than brand-promoted.
- Owned content structured for AI parseability: Short paragraphs, direct answers in the opening sentence, and clear heading hierarchies all improve how ChatGPT SEO actually functions at the technical level — the layer most crypto content currently ignores.
The citation channel map
Different AI engines weight different source types — a single-channel strategy captures less than 20% of available citation opportunity.
Citation Channel
Primary Engines
What Drives Citation Weight
Financial media (crypto-native)
ChatGPT, Perplexity
Authority indexing, recency
Roundup & comparison content
All engines
Synthesis-ready structure
Community platforms
ChatGPT
Conversational query match
Owned site (structured answers)
Perplexity, AI Overviews
E-E-A-T signals, directness
Original research and data
ChatGPT, Perplexity
Unique citation anchors
YouTube transcripts
Google AI Overviews
Multiformat entity signals
HackGPT prioritizes these channels by project vertical. DeFi protocols, exchanges, and token sales face different citation competitive landscapes — the framework maps execution by project type, not just content format.
The window is open — and closing
The agencies building AI search visibility now will own the citation landscape before competitors recognize that the terrain has changed.
Gartner projects traditional organic search volume will decline 25% by 2026. AI Overview coverage has expanded from 6.5% to 48% of Google queries inside twelve months, and current trajectory points to 70–80% coverage by year-end. In 53.7% of ChatGPT topic categories tracked by Semrush, no brand dominates yet — that blank space is available, but only temporarily.
Research-backed generative engine optimization can lift AI visibility by up to 40%. ICODA’s own results demonstrate that ChatGPT SEO built on citation architecture — not keyword density — can establish an AI engine as a project’s primary lead source within a single quarter. LLM-referred investors convert at 15.9% on ChatGPT versus 1.76% for Google organic. The audience asking AI assistants which protocol to trust is smaller than Google’s total addressable market, and it is decisively higher-intent.
The competitive question for crypto has shifted from who ranks on Google to who gets cited when an investor asks an AI assistant which project to trust. HackGPT is the answer to the second question.
Crypto World
Circle to Acquire Tazapay in $400 Million All-Stock Payments Deal

Circle has agreed to acquire Singapore-headquartered cross-border payments infrastructure company Tazapay in an all-stock transaction with base consideration of $400 million, a deal that would bring local payout rails and banking relationships inside the USDC issuer’s payments business. Circle… Read the full story at The Defiant
Crypto World
Senate Republicans Update CLARITY Act Before September 15 Vote
Senate Republicans have released updated CLARITY Act text ahead of the September 15 procedural vote, adding new rules for non-decentralized DeFi protocols and clarifying how credit unions can deal in crypto.
The changes reflect weeks of negotiation over the August recess, but they leave untouched the ethics provisions that have stalled Democratic support for the bill.
New DeFi and Credit Union Language
The updated bill requires non-decentralized DeFi protocols, platforms that market themselves as decentralized without actually functioning that way, to register with the Commodity Futures Trading Commission (CFTC).
That requirement mirrors Section 10301 of the Banking Committee’s portion of the bill, although crypto developer Roman Storm questioned the phrasing on X, asking how something billed as DeFi could be “non-decentralized.”
The new text also limits the DeFi provisions to spot or cash digital commodity transactions, a change aimed at addressing concerns some Native American tribes had raised about blockchain-based prediction markets. Credit unions, meanwhile, gained clearer authority to deal in crypto under the revised language.
Republican Senator Cynthia Lummis of Wyoming, who has championed the bill, described the revisions as the product of bipartisan negotiations and wrote that the updated text contains more than 100 changes requested by Democrats.
In another post, she put the figure at more than 115 Democratic “wins,” including a felony bar on fraudsters, $150 million for the CFTC and crackdowns on platforms such as Binance.
“Now they need to vote for the bill they built,” she wrote. “Anything less is walking away from their own work.”
Those changes come just days before the Senate is scheduled to vote on whether to invoke cloture on the motion to proceed. The September 15 vote requires 60 senators, leaving Republicans dependent on Democratic support.
Ethics Talks Remain the Bottleneck
The latest changes do not alter the ethics section or the bill’s stablecoin yield provisions, and that matters because ethics has been one of the biggest obstacles to Democratic support.
Yesterday, Coinbase CEO Brian Armstrong backed a “yes” vote and pointed out that lawmakers had resolved the issues his company previously considered must-have changes. He also described the ethics negotiations as one of the last matters to settle.
Democrats, however, have pushed for provisions requiring elected officials to divest relevant crypto interests or place them in blind trusts. The issue became more urgent after some legislators from that party called for scrutiny into President Donald Trump’s crypto dealings, from which he earned $1.2 billion, including from his Official Trump (TRUMP) meme coin.
However, Lummis has argued that failure to pass the bill would not be because of ethics, but because Democrats refused to accept a bipartisan compromise. Treasury Secretary Scott Bessent, in a September 9 post on X, also urged senators to keep negotiating and advance the legislation.
As things stand, the revised text settles some disputes while leaving the most politically sensitive part of the negotiations unchanged, and the upcoming vote will show whether those compromises are enough to get the bill moving.
The post Senate Republicans Update CLARITY Act Before September 15 Vote appeared first on CryptoPotato.
Crypto World
Health Leaders Talk Expanding Access to Specialty Care

Crypto World
A Chinese humanoid-robot startup flips ‘distillation’ claim on OpenAI
The CEO of an Ant-backed humanoid robotics startup has published a letter to OpenAI in Chinese that raises questions about technical and design similarities between the two companies’ recent models.
“People often say major tech companies have intelligence networks monitoring the whole internet, this time I believe it, this is a direct distillation of us without any modifications,” Guo Renjie, CEO of Suzhou-based JoyIn, said in a public statement Thursday, according to a CNBC translation.
He said the startup had publicly presented its “extraterrestrial visitor” AI model framework in Silicon Valley a few weeks ago, before OpenAI’s Chief Scientist published “An Alien Mind” on Sept. 6. Guo questioned similarities in core technological approaches such as “recursive self-improvement” and the use of AI to optimize computing power.
Guo also highlighted similarities in the outer space-inspired design of OpenAI’s GPT-6 Astra web page and the website for JoyIn’s Aether model that he claimed was released two months ago. He added the startup has started the process of filing a lawsuit.
CNBC was unable to independently verify the claims. Some concepts are existing parts of AI research more broadly, although companies connect and implement them differently. OpenAI did not immediately respond to a request for comment.
U.S.-based Anthropic has repeatedly flagged unauthorized “distillation” of its models by Chinese companies to improve their own AI capabilities. On Tuesday, a U.S. cybersecurity agency said six Chinese companies, including DeepSeek and Alibaba, distilled models from Anthropic, Google and OpenAI.
JoyIn’s Aether model, which Guo said he decided to publicly announce Thursday, claims its perceptive, rather than text-based, approach to robotic control enables humanoids to complete tasks with a 90% success rate on first attempt.
Zhu Mingxuan, who led the model’s development, said she left U.S. humanoid company Figure last year, where she had also worked on models for helping humanoid robots mimic human actions. She told CNBC earlier this week that Aether reduced training time by two-thirds, and that she planned to open-source parts of the model, such as those relating to touch, but not portions related to energy use.
Getting humanoids and AI models to perform as intelligently as humans across a variety of tasks has remained a challenge, amid a broader tech race between U.S. and Chinese companies.
Garry Tan, chief executive of famed startup accelerator Y Combinator, told CNBC this month that he would “do nothing” about distillation and joined others in pointing out that the U.S. companies have trained their AI models on data covered under copyright law.
—CNBC’s Kate Rooney and Isabel O’Brien contributed to this report.
Crypto World
Bitcoin ETF Investors Head for Exit While XRP Funds Stack 3 Wins
Bitcoin (BTC) exchange-traded funds saw a $282.6 million outflow on September 10, marking their third consecutive outflow session. XRP (XRP) funds took in money for a third straight day over the same stretch.
The split shows how differently investors are treating the two products. XRP funds have posted one negative day over their past 20 sessions, while Bitcoin flows continue to swing between heavy buying and heavy selling.
Bitcoin ETF Assets Slide Back Under $98 Billion
Bitcoin funds have handed back $449.4 million across the three sessions, according to SoSoValue. Total net assets fell to $97.49 billion, down from $101.3 billion on September 4.
Cumulative net inflows still sit at $55.17 billion, so the recent selling barely dents the overall picture. However, the pace of the reversal stands out.
The pressure spread to other majors. Ethereum (ETH) products shed $29.8 million on September 10, while Solana (SOL) funds lost $482,547.
Bitcoin’s record over the period reads erratic rather than uniformly weak. The same funds absorbed $730.9 million on September 3, the highest daily inflow since January 14, 2026.
Follow us on X to get the latest news as it happens
XRP Funds Keep Buying While the Price Falls
XRP tells a steadier story. The funds have recorded a single outflow day in their past 20 sessions, a $7.2 million exit on September 2, and collected $190.5 million overall during that run.
Bitcoin logged seven negative days across the same window. Ethereum posted three and Solana four, so XRP’s consistency stands out among the larger crypto ETFs.
Meanwhile, the buying held even as the token weakened. XRP traded near $1.36 on September 10 after falling roughly 2.8% on the day.
Cumulative XRP ETF inflows have reached $1.70 billion since launch, with combined net assets of $1.45 billion.
Smaller products joined in. Chainlink (LINK) ETFs added $4.3 million, and Polkadot (DOT) took $663,057, its first daily inflow since June 8.
The coming sessions will test whether XRP’s drip of buying reflects a distinct, patient holder base or simply a quieter version of Bitcoin’s swings.
Subscribe to our YouTube channel to watch leaders and journalists provide expert insights
The post Bitcoin ETF Investors Head for Exit While XRP Funds Stack 3 Wins appeared first on BeInCrypto.
Crypto World
Brevo Login Flaw Linked to Phishing Attacks on 347K Trezor Users
Brevo, an email delivery platform used across the crypto industry, disclosed that an attacker leveraged a login-system weakness to gain access to multiple client accounts. The incident allowed phishing messages to be sent to a combined audience of roughly 347,000 Trezor newsletter subscribers, with additional campaigns also reaching audiences tied to BitBox and CoinTracking.
In a Thursday postmortem, Brevo said the attacker used six accounts to send phishing emails. It also reported that contacts were exported from 43 accounts, while 93 accounts showed no meaningful activity—though Brevo did not clarify whether those categories overlap. Brevo added that the access-control boundary that should have limited the attacker’s reach to a single organization failed.
Key takeaways
- Brevo reported that an authorization boundary failed after an attacker configured an account with single sign-on and invited real users into the setup.
- At least six Brevo accounts were used to send phishing emails.
- Trezor says the initial phishing email was sent to about 347,000 newsletter customers, and it is treating those addresses as potentially exposed.
- BitBox and CoinTracking also confirmed unauthorized newsletter activity routed through Brevo, though they reported no evidence of lost funds or exposed recovery phrases.
How Brevo’s login flaw enabled cross-account access
Brevo’s postmortem describes a pathway in which an attacker created a Brevo account, turned on single sign-on, and then invited legitimate Brevo users into the configuration. Brevo said the design should have confined access to the organization associated with the configuration, but the authorization boundary did not hold.
As a result, the attacker was able to reach every organization the invited users could access. Brevo’s write-up links the exposure directly to this breakdown in access controls, rather than to a breach of the affected organizations’ own systems.
The incident surfaced publicly after warnings from Trezor and BitBox earlier in the week, which pointed to their shared email provider and explained why the fraudulent emails appeared credible and passed ordinary authentication checks.
Phishing mechanics: what recipients were asked to do
Trezor said the phishing email—titled “Critical Security Alert: STM32 Entropy Vulnerability”—included a link to an app designed to solicit wallet backups. According to Trezor, the company disabled the domain at the DNS level within about 20 minutes. Even with the rapid takedown, Trezor reported that about 2,500 people accessed the link before it was blocked.
Trezor also emphasized the broader risk to its subscriber list. In comments provided to Cointelegraph, a Trezor spokesperson said the initial email was sent to 347,000 customers, and that all recipients were subsequently contacted about the danger.
The spokesperson added: “Until we hear more from Brevo, we are treating all roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing.” Trezor further stated that its Brevo account stored only opt-in newsletter email addresses and no other customer data.
Hardware wallet and crypto services respond: exposure without confirmed credential theft
BitBox told Cointelegraph that its unauthorized email was delivered through Brevo and appeared to reach its full newsletter and tutorial audience.
In its response, BitBox said Brevo held only email addresses and language preferences for it. BitBox reported no evidence of compromised company credentials, no indication that attackers downloaded data beyond the newsletter contacts, and no signs of funds being stolen or recovery phrases disclosed. Still, it said it is treating the list as potentially accessed while awaiting Brevo’s logs.
CoinTracking, meanwhile, reported separate phishing activity. The company said its Brevo account distributed an email titled “Data Breach Notice: Please refresh API Keys as soon as possible.” CoinTracking warned recipients not to click the links in the message, indicating that the main threat was credential-related phishing rather than immediate compromise of underlying systems.
Together, the responses underline a common pattern in third-party email incidents: the most immediate harm may be messaging-based, but the bigger operational concern is whether contact lists can be reused for follow-on attacks.
What Brevo disclosed—and what remains unclear
Brevo’s incident report focuses on the account-access path, but some details remain ambiguous for downstream victims. Brevo said contact exports occurred across 43 accounts and that 93 accounts showed no meaningful activity, without specifying whether those numbers overlap or how many organizations were fully affected end-to-end.
Brevo also did not provide, in the disclosed summary, a precise mapping from the six sending accounts to the different affected crypto companies’ audiences. Cointelegraph attempted to request additional information from Brevo but received no response before publication.
For investors, traders, and builders, the relevance extends beyond the immediate phishing harm: reputable crypto firms rely on email service providers to communicate security alerts, product updates, and documentation. When those communications channels can be abused—especially when phishing content looks authentic—users may face repeated attempts that target them again using addresses already in the attacker’s possession.
Going forward, recipients of such newsletters should be cautious about any unexpected security prompts, verify warnings through official channels, and avoid entering sensitive data into links from unsolicited messages. The core uncertainty now is how thoroughly Brevo’s investigation identifies which organizations’ contacts were exported versus merely accessed, and whether the attacker obtained broader metadata that could support additional phishing campaigns.
Crypto firms and their customers should watch for follow-on updates from Brevo’s incident findings—particularly any clarification on which accounts were used for exports and whether any categories of access overlap—while continuing to educate users to treat “urgent security alerts” sent via newsletter channels as untrusted until verified independently.
Crypto World
Block Seeks OCC Charter for Uninsured Bitcoin and Stablecoin Custody Bank

Block has applied to establish Builders Bank & Trust, N.A., which, if approved, would be an uninsured national trust bank under direct federal supervision, the company said on Sept. 8. The proposed bank would provide custody and related fiduciary services, including for bitcoin and stablecoins,… Read the full story at The Defiant
-
Tech3 days agoMemory prices are slowing because buyers ran out of money
-
Business1 day agoMicron Stock Climbs Above $1,031 as AI Memory Crunch and a $50 Billion Outlook Fuel the Rally
-
Crypto World2 days agoBitcoin price risks $76K drop as $78K support weakens
-
Business1 day agoAMD Stock Climbs After Management Lifts 2027 Data Center Outlook Toward $70 Billion in AI Sales
-
Crypto World2 days agoEthereum price stalls below $2,500 as ADX drops to 11
-
Crypto World3 days agoRobinhood Stock: How To Take Advantage With Reduced Risk
-
NewsBeat2 days agoWhat went right this week: an ‘historic’ fall in violent crime, plus more
-
Crypto World1 day agoBitcoin price risks $70K if $78K neckline breaks
-
NewsBeat3 days agoEngland up in reading, maths and science rankings as Scotland and Wales dip
-
Crypto World3 days agoBrent Crude Oil Moves Above $100 for the First Time in 3 Months
-
Crypto World2 days agoBitcoin price holds near $79K as cycle drawdowns narrow
-
Business2 days agoMeta debuts long-awaited personal AI agent, Muse
-
Sports3 days agoPhones confiscated, players sent home: Pakistan’s England tour turmoil revives memories of Mohammad Amir, Salman Butt and Mohammad Asif’s 2010 Lord’s spot-fixing scandal | Cricket News
-
Crypto World3 days agoIntel Stock Jumps 9% on Chip Price Hike Report, US Stake Gains $36 Billion
-
Crypto World1 day agoEthereum price breakout hinges on a close above $2,535
-
Crypto World3 days agoPump Fun and Kraken delete Hunter Biden $LAPTOP promotion
-
Crypto World3 days agoVisa expands stablecoin card network to 160 programs
-
Tech3 days agoStrong Password Policy and Password Manager Guide
-
Crypto World17 hours ago2 Chip Stocks Broke Out This Week. Neither Was Nvidia
-
Tech2 days agoMeta debuts its Muse AI agent. Will consumers trust it?

You must be logged in to post a comment Login