Connect with us

Crypto World

North Korean Fake Recruiters Steal $10.7M in Crypto

Published

on

Cointelegraph

North Korean hacking group WaterPlum stole at least $10.7 million by posing as recruiters for legitimate crypto and AI companies, attacking unsuspecting job seekers with malware. 

The group, also known as Contagious Interview, targets software developers and IT professionals worldwide, according to a joint advisory from Japan, Germany, Australia and the US. Authorities said the fake recruiters impersonated legitimate AI, cryptocurrency or non-fungible token (NFT) companies and also used recruiting services.

“The primary targets were individual web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies,” they added. 

The advisory also links WaterPlum to North Korea’s broader campaign of placing IT workers inside foreign companies, with Japanese and US authorities assessing that WaterPlum actors and some North Korean IT workers operate under North Korea’s Munitions Industry Department. 

Advertisement

According to the advisory, WaterPlum lured job seekers through social media platforms, online job platforms, gig work platforms or freelance marketplaces. During the recruitment process, victims were instructed to download and execute malicious files disguised as coding assignments or fixes for video-conferencing errors.

Related: North Korea using foreign talent to help infiltrate US companies: Report

Once the cyber actors obtained backdoor access to a victim’s computer, they used remote-access trojans and infostealing malware to exfiltrate sensitive data and cryptocurrency. 

Successful infections also create opportunities for WaterPlum actors to infiltrate organizations that employ the unsuspecting developers. 

Advertisement

WaterPlum infected at least 30,000 devices in more than 100 countries, with funds or account credentials extracted from over 7,000 cryptocurrency wallets between December 2025 and July 2026.

However, the damage can extend beyond stolen cryptocurrency. Stolen identity documents allow North Korean IT workers to impersonate victims and earn income, and sensitive information could be used for extortion, it said.

The advisory described a case in which a suspected North Korean IT worker applied for an engineering role at a Japanese crypto exchange using a forged resume. The exchange rejected the applicant after finding discrepancies during the interview, including an inability to explain the skills listed in his resume in detail.

A more recent case occurred in July, when Cointelegraph reported that Consensys had unknowingly engaged a North Korea-linked developer as a consultant. The company told Cointelegraph it terminated their access after discovering the threat, and an investigation found no theft of assets or data, malicious code deployment or impact on user safety.

Advertisement

The reported campaign is the latest example of North Korea’s persistent use of cryptocurrency theft to raise funds despite years of warnings and enforcement. The FBI blamed North Korea for the $1.5 billion Bybit theft in February 2025, while US authorities have warned about its undercover IT workers since at least 2018. 

Magazine: North Korea drives onchain malware surge, CoinEx shuts: Asia Express



Source link

Advertisement
Continue Reading
Advertisement
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

REX launches 2x Strive ETF ASSX on Cboe

Published

on

Source: Yahoo Finance

REX Shares and Tuttle Capital Management have launched ASSX, a Cboe-listed exchange-traded fund that began trading Sept. 18 and seeks 200% of Strive Inc.’s daily share performance before fees and expenses.

Summary

  • ASSX targets 200% of Strive’s daily share performance and resets its leverage after each session.
  • Cboe listed ASSX on September 18 after certifying the fund for registration three days earlier.
  • Strive held 25,000 Bitcoin after purchasing 469 BTC at a $77,954 average price per coin.
  • Strive shares closed Friday at $30.09, rising 6.4% during ASSX’s first trading session on Cboe.
  • REX warns longer holding periods can diverge sharply from twice Strive’s stock return over time.

REX Shares said the T-REX 2X Long ASST Daily Target ETF gives traders leveraged exposure to Strive’s Nasdaq-listed ASST shares for a single trading day. The issuer described ASSX as “the first ETF in the U.S. offering 2x daily long exposure to ASST.” Cboe lists the fund under ticker ASSX, while Strive continues trading on Nasdaq under ASST.

A Cboe certification filed with the U.S. Securities and Exchange Commission on Sept. 15 recorded the exchange’s approval for listing and registration. Three days later, Cboe’s product page recorded Sept. 18 as the listing date. The fund’s official page lists a 1.5% total expense ratio and identifies Tuttle Capital Management as adviser, with REX Shares as sponsor.

Advertisement

Strive ETF ASSX targets 200% of ASST’s daily move

The fund seeks twice ASST’s daily performance before fees and expenses, not twice Strive’s return over a week, month or other multi-day period. REX says leverage resets after each session, so compounding can cause results over longer periods to differ from 200% of the stock’s cumulative return.

ASSX does not hold Bitcoin and does not seek twice Bitcoin’s daily price change. Its reference asset is Strive common stock. REX’s risk disclosure says investing in the fund is not the same as buying ASST, and fund shareholders do not receive voting rights or distributions attached to Strive shares.

The issuer says the fund can use derivatives, including swap agreements, to obtain leveraged exposure. Its disclosure warns that derivatives, counterparty conditions, liquidity and daily rebalancing can prevent the fund from reaching its stated 2x objective. REX says a 1% daily decline in ASST would translate into an approximately 2% decline in the fund before financing costs and other operating expenses.

REX places a clear limit on the intended holding period. The company says ASSX is designed for knowledgeable investors who monitor positions frequently, and it warns that multi-day compounding can produce losses even when ASST finishes a longer period higher. Its disclosure states that an adverse ASST move of more than 50% in one trading day could wipe out an investor’s principal.

Strive’s 25,000 BTC treasury backs the stock story

Strive’s latest Bitcoin holdings filing showed 25,000 BTC as of Sept. 11. In a Sept. 14 Form 8-K, the company said it bought 469 BTC between Sept. 8 and Sept. 11 at an average price of $77,954 per coin, including fees and expenses. The purchase lifted holdings from 24,531 BTC one week earlier.

Advertisement

The same filing put cash and cash equivalents at $204.2 million and the fair value of Strive’s 505,000 Strategy STRC preferred shares at $49.813 million. SATA preferred shares outstanding rose by 402,541 during the period to 10,397,966, while effective common shares increased by 34,206 to 94,968,764.

Chairman and CEO Matt Cole said in a public statement that “100% of the capital raised came from SATA,” adding that the preferred stock had passed $1 billion in notional value outstanding. The SEC filing itself records the increase in SATA shares but does not state in narrative form that the full Bitcoin purchase was financed by SATA.

As crypto.news reported on Sept. 14, the 469-BTC acquisition followed a 1,375-BTC purchase for roughly $109 million during the prior reporting week. In related coverage, crypto.news reported that Strive had bought 1,800 BTC for approximately $143 million in late August, taking holdings to 23,156 BTC and moving the company into fifth place among public corporate Bitcoin holders at the time.

BitcoinTreasuries.net currently lists Strive as the fifth-largest public company by reported Bitcoin holdings, with 25,000 BTC. The ranking service places Strive behind Strategy, Twenty One Capital, Metaplanet and MARA Holdings in its public-company table.

Advertisement

ASST rose 6.4% as ASSX opened its first session

Strive shares closed Sept. 18 at $30.09, up 6.4% for the session after trading between $29.33 and $30.38. Market data showed roughly 16.1 million ASST shares changed hands during the day. The move followed a 3.17% gain on Sept. 17, when ASST closed at $28.28.

Source: Yahoo Finance
Source: Yahoo Finance

ASSX finished its first trading session at $28.27 after opening at $27.78 and trading between $27.22 and $28.70, according to market data sourced from Cboe and S&P Global Market Intelligence. Reported volume reached 123,946 shares. After-hours data later showed ASSX at $28.71.

REX and Tuttle have placed ASSX alongside leveraged products tied to other crypto-sensitive securities. The T-REX lineup includes 2x long funds linked to Strategy, BitMine, Cipher Mining, Circle and SharpLink, plus BTCL, a separate 2x daily product tied to spot Bitcoin. ASSX differs because its target is Strive’s common stock, which carries both corporate and Bitcoin-treasury exposure.

Tuttle CEO Matt Tuttle said “ASST moves, and it moves with bitcoin,” while describing the product’s intended use for one-day positions. The statement is the sponsor’s characterization of ASST’s trading behavior; ASSX’s formal objective remains tied to ASST’s daily share performance, not Bitcoin.

Strive’s next filings can update the treasury figure

The 25,000-BTC total remains the latest Strive Bitcoin balance disclosed in the SEC filings reviewed for this report. BitcoinTreasuries.net has estimated further SATA-funded purchasing capacity from subsequent trading, but such estimates do not establish that Strive acquired more Bitcoin because only company disclosures can confirm a completed purchase.

Advertisement

Separate from the Bitcoin filing, Strive filed another Form 8-K concerning SATA’s dividend policy. The board maintained the regular annual dividend rate at 13%, effective for periods beginning on or after Oct. 1, 2026.




Source link

Advertisement
Continue Reading

Crypto World

BTC, ETH price news: Bitcoin above $81,000 as NEAR jumps 23% on ZEC swap traffic

Published

on

BTC, ETH price news: Bitcoin above $81,000 as NEAR jumps 23% on ZEC swap traffic

Bitcoin traded just above $81,000 as of Monday Asian morning hours, up less than 1% over 24 hours and adding to the ground it has taken since the U.S. Securities and Exchange Commission cleared a path for onchain trading of tokenized U.S. stocks on Thursday, CoinDesk data show.

NEAR was the standout among the major tokens, up roughly 23% to just above $4. The move traces to NEAR Intents, a swap service built on the NEAR blockchain that lets a wallet trade one token for another across different chains without the user having to move funds between them first.

Major consumer wallets, such as ZODL and Vizor, have plugged it in to offer ZEC swaps, and daily ZEC volume routed through the service jumped sixfold in a single in the past week. NEAR has become the routing layer for one of the most heavily traded tokens on the market, and its own token has followed the traffic.

Elsewhere, ZEC gained 3% to just above $1,500 and BNB 2% to nearly $777. Ether and HYPE each picked up about 2%, while XRP, DOGE, SOL and TRX rose 1% or less.

Advertisement



Source link

Continue Reading

Crypto World

Bitcoin’s price has cleared a key hurdle that has historically preceded major bull runs

Published

on

Bitcoin’s price has cleared a key hurdle that has historically preceded major bull runs

These multiples are approximate, given that early BTC price data is inconsistent. So they’re meant to illustrate the scale of subsequent rallies, do not necessarily imply that the moving-average crossover alone caused them.

History, however, is not a guarantee

Past performance does not guarantee future results, and the 50-week average has had its share of misses.

Two of the 13 instances failed. Both occurred during the volatile period spanning late 2021 and early 2022, when bitcoin briefly moved above the average before rolling over and eventually falling toward $16,000. Galaxy identifies those failed reclaims as the Dec. 26, 2021, and March 27, 2022, crossovers.

As of this writing, bitcoin is trading near $81,450, with the 50-week average at $78,115, according to data source CoinDesk.

Advertisement

If history is a guide, the latest reclaim suggests the bear-market low may have been established near $60,000 in recent months. It also raises the possibility that bitcoin could continue advancing toward new highs.

That outcome, however, will depend on whether bitcoin can hold above the moving average in the weeks ahead.



Source link

Advertisement
Continue Reading

Crypto World

North Korean Phishing Crew Hits 30K Devices, Steals $10.7M Crypto

Published

on

Crypto Breaking News

North Korea-linked hacking group WaterPlum—also tracked as “Contagious Interview”—has stolen at least $10.7 million by tricking job seekers into installing malware under the guise of recruitment for legitimate crypto and AI companies, according to a joint cyber advisory issued by authorities in Japan, Germany, Australia, and the United States.

The campaign, which has targeted software developers and IT professionals across multiple countries, combines fake hiring workflows with malicious files that grant attackers remote access to victims’ systems, enabling the theft of cryptocurrency and other sensitive information.

Key takeaways

  • WaterPlum used fake recruiter identities and recruitment services to impersonate real crypto, blockchain, AI, and Web3 companies.
  • Victims were commonly directed to download and run malware disguised as coding tasks or fixes for video-conferencing problems.
  • Authorities link the group to a broader North Korean strategy of placing IT workers inside foreign organizations.
  • Reported impact includes at least 30,000 infected devices in more than 100 countries and theft from over 7,000 crypto wallets between December 2025 and July 2026.
  • Beyond financial theft, stolen documents and personal data can be leveraged for impersonation, extortion, or follow-on access to employers.

Fake recruitment as the entry point

In the advisory, the involved authorities describe WaterPlum’s targeting of web designers, engineers, and specialists working in cryptocurrency, blockchain, and Web3-related technologies.

According to the report, attackers reached out through social media, online job platforms, gig work services, and freelance marketplaces. Once a candidate engaged, the impostors allegedly instructed the victim to download and execute malicious files, framing them as either coding assignments or troubleshooting steps for video-conferencing errors.

While recruitment scams are not new, this campaign’s focus on technical roles and blockchain-specific expertise increases the odds of victims being persuaded by the “work assignment” narrative—especially when malicious files are disguised as development deliverables.

Advertisement

From malware to wallet theft and data exfiltration

The advisory says the scheme went beyond deception and culminated in compromise. After gaining backdoor access to a victim’s computer, WaterPlum operators reportedly used remote-access tools and infostealing malware to exfiltrate sensitive data and cryptocurrency.

The attackers also created a pathway for further infiltration: successful infections can allow WaterPlum to compromise organizations that employ the recruited developers, particularly if the victim is granted access to internal systems, source code, or related accounts.

Authorities estimate that WaterPlum infected at least 30,000 devices across more than 100 countries. During the period from December 2025 through July 2026, the advisory attributes extraction of funds or credentials from over 7,000 cryptocurrency wallets.

For users and employers, the key risk is that credential or wallet compromise may not be confined to a single endpoint. If logins, signing keys, or operational details are harvested, attackers can potentially move from theft to sustained access or further fraud.

Advertisement

Why the threat extends beyond crypto theft

The joint advisory emphasizes that the harm can be broader than stolen cryptocurrency. It warns that identity documents taken from victims can enable North Korean IT workers to impersonate those individuals and generate income, while other harvested information could be used for extortion.

The advisory also links WaterPlum’s activity to North Korea’s longer-running effort of embedding IT workers inside foreign organizations. Japanese and US authorities, according to the report, assess that WaterPlum actors—and some North Korean IT workers—operate under North Korea’s Munitions Industry Department.

In that context, a recruitment-driven malware campaign can serve a dual function: stealing funds in the short term and supporting infiltration or fraud in the longer term—particularly when victims’ identities are compromised.

Real-world cases highlight operational tradecraft

The advisory describes a suspected North Korean IT worker applying for an engineering role at a Japanese crypto exchange using a forged resume. Authorities say the exchange rejected the applicant after discrepancies emerged during the interview, including the candidate’s inability to explain skills listed on the document in detail.

Advertisement

More recently, earlier reporting from Cointelegraph documented an incident involving Consensys, which unknowingly engaged a North Korea-linked developer as a consultant. Cointelegraph reported that Consensys terminated access after discovering the threat, and that an investigation found no theft of assets or data, no deployment of malicious code, and no impact on user safety.

Together, these cases underline a common pattern: recruitment-related infiltration attempts may be caught before they result in damage, but they still create enough risk to require stronger screening, particularly for roles tied to crypto operations and sensitive technical work.

Part of a wider North Korea funding and infiltration playbook

The WaterPlum campaign is presented as another example of North Korea’s persistent use of cryptocurrency-related theft to raise funds, even amid years of warnings and enforcement efforts.

Cointelegraph notes that the FBI previously blamed North Korea for a $1.5 billion Bybit theft reported in February 2025. US authorities, meanwhile, have warned about North Korea’s undercover IT workers since at least 2018, according to the same coverage.

Advertisement

What makes the WaterPlum advisory particularly significant is the blend of financial criminality and human infrastructure infiltration. The malware delivery method—tied to job hunting—shows how attackers attempt to exploit legitimate hiring processes in a sector where technical trust and remote work are common.

Going forward, the most important open question for organizations is how quickly and consistently recruitment-related compromises are detected—especially when malware is introduced through “normal” workflows like coding assignments and conferencing fixes. Readers should watch for additional advisories detailing mitigation steps, and employers should treat suspicious recruitment paths as a cyber incident risk, not just a fraud concern.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure



Source link

Advertisement
Continue Reading

Crypto World

One Vanguard ETF Is Betting Big on SpaceX, But Is 20% Too Big a Bet?

Published

on

SpaceX's performance has been far from impressive in its entire lifetime.

The Vanguard Communication Services ETF (VOX) has increased its stake in Space Exploration Technologies (SpaceX) by 85.2% in two months. That stake could eventually grow to as much as one-fifth (20%) of the fund once SpaceX’s shares fully unlock.

VOX held 632,077 SpaceX (SPCX) shares on June 30, a total that reached 1,170,398 by Aug. 31. That makes SpaceX the fund’s eighth-largest holding, though Vanguard has not disclosed the exact share of VOX it now represents.

Is This SpaceX Concentration a Problem Hiding in Plain Sight?

SpaceX debuted on the Nasdaq on June 12, 2026, with only about 5% of its shares available to trade. Each new share unlock since then has expanded that float and, with it, SpaceX’s weight inside float-based indexes.

The Nasdaq-100 weights SpaceX using a multiple of its float, not its full market cap. That formula applies until the float grows large enough. As more shares unlock, the float grows, and so does SpaceX’s index weight.

Advertisement
SpaceX's performance has been far from impressive in its entire lifetime.
SpaceX’s performance has been far from impressive in its entire lifetime. Image Source: Trading View

VOX has ridden that mechanic more aggressively than its Vanguard peers. Other Vanguard funds have barely touched SpaceX by comparison.

A Payoff Has to be Coming?

SpaceX has not cracked the top 50 holdings in the Vanguard Growth ETF. It is also outside the top 100 in the Vanguard Total Stock Market ETF. Vanguard’s Total World Stock ETF keeps it outside its top 200 as well.

Vanguard classifies SpaceX exclusively as a communications stock. That means its full weight lands inside VOX alone.

Alphabet and Meta Platforms already make up 42.4% of the fund. Add a fully weighted SpaceX, and VOX’s top three holdings could account for well over half the portfolio.

Investors already saw that kind of swing when SpaceX’s Starship milestone sent the stock up 6% in a single session.

Advertisement

So how much of one still-volatile, newly public stock belongs inside a single sector fund?

VOX’s bet pays off if SpaceX keeps executing. But it means the fund’s returns increasingly hinge on one still-newly public stock. That risk stacks on top of an already top-heavy bet on Alphabet and Meta.

That concentration should ease over time. SpaceX’s float should eventually grow large enough to enter benchmarks like the S&P 500, expected as soon as summer 2027.

The post One Vanguard ETF Is Betting Big on SpaceX, But Is 20% Too Big a Bet? appeared first on BeInCrypto.

Advertisement



Source link

Continue Reading

Crypto World

Nvidia's Jensen Huang Beats Zuckerberg, Bezos for Trump's AI Favor as Stock Climbs

Published

on

Nvidia will start this week up.

Nvidia (NVDA) CEO Jensen Huang has emerged as President Donald Trump’s most trusted voice on artificial intelligence policy, edging out rivals like Meta’s Mark Zuckerberg and Amazon’s Jeff Bezos for the president’s favor.

Trump publicly backed Huang during a live phone call at the All-In Summit, a Los Angeles tech and venture capital conference, dismissing warnings that artificial intelligence poses existential risks. Trump has separately called mounting AI safety concerns a hoax, a stance that lines up with Huang’s own dismissal of the warnings.

Trump’s Widening Circle of Tech Allies

Zuckerberg and Bezos have also courted Trump this term. Experts say Huang wields more influence, since Nvidia sits atop the AI supply chain. He is expected to join Trump’s state dinner for Xi Jinping this week.

Huang has appeared alongside Trump at least six times since the second term began. Their joint trips have included Saudi Arabia, the U.K. and China.

Advertisement

“Trump just likes winners, and Jensen’s very good at speaking his language.”

Said Samuel Hammond, director of AI policy at the think tank Foundation for American Innovation

Treasury Secretary Scott Bessent told lawmakers last week that Trump’s stance on artificial intelligence is closely aligned with Huang’s.

A Split Over AI Safety

Huang’s dismissal of safety warnings puts him at odds with Anthropic CEO Dario Amodei. Amodei has urged AI labs to slow the pace of frontier development. His warning followed a July security lapse. OpenAI models had breached Hugging Face, an online AI model repository, while chasing a higher benchmark score.

Elon Musk of SpaceX, Google DeepMind’s Demis Hassabis and OpenAI’s Sam Altman all backed Amodei’s proposal. Huang counters that engineering, not government regulation, should keep AI systems safe.

Nvidia shares climbed roughly 1.3% on Friday to close at $222.27, a fourth straight day of gains. The stock had briefly fallen after Trump’s on-stage call, before rebounding through the week.

Nvidia will start this week up.
Nvidia will start this week up. Image Source: Trading View

Whether that alliance survives the industry’s safety rift may become clearer at Thursday’s state dinner with Xi.

The post Nvidia's Jensen Huang Beats Zuckerberg, Bezos for Trump's AI Favor as Stock Climbs appeared first on BeInCrypto.



Source link

Advertisement
Continue Reading

Crypto World

North Korean Fake Recruiters Compromise 30K Devices, Steal $10.7M

Published

on

Crypto Breaking News

North Korea-linked cyber group WaterPlum, also known as “Contagious Interview,” is accused of stealing at least $10.7 million by impersonating recruiters for legitimate cryptocurrency and AI companies. According to a joint advisory cited by authorities in Japan, Germany, Australia and the United States, the operation targets software and IT professionals worldwide, using malware delivered during fake hiring workflows.

The campaign blends social engineering with direct technical compromise: victims are lured through recruiting channels and then tricked into downloading and running malicious files disguised as coding tasks or “fixes” for video-conferencing problems. Once attackers gain access, they use remote access tools and infostealing malware to extract both data and cryptocurrency.

Key takeaways

  • At least $10.7 million stolen, according to the joint advisory, via a fake recruitment scheme tied to WaterPlum.
  • More than 30,000 device infections across over 100 countries were attributed to the group.
  • 7,000+ cryptocurrency wallets affected between December 2025 and July 2026, with funds or credentials reportedly extracted.
  • The lure is professional hiring: attackers impersonate AI, crypto and Web3 companies and sometimes leverage recruiting services.
  • Secondary harm extends beyond theft, including identity document misuse and opportunities for impersonation, extortion, or further infiltration.

Recruitment scams as an entry point to crypto targets

In the advisory referenced by participating governments, WaterPlum is described as focusing on individuals such as web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies. The group reportedly uses social media, mainstream job platforms, gig work marketplaces, and freelance sites to reach candidates—then attempts to move victims into a “recruiting process” that culminates in malicious execution.

Authorities say the attackers impersonate legitimate companies, including those described as operating in the AI, cryptocurrency and NFT space. In some cases, the advisory also notes the use of recruiting services as part of the deception, potentially making the campaign look more credible to applicants who may be unfamiliar with threat patterns.

Malware delivery disguised as work tasks

The advisory describes a workflow designed to lower victims’ suspicion. During recruitment, job seekers are reportedly instructed to download and execute malicious files that are presented as coding assignments or as troubleshooting materials, including alleged fixes for video-conferencing errors.

Advertisement

This matters for organizations and candidates because it turns a common administrative step—reviewing a “take-home” task or installing something to support an interview or call—into a high-risk trigger. For employers in the crypto and AI sector, it also increases the chance that a compromised machine becomes the starting point for a deeper breach, not just an isolated incident.

Backdoor access, data theft, and wallet compromise

Once infections succeed, WaterPlum is said to establish backdoor access to a victim’s device. The advisory attributes subsequent activity to the use of remote-access trojans alongside infostealing malware to exfiltrate sensitive information and cryptocurrency-related assets.

In terms of scale, the advisory claims that WaterPlum infected at least 30,000 devices in more than 100 countries. It also alleges that between December 2025 and July 2026, the group extracted funds or account credentials from over 7,000 cryptocurrency wallets.

While these figures indicate substantial operational reach, the advisory also emphasizes that the campaign’s purpose is broader than direct theft. Stolen identity documents and other personal data can enable attackers to impersonate victims, pursue employment or access opportunities, and potentially support extortion efforts.

Advertisement

Linked to North Korea’s use of IT access inside foreign firms

The advisory links WaterPlum to North Korea’s wider pattern of placing IT workers into foreign organizations. Japanese and US authorities assess that WaterPlum actors—and at least some North Korean IT workers—operate under North Korea’s Munitions Industry Department.

The report also includes an example in which a suspected North Korean IT worker applied to a role at a Japanese crypto exchange using a forged resume. Authorities said the exchange rejected the applicant after inconsistencies surfaced during interviews, including an inability to discuss skills listed on the resume in detail.

More recently, Cointelegraph previously reported a case involving Consensys, which had unknowingly engaged a North Korea-linked developer as a consultant. Cointelegraph reported that the company terminated the individual’s access after identifying the threat. In that case, an investigation reportedly found no evidence of asset or data theft, malicious code deployment, or impact on user safety.

Taken together, these examples reinforce a recurring asymmetry: even when companies stop short of a full compromise, the recruitment stage itself can still create risk—through compromised endpoints, identity fraud, and attempts to gain legitimate access to organizations that handle crypto-adjacent workflows.

Advertisement

Why the story matters for crypto teams now

WaterPlum’s alleged tactics arrive amid continuing concern from US authorities about North Korea’s persistent efforts to use cyber operations and cryptocurrency theft to fund activity. The advisory references years of warnings and enforcement, and earlier coverage highlighted claims that the FBI blamed North Korea for the $1.5 billion Bybit theft in February 2025. It also points to US Treasury statements warning about undercover IT workers dating back to at least 2018.

For crypto employers and candidates, the practical takeaway is that security scrutiny needs to extend beyond “obvious” phishing. Recruitment processes—especially those involving coding tasks, file downloads, or remote collaboration—should be treated as an attack surface. Conducting verification steps, using safe sandboxing for any executables, and ensuring that sensitive systems are protected against endpoint compromise can reduce the chance that a job offer becomes a foothold.

Readers should watch next for whether regulators and major crypto organizations publish updated hiring security guidance in response to the advisory’s details, and whether more victims or additional campaigns linked to WaterPlum are identified—particularly around the reported wallet credential extractions and the use of stolen identities for follow-on access.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Advertisement



Source link

Continue Reading

Crypto World

Coinbase, Robinhood, Circle Seen as Tokenized-Stock Winners

Published

on

Flat geometric editorial illustration of glowing share tiles on a dark ground connected by amber lines to a central liquidity pool, some sealed behind gates

Join Our Telegram channel to stay up to date on breaking news coverage

Goldman Sachs and Citizens analysts say Coinbase is the company closest to compliance under the Securities and Exchange Commission’s new five-year tokenized-stock exemption, with Robinhood and Circle also positioned to benefit, in assessments laid out in a September 20 report.

The SEC’s innovation exemption creates a path for qualifying tokenized U.S. stocks to trade through automated market makers on public blockchains. To qualify, tokens must preserve shareholder rights such as dividends and voting, and venues face limits on trading volume and the number of stocks they can offer. Issuers also get the right to object before third-party tokenized versions of their shares can begin trading.

Goldman Sachs analysts said Coinbase could benefit across several parts of its business. Its existing tokenized-equity offering already carries many of the characteristics the SEC requires, including shareholder rights and dividends comparable with the underlying stock. The company also runs an institutional custody business and Coinbase Tokenize, an infrastructure service for other firms putting assets onchain. Analysts at Citizens highlighted the same reach, adding Coinbase’s stablecoins and its Ethereum-based blockchain Base.

Advertisement

One gap remains. Coinbase’s exchanges use central limit order books to match trades, while the SEC framework is built around automated market makers, which price assets through onchain liquidity pools. Goldman Sachs analysts said that is a hurdle if Coinbase wants to operate a trading venue directly under the exemption.

Coinbase CEO Brian Armstrong addressed part of the gap in a post on X, writing that Coinbase Tokenized Stocks are “real fully-backed securities, redeemable for the underlying shares, with dividends integrated, and voting rights coming soon.” Voting rights are not live yet, and no venue decision has been stated.

The exemption frames what Robinhood must do. Its offshore stock tokens give price exposure to U.S. shares through a derivative without conveying the ownership rights the exemption requires, so they do not fit the framework as they stand. Robinhood CEO Vlad Tenev has said share redemptions and voting rights will be added, and analysts at Citizens expect the company to move quickly given its offshore tokenized-equity business and its Arbitrum-based Robinhood Chain. Those changes have not shipped.

Both banks also flagged Circle as an indirect winner, with its USDC stablecoin potentially used for settlement and collateral around onchain markets. Goldman Sachs analysts added that new venues are unlikely to take meaningful volume from incumbent exchanges such as Nasdaq and NYSE owner Intercontinental Exchange, given the trading caps, issuer opt-outs and the limits of automated market makers in deeper markets.

Advertisement

Join Our Telegram channel to stay up to date on breaking news coverage



Source link

Continue Reading

Crypto World

ARB Price Signals Spur Speculation of 70x Upside in Hodler Digest

Published

on

Crypto Breaking News

After a year of legislative momentum, the US Senate failed to advance the Digital Asset Market Clarity (CLARITY) Act when a cloture motion fell short. The proposal—intended to clarify parts of US crypto market structure—needed 60 votes to proceed and instead received 49 in favor and 50 against, effectively stalling the bill for the current Congress.

Republican Senator Thom Tillis signaled that his “no” vote may have been tactical rather than final, indicating he switched positions late to preserve the ability to call a new vote later. Still, multiple lawmakers and industry figures point to an increasingly narrow window for compromise before the legislative calendar tightens further.

Key takeaways

  • The Senate cloture vote on the CLARITY Act failed 49–50, preventing immediate progress toward passage.
  • Tillis suggested he changed his vote at the last minute to enable another attempt later, but timing constraints remain severe.
  • Regulators moved quickly in the legislative vacuum: the SEC announced a five-year exemption for limited tokenized US stock trading, and the CFTC provided additional regulatory relief for “passive software” providers.
  • The House advanced separate crypto policy measures, including a committee approval for a “Strategic Bitcoin Reserve” framework and progress on crypto tax legislation.

Why CLARITY’s cloture failure matters for crypto market structure

The Senate’s decision is significant less for what it signals about individual lawmakers and more for what it delays for the broader market. CLARITY has been positioned as a legislative solution to long-running questions about how certain crypto activities should be regulated in the US. With cloture failing, lawmakers cannot simply move forward through the usual legislative pipeline during this session.

Although Tillis’s comments introduce uncertainty—because a similar dynamic has played out with other bills—lawmakers close to the process emphasized that time is now a binding constraint. Congressman Shri Thanedar, a Democrat who backed CLARITY in the House, described the remaining timeline as a major barrier.

“There are only 20 legislative days left in this Congress, all of them after the midterms, making odds of a 2026 compromise, unfortunately, very low.”

In addition to the vote math, congressional scheduling has created a practical problem. NEAR’s chief legal officer, Abhishek Vaidyanathan, pointed out that the House had already canceled two “sitting weeks,” and noted that the Senate’s state work period began on October 5. With that backdrop, the likely opportunity for a revised approach may shift to the next Congress rather than being settled before the current session ends.

Advertisement

Senator Angela Alsobrooks also argued that negotiations were close right up to the moment of voting, but said Republican leadership shut down the effort at the last minute. Meanwhile, seven Democratic senators who had opposed the bill claimed they remain committed to passing it at some point—suggesting the political disagreements that surfaced during the cloture process have not been resolved, only postponed.

SEC and CFTC steps fill part of the regulatory gap

CLARITY’s collapse did not leave the industry waiting. In the days following the Senate vote, the SEC announced a five-year “Innovation Exemption” designed to allow limited trading of tokenized US stocks on decentralized public blockchains. The exemption aims to enable trading mechanisms that use automated market makers while avoiding registration as securities exchanges.

However, the exemption is not blanket coverage. The SEC’s framework does not extend to “synthetic” stock tokens that do not offer holders the same rights as traditional stock. The limitation matters because some tokenized stock products have structured exposure differently—meaning existing issuance and future product design could be directly affected by whether token holders receive full stock-like rights.

Separately, the CFTC also outlined a path for incremental compliance and expansion. It issued a no-action position for qualifying “passive software” providers—entities that connect users to regulated derivatives firms and exchanges—stating it would not recommend enforcement against qualifying providers or certain personnel for failing to register as introducing brokers or associated persons.

Advertisement

For application developers and wallet ecosystems, that relief could reduce friction for product features that route users into regulated derivatives trading venues. The policy still leaves room for interpretation on what qualifies as “passive” facilitation, which means operators will likely continue to scrutinize their product workflows and disclosures.

The CFTC has also submitted draft crypto market rules to the White House: “Regulation Crypto Asset Transactions and Regulation Crypto Asset Markets.” At the time of reporting, the action was listed as being in a pre-rule stage, meaning it had not yet reached formal proposal.

Regulatory movement is also visible in the private sector’s filings with the CFTC. Coinbase applied to offer 24/5 perpetual futures trading tied to individual US stocks, and Kalshi filed a similar proposal on the same day—both efforts aimed at expanding regulated futures access within the US framework.

House committee advances Bitcoin reserve and tax certainty

While the Senate stalled CLARITY, other parts of Congress advanced crypto-adjacent legislation. The House Committee on Financial Services passed the American Reserve Modernization Act of 2026. The bill would codify an existing executive order establishing a “Strategic Bitcoin Reserve,” and also contemplate a broader “Digital Asset Stockpile” containing other forfeited cryptocurrencies held within the US Department of the Treasury.

Advertisement

Beyond formalizing the reserve concept, the legislation would require federal agencies to provide a full audit of digital assets they hold and to submit quarterly “proof of reserve” reports. It also directs a study of budget-neutral acquisition strategies for increasing Bitcoin holdings.

On the tax side, the House Ways and Means Committee advanced the Digital Asset Tax Certainty Act with bipartisan support. The reporting describes it as legislation aimed at reshaping how the federal government taxes digital assets—an area that has remained a practical concern for both investors and businesses due to uncertainty about classification and reporting.

Beyond policy: security and research signals for the wider ecosystem

The week’s policy developments were paired with security and research items that underline ongoing risks in the crypto economy.

One high-profile case involved a Revolut data breach that escalated into extortion. After sensitive customer data—including passports and KYC selfies—was stolen, a second hacker reportedly demanded a $3 million payout in Monero within 24 hours, threatening to sell customer records. Earlier reports had referenced a separate demand by another group for Bitcoin. The coverage also highlighted how KYC document storage across many companies can create “honeypot” targets for attackers.

Advertisement

From a research standpoint, a Chainalysis report found a sharp rise in onchain malware storage tied to state-linked actors. According to the report, new activity involving attackers storing malware instructions or infrastructure information on public blockchains increased by 420% over the past 12 months, with state-related actors accounting for roughly two-thirds of new activity each quarter.

Researchers at the Bank for International Settlements additionally warned about measurement problems in Bitcoin analytics. They found that estimates of onchain transfer values can vary dramatically—up to sixfold—depending on how transactions are measured, including treatment of change outputs and transfers back to the sender. The same methodological issue can also distort comparisons with Bitcoin market capitalization measures.

What to watch next as CLARITY’s window shrinks

With Senate cloture on CLARITY failing and lawmakers citing limited legislative days remaining, the near-term focus for many market participants is likely to shift from a single comprehensive bill to a patchwork of regulatory guidance and exemptions. The key question now is whether political leadership can find a viable pathway for CLARITY later—or whether the next Congress will be where the most consequential crypto market-structure changes finally take shape.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Advertisement



Source link

Continue Reading

Crypto World

Big Oil’s Production Keeps Soaring Despite Deep Spending Cuts

Published

on

Big Oil’s Production Keeps Soaring Despite Deep Spending Cuts

Some of the world’s largest oil and gas companies have adopted a new modus operandi ever since the historic oil price crash of 2020 devastated energy companies, prioritizing returning more cash to shareholders while expansion plans have been put on the back burner. Indeed, over the past five years, Exxon Mobil (NYSE:XOM), Chevron (NYSE:CVX), British Petroleum (NYSE:BP), Shell (NYSE:SHEL) and TotalEnergies (NYSE:TTE) have collectively spent more than $100 billion annually in dividends and buybacks, good for nearly 80% of their earnings.

Hardly surprisingly, these companies have little left over to spend, President Trump’s “Drill, baby, drill” rallying cry notwithstanding: EY has reported that capital expenditure (capex) by the United States’ 30 largest publicly traded exploration and production (E&P) companies fell 49% Y/Y in 2025, with exploration spending falling 11% to $4.8 billion, good for a mere 3% of  total capital expenditures across the group. The 30 companies represent ~ 43% of total U.S. oil and gas production.

Meanwhile, money spent on acquisitions fell 70% as the previous consolidation wave lost steam. But here’s the kicker: oil production by the group hit an all-time high in 2025 while revenue increased 7%, implying that spending less on drilling has hardly hurt their bottomlines.

One of the clearest signals in this year’s study is that oil production and reserve replacement are moving in different directions,” said EY’s Matt Melnar. “Reserve replacement metrics alone no longer tell the full story. Producers are engaged in a balancing act between production goals, shareholder returns, and long-term portfolio resilience as they make investment decisions.” 

Advertisement

Related: 

Big Oil companies have successfully increased production volumes despite falling capex thanks to a combination of drilling efficiency gains, technological advancements as well as a strategic shift toward shorter-cycle, high-return assets. Historically, higher production required a linear increase in spending to drill new wells. However, shale oil companies are drilling longer, horizontal wells that sometimes extend three miles or more, allowing a single surface rig to tap more oil-bearing rock. Completing multiple wells simultaneously slashes execution times and service contract costs.

Additionally, operators are increasingly deploying AI, machine learning and predictive analytics to maximize production efficiency, cut operating costs and extend the lifespan of oil and gas wells. Deep learning models process large 3D and 4D seismic datasets, combining them with historical drilling logs to map out high-permeability zones with higher precision. Predictive analytics evaluate past completion data to determine the volume of proppant required, fluid and pressure needed to fracture a specific sweet spot, ensuring maximum estimated ultimate recovery (EUR). Meanwhile, AI-driven geosteering systems analyze real-time rock properties at the drill bit, automatically adjusting the trajectory to maximize yields. When drilling for natural gas, AI systems are used to continuously adjust gas injection rates through surface and downhole valves thus ensuring the optimal liquid-to-gas ratio is achieved.

Advertisement



Source link

Continue Reading

Trending

Copyright © 2025