A failed hook can now stop the action.
Claude Code 2.1.295 adds onFailure: "block" for command and HTTP hooks:
- Can't start
- Times out
- Exits unexpectedly
Blocking is an explicit option, not a guarantee for every hook.
https://t.co/cxB8MUYU3l
Interrupting a check shouldn't let the prompt through.
Claude Code 2.1.296 reports a fix for interrupted prompt hooks that could pass unchecked prompts. A useful regression test: interrupt the check, then verify the prompt stays blocked.
https://t.co/RlBaYkgrqg
The UK is targeting sanctions-evasion channels.
Its latest action includes three crypto exchanges suspected of helping Russia circumvent financial sanctions.
https://t.co/ObdKcyKGlU
MiCA enforcement now has a three-month cleanup window.
ESMA says national regulators should require crypto platforms to resolve remaining exposure to non-compliant stablecoins as soon as possible, with three months as the outer limit.
https://t.co/ofwBSn0oRf
"Block commands that..." should block them.
Claude Code 2.1.294 fixes instruction-style prompt and agent hooks allowing actions they should forbid. It also improves how instruction-style Stop and SubagentStop hooks are judged.
https://t.co/QXCaWdthuE
The CFTC is seeking input on a federal framework for retail crypto transactions.
Its advance notice of proposed rulemaking starts the process. It is not a final rulebook for crypto markets.
https://t.co/JcoE2bc6Ps
A worker restart should not skip an approval check.
Claude Code 2.1.292 fixes tool calls bypassing plugin permission hooks while the hooks worker restarts. A concrete recovery case to include in coding-agent permission tests.
https://t.co/Wgeixk4HNy
Two proposed US crypto rules are being withdrawn.
FinCEN is withdrawing its crypto-mixing proposal and the proposed reporting rule for unhosted-wallet transactions.
https://t.co/K7X1zAcQI2
An approval reply should never approve a different prompt.
Claude Code 2.1.290 fixes a permission-relay bug: repeated reply IDs within a session are now ignored instead of approving another prompt.
https://t.co/d8iQWU553Q
Protocol governance also has an institutional side.
Aave's Phase 1 ARFC proposes establishing the Aave Foundation. The proposal is now in governance discussion.
https://t.co/l6EVjrE4jB
Two controls to inspect in vLLM 0.31.0:
- Weight-cache preload keeps post-quantized weights in GPU memory across engine restarts.
- An active-sequence cap limits running admission separately from the existing sequence limit.
https://t.co/6w4VbOtDf3
A higher entry bar for Lido's proposed staking route.
The governance proposal calls for an entry bond more than 13 times that of the existing default route.
https://t.co/wPjaHVQv0S
A mod's approval should not override a deny rule.
Claude Code 2.1.289 fixes nested shell deny/ask rules losing precedence to user-installed mods on managed machines. It also closes a Read-denial bypass through symlinked IDE references.
https://t.co/6KWjBxUHIY
Core Lightning warns that attackers are targeting unpatched nodes.
The team says it has received reports of attacks and urges operators on older releases to upgrade. This is a Lightning node-software warning, not a Bitcoin consensus issue.
https://t.co/H6FMkBk262
Urgent security update: If you’re running version 26.06.7 or earlier, please upgrade to the latest release as soon as possible.
We’ve received reports that attackers are targeting unpatched nodes. Keeping your node up to date is an important step in protecting your funds.
A held message was being reported as delivered.
Claude Code 2.1.288 fixes that cross-session status error: the notice now says the message wasn't delivered and names the session holding it.
Agent handoffs need accurate receipts.
https://t.co/ORfLoFFKzN
Coinbase's International Exchange is now read-only.
Coinbase marked its Deribit migration complete on October 1. Trading has moved to Deribit; clients can no longer trade on the old venue.
https://t.co/vlouEZawbX
Deletion safeguards need edge-case tests.
Claude Code 2.1.287 fixes an always-ask check that could disappear when a dangerous rm command also redirected output to a ~ or wildcard path.
Test command combinations, not just isolated actions.
https://t.co/Iuz3gzuwD9
Two fixes worth adding to agent regression tests in Claude Code 2.1.286:
- Lost session history after a crash.
- Background jobs showing done while waiting for approval.
Test recovery and completion states separately.
https://t.co/DKCGQ0TBdt
The UK's crypto authorization window is open.
The FCA says firms intending to continue operating in the UK should apply by 28 February 2027, ahead of the new regime taking effect on 25 October 2027.
https://t.co/mpr0XlWkRT