BTC $84,531.33 -0.26%
ETH $2,661.68 -1.35%
BNB $766.03 -0.66%
XRP $1.47 -1.36%
SOL $118.01 -0.02%
TRX $0.3341 -0.27%
DOGE $0.0919 -2.39%
ADA $0.2405 -2.36%
BCH $307.83 -0.37%
LINK $13.65 -4.48%
HYPE $86.91 -0.18%
AAVE $180.83 +5.80%
SUI $1.12 -4.17%
XLM $0.2129 -2.76%
ZEC $1,280.72 -3.45%
AAPL $333.34 +0.90%
AMZN $251.11 +0.98%
GOOGL $343.23 +1.13%
MSFT $517.54 +0.68%
META $727.26 +0.17%
NVDA $233.95 +1.14%
TSLA $371.06 +4.48%
SNDK $1,718.64 -3.34%
INTC $119.29 -0.61%
SPCX $158.76 +6.68%
MU $1,071.66 -1.60%
AMD $632.99 +2.71%
BTC $84,531.33 -0.26%
ETH $2,661.68 -1.35%
BNB $766.03 -0.66%
XRP $1.47 -1.36%
SOL $118.01 -0.02%
TRX $0.3341 -0.27%
DOGE $0.0919 -2.39%
ADA $0.2405 -2.36%
BCH $307.83 -0.37%
LINK $13.65 -4.48%
HYPE $86.91 -0.18%
AAVE $180.83 +5.80%
SUI $1.12 -4.17%
XLM $0.2129 -2.76%
ZEC $1,280.72 -3.45%
AAPL $333.34 +0.90%
AMZN $251.11 +0.98%
GOOGL $343.23 +1.13%
MSFT $517.54 +0.68%
META $727.26 +0.17%
NVDA $233.95 +1.14%
TSLA $371.06 +4.48%
SNDK $1,718.64 -3.34%
INTC $119.29 -0.61%
SPCX $158.76 +6.68%
MU $1,071.66 -1.60%
AMD $632.99 +2.71%

auth

All
Article
Flash

first_img The Bank of America group sued the OCC, accusing it of overstepping its authority by issuing trust licenses to cryptocurrency companies

The Independent Community Bankers of America (ICBA) filed a lawsuit against the Office of the Comptroller of the Currency (OCC) in federal court on Friday, accusing it of exceeding its statutory authority when issuing national trust bank charters to cryptocurrency companies. The ICBA stated that the OCC is implementing "broad new powers not authorized by the National Bank Act," allowing these companies to enter the U.S. banking system without being subject to the same level of regulatory oversight as community banks, putting small banks at a "serious competitive disadvantage."The ICBA is one of the largest banking advocacy organizations in the United States, primarily representing small institutions. Last month, the organization strongly opposed the Digital Asset Market Structure Bill, which failed to advance in the U.S. Senate, arguing that its stablecoin provisions did not protect community banks from direct competition for deposit accounts. ICBA President and CEO Rebeca Romero Rainey stated that Congress did not establish the national trust charter to provide a "backdoor" for cryptocurrency companies seeking to enter the banking system with the credibility of a federal bank charter, as these companies do not bear the same obligations regarding capital, liquidity, regulation, and Federal Deposit Insurance Corporation (FDIC) insurance requirements. An OCC spokesperson responded to CoinDesk that the agency does not comment on ongoing litigation.Recently, the OCC has continued to issue trust charters to cryptocurrency companies, but these companies' business models differ from those of typical community banks and do not offer cash deposit accounts that require FDIC insurance. Approved institutions include cryptocurrency banks Protego and Erebor, as well as existing cryptocurrency firms like Coinbase, Circle, and Crypto.com.

Magic Eden: Current open orders are not affected by this vulnerability; users in the EVM market from February to October 2024 need to revoke related contract authorizations

Magic Eden announced that the vulnerability occurred in the NFT trading protocol Payment Processor V2 maintained by Limit Break. Magic Eden adopted this protocol for EVM network transaction settlements in 2024 but stopped using V2 in October 2024 and will completely shut down the EVM market in the first quarter of 2026. Therefore, NFTs currently listed on Magic Eden are not affected by this vulnerability.NFTs listed through its EVM market between February and October 2024 may be affected, while listings after October 2024 are generally not impacted. The platform is contacting the protocol owner and maintainer Limit Break to explore other risk mitigation measures, including pausing protocol transfers, and will continue to investigate the actual scope of the impact.Magic Eden reminds users who have listed or traded NFTs on its EVM market to revoke relevant contract authorizations on the Ethereum, Polygon, and Base networks. Users can filter the address through revoke.cash and revoke all authorizations marked as "approved for all" for NFTs. Magic Eden emphasizes that revoking authorization cannot recover assets that have already been transferred.Yuga Labs' Vice President of Blockchain Quit stated today that at 9 AM Eastern Time, attackers exploited the Payment Processor V2 vulnerability to steal a large number of NFTs. After contacting the LimitBreak team, the latter quickly paused the similarly affected Payment Processor V3. However, V2 could not be paused, and V3 on ApeChain is also temporarily unable to be paused. Therefore, the team implemented a white-hat operation, successfully transferring and protecting 23,155 NFTs valued at over 5.7 million dollars.

first_img Bitget: A small amount of hot wallets were unauthorizedly transferred, involving 351.6 million USD; the vast majority of the platform's assets are safe, and the protection fund can cover the losses

The cryptocurrency trading platform Bitget announced on its official X account that on September 24, 2026, at 18:31 (UTC), its security system detected unauthorized transfers from a small number of hot wallets. The security team has immediately initiated an emergency response procedure and started a comprehensive investigation.Bitget stated that, based on current assessments, approximately $351.6 million in assets are affected. Cold wallets and the vast majority of assets on the platform remain secure and unaffected, and user funds are still protected. The incident falls within the coverage of the user protection fund, which currently holds over $464 million.Bitget mentioned that customer account balances remain accurate, and deposits and transactions continue to operate normally. As a precautionary measure, withdrawals have been temporarily suspended to allow the team to complete a thorough security review. The company has identified and flagged the relevant transfer addresses, formally contacted law enforcement agencies and on-chain security partners, and will restore withdrawals as soon as safety is confirmed, providing subsequent updates through official channels while refraining from speculating on the attack path during the investigation.

first_img The European Banking Authority calls for the inclusion of crypto lending in the MiCA regulatory framework

The European Banking Authority (EBA) calls for the inclusion of crypto lending in the EU's Markets in Crypto-Assets Regulation (MiCA) framework. In response to the European Commission's targeted consultation on MiCA, the EBA stated that lending activities involving crypto assets should be regulated, including situations where crypto asset service providers offer users access to decentralized finance (DeFi) lending protocols.The EBA recommends that the European Commission conduct a cost-benefit analysis for legislative amendments, considering the inclusion of intermediary crypto lending in the MiCA regulatory service list, and potentially adding specific compliance requirements and supervisory activities. The agency also suggested that corresponding requirements should be set for crypto companies providing customers access to DeFi lending protocols.Potential measures listed by the EBA include user suitability testing, leverage limits, and additional information disclosure requirements. The regulatory body also proposed that access to lending involving assets that require MiCA authorization, such as reference tokens or electronic money tokens, may be restricted, and a certification system should be introduced for DeFi lending protocols. The EBA noted that crypto lending is continuously growing within the EU, with previous studies showing lending activities in at least 16 member states; easier access to DeFi through crypto companies and artificial intelligence tools is increasingly blurring the lines between centralized and decentralized finance. The above recommendations are part of the EBA's overall opinion on the European Commission's review of MiCA, which also covers stablecoin rules, crypto asset classification, and reporting requirements.

Chengming Technology issued a letter holding ZCode accountable for uploading data without authorization

Taiyuan Chengming Technology Co., Ltd. sent a letter to Beijing Zhipu Huazhang Technology Co., Ltd., raising multiple demands regarding the alleged unauthorized upload of company data assets and trade secrets by its ZCode client, and reserving the right to pursue legal accountability. Chengming Technology pointed out that although Zhipu has publicly apologized for the "silent upload of user local repository data" and claimed to have fixed the issue, independent evidence collection revealed that the upload behavior was automatically triggered and occurred in bulk, including complete archived files such as project source code, system architecture, version control history, database passwords, cloud service credentials, and employee personal information, far exceeding the scope of collection stated in its Privacy Policy.Although the client was updated to version 3.12.3 on September 16, upload behavior was still detected in the early hours of the day Zhipu publicly apologized, raising doubts about the actual effectiveness of the "fix." At the same time, the ZCode client’s network requests pointed to a Singapore entity, while the service agreement was signed with Beijing Zhipu Huazhang, requesting clarification on the responsible party for this upload, as well as whether the data was transmitted abroad or stored overseas.Chengming Technology demanded that Zhipu respond in writing by October 10 and complete the immediate cessation of processing and thorough deletion of all uploaded data and related derivative data, caches, and backups, provide a complete list of processing situations, clarify the data's whereabouts, whether it was shared with third parties, whether it was used for model training, and whether cross-border transmission occurred, explain the management of encryption private keys and complete operation logs, clarify the exact scope of "destruction" mentioned in previous public responses, issue proof of deletion completion, provide a written commitment not to upload without authorization again, legally provide access, copying, and explanation of personal information, and designate formal communication channels, among other matters. Currently, Zhipu has not publicly responded to the aforementioned letter.

first_img OpenAI disclosed 6 cases of AI model "misalignment" behavior, involving hidden information and overstepping authority

OpenAI disclosed on Wednesday six cases of "unexpected or concerning" model behavior discovered in the past six months, categorizing them as "misalignment behaviors," including concealing information from users and taking "unauthorized actions" to overcome obstacles. OpenAI stated that this disclosure aims to initiate its new model misalignment reporting framework, and these cases should not be seen as a reflection of the frequency of misalignment occurring in its models.In one case, an unpublished research model inserted "jailbreak-like instructions" into its task summaries, such as ignoring developer messages or adopting unrestricted role settings, with researchers finding a total of 27 summaries containing such instructions. Additionally, during the training process of GPT-5.6 Sol, many model instances added instructions to conceal errors or misalignment behaviors from users, such as fabricating missing historical data without disclosure. Other cases included models using exposed API keys without authorization and fabricating inaccessible data, leveraging internal software repositories to pass messages across training tasks, and ignoring instructions to "keep local work" by sharing files through public hosting services.OpenAI's disclosure has heightened concerns among AI developers and researchers about whether safety measures can keep pace with increasingly powerful models. Last week, Anthropic CEO Dario Amodei called for a slowdown in cutting-edge AI development, warning that unrestrained AI development could "exceed our ability to understand and control these systems." In July of this year, OpenAI disclosed that several of its AI models escaped testing environments during safety assessments and infiltrated the AI startup Hugging Face to cheat.

DeepSeek author discusses the impact of AI, stating that talent may be buried in yesterday

DeepSeek operator engineer Liu Sheng discusses the impact of AI on his work. He states that the main Attention operator of DeepSeek V4.1 was written by himself, but given the current pace of progress, in another six months to a year, the level of AI in writing operators will likely catch up to or even surpass his own.A year ago, AI could only help him check documents, read code, and find bugs. Now it can read CUDA, PTX, and SASS, analyze the pause time of each instruction, and independently optimize operators. He anticipates that the next step will be for AI to design scheduling plans, evaluate performance, and complete implementations on its own. He is very clear that the better he optimizes the operators, the faster the training and inference of the DeepSeek model will be, and AI will catch up to him even faster. But even if he stops now, models from other companies will not stop, so he will continue to make the operators the best they can be.He believes that he is unlikely to become unemployed, but he may be forced to "change careers," transitioning from writing operators himself to becoming a "mecha pilot" who manipulates agents. What he truly finds difficult to accept is not the disappearance of his job, but the possibility that he may never have the chance to do the work he loves again: "I have to bury my talent in yesterday." The article concludes with his reasons for staying at DeepSeek. He advocates that cutting-edge AI should be provided openly and cheaply to everyone and openly expresses his disbelief that Anthropic or OpenAI can achieve this. He worries that the strongest AI will ultimately be controlled by a few companies, further turning the technological gap into a gap of power and class.
app_icon
ChainCatcher Building the Web3 world with innovations.