
Coinbase's Layer 2 network introduces 'Validity Transactions' and extends the B20 standard for regulated asset management.
AI-generated summary
Base is a Layer 2 network incubated by Coinbase. The Cobalt update follows the Beryl update introduced in June.
The conditional order enters the protocol. Base activated Cobalt on September 30, its third major mainnet update. It introduces Validity Transactions and extends B20, the token standard launched in June to facilitate the issuance of assets with compliance rules.
Layer 2 incubated by Coinbase thus targets two distinct uses: traders who wish to precisely define the conditions for executing a transaction and issuers of stablecoins or tokenized assets subject to regulatory obligations.
Key Points
Validity Transactions become eligible only when several conditions registered in advance are met
Submissions can remain private until included, reducing their exposure to arbitrage bots
B20 allows you to combine KYC or sanctions policies without duplicating their address lists
An optional function authorizes the administrative entry of tokens and registers the onchain operation
Base adds transactions that wait for the right time
Validity Transactions allow you to sign and then submit a transaction accompanied by conditions relating to the state of the network. Base currently supports criteria related to Flashblock balance, storage, block number, or index.
A trader can, for example, prepare a swap that only becomes eligible if the price of a pool reaches a given level before a specific block. The sequencer checks the conditions before any inclusion. If they are never met within the expected period, the transaction expires without being executed.
This mechanic is similar to a conditional order, but it does not reserve any place in a block and does not guarantee execution. A transaction that has become eligible may still remain pending if its fees are insufficient or if the network does not include it in time.
Base also states that submissions remain private until included. This confidentiality limits their exposure in the public mempool and reduces the risk that a robot anticipates the order to supervise the swap of a purchase and a resale, a practice called sandwich attack. However, it does not constitute absolute protection against all forms of reorganization or value extraction.
The validity conditions are sent separately from the signed transaction and do not appear in the operation finally recorded on-chain. The Base documentation nevertheless recommends not placing any secret information in the call data or the criteria used.
B20 combines compliance, securities transactions and capture
Cobalt also extends B20, the ERC-20 compatible standard introduced by the Beryl update on June 25. Its main novelty lies in Composite Policies, which allow you to associate two to four authorization or blocking lists with AND or OR logic.
A fund can thus require that a recipient appear simultaneously on a KYC list and on a register of accredited investors. If its address disappears from either source, the transfer automatically fails. The system reuses existing policies without copying their members or maintaining off-chain synchronization.
Issuers can also schedule a change to the multiplier used to display balances. This function, aligned with the ERC-8056 standard, is used in particular to reflect a share split or the reinvestment of a dividend without modifying the gross balances or the economic value held.
Cobalt finally adds sixteenWithMemo to B20 assets and stablecoins. When an issuer enables this capability and configures the necessary permissions, an administrator can transfer the balance of a designated account to another address. The operation records the originator of the entry, the originating address, the destination, the amount and a 32-byte memo. The latter can serve as a reference, but does not guarantee that a detailed justification is written clearly.

The Danish government announced on Monday the leak of the data of nearly 8.8 million people registered in the central population register, consulted illegally via access from a private company.

Near Intents has recovered all of the $3.8 million stolen in an attack on its cross-chain swap service, following a 48-hour ultimatum from its chief executive.

In the third quarter of 2026, cryptocurrency hacks resulted in the theft of $1.26 billion according to CertiK, despite a 40% increase in bitcoin over the same period. September was the worst month with $768.5 million lost, mainly due to code and infrastructure flaws. Net losses after recoveries amounted to 869.6 million for the quarter, while the sector's insurance capacity fell by 20% year-on-year. Major attacks have targeted Bitget, Liquid Network and Tectonic, exploiting vulnerabilities in third-party providers, cryptographic proofs and lending protocols. AI now accelerates the detection of flaws in smart contracts.

In its 2026 index published on September 23, Chainalysis ranks Brazil first in the world for crypto adoption, ahead of the United States. Latin American activity grew by 9.8%, driven by the massive use of stablecoins.

OpenAI fired three employees for sharing confidential information with a third-party organization. This case comes shortly after the cancellation of GPT-6.1 Astra.

The Ethereum Foundation launched zkAPI, a protocol for paying for AI services via Ethereum without tying requests to an identity or account, ensuring anonymity of transactions through zero-knowledge proofs.