BTC $83,251.67 -1.48%
ETH $2,679.09 -0.23%
BNB $762.45 -2.41%
XRP $1.49 -1.70%
SOL $118.29 -3.00%
TRX $0.3353 +0.43%
DOGE $0.0937 -3.50%
ADA $0.2469 -3.72%
BCH $309.02 -6.61%
LINK $15.48 +10.07%
HYPE $86.72 -4.36%
AAVE $148.33 -3.75%
SUI $1.14 -10.31%
XLM $0.2290 +4.91%
ZEC $1,465.64 -7.20%
AAPL $338.39 -0.51%
AMZN $246.44 -1.16%
GOOGL $342.40 -0.18%
MSFT $508.89 -1.27%
META $717.34 -2.67%
NVDA $228.60 +1.65%
TSLA $357.71 -3.68%
SNDK $1,705.14 -2.78%
INTC $115.29 -5.38%
SPCX $145.85 -2.54%
MU $1,050.32 -2.74%
AMD $607.04 -3.32%
BTC $83,251.67 -1.48%
ETH $2,679.09 -0.23%
BNB $762.45 -2.41%
XRP $1.49 -1.70%
SOL $118.29 -3.00%
TRX $0.3353 +0.43%
DOGE $0.0937 -3.50%
ADA $0.2469 -3.72%
BCH $309.02 -6.61%
LINK $15.48 +10.07%
HYPE $86.72 -4.36%
AAVE $148.33 -3.75%
SUI $1.14 -10.31%
XLM $0.2290 +4.91%
ZEC $1,465.64 -7.20%
AAPL $338.39 -0.51%
AMZN $246.44 -1.16%
GOOGL $342.40 -0.18%
MSFT $508.89 -1.27%
META $717.34 -2.67%
NVDA $228.60 +1.65%
TSLA $357.71 -3.68%
SNDK $1,705.14 -2.78%
INTC $115.29 -5.38%
SPCX $145.85 -2.54%
MU $1,050.32 -2.74%
AMD $607.04 -3.32%

revoke

All
Article
Flash

first_img MEXC user: API not revoked after account was hacked, approximately 340,000 USD was transferred away

A MEXC user posted on X that their account was compromised after someone reset the security items. MEXC has confirmed the account was hacked, frozen the account, and assisted in recovery, but did not revoke the API left by the attacker. From 04:12 to 04:25 on September 27, 2026 (Beijing time), the account transferred out 322,110 USDT and 9,133,999 ONE, totaling approximately $340,000, about 27 minutes after the 24-hour transfer limit was lifted.The user stated that at 03:10 on September 25, they received a reset security item email that was not submitted by them, and about 10 minutes later, the request was approved. Subsequently, the account was logged in from an IP in Jakarta, Indonesia, bound to Google verification, and at 05:05, an API was created, approximately 83 seconds after logging in. At 10:55 that day, MEXC froze the account after a risk review and reverted to the original email. Customer service responded in writing that the review materials met the requirements, so the binding change was approved, and after the risk review, the account was urgently frozen and reverted to the initial email. The user changed their password and Google verification on September 26 but stated that the API was not revoked, and there were no related records in the security operation history.The user also claimed that there were no new login records in the login history when the assets were transferred out. They have submitted a formal claim to MEXC and attempted to report to the police, with the ticket number M2026092712031, requesting the platform to preserve logs, provide a written explanation of the review and API situation, and return the aforementioned assets. MEXC customer service stated that it is currently unable to confirm whether these transfers were initiated via APP, WEB, or API, and the issue has been forwarded to the relevant department.

Magic Eden: Current open orders are not affected by this vulnerability; users in the EVM market from February to October 2024 need to revoke related contract authorizations

Magic Eden announced that the vulnerability occurred in the NFT trading protocol Payment Processor V2 maintained by Limit Break. Magic Eden adopted this protocol for EVM network transaction settlements in 2024 but stopped using V2 in October 2024 and will completely shut down the EVM market in the first quarter of 2026. Therefore, NFTs currently listed on Magic Eden are not affected by this vulnerability.NFTs listed through its EVM market between February and October 2024 may be affected, while listings after October 2024 are generally not impacted. The platform is contacting the protocol owner and maintainer Limit Break to explore other risk mitigation measures, including pausing protocol transfers, and will continue to investigate the actual scope of the impact.Magic Eden reminds users who have listed or traded NFTs on its EVM market to revoke relevant contract authorizations on the Ethereum, Polygon, and Base networks. Users can filter the address through revoke.cash and revoke all authorizations marked as "approved for all" for NFTs. Magic Eden emphasizes that revoking authorization cannot recover assets that have already been transferred.Yuga Labs' Vice President of Blockchain Quit stated today that at 9 AM Eastern Time, attackers exploited the Payment Processor V2 vulnerability to steal a large number of NFTs. After contacting the LimitBreak team, the latter quickly paused the similarly affected Payment Processor V3. However, V2 could not be paused, and V3 on ApeChain is also temporarily unable to be paused. Therefore, the team implemented a white-hat operation, successfully transferring and protecting 23,155 NFTs valued at over 5.7 million dollars.

first_img CoolCash's parent company had its payment license revoked and has initiated liquidation

The payment service provider license of CoolCash (Xiao Yi Payment), the parent company of Tianxu International Technology Co., Ltd., has been revoked by the National Bank of Cambodia and has entered liquidation proceedings. The company and its director, Pang Weizhi, were included in the UK government's sanctions list in March this year due to alleged ties with the Prince Group.The National Bank of Cambodia announced on the 10th that it revoked the payment service provider license of Tianxu International Technology on August 3. This license was issued on May 27, 2024, and was originally valid until 2030. The bank also appointed Morrison Kak MKA Audit Accounting Firm as the liquidator in accordance with Article 68 of the Law on Banking and Financial Institutions to handle liquidation matters and return relevant funds to the company's clients in accordance with the legal priority order.UK sanction documents indicate that Pang Weizhi holds Cambodian and Chinese nationality, with the Cambodian name Pang Visal, and serves as a director of Tianxu International Technology and the parent company of Elephant Delivery, U-Life KH Super App Company Limited. The UK side claims to have reasonable grounds to suspect his ties with the Prince Group and that he has provided financial services or funds, economic resources, goods, or technology to the group. The UK side alleges that the Prince Group is involved in operating scam centers in Cambodia, which include forced labor and serious human rights violations. Tianxu International Technology and Pang Weizhi have been listed as targets of sanctions in both corporate and personal capacities.

first_img AUSTRAC in Australia revoked the registrations of 45 cryptocurrency and remittance institutions within a year

Australia's financial intelligence agency AUSTRAC has canceled, suspended, or refused to renew the registrations of 45 cryptocurrency and remittance service providers in the past year to strengthen the scrutiny of high-risk payment businesses. The involved institutions faced issues such as inactivity, insolvency, or lack of operational capability, as well as failure to report significant changes, incorrect registration information, and significant money laundering or terrorism financing risks. AUSTRAC CEO Brendan Thomas stated that businesses whose registrations have been canceled are not allowed to continue operations, and some related individuals have been referred to domestic and international law enforcement or regulatory agencies. AUSTRAC specifically mentioned BA Digital Ventures operating under the name GetCoins, whose virtual asset registration was canceled in June due to customer complaints, allegedly because the platform was exploited by organized cryptocurrency investment scams, with related actions conducted in cooperation with the national anti-fraud center. The public VASP registration list also included recent disposals of institutions such as Cryptolink, Self Custody, Jam Xchange, and Coinsec Australia. Additionally, AUSTRAC has launched an investigation into Western Union and suspended the cryptocurrency ATM network of Cryptolink.

first_img CFTC acknowledges that it should not sue Gemini and jointly requests the court to withdraw the consent order

The U.S. Commodity Futures Trading Commission (CFTC) announced on Tuesday that it has jointly filed a motion with Gemini Trust Company LLC in the U.S. District Court for the Southern District of New York, requesting the dismissal of a previous judgment against Gemini.The case was originally filed in June 2022, and the parties reached a consent order in January 2025. After a comprehensive review, the CFTC concluded that the lawsuit should not have been filed and would not be filed under current enforcement standards.The review identified six major issues: the complaint was primarily based on statements from a whistleblower of questionable credibility; the investigation targeted Gemini as a victim of fraud rather than the alleged fraudster; there were serious doubts about the strength of the evidence against Gemini; relevant supporting materials were concealed and not submitted to the commissioners during the CFTC's vote on the complaint; the litigation team invoked deliberative process privilege to prevent Gemini from obtaining evidence necessary for its defense; and personnel improperly used CFTC regulatory power to create leverage for settlement.The CFTC determined that continuing to enforce the forward-looking provisions of the consent order is neither consistent with its mission nor in the public interest, and that the non-forward-looking provisions of the consent order (such as civil penalties) have been fulfilled. The parties jointly request the court to vacate the remaining forward-looking provisions.
app_icon
ChainCatcher Building the Web3 world with innovations.