BTC $84,477.57 -0.26%
ETH $2,663.88 -1.33%
BNB $765.87 -0.65%
XRP $1.48 -1.19%
SOL $118.14 +0.07%
TRX $0.3342 -0.26%
DOGE $0.0920 -2.29%
ADA $0.2410 -2.12%
BCH $308.00 -0.29%
LINK $13.68 -4.26%
HYPE $86.99 -0.17%
AAVE $181.04 +5.87%
SUI $1.12 -4.51%
XLM $0.2133 -2.66%
ZEC $1,285.39 -3.62%
AAPL $333.31 +0.88%
AMZN $251.11 +0.96%
GOOGL $343.23 +1.14%
MSFT $517.54 +0.62%
META $727.26 +0.20%
NVDA $233.95 +1.14%
TSLA $371.13 +4.49%
SNDK $1,717.80 -3.43%
INTC $119.25 -0.64%
SPCX $158.69 +6.67%
MU $1,070.52 -1.69%
AMD $632.99 +2.71%
BTC $84,477.57 -0.26%
ETH $2,663.88 -1.33%
BNB $765.87 -0.65%
XRP $1.48 -1.19%
SOL $118.14 +0.07%
TRX $0.3342 -0.26%
DOGE $0.0920 -2.29%
ADA $0.2410 -2.12%
BCH $308.00 -0.29%
LINK $13.68 -4.26%
HYPE $86.99 -0.17%
AAVE $181.04 +5.87%
SUI $1.12 -4.51%
XLM $0.2133 -2.66%
ZEC $1,285.39 -3.62%
AAPL $333.31 +0.88%
AMZN $251.11 +0.96%
GOOGL $343.23 +1.14%
MSFT $517.54 +0.62%
META $727.26 +0.20%
NVDA $233.95 +1.14%
TSLA $371.13 +4.49%
SNDK $1,717.80 -3.43%
INTC $119.25 -0.64%
SPCX $158.69 +6.67%
MU $1,070.52 -1.69%
AMD $632.99 +2.71%

upgrade

All
Article
Flash

first_img Core Lightning warns that old version nodes are under attack and urges operators to upgrade immediately

The Core Lightning team, which develops the open-source Bitcoin Lightning Network node software, has issued an urgent alert stating that reports indicate attackers are targeting nodes that have not installed patches, urging operators still running old versions to upgrade immediately. The team stated: "Emergency security update: If you are using version 26.06.7 or earlier, please upgrade to the latest release as soon as possible."Prior to this, Core Lightning began investigating a potential issue that could affect its experimental features and, in turn, impact user funds on September 16, and approximately six days later, version 26.06.8 was released. This update not only fixed several defects but also provided patches for security vulnerabilities reported responsibly by multiple parties, thanking the Bitcoin Red Team and 12 other individuals and organizations in the release notes, while also acknowledging anonymous reporters.According to the changelog, this round of fixes covers a bug that could cause sender nodes to crash, requests that could exhaust REST interface memory, and a vulnerability that could result in user funds facing confiscation losses when closing payment channels. To provide operators with ample upgrade windows and prevent attackers from taking advantage of reverse engineering and exploitation, this version intentionally obscured some testing content. Additionally, in August of this year, the project initiated a collaborative fixing process after reviewing a large number of AI-generated general vulnerability disclosure reports, and two days later released version 26.06.7 to close confirmed vulnerabilities.

first_img SEC updates cryptocurrency FAQ, stating that token buybacks and network upgrades do not necessarily constitute securities

The U.S. Securities and Exchange Commission's Division of Corporation Finance updated its frequently asked questions document on cryptocurrency assets on Friday, clarifying that token buybacks, network upgrades, and marketing promotions do not automatically make cryptocurrency assets securities. The division stated that announcing a buyback plan for an already functioning cryptocurrency network does not, by itself, make the associated tokens constitute an investment contract; however, for networks that are not yet operational, if the issuer promotes the buyback as a source of returns for holders, this conclusion may not necessarily apply.Regarding the ongoing development issues of cryptocurrency projects after their launch, the document pointed out that once a cryptocurrency system is operational, services used to protect, maintain, improve, or enhance that system and its functions, or to promote network effects, do not fall under the managerial efforts referred to in the Howey test. The existing uses of marketing networks generally do not create profit expectations, and statements regarding future functionalities are similarly true, provided that profit potential is not promoted. The document reiterated that specific judgments still heavily depend on the actual circumstances of each case.This document is based on the interpretive guidance issued by the SEC in March of this year regarding the application of securities laws to cryptocurrency assets, released just weeks after the Clarity Act failed to advance in the Senate, with regulators continuing to operate under existing laws. Additionally, the U.S. Commodity Futures Trading Commission updated its cryptocurrency FAQs on Thursday, stating that futures companies and clearinghouses may invest customer funds in tokenized versions of previously permitted assets, provided that investment and custody requirements are met; regulated companies may use blockchain for record-keeping but must be able to provide relevant records when the blockchain or its block explorer is not operational.

first_img XRP Ledger restarts upgrade, allowing accounts to split payment and compliance permissions

The PermissionDelegationV1_1 upgrade of the XRP Ledger entered a 14-day activation countdown on September 21, having received support from 29 of the 35 trusted validator nodes. If the support rate remains above 80% during this period, the upgrade could officially activate as early as October 5 at 11:18 UTC; at least 28 validator nodes must continue to support it, or the countdown will reset.This feature allows accounts to split permissions by role. For example, a stablecoin issuer can allow a connected compliance system to approve customer accounts holding its tokens while keeping the keys with full control offline; operational accounts can gain payment permissions but cannot change keys or delegate authority to others. Each trustee can have up to 10 permissions, and the main account can modify or revoke them at any time.This is the network's second attempt to introduce this feature. The original version had vulnerabilities that attackers could exploit to make others pay transaction fees with improperly signed transactions, and by repeatedly submitting high-fee transactions, they could deplete the victim's XRP balance. This vulnerability was reported by community testers on September 15, 2025, and validator nodes were advised to reject the amendment, so it was never activated. The fixed version was released with xrpld 3.3.0, changing the way unauthorized transactions are rejected, ensuring that fees are not deducted before signature verification.

first_img Ripple: Asset management institutions are preparing for the payment upgrade Batch V1.1 of the XRP Ledger

According to CoinDesk, Ripple stated that asset management companies and other commercial projects are preparing to use the Batch V1.1 feature of the XRP Ledger. This feature allows up to eight transactions to be combined into a single operation and ensures that all transactions either succeed or fail in an all-or-nothing manner, avoiding situations where one party completes settlement while the other fails.This upgrade is expected to support Delivery Versus Payment (DVP) transactions, allowing asset transfers and payments to be completed simultaneously, while also enabling exchanges, wallets, and market platforms to directly attach service fees to customer transactions for processing.RippleX Engineering Director Ayo Akinyele mentioned that some projects are already being developed around Batch, and once activated, it will bring related work closer to a production environment. Specific partners and launch times will be announced once plans are finalized. The amendment has received support from 30 of the 35 tracked validators on the XRP Ledger, exceeding the 28 votes required to enter the activation countdown. The countdown began on September 15, and if the validator support rate remains above 80% within 14 days, Batch V1.1 is expected to be activated shortly after September 29.Previously, researchers discovered serious flaws in the Batch V1 signature verification process in February, which could prematurely stop checking signatures under certain conditions, allowing attackers to unauthorizedly include transactions from other accounts. The developers subsequently withdrew the original version. Since the amendment had not yet been activated at that time, the vulnerability code did not run on the live ledger, and no funds were exposed.
app_icon
ChainCatcher Building the Web3 world with innovations.