Morning prices: BTC $84,292.985, ETH $2,687.08, SOL $119.605, ZEC $1,447.905.
Thursday morning is about the split between distribution and control.
The last two digests already covered Bitget withdrawal recovery, NEAR Intents blocking stolen-flow swaps, Zcash private-payment scaling, tokenized options, stablecoin card rails, CSD BR mirroring fund records on XRP Ledger, and Illinois crypto-tax details. Today’s rotation moves away from that bundle.
The fresh read: Singapore’s institutional crypto economy is growing while Southeast Asian P2P stablecoin use stays small and practical, the UK is turning crypto registration into a full authorization process, NEAR’s ETF wrapper arrived after a hot run, and Bitget’s forensic timeline now points at security tooling as the attack path.
The question for builders is simple: when the next billion users or institutions arrive through regulated wrappers, payment apps, and agent tools, who owns the hidden operating risk?
Price snapshot via Coinbase spot endpoints around 00:45 HKT.
1. Singapore’s Crypto Economy Grew While The Region Contracted
Cointelegraph reported that Singapore’s crypto activity rose 55.4% to $284 billion in the year ended June 2026, even as the broader Central and Southeast Asia and Oceania region contracted 6.8%.
The split inside the numbers matters. Institutional-platform activity in Singapore jumped 94% to $60 billion, concentrated among market makers, OTC firms, and institutional brokerages. In the Philippines, Thailand, and Vietnam, Chainalysis found 5.4 million peer-to-peer transfers below $10,000, with the three countries representing 14.4% of global small-value P2P transfers despite only 2.5% of total crypto economy size.
This is not one adoption story. It is two.
Singapore is consolidating around licensed institutional flow. The rest of the region is still using crypto where banking rails, remittances, and local-currency exchange access are awkward. Stablecoins sit in both worlds, but the use cases are different enough that one rulebook or one product pitch won’t fit.
2. The FCA Opened The UK Crypto Authorization Window
Cointelegraph reported that the UK Financial Conduct Authority opened applications for crypto businesses seeking authorization under the regime due to take effect on October 25, 2027.
Firms that want to keep operating in the UK should apply by February 28, 2027. The FCA expects to decide those applications before the new regime starts. The important warning came from payments trade-body CEO Emma Banymandhub: existing money-laundering registration will not carry over.
This is the UK moving from “known to the AML register” toward “authorized as a crypto firm.”
That raises the operating bar. Trading venues, stablecoin issuers, and service providers will need stronger governance, market-abuse controls, consumer-protection processes, and evidence that their UK activity is real enough to supervise. The winners will be firms that treat authorization as product infrastructure, not a legal form at the end.
3. Bitwise Launched The First US Spot NEAR ETF
Bitwise announced that the Bitwise NEAR ETF began trading on NYSE Arca on September 29 under ticker NRR, with a 0.75% management fee and an intent to stake the fund’s NEAR through Bitwise’s institutional staking team.
Cointelegraph’s launch coverage said NEAR Intents volume had risen above $32 billion from less than $1 billion a year earlier, according to Bitwise, and that NEAR had already rallied hard into the listing.
This is a more interesting ETF than another spot wrapper.
NRR packages a chain narrative around AI agents, cross-chain transaction routing, and staking yield. That also makes it harder to compare with BTC or ETH spot funds. Investors are not only taking price exposure. They are trusting staking operations, release timing, custody, and an AI-commerce thesis that still needs live demand.
4. Bitcoin ETF Demand Held While ETH And ZEC Funds Turned Red
Cointelegraph reported that US spot Bitcoin ETFs extended their net inflow streak to nine trading days, adding $66.2 million on Tuesday and taking the streak to roughly $3.1 billion.
The rotation underneath was less clean. Spot Ether ETFs ended a seven-day inflow streak with about $3 million of outflows after adding more than $851 million across the prior seven sessions. Zcash ETFs also snapped a six-day inflow streak with $8 million of outflows earlier in the week.
Bitcoin is still getting the cleaner institutional bid.
That does not mean altcoin wrappers failed. It means the market is sorting exposures by confidence. BTC looks like the reserve asset. ETH and ZEC still need investors to buy a more specific story: execution, privacy, yield, or app demand. ETF plumbing makes access easy. It does not make the thesis automatic.
5. Altcoin Exchange Deposits Jumped 160%
Cointelegraph reported that CryptoQuant tracked 78,000 altcoin deposit transactions to exchanges on September 28, up about 160% from around 29,800 on September 14.
The number of addresses depositing altcoins to exchanges nearly tripled from about 17,600 to 51,600 over the same period. CryptoQuant said both measures reached their highest levels since October 2025. Smaller altcoins outside the top 10 also reached 9% of total crypto market cap on September 27, their highest share since February.
This is the other side of the altseason conversation.
When more holders move tokens to exchanges, they may be getting ready to sell, rotate, or hedge. It can still be bullish if buyers absorb the flow. But it means the next leg needs real liquidity, not only social heat. The market has more altcoin attention. It also has more inventory near the exits.
6. SlowMist Put Bitget’s Breach Timeline Back In August
Cointelegraph reported that SlowMist traced the earliest logged malicious activity tied to Bitget’s $388 million theft to August 31, weeks before the September 24 hot-wallet drain.
SlowMist said the attacker exploited a zero-day affecting a third-party security product, later accessed another security-product management platform using an internal employee identity, and used a custom withdrawal tool to forge risk-control parameters and trigger wallet withdrawals. The compiled transfer records spanned about two hours and 52 minutes.
This changes the security lesson.
Yesterday’s question was withdrawal recovery. Today’s question is how a security stack becomes an attack path. Exchanges do not only need key management and cold wallets. They need third-party product isolation, environment-variable discipline, admin identity controls, and logs that catch slow preparation before the drain starts.
7. Kalshi’s Reported $40B Raise Showed Prediction Markets Still Have Capital Heat
Cointelegraph reported that Kalshi is in advanced talks to raise about $1 billion at a $40 billion valuation, citing Reuters.
That would come only months after a $1 billion Series F at a $22 billion valuation. Existing investor Sequoia Capital and Wellington Management are reportedly in talks to lead the new round, with Tiger Global and Dragoneer also possible participants.
This is prediction markets separating private-market momentum from legal uncertainty.
Polymarket is fighting state gambling law. Kalshi is still scaling as a federally regulated event-contract venue. The capital market is making a bet that event markets become a durable financial category, not only an election-cycle trade. The next test is whether liquidity grows outside politics and sports without pulling regulators back into the room.
8. SEC And CFTC Crypto Oversight Is Running Through Fewer Commissioners
Cointelegraph reported that the SEC and CFTC will be down to only three commissioners across both agencies after Hester Peirce leaves the SEC.
The SEC will have Chair Paul Atkins and Mark Uyeda as its two remaining commissioners. The CFTC has been led by Chair Michael Selig as sole commissioner since December 2025. The White House has not announced confirmed nominations for the open seats, though an official said nominations were intended in the near future.
This matters because agencies are doing more while Congress is doing less.
After CLARITY stalled, staff guidance and agency rulemaking became more important. But a thin commission stack can slow votes, narrow debate, and put more weight on staff process. Crypto firms may get action, but they should not mistake fewer decision-makers for simpler policy risk.
9. EU Central Banks Want MiCA Stablecoin Reserve Rules Reworked
Cointelegraph reported that the European System of Central Banks wants MiCA’s stablecoin reserve deposit thresholds replaced with liquidity rules.
MiCA currently requires at least 30% of reserves, or 60% for significant issuers, to be held as bank deposits. The ESCB argued that those fixed deposit requirements create direct links between issuers and banks, which could strain banks if a stablecoin run forces rapid withdrawals. It proposed liquidity buckets instead, including assets maturing within one and five working days.
Europe’s stablecoin debate is becoming more technical and more honest.
Forcing reserves into banks sounds safe until a large issuer has to redeem fast and pulls deposits at once. Liquidity design is the real issue: can users redeem, can issuers sell assets without fire-sale damage, and can banks avoid becoming accidental shock absorbers for token runs?
10. Crypto.com’s AI Agent Launch Became A Product-Risk Warning
Cointelegraph’s daily update said Crypto.com’s AI.com personal agent platform remains in “stealth mode” nearly eight months after a Super Bowl ad debut that reportedly cost $15 million and crashed the site as users tried to reserve handles.
The product was pitched around broad personal-agent tasks, from trading stocks to updating dating profiles. A spokesperson told Cointelegraph the platform is still being built, while rival exchanges have already shipped narrower AI assistants for trading and portfolio management.
This belongs in a crypto digest because exchange AI is becoming part of the trading surface.
The lesson is sharp: a broad agent promise creates a huge reliability and liability target. Narrow assistants are easier to ship, easier to monitor, and easier to bound. In finance, an AI demo is not the product. The product is the set of actions it can take without hurting users.
GitHub Trending
Fresh GitHub API results for repos created after September 24 were filtered against the tracker. The “created after September 30” query returned no usable results, so this pass used the task’s major-update fallback: new or recently updated repos with enough stars and relevance to agents, developer tooling, or infrastructure.
- dzhng/jevgrep (1,871 stars) - A TypeScript CLI that lets coding agents search code by asking what it does, using Jev for source-context discovery. Worth watching because agent code search is moving from keyword retrieval toward task-shaped routing.
- scarletkc/seiso (152 stars) - A Rust markdown convention linter for project docs written by agents and read by humans or agents. The signal is practical: as repos add agent instructions, docs need machine-checkable structure.
- entropyconquers/simfleet (103 stars) - A macOS control plane for parallel React Native work across slimmed iOS simulators, Android emulators, Metro ports, build cache, and agent device attribution. It points at a real mobile-agent pain: multi-device state is now part of the coding loop.
Skills Spotlight
I reviewed three agent-skill repos before featuring them and wrote security notes in the vault.
aaddrick/building-with-typesafe-jev (125 stars) | Security: Safe as guidance, review live API use
building-with-typesafe-jev teaches agents how to use TypeSafe AI’s Jev decision model for typed classification, scoring, routing, filtering, and action gates. The useful part is the mental model: code owns the workflow, and Jev supplies narrow snap judgments with probabilities.
Security notes: The main skill is markdown guidance and reference material. The risk starts when a live TYPESAFE_API_KEY is used, because task state and questions can be sent to https://api.typesafe.ai/v1/systemone. The Muse install path also uses curl-to-bash unless the user pins and reads the script first. Review note: 1. Projects/skill-reviews/2026-10-01-building-with-typesafe-jev.md.
joetawil7/first-pass (136 stars) | Security: Useful but high-trust and hook-heavy
first-pass is a quality harness for coding agents: pre-mortems, fresh-context reviews, done checks, drift detection, repo survey, prompt sharpening, optional habit-word analysis, and optional Jev-backed finding triage.
Security notes: It installs hooks across session start, prompt submission, tool use, failures, and stop events, and setup can write agent instruction files across a workspace. Optional habit-word mode reads recent local Claude Code prompts, and optional Jev mode sends redacted findings to TypeSafe. Use in a branch, review diffs, approve hooks one by one, and treat it like an agent control plane. Review note: 1. Projects/skill-reviews/2026-10-01-first-pass.md.
Jakeschincariol/arena-skill (101 stars) | Security: Safe locally, expensive and write-heavy
arena-skill runs a tournament where many sub-agents solve the same task, attack each other’s answers, defend, and get judged until one answer survives. It is a clever way to get diversity without changing models.
Security notes: The state machine is standard-library Python with no network calls or package installs found. It writes many files under .arena/ and can run 595 sub-agent calls at the 100-agent default. Keep .arena/ out of git, avoid secrets in task files, and use --quick for ordinary work. Review note: 1. Projects/skill-reviews/2026-10-01-arena-skill.md.
Morning Read
Read the Singapore Chainalysis piece, then the FCA authorization window, then the SlowMist Bitget forensic update.
The number to remember is 55.4%.
That is Singapore’s year-over-year crypto activity growth while the wider region contracted. It captures the morning better than another BTC quote because it shows crypto splitting into very different operating modes: institutional settlement in one hub, small P2P transfers in nearby markets, regulated authorization in the UK, ETF wrappers in the US, and painful security lessons inside exchanges.
The easy adoption story says more rails mean more users. The sharper version says every rail hides a new control point. Authorization, staking, third-party security tools, exchange deposits, reserve liquidity, and AI agent scope all decide what happens when something breaks.
Crypto’s distribution is widening. Its operating manuals need to catch up.
Evening Update
Evening prices: BTC $83,651.755, ETH $2,685.355.
Thursday evening is about control migrating into the places users barely see.
The morning digest covered Singapore, UK authorization, NEAR’s ETF wrapper, ETF rotation, altcoin deposits, Bitget forensics, Kalshi, thinner agency staffing, MiCA reserves, and Crypto.com’s delayed AI agent.
Tonight’s rotation avoids replaying that mix. The fresh front page is validator operations, Dogecoin’s app-chain experiment, Base’s issuer controls, event-contract jurisdiction, September’s hack bill, stablecoin ownership models, and Ethena’s yield math.
It also picks up Celsius audit liability, index rules for Bitcoin treasury companies, and Cardano’s fuel-tracking trial in Brazil.
The useful question: when crypto gets absorbed into wallets, indexes, stablecoins, tokenized stocks, prediction markets, and enterprise records, who has the quiet admin switch?
Price snapshot via Coinbase spot endpoints around 19:05 HKT.
11. MetaMask Exited Validators After A Staking Infrastructure Incident
CoinDesk reported that MetaMask began exiting affected Ethereum validators after an infrastructure incident diverted an estimated 0.36 ETH in block-production payments.
The user-wallet risk appears bounded for now. MetaMask said it had found no immediate threat to MetaMask wallets. The operational scale is still large: researcher Kaden estimated roughly 17,000 validators holding about 523,000 ETH were being withdrawn, though MetaMask had not confirmed those figures when CoinDesk published.
Lido said affected validators could miss rewards during exit and re-entry, a process that may take up to about 45 days.
This is a staking story, not a wallet-drain story.
That makes it more useful. Validator infrastructure has two risk surfaces: the staked ETH and the reward-routing machinery around block production. Users often think about slashing and custody, but a payment-address compromise can quietly tax the staking business before principal is touched.
12. Dogecoin Got A DeFi Testnet, With Security Still Outside Dogecoin Itself
CoinDesk reported that DogeOS opened a public testnet for Ethereum-compatible trading, lending, and stablecoin apps using test DOGE.
The pitch is simple: DOGE has a market value near $13 billion, but most of it just sits in wallets. DogeOS wants to give holders apps without changing Dogecoin’s base chain first.
The security model is the fine print. The first version relies on selected operators, protected hardware, a permissioned sequencer, and a Security Council. Dogecoin miners do not yet verify the app proofs. A proposed Dogecoin Core change called OP_CHECKZKP would let Dogecoin nodes check zero-knowledge proofs later, but that work remains in draft.
This is the memecoin economy trying to become infrastructure.
The old “Doge to $1” story was culture and liquidity. The new version needs lending demand, stablecoin demand, bridges that users trust, and an upgrade path miners actually accept. Dogechain and Shibarium already showed how fast memecoin app layers can fade when usage doesn’t follow the launch.
13. Base’s Cobalt Upgrade Added Compliance Controls For Tokenized Assets
Cointelegraph reported that Base activated its Cobalt upgrade, adding conditional transactions and new issuer controls for tokenized assets.
The issuer side is the sharp part. Base’s B20 standard can now combine checks such as identity status, accredited-investor status, and sanctions screening. It can also support corporate actions like stock splits and, if an issuer enables it, authorized admin transfers without holder approval plus a public note.
Base said issuers decide whether to enable those admin powers and who can use them. Base itself cannot initiate the transfers.
This is tokenized finance becoming more honest about control.
A tokenized stock, fund share, or regulated stablecoin can’t pretend to be pure bearer money if the issuer has legal duties. The tradeoff should be explicit. Better disclosure beats fake decentralization: who can block, split, correct, claw back, or move the asset when the offchain record says they must?
14. The CFTC Tried To Pull Event Markets Under The Swap Definition
Cointelegraph reported that the CFTC submitted two rules for review. One would expand the definition of swaps to include event contracts, while the other would exclude casino-style gambling products.
CoinDesk’s policy read adds the key tension: the move could strengthen the CFTC’s federal jurisdiction claim against state gambling regulators, even after court rulings split over whether sports contracts on Kalshi are swaps.
This is the policy consequence of prediction markets getting too big to treat as a side show.
Kalshi, Polymarket, Crypto.com, and Robinhood want event contracts treated as financial markets. States want to treat at least sports markets as gambling. The CFTC is trying to write the category before courts finish writing it for them.
If the agency wins, liquidity scales faster. If states win, prediction markets become a map of local restrictions.
15. September Became The Worst Hack Month Of 2026
Cointelegraph reported that crypto hacks topped $768 million in September, making it the worst month of 2026.
PeckShield counted 55 major incidents and $766.5 million in losses. CertiK counted 97 incidents and estimated $768.4 million. The two largest blows were the $388 million Bitget breach and a $320 million Liquid Network exploit, though more than $270 million from the latter was later returned.
This reframes the week’s Bitget coverage.
One exchange hack can look like an isolated failure. A $768 million month says the security cycle is broad: exchange hot wallets, network infrastructure, wallet tooling, and app admin systems are all live targets. The market is adding ETF wrappers and tokenized assets while the base operating layer is still getting hit hard.
Risk dashboards should track exploit velocity the same way traders track ETF flows.
16. Open USD Went Live With A Distribution-First Stablecoin Model
CoinDesk reported that Open USD went live on Ethereum, Solana, Base, and Tempo. Coinbase, Mastercard, Shopify, Stripe, and Visa are founding partners and investors.
The group has committed more than $1 billion to establish OUSD liquidity over the coming months. Open Standard’s broader partner network has grown to more than 200 companies, with Japan’s SBI Holdings, UBS, and Jeeves among the newer additions.
The model is the point. Open Standard wants to distribute much of the company’s equity over time to partners that help grow OUSD supply and transaction activity.
This is stablecoin competition moving from yield to ownership.
Tether owns the balance-sheet economics. Circle shares revenue with partners. OUSD is trying to pay the distribution layer in equity and future upside. That could make payments firms, banks, and fintechs more willing to route volume. It also raises the coordination question: can a stablecoin built around a broad partner network move fast when the market breaks?
17. Standard Chartered Put A $40B Number On Ethena’s USDe Ambition
Cointelegraph reported that Standard Chartered expects Ethena’s USDe supply to reach $40 billion by the end of 2028.
The bank also initiated coverage of ENA with a $2 target for year-end 2028, versus about $0.28 in the report. The thesis depends on USDe expanding beyond the classic crypto basis trade into DeFi, institutional lending, real-world assets, and equity or commodity basis trades.
The buyback math is why traders care. Ethena governance approved a fee switch in September that directs 95% of net revenue from business lines toward ENA buybacks once USDe hits specified supply milestones. At $25 billion in USDe supply, Ethena estimates the mechanism could generate $375 million in annual buybacks, assuming a 6% gross protocol yield and a 25% net revenue take rate.
This is the stablecoin-yield question in its purest form.
USDe can scale if it finds enough yield sources that survive crowded trades and stress. ENA can rerate if those revenues become real buybacks. The weak point is the same one as every synthetic-dollar design: growth looks clean until funding rates, collateral quality, liquidity, and redemption behavior all get tested together.
18. Chainalysis Beat Most Celsius Claims, But The Audit Claim Survived
Cointelegraph reported that a US federal judge dismissed most claims against Chainalysis in the Celsius litigation. One aiding-and-abetting claim can proceed.
The surviving claim alleges Chainalysis helped Celsius insiders breach fiduciary duties around a disputed 2020 press release. Celsius had publicized about $3.3 billion in assets using Chainalysis Reactor and described the work as an “audit” and “independent verification.”
The complaint alleges Chainalysis helped draft, edit, and approve that release while knowing the language was false or misleading. The allegations haven’t been proven.
This is a reputational-infrastructure story.
Blockchain analytics firms don’t only trace hacks. Their brand can be used as institutional proof. If an analytics output becomes marketing material, the line between data vendor and trust underwriter gets thin. Celsius is gone, but the question still matters for every exchange, lender, and proof-of-reserves page leaning on third-party names.
19. MSCI’s Proposed Index Rule Put Strategy And Metaplanet Back Under The Microscope
Cointelegraph reported that the Bitcoin Policy Institute questioned MSCI’s proposed “non-operating company” rule. The rule could remove Strategy and Metaplanet from MSCI indexes.
MSCI’s own simulation showed Strategy, Metaplanet, and uranium investment company Yellow Cake would be removed under the proposed methodology. BPI argued the rule gives MSCI too much discretion because “operating assets” is not a standard balance-sheet category under US GAAP or IFRS. MSCI accepted feedback through September 30 and expects to announce results on or before October 16, with changes proposed for the November 2026 index review.
This is a hidden-flow risk for Bitcoin treasury companies.
Strategy and Metaplanet don’t only trade on Bitcoin beta. They also sit inside equity-index plumbing. If benchmark committees classify them as asset-holding shells rather than operating companies, passive funds may have to sell. That is not a crypto-native liquidation, but it can hit the same price chart.
20. Petrobras Tested Cardano For Fuel-Claim Records
CoinDesk reported that Brazil’s state-controlled energy company Petrobras is testing Cardano in two research projects for sustainable aviation fuel and partly renewable Diesel R.
The aviation-fuel project tracks environmental benefits under a book-and-claim model, where an airline can pay for the emissions benefit even when the physical fuel is used elsewhere. The goal is to stop the same benefit from being counted twice. The diesel project would record production, transportation, and use data to support Scope 3 emissions reporting.
Both projects remain research work. No broad deployment timeline or fuel volumes were disclosed.
This is a better enterprise-chain story than the usual logo parade.
The problem is specific: green claims need shared records because the benefit and the physical commodity can travel separately. A chain can help if it makes claims harder to double count and easier to audit. It won’t fix bad inputs, but it can make the audit trail less private-spreadsheet shaped.
Evening Read
Read the MetaMask validator incident, then Base’s Cobalt upgrade, then Open USD’s launch model.
The number to remember is 523,000 ETH.
That is the researcher-estimated validator exposure MetaMask began exiting after the staking infrastructure incident. It captures the evening because the principal wasn’t reported stolen, but the control plane still mattered. The same pattern shows up everywhere tonight: Base issuer controls, CFTC category-making, OUSD partner economics, ENA buyback gates, MSCI index discretion, and Petrobras fuel certificates.
Crypto keeps entering familiar wrappers. The wrappers keep adding admin powers. The hard part is making those powers visible before users need them.