BTC…ETH…ETH gas…Fear & Greed…Live data · not advice

Ledgers Academy Letter

The Quiet Ledger: Issue #8 | 2 October 2026

The Bitget forensic reports showed a breach that never touched a private key, and a day later the SEC proposed where investment advisers may hold client crypto. A quiet week for price in which custody was the only real subject.

Subject: Bitget's attacker never stole a key, and the SEC has just proposed who may hold one
Preview: The forensic reports landed on Wednesday: the way in was a security product, and the keys signed what they were told. On Thursday the SEC proposed where investment advisers may keep client crypto.

THE QUIET LEDGER

Issue #8 | Saturday 26 September to Friday 2 October 2026
A week in which the price barely moved and custody was the only subject: the Bitget forensic reports showed a breach that never touched a private key, and the SEC proposed crypto custody rules for investment advisers and funds

Reporting window Saturday 26 September to Friday 2 October 2026. Data cutoff 06:45 UTC on Friday 2 October (08:45 Europe/Stockholm). Prices are CoinGecko 00:00 UTC snapshots unless stated. US fund flows cover the four completed sessions from Monday to Thursday; Friday's session is pending, and so is the US September jobs report, due at 12:30 UTC today.

Bitcoin's daily snapshots spanned only about $1,360 this week, while the important news happened in rulebooks and incident reports. The forensic reports on Bitget's breach arrived on Wednesday and showed that the attacker never needed a private key: it took over the machine that asks for signatures. The next day the SEC proposed crypto custody rules for investment advisers and funds, a step-by-step answer to where a professional may keep a client's coins. Our reading is that custody, not price, is now where crypto's real decisions are made, and this was the week four jurisdictions started writing them down.

A five column timeline of the working week from Monday 28 September to Friday 2 October 2026, with events tagged red when they concern one exchange's custody under repair and green when they concern a rulebook deciding who may hold crypto. Monday: green, the CFTC registers Coinbase Clearing for fully collateralised products only; green, SEC staff narrow their token buyback guidance; red, Bitget reopens bitcoin withdrawals. Tuesday: red, about 463 million dollars of net outflow from Bitget in 24 hours; red, a 131 percent reserve snapshot. Wednesday: red, forensic reports find the attacker entered through two third party security products; green, the US Treasury issues the first binding GENIUS Act rule; green, the UK FCA opens its crypto gateway; green, ESMA sets out its MiCA review requests. Thursday: green, the SEC proposes crypto custody rules for advisers and funds; green, Brazil makes self custody transfers of 10,000 dollars or more reportable. Friday: red, Bitget's final withdrawal phase scheduled for 08:00 UTC; grey, the US jobs report due at 12:30 UTC and pending. A footer reads: one exchange spent the week repairing custody while four jurisdictions wrote down the terms for it.
The working week at a glance. Each item is sourced in the sections below.

1. The Macro Pulse

  • Bitcoin: $84,842 at 00:00 UTC on Friday, up about 0.9 percent from $84,076 a week earlier. An intraday reading of $86,050 at 06:34 UTC puts the week nearer 2.4 percent.
  • Ether: $2,705 at 00:00 UTC, up about 0.5 percent, having sat within $30 of $2,690 all week.
  • Fear and Greed: 72, Greed, up one point from 71 the previous Friday, and between 70 and 74 every day.
  • US spot ETFs, four completed sessions: bitcoin funds took about $51.3 million net; ether funds lost about $100.7 million. Wednesday's $148.7 million bitcoin outflow ended a nine-session streak worth about $3.08 billion. Friday is pending.
  • Rates: the 10-year Treasury yield rose from 5.17 percent to 5.29 percent on Wednesday, the same day as the bitcoin outflow, before easing to 5.24. August core PCE came in at 3.0 percent a year, and the Reserve Bank of Australia raised its cash rate to 4.60 percent on Tuesday.
A three row dashboard for 26 September to 2 October 2026. Top: bitcoin at 00:00 UTC each day, 84,076 dollars on 26 September, 84,417 on 27 September, 84,449 on 28 September, 83,479 on 29 September, 83,640 on 30 September, 83,576 on 1 October and 84,842 on 2 October. Middle: daily net flows into US spot ETFs, bitcoin and ether side by side. No session at the weekend. Monday 28 September bitcoin plus 31.1 million dollars, ether plus 17.1 million. Tuesday bitcoin plus 66.2 million, ether minus 2.8 million. Wednesday bitcoin minus 148.7 million, ending a nine day streak worth about 3.1 billion, ether minus 59.6 million. Thursday bitcoin plus 102.7 million, ether minus 55.4 million. Friday pending. Four session totals plus 51.3 million for bitcoin funds and minus 100.7 million for ether funds. Bottom: the 10-year Treasury yield at each close, 5.17 percent on 25 September, 5.24 on 28 September, 5.26 on 29 September, 5.29 on 30 September, the week's high, and 5.24 on 1 October.
Prices are CoinGecko daily snapshots. Flows are SoSoValue figures as reported by TokenPost and KuCoin News. Yields from the US Treasury daily par yield curve.

The takeaway: after September brought about $2.65 billion into the bitcoin funds, the first week of the new quarter was close to flat, and the one heavy outflow day coincided with the week's highest long-term yield. That is a description of a completed week.

2. This Week in Headlines

Washington: custody and stablecoins get rules

The SEC proposed crypto custody rules for advisers and funds on Thursday, covered in the deep dive below. On Wednesday the Treasury published the first binding rule under the GENIUS Act, an interim final rule setting out how states get their stablecoin regimes certified as substantially similar to the federal one. It opens the state route for issuers with less than $10 billion outstanding.

The CFTC registered Coinbase Clearing on Monday, limited to fully collateralised futures, options and swaps, as our Monday Daily Ledger explained. The same day SEC staff narrowed their token buyback answer: a buyback is outside the "essential managerial efforts" test only on a functional network that "has no central party".

Outside the United States

The UK Financial Conduct Authority opened its crypto authorisation gateway on Wednesday. Firms that want to keep operating should apply by 28 February 2027, the regime starts on 25 October 2027. Authorisation is not automatic. The European Securities and Markets Authority published its MiCA review requests the same day: stricter rules for influencer marketing, disclosure for staking and lending, and clearer criteria for when decentralised finance is genuinely decentralised.

Brazil's Resolution BCB 588 took effect on Thursday. Regulated institutions must now report transfers of at least the equivalent of $10,000 to or from self-custody wallets to COAF, the financial intelligence unit. It is a reporting duty, not a ban or a limit.

Institutions and protocols

Strategy's 8-K reported 1,665 bitcoin bought for $142.7 million at an average of $85,681, taking it to 847,666, funded by selling common stock. BitMine passed six million ether, most of it staked. Bitwise listed a spot NEAR fund that stakes its holdings, and Goldman Sachs made its $100 billion Treasury fund available on Lynq, a permissioned Avalanche network. On Ethereum, the Glamsterdam upgrade is scheduled for the Sepolia test network on 6 October at 13:53 UTC, with mainnet undated.

3. The Weekly Deep Dive: the SEC crypto custody rule for investment advisers

An investment adviser who manages your money and can move it is said to have custody, and the Advisers Act custody rule requires such an adviser to keep client assets with a qualified custodian, such as a bank, a registered broker-dealer or a futures commission merchant. That works for shares. For many crypto assets, as the SEC's own fact sheet concedes, no permitted custodian exists, and whether a state-chartered trust company counts as a "bank" has been a case-by-case legal question. Advisers have had to choose between avoiding crypto and accepting legal uncertainty.

How the proposed SEC crypto custody rule would work

The proposal sets out three tiers, each used only when the one before is unavailable.

A three step ladder showing where a registered investment adviser could hold client crypto under the SEC's 1 October 2026 proposal. Step one, allowed today: a bank or other qualified custodian already permitted under the current rule, with a note that for many tokens no such custodian exists. Step two, new: a state trust company, if before hiring it and yearly the adviser has a reasonable basis to believe its state banking regulator authorises it to hold crypto and that it runs written safeguarding policies, and reviews its audited accounts and internal control report, with client assets segregated from the trust company's own. Step three, new and conditional: the adviser holds the asset itself, only if no permitted custodian is available, checked before and every quarter, documenting safeguarding expertise, requiring two people to approve every transaction, keeping each client in separate addresses, obtaining an accountant's control report within six months and yearly, reviewing cyber controls yearly and sending quarterly statements, with a fund's board reviewing the no custodian finding each quarter. A footer notes that this is a proposal with a 60 day comment period after Federal Register publication.
Conditions abbreviated from SEC release 2026-100 and fact sheet IA-7023. The proposing release has the exact text.

First, an existing qualified custodian. Second, a state trust company, provided the adviser checks every year that its state banking regulator authorises it to hold crypto, reviews its audited accounts and control report, and keeps client assets separate from the trust company's own. Third, only where no permitted custodian is available, the adviser may hold the asset itself, under the heaviest conditions: re-check the absence of a custodian every quarter, require at least two people to authorise every transaction, keep each client in separate addresses, obtain an independent accountant's control report, and agree in writing to treat the asset as a "financial asset" under state law. A fund's board must review that finding each quarter.

Why this week, and where it falls short

The timing is coincidence; the overlap is not. The two-person authorisation rule is a direct control against the failure in Bitget's forensic reports, where a compromised machine issued withdrawals that nobody had approved. Our reading is that the proposal asks advisers for exactly the human check that an automated withdrawal layer is built to do without.

The limits are real. This is a proposal, with comments open for 60 days after Federal Register publication, and nothing changes until a final vote. The self-custody test is one the adviser applies to itself. Per-client addresses improve traceability but multiply the keys to protect, and state trust company supervision differs by state. None of this applies to your own wallet: the rule governs professionals holding other people's assets.

What you can check: if an adviser manages crypto for you, ask which tier your assets would sit in and who the custodian is, and read the adviser's Form ADV on the SEC's adviser search. The proposal would add crypto custody questions to that form.

4. Security and Onchain Radar

Bitget published two forensic reports on Wednesday. Mandiant's status report found that the attacker gained privileged access to two third-party security appliances, planted a web shell, and moved from there to the production wallet job server. SlowMist's progress report traces the earliest malicious activity to 31 August, a zero-day in one of those products, and recovered a custom tool that forged the withdrawal system's risk-control parameters.

A five step chain reconstructed from the Mandiant and SlowMist reports on the Bitget breach, times in UTC. One, 31 August: a zero day in a service on a node of security Product A is used to read a database password, with similar activity on two more nodes on 23 and 25 September. Two, 24 September from 16:07: an employee's identity opens Product B's management platform, followed by command injection, a web shell and a command and control link. Three: a lateral move from the appliance to the production wallet job server, where malicious packages are installed. Four, 17:49: a custom withdrawal tool forges the risk control parameters and calls the normal withdrawal process. Five, 18:31 to 21:23: transfers run for about 2 hours 52 minutes across several chains from the minute monitoring detected them, and two forged bitcoin withdrawals fail. Boxes note that Bitget saw no evidence that private keys were compromised and its cold wallets were untouched, and that the first foothold was 24 days old when the money moved. A footer gives the loss as between 351.6 and 387.5 million dollars, about 1.1 million frozen, and notes that attribution to North Korea is an assessment by Bitget and Elliptic rather than a finding of either report.
Reconstructed from the Mandiant report dated 28 September and the SlowMist report dated 29 September 2026, both published on 30 September. UTC+8 times converted to UTC.

Confirmed: a loss Bitget puts between $351.6 million and $387.5 million, no evidence of compromised private keys, cold wallets untouched, transfers running for nearly three hours after detection, and about $1.1 million frozen by issuers. Not confirmed: the vendors, which neither report names, and the attacker. Bitget and Elliptic point to North Korea; Mandiant does not attribute. Elsewhere, NEAR Intents pledged full compensation after a bridge bug drained about $3.8 million, and a counterfeit of an unlaunched network drew about 768 ETH from 1,335 addresses.

The lesson is that a signing key is only as safe as whatever is allowed to give it instructions. The rules:

  • Keep on any exchange only the balance this week's activity needs. This attacker held a foothold for 24 days before the money moved.
  • On your own hardware wallet, approve only what the device's own screen shows you, and refuse anything it cannot display. That is the personal version of the same failure, covered in our note on blind signing.
  • For shared or business funds, require two approvers for every outgoing transaction, the same control the SEC proposal demands.
  • Treat anyone offering to recover funds for a fee as the next attack.

5. From the Academy Library

Splitting signing authority between people or devices is explained in MPC wallets, and what a reserve snapshot can and cannot prove in proof of reserves. The American and European rulebooks are mapped in the crypto tax and regulatory guide, last week's question about who holds the coins in a fund is in Issue #7, and new readers can start at Academy School.

Three useful, non-affiliate tools: the SEC's Investment Adviser Public Disclosure search for any adviser's Form ADV, the FCA's Financial Services Register for checking a UK firm's status, and the full proposing release, the only source for the exact conditions.

Dates to keep

  • Today, 08:00 and 12:30 UTC: Bitget's final scheduled withdrawal phase, then the US September jobs report.
  • 6 October: Glamsterdam on the Sepolia test network.
  • 27 and 28 October: the next Federal Reserve meeting.
  • 30 November: comments close on the Treasury's state stablecoin rule.
  • 28 February 2027: the FCA's application deadline for firms that want to keep operating in the UK.

The money barely moved this week and the rules moved a great deal. A hack that never touched a key and a proposal requiring two people to approve every transaction arrived two days apart, and between them they describe where crypto's risk now sits.

Disclaimer: This publication is for education and information only. It is not financial, investment, legal, tax, or security advice.

Sources and further reading

Regulation and policy

Security

Institutions and protocols

Markets and macro

Keep reading

Recent letters

The Daily Ledger: 1 October 2026

September was 2026's costliest month for crypto theft, at about $768.4 million on CertiK's count, and two incidents produced roughly 92 percent of it. Net of the 3,400 bitcoin an attacker returned, the month's unrecovered cost is closer to $497 million.

Read letter →

The Daily Ledger: 30 September 2026

August core PCE rose 0.2 percent on the month and 3.0 percent on the year, below expectations, trimming the case for an October rate rise. Bitcoin spiked to about $85,600 and gave the whole move back, closing its best quarter since early 2024 at roughly 42.7 percent.

Read letter →

The Daily Ledger: 29 September 2026

Bitget covered the loss, reopened bitcoin withdrawals, and about $463 million of net outflow followed in 24 hours, its largest single day on record. Nobody was left out of pocket, and customers left anyway, because a covered loss still proves the loss was possible.

Read letter →

The Letter

One clear letter, every week.

Plain analysis of crypto infrastructure, markets and security. No price calls, no referral links, no hype.

Unsubscribe at any time. Read the privacy notice.

Reader reviews

Did you like what you just read?

Tell other readers what worked, what did not, and who you would recommend it to. Every review is read by a human before it is published, and critical reviews get the same treatment as glowing ones.

Leave a review →