Cloned Merchant Profile, The Merchant Who Looked Exactly Like Someone I'd Trust
Same display name, same profile photo, same green Merchant badge I remembered from a trade three weeks earlier that had gone perfectly. I almost skipped my usual check entirely, recognizing someone felt like verifying them.
What stopped me was habit, not suspicion. I always open a profile before I open an order, no exceptions, and this time the exception nearly won. The "member since" date read six days. The merchant I actually remembered had been active for months, with a completion count in the thousands. This one had forty-one.
A profile photo and a display name cost nothing to copy. A badge, a completion history built order by order over months, that's the part that can't be cloned instantly, and it's also the part I'd almost stopped looking at, because the part that's free to fake was the part my memory latched onto first.
I opened a chat instead of an order, mentioned the earlier trade by date, and asked if he remembered it. Long pause. Then a generic reply about having "a lot of customers." The real merchant, I checked separately, had no record of that conversation at all.
Recognizing someone and verifying someone turned out to be two different skills, and I'd been quietly substituting one for the other for longer than I want to admit.
Escrow would have held the crypto regardless of which merchant I'd traded with, that part isn't the risk here. The risk was handing my trust to a photo before checking whether the history behind it belonged to the same person.
I don't know how many other "familiar" profiles I've traded with the same shortcut. Probably more than I'd like to count.
I was going through Dusk's technical announcements last night, mostly skimming, until I hit the description of Hedger and had to reread it twice. Most privacy-focused chains I've looked into lean entirely on zero-knowledge proofs to hide transaction data. Hedger does something different, it pairs ZK proofs with homomorphic encryption, specifically ElGamal over elliptic curve cryptography, which lets computation happen directly on encrypted values without ever decrypting them first.
Homomorphic encryption isn't something I expected to see in a blockchain privacy stack at all. I've mostly run into it in the context of cloud computing, letting a third party process data it never actually gets to read. Seeing that same principle applied to on-chain balances and transfers reframed what "confidential transaction" even means to me, it's not just hiding a number, it's letting the network still compute with that number while it stays hidden.
Worth being clear-eyed about where this actually is right now though. Hedger Alpha only recently opened for public testing, running on Sepolia, and Dusk itself has flagged it as an early build looking for feedback, not a finished production system. The cryptographic approach is what caught my attention, but I'm treating the maturity of the implementation as a separate question I still want to watch.
🔥 What Stage of the Market Cycle Are We Actually In?
Let's try something different this time.
We asked an AI chatbot, Grok, to analyze where Bitcoin currently sits in the market cycle.
Here's what Grok came back with:
Bitcoin appears to be entering a downtrend / late-stage decline.
According to its analysis, Bitcoin is down roughly 50% from its 2025 peak near $126K, while market sentiment remains around the mid-30s on the Fear & Greed Index.
Trading volume has also weakened, while several indicators suggest that bearish momentum may be approaching exhaustion.
Based on the market-cycle framework Grok highlighted, Bitcoin could now be approaching the final challenging stage of the downtrend.
That would suggest one more major correction could still be ahead.
There could even be a new cycle low before the market transitions into the familiar stages of disbelief, skepticism, and eventually renewed growth.
But here's the interesting part:
Is Grok actually identifying the market correctly or is it simply fitting today's data into a familiar historical pattern?
Bitcoin has repeatedly shown that market cycles rarely play out exactly according to textbook models.
A move lower from here could mark the final capitulation phase. But a strong recovery could also invalidate the entire bearish-cycle thesis.
So I'm curious:
Do you agree with Grok?
If it's wrong, which stage of the market cycle do you think we're actually in right now? 😁
Every profile I'd traded with before had a number attached, completion rate, order count, something to measure. This one had zero of everything. 0/0 completion rate. Account created that morning, I checked the timestamp, under six hours old.
I almost scrolled past. Then I realized I was treating "no history" as a worse signal than it actually is, everyone's first trade looks exactly like this, including mine once.
The absence of history isn't proof of anything, good or bad. It's just missing data, and missing data isn't the same as a red flag. I checked what I actually could: the ad's stated limits made sense, the payment method matched something normal, nothing in the terms asked for anything unusual.
I opened the order at the platform's minimum size on purpose, not just "small", small enough that even a worst case cost me almost nothing to learn from. Same checklist I always run: payment confirmed in my own bank app, name matched exactly, nothing rushed. It closed clean, four minutes total, no different from a trade with someone who'd done it four hundred times.
What stayed with me afterward wasn't the trade. It was catching myself, mid-hesitation, about to let a blank profile decide something my own checklist was fully capable of deciding instead. A completion rate tells you what someone has done. It says nothing about someone who hasn't had the chance to do anything yet, good or bad.
I still check the badge first. I just don't let zero be the whole answer anymore.
46 Crypto Robberies, $30M Stolen in H1 2026, What Is a “Wrench Attack”?
For years, crypto security has focused on one question: How do you stop someone from hacking your wallet? But in 2026, there is another threat that is becoming increasingly difficult to ignore: What if the attacker doesn't hack your wallet at all but comes after you? According to Chainalysis, 46 violent attacks targeting crypto holders were recorded worldwide in the first half of 2026. More than $30 million in crypto was actually stolen, with 12 of the 46 attacks ending with victims being forced to hand over their funds. That's roughly a 26% success rate. And those numbers may only represent the cases that became public. Chainalysis has warned that if the current trend continues, 2026 could surpass the $58 million stolen in physical crypto attacks throughout 2025, potentially making it the most violent year in crypto's history. So how are criminals finding their targets? Why is crypto particularly attractive for this type of attack? And more importantly: What can ordinary crypto investors do to protect themselves? 1. You Don't Need to Hack Crypto to Steal It It sounds absurd, but criminals may have realized that breaking into a blockchain or trying to brute-force a seed phrase is often unnecessary. A much easier approach is to figure out: Who owns the Bitcoin, where do they live, and who are their family members? This type of crime has been spreading across multiple countries, with France becoming one of the most prominent examples. Before 2025, France saw only a handful of such incidents each year. In 2025, the number jumped to 19 cases. In just the first half of 2026, around 30 publicly reported cases had already emerged. 1.1 What Is a Wrench Attack? There is a dark joke in cybersecurity: The strongest encryption in the world becomes useless when someone puts a wrench to your head and forces you to unlock the wallet yourself. That's where the term “wrench attack” comes from. It refers to real-world attacks such as home invasions, kidnapping, torture and extortion designed to force victims to surrender their crypto. Chainalysis' figures through the end of June 2026 are alarming: 46 violent crypto-related attacks were recorded globally.More than $30 million was stolen in just the first six months of the year.That is already more than half of the $58 million stolen during all of 2025.12 of the 46 attacks resulted in victims actually surrendering funds, representing a success rate of approximately 26%. And $30 million may only be the visible portion of the problem. Chainalysis itself notes that publicly documented incidents may not reflect the true scale because many victims may choose not to report the attacks publicly. For someone holding a large amount of crypto, speaking publicly about the crime can create another problem: They may have to reveal that they own a significant amount of crypto in the first place. 1.2 Why Are Crypto Holders Such Attractive Targets? You might reasonably ask: There are plenty of wealthy people with mansions, gold, luxury cars and millions in cash. Why are crypto holders becoming such attractive targets? The answer is portability and speed. A $2 million house cannot be transferred in ten minutes. Money held in a bank account may be frozen if suspicious activity is detected. Stealing $10 million worth of physical cash or gold requires transportation, storage, weapons and a network capable of moving or selling the assets. Bitcoin is different. Millions of dollars can potentially be controlled through a small hardware wallet or even a few words written on a piece of paper. Crypto also has another critical characteristic: Transactions are difficult to reverse once confirmed on-chain. If someone forces you to make a bank transfer, the transaction may potentially be blocked or frozen once authorities or the bank identify the fraud. With Bitcoin and many other crypto assets, once the transfer is confirmed, the money has effectively left your control. Real-world incidents show just how brutal this can become. One of the most shocking cases involved David Balland, co-founder of hardware-wallet company Ledger. Balland and his partner were abducted at their home by criminals demanding a $10 million cryptocurrency ransom. Balland was eventually rescued, but he reportedly suffered severe torture during the incident and lost a finger. And then there is the recent case of Harry Yeh, a well-known crypto investor with an estimated fortune of around $2 billion, who was found dead in Paraguay after falling from a high-rise building. Yeh had been a prominent early backer of the Fantom ecosystem. Authorities are still investigating the circumstances surrounding his death, and there is not enough evidence to conclude that it was a crypto-related attack. But the case has nevertheless raised another uncomfortable question: How safe are wealthy crypto investors in the physical world? 1.3 How Does a Wrench Attack Actually Work? According to Chainalysis, these incidents are often not random robberies. They can involve a combination of high-level cybercrime and traditional violent crime. The cybercriminals identify the target. The physical criminals carry out the attack. The process can roughly look like this: 1️⃣ Track the victim An exposed email address, phone number or home address can lead criminals to social-media accounts and a real-world identity. 2️⃣ Estimate the target's wealth Posts showing profits, wallet balances, crypto holdings or even publicly identifiable on-chain activity can help criminals estimate whether the target is worth attacking. 3️⃣ Execute the attack Once the target is selected, criminals can start with phishing and social engineering. Or they can escalate to physical violence. And the most dangerous part of the entire process may actually be step one. Crypto users buy hardware wallets because they believe they are protecting themselves. They use major exchanges because they assume their personal data will be protected. But what happens when the company holding that customer information gets hacked? The attacker may not immediately receive a private key. They may receive something arguably more useful: the identity of a crypto holder and where that person can be found. We've already seen several major examples. Ledger — 2020 and 2026 In 2020, data belonging to nearly 1 million Ledger customers, including more than 270,000 physical addresses and phone numbers, was exposed and circulated online. And earlier this year, customer information was reportedly exposed again through Ledger's e-commerce partner Global-e. Coinbase — 2025 Criminals reportedly bribed a group of overseas customer-support employees to obtain sensitive user information. At least 69,000 customers were affected. The compromised information reportedly included names, addresses, phone numbers, email addresses, identity documents, transaction history and even snapshots of account balances. Trezor — August 2026 Just this month, a logistics provider used by Trezor was reportedly compromised. More than 13,000 customers in countries including the United States, United Kingdom, Italy and Sweden had their personal information and shipping addresses exposed. These were customers who had purchased devices between May 10 and August 8, 2026. The companies can explain the incidents in whatever way they want. But once this data is exposed, it cannot be made private again. And criminals have been handed something extremely valuable: A list of people who may own crypto and the information needed to find them. 2. So How Can Crypto Investors Protect Themselves? Wealthy crypto investors are increasingly treating physical security as seriously as cybersecurity. At the recent Bitcoin 2026 conference in Las Vegas, it became increasingly common to see speakers surrounded by professional security teams. And the cost of this protection has become significant. Coinbase reportedly spent $7.6 million in 2025 on personal security for CEO Brian Armstrong. Gemini spent around $2.5 million for each of the Winklevoss twins, while maintaining security contracts costing as much as $400,000 per month. Obviously, most retail investors don't have millions of dollars to spend on bodyguards. But there is one principle used by wealthy investors that everyone can apply: Don't wait until something happens before thinking about security. Reduce your digital footprint Don't publicly show: Your wallet balanceYour PnLHow much BTC you ownPhotos of your hardware walletYour wallet addressesWhere you store your seed phrase Most importantly, avoid linking your real-world identity to a large on-chain balance whenever possible. Once someone knows that a particular wallet belongs to you, public blockchain data can effectively become a map of your wealth. Protect your real-world information Be careful about exposing: Your home addressYour daily schedulePlaces you regularly visitTravel plansFamily information Your hardware wallet protects your private key. It does not protect your physical location. Assume leaked data is permanently leaked If your email address, phone number or personal details have appeared in a data breach, assume that information is already circulating. Change passwords where necessary. Use strong two-factor authentication. And above all, never respond to urgent requests involving: seed phrases, private keys, wallet recovery codes or emergency wallet updates. 3. Self-Custody or Bitcoin ETF? Physical attacks, data leaks and unexpected technical failures — such as the recent Coldcard incident — are forcing investors to reconsider a question that used to have a much simpler answer: Should you hold Bitcoin yourself, or let a professional institution do it for you? Buying a Bitcoin ETF is increasingly viewed as a possible alternative to self-custody. But before handing over your assets to a third party, there are several questions worth asking: 1. Is the ETF actually backed 100% by real Bitcoin? 2. Where exactly is the Bitcoin stored, and who controls the private keys? 3. If the custodian is also using cold storage, how strong is its security system? 4. What happens if there is a catastrophic loss? 5. What is the actual compensation or insurance mechanism? Take IBIT, BlackRock's spot Bitcoin ETF and one of the largest Bitcoin investment products in the world. BlackRock is the issuer and manager of the ETF. But the actual Bitcoin custody is handled by Coinbase Custody. That distinction matters. The SEC supervises the ETF as a securities product, including disclosure and trading requirements. But even IBIT's own prospectus makes an important point: The custodian can still be exposed to cyberattacks and other security risks, insurance coverage may not be sufficient to cover all losses, and IBIT itself is not guaranteed by BlackRock or the fund sponsor. So buying an ETF does not eliminate custody risk. It simply transfers control of the private keys from you to a professional institution. For many investors, that may still be the better trade-off. But it is important to understand what you are actually giving up: self-custody means accepting operational risk yourself. An ETF means accepting counterparty and custodial risk instead. The Bottom Line The crypto security conversation needs to become much broader. It is no longer enough to ask: “How do I stop someone from stealing my private key?” You also need to ask: “Can someone figure out that I own crypto in the first place?” The safest strategy is not necessarily to blindly choose self-custody or ETFs. It is to understand the risks of both and decide which risks you are actually capable of managing. For those who prefer third-party custody, focus on institutions with strong reputations, transparent custody structures and clear recovery mechanisms. For those who choose self-custody, the responsibility goes far beyond buying a hardware wallet. You need to protect the private key, the digital identity, the physical location and the people around you. Because today, protecting your crypto isn't just about securing the asset. It's about securing yourself. $BTW $PORTAL $AIO
🔥 SafePal Data Leak Exposes Nearly 40,000 Customers
SafePal has disclosed a data breach affecting approximately 39,798 customers who placed orders between March 2, 2025 and April 11, 2026.
The leaked information includes: Full names Email addresses Shipping addresses Phone numbers Purchase details
The good news is that this was not a direct compromise of users' wallets.
SafePal said the incident did not expose seed phrases, private keys, wallet passwords, or other wallet authentication credentials, and there is currently no evidence that customer funds were directly affected.
The real danger now is targeted phishing.
With attackers possessing a customer's name, phone number, address and exact SafePal purchase history, they can create highly convincing impersonation attempts, for example, pretending to be SafePal support and claiming that a firmware update, wallet replacement, or security issue requires immediate action.
In fact, reports of suspicious SafePal impersonation attempts had already surfaced before the company publicly disclosed the breach.
So while your crypto may still be safe, your identity as a hardware-wallet customer may no longer be private.
And in crypto, that distinction matters.
A leaked seed phrase can drain your wallet.
A leaked customer profile can help an attacker trick you into giving them the seed phrase.
🔥 South Korea Could Be Heading Toward Peace Talks With North Korea
South Korean President Lee Jae Myung has proposed that Seoul and Pyongyang begin talks to formally end the Korean War and replace the current armistice with a permanent peace regime.
Speaking during South Korea's 81st Liberation Day ceremony, Lee called for dialogue between the two Koreas and suggested that negotiations could also address ways to halt the advancement of North Korea's nuclear program.
The proposal is significant because the Korean War technically never ended with a peace treaty. The 1950–1953 conflict concluded with an armistice, meaning the two sides remain technically at war.
However, there is already a major obstacle.
Pyongyang has not responded positively at least not yet.
As of August 16, North Korean state media including KCNA and Rodong Sinmun had not even reported Lee's speech. Instead, their coverage focused on domestic Liberation Day commemorations and events honoring former leaders Kim Il-sung and Kim Jong-il.
This is particularly important because North Korea has previously rejected Seoul's efforts at engagement and has continued to characterize South Korea as a hostile state.
So, for now, this is an opening offer rather than an actual peace negotiation.
Lee has made it clear that Seoul wants to reduce military tensions and eventually establish a formal peace regime. But whether Pyongyang is willing to sit at the negotiating table remains the biggest question.
South Korea has opened the door.
Now the market and the world is waiting to see whether Kim Jong Un walks through it.
I almost skimmed past DuskEVM the first time I saw it mentioned, another EVM-compatible layer, another chain letting developers deploy Solidity. I've read that pitch a dozen times from a dozen projects. Then I actually looked at what it's built on and had to slow down.
DuskEVM runs on the OP Stack, the same rollup framework behind chains like Base. On its own that's not unusual anymore, plenty of networks use it. What stopped me was where it settles. Instead of anchoring back to Ethereum the way most OP Stack chains do, DuskEVM settles to DuskDS, Dusk's own consensus and data availability layer, and Hedger sits on top of that same execution environment adding confidential transaction flows through homomorphic encryption and zero-knowledge proofs.
So the familiar rollup machinery is there, but what it's plugged into isn't Ethereum's security and data model, it's a settlement layer purpose-built for regulated finance, with a privacy module riding alongside it from day one. That's a different design decision than borrowing OP Stack just for cheap scaling.
I keep going back and forth on how much that changes for a developer actually building here versus someone just skimming the tech stack from outside. The tooling looks identical to any other EVM deployment. What sits underneath it doesn't.
"58... 57... 56..." - he was narrating it live, he said: a red countdown on his screen, some "system notice" warning the order would auto-cancel and I'd lose priority if I didn't confirm right now.
For those two seconds, his countdown was the only clock in the room. Checking my own screen hadn't even occurred to me yet.
Then I did. My order page showed the normal payment window, same as always, no red numbers, no countdown at all.
Two people looking at the same order, apparently watching two different clocks.
That's the detail that actually mattered, not whether his countdown was real, but that a countdown belonging to this order would've shown up on my side too. Order timers aren't a private whisper to one party. They're shared state, visible identically to both sides, because the platform has no reason to tell two traders in the same trade two different stories.
His clock was real to him, maybe. It just wasn't real to the order.
I told him I didn't see any countdown and asked what triggered it. The urgency riding on it quietly stopped mattering to him a few messages later.
What I keep noticing is how much smaller the trick actually was than the panic it was built to cause. Sixty seconds of pretend jeopardy, aimed at a decision that, if I'd checked my own screen first, had no clock running on it at all.
🔥 Looking Back at the Top Altcoins of 2021 — Where Are They Now?
Back in 2021, crypto communities were full of the same question: "Can I buy this altcoin and hold it for 3–5 years like a stock?"
The idea was simple: find a promising project, accumulate through the cycle, and let time do the rest.
Five years later, the market has given us a pretty brutal answer.
Many of the coins that dominated the Top 10 in 2021 have either disappeared from the top rankings, lost most of their market value, or been completely replaced by newer narratives. CoinMarketCap's historical snapshots show just how dramatically the rankings have changed over time.
And that's the biggest lesson.
Being a Top 10 altcoin today doesn't mean you'll still be relevant five years from now.
Crypto is an extremely competitive market. New chains, new narratives, new technologies and new tokens constantly compete for capital. Even projects that once looked like established blue chips can eventually lose their position.
Bitcoin is the obvious exception.
The point isn't that every altcoin is doomed. Some will survive, some will continue to grow, and a few may become much larger than they are today.
But treating an altcoin like a 5–10 year stock investment simply because it has a large market cap today is a completely different bet. So here's the real question:
Out of today's Top 50 altcoins, how many do you think will still be relevant five years from now? 👀
I've mostly been reading about Dusk through the privacy angle, confidential transactions, encrypted balances, that side of things. Going a layer deeper into the architecture, I noticed there's actually a separate piece sitting underneath everything else called DuskDS, and it's not really about privacy at all, it's about settlement, finality, and data availability.
That distinction stood out to me more than I expected. Privacy features and compliance logic seem to run through DuskEVM and DuskVM above it, but DuskDS looks like the foundation both of those depend on, the part responsible for making sure a transaction is actually settled and final, not just included somewhere in a block.
I've seen enough networks where those two things get treated as basically the same event, a transaction shows up, it looks confirmed, and that gets treated as final. Reading about DuskDS made me pay more attention to that gap, inclusion and settlement aren't automatically the same thing, and for anything handling regulated financial assets that difference isn't just semantics, it's the part auditors and counterparties would actually care about.
What I haven't fully worked out yet is what settlement guarantees look like in practice at that layer, what has to happen before something counts as final, and how that gets verified across the network. I didn't find enough detail to answer that for myself.
If anyone has looked closer at how DuskDS actually defines and enforces finality, I'd be curious how it compares to settlement models on other chains built for regulated assets.
My first P2P order was for an amount small enough that I checked twice before submitting, worried I'd mistyped a decimal.
"Small order, everything okay?" the seller asked, halfway through, like tiny amounts were rare enough to comment on.
They're not rare. I'd just never seen anyone admit to choosing one on purpose.
I wasn't testing the money. I was testing myself, whether I'd actually run every check I'd read about, or quietly skip half of them once the amount felt too small to matter. Easy to promise yourself that in the abstract. Easy to skip the moment it's inconvenient.
So I did all of it anyway. Checked his completion rate like the trade was ten times the size. Matched the payment name character by character. Opened my own banking app instead of trusting his screenshot, even though a screenshot for an amount that small would've cost me almost nothing if wrong.
That's the part I didn't expect going in: fraud doesn't scale down with the order. A stolen dollar and a stolen thousand dollars use the same tricks, only the amount changes, never the method. Treating a small trade carelessly teaches exactly the wrong instinct for the day the amount isn't small anymore.
The trade cleared in about four minutes. Nothing dramatic happened, which was sort of the point, I wasn't trying to survive anything. I was trying to find out which checks I'd actually keep once no one was watching to see if I skipped them.
I still don't know if I'd have caught everything on a first trade ten times the size. I'm glad I didn't find out that way.
After a volatile week, markets are heading into the weekend with relatively little movement:
Gold: holding around $4,400
U.S. equities: slightly lower, largely reflecting profit-taking after yesterday's record highs
Bitcoin: still trading around $62K–$63K
Oil is the exception.
Brent crude climbed around 2% toward $90 after the U.S. threatened to maintain an indefinite blockade of Iranian ports. Trump also reiterated that he would not apologize to Iran and has continued to assert that the Strait of Hormuz will ultimately be under U.S. control.
Brent was around $88.50 on Friday and was heading for a weekly gain of roughly 6%, as tanker attacks and the lack of progress in U.S.-Iran negotiations continued to disrupt shipping through Hormuz.
On the economic front, U.S. July retail sales unexpectedly fell 0.6%, sharply missing expectations for an increase.
Meanwhile, Trump has moved to impose tariffs of up to 100% on imported drones, targeting a sector where Chinese manufacturers account for more than two-thirds of the global market.
So while financial markets are relatively quiet heading into the weekend, the geopolitical risk is anything but quiet.
With Hormuz traffic already severely disrupted, any further escalation could quickly feed back into oil prices → inflation expectations → Fed policy → risk assets.
For now, Bitcoin remains stuck around $62K–$63K, waiting for the next catalyst.
🔥 Washington Is About to Have a Busy Week for Crypto Regulation Next week, crypto executives, traditional finance leaders, and prediction-market operators are set to meet with U.S. policymakers in back-to-back sessions.
On August 19, the White House is expected to host a meeting with representatives from the crypto and prediction-market industries, alongside some traditional finance executives. The agenda and attendee list are still being finalized, and it remains unclear whether President Trump himself will attend.
Then, on August 20, the CFTC will hold the inaugural meeting of its Innovation Advisory Committee, bringing together industry leaders to discuss three major areas:
Crypto regulation AI applications in financial markets Regulation of prediction markets The timing is particularly interesting because the CLARITY Act remains stalled in the Senate, leaving the industry waiting for clearer rules on the regulatory boundaries between the SEC, CFTC, and digital-asset businesses.
Two major meetings in two consecutive days show that Washington is not simply waiting for Congress to solve the problem.
The U.S. is increasingly bringing crypto and financial-industry players directly into the policymaking process.
Whether this eventually produces a comprehensive regulatory framework or simply more discussion, remains to be seen. But one thing is becoming increasingly clear: Crypto regulation is moving back to the center of Washington's agenda.
🔥 $11.8M Lost in Crypto Job Scam Using Fake Recruiters
A sophisticated recruitment scam in Singapore has resulted in approximately $11.8 million in cryptocurrency losses, according to the Singapore Police Force and Cyber Security Agency.
The attack started like a normal recruitment process: 1️⃣ Attackers impersonated crypto recruiters and approached the victim through LinkedIn. 2️⃣ After several interviews via Google Meet, the victim was asked to complete a coding assessment using a company-issued laptop. 3️⃣ The test was hosted on a fake website that quietly installed malware on the device. 4️⃣ The malware stole a session token, allowing the attackers to bypass multi-factor authentication and access the company's Bitbucket code repository. 5️⃣ From there, the attackers modified deployment instructions, gained access to internal servers, bypassed transaction controls and ultimately drained the company's crypto holdings.
What makes this attack particularly dangerous is that the hacker didn't need to directly target the company's crypto wallet at the beginning.
They simply targeted an employee.
Once that employee's device and developer credentials were compromised, the attackers used the company's own infrastructure to move deeper into the system until they could reach the funds.
Singapore authorities have not attributed the attack to any specific hacking group. The incident is a serious reminder for crypto companies that cybersecurity doesn't start at the wallet.
A compromised employee laptop, source-code repository, API credential or deployment pipeline can ultimately become the path to millions of dollars in crypto.
In this case, the $11.8M hack didn't start with a wallet. It started with a job interview.
MSCI Could Kick Strategy and Metaplanet Out of Its Indexes Again
MSCI is once again considering rules that could push Strategy (MSTR), Metaplanet, and other digital-asset treasury companies out of its major indexes. The proposal targets companies whose business model increasingly resembles an investment vehicle — particularly those that repeatedly raise capital through stocks or debt and use the proceeds primarily to accumulate Bitcoin or other digital assets, rather than generating value mainly through their underlying operating business. Among the companies currently facing potential exclusion are: Strategy (MSTR)MetaplanetYellow Cake Meanwhile, SharpLink, whose treasury strategy is centered on ETH, and several similar companies have reportedly been placed under review. This isn't a final decision yet. MSCI is currently conducting a consultation with market participants, with feedback expected through September 30. A final decision is expected around October 16, with any changes potentially taking effect during the November 2026 Index Review. The potential impact is significant. If companies like Strategy are removed from major MSCI indexes, passive funds tracking those indexes could be forced to reduce or completely exit their positions, creating additional selling pressure on MSTR and potentially other Bitcoin treasury stocks. And this isn't the first time MSCI has raised the issue. The index provider previously considered excluding digital-asset treasury companies, but ultimately decided in January 2026 not to implement the exclusion at that time. This time, however, MSCI is approaching the issue through a broader "non-operating company" framework rather than targeting crypto treasury companies alone. That's why this matters. If the proposal eventually goes through, it could directly challenge the capital-raising model that companies like Strategy have used to continuously expand their Bitcoin holdings. For Bitcoin investors, this is a headline worth watching closely because the risk isn't just MSTR getting hit. It could affect the entire Bitcoin treasury company model. $BTC $SNDK $SAMSUNG