TrapDoor Malware Targets Crypto Developers Across Package Registries
Socket says the TrapDoor campaign planted malicious packages across npm, PyPI, and Crates.io to steal wallet data, cloud credentials, SSH keys, and developer secrets.
web3 and ai trends / open source /
Socket says the TrapDoor campaign planted malicious packages across npm, PyPI, and Crates.io to steal wallet data, cloud credentials, SSH keys, and developer secrets.
OKX Ventures and Korea Investment & Securities are each set to invest KRW 80 billion for 19.6% stakes in South Korean crypto exchange Coinone.
Nvidia highlighted eight robotics research papers for ICRA 2026, centered on moving robot policies from simulated training into real-world operation.
Asana completed its acquisition of StackAI, adding a no-code agent workflow platform aimed at enterprise systems such as Salesforce, Oracle, SharePoint, and Asana.
Vitalik Buterin highlighted Interfold as a live implementation path for MACI-style private voting with FHE, threshold cryptography, and zero-knowledge proofs.
Visa has invested in Replit as the companies work on payment tools for apps built by AI coding agents.
YouTube is rolling out a custom feed feature that lets signed-in U.S. viewers generate and edit home-page video feeds from text prompts.
Virtuals Protocol announced that XMAQUINA's DEUS robotics token is live, framing it as a DAO treasury play on physical AI and humanoid robotics.
Google introduced a Pay and Wallet Developer MCP server that lets AI coding tools inspect payment integrations, search docs, and monitor merchant errors.
Snowflake signed a five-year, $6 billion AWS infrastructure commitment focused on Graviton compute, AI services, and enterprise agentic AI workloads.
CrowdStrike, with Google and Shadowserver, disrupted Glassworm infrastructure used to target software developers through poisoned open source projects.
Blockworks launched the Transparency Alliance, a coalition backing standardized token disclosures through its Token Transparency Framework.
OpenBMB released MiniCPM5-1B, a compact open model aimed at local assistants, coding agents, tool-use workflows, and resource-constrained deployment.
The UK added Huobi Global S.A. and other entities to a Russia sanctions list targeting financial-sector support networks.
OpenRouter raised a $113 million Series B led by CapitalG, while investor and company materials point to rapid growth in multi-model AI gateway usage.
Coinbase's Base network launched Base MCP, a remote Model Context Protocol server that lets supported AI clients request wallet and DeFi actions through Base Accounts.
BitMine said it added 111,942 ETH in a week, lifting its Ethereum treasury to 5.39 million tokens and 4.47% of total ETH supply.
Project Open Hand is using Chef Robotics systems to help assemble medically tailored meals in San Francisco.
ClickUp's 22% layoff puts a sharper number on the push to reorganize software teams around internal AI agents.
Indonesia restricted access to Polymarket after classifying the crypto prediction market as online gambling under local law.
Prometheum is framing broker-dealer distribution as the next test for tokenized securities after launching digital brokerage services for traditional accounts.
Aikido says deleted Google API keys can keep authenticating for several minutes, complicating incident response for Gemini-enabled projects.
Keyrock says agentic payments are still early, but crypto payment rails are becoming a serious design path for autonomous AI spending.
OpenAI says an internal general-purpose reasoning model found a counterexample to a long-running unit distance conjecture in discrete geometry.
Vercel added Alibaba's Qwen 3.7 Max to AI Gateway, giving developers another routed model option for coding and agent workloads.
Robinhood Crypto COO Tanya Denisova is leaving the company after more than five years, while Robinhood's reported crypto revenue and app trading volumes fell sharply in the first quarter.
The NTSB temporarily took its public docket system offline after AI and computational methods were used to reconstruct cockpit audio from released sound spectrum imagery.
SEC Commissioner Hester Peirce said a contemplated tokenized stock exemption should be limited to digital representations of existing equities, not synthetic stock-tracking tokens.
House Majority Whip Tom Emmer pushed back on law enforcement concerns over CLARITY Act protections for noncustodial crypto software developers.
NEAR says an upcoming network upgrade will add dynamic resharding, letting the protocol add shards automatically as demand grows.
Spotify and Universal Music Group announced licensing agreements for a paid Premium add-on that will let fans create AI-enabled covers and remixes from participating artists.
Google is packaging Gemini for Home as a partner-facing stack for service providers and hardware makers, including camera intelligence, Home APIs, and reference designs.
New House proposals would restrict campaign insiders and broader event contracts as lawmakers scrutinize prediction markets tied to politics and military events.
Hark, Brett Adcock's secretive AI interface startup, has raised a $700 million Series A and is now valued at $6 billion, according to TechCrunch.
Vercel added xAI's Grok Build 0.1 beta coding model to AI Gateway, giving developers a single endpoint path for the early-access model.
Nvidia used its latest earnings cycle to position Vera, its CPU for agentic AI systems, as a large new data-center market rather than a supporting chip.
The Federal Reserve is seeking comment on a limited payment-account proposal that could give eligible firms narrower access to Reserve Bank payment services.
Google's LiteRT-LM v0.12 update adds early Swift and Web JavaScript APIs, widening the on-device LLM runtime beyond Android and desktop workflows.
Vitalik Buterin outlined a short-term Ethereum privacy plan centered on FOCIL, keyed nonces, and wallet access-layer tooling.
AllUnity is reportedly preparing a Swedish krona stablecoin as the DWS, Flow Traders, and Galaxy-backed issuer expands its regulated European payment rails toward AI-agent use cases.
YouTube is rolling out Ask YouTube for conversational video search and bringing Google's Gemini Omni model into Shorts Remix and the YouTube Create app.
A new White House executive order asks the Federal Reserve to evaluate whether nonbank fintech and digital-asset firms can get more direct access to Reserve Bank payment accounts and services.
Google moved its Tensor ML SDK into beta, tying Pixel 10 TPU deployment to LiteRT and a model garden for on-device AI apps.
Google DeepMind says its Genie 3 world model can generate real-time interactive environments grounded in Google Maps Street View data, while still warning that exact real-world location simulation remains limited.
Vercel says Claude Managed Agents can now run tool calls inside Vercel Sandbox sessions with Firecracker isolation and firewall-brokered credentials.
Echo Protocol says a compromised admin key on its Monad eBTC deployment led to unauthorized minting and about $816,000 in impacted funds.
SandboxAQ says its first LLM-to-LQM integration is live, giving researchers natural-language access to its AQCat Adsorption Spin model for catalyst screening.
Minnesota's new Chapter 93 lets state-chartered banks and credit unions offer virtual-currency custody starting August 1, provided they give notice and keep customer assets segregated.
The Senate Banking Committee advanced H.R. 3633 in a 15-9 vote, moving the Digital Asset Market Clarity Act toward the Senate floor with its stablecoin-yield limits and broader market-structure framework intact.
Official Firedancer docs and release notes show Solana's rollout is advancing through mainnet-ready Frankendancer builds while the full from-scratch validator still has no public release.