Connect with us

Crypto World

HashKey, YF Life test HKDAP stablecoin for insurance payments

Published

on

HashKey, YF Life test HKDAP stablecoin for insurance payments

HashKey Exchange has completed a live transaction using Hong Kong’s first regulated Hong Kong dollar-backed stablecoin, HKDAP, with YF Life, testing a payment route that the companies say could cut premium settlement from two to three business days to near real time.

Summary

  • HashKey and YF Life completed a live HKDAP transaction using real funds.
  • YF Life plans to explore HKDAP payments for insurance premiums.
  • HKDAP payments could cut settlement from two to three business days to near real time.
  • HashKey is an authorised distributor of the regulated Hong Kong dollar stablecoin.

HashKey Holdings said in a press release sent to crypto.news that its licensed trading platform used real funds to complete HKDAP subscription and redemption processes with YF Life Insurance International Limited, as the insurer prepares to explore stablecoin-based premium payments for customers.

The transaction puts HKDAP into an insurance-related use case only days after the stablecoin entered its controlled rollout. HashKey is an authorised distributor for HKDAP, which is issued by Anchorpoint Financial under a stablecoin issuer licence from the Hong Kong Monetary Authority.

Advertisement

YF Life plans to introduce HKDAP as a premium payment option subject to regulatory requirements and its implementation schedule, according to the release. The insurer said it expects to work with HashKey on the payment model and wants to become one of the first insurance companies in Hong Kong to accept the regulated stablecoin for premiums.

HKDAP test uses real funds for insurance payment setup

For the latest transaction, HashKey and YF Life tested the parts of the payment route needed before customers could use HKDAP for insurance premiums.

Real funds were used for both subscription and redemption, meaning the test covered the process of acquiring HKDAP and converting it back as part of the transaction cycle. HashKey said the work provides the basis for YF Life to introduce a regulated stablecoin payment option at a later stage.

Under the proposed customer process, policyholders could subscribe to HKDAP with Hong Kong dollars through HashKey Exchange. Customers who already hold the stablecoin could also withdraw HKDAP to a personal wallet and use it for premium payments.

Advertisement

Settlement time is one of the main areas being tested. According to HashKey, traditional premium payments can require two to three business days before settlement is confirmed, while an HKDAP transaction can provide what the company described as “near to real-time crediting.”

YF Life has not provided a launch date for customer premium payments using HKDAP. Its plans remain subject to relevant regulatory requirements, while the current transaction serves as a live test of the payment setup.

The insurance use case follows HashKey’s entry into HKDAP distribution this week. As crypto.news reported on Aug. 12, Anchorpoint appointed the licensed exchange as an authorised distributor during the token’s beta stage, giving eligible institutions and professional investors access to minting, redemption and fiat conversion services.

Advertisement

HashKey had already completed an HKDAP minting and redemption transaction with eligible clients before working with YF Life. That earlier transaction covered conversions from fiat into HKDAP and back into fiat, testing how customers could enter and exit the stablecoin through the licensed platform.

HKDAP moves from controlled rollout into payment testing

Anchorpoint began the phased HKDAP rollout on Aug. 12, initially opening access through institutional distributors and to professional investors.

During the first stage, the issuer identified cross-border payments, fiat conversion, and settlement involving tokenized real-world assets as initial uses for the stablecoin. Authorised distributors provide the link between Anchorpoint and eligible customers that need to acquire or redeem HKDAP.

HKDAP stands for HKD At Par and is designed to maintain a one-to-one value with the Hong Kong dollar. Anchorpoint has said eligible, high-quality Hong Kong dollar assets will back the stablecoin in line with the requirements applied under the city’s regulated stablecoin framework.

Advertisement

Access has initially been limited as Anchorpoint introduces the token through distributors and other use-case partners. Institutional and professional users can obtain HKDAP through participating channels, while the initial rollout has focused on testing transactions before access expands to additional users and applications.

The YF Life transaction adds insurance payments to the commercial applications now being tested. Under the structure described by HashKey, the exchange provides the regulated route through which customers can obtain HKDAP, while an insurer can receive the stablecoin as payment once the service is introduced.

HashKey said connecting the issuer, a licensed trading platform and an insurance institution allowed the parties to test how a regulated stablecoin could operate inside an existing financial service instead of limiting the exercise to token issuance and redemption.

Hong Kong stablecoin rules govern HKDAP issuance

Anchorpoint secured one of Hong Kong’s first stablecoin issuer licences from the HKMA in April, alongside HSBC, clearing it to issue HKDAP under the Stablecoins Ordinance.

Advertisement

The April licensing approval followed the Stablecoins Ordinance taking effect on Aug. 1, 2025. Under the framework, regulated fiat-referenced stablecoins are subject to requirements covering reserve assets, redemption, asset segregation, governance and anti-money laundering controls.

Anchorpoint is backed by Standard Chartered Bank (Hong Kong), HKT and Animoca Brands. The issuer said after receiving its licence that HKDAP would be introduced in phases, with payments and settlement among the uses planned for the token.

Each HKDAP token is intended to be backed one-to-one by eligible Hong Kong dollar reserves held under the regulated structure. Anchorpoint has used a distribution model in which approved partners handle access to HKDAP instead of the issuer serving every potential customer directly.

HashKey’s role under that setup covers distribution, trading, and related services. During the beta period, eligible institutions and professional investors can acquire the stablecoin through HashKey and supported channels, while Anchorpoint continues testing how HKDAP can be used across different transaction types.

Advertisement

HashKey plans more HKDAP payment use cases

Beyond insurance, HashKey said it plans to work with financial institutions and other industry partners on HKDAP applications involving corporate payments and cross-border trade.

The company identified those areas alongside insurance as potential uses where a regulated Hong Kong dollar stablecoin could be added to existing payment processes.

For YF Life, the next step described in the announcement is the planned introduction of an HKDAP premium payment solution once applicable regulatory requirements and its own roadmap allow it.

Customers would then be able to obtain HKDAP with Hong Kong dollars through HashKey Exchange or use an existing balance transferred to a personal wallet before making a premium payment, according to the companies.

Advertisement

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

Grayscale quietly killed three altcoin ETFs two days before Cardano became eligible

Published

on

Grayscale says Strategy’s $3B BTC sale could calm markets

Grayscale withdrew its Cardano, Polkadot, and Hedera ETF registrations in under four minutes on August 7, exactly two days before ADA cleared the SEC seasoning threshold. With Bitwise and Canary still in the race, the retreat says more about the economics of altcoin ETFs than about Cardano itself.

Summary

  • Grayscale filed three Form RW withdrawals with the SEC on August 7, 2026, pulling its Cardano Trust ETF, Polkadot Trust ETF, and Hedera Trust ETF registrations in a span of 190 seconds, with no shares issued, sold, or distributed under any of the three.

– Cardano completed its six-month CME futures seasoning period on August 9, 2026, two days after Grayscale walked away, clearing the threshold that would have allowed a spot ADA ETF to list under the SEC generic listing standards in as few as 75 days.

– Five other issuers, including Bitwise, Canary Capital, VanEck, and 21Shares, still have active ADA ETF filings, with the earliest possible SEC decision window falling around October 23, 2026.

Advertisement

– Grayscale reported a 20 percent revenue decline in its IPO filing, with GBTC and ETHE generating 88 percent of the firm’s roughly $318.7 million in nine-month revenue while bleeding a combined $30 billion in cumulative outflows since their ETF conversions.

– ADA trades near $0.196 with a $6.55 billion market cap, DOT sits at $0.805, and HBAR has fallen to $0.068, all down more than 60 percent from their all-time highs and collectively representing a fraction of the institutional demand that drove Bitcoin and Ethereum ETF launches.

At 4:33 p.m. Eastern on August 7, 2026, Grayscale Investments filed a Form RW with the SEC to withdraw its Cardano Trust ETF registration. Ninety seconds later, the Hedera Trust ETF followed. Two minutes after that, the Polkadot Trust ETF joined them. Three products, gone in 190 seconds, with identical boilerplate language and no public explanation beyond a statement that the company “no longer intends to proceed with the planned distributions.”

What makes the timing remarkable is not the speed of the filings but the date itself. Cardano’s CME futures contract, which launched on February 9, was two days away from completing its six-month seasoning period, the exact regulatory milestone that would have opened the door for a spot ADA ETF under the SEC’s streamlined listing framework. Grayscale did not just exit the altcoin ETF race. It exited on the finish line.

Advertisement

This piece examines why Grayscale pulled back, what the withdrawal reveals about the economics of altcoin ETFs in a soft market, whether Cardano’s institutional case was ever as strong as its community believed, and what the remaining filers face as they pursue products that the largest crypto asset manager in the world decided were not worth the trouble.

Three withdrawals, one message

The mechanics of the withdrawal are straightforward. Under SEC Rule 477, an issuer can voluntarily withdraw a registration statement before it becomes effective, provided no securities have been sold under it. Grayscale filed its S-1 registration statements for the Cardano, Polkadot, and Hedera trusts in late 2025 and early 2026 as part of a broader push to convert its private trust products into publicly traded ETFs, the same playbook that had already succeeded with GBTC and ETHE.

All three Form RW filings contained identical language. None cited a specific reason for withdrawal. The SEC accepted them without comment. Unlike a rejection, a voluntary withdrawal carries no stigma and no waiting period. Grayscale could refile tomorrow if it chose to.

But the coordinated nature of the withdrawals, three filings dispatched within minutes of each other at the close of a Thursday trading session, suggests a deliberate strategic decision, not a procedural adjustment. This was not a pause. It was a retreat.

Advertisement

The crypto market noticed. ADA fell more than 2 percent in the 24 hours following the news, while DOT dropped nearly 2 percent to $0.805 and HBAR slipped 2.24 percent to $0.068. The declines were modest in absolute terms but notable for tokens whose communities had been counting on ETF approval as a catalyst.

The seasoning clock and what it meant for Cardano

To understand why the timing matters, it helps to understand the regulatory machinery that Grayscale was walking away from.

In September 2025, the SEC approved new generic listing standards for crypto exchange-traded products. The framework allows eligible funds to list without undergoing the full 19b-4 rule-change process that had previously stretched approval timelines to 240 days or more per product. Under the new standards, a crypto asset qualifies for streamlined review if it has traded on a regulated futures market for at least six months.

CME Group launched Cardano futures on February 9, 2026. The six-month clock expired on August 9. On that date, ADA became the newest cryptocurrency to meet the SEC’s eligibility threshold, joining Bitcoin, Ethereum, Solana, and XRP in the small club of assets with a clear path to a spot ETF.

Advertisement

Grayscale knew this. Every issuer in the space knew this. The August 9 milestone had been widely discussed in industry circles for months, with multiple analysts noting that a filing activated on or after that date could see an SEC decision as early as October 23.

Yet Grayscale chose to withdraw two days before the clock expired. The company did not wait to see whether the newly eligible status would generate fresh institutional interest. It did not pause the filing to reassess. It killed it. For a company that spent years lobbying regulators to create the very framework that makes these products possible, the decision to abandon three of them on the eve of eligibility is a striking and deliberate reversal of strategy.

The economics of a product nobody wanted

The most likely explanation for Grayscale’s withdrawal is the simplest one: the numbers did not work.

Launching an ETF is not free. Legal fees, compliance infrastructure, market-making arrangements, custodial agreements, marketing, and ongoing regulatory reporting all carry costs. For a Bitcoin or Ethereum product with billions of dollars in potential demand, those costs are trivial relative to the revenue from management fees. For an altcoin ETF tracking a $6.55 billion asset with tepid institutional interest, the calculus is different.

Advertisement

Consider the existing data points. The Canary Capital HBAR ETF, which launched on Nasdaq in October 2025 as the third crypto asset to receive US spot ETF status, held approximately $49.14 million in net assets as of July 2, 2026. Its market-price return was negative 37.32 percent for the year and negative 63.32 percent since inception. Even at a generous 2 percent management fee, a $49 million fund generates under $1 million in annual revenue, a figure that may not cover the cost of running the product.

The broader altcoin ETF landscape tells a similar story. While XRP ETFs have accumulated roughly $1.5 billion in cumulative inflows and Solana funds have gathered about $1.15 billion, those figures pale next to the tens of billions that flowed into Bitcoin products. Below the top tier, demand drops off sharply. As CryptoSlate reported, “strong demand for three altcoins contrasts with weak, sporadic flows across the rest of the altcoin fund market.”

Grayscale already has a way to offer ADA exposure. Its CoinDesk Crypto 5 ETF, trading under the ticker GDLC, tracks an index that includes Bitcoin, Ethereum, XRP, Solana, and Cardano. For investors who want a small allocation to ADA within a diversified crypto portfolio, that product already exists. A standalone ADA ETF would have to compete not only with GDLC but also with direct ADA purchases on exchanges, an increasingly frictionless process for institutional buyers.

Grayscale’s fee problem and the IPO calculus

The withdrawal also needs to be read in the context of Grayscale’s broader financial position. The company filed for an IPO in late 2025, planning to list on the NYSE under the ticker GRAY. The S-1 filing revealed a business under significant pressure.

Advertisement

GBTC, charging 1.5 percent annually, and ETHE, charging 2.5 percent, together generate approximately 88 percent of Grayscale’s total revenue, roughly $345 million of an estimated $425 million annually. But both products have been hemorrhaging assets. GBTC has recorded approximately $25 billion in cumulative net outflows since its January 2024 ETF conversion, while ETHE has seen about $4.8 billion leave since July 2024. Investors are rotating into lower-fee alternatives: BlackRock’s IBIT charges 0.12 percent, and Fidelity’s FBTC charges 0.25 percent.

Grayscale responded by launching Mini versions of both products at 0.15 percent, which have attracted $3.3 billion in combined inflows since 2024. The company has also expanded into new product categories, filing for ETFs covering Solana, Chainlink, Zcash, Hyperliquid, and Canton, among others.

But expansion costs money. Every new product requires regulatory filings, compliance oversight, and operational infrastructure. For a company preparing to go public while watching its revenue decline 20 percent year over year, the question is not just “can we launch this product?” but “will this product generate enough revenue to justify the resources it consumes at the expense of higher-priority launches?”

For ADA, DOT, and HBAR, the answer appears to have been no. Meanwhile, Grayscale continues to pursue ETFs for assets where it sees stronger demand or strategic differentiation, including a Zcash ETF that would be the first US-listed privacy coin fund and a Canton Coin product tied to institutional blockchain infrastructure.

Advertisement

What the remaining filers face

Grayscale’s exit does not kill the Cardano ETF. Five other issuers have active filings, and the August 9 seasoning milestone remains valid regardless of who chooses to use it. Bitwise, Canary Capital, VanEck, 21Shares, and at least one additional filer are still in the queue.

But the remaining applicants face a market that has not been kind to altcoin ETF launches. The Canary HBAR ETF’s experience is instructive. Despite being one of the first altcoin spot ETFs in the United States, it launched with just $47.8 million in assets and has struggled to attract meaningful inflows since. The lesson is that regulatory approval alone does not create demand. Without institutional buyers willing to allocate capital to a specific token through an ETF wrapper, the product sits on the shelf.

Cardano has some advantages that HBAR lacked at launch. Its market cap of $6.55 billion is substantially larger. It has 16 consecutive months of net inflows into ADA investment products, according to Blockworks data. Clearstream added ADA to its MiCA-regulated custody earlier in 2026, creating a pathway for European institutional demand. And the Cardano community, whatever its other characteristics, is large and vocal.

Advertisement

But “large and vocal” does not always translate to “willing to buy an ETF.” Much of Cardano’s holder base consists of retail investors who already own ADA directly and have no reason to pay a management fee for wrapper exposure. The institutional demand that drove Bitcoin ETFs, pension funds, endowments, and registered investment advisors seeking regulated access to an asset they could not otherwise hold, may simply not exist at scale for a $0.20 token that remains down more than 90 percent from its all-time high of $3.10.

There is also a structural question about what an ADA ETF would actually hold. Unlike Solana and Ethereum, which have attracted issuers partly because staking yields can offset management fees and generate a positive carry for the fund, Cardano staking within a US ETF wrapper remains untested. Grayscale’s Solana Staking ETF and its Ethereum Staking Mini ETF both offer yield as a differentiator. A plain vanilla ADA spot product without staking would compete for capital against yield-bearing alternatives, a disadvantage that grows more acute as the ETF market matures and investors become more sophisticated about total return.

The fee question compounds the problem. Morgan Stanley launched Ethereum and Solana ETFs at 0.14 percent, setting a new floor for the industry. Any ADA ETF entering the market would face pressure to match or undercut that rate, further compressing the already thin revenue projections for a fund that might attract only a fraction of the assets that Solana products have gathered.

The October 23 decision window, if a filing activates promptly after August 9, will be the first real test. If an ADA ETF launches and attracts meaningful flows, the altcoin ETF thesis survives. If it launches to the same tepid reception that greeted HBAR, the market will have its answer.

Advertisement

The opposing case at full strength

The bearish reading of Grayscale’s withdrawal, that altcoin ETFs are a dead end and institutional demand for anything below the top four crypto assets is negligible, deserves a serious challenge.

First, the timing may not be as significant as it appears. Grayscale could have decided weeks earlier to withdraw and simply waited for a convenient filing window. The proximity to August 9 may be coincidental rather than calculated.

Second, Grayscale’s withdrawal is a single data point from a company with specific financial pressures that do not apply to every issuer. Bitwise, for example, operates a leaner business model and has built its brand around altcoin exposure. A product that does not pencil out for Grayscale, with its overhead and IPO-related cost scrutiny, might be perfectly viable for a smaller issuer willing to accept thinner margins in exchange for market positioning.

Third, the altcoin ETF market is young. Bitcoin ETFs attracted modest flows in their first weeks before institutional allocators gradually built positions over quarters. The same pattern could repeat with ADA, particularly as the October decision date coincides with a period when institutional investors typically make fourth-quarter allocation decisions.

Advertisement

Fourth, Cardano’s fundamentals have continued to develop. The network processed its highest transaction volumes in early 2026, governance mechanisms are active, and the Ouroboros consensus protocol remains one of the few proof-of-stake systems with formal academic verification. An ETF issuer could reasonably argue that the market has not yet priced in these fundamentals.

Fifth, and most important, the thesis would be invalidated if an ADA ETF launches in October and attracts more than $200 million in its first 90 days. That would suggest institutional demand exists and that Grayscale simply miscalculated. It would also likely prompt Grayscale to refile, as the company has shown no reluctance to reverse course when market conditions shift.

The 190-second signal the market missed

There is a detail in the withdrawal filings that has received less attention than it deserves, and that a competitor publication is unlikely to have noticed.

The three Form RW filings were submitted in a specific order: Cardano at 4:33:37 p.m. ET, Hedera at 4:34:55 p.m., and Polkadot at 4:36:47 p.m. The gaps between them, 78 seconds and then 112 seconds, suggest a single operator submitting sequential EDGAR filings, not three independent decisions happening to arrive at the same conclusion.

Advertisement

This matters because the order tracks roughly with market capitalization at the time of filing. ADA, the largest of the three at $6.55 billion, went first. HBAR, at roughly $3.1 billion, went second. DOT, at approximately $1.5 billion, went last. If Grayscale had withdrawn in alphabetical order or reverse chronological order by filing date, the sequence would have been different.

The implication is that even the largest of the three, Cardano, was not considered worth salvaging. Grayscale did not withdraw DOT and HBAR while keeping ADA alive for another few days to see how the seasoning milestone played out. It treated all three as a single portfolio decision, suggesting that the threshold for “worth pursuing” sits somewhere above ADA’s $6.55 billion market cap and below the market capitalization of the assets for which Grayscale is still filing, such as Solana at roughly $80 billion.

That threshold has implications far beyond Cardano. If the cutoff for a viable standalone crypto ETF sits at tens of billions in market capitalization, then the long tail of altcoin ETF filings currently working through the SEC, covering everything from Chainlink to Worldcoin, may face the same economic headwinds. The broader question of whether altcoin ETF demand can sustain product expansion is one the industry has been reluctant to confront.

What to watch

October 23 decision window: If an issuer activates a spot ADA ETF filing promptly after August 9, the SEC’s 75-day review period points to late October. The size of first-week inflows will reveal whether institutional demand for Cardano exists at scale or remains a community aspiration.

Advertisement

Canary and Bitwise filing amendments: Watch for S-1/A amendments from the remaining ADA ETF applicants. Active amendments signal continued commitment. Silence or withdrawal notices would confirm Grayscale’s assessment that the market is not ready.

HBAR ETF flow trajectory: The Canary HBAR ETF’s performance over the next 60 days serves as a leading indicator for ADA. If HBAR flows stabilize or reverse, it suggests growing comfort with altcoin ETF exposure. Continued outflows would validate the bearish thesis.

Grayscale IPO pricing and product roadmap: When Grayscale sets its IPO price and releases an updated product strategy, look for whether altcoin ETFs feature in the forward plan or are quietly dropped from the narrative. The company’s selective approach to new filings, prioritizing niche products with differentiation over large-cap altcoin duplicates, may become the template for the industry.

ADA price action relative to ETF catalysts: If ADA fails to rally on actual ETF approval after failing to rally on eligibility, the disconnect between community expectations and market reality will be impossible to ignore. A sustained move above $0.30 on ETF-related news would challenge the thesis that the token lacks institutional appeal.

Advertisement

The information presented in this article is for educational and informational purposes only. It does not constitute financial, investment, legal, or tax advice. Cryptocurrency investments carry significant risk, including the potential loss of all invested capital. Readers should conduct their own research and consult qualified financial advisors before making any investment decisions. Crypto.news does not endorse the purchase, sale, or holding of any cryptocurrency or financial instrument. Past performance is not indicative of future results. Published August 14, 2026.

Is the ADA ETF still happening without Grayscale?

Yes. Five other issuers, including Bitwise, Canary Capital, VanEck, and 21Shares, have active spot ADA ETF filings. Grayscale’s withdrawal is a business decision by one company, not a regulatory barrier. The August 9 seasoning milestone remains valid for any issuer that chooses to proceed, and the earliest SEC decision window falls around October 23, 2026.

Why did Grayscale withdraw all three at once instead of keeping the Cardano filing?

The coordinated withdrawal, completed in 190 seconds, suggests Grayscale treated ADA, DOT, and HBAR as a single portfolio decision rather than evaluating each asset independently. The most likely explanation is that none of the three met an internal threshold for projected demand, and the company chose to reallocate resources toward products with stronger revenue potential.

Advertisement

What is the CME futures seasoning period and why does it matter?

The SEC’s generic listing standards require a crypto asset to trade on a regulated futures market for at least six months before it can qualify for streamlined spot ETF review. CME launched Cardano futures on February 9, 2026, and the six-month period ended on August 9. Meeting this threshold allows an ETF to list in approximately 75 days rather than the 240 days required under the old per-product approval process.

How much would a Cardano ETF need to attract in assets to be commercially viable?

Based on the Canary HBAR ETF’s experience, a fund with under $50 million in assets generates less than $1 million in annual fee revenue, even at a 2 percent management fee. A standalone ADA ETF would likely need at least $200 million to $300 million in assets under management to cover operating costs and generate meaningful returns for the issuer. By comparison, XRP ETFs have attracted roughly $1.5 billion and Solana funds about $1.15 billion.

Could Grayscale refile for a Cardano ETF later?

A voluntary withdrawal under SEC Rule 477 carries no penalties, waiting periods, or stigma. Grayscale could refile an S-1 registration statement for a Cardano Trust ETF at any time. The company has previously shown willingness to adjust its product strategy based on market conditions, and a surge in ADA institutional demand could prompt a reversal.

What does Grayscale’s withdrawal mean for DOT and HBAR prices?

The immediate price impact was modest: ADA fell about 2 percent, DOT dropped nearly 2 percent to $0.805, and HBAR slipped 2.24 percent to $0.068. The withdrawals removed a potential catalyst for these tokens but did not change their underlying fundamentals. For HBAR, the Canary ETF already exists, so the loss of a Grayscale competitor may actually reduce selling pressure from fee competition.

Advertisement

Are altcoin ETFs still worth pursuing for issuers?

The market is splitting into tiers. Bitcoin and Ethereum ETFs have attracted tens of billions. Solana and XRP funds have crossed the $1 billion mark. Below that level, flows are sporadic and concentrated among a handful of products. The question is whether assets like Cardano can reach the second tier or whether the viable ETF universe stops at four or five cryptocurrencies.

Should investors buy ADA ahead of a potential ETF approval?

Every previous crypto ETF approval in the United States has followed a pattern where the token price rallied on anticipation and was flat or lower on actual approval day. ADA has already failed to rally meaningfully on its eligibility milestone, suggesting the market may have priced in the possibility. Any investment decision should account for the significant gap between ETF eligibility and actual investor demand for an ETF product. This is educational analysis, not investment advice.

Source link

Advertisement
Continue Reading

Crypto World

Ripple’s Sherlock audit found 96 bugs before they reached a single wallet

Published

on

Ripple targets $2 trillion payment network with Notabene deal

A $550,000 community audit contest uncovered two critical vulnerabilities in XRP Ledger features that could have drained user accounts without private keys. The findings reveal how Ripple’s audit-before-release model diverges sharply from the broader crypto industry’s patch-after-exploit norm.

Summary

  • Sherlock’s two-week audit contest, which opened on April 13, 2026, uncovered 96 valid vulnerabilities across five proposed XRP Ledger amendments, including 2 critical and 6 high-severity bugs, before any of them reached mainnet.
  • Ripple paid $309,000 in RLUSD bounties from a $550,000 prize pool, marking the first collaboration between Sherlock and Ripple and one of the largest audit contests of 2026.
  • The most severe finding was a signature-validation flaw in the Batch amendment that would have allowed attackers to execute transactions from any account without holding its private keys, first identified on February 19, 2026, by researcher Pranamya Keshkamat and Cantina’s AI tool Apex.
  • A separate critical bug in Permission Delegation allowed malicious actors to silently drain XRP balances through repeated fee charges on invalid delegated transactions, because the code checked permissions before verifying signatures.
  • DeFi exploits exceeded $840 million across more than 50 incidents in the first five months of 2026 alone, a 70% year-over-year increase, and 70% of exploited contracts had been audited but lacked post-deployment monitoring.

XRP Ledger version 3.3.0 shipped on August 6, 2026, carrying five proposed amendments and a bundled cleanup patch. On paper it looked like a routine infrastructure release. Underneath, the update represented the conclusion of a six-month security gauntlet that caught two account-draining bugs, rewrote two entire feature implementations from scratch, and paid hundreds of thousands of dollars to outside researchers who found problems the internal team had missed. The process raises a pointed question for the wider blockchain industry: if Ripple can catch critical flaws before deployment, why does so much of crypto still treat security audits as a post-launch checkbox?

This piece breaks down what the two critical vulnerabilities actually were at a technical level, examines how the audit-vote-activate pipeline compares to competing chains’ security models, and assesses whether the findings strengthen or undermine the case for XRPL as institutional-grade infrastructure.

Advertisement

What the Sherlock contest actually found

The scope covered five pillars of upcoming XRPL functionality: Batch Transactions, Permission Delegation, Multi-Purpose Token (MPT) DEX integration, Confidential Transfers for MPTs, and Sponsored Fees and Reserves. Sherlock, a Web3 security firm that ranks researchers by performance and structures engagements as adversarial contests, opened the audit on April 13, 2026, with a $550,000 RLUSD prize pool. The contest page on Sherlock’s platform listed the engagement as “XRP Ledger – April 2026 Contest – 550,000 RLUSD,” signaling that Ripple paid the bounties in its own stablecoin.

Over two weeks, participants submitted reports that surfaced 96 valid findings: 2 critical, 6 high, 29 medium, and 59 low-severity issues. Ripple distributed $309,000 in RLUSD to contributors. The remaining pool covered Sherlock’s operational costs and lower-tier findings that did not meet the payout threshold.

The contest marked the first formal collaboration between Sherlock and Ripple, and it arrived at a moment when the XRP Ledger’s feature pipeline was expanding faster than at any point in its history. Five amendments shipping simultaneously meant five distinct attack surfaces, each with its own transaction logic, authorization model, and cryptographic requirements. For context, Sherlock’s audit contest model has previously been used by protocols including Aave, Euler, and Olympus DAO, but an engagement covering C++ protocol-level code for a layer-one blockchain was atypical for a platform more commonly associated with Solidity smart contracts.

The severity distribution itself tells a story. The 29 medium-severity findings suggest a category of bugs that would not individually compromise accounts but could create unexpected behavior under specific transaction sequences. The 59 low-severity issues likely include code quality concerns, documentation gaps, and edge cases that could compound under adversarial conditions. The two critical and six high-severity bugs, however, represented exploitable vulnerabilities that warranted immediate remediation.

Advertisement

The Batch amendment bug that could have emptied accounts

The most dangerous vulnerability predated the Sherlock contest by two months. On February 19, 2026, security researcher Pranamya Keshkamat and Cantina’s autonomous AI audit tool Apex independently identified a signature-validation flaw in the original Batch amendment while it was still in its validator voting phase.

The technical failure was precise. Batch Transactions allow up to eight operations to execute atomically under a single outer transaction. The outer transaction’s signature-validation code contained an early-exit condition that could be satisfied without properly verifying who was authorizing the inner transactions. In practice, an attacker could have constructed a Batch transaction containing inner Payment operations targeting a victim account, draining it down to its reserve balance, without ever holding that account’s private keys. The same logic gap would have permitted unauthorized AccountSet, TrustSet, or AccountDelete operations.

The vulnerability disclosure report published on xrpl.org detailed the mechanics: the signer check in the outer transaction could pass without confirming that the entity submitting the batch actually controlled the accounts referenced in the inner transactions. This meant that the atomicity feature designed to improve user experience could have been weaponized to empty any account on the network in a single transaction.

RippleX responded with an emergency release. Rippled version 3.1.1, published on February 23, 2026, four days after discovery, marked both the original Batch amendment and its companion fixBatchInnerSigs as unsupported, preventing validators from voting on or activating them. No funds were lost because the amendment had not yet cleared the 80% validator threshold required for activation. The replacement, BatchV1_1, shipped in version 3.3.0 with the early-exit condition removed, additional authorization guards added, and the signing check scope tightened to verify each inner transaction against the correct signer independently.

Advertisement

Permission Delegation’s silent fee-drain exploit

The second critical vulnerability operated through a subtler mechanism. A September 2025 disclosure documented how the original Permission Delegation implementation allowed an attacker to silently bleed a victim account’s XRP balance without accessing its keys.

The exploit relied on a design feature of the XRP Ledger’s transaction processing that has existed since the network’s earliest days. On XRPL, a transaction that fails with a “tec”-class error still incurs a fee charge, while errors caught earlier in the pipeline, before signature verification, do not. This distinction exists because tec-class failures indicate transactions that were properly formed and signed but failed for business-logic reasons, and the fee prevents spam. Permission Delegation’s original code checked whether a delegate account held the relevant permission before it verified the transaction’s signature. An attacker could repeatedly submit invalid offline-signed transactions with elevated fees against a delegated account, and each failed transaction would still deduct the fee from the victim’s balance.

The economic impact would have compounded quickly. Because the attacker could set arbitrarily high fees on these transactions, a sustained attack could drain an account far faster than normal transaction fees would suggest. The victim would see their balance declining with no corresponding outbound payments, making the attack difficult to diagnose without examining raw transaction metadata.

The fix reclassified the relevant error from tec to ter and reordered the checks so that no fee can be deducted before signature verification passes. The replacement amendment, PermissionDelegationV1_1, carries a default “No” designation in the 3.3.0 registry, meaning validators must actively vote to enable it. This conservative default reflects the sensitivity of the original flaw: even after the rewrite, Ripple chose to require explicit validator opt-in for the feature.

Advertisement

Why both rewrites shipped in a single release

Packaging two security-rewritten amendments alongside three entirely new features in one version was a deliberate choice. RippleX published xrpld 3.3.0 on August 6, 2026, with the code for all six proposals (including a bundled cleanup amendment called fixCleanup3_3_0) present but none of them activated. Under the XRP Ledger’s amendment process, each proposal must sustain more than 80% validator support for two consecutive weeks before going live.

This separation between code availability and feature activation is a structural advantage that most smart-contract platforms lack. On Ethereum, a deployed contract is live the moment it hits the blockchain. On XRPL, code can ship, undergo further review during the voting window, and still be blocked if validators lose confidence. The Batch and Permission Delegation rewrites had already survived the Sherlock contest, a Halborn re-audit that found zero critical or high-risk issues, and months of internal testing. The voting period adds yet another layer of defense before any code touches real funds.

The version also retired five legacy amendments, including Clawback, fixDisallowIncomingV1, fixInnerObjTemplate, fixNFTokenReserve, and fixUniversalNumber, removing dead code paths that could otherwise accumulate as latent attack surface over time.

Advertisement

The five feature amendments in 3.3.0 represent the broadest single expansion of XRPL capabilities to date. Confidential Transfers bring EC-ElGamal encryption and zero-knowledge proofs to Multi-Purpose Tokens, shielding individual balances and transfer amounts from public view while preserving compliance access for authorized parties. Sponsored Fees allow applications to cover network costs on behalf of users, addressing the onboarding friction that has kept consumer-facing applications off decentralized networks. DynamicMPT lets issuers modify token properties after creation, supporting evolving regulatory and business requirements. Together with the Batch and Permission Delegation rewrites, these features target a specific audience: regulated financial institutions that need privacy, atomic settlement, and delegated operations without sacrificing auditability.

Audit before release versus patch after exploit

The contrast between Ripple’s approach and the broader industry’s security track record is stark. DeFi exploits exceeded $840 million across more than 50 incidents in the first five months of 2026, a 70% year-over-year increase over the same period in 2025. North Korea-linked actors accounted for 76% of global crypto hack losses in the first four months of the year. And the most damning statistic: 70% of exploited contracts had been audited but lacked any form of post-deployment monitoring. Only 4% of tracked projects combined audits, active bug bounties, and third-party monitoring controls together.

The Ethereum ecosystem, home to the largest concentration of smart-contract value, operates under a fundamentally different security model. Contracts deploy to mainnet through an immutable transaction. If a vulnerability surfaces afterward, the options are limited: deploy a new contract and migrate users, implement a proxy upgrade pattern that introduces its own attack surface, or accept the risk. The Wormhole bridge hack of 2022 cost $320 million because a deprecated verification function remained in production code. Ronin’s August 2024 exploit cost $12 million because a contract upgrade failed to initialize operator weights correctly. In both cases, audits had been performed; the failures happened after deployment.

Advertisement

The KelpDAO hack on April 18, 2026, which drained approximately $293 million, was the largest single DeFi exploit of the year. The Drift Protocol exploit on Solana on April 1, which cost roughly $286 million, was the largest ever recorded on that chain. These figures are not fringe events. They represent the baseline failure rate of an industry that has collectively lost $16.69 billion to hacks, bridge exploits, and security incidents according to DeFiLlama data.

XRPL’s amendment voting process inverts this sequence. Code ships in a release, but features remain dormant until validators approve them. During the voting window, researchers, node operators, and competing auditors can examine the live codebase with full context. If a problem surfaces, validators simply withhold their votes. No emergency patch, no migration, no proxy contract. The February 2026 Batch bug followed exactly this path: the amendment was in its voting phase, the vulnerability was identified, and an emergency release prevented activation. Zero funds at risk, zero user impact.

This is not to say that the XRPL model is flawless. The amendment process works for protocol-level features but does not extend to applications built on top of the ledger. A poorly coded trust line or MPT integration could still lose funds. And the 80% validator threshold creates its own risks: if too few validators upgrade to a new version, legitimate security patches can stall. But for core protocol changes, the audit-vote-activate pipeline represents a materially different security posture than deploy-and-hope.

What this means for XRPL’s institutional pitch

Ripple has spent 2026 building an institutional infrastructure stack at an aggressive pace. The $1.25 billion acquisition of Hidden Road, a multi-asset prime broker rebranded as Ripple Prime, gave the company a regulated on-ramp for traditional finance. RLUSD reached a $1.72 billion market capitalization in under a year and moved more than $18 billion in transaction volume during Q1 alone. Goldman Sachs disclosed a $153.8 million position across four XRP ETFs. Ripple secured a full Electronic Money Institution license from Luxembourg in February, UK Financial Conduct Authority permissions in January, and a MiCA Crypto-Asset Service Provider license on July 6.

The institutional DeFi features arriving in version 3.3.0 are the technical counterpart to this business development push. Confidential Transfers address the privacy requirements of banks that cannot expose transaction details on a public ledger. Sponsored Fees solve the onboarding friction that has kept retail banking applications off decentralized networks. Permission Delegation, once its rewrite clears the voting process, enables the kind of controlled access models that compliance departments require.

But institutional adoption depends on trust, and trust in blockchain infrastructure ultimately comes down to security track record. The fact that Ripple caught two critical bugs, rewrote two entire feature implementations, paid outside researchers $309,000 to find problems, and still delivered all five features on schedule is a stronger institutional selling point than any individual feature. It suggests a security culture where finding bugs is rewarded and where shipping is subordinate to verification.

Over 300 financial institutions across 55 countries currently use RippleNet, with active On-Demand Liquidity corridors in more than 70 markets. For those institutions, the Sherlock audit results are not abstract. They are evidence that the code running their cross-border payments has been stress-tested by adversarial researchers with financial incentives to break it. Ripple’s four-phase quantum-resistance roadmap, targeting completion by 2028, further signals that the company is engineering for institutional time horizons measured in decades, not deployment cycles.

Advertisement

The opposing case: why skeptics are not convinced

The strongest argument against reading too much into the Sherlock audit runs in two directions.

First, finding 96 bugs before release can be framed as evidence of thorough testing or evidence of sloppy development. Both the Batch and Permission Delegation vulnerabilities were in the original implementations, meaning they cleared internal review before external researchers caught them. The February 2026 Batch bug was not identified by Ripple’s own team but by an independent researcher and an AI tool. If external auditors are the primary safety net, the internal development process may have quality gaps that will eventually produce a vulnerability that no external reviewer catches in time.

Second, the XRPL amendment model’s strength, the ability to prevent activation during the voting window, is also a speed constraint. Ethereum’s willingness to deploy and iterate has enabled a pace of innovation that XRPL cannot match. The five amendments in version 3.3.0 have been in development and review cycles for months. The original Batch amendment was proposed in 2025. For protocols competing for developer attention in fast-moving markets, a six-month security pipeline may be too slow to attract the builder ecosystem that drives network effects.

There is also a concentration risk in the validator set. The 80% activation threshold means that a relatively small number of validators, many of which are operated by entities with close ties to Ripple, control whether amendments go live. Critics argue this is not truly decentralized governance but a curated approval process dressed in consensus language. When Ripple’s own validator voted “yes” on lending amendments in recent weeks, it underscored how much influence the company retains over its nominally decentralized network.

Advertisement

Finally, the $309,000 payout from a $550,000 pool raises a practical question about incentive alignment. Top-tier security researchers command rates that exceed what contest models typically pay per hour of effort. If the most skilled auditors skip XRPL contests because the expected payout per finding is lower than private engagements, the adversarial review may be broad but not deep enough to catch the most sophisticated attack vectors.

These objections have weight. XRP traded near $1.03 in late July 2026, roughly 71% below its $3.65 cycle high set on July 17, 2025, suggesting the market has not yet priced in the institutional narrative. Whether the security track record translates into adoption depends on factors beyond code quality: regulatory clarity, competitive positioning against Ethereum layer-2 solutions, and whether institutions care more about pre-deployment audits than they do about ecosystem size.

What to watch

Validator voting thresholds for the five 3.3.0 amendments: if BatchV1_1 and PermissionDelegationV1_1 clear 80% support within the first voting cycle, it signals validator confidence in the rewrites. A stall would suggest lingering concerns about the rewritten code.

Post-activation bug reports: the real test of the Sherlock audit’s thoroughness comes after features go live. Zero critical findings in the first 90 days would validate the pre-release model; any post-activation vulnerability would undermine the entire thesis.

Advertisement

RLUSD adoption on Confidential Transfers: institutional stablecoin usage on shielded rails would confirm demand for privacy-compliant settlement. Volume metrics in the first quarter after activation will be the clearest signal of whether banks are ready to transact on a public ledger with privacy guarantees.

Sherlock’s next XRPL engagement: whether Ripple continues with adversarial audit contests for future amendments or reverts to traditional private audits will indicate how deeply the pre-release model is embedded in the development culture.

Competing chain security incidents: every major exploit on Ethereum or Solana that traces back to a post-deployment vulnerability strengthens the case for XRPL’s audit-vote-activate pipeline. The comparison is only as strong as the industry’s continued failure to adopt similar processes.

Advertisement

What did the Sherlock audit of XRP Ledger find?

The two-week audit contest, which opened on April 13, 2026, uncovered 96 valid vulnerabilities across five proposed XRPL amendments: 2 critical, 6 high, 29 medium, and 59 low-severity issues. Ripple paid $309,000 in RLUSD bounties from a $550,000 prize pool. All findings were addressed before any of the affected features activated on mainnet.

What was the critical Batch amendment bug?

The original Batch amendment contained a signature-validation flaw that allowed an attacker to execute inner transactions from any account without holding its private keys. The bug was an early-exit condition in the outer transaction’s signing check that could be satisfied without proper authorization verification. Researcher Pranamya Keshkamat and Cantina’s AI tool Apex identified it on February 19, 2026. RippleX patched it in emergency release version 3.1.1 four days later.

How did the Permission Delegation vulnerability work?

The original implementation checked delegate permissions before verifying transaction signatures. On XRPL, transactions that fail with “tec”-class errors still incur fees. An attacker could repeatedly submit invalid transactions with elevated fees against a delegated account, draining its XRP balance without ever holding its keys. The fix reclassified the error type and reordered the verification checks.

Were any funds lost from these vulnerabilities?

No funds were lost. Both critical vulnerabilities were identified before their respective amendments activated on mainnet. The Batch bug was caught during the validator voting phase, and the Permission Delegation flaw was disclosed and patched before activation. The XRP Ledger’s amendment process, which requires 80% validator support for two consecutive weeks, provided a structural buffer that prevented exploitation.

Advertisement

What is Sherlock and how does its audit model work?

Sherlock is a Web3 security firm that structures audits as adversarial contests, ranking researchers by performance and offering financial incentives through prize pools. The XRP Ledger engagement was Sherlock’s first collaboration with Ripple and one of the largest audit contests of 2026. The model differs from traditional private audits by inviting broad participation from independent security researchers competing for bounties, which surfaces a wider range of attack vectors than a small internal team can cover.

How does XRPL’s security model differ from Ethereum’s?

XRPL’s amendment process separates code deployment from feature activation. New features ship in a software release but remain dormant until validators vote to activate them, creating a review window where vulnerabilities can be caught without emergency patches. Ethereum’s smart contracts are live upon deployment, and fixing vulnerabilities requires deploying new contracts, migrating users, or implementing proxy upgrades. In the first five months of 2026, DeFi exploits exceeded $840 million, and 70% of exploited contracts had been audited but lacked post-deployment monitoring.

What features does XRP Ledger version 3.3.0 include?

Version 3.3.0, released on August 6, 2026, contains code for five feature amendments and a cleanup patch. The features include Confidential Transfers for Multi-Purpose Tokens using zero-knowledge proofs, rewritten Batch Transactions for atomic multi-operation settlement, rewritten Permission Delegation for controlled account access, Sponsored Fees allowing applications to cover user costs, and DynamicMPT enabling issuers to modify token properties after creation.

Does this audit make XRPL a safe investment?

The Sherlock audit reflects a rigorous pre-release security process, but code quality is one factor among many that influence investment outcomes. XRP traded near $1.03 in late July 2026, roughly 71% below its cycle high, and market performance depends on regulatory developments, institutional adoption rates, competitive dynamics, and macroeconomic conditions. This is educational analysis, not investment advice. **Disclaimer**: This article was published on August 14, 2026. It is intended for educational and informational purposes only and should not be construed as financial, investment, or legal advice. Cryptocurrency markets are volatile and carry substantial risk. Readers should conduct their own research and consult qualified professionals before making any investment decisions.

Advertisement

Source link

Continue Reading

Crypto World

Trump’s World Liberty Financial delayed its Maldives resort token because of a war

Published

on

World Liberty hearing turns tense as OCC chief rejects pressure claim

The Iran conflict grounded flights, cratered Maldives tourism arrivals by double digits, and forced the Trump family’s crypto venture to shelve what was billed as the world’s first tokenized luxury hotel development. The episode exposes a structural question the real-world asset market has avoided: what happens to a token when the real world breaks?

Summary

  • World Liberty Financial and its partners postponed the MALD1 token sale, originally planned for spring 2026, after the Iran conflict disrupted air corridors serving the Maldives and cut tourist arrivals by as much as 41% in early March.
  • The token, structured through BlackRock-backed Securitize, would have given accredited investors a fixed yield plus a share of loan revenue from Trump International Hotel and Resort, Maldives, a 100-villa project developed by UK-listed Dar Global with a 2030 completion target.
  • WLFI has raised $550 million through governance token sales from more than 85,000 buyers, but the token has lost roughly 83% of its value from its September 2025 peak of $0.331, falling to approximately $0.055 by late July 2026.
  • The broader tokenized real-world asset market excluding stablecoins has grown to between $26 billion and $34 billion in 2026, yet tokenized real estate remains the segment with the slowest institutional adoption and the thinnest secondary trading.
  • Dar Global CEO Ziad El Chaar said the company “continues to review development and launch schedules for its global projects in line with market conditions, regulatory requirements and long-term strategic goals,” without setting a new date.

On February 19, 2026, World Liberty Financial announced one of the most ambitious experiments in real-world asset tokenization: a partnership with BlackRock-backed Securitize and London-listed developer Dar Global to tokenize loan revenue from a Trump-branded luxury resort in the Maldives. Six months later, no token has been sold, no new launch date has been set, and the project sits in indefinite limbo. The reason is not a smart-contract exploit or a regulatory crackdown. It is a war. This piece examines what the delay reveals about the fragility of tying digital tokens to physical assets in unstable regions, the broader track record of the venture behind the deal, and whether the growing RWA market has priced in the risks that the real world routinely delivers.

The deal that was supposed to make history

The Maldives token project was conceived as a first-of-its-kind offering. Unlike previous tokenization efforts that wrapped completed properties in digital securities, WLFI and its partners proposed tokenizing the development phase itself. The token, designated MALD1 on the Securitize platform, would represent interests in loan servicing revenue tied to construction financing for Trump International Hotel and Resort, Maldives.

Advertisement

Dar Global, a subsidiary of Saudi Arabia’s Dar Al Arkan Real Estate Development Company and listed on the London Stock Exchange, is building the resort on a private island roughly 25 minutes by speedboat from Male. Plans call for approximately 100 ultra-luxury beach and overwater villas designed to offer what Dar Global described as “the highest levels of privacy, exclusivity, and sophistication.” Completion is targeted for 2030. The Trump Organization is licensing its brand and hospitality management standards, marking the brand’s first property in the Maldives.

WLFI and Securitize handle the tokenization layer, issuing securities under Rule 506(c) of Regulation D for accredited U.S. investors and Regulation S for non-U.S. persons in offshore transactions. Securitize, which has handled tokenized fund issuances for BlackRock, Hamilton Lane, and Apollo Global, serves as the registered transfer agent and compliance engine for the offering.

Holders of MALD1 tokens would receive a fixed yield, a share of ongoing loan proceeds, and a cut upon any eventual sale of the underlying loan positions. The structure was carefully designed to offer economic exposure without conferring direct property ownership, sidestepping the legal complexities of cross-border real estate title transfer that have stalled earlier tokenization projects in multiple jurisdictions.

When the partnership was announced, Zachary Folkman, a WLFI co-founder, called it “a new model for how real-world value meets blockchain transparency.” The plan was to open sales to qualified investors by spring 2026. Spring came and went.

Advertisement

How a war grounded the token sale

The conflict between the United States, Israel, and Iran that escalated in early 2026 sent shockwaves far beyond the Middle East. Brent crude prices surged from around $70 to over $110 per barrel in March before settling into the $95 to $100 range, and global capital flows into risk assets slowed sharply. For the Maldives, the most immediate effect was the closure of key air corridors over the Gulf region. Airlines that route through the Persian Gulf, including major carriers from the Middle East and South Asia, suspended or rerouted flights, severing connectivity to the Indian Ocean archipelago that depends on air travel for virtually all of its tourist arrivals.

The numbers were stark. Tourist arrivals to the Maldives fell 23.4% in the first week of March 2026 compared with the same period in 2025, according to official data from the Maldives Ministry of Tourism. Average daily arrivals in early March dropped 41.5% compared with February averages. The Maldivian government projected a revenue shortfall of $80 million to $100 million if disruptions persisted for a single month, a serious figure for an economy where tourism accounts for more than 60% of foreign exchange receipts. Even as some viral claims of a 90% tourism collapse proved overstated, the real decline was severe enough to force the government to introduce new visa categories in an effort to attract visitors from unaffected regions.

For a token backed by loan revenue from a resort that does not yet exist, the implications were severe. Construction timelines depend on the movement of materials, labor, and capital through a region that was suddenly difficult to reach. Projected occupancy rates and revenue models, the very inputs that determine the value of MALD1’s yield, became unreliable. Selling a fixed-income token to accredited investors requires credible financial projections, and credible projections require a stable operating environment. No responsible issuer would price a yield curve against a tourism market in freefall.

Bloomberg reported on August 13 that the token sale had been indefinitely postponed, with sources attributing the delay directly to war-driven travel disruptions. Dar Global’s CEO, Ziad El Chaar, offered a carefully worded statement about reviewing schedules but provided no timeline for resumption. The absence of a target date is itself a signal: the company does not know when conditions will allow a credible offering.

Advertisement

WLFI’s track record under scrutiny

The Maldives delay does not exist in isolation. It arrives at a moment when World Liberty Financial’s broader trajectory has drawn increasing skepticism from investors, regulators, and industry analysts.

WLFI launched its governance token sale in October 2024, initially targeting $300 million by selling 20 billion tokens at $0.015 each. Early demand was anemic: only $11 million trickled in during the first phase, and the team slashed its target to $30 million. Then momentum shifted, driven in part by the political attention surrounding the Trump family’s involvement. A second tranche of 5 billion tokens at $0.05 each brought the total raise to $550 million from more than 85,000 participants.

The Trump family’s financial interest in the project is substantial. According to public disclosures, the family receives 75% of net proceeds from WLFI token sales. Trump himself is listed as “co-founder emeritus,” and his 2025 income from the venture was reported at roughly $800 million, making World Liberty Financial one of the most lucrative crypto ventures in history by founder returns.

But the token’s secondary market performance has been punishing. WLFI peaked at approximately $0.331 in September 2025 and then entered a sustained decline, falling to around $0.055 by late July 2026, a drop of roughly 83%. Public estimates indicate that WLFI holders have absorbed $674 million in combined realized and unrealized losses. In April 2026, Forbes reported that WLFI had borrowed $75 million on its own platform, prompting one analyst to warn investors not to become “exit liquidity.”

Advertisement

Governance disputes have compounded the price decline. In April 2026, Tron founder Justin Sun, one of WLFI’s largest individual investors with approximately $75 million in purchases, filed a federal lawsuit alleging that WLFI froze 540 million of his unlocked tokens and 2.4 billion locked tokens and excluded him from governance activities. Sun claimed the contract contained an undisclosed blacklist function that was never disclosed to investors. WLFI countersued in May, accusing Sun of defamation and alleging that he engaged in short selling to suppress the token price and made straw purchases on behalf of undisclosed third parties. The litigation remains unresolved, and the WLFI token fell 15% to a record low after Sun publicly accused the project of embedding a backdoor.

On the product side, WLFI’s USD1 stablecoin has been a notable success by supply metrics, reaching $5.3 billion in circulation by mid-2026. It became a settlement asset on Binance’s perpetual futures markets and was selected as the payment vehicle for Abu Dhabi investment firm MGX’s multibillion-dollar Binance stake. However, concentration risk is pronounced: Binance holds approximately 87% of all USD1 in circulation, raising questions about the stablecoin’s decentralization claims and its vulnerability to a single exchange relationship.

When tokenized assets meet physical reality

The Maldives delay crystallizes a category of risk that the RWA tokenization industry has largely discussed in theory but never confronted in practice. Tokenized U.S. Treasuries or money-market funds, the segments that dominate the current $26 billion to $34 billion RWA market, are backed by assets that exist as electronic entries in regulated custodial systems. They do not depend on weather, geography, or geopolitics. Their yields are predictable because the U.S. government’s capacity to service its debt is, for practical purposes, not affected by whether flights are operating over the Persian Gulf.

Advertisement

Tokenized real estate is fundamentally different. The underlying asset is immovable, jurisdiction-specific, and vulnerable to physical disruption. A resort in the Maldives faces cyclone risk, sea-level rise, political instability in the host country, and, as the current episode proves, conflict in adjacent regions that can sever the transportation links on which the entire business model depends.

The MALD1 token adds additional layers of abstraction. Investors do not own a share of the resort. They own a token representing a share of servicing income from loans used to finance the resort’s construction. If construction delays push the completion date past 2030, if occupancy projections prove optimistic in a region shaken by conflict, or if Dar Global encounters financial difficulties, the yield that makes MALD1 attractive could shrink or vanish entirely. The investor is three steps removed from the physical asset: token to loan servicing rights to loan to resort to tourist spending. Each link in that chain introduces its own failure mode.

This is not a hypothetical concern. The history of tokenized real estate is littered with projects that promised liquidity and delivered illiquidity. Industry analyses of the first wave of tokenization projects, roughly 2019 through 2023, identified three recurring failure modes: legal non-recognition of tokenized title, tiny investor pools restricted to accredited buyers with five-figure minimums, and the absence of market-making infrastructure to support secondary trading. Less than 10% of tokenized real estate projects from that era showed meaningful secondary market volume. Projects that prioritized speed over structural integrity during 2025 faced enforcement actions, platform shutdowns, and investor litigation, particularly when tokens moved to unverified wallets and triggered anti-money laundering investigations.

The MALD1 structure addresses some of these issues. Securitize is a regulated transfer agent with deep experience in compliance infrastructure. The loan-revenue model avoids the title-transfer problem. But no amount of structural engineering can hedge against a war that closes airspace and craters the tourism market on which the underlying asset depends.

Advertisement

The case for WLFI and tokenized hospitality

A fair analysis requires stating the opposing case at full strength. Proponents of the Maldives project, and of RWA tokenization more broadly, would argue that the delay is precisely what a responsible issuer should do. Launching a token sale into a disrupted market would expose investors to mispriced risk and potentially trigger regulatory scrutiny. By waiting, WLFI and Securitize are protecting investors, not failing them.

There is also a structural argument. Deloitte projects that tokenized real estate will reach $4 trillion in value by 2035, implying a 27% compound annual growth rate. If that projection holds, first movers in luxury hospitality tokenization will have secured a durable competitive advantage. The Maldives project, precisely because it tokenizes the development phase, offers investors exposure to the highest-growth period of a real estate asset’s lifecycle, when value appreciation is steepest.

The broader WLFI ecosystem, despite its token price decline, has delivered real products. USD1 is one of the largest stablecoins in circulation. The subsidiary WLTC Holdings applied in January 2026 for an OCC national trust bank charter covering stablecoin issuance, redemption, and custody. If approved, it would give WLFI a regulated banking entity, a significant competitive moat that few crypto-native ventures can match.

Advertisement

Regional peers offer precedent for optimism. The Dubai Land Department launched a controlled tokenization pilot in February 2026 that explicitly tests governance, investor protection, and operational readiness for secondary market resale. Saudi Arabia’s Open World launched the country’s first licensed RWA Tokenization Center of Excellence in Al Khobar in January 2026, targeting energy, real estate, and carbon credits. The institutional infrastructure is being built, even if the Maldives project is temporarily sidelined.

What would invalidate the bearish thesis? If the Iran conflict resolves or de-escalates enough to restore Maldives air connectivity, if Dar Global delivers construction milestones on schedule, if the MALD1 token launches with strong investor demand and develops meaningful secondary trading, and if WLFI’s governance disputes with Justin Sun reach a resolution that restores market confidence, then the delay will look like prudent risk management rather than a structural flaw. Each of these conditions is plausible. Whether they are probable is a different question.

The SEC’s parallel pause

The MALD1 delay coincides with a related regulatory development that compounds uncertainty for the entire tokenization sector. On August 13, the same day Bloomberg reported the Maldives postponement, CoinDesk reported that the U.S. Securities and Exchange Commission would again delay its proposed “innovation exemption” for tokenized securities.

The exemption, first floated in late 2025, would have created a streamlined regulatory pathway for tokenized real-world assets, potentially reducing compliance costs and accelerating time-to-market for offerings like MALD1. Its repeated delays reflect unresolved tensions between the White House, which has publicly supported crypto innovation, and SEC staff, who have raised concerns about investor protection in tokenized offerings that blur the line between securities and commodities.

Advertisement

For WLFI, the regulatory uncertainty is particularly acute. The project exists at the intersection of presidential politics, family financial interests, and securities law. Any tokenized offering associated with the sitting president’s family will receive heightened scrutiny from regulators, regardless of the formal recusal arrangements in place. The SEC’s reluctance to finalize the innovation exemption suggests that the regulatory environment for complex tokenized offerings remains unsettled, adding another variable to the MALD1 relaunch calculus.

The tangibility paradox

Most coverage of the WLFI Maldives delay focuses on either the political angle (another Trump crypto controversy) or the market angle (RWA tokenization faces headwinds). Both framings miss the deeper structural lesson that no competitor has articulated clearly.

The Maldives token exposes a paradox at the heart of real-world asset tokenization. The entire value proposition of RWA tokens is that they connect blockchain efficiency to tangible, physical value. But the more tangible the asset, the more exposed the token becomes to forces that no smart contract can mitigate. A tokenized Treasury bill is safe precisely because it is abstract, an electronic claim on the full faith and credit of the U.S. government. A tokenized resort in the Indian Ocean is vulnerable precisely because it is real, a collection of villas on a low-lying island in a geopolitically sensitive region, reachable only by air routes that can be shut down by events thousands of kilometers away.

This paradox does not mean real estate tokenization is unworkable. It means the market needs to develop pricing models that account for geopolitical risk, supply-chain disruption, climate vulnerability, and the correlation between these factors and the revenue streams that back tokenized securities. Current models, borrowed largely from traditional real estate finance, do not adequately capture these compounding risks because traditional real estate finance does not typically involve selling fractional interests in development-phase loans on assets in conflict-adjacent zones to a global investor base via blockchain rails.

Advertisement

The WLFI Maldives case may ultimately become a case study in how the industry matures. If it prompts issuers, platforms, and regulators to build better risk frameworks for location-dependent tokenized assets, the delay will have served a purpose beyond its immediate commercial impact. If it is treated as an isolated incident and the market moves on without structural adjustment, the next disruption will deliver the same lesson at higher cost.

What to watch

– **Maldives air traffic recovery**: Monthly tourist arrival data from the Maldives Ministry of Tourism will signal whether the travel disruption that prompted the delay is easing or persisting.

– **MALD1 relaunch timeline**: Any announcement from WLFI, Securitize, or Dar Global about a new launch date or revised offering terms will indicate whether the project remains commercially viable.

Advertisement

– **SEC innovation exemption status**: The next scheduled review of the tokenization exemption, expected in Q4 2026, will determine the regulatory runway for offerings like MALD1.

– **WLFI governance litigation resolution**: The outcome of the Sun v. WLFI and WLFI v. Sun lawsuits will shape investor confidence in the project’s governance structure and management credibility.

– **Dar Global construction milestones**: Quarterly updates from Dar Global on the physical progress of Trump International Hotel and Resort, Maldives, will test whether the 2030 completion target remains achievable.

Advertisement

What is the MALD1 token?

MALD1 is a tokenized security issued through Securitize that represents a share of loan servicing revenue tied to the construction financing of Trump International Hotel and Resort, Maldives. It offers a fixed yield plus a share of ongoing loan proceeds, and it is available only to accredited investors under U.S. Regulation D and Regulation S exemptions.

Why was the Maldives token sale delayed?

The token sale, originally planned for spring 2026, was postponed because the Iran conflict disrupted air corridors serving the Maldives, causing tourist arrivals to drop by as much as 41% in early March. The disruption undermined the revenue projections that underpin the token’s value proposition, and no responsible issuer would launch into those conditions.

How much has WLFI raised from token sales?

World Liberty Financial raised approximately $550 million through its governance token sale, which concluded in early 2025 with more than 85,000 participants. The initial tranche sold 20 billion tokens at $0.015 each, and a second tranche sold 5 billion tokens at $0.05 each. The Trump family receives 75% of net proceeds from these sales.

What is USD1 and how large is it?

USD1 is a stablecoin issued by World Liberty Financial, pegged 1:1 to the U.S. dollar and backed by short-term Treasuries and cash equivalents. It reached a circulating supply of approximately $5.3 billion by mid-2026, making it one of the largest stablecoins in circulation, though Binance holds roughly 87% of total supply.

Advertisement

What are the main challenges facing tokenized real estate?

Tokenized real estate faces liquidity risk from thin secondary markets, legal risk from jurisdictions that do not recognize tokenized title, geopolitical risk when assets are located in unstable or conflict-adjacent regions, and structural risk when tokens represent indirect claims such as loan revenue rather than direct ownership. Less than 10% of first-wave tokenized real estate projects showed meaningful secondary trading volume.

Who is building the Maldives resort?

Dar Global, a London-listed subsidiary of Saudi Arabia’s Dar Al Arkan Real Estate Development Company, is the developer. The Trump Organization is licensing its brand and hospitality management standards. The resort is planned to feature approximately 100 ultra-luxury beach and overwater villas on a private island near Male, with completion targeted for 2030.

What happened in the Justin Sun lawsuit against WLFI?

In April 2026, Tron founder Justin Sun sued WLFI in federal court, alleging that the project froze approximately 540 million of his unlocked tokens and 2.4 billion locked tokens and excluded him from governance without disclosure. WLFI countersued in May, accusing Sun of defamation and market manipulation through short selling. Both cases remain pending.

Is the MALD1 token a good investment?

The MALD1 token has not yet been sold, so there is no market price or performance data to evaluate. Any future offering will carry significant risks, including construction delays, geopolitical disruption, regulatory uncertainty, and the governance challenges that have affected WLFI’s broader token ecosystem. Prospective investors should review the private placement memorandum and consult qualified financial and legal advisors before committing capital. This is educational analysis, not investment advice. *Disclaimer: This article was published on August 14, 2026. It is intended for educational and informational purposes only and does not constitute financial, investment, or legal advice. The author and publisher do not hold positions in any tokens or securities mentioned. Readers should conduct their own research and consult qualified professionals before making investment decisions.*

Advertisement

Source link

Continue Reading

Crypto World

Bitcoin Red Team flags 7,958 issues after Kimi K3 scan

Published

on

PlanC Flags $75K–$80K as Potential Bitcoin Cycle Bottom

Bitcoin Red Team has expanded its AI-assisted security review to 501 Bitcoin-related open-source projects, logging 7,958 findings in its latest detailed tally after 108 hours of work. 

Summary

  • Bitcoin Red Team scanned 501 projects and logged 7,958 findings after 108 hours of reviews.
  • Researchers classified 1,280 findings as high or critical, but many still require human verification today.
  • About 24.7% of findings had reproducible proofs, while 29.4% were reported upstream to project maintainers.
  • Kimi K3 became the campaign’s primary AI workhorse as researchers tested Bitcoin open-source software extensively.
  • BTCPay Server released fixes after Bitcoin Red Team and independent researchers reported security vulnerabilities recently.

Calle, a pseudonymous Bitcoin developer involved in the effort, said on Aug. 13 that the team has now completed a basic scan of almost the entire Bitcoin open-source ecosystem and that much of the easier-to-find vulnerability surface has already been examined.

The headline numbers require an important distinction. The 7,958 findings do not represent 7,958 confirmed exploitable vulnerabilities. The team classified 1,280 as high or critical, while 24.7% of all findings had been dynamically reproduced and 29.4% had been reported upstream at the 108-hour mark. Maintainer review and human reproduction remain part of the verification process.

Advertisement

Kimi K3 has become a security force multiplier

Calle said two weeks of work with Moonshot AI’s Kimi K3 exposed how quickly modern models can examine years of accumulated open-source code. He described the situation as a “massive collision” between older software and frontier AI, adding “everything is broken, bitcoin is burning.” The wording is his characterization and should not be read as evidence that Bitcoin Core or every Bitcoin project is compromised.

Independent testing supports the narrower point that Kimi K3 has meaningful cybersecurity capability. A joint U.K. AI Security Institute and U.S. CAISI assessment found the model outperformed GLM-5.2 on exploit-development testing but remained behind the strongest U.S. closed models. Kimi K3 scored 32% on ExploitBench and reached arbitrary code execution on zero of 41 samples in that test.

Bitcoin Red Team’s earlier sweep found 4,962 potential issues across 390 Bitcoin projects, including 720 then classified as high or critical. The newer tally shows the review expanded materially after that first wave.

Advertisement

Maintainers are already validating and patching findings

The campaign has moved beyond automated scanning. BTCPay Server’s official GitHub release credited Bitcoin Red Team researchers Bruno Garcia and Ben Carman with reporting a critical vulnerability that was already being exploited. Version 2.4.2 fixed a two-factor authentication bypass affecting Greenfield Basic Authentication.

BTCPay later confirmed that attackers had obtained LND admin macaroon credentials from affected installations and used them to access connected Lightning wallets. The project said it was processing additional reports from Bitcoin Red Team, Project Loupe, Magic Grants and independent researchers while strengthening its scanning and review processes.

On Aug. 14, BTCPay announced another security-focused release candidate, v2.4.3-rc4, addressing vulnerabilities reported by those groups. In related coverage, BTCPay supporters backed a recovery bounty after the earlier exploit and the foundation pledged 0.21 BTC to the Bitcoin Red Team fund.

Those fixes give concrete evidence that maintainers are validating at least some serious Red Team reports. They do not validate every item in the 7,958-finding dataset. AI-assisted audits can produce false positives, duplicate reports and severity assessments that change after manual investigation, making verification central to interpreting the numbers.

Advertisement

Bitcoin projects face a faster security cycle

Calle argued that unmaintained projects should now be treated with greater caution because AI has sharply lowered the cost of finding and testing weaknesses. He also said response time is becoming a useful indicator of project health and that maintainers will increasingly need their own continuing AI audit pipelines rather than occasional external reviews. Those are Calle’s conclusions from the campaign rather than universal security rules.

The wider ecosystem is already moving in that direction. OpenSats has created a fast-tracked red-teaming grant route focused partly on reimbursing researchers for LLM costs. More than 40 Bitcoin and digital-asset organizations have also asked leading AI laboratories to give vetted open-source defenders controlled access to frontier models.

As crypto.news reported, the industry coalition warned Bitcoin developers could fall behind attackers without access to advanced AI models. The request does not seek unrestricted access. It proposes vetted researchers, secure environments, sufficient compute and direct communication channels with AI security teams.

The next phase is likely to move more slowly than the initial sweep. Automated discovery can scale quickly, while reproduction, responsible disclosure, patch development and regression testing require more time. Projects receiving reports must determine which findings are exploitable, how urgently users need updates and when technical details can safely become public.

Advertisement

For Bitcoin users, the takeaway is narrower than the largest numbers suggest. The Red Team has reported a large volume of potential weaknesses across Bitcoin-related software, not evidence that Bitcoin’s base consensus protocol has failed. The immediate security concern centers on wallets, Lightning infrastructure, payment software and libraries carrying older or lightly reviewed code.

Source link

Advertisement
Continue Reading

Crypto World

Ethereum study flags 65,340 risky addresses tied to $574.8M

Published

on

Ethereum proposal could end staking rewards at 50%

A USENIX Security ’26 study has identified 65,340 high-risk address instances across Ethereum and BNB Smart Chain, linking them to 126,982.94 ETH and 17,726.7 BNB in native-token losses. 

Summary

  • Researchers identified 65,340 high-risk address instances across Ethereum and BNB Chain in their large-scale study.
  • Estimated losses reached 126,982.94 ETH and 17,726.7 BNB, valued by researchers above $574.8 million overall.
  • Researchers extracted 16.3 million private keys from 63,004 GitHub repositories for their cross-chain analysis dataset.
  • Their detection framework achieved 99.11% precision after manual sampling validation across both analyzed blockchain networks.
  • Two newly described attack vectors exploited deterministic contract addresses and EIP-7702 delegated account control mechanisms.

The paper, presented at the 35th USENIX Security Symposium in Baltimore, estimates their dollar value at more than $574.8 million.

The dollar figure needs context. The researchers say they valued the token losses using reference prices of $4,408 per ETH and $847 per BNB rather than prices at the time of every transaction. They describe their findings as a conservative lower bound” because the analysis covers only native ETH and BNB on the two networks and may miss less obvious cases.

Advertisement

Ethereum address misuse spans contract and private-key risks

The researchers divide “Address Misuse” into two categories. Contract Account misuse happens when users treat an address without deployed contract code as a contract address, often because the same address is used in another network context. The study identified 49,344 such instances, associated with losses of 22,738.41 ETH and 8,681.41 BNB.

Advertisement

Externally Owned Account misuse involves addresses whose private keys are exposed or show strong onchain signs of compromised control. Researchers identified 15,996 EOA misuse instances associated with 104,244.53 ETH and 9,045.29 BNB in losses. More than 95% of EOA misuse losses came from the GitHub exposed-key subtype.

Two new attack paths account for about $15.7M

The first newly described attack takes advantage of deterministic contract-address creation. Attackers can promote a contract address on a testnet, wait for users to mistakenly send mainnet funds to the matching no-code address, and later deploy withdrawal code at the same location. Researchers linked 469 malicious contracts to 3,446.37 ETH and 431.79 BNB in losses.

The second uses EIP-7702 against accounts with already exposed private keys. Attackers delegate those EOAs to malicious code that automatically sweeps incoming funds. The paper found 17,270 cases, producing losses of 25.86 ETH and 33.45 BNB. Using the paper’s reference prices, the two newly described vectors together account for roughly $15.7 million.

The 99.11% figure is precision, not universal verification

The team mined 63,004 GitHub repositories created between January 2015 and May 2025, extracting 10.3 million unique candidate addresses and 16.3 million private keys after deduplication. It also used Ethereum Stack Exchange and Stack Overflow data before analyzing transactions on Ethereum and BNB Smart Chain.

Advertisement

Researchers manually sampled results and reported 99.11% overall detection precision. That does not mean every one of the 65,340 instances was individually manually verified. The authors acknowledge possible heuristic false positives and incomplete data, while ERC-20, NFT and other chains are excluded from the headline loss calculation.

EIP-7702 security concerns are widening

Ethereum’s official guidance warns that malicious EIP-7702 delegation can give hostile contract code control over assets. A separate USENIX Security ’26 study found more than 63% of analyzed EIP-7702 authorization transactions were associated with malicious EOA-targeted attacks, identifying 924 malicious contract accounts across seven supported chains.

As previously reported, EIP-7702 delegations were linked to automated wallet-draining activity after Ethereum’s Pectra upgrade. In related coverage, attackers later drained about $3.1 million from Polymarket users through phishing and malicious delegated execution.

The authors recommend wallet warnings for known exposed keys and cross-chain contract mismatches, stronger secret management for developers and clearer address-to-network documentation. They also propose considering chain identifiers in future contract-address derivation. Those are research recommendations, not adopted Ethereum or BNB Chain protocol changes.

Advertisement

The researchers plan to expand future work to additional chains and token types. Until then, the 126,982.94 ETH and 17,726.7 BNB totals are best read as measured native-token losses within the study’s defined scope, while $574.8 million remains a standardized valuation estimate.

Source link

Advertisement
Continue Reading

Crypto World

CFTC sets Aug. 20 crypto talks as CLARITY vote waits

Published

on

CFTC scraps no deny rule as crypto enforcement shift deepens

The Commodity Futures Trading Commission will use its inaugural Innovation Advisory Committee meeting on Aug. 20 to examine crypto regulation, artificial intelligence and prediction markets as Congress delays action on a broader digital asset market structure bill. 

Summary

  • CFTC advisers will discuss crypto regulation on August 20 as Congress delays market structure legislation.
  • The agenda includes using existing statutory authority while complementing future congressional legislation on digital assets.
  • Senate cloture on the CLARITY Act’s motion to proceed is scheduled to ripen September 15.
  • SEC canceled its August 14 crypto offering meeting and has not announced a replacement date.
  • Michael Selig currently serves as the CFTC’s sole commissioner despite the agency’s statutory five-seat structure.

The three-hour meeting begins at 1 p.m. ET in Washington and will be streamed publicly, according to the CFTC release.

The timing gives the meeting a sharper policy role than a routine technology discussion. The CFTC agenda explicitly lists “opportunities to modernize existing rules using current statutory authority” and areas where regulatory action can “complement future congressional legislation.” However, the IAC is advisory. It will not vote on a crypto rule, and its recommendations do not automatically represent the Commission’s position.

Advertisement

CFTC crypto talks focus on what regulators can do now

The first 50-minute session, titled “Crypto’s Regulatory Evolution: From Uncertainty to Clarity,” will cover the lack of a comprehensive federal market structure framework, overlapping jurisdictions and recent regulatory efforts. It also lists cybersecurity, operational resilience and crypto infrastructure as areas needed for trusted markets.

That wording stops short of saying the CFTC will create the CLARITY Act through regulation. The agency can interpret and modernize rules within its existing authority, but Congress would be needed to change statutory jurisdiction more broadly. Earlier this year, the CFTC and SEC jointly issued an interpretation on how federal securities laws apply to crypto assets, showing how the agencies can provide guidance without waiting for a new statute.

Advertisement

As previously reported, the CFTC’s first Innovation Advisory Committee meeting will cover crypto, AI and prediction markets, but no proposed crypto rule is scheduled for a vote at the session.

CLARITY Act now faces a September 15 Senate test

The Digital Asset Market Clarity Act has not failed. Majority Leader John Thune filed cloture on the motion to proceed before the Senate left Washington. The Senate schedule says that motion will ripen at 2:15 p.m. on Sept. 15, one day after senators return for regular business.

As previously reported, the CLARITY Act faces a September 15 procedural vote and still needs enough support to clear the Senate’s 60-vote cloture threshold. Even successful cloture would only move the chamber toward considering the bill. Debate, amendments and a final vote would still follow, while any Senate text differing from the House version would require further congressional action.

SEC cancels its planned August 14 crypto meeting

The latest update changes the earlier narrative that the CFTC would follow an SEC meeting on new crypto offering rules. The SEC had scheduled an Aug. 14 open meeting to consider proposing a tailored offering regime for certain investment contracts involving crypto assets. On Aug. 13, however, the Commission formally canceled that meeting.

Advertisement

The SEC’s notice gave no reason and announced no replacement date. As previously reported, the planned session would have considered tailored rules for crypto investment contract offerings. Its cancellation does not withdraw the SEC’s wider crypto agenda, but no proposal will be considered at the previously scheduled Friday meeting.

What happens next for U.S. crypto regulation

The CFTC meeting remains scheduled for Aug. 20. Its crypto session will be followed by discussions on AI and prediction markets, including market surveillance, manipulation concerns and federal versus state jurisdiction. Members of the public can submit written comments through Aug. 27.

Chairman Michael Selig currently sits alone on a Commission designed for five commissioners, according to the CFTC’s official leadership page. The agency therefore lacks the bipartisan panel contemplated by its normal five-seat structure while major crypto and prediction-market policies are being developed.

The next concrete dates are Aug. 20 for the IAC discussion, Aug. 27 for comments and Sept. 15 for the CLARITY cloture test. The CFTC’s existing authority over crypto remains narrower than the framework Congress is considering. The Aug. 20 meeting can shape agency priorities, but it cannot substitute for legislation that changes the agencies’ statutory powers.

Advertisement

Source link

Advertisement
Continue Reading

Crypto World

FG Nexus exits ETH treasury after $45.2M loss

Published

on

Ethereum Foundation begins staking 70,000 ETH from treasury

FG Nexus sold all of its digital assets before June 30, ending an Ethereum treasury strategy less than a year after it launched. 

Summary

  • FG Nexus sold all digital assets before June 30, ending its Ethereum treasury strategy entirely.
  • First-half digital asset operations lost $45.207 million while staking generated only $144,000 in total revenue.
  • ETH sales generated $60.956 million cash, with another $14.983 million receivable fully collected during July.
  • FG Nexus had peaked at 50,770 ETH in September 2025 before beginning its treasury unwind.
  • Management plans to redirect capital toward manufactured housing, though no definitive FG Communities deal exists.

The Nasdaq-listed company disclosed the completed exit in its Aug. 12 filing, which reclassified the digital asset business as discontinued operations.

The filing shows that FG Nexus received $60.956 million in cash from ETH sales during the first half of 2026. A further $14.983 million remained receivable at June 30 and was collected in July. The company held no cryptocurrency at quarter end.

Advertisement

FG Nexus records $45.2M loss from digital asset exit

FG Nexus reported a $45.207 million loss from its discontinued digital asset operations for the first six months of 2026. The total included a $41.167 million loss on ETH digital assets, a $2.793 million impairment on digital intangible assets and $1.789 million in general and administrative expenses.

Those figures matter because the $45.207 million should not be described as the realized loss from selling ETH alone. The business also recorded a $398,000 gain on digital intangible assets and only $144,000 of staking revenue. Its broader consolidated net loss for the first half reached $56.928 million.

In addition, FG Nexus announced its Ethereum treasury strategy in July 2025 and said its digital asset business began in August. By Sept. 28, the company reported holding 50,770 ETH, valued at about $207 million using its reference price at the time, with an average purchase price near $3,860.

As previously reported, FG Nexus raised $200 million while making Ethereum its primary treasury asset, with plans to generate returns through staking and other Ethereum opportunities. By June, however, the company was unwinding that position. Crypto.news later reported that FG Nexus moved another 10,000 ETH as its treasury losses widened.

Cash from ETH sales is being redirected toward real estate

FG Nexus announced on July 1 that its board had authorized management to exit digital assets and create a real estate operating subsidiary focused mainly on land lease manufactured housing properties. CEO Kyle Cerminara said the company intended to “reallocate all of our capital from digital assets to cash flow producing real estate over the near term.” That remains a forward-looking company plan.

Advertisement

The company is also considering a potential combination with FG Communities, but the quarterly filing says board discussions remain preliminary and no decision or definitive agreement has been reached. An independent special committee is reviewing the potential transaction and has retained a financial adviser to provide a fairness opinion.

The ETH liquidation has increased available cash. FG Nexus reported $24.9 million of cash and equivalents at June 30. After receiving the ETH sale receivable and $15.5 million from the redemption of FG Merger II shares, cash reached approximately $51.4 million by July 31.

What happens next for FG Nexus

The next test is whether FG Nexus can turn that liquidity into income-producing property assets. The company has not announced a definitive FG Communities transaction or disclosed completed acquisitions under the new manufactured housing strategy. Its existing Quebec property also remains held and used after an earlier nonbinding sale proposal became unlikely to close.

FGNX traded at $7.59 on Aug. 13, up about 8.9% from the previous close. The company had already announced its crypto exit on July 1, however, so the move cannot be attributed solely to the later quarterly disclosure.

Advertisement

The reversal closes a short corporate Ethereum experiment that once aimed to make FG Nexus a major ETH holder. It also shows the financial tradeoff in this particular treasury strategy: first-half staking generated $144,000, while the discontinued digital asset operation recorded a $45.207 million loss.

Source link

Advertisement
Continue Reading

Crypto World

Gemini posts $107.7M Q2 loss as spot volume drops 66%

Published

on

Gemini posts $107.7M Q2 loss as spot volume drops 66%

Gemini Space Station reported a $107.7 million net loss for the second quarter ended June 30, extending its run to four consecutive quarterly losses since its September 2025 Nasdaq listing. 

Summary

  • Gemini reported a $107.7 million Q2 net loss, its fourth consecutive quarterly loss since IPO.
  • Total revenue rose 37% year over year to $45.5 million, led by expanding services revenue.
  • Spot trading volume fell 66% year over year to $3.8 billion amid weaker crypto markets.
  • Credit card revenue jumped 231% to $16.2 million while total transaction losses reached $20.1 million.
  • Assets on platform declined 54% to $8.4 billion, reflecting valuations and select institutional custody outflows.

Revenue rose 37% year over year to $45.5 million, but the exchange’s core spot trading business weakened sharply as total volume fell to $3.8 billion from $11.3 billion a year earlier.

The company’s Aug. 13 SEC filing showed the loss narrowed 19% from $133.2 million in Q2 2025. Gemini’s operating loss was $76.9 million, improving 18% from the first quarter, while operating expenses declined 15% sequentially to $122.4 million. The reduction followed February workforce cuts and exits from several international markets.

Advertisement

Gemini Q2 revenue grew as exchange trading contracted

Transaction revenue declined 15% year over year to $17.8 million. Exchange revenue fell 38% to $12.5 million as retail and institutional activity slowed. Retail spot volume dropped 53% to $700 million, while institutional volume fell 68% to $3.1 billion.

The weaker exchange business was partly offset by other activities. Services revenue rose 149% to $23.5 million. Credit card revenue jumped 231% to $16.2 million, staking revenue increased 50% to $4 million, and over the counter revenue rose to $4.7 million from $611,000. Gemini’s first quarter results had already shown a growing reliance on credit cards and other non exchange products, as crypto.news reported.

Credit losses and crypto marks kept the loss elevated

The company recorded $20.1 million in transaction losses, up from $3.6 million a year earlier. The total included a $16.1 million provision for expected credit losses on its credit card portfolio. Gemini said about $10 million of the Q2 provision related to accounts originated during the first quarter and associated with identified fraud activity.

The company said it added fraud detection and account monitoring controls. Management said the elevated provision was concentrated in the affected cohort and “does not reflect broad based deterioration” in the credit portfolio. That remains Gemini management’s assessment. Separately, the company recorded a $60.7 million realized and unrealized loss on crypto assets and receivables, partly offset by a $35.7 million gain on related party crypto loans.

Advertisement

Gemini pushes stocks and prediction markets as assets fall

Assets on Gemini’s platform fell 54% year over year to $8.4 billion from $18.2 billion. The company attributed the decline to lower crypto valuations and select institutional custody outflows. Monthly transacting users rose 11% to 580,000 from a year earlier, although the figure slipped 2% from the first quarter.

The company is trying to reduce its dependence on spot crypto fees. Prediction markets generated $524,000 in Q2 revenue, while event contracts traded increased 93% from the first quarter and cumulative contracts surpassed 225 million. The company also launched commission free stock trading for eligible U.S. customers in July, expanding its push beyond crypto trading, as crypto.news reported.

What happens next for Gemini

The company’s U.S. expansion is supported by regulated derivatives infrastructure. The CFTC lists Gemini Titan as a designated contract market, while its registry shows Gemini Olympus became a registered derivatives clearing organization on April 29. Gemini said its clearinghouse went live on Aug. 4, allowing it to settle its own prediction contracts and explore additional U.S. derivatives products.

Management is scheduled to discuss the quarter on an earnings call at 8:30 a.m. ET on Aug. 14. Investors will be watching whether services growth can offset weaker spot trading and whether credit losses normalize. The company also remains a defendant in an investor class action over its IPO disclosures and strategy shift. The federal docket shows the case remains active.

Advertisement

Source link

Advertisement
Continue Reading

Crypto World

JPMorgan ended Polymarket banking relationship in 2025

Published

on

Morgan Stanley taps Galaxy to offer crypto-backed access to Bitcoin ETF products

JPMorgan Chase ended its banking relationship with prediction market Polymarket in October 2025 over regulatory concerns and told the company to find another bank, the Financial Times reported on Aug. 14. 

Summary

  • JPMorgan ended Polymarket’s banking relationship in October 2025 and directed it toward another banking partner.
  • Polymarket has since moved to another bank while retaining other commercial relationships with JPMorgan entities.
  • JPMorgan invited CEO Shayne Coplan to a February conference and reportedly seeks potential IPO underwriting.
  • Polymarket is reportedly seeking roughly $1 billion at a valuation exceeding $20 billion from investors.
  • Polymarket’s U.S. exchange operates through CFTC designated QCX while federal and state regulatory disputes continue.

Polymarket has since moved to an unidentified banking partner.

The account closure did not end all business between the companies. Polymarket told the FT it maintains “a close, active relationship with JPMorgan across multiple entities, operational integrations and material handling of customer fund flows.” JPMorgan declined to comment. The company’s description of the remaining relationship has not been independently detailed publicly.

Advertisement

JPMorgan’s exit came during Polymarket’s U.S. transition

The timing matters because Polymarket was still rebuilding its U.S. regulatory position. The CFTC order in January 2022 required Blockratize, the company behind Polymarket, to pay a $1.4 million civil penalty and wind down markets that did not comply with federal derivatives law.

By October 2025, the company had acquired QCX and QC Clearing and secured a CFTC staff letter granting narrow no action relief on certain reporting and recordkeeping requirements. The CFTC registry currently lists QCX LLC, doing business as Polymarket US, as a designated contract market. The Commission amended its designation in November to permit futures commission merchant intermediation.

Polymarket still faces regulatory and legal scrutiny

The regulatory picture remains unsettled. The FT reported in June that the CFTC had opened another investigation into Polymarket, citing a person familiar with the matter. The regulator had not publicly confirmed the investigation, and both the CFTC and Polymarket declined to comment on its focus.

Advertisement

XState and local scrutiny has also continued. In related coverage, Polymarket US and Kalshi won preliminary relief against Minnesota’s prediction market ban on July 27. The federal court stressed that its preliminary injunction was not a final determination on the merits. On Aug. 12, the New York City Council also announced an inquiry into prediction market marketing and requested information from Polymarket and three other platforms.

JPMorgan kept other ties despite closing the account

The FT reported that JPMorgan invited Polymarket CEO Shayne Coplan to speak at a private banking conference in Miami in February. The bank is also reportedly interested in an underwriting role if Polymarket eventually pursues an initial public offering. No public IPO filing has been announced.

The continuing relationship makes the episode more complex than a complete corporate break. It also comes during a wider U.S. debate over debanking. The Office of the Comptroller of the Currency said in its December review that it examined nine large national banks, including JPMorgan, and found policies at each that restricted some lawful industries or subjected them to escalated reviews. The OCC said its broader work remains ongoing.

Funding talks could value Polymarket above $20 billion

Polymarket is separately in early talks to raise roughly $1 billion at a valuation above $20 billion, Reuters reported on Aug. 4, citing Bloomberg. Reuters said it could not independently verify the report, while Polymarket did not respond to its request for comment. The figures therefore remain reported targets rather than a completed financing.

Advertisement

As crypto.news previously reported, the platform’s reported $1 billion fundraising talks could value it above $20 billion. ICE, the New York Stock Exchange parent, initially invested $1 billion in October 2025 and announced another $600 million direct investment on March 27, 2026.

What happens next for Polymarket

Polymarket’s immediate regulatory path will depend partly on the reported CFTC investigation and continuing state cases. The Minnesota injunction currently protects its federally regulated exchange from that state’s ban, but the litigation over federal derivatives authority and state gambling powers has not reached a final ruling.

Its capital markets plans are less certain. JPMorgan’s reported interest in future underwriting does not establish that an IPO will happen, and no public registration statement has been identified. The proposed $1 billion fundraising round also remains under discussion. Formal company announcements or securities filings would provide the next verifiable milestones.

Advertisement

Source link

Continue Reading

Crypto World

Bitcoin’s Bottom Has a Date: And It’s Closer Than You Think

Published

on

Ever since bitcoin started to lose value rapidly and consistently in Q4 last year, the main question within the cryptocurrency community is how low it can go. The next one was: when and where it will bottom out.

Analysts began speculating after each leg down. At first, it was $60,000 when BTC dipped to that level in February. Months later, though, it crashed to $59,000, $58,000, and even slightly below that on July 1. As such, the bottom figures have slightly changed. Now, popular analyst Rekt Fencer brought some historical figures to outline the exact date.

October 2026: Here We Go

In an August 13 tweet, the market commentator outlined that there are 53 days left (now 51 since two days have already passed) until this market slumber and sluggishness end. They based this prediction on previous BTC cycles, as bull markets lasted approximately 1,064 days, while the subsequent bear phases required roughly 364 days to find their ultimate bottom. The pattern sounds simple, but it has been surprisingly consistent.

Bitcoin’s bull cycle from the 2015 bottom to its 2017 peak lasted exactly 1,064 days. The painful bear market needed another 364 days before the cryptocurrency finally bottomed in December 2018.

Advertisement

History almost perfectly repeated itself from that 2018 bottom to the November 2021 peak. Guess what: another 364-day decline followed that culminated in the 2022 bear-market low.

It gets better. BTC’s latest bull cycle ran from late 2022 until October 2025. Yes, another approximately 1,064 days. If the second half of this pattern repeats as accurately as the first, Rekt Fencer believes the next bottom will arrive on October 5, 2026.

October in Focus

The screenshot reshared by Rekt Fencer has been a popular one in the crypto community. The reason for this is its surprising accuracy. The previous two major BTC bear markets required approximately 363 and 376 days, respectively, to move from their cycle peaks to eventual capitulation lows.

Applying that range to Bitcoin’s October 2025 ATH produces a potential bottoming window between roughly October 4 and 17 this year. Ali Martinez recently outlined almost the same possibility, but his dates ranged between October 6 and 16.

There’s an obvious problem with relying too heavily on particular calendar patterns. BTC’s previous cycles developed under entirely different macroeconomic environments. Today’s market includes spot ETFs, enormous institutional holders, corporate treasuries, a different regulatory landscape, and far greater integration with TradFi.

Interest rates, liquidity, ETF flows, geopolitical developments, and Fed policy could easily break even the most accurate pattern. As such, October 5 (or 6-16) shouldn’t be treated as some predetermined date on which BTC is guaranteed to print its lowest candle before it explodes to new peaks within days, weeks, or even months.

Advertisement

But then again, it’s always good to have a North Star, and October 2026 has quickly become the month every crypto investor has circled on the calendar.

The post Bitcoin’s Bottom Has a Date: And It’s Closer Than You Think appeared first on CryptoPotato.

Source link

Advertisement
Continue Reading

Trending

Copyright © 2025