BTC $78,904.00 -0.27%
ETH $2,471.94 -1.66%
BNB $692.44 -1.34%
XRP $1.38 -3.22%
SOL $103.89 -2.67%
TRX $0.3336 -2.09%
DOGE $0.0833 -3.59%
ADA $0.1981 -3.62%
BCH $247.82 -2.44%
LINK $11.41 -2.19%
HYPE $84.07 +0.65%
AAVE $123.63 -4.01%
SUI $0.7272 -4.37%
XLM $0.1784 -2.14%
ZEC $858.02 -1.78%
BTC $78,904.00 -0.27%
ETH $2,471.94 -1.66%
BNB $692.44 -1.34%
XRP $1.38 -3.22%
SOL $103.89 -2.67%
TRX $0.3336 -2.09%
DOGE $0.0833 -3.59%
ADA $0.1981 -3.62%
BCH $247.82 -2.44%
LINK $11.41 -2.19%
HYPE $84.07 +0.65%
AAVE $123.63 -4.01%
SUI $0.7272 -4.37%
XLM $0.1784 -2.14%
ZEC $858.02 -1.78%

bank

All
Article
Flash

Vice Governor of the Central Bank Lu Lei: The boundaries of responsibility for intelligent payment systems cannot be ambiguous, and a self-discipline convention will be released

According to Mobile Payment Network, Lu Lei, a member of the Party Committee and Vice President of the People's Bank of China, stated at the 15th China Payment Clearing Forum that intelligent agent payments must not blur the boundaries of responsibility between consumers, operating institutions, and algorithm systems. Lu Lei believes that the essence of payment is the transfer of fund ownership, which objectively requires that the results of transactions are predictable, responsibilities are definable, and traces are traceable. Large models and autonomous intelligent agents have characteristics such as output randomness and insufficient transparency of logic. If transaction decision-making authority is blindly or excessively granted to intelligent agents, it will affect the trust foundation of fund transactions. The current governance rules of the payment industry and dispute resolution mechanisms are built around "humans as the final decision-makers in transactions." The new model of intelligent agents automatically initiating and assisting in transactions easily blurs the boundaries of responsibility, and the existing governance rules need to be optimized and improved.Regarding the issue of insufficient compatibility of protocol standards in the field of intelligent agent payments, Lu Lei emphasized that the dispute over protocols is essentially a dispute over business rules and technical standards, as well as a struggle for dominance in the era of artificial intelligence. The People's Bank of China continues to strengthen its tracking research on technological innovation, especially intelligent agent payments, guiding the Payment Clearing Association to leverage its advantages in industry self-regulation. Based on extensive soliciting of opinions, they will formulate and publish the "Self-Regulatory Convention for Intelligent Agent Payment Applications," and will continue to work on coordinating protocols and standards, as well as innovating risk governance. Lu Lei proposed three hopes to market institutions: actively respond to and implement the industry self-regulatory convention, with payment security and risk prevention as the bottom line, and consumer rights protection as the focal point; continuously track the trends of cutting-edge technologies such as large models and intelligent agents both domestically and internationally, and build technical reserves and application capabilities; adhere to the principle of rules and standards first, strengthen coordination and compatibility among different protocols and standards, and cooperate with regulatory authorities to promote the construction of a foundational protocol and technical standard system for intelligent agent payments.

SemiAnalysis releases Neocloud security deep report: Infrastructure configuration errors are shocking, and cross-tenant RCE could affect banks, telecommunications, and even a country's intelligence agency

The semiconductor and AI independent research organization SemiAnalysis released a deep security report on Neocloud (new cloud), revealing various cross-tenant security vulnerabilities discovered during the ClusterMAX 3 testing period. In a four-month test covering 25 vendors and 32 clusters, the team achieved multiple instances of cross-tenant remote code execution (RCE) solely by exploiting publicly known vulnerabilities and basic configuration checks. Affected entities included banks, telecommunications companies, universities, research institutions, AI laboratories, and even a national intelligence agency.Typical issues included: shared Kubernetes control plane leading to tenant metadata visibility, container escape, exposure of BMC/IPMI management networks, incorrect configuration of InfiniBand security keys (P_Key, SA_Key, M_Key), unfortified default trust mode of BlueField DPU, Grafana monitoring dashboards using god-level API keys, and lack of VXLAN isolation in front-end networks. The report specifically pointed out a cascading vulnerability case: a misconfiguration of shared vCluster combined with software versions being two years out of date ultimately completed the POC verification of cross-tenant RCE within an afternoon.Notably, the report questioned the mainstream narrative that "AI has fundamentally changed the pace of cybersecurity": statistics on CVEs for NVIDIA GPU drivers, CUDA, PyTorch, Kubernetes, Docker, and the Linux kernel showed that there was no significant increase in vulnerabilities after the popularization of AI coding models, with most data supporting the "no change hypothesis." The report also detailed the incident where an OpenAI-trained agent attacked Hugging Face, where the AI agent achieved cluster-level privilege escalation through a message board established via Artifactory, which went undetected from May to July. While building POC verification for existing vulnerabilities, the team found that Claude Fable and GPT-5.6 Sol frequently rejected security-related requests, ultimately relying on open-source models such as DeepSeek V4, Kimi K3, and GLM-5.2 to complete the task.SemiAnalysis stated that the core issue in the Neocloud (new cloud) industry is not the new risks brought by AI, but rather the long-term absence of basic patch management, tenant isolation, and security design. They recommended that vendors establish automated security announcement monitoring systems and rectify single points of failure that could expose all users' architectural patterns.

first_img Attackers stole over $1 million in user funds from the new Solana bank Avici

Solana's new bank Avici is facing ongoing attacks, with attackers having stolen over $1 million from users. The attackers' wallet holds 10,005.03 SOL (approximately $1.07 million) and about $11,600 in USDC and USDT. The attack method involves first calling the SubmitSignatures of the Avici authorization program, then calling the AddCollateralAdmin of the collateral program, and finally executing WithdrawCollateralAsset to withdraw the balance. Both of Avici's programs are upgradable and share the same standard Solana account instead of multi-signature upgrade permissions.Avici confirmed the incident 1 hour and 53 minutes after the first theft transaction, stating, "We are aware of the issue affecting card balance withdrawals and are working directly with all relevant partners to resolve it." Prior to this, users had reported stolen balances on social media. A real-time tracker established by anonymous on-chain analyst STACC recorded 125 different sending accounts, with transfer amounts ranging from approximately 9 USDC to over 26,000 USDT.As a result, the AVICI token fell 49.4% in 24 hours to $0.2175, with a market cap of approximately $2.84 million, hitting an all-time low. Avici raised funds through MetaDAO in October 2025, with an original cap of $3.5 million, but the final committed amount reached $34.2 million, and the team refunded 89.8% of the committed USDC.

first_img The Clarity Act has been postponed to September, and banks are still accelerating their layout of tokenized deposits

Vassilis Tziokas from Matter Labs pointed out in a CoinDesk article that the U.S. Senate has postponed the Clarity Act until September. This market structure bill failed to complete the final vote before the August recess, meaning that regulatory rules for the digital asset market will take weeks to be implemented. Meanwhile, banks are not waiting for regulation; JPMorgan has processed over $30 trillion in transactions through the Kinexys platform and launched the deposit token JPMD, while Citigroup operates cross-border Treasury token services. A clearinghouse, in collaboration with 17 major financial institutions, plans to achieve on-chain tokenized deposit clearing by 2027.The article argues that the interoperability of interbank tokenized deposits does not come from messaging standards or token bridges, but is realized through clearing mechanisms: the sending bank redeems tokens, the receiving bank issues its own tokens, inter-institutional obligations are recorded and netted, and ultimately settled in central bank currency. The engineering challenge lies in simultaneously satisfying privacy, neutrality, and verifiability; each institution must operate its own ledger, prove transfers through cryptography without exposing underlying data, and anchor to a neutral settlement facility owned by no participants.The author notes that the Clarity Act will not directly regulate tokenized deposits, but it can clarify the boundaries of the digital asset market and improve the stablecoin framework established by the GENIUS Act. The Global Financial Markets Association's report in April 2026 lists unresolved gaps such as unified processing of cross-border tokenized deposits and guidelines for off-network transfers, which are regulatory unlocking points for interbank tokenized fund interoperability. In the face of regulatory uncertainty, banks rationally choose to isolate, and each month of delay rewards closed gardens.

first_img Members of the Abu Dhabi royal family are reported to support a cryptocurrency banking project associated with Trump

According to a report by The Wall Street Journal citing informed sources, Sheikh Tahnoon bin Zayed Al Nahyan, a member of the Abu Dhabi royal family, is the backer behind StringZ Holding RSC, which holds a 49% stake in WLTC Holdings, the parent company of World Liberty Financial, associated with the Trump family, which is proposing a U.S. trust bank. It is said that entities linked to the Trump family hold an additional 38% stake in the company.The Office of the Comptroller of the Currency (OCC) granted preliminary conditional approval to World Liberty Trust Company on August 14. The decision announced by the OCC confirms that StringZ is an investor in WLTC Holdings and has signed a commitment not to interfere with the bank, but does not specify Tahnoon as its backer or disclose his shareholding percentage. The trust bank must meet OCC's pre-operational requirements and obtain final approval before it can begin operations.Tahnoon previously supported the acquisition of a 49% stake in World Liberty Financial for $500 million, prompting U.S. Democratic senators to call for hearings on the deal and investigate whether it affects U.S. policy towards the UAE. Tahnoon currently serves as the UAE's National Security Advisor and is also the chairman of the artificial intelligence company G42. Cointelegraph reached out to the Trump Organization for comment, but had not received a response by the time of publication.
app_icon
ChainCatcher Building the Web3 world with innovations.