Crypto World
Zano Reverts Blockchain After Gateway Address Exploit in April
Zano has rolled back roughly a month of blockchain history after it identified a vulnerability tied to “Gateway Addresses” that, according to the project’s core team, enabled unauthorized ZANO and Freedom Dollar (fUSD) to enter circulation.
In an update shared Sunday, Zano said the network was restarted at block 3,833,000—immediately before Hard Fork 6, which introduced the affected functionality. The recovery now depends on ecosystem participants, including nodes, miners, stakers, exchanges, and other services, upgrading to the revised software.
Key takeaways
- Zano restarted the chain at block 3,833,000, rolling back about a month of activity tied to an exploit linked to Gateway Addresses.
- The rollback removes both legitimate transactions from that window and the unauthorized ZANO and fUSD that entered circulation.
- Payments already completed on other blockchains cannot be undone, limiting how far the recovery can reverse real-world settlement.
- Zano says it will handle remediation for affected parties through a reimbursement and claims process, though details have not yet been published.
- The fix requires coordinated adoption by infrastructure operators and service providers, including exchanges and other third parties that integrate with Zano.
Hard Fork 6 and the Gateway Address vulnerability
Zano has not published a full post-mortem as of publication, but it has confirmed that the problem originated with Gateway Addresses—a feature designed to simplify how external platforms such as bridges, exchanges, and payment services integrate with the Zano network.
According to the project’s explanation, Gateway Addresses enable these services to manage funds using a single “account-style” balance rather than handling payments as scattered transaction outputs.
Before Gateway Addresses existed, Zano wallets operated using separate transaction outputs (UTXOs). For exchanges and similar services, that meant incoming funds required blockchain scanning to identify which outputs belonged to a platform, followed by selecting specific outputs for withdrawals.
The introduced feature changed that workflow by offering a different way to account for funds—one that, in Zano’s view, became the pathway for the vulnerability that allowed unauthorized tokens to be minted or otherwise introduced into circulation.
What the rollback does—and what it cannot fix
Zano’s rollback invalidates the on-chain record of the affected period. The project states that transactions processed during that time will no longer appear on the restored chain. It also says the unauthorized ZANO and fUSD created or introduced through the exploit will be removed from the recovered ledger.
However, Zano cautioned that the rollback cannot reverse payments already settled on other blockchains. That distinction matters for users and service operators: if cross-chain transfers or off-chain settlements were completed before the restart, those transfers may not be recoverable even if the originating chain history is rewritten.
Zano also indicated that it is working to account for losses and will publish a reimbursement and claims process. The project did not provide the mechanics of how losses will be calculated or what documentation will be required within the material available at the time of writing.
Why Zano chose to restart the network
Zano’s head of marketing and growth, Quinten van Welzen, framed the decision as a trade-off between restoring the integrity of the currency supply and accepting a painful loss of history.
In statements shared alongside the rollback announcement, van Welzen argued that “doing nothing” would have allowed unauthorized ZANO and fUSD to remain in circulation without limits—effectively diluting holders and breaking what he described as the basic promise a currency makes: a fixed supply. He also suggested that allowing the attacker to retain value would set a dangerous precedent.
He acknowledged that restarting the chain from before Hard Fork 6 carries costs, including the disappearance of about a month of transaction history. At the same time, van Welzen said the rollback restores the supply that users expected and leaves a path for rebuilding trust.
Gateway Addresses and the risks of integration features
Zano’s broader context helps explain why the exploit mattered. The project launched in May 2019 as a layer-1 blockchain focused on private payments. Standard private transactions are designed to conceal senders, receivers, transferred amounts, and asset types.
Beyond its native token (ZANO), Zano allows users to deploy and mint custom digital assets. Freedom Dollar (fUSD) is one such token operating on the Zano blockchain. The vulnerability therefore wasn’t confined to a single token: unauthorized issuance affected both ZANO and an issued asset tied to the same underlying system.
Gateway Addresses were created to make integrations easier—especially for services that need to handle deposits and withdrawals without scanning UTXOs manually. But Zano’s response underscores a central theme in blockchain security: features that simplify custody and balances for third parties can also concentrate risk if they introduce new assumptions or pathways an attacker can abuse.
In that light, the coordination requirements for the restart carry practical weight. Zano said the recovery requires participating nodes, miners, stakers, exchanges, and other services to adopt the update. Without broad adoption, the network could split between versions, complicating settlement and increasing operational risk for trading venues and custodial providers.
For users, the rollback also highlights a limitation that extends beyond Zano itself: even if the originating chain is corrected, downstream effects—especially those involving cross-chain transfers or already-completed settlement—may remain permanent.
Looking ahead, attention should focus on the reimbursement and claims process Zano said it will publish, as well as how quickly exchanges and infrastructure operators finalize adoption of the restart. The project’s next security communications—whether it eventually releases a deeper technical post-mortem—will also be important for assessing whether Gateway Addresses will be reworked to prevent similar failures.
Crypto World
Zano Reverts Blockchain to Earlier Height After Gateway Exploit
Zano’s core team has restarted the Zano blockchain to undo roughly a month of activity after it identified a vulnerability tied to “Gateway Addresses” that allowed unauthorized ZANO and Freedom Dollar (fUSD) tokens to enter circulation. The restart reverts the chain to block 3,833,000—immediately before Hard Fork 6 introduced the affected feature.
According to the project’s leadership, the recovery will only take full effect once participating nodes, miners, stakers, exchanges, and other services adopt the updated software. The team says transactions and token activity that occurred during the compromised period will no longer appear on the recovered chain. However, it also warns that the rollback cannot reverse payments that were already settled on other blockchains.
Key takeaways
- Zano restarted the chain at block 3,833,000, rolling back about a month of history linked to an exploit affecting Gateway Addresses.
- The reset targets activity after the Hard Fork 6 feature deployment, meaning compromised transactions won’t show on the restored chain.
- Participating nodes, miners, stakers, exchanges, and other infrastructure providers must upgrade to complete the recovery.
- Zano says it will publish a reimbursement and claims process to address losses, though cross-chain settlements cannot be undone.
Rollback mechanics: what changed and what can’t be reversed
The project says the vulnerability’s impact is limited to the period after Hard Fork 6, when Gateway Addresses were introduced. By restarting the network from block 3,833,000, Zano invalidates both legitimate transactions included after that block and any unauthorized ZANO and fUSD that the exploit minted or introduced.
That matters for users and service operators because it effectively resets the on-chain record for that interval. Anyone who relied on transactions during the rolled-back window—whether for balances, accounting, or automated workflows—will need to reprocess those events against the restored chain state.
At the same time, the team draws a clear boundary around what is feasible. While the rollback can change what is recognized on Zano itself, it cannot undo transactions already finalized elsewhere. For users who moved value through cross-chain transfers or other external systems, the project’s update implies that losses tied to already-settled external payments may not be recoverable via the chain restart alone.
What are “Gateway Addresses,” and why they became a target
Zano says it has not published a full post-mortem yet, but it confirmed the exploit originated with Gateway Addresses. The feature was created to make integrations easier for bridges, exchanges, and payment services by allowing them to manage funds through a single account-style balance model.
Before Gateway Addresses, Zano wallets tracked funds as separate transaction outputs (UTXOs), rather than as one consolidated account balance. That difference influences how exchanges and payment processors work: services had to scan the blockchain to identify incoming payments, track which outputs corresponded to customer deposits, and select appropriate outputs when users requested withdrawals.
By contrast, an account-style abstraction can streamline integration logic—especially for services that want a unified view of balances. The Zano team’s decision to revert the network “immediately before Hard Fork 6,” however, suggests the abstraction layer introduced new attack surface that was not sufficiently contained.
Zano’s public explorer shows the rollback taking place on Sunday, reflecting the chain reset and the shift back to the pre–Hard Fork 6 state. The project did not provide additional technical details in the excerpted information, but the explicit identification of Gateway Addresses helps narrow the likely root cause to the feature rather than to core transaction privacy itself.
Token supply, trust, and the case for restarting
The Zano leadership framed the restart as a tradeoff between immediate disruption and long-term credibility. Quinten van Welzen, head of marketing and growth, argued that “doing nothing” would have meant unauthorized ZANO and fUSD remaining in circulation indefinitely—diluting holders and undermining the idea of a fixed supply.
Van Welzen also suggested that allowing the compromised supply to stand would signal to future attackers that they could retain value after an exploit. In that view, the most damaging outcome would not just be the technical breach, but the precedent it sets for adversaries.
Restarting from an earlier block, he said, comes with real costs: it eliminates about a month of blockchain history and requires the community to rebuild trust. Still, the team’s position is that restoring the intended supply and restarting from a clean state offers a path back that justifies the disruption.
Why exchanges and validators are central to the fix
Zano’s recovery depends on adoption. The team said participating nodes, miners, stakers, exchanges, and other services must adopt the update so the network stabilizes on the recovered chain state. This requirement is especially important for institutional and high-throughput operators, where delayed upgrades can lead to inconsistent balances, duplicate processing, or mismatched transaction histories.
For traders and users, the implication is straightforward: infrastructure readiness will determine how quickly services converge on the restored ledger. For exchanges in particular, the rollback also affects deposit and withdrawal accounting—so operators may need to re-sync transaction histories and ensure customer records match the post-recovery state.
In parallel, Zano says it is working to account for losses. The team indicated that it will publish a reimbursement and claims process, which should become a key reference for affected parties once the details are released. Until then, the only fully reliable takeaway for users is that transactions from the compromised period are expected to disappear from the restored chain, while any already-settled activity outside Zano may not be reversible through the rollback.
Going forward, readers should watch for the promised reimbursement/claims instructions and any technical follow-up that clarifies exactly how Gateway Addresses were exploited, because those details will likely determine how integrators adjust their systems and how quickly confidence can be rebuilt after the Hard Fork 6 rollback.
Crypto World
BlackRock CIO Dumps Stocks for High-Grade Bonds. Here’s Why
BlackRock’s Rick Rieder is cutting stocks. He says high-grade bonds paying 7% to 8% now beat the 10% to 12% he expects from equities.
Rieder is chief investment officer of global fixed income at BlackRock and oversees about $2.4 trillion. He spoke on Yahoo Finance’s Sozzi Unleashed about the 10-year Treasury yield above 5%.
Why the US Treasury Yield Matters
The 10-year yield is the interest rate the US government pays to borrow for a decade. It shapes mortgage rates, company loans, and stock prices.
This month it rose above 5% for the first time since 2007. TradingView data shows it at 5.167% on Sept. 26, with the 30-year yield at 5.49%.
The Federal Reserve raised its benchmark rate to 3.75%–4% on September 16, its first hike in more than three years. Rieder called the moment “not a crisis, but an eye-opener.”
Rieder graded stocks a B-minus, lower than he had for a long time. He still likes chipmakers and memory storage, where he sees order backlogs. However, higher inflation-adjusted rates and slowing AI growth weigh on the rest of the market.
An income fund he runs yields 7.2% with an A-minus credit rating. It also holds bonds that mature or reset within three years, which limits losses if rates continue to rise. He has also sold some mortgage bonds, which lose value when rates climb.
Yields are already pushing mortgage rates to 7.45%. Rieder said the housing market is “frozen.”
What Another Fed Rate Hike Would Cost
Rieder argued the Fed should not be raising rates. Still, he expects one more hike. He warned it would inflate US debt costs.
“For every 100 basis points of move, it’s somewhere between 130 and 150 billion dollar cost to the US government,” he said in the interview.
One hundred basis points equals one percentage point.
Not everyone reads high yields as bad for stocks. Fundstrat’s Tom Lee argues rising yields favor strong companies.
Rieder added that when the 10-year starts at 5%, the next year’s bond return has averaged about 9.5%. Even so, he advised against rushing into it now. He pointed to strong growth, a war, and heavy new government borrowing.
He is now watching jobs reports for signs that US growth is slowing. BlackRock’s real-time tracking puts growth at 6.5% to 7%.
The post BlackRock CIO Dumps Stocks for High-Grade Bonds. Here’s Why appeared first on BeInCrypto.
Crypto World
Bitcoin (BTC), Nasdaq futures decline as Trump won’t rule out more Iran strikes
At the United Nations General Assembly, Iran proposed an agreement to reopen the Strait of Hormuz, a major oil chokepoint disrupted by the war, for a seven-day period and pause fighting, followed by broader negotiations on issues.
Trump, however, rejected the proposal, saying that Iran is looking for a deal because it was under heavy pressure. Trump also stressed on Truth Social that Iran “cannot have a nuclear weapon.”
This lingering geopolitical uncertainty has stoked inflation fears since the war began in early March, lifting Treasury yields. The 10-year yield has risen by 127 basis points to 5.20%, the highest since 2007, amid inflation fears, Fed rate-hike bets and debt concerns.
Bitcoin fell early this year, but has bounced back strongly in the third quarter, shrugging off these uncertainties. Prices are up 42% in three months, outperforming every major asset, including Nasdaq and gold.
Analysts are now watching incoming data for cues about the next move in the cryptocurrency.
“For investors, the 83,800-84,000 zone is an important near-term support. The 85,000-85,800 area is the immediate resistance zone. It would be prudent to avoid chasing the rally at current levels,” Vikram Subburaj, CEO of India-based Giottus exchange, said in an email.
Crypto World
China's Industrial Profits Slow to 4.2% Showing The AI Boom Left It Behind
China’s industrial profits grew 4.2% in August from a year earlier, official data showed Monday. Cumulative profit growth for the year has now slowed for a fourth straight month.
That cumulative pace peaked at 24.7% through April and has eased to 15.7% through August. Meanwhile, an AI-driven profit boom is lifting rival economies far faster.
The AI Boom China Missed
South Korea’s audited companies posted a record operating margin of 16.9% in the second quarter. That is up nearly 12 percentage points from a year earlier.
Manufacturing margins alone leaped almost fivefold, to 24.0%, driven by chipmakers riding the artificial intelligence memory wave.
Japan told a similar story. Corporate profits jumped 24.6% year-on-year in the second quarter, beating estimates comfortably.
Across the Pacific, US manufacturers saw after-tax profits climb to $370.1 billion in the second quarter. That is up from $225.8 billion a year earlier.
By contrast, China’s 4.2% barely registers as growth.
Europe Is the Exception
However, one major economy is struggling harder than Beijing. Eurozone industrial production fell 1.2% year-on-year in January and was flat by July.
The Eurozone’s manufacturing gauge hit a 44-month high in February, led by a German rebound. Germany’s own index returned to expansion for the first time in more than three years.
China’s factories are slowing down. Europe’s are barely moving at all.
What It Means
The split exposes a widening fault line in the global economy. AI hardware is minting profits in Seoul, Tokyo and Washington.
Beijing sits stuck in the middle. Brussels sits further behind.
The post China's Industrial Profits Slow to 4.2% Showing The AI Boom Left It Behind appeared first on BeInCrypto.
Crypto World
Trump-Xi summit analysis: ‘Tangible outcomes’ needed for U.S.-China truce to hold
U.S. President Donald Trump welcomes Chinese President Xi Jinping to speak during a state dinner in the East Room of the White House on September 24, 2026 in Washington, DC.
Kevin Dietsch | Getty Images News | Getty Images
BEIJING — In a summit dominated by spectacle, the U.S. and China have essentially agreed to keep talking.
President Donald Trump hosted Chinese President Xi Jinping in Washington, D.C., last Wednesday to Friday in Xi’s second state visit since 2015. Trump personally greeted Xi at the airport in a very rare gesture, and more than 100 people, mostly from U.S. government and businesses, attended a state dinner for Xi.
But there were few breakthroughs, including a far shorter-than-expected two-month trade truce extension.
“I’m concerned that this kind of diplomacy and this fragile detente is really unsustainable — if it doesn’t result in more tangible outcomes or in addressing in some way the strategic challenges that are clearly manifest across the entire relationship, from the strategic relationship to economics,” Daniel Kritenbrink, partner at consultancy The Asia Group, said Monday on CNBC’s “Squawk Box Asia.”
Statements from both countries following the summit agreed on only a handful of points.
Peter Alexander, Shanghai-based managing director of Z-ben Advisors, said he was surprised the two sides issued separate statements rather than a joint one.
It means “the two sides are truly locked in a battle seeking to determine where escalation dominance in the relationship resides,” Alexander said in a note Monday. He had expected Xi would not likely travel to the U.S. unless a joint statement had been agreed to in advance.

Here are major areas where the U.S. and China sent similar messages, according to their readouts released over the weekend:
First, Trump and Xi both intend to attend the APEC meeting in Shenzhen in November, and the G20 summit in Miami in December.
Second, the two countries agreed to hold an AI dialogue in the next two months, and establish a communication channel for AI incidents. But while the U.S. used the term “Super Intelligence,” China still referred to the technology as AI in its readout.
Third, both readouts pointed to how the U.S. and China were allies during World War II and “fought side by side to win the war.”
During the summit, the two presidents each referenced that cooperation in relation to Japan.
When welcoming Xi to the White House, Trump referenced the Flying Tigers, a group of American pilots that fought the Japanese in Myanmar and China in the early 1940s.
Xi’s dinner toast to Trump was more specific: “Over 80 years ago, the Chinese and American people stood shoulder to shoulder in a fight against Japanese militarist aggressors.”
Analysts from both the U.S. and China pointed out the historical reference also signaled broader efforts between the two countries to cooperate.
But a Chinese social media account called “Chairman Rabbit,” long seen as having insight into Beijing’s thinking, directly linked the World War II comments to Japan.
“If we were to say who the biggest loser was of this China-U.S. Summit in Washington, D.C., it would be the Sanae Takaichi government,” the account wrote in an article Saturday. That’s according to a CNBC translation of the Chinese.
Nearly a year ago, Takaichi drew Beijing’s ire by indicating an attempt to seize Taiwan by force could prompt Japan’s Self-Defense Forces to intervene. Beijing considers the independent, self-ruled island part of its territory. During the latest meeting with Trump, Xi urged the U.S. to oppose “Taiwan independence.”
Fourth, the U.S. and Chinese presidents signaled some alignment on limiting Iran’s nuclear weapon capabilities, and agreed “no country or institution can be allowed to impose tolls on international waterways.”
Fifth, both countries formalized Board of Trade and Board of Investment plans, and agreed to reduce tariffs on $30 billion worth of goods from the other.
China’s Commerce Ministry said Monday that this figure would include Chinese coal imports from the U.S., and noted plans for purchases in 2027 and 2028, without specifying an amount. The U.S. readout said each year would see Chinese imports of at least 10 million metric tons of coal.
The two countries also said they would establish a working group to discuss agricultural trade, with China’s Commerce Ministry specifying sector talks would start before the end of 2026.
Businesses will now watch the timeliness of implementation.
“Despite the red-carpet treatment and effusiveness of both Trump and Xi, the two sides’ fact sheets suggest how wary each is of the other,” said Scott Kennedy, senior advisor and trustee chair in Chinese business and economics at the U.S.-based think tank Center for Strategic and International Studies.
“The deliverables on trade, rare earths, refined oil, investment, and AI are all quite limited and tentative,” he said. “Although Taiwan was discussed, it did not find its way in either side’s official readout, suggesting no progress.”
China’s Commerce Ministry statement Monday also referenced plans to increase flights between the two countries, and open the financial sector to businesses from all countries, but did not elaborate.
On Sunday, Zoo Atlanta announced two giant pandas arrived from China, just days after Xi said Beijing was sending the bears.
Crypto World
Newsom Signs California Ban on Public Official Memecoins

The law also restricts crypto companies from offering certain memecoins tied to public officials to California residents and takes effect for tokens issued from Jan. 1, 2027.
Crypto World
Zano Rolls Back Blockchain by a Month After Exploit
Zano has rolled back approximately a month of blockchain history after a vulnerability involving Gateway Addresses allowed unauthorized ZANO and Freedom Dollar to enter circulation, according to its core team.
The Zano blockchain has been restarted at block 3,833,000, immediately before Hard Fork 6, which introduced the affected feature. The recovery requires participating nodes, miners, stakers, exchanges and other services to adopt the update, the team said Sunday.
The rollback invalidates a month of legitimate transactions along with the unauthorized tokens, meaning transactions made during that period will no longer appear on the recovered chain and may need to be reconciled. It also cannot reverse payments already settled on other blockchains. The team said it is working to account for any losses and will publish a reimbursement and claims process.
“Doing nothing meant unauthorized ZANO and fUSD in circulation without limit, diluting every holder and breaking the most basic promise a currency makes: a fixed supply,” said Zano’s head of marketing and growth Quinten van Welzen. “It would also tell every future attacker that exploited coins get to keep their value. No project survives that.”
Zano identifies Gateway Address exploit
Zano has not released a post-mortem at the time of publication, but confirmed the issue came from Gateway Addresses, a feature developed to make it easier for bridges, exchanges and payment services to integrate with Zano by letting them manage funds through a single account-style balance (similar to other blockchains).
Before Gateway Addresses, Zano’s ordinary wallets tracked funds as separate transaction outputs (UTXOs), rather than a single account balance. Exchanges and other services had to scan the blockchain to identify incoming payments, track those outputs and select which ones to spend when processing withdrawals.

Zano launched in May 2019 as a layer-1 blockchain focused on private payments. Its standard private transactions conceal senders, receivers, transferred amounts and asset types. While it has a native token, ZANO, the blockchain also allows users to deploy and mint custom digital assets. Freedom Dollar (fUSD) is one such token that operates on the Zano blockchain.
Related: Bitget CEO suspects North Korea behind $352M hack, citing IP clues
“Restarting the chain from before Hard Fork 6 costs a month of history, and it costs trust, which we’ll have to earn back,” said van Welzen.
“But it restores the supply everyone signed up for, and it leaves a path to rebuild. Which is better than 7 years of hard work left to die. We know it hurts. But not doing it would have hurt more.”
Magazine: THORChain under fire over Bitget, ETH evolves beyond blockchain: Hodler’s Digest
Crypto World
Falling Oil Could Trigger a 10% Stock Market Rally, Says Wall Street Strategist
Will the stock and crypto markets end 2026 with notable gains? The definitive answer likely depends on oil prices. It’s the biggest obstacle.
The US 10-year Treasury yield ended Friday at 5.17%, its highest level since 2007, after the Federal Reserve raised rates this month. This is usually bearish for the stock and crypto markets, as investors see Treasury bonds as the safer asset.
Yet Turtle Creek strategist David Spika believes the S&P 500 could still climb another 5% to 10% before year-end. His case starts with crude.
Will Oil Prices Go Down By December?
WTI oil closed Friday near $92, down sharply from levels above $100 earlier this month. Spika argues that if oil keeps falling, inflation pressure should ease with it.
That could drag long-term borrowing costs lower and give expensive stocks more room to run.
There are reasons for the retreat.
- Saudi Arabia has restarted its East-West pipeline, giving its crude another route around the Strait of Hormuz.
- Donald Trump also said US officials held a three-hour meeting with Iran’s delegation at the UN this week.
For markets, cheaper oil would arrive at a useful moment. On September 16, the Fed raised its benchmark rate by 25 basis points to 3.75%-4%, saying inflation remains elevated.
Spika thinks the 10-year Treasury yield could fall toward 4.75%-4.78% if oil prices continue to fall. That would ease one of the biggest pressures on equity valuations.
“I think stocks have in the 5 or 10% upside before year end,” Spika said, while warning earnings growth should slow next year.
His preferred names include Microsoft, whose Azure revenue grew 43% in its latest quarter, and Berkshire Hathaway, which held about $365.5 billion in cash and short-term Treasurys at the end of June.
The catch is oil can reverse quickly. Hormuz flows remain below pre-war levels, peace efforts remain uncertain, and investors are weighing more rate-hike risk.
Spika’s bullish call therefore rests on a fragile assumption: oil stays low enough, for long enough, to convince the bond market that inflation is losing another source of pressure.
The post Falling Oil Could Trigger a 10% Stock Market Rally, Says Wall Street Strategist appeared first on BeInCrypto.
Crypto World
THORChain Faces Scrutiny Over Bitget as Ethereum’s Role Expands
Cross-chain custody and censorship resistance collided with a high-profile breach narrative this week after Bitget publicly urged the decentralized liquidity protocol THORChain to block addresses allegedly tied to stolen funds. The dispute has reignited questions about what “decentralization” requires—and what it does not—when theft victims point to on-chain activity they believe is known to be malicious.
The push began after Bitget reported unauthorized transfers that it later revised upward, with the exchange attributing the suspected actor to North Korea based on preliminary investigative signals. In response, THORChain’s stance—whether it can meaningfully blacklist the relevant addresses, and whether it should—has become the center of an argument that is now spilling beyond technical governance and into the broader ethics of permissionless networks.
Key takeaways
- Bitget said unauthorized transfers rose from $351.6 million to $387.5 million, and later pointed to IP clues it believes link the activity to VPN infrastructure used by a North Korean hacking group.
- Bitget CEO Gracy Chen publicly asked THORChain to block addresses tied to the alleged theft connected to the Bybit-linked flow on THORChain.
- THORChain’s compliance position is unclear in practice because its ability to blacklist specific addresses has been questioned, including references to earlier admin-key changes.
- The debate is also exposing an asymmetry: decentralized funds may still be traceable after swaps, but protocols differ in whether they can or should exert address-level controls.
- While governance and security principles are at stake, THORChain has also faced criticism of its operational decentralization compared with networks like Bitcoin and Ethereum.
Bitget’s breach claims and the “block the addresses” demand
Bitget disclosed that it had detected “unauthorized transfers” tied to a security incident on September 25. According to Cointelegraph reporting, the exchange initially put the figure at $351.6 million, before updating it to $387.5 million. Bitget also stated that a preliminary investigation had linked IP addresses involved in the incident to VPN services associated with North Korean hacking operations, though the evidence was described as suggestive rather than definitive.
Bitget CEO Gracy Chen publicly argued that decentralized protocols should not serve as a destination for funds connected to theft. She said decentralization is a design principle, not a shield for facilitating known stolen assets, and urged THORChain to block addresses it believed were tied to the incident.
That framing matters because it reframes a typical “hack victim versus exchange” story into a “hack victim versus liquidity routing” story. If a stolen-flow path crosses a decentralized exchange-like venue, the conversation shifts from incident response alone to the network-level question of whether platforms can limit interaction with suspected addresses.
Why THORChain is at the center of the argument
As Bitget’s criticism spread, the broader context involved a prior major breach attributed to North Korean actors: the Bybit hack, reported by Cointelegraph as a $1.5 billion incident. Cointelegraph coverage also noted that funds from that attack were reportedly swapped on THORChain.
THORChain has often been described as a decentralized liquidity mechanism rather than a privacy mixer, and the general claim in the surrounding debate is that funds are still traceable after being swapped. That traceability is crucial: it gives victims and investigators a basis for arguing that specific on-chain participants should be restricted, even if the destination is a decentralized protocol.
However, what victims want—address-level blocking—may not align with how THORChain is technically or politically structured. The article notes that THORChain previously paused its chain quickly following its own $10.7 million hack in May. That detail highlights that the protocol can react decisively to security events, even as it faces scrutiny over whether it can selectively censor or restrict particular counterparties.
Can THORChain blacklist, and should it?
Whether THORChain can blacklist addresses is described as unclear in the reporting. The text points to a reference from February 2025, when THORChain said it had retired an admin key that would have provided the power to blacklist certain addresses.
This uncertainty is important for readers because it changes the nature of the request from “should a protocol do this?” to “can the protocol do this at all without undermining its own design?” Even if governance messaging supports compliance, protocol capabilities and key management can set hard boundaries on what is feasible.
Meanwhile, critics of address blocking argue that allowing decentralized protocols to respond to coercive demands would create a censorship precedent. The debate also includes an “ethics versus practicality” tension: victims emphasize harm reduction and reducing stolen-fund liquidity, while decentralization advocates emphasize permissionless access as an anti-tyranny safeguard.
At the same time, the article draws attention to concerns about THORChain’s decentralization level compared with Bitcoin or Ethereum. It cites the idea that THORChain does not match the governance model of the most decentralized networks and references past claims around administrative functionality. Those points are used to argue that the protocol’s permissionless claims may be overstated in practice.
For traders and builders, the operational reality is what matters most: if a protocol cannot enforce address-level exclusions, then users may still be exposed to flows they would rather avoid. If it can enforce them, then the network may face governance attacks, reputation risk, and the possibility of politically motivated address targeting. Either way, the outcome affects how participants assess risk and compliance expectations.
Market reaction and what to watch next
The controversy has not only sparked governance debate; it also appears to have attracted market attention. The article states that THORChain’s native token RUNE surged 50% over a week amid the publicity around the dispute.
Looking ahead, the key question is whether THORChain will clarify what address-level controls it can implement—if any—and what governance process would apply if requests from centralized exchanges are escalated. Readers should also watch how the underlying theft narrative evolves: Bitget’s attribution remains tied to preliminary investigation signals, and the strength of the evidence will influence whether future calls for restrictions gain wider traction.
In parallel, this episode underscores a broader industry challenge: even in decentralized systems, “who can stop stolen funds?” will increasingly depend on technical capabilities, governance choices, and the willingness of markets to treat permissionless routing as either a resilience feature or a liability.
Crypto World
THORChain Under Fire Over Bitget, ETH Evolves Beyond Blockchain: Hodler’s Digest
ThorChain under fire because it won’t blacklist stolen Bitget funds
Stop me if you’ve heard this before: A centralized exchange with lax security gets hacked by the North Koreans for $387.5 million, and then somehow shifts the blame game onto a decentralized exchange for not blacklisting the addresses.
The drama began on September 25 when the Asian focused exchange Bitget revealed $351.6 million in “unauthorized transfers” but it later upgraded the tally to $387.5 million. It said a preliminary investigation had linked the IP addressees to VPN services used by a North Korean hacking group.
While that isn’t firm proof, CEO Gracy Chen said its investigators had flagged other similarities with previous thefts.
North Korean hackers were believed to be behind the $1.5 billion Bybit exchange hack, and much of the funds from that attack were then swapped on the decentralized exchange THORChain (which is not a mixer and funds can still be traced after being swapped).
Chen then publicly called on THORChain to block the addresses linked to the attack. “Decentralization is a design principle, not a shield for facilitating known stolen funds,” she thundered. Thorchain politely said no chance, which has set off a massive debate over whether they can or should comply with Chen’s request. Decentralization maxis like Joel Valenzuela said doing so would undermine crypto’s cypherpunk ethos. “If we let decentralized protocols to be bullied into setting a censorship precedent, or make it toxic to interact with permissionless protocols, then we lose to tyranny. Full stop,” he said.
But THORChain isn’t as decentralized as Bitcoin or Ethereum, and it coordinated to quickly pause the chain when it got hacked for $10.7 million in May. “Thorchain is like 5 retards in a discord coordinating secret updates in between talking about the stolen funds they’re profiting from and lying about the admin functionality they abuse regularly to rug their users and NO’s,” said cybersecurity expert Tay Vano.
However THORChain’s ability to blacklist particular addresses is unclear. Back in February 2025 it revealed it had retired the admin key which would give it the power to do so.
All publicity is good publicity and THORChain’s native token RUNE has surged 50% in a week.

Where we’re going we won’t NEED blockchain says Vitalik
Ethereum creator Vitalik Buterin has rallied the troops with an inspiring post outlining how Ethereum is being rebuilt from the ground up to integrate zero knowledge proofs, parallel processing, privacy and post quantum technology to genuinely become “the cryptographic world computer.”
“It’s really not just a blockchain anymore. It’s a hybrid architecture that combines together blockchains and modern cryptography, to enable much more powerful properties,” he wrote, describing “an architecture that combines blockchains with cryptographic privacy and verification, and powerful decentralized off-chain components.” The Hegota fork, which is planned for next year, would likely Ethereum’s last “normal” fork he said.

Source: Brian Armstrong
Coinbase founder Brian Armstrong — a man who rarely utters the word “Ethereum” — reposted an analysis of the blog from a small account named “Cryptographic” said the analysis was “interesting.” Cryptographic summed up the thrust of Buterin’s post by saying it changed the whole meaning of “onchain” and meant Ethereum really was becoming a “world computer.”
“Instead of every part of an app having to execute inside a smart contract you can push a huge amount of complexity elsewhere and still inherit Ethereum’s guarantees.”
Aave founder Stani Kulechov made a similar point, arguing: “There are countless of use-cases where Ethereum verifiability would be useful beyond smart contact execution environment for finance to expand what we can actually do in DeFi while minimizing trust. Quite excited for the potential here.”
Crypto Mom retires, suggests ZK proofs for KYC
SEC Commissioner Hester Peirce has submitted her formal resignation from the US Securities and Exchange Commission, effective Oct. 2.
Peirce, affectionately known as “Crypto Mom” amid her advocacy of clear, rules-based regulation of the crypto industry, posted a copy of her resignation letter on her X account Friday.
Cointelegraph reported in May that Peirce planned to join the law school of Regent University in Virginia as an associate professor in November.
On her way out the door she criticized excessive KYC data storage, saying that storing IDs online created large numbers of databases vulnerable to hacks without improving enforcement. Instead, she advocated using zero knowledge proofs, which are able to verify eligibility without sending ID documents through. “One can prove that you qualify without that counterparty knowing your name, income, or address,” she said.
Magazine covered this very subject earlier this month.
Open AI called for Australian Senate inquiry following rogue AI hack
The CEOs of OpenAI and Anthropic have reportedly been summoned to appear at an Australian Senate inquiry into AI, just days after news broke that a rogue OpenAI bot had hacked the country’s health data.
The Australian Medicare breach is one of the highest-profile incidents of AI agents accessing external systems outside the US, according to a Sunday Business World report.
Cointelegraph reported last Thursday that the OpenAI research agent had bypassed blocks on the Australian government health data portal and accessed non-public files in June. It somehow didn’t get around telling the Australians until September 10.

Michael Saylor outlines ‘bill of digital rights’
Michael Saylor, co-founder of Strategy, said that an age of digital assets and intelligence needs a “bill of digital rights,” rather than restrictions.
These rights include (1) the freedom to create new digital assets and (2) to issue them to the market to finance business and productivity. They also include (3) the right to hold them or choose a custodian, as well as (4) to transfer them, to move the assets among people, companies, wallets and service providers. Finally, (5) to use them, to spend, invest, earn income and borrow against digital assets.
This week the Strategy board announced it would seek shareholder approval to move its four preferred stocks, including STRC, to daily dividend payments without changing their dividend rates or the total amount paid.

Winners and Losers
At the end of the week, Bitcoin (BTC) is up 3.8% to trade at $84,222, Ethereum (ETH) is up 3.7% to trade at $2,674 and XRP (XRP) is up 7% to $1.50. The total market cap is at $2.88 trillion according to CoinMarketCap.
Among the biggest 100 cryptocurrencies, the top three altcoin winners of the week are Quant (QNT) with a 435% gain, Sei (SEI) on 44%, and Artificial Superintelligence Alliance (FED) on 41%.
The top three altcoin losers of the week are Falcon Finance (FF) which was down 25.3%, MemeCore (M) down 20.3% and Avalanche (AVAX) down 4.5%.
Top Prediction of the Week
Bitwise says NEAR could be headed to $562
Bitwise’s new NEAR ETF is about to launch, and its chief investment officer Matt Houghan has jumped into promotion duties by co-authoring some of the most optimistic predictions you’re likely to see this month. The new fund, called the Bitwise NEAR ETF, is expected to list on NYSE Arca under the ticker NRR.
Bitwise’s 39-page investment report NEAR states the “base case” is a price target of $155 by 2030 while the bull case is $562. The bearish case suggests a price of $1.63.
Last week Near Protocol’s native token surged 80% to be the top performer in the Top 100. The surge came after Near unveiled private Hyperliquid perps trading.
Top FUD of the Week
Kalshi loses appeal, setting up potential Supreme Court case
Prediction market Kalshi lost on appeal when a court ruled that Ohio and Tennessee can regulate sports-event contracts under their state gambling laws.
The ruling followed a similar finding from the 9th Circuit Court of Appeals last month, which broke from an April decision by the 3rd Circuit Court of Appeals allowing the company to do business in New Jersey as its appeal process proceeds.
The April ruling said Kalshi was likely to succeed with its argument that federal law preempts New Jersey’s regulations, all of which has set up a potential Supreme Court case.
Tether says it had ‘limited’ exposure to bank linked to $84M US seizure
Stablecoin issuer Tether said that it had a very small amount of assets at a bank that had $84 million in assets frozen by US prosecutors.
In response to reports linking Tether and Bitfinex to a Montana-based payments business named in a civil forfeiture complaint, a company spokesperson told Cointelegraph that it had “no knowledge” of any of the alleged conduct. Tether confirmed it was a customer of EQIBank, but the amount held at the bank represented 0.034% of the group’s total assets.
Magic Eden scare puts 3,832 NFTs in whitehat protective custody
A whitehat moved 3,832 non-fungible tokens from hundreds of wallets on Friday amid concerns about a vulnerability involving NFT marketplace Magic Eden.
NFT community member who goes by Cirrus on X flagged the activity on Friday, saying a single wallet moved 3,832 NFTs from hundreds of wallets. Cirrus said the transactions appeared as sales through Magic Eden and advised NFT holders to revoke permissions as a precaution.
Shortly afterward, Yuga Labs’ pseudonymous vice president of blockchain, 0xQuit, said the transfers were part of a white-hat operation. He said the NFTs held in the receiving wallet are safe and “will be returned once they are no longer at risk.”
Top Magazine Features of the Week
The SEC has opened a five-year path for tokenized stocks, but only some products and venues fit the model. Will Uniswap, Robinhood, Coinbase or Kraken come out on top?

The IRS can now see your crypto gains, but has no idea about the cost-basis. That’s proving to be a big headache for some cryptocurrency investors.
The APAC region accounts for half of the Global Crypto Adoption Index. Bitget suffers massive $352M loss and OpenAI forgets to mention its agents hacked the Australian Government.
Cointelegraph publishes long-form journalism, analysis and narrative reporting produced by Cointelegraph’s in-house editorial team with subject-matter expertise. All articles are edited and reviewed by Cointelegraph editors in line with our editorial standards. Some articles contain affiliate links, from which Cointelegraph may earn a commission. These relationships do not influence which products we review or our editorial conclusions. Content published in here does not constitute financial, legal or investment advice. Readers should conduct their own research and consult qualified professionals where appropriate. Cointelegraph maintains full editorial independence.
-
Fashion2 days agoWeekend Open Thread: J.McLaughlin – Corporette.com
-
Crypto World5 days agoGoldman Sachs and Deutsche Bank Agree: The S&P 500 Rally Isn't Over
-
Fashion4 days ago8 iPhone Accessories That Add Personality
-
Entertainment5 days agoThese 17 Fall Amazon Dresses Seriously Look Like Anthropologie
-
Tech5 days agoReolink’s solar 4K security camera falls to its lowest price in months
-
Crypto World5 days agoThis Bearish Netflix Stock Trade Can Cash In On Video Streaming Giant’s Woes
-
Crypto World6 days agoTrump-Xi Polymarket Odds for Handshake Hit 50%
-
Tech7 days agoGoogle’s $899 Googlebook is a bet that you’ll buy a new laptop for Gemini
-
Crypto World4 days agoCrude Oil Prices Pressured by Diplomatic Hopes in the Middle East
-
Business5 days agoOil Price Today (September 23): Crude oil below $100 on hopes of US-Iran talks. What did Trump say?
-
Crypto World4 days agoBitcoin price tests $83,600 Supertrend support after $87K rejection
-
Crypto World4 days agoBitcoin Threatens Sub-$84,000 Breakdown as Long Liquidations Spike
-
Crypto World5 days agoBitGo says Bitcoin absorbed Fed hike, CLARITY failure
-
Crypto World6 days agoMeta Jumps 11% As Muse Shines and Investors Show an Appetite for Advancing AI
-
Crypto World5 days agoDid Jim Cramer Just Give GameStop Stock the Kiss of Death When He Said the Turnaround Is Working?
-
Crypto World7 days agoBitcoin price holds above $81K as key catalysts line up
-
Crypto World6 days agoTrump, Xi Meet on S&P 500's Best Day Since Early August: Will Markets Stay Bullish?
-
Tech4 days agoUiPath’s Dines says AI needs a manual and launches Cartographer to write it
-
Tech7 days agoAmazon blocks Meta’s Muse AI assistant in new standoff over agentic shopping
-
Crypto World7 days agoStrategy Adds 950 BTC for $76M, Funds $174M STRC Buyback

You must be logged in to post a comment Login