GCP Exclusive Reporting

10/cate3/GCP Exclusive Reporting

Featured Startups

5/cate1/icos

exchanges

6/cate2/exchanges

videos

6/cate3/videos

regulations

5/cate1/regulations

Now Playing:

3/cate6/videos

Recent post

Senate Pushes CLARITY Act Vote to September, Extending Crypto's Regulatory Wait...

CLARITY Act Vote

Washington has given the crypto industry a familiar product update: the Digital Asset Market Clarity Act is not dead, but the launch date has slipped. The U.S. Senate will not vote on the market-structure bill before the August recess, moving its next real chance of action to September.

Senate Majority Leader John Thune said there would be no August vote, with a possible vote in September. The delay follows unresolved disagreements between the parties, including demands for stronger ethics rules, enforcement provisions and market safeguards. The result is straightforward for traders and companies: the regulatory map remains unfinished for at least another month.

What the bill is trying to settle

The bill, H.R. 3633, is designed to create a clearer U.S. framework for digital-asset markets. At its core, it aims to define responsibilities across the Securities and Exchange Commission and Commodity Futures Trading Commission, while setting rules that would matter to token issuers, exchanges, brokers and customers. That may sound like Capitol Hill furniture-moving, but the practical stakes are substantial: classification and registration rules help determine which products can be offered, by whom, and under what compliance burden.

The House has already passed the measure, and its official Congress record lists it on the Senate Legislative Calendar. The Senate, however, is not a conveyor belt. A calendar placement means the bill is available for consideration, not that the chamber has solved its political and procedural problems.

Why the August miss matters

The Senate is scheduled to return on Sept. 14, leaving a relatively short working window before other legislative deadlines and election-season pressures crowd the agenda. Industry participants had hoped senators would remain in session long enough to resolve final disputes. That did not happen, and the bill now arrives in September with the same complicated questions still waiting for it.

For exchanges and U.S.-based crypto businesses, delay has a cost even without a new ban or enforcement action. Companies must still make product, custody, listing and compliance decisions under overlapping claims of authority. Investors also have to price the chance that a rulebook appears, changes materially, or remains stuck in the legislative queue. Regulatory uncertainty is not exciting, unless your hobby is modeling downside cases in a spreadsheet.

What has to happen next

A September vote is possible, not guaranteed. Senators will need to settle whether the bill has sufficient guardrails around consumer protection, enforcement and conflicts of interest, then navigate the usual Senate procedural gauntlet. Reporting on the delay indicated that unresolved bipartisan issues, rather than a simple lack of floor time, kept the measure from moving before recess.

Traders should avoid treating a September date as an automatic bullish or bearish catalyst. A credible path toward market-structure rules could improve confidence for institutions and U.S. platforms, but the final text and the timing of any vote matter more than the calendar headline. It is also possible the debate produces amendments that shift the bill's impact for particular categories of tokens or intermediaries.

For now, the CLARITY Act remains one of crypto's most consequential U.S. policy files, just delayed rather than decided. September will show whether the Senate can turn broad support for clearer rules into actual legislation, or whether the industry gets another reminder that “soon” is Washington's most flexible unit of time.

---------------

Author: Cedric Holloway
New York Newsroom
Breaking Crypto News

Bitcoin Reclaims $65,000 After Payrolls Miss - is it a Breakout or a Fake-out?

Bitcoin price

Bitcoin got the macro catalyst traders had been waiting for on Friday: a U.S. jobs report soft enough to restart the argument over how much room the Federal Reserve has to ease. BTC pushed as high as $65,340 on Bitstamp, up roughly 1.3% on the day, after July nonfarm payrolls showed the economy lost 23,000 jobs instead of adding the roughly 80,000 economists expected.

That is a meaningful miss, not a rounding error. The Bureau of Labor Statistics also revised May and June employment lower by a combined 103,000 jobs. July unemployment came in at 4.1%, little changed from the prior month, but the larger message was clear: the labor market is no longer giving the Fed the same comfortable cushion it appeared to have a few months ago. The full payroll release gave risk markets exactly the kind of ambiguity they enjoy turning into a bid.

Why Bitcoin cared

A cooler labor market can reduce the case for keeping monetary policy tight, assuming inflation does not decide to become difficult again. Lower expected rates generally help long-duration and liquidity-sensitive assets, and crypto has spent years proving it belongs in that unruly group. Traders swiftly repriced the rate discussion after the data, helping bitcoin take another run at a zone that had repeatedly capped it near $65,000.

The setup was especially notable because the prior session had pointed the other way. Stronger-than-expected jobless-claims data had helped push BTC down to about $64,384, while $64,800 to $65,000 remained a stubborn resistance band. In other words, bitcoin did not suddenly discover a new narrative. It got a fresh macro datapoint that challenged the one from a day earlier. Markets, in their eternal quest for efficiency, can now argue with themselves using two labor reports instead of one.

The number to watch is still $65,000

Friday's intraday high matters, but it is not the same as a clean break and hold. Bitcoin had been hovering near $64,350 before the payrolls release and remains in a range where quick moves above $65,000 have not yet turned into durable acceptance. For traders, the useful question is less whether BTC printed a satisfying headline number and more whether spot demand can keep it above the former ceiling when the initial macro reaction fades.

Near-term support remains clustered around the low-$64,000 area, based on this week's price action. A sustained move above the Friday high would put the next nearby round-number zone near $67,000 on more desks, while a return below $65,000 would make this another familiar range trade rather than the start of a clean trend. Current price feeds put BTC near $65,000, reinforcing just how close the market remains to that decision point.

What changes next

The next major test is whether incoming inflation data agrees with the rate-friendly reading investors drew from payrolls. Weak employment can support risk appetite, but it does not automatically produce easier policy. If inflation stays sticky, the Fed could remain cautious and leave crypto with a very expensive false start.

For now, the report gave bitcoin a lift and returned $65,000 to center stage. That is progress, but not a coronation. A breakout needs follow-through, and BTC has seen enough dramatic intraday reversals to know that one cheerful Friday candle is not a binding contract.

Bitcoin has regained a key psychological level on softer labor data; the next few sessions will show whether that level becomes support or merely another well-photographed ceiling.

---------------

Author: Ren Nakamura
Asia Newsroom
Breaking Crypto News

$70 Million in Bitcoin Vanished From Coldcard Wallets - Make Sure YOUR Crypto is Safe...

For years the whole pitch behind a Coldcard was that nobody could reach your Bitcoin unless they were physically holding the device in their hands.

That promise came apart this week, when an attacker quietly swept around 1,082 BTC, worth roughly $70 million, out of more than a thousand wallets in under an hour. The unsettling part is that the thief never touched a single device, never phished anyone, and never needed a PIN or a password. These coins were sitting in cold storage, offline, kept exactly the way every self-custody guide tells you to keep them. And they walked out anyway. For a corner of crypto that treats hardware wallets as the gold standard of safety, this is a genuinely rough moment.

Blockchain analysts at Galaxy Digital, who have been tracking the drain, first put the losses near $38 million before revising the number upward as more addresses turned up in the sweep. Hardware wallet maker Coinkite has confirmed the flaw and rushed out patched firmware, but by then the money was long gone. According to Coinkite's own security advisory, the theft happened roughly a day before the company managed to warn users publicly, so plenty of people watched their balances drop to zero before they had any idea anything was wrong. When your entire brand is built on paranoid, belt-and-suspenders security, a delay like that is about as bad as it gets. The company says it is still working to pin down the full scope of the damage.

A five-year-old bug in how the wallet made its keys

The root cause here is boring and alarming at the same time. When you set up a hardware wallet, it is supposed to build your seed phrase from true randomness, the kind that makes guessing it mathematically hopeless. Somewhere in a firmware build shipped back in March 2021, Coldcard's software started skipping its dedicated hardware random number generator and quietly fell back to predictable values pulled from the chip itself. Instead of the expected 128 bits of entropy, affected Mk3 devices were producing seeds with only about 40 bits, and later Mk4, Mk5 and Q models landed somewhere around 72 bits. In plain English, the recovery phrase that was meant to be unguessable became something a determined attacker with modern hardware could grind through.

What makes it worse is that this sat undetected for more than five years. Every wallet created on the affected builds carried the same weakness baked in from the very start, whether or not the owner ever did a single thing wrong. Some researchers have suggested that automated or AI-assisted tooling may have helped the attacker chew through the reduced keyspace fast enough to clear so many wallets in one sitting, though that claim has not been confirmed. Coinkite says the fixed firmware restores proper randomness, but a patch cannot rewrite history. Any seed generated on the old software still exists in its weakened form, which is exactly why the advice coming out now has been so blunt.

The people who got hit did everything "right"

This one stings because it landed on the folks who followed the standard advice to the letter. The drained wallets largely belonged to long-term holders who pulled their coins off exchanges years ago and left them sitting untouched in cold storage, which is supposed to be the responsible move. Their reward for being careful was watching those balances vanish while newer and less disciplined traders on custodial platforms were completely unaffected. There is a bitter twist buried in here too. Users who bothered to add their own dice rolls during setup, or who layered on a passphrase or a multisig arrangement, appear to have been protected, because that extra input put back the randomness the firmware had thrown away, and the people most exposed were the ones who simply trusted the device to handle its single most important job.

What to do if you own one

If you have a Coldcard, the guidance from Coinkite is direct: treat your seed as compromised and move your funds. That means updating to the patched firmware, generating a brand new seed on that updated hardware, and then sending everything over to the fresh wallet, because a firmware update on its own fixes nothing when the weak seed already exists. Annoyingly, there is no self-test that tells you whether your particular seed falls inside the guessable range, so the only safe assumption is that it might. You can check your firmware version under the Advanced menu on the device, and anything generated on the vulnerable builds between 2021 and the recent fix should be treated as suspect. Bitcoin slipped about 3% as the scale of the mess sank in, and the timing hands an easy talking point to everyone who has been pushing regulated custodians and spot ETFs over do-it-yourself storage.

The uncomfortable lesson is that "not your keys, not your coins" was always sold as the safer road, and for the most part it still is, but your keys only protect you if they were actually random to begin with. A single quiet build error hid for half a decade inside one of the most trusted names in Bitcoin self-custody, and it took a $70 million heist for anyone to catch it. None of this means hardware wallets are a scam or that cold storage is suddenly dead. It does mean the unglamorous stuff, the firmware updates and the extra entropy and the passphrases and the multisig setups, is the part that quietly saves you, right up until the day it turns out to be the only thing standing between you and an empty wallet.

---------------

Author: Cedric Holloway
New York Newsroom
Breaking Crypto News

Samsung Is Putting Stablecoins on 240 Million Phones... It Just Won't Say Which Ones, or When.

Samsung crypto wallet


Samsung just told hundreds of millions of phone owners they'll soon be able to hold digital dollars right next to their boarding passes and coffee loyalty cards.

At Galaxy Unpacked in London on July 22, the company confirmed that Samsung Wallet will get native stablecoin support, putting dollar-pegged tokens into the same app people already use to tap their phone at the checkout. For an industry that has spent years arguing stablecoins are the killer app for crypto, having one of the biggest hardware makers on earth agree out loud is a big deal. Samsung says the feature would make it one of the first major smartphone brands to support stablecoins natively on its devices, and that reach is the whole story here. This is a company that ships phones by the hundreds of millions every year, so the potential distribution dwarfs anything a standalone crypto wallet could ever dream of building on its own.

And yet, for an announcement this large, Samsung was strangely quiet on the details that actually matter. It showed a mockup with Circle's USDC on stage, then declined to name USDC, Tether, or any other issuer as a confirmed partner. There is no launch date, no word on which blockchains will be supported, no list of eligible countries, and no answer to the single most important question for anyone who cares about their money: will Samsung hold your funds, or will you? That last point, custodial versus non-custodial, is the difference between a real crypto wallet and a glorified balance display, and so far Samsung has said nothing about it. For a feature meant to inspire trust, that is a lot of blanks left unfilled.

The credit card is the part that's actually shipping

Buried under the stablecoin headlines was the thing Samsung actually launched that same day: the Samsung Galaxy Card. It's a credit card issued by Barclays and running on the Visa network, and it went live in the United States on July 22 with no "coming soon" asterisk attached. The rewards structure is aimed squarely at keeping you inside Samsung's world, with 5% back on Samsung purchases, 3% on anything you buy through Samsung Wallet, and 2% on streaming services. On its own that's a fairly ordinary co-branded card, the kind every big brand eventually launches to lock in loyal customers. What makes it interesting is the context, because Samsung is clearly trying to turn Wallet from a place you store a plane ticket into a full financial hub, and stablecoins are meant to be the piece that makes it all feel modern.

Read together, the card and the stablecoin tease point at the same ambition. Samsung wants Wallet to be where you keep money, spend money, and eventually move money, all without opening a separate banking or crypto app. The card handles the spending side today, and it works right now. The stablecoin support, whenever it actually arrives, is supposed to handle the moving-money-around side, letting people send digital dollars roughly as easily as they send a photo. It's a coherent plan on paper, but plans on paper have a habit of slipping, and Samsung gave itself plenty of room to slip by refusing to commit to any date at all.

Wider implications

Even if you never personally plan to keep a single dime of USDC in your phone, if you trade crypto this is good news. Retail crypto adoption has historically gone stablecoins first and speculation second. Someone who already holds a stablecoin balance in an app they trust is a much shorter walk away from buying bitcoin or ether than someone who holds nothing at all and has to sign up for an exchange from scratch. If Samsung genuinely puts even a basic stablecoin feature in front of a big chunk of its user base, it quietly widens the top of the funnel for the entire market. That's a slow-burn effect rather than an overnight one, and it won't show up on a candlestick chart next week no matter how much anyone wants it to.

Which is exactly why you shouldn't expect this to move prices in any immediate way. The crypto industry has a long and unimpressive record of "major partnership" and "mainstream adoption" headlines that felt enormous in the moment and then did absolutely nothing to the charts over the following month. Infrastructure announcements tend to work like that. They matter over years, not days, and this one is especially soft because so much of it is still a mockup and a promise rather than shipping code. Treat it as a directional signal about where consumer fintech is heading, which is clearly toward digital dollars living inside apps you already have, and not as a reason to reposition your portfolio today.

The small print

So where does all this leave things? Samsung has made a loud and credible commitment to putting stablecoins in front of an enormous audience, and that commitment is genuinely meaningful for the long arc of adoption. But a commitment with no named partner, no date, no chain, and no custody model is still mostly a statement of intent, and intent has always been cheap in this industry. The Galaxy Card is real and available now, the stablecoin wallet is a slide and a mockup, and the gap between those two things is worth remembering the next time someone tells you crypto just went mainstream overnight. Watch for the follow-up details in the months ahead, because that's when we'll actually find out whether Samsung is building a real crypto wallet or just a nicer place to stare at a number.

---------------

Author: Ren Nakamura
Asia Newsroom
Breaking Crypto News

Nine of Crypto's Biggest Players Are Racing to Quantum-Proof Bitcoin - and Satoshi's Million Coins Are the One Thing They Can't Save


Nine of the biggest names in crypto just agreed to spend $15 million defending Bitcoin against a machine that does not exist yet.


On July 23, BlackRock, Coinbase, Strategy, Fidelity Digital Assets, Galaxy, ARK Invest, Block, Blockstream and Anchorage Digital announced the Bitcoin Security Consortium, a three-year commitment to fund security research and open-source development for the network they have all bet heavily on. The dollar figure is modest by the standards of any one of these firms, but the message lands louder than the money. These are companies that between them custody or manage hundreds of billions of dollars in Bitcoin, and they are now saying out loud that the cryptography holding it all together needs work before a real threat shows up. That threat, the one everyone keeps circling back to, is quantum computing. The timeline is fuzzy, but the group clearly decided it would rather move early than explain later why it waited.

What the money actually buys

The structure here is worth understanding, because it is not what most people picture when they hear the word "consortium." The $15 million is not pooled into a shared war chest that some committee doles out. Each member directs its own share independently, choosing which developers, researchers or organizations to back with its dollars. The group has said it will not direct Bitcoin's development, will not take sides on proposed protocol changes, and will not touch governance in any form. In plain terms, they are writing checks and then stepping back, which for a network built on the idea that no big player should be able to steer it is a meaningful promise to make in public.

Galaxy had already gotten a head start, launching a separate $5 million quantum readiness effort two days earlier that focuses on quantum-resistant signatures, wallet migration tools and security audits. Whether that money folds into the $15 million total or sits alongside it was never made clear, which is a small reminder that this whole space is still being figured out on the fly. What matters is the direction of travel. A year ago the quantum question lived mostly in academic papers and the darker corners of crypto Twitter. Now it has a line item on the budgets of some of the largest financial firms on the planet, and that shift alone tells you something changed.

Why quantum keeps everyone up at night

Bitcoin's security rests on a type of math that ordinary computers cannot crack in any reasonable amount of time. A powerful enough quantum computer running an approach called Shor's algorithm could change that by working backward from a public key to the private key that controls the coins. The uncomfortable part is that any address that has ever exposed its public key on the blockchain is potentially in range of that kind of attack. Researchers estimate that roughly a quarter of all Bitcoin sits in addresses with exposed public keys, including around 1.9 million BTC in the oldest address format and several million more in addresses that have been reused. Nobody thinks a machine capable of this exists today, and credible estimates put it a few years out.

The scarier wrinkle is that an attacker does not need the quantum computer to exist yet in order to start preparing. Public keys sitting on a public blockchain can be copied and archived right now, then cracked later once the hardware finally catches up. Security researchers have a grim name for this waiting game, calling it "harvest now, decrypt later." It means the clock is already running even though the weapon has not been built, and it explains why firms with a lot of Bitcoin on their books would rather fund the fix years early than gamble on exactly when the threat becomes real. Prevention is a lot cheaper than trying to claw back coins that have already vanished into a quantum attacker's wallet.

The coins nobody can rescue

There is one pile of Bitcoin the consortium's money can never protect, no matter how good the new cryptography gets. Satoshi Nakamoto's estimated one million or so coins sit in the original Pay-to-Public-Key format, with the public keys written directly onto the blockchain for anyone to see. Moving that Bitcoin to a safer, quantum-resistant address would require signing a transaction with Satoshi's private keys, and Bitcoin's creator has been silent for well over a decade. So those coins stay exactly where they are, permanently visible, essentially a giant target that will be sitting there whenever quantum hardware finally arrives. It is one of the stranger tensions in all of crypto, where the founder's untouchable fortune doubles as the network's most obvious weak spot.

The good news is that the tools to fix most of this already exist, since standards bodies have approved several post-quantum signature schemes that Bitcoin could eventually adopt. What has been missing is money, coordination and a sense of urgency from the players with the most to lose, and that is exactly the gap this consortium is trying to close. Fifteen million dollars will not quantum-proof Bitcoin on its own, and the hardest technical and political work of actually changing the protocol still lies ahead. But when firms this large start funding a problem years before it turns into an emergency, it is usually worth paying attention to what has them worried.

---------------

Author: Dorian Fenwick
Silicon Valley Newsroom
Breaking Crypto News

The Hack They Called "Structurally Impossible" in 2023 Just Cost Them $1.65...

Allbridge spent 2023 explaining why this exact attack could never work on its pools again.

On Sunday night an attacker drained roughly $1.65 million in stablecoins out of Allbridge Core's Solana liquidity pools, and the method was not some novel zero-day that nobody saw coming. It was a flash loan pool-ratio manipulation, the same class of attack that hit Allbridge's BNB Chain pools in May 2023 for about $570,000. Back then the team published a postmortem, took the loss on the chin, and committed to an architectural change that was supposed to make the whole category of attack structurally impossible going forward. Three years later, that promise met reality on a different chain, and reality won. The protocol has since paused Core while it investigates.

For anyone who provides liquidity to cross-chain bridges, this one is worth reading past the headline number. The dollar figure is small by 2026 standards, well under what Ostium lost to a compromised oracle key just five days earlier, and nowhere near the nine-figure bridge disasters that defined the last cycle. But the size of the loss is not really the story here. The story is that a documented vulnerability with a documented fix stayed open on a production chain for three years, and nobody caught it until someone with a Kamino account decided to check.

How the attacker allegedly pulled it off

The sequence started with a $1.12 million flash loan taken from Kamino, a Solana lending protocol. Flash loans let you borrow a large sum with no collateral as long as you repay it inside the same transaction, which makes them perfect for anyone who wants temporary size to push a pool out of balance. The attacker used that borrowed capital to rapidly swap USDC for USDT inside Allbridge's Solana pools, skewing the ratio between the two assets far away from where it should sit. Allbridge's pricing math then treated that distorted ratio as real, which let the attacker withdraw more value than they put in. Repeat the loop, repay the loan, keep the difference, and walk away with roughly $1.65 million in about the time it takes to read this paragraph.

None of that is exotic. Flash loan pool manipulation has been in every DeFi security checklist since 2020, and auditors flag it as a matter of routine. What makes it work is a specific structural condition: two or more swappable assets sitting in pools that can be interacted with inside a single atomic transaction. Remove that condition and the attack has nothing to grip. That is precisely what Allbridge said it was doing after the BNB Chain incident.

The 2023 fix that never reached Solana

After the May 2023 attack, Allbridge's stated remedy was to move to a single liquidity pool per blockchain. One pool means no sibling pool to swap against, no ratio to distort, and no path for a flash loan to do anything useful. On paper it is a clean fix, and it is the kind of answer that reassures depositors because it changes the shape of the system rather than patching a symptom. The team also recovered roughly $465,000 of the 2023 losses through a white-hat arrangement with the attacker, which at the time looked like a reasonably competent handling of a bad week.

The Solana deployment, though, was still running USDC and USDT pools side by side. That is exactly the configuration the single-pool policy was meant to retire. Whether it was never migrated, was migrated and later reverted, or simply predates the policy in a way nobody revisited, the practical result is the same. A security commitment that existed in a blog post did not exist in the code on at least one chain, and there was apparently no process catching the gap. On-chain analysts including researchers tracking the incident flagged the pause and the fund movements within hours.

Where the money went, and what Allbridge is asking for

The stolen stablecoins were bridged from Solana to Ethereum and then split across multiple addresses, with portions reportedly routed into privacy pools to make tracing harder. That is a familiar pattern at this point and it usually means recovery odds drop sharply once the funds land. Allbridge has paused Core operations, advised liquidity providers to withdraw, and made an additional request that says a lot about how these events actually unfold: it asked traders who profited from the temporary pool imbalance to send the money back. Ordinary arbitrage bots almost certainly picked up free value while the pools were skewed, and those operators did nothing wrong beyond taking a trade the market offered them. Getting that money back is a matter of goodwill, not enforcement, so nobody should count on it.

There is no compensation plan announced yet and no timeline for Core coming back online. Anyone with capital still parked in Allbridge pools on any chain should treat the withdrawal advisory as the operative instruction rather than waiting to see how the investigation reads.

Lessons Learned?

Bridges remain one of the most attacked surfaces in crypto for an obvious reason: they concentrate a lot of idle capital in contracts that have to trust conditions on two different chains at once. What happened here is worse than a clever exploit, because a clever exploit at least implies the defenders were beaten by something new. This was a known attack against a known configuration on a protocol that had already been burned by it once and had publicly described the cure.

If you provide liquidity anywhere, the useful takeaway is that a postmortem is a statement of intent, not proof of work completed. Ask which chains a fix actually shipped to. Multi-chain deployments drift, and the chain everyone stopped watching is the one that gets hit. Allbridge will probably survive this given the modest size of the loss, but the reputational damage of getting caught by your own 2023 homework is going to stick around a lot longer than $1.65 million.

---------------

Author: Rowan Marrow
Seattle Newsroom
Breaking Crypto News

Ethical Hackers Found a Way to Break a $70 Billion Blockchain - With a $3,000 Budget...

Turns out you don't need a nation-state budget to threaten a multi-billion dollar blockchain. You need about $3,000 and a very good weekend.

That is the uncomfortable lesson from a disclosure that went public on July 4, when security firm Hexens revealed a critical flaw it found in Aptos back in February. The bug lived inside the Move virtual machine, the engine that runs every smart contract on the chain, and it was serious enough that Hexens put the first-order systemic risk at roughly $70 billion. For a network that markets itself on speed and safety, that is not a number anyone wants attached to their name. The good news, which we will get to, is that no funds were ever lost. The bad news is how little it would have taken to change that.

The story matters because Aptos is not some abandoned testnet. It is a top-tier layer-1 with real stablecoins, real bridges, and real money parked in its ecosystem. When a researcher tells you a flaw could have reached that much value, they are not just talking about tokens sitting in wallets. They are talking about the plumbing that connects Aptos to the rest of crypto. And the people who found this did it on a budget that would not cover a decent gaming PC.

What they actually found

Hexens described the issue as a "stale-cache bug" that led to a type-confusion vulnerability. In plain terms, that means the software could be tricked into treating one kind of on-chain resource as if it were a completely different one. If you have ever handed someone the wrong key and watched them open a door they were never supposed to touch, you get the general idea. According to the firm, the flaw let an attacker potentially hijack on-chain structs and authority resources, which are the core data structures that decide who owns what and who is allowed to do what. Mess with those, and the normal rules about ownership stop meaning very much.

Type confusion is one of those bug classes that sounds academic until it is pointed at real money. It has haunted traditional software for decades, and the Move language was specifically designed to make this sort of thing hard to pull off. That is part of why this disclosure stings a little. The whole selling point of Move is that it treats digital assets as a special resource the compiler guards closely, so seeing a type-confusion flaw surface in Aptos is a bit like finding a leak in the one boat everyone promised was unsinkable.

The scary part: It took $3,000 to make it happen

Plenty of blockchain exploits require deep pockets, insider access, or control of a big chunk of the network. This one, allegedly, did not. Hexens says it simulated the attack under real network conditions with a success rate above 90 percent, using a server setup that cost around $3,000 and stood in for roughly a third of the validator set. No special permissions, no insider help, no cooperation from anyone already inside the system. That combination is what turns a technical curiosity into a genuine emergency, because it means the barrier to entry was almost nothing. When the cost of breaking something is measured in hundreds or low thousands of dollars and the prize is measured in billions, you are relying entirely on nobody else noticing first.

Where the $70 billion number comes from

A $70 billion figure sounds almost cartoonish for a chain whose own token market cap is a fraction of that, so it is worth explaining. Hexens was not claiming $70 billion sits directly on Aptos. The estimate covers everything the flaw could have reached through the connections crypto has quietly built over the last few years. That includes value moving across bridges, cross-chain messaging systems, stablecoin administration flows, and assets custodied by centralized exchanges that touch the network. Modern crypto is stitched together, and a hole in one important chain does not stay politely contained to that chain. That is the real warning here, and it applies to a lot more than just Aptos.

The quiet fix nobody heard about until now

Here is the part that keeps this from being a horror story. Hexens reported the flaw through Aptos Labs' bug bounty program on February 25, and the team says a fix was developed, tested, and pushed to mainnet within hours of discovery. An Aptos spokesperson told CoinDesk that no users or funds were impacted at any point, and the details were only made public months later, which is exactly how responsible disclosure is supposed to work. The researchers got paid, the hole got patched before anyone with bad intentions found it, and the wider world found out once it was safe to talk about.

Still, it is worth sitting with what almost happened. A flaw that could have rippled across $70 billion in connected value was closed off by a bug bounty and a fast engineering response, not by luck at the moment of attack. If white-hat researchers had not gotten there first, this would read very differently. The lesson for anyone holding crypto is not to panic about Aptos specifically, which is now patched, but to notice how much of this industry's safety still depends on a small group of ethical hackers choosing to send an email instead of draining a wallet. That is a thin line to be standing on, and it is worth remembering the next time a chain tells you it is unbreakable.

---------------

Author: Dorian Fenwick
Silicon Valley Newsroom
Breaking Crypto News

236,000 Crypto Scam Sites Trace Back to a Single Chinese App Builder...

Crypto scam network glow

A new investigation just put a number on something every crypto user should be worried about.

Threat intel firm Infoblox identified 236,493 distinct second-level domains that are all built on the same Chinese open-source app framework, DCloud Uni-App, and a huge portion of them exist for one purpose, which is to drain crypto wallets and run fake exchanges. The framework itself is perfectly legitimate, used by real developers around the world to ship apps to iOS, Android, and the web from a single codebase. That same convenience is what makes it so attractive to fraud crews. They get a polished, mobile-friendly fake exchange or fake investment dashboard in days instead of months, and the underlying code looks indistinguishable from a thousand actual startups.

Why This Is Worse Than the Usual Scam Site Sprawl

The numbers tell their own story about how quickly this got out of hand. Before October 2024, Infoblox was seeing a few thousand new DCloud-fingerprinted scam sites appear each month, which already would be a lot. After the RainbowEx scandal broke into international headlines that fall, the rate ballooned to roughly 15,000 newly observed sites per month at peak. Scammers apparently looked at the press coverage and decided the playbook was worth copying at scale, not abandoning. The sites target speakers of at least eight languages and span every continent, posing as everything from major stock exchanges to retail giants to messaging platforms. Most of them are hosted on Cloudflare, AWS, Alibaba Cloud, and Tencent Cloud, which lets them blend in with real businesses and makes simple IP blocklists basically useless.

Few RainbowEx and the Argentine Town That Got Wiped Out

If you want a sense of what victims actually experience, the RainbowEx case is the textbook example. In 2024, residents of San Pedro, Argentina poured money into what looked like a slick cryptocurrency exchange. The dashboard showed live trades, balances climbed steadily, and stablecoin deposits flowed in without issue. Then withdrawals stopped working. Thousands of people in a single small town discovered the trades had been fabricated, the balances were synthetic, and the operators were gone. Argentine authorities later arrested seven people allegedly tied to the operation, but most of the money is gone, and the exact same template, with cosmetic branding changes, is now running on a measurable percentage of those 236,000 domains.

What an Average Trader Should Actually Do About It

There is no clean solution here, because the underlying framework is legitimate software and the hosts are mainstream cloud providers who cannot deplatform their entire customer base. About 6% of confirmed scam domains were found running on bulletproof hosts like CTG Server Limited, which has been flagged for malicious activity before, so at least those have a clear villain. The rest hide in normal traffic. Anyone evaluating a new exchange, airdrop site, or investment opportunity found through a Telegram group, WhatsApp chat, or Twitter DM should treat the polish of the website as evidence of nothing at all. Check whether the company is registered anywhere real, whether withdrawals actually work for small amounts before sending large ones, and whether the domain was registered in the last few months. If the answer to any of those raises a flag, walk away. The Hacker News has additional technical detail for anyone who wants to dig deeper.

The takeaway from this count is uncomfortable but useful. The crypto scam economy is no longer a scattered collection of one-off sites built by individual scammers working in their basements. It is an industrial production line running on shared tooling, mainstream hosting, and proven playbooks, and 236,000 storefronts is just what was visible enough to count. Treat every unfamiliar exchange link the way you would treat an unsolicited email asking for your password, because at this scale, the odds are not in your favor.

---------------

Author: Ren Nakamura
Asia Newsroom
Breaking Crypto News