Crypto World
KOSPI Spikes 5% on Opening, Riding Micron’s Surprise Earnings
South Korea’s KOSPI surged more than 5% at the open on June 25, pushing back above 8,900 from 8,400 the prior session. Micron Technology’s fiscal Q3 2026 results, which well exceeded Wall Street expectations, drove the move.
The Korea Exchange (KRX) activated a buy-side sidecar shortly after the open, suspending program trading for five minutes. The mechanism triggers when the KOSPI 200 Futures index climbs 5% or more for at least one minute.
Micron Results Catalyze the Move
Micron reported fiscal Q3 2026 revenue of $41.46 billion, more than four times the $9.30 billion it posted in the same quarter a year earlier. Adjusted earnings per share came in at $25.11, well above the analyst consensus of around $20.78. The stock gained roughly 15% in after-hours trading following the announcement.
SK Hynix jumped more than 10% in early morning trading and triggered a static volatility interruption (VI) at the open, briefly switching to single-price trading for two minutes. After the VI lifted, the stock moved quickly back toward its prior level.
Samsung Electronics and SK Hynix reclaimed the 360,000 won and 2.8 million won levels, respectively. As BeInCrypto reported, SK Hynix recently surpassed Samsung in market cap for the first time since 2000.
K Hynix and Samsung Lead the Charge
By investor type, individuals net bought roughly 490 billion won and institutions added around 100 billion won. Foreign investors net sold approximately 600 billion won, extending a streak of net selling that has now totaled around 12.2 trillion won over the past five trading days.
The divergence mirrors the pattern seen after South Korea’s previous market rebound, when retail buyers absorbed foreign selling in the early session.
Han Ji-young, a researcher at Kiwoom Securities, pointed to a combination of macro tailwinds and Micron’s outperformance.
“In a favorable macro environment, including falling oil prices and the U.S. 10-year Government Bonds yield falling below 4.4%, Micron’s earnings surprise and the more than 5% strength in the KOSPI200 night futures combined to send the index surging at the open.” — Han Ji-young, Kiwoom Securities
The post KOSPI Spikes 5% on Opening, Riding Micron’s Surprise Earnings appeared first on BeInCrypto.
Crypto World
The $70 million Coldcard exploit prompts CZ to urge wallet diversification.
Crypto holders used to focus on diversifying their coins. Now, following a $70 million Coldcard exploit, they’re being told to diversify their wallets as well.
On Saturday, Binance founder Changpeng Zhao, known as CZ, asked crypto holders to split their funds across multiple wallets following a major security failure in popular Coldcard hardware devices.
“Even hardware wallets can have bugs. Even old wallets (with long history) can have bugs. How to mitigate? Split your funds in a few wallets maybe? This has a different set of risks. Nothing is 100%. Stay informed. Stay SAFU!,” he said.
On July 30, some bitcoin users discovered that funds from their Coldcard wallets had been stolen in a series of unexpected transactions. The attacker exploited a firmware flaw dating to March 2021 that weakened the randomness used to generate recovery seeds on certain Coldcard models. By reconstructing private keys offline, the attacker was able to drain funds without ever physically accessing the devices.
Initial reports said about 594 BTC, worth $38 million at the time, were drained from around 500 wallet in a 25-minute window. Subsequent analysis by Galaxy Research expanded the scope to 1,082.65 bitcoin, valued at approximately $70 million, drained from 1,196 addresses over about 41 minutes. Many of the affected wallets had sat dormant for years.
Coldcard maker Coinkite has acknowledged the bug, apologized, and released emergency firmware updates. The company has advised users who generated seeds on affected versions to create entirely new seeds on patched devices and carefully migrate funds, noting that simply updating firmware does not secure an already-created vulnerable seed.
The episode has renewed debate over the limits of self-custody. Hardware wallets are widely viewed as one of the strongest options for securing bitcoin offline, yet the Coldcard case shows that even long-established devices can harbor critical flaws that remain undetected for years.
CZ’s suggestion of diversification acknowledges that spreading risk comes with its own practical challenges, including more complex key management.
Crypto World
What is a mainnet? Production blockchain explained
A mainnet is the production version of a blockchain network where transactions carry real economic value and are permanently recorded. When a cryptocurrency project launches its mainnet, it moves from concept to reality, and every line of code becomes a financial commitment.
Summary
- A mainnet is a fully operational blockchain network where tokens have real market value, transactions are irreversible, and the consensus mechanism secures actual economic activity.
- Mainnet launches are milestone events that typically follow months or years of testnet development, security audits, and community governance processes.
- Hard forks and protocol upgrades on a mainnet are high stakes operations because bugs cannot be rolled back without consensus from the entire network of validators and users.
- Major mainnet launches in 2026 include Robinhood’s layer 2 for tokenized stock trading, Firedancer on Solana, and multiple stablecoin mainnets including Tether’s USAT on Celo.
- The security assumptions of a mainnet differ fundamentally from a testnet because real economic incentives create both stronger security guarantees and more sophisticated attack vectors.
In software development, production is where the stakes are real. A bug in a development environment is a learning opportunity. A bug in production is an incident report. In blockchain, the gap between these two states is even wider because blockchain transactions are, by design, difficult or impossible to reverse.
A mainnet is a blockchain’s production environment. It is the live, operational network where tokens have market prices, smart contracts control real funds, and the consensus mechanism protects real economic value. Everything that happens before mainnet, including testnets, audits, and governance votes, exists to reduce the probability that something goes wrong after mainnet launch.
This article explains what a mainnet is, how mainnet launches work, what happens when mainnets are upgraded through hard forks, and what risks remain even after a successful launch. If you hold cryptocurrency on any blockchain, you are interacting with a mainnet, and understanding how it works is fundamental to understanding the security of your assets.
What makes a mainnet different from a testnet
The technical infrastructure of a mainnet and its corresponding testnet is largely identical. Both run the same node software, use the same consensus algorithm, and process transactions using the same virtual machine. The differences are economic and social rather than technical.
On a mainnet, tokens have market value. This means validators and miners have financial incentives to act honestly because their staked tokens or mining hardware represents real capital at risk. It also means attackers have financial incentives to exploit vulnerabilities because successful attacks can be monetized. This duality, where real value creates both stronger defense and stronger offense, is the fundamental characteristic of a mainnet.
The validator set on a mainnet is typically much larger and more geographically distributed than on a testnet. Ethereum mainnet has over 1 million active validators as of mid 2026. Its testnets have a few thousand. This scale difference affects network behavior, propagation times, and the difficulty of coordinating upgrades.
State size is another critical difference. Ethereum’s mainnet state, the accumulated data from every transaction since genesis in July 2015, is hundreds of gigabytes. Testnets are reset periodically and never accumulate state at this scale. Performance issues related to state bloat, database fragmentation, and node synchronization time are mainnet problems that testnets rarely surface.
The anatomy of a mainnet launch
A mainnet launch is the moment a blockchain network goes live with real economic value. For new layer 1 chains, this means activating the genesis block and enabling token transfers. For layer 2 networks, this means deploying the bridge contracts to the parent chain and opening the network to public transactions.
Robinhood’s layer 2 mainnet launch in mid 2026 illustrates the typical process. The team first ran a public testnet that processed 4 million transactions in its first week. After testnet validation, security audits, and regulatory approvals, the mainnet launched with tokenized stock trading functionality. The launch was phased, with a limited set of assets available initially and additional assets added over subsequent weeks.
Mainnet launches carry risks that testnet deployments do not. Bridge contracts that control the flow of value between layers are high value targets for attackers. Smart contract bugs that were not caught during testing become exploitable the moment real value is deposited. The coordination required to launch a mainnet, involving exchanges, wallet providers, infrastructure operators, and application developers, introduces organizational risks that are absent from testnets.
Some projects use a staged mainnet launch where the network goes live with training wheels: centralized sequencers, admin keys that can pause the protocol, or spending limits on smart contracts. These safety measures reduce the blast radius of potential bugs but require users to trust the project team, which partially contradicts the decentralization promise. Most projects commit to removing these training wheels on a published timeline, though some have taken years to do so.
Hard forks and mainnet upgrades
A mainnet is not static. Blockchain protocols evolve through upgrades that add new features, fix bugs, or change economic parameters. When an upgrade requires all nodes to update their software simultaneously, it is called a hard fork. When an upgrade is backward compatible and does not require all nodes to update at once, it is called a soft fork.
Hard forks on a mainnet are high stakes coordination events. If a significant portion of validators do not upgrade their software before the fork height, the chain can split into two incompatible networks. This happened with Ethereum and Ethereum Classic in 2016, with Bitcoin and Bitcoin Cash in 2017, and with several smaller chains since. Chain splits create confusion, duplicate transactions, and can permanently fragment a network’s community and economic value.
Cardano’s van Rossem hard fork in 2026 demonstrated modern hard fork governance. The upgrade went through an on chain voting process where stake pool operators signaled their readiness before the protocol activated the new rules. This governance mechanism reduces the risk of chain splits by making upgrade coordination explicit and measurable.
Ethereum’s approach to hard forks has evolved toward coordinated network upgrades with names like Shanghai, Cancun, and Pectra. Each upgrade bundles multiple protocol changes, goes through extensive testnet validation, and is activated at a predetermined block number or slot that all node operators know in advance. The Firedancer client for Solana represents a different approach, where a new validator client implementation is deployed alongside existing clients to increase client diversity without requiring a hard fork.
Mainnet security in practice
The security of a mainnet rests on three pillars: the correctness of the protocol software, the economic incentives of the consensus mechanism, and the diversity and distribution of the validator set.
Protocol correctness is addressed through code audits, formal verification, and testnet deployment. But audits are not guarantees. The history of blockchain exploits includes multiple incidents where audited contracts were exploited through vulnerabilities that the auditors missed. Formal verification, which mathematically proves that code behaves according to a specification, offers stronger guarantees but is expensive and only as good as the specification it verifies.
Economic security comes from the cost of attacking the network. On a proof of work mainnet, this cost is the energy and hardware required to sustain a 51 percent attack. On a proof of stake mainnet, this cost is the capital required to acquire a controlling stake, plus the risk of that stake being slashed if the attack is detected. Both models tie security to real economic value, which only exists on a mainnet.
Validator diversity means running multiple independent client implementations. If all validators run the same software and that software has a bug, the entire network is vulnerable. Ethereum currently has multiple execution clients, including Geth, Nethermind, and Besu, and multiple consensus clients, including Prysm, Lighthouse, Teku, and Lodestar. No single client implementation has a majority share, which means a bug in any one client cannot bring down the entire network.
What mainnet status does not cover
A project being on mainnet does not mean it is safe, decentralized, or battle tested. Many projects launch their mainnet with centralized components, limited validator sets, or admin keys that give the founding team control over critical protocol parameters. Mainnet status is a necessary but not sufficient condition for trustworthiness.
Mainnet status does not guarantee permanence. Several blockchain projects have launched mainnets that were later abandoned, shut down, or migrated to new chains. The tokens associated with those mainnets lost their value. Launching a mainnet is not the finish line. Sustaining it requires ongoing development, community participation, and economic viability.
Mainnet status does not indicate regulatory compliance. A blockchain can be technically operational while operating in legal gray areas. Tether’s USAT stablecoin launching on Celo as its second mainnet deployment illustrates how stablecoin projects must navigate both technical mainnet requirements and regulatory frameworks across multiple jurisdictions simultaneously.
Mainnet performance metrics should be read with context. A blockchain reporting high transaction throughput may be running with a small validator set, minimal decentralization, or artificial test traffic. The throughput that matters is sustained throughput under adversarial conditions with a geographically distributed validator set, not peak throughput on a permissioned or lightly loaded network.
Practical checks for evaluating mainnets
When evaluating whether a blockchain’s mainnet is robust, several indicators are more informative than marketing claims.
Check the age of the mainnet. A blockchain that has been running continuously for years with significant value at stake has survived conditions that a newly launched network has not. Bitcoin’s mainnet has run since January 2009 without a single hour of downtime. Ethereum’s has run since July 2015 with brief interruptions during consensus incidents. Newer chains have shorter track records and correspondingly less demonstrated reliability.
Check the validator count and distribution. A mainnet with thousands of validators distributed across dozens of countries is more resilient than one with a few dozen validators in a single data center. Block explorers and network dashboards for most chains publish this data.
Check whether admin keys or upgrade mechanisms exist that could allow a small group to modify the protocol without community consensus. Many new mainnets launch with multisig admin controls that could theoretically be used to drain funds, pause the network, or censor transactions. Understanding who holds these keys and under what conditions they can be used is essential due diligence.
Check the total value locked and the duration for which that value has been locked. A mainnet securing billions of dollars for years has a stronger security track record than one that recently attracted a spike of deposits following a token incentive program. The depth of the security test is proportional to both the amount of value at risk and the time period over which that value has been at risk.
Frequently asked questions
What is a mainnet in simple terms?
A mainnet is the live, production version of a blockchain where real transactions happen with real money. It is the opposite of a testnet, which uses fake tokens for testing. When you buy, sell, or transfer cryptocurrency, you are using a mainnet.
What happens during a mainnet launch?
During a mainnet launch, a blockchain network goes live for the first time with real economic value. The genesis block is created, validators or miners begin processing transactions, and tokens become tradable on exchanges. Mainnet launches typically follow months of testnet development and security auditing.
Can a mainnet be shut down?
A truly decentralized mainnet cannot be shut down by any single entity because it runs across thousands of independent computers worldwide. However, less decentralized mainnets with few validators or centralized control points could theoretically be stopped. Some smaller blockchain projects have had their mainnets shut down or abandoned.
What is a hard fork on a mainnet?
A hard fork is a protocol upgrade that is not backward compatible, meaning all nodes must update their software to remain on the same network. If some nodes do not update, the chain splits into two separate networks. Hard forks are used to add major new features or fix critical bugs.
How do I know if a project has launched its mainnet?
Check the project’s official website and social media channels for mainnet launch announcements. You can also check block explorers to see if the network is producing blocks with real transactions. Token listings on major exchanges typically coincide with mainnet launches. Be cautious of projects that claim mainnet status but actually run on another chain’s infrastructure.
Is mainnet the same as layer 1?
Not exactly. A mainnet is any production blockchain network. Layer 1 refers specifically to the base chain that provides its own consensus and security. Layer 2 networks like Arbitrum, Optimism, and zkSync also have mainnets, but they rely on a layer 1 mainnet for final settlement and security. Both layer 1 and layer 2 networks have mainnets.
What risks exist on a mainnet that do not exist on a testnet?
On a mainnet, smart contract bugs can result in permanent loss of real funds. Economic attacks like front running, sandwich attacks, and oracle manipulation only work when tokens have real value. Regulatory risks, validator collusion, and bridge exploits are all mainnet-specific risks because they depend on real economic incentives.
How long does it typically take from testnet to mainnet?
The timeline varies widely. Simple projects may go from testnet to mainnet in weeks. Complex layer 1 launches can take months to years. Ethereum’s transition from proof of work to proof of stake spent over two years in testnet and development phases before the mainnet Merge in September 2022. The more value a mainnet will secure, the longer the testing period should be.
Disclaimer: This article is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency investments carry significant risk. Always conduct your own research before making any investment decisions. Information is accurate as of August 1, 2026.
Crypto World
$70 Million Gone in 40 Minutes: CZ Weighs in on Coldcard Fallout
Changpeng Zhao (CZ) has a warning for Bitcoin holders. Hardware wallets can fail too. He spoke days after a Coldcard firmware bug let thieves work out private keys and take $70 million.
Researchers at Galaxy and Block tracked the theft. Attackers emptied 1,196 wallets in 41 minutes on July 30. Nobody touched a single device.
CZ Points to the Limits of Cold Storage
CZ, the founder and former CEO of Binance exchange, says a wallet can be old, trusted, and still broken.
When he posted, early reports put the loss at $38 million. The real figure turned out to be almost double that.
“Even hardware wallets can have bugs. Even old wallets (with long history) can have bugs. How to mitigate? Split your funds in a few wallets maybe? This has a different set of risks. Nothing is 100%. Stay informed. Stay SAFU!” wrote CZ.
Follow us on X to get the latest news as it happens
His advice was to spread coins across several wallets. He also admitted that this brings new risks of its own.
CZ has been candid lately about calls he got wrong. One was the stablecoin market he dismissed, now worth over $300 billion.
How the Coldcard Firmware Bug Made Seeds Guessable
Every wallet starts with one huge secret number. It is called a seed. Every key and address grows out of it. That number has to be random. Coldcard used a dedicated chip to make it random.
Then came a coding mistake in March 2021. The job quietly passed to a weak backup instead. That backup leaned on the device serial number and its clock. Both can be worked out.
So the number stopped being huge. Block’s engineers put the range at roughly four billion options on newer models. A computer can chew through that.
Thieves simply built the seeds themselves. They turned each one into addresses. Then they scanned the public blockchain for funded matches.
Galaxy mapped the sweeps. Every one paid the exact same fee, far above normal. None left change behind. That is software, not a person.
“The full event spans six blocks and 41 minutes. Three intervening blocks contain no sweep activity at all, suggesting the transactions were broadcast in batches rather than streamed,” Galaxy Researchers indicated.
Owners Still Cannot Test Their Own Seeds
Coinkite has shipped fixed firmware for every model. An update cannot repair a seed that already exists.
If yours is exposed, you need a fresh seed and a new wallet. BeInCrypto’s earlier Coldcard theft coverage walks through the steps.
Two things help. The advisory says 50 or more private dice rolls at setup keep a seed strong. A good passphrase adds another wall, the same gap flagged over missing BIP39 passphrase support on phones.
There is still no test you can run at home. Block also lists the older Mk2 as at risk. Coinkite’s advisory does not name it.
The stolen coins have not moved. They sit in four wallets.
Galaxy says more sweeps are possible while weak seeds hold money. Block traced the thief through a paid data account and passed its findings to authorities.
While it has been a record year for crypto breaches, this one still stands apart. Storing a key safely was meant to be the easy part.
The post $70 Million Gone in 40 Minutes: CZ Weighs in on Coldcard Fallout appeared first on BeInCrypto.
Crypto World
What is proof of work? Bitcoin consensus explained
Proof of work is a consensus mechanism that forces computers to spend measurable energy solving a mathematical puzzle before they can add a new block of transactions to a blockchain. It is the reason bitcoin has value as a settlement network and the reason that network consumes more electricity than some countries.
Summary
- Proof of work requires miners to find a hash output below a target threshold by repeatedly guessing a nonce value, consuming real computational energy in the process.
- Bitcoin adjusts its mining difficulty every 2,016 blocks, roughly every two weeks, to maintain an average block time of 10 minutes regardless of how much computing power joins or leaves the network.
- The global bitcoin network hash rate exceeded 1 exahash per second in mid 2026, meaning miners collectively perform more than one quintillion hash computations every second.
- Proof of work is not the only consensus mechanism. Proof of stake, used by Ethereum since September 2022, replaces energy expenditure with economic collateral but introduces different security tradeoffs.
- The environmental debate around proof of work is real but more nuanced than headlines suggest. Roughly 55 to 60 percent of bitcoin mining uses renewable energy sources according to 2025 industry surveys.
Most explanations of proof of work start with an analogy. They compare it to a lottery, a puzzle, or a race. These analogies are useful but they obscure the critical detail: proof of work is not about solving a problem. It is about proving that you spent resources attempting to solve it.
That distinction matters because it explains why bitcoin works as a decentralized ledger. No central authority decides who gets to write the next page of the transaction record. Instead, the network awards that right to whoever demonstrates the most computational effort. The cost of that effort is what makes the record trustworthy.
This article explains what proof of work actually does at a technical level, why it was chosen for bitcoin, how it compares to alternatives, and what it does not protect against. If you have heard that proof of work wastes energy or that it is obsolete, the arithmetic tells a more complicated story.
How hashing works
A hash function takes an input of any length and produces an output of fixed length. Bitcoin uses SHA-256, which produces a 256 bit output regardless of whether the input is a single character or an entire novel. The output looks random but is deterministic: the same input always produces the same output, and changing a single bit of the input produces a completely different output.
This property, called the avalanche effect, is what makes hashing useful for proof of work. There is no shortcut to finding an input that produces a specific output. The only way to find one is to try inputs until you get lucky. Every attempt costs a small amount of energy, and the probability of success on any single attempt is vanishingly small.
When a miner constructs a candidate block, they assemble a set of unconfirmed transactions, add a block header containing metadata like the previous block hash and a timestamp, and include a field called the nonce. The miner then hashes the block header repeatedly, incrementing the nonce each time, until the resulting hash is numerically below a target value set by the network. That target is what determines the difficulty.
The difficulty adjustment
Bitcoin was designed to produce one block approximately every 10 minutes. But the amount of computing power on the network changes constantly as miners join, leave, upgrade hardware, or lose access to cheap electricity. Without a mechanism to account for these changes, blocks would arrive faster when more miners join and slower when they leave.
The difficulty adjustment solves this problem. Every 2,016 blocks, the bitcoin protocol compares the actual time it took to mine those blocks against the expected time of 20,160 minutes. If blocks arrived faster than expected, difficulty increases. If slower, it decreases. The adjustment is capped at a factor of four in either direction to prevent sudden swings.
This mechanism is one of the most elegant engineering decisions in bitcoin. It means the network self-regulates regardless of external conditions. When China banned bitcoin mining in 2021 and roughly half of the global hash rate went offline overnight, the difficulty adjusted downward and blocks kept arriving. When that hash rate migrated to the United States, Kazakhstan, and other jurisdictions and came back online, difficulty adjusted upward again.
The difficulty adjustment also explains why mining difficulty can fall sharply when miners leave the network, as happened in mid 2026 when several large operators pivoted their infrastructure to AI data center operations. The network does not care why miners leave. It simply makes the puzzle easier until block times normalize.
Why energy expenditure creates security
The central insight of proof of work is that energy expenditure creates an unforgeable cost. To rewrite bitcoin’s transaction history, an attacker would need to redo the proof of work for every block they want to change, plus outpace the honest miners who continue extending the chain. This is called a 51 percent attack because it requires controlling more than half of the network’s total hash rate.
The economics make this prohibitive for bitcoin. At current hash rates, sustaining a 51 percent attack would require acquiring and operating more mining hardware than exists in any single country. The electricity cost alone would run into tens of millions of dollars per day. And even if an attacker succeeded, the market would likely crash the price of bitcoin in response, destroying the value of whatever the attacker hoped to steal.
This economic security model is sometimes called thermodynamic security. The idea is that the laws of physics guarantee a minimum cost to attack the network because hash computations require energy and energy has a market price. No amount of clever software can reduce the energy required to perform a SHA-256 computation below a physical floor.
Critics point out that this security comes at a steep cost. The bitcoin network consumes an estimated 150 to 170 terawatt hours of electricity per year, comparable to the annual consumption of Poland or Argentina. Supporters counter that this consumption secures a network carrying trillions of dollars in value and that the relevant comparison is not to zero energy but to the energy consumed by the traditional financial system’s data centers, office buildings, armored vehicles, and vault infrastructure.
Proof of work versus proof of stake
Proof of stake replaces computational work with economic collateral. Instead of spending energy to find a valid hash, validators lock up cryptocurrency as a stake and are selected to propose blocks based on the size of their stake and other factors. If they propose invalid blocks, their stake is partially destroyed through a process called slashing.
Ethereum made this transition in September 2022, moving from proof of work to proof of stake in an event called The Merge. The switch reduced Ethereum’s energy consumption by approximately 99.95 percent. It also changed the network’s security model from one based on energy expenditure to one based on capital at risk.
The debate between the two mechanisms is not settled. Proof of work advocates argue that energy expenditure provides a more robust and censorship resistant form of security because it ties block production to physical resources that cannot be seized or frozen by governments. Proof of stake advocates argue that the security per dollar spent is higher, that the environmental cost is negligible, and that the economic incentives align validators with network health just as effectively.
Both sides have valid points. The choice between them depends on what properties you prioritize. For a network designed to be a global, permissionless, censorship resistant monetary base layer, proof of work’s physical grounding is a feature. For a network designed to support high throughput smart contract execution, proof of stake’s efficiency makes more practical sense.
The mining hardware evolution
Bitcoin mining began on CPUs. Satoshi Nakamoto mined the genesis block on a standard desktop processor. Within two years, miners discovered that GPUs could perform SHA-256 computations far more efficiently. Within four years, field programmable gate arrays entered the picture. By 2013, the first application specific integrated circuits, known as ASICs, arrived and rendered every previous generation of mining hardware obsolete overnight.
Today, bitcoin mining is dominated by purpose built ASIC machines manufactured primarily by Bitmain, MicroBT, and Canaan. The latest generation models from 2025 and 2026 achieve energy efficiencies around 15 to 20 joules per terahash, compared to thousands of joules per terahash for the GPU miners of 2011. Each generation of hardware makes mining more efficient per unit of computation but does not reduce the total energy consumed by the network because difficulty adjusts upward to absorb the additional capacity.
This dynamic creates an arms race. Miners who deploy the newest hardware first gain a temporary advantage in efficiency and profitability. But as more efficient hardware comes online and difficulty rises, older machines become unprofitable and are retired. The regulatory landscape around mining operations has also evolved, with the SEC issuing guidance on how proof of work mining interacts with securities regulations.
The concentration of ASIC manufacturing in a small number of companies raises supply chain concerns. If a single manufacturer controls the majority of new mining hardware production, they have significant influence over who can mine and at what cost. This is an ongoing tension in the bitcoin ecosystem between the ideal of decentralized participation and the economic reality of specialized hardware manufacturing.
The energy debate in numbers
The environmental criticism of proof of work is the most common objection to bitcoin. The numbers are large and the criticism is not baseless. But the debate requires context that most coverage omits.
According to the Cambridge Centre for Alternative Finance and multiple 2025 industry reports, bitcoin mining consumes roughly 150 to 170 TWh per year. For comparison, global air conditioning consumes approximately 2,000 TWh per year. Global data centers consume approximately 1,000 TWh. Gold mining and processing consumes an estimated 240 TWh. The traditional banking system’s total energy footprint, including branches, ATMs, data centers, and transport, is estimated at 260 to 300 TWh.
The renewable energy share of bitcoin mining has increased steadily. The Bitcoin Mining Council, an industry group representing companies that account for roughly half of global hash rate, reported that 59.5 percent of mining energy came from renewable or zero emission sources in its Q4 2025 survey. Independent estimates from the International Energy Agency place the figure somewhat lower, around 50 to 55 percent, noting that self reporting by mining companies may overstate renewable usage.
A growing number of mining operations specifically target stranded or curtailed energy. These are situations where energy is being produced but has no buyer, either because of grid congestion, geographic isolation, or intermittent generation from wind and solar that exceeds local demand. In these cases, bitcoin mining acts as a buyer of last resort for energy that would otherwise be wasted. Whether this dynamic makes mining a net positive for renewable energy deployment is debated, but the economic incentive is clear: miners are drawn to the cheapest electricity available, and the cheapest electricity is increasingly renewable.
What proof of work does not cover
Proof of work secures the ordering and immutability of transactions on the blockchain. It does not secure the transactions themselves before they are confirmed. Unconfirmed transactions in the mempool can be reordered, censored, or front run by miners who have visibility into pending transactions before they are included in a block.
Proof of work does not protect users from sending bitcoin to the wrong address, losing their private keys, or falling for social engineering attacks. It does not validate the economic merits of any transaction. It simply ensures that once a transaction is included in a block and buried under subsequent blocks, it becomes exponentially more expensive to reverse.
Proof of work also does not prevent all forms of centralization. Mining pools, which allow individual miners to combine their hash rate and share rewards proportionally, have concentrated block production among a small number of pool operators. As of mid 2026, the top five mining pools control more than 75 percent of bitcoin’s hash rate. While individual miners can switch pools freely, the operational reality is that pool concentration creates potential points of coercion or regulatory pressure.
Finally, proof of work does not guarantee a particular level of transaction throughput. Bitcoin’s block size and block time are fixed parameters. Other proof of work chains have explored different throughput approaches, but the consensus mechanism itself is concerned with security and ordering, not speed.
Practical checks for verifying proof of work claims
If you want to independently verify claims about proof of work and bitcoin mining, several tools and data sources are available.
The bitcoin block explorer at mempool.space shows real time data on block production, including the hash of each block, the difficulty target it was mined against, and the number of transactions it contains. You can verify that each block hash is numerically below the difficulty target by converting the hash to a decimal number and comparing it to the target.
Hash rate estimates are available from multiple sources including Blockchain.com, Glassnode, and CoinMetrics. These are estimates because the actual hash rate is not directly observable. It is inferred from the rate at which blocks are found relative to the current difficulty. Short term fluctuations in estimated hash rate reflect the randomness inherent in mining, not actual changes in deployed hardware.
Energy consumption estimates from the Cambridge Centre for Alternative Finance use a model based on hardware efficiency assumptions and electricity price data. The model is transparent and its methodology is published. It is the most widely cited independent estimate but relies on assumptions about the mix of hardware deployed globally, which introduces uncertainty.
For verifying the renewable energy claims, the Bitcoin Mining Council publishes quarterly reports with survey data. The Bitcoin ESG Forecast by Daniel Batten provides an alternative estimate using a different methodology. Comparing multiple sources gives a more reliable picture than relying on any single estimate.
Frequently asked questions
What is proof of work in simple terms?
Proof of work is a system where computers compete to solve a mathematical puzzle. The first computer to find a valid solution gets to add the next block of transactions to the blockchain and earns a reward. The puzzle requires real energy to solve, which is what makes the system secure against tampering.
Why does bitcoin use proof of work instead of proof of stake?
Bitcoin uses proof of work because it ties the security of the network to physical energy expenditure, which cannot be faked, seized, or censored by any single entity. Proof of stake ties security to capital deposited within the system itself, which some argue creates different centralization risks. Bitcoin’s creator chose proof of work as the more conservative and censorship resistant option for a monetary base layer.
How much energy does bitcoin mining actually consume?
Bitcoin mining consumes an estimated 150 to 170 terawatt hours of electricity per year as of 2026. For context, global data centers consume roughly 1,000 TWh, air conditioning consumes about 2,000 TWh, and the traditional banking system consumes an estimated 260 to 300 TWh. Roughly 50 to 60 percent of bitcoin mining energy comes from renewable sources.
What is a 51 percent attack?
A 51 percent attack occurs when a single entity controls more than half of a proof of work network’s total hash rate. This would allow them to rewrite recent transaction history, double spend coins, or censor specific transactions. On bitcoin, the cost of sustaining such an attack is prohibitively expensive due to the massive amount of mining hardware and electricity required.
What happens when all 21 million bitcoin are mined?
The last bitcoin is expected to be mined around the year 2140. After that, miners will no longer receive block subsidies but will continue to earn transaction fees for processing transactions. Whether transaction fees alone will provide sufficient economic incentive to maintain current levels of hash rate and security is an open question that the bitcoin community actively debates.
Can you mine bitcoin on a regular computer?
Technically yes, but practically no. The difficulty of bitcoin mining is so high that a regular computer would take millions of years to find a single valid block on average. Bitcoin mining now requires specialized ASIC hardware that performs SHA-256 computations orders of magnitude more efficiently than general purpose processors.
What is the bitcoin halving?
The halving is a programmed event that occurs every 210,000 blocks, roughly every four years, which cuts the block subsidy reward in half. The most recent halving in April 2024 reduced the reward from 6.25 BTC to 3.125 BTC per block. Halvings reduce the rate of new bitcoin creation and contribute to bitcoin’s fixed supply cap of 21 million coins.
Is proof of work the same as bitcoin mining?
Not exactly. Proof of work is the consensus mechanism, which is the set of rules that determines how the network agrees on the state of the ledger. Mining is the activity of performing proof of work computations in exchange for block rewards. Other cryptocurrencies like Litecoin and Dogecoin also use proof of work but with different hash algorithms. Mining is the practical implementation of proof of work, not a synonym for it.
Disclaimer: This article is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency investments carry significant risk. Always conduct your own research before making any investment decisions. Information is accurate as of August 1, 2026.
Crypto World
A build error in Coldcard’s firmware drained $38 million in bitcoin in 25 minutes
Coinkite says an attacker used AI to find a flaw its own AI review missed, exposing 500 wallets to a seed generation bug that reduced 128 bits of entropy to 40.
Summary
- An attacker drained 594 BTC, approximately $38 million, from roughly 500 Coldcard hardware wallets in 25 minutes on July 31, exploiting a seed generation flaw present since March 2021.
- The bug reduced the effective entropy of Mk3 seeds from 128 bits to approximately 40 bits, making private keys guessable through brute force computation instead of cryptographic attack.
- Coinkite, the maker of Coldcard, believes the attacker used AI to discover the flaw in its open source firmware, and says its own AI audit of the same code weeks earlier found nothing.
- Every current Coldcard model is affected to some degree, with Mk4, Q, and Mk5 seeds estimated at roughly 72 bits of entropy instead of 128, and updating the firmware does not repair seeds already created.
- Block, Trezor, and Ledger have confirmed their products are unaffected, while the incident raises fundamental questions about whether hardware wallets can be trusted as the sole custodial layer for significant bitcoin holdings.
The attack took 25 minutes. At 2:14 a.m. UTC on July 31, a single entity began sweeping bitcoin from Coldcard hardware wallets. By 2:39 a.m., 594 BTC had moved from approximately 500 wallets into a consolidation address. The funds, worth roughly $38 million at the time of the sweep, were not stolen through phishing, malware, or physical access to the devices. They were stolen because the devices generated predictable private keys.
Coinkite, the Toronto based company that manufactures Coldcard, published an advisory and a technical breakdown on July 30 after discovering the flaw. The company said a build error in its firmware caused seed generation to draw randomness from a software fallback rather than the hardware random number generator the device was designed to use. The bug had been present since firmware version 4.0.1, released in March 2021. Every seed generated on an affected Coldcard during the past five years was weaker than its owner believed.
The implications extend beyond the immediate financial loss. Coldcard has been the hardware wallet of choice for bitcoin maximalists, security researchers, and institutional custodians who prioritize air gapped, open source, bitcoin only security. If the most trusted hardware wallet in bitcoin could ship a five year old entropy bug without detection, the question is not whether Coldcard failed. The question is whether any hardware wallet can be trusted as a single point of custodial security.
The mechanism: how 128 bits became 40
The technical explanation is both simple and alarming. Coldcard’s firmware calls a function to fetch randomness during seed generation. Two implementations of that function existed in the codebase with identical signatures: the hardware random number generator that Coinkite wrote, and a software fallback inherited from MicroPython, the embedded Python runtime the firmware is built on.
A preprocessor guard was supposed to select the hardware implementation. But the guard checked only whether a configuration setting was defined, not whether its value was correct. When the firmware was compiled, the build system resolved the ambiguity by selecting the software fallback. The build completed without warnings. The resulting firmware generated seeds that appeared normal, produced valid bitcoin addresses, and accepted deposits without any indication that the underlying entropy was catastrophically weak.
On the Mk3, Coinkite estimates the effective search space for a seed generated under this condition at approximately 40 bits. A 128 bit seed has more possible combinations than there are atoms in the observable universe. A 40 bit seed has roughly one trillion combinations. That is within reach of a moderately resourced attacker using commodity hardware. The difference is not a rounding error. It is the difference between a lock that cannot be picked and a lock that can be kicked open.
The Mk4, Q, and Mk5 models include additional secure elements that mix their own entropy into the seed generation process. Coinkite estimates these models produce seeds with approximately 72 bits of effective entropy under the bug. That is materially better than 40 bits but still far below the 128 bit target. A 72 bit key space is not practically brute forceable with current consumer hardware, but it is within theoretical reach of a well funded adversary with access to specialized computing resources.
The most critical detail in Coinkite’s advisory is a single sentence: “Updating the firmware does not change or repair an existing seed.” Every Coldcard owner who generated a seed on affected firmware must create a new seed on patched hardware and migrate their funds. There is no software fix for a weak private key. The key itself must be replaced.
The AI dimension
Coinkite’s advisory introduced a claim that drew immediate scrutiny from the security community. The company said it believes “someone used AI to review previous versions of our firmware” to discover the bug. It added that it had run “one of the best available models” over the same code weeks before the attack, and the model “did not find this bug or anything serious.”
The claim is plausible but unverified. The Coldcard firmware is open source and publicly available on GitHub. Any person or automated system can review it. The specific class of bug, a preprocessor guard that checks definition rather than value, is the kind of subtle code path error that large language models have shown varying ability to detect depending on context, prompt engineering, and the model used.
The asymmetry Coinkite described is real even if its specific attribution is speculative. Attackers and defenders do have access to the same AI tools. But attackers have a structural advantage: they need to find one exploitable flaw, while defenders need to find all of them. An AI that reviews code and reports nothing serious provides false confidence. An AI that reviews code and finds a single exploitable path provides the attacker with everything needed.
The incident also raises questions about the security audit process for hardware wallets more broadly. Coldcard has been praised for its open source approach, which allows anyone to inspect the firmware. But open source visibility is only as valuable as the quality of the inspections performed. If the manufacturer’s own AI review, presumably conducted with full context about the codebase’s architecture and intent, missed the bug, the open source advantage becomes theoretical, not practical.
The security research community has debated the AI attribution claim with skepticism. Several researchers noted on social media that the specific bug class, a preprocessor guard checking definition versus value, is well documented in embedded systems literature and could have been found through conventional code review. The AI framing, they argued, risks obscuring a more fundamental failure: that Coinkite did not have sufficient human review processes in place for a critical code path that had not changed in five years. Whether AI found the bug or a human researcher did, the underlying problem is the same. The code was public, the bug was subtle but not novel, and nobody on the defending side caught it.
Block published an independent technical analysis on July 31 confirming that none of its products, including Bitkey, are affected. Block’s hardware lead Max Guise urged anyone with an affected Coldcard to “move funds as soon as they safely can.” Trezor confirmed its devices use a different entropy generation approach and are not vulnerable. Ledger has not published a formal response but its Secure Element architecture uses a dedicated hardware random number generator that operates independently of the firmware.
The five year window
The timeline of the vulnerability is as damaging as the vulnerability itself. Firmware version 4.0.1, which introduced the bug, was released in March 2021. Every seed generated on an affected Coldcard between March 2021 and the patched firmware releases on July 31, 2026, is potentially compromised. That is five years and four months of affected seed generation.
During that window, Coldcard shipped the Mk3 (affected at 40 bits), the Mk4 (affected at 72 bits), and the Q (affected at 72 bits). The Mk5, released in 2026, is also affected at 72 bits. Coinkite released multiple firmware updates during this period, none of which addressed or detected the entropy issue. The company’s own security reviews, including the recent AI audit, did not catch it.
The five year window also coincided with a period of significant bitcoin price appreciation. Seeds generated on affected Mk3 devices in 2021, when bitcoin traded between $29,000 and $69,000, now protect holdings at prices above $60,000. The economic incentive for an attacker to invest computational resources in brute forcing 40 bit keys increased with every price rally. A wallet holding 1 BTC that was worth $30,000 when the seed was generated is now worth twice that. The attacker’s return on investment improved simply by waiting.
The number of affected wallets is difficult to estimate precisely. Coinkite does not publish sales figures. The 500 wallets drained in the initial attack represent the most exposed subset, likely Mk3 users with the weakest 40 bit entropy who held balances large enough to justify the attacker’s computational investment. The total number of wallets with compromised seeds across all affected models could be significantly larger.
The attacker’s consolidation pattern suggests systematic preparation. The 594 BTC were swept from approximately 500 wallets into a consolidation address and then moved to a single address holding 562 BTC. The 25 minute execution window and the number of wallets targeted simultaneously indicate the attacker had precomputed the vulnerable keys before initiating the sweep. This was not an opportunistic attack. It was an operation that required weeks or months of preparation.
On chain analysis of the sweep shows a methodical execution sequence. The attacker did not broadcast all 500 transactions simultaneously, which would have risked mempool congestion and potential front running by MEV style bots monitoring for unusual transaction patterns. Instead, the transactions were batched in groups, each batch confirming within one or two blocks. The consolidation address received funds across multiple blocks before a final transaction moved 562 BTC to what appears to be a long term holding address. As of this writing, the funds have not moved further.
The migration problem
Coinkite’s remediation guidance asks affected users to perform a wallet migration: generate a new seed on patched firmware, verify the backup, send a test transaction, and then move remaining funds. The process is straightforward for users with a single wallet and moderate balances. It is significantly more complex for users with multisig setups, timelocked transactions, or wallets that serve as one key in a larger custodial arrangement.
The migration also creates its own security risks. Moving funds from a compromised wallet to a new wallet requires the compromised wallet to sign a transaction. If the attacker has already computed the private key, the attacker can front run the migration by monitoring the blockchain for any transaction from the compromised address and immediately sweeping remaining funds. Users with significant balances face a race condition between their own migration and the attacker’s sweep.
For users holding bitcoin in multisig arrangements where a Coldcard served as one of multiple signing devices, the migration is more complex but the risk is partially mitigated. A 2 of 3 multisig wallet where only one key was generated on an affected Coldcard remains secure as long as the attacker cannot compromise a second key. However, the compromised key still weakens the overall security model and should be replaced. The process requires coordinating with all key holders to construct a new multisig wallet with a replacement key, sign a migration transaction with the existing quorum, and verify the new arrangement before moving remaining funds.
Coinkite addressed one edge case that provides partial relief. Users who added at least 50 independent dice rolls during seed generation contributed enough external entropy to bring the total above 128 bits regardless of the firmware bug. The dice input was hashed together with the device generated randomness, so strong dice entropy compensated for weak device entropy. Users who added 99 or more rolls contributed approximately 256 bits from dice alone.
The dice exception highlights an irony. The users most likely to have added extensive dice rolls during seed generation are the most security conscious users, precisely the demographic that chose Coldcard specifically because of its reputation for superior security practices. For these users, their own paranoia about entropy quality may have inadvertently protected them from the manufacturer’s failure to deliver it.
What this means for hardware wallet security
The Coldcard incident is not the first hardware wallet compromise. Ledger faced a database breach in 2020 that exposed customer information. Trezor disclosed a physical extraction vulnerability in 2023. But those incidents involved either metadata exposure or physical access requirements. The Coldcard bug is different because it undermines the fundamental security promise of the device: that it generates truly random private keys.
The timing compounds the damage. The incident arrives as bitcoin trades near all time highs, and institutional adoption of self custody solutions has accelerated. Companies and family offices that selected Coldcard specifically for its security reputation now face an urgent operational decision: migrate funds on potentially compromised keys while racing against an attacker who may have already computed those keys.
The incident challenges several assumptions that the bitcoin community has treated as foundational. The assumption that open source firmware is inherently more secure than proprietary firmware because it can be audited. The assumption that hardware random number generators in dedicated bitcoin devices are more trustworthy than software alternatives. The assumption that a device focused exclusively on bitcoin, rather than supporting multiple cryptocurrencies, will have a simpler and therefore more auditable codebase.
None of these assumptions are wrong in principle. They are wrong only as absolutes. Open source firmware can be audited, but it was not audited effectively. Hardware random number generators are more trustworthy, but only when the build system actually links to them. A bitcoin only codebase is simpler, but simplicity did not prevent a five year old bug from going undetected.
The practical lesson is that hardware wallets should not be treated as the sole custodial layer for significant bitcoin holdings. Multisignature arrangements that distribute keys across multiple devices from different manufacturers, combined with independently generated entropy sources, provide defense in depth that no single device can match. The Coldcard incident demonstrates that even the most trusted device can fail in ways that are invisible to the user until the funds are gone.
The broader question is whether the hardware wallet industry’s security review processes are adequate for the assets they protect. A $38 million loss from a single firmware bug suggests they are not. The self custody model that bitcoin advocates promote requires custodial tools that meet a standard of reliability comparable to the banking infrastructure they seek to replace. After Coldcard, that standard has not been met.
What to watch
- The attacker’s movement of the 562 BTC consolidation. Whether the funds are mixed, sent to exchanges, or held in place will provide information about the attacker’s sophistication and jurisdiction. Chain analysis firms are already monitoring the address.
- Additional affected wallets beyond the initial 500. The attacker may have computed keys for additional wallets but chose not to sweep them simultaneously. The total exposure across all affected Coldcard models could be significantly larger than the initial $38 million.
- The pace of user migration. Coinkite cannot force users to generate new seeds. The number of wallets that remain on compromised seeds after 30, 60, and 90 days will indicate how effectively the advisory reached the affected user base.
- Regulatory response. A $38 million loss caused by a manufacturer’s firmware bug in a consumer financial product would trigger regulatory action in traditional finance. Whether consumer protection agencies or financial regulators respond to this incident will signal how governments classify hardware wallets.
- Competing manufacturers’ security disclosures. Block, Trezor, and Ledger have confirmed they are unaffected. Whether they publish detailed technical analyses of their own entropy generation processes will indicate whether the industry treats this as a Coldcard specific failure or a systemic review opportunity.
Frequently asked questions
How much bitcoin was stolen in the Coldcard exploit?
Approximately 594 BTC, worth roughly $38 million, was drained from about 500 Coldcard hardware wallets in 25 minutes on July 31, 2026. The funds were consolidated into a single address holding 562 BTC.
What caused the Coldcard vulnerability?
A build error in Coldcard’s firmware caused seed generation to use a software random number fallback from MicroPython instead of the hardware random number generator. A preprocessor guard checked only whether a configuration setting was defined, not its value, so the build linked to the wrong implementation without warning.
How weak were the affected seeds?
Mk3 seeds had approximately 40 bits of effective entropy instead of the intended 128 bits. Mk4, Q, and Mk5 seeds had approximately 72 bits due to additional entropy from their secure elements. A 40 bit key space is brute forceable with commodity hardware.
Does updating the firmware fix the problem?
No. Updating the firmware corrects future seed generation but does not repair a seed already created on affected firmware. Users must generate a new seed on patched hardware and migrate all funds to the new wallet.
Which Coldcard models are affected?
Every current model is affected to some degree. The Mk3 is most severely affected at 40 bits of entropy. The Mk4, Mk5, and Q are affected at approximately 72 bits. Tapsigner, Opendime, and Satscard use different code and are not affected.
Are other hardware wallets affected?
Block, Trezor, and Ledger have confirmed their products are not affected. Block published an independent technical analysis. Trezor said its devices use a different entropy generation approach. The vulnerability is specific to Coldcard’s firmware build process.
Did Coinkite know about the bug before the attack?
Coinkite says it discovered the flaw and published an advisory on July 30, after the bug was reported. The company says it ran an AI review of its firmware weeks before the attack and the review did not find the issue. The bug had been present since March 2021.
What should Coldcard owners do now?
Update to the latest firmware for your model. Generate a new seed on the patched device. Verify the backup and a receive address. Send a test transaction. Move remaining funds. Users who added at least 50 independent dice rolls during original seed generation may not need to migrate, but Coinkite recommends migrating regardless.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. The information presented reflects publicly available data as of July 31, 2026. Readers should conduct their own research and consult qualified professionals before making security or custody decisions.
Crypto World
Bitcoin price tests $63K as ETF outflows hit $265M
Bitcoin price hovered near $63,000 on Aug. 1 as US ETF outflows, weakening momentum and regulatory uncertainty kept buyers on the sidelines.
Summary
- Bitcoin price is testing the $63,150 Fibonacci support after retreating from July’s $66,900 high.
- US spot Bitcoin ETFs recorded $265 million in net outflows on July 31.
- 4-hour money flow fell to −0.22, indicating sustained selling pressure.
- Liquidation clusters near $62,000 and $65,000 could shape Bitcoin’s next move.
Bitcoin price struggles to hold $63,000
According to data from crypto.news, Bitcoin (BTC) price traded at approximately $63,082 at the time of writing after briefly falling below $63,000 during the latest selloff. The asset has now erased most of its recovery from the July 21 high near $66,900.
The daily chart places Bitcoin directly below the 78.6% Fibonacci retracement level at $63,150. This level is measured from the decline between the May peak of $82,492 and the June low of $57,884.

A daily close below $63,150 would confirm that buyers failed to defend the retracement level. Bitcoin could then retest the $62,000 area, followed by the psychological $60,000 support if selling accelerates.
Holding the current zone would leave room for another consolidation phase. However, Bitcoin must recover above $64,000 before the immediate pressure begins to ease.
Bitcoin momentum indicators turn bearish
Momentum readings on the daily and 4-hour charts favor sellers.
Bitcoin’s daily relative strength index has fallen to 45.12, below its moving average of 51.99. The reading is not yet oversold, meaning the market could decline further before reaching conditions that typically attract dip buyers.
The daily moving average convergence divergence indicator has also produced a bearish setup. The MACD line has crossed below its signal line, while the histogram has moved into negative territory at −218.84.
On the 4-hour chart, Bitcoin is trading below the Bollinger Band midpoint at $63,886 and close to the lower band at $62,489. The upper band near $65,284 marks the first major volatility-based resistance.

Chaikin Money Flow has dropped to −0.22 on the same timeframe. The negative reading indicates that capital is leaving Bitcoin as it trades near support, reducing the strength of any short-term recovery attempt.
ETF outflows add pressure on Bitcoin
US spot Bitcoin ETFs posted a combined net outflow of approximately $265 million on July 31, according to SoSoValue data.
BlackRock’s iShares Bitcoin Trust led the withdrawals with $123 million in net outflows. Fidelity’s FBTC followed with approximately $54.8 million.
The daily outflow ended a two-session inflow streak and showed that institutional demand remained fragile at the start of August. Total assets held by the US spot Bitcoin ETFs stood at approximately $76.29 billion, equivalent to 6.04% of Bitcoin’s market value.
Traders are also monitoring the CLARITY Act negotiations in Washington. The White House is expected to review a bipartisan ethics proposal as lawmakers seek enough support to move the market structure bill forward before the Senate’s August recess.
Polymarket traders placed the probability of the CLARITY Act becoming law in 2026 at just 27% on Aug. 1. Prediction-market odds reflect trader positioning rather than a reliable legislative forecast, but the decline points to limited confidence that lawmakers will resolve their differences quickly.

Liquidation map identifies $62K and $65K targets
Bitcoin’s one-week liquidation heatmap shows large concentrations of leveraged positions on both sides of the current price.

The nearest downside liquidity cluster sits around $62,000. A break below the 4-hour lower Bollinger Band at $62,489 could push Bitcoin toward this area as long positions are forced to close.
A smaller concentration appears near $63,300, which could act as an immediate target during a rebound. Above that level, the strongest nearby short-liquidation zones extend from approximately $65,000 to $66,000.
These concentrations can attract price as exchanges close leveraged positions, but they do not guarantee direction. Bitcoin could first sweep liquidity below $63,000 before attempting to recover, particularly while money flow remains negative.
Can Bitcoin price rebound toward $65,000?
Bitcoin needs to reclaim the 4-hour Bollinger midpoint near $63,886 to establish an initial recovery signal. A move above $64,000 would open a path toward $65,000 and the upper Bollinger Band at $65,284.
Clearing that area could trigger short liquidations and allow Bitcoin to retest $65,800 to $66,000. The broader recovery would remain incomplete until price breaks above the July high near $66,900 and the 0.618 Fibonacci level at $67,284.
Crypto analyst Ali Martinez also identified a TD Sequential sell signal on Bitcoin’s three-day chart.
“Bitcoin is flashing a warning sign,” Martinez said, adding that the signal appeared shortly before the start of August.
The TD Sequential attempts to identify trend exhaustion, but it does not independently confirm a decline. Bitcoin’s reaction at $63,150, ETF demand, and developments around the CLARITY Act will provide more immediate signals.
A sustained break below $62,000 would weaken the outlook and expose $60,000, followed by the June low near $57,884. Conversely, a recovery above $65,284 would reduce the immediate bearish pressure and shift attention back toward $67,284.
Disclosure: This article does not represent investment advice. The content and materials featured on this page are for educational purposes only.
Crypto World
Tether’s $1.5 billion Q2 profit and the reserve buffer problem
Tether earned $1.5 billion in three months while its safety cushion fell by half, raising questions about whether the world’s largest stablecoin can sustain its reserve strategy through a rate cycle.
Summary
- Tether reported $1.5 billion in net operating profit for the second quarter of 2026, driven primarily by returns from US Treasury holdings and repurchase agreement operations.
- The company’s excess reserves fell from a record $8.23 billion at the end of Q1 to $4.11 billion at the end of Q2, a decline of approximately 50% in three months.
- USDT supply reached $184.6 billion, representing more than 60% of the global stablecoin market, while net issuance grew by only $446 million during the quarter.
- Tether increased its gold holdings by 14 tons to 146.2 metric tons and its bitcoin holdings to 98,933 BTC, but both positions lost value as gold fell 15% and bitcoin declined from $68,200 to $58,600 during the period.
- The KPMG audit that began in March 2026 continues without a completion date, and the GENIUS Act’s 2028 compliance deadline creates a regulatory clock that Tether has not yet publicly addressed.
The numbers look strong. Tether generated $1.5 billion in net operating profit during the second quarter of 2026, according to its latest attestation prepared by BDO and released on July 31. The stablecoin issuer’s total assets stood at $187.75 billion against $183.64 billion in liabilities. USDT retained more than 60% of the global stablecoin market. By every headline metric, the quarter was a success.
But the headline metrics obscure a structural shift in Tether’s balance sheet that deserves closer examination. The company’s excess reserves, the buffer between what Tether owns and what it owes to USDT holders, fell from $8.23 billion to $4.11 billion in a single quarter. That is a 50% decline in the safety cushion that Tether has spent years building. A company that earned $1.5 billion in profit somehow ended the quarter with half the reserve buffer it started with.
The explanation involves gold, bitcoin, secured lending, and the fundamental question of what a stablecoin issuer’s balance sheet should look like. Tether’s Q2 results reveal a company caught between its role as the infrastructure layer for global dollar access and its ambition to operate as a diversified financial conglomerate.
Where $4 billion went
The arithmetic of the reserve decline is straightforward. Tether entered Q2 with $8.23 billion in excess reserves. It earned $1.5 billion in operating profit. Without any other changes, the buffer should have grown to approximately $9.7 billion. Instead, it fell to $4.11 billion. That implies roughly $5.6 billion in value left the balance sheet through some combination of unrealized losses, capital deployment, and operational expenditure.
The two largest contributors were gold and bitcoin. Tether increased its gold holdings from 132.2 metric tons to 146.2 metric tons during the quarter, purchasing approximately 14 additional tons. But the price of gold fell roughly 15% to just above $4,000 per ounce during the same period. The result: the value of Tether’s gold position declined from $19.84 billion to $18.84 billion despite the company buying more of it. The net loss on gold was approximately $1 billion.
Bitcoin told a similar story. Tether added 1,796 BTC to reach a total of 98,933 coins. But the bitcoin price used in the attestation declined from $68,200 to $58,600 during the quarter. The value of the bitcoin position fell from $6.62 billion to $5.80 billion, a decline of approximately $820 million despite the additional purchases.
Between gold and bitcoin alone, Tether absorbed roughly $1.8 billion in unrealized losses during Q2. Combined with the capital deployed to purchase additional gold and bitcoin, the expansion of the USAT stablecoin infrastructure, and operating expenses, the $5.6 billion gap between expected and actual reserve growth becomes explicable. But explicable is not the same as comfortable.
The secured lending reduction added another dimension. Tether cut its outstanding secured loans by approximately $2.38 billion, a 15% decline. Reducing secured lending is generally positive for reserve quality because it replaces counterparty risk with direct asset holdings. But the timing of the reduction, during a quarter when the reserve buffer was already under pressure from mark to market losses, suggests that some of the lending reduction may have been involuntary. Tether did not disclose the identities of borrowers or the collateral involved, leaving analysts to speculate about whether loans were called, matured, or deliberately wound down.
The net effect is a balance sheet that looks materially different from three months earlier. At the end of Q1, Tether could point to $8.23 billion in excess reserves as evidence that USDT holders had a substantial cushion beyond dollar for dollar backing. At the end of Q2, that cushion is half the size despite continued profitability. The trajectory matters more than any single quarter’s snapshot.
The reserve composition question
Tether’s reserve strategy has evolved significantly over the past three years. The company has shifted the majority of its reserves into US Treasury securities and short duration government debt, a move that addressed years of criticism about the transparency and quality of its backing. The Treasury portfolio is now the primary source of Tether’s operating profit and the foundation of its claim that USDT is fully backed by liquid, high quality assets.
But Tether has simultaneously built substantial positions in gold and bitcoin, assets that do not generate yield and are subject to significant price volatility. At the end of Q2, Tether held approximately $18.84 billion in gold and $5.80 billion in bitcoin. Together, these positions represented roughly $24.6 billion, or about 13% of total assets.
For a company whose core obligation is maintaining a 1:1 peg to the US dollar, holding 13% of reserves in volatile non dollar assets creates a structural tension. When gold and bitcoin rise, the excess reserve buffer expands and Tether looks increasingly overcollateralized. When they fall, as they did in Q2, the buffer shrinks rapidly even as the operating business continues to generate profit.
The question is whether Tether’s reserve strategy is optimized for the stablecoin business or for Tether the company. A pure stablecoin issuer would hold 100% of reserves in short duration dollar denominated instruments, maximizing liquidity and minimizing volatility. Tether’s choice to hold gold and bitcoin reflects a different objective: building long term value for the company’s owners beyond the stablecoin operation itself.
The interest rate dependency
Tether’s $1.5 billion quarterly profit depends almost entirely on one variable: the yield on short term US government debt. The company earns its revenue by holding USDT holders’ dollars in Treasury bills and repo agreements. When rates are high, Tether is extraordinarily profitable. When rates fall, that profit declines proportionally.
The Federal Reserve’s current policy rate makes Tether one of the most profitable financial operations in the world on a per employee basis. The company reportedly has fewer than 100 employees. Its annualized revenue per employee exceeds $60 million, a figure that dwarfs the most profitable technology companies. But this profit model has no moat. It depends on a macroeconomic condition, high US interest rates, that Tether cannot control and that most economists expect to reverse over the next 12 to 24 months.
Paolo Ardoino, Tether’s CEO, framed Q2 as evidence of resilience. “Through all of the volatility, USDT remained fully backed with our reserves still exceeding liabilities by $4.11 billion,” he said in the company’s statement. The framing is technically accurate. But “fully backed” and “safely buffered” are different standards, and the Q2 results expose the gap between them.
If the Fed cuts rates by 200 basis points over the next year, Tether’s annualized operating profit would fall from approximately $6 billion to roughly $3 billion, assuming constant USDT supply. That is still an enormous figure, but the trajectory matters. A declining profit stream makes it harder to rebuild the reserve buffer, fund expansion projects, and maintain the gold and bitcoin positions that have already demonstrated their ability to consume billions in unrealized losses during a single quarter.
The GENIUS Act’s 2028 compliance deadline adds a regulatory dimension to the interest rate question. If Tether must restructure its reserves or operations to comply with US stablecoin legislation, the cost of compliance will arrive precisely when falling rates are already compressing margins.
The audit that has not arrived
Tether announced in March 2026 that it had engaged KPMG to conduct its first full financial audit. The engagement was widely reported as a milestone for a company that had faced years of criticism for relying on quarterly attestations from smaller accounting firms rather than a comprehensive audit from a Big Four firm.
Five months later, the KPMG audit has not been completed. Tether’s Q2 attestation was again prepared by BDO, the same firm that has handled previous attestations. The Q2 release stated that “the Big Four audit process continued” but provided no completion date, interim findings, or timeline.
An attestation and an audit are fundamentally different exercises. An attestation verifies that a company’s stated financial figures are accurate at a specific point in time. An audit examines the company’s financial statements, internal controls, and accounting practices over a full reporting period. The distinction matters because an attestation can confirm that Tether held $187.75 billion in assets on June 30 without examining how those assets were managed, valued, or moved during the preceding 90 days.
The delay is not necessarily a red flag. Big Four audits of complex financial institutions routinely take 12 to 18 months. But the absence of a timeline creates uncertainty that compounds with each quarterly attestation that arrives without the audit attached. Tether’s competitors, including Circle, which issues USDC, already publish audited financial statements. The longer the KPMG process takes without a public update, the more the engagement risks becoming a liability for Tether’s credibility rather than an asset. If the audit eventually produces a clean opinion, the delay will be forgotten. If it surfaces material findings or qualifications, the five month silence will look like a warning that the market ignored.
The competitive landscape
Tether’s 60% market share is formidable but not unassailable. USDC, issued by Circle, has grown steadily and now represents approximately 25% of the stablecoin market. Circle completed its IPO in early 2026 and publishes regular financial disclosures as a public company. For institutional users who require audited counterparties, Circle’s transparency advantage is significant.
The emerging regulatory framework in the United States may further reshape the competitive landscape. The GENIUS Act, if enacted in its current form, would require stablecoin issuers serving US customers to meet specific reserve, disclosure, and compliance standards. Tether’s offshore corporate structure, domiciled in El Salvador, could complicate its ability to meet these requirements without significant restructuring.
Meanwhile, new entrants continue to arrive. PayPal’s PYUSD has captured modest market share. Banks including JPMorgan and Bank of America have launched or announced proprietary stablecoin products. The common thread among these competitors is that they operate within established regulatory frameworks, a characteristic that could become a decisive advantage as stablecoin regulation matures.
Tether’s response has been to expand beyond stablecoins entirely. The company has invested in bitcoin mining, artificial intelligence infrastructure, and telecommunications. It has also launched USAT, a US focused stablecoin that recently deployed on Celo as its second mainnet. These diversification efforts may generate value over time, but they also consume capital that could otherwise strengthen the reserve buffer. In Q2, the buffer declined while the company continued to fund expansion.
The private ownership structure adds another layer of complexity. Unlike Circle, which must answer to public shareholders, Tether operates with minimal external governance. The company’s capital allocation decisions, including the choice to hold nearly $25 billion in gold and bitcoin, are made by a small group of executives and owners without the scrutiny that comes with public listing. The Q2 reserve decline occurred under conditions that a public company board would likely have flagged for discussion well before the buffer halved.
The $184.6 billion question
USDT supply grew by only $446 million during Q2, the slowest quarterly growth in more than two years. For a token that added tens of billions in supply during 2024 and early 2025, the near stagnation is notable. The slowdown occurred despite continued growth in Tether’s user base, which the company said expanded by more than 30 million users during the quarter.
The disconnect between user growth and supply growth suggests that new USDT users are transacting in smaller amounts or using the token primarily for payments and transfers rather than as a store of value. That is consistent with Tether’s narrative about serving the unbanked and providing dollar access in emerging markets. But it also means the USDT supply, and therefore Tether’s revenue base, may be approaching a plateau at current interest rates and market conditions.
The 30 million new users Tether cited represent a significant expansion of its reach, particularly in regions where traditional banking infrastructure is limited or where local currencies face sustained devaluation. Tether has actively pursued partnerships in Africa, Latin America, and Southeast Asia to position USDT as everyday payment infrastructure. The Nairobi Securities Exchange memorandum of understanding, signed on July 28, is the latest example of this strategy. But payment volume and stablecoin supply are different metrics. A user who receives $50 in USDT, spends it within hours, and never holds a balance contributes to transaction volume but not to the outstanding supply that generates Tether’s revenue.
The slowdown in supply growth also coincides with increased competition from USDC in institutional and regulated markets. As Circle’s public listing provides greater transparency and US based stablecoin legislation approaches, some institutional flows that previously favored USDT may be shifting to USDC or emerging alternatives. Tether’s dominance in retail and emerging market payments remains unchallenged, but the marginal growth that drives supply expansion may increasingly come from segments where per user balances are small.
If USDT supply growth has stalled while the reserve buffer is declining, Tether faces a narrowing path. The company needs strong operating profits to rebuild reserves. Those profits depend on high interest rates and growing supply. Rates are expected to fall. Supply growth has slowed. The buffer is the variable that absorbs the difference.
At $4.11 billion, the excess reserve buffer represents approximately 2.2% of USDT’s total supply. That is a thin margin for a $184.6 billion obligation, particularly when 13% of the backing assets are subject to significant price volatility. The record $8.23 billion buffer reported at the end of Q1 provided a 4.5% cushion. The halving of that cushion in a single quarter demonstrates how quickly market conditions can erode what took years to build.
What to watch
- The KPMG audit timeline. Tether has said the process is ongoing but has not provided a completion date. The first audited financial statement from Tether would be a watershed event for stablecoin transparency. Continued delays without explanation will erode the credibility advantage the engagement was intended to create.
- Gold and bitcoin price movements in Q3. If gold and bitcoin recover in the third quarter, Tether’s reserve buffer will expand mechanically without any operational improvement. If they decline further, the buffer could fall below $3 billion, a level that would intensify scrutiny from regulators and analysts.
- Federal Reserve rate decisions. Each 25 basis point cut reduces Tether’s annualized operating profit by approximately $450 million. The timing and pace of rate cuts will determine whether Tether can maintain its current profit trajectory or faces a structural decline in earnings.
- USDT supply growth trajectory. Whether the $446 million quarterly growth in Q2 was a temporary slowdown or the beginning of a plateau will shape Tether’s revenue outlook for the next 12 months. Supply growth in Q3 will provide a clearer signal.
- GENIUS Act implementation timeline. The 2028 compliance deadline gives Tether approximately 18 months to determine whether and how to restructure for US market access. Any public statements about compliance strategy will signal whether Tether intends to compete directly in the US or cede that market to regulated competitors.
Frequently asked questions
How much profit did Tether make in Q2 2026?
Tether reported approximately $1.5 billion in net operating profit for the second quarter of 2026, according to its BDO attestation released July 31. The profit was driven primarily by returns from US Treasury holdings and repurchase agreement operations.
Why did Tether’s reserve buffer fall by half?
The excess reserve buffer declined from $8.23 billion to $4.11 billion primarily due to unrealized losses on gold and bitcoin holdings. Gold fell approximately 15% and bitcoin declined from $68,200 to $58,600 during the quarter, erasing roughly $1.8 billion in value from those positions alone. Additional capital deployment and operating expenses accounted for the remainder.
How much gold does Tether hold?
Tether held approximately 146.2 metric tons of physical gold at the end of Q2 2026, valued at roughly $18.84 billion. The company added 14 tons during the quarter, increasing from 132.2 tons, but the value of its gold position declined by about $1 billion due to falling gold prices.
How much bitcoin does Tether own?
Tether held 98,933 BTC at the end of Q2 2026, valued at approximately $5.80 billion. The company added 1,796 coins during the quarter. The value of the position declined from $6.62 billion due to bitcoin’s price falling from $68,200 to $58,600 during the period.
What is the current USDT supply?
USDT supply reached approximately $184.6 billion at the end of Q2 2026, representing more than 60% of the global stablecoin market. Supply grew by only $446 million during the quarter, the slowest quarterly growth in more than two years.
Has Tether completed its Big Four audit?
No. Tether engaged KPMG in March 2026 to conduct its first full financial audit, but the process has not been completed. The Q2 attestation was again prepared by BDO. Tether said the Big Four audit process is continuing but provided no completion date.
How does Tether make money?
Tether earns revenue primarily by investing USDT holders’ dollars in US Treasury securities and repurchase agreements. The interest earned on these investments constitutes the company’s operating profit. At current interest rates, this model generates approximately $6 billion in annualized profit.
What is the GENIUS Act and how does it affect Tether?
The GENIUS Act is proposed US legislation that would establish regulatory requirements for stablecoin issuers serving US customers. If enacted, it would impose reserve, disclosure, and compliance standards with a 2028 deadline. Tether’s offshore corporate structure could complicate its ability to meet these requirements without significant restructuring.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. The information presented reflects publicly available data as of August 1, 2026. Readers should conduct their own research and consult qualified professionals before making financial decisions.
Crypto World
difficulty falls 19.9% as miners pivot to AI
Bitcoin mining difficulty has dropped 19.9% from its peak in the third deepest ASIC era decline on record, as miners sell bitcoin at record rates and redirect power capacity toward artificial intelligence data centers.
Summary
- Bitcoin mining difficulty has fallen 19.9% from its November 2025 peak of approximately 156 trillion to 126.23 trillion, the third deepest decline since dedicated ASIC hardware replaced graphics processors.
- Network hashrate declined roughly 12% from its late 2025 peak above one zettahash per second to approximately 868 exahashes per second by late July 2026, with Bitcoin Magazine Pro tracking 287 consecutive days of downward trend.
- Publicly traded miners sold more than 32,000 BTC in the first quarter of 2026 alone, exceeding their combined sales for all of 2025 and surpassing the 20,000 BTC sold during the 2022 Terra Luna collapse.
- Major mining companies including Hut 8, Core Scientific, and TeraWulf have signed multi billion dollar AI data center agreements, with Hut 8’s total contracted AI portfolio reaching $26.6 billion.
- Mining stocks have diverged from bitcoin’s price, with a basket of mining equities gaining 56% in early 2026 while bitcoin fell 17%, as investors increasingly value miners as energy infrastructure companies.
Bitcoin mining difficulty has dropped 19.9% from its all time peak. That single number captures a transformation that has been building for months but accelerated through the first half of 2026: the economics of mining bitcoin have deteriorated to the point where a meaningful share of the global fleet has shut down, and the operators that remain are increasingly looking beyond bitcoin for revenue.
The decline, tracked by Bitcoin Magazine Pro from the November 2025 peak of roughly 156 trillion to 126.23 trillion as of the July 25 adjustment, ranks as the third deepest drawdown since application specific integrated circuits became the standard mining hardware. Only the aftermath of China’s 2021 mining ban and a 2018 bear market contraction produced deeper declines. But unlike those episodes, this one has no single policy catalyst. It is the compound result of a lower bitcoin price, rising energy costs, post halving revenue compression, and a structural shift in how mining companies view their own business.
The capitulation is visible across every metric: hashrate, difficulty, miner selling, and hashprice. What makes this cycle different is what comes next. The miners who survive are not simply waiting for higher bitcoin prices. They are converting their facilities into AI data centers.
How difficulty measures mining health
Bitcoin’s difficulty adjustment is one of the protocol’s most elegant mechanisms. Every 2,016 blocks, roughly every two weeks, the network recalculates how hard it is to mine a new block. If blocks arrived faster than one every ten minutes during the previous epoch, difficulty increases. If they arrived slower, difficulty decreases. The system exists to keep block production steady regardless of how much computing power is pointed at the network.
When difficulty falls, it means hashrate has left the network. Miners have switched off machines, either because their operating costs exceed their revenue or because they have found more profitable uses for their power capacity. A falling difficulty makes mining easier for the operators who remain, temporarily improving their economics until the incentive draws hashrate back.
The current 19.9% decline from peak is notable for both its depth and duration. Bitcoin Magazine Pro’s data shows the downward trend extending approximately 287 days, making it one of the longest sustained mining contractions in bitcoin’s history. The July 25 adjustment of negative 0.74% was the ninth downward adjustment of 2026. The previous major drop in June was 10.09%, which ranked as bitcoin’s 11th largest single downward adjustment ever, reducing difficulty from 138.96 trillion to 124.93 trillion.
Difficulty has also turned negative on a year over year basis for only the second time in bitcoin’s history. The previous instance followed China’s 2021 mining ban, when authorities forced an estimated 50% of global hashrate offline in a matter of weeks. That comparison is instructive: the current decline has reached similar severity without any government ban, driven entirely by market forces.
The economics behind the shutdown
The fundamental problem is arithmetic. After the April 2024 halving, miners receive 3.125 BTC per block, half what they earned before. That reduction was expected. What was not expected was that bitcoin’s price would fail to compensate.
Bitcoin traded near $63,100 on July 31, down approximately 47% over 12 months and nearly 50% below its October 2025 record. For miners, this price decline arrives on top of the halving’s structural revenue cut. The combined effect has been devastating for operators running older hardware or paying higher electricity rates.
The math is stark. Before the halving, a miner producing one block earned 6.25 BTC. At bitcoin’s October 2025 peak near $120,000, that block was worth $750,000. Today, the same miner earns 3.125 BTC per block at a price near $63,100, yielding approximately $197,000. That is a 74% decline in per block dollar revenue in less than a year. No industry can absorb that kind of revenue compression without significant operational fallout.
Transaction fees, which historically provide a secondary revenue stream for miners, have not offset the decline. Fee revenue as a percentage of total mining revenue has remained in the low single digits through most of 2026, well below the spikes that accompanied the inscription boom in late 2023 and early 2024. The fee market has normalized, removing what had briefly appeared to be a structural supplement to block rewards.
Hashprice, which measures the expected daily revenue from one petahash of computing power, stood near $32 per PH/s per day in late July. That figure sits below the breakeven threshold for many operations. CoinShares estimated in March 2026 that 15% to 20% of the global mining fleet was operating at a loss. Older machines, including models from the Antminer S19 generation, cannot generate positive cash flow at current prices unless operators have electricity costs below approximately five cents per kilowatt hour.
The result is a fleet rationalization. Miners with newer hardware, primarily the Antminer S21 and comparable models, continue to operate profitably at current prices. Miners with older hardware and higher power costs are shutting down, selling their bitcoin reserves, or converting their facilities to other uses. The 12% decline in hashrate from the late 2025 peak of over one zettahash per second to approximately 868 EH/s by late July reflects this ongoing culling.
Record bitcoin sales by miners
The selling pressure from mining companies has been extraordinary. Publicly traded miners sold more than 32,000 BTC in the first quarter of 2026, a single quarter record that exceeded their combined sales for all of 2025. The total also surpassed the roughly 20,000 BTC sold during Q2 2022, when the Terra Luna collapse sent bitcoin below $20,000.
The individual disclosures paint a clear picture of the pressure. Riot Platforms sold 3,778 BTC in Q1 at an average price near $76,626, generating approximately $289.5 million, while producing only 1,473 coins in the same period. Core Scientific liquidated roughly 1,900 BTC worth about $175 million in January alone. Cango sold 2,000 BTC in March for approximately $143 million, using proceeds to retire bitcoin backed loans.
In a single week during Q1, MARA, Genius Group, and Nakamoto Holdings revealed combined sales of more than 15,000 coins. These were not routine sales of freshly mined production to cover electricity bills. They were drawdowns of treasury reserves that companies had previously chosen to hold.
The aggregate miner reserve, the total bitcoin held by mining companies, has been declining since 2023. It fell from more than 1.86 million BTC at the end of that year toward roughly 1.8 million by mid 2026. The sustained drawdown suggests that this is not opportunistic selling but a structural shift in how mining companies manage their balance sheets.
The selling also reflects the debt burden that many miners accumulated during the 2024 and early 2025 expansion cycle. Companies borrowed against their bitcoin holdings and future production to finance fleet upgrades and facility construction. As bitcoin’s price fell and revenue declined, those loans required either refinancing at unfavorable terms or liquidation of the bitcoin collateral. Cango’s March sale of 2,000 BTC was explicitly used to retire bitcoin backed loans, a pattern that has repeated across the industry.
The irony is that miner selling itself contributes to the price pressure that makes mining less profitable. When miners sell tens of thousands of bitcoin into the market over a single quarter, they add supply at a time when demand is already weakened by broader market conditions. The selling becomes self reinforcing: lower prices lead to more selling, which pushes prices lower, which forces more machines offline, which triggers more selling of treasury reserves to cover fixed costs.
The AI pivot
The most significant development in the mining industry is not about bitcoin at all. It is about artificial intelligence.
Mining companies operate large scale power infrastructure in locations with grid access, cooling capacity, and favorable energy contracts. Those same characteristics are exactly what AI data center operators need. The realization has transformed the investment thesis for publicly traded miners, turning them from pure bitcoin proxies into energy infrastructure companies.
Hut 8 provides the most dramatic example. The company signed a second 15 year lease on July 20 for 352 megawatts at its Beacon Point campus in Texas. The agreement raised the campus’s base term contract value to $19.6 billion and Hut 8’s total contracted AI portfolio to $26.6 billion. Initial delivery for the second phase is scheduled for Q2 2028. Hut 8’s shares more than quadrupled over the preceding 12 months and rose 11% after the announcement.
Core Scientific followed on July 28 with an AMD partnership anchored by 15 year agreements covering approximately 530 MW. The company said its total leased customer capacity had reached roughly 1.1 GW, representing more than $24 billion in potential contracted revenue.
TeraWulf’s transition is already generating revenue. The company reported $21 million in AI and high performance computing hosting revenue in Q1 2026, surpassing its bitcoin mining revenue of less than $13 million for the first time. HIVE Digital announced a $2.55 billion AI super factory project near Toronto designed to host more than 100,000 GPUs.
The scale of these AI commitments dwarfs the bitcoin mining operations they are displacing. Hut 8’s $26.6 billion in contracted AI revenue over 15 years exceeds what the company could plausibly earn from bitcoin mining over the same period at current prices and difficulty levels.
The pivot is not limited to North America. Mining operators in the Nordics, the Middle East, and parts of Central Asia are exploring similar conversions, attracted by the same logic: AI workloads pay more per megawatt hour than bitcoin mining and provide contractual revenue certainty that bitcoin mining cannot offer. A 15 year lease agreement with a hyperscaler eliminates the price volatility, halving risk, and difficulty uncertainty that define the bitcoin mining business.
The infrastructure requirements are different, however. AI data centers need higher power density, better cooling, more reliable uptime guarantees, and enterprise grade networking that most mining facilities were not built to provide. The conversion from mining to AI hosting requires significant capital expenditure, which is part of why miners are selling bitcoin reserves and issuing equity. The transition is not free, and companies that underestimate the engineering and capital requirements may find themselves stuck between a declining mining business and an AI hosting business that is not yet ready to generate revenue.
Why mining stocks diverged from bitcoin
The AI pivot has broken the historical relationship between mining stocks and bitcoin’s price. A basket of bitcoin mining equities gained 56% during the early months of 2026 while bitcoin fell 17%, according to research cited by industry analysts. That divergence would have been unthinkable two years ago, when mining stocks moved in lockstep with bitcoin’s price, only with greater amplitude.
Investors are now valuing these companies on their power contracts, real estate, and AI revenue potential, not on their bitcoin production. The market is pricing in a future where bitcoin mining is a secondary revenue stream for companies whose primary business is providing power and infrastructure for artificial intelligence workloads.
This creates an ironic dynamic for bitcoin’s network security. The same companies that built the infrastructure securing the bitcoin network are now economically incentivized to redirect that infrastructure toward AI. Every megawatt that moves from mining to AI hosting reduces the hashrate protecting bitcoin’s blockchain. The difficulty adjustment compensates for the loss automatically, but the trend raises questions about the long term security implications if mining becomes a marginal activity for what were once dedicated mining companies.
The counterargument is that the AI revenue stream makes these companies more financially resilient, which ultimately benefits the bitcoin network. A mining company with $26 billion in contracted AI revenue can afford to keep mining bitcoin through price downturns that would force a pure play miner to shut down entirely. The AI business subsidizes the mining operation.
The historical parallel is not perfect, but it is instructive. After the 2021 China ban, difficulty dropped more than 50% before recovering within months as displaced miners relocated and reconnected. That episode proved that bitcoin’s difficulty adjustment mechanism works as designed: when enough hashrate leaves, difficulty falls until mining becomes profitable again for the remaining operators, creating an economic incentive for hashrate to return. The current episode tests whether the same self correcting mechanism applies when the departure of hashrate is driven not by a ban but by a better economic opportunity. Miners who leave for AI may not return even if bitcoin prices recover, because the AI revenue exceeds what bitcoin mining can offer.
What capitulation historically signals
Miner capitulation has historically preceded bitcoin price recoveries. The logic is straightforward: when the weakest miners shut down and sell their reserves, the selling pressure eventually exhausts itself. Difficulty falls, making mining cheaper for survivors. The supply of newly mined bitcoin continues at a fixed rate regardless of hashrate, but the forced selling from distressed operators slows as those operators exit the market.
The 2022 capitulation followed this pattern. Miners sold aggressively through Q2 and Q3, difficulty fell, and by early 2023, bitcoin had begun a sustained recovery that eventually carried prices to new all time highs. Proponents of the capitulation thesis argue that the current period will resolve similarly: the pain is intense but temporary, and the difficulty adjustment ensures that mining always returns to profitability for the marginal operator.
The structural difference this time is the AI alternative. In previous cycles, sidelined mining capacity had no productive alternative use. It simply sat idle until bitcoin prices made mining profitable again. Today, that capacity has a buyer willing to pay more, which means the recovery mechanism may not function as cleanly as it has in the past.
What to watch
- The next difficulty adjustment. Whether difficulty continues to fall or stabilizes will signal whether the current round of miner shutdowns has run its course. A sustained difficulty increase would indicate that surviving miners are expanding or that sidelined operators are reconnecting.
- Q2 miner selling data. The 32,000 BTC sold in Q1 set a record. Whether Q2 selling accelerated, stabilized, or declined will indicate the severity of the remaining financial pressure on listed operators.
- Bitcoin price relative to production cost. Some analysts estimate the average production cost for the global mining fleet near $80,000. Bitcoin trading at approximately $63,100 means a significant portion of miners are operating below cost. A price recovery above $80,000 would alleviate much of the current pressure.
- AI data center construction timelines. The announced deals from Hut 8, Core Scientific, and others involve multi year construction timelines. Whether these projects proceed on schedule and begin generating revenue will determine whether the AI pivot delivers on its promise.
- Regulatory treatment of dual use facilities. Mining companies that operate both bitcoin mining and AI hosting from the same campuses may face different regulatory frameworks for each activity. How jurisdictions classify and regulate these hybrid operations could affect the economics of the pivot.
Frequently asked questions
How much has bitcoin mining difficulty dropped?
Bitcoin mining difficulty has fallen 19.9% from its all time peak of approximately 156 trillion set in November 2025 to 126.23 trillion as of the July 25, 2026 adjustment. This is the third deepest decline since dedicated ASIC mining hardware became standard.
Why is bitcoin mining difficulty falling?
Difficulty falls when miners switch off their machines, which slows block production. The current decline results from lower bitcoin prices, post halving revenue cuts, high electricity costs, and mining companies redirecting power capacity toward AI data centers.
How much bitcoin have miners sold in 2026?
Publicly traded miners sold more than 32,000 BTC in the first quarter of 2026 alone, a single quarter record. This exceeded their combined sales for all of 2025 and surpassed the roughly 20,000 BTC sold during the 2022 bear market.
What is hashprice and why does it matter?
Hashprice measures the expected daily revenue a miner earns per unit of computing power (per petahash per second). It stood near $32 per PH/s per day in late July 2026, below the breakeven threshold for many operators with older hardware.
Why are mining stocks going up while bitcoin is falling?
Mining stocks have diverged from bitcoin because investors are valuing these companies as AI and energy infrastructure operators. A basket of mining equities gained 56% in early 2026 while bitcoin fell 17%, driven by multi billion dollar AI data center contracts.
Which mining companies are pivoting to AI?
Hut 8 has $26.6 billion in contracted AI portfolio value. Core Scientific has roughly 1.1 GW in leased AI capacity worth over $24 billion. TeraWulf’s AI hosting revenue surpassed its mining revenue in Q1 2026. HIVE Digital announced a $2.55 billion AI super factory near Toronto.
What is the bitcoin mining difficulty adjustment?
The difficulty adjustment is an automatic mechanism that recalibrates how hard it is to mine a bitcoin block every 2,016 blocks, roughly every two weeks. It keeps block production steady at approximately one block every ten minutes regardless of total network hashrate.
Is bitcoin mining still profitable in 2026?
For miners with the newest hardware and low electricity costs, mining remains profitable. CoinShares estimated in March 2026 that 15% to 20% of the fleet was operating at a loss. The breakeven threshold for older machines sits near $35 per PH/s per day, above the current hashprice.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. The information presented reflects publicly available data as of August 1, 2026. Readers should conduct their own research and consult qualified professionals before making financial decisions.
Crypto World
The $4 billion Iran sanctions evasion network through crypto
The United States has sanctioned Iranian exchanges, frozen nearly $1 billion in cryptocurrency, and traced $3.84 billion in Iran-linked flows through a single offshore exchange, exposing the scale of sanctions evasion through digital assets.
Summary
- The US Treasury has sanctioned four Iranian cryptocurrency exchanges, including Nobitex, which handles approximately 50% of Iran’s crypto trading volume, as part of Operation Economic Fury launched in April 2026.
- Treasury has seized or frozen nearly $1 billion in cryptocurrency from Iranian exchanges and wallets since the US-Israeli strikes on Tehran in February, including a $344 million USDT freeze in April and a $131 million freeze in July.
- The Wall Street Journal reported that Iran-linked entities moved more than $3.84 billion through crypto exchange CoinEx since 2019, with investigators tracing flows from Central Bank of Iran wallets that connected to the North Korean Bybit hack.
- Chainalysis estimated that Iranian crypto outflows reached $4.18 billion in 2025, a 70% year over year increase, as the rial collapsed and citizens sought alternatives to the sanctioned banking system.
- The enforcement campaign reveals both the capabilities and limitations of crypto sanctions: centralized stablecoins like USDT can be frozen by issuers, but decentralized protocols and cross chain transactions continue to provide routes for moving value beyond government control.
The numbers tell the story before the analysis begins. Nearly $1 billion in Iranian cryptocurrency seized by the US Treasury. More than $3.84 billion in Iran-linked flows traced through a single offshore exchange. Iranian crypto outflows of $4.18 billion in a single year. Four domestic Iranian exchanges sanctioned. Executives added to the OFAC list. Central Bank of Iran wallets frozen on the Tron network.
These figures, accumulated over the first half of 2026, describe the largest and most technically sophisticated sanctions enforcement campaign ever conducted through blockchain infrastructure. The US government is not merely identifying Iranian crypto activity. It is actively seizing, freezing, and blocking it at multiple points in the financial chain. The question is whether the campaign is working or whether it is simply documenting the scale of a problem it cannot contain.
The answer is probably both. The United States has developed meaningful new tools for sanctions enforcement on public blockchains, and it is deploying them at unprecedented scale. At the same time, the gap between what investigators can see and what they can stop is wide and growing. Iranian crypto activity grew 70% year over year in 2025 even as US surveillance capabilities expanded. Every enforcement action generates a public record of Iranian evasion methods, which Iranian operators then adapt against. The cat-and-mouse dynamic is running faster than the enforcement side can respond.
Operation Economic Fury
The enforcement campaign has a name: Economic Fury. Treasury Secretary Scott Bessent introduced it on April 14, 2026, as the financial arm of the US response to the military conflict that began with joint US and Israeli strikes on Tehran in February. The campaign targets Iran’s use of cryptocurrency exchanges, wallets, and traditional financial networks that officials accuse of supporting sanctions evasion and military financing.
The campaign followed months of intelligence gathering that began before the military strikes. Treasury officials had been tracking Iranian crypto networks since at least 2024, when Chainalysis and TRM Labs began publishing research on the scale of Iranian stablecoin adoption. The strikes accelerated the timeline from monitoring to action.
The first major crypto action came in April, when Tether froze approximately $344 million in USDT across two Tron wallets after US authorities linked the addresses to Iranian networks. One wallet held about $213 million; the other contained roughly $131 million. Blockchain analysis found transaction patterns associated with wallets linked to Iran’s Islamic Revolutionary Guard Corps and intermediaries connected to the Central Bank of Iran.
In June, Treasury escalated by sanctioning four Iranian cryptocurrency exchanges: Nobitex, Wallex, Bitpin, and Ramzinex. Nobitex, the largest, handles approximately 50% of Iran’s cryptocurrency trading volume according to Chainalysis and claims to serve 11 million users. Treasury also added Nobitex CEO Seyed Ali Khoee and chairman Amir Hossein Rad to the OFAC sanctions list, making them personally subject to asset freezes and travel restrictions.
In July, Treasury froze an additional $131 million in USDT held in four Tron wallets tied to the Central Bank of Iran. Bessent said on X that Treasury remained “committed to disrupting and degrading Iran’s illicit financial activities, including its abuse of digital assets.”
By late July, Bessent disclosed that the cumulative total of cryptocurrency seized or frozen from Iranian sources since the conflict began had approached $1 billion. The figure, while significant, represents assets identified by investigators and does not include Iranian-linked cryptocurrency that moved through compliant exchanges and was not captured in enforcement actions.
The CoinEx connection
While Treasury focused on domestic Iranian exchanges, a parallel investigation exposed the offshore dimension of Iran’s crypto network. On June 24, the Wall Street Journal reported that Iran-linked entities had moved more than $3.84 billion through crypto exchange CoinEx since 2019.
The investigation, citing TRM Labs and public on-chain data, found that CoinEx had become one of the primary routes for moving funds outside US sanctions. More alarmingly, investigators traced activity from two wallets controlled by the Central Bank of Iran and found links to assets stolen from Bybit by North Korean hackers in what was one of the largest thefts in crypto history, involving approximately $1.5 billion in virtual assets.
CoinEx denied any knowledge of Iran-linked activity. The exchange said that on-chain fund flows through a platform do not prove knowledge, support, or participation. It also said it had strengthened Iran-related risk reviews, geo-fencing, sanctions screening, and transaction monitoring. CoinEx has not been subject to new US sanctions as of this writing, but the WSJ report placed it under heightened regulatory scrutiny.
The $3.84 billion figure is notable not just for its size but for its duration. The flows spanned seven years, from 2019 through 2026, covering periods when international attention to Iranian crypto activity was already high. The Financial Action Task Force had placed Iran on its blacklist for most of that period. The fact that billions in Iranian linked flows continued through a single exchange for seven years without triggering enforcement action until journalists reported it raises questions about the gap between blockchain transparency and operational enforcement.
TRM Labs data cited in the WSJ report also showed that CoinEx was not the only offshore exchange processing Iranian flows. Several smaller platforms with limited compliance infrastructure handled significant volumes. The concentration at CoinEx reflects the exchange’s combination of low fees, minimal identity verification requirements during the relevant period, and availability in jurisdictions where Iranian users could access the platform without VPN restrictions.
The CoinEx case illustrates a fundamental challenge in crypto sanctions enforcement. Centralized exchanges operate as choke points where authorities can intervene, but only if the exchange cooperates or is within jurisdictional reach. CoinEx is based outside US jurisdiction. Its compliance response, strengthening internal controls after public reporting, is the kind of reactive posture that allows billions in flows before any intervention occurs.
The scale of Iranian crypto adoption
The enforcement actions unfold against a backdrop of massive and growing cryptocurrency adoption within Iran. Chainalysis estimated that Iranian crypto outflows reached $4.18 billion in 2025, a 70% increase over the previous year. The surge coincided with the collapse of the Iranian rial, which lost approximately 40% of its value against the dollar during the same period, and intensifying sanctions that cut Iran further from the global banking system.
For ordinary Iranians, cryptocurrency serves the same function it serves in other countries experiencing currency devaluation and capital controls: a way to preserve savings and move value across borders. The distinction between legitimate civilian use and sanctions evasion is difficult to draw at scale, and US enforcement actions have not attempted to make the distinction. When Treasury sanctions an exchange like Nobitex that serves 11 million users, the action affects both the IRGC operative moving military funds and the shopkeeper converting rials to USDT to protect against inflation.
Reuters reported that Nobitex was founded in 2018 by brothers Ali and Mohammad Kharrazi, who used the surname Aghamir, and that the pair belong to a politically connected Iranian family. Nobitex rejected the characterization, describing itself as a private and independent company with no relationship to the IRGC, Iran’s central bank, or other state institutions.
The platform’s scale suggests that Iranian crypto activity is not a marginal phenomenon. If Nobitex alone handles 50% of Iran’s crypto trading and processes volumes proportional to the $4.18 billion in outflows that Chainalysis tracked, the total Iranian crypto economy is likely larger than what any single data provider captures.
Tron is the dominant blockchain for Iranian USDT activity, but on-chain analysis shows significant use of Ethereum-based assets and bitcoin for larger transactions. Iran’s geographic position as a major energy producer gives it access to cheap electricity that has long sustained domestic bitcoin mining. Even under US pressure, Iran’s mining industry continues to produce bitcoin that is then sold through non-compliant channels, mixing mined coins with purchased ones in ways designed to obscure provenance.
What the $4.18 billion Chainalysis figure captures is primarily exchange-mediated activity. Peer-to-peer crypto transactions, informal hawala-style networks that use crypto as a settlement layer, and government-level transactions that go through diplomatic channels are not fully reflected in the data. The total Iranian crypto economy, combining formal exchange activity with informal flows, is likely substantially larger than the $4 billion headline figure cited by US officials.
How stablecoin controls enable enforcement
The most effective tool in Treasury’s crypto sanctions arsenal is not blockchain analysis or traditional intelligence. It is the freeze function built into centralized stablecoins. USDT, issued by Tether on various blockchains including Tron, contains issuer level controls that allow Tether to freeze specific addresses, preventing the stablecoins from being transferred regardless of who holds the private keys.
Every major freeze in the Iran campaign has involved USDT on Tron. The $344 million April action and the $131 million July action both targeted Tron wallets holding USDT. The pattern is not coincidental. Tron’s low transaction fees and fast settlement have made it the preferred blockchain for USDT transfers in emerging markets, including Iran. That same preference concentrates Iranian stablecoin holdings in a token that the issuer can freeze on demand.
This creates an asymmetry that favors enforcement. Iranian entities using USDT accept a counterparty risk that bitcoin users do not face: Tether can render their holdings inaccessible with a single transaction. The $475 million in USDT freezes during the Economic Fury campaign shows that this risk is not theoretical.
Tether’s cooperation with US authorities is not legally required in the traditional sense. Tether is incorporated offshore and is not subject to direct US regulatory jurisdiction. But the company has consistently complied with US law enforcement freeze requests, a pattern that reflects both the practical reality of wanting US banking relationships and the risks of being designated as a sanctions violator under OFAC regulations. Tether’s voluntary compliance with freeze requests is one reason why USDT on Tron became the enforcement mechanism of choice in the Iran campaign.
The limitation is that the freeze mechanism only works for centralized stablecoins. Iran has also adopted bitcoin and other decentralized assets for cross border transactions, including accepting cryptocurrency for weapons sales. Bitcoin cannot be frozen by any issuer. Decentralized exchanges and cross chain bridges provide routes that do not pass through compliant intermediaries. The freeze function addresses the largest and most visible flows but not the entire ecosystem.
The Bybit hack connection
The WSJ’s discovery that Central Bank of Iran wallets were linked to assets from the North Korean Bybit hack adds a dimension that extends beyond Iran sanctions. It suggests that the networks facilitating Iranian sanctions evasion overlap with the infrastructure used for state sponsored cybercrime.
The FBI attributed the Bybit hack to North Korean actors who stole approximately $1.5 billion in virtual assets. The hackers converted stolen funds into bitcoin and other tokens across many wallets, using decentralized protocols including THORChain to obfuscate the trail. THORChain processed almost $3 billion in trading volume from swaps tied to stolen Bybit assets, according to on-chain tracking.
The intersection of Iranian sanctions evasion and North Korean cybercrime through a common exchange infrastructure raises questions about whether these networks are coordinated or simply convergent. Two sanctioned states using similar crypto channels to evade financial restrictions could reflect shared operational methods, shared intermediaries, or merely the natural tendency of illicit actors to gravitate toward the same low compliance venues.
For regulators, the connection strengthens the argument for applying comprehensive sanctions screening and transaction monitoring requirements to all centralized exchanges, regardless of jurisdiction. For the crypto industry, it highlights the reputational and regulatory risk of operating exchanges that attract illicit flows through weak compliance.
The Bybit connection also matters for how crypto exchanges frame their role in global financial crime. For years, exchanges in non-US jurisdictions argued that sanctions compliance was a US issue, not a global one. The discovery that the same wallets connected both Iranian government funds and North Korean cybercrime proceeds changes the argument. State-sponsored actors from multiple sanctioned countries are using the same infrastructure, which pushes exchanges into a position where choosing not to comply with US sanctions implicitly means becoming a service provider for state-level threat actors.
FinCEN and OFAC have signaled in recent regulatory correspondence that they intend to pursue secondary sanctions against offshore exchanges that knowingly or negligently process flows from sanctioned jurisdictions. Whether CoinEx, which handled $3.84 billion in Iran-linked flows, faces secondary sanctions action will be a test case for how aggressively that posture is applied in practice.
The enforcement paradox
The Iran crypto sanctions campaign reveals a paradox at the heart of blockchain based enforcement. The same transparency that allows investigators to trace $3.84 billion in flows through CoinEx or identify Central Bank of Iran wallets on Tron also shows the scale of activity that proceeded without intervention for years.
Treasury’s ability to freeze USDT, sanction exchanges, and trace on chain activity represents a significant expansion of sanctions enforcement capabilities compared to the traditional banking system. But the $4.18 billion in Iranian crypto outflows in 2025 alone suggests that enforcement is capturing a fraction of total activity. The actions are significant in dollar terms but may represent less than 25% of annual Iranian crypto flows based on available estimates.
Critics of the campaign argue that sanctioning exchanges like Nobitex primarily harms ordinary Iranians who have no alternative to crypto for preserving savings. Proponents argue that the distinction between civilian and military use cannot be drawn cleanly when the Iranian government uses the same financial networks as the civilian population, and that targeting the infrastructure is the only viable method at scale.
The campaign also faces a structural limitation: as enforcement increases on centralized platforms, activity migrates to decentralized alternatives. Each successful USDT freeze teaches Iranian operators to diversify into bitcoin, privacy coins, or decentralized stablecoins that cannot be frozen. The enforcement action itself accelerates the adaptation that makes future enforcement harder.
What to watch
- Additional exchange sanctions. CoinEx has not been sanctioned despite the WSJ report. Whether Treasury acts against offshore exchanges that process Iranian flows will test the limits of US jurisdictional reach.
- The total seized figure. Treasury’s $1 billion in seized crypto is a running total. Whether it continues to grow at the current pace or plateaus will indicate whether enforcement is keeping up with the flow.
- Migration to decentralized platforms. If Iranian entities shift from USDT on Tron to bitcoin, decentralized stablecoins, or privacy focused protocols, the freeze mechanism that has powered most seizures will become less effective.
- Regulatory response to the Bybit-Iran link. The connection between Iranian sanctions evasion and North Korean cybercrime through shared exchange infrastructure may drive new compliance requirements for exchanges globally.
- Impact on Iranian civilians. The sanctions affect both government entities and ordinary citizens who use crypto as an inflation hedge. How the humanitarian dimension is addressed, or not addressed, will influence the political sustainability of the campaign.
Frequently asked questions
How much Iranian cryptocurrency has the US seized?
The US Treasury has seized or frozen nearly $1 billion in cryptocurrency from Iranian exchanges and wallets since the military conflict began in February 2026. Major actions include a $344 million USDT freeze in April and a $131 million freeze in July, both involving wallets on the Tron network.
What is Operation Economic Fury?
Operation Economic Fury is a US Treasury campaign launched on April 14, 2026, targeting Iran’s financial networks including cryptocurrency exchanges, wallets, and traditional banking channels. The campaign is the financial arm of the US response to the military conflict with Iran.
Which Iranian crypto exchanges were sanctioned?
Treasury sanctioned four Iranian exchanges in June 2026: Nobitex, Wallex, Bitpin, and Ramzinex. Nobitex, the largest, handles approximately 50% of Iran’s crypto trading volume and claims 11 million users. Two Nobitex executives were also added to the OFAC sanctions list.
How much money flowed through CoinEx from Iran?
The Wall Street Journal reported that Iran-linked entities moved more than $3.84 billion through crypto exchange CoinEx since 2019, based on TRM Labs data and public on chain analysis. CoinEx denied knowledge of Iran-linked activity and said it strengthened compliance controls.
How does the US freeze cryptocurrency?
The US leverages the freeze function built into centralized stablecoins like USDT. Tether can freeze specific wallet addresses, preventing tokens from being transferred. This mechanism does not work for decentralized assets like bitcoin, which cannot be frozen by any issuer.
What is the connection between Iran and the Bybit hack?
Investigators traced activity from Central Bank of Iran wallets to assets stolen from Bybit by North Korean hackers, who took approximately $1.5 billion in virtual assets. The connection suggests that Iranian sanctions evasion networks and North Korean cybercrime infrastructure may share common exchange intermediaries.
How much crypto do Iranians use?
Chainalysis estimated that Iranian crypto outflows reached $4.18 billion in 2025, a 70% increase year over year. The surge coincided with the collapse of the Iranian rial and intensifying sanctions that cut Iran from the global banking system.
Can Iran avoid crypto sanctions?
Centralized stablecoins can be frozen, but decentralized assets like bitcoin cannot. As enforcement increases on centralized platforms, Iranian entities are expected to migrate toward decentralized protocols, privacy coins, and cross chain bridges that operate beyond the reach of issuer level controls.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. The information presented reflects publicly available data as of August 1, 2026. Readers should conduct their own research and consult qualified professionals before making financial or legal decisions.
Crypto World
Bitcoin ETFs Stay Positive Into July as Late-Sell Pressure Fades
US-listed spot Bitcoin exchange-traded funds (ETFs) finished July with net inflows, even after a late-month pullback that underscored how cautious investors remained going into August. According to SoSoValue, the funds brought in $172.4 million in net inflows during July—enough to reverse two straight months of outflows.
The month’s positive result was tempered by volatility in the final stretch. On the final Friday of July, spot Bitcoin ETFs logged a $265.4 million net outflow, the largest single-day withdrawal since July 13, suggesting the rebound in demand was not fully sustained.
Key takeaways
- Spot Bitcoin ETFs took in $172.4 million in net inflows in July, reversing two consecutive months of outflows, according to SoSoValue.
- Despite the monthly gain, the last Friday of July saw a $265.4 million net outflow—Bitcoin ETFs’ biggest daily withdrawal since July 13.
- Year-to-date flows remain negative: US spot Bitcoin ETFs have recorded about $5.29 billion in net outflows in 2026.
- Ether ETFs were steadier, ending July with $365.2 million in net inflows and a four-week inflow run, per SoSoValue.
- XRP ETFs also posted continued demand, adding $27.3 million in net inflows in July while recording their fifth positive month of 2026.
Bitcoin ETFs return to inflows—weak finish signals caution
SoSoValue data indicates July’s net inflow improved the outlook for spot Bitcoin ETF investors after a difficult stretch. The article notes that investors pulled nearly $7 billion in aggregate outflows over the previous two months, including what earlier reporting described as the largest monthly outflow of 2026 in June, totaling $4.5 billion (coverage referenced in the original piece: Cointelegraph).
Still, the late-month selling pressure matters for how traders may read positioning. The $265.4 million outflow on the final Friday of July not only flipped daily flows negative, but also marked the largest daily withdrawal since mid-July. In practical terms, that pattern suggests July’s inflows were vulnerable to sudden risk-off behavior—important for anyone tracking ETF flow-driven momentum.
On a broader time frame, weekly flows also turned negative at the end of the month. For the week ending July 31, Bitcoin ETFs recorded a $61.53 million outflow after three consecutive weeks of inflows. That shift reinforces the message that demand improved during parts of July, but participation thinned as the month closed.
Where 2026 stands: cumulative outflows stay elevated
Even with a positive July, the year-to-date picture for US-listed spot Bitcoin ETFs remains firmly in the red. Based on the figures cited from SoSoValue, Bitcoin ETFs have accumulated roughly $5.29 billion in net outflows in 2026.
The monthly distribution shows a market that has not found consistent footing. March, April, and July are the only months reported as positive so far this year, bringing total inflows of $3.46 billion. Meanwhile, the remaining months—January, February, May, and June—accounted for outflows totaling about $8.75 billion.
Despite that imbalance, the products have still attracted meaningful long-term net capital since launch. The article states that US spot Bitcoin ETFs have drawn $51.32 billion in cumulative net inflows, and that total net assets reached $76.29 billion at the end of July.
Ether ETFs keep the momentum going
While Bitcoin ETFs faced renewed selling pressure at the end of July, Ether-related products showed comparatively steadier demand. According to SoSoValue, US spot Ether ETFs ended July with $365.2 million in net inflows and maintained four consecutive weeks of inflows.
That marks a second month of positive flows for Ether ETFs in 2026 after April’s $356 million inflow. Yet, the recovery is not enough to fully erase earlier weakness: despite this improvement, the article notes Ether ETFs are still around $1.1 billion in net outflows year to date.
For investors, the contrast between Bitcoin and Ether flows can be informative. It suggests that even if market-wide sentiment is cautious, some capital has been willing to rotate into Ether exposure—at least at the ETF level—rather than staying entirely risk-off.
XRP ETFs post another positive month
Other altcoin ETF categories also appear to have avoided the same late-month stress seen in Bitcoin. XRP ETFs, in particular, maintained steadier activity. The article reports that XRP ETFs recorded $27.3 million in inflows during July and marked their fifth positive month of 2026.
Year-to-date, XRP ETFs have generated about $343 million in net inflows, positioning them as one of the stronger-performing crypto ETF segments in the market this year, at least based on the net flow figures cited.
In a market where ETF flows can swing quickly with broader macro conditions and crypto price action, continued positive monthly demand for XRP products can serve as a signal that some investors are still finding specific altcoin exposure compelling—even when Bitcoin faces repeated episodes of volatility.
Going forward, traders and long-term holders will likely watch whether Bitcoin ETF demand can withstand similar end-of-month selling pressure, especially since weekly flows flipped negative as July closed. At the same time, the relative stability in Ether and XRP inflows may keep comparing as a useful read on whether the next wave of capital concentrates in Bitcoin or broadens across the rest of the crypto ETF complex.
-
Sports6 days agoCommonwealth Games boxing: Jadumani Singh seals dominant 5-0 win over Pakistan’s Sumama Rehman to enter quarter-finals | Commonwealth Games News
-
Business3 days agoWhy Trees Belong on the Risk Register
-
Fashion15 hours agoWeekend Open Thread: Wit & Wisdom
-
Politics12 hours agoMeta enters AI-training agreement with far-right ‘propaganda rag’ Newsmax
-
Tech5 days agoIntel is reversing course and bringing hyper-threading back to its server chips
-
Crypto World7 days agoRipple bought a bank in pieces. The $4 billion audit
-
Politics5 days agoLuke Littler dismantles Gerwyn Price to retain title in Blackpool
-
Politics4 days agoThe Part of the Electric Transition Nobody Wants to Discuss
-
News Videos6 days agoBITCOIN JUST ENTERED THIS CRITICAL ZONE…
-
Entertainment4 days ago‘Stargate’ Creator’s New Sci-Fi Series Returns for Season 3 Tomorrow
-
Business3 days agoMajor shareholder moves on Canyon
-
Crypto World6 days agoXRP Ledger adds $2.6B as RWA inflows rank second
-
Politics6 days agoSpain sweeps the board at 2026 World Cup with individual awards
-
News Videos2 days agoBitcoin Enters the 3rd Stage of the Bear Market
-
Crypto World3 hours agoXRP Ledger v3.3.0 brings five institutional features
-
Entertainment6 days agoSara Gilson Killed By Husband After Viral “Pedophile” TikTok Video
-
Crypto World3 days agoKraken Enables Retail Access to Jersey Mike’s IPO via Tokenized Shares
-
News Videos4 days agoClaude: Build Financial Dashboards in Minutes (2026)
-
Tech4 days agoNew macOS Sequoia & Sonoma security updates for older Macs
-
Politics2 days agoLuke Littler’s dominance sparks GOAT debate

You must be logged in to post a comment Login