Google

Google Shuts Down Duplex on the Web, Its Attempt To Bring AI Smarts To Retail Sites and More (techcrunch.com) 8

Google is shutting down Duplex on the Web, its AI-powered set of services that navigated sites to simplify the process of ordering food, purchasing movie tickets and more. From a report: According to a note on a Google support page, Google on the Web and any automation features enabled by it will no longer be supported as of this month. Google introduced Duplex on the Web, an outgrowth of its call-automating Duplex technology, during its 2019 Google I/O developer conference. To start, it was focused on a couple of narrow use cases, including opening a movie theater chain's website to fill out all of the necessary information on a user's behalf -- pausing to prompt for choices like seats. But Duplex on the Web later expanded to passwords, helping users automatically change passwords exposed in a data breach, as well as assisted checkout for ecommerce retailers, flight check-in for airline sites and automatic discount finding. The promise of Duplex on the Web was that you'd be able to issue Google Assistant a command like "Book me a car from Hertz" and have Duplex pull up the relevant web page and automatically fill in details like your name, car preferences, trip dates, payment information (using information from Gmail and Chrome autofill), and more.
The Military

US Army Planned To Pay Streamers Millions To Reach Gen-Z Through Call of Duty (vice.com) 85

The U.S. Army allocated millions of dollars to sponsor a wide range of esports tournaments, individual high profile Call of Duty streamers, and Twitch events in the last year to specifically grow its audience with Gen-Z viewers, and especially women and Black and Hispanic people, according to internal Army documents obtained by Motherboard. From the report: In many cases the sponsorships ultimately did not happen -- the Army ordered a stop of all spending with Call of Duty's publisher Activision after the company faced a wave of sexual harrassment complaints. But the documents provide much greater insight into the Army's goals and intentions behind its planned integrations with Call of Duty and other massive entertainment franchises.

"Audience: Gen-Z Prospects (A18-24)," one section of the documents read. "Focus on the growth of females, Black & Hispanics." Motherboard obtained the documents through the Freedom of Information Act (FOIA). A table included in the documents lists the funds the Army planned to spend on various platforms, events, and streamers. At the top, is Twitch and its HBCU [Historically Black Colleges and Universities] Showdown. Previous seasons of this esports league had players compete in Madden and NBA games. The Army planned to spend $1 million on sponsoring the event. The documents show that the U.S. military considered gaming and, in particular, Call of Duty, as a potentially useful branding and recruiting tool.

Programming

Using Rust at a Startup: A Cautionary Tale (scribe.rip) 141

"Rust is awesome, for certain things. But think twice before picking it up for a startup that needs to move fast," Matt Welsh, co-founder and chief executive of Fixie.ai and former Google engineering director, writes in a blog post. From the post: I hesitated writing this post, because I don't want to start, or get into, a holy war over programming languages. (Just to get the flame bait out of the way, Visual Basic is the best language ever!) But I've had a number of people ask me about my experience with Rust and whether they should pick up Rust for their projects. So, I'd like to share some of the pros and cons that I see of using Rust in a startup setting, where moving fast and scaling teams is really important. Right up front, I should say that Rust is very good at what it's designed to do, and if your project needs the specific benefits of Rust (a systems language with high performance, super strong typing, no need for garbage collection, etc.) then Rust is a great choice. But I think that Rust is often used in situations where it's not a great fit, and teams pay the price of Rust's complexity and overhead without getting much benefit.

My primary experience from Rust comes from working with it for a little more than 2 years at a previous startup. This project was a cloud-based SaaS product that is, more-or-less, a conventional CRUD app: it is a set of microservices that provide a REST and gRPC API endpoint in front of a database, as well as some other back-end microservices (themselves implemented in a combination of Rust and Python). Rust was used primarily because a couple of the founders of the company were Rust experts. Over time, we grew the team considerably (increasing the engineering headcount by nearly 10x), and the size and complexity of the codebase grew considerably as well. As the team and codebase grew, I felt that, over time, we were paying an increasingly heavy tax for continuing to use Rust. Development was sometimes sluggish, launching new features took longer than I would have expected, and the team was feeling a real productivity hit from that early decision to use Rust. Rewriting the code in another language would have, in the long run, made development much more nimble and sped up delivery time, but finding the time for the major rewrite work would have been exceedingly difficult.

So we were kind of stuck with Rust unless we decided to bite the bullet and rewrite a large amount of the code. Rust is supposed to be the best thing since sliced bread, so why was it not working so well for us? [...] Despite being some of the smartest and most experienced developers I had worked with, many people on the team (myself included) struggled to understand the canonical ways to do certain things in Rust, how to grok the often arcane error messages from the compiler, or how to understand how key libraries worked (more on this below). We started having weekly "learn Rust" sessions for the team to help share knowledge and expertise. This was all a significant drain on the team's productivity and morale as everyone felt the slow rate of development. As a comparison point of what it looks like to adopt a new language on a software team, one of my teams at Google was one of the first to switch entirely from C++ to Go, and it took no more than about two weeks before the entire 15-odd-person team was quite comfortably coding in Go for the first time.

IBM

IBM and Maersk Abandon Ship on TradeLens Logistics Blockchain (coindesk.com) 28

Maersk and IBM will wind down their shipping blockchain TradeLens by early 2023, ending the pair's five-year project to improve global trade by connecting supply chains on a permissioned blockchain. From a report: TradeLens emerged during the "enterprise blockchain" era of 2018 as a high-flying effort to make inter-corporate trade more efficient. Open to shipping and freight operators, its members could validate the transaction of goods as recorded on a transparent digital ledger.

The idea was to save its member-shipping companies money by connecting their world. But the network was only as strong as its participants; despite some early wins, TradeLens ultimately failed to catch on with a critical mass of its target industry. "TradeLens has not reached the level of commercial viability necessary to continue work and meet the financial expectations as an independent business," Maersk Head of Business Platforms Rotem Hershko said in a statement.

Iphone

Smartphones Wiped 97% of Compact Digital Camera Market 96

Japanese camera manufacturers are bidding farewell to a once-major component of their operations, with Panasonic Holdings and Nikon suspending development of entry-level point-and-shoot cameras under their flagship brands. From a report: The companies will instead focus resources on pricier mirrorless models going forward, aiming to navigate a market upended by smartphones. Casual photographers flocked to compact digital cameras in the mid- to late 1990s, embracing their affordability and portability compared with single-lens reflex cameras. Global shipments reached 110 million units in 2008, according to the Camera & Imaging Products Association (CIPA). But as the iPhone and other camera-equipped smartphones won general consumers over, the camera industry fell off a cliff. Global shipments of compact digital cameras plunged 97% from the 2008 level to just 3.01 million units in 2021.

Panasonic has been scaling back its model offerings in Lumix compact digital cameras, which debuted in 2001 and enjoyed high spots in domestic rankings at one point. The company has not released any new product for the price range below 50,000 yen ($370 at current rates) or so since 2019 and has no plans to develop a low-priced model going forward. "We've halted developing any new models that can be replaced by a smartphone," a spokesperson said. Panasonic will continue production of current offerings. But its focus going forward will be on developing high-end mirrorless cameras for photography enthusiasts and professionals. Nikon has suspended development of new compact models in its Coolpix line. It now offers just two models with high-powered lenses but it is "closely monitoring market trends" to determine production volumes going forward, according to an official. Nikon has also withdrawn from development of SLR cameras to specialize in upmarket mirrorless single-lens models. These companies are following in rivals' footsteps. Fujifilm has discontinued production of its FinePix compact cameras and will develop only the X100V series and other pricier models.
The Military

Pentagon Debuts Its New Stealth Bomber, the B-21 Raider 108

America's newest nuclear stealth bomber is making its public debut after years of secret development and as part of the Pentagon's answer to rising concerns over a future conflict with China. From a report: The B-21 Raider is the first new American bomber aircraft in more than 30 years. Almost every aspect of the program is classified. Ahead of its unveiling Friday at an Air Force facility in Palmdale, California, only artists' renderings of the warplane have been released. Those few images reveal that the Raider resembles the black nuclear stealth bomber it will eventually replace, the B-2 Spirit.

The bomber is part of the Pentagon's efforts to modernize all three legs of its nuclear triad, which includes silo-launched nuclear ballistic missiles and submarine-launched warheads, as it shifts from the counterterrorism campaigns of recent decades to meet China's rapid military modernization. China is on track to have 1,500 nuclear weapons by 2035, and its gains in hypersonics, cyber warfare, space capabilities and other areas present "the most consequential and systemic challenge to U.S. national security and the free and open international system," the Pentagon said this week in its annual China report.
Facebook

Meta Urges Washington To Take Hands-Off Approach To Regulating the Metaverse (bloomberg.com) 54

Meta is urging policymakers to hold off on creating new rules governing the metaverse. From a report: In a policy paper released Friday, Meta argues that many of the world's existing laws and regulations will also apply to activity in the metaverse -- a catch-all term that refers to an immersive virtual world that doesn't yet exist in which users could someday work, play games, shop and interact. Edward Bowles, Meta's head of fintech policy, told reporters that regulators could "stymie innovation" if they create an entirely new regulatory scheme for the metaverse. It's common for corporations, particularly Silicon Valley titans, to discourage politicians from creating new regulations. But in recent years, lawmakers have become interested in reining in the biggest tech companies -- including their investments in virtual reality. The paper is an effort by Meta to shape future legislation impacting the metaverse, a technology so central to the company's mission that it rebranded to "Meta" from "Facebook" last year.
Technology

BloomTech, Previously Lambda School, Cuts Half of Staff (techcrunch.com) 13

A little over a year after buzzy coding bootcamp Lambda School rebranded as Bloom Institute of Technology, the venture-backed startup is conducting massive layoffs, TechCrunch reported, citing sources. From the report: The workforce reduction, per people familiar with the matter, has impacted half of the company's staff across content, product, data and engineering teams. The layoff is expected to have impacted around 88 employees, using metrics provided in BloomTech's 2022 diversity report metrics.

Employees were called into an All Hands meeting this morning in which BloomTech CEO Austen Allred notified staff of the impending layoffs. After the meeting, those impacted were notified via e-mail. According to documents seen by TechCrunch, employees will get normal pay and medical benefits until January 31, 2023 and are "expected to work" through that period. Those laid off were also offered optional time with managers to talk.

Mozilla

Mozilla Acquires Active Replica To Build On its Metaverse Vision (techcrunch.com) 39

An automated status updater for Slack isn't the only thing Mozilla acquired this week. From a report: On Wednesday, the company announced that it snatched up Active Replica, a Vancouver-based startup developing a "web-based metaverse." According to Mozilla SVP Imo Udom, Active Replica will support Mozilla's ongoing work with Hubs, the latter's VR chatroom service and open source project. Specifically, he sees the Active Replica team working on personalized subscription tiers, improving the onboarding experience and introducing new interaction capabilities in Hubs.

"Together, we see this as a key opportunity to bring even more innovation and creativity to Hubs than we could alone," Udom said in a blog post. "We will benefit from their unique experience and ability to create amazing experiences that help organizations use virtual spaces to drive impact. They will benefit from our scale, our talent, and our ability to help bring their innovations to the market faster." Active Replica was founded in 2020 by Jacob Ervin and Valerian Denis. Ervin is a software engineer by trade, having held roles at AR/VR startups Metaio, Liminal AR and Occipital. Denis has a history in project management -- he worked for VR firms including BackLight, which specializes in location-based and immersive VR experiences for brands.

Privacy

Hive Social Turns Off Servers After Researchers Warn Hackers Can Access All Data (arstechnica.com) 73

An anonymous reader quotes a report from Ars Technica: Hive Social, a social media platform that has seen meteoric growth since Elon Musk took over Twitter, abruptly shut down its service on Wednesday after a security advisory warned the site was riddled with vulnerabilities that exposed all data stored in user accounts. "The issues we reported allow any attacker to access all data, including private posts, private messages, shared media and even deleted direct messages," the advisory, published on Wednesday by Berlin-based security collective Zerforschung, claimed. "This also includes private email addresses and phone numbers entered during login." The post went on to say that after the researchers privately reported the vulnerabilities last Saturday, many of the flaws they reported remained unpatched. They headlined their post "Warning: do not use Hive Social." Hive Social responded by pulling down its entire service. "The Hive team has become aware of security issues that affect the stability of our application and the safety of our users," company officials wrote. "Fixing these issues will require temporarily turning off our servers for a couple of days while we fix this for a better and safer experience."

Technical details are being withheld to prevent the active exploitation of them by malicious hackers. According to Business Insider, Hive Social's user base has doubled in the last few weeks, going from about 1 million to 2 million as of last week. The site is only being staffed by two people, "neither of whom had much of a background in security," reports Ars.
Android

Google Reports Decline In Android Memory Safety Vulnerabilities As Rust Usage Grows (9to5google.com) 23

Last year, Google announced Android Open Source Project (AOSP) support for Rust, and today the company provided an update, while highlighting the decline in memory safety vulnerabilities. 9to5Google reports: Google says the "number of memory safety vulnerabilities have dropped considerably over the past few years/releases."; Specifically, the number of annual memory safety vulnerabilities fell from 223 to 85 between 2019 and 2022. They are now 35% of Android's total vulnerabilities versus 76% four years ago. In fact, "2022 is the first year where memory safety vulnerabilities do not represent a majority of Android's vulnerabilities."

That count is for "vulnerabilities reported in the Android security bulletin, which includes critical/high severity vulnerabilities reported through our vulnerability rewards program (VRP) and vulnerabilities reported internally." During that period, the amount of new memory-unsafe code entering Android has decreased: "Android 13 is the first Android release where a majority of new code added to the release is in a memory safe language. "

Rust makes up 21% of all new native code in Android 13, including the Ultra-wideband (UWB) stack, DNS-over-HTTP3, Keystore2, Android's Virtualization framework (AVF), and "various other components and their open source dependencies." Google considers it significant that there have been "zero memory safety vulnerabilities discovered in Android's Rust code" so far across Android 12 and 13.
Google's blog post today also talks about non-memory-safety vulnerabilities, and its future plans: "... We're implementing userspace HALs in Rust. We're adding support for Rust in Trusted Applications. We've migrated VM firmware in the Android Virtualization Framework to Rust. With support for Rust landing in Linux 6.1 we're excited to bring memory-safety to the kernel, starting with kernel drivers.
Security

Hyundai App Bugs Allowed Hackers To Remotely Unlock, Start Cars (bleepingcomputer.com) 29

Vulnerabilities in mobile apps exposed Hyundai and Genesis car models after 2012 to remote attacks that allowed unlocking and even starting the vehicles. BleepingComputer reports: Security researchers at Yuga Labs found the issues and explored similar attack surfaces in the SiriusXM "smart vehicle" platform used in cars from other makers (Toyota, Honda, FCA, Nissan, Acura, and Infinity) that allowed them to "remotely unlock, start, locate, flash, and honk" them. At this time, the researchers have not published detailed technical write-ups for their findings but shared some information on Twitter, in two separate threads.

The mobile apps of Hyundai and Genesis, named MyHyundai and MyGenesis, allow authenticated users to start, stop, lock, and unlock their vehicles. After intercepting the traffic generated from the two apps, the researchers analyzed it and were able to extract API calls for further investigation. They found that validation of the owner is done based on the user's email address, which was included in the JSON body of POST requests. Next, the analysts discovered that MyHyundai did not require email confirmation upon registration. They created a new account using the target's email address with an additional control character at the end. Finally, they sent an HTTP request to Hyundai's endpoint containing the spoofed address in the JSON token and the victim's address in the JSON body, bypassing the validity check. To verify that they could use this access for an attack on the car, they tried to unlock a Hyundai car used for the research. A few seconds later, the car unlocked. The multi-step attack was eventually baked into a custom Python script, which only needed the target's email address for the attack.

Yuga Labs analysts found that the mobile apps for Acura, BMW, Honda, Hyundai, Infiniti, Jaguar, Land Rover, Lexus, Nissan, Subaru, and Toyota, use SiriusXM technology to implement remote vehicle management features. They inspected the network traffic from Nissan's app and found that it was possible to send forged HTTP requests to the endpoint only by knowing the target's vehicle identification number (VIN). The response to the unauthorized request contained the target's name, phone number, address, and vehicle details. Considering that VINs are easy to locate on parked cars, typically visible on a plate where the dashboard meets the windshield, an attacker could easily access it. These identification numbers are also available on specialized car selling websites, for potential buyers to check the vehicle's history. In addition to information disclosure, the requests can also carry commands to execute actions on the cars. [...] Before posting the details, Yuga Labs informed both Hyundai and SiriusXM of the flaws and associated risks. The two vendors have fixed the vulnerabilities.

Social Networks

Kanye West Is No Longer Buying Parler (axios.com) 94

Parler announced Thursday it reached a mutual agreement with Ye, formerly known as Kanye West, to terminate the sale of the social media app. Axios reports: The deal already was on life support, as Axios previously reported, and it's unclear if a formal merger agreement was ever signed. Parler originally said it had an agreement "in principle," and today referred to it as "intent of sale." A Parler spokesperson previously told Axios that the acquisition was set to close by year-end but declined to say if Ye ever had signed paperwork to that effect.

In a statement, Parler's parent company said: "This decision was made in the interest of both parties in mid-November. Parler will continue to pursue future opportunities for growth and the evolution of the platform for our vibrant community." A source familiar with the situation said that Ye's precarious financial situation -- including the loss of his Adidas deal -- played a role in the deal collapse.

The Internet

Web Browsers Drop Mysterious Company With Ties To US Military Contractor (washingtonpost.com) 57

An anonymous reader quotes a report from the Washington Post: Major web browsers moved Wednesday to stop using a mysterious software company that certified websites were secure, three weeks after The Washington Post reported its connections to a U.S. military contractor. Mozilla's Firefox and Microsoft's Edge said they would stop trusting new certificates from TrustCor Systems that vouched for the legitimacy of sites reached by their users, capping weeks of online arguments among their technology experts, outside researchers and TrustCor, which said it had no ongoing ties of concern. Other tech companies are expected to follow suit.

The Post reported on Nov. 8 that TrustCor's Panamanian registration records showed the same slate of officers, agents and partners as a spyware-maker identified this year as an affiliate of Arizona-based Packet Forensics, which has sold communication interception services to U.S. government agencies for more than a decade. One of those contracts listed the "place of performance" as Fort Meade, Md., the home of the National Security Agency and the Pentagon's Cyber Command. The case has put a new spotlight on the obscure systems of trust and checks that allow people to rely on the internet for most purposes. Browsers typically have more than a hundred authorities approved by default, including government-owned ones and small companies, to seamlessly attest that secure websites are what they purport to be.
"Certificate Authorities have highly trusted roles in the internet ecosystem and it is unacceptable for a CA to be closely tied, through ownership and operation, to a company engaged in the distribution of malware," Mozilla's Kathleen Wilson wrote to a mailing list for browser security experts. "Trustcor's responses via their Vice President of CA operations further substantiates the factual basis for Mozilla's concerns."
Australia

Australia Will Now Fine Firms Up To $33.4 Million for Data Breaches (bleepingcomputer.com) 19

The Australian parliament has approved a bill to amend the country's privacy legislation, significantly increasing the maximum penalties to AU$50 million for companies and data controllers who suffered large-scale data breaches. From a report: The financial penalty introduced by the new bill is set to whichever is greater: AU$50 million, three times the value of any benefit obtained through the misuse of information, and 30% of a company's adjusted turnover in the relevant period.

Previously, the penalty for severe data exposures was AU$2.22 million, considered wholly inadequate to incentivize companies to improve their data security mechanisms. The new bill comes in response to a series of recent cyberattacks against Australian companies, including ransomware and network breaches, resulting in the exposure of highly sensitive data for millions of people in the country. "The Albanese Labor government has wasted no time in responding to recent major data breaches. We have announced, introduced, and delivered legislation in just over a month," reads the media announcement. "These new, larger penalties send a clear message to large companies that they must do better to protect the data they collect."

Social Networks

Messaging App Telegram Moving Into Crypto 29

As the FTX collapse continues to reverberate through the cryptocurrency sector, Telegram CEO Pavel Durov wants to revive some of the good will toward blockchain technology by developing a range of decentralized tools including digital asset exchanges. From a report: "The blockchain industry was built on the promise of decentralization, but ended up being concentrated in the hands of a few who began to abuse their power," Durov wrote Wednesday on his Telegram page. "As a result, a lot of people lost their money when FTX, one of the largest exchanges, went bankrupt." The antidote to FTX's downfall is renewed prioritization of decentralization, he said. Durov maintained that blockchain projects must return to their roots of decentralization, and move away from relying on third-party corporations.

Additionally, he said it's possible today for developers to steer the blockchain away from centralization with the release of new products that a wide audience can access. Moving forward, Telegram, a messaging and social-media app, will build non-custodial wallets and decentralized exchanges for millions of people to trade and store cryptocurrencies, Durov said. "This way we can fix the wrongs caused by the excessive centralization, which let down hundreds of thousands of cryptocurrency users," he said. "The time when the inefficiencies of legacy platforms justified centralization should be long gone. With technologies like TON reaching their potential, the blockchain industry should be finally able to deliver on its core mission -- giving the power back to the people."
Mozilla

Mozilla Acquires Team Behind Pulse, an Automated Status Updater for Slack (techcrunch.com) 5

Firefox developer Mozilla is making a rare foray into the world of mergers and acquisitions, with news that it has snapped up recently-shuttered California-based productivity startup Pulse. From a report: Terms of the deal haven't been disclosed, but the deal is tantamount to an "acqui-hire," with Mozilla looking to deploy the Pulse team across an array of machine learning (ML) projects. "We're acquiring Pulse for the incredible team they have built," Mozilla chief product officer Steve Teixeira told TechCrunch. "As we look to continue to improve user experiences across all of our products, ML will be a core part of that."

Founded out of Menlo Park in 2019, Pulse in its initial guise was a "virtual office" platform called Loop Team, but after honing the idea for a couple of years it pivoted and rebranded last November. Pulse, essentially, was an automated status-updating tool that used signals based on pre-configured integrations and preferences set by the user. For example, users could synchronize Pulse with their calendar and Slack, setting rules to stipulate what their status and corresponding emoji should be based on keywords in their calendar event title. If their schedule for a particular time says "hair appointment" from 12-1pm, then the person's Slack status update might display a scissors emoji alongside the word "haircut." Or, it might say "birthday" alongside a cake emoji if that's what is in their calendar.

United Kingdom

Just 22% of Techies in UK Aged 50 or Older, Says Chartered Institute For IT (theregister.com) 105

A little more than one in five techies in Britain is aged 50 or older, and enticing more of that demographic to enter the world of information technology could help alleviate a perennial skills gap. From a report: This is according to research by the British Computer Society (BCS), which reckons just 22 percent (413,000) of the 1.9 million IT specialists in the local industry are at or past the half century mark. To fall in line with the average number of 50 year olds or older across all other employment areas (561,000) in the UK, an additional 148,000 people in that grouping are needed in the tech sector, the BCS claimed, basing its finding on data provided by the Office for National Statistics.

"We can only achieve the government's ambition for the UK to be the 'next Silicon Valley' by closing the digital skills gap and making this vital profession attractive to a far broader range of people," said Rashik Parmar MBE, CEO of the BCS. For those not aware, the UK government's latest harebrained scheme, outlined in the Autumn statement by Chancellor Jeremy Hunt, is to convert the island nation into "the next Silicon Valley". Sounds plausible? Oven-baked plan? No, we didn't think so either. The age factor was most pronounced in the north-east of the UK where just one in eight programmers/developers was 50 or over, the research found -- but didn't state why.

Businesses

Irish Companies Report Success With Trial of Four-Day Working Week (www.rte.ie) 82

AmiMoJo writes: A research project that saw a four-day working week being trialled across 12 businesses has been deemed a success by both the companies and employees involved. The project, backed by the trade union Forsa and carried out in partnership by Four-Day Week Ireland, UCD and Boston College, examined the financial, social, and environmental impact that a four-day working week would have on businesses and employees in Ireland. Nine of the 12 companies that took part in the six-month trial said they were committed to continuing with the four-day-week schedule. The other three said they were also planning to continue but did not commit to keeping it long-term.

Seven companies provided data on revenue and of those, six reported monthly revenue growth, with one seeing a decline. Two companies that tracked energy usage found reductions. In general, management of the companies were said to have been very pleased with the outcome of the trial in terms of productivity and overall experience. On a scale of 1-10, from very negative to very positive, the companies' average rating for the trial was 9.2.

Businesses

Rising Tether Loans Add Risk To Stablecoin, Crypto World (wsj.com) 73

The company behind the tether stablecoin has increasingly been lending its own coins to customers rather than selling them for hard currency upfront. The shift adds to risks that the company may not have enough liquid assets to pay redemptions in a crisis. From a report: Tether says it lends only to eligible customers and requires that borrowers post lots of "extremely liquid" collateral, which could be sold for dollars if borrowers default. These loans have appeared for several quarters in the financial reports that Tether shows on its website. In the most recent report, they reached $6.1 billion as of Sept. 30, or 9% of the company's total assets. They were $4.1 billion, or 5% of total assets, at the end of 2021.

Tether calls them "secured loans" and discloses little about the borrowers or the collateral accepted. Alex Welch, a Tether spokeswoman, confirmed that all of the secured loans listed in the reports were issued and denominated in tether. The company said the loans were short-term and that Tether holds the collateral. Tether, which is incorporated in the British Virgin Islands, doesn't publish audited financial statements or a complete balance sheet, leaving outsiders with an incomplete picture of the company's financial health. "Tether's disclosures are limited to the information contained in the mentioned reports," Ms. Welch said. The rise in Tether's lending represents a broad risk to the crypto world. Stablecoins such as tether are anchors in the system. They are vital for trading many cryptocurrencies and are widely held by traders. The premise of tether -- and other stablecoins -- is that the issuer always will redeem one coin for $1. Issuers take pains to demonstrate they have ample funds available to do so. The company's reports show only U.S. dollar amounts for the loans and don't say the loans were made in tether tokens. The reports also say the loans were "fully collateralized by liquid assets."

Slashdot Top Deals