Connect with us
DAPA Banner
DAPA Coin
DAPA
COIN PAYMENT ASSET
PRIVACY · BLOCKDAG · HOMOMORPHIC ENCRYPTION · RUST
ElGamal Encrypted MINE DAPA
🚫 GENESIS SOLD OUT
DAPAPAY COMING

Crypto World

Collector Crypt Fees Jump 129% in a Week as Solflare Brings Card-Pack Trading Into the Wallet

Published

on

Collector Crypt Fees Jump 129% in a Week as Solflare Brings Card-Pack Trading Into the Wallet


Collector Crypt, the Solana-native platform that tokenizes graded physical trading cards for on-chain trading, posted a 129% week-over-week jump in fee revenue after Solflare embedded its card-pack mechanic directly into the wallet interface. The platform generated $3.86 million in fees over the… Read the full story at The Defiant

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

Binance tests staff monthly with fake phishing attacks

Published

on

Binance Philippines return hits wall as BSP flags license gap

Binance runs simulated phishing attacks against its employees every month to reduce social engineering risks. 

Summary

  • Binance runs monthly phishing simulations to measure employee awareness and identify weak security habits early.
  • Workers who fail receive training, while repeated severe failures can lower ratings and risk dismissal.
  • Recruiter lures and fake conference invitations mirror scams already causing large losses across cryptocurrency firms.

Chief security officer Jimmy Su said the exchange’s red team creates fake attacks to test whether staff recognise suspicious messages, links and requests. Employees who fail must complete follow-up training. Repeated failures can also affect performance ratings and may lead to dismissal.

The programme targets human errors that attackers use to enter crypto companies. Binance has operated the drills for three to four years, according to Su. He said the company’s security habits had improved during that period. Binance reports 323 million registered users, while DefiLlama tracks about $137.5 billion in assets linked to the exchange.

Advertisement

Binance ties phishing tests to staff reviews

The red team uses methods that resemble real attacks. One test may present a fake recruiter offering a job. Another may promise free access to a conference and request personal details. The team records whether employees open the message, follow a link or share information that could expose company systems.

Su said workers who fail receive remedial training. Repeated failure “will negatively impact their rating,” he said. Severe cases may push a worker’s rating to the lowest level and result in dismissal. The policy gives employees a direct work-related reason to verify unexpected messages before responding.

Binance has described its red team as an internal group of ethical hackers that tests systems from an attacker’s point of view. The exchange also works with external researchers through bug bounty programmes. Its security model covers technical weaknesses and employee behaviour because attackers may enter through trusted accounts or devices.

Advertisement

Social engineering drives crypto security cases

The drills come as social engineering causes a large share of reported crypto losses. AMLBot reviewed more than 2,500 investigations and found that 65% of the cases it handled in 2025 began with social engineering rather than direct software exploits. Phishing represented 18% of its cases, while device compromise accounted for 13%.

Attackers often spend days or months building trust before asking a target to open a file, approve a wallet request or run a command. This method can defeat technical controls when a worker has access to private keys, administrator accounts or internal systems. Stolen credentials can lead directly to liquid assets that move across blockchains within minutes.

As crypto.news reported, the April 2026 attack on Drift Protocol drained about $285 million after attackers compromised an administrator key. Researchers linked the breach to social engineering and operational security failures rather than faulty smart contracts. The attacker changed market settings and withdrawal limits before removing assets across dozens of transactions.

Fake meetings and job offers remain common lures

Su identified fake job interviews as one scenario used in Binance’s tests. Real attackers use the same approach against developers, executives and investment teams. They may move a conversation from LinkedIn, Telegram or email into a video meeting, then claim that the victim’s camera or microphone needs an update.

Advertisement

North Korea-linked hackers have used compromised Telegram accounts and deepfake Zoom calls to contact crypto professionals. The attackers impersonated known contacts and asked victims to install files that claimed to fix audio problems. Those files instead delivered malware capable of accessing devices, browser data and crypto wallets.

A Venus Protocol user lost about $13.5 million in September 2025 after approving a malicious transaction. Venus paused its lending platform and recovered the assets through an emergency governance process. The case showed how a user-level compromise can place assets at risk even when a protocol’s contracts remain intact.

Frequent drills aim to reduce predictable errors

Monthly simulations let Binance compare failure rates and update training when attackers change their methods. A single annual course may not prepare staff for new lures built around current events, trusted contacts or job offers. Frequent tests also show whether workers report suspicious messages instead of only deleting them.

However, simulations cannot remove every risk. Attackers can hijack genuine accounts, copy earlier conversations and use artificial intelligence to create convincing audio, video and written messages. Firms still need access controls, transaction limits, device monitoring and fast incident response alongside employee training.

Advertisement

Su said Binance’s early security habits “left a lot to be desired,” but repeated testing brought improvement. The exchange treats staff awareness as part of its wider defence system rather than a one-time compliance task. Employees still need to verify unusual requests through a separate channel before opening files, sharing information or approving transactions.

Source link

Advertisement
Continue Reading

Crypto World

Wise turns to GENIUS Act after OCC rejects U.S. bank charter

Published

on

Wise turns to GENIUS Act after OCC rejects U.S. bank charter

Wise plans to submit a new application for a U.S. national trust bank charter under the GENIUS Act after the Office of the Comptroller of the Currency rejected its first bid.

Summary

  • Wise plans a fresh U.S. charter application under the GENIUS Act after the OCC rejection.
  • The OCC cited weak AML controls, management gaps, and limited national banking experience in denial.
  • William Blair expects Wise to remain rail-agnostic rather than make stablecoins its core business model.

The July 21 decision ended the payments company’s effort to create Wise National Trust in Austin, Texas. Wise disclosed the outcome on July 24 and said its current U.S. services continue without change. The company still operates through money-transmitter licences across 48 states and four territories.

The new filing will use the federal framework for payment stablecoins rather than the structure in Wise’s original June 2025 application. Wise said the earlier plan relied on access to Federal Reserve payment systems that is no longer practical. Its London-listed shares fell as much as 10% after the denial became public. Wise said it had strengthened financial-crime controls since filing the original plan and would address the regulator’s findings in its next submission.

Advertisement

OCC rejects Wise application over compliance concerns

The OCC’s decision said Wise did not show that the proposed trust bank could meet U.S. legal and regulatory requirements. The regulator focused on weaknesses in anti-money laundering and countering the financing of terrorism controls. It also said Wise U.S. had a record of failing to meet rules that apply to money services businesses. The proposed bank planned to rely heavily on Wise U.S. and other group companies for compliance work.

The regulator also questioned the experience of the proposed directors and managers. It said the team did not show enough knowledge of national banking rules, fiduciary services, or AML/CFT operations. Wise National Trust had planned to offer multi-currency stored-value accounts, payment processing, and fiduciary services. The OCC stated that approval would conflict with its charter policies. However, the decision does not stop Wise from filing another application after addressing the issues.

Wise shifts its plan toward the GENIUS Act

Wise gave a separate reason for changing course. The company said the Federal Reserve has generally paused account access for uninsured trust banks while it develops a new payment-account policy. “With the Federal Reserve generally pausing account access for an uninsured trust bank, the approach in our application became non-viable,” Wise said. The original plan aimed to let Wise settle U.S. dollar payments more directly and reduce its reliance on partner banks.

Wise now plans to apply under the GENIUS Act, which created a federal licensing and supervision system for payment stablecoin issuers. The company has not said it will launch its own stablecoin. William Blair analysts also said they do not expect a major change in Wise’s position. They described the company as “agnostic of the rail,” meaning it remains focused on lowering cross-border payment costs whether transfers use traditional systems or digital assets.

Advertisement

Stablecoin rules remain unfinished

The GENIUS Act became law in July 2025. It sets reserve, redemption, reporting, consumer protection, and compliance requirements for approved payment stablecoin issuers. The law is due to take effect on January 18, 2027, or 120 days after regulators publish final rules, whichever comes first. The OCC published its main proposed rule in March, while Treasury later proposed AML and sanctions standards.

Final rules were still pending when Wise announced its new plan. As crypto.news reported, regulators missed the July 18 rulemaking deadline, leaving key details unresolved. Wise will need to explain what activities its new entity would conduct, how it would use stablecoins, and how it would meet the stricter AML/CFT standards planned for permitted issuers. A new application must also explain how the charter would work without the unrestricted Federal Reserve access assumed in the earlier model.

Wise joins a wider U.S. charter race

Wise is entering a crowded federal licensing process. The OCC has approved several digital asset companies for national trust charters during the past year.Circle received final approval in July 2026 after gaining conditional approval in December. Ripple, Paxos, BitGo, Fidelity Digital Assets, Crypto.com, Bridge, and Coinbase have also received conditional decisions or entered the process.

The approvals have drawn opposition from banking groups and some lawmakers. Crypto.news reported that the Bank Policy Institute retained outside lawyers while considering a challenge to the OCC’s trust-charter policy. Wise’s case differs because the regulator issued a direct denial tied to its compliance record and management plan. The new GENIUS Act filing may offer a different route, but it will still require Wise to satisfy the OCC’s standards before gaining a charter.

Advertisement

Source link

Continue Reading

Crypto World

BitMart shuts down trading as BMX crashes more than 60%

Published

on

BitMart shuts down trading as BMX crashes more than 60%

BitMart has started a phased shutdown of its global cryptocurrency exchange after reviewing its operating conditions, market environment, and future strategy. 

Summary

  • BitMart stopped new registrations, deposits, and orders before ending all trading services on August 26.
  • BMX lost about 63% in 24 hours as traders reacted to the exchange’s shutdown announcement.
  • Withdrawals remain available, but BitMart advised users to submit requests before August 26’s recommended deadline.

According to the official shutdown notice, the exchange stopped new registrations, cryptocurrency and fiat deposits, and new spot orders from 01:30 UTC on July 26. Futures accounts entered reduce-only mode, while copy trading, grid trading, API trading, and other automated services began winding down.

The exchange will end all spot, futures, and other trading services at 01:00 UTC on August 26. However, the full platform will not close on that date. BitMart plans to terminate trading-platform operations at 15:59 UTC on January 31, 2027. Users will retain limited account access for a period after that date to review records and submit withdrawals.

Advertisement

BitMart sets withdrawal and position deadlines

BitMart told users to close all positions before 01:00 UTC on August 26 and recommended submitting withdrawals before 05:00 UTC the same day. Withdrawals remain open, but requests may face identity, source-of-funds, wallet ownership, sanctions, Travel Rule, and security reviews. Heavy demand or network congestion may extend processing times.

Advertisement

The exchange asked customers to cancel open orders, redeem eligible Earn, staking, and lending products, and download account records. BitMart may settle any futures positions still open when trading ends using its mark price, index price, or other applicable rules. Users who miss the recommended withdrawal period will enter a separate process that BitMart plans to explain later.

BMX falls as traders react to the shutdown

BMX, the exchange’s platform token, fell by around 63% during the 24 hours surrounding the announcement. BitMart’s own market page showed a decline of about 64.9% at one stage, while CoinGecko’s BMX page placed the token near $0.164 on July 26 with about $6.1 million in daily volume. The sharp move reflected the token’s close link to exchange activity.

BMX provides trading-fee discounts and other platform benefits. The planned end of trading removes much of that direct use. Price readings varied across trackers because the market moved quickly and platforms used different update times. CoinGecko data placed the token’s market value near $55.6 million on July 26, down from more than $100 million earlier in the week.

Closure follows recent service restrictions

BitMart did not identify a single event behind the shutdown. Its notice referred only to “operating conditions, market environment, and future strategic direction.” The exchange did not state that it had entered insolvency, and it did not connect the decision to a security incident, regulatory order, or lack of customer assets. Users therefore still lack a detailed financial explanation.

Advertisement

The decision followed several service changes. BitMart suspended its automated market-making bot on July 24 and returned users’ principal and earnings to spot accounts. It also ended spot margin trading, with forced liquidation scheduled for July 26. On July 23, the exchange told remaining U.S.-linked users to close positions and withdraw by August 8 during a compliance review.

BitMart follows other crypto platform closures

The announcement came three days after BitMEX said it would close its derivatives exchange on September 23 following a strategic review. BitMEX stopped new registrations and set August 26 as the date when customers could no longer open new positions. Odos also announced plans to shut its decentralized exchange aggregator on July 30, although the platforms gave different reasons and timelines.

BitMart entered the market in 2017 and grew through a wide selection of smaller tokens. A 2021 Series B round led by Alexander Capital Ventures valued the company at more than $300 million. Fenbushi Capital had made an earlier investment in 2019. Days after the Series B announcement, attackers compromised two hot wallets and stole assets valued at about $150 million by BitMart, while outside estimates reached $196 million.

BitMart said at the time that it would use its own funds to compensate affected customers. The shutdown notice did not link the wind-down to that breach, which occurred nearly five years earlier. In May 2026, BitMart said “all platform operations are running normally” while responding to online concerns about withdrawals and risk controls. It also said it planned to publish proof of reserves after completing security preparations.

Advertisement

The exchange now warns that scammers may exploit the shutdown. BitMart said it will not charge an expedited withdrawal fee or ask for passwords, two-factor codes, private keys, or recovery phrases. It advised users to rely on its official website, app, registered emails, and support system. Customers must also check networks and addresses before transferring funds.

Source link

Advertisement
Continue Reading

Crypto World

BMX Token Crashes 46% as BitMart Announces Exchange Wind Down

Published

on

BitMart Token (BMX) Price Performance

Cryptocurrency exchange BitMart will shut down its trading platform, beginning an orderly wind-down on Sunday.

The announcement sent BitMart Token (BMX) tumbling, with the exchange token posting double-digit losses over the past 24 hours. The platform urged users to close positions and withdraw assets without delay.

BitMart Sets a 6-Month Runway Before Full Closure

BitMart attributed the decision to a review of its operations, market conditions, and future strategic direction.

“BitMart has made the difficult decision to commence an orderly wind-down of its trading platform operations. We deeply regret having to make this decision,” the team said.

Follow us on X to get the latest news as it happens

Advertisement

The notice sets a staged timeline. The platform suspended new registrations, deposits, and orders on July 26, 2026, at 01:30 UTC.

Futures accounts switched to reduce-only mode on July 26. Spot trading also stopped accepting new orders that day.

Copy trading, grid trading, and API trading services are being discontinued in phases. Earn, staking, lending, and Launchpad products will wind down under their own schedules.

Advertisement

All spot, futures, and other trading ends at 01:00 UTC on August 26. Platform operations then cease entirely at 15:59 UTC on January 31, 2027.

The exchange asked users to complete identity verification and close positions before that August deadline. It also asked users to submit withdrawal requests by 05:00 UTC on August 26, 2026.

BMX Slides as Exchange Closures Pile Up

The market reaction was immediate. BMX traded near $0.11016 on Sunday, down 46.08% on the day.

That leaves it roughly 82% below its record high of $0.61905, reached on June 5, 2024.

Advertisement
BitMart Token (BMX) Price Performance
BitMart Token (BMX) Price Performance. Source: BeInCrypto Markets

The closure arrives just days after BitMEX told users it would end operations on September 23. Two established venues are therefore exiting within the same week.

Users now have one month to exit positions before trading stops on BitMart.

Subscribe to our YouTube channel to watch leaders and journalists provide expert insights

The post BMX Token Crashes 46% as BitMart Announces Exchange Wind Down appeared first on BeInCrypto.

Advertisement

Source link

Continue Reading

Crypto World

North Korea hackers scan crypto wallets through fake Zoom calls

Published

on

Consensys halts releases after North Korea-linked developer gains access

  • BlueNoroff scans browser wallets before deciding which fake meeting targets should receive its malware payload.
  • Hijacked Telegram accounts help attackers contact trusted industry peers and extend the campaign through victims.
  • The phishing kit supports Windows and macOS, stealing browser keys, system data, and Telegram sessions.

North Korea-linked hacking group BlueNoroff is using fake Zoom and Microsoft Teams meetings to profile cryptocurrency users before delivering malware. 

Cybersecurity firm JUMPSEC said it recovered and analysed source code from an active phishing kit after its operators exposed JavaScript source maps on live infrastructure. The files showed separate Zoom and Teams lures, wallet-scanning tools, operator controls and malware delivery paths for Windows and macOS.

The attack often begins through a Telegram account that the target already trusts. The hackers take over accounts belonging to crypto contacts, then send a Calendly invitation that leads to a lookalike meeting domain. JUMPSEC described the system as a repeatable victim pipeline because one stolen Telegram session can help the attackers contact the next group of targets.

BlueNoroff checks crypto wallets before sending malware

The phishing page starts scanning the browser when a user enters the fake meeting. It looks for Ethereum wallet connections through EIP-6963 and older browser methods. It also checks for non-EVM wallets, including Solana tools. The results reach an operator panel without alerting the victim. This lets the attackers identify wallets and choose higher-value targets before pushing the next stage.

Advertisement

On Windows, the implant also lists extension IDs across Chrome, Edge, Brave, Opera, Vivaldi and Firefox variants. Operators can compare those IDs with known wallet extensions such as MetaMask. JUMPSEC called this a system that profiles wallets “before malware delivery.” The method differs from broad phishing campaigns because the attackers gather wallet data before deciding how far to take the intrusion.

Fake Zoom and Teams calls build trust

Victims first see a convincing meeting page that requests their name and webcam access. The site then sends the camera stream to the attacker’s control panel. After the victim joins, the screen shows “waiting for other participants.” An operator can enter with a prepared video, send messages such as “your mic isn’t working,” and trigger a fake “Zoom SDK Update” prompt.

JUMPSEC found that the displayed participant video was not live. The attackers combined AI-generated headshots with body movements captured in earlier meetings. They could then show a familiar-looking person while using a Telegram account that belonged to a real contact. The Teams version included emoji reactions, device settings, background effects and wider wallet checks, making it more polished than the Zoom kit. The source code also contained an unfinished Google Meet option. JUMPSEC said Zoom and Teams suit the lure because both use desktop clients, making an urgent software update appear more credible.

Malware targets both Windows and macOS

On Windows, the copied ClickFix command runs a small PowerShell loader. It downloads a VBScript, adds a Microsoft Defender exclusion and restarts Defender so the change takes effect. The implant gathers system details, checks browsers for wallet extensions and looks for Telegram Web files. It can also receive later payloads from the operators, although JUMPSEC did not recover every final-stage file.

Advertisement

The macOS path downloads a fake Zoom or Teams installer while a stealer runs in the background. Researchers found versions that collected system information and Chrome master keys from Apple’s Keychain. The malware sent data through a Telegram bot and could download another payload. JUMPSEC traced four macOS variants between April 22 and July 15, showing that the operators kept changing the toolkit during the campaign.

Campaign builds on earlier crypto meeting scams

The findings expand earlier research into BlueNoroff’s fake meeting operations. In April, Arctic Wolf reported more than 80 lookalike Zoom and Teams domains and identified 100 additional targets whose media appeared on attacker infrastructure. It said 80% of the identified targets worked in crypto, blockchain finance or related investment sectors, while founders and chief executives made up 45%.

North Korean attackers had already used compromised Telegram accounts, spoofed meeting invitations and fake software updates to target crypto executives. Another crypto.news report described a related macOS campaign that asked victims to run commands during fake calls. Earlier coverage of NimDoor malware also linked fake Zoom updates to theft attempts against browser credentials, wallet data and Telegram files.

The latest kit gives operators direct control over the pace of each meeting and the malware prompt. JUMPSEC advised organisations to treat meeting links from trusted accounts with care because the sender’s account may already be compromised. Crypto teams can verify unusual invitations through another channel, avoid commands or updates presented during calls, revoke exposed Telegram sessions and isolate any device that ran the requested script. Teams should also review PowerShell activity, Defender exclusions, Keychain access and new Telegram logins after any suspect call. A password reset alone may not remove stolen sessions or malware already running on the device across affected systems.

Advertisement

Source link

Continue Reading

Crypto World

Uniswap launches Permissioned Pools for compliant onchain trading

Published

on

Uniswap records largest UNI burn as Hayden Adams backs DeFi

Uniswap Labs has launched Permissioned Pools on Uniswap v4, adding onchain access checks for regulated assets that cannot trade freely between every wallet. 

Summary

  • Permissioned Pools check issuer-managed allowlists before swaps or liquidity actions can proceed through Uniswap v4.
  • Superstate, Securitize, and Dowgo helped build compliant trading infrastructure for tokenized funds, equities, and securities.
  • Regular Uniswap v4 pools remain permissionless, giving developers a separate option for restricted regulated assets.

The open-source hook standard lets approved users swap tokenized funds, securities, equities and other restricted assets through automated market maker pools. Uniswap announced the product on July 23, 2026, after working with firms that issue and manage regulated onchain assets. It keeps issuer compliance controls visible and enforceable onchain.

Launch partners include Superstate, Securitize and Dowgo. Each partner helped shape parts of the standard or its compliance links. The launch does not change regular Uniswap v4 pools. Those pools remain permissionless, while issuers can choose the restricted format when an asset requires identity checks, transfer rules or investor eligibility controls.

Advertisement

How Uniswap Permissioned Pools work

Permissioned Pools check an issuer-managed allowlist before every swap. The hook also checks the list before a user creates a liquidity provider position. When a wallet lacks approval, the transaction cannot continue. The issuer controls the list and its rules, rather than Uniswap or a public interface. Uniswap said the checks run “at the protocol level, not on the frontend,” which makes the restriction part of the pool’s smart-contract process.

The design uses Uniswap v4 hooks, which let developers add custom instructions to a pool at set points in a transaction. It also uses v4 virtual accounting to calculate exchanges while the regulated assets remain inside a permissioned contract. Approved traders still use an AMM instead of a traditional order book. Liquidity providers supply the assets, while the pool’s code handles pricing and settlement under the issuer’s access rules.

Launch partners connect regulated assets to AMMs

Superstate joined as an early design partner and helped develop the format for tokenized equities and funds. The company issues onchain financial products and operates services for tokenized funds and company shares. Its July 23 update said the standard could connect eligible tokenized equities with AMMs, lending markets and other approved financial applications.

Advertisement

Securitize worked with Uniswap Labs before the wider standard launched. The firms focused on making assets issued through Securitize’s DS Protocol compatible with compliant onchain trading. Dowgo contributed an ERC-3643 integration, a token standard that supports identity checks and transfer controls. Uniswap said Dowgo plans to use Permissioned Pools after it receives DLT TSS authorisation under the European Union’s DLT Pilot Regime. Dowgo says its application remains under review by France’s ACPR.

Regular Uniswap v4 pools remain permissionless

The new system applies only when an issuer or developer deploys a Permissioned Pool for a selected asset. It does not add a general identity check to Uniswap v4. Developers can continue creating standard pools without asking Uniswap Labs for approval, and users can continue accessing those pools under the protocol’s existing rules.

This split gives regulated issuers a separate route to AMM liquidity without turning the wider protocol into a closed trading venue. Uniswap said developers can choose either model: build permissionlessly on v4 or deploy a restricted pool for an asset with legal transfer conditions. The issuer remains responsible for the allowlist and investor access, while the hook enforces those decisions during swaps and liquidity actions.

Tokenized asset growth raises demand for compliance controls

Permissioned Pools follow Uniswap’s June rollout of tokenized securities across its web app, wallet and API. That earlier update gave eligible users access to blockchain-based products linked to companies such as Apple, Nvidia and Tesla. Uniswap warned that some products may not represent direct ownership and may face KYC, transfer or geographic restrictions. The new pool standard gives issuers another way to enforce such rules directly in trading infrastructure.

Advertisement

Uniswap cited an estimate that the tokenized asset market could reach $11 trillion by 2030. Current figures remain far below that forecast. As crypto.news reported, tokenized real-world assets stood near $34 billion in May 2026, including about $1.55 billion in tokenized equities. Related coverage also found that transfer agents often control wallet allowlists and the official ownership records behind tokenized securities.

Regulators continue to examine how these products protect ownership and shareholder rights. As previously reported, the U.S. Securities and Exchange Commission delayed a proposed tokenized-stock exemption after exchanges raised questions about investor safeguards and record keeping. Securitize chief executive Carlos Domingo said any framework should “apply to the right instruments.” Permissioned Pools address transaction access at the smart-contract level, but each issuer must still follow the securities laws and licensing rules that apply to its product and market.

Source link

Advertisement
Continue Reading

Crypto World

Upbit expands KRW market with two major DeFi token listings

Published

on

Upbit lists Derive (DRV) with KRW, BTC and USDT trading pairs

Upbit has added Morpho (MORPHO) and Euler (EUL) to its Korean won market, expanding direct KRW trading for two Ethereum-based decentralized lending projects in Korea. 

Summary

  • Upbit added MORPHO and EUL KRW pairs, giving traders access to two DeFi lending tokens.
  • Euler’s KRW trading launch moved to 2:00 p.m. KST, two hours later than initially scheduled.
  • EUL gained about 74% before launch, while MORPHO posted a smaller rise and heavier volume.

MORPHO/KRW opened on July 25 at 6:00 p.m. KST, while Upbit planned EUL/KRW for July 26.

However, Upbit changed Euler’s launch timetable shortly before trading. The exchange moved the start from 12:00 p.m. to 2:00 p.m. KST on July 26. The notice said, “The trading support start time for EUL will change.” Deposits and withdrawals for both assets remain limited to the Ethereum network. The listings also broaden access beyond existing BTC and USDT pairs already available for both assets on Upbit.

Advertisement

Upbit delays EUL trading after adding the KRW pair

Upbit did not give a detailed reason for the two-hour delay. Its notice said trading may start later when the exchange has not secured enough liquidity. The platform had already created the EUL/KRW market page, but users still had to follow the revised 2:00 p.m. KST start time.

The exchange also placed temporary controls on the launch. Upbit will block buy orders for about five minutes after trading begins. During the same period, it will restrict sell orders priced more than 10% below the previous closing price. For roughly two hours, users may place limit orders only. Upbit set the reference close at 0.00003019 BTC, equal to 2,845 won in its notice.

EUL price surges before the scheduled Upbit launch

EUL recorded the stronger market response. At the time of writing, Binance data placed the token near $2.22, up about 74% over 24 hours, with trading volume above $200 million. CoinMarketCap data also linked the move to the Upbit listing and reported a sharp rise in volume before the KRW market opened.

The reaction follows earlier cases in which Korean won listings drove fast changes in EUL trading. As crypto.news reported in September 2025, EUL rose more than 30% after Bithumb announced a KRW pair. The token had also gained after Coinbase added it to its asset roadmap in July 2025. Those earlier moves show that new exchange access can quickly change short-term demand, although gains can reverse when initial activity slows.

Advertisement

Morpho gains another route to Korean won liquidity

Morpho’s KRW pair opened a day earlier. Upbit scheduled MORPHO/KRW trading for 6:00 p.m. KST on July 25 and supported deposits and withdrawals through Ethereum only. Market trackers recorded a smaller price move than EUL, but they also showed a sharp increase in MORPHO trading volume after the announcement.

MORPHO traded near $1.95 on July 26, up about 1.5% over 24 hours. CoinGecko placed its market value above $1.2 billion and reported that daily volume had increased by more than 400% from the previous day. The listing adds a direct won pair for a token that Upbit already offers in its BTC and USDT markets.

The new KRW access also follows a series of Morpho product and funding updates.Morpho launched Midnight on Base in July, offering fixed-rate and fixed-term lending. The network said it held more than $11 billion in deposits. In June, Morpho raised $175 million from investors including Paradigm, a16z Crypto and Ribbit Capital, with the transaction reportedly valuing the project at about $2 billion.

Upbit backs two modular Ethereum lending protocols

Morpho and Euler both provide infrastructure for onchain lending, but they use different systems. Morpho lets developers and asset managers create lending markets and vaults with selected collateral, risk settings and interest models. MORPHO supports governance and other functions across the network.

Advertisement

Euler v2 uses modular vaults that users and developers can build for different lending markets. Its Euler Vault Kit supports the creation of vaults, while the Ethereum Vault Connector can link positions across compatible vaults. EUL serves governance, rewards and fee-related functions within the protocol.

Euler rebuilt its platform after a 2023 exploit drained about $197 million from its earlier version. The attacker later returned most of the funds. As crypto.news previously reported, Euler expanded through v2 and later launched on networks including Sonic. The protocol reported more than $2 billion in total borrowing and about $4 billion in deposits by October 2025.

Upbit’s back-to-back MORPHO and EUL listings give Korean traders new won-denominated access to two lending protocols. However, the fast EUL price rise and the exchange’s opening controls point to high volatility around the launch. Upbit advised users to confirm the Ethereum network and token contract before sending funds, because unsupported deposits may require a long return process.

Advertisement

Source link

Continue Reading

Crypto World

Bitcoin Miner Poolin Files Bankruptcy, Seeks $52M Texas Asset Sale

Published

on

Singapore-based Bitcoin mining company Poolin on July 22 filed for Chapter 11 bankruptcy protection in New Jersey, alongside its US affiliates Lonestar Dream Inc. and Lonestar Taproot LLC. The firm is also looking for court approval for a $52 million sale of its Texas mining properties.

The bankruptcy filing comes nearly four years after Poolin froze customer withdrawals, leaving thousands of wallet users with IOU tokens and turning a mining business failure into a long-running creditor dispute.

Poolin Enters Chapter 11 With $173 Million in Liabilities

Court records filed in the US Bankruptcy Court for the District of New Jersey show Poolin listed between 10,001 and 25,000 creditors, with petition assets estimated between $1 million and $10 million.

Chief Restructuring Officer Michael DuFrayne’s declaration placed prepetition obligations at about $173.1 million, with roughly $163.7 million tied to unsecured IOUs issued to Poolin Wallet customers.

Advertisement

The company’s current bankruptcy case is focused on selling its Texas assets rather than rebuilding its mining operations. Lonestar Dream stopped mining and hosting activities at its Pyote and Tarbush sites on July 10, according to the filing documents.

Poolin has entered asset purchase agreements with Thor CALAP LLC for a combined $52 million stalking-horse bid. The offer includes $15 million for the Pyote property and associated power rights and equipment, plus $37 million for Tarbush power rights and equipment. The deal remains subject to competing bids and court approvals.

The company spent more than three months marketing the asset, contacting over 335 potential buyers, including cryptocurrency miners and artificial intelligence and high-performance computing operators. The process resulted in 28 confidentiality agreements, seven letters of intent and three additional expressions of interest.

Poolin’s Texas expansion struggled after the company moved mining operations from China as Beijing imposed a ban on mining in the year 2021. It expected to receive up to 600 megawatts of power, but only 100 megawatts were made available. This meant the equipment the firm had bought for its US run ended up being more than was necessary.

Advertisement

Some of that equipment was sold, resulting in a loss of $8.8 million from fiscal year 2023 to 2025. In the end, Lonestar Dream and Lonestar Taproot accumulated about $45.9 million in losses.

The Collapse of Poolin Wallet Remains Central to Creditor Claims

Poolin’s financial problems go beyond mining, as back in June 2022, when Bitcoin fell below $20,000, it triggered margin calls from Tether against collateral the firm had pledged through the Poolin Wallet. It then transferred almost all of that collateral to Antalpha and borrowed about $213 million against crypto assets valued at just under $356 million.

However, in September 2022, Poolin Wallet suspended withdrawals and issued around $163.7 million worth of IOU tokens to customers, with about 11,700 wallet users holding balances above $100, according to the filing.

Bitcoin later fell below $16,800 in November 2022, after which Poolin ceased operations, and Antalpha liquidated the collateral. Management estimated that about $260 million was owed to Antalpha against digital assets valued near $265 million at the time.

Advertisement

Poolin was once one of the largest Bitcoin mining pools globally, reaching roughly 14% of the Bitcoin network’s mining share in 2019. However, the company’s remaining value now depends on the Texas asset sale and the outcome of the bankruptcy process.

The court-supervised auction will determine how much creditors recover, and any distribution will depend on competing bids, sale expenses, administrative claims, and approval of the proposed liquidation plan.

The post Bitcoin Miner Poolin Files Bankruptcy, Seeks $52M Texas Asset Sale appeared first on CryptoPotato.

Source link

Advertisement
Continue Reading

Crypto World

Binance Details Staff Phishing Campaigns to Counter Social Engineering

Published

on

Crypto Breaking News

Binance says it has been running internal, simulated phishing attacks against its own staff for several years—testing how well employees resist social engineering attempts and tying repeat failures to remediation training and performance consequences. The exchange’s chief security officer, Jimmy Su, described the program as a way to measure whether “security hygiene” is improving inside a growing organization.

Su told Cointelegraph that Binance’s internal red team performs phishing simulations on a monthly basis. Employees who fail receive remediation training, while continued poor performance can affect their performance review ratings and, in extreme cases, lead to dismissal.

Key takeaways

  • Binance conducts monthly phishing simulations via an internal red team, according to its chief security officer Jimmy Su.
  • Failed phishing tests are followed by remediation training, aiming to improve employees’ security habits over time.
  • Results can influence performance reviews; repeated failures may lower ratings to the point that employment risk increases.
  • Su says Binance has run these simulated attacks for roughly three to four years, with security hygiene improving compared with earlier stages.
  • The described tactics reflect broader industry risk: social engineering continues to be a major driver of crypto security incidents.

How Binance tests resistance to social engineering

Binance’s approach centers on realism: the red team acts as an attacker to probe the company’s human layer, not just technical controls. Su said the simulations are designed to show whether employees have become more vigilant over time, adding that the program has been running for about three to four years.

“We do phishing attacks on our own employees on a monthly basis just so we understand if our security hygiene is improving,” Su told Cointelegraph. The goal, he said, is to spot weaknesses early—before malicious actors can exploit them in real incidents.

“The ones that have failed it, we will do remediation training.”

Su also said that early on, security hygiene “left a lot to be desired.” But after continuing the internal testing for a sustained period, Binance has seen meaningful improvement. That long-running cadence matters because human error is rarely solved through a one-time training session; it often requires repeated exposure, feedback, and accountability.

Advertisement

Escalating accountability: training and performance reviews

Binance’s internal program isn’t only about education—it’s also about incentives. Su stated that employees are encouraged to perform well because simulation results are reflected in performance reviews.

“If someone repeatedly fails the phishing-simulation attack, that will negatively impact their rating. That’s the incentive to be vigilant.”

He added that repeated, severe failures could cause a person’s rating to “bottom out,” which could ultimately lead to dismissal. While exact thresholds or timelines were not specified, the direction is clear: Binance treats recurring susceptibility to phishing as a measurable risk rather than a purely training-based issue.

For employees and managers, this changes the information security conversation. Instead of treating phishing defenses as optional training, the simulations become part of how the organization assesses readiness—suggesting a shift toward continuous security evaluation.

The tactics: recruiter lures and Zoom-style schemes

Su described at least one scenario used in the red team’s simulations: the team poses as job recruiters. That reflects a common pattern in real-world phishing—using credible context and urgency to lower an employee’s guard, especially when the target might be inclined to respond to hiring-related messages.

Advertisement

He also referenced well-known social engineering techniques that have circulated widely in the crypto ecosystem, including “Zoom meeting attacks,” in which attackers try to get victims to install malware disguised as a meeting update. These attacks often begin with a lure such as a fake job opportunity, and they can also use other hooks like proposed funding or partnerships.

The Binance description aligns with incidents seen across the sector. Earlier coverage cited by Cointelegraph notes that AMLBot estimated that 65% of crypto security incidents in 2025 were driven by social engineering. Separately, a major hack suffered by Drift Protocol in April was described as following a long-term social engineering campaign.

One example of the “Zoom client” pattern occurred in September 2025, when a major Venus Protocol user reportedly lost around $13 million after a malicious Zoom client compromised their computer and granted an attacker control over their account. Venus paused the protocol and used an emergency governance vote to recover the assets, later returning positions worth $11.4 million to the victim, according to the related Cointelegraph reporting referenced in the original article.

Why internal phishing testing is becoming standard in crypto

Binance’s public discussion of internal simulated phishing comes at a time when social engineering is widely recognized as a persistent—and often underestimated—attack surface in digital-asset businesses. The reason these programs can matter is that even sophisticated security stacks cannot fully prevent compromise if employees can be tricked into revealing access, installing malware, or granting approvals.

Advertisement

Binance is also operating at a scale where human processes can become especially important. The exchange says it has 323 million registered users, and DefiLlama estimates Binance holds $137.7 billion in assets. In environments this large, attackers have strong incentives to focus on the easiest pathway to access—often the human decision layer.

Su indicated that Binance has treated phishing resilience as an ongoing operational discipline rather than a compliance box. He described scenarios that include collecting personal information through seemingly benign interactions, such as offering free conference invites as a way to see how many targets would share details.

That emphasis on varied lures is an important point for investors and operators watching the sector: attackers adapt, and defensive training must adapt too. Simulations that only teach one “shape” of attack can become outdated quickly, while programs that rotate scenarios help test whether employees can recognize patterns rather than memorize scripts.

What readers should watch next is whether other major exchanges and custody platforms adopt similar accountability-driven simulation programs—and, crucially, whether regulators and internal auditors begin to treat phishing resistance testing as a measurable control rather than a general training activity.

Advertisement

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Source link

Advertisement
Continue Reading

Crypto World

Sberbank sets Dec. 1 deadline for Russia crypto trading launch

Published

on

Sberbank sets Dec. 1 deadline for Russia crypto trading launch

Sberbank plans to launch cryptocurrency trading infrastructure and a digital depository by Dec. 1, 2026.

Summary

  • Sberbank plans to launch regulated crypto trading, custody, settlement, and depository services by December 1.
  • Russia’s new crypto framework starts September 1, with licensing compliance required by July 1, 2027.
  • Non-qualified investors may buy up to 300,000 rubles yearly after passing a mandatory knowledge test.

The system will support regulated crypto trading, custody and settlement for eligible customers in Russia.

The project follows the approval of new rules covering crypto exchanges, brokers, banks and digital depositories. Russia will introduce the wider regulatory framework on Sept. 1, 2026, while companies will receive additional time to meet licensing requirements.

Advertisement

Sberbank plans digital custody and off-chain records

According to Interfax, Sberbank’s digital depository will record customers’ cryptocurrency ownership and account for many transactions outside public blockchain networks. The bank will also manage active wallets for deposits, withdrawals and transfers.

Alexander Vedyakhin, Sberbank’s first deputy chairman, said the bank intends to complete the required systems before the December deadline.

“Sber plans to implement the necessary infrastructure and launch the digital depository by Dec. 1, 2026.”

Advertisement

Sberbank has not yet named the cryptocurrencies that its platform will support. The bank has also not disclosed fees, customer eligibility rules or withdrawal limits. These details may depend on supporting regulations that Russian authorities still need to approve.

Under the planned structure, customers could hold recorded crypto rights inside Sberbank’s system. The bank would then use its controlled wallets when customers deposit, withdraw or transfer assets to external addresses.

Russia introduces rules for investors and intermediaries

The Bank of Russia said the new framework will allow qualified and non-qualified investors to purchase cryptocurrencies through regulated intermediaries. However, different limits will apply to each group.

Non-qualified investors must pass a knowledge test before buying eligible cryptocurrencies. They may purchase up to 300,000 rubles of crypto each year through one intermediary. Public access will focus on assets that meet liquidity and market-size standards set by regulators.

Advertisement

Qualified investors must also complete testing, but they will have access to a wider range of assets without the same annual limit. Banks, brokers and asset managers may offer services under their existing licences and added crypto requirements.

Meanwhile, new cryptocurrency exchanges and digital repositories will require separate approval. The Bank of Russia will supervise the market and set standards for custody, accounting and customer protection.

Russia will continue to prohibit cryptocurrency payments for goods and services inside the country. However, companies may use crypto for approved cross-border settlements. Residents may also need to report some foreign crypto holdings and transactions to tax authorities.

The framework takes effect on Sept. 1, 2026. Companies covered by the new rules will have until July 1, 2027 to secure licences and bring their systems into compliance.

Advertisement

Sberbank expands its existing digital asset services

Sberbank has operated in Russia’s regulated digital asset sector since joining the register of information system operators in 2022. The bank has issued digital financial assets and structured products linked to Bitcoin, Ethereum and cryptocurrency baskets.

Ascrypto.news previously reported, Sberbank was preparing a crypto wallet and digital asset depository before the new framework’s launch. The report said the bank could also consider access to foreign crypto exchanges, depending on final regulatory requirements.

Sberbank has also tested cryptocurrency-backed lending. In December 2025, the bank completed a pilot loan with Russian Bitcoin miner Intelion Data. The company pledged mined cryptocurrency as collateral.

Reuters reported that Sberbank later considered offering similar loans to corporate customers. The bank said miners and companies holding digital assets had shown interest in using crypto as collateral.

Advertisement

The bank has also explored cryptocurrency custody services. In July 2025,Reuters reported that Sberbank had submitted proposals to the central bank on storing Russian customers’ crypto assets through regulated banking infrastructure.

Russian financial companies prepare for crypto trading

Other Russian financial institutions are also preparing services under the new framework. According to crypto.news, VTB and T-Bank were developing digital depository services, while Moscow Exchange was considering regulated cryptocurrency operations.

Alfa-Bank has also tested limited crypto services and custody tools. These projects show that large Russian financial groups are positioning their systems around the new rules before the July 2027 licensing deadline.

The regulated market will divide responsibilities among banks, brokers, exchanges and repositories. Brokers may process customer orders, while exchanges provide trading services. Digital repositories will record customer rights and custody arrangements.

Advertisement

Sberbank’s Dec. 1 launch target places its project within the regulatory transition period. Before opening the service, the bank must complete its wallet, trading, accounting and custody systems. It must also publish supported assets, fees and customer access requirements.

Source link

Advertisement
Continue Reading

Trending

Copyright © 2025