Hong Kong SFC Gives Crypto Platforms 1 Year to Ditch SMS OTPs
The Hong Kong SFC is forcing licensed exchanges to replace one-time passwords with cryptographic 2FA, and the liability shift is the part exchanges are reading closely.
The Hong Kong SFC is forcing licensed exchanges to replace one-time passwords with cryptographic 2FA, and the liability shift is the part exchanges are reading closely.
The 12-month deadline lands as spoofing attacks climb at Hong Kong-licensed platforms; the move redefines the authentication baseline every retail-facing venue must meet.
Immunefi logged 207 incidents, the highest count on record, yet total losses fell to $972M as DeFi exploit damage continued its multi-year reset from the $2.62B 2022 high.
The dollar figure is a reminder that pre-deploy review still leaves exploitable surface, and the gap is widening as AI-tuned exploit tooling shortens the window between disclosure and attack.
The shutdown cites MiCA, regulatory, financial and operational pressure, and a Coin Bureau report points to empty hot wallets, framing a full-balance recovery as uncertain for AscendEX users.
The exchange blamed a failed strategic transaction and MiCA pressure for the July 1 shutter, but the more dangerous signal is the empty hot wallets ZachXBT flagged weeks earlier.
A former top-10 CEX backed by Polychain and Hack VC went dark on July 1, the same day on-chain sleuth ZachXBT warned that public wallets had run dry on ETH, USDT and SOL.
The governing-group exit is more consequential than the dollar figure: one of Cardano's three founding entities is stepping away from the coalition designed to coordinate treasury-funded…
The platform's wallet-to-wallet model sidesteps the pooled-custody attack surface that drained KelpDAO, Drift, and Grinex in a single quarter.
The Strait of Hormuz carries roughly a fifth of global oil shipments; a direct US-Iran kinetic exchange there is the risk-off macro shock markets have been pricing as tail.
The figure represents Bitcoin held in legacy address types vulnerable to a sufficiently powerful quantum computer, framing a long-tail threat still years away from capability.
A $65M flash loan inflated a redemption to $70.9M and walked away with $6M, a textbook manipulation of the Lazy Summer Protocol's smart contracts.
The DeFi lending protocol lost just over $6M in a single exploit, the latest in a string of mid-cap DeFi venues taken down by attackers in 2025.
The attack is hitting a yield-aggregator specifically built for institutional-grade vault infrastructure, putting fresh attention on the security stack behind DeFi's automated strategies.
Treasury's $10B scam warning and a new DeFi coalition show the industry is finally treating social engineering and state-linked hackers as the primary attack surface, not smart-contract bugs.
A five-month dormant wallet dumping its full $21.4M SOL hoard into ETH and then through a mixer is a textbook post-exploit cleanup, and a reminder that stolen Solana still finds an off-ramp to…
With recovery odds described as low, the project is stepping away from its identity-and-blockchain roots, a strategic retreat that signals how deep the damage runs.
The Treasury action bundles sanctions against ISIS-K's Tron-Monero rails with a $30M Brazil-linked PCC laundering network, sharpening the role of centralized stablecoin issuers in actual enforcement.
The Japanese financial group's exit pulls roughly 2% of network hashrate off the table with a month to migrate, layering fresh pool-concentration risk onto a sector already squeezed on margins.
The speed of the recovery is the story: every depositor restored in under two weeks, a full post-mortem incoming, and a 136% TAIKO rally signaling that the market treats containment as legitimate…