Blockchain RIO 2026 (11-13 Aug, Rio) positioned Brazil as the crypto hub. +500 speakers, +150 sponsors. Key topics: regulation, tokenization, stablecoins, RWA and TradFi x Crypto.
EverValue (Platinum Sponsor) presented EVA: a token on Arbitrum backed by BTC from its own mining in Paraguay. Burn Vault audited + deflationary model
• Fixed supply: 21M • Burned: 2.4M • Circulating: 18.6M • Backing: 418.55 BTC • +3,000 ASICs across 6 mines • 11.78 BTC mined (30 days) • +750 days of BTC flowing in
Burn 1 EVA = 52,712 sats (increases daily). “Bitcoin boosted” with growing collateral.
Trench #6 They sent Perpl points. I was testing the bots.
I pushed $145k in volume Points +7.54 mPoint +8.49 ($8 rebased)
Cost per 1 point: $19.230 of volume. The value went to more than double just by pushing with MM bots I was testing.
Overall the metrics are coming out great because I’m farming at zero cost thanks to the rebate, delta neutral, and the funding rates. (Example: today BTC pays 49% APR, which if you trade it at 5x = 245% of your base capital). Ideal for stable DN with another DEX, where most pay 10%.
So you’d be left with a net APR of (49% - 10%) / 2 = 19.5% ≈ 20%. A net APR of 20% across both legs (short and long) is very good—especially for Bitcoin, which due to its stability lets you push more leverage than the rest of the assets.
In summary, although I don’t have many points, at the moment they’re all being farmed at zero cost (of course, this is thanks to the mPOINT rebate that will be charged when the campaign ends).
They hacked the shipping provider’s database and filtered data from Trezor buyers from the last 90 days.
The attackers obtain the name, address, email, etc.
These leaks are a problem, mainly because of the email: they use it to send you phishing or scam emails. The physical address: it’s not that they’re going to come to your home personally (there are 11,000 addresses and they don’t even know if you have any assets), but they send you physical letters that look original from Trezor to scam you.
What I don’t understand is that, with everything that has happened over these years, they still don’t have an anonymous delivery system.
Things shouldn’t be delivered to your home, but rather picked up at some delivery point, using anonymous data, etc.
Personally, I’ve never bought from the official website; I’ve only done so in trusted physical stores attended by their own owner, who are official resellers. They’re not in my city, I pay in cash and without them recording any data, and if they don’t invoice it, even better.
Users are drained by scam ads sponsored by Google. In this case, Ledger → same modus operandi as with Trezor.
1) They create a fake page similar to the original. 2) They pay Google a lot of money to sponsor it. 3) The ad shows up first in searches. 4) The user enters and inputs their seed phrase. 5) They get drained. 6) After a few days, Google removes the ad for not complying with the policies.
Final result:
❌ The user loses their money because they don’t understand what they’re doing.
You’re farming ants while the elephants are escaping.
The perpetual DEXs (new and current) are already out of stock. They reached their cycle, just like L2s. None of them bring anything truly disruptive. It all ended after Hyperliquid, Aster, Lighter, and Variational.
We’re still focused on the ants… while the elephants slip away.
The real elephants of this cycle come from the new major evolution: the stock market (Wall Street). That’s where the biggest fish are, the richest and most powerful millionaires.
Ask a millionaire if they know Orderly, Hibachi, or GRVT: they’ll look at you weird. Ask them about Apple, Microsoft, or the S&P 500: they’ll say yes, and that they’re stockholders.
That same energy and capital will explode into tokenized equities projects. That’s where the real blast happens: they bring fresh money, big money.
Today there are 3 main players creating this industry: xStocks, Ondo, and a third one (next post).
Even though almost nobody says it (so as not to dilute), I’d go hard for these monsters:
- xStocks leads on Solana, just landed on Hyperliquid, and is looking to lead the market. - Ondo Finance fights elbow to elbow. It has its own market and launched a perpetuals DEX. We’re early: it gives away $175k weekly in USDC, 50% off fees, and a points system that will end with a strong drop of $ONDO. It has everything for an epic battle.
Staying out of these projects means missing one of the best opportunities of the cycle. While everyone else operates with the same synthetics (and we don’t even know if they make it alive to the TGE), these are the creators and custodians of the real assets.
Yes, we’re hunters of airdrops and we farm almost everything. But these can’t be missed: they’re the ones bringing the next big change.
It’s like organizing a World Cup and not calling France, Argentina, and Spain. We play with Cabo Verde and Egypt… but we also play with the big ones.
Links: Argentina xStock → https://defi.xstocks.fi/points?ref=DRAGON Spain Ondo → https://app.ondoperps.xyz/?ref=KWVXWZ
And if quantum computing has already arrived and is being deployed silently, like guerrillas in a South American jungle.
Small groups, with small but lethal attacks.
Imagine this: if quantum comes out at scale and they steal all the Bitcoin, they would automatically go to zero. Nobody wants an asset that has been stolen in its entirety.
Such an expense and infrastructure deployed to steal everything and have it amount to nothing makes no sense.
Those behind quantum are brilliant people with a high IQ, and they will know how to move 100 times better than we do.
So what if the plan is to deploy quantum and carry out small attacks?
Bursts that destroy something, but not everything.
Bursts that remain as isolated attacks only, like the Coldcard attack of 1,800 BTC across more than 4,500 addresses totaling more than $130 million.
Although the attack had repercussions, it was not enough for the price of $Bitcoin to fall.
A small attack of $130 million, without any loss in the price of Bitcoin, is an enormous haul.
So what if quantum is already attacking in this way, going unnoticed, without raising suspicion that it’s quantum?
These are my concerns.
Dragoncrip
·
--
🚨 They broke the 4 wallets with passphrase.
The hacker from the Coldcard attack, after a week, broke the wallets with passphrase.
Let’s remember that the example used the BIP-39 dictionary words, meaning they are 2048 easy and well-known words in English.
Finding a single word requires only 2048 attempts. By brute force, finding that key takes just a few seconds:
- 1 word is trivial: seconds or less. Combinations: 2.048
- 2 words is easy: minutes with decent hardware. Combinations: 4.2 million
- 3 words is moderate: hours with modern GPUs. Combinations: 8.59 billion
While those times are fast, it’s because the attacker already had the seed phrase and knew that wallet (which was made public) had as its passphrase BIP-39 dictionary words.
As a recommendation, the passphrase gives you time to take action, and that time depends on how strong that key is.
- Never use 1, 2, or 3 words from the BIP-39 list as a passphrase (they’re easy). - Never use only numbers; they’re easy. - Spanish words are stronger than English ones. - Use mixed characters (uppercase, lowercase, numbers, and symbols).
The hacker from the Coldcard attack, after a week, broke the wallets with passphrase.
Let’s remember that the example used the BIP-39 dictionary words, meaning they are 2048 easy and well-known words in English.
Finding a single word requires only 2048 attempts. By brute force, finding that key takes just a few seconds:
- 1 word is trivial: seconds or less. Combinations: 2.048
- 2 words is easy: minutes with decent hardware. Combinations: 4.2 million
- 3 words is moderate: hours with modern GPUs. Combinations: 8.59 billion
While those times are fast, it’s because the attacker already had the seed phrase and knew that wallet (which was made public) had as its passphrase BIP-39 dictionary words.
As a recommendation, the passphrase gives you time to take action, and that time depends on how strong that key is.
- Never use 1, 2, or 3 words from the BIP-39 list as a passphrase (they’re easy). - Never use only numbers; they’re easy. - Spanish words are stronger than English ones. - Use mixed characters (uppercase, lowercase, numbers, and symbols).
Dragoncrip
·
--
The power of adding a passphrase to your wallet increases your security by thousands of times.
Here’s a nice test story:
The experienced user @ColeTU would use a Coldcard Mk3 wallet and, from that seed, create 4 more wallets, but with a passphrase.
Then he would send funds in equal parts to those 5 wallets to see what would happen to his funds.
For this, to his original seed he created 4 additional derivations using a passphrase and sent funds to each of them:
With this, he wanted to see whether the funds were safe and how long it would take for them to be compromised until they were stolen.
The responses didn’t take long to arrive. In the first few minutes, the original wallet (the seed only) is instantly drained: all its funds are stolen in a snap.
Days passed, and almost a week later, the remaining 4 wallets with different levels of passphrase difficulty are still intact.
Even the one with the lowest security—the easiest one-word passphrase—remains intact, with the funds not stolen.
This shows the great protection that a passphrase gives our seed, even with a simple key of just one word.
A week passed, and one of the main features that this mechanism provides is TIME. Passphrases give you the world’s most valuable asset: TIME. Time to take action and save your assets. Time to move your assets to another new wallet. Time between losing or winning.
If this user had been attacked at the time the Coldcard was being drained, he would have lost the “lure” assets of the primary wallet (the one with the seed only), but he would have had enough time to save the rest of his assets.
Take care of your assets; take care of your security.
With this, he wanted to see whether the funds were safe and how long it would take for them to be compromised until they were stolen.
The responses didn’t take long to arrive. In the first few minutes, the original wallet (the seed only) is instantly drained: all its funds are stolen in a snap.
Days passed, and almost a week later, the remaining 4 wallets with different levels of passphrase difficulty are still intact.
Even the one with the lowest security—the easiest one-word passphrase—remains intact, with the funds not stolen.
This shows the great protection that a passphrase gives our seed, even with a simple key of just one word.
A week passed, and one of the main features that this mechanism provides is TIME. Passphrases give you the world’s most valuable asset: TIME. Time to take action and save your assets. Time to move your assets to another new wallet. Time between losing or winning.
If this user had been attacked at the time the Coldcard was being drained, he would have lost the “lure” assets of the primary wallet (the one with the seed only), but he would have had enough time to save the rest of his assets.
Take care of your assets; take care of your security.
xStock brings Hyperliquid the full potential of the tokenized stock market in SPOT. This is going to be wild.
The tokenized stock market is advancing at an unstoppable pace. There are 3 major players, and from there will come the new big airdrop narrative of this cycle.
Everyone farms perpetual DEXs, but the real exponential growth is happening from the bottom up: tokenized stocks. The big hit of this cycle will come from them.
Today I’m talking to you about xStock, which just landed with everything on Hyperliquid (the largest decentralized exchange in the world).
They bought 1 slot on Hyperliquid for 500 $HYPE each (total $270,000), to bring the best tokenized stock market in SPOT.
They will be implemented and start generating points in xStock.
With only 200,000 users and fewer than 30k wallets actually earning points, we’re early.
People aren’t paying attention to this passive farming… and that’s the best part: we can accumulate more points before the boom driven by Hyperliquid.
This combination benefits both: - Hyperliquid becomes stronger, with more volume and profits. - xStock grows in volume and market share.
A genkidama is being built in silence. When it explodes, it’s going to be huge.
Go farm now while only about 30k wallets are getting points. Then the mass of 2–3 million arrives.
Link: https://defi.xstocks.fi/points?ref=DRAGON
If you want, in the next post I’ll explain all the different ways to farm it. Put it in the comments.
The tokenized stock market is going to be enormous.
Dragoncrip
·
--
Testing a second xStocks account with just $85.
The results in 3 days are:
- 95.173 points - I ended up ranked 6,300 - I’m in the Top 5% - Account without referrals - And if TODAY they gave me the Airdrop, I’d take $57 based on my thesis.
All of this in just 3 days, and I still have a lot ahead. How did I do it?
Buying STRC’s YT on Pendle.
Summary (<1500 characters):
1) A good move on Pendle with STRC’s YT (Strategy’s preferred shares that pay a 12% dividend).
STRC’s YT is at **83x** + a 2x points booster = 165x in points.
With $100: - $8,300 power for the 12% dividend - $16,600 power to farm xStock points
The other side: - The YT expires and is worth $0 (you lose the capital). You have ~20 days left. - Dividends every 15 days (0.5% each). After that there’s 1 payment → at 83x that would be about ~$41.5 per each $100.
Strategy: Enter cheap, farm points, and exit before expiration (selling at a higher price) or collect the dividend and sell. After the dividend, the price drops; before it rises.
Real example: I entered with 1 STRC 3 days ago → now it’s worth 1.0035. I’m up in both profit + free points.
I fell for a Trezor phishing scam by @Trezor, THIS IS HOW THEY STEAL FROM YOU
I fell for a Trezor phishing scam -> THIS IS HOW THEY STEAL FROM YOU -> WARNING This is how 99% of phishing scams work → If you pay attention, you can save yourself 1) They set up a website, a clone of the Trezor home page 2) They put in a large amount of money so that Google sponsors them in the results and they appear first. The information in the results is almost identical to the original 2) The person has a Trezor or buys one and at some point has a doubt or problem, or just wants to operate from the wallet.
Jumper Advance, the new evolution of jumper. It allows you to set an Order Limit operation.
For example, I want to wait to buy a Bitcoin dip directly from the wallet.
1) I choose Limits 2) I choose my buy price -5% in my case ($61.784) 3) I set the amount I want to buy 4) I select for how many days I want my order to be active 5) I choose the DEX to trade on
I confirm and wait: if at dawn the price drops, it reaches my price and rises—this order triggers.
It’s ideal. Today I used it to sell an asset with a slight rise of 2%, and it executed when it went up for a moment.
- 95.173 points - I ended up ranked 6,300 - I’m in the Top 5% - Account without referrals - And if TODAY they gave me the Airdrop, I’d take $57 based on my thesis.
All of this in just 3 days, and I still have a lot ahead. How did I do it?
Buying STRC’s YT on Pendle.
Summary (<1500 characters):
1) A good move on Pendle with STRC’s YT (Strategy’s preferred shares that pay a 12% dividend).
STRC’s YT is at **83x** + a 2x points booster = 165x in points.
With $100: - $8,300 power for the 12% dividend - $16,600 power to farm xStock points
The other side: - The YT expires and is worth $0 (you lose the capital). You have ~20 days left. - Dividends every 15 days (0.5% each). After that there’s 1 payment → at 83x that would be about ~$41.5 per each $100.
Strategy: Enter cheap, farm points, and exit before expiration (selling at a higher price) or collect the dividend and sell. After the dividend, the price drops; before it rises.
Real example: I entered with 1 STRC 3 days ago → now it’s worth 1.0035. I’m up in both profit + free points.
Remember: YTs lose value every day until they’re worth zero at expiration. They’re meant to squeeze points, not to hold.
Dragoncrip
·
--
Tokenized stocks are growing at an exponential rate.
Solana’s strongest player → @xtocksFi
has just surpassed $600M in tokenized shares.
Q2 2026 Total volume of tokenized assets on-chain: $5.8B xStocks contributed more than $2 billion.
Tokenized stocks (Equities – purple color) became the absolute engine of growth.
Look at how the purple outgrew the rest of the categories. Growth is blasting off. Just compare the Q2 2025 vs. Q2 2026 chart. It’s simply overwhelming.
I wouldn’t leave this out, not in a million years, of farming xStocks points.
We’re early, and the time to rack up points is now.
To give you an idea: • There are 180,000 wallets • With 400 points (easy) → Top #22,000 (top 13%) • With 21,000 points → Top #10,000 (top 6%) • With 700,000 points → Top #1,800 (Top 1%)
This could be a big airdrop, given the strong growth this narrative is seeing.
In the meantime, here’s the link with a 20% booster defi.xstocks.fi/points?ref=DRAGON
How strong is choosing a 3-word PassPhrase with numbers and symbols, about 15 characters?
A life to break it
Why?
The process is deliberately slow. That is the security design of BIP39.
For each attempt, it has to calculate the entire key-derivation process.
That means thousands of heavy cryptographic operations (HMAC + SHA-512) for each attempt.
That is the strength of having the seed plus the Passphrase
Dragoncrip
·
--
How to Create the PassPhrase in the Rabby Hot Wallet
One of the most recent problems we had after the Coldcard attack was the generation of the seed phrase from the device. Everyone of us wondered how to protect ourselves or increase security.
One of the most efficient ways and one of the strongest defense vectors is to have a Passphrase.
The ideal is to use a hardware wallet, but in the DeFi ecosystem, especially in the Farmer airdrop, where we make dozens of clicks, transactions, and signatures every day, it’s common to use a web wallet and, in most cases, a hot wallet. That’s why this tutorial explains how to add one more layer of security to our seed phrase in a hot wallet.
How to Create the PassPhrase in the Rabby Hot Wallet
One of the most recent problems we had after the Coldcard attack was the generation of the seed phrase from the device. Everyone of us wondered how to protect ourselves or increase security. One of the most efficient ways and one of the strongest defense vectors is to have a Passphrase. The ideal is to use a hardware wallet, but in the DeFi ecosystem, especially in the Farmer airdrop, where we make dozens of clicks, transactions, and signatures every day, it’s common to use a web wallet and, in most cases, a hot wallet. That’s why this tutorial explains how to add one more layer of security to our seed phrase in a hot wallet.
Ondo gives away $100 USDC They come with everything and want to dominate the RWA game—they want to become the top 1, and the move they’re making is phenomenal.
They’re giving away $100 USDC in selected accounts that meet these requirements
- They operated with more than $1M on Hyperliquid (HIP-3) - They never deposited funds in ONDO
This is the Ribbon indicator I have set on the 200 and 300-week moving average; it highlights that range in green.
Strategic $MSTR has already broken through the zone—good place to look for accumulation.
$Bitcoin enters the range slowly, dips, peeks in, and then goes back above again. Very nice zones to make medium- and long-term entries.
While BTC is like Messi: the sample—touches, walks, stays calm, hooks on, walks. MSTR is like Mbappé: he darts hard, hits from far away, calms down, drops, goes back, then fires from the libero and breaks the area with force.
How I miss the FIFA World Cup—I’ve got withdrawal, damn it.
Dragoncrip
·
--
🚨 URGENT – DROP EVERYTHING YOU’RE DOING:
Every crypto user should use at least 12 words + a passphrase (13 security elements). Save this post.
If they hack you or steal your 12 words, they’ll still be missing the passphrase. Even with brute force (2048 words), they won’t get it.
### Advantages of the passphrase: 1. Exponentially increases security. 2. Lets you have many wallets on the same device (one per passphrase). 3. It’s the best alarm: if someone uses your seed phrase, you’ll notice and have time to move the funds. 4. Protects you from physical theft. You hand over the main wallet (with a little “bait” money) and your real assets stay safe behind the passphrase.
### How it works: The 12 words generate a binary seed. When you add the passphrase, a completely different binary is generated. Example: - 12 words without passphrase → Main wallet - 12 words + “dog” → Hidden wallet 1 - 12 words + “Dragon” → Hidden wallet 2
If you lose the passphrase, you lose access to that wallet.
### Practical recommendation: Always keep a small balance ($500–$1000) in the main wallet (without passphrase). If it gets stolen, it’s the sign that your seed was compromised and you have time to act.
### How it’s used depending on the device: - Ledger: each passphrase is linked to a different PIN. - Trezor: it asks you to type the passphrase every time you log in. - Hot wallets (Rabby, etc.): you load the 12 words + the passphrase and you’re done.
### How to store it: Seed phrase in one place (preferably metal), and the passphrases in another location or kept separately.
Final summary: the passphrase is mandatory. Without it, you’re playing with fire.