Connect with us

Crypto World

DeFi has lost $1.3 billion to hacks in 2026 and the same attack keeps working

Published

on

Gnosis Pay exploit tied to Zodiac delay module as users exit

Compromised keys, not broken code, now drive the majority of crypto theft, and North Korea is cashing the checks.

Summary

  • DeFi protocols have lost at least $1.3 billion to exploits in the first eight months of 2026, according to Forbes and CertiK, with compromised private keys overtaking smart contract bugs as the leading attack vector for the first time on record.
  • Drift Protocol lost $285 million on April 1 after attackers spent months social engineering their way to an admin key, then drained the protocol in 128 seconds. KelpDAO lost $290 million 17 days later through a single compromised verifier on its LayerZero bridge.
  • North Korea’s Lazarus Group (operating as TraderTraitor) has been attributed to at least $575 million of 2026 losses across the Drift and KelpDAO hacks alone, meaning a single state actor accounts for roughly 44% of the year’s total.
  • Bridge infrastructure remains the dominant failure point. AFX Trade ($24.15 million), VerusCoin ($19.14 million across two exploits), and the Cosmos EVM underflow chain ($20.8 million across MANTRA, TAC, and KiiChain) all involved cross-chain verification layers that broke in the same predictable way.
  • The Coldcard hardware wallet exploit ($130 million, July 30) proved that the compromised key problem extends beyond DeFi protocols. A firmware bug made seeds guessable, and attackers brute-forced their way into thousands of wallets without touching a single network.

Eight months into the year, and the crypto industry has already replayed the same failure mode enough times to fill a textbook. The attack surface has not changed. Protocols keep trusting a small number of keys, signers, and verification nodes, and attackers keep finding that it is cheaper to compromise one person than to break one smart contract.

The numbers are stark. CertiK’s Hack3d H1 2026 report and Forbes both put total crypto hack losses at $1.3 billion through the first half of the year. TRM Labs arrived at a similar figure, noting that losses were trending just below the $1 billion mark for DeFi alone. The rekt.news leaderboard, which tracks individual exploits above $3 million, lists more than 30 incidents from 2026 so far, with the top two alone accounting for $575 million.

Advertisement

What separates 2026 from prior years is not the dollar amount. It is the attack taxonomy. The year’s biggest thefts did not exploit reentrancy bugs, flash loan loops, or oracle manipulation. They exploited people. Social engineering, session hijacking, validator key theft, and governance capture now drive the majority of losses by dollar value. The code passed every audit. The humans around it did not.

Two hacks, one playbook, $575 million gone

The year’s defining moment happened in an 18-day window between April 1 and April 18.

On April 1, attackers drained Drift Protocol of $285 million in 128 seconds. Drift was Solana’s largest perpetuals exchange. The exploit did not touch a single line of smart contract logic. The attackers had spent months posing as a quantitative trading firm, attending conferences, meeting Drift contributors in person across multiple countries, and building the kind of trust that this industry runs on.

By the time they struck, they had obtained pre-signed authority from Drift’s Security Council using a durable nonce, a legitimate Solana feature. They whitelisted a worthless token called CVT, deposited 500 million of it as collateral against a fake oracle they had controlled for three weeks, and withdrew $285 million in USDC, SOL, and ETH.

Neodyme’s 2024 audit had flagged the exact mechanism. The report noted that admin instructions like InitializeSpotMarket accepted an oracle account with zero validation. It was rated informational, reasoning that only the admin could call it. Two years later, the admin key was in the wrong hands, and the informational finding became a nine-figure exit.

Seventeen days later, on April 18, KelpDAO lost $290 million through its LayerZero bridge. The method was entirely different. No conference circuit, no fake trading desk. Someone social-engineered a LayerZero Labs developer on March 6, lifted their session keys, and used that access to poison the RPC infrastructure feeding LayerZero’s verifier network. External nodes were DDoS-ed into silence. The remaining compromised nodes signed off on a forged cross-chain message, and the bridge minted 116,500 unbacked rsETH.

Advertisement

The stolen rsETH went straight into Aave as collateral, borrowed real WETH against itself, and moved out before the emergency multisig had assembled enough signatures to pause. Aave’s total value locked dropped $6.28 billion in 48 hours. Nine protocols froze markets. Arbitrum’s Security Council used emergency powers to seize 30,766 ETH from the attacker’s wallet on-chain, a move that split opinion almost as much as the exploit itself.

Both hacks passed their audits. Both teams had followed standard security practices. Both lost everything to a single compromised key.

The Lazarus assembly line

Investigators linked both Drift and KelpDAO to TraderTraitor, a subgroup of North Korea’s Lazarus Group. Mandiant, CrowdStrike, Elliptic, and LayerZero jointly confirmed the KelpDAO attribution. Elliptic tied Drift to the same unit with medium-high confidence.

This is not new. Lazarus was behind the $1.5 billion Bybit hack in February 2025, identified by on-chain investigator ZachXBT within hours. Before that, the same group hit Radiant Capital, the Ronin Bridge, WazirX, and Harmony’s Horizon Bridge across 2022 through 2024. The U.S. Treasury, FBI, and CISA have all published joint advisories naming the group and its tactics.

Advertisement

What changed in 2026 is the sophistication of the social engineering layer. The Drift attackers built relationships over months. The KelpDAO attackers targeted a specific developer’s session credentials. In both cases, the initial breach happened through trust, not technology. The technical exploitation only began after the human layer was already compromised.

CertiK’s Ronghui Gu put it plainly in an interview with Forbes: “A protocol can pass a flawless code audit and still lose millions because of a compromised admin key.” That quote now reads more like a warning label than an observation.

Advertisement

Bybit has since sued North Korea, its intelligence agency, and the Lazarus Group in U.S. federal court, trying to recover assets from the $1.5 billion hack. The legal theory is novel, but it underscores how few options victims have when the attacker is a sovereign state.

The math is uncomfortable. Drift ($285 million) plus KelpDAO ($290 million) equals $575 million from a single threat actor in 18 days. Against a total 2026 loss figure of $1.3 billion, Lazarus accounts for at least 44% of all stolen funds. If you include the Bybit hack from late February 2025, the group’s rolling 18-month tally exceeds $2 billion.

Bridges keep breaking the same way

Bridges are crypto’s soft underbelly. They have been since the Ronin Bridge hack in 2022 ($624 million), the Wormhole hack ($326 million), and the Nomad hack ($190 million). Four years later, the pattern has not changed.

In 2026, bridge exploits include KelpDAO ($290 million, single-verifier compromise), AFX Trade ($24.15 million, five compromised validator signatures on an Arbitrum USDC bridge), and VerusCoin ($19.14 million across two separate exploits of the same Ethereum bridge in May and July). The Cosmos EVM underflow bug hit three chains in quick succession: MANTRA ($3.6 million), TAC ($7.5 million), and KiiChain ($9.7 million), all through the same cross-shard receipt replay vulnerability.

Advertisement

The common thread is verification. Bridges must confirm that a message or transaction on one chain is valid before executing it on another. That confirmation almost always relies on a small set of signers, validators, or oracle nodes. Compromise enough of them, and the bridge does exactly what it was designed to do: release funds on the destination chain against what it believes is a legitimate request from the source chain.

AFX Trade is a case study in how thin the margins are. On July 22, five compromised validator signatures cleared the two-thirds quorum on its Arbitrum bridge, draining $24.15 million in USDC. The attacker moved the funds to Ethereum, swapped for 12,467.5 ETH, and consolidated into a single wallet. All of this happened 49 days after AFX had proudly promoted a security audit from Zellic. That audit documented zero test coverage and left acknowledgments unfixed. The dispute window on the bridge was 200 seconds. It disputed nothing.

The VerusCoin Bridge was hit twice: $11.6 million in May, then $7.54 million in July. Same bridge, different gap in the same broken trust boundary. The second time, there was no statement, no bounty offer, no communication at all.

The fix is known but rarely applied. Multi-verifier configurations, where a bridge requires confirmation from multiple independent verification networks before releasing funds, would have stopped both the KelpDAO and AFX Trade exploits. LayerZero publicly blamed KelpDAO for running a single-verifier setup. KelpDAO fired back with Dune data showing 47% of all LayerZero OApp contracts, more than 1,200 of them, use the exact same configuration. Over two and a half years and eight documented integration conversations, KelpDAO says LayerZero reviewed its setup each time and raised no objections.

Advertisement

This is the real scandal. The fix exists. The infrastructure supports it. Almost nobody uses it.

Audits are checking the wrong surface

Rekt.news published an editorial in July 2026 titled “Wrong Attack Surface” that crystallized what the year’s exploits had been screaming: the biggest losses all passed their audits because auditors were checking the code, and the code was fine.

CredShields put it directly in their Drift post-mortem: the attack surface has moved “up the stack to governance, to signers, and to the people building the protocols themselves.”

Traditional smart contract audits review Solidity or Rust for reentrancy, overflow, and access control bugs. They do not review operational security practices, key management procedures, social engineering resilience, or the off-chain infrastructure that feeds data to on-chain contracts. The KelpDAO exploit happened in LayerZero’s RPC infrastructure, which sat outside every audit scope. The Drift exploit happened through social engineering that compromised an admin key, which no code audit is designed to catch.

The Coldcard exploit is the most extreme example. On July 30, 2026, attackers began draining Bitcoin wallets secured by Coldcard hardware devices. A firmware bug had swapped the hardware random number generator for a predictable software fallback, shrinking the entropy of wallet seeds to a brute-forceable range. No phishing, no malware, no stolen device. Attackers ran the math on their own machines, derived candidate addresses, matched them against the public blockchain, and extracted the private keys for free.

Galaxy Research traced the initial wave to 1,082.65 BTC stolen from 1,196 addresses in 41 minutes. By August 7, the high-confidence tally had grown to 1,596 BTC from roughly 7,300 addresses, with candidate-inclusive estimates pushing past 2,055 BTC, or roughly $130 million. More than 25 separate attack patterns were identified. At least 15 independent attackers exploited the same flaw.

Advertisement

Coinkite, the maker of Coldcard, issued a preliminary advisory the same day and CEO NVK posted a public apology. But a firmware update could not fix wallets whose seeds had already been generated with the broken entropy. Those seeds needed to be replaced entirely.

The Coldcard incident is not a DeFi hack in the traditional sense. It is something worse: proof that the compromised key problem runs deeper than protocol governance. Even users who did everything the self-custody playbook recommends, hardware wallet, offline signing, no third-party custody, lost funds because the key generation itself was flawed.

What actually fixes this

The boring answer is the correct one. The 2026 exploit pattern has three failure points, and each has a known mitigation that most protocols have not adopted.

Key management: Multi-party computation (MPC) wallets and hardware security modules (HSMs) with threshold signing eliminate the single-key risk that enabled the Drift hack. Timelock delays on admin actions, combined with on-chain monitoring that alerts when privileged transactions are queued, give security teams a window to respond. Drift’s 128-second drain worked because there was no delay between key compromise and fund extraction.

Advertisement

Bridge verification: Multi-verifier configurations, where two or more independent verification networks must agree before a bridge releases funds, are the direct answer to the KelpDAO single-verifier failure. LayerZero supports this natively. The fact that 47% of its applications still run single-verifier setups is a configuration problem, not a technology problem.

Operational security: No code audit can protect against social engineering. Protocols handling nine-figure TVL need dedicated operational security programs: hardware-enforced authentication for all privileged access, mandatory multi-signature requirements that cannot be bypassed by a single signer, and security training that treats social engineering as a primary threat vector.

The Cosmos EVM underflow bug offers a different lesson. Cosmos Labs had known about the bug since April 2026 but misjudged its severity. When it was finally exploited across MANTRA, TAC, and KiiChain in August, all three chains halted too late. The funds had already bridged out. Responsible disclosure only works if the recipients treat the disclosure with urgency.

Term Labs’ governance attack ($8.5 million, August 2026) points to another gap. Near-zero voter participation let one wallet seize control of the protocol’s vaults for minimal cost, bypassing the governance delay entirely. When nobody votes, governance is just another attack surface. Quorum requirements, vote-locking periods, and guardian mechanisms that can veto suspicious proposals during a review window are standard tools that Term Labs had not implemented.

Advertisement

What to watch

The second half of 2026 will determine whether the industry treats these failures as lessons or as tolerable costs of doing business. Five indicators will tell the story:

Multi-verifier adoption rate on LayerZero: If the percentage of single-verifier OApps drops meaningfully from 47% by year-end, the KelpDAO lesson landed. If it holds steady, expect a repeat.

Timelock adoption on admin keys: Watch for protocols above $100 million TVL implementing mandatory delays on privileged transactions. Drift’s 128-second drain should make this non-negotiable.

Advertisement

Lazarus Group attribution in new exploits: The U.S. Treasury, Chainalysis, and TRM Labs all track Lazarus activity. Any new attribution to TraderTraitor signals that the group’s social engineering pipeline remains operational.

Cosmos EVM patch adoption across IBC chains: The underflow bug hit three chains. Dozens more run the same codebase. The speed of patching across the Cosmos ecosystem will show whether cross-chain coordination has improved.

Insurance protocol payouts and capacity: On-chain insurance providers like Nexus Mutual and Sherlock absorbed significant claims in H1 2026. If underwriting capacity shrinks or premiums spike, it signals that the market is pricing in continued attacks at current levels.

How much has DeFi lost to hacks in 2026?

At least $1.3 billion through the first half of 2026, according to CertiK’s Hack3d report and Forbes. The rekt.news leaderboard lists more than 30 individual exploits above $3 million for the year, with the two largest, Drift Protocol ($285 million) and KelpDAO ($290 million), accounting for $575 million combined. The full-year figure will climb further once H2 losses are tallied.

Advertisement

What was the biggest DeFi hack of 2026?

KelpDAO lost approximately $290 million on April 18 when attackers compromised a LayerZero developer’s session keys, poisoned the RPC infrastructure feeding the bridge’s verifier network, and minted 116,500 unbacked rsETH. The stolen tokens were funneled into Aave as collateral, triggering a $6.28 billion TVL drop across the lending protocol and market freezes at nine separate DeFi platforms.

How did the Drift Protocol hack work?

Attackers posed as a quantitative trading firm and built trust with Drift Protocol contributors over several months through conferences and in-person meetings. They obtained pre-signed authority from Drift’s Security Council using a durable nonce, whitelisted a fake token called CVT with a self-controlled oracle, deposited it as collateral, and withdrew $285 million in 128 seconds. The exploit used only legitimate Solana features and admin permissions, not a code bug.

Is North Korea really behind most crypto hacks?

North Korea’s Lazarus Group, specifically its TraderTraitor subunit, has been attributed to at least $575 million in 2026 DeFi losses across the Drift Protocol and KelpDAO hacks. Combined with the $1.5 billion Bybit hack from February 2025, the group’s rolling 18-month tally exceeds $2 billion. Mandiant, CrowdStrike, Elliptic, the FBI, and the U.S. Treasury have all published attributions tying specific exploits to Lazarus operations.

Why do crypto bridges keep getting hacked?

Bridges depend on a small set of validators or verification nodes to confirm that a cross-chain message is real before releasing funds on the destination chain. Compromise enough of those signers, and the bridge follows its own rules, releasing funds against what it believes is a valid request. The KelpDAO exploit used one compromised verifier. The AFX Trade exploit used five. The underlying problem is that most bridges concentrate trust in too few parties, and many still run single-verifier configurations even when multi-verifier alternatives are available.

Advertisement

What is a compromised key attack?

A compromised key attack is when someone gains control of a private key, admin key, or signing authority that has privileged access to a protocol’s funds or configuration. In 2026, these attacks overtook smart contract exploits as the leading cause of DeFi losses by dollar value. The attacker does not need to find a code bug. They need to find a person, whether through social engineering, session hijacking, phishing, or insider access.

Can smart contract audits prevent these hacks?

No, at least not the kind of audits most protocols commission today. Traditional smart contract audits check code for bugs like reentrancy, overflow, and access control flaws. They do not cover key management practices, operational security, social engineering resilience, or off-chain infrastructure. The KelpDAO exploit happened in LayerZero’s RPC layer, outside every audit scope. The Drift exploit happened through months of social engineering. Both protocols had clean audits at the time of their exploits.

What is the Coldcard hack and how does it relate to DeFi security?

On July 30, 2026, attackers began draining Bitcoin from Coldcard hardware wallets after discovering a firmware bug that replaced the hardware random number generator with a predictable software fallback. Seeds became brute-forceable. Galaxy Research tracked at least $130 million in losses across thousands of wallets. The Coldcard hack is not a DeFi protocol exploit, but it proves the same point: when the key itself is compromised, no amount of on-chain security matters. The problem is not limited to smart contracts or bridges. It runs through the entire stack.

Advertisement

This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency investments carry significant risk. Always conduct your own research before making investment decisions. Information is accurate as of Sept. 4, 2026.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

AMBA Stock: Ambarella Posts Mixed Fiscal Q2 Earnings Report

Published

on

AMBA Stock: Ambarella Posts Mixed Fiscal Q2 Earnings Report

Chipmaker Ambarella (AMBA) late Thursday narrowly beat analyst estimates for its fiscal second quarter and matched views with its sales forecast for fiscal Q3. AMBA stock rose in extended trading. The Santa Clara, Calif.-based maker of edge AI chips earned an adjusted 18 cents a share on sales of $108.1 million in the quarter ended July 31. Analysts surveyed by…

Copyright ©2026 Investor’s Business Daily, LLC. All rights reserved. 87990cbe856818d5eddac44c7b1cdeb8

Source link

Continue Reading

Crypto World

Robinhood Bolts Above Entry, Analysts Hike Views On Momentum, Outlook

Published

on

Robinhood Bolts Above Entry, Analysts Hike Views On Momentum, Outlook

Robinhood Markets Robinhood Markets HOOD $ 123.52 $1.20 0.96% 48% IBD Stock Analysis Bolts past 112.45 buy point, extended above buy zone peak at 118.07. IBD Composite Rating 92/99 Industry Group Ranking 8/197 Emerging Pattern Cup with Handle Cup with Handle A positive chart pattern named such because it resembles the outline of a coffee cup with a handle. The…

Copyright ©2026 Investor’s Business Daily, LLC. All rights reserved. 87990cbe856818d5eddac44c7b1cdeb8

Source link

Continue Reading

Crypto World

Zcash Hits $1,000 for the First Time in a Decade. How Far Can It Go?

Published

on

Zcash Hits $1,000 for the First Time in a Decade. How Far Can It Go?

Zcash is seemingly winning this bullish cycle in the crypto market. ZEC is up nearly 100% over the past month, crossing  $1,000 for the first time in almost a decade.

ZEC briefly climbed above $1,045 on Friday. The move pushed its market value to roughly $17 billion and brought the privacy coin back to four figures for the first time since the chaotic opening days of trading in 2016.

Those early prices came when very little ZEC was circulating, making them poor comparisons with today’s market. So, how far will Zcash go in this cycle? 

Zcash 1-month Chart. Source: CoinGecko

Why Zcash Suddenly Exploded

Several forces have converged behind the rally.

Grayscale launched its US-listed Zcash ETF in late August, opening ZEC exposure to traditional investors through brokerage accounts. The fund has since attracted fresh inflows while holding more than 400,000 ZEC.

Meanwhile, demand for privacy-focused cryptocurrencies has returned. More ZEC is moving into shielded pools, while recent technical upgrades have made private transactions faster.

Advertisement

The latest leg higher also had help from derivatives traders.

Roughly $34.5 million in ZEC short positions were liquidated during the breakout. Traders betting against Zcash were forced to buy back their positions as prices rose, adding fuel to the move.

However, leverage has continued building after the squeeze. Total ZEC open interest has climbed toward $2.4 billion, up sharply from around $1.6 billion days earlier.

Advertisement

That makes what happens around $1,000 especially important.

Zcash Open Interest Hits Record High. Source: Coinglass

Can Zcash Hold $1,000?

The short-term chart still favors buyers.

On the one-hour chart, ZEC’s 20-period exponential moving average has risen to roughly $1,000. That means the psychological price level now lines up with a widely watched short-term trend indicator.

The first important zone sits between roughly $985 and $1,005.

If ZEC falls into that area and buyers repeatedly push it back above $1,000, the breakout begins to look more durable. A move through the recent $1,045-$1,055 high could then open another attempt at $1,100.

Advertisement

However, momentum is already stretched.

Zcash Price Chart. Source: TradingView

ZEC’s daily Relative Strength Index is close to 80, a level commonly associated with an overheated market. The four-hour RSI is around 70.

That does not automatically mean the rally is ending. Strong markets can remain overbought for long periods. It does mean traders should expect sharper swings.

If $1,000 fails, the next major test sits around $935-$955. Several short-term moving averages converge in that region, making it the clearest area where buyers could attempt to form another higher low.

A deeper fall toward $900 would weaken the structure further. Below roughly $850, ZEC would return toward the area where its latest breakout began.

Advertisement

For now, the larger trend remains firmly upward. ZEC trades well above its major daily moving averages, while each recent correction has produced a higher low.

The bigger risk comes from leverage.

Open interest has surged alongside price. If funding rates also become heavily positive, too many traders may end up crowded into leveraged long positions. That could turn a routine pullback into a rapid liquidation event.

So $1,000 matters twice: as a psychological milestone and as the first serious test of whether this rally can build a stable base after an explosive run.

Advertisement

The post Zcash Hits $1,000 for the First Time in a Decade. How Far Can It Go? appeared first on BeInCrypto.

Source link

Advertisement
Continue Reading

Crypto World

Magnite Stock: Advertising Leader Touches Buy Point But Reverses

Published

on

Magnite Stock: Advertising Leader Touches Buy Point But Reverses

Advertising leader Magnite (MGNI) is attempting to clear its latest buy point in the wake of a strong quarterly earnings report. That makes Magnite stock Thursday’s pick for IBD 50 Growth Stocks To Watch from Investor’s Business Daily. Magnite operates as one of the largest independent sell-side advertising platforms, helping publishers and media owners sell and manage their digital ad…

Copyright ©2026 Investor’s Business Daily, LLC. All rights reserved. 87990cbe856818d5eddac44c7b1cdeb8

Source link

Continue Reading

Crypto World

QuFi Unveils Post-Quantum Verification for Bitcoin Testnet

Published

on

Crypto Breaking News

QuFi Network says it has launched a post-quantum verification platform aimed at protecting digital assets from future quantum-computing threats—without forcing existing blockchain settlement layers to undergo immediate upgrades. The core idea is to add a separate verification step that can use post-quantum cryptography while leaving the underlying networks to continue settling transactions in their current forms.

Alongside the platform, QuFi introduced uBTC, a proof-of-concept applying the verification approach to Bitcoin. In the implementation described by QuFi, uBTC runs on Bitcoin Testnet, verifies BTC collateral, and produces cryptographic proofs that govern how value moves between settlement environments, with final redemptions settling as standard Bitcoin transactions.

Key takeaways

  • QuFi’s platform separates transaction verification from on-chain settlement, using a dedicated network of nodes for post-quantum checks.
  • The uBTC proof-of-concept applies the verification layer to Bitcoin Testnet while keeping ultimate redemptions compatible with normal Bitcoin transaction settlement.
  • QuFi reports using three post-quantum cryptographic standards—ML-DSA-65, SLH-DSA, and ML-KEM-1024—for signatures and key exchange.
  • The announcement adds to a broader push across the ecosystem to prepare for quantum risks through methods that avoid immediate hard forks or chain-wide rewrites.

A verification layer built to avoid chain migrations

According to QuFi, the platform is designed to reduce some of the practical friction that can come with adopting post-quantum cryptography directly at the blockchain protocol level. QuFi’s stated motivation is that larger post-quantum signatures and related cryptographic operations can increase storage, bandwidth, and computation requirements when deployed inside individual blockchains.

Instead of changing how settlement networks validate transactions at the base layer, QuFi says it “separates verification from settlement.” The company describes a decentralized set of verification nodes that validates transactions using post-quantum cryptography before those transactions are settled on existing blockchain networks. For users and integrators, the practical implication is that post-quantum protections could be introduced as an additional infrastructure component rather than as a sudden protocol overhaul.

QuFi also positioned the platform around a concrete cryptographic toolbox: ML-DSA-65 and SLH-DSA for digital signatures, and ML-KEM-1024 for secure key exchange. The use of multiple standards suggests QuFi is aiming for flexibility in how verification and key establishment work across different flows, though the performance and operational trade-offs of each element are not detailed in the announcement.

Advertisement

uBTC: post-quantum checks for Bitcoin collateral (test environment)

QuFi’s uBTC system is a proof-of-concept that takes the verification approach and tests it against Bitcoin’s asset layer. The described design is relatively specific: uBTC verifies BTC collateral and generates cryptographic proofs that define how value can move between settlement environments. Redemptions, QuFi says, ultimately settle as standard Bitcoin transactions.

Operating on Bitcoin Testnet4 means the work is currently in a test stage rather than live production settlement. For investors and builders, the key reason to watch this kind of design is that it targets compatibility—by generating proofs for movement rules, rather than requiring Bitcoin itself to immediately adopt a new post-quantum signature scheme. However, the real-world effectiveness will depend on how the proof system behaves under realistic load, how verification nodes are governed and secured, and whether the proof workflow can be made robust for everyday wallet and custody operations.

Quantum defenses are spreading—sometimes with clear trade-offs

QuFi’s announcement lands in the middle of a wider industry campaign to harden blockchains against quantum-era threats. Recent efforts show a pattern: many teams are trying to prepare without forcing disruptive upgrades, but each approach comes with costs.

Earlier in August, StarkWare tested a quantum-resistant Bitcoin transaction on mainnet without requiring a fork. According to reporting from Cointelegraph, the experiment ran for hours, cost roughly $150 to $200, and produced a nonstandard transaction format that required direct submission to a miner. That experience illustrates one of the practical barriers to immediate post-quantum adoption at the settlement-layer level: even when a scheme works, it can be expensive and operationally awkward.

Advertisement

The same month, a pilot involving banks and regulators across Europe, the Middle East, and Asia tested post-quantum wallets and onchain transfers using ML-DSA-65, a standard that QuFi also lists among its cryptographic choices. In parallel, the Ethereum Foundation reportedly removed the Poseidon hash function from its planned post-quantum architecture in favor of established alternatives such as SHA or BLAKE. Together, those moves underline how the search for “quantum readiness” is not just about adding new cryptography, but also about selecting components that are mature, implementable, and safe under realistic engineering constraints.

Bitcoin developers have also been exploring protocol-level mechanisms. Cointelegraph previously covered work from Blockstream researchers around a Bitcoin Improvement Proposal for SHRINCS, an experimental post-quantum signature scheme intended to reduce the size and performance costs of quantum-resistant signatures. The same coverage highlighted important trade-offs: SHRINCS uses stateful signatures to keep signatures smaller, which requires wallets to track previously used signing keys. It also remains in an early stage without a completed security proof and introduces complexity that could create user failure modes.

Why QuFi’s approach matters—and what to watch next

The main difference in QuFi’s pitch is architectural. By placing post-quantum verification in an external layer and keeping settlement tied to existing blockchain networks, QuFi is aiming to avoid the immediate overheads and interoperability friction that can arise when chains are forced to adopt larger post-quantum primitives all at once.

That said, a verification layer introduces its own questions that the market will likely evaluate over time: how decentralized and credible the verification network is, how proofs are generated and validated end-to-end, and whether operational requirements for key management and custody remain manageable. For Bitcoin-related use cases, particular attention will be on how uBTC’s testnet results translate to real wallet and exchange integration patterns—especially if the goal is to support production redemptions without requiring nonstandard transaction formats or special miner submission paths.

Advertisement

Readers should watch for updates that move beyond testnet demonstrations—particularly performance metrics, security assumptions for the verification network, and any clarity on how this approach could interoperate with broader custody, compliance, and wallet tooling as quantum transition planning accelerates across the ecosystem.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Source link

Advertisement
Continue Reading

Crypto World

US, UK join forces to target crypto scam centers and investment fraud

Published

on

US, UK join forces to target crypto scam centers and investment fraud

The United States and United Kingdom have formed a joint law enforcement alliance to investigate and dismantle scam centers behind cryptocurrency investment fraud and other cyber-enabled schemes.

Summary

  • The US and UK have signed a joint agreement to investigate and disrupt crypto scam centers and organized crime networks.
  • Authorities will share intelligence, pursue overlapping cases and determine which country should prosecute specific suspects.
  • Reported US losses from cyber enabled investment fraud climbed 89% from $4.57 billion in 2023 to $8.65 billion in 2025.
  • The agencies plan their first in person disruption operation with private sector partners in London in early October.

The U.S. Department of Justice announced on Sept. 3 that the U.S. Attorney’s Office for the District of Columbia, the Crown Prosecution Service of England and Wales and the UK National Crime Agency had signed a memorandum of understanding focused on cross-border enforcement against the operations.

The DOJ called the pact the first international cooperation agreement of its kind specifically designed to disable scam centers carrying out cryptocurrency and cyber-enabled investment fraud. U.S. authorities estimate such schemes are costing Americans approximately $10 billion a year.

Advertisement

US and UK crypto scam alliance targets common cases

Investigators from both countries will pursue parallel investigations into common targets, exchange information on organized crime syndicates and determine which jurisdiction should handle specific cases where their investigations overlap.

Authorities have already identified several cases of common interest, according to the DOJ. The agencies plan to meet with private-sector companies in London in early October for an in-person disruption operation hosted by the National Crime Agency.

U.S. Attorney Jeanine Ferris Pirro signed the agreement alongside Crown Prosecutor for England and Wales Stephen Parkinson and NCA Director General Graeme Biggar at the residence of UK Ambassador to the United States Sir Christian Turner.

Pirro said the agencies would work together to disable transnational organized crime networks operating scam compounds and targeting victims while using trafficked workers to carry out fraudulent schemes.

Advertisement

The alliance builds on existing cooperation between U.S. and UK authorities. During a May enforcement initiative organized by the Scam Center Strike Force, the NCA joined agencies from Australia, Canada, New Zealand and Thailand, along with private companies, to exchange information on scam infrastructure.

That operation resulted in the disruption of more than 1.4 million social media and email accounts, while private companies froze more than $3.8 million in cryptocurrency linked to laundering funds stolen from Americans. Seven suspected scammers were arrested in Thailand, and authorities disrupted servers, network connections and other infrastructure.

Crypto.news previously reported that Coinbase froze over $3 million in cryptocurrency linked to Southeast Asian scam networks during the enforcement effort. Meta, Microsoft and Starlink took action against accounts and infrastructure linked to suspected fraud operations.

Crypto investment fraud losses reached $8.65 billion

The new agreement follows a sharp rise in reported losses from cyber-enabled investment fraud in the United States.

Advertisement

FBI Internet Crime Complaint Center data cited by the DOJ showed reported losses from such scams climbed 89% from $4.57 billion in 2023 to $8.65 billion in 2025. Cyber-enabled fraud accounted for almost 85% of all losses reported to the center last year.

The DOJ cautioned that the figures were largely based on reports submitted by victims and could substantially understate actual losses because many fraud cases are never reported.

Created by Pirro in November 2025, the Scam Center Strike Force has concentrated on Chinese organized crime groups accused of running compounds primarily across Southeast Asia.

Advertisement

Its investigations cover cryptocurrency investment scams, cyber-enabled fraud, human trafficking and money laundering. Participating agencies include the FBI, U.S. Secret Service, Justice Department Criminal Division, U.S. Postal Inspection Service, IRS Criminal Investigation and Homeland Security Investigations, while the Treasury and State departments work with the task force on related actions.

Federal prosecutors have increasingly pursued the cryptocurrency and online infrastructure used by the networks. In July, the DOJ sought forfeiture of $25 million recovered through five investigations involving suspected victims in the United States and Canada.

Those cases involved fake cryptocurrency investment platforms and laundering networks linked to China, Malaysia and Cambodia. Prosecutors said at the time that the Scam Center Strike Force had seized more than $800 million since its November 2025 launch.

Authorities have targeted Southeast Asian scam compounds

A major enforcement action announced in April demonstrated the scale of the networks under investigation. U.S. authorities charged two Chinese nationals accused of managing a cryptocurrency investment fraud compound in Burma and attempting to establish another operation in Cambodia.

Advertisement

The DOJ said more than $700 million in cryptocurrency linked to suspected scam-related money laundering had been restrained through coordinated enforcement actions. Authorities seized 503 fake investment websites and a Telegram channel with more than 6,000 followers that prosecutors said was used to recruit people to a scam compound in Cambodia.

Workers were allegedly attracted with promises of high-paying employment before being held against their will and forced to participate in fraud schemes. Some job advertisements specifically sought workers who could speak with American accents and work during U.S. daytime hours.

Fraudulent cryptocurrency platforms used by such networks commonly displayed fake account balances and investment returns to persuade victims to send more funds. Investigators have tied similar methods to relationship-based schemes in which scammers spend extended periods building trust before introducing fake investment opportunities.

An international crackdown announced in April led to 276 arrests and the disruption of at least nine scam centers connected to investment fraud. Dubai police detained 275 people, while another suspect was arrested in Thailand as investigators pursued networks accused of using fake cryptocurrency platforms.

Advertisement

Chinese, U.S. and UAE authorities later described the Dubai action as their first joint crackdown on telecom and online fraud. Investigators said suspects used social media to establish fake romantic relationships before directing victims toward purported high-return cryptocurrency investments.

Regional governments step up action against scam centers

Countries where scam compounds operate have pursued their own enforcement and legislative measures as international investigations continue.

Myanmar’s Parliament approved an anti-online scam bill on July 28 after lawmakers reconciled versions adopted by its two chambers.

A draft published in May proposed prison sentences ranging from 10 years to life for operating an online scam center or committing digital currency fraud. It covered recruitment, financial facilitation, telecommunications support and other activities connected with online fraud networks.

Advertisement

The draft permitted capital punishment where violence, torture, unlawful detention or cruel treatment was used to force people to work in scam operations, with the death penalty required when such conduct caused a person’s death.

Final amended legislation, a presidential assent notice and a commencement date had not been publicly confirmed when the parliamentary approval was reported on July 29.

International enforcement has continued outside Southeast Asia as investigators follow the financial infrastructure used by organized fraud groups. An INTERPOL operation running from November 2025 through June 2026 resulted in 58 arrests and involved authorities from 22 countries, including the United States and United Kingdom.

Investigators examined romance scams, fake cryptocurrency investments, business email fraud and the shell companies, bank accounts and digital wallets used to move proceeds. Separately, an INTERPOL-led operation announced in July resulted in 5,811 arrests across 97 countries and territories, with authorities blocking more than 31,000 bank accounts and intercepting $293 million in illicit assets.

Advertisement

The U.S.-UK agreement now provides a formal framework for investigators and prosecutors in both countries to share information, pursue overlapping scam-center cases and decide where suspects should face prosecution. Their first planned joint disruption event under the pact is scheduled to take place with private-sector partners in London in early October.

Source link

Advertisement
Continue Reading

Crypto World

Binance warns users as phishing texts increase

Published

on

Binance outflows triple as ETH withdrawals hit 3-year high

Binance warned cryptocurrency users on Sept. 3 about an increase in phishing attacks involving text messages disguised as account security alerts.

Summary

  • Binance warned users about phishing texts disguised as urgent security alerts containing shortened malicious links.
  • The exchange said it never asks customers to verify or secure accounts through text links.
  • Users can check suspicious communications through Binance Verify before responding or entering any account information.
  • Withdrawal address whitelists restrict transfers to destinations approved by account holders before any withdrawal request.
  • Binance disclosed no victim count or financial losses connected specifically to its latest phishing warning.

The exchange said scammers were sending messages claiming that account settings had changed or that suspicious login activity had occurred. The messages include shortened links and direct recipients to “verify” or “secure” their accounts.

Binance did not disclose how many users received the messages. It also provided no figure for losses connected specifically to the latest campaign.

Advertisement

Binance phishing texts create false urgency

The fraudulent messages are designed to resemble official Binance notifications. They commonly warn about an unexpected login, changed account settings or another supposed security issue requiring immediate action.

The links may direct recipients to websites created to imitate Binance’s login or account verification pages. Scammers can then attempt to collect passwords, authentication codes or other information needed to access the victim’s account.

“We’ve recently observed an increase in phishing attacks targeting crypto users,” Binance said, without quantifying the increase.

The warning follows earlier campaigns using the exchange’s name. In 2025, the Australian Federal Police said scammers sent spoofed messages that appeared within existing Binance message threads. As previously reported, those messages falsely claimed that customer accounts had been compromised.

Binance says text links should not be trusted

Binance said it will never ask customers to click a link in a text message to verify or secure an account. Users who receive unexpected messages should instead open the official Binance application or enter the exchange’s address directly.

Advertisement

Customers can also use Binance Verify to check whether a website address, email address, phone number, social media account or other contact belongs to the exchange. Verification should take place before users enter account information or contact anyone presented as customer support.

Anyone who has already followed a suspicious link should contact Binance customer support through the official application. Users should avoid communicating further with the sender or providing passwords, recovery phrases and authentication codes.

Three account controls can limit phishing losses

Binance advised users to enable its withdrawal address whitelist. The feature limits withdrawals to wallet addresses approved by the account holder, creating another barrier if an attacker obtains login credentials.

The exchange published a separate guide explaining how customers can activate and manage the whitelist. Users should secure access to the email account and authentication method used to approve changes because attackers may target those services as well.

Advertisement

Binance also recommended activating its anti-phishing code. Once configured, legitimate Binance emails include a personalized code selected by the user. An email without the correct code may be fraudulent, although customers should still check its sender and destination links.

The protection applies to email rather than ordinary text messages. Binance’s instructions explain how users can create and update the code through their account security settings.

Binance also uses automated systems to detect suspicious behavior during logins, trading and withdrawals. The exchange previously said more than 100 artificial intelligence models support its fraud controls. According to related crypto.news reporting, Binance attributed an eightfold reduction in phishing success rates to those systems.

Platform controls cannot prevent every loss when customers voluntarily provide credentials or approve transfers after receiving deceptive instructions. Withdrawal whitelists, passkeys and application-based authentication can add barriers, but users still need to verify unexpected communications independently. Binance recommends contacting support only through its official application or website, particularly after opening a suspicious link.

Advertisement

Earlier scams show how impersonation causes losses

Binance impersonation through text messages is not new. Hong Kong police said 11 users lost approximately $446,000 in a 2023 campaign after receiving messages that threatened to deactivate their accounts unless they completed verification. The victims followed links contained in fraudulent messages.

In July 2026, Hong Kong’s Securities and Futures Commission ordered licensed crypto platforms and brokers to replace authentication based on SMS, email or app-generated one-time codes. The new standards require phishing-resistant authentication methods within 12 months.

Binance’s latest warning does not identify a deadline, investigation or regulatory action. The campaign remains an account-security matter, with users advised to verify communications and contact official support if they disclosed information or followed a suspicious link.

Advertisement

Source link

Continue Reading

Crypto World

‘Saint Seiya’ creator sues former manager over $20M, crypto investments

Published

on

Kalshi, Polymarket sued by Baltimore over sports event contracts

“Saint Seiya” creator Masami Kurumada has sued his former manager and other defendants for roughly 2.89 billion yen ($19.6 million) after alleging that billions of yen were diverted from his companies over six years, with some of the money believed to have been invested in cryptocurrency.

Summary

  • ‘Saint Seiya’ creator Masami Kurumada is seeking roughly 2.89 billion yen in damages from his former manager and other defendants.
  • The former manager is accused of diverting approximately 4.68 billion yen from three companies over about six years.
  • Kurumada’s lawyers said some of the allegedly embezzled funds are believed to have been used for cryptocurrency investments.
  • Roughly 1.8 billion yen has already been repaid, with the lawsuit seeking recovery of the remaining losses.

According to the lawsuit filed with the Tokyo District Court on Sept. 2, Kurumada Production and two other companies headed by the 72-year-old manga artist claim they suffered approximately 4.68 billion yen in losses between 2018 and 2024 through unauthorized transfers and diverted licensing payments.

The former manager, who served as a director of the three companies, had been entrusted with accounting, editorial work and other administrative duties for years. Kurumada’s lawyers said the manager has acknowledged taking the funds and told them he had acted with Kurumada’s interests in mind and had no malicious intent.

Advertisement

Some of the diverted money is believed to have been used for cryptocurrency investments, according to Kurumada’s legal representatives.

Kurumada seeks 2.89 billion yen after partial repayment

The three companies are seeking approximately 2.89 billion yen in damages from the former manager, his relatives, acquaintances and other parties after roughly 1.8 billion yen of the alleged losses was repaid.

Court filings allege that the former manager transferred money without authorization from bank accounts belonging to Kurumada’s companies into accounts held by separate companies he had established or controlled.

Another method involved licensing revenue. Business partners that would normally have paid licensing fees to Kurumada’s companies were allegedly directed to send the money elsewhere, allowing funds generated from Kurumada’s intellectual property to be diverted.

Advertisement

The alleged transactions continued for around six years before irregularities were uncovered during a Tokyo Regional Taxation Bureau audit in 2024.

Kurumada said he had left the movement of money entirely in the former manager’s hands and was unaware of the scale of the funds passing through the companies.

Speaking at a press conference in Tokyo after the lawsuit was filed, Kurumada said he initially found the allegations difficult to believe after spending decades working in the manga and anime business.

Advertisement

“I really couldn’t believe it,” Kurumada said, describing his feelings after learning about the alleged losses.

He said the situation eventually left him feeling empty and frustrated after a person he trusted with his finances was accused of diverting company money for years.

Crypto investments reportedly involved diverted funds

Kurumada’s lawyers said interviews conducted with the former manager indicated that at least part of the money had been directed into cryptocurrency investments.

The available court reports have not identified which cryptocurrencies were purchased, the platforms used to make the investments or how much of the alleged 4.68 billion yen was ultimately placed into digital assets.

Advertisement

No information has been disclosed on whether the cryptocurrency investments produced gains or losses, or whether any digital assets remain among the funds that Kurumada’s companies are seeking to recover.

The case comes as Japanese authorities have increased scrutiny of cryptocurrency transactions linked to fraud and other financial crimes. In August, crypto.news previously reported that Japan’s Financial Services Agency and National Police Agency had requested stronger withdrawal controls from domestic crypto exchanges, including waiting periods for newly registered withdrawal addresses and faster restrictions on suspicious accounts.

Official figures cited at the time showed Japan recorded 18,067 special fraud cases through May 2026, with losses reaching 151.47 billion yen. Social media investment scams accounted for 5,099 cases and 70.04 billion yen of those losses.

Japanese authorities have dealt with crypto-linked cases extending beyond investment scams. Tokyo police in June arrested Hu Xiaowei, an alleged senior figure connected to Cambodia’s Prince Group, which U.S. authorities have accused of involvement in cryptocurrency investment fraud and money laundering.

Advertisement

A separate Nikkei investigation published that month linked a crypto fraud operating through Japan to a Chinese network suspected of exporting fentanyl precursor chemicals. The reported scheme used Japanese internet domains and a fake token called Zksync.jp to target cryptocurrency users.

Japan has tightened its crypto framework

Japan has been changing the rules governing legitimate digital asset activity at the same time authorities are strengthening controls against fraud.

The country’s parliament in July passed financial law amendments that classify cryptocurrencies as financial products under the Financial Instruments and Exchange Act.

The legislation creates a framework for stricter market oversight and insider trading restrictions while opening a route toward domestic crypto exchange-traded funds and a proposed 20% tax treatment for cryptocurrency gains.

Advertisement

Major financial groups have been preparing products under the changing framework. SBI, Rakuten, Nomura and other Japanese financial institutions have been exploring crypto investment trusts as regulators work toward allowing investment funds to hold digital assets.

The cryptocurrency component of Kurumada’s lawsuit, however, concerns the alleged use of company funds after they had been diverted, based on statements from his legal team, rather than an allegation against a cryptocurrency platform or digital asset issuer.

Saint Seiya licensing revenue was allegedly redirected

Kurumada’s works have generated substantial licensing income, particularly as “Saint Seiya” developed an international audience through manga, animation, merchandise and other products.

At the Tokyo press conference, Kurumada said revenue had increased substantially over the past decade as Chinese companies, including Tencent and Alibaba, became involved with products connected to his work.

Advertisement

The scale of those payments formed part of the alleged mechanism described in the lawsuit, with licensing fees from business partners among the funds that Kurumada’s side says were redirected.

Kurumada made his debut with “Sukeban Arashi” before creating titles including “Ring ni Kakero.” “Saint Seiya,” one of his best-known works, later became an animated series and developed a large audience outside Japan.

The alleged embezzlement affected plans connected to his work as well. Kurumada said a planned exhibition of original artwork at Roppongi Hills in Tokyo in 2024 had to be canceled after the financial irregularities were discovered.

He apologized to fans who had expected to attend the exhibition and said he now intends to hold it in Tokyo’s Ikebukuro district in spring 2027.

Advertisement

Despite saying the episode had temporarily left him distrustful of people, Kurumada told reporters that he intends to continue drawing for readers and fans of “Saint Seiya” and his other manga around the world.

Source link

Advertisement
Continue Reading

Crypto World

AMC CEO Adam Aron hits out at Robinhood over tokenized AMC shares

Published

on

What is a stock buyback? How repurchases affect price

AMC Entertainment CEO Adam Aron has rejected Robinhood’s tokenized product linked to AMC shares and said the theater chain will seek legal advice over an offering created without the company’s involvement.

Summary

  • AMC CEO Adam Aron said the theater chain has no connection to Robinhood’s tokenized product tracking AMC shares and does not condone it.
  • Aron called the practice “contemptible” and “outrageous” and said AMC will ask outside securities counsel to examine the matter.
  • Robinhood’s stock tokens provide economic exposure to underlying equities but do not give holders ownership or shareholder rights in the companies they track.
  • OpenAI previously rejected Robinhood tokens linked to the private company, saying they were not OpenAI equity and had not been endorsed by the firm.

According to Aron, AMC has no connection to Robinhood’s effort involving tokenized real-world assets and Stock Tokens, despite a product carrying the company’s name and tracking its publicly traded shares.

“Robinhood apparently is behind an effort related to ‘tokenized real-world assets including Stock Tokens’ for AMC Entertainment,” Aron wrote on X on Thursday. “We have no connection to this at all, and do not condone it in any way.”

The AMC chief described the practice as “contemptible” and “outrageous,” adding that the company plans to ask outside securities counsel to examine the matter.

Advertisement

AMC rejects Robinhood tokenized stock product

Aron’s objection centers on a distinction between AMC’s publicly traded shares and a blockchain-based financial product designed to provide exposure to their price.

Robinhood’s stock tokens do not make investors shareholders of the companies they track. Its Classic Stock Tokens are derivative contracts that provide economic exposure to U.S. stocks and exchange-traded products, while holders do not own the underlying shares or receive shareholder rights such as voting rights.

Robinhood owns the assets supporting its Classic Stock Tokens and holds them through a U.S.-licensed institution. The contracts are offered under MiFID II in Europe, according to the brokerage.

A separate generation of transferable Robinhood Stock Tokens uses a different structure. The ERC-20 assets are tokenized debt securities issued by Robinhood Assets (Jersey) Limited and provide economic exposure to underlying securities without granting legal or beneficial rights against the companies that issued those shares.

Advertisement

The distinction has become more visible as financial firms experiment with different structures for putting stock exposure on blockchains. Some products are derivatives that follow a security’s price, while other models hold shares through custodians and issue tokens backed by the underlying equity.

Issuer-sponsored tokenization goes further by placing registered shares onchain with the participation of the company whose equity is being represented.

Robinhood has made the first model a major part of its international expansion. Its European platform currently advertises more than 2,000 Classic Stock Tokens linked to U.S. stocks and exchange-traded products, with trading available around the clock from Monday through Friday.

Robinhood has expanded tokenized stocks onchain

Robinhood’s tokenization plans moved further onchain in July when the company launched Robinhood Chain, an Ethereum Layer 2 network built using Arbitrum technology.

Advertisement

As crypto.news previously reported, the July 1 rollout opened Stock Token trading through Robinhood Wallet to eligible users across more than 120 countries, subject to local restrictions. The network was built to support tokenized real-world assets alongside decentralized finance applications.

Robinhood Chain launched with 95 tokenized equities and infrastructure that allowed the assets to interact with decentralized exchanges and lending applications. Stock Tokens on the network can be transferred as ERC-20 assets and integrated into onchain applications.

Usage has since increased. Combined tokenized-stock trading volume through Uniswap on Robinhood Chain reached $1 billion in August, according to Uniswap founder Hayden Adams.

Advertisement

The products remain unavailable to U.S. investors. Robinhood says the Stock Tokens issued by its Jersey entity are not registered under U.S. securities laws and cannot be offered, sold or delivered directly or indirectly in the United States or to U.S. persons.

Robinhood’s tokenization strategy has expanded beyond simply recreating the trading experience of a brokerage account. Stock Tokens on its blockchain can be transferred between supported wallets and applications, traded through decentralized exchanges and integrated into DeFi products.

The network had already attracted $431 million in total value locked and nearly $400 million in stablecoin market capitalization within three weeks of launch, according to a FalconX report covered in July. Robinhood’s tokenized stocks stood at approximately $14 million at the time, compared with roughly $851 million for Ondo and around $481 million for xStocks.

OpenAI previously rejected Robinhood tokens

AMC is not the first company to object to a Robinhood product carrying its name without its participation.

Advertisement

OpenAI rejected Robinhood tokens linked to the privately held artificial intelligence company in July 2025 after the brokerage announced a promotion giving eligible European customers exposure to OpenAI and SpaceX.

“These ‘OpenAI tokens’ are not OpenAI equity,” the company said at the time, adding that it had not partnered with Robinhood or endorsed the offering.

Robinhood CEO Vlad Tenev defended the product after OpenAI’s response, explaining that the tokens were intended to provide retail investors with indirect exposure to private assets. The structure used a special-purpose vehicle holding an economic interest linked to OpenAI rather than shares issued directly to token holders by the company.

The disagreement exposed the same ownership distinction now involved in AMC’s objection: a financial product can track or provide economic exposure to a company without being equity issued or endorsed by that company.

Advertisement

Robinhood’s publicly traded Stock Tokens use similar terminology while carrying specific disclosures about what investors receive. The company states that holders gain economic exposure to the underlying security but do not obtain legal or beneficial rights against its issuer.

Tokenized stock models are taking different forms

Other financial and crypto companies are pursuing structures that more directly connect tokens with the underlying shares.

Base founder Jesse Pollak said in July that the Ethereum Layer 2 network and Coinbase were working on 1:1-backed tokenized stocks designed to be supported by actual underlying shares.

Pollak contrasted the planned structure with Robinhood’s derivatives, saying Coinbase and Base were preparing a model backed one-for-one by equity. He acknowledged at the time that Robinhood had moved faster in bringing tokenized equities into an Ethereum Virtual Machine-compatible environment.

Advertisement

Robinhood itself has continued to build infrastructure around its version of the market. Its July mainnet rollout brought tokenized stocks together with decentralized lending, perpetual futures and other blockchain-based financial products.

Stock Tokens can use Chainlink price feeds on Robinhood Chain, allowing applications to read prices directly onchain. The ERC-20 format means developers can integrate the assets into compatible wallets, trading venues and DeFi protocols without requiring a separate token standard.

AMC has not announced legal action against Robinhood. Aron said the company will first ask outside securities counsel to review the tokenized AMC product and the circumstances surrounding its use of the company’s name.

Advertisement

Source link

Continue Reading

Crypto World

SoFi taps Kraken Prime and lists SoFiUSD

Published

on

SoFi taps Kraken Prime and lists SoFiUSD

SoFi Technologies and Kraken parent Payward announced a partnership on Sept. 3 connecting SoFi’s banking and dollar-settlement services with Kraken’s digital asset trading infrastructure.

Summary

  • Payward will join SoFi’s real-time settlement network, enabling round-the-clock U.S. dollar transfers for institutional clients.
  • Kraken will list SoFiUSD, extending access to SoFi’s dollar-redeemable bank-issued stablecoin across its trading platform.
  • SoFi will route digital asset orders through Kraken Prime as an additional source of liquidity.
  • Qualified custody may follow as the partnership expands, but neither company provided a deployment timetable.
  • SOFI closed near $18.51 after rising 3.7%, without evidence attributing gains solely to partnership news.

Payward will join the SoFi Exchange Network, known as SEN, while Kraken will list the SoFiUSD stablecoin. SoFi will use Kraken Prime as an additional liquidity and execution provider for cryptocurrency trades placed through its application.

Advertisement

SoFi gives Kraken access to 24/7 dollar settlement

SEN allows institutional clients to transfer and settle U.S. dollars outside traditional banking hours. Payward’s participation will give eligible Kraken institutional customers access to those settlement rails for round-the-clock liquidity management.

The companies said the connection removes delays that can arise when cryptocurrency markets remain open but banking services are unavailable. Digital asset platforms operate continuously, while many conventional bank transfers remain tied to business days and scheduled processing periods.

Payward will also use SoFi’s Big Business Banking services. SoFi introduced that division in April to combine enterprise banking, payments and digital asset capabilities within one offering.

As previously reported, SoFi’s enterprise platform brought fiat and crypto services together while allowing institutional customers to manage U.S. dollars, SoFiUSD and selected digital assets.

Advertisement

Kraken Prime will execute SoFi crypto orders

SoFi will route cryptocurrency order flow through Kraken Prime, which uses smart routing to compare prices and available market depth across supported trading venues. The system selects where an order should be executed rather than relying on one order book.

Kraken said the arrangement could provide SoFi with deeper liquidity and improved execution pricing. The final price available to a customer will still depend on market conditions, order size, available liquidity and applicable fees.

Kraken Prime combines trading, custody and other institutional services through one relationship. SoFi described it as an additional liquidity source, meaning the partnership does not necessarily make Kraken its sole execution provider.

Qualified custody services may be added as the relationship develops. Neither company provided a launch date, named a custody entity or described which assets could eventually receive that support.

Advertisement

“The infrastructure behind that experience should connect them to deep, liquid markets built to operate at scale,” Payward co-CEO David Ripley said.

SoFiUSD expands beyond SoFi’s banking application

Kraken will list SoFiUSD for retail, professional and institutional customers. The stablecoin is designed to maintain one-to-one redemption for U.S. dollars and is issued through SoFi’s regulated banking structure.

SoFiUSD became available through SoFi’s application in May. The initial rollout supported Ethereum and Solana, giving members the ability to buy, sell, hold and convert the token. The product opened stablecoin access to nearly 15 million SoFi members.

The Kraken listing gives SoFiUSD distribution outside its issuer’s application. However, the companies did not disclose available trading pairs, supported deposit networks, initial liquidity or the precise listing time.

SoFi has also said federal stablecoin rules may require SoFiUSD to migrate to a separately licensed or regulated entity. That possible restructuring was disclosed earlier and is not described as part of the Payward agreement.

Advertisement

Partnership connects two expanding financial platforms

The arrangement reflects expansion from both directions. SoFi is adding digital asset trading, stablecoins and blockchain settlement to its banking services. Kraken has expanded beyond cryptocurrency trading into equities, derivatives and institutional prime brokerage.

SoFi’s crypto business generated $121.6 million in transaction revenue during the first quarter of 2026, according to its financial disclosures. Related costs reached $120.7 million, leaving approximately $852,000 in net crypto transaction revenue. Crypto.news previously found that transaction costs consumed most of SoFi’s crypto revenue.

SOFI shares closed near $18.51 on Sept. 3, up approximately 3.7% for the session. The shares traded between $17.63 and $18.70 during the day.

No verified evidence showed that the partnership announcement alone caused the increase. Broader market conditions and company-specific trading may also have contributed.

Advertisement

The companies said they could extend the relationship into payments, treasury services, lending and additional digital asset products. Those areas remain prospective, with no deadlines or confirmed product launches announced.

Source link

Advertisement
Continue Reading

Trending

Copyright © 2025