BTC $84,647.81 -2.12%
ETH $2,684.78 -2.39%
BNB $769.06 -1.17%
XRP $1.49 -3.12%
SOL $119.39 -2.16%
TRX $0.3367 +0.43%
DOGE $0.0927 -4.12%
ADA $0.2457 -3.87%
BCH $311.88 -1.61%
LINK $13.94 -3.51%
HYPE $88.09 -3.50%
AAVE $182.83 -1.06%
SUI $1.18 +0.31%
XLM $0.2148 -4.13%
ZEC $1,316.94 -5.08%
AAPL $333.22 +0.43%
AMZN $251.76 +0.77%
GOOGL $343.00 +0.91%
MSFT $517.71 +0.02%
META $728.21 -0.10%
NVDA $234.44 -0.07%
TSLA $371.00 +4.08%
SNDK $1,717.56 -2.69%
INTC $118.18 -3.44%
SPCX $159.02 +6.54%
MU $1,069.58 -2.42%
AMD $632.53 +1.11%
BTC $84,647.81 -2.12%
ETH $2,684.78 -2.39%
BNB $769.06 -1.17%
XRP $1.49 -3.12%
SOL $119.39 -2.16%
TRX $0.3367 +0.43%
DOGE $0.0927 -4.12%
ADA $0.2457 -3.87%
BCH $311.88 -1.61%
LINK $13.94 -3.51%
HYPE $88.09 -3.50%
AAVE $182.83 -1.06%
SUI $1.18 +0.31%
XLM $0.2148 -4.13%
ZEC $1,316.94 -5.08%
AAPL $333.22 +0.43%
AMZN $251.76 +0.77%
GOOGL $343.00 +0.91%
MSFT $517.71 +0.02%
META $728.21 -0.10%
NVDA $234.44 -0.07%
TSLA $371.00 +4.08%
SNDK $1,717.56 -2.69%
INTC $118.18 -3.44%
SPCX $159.02 +6.54%
MU $1,069.58 -2.42%
AMD $632.53 +1.11%

permi

All
Article
Flash

first_img XRP Ledger restarts upgrade, allowing accounts to split payment and compliance permissions

The PermissionDelegationV1_1 upgrade of the XRP Ledger entered a 14-day activation countdown on September 21, having received support from 29 of the 35 trusted validator nodes. If the support rate remains above 80% during this period, the upgrade could officially activate as early as October 5 at 11:18 UTC; at least 28 validator nodes must continue to support it, or the countdown will reset.This feature allows accounts to split permissions by role. For example, a stablecoin issuer can allow a connected compliance system to approve customer accounts holding its tokens while keeping the keys with full control offline; operational accounts can gain payment permissions but cannot change keys or delegate authority to others. Each trustee can have up to 10 permissions, and the main account can modify or revoke them at any time.This is the network's second attempt to introduce this feature. The original version had vulnerabilities that attackers could exploit to make others pay transaction fees with improperly signed transactions, and by repeatedly submitting high-fee transactions, they could deplete the victim's XRP balance. This vulnerability was reported by community testers on September 15, 2025, and validator nodes were advised to reject the amendment, so it was never activated. The fixed version was released with xrpld 3.3.0, changing the way unauthorized transactions are rejected, ensuring that fees are not deducted before signature verification.

first_img Polygon plans to deploy a permissionless burn contract, with the first round burning 100 million POL

Sandeep Nailwal, CEO of the Polygon Foundation, stated that Polygon is preparing to deploy a permissionless burn contract that allows anyone to permanently burn 100 million POL, which accounts for approximately 83% of the 121 million tokens held by the Polygon base fee collector. The contract is currently live on the testnet and will be deployed to the mainnet after the security committee completes the final signature.The first round of burns will permanently destroy 100 million POL, after which community members can trigger burns every quarter. Polygon's documentation indicates that the base fee is determined by the network and will be burned, with Nailwal stating that each base fee will inject POL into the collector. Based on the above data, approximately 21 million POL will remain in the collector after the initial burn.This burn represents about 1% of the initial supply of 10 billion POL, and based on a total supply of approximately 10.716 billion as shown by Blockscout, it accounts for about 0.93%. The burn will not set a hard cap on POL, which will continue to be issued, with an annual issuance rate of about 2% after June 2025. Nailwal also mentioned that POL has entered deflation starting January 2026, citing data from his "ChatGPT Analyst" that Polygon's revenue in 2026 will be $24.5 million, higher than Arbitrum's $8.41 million and Near's $5.6 million.

macOS malware can bypass Telegram's two-factor authentication to steal cryptocurrency wallets and account permissions

According to FinanceFeeds, security researchers have discovered an information-stealing malware targeting macOS devices that is attacking cryptocurrency users. This malware can hijack Telegram Desktop sessions, steal passwords and wallet databases, further controlling user accounts and stealing digital assets. Currently affected wallets and applications include software wallets like Exodus, Atomic, Electrum, Wasabi, and Monero.The malware is capable of extracting sensitive information from macOS Keychain, Safari Cookies, Apple Notes, Telegram Desktop, and multiple cryptocurrency wallet-related databases, including login credentials, authenticated session files, wallet data, and browser extension information. Security analysis points out that the danger of this attack chain lies in its reliance not on a single wallet vulnerability, but on collecting various types of data from the device, linking device intrusion, account takeover, wallet cracking, and mnemonic phrase theft together. Among these, Telegram Desktop sessions have become a key target.Attackers can copy authenticated Telegram local session data and restore the login on another Mac device without needing to enter a phone number, verification code, or Telegram two-factor authentication password. This means that Telegram 2FA cannot provide complete protection in this attack scenario, as the attacker is not performing a new login but is exploiting an already trusted local session. For cryptocurrency users, the risks are further amplified. Since Telegram is widely used for exchange customer service, project communities, OTC trading, and wallet communication, once attackers gain access to user session permissions, they could impersonate the victim, read private chats, locate asset information, and even spread malicious links to contacts.

Aleo releases a white paper on privacy stablecoins, proposing a permissionless institutional-level privacy stablecoin architecture

Aleo released the privacy stablecoin white paper "Stablecoin Privacy," stating that the privacy layer is the key infrastructure missing for blockchain payment rails to be adopted by mainstream institutions. Aleo indicated that as the GENIUS Act provides opportunities for the widespread adoption of stablecoins, the issue of permanently public transaction information on public blockchains may still hinder institutions from using stablecoins in scenarios such as payroll, fund management, and vendor payments.Aleo claims that existing solutions do not adequately meet the needs of institutions in terms of privacy protection and risk management. The white paper proposes a permissionless private stablecoin architecture based on Aleo, which introduces programmable risk mitigation mechanisms while protecting transaction privacy through zero-knowledge technology and programmable smart contracts, allowing institutions to conduct private transactions without sacrificing compliance and risk control.It is reported that the team members behind this white paper have long been dedicated to research at the intersection of cryptography, policy, and financial systems. Aleo's Global Policy Director Yaya J. Fanusie, member of the Crypto Innovation Council and former Global Financial Crimes Compliance Officer at Coinbase Valerie-Leila Jaber, and cryptographer and Johns Hopkins University Computer Science Professor Matthew Green possess rare practical experience in private payments, financial regulation, and zero-knowledge cryptography.
app_icon
ChainCatcher Building the Web3 world with innovations.