Connect with us

Crypto World

Coldcard’s RNG flaw is still draining wallets, and an AI audit just found 85 more critical bugs across Bitcoin

Published

on

Coldcard pushes bitcoin back to exchanges: the anti-self-custody trade

A five-year firmware error turned Coldcard into the largest known Bitcoin seed-theft, while AI-assisted analysis of the broader ecosystem is surfacing how systematically the industry has underestimated the same class of vulnerability.

Summary

  • Attackers have stolen a confirmed 1,596 BTC from about 7,300 Coldcard addresses across three attack waves, with total losses potentially reaching 2,055 BTC, close to $130 million, if a fourth wave is verified through victim reports.
  • The breach originated in a March 2021 firmware error that silently substituted a predictable software pseudo-random number generator for Coldcard’s hardware true random number generator during wallet seed creation, leaving seeds with as few as 40 bits of effective entropy on older devices.
  • Fifteen or more distinct attackers have exploited the same flaw without physical device access, and roughly 90% of stolen funds remain unmoved, giving investigators a narrow window to coordinate with exchanges and law enforcement before laundering activity accelerates.
  • Block’s Bitcoin engineering and security team independently confirmed the flaw, and Coinkite has released corrected firmware and destroyed all affected-device inventory, but existing vulnerable seeds require complete wallet migration regardless of firmware version installed.
  • The incident has triggered calls from Kraken’s chief security officer for mandatory independent entropy testing across all hardware wallet manufacturers, alongside a wave of AI-assisted security analysis of Bitcoin wallet codebases that has identified dozens of additional entropy handling failures the industry’s existing review processes had not caught.

On July 30, 2026, a coordinated sweep removed more than 1,082 Bitcoin from 1,196 hardware wallets in approximately 41 minutes. No device was stolen. No PIN was guessed. The Bitcoin protocol was untouched. The attackers worked from a laptop and an offline seed-reconstruction tool, because a firmware error introduced five years earlier had made the seeds of certain Coldcard models predictable enough to reconstruct without handling the hardware. By August 3, Galaxy Research had confirmed 1,596 BTC stolen from about 7,300 addresses, with a suspected fourth wave potentially pushing losses to approximately 2,055 BTC, close to $130 million. As investigators distributed flagged addresses to law enforcement and exchanges, a parallel wave of AI-powered security analysis swept other Bitcoin wallet codebases and surfaced entropy handling failures that conventional review had missed, suggesting Coldcard is the most visible instance of a far wider problem.

What went wrong inside the firmware

The vulnerability traces to a single macro-check error introduced during a March 2021 Coldcard firmware migration. Coinkite, the Canadian hardware wallet manufacturer, was integrating a new cryptographic library called libngu as part of a broader codebase update. During that integration, an incorrect conditional check caused wallet seed generation to bind to a software pseudo-random number generator called Yasmarang, built into the MicroPython embedded Python runtime, instead of the STM32 hardware true random number generator the device contains.

Advertisement

The production board configuration for every affected Coldcard model sets the macro MICROPY_HW_ENABLE_RNG to zero, because Coldcard provides its own separate hardware RNG wrapper. Libngu checks for this macro using a #ifndef conditional, which tests only whether the macro is defined in the build environment, not whether its value is nonzero. Because the macro was defined with a value of zero instead of absent entirely, libngu treated the hardware source as available and silently bound the seed-generation function to MicroPython’s deterministic Yasmarang generator. That generator produces output seeded from the microcontroller’s unique identifier and timer registers at boot, neither of which provides cryptographic randomness.

The hardware RNG continued running in other firmware functions throughout the entire affected period. Internal code reviews at Coinkite could confirm the generator was present, accessible, and called in the firmware without detecting that wallet seed creation had quietly redirected to the weaker source. Coinkite said in its technical postmortem that it had no knowledge the MicroPython fallback existed in that code path until the post-incident investigation, a detail that underscores how a single incorrect boolean check can survive years of review precisely because the intended component is visible and functional everywhere else.

Block’s Bitcoin engineering and security team independently identified the same error. The team traced the #ifndef macro check, confirmed the Yasmarang binding, and published a technical disclosure stating that the affected firmware called the deterministic fallback instead of the STM32 hardware source during seed creation. Block said it had not completed full empirical testing of exploitability but decided early disclosure was appropriate because active theft reports had already emerged.

The impact on entropy differed by device. Seeds generated on Mk2 and Mk3 devices running affected firmware versions from 4.0.0 through 4.1.9 contain roughly 40 bits of effective entropy, with no cryptographically generated input added to the random number generator output at all. Mk4, Mk5, and Q devices receive a small contribution from a secure element at boot, but libngu hashes and truncates that input to four bytes before using it to reseed only a single 32-bit word of the Yasmarang state. The result is approximately 72 bits of effective entropy rather than the intended 128, an exposure roughly 72 quadrillion times weaker than the intended design.

Advertisement

How attackers reconstructed wallets without physical access

A seed phrase is computationally infeasible to guess when it draws from 128 bits of uniform randomness. A seed drawing from 40 bits of entropy occupies roughly one trillion possible values. An attacker who can constrain the Yasmarang seed further, using publicly available information about the MCU unique identifier and typical boot timing for a given device model, reduces that space to something modern hardware can traverse.

Bitcoin addresses derived from any seed are publicly visible on the blockchain. An attacker who understands the Coldcard firmware flaw can enumerate the Yasmarang output sequences possible for a target device family, derive the Bitcoin addresses that each candidate seed would produce, and compare every derived address against the full public blockchain. Any match reveals a wallet whose private keys the attacker can recreate offline and use to authorize a transfer without touching the original hardware, knowing the device PIN, or interacting with the Bitcoin network in any way that would look unusual until the moment the transfer itself is broadcast.

The attack requires no cooperation from the victim, no network access to the victim’s device, and no vulnerability in the Bitcoin protocol. It is a consequence of the seed being drawn from a statistically small number of possible values instead of the 2^128 possibilities the device is designed to provide.

Block noted in its disclosure that practical exploitation cost depends on available MCU identifier information, boot timing, and prior RNG call history, and that no end-to-end brute-force benchmark has been published for any affected model.

Advertisement

Four attack waves and a $130 million toll

Galaxy Research has tracked four suspected waves of theft activity since July 30, combining on-chain data, victim reports, and coordination with law enforcement, exchanges, and blockchain analytics companies.

The first wave struck July 30 and removed 1,082.65 BTC from 1,196 addresses over approximately 41 minutes. Two subsequent waves targeted additional wallets exhibiting the same address profile. Galaxy confirmed those three waves, along with 14 smaller linked incidents, as responsible for the theft of 1,596 BTC from about 7,300 addresses. Galaxy head of research Alex Thorn identified a suspected fourth wave on August 3 after observing transaction patterns matching the earlier attacks, with his running estimate settling at 448.7 BTC moved from 709 additional addresses. The sweep rate during the most active period reached 13.8 wallet drains per Bitcoin block, compared with a baseline of 0.3 per block during a pre-incident control window, a pace roughly 45 times above normal. Galaxy’s confirmed estimate and fourth-wave analysis placed possible total losses at approximately 2,055 BTC.

Advertisement

The firm has stressed that its figures come from on-chain analysis and verified victim reports, not Coinkite’s own device records, and that blockchain data alone cannot determine whether a single actor carried out every wave. The firm identified at least 15 distinct attackers across all observed waves.

The largest single theft involved 1,159 BTC removed across seven addresses in one coordinated sweep. As of August 5, all of those funds remained unmoved and had not entered mixers or cash-out services. A separate, smaller attacker had begun attempting to launder stolen funds, routing 64 BTC toward a mixer, with approximately 10 BTC mixed during the first pass and the remainder split into outputs of roughly 7 BTC each for further rounds.

Chainalysis found that Canadian Bitcoin holders account for about 25% of attributable losses. Galaxy has distributed roughly 600 flagged attacker and victim addresses to U.S. federal law enforcement and exchanges to support monitoring. Around 90% of stolen Bitcoin has not moved, giving compliance teams time to flag destinations before funds reach cash-out services, though Galaxy has warned that new attackers may still be targeting unpatched wallets.

Why the flaw survived five years of review

Advertisement

The macro-check error remained undetected for more than five years because of how hardware wallet firmware is typically reviewed.

Standard security assessments verify that the correct entropy source is present in the codebase, accessible from the right modules, and referenced in the seed-generation logic. Auditors confirm presence at the source level without tracing every conditional compilation path to its binary outcome to verify which function the code actually calls at runtime. In the Coldcard case, the STM32 hardware RNG was present, accessible, and actively called in multiple other firmware functions. The only code path where it was silently replaced was wallet seed creation, and the replacement was invisible to source-level review because the incorrect #ifndef check behaved unexpectedly at compilation.

Kraken chief security officer Nick Percoco argued after the incident that this pattern exposes a structural gap in hardware wallet certification. Existing frameworks, including Common Criteria evaluations, CSPN reviews, and vendor-commissioned audits, check physical security, secure element integrity, protocol implementation, and cryptographic library correctness. None of those frameworks systematically verify that production firmware at the moment of wallet creation actually calls the approved source of entropy rather than a fallback.

“Production firmware should undergo independent testing to confirm that the approved source of randomness is the one actually used,” Percoco said.

Advertisement

He cited NIST SP 800-90B, the United States standard for true random number generator testing and validation, and Germany’s BSI AIS-31 as existing frameworks that model what end-to-end entropy verification looks like in other regulated domains. He compared the hardware wallet certification gap with PIN entry device standards, where independent laboratory testing is mandatory before products can ship, and with U.S. government cryptographic module approvals, where entropy source validation is part of the FIPS 140 process. No equivalent independent check currently covers hardware wallet seed generation.

AI-driven audits surface a wider pattern

The Coldcard disclosure prompted security researchers to apply automated analysis methods to Bitcoin wallet firmware, embedded cryptographic libraries, and shared software components used across multiple wallet implementations. The goal was to determine whether the same class of error, specifically entropy source misdirection that survives source-level review because it only manifests at compilation or runtime, existed elsewhere in the Bitcoin custody ecosystem.

AI-assisted static analysis addresses this problem differently from manual review. A model trained on cryptographic vulnerability patterns can simulate compilation conditionals, trace every call binding that reaches a seed-generation or key-derivation function, and flag any path where the intended entropy source is overridden, replaced, or weakened under a specific build configuration. A human reviewer reading source code sees an entropy source called; an automated tool traces what that call actually resolves to in the compiled binary under each possible macro or configuration state.

Applied systematically across Bitcoin wallet firmware and shared cryptographic libraries in the weeks following the Coldcard disclosure, this approach identified 85 critical-severity findings across multiple wallet implementations and supporting libraries. The issues include incorrect fallback bindings similar to the Coldcard macro-check error, insufficient reseed entropy that leaves a weak software generator state only partially overwritten by hardware input, and conditional compilation paths that produce substantially weaker randomness under specific device configurations while passing standard source-level code review.

Advertisement

Coordinated vendor disclosure processes are underway for affected implementations, and the full set of findings is being released on timelines aligned with remediation schedules. Not all 85 findings have been made public as of August 7, 2026. The scale and distribution of the findings extend the concern Percoco raised about Coldcard into a much broader context. If a single incorrect boolean check in one vendor’s library could redirect entropy without detection for five years, the AI audit is providing an early answer to how common that class of oversight may be across the broader ecosystem.

Coinkite’s response and what remains unresolved

Coinkite disclosed the vulnerability publicly after its internal investigation and after Block’s independent disclosure confirmed the findings. The company released corrected firmware for every affected model: version 4.2.0 for Mk2 and Mk3, version 5.6.0 for Mk4 and Mk5, version 1.5.0Q for the Q model, and Edge versions 6.6.0X and 6.6.0QX for Mk4 and Q respectively on the Edge release track.

Coinkite halted all outbound shipments after confirming the vulnerability and said it destroyed every device containing affected firmware that remained in its facilities. The company advised affected users to retain their old hardware rather than discarding it, because original devices may become relevant if stolen funds are eventually recovered through legal proceedings. Coinkite’s legal team is coordinating with law enforcement agencies across multiple jurisdictions.

The most critical limitation of the firmware update is that it does not repair any seed generated under affected firmware. The vulnerability is in the seed-creation process, not in the device’s ongoing operation. A new seed generated on corrected firmware is safe. An old seed generated under affected firmware is permanently weakened regardless of what firmware version the device subsequently runs. Migrating to corrected firmware without also generating a new seed leaves the underlying wallet exposed to the same offline brute-force attack.

Advertisement

Coinkite’s advisory notes one exception: users who added at least 50 fair, independent, private dice rolls when originally generating their seed may have supplemented the weak firmware entropy enough that their specific seed is not at risk from this flaw. A strong, unique BIP-39 passphrase reduces immediate exposure but does not repair the underlying seed. Seeds exported from a Coldcard to any other wallet remain affected regardless of where they are stored.

The custody debate the hack reignited

The Coldcard incident has reopened a recurring argument about self-custody versus managed exchange storage. The 2022 FTX collapse moved a substantial share of Bitcoin from exchange accounts into hardware wallets, with self-custody positioned as the default defense against counterparty risk. The Coldcard flaw is now running the same flow in the opposite direction.

OKX chief compliance officer Jonathan Brockmeier said the exchange has seen record inflows since the Coldcard attacks began. He described the shift as “the flip side of FTX.” OKX reported preventing $26.3 million in scam-related losses in the first half of 2026 and protecting more than $1.1 billion in customer assets during the same period, citing AI-driven monitoring of blockchain activity and account behavior as core components of its security architecture.

K33 Research reported that nearly 890,000 BTC moved on-chain in the seven days following the initial attacks, the highest seven-day active supply figure recorded in 2026. Bitcoin’s 30-day high-to-low trading range during the same period was the narrowest since 2023, with realized volatility falling below that of the Nasdaq 100, meaning the Coldcard-driven spike in on-chain activity occurred against a backdrop of unusually calm price action. K33 head of research Vetle Lunde attributed the spike to Coldcard-related address migrations and noted that similar surges in on-chain activity have historically appeared near market turning points.

Advertisement

Ripple CTO Emeritus David Schwartz compared Coldcard losses with the 2011 MF Global collapse and pointed to a structural difference: regulated financial institutions offer insurance and bankruptcy recovery mechanisms, while Coldcard users whose Bitcoin was drained through reconstructed seeds have no comparable safety net. Recovery depends on whether law enforcement can trace and reclaim the Bitcoin through coordinated exchange and legal action.

What to watch

New attack waves. Galaxy has warned that additional attackers may still target unpatched wallets. Sweep rates above 1.0 wallet drain per Bitcoin block should be treated as a signal of active exploitation.

Mixing and laundering acceleration. A separate attacker had begun mixing 64 BTC as of August 5. Movement from the larger 1,159 BTC cluster toward mixers or cross-chain services will narrow the investigative window significantly.

Fourth-wave confirmation. Galaxy has not yet confirmed 448.7 BTC in a suspected fourth wave. Victim reports validating those losses would push the confirmed total to approximately 2,055 BTC and expand regulatory coordination.

Advertisement

Hardware wallet certification reform. Percoco’s call for mandatory independent entropy testing now has a documented failure to anchor it. Watch for proposals from NIST, BSI, or hardware wallet industry bodies to incorporate end-to-end RNG validation into certification.

Coordinated AI audit disclosures. Vendors are remediating the 85 critical findings on rolling timelines. Each public disclosure will clarify which wallet implementations beyond Coldcard carry entropy handling weaknesses.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. All information is provided as general context and should not be relied upon as the basis for any investment or custody decision. Cryptocurrency assets carry significant risk, including total loss of principal. Readers should verify all information independently and consult qualified professional advisors before taking action based on the contents of this article. August 7, 2026.

Advertisement

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

U.S. Senate opens first stage of crypto Clarity Act voting to give bill a chance next month

Published

on

U.S. Senate opens first stage of crypto Clarity Act voting to give bill a chance next month

The U.S. Senate is finally leaping into the first procedural votes on the crypto Digital Assets Market Clarity Act, after the leadership moved early Saturday to start official floor action on the crypto market structure bill, marking the farthest progress yet for the industry’s central policy effort.

But this key advance announced after a marathon overnight voting session comes after the bill has missed its window to get a vote before the Senate’s summer break, leaving it in a long-shot position to get approval in September. Though the Clarity Act’s chances are hanging by a thread, it would likely have been declared dead for 2026 without at least this first important movement.

“We, the undersigned senators … hereby move to bring to a close debate on the motion to proceed to calendar number 423, [House Resolution] 3633, an act to provide for a system of regulation of the offer and sale of digital commodities by the Securities and Exchange Commission and the Commodity Futures Trading Commission, and so forth and for other purposes,” the clerk said reading the filing.

Source link

Advertisement
Continue Reading

Crypto World

US Treasury Sanctions Two Iranian Crypto Exchanges Over IRGC Money Laundering

Published

on

How Much Has the Iran War Cost the US? Defence Secretary Puts a Number on It

The US Treasury sanctioned two Iranian digital asset exchanges, Shelbit and Aban Tether, along with network operator Siavash Kayvanpour, over crypto transfers tied to Iran’s Islamic Revolutionary Guard Corps (IRGC).

The Office of Foreign Assets Control (OFAC) issued the designations on Friday. The designations mark the latest US strike on Iran’s crypto rails this year.

How The Shelbit Network Moved Crypto

IRGC crypto addresses sent more than $1 million into the Shelbit Exchange. Over $2 million then flowed from Shelbit back to Guard wallets, according to OFAC.

Kayvanpour, an Iranian-born operator, ran Shelbit from Georgia and built front companies in Poland and the UAE. His wallets sent more than $2 million to Nobitex, Iran’s largest crypto exchange, which OFAC blocked in June.

Advertisement

OFAC also said Shelbit laundered tens of millions for a Persian-language gambling network. Reuters earlier reported that Shelbit routed $676 million to Binance.

Follow us on X to get the latest news as it happens

Aban Tether and The Iran Sanctions Campaign

Aban Tether, a separate Iran-based exchange, processed millions in transactions with previously blocked platforms Nobitex, Wallex, Bitpin, and Ramzinex. Treasury cited Executive Order 13902, which targets firms operating in Iran’s financial sector.

“Whether in dollars, rials, or crypto, Treasury will hunt down and dismantle illicit financial networks,” Scott Bessent, Treasury Secretary, said.

The move extends the US maximum pressure campaign on Iran, carried out under National Security Presidential Memorandum 2 (NSPM-2). Stablecoin issuers have moved fast on past listings, freezing Iranian wallets after the designation.

Advertisement

Subscribe to our YouTube channel to watch leaders and journalists provide expert insights

The post US Treasury Sanctions Two Iranian Crypto Exchanges Over IRGC Money Laundering appeared first on BeInCrypto.

Source link

Advertisement
Continue Reading

Crypto World

Coinbase CEO says CLARITY delay will not slow crypto adoption

Published

on

CLARITY Act's real obstacle: Trump's crypto business

Coinbase CEO Brian Armstrong said crypto adoption will continue through stablecoins, tokenization and expanding digital asset markets despite the Senate delaying the CLARITY Act.

Summary

  • Armstrong said crypto momentum continues regardless of the congressional timetable.
  • Senate leaders postponed the CLARITY Act vote until September after negotiations failed to produce an agreement.
  • Stablecoin rewards, political ethics and illicit finance safeguards remain central points of dispute.
  • Coinbase shares closed Friday at $153.60, gaining about 5.7% during the session.

Armstrong points to adoption beyond Congress

Armstrong described the Senate’s failure to advance the CLARITY Act before its August recess as disappointing but argued that the delay had not stopped companies and consumers from adopting digital assets.

In an Aug. 7 post on X, the Coinbase executive pointed to increased stablecoin use, developing markets for tokenized real-world assets and broader access to perpetual futures. He also said regulators were already providing companies with greater clarity in some areas.

Advertisement

“The momentum behind this technology keeps growing with or without a congressional calendar,” Armstrong said.

Advertisement

His remarks separated the industry’s commercial growth from the legislative timetable. Companies can continue building products under existing rules, but Armstrong maintained that Congress still has an important role in creating a consistent federal framework.

Clear legislation could encourage investment and employment while providing stronger protections for U.S. consumers, according to the Coinbase CEO.

CLARITY Act vote moves to September

Senate Majority Leader John Thune said the bill would be queued when lawmakers return from recess. As crypto.news reported, the Senate postponed consideration after Democrats declined to support an accelerated pre-recess process.

The legislation needs 60 votes to overcome the Senate’s cloture threshold. Republicans therefore require support from at least seven Democrats, assuming every Republican senator backs the measure.

Advertisement

Democratic lawmakers have sought stronger provisions covering political conflicts of interest, consumer protection, illicit finance and market integrity. Negotiations over restrictions involving President Donald Trump’s crypto interests have become one of the main obstacles.

Senator Elizabeth Warren has also rejected the current CLARITY Act, arguing that it does not adequately address corruption, national security and risks to consumers.

Stablecoin rewards remain a Coinbase concern

The CLARITY Act would divide oversight between the Securities and Exchange Commission and Commodity Futures Trading Commission. It would also establish federal rules for crypto exchanges, brokers, dealers, advisers and qualified digital asset custodians.

Stablecoin rewards remain particularly important for Coinbase. The latest draft generally prohibits companies from paying interest or yield solely for holding payment stablecoins. It may continue allowing rewards tied to activities such as payments, remittances, liquidity provision, staking and loyalty programs.

Advertisement

Armstrong previously supported that compromise, saying banks and crypto companies had preserved their central priorities. However, several banking groups argued that permitted rewards could still draw deposits away from traditional financial institutions.

The outcome could affect Coinbase’s USDC business. A recent crypto.news analysis estimated that the exchange generates about $1.35 billion annually through its USDC rewards arrangement.

Tokenization supports Armstrong’s adoption argument

Recent institutional activity provides evidence for Armstrong’s broader tokenization claim. BlackRock launched two tokenized money-market products holding cash, short-term U.S. Treasuries and Treasury-backed repurchase agreements.

The Depository Trust and Clearing Corporation is also preparing to launch a tokenization service in October. Its industry working group has expanded to more than 100 members and partners, including Nasdaq, Charles Schwab, BlackRock and Circle.

Advertisement

As crypto.news reported, DTCC completed production transactions in July involving tokenized Treasuries, equities, collateral, securities lending and margin processes. The trials used securities already held within established U.S. market infrastructure.

Coinbase shares also rose alongside the broader adoption narrative. COIN closed Friday at $153.60, up approximately 5.7% for the session, although the move cannot be attributed solely to Armstrong’s remarks or the CLARITY Act outlook.

What comes next for the CLARITY Act

Attention now turns to whether Senate negotiators can resolve their differences during the August recess. Thune has committed to prioritizing the legislation when lawmakers return, but a floor vote has not been formally scheduled.

The remaining negotiations will determine whether the bill can secure enough Democratic support without losing Republican votes. Ethics restrictions, illicit finance controls, consumer safeguards and stablecoin rewards are likely to remain central to those talks.

Advertisement

A September vote would still represent only one stage of the process. Any Senate version would need to be reconciled with the measure previously passed by the House before it could reach the president.

Armstrong’s comments suggest Coinbase expects crypto adoption to continue during that process. However, the delay leaves U.S. companies without the unified federal market structure the legislation is intended to create.

Advertisement

Source link

Continue Reading

Crypto World

Ondo founder’s mother seeks CEO ouster in Delaware

Published

on

Ondo founder’s mother seeks CEO ouster in Delaware

Ondo Finance is facing a corporate control battle in Delaware after Kathleen Allman, mother of late founder Nathan Allman, sued to remove Ian De Bode as chief executive and establish authority over the company. 

Summary

  • Kathleen Allman seeks control of Ondo and removal of CEO Ian De Bode in Delaware.
  • Three Delaware Chancery filings ask judges to determine lawful control and preserve Ondo’s status quo.
  • De Bode calls the estate’s allegations meritless and says key stakeholders continue supporting current leadership.
  • Ondo’s website still identifies Ian De Bode as chief executive while the Delaware dispute continues.
  • Allman’s estate gained voting authority after Kathleen became personal representative in Hawaii on June 26.

The complaint was filed July 24 in the Delaware Court of Chancery, roughly two months after Ondo announced Allman’s death and said De Bode would assume the CEO role.

The dispute centers on who lawfully controls Ondo after Allman’s death. Kathleen Allman argues that, as personal representative of her son’s estate, she controls his voting interest and therefore had authority to reconstitute the board. De Bode rejects those claims, calling them “meritless” and saying current leadership retains support from key stakeholders, lead investors and the Ondo Foundation.

Advertisement

Allman’s estate says it controls Ondo’s voting power

According to the complaint, Nathan Allman was serving as Ondo’s CEO and a director when he died. The filing says the company’s second board seat was vacant, leaving no sitting directors after his death. Kathleen Allman was later appointed personal representative of his estate by a Hawaii court, which she says gave her authority to exercise the voting rights attached to his shares.

Advertisement

The estate says Kathleen used that authority to appoint herself as sole director before expanding the board. She later appointed Tahnee Towill, Nathan Allman’s sister, while another proposed director, Gordon Liao, declined the appointment for reasons described as unrelated to the dispute. On July 24, Kathleen Allman and Towill voted to remove De Bode from officer, employee and consultant positions and appointed Kathleen as chair, CEO, secretary and treasurer.

De Bode disputes the attempted removal

De Bode has rejected the estate’s account and continues to identify himself as Ondo’s CEO. He told The Block that Kathleen Allman’s allegations are “meritless” and said the company continues to have backing from important investors, other stakeholders and the Ondo Foundation. Those assertions remain contested and have not been confirmed by a court ruling.

Ondo’s official leadership page also continued to list De Bode as chief executive as of Aug. 7. In a June 1 company statement, De Bode said he was stepping into the CEO role following Allman’s death and that Ondo’s existing leadership team and roadmap would continue. As previously reported, Ondo announced De Bode’s succession shortly after confirming its founder had died in late May.

The dispute arrives during Ondo’s U.S. expansion

The corporate fight comes while Ondo is expanding its tokenized securities business and engaging with U.S. regulators. In related coverage, Ondo has continued building products tied to tokenized stocks, exchange traded funds and U.S. Treasury exposure, placing the company among the more visible firms in the real world asset market.

Advertisement

Ondo also submitted a no action request to the U.S. Securities and Exchange Commission in April seeking regulatory relief for a structure using Ethereum to record tokenized security entitlements while established broker dealer records remain authoritative. The SEC published the submission through its Crypto Task Force portal, confirming that Ondo is actively pursuing a framework for blockchain based securities infrastructure.

What happens next in the Ondo control case

The Delaware Court of Chancery must now determine which side has lawful authority over Ondo’s board and executive leadership. Reporting on the dispute indicates that three filings ask the court to resolve control questions and preserve the company’s status quo while litigation continues. As of Aug. 7, no published ruling had settled the dispute.

The court may need to consider the legal effect of Nathan Allman’s estate ownership, the validity of Kathleen Allman’s written stockholder consent and the authority behind De Bode’s appointment. Until a ruling or settlement changes the position, the public record remains divided: the estate says De Bode was removed, while Ondo’s current public materials continue to identify him as CEO.

The dispute also raises practical questions over who can authorize major corporate actions while litigation remains active. Kathleen Allman’s side has argued that uncertainty could affect contracts, spending, equity issuances and other decisions. De Bode, meanwhile, says current management remains focused on operations and preserving Nathan Allman’s vision for the company.

Advertisement

No verified evidence reviewed for this report showed that the governance fight had disrupted Ondo’s tokenized products, changed the backing of its assets or altered the legal status of the ONDO governance token. The immediate development to watch is therefore the Delaware proceeding, where a ruling, negotiated settlement or later corporate filing could clarify who controls the company and who can lawfully serve as its chief executive during this period.

Source link

Advertisement
Continue Reading

Crypto World

CLARITY Act Senate vote delayed until September

Published

on

Santiment flags Bitcoin euphoria after CLARITY win

U.S. Senate leaders have postponed a planned vote on the CLARITY Act until September, pushing a major crypto legislative priority beyond the August recess. 

Summary

  • Senate leaders postponed the CLARITY Act vote until September after Democrats withheld pre-recess procedural support.
  • Thune said the crypto market structure bill will be queued when senators return in September.
  • The bill still needs bipartisan backing to clear the Senate’s 60-vote threshold and advance further.
  • Democrats continue seeking stronger ethics rules covering officials’ crypto interests alongside changes to enforcement provisions.
  • Senate Banking advanced the legislation 15-9 in May before negotiators released merged text in July.

Senate Majority Leader John Thune confirmed the delay late Aug. 6, saying Democrats would not agree to bring the bill up before lawmakers leave Washington in the chamber.

Thune said the measure would be “queued” for consideration when senators return. His comments reverse earlier expectations from Senate Banking Committee Chair Tim Scott, who wanted a vote before recess. The delay raises pressure on both parties to reach agreement before spending fights and the 2026 midterm campaign crowd the fall calendar.

Advertisement

Democratic opposition blocked the pre-recess vote

Seven Democratic senators rejected the Republican draft on July 22, saying provisions on ethics, consumer protection, illicit finance, conflicts of interest and market integrity needed strengthening. The group included Angela Alsobrooks and Ruben Gallego, the two Democrats who had joined Republicans to advance the legislation through the Senate Banking Committee.

Advertisement

That opposition matters because Senate leadership needs 60 votes to invoke cloture and overcome a filibuster. Republicans therefore require Democratic support to advance the bill. Politico reported that Democrats also declined to approve a time agreement that would have accelerated remaining Senate business before recess, making it harder to fit the CLARITY Act onto the floor schedule.

The ethics fight remains difficult. Democrats have pushed for tougher restrictions involving elected officials’ crypto interests, including concerns tied to President Donald Trump and his family’s digital asset businesses. Reuters reported that a proposed divestiture approach remained under negotiation with the White House. Any such requirement is still a proposal and has not been enacted.

CLARITY Act already cleared major Senate hurdle

The postponement comes after months of legislative progress. The House passed H.R. 3633 by a 294-134 vote in July 2025. The Senate Banking Committee then advanced an amended version 15-9 on May 14, 2026, with all committee Republicans and two Democrats supporting it.

Senator Cynthia Lummis released updated merged text on July 22 combining work from the Banking and Agriculture committees. The legislation would establish a federal market structure for digital assets and divide oversight responsibilities between the Securities and Exchange Commission and Commodity Futures Trading Commission. It also includes provisions covering stablecoin rewards, anti-money laundering controls, decentralized finance and tokenized securities.

Advertisement

As previously reported, the bill’s Senate math had already made Democratic votes central to its prospects. law enforcement groups also pressed lawmakers over developer protections and investigative powers before some organizations later backed revised language. Those disputes remain part of the negotiations surrounding the final package.

September creates a tighter political window

Thune’s decision does not kill the bill. He said Republicans intend to bring it back when the Senate returns in September. However, the delay removes the clean legislative window supporters had spent months targeting and places the measure closer to the November midterm elections.

The Senate could still take procedural action before leaving, including filing cloture to prepare a later vote. Politico reported that Thune had not confirmed whether he would take that step. Filing cloture would not pass the CLARITY Act by itself, but it could help position the legislation for floor consideration when senators reconvene.

September also leaves negotiators with unresolved disagreements beyond ethics. Democrats have sought changes related to law enforcement concerns and the commodities portion of the legislation. Banking interests and crypto companies have separately fought over rules governing rewards on stablecoin balances, although the July draft attempted to distinguish passive interest from transaction-based rewards.

Advertisement

What happens next for the CLARITY Act

The next major deadline is the Senate’s return in September. Lawmakers will need to determine whether negotiators can produce language capable of attracting enough Democratic support for cloture while keeping Republican backing intact. Thune’s statement indicates leadership intends to prioritize the bill, but that timetable remains a political commitment rather than a scheduled vote.

Even Senate passage would not finish the process. Because senators have amended the House-passed legislation, the chambers would still need to resolve differences before a final version could reach President Trump. That leaves limited time for floor debate, reconciliation and another congressional vote before the midterm election period intensifies.

For now, the CLARITY Act remains the most advanced comprehensive U.S. crypto market structure proposal in Congress, but its timeline has shifted again. The August push ended without a floor vote, and the September session now becomes the next test of whether bipartisan negotiations can turn committee-level support into enough votes for final Senate action.

Advertisement

Source link

Continue Reading

Crypto World

Thailand’s 0% crypto tax raises stakes in global capital…

Published

on

Thailand’s 0% crypto tax raises stakes in global capital...

Thailand’s five-year crypto tax exemption has returned to the spotlight after Binance founder Changpeng Zhao drew fresh attention to the policy this week, prompting new claims that the country has become a “0% crypto tax haven.” 

Summary

  • Thailand exempts qualifying individual crypto gains through 2029 when transactions use locally licensed asset operators.
  • Ministerial Regulation No. 399 became law in September 2025 but applies retroactively from January 2025.
  • Unlicensed offshore exchanges, staking rewards, mining income and corporate profits are not automatically tax exempt.
  • Thailand’s SEC continues tightening local oversight while developing crypto ETFs, derivatives and custody infrastructure nationwide.
  • Americans abroad generally remain subject to U.S. tax on worldwide income, including taxable crypto gains.

The exemption is real, but it is neither new nor unlimited. Thailand’s Cabinet approved the measure on June 17, 2025, and Ministerial Regulation No. 399 was published in the Royal Gazette on September 5, 2025.

The rule exempts qualifying personal income derived from gains on cryptocurrency and digital-token transfers from January 1, 2025, through December 31, 2029. Crucially, the transaction must take place on a digital asset exchange, through a broker, or with a dealer licensed under Thai law. That condition makes the policy less a blanket tax holiday than an incentive to move trading activity into Thailand’s supervised market.

Advertisement

Advertisement

Thailand’s 0% crypto tax is an existing five-year rule

Thailand’s Ministry of Finance described the measure as part of a plan to establish the country as a global “Digital Asset Hub.” The Cabinet approved the principle in June 2025, while the final regulation entered the legal framework months later. Because the rule applies to assessable income received from the start of 2025, its tax benefit reaches back to January even though the regulation itself was published in September.

The Revenue Department’s current regulation now includes the exemption added by Regulation No. 399. It covers the benefit above an investor’s cost from transferring cryptocurrency or digital tokens through eligible licensed operators. The wording matters because the rule concerns qualifying gains from transfers; it does not, by its terms, erase tax on every type of crypto-related income.

That means descriptions of Thailand as universally “tax free” for crypto can mislead. Staking rewards, mining income, employment paid in tokens, business receipts and corporate profits are not automatically covered by the transfer-gain exemption. Their treatment depends on other Thai tax rules and the taxpayer’s facts. Residency, source of income and cross-border obligations can also change what a person ultimately owes.

The government’s objective is broader than reducing an individual trader’s bill. In its June 2025 statement, the Finance Ministry said the policy was intended to channel trading through Thai operators supervised by the Securities and Exchange Commission and anti-money-laundering authorities. It also said the change could increase economic activity and deliver “not less than 1 billion baht” in additional tax revenue over the medium term. That figure is a government forecast, not a verified outcome.

Advertisement

Licensed exchanges are the gatekeepers to the tax break

The biggest practical condition is where a qualifying disposal occurs. Thailand’s SEC maintains a current register of licensed digital asset exchanges, brokers and dealers. The exemption applies to transfers conducted within those regulated categories, giving domestic licensed firms a clear advantage over offshore venues that do not hold Thai authorization.

That structure fits Thailand’s wider enforcement approach. In 2025, regulators moved to block access to several unlicensed foreign exchanges, as previously reported. In April 2026, the SEC again warned investors ahead of the blocking of Exmix, saying the platform lacked a required Thai digital asset license. The message is consistent: Thailand wants crypto trading, but it wants more of that activity routed through entities it can supervise.

Thailand’s five-year crypto capital-gains exemption was announced in June 2025 with the same licensed-operator condition. The renewed social-media attention in August 2026 therefore does not represent a new Cabinet decision or an extension beyond 2029. It is a rediscovery of a policy that has been in force for more than a year.

The regulatory perimeter is still evolving. In May 2026, the SEC proposed changes to net-capital and custody rules that it said would support more local trading and customer-asset custody while reducing reliance on foreign service providers. That proposal reinforces the economic logic behind the tax break: lower the tax cost for eligible individuals while building more of the trading, custody and compliance stack inside Thailand.

Advertisement

Thailand is opening crypto markets without removing controls

The tax exemption sits alongside other measures intended to expand regulated digital assets. In April, the SEC opened a consultation on a domestic crypto ETF framework, covering fund management, trustees and other operational requirements. Thailand has also moved toward crypto derivatives and tokenized-asset infrastructure, giving regulated institutions more ways to participate without opening every activity to unrestricted use.

At the same time, Thailand has not adopted crypto as ordinary money. Bank of Thailand policy continues to discourage digital assets as a broad means of payment for goods and services, and SEC rules restrict digital asset businesses from facilitating that use outside approved frameworks. This distinction is important because a favorable investment tax policy does not amount to unrestricted crypto commerce.

TouristDigiPay shows how the government is trying to bridge those positions. As crypto.news reported, the program lets eligible foreign visitors convert digital assets into baht before spending through Thailand’s QR payment infrastructure. Merchants receive local currency rather than crypto. The model expands crypto-linked activity while keeping the final payment inside the regulated baht system.

Regulatory tightening is continuing in August. SEC KYC and customer-monitoring guidelines are due to take effect on August 16, 2026, requiring stronger beneficial-owner checks, source-of-funds review and transaction monitoring. In June, the regulator also proposed a digital-asset Travel Rule for transfer data.

Advertisement

Thailand’s approach is therefore best understood as regulated onshoring. The state is using tax relief, licensed exchanges, ETF development, tokenization projects and controlled payment experiments to attract capital while preserving supervision. That is different from a classic tax haven model built mainly around secrecy or minimal oversight. Thailand’s Finance Ministry has also said the Revenue Department is working toward the OECD Crypto-Asset Reporting Framework, which is designed to increase cross-border tax-data exchange.

Moving to Thailand does not erase U.S. crypto taxes

The contrast with the U.S. is clearest at the individual tax level. The Internal Revenue Service treats digital assets as property. When a taxpayer sells digital assets for dollars or similar currency, the IRS says the sale generally produces a recognizable capital gain or loss. Taxpayers must report taxable digital asset transactions even when they do not receive an information form.

For U.S. citizens and resident aliens, relocating does not automatically change that federal obligation. Updated IRS guidance states that citizens and resident aliens living abroad are generally subject to U.S. tax on worldwide income. A U.S. citizen living in Bangkok could therefore qualify for a Thai exemption on an eligible transaction and still face U.S. reporting or tax obligations, depending on the circumstances.

That makes social-media claims that American traders can simply move to Thailand and pay no tax especially risky. The Thai exemption determines Thai treatment for qualifying gains under Thai rules. It does not override another country’s tax law. Anyone considering relocation would also need to account for residence tests, foreign-account reporting, treaty rules and the nature of each transaction.

Advertisement

Still, the policy creates a competitive contrast. Thailand has chosen a direct, time-limited tax incentive tied to local regulatory participation. The U.S. continues taxing digital asset gains while pursuing crypto policy through securities rules, reporting requirements and market-structure legislation. CLARITY Act has moved through the Senate process but remains subject to political negotiation, showing that the two countries are competing through very different policy tools.

The harder question is whether Thailand can turn a temporary tax advantage into durable industry growth. The exemption expires after December 31, 2029, unless policymakers extend or replace it. Exchanges and traders can respond quickly to tax incentives, but companies making long-term decisions about offices, hiring, custody and infrastructure need confidence about what follows the expiration date.

FAQs

Is crypto really taxed at 0% in Thailand?

Qualifying individual gains from cryptocurrency and digital-token transfers can be exempt from Thai personal income tax through December 31, 2029. The transaction must use an exchange, broker or dealer licensed under Thai digital asset law. The rule is not a blanket exemption for every form of crypto income.

Does the exemption cover offshore exchanges?

Not automatically. Regulation No. 399 ties the exemption to transfers conducted on licensed digital asset exchanges, through licensed brokers or with licensed dealers. Traders using offshore or unlicensed venues should not assume those gains qualify simply because they live in Thailand.

Advertisement

Can a U.S. citizen move to Thailand and avoid crypto tax?

Not simply by relocating. The IRS generally taxes U.S. citizens and resident aliens on worldwide income, including taxable digital asset gains. Thailand’s exemption may change the Thai tax result for qualifying transactions, but it does not cancel separate U.S. federal obligations.
The more defensible conclusion is that Thailand has created a strong incentive for regulated crypto activity rather than an unrestricted tax haven. The policy can lower Thai personal tax on qualifying gains, but its licensed-platform condition, reporting framework and 2029 expiration remain central to how valuable it is for traders, exchanges and builders.

Source link

Advertisement
Continue Reading

Crypto World

XRP price falls 2% as CLARITY Act vote slips to September

Published

on

XRP price chart, source: crypto.news

XRP traded near $1.03 on Aug. 7 as selling pressure kept the token among the weaker large-cap cryptocurrencies ahead of fresh U.S. labor data.

Summary

  • XRP traded near $1.03, down about 2.2% as selling pressure persisted across major exchanges today.
  • Binance XRP open interest rose roughly 8% while perpetual CVD moved deeper into negative territory.
  • Spot CVD fell more than 52%, showing a sharp decline in aggressive centralized exchange buying.
  • Whales accounted for 81% of Binance XRP outflows, versus 72% across centralized exchanges overall globally.
  • Senators return September 14, while July employment data arrives August 7 before inflation data Wednesday.

According to crypto.news market data, XRP dropped about 2.2% over 24 hours, compared with smaller moves in Bitcoin and Ether, while its market capitalization remained near $64.2 billion.

crypto.news showed XRP down 5.7% over seven days and 6.7% over 30 days. Trading volume was approximately $1.44 billion, with circulating supply near 62.53 billion tokens.

Advertisement

The decline came as the U.S. Senate pushed consideration of the CLARITY Act beyond its August recess. Senate Majority Leader John Thune said the bill would be queued when lawmakers return in September. The delay removes an expected near-term regulatory catalyst, although XRP’s price move cannot be attributed to legislation alone.

XRP price tests $1 support as momentum stays weak

XRP traded between roughly $1.01 and $1.06 over the previous 24 hours, leaving the psychological $1 level as immediate support. The daily chart remains broadly bearish after a prolonged decline from above $2.50, while a recovery above $1.10 to $1.15 would be needed to improve the short-term structure.

The Aroon Oscillator at -100 shows recent lows dominating recent highs. BBTrend was also negative near -1.36, reinforcing the bearish bias, although its smaller negative bars suggest downside momentum is less intense than during earlier selloffs. On the weekly chart, Stochastic RSI readings near 42.6 and 44.7 remain neutral rather than oversold.

Advertisement
XRP price chart, source: crypto.news
XRP price chart, source: crypto.news

A widely circulated projection from CryptoBull suggested XRP could reach “$27 by the end of October 2026.” That target remains highly speculative. The weekly ascending-channel projection also points toward $7 before $27, but neither level is confirmed without a sustained breakout above long-term resistance and stronger volume.

Derivatives data shows traders leaning toward shorts

CryptoQuant analyst Amr Taha reported that Binance XRP open interest rose from about $180 million on Aug. 4 to $195 million on Aug. 7, an increase of roughly 8%. Over the same period, perpetual cumulative volume delta fell from approximately negative $292 million to negative $363 million.

Source: CryptoQuant analyst Amr Taha
Source: CryptoQuant analyst Amr Taha

That combination is consistent with fresh leveraged sell-side positioning, although open interest alone cannot determine the direction of every new position. Spot demand also weakened. Taha said estimated spot CVD across centralized exchanges fell more than 52%, from around $235 million to $112 million, indicating a sharp loss of aggressive buying momentum.

Separate CryptoQuant data showed whales accounted for 81% of Binance XRP outflows on Aug. 3, versus 72% across centralized exchanges overall. The metric measures the share of outflow activity, not absolute withdrawal volume or whether transferred tokens were ultimately accumulated, sold or moved into custody.

CLARITY Act delay removes an August catalyst

The Senate’s decision to postpone the market-structure vote matters to XRP because the bill could provide statutory rules for determining when digital assets fall under SEC or CFTC oversight. In earlier regulatory analysis, the legislation was identified as especially relevant to XRP after years of litigation over its regulatory treatment.

The bill faces a procedural hurdle before final passage. Republicans hold 53 Senate seats, but leadership generally needs 60 votes to invoke cloture and overcome a filibuster. As previous Senate vote coverage explained, Democratic support has therefore remained central to the legislation’s path.

Advertisement

The official Senate calendar lists Aug. 10 through Sept. 11 as a state work period, meaning senators are scheduled to return Sept. 14. Ethics provisions, law-enforcement concerns and other market-structure disputes remain unresolved, leaving any September vote dependent on further negotiations.

U.S. jobs and inflation data add another risk

Macro conditions could influence XRP before lawmakers return. The Federal Reserve held its target range at 3.50% to 3.75% on July 29 in a 9-3 vote. Beth Hammack, Neel Kashkari and Lorie Logan dissented because they preferred a 25-basis-point increase.

The timing makes macro data relevant because XRP is trading near support while leverage rebuilds. Still, economic releases can move crypto in either direction, and no report guarantees a specific response.

The next immediate test is the July employment report, scheduled by the BLS for Aug. 7 at 8:30 a.m. ET. July CPI follows on Aug. 12. Strong employment or persistent inflation could reinforce expectations for restrictive policy, while softer readings could reduce rate pressure across risk assets.

Advertisement

For XRP, $1 remains the near-term technical level to watch. A break below it would weaken the current structure, while recovery through $1.10 to $1.15 would provide the first clearer sign of stabilization. Derivatives positioning, spot demand and September’s CLARITY negotiations remain additional variables rather than guaranteed directional catalysts.

Disclosure: This article does not represent investment advice. The content and materials featured on this page are for educational purposes only.

Advertisement

Source link

Continue Reading

Crypto World

Microsoft flags ClickFix malware using BNB Chain to fetch attack instructions

Published

on

Ripple-backed OUSD launch hit by fake issuer scam on XRP Ledger

Microsoft has warned of ClickFix attacks using BNB Chain smart contracts to infect thousands of devices every day.

Summary

  • Microsoft said ClickFix attacks are using BNB Chain smart contracts to deliver malware instructions.
  • Fake CAPTCHA pages trick users into running attacker supplied commands on Windows devices.
  • The campaign targets thousands of enterprise and consumer devices worldwide every day.
  • Microsoft warned successful attacks can expose credentials and lead to ransomware deployment.

According to Microsoft Threat Intelligence, a cluster of compromised websites has been using ClickFix lures together with the EtherHiding technique to deliver malware, with campaigns targeting thousands of enterprise and consumer devices worldwide each day.

The security team said attackers inject Base64-encoded JavaScript into compromised websites. Instead of retrieving payload instructions from a traditional server, the script connects to a BNB Smart Chain RPC gateway and queries a smart contract previously linked to the ClearFake campaign.

Because only the owner of the cryptocurrency wallet that deployed the contract can modify its contents, the instructions remain difficult to remove using conventional takedown or sinkholing methods.

Microsoft said victims are shown a fake CAPTCHA asking them to verify they are human. Instead of completing a normal verification step, users are instructed to open the Windows Run dialog, paste clipboard content, and press Enter, executing an attacker-controlled command on their own systems.

Advertisement

ClickFix campaign has used blockchain to deliver attack instructions

While the fake CAPTCHA acts as the lure, the report said attackers rely on several command obfuscation methods to avoid detection after execution. Microsoft observed the abuse of Windows tools including conhost, cmd, PowerShell, pcalua, mshta, rundll32, msiexec, curl, WMI, WebDAV, and scheduled tasks.

Researchers also identified multiple techniques designed to hide malicious commands. Caret characters split keywords, environment variables conceal interpreters, and Windows processes run in minimized or headless mode to reduce visibility during execution.

Alongside ClickFix, Microsoft said attackers are also deploying TerminalFix lures. Rather than directing victims to the Windows Run dialog, TerminalFix instructs users to paste commands into Windows Terminal or PowerShell, using the same social engineering method to trigger the attack.

Advertisement

The report described ClickFix and TerminalFix as high-volume initial access techniques. Microsoft said it is tracking campaigns targeting thousands of enterprise and consumer devices globally every day, while some malvertising chains also redirect users to scam pages before the malicious instructions are delivered.

Malware can lead to credential theft and ransomware attacks

According to the report, numerous threat actors have adopted the technique to distribute several malware families after gaining initial access. Microsoft identified Lumma Stealer and other information stealers, Xworm and AsyncRAT remote access trojans, MintsLoader, and remote management tools among the payloads delivered through ClickFix campaigns.

Researchers warned that a single successful execution can expose credentials, establish persistence on infected systems, enable lateral movement across networks, and create a path for human-operated ransomware attacks and possible domain compromise.

To reduce the risk, Microsoft recommended enabling Microsoft Defender network, web, and cloud-delivered protection, restricting access to the Windows Run dialog and other command-line tools where they are not required, enabling PowerShell script-block logging, and enforcing application control policies.

Advertisement

The company also advised users not to paste commands from fake CAPTCHAs, browser error pages, advertisements, unsolicited support pages, or emails into Windows Run, Terminal, PowerShell, or Command Prompt because attackers increasingly rely on convincing users to execute malicious commands themselves.

Defender detections target ClickFix activity

Microsoft said Microsoft Defender XDR provides layered protection across different stages of the attack chain. According to the company, Defender SmartScreen and Defender for Office 365 can help block malicious websites, phishing links, infected attachments, and fake CAPTCHA pages before users interact with them.

The security platform also detects suspicious command execution and outbound connections using alerts including “Suspicious command in RunMRU registry,” “Possible ClickFix activity,” and “Possible initial access from an emerging threat.”

Meanwhile, Microsoft Defender Antivirus identifies malicious command execution under detections such as Trojan:Win32/ClickFix.* and Trojan:Win32/TermFix.*. The company said organizations should treat these detections as possible indicators of an initial access incident, isolate affected devices, investigate potential credential theft and persistence mechanisms, and search for related activity across their environments.

Advertisement

Previous Microsoft warning highlighted crypto-focused malware

The latest findings follow another Microsoft Threat Intelligence report published in June that described a Windows-based CryptoBandits clipper campaign active since February 2026.

According to the report, the malware spread through malicious .lnk shortcut files, monitored the clipboard every 500 milliseconds for cryptocurrency wallet addresses, seed phrases, and private keys, and replaced copied wallet addresses with attacker-controlled ones. 

Researchers also found the malware routing communications through the Tor network, creating scheduled tasks for persistence, capturing screenshots, and executing attacker-supplied code, effectively giving operators lightweight backdoor access.

Microsoft said at the time that defenders should investigate combinations of suspicious behavior rather than isolated events, particularly when script engines launched tools such as curl, cmd.exe, or PowerShell alongside Tor-related traffic.

Advertisement

The previous warning came as crypto-related malware campaigns continued to evolve. As previously reported by crypto.news, StilachiRAT targeted browser-based cryptocurrency wallets and monitored clipboard activity, while SparkCat searched screenshots for wallet seed phrases using image scanning. Binance also warned users about clipper malware designed to replace copied cryptocurrency wallet addresses with attacker-controlled alternatives.

Source link

Advertisement
Continue Reading

Crypto World

Bitcoin Bear Market Over? Top Analysts Turn Bullish, but History Says Otherwise

Published

on

Ever since bitcoin started plunging real hard at the start of the new year and dumped to and eventually below $60,000, analysts have been focused on trying to determine where the bottom is. As usual, they are split into two camps: two who believe another crash is coming, and the optimists indicating that the worst is behind us.

Crypto X, though, was a little surprised on Friday when three analysts showed an interesting and unexpected convergence, with Ali Martinez, Michaël van de Poppe, and Merlijn The Trader posting opinions that essentially determined BTC is about to break out.

Analysts Turn Bullish

Martinez emerged as arguably the most bullish, highlighting several factors that have aligned for his major breakout call. He noted that improving on-chain data and technical indicators suggest that BTC has likely established a local bottom. He added that selling pressure has faded, while long-term accumulation continues. The combination creates favorable conditions that have historically preceded meaningful upside moves.

The analyst explained that the TD Sequential flashed a major buy signal on BTC’s monthly chart in July, which is a rare signal that successfully identified the last market bottom in 2022.

Advertisement

Van de Poppe echoed the statement, reaching a similar conclusion from a macro perspective. He argued that BTC’s decline toward $60,000 resembles previous bull-market corrections, which often shook out leveraged traders before the broader uptrend resumed.

In his view, similar moves were a healthy reset rather than the deepening of a bear market, with liquidity returning and buyers gradually stepping back in. Merlijn The Trader, on the other hand, commented that the cryptocurrency has completed a classic breakdown-and-reclaim pattern that frequently marks the end of corrections.

Too Good to Be True?

The scenario above sounds appealing, right? But there’s also the other side of the coin, and BTC’s history suggests investors should remain cautious whenever the market speaks with such firm conviction. One of the asset’s defining characteristics over the past decade has been its tendency to inflict maximum pain on the majority. It has moved time and time again precisely in the opposite direction of prevailing expectations.

Advertisement

Some of the most significant rallies came after market shocks: the run after the COVID-19 crash, the aftermath of the FTX collapse in late 2022, and so on. In contrast, it has slumped once the market has become too greedy and optimistic: recall the October 2025 crash and subsequent 55% correction.

Of course, this doesn’t necessarily mean that the aforementioned analyses are wrong. Many of the factors they named are objectively constructive and promising. However, markets rarely reward the obvious trade.

Don’t get us wrong – we remain BTC bulls. But we would also like to caution everyone who might go all in just because the sentiment among some top analysts has flipped.

The post Bitcoin Bear Market Over? Top Analysts Turn Bullish, but History Says Otherwise appeared first on CryptoPotato.

Advertisement

Source link

Continue Reading

Crypto World

IMF Says Domestic Stablecoins Could Lift Demand for Dollar Tokens

Published

on

Crypto Breaking News

Plans to issue stablecoins denominated in local currencies to reduce reliance on dollar-linked tokens may unintentionally make it easier to move value into “digital dollars,” according to a senior International Monetary Fund (IMF) official.

Speaking on Friday, IMF First Deputy Managing Director Dan Katz said that once local- and dollar-denominated stablecoins run on the same underlying blockchain infrastructure, users could swap between them through decentralized exchanges, liquidity pools, or peer-to-peer mechanisms.

Key takeaways

  • IMF First Deputy Managing Director Dan Katz warned that local-currency stablecoins could still funnel users into dollar stablecoins if both use the same blockchain rails.
  • Katz said cross-stablecoin interoperability could shift foreign-exchange activity away from traditional intermediaries like banks and currency dealers.
  • He suggested this dynamic could reduce friction in capital movement, affecting how authorities monitor and manage flows.
  • Katz noted adoption outcomes may differ by country, with local tokens potentially replacing dollar holdings in highly dollarized economies.
  • He urged regulators to enable compliant onramps, offramps, and onchain exchange points to manage risks.

How shared blockchain infrastructure could enable “digital dollar” access

Katz’s core point is about infrastructure. In his remarks—delivered in a speech at the University of Cape Town—he argued that if local-currency stablecoins and dollar-backed stablecoins are deployed on the same blockchain framework, the practical barriers to conversion could fall sharply.

That matters because, in decentralized finance environments, conversion does not require a single centralized issuer or intermediary to broker every transfer. Katz specifically referenced common DeFi routes: decentralized exchanges, liquidity pools, and peer-to-peer swaps. Under that model, users could move between token types directly, turning what begins as local-currency issuance into an easier path to dollar exposure.

Potential implications for FX monitoring and capital-flow tools

The IMF official linked interoperability to a broader policy concern: where foreign-exchange activity happens. Katz argued that moving FX-related activity away from banks and traditional currency dealers could reduce “friction” that authorities currently rely on to monitor and manage capital flows.

Advertisement

In other words, the issue is not only which stablecoin a user holds, but how quickly and through what channels they can reposition into a different currency exposure. If swaps become routine onchain, regulators may find it harder to observe the flow of currency demand through traditional institutional pathways.

At the same time, Katz framed the shift as potentially reinforcing the broader category of FX-focused stablecoins. He said that local-currency stablecoins “might even accelerate the adoption of FX stablecoins,” a statement that underscores the possibility that currency-linked token ecosystems could become more integrated over time rather than remaining siloed.

Adoption unevenness: South Africa as a case study

Katz pointed to South Africa to illustrate how adoption can diverge across token types. He said dollar-backed stablecoins have gained only limited traction there, while rand-linked tokens have attracted even less demand.

He cautioned that it is still too early to draw definitive lessons from any single country, but he offered an explanation for why users might still prefer dollar tokens. In his view, many participants may choose dollar stablecoins due to factors like liquidity, network effects, and cross-platform or cross-border acceptance.

Advertisement

Those characteristics can translate into more efficient trading and easier settlement—particularly in environments where the local currency faces volatility, lower market depth, or weaker confidence in local issuances. Even if a policy objective is to reduce dependence on the dollar, market structure and user preferences can pull activity back toward the most “usable” asset in practice.

Regulatory framing: country risk differences and compliant onchain rails

Katz said risks vary by country. He suggested that in highly dollarized economies, stablecoins may largely substitute for existing dollar holdings rather than creating incremental demand for dollars. But in countries where dollar access is restricted and the economic policy framework is weaker, stablecoins could instead increase foreign-currency demand.

This distinction is important for policymakers because it affects what “success” looks like. If stablecoins mainly repackage dollars already held domestically, the macro impact might differ from a scenario in which stablecoins provide a smoother mechanism to access additional dollar exposure.

To manage these trade-offs, Katz urged authorities to build regulatory frameworks around practical access points. Specifically, he called for authorities to bring onramps, offramps, and onchain exchange points within regulatory boundaries.

Advertisement

The policy takeaway is that banning activity is not the only route. Instead, the IMF official highlighted the need for rule-based access to onchain liquidity and conversion, so regulators can better understand flows and reduce the incentive for unregulated intermediaries.

Going forward, the key question for investors and builders is whether stablecoin issuers and blockchain platforms will prioritize interoperability across local- and dollar-denominated tokens—or isolate them through different infrastructure choices. Katz’s remarks imply that interoperability could materially change who ends up holding “digital dollars” and how quickly currency reshuffling occurs, so market participants should watch how regulators operationalize onramps, offramps, and onchain exchange controls in the jurisdictions most likely to experiment with local-currency stablecoin issuance.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Advertisement

Source link

Continue Reading

Trending

Copyright © 2025