Connect with us

Crypto World

Inside the Fake Crypto Startup That Fooled North Korean IT Workers

Published

on

Inside the Fake Crypto Startup That Fooled North Korean IT Workers

It isn’t often that a reporter gets asked to pose as a venture capitalist to fool suspected North Korean IT workers.

But in June, I found myself joining a Zoom call as “Aelin Ashriver,” an investor from the fictitious Definitive Communications, to meet the development team of crypto startup Ballena Azul.

The IT workers on the call believed they were pitching for VC backing for their startup. In reality they had spent weeks working inside a fake crypto company set up purely to study their methods and infrastructure by Mauro Eldritch, founder of cybersecurity firm BCA LTD, and Heiner García, a cyber threat intelligence analyst at Telefónica Tech and founder of NorthScan.

Cointelegraph tagged along for one stage of the investigation.

Advertisement

During the call, I played up the ruse by suggesting I might even be able to land Ballena Azul some coverage in Cointelegraph.

So at least someone was telling the truth.

Suspected DPRK IT workers pitch for venture capital backing from the fictitious Definitive Communications, played by Cointelegraph. Source: ANY.RUN

Building a company for suspected North Korean IT workers

Eldritch and García built the fictitious Ballena Azul with infrastructure provided by cybersecurity platform ANY.RUN. An existing UK registration for an unrelated company of the same name, which was dissolved in 2022, added legitimacy to the project.

Eldritch assumed the identity of co-founder “Leonardo Nelson,” while García took on the alias “Andy Jones” and posed as the company’s team lead.

Advertisement

Related: North Korean cyber spies are no longer just remote threats

One of the most valuable pieces of intel that the five-week ruse exposed were the external servers the workers used as intermediary points before connecting to Ballena Azul’s controlled virtual desktops.

Exposed servers were particularly valuable because such infrastructure is often recycled across operations and can remain active for long periods.

García tells Magazine the servers were associated with malware families linked to North Korean campaigns that steal credentials, crypto wallet data and other sensitive information.

Advertisement

“Some of the servers we found were tied back to distributing InvisibleFerret and BeaverTail/OtterCookie in prior years and were active to this day,” he says.

But some others were totally new and had zero intelligence about them, looking clean and keeping outside of mainstream block lists or threat feeds.”

He adds that the infrastructure could serve multiple purposes, with servers previously used for malware distribution also acting as command-and-control infrastructure, and as proxies for operators carrying out their day-to-day work.

The suspected workers do not need to deploy malware to pose a threat, according to the researchers. Once hired, they can gain legitimate access to a company’s internal systems, source code and other sensitive information. The longer they remain undetected, the longer they can continue drawing salaries that researchers say ultimately help fund the North Korean regime.

The operation also showed the group relied on artificial intelligence tools to help compensate for gaps in their technical knowledge. They used ChatGPT for writing and coding, including to answer basic questions and complete assignments they struggled with themselves. They preferred Google Gemini for image alteration and document forgery.

Advertisement

A suspected DPRK IT worker and ChatGPT team up in an attempt to obtain testnet crypto during the Ballena Azul operation. Source: ANY.RUN

Other tools employed included remote desktop software, crypto wallets and a service for sharing two-factor authentication codes.

North Korean IT workers have become a growing cybersecurity threat to the cryptocurrency industry. Consensys said in July that it had engaged a North Korea-linked developer through a third-party service provider before identifying the threat and cutting off access.

In another case, US prosecutors charged four North Korean nationals in 2025 with using false identities to obtain remote IT jobs and allegedly stealing more than $900,000 in cryptocurrency from two companies, including a US blockchain research and development firm.

The US Treasury said in March that North Korean IT worker schemes generated nearly $800 million in 2024 to help fund the Pyongyang regime’s weapons-of-mass-destruction programs.

Advertisement

Inside fake crypto company Ballena Azul

The ruse began when García connected with a recruiter via GitHub, who had been linked to Famous Chollima, a threat group associated with North Korean IT worker operations.

García said that Ballena Azul needed to hire software developers and the recruiter offered up “Jack Anderson,” “Angelo Espree” and “Lucas Theo.” At least two of them presented US identification.

The trio were given various programming assignments inside controlled virtual desktop environments, which allowed García and Eldritch to observe how they worked.

Angelo Espree was one of the developers onboarded through a recruiter associated with DPRK operations. Source: ANY.RUN

The researchers also deliberately introduced technical problems, including selective network outages and disappearing mouse cursors, to see how the suspected workers reacted and which tools they turned to when things went wrong.

Advertisement

“Honestly, the biggest surprise was how much of it ran on improvisation,” García says. “There was no rigid playbook, no polished corporate process behind them.”

During their many weeks working inside the controlled environments, the suspected North Koreans left behind a treasure trove for the researchers, including chat logs, AI conversations, crypto wallet information, VPN exit nodes and hours of live video footage. Their connections also exposed the servers that became one of the investigation’s most valuable findings.

To be sure, the heavy AI reliance isn’t unique to the workers hoodwinked in Ballena Azul’s operation. 

Ballena Azul workers generally used AI as a crutch for coding and technical tasks they struggled with. Reuters reported Monday that another North Korean hacking group, Kimsuky, was using AI for a more offensive purpose. The group was reportedly running AI tools locally to help automate cyberattacks, analyze stolen data and produce more convincing phishing campaigns.

Advertisement

Evolving playbook of remote DPRK IT workers

This was not the first time Cointelegraph has played a minor role in exposing suspected North Korean workers.

In February 2025, García and Cointelegraph conducted a job interview for a suspected operative calling himself “Motoki.” The developer claimed to be Japanese but ragequit the interview after being asked to introduce himself in his mother tongue.

Still, García kept communicating with him. Motoki eventually offered to send García money to buy a computer that he could access remotely, allowing him to work through a local machine instead of connecting through a VPN to bypass restrictions used by employers and freelance platforms.

Related: From Sony to Bybit: How Lazarus Group became crypto’s supervillain

Advertisement

García later documented suspected North Korean operatives recruiting freelancers to provide verified accounts, identities and remote access to their computers. In one version of the scheme, operatives could work through machines physically located in the US, making them appear to employers and freelance platforms as US-based contractors.

In May, two US “laptop farmers” — people who hosted a cluster of computers that North Koreans could remotely access — were sentenced to 18 months in prison for helping DPRK IT workers pose as US-based employees in schemes that generated more than $1.2 million and affected nearly 70 companies.

Taking Ballena Azul down

All fake things must come to an end, so the researchers introduced “Benito Camella,” Ballena Azul’s co-founder, who had supposedly been focused on other business in Milan while the company expanded.

When he returned, Camella confronted the workers over discrepancies in their identities and documents. The confrontation quickly began to clear the chat room. Espree left the video call first, while Anderson stayed longer before realizing the scheme was unraveling.

Advertisement

“Are you living two lives, Mr. Anderson?” Camella asks Jack Anderson during the confrontation. Source: ANY.RUN

But the researchers kept the deception going even after the meeting ended. In the company’s Telegram channel, the “CEO” accused “Andy Jones” of bringing in “illegal workers” and putting the company at risk. “Jones” responded that he had been under pressure to build a team quickly and was not being paid enough to do it. He maintained that he had done the best he could with what he had.

The staged argument ended with the fake CEO terminating both their working relationship and friendship, keeping up the appearance that Ballena Azul had collapsed because of a disastrous hiring decision.

One of the suspected North Koreans later contacted García privately to apologize for what had happened and ask whether he was all right.

According to the researchers, they never heard from the rest of the group again.

Advertisement

To this day, they say, the suspected workers do not know they wasted weeks working inside an environment built to extract intelligence from them.

Magazine: Do the Coldcard attacks mean all hardware wallets are now insecure?

Editor’s note: Cointelegraph could not independently confirm the nationality or affiliation of the suspected DPRK IT workers, and no government agency has publicly identified them.

Cointelegraph publishes long-form journalism, analysis and narrative reporting produced by Cointelegraph’s in-house editorial team with subject-matter expertise. All articles are edited and reviewed by Cointelegraph editors in line with our editorial standards. Some articles contain affiliate links, from which Cointelegraph may earn a commission. These relationships do not influence which products we review or our editorial conclusions. Content published in here does not constitute financial, legal or investment advice. Readers should conduct their own research and consult qualified professionals where appropriate. Cointelegraph maintains full editorial independence.

Advertisement

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

U.S. CPI inflation slows to 3.4% as expected, bitcoin (BTC) holds near $64,000

Published

on

U.S. CPI inflation slows to 3.4% as expected, bitcoin (BTC) holds near $64,000

U.S. inflation in July was in line with expectations, leaving expectations for another Federal Reserve rate hike broadly unchanged.

The Consumer Price Index (CPI) rose 0.1% in July from the previous month, compared with economists’ forecast for a 0.1% increase and June’s 0.4% decline.

On a year-over-year basis, CPI rose 3.4%, in line with forecasts and slightly lower than June’s 3.5% reading.

Core CPI, which excludes food and energy, rose 0.2% month over month in July, compared with forecasts for a 0.2% increase and an unchanged reading in June. On a year-over-year basis, core CPI rose 2.5% as expected by analysts and edging lower from June’s 2.6%.

Advertisement

Bitcoin fell from $64,400 to $64,080 in a knee-jerk reaction before stabilizing, still largely flat over 24 hours. Nasdaq 100 futures traded 0.7% higher.

Treasury yields remained under pressure, maintaining pre-CPI weakness. The two-year hovered at 4.19%, down 3.6 basis points on the day, and the 10-year yield stood at 4.66%, also down three basis points.

Already a key data point for markets, July’s CPI report took on added importance after a weaker-than-expected U.S. employment report showed that the economy unexpectedly shed 23,000 jobs in July.

Source link

Advertisement
Continue Reading

Crypto World

Standard Chartered-led Anchorpoint launches Hong Kong dollar stablecoin

Published

on

CLARITY will strengthen dollar stablecoins, but Asia wins on yield: HashKey Research

Standard Chartered-led Anchorpoint Financial has started a limited rollout of HKDAP, its Hong Kong dollar-backed stablecoin, four months after securing one of the city’s first two issuer licences.

The initial rollout will focus on institutional payments and settlement before adding more access channels and cross-border applications.

HashKey Exchange and OSL Group joined as authorized distributors, allowing eligible institutions and professional investors to obtain HKDAP through their apps and other supported channels, according to separate announcements.

HashKey said it had completed its first minting and redemption transaction for the token, including conversions between HKDAP and fiat currency.

Advertisement

Anchorpoint, a joint venture between Standard Chartered, Animoca Brands and HKT, plans to use distributors and commercial partners to bring the token into payments, settlement and other financial applications. HKDAP stands for “Hong Kong dollar at par.”

Stablecoins are cryptocurrencies with values pegged to an external reference such as fiat currencies. Stablecoins are widely used to finance crypto trading, serve as a means of payment and facilitate cross‑border capital flows. The combined market cap of all stablecoins was nearly $287 billion as of this writing.

Source link

Advertisement
Continue Reading

Crypto World

Smart contract blockchain Solana nearly froze Wednesday, Marinade Finance says

Published

on

Smart contract blockchain Solana nearly froze Wednesday, Marinade Finance says

The latest issue started with a bad internet route from Teraswitch’s Miami facility that then spread to data centers across Europe and Asia, cutting off validators in London, Amsterdam, Frankfurt, Singapore and Tokyo. North America stayed online. The company fixed the issue in about 10 minutes, and traffic was flowing again by 4:16 a.m. UTC.

One single network operator, identified as AS2032, controlled more than a quarter of all the tokens people had locked up to secure the network, which was more than the Solana-prescribed safety limit. Almost all of those tokens went offline at the same time. Other companies lost another 14 million tokens in the same short period. Most of the affected validators, including the big one called Helius, stayed offline for the full 33 minutes because their backup systems never switched on.

This whole event is a clear warning: if more than one-third of the network’s tokens ever go offline at once, the entire blockchain freezes for every single person holding SOL, and there is no quick way to fix the bigger damage that would follow.

Source link

Advertisement
Continue Reading

Crypto World

Pi Network price gains 5% as CPI cools, upgrade passes

Published

on

Pi Network daily chart shows PI holding above its 20-day SMA at $0.0853 but below $0.096 resistance.

Pi Network price rose more than 5% toward $0.090 on Aug. 12 as the Protocol 26 deadline passed and softer U.S. inflation data supported speculative assets.

Summary

  • Pi Network price rose more than 5% before settling near $0.088 during the session.
  • Protocol 26’s Aug. 11 deadline required Mainnet node operators to update or lose connectivity.
  • PI remains above its 20-day moving average at $0.0853, but below the 50-day average.
  • A breakout above $0.096–$0.10 could open a path toward $0.12 and potentially $0.15.

Pi Network price action today

According to data from crypto.news, Pi Network (PI) price climbed more than 5% to approach $0.090 on Aug. 12, while trading activity reportedly increased by about 35%. PI traded near $0.0883 at the time of writing after giving back part of its intraday advance.

The move followed the Aug. 11 deadline for Mainnet node operators to complete the Protocol 26 upgrade. The Pi Core Team previously said nodes that missed the cutoff would lose Mainnet connectivity until they installed the required update.

Advertisement

No widespread network disruption had been reported by the time of writing. However, the team had not published figures showing how many operators completed the upgrade, making it difficult to confirm the participation rate across Pi Network’s node infrastructure.

Protocol 26 improves smart contract safety, state management, interoperability, and cryptographic functions. The upgrade is also intended to prepare the network for Protocol 27, the final planned step in the current protocol update sequence.

Cooling US inflation supports PI recovery

U.S. macroeconomic conditions provided a second tailwind for PI and the broader crypto market. The Bureau of Labor Statistics reported that the Consumer Price Index rose 0.1% in July and 3.4% from a year earlier.

Advertisement

Annual inflation slowed from 3.5% in June, while core CPI increased 0.2% month over month and 2.5% annually. Both annual readings eased from the previous month.

Slower inflation can reduce pressure on the Federal Reserve to raise interest rates further. Lower rate expectations generally support risk assets by improving liquidity conditions, although PI’s immediate move remained closely tied to the network upgrade and retail trading activity.

PI’s price is still more than 95% below its February 2025 peak, leaving the token exposed to sharp swings as short-term traders respond to technical breakouts and project updates.

Supply also remains an important risk. Data attributed to PiScan indicates that approximately 775.8 million PI could be unlocked by the end of 2026. Unlocks do not guarantee immediate selling, but they may increase the amount of PI available in the market if recipients choose to sell.

Advertisement

PI price holds above short-term support

The daily chart shows PI trading above its 20-day simple moving average at $0.0853. Reclaiming the average marks an improvement from the sustained downtrend that pushed the token from above $0.20 in March to a July low near $0.071.

Pi Network daily chart shows PI holding above its 20-day SMA at $0.0853 but below $0.096 resistance.
Pi Network price daily chart — Aug. 12 | Source: crypto.news

Bull-bear power has also turned slightly positive at 0.00166, indicating that buyers have gained limited control around the current range. Price has nevertheless failed to produce a decisive trend reversal.

PI remains below the 50-day moving average at $0.0961, which forms the first major resistance zone. The 100-day and 200-day averages sit much higher at $0.1215 and $0.1489, respectively, showing that the broader daily trend remains bearish.

A daily close above $0.096 would strengthen the recovery case and place the psychological $0.10 level in focus. Clearing both barriers could allow buyers to target the 100-day average near $0.12.

Failure to hold $0.0853 would weaken the current setup. Sellers could then test $0.080, followed by the July support area between $0.071 and $0.075.

Advertisement

4-hour indicators show weak but improving momentum

PI’s 4-hour chart shows price consolidating between approximately $0.085 and $0.092 after recovering from the late-July low. Buyers have repeatedly defended the lower end of the range, but rallies have lost momentum around $0.090–$0.093.

Pi Network 4-hour chart shows PI consolidating near $0.088 as RSI approaches 50 and MACD momentum improves.
Pi Network price 4-hour chart — Aug. 12 | Source: crypto.news

The 4-hour Relative Strength Index stood at 49.79, just below the neutral 50 level. The reading shows that selling pressure has eased without confirming strong bullish momentum.

MACD offered a slightly more constructive signal. Its histogram turned positive at 0.00006 as the MACD line moved above the signal line, although both remained below zero. The setup points to an early recovery attempt rather than a confirmed breakout.

A 4-hour close above $0.093 would improve the short-term structure and expose the $0.096–$0.10 resistance zone. Losing $0.085, however, would invalidate the immediate bullish setup and raise the risk of another move toward $0.080.

Analyst sees $0.15 target after triangle breakout

Crypto analyst Crypto With Gopal said PI was compressing between descending resistance and rising support, creating a large triangle pattern.

Advertisement

According to the analyst’s chart, a clean break above approximately $0.10 could trigger a larger move toward $0.15. Such a move would require PI to reclaim its 50-day and 100-day moving averages before challenging the 200-day average near the analyst’s target.

Advertisement

Until PI closes above $0.10, the pattern remains unconfirmed. The token’s position below its major long-term averages and the pending supply unlocks continue to limit the strength of the bullish case.

Disclosure: This article does not represent investment advice. The content and materials featured on this page are for educational purposes only.

Advertisement

Source link

Advertisement
Continue Reading

Crypto World

Trump Breaks Silence on Secret Plane Switch in Turkey Over Possible Iranian Threat

Published

on

Trump Breaks Silence on Secret Plane Switch in Turkey Over Possible Iranian Threat

Trump isn’t the only President to execute a decoy mission

Although rare, a decoy maneuver such as this is not unheard of when it comes to presidential travel.

A similar episode occurred in March 2000, when former President Bill Clinton secretly switched to a decoy jet, with all of the markings of Air Force One, as he traveled to Islamabad, Pakistan for a visit marked by extraordinary security.

The switch was revealed when a Secret Service agent resembling Clinton stepped out of Air Force One upon touching down in Pakistan, while Clinton disembarked from the second aircraft. 

Advertisement

However, at least one member of the White House pool was aware of the ruse: Susan Page, then-president of the White House Correspondents’ Association, who was covering the trip for USA TODAY.

Page this week broke her 26-year silence on the briefing that preceded the secret switch.

“They told me about the extraordinary security procedures being taken because of the dangers in flying there, including use of the decoy plane,” she told the Post. “Of course, the dangers threatened the journalists covering the trip as well as President Clinton.”

Source link

Advertisement
Continue Reading

Crypto World

Crypto Firms Ask AI Companies for Early Access to Bitcoin Devs

Published

on

Crypto Breaking News

A coalition of crypto companies and industry groups has asked frontier artificial intelligence (AI) labs to provide Bitcoin developers and other open-source “defenders” early access to their most capable models. The request comes in a letter published Monday by the Bitcoin Policy Institute (BPI), arguing that current access arrangements can leave critical infrastructure teams operating behind the pace of rapidly advancing AI-assisted cyber capabilities.

In the letter, signatories say many defenders—including Bitcoin Core developers—can be limited by the absence of dedicated “trusted-access programs” and by guardrails applied to publicly available frontier systems. As a result, they contend that qualified teams may be forced to rely on less capable open-weight models, even as attackers may use more powerful AI tooling to probe for weaknesses.

Key takeaways

  • The Bitcoin Policy Institute letter calls for “standing trusted-access programs” so open-source financial infrastructure defenders can use top-tier frontier AI before widespread public release.
  • Signatories argue that guardrails and limited access to advanced models can hinder security research and response for Bitcoin and broader crypto systems.
  • The letter links the push to the rising scale of AI-enabled vulnerability discovery and threats, citing multiple reports from open-source maintainers.
  • Industry data referenced in the letter points to a sharp jump in monthly crypto hacks, with April 2026 losses exceeding $634 million.
  • The coalition includes major ecosystem participants such as Anchorage Digital, BitGo, Bitwise, Blockstream, Kraken, Ledger, and Trezor, among others.

Why the letter centers on “trusted access”

The BPI says the economics of security research and cyber operations are shifting as frontier AI models become more capable. According to the letter, advanced systems can search large codebases, surface potential weaknesses, and compress timelines for complex technical work—benefits that apply not only to attackers, but also to defenders responsible for maintaining open-source financial infrastructure.

Without early, dedicated access programs, the letter warns that defenders may struggle to keep pace with evolving threats. It also argues that cyber incidents exploiting open-source vulnerabilities can translate directly into real-world harm, including the risk of losing “life savings,” given how widely open-source software underpins digital finance.

To address this asymmetry, the letter asks frontier AI labs to “establish or expand standing trusted-access programs” for qualified open-source defenders. The focus is less on broad public access and more on structured access channels for teams charged with safeguarding infrastructure.

Advertisement

What data and security commentary are used to support the case

The letter points to recent increases in hack activity across the sector. It cites DefiLlama data showing that total monthly crypto hacks surged in April 2026, with malicious actors stealing more than $634 million from cryptocurrency platforms—described as the highest monthly total since the Bybit hack. That earlier incident, the letter notes, contributed to losses of roughly $1.4 billion in February 2025, again according to DefiLlama.

In addition to incident volume, the letter frames AI as a force multiplier for vulnerability discovery. It references concerns raised across the crypto security industry as newer AI systems make it easier to automate parts of the probing and exploit development cycle.

Earlier coverage cited within the letter highlights comments from Mitchell Amador, CEO of bug bounty platform Immunefi, who characterized the moment as a “vulnerability apocalypse” in relation to developments in AI-assisted research. The letter also mentions the emergence of newer frontier models—described in the article as Claude Opus 4.8 and ChatGPT 5.5—as part of the broader shift raising security stakes.

Who signed the request

The open letter is co-signed by a broad cross-section of the crypto industry, signaling that the concern is not confined to one segment of infrastructure. Alongside the Bitcoin Policy Institute, the signatories include organizations such as the African Bitcoin Institute, Anchorage Digital, BitGo, Bitwise, Blockstream, Bull Bitcoin, MARA, Kraken, Ledger, and Trezor, among others.

Advertisement

By bringing together companies spanning custody, exchanges, analytics, wallet infrastructure, and Bitcoin-focused organizations, the letter underscores the “system-wide” nature of the risk it describes: open-source code and shared software dependencies can affect multiple products, operators, and user bases at once.

Implications for Bitcoin developers and the broader security community

If frontier AI labs establish or expand trusted-access programs as requested, the most immediate practical impact would be on the speed and effectiveness of defensive work around open-source financial infrastructure. In the letter’s framing, having early access to capable models could improve how maintainers audit code, identify potential weaknesses, and respond to new exploit techniques.

The request also highlights a tension that many in security research recognize: attackers may benefit from advanced tools faster than defenders can. By arguing that public guardrails and limited availability of powerful models can block legitimate defense work, the letter effectively calls for a policy-like solution—one that treats certain defenders as authorized users of frontier capabilities.

At the same time, it remains unclear what “standing trusted-access programs” would look like in practice, including how labs would vet applicants, what models would be shared, and how output would be handled. The letter is a policy request rather than a technical specification, so builders and investors should watch for follow-up actions that clarify implementation details.

Advertisement

For now, the key signal is the coalition’s insistence that time-to-defense matters as AI capabilities scale—especially as hack activity remains elevated and AI-assisted vulnerability discovery accelerates. The next phase will likely involve whether frontier AI labs respond, and whether any program structures emerge that could help Bitcoin and other open-source maintainers close the gap between defensive capacity and adversarial capability.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Source link

Advertisement
Continue Reading

Crypto World

How the Company Analyses Changes in Financial Market

Published

on

How the Company Analyses Changes in Financial Market

London, United Kigdom, August 12th, 2026, Chainwire

HCB Advisory has published a new analysis examining the role of market sentiment in financial markets and how changes in investor behaviour, demand, and expectations can influence short- and medium-term asset price movements.

Financial markets are shaped not only by economic indicators and fundamental developments, but also by the behaviour and expectations of market participants. Changes in investor confidence, risk appetite, demand for particular assets, and reactions to new information can contribute to significant changes in market dynamics.

According to HCB Advisory, analysing market sentiment can provide an additional perspective when assessing financial markets. By observing how participants respond to economic developments, corporate news, monetary policy decisions, and changes in broader market conditions, analysts can gain a better understanding of the factors influencing price movements.

Advertisement

“Market sentiment can provide important context when analysing short- and medium-term changes in asset prices,” Blake Rees said a representative of HCB Advisory. “Investor behaviour, changes in demand, and reactions to new information can all contribute to market dynamics. Understanding these factors allows analysts to evaluate price movements from a broader perspective.”

Understanding Market Sentiment

Market sentiment describes the general attitude and expectations of participants toward a particular asset, market, or the broader financial environment.

Sentiment can change as investors respond to new information, economic data, company announcements, central bank decisions, geopolitical developments, or changes in financial conditions.

Periods of positive sentiment may be associated with increased risk appetite and stronger demand for certain assets. Conversely, declining confidence can lead investors to become more cautious and reduce exposure to assets perceived as carrying greater uncertainty.

Advertisement

HCB Advisory notes that sentiment is not necessarily uniform across all market participants. Different investors can interpret the same information differently, creating a range of expectations and contributing to changes in market activity.

Investor Behaviour and Market Dynamics

Investor behaviour represents an important component of sentiment analysis.

Market participants continuously evaluate available information and make decisions based on their expectations about future conditions. These decisions can affect buying and selling activity and, consequently, the balance between supply and demand.

Advertisement

According to HCB Advisory, observing changes in investor behaviour can help analysts understand why an asset may experience increased activity even when there has been no major change in its underlying fundamentals.

Behaviour can also change rapidly when new information enters the market. Unexpected economic data, policy announcements, or significant corporate developments can alter expectations within a short period of time.

For this reason, monitoring behavioural changes can complement traditional market analysis.

Changes in Demand

Advertisement

Demand is another important indicator when assessing market sentiment.

An increase in demand can indicate growing interest in a particular asset or market segment, while declining demand may reflect a reduction in investor interest or a shift toward alternative opportunities.

HCB Advisory considers changes in demand alongside other market indicators rather than treating them as an independent signal.

Trading volumes, price movements, liquidity, and broader market conditions can provide additional context when evaluating whether changes in demand represent a temporary development or part of a broader shift in sentiment.

Advertisement

Understanding these relationships can help analysts develop a more complete view of market behaviour.

Identifying Potential Trading Signals

Changes in sentiment and investor behaviour can also be incorporated into the process of identifying potential trading signals.

A trading signal does not necessarily represent a prediction of future market performance. Instead, it can serve as an indicator that a particular market condition or change in participant behaviour may require additional analysis.

Advertisement

For example, a significant increase in trading activity accompanied by a change in investor sentiment may indicate that market participants are responding to new information.

Similarly, a sharp change in demand may prompt analysts to investigate the factors behind the movement and determine whether it is connected to broader market developments.

According to HCB Advisory, such signals should be evaluated together with other analytical factors rather than used in isolation.

Combining Sentiment With Market Analysis

Advertisement

Market sentiment is only one component of a broader analytical framework.

Traditional market analysis can include economic indicators, interest rates, inflation, corporate developments, valuation measures, liquidity conditions, and other factors relevant to a particular asset.

HCB Advisory believes that combining these areas of analysis with information about investor behaviour can provide a broader perspective on market conditions.

For example, a change in asset prices may be driven by fundamental developments, changing expectations, or a combination of both. Understanding the role of sentiment can help analysts examine the behavioural component of the movement.

Advertisement

This approach is particularly relevant when evaluating short- and medium-term market changes, where investor expectations can influence price dynamics over relatively short periods.

Technology and Sentiment Analysis

Modern financial technologies are creating new opportunities for analysing market sentiment.

Analytical platforms can process large volumes of information from financial markets, news sources, economic publications, and other data channels. Advanced data-processing systems can help identify changes in activity and highlight developments that may require further investigation.

Advertisement

Artificial intelligence and machine learning technologies can also assist with processing large datasets and identifying patterns in market behaviour.

According to HCB Advisory, these tools can support analysts by improving the speed at which information is collected and organized.

However, technological systems still require interpretation. Changes in sentiment can have different meanings depending on the broader market environment, making professional analysis an important part of the process.

Short-Term and Medium-Term Market Movements

Advertisement

Sentiment analysis can be particularly relevant when examining short- and medium-term price dynamics.

In the short term, markets can respond quickly to changes in expectations, news events, and investor positioning. Over longer periods, sentiment can interact with economic and fundamental developments to influence broader market trends.

HCB Advisory emphasizes that distinguishing between temporary changes in sentiment and more persistent shifts is an important part of the analytical process.

A short-lived increase in demand may have a different significance from a sustained change in investor behaviour that continues across multiple trading sessions or market cycles.

Advertisement

Avoiding a Single-Indicator Approach

HCB Advisory stresses that no single sentiment indicator can provide a complete explanation of market behaviour.

Investor sentiment can change quickly, and indicators based on historical or current activity may not fully reflect future developments.

For this reason, the company advocates combining sentiment analysis with broader market research.

Advertisement

Analysts can consider price dynamics, trading activity, economic conditions, liquidity, fundamental developments, and other relevant information alongside changes in investor behaviour.

This multi-factor approach can provide greater context when evaluating potential market scenarios.

Looking Ahead

Financial markets are becoming increasingly data-driven, while investors have access to information from a growing number of sources.

Advertisement

As information becomes more readily available, understanding how market participants respond to that information may become increasingly relevant to financial analysis.

According to HCB Advisory, the combination of traditional market research, behavioural analysis, and modern data-processing technologies can provide additional insight into changing market conditions.

The company concludes that understanding investor behaviour and changes in market sentiment can help analysts evaluate the reasons behind short- and medium-term price movements more comprehensively.

About HCB Advisory

Advertisement

HCB Advisory is a financial research and advisory company focused on financial markets, investment analysis, market intelligence, and modern financial technologies. The company publishes research and industry insights covering global economic developments, market trends, investor behaviour, investment processes, and the evolution of financial decision-making.

Website: https://hcbadvisory.com/

Disclaimer

This press release is provided for informational purposes only and does not constitute financial, investment, legal, or tax advice. Market sentiment and behavioural indicators cannot guarantee future price movements or investment outcomes. The information presented is for general informational purposes and should not be interpreted as a recommendation to buy, sell, or hold any financial instrument, security, digital asset, or investment product.

Advertisement
Contact

Caleb Grant
marketing@hcbadvisory.com

Source link

Advertisement
Continue Reading

Crypto World

Harmony’s ONE token crashes 40% following a major exploit

Published

on

Harmony’s ONE token crashes 40% following a major exploit

Key takeaways

  • Harmony’s ONE token plunged roughly 40% following an apparent exploit that created about 4 billion tokens.
  • The unauthorized issuance was equivalent to approximately 26% of ONE’s existing supply.
  • Harmony released an emergency software update to prevent further minting and urged network operators to install it immediately.

Harmony’s ONE token fell approximately 40% on Wednesday after an apparent exploit reportedly created around 4 billion new tokens.

Harmony confirmed the attack and instructed the network operators responsible for maintaining the blockchain to install an emergency software update. The project said the patch would prevent the attacker from minting additional ONE tokens.

However, the update does not resolve the status of tokens that were already created. Harmony is still evaluating how to isolate or remove those assets from circulation.

The scale of the incident triggered intense selling pressure as traders assessed the risks of token dilution, exchange deposits, and a potential reversal of blockchain transactions.

Advertisement

Unauthorized issuance equals 26% of ONE supply

Approximately 15 billion ONE tokens existed before the exploit. The creation of another 4 billion represents a sudden supply increase of roughly 26%.

Such a large unauthorized issuance can severely dilute existing holders. If the attacker successfully transfers the newly created tokens to exchanges and sells them, the additional circulating supply could place further downward pressure on ONE’s price.

Harmony has not officially confirmed the total number of tokens minted or explained how the reported 4 billion figure was calculated.

The network was once among the cryptocurrency industry’s largest projects, reaching a market capitalization of approximately $4 billion in January 2022.

Advertisement

Harmony temporarily paused its token bridge to prevent potentially compromised assets from moving between networks.

The project also asked centralized exchanges to block and freeze funds traced to four wallet addresses associated with the incident. By flagging those addresses, Harmony hopes trading platforms can prevent the attacker from converting or withdrawing the newly minted tokens.

Cooperation from exchanges may limit the damage if the assets remain identifiable. However, recovery becomes more difficult if the tokens are swapped through decentralized exchanges, transferred to other networks or divided among additional wallets.

Blockchain transaction monitoring may still allow investigators to trace some movements, but it cannot guarantee that all unauthorized assets will be recovered.

Advertisement

Harmony’s software update is intended to close the vulnerability and stop any additional ONE from being created.

Network operators must adopt the new software for the patch to become effective across the blockchain. A coordinated upgrade is therefore essential to ensure that validators and other infrastructure providers follow the corrected network rules.

Harmony has not publicly identified the vulnerability, disclosed how the attacker gained minting authority or confirmed whether any additional parts of the protocol remain at risk.

Until the project releases a complete technical explanation, uncertainty may continue to weigh on ONE and applications operating on the network.

Advertisement

“We are working on a patch and rollback options,” Harmony said, promising further updates as its investigation progresses.

A rollback would return the blockchain to a state recorded before the exploit. The network would then resume from that point, removing subsequent transactions from its accepted history.

This approach could erase the creation of unauthorized tokens still on Harmony. However, it could also reverse legitimate transactions completed after the selected rollback point.

Will ONE recover following the massive dip?

The ONE/USD 4-hour chart is extremely bearish and efficient, as ONE has lost 40% of its value in the last 24 hours.

Advertisement

The coin briefly dropped to the $0.000605 level before bouncing back to now trade above $0.00074.

The technical indicators suggest that the bears are currently in control. The RSI of 12 means that ONE is currently in an oversold territory. The MACD lines also support the bearish narrative.

ONE/USD 4H Chart

If the bearish trend persists, ONE could retest the daily low of $0.000605 before heading towards the $0.00050 psychological level.

However, if the bulls regain control, they would likely seek efficiency on the 4-hour chart at the $0.00112 level in the near term.

Advertisement

Source link

Advertisement
Continue Reading

Crypto World

New York City Council probes prediction markets’ marketing strategies

Published

on

New York City Council probes prediction markets' marketing strategies

A Kalshi billboard displaying New York City mayoral election odds in Times Square in New York, US, on Tuesday, Nov. 4, 2025.

Adam Gray | Bloomberg | Getty Images

The New York City Council is investigating marketing practices by prediction market platforms, the office of Council Speaker Julie Menin said on Wednesday. 

Advertisement

In letters to four prediction market platforms — Polymarket, Kalshi, Coinbase and Gemini Titan — Menin wrote that the council has been examining allegations of “false, deceptive, unconscionable, and objectionable marketing practices” by event contract exchanges for months. 

“Prediction markets aggressively entice consumers to bet and wager on sports, politics, culture, weather, and pretty much anything,” Menin said in a statement. “I intend to harness the full power of the Council to protect New Yorkers from deceptive and predatory marketing practices by prediction market platforms.”

Menin the letters referenced an investigation by The Wall Street Journal that claimed that Polymarket conducted misleading marketing campaigns. The Journal said in a June article that Polymarket made it appear as though content creators it partnered with were winning on the platform when, in fact, they were not using their own money. The Journal’s reporting led to an investigation by the Commodity Futures Trading Commission, the federal regulator for prediction markets.

CNBC reported on Tuesday that Polymarket has taken steps to revamp its marketing strategy, including through updated and streamlined guidelines for staff at the company and the content creators it works with. 

Advertisement

Menin added in her letters to the platforms that the council is investigating whether such advertising strategies are used by other prediction market companies. A memo attached to these letters said the allegations against Polymarket show an urgent need to determine if legislation or other policy changes are necessary. Menin’s office added that the council plans to hold a hearing on the matter. 

The memo, which also described the probe, made clear that the inquiry is not exploring whether or not event contract exchanges violate New York’s state gambling laws.

New York state is currently in active litigation against Kalshi, Coinbase and Gemini, alleging that the companies are running illegal gambling operations. The platforms assert that they are federally regulated financial exchanges and aren’t subject to state betting laws. New York state is currently not in litigation against Polymarket. 

Kalshi, Polymarket and Gemini are all headquartered in New York City. Coinbase officially operates out of Texas, but announced plans earlier this year to expand its total workforce to more than 1,000 employees in New York

Advertisement

“We look forward to engaging with The New York City Council on this matter,” a Polymarket spokesperson said in a statement.

When contacted by CNBC for comment, a Coinbase spokesperson said, “Coinbase offers our customers access to federally regulated prediction markets overseen by the CFTC, and fully complies with applicable laws.”‘

Kalshi spokesperson Dani Lever in a statement said that the company looks “forward to educating the New York City Council about our business model and practices.”

Gemini did not immediately respond to a request for comment. 

Advertisement

Disclosure: CNBC and Kalshi have a commercial relationship that includes customer acquisition and a minority investment.

Choose CNBC as your preferred source on Google and never miss a moment from the most trusted name in business news.

Source link

Continue Reading

Crypto World

Fidelity files with SEC to add staking to Ethereum ETF

Published

on

Fidelity files with SEC to add staking to Ethereum ETF

Fidelity files with SEC to add staking to Ethereum ETF

Fidelity plans to add staking to its Ether fund, with 85% of rewards retained by FETH and quarterly cash distributions planned for investors.

Source link

Continue Reading

Trending

Copyright © 2025