Home Blog Page 10

Swift Links Two Banks’ Tokenized Deposits in First Live Transaction

TL;DR

  • HSBC and Standard Chartered completed the first live cross-border transaction between two banks using Swift tokenized deposits infrastructure.
  • Swift’s ledger coordinated payment instructions while final settlement continued through the banks’ existing payment systems.
  • The transaction does not yet show how the system performs at higher volumes, across more currencies, or with more participating banks.

On August 19, HSBC and Standard Chartered completed the first live cross-border transaction between two banks on Swift’s blockchain-based ledger, using tokenized deposits, digital versions of bank deposits. Swift is the messaging network banks use to move money internationally.

The banks did not disclose the amount, the currencies involved, the payment corridor, or how long settlement took.

How the two systems connected

HSBC and Standard Chartered each already run their own systems for issuing tokenized deposits, digital records that represent money customers hold in their bank accounts. Before this test, those two systems had no way to talk to each other, similar to two companies running incompatible accounting software.

Swift’s ledger gave the banks a shared space to exchange payment instructions and agree on what each owed the other. Once that agreement was recorded, the actual transfer of money still happened through the banks’ existing payment systems. So Swift added a coordination layer to the infrastructure. The ledger allows two different bank networks to confirm and reconcile a transaction before final settlement through existing payment systems.

Is a tokenized deposit the same as a stablecoin?

No. A tokenized deposit is a digital claim on money a customer already holds in a specific bank account. The bank issues it, tracks it, and remains responsible for the underlying deposit. HSBC converts eligible deposits into tokens at a one-to-one ratio. Clients can then move those balances between approved HSBC locations, subject to local rules.

A stablecoin works differently. It is typically issued by a company rather than a bank. It tracks a reference asset such as a currency, and often trades on public blockchain networks open to anyone. A tokenized deposit stays inside the issuing bank’s regulated system and does not circulate the same way.

Where this fits Swift’s wider pilot

Swift announced on July 9 that its blockchain-based ledger was ready for initial use. At that point, 17 banks across six continents were preparing to run their own live tests with tokenized deposits.

The goal behind the effort is to enable cross-border payments at any hour, including nights and weekends, when traditional transfers slow down or require banks to keep funds parked in multiple locations in advance. A shared ledger could reduce how much money banks need to hold in reserve just to cover timing gaps.

HSBC’s tokenized deposit service, called TDS, is already live in six markets: Hong Kong, Singapore, Luxembourg, the UK, the US and the UAE. That footprint gives the pilot a base to expand from if other bank pairs replicate what HSBC and Standard Chartered just completed.

Scaling beyond a single transaction

Two banks can now exchange and reconcile tokenized deposit obligations through Swift’s shared ledger. The banks did not name any corporate clients involved or say when the connection might become available for customer use.

Whether the system holds up at higher transaction volumes and across more currencies depends on getting more of Swift’s 17 pilot banks trading with each other across different markets, producing enough activity for a real stress test.

Kraken US Stock Trading Reaches European Users

Glass facade of a modern office tower reflecting the Kraken logo, with blurred financial charts and ticker tape in the background, symbolizing crypto IPO ambitions and institutional finance.

TL;DR

  • Kraken now gives eligible EEA customers access to stock trading in more than 7,000 U.S.-listed shares.
  • Stock trading operates under Kraken’s Cyprus-licensed entity, while xStocks are issued and offered through separate entities.
  • Traditional shares provide equity ownership, while xStocks are tokens with different custody, legal claims and investor protections.

Eligible customers across the European Economic Area can now trade more than 7,000 U.S.-listed stocks with Kraken. On August 18, the exchange added conventional shares to its offering of crypto and tokenized equities inside its trading platform.

US stock trading is available through Kraken Pro on desktop and mobile, as well as the main Kraken app. Kraken says stock trading is commission-free, but spreads, foreign-exchange costs and other fees may apply.

Stock access is live across the EEA

The service operates through Payward Europe Digital Solutions (CY) Limited, authorized under the European Union’s MiFID II framework. Cyprus’s securities regulator lists the company as an authorized investment firm with licence number 342/17. MiFID II sets conduct and investor-protection requirements for firms providing investment services in the bloc.

Kraken already offered crypto assets and xStocks to eligible customers in parts of Europe. Conventional equities extend that platform beyond its original role as a crypto exchange. Users can now hold more types of investments in one account, instead of moving funds between a crypto venue and a separate broker. The service is not available to every resident or every account automatically. Kraken limits access to eligible customers, and geographic restrictions and additional terms still apply.

How traditional shares and xStocks differ

Kraken presents more than 7,000 conventional U.S. stocks alongside 700+ xStocks and over 600 crypto assets, priced and displayed in the same interface. But what a customer actually holds behind that price differs by product.

A traditional share represents equity ownership in a listed company, carrying shareholder rights that depend on the security, broker arrangements and local rules.

An xStock carries no such ownership. It is a token issued by Backed Assets (JE) Limited, built to track a share’s price with 1:1 backing from the underlying stock. Token buyers hold no direct voting rights or dividend entitlements, and no legal claim on the company’s residual assets in a liquidation.

Eligible users can transfer xStocks to supported self-custody wallets and use them in compatible onchain applications, capabilities a traditional share does not have. Users can also trade the tokens outside regular stock-market hours.

Self-custody and onchain use carry their own risks. Kraken’s disclosure lists technology, liquidity, issuer, counterparty and regulatory risks for xStocks, including the possibility of losing the full investment.

Regulation follows two separate routes

MiFID II is the EU framework that governs traditional brokers, requiring firms to meet set conduct and investor-protection standards. Kraken holds that authorization for the its new stock service via Payward Europe Digital Solutions, its Cyprus-licensed entity. 

xStocks are tokenized stocks. Backed Assets issues the tokens in Jersey, and Payward Digital Solutions offers them to customers through a Bermuda-licensed entity. Kraken states that xStocks are not registered with local securities regulators. They are unavailable in several markets, including the United States and United Kingdom.

When comparing the products, customers should note how traditional shares and xStocks differ in custody arrangements, legal claims and available protections.

What European customers still need to check

Kraken plans to take its combined stock and tokenized-equity offering into more markets. It has not provided a country-by-country expansion schedule.

Before placing an order, users need to confirm which product they selected and which legal entity provides it. They should check trading hours, withdrawal options, currency-conversion costs and tax treatment.

How the SEC’s Crypto Rules Could Change Token Fundraising in the US

TL;DR

  • The SEC’s proposed crypto offering rules would create two fundraising exemptions for token issuers and a conditional path out of investment-contract status.
  • The larger exemption includes $20 million and $75 million tiers, with audited financial statements required only at the higher tier.
  • The proposal is open for public comment for 60 days after publication in the Federal Register.

On August 18, the U.S. Securities and Exchange Commission proposed Regulation Crypto Assets, outlining two tailored fundraising exemptions for crypto issuers and a conditional safe harbor that could eventually move qualifying assets outside investment-contract treatment.

The proposal arrives while Congress has yet to pass digital-asset market-structure legislation, leaving the SEC to address crypto offering rules within the existing federal securities framework. The draft outlines how token projects could raise capital under securities-law conditions and later exit investment-contract status if they met specified requirements.

The framework would preserve disclosure obligations and federal protections for investors while creating crypto-specific routes that differ from full securities registration.

Why is the SEC acting now?

Regulation Crypto Assets builds on a March 2026 interpretive release, in which the SEC clarified how federal securities laws apply to crypto assets and transactions.

Despite months of negotiating over digital-asset market-structure rules, the Senate left for its August recess without voting on the CLARITY Act. With the legislation still unresolved, the SEC moved to define rules within the existing framework. The proposal marks the first major crypto rule-making action under SEC Chairman Paul Atkins’ tenure that directly addresses offering rules.

How would the framework work?

The proposal would create two exemptions for issuers raising capital while a crypto asset is still treated as part of an investment contract.

The smaller route would permit a one-time offering of up to $5 million during a four-year period. A larger exemption would allow offerings of up to $75 million during each 12-month period, structured in two tiers: a $20 million tier and a $75 million tier, each measured over its own 12-month period. Both tiers would require financial statements, with audited financial statements required only at the $75 million tier. Ongoing reporting would apply across the exemption. The two fundraising paths would give qualifying issuers alternatives to full securities registration.

Once an issuer has completed or permanently ceased the essential managerial efforts it promised investors, it could seek to exit investment-contract status entirely through the proposal’s conditional safe harbor, which ties the asset’s regulatory treatment to whether the issuer’s role in the project has actually ended.

What would it mean in practice?

Issuers relying on the proposed framework would still need to provide investors with narrative disclosures covering the issuer, the crypto asset, the network, conflicts, risks and other information relevant to an investment decision.

The proposal uses principles-based disclosures designed around crypto-specific fundraising instead of requiring every qualifying issuer to follow the same filing model used by a traditional public company.

Federal investor-protection rules would continue to apply regardless of whether an issuer uses one of the offering exemptions or an asset qualifies for the safe harbor. Antifraud and antimanipulation provisions would remain in force across the framework.

The exemptions would preempt certain state registration and qualification requirements for covered transactions, while issuers would still need to meet the eligibility conditions attached to the federal framework.

What comes next?

The SEC opened file S7-2026-27 for public comment. The comment period runs for 60 days after the proposal appears in the Federal Register.

The comments will reveal whether participants think the SEC’s interpretation of existing securities law goes far enough, or too far, for an industry that is tired of waiting on Congress.

DefiLlama Founder Let a Scam App Drain His Wallet to Get Apple’s Attention

TL;DR

  • DefiLlama’s founder let a fake DefiLlama app drain a small wallet after months of unsuccessful reports to Apple, and the listing was removed within days.
  • The impersonating app asked users for their seed phrase, giving its operators full control over any wallet entered into the app.
  • The case highlights how crypto app impersonation can survive storefront review and why users should verify the developer before trusting a wallet-related app.

For months, DefiLlama flagged a fake version of its app to Apple over trademark violations and impersonation. But Apple left the listing up. So the analytics platform’s pseudonymous founder, known as 0xngmi, funded a small wallet, installed the impersonating app himself, and let it steal the money.

0xngmi disclosed the episode in a series of posts on X on August 15. The fake app was a simple clone. It asked users to enter their seed phrase, the string of words that grants full control over the related crypto wallet. No legitimate analytics app needs that phrase.

0xngmi said the operators behind the app had verified their Apple developer account using a defunct, decades-old shoe business. The same group had targeted other major crypto brands with similar impersonation attempts.

The reporting timeline

According to 0xngmi, DefiLlama’s team reported the fake app to Apple’s abuse and trademark channels repeatedly, describing the impersonation and the brand infringement in detail. Despite the continuous effort, the listing stayed up for months.

So, the team changed tactics. They loaded a wallet with a small amount of crypto, installed the app, and went through its flow, entering the seed phrase where it was requested. As expected, the funds disappeared. Instead of simply filing another complaint, 0xngmi now sent evidence to Apple that the app was indeed malicious. Apple removed the app within days of receiving it.

Why DefiLlama waited to ship its own app

The impersonation problem was not isolated to one listing, and it delayed DefiLlama’s own mobile app launch. 0xngmi said the team held off releasing its official app until the most dangerous fake versions were cleared from the App Store. They wanted to prevent new users from downloading the wrong one during launch week.

DefiLlama’s official app went live afterward. Apple’s listing names DefiLlama as the developer and DEFILLAMA LIMITED as the provider, matching the entity behind defillama.com. Version 1.0 shipped June 5, with updates following through August 8. Google Play lists the same developer and links to the same site. Both stores’ descriptions are explicit that the app is for research, not custody. It does not hold funds or execute trades.

DefiLlama is not the first crypto brand this has happened to, and it will not be the last. Clones of Rabby Wallet and Curve Finance have surfaced on the App Store before. Researchers counted 26 fraudulent wallet apps targeting seed phrases as recently as April. Apple says it rejects hundreds of thousands of copycat submissions a year, showing how widespread app impersonation has become.

Apple has yet to explain the part of 0xngmi’s account that matters most: why a founder’s trademark complaints went nowhere for months, while a self-inflicted wallet drain removed the same listing in days.

SafePal Breach Exposed Shipping Data for Nearly 40,000 Buyers

TL;DR

  • At data breach at SafePal exposed order information for 39,798 customers, including names, contact details, shipping addresses and purchase records.
  • SafePal says it never stored wallet credentials in the affected system, but the exposed data could support targeted phishing and other security risks.
  • A dataset matching SafePal’s disclosed customer count and order window has been advertised for sale online, though its authenticity has not been independently confirmed.

SafePal disclosed on August 16 that unauthorized parties accessed order information for approximately 39,798 customers. The exposed records included names, email addresses, shipping addresses, phone numbers and purchase details.

SafePal’s hardware wallets ship blank. Customers generate their own seed phrase, private key and wallet password after delivery. That data never reaches SafePal’s systems, meaning it was never there for the breach, or the attacker, to reach. The data breach also did not involve payment-card numbers or government identification, according to the company.

The immediate concern after this incident is targeted phishing. A scammer who knows which wallet someone bought and where it was delivered can make a fake support message look more convincing.

An order-tracking flaw exposed customer details

SafePal traced the incident to an authorization flaw in a plug-in used for tracking orders. Under certain conditions, the flaw allowed an unauthorized person to view another customer’s order information.

The affected records relate to orders placed from March 2, 2025, through April 11, 2026. SafePal has not said when the unauthorized access began or how long it lasted.

SafePal’s incident FAQ says the company received its first report consistent with the problem in early May. It initially treated the report as an isolated case, then opened a broader investigation. The company began rebuilding its order-processing pipeline in July and says that work confirmed the cause.

Apart from the order-tracking flaw, SafePal also detected a separate glitch in its data-retention process. The company’s automated cleanup process stopped working correctly between September 2025 and April 2026. Though it is not directly related to the authorization flaw, it kept customer records longer than needed, increasing the number of affected users.

Why the SafePal data breach creates phishing risk

Anyone who owns cryptocurrency has reason to treat their delivery details as sensitive, not just hardware-wallet buyers. A shipping address tied to a crypto purchase can reveal a location where a specific person can be found, whether that’s their home, workplace or anywhere else they receive deliveries. Phishing remains the primary risk from this kind of exposure. But wrench attacks, physical robberies where someone is targeted and coerced into handing over their crypto, are becoming more common. A data leak like this one can carry consequences beyond phishing.

SafePal warned customers about fraudulent calls, emails, text messages and letters. For example, a scammer might pose as support staff, offering a fake refund or a bogus replacement device as a pretext to ask for a recovery phrase or private key.

So far, the company says it has identified and removed more than 30 fraudulent websites and phishing links connected with the activity. The company has not provided estimates on how many customers lost money, or how much of the stolen data has actually been misused.

Meanwhile, the stolen dataset appeared for sale on a cybercrime forum, according to the security research account DarkWebInformer. The listing cites the same order window and the same customer count SafePal disclosed. There is no independent confirmation that the data offered for sale is authentic.

When affected users need to move funds

SafePal emailed affected customers from security@safepal.com on August 16. Buyers can also check an order number and shipping country through the verification page on SafePal’s website.

The company says customers do not need to replace their hardware wallet or move their assets solely because their order information was included in the incident. But if they entered a seed phrase or private key somewhere after receiving a suspicious message, that wallet should be treated as compromised. SafePal recommends creating a new wallet through a trusted device or official application and moving any remaining assets to it right away.

Customers should not follow any links in unexpected messages, and should instead type SafePal’s address directly into a browser. Genuine SafePal support staff will never request a recovery phrase, private key or wallet password.

An independent review is still pending

SafePal says it fixed the authorization flaw and added more security controls. It also reduced the retention period for personal information in the relevant order-processing system to 90 days, subject to legal requirements.

The company also contacted its third-party logistics and fulfillment partners as part of the investigation. It found no evidence that the breach extended into their systems.

An independent review is underway, though SafePal did not name the security firm and did not publish any findings thus far.

There are still gaps to fill on when the data was accessed or how many unauthorized users were involved. SafePal must also evaluate any financial losses linked to phishing attempts stemming from the breach. The independent review and future incident updates should show whether the exposure remained limited to the records SafePal has identified.

- Advertisement -

FEATURED