‹ BackNewsCrypto Wallets

Crypto Wallets

North Korea-linked WaterPlum used fake job offers to steal at least $10.71 million, agencies warn
CFTC
2026-09-17 21:29:54

CFTC Staff Says Wallets Can Offer Regulated Perps Without Broker Registration

Staff at the U.S. Commodity Futures Trading Commission said Thursday that software developers may integrate regulated derivatives trading into self-custodial crypto wallets without registering as brokers, provided they meet a set of stated conditions. The guidance came in Staff Letter 26-25 from the CFTC’s Market Participants Division, which said it would not recommend enforcement against providers of passive software for failing to register as introducing brokers, or against related personnel for failing to register as associated persons. The position extends relief that had previously been available only to Phantom Technologies under Letter 26-09, issued in March. According to the division, other similarly situated passive software providers later sought the same treatment. Under the new letter, covered software can route user orders directly to registered exchanges, futures commission merchants, or introducing brokers for products including event contracts, perpetual contracts, and other CFTC-regulated derivatives. The relief comes with 10 conditions, including user disclosures, compliance with National Futures Association marketing rules, and joint-and-several liability undertakings between the software provider and each venue or broker it works with. The division also said its position is not binding on the full Commission and will remain in place only until the CFTC adopts a rule or guidance on when software developers must register. The relief is not limited to crypto software.

360
CFTC Staff Says Wallets Can Offer Regulated Perps Without Broker Registration
CFTC eases registration stance for passive software providers tied to regulated trading
CFTC expands passive software relief, letting crypto wallets connect to regulated derivatives venues without broker registration
CFTC
2026-09-18 03:56:03

CFTC broadens no-action relief for software providers connecting wallets to regulated derivatives markets

The U.S. Commodity Futures Trading Commission’s Market Participants Division issued Staff Letter 26-25 on Sept. 17, extending a no-action position that had previously applied only to Phantom Technologies to all qualifying passive software providers. The move lowers the barrier for crypto wallets, trading interfaces, and other software developers to connect users to CFTC-regulated derivatives markets without first registering as Introducing Brokers, provided they act as access points rather than brokers. Under the framework, eligible software can display market data, aggregate positions, present product information, and transmit user orders for futures, perpetual contracts, and event contracts to regulated entities. The letter also allows certain revenue-sharing arrangements and transaction-based fees. At the same time, the CFTC drew firm limits: software providers cannot hold or control customer assets, cannot generate explicit buy or sell signals, and cannot determine order routing or execution. The relief is not a blanket exemption. Letter 26-25 sets out 10 conditions, including disclosure of relationships and conflicts, risk disclosures, recordkeeping, and written commitments with each partnering CFTC-registered entity under joint and several liability. The agency also said the position reflects the view of the Market Participants Division only and may be changed, suspended, or terminated if facts change or formal rules are introduced later.

340
CFTC broadens no-action relief for software providers connecting wallets to regulated derivatives markets
EU cyber rules give crypto wallet makers 24 hours to report exploited flaws
EU Cyber Resilience Act Takes Effect, Crypto Wallet Vendors Face 24-Hour Vulnerability Reporting Rule
EU
2026-09-14 11:51:35

EU Cyber Resilience Act Takes Effect With Tight Breach Reporting Rules for Crypto Wallet Providers

The European Union’s Cyber Resilience Act, or CRA, officially took effect on Sept. 11, setting stricter incident-reporting obligations for providers of crypto hardware and software wallets sold in the EU market. Under the new rules, firms must file an early warning report within 24 hours after discovering an actively exploited vulnerability or a severe security flaw, then submit a full notification within 72 hours. After corrective or mitigation measures are taken, manufacturers must provide a final report within 14 days, while severe incidents must be fully reported within one month. The European Commission said the reporting framework is meant to better protect consumers and businesses from cyber threats. The rules apply to all products with digital elements offered on the EU market and form part of the bloc’s broader cybersecurity strategy. Penalties in the final draft are substantial: companies that fail to comply with Articles 13 and 14 may face administrative fines of up to €15 million, roughly $17.3 million, or 2.5% of global annual turnover, whichever is higher. Firms that submit incorrect, incomplete, or misleading information may be fined up to €5 million. The measure comes after several security incidents involving wallet providers. Trezor said on Sept. 4 that a data breach at logistics vendor ShipMonk affected about 67,000 U.S. customers, above the initial estimate of 14,000. This week, Trezor and BitBox also warned users about phishing emails disguised as urgent security notices. In June, Layer-1 blockchain network Zilliqa said a flaw in its Ledger app could allow attackers to recover private keys using public on-chain data.

850
EU Cyber Resilience Act Takes Effect With Tight Breach Reporting Rules for Crypto Wallet Providers