Crypto World
Strategy Hasn’t Bought Bitcoin in 6 Weeks and Just Sold at a Loss Again: What Does Saylor’s New Framework Actually Mean?
In the latest Bitcoin news, Strategy (MSTR) sold 1,638 BTC for approximately $105 million last week, disclosed via an SEC filing dated August 3, 2026, marking the firm’s third discrete Bitcoin disposal of 2026 and its sixth consecutive week without a purchase.
The proceeds, combined with $290.6 million raised through common stock issuance, funded $81.2 million in STRC preferred stock repurchases and added $250 million to Strategy’s USD reserve, pushing that figure to $4 billion.
The average sale price for the latest tranche was roughly $64,000 per BTC, meaningfully below Strategy’s overall average acquisition cost of $75,419.
With 842,138 BTC on the books at a total cost of $63.51 billion, the company is sitting on a paper loss of approximately $10.9 billion at current prices, according to Arkham Research.
MSTR slipped 1.9% in pre-market trading following the disclosure, with Bitcoin near $63,500.
Discover: Get Paid to Be Right, $25 to Start on Kalshi
Bitcoin News: Why Strategy Keeps Selling Below Cost
The mechanics here matter. Strategy finances its Bitcoin treasury through a stack of debt instruments and preferred-stock obligations, STRC, STRK, STRD, STRF, and STRE, all carrying fixed or variable dividends that must be settled in U.S. dollars.
Quarterly preferred dividend costs have surged from $49.1 million a year ago to $400.7 million, according to supplementary research, leaving the firm with no viable alternative to regular cash generation.
To codify this shift, Michael Saylor’s firm introduced the Digital Credit Capital Framework in late June 2026, which explicitly authorizes BTC sales to fund dividends, debt service, and repurchases.
This formalizes what was effectively already happening: Bitcoin is no longer treated as an untouchable reserve but as an active liquidity source. The “never sell” chapter has closed.
The sale proceeds were split between two uses: a portion went directly to STRC dividend payments, and the remainder funded the buyback of 912,143 STRC shares for $81.2 million in aggregate, according to the primary source.
Repurchasing preferred shares below their $100 stated value is arithmetically accretive. Strategy retires $100 of future obligations for less than $100 in cash. The question is whether the pace of buybacks is sufficient to push STRC meaningfully closer to par.

STRC closed July at $89.46, and Strategy confirmed it will hold the annual dividend rate at 12% rather than raise it further, stating it will not recommend an increase until shares trade consistently near $100.
At the current discount, that 12% stated yield translates to an effective yield of roughly 13.4% for buyers in the secondary market – a spread that signals the market still prices in meaningful execution risk on this crypto treasury model.
Strategy’s Q2 results further illustrated the financial pressure, with an $8.22 billion net loss driven largely by unrealized Bitcoin impairments.
Discover: Your Market Calls Are Worth Something. Start With Free $25 on Kalshi
Six Weeks Without a BTC Purchase: What That Signals
The accumulation pause is now the most structurally significant data point that Strategy produces each week. Since early 2020, the company’s identity and a meaningful portion of MSTR’s equity premium over net asset value rested on relentless BTC acquisition.
Six weeks of no purchases, alongside three sales totaling roughly 5,258 BTC and $323 million in proceeds, represents a clean break from that pattern.
All three 2026 disposals have been executed below the $75,419 average cost basis, meaning Strategy is realizing losses on each tranche to service obligations that compound regardless of Bitcoin’s price.
The $4 billion USD reserve, which the company says covers approximately 2.3 years of preferred dividends and interest, provides a buffer, but it also represents capital that is not working in BTC. The opportunity cost calculus cuts both ways: if Bitcoin recovers above $75,000, Strategy’s pause looks costly; if BTC extends its decline, the cash cushion looks prudent.
Strategy remains one of the largest corporate holders of Bitcoin globally despite the reductions, with 842,138 BTC still on its balance sheet. The disposals to date are a small fraction of total holdings, and the firm has not signaled any intent to substantially reduce its BTC position.
What has changed is the framing: Bitcoin is now explicitly a funding source for a complex institutional treasury structure, not simply a one-directional accumulation play.
Discover: Get Paid to Be Right, $25 to Start on Kalshi
Don’t Miss Out on Our $1,000 USDT Airdrop on ByBit
The post Strategy Hasn’t Bought Bitcoin in 6 Weeks and Just Sold at a Loss Again: What Does Saylor’s New Framework Actually Mean? appeared first on Cryptonews.
Crypto World
Wall Street predicts XRP ETFs will attract $8 billion in inflows, with XRP holders potentially earning up to $9,000 per day
Disclosure: This article does not represent investment advice. The content and materials featured on this page are for educational purposes only.
XRP ETF inflows surpass $1.5 billion as investors increasingly explore alternative strategies, including EX DeFi cloud mining, for long-term crypto exposure.
Summary
- XRP ETF inflows surpass $1.5B as institutional demand grows and investors explore new digital asset opportunities.
- XRP ETF milestone boosts market confidence, while EX DeFi attracts attention from investors seeking alternative yield options.
- Institutional XRP demand accelerates with ETFs crossing $1.5B in inflows amid evolving investment strategies.
According to previous forecasts from JPMorgan and Standard Chartered, spot XRP ETFs are expected to attract $4 billion to $8 billion in inflows in the long term.

While current inflows into XRP ETFs have not yet reached the high levels previously predicted by Wall Street, the cumulative net inflows have already reached approximately $1.51 billion, successfully surpassing a significant milestone and further strengthening market confidence in XRP’s long-term prospects.
With ETFs continuing to receive funding support, and XRP prices not yet showing a significant increase, many investors are beginning to consider a practical question: besides waiting for price appreciation, are there more efficient and sustainable ways to participate in XRP’s long-term value growth?
Against this backdrop, a growing number of investors are turning their attention to EX DeFi cloud mining platforms, hoping to explore more diverse long-term returns on digital assets amidst market volatility, rather than solely relying on XRP’s price appreciation.
XRP ETF inflows surpass $1.5 billion, market attention continues to rise
According to market data cited by TradingView, driven by continuous net inflows, XRP-related exchange-traded funds (ETFs) have seen cumulative inflows exceeding $1.5 billion, marking a significant milestone for XRP.
Meanwhile, overall market liquidity continues to improve. Although XRP trading activity has slowed somewhat, and many retail investors remain relatively cautious, institutional investor demand has maintained a slight increase, contributing to continued net inflows for most trading days.
ETF inflows continue, XRP investors focus on more diverse participation methods
With the continued inflow of ETF funds, more and more XRP investors are focusing on EX DeFi, exploring more robust and sustainable ways to grow the value of digital assets through its automated cloud mining system and yield aggregation mechanism.
Compared to highly volatile leveraged trading or ETF investments, EX DeFi offers a more convenient way to participate in digital assets, helping users engage with the XRP ecosystem even in volatile markets and further improve the efficiency of digital asset utilization to generate returns. For users with a certain amount of capital, different asset management solutions can be chosen according to their needs to explore long-term value growth opportunities.
About EX DeFi
Headquartered in the UK, EX DeFi strictly adheres to local laws and regulations and operates under European regulatory frameworks such as MiCA and MiFID II. It continuously strengthens platform governance, security measures, and operational transparency to create a safe, reliable, and sustainable cloud mining service for users.
The platform employs a multi-layered security architecture, including:
- PwC annual financial and security compliance audit
- Lloyd’s of London digital asset custody insurance
- Cloudflare enterprise-grade cybersecurity protection and McAfee® security system
- Cold and hot wallets, multi-layered encryption architecture, and two-factor authentication (2FA).
Currently, EX DeFi supports multiple mainstream digital assets such as XRP, BTC, ETH, USDT, USDC, DOGE, LTC, and SOL, providing users with more flexible and convenient choices.
How to earn daily yields with EX DeFi
EX DeFi is easy to use; even beginners can get started in minutes with just four steps:
1: Register an Account
2: Deposit Cryptocurrency
On the Deposit Center page, select XRP (or other cryptocurrencies), copy the corresponding deposit address on the platform, and then transfer the XRP through a wallet or exchange. (No tags required)
3: Choose a Mining Contract
Choose a mining plan that suits a particular budget; mining will start automatically after system activation.
4: Automatically Receive Daily Rewards
The platform provides 24/7 intelligent mining services, with rewards automatically settled to an account 24 hours a day. Users can easily earn passive income without any user intervention.
Popular profit contracts
BTC (Beginner Trial Contract): Investment of $100, Term: 2 days, Daily Yield: $4, Total Profit: $100 + $8
DOGE (Golden Shell Mini Dogecoin Pro): Investment of $500, Term: 6 days, Daily Yield: $6.5, Total Profit: $500 + $39
BTC (Canaan-Avalon-A1466): Investment of $1,000, Term: 10 days, Daily Yield: $13.4, Total Profit: $1,000 + $134
LTC (Bitmain Antminer L7): Investment of $5,000, Term: 20 days, Daily Yield: $73.5, Total Profit: $5,000 + $1,470
BTC (Bitmain S19K-Pro): Investment of $10,000, Term: 30 days, Daily Yield: $161, Total Profit: $10,000 + $4,830
Click here for more details on popular EX DeFi mining contracts.
Summary
While the inflow of funds into the XRP ETF still falls short of Wall Street’s previous expectations, continued institutional inflows, an improving regulatory environment, and the development of the XRP ecosystem continue to provide strong support for its long-term value. In the future, XRP’s market performance will still depend on fund flows, application implementation, and changes in the overall market environment.
Against this backdrop, more and more investors are focusing on long-term allocation and return management of digital assets, rather than just price fluctuations. EX DeFi aims to provide users with more diverse participation methods through smarter and more efficient cloud mining services, meeting the needs of different investors for long-term digital asset value growth.
Instead of chasing price increases, visit the official EX DeFi platform as soon as possible to start mining with one click and easily earn XRP.
Disclosure: This content is provided by a third party. Neither crypto.news nor the author of this article endorses any product mentioned on this page. Users should conduct their own research before taking any action related to the company.
Crypto World
As Clarity Act teeters, mystery group hammers away at crypto in Washington ads
The crypto industry’s central policy drive is to get U.S. laws that elevate it to a fully regulated and government-approved corner of the financial system. While the legislation to do that is struggling with its final Senate test, a mystery organization is flooding Washington, DC, with ads linking crypto to terrorists and drug cartels.
Across television and social media, the localized campaign warns in one example: “The worst people operating in the darkest places use crypto because there are no guardrails,” citing connections to drug cartels, terrorists and people praying against seniors.
“Let’s bring crypto out of the shadows now,” the ads say.
The recently emerging group behind the campaign is Crypto Watchdog, run by Executive Director Chapin Fay, a media strategist who had been involved in past Republican political campaigns but hadn’t been previously associated with crypto matters.
“Our mission is fairly simple and direct,” he told CoinDesk in an interview. “It’s to bring sunlight and transparency to an over-$2 trillion industry that has historically not been very transparent.”
Crypto World
A New Ethereum Proposal Could Halve Staking Rewards: Who Feels It First?
Ethereum Foundation researcher Justin Drake and five co-authors want to shrink the reward for staking ETH. Their draft plan would switch that reward off once half of all ETH is locked up.
Stakers would earn less. Everyone else would hold a slightly bigger slice of ETH. BeInCrypto maths puts the new reward near 1.1% a year, down from 2.6% now.
Why the Justin Drake Ethereum Proposal Targets Issuance
Ethereum pays people to help run it. Lock up ETH, help check transactions, earn new ETH.
The catch is that the payment never really stops. Even if every ETH were staked, it would still pay roughly 1.51% a year. BeInCrypto checked that against the code.
Follow us on X to get the latest news as it happens
So the staked pile keeps growing. It now sits at 41.1 million ETH, or 33.7% of all ETH in existence.
It is also bunching up. Lido alone holds 9.41 million ETH, by its own count, and Ethereum staking remains concentrated in a few hands.
The fix is simple, that every few minutes, the network would take a slice of each reward and destroy it.
That slice grows as more ETH gets staked. Today it would swallow 56%. At 60.25 million ETH, it would take the lot.
Burning is not new here. EIP-1559 already destroys part of every transaction fee.
Drake is the famous name, but not the author. A researcher known only as pintail wrote it. The argument itself has run since January 2023.
The Case Against Cutting ETH Staking Rewards
The plan says the biggest operators feel the squeeze first. The maths says not for a while.
BeInCrypto applied the plan’s own formula to Lido. Growth keeps paying Lido until about 49 million ETH is staked. That is nearly 8 million more than today.
The authors admit one reason. Validators also earn by ordering transactions, called Maximal Extractable Value (MEV). The burn never touches that money, and it always rewards getting bigger.
They put that side income below 78,300 ETH last year, worth 0.20% at most. That figure is theirs. BeInCrypto could not confirm it.
Home stakers face a second squeeze. Fines stay the same size while earnings shrink. Recovering from a few hours offline would take about four times longer.
So why half? The authors chose it on judgement, not on data.
“Half the supply is the last figure that refers to anything beyond preference: it is the majority threshold the risks above turn on,” they wrote.
That reasoning matters for ETH price levels, with ether near $1,866 on Tuesday. Reward changes move money fast, as the record ETH validator exit queue showed in 2025.
Nothing is settled yet. The plan is only a draft. It still needs editors, client teams, and a network upgrade.
Even day one stings. Rewards would drop 13% straight away. The question is whether big stakers accept a rule that stops paying them to grow.
The post A New Ethereum Proposal Could Halve Staking Rewards: Who Feels It First? appeared first on BeInCrypto.
Crypto World
Clarity Act sits idle over Trump ethics question as Warren asks SEC to investigate him
The $TRUMP coin was worth more than $46 at its height, but it steadily declined to its current price of $1.47. The token saw brief spikes in value when the company behind it announced it would host dinners — including at Trump’s Mar-a-Lago, with the president as the keynote speaker — but that price action was temporary both times.
In what’s likely to pack more political needling than actual regulatory results, the letter comes as negotiators hoping to finish the Digital Asset Market Clarity Act are awaiting the White House’s response to the latest revamping of the contentious section that would ban senior government officials from direct involvement in crypto projects.
For its part, the SEC has already ruled memecoins as generally outside its sphere of influence. In one of the early staff crypto statements after the Trump administration took over, the agency declared that memecoins have “limited or no use or functionality” and don’t check a box as securities under the law.
The ability for a government official, such as President Trump, to issue such a token is at the center of the negotiation over the ethics section of the Clarity Act. Trump recently agreed to be subjected to a limit, though the restrictions he agreed to would have very narrow practical effect. Democrats refused the approach and said they’d oppose the legislation unless that provision was made stronger, so Senators Thom Tillis, a Republican, and Ruben Gallego, a Democrat, negotiated a tougher version. The rewrite was sent to the White House last week, which hasn’t yet responded days later.
Crypto World
David Schwartz weighs in on $100M Coldcard hack
David Schwartz said the Coldcard breach shows that rare custody failures can produce devastating losses, comparing the incident with past breakdowns in traditional finance.
Summary
- Coldcard-related thefts have exceeded $100 million, according to Galaxy Research.
- Schwartz compared the custody risk with MF Global’s 2011 collapse but pointed to differences in insurance protection.
- A firmware flaw allowed attackers to reconstruct vulnerable wallet seeds without accessing the physical devices.
- Coinkite said affected users must create new seeds and move their funds because firmware updates cannot repair old seeds.
Schwartz compares Coldcard breach with TradFi failures
Ripple CTO Emeritus David Schwartz framed the Coldcard attack as an example of outlier risk—the possibility that a rare technical failure can cause losses far beyond what users expect.
Schwartz compared the incident with the 2011 collapse of MF Global, where customers temporarily lost access to funds after the brokerage misused money that should have remained segregated. His comments challenged the assumption that self-custody removes every form of counterparty or operational risk.
Hardware wallets allow users to control their private keys without relying on an exchange or other financial intermediary. However, owners must still trust that the device’s hardware and firmware generate and protect those keys correctly.
Schwartz also pointed to a major difference between traditional finance and crypto self-custody. Customers of regulated financial institutions may have access to insurance, bankruptcy proceedings, or other recovery mechanisms. Coldcard owners whose Bitcoin was stolen through compromised seeds currently have no comparable safety net.
What is the Coldcard hack?
Coldcard is a Bitcoin-only hardware wallet made by Canadian manufacturer Coinkite. The device stores private keys offline and can sign transactions without directly connecting to the internet.
The current breach did not involve attackers remotely accessing Coldcard devices. Instead, it resulted from a seed-generation flaw introduced through firmware released in March 2021.
According to Coinkite’s technical review, affected firmware used a software-based pseudorandom number generator rather than obtaining sufficient randomness from the device’s hardware generator. The problem affected seeds created on certain Coldcard firmware versions, including Mk2 and Mk3 releases from version 4.0.1 through 4.1.9.
Seed phrases should contain enough randomness to make guessing them computationally unrealistic. The Coldcard flaw reduced that protection, allowing attackers to generate possible seeds offline and compare their derived Bitcoin addresses with publicly visible addresses on the blockchain.
Once attackers found a match, they could recreate the wallet’s private keys and transfer its Bitcoin. They did not need to steal the hardware wallet, know its PIN, or compromise the Bitcoin network.
Coldcard losses exceed $100 million
As reported by crypto.news earlier, Galaxy Research said it had identified 1,596 BTC stolen from about 7,300 addresses across three confirmed attack waves. The firm also linked roughly 14 smaller incidents to the same seed-generation flaw.
A suspected fourth wave could raise the total to about 2,055 BTC, worth close to $130 million. However, Galaxy has not yet confirmed those additional losses.
The first major sweep occurred around July 30, when more than 1,000 BTC was removed from over 1,200 addresses in less than an hour. Two additional waves later targeted other wallets created using vulnerable seeds.
Galaxy shared hundreds of suspected attacker addresses with U.S. federal investigators, exchanges and blockchain security companies. About 90% of the Bitcoin stolen during the confirmed waves had not moved again at the time of its latest update.
The Bitcoin protocol was not compromised. The theft resulted from weak wallet-seed generation, meaning Bitcoin held in wallets created through unaffected software or hardware was not exposed by this specific flaw.
Coldcard owners must replace vulnerable seeds
Coinkite has released corrected firmware for affected Coldcard models. However, installing an update does not make an existing vulnerable seed secure.
The company’s security advisory instructs Mk2 and Mk3 owners who created seeds using firmware versions 4.0.1 through 4.1.9 to update to version 4.2.0 or later, generate a completely new seed and transfer their Bitcoin.
Users should first send a small test transaction and verify the receiving wallet before moving the remaining balance. Coinkite said its corrected seed-generation process is sufficient, while adding at least 50 private dice rolls remains an optional method for users seeking independent entropy.
The breach shows that air-gapped hardware can reduce online attack exposure without eliminating firmware, manufacturing, or seed-generation risks. For affected owners, moving funds to a newly generated wallet remains the only way to remove the immediate threat.
Crypto World
Teen Drama Sterling Point Is the Best Kind of Lazy-Summer Throwback
Plenty of classic teen-drama tropes come into play. Not only does Annie get caught in a love triangle, but her two suitors each represent opposing factions of the community: townies and summer people. Ellis (Jacob Whiteduck-Lavoie) is a hard-working, year-round resident, and Rory (Daniel Quinn Toye) a rich New York acquaintance whose family has a luxurious vacation home nearby. As also tends to be the case in stories aimed at teens, the young characters are remarkably autonomous. But creator and co-showrunner Megan Park, whose films The Fallout and My Old Ass displayed deep insight into the inner lives of young women, isn’t mindlessly mimicking the mini-adults of Euphoria and Gossip Girl. (Sterling Point shares co-showrunners with the latter series, in Josh Schwartz and Stephanie Savage, which goes to show how conscious a choice its divergence from its millennial predecessors must be.) Like Annie, most of these characters have been forced by their parents to fend for themselves, emotionally if not quite literally. One of the most charming performances in a show that has many of them comes from Bo Bragason as Oona, a bubbly lesbian flirt whose mom has jetted off to India, leaving her in charge of her little sister (Mabel Strachan) and their houseboat.
Crypto World
At Least 15 Attackers Exploited Coldcard Vulnerability: Report
Galaxy Digital’s research team says the Coldcard wallet exploit has been used by at least 15 different attackers, based on new victim reports submitted after the incident. In remarks shared this week, Alex Thorn, head of research at Galaxy Digital, suggested that these additional reports helped identify variants that might otherwise have remained hidden.
Thorn also indicated that losses tied to the exploit have risen as investigators mapped multiple waves of activity. Galaxy Research estimates the confirmed thefts total about $100 million across three waves, with an additional suspected fourth wave that could lift the figure to roughly $130 million in Bitcoin.
Key takeaways
- Galaxy Digital reports at least 15 distinct attackers behind the Coldcard exploitation, based on newly received victim accounts.
- Galaxy Research estimates confirmed losses at about $100 million across three attack waves, with a potential fourth wave raising the estimate to ~$130 million.
- Security debate is returning to cold storage practices, particularly how much safety comes from self-custody versus wallet design.
- Industry discussion highlights how emerging AI capabilities could lower the time and cost of vulnerability discovery—though independent validation remains limited.
- Researchers point to wallet entropy and firmware behavior as potential factors that make exploitation easier under certain conditions.
Coldcard thefts widen as investigators compare victim reports
In a Tuesday post on X, Thorn said that new victim reports enabled Galaxy to identify additional attacker activity. He framed the significance of the new reporting as both quantitative and technical: the exploit behavior differed from typical theft patterns seen in hacks against centralized exchanges, making careful attribution and investigation more dependent on detailed victim information.
Thorn wrote that even a relatively small report—less than 1 BTC stolen from a victim—was sufficient to detect a new attack pattern. He noted that this new attack involved roughly 12 BTC siphoned from 126 addresses, underscoring how the same underlying vulnerability could be used in different operational ways.
Earlier coverage of the Coldcard exploitation described multiple “waves” of activity. Galaxy Research’s current figures build on that approach by tracking confirmed incidents and assessing whether activity patterns resemble a further wave of exploitation.
Loss estimates: three confirmed waves, plus a suspected fourth
According to Galaxy Research, the total losses from the Coldcard exploit have grown to approximately $100 million across three confirmed attack waves. Thorn’s research also points to a suspected fourth wave that, if validated, would bring the potential total to about $130 million in Bitcoin.
For users and investors, the practical value of this breakdown is that it turns an incident that initially looked like a one-off event into something closer to an evolving campaign. Waves of theft imply repeated operational access—either through different attacker infrastructure, different timing, or different exploit paths that still converge on the vulnerable behavior.
Debate over “AI hardening” and whether models can rediscover exploits
The renewed attention has also reopened a broader debate: whether AI tools can meaningfully compress the time between disclosure and exploitation, and whether “AI hardening” could have prevented the attack.
Dragonfly managing partner Haseeb Qureshi argued on X that “$2 of AI hardening” could have stopped the Coldcard exploit, citing social media claims that some AI models rediscovered the underlying vulnerability in under 20 minutes. His comments referenced reports that a model named Claude could regenerate the vulnerability in eight minutes, as well as a separate claim that an open-source model (GLM 5.2) could rediscover the exploit in 20 minutes even with web access disabled.
However, Tokenomist data lead Tatsapat Saerejittima told Cointelegraph that it is unlikely AI models would have independently found the vulnerability before it became public. Saerejittima argued that the most prominent “fast rediscovery” claim appears to stem from a pseudonymous user who scanned code after the vulnerability was already known, without a blind test, a documented methodology, or an assessment of false-positive rates.
“The claim that AI found it in 2 mins came from a pseudonymous Reddit user who scanned the code after the vulnerability had already become public. There was no blind test, no documented methodology, and no assessment of the model’s false-positive rate.”
That distinction matters. If “rediscovery” is based on post-disclosure inputs, then the timeframe reflects reuse of known information rather than a model’s ability to autonomously uncover unknown vulnerabilities under real-world conditions. For wallet users, builders, and auditors, the difference affects how confidently security teams can treat AI-assisted testing as a substitute for formal review and threat modeling.
Private key setup and entropy may have made exploitation easier
Another line of analysis focuses less on AI capabilities and more on the cryptographic design and implementation details of the device’s key generation process.
Crypto research company Castle Labs co-founder Francesco said that increasing AI capabilities could reduce the cost and time needed to discover cryptocurrency vulnerabilities. He also suggested that Coldcard’s private key may have played a role in why the exploit worked.
Francesco pointed to a “level of private key entropy (40 bits) much lower than the standard adopted by other wallets (a 12-word seed is 128 bits).” He attributed this discrepancy to a firmware bug, which he said would make exploitation easier because the search space is smaller than it would be under typical seed-based entropy assumptions.
He further stated that he expects the cost of bug discovery to continue decreasing as AI models improve and become more embedded in both cybersecurity workflows and exploitation attempts. Even without relying on any single “AI rediscovery” claim, the underlying idea—that automation can accelerate identification and exploitation—aligns with the broader security trend toward faster vulnerability discovery and weaponization.
In practice, these findings shift attention to what should change next for hardware wallet security: not only whether vulnerabilities are found quickly, but how wallet firmware handles entropy, key generation, and edge cases that could alter the effective security assumptions.
As the industry digests Galaxy’s expanding attribution data and the ongoing discussion of exploit mechanics, readers should watch for whether additional theft activity continues to be classified into further waves—and, just as importantly, what technical mitigations are recommended or adopted to address the entropy or firmware conditions implicated by researchers.
Crypto World
Bitcoin bridge Boltz suspends services as AI hacks outpace patches
Bitcoin bridge Boltz has suspended services indefinitely due to repeated attacks on its infrastructure by hackers using AI tools.
Boltz’ announced that it could no longer “responsibly re-enable Boltz swaps” while it’s “being actively targeted by what appear to be multiple resourceful groups while we race to deploy fixes.”
Indeed, the company claimed that over the past few months it had witnessed a “steady rise in automated, AI-assisted probing of our infrastructure” that resulted in several exploits.
Every exploit has apparently been contained, but Boltz is now worried that it can’t keep up with fixing exploits as its attackers “iterate faster than a team our size can find and patch.”
Read more: Coldcard hacker’s BTC wallet flooded with on-chain messages
It said, “What we are seeing is a major paradigm shift for Bitcoin services operating on an open source stack, and it needs careful analysis. Do not expect swap services to resume shortly.”
The company stressed that “no user funds were ever at risk,” and that any “losses were ours alone.”
Boltz Swap Services didn’t hold user funds as a custodian. Instead, the company operated a non-custodial bridge that used hashed timelock contracts to execute atomic swaps between regular BTC, Lightning Network BTC, and Liquid Network BTC.
Funds either fully swapped or fully reverted within one block.
Boltz suspension leads to collateral damage
Boltz’s closure of swap services has had a knock-on effect on Bitcoin firms Bull Bitcoin and Aqua Wallet.
Bull Bitcoin warned that lightning payments and Liquid to Bitcoin swaps in its wallet will now “fail without explanation,” and it’s working to find a solution.
Aqua Wallet similarly warned that these types of swaps are no longer available, and that it’s working with Boltz and attempting to find alternative means for lightning swaps.
A major seed phrase exploit affecting the Bitcoin hardware wallet Coldcard, which has now reportedly led to the theft of over $100 million worth of BTC, is also believed to have originated from AI software.
Read more: Former FBI agent indicted for stealing crypto from FBI
These two high profile exploits have led to concern over AI usage by hackers.
In response to Boltz’ pause, Swan co-founder Yan Pritzker said, “AI attackers are getting more and more sophisticated and small teams are going to have a tough time keeping up with the attacks.
“There’s a significant overhead to building and running enterprise security in the age of LLMs, which will price out many innovative startups wanting to work on services related to client funds — even non custodial ones. Which really sucks.”
Former Lightning Labs business developer Lucas Ferreira described Boltz’ situation as “very unfortunate.” He noted that while its team was “brilliant,” it’s still only a small team facing AI-powered groups of hackers.
He added, “We’ll need more funding for the open-source space if we want our infrastructure to remain secure and resilient.”
Got a tip? Send us an email securely via Protos Leaks. For more informed news and investigations, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.
Crypto World
Polymarket seeks fundraising round at more than $20 billion valuation
A Polymarket billboard displaying New York City mayoral election odds in Times Square in New York, US, on Tuesday, Nov. 4, 2025.
Adam Gray | Bloomberg | Getty Images
Prediction market platform Polymarket is in talks for a fundraising round that would value the company at north of $20 billion, a person familiar with the matter confirmed to CNBC.
The talks and valuation come after the company told CNBC in late June that its annualized revenue was well above $1 billion, following the launch of its regulated U.S. exchange in May.
Bloomberg first reported on Tuesday about the new talks and valuation. Polymarket declined a request to comment by CNBC.
The person familiar with the situation — who asked not to be named to discuss the ongoing fundraising talks — also confirmed that the company previously closed a funding round in April that valued Polymarket at $15 billion.
The Information first reported about the funding round that same month, but the company did not confirm the round’s closure at the time. That round included an additional $600 million direct cash investment by New York Stock Exchange owner Intercontinental Exchange announced in March, Bloomberg reported.
Prediction market platforms are continuing to experience huge growth while staying private. In May, Polymarket’s chief rival, Kalshi, announced the closure of a funding round that valued the company at $22 billion. The Financial Times reported in June that Kalshi was in talks to raise new funds in the third quarter and would seek a $40 billion valuation.
If a new funding round for Polymarket closes, it would mark the first since the U.S. exchange’s official launch, though the platform debuted with a waitlist in December. The U.S. exchange is doing north of $100 million in notional volume per day — up from around $75 million at the end of May — while the company’s international platform is recording daily notional volume above $150 million, according to data from Dune Analytics.
— CNBC’s Ananya Chetia contributed reporting
Disclosure: CNBC and Kalshi have a commercial relationship that includes customer acquisition and a minority investment.
Crypto World
Banking giant Intesa Sanpaolo cuts IBIT stake 94%, triples ether ETF holding
It wasn’t alone in rejigging its exposure to cryptocurrencies. U.S. spot bitcoin ETFs overall recorded roughly $4.89 billion of net outflows in the three months through June, according to SoSoValue data. IBIT alone lost $2.95 billion. Spot ether ETFs also suffered, with more than $715 million in outflows.
Intesa Sanpaolo, in contrast, tripled its stake in BlackRock’s iShares Staked Ethereum Trust ETF (ETHB) to 349,600 shares. The position was worth $7.10 million at quarter-end, up from $3.15 million.
Among crypto-linked equities, the bank nearly doubled its BitGo Holdings (BTGO) position to 323,000 shares, while reducing its stake in Coinbase Global (COIN) by 32%, Circle Internet (CRCL) by 10% and Robinhood Markets (HOOD) by 43%.
The filing also shows a new 5.66 million-share SpaceX (SPCX) position valued at $966.42 million, making it Intesa’s largest disclosed holding. SpaceX, which went public on June 12, holds 18,712 bitcoin worth $1.18 billion. It reduced its holdings in Tesla (TSLA) by 92%.
Intesa made its first direct bitcoin purchase in January 2025, acquiring 11 BTC for about 1 million euros ($1.2 million) as part of what CEO Carlo Messina described as an experiment.
-
Business6 days agoWhy Trees Belong on the Risk Register
-
Fashion4 days agoWeekend Open Thread: Wit & Wisdom
-
Politics4 days agoMeta enters AI-training agreement with far-right ‘propaganda rag’ Newsmax
-
Entertainment7 days ago‘Stargate’ Creator’s New Sci-Fi Series Returns for Season 3 Tomorrow
-
Crypto World3 days agoMicroStrategy Post-Earnings CLARITY Act Push Could Add New Catalyst for Its Stock
-
Politics6 days agoReform UK betrays West Mids residents by running from party pledges
-
Business7 days agoMajor shareholder moves on Canyon
-
Crypto World3 days agoXRP Ledger v3.3.0 brings five institutional features
-
News Videos5 days agoBitcoin Enters the 3rd Stage of the Bear Market
-
Crypto World7 days agoKraken Enables Retail Access to Jersey Mike’s IPO via Tokenized Shares
-
Politics2 days agoZack Polanski: an incitement to murder Nigel Farage?
-
Politics5 days agoLuke Littler’s dominance sparks GOAT debate
-
Sports5 days agoSeema Kaliramna Wins Discus Throw Bronze, Takes India’s CWG Medals Tally To 17
-
News Videos7 days agoClaude: Build Financial Dashboards in Minutes (2026)
-
Crypto World4 days agoNew York sues Kalshi over prediction market gambling
-
Crypto World2 days agoCrypto PAC spending tops $2M in Michigan House race
-
Business7 days agoJohnson & Johnson agrees to $5.5B settlement over talc cancer claims
-
Business4 days agoTrump Announces Hamas Disarmament Agreement as Iran Strikes Kuwait Air Base and US Attacks Pause Overnight
-
Tech6 days agoGemini can now summarize the messiest comment threads in Google Docs
-
Tech2 days agoESET tracks rise in malicious AI skills and adaptable malware

You must be logged in to post a comment Login