Binance Square
Coinstelegram
3.9k Posts

Coinstelegram

Square Verified+
Coinstelegram is a leading blockchain & altcoins cryptocurrency media
0 Following
19.6K+ Followers
3.2K+ Liked
Posts
·
--
Article
Hunter Biden Launches $LAPTOP Memecoin, the Latest Political Token to Follow $TRUMP’s LeadHunter Biden, son of former President Joe Biden, is launching his own cryptocurrency built directly around the controversial laptop that became a flashpoint of the 2020 presidential election. The token, called $LAPTOP, is scheduled to debut September 9 on Base, the Ethereum layer-2 blockchain network created by Coinbase Global, according to reporting from the Wall Street Journal citing people familiar with the matter. How the Announcement Unfolded The Journal first reported the launch Monday morning. Shortly afterward, Biden confirmed the news himself, posting “$LAPTOP” alongside a September 9 launch date on X, accompanied by a compilation video featuring news outlets and Trump administration officials referencing the laptop saga over the years. The announcement transforms one of the most politically weaponized personal scandals of the past decade into a tradeable digital asset. The Laptop’s Origin Story The laptop at the center of the controversy was dropped off at a computer repair shop in Wilmington, Delaware, in April 2019. The shop’s owner later provided its contents to the FBI, which formally seized the device roughly five months later. The laptop reportedly contained emails, financial documents, and business records, along with explicit personal photos and images appearing to show Biden using drugs. The device and its contents became a major media flashpoint in conservative-leaning outlets in the run-up to the 2020 election, fueling extensive political commentary and investigations into Hunter Biden’s business dealings. Biden’s legal team has previously stated that the files were manipulated, disputing the authenticity of some material that circulated publicly. Biden himself has continued discussing the episode candidly on social media, Substack, and various podcast appearances in recent months. In a June post on X, he wrote: “What they found was evidence of a man who suffered for a period of time from a severe addiction to crack cocaine and alcohol,” adding that federal prosecutors ultimately found no evidence of corruption or criminal activity beyond matters related to his drug use. Biden’s Crypto Advocacy The memecoin launch follows a period of increasingly vocal public support for digital assets from Biden. He has previously argued on X that Congress needs “to truly understand the value and potential utility of cryptocurrency,” and separately described “decentralized digital currency” as “the inevitable future” — positioning himself, at least rhetorically, as a crypto advocate ahead of his own token launch. Token Structure and Distribution According to details of the launch, $LAPTOP will have a total supply of 1 billion tokens. The distribution plan allocates 30% to the project’s founders, subject to a vesting schedule restricting when those tokens can be sold, while another 20% will be distributed via airdrops to selected cryptocurrency holders and newsletter or platform subscribers. The project has also outlined plans to burn — permanently remove from circulation — up to 30% of the total token supply if specific political or market-related milestones are met, though the precise nature of those milestones has not been fully detailed publicly. Notably, Pump.fun, a popular Solana-based token launch platform, initially published a post referencing the $LAPTOP launch before subsequently deleting it — a detail that has fueled speculation among crypto observers about the platform’s level of involvement or its decision to distance itself from the project. Part of a Broader Trend of Political Memecoins Biden’s launch places him within a growing category of politically branded cryptocurrencies that has gained significant traction since early 2025, most notably the $TRUMP token. That coin, built on the Solana blockchain, launched in January 2025 just ahead of Donald Trump’s second presidential inauguration, announced via Truth Social and X on January 17-18, 2025. Its branding drew directly on imagery from the July 2024 assassination attempt against Trump in Butler, Pennsylvania, featuring the president with a raised fist alongside the phrase “FIGHT FIGHT FIGHT.” Of the token’s 1 billion total supply, 200 million coins were released publicly in the initial offering, while Trump-affiliated companies retained the remaining 800 million. First Lady Melania Trump subsequently launched a companion token of her own. $TRUMP’s price trajectory has been extremely volatile: the token peaked between $73 and $75 shortly after its January 2025 launch, before falling to an all-time low of $1.37 on August 13, 2026. As of recent trading, the token sits around $2.27 — still down sharply from its early highs, though well above its 2026 low point. The $TRUMP token has drawn sustained criticism from ethics experts and political observers, who argue that a sitting president profiting from a personally branded cryptocurrency creates a severe conflict of interest, potentially allowing wealthy individuals and foreign entities to purchase direct financial access to the presidency through token purchases. Why This Launch Matters Biden’s decision to launch $LAPTOP represents an unusual reversal: rather than distancing himself from a scandal that dogged both his father’s presidency and his own public image, Biden appears to be directly monetizing it, leaning into the very controversy that critics used against him for years. The move mirrors a broader pattern in which polarizing political figures and moments — regardless of which side of the political spectrum they originate from — have increasingly been repackaged as speculative crypto assets aimed at supporters, critics, and speculators alike who want exposure to the underlying cultural moment rather than any underlying business or utility. What Comes Next With the token set to launch September 9 on Base, market attention will likely focus on early trading volume, initial price action, and whether $LAPTOP follows a trajectory similar to $TRUMP’s extreme early volatility. Given the polarizing nature of the underlying reference and Hunter Biden’s own public profile, the launch is likely to generate significant media attention and mixed reactions from both crypto traders and political commentators, regardless of how the token ultimately performs in the market.

Hunter Biden Launches $LAPTOP Memecoin, the Latest Political Token to Follow $TRUMP’s Lead

Hunter Biden, son of former President Joe Biden, is launching his own cryptocurrency built directly around the controversial laptop that became a flashpoint of the 2020 presidential election.
The token, called $LAPTOP, is scheduled to debut September 9 on Base, the Ethereum layer-2 blockchain network created by Coinbase Global, according to reporting from the Wall Street Journal citing people familiar with the matter.
How the Announcement Unfolded
The Journal first reported the launch Monday morning. Shortly afterward, Biden confirmed the news himself, posting “$LAPTOP” alongside a September 9 launch date on X, accompanied by a compilation video featuring news outlets and Trump administration officials referencing the laptop saga over the years. The announcement transforms one of the most politically weaponized personal scandals of the past decade into a tradeable digital asset.
The Laptop’s Origin Story
The laptop at the center of the controversy was dropped off at a computer repair shop in Wilmington, Delaware, in April 2019. The shop’s owner later provided its contents to the FBI, which formally seized the device roughly five months later. The laptop reportedly contained emails, financial documents, and business records, along with explicit personal photos and images appearing to show Biden using drugs. The device and its contents became a major media flashpoint in conservative-leaning outlets in the run-up to the 2020 election, fueling extensive political commentary and investigations into Hunter Biden’s business dealings.
Biden’s legal team has previously stated that the files were manipulated, disputing the authenticity of some material that circulated publicly. Biden himself has continued discussing the episode candidly on social media, Substack, and various podcast appearances in recent months. In a June post on X, he wrote: “What they found was evidence of a man who suffered for a period of time from a severe addiction to crack cocaine and alcohol,” adding that federal prosecutors ultimately found no evidence of corruption or criminal activity beyond matters related to his drug use.
Biden’s Crypto Advocacy
The memecoin launch follows a period of increasingly vocal public support for digital assets from Biden. He has previously argued on X that Congress needs “to truly understand the value and potential utility of cryptocurrency,” and separately described “decentralized digital currency” as “the inevitable future” — positioning himself, at least rhetorically, as a crypto advocate ahead of his own token launch.
Token Structure and Distribution
According to details of the launch, $LAPTOP will have a total supply of 1 billion tokens. The distribution plan allocates 30% to the project’s founders, subject to a vesting schedule restricting when those tokens can be sold, while another 20% will be distributed via airdrops to selected cryptocurrency holders and newsletter or platform subscribers. The project has also outlined plans to burn — permanently remove from circulation — up to 30% of the total token supply if specific political or market-related milestones are met, though the precise nature of those milestones has not been fully detailed publicly.
Notably, Pump.fun, a popular Solana-based token launch platform, initially published a post referencing the $LAPTOP launch before subsequently deleting it — a detail that has fueled speculation among crypto observers about the platform’s level of involvement or its decision to distance itself from the project.
Part of a Broader Trend of Political Memecoins
Biden’s launch places him within a growing category of politically branded cryptocurrencies that has gained significant traction since early 2025, most notably the $TRUMP token. That coin, built on the Solana blockchain, launched in January 2025 just ahead of Donald Trump’s second presidential inauguration, announced via Truth Social and X on January 17-18, 2025. Its branding drew directly on imagery from the July 2024 assassination attempt against Trump in Butler, Pennsylvania, featuring the president with a raised fist alongside the phrase “FIGHT FIGHT FIGHT.”
Of the token’s 1 billion total supply, 200 million coins were released publicly in the initial offering, while Trump-affiliated companies retained the remaining 800 million. First Lady Melania Trump subsequently launched a companion token of her own. $TRUMP’s price trajectory has been extremely volatile: the token peaked between $73 and $75 shortly after its January 2025 launch, before falling to an all-time low of $1.37 on August 13, 2026. As of recent trading, the token sits around $2.27 — still down sharply from its early highs, though well above its 2026 low point.
The $TRUMP token has drawn sustained criticism from ethics experts and political observers, who argue that a sitting president profiting from a personally branded cryptocurrency creates a severe conflict of interest, potentially allowing wealthy individuals and foreign entities to purchase direct financial access to the presidency through token purchases.
Why This Launch Matters
Biden’s decision to launch $LAPTOP represents an unusual reversal: rather than distancing himself from a scandal that dogged both his father’s presidency and his own public image, Biden appears to be directly monetizing it, leaning into the very controversy that critics used against him for years.
The move mirrors a broader pattern in which polarizing political figures and moments — regardless of which side of the political spectrum they originate from — have increasingly been repackaged as speculative crypto assets aimed at supporters, critics, and speculators alike who want exposure to the underlying cultural moment rather than any underlying business or utility.
What Comes Next
With the token set to launch September 9 on Base, market attention will likely focus on early trading volume, initial price action, and whether $LAPTOP follows a trajectory similar to $TRUMP’s extreme early volatility. Given the polarizing nature of the underlying reference and Hunter Biden’s own public profile, the launch is likely to generate significant media attention and mixed reactions from both crypto traders and political commentators, regardless of how the token ultimately performs in the market.
Verified
Hunter Biden Launches $LAPTOP Memecoin, the Latest Political Token to Follow $TRUMP’s LeadHunter Biden, son of former President Joe Biden, is launching his own cryptocurrency built directly around the controversial laptop that became a flashpoint of the 2020 presidential election. The token, called $LAPTOP, is scheduled to debut September 9 on Base, the Ethereum layer-2 blockchain network created by Coinbase Global, according to reporting from the Wall Street Journal citing people familiar with the matter. How the Announcement Unfolded The Journal first reported the launch Monday morning. Shortly afterward, Biden confirmed the news himself, posting “$LAPTOP” alongside a September 9 launch date on X, accompanied by a compilation video featuring news outlets and Trump administration officials referencing the laptop saga over the years. The announcement transforms one of the most politically weaponized personal scandals of the past decade into a tradeable digital asset. The Laptop’s Origin Story The laptop at the center of the controversy was dropped off at a computer repair shop in Wilmington, Delaware, in April 2019. The shop’s owner later provided its contents to the FBI, which formally seized the device roughly five months later. The laptop reportedly contained emails, financial documents, and business records, along with explicit personal photos and images appearing to show Biden using drugs. The device and its contents became a major media flashpoint in conservative-leaning outlets in the run-up to the 2020 election, fueling extensive political commentary and investigations into Hunter Biden’s business dealings. Biden’s legal team has previously stated that the files were manipulated, disputing the authenticity of some material that circulated publicly. Biden himself has continued discussing the episode candidly on social media, Substack, and various podcast appearances in recent months. In a June post on X, he wrote: “What they found was evidence of a man who suffered for a period of time from a severe addiction to crack cocaine and alcohol,” adding that federal prosecutors ultimately found no evidence of corruption or criminal activity beyond matters related to his drug use. Biden’s Crypto Advocacy The memecoin launch follows a period of increasingly vocal public support for digital assets from Biden. He has previously argued on X that Congress needs “to truly understand the value and potential utility of cryptocurrency,” and separately described “decentralized digital currency” as “the inevitable future” — positioning himself, at least rhetorically, as a crypto advocate ahead of his own token launch. Token Structure and Distribution According to details of the launch, $LAPTOP will have a total supply of 1 billion tokens. The distribution plan allocates 30% to the project’s founders, subject to a vesting schedule restricting when those tokens can be sold, while another 20% will be distributed via airdrops to selected cryptocurrency holders and newsletter or platform subscribers. The project has also outlined plans to burn — permanently remove from circulation — up to 30% of the total token supply if specific political or market-related milestones are met, though the precise nature of those milestones has not been fully detailed publicly. Notably, Pump.fun, a popular Solana-based token launch platform, initially published a post referencing the $LAPTOP launch before subsequently deleting it — a detail that has fueled speculation among crypto observers about the platform’s level of involvement or its decision to distance itself from the project. Part of a Broader Trend of Political Memecoins Biden’s launch places him within a growing category of politically branded cryptocurrencies that has gained significant traction since early 2025, most notably the $TRUMP token. That coin, built on the Solana blockchain, launched in January 2025 just ahead of Donald Trump’s second presidential inauguration, announced via Truth Social and X on January 17-18, 2025. Its branding drew directly on imagery from the July 2024 assassination attempt against Trump in Butler, Pennsylvania, featuring the president with a raised fist alongside the phrase “FIGHT FIGHT FIGHT.” Of the token’s 1 billion total supply, 200 million coins were released publicly in the initial offering, while Trump-affiliated companies retained the remaining 800 million. First Lady Melania Trump subsequently launched a companion token of her own. $TRUMP’s price trajectory has been extremely volatile: the token peaked between $73 and $75 shortly after its January 2025 launch, before falling to an all-time low of $1.37 on August 13, 2026. As of recent trading, the token sits around $2.27 — still down sharply from its early highs, though well above its 2026 low point. The $TRUMP token has drawn sustained criticism from ethics experts and political observers, who argue that a sitting president profiting from a personally branded cryptocurrency creates a severe conflict of interest, potentially allowing wealthy individuals and foreign entities to purchase direct financial access to the presidency through token purchases. Why This Launch Matters Biden’s decision to launch $LAPTOP represents an unusual reversal: rather than distancing himself from a scandal that dogged both his father’s presidency and his own public image, Biden appears to be directly monetizing it, leaning into the very controversy that critics used against him for years. The move mirrors a broader pattern in which polarizing political figures and moments — regardless of which side of the political spectrum they originate from — have increasingly been repackaged as speculative crypto assets aimed at supporters, critics, and speculators alike who want exposure to the underlying cultural moment rather than any underlying business or utility. What Comes Next With the token set to launch September 9 on Base, market attention will likely focus on early trading volume, initial price action, and whether $LAPTOP follows a trajectory similar to $TRUMP’s extreme early volatility. Given the polarizing nature of the underlying reference and Hunter Biden’s own public profile, the launch is likely to generate significant media attention and mixed reactions from both crypto traders and political commentators, regardless of how the token ultimately performs in the market.

Hunter Biden Launches $LAPTOP Memecoin, the Latest Political Token to Follow $TRUMP’s Lead

Hunter Biden, son of former President Joe Biden, is launching his own cryptocurrency built directly around the controversial laptop that became a flashpoint of the 2020 presidential election.
The token, called $LAPTOP, is scheduled to debut September 9 on Base, the Ethereum layer-2 blockchain network created by Coinbase Global, according to reporting from the Wall Street Journal citing people familiar with the matter.
How the Announcement Unfolded
The Journal first reported the launch Monday morning. Shortly afterward, Biden confirmed the news himself, posting “$LAPTOP” alongside a September 9 launch date on X, accompanied by a compilation video featuring news outlets and Trump administration officials referencing the laptop saga over the years. The announcement transforms one of the most politically weaponized personal scandals of the past decade into a tradeable digital asset.
The Laptop’s Origin Story
The laptop at the center of the controversy was dropped off at a computer repair shop in Wilmington, Delaware, in April 2019. The shop’s owner later provided its contents to the FBI, which formally seized the device roughly five months later. The laptop reportedly contained emails, financial documents, and business records, along with explicit personal photos and images appearing to show Biden using drugs. The device and its contents became a major media flashpoint in conservative-leaning outlets in the run-up to the 2020 election, fueling extensive political commentary and investigations into Hunter Biden’s business dealings.
Biden’s legal team has previously stated that the files were manipulated, disputing the authenticity of some material that circulated publicly. Biden himself has continued discussing the episode candidly on social media, Substack, and various podcast appearances in recent months. In a June post on X, he wrote: “What they found was evidence of a man who suffered for a period of time from a severe addiction to crack cocaine and alcohol,” adding that federal prosecutors ultimately found no evidence of corruption or criminal activity beyond matters related to his drug use.
Biden’s Crypto Advocacy
The memecoin launch follows a period of increasingly vocal public support for digital assets from Biden. He has previously argued on X that Congress needs “to truly understand the value and potential utility of cryptocurrency,” and separately described “decentralized digital currency” as “the inevitable future” — positioning himself, at least rhetorically, as a crypto advocate ahead of his own token launch.
Token Structure and Distribution
According to details of the launch, $LAPTOP will have a total supply of 1 billion tokens. The distribution plan allocates 30% to the project’s founders, subject to a vesting schedule restricting when those tokens can be sold, while another 20% will be distributed via airdrops to selected cryptocurrency holders and newsletter or platform subscribers. The project has also outlined plans to burn — permanently remove from circulation — up to 30% of the total token supply if specific political or market-related milestones are met, though the precise nature of those milestones has not been fully detailed publicly.
Notably, Pump.fun, a popular Solana-based token launch platform, initially published a post referencing the $LAPTOP launch before subsequently deleting it — a detail that has fueled speculation among crypto observers about the platform’s level of involvement or its decision to distance itself from the project.
Part of a Broader Trend of Political Memecoins
Biden’s launch places him within a growing category of politically branded cryptocurrencies that has gained significant traction since early 2025, most notably the $TRUMP token. That coin, built on the Solana blockchain, launched in January 2025 just ahead of Donald Trump’s second presidential inauguration, announced via Truth Social and X on January 17-18, 2025. Its branding drew directly on imagery from the July 2024 assassination attempt against Trump in Butler, Pennsylvania, featuring the president with a raised fist alongside the phrase “FIGHT FIGHT FIGHT.”
Of the token’s 1 billion total supply, 200 million coins were released publicly in the initial offering, while Trump-affiliated companies retained the remaining 800 million. First Lady Melania Trump subsequently launched a companion token of her own. $TRUMP’s price trajectory has been extremely volatile: the token peaked between $73 and $75 shortly after its January 2025 launch, before falling to an all-time low of $1.37 on August 13, 2026. As of recent trading, the token sits around $2.27 — still down sharply from its early highs, though well above its 2026 low point.
The $TRUMP token has drawn sustained criticism from ethics experts and political observers, who argue that a sitting president profiting from a personally branded cryptocurrency creates a severe conflict of interest, potentially allowing wealthy individuals and foreign entities to purchase direct financial access to the presidency through token purchases.
Why This Launch Matters
Biden’s decision to launch $LAPTOP represents an unusual reversal: rather than distancing himself from a scandal that dogged both his father’s presidency and his own public image, Biden appears to be directly monetizing it, leaning into the very controversy that critics used against him for years.
The move mirrors a broader pattern in which polarizing political figures and moments — regardless of which side of the political spectrum they originate from — have increasingly been repackaged as speculative crypto assets aimed at supporters, critics, and speculators alike who want exposure to the underlying cultural moment rather than any underlying business or utility.
What Comes Next
With the token set to launch September 9 on Base, market attention will likely focus on early trading volume, initial price action, and whether $LAPTOP follows a trajectory similar to $TRUMP’s extreme early volatility. Given the polarizing nature of the underlying reference and Hunter Biden’s own public profile, the launch is likely to generate significant media attention and mixed reactions from both crypto traders and political commentators, regardless of how the token ultimately performs in the market.
Article
Pitch Fest Bali 2026 Wraps: ObsessionDB Wins, 13 Startups Pitch to a Room of Leading VCsPitch Fest Bali 2026 Wraps: ObsessionDB Wins, 13 Startups Pitch to a Room of Leading VCs DeltaV-presented, invite-only Web3 demo day drew a VC panel spanning SC Ventures, TBV, Ape Ventures, Yellow, Cicada, and Kosmos Ventures, with $100K+ in prizes, credits, and support on the line. Held August 19 in Jimbaran, Bali, the day before Coinfest Asia. BALI, INDONESIA. [ Release Date ]. Luvon Labs and SpedaxAI wrapped Pitch Fest Bali 2026 on August 19, an invite-only Web3 demo day presented by DeltaV and held at Dewata Padel in Jimbaran, the day before Coinfest Asia. Thirteen curated startups pitched live to a panel of leading venture investors, competing for a prize pool of more than $100,000 in prizes, credits, and support. The room delivered on what it promised. Founders, funds, and exchanges spent the day in a curated space built for real conversations instead of conference-floor noise, and the read since has been consistent: attendees and partners have called it one of the most ROI-driven side events of Coinfest Asia week. ObsessionDB Takes the Win After thirteen live pitches, ObsessionDB took first place, and in a fitting turn, one of the event’s own infrastructure sponsors backed the room, then won it. ObsessionDB is fully managed ClickHouse, the same engine, queries, and tools teams already know, delivering sub-second queries at any scale without any infrastructure to run themselves. Provvypay placed second. The startup runs a unified payment infrastructure connecting Stripe and Hedera with automated accounting, giving businesses a real-time view of their commercial position before it hits the books. MOI placed third. MOI is building the participant layer for AI agents, giving every human or agent persistent, on-chain, portable identity and authority in computation, so agents can be monitored, scoped, and revoked in real time. A Judging Panel That Showed Up Founders pitched to a panel that included Alexis Sirkia (Co-Founder and Captain, Yellow), Tobias Bauer (Co-Founder and General Partner, TBV), Maxim Moris (Co-Founder and CEO, Cicada), Sheridan Hammond (Founder, Kosmos Ventures), Daria Chernozub (Global Adoption Head and SEA Lead, Dash), Alex Toh (Lead, Funds Management, SC Ventures by Standard Chartered), and Ardi Wicaksono (Head of Blockchain and Web3 Investment, Hilton Tech Fund). Trive Digital, Spores Network, and CoinSwitch Ventures were also in the room as attending VCs. Partners Behind the Day Pitch Fest Bali 2026 was presented by DeltaV as title sponsor, with Golden Grid, ObsessionDB, Kenomic, hashlock, [H.E.], and humaneffort on board as sponsors. BrandPR served as PR partner, and Dewata Padel hosted the day as venue partner. WEEX joined as a notable attending exchange, and the event was amplified by more than 50 media and community partners across the region. EV-GO also joined as a partner. EV-GO is the first real-world utility project backed by EV-READY and ID Opentech, Indonesia’s largest EV group, with more than 1 million vehicle-to-EV conversion quotas already secured and a battery infrastructure build-out worth over $1 billion. Backerstage Capital came on as an event partner. The team runs closed, founder-and-investor events across crypto, ten so far across six countries, with their next stop being the Founder x VC Summit in Singapore this October during Token2049 week. In Their Words “The pitches were the easy part,” said Anubhav Tomar, Co-Founder of Luvon Labs. “What made the day work was the room itself. Watching one of our own sponsors pitch their way to the win says everything about what we built here.” What’s Next Bali is the first stop in a planned series of curated demo days across major global crypto hubs, with editions targeted for Singapore, Mumbai, and London. Partners who came in early on Bali get a head start on a platform built to grow across several markets. About Luvon Labs Luvon Labs is a full-stack venture partner for Web3 founders, working end-to-end from build to raise. The studio ships the entire stack, brand and UX, smart contracts in Solidity and Rust, AI agents, mobile apps, and the infrastructure that keeps products live and scaling, then stays in the room through go-to-market and fundraising, backed by a global investor network built over years in the ecosystem. To date, Luvon Labs has shipped 50+ products for 30+ clients across 15+ countries, spanning BNB Chain, EVM, and Solana. Guided by its philosophy, Build With Intent, Luvon treats every team it works with as a long-term relationship, not a one-off engagement. More at luvonlabs.com. About SpedaxAI SpedaxAI is a no-code AI creation studio that lets businesses and creators build, deploy, and monetize autonomous AI agents in minutes. It combines enterprise-grade AI models with Web3 infrastructure, so users can embed custom agents across platforms or mint them as ownable, royalty-earning digital assets. More at spedaxai.com. About BrandPR BrandPR is a specialized PR and marketing agency partnering with Luvon Labs to empower AI and Web3 brands worldwide. Since 2022, BrandPR has helped crypto, blockchain, and AI clients gain exposure through top-tier media coverage and community-building. More at brandpr.io.About Golden Grid Golden Grid is an on-chain pixel lottery where players claim a block on a living grid with original pixel art or a logo, connect their wallet, and take a shot at crypto, NFTs, and rewards from a prize pool that grows as more players join. Built around the lore of Ratoshi and the Syndicate, the platform runs on one rule: luck must circulate. More at goldengrid.xyz. About HashLock Hashlock is the industry leading blockchain cybersecurity and smart contract auditing firm. We specialise in manual analysis led security research, securing billions of dollars in digital assets, with clients ranging from innovative web3 startups to global blockchain enterprises.More at https://hashlock.com/About Kenomic Kenomic is an AI-powered platform built for the entire token lifecycle, guiding founders through design, validation, launch, and post-launch management in one place. Its conversational AI agent, Keni, turns a plain project description into a launch-ready tokenomics model, backed by a digital-twin simulation engine that stress-tests the design across millions of market scenarios and a Kenomic Score that measures resilience before launch. Kenomic then deploys audit-grade smart contracts across 9 chains and keeps managing vesting, staking, airdrops, and treasury long after launch day. More at kenomic.ai.   Media and Partnership Contact Anubhav Tomar, Co-Founder, Luvon Labs Email: anubhav@luvonlabs.com Telegram: @anubhavcfx Web: Luvonlabs.com

Pitch Fest Bali 2026 Wraps: ObsessionDB Wins, 13 Startups Pitch to a Room of Leading VCs

Pitch Fest Bali 2026 Wraps: ObsessionDB Wins, 13 Startups Pitch to a Room of Leading VCs
DeltaV-presented, invite-only Web3 demo day drew a VC panel spanning SC Ventures, TBV, Ape Ventures, Yellow, Cicada, and Kosmos Ventures, with $100K+ in prizes, credits, and support on the line. Held August 19 in Jimbaran, Bali, the day before Coinfest Asia.
BALI, INDONESIA. [ Release Date ]. Luvon Labs and SpedaxAI wrapped Pitch Fest Bali 2026 on August 19, an invite-only Web3 demo day presented by DeltaV and held at Dewata Padel in Jimbaran, the day before Coinfest Asia. Thirteen curated startups pitched live to a panel of leading venture investors, competing for a prize pool of more than $100,000 in prizes, credits, and support.
The room delivered on what it promised. Founders, funds, and exchanges spent the day in a curated space built for real conversations instead of conference-floor noise, and the read since has been consistent: attendees and partners have called it one of the most ROI-driven side events of Coinfest Asia week.
ObsessionDB Takes the Win
After thirteen live pitches, ObsessionDB took first place, and in a fitting turn, one of the event’s own infrastructure sponsors backed the room, then won it. ObsessionDB is fully managed ClickHouse, the same engine, queries, and tools teams already know, delivering sub-second queries at any scale without any infrastructure to run themselves.
Provvypay placed second. The startup runs a unified payment infrastructure connecting Stripe and Hedera with automated accounting, giving businesses a real-time view of their commercial position before it hits the books.
MOI placed third. MOI is building the participant layer for AI agents, giving every human or agent persistent, on-chain, portable identity and authority in computation, so agents can be monitored, scoped, and revoked in real time.
A Judging Panel That Showed Up
Founders pitched to a panel that included Alexis Sirkia (Co-Founder and Captain, Yellow), Tobias Bauer (Co-Founder and General Partner, TBV), Maxim Moris (Co-Founder and CEO, Cicada), Sheridan Hammond (Founder, Kosmos Ventures), Daria Chernozub (Global Adoption Head and SEA Lead, Dash), Alex Toh (Lead, Funds Management, SC Ventures by Standard Chartered), and Ardi Wicaksono (Head of Blockchain and Web3 Investment, Hilton Tech Fund). Trive Digital, Spores Network, and CoinSwitch Ventures were also in the room as attending VCs.
Partners Behind the Day
Pitch Fest Bali 2026 was presented by DeltaV as title sponsor, with Golden Grid, ObsessionDB, Kenomic, hashlock, [H.E.], and humaneffort on board as sponsors. BrandPR served as PR partner, and Dewata Padel hosted the day as venue partner. WEEX joined as a notable attending exchange, and the event was amplified by more than 50 media and community partners across the region.
EV-GO also joined as a partner. EV-GO is the first real-world utility project backed by EV-READY and ID Opentech, Indonesia’s largest EV group, with more than 1 million vehicle-to-EV conversion quotas already secured and a battery infrastructure build-out worth over $1 billion.
Backerstage Capital came on as an event partner. The team runs closed, founder-and-investor events across crypto, ten so far across six countries, with their next stop being the Founder x VC Summit in Singapore this October during Token2049 week.
In Their Words
“The pitches were the easy part,” said Anubhav Tomar, Co-Founder of Luvon Labs. “What made the day work was the room itself. Watching one of our own sponsors pitch their way to the win says everything about what we built here.”
What’s Next
Bali is the first stop in a planned series of curated demo days across major global crypto hubs, with editions targeted for Singapore, Mumbai, and London. Partners who came in early on Bali get a head start on a platform built to grow across several markets.
About Luvon Labs
Luvon Labs is a full-stack venture partner for Web3 founders, working end-to-end from build to raise. The studio ships the entire stack, brand and UX, smart contracts in Solidity and Rust, AI agents, mobile apps, and the infrastructure that keeps products live and scaling, then stays in the room through go-to-market and fundraising, backed by a global investor network built over years in the ecosystem. To date, Luvon Labs has shipped 50+ products for 30+ clients across 15+ countries, spanning BNB Chain, EVM, and Solana. Guided by its philosophy, Build With Intent, Luvon treats every team it works with as a long-term relationship, not a one-off engagement. More at luvonlabs.com.
About SpedaxAI
SpedaxAI is a no-code AI creation studio that lets businesses and creators build, deploy, and monetize autonomous AI agents in minutes. It combines enterprise-grade AI models with Web3 infrastructure, so users can embed custom agents across platforms or mint them as ownable, royalty-earning digital assets. More at spedaxai.com.
About BrandPR
BrandPR is a specialized PR and marketing agency partnering with Luvon Labs to empower AI and Web3 brands worldwide. Since 2022, BrandPR has helped crypto, blockchain, and AI clients gain exposure through top-tier media coverage and community-building. More at brandpr.io.About Golden Grid
Golden Grid is an on-chain pixel lottery where players claim a block on a living grid with original pixel art or a logo, connect their wallet, and take a shot at crypto, NFTs, and rewards from a prize pool that grows as more players join. Built around the lore of Ratoshi and the Syndicate, the platform runs on one rule: luck must circulate. More at goldengrid.xyz.
About HashLock
Hashlock is the industry leading blockchain cybersecurity and smart contract auditing firm. We specialise in manual analysis led security research, securing billions of dollars in digital assets, with clients ranging from innovative web3 startups to global blockchain enterprises.More at https://hashlock.com/About Kenomic
Kenomic is an AI-powered platform built for the entire token lifecycle, guiding founders through design, validation, launch, and post-launch management in one place. Its conversational AI agent, Keni, turns a plain project description into a launch-ready tokenomics model, backed by a digital-twin simulation engine that stress-tests the design across millions of market scenarios and a Kenomic Score that measures resilience before launch. Kenomic then deploys audit-grade smart contracts across 9 chains and keeps managing vesting, staking, airdrops, and treasury long after launch day. More at kenomic.ai.

Media and Partnership Contact
Anubhav Tomar, Co-Founder, Luvon Labs
Email: anubhav@luvonlabs.com
Telegram: @anubhavcfx
Web: Luvonlabs.com
Pitch Fest Bali 2026 Wraps: ObsessionDB Wins, 13 Startups Pitch to a Room of Leading VCsPitch Fest Bali 2026 Wraps: ObsessionDB Wins, 13 Startups Pitch to a Room of Leading VCs DeltaV-presented, invite-only Web3 demo day drew a VC panel spanning SC Ventures, TBV, Ape Ventures, Yellow, Cicada, and Kosmos Ventures, with $100K+ in prizes, credits, and support on the line. Held August 19 in Jimbaran, Bali, the day before Coinfest Asia. BALI, INDONESIA. [ Release Date ]. Luvon Labs and SpedaxAI wrapped Pitch Fest Bali 2026 on August 19, an invite-only Web3 demo day presented by DeltaV and held at Dewata Padel in Jimbaran, the day before Coinfest Asia. Thirteen curated startups pitched live to a panel of leading venture investors, competing for a prize pool of more than $100,000 in prizes, credits, and support. The room delivered on what it promised. Founders, funds, and exchanges spent the day in a curated space built for real conversations instead of conference-floor noise, and the read since has been consistent: attendees and partners have called it one of the most ROI-driven side events of Coinfest Asia week. ObsessionDB Takes the Win After thirteen live pitches, ObsessionDB took first place, and in a fitting turn, one of the event’s own infrastructure sponsors backed the room, then won it. ObsessionDB is fully managed ClickHouse, the same engine, queries, and tools teams already know, delivering sub-second queries at any scale without any infrastructure to run themselves. Provvypay placed second. The startup runs a unified payment infrastructure connecting Stripe and Hedera with automated accounting, giving businesses a real-time view of their commercial position before it hits the books. MOI placed third. MOI is building the participant layer for AI agents, giving every human or agent persistent, on-chain, portable identity and authority in computation, so agents can be monitored, scoped, and revoked in real time. A Judging Panel That Showed Up Founders pitched to a panel that included Alexis Sirkia (Co-Founder and Captain, Yellow), Tobias Bauer (Co-Founder and General Partner, TBV), Maxim Moris (Co-Founder and CEO, Cicada), Sheridan Hammond (Founder, Kosmos Ventures), Daria Chernozub (Global Adoption Head and SEA Lead, Dash), Alex Toh (Lead, Funds Management, SC Ventures by Standard Chartered), and Ardi Wicaksono (Head of Blockchain and Web3 Investment, Hilton Tech Fund). Trive Digital, Spores Network, and CoinSwitch Ventures were also in the room as attending VCs. Partners Behind the Day Pitch Fest Bali 2026 was presented by DeltaV as title sponsor, with Golden Grid, ObsessionDB, Kenomic, hashlock, [H.E.], and humaneffort on board as sponsors. BrandPR served as PR partner, and Dewata Padel hosted the day as venue partner. WEEX joined as a notable attending exchange, and the event was amplified by more than 50 media and community partners across the region. EV-GO also joined as a partner. EV-GO is the first real-world utility project backed by EV-READY and ID Opentech, Indonesia’s largest EV group, with more than 1 million vehicle-to-EV conversion quotas already secured and a battery infrastructure build-out worth over $1 billion. Backerstage Capital came on as an event partner. The team runs closed, founder-and-investor events across crypto, ten so far across six countries, with their next stop being the Founder x VC Summit in Singapore this October during Token2049 week. In Their Words “The pitches were the easy part,” said Anubhav Tomar, Co-Founder of Luvon Labs. “What made the day work was the room itself. Watching one of our own sponsors pitch their way to the win says everything about what we built here.” What’s Next Bali is the first stop in a planned series of curated demo days across major global crypto hubs, with editions targeted for Singapore, Mumbai, and London. Partners who came in early on Bali get a head start on a platform built to grow across several markets. About Luvon Labs Luvon Labs is a full-stack venture partner for Web3 founders, working end-to-end from build to raise. The studio ships the entire stack, brand and UX, smart contracts in Solidity and Rust, AI agents, mobile apps, and the infrastructure that keeps products live and scaling, then stays in the room through go-to-market and fundraising, backed by a global investor network built over years in the ecosystem. To date, Luvon Labs has shipped 50+ products for 30+ clients across 15+ countries, spanning BNB Chain, EVM, and Solana. Guided by its philosophy, Build With Intent, Luvon treats every team it works with as a long-term relationship, not a one-off engagement. More at luvonlabs.com. About SpedaxAI SpedaxAI is a no-code AI creation studio that lets businesses and creators build, deploy, and monetize autonomous AI agents in minutes. It combines enterprise-grade AI models with Web3 infrastructure, so users can embed custom agents across platforms or mint them as ownable, royalty-earning digital assets. More at spedaxai.com. About BrandPR BrandPR is a specialized PR and marketing agency partnering with Luvon Labs to empower AI and Web3 brands worldwide. Since 2022, BrandPR has helped crypto, blockchain, and AI clients gain exposure through top-tier media coverage and community-building. More at brandpr.io. About Golden Grid Golden Grid is an on-chain pixel lottery where players claim a block on a living grid with original pixel art or a logo, connect their wallet, and take a shot at crypto, NFTs, and rewards from a prize pool that grows as more players join. Built around the lore of Ratoshi and the Syndicate, the platform runs on one rule: luck must circulate. More at goldengrid.xyz. About HashLock Hashlock is the industry leading blockchain cybersecurity and smart contract auditing firm. We specialise in manual analysis led security research, securing billions of dollars in digital assets, with clients ranging from innovative web3 startups to global blockchain enterprises.More at https://hashlock.com/ About Kenomic Kenomic is an AI-powered platform built for the entire token lifecycle, guiding founders through design, validation, launch, and post-launch management in one place. Its conversational AI agent, Keni, turns a plain project description into a launch-ready tokenomics model, backed by a digital-twin simulation engine that stress-tests the design across millions of market scenarios and a Kenomic Score that measures resilience before launch. Kenomic then deploys audit-grade smart contracts across 9 chains and keeps managing vesting, staking, airdrops, and treasury long after launch day. More at kenomic.ai.   Media and Partnership Contact Anubhav Tomar, Co-Founder, Luvon Labs Email: anubhav@luvonlabs.com Telegram: @anubhavcfx Web: Luvonlabs.com

Pitch Fest Bali 2026 Wraps: ObsessionDB Wins, 13 Startups Pitch to a Room of Leading VCs

Pitch Fest Bali 2026 Wraps: ObsessionDB Wins, 13 Startups Pitch to a Room of Leading VCs
DeltaV-presented, invite-only Web3 demo day drew a VC panel spanning SC Ventures, TBV, Ape Ventures, Yellow, Cicada, and Kosmos Ventures, with $100K+ in prizes, credits, and support on the line. Held August 19 in Jimbaran, Bali, the day before Coinfest Asia.
BALI, INDONESIA. [ Release Date ]. Luvon Labs and SpedaxAI wrapped Pitch Fest Bali 2026 on August 19, an invite-only Web3 demo day presented by DeltaV and held at Dewata Padel in Jimbaran, the day before Coinfest Asia. Thirteen curated startups pitched live to a panel of leading venture investors, competing for a prize pool of more than $100,000 in prizes, credits, and support.
The room delivered on what it promised. Founders, funds, and exchanges spent the day in a curated space built for real conversations instead of conference-floor noise, and the read since has been consistent: attendees and partners have called it one of the most ROI-driven side events of Coinfest Asia week.
ObsessionDB Takes the Win
After thirteen live pitches, ObsessionDB took first place, and in a fitting turn, one of the event’s own infrastructure sponsors backed the room, then won it. ObsessionDB is fully managed ClickHouse, the same engine, queries, and tools teams already know, delivering sub-second queries at any scale without any infrastructure to run themselves.
Provvypay placed second. The startup runs a unified payment infrastructure connecting Stripe and Hedera with automated accounting, giving businesses a real-time view of their commercial position before it hits the books.
MOI placed third. MOI is building the participant layer for AI agents, giving every human or agent persistent, on-chain, portable identity and authority in computation, so agents can be monitored, scoped, and revoked in real time.
A Judging Panel That Showed Up
Founders pitched to a panel that included Alexis Sirkia (Co-Founder and Captain, Yellow), Tobias Bauer (Co-Founder and General Partner, TBV), Maxim Moris (Co-Founder and CEO, Cicada), Sheridan Hammond (Founder, Kosmos Ventures), Daria Chernozub (Global Adoption Head and SEA Lead, Dash), Alex Toh (Lead, Funds Management, SC Ventures by Standard Chartered), and Ardi Wicaksono (Head of Blockchain and Web3 Investment, Hilton Tech Fund). Trive Digital, Spores Network, and CoinSwitch Ventures were also in the room as attending VCs.
Partners Behind the Day
Pitch Fest Bali 2026 was presented by DeltaV as title sponsor, with Golden Grid, ObsessionDB, Kenomic, hashlock, [H.E.], and humaneffort on board as sponsors. BrandPR served as PR partner, and Dewata Padel hosted the day as venue partner. WEEX joined as a notable attending exchange, and the event was amplified by more than 50 media and community partners across the region.
EV-GO also joined as a partner. EV-GO is the first real-world utility project backed by EV-READY and ID Opentech, Indonesia’s largest EV group, with more than 1 million vehicle-to-EV conversion quotas already secured and a battery infrastructure build-out worth over $1 billion.
Backerstage Capital came on as an event partner. The team runs closed, founder-and-investor events across crypto, ten so far across six countries, with their next stop being the Founder x VC Summit in Singapore this October during Token2049 week.
In Their Words
“The pitches were the easy part,” said Anubhav Tomar, Co-Founder of Luvon Labs. “What made the day work was the room itself. Watching one of our own sponsors pitch their way to the win says everything about what we built here.”
What’s Next
Bali is the first stop in a planned series of curated demo days across major global crypto hubs, with editions targeted for Singapore, Mumbai, and London. Partners who came in early on Bali get a head start on a platform built to grow across several markets.
About Luvon Labs
Luvon Labs is a full-stack venture partner for Web3 founders, working end-to-end from build to raise. The studio ships the entire stack, brand and UX, smart contracts in Solidity and Rust, AI agents, mobile apps, and the infrastructure that keeps products live and scaling, then stays in the room through go-to-market and fundraising, backed by a global investor network built over years in the ecosystem. To date, Luvon Labs has shipped 50+ products for 30+ clients across 15+ countries, spanning BNB Chain, EVM, and Solana. Guided by its philosophy, Build With Intent, Luvon treats every team it works with as a long-term relationship, not a one-off engagement. More at luvonlabs.com.
About SpedaxAI
SpedaxAI is a no-code AI creation studio that lets businesses and creators build, deploy, and monetize autonomous AI agents in minutes. It combines enterprise-grade AI models with Web3 infrastructure, so users can embed custom agents across platforms or mint them as ownable, royalty-earning digital assets. More at spedaxai.com.
About BrandPR
BrandPR is a specialized PR and marketing agency partnering with Luvon Labs to empower AI and Web3 brands worldwide. Since 2022, BrandPR has helped crypto, blockchain, and AI clients gain exposure through top-tier media coverage and community-building. More at brandpr.io.
About Golden Grid
Golden Grid is an on-chain pixel lottery where players claim a block on a living grid with original pixel art or a logo, connect their wallet, and take a shot at crypto, NFTs, and rewards from a prize pool that grows as more players join. Built around the lore of Ratoshi and the Syndicate, the platform runs on one rule: luck must circulate. More at goldengrid.xyz.
About HashLock
Hashlock is the industry leading blockchain cybersecurity and smart contract auditing firm. We specialise in manual analysis led security research, securing billions of dollars in digital assets, with clients ranging from innovative web3 startups to global blockchain enterprises.More at https://hashlock.com/
About Kenomic
Kenomic is an AI-powered platform built for the entire token lifecycle, guiding founders through design, validation, launch, and post-launch management in one place. Its conversational AI agent, Keni, turns a plain project description into a launch-ready tokenomics model, backed by a digital-twin simulation engine that stress-tests the design across millions of market scenarios and a Kenomic Score that measures resilience before launch. Kenomic then deploys audit-grade smart contracts across 9 chains and keeps managing vesting, staking, airdrops, and treasury long after launch day. More at kenomic.ai.

Media and Partnership Contact
Anubhav Tomar, Co-Founder, Luvon Labs
Email: anubhav@luvonlabs.com
Telegram: @anubhavcfx
Web: Luvonlabs.com
Article
$320 Million Vanishes From Liquid Network in Mysterious “White-Hat” Withdrawal, Blockstream ConfirmsLiquid Network, the Bitcoin layer-2 sidechain operated by a global federation of crypto exchanges and financial institutions, confirmed a major security incident after roughly 4,000 BTC — worth approximately $320 million and representing nearly all of the network’s reported reserves — was withdrawn from its federation wallet by unidentified parties claiming to be ethical hackers. The network has been paused entirely while Blockstream, its lead technical operator, attempts to make contact with those responsible. How the Incident Unfolded The withdrawal was disclosed by Liquid Network via its official X account on the evening of September 6: “We are aware of a security incident on @Liquid_BTC. Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet. The @Blockstream team is working on contacting them on-chain with a signed message.” The scale of the withdrawal is striking relative to the network’s total holdings — the roughly 4,000 BTC removed represents approximately 95% of Liquid’s reported bitcoin reserves, which stood at an estimated 4,200 BTC immediately before the incident occurred. In other words, whoever executed the transaction drained nearly the entirety of the network’s federation-held bitcoin in a single move. Notably, the individuals or group behind the withdrawal left a direct message embedded in the transaction itself, stating simply: “we are whitehats. contact us on chain.” That on-chain communication is now central to Blockstream’s response, since it suggests the party responsible may be attempting to signal legitimate intentions — a claim commonly associated with security researchers who identify and exploit a vulnerability specifically to prevent malicious actors from doing so first, typically with the intent of eventually returning the funds. What Blockstream Says Happened Technically In follow-up statements, Liquid Network provided additional technical detail about how the funds were moved. According to the network’s disclosure, the withdrawal was executed via the SideSwap PAK, or Peg-out Authorization Key — a specific cryptographic mechanism used to authorize the process of moving bitcoin off the Liquid sidechain and back onto the main Bitcoin blockchain. Critically, Liquid Network stated explicitly that this particular key was not compromised, and clarified that no other keys within the system were compromised either — an important distinction, since it suggests the withdrawal may have exploited a functional or logical vulnerability in how the authorization process works, rather than resulting from a stolen or leaked private key. Immediate Response and Network-Wide Impact In the immediate aftermath, Liquid Network took several containment steps. Cryptocurrency exchanges holding LBTC — the tokenized representation of Bitcoin that circulates on the Liquid sidechain — were notified and directed to pause both deposits and withdrawals of the asset while the situation is investigated. The network also temporarily disabled its bridge nodes, the infrastructure responsible for processing transactions moving between the Bitcoin mainchain and the Liquid sidechain. With bridge nodes offline, no new transactions can currently be submitted to the network, effectively freezing all Liquid sidechain activity until the issue is resolved. Liquid Network was careful to clarify the scope of the incident, stating that other assets issued on the network — including USDT, DePix, and various tokenized real-world assets (RWAs) — were not affected by the security event, with the impact isolated specifically to the federation’s bitcoin reserves and the LBTC token tied to them. In its statement, the network acknowledged the disruption to users directly: “Liquid wallets will be impacted, and we’re sorry for any inconvenience. Federation members are actively working on resolving this so we can restore normal network activity.” Understanding Liquid Network’s Structure Liquid Network functions as a layer-2 sidechain built on top of Bitcoin, designed to enable faster and more confidential transactions for cryptocurrency exchanges, traders, and financial institutions than would typically be possible directly on the Bitcoin mainchain. Rather than being controlled by a single company, the network is governed by the Liquid Federation — a decentralized consortium of Bitcoin-focused companies, cryptocurrency exchanges, and financial institutions spread across the globe that collectively manage the network’s operations and security. Blockstream, the software company that originally developed Liquid Network, continues to serve as its primary technical service provider, though it does not hold unilateral control. Because governance authority is distributed among numerous federation members worldwide, no single individual or organization has complete authority over the network — a structure intended to reduce single points of failure, though this incident raises new questions about how that distributed authority model handles a rapid, large-scale security event. The “White-Hat” Question The self-identification of the actors as “white-hat hackers” carries significant weight for how this incident is ultimately resolved, but it remains an unverified claim rather than a confirmed fact at this stage. In cryptocurrency security incidents, parties who move funds during an active exploit sometimes genuinely act to protect the funds from other, less scrupulous attackers who might have discovered the same vulnerability, later negotiating a “bug bounty” arrangement to return the assets in exchange for a reward and immunity from prosecution. In other cases, however, the “white-hat” framing has historically been used by attackers as a negotiating tactic after the fact, once they realize returning funds may be legally and financially safer than attempting to launder $320 million in stolen bitcoin. Blockstream’s active attempt to establish on-chain communication suggests the company is treating this as an open negotiation rather than a resolved matter. What Happens Next As of publication, Liquid Network remains fully paused, LBTC deposits and withdrawals remain suspended across participating exchanges, and Blockstream has not yet confirmed whether contact with the responsible party has been established or whether any funds have been returned. Given the incident occurred during evening hours and involves an unusually large sum relative to the network’s total reserves, additional details, technical post-mortems, and updates on fund recovery are expected to continue emerging in the hours and days following this initial disclosure.

$320 Million Vanishes From Liquid Network in Mysterious “White-Hat” Withdrawal, Blockstream Confirms

Liquid Network, the Bitcoin layer-2 sidechain operated by a global federation of crypto exchanges and financial institutions, confirmed a major security incident after roughly 4,000 BTC — worth approximately $320 million and representing nearly all of the network’s reported reserves — was withdrawn from its federation wallet by unidentified parties claiming to be ethical hackers.
The network has been paused entirely while Blockstream, its lead technical operator, attempts to make contact with those responsible.
How the Incident Unfolded
The withdrawal was disclosed by Liquid Network via its official X account on the evening of September 6:
“We are aware of a security incident on @Liquid_BTC. Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet. The @Blockstream team is working on contacting them on-chain with a signed message.”
The scale of the withdrawal is striking relative to the network’s total holdings — the roughly 4,000 BTC removed represents approximately 95% of Liquid’s reported bitcoin reserves, which stood at an estimated 4,200 BTC immediately before the incident occurred. In other words, whoever executed the transaction drained nearly the entirety of the network’s federation-held bitcoin in a single move.
Notably, the individuals or group behind the withdrawal left a direct message embedded in the transaction itself, stating simply: “we are whitehats. contact us on chain.” That on-chain communication is now central to Blockstream’s response, since it suggests the party responsible may be attempting to signal legitimate intentions — a claim commonly associated with security researchers who identify and exploit a vulnerability specifically to prevent malicious actors from doing so first, typically with the intent of eventually returning the funds.
What Blockstream Says Happened Technically
In follow-up statements, Liquid Network provided additional technical detail about how the funds were moved. According to the network’s disclosure, the withdrawal was executed via the SideSwap PAK, or Peg-out Authorization Key — a specific cryptographic mechanism used to authorize the process of moving bitcoin off the Liquid sidechain and back onto the main Bitcoin blockchain.
Critically, Liquid Network stated explicitly that this particular key was not compromised, and clarified that no other keys within the system were compromised either — an important distinction, since it suggests the withdrawal may have exploited a functional or logical vulnerability in how the authorization process works, rather than resulting from a stolen or leaked private key.
Immediate Response and Network-Wide Impact
In the immediate aftermath, Liquid Network took several containment steps. Cryptocurrency exchanges holding LBTC — the tokenized representation of Bitcoin that circulates on the Liquid sidechain — were notified and directed to pause both deposits and withdrawals of the asset while the situation is investigated. The network also temporarily disabled its bridge nodes, the infrastructure responsible for processing transactions moving between the Bitcoin mainchain and the Liquid sidechain. With bridge nodes offline, no new transactions can currently be submitted to the network, effectively freezing all Liquid sidechain activity until the issue is resolved.
Liquid Network was careful to clarify the scope of the incident, stating that other assets issued on the network — including USDT, DePix, and various tokenized real-world assets (RWAs) — were not affected by the security event, with the impact isolated specifically to the federation’s bitcoin reserves and the LBTC token tied to them.
In its statement, the network acknowledged the disruption to users directly:
“Liquid wallets will be impacted, and we’re sorry for any inconvenience. Federation members are actively working on resolving this so we can restore normal network activity.”
Understanding Liquid Network’s Structure
Liquid Network functions as a layer-2 sidechain built on top of Bitcoin, designed to enable faster and more confidential transactions for cryptocurrency exchanges, traders, and financial institutions than would typically be possible directly on the Bitcoin mainchain. Rather than being controlled by a single company, the network is governed by the Liquid Federation — a decentralized consortium of Bitcoin-focused companies, cryptocurrency exchanges, and financial institutions spread across the globe that collectively manage the network’s operations and security.
Blockstream, the software company that originally developed Liquid Network, continues to serve as its primary technical service provider, though it does not hold unilateral control. Because governance authority is distributed among numerous federation members worldwide, no single individual or organization has complete authority over the network — a structure intended to reduce single points of failure, though this incident raises new questions about how that distributed authority model handles a rapid, large-scale security event.
The “White-Hat” Question
The self-identification of the actors as “white-hat hackers” carries significant weight for how this incident is ultimately resolved, but it remains an unverified claim rather than a confirmed fact at this stage. In cryptocurrency security incidents, parties who move funds during an active exploit sometimes genuinely act to protect the funds from other, less scrupulous attackers who might have discovered the same vulnerability, later negotiating a “bug bounty” arrangement to return the assets in exchange for a reward and immunity from prosecution.
In other cases, however, the “white-hat” framing has historically been used by attackers as a negotiating tactic after the fact, once they realize returning funds may be legally and financially safer than attempting to launder $320 million in stolen bitcoin. Blockstream’s active attempt to establish on-chain communication suggests the company is treating this as an open negotiation rather than a resolved matter.
What Happens Next
As of publication, Liquid Network remains fully paused, LBTC deposits and withdrawals remain suspended across participating exchanges, and Blockstream has not yet confirmed whether contact with the responsible party has been established or whether any funds have been returned.
Given the incident occurred during evening hours and involves an unusually large sum relative to the network’s total reserves, additional details, technical post-mortems, and updates on fund recovery are expected to continue emerging in the hours and days following this initial disclosure.
$320 Million Vanishes From Liquid Network in Mysterious “White-Hat” Withdrawal, Blockstream ConfirmsLiquid Network, the Bitcoin layer-2 sidechain operated by a global federation of crypto exchanges and financial institutions, confirmed a major security incident after roughly 4,000 BTC — worth approximately $320 million and representing nearly all of the network’s reported reserves — was withdrawn from its federation wallet by unidentified parties claiming to be ethical hackers. The network has been paused entirely while Blockstream, its lead technical operator, attempts to make contact with those responsible. How the Incident Unfolded The withdrawal was disclosed by Liquid Network via its official X account on the evening of September 6: “We are aware of a security incident on @Liquid_BTC. Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet. The @Blockstream team is working on contacting them on-chain with a signed message.” The scale of the withdrawal is striking relative to the network’s total holdings — the roughly 4,000 BTC removed represents approximately 95% of Liquid’s reported bitcoin reserves, which stood at an estimated 4,200 BTC immediately before the incident occurred. In other words, whoever executed the transaction drained nearly the entirety of the network’s federation-held bitcoin in a single move. Notably, the individuals or group behind the withdrawal left a direct message embedded in the transaction itself, stating simply: “we are whitehats. contact us on chain.” That on-chain communication is now central to Blockstream’s response, since it suggests the party responsible may be attempting to signal legitimate intentions — a claim commonly associated with security researchers who identify and exploit a vulnerability specifically to prevent malicious actors from doing so first, typically with the intent of eventually returning the funds. What Blockstream Says Happened Technically In follow-up statements, Liquid Network provided additional technical detail about how the funds were moved. According to the network’s disclosure, the withdrawal was executed via the SideSwap PAK, or Peg-out Authorization Key — a specific cryptographic mechanism used to authorize the process of moving bitcoin off the Liquid sidechain and back onto the main Bitcoin blockchain. Critically, Liquid Network stated explicitly that this particular key was not compromised, and clarified that no other keys within the system were compromised either — an important distinction, since it suggests the withdrawal may have exploited a functional or logical vulnerability in how the authorization process works, rather than resulting from a stolen or leaked private key. Immediate Response and Network-Wide Impact In the immediate aftermath, Liquid Network took several containment steps. Cryptocurrency exchanges holding LBTC — the tokenized representation of Bitcoin that circulates on the Liquid sidechain — were notified and directed to pause both deposits and withdrawals of the asset while the situation is investigated. The network also temporarily disabled its bridge nodes, the infrastructure responsible for processing transactions moving between the Bitcoin mainchain and the Liquid sidechain. With bridge nodes offline, no new transactions can currently be submitted to the network, effectively freezing all Liquid sidechain activity until the issue is resolved. Liquid Network was careful to clarify the scope of the incident, stating that other assets issued on the network — including USDT, DePix, and various tokenized real-world assets (RWAs) — were not affected by the security event, with the impact isolated specifically to the federation’s bitcoin reserves and the LBTC token tied to them. In its statement, the network acknowledged the disruption to users directly: “Liquid wallets will be impacted, and we’re sorry for any inconvenience. Federation members are actively working on resolving this so we can restore normal network activity.” Understanding Liquid Network’s Structure Liquid Network functions as a layer-2 sidechain built on top of Bitcoin, designed to enable faster and more confidential transactions for cryptocurrency exchanges, traders, and financial institutions than would typically be possible directly on the Bitcoin mainchain. Rather than being controlled by a single company, the network is governed by the Liquid Federation — a decentralized consortium of Bitcoin-focused companies, cryptocurrency exchanges, and financial institutions spread across the globe that collectively manage the network’s operations and security. Blockstream, the software company that originally developed Liquid Network, continues to serve as its primary technical service provider, though it does not hold unilateral control. Because governance authority is distributed among numerous federation members worldwide, no single individual or organization has complete authority over the network — a structure intended to reduce single points of failure, though this incident raises new questions about how that distributed authority model handles a rapid, large-scale security event. The “White-Hat” Question The self-identification of the actors as “white-hat hackers” carries significant weight for how this incident is ultimately resolved, but it remains an unverified claim rather than a confirmed fact at this stage. In cryptocurrency security incidents, parties who move funds during an active exploit sometimes genuinely act to protect the funds from other, less scrupulous attackers who might have discovered the same vulnerability, later negotiating a “bug bounty” arrangement to return the assets in exchange for a reward and immunity from prosecution. In other cases, however, the “white-hat” framing has historically been used by attackers as a negotiating tactic after the fact, once they realize returning funds may be legally and financially safer than attempting to launder $320 million in stolen bitcoin. Blockstream’s active attempt to establish on-chain communication suggests the company is treating this as an open negotiation rather than a resolved matter. What Happens Next As of publication, Liquid Network remains fully paused, LBTC deposits and withdrawals remain suspended across participating exchanges, and Blockstream has not yet confirmed whether contact with the responsible party has been established or whether any funds have been returned. Given the incident occurred during evening hours and involves an unusually large sum relative to the network’s total reserves, additional details, technical post-mortems, and updates on fund recovery are expected to continue emerging in the hours and days following this initial disclosure.

$320 Million Vanishes From Liquid Network in Mysterious “White-Hat” Withdrawal, Blockstream Confirms

Liquid Network, the Bitcoin layer-2 sidechain operated by a global federation of crypto exchanges and financial institutions, confirmed a major security incident after roughly 4,000 BTC — worth approximately $320 million and representing nearly all of the network’s reported reserves — was withdrawn from its federation wallet by unidentified parties claiming to be ethical hackers.
The network has been paused entirely while Blockstream, its lead technical operator, attempts to make contact with those responsible.
How the Incident Unfolded
The withdrawal was disclosed by Liquid Network via its official X account on the evening of September 6:
“We are aware of a security incident on @Liquid_BTC. Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet. The @Blockstream team is working on contacting them on-chain with a signed message.”
The scale of the withdrawal is striking relative to the network’s total holdings — the roughly 4,000 BTC removed represents approximately 95% of Liquid’s reported bitcoin reserves, which stood at an estimated 4,200 BTC immediately before the incident occurred. In other words, whoever executed the transaction drained nearly the entirety of the network’s federation-held bitcoin in a single move.
Notably, the individuals or group behind the withdrawal left a direct message embedded in the transaction itself, stating simply: “we are whitehats. contact us on chain.” That on-chain communication is now central to Blockstream’s response, since it suggests the party responsible may be attempting to signal legitimate intentions — a claim commonly associated with security researchers who identify and exploit a vulnerability specifically to prevent malicious actors from doing so first, typically with the intent of eventually returning the funds.
What Blockstream Says Happened Technically
In follow-up statements, Liquid Network provided additional technical detail about how the funds were moved. According to the network’s disclosure, the withdrawal was executed via the SideSwap PAK, or Peg-out Authorization Key — a specific cryptographic mechanism used to authorize the process of moving bitcoin off the Liquid sidechain and back onto the main Bitcoin blockchain.
Critically, Liquid Network stated explicitly that this particular key was not compromised, and clarified that no other keys within the system were compromised either — an important distinction, since it suggests the withdrawal may have exploited a functional or logical vulnerability in how the authorization process works, rather than resulting from a stolen or leaked private key.
Immediate Response and Network-Wide Impact
In the immediate aftermath, Liquid Network took several containment steps. Cryptocurrency exchanges holding LBTC — the tokenized representation of Bitcoin that circulates on the Liquid sidechain — were notified and directed to pause both deposits and withdrawals of the asset while the situation is investigated. The network also temporarily disabled its bridge nodes, the infrastructure responsible for processing transactions moving between the Bitcoin mainchain and the Liquid sidechain. With bridge nodes offline, no new transactions can currently be submitted to the network, effectively freezing all Liquid sidechain activity until the issue is resolved.
Liquid Network was careful to clarify the scope of the incident, stating that other assets issued on the network — including USDT, DePix, and various tokenized real-world assets (RWAs) — were not affected by the security event, with the impact isolated specifically to the federation’s bitcoin reserves and the LBTC token tied to them.
In its statement, the network acknowledged the disruption to users directly:
“Liquid wallets will be impacted, and we’re sorry for any inconvenience. Federation members are actively working on resolving this so we can restore normal network activity.”
Understanding Liquid Network’s Structure
Liquid Network functions as a layer-2 sidechain built on top of Bitcoin, designed to enable faster and more confidential transactions for cryptocurrency exchanges, traders, and financial institutions than would typically be possible directly on the Bitcoin mainchain. Rather than being controlled by a single company, the network is governed by the Liquid Federation — a decentralized consortium of Bitcoin-focused companies, cryptocurrency exchanges, and financial institutions spread across the globe that collectively manage the network’s operations and security.
Blockstream, the software company that originally developed Liquid Network, continues to serve as its primary technical service provider, though it does not hold unilateral control. Because governance authority is distributed among numerous federation members worldwide, no single individual or organization has complete authority over the network — a structure intended to reduce single points of failure, though this incident raises new questions about how that distributed authority model handles a rapid, large-scale security event.
The “White-Hat” Question
The self-identification of the actors as “white-hat hackers” carries significant weight for how this incident is ultimately resolved, but it remains an unverified claim rather than a confirmed fact at this stage. In cryptocurrency security incidents, parties who move funds during an active exploit sometimes genuinely act to protect the funds from other, less scrupulous attackers who might have discovered the same vulnerability, later negotiating a “bug bounty” arrangement to return the assets in exchange for a reward and immunity from prosecution.
In other cases, however, the “white-hat” framing has historically been used by attackers as a negotiating tactic after the fact, once they realize returning funds may be legally and financially safer than attempting to launder $320 million in stolen bitcoin. Blockstream’s active attempt to establish on-chain communication suggests the company is treating this as an open negotiation rather than a resolved matter.
What Happens Next
As of publication, Liquid Network remains fully paused, LBTC deposits and withdrawals remain suspended across participating exchanges, and Blockstream has not yet confirmed whether contact with the responsible party has been established or whether any funds have been returned.
Given the incident occurred during evening hours and involves an unusually large sum relative to the network’s total reserves, additional details, technical post-mortems, and updates on fund recovery are expected to continue emerging in the hours and days following this initial disclosure.
Article
Connected Africa 2026 – 7th Edition Telecom Innovation & Excellence AwardsConnected Africa 2026 – 7th Edition Telecom Innovation & Excellence Awards Africa’s Premier Telecom SummitTheme: Driving Africa’s Telecom Shift to Digital Platforms and Next-Gen Infrastructure Date: 15 October 2026Venue: Johannesburg, South Africa Johannesburg, South Africa – The International Center for Strategic Alliances (ICSA) proudly announces the 7th Edition of Connected Africa – Telecom Innovation & Excellence Awards, set to take place on 15 October 2026. Recognized as Africa’s premier telecom and digital-infrastructure summit, Connected Africa 2026 will convene the continent’s most influential leaders across telecom, banking, cybersecurity, cloud, and enterprise technology to accelerate South Africa’s digital future. As ICSA’s flagship telecom and digital-infrastructure platform, Connected Africa has consistently delivered high-impact dialogue, strategic partnerships, and market-defining insights across emerging economies. The 2026 edition builds on this legacy—bringing together policymakers, regulators, CXOs, and innovators to explore how intelligent technologies are reshaping banking, security, and enterprise modernization in South Africa. A Strategic Moment for South Africa’s Digital Economy South Africa stands at a pivotal inflection point in its digital transformation journey. With rapid advancements in 5G, cloud, AI, cybersecurity, and digital finance, the nation is accelerating toward a more connected, secure, and resilient economy. Connected Africa 2026 will serve as a critical platform to examine policy direction, investment priorities, and technology adoption—aligning public and private sectors to unlock inclusive, technology-driven growth. Key Focus Areas Intelligent banking & embedded finance powering next-generation digital services Cybersecurity resilience and real-time threat intelligence Cloud modernization, hyperscale data centers, and edge computing 5G evolution, network intelligence, and advanced connectivity Digital identity, fraud prevention, and secure transaction frameworks Enterprise modernization through automation, IoT, and AI Cross-industry collaboration shaping South Africa’s digital future Why Connected Africa Matters Connected Africa 2026 is more than a summit—it is a strategic nexus for decision-makers shaping national and continental digital agendas. Participants gain: High-level dialogue across telecom, finance, government, and enterprise Actionable insights into investments driving digital modernization Solution showcases addressing connectivity, security, and scalability challenges Strategic partnerships spanning public and private sectors Telecom Innovation & Excellence Awards A cornerstone of the 7th edition, the Telecom Innovation & Excellence Awards will celebrate organizations and leaders delivering outstanding impact across network innovation, digital inclusion, security excellence, enterprise transformation, and customer experience—reinforcing Africa’s global leadership in telecom and digital infrastructure. Participation Opportunities Connected Africa 2026 is open for: Sponsorship & strategic partnerships Speaking & thought-leadership engagements Technology exhibitions & innovation showcases Enterprise, government, and industry registrations About ICSA The International Center for Strategic Alliances (ICSA) is a global organization committed to advancing digital transformation, infrastructure development, and industry collaboration through high-impact conferences, executive engagements, and strategic forums across emerging markets. ICSA’s platforms connect decision-makers with technology leaders to drive measurable outcomes and long-term growth. For Engagement & EnquiriesTel: +44 20 3808 8625Email: info@intercsa.comWebsite: https://connected-africa.com/summit/  

Connected Africa 2026 – 7th Edition Telecom Innovation & Excellence Awards

Connected Africa 2026 – 7th Edition Telecom Innovation & Excellence Awards
Africa’s Premier Telecom SummitTheme: Driving Africa’s Telecom Shift to Digital Platforms and Next-Gen Infrastructure
Date: 15 October 2026Venue: Johannesburg, South Africa
Johannesburg, South Africa – The International Center for Strategic Alliances (ICSA) proudly announces the 7th Edition of Connected Africa – Telecom Innovation & Excellence Awards, set to take place on 15 October 2026. Recognized as Africa’s premier telecom and digital-infrastructure summit, Connected Africa 2026 will convene the continent’s most influential leaders across telecom, banking, cybersecurity, cloud, and enterprise technology to accelerate South Africa’s digital future.
As ICSA’s flagship telecom and digital-infrastructure platform, Connected Africa has consistently delivered high-impact dialogue, strategic partnerships, and market-defining insights across emerging economies. The 2026 edition builds on this legacy—bringing together policymakers, regulators, CXOs, and innovators to explore how intelligent technologies are reshaping banking, security, and enterprise modernization in South Africa.
A Strategic Moment for South Africa’s Digital Economy
South Africa stands at a pivotal inflection point in its digital transformation journey. With rapid advancements in 5G, cloud, AI, cybersecurity, and digital finance, the nation is accelerating toward a more connected, secure, and resilient economy. Connected Africa 2026 will serve as a critical platform to examine policy direction, investment priorities, and technology adoption—aligning public and private sectors to unlock inclusive, technology-driven growth.
Key Focus Areas
Intelligent banking & embedded finance powering next-generation digital services
Cybersecurity resilience and real-time threat intelligence
Cloud modernization, hyperscale data centers, and edge computing
5G evolution, network intelligence, and advanced connectivity
Digital identity, fraud prevention, and secure transaction frameworks
Enterprise modernization through automation, IoT, and AI
Cross-industry collaboration shaping South Africa’s digital future
Why Connected Africa Matters
Connected Africa 2026 is more than a summit—it is a strategic nexus for decision-makers shaping national and continental digital agendas. Participants gain:
High-level dialogue across telecom, finance, government, and enterprise
Actionable insights into investments driving digital modernization
Solution showcases addressing connectivity, security, and scalability challenges
Strategic partnerships spanning public and private sectors
Telecom Innovation & Excellence Awards
A cornerstone of the 7th edition, the Telecom Innovation & Excellence Awards will celebrate organizations and leaders delivering outstanding impact across network innovation, digital inclusion, security excellence, enterprise transformation, and customer experience—reinforcing Africa’s global leadership in telecom and digital infrastructure.
Participation Opportunities
Connected Africa 2026 is open for:
Sponsorship & strategic partnerships
Speaking & thought-leadership engagements
Technology exhibitions & innovation showcases
Enterprise, government, and industry registrations
About ICSA
The International Center for Strategic Alliances (ICSA) is a global organization committed to advancing digital transformation, infrastructure development, and industry collaboration through high-impact conferences, executive engagements, and strategic forums across emerging markets. ICSA’s platforms connect decision-makers with technology leaders to drive measurable outcomes and long-term growth.
For Engagement & EnquiriesTel: +44 20 3808 8625Email: info@intercsa.comWebsite: https://connected-africa.com/summit/
Connected Africa 2026 – 7th Edition Telecom Innovation & Excellence AwardsConnected Africa 2026 – 7th Edition Telecom Innovation & Excellence Awards Africa’s Premier Telecom Summit Theme: Driving Africa’s Telecom Shift to Digital Platforms and Next-Gen Infrastructure Date: 15 October 2026 Venue: Johannesburg, South Africa Johannesburg, South Africa – The International Center for Strategic Alliances (ICSA) proudly announces the 7th Edition of Connected Africa – Telecom Innovation & Excellence Awards, set to take place on 15 October 2026. Recognized as Africa’s premier telecom and digital-infrastructure summit, Connected Africa 2026 will convene the continent’s most influential leaders across telecom, banking, cybersecurity, cloud, and enterprise technology to accelerate South Africa’s digital future. As ICSA’s flagship telecom and digital-infrastructure platform, Connected Africa has consistently delivered high-impact dialogue, strategic partnerships, and market-defining insights across emerging economies. The 2026 edition builds on this legacy—bringing together policymakers, regulators, CXOs, and innovators to explore how intelligent technologies are reshaping banking, security, and enterprise modernization in South Africa. A Strategic Moment for South Africa’s Digital Economy South Africa stands at a pivotal inflection point in its digital transformation journey. With rapid advancements in 5G, cloud, AI, cybersecurity, and digital finance, the nation is accelerating toward a more connected, secure, and resilient economy. Connected Africa 2026 will serve as a critical platform to examine policy direction, investment priorities, and technology adoption—aligning public and private sectors to unlock inclusive, technology-driven growth. Key Focus Areas Intelligent banking & embedded finance powering next-generation digital services Cybersecurity resilience and real-time threat intelligence Cloud modernization, hyperscale data centers, and edge computing 5G evolution, network intelligence, and advanced connectivity Digital identity, fraud prevention, and secure transaction frameworks Enterprise modernization through automation, IoT, and AI Cross-industry collaboration shaping South Africa’s digital future Why Connected Africa Matters Connected Africa 2026 is more than a summit—it is a strategic nexus for decision-makers shaping national and continental digital agendas. Participants gain: High-level dialogue across telecom, finance, government, and enterprise Actionable insights into investments driving digital modernization Solution showcases addressing connectivity, security, and scalability challenges Strategic partnerships spanning public and private sectors Telecom Innovation & Excellence Awards A cornerstone of the 7th edition, the Telecom Innovation & Excellence Awards will celebrate organizations and leaders delivering outstanding impact across network innovation, digital inclusion, security excellence, enterprise transformation, and customer experience—reinforcing Africa’s global leadership in telecom and digital infrastructure. Participation Opportunities Connected Africa 2026 is open for: Sponsorship & strategic partnerships Speaking & thought-leadership engagements Technology exhibitions & innovation showcases Enterprise, government, and industry registrations About ICSA The International Center for Strategic Alliances (ICSA) is a global organization committed to advancing digital transformation, infrastructure development, and industry collaboration through high-impact conferences, executive engagements, and strategic forums across emerging markets. ICSA’s platforms connect decision-makers with technology leaders to drive measurable outcomes and long-term growth. For Engagement & Enquiries Tel: +44 20 3808 8625 Email: info@intercsa.com Website: https://connected-africa.com/summit/  

Connected Africa 2026 – 7th Edition Telecom Innovation & Excellence Awards

Connected Africa 2026 – 7th Edition Telecom Innovation & Excellence Awards
Africa’s Premier Telecom Summit
Theme: Driving Africa’s Telecom Shift to Digital Platforms and Next-Gen Infrastructure
Date: 15 October 2026
Venue: Johannesburg, South Africa
Johannesburg, South Africa – The International Center for Strategic Alliances (ICSA) proudly announces the 7th Edition of Connected Africa – Telecom Innovation & Excellence Awards, set to take place on 15 October 2026. Recognized as Africa’s premier telecom and digital-infrastructure summit, Connected Africa 2026 will convene the continent’s most influential leaders across telecom, banking, cybersecurity, cloud, and enterprise technology to accelerate South Africa’s digital future.
As ICSA’s flagship telecom and digital-infrastructure platform, Connected Africa has consistently delivered high-impact dialogue, strategic partnerships, and market-defining insights across emerging economies. The 2026 edition builds on this legacy—bringing together policymakers, regulators, CXOs, and innovators to explore how intelligent technologies are reshaping banking, security, and enterprise modernization in South Africa.
A Strategic Moment for South Africa’s Digital Economy
South Africa stands at a pivotal inflection point in its digital transformation journey. With rapid advancements in 5G, cloud, AI, cybersecurity, and digital finance, the nation is accelerating toward a more connected, secure, and resilient economy. Connected Africa 2026 will serve as a critical platform to examine policy direction, investment priorities, and technology adoption—aligning public and private sectors to unlock inclusive, technology-driven growth.
Key Focus Areas
Intelligent banking & embedded finance powering next-generation digital services
Cybersecurity resilience and real-time threat intelligence
Cloud modernization, hyperscale data centers, and edge computing
5G evolution, network intelligence, and advanced connectivity
Digital identity, fraud prevention, and secure transaction frameworks
Enterprise modernization through automation, IoT, and AI
Cross-industry collaboration shaping South Africa’s digital future
Why Connected Africa Matters
Connected Africa 2026 is more than a summit—it is a strategic nexus for decision-makers shaping national and continental digital agendas. Participants gain:
High-level dialogue across telecom, finance, government, and enterprise
Actionable insights into investments driving digital modernization
Solution showcases addressing connectivity, security, and scalability challenges
Strategic partnerships spanning public and private sectors
Telecom Innovation & Excellence Awards
A cornerstone of the 7th edition, the Telecom Innovation & Excellence Awards will celebrate organizations and leaders delivering outstanding impact across network innovation, digital inclusion, security excellence, enterprise transformation, and customer experience—reinforcing Africa’s global leadership in telecom and digital infrastructure.
Participation Opportunities
Connected Africa 2026 is open for:
Sponsorship & strategic partnerships
Speaking & thought-leadership engagements
Technology exhibitions & innovation showcases
Enterprise, government, and industry registrations
About ICSA
The International Center for Strategic Alliances (ICSA) is a global organization committed to advancing digital transformation, infrastructure development, and industry collaboration through high-impact conferences, executive engagements, and strategic forums across emerging markets. ICSA’s platforms connect decision-makers with technology leaders to drive measurable outcomes and long-term growth.
For Engagement & Enquiries
Tel: +44 20 3808 8625
Email: info@intercsa.com
Website: https://connected-africa.com/summit/
Article
Robinhood Chain Hits $34.6B DEX Volume As ‘Stonks’ Meme Coin Trend Takes OffRobinhood Chain has recorded $34.6 billion in cumulative decentralized exchange (DEX) volume and $1.27 billion in protocol total value locked (TVL) just over two months after launching its public mainnet. Robinhood Crypto disclosed the figures in a two-month network update, which also showed 576 million transactions, 12.3 million addresses and more than 190 Stock Tokens already live on the blockchain. The milestone comes as activity on Robinhood Chain expands beyond tokenized equities into a new speculative market combining traditional stocks with crypto-native meme culture. Memecoins paired directly with Robinhood Stock Tokens — a trend increasingly referred to by traders as “Stonks” or “stock memes” — have started attracting significant trading activity, while Pons, a token launchpad built on the network, has become one of crypto’s largest fee-generating applications. Robinhood Chain Reaches $34.6 Billion in DEX Volume According to Robinhood Crypto, Robinhood Chain reached several major milestones during its first two months: – $34.6 billion in total DEX volume – $1.27 billion in protocol TVL – 576 million total transactions – 12.3 million total addresses – More than 190 Stock Tokens – Over $3 billion in cumulative Stock Token DEX volume – $7.29 billion in perpetual futures trading volume through Lighter The figures are Robinhood’s own reported network statistics and highlight the rapid growth of its onchain ecosystem. Robinhood Chain’s public mainnet officially launched on July 1, 2026, following the release of its public testnet on February 10. The network is an Ethereum Layer 2 built using the Arbitrum Platform and settles to Ethereum. ETH is used as its native gas token. Robinhood describes the blockchain as purpose-built for financial services and tokenized real-world assets. At launch, Robinhood announced integrations with infrastructure providers including Chainlink, Alchemy and BitGo, alongside DeFi platforms including Uniswap. Its Stock Tokens are available to eligible Robinhood Wallet users in more than 120 countries, depending on jurisdiction. Importantly, Robinhood Stock Tokens do not represent direct ownership of shares in the underlying companies. Robinhood describes the products as tokenized debt securities that provide economic exposure to the relevant underlying assets without granting traditional shareholder ownership or voting rights. Pons Becomes a Major Driver of Robinhood Chain Activity One of the biggest beneficiaries of Robinhood Chain’s recent activity has been Pons, a third-party token launchpad that allows users to create and trade tokens on the network. Pons generated approximately $5.95 million in fees over a 24-hour period on September 3, according to DefiLlama data cited by CoinDesk. That temporarily placed it fourth among all protocols tracked by the platform, behind Tether, Uniswap and Circle, while exceeding the fees generated by Robinhood Chain itself during the same period. Nearly 25,000 tokens were created through Pons on September 2, while daily trading volume reached approximately $544 million. The platform’s native PONS token has benefited from the surge in activity. On September 3, PONS traded around $0.5978 on its Uniswap pool, up 31.82% over 24 hours and around 181 times above its July 17 low of $0.0033, according to Decrypt. PONS had also overtaken CASHCAT in late August to become the largest Robinhood Chain-native cryptocurrency by market capitalization at the time. Another catalyst arrived on September 2, when Binance Wallet added PONS and FLORK to Binance Alpha, with PONS available through Binance Alpha 1.0. Pons is not an official Robinhood product, but its growth demonstrates how permissionless applications are developing independently on top of Robinhood’s blockchain. What Are ‘Stonks’ on Robinhood Chain? A particularly unusual trend has now emerged around Robinhood Chain’s biggest differentiating feature: tokenized stocks. Crypto traders have started creating memecoins whose DEX liquidity is paired directly with tokenized stocks rather than conventional assets such as ETH or stablecoins. The trend has been described across the emerging Robinhood Chain community as “stock memes” or “Stonks.” “Stonks” itself is an intentional misspelling of “stocks” originating from a long-running internet meme used humorously to describe financial markets, questionable investment decisions and unexpectedly successful trades. On Robinhood Chain, the term has taken on a more literal meaning as meme tokens become connected to onchain representations of traditional financial assets. Stock-meme projects have appeared around tokenized assets referencing companies and products including AMC Entertainment, Nvidia, Apple and Tesla, among others. Instead of a conventional MEME/ETH liquidity pool, for example, a project can establish liquidity against a tokenized equity. The structure does not mean the memecoin is issued, approved or backed by the company represented by the stock token. It remains a separate speculative crypto asset. AMC Controversy Sends the Stonks Trend Into Overdrive The distinction became particularly important on September 3 when AMC Entertainment CEO Adam Aron publicly criticized Robinhood’s tokenized version of AMC stock. Aron said AMC had no connection with the product and did not approve or endorse it. He also questioned its legal structure and said AMC would ask outside securities counsel to examine the matter. Robinhood CEO Vlad Tenev responded publicly by asking: “What’s the concern?” Robinhood’s disclosures state that its Stock Tokens provide economic exposure rather than actual ownership of the companies whose securities they track and are not offered to U.S. persons. Crypto traders quickly turned the controversy itself into another market. A Robinhood Chain memecoin called MEME, paired against the tokenized AMC asset, exploded in value within hours of its launch. GMGN data cited by BlockBeats showed its market capitalization passing $11.2 million early on September 4 before later exceeding $30 million. As speculation accelerated, the token briefly approached $150 million in market capitalization, with approximately $87.4 million in trading volume reported at that stage. The move illustrates both the appeal and extreme risk of the emerging Stonks market: valuations can change by tens of millions of dollars within hours, and the memecoins themselves have no corporate relationship with the companies referenced by their paired Stock Tokens. Robinhood Chain Blurs the Line Between TradFi and Crypto Culture Robinhood originally positioned its blockchain around bringing traditional financial assets onchain. Stock Tokens can be traded through decentralized venues and, according to Robinhood, potentially integrated into DeFi applications as collateral or deposited into lending markets. Two months after launch, however, the network is demonstrating another consequence of making traditional assets programmable: permissionless crypto markets can build entirely new products around them. The result is an unusual collision between RWAs, DeFi and memecoin speculation. Robinhood Chain’s $34.6 billion in reported DEX volume shows that significant activity has already reached the network. Pons’ explosive growth and the emergence of Stock Meme trading suggest that tokenized equities are not being used solely as digital versions of traditional investments. They are also becoming building blocks for a new — and highly speculative — category of onchain markets.

Robinhood Chain Hits $34.6B DEX Volume As ‘Stonks’ Meme Coin Trend Takes Off

Robinhood Chain has recorded $34.6 billion in cumulative decentralized exchange (DEX) volume and $1.27 billion in protocol total value locked (TVL) just over two months after launching its public mainnet. Robinhood Crypto disclosed the figures in a two-month network update, which also showed 576 million transactions, 12.3 million addresses and more than 190 Stock Tokens already live on the blockchain.
The milestone comes as activity on Robinhood Chain expands beyond tokenized equities into a new speculative market combining traditional stocks with crypto-native meme culture. Memecoins paired directly with Robinhood Stock Tokens — a trend increasingly referred to by traders as “Stonks” or “stock memes” — have started attracting significant trading activity, while Pons, a token launchpad built on the network, has become one of crypto’s largest fee-generating applications.
Robinhood Chain Reaches $34.6 Billion in DEX Volume
According to Robinhood Crypto, Robinhood Chain reached several major milestones during its first two months:
– $34.6 billion in total DEX volume – $1.27 billion in protocol TVL – 576 million total transactions – 12.3 million total addresses – More than 190 Stock Tokens – Over $3 billion in cumulative Stock Token DEX volume – $7.29 billion in perpetual futures trading volume through Lighter
The figures are Robinhood’s own reported network statistics and highlight the rapid growth of its onchain ecosystem.
Robinhood Chain’s public mainnet officially launched on July 1, 2026, following the release of its public testnet on February 10. The network is an Ethereum Layer 2 built using the Arbitrum Platform and settles to Ethereum. ETH is used as its native gas token. Robinhood describes the blockchain as purpose-built for financial services and tokenized real-world assets.
At launch, Robinhood announced integrations with infrastructure providers including Chainlink, Alchemy and BitGo, alongside DeFi platforms including Uniswap. Its Stock Tokens are available to eligible Robinhood Wallet users in more than 120 countries, depending on jurisdiction.
Importantly, Robinhood Stock Tokens do not represent direct ownership of shares in the underlying companies. Robinhood describes the products as tokenized debt securities that provide economic exposure to the relevant underlying assets without granting traditional shareholder ownership or voting rights.
Pons Becomes a Major Driver of Robinhood Chain Activity
One of the biggest beneficiaries of Robinhood Chain’s recent activity has been Pons, a third-party token launchpad that allows users to create and trade tokens on the network.
Pons generated approximately $5.95 million in fees over a 24-hour period on September 3, according to DefiLlama data cited by CoinDesk. That temporarily placed it fourth among all protocols tracked by the platform, behind Tether, Uniswap and Circle, while exceeding the fees generated by Robinhood Chain itself during the same period.
Nearly 25,000 tokens were created through Pons on September 2, while daily trading volume reached approximately $544 million.
The platform’s native PONS token has benefited from the surge in activity. On September 3, PONS traded around $0.5978 on its Uniswap pool, up 31.82% over 24 hours and around 181 times above its July 17 low of $0.0033, according to Decrypt. PONS had also overtaken CASHCAT in late August to become the largest Robinhood Chain-native cryptocurrency by market capitalization at the time. Another catalyst arrived on September 2, when Binance Wallet added PONS and FLORK to Binance Alpha, with PONS available through Binance Alpha 1.0.
Pons is not an official Robinhood product, but its growth demonstrates how permissionless applications are developing independently on top of Robinhood’s blockchain.
What Are ‘Stonks’ on Robinhood Chain?
A particularly unusual trend has now emerged around Robinhood Chain’s biggest differentiating feature: tokenized stocks.
Crypto traders have started creating memecoins whose DEX liquidity is paired directly with tokenized stocks rather than conventional assets such as ETH or stablecoins.
The trend has been described across the emerging Robinhood Chain community as “stock memes” or “Stonks.”
“Stonks” itself is an intentional misspelling of “stocks” originating from a long-running internet meme used humorously to describe financial markets, questionable investment decisions and unexpectedly successful trades. On Robinhood Chain, the term has taken on a more literal meaning as meme tokens become connected to onchain representations of traditional financial assets. Stock-meme projects have appeared around tokenized assets referencing companies and products including AMC Entertainment, Nvidia, Apple and Tesla, among others. Instead of a conventional MEME/ETH liquidity pool, for example, a project can establish liquidity against a tokenized equity.
The structure does not mean the memecoin is issued, approved or backed by the company represented by the stock token. It remains a separate speculative crypto asset.
AMC Controversy Sends the Stonks Trend Into Overdrive
The distinction became particularly important on September 3 when AMC Entertainment CEO Adam Aron publicly criticized Robinhood’s tokenized version of AMC stock.
Aron said AMC had no connection with the product and did not approve or endorse it. He also questioned its legal structure and said AMC would ask outside securities counsel to examine the matter. Robinhood CEO Vlad Tenev responded publicly by asking:
“What’s the concern?”
Robinhood’s disclosures state that its Stock Tokens provide economic exposure rather than actual ownership of the companies whose securities they track and are not offered to U.S. persons.
Crypto traders quickly turned the controversy itself into another market. A Robinhood Chain memecoin called MEME, paired against the tokenized AMC asset, exploded in value within hours of its launch. GMGN data cited by BlockBeats showed its market capitalization passing $11.2 million early on September 4 before later exceeding $30 million. As speculation accelerated, the token briefly approached $150 million in market capitalization, with approximately $87.4 million in trading volume reported at that stage.
The move illustrates both the appeal and extreme risk of the emerging Stonks market: valuations can change by tens of millions of dollars within hours, and the memecoins themselves have no corporate relationship with the companies referenced by their paired Stock Tokens.
Robinhood Chain Blurs the Line Between TradFi and Crypto Culture
Robinhood originally positioned its blockchain around bringing traditional financial assets onchain. Stock Tokens can be traded through decentralized venues and, according to Robinhood, potentially integrated into DeFi applications as collateral or deposited into lending markets.
Two months after launch, however, the network is demonstrating another consequence of making traditional assets programmable: permissionless crypto markets can build entirely new products around them.
The result is an unusual collision between RWAs, DeFi and memecoin speculation. Robinhood Chain’s $34.6 billion in reported DEX volume shows that significant activity has already reached the network. Pons’ explosive growth and the emergence of Stock Meme trading suggest that tokenized equities are not being used solely as digital versions of traditional investments.
They are also becoming building blocks for a new — and highly speculative — category of onchain markets.
Article
Ledger Faces $500 Million Class Action Alleging Company Concealed Data Breach That Enabled $1.95 ...Ledger SAS, the world’s leading hardware cryptocurrency wallet manufacturer, is facing a proposed class-action lawsuit in the U.S. District Court for the Southern District of New York, with the plaintiff alleging the company’s alleged failure to properly disclose a 2023 data breach directly enabled a sophisticated social engineering attack that drained nearly $2 million from his crypto wallets. The lawsuit seeks at least $500 million in damages on behalf of a potential class of up to 210,000 affected users. How the Alleged Theft Unfolded Plaintiff Douglas Kim filed the complaint on August 27, 2026. According to the filing, Kim purchased his first Ledger hardware wallet in 2017 and later upgraded to a Ledger Nano X in 2021 — establishing a customer relationship spanning nearly a decade before the alleged theft occurred. The complaint states that in February 2025, Kim was contacted by individuals claiming to represent Coincover and Ledger. The callers reportedly told him there had been an attempted enrollment in Ledger Recover, the company’s optional key-recovery service, and directed him to a website where he was instructed to provide sensitive information. According to the lawsuit, that information allegedly allowed the attackers to gain access to his cryptocurrency holdings. Kim discovered on February 20, 2025, that approximately $1.95 million had been transferred out of his wallets. He has reportedly not recovered any of the stolen assets. Tracing the Attack Back to a 2023 Security Incident The lawsuit’s central legal theory connects Kim’s individual loss to a broader security failure at Ledger dating back to December 2023, when the company’s Connect Kit — a software library that allows Ledger hardware wallets to interface with decentralized applications — was compromised. According to the complaint, attackers gained access through a former Ledger employee and used the compromised software library to facilitate fraudulent transactions across the platform. The filing further alleges, on information and belief, that customer data exposed during that 2023 incident was subsequently used to specifically target Kim in the February 2025 social engineering scheme — providing attackers with the contact information and contextual detail needed to convincingly impersonate Ledger and Coincover representatives. A Pattern the Lawsuit Says Goes Back Even Further The complaint frames the 2023 incident as part of a longer pattern of security failures at Ledger, pointing back to a separate 2020 data breach that exposed personal information belonging to approximately 270,000 customers, including names, email addresses, phone numbers, and other personally identifiable information. According to the lawsuit, Ledger failed to timely and fully disclose the scope of the 2023 breach specifically, and that the leaked data from both incidents ultimately circulated on dark web marketplaces, where it could be purchased and used by scammers to craft convincing impersonation attacks against Ledger’s customer base. The complaint characterizes this history in stark terms: “Ledger has demonstrated a disturbing pattern of negligent, reckless, and irresponsible behavior with regard to its security posture and a callous disregard for its obligations to the privacy of its customers’ [personally identifiable information].” The Legal Claims Kim’s lawsuit brings multiple causes of action against Ledger, including violations of New York General Business Law Sections 349 and 350 — the state’s core consumer protection statutes governing deceptive business practices — alongside claims of negligence, negligent misrepresentation, promissory estoppel, and breach of the covenant of good faith and fair dealing. The complaint also demands a jury trial. The Scale of the Proposed Class Kim is seeking to represent a nationwide class of Ledger users who may have been similarly affected. The complaint estimates the proposed class could encompass up to 210,000 people, with total damages across the class potentially reaching at least $500 million — a figure that, if the class were certified and the plaintiffs prevailed, would represent one of the largest consumer damages awards in the cryptocurrency hardware industry’s history. Important Legal Caveats It’s worth emphasizing that, as with any newly filed complaint, none of the allegations against Ledger have been proven in court, and the proposed class has not yet been certified by the presiding judge. The case remains in its early stages within the Southern District of New York, and Ledger has not yet filed a formal public response to the specific allegations at the time of this reporting. Why This Case Matters for the Broader Crypto Security Landscape This lawsuit lands amid a broader wave of concern about physical and social engineering attacks targeting hardware wallet customers specifically. Similar incidents involving both Ledger and competitor Trezor have surfaced in recent months, including fraudulent physical mail scams and data exposure incidents tied to third-party shipping and fulfillment partners rather than the wallet manufacturers’ own core infrastructure. What distinguishes the Ledger case is the legal argument being tested: that a company’s delayed or incomplete breach disclosure can itself become the basis for liability when leaked data is later weaponized in downstream fraud, rather than liability being limited to the original breach alone. For the broader hardware wallet industry, the outcome of this case could set an important precedent regarding how quickly and thoroughly companies are legally required to disclose security incidents involving customer data — particularly in an industry where the entire value proposition rests on customers trusting that their private keys and personal information remain secure. If Kim’s theory succeeds, it may push hardware wallet manufacturers toward faster, more comprehensive breach notifications, alongside more aggressive proactive warnings to customers about phishing and impersonation risks whenever a data exposure incident occurs, rather than treating disclosure as a purely discretionary or minimized corporate communications decision.

Ledger Faces $500 Million Class Action Alleging Company Concealed Data Breach That Enabled $1.95 ...

Ledger SAS, the world’s leading hardware cryptocurrency wallet manufacturer, is facing a proposed class-action lawsuit in the U.S. District Court for the Southern District of New York, with the plaintiff alleging the company’s alleged failure to properly disclose a 2023 data breach directly enabled a sophisticated social engineering attack that drained nearly $2 million from his crypto wallets.
The lawsuit seeks at least $500 million in damages on behalf of a potential class of up to 210,000 affected users.
How the Alleged Theft Unfolded
Plaintiff Douglas Kim filed the complaint on August 27, 2026. According to the filing, Kim purchased his first Ledger hardware wallet in 2017 and later upgraded to a Ledger Nano X in 2021 — establishing a customer relationship spanning nearly a decade before the alleged theft occurred.
The complaint states that in February 2025, Kim was contacted by individuals claiming to represent Coincover and Ledger. The callers reportedly told him there had been an attempted enrollment in Ledger Recover, the company’s optional key-recovery service, and directed him to a website where he was instructed to provide sensitive information. According to the lawsuit, that information allegedly allowed the attackers to gain access to his cryptocurrency holdings. Kim discovered on February 20, 2025, that approximately $1.95 million had been transferred out of his wallets. He has reportedly not recovered any of the stolen assets.
Tracing the Attack Back to a 2023 Security Incident
The lawsuit’s central legal theory connects Kim’s individual loss to a broader security failure at Ledger dating back to December 2023, when the company’s Connect Kit — a software library that allows Ledger hardware wallets to interface with decentralized applications — was compromised. According to the complaint, attackers gained access through a former Ledger employee and used the compromised software library to facilitate fraudulent transactions across the platform.
The filing further alleges, on information and belief, that customer data exposed during that 2023 incident was subsequently used to specifically target Kim in the February 2025 social engineering scheme — providing attackers with the contact information and contextual detail needed to convincingly impersonate Ledger and Coincover representatives.
A Pattern the Lawsuit Says Goes Back Even Further
The complaint frames the 2023 incident as part of a longer pattern of security failures at Ledger, pointing back to a separate 2020 data breach that exposed personal information belonging to approximately 270,000 customers, including names, email addresses, phone numbers, and other personally identifiable information. According to the lawsuit, Ledger failed to timely and fully disclose the scope of the 2023 breach specifically, and that the leaked data from both incidents ultimately circulated on dark web marketplaces, where it could be purchased and used by scammers to craft convincing impersonation attacks against Ledger’s customer base.
The complaint characterizes this history in stark terms:
“Ledger has demonstrated a disturbing pattern of negligent, reckless, and irresponsible behavior with regard to its security posture and a callous disregard for its obligations to the privacy of its customers’ [personally identifiable information].”
The Legal Claims
Kim’s lawsuit brings multiple causes of action against Ledger, including violations of New York General Business Law Sections 349 and 350 — the state’s core consumer protection statutes governing deceptive business practices — alongside claims of negligence, negligent misrepresentation, promissory estoppel, and breach of the covenant of good faith and fair dealing. The complaint also demands a jury trial.
The Scale of the Proposed Class
Kim is seeking to represent a nationwide class of Ledger users who may have been similarly affected. The complaint estimates the proposed class could encompass up to 210,000 people, with total damages across the class potentially reaching at least $500 million — a figure that, if the class were certified and the plaintiffs prevailed, would represent one of the largest consumer damages awards in the cryptocurrency hardware industry’s history.
Important Legal Caveats
It’s worth emphasizing that, as with any newly filed complaint, none of the allegations against Ledger have been proven in court, and the proposed class has not yet been certified by the presiding judge. The case remains in its early stages within the Southern District of New York, and Ledger has not yet filed a formal public response to the specific allegations at the time of this reporting.
Why This Case Matters for the Broader Crypto Security Landscape
This lawsuit lands amid a broader wave of concern about physical and social engineering attacks targeting hardware wallet customers specifically. Similar incidents involving both Ledger and competitor Trezor have surfaced in recent months, including fraudulent physical mail scams and data exposure incidents tied to third-party shipping and fulfillment partners rather than the wallet manufacturers’ own core infrastructure.
What distinguishes the Ledger case is the legal argument being tested: that a company’s delayed or incomplete breach disclosure can itself become the basis for liability when leaked data is later weaponized in downstream fraud, rather than liability being limited to the original breach alone.
For the broader hardware wallet industry, the outcome of this case could set an important precedent regarding how quickly and thoroughly companies are legally required to disclose security incidents involving customer data — particularly in an industry where the entire value proposition rests on customers trusting that their private keys and personal information remain secure.
If Kim’s theory succeeds, it may push hardware wallet manufacturers toward faster, more comprehensive breach notifications, alongside more aggressive proactive warnings to customers about phishing and impersonation risks whenever a data exposure incident occurs, rather than treating disclosure as a purely discretionary or minimized corporate communications decision.
Robinhood Chain Hits $34.6B DEX Volume as ‘Stonks’ Meme Coin Trend Takes OffRobinhood Chain has recorded $34.6 billion in cumulative decentralized exchange (DEX) volume and $1.27 billion in protocol total value locked (TVL) just over two months after launching its public mainnet. Robinhood Crypto disclosed the figures in a two-month network update, which also showed 576 million transactions, 12.3 million addresses and more than 190 Stock Tokens already live on the blockchain. The milestone comes as activity on Robinhood Chain expands beyond tokenized equities into a new speculative market combining traditional stocks with crypto-native meme culture. Memecoins paired directly with Robinhood Stock Tokens — a trend increasingly referred to by traders as “Stonks” or “stock memes” — have started attracting significant trading activity, while Pons, a token launchpad built on the network, has become one of crypto’s largest fee-generating applications. Robinhood Chain Reaches $34.6 Billion in DEX Volume According to Robinhood Crypto, Robinhood Chain reached several major milestones during its first two months: – $34.6 billion in total DEX volume – $1.27 billion in protocol TVL – 576 million total transactions – 12.3 million total addresses – More than 190 Stock Tokens – Over $3 billion in cumulative Stock Token DEX volume – $7.29 billion in perpetual futures trading volume through Lighter The figures are Robinhood’s own reported network statistics and highlight the rapid growth of its onchain ecosystem. Robinhood Chain’s public mainnet officially launched on July 1, 2026, following the release of its public testnet on February 10. The network is an Ethereum Layer 2 built using the Arbitrum Platform and settles to Ethereum. ETH is used as its native gas token. Robinhood describes the blockchain as purpose-built for financial services and tokenized real-world assets. At launch, Robinhood announced integrations with infrastructure providers including Chainlink, Alchemy and BitGo, alongside DeFi platforms including Uniswap. Its Stock Tokens are available to eligible Robinhood Wallet users in more than 120 countries, depending on jurisdiction. Importantly, Robinhood Stock Tokens do not represent direct ownership of shares in the underlying companies. Robinhood describes the products as tokenized debt securities that provide economic exposure to the relevant underlying assets without granting traditional shareholder ownership or voting rights. Pons Becomes a Major Driver of Robinhood Chain Activity One of the biggest beneficiaries of Robinhood Chain’s recent activity has been Pons, a third-party token launchpad that allows users to create and trade tokens on the network. Pons generated approximately $5.95 million in fees over a 24-hour period on September 3, according to DefiLlama data cited by CoinDesk. That temporarily placed it fourth among all protocols tracked by the platform, behind Tether, Uniswap and Circle, while exceeding the fees generated by Robinhood Chain itself during the same period. Nearly 25,000 tokens were created through Pons on September 2, while daily trading volume reached approximately $544 million. The platform’s native PONS token has benefited from the surge in activity. On September 3, PONS traded around $0.5978 on its Uniswap pool, up 31.82% over 24 hours and around 181 times above its July 17 low of $0.0033, according to Decrypt. PONS had also overtaken CASHCAT in late August to become the largest Robinhood Chain-native cryptocurrency by market capitalization at the time. Another catalyst arrived on September 2, when Binance Wallet added PONS and FLORK to Binance Alpha, with PONS available through Binance Alpha 1.0. Pons is not an official Robinhood product, but its growth demonstrates how permissionless applications are developing independently on top of Robinhood’s blockchain. What Are ‘Stonks’ on Robinhood Chain? A particularly unusual trend has now emerged around Robinhood Chain’s biggest differentiating feature: tokenized stocks. Crypto traders have started creating memecoins whose DEX liquidity is paired directly with tokenized stocks rather than conventional assets such as ETH or stablecoins. The trend has been described across the emerging Robinhood Chain community as “stock memes” or “Stonks.” “Stonks” itself is an intentional misspelling of “stocks” originating from a long-running internet meme used humorously to describe financial markets, questionable investment decisions and unexpectedly successful trades. On Robinhood Chain, the term has taken on a more literal meaning as meme tokens become connected to onchain representations of traditional financial assets. Stock-meme projects have appeared around tokenized assets referencing companies and products including AMC Entertainment, Nvidia, Apple and Tesla, among others. Instead of a conventional MEME/ETH liquidity pool, for example, a project can establish liquidity against a tokenized equity. The structure does not mean the memecoin is issued, approved or backed by the company represented by the stock token. It remains a separate speculative crypto asset. AMC Controversy Sends the Stonks Trend Into Overdrive The distinction became particularly important on September 3 when AMC Entertainment CEO Adam Aron publicly criticized Robinhood’s tokenized version of AMC stock. Aron said AMC had no connection with the product and did not approve or endorse it. He also questioned its legal structure and said AMC would ask outside securities counsel to examine the matter. Robinhood CEO Vlad Tenev responded publicly by asking: “What’s the concern?” Robinhood’s disclosures state that its Stock Tokens provide economic exposure rather than actual ownership of the companies whose securities they track and are not offered to U.S. persons. Crypto traders quickly turned the controversy itself into another market. A Robinhood Chain memecoin called MEME, paired against the tokenized AMC asset, exploded in value within hours of its launch. GMGN data cited by BlockBeats showed its market capitalization passing $11.2 million early on September 4 before later exceeding $30 million. As speculation accelerated, the token briefly approached $150 million in market capitalization, with approximately $87.4 million in trading volume reported at that stage. The move illustrates both the appeal and extreme risk of the emerging Stonks market: valuations can change by tens of millions of dollars within hours, and the memecoins themselves have no corporate relationship with the companies referenced by their paired Stock Tokens. Robinhood Chain Blurs the Line Between TradFi and Crypto Culture Robinhood originally positioned its blockchain around bringing traditional financial assets onchain. Stock Tokens can be traded through decentralized venues and, according to Robinhood, potentially integrated into DeFi applications as collateral or deposited into lending markets. Two months after launch, however, the network is demonstrating another consequence of making traditional assets programmable: permissionless crypto markets can build entirely new products around them. The result is an unusual collision between RWAs, DeFi and memecoin speculation. Robinhood Chain’s $34.6 billion in reported DEX volume shows that significant activity has already reached the network. Pons’ explosive growth and the emergence of Stock Meme trading suggest that tokenized equities are not being used solely as digital versions of traditional investments. They are also becoming building blocks for a new — and highly speculative — category of onchain markets.

Robinhood Chain Hits $34.6B DEX Volume as ‘Stonks’ Meme Coin Trend Takes Off

Robinhood Chain has recorded $34.6 billion in cumulative decentralized exchange (DEX) volume and $1.27 billion in protocol total value locked (TVL) just over two months after launching its public mainnet. Robinhood Crypto disclosed the figures in a two-month network update, which also showed 576 million transactions, 12.3 million addresses and more than 190 Stock Tokens already live on the blockchain.
The milestone comes as activity on Robinhood Chain expands beyond tokenized equities into a new speculative market combining traditional stocks with crypto-native meme culture. Memecoins paired directly with Robinhood Stock Tokens — a trend increasingly referred to by traders as “Stonks” or “stock memes” — have started attracting significant trading activity, while Pons, a token launchpad built on the network, has become one of crypto’s largest fee-generating applications.
Robinhood Chain Reaches $34.6 Billion in DEX Volume
According to Robinhood Crypto, Robinhood Chain reached several major milestones during its first two months:
– $34.6 billion in total DEX volume
– $1.27 billion in protocol TVL
– 576 million total transactions
– 12.3 million total addresses
– More than 190 Stock Tokens
– Over $3 billion in cumulative Stock Token DEX volume
– $7.29 billion in perpetual futures trading volume through Lighter
The figures are Robinhood’s own reported network statistics and highlight the rapid growth of its onchain ecosystem.
Robinhood Chain’s public mainnet officially launched on July 1, 2026, following the release of its public testnet on February 10. The network is an Ethereum Layer 2 built using the Arbitrum Platform and settles to Ethereum. ETH is used as its native gas token. Robinhood describes the blockchain as purpose-built for financial services and tokenized real-world assets.
At launch, Robinhood announced integrations with infrastructure providers including Chainlink, Alchemy and BitGo, alongside DeFi platforms including Uniswap. Its Stock Tokens are available to eligible Robinhood Wallet users in more than 120 countries, depending on jurisdiction.
Importantly, Robinhood Stock Tokens do not represent direct ownership of shares in the underlying companies. Robinhood describes the products as tokenized debt securities that provide economic exposure to the relevant underlying assets without granting traditional shareholder ownership or voting rights.
Pons Becomes a Major Driver of Robinhood Chain Activity
One of the biggest beneficiaries of Robinhood Chain’s recent activity has been Pons, a third-party token launchpad that allows users to create and trade tokens on the network.
Pons generated approximately $5.95 million in fees over a 24-hour period on September 3, according to DefiLlama data cited by CoinDesk. That temporarily placed it fourth among all protocols tracked by the platform, behind Tether, Uniswap and Circle, while exceeding the fees generated by Robinhood Chain itself during the same period.
Nearly 25,000 tokens were created through Pons on September 2, while daily trading volume reached approximately $544 million.
The platform’s native PONS token has benefited from the surge in activity. On September 3, PONS traded around $0.5978 on its Uniswap pool, up 31.82% over 24 hours and around 181 times above its July 17 low of $0.0033, according to Decrypt. PONS had also overtaken CASHCAT in late August to become the largest Robinhood Chain-native cryptocurrency by market capitalization at the time.
Another catalyst arrived on September 2, when Binance Wallet added PONS and FLORK to Binance Alpha, with PONS available through Binance Alpha 1.0.
Pons is not an official Robinhood product, but its growth demonstrates how permissionless applications are developing independently on top of Robinhood’s blockchain.
What Are ‘Stonks’ on Robinhood Chain?
A particularly unusual trend has now emerged around Robinhood Chain’s biggest differentiating feature: tokenized stocks.
Crypto traders have started creating memecoins whose DEX liquidity is paired directly with tokenized stocks rather than conventional assets such as ETH or stablecoins.
The trend has been described across the emerging Robinhood Chain community as “stock memes” or “Stonks.”
“Stonks” itself is an intentional misspelling of “stocks” originating from a long-running internet meme used humorously to describe financial markets, questionable investment decisions and unexpectedly successful trades. On Robinhood Chain, the term has taken on a more literal meaning as meme tokens become connected to onchain representations of traditional financial assets.
Stock-meme projects have appeared around tokenized assets referencing companies and products including AMC Entertainment, Nvidia, Apple and Tesla, among others. Instead of a conventional MEME/ETH liquidity pool, for example, a project can establish liquidity against a tokenized equity.
The structure does not mean the memecoin is issued, approved or backed by the company represented by the stock token. It remains a separate speculative crypto asset.
AMC Controversy Sends the Stonks Trend Into Overdrive
The distinction became particularly important on September 3 when AMC Entertainment CEO Adam Aron publicly criticized Robinhood’s tokenized version of AMC stock.
Aron said AMC had no connection with the product and did not approve or endorse it. He also questioned its legal structure and said AMC would ask outside securities counsel to examine the matter. Robinhood CEO Vlad Tenev responded publicly by asking:
“What’s the concern?”
Robinhood’s disclosures state that its Stock Tokens provide economic exposure rather than actual ownership of the companies whose securities they track and are not offered to U.S. persons.
Crypto traders quickly turned the controversy itself into another market.
A Robinhood Chain memecoin called MEME, paired against the tokenized AMC asset, exploded in value within hours of its launch. GMGN data cited by BlockBeats showed its market capitalization passing $11.2 million early on September 4 before later exceeding $30 million. As speculation accelerated, the token briefly approached $150 million in market capitalization, with approximately $87.4 million in trading volume reported at that stage.
The move illustrates both the appeal and extreme risk of the emerging Stonks market: valuations can change by tens of millions of dollars within hours, and the memecoins themselves have no corporate relationship with the companies referenced by their paired Stock Tokens.
Robinhood Chain Blurs the Line Between TradFi and Crypto Culture
Robinhood originally positioned its blockchain around bringing traditional financial assets onchain. Stock Tokens can be traded through decentralized venues and, according to Robinhood, potentially integrated into DeFi applications as collateral or deposited into lending markets.
Two months after launch, however, the network is demonstrating another consequence of making traditional assets programmable: permissionless crypto markets can build entirely new products around them.
The result is an unusual collision between RWAs, DeFi and memecoin speculation.
Robinhood Chain’s $34.6 billion in reported DEX volume shows that significant activity has already reached the network. Pons’ explosive growth and the emergence of Stock Meme trading suggest that tokenized equities are not being used solely as digital versions of traditional investments.
They are also becoming building blocks for a new — and highly speculative — category of onchain markets.
Ledger Faces $500 Million Class Action Alleging Company Concealed Data Breach That Enabled $1.95 ...Ledger SAS, the world’s leading hardware cryptocurrency wallet manufacturer, is facing a proposed class-action lawsuit in the U.S. District Court for the Southern District of New York, with the plaintiff alleging the company’s alleged failure to properly disclose a 2023 data breach directly enabled a sophisticated social engineering attack that drained nearly $2 million from his crypto wallets. The lawsuit seeks at least $500 million in damages on behalf of a potential class of up to 210,000 affected users. How the Alleged Theft Unfolded Plaintiff Douglas Kim filed the complaint on August 27, 2026. According to the filing, Kim purchased his first Ledger hardware wallet in 2017 and later upgraded to a Ledger Nano X in 2021 — establishing a customer relationship spanning nearly a decade before the alleged theft occurred. The complaint states that in February 2025, Kim was contacted by individuals claiming to represent Coincover and Ledger. The callers reportedly told him there had been an attempted enrollment in Ledger Recover, the company’s optional key-recovery service, and directed him to a website where he was instructed to provide sensitive information. According to the lawsuit, that information allegedly allowed the attackers to gain access to his cryptocurrency holdings. Kim discovered on February 20, 2025, that approximately $1.95 million had been transferred out of his wallets. He has reportedly not recovered any of the stolen assets. Tracing the Attack Back to a 2023 Security Incident The lawsuit’s central legal theory connects Kim’s individual loss to a broader security failure at Ledger dating back to December 2023, when the company’s Connect Kit — a software library that allows Ledger hardware wallets to interface with decentralized applications — was compromised. According to the complaint, attackers gained access through a former Ledger employee and used the compromised software library to facilitate fraudulent transactions across the platform. The filing further alleges, on information and belief, that customer data exposed during that 2023 incident was subsequently used to specifically target Kim in the February 2025 social engineering scheme — providing attackers with the contact information and contextual detail needed to convincingly impersonate Ledger and Coincover representatives. A Pattern the Lawsuit Says Goes Back Even Further The complaint frames the 2023 incident as part of a longer pattern of security failures at Ledger, pointing back to a separate 2020 data breach that exposed personal information belonging to approximately 270,000 customers, including names, email addresses, phone numbers, and other personally identifiable information. According to the lawsuit, Ledger failed to timely and fully disclose the scope of the 2023 breach specifically, and that the leaked data from both incidents ultimately circulated on dark web marketplaces, where it could be purchased and used by scammers to craft convincing impersonation attacks against Ledger’s customer base. The complaint characterizes this history in stark terms: “Ledger has demonstrated a disturbing pattern of negligent, reckless, and irresponsible behavior with regard to its security posture and a callous disregard for its obligations to the privacy of its customers’ [personally identifiable information].” The Legal Claims Kim’s lawsuit brings multiple causes of action against Ledger, including violations of New York General Business Law Sections 349 and 350 — the state’s core consumer protection statutes governing deceptive business practices — alongside claims of negligence, negligent misrepresentation, promissory estoppel, and breach of the covenant of good faith and fair dealing. The complaint also demands a jury trial. The Scale of the Proposed Class Kim is seeking to represent a nationwide class of Ledger users who may have been similarly affected. The complaint estimates the proposed class could encompass up to 210,000 people, with total damages across the class potentially reaching at least $500 million — a figure that, if the class were certified and the plaintiffs prevailed, would represent one of the largest consumer damages awards in the cryptocurrency hardware industry’s history. Important Legal Caveats It’s worth emphasizing that, as with any newly filed complaint, none of the allegations against Ledger have been proven in court, and the proposed class has not yet been certified by the presiding judge. The case remains in its early stages within the Southern District of New York, and Ledger has not yet filed a formal public response to the specific allegations at the time of this reporting. Why This Case Matters for the Broader Crypto Security Landscape This lawsuit lands amid a broader wave of concern about physical and social engineering attacks targeting hardware wallet customers specifically. Similar incidents involving both Ledger and competitor Trezor have surfaced in recent months, including fraudulent physical mail scams and data exposure incidents tied to third-party shipping and fulfillment partners rather than the wallet manufacturers’ own core infrastructure. What distinguishes the Ledger case is the legal argument being tested: that a company’s delayed or incomplete breach disclosure can itself become the basis for liability when leaked data is later weaponized in downstream fraud, rather than liability being limited to the original breach alone. For the broader hardware wallet industry, the outcome of this case could set an important precedent regarding how quickly and thoroughly companies are legally required to disclose security incidents involving customer data — particularly in an industry where the entire value proposition rests on customers trusting that their private keys and personal information remain secure. If Kim’s theory succeeds, it may push hardware wallet manufacturers toward faster, more comprehensive breach notifications, alongside more aggressive proactive warnings to customers about phishing and impersonation risks whenever a data exposure incident occurs, rather than treating disclosure as a purely discretionary or minimized corporate communications decision.

Ledger Faces $500 Million Class Action Alleging Company Concealed Data Breach That Enabled $1.95 ...

Ledger SAS, the world’s leading hardware cryptocurrency wallet manufacturer, is facing a proposed class-action lawsuit in the U.S. District Court for the Southern District of New York, with the plaintiff alleging the company’s alleged failure to properly disclose a 2023 data breach directly enabled a sophisticated social engineering attack that drained nearly $2 million from his crypto wallets.
The lawsuit seeks at least $500 million in damages on behalf of a potential class of up to 210,000 affected users.
How the Alleged Theft Unfolded
Plaintiff Douglas Kim filed the complaint on August 27, 2026. According to the filing, Kim purchased his first Ledger hardware wallet in 2017 and later upgraded to a Ledger Nano X in 2021 — establishing a customer relationship spanning nearly a decade before the alleged theft occurred.
The complaint states that in February 2025, Kim was contacted by individuals claiming to represent Coincover and Ledger. The callers reportedly told him there had been an attempted enrollment in Ledger Recover, the company’s optional key-recovery service, and directed him to a website where he was instructed to provide sensitive information. According to the lawsuit, that information allegedly allowed the attackers to gain access to his cryptocurrency holdings. Kim discovered on February 20, 2025, that approximately $1.95 million had been transferred out of his wallets. He has reportedly not recovered any of the stolen assets.
Tracing the Attack Back to a 2023 Security Incident
The lawsuit’s central legal theory connects Kim’s individual loss to a broader security failure at Ledger dating back to December 2023, when the company’s Connect Kit — a software library that allows Ledger hardware wallets to interface with decentralized applications — was compromised. According to the complaint, attackers gained access through a former Ledger employee and used the compromised software library to facilitate fraudulent transactions across the platform.
The filing further alleges, on information and belief, that customer data exposed during that 2023 incident was subsequently used to specifically target Kim in the February 2025 social engineering scheme — providing attackers with the contact information and contextual detail needed to convincingly impersonate Ledger and Coincover representatives.
A Pattern the Lawsuit Says Goes Back Even Further
The complaint frames the 2023 incident as part of a longer pattern of security failures at Ledger, pointing back to a separate 2020 data breach that exposed personal information belonging to approximately 270,000 customers, including names, email addresses, phone numbers, and other personally identifiable information. According to the lawsuit, Ledger failed to timely and fully disclose the scope of the 2023 breach specifically, and that the leaked data from both incidents ultimately circulated on dark web marketplaces, where it could be purchased and used by scammers to craft convincing impersonation attacks against Ledger’s customer base.
The complaint characterizes this history in stark terms:
“Ledger has demonstrated a disturbing pattern of negligent, reckless, and irresponsible behavior with regard to its security posture and a callous disregard for its obligations to the privacy of its customers’ [personally identifiable information].”
The Legal Claims
Kim’s lawsuit brings multiple causes of action against Ledger, including violations of New York General Business Law Sections 349 and 350 — the state’s core consumer protection statutes governing deceptive business practices — alongside claims of negligence, negligent misrepresentation, promissory estoppel, and breach of the covenant of good faith and fair dealing. The complaint also demands a jury trial.
The Scale of the Proposed Class
Kim is seeking to represent a nationwide class of Ledger users who may have been similarly affected. The complaint estimates the proposed class could encompass up to 210,000 people, with total damages across the class potentially reaching at least $500 million — a figure that, if the class were certified and the plaintiffs prevailed, would represent one of the largest consumer damages awards in the cryptocurrency hardware industry’s history.
Important Legal Caveats
It’s worth emphasizing that, as with any newly filed complaint, none of the allegations against Ledger have been proven in court, and the proposed class has not yet been certified by the presiding judge. The case remains in its early stages within the Southern District of New York, and Ledger has not yet filed a formal public response to the specific allegations at the time of this reporting.
Why This Case Matters for the Broader Crypto Security Landscape
This lawsuit lands amid a broader wave of concern about physical and social engineering attacks targeting hardware wallet customers specifically. Similar incidents involving both Ledger and competitor Trezor have surfaced in recent months, including fraudulent physical mail scams and data exposure incidents tied to third-party shipping and fulfillment partners rather than the wallet manufacturers’ own core infrastructure.
What distinguishes the Ledger case is the legal argument being tested: that a company’s delayed or incomplete breach disclosure can itself become the basis for liability when leaked data is later weaponized in downstream fraud, rather than liability being limited to the original breach alone.
For the broader hardware wallet industry, the outcome of this case could set an important precedent regarding how quickly and thoroughly companies are legally required to disclose security incidents involving customer data — particularly in an industry where the entire value proposition rests on customers trusting that their private keys and personal information remain secure.
If Kim’s theory succeeds, it may push hardware wallet manufacturers toward faster, more comprehensive breach notifications, alongside more aggressive proactive warnings to customers about phishing and impersonation risks whenever a data exposure incident occurs, rather than treating disclosure as a purely discretionary or minimized corporate communications decision.
Article
EU Just Put ChatGPT in the Same Regulatory Bucket As Google — Here’s What That MeansThe European Commission has formally designated ChatGPT as a Very Large Online Search Engine (VLOSE) under the EU’s Digital Services Act (DSA), placing OpenAI’s flagship product under the same heightened regulatory scrutiny previously reserved for platforms like Google Search and Bing. The same announcement designated Reddit and Roblox as Very Large Online Platforms (VLOPs), subjecting both to comparable obligations. All three companies now have until January 2027 to bring their services into full compliance with the DSA’s most demanding requirements. Why These Three Platforms Crossed the Threshold Under the DSA, any online service must self-report reaching an average of at least 45 million monthly active users within the European Union to qualify for VLOP or VLOSE designation — a threshold representing roughly 10% of the EU’s total population. ChatGPT, Reddit, and Roblox all confirmed they had surpassed this figure, triggering their formal classification by the Commission. OpenAI’s own disclosed figures put the scale of ChatGPT’s European search usage well beyond the minimum threshold. According to data OpenAI submitted covering the period from October 2025 through March 31, 2026, ChatGPT’s search functionality alone averaged approximately 159.1 million monthly users across the European Union — more than three times the 45-million threshold required for VLOSE status. What Changes for OpenAI Now With the VLOSE designation in effect, ChatGPT becomes subject to the DSA’s most stringent obligations, specifically designed for platforms and search engines the Commission considers capable of generating systemic risk at EU-wide scale. OpenAI must now identify, assess, and actively mitigate systemic risks tied to its service, spanning several specific categories: the spread of illegal content, the protection of minors using the platform, users’ physical and mental well-being, the protection of fundamental rights, and risks to electoral processes and public security. Beyond risk assessment, OpenAI is required to establish an internal compliance function specifically dedicated to DSA obligations, undergo independent, externally conducted audits at least once per year, and provide relevant operational data to both the European Commission and national regulators across member states. Additionally, vetted external researchers will gain the ability to formally request access to platform data needed to independently study systemic risks — a transparency requirement that has, for other VLOPs and VLOSEs, previously extended to areas like recommendation algorithm behavior and content moderation practices. Mitigation measures the Commission can require are not limited to policy changes; they can extend to structural modifications of how the underlying service and its algorithmic or recommendation systems actually operate. For ChatGPT specifically, this could mean adjustments to how its search functionality surfaces information, handles queries related to elections or public health, or filters content accessible to younger users. The Financial Stakes of Non-Compliance The DSA carries substantial financial consequences for platforms that fail to meet these obligations. Companies designated as VLOPs or VLOSEs that violate the regulation can face fines of up to 6% of their global annual revenue — not merely EU-generated revenue, but the company’s total worldwide turnover. Beyond financial penalties, the Commission retains authority to formally compel companies to remedy identified violations directly. Part of a Broader EU Regulatory Push on AI and Tech Platforms This designation does not exist in isolation. It follows closely on the heels of a separate but related regulatory expansion: in August 2026, the European Commission gained formal authority to impose fines on providers of general-purpose AI models specifically for violations of the EU’s AI Act, a distinct piece of legislation targeting the development and deployment of artificial intelligence systems rather than online platform behavior. Together, the DSA designation and the AI Act enforcement authority signal that EU regulators are now applying overlapping layers of scrutiny to major AI companies — one focused on platform-level systemic risk (DSA), the other on the underlying AI models and systems themselves (AI Act). This regulatory environment sits alongside the EU’s ongoing “Chat Control” framework governing messaging platforms, which currently operates under temporary rules allowing voluntary scanning of unencrypted content for child sexual abuse material, with end-to-end encrypted messages remaining outside the scope of that scanning permission. EU governments extended those temporary provisions through April 2028 while broader legislative debate over a permanent framework continues — illustrating a wider pattern of the EU building out comprehensive digital governance across search, social platforms, AI systems, and messaging simultaneously. What This Means for the EU Market The practical impact on OpenAI’s European operations is likely to be significant, though not necessarily disruptive to everyday users. Companies designated as VLOPs or VLOSEs under the DSA — including Google, Meta, TikTok, and Amazon before them — have generally responded by building out dedicated EU compliance teams, publishing periodic risk assessment reports, and in some cases modifying algorithmic systems specifically for EU users to satisfy regulatory requirements, sometimes resulting in feature differences between EU and non-EU versions of a product. For OpenAI specifically, the designation formalizes something the sheer scale of ChatGPT’s European user base had already made inevitable: treatment as critical digital infrastructure rather than an emerging technology product exempt from the compliance burdens applied to established search engines and social platforms. Given that ChatGPT’s search feature alone reaches over 159 million monthly EU users — a figure larger than the entire population of most EU member states combined — the Commission’s designation reflects a recognition that generative AI search tools have already achieved a scale of societal reach comparable to the platforms the DSA was originally built to regulate. What Happens Next OpenAI, Reddit, and Roblox now have until January 2027 to demonstrate full compliance with their respective VLOSE and VLOP obligations. Given the precedent set by earlier DSA enforcement actions against other major platforms, the coming months are likely to bring public risk assessment disclosures, potential structural changes to how these services operate for EU users, and continued scrutiny from both the European Commission and vetted independent researchers examining how these platforms manage the systemic risks the DSA is designed to address.

EU Just Put ChatGPT in the Same Regulatory Bucket As Google — Here’s What That Means

The European Commission has formally designated ChatGPT as a Very Large Online Search Engine (VLOSE) under the EU’s Digital Services Act (DSA), placing OpenAI’s flagship product under the same heightened regulatory scrutiny previously reserved for platforms like Google Search and Bing.
The same announcement designated Reddit and Roblox as Very Large Online Platforms (VLOPs), subjecting both to comparable obligations. All three companies now have until January 2027 to bring their services into full compliance with the DSA’s most demanding requirements.
Why These Three Platforms Crossed the Threshold
Under the DSA, any online service must self-report reaching an average of at least 45 million monthly active users within the European Union to qualify for VLOP or VLOSE designation — a threshold representing roughly 10% of the EU’s total population. ChatGPT, Reddit, and Roblox all confirmed they had surpassed this figure, triggering their formal classification by the Commission.
OpenAI’s own disclosed figures put the scale of ChatGPT’s European search usage well beyond the minimum threshold. According to data OpenAI submitted covering the period from October 2025 through March 31, 2026, ChatGPT’s search functionality alone averaged approximately 159.1 million monthly users across the European Union — more than three times the 45-million threshold required for VLOSE status.
What Changes for OpenAI Now
With the VLOSE designation in effect, ChatGPT becomes subject to the DSA’s most stringent obligations, specifically designed for platforms and search engines the Commission considers capable of generating systemic risk at EU-wide scale. OpenAI must now identify, assess, and actively mitigate systemic risks tied to its service, spanning several specific categories: the spread of illegal content, the protection of minors using the platform, users’ physical and mental well-being, the protection of fundamental rights, and risks to electoral processes and public security.
Beyond risk assessment, OpenAI is required to establish an internal compliance function specifically dedicated to DSA obligations, undergo independent, externally conducted audits at least once per year, and provide relevant operational data to both the European Commission and national regulators across member states. Additionally, vetted external researchers will gain the ability to formally request access to platform data needed to independently study systemic risks — a transparency requirement that has, for other VLOPs and VLOSEs, previously extended to areas like recommendation algorithm behavior and content moderation practices.
Mitigation measures the Commission can require are not limited to policy changes; they can extend to structural modifications of how the underlying service and its algorithmic or recommendation systems actually operate. For ChatGPT specifically, this could mean adjustments to how its search functionality surfaces information, handles queries related to elections or public health, or filters content accessible to younger users.
The Financial Stakes of Non-Compliance
The DSA carries substantial financial consequences for platforms that fail to meet these obligations. Companies designated as VLOPs or VLOSEs that violate the regulation can face fines of up to 6% of their global annual revenue — not merely EU-generated revenue, but the company’s total worldwide turnover. Beyond financial penalties, the Commission retains authority to formally compel companies to remedy identified violations directly.
Part of a Broader EU Regulatory Push on AI and Tech Platforms
This designation does not exist in isolation. It follows closely on the heels of a separate but related regulatory expansion: in August 2026, the European Commission gained formal authority to impose fines on providers of general-purpose AI models specifically for violations of the EU’s AI Act, a distinct piece of legislation targeting the development and deployment of artificial intelligence systems rather than online platform behavior. Together, the DSA designation and the AI Act enforcement authority signal that EU regulators are now applying overlapping layers of scrutiny to major AI companies — one focused on platform-level systemic risk (DSA), the other on the underlying AI models and systems themselves (AI Act).
This regulatory environment sits alongside the EU’s ongoing “Chat Control” framework governing messaging platforms, which currently operates under temporary rules allowing voluntary scanning of unencrypted content for child sexual abuse material, with end-to-end encrypted messages remaining outside the scope of that scanning permission. EU governments extended those temporary provisions through April 2028 while broader legislative debate over a permanent framework continues — illustrating a wider pattern of the EU building out comprehensive digital governance across search, social platforms, AI systems, and messaging simultaneously.
What This Means for the EU Market
The practical impact on OpenAI’s European operations is likely to be significant, though not necessarily disruptive to everyday users. Companies designated as VLOPs or VLOSEs under the DSA — including Google, Meta, TikTok, and Amazon before them — have generally responded by building out dedicated EU compliance teams, publishing periodic risk assessment reports, and in some cases modifying algorithmic systems specifically for EU users to satisfy regulatory requirements, sometimes resulting in feature differences between EU and non-EU versions of a product.
For OpenAI specifically, the designation formalizes something the sheer scale of ChatGPT’s European user base had already made inevitable: treatment as critical digital infrastructure rather than an emerging technology product exempt from the compliance burdens applied to established search engines and social platforms. Given that ChatGPT’s search feature alone reaches over 159 million monthly EU users — a figure larger than the entire population of most EU member states combined — the Commission’s designation reflects a recognition that generative AI search tools have already achieved a scale of societal reach comparable to the platforms the DSA was originally built to regulate.
What Happens Next
OpenAI, Reddit, and Roblox now have until January 2027 to demonstrate full compliance with their respective VLOSE and VLOP obligations. Given the precedent set by earlier DSA enforcement actions against other major platforms, the coming months are likely to bring public risk assessment disclosures, potential structural changes to how these services operate for EU users, and continued scrutiny from both the European Commission and vetted independent researchers examining how these platforms manage the systemic risks the DSA is designed to address.
EU Just Put ChatGPT in the Same Regulatory Bucket as Google — Here’s What That MeansThe European Commission has formally designated ChatGPT as a Very Large Online Search Engine (VLOSE) under the EU’s Digital Services Act (DSA), placing OpenAI’s flagship product under the same heightened regulatory scrutiny previously reserved for platforms like Google Search and Bing. The same announcement designated Reddit and Roblox as Very Large Online Platforms (VLOPs), subjecting both to comparable obligations. All three companies now have until January 2027 to bring their services into full compliance with the DSA’s most demanding requirements. Why These Three Platforms Crossed the Threshold Under the DSA, any online service must self-report reaching an average of at least 45 million monthly active users within the European Union to qualify for VLOP or VLOSE designation — a threshold representing roughly 10% of the EU’s total population. ChatGPT, Reddit, and Roblox all confirmed they had surpassed this figure, triggering their formal classification by the Commission. OpenAI’s own disclosed figures put the scale of ChatGPT’s European search usage well beyond the minimum threshold. According to data OpenAI submitted covering the period from October 2025 through March 31, 2026, ChatGPT’s search functionality alone averaged approximately 159.1 million monthly users across the European Union — more than three times the 45-million threshold required for VLOSE status. What Changes for OpenAI Now With the VLOSE designation in effect, ChatGPT becomes subject to the DSA’s most stringent obligations, specifically designed for platforms and search engines the Commission considers capable of generating systemic risk at EU-wide scale. OpenAI must now identify, assess, and actively mitigate systemic risks tied to its service, spanning several specific categories: the spread of illegal content, the protection of minors using the platform, users’ physical and mental well-being, the protection of fundamental rights, and risks to electoral processes and public security. Beyond risk assessment, OpenAI is required to establish an internal compliance function specifically dedicated to DSA obligations, undergo independent, externally conducted audits at least once per year, and provide relevant operational data to both the European Commission and national regulators across member states. Additionally, vetted external researchers will gain the ability to formally request access to platform data needed to independently study systemic risks — a transparency requirement that has, for other VLOPs and VLOSEs, previously extended to areas like recommendation algorithm behavior and content moderation practices. Mitigation measures the Commission can require are not limited to policy changes; they can extend to structural modifications of how the underlying service and its algorithmic or recommendation systems actually operate. For ChatGPT specifically, this could mean adjustments to how its search functionality surfaces information, handles queries related to elections or public health, or filters content accessible to younger users. The Financial Stakes of Non-Compliance The DSA carries substantial financial consequences for platforms that fail to meet these obligations. Companies designated as VLOPs or VLOSEs that violate the regulation can face fines of up to 6% of their global annual revenue — not merely EU-generated revenue, but the company’s total worldwide turnover. Beyond financial penalties, the Commission retains authority to formally compel companies to remedy identified violations directly. Part of a Broader EU Regulatory Push on AI and Tech Platforms This designation does not exist in isolation. It follows closely on the heels of a separate but related regulatory expansion: in August 2026, the European Commission gained formal authority to impose fines on providers of general-purpose AI models specifically for violations of the EU’s AI Act, a distinct piece of legislation targeting the development and deployment of artificial intelligence systems rather than online platform behavior. Together, the DSA designation and the AI Act enforcement authority signal that EU regulators are now applying overlapping layers of scrutiny to major AI companies — one focused on platform-level systemic risk (DSA), the other on the underlying AI models and systems themselves (AI Act). This regulatory environment sits alongside the EU’s ongoing “Chat Control” framework governing messaging platforms, which currently operates under temporary rules allowing voluntary scanning of unencrypted content for child sexual abuse material, with end-to-end encrypted messages remaining outside the scope of that scanning permission. EU governments extended those temporary provisions through April 2028 while broader legislative debate over a permanent framework continues — illustrating a wider pattern of the EU building out comprehensive digital governance across search, social platforms, AI systems, and messaging simultaneously. What This Means for the EU Market The practical impact on OpenAI’s European operations is likely to be significant, though not necessarily disruptive to everyday users. Companies designated as VLOPs or VLOSEs under the DSA — including Google, Meta, TikTok, and Amazon before them — have generally responded by building out dedicated EU compliance teams, publishing periodic risk assessment reports, and in some cases modifying algorithmic systems specifically for EU users to satisfy regulatory requirements, sometimes resulting in feature differences between EU and non-EU versions of a product. For OpenAI specifically, the designation formalizes something the sheer scale of ChatGPT’s European user base had already made inevitable: treatment as critical digital infrastructure rather than an emerging technology product exempt from the compliance burdens applied to established search engines and social platforms. Given that ChatGPT’s search feature alone reaches over 159 million monthly EU users — a figure larger than the entire population of most EU member states combined — the Commission’s designation reflects a recognition that generative AI search tools have already achieved a scale of societal reach comparable to the platforms the DSA was originally built to regulate. What Happens Next OpenAI, Reddit, and Roblox now have until January 2027 to demonstrate full compliance with their respective VLOSE and VLOP obligations. Given the precedent set by earlier DSA enforcement actions against other major platforms, the coming months are likely to bring public risk assessment disclosures, potential structural changes to how these services operate for EU users, and continued scrutiny from both the European Commission and vetted independent researchers examining how these platforms manage the systemic risks the DSA is designed to address.

EU Just Put ChatGPT in the Same Regulatory Bucket as Google — Here’s What That Means

The European Commission has formally designated ChatGPT as a Very Large Online Search Engine (VLOSE) under the EU’s Digital Services Act (DSA), placing OpenAI’s flagship product under the same heightened regulatory scrutiny previously reserved for platforms like Google Search and Bing.
The same announcement designated Reddit and Roblox as Very Large Online Platforms (VLOPs), subjecting both to comparable obligations. All three companies now have until January 2027 to bring their services into full compliance with the DSA’s most demanding requirements.
Why These Three Platforms Crossed the Threshold
Under the DSA, any online service must self-report reaching an average of at least 45 million monthly active users within the European Union to qualify for VLOP or VLOSE designation — a threshold representing roughly 10% of the EU’s total population. ChatGPT, Reddit, and Roblox all confirmed they had surpassed this figure, triggering their formal classification by the Commission.
OpenAI’s own disclosed figures put the scale of ChatGPT’s European search usage well beyond the minimum threshold. According to data OpenAI submitted covering the period from October 2025 through March 31, 2026, ChatGPT’s search functionality alone averaged approximately 159.1 million monthly users across the European Union — more than three times the 45-million threshold required for VLOSE status.
What Changes for OpenAI Now
With the VLOSE designation in effect, ChatGPT becomes subject to the DSA’s most stringent obligations, specifically designed for platforms and search engines the Commission considers capable of generating systemic risk at EU-wide scale. OpenAI must now identify, assess, and actively mitigate systemic risks tied to its service, spanning several specific categories: the spread of illegal content, the protection of minors using the platform, users’ physical and mental well-being, the protection of fundamental rights, and risks to electoral processes and public security.
Beyond risk assessment, OpenAI is required to establish an internal compliance function specifically dedicated to DSA obligations, undergo independent, externally conducted audits at least once per year, and provide relevant operational data to both the European Commission and national regulators across member states. Additionally, vetted external researchers will gain the ability to formally request access to platform data needed to independently study systemic risks — a transparency requirement that has, for other VLOPs and VLOSEs, previously extended to areas like recommendation algorithm behavior and content moderation practices.
Mitigation measures the Commission can require are not limited to policy
changes; they can extend to structural modifications of how the underlying service and its algorithmic or recommendation systems actually operate. For ChatGPT specifically, this could mean adjustments to how its search functionality surfaces information, handles queries related to elections or public health, or filters content accessible to younger users.
The Financial Stakes of Non-Compliance
The DSA carries substantial financial consequences for platforms that fail to meet these obligations. Companies designated as VLOPs or VLOSEs that violate the regulation can face fines of up to 6% of their global annual revenue — not merely EU-generated revenue, but the company’s total worldwide turnover. Beyond financial penalties, the Commission retains authority to formally compel companies to remedy identified violations directly.
Part of a Broader EU Regulatory Push on AI and Tech Platforms
This designation does not exist in isolation. It follows closely on the heels of a separate but related regulatory expansion: in August 2026, the European Commission gained formal authority to impose fines on providers of general-purpose AI models specifically for violations of the EU’s AI Act, a distinct piece of legislation targeting the development and deployment of artificial intelligence systems rather than online platform behavior. Together, the DSA designation and the AI Act enforcement authority signal that EU regulators are now applying overlapping layers of scrutiny to major AI companies — one focused on platform-level systemic risk (DSA), the other on the underlying AI models and systems themselves (AI Act).
This regulatory environment sits alongside the EU’s ongoing “Chat Control” framework governing messaging platforms, which currently operates under temporary rules allowing voluntary scanning of unencrypted content for child sexual abuse material, with end-to-end encrypted messages remaining outside the scope of that scanning permission. EU governments extended those temporary provisions through April 2028 while broader legislative debate over a permanent framework continues — illustrating a wider pattern of the EU building out comprehensive digital governance across search, social platforms, AI systems, and messaging simultaneously.
What This Means for the EU Market
The practical impact on OpenAI’s European operations is likely to be significant, though not necessarily disruptive to everyday users. Companies designated as VLOPs or VLOSEs under the DSA — including Google, Meta, TikTok, and Amazon before them — have generally responded by building out dedicated EU compliance teams, publishing periodic risk assessment reports, and in some cases modifying algorithmic systems specifically for EU users to satisfy regulatory requirements, sometimes resulting in feature differences between EU and non-EU versions of a product.
For OpenAI specifically, the designation formalizes something the sheer scale of ChatGPT’s European user base had already made inevitable: treatment as critical digital infrastructure rather than an emerging technology product exempt from the compliance burdens applied to established search engines and social platforms. Given that ChatGPT’s search feature alone reaches over 159 million monthly EU users — a figure larger than the entire population of most EU member states combined — the Commission’s designation reflects a recognition that generative AI search tools have already achieved a scale of societal reach comparable to the platforms the DSA was originally built to regulate.
What Happens Next
OpenAI, Reddit, and Roblox now have until January 2027 to demonstrate full compliance with their respective VLOSE and VLOP obligations. Given the precedent set by earlier DSA enforcement actions against other major platforms, the coming months are likely to bring public risk assessment disclosures, potential structural changes to how these services operate for EU users, and continued scrutiny from both the European Commission and vetted independent researchers examining how these platforms manage the systemic risks the DSA is designed to address.
Article
Lazarus Group Moves $30 Million Through Hyperliquid As Trump Pushes to Bring Exchange OnshoreWallets linked to North Korea’s state-sponsored Lazarus Group have moved more than $30 million in Bitcoin through decentralized exchange Hyperliquid over the past three weeks, according to blockchain analysis — a development that lands at an especially awkward moment, just as President Trump publicly pushes to bring the platform fully into the U.S. regulatory system. How the Funds Moved Emmett Gallic, an analyst at blockchain intelligence firm Arkham, identified the wallet activity and traced it back to addresses first attributed to Lazarus Group by independent investigator ZachXBT in 2024, at which point those wallets were already linked to $61 million in previously stolen funds. According to Gallic, the funds followed a consistent laundering pattern: Bitcoin arrived on Hyperliquid through HyperUnit, the platform’s asset bridge, where it was traded into Ethereum (ETH) and Solana (SOL). From there, the converted assets were bridged out across Tron, Solana, and Ethereum networks before ultimately landing as deposits at centralized exchanges including Kraken, LBank, and KuCoin, alongside several unlabeled Tron-based services. Gallic identified two distinct wallet clusters. The larger cluster, responsible for roughly $30 million in inbound volume, traced directly back to addresses already confirmed as belonging to Lazarus Group. A second, smaller cluster — accounting for approximately $5 million in Hyperliquid volume — showed dormancy patterns, address structures, and counterparty behavior closely matching the confirmed Lazarus wallets, though it has not been definitively attributed. In his own words, Gallic wrote: “Addresses linked to OFAC Sanctioned Lazarus Group (North Korea) have been actively moving $30M+ through Hyperliquid (HyperUnit) as recent as yesterday.” Who Is Lazarus Group Lazarus Group is a hacking organization widely assessed by Western intelligence agencies and cybersecurity firms to operate on behalf of the North Korean government, generating revenue for the state through cybercrime — most notably large-scale cryptocurrency theft — to help fund the country’s weapons programs amid international sanctions. The U.S. Treasury’s Office of Foreign Assets Control (OFAC) formally sanctioned the group in 2019, making transactions involving its wallets illegal for U.S. persons and entities under U.S. jurisdiction to knowingly facilitate. The group’s track record includes some of the largest crypto heists in history. It has been directly linked to the 2022 Ronin Network bridge exploit, which resulted in losses exceeding $600 million, and more recently to the February 2025 Bybit hack, which drained approximately $1.5 billion and stands as the largest single crypto theft ever recorded. According to reporting from BeInCrypto, North Korea-linked actors are estimated to have stolen roughly $1.6 billion in cryptocurrency during just the first half of 2025 alone — representing approximately 70% of all global crypto losses during that period. Security researchers have consistently noted that Lazarus Group typically relies on exactly this kind of multi-hop laundering pattern — cycling stolen funds through several blockchains and swapping between assets — specifically to obscure the money trail before cashing out through centralized exchanges. Why This Is a Problem for Hyperliquid Specifically The timing is particularly uncomfortable for Hyperliquid. The decentralized derivatives exchange operates without the standard know-your-customer (KYC) identity verification requirements common at centralized platforms, a design choice that has previously drawn scrutiny over its potential use as a venue for sanctions evasion. Unlike a centralized exchange, which can freeze suspicious accounts or block known sanctioned addresses at the point of deposit, Hyperliquid’s permissionless architecture makes it structurally more difficult to prevent sanctioned actors from accessing the platform in the first place. This isn’t a hypothetical reputational risk — it directly intersects with Hyperliquid’s most significant near-term business goal: gaining legitimate access to the U.S. market. President Trump named Hyperliquid specifically during an August White House event, stating: “I understand that Mike is also working to bring Hyperliquid into the United States in a fully compliant and legal fashion, working very hard on that” — crediting Commodity Futures Trading Commission (CFTC) Chairman Michael Selig with leading that regulatory effort. Selig’s CFTC has already cleared a Bitcoin perpetual futures product on a registered exchange earlier this year, a precedent that could inform how regulators ultimately evaluate Hyperliquid’s own application for U.S. market access. The disclosure of sustained, sanctioned-entity fund flows through the platform — surfacing at precisely the moment U.S. regulators are actively evaluating Hyperliquid’s path to compliant onshore operation — creates a direct tension the exchange will need to address. Regulators considering whether to grant Hyperliquid legitimate U.S. market access will now have to weigh that decision against fresh, documented evidence of North Korean state-linked laundering activity moving through the exact same platform, raising the practical question of what technical or compliance safeguards Hyperliquid can implement without abandoning the permissionless, non-KYC model that defines its product. Market Reaction Has Been Muted So Far Despite the seriousness of the sanctions questions raised, the market’s response has been notably subdued. HYPE, Hyperliquid’s native governance token, traded at $84 at time of reporting, reflecting a 5% gain over the prior 24 hours — a move that suggests traders have not yet meaningfully priced in any sanctions-related risk to the platform. Notably, HYPE had set a record all-time high of $86.71 on August 27, just days before the Lazarus-linked wallet activity became public, indicating the token’s momentum entering this news cycle was already strongly positive. What Comes Next The core tension now facing Hyperliquid is straightforward but consequential: the same permissionless, KYC-free architecture that has driven its growth and trading volume is precisely what makes it structurally vulnerable to exactly the kind of sanctioned-actor activity now under public scrutiny. As CFTC Chairman Selig continues working toward a compliant path for Hyperliquid to formally enter the U.S. market, this disclosure adds a concrete data point regulators will almost certainly need to address — whether through mandated compliance tooling, transaction monitoring requirements, or other safeguards — before any onshoring effort can move forward. For now, neither Hyperliquid nor U.S. regulators have publicly detailed how, or whether, the platform plans to respond to the specific fund flows identified by Arkham’s analysis.

Lazarus Group Moves $30 Million Through Hyperliquid As Trump Pushes to Bring Exchange Onshore

Wallets linked to North Korea’s state-sponsored Lazarus Group have moved more than $30 million in Bitcoin through decentralized exchange Hyperliquid over the past three weeks, according to blockchain analysis — a development that lands at an especially awkward moment, just as President Trump publicly pushes to bring the platform fully into the U.S. regulatory system.
How the Funds Moved
Emmett Gallic, an analyst at blockchain intelligence firm Arkham, identified the wallet activity and traced it back to addresses first attributed to Lazarus Group by independent investigator ZachXBT in 2024, at which point those wallets were already linked to $61 million in previously stolen funds.
According to Gallic, the funds followed a consistent laundering pattern: Bitcoin arrived on Hyperliquid through HyperUnit, the platform’s asset bridge, where it was traded into Ethereum (ETH) and Solana (SOL). From there, the converted assets were bridged out across Tron, Solana, and Ethereum networks before ultimately landing as deposits at centralized exchanges including Kraken, LBank, and KuCoin, alongside several unlabeled Tron-based services.
Gallic identified two distinct wallet clusters. The larger cluster, responsible for roughly $30 million in inbound volume, traced directly back to addresses already confirmed as belonging to Lazarus Group. A second, smaller cluster — accounting for approximately $5 million in Hyperliquid volume — showed dormancy patterns, address structures, and counterparty behavior closely matching the confirmed Lazarus wallets, though it has not been definitively attributed. In his own words, Gallic wrote:
“Addresses linked to OFAC Sanctioned Lazarus Group (North Korea) have been actively moving $30M+ through Hyperliquid (HyperUnit) as recent as yesterday.”
Who Is Lazarus Group
Lazarus Group is a hacking organization widely assessed by Western intelligence agencies and cybersecurity firms to operate on behalf of the North Korean government, generating revenue for the state through cybercrime — most notably large-scale cryptocurrency theft — to help fund the country’s weapons programs amid international sanctions. The U.S. Treasury’s Office of Foreign Assets Control (OFAC) formally sanctioned the group in 2019, making transactions involving its wallets illegal for U.S. persons and entities under U.S. jurisdiction to knowingly facilitate.
The group’s track record includes some of the largest crypto heists in history. It has been directly linked to the 2022 Ronin Network bridge exploit, which resulted in losses exceeding $600 million, and more recently to the February 2025 Bybit hack, which drained approximately $1.5 billion and stands as the largest single crypto theft ever recorded.
According to reporting from BeInCrypto, North Korea-linked actors are estimated to have stolen roughly $1.6 billion in cryptocurrency during just the first half of 2025 alone — representing approximately 70% of all global crypto losses during that period. Security researchers have consistently noted that Lazarus Group typically relies on exactly this kind of multi-hop laundering pattern — cycling stolen funds through several blockchains and swapping between assets — specifically to obscure the money trail before cashing out through centralized exchanges.
Why This Is a Problem for Hyperliquid Specifically
The timing is particularly uncomfortable for Hyperliquid. The decentralized derivatives exchange operates without the standard know-your-customer (KYC) identity verification requirements common at centralized platforms, a design choice that has previously drawn scrutiny over its potential use as a venue for sanctions evasion. Unlike a centralized exchange, which can freeze suspicious accounts or block known sanctioned addresses at the point of deposit, Hyperliquid’s permissionless architecture makes it structurally more difficult to prevent sanctioned actors from accessing the platform in the first place.
This isn’t a hypothetical reputational risk — it directly intersects with Hyperliquid’s most significant near-term business goal: gaining legitimate access to the U.S. market. President Trump named Hyperliquid specifically during an August White House event, stating: “I understand that Mike is also working to bring Hyperliquid into the United States in a fully compliant and legal fashion, working very hard on that” — crediting Commodity Futures Trading Commission (CFTC) Chairman Michael Selig with leading that regulatory effort.
Selig’s CFTC has already cleared a Bitcoin perpetual futures product on a registered exchange earlier this year, a precedent that could inform how regulators ultimately evaluate Hyperliquid’s own application for U.S. market access.
The disclosure of sustained, sanctioned-entity fund flows through the platform — surfacing at precisely the moment U.S. regulators are actively evaluating Hyperliquid’s path to compliant onshore operation — creates a direct tension the exchange will need to address. Regulators considering whether to grant Hyperliquid legitimate U.S. market access will now have to weigh that decision against fresh, documented evidence of North Korean state-linked laundering activity moving through the exact same platform, raising the practical question of what technical or compliance safeguards Hyperliquid can implement without abandoning the permissionless, non-KYC model that defines its product.
Market Reaction Has Been Muted So Far
Despite the seriousness of the sanctions questions raised, the market’s response has been notably subdued. HYPE, Hyperliquid’s native governance token, traded at $84 at time of reporting, reflecting a 5% gain over the prior 24 hours — a move that suggests traders have not yet meaningfully priced in any sanctions-related risk to the platform. Notably, HYPE had set a record all-time high of $86.71 on August 27, just days before the Lazarus-linked wallet activity became public, indicating the token’s momentum entering this news cycle was already strongly positive.
What Comes Next
The core tension now facing Hyperliquid is straightforward but consequential: the same permissionless, KYC-free architecture that has driven its growth and trading volume is precisely what makes it structurally vulnerable to exactly the kind of sanctioned-actor activity now under public scrutiny.
As CFTC Chairman Selig continues working toward a compliant path for Hyperliquid to formally enter the U.S. market, this disclosure adds a concrete data point regulators will almost certainly need to address — whether through mandated compliance tooling, transaction monitoring requirements, or other safeguards — before any onshoring effort can move forward. For now, neither Hyperliquid nor U.S. regulators have publicly detailed how, or whether, the platform plans to respond to the specific fund flows identified by Arkham’s analysis.
Lazarus Group Moves $30 Million Through Hyperliquid as Trump Pushes to Bring Exchange OnshoreWallets linked to North Korea’s state-sponsored Lazarus Group have moved more than $30 million in Bitcoin through decentralized exchange Hyperliquid over the past three weeks, according to blockchain analysis — a development that lands at an especially awkward moment, just as President Trump publicly pushes to bring the platform fully into the U.S. regulatory system. How the Funds Moved Emmett Gallic, an analyst at blockchain intelligence firm Arkham, identified the wallet activity and traced it back to addresses first attributed to Lazarus Group by independent investigator ZachXBT in 2024, at which point those wallets were already linked to $61 million in previously stolen funds. According to Gallic, the funds followed a consistent laundering pattern: Bitcoin arrived on Hyperliquid through HyperUnit, the platform’s asset bridge, where it was traded into Ethereum (ETH) and Solana (SOL). From there, the converted assets were bridged out across Tron, Solana, and Ethereum networks before ultimately landing as deposits at centralized exchanges including Kraken, LBank, and KuCoin, alongside several unlabeled Tron-based services. Gallic identified two distinct wallet clusters. The larger cluster, responsible for roughly $30 million in inbound volume, traced directly back to addresses already confirmed as belonging to Lazarus Group. A second, smaller cluster — accounting for approximately $5 million in Hyperliquid volume — showed dormancy patterns, address structures, and counterparty behavior closely matching the confirmed Lazarus wallets, though it has not been definitively attributed. In his own words, Gallic wrote: “Addresses linked to OFAC Sanctioned Lazarus Group (North Korea) have been actively moving $30M+ through Hyperliquid (HyperUnit) as recent as yesterday.” Who Is Lazarus Group Lazarus Group is a hacking organization widely assessed by Western intelligence agencies and cybersecurity firms to operate on behalf of the North Korean government, generating revenue for the state through cybercrime — most notably large-scale cryptocurrency theft — to help fund the country’s weapons programs amid international sanctions. The U.S. Treasury’s Office of Foreign Assets Control (OFAC) formally sanctioned the group in 2019, making transactions involving its wallets illegal for U.S. persons and entities under U.S. jurisdiction to knowingly facilitate. The group’s track record includes some of the largest crypto heists in history. It has been directly linked to the 2022 Ronin Network bridge exploit, which resulted in losses exceeding $600 million, and more recently to the February 2025 Bybit hack, which drained approximately $1.5 billion and stands as the largest single crypto theft ever recorded. According to reporting from BeInCrypto, North Korea-linked actors are estimated to have stolen roughly $1.6 billion in cryptocurrency during just the first half of 2025 alone — representing approximately 70% of all global crypto losses during that period. Security researchers have consistently noted that Lazarus Group typically relies on exactly this kind of multi-hop laundering pattern — cycling stolen funds through several blockchains and swapping between assets — specifically to obscure the money trail before cashing out through centralized exchanges. Why This Is a Problem for Hyperliquid Specifically The timing is particularly uncomfortable for Hyperliquid. The decentralized derivatives exchange operates without the standard know-your-customer (KYC) identity verification requirements common at centralized platforms, a design choice that has previously drawn scrutiny over its potential use as a venue for sanctions evasion. Unlike a centralized exchange, which can freeze suspicious accounts or block known sanctioned addresses at the point of deposit, Hyperliquid’s permissionless architecture makes it structurally more difficult to prevent sanctioned actors from accessing the platform in the first place. This isn’t a hypothetical reputational risk — it directly intersects with Hyperliquid’s most significant near-term business goal: gaining legitimate access to the U.S. market. President Trump named Hyperliquid specifically during an August White House event, stating: “I understand that Mike is also working to bring Hyperliquid into the United States in a fully compliant and legal fashion, working very hard on that” — crediting Commodity Futures Trading Commission (CFTC) Chairman Michael Selig with leading that regulatory effort. Selig’s CFTC has already cleared a Bitcoin perpetual futures product on a registered exchange earlier this year, a precedent that could inform how regulators ultimately evaluate Hyperliquid’s own application for U.S. market access. The disclosure of sustained, sanctioned-entity fund flows through the platform — surfacing at precisely the moment U.S. regulators are actively evaluating Hyperliquid’s path to compliant onshore operation — creates a direct tension the exchange will need to address. Regulators considering whether to grant Hyperliquid legitimate U.S. market access will now have to weigh that decision against fresh, documented evidence of North Korean state-linked laundering activity moving through the exact same platform, raising the practical question of what technical or compliance safeguards Hyperliquid can implement without abandoning the permissionless, non-KYC model that defines its product. Market Reaction Has Been Muted So Far Despite the seriousness of the sanctions questions raised, the market’s response has been notably subdued. HYPE, Hyperliquid’s native governance token, traded at $84 at time of reporting, reflecting a 5% gain over the prior 24 hours — a move that suggests traders have not yet meaningfully priced in any sanctions-related risk to the platform. Notably, HYPE had set a record all-time high of $86.71 on August 27, just days before the Lazarus-linked wallet activity became public, indicating the token’s momentum entering this news cycle was already strongly positive. What Comes Next The core tension now facing Hyperliquid is straightforward but consequential: the same permissionless, KYC-free architecture that has driven its growth and trading volume is precisely what makes it structurally vulnerable to exactly the kind of sanctioned-actor activity now under public scrutiny. As CFTC Chairman Selig continues working toward a compliant path for Hyperliquid to formally enter the U.S. market, this disclosure adds a concrete data point regulators will almost certainly need to address — whether through mandated compliance tooling, transaction monitoring requirements, or other safeguards — before any onshoring effort can move forward. For now, neither Hyperliquid nor U.S. regulators have publicly detailed how, or whether, the platform plans to respond to the specific fund flows identified by Arkham’s analysis.

Lazarus Group Moves $30 Million Through Hyperliquid as Trump Pushes to Bring Exchange Onshore

Wallets linked to North Korea’s state-sponsored Lazarus Group have moved more than $30 million in Bitcoin through decentralized exchange Hyperliquid over the past three weeks, according to blockchain analysis — a development that lands at an especially awkward moment, just as President Trump publicly pushes to bring the platform fully into the U.S. regulatory system.
How the Funds Moved
Emmett Gallic, an analyst at blockchain intelligence firm Arkham, identified the wallet activity and traced it back to addresses first attributed to Lazarus Group by independent investigator ZachXBT in 2024, at which point those wallets were already linked to $61 million in previously stolen funds.
According to Gallic, the funds followed a consistent laundering pattern: Bitcoin arrived on Hyperliquid through HyperUnit, the platform’s asset bridge, where it was traded into Ethereum (ETH) and Solana (SOL). From there, the converted assets were bridged out across Tron, Solana, and Ethereum networks before ultimately landing as deposits at centralized exchanges including Kraken, LBank, and KuCoin, alongside several unlabeled Tron-based services.
Gallic identified two distinct wallet clusters. The larger cluster, responsible for roughly $30 million in inbound volume, traced directly back to addresses already confirmed as belonging to Lazarus Group. A second, smaller cluster — accounting for approximately $5 million in Hyperliquid volume — showed dormancy patterns, address structures, and counterparty behavior closely matching the confirmed Lazarus wallets, though it has not been definitively attributed. In his own words, Gallic wrote:
“Addresses linked to OFAC Sanctioned Lazarus Group (North Korea) have been actively moving $30M+ through Hyperliquid (HyperUnit) as recent as yesterday.”
Who Is Lazarus Group
Lazarus Group is a hacking organization widely assessed by Western intelligence agencies and cybersecurity firms to operate on behalf of the North Korean government, generating revenue for the state through cybercrime — most notably large-scale cryptocurrency theft — to help fund the country’s weapons programs amid international sanctions. The U.S. Treasury’s Office of Foreign Assets Control (OFAC) formally sanctioned the group in 2019, making transactions involving its wallets illegal for U.S. persons and entities under U.S. jurisdiction to knowingly facilitate.
The group’s track record includes some of the largest crypto heists in history. It has been directly linked to the 2022 Ronin Network bridge exploit, which resulted in losses exceeding $600 million, and more recently to the February 2025 Bybit hack, which drained approximately $1.5 billion and stands as the largest single crypto theft ever recorded.
According to reporting from BeInCrypto, North Korea-linked actors are estimated to have stolen roughly $1.6 billion in cryptocurrency during just the first half of 2025 alone — representing approximately 70% of all global crypto losses during that period. Security researchers have consistently noted that Lazarus Group typically relies on exactly this kind of multi-hop laundering pattern — cycling stolen funds through several blockchains and swapping between assets — specifically to obscure the money trail before cashing out through centralized exchanges.
Why This Is a Problem for Hyperliquid Specifically
The timing is particularly uncomfortable for Hyperliquid. The decentralized derivatives exchange operates without the standard know-your-customer (KYC) identity verification requirements common at centralized platforms, a design choice that has previously drawn scrutiny over its potential use as a venue for sanctions evasion. Unlike a centralized exchange, which can freeze suspicious accounts or block known sanctioned addresses at the point of deposit, Hyperliquid’s permissionless architecture makes it structurally more difficult to prevent sanctioned actors from accessing the platform in the first place.
This isn’t a hypothetical reputational risk — it directly intersects with Hyperliquid’s most significant near-term business goal: gaining legitimate access to the U.S. market. President Trump named Hyperliquid specifically during an August White House event, stating: “I understand that Mike is also working to bring Hyperliquid into the United States in a fully compliant and legal fashion, working very hard on that” — crediting Commodity Futures Trading Commission (CFTC) Chairman Michael Selig with leading that regulatory effort.
Selig’s CFTC has already cleared a Bitcoin perpetual futures product on a registered exchange earlier this year, a precedent that could inform how regulators ultimately evaluate Hyperliquid’s own application for U.S. market access.
The disclosure of sustained, sanctioned-entity fund flows through the platform — surfacing at precisely the moment U.S. regulators are actively evaluating Hyperliquid’s path to compliant onshore operation — creates a direct tension the exchange will need to address. Regulators considering whether to grant Hyperliquid legitimate U.S. market access will now have to weigh that decision against fresh, documented evidence of North Korean state-linked laundering activity moving through the exact same platform, raising the practical question of what technical or compliance safeguards Hyperliquid can implement without abandoning the permissionless, non-KYC model that defines its product.
Market Reaction Has Been Muted So Far
Despite the seriousness of the sanctions questions raised, the market’s response has been notably subdued. HYPE, Hyperliquid’s native governance token, traded at $84 at time of reporting, reflecting a 5% gain over the prior 24 hours — a move that suggests traders have not yet meaningfully priced in any sanctions-related risk to the platform. Notably, HYPE had set a record all-time high of $86.71 on August 27, just days before the Lazarus-linked wallet activity became public, indicating the token’s momentum entering this news cycle was already strongly positive.
What Comes Next
The core tension now facing Hyperliquid is straightforward but consequential: the same permissionless, KYC-free architecture that has driven its growth and trading volume is precisely what makes it structurally vulnerable to exactly the kind of sanctioned-actor activity now under public scrutiny.
As CFTC Chairman Selig continues working toward a compliant path for Hyperliquid to formally enter the U.S. market, this disclosure adds a concrete data point regulators will almost certainly need to address — whether through mandated compliance tooling, transaction monitoring requirements, or other safeguards — before any onshoring effort can move forward. For now, neither Hyperliquid nor U.S. regulators have publicly detailed how, or whether, the platform plans to respond to the specific fund flows identified by Arkham’s analysis.
Cronos Blockchain Halted After Attacker Drains $75 Million From Tectonic Lending ProtocolCronos, the blockchain network originally developed by Crypto.com, took the unusual step of halting its entire chain after an attacker exploited Tectonic, the network’s largest lending protocol, in an attack preliminarily estimated at $75 million. The incident marks the third price-manipulation exploit of this specific style to hit DeFi lending protocols in recent months, following similar attacks on Moonwell and the reUSD/Pendle YT market. How the Attack Worked According to onchain researcher Weilin Li, who has been tracking the exploit in real time, the attacker manipulated the price of TONIC, Tectonic’s own governance token, before borrowing heavily against the artificially inflated collateral value. Li explained the underlying vulnerability plainly: “The root cause is simple: TONIC, it’s own governance token has a 20% collateral factor, with very thin liquidity. The attacker performed a Mango-market style pump-and-borrow price manipulation attack. TONIC’s price surged by 100x within 20 minutes.” The attack technique echoes the infamous 2022 Mango Markets exploit, in which an attacker used a similar strategy — artificially pumping the price of a low-liquidity token, then using the inflated valuation as collateral to borrow far more in other assets than the position was legitimately worth. In Tectonic’s case, allowing TONIC itself to be used as collateral at a 20% factor, combined with thin trading liquidity that made the token’s price easy to manipulate, created the exact conditions such an attack requires. The Race to Contain the Damage Cronos Network moved quickly once the exploit was detected, posting on X: “We identified an exploit in Tectonic. The Cronos Network has been halted and we’ll provide updates here.” The team later added it remained halted while investigating “with support from security teams across the industry.” That rapid response appears to have limited the attacker’s ability to move stolen funds off-chain. According to Li, the attacker managed to bridge only approximately $6 million to Ethereum before Cronos halted the network, leaving roughly $60 million still stranded on the Cronos chain itself. Notably, rather than attempting further transfers, the attacker deposited that $60 million into a decentralized exchange liquidity pool on Cronos — a move Li suggested may have been intended to avoid having the funds blacklisted or frozen. Li’s tracking identified three distinct wallet addresses tied to the exploit: one holding roughly $60 million on Cronos, another holding the $6 million bridged to Ethereum, and a separate borrow position wallet. Li later flagged a fourth address, a second attacker-controlled wallet holding an additional $8 million on Cronos, bringing the total estimated loss to approximately $75 million. Tectonic’s Response Tectonic confirmed the incident on X, stating: “We are aware of an incident affecting Tectonic and our team is actively investigating. As a precaution, please do not interact with the protocol until we confirm it is safe to do so. We will post a verified update here as soon as we have one.” As of publication, Tectonic has not officially confirmed the exact dollar amount lost or formally identified the root cause, though Li’s independent onchain analysis aligns closely with the mechanics described. Crypto.com’s Role Crypto.com CEO Kris Marszalek addressed the incident directly, stating on X that the exchange’s own app and trading platform were not compromised by the exploit, and that Crypto.com’s security team was actively assisting Cronos with the ongoing investigation. It’s worth clarifying the relationship between the entities involved: Cronos was originally developed by Crypto.com as its underlying blockchain network, while Tectonic operates as an independent, third-party DeFi lending protocol built on top of Cronos — notably, it was the first such lending platform to launch on the network. The distinction matters for users trying to understand exposure: a Cronos-based DeFi protocol being exploited does not necessarily indicate any vulnerability in Crypto.com’s centralized exchange infrastructure. Tectonic’s Scale Before the Attack Prior to the exploit, Tectonic carried substantial size within the Cronos ecosystem. According to DeFiLlama data, the protocol held approximately $121.7 million in total value locked, with roughly $82.7 million in active outstanding loans — meaning the reported $75 million loss represents a significant majority of the protocol’s pre-incident holdings. A Pattern of Repeated Price-Manipulation Attacks Li specifically noted that this marks the third “Mango Market-style” attack to hit DeFi protocols recently, following incidents at Moonwell and the reUSD market on Pendle’s yield-tokenization platform. This repetition highlights a persistent structural weakness across DeFi lending: protocols that allow low-liquidity, native governance tokens to be used as loan collateral remain acutely vulnerable to price manipulation, regardless of how many times the same fundamental attack pattern has already played out across the industry. Part of a Brutal Year for DeFi Security The Tectonic exploit adds to what has already become one of the most damaging years on record for decentralized finance security. Security researchers tracking on-chain incidents estimate first-half 2026 DeFi losses between roughly $970 million and $1 billion across more than 200 recorded attacks, according to data compiled by firms including TRM Labs and Immunefi. The year’s two largest incidents prior to Tectonic were the KelpDAO exploit in April, which cost approximately $292 million after compromised infrastructure fed false data to a cross-chain bridge, and the Drift Protocol attack, also in April, which resulted in roughly $285 million in losses tied to compromised administrative keys. Both of those attacks were attributed by blockchain analytics firms to North Korea-linked threat actors. More recently, the Ostium perpetuals platform on Arbitrum lost approximately $18 million to an oracle manipulation exploit in July, while DeFi yield protocol Summer.fi lost roughly $6 million to a flash loan attack the same month. What Happens Next Cronos remains halted as of publication while the investigation continues in coordination with outside security teams. Users of Tectonic and other Cronos-based protocols have been advised to avoid interacting with affected contracts until officials confirm the network and protocol are secure. Whether any portion of the roughly $68 million still sitting in attacker-controlled wallets on Cronos can be recovered or frozen will likely depend on how quickly the network can resume operations and whether Cronos validators or affiliated exchanges can act on the identified addresses before further funds move.

Cronos Blockchain Halted After Attacker Drains $75 Million From Tectonic Lending Protocol

Cronos, the blockchain network originally developed by Crypto.com, took the unusual step of halting its entire chain after an attacker exploited Tectonic, the network’s largest lending protocol, in an attack preliminarily estimated at $75 million.
The incident marks the third price-manipulation exploit of this specific style to hit DeFi lending protocols in recent months, following similar attacks on Moonwell and the reUSD/Pendle YT market.
How the Attack Worked
According to onchain researcher Weilin Li, who has been tracking the exploit in real time, the attacker manipulated the price of TONIC, Tectonic’s own governance token, before borrowing heavily against the artificially inflated collateral value. Li explained the underlying vulnerability plainly:
“The root cause is simple: TONIC, it’s own governance token has a 20% collateral factor, with very thin liquidity. The attacker performed a Mango-market style pump-and-borrow price manipulation attack. TONIC’s price surged by 100x within 20 minutes.”
The attack technique echoes the infamous 2022 Mango Markets exploit, in which an attacker used a similar strategy — artificially pumping the price of a low-liquidity token, then using the inflated valuation as collateral to borrow far more in other assets than the position was legitimately worth. In Tectonic’s case, allowing TONIC itself to be used as collateral at a 20% factor, combined with thin trading liquidity that made the token’s price easy to manipulate, created the exact conditions such an attack requires.
The Race to Contain the Damage
Cronos Network moved quickly once the exploit was detected, posting on X:
“We identified an exploit in Tectonic. The Cronos Network has been halted and we’ll provide updates here.”
The team later added it remained halted while investigating “with support from security teams across the industry.”
That rapid response appears to have limited the attacker’s ability to move stolen funds off-chain. According to Li, the attacker managed to bridge only approximately $6 million to Ethereum before Cronos halted the network, leaving roughly $60 million still stranded on the Cronos chain itself. Notably, rather than attempting further transfers, the attacker deposited that $60 million into a decentralized exchange liquidity pool on Cronos — a move Li suggested may have been intended to avoid having the funds blacklisted or frozen.
Li’s tracking identified three distinct wallet addresses tied to the exploit: one holding roughly $60 million on Cronos, another holding the $6 million bridged to Ethereum, and a separate borrow position wallet. Li later flagged a fourth address, a second attacker-controlled wallet holding an additional $8 million on Cronos, bringing the total estimated loss to approximately $75 million.
Tectonic’s Response
Tectonic confirmed the incident on X, stating:
“We are aware of an incident affecting Tectonic and our team is actively investigating. As a precaution, please do not interact with the protocol until we confirm it is safe to do so. We will post a verified update here as soon as we have one.”
As of publication, Tectonic has not officially confirmed the exact dollar amount lost or formally identified the root cause, though Li’s independent onchain analysis aligns closely with the mechanics described.
Crypto.com’s Role
Crypto.com CEO Kris Marszalek addressed the incident directly, stating on X that the exchange’s own app and trading platform were not compromised by the exploit, and that Crypto.com’s security team was actively assisting Cronos with the ongoing investigation.
It’s worth clarifying the relationship between the entities involved: Cronos was originally developed by Crypto.com as its underlying blockchain network, while Tectonic operates as an independent, third-party DeFi lending protocol built on top of Cronos — notably, it was the first such lending platform to launch on the network.
The distinction matters for users trying to understand exposure: a Cronos-based DeFi protocol being exploited does not necessarily indicate any vulnerability in Crypto.com’s centralized exchange infrastructure.
Tectonic’s Scale Before the Attack
Prior to the exploit, Tectonic carried substantial size within the Cronos ecosystem. According to DeFiLlama data, the protocol held approximately $121.7 million in total value locked, with roughly $82.7 million in active outstanding loans — meaning the reported $75 million loss represents a significant majority of the protocol’s pre-incident holdings.
A Pattern of Repeated Price-Manipulation Attacks
Li specifically noted that this marks the third “Mango Market-style” attack to hit DeFi protocols recently, following incidents at Moonwell and the reUSD market on Pendle’s yield-tokenization platform. This repetition highlights a persistent structural weakness across DeFi lending: protocols that allow low-liquidity, native governance tokens to be used as loan collateral remain acutely vulnerable to price manipulation, regardless of how many times the same fundamental attack pattern has already played out across the industry.
Part of a Brutal Year for DeFi Security
The Tectonic exploit adds to what has already become one of the most damaging years on record for decentralized finance security. Security researchers tracking on-chain incidents estimate first-half 2026 DeFi losses between roughly $970 million and $1 billion across more than 200 recorded attacks, according to data compiled by firms including TRM Labs and Immunefi.
The year’s two largest incidents prior to Tectonic were the KelpDAO exploit in April, which cost approximately $292 million after compromised infrastructure fed false data to a cross-chain bridge, and the Drift Protocol attack, also in April, which resulted in roughly $285 million in losses tied to compromised administrative keys. Both of those attacks were attributed by blockchain analytics firms to North Korea-linked threat actors. More recently, the Ostium perpetuals platform on Arbitrum lost approximately $18 million to an oracle manipulation exploit in July, while DeFi yield protocol Summer.fi lost roughly $6 million to a flash loan attack the same month.
What Happens Next
Cronos remains halted as of publication while the investigation continues in coordination with outside security teams. Users of Tectonic and other Cronos-based protocols have been advised to avoid interacting with affected contracts until officials confirm the network and protocol are secure.
Whether any portion of the roughly $68 million still sitting in attacker-controlled wallets on Cronos can be recovered or frozen will likely depend on how quickly the network can resume operations and whether Cronos validators or affiliated exchanges can act on the identified addresses before further funds move.
Article
Cronos Blockchain Halted After Attacker Drains $75 Million From Tectonic Lending ProtocolCronos, the blockchain network originally developed by Crypto.com, took the unusual step of halting its entire chain after an attacker exploited Tectonic, the network’s largest lending protocol, in an attack preliminarily estimated at $75 million. The incident marks the third price-manipulation exploit of this specific style to hit DeFi lending protocols in recent months, following similar attacks on Moonwell and the reUSD/Pendle YT market. How the Attack Worked According to onchain researcher Weilin Li, who has been tracking the exploit in real time, the attacker manipulated the price of TONIC, Tectonic’s own governance token, before borrowing heavily against the artificially inflated collateral value. Li explained the underlying vulnerability plainly: “The root cause is simple: TONIC, it’s own governance token has a 20% collateral factor, with very thin liquidity. The attacker performed a Mango-market style pump-and-borrow price manipulation attack. TONIC’s price surged by 100x within 20 minutes.” The attack technique echoes the infamous 2022 Mango Markets exploit, in which an attacker used a similar strategy — artificially pumping the price of a low-liquidity token, then using the inflated valuation as collateral to borrow far more in other assets than the position was legitimately worth. In Tectonic’s case, allowing TONIC itself to be used as collateral at a 20% factor, combined with thin trading liquidity that made the token’s price easy to manipulate, created the exact conditions such an attack requires. The Race to Contain the Damage Cronos Network moved quickly once the exploit was detected, posting on X: “We identified an exploit in Tectonic. The Cronos Network has been halted and we’ll provide updates here.” The team later added it remained halted while investigating “with support from security teams across the industry.” That rapid response appears to have limited the attacker’s ability to move stolen funds off-chain. According to Li, the attacker managed to bridge only approximately $6 million to Ethereum before Cronos halted the network, leaving roughly $60 million still stranded on the Cronos chain itself. Notably, rather than attempting further transfers, the attacker deposited that $60 million into a decentralized exchange liquidity pool on Cronos — a move Li suggested may have been intended to avoid having the funds blacklisted or frozen. Li’s tracking identified three distinct wallet addresses tied to the exploit: one holding roughly $60 million on Cronos, another holding the $6 million bridged to Ethereum, and a separate borrow position wallet. Li later flagged a fourth address, a second attacker-controlled wallet holding an additional $8 million on Cronos, bringing the total estimated loss to approximately $75 million. Tectonic’s Response Tectonic confirmed the incident on X, stating: “We are aware of an incident affecting Tectonic and our team is actively investigating. As a precaution, please do not interact with the protocol until we confirm it is safe to do so. We will post a verified update here as soon as we have one.” As of publication, Tectonic has not officially confirmed the exact dollar amount lost or formally identified the root cause, though Li’s independent onchain analysis aligns closely with the mechanics described. Crypto.com’s Role Crypto.com CEO Kris Marszalek addressed the incident directly, stating on X that the exchange’s own app and trading platform were not compromised by the exploit, and that Crypto.com’s security team was actively assisting Cronos with the ongoing investigation. It’s worth clarifying the relationship between the entities involved: Cronos was originally developed by Crypto.com as its underlying blockchain network, while Tectonic operates as an independent, third-party DeFi lending protocol built on top of Cronos — notably, it was the first such lending platform to launch on the network. The distinction matters for users trying to understand exposure: a Cronos-based DeFi protocol being exploited does not necessarily indicate any vulnerability in Crypto.com’s centralized exchange infrastructure. Tectonic’s Scale Before the Attack Prior to the exploit, Tectonic carried substantial size within the Cronos ecosystem. According to DeFiLlama data, the protocol held approximately $121.7 million in total value locked, with roughly $82.7 million in active outstanding loans — meaning the reported $75 million loss represents a significant majority of the protocol’s pre-incident holdings. A Pattern of Repeated Price-Manipulation Attacks Li specifically noted that this marks the third “Mango Market-style” attack to hit DeFi protocols recently, following incidents at Moonwell and the reUSD market on Pendle’s yield-tokenization platform. This repetition highlights a persistent structural weakness across DeFi lending: protocols that allow low-liquidity, native governance tokens to be used as loan collateral remain acutely vulnerable to price manipulation, regardless of how many times the same fundamental attack pattern has already played out across the industry. Part of a Brutal Year for DeFi Security The Tectonic exploit adds to what has already become one of the most damaging years on record for decentralized finance security. Security researchers tracking on-chain incidents estimate first-half 2026 DeFi losses between roughly $970 million and $1 billion across more than 200 recorded attacks, according to data compiled by firms including TRM Labs and Immunefi. The year’s two largest incidents prior to Tectonic were the KelpDAO exploit in April, which cost approximately $292 million after compromised infrastructure fed false data to a cross-chain bridge, and the Drift Protocol attack, also in April, which resulted in roughly $285 million in losses tied to compromised administrative keys. Both of those attacks were attributed by blockchain analytics firms to North Korea-linked threat actors. More recently, the Ostium perpetuals platform on Arbitrum lost approximately $18 million to an oracle manipulation exploit in July, while DeFi yield protocol Summer.fi lost roughly $6 million to a flash loan attack the same month. What Happens Next Cronos remains halted as of publication while the investigation continues in coordination with outside security teams. Users of Tectonic and other Cronos-based protocols have been advised to avoid interacting with affected contracts until officials confirm the network and protocol are secure. Whether any portion of the roughly $68 million still sitting in attacker-controlled wallets on Cronos can be recovered or frozen will likely depend on how quickly the network can resume operations and whether Cronos validators or affiliated exchanges can act on the identified addresses before further funds move.

Cronos Blockchain Halted After Attacker Drains $75 Million From Tectonic Lending Protocol

Cronos, the blockchain network originally developed by Crypto.com, took the unusual step of halting its entire chain after an attacker exploited Tectonic, the network’s largest lending protocol, in an attack preliminarily estimated at $75 million.
The incident marks the third price-manipulation exploit of this specific style to hit DeFi lending protocols in recent months, following similar attacks on Moonwell and the reUSD/Pendle YT market.
How the Attack Worked
According to onchain researcher Weilin Li, who has been tracking the exploit in real time, the attacker manipulated the price of TONIC, Tectonic’s own governance token, before borrowing heavily against the artificially inflated collateral value. Li explained the underlying vulnerability plainly:
“The root cause is simple: TONIC, it’s own governance token has a 20% collateral factor, with very thin liquidity. The attacker performed a Mango-market style pump-and-borrow price manipulation attack. TONIC’s price surged by 100x within 20 minutes.”
The attack technique echoes the infamous 2022 Mango Markets exploit, in which an attacker used a similar strategy — artificially pumping the price of a low-liquidity token, then using the inflated valuation as collateral to borrow far more in other assets than the position was legitimately worth. In Tectonic’s case, allowing TONIC itself to be used as collateral at a 20% factor, combined with thin trading liquidity that made the token’s price easy to manipulate, created the exact conditions such an attack requires.
The Race to Contain the Damage
Cronos Network moved quickly once the exploit was detected, posting on X:
“We identified an exploit in Tectonic. The Cronos Network has been halted and we’ll provide updates here.”
The team later added it remained halted while investigating “with support from security teams across the industry.”
That rapid response appears to have limited the attacker’s ability to move stolen funds off-chain. According to Li, the attacker managed to bridge only approximately $6 million to Ethereum before Cronos halted the network, leaving roughly $60 million still stranded on the Cronos chain itself. Notably, rather than attempting further transfers, the attacker deposited that $60 million into a decentralized exchange liquidity pool on Cronos — a move Li suggested may have been intended to avoid having the funds blacklisted or frozen.
Li’s tracking identified three distinct wallet addresses tied to the exploit: one holding roughly $60 million on Cronos, another holding the $6 million bridged to Ethereum, and a separate borrow position wallet. Li later flagged a fourth address, a second attacker-controlled wallet holding an additional $8 million on Cronos, bringing the total estimated loss to approximately $75 million.
Tectonic’s Response
Tectonic confirmed the incident on X, stating:
“We are aware of an incident affecting Tectonic and our team is actively investigating. As a precaution, please do not interact with the protocol until we confirm it is safe to do so. We will post a verified update here as soon as we have one.”
As of publication, Tectonic has not officially confirmed the exact dollar amount lost or formally identified the root cause, though Li’s independent onchain analysis aligns closely with the mechanics described.
Crypto.com’s Role
Crypto.com CEO Kris Marszalek addressed the incident directly, stating on X that the exchange’s own app and trading platform were not compromised by the exploit, and that Crypto.com’s security team was actively assisting Cronos with the ongoing investigation.
It’s worth clarifying the relationship between the entities involved: Cronos was originally developed by Crypto.com as its underlying blockchain network, while Tectonic operates as an independent, third-party DeFi lending protocol built on top of Cronos — notably, it was the first such lending platform to launch on the network.
The distinction matters for users trying to understand exposure: a Cronos-based DeFi protocol being exploited does not necessarily indicate any vulnerability in Crypto.com’s centralized exchange infrastructure.
Tectonic’s Scale Before the Attack
Prior to the exploit, Tectonic carried substantial size within the Cronos ecosystem. According to DeFiLlama data, the protocol held approximately $121.7 million in total value locked, with roughly $82.7 million in active outstanding loans — meaning the reported $75 million loss represents a significant majority of the protocol’s pre-incident holdings.
A Pattern of Repeated Price-Manipulation Attacks
Li specifically noted that this marks the third “Mango Market-style” attack to hit DeFi protocols recently, following incidents at Moonwell and the reUSD market on Pendle’s yield-tokenization platform. This repetition highlights a persistent structural weakness across DeFi lending: protocols that allow low-liquidity, native governance tokens to be used as loan collateral remain acutely vulnerable to price manipulation, regardless of how many times the same fundamental attack pattern has already played out across the industry.
Part of a Brutal Year for DeFi Security
The Tectonic exploit adds to what has already become one of the most damaging years on record for decentralized finance security. Security researchers tracking on-chain incidents estimate first-half 2026 DeFi losses between roughly $970 million and $1 billion across more than 200 recorded attacks, according to data compiled by firms including TRM Labs and Immunefi.
The year’s two largest incidents prior to Tectonic were the KelpDAO exploit in April, which cost approximately $292 million after compromised infrastructure fed false data to a cross-chain bridge, and the Drift Protocol attack, also in April, which resulted in roughly $285 million in losses tied to compromised administrative keys. Both of those attacks were attributed by blockchain analytics firms to North Korea-linked threat actors. More recently, the Ostium perpetuals platform on Arbitrum lost approximately $18 million to an oracle manipulation exploit in July, while DeFi yield protocol Summer.fi lost roughly $6 million to a flash loan attack the same month.
What Happens Next
Cronos remains halted as of publication while the investigation continues in coordination with outside security teams. Users of Tectonic and other Cronos-based protocols have been advised to avoid interacting with affected contracts until officials confirm the network and protocol are secure.
Whether any portion of the roughly $68 million still sitting in attacker-controlled wallets on Cronos can be recovered or frozen will likely depend on how quickly the network can resume operations and whether Cronos validators or affiliated exchanges can act on the identified addresses before further funds move.
Abu Dhabi Investor Holds Nearly Half of Trump Family’s New Crypto Bank, WSJ ReportsA newly disclosed ownership structure reveals that the Trump family’s planned cryptocurrency bank is substantially backed by a United Arab Emirates royal, with an entity linked to Sheikh Tahnoun bin Zayed Al Nahyan holding a 49% stake in the venture’s holding company — nearly matching the 38% ownership held by the Trump family’s own crypto business, according to a Wall Street Journal report citing people familiar with the matter. The Ownership Structure Behind the Bank The stake belongs to WLTC Holdings, the entity World Liberty Financial (WLFI) established specifically to house its banking operations. According to the Journal’s reporting, an entity connected to Sheikh Tahnoun — sometimes referred to in diplomatic and intelligence circles as the “spy sheikh” — controls just under half of that holding company, while a company affiliated with President Donald Trump’s family holds an additional 38%. Tahnoun’s stake is structured through StringZ Holding RSC, an entity registered in Abu Dhabi in April 2025 and subsequently re-registered in the U.S. state of Delaware roughly a month later. According to the Journal, StringZ is backed by Tahnoun and a group of co-investors. Tahnoun serves as the UAE’s national security adviser and is the brother of the country’s president, Mohamed bin Zayed Al Nahyan — placing him among the most powerful figures in Emirati government and finance. This is not Tahnoun’s first major investment in World Liberty’s ecosystem. Reporting earlier this year revealed that a separate entity connected to him, Aryam Investment 1, invested $500 million directly into World Liberty Financial itself, securing a 49% stake in the parent company. The banking subsidiary structure now mirrors that same ownership percentage, this time channeled through StringZ Holding rather than Aryam. Regulatory Approval and Unusual Conditions The banking venture cleared a significant regulatory hurdle on August 14, 2026, when the Office of the Comptroller of the Currency (OCC) granted preliminary conditional approval for World Liberty Trust Co. to obtain a national trust bank charter. The approval allows the entity to operate as a specialized “crypto bank” — rather than a traditional deposit-taking or loan-issuing institution, the trust charter permits World Liberty to directly issue, safeguard, and manage its own dollar-backed stablecoin, USD1, without relying on third-party intermediaries. Before beginning operations, the company must still satisfy a series of additional requirements and pass a final regulatory review. Notably, as part of the approval process, the OCC required three major shareholders — including StringZ Holding and the Trump family-affiliated entity — to sign passive-ownership agreements. Under these agreements, the shareholders committed not to seek control over the bank or interfere with its management. According to the Journal, conditions of this kind are rarely imposed in the context of U.S. banking license approvals, underscoring the level of regulatory scrutiny applied to this particular ownership structure. What the Bank Will Actually Do World Liberty began building its dedicated banking arm in July 2025, shortly after passage of the GENIUS Act, federal legislation that permits qualified stablecoin issuers to directly hold the reserve assets backing their tokens. Currently, USD1’s issuance is handled by BitGo, which simultaneously serves as custodian for the stablecoin’s reserves and collects a share of the revenue generated from investing those reserves. Once World Liberty finalizes its full banking license, the company plans to bring those functions in-house, additionally offering fee-based custody services for clients’ cryptocurrency holdings. As of this writing, USD1’s market capitalization stands at $4.08 billion. Political Scrutiny in Washington The involvement of UAE-linked investors in the Trump family’s banking venture has already drawn scrutiny from congressional Democrats. Back in February, Senator Elizabeth Warren formally requested that then-OCC head Jonathan Gould disclose information regarding Tahnoun’s potential involvement in the banking project. Subsequently, a coalition of 40 lawmakers raised concerns about the risks posed by foreign ownership, national security implications, and questions surrounding the independence of the bank charter approval process. In response to Journal inquiries, the OCC stated that WLFI’s application was reviewed by career agency staff with input from government ethics experts. A World Liberty spokesperson confirmed that account of the review process but declined to disclose additional details regarding the venture’s shareholder structure. The White House has previously and repeatedly rejected claims that the arrangement constitutes a conflict of interest for the president. Why This Matters The ownership disclosure adds a significant new dimension to an already closely watched intersection of presidential family business interests, foreign sovereign wealth, and U.S. banking regulation. Tahnoun’s consistent pattern of investment across both World Liberty Financial’s parent company and its new banking subsidiary — totaling roughly $500 million in the parent entity alone, alongside a near-majority stake in the bank itself — establishes the UAE as arguably the single most consequential foreign stakeholder in a financial institution directly tied to a sitting U.S. president’s family. The passive-ownership agreements imposed by the OCC suggest regulators were aware of the sensitivity surrounding this specific ownership arrangement, even as the agency ultimately granted preliminary approval. Whether those agreements prove sufficient to address the national security and conflict-of-interest concerns raised by lawmakers will likely remain a central question as World Liberty Trust Co. works through its remaining requirements toward final licensure. What Comes Next World Liberty must still satisfy the OCC’s outstanding conditions and pass a final regulatory review before the trust bank can begin formal operations. Given the scale of political attention the venture has already attracted — spanning direct Senate inquiries and a 40-lawmaker coalition letter — the coming months are likely to bring continued congressional and media scrutiny as the bank moves toward launch, particularly regarding how the passive-ownership commitments from its largest shareholders will be monitored and enforced once the institution becomes operational.

Abu Dhabi Investor Holds Nearly Half of Trump Family’s New Crypto Bank, WSJ Reports

A newly disclosed ownership structure reveals that the Trump family’s planned cryptocurrency bank is substantially backed by a United Arab Emirates royal, with an entity linked to Sheikh Tahnoun bin Zayed Al Nahyan holding a 49% stake in the venture’s holding company — nearly matching the 38% ownership held by the Trump family’s own crypto business, according to a Wall Street Journal report citing people familiar with the matter.
The Ownership Structure Behind the Bank
The stake belongs to WLTC Holdings, the entity World Liberty Financial (WLFI) established specifically to house its banking operations. According to the Journal’s reporting, an entity connected to Sheikh Tahnoun — sometimes referred to in diplomatic and intelligence circles as the “spy sheikh” — controls just under half of that holding company, while a company affiliated with President Donald Trump’s family holds an additional 38%.
Tahnoun’s stake is structured through StringZ Holding RSC, an entity registered in Abu Dhabi in April 2025 and subsequently re-registered in the U.S. state of Delaware roughly a month later. According to the Journal, StringZ is backed by Tahnoun and a group of co-investors. Tahnoun serves as the UAE’s national security adviser and is the brother of the country’s president, Mohamed bin Zayed Al Nahyan — placing him among the most powerful figures in Emirati government and finance.
This is not Tahnoun’s first major investment in World Liberty’s ecosystem. Reporting earlier this year revealed that a separate entity connected to him, Aryam Investment 1, invested $500 million directly into World Liberty Financial itself, securing a 49% stake in the parent company. The banking subsidiary structure now mirrors that same ownership percentage, this time channeled through StringZ Holding rather than Aryam.
Regulatory Approval and Unusual Conditions
The banking venture cleared a significant regulatory hurdle on August 14, 2026, when the Office of the Comptroller of the Currency (OCC) granted preliminary conditional approval for World Liberty Trust Co. to obtain a national trust bank charter. The approval allows the entity to operate as a specialized “crypto bank” — rather than a traditional deposit-taking or loan-issuing institution, the trust charter permits World Liberty to directly issue, safeguard, and manage its own dollar-backed stablecoin, USD1, without relying on third-party intermediaries.
Before beginning operations, the company must still satisfy a series of additional requirements and pass a final regulatory review.
Notably, as part of the approval process, the OCC required three major shareholders — including StringZ Holding and the Trump family-affiliated entity — to sign passive-ownership agreements. Under these agreements, the shareholders committed not to seek control over the bank or interfere with its management. According to the Journal, conditions of this kind are rarely imposed in the context of U.S. banking license approvals, underscoring the level of regulatory scrutiny applied to this particular ownership structure.
What the Bank Will Actually Do
World Liberty began building its dedicated banking arm in July 2025, shortly after passage of the GENIUS Act, federal legislation that permits qualified stablecoin issuers to directly hold the reserve assets backing their tokens.
Currently, USD1’s issuance is handled by BitGo, which simultaneously serves as custodian for the stablecoin’s reserves and collects a share of the revenue generated from investing those reserves. Once World Liberty finalizes its full banking license, the company plans to bring those functions in-house, additionally offering fee-based custody services for clients’ cryptocurrency holdings. As of this writing, USD1’s market capitalization stands at $4.08 billion.
Political Scrutiny in Washington
The involvement of UAE-linked investors in the Trump family’s banking venture has already drawn scrutiny from congressional Democrats. Back in February, Senator Elizabeth Warren formally requested that then-OCC head Jonathan Gould disclose information regarding Tahnoun’s potential involvement in the banking project. Subsequently, a coalition of 40 lawmakers raised concerns about the risks posed by foreign ownership, national security implications, and questions surrounding the independence of the bank charter approval process.
In response to Journal inquiries, the OCC stated that WLFI’s application was reviewed by career agency staff with input from government ethics experts. A World Liberty spokesperson confirmed that account of the review process but declined to disclose additional details regarding the venture’s shareholder structure. The White House has previously and repeatedly rejected claims that the arrangement constitutes a conflict of interest for the president.
Why This Matters
The ownership disclosure adds a significant new dimension to an already closely watched intersection of presidential family business interests, foreign sovereign wealth, and U.S. banking regulation. Tahnoun’s consistent pattern of investment across both World Liberty Financial’s parent company and its new banking subsidiary — totaling roughly $500 million in the parent entity alone, alongside a near-majority stake in the bank itself — establishes the UAE as arguably the single most consequential foreign stakeholder in a financial institution directly tied to a sitting U.S. president’s family.
The passive-ownership agreements imposed by the OCC suggest regulators were aware of the sensitivity surrounding this specific ownership arrangement, even as the agency ultimately granted preliminary approval. Whether those agreements prove sufficient to address the national security and conflict-of-interest concerns raised by lawmakers will likely remain a central question as World Liberty Trust Co. works through its remaining requirements toward final licensure.
What Comes Next
World Liberty must still satisfy the OCC’s outstanding conditions and pass a final regulatory review before the trust bank can begin formal operations. Given the scale of political attention the venture has already attracted — spanning direct Senate inquiries and a 40-lawmaker coalition letter — the coming months are likely to bring continued congressional and media scrutiny as the bank moves toward launch, particularly regarding how the passive-ownership commitments from its largest shareholders will be monitored and enforced once the institution becomes operational.
Moonwell Hit by $8.7M DeFi Exploit on Base as Protocol Restricts BorrowingDecentralized finance lending protocol Moonwell has suffered an exploit on Base with estimated losses of approximately $8.7 million, according to blockchain security researchers monitoring the incident. PeckShieldAlert flagged the suspicious activity on August 27, reporting that roughly $8.7 million had been drained and identifying an address holding the affected funds. Other blockchain security researchers subsequently reported activity involving Moonwell’s MAMO market on Base. Moonwell acknowledged an issue affecting its MAMO Core Market on Base and said it was actively investigating the incident. The protocol did not immediately confirm the final amount lost or publish a full technical post-mortem. As an emergency measure, Moonwell sharply reduced borrowing limits across its Base Core Markets and restricted supply for MAMO and WELL while the investigation continues. Moonwell Restricts Base Markets Following $8.7M Exploit In its initial response, Moonwell said it had introduced precautionary restrictions designed to prevent additional borrowing while developers investigate the incident. The protocol stated: “As a precaution, borrow caps for all Core Markets on Base have been set to 1 wei, preventing new borrowing and limiting the potential for further impact. The supply caps for MAMO and WELL have also been set to 1 wei. All other supply caps remain unchanged.” Setting a borrow cap to 1 wei — the smallest denomination of an Ethereum-compatible asset — effectively prevents meaningful new borrowing from the affected markets without necessarily shutting down every function of the protocol. Moonwell said it would provide another update later in the day. Security firm Blockaid separately reported detecting suspicious activity involving Moonwell on Base. Its initial analysis said an attacker manipulated the valuation of MAMO collateral and used it to borrow cbBTC, with more than $4 million in cbBTC observed as affected during the early stages of the investigation. Subsequent reports put total losses at approximately $8.7 million and indicated that additional liquid assets were involved. Because Moonwell has not yet released its final incident report, the exact exploit mechanism and definitive loss figure should still be treated as preliminary. What Is Moonwell and How Does Its DeFi Lending Protocol Work? Moonwell is a decentralized lending and borrowing protocol that allows users to supply digital assets to earn yield or deposit cryptocurrency as collateral to borrow other assets. According to Moonwell’s documentation, borrowers generally take overcollateralized loans, with borrowing capacity determined by the value of their supplied collateral and risk parameters established through Moonwell governance. The protocol operates across networks including Base, OP Mainnet, Moonbeam and Moonriver, while Moonwell has also expanded lending and borrowing services to Ethereum mainnet. Moonwell is non-custodial, meaning users interact with smart contracts rather than handing their funds to a centralized financial institution. Onchain lending protocols use parameters such as collateral factors, supply caps and borrow caps to control how much exposure individual markets can create. Before the latest incident, Moonwell documentation listed MAMO as a supported Base asset with a 50% collateral factor. Such risk parameters are particularly important for assets with limited liquidity because sharp or manipulated price movements can potentially distort the value of collateral used by lending markets. The Moonwell ecosystem also uses WELL as a governance token. Delegated WELL holders can participate in governance proposals and vote on changes affecting the protocol. DeFi Hacks Remain a Major Crypto Security Risk in 2026 The Moonwell exploit comes during another difficult year for crypto and DeFi security. Different security companies use different methodologies for counting exploits, phishing incidents, wallet compromises and other forms of crypto theft, meaning industry-wide loss estimates vary. CertiK calculated that the broader Web3 ecosystem lost more than $1.31 billion across 344 security incidents in the first half of 2026. Wallet compromises alone accounted for more than $444 million of those losses. Immunefi produced a lower figure using its own methodology, estimating approximately $972 million in losses across 207 hacks during H1 2026. It estimated that DeFi exploits accounted for roughly $680.3 million. The number of incidents was nevertheless the highest the company had recorded for a first-half period. The differences underline why crypto hack statistics should be attributed to individual security trackers rather than presented as one universally accepted total. April was particularly damaging. Binance Research, citing DeFiLlama data, reported approximately $635 million in losses from 28 hack events during the month. Kelp DAO and Drift Rank Among 2026’s Biggest DeFi Exploits Two incidents accounted for a large portion of 2026’s DeFi losses. In April, Kelp DAO suffered an exploit worth approximately $292 million involving its cross-chain infrastructure. An attacker drained about 116,500 rsETH, prompting emergency responses across several DeFi platforms exposed to the asset. The incident became one of the largest DeFi exploits recorded in 2026. Earlier that month, Solana-based Drift Protocol lost approximately $285 million. Chainalysis said attackers obtained administrative control following an extended social-engineering operation involving pre-signed transactions using Solana’s durable nonce functionality. The attackers were then able to use artificially valued collateral to extract real assets from the protocol. The incidents demonstrate that DeFi risks extend beyond conventional smart-contract bugs. Oracle and collateral-price manipulation, compromised administrative permissions, cross-chain infrastructure, governance systems, private keys and social engineering can all become attack vectors. For lending protocols in particular, collateral pricing and liquidity controls are critical because the system depends on correctly determining how much a deposited asset is worth relative to what a user can borrow against it. Moonwell’s decision to reduce Base borrow caps to 1 wei therefore represents an attempt to limit additional exposure while investigators determine exactly how the MAMO market was affected. As of Moonwell’s first public statement, the investigation remained ongoing, and the protocol said additional information would be released later on August 27. A complete assessment of the exploit, including the final losses, root cause and any potential recovery plan, will depend on Moonwell’s subsequent technical findings.

Moonwell Hit by $8.7M DeFi Exploit on Base as Protocol Restricts Borrowing

Decentralized finance lending protocol Moonwell has suffered an exploit on Base with estimated losses of approximately $8.7 million, according to blockchain security researchers monitoring the incident. PeckShieldAlert flagged the suspicious activity on August 27, reporting that roughly $8.7 million had been drained and identifying an address holding the affected funds. Other blockchain security researchers subsequently reported activity involving Moonwell’s MAMO market on Base.
Moonwell acknowledged an issue affecting its MAMO Core Market on Base and said it was actively investigating the incident. The protocol did not immediately confirm the final amount lost or publish a full technical post-mortem. As an emergency measure, Moonwell sharply reduced borrowing limits across its Base Core Markets and restricted supply for MAMO and WELL while the investigation continues.
Moonwell Restricts Base Markets Following $8.7M Exploit
In its initial response, Moonwell said it had introduced precautionary restrictions designed to prevent additional borrowing while developers investigate the incident. The protocol stated:
“As a precaution, borrow caps for all Core Markets on Base have been set to 1 wei, preventing new borrowing and limiting the potential for further impact. The supply caps for MAMO and WELL have also been set to 1 wei. All other supply caps remain unchanged.”
Setting a borrow cap to 1 wei — the smallest denomination of an Ethereum-compatible asset — effectively prevents meaningful new borrowing from the affected markets without necessarily shutting down every function of the protocol.
Moonwell said it would provide another update later in the day.
Security firm Blockaid separately reported detecting suspicious activity involving Moonwell on Base. Its initial analysis said an attacker manipulated the valuation of MAMO collateral and used it to borrow cbBTC, with more than $4 million in cbBTC observed as affected during the early stages of the investigation. Subsequent reports put total losses at approximately $8.7 million and indicated that additional liquid assets were involved.
Because Moonwell has not yet released its final incident report, the exact exploit mechanism and definitive loss figure should still be treated as preliminary.
What Is Moonwell and How Does Its DeFi Lending Protocol Work?
Moonwell is a decentralized lending and borrowing protocol that allows users to supply digital assets to earn yield or deposit cryptocurrency as collateral to borrow other assets.
According to Moonwell’s documentation, borrowers generally take overcollateralized loans, with borrowing capacity determined by the value of their supplied collateral and risk parameters established through Moonwell governance. The protocol operates across networks including Base, OP Mainnet, Moonbeam and Moonriver, while Moonwell has also expanded lending and borrowing services to Ethereum mainnet.
Moonwell is non-custodial, meaning users interact with smart contracts rather than handing their funds to a centralized financial institution. Onchain lending protocols use parameters such as collateral factors, supply caps and borrow caps to control how much exposure individual markets can create.
Before the latest incident, Moonwell documentation listed MAMO as a supported Base asset with a 50% collateral factor. Such risk parameters are particularly important for assets with limited liquidity because sharp or manipulated price movements can potentially distort the value of collateral used by lending markets.
The Moonwell ecosystem also uses WELL as a governance token. Delegated WELL holders can participate in governance proposals and vote on changes affecting the protocol.
DeFi Hacks Remain a Major Crypto Security Risk in 2026
The Moonwell exploit comes during another difficult year for crypto and DeFi security.
Different security companies use different methodologies for counting exploits, phishing incidents, wallet compromises and other forms of crypto theft, meaning industry-wide loss estimates vary. CertiK calculated that the broader Web3 ecosystem lost more than $1.31 billion across 344 security incidents in the first half of 2026. Wallet compromises alone accounted for more than $444 million of those losses.
Immunefi produced a lower figure using its own methodology, estimating approximately $972 million in losses across 207 hacks during H1 2026. It estimated that DeFi exploits accounted for roughly $680.3 million. The number of incidents was nevertheless the highest the company had recorded for a first-half period.
The differences underline why crypto hack statistics should be attributed to individual security trackers rather than presented as one universally accepted total.
April was particularly damaging. Binance Research, citing DeFiLlama data, reported approximately $635 million in losses from 28 hack events during the month.
Kelp DAO and Drift Rank Among 2026’s Biggest DeFi Exploits
Two incidents accounted for a large portion of 2026’s DeFi losses.
In April, Kelp DAO suffered an exploit worth approximately $292 million involving its cross-chain infrastructure. An attacker drained about 116,500 rsETH, prompting emergency responses across several DeFi platforms exposed to the asset. The incident became one of the largest DeFi exploits recorded in 2026.
Earlier that month, Solana-based Drift Protocol lost approximately $285 million. Chainalysis said attackers obtained administrative control following an extended social-engineering operation involving pre-signed transactions using Solana’s durable nonce functionality. The attackers were then able to use artificially valued collateral to extract real assets from the protocol.
The incidents demonstrate that DeFi risks extend beyond conventional smart-contract bugs. Oracle and collateral-price manipulation, compromised administrative permissions, cross-chain infrastructure, governance systems, private keys and social engineering can all become attack vectors.
For lending protocols in particular, collateral pricing and liquidity controls are critical because the system depends on correctly determining how much a deposited asset is worth relative to what a user can borrow against it.
Moonwell’s decision to reduce Base borrow caps to 1 wei therefore represents an attempt to limit additional exposure while investigators determine exactly how the MAMO market was affected.
As of Moonwell’s first public statement, the investigation remained ongoing, and the protocol said additional information would be released later on August 27. A complete assessment of the exploit, including the final losses, root cause and any potential recovery plan, will depend on Moonwell’s subsequent technical findings.
Log in to explore more content
Join global crypto users on Binance Square
⚡️ Get latest and useful information about crypto.
💬 Trusted by the world’s largest crypto exchange.
👍 Discover real insights from verified creators.
Email / Phone number
Sitemap
Cookie Preferences
Platform T&Cs