FCA Opens Crypto Authorization Gateway Ahead of 2027 Regime

Scales of justice over a dark-toned Union Jack flag background. 

The United Kingdom’s Financial Conduct Authority has opened its authorization gateway for crypto firms, giving businesses operating in the country a defined window to prepare for a broader regulatory regime scheduled to take effect next year. The FCA began accepting applications on September 30, 2026. Firms that want to continue providing regulated cryptoasset services in the UK should apply within the window ending February 28, 2027, ahead of the new framework taking effect on October 25, 2027. The opening marks a significant change for crypto businesses that have so far operated primarily under the UK’s anti-money laundering and financial promotion requirements. Key takeaways FCA authorization requires a fresh assessment The new process goes beyond registering a crypto business with the FCA for anti-money laundering purposes. Applicants will have to demonstrate that their businesses can meet requirements covering how customers are protected, how client assets are safeguarded and how firms manage financial and operational risks. The FCA will also assess whether businesses have adequate controls to support market integrity and remain financially resilient. That means firms already registered under the UK’s Money Laundering Regulations cannot assume their existing status will carry over. The FCA’s guidance makes clear that businesses conducting activities within the new regulatory perimeter will need authorization under the new regime. Dominic Cashman, the FCA’s director of authorization, said the new framework is intended to give consumers greater protection while providing firms with a clearer regulatory structure. The Payments Association CEO Emma Banymandhub told The Block that existing MLR-registered firms should approach the process as a fresh authorization exercise. She also called for implementation that remains proportionate for smaller and growing businesses. Application timing affects transitional protections The end of the February application window does not mean businesses must immediately stop operating if the FCA has not reached a decision by then. Under the FCA’s authorization gateway guidance, qualifying existing firms that apply during the window may continue providing specified cryptoasset services, including taking on new business, if their applications remain undecided when the new regime begins. This is subject to the applicable saving provisions. The FCA expects applications submitted during the window to be decided before the regime starts. Firms can still apply after February 28. However, those applying after the window but before the regime begins face different conditions if they have not been authorized by October 25, 2027. Under the transitional provision, they may only carry out activities needed to fulfil pre-existing contracts and cannot enter into new contracts with UK customers. New crypto rules extend beyond AML The FCA published its final cryptoasset rules and guidance in June 2026 after consultations covering areas including stablecoin issuance, trading platforms and custody. The framework also introduces requirements around cryptoasset admissions and disclosures, market abuse, prudential standards and consumer protection. Its scope extends across activities including crypto trading platforms, dealing and arranging, custody, staking and certain lending and borrowing services. The market abuse rules are particularly significant because they address activities such as insider trading and market manipulation. These measures add protections for investors, although they do not remove the risks of trading cryptocurrency. The framework also strengthens stablecoin regulation, with requirements relating to backing assets, safeguarding, redemption and customer disclosures. The FCA has been preparing firms for the authorization process through pre-application support and other guidance as the industry moves toward the October 2027 implementation date. What comes next for UK crypto firms The opening of the FCA’s authorization gateway marks the next step in the UK’s approach to crypto regulation. Crypto businesses now have a clear application window to assess their operations, prepare documentation and demonstrate that they can meet the regulator’s standards. For firms already operating under the UK’s existing AML framework, the key change is that registration alone will not be enough. Firms seeking to continue regulated activities should prepare for full authorization ahead of the regime’s October 25, 2027 start date.

Comer Probes Crypto Platforms Over Identity Checks & Suspicious Trades

Collage graphic with 'YES OR NO' 

House Oversight Committee Chairman James Comer has expanded a congressional investigation into potential insider trading on prediction markets, seeking records from Crypto.com, Hyperliquid and PredictIt on identity verification, suspicious trading and referrals to regulators. The committee’s document requests, sent on September 29, 2026, broaden a probe that began in May with inquiries to Polymarket and Kalshi. The committee said it is examining whether users, including government employees, contractors and other insiders, can use nonpublic or classified information to profit from event contracts. Key takeaways Hyperliquid’s $1.1 billion short trade draws scrutiny The Hyperliquid request focuses partly on reports of a large leveraged short position involving Bitcoin and Ether perpetual contracts that was established before President Donald Trump announced a U.S. tariff policy in October 2025. The committee’s letter cites an analysis describing a roughly $1.1 billion short opened about 30 hours before Trump’s announcement and closed shortly afterward, reportedly generating more than $150 million in profit. However, the letter does not establish that the trader had advance knowledge of the government decision or that the transaction constituted insider trading. Comer is asking Hyperliquid for records covering its identity verification and Know Your Customer (KYC) procedures, geographic access restrictions and systems used to identify anomalous trading. The committee also wants information on trades or accounts flagged as suspicious and any referrals to the Department of Justice, Commodity Futures Trading Commission or other U.S. authorities. The request also covers any event contracts linked to Federal Reserve decisions, elections and geopolitical outcomes. A Hyperliquid Labs spokesperson told The Block that the company was aware of the request and was reviewing it. Crypto.com faces questions about employee and government trading The Crypto.com request takes a broader look at how the exchange handles potential conflicts involving employees, affiliates and government officials. Comer asked for details on identity verification procedures across Crypto.com’s international exchange and Crypto.com Derivatives North America, including geographic restrictions intended to prevent U.S. users from accessing the international platform. The committee also wants records of suspicious trades and referrals to regulators or law enforcement since January 2024. In addition, it asked whether employees, contractors or affiliates with advance knowledge of digital asset listings, delistings, liquidity or custody decisions were restricted from trading related event contracts. Another request seeks information on current or former federal officials who may have traded contracts connected to cryptocurrency regulatory outcomes or Crypto.com’s own regulatory status. PredictIt request focuses on political contracts PredictIt, operated by Aristotle Exchange, received a separate request focused heavily on political event contracts. The committee wants records covering identity verification, suspicious trading detection and referrals to authorities. It specifically requested information on trades involving elections, nominations, confirmations, legislative actions and other government decisions. Comer also asked PredictIt to provide documents concerning the removal of its per-contract trader limit under CFTC Letter No. 25-20, including any analysis of whether the change affected trading scale, liquidity or the platform’s ability to identify potential insider trading. The company has also been asked to provide a staff briefing, with the overall request covering January 2024 onward and a response deadline of October 13, 2026. Investigation could shape prediction market rules The latest requests build on the committee’s May investigation into Polymarket and Kalshi. According to the House Oversight Committee, those platforms have provided nearly 1,000 documents and participated in five briefings with investigators. The investigation was prompted by concerns about whether platforms can adequately prevent insider trading. The committee has also cited the April 2026 indictment of U.S. Army Master Sergeant Gannon Ken Van Dyke. Prosecutors alleged that he used classified information related to a U.S. military operation to make more than $409,000 through Polymarket wagers. An indictment does not establish guilt. Comer said the investigation is intended to determine whether platforms are meeting their legal obligations and whether additional congressional action is necessary. What happens next The expanded requests put identity verification and market surveillance under closer congressional examination across both crypto trading infrastructure and prediction markets. For Hyperliquid, the focus includes a high-value derivatives trade and event contracts, while Crypto.com faces questions about employee and government-related trading. PredictIt is being examined primarily through its political markets and trading controls. The companies have been asked to provide the requested information by October 13, 2026. Their responses could give the committee a broader view of how platforms detect suspicious activity and handle users who may have access to nonpublic information.

ZANO ROLLS BACK BLOCKCHAIN AFTER GATEWAY ADDRESS EXPLOIT

A man in a white shirt holding up a long scroll labeled 'Transaction history' 

Zano has restarted its blockchain from block 3,833,000, effectively removing about a month of transaction history after a vulnerability in its newly introduced Gateway Address system allowed unauthorized ZANO and Freedom Dollar (fUSD) tokens to enter circulation. The rollback came after Zano determined that the unauthorized assets could not be reliably separated from legitimate coins once they had entered the network. The recovery therefore reverted the chain to the point immediately before Hard Fork 6, which activated Gateway Addresses on August 26. The decision also removed legitimate transactions recorded during the affected period. Zano said the incident did not compromise wallet spend keys or ordinary transaction privacy. However, exchanges, miners, stakers, node operators and other services must migrate to the recovered chain for the restart to function across the network. KEY TAKEAWAYS GATEWAY ADDRESS VULNERABILITY TRIGGERS EMERGENCY ROLLBACK Gateway Addresses were introduced through Hard Fork 6 to make it easier for exchanges, bridges and payment services to integrate with Zano. Unlike Zano’s traditional UTXO based addresses, Gateway Addresses use an account style balance that allows services to manage funds more similarly to account based blockchain systems. The feature became the entry point for the exploit shortly after the hard fork. According to Zano’s post mortem, an attacker registered a Gateway Address on August 28 after paying the required 100 ZANO registration fee. The following day, the attacker used the vulnerability to create approximately 18.4 million ZANO in a single transaction. Another exploit on September 25 produced a further 18.4 million ZANO, followed by the creation of approximately 1.8 quadrillion fUSD. The unauthorized ZANO was particularly difficult to remove because it behaved like legitimate ZANO once created. Zano explained: “These coins functioned as authentic ZANO and could be spent normally.” That left the project with limited options for restoring the intended supply without rewriting the affected portion of the ledger. ROLLBACK REMOVES LEGITIMATE TRANSACTIONS TOO Zano’s decision to return the chain to block 3,833,000 means transactions confirmed after that point are absent from the recovered blockchain. Users who made legitimate payments during the affected month may therefore see those transactions missing from their current chain history. The rollback also has limits beyond Zano’s own network. Transactions involving assets that had already been settled on separate blockchains cannot be reversed by changing Zano’s history. The team has advised affected users to retain transaction IDs and trading records while the recovery process is finalized. Exchanges and other services must independently migrate to the recovered chain, meaning users are expected to wait for individual platforms to confirm that deposits and withdrawals have resumed before moving funds. MEXC was among the exchanges that temporarily suspended ZANO and fUSD deposits and withdrawals while the recovery was implemented. ZANO BEGINS RECOVERY AFTER NETWORK RESTART The project says its priority is now restoring balances affected by the rollback and helping exchanges, wallets and payment providers return to normal operations. Zano has said recovery funding will come from its development fund, members of the team and contributors who have committed support. The project also said it does not intend to increase ZANO’s supply to finance the recovery. The technical investigation has since produced a formal post mortem covering how the Gateway Address vulnerability was exploited and why it remained undetected. Zano has also said the affected Gateway Address functionality will remain subject to further review, auditing and testing before it is considered for restoration. The incident also exposed weaknesses in the testing process surrounding the new feature. According to Zano’s post mortem, internal audits, bug bounty efforts and AI assisted testing did not identify the vulnerability before it was exploited. CONCLUSION Zano’s month-long rollback demonstrates the difficult choices that can follow a protocol level vulnerability when unauthorized assets become indistinguishable from legitimate supply. The restart removed the unauthorized ZANO and fUSD activity, but it also erased legitimate transactions and created additional work for exchanges, service providers and users. Zano now faces the task of restoring affected balances while demonstrating that the Gateway Address system and related code can operate safely. The recovery process will ultimately depend not only on the updated software but also on coordinated adoption across the network. For Zano, restoring the intended token supply was only the first step. Rebuilding confidence in the network’s infrastructure and its ability to protect asset issuance will be the longer term challenge.

BITCOIN TESTS LONG-TERM HOLDER SUPPLY CLUSTER AS LEVERAGE CLEARS

Stack of Bitcoin coins 

Bitcoin is testing a major long-term holder cost basis zone after pulling back from its recent move toward $87,000, while derivatives positioning has cooled significantly. Glassnode data show the largest concentration of long-term holder supply between $84,000 and $85,000, making the area a key point of attention as the market enters the fourth quarter. The setup has changed further since the initial test. Bitcoin moved back above $85,000 on October 2 after sellers cleared much of the sell wall around that level, with the cryptocurrency trading near $86,700 at the time of The Block’s report. KEY TAKEAWAYS BITCOIN CONFRONTS CONCENTRATED HOLDER SUPPLY Bitcoin’s retreat from last week’s high brought it back toward a price range where a large amount of long-term holder supply is concentrated. Glassnode previously identified the broader $81,000 to $86,000 range as an important supply area. Its latest data narrowed the most concentrated band to $84,000 to $85,000. Bitcoin was trading near $84,000 when the analysis was published on September 29, following a move to roughly $87,000. Capital.com analyst Daniela Hathorn also identified $84,000 to $85,000 as an important area during a pullback, while $87,000 to $88,000 represented a nearby resistance zone. JPMorgan separately referenced approximately $85,000 as an estimated Bitcoin production cost, a level that could reduce pressure on miners if prices remain above it. The market subsequently pushed through the $85,000 area. Glassnode said sellers had partially filled orders around $85,000 before removing the remaining tasks, leaving the next notable group of sell orders near $87,000. DERIVATIVES LEVERAGE HAS FALLEN SHARPLY The price action has been accompanied by a substantial reduction in derivatives exposure. Glassnode reported that Bitcoin’s coin-denominated open interest had dropped to its lowest level since March and was almost 20% below its August level. Bitcoin, meanwhile, remained roughly 35% above its August low of about $62,000. Bitfinex analysts said much of the leverage accumulated during the rally toward $87,000 had been cleared, with perpetual futures positioning moving close to neutral. This distinction matters because open interest measures active derivatives contracts rather than direct spot demand. A decline in open interest therefore shows that leveraged positions have been reduced, but it does not by itself establish whether traders have turned bullish or bearish. Bitfinex described the next phase as dependent more heavily on spot demand. Its earlier base case called for Bitcoin to trade within a range between the $84,000 long-term holder cluster and the $87,722 yearly open through the end of September. MACRO CONDITIONS PROVIDE A MIXED BACKDROP Economic data have since offered some relief. August headline PCE inflation increased 0.3% month over month and 3.4% annually, while core PCE rose 0.2% monthly and 3% from a year earlier. The softer core reading reduced expectations for another Federal Reserve rate hike in October. However, Treasury yields remain elevated, keeping pressure on risk assets. Analysts cited by The Block have continued to point to higher yields as a constraint on Bitcoin, while crude oil prices have also added pressure to non-yielding assets. Institutional demand has also shown mixed signals. U.S. spot Bitcoin ETFs ended a nine-day inflow streak worth approximately $3.1 billion on September 30, recording $148.7 million in combined net outflows. CONCLUSION Bitcoin’s test of the $84,000 to $85,000 long-term holder supply cluster came alongside a major reduction in derivatives leverage, leaving the market less dependent on crowded futures positioning than during the move toward $87,000. The subsequent move above $85,000 has shifted immediate attention toward the $87,000 area, where Glassnode identified the next concentration of sell orders. At the same time, mixed ETF flows, elevated yields and changing expectations for Federal Reserve policy remain important factors for spot demand. The combination of concentrated holder supply and reduced leverage gives Bitcoin a clearly defined market structure to watch as the fourth quarter begins.

SENATE REPORT LINKS TETHER’S USDT TO IRAN SHADOW BANKING

Tether coins floating 

A new US Senate investigation has raised fresh questions about the use of Tether’s USDT stablecoin in Iran-linked financial networks, alleging that the token has become a major channel for moving funds outside traditional banking systems and around sanctions. The 28-page report, titled “Tethered to Terrorism: Crypto and Iran’s Shadow Banking Network,” was released on Sept. 28 by Democratic staff of the Senate Permanent Subcommittee on Investigations, led by Ranking Member Richard Blumenthal. Investigators analyzed blockchain activity involving 846 wallets sanctioned or targeted for seizure because of their links to Iran and regional proxies. KEY TAKEAWAYS USDT DOMINATES IRAN-LINKED CRYPTO ACTIVITY The Senate report points to USDT’s liquidity and widespread availability as key reasons for its use by Iran-linked networks. Unlike traditional banking transfers, stablecoin transactions can move across borders without relying on correspondent banking relationships. Of the 846 wallets examined, 84% conducted all or nearly all of their transactions in USDT. The figure was higher among wallets designated by Israel, with 87% of 757 addresses showing predominant USDT activity. Among 101 wallets designated by the US Treasury’s Office of Foreign Assets Control, the proportion was 57%. The report says the network was used for transactions involving Iranian financial institutions and groups including Hezbollah and the Houthis. Investigators also identified activity they said was connected to the procurement of drones and other military equipment. One case cited in the report involved more than $603 million in USDT received by sanctioned Iranian nationals Alireza Derakhshan and Arash Estaki Alivand between 2021 and 2025. The investigators said the funds moved through a wider network connected to Iranian entities and regional proxies. SENATE QUESTIONS TETHER’S COMPLIANCE PRACTICES The investigation does not establish that Tether itself violated US sanctions or money laundering laws. Instead, Blumenthal asked the Treasury Department and Justice Department to examine whether Tether’s compliance practices were sufficient and whether the company may have breached applicable laws. The report particularly criticized what investigators described as delays in freezing wallets associated with illicit activity. In one case, more than $34.6 million allegedly moved from wallets linked to Hezbollah before Tether froze the addresses. Blumenthal said the findings show how USDT can be used by Iranian networks to bypass conventional financial restrictions. “My new PSI report exposes how Tether and its flagship token have become central to Iran’s shadow banking system,” Blumenthal said, arguing that the network allows Iran to finance regional proxies and procure military equipment. The investigation was also referred to Treasury Secretary Scott Bessent and Attorney General Todd Blanche for further examination. The Senate subcommittee’s document archive lists the report alongside letters sent to both officials on Sept. 28. TETHER POINTS TO $550 MILLION IN FREEZES Tether responded on the same day by highlighting its cooperation with US and international authorities. The company said actions involving USDT had resulted in approximately $550 million being frozen during 2026 across wallets identified by US authorities as connected to Iran’s Central Bank and Iranian sanctions networks. That included more than $344 million frozen in April across two addresses and more than $130 million across four wallets in July. Tether CEO Paolo Ardoino defended the company’s ability to assist authorities, saying: “Tether has consistently demonstrated that USD₮ is not a haven for sanctioned actors, terrorist organizations or criminal networks.” Ardoino also argued that public blockchains provide authorities with visibility into financial movements that are not available with cash, allowing Tether to act when credible information is supplied by law enforcement. The company said its cooperation extends beyond Iran, noting that it works with hundreds of law enforcement agencies and has supported investigations involving sanctions evasion, fraud and terrorist financing. WHAT THE REPORT COULD MEAN FOR STABLECOINS The investigation adds another layer to the growing debate over how stablecoin issuers should monitor activity involving their tokens. USDT’s dominance in the wallets examined by the Senate staff does not by itself establish that Tether knowingly facilitated illicit transactions. However, the findings could increase scrutiny of how issuers respond to suspicious activity, sanctions designations and requests from government agencies. The report also highlights a broader feature of blockchain-based finance: the same public transaction records that can expose illicit networks can also allow investigators to trace and freeze assets after authorities identify the relevant wallets. CONCLUSION The Senate investigation has placed Tether’s USDT under renewed scrutiny over its use in Iran-linked financial networks. Investigators found that the stablecoin was the dominant asset among hundreds of sanctioned or seizure-targeted wallets and raised questions about the speed and consistency of Tether’s previous freezing actions. Tether disputes the implication that USDT provides a safe haven for sanctioned actors and points to roughly $550 million in Iran-linked assets frozen during 2026. The next stage will depend on whether the Treasury and Justice Department pursue the investigation requested by Blumenthal and what those agencies determine about Tether’s sanctions and anti-money laundering controls.

CALIFORNIA BANS PUBLIC OFFICIALS FROM LAUNCHING MEMECOINS

Coin logo with a pixelated 'M' icon

California Governor Gavin Newsom has signed legislation prohibiting public officials from issuing memecoins, adding new restrictions on digital assets connected to government officials and expanding the state’s cryptocurrency fraud enforcement framework. Assembly Bill 2409, signed on Sept. 27, prevents covered California public officers and employees from issuing memecoins. It also restricts digital asset service providers from listing certain memecoins for California residents when those tokens are offered by or in partnership with federal, state or local public officials. The listing restriction applies to qualifying coins issued on or after Jan. 1, 2027. KEY TAKEAWAYS CALIFORNIA TARGETS OFFICIAL-LINKED MEMECOINS AB 2409 defines a memecoin as a digital asset associated with internet memes, characters, current events or trends and promoted to attract an online community interested in buying and trading it. The legislation specifically targets the intersection between public office and these types of speculative digital assets. The law does not constitute a blanket prohibition on memecoins in California. Instead, its restrictions focus on coins connected to public officials and certain government employees. Under the enacted legislation, a digital asset service provider cannot list for sale to a California resident a qualifying memecoin issued from Jan. 1, 2027, when it is offered by or in partnership with a federal public official or a state or local public officer. The law also provides for civil enforcement by the California attorney general, district attorneys, city attorneys and county counsel. The legislation therefore creates a distinction between ordinary memecoins and those tied directly to political or government figures. NEWSOM POINTS TO TRUMP’S CRYPTO ACTIVITIES Newsom’s announcement explicitly framed the new law against the backdrop of Trump’s TRUMP memecoin. In his statement, Newsom argued that public officials should not financially benefit from their government positions. “While the scam that is Donald Trump continues to hurt American families, California is fighting to make our economy work for people, not the powerful,” Newsom said. “No official should profit off their office.” Those comments are part of Newsom’s stated rationale for the legislation and his broader criticism of Trump’s cryptocurrency activities. The California governor’s office cited reporting that nearly one million people who bought the TRUMP token had collectively lost more than $3 billion, while Trump received approximately $636 million in proceeds. The law itself, however, establishes restrictions based on the status of the issuer and the relationship between the token and a public official rather than naming a specific cryptocurrency. CALIFORNIA ALSO EXPANDS CRYPTO FRAUD ENFORCEMENT The memecoin legislation was signed alongside a broader package of consumer protection and accountability measures. Among them is Senate Bill 1208, which addresses money laundering involving digital assets. The law expands the definition of money laundering, through Jan. 1, 2032, to include certain transactions involving digital assets. California Attorney General Rob Bonta said the measure is intended to provide prosecutors and law enforcement with another mechanism for recovering stolen digital assets for victims of cryptocurrency fraud. California has also previously required certain public officials to disclose cryptocurrency and other digital financial assets when those holdings could create a disqualifying financial interest, according to Newsom’s office. WHAT THE NEW RULES MEAN FOR CRYPTO The legislation introduces additional compliance requirements for digital asset businesses serving California residents, particularly those handling tokens associated with public officials. AB 2409 became law after being chaptered by California’s Secretary of State on Sept. 27 as Chapter 473 of the 2026 statutes. Its restrictions on qualifying newly issued official-linked memecoins begin in 2027. The development also illustrates how US states are addressing specific cryptocurrency activities while federal lawmakers continue debating broader digital asset rules. CONCLUSION California’s new memecoin law focuses on a narrow category of digital assets: those issued or promoted in connection with public officials. Rather than banning memecoins generally, AB 2409 restricts public officials from issuing them and limits the ability of digital asset service providers to offer qualifying official-linked tokens to California residents. Combined with SB 1208’s expanded money-laundering provisions, the measures give California additional legal tools for addressing cryptocurrency related conflicts of interest and fraud while imposing new obligations on parts of the digital asset industry.