Crypto World
OKX schedules delisting of GODS, PRCL and DUCK spot trading pairs
OKX has scheduled the removal of six GODS, PRCL and DUCK spot trading pairs while suspending deposits for the affected tokens from Aug. 7 and setting Nov. 7 as the withdrawal deadline.
Summary
- OKX will remove six GODS, PRCL and DUCK spot trading pairs across Aug. 14 and Aug. 17.
- Deposits for the three tokens have already been suspended, while withdrawals will remain open until Nov. 7.
- The exchange has not disclosed a reason for delisting the affected spot markets.
- The latest changes follow OKX’s recent regulatory and operational updates across Europe, South Korea and the United States.
According to an OKX announcement, the exchange will remove three margin-settled spot pairs GODS/USD, PRCL/USD, and DUCK/USD, between 16:00 and 18:00 UTC on Aug. 14. Three additional spot pairs quoted in USDT and EUR will follow three days later, with GODS/USDT, PRCL/USDT and DUCK/USDT scheduled for delisting during the same two-hour window on Aug. 17.
The exchange has also introduced a phased timeline for the affected assets. Deposits for GODS, PRCL and DUCK stopped at 16:00 UTC on Aug. 7, while withdrawals for the three tokens will remain available until 16:00 UTC on Nov. 7.
OKX has split the trading pair removals across two dates
Rather than removing all markets at once, the exchange has divided the delisting into two stages.
On Aug. 14, users will lose access to GODS/USD, PRCL/USD and DUCK/USD trading pairs. Three days later, OKX will remove GODS/USDT, PRCL/USDT and PRCL/EUR alongside DUCK/USDT, completing the process for all six spot markets listed in the notice.
At the same time, the exchange has already halted deposits for the related assets, preventing users from transferring additional GODS, PRCL or DUCK tokens onto the platform. Withdrawals remain available for another three months before closing in November, giving holders additional time to move their assets elsewhere.
The announcement did not state the reason for removing the trading pairs.
Deposit suspension starts before withdrawal deadline
The published timetable separates trading, deposits and withdrawals into different stages.
Deposit services for the affected cryptocurrencies ended first on Aug. 7. Trading activity will continue until the scheduled delisting windows in mid-August, after which the listed spot pairs will no longer be available.
Withdrawal support, however, will continue until Nov. 7, providing a longer period for customers who still hold the affected tokens after trading ends.
Crypto exchanges commonly separate delisting from withdrawal deadlines, allowing users to transfer assets after markets have been removed. In this case, OKX has provided nearly three months between the end of deposits and the final withdrawal cutoff.
OKX continues operational changes across multiple markets
The latest asset removals come during a period of operational updates across several regions.
Earlier in July, Digital Asset reported that the OKX Android application had returned to South Korea’s Google Play Store after a four-day suspension, making it the first recently restricted overseas crypto exchange to regain access on the platform. The restoration followed Google’s temporary removal of the app, while exchanges such as Bybit remained unavailable in the Korean Play Store.
Digital Asset had previously found that dozens of overseas exchange applications became inaccessible on Google Play as South Korea tightened oversight of overseas virtual asset service providers operating without local registration.
Although some exchanges had been identified by the country’s Financial Intelligence Unit as unreported VASPs, the publication reported that Google’s restrictions also affected several platforms that were not included on the FIU’s published enforcement list.
Outside South Korea, OKX has continued expanding regulated services in Europe. In July, the exchange launched a one-way USDT-to-USDC conversion service for eligible customers across 30 European Union and European Economic Area countries operating under its Markets in Crypto-Assets license.
The service allows users to deposit USDT and voluntarily convert their holdings into MiCA-compliant USDC as European exchanges reduce support for Tether’s stablecoin following the regulation’s implementation.
OKX has also expanded its institutional strategy
Operational changes have coincided with new corporate developments at the exchange.
Last month, OKX appointed former New York Governor Andrew Cuomo to its board of directors after he had advised the company on U.S. regulatory and institutional strategy since 2023. According to the company, the appointment formalized an existing relationship as OKX continued expanding its U.S. operations following the relaunch of its U.S. exchange and self-custody wallet in 2025.
The company has also continued working with Intercontinental Exchange through a planned joint venture focused on blockchain-based financial products. According to OKX, Cuomo will remain co-chair of the initiative, which is intended to combine ICE’s market infrastructure with the exchange’s blockchain technology, subject to regulatory approvals.
Crypto World
Brazil Adds Crypto Transfer Holds for Fraud Prevention
The rules, effective Jan. 1, 2027, cover transactions above $10,000 sent to overseas providers or self-custody wallets, along with other transfers flagged for review.
Brazil’s central bank will require virtual asset service providers (VASPs) to place precautionary holds of up to 24 hours on certain transfers to foreign platforms or self-custody wallets as part of new measures aimed at preventing fraud.
On Friday, the Banco Central do Brasil (BCB) said the requirement will apply to funds received above $10,000, either in a single transaction or based on a customer’s total transactions in a day. Providers must also hold other transfers requiring further scrutiny under their risk-management policies.
The rules take effect on Jan. 1, 2027. Providers must notify customers of holds and keep records of fraud incidents, attempted fraud and corrective actions. A VASP may complete its assessment and release a transfer before the 24 hours expire, provided that it follows parameters set out by the central bank.
The measure adds Brazil to a growing list of jurisdictions tightening crypto safeguards as regulators confront scams that exploit the speed and cross-border reach of digital assets.
Brazil joins global push against crypto scams
Brazil’s move follows anti-scam measures introduced in other jurisdictions. In Japan, the Financial Services Agency and National Police Agency asked crypto exchanges to restrict withdrawals after customers deposit fiat currency or buy digital assets.
The authorities also called for platforms to require customers to preregister withdrawal addresses and impose a waiting period before newly added addresses can be used.
Other proposed safeguards include customer-specific withdrawal limits, stronger monitoring, phishing-resistant multifactor authentication and checks that the name of a bank remitter matches the crypto account holder.
Unlike Brazil’s regulation, the Japanese measures are not binding. In addition, exchanges can determine implementation based on their operations and exposure to misuse.
Related: Brazil bars crypto settlement in regulated cross-border payment rails
European regulators have warned of criminals impersonating watchdogs and crypto companies as users search for licensed service providers after the EU’s Markets in Crypto-Assets licensing deadline.
France’s financial regulator reported cases involving fake websites, while the European Securities and Markets Authority said scammers had misused its identity and logo in falsified documents.
Magazine: 10 weirdest things ever tokenized… including farts
Crypto World
China Makes Largest Gold Purchase Since 2023 as Bullion’s Price Surges 8%
China made its largest monthly gold purchase in nearly three years and continues a massive accumulation streak, while other central banks have refocused on the precious metal.
This is among the reasons behind the asset’s price resurgence over the past week, in which it gained 8% from bottom to top.
China Buys Big
Data provided by The Kobeissi Letter shows that the People’s Bank of China (PBOC) added approximately 640,000 troy ounces, or roughly 20 tons, of gold in July alone, making it the biggest single-month purchase since October 2023.
Its streak has extended to a highly impressive 21 consecutive months of buying gold. The reserves climbed to just over 76 million ounces at the end of July from under 75.5 million in June. Current prices show that the country’s gold stash is worth over $306 billion.
Perhaps the bigger story here is the pace at which China is accelerating its purchases. It added only 160,000 ounces in March, followed by progressively larger acquisitions over the subsequent months. June’s 480,000-ounce accumulation was already the biggest in almost three years, only to be beaten by July’s acquisition.
Beijing has also focused on moving a large portion of its gold reserves from London to Hong Kong as it continues to support the city’s ambition to become a major precious metal hub.
“The relocation is set to continue as Hong Kong launches a new gold-clearing system aimed at making the city a bigger center for global gold trading and pricing,” said the analysts at The Kobeissi Letter.
Meanwhile, the World Gold Council data shows that central banks purchased a record 289 tonnes of gold during Q2, which is a 74% increase compared with the same period last year.
In contrast to its gold behavior, China actually tightened its cryptocurrency restrictions again earlier this year, confirming that any digital asset-related business activities remain illegal. It also expanded the scrutiny to stablecoins and real-world asset tokenization.
BTC vs Gold
The record accumulation from the PBOC and other central banks helped gold’s price stop its freefall and recover significantly over the past week. The precious metal fell from its ATH of $5,600/oz to just under $4,000 within months, but rebounded by 8% in the past week to close at $4,342. Interestingly, this recovery helped gold return to a breakeven YTD price.
As such, the bullion, even though it’s not really in the green in 2026, has performed a lot better than the so-called digital gold. BTC continues to struggle at $65,000, down over 25% since the start of the year.
The post China Makes Largest Gold Purchase Since 2023 as Bullion’s Price Surges 8% appeared first on CryptoPotato.
Crypto World
CLARITY Act faces Sept. 15 test as Grayscale sees low odds
Grayscale Head of Research Zach Pandl said on Aug. 8 that the CLARITY Act now appears unlikely to become law this year, pointing to a crowded Senate calendar and election year politics.
Summary
- Senate leaders filed cloture on CLARITY, setting a September 15 procedural test after August recess.
- Grayscale says passage this year appears unlikely, citing the Senate calendar and election year politics.
- The Senate Banking Committee advanced the bill 15 to 9 in a bipartisan May vote.
- SEC rulemaking can continue without CLARITY, including planned changes for crypto trading and custody rules.
- Grayscale warns missing federal legislation may push new investment and developer activity toward overseas markets.
Yet the bill has not been shelved. Senate Majority Leader John Thune has filed cloture on H.R. 3633, creating a concrete procedural test when lawmakers return in September.
The development leaves U.S. crypto policy on two tracks. Congress still has an opportunity to establish a permanent market structure framework, while the Securities and Exchange Commission is moving ahead with its own crypto agenda covering issuance, custody, trading and onchain securities. Grayscale argues that crypto markets can continue operating without CLARITY, but warns that the absence of legislation could make the U.S. less attractive for some new investment and development.
CLARITY Act now has a Sept. 15 Senate test
The U.S. Senate Daily Press record shows that Thune filed cloture on the motion to proceed to the Digital Asset Market Clarity Act before the Senate adjourned. The chamber is scheduled to return for regular business on Sept. 14.
More importantly, the Senate schedule says the cloture motion for H.R. 3633 will ripen at 2:15 p.m. on Sept. 15. The step concerns whether senators will proceed to consideration of the legislation. It is not a final passage vote, and the bill would still face debate, amendments and another vote if the Senate agrees to move forward. As crypto.news reported, the legislation needs enough bipartisan support to clear the Senate’s 60 vote cloture threshold.
The bill already has a bipartisan record. The House approved the earlier version 294 to 134 in July 2025, with 78 Democrats supporting it. The Senate Banking Committee then advanced its portion 15 to 9 in May 2026. Democratic senators joined Republicans during that committee vote.
Grayscale sees a narrowing path through Congress
Pandl’s assessment is less optimistic about the remaining legislative window. In Grayscale’s Aug. 8 research note, he wrote that the “chances of passage this year now appear low.” He attributed that view to the Senate calendar and election year politics rather than to an immediate threat to blockchain networks themselves.
Grayscale said failure to enact the bill would not immediately change how Bitcoin functions, halt major blockchain networks or stop the expansion of stablecoin payments. The firm’s concern instead centers on capital formation, tokenized securities, intermediary oversight and developer protections that would receive a more durable statutory basis under comprehensive legislation. Those conclusions are Grayscale’s policy assessment, not a guarantee of how investment would respond.
The firm also warned that “a greater share of new investment may occur overseas” without a federal market structure framework. Pandl argued that jurisdictions offering clearer token issuance rules and stronger developer protections could attract activity that might otherwise take place in the U.S. The forecast remains uncertain and depends on future policy decisions as well as industry behavior.
SEC rulemaking could fill part of the regulatory gap
Congress is not the only source of U.S. crypto policy. In March, the SEC issued a formal interpretation addressing several categories of crypto assets and explaining how federal securities laws apply to activities including staking, mining, airdrops and asset wrapping. It also addressed when a nonsecurity crypto asset may become tied to an investment contract.
The agency’s 2026 regulatory agenda goes further. It lists possible rules for crypto asset offerings and safe harbors, changes to accommodate crypto trading on alternative trading systems and national exchanges, and updates to custody requirements. The SEC also says its framework needs to account for onchain securities. In related coverage, regulatory action was already emerging as an alternative path if Congress failed to complete CLARITY.
Agency action, however, is not identical to legislation. SEC rules operate within authority Congress has already given the regulator and can be altered by later commissions, challenged in court or revised through future rulemaking. A statute can instead establish responsibilities across agencies and impose requirements Congress chooses to write directly into law.
What happens next for the CLARITY Act
Attention now turns to Sept. 15. The procedural filing prevents the August recess from becoming the immediate end of the bill’s 2026 effort, but it does not show that lawmakers have resolved the disputes that delayed action before the break. Senators have continued debating ethics provisions, stablecoin rewards, enforcement authority, consumer protections and illicit finance rules.
Those divisions remain visible within the Senate Banking Committee. Chairman Tim Scott and other Republican sponsors argue that the framework would provide clearer rules while keeping digital asset development in the U.S. Meanwhile, committee minority staff released a fresh analysis on Aug. 5 arguing that the current text contains weaknesses involving investor protection, national security and ethics. Those are competing legislative positions rather than settled findings about the final bill.
Sen. Cynthia Lummis released updated text on July 22 combining work from the Banking and Agriculture committees. Even if senators clear the September procedural hurdle and eventually approve a revised bill, differences with the House passed version would still have to be resolved before legislation could reach the president.a
As of then, Grayscale’s broader argument remains testable rather than settled. Congress has given CLARITY another route forward in September, while the SEC has demonstrated that regulatory changes can continue independently. The Sept. 15 vote will provide the next measurable indication of whether those two paths continue in parallel or whether Congress can still produce a comprehensive U.S. crypto market structure law in 2026.
Crypto World
Analyst Expects XRP’s Strongest Price Reversal Ever, but Polymarket Disagrees
Perhaps due to the delay of the CLARITY Act at the end of the week, Ripple’s cross-border token slipped to a major support level at just over $1.00, and questions arose whether a dip below that line is only a matter of time.
However, it has managed to remain above it during the weekend, and now a few analysts have noted that a major rebound is coming. One even called it ‘the strongest in history.’
Will XRP Bounce Immediately?
The asset’s slip to $1.02 on Friday pushed its RSI into a highly oversold area, which, according to popular analyst Dark Defender, means that the indicator has bottomed on the weekly timeframe. They explained it as the sub-wave structure within the Grand Wave, suggesting the completion of the major correction.
Consequently, Dark Defender turned highly bullish, indicating that investors should “expect the strongest reversal in history” once XRP reclaims the $1.05 zone, which is still being tested from the downside.
Fellow analyst Gerla agreed, noting that the asset just “swept the lows and bounced straight from major support.” He added that the price printed a lower low, while the RSI charted a bullish divergence. As long as XRP remains above $1.02, it has the chance to reclaim $1.08, which could send it “into a serious reversal.”
$XRP just swept the lows and bounced straight from major support.
Price made a lower low while RSI printed a bullish divergence.
The long-term trendline is also being tested perfectly.$1.02 held.
Now a reclaim of $1.08 could send $XRP into a serious reversal. pic.twitter.com/OXCKFiCGr2
— Gerla (@CryptoGerla) August 8, 2026
Meanwhile, other highly optimistic analysts, such as ChartNerd and EGRAG CRYPTO, presented long-term charts hinting at a major breakout ahead for XRP. Their targets sound quite far-fetched at the moment, given the current market conditions, but they are aligned on the expectation that they will be in the low- to mid-double-digit range.
Polymarket Odds Disagree
Unlike the aforementioned bullish expectations, traders on Polymarket are quite convinced that XRP’s path includes a dip below the coveted $1.00 level. In fact, the odds have risen to 65% for such a drop even by the end of the month. In contrast, a rise to $1.20 has a much smaller probability percentage of 17%, while a more profound rebound to $1.40 is at a negligible 2%.
BREAKING: XRP projected to crash below $1.00 by the end of the month.
65% chance.https://t.co/z5yfnlniyq
— Polymarket (@Polymarket) August 8, 2026
XRP’s painful history in August could be among the reasons behind this rather bearish view, as the asset has closed in the red in all four of the last editions. Moreover, it was just four times in the green since 2013.
The post Analyst Expects XRP’s Strongest Price Reversal Ever, but Polymarket Disagrees appeared first on CryptoPotato.
Crypto World
BTCPay Limits Remote Lightning Access After Reported Node Drains
BTCPay Server has taken a defensive step for Bitcoin Lightning users, temporarily blocking public remote connections to Lightning Network nodes running LND after attackers reportedly exploited a critical vulnerability to steal credentials and move funds.
The project said Lightning payments can still be processed, but external wallets—such as Zeus—will be unable to connect via a BTCPay Server domain or a Tor onion address in Docker-based deployments until BTCPay decides it is safe to re-enable that remote access pathway.
Key takeaways
- BTCPay Server has temporarily restricted public remote access to LND nodes in Docker deployments to reduce the chance of further credential misuse.
- Version 2.4.2 installs LND 0.21.1 and automatically regenerates Lightning “macaroon” credentials for standard BTCPay installations.
- Operators are urged to look for signs of compromise, including unauthorized payments, unexpected channel closures, unfamiliar peers, and mismatches between onchain/Lightning balances.
- Deployments that expose LND through routes outside BTCPay—such as a user-managed reverse proxy, Tor service, or forwarded ports—must rotate credentials separately.
Why BTCPay is limiting remote access
In a statement shared by BTCPay Server on X, the team said the restriction is designed to prevent external wallets from reaching affected Lightning nodes through BTCPay’s publicly exposed endpoints. The immediate concern is not the Lightning protocol itself, but how remote access can be abused when attackers gain control over the credentials that authorize actions on an LND node.
BTCPay emphasized that the change is intended to be temporary. It also indicated its plan is to bring remote access back once it determines it is safe—an important operational detail for service providers that rely on broad wallet connectivity for day-to-day payments.
What version 2.4.2 changes in LND authentication
BTCPay’s fix centers on credential rotation. According to the project’s security guidance, attackers were able to obtain “macaroon” credential files without proper authentication. Macaroons are the authorization artifacts LND uses to control access to node capabilities. If an attacker acquires them, the potential outcome is full take-over of the LND node and the ability to move funds.
BTCPay said version 2.4.2 addresses the issue by installing LND version 0.21.1 and automatically regenerating macaroon credentials on standard BTCPay setups. For operators, this is significant because it reduces the likelihood of lingering compromised credentials after an update—though it does not eliminate the need for active incident checks.
The project advised operators to verify whether compromise attempts occurred by reviewing several common indicators: unauthorized payments, unexpected channel closures, unfamiliar peers, and discrepancies between their records and either onchain or Lightning balances.
Actions operators must take beyond updating BTCPay
BTCPay’s instructions also draw an important line between what the software controls and what an operator configures. The team stated that installing the update does not automatically close access routes managed independently by the operator. If an LND node is exposed through other paths—such as a reverse proxy configured by the operator, a Tor service not run through BTCPay, or a forwarded port—then credential rotation may need to happen separately.
That distinction matters because it changes the practical remediation workflow. Updating BTCPay may fix the credential lifecycle for standard deployments, but it may not fully protect a node that is independently reachable. For operators, the key is to inventory how their LND node is reachable and ensure authorization material is rotated everywhere that the node can be accessed.
Reported impacts from operators
BTCPay’s warning is not theoretical. At least two operators publicly reported that their Lightning nodes were drained after the incident.
Foundation CEO Zach Herbert said the Lightning node associated with the hardware-wallet company’s setup was drained overnight. He later clarified that the company’s hot wallet was unaffected, while its Lightning channels were closed and funds were swept. The operators did not disclose the amount lost.
Bitcoin publication Citadel21 also reported that its Lightning node had been swept, without specifying the size of the loss.
While these reports are limited, they underline the risk that credential compromise can translate into direct fund movement via Lightning channels—reinforcing why BTCPay is restricting public remote access and why operators are being asked to check channel and peer activity closely.
Broader security implications for Bitcoin users
BTCPay’s incident comes amid a wider pattern of security problems affecting popular Bitcoin products. The BTCPay breach is described as part of the most recent wave of vulnerabilities impacting Bitcoin-adjacent tooling, following a Coldcard hardware-wallet flaw that was linked to more than $100 million in confirmed losses, as referenced in earlier coverage by Cointelegraph.
In other words, the underlying Bitcoin network is not the target; the failures occur in the surrounding systems—wallets, custody interfaces, and node management software—that users depend on to interact with the protocol.
For Lightning operators, the immediate next steps are clear: update to BTCPay Server version 2.4.2 (or apply the relevant fixes), verify that macaroon credentials are rotated as expected, and actively audit for unauthorized payments, unexpected channel behavior, unfamiliar peers, and balance mismatches. As BTCPay evaluates when to restore remote access, operators should also monitor how their own exposure routes outside BTCPay are configured—because those may determine whether the risk has truly been eliminated.
Crypto World
BTCPay Limits Remote Lightning Access After Attackers Steal Funds
BTCPay Server has temporarily blocked public remote connections to Lightning Network nodes running the Lightning Network Daemon (LND) after attackers exploited a critical vulnerability to obtain credentials and move funds. The project says Lightning payments can still proceed, while it works to make remote access safe again.
In a security-driven update, BTCPay Server announced that version 2.4.2 installs LND version 0.21.1 and automatically regenerates the “macaroon” credential files used to control LND on standard deployments. Operators are also urged to inspect their nodes for signs of compromise, including unauthorized payments, unexpected channel closures, suspicious peers, and mismatches between recorded balances and what’s actually present onchain or in Lightning.
Key takeaways
- BTCPay Server 2.4.2 restricts public remote connections to LND on Docker deployments, preventing external wallets from connecting via BTCPay domains or Tor onion addresses.
- The update automatically installs LND 0.21.1 and regenerates LND macaroon credentials on standard BTCPay installations.
- Operators should monitor for unauthorized payments, unexpected channel closures, unfamiliar peers, and balance discrepancies as indicators of theft.
- If an operator exposes LND through their own reverse proxy, Tor service, port forwarding, or other routes outside BTCPay, credentials must be rotated separately.
Why BTCPay moved to block remote LND access
BTCPay Server’s advisory centers on a specific failure mode: a critical vulnerability that, according to BTCPay, allowed an unauthenticated remote attacker to obtain the macaroon credential files that authorize control of an LND node.
Those credentials are effectively the key material that lets a party manage or act on behalf of the node. BTCPay warned that exposed credentials could enable attackers to take control of the LND instance and move funds.
To reduce the attack surface while remediation is rolled out, BTCPay temporarily restricted public remote connections to Lightning nodes running LND software through BTCPay-managed endpoints. In its statement, BTCPay highlighted that the change blocks external wallets—including Zeus—from connecting through a BTCPay Server domain or a Tor onion address in Docker deployments.
Importantly for day-to-day operators, BTCPay said Lightning payments can continue. The restriction is framed as a stopgap measure until the project believes it is safe to restore the prior remote-access functionality.
What the 2.4.2 update changes for operators
BTCPay’s fix is delivered through version 2.4.2. The project says this release installs LND version 0.21.1 and automatically regenerates macaroon credentials on standard BTCPay installations.
That automatic rotation is designed to address the core risk identified in the security advisory: attackers who acquired credentials could use them after the fact unless the underlying authorization artifacts are replaced. By updating both the LND version and the credentials used for control, BTCPay is effectively forcing the authorization state to reset for typical deployments.
Alongside the software changes, BTCPay provided a targeted checklist for operators to validate that compromise has not occurred. The project advised checking for:
- Unauthorized payments, which would indicate someone managed the node outside the operator’s intent.
- Unexpected channel closures, which can signal hostile channel management or forced routing behavior.
- Unfamiliar peers, which may reveal that an attacker established connections to the node.
- Discrepancies between what operators expect and what appears in their onchain or Lightning balances.
Crucially, BTCPay also addressed a deployment reality: not every operator exposes LND only through BTCPay’s own routing. For those running their own reverse proxy, Tor service, forwarded port, or alternative access path, BTCPay said installing the update does not close access routes managed independently. In those cases, operators must rotate credentials separately for any LND exposure outside BTCPay-controlled endpoints.
Public reports of losses, without disclosed amounts
After the vulnerability and remediation became part of the public conversation, at least two operators reported losses linked to their Lightning nodes being swept, though neither disclosed the amount taken.
Foundation CEO Zach Herbert stated that the hardware-wallet company’s Lightning node was drained overnight. He later clarified that its hot wallet was unaffected, while its Lightning channels were closed and the funds were swept—suggesting the compromise was confined to Lightning-channel controls rather than broader wallet infrastructure.
Separately, Bitcoin publication Citadel21 reported that its Lightning node had been swept. Like Herbert’s comments, the publication did not provide figures for how much was lost.
While the reports do not establish the scale of the incident across all BTCPay users, they do reinforce the advisory’s practical implication: credential exposure can translate into actionable control over Lightning funds, and remediation needs to happen quickly and thoroughly.
Security incidents keep targeting Bitcoin infrastructure around the network
BTCPay’s incident is the latest in a run of security problems affecting popular Bitcoin products. Earlier coverage from Cointelegraph highlighted a Coldcard hardware-wallet flaw associated with more than $100 million in confirmed losses, underscoring that the targets have tended to be software and infrastructure components built around Bitcoin—not the Bitcoin protocol itself.
This pattern matters because it shifts risk away from “Bitcoin as a network” and toward the systems people use to interact with it: wallets, node operators, payment servers, and bridging software between users and blockchain operations. In practice, that means the most valuable defenses are often operational—timely patching, correct credential rotation, careful exposure management, and continuous monitoring for anomalies.
BTCPay’s temporary restriction of remote access can be read as another step in that operational defense model: reduce inbound paths that could allow credential abuse, even as updates roll out and operators harden their setups.
For now, the most important thing for BTCPay operators is to apply version 2.4.2 and verify their exposure paths, then audit their nodes for the specific compromise indicators BTCPay listed. Readers should also watch for whether BTCPay restores remote-access features once it determines the remaining risk has been fully mitigated for the relevant deployment types.
Crypto World
No CLARITY Act, No Problem? Grayscale Explains Crypto’s Plan B
The CLARITY Act got stuck in political limbo at the end of the business week until lawmakers return from their August recess, and Grayscale laid out a potential plan ahead for the US crypto industry if Congress ultimately fails to deliver the highly anticipated market structure this year.
There’s no need to sugarcoat it: it would be a setback at first, but the company sees a path forward.
Crypto Will Survive
Grayscale has weighed in on several occasions on the bill’s potential, and its latest analysis admitted that an agreement this year still remains technically possible. However, the reality of the Senate calendar and the upcoming midterm elections have made official passage increasingly difficult.
Their report comes just as Senate Majority Leader John Thune filed cloture on the motion to proceed with the legislation before lawmakers left Washington last week. The procedural vote is scheduled for September 15 but still requires 60 votes. Importantly, it’s not a final vote on the bill, just to determine whether senators can advance toward formally considering it.
If they fail to do so, Grayscale argued that Washington has several other avenues to move crypto regulation forward even without comprehensive legislation from Congress. Perhaps the most significant path is the regulatory agencies themselves.
The CFTC and SEC have already become considerably more accommodating toward the crypto industry compared to previous years, as they can continue developing rules and interpretations governing the market even if Congress remains on the sidelines.
Nevertheless, these watchdogs are still limited in what they can accomplish without new legislation, particularly when it comes to establishing permanent jurisdictional boundaries between themselves. Yet, they can still address some major points of inflection within the industry, such as tokenized securities, custody, and trading.
On the plus side, institutional involvement has skyrocketed over the past few years through spot ETFs, stablecoins, tokenized RWAs, and growing Wall Street participation even as the CLARITY Act lingers. The GENIUS Act already provided a federal framework for payment stablecoins, which was a major win, added Grayscale’s Head of Research, Zach Pandl.
Odds Keep Slipping
The bill’s stagnation at the end of the business week was a blow for the industry, but Thune’s cloture brought some hope. However, several key issues remain, such as ethical disagreements, illicit finance rules, and language from the Senate Agriculture Committee.
Republicans don’t have enough votes to proceed alone, even if they all support the bill, as they need at least seven Democrats or independents. These difficulties, without a clear resolution in sight, have harmed expectations for passage this year, with Galaxy Research cutting the probability from 50% to just 30%.
The post No CLARITY Act, No Problem? Grayscale Explains Crypto’s Plan B appeared first on CryptoPotato.
Crypto World
BTCPay Server Rotates Credentials After Lightning Exploit
BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon (LND) software after attackers exploited a critical vulnerability to obtain credentials and move funds.
BTCPay said the restriction prevents external wallets such as Zeus from connecting through a BTCPay Server domain or Tor onion address on Docker deployments. BTCPay said Lightning payments can continue and that it plans to restore the remote-access option when it considers it safe.
Version 2.4.2 installs LND version 0.21.1 and automatically regenerates the macaroon credentials on standard BTCPay installations. The project advised operators to check for unauthorized payments, unexpected channel closures, unfamiliar peers and discrepancies in their onchain or Lightning balances.
The BTCPay breach is the latest security incident involving widely used Bitcoin products, following a Coldcard hardware-wallet flaw linked to more than $100 million in confirmed losses. The separate incidents affected software surrounding Bitcoin rather than the network’s underlying protocol.
Update automatically rotates Lightning credentials
BTCPay said the vulnerability allowed an unauthenticated remote attacker to obtain “macaroon” credential files used to control LND, an implementation of the Lightning Network. The project said the exposed credentials could allow attackers to take control of an LND node and move its funds.
According to the project’s security advisory, version 2.4.2 installs LND version 0.21.1 and automatically regenerates macaroon credentials on standard BTCPay installations. It advised operators to check for unauthorized payments, unexpected channel closures, unfamiliar peers and discrepancies between their records and onchain or Lightning balances.
Related: Coldcard exploit pushes July losses to $247M as second-worst month of 2026
BTCPay also said operators exposing LND through their own reverse proxy, Tor service, forwarded port, or another route outside BTCPay must rotate their credentials separately. The project said installing the update does not close access routes managed independently by the operator.
At least two operators publicly reported losses. Foundation CEO Zach Herbert said the hardware-wallet company’s Lightning node was drained overnight. He later clarified that its hot wallet was unaffected, while its Lightning channels were closed and the funds swept.
Bitcoin publication Citadel21 also reported that its Lightning node had been swept. Neither operator disclosed the amount lost.
Magazine: 10 weirdest things ever tokenized… including farts
Crypto World
Bitcoin split after BIP-110 fails, the new chain stopped after two blocks
Bitcoin mining firm AntPool mined the first non-signalling block, which the rest of the network accepted and BIP-110 nodes rejected, and a miner using Ocean produced the alternative that the breakaway chain followed instead. (A miner is an entity that uses massive computing resources to maintain bitcoin and process its transactions, earning newly issued bitcoin and fees for the work.)
AntPool and Ocean are mining pools, where many operators combine their machines and share the rewards.
The stall has a mechanical cause that is hard to escape. Bitcoin recalculates how difficult mining is every 2,016 blocks, aiming to keep blocks arriving roughly every ten minutes.
The breakaway chain inherited bitcoin’s current setting but has a tiny share of the machines, so its blocks arrive at long intervals. It cannot make mining easier until it completes 2,016 blocks at that pace. The monitor puts that at 350 days away, against 14 days for bitcoin.

Support was never there. Only 2.53% of blocks signalled for BIP-110 over the past two weeks, against the 55% needed to activate it without a split.
That leaves the fork coin in an awkward position for anyone hoping to sell it. Both chains still accept identical transactions, so a signed transaction sending fork coins also works on bitcoin, and a buyer can rebroadcast it there and collect real BTC from the same seller — opening up the chances of a novel attack method that users should keep track of.
Crypto World
Okta Stock: How Cybersecurity Firm Is Targeting ‘Nonhuman’ Identity
Okta Cl A Okta Cl A OKTA $ 148.32 $4.81 3.35% 44% IBD Stock Analysis Stock bouncing off 21-day after rebounding from 10-week OKTA may be working on new base IBD Composite Rating 99/99 Industry Group Ranking 3/197 Emerging Pattern Pullback Pullback A stock may pull back after a breakout, often to the 50-day line. A rebound from the first…
Copyright ©2026 Investor’s Business Daily, LLC. All rights reserved. 87990cbe856818d5eddac44c7b1cdeb8
-
Politics7 days agoZack Polanski: an incitement to murder Nigel Farage?
-
Fashion2 days agoFrugal Friday’s Workwear Report: Cap-Sleeve Pointelle Crewneck Sweater
-
Fashion2 days agoWeekend Open Thread: Mattifying Sunscreen
-
Crypto World7 days agoCrypto PAC spending tops $2M in Michigan House race
-
Business6 days agoDTCR: Deleveraging And A Hedge Fund Collapse Point To A Possible AI Bottom
-
Crypto World7 days agoXRP Ledger urges node upgrade after manifest flood
-
Sports3 days agoJordan Coyle & Cordiamo take Laya Arena Stakes at RDS
-
News Videos23 hours agoCan Astrology Help Find Gold and Silver Trends? A Financial Astrology Guide
-
Crypto World5 days agoUS Tech Stocks See Largest 5-Week Inflow in History: Can Nasdaq Break Its Downtrend?
-
Business3 days agoUS stocks: Dow closes at record on Mideast optimism; SpaceX, AMD drag Nasdaq
-
Politics3 days agoReform UK And Greens Sink To Lowest Favourability Ratings To Date
-
Business4 days agoNvidia Stock Climbs 2.5% as Chip Sector Rally Builds Ahead of AMD Earnings, Nvidia’s Own Report Looms
-
Crypto World5 days agoPolymarket targets $20 billion valuation as competition heats up in prediction market sector
-
Tech6 days agoOpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems
-
Tech4 days agoOpenAI, Anthropic AI agents targeted real people and systems in cyber tests
-
Business3 days agoSupply chain issues impact Ingredion
-
News Videos6 days ago#crypto #cryptocurrency #cryptonews #cuet2026 #ceuta
-
Business6 days agoMyspace owners announce plans to relaunch the once-popular platform
-
News Videos6 days agoCrypto.com Partners with UFC for UFC 331 Event
-
Crypto World5 days agoCLARITY Act Senate Vote Locked In, But 60-Vote Hurdle Looms Large

You must be logged in to post a comment Login