BTC $83,495.89 -1.22%
ETH $2,681.54 -0.16%
BNB $764.50 -1.64%
XRP $1.49 -1.99%
SOL $118.63 -3.24%
TRX $0.3358 +0.64%
DOGE $0.0937 -3.20%
ADA $0.2456 -3.56%
BCH $307.89 -7.73%
LINK $15.24 +8.74%
HYPE $87.78 -4.13%
AAVE $147.35 -4.47%
SUI $1.14 -8.24%
XLM $0.2283 +5.82%
ZEC $1,461.33 -8.77%
AAPL $338.53 -0.50%
AMZN $246.48 -1.46%
GOOGL $342.56 -0.42%
MSFT $509.99 -1.40%
META $715.99 -4.58%
NVDA $228.86 +1.57%
TSLA $357.89 -4.17%
SNDK $1,710.30 -4.16%
INTC $115.95 -7.77%
SPCX $145.84 -2.05%
MU $1,053.08 -3.87%
AMD $608.78 -3.97%
BTC $83,495.89 -1.22%
ETH $2,681.54 -0.16%
BNB $764.50 -1.64%
XRP $1.49 -1.99%
SOL $118.63 -3.24%
TRX $0.3358 +0.64%
DOGE $0.0937 -3.20%
ADA $0.2456 -3.56%
BCH $307.89 -7.73%
LINK $15.24 +8.74%
HYPE $87.78 -4.13%
AAVE $147.35 -4.47%
SUI $1.14 -8.24%
XLM $0.2283 +5.82%
ZEC $1,461.33 -8.77%
AAPL $338.53 -0.50%
AMZN $246.48 -1.46%
GOOGL $342.56 -0.42%
MSFT $509.99 -1.40%
META $715.99 -4.58%
NVDA $228.86 +1.57%
TSLA $357.89 -4.17%
SNDK $1,710.30 -4.16%
INTC $115.95 -7.77%
SPCX $145.84 -2.05%
MU $1,053.08 -3.87%
AMD $608.78 -3.97%

permissions

All
Article
Flash

first_img XRP Ledger restarts upgrade, allowing accounts to split payment and compliance permissions

The PermissionDelegationV1_1 upgrade of the XRP Ledger entered a 14-day activation countdown on September 21, having received support from 29 of the 35 trusted validator nodes. If the support rate remains above 80% during this period, the upgrade could officially activate as early as October 5 at 11:18 UTC; at least 28 validator nodes must continue to support it, or the countdown will reset.This feature allows accounts to split permissions by role. For example, a stablecoin issuer can allow a connected compliance system to approve customer accounts holding its tokens while keeping the keys with full control offline; operational accounts can gain payment permissions but cannot change keys or delegate authority to others. Each trustee can have up to 10 permissions, and the main account can modify or revoke them at any time.This is the network's second attempt to introduce this feature. The original version had vulnerabilities that attackers could exploit to make others pay transaction fees with improperly signed transactions, and by repeatedly submitting high-fee transactions, they could deplete the victim's XRP balance. This vulnerability was reported by community testers on September 15, 2025, and validator nodes were advised to reject the amendment, so it was never activated. The fixed version was released with xrpld 3.3.0, changing the way unauthorized transactions are rejected, ensuring that fees are not deducted before signature verification.

macOS malware can bypass Telegram's two-factor authentication to steal cryptocurrency wallets and account permissions

According to FinanceFeeds, security researchers have discovered an information-stealing malware targeting macOS devices that is attacking cryptocurrency users. This malware can hijack Telegram Desktop sessions, steal passwords and wallet databases, further controlling user accounts and stealing digital assets. Currently affected wallets and applications include software wallets like Exodus, Atomic, Electrum, Wasabi, and Monero.The malware is capable of extracting sensitive information from macOS Keychain, Safari Cookies, Apple Notes, Telegram Desktop, and multiple cryptocurrency wallet-related databases, including login credentials, authenticated session files, wallet data, and browser extension information. Security analysis points out that the danger of this attack chain lies in its reliance not on a single wallet vulnerability, but on collecting various types of data from the device, linking device intrusion, account takeover, wallet cracking, and mnemonic phrase theft together. Among these, Telegram Desktop sessions have become a key target.Attackers can copy authenticated Telegram local session data and restore the login on another Mac device without needing to enter a phone number, verification code, or Telegram two-factor authentication password. This means that Telegram 2FA cannot provide complete protection in this attack scenario, as the attacker is not performing a new login but is exploiting an already trusted local session. For cryptocurrency users, the risks are further amplified. Since Telegram is widely used for exchange customer service, project communities, OTC trading, and wallet communication, once attackers gain access to user session permissions, they could impersonate the victim, read private chats, locate asset information, and even spread malicious links to contacts.
app_icon
ChainCatcher Building the Web3 world with innovations.