Home Blog Page 4

Hackers Demand $3 Million From Revolut or Threaten to Sell Data

TL;DR

  • A group calling itself IAmNotAVillain has issued a $3 million Revolut ransom demand payable in 6,000 XMR.
  • The group threatens to sell stolen customer data, while Revolut says none of the competing claimants has contacted it directly.
  • Around 680 customers were targeted after fraudulent requests from a legitimate government-agency email domain led Revolut to disclose sensitive data.

A group calling itself “IAmNotAVillain” is demanding $3 million ransom from Revolut, payable in Monero. It says it will sell stolen customer data if the company does not pay. The threat adds extortion to a breach that started with a forged government request.

What happened

Revolut disclosed last week that fraudulent requests from a legitimate government-agency email domain led it to hand sensitive customer data to an unauthorized party. The company confirmed the breach on September 12.

The ransom demand

IAmNotAVillain published the ransom demand to Revolut on its website Wednesday afternoon, alongside a running countdown clock. The message set a 24-hour deadline for 6,000 XMR, roughly $3 million, or the data would be sold.

The group chose Monero over Bitcoin deliberately. Monero transactions are harder to trace than Bitcoin, the currency an earlier, competing claimant had demanded.

The group sent the Financial Times a one-minute recording of someone scrolling through what it called Revolut customer files.

Which government agency?

Revolut never named the government agency whose domain the fraudulent requests used. Italian reporting has since filled that gap independently: multiple outlets identified the account as belonging to the Prefecture of Reggio Calabria, tied to Italy’s Interior Ministry.

Prosecutors in Reggio Calabria opened an investigation into unauthorized access to a government computer system. Italy’s National Anti-Mafia and Anti-Terrorism Directorate joined the probe, since the case involves a government entity. Investigators are trying to determine whether someone breached the institutional email account or cloned it. Revolut has continued to decline naming the agency, citing the active investigation.

IAmNotAVillain separately claimed to hold 147 GB of material pulled from Italian law-enforcement systems, gathered over a six-month operation. The cache reportedly includes internal documents and personal files such as calendars. Italian authorities have not confirmed a breach of police systems. The claim describes a target far larger than the Revolut customer data itself.

How the group chose its targets

The group told the Financial Times it identified its roughly 680 targets through on-chain analysis, cross-referencing blockchain activity with Revolut accounts to find customers holding substantial crypto balances. It called them “crypto whales.”

Switzerland and France account for most of the affected accounts. The remainder spread across 31 other countries. National figures reported separately put the count at 12 in Ireland, 25 in Spain, and 27 in Romania.

The method gives an attacker-side account to an earlier claim from security researcher ZachXBT. He said the operation looked aimed at high-net-worth users, not a mass dump of Revolut’s customer base.

Whoever is behind this

Multiple identities have claimed responsibility for the breach, and they contradict each other. A group calling itself “Revolut Smilik” previously demanded 10,000 Bitcoin, worth roughly $780 million at the time. IAmNotAVillain publicly disputed the claim, alleging a former associate leaked a small sample before claiming credit for the breach. The group warned others not to deal with the rival.

A third site, revoloot.lol, surfaced separately with its own claim of responsibility, according to Dark Web Informer. IAmNotAVillain’s own site went offline around the time Cointelegraph checked it for comment.

Revolut maintains none of the claimants has made direct contact, a position the company has repeated with each new demand.

Regulatory fallout

Britain’s Information Commissioner’s Office confirmed it received a report on the incident and is assessing the information provided. The Financial Conduct Authority is engaging with Revolut separately.

Italy’s data protection authority ordered banks nationwide to review their data-access systems and report any vulnerabilities. The regulator also contacted its Lithuanian counterpart, since Revolut’s registered office sits in Lithuania.

French Court Rejects Emergency Challenge to DAC8 Crypto Reporting

TL;DR

  • France’s Conseil d’État rejected an emergency request to suspend DAC8 crypto reporting requirements.
  • The court found that Paymium and the other applicants had not demonstrated sufficient urgency to justify suspending the decree.
  • The ruling keeps the reporting framework in place but does not decide whether the French decree is ultimately lawful.

France’s highest administrative court has rejected an emergency attempt to suspend the country’s crypto reporting requirements under the European Union’s DAC8 framework. The September 14 decision keeps those rules in place. A broader legal challenge is still pending.

French exchange Paymium brought the case alongside Leonod and Satoshi Portal Inc., companies associated with Bitcoin services provider Bull Bitcoin. They challenged a December 2025 decree requiring crypto service providers to collect and report information about users and transactions to French tax authorities.

Court finds no grounds for emergency suspension

The companies filed their emergency request on August 26, seeking suspension of Decree No. 2025-1276 while their challenge proceeds. Under French administrative law, an interim suspension requires two things. Applicants must demonstrate urgency, and they must raise an argument capable of creating serious doubt about the legality of the disputed measure.

The Conseil d’État found that the companies had not met the urgency requirement.

According to the decision, the applicants argued that requiring crypto companies to collect, process, verify and retain personal information interferes with users’ privacy and data-protection rights. They also challenged the requirement to transmit relevant information to the tax administration.

The court weighed those concerns against the public interest attached to preventing tax fraud and tax evasion. The alleged privacy impact was not sufficient, the court concluded, to establish the immediate urgency needed to suspend the decree before the main case is decided.

Data security becomes central to the challenge

Data security was another part of the companies’ case. The applicants argued that the reporting system could increase the risk that sensitive information about crypto users and transactions is compromised.

The court found that the companies had not demonstrated how the storage arrangements they described would increase that risk. The possibility of a data breach, where the probability was very low, was insufficient on its own to establish urgency, the court added.

The companies pointed to the breadth of the reporting requirement itself. DAC8 expands the EU’s system of administrative cooperation on taxation to crypto assets, requiring covered service providers in France to conduct due diligence and report specified information.

France’s crypto reporting decree remains active

France implemented the relevant requirements through legislation and Decree No. 2025-1276. The decree entered into force on January 1, 2026 and applies to transactions conducted from that date, with declarations covering those transactions beginning in 2027. The information covered can include identifying details such as a reportable person’s name, address, tax residence and tax identification number, alongside information about reportable crypto transactions.

France’s tax administration has published technical information for providers preparing to transfer information under the CARF/DAC8 reporting system. The guidance points providers to provisions of the French General Tax Code and the December 2025 decree governing the obligations.

Providers must now proceed under that framework. The decree sets June 15, 2027 as the deadline for the first declarations, covering transactions carried out in 2026.

Court did not decide whether DAC8 implementation is lawful

Paymium and the other applicants raised several arguments questioning the legality of the French decree. They alleged that the decree violates EU privacy protections and that regulators skipped a required consultation with France’s data-protection authority, CNIL. They also disputed the scope of the reporting requirements as applied to certain crypto services.

The Conseil d’État did not resolve those arguments. The court rejected the emergency request once it determined that the applicants had failed to demonstrate urgency. It did not examine whether their legal arguments were capable of creating serious doubt about the decree’s validity.

The September ruling is not a final judicial endorsement of the French rules.

The broader proceedings will determine whether the privacy, data-protection and EU-law arguments behind the challenge hold up.

Senate Vote Stalls CLARITY Act After 49–50 Defeat

TL;DR

  • The Senate failed to clear the 60-vote cloture threshold needed to move toward formal consideration of the CLARITY Act.
  • The bill is not dead, but supporters must build a broader coalition before seeking another vote.
  • With Congress yet to act, SEC and CFTC rule making is taking on greater near-term importance for US crypto markets.

The US Senate failed to advance the CLARITY Act on September 15. The crypto market-structure bill faltered before debate could formally begin. Senators voted 49–50 on cloture for the motion to proceed, well short of the 60 votes required to move the legislation forward.

The defeat sharply reduced the chance that Congress will pass the legislation in 2026. Existing rule making by the Securities and Exchange Commission (SEC) and Commodity Futures Trading Commission (CFTC) will now carry more weight in the near term.

Senators rejected the next procedural step

The Senate vote on the CLARITY Act took place at 2:19 p.m. Washington time. Without 60 votes, the Senate could not proceed to formal consideration of H.R. 3633.

All voting Democrats opposed the motion, joined by Susan Collins (R-Maine), Josh Hawley (R-Missouri), and Jerry Moran (R-Kansas). Also Republican Senator Thom Tillis voted no, albeit in a procedural move that preserves an option to seek reconsideration.

A motion to proceed opens debate on whether the Senate should take up a bill at all. Debate on that motion can continue without limit unless senators invoke cloture, which requires 60 votes and caps further debate. Tuesday’s vote tested cloture on the motion to proceed to H.R. 3633. Falling short left the debate over taking up the bill unresolved. A future cloture vote could still close that debate. Clearing it would open the way to a vote on the motion to proceed, then formal floor consideration.

The bill is not permanently dead, but reconsideration would still require supporters to assemble a broader coalition. The Senate is also due to leave Washington for much of October before the midterm elections, narrowing the available calendar.

The bill would divide oversight between two agencies

The CLARITY Act aims to create a federal framework for crypto markets. Its central task is to divide oversight of tokens and trading activity between the SEC and CFTC. It would also give the CFTC greater authority over spot markets for qualifying crypto assets.

Supporters argue that a federal law would give companies and investors clearer, more durable rules. The House passed an earlier version in July 2025, but Senate negotiations produced disputes over ethics, enforcement and stablecoin rewards.

Those disputes remained unresolved before Tuesday’s vote. Democrats sought stronger restrictions on crypto interests held by a sitting president and family members. Banks and crypto companies also disagreed over when platforms may offer customers rewards connected to stablecoins.

Agency rulemaking returns to the foreground

The SEC and CFTC have been coordinating on crypto rule making since September 2025, when the two agencies’ staff jointly cleared the way for exchanges to trade certain spot crypto products. The agencies signed a formal memorandum of understanding in March 2026 and issued a joint interpretation classifying crypto assets under federal securities law days later.

In August, the SEC built on that interpretation with a proposed rule creating new registration exemptions for crypto asset offerings. Around the same time, White House crypto adviser Patrick Witt said federal regulators would step in if Congress failed to pass the CLARITY Act. CFTC Chairman Michael Selig said his agency was prepared to move quickly on its own rules for crypto asset markets if the bill did not advance.

That coordination continues now that the CLARITY Act has stalled. Both agencies are acting under their current statutory authority. That authority can shift with a change in interpretation, and future administrations can revisit agency rules more easily than a statute passed by Congress.

Agency rule making lacks the legal certainty a new statute would provide. Any new rule could face court challenges. Until Congress revives the CLARITY Act or passes another measure, agency rule making remains the industry’s main path forward, even though it falls short of the speed and certainty many in the industry want. The European Union’s MiCA framework has been in full effect since July 2026, and the European Commission is already reviewing it for possible updates, a level of statutory clarity the United States does not yet have.

Crypto shares fell, but the vote was not the only pressure

Meanwhile, crypto-linked stocks dropped after the vote. Coinbase, Circle and Galaxy saw declines of more than 8% during Tuesday’s session. Bitcoin also fell about 3% over 24 hours and briefly approached $75,000.

US stocks were already under pressure before the Federal Reserve’s rate decision today. Investors were also reducing exposure to risk assets more broadly. Still, the timing suggests that investors treated the Senate’s failed vote to advance the CLARITY Act as a setback for regulatory clarity and overall market sentiment.

Tillis has entered a motion to reconsider, but Senate leaders have not scheduled another vote. The chamber has roughly 14 working days before it recesses ahead of the midterm elections.

CoinEx Shuts Down Trading as Customers Get Until December to Withdraw

TL;DR

  • CoinEx is shutting down after nine years, with trading services ending in stages before the exchange closes fully on December 22.
  • Customers can withdraw funds until December 22. Remaining USDT will then move to an independent custody arrangement with monthly fees.
  • The closure follows years of regulatory and security scrutiny and comes as trading activity increasingly concentrates on larger exchanges.

CoinEx announced on September 15, 2026 that it will shut down after nine years of operation. Founder and CEO Haipo Yang cited mounting security and compliance risks and said he turned down a sale in favor of what he called a clean ending. The Hong Kong-based exchange will wind down in stages through December 22, when withdrawals close for good.

The Shutdown Timeline

CoinEx set four cutoff dates for the wind-down. New account registrations and referral rewards ended immediately on September 15, and futures contracts moved into reduce-only mode, which blocks new or larger positions.

Margin trading, crypto loans, staking, and Earn products close on September 22. Most deposit addresses close the same day, apart from the exchange’s native CET token.

Spot trading stops on September 29 at 02:00 UTC, and CoinEx Smart Chain and OneSwap, the exchange’s blockchain and decentralized exchange, shut down the same day.

Withdrawals remain open until December 22 at 02:00 UTC+8, when CoinEx says the exchange formally closes.

What Happens to Customer Balances

CoinEx says its reserve ratio exceeds 100 percent, meaning it holds more in assets than it owes customers. CoinEx will buy back remaining CET balances at 0.005 USDT each, with no cap on the amount.

USDT left on the platform after December 22 moves into an independent custody arrangement, where a 5 percent monthly fee applies. The claims window on that arrangement closes August 22, 2028. CoinEx has not addressed what happens to balances still unclaimed once that window closes.

Why CoinEx Says It Is Closing

In his statement, Yang said CoinEx never became one of the industry’s largest exchanges, and pointed to compliance and security costs that have grown harder to manage. He said he considered selling the business, and decided against it. “A clean ending is the right ending,” he wrote.

CoinEx’s public notice pointed to a prolonged market downturn and shrinking industry-wide trading volume, and it said compliance costs had exceeded reasonable boundaries in major jurisdictions.

A Regulatory and Security Record

CoinEx has drawn regulatory and security scrutiny before this closure. In 2023, the New York Attorney General accused CoinEx of running an unregistered securities and commodities business. CoinEx settled for $1.7 million and agreed to leave the state.

The same year, a hot-wallet breach cost CoinEx roughly $54 million. On-chain investigators later tied the breach to North Korea’s Lazarus Group.

In June 2026, blockchain analytics firm TRM Labs published a report on CoinEx’s transaction history. It alleged the exchange processed $3.84 billion in transactions tied to sanctioned Iranian entities since 2019. Of that, $67 million traced to the Central Bank of Iran.

Funds from the Bybit hack, a $1.5 billion theft investigators tied to North Korea, passed through Iranian wallets connected to CoinEx, the Wall Street Journal reported. CoinEx disputed the characterization, saying on-chain transaction flows do not establish a platform’s knowledge of, or participation in, illicit activity.

Yang’s closure notice did not name the TRM Labs report or reference Iran. Three months separate the report from the closure, and the link remains circumstantial.

Part of a Wider Consolidation Among Exchanges

CoinEx’s closure follows two others announced in July 2026. BitMEX will close on September 23, after eleven years in business. The exchange pioneered the perpetual swap, a contract now standard across crypto trading. BitMart stopped trading on August 26, seven years after it launched, and plans to close fully on January 31, 2027.

Analysts tied both closures to a broader decline in retail spot trading volume, and liquidity has concentrated on the largest platforms. CoinEx’s own daily volume sat at roughly $70 million in mid-September, according to CoinGecko data. Competitors like Gate and CoinW each handle more than $1 billion.

Two pieces of the business survive the wind-down. The mining pool ViaBTC, under the same founders, keeps running on its own, and the exchange’s self-custody tools, CoinEx Wallet and Vault, stay active.

Mexico Expands Search After Puebla Crypto Mine Seizure Grows to Over 1,000 Machines

TL;DR

  • Mexican authorities seized 1,032 pieces of cryptomining equipment from a suspected illegal operation in Tlaola, Puebla.
  • Investigators suspect electricity theft at the crypto mine in Puebla, while its operators and financiers remain unidentified.
  • Authorities are searching for similar sites, and no connection between the operation and a specific cartel has been publicly established.

Mexican authorities have widened their search for illegal cryptocurrency mining sites after a raid near a hydroelectric system in Puebla grew from an initial seizure of roughly 300 machines to more than 1,000. The investigation centers on suspected electricity theft. The identity of the operation’s financiers remains unconfirmed.

A second search doubles the seized equipment

Federal and state authorities first entered a remote building in Tlaola, a municipality in Puebla’s Sierra Norte mountain region, on September 3. They disclosed the initial findings on September 6: about 300 graphics processing units, 80 medium-voltage terminals, one transformer and eight satellite antennas.

A second search of the same property on September 11 raised the total to 1,032 pieces of cryptomining equipment, according to the Mexican Navy. Officials described the update as a fuller inventory of the same site, not the discovery of a separate facility. No arrests followed either search.

The facility’s size and location have prompted scrutiny of possible organized-crime involvement. Investigators have not publicly identified its operators or established a connection to a specific cartel.

Power theft, not mining, is the alleged crime

Cryptocurrency mining is not prohibited in Mexico, but that’s also not what authorities are investigating. The alleged illegal conduct concerns the source of the electricity and the connection used to power the machines.

The site stood close to infrastructure linked to the Nuevo Necaxa hydroelectric system. Authorities are probing whether its operators drew electricity illegally from federal power infrastructure.

Mining equipment performs repeated calculations to create or validate units of a cryptocurrency. The process can consume large amounts of electricity, especially when hundreds of machines operate continuously and require cooling. Power is one of a mining operation’s largest expenses. Operators who avoid paying for it remove a major cost while shifting the financial burden and infrastructure risk elsewhere.

Authorities have not disclosed which cryptocurrency the machines were mining. Calling the facility a Bitcoin mine would go beyond the confirmed evidence; the equipment recovered so far consists of GPUs, hardware suited to coins other than Bitcoin.

Noise and electricity demand exposed the site

The Puebla crypto mine sat in a sparsely populated mountain area, but its power consumption and mechanical noise made it difficult to conceal. Two residents told Reuters they could hear the equipment from about one kilometer away. The building stood roughly twice that distance from the nearest village.

Francisco Sánchez González, Puebla’s public security chief, said mining facilities seek remote locations because they consume substantial electricity and produce considerable noise. Electricity consumption and noise led authorities to the property, which state police had already been monitoring for its proximity to the Nuevo Necaxa dam.

Cartel involvement remains unconfirmed

Officials suspect the facility’s technical scale points to organized financing. Investigators have filed no charges, and no wallet addresses have surfaced publicly connecting the site to any proceeds. Who purchased the equipment remains unknown. So does what the machines were mining and where the proceeds went.

Authorities are searching for similar operations

The discovery in Tlaola was not the first in the region. Authorities dismantled three other suspected illegal mining operations in Puebla and neighboring Tlaxcala in 2025, according to El País.

Officials are extending their inquiries to surrounding municipalities and coordinating with nearby states. The mine in Puebla shows how illicit crypto operations can create consequences outside cryptocurrency markets: stolen public electricity and industrial-scale infrastructure disrupting the communities nearby.

How many more sites the joint search turns up, and whether any match Tlaola’s scale, is the question authorities have yet to answer.

- Advertisement -

FEATURED