Single – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Fri, 05 Sep 2025 07:28:40 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Single – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Coinbase Bundles Crypto and Tech Giants in Single Futures Product https://earlybirdsinvest.com/coinbase-bundles-crypto-and-tech-giants-in-single-futures-product/ https://earlybirdsinvest.com/coinbase-bundles-crypto-and-tech-giants-in-single-futures-product/#respond Fri, 05 Sep 2025 07:28:39 +0000 https://earlybirdsinvest.com/coinbase-bundles-crypto-and-tech-giants-in-single-futures-product/

Coinbase



$1.77B

is preparing to
release a new futures product that merges exposure to cryptocurrencies and major US technology firms into one investment.

This upcoming index will offer a bundled approach, which lets traders gain access to both markets through a single contract. The product, known as the “Mag7 + Crypto Equity Index Futures“, is scheduled to go live on September 22.

It will track shares of seven tech companies—Apple, Microsoft, Alphabet, Amazon, Nvidia, Meta, and Tesla—as well as Coinbase’s own stock and two BlackRock exchange-traded funds (ETFs) tied to Bitcoin
BTC


$112,568.65

and Ethereum.

What is Decentralized Crypto Gambling? (Animated Explainer)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Coinbase stated that the US market currently lacks any futures instruments that link both equity and crypto markets together. This new product is designed to offer access to two asset types that usually require separate trades.

Each asset in the index will be given an equal 10% weight, which ensures none of them dominates the contract’s value.

Contracts are to be settled in cash on a monthly basis, and the value of one contract will be equal to $1 multiplied by the total value of the fund.

Quarterly adjustments will be made to rebalance the weight of each component. MarketVector, an established index provider, will handle the task of maintaining and calculating the index.

Coinbase’s CEO, Brian Armstrong, mentioned on X that the exchange plans to introduce more products like this to become a platform that offers a wider range of trading options across various markets.

Recently, Coinbase and OKX



$2.25B

offered support for Australians who want to add crypto to their self-managed superannuation funds (SMSFs). What did the two exchanges say? Read the full story.


]]>
https://earlybirdsinvest.com/coinbase-bundles-crypto-and-tech-giants-in-single-futures-product/feed/ 0 56847
This single point of failure can kill web3’s dream of an open, decentralized internet https://earlybirdsinvest.com/this-single-point-of-failure-can-kill-web3s-dream-of-an-open-decentralized-internet/ https://earlybirdsinvest.com/this-single-point-of-failure-can-kill-web3s-dream-of-an-open-decentralized-internet/#respond Sat, 26 Jul 2025 22:51:06 +0000 https://earlybirdsinvest.com/this-single-point-of-failure-can-kill-web3s-dream-of-an-open-decentralized-internet/

The following article is a guest post and opinion of Chris “Jinx” Jenkins, Head of Operations at Pocket Network.

Internet pioneer Tim Berners-Lee once dreamed of an open and accessible digital information system. His vision for the web — a virtual space where everyone had equitable opportunities to contribute, collaborate, share, and learn together — has shifted.

But the internet has moved in the opposite direction from this open garden. From single points of failure to censorship by sectors both public and private, it is now in the middle of a fight between messaging-obsessed political bodies and profit-hungry corporations, each seeking to control or monetize information flows.

Web3, powered by decentralized apps (DApps), promises to rekindle Berners-Lee’s dream of a permissionless space for free, open communication and innovation. Yet ironically, DApps today also rely heavily on centralized infrastructure or data sources. These single points of failure compromise the entire ecosystem’s security and integrity — as seen in many of the complaints around Solana.

Systems are only as secure as their weakest points. And to fulfill Web3’s ethos, DApps must adopt and implement genuinely open, decentralized, and verifiable infrastructure.

DApps Suffer from Concentrated Vulnerabilities

Most developers build the front end of DApps on a decentralized interface, but depend on centralized data infrastructure for backend support.

DApps largely run on centralized data hosting platforms and cloud providers like Amazon Web Services, Google Cloud, and Microsoft Azure. Although easily accessible, these platforms are susceptible to single-point failures and censorship, leading to global outages and downtime.

History is a witness to these failures. There are multiple examples where Infrastructure-as-a-Service platforms have faced disruptions, interrupting seamless DApp usage.

For instance, although MetaMask functions as a decentralized wallet, its endpoints run on centralized tech like Infura to access Ethereum. In 2022, when Infura blocked access after U.S. sanctions, MetaMask users temporarily couldn’t access their wallets from specific regions.

This is not an isolated incident. Infura clients have also faced interruptions in the past. Similarly, Solana and Polygon users faced outages due to the overloading of centralized RPCs during high network traffic.

DApps using centralized infrastructure to supply data are thus susceptible to downtime, information inaccuracies, usage gaps, and disconnected data flows. These incidents demonstrate the need to shift to decentralized infrastructure for data transferability and smooth accessibility without facing outages.

The Need for a Decentralized DApp Ecosystem

DApps without a decentralized stack are an oxymoron.

Instead of AWS, Google, or Azure, DApps must use open-source solutions like InterPlanetary File System (IPFS), Filecoin, or Arweave. These protocols provide a tamper-proof, distributed storage facility with high uptime and protection against random outages.

DApps running on decentralized infrastructure work with independent node operators. This helps distribute data queries across the network, eliminating single points of failure for unstoppable data availability.

Since individual nodes cannot block information flows, DApps run smoothly even when several nodes are offline. So the network always remains accessible without any downtime.

Decentralized infrastructure further removes the dependency on intermediaries who arbitrarily control data flows. Instead, DApps can connect with data, service providers, and users within an integrated, enmeshed open-source system.

Pocket Network unlocks open data accessibility so that any DApp can get the information it needs, without relying on centralized or singular entities. Pocket’s Shannon upgrade created the first truly permissionless Open API Network.

Decentralized social networks like BlueSky and the AT Protocol don’t depend on centralized RPCs. Rather, they work with decentralized RPCs to access open data. Similarly, DeFi protocols using Chainlink don’t need to depend on centralized APIs to source real-time on-chain price data.

A robust, genuinely decentralized tech stack is critical for DApps to build a digital ecosystem without single points of failure, paving the way to return to Berners-Lee’s vision of a globally accessible network.

Towards Berners-Lee’s Vision of an Open Internet

Tim didn’t envision a society where a few megacorporations build walled gardens with asymmetrical relationships between users and companies. He wanted open communication in the digital world without any powerful intermediaries controlling information exchange.

This vision is aligned with Satoshi Nakamoto’s idea of a decentralized, peer-to-peer exchange system. And although crypto now leans toward a casino-style gambling circus, that was not how Nakamoto and the cypherpunk community imagined it to be.

That said, Web3 innovators are actively building the infrastructure necessary to bring Tim and Satoshi’s vision to fruition. Because an open digital world with equitable accessibility is a must-have, not a nice-to-have.

Decentralized infrastructure protocols for open-source data are rapidly emerging as the new frontier for seamless data accessibility to train AI models and support cross-chain DApp usage. With a $350 billion open data market, it’s critical to wrest control away from centralized providers and distribute it among decentralized operators.

To thrive, crypto, AI, and other emerging tech must reject Web2’s business model and embrace the internet’s OG vision, now enshrined in the Web3 paradigm. Moving toward a decentralized infrastructure that doesn’t suffer from single points of failure is crucial to building a resilient and reliable internet.

Mentioned in this article
]]>
https://earlybirdsinvest.com/this-single-point-of-failure-can-kill-web3s-dream-of-an-open-decentralized-internet/feed/ 0 49852
$100,000,000 Stolen From Central Bank of Brazil in Single Night After Alleged Insider Sold Credentials to Hackers: Report https://earlybirdsinvest.com/100000000-stolen-from-central-bank-of-brazil-in-single-night-after-alleged-insider-sold-credentials-to-hackers-report/ https://earlybirdsinvest.com/100000000-stolen-from-central-bank-of-brazil-in-single-night-after-alleged-insider-sold-credentials-to-hackers-report/#respond Tue, 08 Jul 2025 07:19:50 +0000 https://earlybirdsinvest.com/100000000-stolen-from-central-bank-of-brazil-in-single-night-after-alleged-insider-sold-credentials-to-hackers-report/

Hackers reportedly stole $100 million from the Central Bank of Brazil using security credentials purchased from an alleged insider.

According to a new AP report, the cyberattack targeted Brazil’s popular instant payment system, known as PIX, to steal the massive nine-figure sum.

Hackers were able to pull off the scheme by infiltrating the C&M system, the software company that facilitates connections between financial institutions and the central bank to enable PIX payment transactions.

Police say the hackers used security credentials they allegedly purchased from C&M employee João Roque, who they just arrested. Roque allegedly told investigators he was recruited by the hackers last year and sold them his credentials. The AP was unable to reach Roque’s attorneys for comment.

After gaining access to the C&M system, the hackers initiated fake PIX operations, making off with $100 million in a single night from financial institutions that are plugged into the C&M network.

Police say they are attempting to identify the hackers and that at least four other people participated in the crime. Authorities are also attempting to freeze the suspected stolen assets, and say they have blocked about half the stolen funds connected to the scheme.

In a statement published by local media, C&M says that it is cooperating with authorities and that the breach was likely due to unauthorized access to security credentials, not system flaws.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/100000000-stolen-from-central-bank-of-brazil-in-single-night-after-alleged-insider-sold-credentials-to-hackers-report/feed/ 0 46419
Crypto Firms To Report Every Single Transaction Under New UK Laws https://earlybirdsinvest.com/crypto-firms-to-report-every-single-transaction-under-new-uk-laws/ https://earlybirdsinvest.com/crypto-firms-to-report-every-single-transaction-under-new-uk-laws/#respond Mon, 19 May 2025 18:56:06 +0000 https://earlybirdsinvest.com/crypto-firms-to-report-every-single-transaction-under-new-uk-laws/

Businesses providing crypto services in the UK will be required to collect more extensive user and transaction data by next year.

The HM Revenue and Customs (HMRC) says the new rule covers all UK-based reporting crypto-asset service providers (RCASPs), which include exchanges, brokers, dealers, and any firm that transacts with digital assets on behalf of users or provides a platform for the transactions. 

The government will implement the policy as part of the Crypto-Asset Reporting Framework (CARF), a global initiative that promotes the exchange of information between countries to address tax evasion risks related to digital assets.

“From 1 January 2026, if you provide cryptoasset services in the UK, you’ll have new responsibilities for collecting data and reporting it to HMRC.

This is because the UK is introducing the Organisation for Economic Development (OECD) Cryptoasset Reporting Framework (CARF), and extending it to include domestic reporting.”

Crypto firms will have to collect data such as names, dates of birth, addresses and country of residence for individual users and business names and addresses for entity users, which include companies, partnerships, trusts and charities. 

For transactions involving users based in the UK or other countries participating in the CARF, crypto firms need to record the type of crypto asset and transaction involved as well as the value and number of units. 

The HMRC urges crypto firms to verify the accuracy of the information they collect since there will be penalties of up to £300, or around $399, per user for inaccurate, incomplete or unverified reports.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/crypto-firms-to-report-every-single-transaction-under-new-uk-laws/feed/ 0 37146
HashEx Security Alert – A Single Signature Could Drain Your Wallet https://earlybirdsinvest.com/hashex-security-alert-a-single-signature-could-drain-your-wallet/ https://earlybirdsinvest.com/hashex-security-alert-a-single-signature-could-drain-your-wallet/#respond Sat, 05 Apr 2025 05:35:14 +0000 https://earlybirdsinvest.com/hashex-security-alert-a-single-signature-could-drain-your-wallet/
HodlX Guest Post  Submit Your Post

 

Zero days without incidents in the DeFi space. This time the vulnerability was discovered in a widely used ‘elliptic library.’

What makes matters worse its exploitation could lead to hackers taking control of users’ private keys and draining wallets.

All through a simple fraudulent message signed by a user. Is this a critical issue?

The first thing to consider is the fact that libraries like elliptic provide developers with ready-made code components.

This means that instead of writing the code from scratch and checking it as they go, developers just borrow the elements they need.

While it’s considered to be a safer practice, since the libraries are continuously used and tested, this also increases the risks if one vulnerability gets through.

Elliptic library is used extensively across the JavaScript ecosystem. It powers cryptographic functions in many well-known blockchain projects, web applications and security systems.

According to NPM statistics, the package containing the error is downloaded approximately 12–13 million times weekly, with over 3,000 projects directly listing it as a dependency.

This broad usage implies that the vulnerability potentially affects a vast number of applications especially cryptocurrency wallets, blockchain nodes and electronic signature systems as well as any service relying on ECDSA signatures through elliptic, especially when handling externally provided input.

This vulnerability allows remote attackers to fully compromise sensitive data without proper authorization.

That’s why the issue received an extremely high severity rating approximately nine out of 10 on the CVSS scale.

It’s important to point out that exploiting this vulnerability requires a very specific sequence of actions and the victim must sign arbitrary data provided by the attacker.

That means that some projects may remain safe, for example, if an application only signs predetermined internal messages.

Still, many users don’t pay as much attention when signing messages via crypto wallets as they do when signing a transaction.

Whenever a Web 3.0 site asks users to sign terms of service, users often neglect to read them.

Similarly, users might quickly sign a message for an airdrop without fully understanding the implications.

Technical details

The problem comes from not handling errors properly during the creation of ECDSA (Elliptic Curve Digital Signature Algorithm) signatures.

ECDSA is commonly used to confirm that messages, like blockchain transactions, are genuine.

To create a signature, you need a secret key only the owner knows it and a unique random number called a ‘nonce.’

If the same nonce is used more than once for different messages, someone could figure out the secret key using math.

Normally, attackers can’t figure out the private key from one or two signatures because each one uses a unique random number (nonce).

But the elliptic library has a flaw – if it gets an odd type of input (like a special string instead of the expected format), it could create two signatures with the same nonce for different messages.

This mistake could reveal the private key, which should never happen in proper ECDSA use.

To exploit this vulnerability, an attacker needs two things.

  • A valid message and its signature from the user for instance, from any previous interactions
  • The user to sign a second message explicitly created to exploit the vulnerability

With these two signatures, the attacker can compute the user’s private key, gaining full access to funds and actions associated with it. Detailed information is available in the GitHub Security Advisory.

Exploitation scenarios

Attackers may exploit this vulnerability through various methods, including the following.

  • Phishing attacks that direct users to fake websites and request message signatures
  • Malicious DApps (decentralized applications) disguised as harmless services, such as signing terms of use or participating in airdrops
  • Social engineering convincing users to sign seemingly harmless messages
  • Compromising servers’ private keys that sign messages from users

A particularly concerning aspect is users’ generally lax attitude toward signing messages compared to transactions.

Crypto projects frequently ask users to sign terms of service or airdrop participation messages, potentially making exploitation easier.

So, think about it would you sign a message to claim free tokens? What if that signature could cost you your entire crypto balance?

Recommendations

Users must promptly update all applications and wallets that utilize the elliptic library for signatures to the latest secure version.

Exercise caution when signing messages, particularly from unfamiliar or suspicious sources.

Developers of wallets and applications should verify their elliptic library version.

If any users could be affected by the vulnerable version, developers must inform them about the urgent need for updating.


Gleb Zykov is the co-founder and CTO of HashEx Blockchain Security. He has more than 14 years of experience in the IT industry and over eight years in internet security, as well as a strong technical background in blockchain technology (Bitcoin, Ethereum and EVM-based blockchains).

 

Check Latest Headlines on HodlX

Follow Us on Twitter Facebook Telegram

Check out the Latest Industry Announcements
 

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any loses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: DALLE3

]]>
https://earlybirdsinvest.com/hashex-security-alert-a-single-signature-could-drain-your-wallet/feed/ 0 29094