GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Regulation/Compliance

News linked to both this project and an event.

Bitget Wallet Integrates RWA Protocol Reality, Supporting Over 1,700 Tokenized US Stocks

Odaily News: Bitget Wallet has announced its integration with RWA protocol Reality, opening trading access to over 1,700 rToken tokenized US stocks. Through this integration, users can trade tokenized US stocks 24/7 on Arbitrum and Morph without needing to open an overseas brokerage account, submit KYC, complete a W-8BEN form, or arrange a wire transfer. Dividends generated by the corresponding underlying assets will be credited to Bitget Wallet in USDT at a 1:1 ratio.Reality is a compliant tokenized asset issuance platform, licensed under El Salvador's digital asset issuance law framework. Its issued rTokens are backed 1:1 by real US stocks, currently supporting over 1,700 tokenized US stocks including rTSM, rNVDA, rAAPL, and rQQQ, covering approximately 95% of US market trading volume. rTokens can connect directly to liquidity across all US markets including Nasdaq and the NYSE, with underlying assets compliantly custodied by FINRA-licensed broker-dealer Alpaca Securities, maintaining a reserve ratio exceeding 100%, with third-party CPA firms issuing daily real-time Proof of Reserve (PoR). This integration will further advance Bitget Wallet's Everyday Finance strategy, aiming to enable users to seamlessly conduct everyday transactions of traditional financial assets through an on-chain wallet.

CoinEx Announces Cessation of Operations and Launch of Orderly Wind-Down Process, Trading Platform to Officially Close on December 22

Odaily Report: CoinEx has issued an announcement stating that after careful evaluation, due to factors including the prolonged downturn in the crypto market, the significant contraction in overall industry trading volume and liquidity, and the continuously rising regulatory requirements and compliance costs, CoinEx has decided to cease operations and will enter an orderly wind-down process starting September 15. CoinEx stated that its current asset reserve ratio exceeds 100%, and all user assets are fully backed by sufficient reserves.According to the arrangement, CoinEx will cease all non-spot business on September 22, halt all spot trading on September 29, and CoinEx Smart Chain (CSC) and OneSwap will also cease operations on the same day; withdrawal services will continue until December 22, at which point the CoinEx trading platform will officially cease operations. CoinEx Wallet and CoinEx Vault are not affected by this shutdown and will continue to provide services as normal.

Non-custodial developer criminal liability explicit protection removed, Coin Center says Roman Storm prosecution theory still not excluded

Bitcoin News posted on X platform stating that Coin Center says the latest revised BRCA text removes the provision that provided explicit criminal liability protection for developers who do not control user funds under 18 U.S.C. § 1960. The revised text would still protect developers who do not control user funds from being deemed money transmitters under the Bank Secrecy Act and FinCEN regulations, thereby significantly raising the difficulty of prosecuting developers solely for failing to obtain a money transmitter license or register with the federal government. However, the text cannot prevent prosecutors from arguing that developers knowingly transmitted funds derived from criminal activity, a theory that has become the core basis in the criminal cases against Tornado Cash developer Roman Storm and Samourai Wallet developers. Coin Center believes that this compromise represents substantive progress on the regulatory front, but developers still face broader money transmission criminal prosecution theories from the U.S. Department of Justice; if the CLARITY Act passes with the revised BRCA, the related disputes will mainly shift to the courts.

EU's Cyber Resilience Act Takes Effect: Crypto Wallet Vulnerabilities Must Be Reported Within 24 Hours

The EU's Cyber Resilience Act has taken effect. Cryptocurrency hardware and software wallet providers must submit an initial early warning within 24 hours after discovering actively exploited vulnerabilities or severe security flaws in their products, and submit a full notification within 72 hours.Manufacturers must submit a final report within 14 days after corrective or mitigating measures become available; serious incidents must be reported within one month. Companies that violate the relevant regulations may face fines of up to €15 million or 2.5% of global annual turnover, whichever is higher; providing false, incomplete, or misleading information may result in fines of up to €5 million. (Cointelegraph)

Bitget Wallet Officially Joins BCCC, Japan's Largest Blockchain Alliance, to Participate in Self-Custodial Wallet Compliance Discussions

Odaily News: Bitget Wallet has announced its official membership in the Blockchain Collaborative Consortium (BCCC) of Japan, becoming the first global ToC self-custodial wallet to join the BCCC to date.As Japan officially implements new regulations related to crypto-asset intermediation services in June 2026, Bitget Wallet will participate in industry policy discussions as a BCCC member, exploring the role and positioning of self-custodial wallets within the regulatory framework; at the same time, it will leverage its global self-custodial wallet operational experience to engage in institutional dialogue in the Japanese market, and promote awareness and adoption of on-chain everyday finance among Japanese users.Founded in 2016, the BCCC is Japan's first and largest blockchain industry association, with over 270 member companies and multiple specialized committees including DeFi and stablecoin committees. The alliance has long served as a policy communication and collaboration bridge between Japan's blockchain industry and regulatory authorities.

Mastercard Launches Wallet Pay to Enter the 4.3 Billion-User Digital Wallet Market

According to Bitcoin.com, Mastercard officially launched the Wallet Pay payment solution on September 10, aiming to connect global digital wallets to its international payment network. The solution supports NFC contactless, QR code, online, and cross-border payments, covering over 200 countries and regions and 150 currencies. Global digital wallet users currently exceed 4.3 billion and are projected to surpass 6 billion by 2030. Participating entities include major wallet operators such as Alipay+, Mercado Pago, and MTN. Additionally, Mastercard announced support for the settlement of six compliant stablecoins across eight blockchain networks, and is partnering with over 85 institutions through its Crypto Partner Program to advance blockchain payment infrastructure.

Sparrow Wallet Releases Version 2.5.4, AI-Assisted Code Review Fixes Multiple Security Vulnerabilities

According to Decrypt, privacy-focused Bitcoin wallet Sparrow Wallet released version 2.5.4 on August 28. Developer Craig Raw stated that the update was driven by an AI-assisted code review, with the majority of fixes originating from it. This review was prompted by the recent seed generation code vulnerability exploit affecting Coldcard, as well as the release of unrestricted AI models in China, which has significantly enhanced vulnerability scanning capabilities across large codebases. Key updates include: validating the authenticity of transactions returned by Electrum servers, enforcing stricter BitBox02 hardware wallet security requirements (firmware v9.4.0 or higher required), patching local DNS leaks, and masking sensitive credentials in debug logs. Raw noted that there are no indications of any exploits being leveraged, user funds remain secure, and he still advises all users to update at their earliest convenience.

Independent verification scope expanded, Sparrow Wallet releases v2.5.4 security update

Odaily News: Sparrow Wallet v2.5.4 has been released following an extensive AI-assisted review, featuring multiple security hardening updates aimed at reducing users' reliance on external servers such as Electrum.Additionally, this version strengthens Ledger, Keycard, Trezor, Payjoin, PSBT, and multi-signature handling, removes Bitcoin Core credentials and other sensitive information from debug logs, restricts permissions for existing wallet and backup directories to owner-only access, closes residual local DNS resolution leaks when using Tor, and reinforces validation for wallet import, signing, downloads, and server responses. The update expands Sparrow Wallet's scope of independent verification for transaction data, hardware devices, and other inputs, reducing dependence on data provided by external servers. (Bitcoin News)

Banxa Launches Native Infrastructure to Embed Stablecoin Buying and Selling Processes into Partner Applications

According to BeInCrypto, payment company Banxa launched Banxa Native on August 20, providing embedded fiat deposit and withdrawal infrastructure for wallets, exchanges, and fintech platforms. Partners can execute fiat purchases or sales of crypto assets within their own interfaces, while Banxa provides backend pricing, compliance verification, and settlement services, reducing the need to redirect to third-party pages or undergo repetitive KYC verifications. For example, users can directly purchase USDC via Apple Pay, Google Pay, or bank cards within the wallet; for users who have already completed identity verification, their KYC information can be passed from the partner platform to Banxa, streamlining the process for subsequent transactions. Trust Wallet CEO Felix Fan stated that this partnership helps directly embed compliant fiat-to-crypto channels into the user journey.

IRS Warns of New Crypto Phishing Scam: Fake Letters Using QR Codes to Steal Wallet Private Keys

Odaily News - The U.S. Internal Revenue Service (IRS) has issued a warning about an advanced email phishing campaign targeting cryptocurrency holders in the United States. Attackers are using forged official tax letters to trick users into scanning malicious QR codes, aiming to steal crypto wallet credentials and private keys.According to reports, the attackers are impersonating the IRS by sending physical letters that create a sense of urgency under the guise of "tax compliance" or "account verification," and include QR codes within the correspondence. Once users scan these codes, they may be redirected to counterfeit websites, potentially exposing wallet login information, recovery phrases, or private keys, ultimately leading to the theft of digital assets.The IRS reminds taxpayers that official agencies will never request users to provide crypto wallet private keys, recovery phrases, or perform similar "wallet verification" procedures through unofficial channels. Cryptocurrency holders should remain vigilant against any suspicious emails or letters that ask them to scan QR codes, connect wallets, or submit sensitive information.As the number of crypto asset holders continues to grow, social engineering attacks targeting digital wallets are on the rise. Regulatory and security agencies are stepping up efforts to raise awareness and prevent such fraudulent activities. (CoinDesk)

Figure Co-founder to Launch The Wallet Co, Integrating RWA, Prediction Markets, and AI Agents

Odaily News Figure Co-founder and Executive Chairman Mike Cagney announced that the company will launch a mobile application called The Wallet Co, designed to combine the ease of modern fintech with self-custody and blockchain-native products.The Wallet Co will offer features such as instantly spendable interest-bearing cash, RWA yields, and securities prediction markets, with an AI Agent built into every wallet.Additionally, The Wallet Co is publicly hiring for operations and compliance lead roles, requiring relevant experience in KYC/AML, payments, and fund flows.

Bitcoin.com Wallet Integrates UAE's First CBUAE-Registered USD Stablecoin USDU

Odaily News: Cryptocurrency platform Bitcoin.com has announced the integration of USDU into its self-custody Bitcoin.com Wallet, serving millions of wallet users. USDU, issued by Universal Digital Intl Limited (Universal), is the first USD stablecoin registered as a foreign payment token by the Central Bank of the UAE (CBUAE). USDU is an Ethereum ERC-20 token, with each token backed 1:1 by liquid USD reserves held by regulated banks in the UAE. The reserves are independently attested monthly by a third-party accounting firm, with reports published on Universal's official website. Bitcoin.com Wallet's web and mobile versions will support self-custody holding, sending, and receiving of USDU. Bitcoin.com will accept USDU as payment for designated services and plans to enable its use for payments between users and merchants within its products. The wallet will also offer stablecoin education and Learn-to-Earn content. Exchange and buy/sell functionalities will be launched after support from third-party service providers, with availability varying by jurisdiction. (Bitcoin.com News)

Ledger: Coldcard Vulnerability Losses Reach Approximately $130 Million, Hardware Wallet Security Needs to Adapt to AI

Odaily News: Hardware wallet manufacturer Ledger has stated that the recent Coldcard vulnerability indicates the hardware Bitcoin wallet industry needs to reassess its security model. Ledger CTO Charles Guillemet stated that Ledger devices were not affected, as their recovery phrases are generated by a hardware random number generator built into a certified secure element. Coldcard manufacturer Coinkite disclosed last week that its air-gapped Coldcard Bitcoin hardware wallet contains a vulnerability traceable to firmware versions from March 2021. The vulnerability uses a software fallback mechanism to generate wallet recovery seeds, allowing certain private keys to be guessed, with related losses reaching approximately $130 million. Coinkite released a fixed firmware on Sunday and urged affected users to transfer funds to newly generated wallets. Charles Guillemet stated that open source is different from being audited — the flaw had existed in public code for over five years, and AI is enabling attackers to scan code and identify vulnerabilities at machine speed. Charles Guillemet also said that over the past two years, Ledger has combined AI with security engineers and cryptography experts to review code and identify vulnerabilities. He believes that when evaluating hardware wallets, users should understand how randomness is generated and whether that process has received independent certification.

Kraken Chief Security Officer: Coldcard Vulnerability Leads to Over $90 Million in Bitcoin Stolen, Hardware Wallet Industry Testing Mechanisms Require Urgent Overhaul

According to Cointelegraph, Coinkite, the manufacturer of Coldcard hardware wallets, disclosed that its devices have contained a random number generator (RNG) vulnerability persisting for up to five years since March 2021. The vulnerability stemmed from a firmware upgrade that mistakenly routed wallet seed generation to a less secure MicroPython pseudo-random number generator (PRNG), rather than the originally designed true random number generator (TRNG). Since code reviews only verified the existence of TRNG code without confirming whether it was actually invoked, the vulnerability remained undetected for a long period. To date, over 4,500 addresses have been compromised, with nearly $90 million worth of Bitcoin stolen. Kraken Chief Security Officer Nick Percoco stated that this incident should serve as a "wake-up call" for the hardware wallet industry, calling for the introduction of independent third-party testing mechanisms to mandate verification of whether the entropy sources actually invoked by production firmware are certified. Coinkite has suspended all device shipments and destroyed affected inventory after confirming the vulnerability, and stated it will cooperate with law enforcement agencies across multiple countries to trace the responsible parties.

Bloomberg ETF Analyst Questions Coldcard Team Size: Approximately 5-Person Team Undertaking Critical Wallet Security Responsibilities Poses Risk

Bloomberg Senior ETF Analyst Eric Balchunas commented on the Coldcard wallet security incident, questioning whether a company with only about 5 employees is suitable to undertake such critical Bitcoin storage responsibilities. He stated that the number of employees behind Coldcard "seems unbelievably low," asking whether people would be willing to store their life savings in a bank with only 5 employees headquartered in Canada. In the crypto industry, this might be viewed as a feature, but from a traditional finance perspective, it becomes a clear risk signal. Balchunas further stated that, in comparison, institutions with larger teams such as Coinbase and Ledger may hold advantages in security investment and operational capabilities, even if users need to bear higher transaction costs. Bitcoin ETFs offer another option: investors can obtain the security guarantees provided by large, professional, regulated financial institutions while also enjoying lower management fees.

IRS Issues Fraud Alert: Fake Crypto Tax Letters Target Wallet and Exchange Credentials

Odaily News: The U.S. Internal Revenue Service (IRS) issued a fraud alert on July 30, warning that scammers are mailing counterfeit IRS notices requiring cryptocurrency holders to register through a non-existent "Digital Asset Compliance Portal" before an urgent deadline. Each fraudulent letter contains a QR code that directs recipients to a website impersonating IRS.gov. The fake portal may request personal information, cryptocurrency wallet details, exchange login credentials, recovery phrases, private keys, or other data that could be used for theft. Cryptocurrency exchange Coinbase and cybersecurity firm Darktower traced the related infrastructure to a domain registered through a Hong Kong-based registrar shortly before the letters were distributed. Investigators found that the website is hosted in Romania, on a network previously associated with phishing pages impersonating financial institutions.

Fiat24 suspends crypto asset deposits and new user registration, to upgrade internal risk control and compliance system

As the provider of bank account and card services for crypto wallets and payment card products such as SafePal and Bitget Wallet, Fiat24 stated that due to the growth in user base and trading volume outpacing the expansion of its risk management, compliance, and customer service capabilities, it has suspended crypto asset deposits and temporarily halted new user registrations starting July 14 to upgrade its internal control systems. Its international wire transfers, foreign exchange conversions, and P2P payments remain operational, while the resumption time for crypto asset deposits has not yet been announced.

Triple-A Treasury Wallet Hacked, Approximately $11.8 Million Lost

According to Cointelegraph, Singapore stablecoin payment company Triple-A confirmed its treasury wallet was accessed without authorization, with on-chain investigator Specter estimating losses at approximately $11.8 million. The company stated that customer funds are held in separate trust accounts and were not affected by this incident, and the relevant losses will be covered by the company's own financial reserves. Triple-A has currently restored all services and is collaborating with cybersecurity experts, blockchain forensic agencies, and the Singapore Police Force to investigate and track the stolen assets.

SecondFi to Gradually Shut Down Wallet Services After $2.6 Million ADA Theft

Cardano ecosystem wallet SecondFi announced that due to a cryptographic defect in its wallet software, approximately 16.1 million ADA (worth around $2.6 million) were stolen. The platform will gradually shut down the SecondFi and Yoroi wallet services. This incident has affected 374 wallets. SecondFi stated that an independent investigation by blockchain intelligence agency Groom Lake identified the attackers as a sophisticated external actor and found indicators potentially linked to North Korea's Lazarus Group, though attribution has not yet been confirmed. SecondFi is developing a recovery tool based on zero-knowledge proofs to help affected users recover assets while limiting the information that needs to be shared. The tool is still being tested and will undergo third-party audits before its planned release in August. SecondFi is also preparing a wallet export feature to allow users to migrate their assets to other services. The platform has not announced a direct compensation plan, nor has it indicated whether it will use its own funds to compensate users.

Zilliqa: Security Incident at CEX Partner's Cold Wallet, Some ZIL Stolen

according to Zilliqa's monitoring, it has learned of a security incident involving a CEX partner, where some ZIL has been stolen from a cold wallet. The incident is currently under investigation, and the team is working with relevant parties to determine the root cause and the scope of the impact. As a precautionary measure, Zilliqa has notified all CEX partners to temporarily suspend ZIL deposits and withdrawals to prevent the stolen funds from being transferred or sold through centralized platforms. The official stated that further updates will be released after verifying the information and reminded the community to only follow information published through official channels.