Operator is a decentralized AI agent infrastructure where users can build and deploy agents that are truly their own and then make them available to the world.
According to Caixin, Cambodia has publicly disclosed the inner workings of the telecom fraud compound known as "Zone 8" for the first time. Dubbed a "scam city," it is Cambodia's largest fraud operation, capable of housing up to 20,000 individuals trafficked and forced to engage in online fraud. The site is operated by the Cambodian company Legend Innovation. Blockchain analytics firm Elliptic's investigation revealed that the operator is linked to Prince Group. Legend Innovation is alleged to maintain ties with the US- and UK-sanctioned Prince Group through corporate phone numbers, director activities, and related business records. Notably, the registered phone number used by Legend Innovation previously appeared in documents concerning a real estate company alleged to be part of Prince Group's network.
the United States, the European Union, and the United Kingdom have jointly announced sanctions against a group of individuals involved in state-sponsored hacking organizations, cybercriminal groups, and their infrastructure providers. The targets are accused of causing billions of dollars in losses to global enterprises, critical infrastructure, and government agencies. Among them, the most notable is the EU's sanction against Russian cybercriminal Vitaly Nikolayevich Kovalev, also known as "Stern." The EU identified Stern as one of the core managers of the notorious Trickbot Group ransomware syndicate, which is behind high-risk ransomware variants such as Conti ransomware and Ryuk.On-chain analysis shows that wallet addresses linked to Stern have collectively received over $300 million in ransom payments, potentially making him the most prolific ransomware operator ever identified.According to the analysis, the $300 million figure represents only Stern's personal gains, while the total illicit income of the Trickbot Group could be significantly higher. On-chain fund flows indicate that Stern had transactional ties with multiple ransomware ecosystems, including Ryuk, Conti, Diavol, Karakurt, Royal, and Quantum.The investigation reveals that Stern played a role similar to a "CEO" within the Trickbot organization, responsible for budget management, personnel recruitment, infrastructure procurement, and attack planning. (Chainalysis)
The French Financial Markets Authority (AMF) announced that, effective from June 30, 2026, it will revoke the Digital Asset Service Provider (PSAN) registration of AUTOMATA France SAS (operating Vancelian.com). The regulator noted that the company engaged in crowdfunding activities without obtaining the necessary authorization, reflecting that its management and significant shareholders failed to meet integrity and competence requirements.
According to Decrypt, Missouri Attorney General Catherine Hanaway has filed a lawsuit against Bitcoin ATM operator CoinFlip, accusing it of “knowingly facilitating fraudulent transactions” and seeking a $1.83 million fine as well as a ban on its operations in the state. CoinFlip responded that the lawsuit is “baseless” and urged authorities to instead investigate the actual criminals. Against this backdrop, U.S. states are intensifying regulatory crackdowns on Bitcoin ATMs—particularly targeting scams targeting elderly individuals. FBI data shows that related losses reached $389 million in 2025.
According to Cointelegraph, Missouri Attorney General Catherine Hanaway has filed a lawsuit against GPD Holdings—the parent company of cryptocurrency ATM operator CoinFlip—accusing it of “intentionally facilitating fraudulent transactions and profiting from them,” with victims including elderly residents and veterans in the state. The lawsuit stems from a targeted investigation launched by Missouri in December 2025 into multiple crypto ATM companies, which alleged “deceptive fee structures” and fraudulent conduct. The Attorney General’s Office is asking the court to rule that CoinFlip violated the Missouri Merchandising Practices Act, prohibit it from continuing operations in the state, impose a $1,000 fine for each violation over the past five years (capped at $1.826 million), and provide restitution to affected consumers. CoinFlip currently operates 136 crypto ATMs in Missouri and 4,229 nationwide. Notably, Bitcoin Depot—another major crypto ATM operator—filed for bankruptcy earlier this month, and regulatory pressure is intensifying across the entire industry.
Ethena founder Guy Young stated that USDe backing assets currently have no direct exposure to stETH or other liquid staking tokens, and he expects this incident will not impact Ethena.
Blockaid warns that users who previously authorized Payment Processor V2 as an NFT Operator should immediately revoke the relevant authorization. Simply canceling listings or Master Nonce cannot remove this permission.
According to Yonhap News Agency, the South Korean Financial Supervisory Service has sent an inspection opinion letter to Upbit's operating company, officially initiating the sanction procedure. Subsequently, the sanction content will be finally determined after going through procedures such as company explanation, the Sanction Deliberation Committee, the Securities and Futures Commission, and the Financial Services Commission. Yonhap News Agency stated that since the current "Virtual Asset User Protection Act" mainly targets user protection and unfair trading, it lacks direct and clear sanction provisions for hacking/system accidents, resulting in uncertainty regarding the severity of the sanctions.
the United States, the European Union, and the United Kingdom have jointly announced sanctions against a group of individuals involved in state-sponsored hacking organizations, cybercriminal groups, and their infrastructure providers. The targets are accused of causing billions of dollars in losses to global enterprises, critical infrastructure, and government agencies. Among them, the most notable is the EU's sanction against Russian cybercriminal Vitaly Nikolayevich Kovalev, also known as "Stern." The EU identified Stern as one of the core managers of the notorious Trickbot Group ransomware syndicate, which is behind high-risk ransomware variants such as Conti ransomware and Ryuk.On-chain analysis shows that wallet addresses linked to Stern have collectively received over $300 million in ransom payments, potentially making him the most prolific ransomware operator ever identified.According to the analysis, the $300 million figure represents only Stern's personal gains, while the total illicit income of the Trickbot Group could be significantly higher. On-chain fund flows indicate that Stern had transactional ties with multiple ransomware ecosystems, including Ryuk, Conti, Diavol, Karakurt, Royal, and Quantum.The investigation reveals that Stern played a role similar to a "CEO" within the Trickbot organization, responsible for budget management, personnel recruitment, infrastructure procurement, and attack planning. (Chainalysis)
Ethena founder Guy Young stated that USDe backing assets currently have no direct exposure to stETH or other liquid staking tokens, and he expects this incident will not impact Ethena.
Odaily News: The CFTC's Division of Market Oversight issued a staff advisory on September 22 stating that contracts tied to specific individuals' statements, appearances, or interactions are more susceptible to manipulation risks, requiring exchanges to explain protective measures on a contract-by-contract basis, including whether outcome determiners are bound by independent obligations, whether they may be subject to pressure, whether outcomes can be externally verified, and whether monitoring mechanisms are suited to the relevant risks.The document represents staff views and does not constitute binding rules, nor does it prohibit such markets. The CFTC also disclosed that a White House teleprompter operator once used early access to speech drafts to trade such contracts, earning $107,500; Kalshi subsequently still listed the relevant market and said it had responded to prior discussions with the CFTC.
Ethena founder Guy Young stated that USDe backing assets currently have no direct exposure to stETH or other liquid staking tokens, and he expects this incident will not impact Ethena.
Blockaid warns that users who previously authorized Payment Processor V2 as an NFT Operator should immediately revoke the relevant authorization. Simply canceling listings or Master Nonce cannot remove this permission.
Odaily News: The CFTC's Division of Market Oversight issued a staff advisory on September 22 stating that contracts tied to specific individuals' statements, appearances, or interactions are more susceptible to manipulation risks, requiring exchanges to explain protective measures on a contract-by-contract basis, including whether outcome determiners are bound by independent obligations, whether they may be subject to pressure, whether outcomes can be externally verified, and whether monitoring mechanisms are suited to the relevant risks.The document represents staff views and does not constitute binding rules, nor does it prohibit such markets. The CFTC also disclosed that a White House teleprompter operator once used early access to speech drafts to trade such contracts, earning $107,500; Kalshi subsequently still listed the relevant market and said it had responded to prior discussions with the CFTC.
According to Caixin, Cambodia has publicly disclosed the inner workings of the telecom fraud compound known as "Zone 8" for the first time. Dubbed a "scam city," it is Cambodia's largest fraud operation, capable of housing up to 20,000 individuals trafficked and forced to engage in online fraud. The site is operated by the Cambodian company Legend Innovation. Blockchain analytics firm Elliptic's investigation revealed that the operator is linked to Prince Group. Legend Innovation is alleged to maintain ties with the US- and UK-sanctioned Prince Group through corporate phone numbers, director activities, and related business records. Notably, the registered phone number used by Legend Innovation previously appeared in documents concerning a real estate company alleged to be part of Prince Group's network.
Coinbase disclosed that its global intelligence team assisted law enforcement agencies in dismantling the phishing-as-a-service platform EvilTokens. The platform leverages artificial intelligence to analyze victims’ email accounts and bypasses multi-factor authentication via Microsoft’s device code login mechanism to execute Business Email Compromise and fund transfer fraud.
According to Bloomberg, Singapore data center operator DayOne has confidentially filed an initial public offering (IPO) application with the U.S. Securities and Exchange Commission (SEC), planning to list in the U.S. as early as the next quarter of this year. The company plans to raise approximately $5 billion, with a listing valuation of around $20 billion. However, relevant details are still under discussion, and the offering size and timing may change.