BTC $84,196.50 +0.17%
ETH $2,679.84 -0.23%
BNB $775.24 +0.35%
XRP $1.53 +1.73%
SOL $116.58 +1.32%
TRX $0.3386 -1.36%
DOGE $0.0952 +0.94%
ADA $0.2489 +3.40%
BCH $333.90 -1.32%
LINK $13.43 +8.22%
HYPE $91.86 -1.13%
AAVE $145.50 +4.20%
SUI $1.01 +6.05%
XLM $0.2199 +8.30%
ZEC $1,543.88 +1.13%
AAPL $335.87 -0.10%
AMZN $250.93 +1.11%
GOOGL $343.28 +1.28%
MSFT $497.67 -0.13%
META $780.52 +6.16%
NVDA $225.39 +0.36%
TSLA $380.13 +0.59%
SNDK $1,787.24 +0.42%
INTC $129.66 +7.16%
SPCX $148.82 +0.26%
MU $1,090.33 +2.92%
AMD $641.29 +5.50%
BTC $84,196.50 +0.17%
ETH $2,679.84 -0.23%
BNB $775.24 +0.35%
XRP $1.53 +1.73%
SOL $116.58 +1.32%
TRX $0.3386 -1.36%
DOGE $0.0952 +0.94%
ADA $0.2489 +3.40%
BCH $333.90 -1.32%
LINK $13.43 +8.22%
HYPE $91.86 -1.13%
AAVE $145.50 +4.20%
SUI $1.01 +6.05%
XLM $0.2199 +8.30%
ZEC $1,543.88 +1.13%
AAPL $335.87 -0.10%
AMZN $250.93 +1.11%
GOOGL $343.28 +1.28%
MSFT $497.67 -0.13%
META $780.52 +6.16%
NVDA $225.39 +0.36%
TSLA $380.13 +0.59%
SNDK $1,787.24 +0.42%
INTC $129.66 +7.16%
SPCX $148.82 +0.26%
MU $1,090.33 +2.92%
AMD $641.29 +5.50%

idg

All
Article
Flash

U.S. SEC Chairman: Building a Bridge to Lasting Rules for Tokenized Stock On-Chain Trading

SEC Chairman Paul Atkins issued a statement regarding the committee's approval of the "innovation exemption." He pointed out that more than a week ago, Congress failed to advance the CLARITY Act, thus the SEC today took significant steps within its statutory authority to bring the U.S. capital markets into the digital age by promoting on-chain trading of specific tokenized stocks.The order grants two types of temporary, conditional exemptions under Section 36(a)(1) of the Securities Exchange Act: first, it exempts "Tokenized Securities Venues" (TSV) from the definition of "exchange" under the Securities Exchange Act; second, it exempts specific liquidity providers ("regulated companies") from the definition of "dealer." Atkins emphasized that the anti-fraud and anti-manipulation provisions of federal securities laws fully apply to all securities activities in these markets, without exception.The exemption comes with several investor protection conditions: TSV must be U.S. entities and comply with OFAC sanctions; access standards must be set for a licensing system, allowing only specific participants to trade; synthetic products cannot be used—tokenized NMS "national market system" stocks must be tokenized by the issuer of the underlying stock or its representative, or by a third party not affiliated with the issuer, and holders must enjoy the same rights as traditional securities (including dividends and voting rights); issuers have the right to oppose and prevent their securities from being traded on TSV.Atkins stated that the committee is not solidifying current technology as future standards but rather allowing the market to evolve, monitoring its development, and using this as a basis to establish a more flexible, future-oriented regulatory framework. This exemption is a temporary measure, and the committee is seeking public input on all aspects, emphasizing that this transitional arrangement must be followed by the establishment of permanent rules to ensure that on-chain markets maintain a viable path as capital markets evolve.

Slow Mist Reveals Details of the Allbridge Cross-Chain Bridge Attack: Forged CCTP Messages, Flash Loans, Insufficient Minting Result Verification

The Slow Mist security team disclosed that the cross-chain bridge project Allbridge was attacked on August 19, 2026, resulting in a loss of approximately $190,000. Notably, this attack was not executed instantly; the attacker had begun laying the groundwork nearly a month prior and bypassed the verification mechanism by forging cross-chain messages. According to Slow Mist's analysis, on July 26, the attacker directly called Circle's MessageTransmitterV2.sendMessage function on the Polygon chain, constructing a cross-chain message disguised as a CCTP style message, claiming that a transfer of 1 million USDC existed, but in reality, no USDC destruction operation took place. Subsequently, Circle generated a valid verification proof (attestation) for this complete message according to normal procedures.About 24 days later, on August 19, the attacker waited for the Base Router to receive a real CCTP deposit, increasing the balance to approximately 191,000 USDC, and initiated the attack just 6 seconds later. The attacker utilized the previously forged message and verification proof to call Allbridge's receiveCctpMessage function. Due to the project's lack of critical verification, the system mistakenly recognized the false cross-chain message as a real deposit and recorded a limit of 1 million USDC. The attacker then temporarily borrowed approximately 809,000 USDC through an Aave flash loan, matching the Router balance with the forged amount, and used the internal credit record to call the transfer function, ultimately transferring out approximately 999,000 USDC (after a 0.1% fee). After repaying the flash loan and fees, the attacker netted a profit of about $189,800. The root cause of this vulnerability lies in Allbridge's failure to verify the identities of the sender and receiver of the cross-chain message, as well as not confirming whether USDC was genuinely minted and whether the balance actually increased, instead directly trusting the amounts and message hash data constructed by the attacker. Slow Mist emphasizes that on-chain message verification does not equate to the actual arrival of real assets. Cross-chain protocols not only need to verify the authenticity of messages but must also ensure that the message source is trustworthy, that the receiver is Circle's official TokenMessengerV2, and that asset accounting can only proceed after confirming the actual minting of assets and changes in balance. This incident once again highlights the security risks of cross-chain bridges in the message verification and asset settlement processes.
app_icon
ChainCatcher Building the Web3 world with innovations.