Connect with us

Crypto World

XRP Ledger privacy vote targets $530M RWA market

Published

on

XRPL lending protocol enters key validator voting phase

XRP Ledger validators will vote on a privacy amendment designed for institutional transfers as the network hosts more than $530 million in distributed tokenized assets outside RLUSD.

Summary

  • Confidential Transfers would encrypt MPT balances and payment amounts while keeping accounts and token types visible.
  • XRPL hosts about $1.38 billion in distributed assets, including $845.7 million of RLUSD.
  • The first version supports direct MPT payments only, excluding exchange trades, escrow and checks.
  • Activation requires 80% validator support for two consecutive weeks.

XRP Ledger privacy amendment enters validator process

XRP Ledger version 3.3.0, released on Aug. 6, includes six proposed amendments focused largely on institutional asset issuance and settlement.

Confidential Transfers is the most privacy-focused proposal. It would allow users to encrypt balances and payment amounts attached to Multi-Purpose Tokens, or MPTs, which XRPL designed for assets such as tokenized funds, bonds and other financial instruments.

Advertisement

Accounts involved in a payment and the type of asset being transferred would remain visible. However, outside observers would not be able to see the value held by each account or the amount sent in an individual transaction.

The ledger would use cryptographic proofs to confirm that a transaction is valid and that balances remain consistent without publicly revealing the underlying figures. That structure targets institutions that need transaction confidentiality while operating on a shared ledger.

None of the amendments became active with the software release. XRPL validators must approve each proposal separately before it can become part of the network.

Advertisement

Privacy feature targets growing XRPL RWA market

RWA.xyz data tracks about $1.38 billion in distributed real-world assets on the XRP Ledger. Ripple’s RLUSD stablecoin accounts for approximately $845.7 million of that amount.

Removing RLUSD leaves more than $530 million in other distributed tokenized assets that could potentially use the privacy feature. Ondo Finance accounts for about $212.6 million, followed by VERT Capital at $116.1 million and Archax at $55.4 million. Societe Generale represents another $11.6 million.

The market remains concentrated among several large issuers, but recent launches show that XRPL is moving beyond pilot programs.

As crypto.news previously reported, Aviva Investors launched a tokenized share class of its U.S. Dollar Liquidity Fund on XRPL on July 29. The regulated product uses blockchain records while BNY Mellon continues to hold the underlying assets.

Advertisement

Ripple has also invested in ZILO and Licuido to expand fund administration, token issuance, secondary trading and collateral tools built around the ledger.

Confidential Transfers remain limited at launch

Confidential Transfers would initially apply only to direct MPT payments between accounts. Holders must opt into the encrypted format before using it.

The first version would not support transactions conducted through XRPL’s built-in decentralized exchange. It would also exclude escrow arrangements and checks, limiting its immediate usefulness for more complicated institutional workflows.

Version 3.3.0 includes other amendments that could address some of those workflows. Batch would let users package up to eight transactions together, including an atomic mode in which every transaction succeeds or the entire group fails.

Advertisement

Sponsor would allow one account to cover another account’s transaction fees and reserve requirements. This could let institutions onboard users without requiring each participant to obtain XRP before making a transaction.

Permission Delegation would allow an account to authorize another party to submit only specified transaction types. Dynamic MPT, meanwhile, would let issuers modify certain token properties after issuance.

US Treasury settlement provides institutional test case

The privacy proposal could be relevant to U.S.-linked tokenized securities already using XRPL. In May, JPMorgan, Mastercard, Ripple and Ondo tested the redemption of a tokenized U.S. Treasury fund.

Ondo’s OUSG moved over XRPL while JPMorgan’s Kinexys network handled the corresponding dollar settlement. The asset leg reportedly cleared in under five seconds.

Advertisement

The test showed how regulated financial institutions could connect blockchain-based assets with established banking systems. Confidential Transfers would add an option to shield position sizes during similar direct transfers, although its initial limitations mean it would not cover every stage of issuance, trading or redemption.

Each XRPL amendment requires support from at least 80% of trusted validators for two continuous weeks. The next test is therefore whether Confidential Transfers clears that threshold—and whether institutions already issuing assets on XRPL choose to use it once available.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

Bitcoin BIP-110 fork could expose holders to replay attacks

Published

on

Bitcoin policy group joins U.S. State Department freedom tech push

Bitcoin holders could lose real BTC if they try to sell coins created by a potential BIP-110 chain split without first separating their balances.

Summary

  • BIP-110 nodes will reject non-signaling blocks beginning at Bitcoin block 961,632.
  • A minority chain could emerge without built-in replay protection if miners continue producing compatible blocks.
  • Transactions selling forked coins could also move the holder’s real BTC on the main chain.
  • Miner signaling stood near 2.6% on Friday, far below the proposal’s 55% threshold.

BIP-110 fork could put real Bitcoin at risk

Bitcoin developer Kevin Loaec warned holders against moving coins following a possible BIP-110 chain split, citing the risk of replay attacks.

A split would create two transaction histories with the same balances at the point of separation. Anyone holding 10 BTC before the fork, for example, would initially control 10 coins on each resulting chain.

This second balance may appear to offer free money if a buyer offers to purchase the BIP-110 coins. However, both networks could initially recognize the same signed transaction.

A buyer could copy the transaction used to transfer the forked coins and broadcast it on the main Bitcoin network. If accepted, the seller would transfer the same amount of real BTC to the buyer’s address.

Advertisement

The attack would not give the buyer access to the holder’s entire wallet. Only the inputs included in the signed transaction would move, while transaction fees could be charged on both chains.

Loaec said large holders may be targeted first because a successful replay involving their wallets would produce a larger return. Holders who do not know how to separate the balances can avoid that risk by leaving their coins unmoved, as there would be no signed transaction to replay.

Why Bitcoin could split at block 961,632

BIP-110, formally called the Reduced Data Temporary Softfork, seeks to restrict images, text and other non-payment data stored through Bitcoin transactions for about one year.

Miners can activate the proposal early by signaling support in 1,109 of a 2,016-block difficulty period, equal to 55% of blocks. That threshold has not been reached.

Advertisement

The proposal also contains a mandatory signaling mechanism. From block 961,632 through block 963,647, nodes enforcing BIP-110 will reject any block that does not signal support through bit 4. Lock-in would occur no later than block 963,648, with the new data restrictions becoming active at block 965,664.

Most miners are not signaling for the proposal. The BIP-110 tracker showed support near 2.6% on Friday, making it possible that enforcing nodes reject the chain supported by most Bitcoin mining power.

A second chain would emerge only if miners continue extending the BIP-110 branch. Without enough mining power, that branch could produce blocks slowly or stop advancing entirely. The split is therefore possible, but not guaranteed.

Replay protection remains absent during the split

BIP-110 does not automatically make transactions valid on one branch and invalid on the other. Its restrictions on transaction data are not scheduled to activate until block 965,664, expected around the beginning of September.

Advertisement

Until the chains produce coins unique to their respective histories, ordinary transactions may remain valid on both. Users would need to “split” their coins by obtaining and spending outputs that exist on only one branch before transacting safely.

Wallet providers or exchanges could eventually create tools to handle that process. However, users who attempt to sell forked coins immediately may have no clear way to confirm that the transaction cannot be replayed.

US holders could also face tax and record-keeping questions if the minority-chain coins acquire a market value. The immediate concern, however, is technical: spending the new asset could unintentionally transfer an equivalent amount of BTC.

BIP-110 opposition grows before signaling window

crypto.news previously reported that Blockstream co-founder Adam Back and Strategy founder Michael Saylor opposed BIP-110, citing censorship and chain-split concerns.

Advertisement

Saylor described the proposal as a consensus change arising from a dispute over spam and warned that it would establish a dangerous precedent. Bitcoin developer Luke Dashjr has continued supporting BIP-110, arguing that non-payment data increases storage costs and moves Bitcoin away from its monetary purpose.

The mandatory signaling window is expected to begin this weekend, although the timing could shift because Bitcoin blocks do not arrive at exact ten-minute intervals. Holders who cannot verify that their coins have been separated face the lowest replay risk by waiting until wallets, exchanges, and miners clarify which chain they support.

Source link

Advertisement
Continue Reading

Crypto World

BitMEX spent two years seeking buyer before shutdown: Report

Published

on

BitMEX spent two years seeking buyer before shutdown: Report

BitMEX reportedly spent two years seeking a buyer before deciding to close the crypto derivatives exchange, as founder control, declining activity and legal baggage deterred potential acquirers.

Summary

  • BitMEX discussed a sale with multiple prospective buyers, including competing exchanges and Exodus.
  • Founder control, shrinking revenue and reputation concerns reportedly complicated the negotiations.
  • The exchange was reportedly seeking a valuation of about $1 billion during the process.
  • BitMEX will restrict trading on Aug. 26 and close the exchange on Sept. 23.

BitMEX held sale talks for two years

BitMEX explored a sale with several potential acquirers over approximately two years but failed to secure an agreement, CoinDesk reported, citing a person familiar with the private discussions.

Potential buyers included rival cryptocurrency exchanges and payment and wallet company Exodus.

Advertisement

Broadhaven Capital Partners reportedly advised the Seychelles-based exchange during the process. crypto.news first reported BitMEX’s search for a buyer in February 2025, although the investment bank had reportedly joined the process in late 2024.

BitMEX was said to be seeking a valuation of approximately $1 billion. However, it remains unclear whether any interested company submitted a formal bid.

The reported sale attempt ended without a deal before BitMEX’s parent company, HDR Global Trading, completed a strategic review and approved the exchange’s closure.

Advertisement

Founder ownership reportedly complicated negotiations

BitMEX co-founders Arthur Hayes, Ben Delo and Samuel Reed left management after U.S. authorities filed criminal charges against them in 2020. Despite their departures, the three reportedly retained control of a large majority of the company’s equity.

According to CoinDesk’s source, the structure concerned at least one prospective buyer and made negotiations more difficult. Acquirers often reserve part of a transaction’s consideration for current managers, giving executives an incentive to remain with the business after a takeover.

That arrangement was harder to structure at BitMEX because the founders remained major owners without operating the exchange, the report said.

The company also experienced a management overhaul while its future remained uncertain. crypto.news previously reported that BitMEX replaced CEO Stephan Lutz with chief financial officer Ina Steiner, and growth chief Raphael Polansky also left. Former chief operating officer Peter Wilkinson subsequently became CEO.

Advertisement

Declining market share weakened buyer interest

BitMEX continued losing trading activity while the sale discussions were underway, limiting the valuation prospective buyers were willing to consider.

Monthly futures volume had exceeded $100 billion during parts of 2021 but declined to between $25 billion and $30 billion in late 2024, according to figures previously cited by The Block. CoinDesk’s source said the deteriorating business made buyers reluctant to pay the revenue multiple normally attached to a growing company.

Activity migrated to larger centralized exchanges and decentralized perpetual futures platforms. Hyperliquid recorded about $2.6 trillion in notional trading volume during 2025, nearly double Coinbase’s $1.4 trillion, according to Artemis data previously covered by crypto.news.

The shift carries added symbolism because BitMEX helped popularize perpetual swaps through its XBTUSD contract in 2016. The product allows leveraged positions without an expiry date and uses funding payments to keep contract prices close to the underlying spot market.

Advertisement

US legal history added reputational risk

BitMEX’s U.S. regulatory record reportedly presented another obstacle. The exchange pleaded guilty to violating the Bank Secrecy Act after authorities accused it of operating without an adequate anti-money laundering program. Its co-founders also pleaded guilty before receiving presidential pardons in 2025.

BitMEX now faces a proposed U.S. class action alleging that it profited from forced customer liquidations. As crypto.news reported, the plaintiffs are seeking the return of 622.66 BTC plus damages. The claims remain allegations and have not been proven in court.

BitMEX will move into reduce-only trading on Aug. 26, preventing users from opening new positions. The exchange will close on Sept. 23, ending an 11-year run. Customers have been asked to close positions and withdraw their assets before operations end.

Advertisement

Source link

Continue Reading

Crypto World

Best Mutual Funds Bet Big On Apple, Marvell And 15 Others

Published

on

Number 3, comic style

In the latest monthly report, the best mutual funds showed a voracious appetite for shares of Marvell Technology (MRVL), Apple (AAPL) and Banco Santander (SAN). They also placed massive bets on 14 other companies, including Palo Alto Networks (PANW), GE Aerospace (GE) and Eli Lilly (LLY). Marvell led the list, raking in $18.38 billion from the best mutual funds. Apple…

Copyright ©2026 Investor’s Business Daily, LLC. All rights reserved. 87990cbe856818d5eddac44c7b1cdeb8

Source link

Continue Reading

Crypto World

Bhutan Resumes Bitcoin Selling Spree: Here’s the Latest BTC Transfer

Published

on

Less than a year after announcing plans to develop a new special administrative region called Gelephu Mindfulness City (GMC) using the proceeds of BTC sales acquired through hydropower mining, the Royal Government of Bhutan has continued to offload as the asset’s price is trying to stabilize at around $65,000.

Data from the on-chain analytics resource Lookonchain indicated that the administration has deposited almost 435 BTC (worth around $28 million) into Binance, likely with the intention to sell, as in all previous examples.

The sale from August 7 is significantly smaller than the one completed in July, when wallets linked to the government transferred 700 BTC to Binance. Before that, they sold 533 BTC in mid-June and another substantial batch of 738 units in early June.

Advertisement

May was a more modest month, in which the government sent two batches of 100 and 90 BTC to be sold on the world’s largest crypto exchange, according to data from Arkham and Lookonchain.

CryptoPotato also reported a previous major disposition that took place in March, in which Bhutan’s administration offloaded $45 million worth of the asset within a few days.

Thus, the country continues its plan to create Gelephu Mindfulness City with the proceeds of its BTC sales, announced at the end of 2025. GMC is a massive project, designed to work as a multi-generational special administrative economic zone spanning over 2,600 square kilometers. It will work as an autonomous region focused on green technology, digital finance, and sustainable urban living.

The post Bhutan Resumes Bitcoin Selling Spree: Here’s the Latest BTC Transfer appeared first on CryptoPotato.

Advertisement

Source link

Continue Reading

Crypto World

Dow Jones Futures: What To Do As Stock Market Revs Up; Warren Buffett, Cisco, Lumentum Due

Published

on

Dow Jones Futures: What To Do As Stock Market Revs Up; Warren Buffett, Cisco, Lumentum Due

Dow Jones futures will open Sunday evening, along with S&P 500 futures and Nasdaq futures. Iran news will be in focus. Warren Buffett’s Berkshire Hathaway reports on Saturday, with Cisco, Lumentum and Applied Materials among the notable earnings this coming week. A stock market rally is back in full force, with the S&P 500 and Dow Jones hitting new highs…

Copyright ©2026 Investor’s Business Daily, LLC. All rights reserved. 87990cbe856818d5eddac44c7b1cdeb8

Source link

Continue Reading

Crypto World

What Happens When the World is on Fire

Published

on

What Happens When the World is on Fire

Between drought, heat, and wildfire, much of the world is summering in record-breaking territory. The U.K., its iconic green landscape now parched to desert brown, is suffering one of its worst droughts since record-keeping began. Eight time zones away, Spokane, Washington, endures similarly outlandish temperatures as it continues to battle the most destructive wildfire the city and state has ever seen. With no relief in sight, there is, according to the city’s mayor, Lisa Brown, a years-long recovery already baked in. British Columbia, which has suffered several of the worst fire seasons in its history over the past decade, is bracing itself for the worst one yet. In Utah, fire officials are saying the same thing. In Russia this month, temperatures broke 90°F. at two different weather stations at the Arctic Circle, nearly 3,000 miles north of Miami, where such temperatures are the norm for this time of year.

Source link

Continue Reading

Crypto World

Bitcoin ETFs draw $853.5M in five-day inflow streak

Published

on

BlackRock scores major SEC win as IBIT options cap quadruples

U.S. spot Bitcoin ETFs attracted $853.5 million during five consecutive inflow sessions as August demand reversed the previous week’s withdrawals.

Summary

  • Bitcoin ETFs recorded five straight inflow days from Aug. 3 through Aug. 7.
  • Weekly net inflows reached approximately $853.5 million, according to SoSoValue.
  • August flows are already nearly five times July’s $172.4 million total.
  • Ethereum ETFs added another $244.9 million during the same trading week.

Bitcoin ETF inflows reverse previous week’s withdrawals

U.S. spot Bitcoin ETFs opened August with $170.1 million in net inflows on Aug. 3, followed by $211.5 million on Aug. 4, according to SoSoValue.

Inflows increased to $244.4 million on Aug. 5, the strongest session of the week. The funds subsequently added approximately $128.8 million on Aug. 6 and $98.85 million on Aug. 7.

Advertisement

The five daily results produced approximately $853.5 million in combined net inflows, depending on rounding. The performance represented a roughly $915 million swing from the previous week, when the products recorded $61.5 million in net outflows.

The streak also followed a volatile end to July. crypto.news previously reported that investors withdrew approximately $265 million from the funds on July 31. BlackRock’s IBIT lost $123 million that day, while Fidelity’s FBTC recorded $54.8 million in withdrawals.

BlackRock accounts for most Bitcoin ETF demand

BlackRock remained the largest source of new demand during the August streak. IBIT attracted an estimated $693 million over the five sessions, accounting for roughly 81% of the category’s total inflows.

Advertisement

The fund added $86.71 million on Aug. 7 alone. Fidelity’s FBTC followed with $40.95 million, while Bitwise’s BITB and ARK 21Shares’ ARKB drew $2.11 million and $1.94 million, respectively.

Those allocations offset $19.37 million in withdrawals from Invesco and Galaxy’s BTCO, $10.55 million from VanEck’s HODL and $2.94 million from Hashdex’s DEFI.

Total spot Bitcoin ETF net assets reached $79.50 billion by the end of Aug. 7, equal to approximately 6.10% of Bitcoin’s market capitalization. Cumulative net inflows since launch stood at $52.18 billion, while the products generated $1.57 billion in daily trading value.

August’s $853.5 million inflow total is already nearly five times the approximately $172.4 million attracted during all of July. It is also about 395% higher than July’s full-month result after only five trading sessions.

Advertisement

Ethereum ETFs add $244.9 million during the week

U.S. spot Ethereum ETFs also recorded a strong week, attracting approximately $244.9 million from Aug. 3 through Aug. 7.

The products began with an $11.42 million outflow before adding $53.75 million on Aug. 4, and $60.86 million on Aug. 5. Daily inflows then increased to $92.15 million on Aug. 6 before easing to $49.60 million on Aug. 7.

Crypto.news reported that the Aug. 6 inflow coincided with Ether holding above $1,900 and approaching the $2,000 psychological level.

BlackRock’s ETHA drove much of the demand, collecting $50.34 million on Aug. 5, $81.14 million on Aug. 6 and $38.15 million on Aug. 7. Total Ethereum ETF net assets reached approximately $10.74 billion, representing 4.65% of Ether’s market capitalization.

Advertisement

Bitcoin and Ethereum ETFs therefore attracted nearly $1.10 billion combined during the week.

Other crypto ETF flows remain limited

Smaller crypto ETF categories did not experience comparable demand. HYPE products recorded modest positive flows, including roughly $1 million on Aug. 5 and $2.84 million on Aug. 6.

XRP funds finished slightly negative after a $3.58 million withdrawal on Aug. 5 offset the $1.15 million attracted on Aug. 3. Solana ETFs were broadly flat, with a $1 million inflow on Aug. 4 largely canceled by an $859,500 withdrawal on Aug. 6.

The differences show that regulated crypto investment demand remained concentrated in Bitcoin and Ethereum during the opening week of August.

Advertisement

Bitcoin itself remained below $65,000 despite the inflows. crypto.news previously reported that ETF demand supported the $64,000 area, but had not produced a confirmed breakout.

Source link

Advertisement
Continue Reading

Crypto World

A Deep Dive Into One Of The Most Significant Hacks In Recent Memory

Published

on

Crypto Breaking News

Coldcard is a Bitcoin-only hardware wallet created by Coinkite, a Toronto-based company specializing in ultra-secure self-custody hardware. The hardware wallet is marketed as a highly secure cold storage option for long-term Bitcoin users and has received plaudits from users and experts alike. However, the Coldcard exploit could change that perspective and have far-reaching implications for “self-custody,” a hill many in crypto choose to die on.

The Coldcard Exploit Timeline

Let’s get into the nitty-gritty of the exploit. On July 30, individual Bitcoin holders using Coldcard noticed that their wallets were inexplicably drained. Among them was author Jonathan Goodman, who lost $1.6 million in BTC to the exploit. Goodman’s post about the hack on X was possibly the first time the hack was discussed in the public domain. Meanwhile, blockchain intelligence firm Galaxy Research detected suspicious transaction waves in a 41-minute window, hours before Coinkite issued its first advisory regarding the exploit. Unlike most exploits, the Coldcard exploit unfolded in waves, with the number of affected wallets rising almost daily.

The vulnerability impacted several models, including the Mk2, Mk3, Mk4, Mk5, and Q. However, Coinkite products built on separate codebases, including Tapsigner, Opendime, and Satscard, were unaffected.

The first wave was detected on July 30, when a hacker or hackers began targeting Bitcoin held in Coldcard hardware wallets. The hackers drained 500 wallets in a 25-minute window during the first wave, siphoning around 594 BTC, worth around $38 million, to a new address. The numbers are staggering for such a small window, but this was just a prelude to what was to come. The first wave lasted 41 minutes and affected 1,196 wallets. As more data poured in, Galaxy Research pegged the first wave figures at 1,082.65 BTC stolen from 1,196 wallets, around 0.9 BTC from each wallet.

Advertisement

Galaxy Research detected two subsequent waves on July 31 and August 1, respectively. The hackers stole around 76 BTC from 1,477 wallets during the second sweep and 208 BTC from 1,912 wallets during the third sweep. A suspected fourth wave was detected on August 4, with researchers identifying an additional 600 wallets. Early estimates put losses at over $130 million, a figure that could increase as hackers continue targeting vulnerable addresses.

Wave Date Wallets Affected BTC Stolen
1 July 30 1,196 1,082.65 BTC
2 July 31 Roughly 1,477 76 BTC
3 August 1 1,912 208 BTC
4 (Possibly Ongoing) Detected by August 4 Over 600 Figure Not Publicly Available

A highly unusual aspect is the nature of the exploit. The BTC wasn’t stolen through an elaborate social engineering scheme or the usual phishing or exchange attacks that we usually see. It wasn’t even a supply chain compromise like the one that hit Ledger in 2023. This was a bug that sat undetected for five years, until someone, somehow, discovered it and used it to blindside Coldcard wallet users.

How Does The Coldcard Number Generator Work

Coldcard wallets generate their own randomness every time a user creates a new seed. The randomness underpins the security the wallets are known for. Any compromise to this randomness would prove disastrous, as the ongoing exploit has proved. These wallets are designed to generate and store private keys offline and are never directly connected to the internet. Instead, they communicate with the blockchain using an air-gapped environment through QR codes and MicroSD cards.

The Code That Started It All

At the heart of the exploit sits an innocuous firmware update pushed by Coldcard in March 2021. Firmware version 4.0.1 migrated Coldcard’s cryptography to libsecp256k1, the library underpinning Bitcoin Core, a sound decision by every definition of the word. However, this inadvertently moved seed generation to MicroPython’s Yasmarang PRNG, used on devices with no randomness chips.

Advertisement

You may be wondering why.

According to Block’s security and engineering team, the 2021 update changed how the firmware called its cryptographic library during the seed generation phase. The library misread a production build configuration flag that checks whether the hardware random number generator (RNG) was available. This event went unnoticed, and the firmware began generating “deterministic, pseudorandom seed phrases from a significantly smaller entropy pool without adding fresh entropy.”

Let me explain the preceding sentence. A hardware wallet typically uses two components: a physical randomness source embedded in the chip (TRNG) and an algorithm that uses true randomness from the TRNG to generate seed phrases (CSPRNG). Coldcard wallets use a hardware-based true random number generator built directly into its microchip. Additionally, users can add physical dice rolls to increase randomness.

When Coinkite pushed the 2021 update, the firmware reverted to a backup PRNG without alerting the user. The PRNG relied on the wallet’s UID instead of fresh entropy, making the output predictable. Here’s where the vulnerability comes in. If an attacker can determine a device’s possible UID, they could narrow down the seed phrases generated by the wallet.

Advertisement

So what effect did this have?

Seed phrases generated using firmware 4.0.1 looked like a standard 12- or 24-word phrase. However, the randomness of the underlying numbers was compromised, making them significantly weaker. A 12-word BIP-39 seed typically carries 128 bits of entropy. Let me put this unremarkable figure into perspective using a simple analogy. 128 bits of entropy effectively gives ~3.4 × 10³⁸ possible seeds. The age of the universe is 13.8 billion years. If a hacker tried to brute-force 128 bits of entropy at a trillion guesses per second, it would take them 800 million times the age of the universe to run through all possible combinations.

Entropy fell to 72 bits on Mk4, Mk5, and Coldcard Q devices, reducing the possible seeds to ~4.7 × 10²¹. This is well below the 128-bit threshold and exploitable by determined hackers with time and resources. It fell even lower (40 bits) on Mk2 and Mk3 devices, well within the reach of an attacker with even modest resources.

Now, you may read this and think an upgrade could fix the vulnerability. Not exactly. A firmware update fixes the problem for seeds generated after the vulnerability was patched. However, seeds generated using firmware 4.0.1 remain vulnerable. Coinkite has recommended that all users who created seed phrases using the compromised firmware generate a new seed phrase and move their funds to a new wallet.

Advertisement

Details And On-Chain Analysis

Galaxy Research highlighted differences in transaction construction across the attack waves, suggesting multiple threat actors instead of a single entity. A TechCrunch report cited other blockchain monitoring firms to confirm Galaxy Research’s observation, stating that Coldcard wallets were targeted by at least a dozen hackers.

Here is a breakdown of the attack waves that targeted Coldcard. However, these figures could change as analysts believe the exploit is ongoing and details of more affected wallets could emerge over time.

  • Galaxy Research flagged suspicious transactions detected on July 30, identifying around 594 BTC drained from 500 single-signature wallets. The first wave lasted for 41 minutes, targeting 1,196 wallets and draining 1,082.65 BTC.
  • The second wave followed the same pattern, with hackers draining 76 BTC from 1,477 wallets, taking the total to 1,158.66 BTC (~$75.1 million) from 2,673 addresses.
  • The third wave targeted 1,912 wallets, draining 208 BTC and taking the total to 1,367 BTC (~$88–89 million) across over 4,500 addresses.
  • The fourth wave could still be ongoing, with TRM Labs updating the figures to 1,816 BTC from over 5,200 addresses. These numbers could change as more reports come to light.

TRM Labs tracked the stolen BTC to a pool of addresses linked to the attackers. Surprisingly, the attackers have made very little attempt to move, launder, or mix the funds so far. This is likely because the attackers want to target as many vulnerable wallets as possible before worrying about laundering or mixing the stolen funds. A single deposit of 64.9 BTC on Wasabi and 200 ETH on Tornado Cash are the only laundering activity tracked so far.

This is probably why the exploit has not been attributed to groups like North Korea’s Lazarus that launder stolen funds within hours. Funnily enough, the hackers themselves are being inundated with spam messages, with one message offering to launder the stolen funds for a nominal fee.

Coinkite’s Response And Advisory

Coinkite issued several advisories as the scope of the exploit became clearer. The Coldcard manufacturer published a security advisory following the first wave. The initial advisory covered Mk3 devices and firmware 4.0.1 and 4.1.9. Coinkite released an updated advisory and firmware for Mk4/Mk5 (version 5.6.0 or later) and Coldcard Q (version 1.5.0Q or later). The advisory was updated again on August 1, confirming that the exploit had also impacted Mk2 devices. The latest advisory also narrowed the firmware impacted by the exploit and released a fixed firmware update for Mk2/Mk3 (version 4.2.0).

Advertisement

The update also officially recognized that seed phrases generated with at least 50 manual dice rolls contained enough randomness and were not at risk.

Coinkite has stressed that simply updating the firmware will not fix wallets that have already generated a seed. It advised users who generated a seed between March 2021 and the latest firmware update to treat their seed as compromised and move their funds to a new wallet or generate a new seed on a patched firmware.

Why Was The Coldcard Vulnerability Undetected For So Long

One of the biggest talking points of this entire episode is why nobody detected the bug, which was shipped in a firmware update in March 2021. One detail to remember is that Coldcard’s firmware is open source and publicly available. Coinkite speculated in one of its advisories that the bug may have been discovered during an AI-assisted review of the code. However, this theory is unconfirmed as of now.

The exploit adds to the ongoing conversation about hackers using AI systems to find and exploit vulnerabilities in already-reviewed code. Separately, several AI labs, including OpenAI, Anthropic, and Meta, have revealed that their models access real systems during testing. These incidents occurred due to misconfigured environments allowing the models to gain internet access, or because the AI models exploited vulnerabilities during certain tests.

Advertisement

Some recent examples include:

  • One of OpenAI’s internal models accessed Hugging Face production infrastructure by breaking out of a test environment and exploiting a zero-day vulnerability.
  • According to one report in ALMCorp, an Anthropic audit revealed some Claude models, including Opus 4.7 and Mythos 5, accessed the internet and gained unauthorized access to systems of three organizations.
  • Meta’s Muse Spark AI model accessed an external company’s systems and altered internal data.

What Are The Implications For Bitcoin Self Custody

The Coldcard exploit could potentially change Bitcoin custody forever, raise questions about mass adoption, and highlight the complexities of self-custody. First, none of the affected users did anything wrong. They did not fall victim to a social engineering scam or click on a malicious link.

The incident has cast doubt on self-custody, a concept the Bitcoin and broader crypto community swears by. The exploit also reinforces the argument many have made that self-custody does not eliminate risk, it only relocates it. Some, including Taproot developer Udi Wertheimer, have argued that the community cannot assume that Bitcoin stored in cold wallets indefinitely is safe and users must remain vigilant about emerging threats.

The threat landscape has evolved as well. According to Blockaid, the majority of crypto losses this year have been attributed to key compromises and operational security features. The Coldcard exploit is an extreme example of the latter.

Moreover, the incident could push fence-sitters towards institutional and retail exposure to Bitcoin through spot Bitcoin ETFs.

Advertisement

However, self-custody advocates have pointed out that the exploit occurred because of a firmware bug, not a hardware flaw, arguing that self-custody is the safest way to store Bitcoin.

What Steps Can Coldcard Users Take

Coldcard users, especially those who have generated their seeds between March 2021 and Coinkite’s latest advisory, must follow the steps listed below.

  • Check the Model and Firmware – If you own a Coldcard Mk2, Mk3, Mk4, Mk5, or Q and generated a seed between March 2021 and the latest update, the seed may be compromised.
  • Update Firmware – Coinkite has released firmware updates for the affected devices. Mk2 and Mk3 users can update to version 4.2.0 and above. Mk4 and Mk5 users can upgrade to 5.6.0 and above, while Coldcard Q users can update to 1.5.0Q.
  • Check Entropy – Coinkite’s advisory states that the seeds of users who have used the Add Dice feature and completed 50 private, independent rolls are not at risk. However, if you have used fewer than 50 rolls, or not used the Add Dice feature at all, your seed may be compromised.
  • Recheck Passphrase – A BIP-39 passphrase adds another layer of security. However, users must ensure their passphrase is long, unique, and unrecorded. Shorter phrases cannot be deemed secure.

FAQs

What Caused The Coldcard Exploit

The root cause of the exploit was a bug that shipped in March 2021. The error altered how the firmware called its cryptographic library, causing it to revert to a weak software random number generator instead of relying on the Coldcard device’s source of entropy. This led to the key strength falling from the standard 128 bits to as low as 40 bits on some devices, making them susceptible to brute-force attacks.

Will Updating The Firmware Protect The Wallet From The Exploit

This is where things could get tricky for users. It is generally assumed that if the firmware has a bug, it can be updated to fix that bug. However, in Coldcard’s case, it’s only partially correct. A firmware update fixes the RNG issue moving forward, but does not retroactively fix seeds generated on the vulnerable software. Users should treat seeds generated between March 2021 and Coinkite’s latest update as compromised and move their funds after generating a new seed on an updated device.

Does The Hacker Need Physical Access To Exploit The Vulnerability

No, hackers can use brute-force attacks without needing access to the actual device.

Advertisement

Did The Exploit Impact Tapsigner, Satscard, Or Opendime Devices

No, these devices run on separate codebases and were not impacted by the exploit, which is limited to Mk2, Mk3, Mk4, Mk5, and Coldcard Q devices.

Has Anyone Claimed Responsibility For The Attack

No single entity has claimed responsibility for the exploit. Blockchain analysis revealed differences between transaction patterns, suggesting the involvement of multiple threat actors exploiting the same vulnerability.

Is My Coldcard Wallet Compromised

The Coldcard wallet is not compromised, and a firmware update fixes the vulnerability for new seeds. However, seeds generated between March 2021 and Coinkite’s latest update are vulnerable.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Advertisement

Source link

Continue Reading

Crypto World

XRP ETF Inflows Have Collapsed 79% Since May as the CLARITY Act Stalls, Is $1 About to Break?

Published

on

xrp logo

In the latest XRP News, Ripple XRP traded near $1.03 after a 1.24% 24-hour decline, leaving the token testing its psychologically critical $1 support zone as legislative momentum in Washington grinds to a halt.

The U.S. Senate’s decision to move consideration of the Digital Asset Market CLARITY Act past its August 7 recess leaves September 14 as the earliest plausible window for floor action rather than a confirmed voting date.

That delay deprives the market of a near-term catalyst and forces institutional buyers to evaluate whether regulatory clarity can materialize before the 2026 midterm election cycle takes over Congress.

Xrp (XRP)
24h7d30d1yAll time

The legislative setback highlights a persistent gap between regulatory expectation and legislative execution in crypto regulation.

Advertisement

While agency-level interpretations have acknowledged the token’s commodity treatment, asset managers and corporate balance sheets continue to delay large-scale commitments until Congress embeds those definitions directly into federal statute.

Discover: Everyone’s Got a Take. Get Free $25 to Actually Trade Yours

Senate Vote Timelines and Legislative Bottlenecks

The CLARITY Act cleared the House in July 2025 by a 294-134 vote and passed the Senate Banking Committee 15-9 in May 2026, landing on the Senate floor calendar on June 1.

Advertisement

Senate Majority Leader John Thune has yet to grant the bill floor time, choosing instead to prioritize executive nominations and a foreign sanctions package.

Photo: John Thune

With Republicans commanding 53 seats, leadership requires at least seven Democratic crossover votes to reach the 60-vote threshold needed to invoke cloture and clear procedural filibusters.

Democratic resistance centers on two main policy disputes. Commercial banks have aggressively lobbied against stablecoin provisions that allow crypto exchanges to pay yield on holdings, warning that yield-bearing stablecoins threaten traditional bank deposits.

Meanwhile, senior lawmakers have insisted on tighter ethics restrictions barring executive officials from participating in private crypto projects-a provision whose latest iteration was transmitted to the White House on July 30.

Senator Cynthia Lummis acknowledged the bipartisan friction, noting that even Republican support faces hurdles with key members remaining “really resistant” to passing the market-structure framework without broader concessions.

Because the Senate leaves for its state work period from August 10 through September 11, the bill cannot proceed without a cloture motion filed before the break.

Without that procedural filing, the legislation must compete for limited calendar space alongside imperative government funding debates when lawmakers return on September 14.

Furthermore, because the Senate draft differs from the House version, both chambers would still need to reconcile and pass identical text within a tight September window before lawmakers adjourn again for October campaign recourses.

Advertisement

Discover: Your Market Calls Are Worth Something. Start With Free $25 on Kalshi

XRP News: Institutional Inflows Stall as Odds Compress

The market impact of legislative stagnation is clearly visible across institutional investment flows. U.S. spot XRP ETFs took in $131.94 million in May during the peak of Senate committee momentum, but monthly net inflows contracted sharply to $59.46 million in June and just $27.29 million in July.

Source: SoSoValue

Institutional allocators appear unwilling to scale up positions while legal status rests on revocable regulatory interpretations rather than statutory law.

Prediction markets have aggressively re-priced the bill’s legislative prospects. Traders on Kalshi dropped the probability of the CLARITY Act becoming law in 2026 to approximately 17%, down sharply from an 82% high in February.

Advertisement

Discover: Get Paid to Be Right, $25 to Start on Kalshi

Don’t Miss Out on Our $1,000 USDT Airdrop on ByBit

The post XRP ETF Inflows Have Collapsed 79% Since May as the CLARITY Act Stalls, Is $1 About to Break? appeared first on Cryptonews.

Source link

Advertisement
Continue Reading

Crypto World

EU to revise MiCA rules in 2027 amid US stablecoin push

Published

on

Bitget bets on tokenized Wall Street with new Reality platform

European Union officials are preparing to revise the bloc’s MiCA crypto framework in 2027 as foreign stablecoin restrictions and faster U.S. rulemaking expose gaps in the existing regime.

Summary

  • EU diplomats reportedly expect MiCA revisions in 2027, despite an ongoing European Commission consultation.
  • Changes could address rules that have left non-EU stablecoins such as USDT without authorization.
  • The review may expand MiCA to cover tokenized deposits, payments and other real-world assets.
  • U.S. adoption of the GENIUS Act has added pressure on Europe to reassess its approach.

EU officials reportedly see MiCA revision as unavoidable

European diplomats said policymakers are expected to reopen the Markets in Crypto-Assets Regulation in 2027, according to a Euronews report.

The planned revision would examine how MiCA treats stablecoins issued outside the European Union. Current requirements have prevented several foreign issuers from receiving authorization, limiting their access to regulated exchanges across the bloc.

Advertisement

“Reopening the file seems unavoidable at this stage,” an unidentified European diplomat told Euronews.

The diplomat cited positions taken by European institutions, including the European Central Bank, along with changes in global regulation and digital-asset technology.

No final proposal has been published. Any amendment would need to pass through the EU’s legislative process before taking effect.

Advertisement

MiCA consultation could shape the 2027 proposal

The European Commission opened a targeted MiCA consultation on May 20 to determine whether the framework remains fit for purpose following its initial implementation.

The consultation covers developments that have occurred since MiCA entered into application. Its deadline has been extended to Sept. 30, with crypto issuers, service providers, regulators, central banks and finance ministries invited to respond.

The Commission said the feedback would support a report required under Articles 140 and 142 of MiCA. That report could be accompanied by legislation to amend or expand the regulation if officials conclude that changes are warranted.

Crypto.news previously reported that the review could examine stablecoin issuance, decentralized finance, tokenized assets and cross-border supervision.

Advertisement

Tether exclusion exposes stablecoin licensing gap

MiCA’s final transition period for crypto-asset service providers ended on July 1, forcing covered companies to obtain authorization or stop providing regulated services.

The change left Tether’s USDT without a compliant route onto regulated EU exchanges because the issuer did not seek authorization. Coinbase, Kraken and Crypto.com were among the platforms that removed USDT trading for European customers, according to crypto.news.

Tether CEO Paolo Ardoino has criticized MiCA’s reserve requirements, particularly rules requiring stablecoin issuers to hold a large portion of their reserves in European bank deposits.

Circle took a different approach by securing authorization for USDC and EURC. Stripe-owned Bridge also recently joined the MiCA register, raising the number of authorized electronic-money-token issuers to 42. The bloc had also registered 324 authorized crypto-asset service providers.

Advertisement

A revision could create a route for foreign issuers while preserving EU reserve, disclosure and consumer-protection requirements.

US stablecoin rules add pressure on Europe

The reported review comes as the United States advances its stablecoin framework under the GENIUS Act, signed into law in July 2025.

The law established federal requirements for payment-stablecoin reserves, redemptions, disclosures and supervision. Although U.S. agencies missed a one-year deadline to finalize several implementing rules, the framework has already given issuers and financial institutions a federal structure for entering the sector.

European officials are also considering whether MiCA should cover newer forms of tokenization. Possible additions include tokenized deposits, payment instruments and real-world assets that fall outside or sit between existing regulatory categories.

Advertisement

MiCA was approved by the Council of the EU in May 2023. A 2027 revision would allow policymakers to update rules based on several years of implementation, market changes and competition from the expanding U.S. stablecoin sector.

Source link

Advertisement
Continue Reading

Trending

Copyright © 2025