Autor Cointelegraph By Felix Ng

Zano exploiter created 36.9M unauthorized ZANO before blockchain rollback

Zano revealed that the attacker who exploited its Gateway Address vulnerability over the last month used it to create 36.9 million Zano (ZANO), along with Freedom Dollar (fUSD) tokens, before the decision was made to roll the blockchain back by a month. In a post-mortem published Thursday, Zano said the attacker first exploited the vulnerability on Aug. 29, creating approximately 18.4 million ZANO in a single transaction. The attacker repeated the exploit on Sept. 25, minting another 18.4 million ZANO, before using the same method to create fUSD. The team said a portion entered the Zano ecosystem. “These coins functioned as authentic ZANO and could be spent normally,” the team wrote in its post-mortem. Cointelegraph reached out to Zano for comment.The figures shed light on why the Zano team called for a rollback of about a month of blockchain history, including legitimate transactions. The team acknowledged that the rollback would hurt trust but argued it was necessary to remove unauthorized supply as it could not be distinguished from legitimate coins.Attacker paid 100 ZANO exploit entry fee Zano’s post-mortem said the attacker paid 100 ZANO to set up the exploit, worth about $553 at the time of publication. The attacker registered a Gateway Address on Aug. 28, paid the registration fee, then tested a fabricated asset before the first unauthorized mint the next day. The first 18.4 million ZANO mint went unnoticed for nearly a month. The team said the unauthorized coins appeared like ordinary outputs, and internal teams flagged the activity after the second mint.Related: Zano rolls blockchain back a month after Gateway Address exploitZano said AI-assisted testing, internal audits or bug bounties failed to pick up the bug. Meanwhile, Zano said Wednesday it is working to restore affected balances using its developer fund, team members’ personal funds and committed contributions. Recovery will primarily run through exchanges and payment services, with exchanges to replay withdrawals reversed by the rollback and the team credited the affected deposits. Magazine: China warns foreign spies about crypto, Singapore dominates Asia: Asia ExpressCointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

Čítaj viac

Core Lightning warns attackers are targeting unpatched nodes

The team behind Core Lightning, an open-source node software for the Bitcoin Lightning Network, has urged operators running older versions to upgrade immediately after receiving reports of attackers targeting unpatched nodes. “Urgent security update: If you’re running version 26.06.7 or earlier, please upgrade to the latest release as soon as possible,” the team said on Friday. Core Lightning did not specify which vulnerabilities attackers were targeting or the potential impact. Cointelegraph reached out to Core Lightning for comment. Source: BlockstreamOn Sept. 16, Core Lightning said it was investigating reports of a potential issue affecting experimental features in Core Lightning that could impact user funds. It then released version 26.06.8 around six days later.The Sept. 22 update delivered bug fixes alongside patches for “vulnerabilities responsibly reported by a number of sources.” The release notes credit the Bitcoin Red Team and 12 other named individuals and groups, along with anonymous reporters. Some of the fixes addressed flaws that could crash senders’ nodes, requests that could exhaust memory in its REST interface and a channel-closing bug that could cause users to lose funds to a penalty, according to the changelog. However, the release deliberately withheld some tests to make it harder for attackers to reverse-engineer and exploit vulnerabilities while operators upgraded. In August, Core Lightning said it was working on a coordinated fix after assessing a high volume of AI-generated Common Vulnerabilities and Exposures (CVE) reports over recent weeks. Two days later, it released 26.06.7 to address the confirmed vulnerabilities. Related: Core Lightning confirms multiple vulnerabilities, prepares security updateCointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

Čítaj viac

SEC moves to clear custody hurdle for advisers offering crypto

The US securities regulator has proposed easing rules governing how investment advisers and funds hold crypto, potentially clearing a regulatory hurdle that has held some businesses back from offering clients digital asset investments. The proposal, published on Thursday, would let investment advisers hold clients’ crypto assets themselves when no eligible crypto custodian is available, with conditions. It would also allow state trust companies to serve as crypto custodians. “The crypto asset market has grown from a niche curiosity into a multi-trillion-dollar asset class to which investors actively seek exposure. Unfortunately, our rules and regulations have not kept pace,” US Securities and Exchange Commission Chair Paul Atkins said in a statement. The proposal targets a practical barrier to crypto investment: investment advisers can struggle to find a qualified custodian for a particular token, limiting the investments they can offer clients.The Digital Chamber has previously raised concerns about the lack of qualified crypto custodians. In a May 2025 submission to the SEC, the Digital Chamber said some advisers had declined token allocations or asked portfolio companies to retain them until custody became available. In a statement on Thursday, SEC Commissioner Hester Peirce likened the uncertainty to a regulatory “roller coaster,” saying advisers have been “gritting their teeth and holding on for dear life” while awaiting workable custody rules. Self-custody would come with safeguards Under the SEC proposal, advisers seeking to hold clients’ crypto themselves would have to establish that no permitted custodian is available for each asset and reassess that determination quarterly. If a custodian becomes available, the assets would need to be transferred as soon as reasonably practicable. Self-custody would also require safeguards around private keys, cybersecurity and separation of each client’s holdings. At least two authorized individuals would have to approve any transfer of a self-custodied crypto asset. Related: US SEC follows CFTC in staff guidance for cryptoSEC Commissioner Mark Uyeda said the proposal recognized that adviser custody creates “an inherent conflict of interest,” and that advisers’ fiduciary duties would continue to apply when they hold clients’ crypto.The proposal would also allow regulated funds to maintain crypto assets in self-custody with their investment adviser, provided the adviser meets self-custody requirements and the fund’s board oversees the arrangement.State trust company optionUsing a state trust company — a financial firm authorized by a US state to look after assets on other people’s behalf — would carry separate conditions. These include making sure the state trust company is authorized by the relevant state authority to provide crypto custody, has reasonable procedures to safeguard crypto assets from loss, theft or misappropriation and has audited financial statements and internal control reports and ensuring client holdings are segregated from the company’s own assets. The package also proposes changes to audit, recordkeeping and disclosure requirements. The SEC will accept public comments for 60 days after the proposal is published in the Federal Register.The latest proposal adds to a push by the SEC and Commodity Futures Trading Commission to set clearer rules for crypto under their existing powers after the CLARITY Act failed to advance in the Senate last month. The CFTC has submitted a crypto-market proposal for White House review, while the SEC has opened a path for trading tokenized stocks. Magazine: China warns foreign spies about crypto, Singapore dominates Asia: Asia Express

Čítaj viac

LATAM stablecoin liquidity may depend on few providers, investor says

Latin America’s stablecoin payment ecosystem may depend on a small group of underlying liquidity providers, potentially disrupting customers’ ability to cash out into local currency if a key provider loses banking access, according to Verda Ventures partner Amit Chu.In a newly published report from crypto venture companies Varys Capital and Verda Ventures, drawing on Verda’s Stablescape database, researchers analyzed 494 companies in the region, but found only 16 whose primary business is providing wholesale stablecoin-to-fiat liquidity, corporate treasury and credit, warning that “fragility in the system is concentrated in its thinnest layer.”“There are many sellers of liquidity and very few specialists. What we can’t see from public data is how many of them warehouse the currency risk themselves and how many pass it to the same few desks and exchanges. Our view is that it’s the second, and that’s the fragility the report is pointing at,” Chu told Cointelegraph. Stablecoins are playing a growing role in Latin America’s crypto economy. According to a September Chainalysis report, stablecoins by June 2026 accounted for 32.1% of cross-border crypto value, and 22.1% of domestic P2P activity and 17.6% of personal wallet balances in the region.Countries with the greatest monetary instability exhibited the fastest growth in stablecoin adoption. Source: Varys Capital and Verda VenturesChu said a disruption affecting a key provider could leave users holding stablecoins as they face higher costs or delays when converting them into a local currency. “The problem would be at the exits. Spreads would widen, cash-outs to local bank accounts would slow or pause, and funds in transit with the failed desk could be stuck,” he said. Related: Stablecoin firms have a $112B additional opportunity in LATAM remittance However, the report doesn’t establish the degree to which liquidity itself is concentrated. Chu said Stablescape does not track transaction volumes and doesn’t provide market share figures. Exchanges and payment companies classified elsewhere in the database also supply liquidity, though Chu said Verda believes some ultimately depend on the same underlying desks. Chu said licensing is the biggest lever for reducing concentration, as clearer rules would make it easier for banks to serve liquidity providers. He also pointed to local-currency stablecoins, which could allow more market makers to settle transactions onchain, while global trading firms are beginning to quote Latin American currency pairs. Chu also cautioned against assuming that a small number of specialists necessarily signals a problem. “Mature FX markets also have far fewer dealers than customer-facing firms. What matters is redundancy and capital,” he said. “Each major currency should have several independent, well-capitalized desks with separate banking relationships, and each wallet should be able to route between multiple players.”The report generally identified Latin America as a growth opportunity, particularly for businesses addressing cross-border payments. It argued that fragmented banking systems and costly transfers create demand for services that make it easier for people and businesses to move money between countries.Magazine: Altseason is coming — and traders are more discerning this time

Čítaj viac

Získaj BONUS 8 € v Bitcoinoch

nakup bitcoin z karty

Registrácia Binance

Burza Binance

Aktuálne kurzy