Crypto Enforcement Watch: The DOJ Turns Toward Binance Itself, 52.37 Bitcoin Reaches a Wyoming Trust, and Brussels Is Asked to Rewrite Stablecoin Reserves
Four developments in the past two days matter for anyone holding or building in crypto: a criminal inquiry that turned toward Binance itself, 52.37 recovered bitcoin placed in a trust meant to give it back, a push to rewrite Europe’s stablecoin reserve rules, and a $2 million drain that involved no broken code. Here is what each one changes.
Manhattan Prosecutors Now Ask What Binance Knew
Bloomberg reported early on September 22 that the U.S. Attorney’s Office for the Southern District of New York, with the Justice Department’s Criminal Division, is investigating whether Binance violated U.S. sanctions on Iran by failing to stop certain trading. Binance said it has zero tolerance for sanctions violations and cooperates with law enforcement. An investigation is not a charge, and many close without one.
The shift matters. Earlier reporting described prosecutors asking whether Iranian users abused the platform; this describes them asking whether the exchange knew and did nothing. That lands harder because Binance pleaded guilty in November 2023, paid roughly $4.3 billion, and accepted independent compliance monitors. Conduct after a resolution like that is judged on a different scale.
52.37 Bitcoin From the Coldcard Exploit Reaches a Wyoming Trust
On September 21, Galaxy Research’s Alex Thorn disclosed that white-hat operators consolidated 52.37 BTC recovered from the Coldcard entropy exploit into an address held by Crypto Recovery Trust, a Wyoming statutory trust created to return compromised assets to verified owners. Against high-confidence losses of 1,789.28 BTC across 8,865 addresses, this is a sliver. The structure is the notable part: rescuing coins is the easy half, and what follows is ownership review, source-of-funds work, sanctions screening, and notice. Victims claim by signing a message from the affected wallet, not by handing over keys.
Europe’s Central Banks Ask Brussels to Rewrite Stablecoin Reserves
The European System of Central Banks filed its response to the Commission’s MiCA review consultation on September 22, asking lawmakers to delete the fixed deposit quotas. Article 54 requires at least 30% of e-money token funds to sit in bank deposits, with a floor for significant tokens that cannot fall below 60%. The ESCB would substitute a liquidity test keyed to one-day and five-day maturities. It leaves alone the Article 49 right to redeem at par and the Article 50 interest ban, which it wants kept even for indirect yield. Nothing changed on filing; issuers remain bound by Article 54.
One Valid Signature, Two Protocols, About $2 Million
Blockaid reported on September 20 that one wallet drained roughly $1.56 million in FET from Fetch.ai’s TokenConversionManagerV3 contract using a valid conversion-authorizer signature, and received about $452,000 of NuNet’s NTX minted from that project’s deployer. NTX fell more than 70% to an all-time low of $0.000328. Legally the mechanism matters more than the number: nothing was broken. Valid credentials did something the protocol permitted, which fits poorly with insurance language written around unauthorized access, and which moves the inquiry from code quality toward key custody and signer controls, where a standard of care is easier to state and breach easier to prove.
How to Protect Yourself
If you generated a seed on a Coldcard before the firmware fix, updating firmware does not repair it: create a new seed on patched firmware and migrate funds, ideally behind a passphrase or multisig. Check your addresses against the recovery trust’s public tool, and treat any recovery service asking for your seed phrase or an upfront fee as a second fraud. Projects should inventory who holds signing authority over mint and upgrade functions.
On recourse, document early: transaction hashes, wallet addresses, device model and firmware version, and correspondence. Report losses to the FBI’s Internet Crime Complaint Center and your state regulator. Limitations periods often begin earlier than victims assume, and tracing gets harder once funds pass through a mixer or bridge. Where a recovery trust or forfeiture proceeding exists, claims run on a deadline counsel can help you meet.
At Coin Counsel, we work with individuals and businesses navigating the legal fallout of crypto fraud — whether you’re a victim seeking recovery, a company facing regulatory scrutiny, or a project working to stay compliant in an increasingly complex legal landscape. The rules are evolving fast, and the cost of getting it wrong has never been higher. Contact us at coin-counsel.com to speak with a crypto-focused attorney today.
Disclaimer
This blog post is for informational purposes only and does not constitute legal advice. Reading this content does not create an attorney-client relationship between you and Coin Counsel or Franco Law PLLC. The legal landscape surrounding cryptocurrency is rapidly evolving and varies by jurisdiction. Do not act or refrain from acting based on information in this post without first consulting a qualified attorney. If you believe you have been the victim of crypto fraud, contact us at coin-counsel.com for a consultation.