Morning prices: BTC $84,213.84, ETH $2,683.12, SOL $117.295.
Friday morning is about hidden fragility meeting better measurement.
The last three digests already covered Singapore institutional flows, UK authorization, NEAR’s ETF wrapper, Bitget forensics, MetaMask validator exits, Base issuer controls, DogeOS, event-market jurisdiction, MiCA reserve mechanics, and Ethena yield math. Today’s rotation keeps only the stories where the facts changed overnight.
The fresh read: crypto’s strongest quarter still carried a $1.26 billion security bill, NEAR Intents went from blocking stolen flow to patching its own exploit, Bloomberg made stablecoin data part of the professional terminal workflow, and Latin America’s payment stack may lean on too few cash-out providers.
The question for builders is blunt: when crypto rails become ordinary financial infrastructure, where is the thinnest layer?
Price snapshot via Coinbase spot endpoints around 00:13 HKT.
1. Bitcoin Started October In The Same Range, But Citi Raised The Target
CoinDesk’s markets page said bitcoin opened the new quarter stuck in the old $82,000 to $85,000 range, even after a soft-inflation pop briefly carried price above $85,000.
The more useful signal was the institutional forecast beside it: Citi raised its 12-month bitcoin target to $113,000 and lifted its ether target from $2,240 to $3,028 as ETF flows resumed.
This is not euphoria. It is a market being repriced by two different clocks.
Spot still has to clear the same near-term macro range. Allocators are looking a year out and deciding regulated exposure deserves a higher base case. That makes the $82,000 to $85,000 zone less boring than it looks: price is chopping while sell-side targets and product access keep moving up.
2. Crypto Lost $1.26B To Security Incidents In Q3
Cointelegraph reported that CertiK counted $1.26 billion of crypto security losses across 247 incidents in the third quarter, up 53.9% from $819.4 million in Q2.
September did most of the damage. CertiK tracked roughly $769 million in losses across 99 incidents, while PeckShield separately counted 55 major incidents and $766.5 million stolen. The biggest losses were the Bitget breach, the Liquid Network exploit, Tectonic, and a Coldcard theft.
This is the ugly side of a bull quarter.
ETF inflows can insulate institutions from DeFi exploit risk, but they do not erase the sector’s reputation problem. Every month like September pushes serious users toward regulated wrappers, custodians, and insurance language. Onchain finance wants capital efficiency. Capital wants fewer emergency war rooms.
3. NEAR Intents Patched Its Own $3.8M Exploit
Cointelegraph reported that cross-chain protocol NEAR Intents lost $3.8 million after a bug involving Omni deposit and withdrawal infrastructure and a NEAR Intents smart contract.
The protocol said users will be made whole, the contract-side vulnerability has been patched, and a fuller report will follow. ZachXBT analysis cited in the piece said funds moved to KuCoin and then bridged to Bitcoin.
This lands awkwardly because NEAR Intents was just in the news for blocking more than $50 million of Bitget-linked swap attempts and freezing more than $500,000.
The lesson is not hypocrisy. It is that intervention tools and protocol safety are separate jobs. A cross-chain service can help stop bad flow and still carry its own integration bugs. Users need both: a clear incident policy and contracts that do not turn deposit plumbing into loss plumbing.
4. Latin America’s Stablecoin Stack May Depend On 16 Liquidity Providers
Cointelegraph reported that a Verda Ventures and Varys Capital report mapped 494 Latin American stablecoin companies, but found only 16 focused mainly on wholesale liquidity, treasury, and credit.
Verda partner Amit Chu said the fragility sits in that thin liquidity layer. Chainalysis data cited in the piece put stablecoins at 32.1% of cross-border crypto value in the region by June 2026, plus 22.1% of domestic P2P activity and 17.6% of personal wallet balances.
This is the stablecoin adoption story after the app screenshots.
Users care about cashing out into local currency. If only a handful of providers supply that bridge, banking access, treasury lines, and wholesale spreads become the real uptime layer. Stablecoin payments can look distributed at the wallet level while still being concentrated at the fiat exit.
5. Bloomberg Put Stablecoin Metrics Inside The Terminal
Cointelegraph reported that Bloomberg launched an Allium-powered stablecoin dashboard for Terminal users.
The dashboard covers stablecoins with more than $100 million in circulation, representing over 98% of the market. Users can compare supply, mints, burns, transfer volume, velocity, blockchain network, and peg type through RWAS <GO>. DeFiLlama data cited in the piece put total stablecoin market cap above $306 billion, with USDT near 60% share.
This is boring in the best way.
Stablecoins are moving from crypto dashboards into the same screen as rates, FX, money markets, and fixed income. That changes the user. A portfolio manager does not need a wallet to care about stablecoin velocity. They need a reliable feed that says whether token dollars are growing, shrinking, moving, or sitting still.
6. Illinois Agreed To Delay Its 0.2% Crypto Tax
CoinDesk reported that Illinois agreed to postpone its 0.2% digital asset transaction tax until July 1, pending court approval.
The Digital Chamber and Illinois Blockchain Association negotiated the delay while the legal challenge continues. The tax was previously scheduled for January 1, 2027 and applies to digital asset activity involving firms above $100,000 in receipts.
This is not a policy win yet. It is time.
The delay lets both sides fight the legal question before firms have to build collection systems around an unsettled rule. For builders, the important part is the tax base. A tiny rate can still be expensive if it touches too many transfers, fees, bridges, custody movements, or stablecoin flows.
7. Binance’s EU Exemption Use Drew Fresh Scrutiny
Cointelegraph’s daily update said European regulators are scrutinizing Binance’s use of a licensing exemption to keep serving EU customers without full authorization under MiCA.
Binance previously told Cointelegraph it remained committed to long-term compliant operations in Europe and continued pursuing MiCA authorization.
This matters because MiCA’s transition period is becoming a real market-structure filter.
The question is no longer whether large offshore venues want Europe. They do. The harder question is whether interim exemptions become a practical bridge or a reputational liability. Users may not notice the legal route until regulators force a service change. Institutions will notice sooner.
8. Petrobras Used Cardano To Track Renewable Fuel Claims
Cointelegraph reported that Petrobras developed two Cardano-based applications to track sustainability data for sustainable aviation fuel and Diesel R renewable fuel.
One app tokenizes environmental attributes tied to sustainable aviation fuel using a Book-and-Claim model designed to prevent double counting. A second app tracks checkpoints for renewable diesel production, transportation, and use. Shell’s Avelia platform was cited as a similar blockchain-based fuel-claim system, with more than 84 million gallons of SAF entering the global network since 2022.
This is not DeFi, but it is a useful protocol story.
The value is not the token. The value is an auditable claim that can travel separately from the physical fuel without being counted twice. That is exactly where blockchains can help boring industries: not by making everything tradeable, but by making record conflicts harder to hide.
9. Chainalysis Beat Most Celsius Claims, But One Audit Claim Survived
Cointelegraph reported that a US federal judge dismissed most claims against Chainalysis in Celsius litigation, but allowed one aiding-and-abetting claim to proceed.
The surviving claim concerns Celsius’ disputed $3.3 billion audit and alleges Chainalysis helped Celsius insiders breach fiduciary duties. The judge dismissed 15 other claims.
This is a reminder that analytics firms are part of crypto’s trust stack.
When an exchange, lender, or custodian waves around an audit, proof, attestation, dashboard, or forensic partner, users hear “verified.” Courts may ask a narrower question: who knew what, when, and did their work help publish a false picture? The compliance vendor is no longer outside the blast radius.
10. Prediction Markets And Tokenization Kept Pulling On Old Rules
CoinDesk’s prediction-markets page showed the UK FCA weighing whether to ease its financial prediction-market ban, even as its public position still supports the restriction. CoinDesk’s finance page also showed market-infrastructure firms asking the EU to remove or raise caps in its tokenization trial.
Both stories point in the same direction: regulated finance wants more onchain and event-contract experimentation, but the rulebooks still treat many of these products as edge cases.
This is where 2026 keeps getting interesting.
Prediction markets have retail demand. Tokenized securities have institutional demand. Regulators are trying to separate useful market structure from gambling, leverage, synthetic exposure, and consumer harm. The winners will be the products that make the control surface obvious before the product gets big.
GitHub Trending
Fresh GitHub API results for repos created after September 30 were thin, so this pass used the task’s major-update fallback: fresh or recently updated repos with enough attention and relevance to agents, developer tooling, infrastructure, or crypto operations. I skipped repeat entries already in the tracker and obvious abuseware.
- Louis-CFM/coucou (2,232 stars) - A tiny macOS notch and Windows top-bar companion that watches Claude Code sessions. The useful signal is session visibility: coding agents are becoming long-running local coworkers, so operators want ambient status, not another terminal tab.
- firelex/jeff (1,248 stars) - A small “System 1” decision model for millisecond option selection with calibrated probabilities and swappable LoRA adapters. Worth watching because agent stacks keep needing cheap classifiers, routers, and gates that do not call a giant model for every judgment.
- openai/mcp-extensions (581 stars) - A TypeScript repo for building MCP-backed extensions that feel native in ChatGPT. The repo is early, but the direction matters: plugins are moving from loose tool calls toward packaged product surfaces.
Skills Spotlight
I reviewed three agent-skill repos before featuring them and wrote security notes in the vault.
rehan-remade/universal-modder (1,367 stars) | Security: Review before install or real game-folder use
universal-modder packages skills, a Python um CLI, and a knowledge base for agent-led PC game modding: recon, backups, asset generation, reverse engineering routes, Windows driving, recording, packaging, and field notes. It is impressive because it treats game modding as an operating loop instead of a pile of prompts.
Security notes: This is a high-trust toolkit. It can call fal through a remote MCP/API using FAL_KEY, run ffmpeg, Blender, PowerShell, GitHub CLI, and Windows process/input tools, download ffmpeg for Windows setup, and write or restore files around game saves. The repo has real safety rules, PID-only process kills, and publish checks for secrets/game files, but install it first in a disposable modding workspace. Review note: 1. Projects/skill-reviews/2026-10-02-universal-modder.md.
nanaism/yomiyasu (875 stars) | Security: Safe for local markdown use
yomiyasu is a Japanese writing skill that removes AI-like stiffness from generated Japanese, especially for technical articles, specs, PR descriptions, and internal reports. It also ships local lint and diff scripts for measuring unnatural phrasing and meaning drift.
Security notes: The packaged utilities use Python standard library only, read user-supplied text files, and do not add a network path in normal use. Corpus-building scripts write local test files and include subprocess-based development workflows, so treat those as maintainer tooling. Review note: 1. Projects/skill-reviews/2026-10-02-yomiyasu.md.
kaankiziltug/logo-design-skill (1,288 stars) | Security: Safe for trusted local SVG workflows
logo-design-skill gives agents a full identity-design process: brief, research, concept generation, SVG construction, audits, preview sheets, presentation boards, exports, favicons, and a large classified reference library of real logos.
Security notes: Most scripts are local Python and do not call remote APIs. The main risk is renderer execution: render_png.py may run CairoSVG, rsvg-convert, Inkscape, headless Chrome, or Quick Look on SVG/HTML inputs. Use it on trusted assets or isolate it for third-party SVGs. Also treat the reference library as study material, not source art. Review note: 1. Projects/skill-reviews/2026-10-02-logo-design-skill.md.
Morning Read
Read the Q3 security-loss report, then the LatAm stablecoin liquidity piece, then the Bloomberg stablecoin Terminal brief.
The number to remember is 16.
That is how many companies the LatAm stablecoin report found focused mainly on wholesale liquidity, treasury, and credit out of a 494-company map. It captures the morning better than the BTC quote because it shows where crypto systems can look broad at the app layer while staying narrow underneath.
Security losses, stablecoin dashboards, tax delays, MiCA exemptions, fuel traceability, audit liability, and prediction-market rules all point at the same thing: crypto is becoming legible to traditional finance, courts, and regulators. Legibility is good. It also makes the weak layers easier to find.
The next phase is not only about more users. It is about proving the hidden operators can survive stress.
Evening Update
Evening prices: BTC $86,347.935, ETH $2,745.205, SOL $121.65.
Friday evening is about the operating layer becoming visible.
The morning digest covered the Q3 hack bill, NEAR Intents’ exploit, Latin America’s stablecoin liquidity bottleneck, and Bloomberg’s stablecoin dashboard.
It also covered Illinois’ tax delay, Binance’s EU exemption scrutiny, Petrobras on Cardano, Celsius audit liability, prediction-market rules, and the morning GitHub and skills rotation.
Tonight’s rotation avoids replaying that stack. The fresh front page is South Korea turning tokenized securities into licensed market structure, Europe arguing over stablecoin rewards, and Zano choosing rollback over counterfeit supply.
It also picks up Ethereum’s private API payments, Lightning’s urgent patch call, and Aave-adjacent adapter risk. Protocol safety can still be undermined one layer up.
The useful question: when crypto products depend on wrappers, adapters, local licenses, and offchain recovery processes, which layer do users actually trust?
Price snapshot via Coinbase spot endpoints around 18:13 HKT.
11. South Korea Put Numbers On Tokenized Securities
Cointelegraph reported that South Korea’s Financial Services Commission proposed detailed rules for tokenized securities ahead of a February 2027 rollout.
The proposal would allow stocks, bonds, funds, and some fractional investment securities to be issued and circulated in tokenized form. Issuers that directly manage customer accounts would need at least 4 billion won, about $2.8 million, in equity capital plus dedicated compliance and technology staff. A new OTC exchange license would cover debt securities, and retail net purchases would be capped at 100 million won, about $70,000, per OTC exchange each year.
This is tokenization becoming domestic market structure, not just a global RWA deck.
Korea is defining who can issue, who can trade, how much retail can buy, and what operating capital sits behind the ledger.
That is the part institutions care about. The chain is useful only after the legal wrapper knows what kind of market it is.
12. Korean Exchange Profits Fell 78% As Retail Attention Moved Elsewhere
Cointelegraph reported that South Korean crypto exchange operating profits fell 78% in the first half of 2026.
KoFIU data showed average daily trading volume down 44% from the prior six months, market capitalization down 33%, won-denominated deposits down 35%, and exchange sales down 41%. The survey covered 26 registered virtual asset service providers, including 17 exchange operators and nine custody or wallet firms. The number of trading-eligible accounts still edged up 0.4%.
That split is the real signal.
More people can be enabled to trade while less money actually trades. Korea’s market is not lacking account creation. It is lacking intensity. If domestic equities keep pulling oxygen away from tokens, Korean exchanges have to compete on products, tokenized securities access, custody, and payment utility rather than waiting for another retail mania.
13. Europe Got A 50,000-Letter Stablecoin Rewards Fight
Cointelegraph reported that Stand With Crypto EU said more than 50,000 Europeans wrote to the European Commission.
They asked Brussels to loosen MiCA restrictions on stablecoin rewards.
The campaign wants regulated providers to offer incentives such as cashback, loyalty benefits, and fee reductions. The group said more than 126,000 people have also signed a broader petition.
The other side is central-bank pressure. The European System of Central Banks wants the interest ban extended to lending, borrowing, and staking-style arrangements. It also wants reserve-deposit requirements replaced with liquidity rules.
Europe’s stablecoin fight is no longer abstract.
The consumer-facing question is rewards. The central-bank question is deposit flight and bank stress. The issuer question is whether euro stablecoins can compete with dollar tokens if they cannot pay users anything. MiCA gave Europe a framework. The review is about whether that framework makes regulated stablecoins useful enough to matter.
14. Zano Rolled Back A Month After Counterfeit Supply Became Indistinguishable
Cointelegraph reported that a Zano exploiter created 36.9 million unauthorized ZANO and about 1.8 quadrillion fUSD.
The team later rolled back roughly a month of blockchain history.
The attacker first exploited the Gateway Address vulnerability on August 29, then repeated the exploit on September 25. Zano said the counterfeit coins functioned like authentic ZANO and could be spent normally, which meant the team could not simply remove bad balances without also touching legitimate chain history.
This is one of the ugliest governance choices in crypto.
Leaving the supply alive would poison the monetary system. Rolling back the chain hurts finality and honest users. There is no clean slogan here. When a bug creates valid-looking money, the project has to choose which promise breaks: immutability, supply integrity, or user recovery.
15. Ethereum’s zkAPI Made Private Prepaid API Access Real
Cointelegraph reported that Ethereum’s zkAPI went live on mainnet.
The launch turned an earlier zero-knowledge API payment proposal into a working implementation.
Users deposit funds into an Ethereum vault and use zero-knowledge proofs to show they have enough credit for API requests without revealing which deposits are theirs. The initial use case is private, prepaid access to AI and other metered APIs through short-lived API keys with spending limits. The project also released a local client, SDK, and browser chat implementation.
The limitation matters: zkAPI does not hide prompt contents or network metadata from the provider.
Even with that caveat, this is a useful privacy primitive. It separates billing identity from usage access, which is exactly where AI services, data APIs, and agent tooling get uncomfortable. Users may accept providers seeing the request. They may not want every request tied to the same payment identity forever.
16. Core Lightning Told Old Nodes To Upgrade Immediately
Cointelegraph reported that Core Lightning warned node operators running version 26.06.7 or earlier to upgrade after reports of attackers targeting unpatched nodes.
The team did not publicly detail the active attack path. The earlier 26.06.8 release patched issues that could crash sender nodes, exhaust memory through the REST interface, and cause users to lose funds to a penalty during channel close. Some tests were withheld to make reverse engineering harder while operators upgraded.
This is the boring maintenance story users only notice when it fails.
Lightning reliability depends on many small operators staying patched. That is a hard distribution problem. The network can be technically decentralized while still carrying correlated software risk if enough nodes sit on old releases after a warning.
17. Aave V3 Was Fine, But A Third-Party Adapter Still Lost $305K
Cointelegraph reported that an attacker drained about $305,000 from two Safe multisig wallets.
The path ran through a third-party adapter built on top of Aave V3.
Aave founder Stani Kulechov said Aave V3 contracts were unaffected. SlowMist said the attacker exploited an access-control flaw in a module used to open and close leveraged Aave V3 positions through Safe wallets. The adapter also let the caller control router and swap transaction data. About 1,300 WETH in debt was repaid during the attack to unlock collateral, and the attacker ultimately stole 114.09 ETH.
This is composability’s less glamorous side.
The base protocol can be sound and users can still lose money through automation sitting above it. Wallet modules, leverage helpers, adapters, routers, and transaction builders become part of the risk surface. “Aave was unaffected” is true. It is also not enough comfort for the Safes that were drained.
18. Porsche’s Web3 Project Ended With Most Of The Volume In The Rearview
Cointelegraph reported that Porsche is winding down its Web3 project and Pioneers Circle community.
The decision comes nearly four years after Porsche launched its 911 NFT collection.
The NFTs will remain onchain, the Discord will become a read-only archive, and the project account will stop receiving active updates. The collection originally targeted 7,500 tokens but halted minting at 2,363 after complaints about pricing and utility.
OpenSea data cited in the report put all-time trading volume near $20 million. The past year saw only about $38,000, and the past month about $2,900.
This is a clean brand-NFT epitaph.
Luxury logos were never enough. A durable community needs repeat utility, credible privileges, and a reason to keep showing up after mint day. Porsche can archive the experiment without threatening its main business. Smaller brands do not get that luxury.
19. Tokenized RWAs Hit $34.5B, But The Mix Does Not Mirror TradFi
Cointelegraph reported that Dune put tokenized real-world assets at $34.5 billion as of August 31.
That was up more than 140% year over year.
The important detail is composition. Cash equivalents still dominate supply, but equities were the most actively traded segment. In tokenized equities, single stocks made up 81% of spot supply while ETFs were 19%. Separate Binance Research data put tokenized equities at $4.43 billion as of September 15, up 390% in 2026 but still only 0.0029% of the $151.9 trillion global listed-equity market.
Tokenized markets are not just smaller copies of old markets.
Onchain investors may prefer single-name access, 24/7 trading, collateral mobility, or assets unavailable through local brokers. That means adoption will not map neatly to ETF penetration in TradFi. Tokenization is a distribution change first. Portfolio construction comes after the rails prove they can settle and stay compliant.
20. Bitcoin Broke The $85K Wall, But Confirmation Still Runs Through Flows
Cointelegraph reported that bitcoin pushed toward $87,000 after buyers cleared sell orders around $85,000.
BTC reached $86,857 on Bitstamp before pulling back.
Short liquidations topped $122 million over 24 hours, with cross-crypto liquidations around $210 million. A separate Cointelegraph report said US spot Bitcoin ETFs took in $102.7 million on Thursday after a $148.7 million outflow the prior day, while Ether ETFs saw a third straight outflow and Solana ETFs extended a two-session outflow streak.
The price move is useful, but the confirmation test is cleaner.
A one-day liquidity break can be short covering. A durable move needs volume, ETF demand, and less sell-wall rebuilding above spot. The difference from the morning is that bitcoin stopped merely ranging and forced traders to chase. Now flows have to prove the chase has real buyers behind it.
Evening Read
Read the South Korea tokenized-securities proposal, then the MiCA stablecoin rewards fight, then the Zano rollback post-mortem coverage.
The number to remember is 36.9 million.
That is how much unauthorized ZANO the attacker created before the rollback decision. It captures the evening better than the BTC breakout because it shows the operational truth underneath the market tape: crypto rails are only as strong as their recovery choices.
Korea’s tokenized securities rules, Europe’s stablecoin-reward fight, Core Lightning’s patch warning, Aave adapter losses, zkAPI privacy limits, and Zano’s rollback all point at the same thing. The next phase is not about whether crypto can plug into finance. It already can.
The harder question is what happens when the plug gets hot.