Crypto World
Strategy Authorizes up to $1.25B of Bitcoin Sales as Saylor Formalizes Capital Pivot

Michael Saylor's Strategy said it can now sell Bitcoin to fund dividends, interest and stock buybacks, formalizing a capital pivot for the world's largest corporate holder of the cryptocurrency. The company, which holds 847,363 BTC, said in a press release and an 8-K filing with the U.S. Securities… Read the full story at The Defiant
Crypto World
BancaStato and Sygnum launch regulated crypto trading in Switzerland
Swiss cantonal bank BancaStato has gone live with regulated cryptocurrency trading through a partnership with digital-asset banking firm Sygnum, using the banks’ existing technology stack. The launch, announced this week to Cointelegraph, brings crypto buy, sell, and holding services to BancaStato clients via their current web and mobile banking apps.
BancaStato’s customers can access four crypto assets—Bitcoin (BTC), Ether (ETH), Litecoin (LTC), and Solana (SOL)—directly in their banking interface. The integration is built on Sygnum’s B2B banking platform and connected into Avaloq’s core and digital banking software, aiming to reduce operational duplication for the bank.
Key takeaways
- BancaStato is now offering regulated crypto trading and custody through its existing web and mobile banking channels.
- The service is powered by Sygnum’s B2B platform, integrated into Avaloq banking software rather than requiring a standalone crypto system.
- Clients can trade and hold BTC, ETH, LTC, and SOL through BancaStato’s apps.
- Sygnum says its approach is designed to shorten the timeline for banks to move from planning to live crypto offerings.
- BancaStato joins a growing network of financial institutions already using Sygnum’s B2B infrastructure.
Crypto access embedded in BancaStato banking apps
According to BancaStato’s announcement shared with Cointelegraph, the cantonal bank for the Italian-speaking Ticino region has joined Sygnum’s business-to-business platform to provide regulated digital-asset services.
The practical change for customers is that crypto functionality is routed through the bank’s familiar user experience. BancaStato clients can buy, sell, and hold the supported assets through existing web and mobile banking applications, rather than using a separate crypto venue.
Sygnum and its technology partners also highlighted that the system is designed to integrate into BancaStato’s current banking operations. In particular, Sygnum’s trading and custody functions are connected through Avaloq’s platform, allowing the bank to offer crypto without adopting an entirely independent infrastructure stack.
How the Avaloq–Sygnum setup is intended to work
The integration links Sygnum’s application programming interface (API) to Avaloq, which develops the core banking and digital banking software used by many financial institutions. The companies said this approach connects Sygnum directly to Avaloq’s banking environment.
They also claim the design can remove the need for a separate order management system for crypto activity. If accurate in deployment, that matters for operational efficiency: order management is often one of the more complex layers in moving from “decision” to a production-grade trading and custody service. Streamlining those components can reduce implementation friction and ongoing maintenance requirements.
Fritz Jost, Sygnum’s chief B2B officer, told Cointelegraph that BancaStato is the first bank using Avaloq’s software-as-a-service model to enable customers to buy, hold, and sell crypto assets via the bank’s e-banking platforms using Sygnum’s API. Jost described the rollout as a milestone for the maturity and scalability of regulated digital-asset infrastructure.
Sygnum’s expanding European banking partnerships
BancaStato is not an isolated example of European banks using the Sygnum model. Sygnum says it has more than 25 financial institutions using its B2B platform to deliver regulated digital-asset services. In addition to BancaStato, Sygnum’s banking partners cited include Societe Generale-FORGE, PostFinance, and VZ Depotbank.
This kind of partnership structure is built around letting banks reuse a licensed and operational infrastructure layer—while banks retain responsibility for their own customer-facing regulatory decisions and arrangements.
Jost told Cointelegraph that partner banks remain responsible for their regulatory frameworks, while Sygnum provides elements including licensing, custody, and trading infrastructure. He argued that this separation is what can allow banks to move from internal planning to a live offering “in months rather than years,” reflecting the time savings compared with building crypto capabilities and obtaining approvals independently.
MiCA licensing and the post-transition ramp
The BancaStato launch arrives amid a broader shift in Europe’s crypto regulatory environment. In late June, Sygnum announced that its Liechtenstein-based subsidiary, Sygnum Europe AG, received a crypto-asset service provider (CASP) license under the EU’s Markets in Crypto-Assets (MiCA) framework from Liechtenstein’s Financial Market Authority (FMA).
Sygnum said the MiCA license helps enable European partner banks to “plug into” standardized bank-to-bank infrastructure without facing a multi-year process of creating and licensing their own crypto operations. As described by Jost, the licensing status supports the ability to deliver regulated services through established channels rather than starting from scratch.
The MiCA license also came shortly before the end of the transitional period for the Markets in Crypto-Assets Regulation on July 1, according to Cointelegraph coverage of the transition timeline. With the transitional phase concluded, regulated crypto services in Europe have more defined compliance expectations, making it more important for institutions to have a clear operational model for custody and trading.
For investors, traders, and other market participants, these bank integrations can influence the “on-ramps” available to traditional finance customers. Even when token support is initially limited, extending regulated access through mainstream banking interfaces can broaden participation and reduce reliance on separate crypto exchanges for entry-level activities.
BancaStato’s next step will likely be whether it expands beyond its initial set of four supported assets, and how quickly other Avaloq-using institutions follow the same API-based approach. Readers should also watch for future announcements on additional token support and for how partner banks refine their operational processes as MiCA compliance requirements fully settle into day-to-day business.
Crypto World
Bitcoin, Ethereum-linked protocols lose $35 million in multiple attacks hours apart
Another confirmed attack was B² Network, a scaling network built to make Bitcoin cheaper and faster to transact on.
B² said in Asian morning hours Thursday an attacker gained unauthorized access to the upgrade authority of its token staking contract, the administrative permission that controls how that contract behaves.
Security firm Lookonchain traced roughly $3.86 million in B2 tokens that were sold, converted to ether and stablecoins, and moved on. B² said it had contained the incident, suspended staking and would fully compensate affected users.
A smart contract is only as safe as the keys and permissions that control it. If an attacker seizes the authority to change how a contract works, the code does not need a bug, because the attacker can simply rewrite the rules or drain the funds directly.
This is the failure mode behind the largest thefts in crypto history, from the Wormhole and Nomad bridge hacks of 2022 to KelpDAO’s roughly $290 million loss earlier this year.

And it is about to get harder to defend. In an analysis published this week, OpenAI disclosed that during an internal evaluation its AI models broke out of their test environment and compromised the servers of Hugging Face, chaining together stolen credentials and previously unknown software flaws to do it.
Crypto World
BancaStato Launches Bitcoin Trading With Sygnum
Swiss bank BancaStato has launched regulated cryptocurrency trading using digital asset bank Sygnum and banking software provider Avaloq.
BancaStato, the cantonal bank serving Switzerland’s Italian-speaking Ticino region, joined Sygnum’s business-to-business (B2B) banking platform to offer crypto asset services, according to a Thursday announcement shared with Cointelegraph.
The integration allows BancaStato customers to buy, sell and hold four crypto assets, including Bitcoin (BTC), Ether (ETH), Litecoin (LTC) and Solana (SOL), through the bank’s existing web and mobile banking apps.
BancaStato joins more than 25 financial institutions using Sygnum’s B2B platform to offer regulated digital asset services.
How BancaStato’s crypto service works
BancaStato integrated Sygnum’s trading and custody services into its existing Avaloq banking system.
Headquartered in Zurich, Avaloq develops the software banks use to run their core banking and digital banking services. The integration connects Sygnum’s application programming interface (API) directly to Avaloq’s platform, allowing customers to access crypto trading from their existing banking app.
The setup also removes the need for a separate order management system, which the companies said reduces operational complexity and makes it easier to add new features.
Related: Revolut says USDT delisting is limited to EEA, Switzerland
According to Fritz Jost, Sygnum’s chief B2B officer, BancaStato is the first bank using Avaloq’s software-as-a-service platform to let customers buy, hold and sell crypto assets through its e-banking platforms using Sygnum’s API. Jost said the launch marked a “significant step in the maturity and scalability of regulated digital asset infrastructure.”
Sygnum expands European banking network
Sygnum’s banking partners include Societe Generale-FORGE, PostFinance and VZ Depotbank.
Sygnum announced in late June that its Liechtenstein-based subsidiary, Sygnum Europe AG, received a crypto-asset service provider (CASP) license under the European Union’s Markets in Crypto-Assets (MiCA) regulation from Liechtenstein’s Financial Market Authority (FMA).
“This means European partner banks can plug into the same proven bank-to-bank infrastructure without going through the multi-year process of building and licensing their own crypto operations,” Jost told Cointelegraph.

Source: Sygnum Bank
He said banks remain responsible for their own regulatory arrangements, while Sygnum provides the licensing, custody and trading infrastructure. “That is exactly what allows a bank to go from decision to live offering in months rather than years.”
The license came shortly before the end of the Markets in Crypto-Assets Regulation transitional period on July 1, allowing Sygnum Europe to provide regulated crypto asset services under MiCA.
Magazine: Binance & OKX users face $1,900 fines in Vietnam, Coinbase in China? Asia Express
Crypto World
Hedge Fund Billionaire Paulson Says Gold Bull Run Only Just Beginning
The hedge fund billionaire who made his fortune shorting subprime mortgages before the 2008 financial crisis said gold is only in the early stages of a long-term bull market.
Paulson argued that fading trust in fiat currencies will keep pushing investors toward gold. He said demand is broadening beyond central banks to include private investors too.
Central Banks Keep Buying as Paulson Bets Bigger on Miners
Central banks have expanded their gold reserves for several years. A recent industry survey found most plan to keep growing their holdings, even as they logged 41 tonnes of purchases during one of gold’s weaker months this year.
Spot gold traded near $4,121 an ounce Wednesday night. That is up sharply from June’s sub-$4,000 dip, though still well below the record $5,600 gold touched in late January.
“As people lose faith in paper currencies, gold as an alternative will continue to grow.”
— John Paulson, CNBC
Paulson’s NovaGold Goes Big in Mining
Paulson’s comments came as NovaGold Resources (NG) agreed to acquire his firm’s 40% stake in the Donlin Gold project in Alaska. Paulson serves as NovaGold’s co-chairman.
The deal raises NovaGold’s ownership of the project to 100%. It creates a new US-domiciled company worth roughly $4.2 billion, with existing NovaGold shareholders holding about 65% and Paulson receiving the remaining 35%.
Paulson said he prefers early-stage gold miners over bullion itself. He pointed to NovaGold’s 40 million ounces of gold resources against that valuation as evidence of the upside.
Not every bank shares his conviction. JPMorgan recently cut its Q4 forecast for gold after a volatile stretch, even while keeping a bullish long-term view.
The NovaGold deal still needs shareholder, court, and regulatory approval, with both companies targeting a close in the fourth quarter.
The post Hedge Fund Billionaire Paulson Says Gold Bull Run Only Just Beginning appeared first on BeInCrypto.
Crypto World
Chainlink Whale Activity Explodes as $100 LINK Predictions Gain Momentum
Two types of whale activity have rocketed on the Chainlink network, including a substantial LINK accumulation, which could point to a resurgence in the ecosystem and the native token’s price performance.
Chainlink continues to improve in terms of Real World Assets development, increasing to the second position in Santiment’s recent ranking.
LINK Whale Activity Blossoms
Citing recent data from Santiment again, popular crypto analyst Ali Martinez noted that whale activity on Chainlink had “surged over the past two weeks.” The graph below demonstrates the impressive increase, which included more than 20 transactions for over $1 million earlier this week. According to Martinez, this signals “growing interest from large holders.”
Whale activity on the Chainlink $LINK network has surged over the past two weeks.
Today alone, more than 20 transactions worth over $1 million each were recorded, signaling growing interest from large holders. pic.twitter.com/iIvZ68joXx
— Ali Charts (@alicharts) July 22, 2026
Separately, the analyst said whales had gone on an accumulation spree, acquiring over 14 million LINK tokens within less than a month.
“Large-scale accumulation like this often reflects growing confidence from major holders and is worth keeping an eye on,” he concluded.
The data shows that their holdings have grown from under 170 million to roughly 182-3 million as of the start of the current business week.
Meanwhile, Santiment’s RWA development ranking placed LINK in second place, trailing only Hedera. The ranking compares how these chains performed compared to the previous month, showing a solid performance from Chainlink.
$50-$100 LINK?
Crypto Patel recently weighed in on LINK’s price performance, warning that 99% of people will ignore the setup before “it’s too late.” The analyst compared the current market behavior with the moves from six years ago when the token went on a wild ride that eventually brought it up to its all-time high of almost $53 (CoinGecko data).
He believes the fact that the spot LINK ETFs have not seen a single red month is extremely bullish, even though the net inflows have slowed since May. The cumulative total net inflows are well over $125 million, which, he noted, is proof that “smart money continues to accumulate,” but most retail investors “still believe LINK is dead.”
After outlining the current environment as the “biggest” opportunity since conviction is at its lowest, Patel brought up some massive price targets for LINK during the next bull cycle of somewhere between $50 and $100.
The post Chainlink Whale Activity Explodes as $100 LINK Predictions Gain Momentum appeared first on CryptoPotato.
Crypto World
Ethics Rules Were Not Enough to Win Democrats on CLARITY Act
Seven Senate Democrats say the updated CLARITY Act text falls short. They opposed the proposed draft, even after it added ethics rules barring public officials from issuing digital assets.
The 616-page bill needs 60 votes to clear the Senate. Their opposition complicates the path to that threshold before the August recess.
What the New CLARITY Act Text Adds
Senate Republicans released the 616-page bill, formally H.R. 3633, on Wednesday. The Digital Asset Market Clarity Act sets a federal framework for crypto oversight.
The text divides authority between the Securities and Exchange Commission (SEC) and the Commodity Futures Trading Commission (CFTC). Only 2 parts are new since the May draft.
The additions are ethics requirements and a law enforcement section with stablecoin seizure powers. The former stops covered officials from issuing or sponsoring a digital asset in exchange for consideration.
The group spans the President, Vice President, and lawmakers, plus their spouses, throughout their time in office. The agreement sunsets on January 20, 2029.
Democrats and Banks Seek Changes
Nonetheless, the addition was not enough for democrats. Senators Catherine Cortez Masto, Angela Alsobrooks, Cory Booker, Ruben Gallego, John Hickenlooper, Mark Warner, and Raphael Warnock said the language still needs work, alongside consumer protection, illicit finance, and market integrity.
“The Republican-proposed text of the CLARITY Act as it currently stands falls short… We have been working in good faith with our Republican colleagues for the past year and will continue doing so to get this over the finish line,” the statement read
According to Semafor, Alsobrooks said she will oppose the crypto bill unless Republicans strengthen its ethics rules. She criticized the draft for relying only on the Justice Department to enforce them and called that approach “wild and unserious and stone crazy.” She wants state attorneys general empowered to act if the DOJ does not.
Follow us on X to get the latest news as it happens
Meanwhile, the banking industry is also seeking changes. Six trade groups, led by the American Bankers Association (ABA), signed a joint statement on deposit risk.
“The latest version of the Digital Asset Market Clarity Act released today in the Senate still puts at risk the local lending that drives economic activity in the US,” they said.
Majority Leader John Thune plans to bring the bill to the floor next week. Whether the revised text wins enough Democratic support remains the key question.
Subscribe to our YouTube channel to watch leaders and journalists provide expert insights
The post Ethics Rules Were Not Enough to Win Democrats on CLARITY Act appeared first on BeInCrypto.
Crypto World
Verus Ethereum Bridge hacked again for $7.54M after May exploit
The Verus Ethereum Bridge has suffered another exploit, with an attacker draining about $7.54 million in assets from the same contract hit in May.
Summary
- Verus Ethereum Bridge lost about $7.54 million in a new exploit targeting its import path.
- Blockaid says the attack resembles May’s exploit, though the root cause remains under active investigation.
- Three crypto exploits reported Thursday caused combined losses of roughly $35.55 million, according to Lookonchain.
Blockchain security firm Blockaid detected the attack on Ethereum on July 23 and said the attacker used the bridge’s import path to trigger payouts that were not backed by matching assets on the source side.
The incident involved a different transaction and attacker-controlled wallet from the May breach, according to Blockaid. The firm said the new attack used the same bridge contract, entry path and apparent bug class. However, the exact root cause remained under investigation when the alert was published.
Verus bridge exploit drains multiple assets
Onchain records show the exploit transaction interacted with the Verus Ethereum Bridge contract at 03:45 UTC on July 23. The transaction transferred about 1,137 ETH and several tokens to an attacker-controlled address. The assets included tBTC, USDC, USDT, EURC, MKR and scrvUSD. Etherscan valued the main bridge outflows at roughly $7.54 million at the time.
Blockaid said the attacker abused the bridge import process to produce unbacked Ethereum-side payouts. The firm identified the receiving address as 0xCFd0…2D54 and linked the withdrawal to the same bridge contract involved in the earlier Verus incident. It has not yet published a complete technical report on the new transaction.
Additionally, the latest exploit comes about two months after the Verus Ethereum Bridge lost roughly $11.58 million in a separate attack. Security researchers said the May attacker exploited a validation gap that allowed a forged cross-chain import to pass verification even though the value committed on the source side did not match the payout released on Ethereum.
Blockaid said the July attack “appears related to the previous Verus Ethereum Bridge incident in May 2026.” It also described the two incidents as involving the “same bridge contract, same entry path, and same bug class,” although a confirmed technical cause for the latest exploit has not been released.
As crypto.news reported in May, the first Verus bridge attacker later returned 4,052.4 ETH, worth about $8.5 million at the time, after the project offered settlement terms. The attacker kept 1,350 ETH as a bounty. The returned amount represented about 75% of the funds held by the exploiter after the stolen assets had been converted into ETH.
Three exploits reported within hours
The Verus attack formed part of a broader series of security incidents reported within hours. Onchain tracker Lookonchain said AFX Trade, Verus and B² Network had suffered exploits with combined reported losses of about $35.55 million. The figures included $24.15 million from AFX, about $7.55 million from Verus and roughly $3.86 million from B² Network.
Earlier today, an AFX-operated bridge lost $24.15 million in USDC before the attacker moved the funds to Ethereum and converted them into 12,467 ETH. Offchain Labs said that incident did not affect Arbitrum’s native bridge and originated from infrastructure operated by a third-party protocol.
The incidents add to continued scrutiny of cross-chain systems. A recent crypto.news explainer noted that bridges must verify events across separate blockchains while controlling assets held in shared reserves. Errors in message validation, contract logic or access controls can allow a transaction to release assets without a valid matching transfer.
Root cause and recovery details remain pending
Blockaid said the new Verus exploit appears to involve the same type of weakness seen in May, but stopped short of confirming that the exact earlier vulnerability caused the July drain. The May attack involved missing validation between the value committed on the source chain and the amount released on Ethereum, according to security analyses.
The latest transaction confirms that funds left the Verus bridge for the new attacker wallet, but the reviewed sources did not confirm whether any assets had since been frozen, returned or recovered. They also did not provide a new remediation plan or a timeline for changes to bridge operations.
Further technical details could clarify whether the May flaw remained exploitable, whether a related weakness caused the new incident, or whether the attacker used another route through the same import process. The attacker’s next fund movements could also show whether the stolen assets are converted or moved through other services.
The case remains a developing story.
Crypto World
Louisiana pension fund boosts Bitcoin exposure with 21,300 MSTR shares
The Louisiana State Employees’ Retirement System has increased its stake in Strategy, giving the public pension fund more indirect exposure to Bitcoin through the Nasdaq-listed company.
Summary
- Louisiana’s pension fund raised its Strategy holding to 21,300 shares, increasing indirect exposure to Bitcoin.
- The $16.3 billion retirement system added 700 MSTR shares from its first-quarter holding of 20,600.
- Strategy currently holds 843,775 Bitcoin, keeping MSTR closely tied to movements in Bitcoin’s market price.
A regulatory filing covering holdings as of June 30 shows the retirement system owned 21,300 Strategy shares, up 3.4% from 20,600 shares at the end of the first quarter. The position had a quarter-end reported value of about $1.85 million. BitcoinTreasuries.NET later valued the holding at roughly $2.13 million in a July 22 post.
Louisiana pension fund adds to Strategy position
The latest disclosure shows that the Louisiana State Employees’ Retirement System added 700 MSTR shares during the second quarter. The fund previously held 20,600 shares as of March 31, according to institutional ownership data.
BitcoinTreasuries.NET described the move by saying, “Government employees are getting BTC exposure.” However, the fund does not directly hold Bitcoin through the reported position. It owns shares in Strategy, whose balance sheet contains the largest corporate Bitcoin treasury.
The size of the retirement system has been reported using different measures. LASERS said in August 2025 that its investment assets stood at $16.3 billion. Its official history page says the total market value of assets reached $17.2 billion for the fiscal year ending June 30, 2025. The MSTR position therefore accounts for only a small part of the overall portfolio.
LASERS administers 24 retirement plans covering more than 150,000 members and their families. Its broader portfolio includes traditional equities and other asset classes, meaning the Strategy holding represents one listed equity position rather than a direct allocation of pension assets into Bitcoin.
MSTR offers indirect exposure to Strategy’s Bitcoin treasury
Strategy describes itself as a Bitcoin treasury company and uses equity, debt and other securities to finance its balance sheet. The company says its securities offer investors varying degrees of economic exposure to Bitcoin while it continues operating its enterprise software business.
The company currently holds 843,775 BTC. As crypto.news reported, the Bitcoin balance remained unchanged through July 19 while Strategy raised another $263.5 million through MSTR share sales and increased its U.S. dollar reserve to $3.225 billion.
MSTR does not track Bitcoin in the same way as a spot Bitcoin exchange-traded fund. Its price can also respond to share issuance, financing costs, corporate decisions and changes in how investors value Strategy’s Bitcoin holdings. The Louisiana fund’s position therefore gives it indirect Bitcoin-linked exposure through company stock rather than ownership of BTC itself.
The increased pension fund position also comes during a changing period for Strategy. The company reduced its Bitcoin holdings to 843,775 BTC in early July after selling some of its treasury assets under a new capital framework. Its holdings have remained at that level in subsequent disclosures. As previously reported, the sales marked a change from Strategy’s long-running accumulation-focused approach.
Pension funds explore more routes to Bitcoin exposure
The Louisiana position comes as retirement funds and state-backed investment systems test different ways to gain crypto exposure. Some use shares of Bitcoin treasury companies or regulated investment products rather than holding digital assets directly.
Japan’s National Business Corporate Pension Fund plans to allocate about 1% of its assets to crypto through a managed multi-asset fund during fiscal 2026. The fund described the allocation as part of its currency diversification strategy.
In the U.S., states are also considering crypto-linked options for public funds. Indiana enacted legislation that opens a route for certain public retirement and savings programs to offer at least one crypto-linked investment option through self-directed brokerage services.
Meanwhile, Florida lawmakers proposed allowing selected state-controlled funds, including pension assets, to allocate up to 10% to eligible Bitcoin products and other approved digital assets. Those proposals use a different structure from Louisiana’s Strategy investment.
In addition, the Louisiana fund’s increase from 20,600 to 21,300 shares represents a modest change within a multibillion-dollar retirement portfolio. Still, the filing confirms that the pension manager maintained and expanded its position rather than exiting MSTR during the second quarter.
The move also occurred while Strategy remained the largest publicly traded corporate holder of Bitcoin. With 843,775 BTC on its balance sheet, changes in Bitcoin’s market value remain an important factor for investors holding MSTR, although the stock carries risks and characteristics separate from direct Bitcoin ownership.
Crypto World
Hackers Drain $31.6M After Two Crypto Bridge Breaches in 7 Hours
Cross-chain security issues remain a major pain point for crypto markets, after investigators reported two separate bridge-related exploits occurring only hours apart. According to on-chain analytics firm Blockaid, the combined theft totaled more than $31.6 million, with funds taken from bridge infrastructure used by decentralized perpetual exchange AFX and the Verus Ethereum Bridge.
Blockaid said AFX’s bridge lost $24.15 million on Wednesday, before another attack targeting the Verus Ethereum Bridge resulted in roughly $7.5 million drained from bridge reserves. The back-to-back incidents underscore how bridge operators—and the protocols that integrate them—can be exposed even when exploits are not tied to a single chain-level weakness.
Key takeaways
- Blockaid reported losses of $24.15 million from an AFX-operated bridge on Arbitrum and about $7.5 million drained from the Verus Ethereum Bridge within hours.
- Offchain Labs co-founder Stephen Goldfeder said Arbitrum’s native bridge was not hacked, pointing to activity originating from a third-party protocol.
- Security researchers suggested the AFX incident may have involved compromised keys rather than a smart contract logic flaw.
- Blockaid said the Verus exploit appears to mirror a prior May incident, using a similar method while involving a different attacker wallet.
- Both cases highlight that bridges remain high-value targets because they custody large asset pools and move value across ecosystems.
AFX bridge exploit on Arbitrum: what was targeted
Blockaid said it detected an exploit at 9:30 pm UTC aimed at a bridge operated by AFX, a decentralized perpetual exchange running on Arbitrum. The investigation framed the event as a bridge compromise affecting a third-party integration rather than a breach of Arbitrum’s core bridging infrastructure.
According to Offchain Labs co-founder Stephen Goldfeder, a bridge hack report circulating online had impacted a transaction originating from a third-party protocol, and that the Arbitrum native bridge itself had not been exploited. Goldfeder stated that the transaction in question originated from another protocol and emphasized that Arbitrum’s native bridge “has not been hacked or exploited in any way.”
Additional analysis from SunSec, the founder of the DeFi security community DeFiHackLabs and a contributor to SEAL, suggested that the evidence pointed more toward compromised keys than toward a vulnerability in smart contract logic. While that distinction matters for incident response—key compromise typically demands urgent credential rotation and broader access review—it also signals that the weakest point may not always be the bridge contracts themselves.
Cointelegraph sought comment from AFX regarding the reported exploit, but the additional reporting available here centers on what Blockaid and affiliated investigators observed during the incident.
Verus Ethereum Bridge attack: a similar method to May
In a separate incident, Blockaid reported an exploit targeting the Verus Ethereum Bridge that drained approximately $7.5 million across multiple assets held in bridge reserves. The listed tokens included Ether (ETH), tBTC, USDC, USDt, EURC, MKR, and scrvUSD.
Blockaid said the attack method appears similar to a previous Verus Ethereum Bridge incident reported in May, which resulted in the theft of $11.58 million. In that earlier case, Blockaid said the same overall approach was used, but by a different attacker wallet.
According to Blockaid, the attacker used the bridge “import path” to trigger “unbacked Ethereum-side payouts.” In practical terms, this points to a workflow-level weakness: attackers may be able to induce the bridge to release assets on one side of the system without corresponding backing on the other side, creating a direct path to reserve depletion.
For users and integrators, the repeated nature of the tactic raises a persistent risk: even when teams patch one vulnerability, the operational mechanics of how imports and payouts are handled can remain exploitable if the underlying assumptions aren’t fully addressed.
Why bridge failures keep recurring
Bridge exploits are difficult to eliminate entirely because cross-chain infrastructure often combines multiple components: custody of assets, message passing or import/export mechanisms, and permissioning for triggering settlement flows. When attackers find a seam between those elements—whether through compromised credentials, incorrect authorization, or weaknesses in how cross-chain states are validated—the result is frequently rapid draining of funds.
On-chain investigator TheCrypticWolf summarized the broader issue in a post on X, arguing that bridges remain a weak link until “security is upgraded.” While that statement reflects a general view rather than new incident-specific evidence, the two reported attacks within the same day give it concrete support: high-value bridge reserves make the system attractive, and high complexity makes comprehensive hardening challenging.
There is also an important asymmetry across the two incidents. Blockaid’s reporting on the AFX case was paired with Goldfeder’s clarification that Arbitrum’s native bridge was not compromised, suggesting the problem lay in third-party integration or bridge controls tied to a particular protocol. In contrast, Blockaid’s description of the Verus incident emphasizes how the bridge import mechanism can lead to Ethereum-side payouts that are not properly backed—an issue that may relate more directly to settlement logic and state assumptions.
What to watch next for affected ecosystems
Bridge-related incidents typically lead to emergency measures such as pause controls, increased monitoring, and changes to custody or authorization workflows. Readers should watch for follow-up disclosures from AFX and the Verus ecosystem, especially around what Blockaid and other investigators determine about root cause—whether it’s key compromise, an authorization failure, or a repeatable weakness in import/export settlement.
More broadly, these events reinforce that cross-chain exposure isn’t limited to the bridge operators alone: decentralized applications and traders relying on bridges for liquidity and settlement should treat bridge security as a continuously evolving risk, not a one-time checkbox.
Crypto World
SEC Agrees to Overhaul Recordkeeping After Settling Coinbase Lawsuit Over Gensler’s Lost Texts
The US Securities and Exchange Commission went on a blatant war against the cryptocurrency industry in the past couple of years of Gary Gensler’s tenure, especially following the loud collapse of FTX.
However, the new administration settled most cases, and now it was time for one that was actually initiated by Coinbase. It came with some groundbreaking changes as well.
From Defendant to Plaintiff
The legal disputes between the two parties began in 2023 when the regulator went after the largest US-based crypto exchange. However, the roles reversed a year later when Coinbase, through its research firm History Associates, sued the watchdog after the latter denied requests for internal communications related to its approach to crypto regulation.
The Brian Armstrong-led firm argued that the requested records could shed some light on how the SEC developed its enforcement strategy against crypto companies during the Biden administration, including legal theories underpinning several high-profile lawsuits. Recall that the SEC had sued industry giants like Binance, Ripple, and many others.
The agency has now settled with Coinbase in the Freedom of Information Act (FOIA) lawsuit and has agreed to pay $150,000 in attorney fees, release two previously withheld documents, and review its policies governing the presentation of text messages and other electronic communications.
The settlement was announced in an opinion piece by Coinbase Chief Legal Officer Paul Grewal, who said it marked an important victory for government transparency. However, there’s no official confirmation from the SEC as of press time.
Why It Matters
Under Gensler’s leadership, the agency imposed billions of dollars in penalties on banks and financial institutions for failing to preserve employee communications conducted through texts and other unofficial channels. Coinbase, on the other hand, argued that the regulator should be held to the same standards it had enforced against the private sector.
The legal dispute intensified after the SEC disclosed that certain texts involving Gensler and other senior officials had been automatically deleted, making them unavailable for production under the FOIA requests.
Although the settlement does not confirm any wrongdoing by the SEC, it requires the watchdog to review its record-retention procedures, which is believed to be particularly groundbreaking for a regulator whose own rules emphasize preserving official communications.
The post SEC Agrees to Overhaul Recordkeeping After Settling Coinbase Lawsuit Over Gensler’s Lost Texts appeared first on CryptoPotato.
-
NewsBeat7 days agoLondon Mayor Sadiq Khan handed a peerage by Keir Starmer alongside 15 other Labour figures… just days before the PM leaves No10
-
Fashion6 days agoWeekend Open Thread – Corporette.com
-
Politics5 days agoThe House | The City of London can help the new chancellor deliver growth in every postcode
-
Crypto World5 days agoRipple Payments Joins MiCA With 14 Firms, Does It Mean Anything For XRP?
-
Crypto World6 days agoTwo July Windows Left: The CLARITY Act’s Senate Fight and What Failure Means
-
Politics4 days agoDemocrats look to World Cup watch parties to register thousands of voters
-
Crypto World5 days agoRipple wins EU-wide access as ESMA adds it to MiCA register
-
Crypto World2 days agoGrayscale Files For Worldcoin ETF, WLD Registers Sharp Rise
-
NewsBeat3 days agoUnregistered fitter used Gas Safe logo on business flyers
-
Tech2 days agoSail Virtually Aboard The “Itanic” With IA-64 Emulator
-
Crypto World6 days agoInjective Submits SEC Transfer-Agent Registration to Onchain Ownership Records
-
Tech2 days ago
Turtle Beach Command Series KB7 review: a nifty screen-equipped gaming keyboard
-
NewsBeat6 days agoRegistration is now open for March for Men with Kev 2026
-
Business1 day agoNew Jersey voter registration controversy explained: How 6,600 noncitizens got on the rolls, and what happens next
-
Crypto World6 days agoClaude Fable 5 Slips to Second in AI Coding Leaderboard
-
News Videos6 days agoMoney | Class 12 Economics | CBSE Board Exam 2026-27
-
Business6 days agoBanco Bilbao Vizcaya Argentaria, S.A. (BBVA) Discusses Global Macro Environment and Economic Outlook for Core Markets Transcript
-
Crypto World5 days agoKaspersky exposes OkoBot’s 20-module crypto wallet attack
-
News Videos4 days agoBig Money Is Entering XRP
-
NewsBeat5 days agoDurham County Council to send out electoral registration emails

You must be logged in to post a comment Login