North Korea h2026-09-20 00:51:39North Korea-linked WaterPlum used fake job offers to steal at least $10.71 million, agencies warnA joint warning from the U.S. Federal Bureau of Investigation, Japan’s National Police Agency and other international authorities says the North Korea-linked hacking group WaterPlum, also known as Contagious Interview, ran a fake recruitment campaign targeting IT developers worldwide. According to the alert, the group posed as companies in the AI, cryptocurrency and NFT sectors between December 2025 and July 2026 and approached job seekers through social media and recruiting platforms. Victims were told to complete technical interviews or coding tests, then tricked into downloading malicious files. The warning says the operation infected more than 30,000 devices across over 100 countries and regions and stole data from more than 7,000 crypto wallets. At least $10.71 million was transferred into wallets controlled by the attackers. The case was highlighted in a multi-agency alert cited by Odaily.550
CFTC2026-09-17 21:29:54CFTC Staff Says Wallets Can Offer Regulated Perps Without Broker RegistrationStaff at the U.S. Commodity Futures Trading Commission said Thursday that software developers may integrate regulated derivatives trading into self-custodial crypto wallets without registering as brokers, provided they meet a set of stated conditions. The guidance came in Staff Letter 26-25 from the CFTC’s Market Participants Division, which said it would not recommend enforcement against providers of passive software for failing to register as introducing brokers, or against related personnel for failing to register as associated persons. The position extends relief that had previously been available only to Phantom Technologies under Letter 26-09, issued in March. According to the division, other similarly situated passive software providers later sought the same treatment. Under the new letter, covered software can route user orders directly to registered exchanges, futures commission merchants, or introducing brokers for products including event contracts, perpetual contracts, and other CFTC-regulated derivatives. The relief comes with 10 conditions, including user disclosures, compliance with National Futures Association marketing rules, and joint-and-several liability undertakings between the software provider and each venue or broker it works with. The division also said its position is not binding on the full Commission and will remain in place only until the CFTC adopts a rule or guidance on when software developers must register. The relief is not limited to crypto software.360
CFTC2026-09-18 01:49:22CFTC eases registration stance for passive software providers tied to regulated tradingThe U.S. Commodity Futures Trading Commission said on Sept. 18 that its Division of Market Participants has issued a no-action position for certain "passive software" providers. Under the guidance, staff will not recommend enforcement action if a provider has not registered as an introducing broker or associated person, provided specific conditions are met and the software only helps users trade with regulated futures commission merchants, introducing brokers, or designated contract markets. The covered platforms also cannot custody user assets or make trading decisions on a user’s behalf. The measure expands a case-specific arrangement granted in March this year to crypto wallet Phantom and extends the approach to other qualifying software providers. According to BlockBeats, industry participants said the move could make it easier for crypto wallets, websites, and other online platforms to connect users to regulated prediction markets and other CFTC-regulated products. The guidance is being viewed as supportive of product development and innovation in crypto market tools.340
CFTC2026-09-18 01:44:28CFTC expands passive software relief, letting crypto wallets connect to regulated derivatives venues without broker registrationThe U.S. Commodity Futures Trading Commission has widened its no-action relief for "passive software" providers, opening the door for crypto wallets, DeFi wallets, and other applications to connect users to regulated derivatives exchanges and prediction markets without registering as introducing brokers. The move extends beyond the agency’s March relief for Phantom Technologies and sets out a broader compliance path for software providers that act only as access points. The relief is not open-ended. To qualify, providers cannot exercise discretion over user orders, cannot handle customer funds, and must remain limited to passive access functions. In practical terms, the wallet can serve as a bridge, but it cannot trade on a user’s behalf or operate like a traditional intermediary. The timing also stands out. The CFTC action came two days after the CLARITY bill failed to advance in the Senate, where a cloture motion received 49 votes, short of the 60-vote threshold. On the same day, CFTC Chair Michael Selig and SEC Chair Paul Atkins each signaled that rulemaking would continue even without congressional legislation, and the SEC separately approved temporary relief for tokenized U.S. stock trading on qualified on-chain venues.410
CFTC2026-09-18 03:56:03CFTC broadens no-action relief for software providers connecting wallets to regulated derivatives marketsThe U.S. Commodity Futures Trading Commission’s Market Participants Division issued Staff Letter 26-25 on Sept. 17, extending a no-action position that had previously applied only to Phantom Technologies to all qualifying passive software providers. The move lowers the barrier for crypto wallets, trading interfaces, and other software developers to connect users to CFTC-regulated derivatives markets without first registering as Introducing Brokers, provided they act as access points rather than brokers. Under the framework, eligible software can display market data, aggregate positions, present product information, and transmit user orders for futures, perpetual contracts, and event contracts to regulated entities. The letter also allows certain revenue-sharing arrangements and transaction-based fees. At the same time, the CFTC drew firm limits: software providers cannot hold or control customer assets, cannot generate explicit buy or sell signals, and cannot determine order routing or execution. The relief is not a blanket exemption. Letter 26-25 sets out 10 conditions, including disclosure of relationships and conflicts, risk disclosures, recordkeeping, and written commitments with each partnering CFTC-registered entity under joint and several liability. The agency also said the position reflects the view of the Market Participants Division only and may be changed, suspended, or terminated if facts change or formal rules are introduced later.340
European Unio2026-09-14 11:38:44EU cyber rules give crypto wallet makers 24 hours to report exploited flawsCryptocurrency wallet providers in the European Union now face a tight disclosure schedule under the bloc’s Cyber Resilience Act. The new rules require hardware and software wallet makers to file an early warning within 24 hours after becoming aware of an actively exploited bug or severe vulnerability affecting their products, then submit a full notification within 72 hours. A final report must follow 14 days after corrective or mitigating measures become available, while severe incidents must be fully reported within one month. The reporting regime applies to products with digital elements made available in the EU, not only crypto wallets, and sits within the European Commission’s broader cybersecurity strategy. Penalties are steep: companies that fail to comply with Articles 13 and 14 can face fines of up to 15 million euros, or 2.5% of worldwide annual turnover, whichever is higher. Supplying incorrect, incomplete or misleading information can trigger fines of up to 5 million euros. The move comes after recent security incidents involving wallet providers and related service vendors, including Trezor’s disclosure that 67,000 additional US customers were exposed in a breach tied to shipping provider ShipMonk, phishing warnings issued by Trezor and BitBox, and a June warning from Zilliqa about a flaw in the Zilliqa Ledger app that could expose private keys.360
European Unio2026-09-14 11:57:41EU Cyber Resilience Act Takes Effect, Crypto Wallet Vendors Face 24-Hour Vulnerability Reporting RuleThe European Union’s Cyber Resilience Act has taken effect, setting firm disclosure deadlines for makers of cryptocurrency software and hardware wallets. Under the rule, providers that discover an actively exploited vulnerability or a severe security flaw in their products must file an initial warning within 24 hours and submit a full notification within 72 hours. Manufacturers must then provide a final report within 14 days after a corrective fix or mitigation becomes available. Separate reporting obligations also apply to severe incidents, which must be reported within one month. The penalty framework is also substantial. Companies that fail to comply can face fines of up to €15 million or 2.5% of global annual turnover, whichever is higher. Firms that submit incorrect, incomplete, or misleading information can be fined up to €5 million, according to Cointelegraph as cited by Odaily.730
EU2026-09-14 11:51:35EU Cyber Resilience Act Takes Effect With Tight Breach Reporting Rules for Crypto Wallet ProvidersThe European Union’s Cyber Resilience Act, or CRA, officially took effect on Sept. 11, setting stricter incident-reporting obligations for providers of crypto hardware and software wallets sold in the EU market. Under the new rules, firms must file an early warning report within 24 hours after discovering an actively exploited vulnerability or a severe security flaw, then submit a full notification within 72 hours. After corrective or mitigation measures are taken, manufacturers must provide a final report within 14 days, while severe incidents must be fully reported within one month. The European Commission said the reporting framework is meant to better protect consumers and businesses from cyber threats. The rules apply to all products with digital elements offered on the EU market and form part of the bloc’s broader cybersecurity strategy. Penalties in the final draft are substantial: companies that fail to comply with Articles 13 and 14 may face administrative fines of up to €15 million, roughly $17.3 million, or 2.5% of global annual turnover, whichever is higher. Firms that submit incorrect, incomplete, or misleading information may be fined up to €5 million. The measure comes after several security incidents involving wallet providers. Trezor said on Sept. 4 that a data breach at logistics vendor ShipMonk affected about 67,000 U.S. customers, above the initial estimate of 14,000. This week, Trezor and BitBox also warned users about phishing emails disguised as urgent security notices. In June, Layer-1 blockchain network Zilliqa said a flaw in its Ledger app could allow attackers to recover private keys using public on-chain data.850