Crypto World
How $VLAD farms its victims
When hackers hijacked Robinhood’s CEO’s X account, they did not run the usual smash-and-grab. They launched a token whose liquidity is locked forever, un-ruggable by design, and are collecting trading fees from it in perpetuity. The rug pull just evolved into a yield product, and the anti-scam infrastructure built the machine.
Summary
- Hackers compromised Robinhood CEO Vlad Tenev’s X account on Thursday and promoted Vladhood ($VLAD) as the “official mascot” of Robinhood Chain, drawing 175,000 views in under 20 minutes and $22 million in trading volume.
- The operation was premeditated, not opportunistic: the token contract deployed 46 minutes before the hacked post, through the Pons launchpad, with Tenev’s own X profile listed as the token’s official website.
- The mechanism is the story: Pons locks a token’s liquidity permanently, making rug pulls impossible, but lets creators claim trading fees, so the attacker farms income from every trade, roughly $59,000 claimed in the first hours and still accruing, atop total proceeds estimated at $1.2-1.3 million.
- The design inverts a decade of scam economics: instead of one exit event, the scammer holds a perpetual annuity on victim activity, and the anti-rug protection that legitimizes the launchpad is precisely what guarantees the income.
- It is the second executive-account token scam on Robinhood Chain in eleven days, six days before the company’s earnings call, and it poses a question the industry has not answered: who is liable when scam-proofing infrastructure becomes the scam’s business model.
Crypto crime has a classical form, refined over a decade: create a token, manufacture credibility, collect the victims’ money, and vanish, the rug pull, a crime with a beginning, a middle, and above all an end. What happened on Thursday, when hackers seized the X account of Robinhood’s chief executive and pointed 15 million followers at a memecoin called Vladhood, had the beginning and the middle and then, deliberately, no end.
The attackers launched $VLAD through a launchpad whose signature safety feature locks a token’s liquidity forever, which means the token cannot be rugged, which means, and here is the inversion worth an entire article, the scam never has to stop. The locked pool collects trading fees on every swap, the launchpad pays those fees to the token’s creator, and the creator is the hacker, who called the fee-collection function six times in the first two hours and has no reason ever to stop calling it. The rug pull was a robbery. This is a toll booth, built on stolen credibility, operated in public, generating income for its architect with every trade, protected by the exact mechanism the industry built to protect traders. The Defiant’s on-chain forensics documented the machine within hours; what the machine means, for scam economics, for the launchpads, and for the brokerage whose chain now hosts its second executive-impersonation token in eleven days, is the subject here.
The operation, reconstructed
The timeline, assembled from on-chain records and the forensic work of The Defiant and Onchain Lens, settles the fact that reframes everything else: this was a single coordinated operation, planned around the account takeover, not a scammer riding a lucky hack.
At 12:38 pm ET on Thursday, a wallet with no prior history launched Vladhood through Pons, the busiest of the Pump.fun-style launchpads that colonized Robinhood Chain in its first month. The launch parameters included a detail that functions as a confession of premeditation: the token’s official website field listed Tenev’s X profile URL, meaning the creators configured the token around an account they did not yet publicly control. Forty-six minutes later, the post appeared on that account: Does Robinhood love memes? The answer is yes, introducing $VLAD as the official mascot of Robinhood Chain, falsely promising a Robinhood app listing, signed off, Welcome to the Hood, with the contract address attached. The credibility stack was complete: a verified account, a CEO’s voice, a chain the CEO actually launched three weeks earlier, and a claim, app listing, that sat exactly on the boundary of plausible.
The market did what engineered credibility makes it do. The post drew more than 175,000 views in under 20 minutes; the token ran up more than 90,000% from launch; volume reached $22 million across roughly 85,000 swaps in the main pool; the market cap touched somewhere between $4 million and $10 million depending on the snapshot; 5,266 holders and 137,000 transfers accumulated on a contract deployed that afternoon. Robinhood’s communications team confirmed the compromise roughly 41 minutes after the post and worked with X to delete it; the chain’s own explorer flagged the contract as a likely scam. On-chain monitors estimate wallets tied to the operation extracted around 650 to 690 ETH, between $1.2 million and $1.3 million, through the classic half of the play, early wallets, holding a reported 70% of supply, selling into the spike.
And then the part that makes this a new genre: the sale was not the payday’s end. It was the down payment.
The mechanism: anti-rug as annuity
To see the innovation, start with the protection it exploits, because the protection is real and the exploitation is parasitic on its virtue.
Launchpads in the Pump.fun lineage answered the rug pull structurally: when a token graduates to a trading pool, the platform locks the liquidity in a locker contract the creator cannot drain. The creator cannot pull the pool, so the classic exit, remove liquidity, collapse the price to zero, vanish, is mechanically impossible, which is the safety pitch that lets these platforms describe themselves as scam-resistant and lets traders ape into anonymous tokens with one category of fear removed. Pons implements the standard design with the standard incentive attached: locked liquidity still generates trading fees on every swap, and those fees are claimable by the token’s creator, a reasonable arrangement meant to reward legitimate builders whose tokens sustain volume.
Now run the $VLAD operation through that machinery. The attacker cannot rug, and does not need to. Every trade in the pool, the panic selling after the exposure, the bagholders averaging down, the day traders playing the volatility, the bots arbitraging the chaos, pays a fee, and the fee flows to the creator wallet on demand. Starting seven minutes after the fake post, the wallet called the locker’s fee-collection function six times over roughly two hours, netting about 31.6 ETH, roughly $59,000, and the meter is still running: the balance grows as long as anyone, for any reason, trades the token. The Defiant’s framing captures the inversion precisely: the wallet did not need to pull liquidity to cash out. The token never rugged. It just collects.
The economics deserve to be stated as the design they are. A rug pull monetizes credibility once, in a single extractive event that ends the scam and starts the manhunt. The locked-liquidity structure converts the same stolen credibility into an income-producing asset: a perpetual claim on the trading activity of a token that cannot die by its creator’s hand, whose infamy itself sustains volume, and whose victims’ every attempt to trade out of their position pays the person who put them in it. The scam has acquired a business model, and the business model was donated by the anti-scam infrastructure. Eleven days earlier, crypto.news covered the predecessor eleven days earlier, the SCATMAN operation, run through SpaceX’s hijacked accounts onto this same chain, which took $135,000 in the classical style and ended. $VLAD’s operators took ten times that in the opening hours and, structurally, have not ended at all. That delta, between a robbery and a franchise, is the evolution this incident marks.
The venue, the timing, and the liability question
The setting compounds the story, because the chain hosting this evolution belongs to a licensed brokerage six days from its earnings call.
Robinhood Chain’s first month, as this publication has documented in the venue’s first-month composition problem, delivered $700 million in assets, 300,000 daily active addresses, top-tier DEX volume, third place in seven-day chain revenue, and a composition problem: memecoins driving the overwhelming majority of activity against roughly $13 million in the tokenized real-world assets the chain was built for. The scam wave is the composition problem’s sharpest edge, SCATMAN through hijacked SpaceX accounts on July 12, a launchpad going dark mid-boom with an estimated $12 million in fees, and now the chain’s own founder’s face on its most sophisticated fraud, a token the chain’s explorer flags as a scam while the chain’s fee mechanics, this is the uncomfortable part, collect revenue on every one of its trades, as does the sequencer’s operator. A brokerage whose regulatory identity is bringing compliant rails to digital assets is earning protocol revenue, however small, on a fraud impersonating its own CEO, and its earnings call, where management must frame the chain’s first month for analysts and its Say-platform retail questioners, now has its opening exhibit. That is the earnings call this incident now precedes.
The liability question is the one the industry has not answered, and $VLAD converts it from hypothetical to operational. The launchpad designed the locker; the locker guarantees the scammer’s income; the design choice that prevents one crime funds another. Is Pons, which profits from launch fees and whose factory contract the explorer flagged, a neutral tool provider, the Section 230 of token creation, or does operating a fee-annuity machine that any account thief can drive create obligations, to freeze creator-fee claims on flagged tokens, to require identity for fee withdrawal, to build the kill switch the anti-rug design deliberately omitted? Every answer has a cost: freezable fees reintroduce the trusted operator the architecture exists to remove, identity requirements gut the permissionless launch model that generates the volume, and doing nothing leaves the annuity running. The same trilemma applies one level up, to the chain, and one level higher, to X, whose verified-account security has now been the entry point for two nine-figure-audience token frauds in eleven days on the chain the scams chose alone, part of a lineage running from the 2024 celebrity-account wave through this month’s fake Armstrong coin. Executive social accounts have become, functionally, financial infrastructure, secured like consumer products.
The economics of borrowed trust, quantified
Step back from the mechanism and the incident yields something rarer than a forensic timeline: a clean measurement of what stolen credibility is worth per minute, and a market structure that prices it.
Run the numbers as a conversion funnel. The hijacked account held roughly 15 million followers; the post survived approximately 20 minutes in primary distribution and drew 175,000 views; the token processed $22 million in volume and accumulated 5,266 holders within hours; the operators extracted $1.2 to $1.3 million in direct proceeds plus the ongoing fee stream. That is roughly $65,000 of extraction per minute of post uptime, about $7.40 per view, and around $250 of eventual volume per view, numbers that explain, better than any security advisory, why executive account compromise has become a professionalized industry with its own supply chain: access brokers who source the credentials, operators who build the token infrastructure in advance, and distribution specialists who time the post. The 46-minute pre-deployment is the industrial tell, the attack was inventory waiting for its distribution moment, and the same funnel mathematics applied to the SCATMAN operation, a smaller account constellation and a cruder mechanism, yielded a tenth of the proceeds, which is exactly the relationship a maturing industry’s cohort analysis would predict: returns scale with audience quality and mechanism sophistication, and both are improving.
The funnel also identifies where defense actually binds, and it is not where the industry spends. Post-hoc measures, explorer flags, account restoration, post deletion, all activated within the hour here, and the operation was profitable within seven minutes; the deletion ended distribution after the extraction window had already closed. The binding constraint is upstream: the account security that gates the distribution moment, and the launch infrastructure that lets the monetization machine be assembled anonymously in advance. Which is why the two reforms with actual leverage are unfashionable ones, hardware-key mandates and session-hygiene requirements for accounts above an audience threshold, effectively treating large verified accounts as the financial infrastructure they now are, and creator-fee escrow periods on launchpads, a delay between fee accrual and fee claim long enough for flags to propagate, which would have converted $VLAD’s annuity into a frozen exhibit without touching the permissionless launch itself. Neither reform requires identifying anyone; both attack the funnel’s throughput rather than its aftermath. The industry’s current posture, in which a nine-figure-audience account is secured by whatever its owner chose and a flagged scam’s fees flow to its operator in real time, is not a policy. It is a bounty schedule, published daily, and Thursday’s operators simply read it.
What to watch
The fee meter. The creator wallet’s claims are public and ongoing. Whether the balance crosses six figures, and whether anyone, Pons, the chain, a court, ever interrupts it, is the cleanest measure of whether the industry treats this as an incident or a precedent. As of the first day, nothing in the architecture can stop it.
The launchpad’s response. Pons faces the trilemma first: freeze mechanics, identity gates, or explicit neutrality. Its choice, and whether Robinhood Chain pressures it, writes the first draft of the fee-annuity era’s rules, and every copycat is watching. The design is trivially replicable on any chain with a locked-liquidity launchpad, which is all of them.
The earnings call, July 29. Whether analysts or Say questioners force management to address the scam wave on the record, and whether the answer gestures at curation, moderation, or enforcement, would mark the first time a public brokerage defines its responsibility for frauds conducted on infrastructure it operates and profits from.
The security postmortem. How the attackers took the account, SIM swap, session theft, insider access, matters for every executive in the industry, because the $VLAD operation’s real innovation was pairing patient token engineering with account compromise as a single planned instrument. The 46-minute gap between deployment and post is the tell: this was manufactured, and manufacturing scales.
The rug pull is dying the way all crimes die, by evolving into something the law has not named yet. $VLAD’s architects understood what the industry’s own safety engineering had built: a machine that converts stolen credibility into permanent income, legally ambiguous, mechanically unstoppable, and hosted on the most scrutinized new chain in crypto. The $59,000 in claimed fees is a small number. The design it proves out is not, because every locked pool on every launchpad on every chain is now, visibly, a potential annuity for whoever can manufacture one hour of borrowed trust, and the industry that built the locks has not built the thing that comes after: a way to stop paying the thief.
A closing note on the naming problem, because it will shape the response. The legal system has vocabulary for the rug pull: theft, wire fraud, market manipulation, each with elements prosecutors know how to plead against an exit event. The fee annuity fits none of them cleanly. The initial impersonation is straightforwardly criminal, identity theft and securities-adjacent fraud in the account takeover and the false listing claim, and any eventual defendant will face those counts. But the ongoing income stream is stranger: after the exposure, every subsequent trader in $VLAD acts with full knowledge that the token is flagged, the fees are disclosed by the mechanism itself, and the operator extracts value not by deceiving anyone still present but by having once deceived people no longer trading. Whether collecting contractually-defined fees from a pool of informed speculators constitutes ongoing fraud, unjust enrichment, or merely distasteful legality is a question no court has answered, and the answer determines whether the annuity can be seized, whether launchpads face aiding liability for paying it out, and whether the design spreads with impunity. It is another case of when mechanism design meets adversaries. The industry’s enforcement history suggests the question gets answered slowly and by the worst possible case: some future iteration of this design, at ten times the scale, attached to a fraud egregious enough to force the doctrine. Until then, the $VLAD wallet keeps calling its function, the locker keeps paying, and the gap between what the mechanism permits and what the law has named sits open, collecting fees.
Frequently asked questions
What happened to Vlad Tenev’s X account?
Hackers took control of the Robinhood CEO’s verified X account on Thursday, July 23, and posted a promotion for a fake memecoin called Vladhood ($VLAD), presenting it as the official mascot of Robinhood Chain and falsely claiming it would be listed on the Robinhood app. The post drew over 175,000 views in under 20 minutes before removal. Robinhood confirmed the compromise about 41 minutes after the post and said it was working with X to restore access.
Was this an opportunistic hack?
No, it was premeditated and coordinated. On-chain records show the token contract was deployed through the Pons launchpad 46 minutes before the fraudulent post appeared, and the launch configuration listed Tenev’s own X profile as the token’s official website, meaning the operation was built around an account takeover that had not yet happened publicly. The account compromise and token launch were parts of a single planned instrument.
How much did the attackers make?
Two figures describe it. On-chain monitors estimate total proceeds of roughly 650 to 690 ETH, about $1.2 to $1.3 million, largely from early wallets, holding a reported 70% of supply, selling into the spike. Separately, the locked liquidity pool has paid the creator wallet approximately $59,000 in trading fees in the first hours, claimed across six withdrawals, and that stream continues to accrue with every trade.
Why is the token impossible to rug pull, and why does that matter?
The Pons launchpad locks a token’s liquidity in a locker contract the creator cannot drain, a standard anti-rug protection. That makes the classic exit scam impossible, but the locked pool still generates trading fees that the creator can claim. The attacker therefore holds a perpetual income stream from all trading in the token, converting a one-time scam into an ongoing annuity that the protection itself guarantees.
How does this compare to the SCATMAN incident?
SCATMAN, eleven days earlier, used hijacked SpaceX and Starlink accounts to promote a token on the same chain and extracted roughly $135,000 in the traditional pump-and-dump style, an operation with an end. $VLAD extracted roughly ten times more in its opening hours and structurally has no end, because the fee stream persists. The two incidents mark an evolution in method on the same venue within two weeks.
Does Robinhood bear responsibility for scams on its chain?
That is the unresolved question the incident sharpens. The chain is permissionless, and Robinhood did not authorize the token, but the network and its sequencer earn revenue on all activity, including fraud, and the chain’s explorer flagging cannot stop trading or fee claims. The launchpad faces the same trilemma: freezing fees or requiring identity would compromise the permissionless model, while inaction leaves the annuity running. No platform has yet defined its obligations.
What should users take from this?
That verified executive accounts are now a primary fraud vector: two major incidents in eleven days used hijacked official accounts, and posts announcing surprise tokens should be treated as compromises by default, checked against official company channels, which stayed silent in both cases. Locked liquidity means a token cannot be rugged; it does not mean the token is legitimate, and in this design, trading a flagged token pays its creator.
Could this scam model spread?
Easily, which is its significance. Any launchpad that combines locked liquidity with creator-claimable fees, the dominant design across chains, can host the same structure, and the required ingredient, an hour of borrowed credibility, can come from any compromised account with reach. Until platforms build mechanisms to interrupt fee claims on flagged tokens, each such pool is a potential perpetual payout for whoever manufactures the trust. This is educational analysis, not financial or legal advice.
Disclaimer: This article is for information and educational purposes only and does not constitute financial, investment, or legal advice. It describes an ongoing security incident based on on-chain data and reporting available at the time of writing, and figures may change as investigations continue. Never interact with tokens promoted through unverified or compromised channels. Always do your own research. Information is accurate as of July 24, 2026.
Crypto World
BitMart to shut down after nine years, exchange token crashes 58%
BMX, the platform’s token, fell to about 8 cents, down 58% over 24 hours, cutting its market value to roughly $27 million. The token was already down about 70% over the past year, so Sunday’s drop extended a long decline rather than starting one.
The exchange’s trading figures are significant, despite the closure. BitMart reported about $1.6 billion in 24-hour volume, up 51% from the previous period, with bitcoin accounting for nearly half of it. That jump more plausibly reflects users unwinding positions and moving funds out than any fresh demand, but it leaves open why a platform still clearing that kind of flow is closing.
Meanwhile, the withdrawal terms carry more friction than a routine exit. BitMart said requests may face additional review covering identity verification, device and IP checks, withdrawal-address screening, source-of-funds questions and sanctions checks, and warned that processing could stretch if request volumes spike.
BitMart lost about $196 million to a hot-wallet breach in December 2021, one of the larger exchange hacks of that cycle, and covered customer losses at the time.
Crypto World
Shiba Inu Price Soars 35% on a Dull Day as Whale Returns With Massive SHIB Purchase
In another relatively boring and uneventful trading day during the weekend, in which most cryptocurrencies have remained sideways, the second-largest meme coin by market cap exploded in a rare reminder of what the niche used to do a few years ago.
Some of the potential reasons behind this massive surge seem to be related to a returning whale and other on-chain factors.
SHIB’s Big Pump
The popular meme coin, once touted as the Dogecoin killer, actually began its ascent yesterday evening. It stood below $0.0000042 before it shot up to $0.0000052 and to $0.0000058 earlier today, posting a massive double-digit surge. The latter became its highest price tag in just over two months.
Recall that the token was rejected at $0.0000067 in May, and the subsequent painful correction drove it south toward $0.000004, which translated into a multi-year low. As such, SHIB has now returned to the top 30 alts by market cap as its own has jumped to over $3.3 billion on CoinGecko.
Moreover, it has solidified its spot as the second-largest meme coin by that metric, even though a few others have posted impressive gains as well. PEPE is up by 9%, M has added 4%, while DOGE has jumped by 5.5%.

Why Is That?
Surging by double digits on a random Sunday used to be the norm in the meme coin space years ago. However, the niche has fallen out of investors’ grace lately, with interest dwindling over time. As such, it’s intriguing to see what the latest developments in the Shiba Inu ecosystem are that might have propelled this rally.
The one thing that stands out on X is the behavior of a certain SHIB whale who has resumed accumulating after over half a year of inactivity. According to reports, the unknown market participant has splashed $125,000 to accumulate over 30 billion tokens. Although one standalone purchase cannot guarantee a 35% jump, it can be regarded as the market signal other investors are waiting for to join.
The SHIB token burn mechanism also shows a massive surge in the past day of over 3,200% (and 500% weekly). This means that the actual number of coins in circulation has declined violently, which is typically a bullish signal.
SHIB coins stored on crypto exchanges have also fallen in the past few weeks, according to data from CryptoQuant. Lastly, some analysts argued that the asset has broken out of key resistance levels and trendlines, while the community rejoices in the move, indicating that it’s finally paying off after “years of accumulation.”
The post Shiba Inu Price Soars 35% on a Dull Day as Whale Returns With Massive SHIB Purchase appeared first on CryptoPotato.
Crypto World
Robinhood eyes Crypto.com deal as prediction market race heats up
Robinhood is reportedly holding talks with Crypto.com about adding the exchange’s event contracts to its prediction markets hub.
Summary
- Robinhood reportedly wants Crypto.com contracts to broaden its prediction market exchange network and product range.
- Any agreement could deepen Robinhood’s competition with Kalshi while reducing reliance on a single provider.
- Federal and state regulators remain divided over who controls sports-linked event contracts across the U.S.
The proposed arrangement would let Robinhood users trade yes-or-no contracts supplied by Crypto.com, according to people familiar with the discussions cited by The Wall Street Journal. Neither company has announced an agreement, and the report said the talks may not result in a completed deal.
https://x.com/WSJmarkets/status/2080785057954902434?s=20
The discussions come as Robinhood builds a wider network of exchanges rather than relying on one source of event contracts. A company spokesperson said Robinhood “will continue to partner with multiple exchanges” to give customers a broad and reliable market. The strategy could add Crypto.com alongside Kalshi, ForecastEx and Rothera, the exchange created through Robinhood’s venture with Susquehanna International Group.
Robinhood seeks more prediction market suppliers
Robinhood launched its prediction markets hub in March 2025 with contracts routed through Kalshi, a Commodity Futures Trading Commission-regulated exchange. Its products cover outcomes tied to sports, politics, economics and other public events. Robinhood later added ForecastEx and began routing contracts through Rothera in June 2026.
Rothera gives Robinhood a closer link to the exchange layer because Robinhood owns the venture with Susquehanna. The company said in June that the new route lowered customer trading costs. Adding Crypto.com would create another source of contracts and could help Robinhood maintain product availability when one exchange lacks a market or faces a service issue.
Crypto.com expands event contract distribution
Crypto.com already offers prediction trading through Crypto.com Derivatives North America, a CFTC-regulated exchange and clearinghouse. Its contracts use a simple yes-or-no format based on future events. The company also launched OG Prediction Markets as a separate platform in February 2026 and has expanded distribution through partners.
In June, FanDuel Predicts expanded its offering with sports, entertainment and combination contracts supplied through Crypto.com and OG Prediction Markets. Crypto.com has also announced a planned prediction-market integration with Truth Social, although The Wall Street Journal reported that the product had not launched by July 24. A Robinhood deal would place its contracts before another large retail trading audience.
Kalshi rivalry grows as revenue forecasts rise
Robinhood and Kalshi started as distribution partners, but their businesses now overlap more directly. Kalshi has expanded beyond standard event contracts, while Robinhood has built Rothera and added more exchange partners. Kalshi chief executive Tarek Mansour described Robinhood as both a partner and a competitor, adding, “We’ll see who ends up with a better product.”
The reported Crypto.com talks arrived after Bernstein raised its Robinhood share-price target to $160 from $130. The firm estimated that Robinhood’s prediction-market revenue could reach about $1.7 billion by 2028. As crypto.news previously reported, Bernstein also forecast $586 million in Robinhood prediction-market revenue for 2026, supported by higher World Cup activity and Rothera volumes.
Bernstein expects total prediction-market trading volume to grow from about $51 billion in 2025 to $1 trillion by 2030. The projection assumes wider distribution, more institutional use and clearer rules. Sports contracts currently generate much of the activity, but analysts expect economic, political and business contracts to form a larger share over time.
State and federal regulators remain divided
Robinhood’s possible expansion comes during a legal fight over who can regulate event contracts. The CFTC says federal law gives it exclusive authority over commodity derivatives traded on registered exchanges. In 2026, the agency sued several states after officials moved against prediction-market operators.
States argue that some sports-related contracts function like gambling and should follow local licensing, age and consumer-protection rules. Wisconsin’s actions included complaints against Crypto.com and Robinhood, along with Kalshi, Polymarket and Coinbase.the CFTC responded by seeking to block the state’s enforcement and preserve federal oversight.
The conflict has produced different rulings and restrictions across the country. New York sued Coinbase and Gemini over claims that their event-contract products violated state gambling rules. The CFTC later filed its own case against New York and maintained that federal law takes priority.
Any Robinhood-Crypto.com arrangement would still depend on contract availability, regulatory status and the final terms between the companies. Robinhood has not confirmed that Crypto.com contracts will appear in its app. For now, the talks show that the company is considering another supplier as competition grows among exchanges, brokers and crypto platforms seeking a larger share of event trading.
Crypto World
Binance tests staff monthly with fake phishing attacks
Binance runs simulated phishing attacks against its employees every month to reduce social engineering risks.
Summary
- Binance runs monthly phishing simulations to measure employee awareness and identify weak security habits early.
- Workers who fail receive training, while repeated severe failures can lower ratings and risk dismissal.
- Recruiter lures and fake conference invitations mirror scams already causing large losses across cryptocurrency firms.
Chief security officer Jimmy Su said the exchange’s red team creates fake attacks to test whether staff recognise suspicious messages, links and requests. Employees who fail must complete follow-up training. Repeated failures can also affect performance ratings and may lead to dismissal.
The programme targets human errors that attackers use to enter crypto companies. Binance has operated the drills for three to four years, according to Su. He said the company’s security habits had improved during that period. Binance reports 323 million registered users, while DefiLlama tracks about $137.5 billion in assets linked to the exchange.
Binance ties phishing tests to staff reviews
The red team uses methods that resemble real attacks. One test may present a fake recruiter offering a job. Another may promise free access to a conference and request personal details. The team records whether employees open the message, follow a link or share information that could expose company systems.
Su said workers who fail receive remedial training. Repeated failure “will negatively impact their rating,” he said. Severe cases may push a worker’s rating to the lowest level and result in dismissal. The policy gives employees a direct work-related reason to verify unexpected messages before responding.
Binance has described its red team as an internal group of ethical hackers that tests systems from an attacker’s point of view. The exchange also works with external researchers through bug bounty programmes. Its security model covers technical weaknesses and employee behaviour because attackers may enter through trusted accounts or devices.
Social engineering drives crypto security cases
The drills come as social engineering causes a large share of reported crypto losses. AMLBot reviewed more than 2,500 investigations and found that 65% of the cases it handled in 2025 began with social engineering rather than direct software exploits. Phishing represented 18% of its cases, while device compromise accounted for 13%.
Attackers often spend days or months building trust before asking a target to open a file, approve a wallet request or run a command. This method can defeat technical controls when a worker has access to private keys, administrator accounts or internal systems. Stolen credentials can lead directly to liquid assets that move across blockchains within minutes.
As crypto.news reported, the April 2026 attack on Drift Protocol drained about $285 million after attackers compromised an administrator key. Researchers linked the breach to social engineering and operational security failures rather than faulty smart contracts. The attacker changed market settings and withdrawal limits before removing assets across dozens of transactions.
Fake meetings and job offers remain common lures
Su identified fake job interviews as one scenario used in Binance’s tests. Real attackers use the same approach against developers, executives and investment teams. They may move a conversation from LinkedIn, Telegram or email into a video meeting, then claim that the victim’s camera or microphone needs an update.
North Korea-linked hackers have used compromised Telegram accounts and deepfake Zoom calls to contact crypto professionals. The attackers impersonated known contacts and asked victims to install files that claimed to fix audio problems. Those files instead delivered malware capable of accessing devices, browser data and crypto wallets.
A Venus Protocol user lost about $13.5 million in September 2025 after approving a malicious transaction. Venus paused its lending platform and recovered the assets through an emergency governance process. The case showed how a user-level compromise can place assets at risk even when a protocol’s contracts remain intact.
Frequent drills aim to reduce predictable errors
Monthly simulations let Binance compare failure rates and update training when attackers change their methods. A single annual course may not prepare staff for new lures built around current events, trusted contacts or job offers. Frequent tests also show whether workers report suspicious messages instead of only deleting them.
However, simulations cannot remove every risk. Attackers can hijack genuine accounts, copy earlier conversations and use artificial intelligence to create convincing audio, video and written messages. Firms still need access controls, transaction limits, device monitoring and fast incident response alongside employee training.
Su said Binance’s early security habits “left a lot to be desired,” but repeated testing brought improvement. The exchange treats staff awareness as part of its wider defence system rather than a one-time compliance task. Employees still need to verify unusual requests through a separate channel before opening files, sharing information or approving transactions.
Crypto World
Wise turns to GENIUS Act after OCC rejects U.S. bank charter
Wise plans to submit a new application for a U.S. national trust bank charter under the GENIUS Act after the Office of the Comptroller of the Currency rejected its first bid.
Summary
- Wise plans a fresh U.S. charter application under the GENIUS Act after the OCC rejection.
- The OCC cited weak AML controls, management gaps, and limited national banking experience in denial.
- William Blair expects Wise to remain rail-agnostic rather than make stablecoins its core business model.
The July 21 decision ended the payments company’s effort to create Wise National Trust in Austin, Texas. Wise disclosed the outcome on July 24 and said its current U.S. services continue without change. The company still operates through money-transmitter licences across 48 states and four territories.
The new filing will use the federal framework for payment stablecoins rather than the structure in Wise’s original June 2025 application. Wise said the earlier plan relied on access to Federal Reserve payment systems that is no longer practical. Its London-listed shares fell as much as 10% after the denial became public. Wise said it had strengthened financial-crime controls since filing the original plan and would address the regulator’s findings in its next submission.
OCC rejects Wise application over compliance concerns
The OCC’s decision said Wise did not show that the proposed trust bank could meet U.S. legal and regulatory requirements. The regulator focused on weaknesses in anti-money laundering and countering the financing of terrorism controls. It also said Wise U.S. had a record of failing to meet rules that apply to money services businesses. The proposed bank planned to rely heavily on Wise U.S. and other group companies for compliance work.
The regulator also questioned the experience of the proposed directors and managers. It said the team did not show enough knowledge of national banking rules, fiduciary services, or AML/CFT operations. Wise National Trust had planned to offer multi-currency stored-value accounts, payment processing, and fiduciary services. The OCC stated that approval would conflict with its charter policies. However, the decision does not stop Wise from filing another application after addressing the issues.
Wise shifts its plan toward the GENIUS Act
Wise gave a separate reason for changing course. The company said the Federal Reserve has generally paused account access for uninsured trust banks while it develops a new payment-account policy. “With the Federal Reserve generally pausing account access for an uninsured trust bank, the approach in our application became non-viable,” Wise said. The original plan aimed to let Wise settle U.S. dollar payments more directly and reduce its reliance on partner banks.
Wise now plans to apply under the GENIUS Act, which created a federal licensing and supervision system for payment stablecoin issuers. The company has not said it will launch its own stablecoin. William Blair analysts also said they do not expect a major change in Wise’s position. They described the company as “agnostic of the rail,” meaning it remains focused on lowering cross-border payment costs whether transfers use traditional systems or digital assets.
Stablecoin rules remain unfinished
The GENIUS Act became law in July 2025. It sets reserve, redemption, reporting, consumer protection, and compliance requirements for approved payment stablecoin issuers. The law is due to take effect on January 18, 2027, or 120 days after regulators publish final rules, whichever comes first. The OCC published its main proposed rule in March, while Treasury later proposed AML and sanctions standards.
Final rules were still pending when Wise announced its new plan. As crypto.news reported, regulators missed the July 18 rulemaking deadline, leaving key details unresolved. Wise will need to explain what activities its new entity would conduct, how it would use stablecoins, and how it would meet the stricter AML/CFT standards planned for permitted issuers. A new application must also explain how the charter would work without the unrestricted Federal Reserve access assumed in the earlier model.
Wise joins a wider U.S. charter race
Wise is entering a crowded federal licensing process. The OCC has approved several digital asset companies for national trust charters during the past year.Circle received final approval in July 2026 after gaining conditional approval in December. Ripple, Paxos, BitGo, Fidelity Digital Assets, Crypto.com, Bridge, and Coinbase have also received conditional decisions or entered the process.
The approvals have drawn opposition from banking groups and some lawmakers. Crypto.news reported that the Bank Policy Institute retained outside lawyers while considering a challenge to the OCC’s trust-charter policy. Wise’s case differs because the regulator issued a direct denial tied to its compliance record and management plan. The new GENIUS Act filing may offer a different route, but it will still require Wise to satisfy the OCC’s standards before gaining a charter.
Crypto World
BitMart shuts down trading as BMX crashes more than 60%
BitMart has started a phased shutdown of its global cryptocurrency exchange after reviewing its operating conditions, market environment, and future strategy.
Summary
- BitMart stopped new registrations, deposits, and orders before ending all trading services on August 26.
- BMX lost about 63% in 24 hours as traders reacted to the exchange’s shutdown announcement.
- Withdrawals remain available, but BitMart advised users to submit requests before August 26’s recommended deadline.
According to the official shutdown notice, the exchange stopped new registrations, cryptocurrency and fiat deposits, and new spot orders from 01:30 UTC on July 26. Futures accounts entered reduce-only mode, while copy trading, grid trading, API trading, and other automated services began winding down.
The exchange will end all spot, futures, and other trading services at 01:00 UTC on August 26. However, the full platform will not close on that date. BitMart plans to terminate trading-platform operations at 15:59 UTC on January 31, 2027. Users will retain limited account access for a period after that date to review records and submit withdrawals.
BitMart sets withdrawal and position deadlines
BitMart told users to close all positions before 01:00 UTC on August 26 and recommended submitting withdrawals before 05:00 UTC the same day. Withdrawals remain open, but requests may face identity, source-of-funds, wallet ownership, sanctions, Travel Rule, and security reviews. Heavy demand or network congestion may extend processing times.
The exchange asked customers to cancel open orders, redeem eligible Earn, staking, and lending products, and download account records. BitMart may settle any futures positions still open when trading ends using its mark price, index price, or other applicable rules. Users who miss the recommended withdrawal period will enter a separate process that BitMart plans to explain later.
BMX falls as traders react to the shutdown
BMX, the exchange’s platform token, fell by around 63% during the 24 hours surrounding the announcement. BitMart’s own market page showed a decline of about 64.9% at one stage, while CoinGecko’s BMX page placed the token near $0.164 on July 26 with about $6.1 million in daily volume. The sharp move reflected the token’s close link to exchange activity.
BMX provides trading-fee discounts and other platform benefits. The planned end of trading removes much of that direct use. Price readings varied across trackers because the market moved quickly and platforms used different update times. CoinGecko data placed the token’s market value near $55.6 million on July 26, down from more than $100 million earlier in the week.
Closure follows recent service restrictions
BitMart did not identify a single event behind the shutdown. Its notice referred only to “operating conditions, market environment, and future strategic direction.” The exchange did not state that it had entered insolvency, and it did not connect the decision to a security incident, regulatory order, or lack of customer assets. Users therefore still lack a detailed financial explanation.
The decision followed several service changes. BitMart suspended its automated market-making bot on July 24 and returned users’ principal and earnings to spot accounts. It also ended spot margin trading, with forced liquidation scheduled for July 26. On July 23, the exchange told remaining U.S.-linked users to close positions and withdraw by August 8 during a compliance review.
BitMart follows other crypto platform closures
The announcement came three days after BitMEX said it would close its derivatives exchange on September 23 following a strategic review. BitMEX stopped new registrations and set August 26 as the date when customers could no longer open new positions. Odos also announced plans to shut its decentralized exchange aggregator on July 30, although the platforms gave different reasons and timelines.
BitMart entered the market in 2017 and grew through a wide selection of smaller tokens. A 2021 Series B round led by Alexander Capital Ventures valued the company at more than $300 million. Fenbushi Capital had made an earlier investment in 2019. Days after the Series B announcement, attackers compromised two hot wallets and stole assets valued at about $150 million by BitMart, while outside estimates reached $196 million.
BitMart said at the time that it would use its own funds to compensate affected customers. The shutdown notice did not link the wind-down to that breach, which occurred nearly five years earlier. In May 2026, BitMart said “all platform operations are running normally” while responding to online concerns about withdrawals and risk controls. It also said it planned to publish proof of reserves after completing security preparations.
The exchange now warns that scammers may exploit the shutdown. BitMart said it will not charge an expedited withdrawal fee or ask for passwords, two-factor codes, private keys, or recovery phrases. It advised users to rely on its official website, app, registered emails, and support system. Customers must also check networks and addresses before transferring funds.
Crypto World
BMX Token Crashes 46% as BitMart Announces Exchange Wind Down
Cryptocurrency exchange BitMart will shut down its trading platform, beginning an orderly wind-down on Sunday.
The announcement sent BitMart Token (BMX) tumbling, with the exchange token posting double-digit losses over the past 24 hours. The platform urged users to close positions and withdraw assets without delay.
BitMart Sets a 6-Month Runway Before Full Closure
BitMart attributed the decision to a review of its operations, market conditions, and future strategic direction.
“BitMart has made the difficult decision to commence an orderly wind-down of its trading platform operations. We deeply regret having to make this decision,” the team said.
Follow us on X to get the latest news as it happens
The notice sets a staged timeline. The platform suspended new registrations, deposits, and orders on July 26, 2026, at 01:30 UTC.
Futures accounts switched to reduce-only mode on July 26. Spot trading also stopped accepting new orders that day.
Copy trading, grid trading, and API trading services are being discontinued in phases. Earn, staking, lending, and Launchpad products will wind down under their own schedules.
All spot, futures, and other trading ends at 01:00 UTC on August 26. Platform operations then cease entirely at 15:59 UTC on January 31, 2027.
The exchange asked users to complete identity verification and close positions before that August deadline. It also asked users to submit withdrawal requests by 05:00 UTC on August 26, 2026.
BMX Slides as Exchange Closures Pile Up
The market reaction was immediate. BMX traded near $0.11016 on Sunday, down 46.08% on the day.
That leaves it roughly 82% below its record high of $0.61905, reached on June 5, 2024.
The closure arrives just days after BitMEX told users it would end operations on September 23. Two established venues are therefore exiting within the same week.
Users now have one month to exit positions before trading stops on BitMart.
Subscribe to our YouTube channel to watch leaders and journalists provide expert insights
The post BMX Token Crashes 46% as BitMart Announces Exchange Wind Down appeared first on BeInCrypto.
Crypto World
North Korea hackers scan crypto wallets through fake Zoom calls
- BlueNoroff scans browser wallets before deciding which fake meeting targets should receive its malware payload.
- Hijacked Telegram accounts help attackers contact trusted industry peers and extend the campaign through victims.
- The phishing kit supports Windows and macOS, stealing browser keys, system data, and Telegram sessions.
North Korea-linked hacking group BlueNoroff is using fake Zoom and Microsoft Teams meetings to profile cryptocurrency users before delivering malware.
Cybersecurity firm JUMPSEC said it recovered and analysed source code from an active phishing kit after its operators exposed JavaScript source maps on live infrastructure. The files showed separate Zoom and Teams lures, wallet-scanning tools, operator controls and malware delivery paths for Windows and macOS.
The attack often begins through a Telegram account that the target already trusts. The hackers take over accounts belonging to crypto contacts, then send a Calendly invitation that leads to a lookalike meeting domain. JUMPSEC described the system as a repeatable victim pipeline because one stolen Telegram session can help the attackers contact the next group of targets.
BlueNoroff checks crypto wallets before sending malware
The phishing page starts scanning the browser when a user enters the fake meeting. It looks for Ethereum wallet connections through EIP-6963 and older browser methods. It also checks for non-EVM wallets, including Solana tools. The results reach an operator panel without alerting the victim. This lets the attackers identify wallets and choose higher-value targets before pushing the next stage.
On Windows, the implant also lists extension IDs across Chrome, Edge, Brave, Opera, Vivaldi and Firefox variants. Operators can compare those IDs with known wallet extensions such as MetaMask. JUMPSEC called this a system that profiles wallets “before malware delivery.” The method differs from broad phishing campaigns because the attackers gather wallet data before deciding how far to take the intrusion.
Fake Zoom and Teams calls build trust
Victims first see a convincing meeting page that requests their name and webcam access. The site then sends the camera stream to the attacker’s control panel. After the victim joins, the screen shows “waiting for other participants.” An operator can enter with a prepared video, send messages such as “your mic isn’t working,” and trigger a fake “Zoom SDK Update” prompt.
JUMPSEC found that the displayed participant video was not live. The attackers combined AI-generated headshots with body movements captured in earlier meetings. They could then show a familiar-looking person while using a Telegram account that belonged to a real contact. The Teams version included emoji reactions, device settings, background effects and wider wallet checks, making it more polished than the Zoom kit. The source code also contained an unfinished Google Meet option. JUMPSEC said Zoom and Teams suit the lure because both use desktop clients, making an urgent software update appear more credible.
Malware targets both Windows and macOS
On Windows, the copied ClickFix command runs a small PowerShell loader. It downloads a VBScript, adds a Microsoft Defender exclusion and restarts Defender so the change takes effect. The implant gathers system details, checks browsers for wallet extensions and looks for Telegram Web files. It can also receive later payloads from the operators, although JUMPSEC did not recover every final-stage file.
The macOS path downloads a fake Zoom or Teams installer while a stealer runs in the background. Researchers found versions that collected system information and Chrome master keys from Apple’s Keychain. The malware sent data through a Telegram bot and could download another payload. JUMPSEC traced four macOS variants between April 22 and July 15, showing that the operators kept changing the toolkit during the campaign.
Campaign builds on earlier crypto meeting scams
The findings expand earlier research into BlueNoroff’s fake meeting operations. In April, Arctic Wolf reported more than 80 lookalike Zoom and Teams domains and identified 100 additional targets whose media appeared on attacker infrastructure. It said 80% of the identified targets worked in crypto, blockchain finance or related investment sectors, while founders and chief executives made up 45%.
North Korean attackers had already used compromised Telegram accounts, spoofed meeting invitations and fake software updates to target crypto executives. Another crypto.news report described a related macOS campaign that asked victims to run commands during fake calls. Earlier coverage of NimDoor malware also linked fake Zoom updates to theft attempts against browser credentials, wallet data and Telegram files.
The latest kit gives operators direct control over the pace of each meeting and the malware prompt. JUMPSEC advised organisations to treat meeting links from trusted accounts with care because the sender’s account may already be compromised. Crypto teams can verify unusual invitations through another channel, avoid commands or updates presented during calls, revoke exposed Telegram sessions and isolate any device that ran the requested script. Teams should also review PowerShell activity, Defender exclusions, Keychain access and new Telegram logins after any suspect call. A password reset alone may not remove stolen sessions or malware already running on the device across affected systems.
Crypto World
Uniswap launches Permissioned Pools for compliant onchain trading
Uniswap Labs has launched Permissioned Pools on Uniswap v4, adding onchain access checks for regulated assets that cannot trade freely between every wallet.
Summary
- Permissioned Pools check issuer-managed allowlists before swaps or liquidity actions can proceed through Uniswap v4.
- Superstate, Securitize, and Dowgo helped build compliant trading infrastructure for tokenized funds, equities, and securities.
- Regular Uniswap v4 pools remain permissionless, giving developers a separate option for restricted regulated assets.
The open-source hook standard lets approved users swap tokenized funds, securities, equities and other restricted assets through automated market maker pools. Uniswap announced the product on July 23, 2026, after working with firms that issue and manage regulated onchain assets. It keeps issuer compliance controls visible and enforceable onchain.
Launch partners include Superstate, Securitize and Dowgo. Each partner helped shape parts of the standard or its compliance links. The launch does not change regular Uniswap v4 pools. Those pools remain permissionless, while issuers can choose the restricted format when an asset requires identity checks, transfer rules or investor eligibility controls.
How Uniswap Permissioned Pools work
Permissioned Pools check an issuer-managed allowlist before every swap. The hook also checks the list before a user creates a liquidity provider position. When a wallet lacks approval, the transaction cannot continue. The issuer controls the list and its rules, rather than Uniswap or a public interface. Uniswap said the checks run “at the protocol level, not on the frontend,” which makes the restriction part of the pool’s smart-contract process.
The design uses Uniswap v4 hooks, which let developers add custom instructions to a pool at set points in a transaction. It also uses v4 virtual accounting to calculate exchanges while the regulated assets remain inside a permissioned contract. Approved traders still use an AMM instead of a traditional order book. Liquidity providers supply the assets, while the pool’s code handles pricing and settlement under the issuer’s access rules.
Launch partners connect regulated assets to AMMs
Superstate joined as an early design partner and helped develop the format for tokenized equities and funds. The company issues onchain financial products and operates services for tokenized funds and company shares. Its July 23 update said the standard could connect eligible tokenized equities with AMMs, lending markets and other approved financial applications.
Securitize worked with Uniswap Labs before the wider standard launched. The firms focused on making assets issued through Securitize’s DS Protocol compatible with compliant onchain trading. Dowgo contributed an ERC-3643 integration, a token standard that supports identity checks and transfer controls. Uniswap said Dowgo plans to use Permissioned Pools after it receives DLT TSS authorisation under the European Union’s DLT Pilot Regime. Dowgo says its application remains under review by France’s ACPR.
Regular Uniswap v4 pools remain permissionless
The new system applies only when an issuer or developer deploys a Permissioned Pool for a selected asset. It does not add a general identity check to Uniswap v4. Developers can continue creating standard pools without asking Uniswap Labs for approval, and users can continue accessing those pools under the protocol’s existing rules.
This split gives regulated issuers a separate route to AMM liquidity without turning the wider protocol into a closed trading venue. Uniswap said developers can choose either model: build permissionlessly on v4 or deploy a restricted pool for an asset with legal transfer conditions. The issuer remains responsible for the allowlist and investor access, while the hook enforces those decisions during swaps and liquidity actions.
Tokenized asset growth raises demand for compliance controls
Permissioned Pools follow Uniswap’s June rollout of tokenized securities across its web app, wallet and API. That earlier update gave eligible users access to blockchain-based products linked to companies such as Apple, Nvidia and Tesla. Uniswap warned that some products may not represent direct ownership and may face KYC, transfer or geographic restrictions. The new pool standard gives issuers another way to enforce such rules directly in trading infrastructure.
Uniswap cited an estimate that the tokenized asset market could reach $11 trillion by 2030. Current figures remain far below that forecast. As crypto.news reported, tokenized real-world assets stood near $34 billion in May 2026, including about $1.55 billion in tokenized equities. Related coverage also found that transfer agents often control wallet allowlists and the official ownership records behind tokenized securities.
Regulators continue to examine how these products protect ownership and shareholder rights. As previously reported, the U.S. Securities and Exchange Commission delayed a proposed tokenized-stock exemption after exchanges raised questions about investor safeguards and record keeping. Securitize chief executive Carlos Domingo said any framework should “apply to the right instruments.” Permissioned Pools address transaction access at the smart-contract level, but each issuer must still follow the securities laws and licensing rules that apply to its product and market.
Crypto World
Upbit expands KRW market with two major DeFi token listings
Upbit has added Morpho (MORPHO) and Euler (EUL) to its Korean won market, expanding direct KRW trading for two Ethereum-based decentralized lending projects in Korea.
Summary
- Upbit added MORPHO and EUL KRW pairs, giving traders access to two DeFi lending tokens.
- Euler’s KRW trading launch moved to 2:00 p.m. KST, two hours later than initially scheduled.
- EUL gained about 74% before launch, while MORPHO posted a smaller rise and heavier volume.
MORPHO/KRW opened on July 25 at 6:00 p.m. KST, while Upbit planned EUL/KRW for July 26.
However, Upbit changed Euler’s launch timetable shortly before trading. The exchange moved the start from 12:00 p.m. to 2:00 p.m. KST on July 26. The notice said, “The trading support start time for EUL will change.” Deposits and withdrawals for both assets remain limited to the Ethereum network. The listings also broaden access beyond existing BTC and USDT pairs already available for both assets on Upbit.
Upbit delays EUL trading after adding the KRW pair
Upbit did not give a detailed reason for the two-hour delay. Its notice said trading may start later when the exchange has not secured enough liquidity. The platform had already created the EUL/KRW market page, but users still had to follow the revised 2:00 p.m. KST start time.
The exchange also placed temporary controls on the launch. Upbit will block buy orders for about five minutes after trading begins. During the same period, it will restrict sell orders priced more than 10% below the previous closing price. For roughly two hours, users may place limit orders only. Upbit set the reference close at 0.00003019 BTC, equal to 2,845 won in its notice.
EUL price surges before the scheduled Upbit launch
EUL recorded the stronger market response. At the time of writing, Binance data placed the token near $2.22, up about 74% over 24 hours, with trading volume above $200 million. CoinMarketCap data also linked the move to the Upbit listing and reported a sharp rise in volume before the KRW market opened.
The reaction follows earlier cases in which Korean won listings drove fast changes in EUL trading. As crypto.news reported in September 2025, EUL rose more than 30% after Bithumb announced a KRW pair. The token had also gained after Coinbase added it to its asset roadmap in July 2025. Those earlier moves show that new exchange access can quickly change short-term demand, although gains can reverse when initial activity slows.
Morpho gains another route to Korean won liquidity
Morpho’s KRW pair opened a day earlier. Upbit scheduled MORPHO/KRW trading for 6:00 p.m. KST on July 25 and supported deposits and withdrawals through Ethereum only. Market trackers recorded a smaller price move than EUL, but they also showed a sharp increase in MORPHO trading volume after the announcement.
MORPHO traded near $1.95 on July 26, up about 1.5% over 24 hours. CoinGecko placed its market value above $1.2 billion and reported that daily volume had increased by more than 400% from the previous day. The listing adds a direct won pair for a token that Upbit already offers in its BTC and USDT markets.
The new KRW access also follows a series of Morpho product and funding updates.Morpho launched Midnight on Base in July, offering fixed-rate and fixed-term lending. The network said it held more than $11 billion in deposits. In June, Morpho raised $175 million from investors including Paradigm, a16z Crypto and Ribbit Capital, with the transaction reportedly valuing the project at about $2 billion.
Upbit backs two modular Ethereum lending protocols
Morpho and Euler both provide infrastructure for onchain lending, but they use different systems. Morpho lets developers and asset managers create lending markets and vaults with selected collateral, risk settings and interest models. MORPHO supports governance and other functions across the network.
Euler v2 uses modular vaults that users and developers can build for different lending markets. Its Euler Vault Kit supports the creation of vaults, while the Ethereum Vault Connector can link positions across compatible vaults. EUL serves governance, rewards and fee-related functions within the protocol.
Euler rebuilt its platform after a 2023 exploit drained about $197 million from its earlier version. The attacker later returned most of the funds. As crypto.news previously reported, Euler expanded through v2 and later launched on networks including Sonic. The protocol reported more than $2 billion in total borrowing and about $4 billion in deposits by October 2025.
Upbit’s back-to-back MORPHO and EUL listings give Korean traders new won-denominated access to two lending protocols. However, the fast EUL price rise and the exchange’s opening controls point to high volatility around the launch. Upbit advised users to confirm the Ethereum network and token contract before sending funds, because unsupported deposits may require a long return process.
-
Fashion2 days agoWeekend Open Thread: Brooks Brothers
-
Politics7 days agoDemocrats look to World Cup watch parties to register thousands of voters
-
News Videos7 days agoBig Money Is Entering XRP
-
Tech5 days agoSail Virtually Aboard The “Itanic” With IA-64 Emulator
-
Tech5 days ago
Turtle Beach Command Series KB7 review: a nifty screen-equipped gaming keyboard
-
Crypto World5 days agoGrayscale Files For Worldcoin ETF, WLD Registers Sharp Rise
-
NewsBeat6 days agoUnregistered fitter used Gas Safe logo on business flyers
-
Business4 days agoNew Jersey voter registration controversy explained: How 6,600 noncitizens got on the rolls, and what happens next
-
Entertainment5 days agoJohnny Depp’s R-Rated Gothic Cult Classic Gets New Release Ahead of Sydney Sweeney Remake
-
Crypto World3 days agoEthics, other provisions in crypto Clarity Act to be further discussed
-
Tech6 days agoWatch Flock Safety CEO Garrett Langley discuss the future of surveillance at TechCrunch Disrupt 2026
-
NewsBeat5 days agoShanghai science forum photos show China’s AI and robotics advances in rivalry with US
-
Crypto World6 days agoCircle’s President Sold Over 360,000 Shares, The Filings Explain Why
-
Tech6 days agoSubway Sandwich Computers Get a Second Life as Gaming Machines
-
Sports2 days ago2026 3M Open leaderboard: Scottie Scheffler finds putter in Round 1, sits three back
-
News Videos2 days agoThe Peugeot Family: How 200 Years of an “Old Money” Dynasty Died in A Boardroom
-
Fashion2 days ago16 Dresses for the High Summer Event
-
Tech7 days agoHow To Use Claude’s Reflect Dashboard And Learn When It’s Time To Touch Grass
-
Tech6 days agoThe 35 Best Board Games for Family Game Night
-
Entertainment6 days agoStephen Colbert Returns to Social Media After Late Show End

You must be logged in to post a comment Login