Connect with us

Crypto World

How Does Climate Change Impact Nor’easters?

Published

on

How Does Climate Change Impact Nor'easters?

“Not every storm is becoming more intense, but the intense storms are becoming more intense—whether that be a thunderstorm, a hurricane, one of these nor’easters,” Barlow says.

One thing that doesn’t seem to be changing is the number of storms, Barlow adds. “We’re not seeing any changes in the overall average, and the total number of storms might actually be going down a little bit,” he notes.

In an ever warming world, storms are only going to continue to intensify. Climate change is increasing the number of “billion dollar disasters,” disasters that top at least $1 billion in damage, that take place in the U.S. each year. The average length of time between billion-dollar disasters has fallen—from 82 days during the 1980s to 16 days during the last 10 years. In 2025, the U.S. experienced a billion-dollar weather or climate disaster once every 10 days. 

“Until we stop increasing the amount of greenhouse gasses in the atmosphere, the intensity of rainfall, the intensity of these storms, will continue to increase as well,” says Barlow. “Until we stop making things worse, things are going to keep getting worse.”

Advertisement



Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

Google’s PageBreak finds over 500 XSS flaws in its web apps

Published

on

Google bans Chrome prediction market extensions amid Kalshi battle

Google has disclosed that its PageBreak AI security agent has found over 500 cross-site scripting vulnerabilities across the company’s web applications.

Summary

  • Google says PageBreak tests suspected flaws against running applications before sending reports to product teams.
  • The agent uses Gemini models for most scans and separate tools to confirm whether an exploit works.
  • Applications built on Google’s high-assurance frameworks had two XSS findings as of Sep. 4.
  • Google plans to connect PageBreak more closely with CodeMender, which generates security fixes.

The Google Product Security team said PageBreak began as a pilot in November 2025 and became a formal project in January 2026. It tests Google’s own web applications and has found cross-site scripting, or XSS, flaws even on sensitive company domains. Google did not identify the affected applications in its announcement.

XSS occurs when an application allows an attacker’s script to run in another user’s browser. Depending on the application and the attacker’s access, the flaw can expose data or let someone act through an affected user’s session. Google reported more than 500 findings across its applications, but did not give a breakdown by product or severity.

Advertisement

How PageBreak confirms suspected flaws

Rather than sending every suspected bug to a product team, PageBreak passes each candidate to a specialized validator. For an XSS finding, the validator inserts a JavaScript payload, loads the affected page, and checks whether the script runs. Google said the validation step has kept the system’s false positive rate close to zero.

The agent can also test other types of flaws. According to Google, its validators check whether an injected input changes a database query, whether an application exposes a file through path traversal, or whether it can be made to execute code. A separate check looks for requests that an application sends to internal services.

Most PageBreak scans use Gemini models, including Gemini 3.1 Pro and Gemini 3.5 Flash, although Google said the agent can work with different models. The validators themselves are not written by the AI agent. Google also runs agents through repeated attempts because a model can follow an unproductive path before finding a workable exploit.

Advertisement

Google built the validation process in response to a problem its security staff had encountered: AI-generated reports can describe convincing attack paths that fail when tested. Under PageBreak’s process, unverified candidates stay within the security team’s workflow. They can guide later scans or help engineers build new validators, but Google said they are not sent to product teams as confirmed bugs.

PageBreak found two flaws in protected applications

Among hundreds of applications built on Google’s high-assurance web frameworks, PageBreak identified two XSS vulnerabilities as of Sep. 4, Google said. Both were confined to internal applications or debug endpoints with gaps in their security protections. The result covers that group of applications; Google’s figure of over 500 findings covers its first-party web applications more generally.

The framework result gives Google a way to test how its application design holds up against repeated scans. PageBreak also has access to company tools that help it inspect applications at scale. Google said its code repository lets the agent follow paths across services, while security data from live web traffic can connect a requested page to the relevant source code. Existing scanners give it authenticated access to internal sites that can be difficult for an outside researcher to examine.

Those resources help explain the scope of Google’s findings without suggesting that another organization could obtain the same results simply by running a Gemini model. PageBreak’s reported count comes from scans of Google’s applications with access to Google’s code, traffic data and testing systems.

Advertisement

Crypto teams face the same verification workload

The problem of checking AI-generated security reports has also surfaced in crypto software. In July, Ethereum Foundation security research described a process in which agents develop potential findings and separate reviewers try to reproduce them. The foundation reported one confirmed flaw in libp2p, later disclosed as CVE-2026-34219, while warning that plausible reports can involve unreachable code or attack conditions that do not hold in practice.

For teams that handle crypto users’ funds, the difference between a candidate issue and a working exploit affects how quickly a report can lead to a fix. An August Bitcoin Red Team scan logged 7,958 findings across 501 open-source projects after 108 hours. At that point, 24.7% of the findings had reproducible proofs; the full tally did not represent 7,958 confirmed exploitable vulnerabilities.

Earlier reporting on crypto bug bounties described a similar review burden. Cosmos Labs co-CEO Barry Plunkett said in April that submissions to its program had risen 900% from the previous year, including both valid and invalid reports. PageBreak is an internal Google tool, and Google has not said it is available to crypto projects.

Google plans to pair findings with fixes

Even after limiting reports to verified findings, Google said its product teams still receive a high volume of security work. PageBreak is therefore working with other Google projects, including CodeMender, an agent that generates bug fixes. Google plans to deepen that connection so product teams can review proposed fixes alongside confirmed vulnerabilities.

Advertisement



Source link

Continue Reading

Crypto World

OG.com Joins US Push for Single-Stock Perpetual Futures

Published

on

OG.com Joins US Push for Single-Stock Perpetual Futures

OG.com Markets is seeking US regulatory approval to offer perpetual futures tied to individual stocks, as trading platforms push to bring the popular derivatives product to US equity markets.

In a Thursday filing with the Commodity Futures Trading Commission (CFTC), OG.com proposed new rules allowing it to list cash-settled single-stock futures that never expire and can trade 24 hours a day, five days a week.

OG.com was recently spun out of crypto exchange Crypto.com as an independent prediction markets and derivatives platform valued at $5 billion. At the time, CEO Kris Marszalek said the platform planned to expand beyond prediction markets into futures and perpetual contracts.

Shortly after the spin-off, Robinhood took an equity stake in OG.com as part of a multi-year deal to use its CFTC-regulated derivatives exchange and clearinghouse for prediction markets.

Advertisement

Unlike traditional futures contracts, perpetual futures, or “perps,” have no expiration date, allowing traders to maintain exposure without periodically rolling into new contracts. The product was pioneered in crypto by BitMEX in 2016.

Related: President Trump’s media company to terminate Crypto.com deal

Perpetual futures push expands into US stocks

Crypto trading platforms and prediction markets are increasingly looking to bring one of the digital asset market’s most popular derivatives products to US stocks, with OG.com joining a growing group seeking regulatory approval.

On Sept. 18, Coinbase, Kraken parent Payward through its Bitnomial exchange, and prediction market Kalshi all filed to offer perpetual futures tied to individual US stocks.

Advertisement

The filings came after US regulators, including the Securities and Exchange Commission (SEC) and CFTC, pushed ahead with crypto initiatives despite the CLARITY Act failing to advance in the Senate on Sept. 15.

Source: Paul Atkins

Just days after the vote, the SEC cleared limited onchain trading of tokenized US stocks under its Innovation Exemption, while the CFTC expanded regulatory relief for software providers connecting users to regulated derivatives platforms, including those offering perpetual contracts.

The CFTC had already begun laying the regulatory groundwork for perpetual futures months earlier.

In May, the agency established a case-by-case review process for perpetual contracts and approved Kalshi’s Bitcoin perpetual futures product, followed in June by temporary relief allowing certain registered exchanges to convert existing crypto futures into contracts without expiration dates.

Advertisement

Magazine: Exchanges reporting crypto gains to IRS becomes tax nightmare



Source link

Continue Reading

Crypto World

Appeals court rules that states can regulate Kalshi’s sports prediction markets, dealing another legal blow to platforms

Published

on

Appeals court rules that states can regulate Kalshi’s sports prediction markets, dealing another legal blow to platforms

The 6th U.S. Circuit Court of Appeals ruled on Friday that states have a right to regulate sports-related event contracts on prediction market platforms, marking a second major legal defeat for the industry as a fight at the U.S. Supreme Court looms. 

In a unanimous decision, the three judge panel said that Ohio and Tennessee are permitted to apply their state gambling laws to Kalshi’s sports-related event contracts. 

“We hold that Kalshi has not shown that its sports-event contracts satisfy the statutory definition of a ‘swap’ so as to fall within the scope of the CFTC’s ‘exclusive jurisdiction,’” the opinion said. 

Kalshi and other prediction market platforms argue all event contracts are swaps, a type of financial derivative that is regulated by the Commodity Futures Trading Commission. However, states assert that platforms’ sports-related offerings amount to gambling, and thus should be regulated by their laws related to sports betting. 

Advertisement

This disagreement has spawned a legal battle across the country as states sue platforms for operating what they often claim are illegal gambling operations, while exchanges also sue states to block them from enforcing local laws on what they argue should be federally-regulated financial exchanges. 

The CFTC has sued nine states to defend what it believes is its exclusive right to regulate event contracts, given to it by the Commodity Exchange Act. But the 6th Circuit panel rejected that notion. 

“Even assuming that Kalshi’s sports-event contracts are swaps, we alternatively hold that the CEA neither expressly nor impliedly preempts Ohio’s or Tennessee’s gambling laws,” the opinion said. The decision overturns a Tennessee federal district court ruling that sided with Kalshi, and reaffirms a decision by a federal district court in Ohio that sided with the states’ argument. 

“Kalshi attempted an end run around Tennessee law to avoid any of the rules or taxes associated with sports gambling. They failed,” said Jonathan Skrmetti, Tennessee’s attorney general.

Advertisement

“Sports wagering is heavily regulated because it can do a lot of harm, and I’m glad we thwarted Kalshi’s efforts to remove every safeguard and put Tennessee sports bettors at risk,” he added.

Kalshi nor the CFTC immediately responded to requests for comment. CNBC has also reached out to the Ohio attorney general’s office for comments. 

The latest ruling now means prediction market platforms have notched two losses in legal fights at the appeals court level. The 9th U.S. Circuit Court of Appeals ruled last month that Nevada has a right to regulate sports-related event contracts, stating that they were sports bets and not swaps. Meanwhile, the 3rd U.S. Circuit Court of Appeals ruled against New Jersey in April and said the CFTC has the exclusive right to regulate all swaps, no matter the contract type. 

New Jersey appealed that decision in a petition to the Supreme Court earlier this month. It is not clear whether the Supreme Court will take up the case now, or wait until further decisions from circuit courts on the issue of sports-related event contracts are delivered. 

Advertisement

Disclosure: CNBC and Kalshi have a commercial relationship that includes customer acquisition and a minority investment.



Source link

Continue Reading

Crypto World

The True Story Behind ‘Unabomber’

Published

on

The True Story Behind 'Unabomber'

The psychological experiment scenes presented a different challenge. Tremblay was strapped to a chair, limiting his movement and expressions. “I learned to utilize that unfamiliar and uncomfortable environment to my advantage,” Tremblay says. “Because Ted himself in that moment is also experiencing that discomfort and unfamiliarity at the same time.”

How accurate is the Netflix movie?

Unabomber is grounded in documented events from Kaczynski’s life, but the film also takes creative liberties with gaps in the historical record.

“But that was fun for the filmmakers and us actors as we got to create something unique from the story we pieced together and that excited me because it distinguishes our film from other tellings of the Unabomber’s story,” Tremblay says.

Advertisement

For Metz, the film was also an opportunity to explore parts of Kaczynski’s story that are less familiar to audiences.

“In developing the film, we found that the psychological experiments conducted on Ted Kaczynski during his time at Harvard were unknown to most people, some were not even aware he attended Harvard,” Metz says. “While our film doesn’t offer a complete biography, we chose to present a filmic take on his story and a narrative opening into the mind of Ted Kaczynski.”



Source link

Advertisement
Continue Reading

Crypto World

OG.com Pursues CFTC Approval to Launch Single-Stock Perpetual Futures

Published

on

Crypto Breaking News

OG.com Markets has submitted a filing to the U.S. Commodity Futures Trading Commission (CFTC) seeking approval to launch cash-settled perpetual futures linked to individual stocks—an effort to bring a product format widely used in crypto derivatives into traditional equity markets.

According to the CFTC filing released Thursday, the proposed rules would cover single-stock futures that do not expire (“perpetuals”), trade around the clock, and are designed to offer continuous exposure without requiring traders to roll positions into new contract months.

Key takeaways

  • OG.com Markets is pursuing CFTC approval for perpetual futures tied to specific U.S. equities.
  • The product is described as cash-settled and perpetual, with continuous trading for five days a week.
  • Regulatory momentum comes as other major crypto trading and prediction-market players also seek permission to offer similar stock-linked perps.
  • The CFTC has been building a framework for perpetual contracts through approvals and temporary relief tied to specific arrangements.

OG.com’s CFTC filing outlines stock-linked “perps”

In a Thursday filing with the CFTC, OG.com Markets outlined a proposed rule set intended to enable the listing of cash-settled single-stock futures that never expire. The proposal also calls for trading to operate 24 hours a day, five days a week.

Perpetual futures differ from traditional futures by removing the need for contract expiration. For traders, that structure can reduce the operational friction of rolling between dated contracts, while for markets it can support more continuous liquidity and positioning.

The concept is not new in crypto. Perpetual contracts were pioneered in digital-asset derivatives, with BitMEX introducing an early version of the model in 2016—helping make “perps” one of the most actively traded derivatives formats in the sector.

Advertisement

How OG.com ties into the wider prediction-markets and derivatives shift

OG.com Markets recently emerged as an independent prediction markets and derivatives platform after being spun out from crypto exchange Crypto.com. At the time of the separation, OG.com was described as being valued at $5 billion, and CEO Kris Marszalek said the company planned to expand beyond prediction markets into futures and perpetual contracts.

Shortly after the spin-off, Robinhood acquired an equity stake in OG.com as part of a multi-year agreement. The deal includes the use of OG.com’s CFTC-regulated derivatives exchange and clearinghouse for prediction markets. That backdrop matters because it places OG.com’s U.S. equity-derivatives ambitions directly within a set of business relationships already aligned with regulated derivatives infrastructure.

Importantly, while OG.com is now aiming at stock-linked perpetual futures, its current positioning originates in prediction markets—where the mechanics of cash settlement and continuous trading can be attractive to participants who want to express views over time without physical delivery.

Not alone: Coinbase, Kraken’s parent, and Kalshi have also filed

OG.com’s move fits into a growing cluster of filings from platforms attempting to introduce perpetual futures tied to individual U.S. stocks. Earlier coverage noted that Coinbase, Kraken parent Payward through its Bitnomial exchange, and prediction market platform Kalshi all filed to offer similar stock-linked perpetual futures.

Advertisement

The timing also reflects a regulatory environment that has been more permissive toward certain crypto-adjacent activities than some market participants expected. The shift gained attention after U.S. Senate action failed to advance the proposed CLARITY Act on Sept. 15—yet regulators continued moving forward on crypto initiatives through other channels.

In particular, after the Senate vote, the SEC cleared limited onchain trading of tokenized U.S. stocks under its Innovation Exemption, and the CFTC expanded regulatory relief for software providers that connect users to regulated derivatives platforms, including those offering perpetual contracts.

The CFTC’s groundwork for perpetual contracts

The CFTC’s approach to perpetual futures has not been confined to one company or one application. The agency previously began laying out a path for perpetual contracts through a combination of case-by-case review and targeted relief.

In May, the CFTC established a case-by-case review process for perpetual contracts and approved Kalshi’s Bitcoin perpetual futures product. It then followed in June with temporary relief allowing certain registered exchanges to convert existing crypto futures into contracts without expiration dates.

Advertisement

That incremental regulatory scaffolding helps explain why the market is converging on perpetual structures now. Even without a single comprehensive rule that automatically covers every new product variation, firms can structure applications around how the CFTC has already evaluated perpetual contracts—making the approval process feel more navigable than it might have been in earlier years.

For investors and traders, the key question is how quickly the CFTC can translate precedent from crypto perpetuals and targeted relief into approvals for cash-settled, stock-linked perps. Watch for updates on the OG.com rulemaking process and whether regulators request changes to trading mechanics, settlement terms, or operational guardrails as these filings move through review.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure



Source link

Advertisement
Continue Reading

Crypto World

In ‘Ha-Chan, Shake Your Booty!,’ Dance and Desire Are Remedies for Grief

Published

on

In 'Ha-Chan, Shake Your Booty!,' Dance and Desire Are Remedies for Grief

When Haru meets Fedir—whose wife is a Paris-based dance champion, though the marriage is an open one—she glimpses fresh possibilities, or at least just an adventure. In an early scene, after she and Fedir have had a pleasant, platonic dinner together, they’re ready to part ways in the street. A crew of drunken businessmen jostle Haru, and Fedir stands up for her. What follows is a cleverly choreographed dream ballet—though the genre is actually the bachata, one of the dance forms Fedir teaches, its movements an expression of longing and heartache—in which Fedir defends Haru’s honor against this gang of boorish men. Other passersby join in, and the scene becomes a metaphor for the act of rejoining life. By the end of the evening, Haru and Fedir have tumbled into bed.

Their two hookups are enjoyable and tender—until the wife shows up, and Haru realizes she has feelings she can’t control. Kikuchi shifts gears smoothly: One minute, she shows how Haru is nearly deadened by sorrow. The next, her exhilaration becomes a kind of artificial sunshine. But a flash of anger and jealousy causes her to act out, in a scene that makes you recoil a bit even as you laugh. Kikuchi is perhaps best known for her roles in movies like Babel and Pacific Rim, as well as HBO’s Tokyo Vice, several episodes of which Wladyka directed. Here, she captures the spirit of a woman who longs to get back to being herself, if only she could remember who that self was. Haru is both breezy and cautious, and totally lost. By the movie’s end, she has found her way forward, because she realizes there’s no going back. She’ll have to be a new person, encompassing the experiences and memories of the old one. Kikuchi captures that difficult butterfly transition as it unfolds; it’s both painful and funny to watch. But in the end, she shows us how Haru finds her way back to the music, which is the only way she can move into the future, one note, and one dance step, at a time.   



Source link

Continue Reading

Crypto World

Blockchain Association sees leadership shift shortly after crypto Clarity Act fizzles

Published

on

Blockchain Association sees leadership shift shortly after crypto Clarity Act fizzles

Summer Mersinger is leaving the helm of the Blockchain Association, one of the crypto industry’s leading advocacy groups, a week after the sector weathered a major legislative setback in the loss of the Digital Asset Market Clarity Act.

Mersinger will be replaced — for now — by Kristin Smith, the organization’s original CEO who ran the association from its launch in 2018 until 15 months ago, according to a Friday statement. The handover is set for October 16, closing a tumultuous era that saw major crypto wins in Washington and a significant defeat last week, when the U.S. Senate failed to advance the Clarity Act in a wide loss in which all the Senate’s Democrats and some Republicans declined to support it.

“I’m proud of how far we’ve come together, from the GENIUS Act to real regulatory clarity at the SEC and CFTC,” said Mersinger, who’d taken the job after leaving her post as a member of the Commodity Futures Trading Commission, in a statement. “Kristin built this association from the ground up, and BA is in good hands. I’ll be cheering them on.”



Source link

Advertisement
Continue Reading

Crypto World

Tether Says ‘Limited’ Exposure after Prosecutors Seize $84M from Business

Published

on

Tether says it had ‘limited’ exposure to bank linked to $84M US seizure

Tether says it had ‘limited’ exposure to bank linked to $84M US seizure

US prosecutors alleged that a payments business illegally transferred hundreds of millions of dollars at the direction of EQIBank, where Tether holds some assets.



Source link

Continue Reading

Crypto World

Death of Former Hack VC Partner Hsin-Ju Chuang Ruled Suicide

Published

on

Crypto Breaking News

Hsin-Ju Chuang, a former partner at the crypto venture firm Hack VC, has died at age 37, according to the San Bernardino County Sheriff-Coroner. The county’s Coroner Death Registry later listed her death as a suicide.

California Highway Patrol officers responded on Aug. 24 to a report southbound on Interstate 15 south of Field Road in Harvard, California, where Chuang was pronounced dead at the scene, the sheriff’s office said in a coroner press release linked in the report.

Key takeaways

  • San Bernardino County Sheriff-Coroner records list Chuang’s death as a suicide after an Aug. 24 response on Interstate 15.
  • Chuang previously worked across major crypto ecosystems, including roles tied to Stellar and Solana.
  • Hack VC said it had not spoken directly with Chuang for more than 10 months and had no additional details about the circumstances.
  • Chuang had publicly accused Hack VC of mistreatment and said she planned to release evidence, according to her earlier posts.

What authorities and county records show

Officer response details point to an Aug. 24 incident on Interstate 15 in Harvard, California. Chuang was pronounced dead at the scene, according to the information referenced from the San Bernardino County Sheriff’s media materials.

A search of the San Bernardino County Sheriff’s Department Coroner Death Register shows Chuang’s entry dated Aug. 24, 2026. The registry later categorized her death as suicide.

Chuang’s background in crypto investing and projects

Chuang’s professional profile traces a career spanning both venture and ecosystem growth. Per her LinkedIn profile, she founded Dystopia Labs and held leadership roles that included head of growth at Stellar and Solana.

Advertisement

In venture, she joined Hack VC in 2021 as a venture partner. Later, she became partner and head of platform in 2025, according to the same publicly listed career history.

Hack VC’s statement and what it said it knew

Hack VC co-founder and managing partner Alexander Pack said the firm was “shocked and saddened” by Chuang’s death and extended condolences to her family, friends, and those close to her.

Pack added that Hack VC had not spoken directly with Chuang for more than 10 months. He said the firm was not aware of the circumstances surrounding her death and that it had “no further information,” urging people to be respectful of those grieving.

Earlier public accusations and unresolved questions

Before her death, Chuang had publicly accused Hack VC of mistreating her during her time at the firm. In her posts, she said she intended to release evidence supporting her allegations.

Advertisement

In that context, Chuang also described attempting suicide after experiencing what she characterized as mistreatment while she was “going through a serious medical emergency,” according to the account presented in the earlier public statement referenced in the report.

With the coroner registry now listing her death as suicide, the relationship between those prior allegations and the circumstances of her death remains a sensitive and unconfirmed area that readers should approach cautiously. Hack VC’s statement emphasizes it did not have recent direct contact and did not know the circumstances at the time of her passing.

Chuang’s death also raises a broader question for the crypto industry: how mental-health and workplace conflict are handled, documented, and addressed—especially in highly networked environments where reputational battles can move quickly into public channels.

For now, what matters most is what additional public information, if any, emerges from the coroner process and whether any further verified details about the earlier claims become available. Observers will likely watch for follow-up statements from those close to Chuang, as well as any developments that clarify the gap between her earlier allegations and the circumstances surrounding her death.

Advertisement

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure



Source link

Continue Reading

Crypto World

Bitget Updates: $388M in Assets Impacted by Security Breach

Published

on

Crypto Breaking News

Bitget has revised its accounting of losses from last week’s security breach, raising the figure tied to attacker-controlled addresses to $387.5 million—up from an earlier estimate of $352 million. The updated incident report, released Thursday and followed by another update Friday, also said the incident remains contained and that no further unauthorized transfers are possible.

The exchange reiterated that it will continue pausing withdrawals and said it has launched a bounty program intended to help freeze or recover affected assets. The key change in Bitget’s latest disclosure is a “more complete accounting” of transfers, including assets that were not included in the initial estimate.

Key takeaways

  • Bitget updated its breach figures: $387.5 million was transferred to attacker-controlled addresses, not $352 million.
  • The exchange said the revision reflects additional accounting of affected assets on Zcash and TRON, without indicating any new unauthorized activity.
  • Withdrawals remain paused, while Bitget launched a bounty program aimed at freezing or recovering funds.
  • Bitget reported involvement of multiple networks, including EVM chains, XRP Ledger, Zcash, and TRON.

What Bitget changed in its incident report

In its revised accounting, Bitget said that the updated figure comes from a fuller reconciliation of transfers that occurred during the incident. The exchange attributed the adjustment to affected assets on Zcash and TRON that were left out of the initial estimate, stating that the new number does not reflect further unauthorized transfers.

Bitget’s statement emphasized containment: the company said the incident remains contained and that “no further unauthorized transfers are possible.” For users watching the case, the practical implication is that the revision is about measurement and scope rather than evidence of an expanded compromise.

Withdrawals paused as attacker routing is traced on-chain

In its Friday update, Bitget confirmed it will continue pausing withdrawals. At the same time, the platform said it has launched a bounty program designed to incentivize efforts to freeze or recover the assets that were moved to addresses controlled by the attacker.

Advertisement

Bitget also pointed to on-chain tracing in explaining where funds went. According to the exchange, “$387.5 million were transferred to attacker-controlled addresses,” with the revised total about $35 million higher than the earlier number. In other words, the updated report is not just a re-phrasing of loss estimates—it is an adjustment tied to the mapping of those transfers to attacker-controlled endpoints.

Networks and assets implicated across the ecosystem

Bitget’s revised incident report lists multiple affected blockchain environments. The exchange said the incident involved addresses on Ethereum Virtual Machine (EVM) networks as well as the XRP Ledger, Zcash, and TRON.

The follow-up disclosure also enumerated several assets the attackers allegedly took. According to Bitget, stolen or affected assets included XRP, Ether (ETH), Tether’s USDt (USDT), Zcash (ZEC), USDC, USDT0, XAUt, BNB, AVAX, and TRX.

For investors and traders, the multi-network nature of the incident matters because it affects how quickly risk can be reduced. Different chains can require different monitoring, compliance processes, and—critically—different operational steps for exchanges trying to halt or limit withdrawals and protect hot and intermediate custody.

Advertisement

Broader industry context and what remains unclear

Even with the clarification on the corrected loss figure, Bitget’s security breach remains among the largest incidents to hit the industry. The article’s context highlights that hackers stole about $1.5 billion worth of Ether from Bybit in February 2025, underscoring how damaging major exchange compromises can be even when withdrawals are halted and funds are monitored.

Notably, Bitget’s later update did not directly address comments made by CEO Gracy Chen from Thursday. In earlier coverage, Chen speculated that a North Korean hacking group might be behind the attack, citing what she described as “IP clues.” The revised incident report, as presented in the update, focuses on accounting and containment rather than attributing the breach to a specific actor.

That leaves an important tension for readers: while the exchange’s updated figures aim to settle questions about scale, attribution and motive appear to remain separate and unresolved in Bitget’s latest public disclosures. As the bounty program ramps up and tracing work continues, additional information could emerge—either from on-chain evidence, coordination efforts to identify and freeze assets, or follow-on updates from the exchange.

For now, market participants should watch whether Bitget later provides more details on recovery efforts and the timeline for when withdrawals might resume, alongside any further revisions to affected totals. The updated numbers suggest the incident’s spread is better understood, but the path from attacker-controlled transfers to recoverable funds—and the question of who carried out the breach—will likely determine the next phase of this story.

Advertisement

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure



Source link

Continue Reading

Trending