Connect with us

Crypto World

Ostium blames off chain breach for $23.75M USDC exploit

Published

on

TrustedVolumes attacker returns $2M, keeps another $2M as bounty

Ostium has concluded that its July exploit originated from compromised off-chain infrastructure rather than a flaw in its smart contracts, after an investigation found the attacker manipulated price reporting to drain 23.75 million USDC from the protocol’s liquidity vault.

Summary

  • Ostium said its investigation found the July exploit originated from compromised off chain infrastructure rather than a flaw in its smart contracts.
  • Fraudulent BTC USD price reports allowed the attacker to drain 23.75 million USDC from the protocol’s OLP liquidity vault.
  • The protocol said automated monitoring detected the attack, trading resumed on July 23, and user collateral remained unaffected.
  • A recovery plan for affected liquidity providers is being finalized and will be shared in a separate update.

According to Ostium’s post-mortem published on Wednesday, the attacker gained unauthorized access to the protocol’s off-chain infrastructure and used it to submit fraudulent BTC-USD price reports. 

The manipulated reports allowed the attacker to create artificial trading profits at the expense of the public OLP vault, while the protocol found no evidence that its smart contracts or governance multisigs had been compromised.

Advertisement

Ostium says exploit bypassed off-chain systems

During its investigation, Ostium said the initial breach occurred outside the protocol’s on-chain infrastructure. The team stated that its findings did not identify any vulnerability in the protocol’s smart contract logic or any compromise involving the multisigs responsible for governing the protocol.

Instead, the attacker abused forwarder paths that the protocol already recognized as valid. Ostium explained that the exploit began with a small test transaction involving a 100 USDC position, producing roughly 897.8 USDC in artificial profit before the attacker expanded the operation.

Following the successful test, the attacker executed the primary batch of transactions, transferring about 11.9 million USDC to a beneficiary wallet. Ostium said six additional standalone exploit cycles followed, bringing the total loss from the OLP vault to 23.75 million USDC.

Advertisement

Earlier reporting from blockchain security firm Blockaid had attributed the incident to a compromised oracle signer private key, saying the attacker bypassed the protocol’s price verification process by submitting manipulated price reports through a registered PriceUpKeep forwarder. At the time, Blockaid estimated that between $11.86 million and $18 million USDC had been withdrawn during approximately 20 trading loops, based on the exploit activity visible on-chain while the attack was still unfolding.

Automated monitoring limited additional losses

While the exploit succeeded in draining funds from the liquidity vault, Ostium said its automated monitoring systems detected the abnormal activity before additional withdrawals could take place. The protocol subsequently halted trading while its investigation continued and has since migrated to a new production environment with updated security controls.

Trading resumed on July 23 after the migration was completed.

Ostium also said trader collateral remained unaffected throughout the incident because user margin stayed inside the protocol’s trading contracts rather than the compromised liquidity pool.

Advertisement

The team added that it is still finalizing a separate recovery plan for liquidity providers whose funds were affected by the exploit. According to the protocol, further details will be released in a dedicated update.

Oracle infrastructure remained central to the attack

Although Ostium’s latest report attributes the incident to unauthorized access to its off-chain infrastructure, its findings are consistent with the attack path previously outlined by Blockaid, which concluded that compromised signing credentials allowed fraudulent price reports to pass the protocol’s verification process.

According to Blockaid’s earlier analysis, the attacker repeatedly opened and closed positions through delegated actions after submitting favorable future-dated price reports. Because the manipulated reports appeared valid to the protocol, each trading cycle generated profits for the attacker while transferring losses to the OLP liquidity vault instead of relying on a vulnerability in the smart contract code itself.

The incident has drawn attention to the security of supporting infrastructure that decentralized finance protocols rely on for external market data. In Ostium’s case, both the protocol’s post-mortem and Blockaid’s earlier investigation concluded that the exploit did not originate from flaws in the core smart contracts.

Advertisement

Ostium exploit followed Nasdaq partnership

The exploit occurred only weeks after Ostium expanded its institutional presence through a partnership with Nasdaq announced in May. At the time, the protocol said Nasdaq’s market data would support equity perpetual products listed on the platform.

Ostium also disclosed during that announcement that it had processed more than $50 billion in cumulative trading volume.

Before the exploit, the protocol had raised approximately $27.8 million from investors including General Catalyst, Jump Crypto, Coinbase Ventures, Wintermute and GSR, according to previous company disclosures.

Advertisement

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

U.S. sanctions Iranian maritime firm over Bitcoin payments

Published

on

GoMining launches Bitcoin commerce tool that cuts out fiat

The U.S. Treasury sanctioned two Iranian maritime insurance companies on July 29, alleging that they supported an Islamic Revolutionary Guard Corps-linked system for collecting revenue from vessels using the Strait of Hormuz.

Summary

  • Two Iranian maritime insurers were sanctioned after Treasury alleged HormuzSafe accepted Bitcoin to evade restrictions.
  • Eight shipping companies and eight vessels were also targeted over alleged Iranian petroleum transport activities.
  • OFAC published no Bitcoin addresses, transaction hashes or payment totals supporting its public designation announcement.

The Office of Foreign Assets Control added HormuzSafe Marine Services Authority and Persian Gulf Marine Insurance Company to its Specially Designated Nationals list. Both were designated under Executive Order 13902 for operating in Iran’s financial sector.

U.S. sanctions target HormuzSafe’s alleged Bitcoin use

Treasury described the two companies as part of an “IRGC-backed extortion scheme” that required commercial vessels to purchase approved maritime insurance before crossing the strait. These are U.S. government allegations, and the sanctions announcement did not include a court ruling against either company.

Advertisement

The department said HormuzSafe was developed by Iran’s Ministry of Economy and “accepts payment in Bitcoin and other digital assets” to bypass Western restrictions. It further alleged that the company generated revenue for the IRGC and helped Iran tighten control over regional shipping.

However, the public Treasury release and OFAC listing did not identify Bitcoin addresses, transaction hashes, payment amounts or specific customers. Therefore, the announcement confirms the U.S. designation and its allegations, but it does not provide public on-chain evidence showing completed Bitcoin payments.

Earlier Bitcoin insurance reports lacked payment evidence

moreover, HormuzSafe promoted maritime insurance payable in Bitcoin in May. The platform reportedly offered digital insurance policies and financial-responsibility certificates for ships operating around the Strait of Hormuz.

Iranian state-linked reports claimed the platform could eventually generate more than $10 billion annually. However, that figure was a projection rather than recorded revenue. No independent adoption data or verified Bitcoin payment records were available at the time.

Advertisement

The July action moves HormuzSafe from a reported sanctions-evasion proposal to an official U.S. sanctions target. Still, the designation does not establish how much cryptocurrency the platform received or whether Bitcoin formed a major part of its revenue.

Eight tankers and eight shipping firms were also targeted

OFAC also sanctioned eight companies accused of operating in Iran’s petroleum sector. The businesses are registered in China, Hong Kong and the Marshall Islands and were linked to vessels that Treasury said transported Iranian crude oil or petroleum products.

Eight tankers were identified as blocked property, including Well Sail, Lily, Al Salmi, Breeze V, Natsumi, Crystal, Nireta and Yehope. Treasury said some had carried millions of barrels of Iranian oil to China since 2022.

The Strait of Hormuz remains a central energy shipping route. U.S. Energy Information Administration data showed that flows through the waterway represented more than one-quarter of global seaborne oil trade and about one-fifth of worldwide oil consumption during 2024 and early 2025.

Advertisement

What happens after the OFAC designation

Property belonging to the sanctioned companies that enters U.S. jurisdiction must be blocked and reported to OFAC. Companies owned at least 50% by one or more blocked parties are also subject to restrictions, even when they are not separately listed.

U.S. persons are generally prohibited from providing funds, services or other economic benefits to the designated companies. Non-U.S. financial institutions may also face sanctions exposure when they knowingly facilitate certain transactions involving blocked parties.

The action did not announce a cryptocurrency seizure, criminal charge or enforcement case against customers who may have used HormuzSafe. Any later asset recovery or prosecution would require additional legal or regulatory action.

U.S. authorities previously froze $344 million in Iran-linked USDT across two Tron addresses. Unlike Bitcoin, USDT can be frozen through controls operated by its centralized issuer.

Advertisement

Source link

Advertisement
Continue Reading

Crypto World

Visa CEO downplays Open USD threat to Tether and USDC

Published

on

Tether freezes USDT in 131 ISIS-K-linked TRON wallets: Chainalysis

Visa Chief Executive Ryan McInerney said the payments company will remain neutral among stablecoins as Open USD prepares to enter a market led by Tether’s USDT and Circle’s USDC.

Summary

  • Visa says its stablecoin strategy will remain multi-coin and multi-chain rather than backing one winner.
  • Open USD plans to launch later this year with more than 140 participating global companies.
  • Visa’s stablecoin platform initially supports Open USD while retaining interoperability with existing settlement products worldwide.

During Visa’s July 28 fiscal third-quarter earnings call, McInerney said the company would remain “multi-coin, multi-chain” and that its role was “not to pick winners.” Instead, Visa plans to help clients connect securely to whichever stablecoins, networks and infrastructure gain adoption.

Advertisement

Visa separates Open USD support from a single-token bet

Visa is one of more than 140 companies supporting Open Standard, the independent consortium developing Open USD. Other participants include Mastercard, Stripe, Coinbase, BlackRock, BNY, Google and several global banks.

However, McInerney’s comments show that Visa does not view its involvement as an exclusive commitment to OUSD. The company already supports several stablecoins and blockchains through settlement, card and money-movement products. Visa previously described its technical approach as a “multi-coin and multi-chain foundation.”

ARK Invest researcher Lorenzo Valente interpreted the response as evidence that partner support may be “closer to a soft LOI than a strategic bet.” That is an analyst’s view, not a disclosed Visa contract term. Neither Visa nor Open Standard has published commitments showing how much capital, distribution or balance-sheet support each partner must provide.

Open Standard plans to launch Open USD later in 2026. Its website says businesses will be able to mint and redeem OUSD without fees or volume limits, while most revenue from the reserves will return to participants that adopt and distribute the token.

That model differs from the issuer-led structures used by USDT and USDC, where the issuing company controls reserve management and related economics. Open Standard says an independent management team and partner-led governance will oversee OUSD. These are planned product features, and the token has not yet launched.

Advertisement

Notably, Open USD’s launch raised questions about Circle’s reserve-income model. Circle shares fell 17.5% on June 30, although Russell index removals also contributed to that day’s decline, making it difficult to isolate OUSD’s effect.

Visa is building infrastructure across stablecoins

Visa’s practical commitment is clearer in its own product releases. On July 16, the company introduced the Visa Stablecoin Platform for banks, fintechs and crypto companies. The platform initially provides access to Open USD, including minting, burning, storage and transfers through a Visa-managed environment.

The company said the platform will also connect with its existing stablecoin settlement, linked-card and money-movement services. In June, Visa reported that its stablecoin settlement activity had reached an annualized run rate of about $7 billion as of March 2026.

Additionally, Visa’s stablecoin platform was described as a route for institutions to use Open USD without building every wallet, security and treasury function internally. Visa’s broader structure could also allow it to serve clients choosing USDC, USDT or another regulated token.

Advertisement

Open USD’s launch will test partner commitment

Open Standard has not announced an exact launch date, initial circulating supply or confirmed transaction volume. Because OUSD is not yet live, there is no verified on-chain activity or market capitalization to compare with USDT and USDC.

The next test will be whether partners integrate OUSD into real payment, settlement and trading products after launch. Visa has already built an initial access route through its platform, but McInerney’s comments indicate the company will continue supporting competing tokens and networks.

Therefore, Open USD may gain distribution through Visa without becoming Visa’s exclusive stablecoin. Adoption will depend on reserve arrangements, regulatory compliance, partner integrations and actual customer demand rather than the size of the consortium alone.

Advertisement

Source link

Continue Reading

Crypto World

Coldcard Mk3 Alert as Experts Investigate $38M Bitcoin Wallet Drain

Published

on

Crypto Breaking News

Canadian hardware wallet maker Coinkite has issued an urgent security warning for owners of its Coldcard Mk3 signing device, advising users to move funds away from wallets whose seed phrases were generated using specific affected firmware versions. The company said the risk applies to Mk3 firmware 4.0.1 (released in March 2021) through 5.0.3, the last firmware version that supports the Mk3—while its Mk4, Q, and Mk5 models are not affected, based on early analysis.

The alert arrives amid renewed scrutiny from Bitcoin security researchers investigating an unexplained, coordinated sweep of 594.48 BTC from single-signature addresses. Coinkite emphasized that, at this stage, there is no definitive public proof linking the Mk3 seed-generation issue to that activity, but the company is asking users to act “out of an abundance of caution.”

Key takeaways

  • Coinkite warns Coldcard Mk3 users to migrate funds from wallets whose seeds were created on affected firmware versions 4.0.1 through 5.0.3.
  • The issue does not appear to affect newer hardware models (Mk4, Q, Mk5), according to Coinkite’s early findings.
  • Coinkite’s guidance focuses on safer recovery hygiene: generate a new seed on an unaffected device, verify backups and receive addresses, and test with a small transaction first.
  • Security analysts are examining a 594.48 BTC sweep from single-signature addresses, but no public evidence currently ties it directly to the Mk3 firmware problem.
  • Coinkite says seeds protected with a BIP-39 passphrase (distinct from the Coldcard PIN) show minimal risk in its preliminary assessment.

Coinkite’s Mk3 seed-generation warning

In a post on its official blog, Coinkite said seeds created on an Mk3 running firmware version 4.0.1 or later versions—up to 5.0.3—may put funds at risk. The company’s early analysis did not identify the same concern for Coldcard Mk4, Q, or Mk5 devices.

The company’s recommendation is practical and staged. Coinkite urged affected users to generate a new seed on a device considered unaffected, confirm that the backup is correct, and ensure they are using the intended receive address. Users should then send a small test transaction before transferring the remainder of the balance.

Coinkite also tried to clarify a point of confusion that often arises in hardware wallet security discussions: in its assessment, the “BIP-39 passphrase” is the relevant protection mechanism, and it should not be conflated with the Coldcard PIN.

Advertisement

From firmware versions to real-world user risk

The significance of Coinkite’s warning lies in how deterministically Bitcoin wallets derive addresses from seed phrases. If seed generation was compromised in a way that reduced randomness—or introduced patterns an attacker could exploit—then previously used addresses may become more guessable. Hardware wallets are designed specifically to make theft difficult precisely because the seed should be unpredictable, so any defect that affects entropy can have downstream consequences.

While the company did not provide technical details in the excerpted warning, it did set boundaries around what users need to check: not every Coldcard Mk3 seed is automatically suspect, but those created on the specified firmware range. For users who cannot confidently identify the exact firmware version used during seed generation, Coinkite’s steps imply a conservative approach: treat the wallet as potentially exposed and migrate funds accordingly.

That “caution first” posture is particularly important given the broader environment. Hardware wallet security incidents—even when the evidence remains circumstantial—tend to trigger defensive behavior from both users and threat researchers, because a stolen seed can sometimes lead to recurring attempts rather than a single breach.

Security researchers link context, not causation

Attention intensified after a Reddit user described a wallet drain they claimed involved a Coldcard Mk3 purchased in May 2021. According to the user’s account, the seed was later restored onto a Coldcard Mk4 in January 2026, meaning it was entered into a second device afterward. The information, however, is self-reported and does not, on its own, establish a direct connection between Coldcard hardware and a larger set of suspicious transactions.

Advertisement

Separately, AnchorWatch CEO and co-founder Rob Hamilton published a preliminary analysis claiming that 594.48 BTC was swept across 500 transactions over a three-block window. In that assessment, Hamilton noted that 1,324 unspent transaction outputs were involved and that the addresses appeared to be single-signature. He also stated that roughly 562 BTC was later consolidated into another address. Hamilton suggested the pattern “looks like there was flawed entropy in wallet generation somewhere along the way,” describing the event as consistent with randomness issues, though this remains an interpretation rather than proof.

At the time of the reporting, the 594.48 BTC was valued at approximately $38.3 million using a Bitcoin price of $64,364.07, according to CoinGecko.

Another researcher, Wizardsardine CEO Kevin Loaec, offered a hypothesis focused on how low-entropy seeds might be produced. In his view, a low-quality random-number generator—potentially from a software component, secure element behavior, device batch, or specific firmware—could have resulted in wallets with insufficient randomness. Loaec suggested an attacker with knowledge of the flaw might use an AI-generated script to brute-force affected wallets, while limiting the search to a narrower set of BIP-84 derivation paths. That would align with why the sweep appears concentrated in native SegWit addresses, and why some wallets may have been only partially drained. He stressed that this theory is still unconfirmed and that further scanning might expose additional holdings.

The key tension across these analyses is the difference between “consistent with a flaw” and “proven caused by this specific device.” Coinkite’s warning sits in the first category—credible internal assessment that certain Mk3 firmware versions may expose users—while the external sweep investigation remains a broader pattern that researchers are still trying to attribute.

Advertisement

What to watch next for affected users

If Coinkite’s risk assessment is accurate, the most important variable for users is whether their seed phrase originated from the affected firmware range and whether it was protected with a BIP-39 passphrase. The company’s preliminary statement that BIP-39 passphrase seeds face “minimal risk” provides some comfort, but it does not eliminate the need for verification and safe migration steps.

Going forward, readers should watch for Coinkite’s promised formal technical review and for further independent analysis that either strengthens or weakens the suspected link between the Mk3 seed-generation issue and the 594.48 BTC sweep. Until that picture is clarified, the prudent takeaway remains the same: treat potentially affected wallets as exposed, and move funds using newly generated seed material on unaffected hardware.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Advertisement

Source link

Continue Reading

Crypto World

BitGo adds 4 quantum controls for Bitcoin wallets

Published

on

Bitcoin crash fails to scare institutions, Coinbase strategist says

BitGo detailed four quantum-risk management controls for institutional Bitcoin wallets in a July 22 product announcement, aiming to measure and reduce public-key exposure before quantum attacks become practical.

Summary

  • Four new BitGo controls score exposure, consolidate UTXOs, remediate addresses, and adjust wallet defaults automatically.
  • Bitcoin public keys become visible after spending, while Taproot outputs expose keys from their creation.
  • No practical quantum attack can break Bitcoin today, leaving BitGo’s tools focused on operational preparation.

The tools apply to supported Bitcoin multi-signature wallets. They include a Quantum Risk Score, a guided address-remediation workflow, a new UTXO selection method and updated default address controls. BitGo said the release supports operational preparation and does not replace any future Bitcoin protocol upgrade.

BitGo turns public-key exposure into a wallet metric

For common hashed-key Bitcoin outputs, spending reveals the public key needed to verify the transaction. If coins remain tied to that key through address reuse or a partial spend, they could become targets if a cryptographically relevant quantum computer eventually derives private keys from public keys.

Advertisement

Taproot requires a separate distinction. Its output key is visible when the output is created, rather than only after a later spend. The draft BIP 360 proposal also identifies Pay-to-Public-Key outputs, reused outputs and Taproot outputs as exposed to long-duration attacks under a future quantum scenario.

BitGo’s Quantum Risk Score gives clients an in-platform measure of exposure across supported wallets. However, the company has not published the score’s formula, weighting system or thresholds. It is therefore a company risk-management measure, not an independent Bitcoin security standard.

Four controls change how institutions handle UTXOs

The new UTXO selection method groups coins by address. When a wallet selects one UTXO from an address, it attempts to include every other UTXO associated with that address. The approach is intended to avoid leaving funds behind after a spend exposes the relevant public key.

The Fix Exposed Addresses workflow moves affected funds into newly generated addresses whose public keys have not appeared onchain. Updated defaults are also intended to reduce reliance on address types and transaction patterns that create earlier exposure.

Advertisement

BitGo said Taproot and Pay-to-Public-Key funds require separate remediation because those formats expose public-key information from creation. The company did not identify support for those remediation paths in the current product release.

BitGo quoted Blockstream co-founder Adam Back as saying “nobody has a quantum computer that can touch Bitcoin today.” That assessment means the product addresses a future risk rather than an active method of stealing Bitcoin. It also does not change Bitcoin’s signature system or protect the network by itself.

Bitcoin developers are separately discussing BIP 360, a draft soft-fork proposal for Pay-to-Merkle-Root outputs. The design removes Taproot’s key-path spend and aims to reduce long-exposure attacks. However, its authors say faster attacks against keys revealed while transactions await confirmation may require post-quantum signatures.

BIP 360 remains a draft and has not been activated on Bitcoin. Any network-wide change would still need technical review, implementation, testing and broad adoption across wallets, nodes and other infrastructure.

Advertisement

Onchain data explains the institutional focus

Glassnode estimated in May that 6.04 million BTC, or 30.2% of issued supply, had public-key exposure at rest. It classified 1.92 million BTC as structurally exposed through output design and 4.12 million BTC as operationally exposed through address reuse, partial spending or custody practices.

The research did not claim those coins can be stolen today. Instead, it measured where public keys are already visible and where better wallet management may reduce exposure. Exchange-related balances represented 1.63 million BTC within Glassnode’s operational category.

However, BitGo and Silence Laboratories tested post-quantum signing inside an institutional custody workflow in May. In related coverage, nine companies pledged $15 million over three years to a Bitcoin security consortium that named post-quantum research as its first focus.

BitGo has not disclosed how many clients can access the controls, whether they carry separate fees or when support may expand. Institutions can use the tools to review and move exposed balances, while wider protection will depend on future Bitcoin proposals and adoption.

Advertisement

Source link

Advertisement
Continue Reading

Crypto World

Binance.US targets prediction markets with CFTC license bid: report

Published

on

Binance.US targets prediction markets with CFTC license bid: report

Binance.US has moved closer to entering the U.S. prediction market business after confirming plans to seek a federal license that would let it offer regulated event contracts to retail customers.

Summary

  • Binance.US plans to apply for a CFTC license to launch a regulated prediction market platform in the U.S.
  • The move advances the exchange’s earlier strategy to expand into derivatives and event contracts beyond spot crypto trading.
  • Robinhood’s latest earnings have shown strong growth in event contract revenue as more trading platforms enter the market.
  • State lawsuits and conflicting court rulings continue to create legal uncertainty for prediction market operators despite federal oversight efforts.

According to Journalist Eleanor Terret, citing comments from Binance.US Chief Executive Officer Stephen Gregory at the Rare Evo conference in Las Vegas, reported that the exchange plans to apply for a Commodity Futures Trading Commission-designated contract market (DCM) license in August. 

If approved, the license would allow Binance.US to list futures, options and event-based contracts under CFTC oversight, adding a new business line beyond its existing spot cryptocurrency services. 

The application also moves forward a strategy Gregory outlined earlier this month, when he said the exchange intended to pursue licenses for derivatives, perpetual futures and prediction markets as part of its expansion plans.

Binance.US moves ahead with prediction market plans

A designated contract market license would place Binance.US alongside a small but expanding group of federally regulated prediction market operators.

Advertisement

Kalshi and Polymarket US already operate in the segment, while Gemini secured its own CFTC license earlier this year. Coinbase has also entered the market through a partnership with Kalshi that offers event contracts to U.S. users.

Competition continues to grow outside the crypto-native exchanges as well. The Wall Street Journal reported last week that Robinhood has discussed adding prediction market contracts from Crypto.com to its brokerage platform, extending the list of financial companies exploring the product category.

The latest move also builds on Binance.US’ recovery strategy. Gregory told earlier this month that the company wanted to regain the roughly 20% share of the U.S. crypto exchange market it once held before regulatory challenges reduced its business. Alongside lower trading fees and renewed liquidity efforts, he identified prediction markets and derivatives as products that could create additional revenue streams, subject to regulatory approvals.

Advertisement

Event contracts have attracted major trading platforms

Interest in prediction markets has accelerated as several companies look beyond traditional crypto trading.

Robinhood’s latest quarterly earnings illustrate that trend. The brokerage reported $156 million in revenue from event contracts during the second quarter, more than 10 times the level recorded a year earlier. According to the company’s earnings release, customers traded more than 13.6 billion event contracts during the quarter, making the category its fastest-growing source of transaction-based revenue.

While Robinhood’s cryptocurrency transaction revenue fell 38% year over year, event contracts, options and equities helped lift total quarterly revenue to a record $1.31 billion.

For Binance.US, the expansion could complement its existing business as the exchange continues rebuilding after several years of regulatory setbacks. Gregory previously said the company had already restored U.S. dollar banking services in most supported states and was working to attract customers back through lower trading costs and stronger liquidity.

Advertisement

CFTC approval may not end legal uncertainty

Federal approval, however, would not remove every legal hurdle facing prediction market operators.

Multiple states continue arguing that sports-related event contracts fall under state gambling laws even when platforms operate under federal commodities regulation.

The legal disagreement intensified this week after a federal judge in Wisconsin rejected the CFTC’s request to stop the state from enforcing its gambling laws against platforms including Kalshi, Polymarket, Crypto.com, Robinhood and Coinbase. Judge William Griesbach ruled that the agency had not demonstrated that sports event contracts qualify as swaps under the Commodity Exchange Act for purposes of obtaining a preliminary injunction.

The court also concluded that Wisconsin’s gambling laws were not preempted by federal commodities regulations, allowing the state’s enforcement effort to continue while litigation proceeds. The CFTC has said it will appeal the decision.

Advertisement

Elsewhere, federal courts have reached different conclusions. Minnesota temporarily blocked enforcement of its prediction market ban, while courts in New York, Michigan and Washington have issued rulings that favored state enforcement in separate disputes. The conflicting outcomes have left operators without a consistent legal standard across the country.

Rule changes remain under review

At the regulatory level, the CFTC is still reviewing proposed amendments to Rule 40.11, which would establish a formal process for evaluating event contracts tied to gaming, war, terrorism, assassination and unlawful activity.

The proposal has drawn comments from exchanges, legal experts, sports organizations and state governments. Earlier this week, attorneys general from 44 states urged the Commission to withdraw and rewrite the proposal, arguing that it extends beyond the authority granted under the Commodity Exchange Act and enters an area traditionally regulated by states.

The National Football League has also called for tighter safeguards on sports prediction markets, including stronger integrity protections and longer regulatory review periods before new contracts become effective. By contrast, the National Hockey League and Major League Baseball have entered commercial partnerships with prediction market platforms.

Advertisement

Separately, the CFTC’s Division of Market Oversight reminded designated contract markets that new event contracts should be submitted with contract-specific legal analysis and settlement details rather than through broad template certifications.

Source link

Advertisement
Continue Reading

Crypto World

SEC ready to act if Congress stalls on CLARITY Act

Published

on

SEC sets September talks as 24-hour stock trading moves closer

U.S. Securities and Exchange Commission Chair Paul Atkins said the regulator is prepared to write crypto market rules if Congress fails to pass the CLARITY Act, offering an agency-led fallback as Senate negotiations continue.

Summary

  • SEC Chair Paul Atkins says agency rules could proceed if Congress fails to pass CLARITY.
  • Senate Banking advanced the bill 15-9, but the full Senate has not voted on it.
  • Agency rulemaking cannot independently grant the CFTC statutory authority over digital commodity spot markets nationwide.

Atkins told CNBC that the SEC was “ready, willing and able” to address issues covered by the bill through its existing authority. However, he said legislation remained the preferred route because “statute is the way to future-proof something.” His comments describe the agency’s intended approach rather than a completed rulemaking action.

On July 28, Atkins also said publicly that the SEC was providing Congress with technical assistance as lawmakers worked on the legislation.

Advertisement

SEC can act, but it cannot replace Congress

The SEC has already placed several crypto initiatives on its 2026 regulatory agenda. Atkins said the agency intends to create clearer rules for crypto fundraising, custody and the trading of tokenized securities onchain.

Advertisement

However, the SEC is considering proposals covering crypto assets, broker-dealers and market structure. Those projects could clarify token offerings, financial responsibility requirements and trading through securities exchanges or alternative trading systems.

However, agency rules have limits. The SEC cannot independently give the Commodity Futures Trading Commission broad statutory authority over digital commodity spot markets. It also cannot permanently stop a future SEC administration from revising or withdrawing regulations.

Atkins acknowledged that distinction in earlier remarks, saying notice-and-comment rules could strengthen the SEC’s approach but that legislation offered the strongest protection against future policy reversals.

CLARITY Act has cleared committees but not the Senate

The House passed the Digital Asset Market Clarity Act in July 2025 by a 294-134 vote. The Senate Agriculture Committee later advanced its Digital Commodity Intermediaries Act in January 2026, proposing a CFTC registration system for digital commodity trading platforms.

Advertisement

Meanwhile, the Senate Banking Committee approved its version of the CLARITY Act by a 15-9 vote on May 14. The committee said the legislation would divide oversight between the SEC and CFTC while creating disclosure, registration and customer-protection rules.

Sen. Cynthia Lummis released updated legislation on July 22 that merged work from both Senate committees. She described the coming weeks as potentially the “last real chance” to pass the framework for several years. That statement reflects her political assessment, not a formal legislative deadline.

As of July 30, the full Senate had not voted on the merged bill. It would still need sufficient support to overcome procedural hurdles, pass the chamber and reconcile any differences with the House-approved text.

Negotiations have continued over ethics rules for elected officials and restrictions on rewards paid to stablecoin holders. Banking groups argue that interest-like stablecoin products could draw deposits away from traditional lenders, while crypto companies say broad limits could restrict lawful customer rewards.

Advertisement

Neither position has become final law. The updated Senate materials include separate sections addressing stablecoin interest and ethics, showing that both subjects remain part of the negotiations.

In addition, CLARITY Act passage odds fell to 27% on Polymarket on July 29 as traders reacted to the delayed Senate timetable. That figure represents prediction-market pricing and does not provide an independent forecast of congressional action.

What happens if Congress does not act

The SEC could publish proposed rules under the Administrative Procedure Act. The process would normally include public comments, commission consideration and possible revisions before any final rule takes effect.

Such rules could provide clearer treatment for token issuance, registered intermediaries and securities trading. However, they would not create the full SEC-CFTC division of authority proposed by the CLARITY Act.

Advertisement

Congress may still take up the merged legislation later in 2026. Until a floor vote is scheduled, the SEC’s regulatory agenda will continue moving separately from the bill.

No verified cryptocurrency price movement can be attributed solely to Atkins’s comments. The next confirmed developments will depend on either formal Senate floor action or the publication of SEC rule proposals.

Advertisement

Source link

Continue Reading

Crypto World

SK Hynix Trader Turns $2.26M Loss Into $6.44M Profit on Earnings Spike

Published

on

SK Hynix Trader Turns $2.26M Loss Into $6.44M Profit on Earnings Spike

On-chain analytics platform Lookonchain tracked a whale that turned a multi-million-dollar loss into a $6.44 million profit in the days leading up to and following the Korean chipmaker’s earnings.

SK Hynix’s stock had been facing a prolonged and substantial downturn as appetite cooled for AI infrastructure companies. However, an impressive earnings result turned things around quickly.

A Rocky Three-Day Trade

Wallet 0xC8b5 opened a 3x leveraged long on 37,229 units of SKHX on July 29. SKHX is a Hyperliquid perpetual contract that tracks SK Hynix’s share price rather than the stock itself. The $37.3 million position briefly showed a $778,000 gain, per Lookonchain.

That gain evaporated fast. A day later, the position’s value fell to $34.28 million. The wallet then faced a $2.26 million unrealized loss, according to a follow-up post. Lookonchain noted the trader had lost more than $1 million on each of the previous three trades. That pattern pointed to another costly bet.

Despite the impressive spike, SK Hynix is still down by nearly 15% over the past 5 days. Image Source: Trading View

The reversal came just as fast. The position’s value climbed to roughly $43 million. The whale now sits on a $6.44 million profit, fully recovering its earlier losses.

Why the Swing Was So Violent

SK Hynix posted record Q2 operating profit on July 29. Surging demand for its HBM4 memory chips drove the results. Yet the stock initially whipsawed lower. Investors weighed South Korea’s broader market selloff and lingering doubts about AI infrastructure spending.

That reversed on July 31. SK Hynix shares surged as much as 28.59% to ₩1,700,000 on the Korea Exchange. It marked their sharpest single-day move in years.

Strong earnings from Amazon and Microsoft sparked a broader AI-stock rally. SK Group Chairman Chey Tae-won added momentum with a rare direct share purchase.

Advertisement

The episode follows a separate $57 million liquidation event on the same SKHX market days earlier. That event underscored how thin the margin for error has become. Leveraged bets that track SK Hynix’s earnings swings now carry real risk.

The post SK Hynix Trader Turns $2.26M Loss Into $6.44M Profit on Earnings Spike appeared first on BeInCrypto.

Source link

Advertisement
Continue Reading

Crypto World

Coldcard Mk3 Warning Amid Unexplained 594 BTC Sweep

Published

on

Coldcard Mk3 Warning Amid Unexplained 594 BTC Sweep

Canadian Bitcoin hardware maker Coinkite has warned users of its Coldcard Mk3 signing device to move funds from wallets whose seed phrases were generated on affected firmware. 

On Thursday, Coinkite said seeds created on an Mk3 running firmware version 4.0.1, released in March 2021, or any later Mk3 version may put funds at risk. The issue extends through version 5.0.3, the final firmware supporting the Mk3, while the Mk4, Q and Mk5 are not affected, according to the company’s early analysis.

The warning comes as Bitcoin security specialists examine an unexplained, coordinated sweep involving 594.48 BTC from single-signature addresses. However, no definitive public evidence has established that the Mk3 issue caused those transfers.

“Out of an abundance of caution,” Coinkite urged affected users to generate a new seed on an unaffected device, verify its backup and receive address, send a small test transaction and only then move the remaining funds. The company said its investigation is ongoing and promised a formal technical review.

Advertisement

Coinkite said its early analysis indicates that affected seeds used with a BIP-39 passphrase face minimal risk, stressing that this refers to a passphrase rather than the Coldcard PIN.

Experts examine 594 BTC sweep

The sweep attracted attention after a Reddit user said funds had been drained from a wallet whose seed was generated on a Coldcard Mk3 bought in May 2021. 

The user said the seed was later restored onto a Coldcard Mk4 in January 2026, meaning it had subsequently been entered into a second device. The account is self-reported and does not establish a connection between Coldcard and the broader sweep.

In a preliminary analysis posted on Friday, AnchorWatch CEO and co-founder Rob Hamilton said that 1,324 unspent transaction outputs were swept across 500 transactions within a three-block window, moving 594.48 BTC. 

Advertisement

At the time of writing, the 594.48 BTC was worth approximately $38.3 million, based on a Bitcoin price of $64,364.07, according to CoinGecko.

Hamilton said all the addresses involved were single-signature and that 562 BTC was later consolidated into another address. “At a glance, this looks like there was flawed entropy in wallet generation somewhere along the way,” he wrote. 

Related: Thousands of crypto wallets at risk from ‘Ill Bloom’ vulnerability: Coinspect

Separately, Wizardsardine CEO Kevin Loaec said his current hypothesis is that a low-entropy random-number generator, potentially in a software library, secure element or particular device batch or firmware version, produced wallet seeds with insufficient randomness.

Advertisement

He suggested that an attacker who knew of the flaw may have used an AI-generated script to brute-force affected wallets, but searched only a limited range of BIP-84 derivation paths. That could explain why the sweep appears concentrated in native SegWit addresses and why some wallets were only partially drained, though Loaec stressed that the theory remains unconfirmed. 

Loaec warned that, if his hypothesis is correct, wallets that were only partially drained may remain at risk of further theft. He added that funds held in other address types could also be exposed if the attacker expands the scan to include them.

Magazine: Inside the ‘fake police raid’ that forced a $1M Bitcoin transfer

Source link

Advertisement
Continue Reading

Crypto World

Aave moves to wind down six chains in $98M cleanup

Published

on

Aave adopts Chainlink CCIP as default engine for cross-chain actions

Aave founder Stani Kulechov said on July 30 that the lending protocol plans to retire dozens of low-use asset reserves and wind down its deployments on six blockchain networks.

Summary

  • Aave proposal targets six deployments holding $12.8 million supplied and $4.1 million in outstanding debt.
  • Fifty low-adoption reserves and twenty-one matured Pendle tokens account for most assets under review today.
  • Users can retain existing positions initially, but freezes and higher rates will encourage orderly exits.

The changes cover approximately $98.1 million in supplied assets and $15.6 million in debt. However, the measures originate from an Aave governance proposal and require DAO approval before full implementation.

The proposal would remove 50 individual reserves, retire 21 matured Pendle principal tokens and close 25 reserves across Sonic, Scroll, zkSync, Metis, Soneium and Aptos.

Advertisement

Advertisement

Aave’s six smaller markets have lost most deposits

The six complete deployments hold $12.8 million in combined supply and $4.1 million in debt. Sonic is the largest, with $7.6 million supplied and $2.7 million borrowed. Its deposits have fallen 74% over six months.

Scroll deposits declined 86% to $2.2 million, while zkSync fell 88% to $844,000. Metis and Soneium dropped to $297,000 and $173,000, respectively. Aptos liquidity fell 94% over six months, leaving $1.7 million supplied and $719,000 borrowed.

LlamaRisk said these deployments generated too little revenue to cover the cost of maintaining price feeds, monitoring systems and operational support. That conclusion reflects the risk provider’s assessment and remains subject to governance review.

Fifty reserves face removal across larger deployments

The remaining proposal targets 50 low-adoption reserves and 21 matured Pendle principal tokens across 11 Aave deployments. Together, they account for $85.3 million in supplied assets and $11.5 million in debt.

Advertisement

Assets marked for removal include low-use collateral, older bridged tokens and duplicate versions of assets that now have native alternatives. For example, bridged USDC variants would be removed from some markets where native USDC is already available.

The largest affected positions include the FBTC and eBTC wrappers on Ethereum. Together, they hold about $16.3 million in supply but only around $63,000 in borrowing. Their balances have fallen sharply because the expected demand for using them as collateral did not develop.

As previously reported, Aave DAO began exploring Pendle principal tokens in 2025. The latest proposal would retire 21 tokens that have reached maturity while allowing newer maturities to replace them where appropriate.

Aave would initially freeze affected reserves and reduce supply and borrowing caps to one unit. Existing positions could remain open, but users would be unable to make new deposits, borrow more funds or use the affected assets as fresh collateral.

Advertisement

For markets with outstanding loans, the proposal would raise the reserve factor, directing more interest to the Aave treasury and reducing returns for suppliers. Whole-market closures would use a 99% reserve factor and a 5% base borrowing rate to encourage borrowers to repay and depositors to withdraw.

If borrowers do not repay, risk managers could raise borrowing rates further. Liquidation thresholds may also be reduced gradually when officials determine that remaining collateral positions create excessive exposure.

Once positions have largely unwound, Aave plans to replace live price feeds with fixed-price oracles before completely retiring the six markets.

DAO approval remains the next step

The proposal is currently at the Aave Request for Comment stage. Under the standard governance process, an ARFC normally proceeds to an off-chain Snapshot vote before reaching a binding Aave Improvement Proposal and on-chain vote.

Advertisement

Therefore, users do not need to close their positions immediately solely because of Kulechov’s announcement. The exact implementation schedule will depend on community feedback, voting and the preparation of the required technical transactions.

The move marks a retreat from Aave’s earlier push to deploy broadly across emerging networks. Aave previously expanded to Linea after receiving DAO approval.

At the same time, the protocol is concentrating resources on Aave V4, institutional markets and higher-use deployments. As crypto.news reported, the DAO approved $25 million in funding to support that strategy.

Aave remains the largest decentralized lending protocol, with about $14.5 billion in total value locked across 23 chains.

Advertisement

Source link

Continue Reading

Crypto World

Bitcoin Miner IREN Stock Surges 30% After CEO Says Demand Outstrips Supply

Published

on

Despite the massive single-day jump, IREN is still down over the past 5 days

Bitcoin miner IREN Limited (NASDAQ: IREN), another company that has pivoted to AI infrastructure, jumped 30% on July 30, clawing back losses from a broader sell-off in AI infrastructure stocks.

Co-CEO Daniel Roberts told investors that customer demand for IREN’s computing capacity outstrips what the company can build right now.

CEO Points to Contracted Revenue, Not the Stock Price

Rather than address the recent volatility directly, Roberts used a post on X to redirect attention to the business itself. He said signed contracts already cover 85% of IREN’s $4 billion-plus 2026 annualized revenue run-rate target. Construction crews are actively working the company’s sites right now, he added.

“What we know today: demand for our capacity exceeds everything we can build, 85% of our $4bn+ 2026 target is signed, and there are thousands of people on our sites right now pouring concrete and racking GPUs. We’ve been through way worse than this. Back to it.”
Daniel Roberts, Co-CEO, IREN

Prepayments Ease Funding Concerns

The rally builds on $2.8 billion in AI cloud contracts IREN signed earlier in July with Microsoft, NVIDIA, Perplexity, and Figure AI. Several of the newer multi-year deals include customer prepayments. These payments cover roughly 45% of the related GPU capital costs, easing investor worry over how IREN funds its buildout.

IREN’s stock had fallen more than 30% over the prior month, alongside peers like TeraWulf and Applied Digital. The drop reflected a wider correction across bitcoin miner stocks pivoting toward AI hosting.

Trading volume on the rebound hit nearly 73 million shares, well above IREN’s roughly 53 million average, consistent with a short-covering squeeze layered on top of the fundamental news.

Despite the massive single-day jump, IREN is still down over the past 5 days
Despite the massive single-day jump, IREN is still down over the past 5 days. Image Source: Trading View

Whether the rebound holds may depend on how IREN’s contracted revenue converts into cash flow as its 1.2 gigawatt 2027 capacity target approaches.

The post Bitcoin Miner IREN Stock Surges 30% After CEO Says Demand Outstrips Supply appeared first on BeInCrypto.

Advertisement

Source link

Continue Reading

Trending

Copyright © 2025