Coldcard disclosed a critical firmware bug that silently bypassed the hardware random number generator (RNG) for five years, allowing an attacker to drain roughly 594 BTC (about $38 million) from around 500 wallets in a 25-minute sweep on July 31, 2026. This is one of the largest hardware wallet exploits in Bitcoin's history. This incident undermines the core promise of hardware wallets — that private keys never leave secure hardware — and could erode confidence in self-custody among Bitcoin holders. If investors lose faith in self-custody solutions, they may shift funds to regulated products like spot ETFs, potentially reshaping the custody landscape. The vulnerability affected Coldcard Mk2 and Mk3 devices where seeds were generated on firmware v4.0.0 through v5.0.3; the attacker swept funds from roughly 500 wallets between 01:31 and 01:56 UTC. Coldcard has urged all affected users to move their funds immediately, but the full extent of exposed seeds remains unknown.
Self-custody means holding your own crypto assets in a wallet you control, rather than trusting an exchange or third party. Hardware wallets like Coldcard are considered among the most secure self-custody tools because they keep private keys offline in a dedicated chip. This exploit, however, shows that even hardware wallets are not immune to firmware-level vulnerabilities, raising questions about the long-term reliability of the 'not your keys, not your coins' ethos.
Tether reported $1.5 billion in operating profit for the second quarter of 2026, while its excess reserve buffer declined by half from the prior quarter's record $8.23 billion. The announcement comes from its latest financial attestation. The reserve buffer is a key measure of Tether's financial resilience and directly affects user confidence in USDT, the world's largest stablecoin. A 50% reduction could raise concerns about backing strength, though the continued profitability may mitigate potential fallout. Excess reserves function as a loss-absorbing layer above the per-token collateral backing Tether's issued tokens. The Q1 buffer of $8.23 billion had been supported by profitability and a reserve base concentrated in short-duration, high-quality liquid instruments.
Stablecoins like USDT are designed to maintain a 1:1 peg with fiat currency, so issuers hold reserves of assets such as Treasuries, gold, and other instruments. 'Excess reserves' are the surplus assets beyond what is needed to back all tokens, serving as a cushion against losses. Independent attestations and audits verify these holdings, though the quality and liquidity of the reserve mix are important for institutional confidence.
Circle has been granted a New York trust charter by the New York State Department of Financial Services (NYDFS), an official state banking authorization that permits the company to provide fiduciary, custody, and asset-management services under the New York Banking Law. This marks a significant regulatory milestone for the stablecoin issuer and strengthens its standing in the evolving crypto regulatory landscape. This milestone boosts Circle's credibility and market access as a leading USDC issuer, potentially accelerating institutional adoption of the stablecoin. It also comes amid a broader regulatory push to formalize oversight of digital assets, signaling that compliant players are gaining a competitive edge in the market. The trust charter is a limited-purpose trust company authorization under New York law, meaning Circle cannot take deposits or make loans like a full commercial bank. The charter enables it to offer custody and fiduciary services, which are critical for managing stablecoin reserves and digital asset custody.
A trust charter from the NYDFS is a state-level license required to operate a trust company in New York, allowing the holder to legally provide fiduciary and custody services. NYDFS is a key financial regulator in the United States, known for enforcing rigorous standards such as the BitLicense for crypto firms. This charter gives Circle clear legal authority to operate in New York, a major financial hub, while aligning with its broader strategy to comply with evolving stablecoin regulations.
A Dubai-based cryptocurrency exchange has been reportedly connected to a $4 billion network used to evade U.S. sanctions against Iran, according to Reuters via CoinDesk. The report raises immediate concerns about the exchange's compliance practices and potential enforcement actions. This development underscores how crypto exchanges can become channels for illicit finance and sanctions evasion, putting global regulators on high alert. It could trigger investigations, enforcement actions, and stricter know-your-customer (KYC) and anti-money laundering (AML) requirements across the industry. The alleged network reportedly moved billions of dollars using digital assets, and the exchange is said to have handled a portion of those funds. Neither the exchange nor the U.S. authorities have yet confirmed the details, and the report cites unnamed sources familiar with the matter.
Sanctions are economic penalties imposed by governments to pressure countries like Iran over activities such as nuclear proliferation or support for terrorism. Crypto exchanges are under growing scrutiny because the pseudonymous nature of digital assets can make sanctions evasion harder to trace, prompting regulators to demand robust compliance programs. The U.S. Office of Foreign Assets Control (OFAC) has previously sanctioned individuals and entities involved in virtual currency-based sanctions evasion.
OpenAI announced that it disrupted a Cambodia-based criminal operation that used ChatGPT to assist in investment, romance, gambling, and impersonation scams. The action is part of OpenAI's ongoing efforts to combat malicious uses of AI. This shows that AI developers are actively enforcing safety policies and taking real-world action against cybercriminals. It highlights the growing role of AI-safety teams in preventing fraud and protecting users from AI-enabled criminal schemes. The scam operation reportedly used ChatGPT to craft convincing messages for romance and impersonation fraud, as well as to support fake investment opportunities and gambling platforms. OpenAI did not disclose the exact scale of the operation or the specific methods used to identify it.
AI models like ChatGPT can be exploited by bad actors to generate fraudulent content at scale. OpenAI has usage policies that prohibit illegal or harmful activity, and it uses automated detection systems and investigations to find and disrupt such abuse. This disruption is part of a broader industry trend where AI labs are increasingly cooperating with security researchers and law enforcement.