Crypto World
US Treasury Sanctions Two Iranian Crypto Exchanges Over IRGC Money Laundering
The US Treasury sanctioned two Iranian digital asset exchanges, Shelbit and Aban Tether, along with network operator Siavash Kayvanpour, over crypto transfers tied to Iran’s Islamic Revolutionary Guard Corps (IRGC).
The Office of Foreign Assets Control (OFAC) issued the designations on Friday. The designations mark the latest US strike on Iran’s crypto rails this year.
How The Shelbit Network Moved Crypto
IRGC crypto addresses sent more than $1 million into the Shelbit Exchange. Over $2 million then flowed from Shelbit back to Guard wallets, according to OFAC.
Kayvanpour, an Iranian-born operator, ran Shelbit from Georgia and built front companies in Poland and the UAE. His wallets sent more than $2 million to Nobitex, Iran’s largest crypto exchange, which OFAC blocked in June.
OFAC also said Shelbit laundered tens of millions for a Persian-language gambling network. Reuters earlier reported that Shelbit routed $676 million to Binance.
Follow us on X to get the latest news as it happens
Aban Tether and The Iran Sanctions Campaign
Aban Tether, a separate Iran-based exchange, processed millions in transactions with previously blocked platforms Nobitex, Wallex, Bitpin, and Ramzinex. Treasury cited Executive Order 13902, which targets firms operating in Iran’s financial sector.
“Whether in dollars, rials, or crypto, Treasury will hunt down and dismantle illicit financial networks,” Scott Bessent, Treasury Secretary, said.
The move extends the US maximum pressure campaign on Iran, carried out under National Security Presidential Memorandum 2 (NSPM-2). Stablecoin issuers have moved fast on past listings, freezing Iranian wallets after the designation.
Subscribe to our YouTube channel to watch leaders and journalists provide expert insights
The post US Treasury Sanctions Two Iranian Crypto Exchanges Over IRGC Money Laundering appeared first on BeInCrypto.
Crypto World
A Deep Dive Into One Of The Most Significant Hacks In Recent Memory
Coldcard is a Bitcoin-only hardware wallet created by Coinkite, a Toronto-based company specializing in ultra-secure self-custody hardware. The hardware wallet is marketed as a highly secure cold storage option for long-term Bitcoin users and has received plaudits from users and experts alike. However, the Coldcard exploit could change that perspective and have far-reaching implications for “self-custody,” a hill many in crypto choose to die on.
The Coldcard Exploit Timeline
Let’s get into the nitty-gritty of the exploit. On July 30, individual Bitcoin holders using Coldcard noticed that their wallets were inexplicably drained. Among them was author Jonathan Goodman, who lost $1.6 million in BTC to the exploit. Goodman’s post about the hack on X was possibly the first time the hack was discussed in the public domain. Meanwhile, blockchain intelligence firm Galaxy Research detected suspicious transaction waves in a 41-minute window, hours before Coinkite issued its first advisory regarding the exploit. Unlike most exploits, the Coldcard exploit unfolded in waves, with the number of affected wallets rising almost daily.
The vulnerability impacted several models, including the Mk2, Mk3, Mk4, Mk5, and Q. However, Coinkite products built on separate codebases, including Tapsigner, Opendime, and Satscard, were unaffected.
The first wave was detected on July 30, when a hacker or hackers began targeting Bitcoin held in Coldcard hardware wallets. The hackers drained 500 wallets in a 25-minute window during the first wave, siphoning around 594 BTC, worth around $38 million, to a new address. The numbers are staggering for such a small window, but this was just a prelude to what was to come. The first wave lasted 41 minutes and affected 1,196 wallets. As more data poured in, Galaxy Research pegged the first wave figures at 1,082.65 BTC stolen from 1,196 wallets, around 0.9 BTC from each wallet.
Galaxy Research detected two subsequent waves on July 31 and August 1, respectively. The hackers stole around 76 BTC from 1,477 wallets during the second sweep and 208 BTC from 1,912 wallets during the third sweep. A suspected fourth wave was detected on August 4, with researchers identifying an additional 600 wallets. Early estimates put losses at over $130 million, a figure that could increase as hackers continue targeting vulnerable addresses.
| Wave | Date | Wallets Affected | BTC Stolen |
| 1 | July 30 | 1,196 | 1,082.65 BTC |
| 2 | July 31 | Roughly 1,477 | 76 BTC |
| 3 | August 1 | 1,912 | 208 BTC |
| 4 (Possibly Ongoing) | Detected by August 4 | Over 600 | Figure Not Publicly Available |
A highly unusual aspect is the nature of the exploit. The BTC wasn’t stolen through an elaborate social engineering scheme or the usual phishing or exchange attacks that we usually see. It wasn’t even a supply chain compromise like the one that hit Ledger in 2023. This was a bug that sat undetected for five years, until someone, somehow, discovered it and used it to blindside Coldcard wallet users.
How Does The Coldcard Number Generator Work
Coldcard wallets generate their own randomness every time a user creates a new seed. The randomness underpins the security the wallets are known for. Any compromise to this randomness would prove disastrous, as the ongoing exploit has proved. These wallets are designed to generate and store private keys offline and are never directly connected to the internet. Instead, they communicate with the blockchain using an air-gapped environment through QR codes and MicroSD cards.
The Code That Started It All
At the heart of the exploit sits an innocuous firmware update pushed by Coldcard in March 2021. Firmware version 4.0.1 migrated Coldcard’s cryptography to libsecp256k1, the library underpinning Bitcoin Core, a sound decision by every definition of the word. However, this inadvertently moved seed generation to MicroPython’s Yasmarang PRNG, used on devices with no randomness chips.
You may be wondering why.
According to Block’s security and engineering team, the 2021 update changed how the firmware called its cryptographic library during the seed generation phase. The library misread a production build configuration flag that checks whether the hardware random number generator (RNG) was available. This event went unnoticed, and the firmware began generating “deterministic, pseudorandom seed phrases from a significantly smaller entropy pool without adding fresh entropy.”
Let me explain the preceding sentence. A hardware wallet typically uses two components: a physical randomness source embedded in the chip (TRNG) and an algorithm that uses true randomness from the TRNG to generate seed phrases (CSPRNG). Coldcard wallets use a hardware-based true random number generator built directly into its microchip. Additionally, users can add physical dice rolls to increase randomness.
When Coinkite pushed the 2021 update, the firmware reverted to a backup PRNG without alerting the user. The PRNG relied on the wallet’s UID instead of fresh entropy, making the output predictable. Here’s where the vulnerability comes in. If an attacker can determine a device’s possible UID, they could narrow down the seed phrases generated by the wallet.
So what effect did this have?
Seed phrases generated using firmware 4.0.1 looked like a standard 12- or 24-word phrase. However, the randomness of the underlying numbers was compromised, making them significantly weaker. A 12-word BIP-39 seed typically carries 128 bits of entropy. Let me put this unremarkable figure into perspective using a simple analogy. 128 bits of entropy effectively gives ~3.4 × 10³⁸ possible seeds. The age of the universe is 13.8 billion years. If a hacker tried to brute-force 128 bits of entropy at a trillion guesses per second, it would take them 800 million times the age of the universe to run through all possible combinations.
Entropy fell to 72 bits on Mk4, Mk5, and Coldcard Q devices, reducing the possible seeds to ~4.7 × 10²¹. This is well below the 128-bit threshold and exploitable by determined hackers with time and resources. It fell even lower (40 bits) on Mk2 and Mk3 devices, well within the reach of an attacker with even modest resources.
Now, you may read this and think an upgrade could fix the vulnerability. Not exactly. A firmware update fixes the problem for seeds generated after the vulnerability was patched. However, seeds generated using firmware 4.0.1 remain vulnerable. Coinkite has recommended that all users who created seed phrases using the compromised firmware generate a new seed phrase and move their funds to a new wallet.
Details And On-Chain Analysis
Galaxy Research highlighted differences in transaction construction across the attack waves, suggesting multiple threat actors instead of a single entity. A TechCrunch report cited other blockchain monitoring firms to confirm Galaxy Research’s observation, stating that Coldcard wallets were targeted by at least a dozen hackers.
Here is a breakdown of the attack waves that targeted Coldcard. However, these figures could change as analysts believe the exploit is ongoing and details of more affected wallets could emerge over time.
- Galaxy Research flagged suspicious transactions detected on July 30, identifying around 594 BTC drained from 500 single-signature wallets. The first wave lasted for 41 minutes, targeting 1,196 wallets and draining 1,082.65 BTC.
- The second wave followed the same pattern, with hackers draining 76 BTC from 1,477 wallets, taking the total to 1,158.66 BTC (~$75.1 million) from 2,673 addresses.
- The third wave targeted 1,912 wallets, draining 208 BTC and taking the total to 1,367 BTC (~$88–89 million) across over 4,500 addresses.
- The fourth wave could still be ongoing, with TRM Labs updating the figures to 1,816 BTC from over 5,200 addresses. These numbers could change as more reports come to light.
TRM Labs tracked the stolen BTC to a pool of addresses linked to the attackers. Surprisingly, the attackers have made very little attempt to move, launder, or mix the funds so far. This is likely because the attackers want to target as many vulnerable wallets as possible before worrying about laundering or mixing the stolen funds. A single deposit of 64.9 BTC on Wasabi and 200 ETH on Tornado Cash are the only laundering activity tracked so far.
This is probably why the exploit has not been attributed to groups like North Korea’s Lazarus that launder stolen funds within hours. Funnily enough, the hackers themselves are being inundated with spam messages, with one message offering to launder the stolen funds for a nominal fee.
Coinkite’s Response And Advisory
Coinkite issued several advisories as the scope of the exploit became clearer. The Coldcard manufacturer published a security advisory following the first wave. The initial advisory covered Mk3 devices and firmware 4.0.1 and 4.1.9. Coinkite released an updated advisory and firmware for Mk4/Mk5 (version 5.6.0 or later) and Coldcard Q (version 1.5.0Q or later). The advisory was updated again on August 1, confirming that the exploit had also impacted Mk2 devices. The latest advisory also narrowed the firmware impacted by the exploit and released a fixed firmware update for Mk2/Mk3 (version 4.2.0).
The update also officially recognized that seed phrases generated with at least 50 manual dice rolls contained enough randomness and were not at risk.
Coinkite has stressed that simply updating the firmware will not fix wallets that have already generated a seed. It advised users who generated a seed between March 2021 and the latest firmware update to treat their seed as compromised and move their funds to a new wallet or generate a new seed on a patched firmware.
Why Was The Coldcard Vulnerability Undetected For So Long
One of the biggest talking points of this entire episode is why nobody detected the bug, which was shipped in a firmware update in March 2021. One detail to remember is that Coldcard’s firmware is open source and publicly available. Coinkite speculated in one of its advisories that the bug may have been discovered during an AI-assisted review of the code. However, this theory is unconfirmed as of now.
The exploit adds to the ongoing conversation about hackers using AI systems to find and exploit vulnerabilities in already-reviewed code. Separately, several AI labs, including OpenAI, Anthropic, and Meta, have revealed that their models access real systems during testing. These incidents occurred due to misconfigured environments allowing the models to gain internet access, or because the AI models exploited vulnerabilities during certain tests.
Some recent examples include:
- One of OpenAI’s internal models accessed Hugging Face production infrastructure by breaking out of a test environment and exploiting a zero-day vulnerability.
- According to one report in ALMCorp, an Anthropic audit revealed some Claude models, including Opus 4.7 and Mythos 5, accessed the internet and gained unauthorized access to systems of three organizations.
- Meta’s Muse Spark AI model accessed an external company’s systems and altered internal data.
What Are The Implications For Bitcoin Self Custody
The Coldcard exploit could potentially change Bitcoin custody forever, raise questions about mass adoption, and highlight the complexities of self-custody. First, none of the affected users did anything wrong. They did not fall victim to a social engineering scam or click on a malicious link.
The incident has cast doubt on self-custody, a concept the Bitcoin and broader crypto community swears by. The exploit also reinforces the argument many have made that self-custody does not eliminate risk, it only relocates it. Some, including Taproot developer Udi Wertheimer, have argued that the community cannot assume that Bitcoin stored in cold wallets indefinitely is safe and users must remain vigilant about emerging threats.
The threat landscape has evolved as well. According to Blockaid, the majority of crypto losses this year have been attributed to key compromises and operational security features. The Coldcard exploit is an extreme example of the latter.
Moreover, the incident could push fence-sitters towards institutional and retail exposure to Bitcoin through spot Bitcoin ETFs.
However, self-custody advocates have pointed out that the exploit occurred because of a firmware bug, not a hardware flaw, arguing that self-custody is the safest way to store Bitcoin.
What Steps Can Coldcard Users Take
Coldcard users, especially those who have generated their seeds between March 2021 and Coinkite’s latest advisory, must follow the steps listed below.
- Check the Model and Firmware – If you own a Coldcard Mk2, Mk3, Mk4, Mk5, or Q and generated a seed between March 2021 and the latest update, the seed may be compromised.
- Update Firmware – Coinkite has released firmware updates for the affected devices. Mk2 and Mk3 users can update to version 4.2.0 and above. Mk4 and Mk5 users can upgrade to 5.6.0 and above, while Coldcard Q users can update to 1.5.0Q.
- Check Entropy – Coinkite’s advisory states that the seeds of users who have used the Add Dice feature and completed 50 private, independent rolls are not at risk. However, if you have used fewer than 50 rolls, or not used the Add Dice feature at all, your seed may be compromised.
- Recheck Passphrase – A BIP-39 passphrase adds another layer of security. However, users must ensure their passphrase is long, unique, and unrecorded. Shorter phrases cannot be deemed secure.
FAQs
What Caused The Coldcard Exploit
The root cause of the exploit was a bug that shipped in March 2021. The error altered how the firmware called its cryptographic library, causing it to revert to a weak software random number generator instead of relying on the Coldcard device’s source of entropy. This led to the key strength falling from the standard 128 bits to as low as 40 bits on some devices, making them susceptible to brute-force attacks.
Will Updating The Firmware Protect The Wallet From The Exploit
This is where things could get tricky for users. It is generally assumed that if the firmware has a bug, it can be updated to fix that bug. However, in Coldcard’s case, it’s only partially correct. A firmware update fixes the RNG issue moving forward, but does not retroactively fix seeds generated on the vulnerable software. Users should treat seeds generated between March 2021 and Coinkite’s latest update as compromised and move their funds after generating a new seed on an updated device.
Does The Hacker Need Physical Access To Exploit The Vulnerability
No, hackers can use brute-force attacks without needing access to the actual device.
Did The Exploit Impact Tapsigner, Satscard, Or Opendime Devices
No, these devices run on separate codebases and were not impacted by the exploit, which is limited to Mk2, Mk3, Mk4, Mk5, and Coldcard Q devices.
Has Anyone Claimed Responsibility For The Attack
No single entity has claimed responsibility for the exploit. Blockchain analysis revealed differences between transaction patterns, suggesting the involvement of multiple threat actors exploiting the same vulnerability.
Is My Coldcard Wallet Compromised
The Coldcard wallet is not compromised, and a firmware update fixes the vulnerability for new seeds. However, seeds generated between March 2021 and Coinkite’s latest update are vulnerable.
Crypto World
XRP ETF Inflows Have Collapsed 79% Since May as the CLARITY Act Stalls, Is $1 About to Break?
In the latest XRP News, Ripple XRP traded near $1.03 after a 1.24% 24-hour decline, leaving the token testing its psychologically critical $1 support zone as legislative momentum in Washington grinds to a halt.
The U.S. Senate’s decision to move consideration of the Digital Asset Market CLARITY Act past its August 7 recess leaves September 14 as the earliest plausible window for floor action rather than a confirmed voting date.
That delay deprives the market of a near-term catalyst and forces institutional buyers to evaluate whether regulatory clarity can materialize before the 2026 midterm election cycle takes over Congress.
The legislative setback highlights a persistent gap between regulatory expectation and legislative execution in crypto regulation.
While agency-level interpretations have acknowledged the token’s commodity treatment, asset managers and corporate balance sheets continue to delay large-scale commitments until Congress embeds those definitions directly into federal statute.
Discover: Everyone’s Got a Take. Get Free $25 to Actually Trade Yours
Senate Vote Timelines and Legislative Bottlenecks
The CLARITY Act cleared the House in July 2025 by a 294-134 vote and passed the Senate Banking Committee 15-9 in May 2026, landing on the Senate floor calendar on June 1.
Senate Majority Leader John Thune has yet to grant the bill floor time, choosing instead to prioritize executive nominations and a foreign sanctions package.

With Republicans commanding 53 seats, leadership requires at least seven Democratic crossover votes to reach the 60-vote threshold needed to invoke cloture and clear procedural filibusters.
Democratic resistance centers on two main policy disputes. Commercial banks have aggressively lobbied against stablecoin provisions that allow crypto exchanges to pay yield on holdings, warning that yield-bearing stablecoins threaten traditional bank deposits.
Meanwhile, senior lawmakers have insisted on tighter ethics restrictions barring executive officials from participating in private crypto projects-a provision whose latest iteration was transmitted to the White House on July 30.
Senator Cynthia Lummis acknowledged the bipartisan friction, noting that even Republican support faces hurdles with key members remaining “really resistant” to passing the market-structure framework without broader concessions.
Because the Senate leaves for its state work period from August 10 through September 11, the bill cannot proceed without a cloture motion filed before the break.
Without that procedural filing, the legislation must compete for limited calendar space alongside imperative government funding debates when lawmakers return on September 14.
Furthermore, because the Senate draft differs from the House version, both chambers would still need to reconcile and pass identical text within a tight September window before lawmakers adjourn again for October campaign recourses.
Discover: Your Market Calls Are Worth Something. Start With Free $25 on Kalshi
XRP News: Institutional Inflows Stall as Odds Compress
The market impact of legislative stagnation is clearly visible across institutional investment flows. U.S. spot XRP ETFs took in $131.94 million in May during the peak of Senate committee momentum, but monthly net inflows contracted sharply to $59.46 million in June and just $27.29 million in July.

Institutional allocators appear unwilling to scale up positions while legal status rests on revocable regulatory interpretations rather than statutory law.
Prediction markets have aggressively re-priced the bill’s legislative prospects. Traders on Kalshi dropped the probability of the CLARITY Act becoming law in 2026 to approximately 17%, down sharply from an 82% high in February.
Discover: Get Paid to Be Right, $25 to Start on Kalshi
Don’t Miss Out on Our $1,000 USDT Airdrop on ByBit
The post XRP ETF Inflows Have Collapsed 79% Since May as the CLARITY Act Stalls, Is $1 About to Break? appeared first on Cryptonews.
Crypto World
XRP Ledger privacy vote targets $530M RWA market
XRP Ledger validators will vote on a privacy amendment designed for institutional transfers as the network hosts more than $530 million in distributed tokenized assets outside RLUSD.
Summary
- Confidential Transfers would encrypt MPT balances and payment amounts while keeping accounts and token types visible.
- XRPL hosts about $1.38 billion in distributed assets, including $845.7 million of RLUSD.
- The first version supports direct MPT payments only, excluding exchange trades, escrow and checks.
- Activation requires 80% validator support for two consecutive weeks.
XRP Ledger privacy amendment enters validator process
XRP Ledger version 3.3.0, released on Aug. 6, includes six proposed amendments focused largely on institutional asset issuance and settlement.
Confidential Transfers is the most privacy-focused proposal. It would allow users to encrypt balances and payment amounts attached to Multi-Purpose Tokens, or MPTs, which XRPL designed for assets such as tokenized funds, bonds and other financial instruments.
Accounts involved in a payment and the type of asset being transferred would remain visible. However, outside observers would not be able to see the value held by each account or the amount sent in an individual transaction.
The ledger would use cryptographic proofs to confirm that a transaction is valid and that balances remain consistent without publicly revealing the underlying figures. That structure targets institutions that need transaction confidentiality while operating on a shared ledger.
None of the amendments became active with the software release. XRPL validators must approve each proposal separately before it can become part of the network.
Privacy feature targets growing XRPL RWA market
RWA.xyz data tracks about $1.38 billion in distributed real-world assets on the XRP Ledger. Ripple’s RLUSD stablecoin accounts for approximately $845.7 million of that amount.
Removing RLUSD leaves more than $530 million in other distributed tokenized assets that could potentially use the privacy feature. Ondo Finance accounts for about $212.6 million, followed by VERT Capital at $116.1 million and Archax at $55.4 million. Societe Generale represents another $11.6 million.
The market remains concentrated among several large issuers, but recent launches show that XRPL is moving beyond pilot programs.
As crypto.news previously reported, Aviva Investors launched a tokenized share class of its U.S. Dollar Liquidity Fund on XRPL on July 29. The regulated product uses blockchain records while BNY Mellon continues to hold the underlying assets.
Ripple has also invested in ZILO and Licuido to expand fund administration, token issuance, secondary trading and collateral tools built around the ledger.
Confidential Transfers remain limited at launch
Confidential Transfers would initially apply only to direct MPT payments between accounts. Holders must opt into the encrypted format before using it.
The first version would not support transactions conducted through XRPL’s built-in decentralized exchange. It would also exclude escrow arrangements and checks, limiting its immediate usefulness for more complicated institutional workflows.
Version 3.3.0 includes other amendments that could address some of those workflows. Batch would let users package up to eight transactions together, including an atomic mode in which every transaction succeeds or the entire group fails.
Sponsor would allow one account to cover another account’s transaction fees and reserve requirements. This could let institutions onboard users without requiring each participant to obtain XRP before making a transaction.
Permission Delegation would allow an account to authorize another party to submit only specified transaction types. Dynamic MPT, meanwhile, would let issuers modify certain token properties after issuance.
US Treasury settlement provides institutional test case
The privacy proposal could be relevant to U.S.-linked tokenized securities already using XRPL. In May, JPMorgan, Mastercard, Ripple and Ondo tested the redemption of a tokenized U.S. Treasury fund.
Ondo’s OUSG moved over XRPL while JPMorgan’s Kinexys network handled the corresponding dollar settlement. The asset leg reportedly cleared in under five seconds.
The test showed how regulated financial institutions could connect blockchain-based assets with established banking systems. Confidential Transfers would add an option to shield position sizes during similar direct transfers, although its initial limitations mean it would not cover every stage of issuance, trading or redemption.
Each XRPL amendment requires support from at least 80% of trusted validators for two continuous weeks. The next test is therefore whether Confidential Transfers clears that threshold—and whether institutions already issuing assets on XRPL choose to use it once available.
Crypto World
EU to revise MiCA rules in 2027 amid US stablecoin push
European Union officials are preparing to revise the bloc’s MiCA crypto framework in 2027 as foreign stablecoin restrictions and faster U.S. rulemaking expose gaps in the existing regime.
Summary
- EU diplomats reportedly expect MiCA revisions in 2027, despite an ongoing European Commission consultation.
- Changes could address rules that have left non-EU stablecoins such as USDT without authorization.
- The review may expand MiCA to cover tokenized deposits, payments and other real-world assets.
- U.S. adoption of the GENIUS Act has added pressure on Europe to reassess its approach.
EU officials reportedly see MiCA revision as unavoidable
European diplomats said policymakers are expected to reopen the Markets in Crypto-Assets Regulation in 2027, according to a Euronews report.
The planned revision would examine how MiCA treats stablecoins issued outside the European Union. Current requirements have prevented several foreign issuers from receiving authorization, limiting their access to regulated exchanges across the bloc.
“Reopening the file seems unavoidable at this stage,” an unidentified European diplomat told Euronews.
The diplomat cited positions taken by European institutions, including the European Central Bank, along with changes in global regulation and digital-asset technology.
No final proposal has been published. Any amendment would need to pass through the EU’s legislative process before taking effect.
MiCA consultation could shape the 2027 proposal
The European Commission opened a targeted MiCA consultation on May 20 to determine whether the framework remains fit for purpose following its initial implementation.
The consultation covers developments that have occurred since MiCA entered into application. Its deadline has been extended to Sept. 30, with crypto issuers, service providers, regulators, central banks and finance ministries invited to respond.
The Commission said the feedback would support a report required under Articles 140 and 142 of MiCA. That report could be accompanied by legislation to amend or expand the regulation if officials conclude that changes are warranted.
Crypto.news previously reported that the review could examine stablecoin issuance, decentralized finance, tokenized assets and cross-border supervision.
Tether exclusion exposes stablecoin licensing gap
MiCA’s final transition period for crypto-asset service providers ended on July 1, forcing covered companies to obtain authorization or stop providing regulated services.
The change left Tether’s USDT without a compliant route onto regulated EU exchanges because the issuer did not seek authorization. Coinbase, Kraken and Crypto.com were among the platforms that removed USDT trading for European customers, according to crypto.news.
Tether CEO Paolo Ardoino has criticized MiCA’s reserve requirements, particularly rules requiring stablecoin issuers to hold a large portion of their reserves in European bank deposits.
Circle took a different approach by securing authorization for USDC and EURC. Stripe-owned Bridge also recently joined the MiCA register, raising the number of authorized electronic-money-token issuers to 42. The bloc had also registered 324 authorized crypto-asset service providers.
A revision could create a route for foreign issuers while preserving EU reserve, disclosure and consumer-protection requirements.
US stablecoin rules add pressure on Europe
The reported review comes as the United States advances its stablecoin framework under the GENIUS Act, signed into law in July 2025.
The law established federal requirements for payment-stablecoin reserves, redemptions, disclosures and supervision. Although U.S. agencies missed a one-year deadline to finalize several implementing rules, the framework has already given issuers and financial institutions a federal structure for entering the sector.
European officials are also considering whether MiCA should cover newer forms of tokenization. Possible additions include tokenized deposits, payment instruments and real-world assets that fall outside or sit between existing regulatory categories.
MiCA was approved by the Council of the EU in May 2023. A 2027 revision would allow policymakers to update rules based on several years of implementation, market changes and competition from the expanding U.S. stablecoin sector.
Crypto World
Morgan Stanley ETF buys $15M Bitcoin during dip
Morgan Stanley’s spot Bitcoin ETF added approximately 232.5 BTC worth $15.05 million as Bitcoin traded below $65,000, lifting the fund’s holdings above 6,500 BTC for the first time.
Summary
- MSBT added 232.5 BTC, valued at approximately $15.05 million, according to Arkham.
- The fund’s holdings increased to 6,563 BTC worth more than $426 million.
- BlackRock, Fidelity and Franklin Templeton also accumulated Bitcoin during the recent market weakness.
- MSBT launched in April with a 0.14% annual management fee.
Morgan Stanley’s Bitcoin ETF adds 232 BTC
Blockchain intelligence platform Arkham reported that the Morgan Stanley Bitcoin Trust increased its holdings by approximately 232.548 BTC as Bitcoin remained under pressure near $65,000.
The purchase was valued at $15.05 million, implying an average price of around $64,718 per Bitcoin. It raised the fund’s total holdings to 6,563 BTC, worth more than $426 million at current market prices.
The transaction marked the first time MSBT’s Bitcoin balance exceeded 6,500 BTC. It also expanded the fund’s holdings during a period when Bitcoin traded below the average purchase price of many recent buyers.
CryptoQuant analyst Axel Adler Jr. said Bitcoin was trading below the realized price of short-term holders, referring to coins held for less than 155 days. Bitcoin traded around $64,952 on Aug. 8, while the short-term holder realized price stood at $67,523.
This left the spot price approximately 3.8% below the cost basis, creating potential selling pressure from recent holders seeking to exit around break-even.
Other Bitcoin ETFs also bought during the dip
Morgan Stanley was not the only major financial institution whose Bitcoin ETF added assets during the latest decline.
Arkham reported on Aug. 4 that BlackRock’s spot Bitcoin ETF bought approximately $111 million worth of BTC during the previous trading session. Fidelity added about $33 million, while Franklin Templeton purchased approximately $9 million.
The three funds accumulated around $153 million in Bitcoin combined. Arkham said none of the tracked ETFs sold Bitcoin that day and that the funds had recorded no Bitcoin sales during the opening sessions of August.
These figures refer to Bitcoin entering wallets associated with the ETFs. Such additions generally reflect investor inflows and the creation of new fund shares rather than purchases made for the asset managers’ corporate balance sheets.
The renewed accumulation followed a difficult period for U.S. spot Bitcoin ETFs. Crypto.news previously reported that the products recorded $265 million in net outflows as Bitcoin tested $63,000 on Aug. 1.
MSBT assets rise from July level
Morgan Stanley launched MSBT on April 8, becoming the first major U.S. commercial bank to issue a spot Bitcoin ETF under its own name.
Crypto.news previously reported that the fund launched with a 0.14% annual management fee. That undercut the 0.25% fees charged by BlackRock’s IBIT and Fidelity’s FBTC, while coming in one basis point below the Grayscale Bitcoin Mini Trust.
MSBT attracted $103 million in cumulative net inflows within eight days of its launch, overtaking WisdomTree’s Bitcoin Fund at the time. The rapid increase pointed to early demand from investors seeking Bitcoin exposure through Morgan Stanley’s investment platform.
The fund held approximately $392 million in net assets as of July 24, according to another crypto.news report citing Morgan Stanley’s product page. Arkham’s latest estimate of more than $426 million suggests its holdings have since expanded by approximately $34 million, though part of that difference may reflect changes in Bitcoin’s market price.
Bitcoin remains below a key holder cost level
Bitcoin’s inability to reclaim the short-term holder realized price leaves $67,523 as an important near-term level. A recovery above that area could reduce pressure on recent buyers currently holding unrealized losses.
Continued ETF purchases may help absorb Bitcoin entering the market, but the latest additions do not confirm that the broader outflow trend has reversed. Daily net-flow data will determine whether Morgan Stanley’s purchase forms part of a sustained return in institutional demand.
Failure to hold the $64,000 area could expose Bitcoin to another test of its recent lows. A move above $67,500, however, would return the asset above the average cost basis of short-term holders and improve its near-term structure.
Crypto World
Bitcoin Payment Tool BTCPay Urges Update After Attackers Steal Funds
BTCPay Server confirmed that attackers exploited a critical flaw to steal funds from users running any version prior to 2.4.2 and urged operators to update immediately.
The self-hosted Bitcoin payment processor released version 2.4.2 to close the vulnerability. The issue allowed an unauthenticated remote attacker to obtain .macaroon credential files for LND, a common Lightning Network implementation.
What BTCPay Server Users Must Do
The stolen credentials could hand an attacker full control of an LND node. From there, the attacker could move funds directly out of the node.
“We have confirmed that attackers exploited this vulnerability. Users were affected and funds were stolen. We are not publishing technical details yet because operators still need time to update,” the team said.
Follow us on X to get the latest news as it happens
The risk applies specifically to deployments using LND. Other Lightning setups and non-Lightning users face no credential exposure, though the project still urged them to update. BTCPay Server’s own on-chain and hot wallets remain unaffected.
Operators who use LND should update to version 2.4.2 and LND 0.21.1 through the maintenance dashboard. The update regenerates macaroons automatically. Those unable to patch immediately were told to take their servers offline.
The project also advised LND users to review node activity for unfamiliar peers, unexpected channel closures, and payments they did not make.
A Second Blow to Bitcoin Self-Custody
The disclosure follows another major security incident. Galaxy Research confirmed on Friday that 1,719 Bitcoin (BTC), worth roughly $111 million, has been stolen from Coldcard users so far. The firm expects total losses to exceed $130 million once outstanding cases are verified.
Neither incident touched the Bitcoin protocol itself. Both instead exposed weaknesses in the tools built around it.
Subscribe to our YouTube channel to watch leaders and journalists provide expert insights
The post Bitcoin Payment Tool BTCPay Urges Update After Attackers Steal Funds appeared first on BeInCrypto.
Crypto World
Pi Network’s PI Reclaims Key Support, Bitcoin (BTC) Fights for $65K: Weekend Watch
Bitcoin’s price jumped to $65,400 on Friday after the weaker-than-expected US jobs report, but it has lost some traction and has remained sideways at around $65,000.
Most larger-cap alts are slightly in the green, aside from HYPE and CRO. The latter has slumped hard after the Trump Media group canceled its partnerships with the company behind it.
BTC Eyes $65K
Last weekend was quite eventful for the primary cryptocurrency and the overall macro scene. BTC had plunged to $62,400 on Friday, tried to rebound to $63,000 on Saturday, but dipped to $62,200 later that evening. It jumped to $63,800 on Sunday after US President Donald Trump called off the scheduled attacks against Iran and raised hopes for an upcoming deal.
However, bitcoin dipped once again to $62,200 on Monday morning before it went on the offensive and spiked to $64,000 within hours. It continued to climb gradually in the following days and tapped $65,000 on Wednesday as the markets expected the deal between the US and Iran to be announced.
It turned out to be false hopes once again, and BTC slipped toward $64,000 on Friday morning after voting on the CLARITY Act was delayed again. Nevertheless, the weak US jobs report led to an immediate spike to $65,400 as the odds for a rate hike in September declined. Nevertheless, BTC was stopped there and now sits at around $65,000.

CRO Tumbles, BEAT Rockets
The big news from the past 24 hours within the industry is the decision by Trump Media, the company behind Truth Social, to cancel its partnership with Crypto.com. The effects were immediate for the latter’s native token, which tumbled by over 12% to a multi-year low of well under $0.05.
HYPE is down by over 3% daily, while ADA has dipped below $0.20 after its recent rally. In contrast, XMR has gained 3%, while DOGE, SOL, ETH, and BNB have marked insignificant gains. BEAT has skyrocketed by over 18% daily as its volatile ride continues.
Pi Network’s native token has jumped by 5% once again and sits above the key resistance at $0.09. Moreover, community sentiment remains bullish.
The total crypto market cap continues to be around $2.3 trillion, with little to no movement on a 24-hour scale.

The post Pi Network’s PI Reclaims Key Support, Bitcoin (BTC) Fights for $65K: Weekend Watch appeared first on CryptoPotato.
Crypto World
Ethereum Price Prediction: Ethereum Is Locked in a Tight Range With Heavy Volume Underneath, Which Way Does It Break?
In the latest Ethereum price prediction, ETH is currently hovering at $1,903.44 following a slight 24-hour decline of 0.19%, reflecting a market locked in tight consolidation.
Spot volume across primary venues remains heavy at roughly $7.2B to $8.7B per day, signaling that liquidity has not vanished despite choppy price action.
Traders face a fragmented spot market where live feeds show wide-ranging discrepancies across trading desks, a hallmark of transitional accumulation zones.
The recent price movement comes amid mixed signals across the time-frame charts. While TradingView charts highlight recent weekly downside pressure, short-term order books show aggressive defense near key liquidity pockets.
Will institutional flows push ETH clear of its immediate range, or is a deeper retest required before momentum restores? The technical structure points to an impending range breakout, with spot flows clustering tightly around primary moving averages.
Discover: Everyone’s Got a Take. Get Free $25 to Actually Trade Yours
Ethereum Price Prediction: Can Ethereum Price Reclaim Key Levels This Week?
Ethereum’s immediate technical structure is a balanced fight between range buyers and overhead supply.
Price action near $1,903.44 keeps ETH situated squarely between key structural floors and major liquidity targets. On-chain metrics show strong order book density in the $1,713 to $1,740 zone, establishing this region as critical lower-bound support.
A break beneath this band invalidates short-term bullish structures and risks exposing lower macro liquidity levels.

To the upside, immediate resistance forms around $1,950, followed by structural overhead near $2,000. Institutional interest remains a core variable. Sustained spot buying is necessary to clear the overhead supply blocks stacked above current price.
Should spot buyers absorb existing order book supply, an expansion toward $2,100 becomes the primary path of least resistance. If resistance holds firm instead, ETH likely persists in sideways range consolidation.
Volatility expansion usually follows prolonged periods of tight trading channels. This one has been tightening for a while.
Discover: Your Market Calls Are Worth Something. Start With Free $25 on Kalshi
Maxi Doge Targets Early Mover Upside as Ethereum Consolidates
For traders seeking explosive upside, large-cap consolidation often prompts capital rotation into high-beta opportunities.
While Ethereum offers structural stability, its multi-billion-dollar market cap inherently caps short-term multiplying potential for active traders targeting aggressive multiples.
This setup has directed speculative liquidity toward early-stage projects offering asymmetric risk profiles.
One emerging target catching trader attention is Maxi Doge ($MAXI), an ERC-20 token built around high-leverage trading culture and community competitions.
The project features a 240-lb canine persona designed to embody intense trading energy alongside a dedicated Maxi Fund treasury for liquidity and ecosystem growth. The presale has already raised $4,838,212.39 at a current token price of $0.0002832, featuring dynamic APY APY staking rewards for early participants.
Recent reports on community demand driving early presales underscore the momentum behind these viral trading ecosystems. However, early-stage micro-caps carry distinct illiquidity and execution risks that demand strict position sizing.
Serious market participants can Research Maxi Doge before the next price tier opens.
Discover: Get Paid to Be Right, $25 to Start on Kalshi
Don’t Miss Out on Our $1,000 USDT Airdrop on ByBit
The post Ethereum Price Prediction: Ethereum Is Locked in a Tight Range With Heavy Volume Underneath, Which Way Does It Break? appeared first on Cryptonews.
Crypto World
Elon Musk Grok AI Predicts XRP Could Be Gearing Up for Something Big
Legislation, not hype, sits at the center of this call. Grok AI predicts XRP climbs from $1.03 to a range of $2.80 to $5 by the end of 2026, and the price prediction stretches to $8 if ETF flows scale far enough.
CLARITY Act passage is the trigger. It would codify commodity status under the CFTC, following the 2025 SEC case closure and joint SEC and CFTC guidance in March 2026.
That combination unlocks deeper U.S. institutional access. Grok treats it as the gate that everything else waits behind.
Spot XRP ETF inflows are the second driver. Cumulative flows have been near $1.5B since launch in late 2025, with room to reach the multi-billion level.

RLUSD adds another layer at roughly $1.6B market cap and dominant on the XRP Ledger. Rising ODL corridor volumes and bank partnerships turn that into real cross-border utility.
XRPL RWA tokenization and network upgrades expand demand further. Potential rate cuts and altseason supply the macro tailwind.
The bear case is described as slight. CLARITY stalling would remove the regulatory catalyst entirely.
Muted ETF flows or a macro risk-off shock would do similar damage. XRP would then range between $0.80 and $1.50.
Discover: Everyone’s Got a Take. Get Free $25 to Actually Trade Yours
XRP Price Prediction: When A Bill In Washington Decides What XRP Is Worth
The daily chart offers no encouragement yet. XRP traded near $3.00 last October and has fallen through every level since.
February broke the $1.80 shelf hard, dropping price toward $1.15. Spring built a consolidation between $1.30 and $1.55 that looked stable. June ended that. Price slid through $1.20 and never reclaimed it.
July and August have brought continued grinding lower. The chart shows lower highs stacked without a single meaningful reversal attempt.
The close reads $1.03501, up 0.10% and $0.00105 on the day. The session ranged from $1.01432 to $1.03855. Support sits at $1.01 and then $1.00 as the psychological floor. Resistance appears at $1.10, then $1.20 and $1.30.
RSI reads 37.44 with its signal line above at 43.35. The oscillator trails by roughly 6 points, which confirms sellers still hold control.
That reading approaches oversold without reaching it. Momentum is weak and pointed down.
Grok’s floor scenario begins at $0.80, not far below this. The market appears to be pricing legislative failure rather than passage.
Discover: Your Market Calls Are Worth Something. Start With Free $25 on Kalshi
Everyone’s got a Predicts Even Grok AI, Yours Can Carry a Price And Make You Money.
Reading the chart is free. Backing the call costs something, which is exactly why the odds on Kalshi tend to move before the headlines do.
It’s a CFTC-regulated exchange for event contracts: the Fed, inflation, crypto price levels, resolved against a defined source. Being right on a slow timeline still loses if the contract expires first, so mind the dates.
→ Get up to $25 to trade your first market on Kalshi
Don’t Miss Out on Our $1,000 USDT Airdrop on ByBit
The post Elon Musk Grok AI Predicts XRP Could Be Gearing Up for Something Big appeared first on Cryptonews.
Crypto World
What Loss Teaches Us About Living
I suspect my body was conserving energy for what came next. But at the time it didn’t feel like bracing. It felt strangely like presence, the kind I attempt but often fail to manufacture for myself. Perhaps, before death showed up, I had been striving too hard, with meditation or with yoga, racing into class, always a little late, hoping to find peace while knowing the parking meter outside had run out.
It turns out presence isn’t something you achieve. It’s what’s left when everything else falls away.
Lexi, the young ICU nurse, helped me get there.. Alone with Harry at his bedside, I interrupted her quiet, steady focus on the monitors and asked her, “How do you do this work, day in and day out?” It’s a question ICU nurses get all the time from people who aren’t in health care. But I know what it’s like to shepherd families through loss. I wanted her to know I saw her—just like she saw me. She paused and shifted her gaze from the machines to me and said, “I try not to get too attached. But sometimes it feels impossible.” Our eyes locked and I knew she understood my pain.
-
Politics6 days agoZack Polanski: an incitement to murder Nigel Farage?
-
Crypto World7 days agoMicroStrategy Post-Earnings CLARITY Act Push Could Add New Catalyst for Its Stock
-
Crypto World6 days agoCrypto PAC spending tops $2M in Michigan House race
-
Business5 days agoDTCR: Deleveraging And A Hedge Fund Collapse Point To A Possible AI Bottom
-
Fashion23 hours agoFrugal Friday’s Workwear Report: Cap-Sleeve Pointelle Crewneck Sweater
-
Tech6 days agoESET tracks rise in malicious AI skills and adaptable malware
-
Crypto World6 days agoXRP Ledger urges node upgrade after manifest flood
-
Fashion18 hours agoWeekend Open Thread: Mattifying Sunscreen
-
News Videos7 days agoFinancial Crash Expert: The 90-Day Collapse Timeline They Are Desperately Hiding.
-
Sports2 days agoJordan Coyle & Cordiamo take Laya Arena Stakes at RDS
-
Crypto World5 days agoUS Tech Stocks See Largest 5-Week Inflow in History: Can Nasdaq Break Its Downtrend?
-
NewsBeat6 days agoTourist plane on sightseeing flight in Peru crashes into a field, killing all 13 people on board
-
Tech6 days agoPage Not Found | WIRED
-
Business3 days agoUS stocks: Dow closes at record on Mideast optimism; SpaceX, AMD drag Nasdaq
-
NewsBeat7 days agoArsenal reach full agreement with Newcastle over Bruno Guimaraes transfer | Football
-
Politics2 days agoReform UK And Greens Sink To Lowest Favourability Ratings To Date
-
NewsBeat7 days agoBikini-clad Jennifer Aniston, 57, kisses hypnotist boyfriend Jim Curtis as they enjoy a romantic getaway aboard a luxury yacht in Spain
-
Business4 days agoNvidia Stock Climbs 2.5% as Chip Sector Rally Builds Ahead of AMD Earnings, Nvidia’s Own Report Looms
-
Crypto World4 days agoPolymarket targets $20 billion valuation as competition heats up in prediction market sector
-
NewsBeat7 days agoMICHAEL GOVE: Burnham’s Labour doesn’t believe in aspiration, just the soft bigotry of low expectations. From education to home ownership, their message to the working class is… know your place

President Trump says, “I don’t want to see China take over crypto.”
You must be logged in to post a comment Login