GCP Exclusive Reporting

10/cate3/GCP Exclusive Reporting

Featured Startups

5/cate1/icos

exchanges

6/cate2/exchanges

videos

6/cate3/videos

regulations

5/cate1/regulations

Now Playing:

3/cate6/videos

Recent post

MetaMask Yanks 17,000 Ethereum Validators Offline After a "Pocket Change" Sized Theft...


An attacker walked off with roughly 0.36 ETH - worth less than a thousand dollars - from MetaMask's Ethereum staking operation. The response? MetaMask yanked roughly 17,000 validators holding about 523,000 ETH, worth around $1.4 billion at current prices, off the network. The ratio of damage done to damage prevented is, to put it mildly, not 1:1.

The incident started on September 30, 2026, when MetaMask disclosed what it called "an ongoing security incident affecting part of our infrastructure." The company was quick to stress it had found no immediate threat to MetaMask wallets. The issue was confined to MetaMask Staking, the validator business formerly known as Consensys Staking, which runs Ethereum validators for Lido, Coinbase, and its own pooled staking product.

What Actually Got Stolen

Not much, is the honest answer. According to on-chain analysis by security researcher 0xKaden and a detailed investigation by Bitquery, the attacker changed the fee-recipient address on about 18 of 19 MetaMask-operated validators that had earned block rewards on September 30. For roughly four and a half hours, between 12:12 and 16:46 UTC, block tips - the extra fees users pay to get transactions included in a block - were redirected to a wallet funded through Tornado Cash.

The total haul: 0.36 ETH. About $950. The wallet, which received 0.1 ETH from Tornado Cash at 10:27 UTC that morning, hadn't moved by the next day. No validator stake was taken. No slashing occurred. The attacker couldn't reach the staked ETH itself, because withdrawal credentials are controlled by the clients, not by MetaMask's staking infrastructure.

So why the massive response? Because the attacker had access to the machines that sign blocks and set fee addresses. That means the signing keys may have been exposed. A signing key can't be rotated - the only fix is to exit the validator entirely and start fresh with a new key. MetaMask began pulling validators before the first tip was even diverted, which suggests they spotted something suspicious early and decided the nuclear option was the safe one.

The Chain Reaction

The exits hit Ethereum's staking queue hard. The withdrawal queue jumped from about 200,000 ETH to over 700,000 ETH in a single day, pushing wait times from three and a half days to nearly two weeks. Lido, whose stETH token is backed by validators MetaMask operates, told stETH holders that the last affected validator would exit by October 7. The full cycle - exit, withdraw, redeposit under fresh keys, and re-enter the activation queue - could take up to 45 days, during which that ETH earns nothing.

For Lido stakers, the real cost isn't stolen funds. It's lost time. About 0.19 ETH in tips from 11 Lido-set blocks went to the intruder instead of Lido's rewards vault. Lido's reserve of 6,750 stETH would have covered a worst-case slashing scenario for its own validators. But had every MetaMask-run validator been slashed simultaneously - which didn't happen - about 22,000 ETH would have burned, exceeding Lido's reserve. The system dodged a much bigger bullet.

A Troubling Backdrop

This isn't happening in a vacuum. Back in July, Drop Site News reported that Consensys - MetaMask's parent company, before it rebranded - had unknowingly hired a software developer linked to North Korea as a consultant for about a month. There's no evidence connecting that incident to the September 30 staking breach. But the Tornado Cash funding, the KuCoin routing, and the quiet professionalism of the attack are enough to make anyone in staking infrastructure a little nervous.

It's also not the first time a staking provider has had to pull validators over a suspected compromise. Kiln, a competing operator, exited all its active validators last September after a $41 million loss in its SOL staking operations, rotating signing keys and treating related infrastructure as potentially compromised. The pattern is becoming familiar: a small breach, a large precautionary response, and a lot of questions about how keys are stored and who can reach them.

MetaMask hasn't publicly explained how the attacker got in, whether signing keys were actually compromised, or which specific infrastructure component was targeted. The company said it's working with external security partners and has not provided further details. For the thousands of stakers whose ETH is now sitting in an exit queue, the silence is not exactly reassuring.

The takeaway for anyone staking ETH through a provider: your principal is probably safe if the provider doesn't control withdrawal keys. But your rewards, your uptime, and your patience are all on the line when something goes wrong. A $950 theft triggered a $1.4 billion validator exodus and a two-week bottleneck for withdrawals. The math is absurd, but the logic is sound. In staking, a compromised signing key isn't a small problem - it's a reason to burn everything down and start over.

---------------

Author: Dorian Fenwick
Silicon Valley Newsroom
Breaking Crypto News

Bitwise Launches NEAR ETF, With 33% of Staking Rewards Going to Fees...

Glowing validator nodes send staking rewards into a transparent investment vault

Bitwise's new NEAR fund brings staking to brokerage accounts, but a third of the rewards is earmarked for fees.

The Bitwise NEAR ETF launched on NYSE Arca on September 29, 2026, under the ticker NRR. Bitwise describes it as the first spot NEAR exchange-traded product in the United States. Its launch announcement highlights network staking rewards of roughly 5%. Investors comparing that figure with the fund's 0.75% annual management fee need to account for a separate charge on the staking rewards themselves.

The prospectus, dated September 24, assigns 33% of the additional NEAR generated by staking to staking expenses. Those fees are shared among the staking agents, the custodian and the sponsor. The trust keeps approximately 67% of the staking rewards. That split does not replace the annual management fee. It means a headline network reward rate cannot be read as the return an NRR shareholder will receive.

How the staking arithmetic changes

A simple illustration shows the difference. If the gross staking rate stayed at exactly 5%, retaining 67% would leave 3.35% before the management fee. Subtracting 0.75 percentage points gives roughly 2.60%, assuming the entire holding stayed staked for a year and ignoring compounding, other costs and token-price changes. That is an illustration of the fee arithmetic, not a forecast or a quoted fund yield. Actual results depend on how much NEAR is staked, the rewards earned and the value of those tokens.

Bitwise's approximately 5% figure is an annualized network rate measured as of September 25. The company says rewards accrue through the fund's net asset value per share, so the figure should not be mistaken for a promised cash payout. Its stated plan is to use its institutional staking team. The announcement does not establish a full year's realized results for this newly launched product. A lower NEAR price can also outweigh the value of additional tokens earned through staking.

The AI pitch still needs to deliver

Bitwise is marketing NEAR as infrastructure for an economy in which AI agents make payments and coordinate transactions. The fund gives brokerage investors another route to express that investment view. It does not establish how much future business those agents will bring to the network. Nor does an exchange listing turn expectations about AI adoption into earnings for token holders. The investment case still depends on demand for NEAR, while the fees apply regardless of whether the AI story delivers.

For traders, the practical comparison is the convenience of holding fund shares against the cost and responsibilities of holding and staking tokens directly. NRR's shares can trade above or below the value of the assets they represent. The product also lacks the same protections as funds registered under the Investment Company Act of 1940. As trading develops, watch the bid-ask spread and the fund's reported staking participation alongside the management fee. The useful number is the reward that actually reaches the fund after costs, considered together with NEAR's price performance.

---------------

Author: Dorian Fenwick
Silicon Valley Newsroom
Breaking Crypto News

Your Next Bitcoin Payment Could Come From an AI Agent - Block Adds Lightning to x402

Glowing AI core sending payments through a lightning network

Block wants Bitcoin to handle the tiny payments AI agents make while getting things done online.

The company announced on September 24 that it had joined the x402 Foundation and contributed Lightning payments to the protocol. Its announcement puts Bitcoin into an open standard for software that can request and pay for services. Block sees fast, inexpensive transactions as essential to that market. The development gives Bitcoin holders a practical adoption story to follow beyond the next price target.

The proposed customer is often a program acting for a person or business. Think of an agent paying for a piece of data it needs to complete a task. The payment could happen within its interaction with the service, without a person stepping through a checkout each time. That is the kind of repeated, small transaction Block is targeting. It is also a very different use of Bitcoin from parking a large balance in a treasury.

A payment request built into the web

The standard uses HTTP 402, the web's Payment Required response. A service receiving an unpaid request can return instructions for payment. The client pays and retries, allowing the service to deliver the requested resource. The x402 project describes applications including paid API access and digital content. Developers can support multiple networks or payment schemes through the same framework.

That flexibility is part of the significance of Lightning joining. The standard is designed to work across currencies and networks, under Linux Foundation governance. Block's contribution adds another way to settle payments inside it. Businesses still need to build services that accept the method, and users need software capable of paying that way. A supported payment option only becomes useful when the two sides actually meet.

The demand still has to show up

At the time of review on September 25, x402's website displayed 75.41 million transactions and $24.24 million in volume for the previous 30 days. Those are figures for the overall protocol. They cannot be counted as activity generated by Block's new Lightning contribution. Block's announcement did not provide a separate Lightning transaction total or a consumer-product rollout date. It would be premature to treat its participation as evidence that millions of agents are already spending bitcoin through the integration.

Block says it will keep contributing to Lightning support and the foundation's working groups. It also plans further tools for agent-driven commerce. The useful test now is whether developers turn that work into services people repeatedly use. Watch for named deployments and payment activity that can actually be attributed to Lightning. The technology has a new route to customers; sustained use will tell us how much that route matters.

---------------

Author: Dorian Fenwick
Silicon Valley Newsroom
Breaking Crypto News

Bitget Raises Hack Estimate to $387.5 Million, Withdraws Still Suspended for All Users...

Fractured exchange vault with glowing reserves shield

Bitget's hack just got more expensive, and customers are still waiting for a withdrawal update.

The exchange raised its estimate to $387.5 million in a September 25 update, replacing the earlier $351.6 million figure. It attributed the difference to previously uncounted Zcash and TRON transfers. Bitget said the revision reflects better accounting of the original incident, not another attack. That distinction matters when an already substantial loss grows overnight.

The original alarm came at 18:31 UTC on September 24, according to Bitget's security notice. The company said only part of its hot and warm wallet infrastructure was affected and its cold wallets remained secure. It paused withdrawals while keeping deposits and trading open. Bitget also said account balances remained accurate. Customers therefore face a separation between what their accounts show and their ability to move those assets elsewhere.

The investigation points beyond stolen keys

CEO Gracy Chen has described a compromise of a backend wallet service, according to Cointelegraph. Her account was that attackers forged transfer information and triggered the authorization-signing process. She said the preliminary investigation did not point to leaked private keys. That would put the weakness in the systems instructing transfers, rather than possession of the keys alone. A complete technical explanation is still important before treating that account as the final root-cause finding.

Chen also raised the possibility of North Korean involvement, citing IP and VPN patterns resembling those associated with a North Korean group. That is a preliminary attribution by the exchange's chief executive. It should not be presented as an independently established identity for the attacker. Mandiant and SlowMist are assisting the investigation, Bitget said. For affected customers, identifying the perpetrators and restoring access are separate problems, even when both are being worked on at once.

A coverage promise still needs an operational recovery

Bitget's original notice said its User Protection Fund held more than $464 million and covered the incident. That was the exchange's assurance about its own resources. It does not mean the stolen assets have already been returned. The September 25 update says some funds have been frozen and introduces conditional 5% bounties for eligible freezing or recovery work. Freezing funds and returning them to the exchange are different stages of that process.

Bitget says it has fixed the vulnerability and is validating security before restoring withdrawals. It promises an announcement about withdrawal status or timing by September 26 at 04:00 UTC. That is a deadline for information, not a guaranteed reopening time. The next useful evidence is a clear service update followed by withdrawals actually working again. Until then, the larger loss estimate and the coverage pledge should be read alongside the access restrictions customers still face.

---------------

Author: Ren Nakamura
Asia Newsroom
Breaking Crypto News

SEC Opens a Five-Year Door to Onchain Stock Trading - But Companies Can Say No

A stock exchange opens into a glowing blockchain portal

Wall Street shares are getting a new route onto crypto trading infrastructure, but the companies behind those shares still get a say.

The SEC issued its Innovation Exemption on September 17, giving qualifying venues a temporary path to trade tokenized U.S. stocks through automated market makers and liquidity pools. Its announcement sets a five-year expiry after publication. The relief covers specified exchange and dealer requirements, subject to conditions. For crypto traders, the immediate significance is a defined framework for bringing familiar stock exposure into an onchain trading environment.

The SEC calls the operators Tokenized Securities Venues, or TSVs. They provide the pools and decide who can access trading. Commissioner Hester Peirce said the exemptions are available to U.S. persons, including established businesses and newcomers. She described the move as an interim step that will help regulators observe how blockchain markets and traditional markets interact. Her statement also makes clear that this framework addresses one particular trading model, leaving room for other approaches.

A stock token has to come with shareholder rights

The venues must verify that qualifying tokens give holders the same rights and privileges as the equivalent traditional shares. That matters because a token tracking a share price can sound deceptively similar to owning the share itself. The SEC's order excludes third-party securities that merely provide synthetic exposure to another security. It also prohibits primary issuance and initial offerings on these venues under this exemption. Traders will need to look at what a product actually represents before treating a familiar ticker as proof of ownership.

Companies also have a way to refuse certain listings. If a token was created by an unaffiliated third party, the venue must notify the underlying stock's issuer and wait at least 30 calendar days after receipt. A written objection delivered within that window prevents the venue from making that token available for trading. Separately, a venue must publish its own operational notice at least 30 calendar days before starting. Those waiting periods mean the announcement does not translate into an instant menu of every U.S. stock in your wallet.

Public blockchains, controlled access

The design combines public infrastructure with permissioned trading. Smart contracts must be public and auditable, and operate on a public, permissionless distributed ledger. The venues still set entry standards for participants using their pools. They must also stop trading a tokenized stock when its underlying stock is halted or suspended on the primary listing exchange. Moving the trade onchain does not make those market stoppages disappear.

Commissioner Mark Uyeda highlighted limits on the number of symbols and trading volume, along with public transaction data intended to make activity easier to monitor. He said the framework would give the agency practical evidence for future policymaking. That leaves a concrete test for the businesses pursuing this market: attract usable liquidity while meeting the conditions. For readers, the next developments worth watching are actual venue notices and the stocks those venues can support. The SEC has supplied a route forward; which shares become available, and how well they trade, will determine how useful it is.

---------------

Author: Cedric Holloway
New York Newsroom
Breaking Crypto News

Your Old Email Password Could Unlock Your Crypto Account, Police Warn

Glowing email envelope and fractured lock connected to a cryptocurrency vault

The password you reused years ago could give someone a route into your crypto account today.

Singapore police warned on September 12 that they have seen an increase in unauthorised access to cryptocurrency accounts through compromised email since mid-August, according to CNA. Investigators found that several affected email accounts had appeared in earlier data breaches on other platforms. Police said exposed credentials and password reuse may have helped attackers gain access. The warning concerns account takeovers, and does not establish that an exchange's own systems were breached.

Once inside an inbox, attackers may be able to work out which crypto services its owner uses. Police described the possibility of password-reset requests followed by interception of reset links, verification messages or one-time passwords delivered by email. They also warned that intruders may alter inbox rules to hide exchange messages by forwarding, archiving or deleting them. That makes a quiet inbox a poor substitute for checking the account itself. A notification cannot warn you if someone has arranged for you never to see it.

The inbox deserves the same attention as the exchange

The practical issue is how much authority your email account has over your other accounts. If it receives recovery links, access to that mailbox can become part of the route to changing a login. Reusing a password creates another connection between services that might otherwise have little to do with each other. An old breach at one website can therefore remain relevant long after you stopped using that website. The police's wording leaves room for differences between individual cases, so this should not be read as a claim that every exchange can be unlocked with email alone.

The warning follows a separate August 21 police advisory about criminals allegedly impersonating Apple support to steal cryptocurrency. In that scheme, police said victims were directed to fraudulent websites and asked for login details and one-time passwords. The reported sequence included unexpected device prompts and unsolicited calls claiming that an account was compromised. Police recorded at least five cases after August 7 in that earlier warning. Those were separate incidents, but they illustrate why an urgent offer to secure an account also needs checking through the provider's official channels.

Check the settings that can hide a takeover

For the latest warning, police recommended unique passwords and multi-factor authentication, with an authenticator app preferred over SMS where available. Their advice also included reviewing email forwarding rules and suspicious login activity. Crypto users were urged to inspect transaction history and enable activity alerts where supported. That review needs to include the mailbox receiving those alerts. Security settings on the exchange are only part of the picture when account recovery depends on another service.

Anyone who suspects a compromise should contact both the email provider and the crypto exchange promptly, police said, asking them to secure or freeze affected accounts where possible. Password changes should cover the affected accounts and other services where the same password was used. A suspicious login or unexplained forwarding rule deserves attention even before you spot an unfamiliar withdrawal. The useful response to this warning is to check your recovery route while you still control it. Start with the inbox that receives your exchange emails.

---------------

Author: Ren Nakamura
Asia Newsroom
Breaking Crypto News

NASDAQ Bets $100 Million on Kraken's Parent as Tokenized Stocks Target 2027...

Glowing bridge connecting traditional financial markets with tokenized equity networks

Nasdaq is putting $100 million behind Kraken's parent company, with tokenized stock trading on the agenda for 2027.

The exchange operator announced the investment agreement with Payward on September 10. Its venture arm will make the investment as the companies expand an existing partnership. Their Nasdaq Equity Tokens, or NETs, are expected to launch in the second quarter of next year. For traders accustomed to crypto markets that never close, the attraction is easy to understand: bringing more of that flexibility to stocks.

The companies still have work to do before that becomes a product traders can use. Nasdaq's announcement describes an agreement to invest and an expected launch date. It does not announce that NET trading has opened today. The distinction matters when a headline combines a familiar Wall Street name with a large dollar figure. A development timetable is useful information, but it is not a completed rollout.

A bigger role for Kraken's parent

The deal values Payward at $21 billion, according to Bloomberg reporting cited by CNBC. That figure is a reported valuation of the company, separate from Nasdaq's $100 million investment. CNBC places the agreement within Kraken's expansion into a broader platform spanning traditional financial products as well as crypto. The distinction is relevant to readers who see every institutional crypto headline as a fresh purchase of Bitcoin. This transaction concerns an ownership investment in a business building trading infrastructure.

The partnership also reaches the systems used to monitor trading. Payward plans to adopt Nasdaq's surveillance technology across its venues, covering crypto and traditional asset markets. Surveillance is less glamorous than a new token launch, but it is part of how venues look for suspicious activity. Adding technology does not, by itself, establish that misconduct cannot happen. Customers will still need to judge the venues and products they use on their actual operation.

What will the token actually give you?

One issue deserves as much attention as the launch date: the rights attached to the token. CNBC describes a wider dispute over tokenized stocks, including a clash between Robinhood and AMC over products referencing AMC shares. Economic exposure to a share price and shareholder rights are different questions. Nasdaq says its framework is designed to preserve protections for issuers and investors. Readers should check the eventual product terms rather than assume that every instrument called a tokenized stock works the same way.

For now, the concrete development is a major exchange operator committing capital to its partnership with a crypto company. The commercial opportunity depends on turning that relationship into a service people can actually access and use. The next useful details will concern launch availability and the terms offered to customers. Traders should also look for clear explanations of how ownership and settlement work in the finished product. The second quarter of 2027 is the milestone to watch, with delivery still ahead.

---------------

Author: Cedric Holloway
New York Newsroom
Breaking Crypto News