Crypto World
NUSD supply falls 76% from February level
NUSD supply has fallen by about 76% from the $226 million level documented in February to $53.6 million as issuer Neutrl has suspended redemptions while assessing an undisclosed issue affecting its reserves.
Summary
- NUSD supply has fallen from about $226 million in February to $53.6 million.
- Neutrl has suspended NUSD minting and redemptions while assessing an undisclosed reserve issue.
- NUSD supply dropped 18.4% over the past 30 days, while transfer volume fell 72.4%.
- BA Labs previously flagged counterparty, operational and liquidity risks tied to Neutrl.
Neutrl said Thursday that unspecified circumstances had affected protocol reserves, prompting it to pause NUSD minting and redemptions as well as other functions on legal advice. The protocol has not identified the affected asset or counterparty, disclosed whether the event caused a realized loss, or provided a timeline for restarting operations.
The current $53.6 million supply compares with approximately $226 million recorded by risk-advisory team BA Labs during an assessment in February. RWA.xyz data also showed that NUSD supply fell 18.4% over the latest 30-day period, although neither dataset establishes that the contraction resulted from the reserve issue disclosed this week.
NUSD remained close to its intended dollar value despite the suspension. RWA.xyz priced the synthetic dollar at about $0.9984 on Friday, while monthly transfer volume had fallen 72.4% to $71.4 million.
NUSD redemptions stop with $53.6 million still in circulation
The suspension prevents approved counterparties from exchanging NUSD for its backing assets while Neutrl determines the condition of its reserves.
Neutrl said it would disclose timing and next steps when more information becomes available. Until then, minting and redemption functions remain unavailable alongside other protocol operations paused following legal advice.
NUSD uses yield-bearing crypto assets and market-neutral strategies to maintain its dollar value. The structure differs from stablecoins backed primarily by cash and short-term government securities because reserve assets can be distributed across custodians, trading venues and investment strategies.
RWA.xyz recorded 615 NUSD holders and 347 active addresses over the preceding 30 days.
Structured-yield protocol Strata also responded to Neutrl’s decision by pausing minting, redemptions and related functions for contracts in its Neutrl market. Several NUSD-linked products operate through the market, while Strata said its other markets remained operational.
Similar redemption and liquidity questions surfaced elsewhere in DeFi in June after MainStreet-linked MSUSD fell sharply below its intended dollar value. As crypto.news reported on MSUSD, Accountable terminated its verification agreement with MainStreet after saying the protocol was unable to meet its standards. MainStreet maintained that its assets remained fully backed and said the problem involved the shutdown of its third-party proof-of-reserves dashboard.
MSUSD traded at about $0.3781 at the time, while PeckShield said the Morpho msY/USDC market reached 100% utilization. MainStreet subsequently deployed more than $8 million in USDC to support liquidity and said it was seeking another proof-of-reserves provider.
February review put NUSD reserves at $233.7 million
Months before the current suspension, BA Labs had examined Neutrl’s reserve structure as part of a proposed integration and classified it as higher risk due to counterparty, operational and liquidity exposure.
Its February assessment estimated NUSD supply at $226 million against $233.7 million in reserves, equivalent to a collateralization ratio of about 103.6%.
More than 87% of those reserves were held through Fireblocks, according to BA Labs, while smaller amounts were maintained on centralized exchanges.
The assessment also examined how users could exit NUSD. Direct redemptions were restricted to KYC or KYB-approved counterparties, meaning ordinary token holders did not necessarily have direct access to Neutrl’s redemption mechanism.
When redemption requests exceeded the protocol’s liquid buffer, BA Labs said they could enter a queue. Neutrl targeted completion of those requests within 48 hours, but the timeframe was not guaranteed.
The distinction between total reserve value and immediately available liquidity has also surfaced in other yield products. In June, Altura began winding down its stablecoin yield vault after processing more than 8.5 million USDT in instant redemptions within 24 hours.
Altura CEO Ranveer Arora said the protocol had no exposure to MainStreet or its underlying strategies. Some assets in Altura’s portfolio nevertheless required normal settlement or redemption periods, leaving the protocol to return funds as capital became available from the underlying positions.
Reserve verification was active months before the pause
Neutrl’s reserve structure had also been subject to external verification before this week’s suspension.
On May 25, Accountable said its Neutrl dashboard provided continuous cryptographic proof that reserves backing NUSD matched the protocol’s liabilities. Neutrl has not said whether its latest reserve issue was identified through that system or through another review.
The protocol also has not disclosed where the affected reserves were held. Its statement did not specify whether the circumstances involved assets under custody, funds held on an exchange, a trading position or exposure to another counterparty.
Proof-of-reserves systems can establish information about assets against reported liabilities but do not necessarily capture every off-chain obligation or guarantee solvency. A June proof-of-reserves explainer detailed how cryptographic attestations can verify holdings while leaving limitations around liabilities, ownership and off-chain obligations.
Synthetic-dollar issuer Ethena has also used outside attestors for its reserve reporting. Chainlink, Harris & Trotter, Chaos Labs and LlamaRisk joined USDe reserve verification in April 2025, with Chainlink sourcing reserve information from custodians, exchanges and blockchain data.
NUSD contracts as stablecoin supply has also declined
NUSD’s reduction has taken place during a period of declining supply across the stablecoin market, although the available data does not connect the two developments.
Total stablecoin supply had fallen about $10 billion from its May record by July, including a $7.7 billion decline during June to approximately $312 billion. The June reduction was the largest monthly drop in dollar terms since the TerraUSD collapse in May 2022.
USDT accounted for roughly $6 billion of the decline from its May level, while USDC had fallen almost $7 billion from its March peak. The overall stablecoin market remained much larger than during previous contraction periods, with the June reduction equal to about 2.4% of supply.
Transaction activity did not decline at the same rate. Adjusted stablecoin transfer volume reached a record $1.78 trillion in June, including about $1.21 trillion processed through USDC and $573 billion through USDT.
For NUSD specifically, RWA.xyz recorded a much steeper decline in activity over the latest month, with transfer volume down 72.4% to $71.4 million as supply fell 18.4% to its current $53.6 million level.
Crypto World
Ripple’s Sherlock audit found 96 bugs before they reached a single wallet
A $550,000 community audit contest uncovered two critical vulnerabilities in XRP Ledger features that could have drained user accounts without private keys. The findings reveal how Ripple’s audit-before-release model diverges sharply from the broader crypto industry’s patch-after-exploit norm.
Summary
- Sherlock’s two-week audit contest, which opened on April 13, 2026, uncovered 96 valid vulnerabilities across five proposed XRP Ledger amendments, including 2 critical and 6 high-severity bugs, before any of them reached mainnet.
- Ripple paid $309,000 in RLUSD bounties from a $550,000 prize pool, marking the first collaboration between Sherlock and Ripple and one of the largest audit contests of 2026.
- The most severe finding was a signature-validation flaw in the Batch amendment that would have allowed attackers to execute transactions from any account without holding its private keys, first identified on February 19, 2026, by researcher Pranamya Keshkamat and Cantina’s AI tool Apex.
- A separate critical bug in Permission Delegation allowed malicious actors to silently drain XRP balances through repeated fee charges on invalid delegated transactions, because the code checked permissions before verifying signatures.
- DeFi exploits exceeded $840 million across more than 50 incidents in the first five months of 2026 alone, a 70% year-over-year increase, and 70% of exploited contracts had been audited but lacked post-deployment monitoring.
XRP Ledger version 3.3.0 shipped on August 6, 2026, carrying five proposed amendments and a bundled cleanup patch. On paper it looked like a routine infrastructure release. Underneath, the update represented the conclusion of a six-month security gauntlet that caught two account-draining bugs, rewrote two entire feature implementations from scratch, and paid hundreds of thousands of dollars to outside researchers who found problems the internal team had missed. The process raises a pointed question for the wider blockchain industry: if Ripple can catch critical flaws before deployment, why does so much of crypto still treat security audits as a post-launch checkbox?
This piece breaks down what the two critical vulnerabilities actually were at a technical level, examines how the audit-vote-activate pipeline compares to competing chains’ security models, and assesses whether the findings strengthen or undermine the case for XRPL as institutional-grade infrastructure.
What the Sherlock contest actually found
The scope covered five pillars of upcoming XRPL functionality: Batch Transactions, Permission Delegation, Multi-Purpose Token (MPT) DEX integration, Confidential Transfers for MPTs, and Sponsored Fees and Reserves. Sherlock, a Web3 security firm that ranks researchers by performance and structures engagements as adversarial contests, opened the audit on April 13, 2026, with a $550,000 RLUSD prize pool. The contest page on Sherlock’s platform listed the engagement as “XRP Ledger – April 2026 Contest – 550,000 RLUSD,” signaling that Ripple paid the bounties in its own stablecoin.
Over two weeks, participants submitted reports that surfaced 96 valid findings: 2 critical, 6 high, 29 medium, and 59 low-severity issues. Ripple distributed $309,000 in RLUSD to contributors. The remaining pool covered Sherlock’s operational costs and lower-tier findings that did not meet the payout threshold.
The contest marked the first formal collaboration between Sherlock and Ripple, and it arrived at a moment when the XRP Ledger’s feature pipeline was expanding faster than at any point in its history. Five amendments shipping simultaneously meant five distinct attack surfaces, each with its own transaction logic, authorization model, and cryptographic requirements. For context, Sherlock’s audit contest model has previously been used by protocols including Aave, Euler, and Olympus DAO, but an engagement covering C++ protocol-level code for a layer-one blockchain was atypical for a platform more commonly associated with Solidity smart contracts.
The severity distribution itself tells a story. The 29 medium-severity findings suggest a category of bugs that would not individually compromise accounts but could create unexpected behavior under specific transaction sequences. The 59 low-severity issues likely include code quality concerns, documentation gaps, and edge cases that could compound under adversarial conditions. The two critical and six high-severity bugs, however, represented exploitable vulnerabilities that warranted immediate remediation.
The Batch amendment bug that could have emptied accounts
The most dangerous vulnerability predated the Sherlock contest by two months. On February 19, 2026, security researcher Pranamya Keshkamat and Cantina’s autonomous AI audit tool Apex independently identified a signature-validation flaw in the original Batch amendment while it was still in its validator voting phase.
The technical failure was precise. Batch Transactions allow up to eight operations to execute atomically under a single outer transaction. The outer transaction’s signature-validation code contained an early-exit condition that could be satisfied without properly verifying who was authorizing the inner transactions. In practice, an attacker could have constructed a Batch transaction containing inner Payment operations targeting a victim account, draining it down to its reserve balance, without ever holding that account’s private keys. The same logic gap would have permitted unauthorized AccountSet, TrustSet, or AccountDelete operations.
The vulnerability disclosure report published on xrpl.org detailed the mechanics: the signer check in the outer transaction could pass without confirming that the entity submitting the batch actually controlled the accounts referenced in the inner transactions. This meant that the atomicity feature designed to improve user experience could have been weaponized to empty any account on the network in a single transaction.
RippleX responded with an emergency release. Rippled version 3.1.1, published on February 23, 2026, four days after discovery, marked both the original Batch amendment and its companion fixBatchInnerSigs as unsupported, preventing validators from voting on or activating them. No funds were lost because the amendment had not yet cleared the 80% validator threshold required for activation. The replacement, BatchV1_1, shipped in version 3.3.0 with the early-exit condition removed, additional authorization guards added, and the signing check scope tightened to verify each inner transaction against the correct signer independently.
Permission Delegation’s silent fee-drain exploit
The second critical vulnerability operated through a subtler mechanism. A September 2025 disclosure documented how the original Permission Delegation implementation allowed an attacker to silently bleed a victim account’s XRP balance without accessing its keys.
The exploit relied on a design feature of the XRP Ledger’s transaction processing that has existed since the network’s earliest days. On XRPL, a transaction that fails with a “tec”-class error still incurs a fee charge, while errors caught earlier in the pipeline, before signature verification, do not. This distinction exists because tec-class failures indicate transactions that were properly formed and signed but failed for business-logic reasons, and the fee prevents spam. Permission Delegation’s original code checked whether a delegate account held the relevant permission before it verified the transaction’s signature. An attacker could repeatedly submit invalid offline-signed transactions with elevated fees against a delegated account, and each failed transaction would still deduct the fee from the victim’s balance.
The economic impact would have compounded quickly. Because the attacker could set arbitrarily high fees on these transactions, a sustained attack could drain an account far faster than normal transaction fees would suggest. The victim would see their balance declining with no corresponding outbound payments, making the attack difficult to diagnose without examining raw transaction metadata.
The fix reclassified the relevant error from tec to ter and reordered the checks so that no fee can be deducted before signature verification passes. The replacement amendment, PermissionDelegationV1_1, carries a default “No” designation in the 3.3.0 registry, meaning validators must actively vote to enable it. This conservative default reflects the sensitivity of the original flaw: even after the rewrite, Ripple chose to require explicit validator opt-in for the feature.
Why both rewrites shipped in a single release
Packaging two security-rewritten amendments alongside three entirely new features in one version was a deliberate choice. RippleX published xrpld 3.3.0 on August 6, 2026, with the code for all six proposals (including a bundled cleanup amendment called fixCleanup3_3_0) present but none of them activated. Under the XRP Ledger’s amendment process, each proposal must sustain more than 80% validator support for two consecutive weeks before going live.
This separation between code availability and feature activation is a structural advantage that most smart-contract platforms lack. On Ethereum, a deployed contract is live the moment it hits the blockchain. On XRPL, code can ship, undergo further review during the voting window, and still be blocked if validators lose confidence. The Batch and Permission Delegation rewrites had already survived the Sherlock contest, a Halborn re-audit that found zero critical or high-risk issues, and months of internal testing. The voting period adds yet another layer of defense before any code touches real funds.
The version also retired five legacy amendments, including Clawback, fixDisallowIncomingV1, fixInnerObjTemplate, fixNFTokenReserve, and fixUniversalNumber, removing dead code paths that could otherwise accumulate as latent attack surface over time.
The five feature amendments in 3.3.0 represent the broadest single expansion of XRPL capabilities to date. Confidential Transfers bring EC-ElGamal encryption and zero-knowledge proofs to Multi-Purpose Tokens, shielding individual balances and transfer amounts from public view while preserving compliance access for authorized parties. Sponsored Fees allow applications to cover network costs on behalf of users, addressing the onboarding friction that has kept consumer-facing applications off decentralized networks. DynamicMPT lets issuers modify token properties after creation, supporting evolving regulatory and business requirements. Together with the Batch and Permission Delegation rewrites, these features target a specific audience: regulated financial institutions that need privacy, atomic settlement, and delegated operations without sacrificing auditability.
Audit before release versus patch after exploit
The contrast between Ripple’s approach and the broader industry’s security track record is stark. DeFi exploits exceeded $840 million across more than 50 incidents in the first five months of 2026, a 70% year-over-year increase over the same period in 2025. North Korea-linked actors accounted for 76% of global crypto hack losses in the first four months of the year. And the most damning statistic: 70% of exploited contracts had been audited but lacked any form of post-deployment monitoring. Only 4% of tracked projects combined audits, active bug bounties, and third-party monitoring controls together.
The Ethereum ecosystem, home to the largest concentration of smart-contract value, operates under a fundamentally different security model. Contracts deploy to mainnet through an immutable transaction. If a vulnerability surfaces afterward, the options are limited: deploy a new contract and migrate users, implement a proxy upgrade pattern that introduces its own attack surface, or accept the risk. The Wormhole bridge hack of 2022 cost $320 million because a deprecated verification function remained in production code. Ronin’s August 2024 exploit cost $12 million because a contract upgrade failed to initialize operator weights correctly. In both cases, audits had been performed; the failures happened after deployment.
The KelpDAO hack on April 18, 2026, which drained approximately $293 million, was the largest single DeFi exploit of the year. The Drift Protocol exploit on Solana on April 1, which cost roughly $286 million, was the largest ever recorded on that chain. These figures are not fringe events. They represent the baseline failure rate of an industry that has collectively lost $16.69 billion to hacks, bridge exploits, and security incidents according to DeFiLlama data.
XRPL’s amendment voting process inverts this sequence. Code ships in a release, but features remain dormant until validators approve them. During the voting window, researchers, node operators, and competing auditors can examine the live codebase with full context. If a problem surfaces, validators simply withhold their votes. No emergency patch, no migration, no proxy contract. The February 2026 Batch bug followed exactly this path: the amendment was in its voting phase, the vulnerability was identified, and an emergency release prevented activation. Zero funds at risk, zero user impact.
This is not to say that the XRPL model is flawless. The amendment process works for protocol-level features but does not extend to applications built on top of the ledger. A poorly coded trust line or MPT integration could still lose funds. And the 80% validator threshold creates its own risks: if too few validators upgrade to a new version, legitimate security patches can stall. But for core protocol changes, the audit-vote-activate pipeline represents a materially different security posture than deploy-and-hope.
What this means for XRPL’s institutional pitch
Ripple has spent 2026 building an institutional infrastructure stack at an aggressive pace. The $1.25 billion acquisition of Hidden Road, a multi-asset prime broker rebranded as Ripple Prime, gave the company a regulated on-ramp for traditional finance. RLUSD reached a $1.72 billion market capitalization in under a year and moved more than $18 billion in transaction volume during Q1 alone. Goldman Sachs disclosed a $153.8 million position across four XRP ETFs. Ripple secured a full Electronic Money Institution license from Luxembourg in February, UK Financial Conduct Authority permissions in January, and a MiCA Crypto-Asset Service Provider license on July 6.
The institutional DeFi features arriving in version 3.3.0 are the technical counterpart to this business development push. Confidential Transfers address the privacy requirements of banks that cannot expose transaction details on a public ledger. Sponsored Fees solve the onboarding friction that has kept retail banking applications off decentralized networks. Permission Delegation, once its rewrite clears the voting process, enables the kind of controlled access models that compliance departments require.
But institutional adoption depends on trust, and trust in blockchain infrastructure ultimately comes down to security track record. The fact that Ripple caught two critical bugs, rewrote two entire feature implementations, paid outside researchers $309,000 to find problems, and still delivered all five features on schedule is a stronger institutional selling point than any individual feature. It suggests a security culture where finding bugs is rewarded and where shipping is subordinate to verification.
Over 300 financial institutions across 55 countries currently use RippleNet, with active On-Demand Liquidity corridors in more than 70 markets. For those institutions, the Sherlock audit results are not abstract. They are evidence that the code running their cross-border payments has been stress-tested by adversarial researchers with financial incentives to break it. Ripple’s four-phase quantum-resistance roadmap, targeting completion by 2028, further signals that the company is engineering for institutional time horizons measured in decades, not deployment cycles.
The opposing case: why skeptics are not convinced
The strongest argument against reading too much into the Sherlock audit runs in two directions.
First, finding 96 bugs before release can be framed as evidence of thorough testing or evidence of sloppy development. Both the Batch and Permission Delegation vulnerabilities were in the original implementations, meaning they cleared internal review before external researchers caught them. The February 2026 Batch bug was not identified by Ripple’s own team but by an independent researcher and an AI tool. If external auditors are the primary safety net, the internal development process may have quality gaps that will eventually produce a vulnerability that no external reviewer catches in time.
Second, the XRPL amendment model’s strength, the ability to prevent activation during the voting window, is also a speed constraint. Ethereum’s willingness to deploy and iterate has enabled a pace of innovation that XRPL cannot match. The five amendments in version 3.3.0 have been in development and review cycles for months. The original Batch amendment was proposed in 2025. For protocols competing for developer attention in fast-moving markets, a six-month security pipeline may be too slow to attract the builder ecosystem that drives network effects.
There is also a concentration risk in the validator set. The 80% activation threshold means that a relatively small number of validators, many of which are operated by entities with close ties to Ripple, control whether amendments go live. Critics argue this is not truly decentralized governance but a curated approval process dressed in consensus language. When Ripple’s own validator voted “yes” on lending amendments in recent weeks, it underscored how much influence the company retains over its nominally decentralized network.
Finally, the $309,000 payout from a $550,000 pool raises a practical question about incentive alignment. Top-tier security researchers command rates that exceed what contest models typically pay per hour of effort. If the most skilled auditors skip XRPL contests because the expected payout per finding is lower than private engagements, the adversarial review may be broad but not deep enough to catch the most sophisticated attack vectors.
These objections have weight. XRP traded near $1.03 in late July 2026, roughly 71% below its $3.65 cycle high set on July 17, 2025, suggesting the market has not yet priced in the institutional narrative. Whether the security track record translates into adoption depends on factors beyond code quality: regulatory clarity, competitive positioning against Ethereum layer-2 solutions, and whether institutions care more about pre-deployment audits than they do about ecosystem size.
What to watch
Validator voting thresholds for the five 3.3.0 amendments: if BatchV1_1 and PermissionDelegationV1_1 clear 80% support within the first voting cycle, it signals validator confidence in the rewrites. A stall would suggest lingering concerns about the rewritten code.
Post-activation bug reports: the real test of the Sherlock audit’s thoroughness comes after features go live. Zero critical findings in the first 90 days would validate the pre-release model; any post-activation vulnerability would undermine the entire thesis.
RLUSD adoption on Confidential Transfers: institutional stablecoin usage on shielded rails would confirm demand for privacy-compliant settlement. Volume metrics in the first quarter after activation will be the clearest signal of whether banks are ready to transact on a public ledger with privacy guarantees.
Sherlock’s next XRPL engagement: whether Ripple continues with adversarial audit contests for future amendments or reverts to traditional private audits will indicate how deeply the pre-release model is embedded in the development culture.
Competing chain security incidents: every major exploit on Ethereum or Solana that traces back to a post-deployment vulnerability strengthens the case for XRPL’s audit-vote-activate pipeline. The comparison is only as strong as the industry’s continued failure to adopt similar processes.
What did the Sherlock audit of XRP Ledger find?
The two-week audit contest, which opened on April 13, 2026, uncovered 96 valid vulnerabilities across five proposed XRPL amendments: 2 critical, 6 high, 29 medium, and 59 low-severity issues. Ripple paid $309,000 in RLUSD bounties from a $550,000 prize pool. All findings were addressed before any of the affected features activated on mainnet.
What was the critical Batch amendment bug?
The original Batch amendment contained a signature-validation flaw that allowed an attacker to execute inner transactions from any account without holding its private keys. The bug was an early-exit condition in the outer transaction’s signing check that could be satisfied without proper authorization verification. Researcher Pranamya Keshkamat and Cantina’s AI tool Apex identified it on February 19, 2026. RippleX patched it in emergency release version 3.1.1 four days later.
How did the Permission Delegation vulnerability work?
The original implementation checked delegate permissions before verifying transaction signatures. On XRPL, transactions that fail with “tec”-class errors still incur fees. An attacker could repeatedly submit invalid transactions with elevated fees against a delegated account, draining its XRP balance without ever holding its keys. The fix reclassified the error type and reordered the verification checks.
Were any funds lost from these vulnerabilities?
No funds were lost. Both critical vulnerabilities were identified before their respective amendments activated on mainnet. The Batch bug was caught during the validator voting phase, and the Permission Delegation flaw was disclosed and patched before activation. The XRP Ledger’s amendment process, which requires 80% validator support for two consecutive weeks, provided a structural buffer that prevented exploitation.
What is Sherlock and how does its audit model work?
Sherlock is a Web3 security firm that structures audits as adversarial contests, ranking researchers by performance and offering financial incentives through prize pools. The XRP Ledger engagement was Sherlock’s first collaboration with Ripple and one of the largest audit contests of 2026. The model differs from traditional private audits by inviting broad participation from independent security researchers competing for bounties, which surfaces a wider range of attack vectors than a small internal team can cover.
How does XRPL’s security model differ from Ethereum’s?
XRPL’s amendment process separates code deployment from feature activation. New features ship in a software release but remain dormant until validators vote to activate them, creating a review window where vulnerabilities can be caught without emergency patches. Ethereum’s smart contracts are live upon deployment, and fixing vulnerabilities requires deploying new contracts, migrating users, or implementing proxy upgrades. In the first five months of 2026, DeFi exploits exceeded $840 million, and 70% of exploited contracts had been audited but lacked post-deployment monitoring.
What features does XRP Ledger version 3.3.0 include?
Version 3.3.0, released on August 6, 2026, contains code for five feature amendments and a cleanup patch. The features include Confidential Transfers for Multi-Purpose Tokens using zero-knowledge proofs, rewritten Batch Transactions for atomic multi-operation settlement, rewritten Permission Delegation for controlled account access, Sponsored Fees allowing applications to cover user costs, and DynamicMPT enabling issuers to modify token properties after creation.
Does this audit make XRPL a safe investment?
The Sherlock audit reflects a rigorous pre-release security process, but code quality is one factor among many that influence investment outcomes. XRP traded near $1.03 in late July 2026, roughly 71% below its cycle high, and market performance depends on regulatory developments, institutional adoption rates, competitive dynamics, and macroeconomic conditions. This is educational analysis, not investment advice. **Disclaimer**: This article was published on August 14, 2026. It is intended for educational and informational purposes only and should not be construed as financial, investment, or legal advice. Cryptocurrency markets are volatile and carry substantial risk. Readers should conduct their own research and consult qualified professionals before making any investment decisions.
Crypto World
Trump’s World Liberty Financial delayed its Maldives resort token because of a war
The Iran conflict grounded flights, cratered Maldives tourism arrivals by double digits, and forced the Trump family’s crypto venture to shelve what was billed as the world’s first tokenized luxury hotel development. The episode exposes a structural question the real-world asset market has avoided: what happens to a token when the real world breaks?
Summary
- World Liberty Financial and its partners postponed the MALD1 token sale, originally planned for spring 2026, after the Iran conflict disrupted air corridors serving the Maldives and cut tourist arrivals by as much as 41% in early March.
- The token, structured through BlackRock-backed Securitize, would have given accredited investors a fixed yield plus a share of loan revenue from Trump International Hotel and Resort, Maldives, a 100-villa project developed by UK-listed Dar Global with a 2030 completion target.
- WLFI has raised $550 million through governance token sales from more than 85,000 buyers, but the token has lost roughly 83% of its value from its September 2025 peak of $0.331, falling to approximately $0.055 by late July 2026.
- The broader tokenized real-world asset market excluding stablecoins has grown to between $26 billion and $34 billion in 2026, yet tokenized real estate remains the segment with the slowest institutional adoption and the thinnest secondary trading.
- Dar Global CEO Ziad El Chaar said the company “continues to review development and launch schedules for its global projects in line with market conditions, regulatory requirements and long-term strategic goals,” without setting a new date.
On February 19, 2026, World Liberty Financial announced one of the most ambitious experiments in real-world asset tokenization: a partnership with BlackRock-backed Securitize and London-listed developer Dar Global to tokenize loan revenue from a Trump-branded luxury resort in the Maldives. Six months later, no token has been sold, no new launch date has been set, and the project sits in indefinite limbo. The reason is not a smart-contract exploit or a regulatory crackdown. It is a war. This piece examines what the delay reveals about the fragility of tying digital tokens to physical assets in unstable regions, the broader track record of the venture behind the deal, and whether the growing RWA market has priced in the risks that the real world routinely delivers.
The deal that was supposed to make history
The Maldives token project was conceived as a first-of-its-kind offering. Unlike previous tokenization efforts that wrapped completed properties in digital securities, WLFI and its partners proposed tokenizing the development phase itself. The token, designated MALD1 on the Securitize platform, would represent interests in loan servicing revenue tied to construction financing for Trump International Hotel and Resort, Maldives.
Dar Global, a subsidiary of Saudi Arabia’s Dar Al Arkan Real Estate Development Company and listed on the London Stock Exchange, is building the resort on a private island roughly 25 minutes by speedboat from Male. Plans call for approximately 100 ultra-luxury beach and overwater villas designed to offer what Dar Global described as “the highest levels of privacy, exclusivity, and sophistication.” Completion is targeted for 2030. The Trump Organization is licensing its brand and hospitality management standards, marking the brand’s first property in the Maldives.
WLFI and Securitize handle the tokenization layer, issuing securities under Rule 506(c) of Regulation D for accredited U.S. investors and Regulation S for non-U.S. persons in offshore transactions. Securitize, which has handled tokenized fund issuances for BlackRock, Hamilton Lane, and Apollo Global, serves as the registered transfer agent and compliance engine for the offering.
Holders of MALD1 tokens would receive a fixed yield, a share of ongoing loan proceeds, and a cut upon any eventual sale of the underlying loan positions. The structure was carefully designed to offer economic exposure without conferring direct property ownership, sidestepping the legal complexities of cross-border real estate title transfer that have stalled earlier tokenization projects in multiple jurisdictions.
When the partnership was announced, Zachary Folkman, a WLFI co-founder, called it “a new model for how real-world value meets blockchain transparency.” The plan was to open sales to qualified investors by spring 2026. Spring came and went.
How a war grounded the token sale
The conflict between the United States, Israel, and Iran that escalated in early 2026 sent shockwaves far beyond the Middle East. Brent crude prices surged from around $70 to over $110 per barrel in March before settling into the $95 to $100 range, and global capital flows into risk assets slowed sharply. For the Maldives, the most immediate effect was the closure of key air corridors over the Gulf region. Airlines that route through the Persian Gulf, including major carriers from the Middle East and South Asia, suspended or rerouted flights, severing connectivity to the Indian Ocean archipelago that depends on air travel for virtually all of its tourist arrivals.
The numbers were stark. Tourist arrivals to the Maldives fell 23.4% in the first week of March 2026 compared with the same period in 2025, according to official data from the Maldives Ministry of Tourism. Average daily arrivals in early March dropped 41.5% compared with February averages. The Maldivian government projected a revenue shortfall of $80 million to $100 million if disruptions persisted for a single month, a serious figure for an economy where tourism accounts for more than 60% of foreign exchange receipts. Even as some viral claims of a 90% tourism collapse proved overstated, the real decline was severe enough to force the government to introduce new visa categories in an effort to attract visitors from unaffected regions.
For a token backed by loan revenue from a resort that does not yet exist, the implications were severe. Construction timelines depend on the movement of materials, labor, and capital through a region that was suddenly difficult to reach. Projected occupancy rates and revenue models, the very inputs that determine the value of MALD1’s yield, became unreliable. Selling a fixed-income token to accredited investors requires credible financial projections, and credible projections require a stable operating environment. No responsible issuer would price a yield curve against a tourism market in freefall.
Bloomberg reported on August 13 that the token sale had been indefinitely postponed, with sources attributing the delay directly to war-driven travel disruptions. Dar Global’s CEO, Ziad El Chaar, offered a carefully worded statement about reviewing schedules but provided no timeline for resumption. The absence of a target date is itself a signal: the company does not know when conditions will allow a credible offering.
WLFI’s track record under scrutiny
The Maldives delay does not exist in isolation. It arrives at a moment when World Liberty Financial’s broader trajectory has drawn increasing skepticism from investors, regulators, and industry analysts.
WLFI launched its governance token sale in October 2024, initially targeting $300 million by selling 20 billion tokens at $0.015 each. Early demand was anemic: only $11 million trickled in during the first phase, and the team slashed its target to $30 million. Then momentum shifted, driven in part by the political attention surrounding the Trump family’s involvement. A second tranche of 5 billion tokens at $0.05 each brought the total raise to $550 million from more than 85,000 participants.
The Trump family’s financial interest in the project is substantial. According to public disclosures, the family receives 75% of net proceeds from WLFI token sales. Trump himself is listed as “co-founder emeritus,” and his 2025 income from the venture was reported at roughly $800 million, making World Liberty Financial one of the most lucrative crypto ventures in history by founder returns.
But the token’s secondary market performance has been punishing. WLFI peaked at approximately $0.331 in September 2025 and then entered a sustained decline, falling to around $0.055 by late July 2026, a drop of roughly 83%. Public estimates indicate that WLFI holders have absorbed $674 million in combined realized and unrealized losses. In April 2026, Forbes reported that WLFI had borrowed $75 million on its own platform, prompting one analyst to warn investors not to become “exit liquidity.”
Governance disputes have compounded the price decline. In April 2026, Tron founder Justin Sun, one of WLFI’s largest individual investors with approximately $75 million in purchases, filed a federal lawsuit alleging that WLFI froze 540 million of his unlocked tokens and 2.4 billion locked tokens and excluded him from governance activities. Sun claimed the contract contained an undisclosed blacklist function that was never disclosed to investors. WLFI countersued in May, accusing Sun of defamation and alleging that he engaged in short selling to suppress the token price and made straw purchases on behalf of undisclosed third parties. The litigation remains unresolved, and the WLFI token fell 15% to a record low after Sun publicly accused the project of embedding a backdoor.
On the product side, WLFI’s USD1 stablecoin has been a notable success by supply metrics, reaching $5.3 billion in circulation by mid-2026. It became a settlement asset on Binance’s perpetual futures markets and was selected as the payment vehicle for Abu Dhabi investment firm MGX’s multibillion-dollar Binance stake. However, concentration risk is pronounced: Binance holds approximately 87% of all USD1 in circulation, raising questions about the stablecoin’s decentralization claims and its vulnerability to a single exchange relationship.
When tokenized assets meet physical reality
The Maldives delay crystallizes a category of risk that the RWA tokenization industry has largely discussed in theory but never confronted in practice. Tokenized U.S. Treasuries or money-market funds, the segments that dominate the current $26 billion to $34 billion RWA market, are backed by assets that exist as electronic entries in regulated custodial systems. They do not depend on weather, geography, or geopolitics. Their yields are predictable because the U.S. government’s capacity to service its debt is, for practical purposes, not affected by whether flights are operating over the Persian Gulf.
Tokenized real estate is fundamentally different. The underlying asset is immovable, jurisdiction-specific, and vulnerable to physical disruption. A resort in the Maldives faces cyclone risk, sea-level rise, political instability in the host country, and, as the current episode proves, conflict in adjacent regions that can sever the transportation links on which the entire business model depends.
The MALD1 token adds additional layers of abstraction. Investors do not own a share of the resort. They own a token representing a share of servicing income from loans used to finance the resort’s construction. If construction delays push the completion date past 2030, if occupancy projections prove optimistic in a region shaken by conflict, or if Dar Global encounters financial difficulties, the yield that makes MALD1 attractive could shrink or vanish entirely. The investor is three steps removed from the physical asset: token to loan servicing rights to loan to resort to tourist spending. Each link in that chain introduces its own failure mode.
This is not a hypothetical concern. The history of tokenized real estate is littered with projects that promised liquidity and delivered illiquidity. Industry analyses of the first wave of tokenization projects, roughly 2019 through 2023, identified three recurring failure modes: legal non-recognition of tokenized title, tiny investor pools restricted to accredited buyers with five-figure minimums, and the absence of market-making infrastructure to support secondary trading. Less than 10% of tokenized real estate projects from that era showed meaningful secondary market volume. Projects that prioritized speed over structural integrity during 2025 faced enforcement actions, platform shutdowns, and investor litigation, particularly when tokens moved to unverified wallets and triggered anti-money laundering investigations.
The MALD1 structure addresses some of these issues. Securitize is a regulated transfer agent with deep experience in compliance infrastructure. The loan-revenue model avoids the title-transfer problem. But no amount of structural engineering can hedge against a war that closes airspace and craters the tourism market on which the underlying asset depends.
The case for WLFI and tokenized hospitality
A fair analysis requires stating the opposing case at full strength. Proponents of the Maldives project, and of RWA tokenization more broadly, would argue that the delay is precisely what a responsible issuer should do. Launching a token sale into a disrupted market would expose investors to mispriced risk and potentially trigger regulatory scrutiny. By waiting, WLFI and Securitize are protecting investors, not failing them.
There is also a structural argument. Deloitte projects that tokenized real estate will reach $4 trillion in value by 2035, implying a 27% compound annual growth rate. If that projection holds, first movers in luxury hospitality tokenization will have secured a durable competitive advantage. The Maldives project, precisely because it tokenizes the development phase, offers investors exposure to the highest-growth period of a real estate asset’s lifecycle, when value appreciation is steepest.
The broader WLFI ecosystem, despite its token price decline, has delivered real products. USD1 is one of the largest stablecoins in circulation. The subsidiary WLTC Holdings applied in January 2026 for an OCC national trust bank charter covering stablecoin issuance, redemption, and custody. If approved, it would give WLFI a regulated banking entity, a significant competitive moat that few crypto-native ventures can match.
Regional peers offer precedent for optimism. The Dubai Land Department launched a controlled tokenization pilot in February 2026 that explicitly tests governance, investor protection, and operational readiness for secondary market resale. Saudi Arabia’s Open World launched the country’s first licensed RWA Tokenization Center of Excellence in Al Khobar in January 2026, targeting energy, real estate, and carbon credits. The institutional infrastructure is being built, even if the Maldives project is temporarily sidelined.
What would invalidate the bearish thesis? If the Iran conflict resolves or de-escalates enough to restore Maldives air connectivity, if Dar Global delivers construction milestones on schedule, if the MALD1 token launches with strong investor demand and develops meaningful secondary trading, and if WLFI’s governance disputes with Justin Sun reach a resolution that restores market confidence, then the delay will look like prudent risk management rather than a structural flaw. Each of these conditions is plausible. Whether they are probable is a different question.
The SEC’s parallel pause
The MALD1 delay coincides with a related regulatory development that compounds uncertainty for the entire tokenization sector. On August 13, the same day Bloomberg reported the Maldives postponement, CoinDesk reported that the U.S. Securities and Exchange Commission would again delay its proposed “innovation exemption” for tokenized securities.
The exemption, first floated in late 2025, would have created a streamlined regulatory pathway for tokenized real-world assets, potentially reducing compliance costs and accelerating time-to-market for offerings like MALD1. Its repeated delays reflect unresolved tensions between the White House, which has publicly supported crypto innovation, and SEC staff, who have raised concerns about investor protection in tokenized offerings that blur the line between securities and commodities.
For WLFI, the regulatory uncertainty is particularly acute. The project exists at the intersection of presidential politics, family financial interests, and securities law. Any tokenized offering associated with the sitting president’s family will receive heightened scrutiny from regulators, regardless of the formal recusal arrangements in place. The SEC’s reluctance to finalize the innovation exemption suggests that the regulatory environment for complex tokenized offerings remains unsettled, adding another variable to the MALD1 relaunch calculus.
The tangibility paradox
Most coverage of the WLFI Maldives delay focuses on either the political angle (another Trump crypto controversy) or the market angle (RWA tokenization faces headwinds). Both framings miss the deeper structural lesson that no competitor has articulated clearly.
The Maldives token exposes a paradox at the heart of real-world asset tokenization. The entire value proposition of RWA tokens is that they connect blockchain efficiency to tangible, physical value. But the more tangible the asset, the more exposed the token becomes to forces that no smart contract can mitigate. A tokenized Treasury bill is safe precisely because it is abstract, an electronic claim on the full faith and credit of the U.S. government. A tokenized resort in the Indian Ocean is vulnerable precisely because it is real, a collection of villas on a low-lying island in a geopolitically sensitive region, reachable only by air routes that can be shut down by events thousands of kilometers away.
This paradox does not mean real estate tokenization is unworkable. It means the market needs to develop pricing models that account for geopolitical risk, supply-chain disruption, climate vulnerability, and the correlation between these factors and the revenue streams that back tokenized securities. Current models, borrowed largely from traditional real estate finance, do not adequately capture these compounding risks because traditional real estate finance does not typically involve selling fractional interests in development-phase loans on assets in conflict-adjacent zones to a global investor base via blockchain rails.
The WLFI Maldives case may ultimately become a case study in how the industry matures. If it prompts issuers, platforms, and regulators to build better risk frameworks for location-dependent tokenized assets, the delay will have served a purpose beyond its immediate commercial impact. If it is treated as an isolated incident and the market moves on without structural adjustment, the next disruption will deliver the same lesson at higher cost.
What to watch
– **Maldives air traffic recovery**: Monthly tourist arrival data from the Maldives Ministry of Tourism will signal whether the travel disruption that prompted the delay is easing or persisting.
– **MALD1 relaunch timeline**: Any announcement from WLFI, Securitize, or Dar Global about a new launch date or revised offering terms will indicate whether the project remains commercially viable.
– **SEC innovation exemption status**: The next scheduled review of the tokenization exemption, expected in Q4 2026, will determine the regulatory runway for offerings like MALD1.
– **WLFI governance litigation resolution**: The outcome of the Sun v. WLFI and WLFI v. Sun lawsuits will shape investor confidence in the project’s governance structure and management credibility.
– **Dar Global construction milestones**: Quarterly updates from Dar Global on the physical progress of Trump International Hotel and Resort, Maldives, will test whether the 2030 completion target remains achievable.
What is the MALD1 token?
MALD1 is a tokenized security issued through Securitize that represents a share of loan servicing revenue tied to the construction financing of Trump International Hotel and Resort, Maldives. It offers a fixed yield plus a share of ongoing loan proceeds, and it is available only to accredited investors under U.S. Regulation D and Regulation S exemptions.
Why was the Maldives token sale delayed?
The token sale, originally planned for spring 2026, was postponed because the Iran conflict disrupted air corridors serving the Maldives, causing tourist arrivals to drop by as much as 41% in early March. The disruption undermined the revenue projections that underpin the token’s value proposition, and no responsible issuer would launch into those conditions.
How much has WLFI raised from token sales?
World Liberty Financial raised approximately $550 million through its governance token sale, which concluded in early 2025 with more than 85,000 participants. The initial tranche sold 20 billion tokens at $0.015 each, and a second tranche sold 5 billion tokens at $0.05 each. The Trump family receives 75% of net proceeds from these sales.
What is USD1 and how large is it?
USD1 is a stablecoin issued by World Liberty Financial, pegged 1:1 to the U.S. dollar and backed by short-term Treasuries and cash equivalents. It reached a circulating supply of approximately $5.3 billion by mid-2026, making it one of the largest stablecoins in circulation, though Binance holds roughly 87% of total supply.
What are the main challenges facing tokenized real estate?
Tokenized real estate faces liquidity risk from thin secondary markets, legal risk from jurisdictions that do not recognize tokenized title, geopolitical risk when assets are located in unstable or conflict-adjacent regions, and structural risk when tokens represent indirect claims such as loan revenue rather than direct ownership. Less than 10% of first-wave tokenized real estate projects showed meaningful secondary trading volume.
Who is building the Maldives resort?
Dar Global, a London-listed subsidiary of Saudi Arabia’s Dar Al Arkan Real Estate Development Company, is the developer. The Trump Organization is licensing its brand and hospitality management standards. The resort is planned to feature approximately 100 ultra-luxury beach and overwater villas on a private island near Male, with completion targeted for 2030.
What happened in the Justin Sun lawsuit against WLFI?
In April 2026, Tron founder Justin Sun sued WLFI in federal court, alleging that the project froze approximately 540 million of his unlocked tokens and 2.4 billion locked tokens and excluded him from governance without disclosure. WLFI countersued in May, accusing Sun of defamation and market manipulation through short selling. Both cases remain pending.
Is the MALD1 token a good investment?
The MALD1 token has not yet been sold, so there is no market price or performance data to evaluate. Any future offering will carry significant risks, including construction delays, geopolitical disruption, regulatory uncertainty, and the governance challenges that have affected WLFI’s broader token ecosystem. Prospective investors should review the private placement memorandum and consult qualified financial and legal advisors before committing capital. This is educational analysis, not investment advice. *Disclaimer: This article was published on August 14, 2026. It is intended for educational and informational purposes only and does not constitute financial, investment, or legal advice. The author and publisher do not hold positions in any tokens or securities mentioned. Readers should conduct their own research and consult qualified professionals before making investment decisions.*
Crypto World
Bitcoin Red Team flags 7,958 issues after Kimi K3 scan
Bitcoin Red Team has expanded its AI-assisted security review to 501 Bitcoin-related open-source projects, logging 7,958 findings in its latest detailed tally after 108 hours of work.
Summary
- Bitcoin Red Team scanned 501 projects and logged 7,958 findings after 108 hours of reviews.
- Researchers classified 1,280 findings as high or critical, but many still require human verification today.
- About 24.7% of findings had reproducible proofs, while 29.4% were reported upstream to project maintainers.
- Kimi K3 became the campaign’s primary AI workhorse as researchers tested Bitcoin open-source software extensively.
- BTCPay Server released fixes after Bitcoin Red Team and independent researchers reported security vulnerabilities recently.
Calle, a pseudonymous Bitcoin developer involved in the effort, said on Aug. 13 that the team has now completed a basic scan of almost the entire Bitcoin open-source ecosystem and that much of the easier-to-find vulnerability surface has already been examined.
The headline numbers require an important distinction. The 7,958 findings do not represent 7,958 confirmed exploitable vulnerabilities. The team classified 1,280 as high or critical, while 24.7% of all findings had been dynamically reproduced and 29.4% had been reported upstream at the 108-hour mark. Maintainer review and human reproduction remain part of the verification process.
Kimi K3 has become a security force multiplier
Calle said two weeks of work with Moonshot AI’s Kimi K3 exposed how quickly modern models can examine years of accumulated open-source code. He described the situation as a “massive collision” between older software and frontier AI, adding “everything is broken, bitcoin is burning.” The wording is his characterization and should not be read as evidence that Bitcoin Core or every Bitcoin project is compromised.
Independent testing supports the narrower point that Kimi K3 has meaningful cybersecurity capability. A joint U.K. AI Security Institute and U.S. CAISI assessment found the model outperformed GLM-5.2 on exploit-development testing but remained behind the strongest U.S. closed models. Kimi K3 scored 32% on ExploitBench and reached arbitrary code execution on zero of 41 samples in that test.
Bitcoin Red Team’s earlier sweep found 4,962 potential issues across 390 Bitcoin projects, including 720 then classified as high or critical. The newer tally shows the review expanded materially after that first wave.
Maintainers are already validating and patching findings
The campaign has moved beyond automated scanning. BTCPay Server’s official GitHub release credited Bitcoin Red Team researchers Bruno Garcia and Ben Carman with reporting a critical vulnerability that was already being exploited. Version 2.4.2 fixed a two-factor authentication bypass affecting Greenfield Basic Authentication.
BTCPay later confirmed that attackers had obtained LND admin macaroon credentials from affected installations and used them to access connected Lightning wallets. The project said it was processing additional reports from Bitcoin Red Team, Project Loupe, Magic Grants and independent researchers while strengthening its scanning and review processes.
On Aug. 14, BTCPay announced another security-focused release candidate, v2.4.3-rc4, addressing vulnerabilities reported by those groups. In related coverage, BTCPay supporters backed a recovery bounty after the earlier exploit and the foundation pledged 0.21 BTC to the Bitcoin Red Team fund.
Those fixes give concrete evidence that maintainers are validating at least some serious Red Team reports. They do not validate every item in the 7,958-finding dataset. AI-assisted audits can produce false positives, duplicate reports and severity assessments that change after manual investigation, making verification central to interpreting the numbers.
Bitcoin projects face a faster security cycle
Calle argued that unmaintained projects should now be treated with greater caution because AI has sharply lowered the cost of finding and testing weaknesses. He also said response time is becoming a useful indicator of project health and that maintainers will increasingly need their own continuing AI audit pipelines rather than occasional external reviews. Those are Calle’s conclusions from the campaign rather than universal security rules.
The wider ecosystem is already moving in that direction. OpenSats has created a fast-tracked red-teaming grant route focused partly on reimbursing researchers for LLM costs. More than 40 Bitcoin and digital-asset organizations have also asked leading AI laboratories to give vetted open-source defenders controlled access to frontier models.
As crypto.news reported, the industry coalition warned Bitcoin developers could fall behind attackers without access to advanced AI models. The request does not seek unrestricted access. It proposes vetted researchers, secure environments, sufficient compute and direct communication channels with AI security teams.
The next phase is likely to move more slowly than the initial sweep. Automated discovery can scale quickly, while reproduction, responsible disclosure, patch development and regression testing require more time. Projects receiving reports must determine which findings are exploitable, how urgently users need updates and when technical details can safely become public.
For Bitcoin users, the takeaway is narrower than the largest numbers suggest. The Red Team has reported a large volume of potential weaknesses across Bitcoin-related software, not evidence that Bitcoin’s base consensus protocol has failed. The immediate security concern centers on wallets, Lightning infrastructure, payment software and libraries carrying older or lightly reviewed code.
Crypto World
Ethereum study flags 65,340 risky addresses tied to $574.8M
A USENIX Security ’26 study has identified 65,340 high-risk address instances across Ethereum and BNB Smart Chain, linking them to 126,982.94 ETH and 17,726.7 BNB in native-token losses.
Summary
- Researchers identified 65,340 high-risk address instances across Ethereum and BNB Chain in their large-scale study.
- Estimated losses reached 126,982.94 ETH and 17,726.7 BNB, valued by researchers above $574.8 million overall.
- Researchers extracted 16.3 million private keys from 63,004 GitHub repositories for their cross-chain analysis dataset.
- Their detection framework achieved 99.11% precision after manual sampling validation across both analyzed blockchain networks.
- Two newly described attack vectors exploited deterministic contract addresses and EIP-7702 delegated account control mechanisms.
The paper, presented at the 35th USENIX Security Symposium in Baltimore, estimates their dollar value at more than $574.8 million.
The dollar figure needs context. The researchers say they valued the token losses using reference prices of $4,408 per ETH and $847 per BNB rather than prices at the time of every transaction. They describe their findings as a “conservative lower bound” because the analysis covers only native ETH and BNB on the two networks and may miss less obvious cases.
Ethereum address misuse spans contract and private-key risks
The researchers divide “Address Misuse” into two categories. Contract Account misuse happens when users treat an address without deployed contract code as a contract address, often because the same address is used in another network context. The study identified 49,344 such instances, associated with losses of 22,738.41 ETH and 8,681.41 BNB.
Externally Owned Account misuse involves addresses whose private keys are exposed or show strong onchain signs of compromised control. Researchers identified 15,996 EOA misuse instances associated with 104,244.53 ETH and 9,045.29 BNB in losses. More than 95% of EOA misuse losses came from the GitHub exposed-key subtype.
Two new attack paths account for about $15.7M
The first newly described attack takes advantage of deterministic contract-address creation. Attackers can promote a contract address on a testnet, wait for users to mistakenly send mainnet funds to the matching no-code address, and later deploy withdrawal code at the same location. Researchers linked 469 malicious contracts to 3,446.37 ETH and 431.79 BNB in losses.
The second uses EIP-7702 against accounts with already exposed private keys. Attackers delegate those EOAs to malicious code that automatically sweeps incoming funds. The paper found 17,270 cases, producing losses of 25.86 ETH and 33.45 BNB. Using the paper’s reference prices, the two newly described vectors together account for roughly $15.7 million.
The 99.11% figure is precision, not universal verification
The team mined 63,004 GitHub repositories created between January 2015 and May 2025, extracting 10.3 million unique candidate addresses and 16.3 million private keys after deduplication. It also used Ethereum Stack Exchange and Stack Overflow data before analyzing transactions on Ethereum and BNB Smart Chain.
Researchers manually sampled results and reported 99.11% overall detection precision. That does not mean every one of the 65,340 instances was individually manually verified. The authors acknowledge possible heuristic false positives and incomplete data, while ERC-20, NFT and other chains are excluded from the headline loss calculation.
EIP-7702 security concerns are widening
Ethereum’s official guidance warns that malicious EIP-7702 delegation can give hostile contract code control over assets. A separate USENIX Security ’26 study found more than 63% of analyzed EIP-7702 authorization transactions were associated with malicious EOA-targeted attacks, identifying 924 malicious contract accounts across seven supported chains.
As previously reported, EIP-7702 delegations were linked to automated wallet-draining activity after Ethereum’s Pectra upgrade. In related coverage, attackers later drained about $3.1 million from Polymarket users through phishing and malicious delegated execution.
The authors recommend wallet warnings for known exposed keys and cross-chain contract mismatches, stronger secret management for developers and clearer address-to-network documentation. They also propose considering chain identifiers in future contract-address derivation. Those are research recommendations, not adopted Ethereum or BNB Chain protocol changes.
The researchers plan to expand future work to additional chains and token types. Until then, the 126,982.94 ETH and 17,726.7 BNB totals are best read as measured native-token losses within the study’s defined scope, while $574.8 million remains a standardized valuation estimate.
Crypto World
CFTC sets Aug. 20 crypto talks as CLARITY vote waits
The Commodity Futures Trading Commission will use its inaugural Innovation Advisory Committee meeting on Aug. 20 to examine crypto regulation, artificial intelligence and prediction markets as Congress delays action on a broader digital asset market structure bill.
Summary
- CFTC advisers will discuss crypto regulation on August 20 as Congress delays market structure legislation.
- The agenda includes using existing statutory authority while complementing future congressional legislation on digital assets.
- Senate cloture on the CLARITY Act’s motion to proceed is scheduled to ripen September 15.
- SEC canceled its August 14 crypto offering meeting and has not announced a replacement date.
- Michael Selig currently serves as the CFTC’s sole commissioner despite the agency’s statutory five-seat structure.
The three-hour meeting begins at 1 p.m. ET in Washington and will be streamed publicly, according to the CFTC release.
The timing gives the meeting a sharper policy role than a routine technology discussion. The CFTC agenda explicitly lists “opportunities to modernize existing rules using current statutory authority” and areas where regulatory action can “complement future congressional legislation.” However, the IAC is advisory. It will not vote on a crypto rule, and its recommendations do not automatically represent the Commission’s position.
CFTC crypto talks focus on what regulators can do now
The first 50-minute session, titled “Crypto’s Regulatory Evolution: From Uncertainty to Clarity,” will cover the lack of a comprehensive federal market structure framework, overlapping jurisdictions and recent regulatory efforts. It also lists cybersecurity, operational resilience and crypto infrastructure as areas needed for trusted markets.
That wording stops short of saying the CFTC will create the CLARITY Act through regulation. The agency can interpret and modernize rules within its existing authority, but Congress would be needed to change statutory jurisdiction more broadly. Earlier this year, the CFTC and SEC jointly issued an interpretation on how federal securities laws apply to crypto assets, showing how the agencies can provide guidance without waiting for a new statute.
As previously reported, the CFTC’s first Innovation Advisory Committee meeting will cover crypto, AI and prediction markets, but no proposed crypto rule is scheduled for a vote at the session.
CLARITY Act now faces a September 15 Senate test
The Digital Asset Market Clarity Act has not failed. Majority Leader John Thune filed cloture on the motion to proceed before the Senate left Washington. The Senate schedule says that motion will ripen at 2:15 p.m. on Sept. 15, one day after senators return for regular business.
As previously reported, the CLARITY Act faces a September 15 procedural vote and still needs enough support to clear the Senate’s 60-vote cloture threshold. Even successful cloture would only move the chamber toward considering the bill. Debate, amendments and a final vote would still follow, while any Senate text differing from the House version would require further congressional action.
SEC cancels its planned August 14 crypto meeting
The latest update changes the earlier narrative that the CFTC would follow an SEC meeting on new crypto offering rules. The SEC had scheduled an Aug. 14 open meeting to consider proposing a tailored offering regime for certain investment contracts involving crypto assets. On Aug. 13, however, the Commission formally canceled that meeting.
The SEC’s notice gave no reason and announced no replacement date. As previously reported, the planned session would have considered tailored rules for crypto investment contract offerings. Its cancellation does not withdraw the SEC’s wider crypto agenda, but no proposal will be considered at the previously scheduled Friday meeting.
What happens next for U.S. crypto regulation
The CFTC meeting remains scheduled for Aug. 20. Its crypto session will be followed by discussions on AI and prediction markets, including market surveillance, manipulation concerns and federal versus state jurisdiction. Members of the public can submit written comments through Aug. 27.
Chairman Michael Selig currently sits alone on a Commission designed for five commissioners, according to the CFTC’s official leadership page. The agency therefore lacks the bipartisan panel contemplated by its normal five-seat structure while major crypto and prediction-market policies are being developed.
The next concrete dates are Aug. 20 for the IAC discussion, Aug. 27 for comments and Sept. 15 for the CLARITY cloture test. The CFTC’s existing authority over crypto remains narrower than the framework Congress is considering. The Aug. 20 meeting can shape agency priorities, but it cannot substitute for legislation that changes the agencies’ statutory powers.
Crypto World
FG Nexus exits ETH treasury after $45.2M loss
FG Nexus sold all of its digital assets before June 30, ending an Ethereum treasury strategy less than a year after it launched.
Summary
- FG Nexus sold all digital assets before June 30, ending its Ethereum treasury strategy entirely.
- First-half digital asset operations lost $45.207 million while staking generated only $144,000 in total revenue.
- ETH sales generated $60.956 million cash, with another $14.983 million receivable fully collected during July.
- FG Nexus had peaked at 50,770 ETH in September 2025 before beginning its treasury unwind.
- Management plans to redirect capital toward manufactured housing, though no definitive FG Communities deal exists.
The Nasdaq-listed company disclosed the completed exit in its Aug. 12 filing, which reclassified the digital asset business as discontinued operations.
The filing shows that FG Nexus received $60.956 million in cash from ETH sales during the first half of 2026. A further $14.983 million remained receivable at June 30 and was collected in July. The company held no cryptocurrency at quarter end.
FG Nexus records $45.2M loss from digital asset exit
FG Nexus reported a $45.207 million loss from its discontinued digital asset operations for the first six months of 2026. The total included a $41.167 million loss on ETH digital assets, a $2.793 million impairment on digital intangible assets and $1.789 million in general and administrative expenses.
Those figures matter because the $45.207 million should not be described as the realized loss from selling ETH alone. The business also recorded a $398,000 gain on digital intangible assets and only $144,000 of staking revenue. Its broader consolidated net loss for the first half reached $56.928 million.
In addition, FG Nexus announced its Ethereum treasury strategy in July 2025 and said its digital asset business began in August. By Sept. 28, the company reported holding 50,770 ETH, valued at about $207 million using its reference price at the time, with an average purchase price near $3,860.
As previously reported, FG Nexus raised $200 million while making Ethereum its primary treasury asset, with plans to generate returns through staking and other Ethereum opportunities. By June, however, the company was unwinding that position. Crypto.news later reported that FG Nexus moved another 10,000 ETH as its treasury losses widened.
Cash from ETH sales is being redirected toward real estate
FG Nexus announced on July 1 that its board had authorized management to exit digital assets and create a real estate operating subsidiary focused mainly on land lease manufactured housing properties. CEO Kyle Cerminara said the company intended to “reallocate all of our capital from digital assets to cash flow producing real estate over the near term.” That remains a forward-looking company plan.
The company is also considering a potential combination with FG Communities, but the quarterly filing says board discussions remain preliminary and no decision or definitive agreement has been reached. An independent special committee is reviewing the potential transaction and has retained a financial adviser to provide a fairness opinion.
The ETH liquidation has increased available cash. FG Nexus reported $24.9 million of cash and equivalents at June 30. After receiving the ETH sale receivable and $15.5 million from the redemption of FG Merger II shares, cash reached approximately $51.4 million by July 31.
What happens next for FG Nexus
The next test is whether FG Nexus can turn that liquidity into income-producing property assets. The company has not announced a definitive FG Communities transaction or disclosed completed acquisitions under the new manufactured housing strategy. Its existing Quebec property also remains held and used after an earlier nonbinding sale proposal became unlikely to close.
FGNX traded at $7.59 on Aug. 13, up about 8.9% from the previous close. The company had already announced its crypto exit on July 1, however, so the move cannot be attributed solely to the later quarterly disclosure.
The reversal closes a short corporate Ethereum experiment that once aimed to make FG Nexus a major ETH holder. It also shows the financial tradeoff in this particular treasury strategy: first-half staking generated $144,000, while the discontinued digital asset operation recorded a $45.207 million loss.
Crypto World
Gemini posts $107.7M Q2 loss as spot volume drops 66%
Gemini Space Station reported a $107.7 million net loss for the second quarter ended June 30, extending its run to four consecutive quarterly losses since its September 2025 Nasdaq listing.
Summary
- Gemini reported a $107.7 million Q2 net loss, its fourth consecutive quarterly loss since IPO.
- Total revenue rose 37% year over year to $45.5 million, led by expanding services revenue.
- Spot trading volume fell 66% year over year to $3.8 billion amid weaker crypto markets.
- Credit card revenue jumped 231% to $16.2 million while total transaction losses reached $20.1 million.
- Assets on platform declined 54% to $8.4 billion, reflecting valuations and select institutional custody outflows.
Revenue rose 37% year over year to $45.5 million, but the exchange’s core spot trading business weakened sharply as total volume fell to $3.8 billion from $11.3 billion a year earlier.
The company’s Aug. 13 SEC filing showed the loss narrowed 19% from $133.2 million in Q2 2025. Gemini’s operating loss was $76.9 million, improving 18% from the first quarter, while operating expenses declined 15% sequentially to $122.4 million. The reduction followed February workforce cuts and exits from several international markets.
Gemini Q2 revenue grew as exchange trading contracted
Transaction revenue declined 15% year over year to $17.8 million. Exchange revenue fell 38% to $12.5 million as retail and institutional activity slowed. Retail spot volume dropped 53% to $700 million, while institutional volume fell 68% to $3.1 billion.
The weaker exchange business was partly offset by other activities. Services revenue rose 149% to $23.5 million. Credit card revenue jumped 231% to $16.2 million, staking revenue increased 50% to $4 million, and over the counter revenue rose to $4.7 million from $611,000. Gemini’s first quarter results had already shown a growing reliance on credit cards and other non exchange products, as crypto.news reported.
Credit losses and crypto marks kept the loss elevated
The company recorded $20.1 million in transaction losses, up from $3.6 million a year earlier. The total included a $16.1 million provision for expected credit losses on its credit card portfolio. Gemini said about $10 million of the Q2 provision related to accounts originated during the first quarter and associated with identified fraud activity.
The company said it added fraud detection and account monitoring controls. Management said the elevated provision was concentrated in the affected cohort and “does not reflect broad based deterioration” in the credit portfolio. That remains Gemini management’s assessment. Separately, the company recorded a $60.7 million realized and unrealized loss on crypto assets and receivables, partly offset by a $35.7 million gain on related party crypto loans.
Gemini pushes stocks and prediction markets as assets fall
Assets on Gemini’s platform fell 54% year over year to $8.4 billion from $18.2 billion. The company attributed the decline to lower crypto valuations and select institutional custody outflows. Monthly transacting users rose 11% to 580,000 from a year earlier, although the figure slipped 2% from the first quarter.
The company is trying to reduce its dependence on spot crypto fees. Prediction markets generated $524,000 in Q2 revenue, while event contracts traded increased 93% from the first quarter and cumulative contracts surpassed 225 million. The company also launched commission free stock trading for eligible U.S. customers in July, expanding its push beyond crypto trading, as crypto.news reported.
What happens next for Gemini
The company’s U.S. expansion is supported by regulated derivatives infrastructure. The CFTC lists Gemini Titan as a designated contract market, while its registry shows Gemini Olympus became a registered derivatives clearing organization on April 29. Gemini said its clearinghouse went live on Aug. 4, allowing it to settle its own prediction contracts and explore additional U.S. derivatives products.
Management is scheduled to discuss the quarter on an earnings call at 8:30 a.m. ET on Aug. 14. Investors will be watching whether services growth can offset weaker spot trading and whether credit losses normalize. The company also remains a defendant in an investor class action over its IPO disclosures and strategy shift. The federal docket shows the case remains active.
Crypto World
JPMorgan ended Polymarket banking relationship in 2025
JPMorgan Chase ended its banking relationship with prediction market Polymarket in October 2025 over regulatory concerns and told the company to find another bank, the Financial Times reported on Aug. 14.
Summary
- JPMorgan ended Polymarket’s banking relationship in October 2025 and directed it toward another banking partner.
- Polymarket has since moved to another bank while retaining other commercial relationships with JPMorgan entities.
- JPMorgan invited CEO Shayne Coplan to a February conference and reportedly seeks potential IPO underwriting.
- Polymarket is reportedly seeking roughly $1 billion at a valuation exceeding $20 billion from investors.
- Polymarket’s U.S. exchange operates through CFTC designated QCX while federal and state regulatory disputes continue.
Polymarket has since moved to an unidentified banking partner.
The account closure did not end all business between the companies. Polymarket told the FT it maintains “a close, active relationship with JPMorgan across multiple entities, operational integrations and material handling of customer fund flows.” JPMorgan declined to comment. The company’s description of the remaining relationship has not been independently detailed publicly.
JPMorgan’s exit came during Polymarket’s U.S. transition
The timing matters because Polymarket was still rebuilding its U.S. regulatory position. The CFTC order in January 2022 required Blockratize, the company behind Polymarket, to pay a $1.4 million civil penalty and wind down markets that did not comply with federal derivatives law.
By October 2025, the company had acquired QCX and QC Clearing and secured a CFTC staff letter granting narrow no action relief on certain reporting and recordkeeping requirements. The CFTC registry currently lists QCX LLC, doing business as Polymarket US, as a designated contract market. The Commission amended its designation in November to permit futures commission merchant intermediation.
Polymarket still faces regulatory and legal scrutiny
The regulatory picture remains unsettled. The FT reported in June that the CFTC had opened another investigation into Polymarket, citing a person familiar with the matter. The regulator had not publicly confirmed the investigation, and both the CFTC and Polymarket declined to comment on its focus.
XState and local scrutiny has also continued. In related coverage, Polymarket US and Kalshi won preliminary relief against Minnesota’s prediction market ban on July 27. The federal court stressed that its preliminary injunction was not a final determination on the merits. On Aug. 12, the New York City Council also announced an inquiry into prediction market marketing and requested information from Polymarket and three other platforms.
JPMorgan kept other ties despite closing the account
The FT reported that JPMorgan invited Polymarket CEO Shayne Coplan to speak at a private banking conference in Miami in February. The bank is also reportedly interested in an underwriting role if Polymarket eventually pursues an initial public offering. No public IPO filing has been announced.
The continuing relationship makes the episode more complex than a complete corporate break. It also comes during a wider U.S. debate over debanking. The Office of the Comptroller of the Currency said in its December review that it examined nine large national banks, including JPMorgan, and found policies at each that restricted some lawful industries or subjected them to escalated reviews. The OCC said its broader work remains ongoing.
Funding talks could value Polymarket above $20 billion
Polymarket is separately in early talks to raise roughly $1 billion at a valuation above $20 billion, Reuters reported on Aug. 4, citing Bloomberg. Reuters said it could not independently verify the report, while Polymarket did not respond to its request for comment. The figures therefore remain reported targets rather than a completed financing.
As crypto.news previously reported, the platform’s reported $1 billion fundraising talks could value it above $20 billion. ICE, the New York Stock Exchange parent, initially invested $1 billion in October 2025 and announced another $600 million direct investment on March 27, 2026.
What happens next for Polymarket
Polymarket’s immediate regulatory path will depend partly on the reported CFTC investigation and continuing state cases. The Minnesota injunction currently protects its federally regulated exchange from that state’s ban, but the litigation over federal derivatives authority and state gambling powers has not reached a final ruling.
Its capital markets plans are less certain. JPMorgan’s reported interest in future underwriting does not establish that an IPO will happen, and no public registration statement has been identified. The proposed $1 billion fundraising round also remains under discussion. Formal company announcements or securities filings would provide the next verifiable milestones.
Crypto World
Bitcoin’s Bottom Has a Date: And It’s Closer Than You Think
Ever since bitcoin started to lose value rapidly and consistently in Q4 last year, the main question within the cryptocurrency community is how low it can go. The next one was: when and where it will bottom out.
Analysts began speculating after each leg down. At first, it was $60,000 when BTC dipped to that level in February. Months later, though, it crashed to $59,000, $58,000, and even slightly below that on July 1. As such, the bottom figures have slightly changed. Now, popular analyst Rekt Fencer brought some historical figures to outline the exact date.
October 2026: Here We Go
In an August 13 tweet, the market commentator outlined that there are 53 days left (now 51 since two days have already passed) until this market slumber and sluggishness end. They based this prediction on previous BTC cycles, as bull markets lasted approximately 1,064 days, while the subsequent bear phases required roughly 364 days to find their ultimate bottom. The pattern sounds simple, but it has been surprisingly consistent.
Bitcoin’s bull cycle from the 2015 bottom to its 2017 peak lasted exactly 1,064 days. The painful bear market needed another 364 days before the cryptocurrency finally bottomed in December 2018.
History almost perfectly repeated itself from that 2018 bottom to the November 2021 peak. Guess what: another 364-day decline followed that culminated in the 2022 bear-market low.
It gets better. BTC’s latest bull cycle ran from late 2022 until October 2025. Yes, another approximately 1,064 days. If the second half of this pattern repeats as accurately as the first, Rekt Fencer believes the next bottom will arrive on October 5, 2026.
BITCOIN HAS 53 DAYS LEFT.$BTC macro cycles are almost too perfect:
2015 ➜ 2017 bull: 1064 days
2017 ➜ 2018 bear: 364 days2018 ➜ 2021 bull: 1064 days
2021 ➜ 2022 bear: 364 days2022 ➜ 2025 bull: 1064 days
If the pattern repeats one more time:
2025 ➜ 2026 bear: 364… https://t.co/R5BYDSY8nb pic.twitter.com/I1E4g3N6fy
— Rekt Fencer (@rektfencer) August 13, 2026
October in Focus
The screenshot reshared by Rekt Fencer has been a popular one in the crypto community. The reason for this is its surprising accuracy. The previous two major BTC bear markets required approximately 363 and 376 days, respectively, to move from their cycle peaks to eventual capitulation lows.
Applying that range to Bitcoin’s October 2025 ATH produces a potential bottoming window between roughly October 4 and 17 this year. Ali Martinez recently outlined almost the same possibility, but his dates ranged between October 6 and 16.
There’s an obvious problem with relying too heavily on particular calendar patterns. BTC’s previous cycles developed under entirely different macroeconomic environments. Today’s market includes spot ETFs, enormous institutional holders, corporate treasuries, a different regulatory landscape, and far greater integration with TradFi.
Interest rates, liquidity, ETF flows, geopolitical developments, and Fed policy could easily break even the most accurate pattern. As such, October 5 (or 6-16) shouldn’t be treated as some predetermined date on which BTC is guaranteed to print its lowest candle before it explodes to new peaks within days, weeks, or even months.
But then again, it’s always good to have a North Star, and October 2026 has quickly become the month every crypto investor has circled on the calendar.
The post Bitcoin’s Bottom Has a Date: And It’s Closer Than You Think appeared first on CryptoPotato.
Crypto World
Bitwise taps Superstate to tokenize shares of select crypto funds
Bitwise Asset Management has partnered with Superstate to develop a system that could let investors hold shares of certain Bitwise funds as blockchain-based tokens, with its Solana staking ETF expected to be the first product considered for the structure.
Summary
- Bitwise has partnered with Superstate to develop blockchain based ownership records for shares of certain funds.
- The Bitwise Solana Staking ETF is expected to be the first fund considered for tokenization, although its launch is not guaranteed.
- Investors could choose between traditional book entry shares and tokenized shares while retaining the same shareholder rights.
- The partnership follows Bitwise cutting 14% of its staff, reducing its global headcount to about 155.
Bitwise said Thursday that the planned framework would change how ownership of fund shares is recorded without changing the rights attached to the shares or the channels investors use to purchase them.
Under the proposed setup, shareholders could choose between holding their shares through the Depository Trust Company in traditional book-entry form or having their ownership recorded on a blockchain using Superstate’s transfer agency infrastructure.
“Shareholders could then elect to hold those shares either in traditional book-entry form through The Depository Trust Company or in tokenized form recorded on a blockchain and maintained through Superstate’s transfer agency infrastructure,” Bitwise said.
The asset manager, which oversees more than $9 billion in client assets across more than 70 investment products, cautioned that the tokenization capability is still being developed and its planned use with individual funds is not guaranteed.
Bitwise fund tokenization would preserve shareholder rights
Rather than creating a separate investment product tied to an existing fund, the planned Bitwise structure would provide another method for recording ownership of the same shares.
According to the company, investors choosing the blockchain option would retain the same shareholder rights as investors whose holdings remain in conventional book-entry form.
Tokenized shares, however, would not be freely transferable outside the blockchain-based system supporting them. Bitwise did not provide a launch date for the service or identify all of the funds that could eventually support tokenized ownership.
Superstate would provide the transfer agency infrastructure needed to maintain the blockchain-based ownership records. The fintech company works with issuers and asset managers on compliant securities issuance, recordkeeping and onchain market infrastructure.
Its role in the Bitwise project follows other fund tokenization work involving traditional and crypto-focused asset managers. In June, Superstate was selected to provide blockchain support for Invesco’s proposed Stablecoin Reserves Onchain Fund and maintain its blockchain-integrated shareholder registry.
Invesco’s filing described a structure connecting conventional fund records with onchain ownership tokens, while the portfolio itself was designed as a Rule 2a-7 government money market fund investing in cash, repurchase agreements and short-term U.S. Treasury securities.
The arrangement also built on an existing relationship between the two companies after Invesco took over day-to-day portfolio management of Superstate’s tokenized U.S. Treasury fund earlier in 2026. Superstate continued providing the product’s tokenization services through its FundOS platform.
Solana staking ETF is first in line for tokenization
Bitwise expects the Bitwise Solana Staking ETF, or BSOL, to be the first fund to use the proposed system, although the company said there is “no assurance” that tokenization of the product will ultimately launch.
BSOL began trading on NYSE Arca in October 2025 after the exchange completed the listing process for the fund. The ETF provides direct exposure to Solana while incorporating staking rewards generated from the SOL held by the product. Its market debut brought $69.45 million in first-day net inflows and lifted total assets to $288.92 million.
The fund is backed by SOL held in institutional cold storage and tracks the Compass Solana Total Return Monthly Index after fees and expenses. Bitwise set its management fee at 0.20% when the product launched.
By mid-May 2026, BSOL had accumulated about $861 million in assets and represented roughly 81% of the assets held across the Solana ETF products tracked at the time. The fund had crossed $500 million in assets within its first 18 days of trading.
Bitwise has continued adding staking to other proposed crypto investment products. In July, the asset manager amended its planned NEAR ETF to include staking and named NYSE Arca, BNY Mellon and Coinbase Custody in the filing.
Superstate has built out its onchain transfer agency business
Superstate’s work with Bitwise also extends its role as a transfer agent for securities represented directly on public blockchains.
The company registered Superstate Services LLC as a transfer agent with the U.S. Securities and Exchange Commission in March 2025, allowing its infrastructure to maintain ownership records for tokenized securities.
At the time, crypto.news reported that Superstate initially planned to use the service for its own USTB and USCC funds before making the infrastructure available to other securities issuers.
Superstate later expanded the model from funds to public equities. Its Opening Bell platform was introduced in May 2025 to allow SEC-registered shares to be issued and traded on public blockchains, initially using Solana. Unlike synthetic products that track the price of a stock, the platform was designed to work with issuer-authorized shares carrying ownership rights.
Galaxy Digital subsequently used the infrastructure to put its Nasdaq-listed shares onchain in September 2025. Superstate served as the registered transfer agent, updating Galaxy’s shareholder records when tokenized shares moved between verified wallets. The Galaxy structure treated the tokens as direct legal representations of the company’s shares rather than wrappers or synthetic instruments.
Superstate has also worked with fund managers on blockchain-native investment products. Coinbase Asset Management introduced its CUSHY digital credit fund in April using Superstate’s FundOS infrastructure, with tokenized shares designed for qualified institutional investors across Ethereum, Solana and Base.
Bitwise partnership follows recent staff cuts
The tokenization project was announced days after Bitwise confirmed a reduction in its workforce.
Earlier this week, the asset manager said it had cut 14% of its employees, leaving its global headcount at about 155 people.
Chief executive Hunter Horsley told The Block that the reductions were intended to better equip the company for its ongoing growth.
Bitwise has continued operating a large range of crypto investment products while expanding its ETF lineup. Alongside BSOL, the firm has filed for or launched funds covering several digital assets, with previous proposals including products tied to XRP, Sui, Aave, Zcash and Tron.
A filing earlier in 2026 also proposed 11 hybrid-structure ETFs covering assets including Aave, Zcash and Tron, with Coinbase Custody Trust Company named as custodian. At the time, the proposed funds had not yet received final ticker symbols.
-
Fashion12 hours agoWeekend Open Thread: Ann Taylor
-
News Videos7 days agoCan Astrology Help Find Gold and Silver Trends? A Financial Astrology Guide
-
Business6 days agoDatadog: Best Of Breed For Multiple Reasons
-
Business6 days agoHow to Start a Cleaning Business: A Step-by-Step Guide
-
Business6 days agoBDC Weekly Review: Private BDC Q2 Numbers Are Strong
-
Business4 days agoOil Price Today (August 11): Crude oil rises to $88 after Trump’s compensation demand dents Hormuz opening. Here’s why
-
NewsBeat3 days agoCommunication cards help banking customers access services or report scams
-
Entertainment7 days ago10 R-Rated Drama Movies That Can Be Called Masterpieces
-
Fashion6 days agoAmazon Sundays: Closet Care Before Fall
-
Business7 days agoMutual Fund Manager Scoops Up Beaten-Down Stocks
-
Politics7 days agoBe quiet, Miriam! – spiked
-
Business6 days ago5 Things You Must Know About Jorge Messi, the Father and Longtime Agent Who Shaped Lionel Messi’s Career
-
Politics5 days agoBen-Gvir’s crocodile project halted but abuses at Ketziot Prison continue
-
Crypto World4 days agoWhy Did Nvidia Stock Fall on Monday Despite a $500 Billion Wall Street AI Deal?
-
Politics6 days agoThe Church of England’s ruinous reparations racket
-
Politics7 days agoCalls to permanently pedestrianise central Belfast following festival success
-
Crypto World7 days agoBitcoin ETFs draw $853.5M in five-day inflow streak
-
Politics5 days agoSaudi Arabia used 86% of missile stockpile defending Iran attacks
-
Crypto World7 days agoA Deep Dive Into One Of The Most Significant Hacks In Recent Memory
-
Entertainment6 days agoWill Ferrell’s New Netflix Series Just Became One of the Streamer’s Biggest Hits of 2026

You must be logged in to post a comment Login