• Home
  • About Us
  • Contact Us
  • Cookies Policy
  • Disclaimer
  • DMCA
  • Privacy Policy
  • Terms and Conditions
Dr Crypton
Secure Your Future in Crypto
Tech & Startup News

Just to be safe, put two rings on it

by admin September 19, 2026
written by admin

For decades, the scientific community operated under the assumption that planetary rings were an exclusive feature of the solar system’s gas giants. Jupiter, Saturn, Uranus, and Neptune—the massive outer planets—were the only known entities surrounded by debris disks, a paradigm that suggested ring formation required the immense gravitational influence of a gas-shrouded behemoth. That long-held consensus was shattered in 2013, when astronomers discovered that a small, dark body known as Chariklo, orbiting in the frigid expanse between Saturn and Uranus, possessed its own set of narrow, distinct rings. This revelation transformed our understanding of celestial mechanics, suggesting that ring systems are far more common in the solar system than previously imagined.

A decade later, new observations from the James Webb Space Telescope (JWST) have revealed that these rings are not static relics of a collision. Instead, they are dynamic, evolving structures that are currently undergoing significant and mysterious physical changes.

The 2013 Discovery and the Mechanics of Occultation

Chariklo, a Centaur—a class of icy minor bodies that cross the orbits of the giant planets—is roughly 250 kilometers in diameter. Its ring system was first identified through the technique of stellar occultation. This method involves waiting for a minor body to pass directly in front of a distant background star from the perspective of Earth. As the object blocks the starlight, observers can measure the dip in luminosity. If an object has rings, the starlight is blocked briefly before and after the main occultation event, creating a distinct "blinking" pattern.

In 2013, ground-based telescopes detected two narrow, dense rings around Chariklo, designated C1R and C2R. These rings sit at approximately 390 and 405 kilometers from the center of the body. They are notably narrow—only a few kilometers wide—and separated by a gap of roughly seven kilometers. The discovery was met with surprise, prompting researchers like Pablo Santos-Sanz of the Instituto de Astrofísica de Andalucía to investigate the composition, stability, and longevity of such structures.

The JWST Campaign: Pushing the Limits of Precision

The recent study, published in Science Advances, utilized the unprecedented sensitivity of the James Webb Space Telescope to re-examine Chariklo during an occultation event on October 18, 2022. Conducting such an observation from space is a logistical feat of extreme complexity. Because JWST is stationed at the second Lagrange point (L2), it requires regular station-keeping maneuvers to maintain its orbit. Aligning the telescope to catch a celestial object as small as Chariklo—which occupies a minuscule portion of the sky—requires precise predictive modeling weeks in advance.

Rings around a tiny body have changed over the past decade

The team faced significant challenges. Between the initial prediction and the event, the projected line of sight shifted by 110 kilometers, nearly missing the object entirely. Because JWST observations must be scheduled 14 days ahead of time, the team operated with limited room for error. Ultimately, the geometry was perfect: the telescope’s sightline skimmed just 7.4 kilometers above the surface of Chariklo, effectively bypassing the main body to focus exclusively on the rings.

Evidence of Rapid Evolution

The data returned by the JWST provided a high-resolution glimpse into the rings, recorded simultaneously in two near-infrared bands at 1.5 and 3.2 micrometers. This was the first time a minor body’s rings had been observed at wavelengths beyond 3 micrometers, a range typically absorbed by Earth’s atmosphere and inaccessible to ground-based observatories.

The findings were unexpected. The inner ring, C1R, appeared significantly darker and denser than in any previous observation. Averaged over ten years of ground-based data, the normal opacity—a measurement of how much starlight the ring blocks—was roughly 0.303. The JWST measurement recorded an opacity of 0.431. To ensure this was not a measurement error or a result of observing a particularly "clumpy" section of the ring, the research team conducted 10 million simulated occultations. They concluded that the probability of these high opacity values being a result of random chance was statistically negligible.

Simultaneously, the outer ring, C2R, appeared to be fading. It was barely visible at 1.5 micrometers and vanished entirely at 3.2 micrometers. This disparity suggested a genuine physical evolution rather than a mere observational anomaly. When researchers analyzed the data using radiative transfer models, they found that no combination of known material properties or grain sizes could reconcile the current state of the rings with their previous appearance. The conclusion, according to Santos-Sanz, is that the rings are actively changing.

Hypotheses and the "Ghost Moon" Theory

The rapid change in the rings’ structure—specifically the thickening of the inner ring and the degradation of the outer one—has sparked several theories. A leading hypothesis involves the presence of a small, as-yet-undetected shepherd moon. In planetary science, shepherd moons are small satellites whose gravitational influence confines ring material, maintaining sharp edges and preventing the debris from dissipating into space.

If such a moon exists within or near the outer ring, it could be responsible for both the stability of the system and the potential migration of material. However, this does not fully explain why the inner ring gained significantly more material than the outer ring lost. The "equivalent width" of the inner ring increased by roughly ten times the amount the outer ring lost, suggesting that there may be other sources of debris replenishment, such as collisions between smaller fragments or cryovolcanic activity on Chariklo itself.

Rings around a tiny body have changed over the past decade

Broader Implications for Solar System Science

The discovery that Chariklo’s rings are dynamic shifts the conversation regarding minor bodies in our solar system. We now know that ring systems exist around a variety of objects beyond the giant planets, including the Centaur Chiron, the dwarf planet Haumea, and the trans-Neptunian object Quaoar.

This phenomenon of "shifting" rings is not unprecedented; observations have shown that the rings of giant planets also change over time. Saturn’s D ring, for instance, has shown measurable contraction, and the rings of Neptune exhibit "arcs" that rearrange themselves over months. The realization that small bodies like Chariklo follow similar patterns suggests a universal mechanism for ring formation and maintenance.

The scientific community now views the rings of Chariklo as a crucial piece of a much larger puzzle. Understanding these systems provides insight into the early solar system’s history, the behavior of icy bodies in the Kuiper Belt, and the gravitational interactions that dictate the architecture of orbital debris.

Future Research Directions

As researchers continue to analyze the JWST data, the focus is shifting toward determining the exact composition of the rings. Preliminary models suggest that the inner ring is composed of larger, more solid particles, while the outer ring appears to be dominated by fine, dusty material. These results remain a work in progress.

The next step for the research team is to capture another occultation, ideally using visible light to corroborate the infrared findings. By comparing data across different electromagnetic spectra, scientists hope to isolate the effects of material scattering from the physical changes in the rings’ density.

As Santos-Sanz noted, this work is an important clue for broader studies. It demonstrates that the outer reaches of our solar system are far more active and complex than previously suspected. The rings around Chariklo are not static ornaments; they are evolving, breathing components of a minor world that continues to challenge our fundamental understanding of space. The study serves as a reminder that even the smallest celestial objects can hold the key to understanding the large-scale processes that govern the evolution of the solar system.

September 19, 2026 0 comment
0 FacebookTwitterPinterestEmail
Tech & Startup News

UmanWrite Lifetime Unlimited Plan Drops to $63.20 in Limited-Time Promotional Sale

by admin September 19, 2026
written by admin

The landscape of digital content creation has undergone a profound transformation over the past several years, driven largely by advancements in generative artificial intelligence. While tools like ChatGPT, Claude, and specialized writing assistants have revolutionized how individuals and enterprises brainstorm, outline, and draft textual material, a persistent challenge remains: the distinct, often mechanical uniformity of AI-generated prose. Readers, editors, and search engines have grown increasingly adept at identifying the standardized cadence, predictable vocabulary, and formulaic structures characteristic of raw artificial intelligence output. In response to this industry-wide hurdle, a new generation of software solutions has emerged, focused specifically on personalizing and humanizing machine-generated text. Among these platforms is UmanWrite, a comprehensive writing and editing suite that allows users to train artificial intelligence models on their unique writing samples. For a limited window ending September 20 at 11:59 p.m. PT, the platform is offering its lifetime UmanWrite Premium Unlimited Plan at a drastic discount, lowering the standard retail price of $1,799 down to $63.20 for customers who apply the promotional code SAVE20 at checkout.

The Evolution of AI Writing and the Search for Authenticity

To understand the value proposition of platforms like UmanWrite, one must examine the rapid trajectory of generative text models since their mainstream proliferation in late 2022. Initially, the primary metric of success for artificial intelligence writing tools was sheer output speed and grammatical correctness. Content creators, copywriters, and corporate communications departments quickly integrated these systems into their daily workflows to accelerate the production of first drafts, email templates, and marketing copy.

However, as the volume of AI-assisted content flooded the internet, diminishing returns quickly set in. Audience engagement began to suffer as readers encountered repetitive phrases, overly formal transitions, and a general lack of authentic voice. Furthermore, search engine algorithms and academic institutions began deploying sophisticated detection mechanisms to flag and penalize unedited machine-generated material. This dynamic created an acute demand for intermediary solutions—tools that could harness the efficiency of large language models while retaining the stylistic nuances, emotional resonance, and vocabulary of individual human authors. UmanWrite was developed to bridge this gap, functioning not merely as a text generator, but as a style-matching ecosystem designed to replicate an author’s distinct linguistic fingerprint.

Core Features and Technological Architecture of UmanWrite

The platform’s primary differentiator is its proprietary Voice Profile system. Rather than relying on a monolithic, one-size-fits-all language model, UmanWrite allows users to upload existing writing samples—ranging from blog posts and academic papers to professional emails and creative fiction—to train custom artificial intelligence profiles. Once calibrated, the software’s context-aware writing tools adapt future generations to match the specific tone, pacing, vocabulary, and stylistic preferences of the user.

Beyond voice replication, the software suite incorporates a dual-purpose mechanism consisting of an AI Humanizer and an AI Detector. The Humanizer module is engineered to restructure sentence syntax, alter predictable word choices, and introduce natural linguistic variations designed to bypass conventional artificial intelligence detection filters. Conversely, the built-in AI Detector allows creators to audit their own drafts prior to publication, ensuring the text does not inadvertently trigger flags from third-party detection software used by educators, publishers, and search platforms.

The ecosystem also functions as a comprehensive editing workspace. It includes an Advanced Grammar Checker that goes beyond basic spell-checking to evaluate clarity, readability, and structural flow. The centralized Writing Studio consolidates these drafting, editing, and humanizing functions into a single interface. Under the terms of the lifetime Unlimited Plan currently on promotion, subscribers are granted unrestricted monthly word generation, with the capacity to process requests of up to 2,500 words in a single prompt, removing the tiered word caps typically imposed by software-as-a-service (SaaS) competitors.

Market Implications for Freelancers, Marketers, and Enterprises

The steep price reduction of the UmanWrite Unlimited Plan arrives at a time when software subscription fatigue is a growing concern for independent professionals and small businesses alike. Modern digital workflows often require separate monthly financial commitments for grammar assistants, SEO optimizers, stock media, and generative AI platforms, with cumulative costs frequently exceeding hundreds of dollars per year.

By offering a lifetime access model for a one-time fee of $63.20—representing a savings of more than $1,735 off the standard list price—the platform targets cost-conscious freelancers, digital marketing agencies, and corporate communications teams looking to streamline overhead expenses.

For freelance writers managing multiple clients, the ability to maintain separate Voice Profiles within a single dashboard offers significant operational efficiency. A freelancer can effortlessly switch between a formal, academic tone for one client and a conversational, casual voice for another without manually recalibrating prompts. Similarly, digital marketers can leverage the software to rapidly generate targeted ad copy, email newsletters, and search engine optimization (SEO) articles tailored to distinct consumer demographics while preserving brand consistency. Small businesses handling internal and external correspondence can likewise deploy the tool to standardize customer communications, public relations releases, and social media campaigns without sacrificing the human element crucial for brand loyalty.

Industry Analysis and the Future of AI Integration

The promotional pricing strategy employed for the UmanWrite lifetime plan reflects a broader shift in the software industry’s distribution models. As the market for artificial intelligence applications becomes increasingly saturated, vendors are utilizing aggressive promotional pricing through third-party deals platforms like StackSocial to rapidly acquire market share and user data.

Industry analysts note that while lifetime subscription models provide immediate financial relief to consumers by eliminating recurring monthly overhead, they also place long-term operational demands on software developers to continuously update their underlying architecture without the predictable revenue stream of traditional SaaS frameworks. For UmanWrite, the success of this promotional push will depend on its ability to continually refine its natural language processing capabilities to keep pace with rapid advancements in foundational large language models.

Nevertheless, tools that prioritize stylistic customization over generic generation represent the logical next phase of text-based technology. As consumers become increasingly immune to standardized machine-written copy, the competitive advantage in digital communication will increasingly belong to those who can effectively blend algorithmic efficiency with authentic human expression. The promotion for the UmanWrite lifetime Unlimited Plan remains active until September 20 at 11:59 p.m. PT, providing a limited window for professionals to evaluate whether style-matched artificial intelligence can successfully integrate into their existing production pipelines.

September 19, 2026 0 comment
0 FacebookTwitterPinterestEmail
Artificial Intelligence & Tech

New insights from Google’s AI & Economy ATLAS

by admin September 19, 2026
written by admin

The Evolution of the ATLAS Project

The AI & Economy ATLAS project was launched as a long-term research endeavor designed to demystify the "black box" of AI integration in the workforce. Since its inception, the initiative has sought to address the lack of empirical, large-scale data regarding how AI is being deployed in real-world settings. By aggregating millions of data points, Google has created a digital repository that allows policymakers, academics, and industry leaders to visualize trends in AI adoption.

This project is a response to the growing demand for data-driven insights into the "AI revolution." While much of the public discourse has been dominated by speculation regarding job displacement, the ATLAS project focuses on the reality of workflow augmentation. The newly launched interactive interface marks a significant milestone in this mission, moving beyond static reports to provide a dynamic environment where users can filter data by country, industry, and specific occupational tasks.

Mapping the AI-Enabled Workforce

One of the most striking findings from the updated ATLAS data is the uneven but pervasive nature of AI adoption. The data demonstrates that AI is not a monolith; its utility varies wildly depending on the functional requirements of a profession.

In the administrative and corporate sectors, AI is primarily utilized for document summarization, data entry automation, and communication optimization. Conversely, in the trades—such as electrical work or manufacturing—AI is increasingly employed through predictive maintenance tools and augmented reality interfaces that assist in complex diagnostic tasks. By providing this granular view, the ATLAS project dispels the myth that AI is exclusively a tool for "white-collar" knowledge workers. It illustrates a future where machine learning models act as specialized assistants across the entire professional spectrum.

Deep Dive: AI in Scientific Research

Perhaps the most profound implications of the new research, conducted by Google and Google DeepMind in collaboration with MIT FutureTech, concern the scientific community. The study, which analyzes 2,600 specialized AI models and incorporates survey data from over 600 scientists in the United States and the United Kingdom, offers a sober look at the intersection of innovation and technology.

According to the findings, the scientific sector has emerged as a leader in AI adoption. Nearly 50% of surveyed scientists report using some form of AI in their daily workflows. The research differentiates between the use of Large Language Models (LLMs) like Gemini and specialized models. LLMs are proving to be general-purpose tools, used across a wide array of scientific fields for literature review, hypothesis generation, and administrative task management. In contrast, specialized AI models—designed for specific predictive or simulation tasks—are becoming the backbone of health and life sciences. These models allow for the analysis of vast biological datasets that would be impossible to process manually, effectively serving as the modern microscope or centrifuge.

The Productivity Paradox: Time Gains vs. Breakthroughs

A critical takeaway from the Google-MIT research is the concept of the "productivity paradox." Scientists reported an average time saving of approximately seven hours per week—a significant gain that should, in theory, accelerate the rate of scientific discovery. However, the data suggests that these hours are not automatically converted into new breakthroughs.

Instead, the research reveals a shifting bottleneck. As AI accelerates the speed at which hypotheses can be generated and simulations run, researchers are finding themselves bogged down by the necessity of validating AI-generated outputs. The "human-in-the-loop" requirement remains a significant hurdle. Furthermore, while AI can simulate millions of variables, physical experimentation and clinical validation remain slow, capital-intensive processes. The research indicates that the true impact of AI on science will not be realized until institutional workflows are fundamentally redesigned to account for the velocity of AI-assisted research. The current backlog of untested hypotheses is a testament to the fact that AI is currently outpacing the traditional physical infrastructure of scientific discovery.

Global Trends and Regional Disparities

The ATLAS data also highlights significant regional variations in AI adoption. Countries with robust digital infrastructure and high concentrations of service-based industries show higher rates of AI integration. In contrast, emerging economies are currently in the early stages of adoption, primarily focusing on digital literacy and the implementation of foundational AI tools.

Google’s researchers emphasize that this "AI divide" is a crucial metric to monitor. As global markets become increasingly intertwined, the ability of a nation’s workforce to leverage AI will likely dictate its future economic competitiveness. By making this data open-access, Google is providing the raw material for international bodies to develop strategies that ensure the benefits of AI are distributed equitably across the global economy.

Implications for the Future of Work

The broader implications of the AI & Economy ATLAS are clear: the integration of AI is not a singular event but a continuous process of economic restructuring. For the average professional, the data suggests that the focus should shift from "AI replacing jobs" to "AI redefining tasks."

The necessity for continuous upskilling is underscored by the findings. As AI takes over repetitive analytical tasks, the value of human labor is shifting toward high-level validation, ethical oversight, and the design of complex workflows. The research from MIT and Google suggests that the next decade will be defined by how successfully organizations can integrate these new tools into existing structures without creating new bottlenecks.

A Long-Term Vision for Research

Looking ahead, Google has committed to maintaining the ATLAS project as a long-term resource. The company plans to collaborate with academic institutions globally to refine the taxonomy of scientific work and expand the datasets to include more industries and geographic regions.

This commitment to transparency and data-sharing is vital. As the technology continues to evolve at an exponential rate, the ability to track these changes with empirical precision is the only way to avoid the pitfalls of hype and misinformation. By grounding the conversation in objective data, the AI & Economy ATLAS provides a stable platform for navigating the uncertain waters of the AI-driven economy.

Methodological Context

The ATLAS project utilizes a sophisticated methodology to track AI usage, relying on a combination of self-reported survey data and digital trace analysis. The taxonomy developed by MIT FutureTech, which categorizes scientific labor into specific, measurable activities, represents a significant advancement in how we define "work." By mapping these activities to AI capabilities, researchers can pinpoint exactly where AI provides value and where it introduces new forms of friction.

This rigorous approach ensures that the insights generated are not merely anecdotal but are statistically significant representations of the current labor market. As the project evolves, the integration of real-time usage data will likely provide even greater clarity on the trajectory of the global economy.

Conclusion: The Road Ahead

The findings from the latest ATLAS update indicate that we are still in the early innings of the AI era. While the time savings reported by scientists and the adoption rates across various professions are impressive, they represent only the beginning of a larger transformation. The challenge for the coming years will be the systemic redesign of workflows—in science, in business, and in public policy—to effectively channel the potential of AI into tangible progress.

For now, the AI & Economy ATLAS serves as both a map and a mirror: it shows us where we are in the adoption cycle and reflects the challenges we must overcome. By providing this information in an accessible, interactive format, Google is enabling a more informed public discourse, one that is built on evidence rather than speculation. As the global community continues to experiment with these powerful tools, the data provided by ATLAS will remain an essential guide to understanding the profound, and often complex, shifts occurring in the global economy. Whether in the laboratory, the office, or the studio, the message from the data is clear: the future of work is not just about using AI, but about understanding how to integrate it effectively into the human experience.

September 19, 2026 0 comment
0 FacebookTwitterPinterestEmail
Cryptocurrency News

EU Cyber Resilience Act Imposes Strict 24-Hour Vulnerability Reporting Window for Software and Crypto Wallet Manufacturers

by admin September 19, 2026
written by admin

The European Union’s sweeping Cyber Resilience Act (CRA) has officially entered a critical phase of practical implementation, fundamentally altering how technology companies operating within the European single market must respond to active cybersecurity threats. Under the newly enacted framework, manufacturers of products with digital elements—ranging from mainstream enterprise software to commercial cryptocurrency hardware wallets—face a rigid mandate: they must issue an early warning to regulatory authorities within a mere 24 hours of discovering that a vulnerability in their product is being actively exploited in the wild. This aggressive timeline marks a definitive departure from traditional vulnerability disclosure models, which historically allowed engineering and security teams weeks, or even months, to investigate, patch, and quietly deploy fixes before notifying the public or oversight bodies.

The introduction of the 24-hour reporting window underscores a broader paradigm shift in European cybersecurity policy. Rather than prioritizing perfection or comprehensive technical post-mortems before reporting, the EU regulatory apparatus now prioritizes early notification and systemic containment. This statutory requirement is not a standalone piece of legislation; rather, it sits as a cornerstone within the much larger, highly comprehensive architecture of the Cyber Resilience Act. Designed to cover virtually all hardware and software products connected to devices or networks sold into the European market, the CRA aims to eliminate weak security links across the entire digital supply chain. For software developers, device manufacturers, and specialized tech sectors alike, compliance with the CRA is no longer a distant future concern; it is an active operational reality that demands immediate restructuring of internal incident response procedures.

Background and Legislative Evolution of the Cyber Resilience Act

To fully understand the gravity of the 24-hour reporting rule, it is essential to examine the regulatory trajectory that brought the Cyber Resilience Act into existence. For decades, the European Union relied on a patchwork of sector-specific directives and voluntary guidelines to govern cybersecurity standards for digital products. While frameworks such as the General Data Protection Regulation (GDPR) set high bars for data privacy, and the Network and Information Security (NIS) directives established baseline security for critical infrastructure operators, consumer-grade software and connected devices largely operated in a regulatory wild west.

As the Internet of Things (IoT) expanded exponentially and software supply chain attacks—such as the infamous SolarWinds breach and widespread open-source library vulnerabilities like Log4j—began to paralyze global commerce, Brussels recognized a glaring legislative gap. Manufacturers could flood the European market with cheap, digitally connected devices and software carrying severe, unpatched security flaws without facing meaningful legal liability.

The legislative journey of the CRA began in earnest in September 2022, when the European Commission formally proposed the regulation. Recognizing that digital vulnerabilities do not respect national borders and that a compromised consumer device or enterprise software package can serve as an entry point for massive cyberattacks, EU lawmakers crafted a law centered on harmonized security rules. Following extensive negotiations between the European Parliament, the Council of the European Union, and various industry stakeholders, the CRA was refined to balance rigorous security mandates with commercial viability.

Throughout 2023 and 2024, the legislation moved through the final stages of approval, culminating in its formal adoption and publication in the Official Journal of the European Union. The rollout of the CRA has been structured in phases, allowing organizations time to adjust their compliance strategies. However, as the enforcement mechanisms and specific incident notification obligations—such as the 24-hour early warning window—come online, the grace period for unprepared companies is coming to an abrupt end.

Chronology of Incident Response Under the New EU Mandate

The operational timeline dictated by the Cyber Resilience Act transforms standard corporate incident response. Under the new statutory framework, the chronology of handling a exploited vulnerability is broken down into distinct, legally binding phases that leave very little room for administrative delay.

The clock begins ticking the exact moment a manufacturer becomes aware that a vulnerability in their product is being actively exploited—a status legally distinct from a mere theoretical or unexploited vulnerability. Within 24 hours of this realization, the manufacturer must submit an initial early warning to the relevant Computer Security Incident Response Team (CSIRT), designated national authorities, or the European Union Agency for Cybersecurity (ENISA), depending on the product category and market reach.

Crucially, this 24-hour early warning does not require a fully developed security patch, nor does it require a complete forensic understanding of how the exploit was engineered. Regulators recognize that 24 hours is rarely enough time to conduct a comprehensive root-cause analysis. Instead, the initial notification is designed as an alarm bell, giving authorities immediate situational awareness so they can track threat actor behavior, issue cross-border alerts, and protect critical infrastructure or dependent downstream services.

Following the initial 24-hour warning, the timeline proceeds to subsequent reporting milestones. Manufacturers are legally required to provide a detailed follow-up report within a specified secondary window—typically within 72 hours of the initial awareness—providing deeper technical insights, indicators of compromise (IoCs), and preliminary mitigation steps. Finally, a comprehensive final report detailing the full impact, remediation measures, and preventive steps must be submitted once the incident has been fully resolved and patched.

Implications for the Cryptocurrency and Digital Wallet Sector

One of the most profound and perhaps underappreciated implications of the Cyber Resilience Act is its sweeping scope, which captures digital asset custody tools and cryptocurrency wallets despite the law not being written explicitly for the blockchain industry. Because the CRA defines its jurisdiction based on the functional characteristics of "products with digital elements," commercial hardware wallets, desktop wallet applications, and mobile wallet software placed on the EU market fall squarely within its regulatory perimeter.

Historically, the cryptocurrency sector has operated in a unique regulatory silo. Governance discussions surrounding digital assets have traditionally focused on financial regulations, anti-money laundering (AML) protocols, know-your-customer (KYC) requirements, and the distinct nuances of smart-contract risk versus traditional cybersecurity. Wallet providers and decentralized finance (DeFi) developers often viewed operational security through the lens of private key management, cryptographic integrity, and financial loss mitigation, frequently treating cybersecurity as a secondary technical concern rather than a regulated compliance obligation.

The CRA shatters this departmentalized mindset. Under European law, a hardware wallet is no longer viewed merely as a secure financial instrument; it is recognized as a connected digital product possessing microcode, firmware, and companion software that could serve as an attack vector. Consequently, wallet manufacturers must now integrate mainstream enterprise-grade cybersecurity compliance into their operational lifecycles. If a zero-day vulnerability in a commercial hardware wallet’s firmware is actively exploited in the wild, the manufacturer is bound by the exact same 24-hour reporting clock that applies to enterprise database software vendors or operating system developers.

This convergence of financial technology and traditional software regulation forces crypto companies to mature rapidly. Legal teams, compliance officers, and core engineering units within wallet-development firms must now establish formal cross-departmental incident escalation pathways. In the past, a crypto startup might spend days quietly verifying an exploit report within a developer Discord channel or GitHub repository before quietly pushing an over-the-air firmware update. Under the CRA, doing so while ignoring the 24-hour regulatory reporting obligation exposes the company to severe legal liability, substantial financial penalties, and potential market exclusion within the European Union.

Open-Source Software Carve-Outs and Ecosystem Nuances

While the regulatory hand of the Cyber Resilience Act is heavy, European legislators recognized the vital role that open-source software plays in the modern digital economy and intentionally carved out specific protections for the open-source community. This distinction is particularly critical for the cryptocurrency and blockchain ecosystem, where a vast majority of foundational infrastructure—including wallet libraries, cryptographic toolkits, and node software—is developed on open-source principles.

The CRA distinguishes between commercial activities and purely non-commercial open-source development. Purely non-commercial open-source software developers and foundations—those distributing software without charging licensing fees or monetizing the code through commercial support and enterprise offerings—are generally exempt from the stringent compliance burdens imposed on commercial market participants.

However, the legal boundary between commercial and non-commercial open-source software is nuanced and heavily scrutinized. If an open-source wallet project is sponsored, maintained, or monetized by a for-profit corporate entity, or if the code is bundled into a paid commercial product placed on the EU market, the exemption evaporates. Commercial entities that utilize open-source components in their proprietary hardware or software products retain ultimate legal responsibility for ensuring that the final integrated product complies with the CRA’s security and reporting mandates.

This dynamic places new pressures on commercial firms that rely on open-source libraries. Companies must maintain rigorous software bill of materials (SBOM) tracking to understand every upstream dependency within their products. If an open-source library utilized by a commercial crypto wallet is found to contain an actively exploited vulnerability, the commercial vendor is legally on the hook to notify European authorities within the mandated 24-hour window, regardless of whether the original flawed code was written in-house or by external community contributors.

Industry Reactions and Operational Challenges

The implementation of the Cyber Resilience Act’s 24-hour reporting window has elicited a complex mixture of praise and concern from industry stakeholders, cybersecurity professionals, and legal experts across Europe and internationally.

From a defensive security perspective, cybersecurity advocates have largely welcomed the measure. Proponents argue that information asymmetry has historically favored cybercriminals, who can exploit vulnerabilities across multiple enterprise targets long before vendors publicly acknowledge the flaw. By forcing companies to report active exploits within 24 hours, the EU aims to create a centralized, rapid-response defensive network that empowers national cybersecurity agencies to issue timely warnings to critical sectors before attacks scale catastrophically.

Conversely, engineering and legal teams have raised substantial operational concerns regarding the sheer feasibility of the 24-hour window. Industry trade groups and software associations have pointed out that cybersecurity incidents rarely present themselves with clear boundaries. When a security alert comes in—often late at night or over a weekend—an organization’s initial task is triage, verification, and containment. Forcing engineering teams to divert precious technical resources away from developing a patch in order to draft legal notifications for regulatory bodies within 24 hours could paradoxically slow down remediation efforts.

Furthermore, legal experts have highlighted the severe legal exposure created by premature reporting. If a company issues a 24-hour early warning based on preliminary data that later turns out to be a false alarm, or if the notification inadvertently leaks sensitive technical details before a patch is ready, it could expose the firm to reputational damage, consumer panic, and potential civil liability from affected users. Consequently, organizations are racing to retain specialized legal counsel and establish automated threat-scoring matrices to determine precisely when an incident crosses the statutory threshold of "active exploitation."

Fact-Based Analysis of Broader Economic and Geopolitical Implications

The enforcement of the Cyber Resilience Act positions the European Union once again as a global regulatory superpower, wielding the "Brussels Effect" to shape international product standards far beyond its geographic borders. Because the EU single market represents one of the largest and most lucrative consumer bases in the world, global technology companies—whether based in Silicon Valley, Shenzhen, or Zug—cannot simply opt out of compliance without abandoning millions of affluent users.

For non-EU software and hardware manufacturers, compliance with the CRA requires restructuring global operations to meet European standards. Companies that maintain fragmented incident response teams across different continents are now finding that they must centralize their security monitoring and legal escalation pathways to ensure that any European-facing product incident can be escalated to executive leadership within hours.

In the long term, this regulatory convergence is likely to drive a maturation of the global software development lifecycle. By legally binding financial accountability to cybersecurity hygiene, the CRA discourages the historical software industry practice of shipping products rapidly and patching vulnerabilities reactively on an ad-hoc basis. Companies that build robust, security-first architectures and transparent incident response frameworks will find themselves well-positioned to capture market share in a security-conscious European marketplace.

At the same time, smaller startups and independent developers may face disproportionate compliance hurdles. The administrative overhead of maintaining legal compliance, monitoring continuous threat landscapes, and managing cross-border regulatory filings requires financial and human capital that early-stage ventures often struggle to secure. This risk of market consolidation—where only well-capitalized enterprises can afford to navigate European regulatory complexity—remains one of the most significant unintended economic consequences of the legislation.

As the clock ticks down on the newly enforced 24-hour reporting mandate, the message to software developers, enterprise tech firms, and digital asset wallet manufacturers alike is unmistakably clear. The era of passive security oversight and delayed disclosures has officially ended. In the modern European regulatory landscape, operational resilience, swift accountability, and transparent communication are no longer optional best practices—they are mandatory conditions for doing business.

September 19, 2026 0 comment
0 FacebookTwitterPinterestEmail
Blockchain Technology

Google Maps introduces AI-powered Ask Maps to the Philippines to streamline navigation during the challenging rainy season

by admin September 19, 2026
written by admin

The digital landscape of navigation in the Philippines has undergone its most significant evolution in over a decade with the official rollout of Ask Maps. This artificial intelligence-driven feature, integrated directly into the Google Maps interface, represents a shift from traditional static mapping to a dynamic, conversational query system. Designed to assist users in navigating the complexities of urban traffic, unpredictable weather patterns, and shifting local environments, the tool promises to change how Filipinos interact with their commute and daily logistical planning.

The Technological Leap: What is Ask Maps?

At its core, Ask Maps utilizes advanced large language models to process natural language queries, allowing users to move beyond simple destination-based searching. By tapping the designated button located beneath the search bar, users can input complex requests that require synthesis of data points. Rather than merely showing a blue line on a map, the system analyzes real-time traffic data, crowd-sourced information, and business status updates to provide curated responses.

This transformation is particularly timely for the Philippine market, where geographical challenges, high traffic density, and extreme weather events often render standard GPS routing insufficient. The transition from a passive mapping tool to an active, conversational assistant reflects a broader industry trend of integrating generative AI into everyday utilities to reduce cognitive load on the user.

Latest Blockchain News, BSV Insights, and AI Web3 Trends from CoinGeek

Navigating the Rainy Season: A Strategic Tool for Filipinos

The Philippines experiences one of the highest frequencies of tropical cyclones globally, with an average of 20 storms entering the Philippine Area of Responsibility (PAR) annually. The rainy season, which typically spans from June to November, frequently brings localized flooding, road closures, and stalled public transportation.

Ask Maps addresses these pain points by offering real-time intelligence on road viability. When a user asks, "Are there any closed or flooded roads from Quezon City to BGC?" the system does not simply provide a search result; it cross-references live traffic data, municipal updates, and community reports to provide a synthesized summary. This summary includes actionable intelligence such as live delay alerts, alternate route suggestions, and confirmation of road passability.

Beyond mere transit, the feature acts as a concierge for commuters stranded by inclement weather. If a user is stuck in a specific business district, they can query the platform for nearby dining options that meet specific criteria—such as indoor accessibility that minimizes exposure to heavy rainfall. By filtering for location, service availability, and proximity, the AI enables users to make informed decisions that prioritize both efficiency and comfort during extreme weather.

A Chronology of Digital Navigation in the Philippines

The arrival of Ask Maps is the latest chapter in a long history of digital transformation in the country.

Latest Blockchain News, BSV Insights, and AI Web3 Trends from CoinGeek
  • Early 2000s: The emergence of digital mapping relied primarily on static online images and printed directories, with minimal real-time data.
  • 2010–2015: The widespread adoption of smartphones led to the integration of basic GPS routing in the Philippines. During this period, traffic data began to be crowdsourced through platforms like Waze, which Google eventually acquired in 2013.
  • 2018–2022: Google Maps expanded its localized features, including the introduction of "Stay Safe" features, business hours verification, and public transport integration in major cities like Metro Manila and Cebu.
  • 2024–2025: The integration of generative AI signals the current phase, where "intent-based" search replaces "keyword-based" search. The rollout of Ask Maps marks the maturation of this AI-first approach for the Philippine market.

Supporting Data and Infrastructure

The necessity of such a tool is underscored by the state of urban mobility in the Philippines. According to data from the Japan International Cooperation Agency (JICA), the economic cost of traffic congestion in Metro Manila is estimated to be in the billions of pesos daily. Furthermore, urban flooding remains a primary cause of productivity loss for thousands of businesses in the National Capital Region.

By providing real-time, context-aware information, Google Maps aims to alleviate the information asymmetry that often contributes to traffic bottlenecks. When commuters are aware of flooding or road maintenance in advance, the resulting redistribution of traffic can lead to more efficient road utilization.

Official Perspectives and User Experience

While Google has not released specific internal user adoption metrics, spokespersons for the tech giant have highlighted that the primary goal of Ask Maps is to simplify complex decision-making. The system is designed to "understand" the user’s intent, whether it is for a recreational road trip or a critical emergency detour.

Industry analysts observe that this move aligns with Google’s global strategy to maintain its dominance in the mapping sector against competitors that are also aggressively integrating AI. For the Filipino user, the value proposition lies in the reduction of "app-switching"—the need to toggle between news sites for weather updates, social media for traffic reports, and mapping apps for navigation. By consolidating these functions, Ask Maps serves as an all-in-one information hub.

Latest Blockchain News, BSV Insights, and AI Web3 Trends from CoinGeek

Broader Implications for Urban Planning and Daily Life

The implications of AI-driven navigation extend beyond individual convenience. As these tools gather more nuanced data, they could theoretically assist local government units (LGUs) in better understanding mobility patterns. While Google maintains strict privacy protocols, the aggregated, anonymized data provided by such high-usage platforms remains a vital resource for urban planners.

Furthermore, for the local business economy, the ability for the AI to prioritize "open" and "accessible" locations during crises provides a lifeline to SMEs. Small businesses that keep their Google Business profiles updated are more likely to be surfaced by the AI during a query, potentially stabilizing revenue during periods of reduced foot traffic caused by typhoons.

Challenges and Future Considerations

Despite the advancements, the efficacy of Ask Maps relies heavily on the quality and frequency of data input. In regions where internet connectivity is unstable or where local government reporting of road conditions is delayed, the AI’s "real-time" accuracy may be compromised. The system’s success depends on a feedback loop: users reporting conditions, businesses updating their status, and the underlying AI models refining their predictive capabilities.

As the technology continues to evolve, users should expect further integration with multimodal transport systems, including real-time updates on train schedules, ferry operations, and ride-sharing availability. For now, the introduction of Ask Maps serves as a significant enhancement to the digital infrastructure of the Philippines, offering a degree of resilience against the unpredictable nature of the country’s climate and urban environment.

Latest Blockchain News, BSV Insights, and AI Web3 Trends from CoinGeek

Conclusion

The launch of Ask Maps in the Philippines is a testament to the increasing role of generative AI in navigating the physical world. By converting data into conversational, actionable advice, Google has provided a tool that addresses the unique daily struggles of Filipinos. Whether it is avoiding a flooded arterial road during a monsoon or simply finding a warm meal during a storm, the integration of intelligence into navigation is set to become an essential component of daily life in the region. As users continue to interact with the system, the platform is expected to become more refined, further cementing its role as a critical utility for modern urban living.

September 19, 2026 0 comment
0 FacebookTwitterPinterestEmail
Blockchain Technology

The GENIUS Act Compliance Cliff: Navigating the Regulatory Vacuum in the Stablecoin Market

by admin September 19, 2026
written by admin

The regulatory landscape for stablecoin issuers in the United States has reached a critical inflection point as the January 18, 2027, effective date for the GENIUS Act looms, creating a high-stakes compliance cliff. Despite a flurry of activity from federal agencies, the structural gap between statutory prohibitions and finalized rulemaking has left the industry in a state of suspended animation. With the statutory deadline now firmly locked, issuers are forced to navigate a period of intense uncertainty, where the prohibition of non-compliant activities will take effect regardless of whether the implementing regulations are fully codified.

The Genesis of the GENIUS Act

The GENIUS Act was introduced as the definitive legislative response to the proliferation of digital-asset-backed stablecoins, aiming to bring the sector under the purview of federal oversight similar to traditional banking institutions. For years, the stablecoin market operated in a gray area, often relying on state-level money transmitter licenses and fragmented compliance regimes. The Act sought to unify these standards, requiring issuers to adhere to strict capital requirements, reserve transparency, and redemption mandates.

However, the implementation phase has been hampered by bureaucratic inertia. Six major federal agencies—the Treasury Department, the Office of the Comptroller of the Currency (OCC), the Federal Reserve, the Federal Deposit Insurance Corporation (FDIC), the Securities and Exchange Commission (SEC), and the Commodity Futures Trading Commission (CFTC)—were tasked with defining the granular requirements for compliance. While all six agencies managed to publish Notices of Proposed Rulemaking (NPRMs) by the July 18, 2026, deadline, none have reached the stage of final rule promulgation. This lag has created a paradox: the law mandates compliance by January 2027, yet the standards for what constitutes "compliance" remain in draft form, subject to potential revisions that could alter the operational requirements for issuers overnight.

Chronology of Regulatory Milestones

The timeline leading to the current standoff is marked by a series of aggressive deadlines and administrative hurdles:

  • December 2025: The OCC issues conditional trust bank approvals to a cohort of industry heavyweights, including Ripple, BitGo, Fidelity, Paxos, and First National Digital Currency Bank, setting the stage for institutional integration.
  • July 10, 2026: Circle achieves a significant milestone as the first and, to date, only issuer to receive final OCC trust bank approval, providing it with a distinct operational head start.
  • July 18, 2026: The federal statutory deadline for the issuance of NPRMs passes. While all relevant agencies meet this mark, the finalization of rules is left open-ended.
  • September 2026: The OCC accelerates its charter pipeline, approving six digital-asset trust charters in a single month, marking the most rapid expansion of federal oversight in the crypto-asset space to date.
  • November 2026: The anticipated deadline for final charter applications under the current OCC framework, serving as the last "window of opportunity" for issuers to secure their federal standing.
  • January 18, 2027: The GENIUS Act’s effective date, at which point the statutory prohibitions become enforceable.

The Compliance Paradox and Its Implications

The primary concern among legal experts and industry analysts is the "compliance cliff." In administrative law, there is a clear distinction between a statute and a regulation. While the GENIUS Act establishes the legal prohibition, the regulations serve as the "how-to" manual for compliance. When the statute takes effect before the regulations are finalized, issuers are left to interpret the law through the lens of draft guidance.

This environment forces firms to commit significant capital toward infrastructure and compliance programs that may require immediate retrofitting if the final rules differ from the NPRMs. For example, if the final rule mandates a higher percentage of cash-equivalent reserves than initially outlined in the draft, an issuer that has already optimized its balance sheet according to the draft risks being in technical violation of the final rule on day one.

Circle, having secured final OCC approval, occupies a unique position. By operating under a fully vetted charter, the firm has already undergone the rigorous examination process required by the OCC. In contrast, those operating under conditional approvals must navigate a dual challenge: finalizing their regulatory standing while simultaneously building systems that satisfy an evolving set of federal expectations.

Data and Institutional Positioning

The institutional pivot toward regulated digital assets is reflected in the volume of applications and the shift in market sentiment. Historically, firms were wary of federal oversight due to the perceived stifling of innovation. However, as the legal environment has hardened, the focus has shifted from "avoiding regulation" to "achieving compliance as a competitive advantage."

The surge in OCC charter approvals in September 2026 indicates that institutional players have accepted the new reality. By seeking federal charters, these firms are essentially "buying in" to the US regulatory framework, trading autonomy for the legal certainty and market access that a federal license provides. This trend is further supported by the SEC’s recent exemptive framework for tokenized stocks, which mirrors the GENIUS Act’s emphasis on transparency and institutional-grade oversight.

Official Perspectives and Industry Response

While the agencies have remained tight-lipped regarding the delay in finalizing rules, sources close to the regulatory process suggest that the complexity of inter-agency coordination is the primary culprit. The requirement to synchronize the mandates of the SEC and the CFTC—two agencies with historically different approaches to digital assets—has proven particularly difficult.

Industry lobbying groups have expressed a mix of frustration and resignation. Privately, executives argue that the uncertainty is "taxing" the industry, forcing them to hold excessive capital in reserve to account for the "what-if" scenarios of pending regulation. However, publicly, there is a consensus that the GENIUS Act provides the long-term clarity necessary for mass adoption, even if the transition period is characterized by volatility.

The Edge Case: What Happens After January 2027?

As the industry approaches January 18, 2027, the focus shifts to the enforcement posture of the federal government. Legal analysts suggest that agencies are unlikely to pursue aggressive enforcement actions against issuers that demonstrate a "good faith" effort to comply with the spirit of the GENIUS Act, provided those issuers are actively engaging with regulators to finalize their standing.

However, the "statutory teeth" of the Act cannot be ignored. Once the law is in effect, the lack of final rules does not grant a stay of execution for non-compliance. Issuers that have failed to initiate the chartering process or that remain in a state of regulatory limbo are the most vulnerable. For these entities, the path forward is binary: accelerate compliance efforts to meet the standards articulated in the NPRMs or begin the process of winding down US-based operations.

Conclusion: A New Era for Digital Assets

The GENIUS Act represents the maturation of the stablecoin market. By forcing a collision between statutory law and regulatory implementation, the US government is effectively purging the market of entities unable or unwilling to meet the threshold of institutional stability. While the transition period is fraught with ambiguity and operational challenges, the long-term result will likely be a more resilient, transparent, and integrated financial ecosystem.

For the winners of this transition, the rewards are substantial. Those with finalized charters and robust compliance infrastructure will be the primary beneficiaries of a market that has finally received the regulatory imprimatur of the federal government. As for the rest, the clock is ticking, and the window for navigating the compliance cliff is rapidly closing. The final months of 2026 will be remembered as the era when the "wild west" of stablecoins officially transitioned into a structured, highly regulated segment of the global financial market.

September 19, 2026 0 comment
0 FacebookTwitterPinterestEmail
Blockchain Technology

Sam Altman-Backed Online Verification Startup World Raises $52.5 Million in Strategic Token Sale

by admin September 19, 2026
written by admin

World, the ambitious digital identity and online verification startup co-founded by OpenAI Chief Executive Officer Sam Altman, has successfully secured $52.5 million in funding through a private token sale to institutional and strategic investors. The transaction involves the company’s native digital asset, WLD, and comes at a critical juncture for the organization as it attempts to cement its footprint in an internet increasingly flooded by artificial intelligence and automated software agents.

According to a press release issued by the company, the participants in the capital raise agreed to a strict 12-month lockup period. Such lockup mechanisms prohibit buyers from selling, transferring, or trading their newly acquired tokens on secondary markets for a set duration. Industry analysts note that a yearlong restriction of this nature is designed to mitigate immediate sell-side pressure on the asset while signaling strong institutional confidence in the long-term utility, economic model, and technological roadmap of the World ecosystem.

The newly injected capital will be channeled directly into the World Foundation, an exempted limited guarantee foundation domiciled in the Cayman Islands. Established specifically to steward the global expansion, decentralization, and stewardship of the World network, the foundation will oversee how these resources are allocated across various operational and developmental fronts.

A High-Profile Syndicate of Digital Asset Investors

The $52.5 million funding round attracted a prominent syndicate of venture capital firms and institutional crypto funds. Pantera Capital, a leading investment firm specializing in digital assets and blockchain technology, acted as the lead buyer for the token sale.

The syndicate also featured several other high-profile entities, including Bain Capital Crypto, Eightco Holdings, Susquehanna Crypto, and Selini Capital. The participation of these major market players underscores continued institutional appetite for infrastructure projects centered around digital identity, despite regulatory scrutiny and macroeconomic headwinds that have periodically chilled the broader crypto landscape.

The broader World project is operationally driven by Tools for Humanity (TFH), a technology company headquartered in San Francisco, California. TFH is led by CEO and co-founder Alex Blania, with Sam Altman serving alongside him as the company’s other prominent co-founder. While TFH builds the underlying consumer applications and hardware required for the network, the decentralized governance and network expansion remain under the purview of the Cayman Islands-based World Foundation.

Combating the Rise of Bots Through Proof of Human Technology

At its core, World is structured around a novel premise: as artificial intelligence and generative models become increasingly sophisticated at mimicking human behavior, distinguishing genuine people from automated bots online will become an existential challenge for digital platforms.

The startup sells access to what it describes as "proof of human" tools. The flagship product of this ecosystem is the World ID—an anonymous digital credential designed to cryptographically verify that an account is operated by a living human being rather than an automated script, bot, or AI agent.

To achieve the highest tier of verification within the system, users must undergo a biometric scanning process. This requires individuals to have their eyes scanned by an "Orb," a custom-engineered, chrome-plated spherical hardware device developed by TFH. The Orb uses advanced optical sensors to capture the distinct patterns of a user’s iris, converting that biological data into an immutable cryptographic identifier. Once generated, the physical iris scan is typically deleted to preserve user privacy, leaving only the cryptographic hash on the decentralized ledger.

These Orbs have been deployed globally, stationed in permanent World offices as well as temporary pop-up locations and partner retail stores across multiple continents. Users manage their digital credentials and interact with the ecosystem via the World application, which functions simultaneously as a digital interface and a self-custodial wallet for the WLD token.

Evolution, Rebranding, and Strategic Pivots

The project’s current iteration is the result of a significant evolution. It originated as a more overtly crypto-centric experiment under the moniker "Worldcoin," sharing the exact name of the digital asset utilized in the recent funding round.

However, as public skepticism, regulatory pushback, and reputational friction surrounding the cryptocurrency industry mounted globally, the leadership team elected to rebrand the enterprise simply as "World." This strategic shift was intended to de-emphasize purely speculative financial trading and pivot public perception toward the project’s utility as a digital infrastructure provider for identity verification.

Despite its grand ambitions and substantial financial backing from Silicon Valley venture capital, World has frequently encountered operational friction. Regulators in multiple international jurisdictions—particularly across Europe and Latin America—have raised data privacy concerns regarding the mass collection of biometric iris data via the Orbs, prompting temporary suspensions and investigations in countries such as Spain, Portugal, and Kenya.

In April, the project attempted to reignite momentum by launching a revamped version of its consumer application. Alongside the app update, TFH announced a series of high-profile integration partnerships with mainstream consumer tech platforms, including dating giant Tinder, video conferencing leader Zoom, and document workflow company Docusign, aimed at embedding World ID verification into everyday digital interactions.

Navigating Market Realities and Internal Restructuring

Scaling a global biometric identity network has proved to be both capital-intensive and consumer-resistant. Despite securing partnerships with major web platforms, World has struggled to achieve widespread mainstream adoption or convince the general public of the immediate necessity of iris-scanning verification.

The economic realities of these growth challenges caught up with the organization earlier this year. In June, Tools for Humanity executed a round of workforce reductions, laying off an undisclosed number of employees as part of a broader corporate restructuring aimed at streamlining operations and extending its financial runway.

Furthermore, the project has navigated the complexities of media reporting surrounding its partnership ecosystem. While initial reports and early promotional materials frequently linked the startup to major entertainment and ticketing entities, clarifications have highlighted a more focused rollout centered primarily on select digital communication, identity, and social platforms.

Broader Implications for the Digital Economy

The successful completion of a $52.5 million token sale with a strict 12-month lockup period provides World with a crucial financial buffer as it seeks to chart a sustainable path forward.

As generative artificial intelligence continues to blur the lines between human and machine-generated content across social media, customer service channels, and enterprise software, the market demand for reliable, privacy-preserving authentication mechanisms is expected to grow. Industry observers note that while skepticism surrounding biometric data collection and tokenized incentives remains high, the influx of institutional capital from firms like Pantera Capital and Bain Capital Crypto ensures that World will have the resources to continue testing its hypothesis on a global scale.

Whether consumers will ultimately embrace iris-scanning technology as a standard prerequisite for online interaction remains an open question. For now, the backing of high-profile Silicon Valley figures and deep-pocketed digital asset funds guarantees that World will remain a central, albeit controversial, player in the ongoing debate over digital trust and identity in the age of artificial intelligence.

September 19, 2026 0 comment
0 FacebookTwitterPinterestEmail
Decentralized Finance (DeFi)

Term Finance Governance Exploit Results in Eight Point Five Million Dollar Loss Due to Unchecked Parameter Manipulation

by admin September 19, 2026
written by admin

On Sunday, August 23, 2026, at 06:25:47 UTC, a critical failure in the governance architecture of the decentralized lending protocol Term Finance resulted in the unauthorized withdrawal of approximately 2,841.74 WETH from its ETH Meta Vault. This event was followed shortly thereafter by a second exploit targeting five USDC vaults, leading to the drainage of an additional 1,679,639 USDC. The total loss, estimated at $8.5 million, was not the result of a traditional technical exploit such as a reentrancy attack, oracle manipulation, or flash loan. Instead, it was a systemic failure of the protocol’s opt-out governance mechanism, which allowed an unprivileged actor to pass a malicious proposal that dismantled the protocol’s own internal security safeguards.

The incident underscores a growing trend in decentralized finance (DeFi) where the "curator model"—designed to simplify yield generation for passive depositors—creates a dangerous concentration of authority that, if left unmonitored, becomes a primary attack vector.

The Mechanism of Failure

Term Finance operates as a fixed-rate lending protocol, distinguishing itself from floating-rate competitors like Aave or Compound by matching borrowers and lenders for fixed maturities. The protocol’s "Strategy Vaults" rely on external risk curators to allocate capital into various sub-vaults across the DeFi ecosystem. To manage these allocations, Term utilizes a governance module where parameter changes are proposed by curators.

Under the protocol’s design, these governance actions are governed by an "opt-out" mechanism. When a proposal is submitted, a voting window opens, and liquidity provider (LP) token holders are given the opportunity to veto the change. If no veto is cast by the end of the period, the proposal is considered approved and becomes executable. Crucially, Term implemented a seven-day timelock as a "second line of defense" to allow for emergency intervention.

However, the exploit revealed that this timelock was not isolated from the governance module itself. The attacker successfully submitted a proposal that included an instruction to set the timelock cooldown period to zero. By doing so, the attacker effectively disarmed the protocol’s final safety mechanism, allowing the malicious transaction to execute immediately upon the expiration of the voting window.

Term Finance: $8.5M Approved by Silence

Chronology of the Exploit

The timeline of the breach suggests a high level of preparation and patience on the part of the attacker.

  • August 17, 2026: A wallet address, 0xa908b3472d76e7744bab0a5911768a4a6300612b, receives 1 ETH from a Tornado Cash pool.
  • August 17, 2026 (05:21 UTC): The attacker deposits 0.5 ETH into the ETH Meta Vault, acquiring a 0.017% share of the vault.
  • August 17, 2026 (05:25 UTC): The attacker deploys a contract that submits "Proposal 5" to the ETH Meta Vault’s governor. The proposal, disguised as a standard parameter update, contains 17 instructions, including the command to delete the seven-day timelock.
  • August 17–23, 2026: The proposal remains active and publicly viewable on-chain for six days. During this time, not a single veto is cast by the curators or the vault’s LP token holders.
  • August 23, 2026 (06:25 UTC): The voting window closes.
  • August 23, 2026 (06:25:47 UTC): The attacker executes the proposal. The contract successfully resets the timelock to zero and triggers a series of actions that move 2,841.74 WETH to the attacker’s address.
  • August 23, 2026 (06:47 UTC): A second wallet executes a similar, more aggressive exploit against five USDC vaults, draining over 1.67 million USDC.

Data Analysis and Financial Impact

The breach was executed with surgical precision, utilizing a relatively small capital stake to gain the required status to initiate governance proposals. On the ETH side, the attacker held only 0.017% of the total vault supply. For the USDC vaults, the attacker’s stake was even smaller, effectively a rounding error compared to the total assets under management.

Despite the removal of the funds, the vault’s accounting software initially continued to reflect the presence of the assets. The vault recorded the stolen funds as a "loan" to a strategy contract, which meant that for a period following the exploit, the share price reported by the vault remained artificially high. This "fictional" valuation poses a secondary risk to users and integrators who rely on automated dashboards to monitor their holdings, as they may be unaware that the underlying collateral has been removed.

Total losses are estimated by third-party security firms, including PeckShield, to be approximately $8.5 million. While the ETH Meta Vault was emptied, the USDC vaults still retain roughly $4.36 million in assets, suggesting that the exploit did not result in a total loss of all protocol liquidity, though the integrity of the vaults remains in question.

Official Responses and Industry Reaction

Term Labs issued a brief statement at 07:32 UTC on the day of the incident: "We are aware of a governance exploit impacting Term vaults. We will share more details once it has been further investigated."

Following the initial drain, the protocol attempted to initiate emergency governance actions—specifically, "Proposal 6" and "Proposal 7"—to attempt to shut down the affected vaults. However, these attempts faced the same logistical hurdles as the original proposals, as they were also subject to the protocol’s established (and currently compromised) governance veto windows.

Term Finance: $8.5M Approved by Silence

Related protocols that utilized Term Finance as a yield source have also been impacted. For instance, Tori Finance, which had capital allocated to Term via a RockawayX-curated vault, saw a loss of approximately $480,000. Reports indicate that Tori Finance representatives have signaled an intent to cover these losses for their depositors, though a formal public disclosure was pending as of the time of reporting.

Broader Implications for Decentralized Governance

The Term Finance exploit serves as a stark case study in the risks of "opt-out" governance models. In theory, these systems are designed to prevent the paralysis of protocols where voter apathy is high. By assuming that silence equals consent, these protocols can iterate and update parameters rapidly. However, as this incident demonstrates, this design shifts the burden of security entirely onto the participants. If no one is actively monitoring the governance queue, the system essentially becomes a "permissionless" extraction machine.

Several key questions remain for the DeFi community:

  1. Authorization Boundaries: How did an unprivileged contract created only minutes prior gain the ability to submit executable proposals? The failure to restrict proposer roles to verified curator addresses appears to be the primary point of vulnerability.
  2. Timelock Integrity: The decision to allow a governance proposal to modify its own safety constraints (the timelock) reflects a critical architectural flaw. Standard security practices dictate that administrative cooldowns should be immutable or protected by a separate, multi-signature override that cannot be triggered by the same mechanism it is intended to guard.
  3. Economic Barriers: The lack of a significant financial bond required to submit a proposal allowed an attacker to initiate a multi-million dollar exploit with less than one ETH of capital. Implementing a stake-based threshold or a slashing mechanism for malicious proposals could mitigate similar future attempts.

Conclusion

The Term Finance exploit is the latest in a series of 2026 security events where the "human" and "process" layers of a protocol failed before the mathematical code did. While developers often focus on preventing reentrancy or oracle manipulation, this incident highlights that the administrative levers—the "governance interface"—are increasingly becoming the most lucrative target for sophisticated actors.

For the average DeFi participant, the lesson is clear: the curator model is not a "set-and-forget" solution. The reliance on third-party judgment, coupled with automated governance, requires constant vigilance. Until protocols implement more robust, hardened, and isolated governance procedures, the risk of "legitimate" but malicious administrative actions will remain a constant, looming threat to the ecosystem’s treasury.

September 19, 2026 0 comment
0 FacebookTwitterPinterestEmail
Cybersecurity & Hacking

AI-Assisted Security Breach: How Researchers Chained Vulnerabilities to Compromise OpenAI Internal Systems

by admin September 19, 2026
written by admin

In a startling demonstration of how artificial intelligence is accelerating the pace of cyber-offensive operations, three researchers from the security firm Hacktron successfully breached OpenAI’s internal infrastructure by chaining two distinct vulnerabilities. By leveraging the advanced capabilities of Anthropic’s Claude Opus 5, the team managed to bypass security barriers to gain unauthorized access to the ChatGPT and Codex accounts of several OpenAI employees. This breach, which culminated in the team accessing an internal code repository, serves as a sobering case study on the risks posed by the integration of AI in modern cyberattacks and the fragility of shared identity management systems.

The Anatomy of the Breach: A Chronology of Access

The exploit chain began not at the heart of OpenAI’s core services, but on its public-facing help forum. The forum, which operates on the open-source Discourse platform, was found to be running an outdated version of the libheif library—a software component responsible for processing high-efficiency image formats like HEIC and HEIF.

On July 24, 2026, the Hacktron team initiated their research. The initial vector was a memory corruption vulnerability within libheif, tracked as CVE-2026-32882. While the vulnerability was publicly documented and patched by developers in May 2026, the specific Debian 12-based server image utilized by the OpenAI forum had not yet received the critical update. The researchers utilized a specially crafted image file to trigger an out-of-bounds read, which they then refined—with significant assistance from Claude Opus 5—to achieve remote code execution (RCE) on the forum’s server.

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

Within 72 hours of the initial assessment, the researchers had transitioned from gaining a foothold on the forum server to compromising the accounts of OpenAI staff members. Because OpenAI utilizes a unified Single Sign-On (SSO) infrastructure, the researchers were able to pivot from the forum’s compromised environment to gain authorized access to the credentials of employees who had logged into the forum using their corporate OpenAI accounts.

The access was verified on September 1, 2026, when the researchers performed a "proof of life" maneuver: they successfully executed a harmless pull request in an internal OpenAI code repository. Following this, the team ceased all operations and reported their findings to OpenAI’s bug bounty program. OpenAI confirmed the remediation of the vulnerability approximately 14 hours after the report was filed.

The Role of AI in Offensive Security

The Hacktron project, dubbed "HEIF Heist," highlights a shift in the cybersecurity landscape. The researchers explicitly noted that previous attempts using earlier models, such as Claude Opus 4.8, failed to navigate the complexities of modern memory protections like Address Space Layout Randomization (ASLR). However, the release of Claude Opus 5 proved to be a turning point.

The model was tasked with writing exploit code within a controlled, automated loop, effectively acting as an intelligent force multiplier. While the researchers emphasized that human oversight remained critical, the AI significantly reduced the time and manual labor required to transition from a theoretical vulnerability to a functional exploit. This capability mirrors recent warnings from industry leaders and government intelligence agencies, which have noted that both criminal syndicates and state-sponsored advanced persistent threat (APT) groups are increasingly integrating generative AI to automate reconnaissance and exploit development.

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

Shared Identity Infrastructure: A Systemic Weakness

A central finding of the report is the danger of "identity coupling." By allowing the same SSO credentials used for internal administrative and development tools (such as GitHub, Slack, and email) to be used for public-facing, lower-trust services like a community forum, OpenAI created an unintended bridge for attackers.

When the forum server was compromised, the shared authentication token allowed the researchers to impersonate employees. This underscores a persistent vulnerability in the modern tech stack: the reliance on centralized authentication providers. If a perimeter service—even one as seemingly benign as a user forum—is breached, it can effectively become a gateway into the core of a company’s sensitive intellectual property if the authentication boundaries are not strictly segmented.

Official Responses and Bounty Outcomes

OpenAI acknowledged the security report with a $6,500 bounty payment. In an official communication, the company clarified that the compensation was issued specifically for the "OpenAI-side finding"—the SSO implementation flaw—rather than the initial breach of the Discourse forum software, which fell outside the scope of their bounty program.

The company has maintained a policy of minimal public disclosure regarding the specific mechanics of the login vulnerability, preferring to confirm the issue through the successful deployment of patches rather than detailing the methodology of the account takeovers. Discourse, the platform provider, has also been active in addressing the upstream issues, emphasizing that self-hosted instances of their software must be regularly updated to ensure that the underlying operating system and its dependencies, such as libheif, are properly patched.

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

Implications for the Broader Cybersecurity Ecosystem

The Hacktron research is part of a wider investigation into image-decoding vulnerabilities across the tech industry. The team claims that their $3,000 investment in AI-driven research led to the discovery of similar vulnerabilities in products from companies including Meta, GitHub, and frameworks like Next.js. While not all of these claims have been independently verified, they point to a systemic issue regarding the maintenance of legacy image-processing libraries in large-scale, enterprise-grade applications.

The implications for organizations are two-fold:

  1. Dependency Hygiene: Software supply chain security is no longer just about third-party libraries in the application code; it extends to the underlying server operating system and its pre-packaged image-processing utilities. Organizations must audit the libraries being used by their web servers to ensure they are current.
  2. Authentication Segmentation: The practice of "Sign in with [Company]" must be evaluated with a zero-trust mindset. If a single identity is used for both public-facing services and internal development environments, the security of the public service must be treated with the same level of rigor as the internal production environment.

Conclusion: A New Frontier of Threat

The incident at OpenAI is a harbinger of a future where the barrier to entry for high-level exploits is significantly lowered by AI. When a single, low-severity bug in a public-facing forum can be chained via AI-generated exploit code to access internal code repositories, the traditional "defense-in-depth" model requires urgent reassessment.

While the researchers in this instance acted with ethical integrity, the "HEIF Heist" serves as a stark reminder of the potential for future, less ethical actors to use these same tools to cause genuine harm. As we move further into the age of AI-augmented security, the speed at which organizations patch their systems will need to match the speed at which AI models can uncover and exploit their vulnerabilities. The era of manual, slow-moving cyber warfare is rapidly giving way to a high-velocity environment where intelligence, rather than just effort, defines the winner.

September 19, 2026 0 comment
0 FacebookTwitterPinterestEmail
Cybersecurity & Hacking

BragJack Attack Technique Hijacks Built-In AI Browser Assistants Across Major Platforms

by admin September 19, 2026
written by admin

Security researchers are increasingly warning that the rapid integration of artificial intelligence into everyday software is creating complex new attack surfaces. A striking example of this evolution has recently come to light through the work of independent security researcher Gal Weizman of Forever Security, who has successfully disclosed and demonstrated a novel attack technique called BragJack. This methodology allows a single, pre-installed malicious browser extension to completely hijack the native AI assistants embedded within prominent Chromium-based browsers and web applications. The implications of this research extend far beyond simple data exfiltration, highlighting fundamental security challenges in how modern web browsers partition privileges between extensions and deeply integrated generative AI frameworks.

The scope of the BragJack proof-of-concept is extensive, targeting five distinct browser-based AI implementations: Google Chrome’s Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic’s Claude in Chrome extension. By exploiting systemic architectural oversights, Weizman was able to demonstrate that an attacker could completely subvert these AI engines without requiring any real-time user interaction once the malicious extension was planted. This capability grants rogue actors unauthorized access to sensitive local files, browsing histories, private communications, and the ability to autonomously execute commands on behalf of the victim. In recognition of the severity of these findings, major technology vendors have awarded Weizman more than $20,000 in bug bounties—with individual payouts ranging from $600 to $7,000—and issued multiple critical CVE identifiers to track and patch the underlying vulnerabilities.

The Architecture of Trust: Understanding the Brain and Body Paradigm

To fully comprehend how BragJack operates, security analysts must examine the modern architectural design of AI-powered browsers. Historically, web browsers functioned as secure sandboxes where extensions operated under tightly monitored constraints, interacting with web pages through well-defined APIs. However, the introduction of generative artificial intelligence has fundamentally altered this paradigm. Browsers no longer merely render web pages; they now interpret intent, summarize content, and take autonomous actions.

In his technical documentation, Weizman conceptualizes these advanced browser assistants as having a distinct "brain" and "body." The brain consists of the underlying large language model (LLM), which processes unstructured human instructions and formulates a plan of action. The body, conversely, comprises privileged browser components and system-level application programming interfaces (APIs) that possess the raw capability to execute those plans. These components can read arbitrary local files, capture high-resolution screenshots, navigate across restricted web domains, manipulate active DOM elements, and access hardware peripherals such as webcams and microphones.

The core vulnerability exploited by BragJack lies in the fact that legacy extension security models were never designed to anticipate an attacker weaponizing a browser extension to manipulate the network traffic and internal resources that these privileged AI components blindly trust. By injecting subtle modifications into communication pipelines, malicious extensions can bypass the conceptual barrier between standard web content and elite system-level AI workflows.

Anatomy of the Exploits: From Chrome to Edge and Beyond

The execution vectors utilized in the BragJack research varied significantly depending on the architectural defenses of each targeted platform. Across all vectors, however, the researcher relied on Chromium’s native declarativeNetRequest (DNR) API. While DNR was originally designed to help privacy and ad-blocking extensions efficiently manage network traffic without inspecting every single web request, Weizman weaponized it to manipulate network headers and redirect internal JavaScript resources.

In the case of Google Chrome, the browser’s internal architecture strictly blocks extensions from directly interacting with the privileged chrome://glic component or injecting unauthorized scripts directly into Google’s core Gemini domains. Despite these safeguards, Weizman discovered that DNR rules could successfully intercept network requests generated by the embedded Gemini web application itself. By strategically weakening security headers and intercepting a vital JavaScript resource, the malicious extension executed code directly within the Gemini security context. This established a direct, trusted communication channel with Chrome’s privileged AI backend, completely bypassing the standard validation flows. Google acknowledged this flaw, assigned it CVE-2026-0628, and rewarded the researcher with a $7,000 bounty before rolling out a comprehensive desktop patch in the stable channel update.

The attack vectors against agentic browsers—such as Perplexity Comet and Opera Neon—demonstrated an even greater capacity for harm because these assistants are explicitly designed to act upon the web rather than merely passive document reading. For Perplexity Comet, the browser’s internal agent trusted several associated domains, including a legacy testing domain that lacked the robust security hardening applied to the primary production site. By utilizing DNR rules to remove a standard redirect, Weizman forced the browser to load this less-protected domain, injected a custom content script, and established a direct dialogue with the built-in assistant. The resulting compromise granted access to localized browsing histories, local files, live screenshots, and the ability to feed synthetic instructions directly to the agent. During demonstrations, Weizman successfully compelled the browser agent to navigate to Perplexity, automatically synthesize and summarize the victim’s private emails, and exfiltrate the resulting data to an external address controlled by the attacker.

Microsoft Edge presented a unique engineering hurdle due to safety features implemented by Microsoft developers. Specifically, Microsoft had deliberately split its AI agent into distinct "Think" and "Do" modes. This segregation was implemented precisely to prevent the model from simultaneously processing arbitrary, untrusted instructions and executing high-privilege system actions. However, Weizman uncovered a critical race condition within the state-management logic. By flooding the application with rapid requests, an attacker could briefly disable the operational restriction while simultaneously forcing a malicious prompt, successfully tricking the agent into executing unauthorized commands before the security state could re-verify itself. Microsoft cataloged this race condition under CVE-2026-55945.

BragJack attacks hijack AI browser agents through malicious extensions

Similar methodology and vulnerabilities were successfully replicated against Opera Neon and the popular Claude in Chrome extension. The findings regarding the Claude extension build upon a growing body of security research. Earlier in the year, security analyses by Manifold Security revealed that the Claude for Chrome extension processed workflows driven by synthetic click events without adequately verifying whether those inputs originated from a genuine human user. That discovery followed the disclosure of ClaudeBleed—another high-profile flaw identified by LayerX—wherein the extension mistakenly trusted the broad claude.ai origin rather than meticulously verifying which specific internal script was driving the transaction.

Prompt Forcing: A New Class of Cyber Threat

One of the most significant conceptual contributions of Weizman’s research is the formalization and naming of a distinct attack vector he terms "Prompt Forcing." To understand the danger of Prompt Forcing, security professionals must contrast it with traditional prompt injection attacks.

In a conventional prompt injection scenario, an adversary hides malicious instructions inside passive content—such as a seemingly innocuous webpage, a PDF document, or an incoming email—in the hope that an AI assistant will read the text and accidentally follow the hidden commands. While dangerous, traditional prompt injection is often bounded by the security context of the specific document or website the AI is currently viewing.

Prompt Forcing, by contrast, fundamentally flips the dynamic. Instead of hoping the AI reads a contaminated document, the attacker’s malicious browser extension directly injects an entirely fabricated prompt and an extensive sequence of chained follow-up instructions straight into the AI agent’s internal input pipeline. Because the prompt originates from what the browser perceives as a legitimate administrative or local extension context, the AI assistant readily accepts the instructions as valid user intent. The model then translates those malicious instructions into authorized browser operations, leveraging its pre-existing high-level privileges to compromise the machine.

This distinction creates an unprecedented hurdle for traditional endpoint detection and response (EDR) software. Because the final malicious actions—such as reading local directories, fetching personal documents, or transmitting browser session data—are physically carried out by legitimate, trusted browser processes acting under the direct orders of their integrated AI assistants, behavioral security tools frequently fail to flag the activity as anomalous. The software is not technically being hacked; rather, legitimate software is being systematically weaponized against its user.

Industry Response, Remediation, and Mitigation Strategies

In the wake of these disclosures, major software vendors have rushed to close the security gaps exposed by the BragJack research. Google and Microsoft have both deployed critical security patches addressing the specific CVEs assigned to their respective browser environments. Perplexity, Opera, and Anthropic have likewise initiated internal code reviews to harden their extension validation checks and reinforce the isolation barriers between third-party extension APIs and internal agent communication channels.

Nevertheless, security analysts emphasize that patching individual vulnerabilities will not suffice to solve the broader structural risk. As web browsers evolve from simple document viewers into autonomous operating environments driven by generative artificial intelligence, the attack surface will inevitably expand. The integration of high-privilege "do" capabilities alongside intelligent "think" engines requires an entirely new philosophy of browser security architecture—one that assumes extensions may be malicious and implements zero-trust boundaries even between internal browser components.

For everyday end-users and enterprise environments alike, the BragJack research serves as a stark reminder of the hidden risks lurking within modern browser extensions. Cybersecurity experts recommend several foundational best practices to mitigate these evolving threats:

  • Maintain Rigorous Software Hygiene: Users should ensure that their web browsers and all associated security patches are updated to the absolute latest versions immediately upon release.
  • Audit Browser Extensions: Individuals and enterprise IT administrators must regularly review installed extensions, promptly removing any add-ons that are unrecognized, outdated, or no longer actively utilized.
  • Exercise Extreme Caution with Permissions: Browser extension permission prompts—particularly those requesting broad, sweeping authorities such as the ability to "read and change all your data on all websites"—should be scrutinized heavily before installation. In many cases, these expansive permissions provide the precise footholds required for advanced exploitation chains like BragJack.

As artificial intelligence continues to redefine the boundaries of human-computer interaction, the security community faces an uphill battle in ensuring that the tools designed to make our digital lives easier do not simultaneously become the most efficient vehicles for our compromise. Detailed technical breakdowns and comprehensive documentation of the BragJack methodology have been published by Forever Security to assist developers and security researchers in fortifying the next generation of intelligent software.

September 19, 2026 0 comment
0 FacebookTwitterPinterestEmail
Newer Posts
Older Posts

Recent Posts

  • The Evolution of the Web3 Wallet: From Private-Key Vault to the Command Center of the Agentic Web
  • Ethereum Foundation Announces Annual Protocol AMA Session Scheduled for September 16
  • Kraken Expands Its Digital Asset Offerings with the Official Listing of Doppler Finance (Xdp)
  • CSD BR and Ripple Collaborate to Integrate XRP Ledger into Brazilian Financial Market Infrastructure
  • Web3 Venture Funding Surges to Record $22 Billion in Third Quarter 2025 Driven by Institutional Adoption

Recent Comments

No comments to show.
  • Facebook
  • Twitter

@2021 - All Right Reserved. Designed and Developed by PenciDesign


Back To Top
Dr Crypton
  • Home
  • About Us
  • Contact Us
  • Cookies Policy
  • Disclaimer
  • DMCA
  • Privacy Policy
  • Terms and Conditions

We are using cookies to give you the best experience on our website.

You can find out more about which cookies we are using or switch them off in .

Dr Crypton
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.