Skip to content

Daily Digest - September 29, 2026

Bitcoin held the $83K area as oil and yields rose, Coinbase completed its regulated derivatives stack, Asia tested market-making rules, and security incidents forced harder choices on censorship and rollback risk.

digestcryptodefimarketsstablecoinstokenizationsecurityinfrastructuregithubskills

Morning prices: BTC $83,794, ETH $2,689.83, SOL $118.76, HYPE $87.84, ZEC $1,401.37, LINK $14.92, UNI $8.71, AAVE $154.58, BNB $761.57, TRX $0.3347, ADA $0.2470, XRP $1.50, DOGE $0.0943, LTC $68.17.

Tuesday morning is about idle money finding fewer places to hide.

The last three published digests leaned hard into stablecoin rules, tokenized equity access, prediction-market law, Solana operating risk, ETF flows, and exchange custody failures. Today’s rotation keeps those threads only where the facts changed. The lead is macro pressure because oil, yields, and inflation data are again setting the hurdle rate for every crypto bid.

The better story sits underneath price: crypto firms want Treasury yield between trades, banks want stablecoin payments without making merchants hold tokens, restaking protocols need profits rather than points, bridges are moving control back to app teams, and compliance fights are following USDT into geopolitics.

Price snapshot via CoinGecko simple-price data around 14:20 HKT. Coinbase spot check at the same pass: BTC $83,723.09, ETH $2,686.67.


1. Bitcoin Held $83K While Oil And Yields Raised The Bar

CoinDesk reported that bitcoin hovered just above $83,100 during Tuesday Asian hours as the 10-year Treasury yield touched its highest level since 2007 and Brent crude moved near $107.

ZEC fell 12% to about $1,380, while SOL and HYPE each lost 3% to 4%. Total crypto market value sat near $2.86 trillion. The next macro test is Wednesday’s August PCE inflation reading.

This is a cleaner market setup than another liquidation headline.

Higher oil feeds inflation risk. Higher Treasury yields raise the return investors can get without taking crypto risk. If bitcoin keeps holding the lower edge of last week’s range, the market is saying the bid is broader than leverage. If it loses $80,000, the rally repair from late September starts looking fragile.

The question for traders is simple: can spot demand beat the new income hurdle?

2. Goldman Put A $100 Billion Treasury Fund Into Crypto Workflows

CoinDesk reported that Goldman Sachs is making its roughly $100 billion FTIXX Treasury fund available through Lynq, a settlement network used by institutional digital-asset firms.

The key twist: Goldman is not tokenizing FTIXX. Lynq is adding the traditional fund as a distribution path, with tZERO Securities handling trades and Lynq’s private Avalanche L1 supporting the workflow. Lynq said it has more than 30 institutional digital-asset firms onboarded and more than $89 million in assets.

That is more interesting than another tokenized-fund launch.

The institutional need is basic: firms such as market makers and OTC desks hold cash between trades and want yield without moving money out of their operating stack. Tokenization is one answer. A traditional fund wired into crypto settlement rails is another.

The read: Wall Street doesn’t always need to put the fund onchain. Sometimes it just needs to put the fund where crypto firms already settle.

3. Citi And Coinbase Expanded Corporate Stablecoin Payments

The Block reported that Citi and Coinbase expanded their partnership to support stablecoin payments for corporate clients.

Coinbase will use Citi’s Virtual Account Wallet to power Virtual Accounts, letting customers accept, hold, and pay fiat while incoming funds can be automatically converted into stablecoins. Citi’s Spring platform will let institutional clients accept stablecoin payments through Coinbase rails, with Coinbase converting digital assets into fiat for settlement.

The first rollout is in the U.S.

This is the bank version of stablecoin adoption: merchants don’t have to hold tokens, manage wallets, or explain private keys to the finance team. They get bank-account-like plumbing and settlement options behind the scenes.

Stablecoins are becoming less visible at the point of use, which is probably how the biggest payment volumes arrive.

4. Restaking’s Fee Math Stopped Matching The Hype

CoinDesk reported that ether.fi is cutting its last structural tie to EigenLayer this quarter, leaving under 1% of assets restaked.

The report’s numbers are harsh. Restaking secures about $10 billion but generated only $99,977 in fees over one week, while plain liquid staking earned about 53 times more per dollar secured. The five largest remaining liquid restaking tokens produced $953,350 in combined gross profit last quarter, down from $2.18 million three quarters earlier.

This is the post-points hangover.

Restaking promised reusable security and extra yield. That can still matter for specific services, but the market now has to price smart-contract risk, slashing risk, liquidity complexity, and the fact that users can earn simpler staking yield without taking the extra path.

The lesson isn’t that restaking is dead. It is that security markets need paying customers, not only TVL.

CoinDesk reported that Chainlink launched CCIP 2.0, letting companies add custom security checks to cross-chain transfers on top of Chainlink’s default 16-operator verifier network.

The timing matters. April’s $292 million KelpDAO exploit was blamed on a rival bridge setup that relied on a single verifier, and Kelp later moved rsETH to Chainlink.

Bridge design is shifting from “trust the network” to “choose your security policy.”

That is powerful because a major protocol can add its own verifier set or checks. It is also less simple because apps now have to make real risk decisions. If they don’t add custom verifiers, CoinDesk notes they rely on Chainlink’s default 16-operator network rather than a separate risk-management network as before.

Cross-chain UX keeps improving. Cross-chain responsibility is getting heavier.

6. THORChain Refused To Blacklist A Bitget Hacker Wallet

CoinDesk reported that a wallet linked to the Bitget hacker swapped about 2,390 ETH, worth roughly $6.3 million, into 75.2 BTC through THORChain.

Bitget had asked THORChain to block publicly identified attacker addresses after the Sept. 24 breach, and offered a 5% bounty for freezing or recovering stolen funds. THORChain rejected selective blacklisting, saying its emergency controls can halt broader network activity but cannot freeze one address or transaction.

This is a brutal test of neutrality.

Centralized issuers can freeze tokens. Exchanges can freeze accounts. A cross-chain swap network has a different social contract. If it adds address-level censorship after one high-profile theft, it changes what users and regulators think the network is.

The result is uncomfortable: neutrality protects ordinary users from arbitrary control, but it can also give attackers an exit route.

7. Franklin Templeton Brought Tokenized Collateral To Bybit

CoinDesk reported that Franklin Templeton is expanding its off-exchange collateral program to Bybit.

Investors can pledge shares in Franklin Templeton’s tokenized money market funds, representing about $686 million in net assets, as collateral for USDT or USDC trading credit lines while still earning yield. The assets are held off-exchange through regulated custodian ByCustody and mirrored inside Bybit’s trading setup.

This is the tokenized Treasury use case getting sharper.

The point isn’t only that a fund share lives on blockchain-integrated records. The point is that a trader can keep yield-bearing collateral away from the exchange while still using it for credit. That directly attacks one of crypto trading’s oldest tradeoffs: earn yield or keep margin ready.

The risk now moves to custody, valuation, margin rules, and how quickly the collateral can be enforced under stress.

8. Senate Democrats Put USDT Back In The Sanctions Fight

CoinDesk reported that Democrats on the Senate Homeland Security and Governmental Affairs Committee’s Permanent Subcommittee on Intelligence published a report alleging USDT has become a key tool in Iran-linked shadow banking.

The report claims Iran-connected crypto networks have processed significant volumes and says Tether has sometimes taken weeks to freeze wallets or responded to requests without blacklisting addresses.

This is the hard edge of stablecoin scale.

USDT works because it is liquid, dollar-denominated, and widely accepted. Those same traits make it useful in gray-market and sanctioned flows. Every new stablecoin payment partnership has to sit beside that policy reality: dollar tokens expand dollar reach, but they also create new enforcement pressure points.

The stablecoin debate is no longer only reserves and yield. It is sanctions throughput.

9. AI Money Agents Could Attack Bank Deposit Stickiness

CoinDesk covered Apollo Chief Economist Torsten Slok’s warning that AI assistants could trigger a slow-motion bank run by automatically moving household cash from low-interest checking accounts into higher-yield options.

Slok pointed to checking rates around 0.1% as the opening. If personal agents routinely sweep idle balances, banks lose cheap deposits that help fund loans.

This belongs in a crypto digest because agentic finance and stablecoin rails are converging.

If an agent can compare bank yields, money market funds, tokenized Treasury funds, and stablecoin rewards, cash starts behaving more like routed order flow. That is good for users who stop donating spread to banks. It is rough for institutions built on inertia.

The next banking risk may not be panic. It may be software that quietly optimizes every idle dollar.

10. Solana ETFs Had A Record Week, But One Issuer Dominated

CoinDesk reported that U.S. spot Solana ETFs drew a record $188 million of net inflows last week.

All seven funds took in money, but Bitwise’s BSOL led with about $128 million, or 68% of the weekly total. BSOL has captured roughly $1.2 billion of the group’s $1.6 billion cumulative inflows. The report also tied the flow story to Solana’s Alpenglow testing, which targets payment finality near 150 milliseconds.

This is the Solana wrapper story with a cleaner data point.

ETF flows show regulated demand. Alpenglow points to payment-grade settlement ambitions. The catch is concentration. If one issuer captures most of the flow, the market may be buying a fund brand and distribution channel as much as the chain.

SOL’s institutional story is improving, but the ETF market is already uneven.

Fresh GitHub API results for repos created after September 27 were filtered against the tracker. I skipped Discord booster scripts, bypass tools, game mods, empty/no-description spikes, and likely abuseware.

  • KKKKhazix/AIHOT (1,622 stars) - A TypeScript framework for building a self-hosted topic scanner and daily news site. Worth watching because it packages the “find sources, filter signal, write briefs” loop that more vertical research sites will want to own.
  • aicheye/supersidian (149 stars) - A fresh Supernote-to-Obsidian sync tool. The repo is young, but the use case is strong: handwritten notebook capture flowing into a markdown vault without turning notes into another silo.
  • santtiago49/system-design-trainer (100 stars) - A browser whiteboard for system-design interview practice with a live capacity model. It sits right at the useful edge of dev education: visual architecture plus numbers instead of static diagrams.

Skills Spotlight

I reviewed three agent-skill repos before featuring them and wrote security notes in the vault.

NVIDIA/SkillSpector (18,537 stars) | Security: Review before broad automation
SkillSpector scans agent skills for prompt injection, data exfiltration, malicious patterns, dependency risk, MCP issues, and other install-time hazards across local paths, Git repos, URLs, and zip files. Security notes: The ingest path is unusually defensive: host allowlists, private-IP blocking, bounded downloads, zip-bomb limits, zip-slip checks, and shell=False Git calls. The main caveat is optional LLM analysis, which can send scanned skill content to configured providers. Run it in an isolated venv or container, use --no-llm for private skills, and scope provider keys. Review note: 1. Projects/skill-reviews/2026-09-29-skillspector.md.

OthmanAdi/planning-with-files (27,170 stars) | Security: Useful but hook-heavy
planning-with-files keeps long-running agent work in task_plan.md, findings.md, progress.md, and optional named plan directories, then injects that state through host hooks so tasks survive compaction and session drift. Security notes: The Codex path shows real hardening: fixed hook routes, bounded file reads, symlink/reparse-point rejection, explicit plan binding, and no network upload path in the reviewed hooks. The risk is the hook surface itself. Installing it means scripts run on prompt, tool, compaction, and stop events. Review exact host hooks before global install and don’t put secrets in planning files. Review note: 1. Projects/skill-reviews/2026-09-29-planning-with-files.md.

teng-lin/notebooklm-py (19,538 stars) | Security: High-trust credential-backed tool
notebooklm-py exposes Gemini Notebook/NotebookLM through a Python API, CLI, skill, MCP server, and optional REST server for source ingestion, cited chat, research, artifact generation, downloads, and sharing. Security notes: The project treats storage_state.json and master_token.json as bearer credentials and includes strong log redaction plus source-add validation for internal URLs, symlinks, credential filenames, and upload roots. The risk is still high: master tokens are durable full-account credentials, and MCP/REST deployment can expose powerful notebook operations. Use dedicated Google accounts, isolated profiles, and explicit IDs for every notebook/source/artifact action. Review note: 1. Projects/skill-reviews/2026-09-29-notebooklm-py.md.

Morning Read

Read the Goldman FTIXX/Lynq piece, then the restaking economics report, then the Citi/Coinbase stablecoin payment expansion.

The number to remember is $99,977.

That is the weekly fee figure CoinDesk cited for a restaking market securing about $10 billion. It captures the morning better than another BTC quote because it forces the right question: which crypto rails produce durable revenue, and which only look important while incentives are paying users to wait?

This morning’s read is that crypto is becoming a cash-management problem. Where does idle money sit between trades? Who earns the yield? Which collateral can count without sitting on an exchange? What happens when software starts routing deposits? Which networks stay neutral when stolen funds move?

The industry is getting better plumbing. Now it has to prove who gets paid for using it.


Evening Update

Evening prices: BTC $84,202.34, ETH $2,715.98.

Tuesday evening is about who gets to intervene when crypto rails misprice, break, or carry bad flow.

The morning digest covered bitcoin’s $83K macro test, Goldman wiring a Treasury fund into crypto settlement, Citi and Coinbase stablecoin payments, restaking fee math, Chainlink bridge controls, THORChain’s refusal to blacklist a Bitget-linked wallet, Franklin Templeton collateral on Bybit, USDT sanctions pressure, AI cash routing, and Solana ETF concentration.

Tonight’s rotation avoids replaying that bundle. The center moved to regulated derivatives, South Korean liquidity rules, European supervision, exchange backend forensics, cross-chain blocking, emergency rollbacks, fake-chain scams, TRON payment tooling, ETH treasury concentration, and Tether’s sanctions-defense numbers.

The useful question: when crypto becomes market infrastructure, which intervention is legitimate - a regulator’s license, an exchange’s protection fund, a protocol’s blocklist, an issuer’s freeze, or a chain rollback?

Price snapshot via Coinbase spot endpoints around 18:14 HKT.

11. Coinbase Completed Its Regulated Derivatives Stack

Cointelegraph reported that Coinbase received CFTC approval to launch Coinbase Clearing LLC as a U.S. derivatives clearing organization.

The registration lets Coinbase clear fully collateralized futures, options on futures, and swaps. It doesn’t let the clearinghouse clear leveraged products. Coinbase now has a futures broker, derivatives exchange, and clearinghouse under the same regulated roof.

This is more than another license.

Clearing is the layer that handles settlement and counterparty risk when a trade breaks. Bringing it in-house gives Coinbase tighter product control, faster operating loops, and a clearer path for USDC-native collateral and 24/7 settlement. The limitation matters too: leveraged and margined products still need other clearing paths.

The read is simple. Crypto derivatives are moving from offshore venue habit into regulated market infrastructure.

12. South Korea Reopened The Market-Maker Debate After A JPYC Peg Spike

Cointelegraph reported that South Korea’s Financial Services Commission is considering whether digital-asset markets need formal market-making rules.

The trigger was ugly. Upbit listed JPYC, a yen-backed stablecoin, on September 17. The token opened at 12 Korean won and reached 37.6 won within an hour, more than four times its market value, because liquidity was thin.

This is a sharp Asian market-structure lesson.

South Korea’s current law effectively blocks market makers because it has no carve-out from manipulation rules. That protects users from fake liquidity, but it can also leave new listings with no stabilizing depth. The JPYC spike shows why “no market makers” can itself become a consumer-protection problem.

Stablecoin rules are not only about reserves. Secondary-market liquidity can hurt users just as fast.

13. ESMA Shifted MiCA From Rulemaking To Supervision

Cointelegraph reported that ESMA Chair Verena Ross said MiCA work is shifting from rulemaking toward supervision and convergence across national regulators.

ESMA’s 2027 priorities include crypto-asset service provider resilience, outsourcing risk, liquidity, reverse solicitation, asset classification, harmonized reporting, and the MIDAS market-abuse surveillance system.

Europe is moving past the headline phase.

The question is no longer whether MiCA exists. It is whether a licensed firm actually has enough operations inside the bloc, whether third-party dependencies are controlled, and whether national regulators see the same risk data. That is where regulatory advantage gets real.

A MiCA badge won’t be the end of the process. It becomes the start of ongoing supervision.

14. The SEC Added Staff Guidance After Congress Failed To Pass Market Structure

Cointelegraph reported that the SEC updated staff FAQs on how federal securities laws may apply to certain crypto assets and transactions after the Senate failed to advance the CLARITY Act.

The staff said the guidance is non-binding and does not create new obligations. Still, the update covers areas builders care about: token buybacks, functional networks, network maintenance, and staking receipt tokens.

This is regulation by operating manual.

Congress did not deliver the clean statute many firms wanted, so the SEC and CFTC are filling the gap with staff answers. That gives builders more hints, but weaker certainty. A FAQ can help a lawyer structure a product. It isn’t the same as a statute that survives the next chair.

The agencies are trying to reduce ambiguity without Congress. That is useful and fragile.

15. Bitget’s Attacker Tested The Thresholds Before The Big Drain

The Block reported that the Bitget attacker ran two small transfers about half an hour before the exchange’s $388 million exploit.

CEO Gracy Chen said the first unauthorized movements were 0.184 ETH and 193 TRX, both below Bitget’s alert threshold. Larger transfers followed across Ethereum, XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism, and Avalanche. Bitget said a third-party security-product zero-day gave the attacker valid admin credentials, while private keys and cold wallets were not compromised.

The lesson is not “private keys are safe.”

The attacker seems to have mapped the control surface before hitting it. Small test withdrawals are not noise when an internal admin path has been compromised. Exchanges need risk engines that understand sequence, permissions, and intent, not only transfer size.

Security failed at the workflow layer, then moved at chain speed.

16. NEAR Intents Took The Opposite Side Of The THORChain Neutrality Fight

Cointelegraph reported that NEAR Intents said it blocked more than $50 million in attempted transfers tied to the Bitget hack.

The protocol said its SHIELD system froze $503,000 during execution, while about $166,000 in suspected stolen funds still passed through. NEAR Intents also said it would give up Bitget’s offered bounty so more funds could be returned through legal process.

This is the day’s clearest contrast with THORChain.

THORChain rejected selective address blocking. NEAR Intents argued that refusing to help launder stolen assets is a protocol choice too. Both positions carry costs. Neutrality preserves open access. Intervention protects victims but adds governance and censorship risk.

The cross-chain market now has two live models in public view.

17. Zano Rolled Back A Month Of Chain History After A Gateway Address Exploit

Cointelegraph reported that Zano restarted its blockchain at block 3,833,000, immediately before Hard Fork 6 introduced Gateway Addresses.

The team said a Gateway Address vulnerability allowed unauthorized ZANO and Freedom Dollar into circulation. The rollback invalidates about a month of legitimate transactions along with the unauthorized assets, and the team said it will publish a reimbursement and claims process.

This is the nuclear option.

A rollback can preserve supply integrity, but it also tells users that finality was conditional. That tradeoff may be defensible for a smaller chain facing unlimited unauthorized issuance. It is still a hard reminder that “immutability” often depends on social consensus when a bug threatens survival.

The chain chose monetary integrity over transaction finality. That choice will follow it.

18. A Fake GIWA Mainnet Drained About $2 Million In ETH

Cointelegraph reported that scammers stole about $2 million in ETH through a fake GIWA blockchain bridge that DYORSWAP initially mistook for the real network.

DYORSWAP said the fraudulent bridge received 767.65 ETH from 1,335 addresses and drained 766.25 ETH. GIWA, the Ethereum layer-2 project from Upbit operator Dunamu, warned that its mainnet had not launched. DYORSWAP said its own contracts were not compromised and that it used its own funds to compensate affected users with more than 200 ETH.

This is not a smart-contract exploit. It is launch-confusion risk.

When a major exchange-linked chain is expected, scammers can weaponize anticipation. Users and integrators need official chain IDs, deployment proofs, verified bridge domains, and a habit of waiting for primary announcements before moving funds.

The fake chain didn’t need to beat the real one technically. It only needed to arrive first in users’ heads.

19. Privy Added Deeper TRON Wallet And Payment Infrastructure

The Block reported that Privy expanded developer support for TRON with transaction signing, policy controls, transfer APIs, and real-time webhook monitoring.

The sponsored report said TRON transfer volume is approaching $30 trillion, with more than 405 million accounts, more than 15 billion transactions, and over $29 billion in TVL. Privy said teams can use the new tools for stablecoin payments, treasury workflows, wallets, and onchain financial products.

Treat the source as product messaging, but the direction matters.

TRON’s stablecoin footprint is already large. The missing layer for many businesses is not another wallet button. It is policy controls, transfer limits, recipient allowlists, webhooks, and treasury operations that feel closer to finance software than crypto tooling.

Stablecoin adoption keeps getting pulled into developer infrastructure.

20. BitMine Is Near Its 5% Ether Supply Target

Cointelegraph reported that BitMine could reach its goal of holding 5% of ETH supply by early November if its recent buying pace continues.

BitMine reported 6,001,302 ETH as of Sunday, equal to 4.9% of the 122.1 million ETH supply it cited. Cointelegraph calculated that 5% would be about 6.105 million ETH, leaving BitMine roughly 103,700 ETH short. The company also said its institutional staking platform, MAVAN, handles more than $2 billion in outside crypto.

This is the ETH treasury story reaching its governance edge.

At 5% of supply, the question is no longer only whether one company can keep buying. It is what the holder does with that position: stake, lend, use it as collateral, sell rewards, vote through governance-adjacent channels, or stop accumulating.

Bitcoin treasury companies mostly test balance-sheet leverage. ETH treasury companies also test network participation.

Evening Read

Read the Coinbase clearinghouse approval, then the South Korea JPYC market-maker story, then the NEAR Intents Bitget response.

The number to remember is $50 million.

That is the amount NEAR Intents says it blocked from Bitget-linked attackers. It captures the evening better than a price quote because it turns a philosophical argument into an operational one: should cross-chain protocols act like neutral pipes, compliance-aware routers, or something in between?

Tonight’s read is that crypto’s next phase is less about whether rails can move value. They can. The harder question is who is allowed to slow, block, reverse, reimburse, or supervise that movement when something goes wrong.