Autor Cointelegraph By Stephen Katte

Polymarket denies data breach, says hacker is selling public data

Prediction markets platform Polymarket has denied recent reports that its customer data was breached after a hacker on the dark web posted what the person claimed was a trove of private user details.Cybersecurity company Vecert Analyzer and several other X accounts that track dark web activity shared screenshots from DarkForums on Tuesday showing a hacker using the pseudonym “xorcat” claiming to have breached Polymarket.In the post, xorcat said they had stolen over 300,000 records, including 10,000 unique user profiles with full names, profile images, proxy wallets and base addresses. Polymarket called the claims of a data breach “complete and utter nonsense” and said the information the hacker posted is already available online.The crypto industry saw a sudden surge in crypto-related hacks and exploits in April, putting many in the space on high alert. Blockchain security company Hacken reported earlier this month that Web3 projects lost $482 million to hacks and scams in the first quarter of 2026 across 44 incidents.“You compromised our platform by accessing publicly accessible API endpoints & on-chain data and *checks notes* are trying to sell the data we offer developers for free? Which VC paid you to post this?” Polymarket said.In another post, the prediction market said: “Part of the beauty of being on chain is all our data is publicly auditable, this is a feature, not a bug. No data was leaked, it’s accessible via our public endpoints & on-chain data. Instead of paying for the data, you can access it for free via our APIs.”Source: Polymarket Hacker claims over 300,000 records stolen The so-called hacker said the data was being posted because Polymarket didn’t have a bug bounty program. Related: Scammers use Gmail dot alias trick to spoof Robinhood in phishing scamHowever, Polymarket has a live bug bounty program that started April 16 and has received 446 reports as of Wednesday.  Source: Dark Web Informer Xorcat also said data was pulled via undocumented API endpoints, pagination bypass and CORS misconfiguration on Polymarket’s Gamma and CLOB APIs. The hacker claimed to have breached other prediction markets and planned to release the data over the next few days.Several security experts have expressed doubt. Vladimir S, a threat researcher and chief security officer at Legalblock, said it appears “someone parsed data and is trying to present it as a [DB] leak. It does not seem probable to me.”Magazine: Forget stablecoin yield, how does the CLARITY Act treat DeFi?   Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

Čítaj viac

Bitcoin’s recent rally is largely fueled by Strategy purchases: Bitwise's Hougan

Bitcoin treasury firm Strategy and its perpetual preferred stock, STRC, have been the “single biggest factor” in Bitcoin’s recent rally, which has jumped 20% from its February low, according to Bitwise chief investment officer Matt Hougan.Over the past eight weeks, Strategy has added $7.2 billion in Bitcoin, Hougan said in a report published Tuesday. “Yes, there have been multiple drivers of the recent rally, including strong buying from ETFs, $3.8 billion since March 1, and renewed purchases by long-term holders. But Strategy has been the single biggest factor,” he said. Bitcoin has traded between $75,849 and $79,321 over the past seven days, according to CoinGecko. It was trading at about $76,486 as of Wednesday, up 21% from its Feb. 6 low of $62,822.Strategy is the largest publicly listed corporate Bitcoin holder. It bought 3,273 Bitcoin for $255 million between April 20 and April 26, bringing total holdings to 818,334 BTC. Source: LookonchainBitcoin buys are set to continue, analyst saysStrategy typically makes weekly Bitcoin purchases. Its latest buying spree pushed its total holdings past those of global asset manager BlackRock, which holds about 812,300 coins on behalf of its clients.Hougan speculates that Strategy’s purchases will “continue for some time to come,” driven by the issuance of STRC, the company’s perpetual preferred stock, which pays a fixed dividend to investors for as long as the company operates. “Strategy issues STRC because it wants to buy more Bitcoin. Most of the capital raised by issuing STRC is used to purchase BTC on the open market,” he said.Related: 80% of Strategy’s ‘Stretch’ buyers are mom-and-pop investors“With junk bonds yielding less than 7% and investors fleeing private credit, STRC’s 11.5% yield — backed by a more than $40 billion bitcoin cushion — looks particularly attractive. I suspect Strategy will raise billions more through STRC,” Hougan added.Saylor has previously claimed that the company can sustain dividend payments indefinitely if Bitcoin continues to grow. Hougan said that at current prices, Strategy could “hypothetically pay existing dividends for 42 years.” However, if Bitcoin rises by 20% a year, it could “pay the dividends forever.”Strategy could surpass Satoshi soonIf Strategy continues at its current pace, its holdings could surpass those of Bitcoin creator Satoshi Nakamoto within the next two years, according to Alex Thorn, head of research at crypto-focused financial services firm Galaxy Digital.Source: Alex ThornWallets believed to be owned by Nakamoto hold 1.1 billion Bitcoin, representing about 5.5% of the total supply. Strategy would need to buy another 277,666 coins to match Nakamoto.However, Strategy’s Bitcoin purchases have varied significantly. The smallest buy in 2026 was 855 Bitcoin in February, while the largest so far this year was on April 20 with 34,164 coins.Magazine: Should users be allowed to bet on war and death in prediction markets?  Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

Čítaj viac

Crypto lobby backs formal removal of ‘reputation risk’ from bank examinations

US crypto lobby group Blockchain Association has thrown its support behind the US Federal Reserve’s proposal to codify the removal of “reputation risk” from its supervision of banks, which has been used in the past to debank crypto companies.In a letter sent Monday in response to the Fed’s request for comment, Ashok Pinto, the group’s executive vice president of legal and government relations, said reputation risk, which was removed as a component of examination programs in June 2025, should be made a formal rule.“The Blockchain Association strongly encourages the Board to move expeditiously to finalize and codify the removal of reputation risk from its supervisory framework,” Pinto wrote.“Regulation is meant to uphold the integrity of our financial system, not to pick winners and losers based on the political winds of the day. Regulated entities are entitled to objective, consistent standards. Reputation risk provides neither,” he added.Source: Blockchain AssociationReputation risk has been used in the past to justify debanking crypto companies and cutting off their access to banking rails, as part of what has been dubbed “Operation Chokepoint 2.0.” Reputation risk is only as neutral as the administration wielding itThe Trump administration has walked back many of the policies that led to crypto debanking, but Pinto argued that a concrete set of rules removing reputation risk from supervisory programs is needed because another, less crypto-friendly US government could come to power in the future. US think tank Cato Institute found in January that most debanking cases in the US resulted from government pressure rather than individual banks’ policies.“Reputation risk is only as neutral as the administration wielding it. The same mechanism used against the digital asset industry under the Biden Administration could be turned against any other lawful business sector under any future administration,” Pinto wrote.“Codifying its removal is a durable, administration-neutral protection for any American business operating lawfully within our financial system.”Final rule should be aligned with other regulatorsAt the same time, Pinto said the Fed board should align its final rule with parallel rulemakings finalized by the Office of the Comptroller of the Currency (OCC) and the Federal Deposit Insurance Corporation (FDIC).Related: Crypto lobby Blockchain Association pitches tax plan to CongressThe OCC and FDIC issued a final rule on April 7 to codify the removal of reputation risk from their supervisory programs.“A standard harmonized across federal departments and agencies would provide regulated entities with the clarity and predictability they are owed,” Pinto wrote.“Ensuring that supervision is grounded in objective, consistent, and measurable standards is essential to preserving the safety and soundness of the financial system and maintaining confidence in the impartiality of the regulatory process.”Magazine: Should users be allowed to bet on war and death in prediction markets? Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

Čítaj viac

Scammers use Gmail dot alias trick to spoof Robinhood in phishing scam

Robinhood users are being warned about a new phishing attack that takes advantage of Gmail’s native “dot alias” feature and flaws in Robinhood’s account creation process to send malicious emails.  Robinhood users on Sunday began reporting on social media of emails originating from the platform’s mail server warning of an unrecognized device login, which linked to phishing websites in the “call to action” button. Source: David GobaudAlex Eckelberry, a cybersecurity researcher and tech CEO, said the phishing campaign wasn’t the result of a hack but instead exploited a native Gmail characteristic that ignores dots in an email address, as well as a “couple of terrible holes” in Robinhood’s account setup.It comes after blockchain security company Hacken reported earlier this month that phishing and social engineering attacks dominated crypto attacks in the first quarter of 2026, accounting for $306 million in losses.Source: Alex EckelberryHackers created fake Robinhood accountsEckelberry said the scam relied on fraudsters creating an account on Robinhood with an email closely mimicking their target’s email address. For example, a Robinhood user could have an email address such as “jane.smith@gmail.com.” The scammer would create a new Robinhood account with an email without the dot in the middle, such as “janesmith@gmail.com.”While Robinhood would treat them as completely separate accounts, Gmail ignores dots in the username part of an email address. This means scammers could prompt Robinhood to automatically send emails intended for their fake account, but have them arrive in their target’s inbox instead. To get a phishing link into the automated email sent when a new Robinhood account is created, the scammers would then add HTML instructions to the optional “device name” field on Robinhood, which Gmail treats as formatting instructions. Source: Abdel“The result is a real email from “noreply@robinhood.com” that passes SPF, DKIM, and DMARC. It looks completely legitimate but now contains injected fake warning text and a working phishing button. Clicking the button leads to a fake login site,” Eckelberry said. The email is only dangerous if information is addedVisiting the fake login website alone isn’t enough for hackers to gain access to an account, Eckelberry said, but entering sensitive information such as passwords could allow bad actors to do so.Related: Robinhood Q4 earnings miss as crypto revenues declineRobinhood’s support account on X posted a statement on Monday confirming that some users received a falsified email from “noreply@robinhood.com” with the subject line “Your recent login to Robinhood” and blamed the issue on an exploit of the “account creation flow.”“This phishing attempt was made possible by an abuse of the account creation flow. It was not a breach of our systems or customer accounts, and personal information and funds were not impacted,” they said.“If you received this email, please delete it and do not click any suspicious links. If you have clicked a suspicious link or have any questions about your account, please contact us directly within the Robinhood app or website.”Magazine: Should users be allowed to bet on war and death in prediction markets? Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

Čítaj viac

Polymarket traders win $37K after Paris weather data glitch, raising suspicion

Two Polymarket accounts have attracted suspicion after making $37,000 betting correctly on two unusual temperature readings of a weather station located in a major airport in France.The two weather-focused prediction markets focused on the highest temperature in Paris on April 6 and 15, using the highest temperature recorded at the Charles de Gaulle Airport Station in degrees Celsius, according to Polymarket.French media outlet BFMTV reported on Monday that the temperature suddenly climbed to over 21 degrees Celsius on April 6, before dropping again immediately. The market resolved with the winner taking over $16,000. The winning account is under 30 days old.Meanwhile, blockchain analytics tool Bubblemaps reported a similar glitch for the April 15 market. The weather station showed 18 degrees Celsius most of the day, then suddenly spiked to 22 degrees Celsius before dropping back.Some have questioned whether foul play was involved. Prediction markets are already facing growing scrutiny over insider trading and possible violations of gambling laws.Source: Bubble Maps“That spike didn’t show on nearby stations,” Bubblemaps analysts said, adding that “Just before the spike, one trader started buying NO shares on 18°C,” before exiting with over $21,000.The winning trader account has been highly active on Polymarket with wagers on crypto and weather. However, this is the largest payout by a wide margin; the next-highest is $13.Ruben Hallali, a meteorologist, told BFMTV the temperature glitch was unlikely to be a natural event and alleged it may have been tampered with on-site.Related: Charles Schwab, Citadel Securities are eying prediction markets“Such temperature variations seem very unlikely, especially on these two dates, and over such a short period. We can imagine that an individual with a good understanding of how the sensors work intervened, resulting in temperatures rising by two degrees at the right time, to validate a bet,” he added.Météo France, the official government weather agency of France, has reportedly made a complaint with the police unit the Roissy Air Transport Gendarmerie Brigade, for alleged tampering with the operation of its automated data processing systems.Magazine: How to fix suspected insider trading on Polymarket and KalshiCointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently. Read our Editorial Policy https://cointelegraph.com/editorial-policy

Čítaj viac

Získaj BONUS 8 € v Bitcoinoch

nakup bitcoin z karty

Registrácia Binance

Burza Binance

Aktuálne kurzy