Home Blog Page 11

OCC Clears World Liberty Trust Company’s National Trust Bank Charter

TL;DR

  • World Liberty Trust Company received preliminary conditional OCC approval to operate as a national trust bank but cannot begin operations until final requirements are met.
  • The proposed bank would handle USD1 issuance, reserve assets and institutional custody while excluding WLFI from its activities.
  • World Liberty Trust must meet capital, governance and examination requirements before the national trust bank can open.

On August 14, the US Office of the Comptroller of the Currency granted preliminary conditional approval to World Liberty Trust Company, National Association (WLTC). The decision moves World Liberty Trust closer to operating as a national trust bank focused on its USD1 stablecoin.

But before the bank can open, World Liberty Trust must meet the OCC’s pre-opening requirements and pass an examination. If it receives final approval, USD1 operations would move under one federally supervised entity.

What the proposed trust bank would do

World Liberty Trust plans to issue and redeem USD1 for institutional clients nationwide. It would also maintain the assets backing the stablecoin and provide custody for USD1 customers and other institutions. The bank could also convert stablecoins already held in custody there into USD1 for institutional clients.

BitGo has served as USD1’s exclusive issuer and custodian since the stablecoin’s March 2025 launch. Although the proposed bank intends to assume those roles, no timetable has been provided for the transfer.

Trust banks are generally distinct from conventional commercial banks. They cannot take ordinary deposits or make loans. World Liberty Trust’s permitted business would stay limited to trust activities and related services described in its approved plan.

What conditions come with the approval

The OCC attached operational and financial conditions to its decision. World Liberty Trust must maintain at least $20 million in capital and appoint a qualified internal audit manager. Before requesting a pre-opening examination, it must also apply for stock in a Federal Reserve Bank and establish the required policies, controls and governance systems.

Also, there’s a deadline attached to all of this. Organizers have 12 months to raise the required capital, while the bank must open within 18 months. The preliminary approval expires if they miss those deadlines, except in limited circumstances accepted by the OCC.

Even after opening, the bank stays exposed to rule changes. It must adjust, stop or divest activities if the GENIUS Act or its implementing regulations demand it. Significant changes to products, services or risk limits would require advance notice and a written non-objection from the OCC.

Where WLFI fits in

The proposed bank would focus on USD1, a dollar-backed stablecoin with more than $4 billion in circulation, according to World Liberty. The OCC decision says the bank will not issue, custody or trade WLFI, the governance token associated with World Liberty Financial.

The charter review also drew questions about ownership and political conflicts. The OCC received seven comments from four commenters. Some raised concerns about President Donald Trump’s family connections to the venture and investments linked to the United Arab Emirates.

The regulator said World Liberty Financial and its outside investors are not parties to the bank application. It obtained passivity commitments from several indirect investors, restricting them from controlling or influencing the proposed bank.

Democratic lawmakers have continued to question whether a Trump-appointed regulator should approve a charter connected to the president’s family. The OCC said career staff reviewed the application under established procedures, while nonpolitical examiners would supervise the bank.

In response, Senator Elizabeth Warren and a group of Senate Democrats, including Angela Alsobrooks and Ruben Gallego, said they would introduce the Ending Presidential Corruption in Banking Act, which would bar senior government officials from owning or controlling a bank.

What comes next

World Liberty called the decision a milestone in a multi-step process. Its proposed five-member board includes co-founder Zach Witkoff as chair. One other director, Robert Witkoff, shares family ties with the chair, while a second, Scott Alper, is a senior executive at the Witkoff Group’s real estate business. Two directors are independent.

World Liberty Financial is 38% owned by an entity affiliated with President Trump and his family, though day-to-day leadership of the proposed bank sits with the Witkoffs, longtime Trump family associates and business partners.

World Liberty is one of at least ten stablecoin and digital-asset firms to win conditional OCC approval since December 2025, including Circle, Ripple, Paxos, Coinbase, Crypto.com, and Sony Bank. Morgan Stanley and Zerohash have applications still pending. Every approved charter, including World Liberty’s, carries the same condition: the OCC can modify, suspend, or rescind it at any point before the bank opens.

Binance Restricts Transactions With 16 Crypto Platforms Tied to Sanctions

TL;DR

  • Binance transaction restrictions cover 16 crypto platforms across three August cutoff dates tied to US and EU sanctions measures.
  • Transactions involving listed platforms may be held for compliance review, while connected wallets may face temporary restrictions.
  • HTX disputes the scope of the measures, but Binance says its August 23 restriction will proceed as scheduled.

Binance announced on August 14 that it will restrict transactions involving 16 named crypto platforms, staggering the rollout across three effective dates this month. The exchange says it may hold transactions tied to those platforms for compliance review, and may temporarily restrict associated user wallets during that review. The practical risk falls on users who send funds to, or receive funds from, a listed platform.

Which platforms are covered

The restrictions apply in three groups.

Effective August 7: Shelbit and Aban Tether Exchange.

Effective August 13: A7 Nigeria, A7 Africa and PilotFinance Ltd.

Effective August 23: Rapira, Aifory Pro, ABCeX, WhiteBird, NoOnecrypto, Tradex, Monease, BitPapa, Exnode/Exnode Pay, HTX and EXMO Ltd.

HTX, formerly known as Huobi, is one of the larger global exchanges by trading volume. Its inclusion marks a step up from the earlier groups, which consist mostly of smaller regional platforms.

What triggered the restrictions?

The US Treasury’s Office of Foreign Assets Control designated Shelbit and Aban Tether Exchange on August 7 over their alleged role in Iran-linked sanctions evasion.

The remaining 14 platforms all correspond to the European Union’s 21st sanctions package against Russia, adopted July 23. That package introduced a new legal tool: a transaction ban that restricts the EU side of a transaction, not the platform itself. The mechanism bars EU entities from transacting with a named platform regardless of where that platform is incorporated or who it serves. All 14 platforms operate outside the EU and UK, since the mechanism only applies to platforms outside the bloc.

The August 13 and August 23 groups are connected. The EU’s stated basis for sanctioning HTX includes its claimed role providing financial services to the A7 network, the same network tied to A7 Nigeria and A7 Africa. The two groups are one EU sanctions package reaching Binance’s users in two stages, ten days apart.

What happens when a transaction is flagged?

Binance says it may hold and review transactions attempted with a listed platform after its cutoff date. It may also restrict wallets connected to those transactions while the review is underway. Such restrictions may include wallets that never directly transacted with a named platform but received funds that passed through one.

Binance has not published a standard review period or a detailed appeal process. Neither has it explained how it identifies indirect exposure through multiple wallet hops. Users with past or planned transfers connected to any of the 16 platforms should expect the possibility of a hold, with no published timeline for resolving it.

How has HTX responded?

Justin Sun, a major stakeholder in HTX, responded to the restrictions on X. He wrote that the matter concerns only Binance’s UK and EU users, that HTX does “not conduct business in the UK or EU,” and that settlement negotiations with regulators in both jurisdictions are already underway.

Binance has not corroborated the claim. It addressed its announcement to all users, without a jurisdictional carve-out stating that the restriction affects only UK or EU accounts. Sun’s statement also does not engage with why the EU named HTX. Every platform in the EU’s 21st sanctions package operates outside the EU and UK, by definition of the third-country mechanism. The sanctions tool covers only platforms outside those jurisdictions; that is a condition of the mechanism, not evidence against HTX.

The “distinct entity” defense already failed once

The UK designated Huobi Global S.A. in May, and HTX responded then by arguing the sanctioned entity is separate from the exchange people actually use. The UK’s Office of Financial Sanctions Implementation rejected that distinction directly. It considers the HTX exchange subject to UK sanctions because of its ownership by Huobi. The EU has not yet said whether it reaches the same conclusion, but the UK precedent works against HTX’s position, not for it.

Source: www.gov.uk UK Financial Sanctions FAQs

The settlement talks are a different case

The UK’s Financial Conduct Authority sued HTX in October 2025 over illegal marketing to UK consumers. The case is unrelated to the sanctions designation. A London court paused that case until late August to allow settlement talks. But any deal reached would resolve the advertising dispute only. It would not lift the sanctions. No outlet has reported settlement talks over the sanctions matter itself, in the UK or the EU.

What HTX has done since the sanctions

Blockchain analysts tracking the exchange found it began generating hundreds of new central wallet addresses in the weeks after the UK designation. Researchers say comparable exchanges do not show such a pattern and that this activity makes HTX’s fund flows harder to trace. The company has also not disclosed its current headquarter after shutting down its previous base in Seychelles. Against that backdrop, a platform that chooses to cut ties with HTX rather than untangle its ownership looks less like caution and more like the only workable option.

Whatever happens between HTX and regulators, Binance’s August 23 restriction goes into effect on schedule. The exchange is not a party to that dispute. It is applying someone else’s sanctions list to its own users’ wallets. The HTX case shows how little room that leaves for a platform to contest the designation from inside its own system.

Tether’s First Full Financial Audit Receives Unqualified KPMG Opinion

TL;DR

  • Tether’s first financial audit received an unqualified KPMG opinion on the issuer’s 2025 financial statements.
  • KPMG examined the full accounts and supporting evidence, including Tether’s gold holdings, instead of checking only one reserve-date snapshot.
  • The signed opinion and complete audited statements are not publicly linked, while newer 2026 reserve figures remain attestation-based.

Tether said on August 13 that KPMG U.S. completed the company’s first full financial audit. The accounting firm issued an unqualified opinion on Tether International’s financial statements for the year ended December 31, 2025.

With the audit Tether moves beyond the quarterly reserve attestations it has published for years. KPMG examined company-wide financial statements and the evidence behind them, not only a snapshot of assets backing USDT, Tether’s dollar-pegged stablecoin, on one reporting date.

A KPMG spokesperson confirmed the unqualified opinion to The Block. Tether did not link the signed audit opinion or complete financial statements in its announcement.

What does the audit check that attestations don’t?

Tether’s quarterly attestations check specific information reported at a particular date. For example, they focus on whether the value and composition of disclosed reserves match the company’s figures at that point.

A financial-statement audit covers more ground. The financial audit included Tether’s balance sheet, income statement, changes in equity and cash flows for 2025. According to Tether, KPMG tested transactions, systems, ownership records, valuations, counterparties and supporting evidence.

Tether also said the auditors physically inspected and counted every gold bar it held. It checked the bars’ existence and identifying information instead of relying only on custodian reports.

KPMG’s unqualified opinion means it concluded that the financial statements fairly presented Tether International’s position in all material respects under U.S. accounting rules. It does not mean every figure is exact to the last dollar. Nor does it eliminate liquidity, market, operational or counterparty risk. A qualified opinion, by contrast, would flag one specific unverified item while still endorsing the rest of the statements; KPMG issued no such carve-out here.

Does the audit reflect Tether’s current reserves?

The audited statements showed reserves exceeding token liabilities by $6.814 billion at the end of 2025, Tether said.

The company has since published a more recent snapshot: a separate BDO attestation for June 30, 2026 shows a $4.11 billion reserve buffer. USDT’s market value has grown beyond $180 billion in the same period. The audit speaks to how Tether’s 2025 books were built, not to what backs the tokens circulating today.

Attestations alone could not settle a question that has hung over Tether since 2021: whether its statements about USDT’s backing could be trusted. That October, the Commodity Futures Trading Commission found the company had made untrue or misleading statements about the token’s dollar backing and fined it $41 million, the kind of finding a quarterly snapshot could not address. Tether CEO Paolo Ardoino said the completed audit proved critics wrong who claimed “the company refused to subject itself to the most rigorous scrutiny.”

Why haven’t the full documents been released?

Tether’s announcement summarizes the audit scope and result. However, the page does not include the signed KPMG opinion, the complete statements or their accompanying notes. Tether is privately held and not registered with the U.S. Securities and Exchange Commission (SEC), so it faces no legal requirement to publish full audited financials. Circle, the SEC-registered issuer of USDC, faces that requirement: it files annual audited statements in its 10-K, the annual report public companies must submit, which becomes publicly searchable through the SEC’s EDGAR database.

The Block reported that KPMG confirmed issuing the opinion but declined further comment because of client confidentiality. CoinDesk separately asked Tether whether it would share KPMG’s findings and had not received an answer when its report was updated.

The missing documents limit what outsiders can assess for themselves. Full statements would show detailed line items, accounting policies and explanatory notes. They could also clarify how Tether accounts for reserve assets, token liabilities, affiliated holdings and valuation methods.

Their absence does not reverse KPMG’s confirmation that it issued an unqualified opinion.

Will Tether repeat the audit next year?

Tether had promised a full audit for years before formally hiring a Big Four firm, one of the four dominant global accounting firms, in March. Completing the engagement answers one longstanding question: a major accounting firm has now signed an unqualified opinion on Tether International’s annual statements.

But the next questions concern access and repeatability. Tether has not said when it will publish the full 2025 documents or whether future annual audits will follow a fixed schedule.

For USDT users, the Tether financial audit adds stronger independent scrutiny than the issuer’s previous reporting.

Trezor Data Breach Exposes 13,689 Customers

TL;DR

  • A data breach exposed personal information belonging to 13,689 Trezor customers through shipping provider ShipMonk.
  • Home addresses and phone numbers were exposed for 11,742 customers, while another 1,947 had partial records involved.
  • Trezor says wallets and private keys were not compromised, but the leaked information could support more targeted phishing attempts.

A data breach at Trezor’s shipping provider ShipMonk exposed personal information belonging to 13,689 hardware-wallet customers. The records included home addresses and phone numbers for 11,742 of them, creating a risk of targeted phishing and other scams.

Trezor disclosed the incident on August 13, three days after ShipMonk reported unauthorized access, and says its devices, private keys and internal systems were not compromised. So far, the company has not linked any crypto theft or scam to the exposed data.

What the ShipMonk breach exposed

The larger group of 11,742 customers had their names, email addresses, phone numbers and shipping addresses exposed. Another 1,947 customers had names, cities and email addresses involved.

The main affected group received Trezor orders between May 10 and August 8, 2026. The affected customers live in the US, UK, Sweden, Colombia, Brazil, Italy and Portugal.

Trezor says it is still verifying with ShipMonk how some orders older than 90 days ended up in the partial-exposure group. Customers who bought through Amazon were not affected because another provider handled those deliveries, Trezor told CoinDesk.

Trezor says it emailed every affected customer from its official support address. According to the company, people who did not receive that notification were not included in the breach.

How the breach affects wallet security

Hardware wallets keep the private keys needed to authorize crypto transactions off any internet-connected computer. The customer data ShipMonk handled for order fulfilment never touched the devices at all. The leaked records cannot unlock a wallet, but they can help a criminal identify someone as a likely crypto owner and craft a message tailored to that person.

Trezor warned that affected customers may receive fraudulent emails, phone calls or letters. For example, a scammer could impersonate Trezor, a bank or a crypto exchange and ask for a wallet backup or other sensitive information.

The company says users should never enter a wallet backup on a website or share it with anyone. It recommends checking unexpected messages against notices on Trezor’s blog and official social accounts.

A software flaw may explain the access

Trezor has not published a full technical account of the ShipMonk breach. However, BleepingComputer reported that ShipMonk attributed the exposure to a vulnerability in Metabase, an analytics platform used to work with company data.

Metabase disclosed the previously unknown flaw on August 6, saying an attacker could gain administrator access, read information available through connected databases and export data. The company patched its cloud service and told self-hosted users to update immediately.

ShipMonk said the software vendor had patched the vulnerability and invalidated active sessions, according to customer notices reviewed by BleepingComputer. ShipMonk began an external technical investigation.

Several details remain unconfirmed. Neither Trezor nor ShipMonk has said when the unauthorized access began or how long it lasted.

What happens next

Trezor says it has no confirmed evidence that anyone published, sold or used the records in an attack. Still, contact details can remain useful to scammers long after a breach.

An Anonymous Delivery option is planned for the European Union in September and the US by the end of 2026, offering locker pickup, neutral packaging and automatic deletion of shipping identifiers after delivery.

The company says its 90-day retention policy limited the exposure because fulfilment providers must delete or anonymize older order data. That safeguard reduced the available records, but it did not protect customers whose details were still needed for recent deliveries and returns. The most concrete unresolved question is how some of the 1,947 partial records came to include orders outside that window. Trezor says it is working with ShipMonk to confirm the exact timeframe and will update its public FAQ once that is settled.

Harmony ONE Exploit Sends Billions to Exchanges as Rollback Looms

TL;DR

  • The Harmony ONE exploit reportedly created roughly 4 billion unauthorized tokens, with about 97% ultimately reaching exchanges.
  • Harmony patched two cross-shard receipt flaws and paused its bridge, but it has not published a postmortem explaining exactly how the exploit occurred.
  • A blockchain rollback could remove unauthorized tokens while also reversing valid trades, DeFi activity and other transactions.

Harmony, a layer-1 blockchain network, released an emergency validator patch on August 12 after an exploit let an attacker create units of its native token, ONE, without authorization. The project also paused its bridge, the system that lets assets move between Harmony and other blockchains, and asked exchanges to freeze funds linked to four wallets. At the same time, Harmony said it was considering a blockchain rollback.

Onchain researcher Juiceberg — an analyst who studies blockchain transaction data directly rather than relying on official disclosures — estimated that the attacker minted roughly 4 billion ONE and that nearly all of it, about 97%, ultimately reached exchanges, either sold or sitting in deposit wallets, leaving roughly 115 million ONE still unsold on the blockchain itself. Harmony has confirmed the exploit, but it has not confirmed either figure or said how much exchanges have frozen. Juiceberg also noted that Harmony’s totalSupply endpoint did not reflect the new tokens, which may have delayed outside detection.

The reported unauthorized mint would equal more than one-quarter of the roughly 15 billion ONE that existed before the incident. ONE fell about 40% during the initial market reaction, according to CoinDesk. Yet holders face excess tokens in circulation. They also face the possibility that a rollback could reverse valid transactions. 

The patch closes two receipt flaws

Harmony’s emergency release, version 2026.1.1, changes how the network verifies cross-shard receipts — the records used when a transaction moves value from one part of the blockchain to another. Harmony splits its network into several parallel sections called shards, and when a transaction moves between them, a receipt confirms the transfer happened correctly so the receiving shard can credit the right account. Validators, the computers that check and approve activity on the network, are responsible for confirming these receipts are valid.

The first flaw was in how the network checked whether enough validators had actually approved a receipt. Instead of confirming which validators had signed off, the check only compared the total size of the group against a required minimum. That meant a receipt carrying no real approvals, marked with an essentially blank signature, could still pass as valid. This affected an older part of Harmony’s validator system, dating from before the network introduced staking.

The second flaw was in how the network tracked whether a receipt had already been used, again in an older part of the system. That tracking relied on information that was not properly checked against the network’s official record of events. That gap meant a receipt that had already been processed could be resubmitted with small changes and made to look new, allowing the receiving account to be credited a second time without a matching debit elsewhere.

The Harmony patch addresses two cross-shard receipt flaws that offered possible routes for unauthorized creation. However, the project has not published a postmortem. It also has not said whether the attacker used one flaw, both flaws or another combination of steps.

Most reported tokens reached exchanges

The Harmony ONE exploit became harder to contain after the newly created tokens moved to centralized exchanges. Juiceberg’s initial estimate put 2.8 billion ONE in exchange deposit wallets. In a follow-up post roughly three hours later, the researcher raised that figure to about 97% of the minted total, either sold or sitting in deposit wallets, with roughly 115 million ONE left available to sell onchain.

Those numbers remain third-party estimates. Harmony has not named the exchanges involved or disclosed how many tokens they froze. It has also not separated amounts already sold from balances still held in deposit accounts.

At ONE’s price during the exploit, near $0.0008, the 4 billion newly created tokens carried a nominal value of roughly $3.2 million. But this figure understates the real impact. Unauthorized issuance dilutes existing holders and adds selling pressure to the market.

Source: CoinMarketCap

A rollback could reverse valid transactions

Harmony said it was evaluating rollback options, but it has not approved one or selected a cutoff block. A rollback would ask validators to accept an earlier version of the ledger and continue the chain from that point.

That could remove unauthorized ONE still recorded on Harmony. It could also erase legitimate transfers completed after the chosen cutoff, including trades, DeFi (decentralized finance) activity and bridge transactions. Tokens in an exchange’s internal system would require coordination with that venue. They would not automatically disappear if Harmony changed its ledger.

The decision therefore extends beyond correcting the ONE token supply. Wallet providers, exchanges and applications would need to agree on which chain history they recognize. Harmony has not explained how it would handle users if a rollback erased valid transactions.

The supply count remains unresolved

Harmony has published a technical fix, but not an account of what actually took place. The project has paused bridge.harmony.one without identifying it as the exploited component, and it has not said when the bridge will reopen or how it will handle transactions affected by the pause. The exploit is Harmony’s third major security incident since 2022, following a Horizon Bridge breach that cost about $100 million and a 2023 bug that improperly minted about 146.3 million ONE.

- Advertisement -

FEATURED