Crypto World
Liquid Network attacker crossed into theft: Immunefi CEO
Immunefi CEO Mitchell Amador has said the Liquid Network attackers lost any claim to white-hat status by retaining 598.5 BTC after returning 3,400 BTC from the roughly 4,000 BTC exploit.
Summary
- Roughly 598.5 BTC remains with the attackers after they returned 3,400 BTC.
- Amador said coordinated disclosure ends when a researcher sets rescue terms without prior approval.
- Protocols should establish rescue rules and bounty limits before an exploit occurs.
- Immunefi’s CEO defended the 10% bounty convention when teams approve it in advance.
Immunefi founder and CEO Mitchell Amador told crypto.news that moving user assets without permission cannot be treated as a rescue when the researcher later keeps part of the funds or sets payment terms.
“Coordinated disclosure ends the moment you set the terms yourself,” Amador said. “The money was never yours to save, so moving it is not a rescue.”
His comments address the dispute left by the Liquid Network incident, in which unidentified actors withdrew roughly 4,000 BTC, valued at about $320 million at the time, before describing themselves as whitehats. They returned 3,400 BTC after Blockstream patched the affected bridge nodes but retained 598.5 BTC.
Blockstream has rejected the group’s demand for a 10% bounty and has said it will not pay for the return of the remaining Bitcoin. The company also rejected the attackers’ claim that the operation amounted to responsible disclosure.
Liquid Network attackers could not set their own terms
Amador said a security researcher must use private disclosure channels, preferably through a defined bug bounty program, instead of taking assets and negotiating a reward afterward.
“Keep a dollar of user funds, and it is theft, whatever the intent was at the outset. The path for a researcher is private disclosure, ideally within a well-defined program.”
The distinction rests on authorization rather than the researcher’s stated motive. Under Amador’s view, finding a real vulnerability does not give someone the right to move user assets, hold them as collateral, or decide what compensation is owed.
Blockstream took a similar position in its Sept. 11 response. As previously reported by crypto.news, the company said taking assets without permission and refusing to return them constituted theft rather than whitehat work.
The company said its earlier discussions with the actors were intended to recover user funds and protect the Bitcoin community. According to Blockstream, engaging in those talks did not mean it had accepted either the withdrawal or the later bounty demand.
A technical review of the exploit found that a cache-key collision in the confidential transaction verification logic allowed the actors to create unbacked L-BTC. They then used SideSwap’s peg-out service to obtain real Bitcoin from the federation reserve.
Federation keys were not compromised, according to Blockstream. The incident instead involved verification logic in the Elements codebase, while the federation nodes were running a release that did not contain the relevant fix.
Rescue terms should exist before an exploit
Rather than negotiating under pressure after funds have moved, Amador said serious protocols should decide their rescue conditions before an emergency occurs.
“Yes, rescue terms must exist ahead of an exploit,” he said. “All serious protocols should set these in advance.”
Predetermined rules can define which systems researchers may test, how they must disclose a vulnerability, and what actions they can take during an active incident. They can also state the maximum bounty, payment conditions, and legal protections available to researchers who remain within the approved scope.
Immunefi developed the Whitehat Safe Harbor framework to establish such conditions before a protocol faces an attack. Amador, who helped shape the framework and has participated in live exploit response teams, compared emergency action with saving a house from a fire: the need for help does not authorize every possible rescue method.
Advance agreements also give protocol teams a basis for distinguishing approved intervention from coercion. Without prior terms, an actor who controls user funds can demand payment while the project faces losses, service disruptions, and pressure from token holders.
Liquid’s actors initially communicated through messages placed in Bitcoin transactions and told Blockstream to patch the flaw before they returned the funds. After Blockstream confirmed that affected bridge nodes had been patched, the group sent 3,400 BTC back to the federation wallet.
No publicly disclosed agreement had allowed the group to retain the remaining 598.5 BTC. The amount also exceeds 10% of the approximately 4,000 BTC involved, although the reported demand centered on a 10% reward.
The 10% crypto bounty convention still has a role
While rejecting the Liquid actors’ attempt to impose their own terms, Amador defended the crypto industry’s informal practice of offering up to 10% of funds at risk as a whitehat bounty.
Without a common reference point, he said, each settlement would need to be negotiated from the beginning, giving an attacker more leverage during an active incident. A defined percentage gives researchers a legal payment route while allowing a protocol to recover most of the exposed assets.
“Ten percent of a $100M exploit is $10M earned legally, with nobody hunting you afterwards,” Amador said. “The alternative for them is moving nine figures onchain while every forensics firm watches.”
The 10% figure has appeared in several recovery offers, but projects usually state the terms themselves. In August, BTCPay Server supporters backed a reward equal to 10% of recovered funds after attackers obtained LND admin macaroon credentials. The proposed payout was capped at 3 BTC if all stolen assets were returned.
Cetus Protocol followed a different formula after its May 2025 exploit. A flaw in its automated market maker logic caused losses of more than $223 million, while the Sui Foundation coordinated with validators to freeze about $163 million. Cetus later announced a $5 million reward for information leading to the identification of the attacker, according to its post-exploit review.
Amador said the reward should generally reach up to 10% of funds at risk while remaining subject to a cap the protocol can afford. Setting the amount too low could make theft more attractive than disclosure, he said, while an excessive payout could leave the rescued project unable to continue operating.
“Price it too high, and paying out can kill the protocol you just saved, which helps nobody,” he said.
Projects may still pay above their stated cap when a report warrants a larger reward, Amador added. Under his proposed model, the protocol retains control over that decision instead of allowing a researcher to establish the fee after taking custody of user assets.
U.S. prosecutions show the risk of unauthorized exploits
For U.S.-based researchers, returning funds or offering to negotiate does not necessarily prevent criminal charges when the original access was unauthorized.
In December 2023, former security engineer Shakeeb Ahmed pleaded guilty to computer fraud after exploiting two decentralized exchanges and obtaining more than $12 million. According to the U.S. Justice Department, Ahmed negotiated with one platform and proposed returning the stolen funds except for $1.5 million if the exchange agreed not to contact law enforcement.
Federal prosecutors said Ahmed later agreed to forfeit more than $12.3 million, including about $5.6 million in fraudulently obtained cryptocurrency. In April 2024, a federal judge sentenced him to three years in prison and ordered the forfeiture of the stolen assets.
Crypto World
Fairshake plans $30M push against Sherrod Brown
Crypto-backed super PAC Fairshake has prepared an expenditure of at least $30 million to oppose former Sen. Sherrod Brown’s return to the U.S. Senate following the failure of the CLARITY Act.
Summary
- Fairshake reportedly plans its largest expenditure of the 2026 election cycle against Brown.
- Brown is challenging Republican Sen. Jon Husted in Ohio’s November special election.
- Brown previously chaired the Senate Banking Committee and opposed several crypto-backed proposals.
- Fairshake and its affiliates had accumulated more than $193 million by January.
Fairshake prepares its largest 2026 expenditure
Eleanor Terrett, host of Crypto in America, reported on X that Fairshake plans to spend at least $30 million against Brown, citing an initial report from The New York Times and confirmation from a spokesperson for the political action committee.
If completed, the allocation would become Fairshake’s largest expenditure during the current election cycle. The decision arrived after the Senate rejected a procedural motion on the Digital Asset Market Clarity Act, an industry-backed bill intended to divide federal oversight of digital assets between the Securities and Exchange Commission and the Commodity Futures Trading Commission.
Brown is seeking an Ohio Senate seat in a special election against Republican Sen. Jon Husted. Describing the campaign as a re-election bid would be inaccurate because Brown lost his former seat to Republican Bernie Moreno in November 2024.
Husted, Ohio’s former lieutenant governor, joined the Senate in January 2025 after Gov. Mike DeWine appointed him to the seat vacated by JD Vance. Vance left the chamber to serve as vice president. The winner of the November 2026 election will complete the remaining portion of Vance’s term, which runs through January 2029.
According to Reuters, election analysts moved the contest from “likely Republican” to “lean Republican” after Brown entered the race in August 2025. Brown had represented Ohio in the Senate for 18 years before Moreno defeated him 50.1% to 46.5%.
CLARITY Act defeat raises the political stakes
The proposed spending follows the failed Senate vote on Sep. 15, when the motion to begin debate on the CLARITY Act received 50 votes to 49. Advancing the measure required support from 60 senators.
Several lawmakers involved in the negotiations voted against the motion, including Democratic Sens. Ruben Gallego, Kirsten Gillibrand and Angela Alsobrooks. Republican Sens. Susan Collins, Josh Hawley, Jerry Moran and Thom Tillis also withheld support.
Disagreements over presidential ethics, stablecoin rewards, protections for decentralized software developers and state authority prevented senators from reaching a final deal. Democrats had sought tighter limits on crypto businesses connected to President Donald Trump and his family, while banking groups pressed lawmakers to restrict rewards offered through stablecoin products.
A revised version would have assigned the CFTC authority over qualifying digital commodities and registered spot-market intermediaries. The SEC would have retained jurisdiction over assets and transactions governed by federal securities laws.
Hours before the vote, Democrats presented a counterproposal through talks involving Senate Minority Leader Chuck Schumer’s office. Republicans rejected it, saying their 635-page bill already included 126 changes requested during bipartisan negotiations.
Fairshake had supported the legislation before the vote through a national television advertising campaign. The PAC’s move into the Ohio race places its election spending behind the same policy campaign after the bill failed to secure enough Senate support.
Public pressure had also grown before the vote. Ripple Chief Legal Officer Stuart Alderoty urged undecided senators to speak with individual token holders, while a National Cryptocurrency Association survey estimated that 67 million Americans owned cryptocurrency in 2026.
Brown’s possible Banking Committee return concerns Fairshake
Brown’s record on the Senate Banking Committee has made his comeback bid important to the crypto industry. As committee chairman from 2021 until January 2025, he raised concerns about illicit finance, money laundering and consumer risks linked to digital assets.
Politico reported in August 2025 that Brown had blocked or resisted several Republican proposals supported by crypto companies while leading the committee. Fairshake spokesperson Josh Vlasto responded at the time by promising continued spending against candidates the group considered hostile to the sector.
“We will continue to support pro-crypto candidates and oppose anti crypto candidates, in Ohio and nationwide.”
A Brown victory would not automatically return him to the chairmanship or make him the committee’s senior Democrat. Senate Democratic rules generally treat service as interrupted when a former member leaves the chamber and later returns, meaning Brown would not necessarily retain the seniority accumulated during his previous 18 years.
Democratic leaders could change their caucus rules or grant Brown an exception, according to Politico. Control of the committee would also depend on whether Democrats win enough seats to take the Senate majority.
Husted has supported legislation favored by the crypto industry since entering the chamber. Politico reported that he backed relevant measures on the Senate floor and supported the sector’s policy goals while serving as Ohio lieutenant governor, although he had not made digital assets a central issue during his early months in Congress.
Crypto PAC enters an expensive Ohio contest
Fairshake has enough available funding to make the reported $30 million commitment. Axios reported in January that Fairshake and its affiliated committees had accumulated more than $193 million for the 2026 midterm elections, almost $60 million above the network’s total spending during the 2024 cycle.
Coinbase and Ripple each contributed another $25 million, while venture capital firm a16z supplied $24 million, according to Axios. Fairshake operates alongside two affiliated groups: Protect Progress, which participates in Democratic races, and Defend American Jobs, which focuses on Republican contests.
The network supports candidates from both parties based on their positions on digital-asset policy. Federal rules allow super PACs to raise and spend unlimited amounts, but they cannot coordinate expenditures directly with candidates or their campaign committees.
Ohio has already drawn heavy outside spending. Reuters reported on Sep. 18 that approximately $298 million in advertising had been spent or reserved for the race, placing it among the most expensive Senate contests of 2026.
Recent surveys cited by Reuters placed Brown three to five percentage points ahead of Husted. Brown’s campaign had raised $38.6 million, compared with $14.3 million for Husted, while Republican organizations launched a separate $14 million advertising campaign supporting the incumbent.
Fairshake previously made Ohio its most expensive target. During the 2024 election, the network spent more than $40 million supporting Moreno against Brown, exceeding its spending in every other race it entered. Moreno defeated Brown by about 207,000 votes and later joined the Senate Banking Committee.
Crypto World
Pepe price jumps 25% but overbought RSI warns of pullback
Pepe price surged nearly 25% on Sep. 21 as the meme coin cleared a major resistance level, although an overbought 4-hour reading raises the risk of a short-term pullback.
Summary
- PEPE price rose 24.75% on the daily chart and traded near $0.00000499.
- Price broke above $0.00000458, a level identified as a key structural barrier.
- The 4-hour RSI reached 82, placing PEPE deep in overbought territory.
- Liquidation data show large leverage clusters below the market near $0.00000360.
According to data from crypto.news, Pepe (PEPE) price traded around $0.00000499 at the time of writing after reaching an intraday high of $0.00000515. The rally lifted the meme coin by 24.75% during the daily session and extended its seven-day gain to nearly 40%, according to CoinGecko.
The token’s market capitalization climbed above $2 billion, while its 24-hour trading volume approached $900 million.
PEPE’s advance came alongside a wider crypto rally led by Bitcoin, which crossed $85,000 for the first time in eight months. Bitcoin exchange-traded funds operated by firms including BlackRock and Fidelity received about $433 million on Friday, according to JPMorgan data cited by the Wall Street Journal.
Broader demand for risk assets helped PEPE accelerate beyond the gradual recovery visible earlier in the week. However, its latest technical readings suggest that buyers may struggle to maintain the same pace without a period of consolidation.
Pepe price clears its major moving averages
The daily PEPE/USDT chart shows that the token has moved above its 20-day, 50-day, 100-day and 200-day simple moving averages.

PEPE’s 20-day SMA stood near $0.00000364, while the 50-day and 100-day averages were located around $0.00000337 and $0.00000330, respectively. The 200-day SMA remained lower at approximately $0.00000305.
Trading above all four averages marks a sharp change from the bearish structure that controlled the market during the first half of 2026. Price had fallen from above $0.000007 in late 2025 to a June low near $0.00000220 before forming a base.
The daily Awesome Oscillator also moved into positive territory at approximately 0.00000033. A positive reading means short-term momentum is stronger than longer-term momentum, supporting the current bullish setup.
The next technical test sits between $0.00000515 and $0.00000550. PEPE briefly touched the lower end of that area during the rally but had not produced a confirmed daily close above it at the time the chart was captured.
4-hour RSI warns of an overheated rally
Shorter-term readings show greater pullback risk after the rapid price increase.
The 4-hour Relative Strength Index rose to 82.05, well above the 70 level commonly used to identify overbought conditions. Its RSI-based moving average stood at 70.13, confirming that momentum accelerated sharply during the breakout.

An overbought RSI does not guarantee an immediate fall, but it can indicate that buyers have already committed substantial capital over a short period. PEPE’s latest 4-hour candle had declined 1.78% from its opening price after reaching $0.00000515, showing early profit-taking near the session high.
The 4-hour Supertrend remained bullish, with its support line near $0.00000431. Holding above that level would preserve the current short-term trend and could allow buyers to retest $0.00000515.
A drop below $0.00000431 would weaken the breakout and expose the former resistance area around $0.00000400. Deeper support sits near the 20-day moving average at $0.00000364.
PEPE liquidation clusters increase pullback risk
CoinGlass’s one-week liquidation heatmap shows that PEPE’s rally moved through several concentrations of leveraged positions between $0.00000410 and $0.00000450.

The largest remaining liquidity concentrations appear below the current price. Dense bands are visible around $0.00000355–$0.00000370, with another strong cluster near $0.00000320.
Liquidation heatmaps show where leveraged positions could face forced closure if the market reaches certain prices. They do not establish that price must move toward those zones, but concentrated leverage can add volatility when a reversal begins.
Smaller clusters also sit above PEPE near $0.00000510–$0.00000524. A renewed move through the intraday high could force additional short liquidations and extend the rally before the market tests higher resistance.
PEPE breakout puts $0.00001 back in focus
Crypto analyst Crypto Patel said PEPE has risen about 97% from a higher-time-frame accumulation zone between $0.00000200 and $0.00000270.
“The accumulation move is already underway. The next trigger is the breakout.”
Patel identified $0.000004583 as the level PEPE needed to reclaim and convert from resistance into support. The market has now traded above that threshold, but a daily close and successful retest would provide stronger confirmation than the initial intraday break.
The analyst listed $0.000010, $0.0000,16 and $0.000027 as possible longer-term targets if PEPE also breaks its higher-time-frame downtrend. Those levels remain projections rather than confirmed destinations, with the first target requiring the token to roughly double from its current price.
PEPE’s immediate outlook depends on whether buyers can defend $0.00000458 after the 25% daily advance. Holding that level would keep $0.00000515 and $0.00000550 in view, while losing it could send the token toward Supertrend support at $0.00000431 or the larger liquidation zone near $0.00000360.
Crypto World
Saudi Arabia Withdraws from mBridge CBDC Project
Saudi Arabia has withdrawn from mBridge, a China-backed cross-border digital currency project designed to enable direct transactions between central banks, according to the Financial Times.
SAMA, Saudi Arabia’s central bank, joined mBridge as a full participant in June 2024 and ended its participation after completing a proof of concept on May 13, 2025, FT reported, citing a statement from the central bank. SAMA said it had planned to end its participation.
MBridge was established in 2021 through a collaboration between the Bank for International Settlements (BIS) Innovation Hub and the central banks of China, Hong Kong, Thailand and the United Arab Emirates, with the aim of making cross-border payments faster and cheaper.
Rather than using a single stablecoin, the platform allows participating central banks to issue and transact in their own digital currencies on a shared ledger, including for cross-border payments and foreign exchange transactions.
The project continued to develop under the BIS until October 2024, when the organization handed it over to the participating central banks after mBridge reached its minimum viable product stage. Then-BIS General Manager Agustín Carstens said the BIS departure was not politically motivated.
The project has nevertheless drawn scrutiny from US policymakers. A 2024 report from the US-China Economic and Security Review Commission said mBridge could eventually provide an alternative cross-border settlement system for countries seeking to evade US sanctions.
Cointelegraph contacted the Saudi Central Bank for comment but did not receive a response by the time of publication.
Related: Chinese newspaper warns of Bitcoin extortion scam using its name
China weighs digital currencies’ role in cross-border payments
China’s central bank, meanwhile, has increasingly focused on the role stablecoins could play in cross-border payments as their use expands globally.
In June, People’s Bank of China Research Bureau director General Wang Xin called for closer monitoring of stablecoins and central bank digital currencies in cross-border payments, along with greater international coordination.
His comments came months after Chinese authorities restricted the unauthorized issuance of renminbi-pegged stablecoins and tokenized real-world assets, including by foreign entities.
Magazine: Who needs CLARITY anyway? ARB could see 70X increase: Hodler’s Digest
Crypto World
Tokenized stocks may see limited U.S. demand: TD Cowen
The SEC has opened a five-year route for tokenized U.S. stock trading, but TD Cowen has found that domestic investors, institutions, and listed companies show little appetite for the products.
Summary
- TD Cowen expects limited adoption among U.S. retail and institutional investors.
- Figure recorded 99.9% of examined trading through its conventional Nasdaq-listed shares.
- SEC relief requires stock tokens to preserve economic, dividend, voting, and liquidation rights.
- Nvidia perpetual futures generated 96% of related notional volume in a Binance snapshot.
TD Cowen said U.S. investors already have efficient access to listed shares, leaving tokenized venues under pressure to offer benefits that outweigh thin liquidity and added operational work.
Reid Noch, vice president of U.S. equity market structure at TD Cowen, wrote in a Friday paper that both retail and institutional demand will likely remain limited during the market’s early stage.
“U.S. investors already have efficient access to the underlying shares,” Noch wrote, adding that tokenized platforms need a compelling benefit to offset their operational complexity and restricted liquidity.
The assessment followed the U.S. Securities and Exchange Commission’s five-year tokenized stock exemption, announced on Sep. 17. The conditional relief lets qualifying Tokenized Securities Venues use permissioned automated market makers and liquidity pools to trade tokenized National Market System stocks.
Eligible liquidity providers can also receive temporary relief from certain dealer-registration requirements. Each participating venue remains subject to limits on the number of stocks it supports and the trading volume processed through the system.
Tokenized stocks must compete with efficient U.S. markets
For American investors, TD Cowen’s concern centers on whether tokenization improves a market that already offers deep liquidity, low-cost brokerage services and fast electronic execution.
Blockchain-based venues could extend stock trading into nights, weekends and holidays. Their automated market makers, or AMMs, would price transactions through asset pools and preset rules instead of matching buyers and sellers in a conventional order book.
In practice, Noch warned that continuous access does not guarantee favorable execution. A pool with limited assets may produce weaker prices, especially when fewer traders and liquidity providers are active outside the main U.S. session.
AMM pricing also places more weight on the amount and composition of assets deposited in each pool. Although a venue may remain technically open around the clock, TD Cowen’s analysis indicates that investors could still prefer established exchanges if the onchain market offers less liquidity or higher trading costs.
U.S. exchanges generally operate their main sessions between 9:30 a.m. and 4 p.m. Eastern Time on weekdays. Several brokers already provide premarket and after-hours access, reducing the value that some domestic traders may place on a separate blockchain venue.
The SEC has attached investor protections to its experiment. Approved tokens must represent NMS stocks and preserve the economic interest, dividends, voting power, and liquidation rights associated with the underlying shares.
Synthetic products that merely follow a company’s stock price do not qualify. As previously covered by crypto.news, the agency’s investor-rights requirements separate qualifying stock tokens from offshore products that may offer economic exposure without making the buyer a shareholder.
Issuer objections could restrict tokenized stock listings
Before a third party tokenizes a company’s shares, the SEC framework requires the proposed venue to notify the issuer. The company then has 30 days to object, according to the TD Cowen paper.
Listed businesses therefore retain some control over whether unrelated operators create blockchain versions of their securities. Trading cannot proceed under the exemption when an issuer objects.
According to Noch, discussions with dozens of issuers found little interest in offering tokenized shares. The group included several companies with large retail investor bases, although crypto-linked businesses such as Figure showed more interest.
“Our conversations with dozens of issuers” revealed minimal demand outside crypto-adjacent companies, Noch wrote.
Figure provides an existing comparison between traditional and blockchain-based shares. Its Nasdaq-listed FIGR stock trades alongside blockchain-native FGRS shares carrying the same economic exposure and voting rights.
During the 24-hour period studied by TD Cowen, conventional FIGR shares accounted for 99.9% of the company’s notional trading. The finding suggests that equal economic and governance rights have not been enough to move meaningful activity away from the Nasdaq-listed security.
Other SEC conditions may also limit how quickly venues can add markets. Smart contracts must be public and auditable, while operators must disclose trading activity, related-party transactions, and key details about their systems.
A venue must also halt a tokenized stock whenever the primary exchange stops trading the underlying shares. As a result, round-the-clock availability would not override an official halt related to volatility, company news or a regulatory issue.
In early September, the SEC also proposed a transfer-agent rule overhaul covering digital ownership records, cybersecurity, asset protection and third-party technology providers. Transfer agents maintain the official shareholder register used for voting, dividends, stock splits and other corporate actions, making their records important when a token claims to represent legal ownership.
Stock perpetuals show stronger demand than tokenized shares
For crypto traders seeking exposure to public companies, TD Cowen found more activity in perpetual futures than in spot stock tokens.
A snapshot of Nvidia-related trading on Binance showed that perpetual futures generated 96% of notional volume, while spot products accounted for 4%. Perpetuals track the price of an asset without transferring ownership of the referenced shares.
The contracts have no fixed expiration date and use recurring funding payments to keep their prices close to the underlying stock. They may also offer leverage, which lets traders control a larger position with less capital but increases liquidation risk when prices move against them.
“As we continue to outline, we see perpetual futures as the stronger demand story,” Noch wrote.
TD Cowen expects platforms to keep adding the products inside and outside the United States, citing retail demand for leverage.
Recent filings support the comparison. On Sep. 18, Coinbase submitted proposals for 50-plus stock perpetuals tied to companies including Nvidia, Microsoft and Tesla. The exchange plans to offer 24-hour trading from Monday through Friday if U.S. regulators clear the contracts.
Coinbase’s proposed products would provide leveraged price exposure without voting rights, dividends or ownership of the referenced shares. Their listing remains subject to regulatory review, and the company has not announced a launch date or complete contract specifications.
Earlier in September, Ondo Finance also asked the SEC and Commodity Futures Trading Commission to apply existing security-futures rules to stock perpetuals. Its Panama-based affiliate had processed $8 billion in cumulative volume within about six weeks, according to Ondo’s regulatory submissions.
Ondo said the offshore platform settles contracts in stablecoins and remains unavailable to American users. Many of its perpetuals reference U.S.-listed companies, allowing eligible non-U.S. traders to follow their stock prices without opening a conventional brokerage account.
Crypto World
ZetaChain Community Votes to Exit L1 and Migrate ZETA to Solana
ZetaChain’s token community has voted to wind down its own layer-1 blockchain and migrate its native ZETA token to Solana. The change was approved via governance proposal 68, with 99.4% of votes supporting the plan and participation at 58%, surpassing the network’s 40% quorum requirement.
While the vote clears the way for the transition, ZetaChain said it will not immediately trigger a full shutdown or migration. A second proposal is expected to lay out the practical details—timing, asset withdrawal windows for cross-chain holdings, token snapshot mechanics, and the conversion process duration.
Key takeaways
- Governance proposal 68 passed with 99.4% approval and 58% participation, clearing the first step toward ZetaChain’s layer-1 shutdown.
- ZETA will move to Solana as an SPL token via a 1:1 conversion, keeping the same ticker and total supply.
- The initial vote does not start the shutdown immediately; a follow-up proposal will specify withdrawal and conversion windows.
- Validators are expected to remain operational during the transition, with staking rewards continuing.
- ZetaChain cites a strategic shift toward its Anuma AI application and encrypted “Private Memory Layer,” reducing the need for a standalone Cosmos SDK chain.
Governance approval clears the path to a Solana token migration
According to the terms outlined in proposal 68, ZETA will become an SPL token on Solana through a 1:1 conversion. The migration is designed to preserve continuity for tokenholders: the ticker remains ZETA and the total supply stays unchanged.
The proposal also clarifies what comes next. It does not itself dictate an immediate cessation of ZetaChain’s layer-1 operations or the start of token migration. Instead, core contributors will bring a second proposal that covers operational specifics, including how and when tokenholders can withdraw assets related to other blockchains, the snapshot block height used to determine entitlements, the shutdown timetable, and the claim and exchange conversion period.
ZetaChain also indicated that validators will continue running, and staking rewards will continue through the transition. That matters for holders who rely on staking income, because it suggests there is intended continuity rather than an abrupt end to network participation.
Why ZetaChain is winding down: focus shifts to Anuma and private AI memory
ZetaChain framed the shutdown as a strategic realignment. The project said that maintaining its own layer-1—built on the Cosmos SDK—no longer fits its current priority around Anuma, its private-focused artificial intelligence application.
In the project’s view, moving the ZETA token to Solana will let it redirect resources away from blockchain maintenance and toward Anuma and the “Private Memory Layer.” The Private Memory Layer is positioned as a way for users to carry encrypted context across AI models, which would be difficult to support without dedicated product and infrastructure investment.
For tokenholders, the core question is how the token’s role changes when the layer-1 network is retired. The proposal keeps supply and ticker consistent, but it leaves open—pending the follow-up documentation—how governance, staking, and token utility will function after migration.
A broader pattern: other crypto projects retreat from standalone chains
ZetaChain’s decision aligns with a wider trend in crypto where teams choose to shut down standalone networks and migrate tokens elsewhere. The article notes that BounceBit and Harmony have both announced plans to retire their own layer-1 infrastructure.
BounceBit reportedly decided to retire its standalone blockchain after an authorization flaw was exploited to steal approximately $3 million in BB tokens. Instead of restarting its layer-1, BounceBit migrated its token to BNB Smart Chain at a 1:1 ratio.
Harmony’s approach has also centered on a pivot away from its layer-1. Earlier coverage cited that Harmony proposed shutting down its layer-1 and migrating its ONE token to Ethereum as an ERC-20, as part of a broader pivot toward an AI video initiative. That proposal followed a period of disruption tied to an exploit that created unauthorized ONE tokens and prompted a rollback plan affecting more than 109,000 transactions.
Security history and the settlement mechanics tokenholders should watch
ZetaChain’s migration comes with additional context around security. The project previously faced a $334,000 exploit in April targeting its cross-chain gateway contract, which drained funds from ZetaChain-controlled wallets across multiple networks including Ethereum, Arbitrum, Base, and BNB Smart Chain.
After the incident, ZetaChain acknowledged that it had dismissed an earlier bug bounty report, claiming it was intended behavior. That decision triggered a review of security processes.
In this light, the operational content of the second governance proposal becomes especially important. Tokenholders and users with assets tied to cross-chain functionality will want clarity on several items that proposal 68 did not specify: the precise withdrawal window for assets connected to other blockchains, how the snapshot block height will be determined, and the mechanics and timeline for token claims and conversion to Solana.
Investors and traders will likely also pay close attention to whether the transition period maintains staking participation and rewards as promised, and whether any changes to token administration accompany the migration.
Going forward, the key thing for ZetaChain stakeholders is the follow-up proposal that defines the shutdown and claim details. Until the network publishes the timeline, snapshot parameters, and conversion window, holders should treat the Solana migration as approved in principle—but not operationally complete.
Crypto World
SlowMist warns Darksword may target wallets on iOS 26.5
SlowMist has warned that attackers may have adapted the Darksword exploit chain to compromise devices running iOS 26.5 and extract private keys from self-custody crypto wallets.
Summary
- Darksword attacks can begin when an iPhone user opens a malicious link in Safari.
- SlowMist says attackers may have adapted the exploit chain to iOS 26.5.
- Google previously confirmed Darksword activity against iOS 18.4 through iOS 18.7.
- Three U.S. investors separately allege fake wallet apps caused $1.835 million in Bitcoin losses.
SlowMist Chief Information Security Officer 23pds said attackers are using Darksword to bypass Apple’s security controls, gain extensive access to affected iPhones, and collect data from locally installed cryptocurrency wallets.
The reported iOS 26.5 exposure has not been independently confirmed by Apple or Google. Google Threat Intelligence Group’s published research documented support for iOS versions 18.4 through 18.7, while 23pds said attackers have since modified the tool to work against the newer operating system.
Darksword may reach iOS 26.5 devices
Google’s Threat Intelligence Group identified Darksword as a full iOS exploit chain that combines six vulnerabilities to compromise devices and deliver separate malicious payloads. The company tracked related activity from at least December 2025 through March 2026.
According to Google, the original framework supported iOS 18.4 through iOS 18.7. One flaw used against iOS 18.6 to 18.7 devices, tracked as CVE-2025-43529, affected JavaScriptCore, the engine that processes JavaScript in Safari. Apple patched the flaw in iOS 18.7.3 and iOS 26.2 after Google reported it.
SlowMist’s latest assessment extends the potential exposure to iOS 26.5, although the security company’s claim has not received official confirmation. No technical analysis cited in the warning established which vulnerability or replacement exploit could let Darksword compromise the newer release.
Attackers generally initiate the compromise through social engineering, according to 23pds. A target receives a link through a social network, messaging app, or another communication channel and opens the page in Safari. Malicious web content then attempts to exploit the browser and other iOS components without requiring the user to install a conventional application.
Once the chain succeeds, the attacker may obtain root-level control, 23pds said. Such access can remove the isolation that normally prevents one application from reading files and credentials belonging to another, placing private keys and other wallet records stored on the device at risk.
Malicious Safari links can expose wallet data
Google found several groups using Darksword with different final-stage payloads, rather than one fixed piece of malware. Depending on the campaign, the payloads could collect account details, messages, browser records, files, location history, saved Wi-Fi data and information linked to cryptocurrency wallets.
The security company connected separate operations to victims in Saudi Arabia, Turkey, Malaysia and Ukraine. Google associated some activity with commercial surveillance providers and suspected state-linked groups, while researchers also found signs that financially motivated actors had gained access to advanced iPhone exploitation tools.
No victim total or confirmed amount of cryptocurrency stolen through Darksword was included in the material supplied by SlowMist. The warning instead focused on the framework’s ability to reach wallet information after compromising the device that stores it.
A similar delivery method appeared in an earlier mobile threat. In March, crypto.news covered Google’s findings on Coruna, an exploit kit containing 23 vulnerabilities across five attack chains. Coruna targeted iPhones running versions from iOS 13 through iOS 17.2.1 and could search files and images for terms such as “backup phrase” and “bank account.”
Google researchers said Coruna fingerprinted a visitor’s device before selecting an exploit suited to the iPhone model and software version. Some operators placed the kit on fake gambling and cryptocurrency sites, allowing the compromise to begin when a target loaded the page.
Recent iOS threats have targeted private keys
Darksword is not the only recent security threat involving cryptocurrency data on Apple devices. Binance warned iPhone and iPad users on Sep. 19 about malicious code found in FomoPeek versions 1.1 and 1.2.
Researchers examining the app found a kernel exploitation framework with eight attack methods and declared support covering iOS 12.0 through 18.7.2 and iOS 26.0 through 26.1. The malicious modules could escape the iOS sandbox, decrypt Keychain data, and access private keys, wallet recovery phrases, account credentials, and files held by other applications, according to a report on FomoPeek.
Binance advised anyone who had installed the affected versions to remove the app, update iOS, and avoid reinstalling it. Self-custody users were also told to create a new wallet on a clean device and transfer their assets, since deleting a malicious app would not protect a wallet if its private key or recovery phrase had already been copied.
Darksword uses a different route because its documented campaigns rely on malicious or compromised websites. Both cases, however, involve attempts to defeat the controls that ordinarily prevent software from obtaining sensitive records held elsewhere on an iPhone.
SlowMist advised users to install mobile operating-system updates promptly and avoid opening unsolicited links sent by strangers. Google and Apple have also treated current software as a central defense because Apple has patched the six vulnerabilities documented in the original Darksword chain.
U.S. investors have also sued Apple over fake wallets
For U.S. crypto holders, the Darksword warning follows a separate dispute over malicious wallet software distributed through Apple’s official marketplace. Three investors filed a federal lawsuit alleging that fake applications impersonating Sparrow Wallet appeared in the App Store and caused about $1.835 million in Bitcoin losses, according to earlier court coverage.
The plaintiffs’ allegations concern fraudulent applications rather than a browser-based exploit. Their case nevertheless centers on the security of Apple’s mobile distribution system and the financial damage that can occur when users trust software presented as a legitimate cryptocurrency wallet.
Another counterfeit application posing as Ledger Live allegedly stole at least $9.5 million from more than 50 victims between April 7 and April 13. Blockchain investigator ZachXBT traced funds from Bitcoin, Ethereum, Solana, Tron, and XRP users to more than 150 KuCoin deposit addresses and a mixing service.
The fake Ledger application asked users to enter their 24-word recovery phrases during what appeared to be a standard wallet setup. Apple later removed the listing, while one victim said he downloaded it while configuring a Ledger device on a new MacBook.
Unlike the Darksword chain, the fraudulent Ledger app did not need to break the operating system’s security controls. Users exposed their wallets by entering recovery phrases into the impersonating software, giving its operators control of every address derived from those phrases.
Crypto World
What Russia’s Parliamentary Election Results Mean for Putin and the War
Trump’s latest comments on the matter came Monday.
“Russia has unfortunately lost control of its Diesel Oil Industry due to its War with Ukraine. A large number of their Diesel refineries have been blown up and are, at least temporarily, out of commission,” Trump said on Truth Social on Sept. 21. “This ridiculous and never ending War with Ukraine must be ended.”
Beginning Saturday, as Russia entered its last day of voting, the government said it intercepted more than 1,600 Ukrainian drones, including 450 directed toward Moscow. The figures, attributed to Moscow Mayor Sergey Sobyanin and reported by state media TASS, have not been independently verified.
According to a statement by Sobyanin on Telegram, this was the largest ever drone attack on the Russian capital, damaging the city’s oil refinery.
How the world reacted to the preliminary election results
European powers have largely condemned the results. That includes France’s foreign ministry, which released a statement on Monday saying that the vote did not meet the conditions for “free, pluralistic, democratic elections.”
Crypto World
Bitcoin price news: BTC eyes $90,000 as leverage is building
Bitcoin has broken out to $86,000, but analysts say the next leg depends on whether spot buyers continue to show up as leverage builds.
Source link
Crypto World
Massive $1 Billion in Liquidations as Bitcoin Taps $87K: What’s Next?
Bitcoin’s price is closing in on $87,000 following an explosive rally, which triggered over $1 billion in liquidations across the crypto derivatives market.
The cryptocurrency reached an intraday high at exactly $87,000 (at the time of this writing), with its total market cap climbing toward $1.8 trillion.

The move extends Bitcoin’s impressive recovery from approximately $75,000 last week and has pushed it to its highest price since January.
Shorts Get Crushed as BTC Rallies Higher
The sharp move caught leveraged traders positioned for further downside.
Data from CoinGlass shows that roughly $1 billion worth of positions were liquidated, of which $900 million were short. More than 139,000 traders saw their positions force-closed, with the single largest liquidation happening on Hyperliquid, which carried a face value of slightly over $20 million.
This massive imbalance suggests that forced short closures provided additional momentum as BTC cleared several resistance levels in quick succession – an avalanche-like event, if you will.
This is called a short squeeze or a liquidation cascade.
What Happens Next for Bitcoin?
Attention is now quickly shifting toward the $88,000 area and beyond toward $90K.
As CryptoPotato recently reported, the popular analyst Doctor Profit highlighted Bitcoin’s reclaim of its 50-week moving average, currently near $78,700, as a very important development from a technical price point. The analyst identified $88K as the next potential target.
Some other analysis places a major bearish block at around this level. Therefore, a sustained break above $88K could bring $90K and even $95K into focus, while the region around $80K and $82K has now turned into an important support zone.
The post Massive $1 Billion in Liquidations as Bitcoin Taps $87K: What’s Next? appeared first on CryptoPotato.
Crypto World
NEAR Rallies ~80% Weekly as Intent Volumes Approach $30B
Near Protocol’s native token has jumped sharply this week as the network expands privacy-focused trading and related infrastructure. Over the past seven days, Near’s token traded around $4.29—up about 78.2%—according to CoinGecko, with CoinGecko also showing total cryptocurrency market capitalization up roughly 6% over the same period.
The rally appears tied to new privacy features launched for perpetual futures trading on near.com, alongside a growing ecosystem around Near Intents, a platform that coordinates cross-chain swaps by matching users with market makers.
Key takeaways
- CoinGecko data shows Near (NEAR) gained about 78% in seven days, outpacing a broader market that rose around 6%.
- Near says deposits and withdrawals for perpetual futures trading on near.com are now confidential by default, obscuring the connection between funding wallets and Hyperliquid trading accounts.
- Near.com’s confidential TVL surpassed $70 million, triggering the first snapshot under the NEAR@3.33 incentive program.
- According to the NEAR Intents Explorer, cumulative volume has reached about $29.3 billion, with $842 million recorded over the last seven days.
Confidential perpetual futures trading becomes the default
Near’s push into privacy accelerated this week after the protocol said on Thursday that deposits and withdrawals for perpetual futures trading through near.com are now confidential by default. In Near’s description, the feature is designed to hide the link between a trader’s funding wallet and a dedicated Hyperliquid trading account.
From an investor and user perspective, the practical effect is straightforward: traders who use near.com for perpetual futures can reduce exposure of wallet-to-account relationships that would otherwise be visible through on-chain flows or traceable account linkages. While the measure doesn’t necessarily prevent all forms of identification—market activity and other metadata can still reveal information—it directly targets a common privacy weakness in trading account structure.
The timing matters because the feature aligns with a broader industry narrative around privacy and confidentiality in finance. Near’s move effectively shifts attention from privacy as a niche value proposition toward privacy as a product feature for mainstream trading workflows.
Confidential TVL milestone and NEAR@3.33 incentives
On the same day, Near also reported that near.com’s confidential total value locked (TVL) crossed $70 million. The announcement said this milestone triggered the first snapshot under its NEAR@3.33 incentive program.
Near stated that the program set aside 333,333 milestone tokens for the first distribution. Under the program rules described in the release, the tokens unlock and convert to NEAR when the token’s three-day volume-weighted average price reaches at least $3.33.
This kind of condition can be significant for token-related expectations because it ties incentives to a price threshold rather than distributing immediately at the moment the TVL checkpoint is recorded. Traders and liquidity providers typically watch how these unlock mechanics may change selling pressure dynamics (for example, whether participants anticipate distributions once a price level is reached).
Near Intents keeps scaling volumes
Beyond trading privacy, Near’s ecosystem is also expanding through NEAR Intents, which enables users to request cross-chain swaps while market makers compete to execute them. On Monday, the NEAR Intents Explorer showed cumulative volume of roughly $29.3 billion.
The explorer also indicated $842 million in volume over the preceding seven days. For the prior 24 hours, privacy-focused Zcash wallet ZODL appeared as the third-largest referral source by volume, generating about $3.8 million across 458 transactions. The explorer also listed a large transaction involving roughly $613,000 worth of ZEC over the previous 24 hours.
While these figures reflect activity within the intent execution network rather than spot trading on a centralized exchange, they matter because higher intent volume can translate into stronger routing, execution competitiveness, and incentives for liquidity provision—factors that can make cross-chain execution more reliable for end users.
Why Zcash is showing up in the privacy narrative
Activity around ZEC in NEAR Intents has drawn commentary from researchers inside the ecosystem. Bitwise research analyst Camran Khosravi said Near and Zcash are “complements,” arguing that Near provides confidential cross-chain infrastructure and access to liquidity for ZEC holders.
Khosravi also cautioned about how TVL metrics can behave. He noted that NEAR Intents’ TVL can rise when the price of ZEC already held within the system increases, even if new deposits do not occur. That distinction is important for interpreting growth: TVL moving up doesn’t always mean user inflows are increasing at the same pace.
Near has continued extending its privacy focus beyond trading. In July, it introduced NEAR AI staking-based payments through near.ai, allowing users to stake NEAR to receive credits for confidential AI inference and agent hosting while keeping ownership of the underlying tokens.
Taken together, these announcements place privacy at the center of Near’s product strategy—spanning trading account confidentiality, cross-chain swap execution, and even confidential compute workflows.
Looking ahead, market participants are likely to watch two things closely: whether near.com’s confidential trading features and the NEAR@3.33 incentive mechanics translate into sustained liquidity growth, and how privacy-oriented assets like ZEC continue to contribute to NEAR Intents’ volume without relying solely on price-driven TVL increases.
-
Fashion3 days agoWeekend Open Thread: Talbots – Corporette.com
-
Tech22 hours agoResearchers escape OpenAI Codex sandbox to run commands on host
-
Crypto World7 days agoRevolut Attackers Warn of Ongoing Daily Customer Data Leaks
-
Crypto World3 days agoCircle launches Arc Studio AI agent for building onchain apps
-
Crypto World6 days agoRobinhood engineers charged over $50K crypto scheme
-
NewsBeat3 days agoTrump says US has reached an agreement to take permanent control of Greenland’s security
-
Crypto World7 days agoKraken Lets xStocks Holders Earn Yield Through DeFi
-
Crypto World3 days agoBitcoin price breaks channel as RSI climbs to 63
-
Crypto World5 days agoUS Charges Robinhood Engineers Over Crypto Listing Trades
-
Crypto World6 days agoWhat Is the Status of the U.S.-Iran Peace Talks? Here's What Both Sides Are Saying
-
Crypto World7 days agoNVIDIA Analysis: Attempted Rising Wedge Breakout Amid Pressure on the AI Sector
-
Tech6 days agoWebb’s IC 348 Mosaic Includes Two-Jupiter Dwarfs, Twin Jets, and a Nursery Still Making Worlds
-
Crypto World3 days agoWorld Money launches in 150+ countries with Stripe
-
Crypto World22 hours agoWho Needs CLARITY Anyway? ARB Could See 70X Increase: Hodler’s Digest
-
Crypto World7 days agoKraken Adds DeFi Yield on Tokenized Stocks and ETF Assets
-
Crypto World3 days agoSilver prices recover quickly, hitting weekly high today
-
Crypto World3 days agoTrading Bitcoin on Robinhood? Why 2% Spread Has Traders Worried
-
Crypto World7 days ago
Can Circle’s Arc Repeat Robinhood Chain’s Meme Coin Boom?
-
Entertainment6 days agoBig Brother Update: Melody Explodes at Drew as Illness Sweeps BB28 House
-
NewsBeat3 days agoUS was ‘on brink of war’ with China over false AI report of nukes moving in Middle East

You must be logged in to post a comment Login