GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Regulation/Compliance

News linked to both this project and an event.

Orlen's Venezuela crude oil deal losses reach up to $424 million, involving a $230 million USDT prepayment

Odaily reports: In November 2023, Orlen Trading Switzerland, a subsidiary of Polish state-owned energy company Orlen, signed a contract to purchase 6 million barrels of Venezuelan crude oil and paid $230 million in unsecured advance payment to Dubai-based trading company Hannon International for conversion into USDT.Hannon International subsequently converted the funds through multiple intermediaries, with $135 million converted into only 85 million USDT, creating a $50 million shortfall. Between January and March 2024, private keys controlling over 132 million USDT were handed over via USB storage devices to brokers affiliated with Venezuela's state oil company.After the transaction, the relevant brokers became unreachable, and the Venezuelan state oil company failed to release the crude oil cargo. Ultimately, only one vessel loaded approximately 500,000 barrels of fuel oil, valued at $28.8 million; Orlen canceled the contract in March 2024, with estimated total losses of $378 million to $424 million.Polish prosecutors have launched a criminal investigation into the management of Orlen Trading Switzerland, with 3 former senior executives indicted and facing up to 25 years in prison. Orlen has initiated international arbitration in Dubai, seeking to recover the $230 million prepayment. (Bitcoin.com News)

Existing mnemonics cannot be fixed through updates; Coldcard reminds affected users to regenerate mnemonics and migrate assets

Coldcard has released the latest firmware 5.6.1 (Mk4/Mk5) and 1.5.1Q (Q). This update is based on a three-week security review following the emergency fix on July 31, addressing security risks brought by the previous mnemonic generation attack. Each newly generated mnemonic must now include at least one source of user entropy, including at least 65 irregular keystrokes, 50 physical dice throws, or 128 physical coin flips, combined with fresh entropy provided by STM32 TRNG, SE1, and SE2. The new firmware also adds instant staged PSBT verification before signing, strengthens USB connection and firmware update boundaries, improves Delta Mode isolation mechanisms, fixes active wallet backup issues, enhances random number generator initialization and fault checking, adjusts SIGHASH default settings, and includes multiple security and correctness improvements. Coldcard stated that this update aims to further reduce the risk of device attacks. The official reminder notes that updating the firmware cannot fix existing mnemonics generated by previously affected firmware. If users' mnemonics fall within the scope of this security advisory, they should first update the device, then generate and verify a completely new mnemonic, and migrate funds to the new wallet. Coldcard recommends that all Mk4, Mk5, and Q users update their devices promptly and verify the signature of the downloaded firmware.