Connect with us

Crypto World

Quantus Founder Warns Crypto’s First Quantum Attack Could Mimic Breach

Published

on

Crypto Breaking News

Quantum computing is often discussed in crypto as a future doomsday scenario—sometimes framed around the idea that Satoshi Nakamoto’s dormant Bitcoin could be drained once “Q-day” arrives. But Quantus Network CEO and co-founder Christopher Smith argues the first real-world impact may look far less cinematic: not a public, forensic-friendly hack, but a series of wallet breaches that are difficult to attribute to quantum capabilities at all.

Smith tells Cointelegraph that once quantum computers become powerful enough to break the public-key cryptography used by major blockchains, attackers may be able to derive private keys from public information on-chain. Crucially, the compromised pathway could avoid triggering obvious internal security failures in wallets or exchanges, leaving investigators with scant evidence beyond the fact that no meaningful breach was detected.

Key takeaways

  • Q-day attacks may be hard to detect because they can be executed without compromising a wallet, device, or exchange infrastructure.
  • Rather than only “Satoshi’s Bitcoin,” early quantum-enabled targets could include high-value administrative keys and other sensitive systems.
  • Security researchers believe attackers might prioritize hot wallets at exchanges because they are less likely to raise alarms quickly.
  • Predictions for when quantum can break modern elliptic-curve cryptography range from late-2020s odds to near-certainty in the early 2030s.
  • Blockchain teams are already migrating toward post-quantum signatures, largely because waiting for certainty is too risky.

Why quantum theft could be indistinguishable from “normal” breaches

Smith’s central warning is that quantum-enabled compromise may not resemble the kind of intrusion that generates clear forensic trails. “When someone cracks your key, you don’t get a memo saying how they did it,” he said in an interview with Cointelegraph. In this scenario, an attacker could compute the corresponding private key after enough quantum capability exists—using information already visible on a public blockchain.

That shift in attack mechanics matters for incident response. Smith suggests that if a highly secure organization were targeted, “the only forensic evidence would be that there was no breach.” The attacker wouldn’t need to exploit the systems in which the wallet is running, nor necessarily leave traces of compromise in logs that would point to a conventional intrusion path.

Security expectations are therefore likely to be mismatched with how the earliest quantum-driven thefts would appear. If investigators primarily look for device-level compromise, key-management failures, or exchange-side intrusions, they could be left without the traditional indicators that typically accompany catastrophic key loss.

Advertisement

The first targets may be more strategic than famous

Much of the public concern about Q-day focuses on Satoshi Nakamoto’s estimated holdings—described in the source reporting as worth roughly $63 billion at the time of writing. Smith argues that while that narrative dominates headlines, the first quantum-enabled targets could be elsewhere.

According to Smith, the earliest high-value targets might include military systems and state secrets. In the crypto ecosystem specifically, he points to the “single most valuable key,” suggesting it could be Tether’s minting key. In his framing, a quantum attacker could mint tokens from an administrative wallet and sell them before the issuer can react.

He also notes that USDT is deployed across multiple networks, and that some of those networks are already working on post-quantum migration. That detail underscores an important practical point: even where a stablecoin is widely used, the risk is not only about user wallets. Administrative or minting keys—or other privileged cryptographic roles—could be where quantum leverage becomes most economically damaging.

Another idea comes from Blockchain Capital security researcher Sean Cheetham. He argues an attacker would more likely pursue hot wallets at exchanges—particularly those “that aren’t going to ring alarm bells”—rather than trying to take famously held coins. Cheetham’s comment suggests attackers may optimize for timing and operational friction: quantum capability might not eliminate the value of choosing targets, it may just change how compromise is achieved.

Advertisement

Smith adds a further wrinkle: attackers could disguise quantum thefts by using plausible, deniable explanations. “There’s an alternative scenario where they… have these plausible, deniable [explanations]: ‘Oh, somebody just lost their keys somehow,’” he said. That increases the chance that quantum-related incidents could be misclassified as ordinary loss or conventional compromise.

Q-day timing remains uncertain as AI reshapes assumptions

Part of what makes Q-day hard to plan around is that forecasts have been moving as quantum progress and related algorithmic improvements develop. In March, Cointelegraph previously reported that Google accelerated its post-quantum migration timeline to 2029, citing an AI-assisted breakthrough suggesting elliptic curve cryptography could be cracked with fewer physical qubits than earlier estimates.

In the current reporting, NGRAVE CEO Roy Blackstone is cited for criticizing earlier quantum threat models that, in his view, did not adequately account for the parallel development of AI. The excerpt attributed to him argues that many threat models assumed ample time before public-key cryptography could be broken, but failed to reflect how quickly AI could evolve alongside quantum research.

Despite this urgency, there is still no single consensus on when quantum computers will be capable of breaking modern cryptography. Smith, whose company is building a blockchain network intended to be quantum-resistant from launch, says there is a “50-50” chance Q-day could arrive by 2028, arguing that continued AI-assisted improvements in quantum algorithms and ongoing hardware research make forecasts less reliable.

Advertisement

Cheetham’s view, as presented in the source, is that the early 2030s are “definitely almost a certainty,” while earlier dates are “more of a trailing probability.” Michael Coates, the Solana Foundation’s chief information security officer, declined to estimate during an earlier interview, telling Cointelegraph that “there’s no way to know.” He also pointed to a long-standing industry pattern: “it is always five years away,” a perspective he says has persisted for a decade or more.

Even with widely varying predictions, the recurring theme across these experts is that uncertainty should not become a reason to delay. Blackstone in the source emphasizes that blockchains have begun migrating to post-quantum signatures because “the damage would be catastrophic if they didn’t.”

What post-quantum migration changes for crypto security

The practical implication of these warnings is straightforward: migrating cryptography is the only way to reduce exposure as quantum timelines shift. While Q-day may be difficult to pinpoint, the risk model changes in a way that makes “wait and see” a poor strategy—especially because early quantum-enabled attacks could be indistinguishable from other security failures.

Post-quantum signature migration, as referenced in the reporting, is therefore not just about long-term research alignment. It changes what defenders can expect in real incidents. If a chain adopts post-quantum signatures, it narrows the window during which attackers might exploit public-key weaknesses through quantum computation. That also reduces the chance that a theft will be misattributed to a conventional breach.

Advertisement

It may also influence how exchanges and institutional custody providers prioritize key management and operational security. If an attacker can derive private keys without “breaching” systems in the usual way, then the strongest defense becomes cryptographic resilience rather than solely perimeter and device hardening.

The open question readers should watch next is how quickly major ecosystems complete post-quantum signature transitions, and whether their migration schedules account for the increasingly AI-influenced pace of quantum-related research. If the earliest quantum compromises can look ordinary, the timing of migration—and how consistently it’s implemented across networks and administrative key roles—may matter as much as any single “Q-day” date.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Advertisement

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

Australia Orders Cryptolink Bitcoin ATMs Offline After Reporting Lapses

Published

on

Crypto Breaking News

Australia’s financial crime regulator AUSTRAC has suspended the operation of Cryptolink’s Bitcoin ATMs for three months, citing ongoing concerns about the company’s compliance with anti-money laundering obligations. The decision pauses Cryptolink’s ability to run as a registered Virtual Asset Service Provider (VASP), effectively taking its crypto ATMs offline during the suspension period.

With Australia hosting the highest number of crypto ATMs in the Asia-Pacific region, the move underscores the regulator’s continued focus on reducing illicit activity linked to automated cash-to-crypto access—especially as authorities have escalated scrutiny of the sector since late 2024.

Key takeaways

  • AUSTRAC suspended Cryptolink’s VASP registration for three months, meaning its Bitcoin ATMs cannot operate during that timeframe.
  • The regulator cited failures to meet core reporting expectations, including threshold transaction reports, and noted the company did not respond to AUSTRAC requests.
  • AUSTRAC said it has “ongoing concerns” about Cryptolink’s ability to manage high-risk transactions through its ATMs.
  • The action follows prior enforcement steps tied to alleged late reporting and weaknesses in Cryptolink’s risk assessments.
  • Cryptolink operates 96 ATMs across major Australian cities, offering cash-to-Bitcoin exchanges.

AUSTRAC suspends Cryptolink’s VASP registration

AUSTRAC CEO Brendan Thomas said the suspension begins Sunday and will last three months. According to AUSTRAC, Cryptolink’s registration as a Virtual Asset Service Provider has been halted, which directly prevents its cryptocurrency ATMs from operating while the order is in effect.

In a statement, Thomas linked the decision to what AUSTRAC described as ongoing concerns regarding Cryptolink’s capacity to handle high-risk activity associated with digital asset transactions. The regulator emphasized that its scrutiny centers on digital currency as a potential money laundering risk, particularly in contexts where cash can be converted into crypto through automated systems.

What AUSTRAC says went wrong

AUSTRAC said Cryptolink failed to meet basic compliance and reporting requirements. The regulator highlighted shortcomings in threshold transaction reporting, a category of submissions that helps authorities identify larger or otherwise significant transactions that may warrant additional attention under anti-money laundering frameworks.

Advertisement

AUSTRAC also stated that Cryptolink did not respond to a request for information from the agency. While the details of the request are not included in the available coverage, the combination of reporting failures and non-response was positioned as a core reason behind the suspension.

“As part of our continued focus on digital currency as a money laundering risk, AUSTRAC has ongoing concerns about the company’s ability to manage high-risk transactions through its CATMs,” Thomas said.

Enforcement background: October 2025 undertaking and a fine

The suspension does not appear as an isolated action. AUSTRAC noted that the move follows an enforceable undertaking Cryptolink entered into in October 2025, after a Cryptocurrency Taskforce identified alleged breaches. AUSTRAC cited alleged late transaction reporting and shortcomings in Cryptolink’s risk assessments as part of that earlier compliance outcome.

AUSTRAC also referenced a separate infringement notice issued to Cryptolink, which AUSTRAC said amounted to $56,340. Cryptolink paid the notice. Together, these steps indicate a regulatory pattern: initial enforcement and corrective expectations in 2025, followed by a further escalation once AUSTRAC concluded its concerns were not resolved.

Advertisement

Earlier AUSTRAC reporting about Cryptolink’s issues has also focused on late reporting, reflecting the regulator’s interest in whether transaction monitoring and reporting systems are robust enough to detect and flag suspicious activity in time.

Cryptolink’s ATM footprint and the compliance ripple effect

Cryptolink operates 96 ATMs in Australia. Its machines are concentrated in major cities, including Sydney, Melbourne, and Brisbane, enabling users to exchange cash for Bitcoin.

For everyday customers, the immediate impact is straightforward: with the suspension in place, Cryptolink’s ATMs should not be able to operate during the three-month window. For the broader market, the development highlights how compliance enforcement can translate into practical restrictions on on-the-ground access to crypto services—turning regulatory findings into operational downtime.

For investors and industry participants, the case is also a reminder that registration status can change quickly when regulators conclude that reporting systems, responses to information requests, or risk controls are inadequate. In a market where crypto ATMs have expanded across multiple jurisdictions, enforcement actions like this can affect how operators prioritize compliance tooling and internal controls, particularly around transaction monitoring and threshold reporting obligations.

Advertisement

Cointelegraph reached out to Cryptolink for comment; no additional response was included in the provided material.

As the suspension period progresses, the key question for readers will be whether Cryptolink can address the specific reporting and risk management concerns AUSTRAC raised—and what AUSTRAC will require to restore the ability for its machines to run. Operators across the sector are likely watching closely, because the regulator’s rationale suggests that both technical reporting performance and responsiveness to regulatory requests will remain central to any future decision on registration status.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Advertisement

Source link

Continue Reading

Crypto World

Robinhood (HOOD) brings crypto trading to UK in AI-powered all-in-one app

Published

on

Robinhood (HOOD) brings crypto trading to UK in AI-powered all-in-one app

Robinhood (HOOD) is introducing zero-fee crypto trading in the U.K. alongside stocks and shares ISAs, equities, options and futures, the company said on Monday.

The all-in-one Robinhood app will bring U.K. customers access to over 50 cryptos including Bitcoin , Ethereum , XRP (XRP), Hyperliquid (HYPE), accessed via Bitstamp, the exchange Robinhood acquired in 2025.

The trading firm is also introducing “Robinhood Cortex Digests for Crypto,” a generative AI-powered widget that analyses breaking news, market data, technical indicators and Robinhood’s proprietary insights. The AI service explains in plain English the key factors driving price movements in individual crypto assets, Robinhood said.

“Our new product provides a transparent, low-cost alternative to many incumbent U.K. platforms, which often rely on opaque pricing structures and apply wide spreads that can erode customers’ returns,” Robinhood said.

Advertisement

“It will begin rolling out to eligible U.K. customers this week.”

The product also expands Robinhood’s growing crypto ecosystem for UK customers. As such, UK developers can build on the highly popular Robinhood Chain, a layer 2 blockchain built on the Arbitrum platform.

Source link

Advertisement
Continue Reading

Crypto World

World Liberty’s $100M WLFI buyer linked to UK money laundering probe

Published

on

World Liberty’s $100M WLFI buyer linked to UK money laundering probe

Guren “Bobby” Zhou, the businessman identified as the person behind Aqua 1’s $100 million purchase of World Liberty Financial tokens, has remained linked to an active British money laundering investigation after his 2021 arrest, despite not being charged.

Summary

  • Zhou was arrested in Britain in 2021 on suspicion of money laundering but has not been charged.
  • Aqua 1 bought $100 million of World Liberty Financial’s WLFI tokens in 2025.
  • The source of the $100 million used for the WLFI purchase remains unclear.
  • Up to $75 million from the Aqua 1 purchase went to a Trump controlled entity.
  • World Liberty has faced congressional scrutiny over separate UAE linked investments.

The New York Times reported Sunday that British authorities arrested Zhou in 2021 on suspicion of money laundering, while a court record filed last November accused him of participating with five other people in a laundering operation dating to 2019.

Two of Zhou’s longtime employees were charged in the case in September 2025, according to the report. One defendant has since pleaded guilty, while the trial involving the charged defendants is scheduled for 2028.

Advertisement

Zhou himself has not been charged with a crime.

The case has drawn attention because Zhou was identified as the businessman behind Aqua 1, the UAE-based investment vehicle that bought $100 million worth of WLFI governance tokens from World Liberty Financial. Reuters previously identified Zhou as the person behind the fund, while the purchase was publicly announced in June 2025.

Aqua 1’s $100 million World Liberty investment remains unexplained

A review of court records, confidential documents and interviews with Zhou’s former associates led the Times to examine how the businessman went from a series of troubled ventures in Britain to overseeing one of the largest publicly known investments in World Liberty.

The newspaper said it was unable to determine where the $100 million used for the WLFI purchase came from.

Advertisement

Blockchain activity examined as part of the report also connected Zhou’s earlier crypto business to the World Liberty transactions. According to the Times, blockchain analytics firm Arkham Intelligence determined that a wallet controlled by Web3Port bought $20 million worth of WLFI in January 2025.

A second wallet believed to be controlled by Aqua 1 purchased another $80 million in June, bringing the combined purchases to $100 million.

Before Aqua 1 emerged publicly, Zhou had led Web3Port, a crypto venture fund that announced a separate $10 million investment in World Liberty shortly after President Donald Trump’s inauguration in January 2025.

Corporate records reviewed by the Times showed that a Web3Port entity registered in the British Virgin Islands was later renamed Aqua 1 GP Limited. Aqua 1 announced its $100 million WLFI purchase about two weeks after the name change.

Advertisement

Aqua 1 had previously denied having a connection to Web3Port after earlier reporting linked the operations. The fund did not specify which parts of that reporting it disputed.

Zhou’s previous businesses faced financial problems

Before relocating from London to Abu Dhabi in 2024, Zhou operated businesses that later faced financial or credibility problems, according to the Times.

One was a British flooring retailer that entered restructuring without repaying roughly $5 million owed to a company controlled by Zhou’s father.

Advertisement

Zhou later launched Caduceus, a crypto project that raised about $7.6 million in funding. Its token had become effectively worthless by 2024, according to the newspaper.

Caduceus had announced backing from China Merchants Securities UK and the Bin Zayed Group, an organization founded by a member of Abu Dhabi’s royal family. Both organizations told the Times that claims about their involvement were “unauthorized and materially false.”

After moving to Abu Dhabi, Zhou became associated with Web3Port and subsequently Aqua 1, putting him behind investments that made the entities major buyers of World Liberty tokens.

The timing also placed Aqua 1 among several UAE-linked investments involving World Liberty that have drawn scrutiny from U.S. lawmakers.

Advertisement

World Liberty token sale sent millions to Trump-controlled entity

Under World Liberty’s revenue-sharing structure, as much as $75 million from Aqua 1’s $100 million token purchase went to a company controlled by Trump and his sons, according to the Times.

Previous reporting showed that 75% of proceeds from WLFI token sales flow to DT Marks DEFI LLC, an entity controlled by Trump.

Trump’s latest financial disclosure listed more than $65.6 million from the sale of equity in WLF Holdco and $236.25 million in distributed World Liberty token-sale proceeds.

The Aqua 1 transaction also benefited the family of World Liberty co-founder Zach Witkoff, according to the Times. His father, Steve Witkoff, serves as a special envoy in the Trump administration.

Advertisement

World Liberty spokesperson David Wachsman told the newspaper that the company had complied with applicable laws and regulations and maintained a compliance program that “meets or exceeds industry standards.”

Wachsman declined to say whether World Liberty knew where Zhou obtained the money used for the investment. He also disputed the newspaper’s portrayal of Zhou but did not identify specific factual inaccuracies in its reporting.

World Liberty investments have faced congressional scrutiny

Questions surrounding Aqua 1 come as U.S. lawmakers have already examined separate UAE-linked investments in World Liberty and whether foreign financial interests could create conflicts involving the Trump administration.

In June, five Democratic senators asked Republican committee leaders to hold hearings into a reported $500 million investment in World Liberty by Aryam Investment 1, an Abu Dhabi-based company backed by UAE national security adviser Sheikh Tahnoon bin Zayed Al Nahyan.

Advertisement

Citing Wall Street Journal reporting, the senators said Aryam acquired a 49% stake in World Liberty through an agreement signed in January 2025.

Their letter asked Congress to examine events that followed the transaction, including the Trump administration’s May 2025 approval of major arms sales and access to advanced artificial intelligence chips for the UAE. The lawmakers said U.S. national security officials had previously raised concerns that China could gain access to the technology.

Senators Elizabeth Warren and Andy Kim had separately asked Treasury Secretary Scott Bessent in February to determine whether the reported UAE investment required review by the Committee on Foreign Investment in the United States.

World Liberty has also faced regulatory questions over its plans to expand its financial operations. During a Senate Banking Committee hearing, Warren questioned Comptroller of the Currency Jonathan Gould about a reported application by World Liberty for a federal bank charter and whether the company had disclosed the foreign investment to regulators.

Advertisement

Gould declined to discuss a pending application and said the Office of the Comptroller of the Currency would follow its established procedures.

Trump has denied involvement in World Liberty’s daily operations. Speaking to reporters in February, he said he did not know about the reported UAE investment and said his sons were responsible for managing the business.

The White House has separately rejected conflict-of-interest allegations, saying Trump’s assets are held in a trust administered by his children and that administration decisions are made independently of his family’s business interests.

Advertisement

Source link

Continue Reading

Crypto World

Bybit is suing North Korea, and it might actually work

Published

on

Bybit is suing North Korea, and it might actually work

The exchange filed a civil lawsuit in a US federal court against North Korea, its intelligence agency, and the Lazarus Group over the $1.5 billion hack of February 2025. A judge has already frozen stolen assets. The case tests whether civil law can do what criminal enforcement has not.

Summary

  • Bybit filed a civil lawsuit on August 7, 2026, in the US District Court for the District of Columbia, naming North Korea, its Reconnaissance General Bureau intelligence agency, and the Lazarus Group as defendants over the $1.5 billion crypto theft of February 21, 2025, which remains the largest recorded cryptocurrency hack.
  • A US federal judge issued a preliminary injunction freezing certain stolen assets held by unidentified individuals and entities listed as John Doe defendants, preventing them from transferring, selling, or otherwise disposing of the identified assets while the litigation continues.
  • The FBI attributed the attack to North Korean actors operating under the name TraderTraitor shortly after the breach, and Bybit CEO Ben Zhou said the exchange had worked with investigators, regulators, other trading platforms, and law enforcement agencies since the attack.
  • The traceability of stolen funds declined over time: 88.87 percent remained traceable in March 2025, but by April 2025, 27.6 percent could no longer be tracked after the attackers converted assets into Bitcoin and dispersed them across thousands of wallets using cross chain protocols and crypto mixers.
  • North Korean groups stole an estimated $2.02 billion in cryptocurrency during 2025 alone, with cumulative theft reaching approximately $6.75 billion, and Lazarus linked attacks allegedly drained another $577 million from Drift Protocol and KelpDAO in April 2026.

On August 7, 2026, Bybit announced it had filed a civil lawsuit in the US District Court for the District of Columbia against the Democratic People’s Republic of Korea, its Reconnaissance General Bureau intelligence agency, and the Lazarus Group. The complaint concerns the February 21, 2025, breach that drained more than 400,000 Ether and staked Ether from the Dubai based exchange, an incident valued at approximately $1.5 billion at the time and still the largest recorded cryptocurrency theft.

The filing is unusual in almost every dimension. A private company is suing a sovereign nation in a US court. The defendants include a state intelligence agency and a hacking group that operates under its direction. The stolen assets have been laundered across thousands of wallets, converted between blockchains, and run through mixing services designed to break the transaction trail. And yet a federal judge granted a preliminary injunction, meaning a court has already determined that there is enough evidence and legal basis to freeze identifiable stolen assets while the case proceeds.

Advertisement

The question is not whether the lawsuit is symbolically important. It clearly is. The question is whether it can produce a practical outcome: the recovery of stolen funds, the creation of legal precedent for future cases, or both. The case arrives at a moment when the crypto industry is searching for institutional tools to complement its technical defenses. Blockchain tracing, exchange cooperation, and bug bounties have been the primary recovery mechanisms after major hacks. A civil lawsuit backed by a federal court order introduces a legal instrument that has not been widely tested in the crypto context but has deep precedent in traditional asset recovery litigation.

What the lawsuit actually claims

The complaint names three defendants. The Democratic People’s Republic of Korea is named as a sovereign state that directed the theft through its intelligence apparatus. The Reconnaissance General Bureau, North Korea’s primary foreign intelligence organization, is named as the agency that oversaw the operation. The Lazarus Group is named as the threat actor that carried out the technical execution.

The case is filed under theories of civil liability that do not require the defendants to appear in court. Bybit is pursuing the claim through the legal mechanisms available against sovereign states and their agents when those states are accused of sponsoring acts that cause financial harm to private parties. The Foreign Sovereign Immunities Act typically shields foreign governments from lawsuits in US courts, but exceptions exist for state sponsored terrorism and certain commercial activities.

Alongside the complaint, Bybit secured a preliminary injunction targeting John Doe defendants, unidentified individuals and entities that hold assets traced to the theft. The injunction bars them from transferring, selling, or otherwise disposing of the identified assets. A preliminary injunction is not a final ruling. It preserves property during litigation. But securing one requires demonstrating to a judge that the plaintiff is likely to succeed on the merits and that the assets would be at risk of dissipation without the order.

Advertisement

Bybit CEO Ben Zhou framed the filing in terms that emphasized accountability over financial recovery. “Our focus has never changed: protect our users first, recover what we can, and make sure the people behind these attacks are held accountable,” Zhou said in a statement.

How the February 2025 hack unfolded

The breach occurred on February 21, 2025, when attackers compromised Bybit’s security infrastructure and drained more than 400,000 ETH and stETH from the exchange. The assets were valued at approximately $1.5 billion at the time, making it the single largest cryptocurrency theft ever recorded.

The FBI attributed the attack to North Korean actors within days. The bureau identified the perpetrators under the operational name TraderTraitor and urged exchanges, validators, and blockchain firms to block transactions connected to addresses identified in the laundering operation. The speed of the attribution was notable. US intelligence agencies had been tracking Lazarus Group operations for years, and the on chain signatures of the attack matched patterns from previous North Korean campaigns.

The attackers moved quickly to launder the stolen funds. Within the first week, a significant portion of the ETH was converted to Bitcoin through cross chain bridges. The Bitcoin was then dispersed across thousands of wallets in a pattern designed to overwhelm tracing tools. By March 2025, Bybit’s CEO reported that 88.87 percent of the stolen funds remained traceable, while 7.59 percent had gone dark through crypto mixers and 3.54 percent had been frozen.

Advertisement

The legal architecture of the complaint reflects a calculated strategy for navigating the unusual challenge of suing a sovereign nation and its intelligence apparatus. By filing in the District of Columbia, Bybit places the case in a jurisdiction where federal courts routinely handle matters involving foreign states and international sanctions. The FSIA exception for state sponsored terrorism is well established in this courthouse, with decades of precedent from cases against Iran, Syria, and Libya providing a roadmap for how plaintiffs can pursue claims against sovereign defendants who refuse to appear. The preliminary injunction freezing stolen assets demonstrates that the court is willing to exercise jurisdiction and issue enforceable orders even before the defendants respond, which in a case against North Korea may never happen.

The traceable share declined over the following months. By April 2025, Zhou disclosed that 27.6 percent of the stolen funds could no longer be tracked. The attackers used a combination of cross chain protocols, mixing services, and decentralized exchanges to obscure the trail. Each hop between chains and each pass through a mixer made the remaining funds harder to follow.

Bybit covered the immediate shortfall through ETH purchases, loans, and deposits from industry counterparties. The exchange continued processing customer withdrawals throughout the crisis, avoiding the liquidity collapse that has followed other major exchange hacks. The operational response was widely credited as one of the more effective post hack recoveries in the industry’s history.

The scale of the laundering operation reveals the sophistication of the North Korean apparatus. The attackers did not simply send the stolen ETH to a single mixer and wait. They ran a multi-stage pipeline. First, the ETH was swapped for other tokens through decentralized exchanges to break the direct link to the Bybit wallets. Then the tokens were bridged to other chains, primarily Bitcoin, through cross chain protocols. The Bitcoin was then split across thousands of newly created wallets in a pattern called “peel chain” laundering, where each wallet sends a small portion to a destination and forwards the remainder to the next wallet in the chain. Each stage added a layer of obfuscation, and the entire process was automated using scripts that executed faster than human analysts could follow in real time.

Advertisement

https://x.com/cryptodotnews/status/2086018579007217931

Why a civil lawsuit and why now

The timing of the filing raises an obvious question: why wait 18 months? The answer involves both legal strategy and the evolution of the available evidence.

Criminal investigations into the hack are ongoing. US law enforcement agencies, including the FBI, are pursuing their own cases against the North Korean actors. Bybit’s civil lawsuit is explicitly separate from those criminal proceedings. The exchange is not dependent on prosecutors’ timelines or priorities.

The laundering infrastructure that the Lazarus Group employed after the Bybit breach illustrates how state backed hackers have professionalized their operations to exploit the structural gaps in cryptocurrency compliance. Within hours of the theft, the stolen Ether moved through a cascade of intermediary wallets designed to break the chain of provenance. The funds then flowed through decentralized exchanges, cross chain bridges, and mixing services that do not perform know your customer checks. By the time law enforcement agencies began coordinating their response, a significant portion of the stolen assets had already been converted into bitcoin and routed through additional obfuscation layers. This rapid dispersal is a signature of North Korean crypto operations, refined through years of practice across multiple high profile thefts.

Advertisement

A civil lawsuit offers several advantages that criminal prosecution does not. First, the burden of proof is lower. Criminal cases require proof beyond a reasonable doubt. Civil cases require a preponderance of the evidence. Second, a civil plaintiff controls its own case. Bybit can pursue recovery on its own schedule rather than waiting for a criminal prosecution that may take years to culminate in a judgment.

Third, and most practically, a civil lawsuit with a preliminary injunction gives Bybit a legal instrument that exchanges and custodians must respect. When Bybit identifies stolen funds on a platform, it can now point to a court order rather than relying on voluntary cooperation. Exchanges that refuse to freeze assets covered by a federal court order face legal exposure of their own.

The 18 month gap also allowed the blockchain tracing to mature. The initial weeks after a major hack are chaotic. Funds move rapidly across chains and through mixers. Over time, some of that movement stops. Funds sit in wallets. They end up on exchanges where withdrawal requires interaction with regulated entities. The preliminary injunction targets those resting points, the wallets and accounts where traceable stolen funds currently sit.

Advertisement

Can you actually sue North Korea and collect

This is the question that makes the case unusual. Suing a sovereign nation in a foreign court is not standard practice, and collecting a judgment against a country that does not participate in the international financial system presents obvious challenges.

The legal framework for suing foreign governments in US courts is governed by the Foreign Sovereign Immunities Act. Under normal circumstances, foreign states are immune from suit in US courts. But exceptions exist. The terrorism exception, added after the 1996 amendments, allows claims against states designated as sponsors of terrorism. North Korea has been on the State Department’s state sponsor of terrorism list since 2017.

Whether the cryptocurrency theft qualifies under the terrorism exception is a legal question that the court will need to address. Previous cases under this exception have involved acts of physical violence, hostage taking, and material support for terrorist organizations. A cryptocurrency hack committed for financial gain rather than political violence may test the boundaries of the statute.

Even if Bybit obtains a default judgment (North Korea is unlikely to send lawyers to defend the case), collecting on that judgment against a state that operates outside the conventional financial system is a separate challenge. The practical value of the lawsuit lies not in extracting payment from Pyongyang but in the ancillary effects: the preliminary injunction that freezes assets, the legal precedent that future victims can cite, and the signal to exchanges and custodians that frozen assets have a court order behind them.

Advertisement

The John Doe component of the lawsuit is potentially more actionable. If the identities of individuals or entities holding the stolen funds are discovered during the litigation, they can be added to the case and subjected to enforcement actions. Unlike North Korea itself, individuals who hold stolen crypto and fail to comply with a federal court order face consequences that can be enforced.

https://x.com/cryptodotnews/status/2086347896077619470

The broader pattern of North Korean crypto theft

The Bybit hack was not an isolated incident. It was the largest single event in a sustained campaign of cryptocurrency theft that US intelligence agencies attribute to the North Korean state.

North Korean groups stole an estimated $2.02 billion in cryptocurrency during 2025, according to Chainalysis data. The Bybit attack accounted for most of that total. Cumulatively, North Korea linked groups have stolen approximately $6.75 billion in digital assets across multiple years of operations.

Advertisement

The threat continued into 2026. In April, Lazarus linked attacks allegedly drained $577 million from Drift Protocol and KelpDAO in two separate incidents. The attacks used different technical methods but shared the same operational playbook: identify a vulnerability in a DeFi protocol or exchange, exploit it rapidly, and move the stolen funds through a pre planned laundering chain that crosses multiple blockchains within hours.

The scale of the theft has geopolitical implications. US and South Korean intelligence agencies have assessed that North Korea channels crypto theft proceeds into its weapons programs, including nuclear and missile development. This assessment is one reason the FBI attributed the Bybit attack so quickly and why US authorities have been unusually active in coordinating with exchanges to freeze funds. The scale of the February 2025 breach, exceeding all prior incidents by a factor of three, forced the industry to confront the inadequacy of its existing response mechanisms and consider whether civil litigation might fill the enforcement gap that criminal prosecution has left open.

For the crypto industry, the North Korean threat has become a baseline security assumption rather than an exceptional risk. Exchanges, DeFi protocols, and bridge operators now design their security models with state sponsored attackers as a primary threat scenario. The Bybit lawsuit adds a legal dimension to what has primarily been a technical and operational response.

The pattern of North Korean attacks also reveals a preference for targeting infrastructure points where large amounts of value are concentrated in a single signing operation. The Bybit attack compromised the process by which the exchange moved funds between cold and warm wallets. The Ronin bridge attack targeted the validator set that controlled cross chain transfers. In both cases, the attackers identified the moment when a single compromised action could move the maximum amount of value. This targeting pattern has forced exchanges to rethink how they structure high value transactions, adding multi party computation, hardware security modules, and time delayed execution to what were previously routine operations.

Advertisement

https://x.com/cryptodotnews/status/2045015901854921186

What the case means for future hack recoveries

The Bybit lawsuit could create a template for how exchanges and other victims pursue stolen funds through civil courts. Previous major hacks, including the Ronin bridge theft in 2022 and the Wormhole exploit in the same year, relied primarily on law enforcement cooperation, voluntary freezes by industry participants, and bounty programs.

A civil lawsuit with a preliminary injunction adds a layer that voluntary cooperation cannot provide: compulsion. When a court orders assets frozen, the custodian holding them has a legal obligation to comply. The order converts a request into a requirement, and non compliance carries legal consequences.

The dual track approach, civil and criminal running simultaneously, also matters. Criminal cases move on prosecutors’ timelines and serve public enforcement objectives. Civil cases move on the plaintiff’s timeline and serve the plaintiff’s recovery objectives. When both tracks operate in parallel, the stolen funds face pressure from multiple legal directions.

Advertisement

For smaller victims who lack Bybit’s resources, the precedent matters more than the specific case. If the lawsuit succeeds in freezing and eventually recovering stolen assets, it creates a roadmap that other victims can follow. If it produces published court opinions on the jurisdictional and immunity questions, those opinions become tools that future plaintiffs can use to streamline their own cases.

The case also tests the crypto industry’s willingness to cooperate with civil court orders. Exchanges that receive freeze requests backed by a federal court injunction face a different calculus than exchanges that receive informal requests from a hack victim. The legal formalization of the recovery process could accelerate compliance across the exchange ecosystem.

There is also a deterrence argument, though its force against a state actor is debatable. Most criminal hackers weigh the expected profit against the expected penalty. For a state intelligence agency that channels theft proceeds into weapons programs, the calculus is different. But the lawsuit creates costs at the laundering stage. Every exchange that freezes assets in response to the court order reduces the amount that reaches its intended destination. If the civil lawsuit makes laundering 5 or 10 percent harder, that translates to hundreds of millions of dollars in stolen value that cannot be converted to cash. Over multiple operations, incremental friction at the laundering stage compounds into a meaningful reduction in the program’s effectiveness.

What to watch

Compliance with the preliminary injunction. The order is only as effective as the willingness of custodians and exchanges to enforce it. Watch for reports of exchanges freezing funds in response to the order, or for disputes where custodians challenge the scope of the injunction.

Advertisement

Additional defendants added to the case. The John Doe structure allows Bybit to add identified individuals and entities as discovery progresses. If blockchain tracing leads to specific custodians, exchanges, or OTC desks that processed stolen funds, they could become parties to the lawsuit.

North Korea’s response or non response. Sovereign defendants in US courts typically either invoke immunity and challenge jurisdiction or simply ignore the proceedings. North Korea’s approach will determine whether the case proceeds by default judgment or through contested litigation on the jurisdictional questions.

Recovery rate compared to criminal track. Bybit has been working with law enforcement since February 2025. The civil lawsuit now runs in parallel. Comparing the amounts recovered through each track will indicate whether civil litigation adds meaningful recovery capacity beyond what criminal enforcement achieves alone.

Follow on lawsuits from other hack victims. If the Bybit case survives jurisdictional challenges and produces asset recovery, other victims of state sponsored hacks may file similar civil complaints. Watch for cases from victims of the Drift Protocol and KelpDAO attacks, which are also attributed to Lazarus Group.

Advertisement

International coordination on asset freezing. The US court order applies to entities within US jurisdiction, but stolen crypto moves globally. Watch for parallel legal actions in jurisdictions like Singapore, the UK, and the EU, where exchanges and custodians may hold portions of the laundered funds. A coordinated multi-jurisdictional freeze would be significantly more effective than a single country order.

North Korean adaptation to the legal pressure. State sponsored hacking groups adapt their laundering techniques in response to enforcement actions. If the civil lawsuit makes conventional exchange-based laundering more difficult, the attackers may shift to peer-to-peer trading, decentralized exchanges without KYC, or privacy chains. The speed and nature of this adaptation will indicate how much friction the legal approach creates.

Frequently asked questions

u003cstrongu003eWhat is Bybit suing North Korea for?u003c/strongu003e

u003cpu003eBybit filed a civil lawsuit alleging that North Korea, through its Reconnaissance General Bureau intelligence agency and the Lazarus Group, stole approximately $1.5 billion in Ether and staked Ether from the exchange on February 21, 2025. The case was filed in the US District Court for the District of Columbia.u003c/pu003e

Advertisement

u003cstrongu003eHas a court already taken action?u003c/strongu003e

u003cpu003eYes. A US federal judge issued a preliminary injunction freezing certain stolen assets held by unidentified individuals and entities listed as John Doe defendants. The order prevents them from transferring or selling the identified assets while the case proceeds.u003c/pu003e

u003cstrongu003eHow much of the stolen funds has been recovered?u003c/strongu003e

u003cpu003eBybit has not disclosed a specific recovery figure. As of April 2025, 27.6 percent of the stolen funds could no longer be tracked. The remaining traceable portion is subject to ongoing recovery efforts through blockchain tracing, industry cooperation, and now the civil lawsuit.u003c/pu003e

u003cstrongu003eCan a private company actually sue a foreign country?u003c/strongu003e

u003cpu003eUnder the Foreign Sovereign Immunities Act, foreign states are generally immune from suit in US courts. However, exceptions exist for states designated as sponsors of terrorism. North Korea has been on the State Department’s state sponsor of terrorism list since 2017. Whether the cryptocurrency theft qualifies under the terrorism exception is a legal question the court will address.u003c/pu003e

u003cstrongu003eIs this lawsuit separate from the FBI investigation?u003c/strongu003e

u003cpu003eYes. Bybit explicitly stated that the civil lawsuit is being pursued independently of ongoing criminal investigations by US law enforcement agencies. The two tracks operate in parallel, each with different procedural rules, burdens of proof, and objectives.u003c/pu003e

Advertisement

u003cstrongu003eWhy did Bybit wait 18 months to file?u003c/strongu003e

u003cpu003eThe timing allowed blockchain tracing to mature, identifying where stolen funds currently sit. It also allowed Bybit to build a factual record sufficient for a preliminary injunction. Filing too early would have risked a weaker case with fewer identifiable assets to freeze.u003c/pu003e

u003cstrongu003eWhat happens if North Korea ignores the lawsuit?u003c/strongu003e

u003cpu003eIf North Korea does not respond, Bybit can seek a default judgment, a court ruling in its favor based on the defendant’s failure to appear. Default judgments against sovereign states are enforceable against the state’s assets within US jurisdiction, though North Korea holds minimal assets subject to US courts.u003c/pu003e

u003cstrongu003eCould other hack victims file similar lawsuits?u003c/strongu003e

u003cpu003eYes. The Bybit case could create a template for civil recovery actions by other victims of state sponsored cryptocurrency theft. If the case produces favorable court opinions on jurisdiction and immunity, those opinions become precedent that future plaintiffs can cite. This is educational analysis, not investment advice.u003c/pu003eu003cpu003eu003cemu003eDisclaimer: This article is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency markets carry significant risk. Always conduct independent research before making investment decisions. Information is current as of August 8, 2026.u003c/emu003eu003c/pu003e

Source link

Advertisement
Continue Reading

Crypto World

The Korean Crypto Laundering Method Behind $6.4 Billion, and Why Police Struggle to Stop It

Published

on

Panic Hits Japan and South Korea Markets: Can Crypto Become the Big Winner?

A single cross-border laundering method has quietly become the backbone of South Korea’s crypto crime wave, accounting for $6.4 billion of the $7.1 billion in illegal crypto transactions recorded in the country since 2021. And despite knowing exactly how it works, police are struggling to stop it.

The technique is called Hwanchigi. It exploits cryptocurrency transfers to move illicit money offshore without touching South Korea’s regulated banking system, making it fast, borderless, and difficult to prosecute. A Crystal Intelligence report tied the method to the vast majority of illegal crypto flows in the country between 2021 and August 2025, and new police data suggests its use is accelerating sharply.

The Numbers Behind the Surge in Korea

National Police Agency figures show money laundering cases involving virtual assets hit 1,214 in the first half of 2026 alone, up from just eight cases in all of 2025. That 152-fold jump pushed money laundering to 79.4% of all crypto offenses detected in H1 2026, displacing investment fraud, which had accounted for 92% of crypto crime through last year.

South Korea’s crackdown on illegal crypto transactions has intensified in recent years, but the case data shows criminal networks are scaling faster than enforcement.

Advertisement

The preferred vehicle is Tether (USDT). Stablecoins now dominate illicit crypto flows globally, and South Korea’s criminals use them to convert drug trafficking proceeds, gambling revenue, and phishing profits into dollars before routing funds through overseas exchanges beyond domestic jurisdiction.

Detection Without Consequence

The enforcement gap is stark. Police made only 18 arrests for crypto money laundering in H1 2026, compared to 42 in 2023, despite detecting nearly 100 times more cases.

The pattern repeats across recent high-profile operations: in June 2026, Seoul Metro Police charged 23 individuals over a laundering network tied to a Cambodia-based phishing group and confiscated $431,000 in proceeds, but the alleged ringleader remains at large under an Interpol Red Notice.

Advertisement

In July 2026, investigators traced and froze $12 million in XRP and Tether after a fake Flare Network staking site drained $8.6 million from 71 investors, but arrests lagged the asset freezes.

The Korea Customs Service seized 7.2 trillion won ($4.92 billion) in illegal foreign exchange transactions in H1 2026, including export companies that accepted crypto to bypass repatriation rules. Over 90% of the 9.5 trillion won in crypto-linked crime referred for prosecution ran through unlicensed channels, not regulated banks.

South Korea can map the money. Following it to a courtroom is a different problem entirely.

The post The Korean Crypto Laundering Method Behind $6.4 Billion, and Why Police Struggle to Stop It appeared first on BeInCrypto.

Advertisement

Source link

Continue Reading

Crypto World

Coinsbuy Faces Reported $7.9 Million Crypto Hack Amid Rising 2026 Attacks

Published

on

ZachXBT Disowns Copycat Meme Coins, Donates $25,000 to Venezuela Relief

Coinsbuy reportedly suffered a $7.9 million crypto theft. Wallets linked to the crypto payments platform were drained across Ethereum (ETH) and Tron (TRX). 

Blockchain investigator Specter Analyst first highlighted the incident through Telegram.

Coinsbuy Pauses Transfers After Reported Hack

Specter Analyst said the attack occurred around 13:00 UTC. Coinsbuy temporarily paused deposits and withdrawals following the incident. The platform has since resumed services, according to the report. 

Follow us on X to get the latest news as it happens

Advertisement

The attacker began moving the stolen assets through exchanges and converting the funds into Monero (XMR). ChangeNOW also reportedly froze a six-figure amount linked to the stolen funds.

The analyst highlighted these theft addresses:

  • 0x4d1bEF2Fe998B3E3C4029EF9EA6A0534d95661d3
  • 0x66790b54B891e2ebdef58a15B969Ff6fb4374b17
  • TVpX9xCzrj6KHeNhhDJoqjzEqFMxdgubGR

The incident is the largest crypto hack reported in August so far. DeFiLlama’s tracker currently lists four crypto-related security incidents this month.

Crypto Hacks Rise as Losses Decline

The latest incident adds to a year that has seen a sharp rise in crypto security breaches. TRM Labs recorded 207 hacks in H1 2026, more than double the 83 incidents reported during the same period last year.

Advertisement

However, the increase in attacks has not translated into higher overall losses. Hackers stole about $972 million in H1 2026, compared with roughly $2.3 billion a year earlier. The 2025 figure was influenced by the $1.5 billion Bybit hack.

The Coinsbuy incident also follows more than $247 million in crypto losses recorded in June. That made June the second-costliest month of 2026 so far, behind April, when losses reached about $644.85 million.

Subscribe to our YouTube channel to watch leaders and journalists provide expert insights

The post Coinsbuy Faces Reported $7.9 Million Crypto Hack Amid Rising 2026 Attacks appeared first on BeInCrypto.

Advertisement

Source link

Continue Reading

Crypto World

Wintermute just got SEC approval to trade stocks, and crypto market makers are quietly becoming broker dealers

Published

on

Wintermute gains U.S. broker status, eyes tokenized stocks

The largest crypto liquidity provider registered with FINRA on August 6. The move signals something larger than one firm’s expansion: the infrastructure that runs crypto markets is migrating onto Wall Street rails.

Summary

  • Wintermute USA LLC registered as a broker dealer with the SEC and FINRA on August 6, 2026, establishing the firm as a regulated proprietary trading entity in U.S. markets with the ability to trade equities, equity options, and exchange traded products tied to digital assets.
  • The registration enables Wintermute to act as an authorized participant (AP) for crypto ETPs, meaning it can create and redeem ETF shares directly with issuers, a role that gives it structural access to the arbitrage mechanism that keeps ETF prices aligned with their underlying assets.
  • Wintermute facilitates over $10 billion in average daily trading volume across more than 60 centralized and decentralized exchanges globally, making it one of the largest liquidity providers in crypto and now one of the few firms that can provide liquidity across both crypto native venues and traditional stock exchanges from a single balance sheet.
  • The broker dealer registration follows Crypto.com’s 2024 acquisition of SEC registered broker dealer Watchdog Capital and Nasdaq’s March 2026 SEC approval for a tokenized share trading rule, forming a pattern where crypto native firms are systematically acquiring or building traditional market infrastructure rather than waiting for traditional firms to enter crypto.
  • The registration is restricted to proprietary trading, meaning Wintermute USA will trade only for its own account and will not offer brokerage services to retail or institutional clients, a limitation that reduces regulatory burden but also limits the firm’s revenue model to market making spreads and AP arbitrage.

On August 6, 2026, Wintermute announced that its affiliate Wintermute USA LLC had registered as a broker dealer with the Securities and Exchange Commission and joined the Financial Industry Regulatory Authority. The registration allows the firm to trade traditional equities and equity options, act as an authorized participant for exchange traded products including crypto ETPs, and self clear digital asset securities transactions. The filing is narrow in scope. The implications are not.

Wintermute is not the first crypto firm to obtain a broker dealer license. Crypto.com acquired Watchdog Capital in 2024. Coinbase has held a broker dealer registration through its institutional arm for years. But Wintermute’s registration is different in kind because Wintermute is not an exchange or a consumer platform. It is a market maker. Its business is providing liquidity, and its advantage is speed, capital efficiency, and infrastructure that operates across dozens of venues simultaneously. Bringing that infrastructure inside the regulatory perimeter of U.S. securities law is not an incremental compliance exercise. It is a positioning move for a market structure that does not fully exist yet but is being built in pieces.

Advertisement

What the registration actually allows

Wintermute USA LLC’s broker dealer registration covers three specific activities, each with distinct strategic significance.

First, the firm can trade traditional equities and equity options on U.S. national securities exchanges. This means Wintermute’s algorithmic trading infrastructure, built to provide liquidity on crypto exchanges, can now operate on the NYSE, Nasdaq, and options exchanges. The technology is different in implementation but similar in concept: market making is the business of quoting bid and ask prices, managing inventory, and profiting from the spread. Wintermute has been doing this on Binance, Coinbase, Uniswap, and over 60 other venues. Doing it on the NYSE is an extension of the same capability into a regulated venue with stricter rules but more stable counterparties.

Second, the firm can act as an authorized participant for exchange traded products. An AP is one of a limited number of entities that can create and redeem ETF shares directly with the fund issuer. When a Bitcoin ETF’s market price rises above its net asset value, APs create new shares by delivering bitcoin to the fund and selling the newly created shares on the exchange, pushing the price back down. When the market price falls below NAV, APs redeem shares for bitcoin and sell the bitcoin, pushing the ETF price back up. This arbitrage mechanism is what keeps ETFs trading near their fair value.

Being an AP for crypto ETPs is strategically valuable because it places Wintermute at the intersection of crypto spot markets, where it already operates, and the regulated ETF market, where institutional capital flows. The firm can now arbitrage between the two markets from a single balance sheet, capturing the spread that exists when ETF prices deviate from spot. The AP role also gives Wintermute visibility into real time ETF demand patterns, which provides information about institutional positioning that is not available through crypto exchange order books alone. This information asymmetry, while legal and standard among APs, is one of the competitive advantages that makes the registration valuable beyond the direct revenue it generates.

Advertisement

Third, the firm can self clear digital asset securities transactions. Self clearing means Wintermute does not need to route its trades through an external clearing firm, reducing costs and operational dependencies. For a proprietary trading firm that may eventually trade tokenized securities, self clearing is a prerequisite for efficient settlement.

The broader pattern: crypto firms buying Wall Street licenses

Wintermute’s registration is part of a pattern that has accelerated since 2024. Crypto native firms are systematically acquiring or building the regulatory infrastructure needed to operate in traditional markets, rather than waiting for traditional firms to build crypto capabilities.

Crypto.com acquired Watchdog Capital, an SEC registered broker dealer, in 2024. The acquisition gave Crypto.com the ability to offer securities trading to its users and to participate in the regulated securities market. In March 2026, the SEC approved a Nasdaq rule change that enables tokenized share trading on the exchange, creating a new venue where digital representations of traditional securities can trade alongside their conventional counterparts.

These moves reflect a strategic calculation. The firms that can provide liquidity across both crypto and traditional venues will have a structural advantage as the boundary between the two markets blurs. Tokenized equities, which represent ownership of traditional stocks on a blockchain, already trade on platforms like Kraken’s xStocks. As regulatory frameworks like the CLARITY Act define the rules for digital assets, the infrastructure for trading tokenized securities will need market makers who understand both the crypto settlement layer and the traditional securities regulatory framework.

Advertisement

Wintermute’s CEO, Evgeny Gaevoy, framed the registration in these terms: “Digital assets and traditional finance will continue to develop in parallel, intersect in new ways, and ultimately integrate more deeply. As the landscape evolves, the firms that succeed will be those that have technical and operational know how to operate in both.”

https://x.com/cryptodotnews/status/2085792086394343734

Why market makers matter more than exchanges

The public conversation about crypto’s integration with traditional finance has focused on exchanges: Coinbase’s IPO, Robinhood’s crypto trading, Kraken’s xStocks. But exchanges are marketplaces. They set the rules and collect the tolls. Market makers are the firms that actually provide the liquidity that makes trading possible.

On a crypto exchange, when you submit a buy order and it fills instantly, it fills because a market maker had a sell order sitting at that price. The market maker does not care about the direction of the trade. It makes money by buying at the bid price and selling at the ask price, capturing the spread between the two. The spread is narrow because multiple market makers compete for order flow.

Advertisement

Wintermute’s advantage in crypto is infrastructure. The firm’s systems can quote prices across 60 plus venues simultaneously, manage inventory across chains and exchanges, and adjust prices in milliseconds as market conditions change. This infrastructure is expensive to build and difficult to replicate, which is why the market making business is concentrated among a handful of firms: Wintermute, Jump Crypto (now Jump Trading), Cumberland DRW, and a few others.

Bringing this infrastructure to traditional equities is a competitive move against incumbent market makers like Citadel Securities, Virtu Financial, and Susquehanna. These firms dominate equities market making but have been slower to build crypto native capabilities. Wintermute is approaching from the other direction: it has the crypto infrastructure and is now adding the equities license.

The competitive dynamics are unclear. Traditional market makers have decades of experience with SEC regulations, exchange connectivity, and risk management frameworks that crypto firms lack. Wintermute has speed and cross venue capabilities that traditional firms are still building. The winner will likely be determined not by which side is better at its home game but by which side adapts faster to the integrated market that is emerging.

The cross venue advantage extends beyond simple price comparison. When Wintermute quotes a bid price on Coinbase and an ask price on Binance, it is effectively creating a private bridge between two liquidity pools that do not otherwise interact. This bridging function reduces fragmentation across the crypto market, which is structurally more fragmented than equities because it operates across hundreds of independent venues with no centralized national best bid and offer (NBBO) system. In traditional equities, the NBBO requires all exchanges to route orders to the venue displaying the best price. In crypto, no such requirement exists. Market makers like Wintermute serve as informal NBBO providers, arbitraging price differences across venues and in the process making prices more consistent for all traders. Extending this capability to equities gives Wintermute a perspective on market microstructure that spans both regulated and unregulated venues, an informational advantage that no purely traditional or purely crypto market maker currently possesses.

Advertisement

There is also a personnel dimension. Wintermute has been hiring compliance and operations staff with traditional finance backgrounds throughout 2025 and 2026. Building a broker dealer is not just a licensing exercise; it requires risk officers, compliance surveillance systems, trade reporting infrastructure, and relationships with clearing houses. The firm’s ability to recruit people who know these systems while retaining the engineers who built its crypto infrastructure will determine whether it can operate effectively across both worlds or becomes bogged down trying to manage two distinct operational cultures under one roof.

The capital requirements are also worth noting. Broker dealers must maintain minimum net capital under SEC Rule 15c3-1. For a proprietary trading firm, the requirement scales with the size and risk profile of its positions. Wintermute’s existing capital base, built from years of profitable crypto market making, gives it a head start. But operating in equities means deploying capital into markets where the competition is better capitalized, the margins are thinner, and the regulatory penalties for errors are steeper. The firm is entering a game where the incumbents have been playing for decades.

The personnel challenge is compounded by compensation dynamics. Traditional finance compliance officers and risk managers command high salaries, and they typically expect the stability and predictability of established financial institutions. Convincing these professionals to join a firm whose primary revenue comes from crypto market making requires both competitive pay and a credible narrative about the firm’s long term trajectory. Wintermute’s registration provides that narrative, but retaining traditional finance hires through the inevitable volatility of crypto revenue cycles will test the firm’s organizational culture in ways that a regulatory filing alone cannot address.

Advertisement

The AP arbitrage opportunity

The authorized participant role for crypto ETPs is arguably the most immediately valuable component of Wintermute’s registration. Bitcoin and Ethereum ETFs hold billions of dollars in assets, and the AP mechanism is the primary tool for keeping those ETFs trading at prices that reflect their underlying holdings.

When Bitcoin’s price moves sharply, the ETF price and the spot price can diverge temporarily. APs profit from closing this gap. If the ETF trades at a 0.5 percent premium to spot, an AP can buy bitcoin at spot, deliver it to the ETF issuer to create new shares, and sell those shares at the premium. The profit is the 0.5 percent spread minus transaction costs.

For Wintermute, this trade is especially attractive because the firm already holds bitcoin and ETH inventory across dozens of venues. It can source the underlying asset at the best available price across its venue network and deliver it to the ETF issuer at a lower effective cost than an AP that trades only on one or two exchanges. The cross venue sourcing advantage is the same edge that makes Wintermute effective in crypto market making, applied to a new product.

The creation and redemption process also introduces a timing dimension that favors firms with existing crypto market infrastructure. When an AP creates new ETF shares, it must deliver the underlying asset, whether bitcoin or ether, to the fund custodian within a specified settlement window. Sourcing that asset quickly and at a predictable price requires access to deep liquidity pools across multiple venues. A market maker that already maintains inventory on dozens of exchanges can fill this requirement faster and at a lower cost than an AP that must first purchase the asset on a single exchange and then transfer it to the custodian. The settlement timing advantage compounds during periods of high volatility, when ETF premiums and discounts are widest and the arbitrage opportunity is most profitable. During the March 2025 bitcoin correction, for example, Bitcoin ETF discounts briefly exceeded 1.5 percent, creating an arbitrage window that APs with fast crypto settlement infrastructure could exploit within minutes while others waited for next day delivery.

Advertisement

The volume opportunity is significant. Bitcoin ETF trading volumes have averaged billions of dollars per day since the January 2024 launch. Each trade represents a potential AP opportunity when the ETF price deviates from NAV. Wintermute’s registration gives it access to this revenue stream alongside established APs like Jane Street, Virtu, and Goldman Sachs.

https://x.com/cryptodotnews/status/2083825629414490177

The tokenized securities bet

The long term strategic logic behind Wintermute’s registration extends beyond current products to a market that is still being built: tokenized securities.

Tokenized securities are digital representations of traditional financial instruments, stocks, bonds, ETFs, issued on a blockchain. They trade using crypto settlement infrastructure (24/7, near instant settlement, programmable) but are subject to securities regulation (registration, disclosure, investor protection). The market is small today but growing. The SEC’s approval of Nasdaq’s tokenized share trading rule in March 2026 was a significant regulatory milestone.

Advertisement

For tokenized securities to achieve meaningful trading volume, they need market makers who can provide liquidity on both the tokenized venue and the traditional venue where the underlying security trades. An investor buying tokenized Apple stock needs to receive a price that is competitive with the price on Nasdaq. That price alignment requires a market maker that can trade on both venues and arbitrage any price differences.

Wintermute’s broker dealer registration positions it to be that market maker. The firm can trade traditional Apple stock on Nasdaq through its broker dealer and tokenized Apple stock on a blockchain based venue through its existing crypto infrastructure. The ability to operate on both rails simultaneously is the competitive moat.

This is a five year bet, not a quarter to quarter revenue play. Tokenized securities volumes are still a fraction of traditional market volumes. But the infrastructure investment required to be ready when the market scales is substantial, and Wintermute is making it now.

The tokenized securities thesis also has a settlement advantage that is easy to overlook. Traditional equities settle on a T+1 basis, meaning the buyer does not receive the shares and the seller does not receive cash until the next business day. Tokenized securities on a blockchain can settle in minutes or seconds. For a market maker, faster settlement means lower capital requirements. Every dollar tied up waiting for settlement is a dollar that cannot be deployed elsewhere. If tokenized securities achieve significant volume, the market maker that can settle both the tokenized and traditional versions simultaneously will have a capital efficiency advantage that compounds across thousands of daily trades.

Advertisement

https://x.com/cryptodotnews/status/2080820829823152211

What this does not resolve

The registration does not make Wintermute a retail broker. The firm trades exclusively for its own proprietary account. It cannot accept customer deposits, manage customer accounts, or provide investment advice. Users will not interact with Wintermute USA directly. They will interact with it indirectly through tighter spreads on the venues where it provides liquidity.

The registration also does not resolve the broader regulatory uncertainty facing digital asset securities. The CLARITY Act, if passed, would define which digital assets are securities and which are commodities. Until that framework exists, trading in digital asset securities carries compliance risk that even a broker dealer registration does not fully mitigate.

Finally, the registration does not eliminate the conflicts of interest inherent in market making. Market makers profit from the spread, which is a cost to traders. They have information advantages from seeing order flow across multiple venues. And their automated systems can react faster than any human trader. These dynamics exist in traditional equities and are well understood by regulators. How they apply to a market maker that operates across both crypto and traditional venues simultaneously is a newer question.

Advertisement

The cross venue information flow is particularly sensitive. A market maker that sees order flow on both Binance and the NYSE possesses information about demand in two markets that are increasingly correlated. If bitcoin’s price moves sharply on Binance, Wintermute’s systems could theoretically adjust equity quotes on Bitcoin ETFs before other market participants process the same information. This is the same type of latency arbitrage that high frequency trading firms have exploited in equities for years, but applied across a market boundary that regulators are only beginning to monitor. FINRA and the SEC will be watching how Wintermute manages information barriers between its crypto and equities desks.

What to watch

Wintermute’s equities and options trading volume. The firm’s performance in traditional markets will signal whether crypto native market makers can compete with incumbents. Initial volumes will be small, but the trajectory matters more than the starting point.

Additional crypto firms seeking broker dealer status. If other major crypto market makers (Jump, Cumberland, Amber Group) pursue similar registrations, it confirms that the industry views traditional market access as a competitive necessity rather than an optional expansion.

Tokenized securities volume growth. Wintermute’s long term thesis depends on tokenized securities becoming a meaningful asset class. Tracking volume on platforms like Kraken’s xStocks and Nasdaq’s tokenized trading framework will indicate whether this bet is paying off.

Advertisement

SEC rulemaking on digital asset securities. The regulatory framework for trading digital asset securities is still being built. SEC guidance on custody, settlement, and disclosure requirements for tokenized securities will shape the market that Wintermute is positioning to serve.

AP market share for crypto ETPs. Wintermute’s share of the creation and redemption flow for Bitcoin and Ethereum ETFs will be an early indicator of the firm’s ability to compete with established APs in a regulated market.

Regulatory scrutiny of cross market information flows. As Wintermute begins trading equities while maintaining its crypto operations, FINRA and the SEC will monitor how the firm manages information barriers between its trading desks. Any enforcement action related to cross market information use would signal that regulators view the convergence of crypto and equities market making as a systemic risk requiring new supervisory frameworks.

Hiring patterns at competing crypto market makers. If Jump Trading, Cumberland, and Amber Group pursue similar registrations and begin hiring traditional finance compliance and trading staff, it confirms that the industry views Wintermute’s move as setting a competitive standard rather than pursuing a niche strategy. The pace of these hires will indicate how quickly the broader crypto market making industry expects the integrated market to materialize.

Advertisement

u003cstrongu003eWhat did Wintermute register for?u003c/strongu003e

u003cpu003eWintermute USA LLC registered as a broker dealer with the SEC and FINRA on August 6, 2026. The registration allows the firm to trade U.S. equities and equity options, act as an authorized participant for exchange traded products including crypto ETPs, and self clear digital asset securities transactions. The registration is limited to proprietary trading.u003c/pu003e

u003cstrongu003eWhat is an authorized participant?u003c/strongu003e

u003cpu003eAn authorized participant (AP) is one of a limited number of entities that can create and redeem ETF shares directly with the fund issuer. APs keep ETF prices aligned with their underlying assets by arbitraging the difference between the ETF market price and its net asset value. Wintermute’s AP status allows it to perform this function for crypto ETPs like Bitcoin and Ethereum ETFs.u003c/pu003e

u003cstrongu003eWill Wintermute offer brokerage services to retail traders?u003c/strongu003e

u003cpu003eNo. Wintermute USA’s registration is restricted to proprietary trading. The firm trades only for its own account and does not accept customer deposits, manage customer accounts, or provide investment advice. Users interact with Wintermute indirectly through the liquidity it provides on exchanges.u003c/pu003e

Advertisement

u003cstrongu003eWhy would a crypto market maker want to trade stocks?u003c/strongu003e

u003cpu003eCrypto and traditional markets are converging through products like crypto ETFs, tokenized securities, and regulated digital asset trading venues. A market maker that can provide liquidity across both crypto and traditional venues has a structural advantage in this integrated market. Wintermute’s registration positions it to capture arbitrage opportunities across market types.u003c/pu003e

u003cstrongu003eHow big is Wintermute’s trading operation?u003c/strongu003e

u003cpu003eWintermute facilitates over $10 billion in average daily trading volume across more than 60 centralized and decentralized exchanges globally. The firm is one of the largest liquidity providers in crypto and now operates in U.S. regulated securities markets as well.u003c/pu003e

u003cstrongu003eAre other crypto firms pursuing broker dealer licenses?u003c/strongu003e

u003cpu003eYes. Crypto.com acquired SEC registered broker dealer Watchdog Capital in 2024. Coinbase has held a broker dealer registration through its institutional arm. The trend suggests that major crypto firms view traditional market access as a competitive necessity as the two market types converge.u003c/pu003e

u003cstrongu003eWhat are tokenized securities?u003c/strongu003e

u003cpu003eTokenized securities are digital representations of traditional financial instruments, such as stocks or bonds, issued on a blockchain. They trade using crypto settlement infrastructure but are subject to securities regulation. Wintermute’s broker dealer registration positions it to provide liquidity for tokenized securities as this market develops.u003c/pu003e

Advertisement

u003cstrongu003eHow does this affect regular crypto traders?u003c/strongu003e

u003cpu003eRegular crypto traders will not interact with Wintermute USA directly. The indirect effect is potentially tighter spreads and better execution on crypto exchanges and ETFs where Wintermute provides liquidity. As the firm’s cross market capabilities expand, its ability to source liquidity across venues may improve the trading experience for users on the platforms it supports.u003c/pu003eu003cpu003e*Disclaimer: This article is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency investments carry significant risks. Always conduct your own research before making any financial decisions. The information in this article is current as of August 8, 2026.*u003c/pu003e

Source link

Continue Reading

Crypto World

Bitcoin miner rejects BIP-110 despite mining through a pool that supported it

Published

on

Solo Bitcoin (BTC) miner nets $200,000 as Coldcard wallet hack rocks sentiment: Crypto Daily

DATUM moves that decision back to the individual miner. An operator can build its own block using its own bitcoin software while still contributing computing power to Ocean and sharing in the pool’s payouts.

Simple Mining used that control to leave the BIP-110 signal out of block 961,634.

“We chose not to signal and the chain extended on our block,” the company said.

That also explains why Ocean has appeared on both sides of the weekend split.

Advertisement

A miner using Ocean produced the first block accepted by the BIP-110 branch on Saturday, according to fork tracker Mempool. Simple Mining then used the same pool and made the opposite choice, producing a block for the dominant bitcoin chain.

Computers running BIP-110 software began rejecting blocks that did not carry its signal at block 961,632, after miner support peaked at about 2.6%, far below the 55% the proposal needed.

The minority branch has struggled since. It produced blocks 961,632 and 961,633 before stalling, while bitcoin kept producing blocks roughly every ten minutes.

By Monday a live monitor showed the main chain at 961,725, putting the BIP-110 branch more than 200 blocks behind.

Advertisement

Source link

Continue Reading

Crypto World

Cysic (CYS) Skyrockets to New All-Time High on Upbit Listing: Details

Published

on

In times when most major cryptocurrencies remain flatlined, every big move, even from smaller-cap alts, becomes news. Today’s example comes from Cysic’s CYS.

The token skyrocketed by over 60% from its low yesterday at $0.8 to a new all-time high of $1.30 before it was rejected and driven sharply south to $0.92 as of press time. The most evident catalyst for this was a big listing on South Korea’s major exchange, Upbit.

CYS/USDT. Source: TradingView
CYS/USDT. Source: TradingView

The controversial part stems from the timing of the rally. The chart above demonstrates that the most substantial wick in the past 12 hours took place at 23:00 UTC on August 9 when the asset tapped $1.30.

However, the actual Upbit announcement on X went live hours later – after 03:00 UTC on August 10. Trading against BTC and USDT began at 14:00 KST (or 05:00 UTC), which raised some eyebrows on Crypto X about potential insider trading.

Nevertheless, the pump-and-dump move is a reality, and the token behind the decentralized infrastructure project building ‘ComputeFi’ is among the most volatile assets today in a rather calm market.

Advertisement

Upbit listings have a long history of impacting the underlying token with immediate gains and subsequent retracements. We reported one such example in early May when the exchange listed B3 – the native token of a layer-3 blockchain network built on Base, and its price skyrocketed by triple digits to $0.0021 at the time.

A quick look at CoinGecko shows that it is trading roughly 80% below that local peak, currently struggling below $0.00045.

The post Cysic (CYS) Skyrockets to New All-Time High on Upbit Listing: Details appeared first on CryptoPotato.

Source link

Advertisement
Continue Reading

Crypto World

Morgan Stanley Raises Chinese AI Startup Zhipu’s Target Price 72%: Stock Surges 37%

Published

on

Zhipu has seen good momentum after it was flagged by Morgan Stanley.

Morgan Stanley raised its price target on Chinese AI startup Zhipu by nearly 72% on Thursday, sending the stock up and capping a five-day run where the company gained over 37%. The bank says China’s AI industry is leaving the price war era behind.

Analyst Gary Yu and colleagues raised Zhipu’s Hong Kong target from HK$990 to HK$1,700, citing two improvements: better access to computing power, the hardware infrastructure required to train and run AI models, and the completion of a new financing round.

From Price Wars to Intelligence-Driven Profits

For months, the dominant concern hanging over China’s AI sector was that an abundance of competing open-weight models would drive homogenization and a race to the bottom on pricing. Morgan Stanley says that logic is breaking down.

“China’s large-model industry is establishing a healthier commercialization environment,” Yu wrote, arguing the sector is shifting “from price competition to monetization driven by model intelligence.” The smarter model wins revenue, not the cheapest one. That shift, if it holds, changes how investors should value the whole sector.

Advertisement
Zhipu has seen good momentum after it was flagged by Morgan Stanley.
Zhipu has seen good momentum after it was flagged by Morgan Stanley. Image Source: Yahoo

Founded in 2019, Zhipu is best known for its GLM series of large language models and raised $4 billion in a Hong Kong share offering earlier this year.

BeInCrypto has tracked China’s AI models closing the gap on Western rivals throughout 2026. Morgan Stanley had previously flagged the potential for a broad AI-driven re-rating of Hong Kong tech stocks.

MiniMax Gets a More Cautious Read

The same report covered two other names. On MiniMax, the bank stayed “constructive” but lowered its target to HK$900. It says the company’s strongest growth will come in later stages rather than near term.

MiniMax still rose 4.8% on the day. Alibaba drew a bullish mention, with analysts pointing to its end-to-end AI capabilities, computing power advantages, and expanding cloud margins.

The broader Hang Seng Index opened 0.53% higher, with the Hang Seng Tech Index up 0.85%.

Advertisement

If Morgan Stanley’s monetization thesis holds, the companies that can translate model intelligence into recurring revenue will reprice sharply. Zhipu’s five-day climb suggests the market is already betting on it.

The post Morgan Stanley Raises Chinese AI Startup Zhipu’s Target Price 72%: Stock Surges 37% appeared first on BeInCrypto.

Source link

Advertisement
Continue Reading

Trending

Copyright © 2025