Welcome to The Protocol, CoinDesk’s weekly wrap of crucial tales in cryptocurrency tech growth. I’m Margaux Nijkerk, a reporter at CoinDesk.
On this concern:
- SwissBorg’s SOL Earn Pockets Exploited for $41.5M After Accomplice’s API Is Compromised
- Ledger CTO Warns of NPM Provide-Chain Assault Hitting 1B+ Downloads
- Backpack Opens Regulated Perpetuals Trade in Europe After FTX EU Acquisition
- Polygon PoS Sees Transaction Finality Lag, Patch in Progress
Community Information
SWISSBORG’S SOL EARN WALLET EXPLOITED: Crypto alternate SwissBorg stated about 192,600 SOL ($41.5 million) was stolen from an exterior pockets used solely for its SOL Earn technique. The exploit stemmed from a accomplice’s compromised utility programming interface (API), a mechanism that permits software program techniques to speak with each other, affecting a single counterparty, the alternate stated in a put up on X. It was not a hack of the SwissBorg platform. The loss affected fewer than 1% of customers and represented about 2% of SwissBorg’s whole belongings, the agency stated. All different funds and techniques stay safe, and consumer balances throughout the SwissBorg app are unaffected. SOL Earn redemptions are paused whereas restoration efforts proceed. SwissBorg says it’ll cowl any shortfall, guaranteeing no consumer losses. The corporate is working with white-hat hackers, safety companies and regulation enforcement to get well the funds. A full incident report will comply with as soon as investigations conclude. This exploit arrives amid a pointy rise in crypto thefts, with over $2.17 billion already stolen in 2025. — Shaurya Malwa Learn extra.
LEDGER CTO WARNS OF PNM ATTACK: Charles Guillemet, the chief expertise officer at {hardware} pockets maker Ledger, warned on X {that a} large-scale provide chain assault was underway after a good developer’s Node Package deal Supervisor (NPM) account was compromised. In line with Guillemet, the malicious code — already pushed into packages with over 1 billion downloads — is designed to silently swap crypto pockets addresses in transactions. Meaning unsuspecting customers may ship funds on to the attacker with out realizing it. Guillemet didn’t title the developer whose account he stated was compromised. The incident underscores how deeply interconnected open-source software program is and why safety lapses in developer instruments can ripple into the crypto financial system virtually immediately. A day later, Guillemet shared that nearly zero crypto customers had been affected by the hack. “NPM is a software generally utilized in software program growth utilizing JavaScript, which makes integrating packages simple for builders,” stated Guillemet in a message to CoinDesk. When an attacker compromises a developer’s account, they’ll slip malicious code into broadly used packages. “The malicious code makes an attempt to empty customers by swapping addresses utilized in transaction or basic on-chain exercise and changing them with the hacker’s deal with,” Guillemet added. — Margaux Nijkerk Learn extra.
BACKPACK EU GOES LIVE FOLLOWING FTX EU ACQUISITION: Backpack Trade, a world cryptocurrency buying and selling platform, stated its European division, Backpack EU, is formally stay. Working out of Cyprus and licensed below the European Union’s MiFID II framework, the alternate is positioning itself as one of many first totally regulated venues in Europe to supply crypto derivatives, beginning with perpetual futures. “So far as I am conscious, it is simply going to be us and Kraken” in Europe providing perpetual futures, Armani Ferrante, the CEO of Backpack, stated in an interview with CoinDesk. The debut follows Backpack’s acquisition of FTX EU earlier this yr. In January, the FTX chapter property stated the sale of FTX EU to Backpack was not licensed. Since then, the difficulty has been resolved and in April the alternate started distributing funds to former FTX EU prospects, fulfilling their pledge to compensate customers affected by the collapse of Sam Bankman-Fried’s crypto empire. Backpack EU will present customers entry to over 40 buying and selling pairs with as much as 10x leverage, the crew stated in an announcement. The platform says it goals to offer each retail and institutional merchants a compliant gateway to superior crypto buying and selling merchandise. The rollout additionally highlights Backpack’s broader technique of rebuilding belief in digital belongings following a string of alternate failures. — Margaux Nijkerk Learn extra.
POLYGON POS CHAIN EXPERIENCES FINALITY LAG: Polygon’s proof-of-stake chain is stay, however transactions are taking longer than regular to lock in, with finality working 10–quarter-hour not on time. Finality is the reassurance {that a} transaction or piece of information is irreversible as soon as confirmed and added to a block within the blockchain. The inspiration stated in an X put up {that a} repair has been recognized and is being rolled out to validators and repair suppliers. The slowdown was tied to points on some Bor/Erigon nodes and RPC suppliers, in accordance with Polygon’s standing web page. Node restarts resolved the issue for a lot of validators, whereas others needed to rewind to the final finalized block earlier than resyncing, a standing web page shared. The disruption comes weeks after Polygon’s Heimdall v2 improve promised 5-second finality by way of a modernized consensus stack. – Shaurya Malwa Learn extra.
In Different Information
- World Liberty Monetary (WLFI), the crypto protocol linked to Donald Trump and his household, blacklisted Tron founder and key investor Justin Solar’s blockchain deal with, stopping him transferring WLFI tokens. The transfer impacts 595 million unlocked WLFI tokens held on the deal with, value roughly $107 million at present costs, in accordance with Arkham information. The motion adopted the Solar-linked deal with making a number of outbound transactions of WLFI tokens on the Ethereum blockchain — together with one for $9 million value of the tokens — blockchain information reveals. Solar, in a translated put up on X, stated that the “deal with solely performed a couple of generic alternate deposit assessments, with very low quantities, after which created deal with dispersion, with out involving any shopping for or promoting, which couldn’t probably have any influence available on the market.” In a later assertion Solar urged the WLFI crew to unblock his tokens. — Sam Reynolds Learn extra.
- Decentralized finance protocol Ethena submitted a proposal to concern Hyperliquid’s forthcoming stablecoin, becoming a member of a bidding competitors that has already attracted firms together with Paxos, Sky, Frax and Agora. The token could be totally backed by Ethena’s USDtb, a stablecoin issued with federally chartered financial institution Anchorage Digital and totally backed by BUIDL, the tokenized cash market fund by asset administration large BlackRock and Securitize. If adopted, Ethena pledged that 95% of web income from USDH reserves would stream again to the Hyperliquid ecosystem, the proposal stated. Ethena additionally stated it will cowl the prices of migrating present USDC buying and selling pairs on Hyperliquid to USDH to ease adoption. — Kristzian Sandor Learn extra.
Regulatory and Coverage
- Nasdaq, the U.S. alternate the place the tech sector’s greatest names listing their shares, is in search of to place equities on the blockchain, asking the U.S. Securities and Trade Fee to bless its effort at the same time as others within the securities world are sprinting towards the identical tokenization purpose.If the SEC submitting is accredited, the alternate will let prospects select both the normal route for buying and selling equities or achieve this on-chain with tokenized shares — an possibility that will be handled with the identical precedence because the legacy technique. The transfer by Nasdaq follows an effort by digital brokerage Robinhood to concern inventory tokens for European prospects in July, giving entry to some 200 U.S. shares and exchange-traded funds (ETFs). Bringing equities and different real-world belongings onto blockchain rails has been among the many most scorching of the digital-asset world’s improvements, and the competitors has been rising fierce for each conventional finance names and crypto natives to make strikes. — Jesse Hamilton Learn extra.
- President Donald Trump’s new crypto man, Patrick Witt, is selecting up the baton from his predecessor, Bo Hines, in goading lawmakers to complete sweeping U.S. crypto insurance policies and pushing regulators to place the brand new stablecoin regulation into apply, he stated in an interview with CoinDesk. Working below the administration’s crypto czar, David Sacks, Witt is the brand new level of contact for crypto issues within the White Home after the transient tenure of his predecessor, who went on to work for stablecoin large Tether. Whereas Hines noticed the conversion of Congress’ stablecoin effort into regulation and was capable of attend the White Home ceremony to cement it, he left shortly after, leaving a prolonged crypto to-do listing for Witt.”There is not any drop off right here,” stated Witt, who was elevated to the job final month, simply two weeks after the administration issued its wide-reaching technique report for tackling U.S. crypto coverage. “We’re preserving the pedal to the steel with all the completely different initiatives on the legislative entrance and the interagency actions advisable within the report.” — Jesse Hamilton Learn extra.
Calendar
- Sept. 22-28: Korea Blockchain Week, Seoul
- Oct. 1-2: Token2049, Singapore
- Oct. 13-15: Digital Asset Summit, London
- Oct. 16-17: European Blockchain Conference, Barcelona
- Nov. 17-22: Devconnect, Buenos Aires
- Dec. 11-13: Solana Breakpoint, Abu Dhabi
- Feb. 10-12, 2026: Consensus, Hong Kong
- Mar. 30-Apr. 2: EthCC, Cannes
- Could 5-7, 2026: Consensus, Miami