Skip to Main Content
09/28/2026|5 minute read

In this issue:

USDC-Affiliated Firms Launch Digital Asset Borrowing, Expand Wrapped BTC

By Rob Musiala

The issuer of the USDC stablecoin recently announced that its affiliate has launched Digital Asset-Backed Borrowing (DABB) on the Arc and Ethereum blockchains. According to a company blog post, “[t]hrough one coordinated workflow, customers can deposit BTC, mint Circle Wrapped Bitcoin (cirBTC), supply cirBTC as collateral through supported third-party lending markets through a wallet you control, and receive borrowed USDC in Circle Mint without selling the BTC that supports the position.”

In a related development, another affiliate of the USDC issuer announced that “Circle Wrapped Bitcoin (cirBTC) is now available on Arc, bringing 1:1 bitcoin-backed (BTC) liquidity into the Economic OS for internet-native financial markets.” According to a blog post, “cirBTC helps market participants put BTC collateral to work across credit, trading, lending, settlement, treasury, and other institutional use cases.”

For more information, please refer to the following links:

OCC Grants Conditional National Trust Bank Charters for Crypto Companies

By Keith Murphy

According to recent reports, the U.S. Office of the Comptroller of the Currency (OCC) granted conditional national trust bank charters to three fintechs: Bastion Platforms, Catena Trust Bank and Agora National Trust Bank. The charters reportedly will allow the firms to expand into activities such as stablecoin issuance, custody, asset management and related digital asset services under a federal regulatory framework, subject to additional conditions and final approval. As noted in the reports, the approvals are particularly meaningful because the GENIUS Act marks the OCC as a primary regulator of stablecoin issuers, making national trust charters more attractive than the burdens of state-by-state regulation. Among other services, the newly chartered fintechs will offer services ranging from white-label stablecoin issuance and wallet services to digital asset banking and custody services to issuance and management of certain stablecoin and related reserve assets, according to the reports.

For more information, please refer to the following links:

U.S. Crypto and Financial Firms Announce Tokenized Securities Initiatives

By Rob Musiala

A major provider of financial information, benchmarks, analytics and credit ratings recently announced that “it has entered into an agreement to acquire OpenZeppelin, the security standard for onchain finance.” According to a press release, “[t]he transaction complements [the company’s] risk assessment and ecosystem development capabilities in digital asset markets, enhancing its ability to create the next generation of onchain security assessments [and] benchmarks, and deliver essential intelligence as capital markets transition onchain.”

In related news, according to reports, major U.S. crypto exchange Blockchain.com recently announced an agreement with a major U.S. stock exchange to give Blockchain.com users access to tokenized U.S. exchange-listed stocks and exchange traded funds (ETFs). The companies also reportedly plan to begin exchanging market data.

And in a final notable item, MoonPay, a crypto payments company, recently announced two collaborations related to tokenized securities. In one collaboration, MoonPay and a major U.S. asset manager and sponsor of crypto ETFs announced “a strategic collaboration” to make the asset manager’s tokenized money market mutual fund “more accessible to everyday investors in the U.S. via MoonPay.”

In the second collaboration, MoonPay announced that “it has entered into a definitive merger agreement to acquire North Capital Investment Technology, Inc. … a leading private-markets infrastructure platform that combines API-first technology with regulated brokerage services.” In a press release, MoonPay’s CEO said, “At MoonPay, we’re building the regulatory foundation to support mass adoption of tokenized real-world assets.”

For more information, please refer to the following links:

CFTC Issues No-Action Position for ‘Passive Software Providers’

By Rob Musiala

On Sept. 17, the U.S. Commodity Futures Trading Commission’s (CFTC) Market Participants Division (MPD) issued a no-action position for the benefit of “passive software providers” (PSPs). According to a press release, “subject to certain specified conditions, MPD will not recommend … enforcement action against any such provider or their relevant personnel for failure to register as an introducing broker or associated person of an introducing broker.” The press release notes that the no-action position “applies solely in relation to … provision and marketing of software to facilitate trading by the provider’s users with registered futures commission merchants, introducing brokers, and designated contract markets.”

The no-action position letter notes that the CFTC’s no-action position is intended to apply “for all PSPs on substantially the same terms as that provided to the software developer in Letter 26-09.” The letter lists 10 specific conditions required for PSPs to be eligible for the no-action relief described and includes a detailed definition of the “Covered Activities” to which the no-action position applies.

For more information, please refer to the following link:

OFAC Adds Iranian Crypto Company to Specially Designated Nationals List

By Rob Musiala

On Sept. 17, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) announced that it “designated BitBank, a priority digital assets venture controlled by OFAC-designated Iranian financier Babak Zanjani (Zanjani), as part of Operation Economic Outcast, the … whole-of-government economic campaign against the Islamic Republic of Iran and its enablers.” The press release notes, “The Department of the Treasury will continue to not only target the Iranian digital asset ecosystem, but also international entities and actors which help facilitate it.”

For more information, please refer to the following links:

Former Girlfriend of ‘Cryptocurrency Fraudster’ Receives Prison Sentence

By Rob Musiala

The U.S. Department of Justice (DOJ) recently announced that “the former girlfriend of a cryptocurrency fraudster … was sentenced … to 18 months in federal prison for failing to report more than $2.6 million in ill-gotten gains she obtained via her then-boyfriend’s criminal activities.” According to a DOJ press release, the defendant used illicit funds to acquire approximately $16 million in cryptocurrency for her former boyfriend, and transferred to her personal bank accounts more than $2.6 million “that she willfully failed to report to the IRS on her federal tax returns.”

For more information, please refer to the following link:

Analysis Provides Details on Blockchain Dead Drops and EtherHiding Tactics

By Amos Kim

Chainalysis recently published a report providing details on a cyberattack technique it refers to as “blockchain dead drops” (BDD), in which cyber threat actors store malware payloads or dynamic command-and-control configuration pointers in locations on public blockchains. According to the report, BDDs provide threat actors with greater campaign durability by utilizing blockchains as coordination layers that survive domain seizures, hosting takedowns and other traditional disruptions. The analysis highlights that BDD activity has surged 440 percent since the launch of Chinese high-capacity open source AI models that reportedly do not restrict the generation of malicious code. According to the report, nation-state threat actors now represent the majority of BDD activity, accounting for roughly two-thirds of new activity by the second quarter of 2026. Among its findings, the report identified the following case studies:

  • A Democratic People’s Republic of Korea (DPRK)-linked group tracked as UNC5342 used smart contracts to deliver credential-stealing malware to job-seeking cryptocurrency developers, a tactic known as EtherHiding. A new variant of this campaign added redundancy by embedding encoded pointers within transactions on the TRON and Aptos blockchains that resolved to the same transaction on the Binance Smart Chain, where the encrypted malware instructions were stored.
  • Suspected Iranian state actors linked to Iran’s Ministry of Intelligence wrote command-and-control infrastructure onto the Bitcoin blockchain by sending small payments to a well-known Bitcoin address with historical ties to Satoshi Nakamoto. The blockchain transactions stored encoded routing data that malware could decode to retrieve the current attacker infrastructure.
  • Russian-language criminal groups embedded BDD into smart contracts on the Polygon blockchain in a Malware-as-a-Service operation. The operator utilized smart contracts as programmable storage, maintaining infrastructure that was resold or rented to downstream affiliates running their own malware campaigns.

For more information, please refer to the following link:


Featured Insights