Hunter Biden’s LAPTOP Token Crashes 99% Since Launch — He Blames “Snipers,” Denies Profiting a Si...
Hunter Biden’s $LAPTOP memecoin has collapsed more than 99% from its all-time high just one day after launch, with the token now trading around $0.77 and holding a market capitalization of roughly $275 million — a staggering fall from its peak price of $199.51 reached within minutes of going live. Biden responded publicly on X, insisting the crash was not a rug pull, denying he personally profited, and blaming thin liquidity, technical glitches, and predatory traders known as “snipers.” The Numbers Behind the Crash $LAPTOP launched September 9, 2026, on Coinbase’s Base blockchain network. According to CoinGecko data, the token opened trading near $3 before spiking wildly within minutes, with different tracking platforms reporting intraday highs ranging from roughly $190 to over $400, depending on the exact pool and timestamp measured — a divergence typical of extremely thin liquidity pools during a chaotic launch. Blockchain intelligence firm Arkham reported that at the token’s absolute peak, its fully diluted valuation (FDV) briefly touched an eye-watering $144 billion, even though the liquidity pool actually backing that price consisted of just $48,000. That imbalance made a collapse effectively inevitable. Within 30 minutes, Arkham reported LAPTOP’s FDV had already fallen to roughly $5 billion. By the following day, the token was trading at approximately $0.77 — down more than 99% from its all-time high of $199.51 — with a market cap near $275 million and a fully diluted valuation of roughly $787 million, according to CoinGecko. Hunter Biden’s Response Biden addressed the crash directly on X, pushing back against media coverage he characterized as misleading. “As you may have seen, the LAPTOP memecoin saw a sharp swing in token price during its first hours of trading,” he wrote. “The headlines are all the same. Token down 99%. Rug pull. Biden Crime Family. The list goes on. This is far from the truth.” He offered a technical explanation for the collapse: “The reality is that available liquidity could not sustain the strong level of interest at launch. Technical issues coupled with predatory ‘snipers,’ who seek to beat liquidity providers to market, caused a spike in price, which has since stabilized to healthy levels.” Biden was also explicit about his own financial involvement, stating the founders’ token allocation remains locked and unsold: “The team’s allocation is locked. Nobody on our side sold, and nobody could have. I, personally, have not made a single dollar.” He noted the fully diluted valuation still sits above $1 billion and said the team is “actively working on the best solutions to optimize liquidity and continue engaging my community.” He also defended the project’s decision to airdrop tokens to wallets that lost money on President Trump’s $TRUMP memecoin, saying, “Somehow the media is painting that as a ‘failure.'” What LAPTOP Actually Is and Why It Launched The token takes its name from the laptop Hunter Biden dropped off at a Delaware repair shop in April 2019 — a device the FBI later seized and whose contents became a major flashpoint in conservative media coverage ahead of the 2020 presidential election. Biden has framed the coin’s launch as an attempt to reclaim ownership of a symbol that dominated years of hostile press coverage about him. According to reporting from the Wall Street Journal and CoinMarketCap, LAPTOP has a total supply of 1 billion tokens, with 35% unlocked at the token’s generation event and the remainder subject to vesting schedules and cliffs extending over 36 months. Founders, including Biden himself, hold 30% of supply, locked for six months with vesting over two years. Another 20% was earmarked for community airdrops distributed in two batches — targeting wallets that had previously lost money on the $TRUMP memecoin, subscribers to Biden’s Substack newsletter, and a mailing list associated with video journalist Andrew Callaghan, who has publicly stated he has no involvement with the project. The token’s economics also include a burn mechanism tied to 30 predetermined outcomes, one of which reportedly involves whether LAPTOP’s market cap ever surpasses that of $TRUMP. On-Chain Activity Raises Questions Blockchain analysis firms tracked significant market maker and early-holder activity during the crash. Arkham data showed market maker GSR received 15.5 million tokens four days before launch, routed through an intermediary address, and began distributing them shortly after trading opened, including transfers of 9 million, 1.5 million, and 500,000 tokens. Trading firm Wintermute separately received roughly 1.8–2.5 million tokens from the project’s Gnosis Safe wallet around launch. According to on-chain tracker lookonchain, one wallet turned a $900 investment into more than $250,000 by selling tokens purchased at $0.40 for an average price of $111 — a 278x return — illustrating how early insiders and bots profited heavily from the volatility that ordinary buyers were caught in. Community Reaction Has Been Overwhelmingly Negative Reaction across crypto social media has been sharply critical, with many traders and commentators explicitly labeling the launch a rug pull rather than accepting Biden’s liquidity-based explanation. Crypto commentator Ash Crypto wrote on X, “THIS IS INSANE… Hunter Biden’s memecoin, LAPTOP crashed 98% within minutes of its launch. It was supposed to compensate the TRUMP losers.” Another trader, Geiger Capital, posted: “Hunter Biden just launched his memecoin… Immediately down -99%. Absolutely perfect.” Adding to the controversy, the project’s official X account reportedly went silent and was suspended following the crash, a development Biden has said the team is working to resolve. What Comes Next With the token now trading roughly 99% below its launch-day peak and community trust already damaged, LAPTOP’s survival will likely hinge on whether the project can demonstrate the liquidity improvements Biden has promised and whether the locked founder allocation genuinely remains untouched over the coming months, as claimed. For now, the episode stands as one of the most volatile political memecoin launches to date — surpassing even the early turbulence of Trump’s own $TRUMP token — and has reignited broader scrutiny over how thinly-liquid celebrity and political memecoins are structured at launch.
Hunter Biden’s LAPTOP Token Crashes 99% Since Launch — He Blames “Snipers,” Denies Profiting a Si...
Hunter Biden’s $LAPTOP memecoin has collapsed more than 99% from its all-time high just one day after launch, with the token now trading around $0.77 and holding a market capitalization of roughly $275 million — a staggering fall from its peak price of $199.51 reached within minutes of going live. Biden responded publicly on X, insisting the crash was not a rug pull, denying he personally profited, and blaming thin liquidity, technical glitches, and predatory traders known as “snipers.” The Numbers Behind the Crash $LAPTOP launched September 9, 2026, on Coinbase’s Base blockchain network. According to CoinGecko data, the token opened trading near $3 before spiking wildly within minutes, with different tracking platforms reporting intraday highs ranging from roughly $190 to over $400, depending on the exact pool and timestamp measured — a divergence typical of extremely thin liquidity pools during a chaotic launch. Blockchain intelligence firm Arkham reported that at the token’s absolute peak, its fully diluted valuation (FDV) briefly touched an eye-watering $144 billion, even though the liquidity pool actually backing that price consisted of just $48,000. That imbalance made a collapse effectively inevitable. Within 30 minutes, Arkham reported LAPTOP’s FDV had already fallen to roughly $5 billion. By the following day, the token was trading at approximately $0.77 — down more than 99% from its all-time high of $199.51 — with a market cap near $275 million and a fully diluted valuation of roughly $787 million, according to CoinGecko. Hunter Biden’s Response Biden addressed the crash directly on X, pushing back against media coverage he characterized as misleading. “As you may have seen, the LAPTOP memecoin saw a sharp swing in token price during its first hours of trading,” he wrote. “The headlines are all the same. Token down 99%. Rug pull. Biden Crime Family. The list goes on. This is far from the truth.” He offered a technical explanation for the collapse: “The reality is that available liquidity could not sustain the strong level of interest at launch. Technical issues coupled with predatory ‘snipers,’ who seek to beat liquidity providers to market, caused a spike in price, which has since stabilized to healthy levels.” Biden was also explicit about his own financial involvement, stating the founders’ token allocation remains locked and unsold: “The team’s allocation is locked. Nobody on our side sold, and nobody could have. I, personally, have not made a single dollar.” He noted the fully diluted valuation still sits above $1 billion and said the team is “actively working on the best solutions to optimize liquidity and continue engaging my community.” He also defended the project’s decision to airdrop tokens to wallets that lost money on President Trump’s $TRUMP memecoin, saying, “Somehow the media is painting that as a ‘failure.'” What LAPTOP Actually Is and Why It Launched The token takes its name from the laptop Hunter Biden dropped off at a Delaware repair shop in April 2019 — a device the FBI later seized and whose contents became a major flashpoint in conservative media coverage ahead of the 2020 presidential election. Biden has framed the coin’s launch as an attempt to reclaim ownership of a symbol that dominated years of hostile press coverage about him. According to reporting from the Wall Street Journal and CoinMarketCap, LAPTOP has a total supply of 1 billion tokens, with 35% unlocked at the token’s generation event and the remainder subject to vesting schedules and cliffs extending over 36 months. Founders, including Biden himself, hold 30% of supply, locked for six months with vesting over two years. Another 20% was earmarked for community airdrops distributed in two batches — targeting wallets that had previously lost money on the $TRUMP memecoin, subscribers to Biden’s Substack newsletter, and a mailing list associated with video journalist Andrew Callaghan, who has publicly stated he has no involvement with the project. The token’s economics also include a burn mechanism tied to 30 predetermined outcomes, one of which reportedly involves whether LAPTOP’s market cap ever surpasses that of $TRUMP. On-Chain Activity Raises Questions Blockchain analysis firms tracked significant market maker and early-holder activity during the crash. Arkham data showed market maker GSR received 15.5 million tokens four days before launch, routed through an intermediary address, and began distributing them shortly after trading opened, including transfers of 9 million, 1.5 million, and 500,000 tokens. Trading firm Wintermute separately received roughly 1.8–2.5 million tokens from the project’s Gnosis Safe wallet around launch. According to on-chain tracker lookonchain, one wallet turned a $900 investment into more than $250,000 by selling tokens purchased at $0.40 for an average price of $111 — a 278x return — illustrating how early insiders and bots profited heavily from the volatility that ordinary buyers were caught in. Community Reaction Has Been Overwhelmingly Negative Reaction across crypto social media has been sharply critical, with many traders and commentators explicitly labeling the launch a rug pull rather than accepting Biden’s liquidity-based explanation. Crypto commentator Ash Crypto wrote on X, “THIS IS INSANE… Hunter Biden’s memecoin, LAPTOP crashed 98% within minutes of its launch. It was supposed to compensate the TRUMP losers.” Another trader, Geiger Capital, posted: “Hunter Biden just launched his memecoin… Immediately down -99%. Absolutely perfect.” Adding to the controversy, the project’s official X account reportedly went silent and was suspended following the crash, a development Biden has said the team is working to resolve. What Comes Next With the token now trading roughly 99% below its launch-day peak and community trust already damaged, LAPTOP’s survival will likely hinge on whether the project can demonstrate the liquidity improvements Biden has promised and whether the locked founder allocation genuinely remains untouched over the coming months, as claimed. For now, the episode stands as one of the most volatile political memecoin launches to date — surpassing even the early turbulence of Trump’s own $TRUMP token — and has reignited broader scrutiny over how thinly-liquid celebrity and political memecoins are structured at launch.
22-Year-Old Singaporean Admits Leading $245 Million Cryptocurrency Theft Scheme
A 22-year-old Singaporean man has pleaded guilty in a U.S. federal court to orchestrating one of the largest cryptocurrency thefts ever prosecuted, admitting to leading a criminal network that stole $245 million in Bitcoin through social engineering, hacking, and even home burglaries — then blew through the proceeds on nightclubs, luxury cars, and designer handbags, BBC reports. The Guilty Plea Malone Lam entered his guilty plea Tuesday to a racketeering conspiracy charge in U.S. District Court, admitting he organized a scheme with friends and online acquaintances to steal $245 million worth of Bitcoin and subsequently launder the proceeds. Lam now faces a maximum possible sentence of 20 years in federal prison. U.S. District Judge Colleen Kollar-Kotelly, who is overseeing the case, did not immediately schedule a sentencing hearing. U.S. Attorney Jeanine Pirro issued a pointed warning following the plea: “If you build a cybercrime empire, we will find you, dismantle your operation, and hold you accountable.” She added that Lam “led an international network that preyed on victims through deception, invaded their privacy, and stole hundreds of millions of dollars in cryptocurrency.” Who Is Malone Lam Lam grew up in Singapore, attending Unity Secondary School in Choa Chu Kang before dropping out of school entirely by age 14. During his teenage years, he became deeply involved in cryptocurrency trading and online gaming communities, including Minecraft and Discord — platforms that would later become central to how he recruited his criminal network. In October 2023, Lam traveled to the United States and settled across multiple locations, including Miami, Los Angeles, and the Hamptons. He entered the country through the Visa Waiver Program, and remained in the U.S. after that authorization expired in January 2024, continuing his criminal activity while living in the country without valid immigration status. How the Criminal Network Operated According to federal prosecutors, Lam launched what investigators have termed the “Social Engineering Enterprise” together with two roommates while living in Texas. Over the following months, the operation expanded to include 14 members spread across California, Connecticut, New York, Florida, and locations outside the United States. Prosecutors say the group’s members connected and coordinated primarily through online gaming platforms. The network identified potential victims — specifically individuals holding large amounts of cryptocurrency — through multiple methods, including hacked databases, personal information purchased on dark web marketplaces, and targeted phishing emails. Once a victim was identified, the group used social engineering tactics to trick them into surrendering confidential account information, which was then used to drain their cryptocurrency wallets. The scheme escalated significantly by 2024. According to court documents, group members began arming themselves with firearms, and on July 8, 2024, the network carried out a physical home invasion, burglarizing a victim’s residence in New Mexico specifically to steal hardware wallets containing cryptocurrency. According to The New York Times, Lam and co-conspirator Jeandiel Serrano even live-streamed one of their social engineering heists to friends online in real time. Where the Stolen Money Went Federal prosecutors detailed an extraordinary spending spree fueled by the stolen funds. According to the Department of Justice, Lam and his associates spent as much as $500,000 in a single evening at nightclubs. The group purchased a fleet of exotic vehicles — reportedly more than 30 high-end luxury automobiles in total — ranging in individual value from $100,000 to $3.8 million. Additional purchases documented by prosecutors included Hermès Birkin handbags worth tens of thousands of dollars each, which the group reportedly threw into crowds during nightclub parties; high-end watches valued up to $500,000; designer clothing worth tens of thousands of dollars; rental properties in Los Angeles, the Hamptons, and Miami; private jet charters; and a dedicated team of private security guards. Lam became a recognizable, “notorious” figure within the Los Angeles and Miami nightclub scenes because of his flamboyant spending habits, and his sudden cryptocurrency wealth drew significant attention even before his arrest, according to testimony heard in a Florida district court. The Arrest and Court Reaction The FBI arrested Lam along with a co-conspirator in Miami on September 18, 2024, effectively dismantling the operation. According to reports, Lam threw his mobile phone into Biscayne Bay in an apparent attempt to destroy evidence just before his arrest, after an off-duty police officer had reportedly tipped him off about his impending detention. At Lam’s first court appearance, U.S. Magistrate Judge Alicia Valle offered a striking characterization of the case: “As I was listening to the evidence, I could only think of Ferris Bueller gone bad” — a reference to the 1986 film about a teenager who fakes illness to skip school for a day of reckless adventure through Chicago. The judge elaborated: “[He] spent this money wildly, going to Los Angeles nightclubs, purchasing more than 30 high-end luxury automobiles. I mean, [that’s] an incredible amount of spending and craziness that followed his coming into more than $230 million.” Prosecuting the Wider Network Lam was not operating alone, and prosecutors have continued pursuing other members of the criminal enterprise. In April of this year, co-conspirator Evan Tangeman was sentenced to 70 months in federal prison specifically for laundering proceeds from the scheme. Prosecutors noted that Tangeman had additionally attempted to destroy evidence following Lam’s arrest — behavior the court explicitly treated as evidence of “consciousness of his guilt” when determining his sentence. According to court filings, the criminal conspiracy is believed to have begun no later than October 2023 and continued operating until at least May 2025 — meaning the network’s activities persisted for roughly eight months even after Lam himself had already been arrested and taken into custody, underscoring how deeply the enterprise had been structured to continue functioning independent of any single member. Why This Case Matters The Lam case stands out even within the increasingly crowded landscape of cryptocurrency theft prosecutions, both for the sheer scale of the loss — $245 million — and for the network’s willingness to escalate from purely digital social engineering into armed, physical home invasions to obtain hardware wallets. That progression illustrates a broader and increasingly documented trend within crypto crime: as cryptocurrency holdings have grown large enough to represent life-changing sums, some criminal networks have shown a willingness to move beyond phishing and hacking into physical violence and coercion, sometimes referred to within the industry as “wrench attacks.” What Happens Next With Lam’s guilty plea now entered, the case moves toward sentencing, though Judge Kollar-Kotelly has not yet set a date for that hearing. Given the maximum 20-year sentence he faces and the precedent set by his co-conspirator’s 70-month sentence for a comparatively smaller role in laundering, prosecutors are likely to push for a substantial prison term reflecting both the scale of the theft and Lam’s position as the network’s identified ringleader. For victims of the scheme and for the broader cryptocurrency industry, the case serves as a stark illustration of how far organized criminal networks are now willing to go — combining digital deception with real-world violence — to target individuals holding substantial digital wealth.
22-Year-Old Singaporean Admits Leading $245 Million Cryptocurrency Theft Scheme
A 22-year-old Singaporean man has pleaded guilty in a U.S. federal court to orchestrating one of the largest cryptocurrency thefts ever prosecuted, admitting to leading a criminal network that stole $245 million in Bitcoin through social engineering, hacking, and even home burglaries — then blew through the proceeds on nightclubs, luxury cars, and designer handbags, BBC reports. The Guilty Plea Malone Lam entered his guilty plea Tuesday to a racketeering conspiracy charge in U.S. District Court, admitting he organized a scheme with friends and online acquaintances to steal $245 million worth of Bitcoin and subsequently launder the proceeds. Lam now faces a maximum possible sentence of 20 years in federal prison. U.S. District Judge Colleen Kollar-Kotelly, who is overseeing the case, did not immediately schedule a sentencing hearing. U.S. Attorney Jeanine Pirro issued a pointed warning following the plea: “If you build a cybercrime empire, we will find you, dismantle your operation, and hold you accountable.” She added that Lam “led an international network that preyed on victims through deception, invaded their privacy, and stole hundreds of millions of dollars in cryptocurrency.” Who Is Malone Lam Lam grew up in Singapore, attending Unity Secondary School in Choa Chu Kang before dropping out of school entirely by age 14. During his teenage years, he became deeply involved in cryptocurrency trading and online gaming communities, including Minecraft and Discord — platforms that would later become central to how he recruited his criminal network. In October 2023, Lam traveled to the United States and settled across multiple locations, including Miami, Los Angeles, and the Hamptons. He entered the country through the Visa Waiver Program, and remained in the U.S. after that authorization expired in January 2024, continuing his criminal activity while living in the country without valid immigration status. How the Criminal Network Operated According to federal prosecutors, Lam launched what investigators have termed the “Social Engineering Enterprise” together with two roommates while living in Texas. Over the following months, the operation expanded to include 14 members spread across California, Connecticut, New York, Florida, and locations outside the United States. Prosecutors say the group’s members connected and coordinated primarily through online gaming platforms. The network identified potential victims — specifically individuals holding large amounts of cryptocurrency — through multiple methods, including hacked databases, personal information purchased on dark web marketplaces, and targeted phishing emails. Once a victim was identified, the group used social engineering tactics to trick them into surrendering confidential account information, which was then used to drain their cryptocurrency wallets. The scheme escalated significantly by 2024. According to court documents, group members began arming themselves with firearms, and on July 8, 2024, the network carried out a physical home invasion, burglarizing a victim’s residence in New Mexico specifically to steal hardware wallets containing cryptocurrency. According to The New York Times, Lam and co-conspirator Jeandiel Serrano even live-streamed one of their social engineering heists to friends online in real time. Where the Stolen Money Went Federal prosecutors detailed an extraordinary spending spree fueled by the stolen funds. According to the Department of Justice, Lam and his associates spent as much as $500,000 in a single evening at nightclubs. The group purchased a fleet of exotic vehicles — reportedly more than 30 high-end luxury automobiles in total — ranging in individual value from $100,000 to $3.8 million. Additional purchases documented by prosecutors included Hermès Birkin handbags worth tens of thousands of dollars each, which the group reportedly threw into crowds during nightclub parties; high-end watches valued up to $500,000; designer clothing worth tens of thousands of dollars; rental properties in Los Angeles, the Hamptons, and Miami; private jet charters; and a dedicated team of private security guards. Lam became a recognizable, “notorious” figure within the Los Angeles and Miami nightclub scenes because of his flamboyant spending habits, and his sudden cryptocurrency wealth drew significant attention even before his arrest, according to testimony heard in a Florida district court. The Arrest and Court Reaction The FBI arrested Lam along with a co-conspirator in Miami on September 18, 2024, effectively dismantling the operation. According to reports, Lam threw his mobile phone into Biscayne Bay in an apparent attempt to destroy evidence just before his arrest, after an off-duty police officer had reportedly tipped him off about his impending detention. At Lam’s first court appearance, U.S. Magistrate Judge Alicia Valle offered a striking characterization of the case: “As I was listening to the evidence, I could only think of Ferris Bueller gone bad” — a reference to the 1986 film about a teenager who fakes illness to skip school for a day of reckless adventure through Chicago. The judge elaborated: “[He] spent this money wildly, going to Los Angeles nightclubs, purchasing more than 30 high-end luxury automobiles. I mean, [that’s] an incredible amount of spending and craziness that followed his coming into more than $230 million.” Prosecuting the Wider Network Lam was not operating alone, and prosecutors have continued pursuing other members of the criminal enterprise. In April of this year, co-conspirator Evan Tangeman was sentenced to 70 months in federal prison specifically for laundering proceeds from the scheme. Prosecutors noted that Tangeman had additionally attempted to destroy evidence following Lam’s arrest — behavior the court explicitly treated as evidence of “consciousness of his guilt” when determining his sentence. According to court filings, the criminal conspiracy is believed to have begun no later than October 2023 and continued operating until at least May 2025 — meaning the network’s activities persisted for roughly eight months even after Lam himself had already been arrested and taken into custody, underscoring how deeply the enterprise had been structured to continue functioning independent of any single member. Why This Case Matters The Lam case stands out even within the increasingly crowded landscape of cryptocurrency theft prosecutions, both for the sheer scale of the loss — $245 million — and for the network’s willingness to escalate from purely digital social engineering into armed, physical home invasions to obtain hardware wallets. That progression illustrates a broader and increasingly documented trend within crypto crime: as cryptocurrency holdings have grown large enough to represent life-changing sums, some criminal networks have shown a willingness to move beyond phishing and hacking into physical violence and coercion, sometimes referred to within the industry as “wrench attacks.” What Happens Next With Lam’s guilty plea now entered, the case moves toward sentencing, though Judge Kollar-Kotelly has not yet set a date for that hearing. Given the maximum 20-year sentence he faces and the precedent set by his co-conspirator’s 70-month sentence for a comparatively smaller role in laundering, prosecutors are likely to push for a substantial prison term reflecting both the scale of the theft and Lam’s position as the network’s identified ringleader. For victims of the scheme and for the broader cryptocurrency industry, the case serves as a stark illustration of how far organized criminal networks are now willing to go — combining digital deception with real-world violence — to target individuals holding substantial digital wealth.
Hunter Biden Launches $LAPTOP Memecoin, the Latest Political Token to Follow $TRUMP’s Lead
Hunter Biden, son of former President Joe Biden, is launching his own cryptocurrency built directly around the controversial laptop that became a flashpoint of the 2020 presidential election. The token, called $LAPTOP, is scheduled to debut September 9 on Base, the Ethereum layer-2 blockchain network created by Coinbase Global, according to reporting from the Wall Street Journal citing people familiar with the matter. How the Announcement Unfolded The Journal first reported the launch Monday morning. Shortly afterward, Biden confirmed the news himself, posting “$LAPTOP” alongside a September 9 launch date on X, accompanied by a compilation video featuring news outlets and Trump administration officials referencing the laptop saga over the years. The announcement transforms one of the most politically weaponized personal scandals of the past decade into a tradeable digital asset. The Laptop’s Origin Story The laptop at the center of the controversy was dropped off at a computer repair shop in Wilmington, Delaware, in April 2019. The shop’s owner later provided its contents to the FBI, which formally seized the device roughly five months later. The laptop reportedly contained emails, financial documents, and business records, along with explicit personal photos and images appearing to show Biden using drugs. The device and its contents became a major media flashpoint in conservative-leaning outlets in the run-up to the 2020 election, fueling extensive political commentary and investigations into Hunter Biden’s business dealings. Biden’s legal team has previously stated that the files were manipulated, disputing the authenticity of some material that circulated publicly. Biden himself has continued discussing the episode candidly on social media, Substack, and various podcast appearances in recent months. In a June post on X, he wrote: “What they found was evidence of a man who suffered for a period of time from a severe addiction to crack cocaine and alcohol,” adding that federal prosecutors ultimately found no evidence of corruption or criminal activity beyond matters related to his drug use. Biden’s Crypto Advocacy The memecoin launch follows a period of increasingly vocal public support for digital assets from Biden. He has previously argued on X that Congress needs “to truly understand the value and potential utility of cryptocurrency,” and separately described “decentralized digital currency” as “the inevitable future” — positioning himself, at least rhetorically, as a crypto advocate ahead of his own token launch. Token Structure and Distribution According to details of the launch, $LAPTOP will have a total supply of 1 billion tokens. The distribution plan allocates 30% to the project’s founders, subject to a vesting schedule restricting when those tokens can be sold, while another 20% will be distributed via airdrops to selected cryptocurrency holders and newsletter or platform subscribers. The project has also outlined plans to burn — permanently remove from circulation — up to 30% of the total token supply if specific political or market-related milestones are met, though the precise nature of those milestones has not been fully detailed publicly. Notably, Pump.fun, a popular Solana-based token launch platform, initially published a post referencing the $LAPTOP launch before subsequently deleting it — a detail that has fueled speculation among crypto observers about the platform’s level of involvement or its decision to distance itself from the project. Part of a Broader Trend of Political Memecoins Biden’s launch places him within a growing category of politically branded cryptocurrencies that has gained significant traction since early 2025, most notably the $TRUMP token. That coin, built on the Solana blockchain, launched in January 2025 just ahead of Donald Trump’s second presidential inauguration, announced via Truth Social and X on January 17-18, 2025. Its branding drew directly on imagery from the July 2024 assassination attempt against Trump in Butler, Pennsylvania, featuring the president with a raised fist alongside the phrase “FIGHT FIGHT FIGHT.” Of the token’s 1 billion total supply, 200 million coins were released publicly in the initial offering, while Trump-affiliated companies retained the remaining 800 million. First Lady Melania Trump subsequently launched a companion token of her own. $TRUMP’s price trajectory has been extremely volatile: the token peaked between $73 and $75 shortly after its January 2025 launch, before falling to an all-time low of $1.37 on August 13, 2026. As of recent trading, the token sits around $2.27 — still down sharply from its early highs, though well above its 2026 low point. The $TRUMP token has drawn sustained criticism from ethics experts and political observers, who argue that a sitting president profiting from a personally branded cryptocurrency creates a severe conflict of interest, potentially allowing wealthy individuals and foreign entities to purchase direct financial access to the presidency through token purchases. Why This Launch Matters Biden’s decision to launch $LAPTOP represents an unusual reversal: rather than distancing himself from a scandal that dogged both his father’s presidency and his own public image, Biden appears to be directly monetizing it, leaning into the very controversy that critics used against him for years. The move mirrors a broader pattern in which polarizing political figures and moments — regardless of which side of the political spectrum they originate from — have increasingly been repackaged as speculative crypto assets aimed at supporters, critics, and speculators alike who want exposure to the underlying cultural moment rather than any underlying business or utility. What Comes Next With the token set to launch September 9 on Base, market attention will likely focus on early trading volume, initial price action, and whether $LAPTOP follows a trajectory similar to $TRUMP’s extreme early volatility. Given the polarizing nature of the underlying reference and Hunter Biden’s own public profile, the launch is likely to generate significant media attention and mixed reactions from both crypto traders and political commentators, regardless of how the token ultimately performs in the market.
Hunter Biden Launches $LAPTOP Memecoin, the Latest Political Token to Follow $TRUMP’s Lead
Hunter Biden, son of former President Joe Biden, is launching his own cryptocurrency built directly around the controversial laptop that became a flashpoint of the 2020 presidential election. The token, called $LAPTOP, is scheduled to debut September 9 on Base, the Ethereum layer-2 blockchain network created by Coinbase Global, according to reporting from the Wall Street Journal citing people familiar with the matter. How the Announcement Unfolded The Journal first reported the launch Monday morning. Shortly afterward, Biden confirmed the news himself, posting “$LAPTOP” alongside a September 9 launch date on X, accompanied by a compilation video featuring news outlets and Trump administration officials referencing the laptop saga over the years. The announcement transforms one of the most politically weaponized personal scandals of the past decade into a tradeable digital asset. The Laptop’s Origin Story The laptop at the center of the controversy was dropped off at a computer repair shop in Wilmington, Delaware, in April 2019. The shop’s owner later provided its contents to the FBI, which formally seized the device roughly five months later. The laptop reportedly contained emails, financial documents, and business records, along with explicit personal photos and images appearing to show Biden using drugs. The device and its contents became a major media flashpoint in conservative-leaning outlets in the run-up to the 2020 election, fueling extensive political commentary and investigations into Hunter Biden’s business dealings. Biden’s legal team has previously stated that the files were manipulated, disputing the authenticity of some material that circulated publicly. Biden himself has continued discussing the episode candidly on social media, Substack, and various podcast appearances in recent months. In a June post on X, he wrote: “What they found was evidence of a man who suffered for a period of time from a severe addiction to crack cocaine and alcohol,” adding that federal prosecutors ultimately found no evidence of corruption or criminal activity beyond matters related to his drug use. Biden’s Crypto Advocacy The memecoin launch follows a period of increasingly vocal public support for digital assets from Biden. He has previously argued on X that Congress needs “to truly understand the value and potential utility of cryptocurrency,” and separately described “decentralized digital currency” as “the inevitable future” — positioning himself, at least rhetorically, as a crypto advocate ahead of his own token launch. Token Structure and Distribution According to details of the launch, $LAPTOP will have a total supply of 1 billion tokens. The distribution plan allocates 30% to the project’s founders, subject to a vesting schedule restricting when those tokens can be sold, while another 20% will be distributed via airdrops to selected cryptocurrency holders and newsletter or platform subscribers. The project has also outlined plans to burn — permanently remove from circulation — up to 30% of the total token supply if specific political or market-related milestones are met, though the precise nature of those milestones has not been fully detailed publicly. Notably, Pump.fun, a popular Solana-based token launch platform, initially published a post referencing the $LAPTOP launch before subsequently deleting it — a detail that has fueled speculation among crypto observers about the platform’s level of involvement or its decision to distance itself from the project. Part of a Broader Trend of Political Memecoins Biden’s launch places him within a growing category of politically branded cryptocurrencies that has gained significant traction since early 2025, most notably the $TRUMP token. That coin, built on the Solana blockchain, launched in January 2025 just ahead of Donald Trump’s second presidential inauguration, announced via Truth Social and X on January 17-18, 2025. Its branding drew directly on imagery from the July 2024 assassination attempt against Trump in Butler, Pennsylvania, featuring the president with a raised fist alongside the phrase “FIGHT FIGHT FIGHT.” Of the token’s 1 billion total supply, 200 million coins were released publicly in the initial offering, while Trump-affiliated companies retained the remaining 800 million. First Lady Melania Trump subsequently launched a companion token of her own. $TRUMP’s price trajectory has been extremely volatile: the token peaked between $73 and $75 shortly after its January 2025 launch, before falling to an all-time low of $1.37 on August 13, 2026. As of recent trading, the token sits around $2.27 — still down sharply from its early highs, though well above its 2026 low point. The $TRUMP token has drawn sustained criticism from ethics experts and political observers, who argue that a sitting president profiting from a personally branded cryptocurrency creates a severe conflict of interest, potentially allowing wealthy individuals and foreign entities to purchase direct financial access to the presidency through token purchases. Why This Launch Matters Biden’s decision to launch $LAPTOP represents an unusual reversal: rather than distancing himself from a scandal that dogged both his father’s presidency and his own public image, Biden appears to be directly monetizing it, leaning into the very controversy that critics used against him for years. The move mirrors a broader pattern in which polarizing political figures and moments — regardless of which side of the political spectrum they originate from — have increasingly been repackaged as speculative crypto assets aimed at supporters, critics, and speculators alike who want exposure to the underlying cultural moment rather than any underlying business or utility. What Comes Next With the token set to launch September 9 on Base, market attention will likely focus on early trading volume, initial price action, and whether $LAPTOP follows a trajectory similar to $TRUMP’s extreme early volatility. Given the polarizing nature of the underlying reference and Hunter Biden’s own public profile, the launch is likely to generate significant media attention and mixed reactions from both crypto traders and political commentators, regardless of how the token ultimately performs in the market.
Pitch Fest Bali 2026 Wraps: ObsessionDB Wins, 13 Startups Pitch to a Room of Leading VCs
Pitch Fest Bali 2026 Wraps: ObsessionDB Wins, 13 Startups Pitch to a Room of Leading VCs DeltaV-presented, invite-only Web3 demo day drew a VC panel spanning SC Ventures, TBV, Ape Ventures, Yellow, Cicada, and Kosmos Ventures, with $100K+ in prizes, credits, and support on the line. Held August 19 in Jimbaran, Bali, the day before Coinfest Asia. BALI, INDONESIA. [ Release Date ]. Luvon Labs and SpedaxAI wrapped Pitch Fest Bali 2026 on August 19, an invite-only Web3 demo day presented by DeltaV and held at Dewata Padel in Jimbaran, the day before Coinfest Asia. Thirteen curated startups pitched live to a panel of leading venture investors, competing for a prize pool of more than $100,000 in prizes, credits, and support. The room delivered on what it promised. Founders, funds, and exchanges spent the day in a curated space built for real conversations instead of conference-floor noise, and the read since has been consistent: attendees and partners have called it one of the most ROI-driven side events of Coinfest Asia week. ObsessionDB Takes the Win After thirteen live pitches, ObsessionDB took first place, and in a fitting turn, one of the event’s own infrastructure sponsors backed the room, then won it. ObsessionDB is fully managed ClickHouse, the same engine, queries, and tools teams already know, delivering sub-second queries at any scale without any infrastructure to run themselves. Provvypay placed second. The startup runs a unified payment infrastructure connecting Stripe and Hedera with automated accounting, giving businesses a real-time view of their commercial position before it hits the books. MOI placed third. MOI is building the participant layer for AI agents, giving every human or agent persistent, on-chain, portable identity and authority in computation, so agents can be monitored, scoped, and revoked in real time. A Judging Panel That Showed Up Founders pitched to a panel that included Alexis Sirkia (Co-Founder and Captain, Yellow), Tobias Bauer (Co-Founder and General Partner, TBV), Maxim Moris (Co-Founder and CEO, Cicada), Sheridan Hammond (Founder, Kosmos Ventures), Daria Chernozub (Global Adoption Head and SEA Lead, Dash), Alex Toh (Lead, Funds Management, SC Ventures by Standard Chartered), and Ardi Wicaksono (Head of Blockchain and Web3 Investment, Hilton Tech Fund). Trive Digital, Spores Network, and CoinSwitch Ventures were also in the room as attending VCs. Partners Behind the Day Pitch Fest Bali 2026 was presented by DeltaV as title sponsor, with Golden Grid, ObsessionDB, Kenomic, hashlock, [H.E.], and humaneffort on board as sponsors. BrandPR served as PR partner, and Dewata Padel hosted the day as venue partner. WEEX joined as a notable attending exchange, and the event was amplified by more than 50 media and community partners across the region. EV-GO also joined as a partner. EV-GO is the first real-world utility project backed by EV-READY and ID Opentech, Indonesia’s largest EV group, with more than 1 million vehicle-to-EV conversion quotas already secured and a battery infrastructure build-out worth over $1 billion. Backerstage Capital came on as an event partner. The team runs closed, founder-and-investor events across crypto, ten so far across six countries, with their next stop being the Founder x VC Summit in Singapore this October during Token2049 week. In Their Words “The pitches were the easy part,” said Anubhav Tomar, Co-Founder of Luvon Labs. “What made the day work was the room itself. Watching one of our own sponsors pitch their way to the win says everything about what we built here.” What’s Next Bali is the first stop in a planned series of curated demo days across major global crypto hubs, with editions targeted for Singapore, Mumbai, and London. Partners who came in early on Bali get a head start on a platform built to grow across several markets. About Luvon Labs Luvon Labs is a full-stack venture partner for Web3 founders, working end-to-end from build to raise. The studio ships the entire stack, brand and UX, smart contracts in Solidity and Rust, AI agents, mobile apps, and the infrastructure that keeps products live and scaling, then stays in the room through go-to-market and fundraising, backed by a global investor network built over years in the ecosystem. To date, Luvon Labs has shipped 50+ products for 30+ clients across 15+ countries, spanning BNB Chain, EVM, and Solana. Guided by its philosophy, Build With Intent, Luvon treats every team it works with as a long-term relationship, not a one-off engagement. More at luvonlabs.com. About SpedaxAI SpedaxAI is a no-code AI creation studio that lets businesses and creators build, deploy, and monetize autonomous AI agents in minutes. It combines enterprise-grade AI models with Web3 infrastructure, so users can embed custom agents across platforms or mint them as ownable, royalty-earning digital assets. More at spedaxai.com. About BrandPR BrandPR is a specialized PR and marketing agency partnering with Luvon Labs to empower AI and Web3 brands worldwide. Since 2022, BrandPR has helped crypto, blockchain, and AI clients gain exposure through top-tier media coverage and community-building. More at brandpr.io.About Golden Grid Golden Grid is an on-chain pixel lottery where players claim a block on a living grid with original pixel art or a logo, connect their wallet, and take a shot at crypto, NFTs, and rewards from a prize pool that grows as more players join. Built around the lore of Ratoshi and the Syndicate, the platform runs on one rule: luck must circulate. More at goldengrid.xyz. About HashLock Hashlock is the industry leading blockchain cybersecurity and smart contract auditing firm. We specialise in manual analysis led security research, securing billions of dollars in digital assets, with clients ranging from innovative web3 startups to global blockchain enterprises.More at https://hashlock.com/About Kenomic Kenomic is an AI-powered platform built for the entire token lifecycle, guiding founders through design, validation, launch, and post-launch management in one place. Its conversational AI agent, Keni, turns a plain project description into a launch-ready tokenomics model, backed by a digital-twin simulation engine that stress-tests the design across millions of market scenarios and a Kenomic Score that measures resilience before launch. Kenomic then deploys audit-grade smart contracts across 9 chains and keeps managing vesting, staking, airdrops, and treasury long after launch day. More at kenomic.ai.
Media and Partnership Contact Anubhav Tomar, Co-Founder, Luvon Labs Email: anubhav@luvonlabs.com Telegram: @anubhavcfx Web: Luvonlabs.com
Pitch Fest Bali 2026 Wraps: ObsessionDB Wins, 13 Startups Pitch to a Room of Leading VCs
Pitch Fest Bali 2026 Wraps: ObsessionDB Wins, 13 Startups Pitch to a Room of Leading VCs DeltaV-presented, invite-only Web3 demo day drew a VC panel spanning SC Ventures, TBV, Ape Ventures, Yellow, Cicada, and Kosmos Ventures, with $100K+ in prizes, credits, and support on the line. Held August 19 in Jimbaran, Bali, the day before Coinfest Asia. BALI, INDONESIA. [ Release Date ]. Luvon Labs and SpedaxAI wrapped Pitch Fest Bali 2026 on August 19, an invite-only Web3 demo day presented by DeltaV and held at Dewata Padel in Jimbaran, the day before Coinfest Asia. Thirteen curated startups pitched live to a panel of leading venture investors, competing for a prize pool of more than $100,000 in prizes, credits, and support. The room delivered on what it promised. Founders, funds, and exchanges spent the day in a curated space built for real conversations instead of conference-floor noise, and the read since has been consistent: attendees and partners have called it one of the most ROI-driven side events of Coinfest Asia week. ObsessionDB Takes the Win After thirteen live pitches, ObsessionDB took first place, and in a fitting turn, one of the event’s own infrastructure sponsors backed the room, then won it. ObsessionDB is fully managed ClickHouse, the same engine, queries, and tools teams already know, delivering sub-second queries at any scale without any infrastructure to run themselves. Provvypay placed second. The startup runs a unified payment infrastructure connecting Stripe and Hedera with automated accounting, giving businesses a real-time view of their commercial position before it hits the books. MOI placed third. MOI is building the participant layer for AI agents, giving every human or agent persistent, on-chain, portable identity and authority in computation, so agents can be monitored, scoped, and revoked in real time. A Judging Panel That Showed Up Founders pitched to a panel that included Alexis Sirkia (Co-Founder and Captain, Yellow), Tobias Bauer (Co-Founder and General Partner, TBV), Maxim Moris (Co-Founder and CEO, Cicada), Sheridan Hammond (Founder, Kosmos Ventures), Daria Chernozub (Global Adoption Head and SEA Lead, Dash), Alex Toh (Lead, Funds Management, SC Ventures by Standard Chartered), and Ardi Wicaksono (Head of Blockchain and Web3 Investment, Hilton Tech Fund). Trive Digital, Spores Network, and CoinSwitch Ventures were also in the room as attending VCs. Partners Behind the Day Pitch Fest Bali 2026 was presented by DeltaV as title sponsor, with Golden Grid, ObsessionDB, Kenomic, hashlock, [H.E.], and humaneffort on board as sponsors. BrandPR served as PR partner, and Dewata Padel hosted the day as venue partner. WEEX joined as a notable attending exchange, and the event was amplified by more than 50 media and community partners across the region. EV-GO also joined as a partner. EV-GO is the first real-world utility project backed by EV-READY and ID Opentech, Indonesia’s largest EV group, with more than 1 million vehicle-to-EV conversion quotas already secured and a battery infrastructure build-out worth over $1 billion. Backerstage Capital came on as an event partner. The team runs closed, founder-and-investor events across crypto, ten so far across six countries, with their next stop being the Founder x VC Summit in Singapore this October during Token2049 week. In Their Words “The pitches were the easy part,” said Anubhav Tomar, Co-Founder of Luvon Labs. “What made the day work was the room itself. Watching one of our own sponsors pitch their way to the win says everything about what we built here.” What’s Next Bali is the first stop in a planned series of curated demo days across major global crypto hubs, with editions targeted for Singapore, Mumbai, and London. Partners who came in early on Bali get a head start on a platform built to grow across several markets. About Luvon Labs Luvon Labs is a full-stack venture partner for Web3 founders, working end-to-end from build to raise. The studio ships the entire stack, brand and UX, smart contracts in Solidity and Rust, AI agents, mobile apps, and the infrastructure that keeps products live and scaling, then stays in the room through go-to-market and fundraising, backed by a global investor network built over years in the ecosystem. To date, Luvon Labs has shipped 50+ products for 30+ clients across 15+ countries, spanning BNB Chain, EVM, and Solana. Guided by its philosophy, Build With Intent, Luvon treats every team it works with as a long-term relationship, not a one-off engagement. More at luvonlabs.com. About SpedaxAI SpedaxAI is a no-code AI creation studio that lets businesses and creators build, deploy, and monetize autonomous AI agents in minutes. It combines enterprise-grade AI models with Web3 infrastructure, so users can embed custom agents across platforms or mint them as ownable, royalty-earning digital assets. More at spedaxai.com. About BrandPR BrandPR is a specialized PR and marketing agency partnering with Luvon Labs to empower AI and Web3 brands worldwide. Since 2022, BrandPR has helped crypto, blockchain, and AI clients gain exposure through top-tier media coverage and community-building. More at brandpr.io. About Golden Grid Golden Grid is an on-chain pixel lottery where players claim a block on a living grid with original pixel art or a logo, connect their wallet, and take a shot at crypto, NFTs, and rewards from a prize pool that grows as more players join. Built around the lore of Ratoshi and the Syndicate, the platform runs on one rule: luck must circulate. More at goldengrid.xyz. About HashLock Hashlock is the industry leading blockchain cybersecurity and smart contract auditing firm. We specialise in manual analysis led security research, securing billions of dollars in digital assets, with clients ranging from innovative web3 startups to global blockchain enterprises.More at https://hashlock.com/ About Kenomic Kenomic is an AI-powered platform built for the entire token lifecycle, guiding founders through design, validation, launch, and post-launch management in one place. Its conversational AI agent, Keni, turns a plain project description into a launch-ready tokenomics model, backed by a digital-twin simulation engine that stress-tests the design across millions of market scenarios and a Kenomic Score that measures resilience before launch. Kenomic then deploys audit-grade smart contracts across 9 chains and keeps managing vesting, staking, airdrops, and treasury long after launch day. More at kenomic.ai.
Media and Partnership Contact Anubhav Tomar, Co-Founder, Luvon Labs Email: anubhav@luvonlabs.com Telegram: @anubhavcfx Web: Luvonlabs.com
$320 Million Vanishes From Liquid Network in Mysterious “White-Hat” Withdrawal, Blockstream Confirms
Liquid Network, the Bitcoin layer-2 sidechain operated by a global federation of crypto exchanges and financial institutions, confirmed a major security incident after roughly 4,000 BTC — worth approximately $320 million and representing nearly all of the network’s reported reserves — was withdrawn from its federation wallet by unidentified parties claiming to be ethical hackers. The network has been paused entirely while Blockstream, its lead technical operator, attempts to make contact with those responsible. How the Incident Unfolded The withdrawal was disclosed by Liquid Network via its official X account on the evening of September 6: “We are aware of a security incident on @Liquid_BTC. Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet. The @Blockstream team is working on contacting them on-chain with a signed message.” The scale of the withdrawal is striking relative to the network’s total holdings — the roughly 4,000 BTC removed represents approximately 95% of Liquid’s reported bitcoin reserves, which stood at an estimated 4,200 BTC immediately before the incident occurred. In other words, whoever executed the transaction drained nearly the entirety of the network’s federation-held bitcoin in a single move. Notably, the individuals or group behind the withdrawal left a direct message embedded in the transaction itself, stating simply: “we are whitehats. contact us on chain.” That on-chain communication is now central to Blockstream’s response, since it suggests the party responsible may be attempting to signal legitimate intentions — a claim commonly associated with security researchers who identify and exploit a vulnerability specifically to prevent malicious actors from doing so first, typically with the intent of eventually returning the funds. What Blockstream Says Happened Technically In follow-up statements, Liquid Network provided additional technical detail about how the funds were moved. According to the network’s disclosure, the withdrawal was executed via the SideSwap PAK, or Peg-out Authorization Key — a specific cryptographic mechanism used to authorize the process of moving bitcoin off the Liquid sidechain and back onto the main Bitcoin blockchain. Critically, Liquid Network stated explicitly that this particular key was not compromised, and clarified that no other keys within the system were compromised either — an important distinction, since it suggests the withdrawal may have exploited a functional or logical vulnerability in how the authorization process works, rather than resulting from a stolen or leaked private key. Immediate Response and Network-Wide Impact In the immediate aftermath, Liquid Network took several containment steps. Cryptocurrency exchanges holding LBTC — the tokenized representation of Bitcoin that circulates on the Liquid sidechain — were notified and directed to pause both deposits and withdrawals of the asset while the situation is investigated. The network also temporarily disabled its bridge nodes, the infrastructure responsible for processing transactions moving between the Bitcoin mainchain and the Liquid sidechain. With bridge nodes offline, no new transactions can currently be submitted to the network, effectively freezing all Liquid sidechain activity until the issue is resolved. Liquid Network was careful to clarify the scope of the incident, stating that other assets issued on the network — including USDT, DePix, and various tokenized real-world assets (RWAs) — were not affected by the security event, with the impact isolated specifically to the federation’s bitcoin reserves and the LBTC token tied to them. In its statement, the network acknowledged the disruption to users directly: “Liquid wallets will be impacted, and we’re sorry for any inconvenience. Federation members are actively working on resolving this so we can restore normal network activity.” Understanding Liquid Network’s Structure Liquid Network functions as a layer-2 sidechain built on top of Bitcoin, designed to enable faster and more confidential transactions for cryptocurrency exchanges, traders, and financial institutions than would typically be possible directly on the Bitcoin mainchain. Rather than being controlled by a single company, the network is governed by the Liquid Federation — a decentralized consortium of Bitcoin-focused companies, cryptocurrency exchanges, and financial institutions spread across the globe that collectively manage the network’s operations and security. Blockstream, the software company that originally developed Liquid Network, continues to serve as its primary technical service provider, though it does not hold unilateral control. Because governance authority is distributed among numerous federation members worldwide, no single individual or organization has complete authority over the network — a structure intended to reduce single points of failure, though this incident raises new questions about how that distributed authority model handles a rapid, large-scale security event. The “White-Hat” Question The self-identification of the actors as “white-hat hackers” carries significant weight for how this incident is ultimately resolved, but it remains an unverified claim rather than a confirmed fact at this stage. In cryptocurrency security incidents, parties who move funds during an active exploit sometimes genuinely act to protect the funds from other, less scrupulous attackers who might have discovered the same vulnerability, later negotiating a “bug bounty” arrangement to return the assets in exchange for a reward and immunity from prosecution. In other cases, however, the “white-hat” framing has historically been used by attackers as a negotiating tactic after the fact, once they realize returning funds may be legally and financially safer than attempting to launder $320 million in stolen bitcoin. Blockstream’s active attempt to establish on-chain communication suggests the company is treating this as an open negotiation rather than a resolved matter. What Happens Next As of publication, Liquid Network remains fully paused, LBTC deposits and withdrawals remain suspended across participating exchanges, and Blockstream has not yet confirmed whether contact with the responsible party has been established or whether any funds have been returned. Given the incident occurred during evening hours and involves an unusually large sum relative to the network’s total reserves, additional details, technical post-mortems, and updates on fund recovery are expected to continue emerging in the hours and days following this initial disclosure.
$320 Million Vanishes From Liquid Network in Mysterious “White-Hat” Withdrawal, Blockstream Confirms
Liquid Network, the Bitcoin layer-2 sidechain operated by a global federation of crypto exchanges and financial institutions, confirmed a major security incident after roughly 4,000 BTC — worth approximately $320 million and representing nearly all of the network’s reported reserves — was withdrawn from its federation wallet by unidentified parties claiming to be ethical hackers. The network has been paused entirely while Blockstream, its lead technical operator, attempts to make contact with those responsible. How the Incident Unfolded The withdrawal was disclosed by Liquid Network via its official X account on the evening of September 6: “We are aware of a security incident on @Liquid_BTC. Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet. The @Blockstream team is working on contacting them on-chain with a signed message.” The scale of the withdrawal is striking relative to the network’s total holdings — the roughly 4,000 BTC removed represents approximately 95% of Liquid’s reported bitcoin reserves, which stood at an estimated 4,200 BTC immediately before the incident occurred. In other words, whoever executed the transaction drained nearly the entirety of the network’s federation-held bitcoin in a single move. Notably, the individuals or group behind the withdrawal left a direct message embedded in the transaction itself, stating simply: “we are whitehats. contact us on chain.” That on-chain communication is now central to Blockstream’s response, since it suggests the party responsible may be attempting to signal legitimate intentions — a claim commonly associated with security researchers who identify and exploit a vulnerability specifically to prevent malicious actors from doing so first, typically with the intent of eventually returning the funds. What Blockstream Says Happened Technically In follow-up statements, Liquid Network provided additional technical detail about how the funds were moved. According to the network’s disclosure, the withdrawal was executed via the SideSwap PAK, or Peg-out Authorization Key — a specific cryptographic mechanism used to authorize the process of moving bitcoin off the Liquid sidechain and back onto the main Bitcoin blockchain. Critically, Liquid Network stated explicitly that this particular key was not compromised, and clarified that no other keys within the system were compromised either — an important distinction, since it suggests the withdrawal may have exploited a functional or logical vulnerability in how the authorization process works, rather than resulting from a stolen or leaked private key. Immediate Response and Network-Wide Impact In the immediate aftermath, Liquid Network took several containment steps. Cryptocurrency exchanges holding LBTC — the tokenized representation of Bitcoin that circulates on the Liquid sidechain — were notified and directed to pause both deposits and withdrawals of the asset while the situation is investigated. The network also temporarily disabled its bridge nodes, the infrastructure responsible for processing transactions moving between the Bitcoin mainchain and the Liquid sidechain. With bridge nodes offline, no new transactions can currently be submitted to the network, effectively freezing all Liquid sidechain activity until the issue is resolved. Liquid Network was careful to clarify the scope of the incident, stating that other assets issued on the network — including USDT, DePix, and various tokenized real-world assets (RWAs) — were not affected by the security event, with the impact isolated specifically to the federation’s bitcoin reserves and the LBTC token tied to them. In its statement, the network acknowledged the disruption to users directly: “Liquid wallets will be impacted, and we’re sorry for any inconvenience. Federation members are actively working on resolving this so we can restore normal network activity.” Understanding Liquid Network’s Structure Liquid Network functions as a layer-2 sidechain built on top of Bitcoin, designed to enable faster and more confidential transactions for cryptocurrency exchanges, traders, and financial institutions than would typically be possible directly on the Bitcoin mainchain. Rather than being controlled by a single company, the network is governed by the Liquid Federation — a decentralized consortium of Bitcoin-focused companies, cryptocurrency exchanges, and financial institutions spread across the globe that collectively manage the network’s operations and security. Blockstream, the software company that originally developed Liquid Network, continues to serve as its primary technical service provider, though it does not hold unilateral control. Because governance authority is distributed among numerous federation members worldwide, no single individual or organization has complete authority over the network — a structure intended to reduce single points of failure, though this incident raises new questions about how that distributed authority model handles a rapid, large-scale security event. The “White-Hat” Question The self-identification of the actors as “white-hat hackers” carries significant weight for how this incident is ultimately resolved, but it remains an unverified claim rather than a confirmed fact at this stage. In cryptocurrency security incidents, parties who move funds during an active exploit sometimes genuinely act to protect the funds from other, less scrupulous attackers who might have discovered the same vulnerability, later negotiating a “bug bounty” arrangement to return the assets in exchange for a reward and immunity from prosecution. In other cases, however, the “white-hat” framing has historically been used by attackers as a negotiating tactic after the fact, once they realize returning funds may be legally and financially safer than attempting to launder $320 million in stolen bitcoin. Blockstream’s active attempt to establish on-chain communication suggests the company is treating this as an open negotiation rather than a resolved matter. What Happens Next As of publication, Liquid Network remains fully paused, LBTC deposits and withdrawals remain suspended across participating exchanges, and Blockstream has not yet confirmed whether contact with the responsible party has been established or whether any funds have been returned. Given the incident occurred during evening hours and involves an unusually large sum relative to the network’s total reserves, additional details, technical post-mortems, and updates on fund recovery are expected to continue emerging in the hours and days following this initial disclosure.
Connected Africa 2026 – 7th Edition Telecom Innovation & Excellence Awards Africa’s Premier Telecom SummitTheme: Driving Africa’s Telecom Shift to Digital Platforms and Next-Gen Infrastructure Date: 15 October 2026Venue: Johannesburg, South Africa Johannesburg, South Africa – The International Center for Strategic Alliances (ICSA) proudly announces the 7th Edition of Connected Africa – Telecom Innovation & Excellence Awards, set to take place on 15 October 2026. Recognized as Africa’s premier telecom and digital-infrastructure summit, Connected Africa 2026 will convene the continent’s most influential leaders across telecom, banking, cybersecurity, cloud, and enterprise technology to accelerate South Africa’s digital future. As ICSA’s flagship telecom and digital-infrastructure platform, Connected Africa has consistently delivered high-impact dialogue, strategic partnerships, and market-defining insights across emerging economies. The 2026 edition builds on this legacy—bringing together policymakers, regulators, CXOs, and innovators to explore how intelligent technologies are reshaping banking, security, and enterprise modernization in South Africa. A Strategic Moment for South Africa’s Digital Economy South Africa stands at a pivotal inflection point in its digital transformation journey. With rapid advancements in 5G, cloud, AI, cybersecurity, and digital finance, the nation is accelerating toward a more connected, secure, and resilient economy. Connected Africa 2026 will serve as a critical platform to examine policy direction, investment priorities, and technology adoption—aligning public and private sectors to unlock inclusive, technology-driven growth. Key Focus Areas Intelligent banking & embedded finance powering next-generation digital services Cybersecurity resilience and real-time threat intelligence Cloud modernization, hyperscale data centers, and edge computing 5G evolution, network intelligence, and advanced connectivity Digital identity, fraud prevention, and secure transaction frameworks Enterprise modernization through automation, IoT, and AI Cross-industry collaboration shaping South Africa’s digital future Why Connected Africa Matters Connected Africa 2026 is more than a summit—it is a strategic nexus for decision-makers shaping national and continental digital agendas. Participants gain: High-level dialogue across telecom, finance, government, and enterprise Actionable insights into investments driving digital modernization Solution showcases addressing connectivity, security, and scalability challenges Strategic partnerships spanning public and private sectors Telecom Innovation & Excellence Awards A cornerstone of the 7th edition, the Telecom Innovation & Excellence Awards will celebrate organizations and leaders delivering outstanding impact across network innovation, digital inclusion, security excellence, enterprise transformation, and customer experience—reinforcing Africa’s global leadership in telecom and digital infrastructure. Participation Opportunities Connected Africa 2026 is open for: Sponsorship & strategic partnerships Speaking & thought-leadership engagements Technology exhibitions & innovation showcases Enterprise, government, and industry registrations About ICSA The International Center for Strategic Alliances (ICSA) is a global organization committed to advancing digital transformation, infrastructure development, and industry collaboration through high-impact conferences, executive engagements, and strategic forums across emerging markets. ICSA’s platforms connect decision-makers with technology leaders to drive measurable outcomes and long-term growth. For Engagement & EnquiriesTel: +44 20 3808 8625Email: info@intercsa.comWebsite: https://connected-africa.com/summit/
Connected Africa 2026 – 7th Edition Telecom Innovation & Excellence Awards Africa’s Premier Telecom Summit Theme: Driving Africa’s Telecom Shift to Digital Platforms and Next-Gen Infrastructure Date: 15 October 2026 Venue: Johannesburg, South Africa Johannesburg, South Africa – The International Center for Strategic Alliances (ICSA) proudly announces the 7th Edition of Connected Africa – Telecom Innovation & Excellence Awards, set to take place on 15 October 2026. Recognized as Africa’s premier telecom and digital-infrastructure summit, Connected Africa 2026 will convene the continent’s most influential leaders across telecom, banking, cybersecurity, cloud, and enterprise technology to accelerate South Africa’s digital future. As ICSA’s flagship telecom and digital-infrastructure platform, Connected Africa has consistently delivered high-impact dialogue, strategic partnerships, and market-defining insights across emerging economies. The 2026 edition builds on this legacy—bringing together policymakers, regulators, CXOs, and innovators to explore how intelligent technologies are reshaping banking, security, and enterprise modernization in South Africa. A Strategic Moment for South Africa’s Digital Economy South Africa stands at a pivotal inflection point in its digital transformation journey. With rapid advancements in 5G, cloud, AI, cybersecurity, and digital finance, the nation is accelerating toward a more connected, secure, and resilient economy. Connected Africa 2026 will serve as a critical platform to examine policy direction, investment priorities, and technology adoption—aligning public and private sectors to unlock inclusive, technology-driven growth. Key Focus Areas Intelligent banking & embedded finance powering next-generation digital services Cybersecurity resilience and real-time threat intelligence Cloud modernization, hyperscale data centers, and edge computing 5G evolution, network intelligence, and advanced connectivity Digital identity, fraud prevention, and secure transaction frameworks Enterprise modernization through automation, IoT, and AI Cross-industry collaboration shaping South Africa’s digital future Why Connected Africa Matters Connected Africa 2026 is more than a summit—it is a strategic nexus for decision-makers shaping national and continental digital agendas. Participants gain: High-level dialogue across telecom, finance, government, and enterprise Actionable insights into investments driving digital modernization Solution showcases addressing connectivity, security, and scalability challenges Strategic partnerships spanning public and private sectors Telecom Innovation & Excellence Awards A cornerstone of the 7th edition, the Telecom Innovation & Excellence Awards will celebrate organizations and leaders delivering outstanding impact across network innovation, digital inclusion, security excellence, enterprise transformation, and customer experience—reinforcing Africa’s global leadership in telecom and digital infrastructure. Participation Opportunities Connected Africa 2026 is open for: Sponsorship & strategic partnerships Speaking & thought-leadership engagements Technology exhibitions & innovation showcases Enterprise, government, and industry registrations About ICSA The International Center for Strategic Alliances (ICSA) is a global organization committed to advancing digital transformation, infrastructure development, and industry collaboration through high-impact conferences, executive engagements, and strategic forums across emerging markets. ICSA’s platforms connect decision-makers with technology leaders to drive measurable outcomes and long-term growth. For Engagement & Enquiries Tel: +44 20 3808 8625 Email: info@intercsa.com Website: https://connected-africa.com/summit/
Robinhood Chain Hits $34.6B DEX Volume As ‘Stonks’ Meme Coin Trend Takes Off
Robinhood Chain has recorded $34.6 billion in cumulative decentralized exchange (DEX) volume and $1.27 billion in protocol total value locked (TVL) just over two months after launching its public mainnet. Robinhood Crypto disclosed the figures in a two-month network update, which also showed 576 million transactions, 12.3 million addresses and more than 190 Stock Tokens already live on the blockchain. The milestone comes as activity on Robinhood Chain expands beyond tokenized equities into a new speculative market combining traditional stocks with crypto-native meme culture. Memecoins paired directly with Robinhood Stock Tokens — a trend increasingly referred to by traders as “Stonks” or “stock memes” — have started attracting significant trading activity, while Pons, a token launchpad built on the network, has become one of crypto’s largest fee-generating applications. Robinhood Chain Reaches $34.6 Billion in DEX Volume According to Robinhood Crypto, Robinhood Chain reached several major milestones during its first two months: – $34.6 billion in total DEX volume – $1.27 billion in protocol TVL – 576 million total transactions – 12.3 million total addresses – More than 190 Stock Tokens – Over $3 billion in cumulative Stock Token DEX volume – $7.29 billion in perpetual futures trading volume through Lighter The figures are Robinhood’s own reported network statistics and highlight the rapid growth of its onchain ecosystem. Robinhood Chain’s public mainnet officially launched on July 1, 2026, following the release of its public testnet on February 10. The network is an Ethereum Layer 2 built using the Arbitrum Platform and settles to Ethereum. ETH is used as its native gas token. Robinhood describes the blockchain as purpose-built for financial services and tokenized real-world assets. At launch, Robinhood announced integrations with infrastructure providers including Chainlink, Alchemy and BitGo, alongside DeFi platforms including Uniswap. Its Stock Tokens are available to eligible Robinhood Wallet users in more than 120 countries, depending on jurisdiction. Importantly, Robinhood Stock Tokens do not represent direct ownership of shares in the underlying companies. Robinhood describes the products as tokenized debt securities that provide economic exposure to the relevant underlying assets without granting traditional shareholder ownership or voting rights. Pons Becomes a Major Driver of Robinhood Chain Activity One of the biggest beneficiaries of Robinhood Chain’s recent activity has been Pons, a third-party token launchpad that allows users to create and trade tokens on the network. Pons generated approximately $5.95 million in fees over a 24-hour period on September 3, according to DefiLlama data cited by CoinDesk. That temporarily placed it fourth among all protocols tracked by the platform, behind Tether, Uniswap and Circle, while exceeding the fees generated by Robinhood Chain itself during the same period. Nearly 25,000 tokens were created through Pons on September 2, while daily trading volume reached approximately $544 million. The platform’s native PONS token has benefited from the surge in activity. On September 3, PONS traded around $0.5978 on its Uniswap pool, up 31.82% over 24 hours and around 181 times above its July 17 low of $0.0033, according to Decrypt. PONS had also overtaken CASHCAT in late August to become the largest Robinhood Chain-native cryptocurrency by market capitalization at the time. Another catalyst arrived on September 2, when Binance Wallet added PONS and FLORK to Binance Alpha, with PONS available through Binance Alpha 1.0. Pons is not an official Robinhood product, but its growth demonstrates how permissionless applications are developing independently on top of Robinhood’s blockchain. What Are ‘Stonks’ on Robinhood Chain? A particularly unusual trend has now emerged around Robinhood Chain’s biggest differentiating feature: tokenized stocks. Crypto traders have started creating memecoins whose DEX liquidity is paired directly with tokenized stocks rather than conventional assets such as ETH or stablecoins. The trend has been described across the emerging Robinhood Chain community as “stock memes” or “Stonks.” “Stonks” itself is an intentional misspelling of “stocks” originating from a long-running internet meme used humorously to describe financial markets, questionable investment decisions and unexpectedly successful trades. On Robinhood Chain, the term has taken on a more literal meaning as meme tokens become connected to onchain representations of traditional financial assets. Stock-meme projects have appeared around tokenized assets referencing companies and products including AMC Entertainment, Nvidia, Apple and Tesla, among others. Instead of a conventional MEME/ETH liquidity pool, for example, a project can establish liquidity against a tokenized equity. The structure does not mean the memecoin is issued, approved or backed by the company represented by the stock token. It remains a separate speculative crypto asset. AMC Controversy Sends the Stonks Trend Into Overdrive The distinction became particularly important on September 3 when AMC Entertainment CEO Adam Aron publicly criticized Robinhood’s tokenized version of AMC stock. Aron said AMC had no connection with the product and did not approve or endorse it. He also questioned its legal structure and said AMC would ask outside securities counsel to examine the matter. Robinhood CEO Vlad Tenev responded publicly by asking: “What’s the concern?” Robinhood’s disclosures state that its Stock Tokens provide economic exposure rather than actual ownership of the companies whose securities they track and are not offered to U.S. persons. Crypto traders quickly turned the controversy itself into another market. A Robinhood Chain memecoin called MEME, paired against the tokenized AMC asset, exploded in value within hours of its launch. GMGN data cited by BlockBeats showed its market capitalization passing $11.2 million early on September 4 before later exceeding $30 million. As speculation accelerated, the token briefly approached $150 million in market capitalization, with approximately $87.4 million in trading volume reported at that stage. The move illustrates both the appeal and extreme risk of the emerging Stonks market: valuations can change by tens of millions of dollars within hours, and the memecoins themselves have no corporate relationship with the companies referenced by their paired Stock Tokens. Robinhood Chain Blurs the Line Between TradFi and Crypto Culture Robinhood originally positioned its blockchain around bringing traditional financial assets onchain. Stock Tokens can be traded through decentralized venues and, according to Robinhood, potentially integrated into DeFi applications as collateral or deposited into lending markets. Two months after launch, however, the network is demonstrating another consequence of making traditional assets programmable: permissionless crypto markets can build entirely new products around them. The result is an unusual collision between RWAs, DeFi and memecoin speculation. Robinhood Chain’s $34.6 billion in reported DEX volume shows that significant activity has already reached the network. Pons’ explosive growth and the emergence of Stock Meme trading suggest that tokenized equities are not being used solely as digital versions of traditional investments. They are also becoming building blocks for a new — and highly speculative — category of onchain markets.
Ledger Faces $500 Million Class Action Alleging Company Concealed Data Breach That Enabled $1.95 ...
Ledger SAS, the world’s leading hardware cryptocurrency wallet manufacturer, is facing a proposed class-action lawsuit in the U.S. District Court for the Southern District of New York, with the plaintiff alleging the company’s alleged failure to properly disclose a 2023 data breach directly enabled a sophisticated social engineering attack that drained nearly $2 million from his crypto wallets. The lawsuit seeks at least $500 million in damages on behalf of a potential class of up to 210,000 affected users. How the Alleged Theft Unfolded Plaintiff Douglas Kim filed the complaint on August 27, 2026. According to the filing, Kim purchased his first Ledger hardware wallet in 2017 and later upgraded to a Ledger Nano X in 2021 — establishing a customer relationship spanning nearly a decade before the alleged theft occurred. The complaint states that in February 2025, Kim was contacted by individuals claiming to represent Coincover and Ledger. The callers reportedly told him there had been an attempted enrollment in Ledger Recover, the company’s optional key-recovery service, and directed him to a website where he was instructed to provide sensitive information. According to the lawsuit, that information allegedly allowed the attackers to gain access to his cryptocurrency holdings. Kim discovered on February 20, 2025, that approximately $1.95 million had been transferred out of his wallets. He has reportedly not recovered any of the stolen assets. Tracing the Attack Back to a 2023 Security Incident The lawsuit’s central legal theory connects Kim’s individual loss to a broader security failure at Ledger dating back to December 2023, when the company’s Connect Kit — a software library that allows Ledger hardware wallets to interface with decentralized applications — was compromised. According to the complaint, attackers gained access through a former Ledger employee and used the compromised software library to facilitate fraudulent transactions across the platform. The filing further alleges, on information and belief, that customer data exposed during that 2023 incident was subsequently used to specifically target Kim in the February 2025 social engineering scheme — providing attackers with the contact information and contextual detail needed to convincingly impersonate Ledger and Coincover representatives. A Pattern the Lawsuit Says Goes Back Even Further The complaint frames the 2023 incident as part of a longer pattern of security failures at Ledger, pointing back to a separate 2020 data breach that exposed personal information belonging to approximately 270,000 customers, including names, email addresses, phone numbers, and other personally identifiable information. According to the lawsuit, Ledger failed to timely and fully disclose the scope of the 2023 breach specifically, and that the leaked data from both incidents ultimately circulated on dark web marketplaces, where it could be purchased and used by scammers to craft convincing impersonation attacks against Ledger’s customer base. The complaint characterizes this history in stark terms: “Ledger has demonstrated a disturbing pattern of negligent, reckless, and irresponsible behavior with regard to its security posture and a callous disregard for its obligations to the privacy of its customers’ [personally identifiable information].” The Legal Claims Kim’s lawsuit brings multiple causes of action against Ledger, including violations of New York General Business Law Sections 349 and 350 — the state’s core consumer protection statutes governing deceptive business practices — alongside claims of negligence, negligent misrepresentation, promissory estoppel, and breach of the covenant of good faith and fair dealing. The complaint also demands a jury trial. The Scale of the Proposed Class Kim is seeking to represent a nationwide class of Ledger users who may have been similarly affected. The complaint estimates the proposed class could encompass up to 210,000 people, with total damages across the class potentially reaching at least $500 million — a figure that, if the class were certified and the plaintiffs prevailed, would represent one of the largest consumer damages awards in the cryptocurrency hardware industry’s history. Important Legal Caveats It’s worth emphasizing that, as with any newly filed complaint, none of the allegations against Ledger have been proven in court, and the proposed class has not yet been certified by the presiding judge. The case remains in its early stages within the Southern District of New York, and Ledger has not yet filed a formal public response to the specific allegations at the time of this reporting. Why This Case Matters for the Broader Crypto Security Landscape This lawsuit lands amid a broader wave of concern about physical and social engineering attacks targeting hardware wallet customers specifically. Similar incidents involving both Ledger and competitor Trezor have surfaced in recent months, including fraudulent physical mail scams and data exposure incidents tied to third-party shipping and fulfillment partners rather than the wallet manufacturers’ own core infrastructure. What distinguishes the Ledger case is the legal argument being tested: that a company’s delayed or incomplete breach disclosure can itself become the basis for liability when leaked data is later weaponized in downstream fraud, rather than liability being limited to the original breach alone. For the broader hardware wallet industry, the outcome of this case could set an important precedent regarding how quickly and thoroughly companies are legally required to disclose security incidents involving customer data — particularly in an industry where the entire value proposition rests on customers trusting that their private keys and personal information remain secure. If Kim’s theory succeeds, it may push hardware wallet manufacturers toward faster, more comprehensive breach notifications, alongside more aggressive proactive warnings to customers about phishing and impersonation risks whenever a data exposure incident occurs, rather than treating disclosure as a purely discretionary or minimized corporate communications decision.
Robinhood Chain Hits $34.6B DEX Volume as ‘Stonks’ Meme Coin Trend Takes Off
Robinhood Chain has recorded $34.6 billion in cumulative decentralized exchange (DEX) volume and $1.27 billion in protocol total value locked (TVL) just over two months after launching its public mainnet. Robinhood Crypto disclosed the figures in a two-month network update, which also showed 576 million transactions, 12.3 million addresses and more than 190 Stock Tokens already live on the blockchain. The milestone comes as activity on Robinhood Chain expands beyond tokenized equities into a new speculative market combining traditional stocks with crypto-native meme culture. Memecoins paired directly with Robinhood Stock Tokens — a trend increasingly referred to by traders as “Stonks” or “stock memes” — have started attracting significant trading activity, while Pons, a token launchpad built on the network, has become one of crypto’s largest fee-generating applications. Robinhood Chain Reaches $34.6 Billion in DEX Volume According to Robinhood Crypto, Robinhood Chain reached several major milestones during its first two months: – $34.6 billion in total DEX volume – $1.27 billion in protocol TVL – 576 million total transactions – 12.3 million total addresses – More than 190 Stock Tokens – Over $3 billion in cumulative Stock Token DEX volume – $7.29 billion in perpetual futures trading volume through Lighter The figures are Robinhood’s own reported network statistics and highlight the rapid growth of its onchain ecosystem. Robinhood Chain’s public mainnet officially launched on July 1, 2026, following the release of its public testnet on February 10. The network is an Ethereum Layer 2 built using the Arbitrum Platform and settles to Ethereum. ETH is used as its native gas token. Robinhood describes the blockchain as purpose-built for financial services and tokenized real-world assets. At launch, Robinhood announced integrations with infrastructure providers including Chainlink, Alchemy and BitGo, alongside DeFi platforms including Uniswap. Its Stock Tokens are available to eligible Robinhood Wallet users in more than 120 countries, depending on jurisdiction. Importantly, Robinhood Stock Tokens do not represent direct ownership of shares in the underlying companies. Robinhood describes the products as tokenized debt securities that provide economic exposure to the relevant underlying assets without granting traditional shareholder ownership or voting rights. Pons Becomes a Major Driver of Robinhood Chain Activity One of the biggest beneficiaries of Robinhood Chain’s recent activity has been Pons, a third-party token launchpad that allows users to create and trade tokens on the network. Pons generated approximately $5.95 million in fees over a 24-hour period on September 3, according to DefiLlama data cited by CoinDesk. That temporarily placed it fourth among all protocols tracked by the platform, behind Tether, Uniswap and Circle, while exceeding the fees generated by Robinhood Chain itself during the same period. Nearly 25,000 tokens were created through Pons on September 2, while daily trading volume reached approximately $544 million. The platform’s native PONS token has benefited from the surge in activity. On September 3, PONS traded around $0.5978 on its Uniswap pool, up 31.82% over 24 hours and around 181 times above its July 17 low of $0.0033, according to Decrypt. PONS had also overtaken CASHCAT in late August to become the largest Robinhood Chain-native cryptocurrency by market capitalization at the time. Another catalyst arrived on September 2, when Binance Wallet added PONS and FLORK to Binance Alpha, with PONS available through Binance Alpha 1.0. Pons is not an official Robinhood product, but its growth demonstrates how permissionless applications are developing independently on top of Robinhood’s blockchain. What Are ‘Stonks’ on Robinhood Chain? A particularly unusual trend has now emerged around Robinhood Chain’s biggest differentiating feature: tokenized stocks. Crypto traders have started creating memecoins whose DEX liquidity is paired directly with tokenized stocks rather than conventional assets such as ETH or stablecoins. The trend has been described across the emerging Robinhood Chain community as “stock memes” or “Stonks.” “Stonks” itself is an intentional misspelling of “stocks” originating from a long-running internet meme used humorously to describe financial markets, questionable investment decisions and unexpectedly successful trades. On Robinhood Chain, the term has taken on a more literal meaning as meme tokens become connected to onchain representations of traditional financial assets. Stock-meme projects have appeared around tokenized assets referencing companies and products including AMC Entertainment, Nvidia, Apple and Tesla, among others. Instead of a conventional MEME/ETH liquidity pool, for example, a project can establish liquidity against a tokenized equity. The structure does not mean the memecoin is issued, approved or backed by the company represented by the stock token. It remains a separate speculative crypto asset. AMC Controversy Sends the Stonks Trend Into Overdrive The distinction became particularly important on September 3 when AMC Entertainment CEO Adam Aron publicly criticized Robinhood’s tokenized version of AMC stock. Aron said AMC had no connection with the product and did not approve or endorse it. He also questioned its legal structure and said AMC would ask outside securities counsel to examine the matter. Robinhood CEO Vlad Tenev responded publicly by asking: “What’s the concern?” Robinhood’s disclosures state that its Stock Tokens provide economic exposure rather than actual ownership of the companies whose securities they track and are not offered to U.S. persons. Crypto traders quickly turned the controversy itself into another market. A Robinhood Chain memecoin called MEME, paired against the tokenized AMC asset, exploded in value within hours of its launch. GMGN data cited by BlockBeats showed its market capitalization passing $11.2 million early on September 4 before later exceeding $30 million. As speculation accelerated, the token briefly approached $150 million in market capitalization, with approximately $87.4 million in trading volume reported at that stage. The move illustrates both the appeal and extreme risk of the emerging Stonks market: valuations can change by tens of millions of dollars within hours, and the memecoins themselves have no corporate relationship with the companies referenced by their paired Stock Tokens. Robinhood Chain Blurs the Line Between TradFi and Crypto Culture Robinhood originally positioned its blockchain around bringing traditional financial assets onchain. Stock Tokens can be traded through decentralized venues and, according to Robinhood, potentially integrated into DeFi applications as collateral or deposited into lending markets. Two months after launch, however, the network is demonstrating another consequence of making traditional assets programmable: permissionless crypto markets can build entirely new products around them. The result is an unusual collision between RWAs, DeFi and memecoin speculation. Robinhood Chain’s $34.6 billion in reported DEX volume shows that significant activity has already reached the network. Pons’ explosive growth and the emergence of Stock Meme trading suggest that tokenized equities are not being used solely as digital versions of traditional investments. They are also becoming building blocks for a new — and highly speculative — category of onchain markets.
Ledger Faces $500 Million Class Action Alleging Company Concealed Data Breach That Enabled $1.95 ...
Ledger SAS, the world’s leading hardware cryptocurrency wallet manufacturer, is facing a proposed class-action lawsuit in the U.S. District Court for the Southern District of New York, with the plaintiff alleging the company’s alleged failure to properly disclose a 2023 data breach directly enabled a sophisticated social engineering attack that drained nearly $2 million from his crypto wallets. The lawsuit seeks at least $500 million in damages on behalf of a potential class of up to 210,000 affected users. How the Alleged Theft Unfolded Plaintiff Douglas Kim filed the complaint on August 27, 2026. According to the filing, Kim purchased his first Ledger hardware wallet in 2017 and later upgraded to a Ledger Nano X in 2021 — establishing a customer relationship spanning nearly a decade before the alleged theft occurred. The complaint states that in February 2025, Kim was contacted by individuals claiming to represent Coincover and Ledger. The callers reportedly told him there had been an attempted enrollment in Ledger Recover, the company’s optional key-recovery service, and directed him to a website where he was instructed to provide sensitive information. According to the lawsuit, that information allegedly allowed the attackers to gain access to his cryptocurrency holdings. Kim discovered on February 20, 2025, that approximately $1.95 million had been transferred out of his wallets. He has reportedly not recovered any of the stolen assets. Tracing the Attack Back to a 2023 Security Incident The lawsuit’s central legal theory connects Kim’s individual loss to a broader security failure at Ledger dating back to December 2023, when the company’s Connect Kit — a software library that allows Ledger hardware wallets to interface with decentralized applications — was compromised. According to the complaint, attackers gained access through a former Ledger employee and used the compromised software library to facilitate fraudulent transactions across the platform. The filing further alleges, on information and belief, that customer data exposed during that 2023 incident was subsequently used to specifically target Kim in the February 2025 social engineering scheme — providing attackers with the contact information and contextual detail needed to convincingly impersonate Ledger and Coincover representatives. A Pattern the Lawsuit Says Goes Back Even Further The complaint frames the 2023 incident as part of a longer pattern of security failures at Ledger, pointing back to a separate 2020 data breach that exposed personal information belonging to approximately 270,000 customers, including names, email addresses, phone numbers, and other personally identifiable information. According to the lawsuit, Ledger failed to timely and fully disclose the scope of the 2023 breach specifically, and that the leaked data from both incidents ultimately circulated on dark web marketplaces, where it could be purchased and used by scammers to craft convincing impersonation attacks against Ledger’s customer base. The complaint characterizes this history in stark terms: “Ledger has demonstrated a disturbing pattern of negligent, reckless, and irresponsible behavior with regard to its security posture and a callous disregard for its obligations to the privacy of its customers’ [personally identifiable information].” The Legal Claims Kim’s lawsuit brings multiple causes of action against Ledger, including violations of New York General Business Law Sections 349 and 350 — the state’s core consumer protection statutes governing deceptive business practices — alongside claims of negligence, negligent misrepresentation, promissory estoppel, and breach of the covenant of good faith and fair dealing. The complaint also demands a jury trial. The Scale of the Proposed Class Kim is seeking to represent a nationwide class of Ledger users who may have been similarly affected. The complaint estimates the proposed class could encompass up to 210,000 people, with total damages across the class potentially reaching at least $500 million — a figure that, if the class were certified and the plaintiffs prevailed, would represent one of the largest consumer damages awards in the cryptocurrency hardware industry’s history. Important Legal Caveats It’s worth emphasizing that, as with any newly filed complaint, none of the allegations against Ledger have been proven in court, and the proposed class has not yet been certified by the presiding judge. The case remains in its early stages within the Southern District of New York, and Ledger has not yet filed a formal public response to the specific allegations at the time of this reporting. Why This Case Matters for the Broader Crypto Security Landscape This lawsuit lands amid a broader wave of concern about physical and social engineering attacks targeting hardware wallet customers specifically. Similar incidents involving both Ledger and competitor Trezor have surfaced in recent months, including fraudulent physical mail scams and data exposure incidents tied to third-party shipping and fulfillment partners rather than the wallet manufacturers’ own core infrastructure. What distinguishes the Ledger case is the legal argument being tested: that a company’s delayed or incomplete breach disclosure can itself become the basis for liability when leaked data is later weaponized in downstream fraud, rather than liability being limited to the original breach alone. For the broader hardware wallet industry, the outcome of this case could set an important precedent regarding how quickly and thoroughly companies are legally required to disclose security incidents involving customer data — particularly in an industry where the entire value proposition rests on customers trusting that their private keys and personal information remain secure. If Kim’s theory succeeds, it may push hardware wallet manufacturers toward faster, more comprehensive breach notifications, alongside more aggressive proactive warnings to customers about phishing and impersonation risks whenever a data exposure incident occurs, rather than treating disclosure as a purely discretionary or minimized corporate communications decision.
EU Just Put ChatGPT in the Same Regulatory Bucket As Google — Here’s What That Means
The European Commission has formally designated ChatGPT as a Very Large Online Search Engine (VLOSE) under the EU’s Digital Services Act (DSA), placing OpenAI’s flagship product under the same heightened regulatory scrutiny previously reserved for platforms like Google Search and Bing. The same announcement designated Reddit and Roblox as Very Large Online Platforms (VLOPs), subjecting both to comparable obligations. All three companies now have until January 2027 to bring their services into full compliance with the DSA’s most demanding requirements. Why These Three Platforms Crossed the Threshold Under the DSA, any online service must self-report reaching an average of at least 45 million monthly active users within the European Union to qualify for VLOP or VLOSE designation — a threshold representing roughly 10% of the EU’s total population. ChatGPT, Reddit, and Roblox all confirmed they had surpassed this figure, triggering their formal classification by the Commission. OpenAI’s own disclosed figures put the scale of ChatGPT’s European search usage well beyond the minimum threshold. According to data OpenAI submitted covering the period from October 2025 through March 31, 2026, ChatGPT’s search functionality alone averaged approximately 159.1 million monthly users across the European Union — more than three times the 45-million threshold required for VLOSE status. What Changes for OpenAI Now With the VLOSE designation in effect, ChatGPT becomes subject to the DSA’s most stringent obligations, specifically designed for platforms and search engines the Commission considers capable of generating systemic risk at EU-wide scale. OpenAI must now identify, assess, and actively mitigate systemic risks tied to its service, spanning several specific categories: the spread of illegal content, the protection of minors using the platform, users’ physical and mental well-being, the protection of fundamental rights, and risks to electoral processes and public security. Beyond risk assessment, OpenAI is required to establish an internal compliance function specifically dedicated to DSA obligations, undergo independent, externally conducted audits at least once per year, and provide relevant operational data to both the European Commission and national regulators across member states. Additionally, vetted external researchers will gain the ability to formally request access to platform data needed to independently study systemic risks — a transparency requirement that has, for other VLOPs and VLOSEs, previously extended to areas like recommendation algorithm behavior and content moderation practices. Mitigation measures the Commission can require are not limited to policy changes; they can extend to structural modifications of how the underlying service and its algorithmic or recommendation systems actually operate. For ChatGPT specifically, this could mean adjustments to how its search functionality surfaces information, handles queries related to elections or public health, or filters content accessible to younger users. The Financial Stakes of Non-Compliance The DSA carries substantial financial consequences for platforms that fail to meet these obligations. Companies designated as VLOPs or VLOSEs that violate the regulation can face fines of up to 6% of their global annual revenue — not merely EU-generated revenue, but the company’s total worldwide turnover. Beyond financial penalties, the Commission retains authority to formally compel companies to remedy identified violations directly. Part of a Broader EU Regulatory Push on AI and Tech Platforms This designation does not exist in isolation. It follows closely on the heels of a separate but related regulatory expansion: in August 2026, the European Commission gained formal authority to impose fines on providers of general-purpose AI models specifically for violations of the EU’s AI Act, a distinct piece of legislation targeting the development and deployment of artificial intelligence systems rather than online platform behavior. Together, the DSA designation and the AI Act enforcement authority signal that EU regulators are now applying overlapping layers of scrutiny to major AI companies — one focused on platform-level systemic risk (DSA), the other on the underlying AI models and systems themselves (AI Act). This regulatory environment sits alongside the EU’s ongoing “Chat Control” framework governing messaging platforms, which currently operates under temporary rules allowing voluntary scanning of unencrypted content for child sexual abuse material, with end-to-end encrypted messages remaining outside the scope of that scanning permission. EU governments extended those temporary provisions through April 2028 while broader legislative debate over a permanent framework continues — illustrating a wider pattern of the EU building out comprehensive digital governance across search, social platforms, AI systems, and messaging simultaneously. What This Means for the EU Market The practical impact on OpenAI’s European operations is likely to be significant, though not necessarily disruptive to everyday users. Companies designated as VLOPs or VLOSEs under the DSA — including Google, Meta, TikTok, and Amazon before them — have generally responded by building out dedicated EU compliance teams, publishing periodic risk assessment reports, and in some cases modifying algorithmic systems specifically for EU users to satisfy regulatory requirements, sometimes resulting in feature differences between EU and non-EU versions of a product. For OpenAI specifically, the designation formalizes something the sheer scale of ChatGPT’s European user base had already made inevitable: treatment as critical digital infrastructure rather than an emerging technology product exempt from the compliance burdens applied to established search engines and social platforms. Given that ChatGPT’s search feature alone reaches over 159 million monthly EU users — a figure larger than the entire population of most EU member states combined — the Commission’s designation reflects a recognition that generative AI search tools have already achieved a scale of societal reach comparable to the platforms the DSA was originally built to regulate. What Happens Next OpenAI, Reddit, and Roblox now have until January 2027 to demonstrate full compliance with their respective VLOSE and VLOP obligations. Given the precedent set by earlier DSA enforcement actions against other major platforms, the coming months are likely to bring public risk assessment disclosures, potential structural changes to how these services operate for EU users, and continued scrutiny from both the European Commission and vetted independent researchers examining how these platforms manage the systemic risks the DSA is designed to address.
EU Just Put ChatGPT in the Same Regulatory Bucket as Google — Here’s What That Means
The European Commission has formally designated ChatGPT as a Very Large Online Search Engine (VLOSE) under the EU’s Digital Services Act (DSA), placing OpenAI’s flagship product under the same heightened regulatory scrutiny previously reserved for platforms like Google Search and Bing. The same announcement designated Reddit and Roblox as Very Large Online Platforms (VLOPs), subjecting both to comparable obligations. All three companies now have until January 2027 to bring their services into full compliance with the DSA’s most demanding requirements. Why These Three Platforms Crossed the Threshold Under the DSA, any online service must self-report reaching an average of at least 45 million monthly active users within the European Union to qualify for VLOP or VLOSE designation — a threshold representing roughly 10% of the EU’s total population. ChatGPT, Reddit, and Roblox all confirmed they had surpassed this figure, triggering their formal classification by the Commission. OpenAI’s own disclosed figures put the scale of ChatGPT’s European search usage well beyond the minimum threshold. According to data OpenAI submitted covering the period from October 2025 through March 31, 2026, ChatGPT’s search functionality alone averaged approximately 159.1 million monthly users across the European Union — more than three times the 45-million threshold required for VLOSE status. What Changes for OpenAI Now With the VLOSE designation in effect, ChatGPT becomes subject to the DSA’s most stringent obligations, specifically designed for platforms and search engines the Commission considers capable of generating systemic risk at EU-wide scale. OpenAI must now identify, assess, and actively mitigate systemic risks tied to its service, spanning several specific categories: the spread of illegal content, the protection of minors using the platform, users’ physical and mental well-being, the protection of fundamental rights, and risks to electoral processes and public security. Beyond risk assessment, OpenAI is required to establish an internal compliance function specifically dedicated to DSA obligations, undergo independent, externally conducted audits at least once per year, and provide relevant operational data to both the European Commission and national regulators across member states. Additionally, vetted external researchers will gain the ability to formally request access to platform data needed to independently study systemic risks — a transparency requirement that has, for other VLOPs and VLOSEs, previously extended to areas like recommendation algorithm behavior and content moderation practices. Mitigation measures the Commission can require are not limited to policy changes; they can extend to structural modifications of how the underlying service and its algorithmic or recommendation systems actually operate. For ChatGPT specifically, this could mean adjustments to how its search functionality surfaces information, handles queries related to elections or public health, or filters content accessible to younger users. The Financial Stakes of Non-Compliance The DSA carries substantial financial consequences for platforms that fail to meet these obligations. Companies designated as VLOPs or VLOSEs that violate the regulation can face fines of up to 6% of their global annual revenue — not merely EU-generated revenue, but the company’s total worldwide turnover. Beyond financial penalties, the Commission retains authority to formally compel companies to remedy identified violations directly. Part of a Broader EU Regulatory Push on AI and Tech Platforms This designation does not exist in isolation. It follows closely on the heels of a separate but related regulatory expansion: in August 2026, the European Commission gained formal authority to impose fines on providers of general-purpose AI models specifically for violations of the EU’s AI Act, a distinct piece of legislation targeting the development and deployment of artificial intelligence systems rather than online platform behavior. Together, the DSA designation and the AI Act enforcement authority signal that EU regulators are now applying overlapping layers of scrutiny to major AI companies — one focused on platform-level systemic risk (DSA), the other on the underlying AI models and systems themselves (AI Act). This regulatory environment sits alongside the EU’s ongoing “Chat Control” framework governing messaging platforms, which currently operates under temporary rules allowing voluntary scanning of unencrypted content for child sexual abuse material, with end-to-end encrypted messages remaining outside the scope of that scanning permission. EU governments extended those temporary provisions through April 2028 while broader legislative debate over a permanent framework continues — illustrating a wider pattern of the EU building out comprehensive digital governance across search, social platforms, AI systems, and messaging simultaneously. What This Means for the EU Market The practical impact on OpenAI’s European operations is likely to be significant, though not necessarily disruptive to everyday users. Companies designated as VLOPs or VLOSEs under the DSA — including Google, Meta, TikTok, and Amazon before them — have generally responded by building out dedicated EU compliance teams, publishing periodic risk assessment reports, and in some cases modifying algorithmic systems specifically for EU users to satisfy regulatory requirements, sometimes resulting in feature differences between EU and non-EU versions of a product. For OpenAI specifically, the designation formalizes something the sheer scale of ChatGPT’s European user base had already made inevitable: treatment as critical digital infrastructure rather than an emerging technology product exempt from the compliance burdens applied to established search engines and social platforms. Given that ChatGPT’s search feature alone reaches over 159 million monthly EU users — a figure larger than the entire population of most EU member states combined — the Commission’s designation reflects a recognition that generative AI search tools have already achieved a scale of societal reach comparable to the platforms the DSA was originally built to regulate. What Happens Next OpenAI, Reddit, and Roblox now have until January 2027 to demonstrate full compliance with their respective VLOSE and VLOP obligations. Given the precedent set by earlier DSA enforcement actions against other major platforms, the coming months are likely to bring public risk assessment disclosures, potential structural changes to how these services operate for EU users, and continued scrutiny from both the European Commission and vetted independent researchers examining how these platforms manage the systemic risks the DSA is designed to address.
Lazarus Group Moves $30 Million Through Hyperliquid As Trump Pushes to Bring Exchange Onshore
Wallets linked to North Korea’s state-sponsored Lazarus Group have moved more than $30 million in Bitcoin through decentralized exchange Hyperliquid over the past three weeks, according to blockchain analysis — a development that lands at an especially awkward moment, just as President Trump publicly pushes to bring the platform fully into the U.S. regulatory system. How the Funds Moved Emmett Gallic, an analyst at blockchain intelligence firm Arkham, identified the wallet activity and traced it back to addresses first attributed to Lazarus Group by independent investigator ZachXBT in 2024, at which point those wallets were already linked to $61 million in previously stolen funds. According to Gallic, the funds followed a consistent laundering pattern: Bitcoin arrived on Hyperliquid through HyperUnit, the platform’s asset bridge, where it was traded into Ethereum (ETH) and Solana (SOL). From there, the converted assets were bridged out across Tron, Solana, and Ethereum networks before ultimately landing as deposits at centralized exchanges including Kraken, LBank, and KuCoin, alongside several unlabeled Tron-based services. Gallic identified two distinct wallet clusters. The larger cluster, responsible for roughly $30 million in inbound volume, traced directly back to addresses already confirmed as belonging to Lazarus Group. A second, smaller cluster — accounting for approximately $5 million in Hyperliquid volume — showed dormancy patterns, address structures, and counterparty behavior closely matching the confirmed Lazarus wallets, though it has not been definitively attributed. In his own words, Gallic wrote: “Addresses linked to OFAC Sanctioned Lazarus Group (North Korea) have been actively moving $30M+ through Hyperliquid (HyperUnit) as recent as yesterday.” Who Is Lazarus Group Lazarus Group is a hacking organization widely assessed by Western intelligence agencies and cybersecurity firms to operate on behalf of the North Korean government, generating revenue for the state through cybercrime — most notably large-scale cryptocurrency theft — to help fund the country’s weapons programs amid international sanctions. The U.S. Treasury’s Office of Foreign Assets Control (OFAC) formally sanctioned the group in 2019, making transactions involving its wallets illegal for U.S. persons and entities under U.S. jurisdiction to knowingly facilitate. The group’s track record includes some of the largest crypto heists in history. It has been directly linked to the 2022 Ronin Network bridge exploit, which resulted in losses exceeding $600 million, and more recently to the February 2025 Bybit hack, which drained approximately $1.5 billion and stands as the largest single crypto theft ever recorded. According to reporting from BeInCrypto, North Korea-linked actors are estimated to have stolen roughly $1.6 billion in cryptocurrency during just the first half of 2025 alone — representing approximately 70% of all global crypto losses during that period. Security researchers have consistently noted that Lazarus Group typically relies on exactly this kind of multi-hop laundering pattern — cycling stolen funds through several blockchains and swapping between assets — specifically to obscure the money trail before cashing out through centralized exchanges. Why This Is a Problem for Hyperliquid Specifically The timing is particularly uncomfortable for Hyperliquid. The decentralized derivatives exchange operates without the standard know-your-customer (KYC) identity verification requirements common at centralized platforms, a design choice that has previously drawn scrutiny over its potential use as a venue for sanctions evasion. Unlike a centralized exchange, which can freeze suspicious accounts or block known sanctioned addresses at the point of deposit, Hyperliquid’s permissionless architecture makes it structurally more difficult to prevent sanctioned actors from accessing the platform in the first place. This isn’t a hypothetical reputational risk — it directly intersects with Hyperliquid’s most significant near-term business goal: gaining legitimate access to the U.S. market. President Trump named Hyperliquid specifically during an August White House event, stating: “I understand that Mike is also working to bring Hyperliquid into the United States in a fully compliant and legal fashion, working very hard on that” — crediting Commodity Futures Trading Commission (CFTC) Chairman Michael Selig with leading that regulatory effort. Selig’s CFTC has already cleared a Bitcoin perpetual futures product on a registered exchange earlier this year, a precedent that could inform how regulators ultimately evaluate Hyperliquid’s own application for U.S. market access. The disclosure of sustained, sanctioned-entity fund flows through the platform — surfacing at precisely the moment U.S. regulators are actively evaluating Hyperliquid’s path to compliant onshore operation — creates a direct tension the exchange will need to address. Regulators considering whether to grant Hyperliquid legitimate U.S. market access will now have to weigh that decision against fresh, documented evidence of North Korean state-linked laundering activity moving through the exact same platform, raising the practical question of what technical or compliance safeguards Hyperliquid can implement without abandoning the permissionless, non-KYC model that defines its product. Market Reaction Has Been Muted So Far Despite the seriousness of the sanctions questions raised, the market’s response has been notably subdued. HYPE, Hyperliquid’s native governance token, traded at $84 at time of reporting, reflecting a 5% gain over the prior 24 hours — a move that suggests traders have not yet meaningfully priced in any sanctions-related risk to the platform. Notably, HYPE had set a record all-time high of $86.71 on August 27, just days before the Lazarus-linked wallet activity became public, indicating the token’s momentum entering this news cycle was already strongly positive. What Comes Next The core tension now facing Hyperliquid is straightforward but consequential: the same permissionless, KYC-free architecture that has driven its growth and trading volume is precisely what makes it structurally vulnerable to exactly the kind of sanctioned-actor activity now under public scrutiny. As CFTC Chairman Selig continues working toward a compliant path for Hyperliquid to formally enter the U.S. market, this disclosure adds a concrete data point regulators will almost certainly need to address — whether through mandated compliance tooling, transaction monitoring requirements, or other safeguards — before any onshoring effort can move forward. For now, neither Hyperliquid nor U.S. regulators have publicly detailed how, or whether, the platform plans to respond to the specific fund flows identified by Arkham’s analysis.
Lazarus Group Moves $30 Million Through Hyperliquid as Trump Pushes to Bring Exchange Onshore
Wallets linked to North Korea’s state-sponsored Lazarus Group have moved more than $30 million in Bitcoin through decentralized exchange Hyperliquid over the past three weeks, according to blockchain analysis — a development that lands at an especially awkward moment, just as President Trump publicly pushes to bring the platform fully into the U.S. regulatory system. How the Funds Moved Emmett Gallic, an analyst at blockchain intelligence firm Arkham, identified the wallet activity and traced it back to addresses first attributed to Lazarus Group by independent investigator ZachXBT in 2024, at which point those wallets were already linked to $61 million in previously stolen funds. According to Gallic, the funds followed a consistent laundering pattern: Bitcoin arrived on Hyperliquid through HyperUnit, the platform’s asset bridge, where it was traded into Ethereum (ETH) and Solana (SOL). From there, the converted assets were bridged out across Tron, Solana, and Ethereum networks before ultimately landing as deposits at centralized exchanges including Kraken, LBank, and KuCoin, alongside several unlabeled Tron-based services. Gallic identified two distinct wallet clusters. The larger cluster, responsible for roughly $30 million in inbound volume, traced directly back to addresses already confirmed as belonging to Lazarus Group. A second, smaller cluster — accounting for approximately $5 million in Hyperliquid volume — showed dormancy patterns, address structures, and counterparty behavior closely matching the confirmed Lazarus wallets, though it has not been definitively attributed. In his own words, Gallic wrote: “Addresses linked to OFAC Sanctioned Lazarus Group (North Korea) have been actively moving $30M+ through Hyperliquid (HyperUnit) as recent as yesterday.” Who Is Lazarus Group Lazarus Group is a hacking organization widely assessed by Western intelligence agencies and cybersecurity firms to operate on behalf of the North Korean government, generating revenue for the state through cybercrime — most notably large-scale cryptocurrency theft — to help fund the country’s weapons programs amid international sanctions. The U.S. Treasury’s Office of Foreign Assets Control (OFAC) formally sanctioned the group in 2019, making transactions involving its wallets illegal for U.S. persons and entities under U.S. jurisdiction to knowingly facilitate. The group’s track record includes some of the largest crypto heists in history. It has been directly linked to the 2022 Ronin Network bridge exploit, which resulted in losses exceeding $600 million, and more recently to the February 2025 Bybit hack, which drained approximately $1.5 billion and stands as the largest single crypto theft ever recorded. According to reporting from BeInCrypto, North Korea-linked actors are estimated to have stolen roughly $1.6 billion in cryptocurrency during just the first half of 2025 alone — representing approximately 70% of all global crypto losses during that period. Security researchers have consistently noted that Lazarus Group typically relies on exactly this kind of multi-hop laundering pattern — cycling stolen funds through several blockchains and swapping between assets — specifically to obscure the money trail before cashing out through centralized exchanges. Why This Is a Problem for Hyperliquid Specifically The timing is particularly uncomfortable for Hyperliquid. The decentralized derivatives exchange operates without the standard know-your-customer (KYC) identity verification requirements common at centralized platforms, a design choice that has previously drawn scrutiny over its potential use as a venue for sanctions evasion. Unlike a centralized exchange, which can freeze suspicious accounts or block known sanctioned addresses at the point of deposit, Hyperliquid’s permissionless architecture makes it structurally more difficult to prevent sanctioned actors from accessing the platform in the first place. This isn’t a hypothetical reputational risk — it directly intersects with Hyperliquid’s most significant near-term business goal: gaining legitimate access to the U.S. market. President Trump named Hyperliquid specifically during an August White House event, stating: “I understand that Mike is also working to bring Hyperliquid into the United States in a fully compliant and legal fashion, working very hard on that” — crediting Commodity Futures Trading Commission (CFTC) Chairman Michael Selig with leading that regulatory effort. Selig’s CFTC has already cleared a Bitcoin perpetual futures product on a registered exchange earlier this year, a precedent that could inform how regulators ultimately evaluate Hyperliquid’s own application for U.S. market access. The disclosure of sustained, sanctioned-entity fund flows through the platform — surfacing at precisely the moment U.S. regulators are actively evaluating Hyperliquid’s path to compliant onshore operation — creates a direct tension the exchange will need to address. Regulators considering whether to grant Hyperliquid legitimate U.S. market access will now have to weigh that decision against fresh, documented evidence of North Korean state-linked laundering activity moving through the exact same platform, raising the practical question of what technical or compliance safeguards Hyperliquid can implement without abandoning the permissionless, non-KYC model that defines its product. Market Reaction Has Been Muted So Far Despite the seriousness of the sanctions questions raised, the market’s response has been notably subdued. HYPE, Hyperliquid’s native governance token, traded at $84 at time of reporting, reflecting a 5% gain over the prior 24 hours — a move that suggests traders have not yet meaningfully priced in any sanctions-related risk to the platform. Notably, HYPE had set a record all-time high of $86.71 on August 27, just days before the Lazarus-linked wallet activity became public, indicating the token’s momentum entering this news cycle was already strongly positive. What Comes Next The core tension now facing Hyperliquid is straightforward but consequential: the same permissionless, KYC-free architecture that has driven its growth and trading volume is precisely what makes it structurally vulnerable to exactly the kind of sanctioned-actor activity now under public scrutiny. As CFTC Chairman Selig continues working toward a compliant path for Hyperliquid to formally enter the U.S. market, this disclosure adds a concrete data point regulators will almost certainly need to address — whether through mandated compliance tooling, transaction monitoring requirements, or other safeguards — before any onshoring effort can move forward. For now, neither Hyperliquid nor U.S. regulators have publicly detailed how, or whether, the platform plans to respond to the specific fund flows identified by Arkham’s analysis.