Crypto World
Ethereum just touched $1,500. Is $1,000 next?
Ethereum has fallen to $1,500. In the depths of the June 2026 crypto selloff, ETH briefly touched the $1,500 level, a price last seen in the depths of previous bear markets and roughly 70% below its August 2025 all-time high of $4,953.
Summary
- Ethereum touched $1,500 after falling roughly 70% from its August 2025 all-time high.
- ETH has fallen harder than Bitcoin because of higher beta, weaker ETF demand, and leveraged liquidations.
- A continued Bitcoin decline toward $50,000–$55,000 could pull Ethereum closer to the $1,000 level.
- Bitcoin’s direction, the ETH/BTC ratio, ETF flows, and Fed policy will determine whether $1,500 holds.
The drop has been faster and deeper than Bitcoin’s, and it has pushed at least one analyst to flag the previously unthinkable: a possible decline toward $1,000.
For an asset that traded near $5,000 less than a year ago, the idea of a three in front of nothing is a brutal reset, and it has Ethereum holders asking the only question that matters right now. Is $1,500 the bottom, or a waypoint on the road to $1,000?
The honest answer requires separating the levels that matter, the forces driving the decline, and the specific conditions that would determine which way it breaks. This piece walks through how Ethereum got to $1,500, why it is falling harder than Bitcoin, what would have to happen for $1,000 to come into play, and what would have to happen to prevent it.
How Ethereum got to $1,500
The fall to $1,500 was not a single event but the culmination of a long decline that accelerated into capitulation.
Ethereum peaked at $4,953 in August 2025. From there it entered a grinding downtrend through late 2025 and into 2026, making lower highs and lower lows even as the broader crypto narrative stayed constructive. The June 2026 selloff turned that grind into a collapse.
As Bitcoin broke below $70,000 and then $62,000, Ethereum fell harder, sliding under $1,900, then $1,800, before touching $1,500 at the worst of the washout. That represents roughly a 70% decline from the peak, the kind of drawdown that defines a deep bear market, not a correction.
The immediate triggers were the same forces hammering all of crypto, amplified for Ethereum. A strong U.S. jobs report crushed hopes for near-term Federal Reserve rate cuts, sending risk assets lower across the board. Fresh U.S.-Iran tensions drove a broad risk-off move. U.S. spot Bitcoin ETFs bled through a record outflow streak, and Ethereum ETFs bled alongside them.
More than $1 billion in leveraged crypto positions was liquidated in cascades, with Ethereum longs among the hardest hit. Every one of these pressures pushed Ethereum down, and because ETH amplifies market moves, it fell further than Bitcoin at each step.
The $1,500 touch was the emotional low point, the level where the question shifted from “how far has it fallen” to “how much further can it go.” Reaching a price not seen since previous bear-market bottoms forced a psychological reckoning.
For holders who bought anywhere near the highs, $1,500 represents catastrophic losses, and the appearance of $1,000 price targets in analyst commentary signals that the market is now seriously entertaining scenarios that would have seemed absurd a year ago. To understand whether those scenarios are realistic, it is necessary to understand why Ethereum specifically has been the bigger loser.
Why Ethereum is falling harder than Bitcoin
Ethereum’s steeper decline is not random. It reflects both a mechanical reality and a structural one, and both point to why $1,000 is even being discussed.
The mechanical reason is beta. Ethereum has consistently exhibited higher beta than Bitcoin, meaning it amplifies whatever Bitcoin does in both directions. When Bitcoin rallies, ETH usually rallies more; when Bitcoin falls, ETH usually falls more.
This is because Ethereum sits one rung down the crypto risk ladder, with shallower liquidity and a smaller institutional base than Bitcoin’s “digital gold” position commands. In a risk-off cascade, capital flees the riskier asset first and fastest, so ETH dropped harder at every stage of the selloff. The 70% drawdown versus Bitcoin’s roughly 50% is beta in action.
The structural reason is the ETH/BTC ratio, which has been in a multi-year decline. This ratio measures Ethereum’s value against Bitcoin directly, stripping out the moves that affect all of crypto, and it has been grinding lower since 2021.
The driver is the institutional demand asymmetry. The January 2024 launch of spot Bitcoin ETFs gave Bitcoin a powerful, steady institutional bid that Ethereum’s later ETFs never matched at the same scale. Bitcoin gained a structural class of buyer; Ethereum did not.
When the broad market retreats, Ethereum has less institutional demand underneath it to cushion the fall. That is why it keeps losing ground to Bitcoin in relative terms and why its absolute price has fallen so much further from its peak.
Add the leverage dynamics and the picture sharpens. Ethereum has carried crowded long positioning and faced persistent whale selling through the downturn, and the liquidation cascades of the June selloff hit those crowded ETH longs hard, mechanically accelerating the decline.
Ethereum therefore fell harder for three compounding reasons: it amplifies market moves by nature, it lacks the institutional demand floor that supports Bitcoin, and its leveraged positioning was violently unwound.
Those same factors are why bears can credibly point further down. If the forces that drove ETH to $1,500 persist, the path to $1,000 is not mechanically blocked the way it would be for an asset with a firmer demand floor.
The case for $1,000
The $1,000 scenario is no longer a fringe call, and it rests on a coherent, if grim, logic worth laying out honestly.
The technical case starts with the absence of support. Having broken decisively below the levels that held in previous cycles, Ethereum is in a zone with little historical price structure to lean on.
When an asset falls through its established support levels, the next meaningful floor can be far below because there are few prior buyers anchored at intermediate prices to step in. The $1,500 level itself, once it fails to hold as support, becomes resistance, and the chart opens toward the psychologically significant $1,000 round number with limited technical obstruction in between.
The fundamental case rests on the same structural weakness that drove the decline. If the institutional demand asymmetry persists, with Bitcoin holding its ETF bid while Ethereum’s flows stay weak, and if the broader macro environment stays hostile with no Fed rate cuts and continued risk-off pressure, then nothing changes the dynamic that has driven ETH down.
The ETH/BTC ratio could keep grinding lower. In a scenario where Bitcoin itself falls toward the $55,000 or even $50,000 levels that some analysts flag, Ethereum’s higher beta would drag it proportionally further down, with $1,000 becoming a natural consequence of a deeper Bitcoin decline rather than an independent event.
The behavioral case is capitulation dynamics. Deep bear markets tend to overshoot to the downside, falling further than fundamentals justify as fear, forced selling, and exhaustion compound.
If the current selloff has more capitulation left to run, ETH could spike toward $1,000 in a final washout even if it does not stay there. The appearance of $1,000 targets in analyst commentary reflects this: it is not necessarily a prediction that Ethereum settles at $1,000, but a recognition that in a continued bear scenario, the combination of no support, persistent structural weakness, and capitulation overshoot could tag that level.
The bears are not being absurd. They are extrapolating the forces that are visibly in control.
The case against $1,000
The bull rebuttal is equally real, and it rests on the argument that the forces driving ETH down are cyclical rather than permanent, and that $1,500 is closer to a bottom than a waypoint.
The valuation case is that $1,500 already prices in enormous pessimism. A 70% drawdown from the peak is, historically, the kind of decline that has marked bear-market bottoms rather than midpoints.
Ethereum at $1,500 trades at a level that long-term holders and value-oriented buyers may see as deeply discounted relative to the network’s actual usage, developer activity, and position as the dominant smart-contract platform. The deeper the price falls below any reasonable estimate of fundamental value, the stronger the incentive for accumulation, which builds a floor.
The fundamental case is that Ethereum’s underlying position has not broken. It remains the leading smart-contract platform, the settlement layer for the largest share of decentralized finance and tokenized assets, and the base layer for a growing ecosystem of Layer-2 networks.
Its development continues, with scaling and efficiency upgrades on the roadmap, and the emergence of Ethereum treasury companies accumulating ETH introduces a new structural demand source that did not exist in previous cycles.
The treasury-company thesis, however, is under pressure from the decline. BitMine was reportedly sitting on roughly $9.58 billion in unrealized ETH losses, while SharpLink’s ETH position was down about $1.59 billion as the market fell. The losses do not automatically mean those firms must sell, but they show that the new demand source also carries balance-sheet risk when ETH declines.
If those treasury vehicles continue accumulating and the institutional demand gap with Bitcoin narrows, the structural weakness that drove the decline could begin to reverse, putting a floor under the price well above $1,000.
The macro case is that the entire selloff is hostage to forces that can turn. The decline has been driven heavily by the hawkish Fed outlook, the Iran risk-off move, and the AI-driven capital rotation away from crypto. None of those is permanent.
A Fed pivot toward rate cuts, an easing of Middle East tensions, or a cooling of the AI trade would relieve the pressure that drove ETH to $1,500. Because Ethereum amplifies moves in both directions, a market recovery would lift ETH faster than Bitcoin.
In the bull scenario, $1,500 marks the capitulation low of a cyclical bear market, and the same high beta that made the fall so brutal makes the eventual recovery sharp. The bulls are betting that the forces in control today are temporary and that betting on $1,000 means betting they persist indefinitely, which they rarely do.
What actually determines which way it breaks
Rather than guess, the useful approach is to identify the specific signals that distinguish the $1,000 path from the $1,500-was-the-bottom path, because they are different and observable.
The first is Bitcoin’s direction because ETH is currently trading as a high-beta bet on Bitcoin more than as an independent asset. As long as Bitcoin keeps falling, Ethereum’s beta means it will keep falling harder, and a Bitcoin decline toward $55,000 or $50,000 would likely drag ETH toward $1,000 mechanically.
If Bitcoin stabilizes and holds support, the single biggest downward force on Ethereum eases. Watch Bitcoin first; it tells you more about ETH’s near-term path than anything Ethereum-specific.
The second is the ETH/BTC ratio. This is the cleanest measure of whether Ethereum’s structural weakness is continuing or reversing.
If the ratio keeps grinding lower, Ethereum is still losing the relative-strength battle and the bear case has the upper hand. If it stabilizes and turns up, it signals that the institutional demand gap may be narrowing, which would support the bottom thesis.
The ratio is the dividing line between “ETH is just falling with the market” and “ETH is structurally broken.”
The third is the macro turn, specifically the Fed and the flow data. Because the selloff is heavily macro-driven, the signals that would flip the picture are a shift in rate-cut expectations and a reversal in ETF flows from outflows back to sustained inflows.
A Fed pivot or a series of softer inflation prints would relieve the pressure on all risk assets, and Ethereum ETF inflows turning positive would signal the institutional demand base is finally building.
Until those indicators turn, the forces that drove ETH to $1,500 remain in control, and the $1,000 scenario stays live.
The honest synthesis is that $1,500 is a genuine inflection point where both scenarios are credible. The broader context tilts the odds toward caution in the near term while leaving the bull case intact over a longer horizon.
In the near term, with Bitcoin still weak, the macro environment hostile, and the ETH/BTC ratio depressed, the forces that would carry Ethereum toward $1,000 are the ones currently in control. A further leg down cannot be dismissed, and the $1,000 targets deserve to be taken seriously rather than waved away.
Over a longer horizon, a 70% drawdown in the leading smart-contract platform, with intact fundamentals and a new treasury-demand source emerging, is the kind of setup that has historically rewarded patient accumulation once the macro turns.
The practical reading for a holder is that $1,500 is not a number to anchor to either as a guaranteed floor or a doomed level. It is the point where Ethereum’s fate splits, and which path it takes will be determined by Bitcoin’s direction, the ETH/BTC ratio, and the macro turn, not by where the price sits today.
Watch those three, not the round numbers.
This article is for informational purposes and does not constitute financial or investment advice. Cryptocurrency markets are highly volatile and price predictions are inherently speculative. The figures and analysis described reflect data available as of June 2026. Always do your own research and consult with qualified financial professionals before making investment decisions.
Crypto World
Wise turns to GENIUS Act after OCC rejects U.S. bank charter
Wise plans to submit a new application for a U.S. national trust bank charter under the GENIUS Act after the Office of the Comptroller of the Currency rejected its first bid.
Summary
- Wise plans a fresh U.S. charter application under the GENIUS Act after the OCC rejection.
- The OCC cited weak AML controls, management gaps, and limited national banking experience in denial.
- William Blair expects Wise to remain rail-agnostic rather than make stablecoins its core business model.
The July 21 decision ended the payments company’s effort to create Wise National Trust in Austin, Texas. Wise disclosed the outcome on July 24 and said its current U.S. services continue without change. The company still operates through money-transmitter licences across 48 states and four territories.
The new filing will use the federal framework for payment stablecoins rather than the structure in Wise’s original June 2025 application. Wise said the earlier plan relied on access to Federal Reserve payment systems that is no longer practical. Its London-listed shares fell as much as 10% after the denial became public. Wise said it had strengthened financial-crime controls since filing the original plan and would address the regulator’s findings in its next submission.
OCC rejects Wise application over compliance concerns
The OCC’s decision said Wise did not show that the proposed trust bank could meet U.S. legal and regulatory requirements. The regulator focused on weaknesses in anti-money laundering and countering the financing of terrorism controls. It also said Wise U.S. had a record of failing to meet rules that apply to money services businesses. The proposed bank planned to rely heavily on Wise U.S. and other group companies for compliance work.
The regulator also questioned the experience of the proposed directors and managers. It said the team did not show enough knowledge of national banking rules, fiduciary services, or AML/CFT operations. Wise National Trust had planned to offer multi-currency stored-value accounts, payment processing, and fiduciary services. The OCC stated that approval would conflict with its charter policies. However, the decision does not stop Wise from filing another application after addressing the issues.
Wise shifts its plan toward the GENIUS Act
Wise gave a separate reason for changing course. The company said the Federal Reserve has generally paused account access for uninsured trust banks while it develops a new payment-account policy. “With the Federal Reserve generally pausing account access for an uninsured trust bank, the approach in our application became non-viable,” Wise said. The original plan aimed to let Wise settle U.S. dollar payments more directly and reduce its reliance on partner banks.
Wise now plans to apply under the GENIUS Act, which created a federal licensing and supervision system for payment stablecoin issuers. The company has not said it will launch its own stablecoin. William Blair analysts also said they do not expect a major change in Wise’s position. They described the company as “agnostic of the rail,” meaning it remains focused on lowering cross-border payment costs whether transfers use traditional systems or digital assets.
Stablecoin rules remain unfinished
The GENIUS Act became law in July 2025. It sets reserve, redemption, reporting, consumer protection, and compliance requirements for approved payment stablecoin issuers. The law is due to take effect on January 18, 2027, or 120 days after regulators publish final rules, whichever comes first. The OCC published its main proposed rule in March, while Treasury later proposed AML and sanctions standards.
Final rules were still pending when Wise announced its new plan. As crypto.news reported, regulators missed the July 18 rulemaking deadline, leaving key details unresolved. Wise will need to explain what activities its new entity would conduct, how it would use stablecoins, and how it would meet the stricter AML/CFT standards planned for permitted issuers. A new application must also explain how the charter would work without the unrestricted Federal Reserve access assumed in the earlier model.
Wise joins a wider U.S. charter race
Wise is entering a crowded federal licensing process. The OCC has approved several digital asset companies for national trust charters during the past year.Circle received final approval in July 2026 after gaining conditional approval in December. Ripple, Paxos, BitGo, Fidelity Digital Assets, Crypto.com, Bridge, and Coinbase have also received conditional decisions or entered the process.
The approvals have drawn opposition from banking groups and some lawmakers. Crypto.news reported that the Bank Policy Institute retained outside lawyers while considering a challenge to the OCC’s trust-charter policy. Wise’s case differs because the regulator issued a direct denial tied to its compliance record and management plan. The new GENIUS Act filing may offer a different route, but it will still require Wise to satisfy the OCC’s standards before gaining a charter.
Crypto World
BitMart shuts down trading as BMX crashes more than 60%
BitMart has started a phased shutdown of its global cryptocurrency exchange after reviewing its operating conditions, market environment, and future strategy.
Summary
- BitMart stopped new registrations, deposits, and orders before ending all trading services on August 26.
- BMX lost about 63% in 24 hours as traders reacted to the exchange’s shutdown announcement.
- Withdrawals remain available, but BitMart advised users to submit requests before August 26’s recommended deadline.
According to the official shutdown notice, the exchange stopped new registrations, cryptocurrency and fiat deposits, and new spot orders from 01:30 UTC on July 26. Futures accounts entered reduce-only mode, while copy trading, grid trading, API trading, and other automated services began winding down.
The exchange will end all spot, futures, and other trading services at 01:00 UTC on August 26. However, the full platform will not close on that date. BitMart plans to terminate trading-platform operations at 15:59 UTC on January 31, 2027. Users will retain limited account access for a period after that date to review records and submit withdrawals.
BitMart sets withdrawal and position deadlines
BitMart told users to close all positions before 01:00 UTC on August 26 and recommended submitting withdrawals before 05:00 UTC the same day. Withdrawals remain open, but requests may face identity, source-of-funds, wallet ownership, sanctions, Travel Rule, and security reviews. Heavy demand or network congestion may extend processing times.
The exchange asked customers to cancel open orders, redeem eligible Earn, staking, and lending products, and download account records. BitMart may settle any futures positions still open when trading ends using its mark price, index price, or other applicable rules. Users who miss the recommended withdrawal period will enter a separate process that BitMart plans to explain later.
BMX falls as traders react to the shutdown
BMX, the exchange’s platform token, fell by around 63% during the 24 hours surrounding the announcement. BitMart’s own market page showed a decline of about 64.9% at one stage, while CoinGecko’s BMX page placed the token near $0.164 on July 26 with about $6.1 million in daily volume. The sharp move reflected the token’s close link to exchange activity.
BMX provides trading-fee discounts and other platform benefits. The planned end of trading removes much of that direct use. Price readings varied across trackers because the market moved quickly and platforms used different update times. CoinGecko data placed the token’s market value near $55.6 million on July 26, down from more than $100 million earlier in the week.
Closure follows recent service restrictions
BitMart did not identify a single event behind the shutdown. Its notice referred only to “operating conditions, market environment, and future strategic direction.” The exchange did not state that it had entered insolvency, and it did not connect the decision to a security incident, regulatory order, or lack of customer assets. Users therefore still lack a detailed financial explanation.
The decision followed several service changes. BitMart suspended its automated market-making bot on July 24 and returned users’ principal and earnings to spot accounts. It also ended spot margin trading, with forced liquidation scheduled for July 26. On July 23, the exchange told remaining U.S.-linked users to close positions and withdraw by August 8 during a compliance review.
BitMart follows other crypto platform closures
The announcement came three days after BitMEX said it would close its derivatives exchange on September 23 following a strategic review. BitMEX stopped new registrations and set August 26 as the date when customers could no longer open new positions. Odos also announced plans to shut its decentralized exchange aggregator on July 30, although the platforms gave different reasons and timelines.
BitMart entered the market in 2017 and grew through a wide selection of smaller tokens. A 2021 Series B round led by Alexander Capital Ventures valued the company at more than $300 million. Fenbushi Capital had made an earlier investment in 2019. Days after the Series B announcement, attackers compromised two hot wallets and stole assets valued at about $150 million by BitMart, while outside estimates reached $196 million.
BitMart said at the time that it would use its own funds to compensate affected customers. The shutdown notice did not link the wind-down to that breach, which occurred nearly five years earlier. In May 2026, BitMart said “all platform operations are running normally” while responding to online concerns about withdrawals and risk controls. It also said it planned to publish proof of reserves after completing security preparations.
The exchange now warns that scammers may exploit the shutdown. BitMart said it will not charge an expedited withdrawal fee or ask for passwords, two-factor codes, private keys, or recovery phrases. It advised users to rely on its official website, app, registered emails, and support system. Customers must also check networks and addresses before transferring funds.
Crypto World
BMX Token Crashes 46% as BitMart Announces Exchange Wind Down
Cryptocurrency exchange BitMart will shut down its trading platform, beginning an orderly wind-down on Sunday.
The announcement sent BitMart Token (BMX) tumbling, with the exchange token posting double-digit losses over the past 24 hours. The platform urged users to close positions and withdraw assets without delay.
BitMart Sets a 6-Month Runway Before Full Closure
BitMart attributed the decision to a review of its operations, market conditions, and future strategic direction.
“BitMart has made the difficult decision to commence an orderly wind-down of its trading platform operations. We deeply regret having to make this decision,” the team said.
Follow us on X to get the latest news as it happens
The notice sets a staged timeline. The platform suspended new registrations, deposits, and orders on July 26, 2026, at 01:30 UTC.
Futures accounts switched to reduce-only mode on July 26. Spot trading also stopped accepting new orders that day.
Copy trading, grid trading, and API trading services are being discontinued in phases. Earn, staking, lending, and Launchpad products will wind down under their own schedules.
All spot, futures, and other trading ends at 01:00 UTC on August 26. Platform operations then cease entirely at 15:59 UTC on January 31, 2027.
The exchange asked users to complete identity verification and close positions before that August deadline. It also asked users to submit withdrawal requests by 05:00 UTC on August 26, 2026.
BMX Slides as Exchange Closures Pile Up
The market reaction was immediate. BMX traded near $0.11016 on Sunday, down 46.08% on the day.
That leaves it roughly 82% below its record high of $0.61905, reached on June 5, 2024.
The closure arrives just days after BitMEX told users it would end operations on September 23. Two established venues are therefore exiting within the same week.
Users now have one month to exit positions before trading stops on BitMart.
Subscribe to our YouTube channel to watch leaders and journalists provide expert insights
The post BMX Token Crashes 46% as BitMart Announces Exchange Wind Down appeared first on BeInCrypto.
Crypto World
North Korea hackers scan crypto wallets through fake Zoom calls
- BlueNoroff scans browser wallets before deciding which fake meeting targets should receive its malware payload.
- Hijacked Telegram accounts help attackers contact trusted industry peers and extend the campaign through victims.
- The phishing kit supports Windows and macOS, stealing browser keys, system data, and Telegram sessions.
North Korea-linked hacking group BlueNoroff is using fake Zoom and Microsoft Teams meetings to profile cryptocurrency users before delivering malware.
Cybersecurity firm JUMPSEC said it recovered and analysed source code from an active phishing kit after its operators exposed JavaScript source maps on live infrastructure. The files showed separate Zoom and Teams lures, wallet-scanning tools, operator controls and malware delivery paths for Windows and macOS.
The attack often begins through a Telegram account that the target already trusts. The hackers take over accounts belonging to crypto contacts, then send a Calendly invitation that leads to a lookalike meeting domain. JUMPSEC described the system as a repeatable victim pipeline because one stolen Telegram session can help the attackers contact the next group of targets.
BlueNoroff checks crypto wallets before sending malware
The phishing page starts scanning the browser when a user enters the fake meeting. It looks for Ethereum wallet connections through EIP-6963 and older browser methods. It also checks for non-EVM wallets, including Solana tools. The results reach an operator panel without alerting the victim. This lets the attackers identify wallets and choose higher-value targets before pushing the next stage.
On Windows, the implant also lists extension IDs across Chrome, Edge, Brave, Opera, Vivaldi and Firefox variants. Operators can compare those IDs with known wallet extensions such as MetaMask. JUMPSEC called this a system that profiles wallets “before malware delivery.” The method differs from broad phishing campaigns because the attackers gather wallet data before deciding how far to take the intrusion.
Fake Zoom and Teams calls build trust
Victims first see a convincing meeting page that requests their name and webcam access. The site then sends the camera stream to the attacker’s control panel. After the victim joins, the screen shows “waiting for other participants.” An operator can enter with a prepared video, send messages such as “your mic isn’t working,” and trigger a fake “Zoom SDK Update” prompt.
JUMPSEC found that the displayed participant video was not live. The attackers combined AI-generated headshots with body movements captured in earlier meetings. They could then show a familiar-looking person while using a Telegram account that belonged to a real contact. The Teams version included emoji reactions, device settings, background effects and wider wallet checks, making it more polished than the Zoom kit. The source code also contained an unfinished Google Meet option. JUMPSEC said Zoom and Teams suit the lure because both use desktop clients, making an urgent software update appear more credible.
Malware targets both Windows and macOS
On Windows, the copied ClickFix command runs a small PowerShell loader. It downloads a VBScript, adds a Microsoft Defender exclusion and restarts Defender so the change takes effect. The implant gathers system details, checks browsers for wallet extensions and looks for Telegram Web files. It can also receive later payloads from the operators, although JUMPSEC did not recover every final-stage file.
The macOS path downloads a fake Zoom or Teams installer while a stealer runs in the background. Researchers found versions that collected system information and Chrome master keys from Apple’s Keychain. The malware sent data through a Telegram bot and could download another payload. JUMPSEC traced four macOS variants between April 22 and July 15, showing that the operators kept changing the toolkit during the campaign.
Campaign builds on earlier crypto meeting scams
The findings expand earlier research into BlueNoroff’s fake meeting operations. In April, Arctic Wolf reported more than 80 lookalike Zoom and Teams domains and identified 100 additional targets whose media appeared on attacker infrastructure. It said 80% of the identified targets worked in crypto, blockchain finance or related investment sectors, while founders and chief executives made up 45%.
North Korean attackers had already used compromised Telegram accounts, spoofed meeting invitations and fake software updates to target crypto executives. Another crypto.news report described a related macOS campaign that asked victims to run commands during fake calls. Earlier coverage of NimDoor malware also linked fake Zoom updates to theft attempts against browser credentials, wallet data and Telegram files.
The latest kit gives operators direct control over the pace of each meeting and the malware prompt. JUMPSEC advised organisations to treat meeting links from trusted accounts with care because the sender’s account may already be compromised. Crypto teams can verify unusual invitations through another channel, avoid commands or updates presented during calls, revoke exposed Telegram sessions and isolate any device that ran the requested script. Teams should also review PowerShell activity, Defender exclusions, Keychain access and new Telegram logins after any suspect call. A password reset alone may not remove stolen sessions or malware already running on the device across affected systems.
Crypto World
Uniswap launches Permissioned Pools for compliant onchain trading
Uniswap Labs has launched Permissioned Pools on Uniswap v4, adding onchain access checks for regulated assets that cannot trade freely between every wallet.
Summary
- Permissioned Pools check issuer-managed allowlists before swaps or liquidity actions can proceed through Uniswap v4.
- Superstate, Securitize, and Dowgo helped build compliant trading infrastructure for tokenized funds, equities, and securities.
- Regular Uniswap v4 pools remain permissionless, giving developers a separate option for restricted regulated assets.
The open-source hook standard lets approved users swap tokenized funds, securities, equities and other restricted assets through automated market maker pools. Uniswap announced the product on July 23, 2026, after working with firms that issue and manage regulated onchain assets. It keeps issuer compliance controls visible and enforceable onchain.
Launch partners include Superstate, Securitize and Dowgo. Each partner helped shape parts of the standard or its compliance links. The launch does not change regular Uniswap v4 pools. Those pools remain permissionless, while issuers can choose the restricted format when an asset requires identity checks, transfer rules or investor eligibility controls.
How Uniswap Permissioned Pools work
Permissioned Pools check an issuer-managed allowlist before every swap. The hook also checks the list before a user creates a liquidity provider position. When a wallet lacks approval, the transaction cannot continue. The issuer controls the list and its rules, rather than Uniswap or a public interface. Uniswap said the checks run “at the protocol level, not on the frontend,” which makes the restriction part of the pool’s smart-contract process.
The design uses Uniswap v4 hooks, which let developers add custom instructions to a pool at set points in a transaction. It also uses v4 virtual accounting to calculate exchanges while the regulated assets remain inside a permissioned contract. Approved traders still use an AMM instead of a traditional order book. Liquidity providers supply the assets, while the pool’s code handles pricing and settlement under the issuer’s access rules.
Launch partners connect regulated assets to AMMs
Superstate joined as an early design partner and helped develop the format for tokenized equities and funds. The company issues onchain financial products and operates services for tokenized funds and company shares. Its July 23 update said the standard could connect eligible tokenized equities with AMMs, lending markets and other approved financial applications.
Securitize worked with Uniswap Labs before the wider standard launched. The firms focused on making assets issued through Securitize’s DS Protocol compatible with compliant onchain trading. Dowgo contributed an ERC-3643 integration, a token standard that supports identity checks and transfer controls. Uniswap said Dowgo plans to use Permissioned Pools after it receives DLT TSS authorisation under the European Union’s DLT Pilot Regime. Dowgo says its application remains under review by France’s ACPR.
Regular Uniswap v4 pools remain permissionless
The new system applies only when an issuer or developer deploys a Permissioned Pool for a selected asset. It does not add a general identity check to Uniswap v4. Developers can continue creating standard pools without asking Uniswap Labs for approval, and users can continue accessing those pools under the protocol’s existing rules.
This split gives regulated issuers a separate route to AMM liquidity without turning the wider protocol into a closed trading venue. Uniswap said developers can choose either model: build permissionlessly on v4 or deploy a restricted pool for an asset with legal transfer conditions. The issuer remains responsible for the allowlist and investor access, while the hook enforces those decisions during swaps and liquidity actions.
Tokenized asset growth raises demand for compliance controls
Permissioned Pools follow Uniswap’s June rollout of tokenized securities across its web app, wallet and API. That earlier update gave eligible users access to blockchain-based products linked to companies such as Apple, Nvidia and Tesla. Uniswap warned that some products may not represent direct ownership and may face KYC, transfer or geographic restrictions. The new pool standard gives issuers another way to enforce such rules directly in trading infrastructure.
Uniswap cited an estimate that the tokenized asset market could reach $11 trillion by 2030. Current figures remain far below that forecast. As crypto.news reported, tokenized real-world assets stood near $34 billion in May 2026, including about $1.55 billion in tokenized equities. Related coverage also found that transfer agents often control wallet allowlists and the official ownership records behind tokenized securities.
Regulators continue to examine how these products protect ownership and shareholder rights. As previously reported, the U.S. Securities and Exchange Commission delayed a proposed tokenized-stock exemption after exchanges raised questions about investor safeguards and record keeping. Securitize chief executive Carlos Domingo said any framework should “apply to the right instruments.” Permissioned Pools address transaction access at the smart-contract level, but each issuer must still follow the securities laws and licensing rules that apply to its product and market.
Crypto World
Upbit expands KRW market with two major DeFi token listings
Upbit has added Morpho (MORPHO) and Euler (EUL) to its Korean won market, expanding direct KRW trading for two Ethereum-based decentralized lending projects in Korea.
Summary
- Upbit added MORPHO and EUL KRW pairs, giving traders access to two DeFi lending tokens.
- Euler’s KRW trading launch moved to 2:00 p.m. KST, two hours later than initially scheduled.
- EUL gained about 74% before launch, while MORPHO posted a smaller rise and heavier volume.
MORPHO/KRW opened on July 25 at 6:00 p.m. KST, while Upbit planned EUL/KRW for July 26.
However, Upbit changed Euler’s launch timetable shortly before trading. The exchange moved the start from 12:00 p.m. to 2:00 p.m. KST on July 26. The notice said, “The trading support start time for EUL will change.” Deposits and withdrawals for both assets remain limited to the Ethereum network. The listings also broaden access beyond existing BTC and USDT pairs already available for both assets on Upbit.
Upbit delays EUL trading after adding the KRW pair
Upbit did not give a detailed reason for the two-hour delay. Its notice said trading may start later when the exchange has not secured enough liquidity. The platform had already created the EUL/KRW market page, but users still had to follow the revised 2:00 p.m. KST start time.
The exchange also placed temporary controls on the launch. Upbit will block buy orders for about five minutes after trading begins. During the same period, it will restrict sell orders priced more than 10% below the previous closing price. For roughly two hours, users may place limit orders only. Upbit set the reference close at 0.00003019 BTC, equal to 2,845 won in its notice.
EUL price surges before the scheduled Upbit launch
EUL recorded the stronger market response. At the time of writing, Binance data placed the token near $2.22, up about 74% over 24 hours, with trading volume above $200 million. CoinMarketCap data also linked the move to the Upbit listing and reported a sharp rise in volume before the KRW market opened.
The reaction follows earlier cases in which Korean won listings drove fast changes in EUL trading. As crypto.news reported in September 2025, EUL rose more than 30% after Bithumb announced a KRW pair. The token had also gained after Coinbase added it to its asset roadmap in July 2025. Those earlier moves show that new exchange access can quickly change short-term demand, although gains can reverse when initial activity slows.
Morpho gains another route to Korean won liquidity
Morpho’s KRW pair opened a day earlier. Upbit scheduled MORPHO/KRW trading for 6:00 p.m. KST on July 25 and supported deposits and withdrawals through Ethereum only. Market trackers recorded a smaller price move than EUL, but they also showed a sharp increase in MORPHO trading volume after the announcement.
MORPHO traded near $1.95 on July 26, up about 1.5% over 24 hours. CoinGecko placed its market value above $1.2 billion and reported that daily volume had increased by more than 400% from the previous day. The listing adds a direct won pair for a token that Upbit already offers in its BTC and USDT markets.
The new KRW access also follows a series of Morpho product and funding updates.Morpho launched Midnight on Base in July, offering fixed-rate and fixed-term lending. The network said it held more than $11 billion in deposits. In June, Morpho raised $175 million from investors including Paradigm, a16z Crypto and Ribbit Capital, with the transaction reportedly valuing the project at about $2 billion.
Upbit backs two modular Ethereum lending protocols
Morpho and Euler both provide infrastructure for onchain lending, but they use different systems. Morpho lets developers and asset managers create lending markets and vaults with selected collateral, risk settings and interest models. MORPHO supports governance and other functions across the network.
Euler v2 uses modular vaults that users and developers can build for different lending markets. Its Euler Vault Kit supports the creation of vaults, while the Ethereum Vault Connector can link positions across compatible vaults. EUL serves governance, rewards and fee-related functions within the protocol.
Euler rebuilt its platform after a 2023 exploit drained about $197 million from its earlier version. The attacker later returned most of the funds. As crypto.news previously reported, Euler expanded through v2 and later launched on networks including Sonic. The protocol reported more than $2 billion in total borrowing and about $4 billion in deposits by October 2025.
Upbit’s back-to-back MORPHO and EUL listings give Korean traders new won-denominated access to two lending protocols. However, the fast EUL price rise and the exchange’s opening controls point to high volatility around the launch. Upbit advised users to confirm the Ethereum network and token contract before sending funds, because unsupported deposits may require a long return process.
Crypto World
Bitcoin Miner Poolin Files Bankruptcy, Seeks $52M Texas Asset Sale
Singapore-based Bitcoin mining company Poolin on July 22 filed for Chapter 11 bankruptcy protection in New Jersey, alongside its US affiliates Lonestar Dream Inc. and Lonestar Taproot LLC. The firm is also looking for court approval for a $52 million sale of its Texas mining properties.
The bankruptcy filing comes nearly four years after Poolin froze customer withdrawals, leaving thousands of wallet users with IOU tokens and turning a mining business failure into a long-running creditor dispute.
Poolin Enters Chapter 11 With $173 Million in Liabilities
Court records filed in the US Bankruptcy Court for the District of New Jersey show Poolin listed between 10,001 and 25,000 creditors, with petition assets estimated between $1 million and $10 million.
Chief Restructuring Officer Michael DuFrayne’s declaration placed prepetition obligations at about $173.1 million, with roughly $163.7 million tied to unsecured IOUs issued to Poolin Wallet customers.
The company’s current bankruptcy case is focused on selling its Texas assets rather than rebuilding its mining operations. Lonestar Dream stopped mining and hosting activities at its Pyote and Tarbush sites on July 10, according to the filing documents.
Poolin has entered asset purchase agreements with Thor CALAP LLC for a combined $52 million stalking-horse bid. The offer includes $15 million for the Pyote property and associated power rights and equipment, plus $37 million for Tarbush power rights and equipment. The deal remains subject to competing bids and court approvals.
The company spent more than three months marketing the asset, contacting over 335 potential buyers, including cryptocurrency miners and artificial intelligence and high-performance computing operators. The process resulted in 28 confidentiality agreements, seven letters of intent and three additional expressions of interest.
Poolin’s Texas expansion struggled after the company moved mining operations from China as Beijing imposed a ban on mining in the year 2021. It expected to receive up to 600 megawatts of power, but only 100 megawatts were made available. This meant the equipment the firm had bought for its US run ended up being more than was necessary.
Some of that equipment was sold, resulting in a loss of $8.8 million from fiscal year 2023 to 2025. In the end, Lonestar Dream and Lonestar Taproot accumulated about $45.9 million in losses.
The Collapse of Poolin Wallet Remains Central to Creditor Claims
Poolin’s financial problems go beyond mining, as back in June 2022, when Bitcoin fell below $20,000, it triggered margin calls from Tether against collateral the firm had pledged through the Poolin Wallet. It then transferred almost all of that collateral to Antalpha and borrowed about $213 million against crypto assets valued at just under $356 million.
However, in September 2022, Poolin Wallet suspended withdrawals and issued around $163.7 million worth of IOU tokens to customers, with about 11,700 wallet users holding balances above $100, according to the filing.
Bitcoin later fell below $16,800 in November 2022, after which Poolin ceased operations, and Antalpha liquidated the collateral. Management estimated that about $260 million was owed to Antalpha against digital assets valued near $265 million at the time.
Poolin was once one of the largest Bitcoin mining pools globally, reaching roughly 14% of the Bitcoin network’s mining share in 2019. However, the company’s remaining value now depends on the Texas asset sale and the outcome of the bankruptcy process.
The court-supervised auction will determine how much creditors recover, and any distribution will depend on competing bids, sale expenses, administrative claims, and approval of the proposed liquidation plan.
The post Bitcoin Miner Poolin Files Bankruptcy, Seeks $52M Texas Asset Sale appeared first on CryptoPotato.
Crypto World
Binance Details Staff Phishing Campaigns to Counter Social Engineering
Binance says it has been running internal, simulated phishing attacks against its own staff for several years—testing how well employees resist social engineering attempts and tying repeat failures to remediation training and performance consequences. The exchange’s chief security officer, Jimmy Su, described the program as a way to measure whether “security hygiene” is improving inside a growing organization.
Su told Cointelegraph that Binance’s internal red team performs phishing simulations on a monthly basis. Employees who fail receive remediation training, while continued poor performance can affect their performance review ratings and, in extreme cases, lead to dismissal.
Key takeaways
- Binance conducts monthly phishing simulations via an internal red team, according to its chief security officer Jimmy Su.
- Failed phishing tests are followed by remediation training, aiming to improve employees’ security habits over time.
- Results can influence performance reviews; repeated failures may lower ratings to the point that employment risk increases.
- Su says Binance has run these simulated attacks for roughly three to four years, with security hygiene improving compared with earlier stages.
- The described tactics reflect broader industry risk: social engineering continues to be a major driver of crypto security incidents.
How Binance tests resistance to social engineering
Binance’s approach centers on realism: the red team acts as an attacker to probe the company’s human layer, not just technical controls. Su said the simulations are designed to show whether employees have become more vigilant over time, adding that the program has been running for about three to four years.
“We do phishing attacks on our own employees on a monthly basis just so we understand if our security hygiene is improving,” Su told Cointelegraph. The goal, he said, is to spot weaknesses early—before malicious actors can exploit them in real incidents.
“The ones that have failed it, we will do remediation training.”
Su also said that early on, security hygiene “left a lot to be desired.” But after continuing the internal testing for a sustained period, Binance has seen meaningful improvement. That long-running cadence matters because human error is rarely solved through a one-time training session; it often requires repeated exposure, feedback, and accountability.
Escalating accountability: training and performance reviews
Binance’s internal program isn’t only about education—it’s also about incentives. Su stated that employees are encouraged to perform well because simulation results are reflected in performance reviews.
“If someone repeatedly fails the phishing-simulation attack, that will negatively impact their rating. That’s the incentive to be vigilant.”
He added that repeated, severe failures could cause a person’s rating to “bottom out,” which could ultimately lead to dismissal. While exact thresholds or timelines were not specified, the direction is clear: Binance treats recurring susceptibility to phishing as a measurable risk rather than a purely training-based issue.
For employees and managers, this changes the information security conversation. Instead of treating phishing defenses as optional training, the simulations become part of how the organization assesses readiness—suggesting a shift toward continuous security evaluation.
The tactics: recruiter lures and Zoom-style schemes
Su described at least one scenario used in the red team’s simulations: the team poses as job recruiters. That reflects a common pattern in real-world phishing—using credible context and urgency to lower an employee’s guard, especially when the target might be inclined to respond to hiring-related messages.
He also referenced well-known social engineering techniques that have circulated widely in the crypto ecosystem, including “Zoom meeting attacks,” in which attackers try to get victims to install malware disguised as a meeting update. These attacks often begin with a lure such as a fake job opportunity, and they can also use other hooks like proposed funding or partnerships.
The Binance description aligns with incidents seen across the sector. Earlier coverage cited by Cointelegraph notes that AMLBot estimated that 65% of crypto security incidents in 2025 were driven by social engineering. Separately, a major hack suffered by Drift Protocol in April was described as following a long-term social engineering campaign.
One example of the “Zoom client” pattern occurred in September 2025, when a major Venus Protocol user reportedly lost around $13 million after a malicious Zoom client compromised their computer and granted an attacker control over their account. Venus paused the protocol and used an emergency governance vote to recover the assets, later returning positions worth $11.4 million to the victim, according to the related Cointelegraph reporting referenced in the original article.
Why internal phishing testing is becoming standard in crypto
Binance’s public discussion of internal simulated phishing comes at a time when social engineering is widely recognized as a persistent—and often underestimated—attack surface in digital-asset businesses. The reason these programs can matter is that even sophisticated security stacks cannot fully prevent compromise if employees can be tricked into revealing access, installing malware, or granting approvals.
Binance is also operating at a scale where human processes can become especially important. The exchange says it has 323 million registered users, and DefiLlama estimates Binance holds $137.7 billion in assets. In environments this large, attackers have strong incentives to focus on the easiest pathway to access—often the human decision layer.
Su indicated that Binance has treated phishing resilience as an ongoing operational discipline rather than a compliance box. He described scenarios that include collecting personal information through seemingly benign interactions, such as offering free conference invites as a way to see how many targets would share details.
That emphasis on varied lures is an important point for investors and operators watching the sector: attackers adapt, and defensive training must adapt too. Simulations that only teach one “shape” of attack can become outdated quickly, while programs that rotate scenarios help test whether employees can recognize patterns rather than memorize scripts.
What readers should watch next is whether other major exchanges and custody platforms adopt similar accountability-driven simulation programs—and, crucially, whether regulators and internal auditors begin to treat phishing resistance testing as a measurable control rather than a general training activity.
Crypto World
Sberbank sets Dec. 1 deadline for Russia crypto trading launch
Sberbank plans to launch cryptocurrency trading infrastructure and a digital depository by Dec. 1, 2026.
Summary
- Sberbank plans to launch regulated crypto trading, custody, settlement, and depository services by December 1.
- Russia’s new crypto framework starts September 1, with licensing compliance required by July 1, 2027.
- Non-qualified investors may buy up to 300,000 rubles yearly after passing a mandatory knowledge test.
The system will support regulated crypto trading, custody and settlement for eligible customers in Russia.
The project follows the approval of new rules covering crypto exchanges, brokers, banks and digital depositories. Russia will introduce the wider regulatory framework on Sept. 1, 2026, while companies will receive additional time to meet licensing requirements.
Sberbank plans digital custody and off-chain records
According to Interfax, Sberbank’s digital depository will record customers’ cryptocurrency ownership and account for many transactions outside public blockchain networks. The bank will also manage active wallets for deposits, withdrawals and transfers.
Alexander Vedyakhin, Sberbank’s first deputy chairman, said the bank intends to complete the required systems before the December deadline.
“Sber plans to implement the necessary infrastructure and launch the digital depository by Dec. 1, 2026.”
Sberbank has not yet named the cryptocurrencies that its platform will support. The bank has also not disclosed fees, customer eligibility rules or withdrawal limits. These details may depend on supporting regulations that Russian authorities still need to approve.
Under the planned structure, customers could hold recorded crypto rights inside Sberbank’s system. The bank would then use its controlled wallets when customers deposit, withdraw or transfer assets to external addresses.
Russia introduces rules for investors and intermediaries
The Bank of Russia said the new framework will allow qualified and non-qualified investors to purchase cryptocurrencies through regulated intermediaries. However, different limits will apply to each group.
Non-qualified investors must pass a knowledge test before buying eligible cryptocurrencies. They may purchase up to 300,000 rubles of crypto each year through one intermediary. Public access will focus on assets that meet liquidity and market-size standards set by regulators.
Qualified investors must also complete testing, but they will have access to a wider range of assets without the same annual limit. Banks, brokers and asset managers may offer services under their existing licences and added crypto requirements.
Meanwhile, new cryptocurrency exchanges and digital repositories will require separate approval. The Bank of Russia will supervise the market and set standards for custody, accounting and customer protection.
Russia will continue to prohibit cryptocurrency payments for goods and services inside the country. However, companies may use crypto for approved cross-border settlements. Residents may also need to report some foreign crypto holdings and transactions to tax authorities.
The framework takes effect on Sept. 1, 2026. Companies covered by the new rules will have until July 1, 2027 to secure licences and bring their systems into compliance.
Sberbank expands its existing digital asset services
Sberbank has operated in Russia’s regulated digital asset sector since joining the register of information system operators in 2022. The bank has issued digital financial assets and structured products linked to Bitcoin, Ethereum and cryptocurrency baskets.
Ascrypto.news previously reported, Sberbank was preparing a crypto wallet and digital asset depository before the new framework’s launch. The report said the bank could also consider access to foreign crypto exchanges, depending on final regulatory requirements.
Sberbank has also tested cryptocurrency-backed lending. In December 2025, the bank completed a pilot loan with Russian Bitcoin miner Intelion Data. The company pledged mined cryptocurrency as collateral.
Reuters reported that Sberbank later considered offering similar loans to corporate customers. The bank said miners and companies holding digital assets had shown interest in using crypto as collateral.
The bank has also explored cryptocurrency custody services. In July 2025,Reuters reported that Sberbank had submitted proposals to the central bank on storing Russian customers’ crypto assets through regulated banking infrastructure.
Russian financial companies prepare for crypto trading
Other Russian financial institutions are also preparing services under the new framework. According to crypto.news, VTB and T-Bank were developing digital depository services, while Moscow Exchange was considering regulated cryptocurrency operations.
Alfa-Bank has also tested limited crypto services and custody tools. These projects show that large Russian financial groups are positioning their systems around the new rules before the July 2027 licensing deadline.
The regulated market will divide responsibilities among banks, brokers, exchanges and repositories. Brokers may process customer orders, while exchanges provide trading services. Digital repositories will record customer rights and custody arrangements.
Sberbank’s Dec. 1 launch target places its project within the regulatory transition period. Before opening the service, the bank must complete its wallet, trading, accounting and custody systems. It must also publish supported assets, fees and customer access requirements.
Crypto World
Binance Runs Monthly “Red Team” Tests on Staff to Thwart Hackers
Binance’s chief security officer, Jimmy Su, says the exchange is actively testing its own workforce against simulated phishing attempts—and tying repeated failures to employment outcomes. Su told Cointelegraph that the internal “red team” runs phishing exercises on a monthly basis to gauge whether security awareness among staff is improving.
According to Su, employees who fail the exercises aren’t just retrained once. Instead, Binance uses remediation training for those who miss the mark, and persistent, repeat failures can ultimately affect their standing at the company, reflecting the role that social engineering plays in real-world cyber incidents.
Key takeaways
- Binance conducts monthly simulated phishing attacks against employees as part of an ongoing internal security program.
- The simulations are carried out by Binance’s red team, a unit focused on ethical hacking and vulnerability discovery.
- Failed employees receive remediation training, while repeated failures can negatively affect performance reviews and potentially job outcomes.
- Binance says the program has been running for three to four years, with Su describing significant improvements in security hygiene over time.
- The company uses multiple real-world lures—such as fake recruiter outreach and other “information collection” tactics—to test staff resilience.
Why Binance is testing its own staff
Su said Binance runs phishing simulations “just so we understand if our security hygiene is improving,” framing the effort as a practical measurement exercise rather than a theoretical awareness campaign. The red team’s role, as described by Su, is to attempt intrusions and interactions that mirror real attack paths, then feed results back into training.
Binance is often described as a large-scale target in crypto due to its user base and market footprint. Su did not provide additional internal metrics in the interview, but the context underscores the stakes: Binance reports 323 million registered users, while DefiLlama estimates the exchange holds $137.7 billion in assets.
For investors and traders, the takeaway is that big exchanges treat human behavior as part of their threat model. The more a firm relies on operational processes—such as customer support, account access, identity verification, and internal tooling—the more social engineering becomes a risk factor that technical defenses alone can’t fully eliminate.
Social engineering remains a recurring breach pathway
Su’s comments land in the context of broader industry reporting on social engineering as a driver of crypto security incidents. In February, AMLBot estimated that 65% of crypto security incidents in 2025 were driven by social engineering. Later, in April, a long-term social engineering campaign preceded Drift Protocol’s $285 million hack, according to earlier coverage referenced by Cointelegraph.
Su also said the simulated attacks have been in place for three to four years. He suggested that security hygiene has improved substantially since the program began: “In the beginning, the security hygiene left a lot to be desired. But after this amount of time, the company has improved significantly,” he said.
This matters because it highlights a specific operational change: Binance is not treating awareness training as a one-time checkbox, but as an ongoing feedback loop. The key shift for organizations is moving from “teach and forget” to “test, measure, and enforce.”
What the simulations look like: recruiting lures and data-harvesting scenarios
One scenario Binance uses is impersonation of job recruiters. Su said the red team poses as recruiters—an approach that mirrors a common pattern seen in phishing incidents across industries, where “legitimate-sounding” contact becomes the entry point for further manipulation.
Su also described another lure: fake “free conference invites” aimed at collecting personal information and determining how many employees fall for it. He emphasized that the job interview process is only one of multiple scenarios used by Binance’s red team.
These details are important because social engineering attacks in crypto don’t always arrive as obvious “click this link” attempts. They can be structured like legitimate professional outreach, scheduling requests, or follow-ups—channels that can appear normal to staff who might otherwise be trained to recognize traditional phishing emails.
Another well-known technique referenced in the interview is the “Zoom meeting attack,” where attackers trick victims into installing malware disguised as a video conferencing update. Many such campaigns begin with a fake job opportunity, but they can also use other professional hooks like project funding or partnership proposals.
How failure is handled: remediation, reviews, and potential dismissal
Binance’s approach doesn’t end with simulated testing. Su said employees who fail the phishing simulations undergo remediation training. He also described incentives tied to the results, stating that performance reviews reflect test outcomes.
Su’s framing is direct: “If someone repeatedly fails the phishing-simulation attack, that will negatively impact their rating. That’s the incentive to be vigilant.”
He further said repeated severe failures could “bottom out” performance ratings, potentially leading to dismissal. While Su did not outline exact thresholds or timelines for dismissal in the interview, the principle is clear: Binance is treating repeated susceptibility to social engineering as a personnel risk, not just a training gap.
Outside centralized exchanges, similar social engineering dynamics have produced major losses in DeFi ecosystems as well. For example, Cointelegraph referenced a September 2025 incident in which a Venus Protocol user reportedly lost around $13 million after a malicious Zoom client compromised a computer and led the attacker to gain control over the victim’s account. Venus paused the protocol and used an emergency governance vote to recover assets, later returning positions worth $11.4 million to the victim, according to earlier coverage cited in the article.
Those examples reinforce the broader point behind Binance’s internal testing: even when attackers target individuals rather than systems, the outcome can still be catastrophic at scale.
What readers should watch next is whether Binance’s approach—monthly red-team phishing tests, remediation, and performance-linked consequences—becomes a more standard pattern across large crypto firms as regulators and stakeholders increasingly focus on operational security beyond code and infrastructure.
-
Fashion2 days agoWeekend Open Thread: Brooks Brothers
-
Politics7 days agoDemocrats look to World Cup watch parties to register thousands of voters
-
News Videos7 days agoBig Money Is Entering XRP
-
Tech5 days agoSail Virtually Aboard The “Itanic” With IA-64 Emulator
-
Tech5 days ago
Turtle Beach Command Series KB7 review: a nifty screen-equipped gaming keyboard
-
Crypto World5 days agoGrayscale Files For Worldcoin ETF, WLD Registers Sharp Rise
-
NewsBeat6 days agoUnregistered fitter used Gas Safe logo on business flyers
-
Business4 days agoNew Jersey voter registration controversy explained: How 6,600 noncitizens got on the rolls, and what happens next
-
Entertainment4 days agoJohnny Depp’s R-Rated Gothic Cult Classic Gets New Release Ahead of Sydney Sweeney Remake
-
Crypto World3 days agoEthics, other provisions in crypto Clarity Act to be further discussed
-
Tech6 days agoWatch Flock Safety CEO Garrett Langley discuss the future of surveillance at TechCrunch Disrupt 2026
-
Crypto World6 days agoCircle’s President Sold Over 360,000 Shares, The Filings Explain Why
-
NewsBeat5 days agoShanghai science forum photos show China’s AI and robotics advances in rivalry with US
-
Tech6 days agoSubway Sandwich Computers Get a Second Life as Gaming Machines
-
Sports2 days ago2026 3M Open leaderboard: Scottie Scheffler finds putter in Round 1, sits three back
-
News Videos2 days agoThe Peugeot Family: How 200 Years of an “Old Money” Dynasty Died in A Boardroom
-
Fashion2 days ago16 Dresses for the High Summer Event
-
Tech6 days agoThe 35 Best Board Games for Family Game Night
-
Tech6 days agoHow To Use Claude’s Reflect Dashboard And Learn When It’s Time To Touch Grass
-
Entertainment6 days agoStephen Colbert Returns to Social Media After Late Show End

You must be logged in to post a comment Login