BTC $78,690.19 -0.59%
ETH $2,471.07 -2.28%
BNB $689.44 -1.96%
XRP $1.38 -2.39%
SOL $102.91 -3.50%
TRX $0.3330 -2.17%
DOGE $0.0830 -3.25%
ADA $0.1966 -3.90%
BCH $246.08 -2.92%
LINK $11.34 -2.97%
HYPE $83.28 -0.43%
AAVE $123.23 -3.49%
SUI $0.7235 -4.02%
XLM $0.1768 -2.37%
ZEC $841.52 -4.46%
BTC $78,690.19 -0.59%
ETH $2,471.07 -2.28%
BNB $689.44 -1.96%
XRP $1.38 -2.39%
SOL $102.91 -3.50%
TRX $0.3330 -2.17%
DOGE $0.0830 -3.25%
ADA $0.1966 -3.90%
BCH $246.08 -2.92%
LINK $11.34 -2.97%
HYPE $83.28 -0.43%
AAVE $123.23 -3.49%
SUI $0.7235 -4.02%
XLM $0.1768 -2.37%
ZEC $841.52 -4.46%

por

PoR (Proof of Reserves) is a verification mechanism used by cryptocurrency exchanges or financial institutions to prove the amount of asset reserves they hold. Through PoR, institutions can demonstrate the transparency and security of their assets to users and regulators, typically achieved through third-party audits or cryptographic proofs. The implementation of PoR helps to enhance user trust in the platform and prevent financial risks caused by insufficient assets.
All
Article
Flash

Gemini receives arbitration support: no liability for the collapse of the Earn lending program

According to CNBC, Gemini Space Station won a legal victory in August, with arbitrators ruling that the cryptocurrency exchange platform did not mislead users and is not responsible for the collapse of its Earn lending program. The claim was made by a user of the digital asset company's lending program Earn at the end of 2024. According to the ruling, there was insufficient evidence to prove that Gemini lied to customers or was negligent in its due diligence with its main lending partner, Genesis Global Capital.The Earn program was launched in 2021, allowing users to earn up to 7.4% annualized returns by lending cryptocurrency. Under this program, Gemini lent assets to institutional borrowers, with Genesis acting as an intermediary. However, in November 2022, Gemini suspended withdrawals from the Earn program, angering some of its more than 300,000 users. This move came shortly after Genesis suspended new loan issuance and redemptions due to a liquidity crisis caused by the downturn in the cryptocurrency market that year. After the freeze on Earn withdrawals, several customers filed legal complaints against Gemini. The New York Attorney General also sued Gemini over the Earn program and reached a $50 million settlement with the company in 2024.In February 2024, Gemini announced that the company had reached a "principled settlement" with Genesis and other creditors regarding the Genesis bankruptcy case. Three months later, Earn users received $2.18 billion in digital assets in physical form, equivalent to 97% of the digital assets owed to Earn users, which is $1 billion more than when Genesis suspended withdrawals in 2022.

The UK's first cryptocurrency tax report shows that 240 people declared £717 million in capital gains

The UK government has released the first official statistics on taxable crypto asset gains, revealing that in the 2024-25 tax year, 240 individuals reported capital gains exceeding £1 million, totaling £717 million, which accounts for more than half of the total £1.38 billion reported by 17,600 individuals. The HM Revenue and Customs (HMRC) stated that 17,600 individuals reported crypto asset disposal gains of £13.8 billion, with taxable gains of £1.38 billion, averaging about £78,000 per person; of these, approximately 87% were male and 13% were female.Selling, exchanging, consuming tokens, or gifting assets to others may trigger tax obligations. HMRC has sent out 81,000 crypto tax letters in the past 12 months, an increase of 25% from about 65,000 letters, approaching the 27,714 letters sent in the 2023-24 tax year. James Murray, the Financial Secretary to the Treasury and Director of Payments, stated that crypto asset gains are subject to tax just like other gains. The UK plans to adjust the tax treatment of certain DeFi transactions starting from April 6, 2027, with related lending and liquidity pool transactions typically deferring capital gains tax until an economic disposal occurs, expected to affect about 700,000 individuals. HMRC estimates that its crypto tax compliance and education activities have generated an additional £168 million in capital gains tax for the 2024-25 fiscal year.

SemiAnalysis releases Neocloud security deep report: Infrastructure configuration errors are shocking, and cross-tenant RCE could affect banks, telecommunications, and even a country's intelligence agency

The semiconductor and AI independent research organization SemiAnalysis released a deep security report on Neocloud (new cloud), revealing various cross-tenant security vulnerabilities discovered during the ClusterMAX 3 testing period. In a four-month test covering 25 vendors and 32 clusters, the team achieved multiple instances of cross-tenant remote code execution (RCE) solely by exploiting publicly known vulnerabilities and basic configuration checks. Affected entities included banks, telecommunications companies, universities, research institutions, AI laboratories, and even a national intelligence agency.Typical issues included: shared Kubernetes control plane leading to tenant metadata visibility, container escape, exposure of BMC/IPMI management networks, incorrect configuration of InfiniBand security keys (P_Key, SA_Key, M_Key), unfortified default trust mode of BlueField DPU, Grafana monitoring dashboards using god-level API keys, and lack of VXLAN isolation in front-end networks. The report specifically pointed out a cascading vulnerability case: a misconfiguration of shared vCluster combined with software versions being two years out of date ultimately completed the POC verification of cross-tenant RCE within an afternoon.Notably, the report questioned the mainstream narrative that "AI has fundamentally changed the pace of cybersecurity": statistics on CVEs for NVIDIA GPU drivers, CUDA, PyTorch, Kubernetes, Docker, and the Linux kernel showed that there was no significant increase in vulnerabilities after the popularization of AI coding models, with most data supporting the "no change hypothesis." The report also detailed the incident where an OpenAI-trained agent attacked Hugging Face, where the AI agent achieved cluster-level privilege escalation through a message board established via Artifactory, which went undetected from May to July. While building POC verification for existing vulnerabilities, the team found that Claude Fable and GPT-5.6 Sol frequently rejected security-related requests, ultimately relying on open-source models such as DeepSeek V4, Kimi K3, and GLM-5.2 to complete the task.SemiAnalysis stated that the core issue in the Neocloud (new cloud) industry is not the new risks brought by AI, but rather the long-term absence of basic patch management, tenant isolation, and security design. They recommended that vendors establish automated security announcement monitoring systems and rectify single points of failure that could expose all users' architectural patterns.
app_icon
ChainCatcher Building the Web3 world with innovations.