
Hyperliquid announced a testnet-only extension called HIP-3* that allows independent market deployers to add optional wallet allowlists to their perpetual markets, enabling granular access controls without affecting existing markets or shifting responsibility to the protocol.
AI-generated summary
Hyperliquid's HIP-3 framework allows independent builders to deploy perpetual markets with customizable parameters. The HIP-3* extension adds optional wallet allowlist functionality on testnet, building upon the existing operator model where deployers maintain stake and assume economic responsibility.
In a Sept. 3 developer update, Hyperliquid API Announcements said the onchain derivatives exchange was adding optional wallet allowlists to builder-run perpetual markets. The testnet-only extension, called HIP-3*, would let a market deployer decide which wallets may trade on its venue without imposing the same access policy across Hyperliquid.
HIP-3 is Hyperliquid's framework for perpetual markets deployed by independent builders. The current API reference says a new venue can be designated HIP-3* when it is created, enabling an onchain allowlist and proxied user actions. Hyperliquid described the feature as optional and strictly additive, with existing markets unchanged. The specification is preliminary, available only on testnet and has no announced mainnet date.
How HIP-3* wallet allowlists work
A HIP-3* deployer can act for a user in five defined ways: add or remove allowlist approval, cancel specified resting orders, cancel all of the user's resting orders and time-weighted average price orders on the venue, place reduce-only orders, and move collateral to another account on the same venue.
Each power is limited by the venue boundary. The documented bulk-cancellation tool leaves orders on other DEXs untouched, the collateral-transfer function is venue-scoped, and every proxied order must be reduce-only. That last restriction allows an operator to reduce a position but not increase one through the proxy function.
A deployer may use all five tools itself or delegate them one by one to approved sub-deployers. One address could administer the allowlist while another handles cancellations, without receiving every available permission.
The reference does not enumerate every action a wallet outside the allowlist may still perform on its own. HIP-3* should therefore be understood as access control and operator powers for one newly created venue, not as a wallet freeze across Hyperliquid.
The design could give firms with customer or jurisdiction restrictions a technical way to build gated perpetual markets while other deployers continue using ordinary HIP-3. It does not amount to regulatory approval, protocol-wide know-your-customer checks or evidence that an institution has adopted HIP-3*. Hyperliquid said the tools are intended to help independent deployers operate under requirements applicable to them, leaving legal and operational choices with each deployer.
That separation also leaves the economic responsibility with the market operator. Under the existing HIP-3 specification, deployers define contracts, maintain oracles, set leverage limits and settle markets. Each deployer DEX has independent margining, order books and settings.
A mainnet HIP-3 deployer must currently maintain 500,000 HYPE in stake. Validators can slash that stake for irregular inputs that jeopardize protocol correctness, uptime or performance. HIP-3* adds access controls to that operator model; it does not shift responsibility for a restricted venue to Hyperliquid or alter permissionless markets elsewhere on the network.

Researchers identified a software cache flaw in Bitcoin sidechain Liquid Network that allowed unbacked L-BTC tokens to be redeemed for real Bitcoin, with evidence suggesting the bug entered the master branch a week prior but was not in a tagged release, leading to divergent node behavior where federation nodes accepted invalid transactions while others rejected them.

Solana Foundation announced a payment-channel system enabling over one million payments per second for AI services, where customers fund channels, merchants provide services, and operators manage payments; recovery mechanisms allow customers to reclaim deposits if operators go silent, while merchants must ensure bills settle on-chain before grace periods end to avoid uncollectible service.

Galaxy Research reported that 97.09 BTC worth about $7.7 million was moved from Wave 3 vaults linked to the Coldcard exploit, with funds routed through THORChain on September 2 and into CoinJoin rounds over the weekend. Across the entire Coldcard exploit, 82% of stolen Bitcoin remains unmoved. The thefts stem from a 2021 firmware flaw in Coinkite devices that weakened seed generation, allowing offline key reconstruction. Coinkite has since overhauled firmware but cannot repair compromised seeds, requiring users to generate new seeds and migrate funds.

An Ethereum prototype that assigns blob-recovery duties to specific nodes reduced estimated network-wide reconstruction computing work by 11–18× in 1,000-node simulations, according to researcher Csaba Kiraly's Sept. 3 report. The design avoids duplicative rebuilding by letting high-custody nodes recover data once and share it via existing channels, offering a simpler step toward the full RowDAS proposal while preserving PeerDAS-style backstop mechanisms.

Ethereum co-founder Vitalik Buterin said there is a 60% probability that SNARKs, fully homomorphic encryption, and indistinguishability obfuscation will eventually operate at less than 10 times the cost of ordinary computation, with a 33% chance all three approach near-zero overhead at scale. He noted cheaper cryptography could enable private proofs, encrypted computation, and hidden program logic, potentially transforming privacy from a specialized feature to a default layer in financial and computational systems, though progress may remain uneven even if the full breakthrough does not occur.

Liquid Network suspended operations after a software bug in the Elements protocol enabled the unauthorized withdrawal of nearly 4,000 BTC. The funds were moved by self-identified 'whitehats' who have promised to return the Bitcoin once the underlying vulnerability is patched.