Category: Coins

Digital assets, cryptocurrencies, blockchain, and currency news.

  • Ethereum Trader 0x6910 Nets $201K Profit on $STANDARD

    Ethereum Trader 0x6910 Nets $201K Profit on $STANDARD

    Crypto Trader 0x6910 Nets $201K Profit on $STANDARD Token in One Hour

    An Ethereum trader identified by the wallet address 0x6910 has captured market attention after securing a $201,000 profit on the $STANDARD token within a single hour. The rapid trade, first highlighted by on-chain analyst @lookonchain, underscores the high-speed profit potential — and inherent risk — present in the current cryptocurrency landscape.

    Inside the Trade: 80 ETH to 160 ETH in 60 Minutes

    According to on-chain data, the transaction unfolded as follows:

    • Entry: 0x6910 spent 80 ETH to acquire 1.14 million $STANDARD tokens.
    • Exit: The same tokens were sold shortly after for 160 ETH.
    • Net Profit: 80 ETH (approximately $201K at current valuations).
    • Timeframe: The entire round trip was completed within one hour.

    This sequence illustrates how certain traders are exploiting short-term price volatility in newer Ethereum-based tokens. $STANDARD, which has been gaining traction among Ethereum enthusiasts, served as the vehicle for this exceptionally fast flip.

    Ethereum’s Role as a High-Velocity Trading Layer

    The trade reinforces Ethereum’s standing as the primary settlement layer for rapid, high-value token swaps. Despite subdued overall trading volume across broader crypto markets, individual opportunities like this continue to surface, drawing attention to the dynamic nature of on-chain activity.

    As more participants leverage Ethereum for near-instant execution, the ecosystem’s utility for speculative trading deepens — even amid mixed macro signals.

    What Market Watchers Are Monitoring Next

    Analysts and traders are now tracking $STANDARD’s liquidity depth and short-term volume trends to gauge whether this move signals sustained interest or an isolated spike. The visibility of such wins may attract additional speculative flow, potentially increasing near-term volatility for the token and similar low-cap assets.

    Both new and veteran participants are likely to watch for follow-through, as quick-profit patterns often precede clustered entry attempts that can amplify price swings.


    Disclaimer: The information provided is for educational purposes only and should not be considered financial advice.

  • Revolut Hackers Publish Client Data and Demand 10,000 Bitcoin Ransom

    Revolut Hackers Publish Client Data and Demand 10,000 Bitcoin Ransom

    Attackers who tricked Revolut into handing over customer records published the data of high-profile clients over the weekend and demanded a ransom of 10,000 Bitcoin, warning on September 14 that they would leak more each day until the European fintech pays.

    Revolut Confirms Sophisticated Impersonation Attack

    Revolut confirmed on September 12 that an unauthorized party had impersonated a government agency, sending fraudulent requests for information from an email on the agency’s real domain with valid technical authentication, which staff processed as a routine legal request.

    Scope of the Data Breach

    As CryptoPotato covered, the data breach included the disclosure of passports, verification selfies, account statements and IBANs, alongside names, dates of birth and home addresses. A Revolut spokesperson said the company recently identified a sophisticated external impersonation scam where an unauthorized third party utilized a legitimate government agency domain email to submit fraudulent requests for information.

    The group calling itself Revolut Smilik posted client files across several Telegram channels and warned it would start releasing more and more data every day until Revolut pays for leaking their customers.

    High-Profile Targets and Ransom Valuation

    The posted material appeared to include data on high-profile individuals, among them company executives, sports professionals, and performing artists, according to The Register, which put the 10,000 Bitcoin demand at more than $782 million. Revolut declined to comment on the ransom.

    Company Response and Regulatory Notification

    The company said it blocked the address on detection and alerted the relevant government agency, law enforcement, data protection and financial regulators, and that its systems and customer funds were unaffected. Revolut said a limited number of customers were affected and that it had contacted them directly, without disclosing a figure or naming the compromised agency.

    The company had earlier said the affected customers’ biometric facial data was not compromised. On-chain investigator ZachXBT, who flagged the incident, said it appeared limited in size and concentrated on high-net-worth users, an assessment neither Revolut nor independent parties have confirmed.

    Stolen Records Heighten Phishing Risk for Crypto Holders

    Revolut lets customers buy and sell more than 90 cryptocurrencies, and the stolen files included some clients’ full Bitcoin transaction histories. Similar leaks have fed targeted scams against crypto holders.

    CryptoPotato documented how criminals used leaked order data to send Ledger owners convincing phishing emails after a separate breach, using a bogus Ledger-Trezor merger to lure them to a fake site that harvested recovery phrases.

    The Revolut demand is yet another breach that turned customer data into leverage against crypto firms, just like it happened to Coinbase when a ransom demand forced the exchange to disclose a breach affecting more than 69,000 customers, exposed after overseas support agents were bribed to hand over their records.

  • US DOJ Seeks $61 Million Over Iran’s Alleged Crypto-Laundered Black Market Oil Sales

    US DOJ Seeks $61 Million Over Iran’s Alleged Crypto-Laundered Black Market Oil Sales

    The legal action unfolds against a backdrop of intensifying missile warfare between Iran and the United States that began in February. The conflict has severely disrupted global oil flows and triggered a sharp surge in energy prices worldwide. Iran’s own crude exports have plummeted under a strict U.S. naval blockade and regional hostilities around the Strait of Hormuz. In response, Tehran has reportedly turned to cryptocurrency to circumvent the blockade and maintain trade channels.

    DOJ Uncovers $1.5 Billion Crypto Pipeline for Iranian Oil Revenue

    According to a Department of Justice statement, prosecutors identified a massive underground financial pipeline, internally dubbed “Entity A”, that moved black-market Iranian oil proceeds through a complex web of unhosted cryptocurrency wallets. Because unhosted wallets store digital assets outside centralized exchanges or third-party custodians, they function much like stashing physical cash in a private residence to prevent authorities from freezing the funds.

    This network transferred massive sums of illicit cash directly to an Iranian crypto exchange, as well as to digital wallets and businesses tied to the Islamic Revolutionary Guard Corps (IRGC).

    Chinese Firms Allegedly Facilitated Multi-Million Dollar Transfers via Binance

    Two Chinese companies, Blessed Trust and Hexa Whale, allegedly acted as the primary facilitators coordinating the vast majority of these multi-million dollar transfers. According to the DOJ statement, both firms used trading accounts on Binance to launder the black-market oil proceeds before funneling the funds back to the Iranian government and its proxies.

  • Strive Acquires 469 Bitcoin, Lifting Treasury to 25,000 BTC

    Strive Acquires 469 Bitcoin, Lifting Treasury to 25,000 BTC

    Strive Adds 469 Bitcoin to Treasury, Holdings Reach 25,000 BTC

    Strive, Inc. (Nasdaq: ASST) acquired 469 bitcoin at an average price of approximately $77,954 per coin between September 8 and September 11, bringing its total corporate treasury to 25,000 BTC, according to a Form 8-K filed with the U.S. Securities and Exchange Commission on September 14. At the stated average price, the purchase represents roughly $36.6 million, inclusive of fees and expenses.

    The Purchase

    In the current report filed under Item 8.01, the Dallas-based asset-management and structured-finance firm disclosed that its bitcoin holdings increased from 24,531 coins as of September 4 to 25,000 as of September 11, a net increase of 469. The acquisition was reported alongside an update to cash and cash equivalents, which stood at approximately $204.2 million as of September 11. Strive, incorporated in Nevada and headquartered in Dallas, Texas, reports its bitcoin position in periodic SEC filings, signaling the asset’s growing weight on its balance sheet. The 8-K, a current report used to disclose material events between quarterly filings, was signed by Chief Executive Officer Matthew Cole.

    Bitcoin as the Treasury Benchmark

    The accumulation mirrors a wider shift among public companies treating bitcoin as a reserve asset. Strategy, the largest corporate bitcoin holder, recently resumed bitcoin purchases after a multi-week pause, while Strive has described bitcoin as its hurdle rate for capital deployment and says it is focused on growing bitcoin per share. Through its SEC-registered subsidiary Strive Asset Management, the firm manages more than $2.7 billion in assets. That framing places Strive among a small but expanding group of public companies actively building bitcoin treasuries rather than holding the asset passively.

    What Comes Next

    Corporate treasuries have continued to add bitcoin even as markets digest macroeconomic uncertainty. Metaplanet, another public company pursuing a bitcoin-treasury strategy, recently reshaped its capital structure to boost bitcoin per share. Strive’s next disclosure will show whether the firm keeps accumulating at a similar pace, and whether the broader cohort of corporate buyers sustains its recent momentum. The move keeps Strive among the public companies steadily converting a portion of their balance sheets into bitcoin, even as the wider market waits for the next catalyst.

  • Swiss Bitcoin Pay Shuts Down Servers After Security Breach Exposes User Data

    Swiss Bitcoin Pay Shuts Down Servers After Security Breach Exposes User Data

    Swiss Bitcoin Pay Takes Servers Offline After Security Breach Exposes User Data

    Swiss Bitcoin Pay, a cryptocurrency payment processing provider, took all its servers offline on Monday following a security incident that raised concerns about unauthorized access to internal systems. The company announced the breach via its official X account, stating that email addresses, Bitcoin addresses, bank IBANs, transaction histories, and hashed user passwords may have been exposed.

    Company Response and Investigation Underway

    Despite the exposure of sensitive customer data, Swiss Bitcoin Pay assured users that no funds were at risk as a result of the incident. The company emphasized that it had not yet determined the full scope of the breach and disabled its servers as a precautionary measure while the investigation continues.

    As of publication, the firm has not disclosed how many customers were affected, the method used by the attacker to gain access, or whether any files were extracted or only viewed. No projected timeline for restoring services has been provided.

    Non-Custodial Design Limits Financial Exposure

    Swiss Bitcoin Pay highlighted that its non-custodial architecture prevents attackers from accessing customer funds directly, as payments flow from customer to merchant and remain isolated from internal systems. However, in a follow-up message on X, the company acknowledged it temporarily holds small user balances during routine operations.

    This temporary custody typically occurs when Lightning Network payments are aggregated into batch transactions for settlement via a single on-chain movement, executed daily, weekly, or monthly. The Lightning Network, a layer-2 protocol built on Bitcoin, enables fast and low-cost transactions by processing off-chain payment channels and settling only aggregate transactions on the main blockchain.

    Swiss Bitcoin Pay clarified that although this operational feature results in brief storage of customer assets, no unauthorized Bitcoin transactions have been identified in connection with the breach.

    Security Experts Warn of Phishing Risks

    Digital security experts have cautioned that the combination of stolen email addresses, Bitcoin addresses, bank IBANs, transaction histories, and hashed passwords poses a significant risk of targeted phishing attacks.

    Security analyst Pasquale Pillitteri described the exposed data as “textbook material for a tailored phishing attack” when these identifiers are combined.

    Another concern arises from the potential to link Bitcoin addresses to real-world identities, which could compromise user privacy and enable tracing of on-chain transaction histories.

    Context of Recent Industry Breaches

    The incident follows a series of high-profile data breaches in the digital asset sector that have heightened concerns about user data security. Blockstream’s Liquid Network was recently impacted by an exploit resulting in nearly 4,000 BTC being stolen. In a separate case, Japan’s Digital Agency reported a leak of 246,000 staff and contractor records, including names, email addresses, and phone numbers.

    Hardware wallet manufacturer Trezor also suffered a data breach exposing customer purchase and shipping information, while a flaw in a SafePal order-tracking plugin impacted nearly 40,000 users. Swiss Bitcoin Pay has not attributed its incident to any known vulnerability or similar exploit used in these earlier cases.

  • Revolut Data Breach: Your Files Are Public – Here’s What to Do

    Revolut Data Breach: Your Files Are Public – Here’s What to Do

    Revolut Data Breach: Immediate Steps After Identity Documents and Bitcoin History Leak Online

    When copies of your ID document, verification selfie, and complete Bitcoin transaction history are bundled together in the hands of strangers, changing your password offers almost no protection. That reality confronts Revolut customers who received breach notifications starting September 14, 2026, the same day stolen documents began appearing publicly. Four priorities now demand action: establish the exact scope of your exposure in writing, close pathways that turn an ID copy into money, treat the link between your home address and crypto holdings seriously, and enforce your rights against the bank while legal deadlines remain open.

    What Happened: From Data Outflow to Public Release

    Until mid-September, the incident was a private data outflow. On the night of September 14, Cointelegraph reported that copies of identity documents and verification selfies belonging to Revolut customers had surfaced online. According to the outlet, the attackers announced on Telegram that they would release further data sets daily until Revolut pays a ransom. One affected customer confirmed to Cointelegraph that the published details match the documents held by Revolut and that the neobank contacted him on Friday.

    Important distinction: The existence of a ransom demand comes solely from the attackers’ own Telegram post, relayed by a trade publication. Revolut does not confirm any such demand. A specific Bitcoin sum circulating on aggregator sites as the alleged ransom lacks solid evidence and is not treated as fact here.

    The practical difference from the previous week is significant. While data held by a single criminal group requires a buyer before it can be weaponized, public availability removes that intermediate step, expanding the pool of potential fraudsters from one group to anyone who finds the files.

    Data Fields Confirmed in Revolut’s Customer Notification

    The trade publication BleepingComputer quotes the notification Revolut sent to affected customers verbatim. According to that text, the breach covers:

    • Full name
    • Date of birth
    • Occupation
    • Postal address
    • Email address
    • Telephone number
    • Copies of an identity card or driving licence
    • Selfies from the identity verification check
    • Account statements including IBAN
    • Withdrawal records
    • Complete transaction history, including Bitcoin transactions

    Revolut describes the number of affected users as limited but provides no figure. The company states its own systems were not compromised and customer funds were not touched. Both claims are plausible but do not alter the victim’s position: the damage sits in the paperwork, not the balance.

    The breach originated from a forged request mimicking an emergency government data request. Such requests are a legitimate procedure where authorities demand subscriber data without judicial oversight in imminent danger scenarios. The forged request came from a genuine government domain and passed technical sender authentication checks. This highlights the vulnerability: a technically valid signed email proves domain authenticity, not the lawfulness of the request behind it.

    Why Blocking Your German ID Card via 116 116 Is the Wrong Move

    Many affected individuals instinctively try to block their ID card through Germany’s free hotline 116 116. In this case, that step is ineffective. The hotline blocks the online ID function (eID) on the card’s chip, which requires the physical card plus a six-digit PIN. A scanned copy cannot trigger the eID.

    Your physical ID card remains in your possession, and the eID is not the attack vector. The risk lies with any provider that accepts an image file of an ID document as proof—credit brokers, mobile operators, mail-order retailers offering purchase on account, and some trading platforms with weak checks. Blocking the eID would only cost you access to digital government services without mitigating the actual threat.

    Effective Identity Protection Measures

    Instead, take these concrete steps:

    • File a criminal complaint with the police via your federal state’s digital police station; the case number serves as evidence against any future fraudulent claims.
    • Request a free copy of your data from major credit reference agencies and check for contracts you never signed.
    • Set a reminder: identity abuse using copied ID documents often surfaces months later. The German Federal Office for Information Security (BSI) details further steps for data breach and doxing victims.

    The Critical Combination: ID Scan Plus KYC Selfie

    A leaked ID scan alone is a known risk. The combination of an ID copy and the selfie from the same identity check is a different order of magnitude because that pair is the standard proof used to open accounts. Many providers require a photo of the document and a facial image, often matched automatically.

    The safeguard is a liveness check, designed to verify a living person is present rather than a static image. Strong procedures demand head movements, changing light patterns, or depth capture; weak ones accept a simple uploaded still image. Wherever only a still image is required, a leaked verification selfie becomes immediately usable.

    Action for crypto users: Identify which trading venues hold your ID document and close unused accounts. Every dormant registration is one less copy of your paperwork in circulation. For active accounts, enable two-factor authentication via an authenticator app or security key—not SMS—because your phone number is part of this breach. Our overview of regulated crypto exchanges in Germany explains how to verify platform supervision.

    Bitcoin Transaction History in the Wrong Hands: Address Clustering Risks

    The inclusion of complete transaction history separates this incident from a typical bank data breach. Bitcoin’s blockchain is public; every transfer is visible. What the chain lacks is the link between an address and a real-world identity. An account statement with withdrawal records provides that link for free.

    Address clustering derives a bundle of addresses from a single known one: when several addresses appear together as transaction inputs, they likely belong to the same wallet. Anyone with one of your withdrawal addresses can work outward and often estimate your total holdings. This technique is neither new nor illegal—analytics firms and investigators have used it for years. What is new is that the starting point for such analysis is now publicly available.

    Should you change your addresses? For future payments, yes; for past transactions, it’s impossible. A transaction written to the blockchain cannot be erased. Practical steps:

    • Use fresh addresses for new incoming payments.
    • Avoid merging old and new holdings in a single transaction.
    • For larger amounts, do not deposit and withdraw through the same platform.

    Home Address Plus Crypto Holdings: Assessing Physical Risk

    On-chain investigator ZachXBT assesses that the breach appears small but deliberately aimed at wealthy users. While this is his assessment and not established fact, it warrants attention because the data structure—postal address, date of birth, occupation, and traceable Bitcoin history—creates a profile extending beyond typical phishing.

    This pattern mirrors the Trezor data breach in September, which exposed names, phone numbers, and home addresses of hardware wallet buyers. The lesson applies equally here:

    • Do not discuss crypto amounts in your neighborhood or on the phone.
    • Treat parcel notifications and supposed bank callbacks with suspicion, even when the caller quotes your name, date of birth, and recent transactions correctly—those details are in the leaked package.

    Implement a callback rule at your bank and trading venues: no process initiated by phone is completed by phone. Hang up and dial the number from your app or account statement. This single habit neutralizes much of the value a cybercriminal can extract from your documents.

    What to Do If Your Revolut Account Is Actually Hacked

    Clarification: no account takeover occurred in this incident. Revolut states documents were disclosed; login credentials were not stolen. If your account is genuinely being controlled by someone else, a different procedure applies:

    1. Block the card in the app, or via customer service if you’ve lost access.
    2. Report every unauthorized debit immediately; under payment services law you are typically reimbursed for unauthorized payments unless you acted with gross negligence, and the bank must prove authorization.
    3. Change your email password—it is the master key to every other login.
    4. Check connected devices and sessions in all accounts using that email, and remove unrecognized sessions.

    Document every step in writing with date and time. This record is essential for any future damage claims or disputes.

    Review Plan with Fixed Dates: Identity Abuse Rarely Starts Immediately

    Weeks or months often pass between a data outflow and the first attack in your name, as data sets are sorted, merged, and passed on. A structured review plan works better than a single frantic afternoon.

    This Week

    • Send the Article 15 GDPR access request.
    • File the criminal complaint.
    • Switch two-factor authentication everywhere to an authenticator app or security key.
    • Note which postal addresses and phone numbers Revolut held on file; any future message quoting those details instantly reveals the source.

    In Four Weeks

    • Request data from credit reference agencies and check for unrecognized entries; every credit inquiry you didn’t initiate is a warning sign.
    • Review login logs of your most important accounts and report any access from regions you weren’t in.

    After Three Months and Six Months

    Repeat the four-week checks. As long as your passport circulates as an image file, it retains value for fraudsters until its expiry date.

    Drop this expectation: Dark web monitoring services only search databases of already-known collections. They provide pointers on older incidents but offer no all-clear for a fresh breach. Rely on your own Article 15 response, not a green light from a monitoring service.

    Your GDPR Rights: Access, Complaint, and Damages

    Revolut’s notification fulfills its obligation under Article 34 GDPR (high-risk breach notification). That email tells you that you are affected, not the extent. Obtain the full scope through Article 15 GDPR (Right of Access): request in writing a copy of all data processed about you and an explicit statement of which categories were disclosed to which recipients. The deadline is one month, extendable by two months with justification. This response is your only solid evidence of what was actually disclosed in your case, and it is free.

    If no answer arrives or the response is unusable, Article 77 GDPR allows a complaint to a supervisory authority—including the authority where you habitually reside. For German customers, that is your state data protection authority. Revolut Bank UAB’s Lithuanian base and the lead supervisory authority procedure do not change this; your state authority accepts the complaint and forwards it. The German branch in Berlin is supervised by BaFin, which is not responsible for data protection.

    Regarding Article 82 GDPR damages, the German Federal Court of Justice ruling of November 18, 2024 (case VI ZR 10/24) clarified that mere loss of control over your data can constitute compensable non-material damage without proven abuse. You must articulate that loss of control; awarded amounts so far sit in the low hundreds.

    Tax Reporting Under DAC8: What Changed in 2026

    Questions about tax office monitoring arise after every such incident. The answer is unrelated to the breach: no one is being monitored. Since January 1, 2026, Germany’s Crypto Asset Tax Transparency Act transposes the EU DAC8 directive, obliging crypto asset service providers to record and transmit tax-relevant customer and transaction data. The first reporting period is the 2026 calendar year, with data due to the Federal Central Tax Office by July 31, 2027.

    Two consequences for you:

    • Details held by crypto providers will grow, not shrink; keeping clean personal records is no longer optional.
    • A reported sum is not your profit—reported figures are proceeds and transactions, while acquisition costs are known only to your documentation. Without your own records, you negotiate against a figure you cannot counter. A portfolio tracker with tax reporting solves this.

    Separating Proven Facts from Unverified Claims

    Several narratives circulate; distinguishing them is crucial for your judgment.

    • Proven: The notification to affected customers with the list of data fields (Revolut sent it; BleepingComputer reproduced it verbatim). Public surfacing of ID documents and verification selfies (confirmed by an affected customer to Cointelegraph).
    • Claimed: The extortion threat of daily publication (from a Telegram post by alleged perpetrators). Revolut does not confirm it; a company under extortion rarely does. Always attribute the claim to its source.
    • Disputed: An older summer episode where a database allegedly holding tens of millions of Revolut records was offered on dark web forums. Revolut denied authenticity, attributing it to compiled material from other sources. Keep this separate from the current incident; conflating them inflates the number of affected customers without evidence.

    Practical takeaway: Expect highly convincing phishing. Knowing your name, date of birth, IBAN, and recent transactions allows attackers to craft sophisticated lures. The only reliable test is the channel, not the content. A genuine bank never asks via email or phone to move funds to a “security account,” enter a recovery phrase, or install remote access software. At the slightest doubt, use the app you installed yourself.

    Self-Custody as a Consequence: Shortening the Data Trail

    This case exposes a property of custodial arrangements invisible in daily use: holding crypto with a provider leaves a complete identity file alongside your balance. That file is the breach’s actual subject. A hardware wallet doesn’t eliminate all risks but shortens the trail at a decisive point: your balance no longer sits with a third party, so that party’s failure or breach no longer separates you from your coins.

    Stay honest about trade-offs. The purchase itself generates data, as the Trezor breach showed; avoid shipping to your home address if possible, and buy only from the manufacturer or authorized resellers. The transfer from an exchange to your wallet is visible on-chain and linkable to your account statements. Responsibility for the recovery phrase then rests entirely with you. Self-custody shifts risk; it does not abolish it.

    For funds remaining on a platform, selection hinges on supervision and custody practices. Ask about segregated custody, the custodian’s identity, and the license under which they operate.

    Revolut Data Breach: Key Takeaways

    1. Establish exposure in writing. Send the Article 15 GDPR access request today and record the date. Without that list, you’ll later argue over assumptions. Simultaneously, check which trading venues hold your ID copy and close unused accounts; our regulated crypto exchange overview highlights what matters for those you keep.
    2. Separate identity and holdings. Use fresh receiving addresses, avoid merging old and new holdings in single transactions, and move long-term holdings into your own custody. Our hardware wallet comparison details devices and their weaknesses.
    3. Order your records before the first DAC8 report. Complete acquisition data is your only counter-argument against reported sums from the 2026 reporting period onward. A tax and portfolio tracker automates the collection.

    As of September 14, 2026. This article is not investment advice. Prices and fee structures change; verify terms with the provider before purchasing.

  • Will the CLARITY Act Pass the Senate Today?

    Will the CLARITY Act Pass the Senate Today?

    Connor Brown, Executive Director of the Bitcoin Policy Institute and former Senate staffer, outlined the stakes as the Senate prepares for a cloture vote today on the CLARITY Act. With Republicans holding 53 seats and two potentially absent, the measure requires 7 to 9 Democrats to cross the aisle to reach the 60-vote threshold. This procedural vote does not decide the bill’s final passage; it determines only whether the Senate can proceed to debate and an eventual up-or-down vote.

    Years of Legislative Groundwork

    Brown characterized the vote as the culmination of years of legislative effort, tracing the lineage back to the Token Taxonomy Act and the Lummis-Gillibrand framework on which he worked during his Senate tenure. He described the current text as Republicans’ “final and best offer” to pass comprehensive digital asset legislation before the election, with only a handful of session days remaining.

    “This really is sort of a buzzer-beater moment,” Brown said, “for this legislative package and for a clear set of lasting rules for the digital asset industry.”

    Ethics Compromise Breaks Logjam

    The provision that stalled negotiations longest—government ethics restrictions—shifted significantly when former President Trump agreed to approximately 80% of Democratic requests. Brown called the resulting compromise “pretty compelling,” noting it extends restrictions to officials’ spouses and grants individual states authority to pursue exchanges and seek injunctions against the Justice Department.

    “80% of the way there,” Brown said, “sounds like a pretty good deal for something that otherwise would be 0% of the way there.”

    Congress vs. Agency Rulemaking

    Brown framed the vote as a fundamental choice: allow regulatory agencies like the SEC and CFTC to write industry rules unilaterally, or give Congress a direct role in shaping the regulatory framework. With Senator Cynthia Lummis’s updated draft reportedly incorporating 115 Democratic-requested changes, Brown argued the question facing senators today is not whether the bill is perfect, but whether Congress wants a seat at the table or prefers to default to agency rulemaking.

  • Balancer May Shut Down Before Its Treasury Runs Dry

    Balancer May Shut Down Before Its Treasury Runs Dry

    Balancer DAO Proposes Orderly Winddown as Monthly Costs Outpace Revenue

    A Balancer Treasury Council member has submitted a proposal for an orderly winddown of the protocol, subject to a governance vote by BAL holders. The plan would halt new development, reduce operations to a limited withdrawal service, and eventually distribute the remaining treasury assets to eligible BAL holders.

    Financial Reality Drives the Proposal

    The proposal rests on a straightforward calculation: Balancer is spending significantly more each month than the protocol and treasury management generate. Monthly operating costs run approximately $150,000, while August protocol revenue reached only about $30,000. Treasury management contributed roughly $25,000 per month, leaving a substantial deficit.

    Balancer had previously attempted to achieve profitability through cost reductions, a simplified token model, and growth in its newer v3 products. According to the proposal, those efforts did not create enough sustained revenue to replace the protocol’s older v2 income. The authors argue that a capped exit budget is preferable to allowing operating costs to continue without a clear path to profitability.

    Phased Transition Timeline

    No changes would take effect unless BAL holders approve the proposal via a Snapshot vote. If approved, Balancer would move through a structured exit period rather than shutting down immediately:

    • Before October 30, 2026: Liquidity providers (LPs) would have an exit window with access to withdrawal guidance.
    • From October 30, 2026: Pools that can be paused would move to withdrawals-only mode, and the bug-bounty program would end.
    • End of May 2027: The first proposed BAL treasury-redemption round would open.
    • End of November 2027: The six-month first-round redemption window would close.

    Balancer does not hold LP assets in the way a centralized exchange holds customer deposits. Users can withdraw through the smart contracts even if the organization stops maintaining its usual interface. Pools whose contracts cannot be paused could remain live, with protocol fees set to zero where the contracts permit it.

    Different Holder Groups Follow Different Routes

    The proposed distribution is not a single process for every Balancer user. Each group must consider its specific withdrawal or redemption path:

    Liquidity Providers

    Review the pool’s withdrawal route. Eligible pools could become withdrawals-only from October 30, while others may continue under different contract rules.

    Ordinary BAL Holders

    Follow the opening-snapshot announcement, then redeem during the proposed six-month first round by burning BAL for a pro-rata, in-kind share of the treasury.

    veBAL Holders

    Existing locks are expected to expire before round one. Holders would exit the 80/20 BAL/WETH pool into BAL before redeeming.

    auraBAL and sdBAL Holders

    These positions would need to unwind through their own protocols and become BAL before the first-round deadline.

    Exploit-Affected LPs

    Recovered funds stay outside the BAL-holder distribution and remain allocated to the affected pools.

    A holder who has not converted auraBAL or sdBAL into BAL by the end of round one would not redeem through Balancer’s claim process. veBAL holders who extend their locks after the proposal date would also need to wait until those new locks expire.

    Special Rule for tetuBAL

    tetuBAL follows a separate rule because it is permanently locked. The proposal fixes tetuBAL ownership at the block when the forum post was published. Those holders would receive BAL equal to half of the measured BAL behind their tetuBAL position, then redeem that BAL in the same first-round process.

    First-Round Participation Determines Later Distributions

    The proposed first round would not be the only payment. After the six-month claim window closes, a second-round airdrop would go only to addresses that redeemed in round one. It would include unspent winddown funds, assets received after the first snapshot, and the share connected to BAL that was not redeemed.

    No separate claim would be needed for that second round. A final sweep six months later would also go to the same first-round redeemers. For BAL holders, missing the first window could therefore mean missing both the initial distribution and any later proceeds collected by the DAO.

    Treasury Estimate Is Not a Fixed Per-Token Value

    The claim rules explain who may receive assets; they do not establish how much each BAL could be worth. The $9 million figure is an estimate of the managed treasury at current prices, while other DAO wallets, positions, and receivables are still being inventoried.

    The amount available for distribution would be fixed only when round one opens, after the DAO has completed its asset inventory and an audit. It could change with token prices, recovery of receivables, funds identified as belonging to third parties, and the costs of completing the winddown.

    The plan sets aside up to $400,000 from November 1 onward: $150,000 through May 2027, $30,000 for the later distribution process, and a $220,000 reserve if needed. At the current $150,000 monthly cost base, the proposal argues that a capped winddown budget is easier to justify than open-ended operating expenses. Any amount not spent would return to the distribution pool.

    Recovered Exploit Funds Must Remain Separate

    Some funds recovered from attacks on Balancer may sit in DAO-controlled addresses, but the proposal states they do not belong to the general treasury. They belong to LPs in the affected pools and would need to be identified and excluded before the treasury snapshot.

    Recovery work would continue through private investigators and law enforcement. Any further funds recovered would go to affected LPs, rather than being added to the BAL-holder distribution.

    Governance Vote Decides Balancer’s Future

    The vote asks BAL holders to choose between preserving an independent protocol with an uncertain revenue path and accepting a structured exit while the treasury can still fund one. Until a Snapshot vote approves the proposal, Balancer’s pools, treasury assets, and operations remain under the current governance arrangements.

    This article is provided for informational purposes only and does not constitute financial, legal, or investment advice. The proposed winddown, its dates, and its distribution rules remain subject to governance approval and may change.

  • Balancer Considers Wind-Down After Restructuring Fails to Revive Revenue

    Balancer Considers Wind-Down After Restructuring Fails to Revive Revenue

    Balancer Proposes Protocol Wind-Down After Restructuring Fails to Generate Revenue

    Balancer, a decentralized exchange and automated market maker, has proposed winding down the protocol after its post-exploit restructuring failed to generate sufficient revenue. CEO Marcus Hardt acknowledged he underestimated how much a $128 million exploit in November 2025 would continue to weigh on adoption.

    Restructuring Cuts Costs But Revenue Falls Short

    The proposal was authored by Balancer Labs CEO Marcus Hardt and published on the Balancer governance forum on Monday. It calls for an orderly wind-down of the protocol and the distribution of its remaining treasury, currently worth more than $9 million, to BAL tokenholders.

    The move follows Balancer Labs’ shutdown in March, when executives opted to continue operating the protocol under a leaner structure. Hardt stated Monday that while the restructuring succeeded in cutting costs and delivering products promised to tokenholders, the revenue side of the plan fell short, echoing profitability challenges faced by several other DeFi protocols this year.

    “What did not come was enough revenue. Most of the protocol’s revenue still comes from v2, and v3 revenue has not grown to replace it. The product worked. It did not sell enough,”

    Hardt said in a statement on X.

    Exploit Impact on Revenue and Adoption

    Data from DefiLlama show that Balancer’s monthly protocol revenue fell to $371,000 in November from $1.13 million in October after an exploit affecting composable stable pools on its legacy v2 protocol. Revenue continued to trend downward into 2026, with August revenue at just $56,781.

    “The November 2025 exploit hit legacy v2 pools. v3 is a different architecture, but the event followed the name into every conversation since and made traction harder to build,”

    Hardt said on the Balancer forum.

    “I underestimated how much the exploit would continue to limit adoption,”

    he added in a separate post on X.

    Phased Shutdown Plan and Treasury Distribution

    Under the proposal, Balancer would begin a phased shutdown next month, with new business development ending and liquidity providers given until Oct. 30 to prepare to exit the protocol. Meanwhile, pools that can be paused would move to withdrawal-only, while those that cannot be paused will continue working but have the protocol fee set to zero where contracts allow it.

    From Nov. 1, Balancer would operate only the minimal infrastructure needed to support withdrawals, and the DAO would be wound down, with a small team to manage the transition. The proposal sets aside up to $400,000 for the wind-down process.

    BAL holders would receive the remaining treasury on a pro-rata basis, with the first distribution scheduled for May 2027, when holders would burn their BAL in exchange for their share of the treasury assets. A second distribution would return unspent wind-down funds and unclaimed assets from the first distribution, followed by a “final sweep” six months later.

    “Continuing on the current path spends the treasury to arrive at the same place later. That treasury belongs to BAL holders. The question is whether what remains reaches holders while it is still substantial, or is spent first on a path that has already been tried,”

    Hardt said.

    Governance Vote Scheduled

    The wind-down requires approval from BAL holders, with a snapshot vote scheduled for Sept. 25 to 29. A rejection would leave Balancer’s existing operating framework in place.

  • CoinEx Shuts Down After 9 Years: Users Must Withdraw Funds by Dec. 22

    CoinEx Shuts Down After 9 Years: Users Must Withdraw Funds by Dec. 22

    Cryptocurrency exchange CoinEx has announced it will cease operations after nearly nine years, citing declining trading volumes, deteriorating liquidity, and escalating regulatory costs. The platform will begin a phased wind-down on September 15, 2026, with a final withdrawal deadline of December 22, 2026.

    Founder Cites Market Downturn and Regulatory Pressure

    In an official announcement, CoinEx attributed the decision to a prolonged crypto market downturn, a significant drop in industry-wide trading volume and liquidity, and rising regulatory and compliance requirements across major markets. Founder Yang Haipo offered a more personal assessment, stating the exchange had weathered multiple bull and bear cycles but failed to achieve the industry-leading position he originally envisioned.

    Yang also highlighted the growing difficulty of managing security and compliance risks. He wrote on X:

    Dear CoinEx Community,Today, I am announcing that CoinEx will cease operations and begin an orderly wind-down.First, what matters most: your assets are safe. CoinEx’s reserve ratio exceeds 100%, and every user asset is fully backed and available for withdrawal. Withdrawals…

    — Haipo Yang (@yhaiyang) September 15, 2026

    In a separate statement, Yang explained the rationale behind rejecting a potential sale: “Carrying unlimited risk for limited revenue is no longer a rational choice.” He noted that users had entrusted assets to the platform and, in many cases, to him personally, leading to the decision to wind down operations while ensuring full asset withdrawals.

    CoinEx Shutdown Timeline: Key Dates for Users

    The exchange has published a detailed phased shutdown schedule:

    • September 15, 2026: New user registrations and referral rewards end. Futures contracts move to “Reduce-Only” mode.
    • September 22, 2026: Margin, Crypto Loans, Staking, Earn, and Futures services close. Most on-chain deposit addresses disabled, except CET deposits.
    • September 29, 2026: All spot trading pairs close. CoinEx Smart Chain (CSC) and OneSwap shut down.
    • December 22, 2026: Withdrawals close, marking the full shutdown of the exchange.

    Urgent Withdrawal Warning and 5% Monthly Custody Fee

    CoinEx emphasized that protecting user funds remains its top priority, confirming a reserve ratio above 100%. Withdrawals will remain open until December 22, 2026, even as other services cease.

    The exchange strongly urged users to withdraw assets early, warning that network congestion, fees, or delays could impact transactions near the deadline. After December 22, any unclaimed USDT will be moved to independent custody and incur a 5% monthly custody fee based on the original balance. Users may submit custody claims until August 22, 2028.

    CET Token Buyback at Fixed Rate

    CoinEx will also close the chapter on its native CET token by repurchasing remaining CET held in user accounts at a fixed rate of 0.005 USDT per token. The exchange stated there will be no quantity limit or additional conditions for the repurchase.

    Yang apologized to CET holders directly: “I am sorry that we were not able to create the long-term value we once hoped CET would deliver.”

    ViaBTC, CoinEx Wallet, and CoinEx Vault Unaffected

    The shutdown will not impact ViaBTC, which operates independently as a Bitcoin mining pool. CoinEx Wallet and CoinEx Vault will also continue operating separately from the exchange.

    ViaBTC Pool Official Statement: Clarification on CoinEx’s Business Strategy Adjustment and the Continued Stability of ViaBTC Pool ServicesDear ViaBTC users and community partners,In response to CoinEx’s latest announcement regarding its strategic shutdown and the wind-down of…

    — ViaBTC (@ViaBTC) September 15, 2026