Connect with us

Crypto World

Bitcoin price tops $65K ahead of key U.S. CPI report

Published

on

Bitcoin (BTC) price analysis, source: crypto.news

Bitcoin pushed above $65,000 during early trading on Aug. 10 before slipping back below the level, extending its recovery as investors reassessed the U.S. interest rate outlook. 

Summary

  • SoSoValue reported $854 million in weekly Bitcoin ETF inflows as BTC briefly topped $65,000 Monday.
  • July payrolls fell 23,000, prompting traders to reduce expectations for another Federal Reserve rate increase.
  • U.S. July CPI arrives Wednesday, with economists expecting headline inflation to slow to 3.4% annually.
  • BlackRock’s IBIT drew $694 million last week, leading positive flows across U.S. Bitcoin ETF products.
  • Bitcoin gained 3.4% over seven days while remaining roughly 48% below its October record high.

BTC was trading near $64,955 at the time of writing, up 0.3% over 24 hours and 3.4% over seven days. Its intraday high reached $65,363.

The move leaves traders with a clear macro event ahead. The Bureau of Labor Statistics will release July consumer inflation data at 8:30 a.m. ET on Wednesday, Aug. 12. The report follows Friday’s unexpectedly weak employment numbers, which reduced expectations that the Federal Reserve would need to raise rates again soon.

Advertisement

Bitcoin gets relief from weaker U.S. jobs data

The U.S. economy lost 23,000 nonfarm payroll jobs in July, while unemployment held near 4.1%, according to official BLS data. May payroll growth was revised down by 66,000 and June by 37,000, removing 103,000 jobs from the two previous estimates combined. Average hourly earnings rose 3.2% from a year earlier.

Bitcoin moved above $65,000 after the report as rate expectations shifted. As crypto.news reported in Friday’s payroll reaction, BTC initially gained almost 2% as investors interpreted weaker hiring as reducing pressure on the Fed to tighten policy. The move has since held, although $65,000 has not yet become firm support.

The policy backdrop remains divided. The Federal Reserve held its target range at 3.50% to 3.75% on July 29, but three voting officials preferred a 25 basis point increase, according to its statement. The central bank also said inflation remained above its 2% goal, partly because of energy related supply pressures.

Advertisement

Bitcoin ETF demand strengthened throughout last week

Institutional demand also improved as Bitcoin approached resistance. SoSoValue reported $854 million in net inflows into U.S. spot Bitcoin ETFs from Aug. 3 through Aug. 7, with BlackRock’s IBIT accounting for about $694 million. The figure marked a reversal from the weaker fund flows seen around the end of July.

There is a small difference between ETF datasets. Farside’s current flows show daily totals of $170.1 million, $211.5 million, $244.4 million, $137.6 million and $101.7 million over the same five sessions, which sum to about $865.3 million. For that reason, the $854 million weekly total is best attributed specifically to SoSoValue rather than treated as a universal figure.

The demand followed several sessions in which ETF buying failed to produce an immediate breakout. In earlier ETF flow coverage, Bitcoin remained near $64,200 on Aug. 7 even after funds recorded four consecutive positive sessions. Friday’s additional inflows extended that streak while BTC continued challenging the same resistance area.

$65,800 remains a closely watched Bitcoin barrier

The price structure has improved since Bitcoin traded near $62,500 at the beginning of last week, but the market has repeatedly struggled between $65,000 and $66,000. Crypto.news previously identified the same area in recent resistance analysis, where $65,000 to $65,500 also contained a concentration of liquidation liquidity.

Advertisement

The Relative Strength Index stood at 55.07, above its moving average of 50.44 and the neutral 50 level. The reading points to moderate bullish momentum, with buyers holding a slight advantage. However, RSI remains well below overbought territory, suggesting momentum has strengthened without becoming stretched.

Bitcoin (BTC) price analysis, source: crypto.news
Bitcoin (BTC) price analysis, source: crypto.news

The Awesome Oscillator was positive at about 664.19, supporting the improving momentum picture. Its histogram bars remained relatively small compared with those recorded during stronger directional moves, so the indicator points to improving momentum rather than confirming a major breakout.

Analyst Michaël van de Poppe has placed the next level slightly higher. In an Aug. 9 post, he called $65,800 the “critical level” and said BTC was “ready for a breakout to at least $73,700.” 

He also cited bullish divergence in longer duration RSI and MACD readings. Those figures are his technical targets, not confirmed price objectives, and Bitcoin still needs to clear the resistance he identified.

What happens next as U.S. inflation takes focus

Wednesday’s CPI report is now the nearest scheduled U.S. catalyst. June consumer prices fell 0.4% from May while rising 3.5% from a year earlier. Core CPI was unchanged during June and rose 2.6% annually. Economists surveyed by Reuters expect July headline inflation to ease to 3.4% annually and core inflation to slow to 2.5%.

The market is also dealing with renewed energy pressure. Brent crude rose 1% to $84.40 on Monday as uncertainty around shipping through the Strait of Hormuz continued. Meanwhile, the U.S. 10 year Treasury yield traded near 4.66%. Futures markets put the probability of a September Fed rate increase near 44%, down from 67% one week earlier.

A hotter CPI reading could rebuild expectations for another increase and put renewed pressure on risk assets. A softer reading could reinforce the interpretation traders drew from Friday’s weak employment report, but it would not guarantee a Bitcoin breakout. The Fed’s next scheduled policy meeting runs Sept. 15 to Sept. 16, leaving policymakers with several more economic releases before deciding whether rates should change.

For Bitcoin, the immediate test therefore remains narrow: holding the recovery around $65,000 while attempting to clear the $65,800 area. Wednesday’s inflation numbers will provide the next evidence on whether the U.S. macro environment supports that move or sends traders back toward the lower end of Bitcoin’s recent range.

Advertisement

Disclosure: This article does not represent investment advice. The content and materials featured on this page are for educational purposes only.

Advertisement

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

BIP-110 Soft Fork Implodes: Mines Just Two Blocks Before Grinding to a Halt

Published

on

A Bitcoin soft fork built around BIP-110 split from the main chain after block 961,632 this week, and it barely got off the ground. The pool backing it, Roughnecks, mined exactly two blocks before the rest of the network’s hashpower left it stranded.

The split was supposed to test whether a determined group of node operators could force miners to fall in line on data spam. Instead, it showed how little leverage a minority actually has once the hashrate refuses to follow.

The Fork Stalls Within Hours

BIP-110 needed miners to signal support by block 961,632, or a mandatory signaling rule would take over. When AntPool mined the first non-signaling block, nodes running Bitcoin Knots split into their own chain. Roughnecks found blocks 961,632 and 961,633 on that branch, then nothing more. Bitcoin’s original chain kept moving at its usual pace and reached block 961,651, opening an 18-block lead within about a day.

The math comes down to difficulty. Bitcoin’s mining difficulty had just adjusted to 127.48T, a target both chains inherited. With only a sliver of total hashpower behind it, the BIP-110 branch found blocks far slower than the usual ten minutes.

Advertisement

BIP-110 supporter Matthew Kratter admitted that the minority chain would need “massive change” to catch up. It never came. By the time Michael Saylor addressed the split, he put the gap at more than 80 blocks and said roughly 99.85 percent of Bitcoin’s hashpower had stayed with the main chain.

Lyn Alden made a similar distinction on August 9, saying the majority of miners, economic nodes, and exchanges continued with the non-fork.

“It’s not that miners are in control,” she wrote. “The fork just didn’t have consensus.”

BIP-110 supporters have rejected that conclusion. Luke Dashjr wrote on August 9 that claims of the proposal’s failure were false. Earlier, he had argued that BIP-110 remained uncontested because no counter-fork had emerged.

However, Roughnecks put out a tweet asking those mining on the BIP-110 chain under the current algorithm to stop until further notice, with investor Fred Krueger pointing out that the lead had grown from “153 to 2.”

Advertisement

Bitcoin’s price barely moved through any of it. BTC traded around $65,000, up modestly on the day and nearly 4% for the week, though still down close to 45% from a year earlier.

Dispute Over Data, Not Just Block Counts

The underlying fight traces back to Bitcoin Core dropping its old limit on OP_RETURN data, which let more non-monetary data, like Ordinals and Runes, fill up blocks that BIP-110 backers wanted reserved for payments.

Farside Investors had warned weeks earlier that the fix carried its own risk. Wallets using Miniscript could still generate addresses built on soon-to-be-banned Taproot scripts, and any bitcoin sent to them after activation would become unspendable. Pay-to-public-key outputs, an old script format holding more than 1.7 million BTC, faced new restrictions too, though existing units could still be spent.

Not everyone who backed BIP-110’s goals agreed with how the attempt played out. Writer Secure Sovereign, who supported the underlying fix but not this activation path, said the effort left BIP-110 as “a distant minority with no realistic path to catching the main chain,” arguing miners never faced real risk of being forked off themselves.

Advertisement

Days later, Bitcoin developer Murch moved to remove Luke Dashjr from his role as a BIP editor, citing his handling of the proposal as a conflict of interest, a dispute still playing out on Bitcoin’s mailing list.

The post BIP-110 Soft Fork Implodes: Mines Just Two Blocks Before Grinding to a Halt appeared first on CryptoPotato.

Source link

Advertisement
Continue Reading

Crypto World

Robinhood rolls out crypto trading in UK with more than 50 assets

Published

on

Trump taps Robinhood for new child investment account rollout

Robinhood has begun offering cryptocurrency trading to eligible UK customers, giving users access to more than 50 digital assets through Bitstamp inside its main investing app.

Summary

  • Robinhood has launched crypto trading for eligible UK customers with access to more than 50 digital assets.
  • Crypto trades are provided through FCA registered Bitstamp UK, which Robinhood acquired for $200 million last year.
  • The service has no trading, custody or account maintenance fees, while foreign exchange fees start at 0.1%.
  • Robinhood has also introduced Cortex Digests for Crypto, an AI powered tool for analyzing crypto price movements.
  • The launch follows Robinhood’s FCA crypto registration on July 31 ahead of the UK’s new authorization regime.

According to a Bloomberg report, the rollout starts this week and brings crypto trading alongside Robinhood’s existing UK products, which include equities, stocks and shares ISAs, options and futures.

Customers can buy and sell assets including Bitcoin, Ethereum, XRP and HYPE, with the trades handled by Bitstamp UK Ltd. Robinhood acquired the long-running crypto exchange for $200 million last year and has since used the business to support parts of its international crypto expansion.

Advertisement

The UK service carries no trading, custody or account maintenance fees, Robinhood said. Customers will instead pay a 0.1% foreign exchange fee when converting currencies, while certain conversions made during weekends will carry a 0.3% fee.

Robinhood crypto trading starts after FCA registration

The launch follows regulatory approval secured shortly before the product rollout. Robinhood’s UK subsidiary was added to the Financial Conduct Authority’s register of cryptoasset firms on July 31, clearing a regulatory requirement for providing cryptocurrency services in the country.

Under the existing UK system, crypto firms must register with the FCA and comply with anti-money laundering requirements before offering covered services. Robinhood had previously disclosed during its July 29 second-quarter earnings report that it planned to introduce crypto products in the UK but did not provide a launch date at the time.

Crypto trading is being provided through Bitstamp UK Ltd, which is registered with the FCA as a cryptoasset service provider. Robinhood warned that cryptocurrencies held through Bitstamp UK are not protected by the Financial Services Compensation Scheme or covered by the Financial Ombudsman Service.

Advertisement

Jordan Sinclair, president of Robinhood UK Ltd and general manager of Bitstamp UK Ltd, said the company sees digital assets becoming an important part of investment portfolios among a new group of UK investors.

“With today’s launch, we’re taking another major step toward becoming the all-in-one investment platform for the UK,” Sinclair said.

Robinhood enters the market before another regulatory change scheduled for the UK crypto sector. Applications under the country’s incoming crypto authorization framework are expected to open at the end of September and remain available until the end of February 2027, with the full regime scheduled to take effect in October 2027.

The FCA registration obtained under the current anti-money laundering framework does not replace authorization under the incoming system. Companies seeking to continue providing covered crypto services after the transition will need to meet the requirements of the new regime.

Cortex adds AI analysis to Robinhood’s UK crypto service

Alongside trading, Robinhood is introducing Cortex Digests for Crypto to UK customers as part of the rollout.

Advertisement

The generative AI feature processes breaking news, technical indicators, market information and Robinhood’s proprietary data to provide explanations for price movements in individual cryptocurrencies. According to the company, the tool is designed to give investors additional market context when evaluating digital assets.

Adding the feature extends Robinhood Cortex into a crypto service that now sits inside the same application as the company’s other UK investment products.

The launch also connects UK customers to a crypto business that has expanded beyond buying and selling tokens. Robinhood has been developing its own blockchain infrastructure through Robinhood Chain, a permissionless Layer 2 network built using Arbitrum technology.

According to company figures, Robinhood Chain has recorded more than $18 billion in decentralized exchange trading volume and more than $840 million in total value locked since launching on July 1.

Advertisement

Developers worldwide, including those in the UK, can build applications on the network. Robinhood has described the blockchain as infrastructure developed to institutional standards.

During the company’s latest earnings period, CEO Vlad Tenev said Robinhood Chain had become the fastest Ethereum Virtual Machine-compatible blockchain to reach 100 million transactions.

Crypto revenue fell as Robinhood expanded other businesses

The UK rollout comes after Robinhood reported lower cryptocurrency transaction revenue during the second quarter despite expanding its digital asset products.

Advertisement

Crypto transaction revenue fell 38% from a year earlier to $100 million in the quarter ended June 30, according to financial results released on July 29.

Other parts of Robinhood’s trading business recorded stronger growth. Prediction markets generated $156 million during the quarter, exceeding crypto transaction revenue for the first time.

Total net revenue increased 32% year over year to $1.31 billion, while net income rose 48% to $573 million compared with the second quarter of 2025.

During the same period, Robinhood launched Robinhood Chain, expanded its Stock Tokens product to more than 120 countries, introduced Robinhood Earn and completed its acquisition of Canadian crypto platform WonderFi.

Advertisement

Prediction markets have also become a larger part of the company’s product lineup. The Wall Street Journal reported in July that Robinhood had discussed adding event contracts from Crypto.com to its prediction markets hub, although neither company confirmed an agreement.

Robinhood already distributes contracts through Kalshi and ForecastEx, while it also operates Rothera through a joint venture with Susquehanna International Group.

Robinhood has continued adding products outside crypto

Days before launching UK crypto trading, Robinhood also filed to raise as much as $200 million for its second publicly listed venture fund.

Regulatory filings showed Robinhood Ventures Fund II plans to offer 7.6 million shares at $25 each, with Robinhood separately selling another 400,000 shares. Subject to regulatory approval, the fund is expected to begin trading on the New York Stock Exchange under the ticker RVII on Aug. 13.

Advertisement

Unlike Robinhood Ventures Fund I, which concentrated on later-stage private companies including OpenAI, Stripe, SpaceX and Databricks, RVII is structured mainly around earlier-stage businesses.

The fund is expected to begin with investments in about 80 private companies and will primarily target seed-stage businesses connected to Y Combinator, including companies founded by current or former accelerator participants and YC alumni.

Robinhood Ventures head Sarah Pinto said the structure is intended to give retail investors access to companies earlier in their development rather than requiring them to wait until an initial public offering.

RVII also introduces fees that were not part of Robinhood’s first venture fund. Regulatory disclosures show investors will pay a 2% annual management fee and a 20% incentive fee on realized gains, while the prospectus warns that shareholders will not have redemption rights before liquidation.

Advertisement

The subscription period is scheduled to close on Aug. 12, according to the filing, with Goldman Sachs serving as lead bookrunner and Citigroup, JPMorgan, UBS and Wells Fargo acting as joint bookrunners.

Source link

Advertisement
Continue Reading

Crypto World

UMX launches beta with crypto and real U.S. stocks

Published

on

UMX debuts cross asset platform, source: Wu Blockchain

UMX, the Unified Market Exchange incubated by Li Lin’s Avenir Group, launched an invitation only public beta on Aug. 10 for professional investors. 

Summary

  • UMX launched an invitation-only beta combining crypto trading with real U.S. stocks, ETFs and options.
  • Users can convert USDT into dollars or borrow against crypto to fund securities purchases directly.
  • UMX says securities positions represent actual shares rather than CFDs or purely price-tracking tokenized products.
  • Stock holdings can be converted into tokens and counted toward crypto account margin requirements directly.
  • Avenir held 18.28 million IBIT shares at March 31, retaining Asia’s largest institutional holder ranking.

The platform combines crypto trading with access to real U.S. stocks, ETFs and U.S. stock options, according to a PANews report citing official disclosures.

The beta is built around moving capital between crypto and securities accounts rather than keeping the two markets separate. UMX says eligible users can trade crypto spot, margin, contracts and options while also accessing U.S. securities through the same broader platform.

Advertisement

UMX beta combines crypto and real U.S. securities

UMX says its securities service gives users positions in actual U.S. shares rather than CFDs or products that only track stock prices. A Wu Blockchain review of UMX disclosures says the service includes stocks, ETFs, options and fractional shares, with trading spanning premarket, regular, after hours and overnight sessions.

UMX debuts cross asset platform, source: Wu Blockchain
UMX debuts cross asset platform, source: Wu Blockchain

The platform is aimed at global professional investors, but access depends on location, account status and product eligibility. The launch material does not establish that the securities service is available to U.S. residents. Offering U.S. listed assets and serving customers located in the U.S. are separate questions, so the distinction should remain clear until UMX publishes more jurisdiction specific details.

Cross asset tools connect stablecoins, crypto and shares

UMX’s main feature is the capital bridge between its crypto and securities sides. Through “Exchange Transfer,” users can convert stablecoins such as USDT into U.S. dollars and move the funds into a securities account. “Loan Transfer” allows crypto assets other than stablecoins to serve as collateral for purchasing power used to trade stocks, ETFs and U.S. stock options.

The platform also says securities holdings can be converted through a “Shares to Token” function into corresponding stock tokens. Those tokens can count toward crypto account margin at applicable discount rates and can later be converted back into securities. The launch reports reviewed do not identify the blockchain, token issuer or detailed custody structure behind those converted positions.

Advertisement

UMX is also testing cross asset margin treatment for eligible wealth management balances. During the beta, it advertises maximum annualized yields of “up to 2.5%” for BTC and “up to 5.5%” for USDT products. Those figures are platform advertised rates rather than guaranteed returns, and UMX says rates, limits and terms depend on the individual product.

Avenir brings a large Bitcoin ETF position to UMX

Avenir Group describes its strategy as integrating traditional finance and digital assets through investment, incubation and operations. The firm has also invested in trading infrastructure, including a February partnership with CoinRoutes aimed at improving institutional execution and capital efficiency across fragmented markets.

An SEC filing by Avenir Tech Ltd, signed by Li Lin, shows 18,276,100 BlackRock iShares Bitcoin Trust shares worth about $702.2 million as of March 31. The filing was submitted May 15 and remains the latest quarterly 13F available as of Aug. 10.

As crypto.news reported in earlier Avenir coverage, the group had already built a large regulated Bitcoin ETF position before expanding further into infrastructure connecting traditional and digital finance.

Advertisement

UMX also enters a market where crypto platforms are moving toward broader financial services. In Binance’s stock trading rollout, eligible users outside the U.S. gained access to thousands of U.S. stocks and ETFs. Meanwhile, recent NYSE tokenization coverage shows traditional exchanges pursuing blockchain based securities infrastructure from the opposite direction.

What happens next for UMX

The public beta remains invitation only. Users with a beta code can register, while those without one can reserve access to the full version and receive launch notifications. UMX has not disclosed a firm date for its wider release in the launch material reviewed.

The next details to watch are the legal entities providing each securities and crypto service, jurisdiction restrictions, custody arrangements and the mechanics behind stock token conversions. For now, the confirmed development is the beta itself: UMX is testing a framework designed to make stablecoins, crypto collateral and real U.S. securities usable within a shared capital system.

Advertisement

Source link

Continue Reading

Crypto World

Bitcoin Red Team Founder Joins Chinese AI Project, Cites Impact

Published

on

Crypto Breaking News

A Bitcoin security researcher says he lost access to an OpenAI capability used in his ongoing vulnerability reviews, forcing him to shift back to open-source Chinese AI models. The move underscores a broader concern within parts of the crypto security community: that the most advanced AI systems may be difficult for “defenders” to use, even when the intent is to reduce risk.

In a post on X Tuesday, AnchorWatch CEO Rob Hamilton said he began integrating OpenAI’s Trust & Cyber capabilities into his Bitcoin Red Team effort on Saturday, only to find his access restricted the next morning. “It absolutely guts me as a patriotic American to have to do this,” Hamilton wrote, adding that he would return to using Chinese open-source models to continue protecting Bitcoin infrastructure.

Key takeaways

  • Rob Hamilton says access to OpenAI’s Trust & Cyber was restricted shortly after he began integrating it into Bitcoin Red Team work.
  • Hamilton frames the change as a defensive tradeoff: open AI models are accessible, while certain frontier tools may be harder for defenders to retain.
  • Bitcoin Red Team conducts vulnerability scanning across hundreds of open-source Bitcoin-related repositories using a mix of AI assistance and human review.
  • Recent hacks in the hardware wallet space have increased pressure on teams trying to detect issues earlier in the development lifecycle.

How Bitcoin Red Team is using AI to find vulnerabilities

Bitcoin Red Team is a volunteer effort that scans a large set of open-source Bitcoin-related repositories for potential vulnerabilities. According to Hamilton’s account, the work relies on AI tools combined with human verification, with the goal of identifying weaknesses that may otherwise go unnoticed or be discovered only after exploitation.

The group’s efforts have reportedly intensified following a widely discussed incident involving a Coldcard hardware wallet hack, which earlier reporting described as resulting in more than $100 million in stolen Bitcoin. While Hamilton’s post does not quantify how the OpenAI access affected the rate or quality of findings, it does connect the research workflow to a broader urgency—namely, that attackers are actively searching for flaws in the systems people rely on to keep funds secure.

What Hamilton says changed after integrating OpenAI Trust & Cyber

Hamilton’s explanation is straightforward: he started using OpenAI’s Trust & Cyber capabilities to support his team’s review process, then lost the ability to continue the investigation that same week. He said he was “prevented from being able to continue the investigation in a further effort to make sure their code changes are sufficient” and also to determine whether other issues remained undiscovered.

Advertisement

In a follow-up argument about the incentive structure for AI access, Hamilton suggested there is a “local minima in policy,” implying that rules governing the availability of intelligence-focused AI capabilities may unintentionally narrow who can use them for defensive purposes. He added that while “black hats” would not hit these issues, “white hats” could be left on the sidelines if the tooling is restricted.

Hamilton’s characterization is notable because it positions the problem less as a technical limitation of AI and more as an access and policy constraint affecting security research workflows. For investors, users, and builders, the practical concern is that fewer defender teams may be able to run high-end analysis at scale—at the exact moment when vulnerabilities across crypto infrastructure need faster detection.

Broader friction over “frontier” AI access in crypto security

This complaint fits into a pattern that has already been raised by crypto executives. Earlier coverage from Cointelegraph noted that many of crypto’s largest players were “still waiting to gain access” to powerful new AI models to strengthen their code from attacks, with only a limited number able to obtain it. In that context, Hamilton’s experience appears as a micro-level example of how access can be uneven—even for teams working on vulnerability discovery rather than exploitation.

The tension is that crypto ecosystems can’t rely solely on open-source tooling if the industry’s risk profile increasingly demands rapid review of complex codebases. Yet, if leading AI providers constrain usage in ways that make defensive experimentation difficult to sustain, security efforts may end up dependent on a patchwork of what is available rather than what is best suited for the task.

Advertisement

Why the shift back to open-source models matters

Hamilton said he would return to Chinese open-source models after the access restriction. That change is significant for two reasons.

  • Continuity: If defender access to frontier systems is inconsistent, researchers may need fallback approaches they can run without interruptions. Open-source models can be deployed and iterated on without waiting for new permissions.
  • Coverage and speed: Teams scanning “hundreds” of repositories depend on automated support to review large volumes. If access to an advanced tool is removed midstream, the research cadence and scope can be affected unless an alternative system fills the gap quickly.

At the same time, Hamilton’s stance does not necessarily imply that open-source models are always inferior. Instead, his argument is that defensive research is being forced to operate within the boundaries of whatever AI is available—while attackers face fewer barriers to pursuing harmful goals. That framing raises a question for the community: how can security research leverage advanced AI while still operating under restrictions intended to prevent misuse?

For readers tracking crypto risk, this story is less about who “has” cutting-edge AI at any given moment and more about whether defender capability can be maintained over time. The next inflection point will be whether access policies are clarified, expanded, or made more predictable for security-focused use cases—especially as vulnerabilities continue to be discovered across wallets and other critical infrastructure.

Hamilton’s update leaves one key uncertainty: what specifically triggered the restriction and whether it was temporary or permanent. What readers should watch next is whether other security teams report similar access changes, and how quickly research workflows adapt without losing the ability to uncover vulnerabilities before they reach production.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Advertisement

Source link

Continue Reading

Crypto World

BTC above $65,000 even as the Senate punts the CLARITY Act to the fall

Published

on

BTC above $65,000 even as the Senate punts the CLARITY Act to the fall

Bitcoin held near $65,200 on Monday, up 3.7% on the week, per CoinDesk data. The move caps a recovery from an early-August low near $62,000, and the whole top of the market came with it. Ether traded near $1,925 and BNB, Solana and TRON all posted weekly gains.

The strength held despite the Senate failing to pass the CLARITY Act before leaving for its August recess on Friday, mustering 51 of the 60 votes needed and pushing any action to September 14 at the earliest.

That the market rose anyway backs what strategists argued last week, that the delay was already priced, so the failure landed as confirmation rather than a fresh blow.

The bid is coming from flows, not headlines.

Advertisement

Spot ETFs have strung together consecutive days of inflows, and a softer dollar since the weak US jobs report has loosened the backdrop that pinned bitcoin through the summer.

Michael Saylor added to the mood over the weekend, posting Strategy’s bitcoin-buy chart with the caption “Doing business,” days after the firm disclosed selling about 1,638 BTC to fund buybacks, which markets read as a tease of another purchase.

Source link

Advertisement
Continue Reading

Crypto World

Australia Orders Cryptolink Bitcoin ATMs Offline After Reporting Lapses

Published

on

Crypto Breaking News

Australia’s financial crime regulator AUSTRAC has suspended the operation of Cryptolink’s Bitcoin ATMs for three months, citing ongoing concerns about the company’s compliance with anti-money laundering obligations. The decision pauses Cryptolink’s ability to run as a registered Virtual Asset Service Provider (VASP), effectively taking its crypto ATMs offline during the suspension period.

With Australia hosting the highest number of crypto ATMs in the Asia-Pacific region, the move underscores the regulator’s continued focus on reducing illicit activity linked to automated cash-to-crypto access—especially as authorities have escalated scrutiny of the sector since late 2024.

Key takeaways

  • AUSTRAC suspended Cryptolink’s VASP registration for three months, meaning its Bitcoin ATMs cannot operate during that timeframe.
  • The regulator cited failures to meet core reporting expectations, including threshold transaction reports, and noted the company did not respond to AUSTRAC requests.
  • AUSTRAC said it has “ongoing concerns” about Cryptolink’s ability to manage high-risk transactions through its ATMs.
  • The action follows prior enforcement steps tied to alleged late reporting and weaknesses in Cryptolink’s risk assessments.
  • Cryptolink operates 96 ATMs across major Australian cities, offering cash-to-Bitcoin exchanges.

AUSTRAC suspends Cryptolink’s VASP registration

AUSTRAC CEO Brendan Thomas said the suspension begins Sunday and will last three months. According to AUSTRAC, Cryptolink’s registration as a Virtual Asset Service Provider has been halted, which directly prevents its cryptocurrency ATMs from operating while the order is in effect.

In a statement, Thomas linked the decision to what AUSTRAC described as ongoing concerns regarding Cryptolink’s capacity to handle high-risk activity associated with digital asset transactions. The regulator emphasized that its scrutiny centers on digital currency as a potential money laundering risk, particularly in contexts where cash can be converted into crypto through automated systems.

What AUSTRAC says went wrong

AUSTRAC said Cryptolink failed to meet basic compliance and reporting requirements. The regulator highlighted shortcomings in threshold transaction reporting, a category of submissions that helps authorities identify larger or otherwise significant transactions that may warrant additional attention under anti-money laundering frameworks.

Advertisement

AUSTRAC also stated that Cryptolink did not respond to a request for information from the agency. While the details of the request are not included in the available coverage, the combination of reporting failures and non-response was positioned as a core reason behind the suspension.

“As part of our continued focus on digital currency as a money laundering risk, AUSTRAC has ongoing concerns about the company’s ability to manage high-risk transactions through its CATMs,” Thomas said.

Enforcement background: October 2025 undertaking and a fine

The suspension does not appear as an isolated action. AUSTRAC noted that the move follows an enforceable undertaking Cryptolink entered into in October 2025, after a Cryptocurrency Taskforce identified alleged breaches. AUSTRAC cited alleged late transaction reporting and shortcomings in Cryptolink’s risk assessments as part of that earlier compliance outcome.

AUSTRAC also referenced a separate infringement notice issued to Cryptolink, which AUSTRAC said amounted to $56,340. Cryptolink paid the notice. Together, these steps indicate a regulatory pattern: initial enforcement and corrective expectations in 2025, followed by a further escalation once AUSTRAC concluded its concerns were not resolved.

Advertisement

Earlier AUSTRAC reporting about Cryptolink’s issues has also focused on late reporting, reflecting the regulator’s interest in whether transaction monitoring and reporting systems are robust enough to detect and flag suspicious activity in time.

Cryptolink’s ATM footprint and the compliance ripple effect

Cryptolink operates 96 ATMs in Australia. Its machines are concentrated in major cities, including Sydney, Melbourne, and Brisbane, enabling users to exchange cash for Bitcoin.

For everyday customers, the immediate impact is straightforward: with the suspension in place, Cryptolink’s ATMs should not be able to operate during the three-month window. For the broader market, the development highlights how compliance enforcement can translate into practical restrictions on on-the-ground access to crypto services—turning regulatory findings into operational downtime.

For investors and industry participants, the case is also a reminder that registration status can change quickly when regulators conclude that reporting systems, responses to information requests, or risk controls are inadequate. In a market where crypto ATMs have expanded across multiple jurisdictions, enforcement actions like this can affect how operators prioritize compliance tooling and internal controls, particularly around transaction monitoring and threshold reporting obligations.

Advertisement

Cointelegraph reached out to Cryptolink for comment; no additional response was included in the provided material.

As the suspension period progresses, the key question for readers will be whether Cryptolink can address the specific reporting and risk management concerns AUSTRAC raised—and what AUSTRAC will require to restore the ability for its machines to run. Operators across the sector are likely watching closely, because the regulator’s rationale suggests that both technical reporting performance and responsiveness to regulatory requests will remain central to any future decision on registration status.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Advertisement

Source link

Continue Reading

Crypto World

Robinhood (HOOD) brings crypto trading to UK in AI-powered all-in-one app

Published

on

Robinhood (HOOD) brings crypto trading to UK in AI-powered all-in-one app

Robinhood (HOOD) is introducing zero-fee crypto trading in the U.K. alongside stocks and shares ISAs, equities, options and futures, the company said on Monday.

The all-in-one Robinhood app will bring U.K. customers access to over 50 cryptos including Bitcoin , Ethereum , XRP (XRP), Hyperliquid (HYPE), accessed via Bitstamp, the exchange Robinhood acquired in 2025.

The trading firm is also introducing “Robinhood Cortex Digests for Crypto,” a generative AI-powered widget that analyses breaking news, market data, technical indicators and Robinhood’s proprietary insights. The AI service explains in plain English the key factors driving price movements in individual crypto assets, Robinhood said.

“Our new product provides a transparent, low-cost alternative to many incumbent U.K. platforms, which often rely on opaque pricing structures and apply wide spreads that can erode customers’ returns,” Robinhood said.

Advertisement

“It will begin rolling out to eligible U.K. customers this week.”

The product also expands Robinhood’s growing crypto ecosystem for UK customers. As such, UK developers can build on the highly popular Robinhood Chain, a layer 2 blockchain built on the Arbitrum platform.

Source link

Advertisement
Continue Reading

Crypto World

World Liberty’s $100M WLFI buyer linked to UK money laundering probe

Published

on

World Liberty’s $100M WLFI buyer linked to UK money laundering probe

Guren “Bobby” Zhou, the businessman identified as the person behind Aqua 1’s $100 million purchase of World Liberty Financial tokens, has remained linked to an active British money laundering investigation after his 2021 arrest, despite not being charged.

Summary

  • Zhou was arrested in Britain in 2021 on suspicion of money laundering but has not been charged.
  • Aqua 1 bought $100 million of World Liberty Financial’s WLFI tokens in 2025.
  • The source of the $100 million used for the WLFI purchase remains unclear.
  • Up to $75 million from the Aqua 1 purchase went to a Trump controlled entity.
  • World Liberty has faced congressional scrutiny over separate UAE linked investments.

The New York Times reported Sunday that British authorities arrested Zhou in 2021 on suspicion of money laundering, while a court record filed last November accused him of participating with five other people in a laundering operation dating to 2019.

Two of Zhou’s longtime employees were charged in the case in September 2025, according to the report. One defendant has since pleaded guilty, while the trial involving the charged defendants is scheduled for 2028.

Advertisement

Zhou himself has not been charged with a crime.

The case has drawn attention because Zhou was identified as the businessman behind Aqua 1, the UAE-based investment vehicle that bought $100 million worth of WLFI governance tokens from World Liberty Financial. Reuters previously identified Zhou as the person behind the fund, while the purchase was publicly announced in June 2025.

Aqua 1’s $100 million World Liberty investment remains unexplained

A review of court records, confidential documents and interviews with Zhou’s former associates led the Times to examine how the businessman went from a series of troubled ventures in Britain to overseeing one of the largest publicly known investments in World Liberty.

The newspaper said it was unable to determine where the $100 million used for the WLFI purchase came from.

Advertisement

Blockchain activity examined as part of the report also connected Zhou’s earlier crypto business to the World Liberty transactions. According to the Times, blockchain analytics firm Arkham Intelligence determined that a wallet controlled by Web3Port bought $20 million worth of WLFI in January 2025.

A second wallet believed to be controlled by Aqua 1 purchased another $80 million in June, bringing the combined purchases to $100 million.

Before Aqua 1 emerged publicly, Zhou had led Web3Port, a crypto venture fund that announced a separate $10 million investment in World Liberty shortly after President Donald Trump’s inauguration in January 2025.

Corporate records reviewed by the Times showed that a Web3Port entity registered in the British Virgin Islands was later renamed Aqua 1 GP Limited. Aqua 1 announced its $100 million WLFI purchase about two weeks after the name change.

Advertisement

Aqua 1 had previously denied having a connection to Web3Port after earlier reporting linked the operations. The fund did not specify which parts of that reporting it disputed.

Zhou’s previous businesses faced financial problems

Before relocating from London to Abu Dhabi in 2024, Zhou operated businesses that later faced financial or credibility problems, according to the Times.

One was a British flooring retailer that entered restructuring without repaying roughly $5 million owed to a company controlled by Zhou’s father.

Advertisement

Zhou later launched Caduceus, a crypto project that raised about $7.6 million in funding. Its token had become effectively worthless by 2024, according to the newspaper.

Caduceus had announced backing from China Merchants Securities UK and the Bin Zayed Group, an organization founded by a member of Abu Dhabi’s royal family. Both organizations told the Times that claims about their involvement were “unauthorized and materially false.”

After moving to Abu Dhabi, Zhou became associated with Web3Port and subsequently Aqua 1, putting him behind investments that made the entities major buyers of World Liberty tokens.

The timing also placed Aqua 1 among several UAE-linked investments involving World Liberty that have drawn scrutiny from U.S. lawmakers.

Advertisement

World Liberty token sale sent millions to Trump-controlled entity

Under World Liberty’s revenue-sharing structure, as much as $75 million from Aqua 1’s $100 million token purchase went to a company controlled by Trump and his sons, according to the Times.

Previous reporting showed that 75% of proceeds from WLFI token sales flow to DT Marks DEFI LLC, an entity controlled by Trump.

Trump’s latest financial disclosure listed more than $65.6 million from the sale of equity in WLF Holdco and $236.25 million in distributed World Liberty token-sale proceeds.

The Aqua 1 transaction also benefited the family of World Liberty co-founder Zach Witkoff, according to the Times. His father, Steve Witkoff, serves as a special envoy in the Trump administration.

Advertisement

World Liberty spokesperson David Wachsman told the newspaper that the company had complied with applicable laws and regulations and maintained a compliance program that “meets or exceeds industry standards.”

Wachsman declined to say whether World Liberty knew where Zhou obtained the money used for the investment. He also disputed the newspaper’s portrayal of Zhou but did not identify specific factual inaccuracies in its reporting.

World Liberty investments have faced congressional scrutiny

Questions surrounding Aqua 1 come as U.S. lawmakers have already examined separate UAE-linked investments in World Liberty and whether foreign financial interests could create conflicts involving the Trump administration.

In June, five Democratic senators asked Republican committee leaders to hold hearings into a reported $500 million investment in World Liberty by Aryam Investment 1, an Abu Dhabi-based company backed by UAE national security adviser Sheikh Tahnoon bin Zayed Al Nahyan.

Advertisement

Citing Wall Street Journal reporting, the senators said Aryam acquired a 49% stake in World Liberty through an agreement signed in January 2025.

Their letter asked Congress to examine events that followed the transaction, including the Trump administration’s May 2025 approval of major arms sales and access to advanced artificial intelligence chips for the UAE. The lawmakers said U.S. national security officials had previously raised concerns that China could gain access to the technology.

Senators Elizabeth Warren and Andy Kim had separately asked Treasury Secretary Scott Bessent in February to determine whether the reported UAE investment required review by the Committee on Foreign Investment in the United States.

World Liberty has also faced regulatory questions over its plans to expand its financial operations. During a Senate Banking Committee hearing, Warren questioned Comptroller of the Currency Jonathan Gould about a reported application by World Liberty for a federal bank charter and whether the company had disclosed the foreign investment to regulators.

Advertisement

Gould declined to discuss a pending application and said the Office of the Comptroller of the Currency would follow its established procedures.

Trump has denied involvement in World Liberty’s daily operations. Speaking to reporters in February, he said he did not know about the reported UAE investment and said his sons were responsible for managing the business.

The White House has separately rejected conflict-of-interest allegations, saying Trump’s assets are held in a trust administered by his children and that administration decisions are made independently of his family’s business interests.

Advertisement

Source link

Continue Reading

Crypto World

Bybit is suing North Korea, and it might actually work

Published

on

Bybit is suing North Korea, and it might actually work

The exchange filed a civil lawsuit in a US federal court against North Korea, its intelligence agency, and the Lazarus Group over the $1.5 billion hack of February 2025. A judge has already frozen stolen assets. The case tests whether civil law can do what criminal enforcement has not.

Summary

  • Bybit filed a civil lawsuit on August 7, 2026, in the US District Court for the District of Columbia, naming North Korea, its Reconnaissance General Bureau intelligence agency, and the Lazarus Group as defendants over the $1.5 billion crypto theft of February 21, 2025, which remains the largest recorded cryptocurrency hack.
  • A US federal judge issued a preliminary injunction freezing certain stolen assets held by unidentified individuals and entities listed as John Doe defendants, preventing them from transferring, selling, or otherwise disposing of the identified assets while the litigation continues.
  • The FBI attributed the attack to North Korean actors operating under the name TraderTraitor shortly after the breach, and Bybit CEO Ben Zhou said the exchange had worked with investigators, regulators, other trading platforms, and law enforcement agencies since the attack.
  • The traceability of stolen funds declined over time: 88.87 percent remained traceable in March 2025, but by April 2025, 27.6 percent could no longer be tracked after the attackers converted assets into Bitcoin and dispersed them across thousands of wallets using cross chain protocols and crypto mixers.
  • North Korean groups stole an estimated $2.02 billion in cryptocurrency during 2025 alone, with cumulative theft reaching approximately $6.75 billion, and Lazarus linked attacks allegedly drained another $577 million from Drift Protocol and KelpDAO in April 2026.

On August 7, 2026, Bybit announced it had filed a civil lawsuit in the US District Court for the District of Columbia against the Democratic People’s Republic of Korea, its Reconnaissance General Bureau intelligence agency, and the Lazarus Group. The complaint concerns the February 21, 2025, breach that drained more than 400,000 Ether and staked Ether from the Dubai based exchange, an incident valued at approximately $1.5 billion at the time and still the largest recorded cryptocurrency theft.

The filing is unusual in almost every dimension. A private company is suing a sovereign nation in a US court. The defendants include a state intelligence agency and a hacking group that operates under its direction. The stolen assets have been laundered across thousands of wallets, converted between blockchains, and run through mixing services designed to break the transaction trail. And yet a federal judge granted a preliminary injunction, meaning a court has already determined that there is enough evidence and legal basis to freeze identifiable stolen assets while the case proceeds.

Advertisement

The question is not whether the lawsuit is symbolically important. It clearly is. The question is whether it can produce a practical outcome: the recovery of stolen funds, the creation of legal precedent for future cases, or both. The case arrives at a moment when the crypto industry is searching for institutional tools to complement its technical defenses. Blockchain tracing, exchange cooperation, and bug bounties have been the primary recovery mechanisms after major hacks. A civil lawsuit backed by a federal court order introduces a legal instrument that has not been widely tested in the crypto context but has deep precedent in traditional asset recovery litigation.

What the lawsuit actually claims

The complaint names three defendants. The Democratic People’s Republic of Korea is named as a sovereign state that directed the theft through its intelligence apparatus. The Reconnaissance General Bureau, North Korea’s primary foreign intelligence organization, is named as the agency that oversaw the operation. The Lazarus Group is named as the threat actor that carried out the technical execution.

The case is filed under theories of civil liability that do not require the defendants to appear in court. Bybit is pursuing the claim through the legal mechanisms available against sovereign states and their agents when those states are accused of sponsoring acts that cause financial harm to private parties. The Foreign Sovereign Immunities Act typically shields foreign governments from lawsuits in US courts, but exceptions exist for state sponsored terrorism and certain commercial activities.

Alongside the complaint, Bybit secured a preliminary injunction targeting John Doe defendants, unidentified individuals and entities that hold assets traced to the theft. The injunction bars them from transferring, selling, or otherwise disposing of the identified assets. A preliminary injunction is not a final ruling. It preserves property during litigation. But securing one requires demonstrating to a judge that the plaintiff is likely to succeed on the merits and that the assets would be at risk of dissipation without the order.

Advertisement

Bybit CEO Ben Zhou framed the filing in terms that emphasized accountability over financial recovery. “Our focus has never changed: protect our users first, recover what we can, and make sure the people behind these attacks are held accountable,” Zhou said in a statement.

How the February 2025 hack unfolded

The breach occurred on February 21, 2025, when attackers compromised Bybit’s security infrastructure and drained more than 400,000 ETH and stETH from the exchange. The assets were valued at approximately $1.5 billion at the time, making it the single largest cryptocurrency theft ever recorded.

The FBI attributed the attack to North Korean actors within days. The bureau identified the perpetrators under the operational name TraderTraitor and urged exchanges, validators, and blockchain firms to block transactions connected to addresses identified in the laundering operation. The speed of the attribution was notable. US intelligence agencies had been tracking Lazarus Group operations for years, and the on chain signatures of the attack matched patterns from previous North Korean campaigns.

The attackers moved quickly to launder the stolen funds. Within the first week, a significant portion of the ETH was converted to Bitcoin through cross chain bridges. The Bitcoin was then dispersed across thousands of wallets in a pattern designed to overwhelm tracing tools. By March 2025, Bybit’s CEO reported that 88.87 percent of the stolen funds remained traceable, while 7.59 percent had gone dark through crypto mixers and 3.54 percent had been frozen.

Advertisement

The legal architecture of the complaint reflects a calculated strategy for navigating the unusual challenge of suing a sovereign nation and its intelligence apparatus. By filing in the District of Columbia, Bybit places the case in a jurisdiction where federal courts routinely handle matters involving foreign states and international sanctions. The FSIA exception for state sponsored terrorism is well established in this courthouse, with decades of precedent from cases against Iran, Syria, and Libya providing a roadmap for how plaintiffs can pursue claims against sovereign defendants who refuse to appear. The preliminary injunction freezing stolen assets demonstrates that the court is willing to exercise jurisdiction and issue enforceable orders even before the defendants respond, which in a case against North Korea may never happen.

The traceable share declined over the following months. By April 2025, Zhou disclosed that 27.6 percent of the stolen funds could no longer be tracked. The attackers used a combination of cross chain protocols, mixing services, and decentralized exchanges to obscure the trail. Each hop between chains and each pass through a mixer made the remaining funds harder to follow.

Bybit covered the immediate shortfall through ETH purchases, loans, and deposits from industry counterparties. The exchange continued processing customer withdrawals throughout the crisis, avoiding the liquidity collapse that has followed other major exchange hacks. The operational response was widely credited as one of the more effective post hack recoveries in the industry’s history.

The scale of the laundering operation reveals the sophistication of the North Korean apparatus. The attackers did not simply send the stolen ETH to a single mixer and wait. They ran a multi-stage pipeline. First, the ETH was swapped for other tokens through decentralized exchanges to break the direct link to the Bybit wallets. Then the tokens were bridged to other chains, primarily Bitcoin, through cross chain protocols. The Bitcoin was then split across thousands of newly created wallets in a pattern called “peel chain” laundering, where each wallet sends a small portion to a destination and forwards the remainder to the next wallet in the chain. Each stage added a layer of obfuscation, and the entire process was automated using scripts that executed faster than human analysts could follow in real time.

Advertisement

https://x.com/cryptodotnews/status/2086018579007217931

Why a civil lawsuit and why now

The timing of the filing raises an obvious question: why wait 18 months? The answer involves both legal strategy and the evolution of the available evidence.

Criminal investigations into the hack are ongoing. US law enforcement agencies, including the FBI, are pursuing their own cases against the North Korean actors. Bybit’s civil lawsuit is explicitly separate from those criminal proceedings. The exchange is not dependent on prosecutors’ timelines or priorities.

The laundering infrastructure that the Lazarus Group employed after the Bybit breach illustrates how state backed hackers have professionalized their operations to exploit the structural gaps in cryptocurrency compliance. Within hours of the theft, the stolen Ether moved through a cascade of intermediary wallets designed to break the chain of provenance. The funds then flowed through decentralized exchanges, cross chain bridges, and mixing services that do not perform know your customer checks. By the time law enforcement agencies began coordinating their response, a significant portion of the stolen assets had already been converted into bitcoin and routed through additional obfuscation layers. This rapid dispersal is a signature of North Korean crypto operations, refined through years of practice across multiple high profile thefts.

Advertisement

A civil lawsuit offers several advantages that criminal prosecution does not. First, the burden of proof is lower. Criminal cases require proof beyond a reasonable doubt. Civil cases require a preponderance of the evidence. Second, a civil plaintiff controls its own case. Bybit can pursue recovery on its own schedule rather than waiting for a criminal prosecution that may take years to culminate in a judgment.

Third, and most practically, a civil lawsuit with a preliminary injunction gives Bybit a legal instrument that exchanges and custodians must respect. When Bybit identifies stolen funds on a platform, it can now point to a court order rather than relying on voluntary cooperation. Exchanges that refuse to freeze assets covered by a federal court order face legal exposure of their own.

The 18 month gap also allowed the blockchain tracing to mature. The initial weeks after a major hack are chaotic. Funds move rapidly across chains and through mixers. Over time, some of that movement stops. Funds sit in wallets. They end up on exchanges where withdrawal requires interaction with regulated entities. The preliminary injunction targets those resting points, the wallets and accounts where traceable stolen funds currently sit.

Advertisement

Can you actually sue North Korea and collect

This is the question that makes the case unusual. Suing a sovereign nation in a foreign court is not standard practice, and collecting a judgment against a country that does not participate in the international financial system presents obvious challenges.

The legal framework for suing foreign governments in US courts is governed by the Foreign Sovereign Immunities Act. Under normal circumstances, foreign states are immune from suit in US courts. But exceptions exist. The terrorism exception, added after the 1996 amendments, allows claims against states designated as sponsors of terrorism. North Korea has been on the State Department’s state sponsor of terrorism list since 2017.

Whether the cryptocurrency theft qualifies under the terrorism exception is a legal question that the court will need to address. Previous cases under this exception have involved acts of physical violence, hostage taking, and material support for terrorist organizations. A cryptocurrency hack committed for financial gain rather than political violence may test the boundaries of the statute.

Even if Bybit obtains a default judgment (North Korea is unlikely to send lawyers to defend the case), collecting on that judgment against a state that operates outside the conventional financial system is a separate challenge. The practical value of the lawsuit lies not in extracting payment from Pyongyang but in the ancillary effects: the preliminary injunction that freezes assets, the legal precedent that future victims can cite, and the signal to exchanges and custodians that frozen assets have a court order behind them.

Advertisement

The John Doe component of the lawsuit is potentially more actionable. If the identities of individuals or entities holding the stolen funds are discovered during the litigation, they can be added to the case and subjected to enforcement actions. Unlike North Korea itself, individuals who hold stolen crypto and fail to comply with a federal court order face consequences that can be enforced.

https://x.com/cryptodotnews/status/2086347896077619470

The broader pattern of North Korean crypto theft

The Bybit hack was not an isolated incident. It was the largest single event in a sustained campaign of cryptocurrency theft that US intelligence agencies attribute to the North Korean state.

North Korean groups stole an estimated $2.02 billion in cryptocurrency during 2025, according to Chainalysis data. The Bybit attack accounted for most of that total. Cumulatively, North Korea linked groups have stolen approximately $6.75 billion in digital assets across multiple years of operations.

Advertisement

The threat continued into 2026. In April, Lazarus linked attacks allegedly drained $577 million from Drift Protocol and KelpDAO in two separate incidents. The attacks used different technical methods but shared the same operational playbook: identify a vulnerability in a DeFi protocol or exchange, exploit it rapidly, and move the stolen funds through a pre planned laundering chain that crosses multiple blockchains within hours.

The scale of the theft has geopolitical implications. US and South Korean intelligence agencies have assessed that North Korea channels crypto theft proceeds into its weapons programs, including nuclear and missile development. This assessment is one reason the FBI attributed the Bybit attack so quickly and why US authorities have been unusually active in coordinating with exchanges to freeze funds. The scale of the February 2025 breach, exceeding all prior incidents by a factor of three, forced the industry to confront the inadequacy of its existing response mechanisms and consider whether civil litigation might fill the enforcement gap that criminal prosecution has left open.

For the crypto industry, the North Korean threat has become a baseline security assumption rather than an exceptional risk. Exchanges, DeFi protocols, and bridge operators now design their security models with state sponsored attackers as a primary threat scenario. The Bybit lawsuit adds a legal dimension to what has primarily been a technical and operational response.

The pattern of North Korean attacks also reveals a preference for targeting infrastructure points where large amounts of value are concentrated in a single signing operation. The Bybit attack compromised the process by which the exchange moved funds between cold and warm wallets. The Ronin bridge attack targeted the validator set that controlled cross chain transfers. In both cases, the attackers identified the moment when a single compromised action could move the maximum amount of value. This targeting pattern has forced exchanges to rethink how they structure high value transactions, adding multi party computation, hardware security modules, and time delayed execution to what were previously routine operations.

Advertisement

https://x.com/cryptodotnews/status/2045015901854921186

What the case means for future hack recoveries

The Bybit lawsuit could create a template for how exchanges and other victims pursue stolen funds through civil courts. Previous major hacks, including the Ronin bridge theft in 2022 and the Wormhole exploit in the same year, relied primarily on law enforcement cooperation, voluntary freezes by industry participants, and bounty programs.

A civil lawsuit with a preliminary injunction adds a layer that voluntary cooperation cannot provide: compulsion. When a court orders assets frozen, the custodian holding them has a legal obligation to comply. The order converts a request into a requirement, and non compliance carries legal consequences.

The dual track approach, civil and criminal running simultaneously, also matters. Criminal cases move on prosecutors’ timelines and serve public enforcement objectives. Civil cases move on the plaintiff’s timeline and serve the plaintiff’s recovery objectives. When both tracks operate in parallel, the stolen funds face pressure from multiple legal directions.

Advertisement

For smaller victims who lack Bybit’s resources, the precedent matters more than the specific case. If the lawsuit succeeds in freezing and eventually recovering stolen assets, it creates a roadmap that other victims can follow. If it produces published court opinions on the jurisdictional and immunity questions, those opinions become tools that future plaintiffs can use to streamline their own cases.

The case also tests the crypto industry’s willingness to cooperate with civil court orders. Exchanges that receive freeze requests backed by a federal court injunction face a different calculus than exchanges that receive informal requests from a hack victim. The legal formalization of the recovery process could accelerate compliance across the exchange ecosystem.

There is also a deterrence argument, though its force against a state actor is debatable. Most criminal hackers weigh the expected profit against the expected penalty. For a state intelligence agency that channels theft proceeds into weapons programs, the calculus is different. But the lawsuit creates costs at the laundering stage. Every exchange that freezes assets in response to the court order reduces the amount that reaches its intended destination. If the civil lawsuit makes laundering 5 or 10 percent harder, that translates to hundreds of millions of dollars in stolen value that cannot be converted to cash. Over multiple operations, incremental friction at the laundering stage compounds into a meaningful reduction in the program’s effectiveness.

What to watch

Compliance with the preliminary injunction. The order is only as effective as the willingness of custodians and exchanges to enforce it. Watch for reports of exchanges freezing funds in response to the order, or for disputes where custodians challenge the scope of the injunction.

Advertisement

Additional defendants added to the case. The John Doe structure allows Bybit to add identified individuals and entities as discovery progresses. If blockchain tracing leads to specific custodians, exchanges, or OTC desks that processed stolen funds, they could become parties to the lawsuit.

North Korea’s response or non response. Sovereign defendants in US courts typically either invoke immunity and challenge jurisdiction or simply ignore the proceedings. North Korea’s approach will determine whether the case proceeds by default judgment or through contested litigation on the jurisdictional questions.

Recovery rate compared to criminal track. Bybit has been working with law enforcement since February 2025. The civil lawsuit now runs in parallel. Comparing the amounts recovered through each track will indicate whether civil litigation adds meaningful recovery capacity beyond what criminal enforcement achieves alone.

Follow on lawsuits from other hack victims. If the Bybit case survives jurisdictional challenges and produces asset recovery, other victims of state sponsored hacks may file similar civil complaints. Watch for cases from victims of the Drift Protocol and KelpDAO attacks, which are also attributed to Lazarus Group.

Advertisement

International coordination on asset freezing. The US court order applies to entities within US jurisdiction, but stolen crypto moves globally. Watch for parallel legal actions in jurisdictions like Singapore, the UK, and the EU, where exchanges and custodians may hold portions of the laundered funds. A coordinated multi-jurisdictional freeze would be significantly more effective than a single country order.

North Korean adaptation to the legal pressure. State sponsored hacking groups adapt their laundering techniques in response to enforcement actions. If the civil lawsuit makes conventional exchange-based laundering more difficult, the attackers may shift to peer-to-peer trading, decentralized exchanges without KYC, or privacy chains. The speed and nature of this adaptation will indicate how much friction the legal approach creates.

Frequently asked questions

u003cstrongu003eWhat is Bybit suing North Korea for?u003c/strongu003e

u003cpu003eBybit filed a civil lawsuit alleging that North Korea, through its Reconnaissance General Bureau intelligence agency and the Lazarus Group, stole approximately $1.5 billion in Ether and staked Ether from the exchange on February 21, 2025. The case was filed in the US District Court for the District of Columbia.u003c/pu003e

Advertisement

u003cstrongu003eHas a court already taken action?u003c/strongu003e

u003cpu003eYes. A US federal judge issued a preliminary injunction freezing certain stolen assets held by unidentified individuals and entities listed as John Doe defendants. The order prevents them from transferring or selling the identified assets while the case proceeds.u003c/pu003e

u003cstrongu003eHow much of the stolen funds has been recovered?u003c/strongu003e

u003cpu003eBybit has not disclosed a specific recovery figure. As of April 2025, 27.6 percent of the stolen funds could no longer be tracked. The remaining traceable portion is subject to ongoing recovery efforts through blockchain tracing, industry cooperation, and now the civil lawsuit.u003c/pu003e

u003cstrongu003eCan a private company actually sue a foreign country?u003c/strongu003e

u003cpu003eUnder the Foreign Sovereign Immunities Act, foreign states are generally immune from suit in US courts. However, exceptions exist for states designated as sponsors of terrorism. North Korea has been on the State Department’s state sponsor of terrorism list since 2017. Whether the cryptocurrency theft qualifies under the terrorism exception is a legal question the court will address.u003c/pu003e

u003cstrongu003eIs this lawsuit separate from the FBI investigation?u003c/strongu003e

u003cpu003eYes. Bybit explicitly stated that the civil lawsuit is being pursued independently of ongoing criminal investigations by US law enforcement agencies. The two tracks operate in parallel, each with different procedural rules, burdens of proof, and objectives.u003c/pu003e

Advertisement

u003cstrongu003eWhy did Bybit wait 18 months to file?u003c/strongu003e

u003cpu003eThe timing allowed blockchain tracing to mature, identifying where stolen funds currently sit. It also allowed Bybit to build a factual record sufficient for a preliminary injunction. Filing too early would have risked a weaker case with fewer identifiable assets to freeze.u003c/pu003e

u003cstrongu003eWhat happens if North Korea ignores the lawsuit?u003c/strongu003e

u003cpu003eIf North Korea does not respond, Bybit can seek a default judgment, a court ruling in its favor based on the defendant’s failure to appear. Default judgments against sovereign states are enforceable against the state’s assets within US jurisdiction, though North Korea holds minimal assets subject to US courts.u003c/pu003e

u003cstrongu003eCould other hack victims file similar lawsuits?u003c/strongu003e

u003cpu003eYes. The Bybit case could create a template for civil recovery actions by other victims of state sponsored cryptocurrency theft. If the case produces favorable court opinions on jurisdiction and immunity, those opinions become precedent that future plaintiffs can cite. This is educational analysis, not investment advice.u003c/pu003eu003cpu003eu003cemu003eDisclaimer: This article is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency markets carry significant risk. Always conduct independent research before making investment decisions. Information is current as of August 8, 2026.u003c/emu003eu003c/pu003e

Source link

Advertisement
Continue Reading

Crypto World

The Korean Crypto Laundering Method Behind $6.4 Billion, and Why Police Struggle to Stop It

Published

on

Panic Hits Japan and South Korea Markets: Can Crypto Become the Big Winner?

A single cross-border laundering method has quietly become the backbone of South Korea’s crypto crime wave, accounting for $6.4 billion of the $7.1 billion in illegal crypto transactions recorded in the country since 2021. And despite knowing exactly how it works, police are struggling to stop it.

The technique is called Hwanchigi. It exploits cryptocurrency transfers to move illicit money offshore without touching South Korea’s regulated banking system, making it fast, borderless, and difficult to prosecute. A Crystal Intelligence report tied the method to the vast majority of illegal crypto flows in the country between 2021 and August 2025, and new police data suggests its use is accelerating sharply.

The Numbers Behind the Surge in Korea

National Police Agency figures show money laundering cases involving virtual assets hit 1,214 in the first half of 2026 alone, up from just eight cases in all of 2025. That 152-fold jump pushed money laundering to 79.4% of all crypto offenses detected in H1 2026, displacing investment fraud, which had accounted for 92% of crypto crime through last year.

South Korea’s crackdown on illegal crypto transactions has intensified in recent years, but the case data shows criminal networks are scaling faster than enforcement.

Advertisement

The preferred vehicle is Tether (USDT). Stablecoins now dominate illicit crypto flows globally, and South Korea’s criminals use them to convert drug trafficking proceeds, gambling revenue, and phishing profits into dollars before routing funds through overseas exchanges beyond domestic jurisdiction.

Detection Without Consequence

The enforcement gap is stark. Police made only 18 arrests for crypto money laundering in H1 2026, compared to 42 in 2023, despite detecting nearly 100 times more cases.

The pattern repeats across recent high-profile operations: in June 2026, Seoul Metro Police charged 23 individuals over a laundering network tied to a Cambodia-based phishing group and confiscated $431,000 in proceeds, but the alleged ringleader remains at large under an Interpol Red Notice.

Advertisement

In July 2026, investigators traced and froze $12 million in XRP and Tether after a fake Flare Network staking site drained $8.6 million from 71 investors, but arrests lagged the asset freezes.

The Korea Customs Service seized 7.2 trillion won ($4.92 billion) in illegal foreign exchange transactions in H1 2026, including export companies that accepted crypto to bypass repatriation rules. Over 90% of the 9.5 trillion won in crypto-linked crime referred for prosecution ran through unlicensed channels, not regulated banks.

South Korea can map the money. Following it to a courtroom is a different problem entirely.

The post The Korean Crypto Laundering Method Behind $6.4 Billion, and Why Police Struggle to Stop It appeared first on BeInCrypto.

Advertisement

Source link

Continue Reading

Trending

Copyright © 2025