# BCB starts Hypernative crypto threat alerts

> Brazil's central bank is rolling out Hypernative real-time crypto threat alerts. ABToken says Mercado Bitcoin and Foxbit should start receiving them within two weeks.

- **Source:** https://ptycoin.com/en/posts/2026-08-30-bcb-hypernative-crypto-threat-alerts/
- **Published:** 2026-08-30
- **Category:** News
- **Author:** Mateo
- **Tags:** brazil, banks, security, exchanges, bitcoin
- **Also published in:** [Español](https://ptycoin.com/es/posts/2026-08-30-bcb-hypernative-crypto-threat-alerts/)

---


Brazil's **Banco Central do Brasil (BCB)** is rolling out a real-time crypto threat-alert system built with blockchain-security firm **Hypernative**, and industry groups expect domestic banks and exchanges including **Mercado Bitcoin** and **Foxbit** to start receiving those alerts within two weeks.

[Valor Econômico reported](https://valor.globo.com/financas/criptomoedas/noticia/2026/08/25/bc-prepara-sistema-de-alertas-para-ameaas-envolvendo-criptoativos.ghtml) on 25 August, updated 28 August, that the tool has already been tested with market participants. **Regina Pedroso**, executive director of the Brazilian Tokenization Association (**ABToken**), told Valor the associations will take the feeds and pass them to members. "The challenge now is to implement the tool. It has already been tested by the Central Bank, some bulletins have already been issued, and now associations have to adapt to receive and distribute the alert," she said.

## What the BCB is actually buying

On **20 August**, [Hypernative said](https://www.hypernative.io/insights/blog/banco-central-do-brasil-advances-to-contracting-hypernative-to-support-real-time-crypto-fraud-intelligence) the BCB is advancing to contract the company to run a continuous on-chain monitoring and fraud-intelligence program for the Brazilian financial sector, covering banks, payment institutions, and virtual-asset service providers. The BCB would be Hypernative's first central-bank customer. The same announcement was [posted on X](https://x.com/HypernativeLabs/status/2090442555825565809) that day.

The company described a proof of value built on Brazilian market data: agents watching BRL and crypto volume anomalies across major local exchanges, plus cross-exchange timing, intraday velocity, and behavioral markers matched to known fraud fingerprints. Hypernative says one preparatory alert fired **14 hours** before funds moved in a confirmed incident. Treat that figure as the vendor's claim. The same post footnotes that it "reflects model capability, not guaranteed detection."

A statement attributed to the BCB in that announcement said existing tooling was built for the traditional financial system, and that as fraud patterns increasingly intersect with cryptoasset flows, timely and explainable alerts matter for supervisory work. The quote appears on Hypernative's site, not in a standalone BCB press release.

Pedroso's emphasis, as carried by Valor and [Bitcoin.com News](https://news.bitcoin.com/security/brazil-deploys-crypto-alerts-system-to-neutralize-cyber-threats/), is narrower and more operational: keep **traceability** when money leaves bank rails and enters crypto wallets.

## The 2025 C&M drain is the scar this is meant to close

On **30 June 2025**, attackers used stolen credentials at **C&M Software**, a connectivity provider for smaller Brazilian financial institutions, to reach reserve accounts used for interbank settlement. [Reuters](https://www.reuters.com/world/americas/brazils-cm-software-hit-by-cyberattack-central-bank-says-2025-07-02/) confirmed the incident and the BCB's order that C&M shut down client access. Six institutions, including **BMP**, reported unauthorized access to those reserve accounts. Reuters did not publish a loss figure.

Later reporting put the haul in a wide range. [CoinDesk](https://www.coindesk.com/business/2025/07/04/hackers-behind-usd140m-brazil-banking-heist-turn-to-crypto-to-launder-their-loot), citing on-chain investigator **ZachXBT**, wrote that attackers converted an estimated **$30 million to $40 million** of a roughly **$140 million** theft into bitcoin, ether, and USDT through Latin American exchanges and OTC desks. Other local estimates ran as high as **$180 million**. ZachXBT said work with Binance, Bitso, Bybit, and Tether froze about **$5 million**.

The cash-out path was the part the existing bank-fraud stack could not see in time: reais moved over **Pix**, then into BTC and USDT. That is the hop the new alert layer is supposed to catch while the coins are still sitting on a Brazilian venue.

## How the feed reaches a desk

This is a sharing system that sits beside the statute. Associations receive bulletins and push them to members. Whether an exchange actually flags, delays, or freezes a withdrawal still depends on that firm's own controls and on rules already on the books.

Those rules are moving on a separate clock. [Resolução BCB nº 584](/en/posts/2026-08-13-brazil-bcb-584-24h-hold-jan-2027/) will, from **1 January 2027**, require a precautionary hold of up to 24 hours on virtual-asset transfers above **US$10,000** (single or same-day total) sent to self-custody or a foreign provider. The Hypernative feed is meant to give compliance desks something to act on during that kind of window, and on smaller tickets that never trip the 584 line.

If you use Mercado Bitcoin, Foxbit, or another Brazilian platform:

- Large Pix-funded buys that immediately leave for a hardware wallet or a foreign exchange are the flows most likely to get extra scrutiny once alerts are live.
- Coins already in a wallet you control sit outside the BCB's reach. The new layer watches the **regulated hop**, not your keys.
- Holding your own keys stays legal. The practical change is speed and questions at the exit.

Supervisors in the rest of LatAm do not automatically get this feed. What they get is a working template: a named vendor, named local exchanges, and a distribution path through industry associations rather than a single central-bank mailbox.

## Takeaway

The BCB is putting Hypernative threat alerts into the hands of Brazilian banks and exchanges, with ABToken expecting Mercado Bitcoin and Foxbit in the first wave over the coming two weeks. The 2025 C&M drain showed how fast stolen reais can become BTC and USDT; this is the operational answer, next to the 2027 24-hour hold.

If you cash in or out through a Brazilian VASP, assume large, fast exits will face more questions. If you already hold keys, that is still the part of the stack the alert cannot pause. This is reporting on a supervisory tool.

---

## Keep reading

- [How to practice a seed phrase restore before you need it](https://ptycoin.com/en/posts/2026-08-18-practice-seed-phrase-restore/index.md): A written seed phrase is only a backup after you prove it restores the same wallet. Practice the restore on a spare or wiped device before real funds depend on it.
- [Self-custody without a single point of failure](https://ptycoin.com/en/posts/2026-08-10-self-custody-without-single-point-of-failure/index.md): A hardware wallet can generate a key badly. Build a self-custody setup that survives a vendor bug: verified backups, your own entropy, passphrases, and multi-vendor multisig.
- [How to read a block explorer and verify a transaction](https://ptycoin.com/en/posts/2026-07-07-read-block-explorer-verify-transactions/index.md): A block explorer is the public receipt for every on-chain move. Learn how to look up a transaction ID, read confirmations, and confirm funds arrived at the right address.

---

Source: PTYcoin — https://ptycoin.com/en/posts/2026-08-30-bcb-hypernative-crypto-threat-alerts/. Free to read and cite with attribution to ptycoin.com. AI-usage terms: https://ptycoin.com/en/ai-usage/
