Connect with us

Crypto World

Strategy Liquidates 1,638 Bitcoin to Pay Dividends, Buy STRC Back

Published

on

Crypto Breaking News

Strategy sold 1,638 Bitcoin between July 27 and Sunday, according to an 8-K filing released Monday with the U.S. Securities and Exchange Commission. The sale, carried out at an average price of $63,957 per BTC, generated about $104.7 million—making it the company’s second-largest Bitcoin selloff of the year.

Strategy said the proceeds were split between its preferred-stock dividend program and its STRC share repurchase activity. Following the transaction, the company reported holding 842,138 Bitcoin, purchased at an aggregate cost of $63.5 billion.

Key takeaways

  • Strategy’s latest disclosed Bitcoin sale totaled 1,638 BTC at an average of $63,957, raising roughly $104.7 million.
  • About $52.4 million of the proceeds was used for dividends on STRC preferred stock, with $52.3 million directed to STRC repurchases.
  • Strategy also reported increasing its US dollar reserve to $4 billion as of Sunday, funded in part by MSTR share sales.
  • STRC traded below its $100 target value in Monday pre-market trading, a condition that can affect Strategy’s financing flexibility.
  • The filing comes amid renewed commentary from industry observers urging Strategy to prioritize cash reserve replenishment over additional BTC buys.

Bitcoin sales fund dividends and STRC buybacks

In the Monday SEC filing, Strategy detailed the July 27–Sunday sale of 1,638 BTC and the resulting proceeds. The company reported using $52.4 million to cover dividend payments on its STRC preferred stock and $52.3 million to repurchase STRC shares.

While this latest selloff follows earlier activity, it is not Strategy’s first major Bitcoin sale this year. The company previously disclosed selling 3,588 BTC for about $216 million on July 6, as covered earlier. It also reported selling 32 BTC in early June, which it described as its first reported BTC sale since a 2022 tax-loss transaction, according to earlier coverage referenced in the filing materials.

The decision matters for investors watching how Strategy balances its core goal—maintaining Bitcoin exposure—with the practical need to support dividend obligations and preferred-share economics. When BTC is sold to meet shareholder payouts, investors often scrutinize whether the company’s capital framework preserves the intended pace of future Bitcoin accumulation.

Advertisement

US dollar reserve rises to $4 billion after equity-related funding

Beyond the Bitcoin sale, Strategy reported raising $290.6 million through MSTR share sales during the same period. According to the filing, $250 million of those proceeds was earmarked to increase its US dollar reserve, which stood at $4 billion as of Sunday. The company also allocated $28.9 million for STRC repurchases and $11.7 million to its cash balance.

In a Monday post on X, Strategy founder and chairman Michael Saylor said the company repurchased $81.2 million worth of STRC stock and extended its US dollar runway by 57 days to 2.3 years. The runway estimate is important because it reflects how long Strategy can continue executing its stated capital approach—particularly dividend-related payments—without being forced to accelerate either Bitcoin sales or external funding.

STRC below target value raises questions about financing conditions

Strategy’s STRC perpetual preferred stock functions as one of the company’s tools for financing Bitcoin purchases. However, in Monday pre-market trading, Yahoo Finance data showed STRC at $89.40, or 10.6% below its $100 target value. Strategy’s common stock, MSTR, was also down slightly in pre-market trading, declining 0.9%.

Trading below the intended par can influence Strategy’s ability to raise funds through STRC sales. It may also affect the company’s incentive to adjust dividend levels to make STRC more attractive to prospective buyers and help stabilize the preferred-stock market price.

Advertisement

This is not a purely theoretical concern. Investors have previously focused on dividend coverage and cash planning as part of Strategy’s broader capital strategy. In a June 24 X post, CryptoQuant CEO Ki Young Ju argued that Strategy should pause further Bitcoin purchases and rebuild cash reserves, after the company’s dividend coverage fell to 14 months from seven years, based on the reporting tied to that commentary. Ju said the company should adopt a systematic framework for purchase timing.

Earlier, Strategy had also laid out a capital framework in an 8-K filing dated June 29. That disclosure included an approach in which Bitcoin sales can fund dividends, an increase of STRC’s annual dividend rate to 12%, and a report that the US dollar reserve had grown to $2.55 billion.

What to watch next

With Strategy reporting both a sizable Bitcoin sale and a significant rise in its US dollar reserve to $4 billion, the near-term question for investors is how sustainably the company can fund dividends and preferred-share repurchases while maintaining its desired Bitcoin exposure. Traders should watch STRC’s trading price relative to its $100 target and monitor whether Strategy’s stated runway and purchase timing adjustments continue to evolve in future filings.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Advertisement

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

Bitcoin price nears $64K as 32,000 BTC hits exchanges

Published

on

Bitcoin daily chart shows BTC rebounding to $63,894 above $63,183 support, while RSI and MACD signal weak momentum.

Bitcoin price rebounded toward $63,900 on Aug. 3 after briefly falling near $62,300, but weak spot demand and fresh short-term holder losses continue to limit its recovery.

Summary

  • Bitcoin price recovered to $63,894 after testing an intraday low of $62,300.
  • The daily RSI remained neutral at 49.28, while the MACD showed weakening momentum.
  • Short-term holders reportedly sent 32,000 BTC to exchanges at a loss within 24 hours.
  • Liquidation liquidity is concentrated near $62,000 and $64,000, raising volatility risks.

Bitcoin price recovers from $62,300

According to data from crypto.news, Bitcoin (BTC) price traded at $63,894 at the time of writing, up 0.51% for the day after moving between $62,300 and $63,993.

The recovery followed a sharp decline toward $62,600 noted in Glassnode’s latest market report. According to the on-chain analytics firm, Bitcoin failed to hold its earlier move above $66,000 as weak spot demand and persistent net selling kept the market within a consolidation phase.

Advertisement

The daily chart shows that BTC has stabilized slightly above the 78.6% Fibonacci retracement level at $63,183. This area has acted as a short-term pivot since the beginning of July, with repeated price movements on both sides of it.

Bitcoin daily chart shows BTC rebounding to $63,894 above $63,183 support, while RSI and MACD signal weak momentum.
Bitcoin price daily chart — Aug. 3 | Source: crypto.news

However, the rebound has not yet changed Bitcoin’s broader structure. BTC continues to trade below its July peak near $66,900 and remains well under the 61.8% Fibonacci retracement level at $67,394.

A daily close above $64,000 would strengthen the short-term recovery. Failure to hold $63,183 could expose Bitcoin to another test of the $62,000 region.

Short-term Bitcoin holders lock in losses

Selling by short-term holders appears to be adding pressure near the lower end of Bitcoin’s range.

Advertisement

A CryptoQuant chart shared by market observer Whale Factor showed that approximately 32,000 BTC reached exchanges at a loss within a single day. The account described the move as the largest short-term holder capitulation event in 30 days.

Transfers to exchanges do not confirm that every coin was sold. Still, coins moving from short-term holders at a loss can indicate defensive positioning or capitulation, particularly when prices are testing support.

Glassnode reported a similar deterioration in market profitability. The proportion of Bitcoin’s supply held in profit is approaching a cyclical low, while investor spending patterns increasingly reflect stop-loss activity.

Long-term holders have remained more resilient. Glassnode said the ratio of supply held by short-term holders relative to long-term holders remains near historical lows, indicating that older coins are not moving at the same rate.

Network activity has also increased. Daily active addresses and adjusted transfer volume moved above their recent statistical ranges, suggesting that Bitcoin’s latest volatility has been accompanied by greater on-chain usage.

Advertisement

Liquidation clusters put $62,000 and $64,000 in focus

CoinGlass’s three-day liquidation heatmap shows two major pools of leveraged positions surrounding Bitcoin’s current price.

Bitcoin three-day liquidation heatmap shows major liquidity clusters near $62,000 and $64,000 as BTC approaches $63,900.
Bitcoin liquidation heatmap | Source: CoinGlass

The closest upside cluster sits between roughly $63,800 and $64,100. Bitcoin’s rebound toward $63,900 has already brought the price into this area, where further gains could force leveraged short positions to close.

Additional liquidity is visible around $64,300, followed by thinner bands near $64,800 and $65,000. A decisive move through $64,100 could therefore accelerate toward the upper clusters, although weak spot buying may limit the size of any short squeeze.

The largest nearby downside concentration is around $61,900 to $62,200. This bright liquidity band sits just below Bitcoin’s latest intraday low and could attract price if the recovery loses momentum.

Bitcoin’s position between these two clusters leaves it vulnerable to sharp moves in either direction. A break above $64,100 could target $65,000, while a decline below $62,000 would put the June–July floor near $57,820 back in view.

Advertisement

Momentum remains neutral despite the rebound

Bitcoin’s daily relative strength index stands at 49.28, slightly below its signal average of 50.87. That reading shows balanced momentum rather than a clear advantage for buyers or sellers.

The MACD is less constructive. Its histogram has turned negative, while the MACD line remains below the signal line. This indicates that the recovery from the late-June low has lost momentum, even though Bitcoin has avoided another major breakdown.

For a stronger bullish reversal, BTC would need to reclaim $64,000 and then clear the July resistance zone between $66,000 and $67,394. The next Fibonacci targets would sit at $70,352 and $73,309.

The bearish scenario would gain traction if Bitcoin closes below $63,183 and subsequently loses $62,000. That would increase the risk of a decline toward $60,000, followed by the broader range floor near $57,820.

Advertisement

US investors will also be watching spot Bitcoin ETF flows for evidence of institutional demand. Glassnode said ETF inflows and trading volumes improved during the past week, providing some support even as spot-market momentum remained weak.

For now, Bitcoin’s rebound has defended near-term support but has not resolved the wider range. The concentration of liquidation leverage on both sides of the price makes $62,000 and $64,100 the main boundaries for the next directional move.

Disclosure: This article does not represent investment advice. The content and materials featured on this page are for educational purposes only.

Advertisement

Source link

Advertisement
Continue Reading

Crypto World

What is account abstraction and why seed phrases are becoming optional

Published

on

What is account abstraction and why seed phrases are becoming optional

Smart accounts replace seed phrases with passkeys, social recovery, and gas sponsorship, making self-custody usable without memorizing 12 words.

Summary

  • Account abstraction (AA) upgrades Ethereum wallets from fixed key pairs to programmable smart contracts that define their own validation rules.
  • ERC-4337, live on mainnet since March 2023, introduced AA without changing Ethereum’s core protocol by routing transactions through an alternative mempool of UserOperations.
  • Passkey wallets such as Coinbase Smart Wallet and Safe replace seed phrases with biometric authentication tied to the device’s secure enclave.
  • Gas sponsorship (paymasters) lets applications pay transaction fees on behalf of users, removing the requirement to hold ETH before interacting with a dapp.
  • Social recovery allows a set of trusted guardians to restore wallet access if a device is lost, eliminating the single point of failure that seed phrases represent.

Introduction

The standard advice for anyone entering crypto has not changed in a decade: write down 12 words, store them offline, and never lose them. This instruction is correct under the old model. Externally owned accounts (EOAs) derive a single private key from that mnemonic, and whoever holds the key controls the funds. There is no recovery, no spending limit, no way to require a second signature. Lose the phrase, lose everything.

Account abstraction changes this premise. Instead of coupling wallet security to a single secret, AA turns the wallet itself into a smart contract, one that can enforce arbitrary rules about who may sign, how gas is paid, and what happens when a key is compromised. The upgrade does not require users to understand smart contracts. From the outside, a passkey wallet looks like logging into an app with a fingerprint. Underneath, the architecture is fundamentally different.

Advertisement

This guide explains how AA works at the protocol level, what ERC-4337 introduced, and why the shift matters for self-custody going forward.

How Ethereum wallets worked before account abstraction

Every Ethereum address before AA was an externally owned account. An EOA is controlled by a private key derived from a mnemonic seed phrase. The account has no on-chain logic. It can send transactions and sign messages, but it cannot enforce rules about those actions. For a broader overview of wallet types and their mechanics, see what are crypto wallets.

This design has three structural limitations:

No recovery mechanism. If the private key is lost and no backup exists, the account is permanently inaccessible. Chainalysis estimates that roughly 20% of all Bitcoin is held in wallets whose keys are presumed lost. Ethereum faces the same problem.

Advertisement

No spending controls. An EOA cannot limit transaction size, restrict destination addresses, or require multiple signatures. A single compromised key means total loss. Organizations that need shared control over funds must use external multisig contracts instead of native account features. For how those multisig setups work and where they have failed, see how crypto’s biggest treasuries get secured and robbed.

Gas must be paid by the sender. Every transaction requires the signing account to hold ETH for gas. A new user receiving tokens on Ethereum cannot move them without first acquiring ETH from somewhere else. This creates an onboarding dead end that has persisted since Ethereum’s launch in 2015.

What ERC-4337 introduced

ERC-4337, authored by Vitalik Buterin, Yoav Weiss, Kristof Gazso, Namra Patel, Dror Tirosh, and Shahaf Nacson, went live on Ethereum mainnet in March 2023. It delivers account abstraction without requiring a hard fork, which was a critical design constraint. Previous AA proposals (EIP-2938, EIP-3074) required protocol-level changes that validators and client teams were reluctant to adopt. ERC-4337 sidesteps this by operating entirely at the smart contract layer.

The standard introduces four components:

Advertisement

UserOperations. Instead of sending a regular transaction, users submit a UserOperation (UserOp), a data structure that describes the intended action. UserOps enter a separate mempool, not the standard transaction mempool. Each UserOp contains the sender’s smart account address, the calldata for the intended action, gas limits, and an optional paymaster address.

Bundlers. Specialized nodes collect UserOps from the alternative mempool, bundle them into a single on-chain transaction, and submit that transaction to the network. The bundler pays gas upfront and is reimbursed by the smart account or a paymaster. Bundling creates gas savings: the fixed overhead of an Ethereum transaction is paid once per bundle rather than once per user action.

EntryPoint contract. A singleton contract deployed at a canonical address on every ERC-4337 chain. All bundled UserOps pass through this contract, which calls each smart account’s validation function, executes the operation, and handles gas accounting. The EntryPoint contract has been audited by OpenZeppelin and is immutable once deployed, providing a stable trust anchor for the entire system.

Paymasters. Optional contracts that sponsor gas on behalf of users. A paymaster can pay fees in exchange for ERC-20 tokens, absorb costs as a dapp subsidy, or implement any other payment logic. The paymaster’s validatePaymasterUserOp function is called during validation, and the paymaster can reject operations that do not meet its criteria.

Advertisement

The result: a wallet is no longer a key pair. It is a smart contract with a programmable validateUserOp function that decides whether a given operation is authorized.

The UserOperation lifecycle in detail

Understanding how a UserOp moves through the system clarifies what makes AA different from regular transactions.

  1. Construction. The wallet application constructs a UserOp containing the target contract call, gas parameters, and a nonce. If a paymaster is involved, the paymaster address and its approval data are included.
  2. Signing. The user signs the UserOp. The signature format is defined by the smart account, not by the protocol. This is the key flexibility: the smart account can accept ECDSA signatures, passkey signatures, multisig thresholds, or any other scheme.
  3. Submission. The signed UserOp is submitted to a bundler via a JSON-RPC endpoint (eth_sendUserOperation). The bundler validates the UserOp off-chain to ensure it will not revert.
  4. Bundling. The bundler groups multiple UserOps into a single transaction that calls the EntryPoint contract’s handleOps function.
  5. Execution. The EntryPoint calls each smart account’s validation function. If validation passes, the EntryPoint executes the operation. If a paymaster is present, the EntryPoint charges the paymaster instead of the smart account for gas.
  6. Confirmation. The bundled transaction is included in a block. Each UserOp within it is treated as an independent action that either succeeds or fails without affecting other UserOps in the bundle.

This lifecycle means the user never interacts with the Ethereum mempool directly. The bundler handles gas estimation, nonce management, and transaction submission. From the user’s perspective, the experience is closer to submitting a form on a website than to broadcasting a raw blockchain transaction.

Passkey wallets and the end of seed phrases

The most visible consequence of AA is that wallets can now authenticate users with passkeys instead of seed phrases.

A passkey is a cryptographic credential stored in a device’s secure enclave (the Secure Enclave on Apple devices, Titan M on Google Pixels, or TPM on Windows machines). The user authenticates with a fingerprint, face scan, or device PIN. The private key never leaves the hardware.

Advertisement

Coinbase Smart Wallet, launched in June 2024, uses this approach. Account creation takes under 10 seconds. The user authenticates with a biometric, and the wallet deploys a smart contract account that recognizes that passkey as a valid signer. There is no seed phrase to write down, no browser extension to install. Coinbase reported deploying over 10 million smart accounts through this flow by early 2026.

Safe (formerly Gnosis Safe) has integrated passkey signing into its smart account framework. Users can add a passkey as one of multiple signers on a multi-signature account, combining the convenience of biometric login with the security of threshold signatures.

The tradeoff is platform dependency. A passkey created on an iPhone is synced through iCloud Keychain. If a user loses all Apple devices and cannot access iCloud, the passkey is gone. This is why social recovery exists as a complementary layer. Passkey wallets are strongest when combined with at least one backup signer that uses a different authentication method.

Social recovery: replacing backup with guardians

Social recovery, proposed by Vitalik Buterin in a 2021 blog post, replaces the single backup (seed phrase) with a group of guardians.

Advertisement

The mechanism works as follows:

  1. The wallet owner designates a set of guardians. Guardians can be friends, family members, institutional custodians, or even other smart contracts.
  2. The owner sets a threshold. For example, 3 of 5 guardians must approve a recovery request.
  3. If the owner loses access, they initiate a recovery process from a new device. Guardians independently confirm the request.
  4. Once the threshold is met, the smart account replaces the lost signing key with a new one.

The guardians do not need to coordinate simultaneously. Most implementations include a time delay (typically 24 to 48 hours) during which the original owner can cancel a fraudulent recovery attempt.

This model eliminates the single point of failure. Losing a device does not mean losing funds, as long as enough guardians are reachable. It also eliminates the physical security burden of storing a seed phrase in a fireproof safe or safety deposit box.

Guardian selection matters significantly. Guardians should be distributed across different geographies, communication channels, and relationship types. If all guardians are in the same group chat and that chat is compromised, the recovery mechanism becomes an attack vector. Some implementations allow adding institutional guardians (such as a hardware wallet provider or a custodial service) alongside personal contacts, creating defense in depth.

Advertisement

Gas sponsorship and how paymasters work

Before AA, a new user who received USDC on Ethereum could not send it anywhere without first acquiring ETH to pay gas. This chicken-and-egg problem has been one of the largest onboarding barriers in crypto.

Paymasters solve this. A paymaster is a smart contract that agrees to cover gas costs for a UserOperation, subject to its own rules.

Three common paymaster models have emerged:

Dapp-sponsored gas. The application pays all gas for its users. The dapp deposits ETH into the paymaster contract and authorizes UserOps from its users. From the user’s perspective, transactions are free. Dapps treat gas as a customer acquisition cost, similar to free shipping in e-commerce. This model is particularly effective on Layer 2 networks where gas costs are fractions of a cent per transaction.

Advertisement

ERC-20 gas payment. The paymaster accepts an ERC-20 token (USDC, DAI) instead of ETH. The user pays for gas, but in a token they already hold. The paymaster swaps the token for ETH to reimburse the bundler. This removes the need for users to hold two separate tokens (the asset they want to use plus ETH for gas).

Subscription or session-based. The paymaster authorizes a batch of operations within a time window or spending limit. A gaming dapp might sponsor 100 transactions per day per user, for example. Session keys extend this concept further: the user signs a single transaction that grants a temporary key the right to perform specific actions (such as moves in a game) without requiring approval for each one.

Pimlico, Alchemy, and Stackup operate paymaster infrastructure that dapps can integrate with a few API calls. Alchemy alone has facilitated over one million smart account deployments through its paymaster and bundler services. The economics are straightforward: on Layer 2 networks where gas costs pennies, sponsoring user transactions is trivially cheap.

EIP-7702 and the road to native account abstraction

ERC-4337 works without protocol changes, but it is not the end state. Ethereum’s roadmap includes EIP-7702 (authored by Vitalik Buterin and Sam Wilson), which was included in the Pectra upgrade.

Advertisement

EIP-7702 introduces a new transaction type that allows an EOA to temporarily point to smart contract code for the duration of a single transaction. The EOA does not permanently become a smart contract. Instead, it can behave like one when needed, gaining access to batched calls, sponsored gas, and custom validation logic, and then revert to standard EOA behavior.

This matters for two reasons. First, it lets existing EOA holders (anyone with a MetaMask wallet today) access AA features without migrating to a new account. Migration has been a major friction point: users do not want to move all their assets, permissions, and on-chain history to a new address. Second, it reduces gas costs because the permanent smart account deployment overhead is avoided for users who only need AA features occasionally.

The long-term vision, discussed across multiple Ethereum Foundation roadmap posts, is that every account on Ethereum becomes a smart account by default. StarkNet and zkSync already implement this: on those networks, every account is a smart contract from creation. EIP-7702 is the bridge that moves Ethereum’s existing user base toward this model without breaking backward compatibility.

Where account abstraction is deployed today

AA adoption is concentrated on Layer 2 networks where gas costs make experimentation cheap.

Advertisement

Base has the highest density of smart accounts, driven by Coinbase Smart Wallet. By mid-2026, Base had processed over 30 million UserOperations. The network’s sub-cent gas costs make paymaster sponsorship economically trivial.

Polygon integrated AA early and offers native account abstraction at the protocol level in its zkEVM rollup. Polygon’s focus on gaming and social applications aligns well with the session-key model, where users need many low-value transactions without repeated approval prompts.

Arbitrum and Optimism support ERC-4337 through the standard EntryPoint contract. Major dapps on both chains have begun migrating onboarding flows to smart accounts, particularly DeFi protocols that want to offer gasless first trades. For context on how Ethereum updates enabled wallets to operate as smart contracts, the timeline begins with the ERC-4337 EntryPoint deployment.

Ethereum mainnet supports ERC-4337 but higher gas costs mean paymaster sponsorship is more expensive. Most mainnet AA usage comes from high-value multi-sig wallets (Safe) rather than consumer dapps. Safe manages over $100 billion in assets across its smart account deployments.

Advertisement

StarkNet and zkSync implement native account abstraction at the protocol level, meaning every account is a smart contract by default. This is the direction Ethereum’s long-term roadmap points toward.

What this does not cover

This guide focuses on the mechanism of account abstraction and its immediate consequences for wallet design. It does not cover:

  • Detailed comparison of specific smart account implementations (Safe, Kernel, Biconomy, ZeroDev)
  • The MEV implications of the UserOperation mempool (for MEV mechanics, see what is MEV)
  • Formal security audits of individual paymaster contracts
  • Cross-chain account abstraction and how smart accounts interact with bridging

Practical checks for evaluating an AA wallet

Before trusting funds to a smart account wallet, consider these questions:

Is the smart contract audited? Check whether the wallet’s smart account implementation has undergone third-party security audits. Safe’s contracts are among the most audited in DeFi. Newer implementations may not have the same track record.

What happens if the provider shuts down? A passkey wallet tied to a single vendor creates a new form of dependency. Look for wallets that allow adding multiple signers, including a traditional private key as a backup.

Advertisement

Where is the passkey stored? Understand whether the passkey is device-bound or synced through a cloud provider. iCloud Keychain and Google Password Manager sync passkeys, which is convenient but expands the attack surface to include cloud account security.

Does the wallet support social recovery? If the only authentication method is a passkey and the passkey is lost, funds may be unrecoverable. Social recovery adds a safety net. Check how many guardians the wallet supports and whether the recovery process has been tested.

What chains does the smart account work on? A smart account on Ethereum mainnet has a different address than the same account on Arbitrum unless the wallet uses CREATE2 deterministic deployment. Verify cross-chain compatibility before depositing funds on multiple networks.

What is the upgrade path? Some smart account implementations are upgradeable (the contract logic can be changed by the owner). This is powerful but introduces risk: a compromised upgrade key could rewrite the wallet’s validation logic. Check whether upgrades require a time delay or multi-party approval.

Advertisement

What is account abstraction in simple terms?

Account abstraction turns a crypto wallet from a fixed key pair into a programmable smart contract. Instead of relying on a single seed phrase, the wallet can enforce custom rules for signing, recovery, and gas payment. The user experience changes from “guard these 12 words with your life” to “log in with your fingerprint.”

Is ERC-4337 the only way to implement account abstraction?

No. ERC-4337 is the most widely adopted standard on Ethereum because it works without protocol changes. StarkNet and zkSync implement native account abstraction at the protocol level. Ethereum’s roadmap includes EIP-7702, which allows EOAs to temporarily delegate to smart contract logic, bringing native AA closer to mainnet.

Are passkey wallets safe?

Passkey wallets are as secure as the device’s secure enclave and the cloud sync service backing them. The private key never leaves the hardware security module, making remote extraction extremely difficult. The main risk is losing access to the cloud account that syncs the passkey across devices. Adding a backup signer or enabling social recovery mitigates this.

Advertisement

Can I still use a seed phrase with account abstraction?

Yes. A smart account can accept a traditional private key (derived from a seed phrase) as one of its authorized signers. Many AA wallets allow users to add a seed-phrase-based key as a backup alongside a passkey. The difference is that the seed phrase is no longer the only option.

What is a paymaster?

A paymaster is a smart contract in the ERC-4337 system that pays gas fees on behalf of users. It can sponsor transactions entirely (dapp-subsidized), accept ERC-20 tokens as gas payment, or enforce spending limits. Paymasters remove the requirement for users to hold ETH before transacting.

How does social recovery work?

The wallet owner designates a group of guardians and sets a threshold (for example, 3 of 5). If the owner loses access, they request recovery from a new device. Once enough guardians approve, the smart account replaces the lost key with a new one. A time delay allows the original owner to cancel fraudulent attempts.

Do I need to pay gas to deploy a smart account?

Deployment costs gas, but the user does not necessarily pay it. Many AA wallet providers sponsor the deployment transaction through a paymaster, so the smart account is created at no cost to the user. The deployment typically happens lazily, only when the user sends their first transaction, rather than at account creation.

Advertisement

Which networks support account abstraction today?

ERC-4337 is live on Ethereum mainnet, Base, Arbitrum, Optimism, Polygon, Avalanche, BNB Chain, and most major EVM networks. StarkNet and zkSync have native AA built into their protocol. Layer 2 networks see the highest usage because low gas costs make paymaster sponsorship economically viable.
*Disclaimer: This article is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency involves significant risk, and you should conduct your own research before making any decisions. Information is accurate as of August 2026.*

Source link

Continue Reading

Crypto World

Boltz Suspends Bitcoin Swaps amid Surge in AI-Assisted Attacks

Published

on

Boltz Suspends Bitcoin Swaps amid Surge in AI-Assisted Attacks

Boltz, a non-custodial Bitcoin swap service, says it is disabling its service until further notice after a rise in AI-assisted hacking attempts over the last few months.

In a post to X on Monday, Boltz said the decision came after seeing a steady increase in “automated AI-assisted probing” of its infrastructure this year. 

“Over the past months… we have dealt with several exploits. Each was contained, but the pattern is clear: attackers now iterate faster than a team our size can find and patch.” 

“After reviewing the results of our own recent security scans, we cannot responsibly re-enable Boltz swaps, especially as we are being actively targeted by what appear to be multiple resourceful groups while we race to deploy fixes.” 

Boltz’s operational pause highlights the difficulty that smaller development teams are facing, as attackers discover vulnerabilities and adapt exploits faster than they can respond.

Advertisement

Source: Boltz

“In the past few days alone we saw a drastic acceleration [of attacks] and we do not believe this asymmetry will reverse,” said Boltz. 

Solana’s security chief calls for automated defense

In July, Solana Foundation’s new chief information security officer, Michael Coates, told Cointelegraph there is a need to switch to automated defenses in the age of AI. 

“We’re at a tipping point as an industry where humans cannot scale to meet these threats,” said Coates. 

Advertisement

“The only path forward we have is to have autonomous defense that operates at the speed of machines.” 

PayPerQ, a pay-per-prompt AI service that takes payment in Bitcoin and other cryptocurrencies, said it has also been dealing with a surge in exploits, possibly AI-powered. 

“We’ve been fighting off exploits every other week for several months, most of which we believe are AI-powered. It’s a very dangerous time out there.” 

No user funds at risk

Boltz lets users perform non-custodial, trustless atomic swaps, moving Bitcoin and Bitcoin-denominated assets between the mainnet and different layers of Bitcoin such as Lightning Network and Liquid Network. 

Related: AI has not triggered DeFi ‘hackpocalypse,’ Dragonfly partner says

Advertisement

DefiLlama shows total value locked on Boltz at the time of writing is $180,860.

Boltz said no user funds have ever been at risk, as all Boltz swaps use advanced cryptography and are non-custodial, which means users retain full control of their assets throughout the swap process. 

Boltz said its API will remain available to process refunds, and its support team will stay reachable. 

“What we are seeing is a major paradigm shift for Bitcoin services operating on an open source stack, and it needs careful analysis. Do not expect swap services to resume shortly.”

Magazine: Fears of AI-driven DeFi hack epidemic overstated for now — but not for long 

Advertisement

Source link

Continue Reading

Crypto World

Bithumb Maps 2028 IPO Timeline as It Tightens Internal Controls

Published

on

Crypto Breaking News

South Korea’s crypto exchange Bithumb said it intends to pursue a preliminary listing review in 2027 and complete an initial public offering (IPO) in 2028. The plan follows a corporate restructuring aimed at clarifying responsibilities across its business units and reducing potential conflicts of interest ahead of regulatory scrutiny.

In its announcement, Bithumb said preparations will include strengthening internal controls and moving from domestic accounting standards to K-IFRS, the international financial reporting framework used by listed companies in South Korea. The exchange added that the schedule could shift depending on market conditions and the timing of reviews by relevant authorities.

Key takeaways

  • Bithumb targets a 2027 preliminary listing review and an IPO completion in 2028, subject to regulatory timelines.
  • The exchange is restructuring its business, including spinning off Bithumb Asset, to separate responsibilities and limit conflicts of interest.
  • Bithumb plans to upgrade internal controls and adopt K-IFRS accounting as part of its listing readiness.
  • The IPO push comes amid intensified competition among South Korean exchanges as rivals deepen ties with traditional finance and technology groups.
  • Recent issues linked to promotional controls and audits at Bithumb-affiliated listed firms add more scrutiny to the group’s broader compliance posture.

Restructuring and K-IFRS as IPO prerequisites

Bithumb’s statement points to two major adjustments intended to make it more “listing-ready.” First, it has reorganized its business structure, including the spin-off of Bithumb Asset, to sharpen accountability across units and reduce the risk of overlapping interests.

Second, it said it will upgrade internal control systems and switch to K-IFRS from domestic accounting standards. For exchanges preparing for public markets, the shift to K-IFRS typically signals an effort to align financial reporting with the requirements expected of companies after they become subject to broader investor and regulator oversight.

The exchange also cautioned that its timetable is not guaranteed. “Market conditions” and the review schedules of relevant authorities could change the pace of its listing process.

Advertisement

Fiat rails and competitive pressure from legacy finance

Bithumb is one of five South Korean exchanges that support fiat trading via real-name bank accounts, an offering delivered through its partnership with KB Kookmin Bank. That positioning matters because fiat on-ramps and compliance-driven user onboarding are central parts of how South Korean exchanges operate and how regulators evaluate market infrastructure.

Meanwhile, Bithumb’s IPO ambitions arrive as competitors push deeper connections with traditional finance and technology players. According to earlier coverage from Cointelegraph, Mirae Asset Consulting took control of rival exchange Korbit on July 23. Cointelegraph also reported that Upbit operator Dunamu is pursuing a share-swap arrangement that would make it a wholly owned subsidiary of Naver Financial, though completion is contingent on regulatory and shareholder approvals.

This backdrop suggests that Bithumb is not just preparing for capital markets—it is also moving in a landscape where large corporate backers may influence customer acquisition, risk management, and the pace of product and infrastructure development.

A compliance test after a 620,000 BTC crediting mix-up

Bithumb’s listing plans also come with attention on its operational controls. In a February promotional error, Bithumb mistakenly credited customer accounts with balances totaling 620,000 Bitcoin rather than distributing 620,000 Korean won in cash rewards. Cointelegraph previously reported that Bithumb recovered 99.7% of the erroneous credits, while customers sold about 1,788 BTC before account freezing.

Advertisement

At a Feb. 11 National Assembly parliamentary hearing, Bithumb CEO Lee Jae-won said the exchange’s process for checking the intended distribution against its actual holdings had failed, and that the promotional amount was not set aside in a separate account. Reporting on the hearing was carried by Yonhap.

For investors, that incident is relevant even though it involved a promotional mechanism rather than core trading operations. It highlights the importance of robust reconciliation procedures—an area regulators often scrutinize when a company moves from private or quasi-private market activity into public-company oversight.

Audit and listing troubles at Bithumb-linked firms

Bithumb’s IPO preparation is further complicated by audit and listing problems reported for companies linked to the exchange. Cointelegraph noted that Vidente, a major Bithumb shareholder, and Bucket Studio, which indirectly controls Vidente, have had their share trading suspended since March 2023 due to audit and other listing issues.

Yonhap reported that in June, Bucket Studio appointed a former police official as its standing auditor, and that Vidente plans to appoint a former National Tax Service official to the same role. Yonhap also said South Korea’s Government Public Service Ethics Committee cleared both hires after concluding there was no close relationship between the officials’ previous duties and their new roles.

Advertisement

While these developments do not automatically block Bithumb’s own listing timeline, they add another layer of scrutiny to the group’s corporate governance narrative—especially as Bithumb positions internal control upgrades and accounting standard changes as central steps toward public-market readiness.

As 2027 approaches, the key question for readers will be whether Bithumb’s announced restructuring, internal control upgrades, and K-IFRS transition can withstand regulatory review while addressing the operational and governance pressure points already in the public record. Any adjustment to the timetable could offer early signals about how regulators weigh those factors against the exchange’s preparation efforts.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Advertisement

Source link

Continue Reading

Crypto World

What are intents and solvers? The invisible layer executing your DeFi trades

Published

on

What are intents and solvers? The invisible layer executing your DeFi trades

Intent-based protocols separate what a user wants from how it gets done, outsourcing execution to competitive solvers who find the best price across fragmented liquidity.

Summary

  • An intent is a signed message describing a desired outcome (for example, “swap 1 ETH for at least 3,200 USDC”) rather than a specific execution path.
  • Solvers are specialized agents that compete to fill intents, searching across DEXs, CEXs, private inventory, and cross-chain liquidity to find the optimal route.
  • CoW Protocol, UniswapX, and Across are the three largest intent-based systems, collectively processing billions in monthly volume by mid-2026.
  • Intent architectures protect users from MEV extraction by removing transactions from the public mempool, where frontrunners and sandwich bots operate.
  • The tradeoff is trust: users must trust that the solver auction is competitive and that the protocol’s settlement contract enforces the promised outcome.

Introduction

Most DeFi users believe they interact directly with an automated market maker when they swap tokens on Uniswap or SushiSwap. In 2022, this was broadly true. A user signed a transaction, that transaction entered the public mempool, a validator included it in a block, and the AMM’s constant-product formula determined the price.

This model has a problem. Public mempools are hunting grounds. MEV bots monitor pending transactions and execute sandwich attacks: they buy before your trade pushes the price up, then sell after, extracting value from the spread. Flashbots estimated that MEV extraction on Ethereum exceeded $600 million in cumulative profit by 2023, with a significant share coming from sandwich attacks on retail swaps. For a deeper look at how this extraction works, see what is MEV.

Advertisement

Intent-based protocols restructure this flow. Instead of broadcasting a transaction that specifies every execution detail, the user signs an intent: a declarative statement of the desired result. A network of solvers then competes to fill that intent at the best possible price, off-chain, without exposing the order to the public mempool.

This guide explains the mechanics of intents and solvers, how the major protocols implement them, and what tradeoffs users accept.

The problem with direct AMM interaction

When a user swaps tokens through a traditional AMM, the transaction encodes a specific path: swap token A for token B on pool X, with a minimum output of Y, by deadline Z. This specificity creates three problems.

MEV vulnerability. The transaction sits in the public mempool until a validator includes it. During that window, bots can see the intended trade and sandwich it, extracting value from the user. Academic research from the Flashbots team documented that sandwich attacks cost retail users an estimated $200 million to $300 million annually on Ethereum alone. One particularly striking case saw a DeFi trader suffer 100% slippage in a sandwich attack, losing the entire value of the trade.

Advertisement

Suboptimal routing. A user submitting a transaction to a single AMM gets that AMM’s price. But liquidity is fragmented across dozens of DEXs, multiple chains, and centralized exchanges. The best price for a given swap might involve splitting the order across three pools on two chains, a route the user’s simple transaction never considers.

Gas inefficiency. Each user pays gas individually. If 50 users want to swap ETH for USDC in the same block, they submit 50 separate transactions, each paying its own gas overhead. There is no mechanism for batching.

How intents work

An intent inverts the transaction model. Instead of specifying how to execute a trade, the user specifies what they want to achieve.

A typical intent contains:

Advertisement
  • Input token and amount. What the user is willing to spend.
  • Output token and minimum amount. What the user wants to receive, with a floor price.
  • Expiration. A deadline after which the intent expires.
  • Signature. Cryptographic proof that the user authorized this intent.

The intent is not a blockchain transaction. It is an off-chain signed message, submitted to a protocol-specific order flow system instead of the Ethereum mempool. This distinction is crucial: because the intent never enters the public mempool, it is invisible to MEV bots scanning for sandwich opportunities.

Once submitted, the intent enters a solver auction. The signed message grants conditional approval for a settlement contract to transfer the user’s input tokens, but only when the solver delivers the promised output. The user’s funds remain in their wallet until the moment of atomic settlement.

What solvers do and how they compete

A solver is an entity (a bot, a market maker, a trading firm) that monitors incoming intents and competes to fill them.

The competition works differently across protocols, but the general structure is:

  1. Intent broadcast. The protocol distributes new intents to registered solvers.
  2. Solution generation. Each solver analyzes the intent and determines how to fill it. A solver might route through multiple DEX pools, tap private inventory, bridge from another chain, or combine several intents into a single batch.
  3. Bid submission. Solvers submit their proposed execution, including the output the user will receive.
  4. Auction resolution. The protocol selects the winning solver, typically the one offering the user the best price after all costs.
  5. On-chain settlement. The winning solver executes the trade on-chain, and the settlement contract verifies that the user received at least the promised minimum output.

Solvers operate at their own risk. They front the capital, pay gas, and handle execution complexity. Their profit comes from the spread between the price they can source and the price they bid to the user, minus gas and capital costs. Competition between solvers compresses this margin, pushing more value back to users.

The economics of solver operation create a natural barrier to entry. Competitive solving requires capital for inventory, low-latency infrastructure for monitoring multiple liquidity sources, and sophisticated routing algorithms. The scale at which MEV bots operate illustrates the computational intensity of on-chain execution optimization. Solvers do the same work but channel the value toward users instead of extracting it.

Advertisement

CoW Protocol: batch auctions and coincidence of wants

CoW Protocol (formerly CowSwap) pioneered the intent-solver model on Ethereum. The name derives from “coincidence of wants” (CoW), a concept from economics.

The key innovation is batch auctions. Instead of filling orders one at a time, CoW Protocol collects intents over a window (approximately 30 seconds), then runs a single batch auction where solvers compete to fill all orders simultaneously.

This creates an opportunity for direct matching. If Alice wants to sell 1 ETH for USDC and Bob wants to buy 1 ETH with USDC, a solver can match them peer-to-peer without touching a liquidity pool. Neither party pays the AMM’s fee or spread. The solver profits by capturing the spread between the two users’ limit prices.

CoW Protocol calls this a “coincidence of wants” trade. In practice, pure CoW trades account for a meaningful minority of volume, but when they occur, both parties get prices better than any AMM can offer.

Advertisement

For orders that cannot be matched peer-to-peer, solvers route through on-chain liquidity. The batch auction format still helps: because all orders settle in a single transaction, gas costs are amortized across the batch. A batch of 30 swaps pays the fixed transaction overhead once, not 30 times.

By mid-2026, CoW Protocol had processed over $80 billion in cumulative volume, making it one of the largest DEX protocols by trade count. Its solver set has also matured, with established market makers and trading firms competing alongside independent solver operators.

UniswapX: Uniswap’s intent layer

UniswapX, launched in 2023, adds an intent-based execution layer on top of Uniswap’s existing liquidity pools.

When a user submits a swap through the Uniswap interface, they can opt into UniswapX. Instead of routing directly through Uniswap V3 or V4 pools, the swap becomes an intent. Solvers (called “fillers” in UniswapX terminology) compete to fill it.

Advertisement

UniswapX introduces Dutch order auctions. The user’s minimum acceptable output starts high and decays over time, following a predefined curve. The first solver willing to fill at the current price wins. This mechanism incentivizes solvers to fill quickly (they get a better margin early) while protecting users from receiving a bad price (the auction starts at an aggressive level).

A critical design choice: if no solver fills the order before it reaches the Uniswap pool price, the order automatically falls back to on-chain Uniswap routing. The user always gets at least the AMM price. Solvers can only win by offering something better.

UniswapX also introduces cross-chain intents. A user on Arbitrum can express an intent to receive tokens on Optimism. The solver handles the bridging, and the settlement contracts on both chains verify the outcome. From the user’s perspective, it is a single swap. This cross-chain capability was expanded in 2025 with permissionless bridging across nine networks, powered by the Across Protocol’s intent infrastructure.

Advertisement

Across: intents for cross-chain transfers

Across Protocol applies the intent-solver model specifically to cross-chain transfers.

Bridging tokens between chains traditionally involved lock-and-mint mechanisms, optimistic verification windows (often 7 days for optimistic rollups), or liquidity pool-based bridges. All of these are slow, expensive, or both.

Across restructures bridging as an intent. The user signs a message: “I have 1,000 USDC on Ethereum and want 1,000 USDC on Arbitrum.” A solver (called a “relayer” in Across) immediately sends 1,000 USDC to the user on Arbitrum from its own inventory, then later claims reimbursement from Across’s settlement system on Ethereum.

The result: bridge times measured in seconds rather than minutes or days. The user does not wait for the cross-chain verification. The solver takes on that waiting risk in exchange for a fee.

Advertisement

Across’s verification layer uses an optimistic oracle (UMA). If the solver’s claim is not disputed within a challenge window, the reimbursement is processed. This creates an economic game where honest relaying is profitable and fraudulent claims are punished by bond slashing.

Across’s collaboration with Uniswap on the Open Intents Framework aims to standardize how intents work across protocols, reducing the fragmentation that currently forces users to pick a specific intent system.

ERC-7683 and the standardization push

A major limitation of current intent systems is that each protocol defines its own intent format, solver network, and settlement contract. An intent submitted to CoW Protocol cannot be filled by a UniswapX solver. This fragmentation limits solver competition and reduces the pool of available liquidity for each system.

ERC-7683, proposed by Uniswap and Across in 2024, aims to create a universal standard for cross-chain intents. The proposal defines a common intent format (called a “CrossChainOrder”) that any protocol can adopt. Solvers who implement the standard can fill intents from any compliant protocol, increasing competition and improving prices.

Advertisement

The standard defines two interfaces: ISettlementContract (which settlement contracts implement) and IOriginSettler / IDestinationSettler (which handle cross-chain execution). By standardizing these interfaces, ERC-7683 would let a single solver operate across CoW Protocol, UniswapX, and Across simultaneously, competing for order flow from all three.

Adoption is still early. The standard requires existing protocols to modify their settlement contracts, which involves security audits and governance votes. But the direction is clear: intent-based trading is moving toward a unified solver marketplace instead of fragmented protocol-specific pools.

The tradeoffs of intent-based systems

Intent-based protocols improve user outcomes on price and MEV protection. They also introduce new trust assumptions and risks.

Solver centralization. In practice, a small number of well-capitalized solvers win most auctions. CoW Protocol’s solver leaderboard consistently shows 3 to 5 solvers handling the majority of volume. If solver competition weakens, users lose the price improvement that makes the system valuable.

Advertisement

Latency. Batch auctions and solver competitions add time between order submission and execution. CoW Protocol’s batches settle roughly every 30 seconds. UniswapX’s Dutch auctions resolve faster but still involve a delay. For time-sensitive trades, this latency can matter.

Solver trust. Users trust that the settlement contract correctly enforces the minimum output. The smart contracts are audited, but they are still smart contracts. Additionally, the off-chain auction mechanism must be fair. If the protocol operator can privilege certain solvers, the auction is not truly competitive.

Censorship risk. Because intents are submitted off-chain to protocol-specific systems, the protocol operator could theoretically censor certain intents. This is a different trust model than submitting transactions directly to Ethereum’s censorship-resistant mempool.

Regulatory attention. Solver networks that route order flow bear structural resemblance to broker-dealers in traditional finance. The question of whether solver activity constitutes regulated market making is unresolved. Regulatory clarity could either legitimize the model or impose compliance requirements that reduce the number of active solvers.

Advertisement

What this does not cover

This guide explains the core mechanism of intents and solvers. It does not cover:

  • The technical implementation of specific solver algorithms
  • Regulatory considerations around solver activity (order flow payment, best execution obligations)
  • Detailed tokenomics of CoW Protocol (COW token) or UMA (used by Across)
  • The relationship between intents and Ethereum’s proposer-builder separation (PBS) roadmap

Practical checks before using intent-based protocols

Compare prices. Before submitting an intent, check the quoted output against direct AMM execution. Intent-based protocols should consistently offer better prices. If they do not, the solver auction may not be competitive.

Understand the fallback. UniswapX falls back to on-chain AMM routing if no solver fills the order. CoW Protocol expires unfilled orders. Know what happens if solvers do not execute your intent.

Check slippage tolerance. The minimum output in an intent functions like a slippage tolerance. Setting it too tight may result in unfilled orders. Setting it too loose gives solvers room to offer worse prices. Most interfaces set a default, but users can adjust it.

Verify the settlement contract. The smart contract that enforces intent execution is the critical trust component. Check whether it has been audited and by whom. Look for contracts that are immutable or governed by a time-locked multisig rather than a single admin key.

Advertisement

Consider order size. Intents offer the most price improvement for medium to large orders, where routing optimization and MEV protection have the greatest impact. For very small swaps on low-gas chains, the price improvement may be negligible because MEV extraction is less profitable on small orders.

Watch for gas overhead. On Ethereum mainnet, the settlement contract execution adds gas costs that may offset the price improvement for small trades. On Layer 2 networks where gas is cheap, this overhead is negligible. Compare the total cost (including gas) of an intent-based swap against a direct AMM trade to see the net benefit.

The future of intent-based trading

Intent-based architectures are expanding beyond simple token swaps. Several trends are emerging by mid-2026.

Multi-action intents. Current intents describe single operations (swap token A for token B). Next-generation systems allow compound intents: “swap A for B, deposit B into a lending protocol, and borrow C against it” as a single atomic intent. Solvers who can execute the entire sequence efficiently compete for the bundle.

Advertisement

AI-powered solvers. Machine learning models are being applied to solver optimization. An AI solver can predict short-term price movements, anticipate liquidity conditions across chains, and dynamically adjust routing strategies. The computational advantage of AI-powered solvers could accelerate the trend toward solver centralization, as only well-resourced teams can train and operate these models.

Intent-aware wallets. Wallets are beginning to default to intent-based execution for all swaps, making the intent layer invisible to users. MetaMask’s integration of Uniswap’s API for in-wallet swaps points toward a future where every wallet swap is automatically routed through a solver auction, with users seeing only the quoted price and confirmation.

Regulatory frameworks. As intent-based trading grows, regulators are beginning to examine whether solver activity constitutes regulated financial services. The Payment for Order Flow (PFOF) model in traditional equity markets has structural similarities to how some protocols compensate solvers. Regulatory clarity will shape whether intent-based trading remains permissionless or requires licensed participants.

Advertisement

What is the difference between a transaction and an intent?

A transaction specifies exactly how to execute an action: call this contract, with these parameters, paying this much gas. An intent specifies the desired outcome: I want to swap this for that, receiving at least this much. The execution details are left to solvers who compete to find the best path.

Do I need to trust solvers with my funds?

No. Solvers never take custody of user funds in well-designed intent protocols. The user signs an intent that authorizes a settlement contract to transfer tokens only when the solver delivers the promised output. The smart contract enforces the atomic swap. If the solver cannot deliver, the trade does not execute.

How do solvers make money?

Solvers profit from the spread between the price they can source liquidity at and the price they bid in the auction. If a solver can buy 1 ETH for 3,195 USDC across various sources and fill a user’s intent at 3,200 USDC, the solver keeps the 5 USDC difference minus gas costs. Competition between solvers compresses this margin over time.

Can intents be censored?

Intents submitted to protocol-specific off-chain systems can theoretically be censored by the protocol operator. This is a different trust assumption than submitting transactions to Ethereum’s decentralized mempool. Some protocols mitigate this by running open solver networks where anyone can participate.

Advertisement

Are intent-based swaps always cheaper than direct AMM trades?

Usually, but not guaranteed. Intent-based protocols offer better prices when solver competition is strong and there is enough order flow to enable batch optimization or coincidence-of-wants matching. For very small trades or during periods of low solver activity, the improvement may be minimal.

What happens if no solver fills my intent?

It depends on the protocol. UniswapX falls back to direct on-chain Uniswap routing, so the trade still executes at the AMM price. CoW Protocol expires unfilled orders after the batch window, and the user can resubmit. Across intents expire if no relayer fills them within the deadline.

How do intents protect against MEV?

Intents are signed messages submitted off-chain, not transactions in the public mempool. Since MEV bots operate by monitoring the mempool for pending transactions to sandwich, removing the transaction from the mempool removes the attack vector. The solver executes the trade on-chain, but the solver is a sophisticated actor who can protect against MEV during their own execution.

Can I use intents for cross-chain trades?

Yes. UniswapX supports cross-chain intents where a user swaps tokens on one chain and receives tokens on another. Across Protocol is built entirely around cross-chain intents for bridging. The solver handles the cross-chain execution, and settlement contracts on both chains verify the outcome.
*Disclaimer: This article is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency involves significant risk, and you should conduct your own research before making any decisions. Information is accurate as of August 2026.*

Advertisement

Source link

Continue Reading

Crypto World

How cross-chain bridges work and why $4 billion has been stolen from them

Published

on

How cross-chain bridges work and why $4 billion has been stolen from them

Bridges move assets between blockchains using lock-and-mint, burn-and-mint, or liquidity pool mechanisms, but their trust assumptions have made them the most exploited category in crypto.

Summary

  • Cross-chain bridges transfer value between blockchains that cannot natively communicate, using mechanisms like lock-and-mint, burn-and-mint, and liquidity pools.
  • Bridge exploits have caused over $4 billion in losses since 2021, making bridges the single most attacked category of smart contracts.
  • The Ronin ($624 million), Wormhole ($326 million), and Nomad ($190 million) hacks each exploited different trust assumptions, from compromised validator keys to faulty message verification.
  • Light client bridges and zero-knowledge proof verification offer stronger security guarantees but are more expensive to operate and slower to deploy.
  • Users should evaluate a bridge’s verification mechanism, audit history, and total value locked relative to its security budget before transferring significant funds.

Introduction

Blockchains do not talk to each other. Ethereum cannot read Solana’s state. Arbitrum cannot verify a transaction on Avalanche. Each chain maintains its own ledger, its own consensus, and its own finality rules. This isolation is a feature of security design, but it creates a practical problem: users hold assets on one chain and want to use them on another.

Bridges exist to solve this. A bridge is a system that lets a user deposit assets on chain A and receive corresponding assets on chain B. The concept sounds simple. The implementation is where billions of dollars have been lost.

Advertisement

The core difficulty is verification. When a user claims to have deposited 100 ETH on Ethereum and asks for 100 ETH on Arbitrum, someone or something must verify that the deposit actually happened. The mechanism chosen for this verification determines the bridge’s security model, its speed, its cost, and its attack surface. As a Coinbase analysis of bridge hacks noted, bridge security failures consistently stem from the gap between the trust assumptions a bridge claims and the trust assumptions it actually enforces.

This guide covers how the major bridge architectures work, why each of the largest exploits succeeded, and what to check before trusting a bridge with your funds.

Lock-and-mint: the original bridge mechanism

The earliest and most common bridge design is lock-and-mint. The mechanism works in three steps:

  1. Lock. The user sends tokens to a smart contract on the source chain. The tokens are locked (held) in that contract, not burned or transferred.
  2. Verify. A set of validators, relayers, or an oracle observes the deposit on the source chain and attests to its validity on the destination chain.
  3. Mint. A smart contract on the destination chain mints a synthetic version of the locked token. The user receives “wrapped ETH” or “bridged USDC” that represents a claim on the locked original.

To move back, the process reverses: the user burns the synthetic token on the destination chain, validators attest to the burn, and the original tokens are unlocked on the source chain.

The security of lock-and-mint depends entirely on the verification step. If an attacker can convince the destination chain that a deposit occurred when it did not, they can mint unbacked tokens. This is exactly what happened in the largest bridge exploits.

Advertisement

The arithmetic problem. Lock-and-mint bridges must maintain a 1:1 ratio between locked originals and minted synthetics. If 10,000 ETH is locked on Ethereum, exactly 10,000 bridged ETH should exist on the destination chain. Any discrepancy means some bridged tokens are unbacked. When exploits create unbacked synthetics, the last users to redeem find the vault empty. This creates a bank-run dynamic: once news of an exploit spreads, every holder of the wrapped token rushes to redeem, knowing that only the first to arrive will receive real assets.

Burn-and-mint: native cross-chain tokens

Burn-and-mint eliminates the wrapped token problem by destroying the original and creating a new one.

  1. Burn. The token is permanently destroyed on the source chain.
  2. Verify. The burn event is verified on the destination chain.
  3. Mint. New tokens are minted natively on the destination chain.

This model works only for tokens whose issuers control minting on multiple chains. Circle’s Cross-Chain Transfer Protocol (CCTP) for USDC is the largest implementation. When a user bridges USDC from Ethereum to Avalanche through CCTP, the Ethereum USDC is burned and native USDC is minted on Avalanche. There are no wrapped tokens, no liquidity fragmentation, and no unbacked synthetics.

The limitation is that burn-and-mint requires the token issuer to deploy and operate infrastructure on every supported chain. It is not a general-purpose mechanism. Arbitrary ERC-20 tokens cannot use burn-and-mint unless their developers build the cross-chain minting infrastructure. CCTP currently supports over a dozen chains, but each integration requires Circle’s direct involvement.

Liquidity pool bridges: speed through capital

A third model avoids both wrapping and burning by using pre-funded liquidity pools on each chain.

Advertisement

The mechanism:

  1. Deposit. The user deposits tokens into a pool on the source chain.
  2. Withdrawal. The user (or a relayer acting on their behalf) withdraws equivalent tokens from a pool on the destination chain.
  3. Rebalancing. The protocol periodically rebalances pools across chains to maintain adequate liquidity.

Stargate (built on LayerZero) and Across Protocol use variations of this model. The advantage is speed: because tokens already exist on the destination chain, there is no minting delay. The user receives real, native tokens immediately.

The tradeoff is capital efficiency. Liquidity must be pre-positioned on every supported chain, and that capital earns a return only when bridges are actively used. During low-volume periods, liquidity providers earn little while their capital sits idle. The aggregate capital requirements across all supported chains can reach hundreds of millions of dollars, creating a barrier to entry and a concentration risk if a single liquidity provider dominates.

The Ronin bridge hack: $624 million from compromised keys

On March 23, 2022, attackers drained $624 million in ETH and USDC from the Ronin bridge, which connected Ethereum to the Ronin sidechain used by the game Axie Infinity.

Ronin’s bridge used a multisig validation scheme. Nine validator nodes verified bridge transactions, and any five could authorize a withdrawal. The security assumption was that compromising five of nine independent validators would be impractical.

Advertisement

The assumption was wrong. Sky Mavis, the company behind Axie Infinity, controlled four of the nine validator nodes. A fifth validator had granted Sky Mavis temporary permission to sign on its behalf during a period of high transaction volume and never revoked the permission.

The attackers (later attributed to North Korea’s Lazarus Group by the FBI) compromised Sky Mavis’s systems and obtained the private keys for all five validators. With five of nine signatures, they authorized two fraudulent withdrawals: 173,600 ETH and 25.5 million USDC.

The exploit was not discovered for six days. It came to light only when a user tried to withdraw 5,000 ETH and found the bridge did not have enough funds.

The lesson. Multisig security is only as strong as the independence of its signers. When a single organization controls a majority of keys, the multisig is a single point of failure with extra steps.

Advertisement

The Wormhole hack: $326 million from a verification bypass

On February 2, 2022, an attacker exploited the Wormhole bridge to mint 120,000 wETH (wrapped ETH) on Solana without depositing any ETH on Ethereum. The exploit was worth approximately $326 million.

Wormhole’s bridge relied on a set of 19 guardians to verify cross-chain messages. The guardians would observe a deposit on Ethereum, produce a signed attestation (called a VAA, Verified Action Approval), and the Solana-side contract would verify the signatures before minting.

The vulnerability was in the Solana-side signature verification. Wormhole’s Solana contract used a deprecated system instruction (verify_signatures) that did not properly validate the accounts passed to it. The attacker crafted a fake guardian set, submitted a forged VAA with signatures from that fake set, and the contract accepted it as valid.

In effect, the attacker told the Solana contract “these guardians approved this mint” and the contract did not check whether the guardians were real.

Advertisement

Jump Crypto, which backed Wormhole, replaced the stolen 120,000 ETH from its own reserves. The full restoration happened within 24 hours, an unprecedented response that prevented cascading losses across Solana DeFi protocols that held wETH.

The lesson. Bridge verification code is high-value attack surface. A single logic error in how signatures are validated can allow unlimited unauthorized minting.

The Nomad hack: $190 million from a faulty update

On August 1, 2022, the Nomad bridge was drained of approximately $190 million. Unlike Ronin and Wormhole, Nomad was not attacked by a sophisticated group. It was drained by hundreds of individual copycats after the initial exploit became public.

Advertisement

Nomad used an optimistic verification model. Cross-chain messages were submitted and assumed valid unless challenged within a 30-minute window. A routine contract upgrade introduced a bug: the contract was initialized with a trusted root of 0x00, the zero bytes32 value.

In Nomad’s verification logic, every message was checked against the trusted root. Because 0x00 is the default value for uninitialized storage in Solidity, every message automatically passed verification. Any user could submit any message and the contract would accept it as proven.

Once the first attacker demonstrated that arbitrary messages were accepted, others copied the transaction, changed the recipient address, and replayed it. The bridge was drained by a swarm of opportunistic attackers, including white-hat hackers who later returned approximately $36 million in recovered funds.

The lesson. Initialization bugs in bridge contracts can be catastrophic. A single misconfigured parameter turned Nomad’s security model from “optimistic verification with fraud proofs” to “no verification at all.”

Advertisement

The Harmony Horizon hack: $100 million from a two-of-five multisig

In June 2022, the Harmony Horizon bridge lost $100 million when attackers compromised the private keys of two out of five validators in the bridge’s multisig. Harmony’s bridge required only two of five signers to approve a transaction, an unusually low threshold for a bridge holding $100 million.

The attack reinforced the Ronin lesson: multisig bridges are only as secure as their weakest signer set. When the threshold is low relative to the number of signers, a single infrastructure compromise can be sufficient. Security researchers had publicly criticized Harmony’s two-of-five threshold before the attack occurred.

The lesson. Threshold selection matters as much as validator count. A five-of-nine multisig offers meaningfully different security than a two-of-five multisig, even though both use the same underlying mechanism.

Cumulative losses and attack patterns

The scale of bridge losses is without precedent in smart contract security. Bridge exploits represent roughly $3 billion of the $17 billion in total crypto hacks over the past decade, making bridges the single most attacked category of smart contracts.

Advertisement

The attack patterns cluster into three categories:

Key compromise. The attacker obtains enough validator or signer keys to forge bridge messages. Ronin and Harmony followed this pattern. The vulnerability is not in the code but in the operational security of the signer infrastructure.

Verification bypass. The attacker finds a bug in the verification logic that allows forged messages to pass. Wormhole followed this pattern. The vulnerability is a code-level error in the most critical function of the bridge contract.

Initialization or upgrade errors. The attacker exploits a misconfiguration introduced during deployment or upgrade. Nomad followed this pattern. The vulnerability is procedural: the team made an error during a routine operation.

Advertisement

Each pattern requires a different defense. Key compromise is mitigated by increasing signer diversity and using hardware security modules. Verification bypass is mitigated by auditing and formal verification. Initialization errors are mitigated by upgrade procedures that include mandatory test runs on forked networks.

A fourth emerging pattern deserves mention: governance attacks. An attacker who accumulates enough governance tokens to control a bridge’s upgrade mechanism can modify the bridge contract to drain funds. This attack is slower and more visible than the others, but it targets bridges whose governance is concentrated or whose time-lock on upgrades is too short. Bridge teams increasingly use multi-day time-locks (48 to 72 hours) on contract upgrades to give users time to withdraw before a malicious change takes effect.

The intent-based alternative to traditional bridges

A newer approach sidesteps bridge contracts entirely by using intent-based cross-chain transfers. Across Protocol and UniswapX’s cross-chain mode let users express a bridging intent: “I have 1,000 USDC on Ethereum and want 1,000 USDC on Arbitrum.” A solver (called a relayer) immediately sends tokens from their own inventory on the destination chain, then later claims reimbursement.

This model reduces the trust surface. The user never deposits tokens into a bridge contract that holds pooled funds. The solver takes on the reimbursement risk, and the settlement contract enforces that the user received the promised output. There is no large pool of locked assets for an attacker to target.

Advertisement

The tradeoff is solver dependency: if no solver is willing to fill the intent at an acceptable price, the transfer does not execute. For high-traffic routes (Ethereum to Arbitrum, Ethereum to Base), solver competition is strong. For low-volume routes, solvers may not be active.

Light client bridges and zero-knowledge verification

The exploits above share a common weakness: they rely on external validators or multisigs to attest that something happened on another chain. If those attestors are compromised, the bridge fails.

Light client bridges take a different approach. Instead of trusting a validator set, the destination chain runs a light client that verifies the source chain’s consensus directly.

A light client bridge to Ethereum, for example, would track Ethereum’s validator set and verify block headers and state proofs on-chain. When a user claims to have deposited tokens on Ethereum, the bridge contract verifies the Merkle proof against the Ethereum block header it has already validated.

Advertisement

This approach is trust-minimized: the bridge trusts the source chain’s consensus, not an external committee. But it is expensive. Verifying Ethereum’s consensus on another chain requires significant computation, which translates to high gas costs.

Zero-knowledge proofs offer a solution to the cost problem. Instead of verifying every validator signature on-chain, a ZK proof can compress the verification into a single succinct proof. The destination chain verifies one proof instead of hundreds of signatures.

Projects like Succinct Labs, Polymer, and Lagrange are building ZK-verified bridges. These are still maturing, but they represent the strongest security model for cross-chain communication: trust the math, not the committee. Early implementations show verification costs dropping as ZK proving systems become more efficient, with some bridges already operating on mainnet with proving times under 30 seconds.

What this does not cover

This guide explains bridge mechanics and the largest exploits. It does not cover:

Advertisement
  • Token-specific bridging strategies or which bridge to use for a given asset
  • Detailed comparison of bridge aggregators (Li.Fi, Socket, Bungee)
  • The economics of liquidity provision for bridge pools
  • Cross-chain messaging protocols beyond their bridging function (LayerZero, Axelar, Chainlink CCIP as general messaging layers)

Practical checks before using a bridge

Check the verification mechanism. Multisig bridges are the weakest model. Light client and ZK-verified bridges are the strongest. Optimistic bridges fall in between. Know what you are trusting.

Look at the validator or guardian set. For multisig bridges, check how many signers exist, who operates them, and whether they are genuinely independent. If the majority of signers belong to the same organization or geographic jurisdiction, the multisig provides limited security.

Review audit history. Bridge contracts are high-value targets. Look for multiple independent audits from reputable firms. A bridge that has not been audited, or has been audited only once, warrants extra caution. Pay attention to the scope of audits: an audit of the token contract does not cover the verification logic.

Consider total value locked versus security budget. A bridge holding $500 million with a five-of-nine multisig presents a very different risk profile than a bridge holding $5 million. Attackers target bridges where the potential payout justifies the effort. The rational attacker calculates whether the cost of compromising enough keys is less than the value that can be extracted.

Test with small amounts first. Before bridging significant value, send a small test transaction. Verify that the receiving address, token, and amount are correct. Bridge transactions are typically irreversible.

Advertisement

Prefer native bridges for rollups. For Ethereum L2 rollups (Arbitrum, Optimism, Base), the canonical bridge inherits security directly from Ethereum’s consensus. Third-party bridges may be faster but introduce additional trust assumptions. Use canonical bridges for large transfers where security matters more than speed.

What is a cross-chain bridge?

A cross-chain bridge is a system that transfers assets or data between two blockchains that cannot natively communicate. The bridge locks, burns, or pools tokens on one chain and issues corresponding tokens on another, using a verification mechanism to ensure the transfer is legitimate.

Why have bridges been hacked so often?

Bridges are high-value targets because they hold large pools of locked assets. They also introduce complex trust assumptions at the boundary between two different security models. A vulnerability in the verification mechanism (compromised keys, faulty signature checks, initialization bugs) can allow an attacker to drain the entire pool in a single transaction.

Advertisement

What is the difference between lock-and-mint and burn-and-mint?

Lock-and-mint holds the original token on the source chain and mints a synthetic (wrapped) version on the destination chain. Burn-and-mint destroys the original and mints a new native token on the destination. Burn-and-mint produces native tokens rather than synthetics but requires the token issuer to control minting on both chains.

Are wrapped tokens safe?

Wrapped tokens are only as safe as the bridge that issued them. If the bridge is exploited and the backing assets are drained, the wrapped tokens become unbacked and lose their peg. Users holding wrapped tokens bear the bridge’s security risk, not just the underlying asset’s risk.

How long does bridging take?

It varies by mechanism. Liquidity pool bridges and intent-based bridges (Across) can complete in seconds. Lock-and-mint bridges with multisig verification typically take 10 to 30 minutes. Optimistic bridges with fraud proof windows can take 7 days for withdrawals from optimistic rollups to Ethereum, though fast bridges can front the liquidity to reduce this.

What is a light client bridge?

A light client bridge verifies the source chain’s consensus directly on the destination chain, rather than relying on an external validator set. It checks block headers and state proofs, trusting the source chain’s own security. This is more trust-minimized than multisig or optimistic verification but costs more gas to operate.

Advertisement

Can I lose money using a bridge?

Yes. If the bridge is exploited after you have deposited but before you have withdrawn, your locked tokens may be stolen. If you hold wrapped tokens and the bridge is hacked, your wrapped tokens may become worthless. Additionally, incorrect destination addresses or unsupported token types can result in permanent loss.

Which bridge should I use?

No single bridge is best for all situations. For USDC, Circle’s CCTP is the most secure option because it uses burn-and-mint with no wrapped tokens. For general ERC-20 transfers, compare the verification mechanisms of available bridges. Prefer bridges with light client or ZK verification, multiple independent audits, and a track record of secure operation. Bridge aggregators like Li.Fi can help compare routes.
*Disclaimer: This article is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency involves significant risk, and you should conduct your own research before making any decisions. Information is accurate as of August 2026.*

Source link

Advertisement
Continue Reading

Crypto World

Ripple Backs Zilo and Licuido to Accelerate Tokenized Markets

Published

on

Crypto Breaking News

Ripple has announced two strategic investments aimed at expanding how regulated tokenized financial assets move across its XRP Ledger (XRPL). The company says the deals are intended to improve “collateral mobility” for tokenized funds—an issue that has become increasingly relevant as institutions look for more efficient ways to use on-chain assets within existing financial workflows.

In a Monday announcement, Ripple said it invested in Zilo, a global transfer agency asset solutions provider for wealth managers, and in Licuido, a tokenization solutions company regulated by the UK Financial Conduct Authority. Financial terms were not disclosed.

Key takeaways

  • Ripple’s new investments target the infrastructure around tokenized asset lifecycle events—transfer agency, issuance, and collateral usage—on XRPL.
  • Zilo is a UK-based transfer agency solutions provider for wealth managers; Licuido is a UK tokenization firm regulated by the FCA.
  • Ripple did not disclose investment amounts, leaving investors to assess impact based on the strategic integration of these partners into XRPL-based services.
  • The announcement arrives amid rising tokenized real-world assets activity, including new XRPL-based launches approved by regulators.

Why transfer agency and tokenization infrastructure matter

Tokenized real-world assets (RWAs) depend on more than issuance and settlement technology. For institutional participation, the operational stack must also support regulated lifecycle components such as transfer agency, issuance processes, and how assets (or their representations) can be pledged or reused as collateral.

Ripple’s stated goal is to bring “regulated transfer agency, issuance, and collateral mobility” into XRPL infrastructure. According to the company, the combination of the two investments is designed to address friction related to idle collateral by enabling tokenized funds to be used as collateral from the point of issuance.

While stablecoins and on-chain settlement get much of the attention, this kind of infrastructure push speaks to a broader theme in RWAs: institutions often need familiar controls, governance, and operational guarantees that mirror traditional market plumbing—only faster, more programmable, and easier to interoperate across counterparties.

Advertisement

Zilo and Licuido: what Ripple says it is buying into

The Zilo investment focuses on transfer agency capabilities for wealth managers. Ripple described Zilo as providing global transfer agency asset solutions, a function that can include administrative and compliance-heavy tasks tied to holding, transferring, and servicing investment products.

For market participants, transfer agency is especially significant because it determines how ownership records are managed, how subscriptions or redemptions are handled, and how compliance and reporting obligations are met. Bringing that layer closer to tokenized issuance and ongoing asset movement can reduce operational handoffs—often one of the major barriers for scaling tokenized offerings.

Licuido, by contrast, is positioned as a tokenization solutions provider that operates in a regulated environment. Ripple highlighted that Licuido is regulated by the UK Financial Conduct Authority, which could be relevant for firms aiming to structure tokenized products with compliance expectations baked into the system rather than added after the fact.

Neither investment’s size was disclosed by Ripple. However, the article notes that UK-based Zilo has raised $58.7 million in total equity funding, based on data compiled by Traxcn.

Advertisement

Momentum across XRPL as tokenized funds expand

Ripple’s move comes shortly after institutional activity on XRPL. Earlier, London-based asset manager Aviva Investors launched a tokenized share class of its US Dollar Liquidity Fund on XRPL, after receiving approval from the Central Bank of Ireland, according to earlier coverage. That development underscored that XRPL-based tokenization is not just a technical experiment—it is reaching regulated asset structures with supervisory sign-off.

The investments also follow Ripple’s own product push on the stablecoin side. Last month, Ripple launched Ripple Mint, a platform that gives institutions new ways to access, mint, redeem, and manage Ripple USD (RLUSD), its US dollar-pegged stablecoin. Together, these efforts indicate a two-pronged strategy: improve tokenized asset tooling around issuance and collateral use, while also expanding institutional access mechanisms for the stablecoin that often anchors value transfer.

At the network level, XRPL is part of a broader acceleration in tokenized RWAs. According to data from RWA.xyz referenced in the source, XRPL is the 11th-largest blockchain network by tokenized real-world assets, with $368 million in tokenized RWAs. Ethereum leads at $17.1 billion, per the same dataset.

Over the past 30 days, total RWA holders increased by 50% to 1.57 million, while total tokenized asset value rose by 1.5% to $37.3 billion. For investors, these figures suggest continued expansion, even as most networks compete on how efficiently they can support regulated asset workflows—not merely on-chain performance.

Advertisement

What to watch next for XRPL-based RWAs

Ripple’s latest announcements point to a practical focus: moving beyond token issuance to the operational lifecycle that institutions require, particularly where collateral reuse and collateral lock-ups can slow capital efficiency. The next question is how quickly these partner integrations translate into deployments—such as new tokenized funds, more standardized custody/transfer agency processes, or demonstrable reductions in collateral idling.

For market participants, attention should also be on whether future XRPL launches continue to follow regulator-approved paths and whether the tokenization stack expands toward wider categories of tokenized products—especially those that require complex transfer and compliance operations.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Advertisement

Source link

Continue Reading

Crypto World

US Tech Stocks See Largest 5-Week Inflow in History: Can Nasdaq Break Its Downtrend?

Published

on

US Tech Stocks See Largest 5-Week Inflow in History: Can Nasdaq Break Its Downtrend?

Tech stocks have attracted their largest five-week inflow in history, fresh fund flow data shows. The Nasdaq Composite has climbed for three straight sessions and now presses against a trendline that has capped it since June.

The surge reverses a sharp July correction across megacap technology names. Fund flows and chart structure now point the same way, although key resistance levels remain unbroken.

Most US Tech Stocks are Trading Upwards on Monday, August 3. Source: Trading Economics

Tech Stocks Attract Record Inflows as Rotation Gathers Pace

Weekly flows into tech funds spiked to roughly $19 billion, the highest single-week reading since at least 2017, according to Barchart. The four-week moving average has turned nearly vertical, capping the strongest five-week stretch on record.

Deutsche Bank strategists led by Parag Thatte counted $15.6 billion in tech fund inflows last week alone. The team argues the rotation is just getting started. It sees hyperscalers as the best risk-reward on offer, with their performance relative to the S&P 500 near a three-year trough.

Advertisement

The buying follows a painful stretch. The Magnificent Seven ETF fell more than 8% from its early June record, while the Philadelphia Semiconductor Index lost over 19%. Earlier this year, semiconductors had outperformed both Big Tech and crypto.

Some strategists read the pullback as a reset rather than a top.

“It would be incredibly hard for us to outrun a bear market in the Mag 7. But the fact that we’ve seen such an aggressive pullback in this group and the market has been flat-ish during that period, I view that as incredibly healthy.”

Mark Hackett, chief market strategist at Nationwide, said in comments reported by Reuters on July 29.

Positioning also leaves room to run. Deutsche Bank notes aggregate equity exposure remains slightly below neutral, with discretionary investors still underweight. Meanwhile, BofA data show that 2026 is on track to reach roughly $152 billion in annual tech inflows, a record.

Advertisement

Nasdaq Bounces off the 0.382 Fib, but the Downtrend Still Holds

The daily chart shows the Nasdaq Composite defended the 0.382 Fibonacci retracement at 24,707 as support. The index has printed three consecutive green sessions. It traded near 25,790 at the time of writing, up 1.6% on the day.

Price is now testing the descending trendline drawn from the record high of 27,190 set on June 1. However, a supply zone between 26,000 and 26,400 sits directly above. That area has rejected every recovery attempt since late June.

Nasdaq daily chart. Source: Tradingview

Momentum favors the bulls for now. The Relative Strength Index (RSI) is trending higher at around 53, still neutral, with room before reaching overbought conditions. Volume remains moderate, suggesting conviction has not fully returned.

Recent weakness in memory names such as Micron and SanDisk shows that the rebound remains uneven beneath the surface.

Nasdaq Price Prediction Hinges on the 26,000 Zone

A confirmed breakout above the trendline would expose the 26,000 to 26,400 resistance area, with the move starting less than 1% above current levels. Clearing that zone could put the 27,190 record back in play, roughly 5.4% higher.

Advertisement

However, rejection at the trendline risks another leg down. First support waits at 24,707, about 4% below. A deeper correction may reach the 0.618 retracement at 23,173, around 10% lower, where an April demand zone also sits.

The calendar could decide the outcome. This week brings a heavy earnings slate and fresh US labor market data, while investors continue to weigh Big Tech’s AI capital spending. The Nasdaq already surged 21.4% in Q2, its best quarter since 2020.

Record inflows say the buyers are back. The trendline will decide whether they get paid.

The post US Tech Stocks See Largest 5-Week Inflow in History: Can Nasdaq Break Its Downtrend? appeared first on BeInCrypto.

Advertisement

Source link

Continue Reading

Crypto World

The Biggest Crypto Threat In 2026 Isn’t Hackers. It’s Your Own Brain

Published

on

Crypto Breaking News

You can audit smart contracts. You can’t audit yourself. And AI just made human manipulation infinitely more convincing.

The Security Problem Nobody Wants To Admit

The crypto industry has spent billions on smart contract audits, multi-signature wallets, hardware security modules, penetration testing, and bug bounties.

All of it assumes the attack vector is technical.

It’s not.

Advertisement

The Solana Foundation’s new CISO Michael Coates said it publicly this week: crypto’s biggest security threats in 2026 are increasingly coming from AI-powered social engineering and compromised credentials. Not smart contract exploits. Not protocol vulnerabilities.

People.

The attackers shifted targets. They’re not trying to break the code anymore. They’re trying to break you.

And AI just gave them tools to do it better than ever.

Advertisement

What Social Engineering Actually Means

Social engineering is the art of manipulating humans into doing things that compromise security.

It’s not new. Con artists have always existed. Phishing emails have been around for decades. Fake customer support calls are as old as telephones.

But here’s what changed in 2026:

AI made social engineering indistinguishable from reality.

Advertisement

Before AI: A phishing email had grammatical errors, strange formatting, a slightly off email address. Trained eyes could catch it.

After AI: A phishing email is grammatically perfect, emotionally calibrated to your specific psychology, sent from a domain that looks exactly right, at a time when you’re most likely to be distracted, referencing real details from your public profiles.

Before AI: A fake customer support call had an accent, a script, tell-tale signs of inauthenticity.

After AI: A deepfake voice replicates your exchange’s actual support team. The conversation flows naturally. It knows your account details because it scraped your public information. It knows how to build rapport before asking for anything.

Advertisement

Before AI: A fake emergency message from a colleague was detectable because it didn’t sound like them.

After AI: It sounds exactly like them because AI trained on their communication style, their LinkedIn posts, and their email patterns.

The human brain evolved to detect threats from other humans. It didn’t evolve to detect threats from AI systems trained specifically to exploit human psychology.

Why Crypto Is The Perfect Target

Every industry faces social engineering. But crypto has properties that make it uniquely vulnerable.

Advertisement

Irreversibility. When someone tricks a bank customer into a wire transfer, there’s a chance, small but real, of reversal. When someone tricks a crypto user into sending funds, it’s gone—permanently. No chargeback. No fraud department. No appeal.

Pseudonymity. Attackers are harder to trace. The accountability that discourages fraud in traditional finance is weaker in crypto.

High Stakes In Individual Wallets. A single compromised wallet can contain life-changing sums. The ROI on targeting a crypto user versus a traditional bank customer is significantly higher.

Community Of Sophisticated Users Who Think They’re Immune. This is the most dangerous property. Crypto users tend to be technically sophisticated. They know about phishing. They know about scams. They think they’re too smart to fall for it.

Advertisement

That confidence is the vulnerability.

The most effective social engineering targets people who think they can’t be manipulated because they’ve stopped being vigilant.

The Attack Pattern That’s Working Right Now

Coates described the shift clearly: attackers are targeting people, not protocols.

Here’s what that looks like in practice in 2026:

Advertisement

The Fake Emergency: You receive a message, voice, text, or email that appears to be from your exchange’s security team. There’s been suspicious activity on your account. You need to verify immediately or face suspension. The urgency is real. The consequences feel immediate. You act without thinking carefully.

The message was AI-generated. The voice was deepfaked. The urgency was engineered.

The Compromised Colleague: Someone in your organization receives what appears to be a message from a trusted colleague—perhaps your CFO, your CTO, your CEO—asking for a wallet transfer. The tone is right. The context makes sense. The request is urgent because there’s a deal closing.

The colleague never sent it. Their communication style was scraped and replicated.

Advertisement

The Too-Good-To-Be-True Opportunity: You’re approached on LinkedIn, Discord, or Telegram by someone who seems genuinely informed about your project, your portfolio, your interests. They have an opportunity—an early investment, an exclusive access, a partnership. The conversation feels real over days or weeks.

It’s AI maintaining a relationship at scale, designed to eventually extract something.

The Recovery Scam: You posted publicly about a crypto problem. Someone, AI or AI-assisted, found it immediately and reached out offering help. They’re helpful, knowledgeable, and patient. They walk you through “recovery steps” that actually compromise your wallet.

All of these work on smart people. Because intelligence doesn’t protect against emotional manipulation. It often makes it worse—smart people are better at rationalizing why the exception is real this time.

Advertisement

The Quantum Problem In The Background

While social engineering is the immediate threat, Coates also flagged what’s coming: quantum computing.

Post-quantum cryptography is no longer a theoretical concern. Anthropic’s AI recently broke a post-quantum cryptography candidate, raising serious questions about the security assumptions underlying current encryption.

Solana is evaluating post-quantum cryptography. Other chains are doing the same.

This is a technical problem that technical solutions can address. Unlike social engineering, which targets humans, quantum threats target mathematics. Mathematics can be upgraded.

Advertisement

But here’s the uncomfortable overlap: the transition to post-quantum cryptography will itself become a social engineering attack surface.

Users will receive communications claiming they need to “upgrade their wallet security” or “migrate their funds to quantum-resistant addresses.” Some of those communications will be legitimate. Some will be AI-generated attacks designed to look legitimate during the transition.

The technical threat and the human threat converge.

Why “Just Be Careful” Isn’t A Solution

The standard advice: be careful. Verify before you act. Don’t click suspicious links. Check email addresses carefully. Never share your seed phrase.

Advertisement

This advice was adequate when social engineering was low-fi, when attacks were detectable by someone paying attention.

It’s not adequate anymore.

Coates said something important: crypto must “meet users where they are” instead of expecting them to act as security experts.

That’s an acknowledgment that the current model—educate users, hope they stay vigilant—is failing.

Advertisement

Because AI-powered social engineering doesn’t require users to make obvious mistakes. It requires them to make very small lapses in judgment at carefully engineered moments.

You’ve been careful a thousand times. The attack only needs to work once.

What Actually Protects You

If human vigilance is insufficient, what works?

Systems That Don’t Require Perfect Human Judgment.

Advertisement

Multi-signature requirements that mean no single person can authorize a large transfer alone. Time delays on large transactions that create a window for human review. Anomaly detection that flags behavior inconsistent with your patterns.

These aren’t exciting. They’re friction. But friction is the point.

The best security doesn’t make you smarter. It makes the attack harder even when you’re not being smart.

Verification Protocols That Don’t Rely on Communication Channels.

Advertisement

If a “colleague” sends an urgent transfer request, the verification doesn’t happen over the same channel. It happens via a pre-established out-of-band protocol—a specific phone number, an in-person confirmation, a code word.

AI can replicate communication channels. It can’t replicate physical presence or pre-established secrets.

Institutional Humility.

The most dangerous users are the ones who’ve never been fooled because they believe they never will be. The most secure users are the ones who assume they’re vulnerable and design their behavior accordingly.

Advertisement

Security isn’t about being smarter than the attacker. It’s about designing systems that work even when you’re not at your best.

The Industry’s Uncomfortable Admission

Coates’ statement represents something significant: a major blockchain foundation publicly admitting that the threat model has shifted.

For years, the crypto security conversation was dominated by smart contract audits, protocol security, code review. The implicit assumption: the humans are fine, the code needs protecting.

Now the CISO of a major blockchain foundation is saying: the humans are the vulnerability. The code is (relatively) fine.

Advertisement

That’s a meaningful shift, and it has implications for how the entire industry thinks about security.

You can’t audit your way out of this one. You can’t write a bug bounty for human psychology. You can’t patch the vulnerability that makes people respond to urgency.

The security stack has to include the human layer, not just user education, which is clearly insufficient. System design that compensates for human fallibility under pressure.

What This Means For Everyone In Crypto

If you’re a user: your biggest risk isn’t a smart contract exploit. It’s a well-timed, well-crafted message that catches you in a moment of stress, urgency, or distraction. Design your security protocols assuming that moment will happen. Remove single points of human failure.

Advertisement

If you’re building: user education is necessary but not sufficient. Build friction into high-stakes actions. Design for the distracted, pressured, temporarily-fooled user, not the ideal vigilant one.

If you’re in security: the threat model has to include AI-powered social engineering as a primary attack vector, not an edge case. Red team exercises need to include sophisticated AI-assisted social engineering simulations.

If you’re an investor: ask every project you invest in: what’s your human security layer? Not just your smart contract audit. What protects against AI-powered attacks on your team members?

The Real Arms Race

Everyone talks about crypto’s AI arms race as a trading problem. AI trading against AI. Faster algorithms, better predictions.

Advertisement

The real arms race is in security. Attackers using AI to exploit human psychology at scale. Defenders using AI to detect anomalous behavior and flag suspicious communications.

One side is attacking a fixed vulnerability: human cognitive limitations under pressure.

The other side is defending a moving target: human behavior across thousands of employees, users, and community members.

The attackers have a structural advantage. They only need to succeed once.

Advertisement

The defenders need to succeed every time.

That asymmetry is the actual security crisis in crypto. Not the code. The people.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Advertisement

Source link

Continue Reading

Crypto World

Using AI to Create Images? Europe Has a New Rule You Must Follow

Published

on

AI Job Displacement Concerns Pushes US Senators to Demand Action

The European Union began enforcing the AI Act’s transparency rules on Sunday. Chatbots operating in the bloc must now tell users they are talking to a machine, and AI-generated deepfakes require clear labels.

The European Commission’s AI Office and national regulators also gained enforcement powers for the first time. Penalties reach €35 million or 7% of global annual turnover for the most serious violations.

Note: A normal person posting an AI-generated image on a personal social media account would not be fined under this EU rule. Personal, non-professional use is excluded from the AI Act. The situation changes when the content is used professionally or commercially. For example, by a business, freelancer, or monetised influencer.

What the EU AI Act Now Requires

The Commission confirmed that Article 50, the law’s transparency chapter, applies from August 2, 2026. AI systems that interact directly with people must reveal they are machines. The duty covers chatbots, voice assistants, and agents from the first interaction onward.

Advertisement

The rules apply to any provider or deployer whose system reaches users in the EU, regardless of where the company is based.

The duty extends beyond conversation. Deployers must flag AI-generated or manipulated images, audio, and video as artificial. Text published to inform the public also needs a label unless a human editor has reviewed it and taken responsibility.

Companies running emotion recognition or biometric categorization systems must inform every person exposed to them. An independent guide to the provision notes that clearly creative or satirical uses face lighter disclosure duties.

One element got extra time. Generative systems already on the market have until December 2, 2026, to add machine-readable watermarks to synthetic content.

Advertisement

Regulators Can Finally Issue Fines

Until now, the AI Act operated largely on trust. General-purpose AI model providers have carried documentation and copyright obligations since August 2025. However, Brussels had no power to compel compliance.

That changed on Sunday. The AI Office may now demand documentation, evaluate models directly, order corrective measures, or pull models from the EU market. Transparency breaches carry fines of up to €15 million or 3% of worldwide turnover.

The stakes rise for prohibited practices, where penalties climb to €35 million or 7%. The shift lands as Europe’s play for Anthropic shows the bloc courting the same firms it now polices.

Advertisement

Most of the Feared Deadline Never Arrived

August 2 was long billed as the EU AI Act’s biggest compliance date. The Digital Omnibus, an amendment package signed July 8, postponed the high-risk obligations due the same day.

Hiring, credit scoring, and law enforcement systems now have until December 2027. AI embedded in regulated products, such as medical devices, has until August 2028.

Lawmakers framed the delay as time for technical standards to mature, while critics called it a retreat under industry pressure. Developers have pushed back on rules globally, recently backing open AI models against proposed limits.

Advertisement
Change What it means Effective
Chatbot disclosure AI systems must identify themselves to users August 2, 2026
Deepfake labels AI-generated media must be disclosed as artificial August 2, 2026
Enforcement powers Fines up to €35 million or 7% of turnover August 2, 2026
Content watermarking Machine-readable marks on synthetic content December 2, 2026
High-risk systems Hiring, credit, and policing AI obligations December 2, 2027
High-risk products AI in medical devices and machinery August 2, 2028

The surviving rules may matter most for crypto. AI trading bots, automated support agents, and token projects using AI-generated promotional videos all fall under the disclosure duties.

The first enforcement actions will show how hard the AI Office intends to swing.

The post Using AI to Create Images? Europe Has a New Rule You Must Follow appeared first on BeInCrypto.

Advertisement

Source link

Continue Reading

Trending

Copyright © 2025