Crypto World
Teen Drama Sterling Point Is the Best Kind of Lazy-Summer Throwback
Plenty of classic teen-drama tropes come into play. Not only does Annie get caught in a love triangle, but her two suitors each represent opposing factions of the community: townies and summer people. Ellis (Jacob Whiteduck-Lavoie) is a hard-working, year-round resident, and Rory (Daniel Quinn Toye) a rich New York acquaintance whose family has a luxurious vacation home nearby. As also tends to be the case in stories aimed at teens, the young characters are remarkably autonomous. But creator and co-showrunner Megan Park, whose films The Fallout and My Old Ass displayed deep insight into the inner lives of young women, isn’t mindlessly mimicking the mini-adults of Euphoria and Gossip Girl. (Sterling Point shares co-showrunners with the latter series, in Josh Schwartz and Stephanie Savage, which goes to show how conscious a choice its divergence from its millennial predecessors must be.) Like Annie, most of these characters have been forced by their parents to fend for themselves, emotionally if not quite literally. One of the most charming performances in a show that has many of them comes from Bo Bragason as Oona, a bubbly lesbian flirt whose mom has jetted off to India, leaving her in charge of her little sister (Mabel Strachan) and their houseboat.
Crypto World
BNY, Galaxy Launch Institutional Crypto Staking Service
Cointelegraph is committed to providing independent, high-quality journalism across the crypto, blockchain, AI, and fintech industries.
All news, reviews, and analyses are produced with full journalistic independence and integrity. For more details on our standards and processes, please read our Editorial Policy.
Crypto World
Amazon’s $3 Trillion Record Lasts One Day as Stock Takes Big Hit
Jeff Bezos wants to sell 15 million Amazon shares. The price tag is about $4.07 billion. Amazon.com Inc. (AMZN) fell more than 2% on Tuesday.
The timing stands out. Amazon had just closed at a record and passed $3 trillion in value for the first time.
Bezos Amazon Stock Sale Was Priced Before the Record
Bezos filed a Form 144. That is the notice an insider files before selling restricted shares.
The notice puts the total value at $4,073,700,000. Divide that by 15 million shares and you get $271.58 each. That was Friday’s closing price, not Monday’s.
Amazon then rose 4.58% on Monday and closed at $284.02, an all-time high. It touched $287.20 during the day.
At Monday’s close, the same shares were worth roughly $4.26 billion. Bezos priced his sale before the record, not after it.
Morgan Stanley Smith Barney will handle the trades on Nasdaq. Bezos received the shares as founder stock in July 1994.
The sales follow a Rule 10b5-1 plan he set up on November 14, 2025. These plans lock in trades months ahead. That shields insiders from claims they traded on private information.
AMZN changed hands near $277.41 late Tuesday morning, down 2.33%. A year ago it closed at $211.65.
Follow us on X to get the latest news as it happens
He Is Selling Less Stock Than He Did Last Year
None of this is new for Bezos. He has filed the same kind of notice repeatedly since 2024.
Here is how his last three compare.
- August 2026, 15 million shares for $4.07 billion, or $271.58 each
- June 2025, 25 million shares for $5.43 billion, or $217.12 each
- November 2024, 16.35 million shares for $3.05 billion, or $186.40 each
So this is his smallest sale by share count. It is his second biggest by dollars.
The stock did that work, not Bezos. Each plan used the same broker and was set months in advance.
AWS Is Why the Price Got This High
Amazon’s second quarter earnings beat started the rally. Sales rose 20% to $200.6 billion. Operating income jumped to $27.5 billion from $19.2 billion.
Amazon Web Services (AWS) is the company’s cloud arm. It grew 37% to $42.2 billion. Its operating income climbed to $16.6 billion from $10.2 billion.
Banks moved fast. More than a dozen raised Amazon price targets. Benchmark went to $400, roughly 44% above Tuesday’s price.
That growth costs money. Amazon spent $54.2 billion on property and equipment last quarter. Over 12 months the bill reached $169 billion.
Free cash flow turned negative, an outflow of $7.6 billion. Other big tech names face the same AI capex draining cash.
Bezos still owned 880,948,653 shares in early May. That is close to 8% of Amazon. This sale trims about 1.7% of his stake.
It reads as diversification, not a warning. The next Form 4 filing will show what the shares actually sold for.
The post Amazon’s $3 Trillion Record Lasts One Day as Stock Takes Big Hit appeared first on BeInCrypto.
Crypto World
Italy’s Biggest Bank Cuts IBIT Exposure by 94% While Buying More Staked Ethereum
Italy’s largest banking group, Intesa Sanpaolo, sharply reduced its reported exposure to BlackRock’s iShares Bitcoin Trust (IBIT) in the second quarter.
While its BTC-related position changed, the bank more than tripled its holdings in staked ETH.
IBIT Holdings Plunges
According to its latest Form 13F, Intesa Sanpaolo held 40,723 IBIT shares as of June 30, which was down 93.7% from the 646,809 reported for March 31. The filing also revealed a major change in its reported call position in the fund. The underlying-share amount linked to its held-call row fell from 2,496,500 shares to 18,000, over a 99% decline.
Meanwhile, a new put position equivalent to 500,000 IBIT shares appeared in the June 30 disclosure. The reported figures, however, do not show that the bank adopted a net bearish strategy on Bitcoin.
Its iShares Staked Ethereum Trust ETF holding rose from 116,200 shares to 349,600. On the other hand, its position in the Bitwise Solana Staking ETF dropped from 2,817 to just seven.
The latest filing comes more than a year after Intesa Sanpaolo made its first direct Bitcoin purchase in January 2025. It bought 11 BTC for about $1.03 million. Back in July 2024, it also used the Polygon network to underwrite Italy’s first on-chain digital bond, worth $25.6 million. Later that year, it began offering options, futures and spot ETFs linked to digital assets through a dedicated desk.
Investors Turn to Ethereum ETFs
The bank’s move is significant as some BlackRock clients have recently made a similar shift. For instance, BSCN said customers of the asset management giant had sold around $60 million worth of the IBIT last week. At the same time, they bought more than $20 million worth of its ETHA spot Ethereum ETF.
While Intesa cut its IBIT position, the broader US spot Bitcoin ETF market has recently moved in the other direction. These funds saw a record monthly net outflow of about $4.5 billion in June. The trend reversed in July, when the funds raked in $172.4 million. That marked a turnaround after two straight months of heavy withdrawals and helped BTC’s prices move back toward $64,000 in the middle of the month.
This sentiment appears to have continued into August, as the ETFs have attracted another $170 million so far. BlackRock’s IBIT remains the leading fund, with almost $61 billion in total inflows since it was first listed.
The post Italy’s Biggest Bank Cuts IBIT Exposure by 94% While Buying More Staked Ethereum appeared first on CryptoPotato.
Crypto World
Samsung is bringing stablecoins to 800 million phones in a massive crypto bet
“By doing so, Samsung Wallet becomes the foundation for an interconnected financial ecosystem across Galaxy devices and services — where it combines payments, rewards, and digital assets into a single unified experience,” he said.
If it follows through, over 800 million would potentially have access to Galaxy’s stablecoin features and other crypto without requiring a separate crypto app or exchange account. Already, there are over one billion active Samsung smartphones worldwide.
Stablecoins and infrastructure
During its Q2 earnings call last week, Samsung SDS CEO Lee Jun-hee said that the company’s stake in crypto exchange Upbit operator Dunamu is a strategic investment to enter the digital asset infrastructure business, including stablecoins and AI-powered payments.
Three Samsung affiliates agreed in May to acquire a 4% stake in Dunamu, the operator of South Korea’s largest cryptocurrency exchange, Upbit, for $408 million. Samsung Securities, Samsung SDS and Samsung Card are the affiliates involved in the deal.
“This is the other half of the same strategy, and from a deal perspective, it is the more telling half,” said Goh. “The wallet announcement secured distribution; SDS and Dunamu will secure the infrastructure beneath it.”
Goh said he believes Samsung is aiming to build the infrastructure itself, rather than rely on a third-party provider. “Their goal is to be positioned in both dollar and won stablecoins while Korea’s framework is still being discussed. The timing is deliberate.”
Crypto World
Wall Street predicts XRP ETFs will attract $8 billion in inflows, with XRP holders potentially earning up to $9,000 per day
Disclosure: This article does not represent investment advice. The content and materials featured on this page are for educational purposes only.
XRP ETF inflows surpass $1.5 billion as investors increasingly explore alternative strategies, including EX DeFi cloud mining, for long-term crypto exposure.
Summary
- XRP ETF inflows surpass $1.5B as institutional demand grows and investors explore new digital asset opportunities.
- XRP ETF milestone boosts market confidence, while EX DeFi attracts attention from investors seeking alternative yield options.
- Institutional XRP demand accelerates with ETFs crossing $1.5B in inflows amid evolving investment strategies.
According to previous forecasts from JPMorgan and Standard Chartered, spot XRP ETFs are expected to attract $4 billion to $8 billion in inflows in the long term.

While current inflows into XRP ETFs have not yet reached the high levels previously predicted by Wall Street, the cumulative net inflows have already reached approximately $1.51 billion, successfully surpassing a significant milestone and further strengthening market confidence in XRP’s long-term prospects.
With ETFs continuing to receive funding support, and XRP prices not yet showing a significant increase, many investors are beginning to consider a practical question: besides waiting for price appreciation, are there more efficient and sustainable ways to participate in XRP’s long-term value growth?
Against this backdrop, a growing number of investors are turning their attention to EX DeFi cloud mining platforms, hoping to explore more diverse long-term returns on digital assets amidst market volatility, rather than solely relying on XRP’s price appreciation.
XRP ETF inflows surpass $1.5 billion, market attention continues to rise
According to market data cited by TradingView, driven by continuous net inflows, XRP-related exchange-traded funds (ETFs) have seen cumulative inflows exceeding $1.5 billion, marking a significant milestone for XRP.
Meanwhile, overall market liquidity continues to improve. Although XRP trading activity has slowed somewhat, and many retail investors remain relatively cautious, institutional investor demand has maintained a slight increase, contributing to continued net inflows for most trading days.
ETF inflows continue, XRP investors focus on more diverse participation methods
With the continued inflow of ETF funds, more and more XRP investors are focusing on EX DeFi, exploring more robust and sustainable ways to grow the value of digital assets through its automated cloud mining system and yield aggregation mechanism.
Compared to highly volatile leveraged trading or ETF investments, EX DeFi offers a more convenient way to participate in digital assets, helping users engage with the XRP ecosystem even in volatile markets and further improve the efficiency of digital asset utilization to generate returns. For users with a certain amount of capital, different asset management solutions can be chosen according to their needs to explore long-term value growth opportunities.
About EX DeFi
Headquartered in the UK, EX DeFi strictly adheres to local laws and regulations and operates under European regulatory frameworks such as MiCA and MiFID II. It continuously strengthens platform governance, security measures, and operational transparency to create a safe, reliable, and sustainable cloud mining service for users.
The platform employs a multi-layered security architecture, including:
- PwC annual financial and security compliance audit
- Lloyd’s of London digital asset custody insurance
- Cloudflare enterprise-grade cybersecurity protection and McAfee® security system
- Cold and hot wallets, multi-layered encryption architecture, and two-factor authentication (2FA).
Currently, EX DeFi supports multiple mainstream digital assets such as XRP, BTC, ETH, USDT, USDC, DOGE, LTC, and SOL, providing users with more flexible and convenient choices.
How to earn daily yields with EX DeFi
EX DeFi is easy to use; even beginners can get started in minutes with just four steps:
1: Register an Account
2: Deposit Cryptocurrency
On the Deposit Center page, select XRP (or other cryptocurrencies), copy the corresponding deposit address on the platform, and then transfer the XRP through a wallet or exchange. (No tags required)
3: Choose a Mining Contract
Choose a mining plan that suits a particular budget; mining will start automatically after system activation.
4: Automatically Receive Daily Rewards
The platform provides 24/7 intelligent mining services, with rewards automatically settled to an account 24 hours a day. Users can easily earn passive income without any user intervention.
Popular profit contracts
BTC (Beginner Trial Contract): Investment of $100, Term: 2 days, Daily Yield: $4, Total Profit: $100 + $8
DOGE (Golden Shell Mini Dogecoin Pro): Investment of $500, Term: 6 days, Daily Yield: $6.5, Total Profit: $500 + $39
BTC (Canaan-Avalon-A1466): Investment of $1,000, Term: 10 days, Daily Yield: $13.4, Total Profit: $1,000 + $134
LTC (Bitmain Antminer L7): Investment of $5,000, Term: 20 days, Daily Yield: $73.5, Total Profit: $5,000 + $1,470
BTC (Bitmain S19K-Pro): Investment of $10,000, Term: 30 days, Daily Yield: $161, Total Profit: $10,000 + $4,830
Click here for more details on popular EX DeFi mining contracts.
Summary
While the inflow of funds into the XRP ETF still falls short of Wall Street’s previous expectations, continued institutional inflows, an improving regulatory environment, and the development of the XRP ecosystem continue to provide strong support for its long-term value. In the future, XRP’s market performance will still depend on fund flows, application implementation, and changes in the overall market environment.
Against this backdrop, more and more investors are focusing on long-term allocation and return management of digital assets, rather than just price fluctuations. EX DeFi aims to provide users with more diverse participation methods through smarter and more efficient cloud mining services, meeting the needs of different investors for long-term digital asset value growth.
Instead of chasing price increases, visit the official EX DeFi platform as soon as possible to start mining with one click and easily earn XRP.
Disclosure: This content is provided by a third party. Neither crypto.news nor the author of this article endorses any product mentioned on this page. Users should conduct their own research before taking any action related to the company.
Crypto World
As Clarity Act teeters, mystery group hammers away at crypto in Washington ads
The crypto industry’s central policy drive is to get U.S. laws that elevate it to a fully regulated and government-approved corner of the financial system. While the legislation to do that is struggling with its final Senate test, a mystery organization is flooding Washington, DC, with ads linking crypto to terrorists and drug cartels.
Across television and social media, the localized campaign warns in one example: “The worst people operating in the darkest places use crypto because there are no guardrails,” citing connections to drug cartels, terrorists and people praying against seniors.
“Let’s bring crypto out of the shadows now,” the ads say.
The recently emerging group behind the campaign is Crypto Watchdog, run by Executive Director Chapin Fay, a media strategist who had been involved in past Republican political campaigns but hadn’t been previously associated with crypto matters.
“Our mission is fairly simple and direct,” he told CoinDesk in an interview. “It’s to bring sunlight and transparency to an over-$2 trillion industry that has historically not been very transparent.”
Crypto World
A New Ethereum Proposal Could Halve Staking Rewards: Who Feels It First?
Ethereum Foundation researcher Justin Drake and five co-authors want to shrink the reward for staking ETH. Their draft plan would switch that reward off once half of all ETH is locked up.
Stakers would earn less. Everyone else would hold a slightly bigger slice of ETH. BeInCrypto maths puts the new reward near 1.1% a year, down from 2.6% now.
Why the Justin Drake Ethereum Proposal Targets Issuance
Ethereum pays people to help run it. Lock up ETH, help check transactions, earn new ETH.
The catch is that the payment never really stops. Even if every ETH were staked, it would still pay roughly 1.51% a year. BeInCrypto checked that against the code.
Follow us on X to get the latest news as it happens
So the staked pile keeps growing. It now sits at 41.1 million ETH, or 33.7% of all ETH in existence.
It is also bunching up. Lido alone holds 9.41 million ETH, by its own count, and Ethereum staking remains concentrated in a few hands.
The fix is simple, that every few minutes, the network would take a slice of each reward and destroy it.
That slice grows as more ETH gets staked. Today it would swallow 56%. At 60.25 million ETH, it would take the lot.
Burning is not new here. EIP-1559 already destroys part of every transaction fee.
Drake is the famous name, but not the author. A researcher known only as pintail wrote it. The argument itself has run since January 2023.
The Case Against Cutting ETH Staking Rewards
The plan says the biggest operators feel the squeeze first. The maths says not for a while.
BeInCrypto applied the plan’s own formula to Lido. Growth keeps paying Lido until about 49 million ETH is staked. That is nearly 8 million more than today.
The authors admit one reason. Validators also earn by ordering transactions, called Maximal Extractable Value (MEV). The burn never touches that money, and it always rewards getting bigger.
They put that side income below 78,300 ETH last year, worth 0.20% at most. That figure is theirs. BeInCrypto could not confirm it.
Home stakers face a second squeeze. Fines stay the same size while earnings shrink. Recovering from a few hours offline would take about four times longer.
So why half? The authors chose it on judgement, not on data.
“Half the supply is the last figure that refers to anything beyond preference: it is the majority threshold the risks above turn on,” they wrote.
That reasoning matters for ETH price levels, with ether near $1,866 on Tuesday. Reward changes move money fast, as the record ETH validator exit queue showed in 2025.
Nothing is settled yet. The plan is only a draft. It still needs editors, client teams, and a network upgrade.
Even day one stings. Rewards would drop 13% straight away. The question is whether big stakers accept a rule that stops paying them to grow.
The post A New Ethereum Proposal Could Halve Staking Rewards: Who Feels It First? appeared first on BeInCrypto.
Crypto World
Clarity Act sits idle over Trump ethics question as Warren asks SEC to investigate him
The $TRUMP coin was worth more than $46 at its height, but it steadily declined to its current price of $1.47. The token saw brief spikes in value when the company behind it announced it would host dinners — including at Trump’s Mar-a-Lago, with the president as the keynote speaker — but that price action was temporary both times.
In what’s likely to pack more political needling than actual regulatory results, the letter comes as negotiators hoping to finish the Digital Asset Market Clarity Act are awaiting the White House’s response to the latest revamping of the contentious section that would ban senior government officials from direct involvement in crypto projects.
For its part, the SEC has already ruled memecoins as generally outside its sphere of influence. In one of the early staff crypto statements after the Trump administration took over, the agency declared that memecoins have “limited or no use or functionality” and don’t check a box as securities under the law.
The ability for a government official, such as President Trump, to issue such a token is at the center of the negotiation over the ethics section of the Clarity Act. Trump recently agreed to be subjected to a limit, though the restrictions he agreed to would have very narrow practical effect. Democrats refused the approach and said they’d oppose the legislation unless that provision was made stronger, so Senators Thom Tillis, a Republican, and Ruben Gallego, a Democrat, negotiated a tougher version. The rewrite was sent to the White House last week, which hasn’t yet responded days later.
Crypto World
David Schwartz weighs in on $100M Coldcard hack
David Schwartz said the Coldcard breach shows that rare custody failures can produce devastating losses, comparing the incident with past breakdowns in traditional finance.
Summary
- Coldcard-related thefts have exceeded $100 million, according to Galaxy Research.
- Schwartz compared the custody risk with MF Global’s 2011 collapse but pointed to differences in insurance protection.
- A firmware flaw allowed attackers to reconstruct vulnerable wallet seeds without accessing the physical devices.
- Coinkite said affected users must create new seeds and move their funds because firmware updates cannot repair old seeds.
Schwartz compares Coldcard breach with TradFi failures
Ripple CTO Emeritus David Schwartz framed the Coldcard attack as an example of outlier risk—the possibility that a rare technical failure can cause losses far beyond what users expect.
Schwartz compared the incident with the 2011 collapse of MF Global, where customers temporarily lost access to funds after the brokerage misused money that should have remained segregated. His comments challenged the assumption that self-custody removes every form of counterparty or operational risk.
Hardware wallets allow users to control their private keys without relying on an exchange or other financial intermediary. However, owners must still trust that the device’s hardware and firmware generate and protect those keys correctly.
Schwartz also pointed to a major difference between traditional finance and crypto self-custody. Customers of regulated financial institutions may have access to insurance, bankruptcy proceedings, or other recovery mechanisms. Coldcard owners whose Bitcoin was stolen through compromised seeds currently have no comparable safety net.
What is the Coldcard hack?
Coldcard is a Bitcoin-only hardware wallet made by Canadian manufacturer Coinkite. The device stores private keys offline and can sign transactions without directly connecting to the internet.
The current breach did not involve attackers remotely accessing Coldcard devices. Instead, it resulted from a seed-generation flaw introduced through firmware released in March 2021.
According to Coinkite’s technical review, affected firmware used a software-based pseudorandom number generator rather than obtaining sufficient randomness from the device’s hardware generator. The problem affected seeds created on certain Coldcard firmware versions, including Mk2 and Mk3 releases from version 4.0.1 through 4.1.9.
Seed phrases should contain enough randomness to make guessing them computationally unrealistic. The Coldcard flaw reduced that protection, allowing attackers to generate possible seeds offline and compare their derived Bitcoin addresses with publicly visible addresses on the blockchain.
Once attackers found a match, they could recreate the wallet’s private keys and transfer its Bitcoin. They did not need to steal the hardware wallet, know its PIN, or compromise the Bitcoin network.
Coldcard losses exceed $100 million
As reported by crypto.news earlier, Galaxy Research said it had identified 1,596 BTC stolen from about 7,300 addresses across three confirmed attack waves. The firm also linked roughly 14 smaller incidents to the same seed-generation flaw.
A suspected fourth wave could raise the total to about 2,055 BTC, worth close to $130 million. However, Galaxy has not yet confirmed those additional losses.
The first major sweep occurred around July 30, when more than 1,000 BTC was removed from over 1,200 addresses in less than an hour. Two additional waves later targeted other wallets created using vulnerable seeds.
Galaxy shared hundreds of suspected attacker addresses with U.S. federal investigators, exchanges and blockchain security companies. About 90% of the Bitcoin stolen during the confirmed waves had not moved again at the time of its latest update.
The Bitcoin protocol was not compromised. The theft resulted from weak wallet-seed generation, meaning Bitcoin held in wallets created through unaffected software or hardware was not exposed by this specific flaw.
Coldcard owners must replace vulnerable seeds
Coinkite has released corrected firmware for affected Coldcard models. However, installing an update does not make an existing vulnerable seed secure.
The company’s security advisory instructs Mk2 and Mk3 owners who created seeds using firmware versions 4.0.1 through 4.1.9 to update to version 4.2.0 or later, generate a completely new seed and transfer their Bitcoin.
Users should first send a small test transaction and verify the receiving wallet before moving the remaining balance. Coinkite said its corrected seed-generation process is sufficient, while adding at least 50 private dice rolls remains an optional method for users seeking independent entropy.
The breach shows that air-gapped hardware can reduce online attack exposure without eliminating firmware, manufacturing, or seed-generation risks. For affected owners, moving funds to a newly generated wallet remains the only way to remove the immediate threat.
Crypto World
At Least 15 Attackers Exploited Coldcard Vulnerability: Report
Galaxy Digital’s research team says the Coldcard wallet exploit has been used by at least 15 different attackers, based on new victim reports submitted after the incident. In remarks shared this week, Alex Thorn, head of research at Galaxy Digital, suggested that these additional reports helped identify variants that might otherwise have remained hidden.
Thorn also indicated that losses tied to the exploit have risen as investigators mapped multiple waves of activity. Galaxy Research estimates the confirmed thefts total about $100 million across three waves, with an additional suspected fourth wave that could lift the figure to roughly $130 million in Bitcoin.
Key takeaways
- Galaxy Digital reports at least 15 distinct attackers behind the Coldcard exploitation, based on newly received victim accounts.
- Galaxy Research estimates confirmed losses at about $100 million across three attack waves, with a potential fourth wave raising the estimate to ~$130 million.
- Security debate is returning to cold storage practices, particularly how much safety comes from self-custody versus wallet design.
- Industry discussion highlights how emerging AI capabilities could lower the time and cost of vulnerability discovery—though independent validation remains limited.
- Researchers point to wallet entropy and firmware behavior as potential factors that make exploitation easier under certain conditions.
Coldcard thefts widen as investigators compare victim reports
In a Tuesday post on X, Thorn said that new victim reports enabled Galaxy to identify additional attacker activity. He framed the significance of the new reporting as both quantitative and technical: the exploit behavior differed from typical theft patterns seen in hacks against centralized exchanges, making careful attribution and investigation more dependent on detailed victim information.
Thorn wrote that even a relatively small report—less than 1 BTC stolen from a victim—was sufficient to detect a new attack pattern. He noted that this new attack involved roughly 12 BTC siphoned from 126 addresses, underscoring how the same underlying vulnerability could be used in different operational ways.
Earlier coverage of the Coldcard exploitation described multiple “waves” of activity. Galaxy Research’s current figures build on that approach by tracking confirmed incidents and assessing whether activity patterns resemble a further wave of exploitation.
Loss estimates: three confirmed waves, plus a suspected fourth
According to Galaxy Research, the total losses from the Coldcard exploit have grown to approximately $100 million across three confirmed attack waves. Thorn’s research also points to a suspected fourth wave that, if validated, would bring the potential total to about $130 million in Bitcoin.
For users and investors, the practical value of this breakdown is that it turns an incident that initially looked like a one-off event into something closer to an evolving campaign. Waves of theft imply repeated operational access—either through different attacker infrastructure, different timing, or different exploit paths that still converge on the vulnerable behavior.
Debate over “AI hardening” and whether models can rediscover exploits
The renewed attention has also reopened a broader debate: whether AI tools can meaningfully compress the time between disclosure and exploitation, and whether “AI hardening” could have prevented the attack.
Dragonfly managing partner Haseeb Qureshi argued on X that “$2 of AI hardening” could have stopped the Coldcard exploit, citing social media claims that some AI models rediscovered the underlying vulnerability in under 20 minutes. His comments referenced reports that a model named Claude could regenerate the vulnerability in eight minutes, as well as a separate claim that an open-source model (GLM 5.2) could rediscover the exploit in 20 minutes even with web access disabled.
However, Tokenomist data lead Tatsapat Saerejittima told Cointelegraph that it is unlikely AI models would have independently found the vulnerability before it became public. Saerejittima argued that the most prominent “fast rediscovery” claim appears to stem from a pseudonymous user who scanned code after the vulnerability was already known, without a blind test, a documented methodology, or an assessment of false-positive rates.
“The claim that AI found it in 2 mins came from a pseudonymous Reddit user who scanned the code after the vulnerability had already become public. There was no blind test, no documented methodology, and no assessment of the model’s false-positive rate.”
That distinction matters. If “rediscovery” is based on post-disclosure inputs, then the timeframe reflects reuse of known information rather than a model’s ability to autonomously uncover unknown vulnerabilities under real-world conditions. For wallet users, builders, and auditors, the difference affects how confidently security teams can treat AI-assisted testing as a substitute for formal review and threat modeling.
Private key setup and entropy may have made exploitation easier
Another line of analysis focuses less on AI capabilities and more on the cryptographic design and implementation details of the device’s key generation process.
Crypto research company Castle Labs co-founder Francesco said that increasing AI capabilities could reduce the cost and time needed to discover cryptocurrency vulnerabilities. He also suggested that Coldcard’s private key may have played a role in why the exploit worked.
Francesco pointed to a “level of private key entropy (40 bits) much lower than the standard adopted by other wallets (a 12-word seed is 128 bits).” He attributed this discrepancy to a firmware bug, which he said would make exploitation easier because the search space is smaller than it would be under typical seed-based entropy assumptions.
He further stated that he expects the cost of bug discovery to continue decreasing as AI models improve and become more embedded in both cybersecurity workflows and exploitation attempts. Even without relying on any single “AI rediscovery” claim, the underlying idea—that automation can accelerate identification and exploitation—aligns with the broader security trend toward faster vulnerability discovery and weaponization.
In practice, these findings shift attention to what should change next for hardware wallet security: not only whether vulnerabilities are found quickly, but how wallet firmware handles entropy, key generation, and edge cases that could alter the effective security assumptions.
As the industry digests Galaxy’s expanding attribution data and the ongoing discussion of exploit mechanics, readers should watch for whether additional theft activity continues to be classified into further waves—and, just as importantly, what technical mitigations are recommended or adopted to address the entropy or firmware conditions implicated by researchers.
-
Business6 days agoWhy Trees Belong on the Risk Register
-
Fashion4 days agoWeekend Open Thread: Wit & Wisdom
-
Politics4 days agoMeta enters AI-training agreement with far-right ‘propaganda rag’ Newsmax
-
Entertainment7 days ago‘Stargate’ Creator’s New Sci-Fi Series Returns for Season 3 Tomorrow
-
Crypto World3 days agoMicroStrategy Post-Earnings CLARITY Act Push Could Add New Catalyst for Its Stock
-
Politics6 days agoReform UK betrays West Mids residents by running from party pledges
-
Business7 days agoMajor shareholder moves on Canyon
-
Crypto World3 days agoXRP Ledger v3.3.0 brings five institutional features
-
News Videos5 days agoBitcoin Enters the 3rd Stage of the Bear Market
-
Crypto World7 days agoKraken Enables Retail Access to Jersey Mike’s IPO via Tokenized Shares
-
Politics2 days agoZack Polanski: an incitement to murder Nigel Farage?
-
Politics5 days agoLuke Littler’s dominance sparks GOAT debate
-
Sports5 days agoSeema Kaliramna Wins Discus Throw Bronze, Takes India’s CWG Medals Tally To 17
-
News Videos7 days agoClaude: Build Financial Dashboards in Minutes (2026)
-
Crypto World4 days agoNew York sues Kalshi over prediction market gambling
-
Crypto World2 days agoCrypto PAC spending tops $2M in Michigan House race
-
Business7 days agoJohnson & Johnson agrees to $5.5B settlement over talc cancer claims
-
Business4 days agoTrump Announces Hamas Disarmament Agreement as Iran Strikes Kuwait Air Base and US Attacks Pause Overnight
-
Tech6 days agoGemini can now summarize the messiest comment threads in Google Docs
-
Tech2 days agoESET tracks rise in malicious AI skills and adaptable malware

You must be logged in to post a comment Login