<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>crime &#8211; Crypto Trading News &amp; Insights: Stay Ahead of the Game</title>
	<atom:link href="https://cryptonews24.eu/category/crime/feed" rel="self" type="application/rss+xml" />
	<link>https://cryptonews24.eu</link>
	<description>Your Source for the Latest Trends, Trading Strategies, and Trading Bot Reviews</description>
	<lastBuildDate>Sun, 27 Sep 2026 04:56:45 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.6.9</generator>

<image>
	<url>https://cryptonews24.eu/wp-content/uploads/2024/07/cryptonews24_favicon512-150x150.jpg</url>
	<title>crime &#8211; Crypto Trading News &amp; Insights: Stay Ahead of the Game</title>
	<link>https://cryptonews24.eu</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Bitget Hacker Moves Millions in XRP as Freezing Fails</title>
		<link>https://cryptonews24.eu/2026/09/cryptonews/bitget-hacker-moves-millions-in-xrp-as-freezing-fails.html</link>
					<comments>https://cryptonews24.eu/2026/09/cryptonews/bitget-hacker-moves-millions-in-xrp-as-freezing-fails.html#respond</comments>
		
		<dc:creator><![CDATA[cryptonews]]></dc:creator>
		<pubDate>Sun, 27 Sep 2026 04:56:45 +0000</pubDate>
				<category><![CDATA[crime]]></category>
		<category><![CDATA[Cryptonews]]></category>
		<guid isPermaLink="false">https://cryptonews24.eu/2026/09/crypto-news/bitget-hacker-moves-millions-in-xrp-as-freezing-fails.html</guid>

					<description><![CDATA[<a href="https://cryptonews24.eu/2026/09/cryptonews/bitget-hacker-moves-millions-in-xrp-as-freezing-fails.html"><img width="150" height="150" src="https://cryptonews24.eu/wp-content/uploads/2026/04/hacker-shutterstock-image-129491249-150x150.jpg" alt="Bitget Hacker Moves Millions in XRP as Freezing Fails" align="left" style="margin: 0 20px 20px 0;max-width:100%" /></a><p>Kosta Gushterov Sat, 26 Sep 2026 14:09:50 +0000  Crime</p>
<p><a href="https://cryptonews24.eu/2026/09/cryptonews/bitget-hacker-moves-millions-in-xrp-as-freezing-fails.html" rel="nofollow">Bitget Hacker Moves Millions in XRP as Freezing Fails at Crypto Trading News &amp; Insights: Stay Ahead of the Game.</a></p>
]]></description>
										<content:encoded><![CDATA[<p>Key Takeaways About 54 million XRP left five attacker wallets. Ripple cannot freeze native XRP balances. Roughly 49 million XRP […]
</p><p>The post <a href="https://coindoo.com/bitget-hacker-moves-millions-in-xrp-as-freezing-fails/" target="_blank" rel="nofollow noopener">Bitget Hacker Moves Millions in XRP as Freezing Fails</a> appeared first on <a href="https://coindoo.com" target="_blank" rel="nofollow noopener">Coindoo</a>.</p>
<h2><strong>Key Takeaways</strong></h2>
<div class="light-yellow-block">
<ul>
<li><strong>About 54 million XRP left five attacker wallets.</strong></li>
<li><strong>Ripple cannot freeze native XRP balances.</strong></li>
<li><strong>Roughly 49 million XRP remains in the original accounts.</strong></li>
<li><strong>Exchanges are the crucial recovery checkpoint.</strong></li>
</ul>
</div>
<p>The stolen XRP is no longer sitting where it first landed. A <a href="https://www.coindesk.com/markets/2026/09/26/bitget-hacker-moves-usd83-million-in-stolen-xrp-that-ripple-cannot-freeze" target="_blank" rel="noopener nofollow">CoinDesk review of XRP Ledger records</a> found that roughly 54 million XRP had left the five original accounts used to hold the Bitget haul by 12:41 UTC on September 26. Two accounts that began with 20 million XRP each had been reduced to about 23 and 55 XRP, while a third held roughly 5.8 million XRP.</p>
<p>About 49 million XRP, valued near $75 million at the time, remained in those first five accounts. That figure only counts the original holding accounts: funds that leave them can still be under the attacker’s control in newly created wallets. The on-chain question is whether the XRP reaches a service that can identify and stop the person controlling it.</p>
<p>To understand what the $83 million figure actually measures, it helps to separate the original theft from the later redistribution.</p>
<h2>The five original wallets show only the first stage</h2>
<p>Public blockchain records show that roughly 103 million XRP left two Bitget-linked XRPL accounts on September 24 and reached the address <a href="https://bithomp.com/explorer/rwNhefsz1UQEusxhCvHip3RANinWi4CTck" target="_blank" rel="noopener nofollow"><code>rwNhefsz1UQEusxhCvHip3RANinWi4CTck</code></a>. Arkham has placed that address in its <a href="https://info.arkm.com/research/hacker-steals-350m-from-bitget-and-begins-on-chain-laundering" target="_blank" rel="noopener nofollow">Bitget Hacker entity</a>.</p>
<p>The amount was then split among five holding accounts. The split confirms where the XRP first went. It cannot, by itself, show whether each later address belongs to the same operator, a laundering intermediary or an exchange customer.</p>
<div style="margin: 30px 0; border-top: 1px solid #cbd5e1; border-bottom: 1px solid #cbd5e1;">
<div style="padding: 17px 0; border-bottom: 1px solid #e2e8f0;"><strong style="display: block; margin-bottom: 4px; color: #0f172a;">The original loss</strong><br>
<span style="color: #475569;">Roughly 103 million XRP was transferred from <a href="https://coindoo.com/bitget-breach-north-korea-link-probed-withdrawals-paused/" target="_blank" rel="nofollow noopener">Bitget-linked wallets</a> into the attacker cluster.</span></div>
<div style="padding: 17px 0; border-bottom: 1px solid #e2e8f0;"><strong style="display: block; margin-bottom: 4px; color: #0f172a;">The latest visible movement</strong><br>
<span style="color: #475569;">About 54 million XRP had left the first five holding accounts by September 26.</span></div>
<div style="padding: 17px 0;"><strong style="display: block; margin-bottom: 4px; color: #0f172a;">The missing fact</strong><br>
<span style="color: #475569;">The public ledger cannot establish how much XRP has been sold or identify every beneficial owner behind the new accounts.</span></div>
</div>
<p>Calling every transfer a “cash-out” would overstate the evidence. A movement between attacker-controlled wallets does not create new selling pressure by itself. Selling becomes a more concrete risk when the route reaches a centralized exchange, OTC desk, instant-swap service or another gateway that can turn XRP into a different asset or fiat money.</p>
<h2>Ripple cannot freeze a native XRP balance</h2>
<p>The limitation is built into how the XRP Ledger treats its native asset. XRP is not an issued token and has no issuer that can blacklist an account. The <a href="https://xrpl.org/docs/concepts/tokens/fungible-tokens/common-misconceptions-about-freezes" target="_blank" rel="noopener nofollow">XRPL documentation</a> states that freeze features apply to issued tokens held through trust lines, not XRP itself.</p>
<p>Ripple, the XRPL Foundation and validators therefore have no built-in authority to mark these native-XRP accounts as frozen. A normal payment from an account that holds sufficient XRP remains valid under the ledger’s current rules.</p>
<blockquote style="margin: 28px 0; padding: 20px 24px; border-left: 4px solid #2563eb; background: #f8fafc; color: #1e293b;">
<p style="margin: 0;"><strong>Traceability is not control.</strong> The XRP Ledger makes the transfers public, yet that transparency does not give Ripple authority to seize or lock native XRP held in another account.</p>
</blockquote>
<p>The contrast is visible in the stablecoin portion of the same breach. <a href="https://www.coindesk.com/markets/2026/09/25/circle-and-tether-step-in-to-freeze-hacker-wallet-after-massive-bitget-crypto-heist" target="_blank" rel="noopener nofollow">CoinDesk reported</a> that Circle and Tether had frozen about $320,000 in USDC and USDT tied to the incident. Those assets include issuer-level blacklist controls. Native XRP does not.</p>
<h2>The important intervention point is the exchange deposit</h2>
<p>Once the XRP reaches an exchange-controlled address, the issue changes from protocol rules to custodial control. The exchange can connect a tagged XRP deposit to a customer account, stop withdrawals or trading, preserve records and respond to investigators.</p>
<p>This distinction is especially relevant on the XRP Ledger because large exchanges commonly use shared deposit wallets. A destination tag tells the exchange which internal customer account should receive a payment. The tag is not public proof of a person’s identity, but it creates a point where the platform can match an on-chain deposit with its own customer records.</p>
<p>A September 25 <a href="https://entrycrypto.com/analysis/bitget-hack-xrp-cash-out-binance-mexc" target="_blank" rel="noopener nofollow">public-XRPL analysis</a> traced one route from an original holding account through intermediary addresses toward Binance and MEXC deposit infrastructure. That does not prove those exchanges received or credited all later transfers, and neither platform should be described as having frozen funds without a public confirmation. It does show why on-chain alerts matter before a large balance reaches an exit.</p>
<style>
    .dark-mode .read-more {background-color: #343a40 !important;}
</style>
<div class="read-more pb-3 pt-3 pt-md-2 px-3 my-4 border bg-light">
<h5 class="text-uppercase border-bottom mb-3 pb-1 d-none d-md-block">READ MORE:</h5>
<p>    <a class="article row text-decoration-none" href="https://coindoo.com/how-cosmos-hub-stopped-and-restarted-to-seize-stolen-atom/" title="How Cosmos Hub Stopped and Restarted to Seize Stolen ATOM" target="_blank" rel="nofollow noopener"></a></p>
<div class="contentRight col-4">
            <span class="imgContainer mt-0"><br>
                <img decoding="async" class="image img-defer" src="https://cryptonews24.eu/wp-content/uploads/2026/09/blockchain-image-for-0f3-560x310.jpg" width="560" style="display:block;margin:10px auto;max-width:560px;max-width:100%;"><br>
            </span>
        </div>
<div class="contentLeft col-8">
<h4 class="title mb-0">How Cosmos Hub Stopped and Restarted to Seize Stolen ATOM</h4>
</div>
<p>    
</p></div>
<h2>The holding accounts are emptying quickly</h2>
<p>That exchange checkpoint is becoming more urgent because the original holding accounts are emptying quickly. They held around 70 million XRP at 04:32 UTC on September 26. Roughly eight hours later, that balance was about 49 million XRP, according to CoinDesk’s review. In another visible detail, one account failed to send roughly 521,000 XRP because it did not have sufficient funds; a second account sent an identical amount to the intended recipient about an hour later.</p>
<p>That pattern supports the conclusion that the funds were being actively redistributed. It does not establish the reason for every transfer, whether a particular wallet belongs to a laundering service, or how much XRP has reached the market. Those require evidence beyond the ledger itself.</p>
<p>The decisive moment is not the next transfer between anonymous wallets. It is the first point at which a traceable XRP balance enters a service that knows who controls the account and can prevent it from leaving again.</p>
<hr>
<p style="text-align: center;"><em>This article is provided for informational purposes only and does not constitute financial, investment or legal advice. On-chain balances, wallet labels and exchange actions can change quickly as the investigation continues.</em></p>
<p>The post <a href="https://coindoo.com/bitget-hacker-moves-millions-in-xrp-as-freezing-fails/" target="_blank" rel="nofollow noopener">Bitget Hacker Moves Millions in XRP as Freezing Fails</a> appeared first on <a href="https://coindoo.com" target="_blank" rel="nofollow noopener">Coindoo</a>.</p>
<p><a href="https://cryptonews24.eu/market-overview">Check our Market Overview </a></p>
<p>Source: https://coindoo.com/bitget-hacker-moves-millions-in-xrp-as-freezing-fails/</p>
<div id="ajax-load-more" class="ajax-load-more-wrap default" data-alm-id="" data-canonical-url="https://cryptonews24.eu/category/crime" data-slug="crime" data-post-id="6233" data-localized="ajax_load_more_vars" data-alm-object="ajax_load_more"><style type="text/css">.alm-btn-wrap{display:block;margin:0 0 25px;padding:10px 0 0;position:relative;text-align:center}.alm-btn-wrap .alm-load-more-btn{appearance:none;background:#ed7070;border:none;border-radius:3px;box-shadow:0 1px 1px rgba(0,0,0,.05);color:#fff;cursor:pointer;display:inline-block;font-size:14px;font-weight:500;height:44px;line-height:1;margin:0;padding:0 22px;position:relative;text-align:center;text-decoration:none;transition:all .1s ease;user-select:none;width:auto}.alm-btn-wrap .alm-load-more-btn:focus,.alm-btn-wrap .alm-load-more-btn:hover{background:#cb5151;color:#fff;text-decoration:none}.alm-btn-wrap .alm-load-more-btn:active{background:#ed7070;box-shadow:inset 0 1px 2px rgba(0,0,0,.1),0 0 0 2px rgba(0,0,0,.05);text-decoration:none;transition:none}.alm-btn-wrap .alm-load-more-btn:before{background-color:rgba(0,0,0,0);background-image:url("data:image/svg+xml;charset=utf-8,%3Csvg xmlns='http://www.w3.org/2000/svg' xml:space='preserve' viewBox='0 0 2400 2400'%3E%3Cg fill='none' stroke='%237f8287' stroke-linecap='round' stroke-width='200'%3E%3Cpath d='M1200 600V100'/%3E%3Cpath d='M1200 2300v-500' opacity='.5'/%3E%3Cpath d='m900 680.4-250-433' opacity='.917'/%3E%3Cpath d='m1750 2152.6-250-433' opacity='.417'/%3E%3Cpath d='m680.4 900-433-250' opacity='.833'/%3E%3Cpath d='m2152.6 1750-433-250' opacity='.333'/%3E%3Cpath d='M600 1200H100' opacity='.75'/%3E%3Cpath d='M2300 1200h-500' opacity='.25'/%3E%3Cpath d='m680.4 1500-433 250' opacity='.667'/%3E%3Cpath d='m2152.6 650-433 250' opacity='.167'/%3E%3Cpath d='m900 1719.6-250 433' opacity='.583'/%3E%3Cpath d='m1750 247.4-250 433' opacity='.083'/%3E%3CanimateTransform attributeName='transform' attributeType='XML' begin='0s' calcMode='discrete' dur='0.83333s' keyTimes='0;0.08333;0.16667;0.25;0.33333;0.41667;0.5;0.58333;0.66667;0.75;0.83333;0.91667' repeatCount='indefinite' type='rotate' values='0 1199 1199;30 1199 1199;60 1199 1199;90 1199 1199;120 1199 1199;150 1199 1199;180 1199 1199;210 1199 1199;240 1199 1199;270 1199 1199;300 1199 1199;330 1199 1199'/%3E%3C/g%3E%3C/svg%3E");background-position:50%;background-repeat:no-repeat;background-size:24px 24px;border-radius:0;content:"";display:block;height:100%;left:0;opacity:0;overflow:hidden;position:absolute;top:0;transition:all .1s ease;visibility:hidden;width:100%;z-index:1}.alm-btn-wrap .alm-load-more-btn.loading{background-color:rgba(0,0,0,0)!important;border-color:rgba(0,0,0,0)!important;box-shadow:none!important;color:rgba(0,0,0,0)!important;cursor:wait;outline:none!important;text-decoration:none}.alm-btn-wrap .alm-load-more-btn.loading:before{opacity:1;visibility:visible}.alm-btn-wrap .alm-load-more-btn.done,.alm-btn-wrap .alm-load-more-btn:disabled{background-color:#ed7070;box-shadow:none!important;opacity:.15;outline:none!important;pointer-events:none}.alm-btn-wrap .alm-load-more-btn.done:before,.alm-btn-wrap .alm-load-more-btn:before,.alm-btn-wrap .alm-load-more-btn:disabled:before{opacity:0;visibility:hidden}.alm-btn-wrap .alm-load-more-btn.done{cursor:default}.alm-btn-wrap .alm-load-more-btn:after{display:none!important}.alm-btn-wrap .alm-elementor-link{display:block;font-size:13px;margin:0 0 15px}@media screen and (min-width:768px){.alm-btn-wrap .alm-elementor-link{left:0;margin:0;position:absolute;top:50%;transform:translateY(-50%)}}.ajax-load-more-wrap.blue .alm-load-more-btn{background-color:#0284c7}.ajax-load-more-wrap.blue .alm-load-more-btn.loading,.ajax-load-more-wrap.blue .alm-load-more-btn:focus,.ajax-load-more-wrap.blue .alm-load-more-btn:hover{background:#0369a1;color:#fff;text-decoration:none}.ajax-load-more-wrap.blue .alm-load-more-btn:active{background-color:#0284c7}.ajax-load-more-wrap.green .alm-load-more-btn{background-color:#059669}.ajax-load-more-wrap.green .alm-load-more-btn.loading,.ajax-load-more-wrap.green .alm-load-more-btn:focus,.ajax-load-more-wrap.green .alm-load-more-btn:hover{background:#047857;color:#fff;text-decoration:none}.ajax-load-more-wrap.green .alm-load-more-btn:active{background-color:#059669}.ajax-load-more-wrap.purple .alm-load-more-btn{background-color:#7e46e5}.ajax-load-more-wrap.purple .alm-load-more-btn.loading,.ajax-load-more-wrap.purple .alm-load-more-btn:focus,.ajax-load-more-wrap.purple .alm-load-more-btn:hover{background:#6e3dc8;color:#fff;text-decoration:none}.ajax-load-more-wrap.purple .alm-load-more-btn:active{background-color:#7e46e5}.ajax-load-more-wrap.grey .alm-load-more-btn{background-color:#7c8087}.ajax-load-more-wrap.grey .alm-load-more-btn.loading,.ajax-load-more-wrap.grey .alm-load-more-btn:focus,.ajax-load-more-wrap.grey .alm-load-more-btn:hover{background:#65686d;color:#fff;text-decoration:none}.ajax-load-more-wrap.grey .alm-load-more-btn:active{background-color:#7c8087}.ajax-load-more-wrap.dark .alm-load-more-btn{background-color:#3f3f46}.ajax-load-more-wrap.dark .alm-load-more-btn.loading,.ajax-load-more-wrap.dark .alm-load-more-btn:focus,.ajax-load-more-wrap.dark .alm-load-more-btn:hover{background:#18181b;color:#fff;text-decoration:none}.ajax-load-more-wrap.dark .alm-load-more-btn:active{background-color:#3f3f46}.ajax-load-more-wrap.is-outline .alm-load-more-btn.loading,.ajax-load-more-wrap.light-grey .alm-load-more-btn.loading,.ajax-load-more-wrap.white .alm-load-more-btn.loading,.ajax-load-more-wrap.white-inverse .alm-load-more-btn.loading{background-color:rgba(0,0,0,0)!important;border-color:rgba(0,0,0,0)!important;box-shadow:none!important;color:rgba(0,0,0,0)!important}.ajax-load-more-wrap.is-outline .alm-load-more-btn{background-color:#fff;border:1px solid hsla(0,78%,68%,.75);color:#ed7070}.ajax-load-more-wrap.is-outline .alm-load-more-btn.done,.ajax-load-more-wrap.is-outline .alm-load-more-btn:focus,.ajax-load-more-wrap.is-outline .alm-load-more-btn:hover{background-color:hsla(0,78%,68%,.05);border-color:#cb5151;color:#cb5151}.ajax-load-more-wrap.is-outline .alm-load-more-btn:active{background-color:hsla(0,78%,68%,.025);border-color:#ed7070}.ajax-load-more-wrap.white .alm-load-more-btn{background-color:#fff;border:1px solid #d6d9dd;color:#59595c}.ajax-load-more-wrap.white .alm-load-more-btn.done,.ajax-load-more-wrap.white .alm-load-more-btn:focus,.ajax-load-more-wrap.white .alm-load-more-btn:hover{background-color:#fff;border-color:#afb3b9;color:#303032}.ajax-load-more-wrap.white .alm-load-more-btn:active{background-color:#f9fafb;border-color:hsla(216,7%,71%,.65)}.ajax-load-more-wrap.light-grey .alm-load-more-btn{background-color:#f3f4f6;border:1px solid hsla(218,4%,51%,.25);color:#3f3f46}.ajax-load-more-wrap.light-grey .alm-load-more-btn.done,.ajax-load-more-wrap.light-grey .alm-load-more-btn:focus,.ajax-load-more-wrap.light-grey .alm-load-more-btn:hover{background-color:#f9fafb;border-color:hsla(218,4%,51%,.5);color:#18181b}.ajax-load-more-wrap.light-grey .alm-load-more-btn:active{border-color:hsla(218,4%,51%,.25)}.ajax-load-more-wrap.white-inverse .alm-load-more-btn{background-color:hsla(0,0%,100%,.3);border:none;box-shadow:none;color:#fff}.ajax-load-more-wrap.white-inverse .alm-load-more-btn:before{background-image:url("data:image/svg+xml;charset=utf-8,%3Csvg xmlns='http://www.w3.org/2000/svg' xml:space='preserve' viewBox='0 0 2400 2400'%3E%3Cg fill='none' stroke='%23f3f4f6' stroke-linecap='round' stroke-width='200'%3E%3Cpath d='M1200 600V100'/%3E%3Cpath d='M1200 2300v-500' opacity='.5'/%3E%3Cpath d='m900 680.4-250-433' opacity='.917'/%3E%3Cpath d='m1750 2152.6-250-433' opacity='.417'/%3E%3Cpath d='m680.4 900-433-250' opacity='.833'/%3E%3Cpath d='m2152.6 1750-433-250' opacity='.333'/%3E%3Cpath d='M600 1200H100' opacity='.75'/%3E%3Cpath d='M2300 1200h-500' opacity='.25'/%3E%3Cpath d='m680.4 1500-433 250' opacity='.667'/%3E%3Cpath d='m2152.6 650-433 250' opacity='.167'/%3E%3Cpath d='m900 1719.6-250 433' opacity='.583'/%3E%3Cpath d='m1750 247.4-250 433' opacity='.083'/%3E%3CanimateTransform attributeName='transform' attributeType='XML' begin='0s' calcMode='discrete' dur='0.83333s' keyTimes='0;0.08333;0.16667;0.25;0.33333;0.41667;0.5;0.58333;0.66667;0.75;0.83333;0.91667' repeatCount='indefinite' type='rotate' values='0 1199 1199;30 1199 1199;60 1199 1199;90 1199 1199;120 1199 1199;150 1199 1199;180 1199 1199;210 1199 1199;240 1199 1199;270 1199 1199;300 1199 1199;330 1199 1199'/%3E%3C/g%3E%3C/svg%3E")}.ajax-load-more-wrap.white-inverse .alm-load-more-btn.done,.ajax-load-more-wrap.white-inverse .alm-load-more-btn:focus,.ajax-load-more-wrap.white-inverse .alm-load-more-btn:hover{background-color:hsla(0,0%,100%,.925);color:#3f3f46}.ajax-load-more-wrap.white-inverse .alm-load-more-btn:active{background-color:hsla(0,0%,100%,.85);box-shadow:inset 0 1px 2px rgba(0,0,0,.1)}.ajax-load-more-wrap.infinite>.alm-btn-wrap .alm-load-more-btn{background:none!important;border:none!important;box-shadow:none!important;cursor:default!important;opacity:0;outline:none!important;overflow:hidden;padding:0;text-indent:-9999px;width:100%}.ajax-load-more-wrap.infinite>.alm-btn-wrap .alm-load-more-btn:before{background-size:28px 28px}.ajax-load-more-wrap.infinite>.alm-btn-wrap .alm-load-more-btn:active,.ajax-load-more-wrap.infinite>.alm-btn-wrap .alm-load-more-btn:focus{outline:none}.ajax-load-more-wrap.infinite>.alm-btn-wrap .alm-load-more-btn.done{opacity:0}.ajax-load-more-wrap.infinite>.alm-btn-wrap .alm-load-more-btn.loading{opacity:1;padding:0}.ajax-load-more-wrap.infinite.classic>.alm-btn-wrap .alm-load-more-btn:before{background-image:url("data:image/svg+xml;charset=utf-8,%3Csvg xmlns='http://www.w3.org/2000/svg' xml:space='preserve' viewBox='0 0 2400 2400'%3E%3Cg fill='none' stroke='%237f8287' stroke-linecap='round' stroke-width='200'%3E%3Cpath d='M1200 600V100'/%3E%3Cpath d='M1200 2300v-500' opacity='.5'/%3E%3Cpath d='m900 680.4-250-433' opacity='.917'/%3E%3Cpath d='m1750 2152.6-250-433' opacity='.417'/%3E%3Cpath d='m680.4 900-433-250' opacity='.833'/%3E%3Cpath d='m2152.6 1750-433-250' opacity='.333'/%3E%3Cpath d='M600 1200H100' opacity='.75'/%3E%3Cpath d='M2300 1200h-500' opacity='.25'/%3E%3Cpath d='m680.4 1500-433 250' opacity='.667'/%3E%3Cpath d='m2152.6 650-433 250' opacity='.167'/%3E%3Cpath d='m900 1719.6-250 433' opacity='.583'/%3E%3Cpath d='m1750 247.4-250 433' opacity='.083'/%3E%3CanimateTransform attributeName='transform' attributeType='XML' begin='0s' calcMode='discrete' dur='0.83333s' keyTimes='0;0.08333;0.16667;0.25;0.33333;0.41667;0.5;0.58333;0.66667;0.75;0.83333;0.91667' repeatCount='indefinite' type='rotate' values='0 1199 1199;30 1199 1199;60 1199 1199;90 1199 1199;120 1199 1199;150 1199 1199;180 1199 1199;210 1199 1199;240 1199 1199;270 1199 1199;300 1199 1199;330 1199 1199'/%3E%3C/g%3E%3C/svg%3E")}.ajax-load-more-wrap.infinite.circle-spinner>.alm-btn-wrap .alm-load-more-btn:before{background-image:url("data:image/svg+xml;charset=utf-8,%3Csvg xmlns='http://www.w3.org/2000/svg' fill='%237f8287' viewBox='0 0 24 24'%3E%3Cpath d='M12 1a11 11 0 1 0 11 11A11 11 0 0 0 12 1m0 19a8 8 0 1 1 8-8 8 8 0 0 1-8 8' opacity='.25'/%3E%3Cpath d='M10.14 1.16a11 11 0 0 0-9 8.92A1.59 1.59 0 0 0 2.46 12a1.52 1.52 0 0 0 1.65-1.3 8 8 0 0 1 6.66-6.61A1.42 1.42 0 0 0 12 2.69a1.57 1.57 0 0 0-1.86-1.53'%3E%3CanimateTransform attributeName='transform' dur='0.75s' repeatCount='indefinite' type='rotate' values='0 12 12;360 12 12'/%3E%3C/path%3E%3C/svg%3E")}.ajax-load-more-wrap.infinite.fading-circles>.alm-btn-wrap .alm-load-more-btn:before,.ajax-load-more-wrap.infinite.fading-squares>.alm-btn-wrap .alm-load-more-btn:before,.ajax-load-more-wrap.infinite.ripples>.alm-btn-wrap .alm-load-more-btn:before{background-size:38px 38px}.ajax-load-more-wrap.infinite.fading-circles>.alm-btn-wrap .alm-load-more-btn:before{background-image:url("data:image/svg+xml;charset=utf-8,%3Csvg xmlns='http://www.w3.org/2000/svg' viewBox='0 0 200 200'%3E%3Ccircle cx='40' cy='100' r='15' fill='%237f8287' stroke='%237f8287' stroke-width='5'%3E%3Canimate attributeName='opacity' begin='-.4' calcMode='spline' dur='1.5' keySplines='.5 0 .5 1;.5 0 .5 1' repeatCount='indefinite' values='1;0;1;'/%3E%3C/circle%3E%3Ccircle cx='100' cy='100' r='15' fill='%237f8287' stroke='%237f8287' stroke-width='5'%3E%3Canimate attributeName='opacity' begin='-.2' calcMode='spline' dur='1.5' keySplines='.5 0 .5 1;.5 0 .5 1' repeatCount='indefinite' values='1;0;1;'/%3E%3C/circle%3E%3Ccircle cx='160' cy='100' r='15' fill='%237f8287' stroke='%237f8287' stroke-width='5'%3E%3Canimate attributeName='opacity' begin='0' calcMode='spline' dur='1.5' keySplines='.5 0 .5 1;.5 0 .5 1' repeatCount='indefinite' values='1;0;1;'/%3E%3C/circle%3E%3C/svg%3E")}.ajax-load-more-wrap.infinite.fading-squares>.alm-btn-wrap .alm-load-more-btn:before{background-image:url("data:image/svg+xml;charset=utf-8,%3Csvg xmlns='http://www.w3.org/2000/svg' viewBox='0 0 200 200'%3E%3Cpath fill='%237f8287' stroke='%237f8287' stroke-width='10' d='M25 85h30v30H25z'%3E%3Canimate attributeName='opacity' begin='-.4' calcMode='spline' dur='1.5' keySplines='.5 0 .5 1;.5 0 .5 1' repeatCount='indefinite' values='1;0.25;1;'/%3E%3C/path%3E%3Cpath fill='%237f8287' stroke='%237f8287' stroke-width='10' d='M85 85h30v30H85z'%3E%3Canimate attributeName='opacity' begin='-.2' calcMode='spline' dur='1.5' keySplines='.5 0 .5 1;.5 0 .5 1' repeatCount='indefinite' values='1;0.25;1;'/%3E%3C/path%3E%3Cpath fill='%237f8287' stroke='%237f8287' stroke-width='10' d='M145 85h30v30h-30z'%3E%3Canimate attributeName='opacity' begin='0' calcMode='spline' dur='1.5' keySplines='.5 0 .5 1;.5 0 .5 1' repeatCount='indefinite' values='1;0.25;1;'/%3E%3C/path%3E%3C/svg%3E")}.ajax-load-more-wrap.infinite.ripples>.alm-btn-wrap .alm-load-more-btn:before{background-image:url("data:image/svg+xml;charset=utf-8,%3Csvg xmlns='http://www.w3.org/2000/svg' viewBox='0 0 200 200'%3E%3Ccircle cx='100' cy='100' r='0' fill='none' stroke='%237f8287' stroke-width='.5'%3E%3Canimate attributeName='r' calcMode='spline' dur='1' keySplines='0 .2 .5 1' keyTimes='0;1' repeatCount='indefinite' values='1;80'/%3E%3Canimate attributeName='stroke-width' calcMode='spline' dur='1' keySplines='0 .2 .5 1' keyTimes='0;1' repeatCount='indefinite' values='0;25'/%3E%3Canimate attributeName='stroke-opacity' calcMode='spline' dur='1' keySplines='0 .2 .5 1' keyTimes='0;1' repeatCount='indefinite' values='1;0'/%3E%3C/circle%3E%3C/svg%3E")}.ajax-load-more-wrap.alm-horizontal .alm-btn-wrap{align-items:center;display:flex;margin:0;padding:0}.ajax-load-more-wrap.alm-horizontal .alm-btn-wrap button{margin:0}.ajax-load-more-wrap.alm-horizontal .alm-btn-wrap button.done{display:none}.alm-btn-wrap--prev{clear:both;display:flex;justify-content:center;margin:0;padding:0;width:100%}.alm-btn-wrap--prev:after{clear:both;content:"";display:table;height:0}.alm-btn-wrap--prev a.alm-load-more-btn--prev{align-items:center;display:inline-flex;font-size:14px;font-weight:500;line-height:1;margin:0 0 10px;min-height:20px;padding:5px;position:relative;text-decoration:none;transition:none}.alm-btn-wrap--prev a.alm-load-more-btn--prev:focus,.alm-btn-wrap--prev a.alm-load-more-btn--prev:hover{text-decoration:underline}.alm-btn-wrap--prev a.alm-load-more-btn--prev:before{background:url("data:image/svg+xml;charset=utf-8,%3Csvg xmlns='http://www.w3.org/2000/svg' xml:space='preserve' viewBox='0 0 2400 2400'%3E%3Cg fill='none' stroke='%237f8287' stroke-linecap='round' stroke-width='200'%3E%3Cpath d='M1200 600V100'/%3E%3Cpath d='M1200 2300v-500' opacity='.5'/%3E%3Cpath d='m900 680.4-250-433' opacity='.917'/%3E%3Cpath d='m1750 2152.6-250-433' opacity='.417'/%3E%3Cpath d='m680.4 900-433-250' opacity='.833'/%3E%3Cpath d='m2152.6 1750-433-250' opacity='.333'/%3E%3Cpath d='M600 1200H100' opacity='.75'/%3E%3Cpath d='M2300 1200h-500' opacity='.25'/%3E%3Cpath d='m680.4 1500-433 250' opacity='.667'/%3E%3Cpath d='m2152.6 650-433 250' opacity='.167'/%3E%3Cpath d='m900 1719.6-250 433' opacity='.583'/%3E%3Cpath d='m1750 247.4-250 433' opacity='.083'/%3E%3CanimateTransform attributeName='transform' attributeType='XML' begin='0s' calcMode='discrete' dur='0.83333s' keyTimes='0;0.08333;0.16667;0.25;0.33333;0.41667;0.5;0.58333;0.66667;0.75;0.83333;0.91667' repeatCount='indefinite' type='rotate' values='0 1199 1199;30 1199 1199;60 1199 1199;90 1199 1199;120 1199 1199;150 1199 1199;180 1199 1199;210 1199 1199;240 1199 1199;270 1199 1199;300 1199 1199;330 1199 1199'/%3E%3C/g%3E%3C/svg%3E") no-repeat 0/20px 20px;content:"";display:block;height:20px;left:50%;opacity:0;position:absolute;top:50%;transform:translate(-50%,-50%);transition:all 75ms ease;visibility:hidden;width:20px;z-index:1}.alm-btn-wrap--prev a.alm-load-more-btn--prev.loading,.alm-btn-wrap--prev a.alm-load-more-btn--prev.loading:focus{color:rgba(0,0,0,0)!important;cursor:wait;text-decoration:none}.alm-btn-wrap--prev a.alm-load-more-btn--prev.loading:before,.alm-btn-wrap--prev a.alm-load-more-btn--prev.loading:focus:before{opacity:1;visibility:visible}.alm-btn-wrap--prev a.alm-load-more-btn--prev.circle-spinner.loading:before{background-image:url("data:image/svg+xml;charset=utf-8,%3Csvg xmlns='http://www.w3.org/2000/svg' fill='%237f8287' viewBox='0 0 24 24'%3E%3Cpath d='M12 1a11 11 0 1 0 11 11A11 11 0 0 0 12 1m0 19a8 8 0 1 1 8-8 8 8 0 0 1-8 8' opacity='.25'/%3E%3Cpath d='M10.14 1.16a11 11 0 0 0-9 8.92A1.59 1.59 0 0 0 2.46 12a1.52 1.52 0 0 0 1.65-1.3 8 8 0 0 1 6.66-6.61A1.42 1.42 0 0 0 12 2.69a1.57 1.57 0 0 0-1.86-1.53'%3E%3CanimateTransform attributeName='transform' dur='0.75s' repeatCount='indefinite' type='rotate' values='0 12 12;360 12 12'/%3E%3C/path%3E%3C/svg%3E")}.alm-btn-wrap--prev a.alm-load-more-btn--prev.fading-circles.loading:before,.alm-btn-wrap--prev a.alm-load-more-btn--prev.fading-squares.loading:before{background-image:url("data:image/svg+xml;charset=utf-8,%3Csvg xmlns='http://www.w3.org/2000/svg' viewBox='0 0 200 200'%3E%3Ccircle cx='40' cy='100' r='15' fill='%237f8287' stroke='%237f8287' stroke-width='5'%3E%3Canimate attributeName='opacity' begin='-.4' calcMode='spline' dur='1.5' keySplines='.5 0 .5 1;.5 0 .5 1' repeatCount='indefinite' values='1;0;1;'/%3E%3C/circle%3E%3Ccircle cx='100' cy='100' r='15' fill='%237f8287' stroke='%237f8287' stroke-width='5'%3E%3Canimate attributeName='opacity' begin='-.2' calcMode='spline' dur='1.5' keySplines='.5 0 .5 1;.5 0 .5 1' repeatCount='indefinite' values='1;0;1;'/%3E%3C/circle%3E%3Ccircle cx='160' cy='100' r='15' fill='%237f8287' stroke='%237f8287' stroke-width='5'%3E%3Canimate attributeName='opacity' begin='0' calcMode='spline' dur='1.5' keySplines='.5 0 .5 1;.5 0 .5 1' repeatCount='indefinite' values='1;0;1;'/%3E%3C/circle%3E%3C/svg%3E")}.alm-btn-wrap--prev a.alm-load-more-btn--prev.ripples.loading:before{background-image:url("data:image/svg+xml;charset=utf-8,%3Csvg xmlns='http://www.w3.org/2000/svg' viewBox='0 0 200 200'%3E%3Ccircle cx='100' cy='100' r='0' fill='none' stroke='%237f8287' stroke-width='.5'%3E%3Canimate attributeName='r' calcMode='spline' dur='1' keySplines='0 .2 .5 1' keyTimes='0;1' repeatCount='indefinite' values='1;80'/%3E%3Canimate attributeName='stroke-width' calcMode='spline' dur='1' keySplines='0 .2 .5 1' keyTimes='0;1' repeatCount='indefinite' values='0;25'/%3E%3Canimate attributeName='stroke-opacity' calcMode='spline' dur='1' keySplines='0 .2 .5 1' keyTimes='0;1' repeatCount='indefinite' values='1;0'/%3E%3C/circle%3E%3C/svg%3E")}.alm-btn-wrap--prev a.alm-load-more-btn--prev button:not([disabled]),.alm-btn-wrap--prev a.alm-load-more-btn--prev:not(.disabled){cursor:pointer}.alm-btn-wrap--prev a.alm-load-more-btn--prev.done{display:none}.alm-listing,.alm-paging-content{outline:none}.alm-listing:after,.alm-paging-content:after{clear:both;content:"";display:table;height:0}.alm-listing{margin:0;padding:0}.alm-listing .alm-paging-content>li,.alm-listing>li{position:relative}.alm-listing .alm-paging-content>li.alm-item,.alm-listing>li.alm-item{background:none;list-style:none;margin:0 0 30px;padding:0 0 0 80px;position:relative}@media screen and (min-width:480px){.alm-listing .alm-paging-content>li.alm-item,.alm-listing>li.alm-item{padding:0 0 0 100px}}@media screen and (min-width:768px){.alm-listing .alm-paging-content>li.alm-item,.alm-listing>li.alm-item{padding:0 0 0 135px}}@media screen and (min-width:1024px){.alm-listing .alm-paging-content>li.alm-item,.alm-listing>li.alm-item{padding:0 0 0 160px}}.alm-listing .alm-paging-content>li.alm-item h3,.alm-listing>li.alm-item h3{margin:0}.alm-listing .alm-paging-content>li.alm-item p,.alm-listing>li.alm-item p{margin:10px 0 0}.alm-listing .alm-paging-content>li.alm-item p.entry-meta,.alm-listing>li.alm-item p.entry-meta{opacity:.75}.alm-listing .alm-paging-content>li.alm-item img,.alm-listing>li.alm-item img{border-radius:2px;left:0;max-width:65px;position:absolute;top:0}@media screen and (min-width:480px){.alm-listing .alm-paging-content>li.alm-item img,.alm-listing>li.alm-item img{max-width:85px}}@media screen and (min-width:768px){.alm-listing .alm-paging-content>li.alm-item img,.alm-listing>li.alm-item img{max-width:115px}}@media screen and (min-width:1024px){.alm-listing .alm-paging-content>li.alm-item img,.alm-listing>li.alm-item img{max-width:140px}}.alm-listing .alm-paging-content>li.no-img,.alm-listing>li.no-img{padding:0}.alm-listing.products li.product{padding-left:inherit}.alm-listing.products li.product img{border-radius:inherit;position:static}.alm-listing.stylefree .alm-paging-content>li,.alm-listing.stylefree>li{margin:inherit;padding:inherit}.alm-listing.stylefree .alm-paging-content>li img,.alm-listing.stylefree>li img{border-radius:inherit;margin:inherit;padding:inherit;position:static}.alm-listing.rtl .alm-paging-content>li{padding:0 170px 0 0;text-align:right}.alm-listing.rtl .alm-paging-content>li img{left:auto;right:0}.alm-listing.rtl.products li.product{padding-right:inherit}.alm-masonry{clear:both;display:block;overflow:hidden}.alm-placeholder{display:none;opacity:0;transition:opacity .2s ease}.ajax-load-more-wrap.alm-horizontal{display:flex;flex-wrap:nowrap;width:100%}.ajax-load-more-wrap.alm-horizontal .alm-listing{display:flex;flex-direction:row;flex-wrap:nowrap}.ajax-load-more-wrap.alm-horizontal .alm-listing>li.alm-item{background-color:#fff;border:1px solid #efefef;border-radius:4px;height:auto;margin:0 2px;padding:20px 20px 30px;text-align:center;width:300px}.ajax-load-more-wrap.alm-horizontal .alm-listing>li.alm-item img{border-radius:4px;box-shadow:0 2px 10px rgba(0,0,0,.075);margin:0 auto 15px;max-width:125px;position:static}.ajax-load-more-wrap.alm-horizontal .alm-listing:after{display:none}.alm-toc{display:flex;gap:5px;padding:10px 0;width:auto}.alm-toc button{background:#f3f4f6;border:1px solid hsla(218,4%,51%,.25);border-radius:3px;box-shadow:none;color:#3f3f46;cursor:pointer;font-size:14px;font-weight:500;height:auto;line-height:1;margin:0;outline:none;padding:8px 10px;transition:all .15s ease}.alm-toc button:focus,.alm-toc button:hover{border-color:hsla(218,4%,51%,.5);box-shadow:0 1px 3px rgba(0,0,0,.075);color:#3f3f46;text-decoration:none}.alm-toc button:focus{box-shadow:inset 0 1px 2px rgba(0,0,0,.05)}</style><ul aria-live="polite" aria-atomic="true" class="alm-listing alm-ajax" data-container-type="ul" data-loading-style="default" data-repeater="default" data-post-type="post" data-order="DESC" data-orderby="date" data-offset="0" data-posts-per-page="5" data-scroll="false" data-button-label="Load More" data-prev-button-label="Load Previous"></ul><div class="alm-btn-wrap" style="visibility: hidden" data-rel="ajax-load-more"><button class="alm-load-more-btn " type="button">Load More</button></div></div>
]]></content:encoded>
					
					<wfw:commentRss>https://cryptonews24.eu/2026/09/cryptonews/bitget-hacker-moves-millions-in-xrp-as-freezing-fails.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Bitget Wallets Flagged in Suspected $170M Security Breach</title>
		<link>https://cryptonews24.eu/2026/09/cryptonews/bitget-wallets-flagged-in-suspected-170m-security-breach.html</link>
					<comments>https://cryptonews24.eu/2026/09/cryptonews/bitget-wallets-flagged-in-suspected-170m-security-breach.html#respond</comments>
		
		<dc:creator><![CDATA[cryptonews]]></dc:creator>
		<pubDate>Fri, 25 Sep 2026 06:45:31 +0000</pubDate>
				<category><![CDATA[crime]]></category>
		<category><![CDATA[Cryptonews]]></category>
		<guid isPermaLink="false">https://cryptonews24.eu/2026/09/crypto-news/bitget-wallets-flagged-in-suspected-170m-security-breach.html</guid>

					<description><![CDATA[<a href="https://cryptonews24.eu/2026/09/cryptonews/bitget-wallets-flagged-in-suspected-170m-security-breach.html"><img width="150" height="150" src="https://cryptonews24.eu/wp-content/uploads/2026/06/bitget-i094-150x150.jpg" alt="Bitget Wallets Flagged in Suspected $170M Security Breach" align="left" style="margin: 0 20px 20px 0;max-width:100%" /></a><p>Kosta Gushterov Thu, 24 Sep 2026 21:13:11 +0000  Crime</p>
<p><a href="https://cryptonews24.eu/2026/09/cryptonews/bitget-wallets-flagged-in-suspected-170m-security-breach.html" rel="nofollow">Bitget Wallets Flagged in Suspected $170M Security Breach at Crypto Trading News &amp; Insights: Stay Ahead of the Game.</a></p>
]]></description>
										<content:encoded><![CDATA[<p>The claim remains unconfirmed. Neither the reported attack method nor the final loss total had been established at publication. The […]
</p><p>The post <a href="https://coindoo.com/bitget-wallets-flagged-in-suspected-170m-security-breach/" target="_blank" rel="nofollow noopener">Bitget Wallets Flagged in Suspected $170M Security Breach</a> appeared first on <a href="https://coindoo.com" target="_blank" rel="nofollow noopener">Coindoo</a>.</p>
<p>The claim remains unconfirmed. Neither the reported attack method nor the final loss total had been established at publication. <a href="https://www.theblock.co/news/markets/2026-09-24-more-than-170-million-in-crypto-moves-from-bitget-wallets-unidentified-address-416345?utm_source=telegram1&amp;utm_medium=social" target="_blank" rel="noopener nofollow">The Block said</a> it had contacted Bitget to ask whether the transfers were tied to a security incident and whether withdrawals had been paused, but no public explanation had been identified at publication.</p>
<p>The alerts concern wallets associated with Bitget’s exchange infrastructure; they do not establish a compromise of the separately branded Bitget Wallet self-custody app.</p>
<h2>What the on-chain trail reportedly shows</h2>
<p><a href="https://x.com/TheBlockCo/status/2103223637692371378" target="_blank" rel="noopener nofollow">The Block reported</a> also that on-chain data appeared to show more than $170 million moving from Bitget hot and cold wallets to one address over roughly an hour. The transfers reportedly included ETH, USDT, USDC, AVAX and BNB.</p>
<div style="margin: 28px 0; padding: 4px 0; border-left: 3px solid #0f172a;">
<div style="padding: 0 0 22px 20px;"><strong style="display: block; color: #0f172a;">1. Assets reportedly left several Bitget-linked wallets</strong><br>
<span style="display: block; margin-top: 5px; color: #475569;">The initial reports identify both hot and cold wallets, rather than a single routine transfer.</span></div>
<div style="padding: 0 0 22px 20px;"><strong style="display: block; color: #0f172a;">2. The funds converged at one fresh address</strong><br>
<span style="display: block; margin-top: 5px; color: #475569;">The recipient did not appear to be labelled as belonging to Bitget or as part of its known wallet structure.</span></div>
<div style="padding: 0 0 0 20px;"><strong style="display: block; color: #0f172a;">3. The recipient reportedly began swapping assets</strong><br>
<span style="display: block; margin-top: 5px; color: #475569;">The reported conversions into ETH are why the movements drew closer scrutiny.</span></div>
</div>
<p><a href="https://x.com/WuBlockchain/status/2103219961313599598" target="_blank" rel="noopener nofollow">Wu Blockchain said</a>, citing MLM monitoring, that three hot wallets and one cold wallet were suspected of being involved. It linked the activity to <a href="https://arkm.com/explorer/address/0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee" target="_blank" rel="noopener nofollow">0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee</a> and stressed that the attack vector and total losses remain unconfirmed.</p>
<p><a href="https://cryptonews24.eu/wp-content/uploads/2026/09/HTAjZ3bbwAAHfrP.jpeg" data-fancybox><img fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-189388" src="https://cryptonews24.eu/wp-content/uploads/2026/09/HTAjZ3bbwAAHfrP-560x227.jpeg" alt="On-chain transfers from Bitget-linked wallets to the reported destination address" width="560" srcset="https://cryptonews24.eu/wp-content/uploads/2026/09/HTAjZ3bbwAAHfrP.jpeg 1200w, https://cryptonews24.eu/wp-content/uploads/2026/09/HTAjZ3bbwAAHfrP-300x122.jpeg 300w, https://cryptonews24.eu/wp-content/uploads/2026/09/HTAjZ3bbwAAHfrP.jpeg 800w, https://cryptonews24.eu/wp-content/uploads/2026/09/HTAjZ3bbwAAHfrP-768x312.jpeg 768w" sizes="(max-width: 1200px) 100vw, 1200px" style="display:block;margin:10px auto;max-width:560px;max-width:100%;"></a></p>
<h2>Withdrawal Complaints Create a Separate Question</h2>
<p>The Block also noted social-media posts and online reports from users who said they were experiencing withdrawal problems. Those claims do not establish that Bitget has suspended withdrawals, and they do not prove that any service issue is connected to the flagged wallet movements.</p>
<p>They nevertheless create a second question for the exchange. If the transfers were authorised wallet management, Bitget can identify the receiving address and explain whether users are facing an unrelated operational delay. If the two developments are connected, a public response becomes more urgent.</p>
<h2>Why $170 million moved does not yet mean $170 million was stolen</h2>
<p>Exchanges regularly shift large balances between hot wallets, cold storage and liquidity-related addresses. A large transfer can look alarming on a blockchain explorer while still being authorised <a class="wpg-linkify wpg-tooltip" title="&lt;h3 class=&quot;wpg-tooltip-title&quot;&gt;&lt;span class=&quot;wpg-tooltip-term-title&quot;&gt;Wallet&lt;/span&gt;&lt;/h3&gt;&lt;div class=&quot;wpg-tooltip-content&quot;&gt;&lt;p&gt;A device or application that securely holds a user's public and private keys while allowing interaction with a blockchain network.&lt;/p&gt;&lt;/div&gt;">wallet</a> management.</p>
<p>The reported pattern here is more difficult to dismiss than a single transfer because assets from several wallets reportedly reached one fresh address that was not identified as Bitget-controlled and then entered swaps. Even so, that is evidence worth investigating, not proof of theft.</p>
<p>The missing fact is simple: does Bitget control the receiving address?</p>
<p>If the exchange identifies it as an internal operational wallet, the breach theory weakens sharply. If the ETH continues through bridges, mixers or wallets unrelated to Bitget, the case for an unauthorised outflow becomes much stronger.</p>
<h2>Three answers matter more than the first loss estimate</h2>
<h3>Is the destination address controlled by Bitget?</h3>
<p>This is the fastest way to separate internal wallet management from a possible compromise. The destination address is publicly visible; only Bitget can say whether it controls it.</p>
<h3>Were the transfers authorised?</h3>
<p>Bitget needs to clarify whether the wallets acted through normal signing procedures or whether access to any part of its infrastructure was compromised. Until then, claims about the method behind the transfers remain speculation.</p>
<h3>Are users or platform services affected?</h3>
<p>The on-chain reports do not establish that customer balances, deposits, withdrawals or trading services have been affected. A public update on those points would matter more to users than another revised estimate of the outflows.</p>
<h2>What would settle the question</h2>
<p>A formal Bitget statement is the next important development, but independent tracing will matter too. Security firms can follow whether the ETH remains in the recipient wallet, is moved through bridges, reaches exchange deposit addresses or enters recognised laundering routes.</p>
<p>That evidence will determine whether the story remains a suspicious sequence of wallet movements or becomes a confirmed exchange security incident. Until then, the $170 million figure should be treated as reported on-chain volume, not a final accounting of losses.</p>
<hr>
<p style="text-align: center;"><em>This article is provided for informational purposes only and does not constitute financial or investment advice. Wallet labels and on-chain estimates can change as new information emerges.</em></p>
<p>The post <a href="https://coindoo.com/bitget-wallets-flagged-in-suspected-170m-security-breach/" target="_blank" rel="nofollow noopener">Bitget Wallets Flagged in Suspected $170M Security Breach</a> appeared first on <a href="https://coindoo.com" target="_blank" rel="nofollow noopener">Coindoo</a>.</p>
<p><a href="https://cryptonews24.eu/market-overview">Check our Market Overview </a></p>
<p>Source: https://coindoo.com/bitget-wallets-flagged-in-suspected-170m-security-breach/</p>
<div id="ajax-load-more-2" class="ajax-load-more-wrap default" data-alm-id="" data-canonical-url="https://cryptonews24.eu/category/crime" data-slug="crime" data-post-id="6233" data-localized="ajax_load_more_2_vars" data-alm-object="ajax_load_more_2"><ul aria-live="polite" aria-atomic="true" class="alm-listing alm-ajax" data-container-type="ul" data-loading-style="default" data-repeater="default" data-post-type="post" data-order="DESC" data-orderby="date" data-offset="0" data-posts-per-page="5" data-scroll="false" data-button-label="Load More" data-prev-button-label="Load Previous"></ul><div class="alm-btn-wrap" style="visibility: hidden" data-rel="ajax-load-more-2"><button class="alm-load-more-btn " type="button">Load More</button></div></div>
]]></content:encoded>
					
					<wfw:commentRss>https://cryptonews24.eu/2026/09/cryptonews/bitget-wallets-flagged-in-suspected-170m-security-breach.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Bitget Breach: North Korea Link Probed, Withdrawals Paused</title>
		<link>https://cryptonews24.eu/2026/09/cryptonews/bitget-breach-north-korea-link-probed-withdrawals-paused.html</link>
					<comments>https://cryptonews24.eu/2026/09/cryptonews/bitget-breach-north-korea-link-probed-withdrawals-paused.html#respond</comments>
		
		<dc:creator><![CDATA[cryptonews]]></dc:creator>
		<pubDate>Fri, 25 Sep 2026 06:45:26 +0000</pubDate>
				<category><![CDATA[crime]]></category>
		<category><![CDATA[Cryptonews]]></category>
		<guid isPermaLink="false">https://cryptonews24.eu/2026/09/crypto-news/bitget-breach-north-korea-link-probed-withdrawals-paused.html</guid>

					<description><![CDATA[<a href="https://cryptonews24.eu/2026/09/cryptonews/bitget-breach-north-korea-link-probed-withdrawals-paused.html"><img width="150" height="150" src="https://cryptonews24.eu/wp-content/uploads/2026/07/hack22-150x150.webp" alt="Bitget Breach: North Korea Link Probed, Withdrawals Paused" align="left" style="margin: 0 20px 20px 0;max-width:100%" /></a><p>Kosta Gushterov Fri, 25 Sep 2026 05:23:59 +0000  Crime</p>
<p><a href="https://cryptonews24.eu/2026/09/cryptonews/bitget-breach-north-korea-link-probed-withdrawals-paused.html" rel="nofollow">Bitget Breach: North Korea Link Probed, Withdrawals Paused at Crypto Trading News &amp; Insights: Stay Ahead of the Game.</a></p>
]]></description>
										<content:encoded><![CDATA[<p>Coindoo first covered the unusual wallet movements in its earlier report, when funds from Bitget-linked wallets were moving to a […]
</p><p>The post <a href="https://coindoo.com/bitget-breach-north-korea-link-probed-withdrawals-paused/" target="_blank" rel="nofollow noopener">Bitget Breach: North Korea Link Probed, Withdrawals Paused</a> appeared first on <a href="https://coindoo.com" target="_blank" rel="nofollow noopener">Coindoo</a>.</p>
<p>Coindoo first covered the unusual wallet movements in its <a href="https://coindoo.com/bitget-wallets-flagged-in-suspected-170m-security-breach/" target="_blank" rel="nofollow noopener">earlier report</a>, when funds from Bitget-linked wallets were moving to a fresh address and being swapped on-chain. Bitget has since confirmed that the transfers were unauthorised.</p>
<h2>How the Bitget Story Changed Overnight</h2>
<table style="width: 100%; border-collapse: collapse; margin: 28px 0; font-size: 18px; line-height: 1.45;">
<thead>
<tr>
<th style="width: 24%; padding: 14px 16px; border: 1px dashed #b8b8b8; text-align: left; color: #333;">Stage</th>
<th style="padding: 14px 16px; border: 1px dashed #b8b8b8; text-align: left; color: #333;">What was known</th>
</tr>
</thead>
<tbody>
<tr>
<td style="padding: 16px; border: 1px dashed #b8b8b8; font-weight: bold; color: #333;">Initial on-chain alert</td>
<td style="padding: 16px; border: 1px dashed #b8b8b8; color: #333;">More than $170 million was seen moving from Bitget-linked wallets to a fresh address, where assets were reportedly swapped.</td>
</tr>
<tr>
<td style="padding: 16px; border: 1px dashed #b8b8b8; font-weight: bold; color: #333;">Bitget’s confirmation</td>
<td style="padding: 16px; border: 1px dashed #b8b8b8; color: #333;">The exchange said unauthorised transfers affected approximately $351.6 million and suspended withdrawals.</td>
</tr>
<tr>
<td style="padding: 16px; border: 1px dashed #b8b8b8; font-weight: bold; color: #333;">Technical update</td>
<td style="padding: 16px; border: 1px dashed #b8b8b8; color: #333;">Bitget says an attacker compromised a backend wallet system and triggered its authorisation flow with spoofed transfer data.</td>
</tr>
<tr>
<td style="padding: 16px; border: 1px dashed #b8b8b8; font-weight: bold; color: #333;">Latest attribution clue</td>
<td style="padding: 16px; border: 1px dashed #b8b8b8; color: #333;">Its CEO reportedly says North Korean involvement cannot be ruled out, but no group has been named.</td>
</tr>
</tbody>
</table>
<p>The two dollar figures should not be read as competing estimates of the same thing. The $170 million number came from the initial visible on-chain flow. Bitget’s later $351.6 million figure is its internal estimate of the assets affected by the breach.</p>
<p>Bitget has not published a wallet-by-wallet reconciliation explaining the difference. What is clear is that the first alert captured only part of a wider incident that the exchange later confirmed from inside its own systems.</p>
<h2>The North Korea Clue Is Not a Final Attribution</h2>
<p>During a live security update, Bitget CEO Gracy Chen said some IP addresses associated with the attack matched VPN-use patterns linked to a North Korean hacker organisation. She also said the activity resembled previous attacks associated with North Korean operators, according to <a href="https://uat2049.chaincatcher.info/en/article/2292167" target="_blank" rel="noopener nofollow">ChainCatcher’s report</a>.</p>
<p>That is a preliminary lead, not a completed attribution. Bitget has not named a group or released the forensic evidence behind the assessment. The company’s current position is that North Korean involvement cannot be ruled out while investigators continue to trace the intrusion.</p>
<h2>The Attack Did Not Require a Stolen Private Key</h2>
<p>Bitget’s explanation changes the technical question around the breach.</p>
<p>In a <a href="https://x.com/GracyBitget/status/2103284265563902056" target="_blank" rel="noopener nofollow">September 25 update</a>, Chen said the attacker compromised a critical backend system within the exchange’s wallet infrastructure. Bitget says the system was then used to create spoofed transfer data that reached its authorisation process and moved funds out.</p>
<blockquote class="twitter-tweet">
<p dir="ltr" lang="en">Here is what we can confirm at this stage:</p>
<p>On the attack:<br>
Our security team has made initial progress in tracing the source. The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization… <a href="https://t.co/5nINjwbXpC" target="_blank" rel="nofollow">https://t.co/5nINjwbXpC</a></p>
<p>— Gracy Chen @Bitget (@GracyBitget) <a href="https://x.com/GracyBitget/status/2103284265563902056?ref_src=twsrc%5Etfw" target="_blank" rel="nofollow">September 25, 2026</a></p>
</blockquote>
<p><script async src="https://platform.x.com/widgets.js" charset="utf-8"></script></p>
<p>The exchange says a private-key leak has been ruled out. It also says it has contained the incident and that no further unauthorised transfers are possible.</p>
<p>That does not make the breach less serious. It shifts the focus from key custody to the systems around it. If Bitget’s account is confirmed, the attacker did not need to possess a wallet key; it needed access to infrastructure capable of producing transfer information that the approval process accepted.</p>
<p>The full incident report therefore matters more than the early North Korea clue. It needs to explain how manipulated data entered the authorisation flow, what controls failed to stop it and what has changed before withdrawals resume.</p>
<h2>A Protection Fund Can Cover Losses, Not Restore Access</h2>
<p>Bitget says its cold wallets were not affected and that the $351.6 million loss falls within the coverage of its User Protection Fund, which it says holds more than $464 million. The exchange also says customer account balances remain accurate.</p>
<table style="width: 100%; border-collapse: collapse; margin: 28px 0; font-size: 18px; line-height: 1.45;">
<thead>
<tr>
<th style="width: 40%; padding: 14px 16px; border: 1px dashed #b8b8b8; text-align: center; color: #333;">What Bitget says is covered</th>
<th style="padding: 14px 16px; border: 1px dashed #b8b8b8; text-align: center; color: #333;">What users still need answered</th>
</tr>
</thead>
<tbody>
<tr>
<td style="padding: 16px; border: 1px dashed #b8b8b8; color: #333;">The estimated $351.6 million loss</td>
<td style="padding: 16px; border: 1px dashed #b8b8b8; color: #333;">When withdrawals will restart</td>
</tr>
<tr>
<td style="padding: 16px; border: 1px dashed #b8b8b8; color: #333;">Customer account balances</td>
<td style="padding: 16px; border: 1px dashed #b8b8b8; color: #333;">Whether every affected system has been repaired</td>
</tr>
<tr>
<td style="padding: 16px; border: 1px dashed #b8b8b8; color: #333;">Cold-wallet assets</td>
<td style="padding: 16px; border: 1px dashed #b8b8b8; color: #333;">A full technical explanation of the breach</td>
</tr>
</tbody>
</table>
<p>This is the practical distinction for users. The protection fund addresses whether Bitget says it can absorb the financial loss. It does not, by itself, restore confidence that the <a class="wpg-linkify wpg-tooltip" title="&lt;h3 class=&quot;wpg-tooltip-title&quot;&gt;&lt;span class=&quot;wpg-tooltip-term-title&quot;&gt;Wallet&lt;/span&gt;&lt;/h3&gt;&lt;div class=&quot;wpg-tooltip-content&quot;&gt;&lt;p&gt;A device or application that securely holds a user's public and private keys while allowing interaction with a blockchain network.&lt;/p&gt;&lt;/div&gt;">wallet</a> systems are ready for normal withdrawals.</p>
<p>Deposits and trading remain available, according to Bitget’s <a href="https://www.bitget.com/support/articles/12560603896024" target="_blank" rel="noopener nofollow">official security notice</a>. Withdrawals remain suspended while the exchange works on remediation and security hardening. Chen said Bitget would announce a restart schedule only once it can give a confirmed timeframe.</p>
<h2>The Remaining Question Is Inside Bitget’s Systems</h2>
<p>The initial $170 million alert asked whether the suspicious wallet movements were real. Bitget has now answered that part: it says the transfers were unauthorised and the total exposure was far higher.</p>
<p>The harder question remains. If private keys were not stolen, how did a compromised backend system generate transfer data that Bitget’s authorisation process accepted?</p>
<p>That answer—not another revised loss estimate—will show whether the exchange has addressed the weakness that allowed the breach in the first place.</p>
<hr>
<p style="text-align: center;"><em>This article is provided for informational purposes only and does not constitute financial or investment advice. Attribution and technical findings can change as Bitget and independent investigators release further evidence.</em></p>
<p>The post <a href="https://coindoo.com/bitget-breach-north-korea-link-probed-withdrawals-paused/" target="_blank" rel="nofollow noopener">Bitget Breach: North Korea Link Probed, Withdrawals Paused</a> appeared first on <a href="https://coindoo.com" target="_blank" rel="nofollow noopener">Coindoo</a>.</p>
<p><a href="https://cryptonews24.eu/market-overview">Check our Market Overview </a></p>
<p>Source: https://coindoo.com/bitget-breach-north-korea-link-probed-withdrawals-paused/</p>
<div id="ajax-load-more-3" class="ajax-load-more-wrap default" data-alm-id="" data-canonical-url="https://cryptonews24.eu/category/crime" data-slug="crime" data-post-id="6233" data-localized="ajax_load_more_3_vars" data-alm-object="ajax_load_more_3"><ul aria-live="polite" aria-atomic="true" class="alm-listing alm-ajax" data-container-type="ul" data-loading-style="default" data-repeater="default" data-post-type="post" data-order="DESC" data-orderby="date" data-offset="0" data-posts-per-page="5" data-scroll="false" data-button-label="Load More" data-prev-button-label="Load Previous"></ul><div class="alm-btn-wrap" style="visibility: hidden" data-rel="ajax-load-more-3"><button class="alm-load-more-btn " type="button">Load More</button></div></div>
]]></content:encoded>
					
					<wfw:commentRss>https://cryptonews24.eu/2026/09/cryptonews/bitget-breach-north-korea-link-probed-withdrawals-paused.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Binance Iran Scrutiny Tests Its Post-Settlement Controls</title>
		<link>https://cryptonews24.eu/2026/09/cryptonews/binance-iran-scrutiny-tests-its-post-settlement-controls.html</link>
					<comments>https://cryptonews24.eu/2026/09/cryptonews/binance-iran-scrutiny-tests-its-post-settlement-controls.html#respond</comments>
		
		<dc:creator><![CDATA[cryptonews]]></dc:creator>
		<pubDate>Tue, 22 Sep 2026 08:22:20 +0000</pubDate>
				<category><![CDATA[crime]]></category>
		<category><![CDATA[Cryptonews]]></category>
		<guid isPermaLink="false">https://cryptonews24.eu/2026/09/crypto-news/binance-iran-scrutiny-tests-its-post-settlement-controls.html</guid>

					<description><![CDATA[<a href="https://cryptonews24.eu/2026/09/cryptonews/binance-iran-scrutiny-tests-its-post-settlement-controls.html"><img width="150" height="150" src="https://cryptonews24.eu/wp-content/uploads/2026/08/binance-logo-phone-300-150x150.jpg" alt="Binance Iran Scrutiny Tests Its Post-Settlement Controls" align="left" style="margin: 0 20px 20px 0;max-width:100%" /></a><p>Kosta Gushterov Tue, 22 Sep 2026 07:26:00 +0000  Crime</p>
<p><a href="https://cryptonews24.eu/2026/09/cryptonews/binance-iran-scrutiny-tests-its-post-settlement-controls.html" rel="nofollow">Binance Iran Scrutiny Tests Its Post-Settlement Controls at Crypto Trading News &amp; Insights: Stay Ahead of the Game.</a></p>
]]></description>
										<content:encoded><![CDATA[<p>Where the case stands What is known Federal prosecutors are reportedly examining possible Iran-sanctions violations. Authorities are reportedly asking whether […]
</p><p>The post <a href="https://coindoo.com/binance-iran-scrutiny-tests-its-post-settlement-controls/" target="_blank" rel="nofollow noopener">Binance Iran Scrutiny Tests Its Post-Settlement Controls</a> appeared first on <a href="https://coindoo.com" target="_blank" rel="nofollow noopener">Coindoo</a>.</p>
<div style="margin: 26px 0; border: 1px solid #cbd5e1; border-radius: 12px; overflow: hidden; background: #ffffff;">
<div style="padding: 14px 18px; background: #172554; color: #ffffff;"><strong>Where the case stands</strong></div>
<div style="padding: 17px 18px; border-bottom: 1px solid #e2e8f0;">
<h3 style="margin: 0 0 10px; color: #047857;">What is known</h3>
<ul style="margin-bottom: 0;">
<li>Federal prosecutors are reportedly examining possible Iran-sanctions violations.</li>
<li>Authorities are reportedly asking whether Binance knowingly allowed certain trading.</li>
<li>Binance remains subject to compliance obligations imposed after its 2023 settlement.</li>
</ul>
</div>
<div style="padding: 17px 18px; background: #f8fafc;">
<h3 style="margin: 0 0 10px; color: #be123c;">What remains unknown</h3>
<ul style="margin-bottom: 0;">
<li>No new charges against Binance have been announced.</li>
<li>The period and transactions covered by the inquiry are undisclosed.</li>
<li>It is unclear whether this is a separate investigation or an expansion of earlier scrutiny.</li>
</ul>
</div>
</div>
<h2>The question is what Binance knew</h2>
<p>US federal prosecutors are investigating whether Binance violated sanctions against Iran by failing to prevent certain trading activity, according to a <a href="https://www.reuters.com/legal/government/binance-under-us-scrutiny-over-possible-iran-sanctions-violations-bloomberg-news-2026-09-22/" target="_blank" rel="noopener nofollow">Reuters report citing Bloomberg</a>.</p>
<p>The Manhattan US Attorney’s Office is reportedly leading the inquiry, with the Justice Department’s criminal division also involved. Prosecutors are said to be examining whether Binance knowingly allowed the trading.</p>
<p>That is a higher threshold than establishing that Iran-linked funds reached the exchange. Investigators would need to determine what information Binance possessed, whether its systems generated warnings and how the company responded.</p>
<p>The Justice Department declined to comment to Reuters, while the Manhattan US Attorney’s Office could not immediately be reached. The report relies on unnamed sources, and no public charging document has been filed.</p>
<h2>Binance made specific compliance promises in 2023</h2>
<p>Binance pleaded guilty in November 2023 to violating the Bank Secrecy Act, failing to register as a money-transmitting business and breaching the International Emergency Economic Powers Act.</p>
<p>Under its <a href="https://www.justice.gov/archives/opa/pr/binance-and-ceo-plead-guilty-federal-charges-4b-resolution" target="_blank" rel="noopener nofollow">Justice Department resolution</a>, the exchange agreed to approximately $4.32 billion in forfeiture and penalties. It was also required to strengthen its anti-money-laundering and sanctions systems and retain an independent compliance monitor for three years.</p>
<p>A separate <a href="https://home.treasury.gov/news/press-releases/jy1925" target="_blank" rel="noopener nofollow">Treasury Department settlement</a> imposed a five-year monitorship. The monitor received access to Binance’s books, records and systems and must report its findings to FinCEN, the Office of Foreign Assets Control and the Commodity Futures Trading Commission.</p>
<p>The earlier case already involved Iran. US authorities said Binance intentionally failed to stop its American customers from trading with users in sanctioned jurisdictions. Between January 2018 and May 2022, the exchange caused more than $898 million in trades between US users and people ordinarily resident in Iran, according to the Justice Department.</p>
<p>The latest scrutiny therefore matters most if it concerns conduct after the settlement. The issue would no longer be whether Binance once had inadequate controls—it admitted that. The issue would be whether the replacement controls performed differently.</p>
<div style="margin: 26px 0; padding: 19px 21px; border-left: 5px solid #7c3aed; border-radius: 8px; background: #f5f3ff; color: #1e293b;">
<h3 style="margin-top: 0; color: #5b21b6;">What the new controls are supposed to do</h3>
<ul style="margin-bottom: 0;">
<li>Verify customers and beneficial owners</li>
<li>Detect restricted locations and concealed access</li>
<li>Screen users and wallets against sanctions data</li>
<li>Trace deposits from high-risk counterparties</li>
<li>Escalate warnings for human review</li>
<li>Restrict accounts and report suspicious activity</li>
</ul>
</div>
<p>No compliance program can guarantee that illicit funds will never reach a platform. Its effectiveness depends on whether suspicious activity is detected, investigated and stopped within a reasonable period.</p>
<h2>The $61 million forfeiture case is relevant—but proves less than it may appear</h2>
<p>The reported investigation emerged days after Manhattan prosecutors filed a separate civil action seeking approximately $61 million in cryptocurrency allegedly derived from black-market Iranian oil sales.</p>
<p>The <a href="https://www.justice.gov/usao-sdny/pr/us-attorney-seeks-forfeiture-61-million-cryptocurrency-iranian-militarys-black-market" target="_blank" rel="noopener nofollow">Justice Department’s complaint</a> alleges that two Hong Kong companies, Blessed Trust and Hexa Whale, used Binance accounts to move proceeds from Iranian oil transactions.</p>
<p>Prosecutors connected the companies to a group of crypto addresses that allegedly received and distributed more than $1.5 billion. Some funds were reportedly routed to businesses and addresses associated with Iran’s Islamic Revolutionary Guard Corps.</p>
<p>The complaint concerns activity extending through 2024 and 2025, after the Binance settlement. However, it seeks forfeiture of the assets and does not charge Binance with laundering the money.</p>
<div style="margin: 24px 0; padding: 18px 20px; border: 1px solid #fed7aa; border-radius: 12px; background: #fff7ed;">
<h3 style="margin-top: 0; color: #9a3412;">The distinction that matters</h3>
<p><strong>The complaint alleges that customers used Binance accounts.</strong></p>
<p style="margin-bottom: 0;"><strong>It does not establish that Binance knew their stated businesses concealed Iranian oil transactions.</strong></p>
</div>
<p>The two developments may be connected, but no public source has established that the forfeiture complaint is the basis of the reported Binance inquiry. Treating them as one confirmed case would go beyond the available evidence.</p>
<h2>An Iranian connection is only the first step</h2>
<p>Several separate facts would need to be established before activity on Binance could become evidence of knowing corporate misconduct.</p>
<div style="margin: 26px 0; border: 1px solid #d9e1ee; border-radius: 12px; overflow: hidden; background: #ffffff;">
<div style="padding: 14px 18px; background: #0f766e; color: #ffffff;"><strong>From platform access to potential liability</strong></div>
<div style="padding: 15px 18px; border-bottom: 1px solid #e2e8f0;"><strong style="color: #0f766e;">1. A user connected with Iran accessed Binance</strong><br>
<span style="color: #475569;">This may breach platform restrictions but does not, by itself, identify a prohibited transaction.</span></div>
<div style="padding: 15px 18px; border-bottom: 1px solid #e2e8f0; background: #f8fafc;"><strong style="color: #0f766e;">2. Iran-linked funds passed through the account</strong><br>
<span style="color: #475569;">This establishes exposure to the funds, not prior knowledge of their origin.</span></div>
<div style="padding: 15px 18px; border-bottom: 1px solid #e2e8f0;"><strong style="color: #0f766e;">3. The activity involved a prohibited party or trade</strong><br>
<span style="color: #475569;">Investigators would then examine whether Binance’s screening systems detected the connection.</span></div>
<div style="padding: 15px 18px; background: #f8fafc;"><strong style="color: #0f766e;">4. Binance received clear warnings but allowed it to continue</strong><br>
<span style="color: #475569;">Evidence of this kind would create a more serious compliance and legal problem.</span></div>
</div>
<p>Iran is subject to broad US restrictions, but nationality, residency and inclusion on an OFAC sanctions list are not interchangeable. The legal analysis can depend on who controlled the account, the underlying transaction, the counterparties involved and whether the activity touched the US financial system.</p>
<h2>Binance says it investigates and removes prohibited users</h2>
<p>Binance told Reuters that it follows a zero-tolerance approach to sanctions violations, cooperates with law enforcement and works to remove bad actors.</p>
<p>The company has separately <a href="https://coindoo.com/binance-denies-slowing-us-crypto-investigations/" target="_blank" rel="nofollow noopener">denied that it reduced cooperation with US crypto investigations</a>, making its handling of alerts and law-enforcement requests part of the wider dispute.</p>
<p>Binance offered a similar defense after Reuters traced at least $676 million from addresses associated with the Dubai-based exchange Shelbit to its platform. The company said Shelbit itself did not hold a Binance account and had not been sanctioned. According to Binance, its compliance team investigated related users, froze their accounts and reported them to law enforcement.</p>
<style>
    .dark-mode .read-more {background-color: #343a40 !important;}
</style>
<div class="read-more pb-3 pt-3 pt-md-2 px-3 my-4 border bg-light">
<h5 class="text-uppercase border-bottom mb-3 pb-1 d-none d-md-block">READ MORE:</h5>
<p>    <a class="article row text-decoration-none" href="https://coindoo.com/robinhood-chains-transactions-arbitrum/" title="How Robinhood Chain’s 10M Daily Transactions Boost Arbitrum" target="_blank" rel="nofollow noopener"></a></p>
<div class="contentRight col-4">
            <span class="imgContainer mt-0"><br>
                <img decoding="async" class="image img-defer" src="https://cryptonews24.eu/wp-content/uploads/2026/03/robinhood231-560x373.jpg" width="560" style="display:block;margin:10px auto;max-width:560px;max-width:100%;"><br>
            </span>
        </div>
<div class="contentLeft col-8">
<h4 class="title mb-0">How Robinhood Chain’s 10M Daily Transactions Boost Arbitrum</h4>
</div>
<p>    
</p></div>
<p>The response describes what a working control system should eventually do. It leaves several questions unanswered:</p>
<div class="light-yellow-block">
<ul>
<li>When did Binance receive the first actionable warning?</li>
<li>How much activity occurred before the accounts were restricted?</li>
<li>Were earlier alerts escalated or dismissed?</li>
<li>Were the required reports submitted on time?</li>
<li>Could related customers return through new companies or accounts?</li>
</ul>
</div>
<h2>The timeline will decide what this story becomes</h2>
<p>The reported inquiry could end without charges, produce another enforcement action or lead to findings from Binance’s monitors. Until authorities disclose more, it cannot be treated as proof that the company breached its settlement obligations.</p>
<p>The most important evidence would show when Binance learned about the relevant customers and what happened next. A prompt investigation, account freeze and report to authorities could indicate that the post-settlement controls worked. Continued trading after clear internal warnings would suggest that the changes failed at the point where they mattered.</p>
<p>The presence of Iran-linked funds on Binance is therefore not the conclusion of the story. The decisive question is whether the exchange’s compliance machinery recognized the risk, and whether anyone chose to ignore it.</p>
<hr>
<p style="text-align: center;"><em>This article is provided for informational purposes only. A reported investigation does not establish wrongdoing, and allegations in civil complaints remain unproven unless established in court.</em></p>
<p>The post <a href="https://coindoo.com/binance-iran-scrutiny-tests-its-post-settlement-controls/" target="_blank" rel="nofollow noopener">Binance Iran Scrutiny Tests Its Post-Settlement Controls</a> appeared first on <a href="https://coindoo.com" target="_blank" rel="nofollow noopener">Coindoo</a>.</p>
<p><a href="https://cryptonews24.eu/market-overview">Check our Market Overview </a></p>
<p>Source: https://coindoo.com/binance-iran-scrutiny-tests-its-post-settlement-controls/</p>
<div id="ajax-load-more-4" class="ajax-load-more-wrap default" data-alm-id="" data-canonical-url="https://cryptonews24.eu/category/crime" data-slug="crime" data-post-id="6233" data-localized="ajax_load_more_4_vars" data-alm-object="ajax_load_more_4"><ul aria-live="polite" aria-atomic="true" class="alm-listing alm-ajax" data-container-type="ul" data-loading-style="default" data-repeater="default" data-post-type="post" data-order="DESC" data-orderby="date" data-offset="0" data-posts-per-page="5" data-scroll="false" data-button-label="Load More" data-prev-button-label="Load Previous"></ul><div class="alm-btn-wrap" style="visibility: hidden" data-rel="ajax-load-more-4"><button class="alm-load-more-btn " type="button">Load More</button></div></div>
]]></content:encoded>
					
					<wfw:commentRss>https://cryptonews24.eu/2026/09/cryptonews/binance-iran-scrutiny-tests-its-post-settlement-controls.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>One Attacker, Multiple Tokens: Inside the Fetch.ai Breach</title>
		<link>https://cryptonews24.eu/2026/09/cryptonews/one-attacker-multiple-tokens-inside-the-fetch-ai-breach.html</link>
					<comments>https://cryptonews24.eu/2026/09/cryptonews/one-attacker-multiple-tokens-inside-the-fetch-ai-breach.html#respond</comments>
		
		<dc:creator><![CDATA[cryptonews]]></dc:creator>
		<pubDate>Sun, 20 Sep 2026 18:57:22 +0000</pubDate>
				<category><![CDATA[crime]]></category>
		<category><![CDATA[Cryptonews]]></category>
		<guid isPermaLink="false">https://cryptonews24.eu/2026/09/crypto-news/one-attacker-multiple-tokens-inside-the-fetch-ai-breach.html</guid>

					<description><![CDATA[<a href="https://cryptonews24.eu/2026/09/cryptonews/one-attacker-multiple-tokens-inside-the-fetch-ai-breach.html"><img width="150" height="150" src="https://cryptonews24.eu/wp-content/uploads/2026/08/crypto-hack-239591295-150x150.jpg" alt="One Attacker, Multiple Tokens: Inside the Fetch.ai Breach" align="left" style="margin: 0 20px 20px 0;max-width:100%" /></a><p>Kosta Gushterov Sun, 20 Sep 2026 10:44:28 +0000  Crime</p>
<p><a href="https://cryptonews24.eu/2026/09/cryptonews/one-attacker-multiple-tokens-inside-the-fetch-ai-breach.html" rel="nofollow">One Attacker, Multiple Tokens: Inside the Fetch.ai Breach at Crypto Trading News &amp; Insights: Stay Ahead of the Game.</a></p>
]]></description>
										<content:encoded><![CDATA[<p>Key Takeaways Fetch.ai traced the attack to a leaked signing key. Approximately 8.7 million FET was removed. Nearly 409 million […]
</p><p>The post <a href="https://coindoo.com/one-attacker-multiple-tokens-inside-the-fetch-ai-breach/" target="_blank" rel="nofollow noopener">One Attacker, Multiple Tokens: Inside the Fetch.ai Breach</a> appeared first on <a href="https://coindoo.com" target="_blank" rel="nofollow noopener">Coindoo</a>.</p>
<div class="light-yellow-block">
<h2><strong>Key Takeaways</strong></h2>
<ul>
<li><strong>Fetch.ai traced the attack to a leaked signing key.</strong></li>
<li><strong>Approximately 8.7 million FET was removed.</strong></li>
<li><strong>Nearly 409 million unauthorized NTX was created.</strong></li>
<li><strong>Additional AGIX and WMTX mints were reported.</strong></li>
<li><strong>The investigation has not reached a final conclusion.</strong></li>
</ul>
</div>
<h2>Fetch.ai’s update changes the scope of the incident</h2>
<p>Initial reports focused on approximately 8.7 million FET, worth around $1.5 million, removed from Fetch.ai’s TokenConversionManagerV3 contract on <a href="https://cryptonews24.eu/2026/03/ethereum/ethereum-eth-the-global-backbone-of-decentralized-applications.html" data-internallinksmanager029f6b8e52c="6" title="Ethereum (ETH)">Ethereum</a>.</p>
<p><a href="https://x.com/blockaid_/status/2101426221825348095" target="_blank" rel="noopener nofollow">Blockaid said</a> the attacker presented a valid conversion-authorizer signature, allowing the contract to release its remaining FET balance. Fetch.ai has since published a <a href="https://x.com/Fetch_ai/status/2101595159054131393" target="_blank" rel="noopener nofollow">preliminary onchain analysis</a> tracing the attack path to a leaked signing key.</p>
<blockquote class="twitter-tweet">
<p dir="ltr" lang="en">An on-chain analysis of the exploit is now available on ASI:One. It traces the attack from the compromised signing key to the attacker’s cash-out wallets. This is not the final analysis.</p>
<p>Read the report: <a href="https://t.co/W95r50VMaY" target="_blank" rel="nofollow">https://t.co/W95r50VMaY</a></p>
<p>Together with <a href="https://x.com/SingularityNET?ref_src=twsrc%5Etfw" target="_blank" rel="nofollow">@SingularityNET</a>, we have deactivated…</p>
<p>— Fetch.ai (@Fetch_ai) <a href="https://x.com/Fetch_ai/status/2101595159054131393?ref_src=twsrc%5Etfw" target="_blank" rel="nofollow">September 20, 2026</a></p>
</blockquote>
<p><script async src="https://platform.x.com/widgets.js" charset="utf-8"></script></p>
<p>The project said it worked with SingularityNET to deactivate the affected wallets and contracts. It also cautioned that the analysis is preliminary and that the investigation remains open.</p>
<p>The same <a class="wpg-linkify wpg-tooltip" title="&lt;h3 class=&quot;wpg-tooltip-title&quot;&gt;&lt;span class=&quot;wpg-tooltip-term-title&quot;&gt;Wallet&lt;/span&gt;&lt;/h3&gt;&lt;div class=&quot;wpg-tooltip-content&quot;&gt;&lt;p&gt;A device or application that securely holds a user's public and private keys while allowing interaction with a blockchain network.&lt;/p&gt;&lt;/div&gt;">wallet</a> that received the FET was later linked to approximately 409 million NTX created through a NuNet deployer account. The tokens were valued near $460,000 when issued.</p>
<p>The incident widened again when <a href="https://lookonchain.com/feeds/73309" target="_blank" rel="noopener nofollow">PeckShield reported</a> that the wallet was also connected to unauthorized mints of approximately 260 million AGIX and 54 million WMTX. The attacker’s holdings were valued near $17 million when the security firm’s findings were reported.</p>
<p>The shared wallet is why researchers have attributed the transactions to the same attacker. It does not yet show whether one leaked key provided access to every affected contract or whether several credentials were compromised.</p>
<div style="display: flex; flex-wrap: wrap; gap: 14px; margin: 26px 0;">
<div style="flex: 1 1 250px; padding: 20px; border: 1px solid #bfdbfe; border-radius: 12px; background: #eff6ff;">
<h3 style="margin: 0 0 10px; color: #1d4ed8;">FET removed</h3>
<p style="margin: 0 0 8px;"><strong>Approximately 8.7 million FET</strong></p>
<p style="margin: 0;">Existing tokens were released from a converter contract.</p>
</div>
<div style="flex: 1 1 250px; padding: 20px; border: 1px solid #fecaca; border-radius: 12px; background: #fef2f2;">
<h3 style="margin: 0 0 10px; color: #b91c1c;">NTX created</h3>
<p style="margin: 0 0 8px;"><strong>Approximately 409 million NTX</strong></p>
<p style="margin: 0;">Tokens were reportedly issued without authorization.</p>
</div>
<div style="flex: 1 1 250px; padding: 20px; border: 1px solid #fde68a; border-radius: 12px; background: #fffbeb;">
<h3 style="margin: 0 0 10px; color: #a16207;">New findings</h3>
<p style="margin: 0 0 8px;"><strong>AGIX and WMTX mints reported</strong></p>
<p style="margin: 0;">PeckShield linked further token creation to the attacker.</p>
</div>
</div>
<h2>The dollar totals hide two different kinds of damage</h2>
<p>The FET and NTX incidents did not affect holders in the same way.</p>
<p>The FET transaction removed tokens that already existed. That created a known loss and gave the attacker assets that could be sold, but it did not directly increase the total number of FET tokens.</p>
<p>The reported NTX transaction reached the token’s issuance process. Instead of transferring a balance from one wallet to another, the deployer account apparently created tokens outside the expected distribution schedule.</p>
<p><a href="https://www.coingecko.com/en/coins/nunet" target="_blank" rel="noopener nofollow">CoinGecko lists</a> a maximum supply of one billion NTX. The reported unauthorized mint was therefore equal to roughly 41% of that amount.</p>
<p>That does not mean every unauthorized token entered circulation. Data providers may also exclude tokens that NuNet later invalidates, burns or replaces through a contract migration. The comparison shows why traders could no longer rely on the displayed supply figure without further clarification from the project.</p>
<p>The later AGIX and WMTX findings make this distinction more important. The central question is no longer how much was removed from one contract, but how widely the compromised permissions could be used to create or release assets.</p>
<h2>Why NTX fell much harder than FET</h2>
<p>NTX fell roughly 70% after the incident became public and reached a new all-time low on September 20. FET declined by a much smaller percentage while the wider crypto market was also trading lower.</p>
<p>The timing and scale of the unauthorized mint provide a plausible explanation for the difference, although they do not prove that the incident caused every part of the NTX decline.</p>
<h3>The reported mint was large relative to supply</h3>
<p>Creating an amount equal to approximately 41% of the stated maximum supply introduced immediate dilution concerns. Traders also had no clear information about how many of the tokens could reach exchanges or decentralized liquidity pools.</p>
<h3>NTX trades in a thin market</h3>
<p>CoinGecko showed less than $50,000 in rolling 24-hour NTX volume when checked. The unauthorized tokens had been valued near $460,000 when created, making the reported mint roughly ten times larger than the token’s recent daily turnover.</p>
<p>The comparison does not measure how much the attacker sold. It illustrates the available market depth: attempting to sell even a fraction of such a position could move the price sharply when relatively few buyers are waiting nearby.</p>
<h3>The market could not immediately verify that minting had stopped</h3>
<p>A stolen balance has a measurable limit. An exposed minting permission creates a more open-ended risk because holders need evidence that the authority has been revoked before they can rule out further issuance.</p>
<div style="margin: 26px 0; padding: 20px 22px; border: 1px solid #fca5a5; border-radius: 12px; background: #fff7f7;">
<h3 style="margin-top: 0; color: #b91c1c;">Why the distinction matters</h3>
<p style="margin-bottom: 0;">FET holders could see how many tokens left the converter. NTX holders also had to question whether the published supply still described the tokens that could exist.</p>
</div>
<h2>A valid signature can still authorize an attack</h2>
<p>A smart contract can verify that a signature came from an approved key, but it cannot determine whether the legitimate owner intended the transaction. Once the signing key was compromised, the attacker’s instruction could appear valid to the contract.</p>
<p>This is why describing the incident only as a smart-contract exploit would be incomplete. The code controlling the withdrawal and the security of the key authorizing it formed one system. A failure in either part could expose the assets.</p>
<p><a href="https://x.com/SlowMist_Team/status/2101503515877396639" target="_blank" rel="noopener nofollow">SlowMist noted</a> that Fetch.ai’s incoming conversion function relied on a single externally owned account signature and lacked some of the additional restrictions present in another conversion function. Fetch.ai’s final report will need to establish how that design interacted with the leaked key.</p>
<p>Blockchain transparency helps researchers follow the resulting transactions, but it does not prevent an approved credential from being misused. A similar limitation appeared in <a href="https://coindoo.com/polymarkets-10m-fraud-attempt-tests-its-blockchain-brand/" target="_blank" rel="nofollow noopener">Polymarket’s reported $10 million fraud attempt</a>: public records can expose what happened after an instruction was accepted, while the harder security problem is deciding who should have been permitted to issue it.</p>
<style>
    .dark-mode .read-more {background-color: #343a40 !important;}
</style>
<div class="read-more pb-3 pt-3 pt-md-2 px-3 my-4 border bg-light">
<h5 class="text-uppercase border-bottom mb-3 pb-1 d-none d-md-block">READ MORE:</h5>
<p>    <a class="article row text-decoration-none" href="https://coindoo.com/ethereum-jumps-above-2600-reaches-highest-price-since-january/" title="Ethereum Jumps Above $2,600, Reaches Highest Price Since January" target="_blank" rel="nofollow noopener"></a></p>
<div class="contentRight col-4">
            <span class="imgContainer mt-0"><br>
                <img decoding="async" class="image img-defer" src="https://cryptonews24.eu/wp-content/uploads/2026/05/ethereum-eth-logo-p-560x373.jpg" width="560" style="display:block;margin:10px auto;max-width:560px;max-width:100%;"><br>
            </span>
        </div>
<div class="contentLeft col-8">
<h4 class="title mb-0">Ethereum Jumps Above $2,600, Reaches Highest Price Since January</h4>
</div>
<p>    
</p></div>
<h2>Deactivating the contracts contains the risk, but does not resolve it</h2>
<p>Fetch.ai’s decision to deactivate affected wallets and contracts is an important containment step. Holders still need a final account of which permissions were exposed and how the affected tokens will be handled.</p>
<div style="margin: 26px 0; border: 1px solid #d9e1ee; border-radius: 12px; overflow: hidden; background: #ffffff;">
<div style="padding: 14px 18px; background: #172554; color: #ffffff;"><strong>What the final investigation needs to establish</strong></div>
<div style="padding: 15px 18px; border-bottom: 1px solid #e5e7eb;"><strong style="color: #1d4ed8;">Access</strong><br>
<span style="color: #475569;">Which keys were exposed and whether every related permission has been revoked.</span></div>
<div style="padding: 15px 18px; border-bottom: 1px solid #e5e7eb;"><strong style="color: #b91c1c;">Supply</strong><br>
<span style="color: #475569;">Which unauthorized tokens will remain recognized by contracts, exchanges and data providers.</span></div>
<div style="padding: 15px 18px; border-bottom: 1px solid #e5e7eb;"><strong style="color: #a16207;">Exposure</strong><br>
<span style="color: #475569;">Whether other contracts use the same signing arrangements or deployer accounts.</span></div>
<div style="padding: 15px 18px;"><strong style="color: #047857;">Recovery</strong><br>
<span style="color: #475569;">Whether the projects will freeze, burn or replace unauthorized tokens and address the losses.</span></div>
</div>
<h2>The permissions now matter more than the first loss estimate</h2>
<p>The incident was initially described as an attack involving approximately $2 million. The later findings make that figure a poor measure of its potential reach.</p>
<p>The more important boundary is the authority the leaked credentials provided. Fetch.ai and the connected projects will need to show that the affected permissions have been removed and that unauthorized tokens cannot continue moving through recognized contracts.</p>
<p>Until that evidence is available, token prices will reflect more than the assets already taken. They will also carry uncertainty over which supply figures and contract permissions the market can still trust.</p>
<hr>
<p style="text-align: center;"><em>This article is provided for informational purposes only and does not constitute financial or investment advice. The investigation remains ongoing, and the reported figures may change as the affected projects and security researchers publish additional findings.</em></p>
<p>The post <a href="https://coindoo.com/one-attacker-multiple-tokens-inside-the-fetch-ai-breach/" target="_blank" rel="nofollow noopener">One Attacker, Multiple Tokens: Inside the Fetch.ai Breach</a> appeared first on <a href="https://coindoo.com" target="_blank" rel="nofollow noopener">Coindoo</a>.</p>
<p><a href="https://cryptonews24.eu/market-overview">Check our Market Overview </a></p>
<p>Source: https://coindoo.com/one-attacker-multiple-tokens-inside-the-fetch-ai-breach/</p>
<div id="ajax-load-more-5" class="ajax-load-more-wrap default" data-alm-id="" data-canonical-url="https://cryptonews24.eu/category/crime" data-slug="crime" data-post-id="6233" data-localized="ajax_load_more_5_vars" data-alm-object="ajax_load_more_5"><ul aria-live="polite" aria-atomic="true" class="alm-listing alm-ajax" data-container-type="ul" data-loading-style="default" data-repeater="default" data-post-type="post" data-order="DESC" data-orderby="date" data-offset="0" data-posts-per-page="5" data-scroll="false" data-button-label="Load More" data-prev-button-label="Load Previous"></ul><div class="alm-btn-wrap" style="visibility: hidden" data-rel="ajax-load-more-5"><button class="alm-load-more-btn " type="button">Load More</button></div></div>
]]></content:encoded>
					
					<wfw:commentRss>https://cryptonews24.eu/2026/09/cryptonews/one-attacker-multiple-tokens-inside-the-fetch-ai-breach.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>US Plans BTC-e Notices for 300,000 Email Addresses</title>
		<link>https://cryptonews24.eu/2026/09/cryptonews/us-plans-btc-e-notices-for-300000-email-addresses.html</link>
					<comments>https://cryptonews24.eu/2026/09/cryptonews/us-plans-btc-e-notices-for-300000-email-addresses.html#respond</comments>
		
		<dc:creator><![CDATA[cryptonews]]></dc:creator>
		<pubDate>Fri, 18 Sep 2026 05:29:51 +0000</pubDate>
				<category><![CDATA[crime]]></category>
		<category><![CDATA[Cryptonews]]></category>
		<guid isPermaLink="false">https://cryptonews24.eu/2026/09/crypto-news/us-plans-btc-e-notices-for-300000-email-addresses.html</guid>

					<description><![CDATA[<a href="https://cryptonews24.eu/2026/09/cryptonews/us-plans-btc-e-notices-for-300000-email-addresses.html"><img width="150" height="150" src="https://cryptonews24.eu/wp-content/uploads/2026/09/email-photo-150x150.jpg" alt="US Plans BTC-e Notices for 300,000 Email Addresses" align="left" style="margin: 0 20px 20px 0;max-width:100%" /></a><p>Kosta Gushterov Thu, 17 Sep 2026 20:34:29 +0000  Crime</p>
<p><a href="https://cryptonews24.eu/2026/09/cryptonews/us-plans-btc-e-notices-for-300000-email-addresses.html" rel="nofollow">US Plans BTC-e Notices for 300,000 Email Addresses at Crypto Trading News &amp; Insights: Stay Ahead of the Game.</a></p>
]]></description>
										<content:encoded><![CDATA[<p>Date check: A September 17 release from San Diego Defenders brought new attention to the case, but Judge Carl J. […]
</p><p>The post <a href="https://coindoo.com/us-plans-btc-e-notices-for-300000-email-addresses/" target="_blank" rel="nofollow noopener">US Plans BTC-e Notices for 300,000 Email Addresses</a> appeared first on <a href="https://coindoo.com" target="_blank" rel="nofollow noopener">Coindoo</a>.</p>
<div style="margin: 24px 0; padding: 16px 18px; border-left: 5px solid #d97706; background: #fffbeb;"><strong>Date check:</strong> A <a href="https://www.globenewswire.com/news-release/2026/09/17/3364297/0/en/san-diego-defenders-forfeiture-law-firm-responds-to-planned-additional-btc-e-notice.html" target="_blank" rel="noopener nofollow">September 17 release from San Diego Defenders</a> brought new attention to the case, but Judge Carl J. Nichols signed the underlying <a href="https://docs.justia.com/cases/federal/district-courts/district-of-columbia/dcdce/1%3A2025cv02085/282163/392" target="_blank" rel="noopener nofollow">court order</a> on August 13.</div>
<h2>The case has moved slowly since the 2017 seizure</h2>
<p>BTC-e was taken offline in 2017 as US authorities pursued the exchange and people connected to its operation. The current civil forfeiture case concerns assets the government alleges were held in BTC-e operating wallets and connected to unlawful activity.</p>
<div style="margin: 24px 0; border-left: 3px solid #334155; padding-left: 18px;">
<p><strong>2017:</strong> Authorities seize BTC-e servers and disrupt the exchange.</p>
<p><strong>June 2025:</strong> The government files the current forfeiture complaint.</p>
<p><strong>August 13, 2026:</strong> The court permits another round of direct notice.</p>
<p><strong>From September 15:</strong> The government must submit monthly progress reports until the notice round is complete.</p>
</div>
<p>The additional emails are intended for addresses associated with accounts that showed positive balances when the servers were seized. The order does not say that every address remains active, belongs to a different person or corresponds to a valid claim.</p>
<h2>The 300,000 figure measures notice, not ownership</h2>
<p>The government’s list comes from BTC-e account records. It therefore measures the number of email addresses selected for outreach—not the number of verified customers, successful claimants or eventual recoveries.</p>
<p>One person may have controlled more than one account, some addresses may now be inactive and some records may not contain enough information to connect an account to its former owner. Other recipients may decide that the value involved does not justify entering a federal forfeiture proceeding.</p>
<p>The court also granted late-claim requests submitted by several specifically identified parties after the government withdrew its opposition. That ruling applies to those requests; it is not a general extension for every former BTC-e customer.</p>
<h2>The government is trying to prevent a notice challenge</h2>
<p>Judge Nichols declined to stop the additional notice round because Supplemental Rule G requires the government to make a reasonable effort to contact people who may claim an interest in property targeted for forfeiture.</p>
<p>That requirement affects more than former users. If the notice process is later found inadequate, a settlement or final judgment could face a challenge from someone who was entitled to notice but did not receive it. Sending emails to the wider account list reduces that risk before the court resolves ownership of the assets.</p>
<h2>This is forfeiture, not a bankruptcy payout</h2>
<p>BTC-e’s former customers are not automatically creditors waiting for an estate administrator to distribute funds. In a civil forfeiture case, the government asks the court to transfer specified property to the United States. A former user seeking part of that property generally must assert a legal interest and support it with evidence.</p>
<p>That means an old account balance is useful evidence, but it does not reserve a corresponding amount of cryptocurrency for its former owner. The court must still consider whether the person has standing, whether the documentation is credible and whether the claimed interest can be connected to the property in the case.</p>
<h2>Recipients face two separate response routes</h2>
<div style="display: flex; flex-wrap: wrap; gap: 16px; margin: 24px 0;">
<div style="flex: 1 1 280px; padding: 18px; border: 1px solid #bfdbfe; border-radius: 10px; background: #eff6ff;">
<h3 style="margin-top: 0; color: #1d4ed8;">Verified court claim</h3>
<p>This route is used to assert an ownership interest and contest the forfeiture in federal court.</p>
<p>San Diego Defenders says a direct notice may require the claim within 35 days after the government sends it. An answer or Rule 12 motion may then be due within 21 days after the claim is filed.</p>
</div>
<div style="flex: 1 1 280px; padding: 18px; border: 1px solid #bbf7d0; border-radius: 10px; background: #f0fdf4;">
<h3 style="margin-top: 0; color: #047857;">Remission or mitigation petition</h3>
<p>This is an administrative request asking the Justice Department to return property or reduce the effect of forfeiture.</p>
<p>According to the law firm, the petition may be due within 30 days after the recipient receives notice.</p>
</div>
</div>
<p>These are separate procedures, and filing one may not preserve rights under the other. Anyone who receives a notice should follow the dates and instructions in that document rather than relying solely on general deadline summaries.</p>
<h2>A positive balance does not establish a claim by itself</h2>
<p><a href="https://www.fincen.gov/news/news-releases/fincen-fines-btc-e-virtual-currency-exchange-110-million-facilitating-ransomware" target="_blank" rel="noopener nofollow">FinCEN said in 2017</a> that BTC-e often collected little customer information beyond a username, password and email address. That history may make it harder to match some accounts with real-world identities nearly a decade later.</p>
<p>The forfeiture complaint concerns assets allegedly held in BTC-e’s operating wallets rather than property already separated into customer-specific accounts. Former users asserting legitimate balances may therefore need records such as account statements, deposit and withdrawal histories, transaction hashes, archived emails or proof that they controlled the relevant funding address.</p>
<p>The government’s allegations against BTC-e do not mean every customer participated in illegal activity. They do mean that a database entry alone may not answer who owns the seized property.</p>
<style>
    .dark-mode .read-more {background-color: #343a40 !important;}
</style>
<div class="read-more pb-3 pt-3 pt-md-2 px-3 my-4 border bg-light">
<h5 class="text-uppercase border-bottom mb-3 pb-1 d-none d-md-block">READ MORE:</h5>
<p>    <a class="article row text-decoration-none" href="https://coindoo.com/clarity-vote-fed-decision-crypto-scenarios-watch/" title="CLARITY Vote and Fed Decision: Crypto Scenarios to Watch" target="_blank" rel="nofollow noopener"></a></p>
<div class="contentRight col-4">
            <span class="imgContainer mt-0"><br>
                <img decoding="async" class="image img-defer" src="https://cryptonews24.eu/wp-content/uploads/2026/04/altcoins-cryptocurrency-203-560x420.webp" width="560" style="display:block;margin:10px auto;max-width:560px;max-width:100%;"><br>
            </span>
        </div>
<div class="contentLeft col-8">
<h4 class="title mb-0">CLARITY Vote and Fed Decision: Crypto Scenarios to Watch</h4>
</div>
<p>    
</p></div>
<h2>Unexpected BTC-e emails should be verified carefully</h2>
<p>A mass notice concerning old cryptocurrency balances is likely to attract impersonation attempts. Before opening attachments, submitting documents or following payment instructions, recipients should:</p>
<div class="light-yellow-block">
<ul>
<li>Confirm that the message identifies the correct federal case and court.</li>
<li>Compare its instructions with the public docket or an official government contact.</li>
<li>Check the sender’s full email domain, not only the displayed name.</li>
<li>Never provide a wallet seed phrase, private key or exchange password.</li>
<li>Reject demands for a “release fee” paid in cryptocurrency.</li>
</ul>
</div>
<p>Neither a verified claim nor a remission petition requires someone to surrender the credentials controlling a cryptocurrency wallet.</p>
<h2>Monthly reports should show how the notice round develops</h2>
<p>The court ordered the government to file an initial progress report by September 15 and another report every 30 days until the additional notice process is complete. The contents of the first report were not available in the public sources reviewed for this article.</p>
<p>Those filings should provide the next measurable update: whether the emails have been sent, how quickly the government is working through the list and whether the expanded outreach brings more claims into the case.</p>
<p>Until those claims are reviewed, 300,000 describes the reach of the proposed notice, not the likely number of recoveries. The monthly filings will indicate whether the wider effort produces additional ownership claims or extends an already lengthy proceeding.</p>
<hr>
<p style="text-align: center;"><em>This article is provided for informational purposes only and does not constitute legal or financial advice. Deadlines and filing requirements may depend on the notice received and the circumstances of an individual claim.</em></p>
<p>The post <a href="https://coindoo.com/us-plans-btc-e-notices-for-300000-email-addresses/" target="_blank" rel="nofollow noopener">US Plans BTC-e Notices for 300,000 Email Addresses</a> appeared first on <a href="https://coindoo.com" target="_blank" rel="nofollow noopener">Coindoo</a>.</p>
<p><a href="https://cryptonews24.eu/market-overview">Check our Market Overview </a></p>
<p>Source: https://coindoo.com/us-plans-btc-e-notices-for-300000-email-addresses/</p>
<div id="ajax-load-more-6" class="ajax-load-more-wrap default" data-alm-id="" data-canonical-url="https://cryptonews24.eu/category/crime" data-slug="crime" data-post-id="6233" data-localized="ajax_load_more_6_vars" data-alm-object="ajax_load_more_6"><ul aria-live="polite" aria-atomic="true" class="alm-listing alm-ajax" data-container-type="ul" data-loading-style="default" data-repeater="default" data-post-type="post" data-order="DESC" data-orderby="date" data-offset="0" data-posts-per-page="5" data-scroll="false" data-button-label="Load More" data-prev-button-label="Load Previous"></ul><div class="alm-btn-wrap" style="visibility: hidden" data-rel="ajax-load-more-6"><button class="alm-load-more-btn " type="button">Load More</button></div></div>
]]></content:encoded>
					
					<wfw:commentRss>https://cryptonews24.eu/2026/09/cryptonews/us-plans-btc-e-notices-for-300000-email-addresses.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Revolut Exposes Bitcoin Activity in Fake Request Incident</title>
		<link>https://cryptonews24.eu/2026/09/cryptonews/revolut-exposes-bitcoin-activity-in-fake-request-incident.html</link>
					<comments>https://cryptonews24.eu/2026/09/cryptonews/revolut-exposes-bitcoin-activity-in-fake-request-incident.html#respond</comments>
		
		<dc:creator><![CDATA[cryptonews]]></dc:creator>
		<pubDate>Sun, 13 Sep 2026 19:35:56 +0000</pubDate>
				<category><![CDATA[crime]]></category>
		<category><![CDATA[Cryptonews]]></category>
		<guid isPermaLink="false">https://cryptonews24.eu/2026/09/crypto-news/revolut-exposes-bitcoin-activity-in-fake-request-incident.html</guid>

					<description><![CDATA[<a href="https://cryptonews24.eu/2026/09/cryptonews/revolut-exposes-bitcoin-activity-in-fake-request-incident.html"><img width="150" height="150" src="https://cryptonews24.eu/wp-content/uploads/2026/09/revolut-329591-scaled-e1768248685202-150x150.webp" alt="Revolut Exposes Bitcoin Activity in Fake Request Incident" align="left" style="margin: 0 20px 20px 0;max-width:100%" /></a><p>Kosta Gushterov Sat, 12 Sep 2026 10:32:22 +0000  Crime</p>
<p><a href="https://cryptonews24.eu/2026/09/cryptonews/revolut-exposes-bitcoin-activity-in-fake-request-incident.html" rel="nofollow">Revolut Exposes Bitcoin Activity in Fake Request Incident at Crypto Trading News &amp; Insights: Stay Ahead of the Game.</a></p>
]]></description>
										<content:encoded><![CDATA[<p>Key Takeaways Revolut reportedly acted on a fake request. Identity and <a href="https://cryptonews24.eu/2026/03/bitcoin-news-now/technical-indicators-in-crypto-trading-a-general-overview-2.html" data-internallinksmanager029f6b8e52c="5" title="Bitcoin">Bitcoin</a>-related records were included. No private-key exposure has been […]
</p><p>The post <a href="https://coindoo.com/revolut-exposes-bitcoin-activity-fake-request-incident/" target="_blank" rel="nofollow noopener">Revolut Exposes Bitcoin Activity in Fake Request Incident</a> appeared first on <a href="https://coindoo.com" target="_blank" rel="nofollow noopener">Coindoo</a>.</p>
<h2><strong>Key Takeaways</strong></h2>
<div class="light-yellow-block">
<ul>
<li><strong>Revolut reportedly acted on a fake request.</strong></li>
<li><strong>Identity and Bitcoin-related records were included.</strong></li>
<li><strong>No private-key exposure has been reported.</strong></li>
<li><strong>The main risk is targeted impersonation.</strong></li>
</ul>
</div>
<h2><strong>The problem began with a fake legal request</strong></h2>
<p><a href="https://www.coindesk.com/tech/2026/09/12/bitcoin-activity-passports-exposed-after-revolut-falls-for-fake-government-request" target="_blank" rel="noopener nofollow">CoinDesk reported</a> that Revolut notified affected users after responding to an emergency government request it later determined was fraudulent when it contacted the relevant authority. The reported disclosure included personal and Bitcoin-related records.</p>
<p>The incident was not described as an attacker taking over a <a class="wpg-linkify wpg-tooltip" title="&lt;h3 class=&quot;wpg-tooltip-title&quot;&gt;&lt;span class=&quot;wpg-tooltip-term-title&quot;&gt;Wallet&lt;/span&gt;&lt;/h3&gt;&lt;div class=&quot;wpg-tooltip-content&quot;&gt;&lt;p&gt;A device or application that securely holds a user's public and private keys while allowing interaction with a blockchain network.&lt;/p&gt;&lt;/div&gt;">wallet</a> or breaking into a customer account. Instead, the failure appears to have occurred while Revolut was verifying a request for customer data. That makes it different from a typical exchange hack: sensitive information may be released without an attacker first defeating a user’s password or two-factor authentication.</p>
<p>The notice was <a href="https://x.com/MagicalTux/status/2098669462816018627" target="_blank" rel="noopener nofollow">shared publicly on X</a>. Revolut had not published a wider public statement or disclosed the number of affected accounts at the time of writing, so the incident’s scale remains unclear.</p>
<blockquote class="twitter-tweet">
<p dir="ltr" lang="en">Revolut customers were targeted in a fraudulent emergency data request sent via an email at a “government agency.” <a href="https://t.co/sS2sbwAt8r" target="_blank" rel="nofollow">https://t.co/sS2sbwAt8r</a></p>
<p>— Mark Karpelès (@MagicalTux) <a href="https://x.com/MagicalTux/status/2098669462816018627?ref_src=twsrc%5Etfw" target="_blank" rel="nofollow">September 12, 2026</a></p>
</blockquote>
<p><script async src="https://platform.x.com/widgets.js" charset="utf-8"></script></p>
<h2><strong>Why Bitcoin records raise the stakes</strong></h2>
<p>CoinDesk reported that the material included identity documents, account information, withdrawal records and Bitcoin-related transaction history. The customer notice did not indicate that private keys, seed phrases or direct access to customer funds had been exposed.</p>
<div style="margin: 28px 0; border: 1px solid #d7dee8; border-radius: 12px; overflow: hidden;">
<div style="padding: 14px 18px; background: #101827; color: #ffffff;"><strong>What the reported records could enable</strong></div>
<table style="width: 100%; border-collapse: collapse; font-size: 15px;">
<tbody>
<tr style="background: #f8fafc;">
<td style="padding: 14px 18px; border-bottom: 1px solid #d7dee8;"><strong>Reported record</strong></td>
<td style="padding: 14px 18px; border-bottom: 1px solid #d7dee8;"><strong>Practical risk</strong></td>
</tr>
<tr>
<td style="padding: 14px 18px; border-bottom: 1px solid #d7dee8;">Passport or identity document</td>
<td style="padding: 14px 18px; border-bottom: 1px solid #d7dee8;">More convincing identity-verification and account-recovery scams.</td>
</tr>
<tr style="background: #f8fafc;">
<td style="padding: 14px 18px; border-bottom: 1px solid #d7dee8;">Contact and account details</td>
<td style="padding: 14px 18px; border-bottom: 1px solid #d7dee8;">Messages tailored to resemble a bank, exchange or compliance team.</td>
</tr>
<tr>
<td style="padding: 14px 18px;">Bitcoin activity or withdrawal history</td>
<td style="padding: 14px 18px;">A way to identify people likely to hold crypto and refer to genuine past transactions.</td>
</tr>
</tbody>
</table>
</div>
<p>Blockchain records do not contain passport details. The risk begins when a regulated platform’s records connect transactions to a verified identity. If reported wallet references, withdrawal details or transaction identifiers can be matched with public blockchain activity, that link may remain useful to attackers after an account password is changed.</p>
<h2><strong>Safe funds do not end the risk</strong></h2>
<p>This was not a custody breach in the usual sense. But a detailed identity-and-activity profile can support months of fraudulent contact. An attacker who knows a person used Bitcoin, has their contact information and can cite a genuine withdrawal has a far more credible basis for a fake support or compliance message.</p>
<p>That is the same risk identified after the <a href="https://coindoo.com/israeli-crypto-broker-bits-of-gold-warns-customers-after-a-data-breach/" target="_blank" rel="nofollow noopener">Bits of Gold customer-data breach</a>: even when assets and private keys remain inaccessible, identity and wallet-related records can make impersonation attempts much more convincing.</p>
<p>A scammer does not need a seed phrase to exploit this information. They may instead ask for a one-time code, claim a wallet must be moved to a “secure” address, or direct a victim to a clone of a legitimate support page. The useful response is caution, not a rushed transfer.</p>
<h2><strong>Not every Bitcoin record identifies a public wallet</strong></h2>
<p>Revolut says it maintains an internal ledger for customer crypto exposure. For that reason, the reported Bitcoin transaction history may refer to activity recorded inside Revolut rather than a complete list of public blockchain addresses.</p>
<p>The distinction matters. Revolut should clarify whether the data included external wallet addresses, transaction identifiers, destination information or only internal account history. These create very different levels of exposure and would determine how easily an attacker could connect a customer’s real identity to visible on-chain activity.</p>
<p>The available evidence supports a narrower conclusion: no private-key leak has been reported, but the stated combination of identity documents and crypto-related records creates a distinct security concern.</p>
<style>
    .dark-mode .read-more {background-color: #343a40 !important;}
</style>
<div class="read-more pb-3 pt-3 pt-md-2 px-3 my-4 border bg-light">
<h5 class="text-uppercase border-bottom mb-3 pb-1 d-none d-md-block">READ MORE:</h5>
<p>    <a class="article row text-decoration-none" href="https://coindoo.com/eu-crypto-wallet-makers-now-report-exploits/" title="EU Crypto Wallet Makers Now Have 24 Hours to Report Exploits" target="_blank" rel="nofollow noopener"></a></p>
<div class="contentRight col-4">
            <span class="imgContainer mt-0"><br>
                <img decoding="async" class="image img-defer" src="https://cryptonews24.eu/wp-content/uploads/2026/07/hardware-crypto-wallets-03925-560x373.jpg" width="560" style="display:block;margin:10px auto;max-width:560px;max-width:100%;"><br>
            </span>
        </div>
<div class="contentLeft col-8">
<h4 class="title mb-0">EU Crypto Wallet Makers Now Have 24 Hours to Report Exploits</h4>
</div>
<p>    
</p></div>
<h2><strong>What Revolut users can do now</strong></h2>
<p>Users who received a Revolut notification should confirm it through the app’s support channel or by visiting Revolut directly, rather than following links in an email or social-media post. They should ask which exact data fields were disclosed and retain a copy of the response.</p>
<p>Revolut users who have not received a notice do not need to move assets or assume their data was exposed. They should watch for an in-app message or a notification sent through Revolut’s verified channels, review the security of their recovery email and phone number, and be especially cautious of unsolicited messages that mention crypto withdrawals or ask them to “secure” a wallet. Changing a password can protect account access, but it does not undo an identity-data disclosure, so the priority is to prevent impersonation rather than make rushed transfers.</p>
<p>Anyone concerned that identity-document data may be involved should treat unsolicited account-recovery, compliance and wallet-verification messages as high risk. No legitimate agent needs a seed phrase, password or one-time authentication code. The <a href="https://www.edpb.europa.eu/topics/security-data-breaches/personal-data-breaches_en" target="_blank" rel="noopener nofollow">European Data Protection Board</a> lists fraud, identity theft and financial loss among the possible consequences of personal-data breaches.</p>
<h2><strong>The next answer needs to be about linkability</strong></h2>
<p>Revolut now needs to explain whether the disclosed records included external wallet addresses, transaction identifiers or only internal account history. That distinction will determine whether affected customers face a conventional identity-fraud problem or a more durable link between their real identity and publicly traceable Bitcoin activity.</p>
<hr>
<p style="text-align: center;"><strong><em>This article is for informational purposes only and does not constitute legal, financial or cybersecurity advice.</em></strong></p>
<p>The post <a href="https://coindoo.com/revolut-exposes-bitcoin-activity-fake-request-incident/" target="_blank" rel="nofollow noopener">Revolut Exposes Bitcoin Activity in Fake Request Incident</a> appeared first on <a href="https://coindoo.com" target="_blank" rel="nofollow noopener">Coindoo</a>.</p>
<p><a href="https://cryptonews24.eu/market-overview">Check our Market Overview </a></p>
<p>Source: https://coindoo.com/revolut-exposes-bitcoin-activity-fake-request-incident/</p>
<div id="ajax-load-more-7" class="ajax-load-more-wrap default" data-alm-id="" data-canonical-url="https://cryptonews24.eu/category/crime" data-slug="crime" data-post-id="6233" data-localized="ajax_load_more_7_vars" data-alm-object="ajax_load_more_7"><ul aria-live="polite" aria-atomic="true" class="alm-listing alm-ajax" data-container-type="ul" data-loading-style="default" data-repeater="default" data-post-type="post" data-order="DESC" data-orderby="date" data-offset="0" data-posts-per-page="5" data-scroll="false" data-button-label="Load More" data-prev-button-label="Load Previous"></ul><div class="alm-btn-wrap" style="visibility: hidden" data-rel="ajax-load-more-7"><button class="alm-load-more-btn " type="button">Load More</button></div></div>
]]></content:encoded>
					
					<wfw:commentRss>https://cryptonews24.eu/2026/09/cryptonews/revolut-exposes-bitcoin-activity-in-fake-request-incident.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Mexico Raids Cartel-Linked Crypto Farm Over Power Theft</title>
		<link>https://cryptonews24.eu/2026/09/cryptonews/mexico-raids-cartel-linked-crypto-farm-over-power-theft.html</link>
					<comments>https://cryptonews24.eu/2026/09/cryptonews/mexico-raids-cartel-linked-crypto-farm-over-power-theft.html#respond</comments>
		
		<dc:creator><![CDATA[cryptonews]]></dc:creator>
		<pubDate>Sun, 13 Sep 2026 19:35:47 +0000</pubDate>
				<category><![CDATA[crime]]></category>
		<category><![CDATA[Cryptonews]]></category>
		<guid isPermaLink="false">https://cryptonews24.eu/2026/09/crypto-news/mexico-raids-cartel-linked-crypto-farm-over-power-theft.html</guid>

					<description><![CDATA[<a href="https://cryptonews24.eu/2026/09/cryptonews/mexico-raids-cartel-linked-crypto-farm-over-power-theft.html"><img width="150" height="150" src="https://cryptonews24.eu/wp-content/uploads/2026/09/bitcoin-mining-crypto-img-3004-150x150.jpg" alt="Mexico Raids Cartel-Linked Crypto Farm Over Power Theft" align="left" style="margin: 0 20px 20px 0;max-width:100%" /></a><p>Alexander Zdravkov Sat, 12 Sep 2026 18:11:54 +0000  Crime</p>
<p><a href="https://cryptonews24.eu/2026/09/cryptonews/mexico-raids-cartel-linked-crypto-farm-over-power-theft.html" rel="nofollow">Mexico Raids Cartel-Linked Crypto Farm Over Power Theft at Crypto Trading News &amp; Insights: Stay Ahead of the Game.</a></p>
]]></description>
										<content:encoded><![CDATA[<p>Key Takeaways Authorities found a remote crypto farm. Electricity theft remains the core allegation. Hardware does not identify the mined […]
</p><p>The post <a href="https://coindoo.com/mexico-raids-cartel-linked-crypto-farm-over-power-theft/" target="_blank" rel="nofollow noopener">Mexico Raids Cartel-Linked Crypto Farm Over Power Theft</a> appeared first on <a href="https://coindoo.com" target="_blank" rel="nofollow noopener">Coindoo</a>.</p>
<div class="light-yellow-block">
<h2><strong>Key Takeaways</strong></h2>
<ul>
<li><strong>Authorities found a remote crypto farm.</strong></li>
<li><strong>Electricity theft remains the core allegation.</strong></li>
<li><strong>Hardware does not identify the mined asset.</strong></li>
<li><strong>Cartel and laundering links remain unproven.</strong></li>
<li><strong>Wallet records could determine the case.</strong></li>
</ul>
</div>
<h2>Authorities are investigating an alleged power-theft operation</h2>
<p>Authorities in Puebla dismantled a cryptocurrency facility near the Nuevo Necaxa hydroelectric system in the Sierra Norte region. <a href="https://www.reuters.com/world/americas/hidden-crypto-farm-mexican-mountains-puts-spotlight-cartel-funding-2026-09-12/" target="_blank" rel="noopener nofollow">Reuters reported</a> that the site contained around 300 graphics processing units, medium-voltage equipment and satellite antennas.</p>
<p>Authorities are investigating whether the site was connected illegally to nearby power infrastructure. If confirmed, stolen electricity would lower the cost of running the machines, allowing the operator to retain mining rewards without paying what is usually one of the largest recurring expenses.</p>
<p>Mining cryptocurrency is not prohibited in Mexico by itself. According to the authorities cited by Reuters and <a href="https://elpais.com/mexico/economia/2026-09-08/una-granja-de-criptomonedas-clandestina-roba-luz-a-una-presa-el-inusual-hallazgo-en-una-comunidad-remota-de-puebla.html" target="_blank" rel="noopener nofollow">El País</a>, the investigation centres on suspected power theft. Reuters also reported that officials are examining possible organised-crime and laundering links, while Mexico’s federal prosecutor declined to comment because the case is active.</p>
<div style="margin: 26px 0; border: 1px solid #d9e1ee; border-radius: 10px; overflow: hidden;">
<div style="padding: 14px 18px; background: #eef4ff; border-bottom: 1px solid #d9e1ee;"><strong>What the published evidence shows</strong></div>
<div style="padding: 16px 18px; border-bottom: 1px solid #e5e7eb;">
<p style="margin: 0 0 6px; font-weight: bold; color: #166534;">Physical setup</p>
<p style="margin: 0;">Authorities found a sizeable computing and electrical installation at a site under investigation for suspected illegal power use.</p>
</div>
<div style="padding: 16px 18px;">
<p style="margin: 0 0 6px; font-weight: bold; color: #b45309;">Information not yet public</p>
<p style="margin: 0;">The reports do not identify the operator, the asset mined, a mining-pool account, a wallet address or an exchange account.</p>
</div>
</div>
<h2>The equipment list does not prove Bitcoin was mined</h2>
<p>A machine seizure establishes capacity, not financial output. The published list does not show which asset was mined, how much was produced or who received any proceeds.</p>
<p>That gap matters in this case because the equipment described was GPU-based. GPUs can support different crypto and computing workloads. <a href="https://cryptonews24.eu/2026/03/bitcoin-news-now/technical-indicators-in-crypto-trading-a-general-overview-2.html" data-internallinksmanager029f6b8e52c="5" title="Bitcoin">Bitcoin</a> mining, by contrast, has long been dominated by specialised ASIC machines, which displaced GPU mining because they are far more efficient at Bitcoin’s SHA-256 calculations, according to the <a href="https://ccaf.io/cbnsi/cbeci/methodology" target="_blank" rel="noopener nofollow">Cambridge Centre for Alternative Finance</a>.</p>
<p>The GPU list therefore cannot establish that the facility was producing Bitcoin rather than another asset or running another type of high-intensity computing. Reuters reported that this was the fourth crypto farm found near the dam since early 2025, which gives authorities reason to investigate the area’s power infrastructure. It does not establish common ownership or a single criminal network.</p>
<h2>Mining does not by itself establish a laundering trail</h2>
<p>If the site was mining, stolen electricity may have reduced the cost of generating crypto rewards. That economic incentive helps explain why authorities examine alleged illegal mining operations, but it does not show that the Puebla site produced or laundered criminal proceeds.</p>
<p>A solo miner receives a reward through the <a class="wpg-linkify wpg-tooltip" title="&lt;h3 class=&quot;wpg-tooltip-title&quot;&gt;&lt;span class=&quot;wpg-tooltip-term-title&quot;&gt;Blockchain&lt;/span&gt;&lt;/h3&gt;&lt;div class=&quot;wpg-tooltip-content&quot;&gt;&lt;p class=&quot;&quot; data-start=&quot;39&quot; data-end=&quot;620&quot;&gt;At its core, blockchain is a digital chain of blocks, but not in the traditional sense. These 'blocks' consist of bits of information, and when we refer to a 'block' and 'chain,' we're talking about digital data stored in a public database. Blockchain provides an innovative way to transfer information automatically and securely. A transaction begins when one party creates a block, which is then verified by thousands, even millions, of computers across the network. This decentralized ledger of financial transactions is constantly evolving, with new data continuously added.&lt;/p&gt;
&lt;p class=&quot;&quot; data-start=&quot;622&quot; data-end=&quot;909&quot;&gt;What makes blockchain tamper-proof is that each record is unique, with its own distinct history. To alter one record would require changing the entire chain of millions of other records. Blockchain is grounded in three key principles: decentralization, transparency, and immutability.&lt;/p&gt;
&lt;/div&gt;">blockchain</a>’s block-reward transaction—unrelated to the Coinbase exchange. A miner using a pool receives payouts based on its share of computing work. Identifying either an address or a pool account would allow investigators to examine later transfers and seek records from exchanges if funds were sent there.</p>
<p>Attribution is the difficult part. A transaction does not reveal its owner on its own, and intermediary wallets or pooled payouts can obscure the route. Once investigators identify a relevant address, however, each subsequent transfer can provide additional transaction history. The difference matters when authorities assess whether crypto was simply the alleged output of stolen power or part of a wider laundering route.</p>
<p>The same problem appears in the analysis of <a href="https://coindoo.com/binance-research-75b-in-illicit-crypto-is-stranded-on-chain-and-cannot-get-out/" target="_blank" rel="nofollow noopener">illicit funds that remain traceable onchain</a>: moving crypto between wallets does not necessarily remove the record investigators can analyse.</p>
<style>
    .dark-mode .read-more {background-color: #343a40 !important;}
</style>
<div class="read-more pb-3 pt-3 pt-md-2 px-3 my-4 border bg-light">
<h5 class="text-uppercase border-bottom mb-3 pb-1 d-none d-md-block">READ MORE:</h5>
<p>    <a class="article row text-decoration-none" href="https://coindoo.com/bnb-chain-surpasses-solana-with-3-6b-rwa-growth/" title="BNB Chain Surpasses Solana With $3.6B RWA Growth" target="_blank" rel="nofollow noopener"></a></p>
<div class="contentRight col-4">
            <span class="imgContainer mt-0"><br>
                <img decoding="async" class="image img-defer" src="https://cryptonews24.eu/wp-content/uploads/2026/04/bnbbinancecoin-560x315.png" width="560" style="display:block;margin:10px auto;max-width:560px;max-width:100%;"><br>
            </span>
        </div>
<div class="contentLeft col-8">
<h4 class="title mb-0">BNB Chain Surpasses Solana With $3.6B RWA Growth</h4>
</div>
<p>    
</p></div>
<h2>Power theft is often the first operational clue</h2>
<p>A legal mining business must cover electricity, equipment, cooling, maintenance and the changing difficulty of mining. An operator that allegedly bypasses the grid still has equipment and upkeep costs, but may avoid one of the largest expenses.</p>
<p>Remote sites can reduce visibility, but the Puebla operation still drew attention through unusual electricity use and mechanical noise, Reuters reported. Meter anomalies, transformer records, equipment purchases, satellite-internet accounts and property access can help establish who ran a site before investigators identify any <a class="wpg-linkify wpg-tooltip" title="&lt;h3 class=&quot;wpg-tooltip-title&quot;&gt;&lt;span class=&quot;wpg-tooltip-term-title&quot;&gt;Wallet&lt;/span&gt;&lt;/h3&gt;&lt;div class=&quot;wpg-tooltip-content&quot;&gt;&lt;p&gt;A device or application that securely holds a user's public and private keys while allowing interaction with a blockchain network.&lt;/p&gt;&lt;/div&gt;">wallet</a>.</p>
<h2>Similar raids point to an energy-theft model</h2>
<p>Puebla is not an isolated example of alleged power theft involving crypto equipment, although the available cases do not establish a shared criminal network. In recent mining raids in Malaysia, the focus was likewise on suspected unauthorised connections to the power grid rather than the act of mining itself.</p>
<p>The common incentive is simple: shifting the cost of electricity onto a utility or public grid can change an operation’s economics. The crypto element then becomes a separate financial question, what asset was generated, who controlled it and how it was moved.</p>
<h2>What evidence would connect the raid to a wider financial network?</h2>
<p>The next disclosures matter more than the number of seized machines. Ownership documents could link the equipment to an operator. Mining-pool records or wallet addresses could identify output, while exchange deposits, cash-out activity or transfers connected to known criminal entities could show whether that output entered a broader financial network.</p>
<p>The raid may show how the alleged operation was financed day to day: through an attempt to avoid electricity costs. Wallet, pool and cash-out records would show whether the resulting crypto became part of a provable cartel-finance or laundering chain.</p>
<hr>
<p style="text-align: center;"><em>This article is provided for informational purposes only and does not constitute legal, financial or investment advice.</em></p>
<p>The post <a href="https://coindoo.com/mexico-raids-cartel-linked-crypto-farm-over-power-theft/" target="_blank" rel="nofollow noopener">Mexico Raids Cartel-Linked Crypto Farm Over Power Theft</a> appeared first on <a href="https://coindoo.com" target="_blank" rel="nofollow noopener">Coindoo</a>.</p>
<p><a href="https://cryptonews24.eu/market-overview">Check our Market Overview </a></p>
<p>Source: https://coindoo.com/mexico-raids-cartel-linked-crypto-farm-over-power-theft/</p>
<div id="ajax-load-more-8" class="ajax-load-more-wrap default" data-alm-id="" data-canonical-url="https://cryptonews24.eu/category/crime" data-slug="crime" data-post-id="6233" data-localized="ajax_load_more_8_vars" data-alm-object="ajax_load_more_8"><ul aria-live="polite" aria-atomic="true" class="alm-listing alm-ajax" data-container-type="ul" data-loading-style="default" data-repeater="default" data-post-type="post" data-order="DESC" data-orderby="date" data-offset="0" data-posts-per-page="5" data-scroll="false" data-button-label="Load More" data-prev-button-label="Load Previous"></ul><div class="alm-btn-wrap" style="visibility: hidden" data-rel="ajax-load-more-8"><button class="alm-load-more-btn " type="button">Load More</button></div></div>
]]></content:encoded>
					
					<wfw:commentRss>https://cryptonews24.eu/2026/09/cryptonews/mexico-raids-cartel-linked-crypto-farm-over-power-theft.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>EU Crypto Wallet Makers Now Have 24 Hours to Report Exploits</title>
		<link>https://cryptonews24.eu/2026/09/cryptonews/eu-crypto-wallet-makers-now-have-24-hours-to-report-exploits.html</link>
					<comments>https://cryptonews24.eu/2026/09/cryptonews/eu-crypto-wallet-makers-now-have-24-hours-to-report-exploits.html#respond</comments>
		
		<dc:creator><![CDATA[cryptonews]]></dc:creator>
		<pubDate>Sat, 12 Sep 2026 09:28:10 +0000</pubDate>
				<category><![CDATA[crime]]></category>
		<category><![CDATA[Cryptonews]]></category>
		<guid isPermaLink="false">https://cryptonews24.eu/2026/09/crypto-news/eu-crypto-wallet-makers-now-have-24-hours-to-report-exploits.html</guid>

					<description><![CDATA[<a href="https://cryptonews24.eu/2026/09/cryptonews/eu-crypto-wallet-makers-now-have-24-hours-to-report-exploits.html"><img width="150" height="150" src="https://cryptonews24.eu/wp-content/uploads/2026/07/hardware-crypto-wallets-03925-150x150.jpg" alt="EU Crypto Wallet Makers Now Have 24 Hours to Report Exploits" align="left" style="margin: 0 20px 20px 0;max-width:100%" /></a><p>Kosta Gushterov Fri, 11 Sep 2026 09:11:27 +0000  Crime</p>
<p><a href="https://cryptonews24.eu/2026/09/cryptonews/eu-crypto-wallet-makers-now-have-24-hours-to-report-exploits.html" rel="nofollow">EU Crypto Wallet Makers Now Have 24 Hours to Report Exploits at Crypto Trading News &amp; Insights: Stay Ahead of the Game.</a></p>
]]></description>
										<content:encoded><![CDATA[<p>Key Takeaways Reporting starts only after active exploitation. First warning arrives within 24 hours. Commercial wallet products are likely covered. […]
</p><p>The post <a href="https://coindoo.com/eu-crypto-wallet-makers-now-report-exploits/" target="_blank" rel="nofollow noopener">EU Crypto Wallet Makers Now Have 24 Hours to Report Exploits</a> appeared first on <a href="https://coindoo.com" target="_blank" rel="nofollow noopener">Coindoo</a>.</p>
<h2><strong>Key Takeaways</strong></h2>
<div class="light-yellow-block">
<ul>
<li><strong>Reporting starts only after active exploitation.</strong></li>
<li><strong>First warning arrives within 24 hours.</strong></li>
<li><strong>Commercial wallet products are likely covered.</strong></li>
<li><strong>Most CRA rules start December 2027.</strong></li>
</ul>
</div>
<h2>The 24-hour reporting rule starts before the wider CRA</h2>
<p>From September 11, manufacturers must report actively exploited vulnerabilities and severe security incidents affecting products with digital elements made available on the EU market. The report is submitted through the <a href="https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp" target="_blank" rel="noopener nofollow">Single Reporting Platform operated by ENISA</a> to the CSIRT in the Member State of the manufacturer’s main establishment and, in normal circumstances, to ENISA.</p>
<p>Most of the EU Cyber Resilience Act (CRA) applies from December 11, 2027, including its wider requirements around product design, documentation and conformity. Article 14, the provision covering exploited vulnerabilities and severe incidents, starts earlier.</p>
<p>That means a wallet company may not yet face the full CRA compliance regime, but it can already have a statutory deadline if an exploit is active. The requirement also applies to in-scope products made available in the EU before December 2027, not only to future devices and software releases.</p>
<h2>Hardware and software wallets may be covered</h2>
<p>The CRA applies to hardware and software products made available commercially in the EU when their intended or reasonably foreseeable use includes a direct or indirect logical or physical connection to a device or network. Commercial hardware wallets and desktop or mobile wallet applications could therefore fall within scope.</p>
<p>The legal obligation sits with the <em>manufacturer</em>: the person or company that develops a product, or has it developed, and markets it under its own name or trademark. A business selling a hardware device or distributing <a class="wpg-linkify wpg-tooltip" title="&lt;h3 class=&quot;wpg-tooltip-title&quot;&gt;&lt;span class=&quot;wpg-tooltip-term-title&quot;&gt;Wallet&lt;/span&gt;&lt;/h3&gt;&lt;div class=&quot;wpg-tooltip-content&quot;&gt;&lt;p&gt;A device or application that securely holds a user's public and private keys while allowing interaction with a blockchain network.&lt;/p&gt;&lt;/div&gt;">wallet</a> software in the EU is a clearer example than an individual contributor to an unrelated open-source project.</p>
<p>Because crypto wallets are not named in the CRA, a specific product’s status may still require a legal assessment.</p>
<div style="margin: 28px 0; padding: 22px; background: #f7f8fc; border: 1px solid #e5e7ef; border-radius: 12px;">
<p style="margin: 0 0 16px; font-size: 18px;"><strong>The CRA reporting timeline after a manufacturer becomes aware</strong></p>
<div style="display: flex; flex-wrap: wrap; gap: 10px; align-items: stretch;">
<div style="flex: 1 1 165px; padding: 14px; background: #ffffff; border-radius: 8px; border: 1px solid #e5e7ef;"><strong>Within 24 hours</strong><br>
<span style="font-size: 14px;">Early warning to authorities and, where applicable, affected EU markets.</span></div>
<div style="flex: 1 1 165px; padding: 14px; background: #ffffff; border-radius: 8px; border: 1px solid #e5e7ef;"><strong>Within 72 hours</strong><br>
<span style="font-size: 14px;">Product details, nature of the exploit, mitigation and user actions.</span></div>
<div style="flex: 1 1 165px; padding: 14px; background: #ffffff; border-radius: 8px; border: 1px solid #e5e7ef;"><strong>Within 14 days</strong><br>
<span style="font-size: 14px;">Final exploited-vulnerability report after a corrective measure is available.</span></div>
<div style="flex: 1 1 165px; padding: 14px; background: #ffffff; border-radius: 8px; border: 1px solid #e5e7ef;"><strong>Within one month</strong><br>
<span style="font-size: 14px;">Final severe-incident report after the 72-hour notification.</span></div>
</div>
</div>
<h2>What wallet makers must report in 24 hours</h2>
<p>The first submission is an early warning, not a completed technical investigation. When a manufacturer becomes aware of an actively exploited vulnerability, it must notify the authorities without undue delay and no later than 24 hours later. The early warning must indicate the Member States where the company knows the affected product has been made available, where applicable.</p>
<p>The same deadline applies to a severe incident affecting product security. In that case, the early warning must at least state whether the company suspects unlawful or malicious activity caused the incident, as well as the relevant markets where the product is available.</p>
<p>More detail is due within 72 hours. The <a href="https://digital-strategy.ec.europa.eu/en/policies/cra-reporting" target="_blank" rel="noopener nofollow">European Commission’s reporting guidance</a> says this notification must include available information about the product and the general nature of the exploit and vulnerability.</p>
<p>It must also cover corrective or mitigating measures already taken, steps users can take, and, where applicable, how sensitive the manufacturer considers the information to be.</p>
<h2>Active exploitation is the key legal trigger</h2>
<p>The 24-hour clock does not start whenever a researcher privately reports a bug. It applies when a manufacturer becomes aware of an <strong>actively exploited</strong> vulnerability, meaning the flaw is being used against the product, or of a severe incident affecting product security. A company can receive a report, investigate it and prepare a patch without automatically falling into the Article 14 deadline. Once it learns that attackers are exploiting the flaw before the fix is complete, the regulated reporting process begins.</p>
<p>Recent Coldcard coverage shows why this threshold matters. In a <a href="https://coindoo.com/crypto-wallet-maker-issues-warning-btc/" target="_blank" rel="noopener nofollow">July warning involving potentially weak seed generation</a>, the practical risk was not limited to identifying the flaw: affected users needed to determine whether their seed was exposed and move funds if necessary.</p>
<h2>The report goes to authorities, not automatically to the public</h2>
<p>A fast reporting deadline may sound like a requirement to reveal an unpatched wallet flaw immediately. That is not what the CRA says. The initial report goes to the relevant CSIRT and ENISA through the Single Reporting Platform; it is not an automatic public advisory or a mandatory blog post containing technical exploit details.</p>
<p>The regulation requires authorities and other parties involved in its application to protect confidential information, including source code, trade secrets and information that could undermine an investigation. In cases involving coordinated vulnerability disclosure, a CSIRT can delay dissemination of an exploited-vulnerability notification to other CSIRTs where justified cybersecurity grounds exist.</p>
<p>Public disclosure remains possible when it is needed to prevent or mitigate a severe incident, handle an ongoing incident or serve the public interest. A CSIRT may then inform the public or require the manufacturer to do so after consulting the company. Wallet makers must give authorities enough information to assess the risk while telling users how to protect themselves without disclosing details that could aid an attacker.</p>
<style>
    .dark-mode .read-more {background-color: #343a40 !important;}
</style>
<div class="read-more pb-3 pt-3 pt-md-2 px-3 my-4 border bg-light">
<h5 class="text-uppercase border-bottom mb-3 pb-1 d-none d-md-block">READ MORE:</h5>
<p>    <a class="article row text-decoration-none" href="https://coindoo.com/ripple-governed-ai-treasury-bet/" title="Ripple Adds Governed AI to Its $1B Treasury Bet" target="_blank" rel="nofollow noopener"></a></p>
<div class="contentRight col-4">
            <span class="imgContainer mt-0"><br>
                <img decoding="async" class="image img-defer" src="https://cryptonews24.eu/wp-content/uploads/2026/08/ripplenet-560x350.webp" width="560" style="display:block;margin:10px auto;max-width:560px;max-width:100%;"><br>
            </span>
        </div>
<div class="contentLeft col-8">
<h4 class="title mb-0">Ripple Adds Governed AI to Its $1B Treasury Bet</h4>
</div>
<p>    
</p></div>
<h2>Open-source wallets are not automatically exempt</h2>
<p>The CRA does not apply to free and open-source software that is not made available on the market in the course of commercial activity. It also does not apply to people who merely contribute code to open-source software that is not under their responsibility.</p>
<p>That is not a blanket exemption for open-source wallet projects. The <a href="https://digital-strategy.ec.europa.eu/en/policies/cra-open-source" target="_blank" rel="noopener nofollow">Commission’s open-source guidance</a> states that a manufacturer placing a free and open-source product on the market remains subject to manufacturer obligations. A product being free does not necessarily mean its supply is non-commercial.</p>
<p>The CRA also creates a separate category for open-source software stewards: legal entities that provide sustained support for a specific open-source product intended for commercial activity. They are not subject to CRA administrative fines, but Article 14 can still require reporting when they are involved in the product’s development or when severe incidents affect the development systems they provide.</p>
<h2>A patch may still leave wallet users exposed</h2>
<p>For crypto wallets, the end of a technical incident is not always the moment a security update becomes available. An update can prevent new exposure while leaving keys, seed phrases or wallet setups created under affected software at risk.</p>
<p>That distinction was clear when <a href="https://coindoo.com/coldcard-releases-security-update-but-affected-seeds-need-replacing/" target="_blank" rel="noopener nofollow">Coldcard released a security update for an earlier seed-generation issue</a>. Updating the device did not make previously generated affected seeds safe; holders still needed to create fresh keys and move their funds. Under the new CRA rule, that operational response may now run alongside a mandatory authority notification when active exploitation is identified.</p>
<p>Wallet makers now need a documented 24-hour process for deciding whether exploitation is active, notifying authorities, preparing mitigation and warning affected users. The next exploit will show whether firms can meet that legal deadline while the incident is still being investigated and a full remediation plan may not yet exist.</p>
<p>The post <a href="https://coindoo.com/eu-crypto-wallet-makers-now-report-exploits/" target="_blank" rel="nofollow noopener">EU Crypto Wallet Makers Now Have 24 Hours to Report Exploits</a> appeared first on <a href="https://coindoo.com" target="_blank" rel="nofollow noopener">Coindoo</a>.</p>
<p><a href="https://cryptonews24.eu/market-overview">Check our Market Overview </a></p>
<p>Source: https://coindoo.com/eu-crypto-wallet-makers-now-report-exploits/</p>
<div id="ajax-load-more-9" class="ajax-load-more-wrap default" data-alm-id="" data-canonical-url="https://cryptonews24.eu/category/crime" data-slug="crime" data-post-id="6233" data-localized="ajax_load_more_9_vars" data-alm-object="ajax_load_more_9"><ul aria-live="polite" aria-atomic="true" class="alm-listing alm-ajax" data-container-type="ul" data-loading-style="default" data-repeater="default" data-post-type="post" data-order="DESC" data-orderby="date" data-offset="0" data-posts-per-page="5" data-scroll="false" data-button-label="Load More" data-prev-button-label="Load Previous"></ul><div class="alm-btn-wrap" style="visibility: hidden" data-rel="ajax-load-more-9"><button class="alm-load-more-btn " type="button">Load More</button></div></div>
]]></content:encoded>
					
					<wfw:commentRss>https://cryptonews24.eu/2026/09/cryptonews/eu-crypto-wallet-makers-now-have-24-hours-to-report-exploits.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Bit2Me Builds a Crypto-Seizure Unit for Police and Courts</title>
		<link>https://cryptonews24.eu/2026/09/cryptonews/bit2me-builds-a-crypto-seizure-unit-for-police-and-courts.html</link>
					<comments>https://cryptonews24.eu/2026/09/cryptonews/bit2me-builds-a-crypto-seizure-unit-for-police-and-courts.html#respond</comments>
		
		<dc:creator><![CDATA[cryptonews]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 18:57:10 +0000</pubDate>
				<category><![CDATA[crime]]></category>
		<category><![CDATA[Cryptonews]]></category>
		<guid isPermaLink="false">https://cryptonews24.eu/2026/09/crypto-news/bit2me-builds-a-crypto-seizure-unit-for-police-and-courts.html</guid>

					<description><![CDATA[<a href="https://cryptonews24.eu/2026/09/cryptonews/bit2me-builds-a-crypto-seizure-unit-for-police-and-courts.html"><img width="150" height="150" src="https://cryptonews24.eu/wp-content/uploads/2026/09/regulation-judge-seize-150x150.jpg" alt="Bit2Me Builds a Crypto-Seizure Unit for Police and Courts" align="left" style="margin: 0 20px 20px 0;max-width:100%" /></a><p>Kosta Gushterov Tue, 08 Sep 2026 09:48:35 +0000  Crime</p>
<p><a href="https://cryptonews24.eu/2026/09/cryptonews/bit2me-builds-a-crypto-seizure-unit-for-police-and-courts.html" rel="nofollow">Bit2Me Builds a Crypto-Seizure Unit for Police and Courts at Crypto Trading News &amp; Insights: Stay Ahead of the Game.</a></p>
]]></description>
										<content:encoded><![CDATA[<p>Key Takeaways Bit2Shield links tracing, custody and liquidation. Authorities control when seized assets are sold. Bitcoinforme handles crypto-to-euro conversions under […]
</p><p>The post <a href="https://coindoo.com/bit2me-builds-crypto-seizure-unit-police-courts/" target="_blank" rel="nofollow noopener">Bit2Me Builds a Crypto-Seizure Unit for Police and Courts</a> appeared first on <a href="https://coindoo.com" target="_blank" rel="nofollow noopener">Coindoo</a>.</p>
<h2><strong>Key Takeaways</strong></h2>
<div class="light-yellow-block">
<ul>
<li><strong>Bit2Shield links tracing, custody and liquidation.</strong></li>
<li><strong>Authorities control when seized assets are sold.</strong></li>
<li><strong>Bitcoinforme handles crypto-to-euro conversions under MiCA.</strong></li>
<li><strong>Multisignature key control remains publicly undisclosed.</strong></li>
<li><strong>Bit2Me reports €1.5 million processed in 2025.</strong></li>
</ul>
</div>
<h2>Bit2Shield connects police operations to asset recovery</h2>
<p>Bit2Shield is the trading name of CryptoShield S.L., a separate company within Bit2Me Group. Spain’s <a href="https://www.boe.es/diario_borme/txt.php?id=BORME-A-2026-165-12" target="_blank" rel="noopener nofollow">official commercial register</a> shows that it began operating on July 23, 2026. Its registered activities include technological investigations, forensic analysis, expert reports, operational support and blockchain intelligence.</p>
<p>CryptoShield’s sole shareholder and administrator is Devteam S.L., which Bit2Me identifies among the companies in its corporate group. Bitcoinforme S.L., a separate entity in the same group, operates Bit2Me’s regulated exchange services.</p>
<p>Bit2Me says Bit2Shield will serve police, courts, public bodies and financial institutions. Its work will extend from the initial investigation to the eventual transfer of sale proceeds.</p>
<p>Bit2Shield is a private service provider, not an enforcement authority. It can assist with a seizure or liquidation only under instructions from the police, a court or another competent body.</p>
<p>Its investigations division will be led by Adrián Maroño, a former member of the Spanish Civil Guard’s Central Operational Unit, according to a <a href="https://www.coindesk.com/business/2026/09/02/bit2me-sets-up-specialized-unit-to-help-law-enforcement-track-down-crypto-assets" target="_blank" rel="noopener nofollow">statement Bit2Me shared with CoinDesk</a>.</p>
<div style="margin: 28px 0; overflow: hidden; border: 1px solid #dbe3f1; border-radius: 16px; background: #ffffff; box-shadow: 0 4px 14px rgba(15,23,42,0.08);">
<div style="padding: 18px 22px; background: linear-gradient(135deg,#0f172a,#1e3a8a); color: #ffffff;">
<p style="margin: 0; font-size: 20px; line-height: 1.3;"><strong>How the proposed seizure process works</strong></p>
</div>
<div style="padding: 18px;">
<table style="width: 100%; border-collapse: collapse; table-layout: fixed; font-size: 16px;">
<thead>
<tr style="background: #f8fafc; color: #0f172a;">
<th style="width: 27%; padding: 13px; text-align: left; border-bottom: 1px solid #dbe3f1; overflow-wrap: anywhere;">Stage</th>
<th style="padding: 13px; text-align: left; border-bottom: 1px solid #dbe3f1; overflow-wrap: anywhere;">Bit2Shield’s stated role</th>
</tr>
</thead>
<tbody>
<tr>
<td style="padding: 13px; border-bottom: 1px solid #e2e8f0; vertical-align: top;"><strong>Identification</strong></td>
<td style="padding: 13px; border-bottom: 1px solid #e2e8f0; vertical-align: top;">Help investigators identify wallets, credentials and relevant transaction data.</td>
</tr>
<tr style="background: #f8fafc;">
<td style="padding: 13px; border-bottom: 1px solid #e2e8f0; vertical-align: top;"><strong>Tracing</strong></td>
<td style="padding: 13px; border-bottom: 1px solid #e2e8f0; vertical-align: top;">Follow blockchain transactions and prepare digitally signed forensic reports.</td>
</tr>
<tr>
<td style="padding: 13px; border-bottom: 1px solid #e2e8f0; vertical-align: top;"><strong>Custody</strong></td>
<td style="padding: 13px; border-bottom: 1px solid #e2e8f0; vertical-align: top;">Arrange multisignature cold storage for seized assets.</td>
</tr>
<tr style="background: #f8fafc;">
<td style="padding: 13px; border-bottom: 1px solid #e2e8f0; vertical-align: top;"><strong>Liquidation</strong></td>
<td style="padding: 13px; border-bottom: 1px solid #e2e8f0; vertical-align: top;">Arrange a sale after authorization from the competent authority.</td>
</tr>
<tr>
<td style="padding: 13px; vertical-align: top;"><strong>Settlement</strong></td>
<td style="padding: 13px; vertical-align: top;">Convert the assets through Bitcoinforme and transfer euros to an official government account.</td>
</tr>
</tbody>
</table>
</div>
</div>
<h2>The €1.5 million figure needs context</h2>
<p>Bit2Me says it processed approximately €1.5 million in seized cryptocurrency during 2025 while working on matters involving Europol, Interpol and Spanish police. According to the company, Chainalysis was used to trace the assets before their conversion into euros for the state.</p>
<p>The figure shows that the group performed seizure-related work before CryptoShield was formally established. It does not reveal the number of cases, the assets involved or whether €1.5 million represents their value when seized, transferred into custody or sold.</p>
<p>Bit2Me describes work on matters involving Europol and Interpol, but it has not published an agency statement or agreement establishing a formal partnership with Bit2Shield.</p>
<h2>What seizing cryptocurrency actually involves</h2>
<p>The first difficult step in the workflow is obtaining effective control of the cryptocurrency. The assets cannot be physically removed from a blockchain; authorities must instead prevent the previous controller from moving them.</p>
<p>With a self-custodied wallet, investigators may need to secure a hardware <a class="wpg-linkify wpg-tooltip" title="&lt;h3 class=&quot;wpg-tooltip-title&quot;&gt;&lt;span class=&quot;wpg-tooltip-term-title&quot;&gt;Wallet&lt;/span&gt;&lt;/h3&gt;&lt;div class=&quot;wpg-tooltip-content&quot;&gt;&lt;p&gt;A device or application that securely holds a user's public and private keys while allowing interaction with a blockchain network.&lt;/p&gt;&lt;/div&gt;">wallet</a>, private key, recovery phrase, passphrase or another signing device. Finding one item does not guarantee access. A wallet may require an additional passphrase or several signatures, while a recovered phrase may control addresses that have not yet been identified.</p>
<p>This distinction has become more important as <a href="https://coindoo.com/crime-gangs-private-vaults-cash-crypto/" target="_blank" rel="nofollow noopener">criminal groups reportedly use private vaults to store crypto credentials</a>. The coins remain recorded onchain; the physical item provides a way to authorize transactions. Investigators must still determine which addresses the recovered credentials control and whether another password, device or signature is required.</p>
<p>If the cryptocurrency is held by an exchange or another custodian, authorities may instead serve a lawful freezing or transfer order on that provider. <a href="https://www.unodc.org/documents/treaties/International_Cooperation_2025/4/CTOC_COP_WG.3_2025_4_E.pdf" target="_blank" rel="noopener nofollow">United Nations guidance</a> notes that seized virtual assets may be transferred to a secure wallet controlled by a court, law-enforcement body, asset-management office or appointed private company.</p>
<p>Bit2Shield may participate at several stages, but each has a different legal purpose. Tracing identifies the assets, freezing or seizure prevents them from being moved, confiscation permanently removes them through a legal decision, and disposal determines whether they are sold, retained or returned to victims.</p>
<h2>Blockchain records are only part of the evidence</h2>
<p>A blockchain can show that a transaction occurred, but an address does not contain the legal name of its controller. A court-ready case therefore needs evidence connecting the onchain activity to a person, account, device or organization.</p>
<p>Exact requirements differ by jurisdiction, but a defensible chain-of-custody record should identify where the credentials were found, who handled them, which addresses they controlled and how the assets were transferred. Transaction hashes, timestamps and access records can preserve an audit trail after the initial seizure.</p>
<p>Bit2Shield says it will prepare digitally signed reports and can present its findings in court. A digital signature can establish that a report has not been altered since it was signed, but it does not prove that the underlying evidence was collected correctly. The company has not publicly detailed its evidence-retention policy, forensic standards or internal access logs.</p>
<style>
    .dark-mode .read-more {background-color: #343a40 !important;}
</style>
<div class="read-more pb-3 pt-3 pt-md-2 px-3 my-4 border bg-light">
<h5 class="text-uppercase border-bottom mb-3 pb-1 d-none d-md-block">READ MORE:</h5>
<p>    <a class="article row text-decoration-none" href="https://coindoo.com/cronos-halts-chain-after-75m-tectonic-exploit/" title="Cronos Halts Chain After $75M Tectonic Exploit" target="_blank" rel="nofollow noopener"></a></p>
<div class="contentRight col-4">
            <span class="imgContainer mt-0"><br>
                <img decoding="async" class="image img-defer" src="https://cryptonews24.eu/wp-content/uploads/2026/09/DEFI-cronos-560x315.webp" width="560" style="display:block;margin:10px auto;max-width:560px;max-width:100%;"><br>
            </span>
        </div>
<div class="contentLeft col-8">
<h4 class="title mb-0">Cronos Halts Chain After $75M Tectonic Exploit</h4>
</div>
<p>    
</p></div>
<h2>Multisignature storage reduces one-key risk</h2>
<p>Bit2Shield plans to hold seized assets in multisignature cold storage. A multisignature wallet requires a specified number of keys to approve a transaction. In a two-of-three arrangement, for example, three keys exist but any two are needed to move the assets.</p>
<p>This can prevent one lost or compromised key from exposing the entire wallet. It can also divide approval between the service provider and the authority that ordered the seizure. If one organization controls enough keys to meet the threshold, however, it can still move the assets without an outside signer.</p>
<p>Bit2Me has not disclosed how many key shares Bit2Shield will create, who will hold them or whether a court or public authority will control at least one required signature. It has also not specified its recovery procedure, insurance coverage or liability if credentials are lost or misused.</p>
<p><a href="https://coindoo.com/former-u-s-government-contractor-arrested-for-alleged-46m-crypto-theft-from-federal-seizure-wallets/" target="_blank" rel="nofollow noopener">Allegations involving the theft of $46 million from U.S. federal seizure wallets</a> illustrate the risk created when contractors or employees receive excessive access to government-controlled assets. Moving keys offline reduces exposure to remote attacks, but it does not remove insider-access risk.</p>
<h2>Authorities decide when seized crypto is sold</h2>
<p>The competent authority, not Bit2Shield, will decide whether and when seized assets are sold.</p>
<p>That decision can materially affect the recovered amount because <a class="wpg-linkify wpg-tooltip" title="&lt;h3 class=&quot;wpg-tooltip-title&quot;&gt;&lt;span class=&quot;wpg-tooltip-term-title&quot;&gt;Cryptocurrency&lt;/span&gt;&lt;/h3&gt;&lt;div class=&quot;wpg-tooltip-content&quot;&gt;&lt;p&gt;Cryptocurrency is a modern digital asset and method of exchange that relies on blockchain technology and is protected by cryptography, ensuring the assets can't be forged. Essentially, cryptocurrencies serve as alternatives to traditional currencies like the euro, dollar, yen, and others. Unlike electronic bank money, the key distinction is that cryptocurrency operates in a decentralized system, with no central authority controlling it.&lt;/p&gt;&lt;/div&gt;">cryptocurrency</a> prices may change between the initial seizure and the conclusion of a case. An early sale removes further price exposure but fixes the asset’s value at that point. Holding it preserves the possibility of appreciation while leaving the state or potential recipients exposed to losses.</p>
<p>Governments do not always follow the same approach. A proposed <a href="https://coindoo.com/arizona-moves-to-build-crypto-reserve-from-seized-criminal-assets/" target="_blank" rel="nofollow noopener">Arizona reserve funded with seized criminal assets</a>, for example, would allow certain cryptocurrency to be retained rather than automatically converted into cash. The proposal shows that retention and liquidation are separate policy choices. Under Bit2Shield’s model, its role in a sale begins only after the competent authority orders one.</p>
<p>Bit2Me has not identified the trading venues, pricing benchmark, fees or slippage controls that would apply to a court-ordered sale. It has also not explained how Bit2Shield would handle a seized token without a liquid euro market.</p>
<h2>Why the regulatory split matters</h2>
<p>Bit2Shield says its investigative, forensic,, expert-report and training activities fall outside the scope of MiCA because CryptoShield S.L. is not operating as a crypto-asset service provider. When a case requires cryptocurrency cryptocurrency to be exchanged for euros, Bitcoinforme S.L. will conduct the conversion.</p>
<p>Bitcoinforme appears in the <a href="https://www.cn.cnmv.es/portal/consultas/proveedores-servicios-criptoactivos?lang=en" target="_blank" rel="noopener nofollow">CNMV register of authorized crypto-asset service providers</a>. That identifies the legal entity expected to perform the regulated exchange service rather than extending the same status automatically to CryptoShield.</p>
<p>The announcement does not identify which legal entity will act as custodian while assets remain in multisignature storage. Contracts with public authorities will need to define who controls the wallets, which which company bears responsibility for the assets and what protections apply before liquidation.</p>
<p>What authorities should establish before using Bit2Shield</p>
<p>Before appointing Bit2Shield, a public institution would need clear answers to five operational operational questions:</p>
<div class="light-yellow-block">
<ul>
<li><strong>Which entity is legally responsible while the assets remain in custody?</strong></li>
<li><strong>Who holds the keys,, and what signing threshold applies?</strong></li>
<li><strong>How are evidence access and asset transfers recorded?</strong></li>
<li><strong>How are sale prices, venues and fees independently checked?</strong></li>
<li><strong>What insurance or compensation applies if assets are lost?</strong></li>
</ul>
</div>
<p>Until those controls are publicly disclosed, outside observers cannot fully assess the custody and execution safeguards behind behind Bit2Shield’s services.</p>
<p>The post <a href="https://coindoo.com/bit2me-builds-crypto-seizure-unit-police-courts/" target="_blank" rel="nofollow noopener">Bit2Me Builds a Crypto-Seizure Unit for Police and Courts</a> appeared first on <a href="https://coindoo.com" target="_blank" rel="nofollow noopener">Coindoo</a>.</p>
<p><a href="https://cryptonews24.eu/market-overview">Check our Market Overview </a></p>
<p>Source: https://coindoo.com/bit2me-builds-crypto-seizure-unit-police-courts/</p>
<div id="ajax-load-more-10" class="ajax-load-more-wrap default" data-alm-id="" data-canonical-url="https://cryptonews24.eu/category/crime" data-slug="crime" data-post-id="6233" data-localized="ajax_load_more_10_vars" data-alm-object="ajax_load_more_10"><ul aria-live="polite" aria-atomic="true" class="alm-listing alm-ajax" data-container-type="ul" data-loading-style="default" data-repeater="default" data-post-type="post" data-order="DESC" data-orderby="date" data-offset="0" data-posts-per-page="5" data-scroll="false" data-button-label="Load More" data-prev-button-label="Load Previous"></ul><div class="alm-btn-wrap" style="visibility: hidden" data-rel="ajax-load-more-10"><button class="alm-load-more-btn " type="button">Load More</button></div></div>
]]></content:encoded>
					
					<wfw:commentRss>https://cryptonews24.eu/2026/09/cryptonews/bit2me-builds-a-crypto-seizure-unit-for-police-and-courts.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
