Crypto World
FG Nexus exits ETH treasury after $45.2M loss
FG Nexus sold all of its digital assets before June 30, ending an Ethereum treasury strategy less than a year after it launched.
Summary
- FG Nexus sold all digital assets before June 30, ending its Ethereum treasury strategy entirely.
- First-half digital asset operations lost $45.207 million while staking generated only $144,000 in total revenue.
- ETH sales generated $60.956 million cash, with another $14.983 million receivable fully collected during July.
- FG Nexus had peaked at 50,770 ETH in September 2025 before beginning its treasury unwind.
- Management plans to redirect capital toward manufactured housing, though no definitive FG Communities deal exists.
The Nasdaq-listed company disclosed the completed exit in its Aug. 12 filing, which reclassified the digital asset business as discontinued operations.
The filing shows that FG Nexus received $60.956 million in cash from ETH sales during the first half of 2026. A further $14.983 million remained receivable at June 30 and was collected in July. The company held no cryptocurrency at quarter end.
FG Nexus records $45.2M loss from digital asset exit
FG Nexus reported a $45.207 million loss from its discontinued digital asset operations for the first six months of 2026. The total included a $41.167 million loss on ETH digital assets, a $2.793 million impairment on digital intangible assets and $1.789 million in general and administrative expenses.
Those figures matter because the $45.207 million should not be described as the realized loss from selling ETH alone. The business also recorded a $398,000 gain on digital intangible assets and only $144,000 of staking revenue. Its broader consolidated net loss for the first half reached $56.928 million.
In addition, FG Nexus announced its Ethereum treasury strategy in July 2025 and said its digital asset business began in August. By Sept. 28, the company reported holding 50,770 ETH, valued at about $207 million using its reference price at the time, with an average purchase price near $3,860.
As previously reported, FG Nexus raised $200 million while making Ethereum its primary treasury asset, with plans to generate returns through staking and other Ethereum opportunities. By June, however, the company was unwinding that position. Crypto.news later reported that FG Nexus moved another 10,000 ETH as its treasury losses widened.
Cash from ETH sales is being redirected toward real estate
FG Nexus announced on July 1 that its board had authorized management to exit digital assets and create a real estate operating subsidiary focused mainly on land lease manufactured housing properties. CEO Kyle Cerminara said the company intended to “reallocate all of our capital from digital assets to cash flow producing real estate over the near term.” That remains a forward-looking company plan.
The company is also considering a potential combination with FG Communities, but the quarterly filing says board discussions remain preliminary and no decision or definitive agreement has been reached. An independent special committee is reviewing the potential transaction and has retained a financial adviser to provide a fairness opinion.
The ETH liquidation has increased available cash. FG Nexus reported $24.9 million of cash and equivalents at June 30. After receiving the ETH sale receivable and $15.5 million from the redemption of FG Merger II shares, cash reached approximately $51.4 million by July 31.
What happens next for FG Nexus
The next test is whether FG Nexus can turn that liquidity into income-producing property assets. The company has not announced a definitive FG Communities transaction or disclosed completed acquisitions under the new manufactured housing strategy. Its existing Quebec property also remains held and used after an earlier nonbinding sale proposal became unlikely to close.
FGNX traded at $7.59 on Aug. 13, up about 8.9% from the previous close. The company had already announced its crypto exit on July 1, however, so the move cannot be attributed solely to the later quarterly disclosure.
The reversal closes a short corporate Ethereum experiment that once aimed to make FG Nexus a major ETH holder. It also shows the financial tradeoff in this particular treasury strategy: first-half staking generated $144,000, while the discontinued digital asset operation recorded a $45.207 million loss.
Crypto World
World Liberty Financial gets OCC nod for USD1 bank
World Liberty Financial has received preliminary OCC approval to establish a national trust bank that would oversee more than $4 billion in USD1 stablecoin circulation.
Summary
- World Liberty Trust must meet the OCC’s conditions before it can begin operations.
- The proposed bank would issue USD1, manage its reserves, and serve institutional custody clients.
- WLTC must maintain at least $20 million in eligible capital before opening.
- WLFI rose after the decision but remains down more than 60% over the past year.
World Liberty Financial must meet OCC conditions
The Office of the Comptroller of the Currency said on Aug. 14 that it had granted preliminary conditional approval for World Liberty Trust Company, National Association, or WLTC, after reviewing the proposed bank’s application and commitments.
World Liberty Financial submitted the application through WLTC Holdings LLC in January. As crypto.news reported at the time, the proposed trust bank was designed to bring USD1 issuance, reserve management, and institutional custody under one federally supervised entity.
Preliminary approval allows World Liberty Financial to organize the bank but does not authorize it to open. According to the OCC’s 19-page approval decision, WLTC must complete its preopening requirements and receive final authorization before starting business.
Until then, the regulator can modify, suspend, or withdraw its approval if a new development raises concerns. WLTC must also notify the OCC about major changes to its business plan before making them.
The bank will need at least $20 million in eligible capital when it opens, while its organizers must submit an updated operating plan and receive OCC non-objection. Required appointments include a qualified internal audit manager, and the regulator must approve the bank’s proposed chief financial officer before the opening date.
WLTC would operate as a wholly owned subsidiary of Delaware-registered WLTC Holdings and maintain its main office in Bay Harbor Islands, Florida. The proposed institution must also apply for stock in a Federal Reserve Bank under federal law.
USD1 operations would move from BitGo to WLTC
Once fully authorized, World Liberty Trust plans to issue and redeem USD1 for institutional clients across the United States. The bank would also maintain the assets backing the dollar-pegged token and provide fiduciary custody services to USD1 users and other institutional customers.
BitGo Bank & Trust currently serves as the exclusive issuer and custodian for USD1. After opening, WLTC intends to acquire the stablecoin’s reserve assets and assume the liabilities connected to them, according to the OCC.
The regulator said the transfer may require additional approval under federal bank merger rules. Any acquisition of reserve assets from BitGo must therefore comply with the conditions set by the agency before the transaction can proceed.
Conversion services would form another part of WLTC’s planned operations. Institutional custody customers could submit approved stablecoins and receive USD1 in return, although the service would be limited to assets held in custody by the bank.
World Liberty Financial said USD1 has surpassed $4 billion in circulation. The company lists U.S. dollars held at financial institutions, U.S. government money market funds, and cash equivalents among the assets supporting the stablecoin.
USD1 is available on centralized platforms including Binance, Coinbase, Kraken, Crypto.com, OKX, and Bybit, as well as decentralized exchanges such as Uniswap and PancakeSwap. Reuters ranked it as the fourth-largest stablecoin by market capitalization following its rapid growth since its March 2025 launch.
World Liberty Trust President and Chairman Zach Witkoff said federal supervision would place the token’s main operations under one regulator.
“A national trust bank brings USD1 issuance, custody, and reserve management together under OCC supervision, examined on the same standards that have governed banks for generations.”
He added that the company welcomed “continuous scrutiny from federal regulators.”
Federal trust bank approval does not cover lending
Despite the bank designation, WLTC would not operate like a traditional commercial lender. National trust banks generally provide custody, fiduciary, settlement, and asset-servicing functions but cannot accept ordinary customer deposits or issue conventional loans.
A federal charter would let WLTC provide approved services nationwide under one primary regulator instead of applying for separate state licenses. The structure also places its operations under regular OCC examinations, along with federal anti-money laundering and sanctions requirements.
The company said customer assets would remain segregated and reserve management would operate independently. WLTC has selected Mack McCain as chief trust officer and Daniel Dietzel, a former chief financial officer at institutional prime broker Hidden Road, as its CFO.
A five-member board would oversee the proposed bank. Alongside Zach Witkoff, the board would include Scott Alper, Robert Witkoff, and independent directors Jeffrey Weiner and Erin Baskett. According to the company, Weiner previously led accounting firm Marcum, while Baskett serves on the Financial Industry Regulatory Authority’s Board of Governors.
World Liberty joins several digital asset companies that have entered the OCC charter process since December 2025. Ripple, Paxos, BitGo, and Fidelity Digital Assets have received conditional approvals, while Coinbase, Crypto.com, and Stripe-owned Bridge have also pursued national trust bank structures.
Circle moved one step further in July when it received final approval to establish its national trust bank. Circle first obtained conditional approval in December 2025 and then completed the OCC’s preopening requirements before receiving authorization.
The OCC reported that uninsured national trust banks under its supervision held $7.2 trillion in assets under administration as of March 31. Custody and safekeeping accounts represented $1.7 trillion, while fiduciary accounts accounted for the remaining $5.5 trillion.
Trump ties keep the charter under scrutiny
World Liberty Financial’s connection to U.S. President Donald Trump and his family has made the application a subject of congressional attention. Trump and members of the Witkoff family helped launch the company in 2024, while Trump later adopted the title of co-founder emeritus.
Sen. Elizabeth Warren asked OCC Comptroller Jonathan Gould in January to pause the charter review until Trump divested his financial interest in the company. Warren said approval could leave a presidential appointee regulating a business financially connected to the president.
Questions increased after reports that an Abu Dhabi-linked entity purchased a 49% interest in World Liberty Financial for $500 million shortly before Trump returned to office. In June, Senate Democrats questioned the potential national security implications of the transaction and its effect on the charter review.
The OCC said it received public comments concerning non-U.S. investors in World Liberty Financial. According to its decision, the foreign investors were not considered principal shareholders of the proposed bank, and several investors signed agreements promising not to control or influence its operations.
Eric Trump signed one of the agreements as president of a Trump family-linked investment vehicle. The regulator said Gould and agency staff followed their legal and ethical duties, while career employees handled the application review and nonpolitical examiners would supervise the bank.
Following the announcement, WLFI initially rose more than 2% to about $0.0597 before giving back part of the advance. TradingView data later placed the token near $0.0558, up about 8% over seven days but more than 65% below its level one year earlier.
Crypto World
Crypto VC will prioritize quantum-ready infrastructure heading into 2027, Moon Pursuit founder says
Moon Pursuit Capital founder Utkarsh Ahuja has said crypto venture investors will prioritize quantum-ready infrastructure heading into 2027 as global VC investment reached $227.4 billion in the second quarter.
Summary
- Global VC investment reached $227.4 billion across 8,440 deals during Q2 2026.
- Ahuja expects post-quantum security and blockchain migration tools to attract more capital.
- Moon Pursuit co-led AmericanFortress’ $8 million seed round with SAVA and 0G Labs.
- NIST and major blockchain developers have already started preparing for quantum-resistant systems.
KPMG’s latest Venture Pulse report found that global venture funding recorded its second-highest quarterly total in Q2, although much of the capital went to large companies working in AI and other advanced technologies.
VC-backed companies raised $227.4 billion across 8,440 deals, down from the record $332.9 billion invested during Q1. OpenAI’s $122 billion round had lifted the first-quarter total, while Anthropic’s $65 billion financing provided the largest contribution in Q2.
US companies received $144.9 billion across 3,644 deals, accounting for nearly 64% of global investment. Other major US transactions included a $12 billion round for AI modeling company Project Prometheus and a $5 billion raise by defense technology company Anduril Industries.
Within the quantum-computing sector, investment slowed from the record pace recorded in 2025 but remained active, according to KPMG. Netherlands-based QuantWare raised $178 million, Germany’s eleQtron secured $66 million, and Quantinuum raised $1.6 billion through a Nasdaq listing that valued the company at $17.6 billion.
Crypto VC could fund quantum preparation before the threat arrives
Ahuja told crypto.news that investors will need to consider quantum risks well before a computer capable of breaking current blockchain security becomes available.
“I think quantum is going to force crypto investors to think much further ahead than they traditionally have,” Ahuja said.
No one can reliably predict when quantum hardware will be able to break the cryptography used to secure digital assets, according to Ahuja. However, he argued that the uncertain timetable does not remove the investment case because upgrading blockchains, wallets, and user infrastructure could take several years.
“If upgrading a blockchain, moving billions of dollars in assets, changing wallet infrastructure, and coordinating users across a decentralized network could take years, then quantum readiness becomes relevant well before the technology reaches that threshold.”
Ahuja expects the issue to send more venture funding toward post-quantum security, cryptographic migration, and infrastructure designed to accept future security upgrades. When assessing companies, he said Moon Pursuit will examine how easily their products can adapt when cryptographic requirements change.
Under that approach, resilience depends partly on whether a network or security provider can move users and assets to new systems without causing extensive disruption. Such migration work may carry particular weight for public blockchains, where developers cannot order every wallet owner, custodian, and validator to upgrade at the same time.
AmericanFortress gives Moon Pursuit a practical migration bet
Moon Pursuit co-led AmericanFortress’ $8 million seed round alongside SAVA Digital Asset Fund and 0G Labs. The company has developed a proposed security system for existing blockchain wallets and filed a patent covering quantum-resistant transaction signing.
Ahuja said the investment was based partly on the product’s planned compatibility with infrastructure already used by crypto networks.
“We were interested in the practicality of migration and the fact that the technology is designed to work with infrastructure that already exists,” he said.
AmericanFortress has proposed a system known as ZK-PoSP that would allow wallets to prove control of their original seed without exposing it. As crypto.news previously reported, the proposed quantum-safe wallet scheme would cover addresses on Bitcoin, Ethereum, and Solana without requiring holders to move their funds or rotate their keys.
The design remains a proposal and would require upgrades at the node level before a blockchain could enforce it. AmericanFortress’ technical paper also describes its post-quantum protection as conjectural rather than proven against a working quantum attack.
Ahuja said the apparent simplicity of the migration process could hide the complexity of the underlying work. Moon Pursuit considered the company’s intellectual property and patent development when assessing whether its technology could be easily copied, he added.
Instead of betting on a precise date for a major quantum breakthrough, Ahuja said venture firms should determine whether a company is solving a problem that already produces commercial demand. Security, cryptography, and infrastructure provide possible markets, but companies still need an adoption plan that does not depend entirely on rapid progress in quantum hardware, he said.
“Separating scientific progress from an investable business model is going to be increasingly important.”
Selective crypto funding favors products with existing demand
According to Galaxy Research, venture firms invested about $4 billion across 355 crypto and blockchain deals in Q1 2026. Funding fell 50% from the previous quarter, while the deal count declined 16%, mainly because the quarter had fewer large later-stage financings.
Trading, exchanges, investing, and lending companies collected approximately $2.6 billion, or close to three-fifths of the quarterly total. Infrastructure ranked second by deal count with 56 transactions, while privacy and security companies completed 22 deals.
Fundraising for crypto-focused venture firms remained difficult. Eight new funds raised about $1.1 billion during Q1, the lowest quarterly fund count since Q3 2020, according to Galaxy. The research firm said AI, spot crypto exchange-traded products, and digital asset treasury companies were also competing for institutional allocations.
US startups received 70.2% of all crypto VC capital and accounted for 43.5% of completed deals during the quarter. Galaxy also found that the median crypto investment exceeded $4.5 million, although it cautioned that available valuation data covered only 12% of the deals and leaned toward later-stage companies.
For Ahuja, investment categories once treated separately are starting to overlap as crypto companies use technology developed in AI, cybersecurity, and quantum research.
“We have spent years treating digital assets, AI, cybersecurity and quantum as fairly distinct investment categories, but some of the most interesting opportunities now sit between them,” he said.
Protocols and applications will continue to receive funding, according to Ahuja, although he expects more capital to reach the underlying systems required for institutions to use digital assets securely. Quantum protection fits within that category because companies can sell preparation and migration tools before quantum hardware reaches the level required to attack blockchains, he added.
US standards and blockchain projects have started preparing
The US National Institute of Standards and Technology finalized its first three post-quantum cryptography standards in August 2024. NIST encouraged system administrators to begin adopting the standards immediately rather than wait for a quantum computer capable of breaking current encryption.
NIST’s timetable calls for quantum-vulnerable algorithms to be deprecated by 2030 and removed from its standards by 2035, with high-risk systems expected to move earlier. The deadline applies to federal cryptographic standards rather than imposing a direct upgrade requirement on decentralized blockchain networks.
Institutional Bitcoin companies have also committed funding to the issue. In July, Strategy, BlackRock, Coinbase, and six other companies created a Bitcoin security consortium whose members pledged a combined $15 million over three years.
Anchorage Digital, ARK Invest, Block, Blockstream, Fidelity Digital Assets, and Galaxy joined the group. Members will choose which developers, researchers, and organizations receive their funding, while the consortium will not direct Bitcoin development or support a specific protocol change.
Ethereum developers have taken a separate route through network research and testing. Ethereum Foundation researcher Justin Drake said on Aug. 13 that Ethereum’s future layer-1 design will move away from the Poseidon hash function and use established functions such as SHA-2 or BLAKE2s.
The Ethereum roadmap change followed advances in proof systems that made traditional hash functions more practical for zero-knowledge technology. A production version of leanVM is scheduled for 2027, followed by planned protocol deployments in 2028.
At the custody level, BitGo and Silence Laboratories completed a post-quantum signing test in May using BitGo’s institutional platform and Silence Laboratories’ multi-party computation system. The simulation used ML-DSA, a digital signature algorithm included in NIST’s FIPS 204 standard, while retaining distributed key control, policy checks, and separate responsibilities across institutional teams.
Crypto World
Morgan Stanley’s XRP Exposure Emerges as Price Struggles Near $1
XRP has shed more than 10% over the past week as its struggle near $1 continues. This downward pressure has pushed the crypto asset’s yearly losses to almost 70%.
Despite the negative sentiment, institutional participation appears to be intact, as several firms continue to use exchange-traded products to gain exposure to XRP.
Institutions Remain Unfazed
Morgan Stanley has disclosed its XRP exposure in the second quarter of 2026. The Wall Street giant holds positions through three XRP-linked exchange-traded funds: Franklin, REX-Osprey, and Bitwise ETF. Its largest position was in the Franklin fund, with 6,715 shares. The filing showed 255 shares of the REX-Osprey ETF and 67 shares of Bitwise’s.
The 13F filing also shows a larger position in Armada Acquisition Corp II, the SPAC partner of Ripple-backed Evernorth Holdings.
Several investment firms have had exposure to the token through exchange-traded products. For example, Wolverine Asset Management held 199,912 shares of the Bitwise XRP ETF. Gallacher Capital Management held 86,744 shares of Canary’s XRP ETF. Main Street Group had 5,261 shares of the same fund.
Meanwhile, Moisand Fitzgerald Tamayo held 964 shares of the Franklin XRP ETF. Additionally, National Bank of Canada revealed 3,848 shares of Bitwise’s XRP ETF.
Opportunity Amid Pressure
The picture looks less encouraging when it comes to XRP’s broader market activity. As reported by CryptoPotato, the Taker Buy/Sell Ratio is around 0.86, its lowest level since last May. The ratio has stayed below 1 for most of the recent period, which means that sellers have generally been more aggressive than buyers in the derivatives market.
There have been short-lived moves above 1, but buyers have yet to establish a clear change in momentum. A move back above that level could be a better sign for XRP, especially if it also starts seeing stronger volume and price action.
For now, however, derivatives traders appear to be leaning toward the sell side. Futures open interest also remains elevated and stands at 435.1 million units, above the 403.6 million 30-day average, with a +1.20σ Z-score, meaning “leverage is still stacked.” As such, the token is at risk of a liquidation cascade if it dumps further.
But the current weakness may also create a potential setup for a future recovery. ChartNerd highlighted $1.24 as an important level to reclaim. If the asset fails to do so, the analyst identified the $0.90-$0.70 range as a possible area where accumulation could take place.
ChartNerd also expects a retest of the 3-month 40 EMA to help XRP form a stronger base. Similar setups played out in 2023 and 2024, according to the analyst.
The post Morgan Stanley’s XRP Exposure Emerges as Price Struggles Near $1 appeared first on CryptoPotato.
Crypto World
The SEC pulled its own crypto vote and nobody saw it coming
The agency cancelled its August 14 Regulation Crypto meeting one day before commissioners were set to vote, citing an “unforeseen scheduling issue” that no one inside or outside the building predicted. With Congress already on recess and the CLARITY Act frozen until September, the double stall leaves every token project in America waiting for rules that neither branch of government can deliver right now.
Summary
- The SEC cancelled its August 14 open meeting to vote on Regulation Crypto, a roughly 400 page proposed rule that would have created three exemption pathways for token offerings, including a $75 million annual fundraising cap and a decentralization safe harbor.
- The cancellation notice appeared on August 13, one day after the White House Office of Information and Regulatory Affairs received the Reg Crypto NPRM under tracking number RIN 3235-AN38, meaning the rulemaking package was already in the federal pipeline when the vote was pulled.
- The Senate left Washington on August 8 without a floor vote on the CLARITY Act, pushing the next procedural motion to September 15 and sending Polymarket odds for passage in 2026 crashing from an 82% February peak to roughly 16%.
- Commissioner Hester Peirce, who led the SEC Crypto Task Force since January 2025, is leaving the agency in November 2026 to join Regent University School of Law, dropping the commission to two active members and creating untested quorum risks for any major rulemaking.
- The joint SEC and CFTC interpretive release from March 17, 2026, which sorted every crypto asset into one of five categories, remains the only binding regulatory framework in effect while both the legislative and administrative paths sit frozen.
The SEC was supposed to vote on the most ambitious crypto rulemaking in the agency’s 90 year history on a Friday morning in August, and then it did not. The cancellation notice landed on the SEC website at approximately 4:30 p.m. Eastern on Wednesday, August 13, offering a single explanation: “unforeseen scheduling issue.” No replacement date. No elaboration. No indication of whether the delay would last days or months. The timing turned a procedural pause into a structural problem, because the other path to regulatory clarity, the CLARITY Act winding through the Senate, had already frozen six days earlier when lawmakers left for a five week recess without bringing the bill to the floor. For the first time since the current administration took office promising to end regulation by enforcement, both tracks toward crypto rules are stalled simultaneously, and no one in Washington has offered a credible timeline for restarting either one.
What the SEC was about to vote on
The open meeting agenda contained a single item: whether to formally propose new rules creating a tailored offering regime for certain investment contracts involving crypto assets. The shorthand for the package is Regulation Crypto, and its ambition matched its length. The roughly 400 page proposal built three legal pathways for token projects seeking to raise capital without triggering the SEC’s full registration requirements.
The first pathway, the startup exemption, would have allowed early stage teams to raise up to $5 million over four years using whitepaper style disclosure instead of the audited financial statements required under traditional securities registration. The second, the fundraising exemption, borrowed its $75 million annual ceiling directly from Regulation A+ Tier 2, the JOBS Act framework that regulators and lawyers have understood since 2015, and added crypto specific requirements including semi-annual reporting and audited financials. The third and most consequential pathway was the investment contract safe harbor, which would have allowed tokens that achieved sufficient decentralization to exit securities classification entirely. Once an issuer could show that it had completed or permanently ceased the essential managerial efforts it promised at launch, the token would shed its securities wrapper and move outside the SEC’s jurisdiction.
A yes vote from the three member commission would not have made any of these pathways law. It would have opened a formal notice and comment period under the Administrative Procedure Act, inviting the public to weigh in on the proposed rules before the agency could finalize them. But even that procedural starting gun carried enormous weight, because it would have signaled that the SEC was committed to building a regulatory infrastructure for digital assets through rulemaking instead of the enforcement actions that defined the previous administration’s approach.
How the cancellation unfolded
The SEC posted the August 14 meeting on its website on August 11, a Monday. By Tuesday, the White House Office of Information and Regulatory Affairs had received the NPRM under RIN 3235-AN38, confirming that the rulemaking package had cleared the agency’s internal review and entered the federal regulatory pipeline. Chair Paul Atkins had spent the preceding weeks signaling that Regulation Crypto was his top priority. The machinery appeared to be working.
Then, on Wednesday afternoon, the SEC replaced the meeting notice with a cancellation. The stated reason, an unforeseen scheduling issue, carried no further detail. The agency did not withdraw the proposal from OIRA’s queue, did not issue a statement from the Chair, and did not announce a replacement date. Reginfo.gov still lists the Crypto Assets proposal as pending review, which multiple legal analysts have interpreted as evidence that the cancellation reflects a delay rather than an abandonment.
The abruptness is what distinguishes this from ordinary Washington scheduling friction. Open meetings are typically announced with enough lead time to signal seriousness, and cancellations at the 24 hour mark are rare enough that former SEC staffers interviewed by several outlets described the move as highly unusual. The gap between the official explanation and the scale of the rulemaking it interrupted has produced a secondary question that the agency has not answered: what, specifically, was unforeseen about the scheduling?
The commissioner question nobody will answer on the record
The SEC currently operates with three commissioners, all Republican: Chair Paul Atkins, Commissioner Mark Uyeda, and Commissioner Hester Peirce. That is a functioning quorum, but it is also the minimum, and the dynamics within a three person body are different from those within the five member commission the Securities Exchange Act of 1934 envisioned.
Peirce, widely known in digital asset circles as “Crypto Mom,” announced in June 2026 that she would leave the agency in November to join Regent University School of Law. Her departure will drop the commission to two active members, a configuration that has no modern precedent for conducting major rulemaking. An SEC rule adopted in 1995 permits the commission to conduct business with fewer than three commissioners, but administrative law scholars have questioned whether a rule finalized by a two member body could survive judicial challenge, particularly after the Supreme Court’s 2024 decision in Loper Bright Enterprises v. Raimondo raised the bar for agency deference.
The timing matters because Peirce’s exit creates a hard deadline: any rulemaking the SEC wants to finalize with a three vote margin must reach a final vote before November. If Regulation Crypto’s notice and comment period runs the standard 60 to 90 days, a vote that does not happen until late September or October would push the final rule into 2027 at the earliest, by which point the commission may have only two members. Two commissioners can still vote, but the APA vulnerability is real. Industry lawyers have already begun flagging the risk that a Reg Crypto final rule adopted by a two member commission could face procedural challenges that a three member vote would not.
None of the three commissioners have publicly addressed whether internal disagreement played a role in the cancellation. The official explanation points to scheduling. But observers have noted that Chair Atkins and Commissioner Uyeda have occasionally diverged on the pace and scope of crypto rulemaking throughout 2026, and that a three person commission offers no room to absorb a single dissent without killing a proposal entirely. Whether the “unforeseen scheduling issue” is a euphemism for a substantive disagreement or a genuine logistical conflict remains an open question that the agency has declined to clarify.
The CLARITY Act froze first
The SEC’s vote was always framed as a fallback. Chair Atkins said publicly that the agency was prepared to write the rules itself if Congress could not act, and the timing of Regulation Crypto’s development tracked directly with the CLARITY Act’s deterioration in the Senate.
The Digital Asset Market Clarity Act passed the House in July 2025 by a 294 to 134 vote with significant bipartisan support. It cleared the Senate Banking Committee in May 2026 by a 15 to 9 margin. Then it stalled. Disagreements over ethics provisions, DeFi protocol treatment, stablecoin yield language, and the government ethics provision that would have restricted certain officials from holding digital assets created a negotiating impasse that Senate leadership could not resolve before the August recess.
Senate Majority Leader John Thune confirmed that the chamber would delay voting on the legislation until after the recess, blaming Democrats for impeding progress. The next procedural vote, a motion to proceed rather than a final passage vote, is scheduled for September 15. But the Senate returns with only three working weeks before election cycle dynamics begin consuming legislative bandwidth, and the bill’s opponents have shown no sign of softening their positions on the outstanding disputes.
Polymarket captures the market’s verdict on those odds. The prediction market contract for the CLARITY Act being signed into law in 2026 peaked at 82% in February, when bipartisan momentum appeared genuine. It dropped to 43% in July after reports that the White House had brokered an ethics deal. It crashed to 16% when the Senate left town without acting. Each missed deadline, a White House floated July 4 signing ceremony, a late July practical window, and now the August recess, has eroded confidence that Congress can deliver comprehensive crypto legislation before gridlock takes permanent hold.
What the double stall means for projects on the ground
The practical consequence of both paths freezing simultaneously is that the only binding federal framework for crypto classification remains the joint SEC and CFTC interpretive release from March 17, 2026. That release sorted every crypto asset into one of five categories: digital commodities, digital collectibles, digital tools, stablecoins, and digital securities. It designated 16 major tokens including Bitcoin, Ethereum, Solana, and XRP as digital commodities under CFTC jurisdiction. It answered the decade old question of whether those specific assets are securities.
But it did not answer the question that Regulation Crypto was designed to address: how new tokens should be issued, what disclosure they require, and when they can exit securities classification. Projects planning token launches in the second half of 2026 now face a regulatory gap where neither the SEC nor Congress has provided usable rules. The startup exemption, the $75 million fundraising pathway, and the decentralization safe harbor all exist only in a draft that has not yet entered the comment period.
Industry groups have pointed to tangible effects. Dozens of crypto projects shut down or relocated outside the United States in 2026, citing regulatory uncertainty as a primary driver. Firms cannot plan custody arrangements, product roadmaps, or compliance architectures without knowing which agency holds jurisdiction over their specific token and what registration requirements apply. The March interpretive release clarified the commodity versus security question for 16 named tokens, but it explicitly did not address the hundreds of smaller assets and new launches that fall outside its scope.
The CFTC, meanwhile, has moved to fill part of the vacuum. The commodity regulator is preparing its inaugural digital asset regulatory session, and the White House convened crypto executives in early August in what multiple outlets described as a signal that the executive branch may be shifting emphasis from SEC securities law to CFTC commodities oversight. Whether that shift produces actionable rules faster than the SEC’s stalled process remains to be seen.
The cost of waiting is not evenly distributed. Well capitalized projects with existing legal teams can absorb months of uncertainty by operating under existing exemptions or structuring around Regulation D private placements. Smaller teams, the ones the startup exemption was specifically designed to help, face a harder calculation. A seed stage protocol that planned to launch under the $5 million whitepaper pathway now has no pathway at all, and every month of delay burns runway without producing the token sale revenue the team budgeted for. The irony is that the projects most vulnerable to regulatory delay are the same ones the SEC’s proposal was most clearly trying to protect. For founders in that position, the August 14 cancellation did not just postpone a rule. It postponed the only rule designed to meet them where they are.
The opposing case: this is a speed bump, not a collapse
The most credible version of the optimistic reading begins with the OIRA queue. The SEC did not withdraw the Reg Crypto NPRM from the White House review process. Reginfo.gov still lists RIN 3235-AN38 as pending, which means the rulemaking package remains intact and can be voted on whenever the commission reschedules. A delay is not a withdrawal, and the SEC has a documented institutional interest in completing the process before Peirce’s November departure narrows the commission.
Supporters of this view also note that the five category token taxonomy from March is already doing real work. The 16 token commodity designation triggered $500 million in Bitcoin ETF inflows during March alone, reversing four months of outflows. The framework is functioning. Regulation Crypto would extend it, not replace it, and the underlying policy direction, replacing enforcement with rulemaking, has not changed.
On the legislative side, the CLARITY Act is delayed but not dead. It cleared two committees with bipartisan votes. The September 15 procedural motion is a real vote, not a symbolic gesture, and Senate leadership has kept the bill on the calendar instead of shelving it. The ethics dispute that stalled negotiations is a solvable problem, not an ideological chasm, and the compromise that emerged in July, prohibiting interest on idle stablecoin balances while permitting activity based rewards, showed that the negotiating parties can find middle ground when political pressure is sufficient.
What would invalidate the thesis that both paths are structurally frozen? Three specific developments: the SEC announcing a replacement meeting date within the next two weeks, the Senate returning early from recess for a procedural vote, or the White House brokering a deal on the remaining CLARITY Act disputes before September 15. Any one of those would break the stall. If all three fail to materialize by late September, the regulatory freeze extends into 2027 and the two member commission scenario becomes the baseline.
Why this cancellation is different from every previous delay
Crypto regulation has been “about to happen” for years. What makes the August 14 cancellation qualitatively different is the convergence of three clocks that had never previously aligned against the industry simultaneously.
The first clock is the SEC’s shrinking commission. Peirce’s departure in November means every month of delay reduces the window for a three member vote. The second clock is the Senate calendar. Congress returns on September 9 with approximately three working weeks before the midterm campaign absorbs all legislative energy, and the CLARITY Act still needs to clear a cloture vote, a floor amendment process, and a conference committee reconciliation with the House version. The third clock is the market. Projects that delayed their launches waiting for Regulation Crypto or the CLARITY Act now face a choice between launching without a clear legal framework, continuing to wait with no guaranteed timeline, or leaving the United States entirely.
No previous delay triggered all three pressures at once. The SEC’s 2023 enforcement pause affected the agency’s posture but not Congress. The CLARITY Act’s July 4 deadline miss affected Congress but not the SEC’s independent rulemaking. The August 14 cancellation is the first event that froze both tracks while a commissioner departure was already counting down, creating a regulatory vacuum with no obvious exit before the end of the year.
A competitor publication would frame this as another episode in Washington’s endless inability to regulate crypto. The difference in this analysis is the specificity of the clocks. This is not a general story about dysfunction. It is a story about three independent timelines that converged on a single week in August and, for the first time, left no fallback path operational.
What to watch
SEC meeting reschedule announcement: If the agency posts a new open meeting date for Regulation Crypto within two weeks of the cancellation, the delay is administrative. If no date appears by September 1, the stall is structural and likely extends past Peirce’s November departure.
September 15 cloture vote on the CLARITY Act: This is the first procedural test when the Senate returns. A successful motion to proceed does not guarantee passage, but it signals that 60 senators are willing to engage with the bill. Failure here effectively kills the CLARITY Act for 2026.
OIRA status of RIN 3235-AN38: The Reginfo.gov listing is a leading indicator. If the SEC withdraws the NPRM from OIRA review, the rulemaking is dead. If it remains pending, the agency still intends to hold the vote.
CFTC digital asset session timing: The commodity regulator’s inaugural digital asset rulemaking session is an alternative signal. If the CFTC moves faster than the SEC to propose rules for digital commodities, the jurisdictional balance shifts further toward commodities oversight and away from the securities framework that Regulation Crypto represents.
Polymarket CLARITY Act contract: The prediction market has tracked every milestone and missed deadline with pricing precision. A sustained move above 25% would indicate that informed bettors see a viable path to passage. Continued decay below 15% would confirm the market’s assessment that 2026 legislation is effectively off the table.
This article was published on August 14, 2026, and reflects information available as of that date. It is intended for educational and informational purposes only and does not constitute investment advice, legal advice, or a recommendation to buy, sell, or hold any digital asset. Regulatory developments can change rapidly, and readers should consult qualified professionals before making decisions based on the information presented here.
What is Regulation Crypto and why does it matter?
Regulation Crypto is a proposed SEC rulemaking that would create three exemption pathways for token offerings: a startup exemption allowing raises up to $5 million, a fundraising exemption capped at $75 million per year, and a decentralization safe harbor that would let sufficiently decentralized tokens exit securities classification. It matters because it represents the SEC’s attempt to regulate crypto through formal rulemaking, moving beyond the enforcement actions that defined previous administrations.
Why did the SEC cancel the August 14 vote?
The SEC cited an “unforeseen scheduling issue” in its cancellation notice, posted on August 13. The agency provided no further detail and did not announce a replacement date. The proposal remains in the OIRA review queue under RIN 3235-AN38, indicating a delay rather than a withdrawal. The specific cause of the cancellation has not been publicly disclosed.
What is the CLARITY Act and where does it stand?
The Digital Asset Market Clarity Act is a congressional bill that would draw jurisdictional boundaries between the SEC and CFTC for digital assets. It passed the House in July 2025 by a 294 to 134 vote and cleared the Senate Banking Committee in May 2026. The Senate left for August recess without a floor vote, and the next procedural motion is scheduled for September 15.
How does Peirce’s departure affect the SEC’s crypto agenda?
Commissioner Hester Peirce, who led the SEC Crypto Task Force, is leaving the agency in November 2026 for a faculty position at Regent University School of Law. Her departure drops the commission from three active members to two, creating untested quorum dynamics for major rulemaking. Administrative law scholars have questioned whether rules finalized by a two member commission could survive judicial challenge.
What is the five category token taxonomy?
The SEC and CFTC jointly published a 68 page interpretive release on March 17, 2026, sorting every crypto asset into five categories: digital commodities, digital collectibles, digital tools, stablecoins, and digital securities. The release designated 16 major tokens, including Bitcoin, Ethereum, Solana, and XRP, as digital commodities under CFTC jurisdiction.
What happens to token projects that were waiting for Regulation Crypto?
Projects planning token launches in the second half of 2026 now face a regulatory gap. The startup exemption, the $75 million fundraising pathway, and the decentralization safe harbor all exist only in a draft that has not entered the comment period. Projects must choose between launching without clear legal guidance, continuing to wait with no guaranteed timeline, or relocating outside the United States.
Could the SEC still finalize Regulation Crypto in 2026?
Technically, yes, but the timeline is tight. If the SEC reschedules the vote by early September, a 60 to 90 day comment period would push the final rule into late 2026 or early 2027. Finalizing before Peirce’s November departure would require an unusually compressed timeline. If the vote does not happen until after her exit, the final rule would be adopted by a two member commission, raising potential legal vulnerabilities.
Is the regulatory freeze permanent?
No. The OIRA listing, the Senate calendar, and the CFTC’s independent rulemaking all represent potential paths to restarting the process. The freeze is a convergence of three independent timelines, not a permanent structural barrier. However, if neither the SEC nor Congress acts before November 2026, the regulatory gap could extend well into 2027. This is educational analysis, not investment advice.
Crypto World
Grayscale quietly killed three altcoin ETFs two days before Cardano became eligible
Grayscale withdrew its Cardano, Polkadot, and Hedera ETF registrations in under four minutes on August 7, exactly two days before ADA cleared the SEC seasoning threshold. With Bitwise and Canary still in the race, the retreat says more about the economics of altcoin ETFs than about Cardano itself.
Summary
- Grayscale filed three Form RW withdrawals with the SEC on August 7, 2026, pulling its Cardano Trust ETF, Polkadot Trust ETF, and Hedera Trust ETF registrations in a span of 190 seconds, with no shares issued, sold, or distributed under any of the three.
– Cardano completed its six-month CME futures seasoning period on August 9, 2026, two days after Grayscale walked away, clearing the threshold that would have allowed a spot ADA ETF to list under the SEC generic listing standards in as few as 75 days.
– Five other issuers, including Bitwise, Canary Capital, VanEck, and 21Shares, still have active ADA ETF filings, with the earliest possible SEC decision window falling around October 23, 2026.
– Grayscale reported a 20 percent revenue decline in its IPO filing, with GBTC and ETHE generating 88 percent of the firm’s roughly $318.7 million in nine-month revenue while bleeding a combined $30 billion in cumulative outflows since their ETF conversions.
– ADA trades near $0.196 with a $6.55 billion market cap, DOT sits at $0.805, and HBAR has fallen to $0.068, all down more than 60 percent from their all-time highs and collectively representing a fraction of the institutional demand that drove Bitcoin and Ethereum ETF launches.
At 4:33 p.m. Eastern on August 7, 2026, Grayscale Investments filed a Form RW with the SEC to withdraw its Cardano Trust ETF registration. Ninety seconds later, the Hedera Trust ETF followed. Two minutes after that, the Polkadot Trust ETF joined them. Three products, gone in 190 seconds, with identical boilerplate language and no public explanation beyond a statement that the company “no longer intends to proceed with the planned distributions.”
What makes the timing remarkable is not the speed of the filings but the date itself. Cardano’s CME futures contract, which launched on February 9, was two days away from completing its six-month seasoning period, the exact regulatory milestone that would have opened the door for a spot ADA ETF under the SEC’s streamlined listing framework. Grayscale did not just exit the altcoin ETF race. It exited on the finish line.
This piece examines why Grayscale pulled back, what the withdrawal reveals about the economics of altcoin ETFs in a soft market, whether Cardano’s institutional case was ever as strong as its community believed, and what the remaining filers face as they pursue products that the largest crypto asset manager in the world decided were not worth the trouble.
Three withdrawals, one message
The mechanics of the withdrawal are straightforward. Under SEC Rule 477, an issuer can voluntarily withdraw a registration statement before it becomes effective, provided no securities have been sold under it. Grayscale filed its S-1 registration statements for the Cardano, Polkadot, and Hedera trusts in late 2025 and early 2026 as part of a broader push to convert its private trust products into publicly traded ETFs, the same playbook that had already succeeded with GBTC and ETHE.
All three Form RW filings contained identical language. None cited a specific reason for withdrawal. The SEC accepted them without comment. Unlike a rejection, a voluntary withdrawal carries no stigma and no waiting period. Grayscale could refile tomorrow if it chose to.
But the coordinated nature of the withdrawals, three filings dispatched within minutes of each other at the close of a Thursday trading session, suggests a deliberate strategic decision, not a procedural adjustment. This was not a pause. It was a retreat.
The crypto market noticed. ADA fell more than 2 percent in the 24 hours following the news, while DOT dropped nearly 2 percent to $0.805 and HBAR slipped 2.24 percent to $0.068. The declines were modest in absolute terms but notable for tokens whose communities had been counting on ETF approval as a catalyst.
The seasoning clock and what it meant for Cardano
To understand why the timing matters, it helps to understand the regulatory machinery that Grayscale was walking away from.
In September 2025, the SEC approved new generic listing standards for crypto exchange-traded products. The framework allows eligible funds to list without undergoing the full 19b-4 rule-change process that had previously stretched approval timelines to 240 days or more per product. Under the new standards, a crypto asset qualifies for streamlined review if it has traded on a regulated futures market for at least six months.
CME Group launched Cardano futures on February 9, 2026. The six-month clock expired on August 9. On that date, ADA became the newest cryptocurrency to meet the SEC’s eligibility threshold, joining Bitcoin, Ethereum, Solana, and XRP in the small club of assets with a clear path to a spot ETF.
Grayscale knew this. Every issuer in the space knew this. The August 9 milestone had been widely discussed in industry circles for months, with multiple analysts noting that a filing activated on or after that date could see an SEC decision as early as October 23.
Yet Grayscale chose to withdraw two days before the clock expired. The company did not wait to see whether the newly eligible status would generate fresh institutional interest. It did not pause the filing to reassess. It killed it. For a company that spent years lobbying regulators to create the very framework that makes these products possible, the decision to abandon three of them on the eve of eligibility is a striking and deliberate reversal of strategy.
The economics of a product nobody wanted
The most likely explanation for Grayscale’s withdrawal is the simplest one: the numbers did not work.
Launching an ETF is not free. Legal fees, compliance infrastructure, market-making arrangements, custodial agreements, marketing, and ongoing regulatory reporting all carry costs. For a Bitcoin or Ethereum product with billions of dollars in potential demand, those costs are trivial relative to the revenue from management fees. For an altcoin ETF tracking a $6.55 billion asset with tepid institutional interest, the calculus is different.
Consider the existing data points. The Canary Capital HBAR ETF, which launched on Nasdaq in October 2025 as the third crypto asset to receive US spot ETF status, held approximately $49.14 million in net assets as of July 2, 2026. Its market-price return was negative 37.32 percent for the year and negative 63.32 percent since inception. Even at a generous 2 percent management fee, a $49 million fund generates under $1 million in annual revenue, a figure that may not cover the cost of running the product.
The broader altcoin ETF landscape tells a similar story. While XRP ETFs have accumulated roughly $1.5 billion in cumulative inflows and Solana funds have gathered about $1.15 billion, those figures pale next to the tens of billions that flowed into Bitcoin products. Below the top tier, demand drops off sharply. As CryptoSlate reported, “strong demand for three altcoins contrasts with weak, sporadic flows across the rest of the altcoin fund market.”
Grayscale already has a way to offer ADA exposure. Its CoinDesk Crypto 5 ETF, trading under the ticker GDLC, tracks an index that includes Bitcoin, Ethereum, XRP, Solana, and Cardano. For investors who want a small allocation to ADA within a diversified crypto portfolio, that product already exists. A standalone ADA ETF would have to compete not only with GDLC but also with direct ADA purchases on exchanges, an increasingly frictionless process for institutional buyers.
Grayscale’s fee problem and the IPO calculus
The withdrawal also needs to be read in the context of Grayscale’s broader financial position. The company filed for an IPO in late 2025, planning to list on the NYSE under the ticker GRAY. The S-1 filing revealed a business under significant pressure.
GBTC, charging 1.5 percent annually, and ETHE, charging 2.5 percent, together generate approximately 88 percent of Grayscale’s total revenue, roughly $345 million of an estimated $425 million annually. But both products have been hemorrhaging assets. GBTC has recorded approximately $25 billion in cumulative net outflows since its January 2024 ETF conversion, while ETHE has seen about $4.8 billion leave since July 2024. Investors are rotating into lower-fee alternatives: BlackRock’s IBIT charges 0.12 percent, and Fidelity’s FBTC charges 0.25 percent.
Grayscale responded by launching Mini versions of both products at 0.15 percent, which have attracted $3.3 billion in combined inflows since 2024. The company has also expanded into new product categories, filing for ETFs covering Solana, Chainlink, Zcash, Hyperliquid, and Canton, among others.
But expansion costs money. Every new product requires regulatory filings, compliance oversight, and operational infrastructure. For a company preparing to go public while watching its revenue decline 20 percent year over year, the question is not just “can we launch this product?” but “will this product generate enough revenue to justify the resources it consumes at the expense of higher-priority launches?”
For ADA, DOT, and HBAR, the answer appears to have been no. Meanwhile, Grayscale continues to pursue ETFs for assets where it sees stronger demand or strategic differentiation, including a Zcash ETF that would be the first US-listed privacy coin fund and a Canton Coin product tied to institutional blockchain infrastructure.
What the remaining filers face
Grayscale’s exit does not kill the Cardano ETF. Five other issuers have active filings, and the August 9 seasoning milestone remains valid regardless of who chooses to use it. Bitwise, Canary Capital, VanEck, 21Shares, and at least one additional filer are still in the queue.
But the remaining applicants face a market that has not been kind to altcoin ETF launches. The Canary HBAR ETF’s experience is instructive. Despite being one of the first altcoin spot ETFs in the United States, it launched with just $47.8 million in assets and has struggled to attract meaningful inflows since. The lesson is that regulatory approval alone does not create demand. Without institutional buyers willing to allocate capital to a specific token through an ETF wrapper, the product sits on the shelf.
Cardano has some advantages that HBAR lacked at launch. Its market cap of $6.55 billion is substantially larger. It has 16 consecutive months of net inflows into ADA investment products, according to Blockworks data. Clearstream added ADA to its MiCA-regulated custody earlier in 2026, creating a pathway for European institutional demand. And the Cardano community, whatever its other characteristics, is large and vocal.
But “large and vocal” does not always translate to “willing to buy an ETF.” Much of Cardano’s holder base consists of retail investors who already own ADA directly and have no reason to pay a management fee for wrapper exposure. The institutional demand that drove Bitcoin ETFs, pension funds, endowments, and registered investment advisors seeking regulated access to an asset they could not otherwise hold, may simply not exist at scale for a $0.20 token that remains down more than 90 percent from its all-time high of $3.10.
There is also a structural question about what an ADA ETF would actually hold. Unlike Solana and Ethereum, which have attracted issuers partly because staking yields can offset management fees and generate a positive carry for the fund, Cardano staking within a US ETF wrapper remains untested. Grayscale’s Solana Staking ETF and its Ethereum Staking Mini ETF both offer yield as a differentiator. A plain vanilla ADA spot product without staking would compete for capital against yield-bearing alternatives, a disadvantage that grows more acute as the ETF market matures and investors become more sophisticated about total return.
The fee question compounds the problem. Morgan Stanley launched Ethereum and Solana ETFs at 0.14 percent, setting a new floor for the industry. Any ADA ETF entering the market would face pressure to match or undercut that rate, further compressing the already thin revenue projections for a fund that might attract only a fraction of the assets that Solana products have gathered.
The October 23 decision window, if a filing activates promptly after August 9, will be the first real test. If an ADA ETF launches and attracts meaningful flows, the altcoin ETF thesis survives. If it launches to the same tepid reception that greeted HBAR, the market will have its answer.
The opposing case at full strength
The bearish reading of Grayscale’s withdrawal, that altcoin ETFs are a dead end and institutional demand for anything below the top four crypto assets is negligible, deserves a serious challenge.
First, the timing may not be as significant as it appears. Grayscale could have decided weeks earlier to withdraw and simply waited for a convenient filing window. The proximity to August 9 may be coincidental rather than calculated.
Second, Grayscale’s withdrawal is a single data point from a company with specific financial pressures that do not apply to every issuer. Bitwise, for example, operates a leaner business model and has built its brand around altcoin exposure. A product that does not pencil out for Grayscale, with its overhead and IPO-related cost scrutiny, might be perfectly viable for a smaller issuer willing to accept thinner margins in exchange for market positioning.
Third, the altcoin ETF market is young. Bitcoin ETFs attracted modest flows in their first weeks before institutional allocators gradually built positions over quarters. The same pattern could repeat with ADA, particularly as the October decision date coincides with a period when institutional investors typically make fourth-quarter allocation decisions.
Fourth, Cardano’s fundamentals have continued to develop. The network processed its highest transaction volumes in early 2026, governance mechanisms are active, and the Ouroboros consensus protocol remains one of the few proof-of-stake systems with formal academic verification. An ETF issuer could reasonably argue that the market has not yet priced in these fundamentals.
Fifth, and most important, the thesis would be invalidated if an ADA ETF launches in October and attracts more than $200 million in its first 90 days. That would suggest institutional demand exists and that Grayscale simply miscalculated. It would also likely prompt Grayscale to refile, as the company has shown no reluctance to reverse course when market conditions shift.
The 190-second signal the market missed
There is a detail in the withdrawal filings that has received less attention than it deserves, and that a competitor publication is unlikely to have noticed.
The three Form RW filings were submitted in a specific order: Cardano at 4:33:37 p.m. ET, Hedera at 4:34:55 p.m., and Polkadot at 4:36:47 p.m. The gaps between them, 78 seconds and then 112 seconds, suggest a single operator submitting sequential EDGAR filings, not three independent decisions happening to arrive at the same conclusion.
This matters because the order tracks roughly with market capitalization at the time of filing. ADA, the largest of the three at $6.55 billion, went first. HBAR, at roughly $3.1 billion, went second. DOT, at approximately $1.5 billion, went last. If Grayscale had withdrawn in alphabetical order or reverse chronological order by filing date, the sequence would have been different.
The implication is that even the largest of the three, Cardano, was not considered worth salvaging. Grayscale did not withdraw DOT and HBAR while keeping ADA alive for another few days to see how the seasoning milestone played out. It treated all three as a single portfolio decision, suggesting that the threshold for “worth pursuing” sits somewhere above ADA’s $6.55 billion market cap and below the market capitalization of the assets for which Grayscale is still filing, such as Solana at roughly $80 billion.
That threshold has implications far beyond Cardano. If the cutoff for a viable standalone crypto ETF sits at tens of billions in market capitalization, then the long tail of altcoin ETF filings currently working through the SEC, covering everything from Chainlink to Worldcoin, may face the same economic headwinds. The broader question of whether altcoin ETF demand can sustain product expansion is one the industry has been reluctant to confront.
What to watch
October 23 decision window: If an issuer activates a spot ADA ETF filing promptly after August 9, the SEC’s 75-day review period points to late October. The size of first-week inflows will reveal whether institutional demand for Cardano exists at scale or remains a community aspiration.
Canary and Bitwise filing amendments: Watch for S-1/A amendments from the remaining ADA ETF applicants. Active amendments signal continued commitment. Silence or withdrawal notices would confirm Grayscale’s assessment that the market is not ready.
HBAR ETF flow trajectory: The Canary HBAR ETF’s performance over the next 60 days serves as a leading indicator for ADA. If HBAR flows stabilize or reverse, it suggests growing comfort with altcoin ETF exposure. Continued outflows would validate the bearish thesis.
Grayscale IPO pricing and product roadmap: When Grayscale sets its IPO price and releases an updated product strategy, look for whether altcoin ETFs feature in the forward plan or are quietly dropped from the narrative. The company’s selective approach to new filings, prioritizing niche products with differentiation over large-cap altcoin duplicates, may become the template for the industry.
ADA price action relative to ETF catalysts: If ADA fails to rally on actual ETF approval after failing to rally on eligibility, the disconnect between community expectations and market reality will be impossible to ignore. A sustained move above $0.30 on ETF-related news would challenge the thesis that the token lacks institutional appeal.
The information presented in this article is for educational and informational purposes only. It does not constitute financial, investment, legal, or tax advice. Cryptocurrency investments carry significant risk, including the potential loss of all invested capital. Readers should conduct their own research and consult qualified financial advisors before making any investment decisions. Crypto.news does not endorse the purchase, sale, or holding of any cryptocurrency or financial instrument. Past performance is not indicative of future results. Published August 14, 2026.
Is the ADA ETF still happening without Grayscale?
Yes. Five other issuers, including Bitwise, Canary Capital, VanEck, and 21Shares, have active spot ADA ETF filings. Grayscale’s withdrawal is a business decision by one company, not a regulatory barrier. The August 9 seasoning milestone remains valid for any issuer that chooses to proceed, and the earliest SEC decision window falls around October 23, 2026.
Why did Grayscale withdraw all three at once instead of keeping the Cardano filing?
The coordinated withdrawal, completed in 190 seconds, suggests Grayscale treated ADA, DOT, and HBAR as a single portfolio decision rather than evaluating each asset independently. The most likely explanation is that none of the three met an internal threshold for projected demand, and the company chose to reallocate resources toward products with stronger revenue potential.
What is the CME futures seasoning period and why does it matter?
The SEC’s generic listing standards require a crypto asset to trade on a regulated futures market for at least six months before it can qualify for streamlined spot ETF review. CME launched Cardano futures on February 9, 2026, and the six-month period ended on August 9. Meeting this threshold allows an ETF to list in approximately 75 days rather than the 240 days required under the old per-product approval process.
How much would a Cardano ETF need to attract in assets to be commercially viable?
Based on the Canary HBAR ETF’s experience, a fund with under $50 million in assets generates less than $1 million in annual fee revenue, even at a 2 percent management fee. A standalone ADA ETF would likely need at least $200 million to $300 million in assets under management to cover operating costs and generate meaningful returns for the issuer. By comparison, XRP ETFs have attracted roughly $1.5 billion and Solana funds about $1.15 billion.
Could Grayscale refile for a Cardano ETF later?
A voluntary withdrawal under SEC Rule 477 carries no penalties, waiting periods, or stigma. Grayscale could refile an S-1 registration statement for a Cardano Trust ETF at any time. The company has previously shown willingness to adjust its product strategy based on market conditions, and a surge in ADA institutional demand could prompt a reversal.
What does Grayscale’s withdrawal mean for DOT and HBAR prices?
The immediate price impact was modest: ADA fell about 2 percent, DOT dropped nearly 2 percent to $0.805, and HBAR slipped 2.24 percent to $0.068. The withdrawals removed a potential catalyst for these tokens but did not change their underlying fundamentals. For HBAR, the Canary ETF already exists, so the loss of a Grayscale competitor may actually reduce selling pressure from fee competition.
Are altcoin ETFs still worth pursuing for issuers?
The market is splitting into tiers. Bitcoin and Ethereum ETFs have attracted tens of billions. Solana and XRP funds have crossed the $1 billion mark. Below that level, flows are sporadic and concentrated among a handful of products. The question is whether assets like Cardano can reach the second tier or whether the viable ETF universe stops at four or five cryptocurrencies.
Should investors buy ADA ahead of a potential ETF approval?
Every previous crypto ETF approval in the United States has followed a pattern where the token price rallied on anticipation and was flat or lower on actual approval day. ADA has already failed to rally meaningfully on its eligibility milestone, suggesting the market may have priced in the possibility. Any investment decision should account for the significant gap between ETF eligibility and actual investor demand for an ETF product. This is educational analysis, not investment advice.
Crypto World
Ripple’s Sherlock audit found 96 bugs before they reached a single wallet
A $550,000 community audit contest uncovered two critical vulnerabilities in XRP Ledger features that could have drained user accounts without private keys. The findings reveal how Ripple’s audit-before-release model diverges sharply from the broader crypto industry’s patch-after-exploit norm.
Summary
- Sherlock’s two-week audit contest, which opened on April 13, 2026, uncovered 96 valid vulnerabilities across five proposed XRP Ledger amendments, including 2 critical and 6 high-severity bugs, before any of them reached mainnet.
- Ripple paid $309,000 in RLUSD bounties from a $550,000 prize pool, marking the first collaboration between Sherlock and Ripple and one of the largest audit contests of 2026.
- The most severe finding was a signature-validation flaw in the Batch amendment that would have allowed attackers to execute transactions from any account without holding its private keys, first identified on February 19, 2026, by researcher Pranamya Keshkamat and Cantina’s AI tool Apex.
- A separate critical bug in Permission Delegation allowed malicious actors to silently drain XRP balances through repeated fee charges on invalid delegated transactions, because the code checked permissions before verifying signatures.
- DeFi exploits exceeded $840 million across more than 50 incidents in the first five months of 2026 alone, a 70% year-over-year increase, and 70% of exploited contracts had been audited but lacked post-deployment monitoring.
XRP Ledger version 3.3.0 shipped on August 6, 2026, carrying five proposed amendments and a bundled cleanup patch. On paper it looked like a routine infrastructure release. Underneath, the update represented the conclusion of a six-month security gauntlet that caught two account-draining bugs, rewrote two entire feature implementations from scratch, and paid hundreds of thousands of dollars to outside researchers who found problems the internal team had missed. The process raises a pointed question for the wider blockchain industry: if Ripple can catch critical flaws before deployment, why does so much of crypto still treat security audits as a post-launch checkbox?
This piece breaks down what the two critical vulnerabilities actually were at a technical level, examines how the audit-vote-activate pipeline compares to competing chains’ security models, and assesses whether the findings strengthen or undermine the case for XRPL as institutional-grade infrastructure.
What the Sherlock contest actually found
The scope covered five pillars of upcoming XRPL functionality: Batch Transactions, Permission Delegation, Multi-Purpose Token (MPT) DEX integration, Confidential Transfers for MPTs, and Sponsored Fees and Reserves. Sherlock, a Web3 security firm that ranks researchers by performance and structures engagements as adversarial contests, opened the audit on April 13, 2026, with a $550,000 RLUSD prize pool. The contest page on Sherlock’s platform listed the engagement as “XRP Ledger – April 2026 Contest – 550,000 RLUSD,” signaling that Ripple paid the bounties in its own stablecoin.
Over two weeks, participants submitted reports that surfaced 96 valid findings: 2 critical, 6 high, 29 medium, and 59 low-severity issues. Ripple distributed $309,000 in RLUSD to contributors. The remaining pool covered Sherlock’s operational costs and lower-tier findings that did not meet the payout threshold.
The contest marked the first formal collaboration between Sherlock and Ripple, and it arrived at a moment when the XRP Ledger’s feature pipeline was expanding faster than at any point in its history. Five amendments shipping simultaneously meant five distinct attack surfaces, each with its own transaction logic, authorization model, and cryptographic requirements. For context, Sherlock’s audit contest model has previously been used by protocols including Aave, Euler, and Olympus DAO, but an engagement covering C++ protocol-level code for a layer-one blockchain was atypical for a platform more commonly associated with Solidity smart contracts.
The severity distribution itself tells a story. The 29 medium-severity findings suggest a category of bugs that would not individually compromise accounts but could create unexpected behavior under specific transaction sequences. The 59 low-severity issues likely include code quality concerns, documentation gaps, and edge cases that could compound under adversarial conditions. The two critical and six high-severity bugs, however, represented exploitable vulnerabilities that warranted immediate remediation.
The Batch amendment bug that could have emptied accounts
The most dangerous vulnerability predated the Sherlock contest by two months. On February 19, 2026, security researcher Pranamya Keshkamat and Cantina’s autonomous AI audit tool Apex independently identified a signature-validation flaw in the original Batch amendment while it was still in its validator voting phase.
The technical failure was precise. Batch Transactions allow up to eight operations to execute atomically under a single outer transaction. The outer transaction’s signature-validation code contained an early-exit condition that could be satisfied without properly verifying who was authorizing the inner transactions. In practice, an attacker could have constructed a Batch transaction containing inner Payment operations targeting a victim account, draining it down to its reserve balance, without ever holding that account’s private keys. The same logic gap would have permitted unauthorized AccountSet, TrustSet, or AccountDelete operations.
The vulnerability disclosure report published on xrpl.org detailed the mechanics: the signer check in the outer transaction could pass without confirming that the entity submitting the batch actually controlled the accounts referenced in the inner transactions. This meant that the atomicity feature designed to improve user experience could have been weaponized to empty any account on the network in a single transaction.
RippleX responded with an emergency release. Rippled version 3.1.1, published on February 23, 2026, four days after discovery, marked both the original Batch amendment and its companion fixBatchInnerSigs as unsupported, preventing validators from voting on or activating them. No funds were lost because the amendment had not yet cleared the 80% validator threshold required for activation. The replacement, BatchV1_1, shipped in version 3.3.0 with the early-exit condition removed, additional authorization guards added, and the signing check scope tightened to verify each inner transaction against the correct signer independently.
Permission Delegation’s silent fee-drain exploit
The second critical vulnerability operated through a subtler mechanism. A September 2025 disclosure documented how the original Permission Delegation implementation allowed an attacker to silently bleed a victim account’s XRP balance without accessing its keys.
The exploit relied on a design feature of the XRP Ledger’s transaction processing that has existed since the network’s earliest days. On XRPL, a transaction that fails with a “tec”-class error still incurs a fee charge, while errors caught earlier in the pipeline, before signature verification, do not. This distinction exists because tec-class failures indicate transactions that were properly formed and signed but failed for business-logic reasons, and the fee prevents spam. Permission Delegation’s original code checked whether a delegate account held the relevant permission before it verified the transaction’s signature. An attacker could repeatedly submit invalid offline-signed transactions with elevated fees against a delegated account, and each failed transaction would still deduct the fee from the victim’s balance.
The economic impact would have compounded quickly. Because the attacker could set arbitrarily high fees on these transactions, a sustained attack could drain an account far faster than normal transaction fees would suggest. The victim would see their balance declining with no corresponding outbound payments, making the attack difficult to diagnose without examining raw transaction metadata.
The fix reclassified the relevant error from tec to ter and reordered the checks so that no fee can be deducted before signature verification passes. The replacement amendment, PermissionDelegationV1_1, carries a default “No” designation in the 3.3.0 registry, meaning validators must actively vote to enable it. This conservative default reflects the sensitivity of the original flaw: even after the rewrite, Ripple chose to require explicit validator opt-in for the feature.
Why both rewrites shipped in a single release
Packaging two security-rewritten amendments alongside three entirely new features in one version was a deliberate choice. RippleX published xrpld 3.3.0 on August 6, 2026, with the code for all six proposals (including a bundled cleanup amendment called fixCleanup3_3_0) present but none of them activated. Under the XRP Ledger’s amendment process, each proposal must sustain more than 80% validator support for two consecutive weeks before going live.
This separation between code availability and feature activation is a structural advantage that most smart-contract platforms lack. On Ethereum, a deployed contract is live the moment it hits the blockchain. On XRPL, code can ship, undergo further review during the voting window, and still be blocked if validators lose confidence. The Batch and Permission Delegation rewrites had already survived the Sherlock contest, a Halborn re-audit that found zero critical or high-risk issues, and months of internal testing. The voting period adds yet another layer of defense before any code touches real funds.
The version also retired five legacy amendments, including Clawback, fixDisallowIncomingV1, fixInnerObjTemplate, fixNFTokenReserve, and fixUniversalNumber, removing dead code paths that could otherwise accumulate as latent attack surface over time.
The five feature amendments in 3.3.0 represent the broadest single expansion of XRPL capabilities to date. Confidential Transfers bring EC-ElGamal encryption and zero-knowledge proofs to Multi-Purpose Tokens, shielding individual balances and transfer amounts from public view while preserving compliance access for authorized parties. Sponsored Fees allow applications to cover network costs on behalf of users, addressing the onboarding friction that has kept consumer-facing applications off decentralized networks. DynamicMPT lets issuers modify token properties after creation, supporting evolving regulatory and business requirements. Together with the Batch and Permission Delegation rewrites, these features target a specific audience: regulated financial institutions that need privacy, atomic settlement, and delegated operations without sacrificing auditability.
Audit before release versus patch after exploit
The contrast between Ripple’s approach and the broader industry’s security track record is stark. DeFi exploits exceeded $840 million across more than 50 incidents in the first five months of 2026, a 70% year-over-year increase over the same period in 2025. North Korea-linked actors accounted for 76% of global crypto hack losses in the first four months of the year. And the most damning statistic: 70% of exploited contracts had been audited but lacked any form of post-deployment monitoring. Only 4% of tracked projects combined audits, active bug bounties, and third-party monitoring controls together.
The Ethereum ecosystem, home to the largest concentration of smart-contract value, operates under a fundamentally different security model. Contracts deploy to mainnet through an immutable transaction. If a vulnerability surfaces afterward, the options are limited: deploy a new contract and migrate users, implement a proxy upgrade pattern that introduces its own attack surface, or accept the risk. The Wormhole bridge hack of 2022 cost $320 million because a deprecated verification function remained in production code. Ronin’s August 2024 exploit cost $12 million because a contract upgrade failed to initialize operator weights correctly. In both cases, audits had been performed; the failures happened after deployment.
The KelpDAO hack on April 18, 2026, which drained approximately $293 million, was the largest single DeFi exploit of the year. The Drift Protocol exploit on Solana on April 1, which cost roughly $286 million, was the largest ever recorded on that chain. These figures are not fringe events. They represent the baseline failure rate of an industry that has collectively lost $16.69 billion to hacks, bridge exploits, and security incidents according to DeFiLlama data.
XRPL’s amendment voting process inverts this sequence. Code ships in a release, but features remain dormant until validators approve them. During the voting window, researchers, node operators, and competing auditors can examine the live codebase with full context. If a problem surfaces, validators simply withhold their votes. No emergency patch, no migration, no proxy contract. The February 2026 Batch bug followed exactly this path: the amendment was in its voting phase, the vulnerability was identified, and an emergency release prevented activation. Zero funds at risk, zero user impact.
This is not to say that the XRPL model is flawless. The amendment process works for protocol-level features but does not extend to applications built on top of the ledger. A poorly coded trust line or MPT integration could still lose funds. And the 80% validator threshold creates its own risks: if too few validators upgrade to a new version, legitimate security patches can stall. But for core protocol changes, the audit-vote-activate pipeline represents a materially different security posture than deploy-and-hope.
What this means for XRPL’s institutional pitch
Ripple has spent 2026 building an institutional infrastructure stack at an aggressive pace. The $1.25 billion acquisition of Hidden Road, a multi-asset prime broker rebranded as Ripple Prime, gave the company a regulated on-ramp for traditional finance. RLUSD reached a $1.72 billion market capitalization in under a year and moved more than $18 billion in transaction volume during Q1 alone. Goldman Sachs disclosed a $153.8 million position across four XRP ETFs. Ripple secured a full Electronic Money Institution license from Luxembourg in February, UK Financial Conduct Authority permissions in January, and a MiCA Crypto-Asset Service Provider license on July 6.
The institutional DeFi features arriving in version 3.3.0 are the technical counterpart to this business development push. Confidential Transfers address the privacy requirements of banks that cannot expose transaction details on a public ledger. Sponsored Fees solve the onboarding friction that has kept retail banking applications off decentralized networks. Permission Delegation, once its rewrite clears the voting process, enables the kind of controlled access models that compliance departments require.
But institutional adoption depends on trust, and trust in blockchain infrastructure ultimately comes down to security track record. The fact that Ripple caught two critical bugs, rewrote two entire feature implementations, paid outside researchers $309,000 to find problems, and still delivered all five features on schedule is a stronger institutional selling point than any individual feature. It suggests a security culture where finding bugs is rewarded and where shipping is subordinate to verification.
Over 300 financial institutions across 55 countries currently use RippleNet, with active On-Demand Liquidity corridors in more than 70 markets. For those institutions, the Sherlock audit results are not abstract. They are evidence that the code running their cross-border payments has been stress-tested by adversarial researchers with financial incentives to break it. Ripple’s four-phase quantum-resistance roadmap, targeting completion by 2028, further signals that the company is engineering for institutional time horizons measured in decades, not deployment cycles.
The opposing case: why skeptics are not convinced
The strongest argument against reading too much into the Sherlock audit runs in two directions.
First, finding 96 bugs before release can be framed as evidence of thorough testing or evidence of sloppy development. Both the Batch and Permission Delegation vulnerabilities were in the original implementations, meaning they cleared internal review before external researchers caught them. The February 2026 Batch bug was not identified by Ripple’s own team but by an independent researcher and an AI tool. If external auditors are the primary safety net, the internal development process may have quality gaps that will eventually produce a vulnerability that no external reviewer catches in time.
Second, the XRPL amendment model’s strength, the ability to prevent activation during the voting window, is also a speed constraint. Ethereum’s willingness to deploy and iterate has enabled a pace of innovation that XRPL cannot match. The five amendments in version 3.3.0 have been in development and review cycles for months. The original Batch amendment was proposed in 2025. For protocols competing for developer attention in fast-moving markets, a six-month security pipeline may be too slow to attract the builder ecosystem that drives network effects.
There is also a concentration risk in the validator set. The 80% activation threshold means that a relatively small number of validators, many of which are operated by entities with close ties to Ripple, control whether amendments go live. Critics argue this is not truly decentralized governance but a curated approval process dressed in consensus language. When Ripple’s own validator voted “yes” on lending amendments in recent weeks, it underscored how much influence the company retains over its nominally decentralized network.
Finally, the $309,000 payout from a $550,000 pool raises a practical question about incentive alignment. Top-tier security researchers command rates that exceed what contest models typically pay per hour of effort. If the most skilled auditors skip XRPL contests because the expected payout per finding is lower than private engagements, the adversarial review may be broad but not deep enough to catch the most sophisticated attack vectors.
These objections have weight. XRP traded near $1.03 in late July 2026, roughly 71% below its $3.65 cycle high set on July 17, 2025, suggesting the market has not yet priced in the institutional narrative. Whether the security track record translates into adoption depends on factors beyond code quality: regulatory clarity, competitive positioning against Ethereum layer-2 solutions, and whether institutions care more about pre-deployment audits than they do about ecosystem size.
What to watch
Validator voting thresholds for the five 3.3.0 amendments: if BatchV1_1 and PermissionDelegationV1_1 clear 80% support within the first voting cycle, it signals validator confidence in the rewrites. A stall would suggest lingering concerns about the rewritten code.
Post-activation bug reports: the real test of the Sherlock audit’s thoroughness comes after features go live. Zero critical findings in the first 90 days would validate the pre-release model; any post-activation vulnerability would undermine the entire thesis.
RLUSD adoption on Confidential Transfers: institutional stablecoin usage on shielded rails would confirm demand for privacy-compliant settlement. Volume metrics in the first quarter after activation will be the clearest signal of whether banks are ready to transact on a public ledger with privacy guarantees.
Sherlock’s next XRPL engagement: whether Ripple continues with adversarial audit contests for future amendments or reverts to traditional private audits will indicate how deeply the pre-release model is embedded in the development culture.
Competing chain security incidents: every major exploit on Ethereum or Solana that traces back to a post-deployment vulnerability strengthens the case for XRPL’s audit-vote-activate pipeline. The comparison is only as strong as the industry’s continued failure to adopt similar processes.
What did the Sherlock audit of XRP Ledger find?
The two-week audit contest, which opened on April 13, 2026, uncovered 96 valid vulnerabilities across five proposed XRPL amendments: 2 critical, 6 high, 29 medium, and 59 low-severity issues. Ripple paid $309,000 in RLUSD bounties from a $550,000 prize pool. All findings were addressed before any of the affected features activated on mainnet.
What was the critical Batch amendment bug?
The original Batch amendment contained a signature-validation flaw that allowed an attacker to execute inner transactions from any account without holding its private keys. The bug was an early-exit condition in the outer transaction’s signing check that could be satisfied without proper authorization verification. Researcher Pranamya Keshkamat and Cantina’s AI tool Apex identified it on February 19, 2026. RippleX patched it in emergency release version 3.1.1 four days later.
How did the Permission Delegation vulnerability work?
The original implementation checked delegate permissions before verifying transaction signatures. On XRPL, transactions that fail with “tec”-class errors still incur fees. An attacker could repeatedly submit invalid transactions with elevated fees against a delegated account, draining its XRP balance without ever holding its keys. The fix reclassified the error type and reordered the verification checks.
Were any funds lost from these vulnerabilities?
No funds were lost. Both critical vulnerabilities were identified before their respective amendments activated on mainnet. The Batch bug was caught during the validator voting phase, and the Permission Delegation flaw was disclosed and patched before activation. The XRP Ledger’s amendment process, which requires 80% validator support for two consecutive weeks, provided a structural buffer that prevented exploitation.
What is Sherlock and how does its audit model work?
Sherlock is a Web3 security firm that structures audits as adversarial contests, ranking researchers by performance and offering financial incentives through prize pools. The XRP Ledger engagement was Sherlock’s first collaboration with Ripple and one of the largest audit contests of 2026. The model differs from traditional private audits by inviting broad participation from independent security researchers competing for bounties, which surfaces a wider range of attack vectors than a small internal team can cover.
How does XRPL’s security model differ from Ethereum’s?
XRPL’s amendment process separates code deployment from feature activation. New features ship in a software release but remain dormant until validators vote to activate them, creating a review window where vulnerabilities can be caught without emergency patches. Ethereum’s smart contracts are live upon deployment, and fixing vulnerabilities requires deploying new contracts, migrating users, or implementing proxy upgrades. In the first five months of 2026, DeFi exploits exceeded $840 million, and 70% of exploited contracts had been audited but lacked post-deployment monitoring.
What features does XRP Ledger version 3.3.0 include?
Version 3.3.0, released on August 6, 2026, contains code for five feature amendments and a cleanup patch. The features include Confidential Transfers for Multi-Purpose Tokens using zero-knowledge proofs, rewritten Batch Transactions for atomic multi-operation settlement, rewritten Permission Delegation for controlled account access, Sponsored Fees allowing applications to cover user costs, and DynamicMPT enabling issuers to modify token properties after creation.
Does this audit make XRPL a safe investment?
The Sherlock audit reflects a rigorous pre-release security process, but code quality is one factor among many that influence investment outcomes. XRP traded near $1.03 in late July 2026, roughly 71% below its cycle high, and market performance depends on regulatory developments, institutional adoption rates, competitive dynamics, and macroeconomic conditions. This is educational analysis, not investment advice. **Disclaimer**: This article was published on August 14, 2026. It is intended for educational and informational purposes only and should not be construed as financial, investment, or legal advice. Cryptocurrency markets are volatile and carry substantial risk. Readers should conduct their own research and consult qualified professionals before making any investment decisions.
Crypto World
Trump’s World Liberty Financial delayed its Maldives resort token because of a war
The Iran conflict grounded flights, cratered Maldives tourism arrivals by double digits, and forced the Trump family’s crypto venture to shelve what was billed as the world’s first tokenized luxury hotel development. The episode exposes a structural question the real-world asset market has avoided: what happens to a token when the real world breaks?
Summary
- World Liberty Financial and its partners postponed the MALD1 token sale, originally planned for spring 2026, after the Iran conflict disrupted air corridors serving the Maldives and cut tourist arrivals by as much as 41% in early March.
- The token, structured through BlackRock-backed Securitize, would have given accredited investors a fixed yield plus a share of loan revenue from Trump International Hotel and Resort, Maldives, a 100-villa project developed by UK-listed Dar Global with a 2030 completion target.
- WLFI has raised $550 million through governance token sales from more than 85,000 buyers, but the token has lost roughly 83% of its value from its September 2025 peak of $0.331, falling to approximately $0.055 by late July 2026.
- The broader tokenized real-world asset market excluding stablecoins has grown to between $26 billion and $34 billion in 2026, yet tokenized real estate remains the segment with the slowest institutional adoption and the thinnest secondary trading.
- Dar Global CEO Ziad El Chaar said the company “continues to review development and launch schedules for its global projects in line with market conditions, regulatory requirements and long-term strategic goals,” without setting a new date.
On February 19, 2026, World Liberty Financial announced one of the most ambitious experiments in real-world asset tokenization: a partnership with BlackRock-backed Securitize and London-listed developer Dar Global to tokenize loan revenue from a Trump-branded luxury resort in the Maldives. Six months later, no token has been sold, no new launch date has been set, and the project sits in indefinite limbo. The reason is not a smart-contract exploit or a regulatory crackdown. It is a war. This piece examines what the delay reveals about the fragility of tying digital tokens to physical assets in unstable regions, the broader track record of the venture behind the deal, and whether the growing RWA market has priced in the risks that the real world routinely delivers.
The deal that was supposed to make history
The Maldives token project was conceived as a first-of-its-kind offering. Unlike previous tokenization efforts that wrapped completed properties in digital securities, WLFI and its partners proposed tokenizing the development phase itself. The token, designated MALD1 on the Securitize platform, would represent interests in loan servicing revenue tied to construction financing for Trump International Hotel and Resort, Maldives.
Dar Global, a subsidiary of Saudi Arabia’s Dar Al Arkan Real Estate Development Company and listed on the London Stock Exchange, is building the resort on a private island roughly 25 minutes by speedboat from Male. Plans call for approximately 100 ultra-luxury beach and overwater villas designed to offer what Dar Global described as “the highest levels of privacy, exclusivity, and sophistication.” Completion is targeted for 2030. The Trump Organization is licensing its brand and hospitality management standards, marking the brand’s first property in the Maldives.
WLFI and Securitize handle the tokenization layer, issuing securities under Rule 506(c) of Regulation D for accredited U.S. investors and Regulation S for non-U.S. persons in offshore transactions. Securitize, which has handled tokenized fund issuances for BlackRock, Hamilton Lane, and Apollo Global, serves as the registered transfer agent and compliance engine for the offering.
Holders of MALD1 tokens would receive a fixed yield, a share of ongoing loan proceeds, and a cut upon any eventual sale of the underlying loan positions. The structure was carefully designed to offer economic exposure without conferring direct property ownership, sidestepping the legal complexities of cross-border real estate title transfer that have stalled earlier tokenization projects in multiple jurisdictions.
When the partnership was announced, Zachary Folkman, a WLFI co-founder, called it “a new model for how real-world value meets blockchain transparency.” The plan was to open sales to qualified investors by spring 2026. Spring came and went.
How a war grounded the token sale
The conflict between the United States, Israel, and Iran that escalated in early 2026 sent shockwaves far beyond the Middle East. Brent crude prices surged from around $70 to over $110 per barrel in March before settling into the $95 to $100 range, and global capital flows into risk assets slowed sharply. For the Maldives, the most immediate effect was the closure of key air corridors over the Gulf region. Airlines that route through the Persian Gulf, including major carriers from the Middle East and South Asia, suspended or rerouted flights, severing connectivity to the Indian Ocean archipelago that depends on air travel for virtually all of its tourist arrivals.
The numbers were stark. Tourist arrivals to the Maldives fell 23.4% in the first week of March 2026 compared with the same period in 2025, according to official data from the Maldives Ministry of Tourism. Average daily arrivals in early March dropped 41.5% compared with February averages. The Maldivian government projected a revenue shortfall of $80 million to $100 million if disruptions persisted for a single month, a serious figure for an economy where tourism accounts for more than 60% of foreign exchange receipts. Even as some viral claims of a 90% tourism collapse proved overstated, the real decline was severe enough to force the government to introduce new visa categories in an effort to attract visitors from unaffected regions.
For a token backed by loan revenue from a resort that does not yet exist, the implications were severe. Construction timelines depend on the movement of materials, labor, and capital through a region that was suddenly difficult to reach. Projected occupancy rates and revenue models, the very inputs that determine the value of MALD1’s yield, became unreliable. Selling a fixed-income token to accredited investors requires credible financial projections, and credible projections require a stable operating environment. No responsible issuer would price a yield curve against a tourism market in freefall.
Bloomberg reported on August 13 that the token sale had been indefinitely postponed, with sources attributing the delay directly to war-driven travel disruptions. Dar Global’s CEO, Ziad El Chaar, offered a carefully worded statement about reviewing schedules but provided no timeline for resumption. The absence of a target date is itself a signal: the company does not know when conditions will allow a credible offering.
WLFI’s track record under scrutiny
The Maldives delay does not exist in isolation. It arrives at a moment when World Liberty Financial’s broader trajectory has drawn increasing skepticism from investors, regulators, and industry analysts.
WLFI launched its governance token sale in October 2024, initially targeting $300 million by selling 20 billion tokens at $0.015 each. Early demand was anemic: only $11 million trickled in during the first phase, and the team slashed its target to $30 million. Then momentum shifted, driven in part by the political attention surrounding the Trump family’s involvement. A second tranche of 5 billion tokens at $0.05 each brought the total raise to $550 million from more than 85,000 participants.
The Trump family’s financial interest in the project is substantial. According to public disclosures, the family receives 75% of net proceeds from WLFI token sales. Trump himself is listed as “co-founder emeritus,” and his 2025 income from the venture was reported at roughly $800 million, making World Liberty Financial one of the most lucrative crypto ventures in history by founder returns.
But the token’s secondary market performance has been punishing. WLFI peaked at approximately $0.331 in September 2025 and then entered a sustained decline, falling to around $0.055 by late July 2026, a drop of roughly 83%. Public estimates indicate that WLFI holders have absorbed $674 million in combined realized and unrealized losses. In April 2026, Forbes reported that WLFI had borrowed $75 million on its own platform, prompting one analyst to warn investors not to become “exit liquidity.”
Governance disputes have compounded the price decline. In April 2026, Tron founder Justin Sun, one of WLFI’s largest individual investors with approximately $75 million in purchases, filed a federal lawsuit alleging that WLFI froze 540 million of his unlocked tokens and 2.4 billion locked tokens and excluded him from governance activities. Sun claimed the contract contained an undisclosed blacklist function that was never disclosed to investors. WLFI countersued in May, accusing Sun of defamation and alleging that he engaged in short selling to suppress the token price and made straw purchases on behalf of undisclosed third parties. The litigation remains unresolved, and the WLFI token fell 15% to a record low after Sun publicly accused the project of embedding a backdoor.
On the product side, WLFI’s USD1 stablecoin has been a notable success by supply metrics, reaching $5.3 billion in circulation by mid-2026. It became a settlement asset on Binance’s perpetual futures markets and was selected as the payment vehicle for Abu Dhabi investment firm MGX’s multibillion-dollar Binance stake. However, concentration risk is pronounced: Binance holds approximately 87% of all USD1 in circulation, raising questions about the stablecoin’s decentralization claims and its vulnerability to a single exchange relationship.
When tokenized assets meet physical reality
The Maldives delay crystallizes a category of risk that the RWA tokenization industry has largely discussed in theory but never confronted in practice. Tokenized U.S. Treasuries or money-market funds, the segments that dominate the current $26 billion to $34 billion RWA market, are backed by assets that exist as electronic entries in regulated custodial systems. They do not depend on weather, geography, or geopolitics. Their yields are predictable because the U.S. government’s capacity to service its debt is, for practical purposes, not affected by whether flights are operating over the Persian Gulf.
Tokenized real estate is fundamentally different. The underlying asset is immovable, jurisdiction-specific, and vulnerable to physical disruption. A resort in the Maldives faces cyclone risk, sea-level rise, political instability in the host country, and, as the current episode proves, conflict in adjacent regions that can sever the transportation links on which the entire business model depends.
The MALD1 token adds additional layers of abstraction. Investors do not own a share of the resort. They own a token representing a share of servicing income from loans used to finance the resort’s construction. If construction delays push the completion date past 2030, if occupancy projections prove optimistic in a region shaken by conflict, or if Dar Global encounters financial difficulties, the yield that makes MALD1 attractive could shrink or vanish entirely. The investor is three steps removed from the physical asset: token to loan servicing rights to loan to resort to tourist spending. Each link in that chain introduces its own failure mode.
This is not a hypothetical concern. The history of tokenized real estate is littered with projects that promised liquidity and delivered illiquidity. Industry analyses of the first wave of tokenization projects, roughly 2019 through 2023, identified three recurring failure modes: legal non-recognition of tokenized title, tiny investor pools restricted to accredited buyers with five-figure minimums, and the absence of market-making infrastructure to support secondary trading. Less than 10% of tokenized real estate projects from that era showed meaningful secondary market volume. Projects that prioritized speed over structural integrity during 2025 faced enforcement actions, platform shutdowns, and investor litigation, particularly when tokens moved to unverified wallets and triggered anti-money laundering investigations.
The MALD1 structure addresses some of these issues. Securitize is a regulated transfer agent with deep experience in compliance infrastructure. The loan-revenue model avoids the title-transfer problem. But no amount of structural engineering can hedge against a war that closes airspace and craters the tourism market on which the underlying asset depends.
The case for WLFI and tokenized hospitality
A fair analysis requires stating the opposing case at full strength. Proponents of the Maldives project, and of RWA tokenization more broadly, would argue that the delay is precisely what a responsible issuer should do. Launching a token sale into a disrupted market would expose investors to mispriced risk and potentially trigger regulatory scrutiny. By waiting, WLFI and Securitize are protecting investors, not failing them.
There is also a structural argument. Deloitte projects that tokenized real estate will reach $4 trillion in value by 2035, implying a 27% compound annual growth rate. If that projection holds, first movers in luxury hospitality tokenization will have secured a durable competitive advantage. The Maldives project, precisely because it tokenizes the development phase, offers investors exposure to the highest-growth period of a real estate asset’s lifecycle, when value appreciation is steepest.
The broader WLFI ecosystem, despite its token price decline, has delivered real products. USD1 is one of the largest stablecoins in circulation. The subsidiary WLTC Holdings applied in January 2026 for an OCC national trust bank charter covering stablecoin issuance, redemption, and custody. If approved, it would give WLFI a regulated banking entity, a significant competitive moat that few crypto-native ventures can match.
Regional peers offer precedent for optimism. The Dubai Land Department launched a controlled tokenization pilot in February 2026 that explicitly tests governance, investor protection, and operational readiness for secondary market resale. Saudi Arabia’s Open World launched the country’s first licensed RWA Tokenization Center of Excellence in Al Khobar in January 2026, targeting energy, real estate, and carbon credits. The institutional infrastructure is being built, even if the Maldives project is temporarily sidelined.
What would invalidate the bearish thesis? If the Iran conflict resolves or de-escalates enough to restore Maldives air connectivity, if Dar Global delivers construction milestones on schedule, if the MALD1 token launches with strong investor demand and develops meaningful secondary trading, and if WLFI’s governance disputes with Justin Sun reach a resolution that restores market confidence, then the delay will look like prudent risk management rather than a structural flaw. Each of these conditions is plausible. Whether they are probable is a different question.
The SEC’s parallel pause
The MALD1 delay coincides with a related regulatory development that compounds uncertainty for the entire tokenization sector. On August 13, the same day Bloomberg reported the Maldives postponement, CoinDesk reported that the U.S. Securities and Exchange Commission would again delay its proposed “innovation exemption” for tokenized securities.
The exemption, first floated in late 2025, would have created a streamlined regulatory pathway for tokenized real-world assets, potentially reducing compliance costs and accelerating time-to-market for offerings like MALD1. Its repeated delays reflect unresolved tensions between the White House, which has publicly supported crypto innovation, and SEC staff, who have raised concerns about investor protection in tokenized offerings that blur the line between securities and commodities.
For WLFI, the regulatory uncertainty is particularly acute. The project exists at the intersection of presidential politics, family financial interests, and securities law. Any tokenized offering associated with the sitting president’s family will receive heightened scrutiny from regulators, regardless of the formal recusal arrangements in place. The SEC’s reluctance to finalize the innovation exemption suggests that the regulatory environment for complex tokenized offerings remains unsettled, adding another variable to the MALD1 relaunch calculus.
The tangibility paradox
Most coverage of the WLFI Maldives delay focuses on either the political angle (another Trump crypto controversy) or the market angle (RWA tokenization faces headwinds). Both framings miss the deeper structural lesson that no competitor has articulated clearly.
The Maldives token exposes a paradox at the heart of real-world asset tokenization. The entire value proposition of RWA tokens is that they connect blockchain efficiency to tangible, physical value. But the more tangible the asset, the more exposed the token becomes to forces that no smart contract can mitigate. A tokenized Treasury bill is safe precisely because it is abstract, an electronic claim on the full faith and credit of the U.S. government. A tokenized resort in the Indian Ocean is vulnerable precisely because it is real, a collection of villas on a low-lying island in a geopolitically sensitive region, reachable only by air routes that can be shut down by events thousands of kilometers away.
This paradox does not mean real estate tokenization is unworkable. It means the market needs to develop pricing models that account for geopolitical risk, supply-chain disruption, climate vulnerability, and the correlation between these factors and the revenue streams that back tokenized securities. Current models, borrowed largely from traditional real estate finance, do not adequately capture these compounding risks because traditional real estate finance does not typically involve selling fractional interests in development-phase loans on assets in conflict-adjacent zones to a global investor base via blockchain rails.
The WLFI Maldives case may ultimately become a case study in how the industry matures. If it prompts issuers, platforms, and regulators to build better risk frameworks for location-dependent tokenized assets, the delay will have served a purpose beyond its immediate commercial impact. If it is treated as an isolated incident and the market moves on without structural adjustment, the next disruption will deliver the same lesson at higher cost.
What to watch
– **Maldives air traffic recovery**: Monthly tourist arrival data from the Maldives Ministry of Tourism will signal whether the travel disruption that prompted the delay is easing or persisting.
– **MALD1 relaunch timeline**: Any announcement from WLFI, Securitize, or Dar Global about a new launch date or revised offering terms will indicate whether the project remains commercially viable.
– **SEC innovation exemption status**: The next scheduled review of the tokenization exemption, expected in Q4 2026, will determine the regulatory runway for offerings like MALD1.
– **WLFI governance litigation resolution**: The outcome of the Sun v. WLFI and WLFI v. Sun lawsuits will shape investor confidence in the project’s governance structure and management credibility.
– **Dar Global construction milestones**: Quarterly updates from Dar Global on the physical progress of Trump International Hotel and Resort, Maldives, will test whether the 2030 completion target remains achievable.
What is the MALD1 token?
MALD1 is a tokenized security issued through Securitize that represents a share of loan servicing revenue tied to the construction financing of Trump International Hotel and Resort, Maldives. It offers a fixed yield plus a share of ongoing loan proceeds, and it is available only to accredited investors under U.S. Regulation D and Regulation S exemptions.
Why was the Maldives token sale delayed?
The token sale, originally planned for spring 2026, was postponed because the Iran conflict disrupted air corridors serving the Maldives, causing tourist arrivals to drop by as much as 41% in early March. The disruption undermined the revenue projections that underpin the token’s value proposition, and no responsible issuer would launch into those conditions.
How much has WLFI raised from token sales?
World Liberty Financial raised approximately $550 million through its governance token sale, which concluded in early 2025 with more than 85,000 participants. The initial tranche sold 20 billion tokens at $0.015 each, and a second tranche sold 5 billion tokens at $0.05 each. The Trump family receives 75% of net proceeds from these sales.
What is USD1 and how large is it?
USD1 is a stablecoin issued by World Liberty Financial, pegged 1:1 to the U.S. dollar and backed by short-term Treasuries and cash equivalents. It reached a circulating supply of approximately $5.3 billion by mid-2026, making it one of the largest stablecoins in circulation, though Binance holds roughly 87% of total supply.
What are the main challenges facing tokenized real estate?
Tokenized real estate faces liquidity risk from thin secondary markets, legal risk from jurisdictions that do not recognize tokenized title, geopolitical risk when assets are located in unstable or conflict-adjacent regions, and structural risk when tokens represent indirect claims such as loan revenue rather than direct ownership. Less than 10% of first-wave tokenized real estate projects showed meaningful secondary trading volume.
Who is building the Maldives resort?
Dar Global, a London-listed subsidiary of Saudi Arabia’s Dar Al Arkan Real Estate Development Company, is the developer. The Trump Organization is licensing its brand and hospitality management standards. The resort is planned to feature approximately 100 ultra-luxury beach and overwater villas on a private island near Male, with completion targeted for 2030.
What happened in the Justin Sun lawsuit against WLFI?
In April 2026, Tron founder Justin Sun sued WLFI in federal court, alleging that the project froze approximately 540 million of his unlocked tokens and 2.4 billion locked tokens and excluded him from governance without disclosure. WLFI countersued in May, accusing Sun of defamation and market manipulation through short selling. Both cases remain pending.
Is the MALD1 token a good investment?
The MALD1 token has not yet been sold, so there is no market price or performance data to evaluate. Any future offering will carry significant risks, including construction delays, geopolitical disruption, regulatory uncertainty, and the governance challenges that have affected WLFI’s broader token ecosystem. Prospective investors should review the private placement memorandum and consult qualified financial and legal advisors before committing capital. This is educational analysis, not investment advice. *Disclaimer: This article was published on August 14, 2026. It is intended for educational and informational purposes only and does not constitute financial, investment, or legal advice. The author and publisher do not hold positions in any tokens or securities mentioned. Readers should conduct their own research and consult qualified professionals before making investment decisions.*
Crypto World
Bitcoin Red Team flags 7,958 issues after Kimi K3 scan
Bitcoin Red Team has expanded its AI-assisted security review to 501 Bitcoin-related open-source projects, logging 7,958 findings in its latest detailed tally after 108 hours of work.
Summary
- Bitcoin Red Team scanned 501 projects and logged 7,958 findings after 108 hours of reviews.
- Researchers classified 1,280 findings as high or critical, but many still require human verification today.
- About 24.7% of findings had reproducible proofs, while 29.4% were reported upstream to project maintainers.
- Kimi K3 became the campaign’s primary AI workhorse as researchers tested Bitcoin open-source software extensively.
- BTCPay Server released fixes after Bitcoin Red Team and independent researchers reported security vulnerabilities recently.
Calle, a pseudonymous Bitcoin developer involved in the effort, said on Aug. 13 that the team has now completed a basic scan of almost the entire Bitcoin open-source ecosystem and that much of the easier-to-find vulnerability surface has already been examined.
The headline numbers require an important distinction. The 7,958 findings do not represent 7,958 confirmed exploitable vulnerabilities. The team classified 1,280 as high or critical, while 24.7% of all findings had been dynamically reproduced and 29.4% had been reported upstream at the 108-hour mark. Maintainer review and human reproduction remain part of the verification process.
Kimi K3 has become a security force multiplier
Calle said two weeks of work with Moonshot AI’s Kimi K3 exposed how quickly modern models can examine years of accumulated open-source code. He described the situation as a “massive collision” between older software and frontier AI, adding “everything is broken, bitcoin is burning.” The wording is his characterization and should not be read as evidence that Bitcoin Core or every Bitcoin project is compromised.
Independent testing supports the narrower point that Kimi K3 has meaningful cybersecurity capability. A joint U.K. AI Security Institute and U.S. CAISI assessment found the model outperformed GLM-5.2 on exploit-development testing but remained behind the strongest U.S. closed models. Kimi K3 scored 32% on ExploitBench and reached arbitrary code execution on zero of 41 samples in that test.
Bitcoin Red Team’s earlier sweep found 4,962 potential issues across 390 Bitcoin projects, including 720 then classified as high or critical. The newer tally shows the review expanded materially after that first wave.
Maintainers are already validating and patching findings
The campaign has moved beyond automated scanning. BTCPay Server’s official GitHub release credited Bitcoin Red Team researchers Bruno Garcia and Ben Carman with reporting a critical vulnerability that was already being exploited. Version 2.4.2 fixed a two-factor authentication bypass affecting Greenfield Basic Authentication.
BTCPay later confirmed that attackers had obtained LND admin macaroon credentials from affected installations and used them to access connected Lightning wallets. The project said it was processing additional reports from Bitcoin Red Team, Project Loupe, Magic Grants and independent researchers while strengthening its scanning and review processes.
On Aug. 14, BTCPay announced another security-focused release candidate, v2.4.3-rc4, addressing vulnerabilities reported by those groups. In related coverage, BTCPay supporters backed a recovery bounty after the earlier exploit and the foundation pledged 0.21 BTC to the Bitcoin Red Team fund.
Those fixes give concrete evidence that maintainers are validating at least some serious Red Team reports. They do not validate every item in the 7,958-finding dataset. AI-assisted audits can produce false positives, duplicate reports and severity assessments that change after manual investigation, making verification central to interpreting the numbers.
Bitcoin projects face a faster security cycle
Calle argued that unmaintained projects should now be treated with greater caution because AI has sharply lowered the cost of finding and testing weaknesses. He also said response time is becoming a useful indicator of project health and that maintainers will increasingly need their own continuing AI audit pipelines rather than occasional external reviews. Those are Calle’s conclusions from the campaign rather than universal security rules.
The wider ecosystem is already moving in that direction. OpenSats has created a fast-tracked red-teaming grant route focused partly on reimbursing researchers for LLM costs. More than 40 Bitcoin and digital-asset organizations have also asked leading AI laboratories to give vetted open-source defenders controlled access to frontier models.
As crypto.news reported, the industry coalition warned Bitcoin developers could fall behind attackers without access to advanced AI models. The request does not seek unrestricted access. It proposes vetted researchers, secure environments, sufficient compute and direct communication channels with AI security teams.
The next phase is likely to move more slowly than the initial sweep. Automated discovery can scale quickly, while reproduction, responsible disclosure, patch development and regression testing require more time. Projects receiving reports must determine which findings are exploitable, how urgently users need updates and when technical details can safely become public.
For Bitcoin users, the takeaway is narrower than the largest numbers suggest. The Red Team has reported a large volume of potential weaknesses across Bitcoin-related software, not evidence that Bitcoin’s base consensus protocol has failed. The immediate security concern centers on wallets, Lightning infrastructure, payment software and libraries carrying older or lightly reviewed code.
Crypto World
Ethereum study flags 65,340 risky addresses tied to $574.8M
A USENIX Security ’26 study has identified 65,340 high-risk address instances across Ethereum and BNB Smart Chain, linking them to 126,982.94 ETH and 17,726.7 BNB in native-token losses.
Summary
- Researchers identified 65,340 high-risk address instances across Ethereum and BNB Chain in their large-scale study.
- Estimated losses reached 126,982.94 ETH and 17,726.7 BNB, valued by researchers above $574.8 million overall.
- Researchers extracted 16.3 million private keys from 63,004 GitHub repositories for their cross-chain analysis dataset.
- Their detection framework achieved 99.11% precision after manual sampling validation across both analyzed blockchain networks.
- Two newly described attack vectors exploited deterministic contract addresses and EIP-7702 delegated account control mechanisms.
The paper, presented at the 35th USENIX Security Symposium in Baltimore, estimates their dollar value at more than $574.8 million.
The dollar figure needs context. The researchers say they valued the token losses using reference prices of $4,408 per ETH and $847 per BNB rather than prices at the time of every transaction. They describe their findings as a “conservative lower bound” because the analysis covers only native ETH and BNB on the two networks and may miss less obvious cases.
Ethereum address misuse spans contract and private-key risks
The researchers divide “Address Misuse” into two categories. Contract Account misuse happens when users treat an address without deployed contract code as a contract address, often because the same address is used in another network context. The study identified 49,344 such instances, associated with losses of 22,738.41 ETH and 8,681.41 BNB.
Externally Owned Account misuse involves addresses whose private keys are exposed or show strong onchain signs of compromised control. Researchers identified 15,996 EOA misuse instances associated with 104,244.53 ETH and 9,045.29 BNB in losses. More than 95% of EOA misuse losses came from the GitHub exposed-key subtype.
Two new attack paths account for about $15.7M
The first newly described attack takes advantage of deterministic contract-address creation. Attackers can promote a contract address on a testnet, wait for users to mistakenly send mainnet funds to the matching no-code address, and later deploy withdrawal code at the same location. Researchers linked 469 malicious contracts to 3,446.37 ETH and 431.79 BNB in losses.
The second uses EIP-7702 against accounts with already exposed private keys. Attackers delegate those EOAs to malicious code that automatically sweeps incoming funds. The paper found 17,270 cases, producing losses of 25.86 ETH and 33.45 BNB. Using the paper’s reference prices, the two newly described vectors together account for roughly $15.7 million.
The 99.11% figure is precision, not universal verification
The team mined 63,004 GitHub repositories created between January 2015 and May 2025, extracting 10.3 million unique candidate addresses and 16.3 million private keys after deduplication. It also used Ethereum Stack Exchange and Stack Overflow data before analyzing transactions on Ethereum and BNB Smart Chain.
Researchers manually sampled results and reported 99.11% overall detection precision. That does not mean every one of the 65,340 instances was individually manually verified. The authors acknowledge possible heuristic false positives and incomplete data, while ERC-20, NFT and other chains are excluded from the headline loss calculation.
EIP-7702 security concerns are widening
Ethereum’s official guidance warns that malicious EIP-7702 delegation can give hostile contract code control over assets. A separate USENIX Security ’26 study found more than 63% of analyzed EIP-7702 authorization transactions were associated with malicious EOA-targeted attacks, identifying 924 malicious contract accounts across seven supported chains.
As previously reported, EIP-7702 delegations were linked to automated wallet-draining activity after Ethereum’s Pectra upgrade. In related coverage, attackers later drained about $3.1 million from Polymarket users through phishing and malicious delegated execution.
The authors recommend wallet warnings for known exposed keys and cross-chain contract mismatches, stronger secret management for developers and clearer address-to-network documentation. They also propose considering chain identifiers in future contract-address derivation. Those are research recommendations, not adopted Ethereum or BNB Chain protocol changes.
The researchers plan to expand future work to additional chains and token types. Until then, the 126,982.94 ETH and 17,726.7 BNB totals are best read as measured native-token losses within the study’s defined scope, while $574.8 million remains a standardized valuation estimate.
Crypto World
CFTC sets Aug. 20 crypto talks as CLARITY vote waits
The Commodity Futures Trading Commission will use its inaugural Innovation Advisory Committee meeting on Aug. 20 to examine crypto regulation, artificial intelligence and prediction markets as Congress delays action on a broader digital asset market structure bill.
Summary
- CFTC advisers will discuss crypto regulation on August 20 as Congress delays market structure legislation.
- The agenda includes using existing statutory authority while complementing future congressional legislation on digital assets.
- Senate cloture on the CLARITY Act’s motion to proceed is scheduled to ripen September 15.
- SEC canceled its August 14 crypto offering meeting and has not announced a replacement date.
- Michael Selig currently serves as the CFTC’s sole commissioner despite the agency’s statutory five-seat structure.
The three-hour meeting begins at 1 p.m. ET in Washington and will be streamed publicly, according to the CFTC release.
The timing gives the meeting a sharper policy role than a routine technology discussion. The CFTC agenda explicitly lists “opportunities to modernize existing rules using current statutory authority” and areas where regulatory action can “complement future congressional legislation.” However, the IAC is advisory. It will not vote on a crypto rule, and its recommendations do not automatically represent the Commission’s position.
CFTC crypto talks focus on what regulators can do now
The first 50-minute session, titled “Crypto’s Regulatory Evolution: From Uncertainty to Clarity,” will cover the lack of a comprehensive federal market structure framework, overlapping jurisdictions and recent regulatory efforts. It also lists cybersecurity, operational resilience and crypto infrastructure as areas needed for trusted markets.
That wording stops short of saying the CFTC will create the CLARITY Act through regulation. The agency can interpret and modernize rules within its existing authority, but Congress would be needed to change statutory jurisdiction more broadly. Earlier this year, the CFTC and SEC jointly issued an interpretation on how federal securities laws apply to crypto assets, showing how the agencies can provide guidance without waiting for a new statute.
As previously reported, the CFTC’s first Innovation Advisory Committee meeting will cover crypto, AI and prediction markets, but no proposed crypto rule is scheduled for a vote at the session.
CLARITY Act now faces a September 15 Senate test
The Digital Asset Market Clarity Act has not failed. Majority Leader John Thune filed cloture on the motion to proceed before the Senate left Washington. The Senate schedule says that motion will ripen at 2:15 p.m. on Sept. 15, one day after senators return for regular business.
As previously reported, the CLARITY Act faces a September 15 procedural vote and still needs enough support to clear the Senate’s 60-vote cloture threshold. Even successful cloture would only move the chamber toward considering the bill. Debate, amendments and a final vote would still follow, while any Senate text differing from the House version would require further congressional action.
SEC cancels its planned August 14 crypto meeting
The latest update changes the earlier narrative that the CFTC would follow an SEC meeting on new crypto offering rules. The SEC had scheduled an Aug. 14 open meeting to consider proposing a tailored offering regime for certain investment contracts involving crypto assets. On Aug. 13, however, the Commission formally canceled that meeting.
The SEC’s notice gave no reason and announced no replacement date. As previously reported, the planned session would have considered tailored rules for crypto investment contract offerings. Its cancellation does not withdraw the SEC’s wider crypto agenda, but no proposal will be considered at the previously scheduled Friday meeting.
What happens next for U.S. crypto regulation
The CFTC meeting remains scheduled for Aug. 20. Its crypto session will be followed by discussions on AI and prediction markets, including market surveillance, manipulation concerns and federal versus state jurisdiction. Members of the public can submit written comments through Aug. 27.
Chairman Michael Selig currently sits alone on a Commission designed for five commissioners, according to the CFTC’s official leadership page. The agency therefore lacks the bipartisan panel contemplated by its normal five-seat structure while major crypto and prediction-market policies are being developed.
The next concrete dates are Aug. 20 for the IAC discussion, Aug. 27 for comments and Sept. 15 for the CLARITY cloture test. The CFTC’s existing authority over crypto remains narrower than the framework Congress is considering. The Aug. 20 meeting can shape agency priorities, but it cannot substitute for legislation that changes the agencies’ statutory powers.
-
Fashion13 hours agoWeekend Open Thread: Ann Taylor
-
News Videos7 days agoCan Astrology Help Find Gold and Silver Trends? A Financial Astrology Guide
-
Business6 days agoDatadog: Best Of Breed For Multiple Reasons
-
Business6 days agoHow to Start a Cleaning Business: A Step-by-Step Guide
-
Business6 days agoBDC Weekly Review: Private BDC Q2 Numbers Are Strong
-
Business4 days agoOil Price Today (August 11): Crude oil rises to $88 after Trump’s compensation demand dents Hormuz opening. Here’s why
-
NewsBeat3 days agoCommunication cards help banking customers access services or report scams
-
Fashion6 days agoAmazon Sundays: Closet Care Before Fall
-
Business6 days ago5 Things You Must Know About Jorge Messi, the Father and Longtime Agent Who Shaped Lionel Messi’s Career
-
Politics7 days agoBe quiet, Miriam! – spiked
-
Politics5 days agoBen-Gvir’s crocodile project halted but abuses at Ketziot Prison continue
-
Business7 days agoMutual Fund Manager Scoops Up Beaten-Down Stocks
-
Crypto World4 days agoWhy Did Nvidia Stock Fall on Monday Despite a $500 Billion Wall Street AI Deal?
-
Crypto World4 days agoRevolut wins French banking licence, creates second EU banking hub
-
Politics6 days agoThe Church of England’s ruinous reparations racket
-
Crypto World7 days agoBitcoin ETFs draw $853.5M in five-day inflow streak
-
Entertainment6 days agoWill Ferrell’s New Netflix Series Just Became One of the Streamer’s Biggest Hits of 2026
-
Politics5 days agoSaudi Arabia used 86% of missile stockpile defending Iran attacks
-
Politics7 days agoCalls to permanently pedestrianise central Belfast following festival success
-
Crypto World7 days agoA Deep Dive Into One Of The Most Significant Hacks In Recent Memory

You must be logged in to post a comment Login