ChainFeeds briefing highlights FomoPeek malware, Gen Z trading habits and Binance delisting rules

ChainFeeds briefing highlights FomoPeek malware, Gen Z trading habits and Binance delisting rules

N
News Editor
2026-09-22 01:51:17
ChainFeeds’ Sept. 22 research briefing pulled together five separate pieces spanning tokenized equities, mobile wallet security, crypto market structure and exchange listings. One note argued that the market may be overstating the scope of the U.S. Securities and Exchange Commission’s innovation exemption for tokenized stocks, drawing a legal distinction between native or custody-backed tokenized equities and synthetic products that merely track names such as AAPL or NVDA. Another report, citing SlowMist, described how FomoPeek versions 1.1 and 1.2 on Apple’s App Store allegedly carried two malicious modules with remote configuration, exploit and cross-app data collection capabilities, and said 19 wallet and note-taking apps were included in collection targets. The same briefing also recapped a view from Noah Goldberg that reflexivity-driven alpha in crypto has not fully disappeared, even as AI compresses traditional forecasting edges. On the market side, Binance Research data cited by Cryptoslate showed Gen Z users were directing a larger share of stock allocations into unleveraged ETFs, trading less frequently than Millennials and Gen X, and behaving more like net accumulators than short-term speculators. IOSG Ventures, in a separate section, examined Binance’s 2026 delistings and argued that spot and derivatives operate under two very different survival filters, with FDV and open interest carrying more signal than raw trading volume.

ChainFeeds puts out its Sept. 22 research roundup

ChainFeeds published its Daily research brief for Sept. 22, pairing the day’s top headlines with a longer digest dated Sept. 21. The edition zeroed in on five questions: has the market exaggerated the upside for tokenized equities under the U.S. Securities and Exchange Commission’s innovation exemption, what exactly happened in the FomoPeek malware case, what HYPE reveals about reflexivity in crypto, whether Gen Z is turning into a more conservative investing group, and what Binance delistings suggest about the rules for staying listed.

ChainFeeds briefing highlights FomoPeek malware, Gen Z trading habits and Binance delisting rules 2

The brief also ran through several Sept. 22 headline items: decentralized prediction market Trueo intends to migrate from Base to Ethereum mainnet; Nillion said Dusk is scheduled to go live on Ethereum mainnet in October and that the first Covenants application is already live on testnet; Strategy was shown sitting on an unrealized BTC gain of $8.209 billion while BitMine was carrying an unrealized ETH loss of $3.674 billion; GMGN began public testing for perpetual contracts; and a Multicoin co-founder said SOL would overtake ETH by market capitalization in this cycle, adding that "hardly anyone actually uses Ethereum."

What the SEC exemption covers in tokenized stocks — and what it does not

In the first long English thread highlighted by ChainFeeds, 100y.eth💜 | a41 said the real issue is simple: what counts as a “tokenized NMS stock”? The post argued that the SEC has, in practice, recognized two structures that matter here.

One is issuer-native tokenization. That means the listed company itself, or someone acting for it, tokenizes actual shares. In that arrangement, the shares can be viewed as being registered directly on-chain by a transfer agent. So the token is the security itself, not some wrapped product that just mirrors the stock price.

The second structure is third-party custody-based tokenization. Here, a third party keeps the underlying shares inside the traditional securities system and tokenizes the investor’s ownership interest or security entitlement. The thread was explicit on the rights question: token holders have to receive the same rights and entitlements as holders of the matching traditional shares, including dividends and voting rights.

What does not make the cut, the post said, is synthetic exposure. If a third party issues its own note, derivative, tracker certificate, or security-based swap that merely follows the price of AAPL or NVDA, that product does not fit the exemption’s definition of a tokenized NMS stock. And that matters. The author’s point was that market reaction has run far past the actual boundaries of the exemption. Tokens like BP, ONDO, HYPE and LIT have all been folded into the story, even though their links to the policy are very different.

ONDO, in the summary’s telling, has the cleaner connection because Ondo has been building a custody-based tokenization setup where the underlying securities stay inside a regulated custody structure while on-chain tokens represent rights tied to those assets. HYPE and LIT stock perpetuals are a different animal. They are derivatives, and they are not the products the SEC exemption was aimed at.

Then the piece moved to Backpack. The market’s standard argument, it said, has been that Backpack tokens are redeemable 1:1 for real shares, which would make them true equity tokens and direct winners from the SEC move. But the author said that skips a legal distinction that really does matter. Backpack itself splits the products into two forms: traditional Backpack securities, which it describes as security entitlements under UCC Article 8, and Backpack Tokens on Solana, which it describes as tokenized claims against an SPV holding the underlying assets. Those are not the same legal instrument. When a user withdraws a traditional stock position from Backpack onto-chain, the original Article 8 security entitlement is not simply shifted onto Solana. It gets converted into a different tokenized instrument, one that can later be redeemed through Backpack Securities on a 1:1 basis back into the corresponding traditional security entitlement.

SlowMist says the App Store versions of FomoPeek included malicious modules

The second item was about FomoPeek. Citing a Sept. 20 report from blockchain security firm SlowMist, Foresight News said the on-chain monitoring tool FomoPeek — which had been listed on Apple’s App Store — contained two malicious modules, apptrace and libapptracecore, in versions 1.1 and 1.2. According to the report, those modules could handle remote configuration, use kernel exploits, escape the sandbox, decrypt Keychain data and collect data across apps.

The probe started after several users reported stolen assets. These cases involved private-key exposure, and some of the affected users had run versions 1.1 or 1.2 before the thefts. SlowMist reviewed historical installation packages and found that version 1.0, first released on Aug. 29, did not include the modules. Version 1.1, released on Sept. 9, introduced the code for the first time. Version 1.2, released on Sept. 12, kept it. By Sept. 16, social platforms already had warnings from users saying assets were stolen after downloading the app. Version 1.3, released on Sept. 17, removed both modules, and the package size fell from 10.47 MB to 1.81 MB.

SlowMist said the main app and the two modules all used the same Apple developer signing identity, while the original packages still contained encrypted metadata used for App Store distribution. That let researchers confirm the malicious modules were already inside the official versions submitted by the developer. So yes, users could have ended up with the affected builds even if they never installed enterprise-signed software and never downloaded the app from a third-party website.

SlowMist separated the two modules by function. apptrace was used for communication with the attacker’s command-and-control server. libapptracecore held the exploit and data-collection code. In testing, researchers captured a list with 135 application identifiers. That gave the server a way to see which wallets were installed on a device, then send that device collection targets without asking the user to select wallet names or type them in manually.

ChainFeeds briefing highlights FomoPeek malware, Gen Z trading habits and Binance delisting rules 3

In the attack chain reconstructed by SlowMist, the framework then picked an exploit route based on the iOS version and device model and tried to obtain kernel-level access beyond ordinary app permissions. If that worked, the malware could get around access limits, read other app directories and try to extract and decrypt sensitive data stored in Keychain. The code included eight exploit strategies and said it was compatible with iOS 12.0 through 18.7.2 and 26.0 through 26.1.

During isolated testing, researchers received collection configurations for 19 wallet and note-taking apps, among them MetaMask, OKX Wallet, Trust Wallet, imToken, TokenPocket and TronLink. They also captured a compressed upload package containing the Apple Notes database and related files.

Using a main attacker address examined in the report by MistTrack, SlowMist’s tracking tool, the report said the address had been active since Sept. 15 and had received a cumulative 579,984.34 USDT by the time the report was published. The funds moved across Ethereum, BNB Chain and Arbitrum, with most of the money consolidated on Ethereum before being sent out in batches.

SlowMist’s advice was blunt. Users who had run FomoPeek 1.1 or 1.2 should stop using the app, should not reinstall it, and should treat all related seed phrases, private keys and other credentials as compromised. The report added that removing the modules in version 1.3 only means that build no longer includes the code; it does not pull back any data that may already have been uploaded. Asset migration, it said, needs to be done on a trusted, updated device that has never had FomoPeek installed, and any new wallet has to be created with a completely new seed phrase. Importing an old seed phrase into another wallet still restores the same account. Changing an app-level unlock password does not replace the on-chain private key. And revoking token approvals does not stop someone who already controls that private key from signing fresh transactions.

Noah Goldberg on HYPE, AI and the shrinking space for alpha

The third article cited by ChainFeeds came from Noah Goldberg, who asked what HYPE’s success says about reflexive alpha in crypto. He opened with AI and investing. Goldberg wrote that investors may wind up relying on AI forecasting tools that can assign highly accurate probability distributions to almost any future event, with market prices absorbing that information quickly and drifting closer to a random walk.

He argued that AI is moving fast toward a point where its predictive ability may be plainly better than that of the best human forecasters. And maybe that is not bad, he wrote, because finance may already be overcrowded. If alpha gets squeezed down to the efficient frontier and only large funds can still pay for data, networks and compute, public markets may still allocate capital well even with fewer professional investors.

Private markets, in his view, may hang on to some interpersonal features that machines do not easily replace. But even there, things could start looking more like institutional sales over time. Companies and investors may simply get better at estimating fair prices, leaving excess return to depend more on access to deals and the ability to negotiate better terms.

Goldberg also said investors often misunderstand why past stars did well, mistaking factor exposure for alpha generation. He compared it to a recent graduate trading tech stocks during the technology bubble: optimism, or even plain naivety, can push someone into taking big risks right when the market is rewarding risk, while the exposure itself stays fuzzy enough that many people fail to see what is really happening.

He pushed that argument into quality investing too. Funds centered on high-quality companies that had not yet clearly lagged the market may still be operating on the same logic, he wrote, just with a lag in how monetary policy feeds through. He pointed to Costco and Walmart, which did not begin underperforming the broader market until 2025, partly because they had been able to pass higher prices on to consumers. As inflation and Treasury yields lifted required returns, their growth rates also increased for a period and offset valuation pressure. Only when long-term rates hit a level that price growth could no longer match did that support start to fade. He added that the same pattern may hold for the remaining compounding winners in megacap technology, since a meaningful share of GDP growth has come from AI-related spending that then feeds into advertising and cloud computing, the core revenue lines of those companies.

Back in crypto, Goldberg said token economics created a new set of market games, and those mechanisms are now being arbitraged in a systematic way. So markets may be entering a period where real alpha gets harder to find and what remains looks much more like factor performance. Reflexivity in crypto, he wrote, can still be a source of alpha, or it can be treated as a return factor. Influencing long-term outcomes through reflexive mechanisms and making money from that still takes skill, but whether the market accepts those games depends heavily on path. His final point was pretty stark: as more people compete for limited social attention by building narratives, the cost of moving markets rises and the payoff shrinks. That cost includes both reputation and capital. Building a new Layer 1 through money and narrative alone, he wrote, now takes more funding and offers lower odds of working.

Binance Research data suggests lower turnover and heavier ETF use among Gen Z

The fourth item summed up a Cryptoslate report built on Binance Research data released on Aug. 12. It looked at how different generations use direct equities, tokenized equities called bStocks and TradFi perpetual contracts. Across all three product buckets, Gen Z posted the lowest turnover among working-age cohorts.

The clearest gap showed up in ETFs. By early August, ETFs accounted for 25% of Gen Z direct equity trading volume, up from 14.6% in June. For Millennials, the comparable number was 9.5%. On the flow side, unleveraged ETFs climbed from 18.5% of Gen Z stock net inflows in June to 21.9% in July, while the share going into individual stocks slipped from 77% to 74.2%.

ChainFeeds briefing highlights FomoPeek malware, Gen Z trading habits and Binance delisting rules 4

In July, Gen Z’s total net stock investment dropped 17.4%. But net inflows into unleveraged ETFs fell only 2%. Net inflows into individual stocks and leveraged products fell 20.4% and 28.5%, respectively. Gen Z was also the only cohort in Binance’s dataset to show growth in the number of ETF holders during July, with a 2.9% increase.

The report said Gen Z’s trading habits did not fit the usual stereotype of hyperactive retail speculation. Among Gen Z accounts that had bought but never sold, the largest average direct-equity ticket size was in the Schwab U.S. Dividend Equity ETF, SCHD, at $16,567, followed by Broadcom at $12,370. Portfolio preferences did lean toward semiconductors and AI. Even so, some of the names most often tied to retail speculation had far smaller average purchase sizes, including Tesla at $633 and Nvidia in bStocks at $514.

About 76% of Gen Z bStocks accounts were net accumulators, the highest share of any generation and 9 percentage points above Millennials. In direct equities, that figure hit 77%, ahead of Gen X at 74% and Baby Boomers at 68%. The report’s implication was straightforward: in products that resemble asset ownership more than short-dated derivatives, Gen Z users were adding to positions instead of churning them.

The gap got wider in leveraged products. Gen Z accounts averaged 13 TradFi perpetual trades per month, below 17 for Millennials, 16.5 for Gen X and 19 for Baby Boomers. Just 14% of Gen Z perpetual accounts counted as high-frequency traders. At the same time, 88.2% of Gen Z TradFi perpetual accounts had no leveraged or inverse ETF trades, and that share rose to 98.9% in bStocks. In July, leveraged and inverse ETFs made up 9.25% of Gen Z direct-equity trading volume but only 3.93% of net inflows, then fell to 2.65% by early August. TradFi perpetuals showed the same kind of split: around 60% of Gen Z accounts were net buyers, yet actual net capital flow was less than 1% of total traded volume. In direct equities, by contrast, net capital flow reached 26.5%, averaging $1,898 in net inflow per account.

IOSG says Binance spot and derivatives use opposite delisting logic

The fifth piece, from IOSG Ventures, looked at Binance’s token delistings in 2026 and argued that spot and derivatives are judged by two very different survival models. The analysis centered on token origin, fully diluted valuation, trading volume and open interest.

The first split was age. Spot delistings have been getting older, while derivatives delistings have been getting newer. Median survival time at delisting for spot tokens rose from 4.1 years in 2022 to 5.1 years in 2026. For derivatives, it dropped from 1.3 years to 0.8 years. Of the 42 spot tokens removed, 31 had been listed in 2021 or earlier, and PIVX, FUN and LRC each lasted 8.6 years. All 28 derivatives delisting events involved contracts launched after 2024, 23 of them listed in 2025, and 11 surviving less than six months.

IOSG said Binance’s historical listing data makes the contrast hard to miss. The exchange has listed 1,114 assets in total: 284 on spot only, 474 on both spot and derivatives, and 356 on derivatives only. Among the derivatives tokens delisted in 2026, 93% had never been listed on spot, meaning they never entered the pool tied to custody, node maintenance and compliance commitments. IOSG described derivatives as a low-commitment quotation layer — cash-settled, non-custodial and not an endorsement — which allows Binance to list a hot narrative fast and remove it just as fast. Spot was described differently: a custody-and-endorsement layer, where every listed asset implies long-term wallet, node and compliance responsibilities. Read that way, spot removals are a cleanup of old inventory, while derivatives removals are a retreat from speculative trial exposure.

Sector mix split as well. In 2026 spot delistings, DeFi accounted for 16 tokens, or 38%; Gaming/NFT for 9, or 21%; Infra/L1/L2 for 8; and DePIN/Data for 5. The first two groups together were close to 60%, and most of those assets had been listed in 2020 or 2021, with 20 of the 42 names concentrated in those two years. Derivatives looked different. Infra/L1/L2 accounted for 10 names, DeFi 4 and Meme 4, suggesting that newer narratives were the main cleanup target.

IOSG also said Binance’s own issuance channels showed up heavily. Among derivatives tokens delisted in 2026, 63% came from Binance Alpha Spotlight, including ZKJ, PUFFER, TANSSI and YALA. On the spot side, 11 of the 42 names, or 26%, came through Launchpool or Launchpad, including NTRN, RDNT, HIGH, MBOX and HFT. IOSG pointed to A2Z as the most extreme case: a Launchpad project listed on spot in July 2025 and delisted in April 2026 after eight months. The paper’s message was blunt enough: Alpha or Launchpool can bring distribution and exposure, but they do not buy a permanent seat.

On the metrics side, IOSG said FDV separated winners and losers much better than turnover. Using a 10m FDV threshold, the delisting rate fell from 49% to 16%, spanning two orders of magnitude. Trading volume between 100k and 3m, by comparison, was almost flat, with delisting rates ranging from 10% to 18%. A quartile comparison showed the same thing. Median FDV in the spot-delisted group was $10.53 million, versus $56.88 million for the still-listed group, a 5.4x gap. Median trading volume was $650,000 versus $1.19 million, only a 1.8x difference.

For derivatives, the delisting rate was 31% when OI sat below 1m and 0% when OI was above 20m. Median OI was 1.21m for the delisted group and 3.13m for contracts that stayed listed. Even then, 2.8% of contracts in the trading-volume bucket above 100m were still delisted. IOSG’s view was that volume can be distorted pretty easily by wash trading, high-frequency strategies or short-term churn. Even daily prints in the millions of dollars may be little more than cheap internal noise in a shallow pool. FDV, in its reading, is a better proxy for a project’s embedded capital base and its ability to resist sell pressure, while OI captures the actual margin and risk capital sitting in the market.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.