CME’s Duffy clashes with CFTC and Kalshi over prediction markets
The confrontation that broke out on Thursday at a CFTC-led meeting could be seen as more than a play for regulation. Prediction markets like Kalshi and Polymarket increasingly tap into crypto settlement systems, while the regulator involved in the conflict is deciding which approach to take for regulating event contracts and perpetual futures in the US. The stakes are quite high as the size of the prediction market ballooned to $63.5 billion in 2025, compared to $16.5 billion in 2024. Whether Washington will implement regulation at the federal level for the prediction market or leave it to the states to regulate it independently may determine whether liquidity is smoothly consolidated or fragmented. CME Group’s CEO Terrence Duffy noted on Thursday that the existing regulatory system can also be exploited by dishonest actors. Duffy calls out self-certified contracts At the CFTC’s Innovation Advisory Committee meeting, Duffy criticized the number of event contracts that exchanges have self-certified rather than submitted for review. He pointed to contracts involving what President Donald Trump might say in his State of the Union address and when Venezuelan President Nicolás Maduro might be removed from power. “There are definitely people who are manipulating these contracts,” Duffy said, according to The Block’s Sarah Wynn. “That is not good for our industry. That is horrible for our industry.” There is a certain irony to his warning. CME embraced event contracts, announcing in February that it had cleared 100 million such contracts since launching the product in December. Duffy pointed to this as evidence of demand coming from “the next generation of potential traders.” However, on Thursday, he tied the integrity of the marketplace to Trump’s vision of the U.S. becoming the “crypto capital of the world,” saying that questionable contracts jeopardize that endeavor. Selig fires back with “fake news” CFTC Chair Michael Selig immediately challenged Duffy’s examples, saying the contracts he cited were never listed in the United States. “This occurred offshore, and that’s fake news,” Selig said. Duffy held his ground. “I’m just bringing it up, that’s not good for markets,” he answered. This situation illustrates a larger battle over jurisdiction. While Selig contended that the CFTC had “exclusive jurisdiction” over prediction markets, including sports contracts, many states insist that such products are gambling products subject to state law. The commission is considering additional rule changes and stronger retail protections. “We’ve heard the concerns of public commenters about inadequate consumer protections for retail loud and clear,” Selig said Thursday. Insider-trading scandals feed the backlash Congress is also examining prediction markets following two cases that received much media attention. A U.S. soldier has been charged with placing bets about the capture of Venezuela’s President Maduro using classified information. Meanwhile, a well-known teleprompter operator of Donald Trump is suspected of betting on Kalshi about events occurring at the State of the Union address following tip-offs about them. Lawmakers have proposed restrictions on sports and casino-style contracts, while the Senate has passed a measure barring its own members from trading on prediction markets. Kalshi and Polymarket have both announced new controls aimed at manipulation and insider activity. The tensions became personal when Kalshi COO Luana Lopes Lara asked Duffy whether CME had ever faced manipulation. “I have more people in my regulatory department than you and your entire company,” Duffy replied. “Maybe you should learn a bit about efficiency then,” Lopes Lara shot back. “Maybe you should learn about credible markets,” Duffy answered. Why crypto traders should track this The dispute is already in court. As Cryptopolitan has reported, CME sued the CFTC and Selig in June over the agency’s approval of Kalshi, arguing that the products should fall under swaps rules rather than futures regulation. That decision matters well beyond prediction markets. Kalshi has since expanded into crypto perpetuals, offering contracts across 13 cryptocurrencies after BTCPERP launched on June 3. If CME succeeds in challenging the CFTC’s framework, the precedent supporting those products could also weaken. That would put not only prediction markets but also some of crypto’s newest regulated derivatives rails under renewed legal scrutiny. U.S. FEDERAL GOVERNMENT │ ▼ ┌──────────────────────────┐ │ CFTC │ │ Commodity Futures │ │ Trading Commission │ └────────────┬─────────────┘ │ Federal derivatives authority │ ┌──────────────────┴─────────────────┐ ▼ ▼ ┌───────────────┐ ┌───────────────┐ │ KALSHI │ │ OTHER DCMs │ │ prediction │ │ / derivatives │ │ market │ │ venues │ └───────┬───────┘ └───────────────┘ │ │ │ DISPUTE │ ▲ ▼ │ ┌──────────────────────┴─────────────────────┐ │ STATE AUTHORITIES │ │ Gaming regulators + state attorneys general │ └──────────────────────┬─────────────────────┘ │ Gambling-law claims │ ▼ ┌────────────────────┐ │ FEDERAL COURTS │ │ Decide whether │ │ federal authority │ │ preempts state law │ └────────────────────┘ This is the actual story: there isn’t one straight hierarchy. There are three overlapping power centers: CFTC says federally regulated derivatives/event contracts fall under federal commodities law. States argue that sports/event contracts can constitute gambling under state law. Federal courts increasingly have to decide where federal jurisdiction ends and state authority begins. Recent litigation demonstrates that this is not theoretical. Washington ordered Kalshi to restrict several markets, while the CFTC has taken the opposite position in its broader fight with state regulators.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
Bitcoin jumped above $75,000, hitting its highest level since April and extending its four-day gain to 20%. Trump pushed Congress to pass the Clarity Act and hinted at regulating Hyperliquid, sending the HYPE token up about 25%. Falling Treasury yields helped drive heavy Bitcoin ETF trading, while crypto volatility climbed and Ether hit a three-month high at $2,272. Crypto stocks rallied, with Coinbase, Strategy, Canaan, Circle and Robinhood all higher as traders watched the political fight over new U.S. crypto rules.
One in seven German numbers on a leaked list belonged to a crypto trader
Rapid7 Labs uncovered Operation ASTERIX, a crypto fraud pipeline that leveraged AI coding assistants to create fake Ledger, Trezor, and Exodus apps. It matched 43,066 phone numbers to actual exchange accounts. Any user who self-custodies their crypto is a potential target. The operation was still ongoing when researchers discovered it. A misconfigured server gave up the whole playbook An exposed web directory was discovered by Rapid7 researchers Anna Širokova and Jan Recinsky on campaign infrastructure. Inside were the raw ingredients of a live fraud operation. The pair’s August 17 report detailed the data trove, which included phone-number datasets, account-validation tools, phishing panels, voice-dialing scripts, the fake wallet applications themselves, and code to siphon stolen data out through Telegram. Most of that tooling was still in use or in development when it leaked. Rapid7 said it could reach out to providers and authorities, including Apple’s security team, while the campaign was happening. The operation is named after Asterisk, the open-source telephony platform recovered on the server. The operator used Asterisk to make the vishing, or voice-phishing, calls to coincide with fake support emails victims had already received. In the open directory there were around 885,000 phone numbers, and the largest file was a collection of 316,002 German mobile numbers. Smaller directories included Hong Kong, Bulgaria, the UK, the US, Canadian fintech customers, and Ledger-related lists. The operators then checked those German numbers against an account checker and confirmed that 43,066 were crypto exchange users. This is a hit rate of about 13.6%, almost one in seven. A further batch of 5,576 numbers was associated with Binance accounts and lined up for attack. The report also mentioned a Kraken checker and fake emails pretending to be from Crypto.com. The count of validated targets sits oddly against the activity logs. The logs recovered indicate that there were only 20 lead lookups during a span of about two weeks. Additionally, six phishing emails were sent, suggesting that the operators favored a slow, hand-selected targeting approach rather than contacting all numbers. The fake apps asked for a seed phrase The apps mimic Trezor Suite and Ledger Live, with Exodus also spoofed, and they ask users to enter a recovery phrase of 12 to 24 words that controls a hardware wallet. That phrase is the master key to the funds, and whoever has it can empty the wallet. The stolen phrases were then exfiltrated via Telegram. Rapid7 found that AI coding assistants were used across the entire development process, not just to spit out isolated snippets. Recovered prompts, shell history, and project files show the operator relying on AI tools to package the Electron apps, obfuscate code, fix builds, and prepare the malware for distribution. The tool was GitHub Copilot. When one model began to refuse parts of the work, the operator switched providers and attempted to break the next model’s safety controls with a custom jailbreak prompt, Rapid7 said. Earlier in August, Trezor warned 13,689 customers after a breach at its shipping partner ShipMonk exposed names, emails, phone numbers, and addresses, as Cryptopolitan reported. Ledger and Trezor owners have also received physical letters with QR codes leading to phishing sites, as Cryptopolitan reported back in February. Hacken, a blockchain security firm, said that phishing and social engineering made up $306 million of the crypto industry’s $482 million in first-quarter losses. Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
The connect-wallet prompt is the tell on a fake AML screening site
Fake anti money laundering screening websites are stealing from crypto investors. These websites prompt users to connect a wallet and sign a transaction, which is not required for any genuine wallet check. Malwarebytes discovered the attack this week. Real wallet screening needs only the public address Banks and regulated firms have to check under anti-money laundering rules that their customers have no links to crime. In crypto, that screening means looking at a wallet address’s public transaction history for contact with hacks, thefts, sanctioned parties, or other suspicious activity. The fraudulent sites take that idea and turn it into a weapon, according to Malwarebytes researcher Stefan Dasic. Some copy the branding of AMLBot, a legitimate screening service. Others run under generic names like “AML Check.” A visitor picks a cryptocurrency, clicks to scan it, and is asked to connect a wallet to see the result. One version that Malwarebytes examined displays a progress bar with messages like “Checking wallet history…” and “Verifying compliance…” before displaying a fake error that asks for a small top-up to “cover the fee.” Tap retry, and the animation runs again before handing back a soothing “Clean, Low Risk” verdict and an offer to download a report. A genuine basic screening requires only the wallet’s public address. It’s a lookup, and there’s no signing, permissions granted, or wallet connecting. “If an AML checker asks you to connect your wallet rather than simply enter its public address, treat that as a warning sign,” the Malwarebytes team wrote. Connecting a wallet does not hand over the keys, but it does expose the public address. This allows the operators to see what assets are inside and build a transaction targeted at that particular wallet. That transaction is then sent to the victim to approve. Approval is the moment the money moves. Researchers advise against confirming an unexpected transaction. Malwarebytes has discovered the same skeleton being used under different names and logos. The kit is being rebranded and resold. A $500 kit phishes recovery phrases behind a 15% bonus This month, Cryptopolitan reported on a $500 turnkey kit available on a cybercrime forum. This kit creates a fake $TSLA presale and scans each visitor’s wallet for valuable assets. It then attempts to phish for the 12-word recovery phrase by offering a 15% bonus. Its admin panel inflates fake balances at will so that the victims keep paying. In May, Solana Floor analysts spotted a scheme that flooded Solana wallets with fake “$CJUP” tokens impersonating Jupiter Exchange’s Jupuary airdrop and redirecting recipients to a drainer site, as Cryptopolitan reported at the time. CoinDCX said it has detected more than 1,212 fake websites impersonating its platform between April 2024 and January 2026. Mumbai police have registered an FIR against fraud being perpetrated through a website impersonating CoinDCX. Malwarebytes advised that anyone who only connected a wallet should disconnect the site. Anyone who gave a token permission to access their wallet should check for unfamiliar permissions and revoke them. Anyone who signed something they didn’t understand should review recent activity and, if funds are exposed, move everything to a new wallet. Anyone who entered a recovery phrase or private key should assume the wallet is compromised. The smartest crypto minds already read our newsletter. Want in? Join them.
The CFTC is preparing crypto market rules in case Congress fails to pass CLARITY
CFTC (Commodity Futures Trading Commission) has started preparing a federal crypto market structure that it can pursue under existing law if Congress fails to pass CLARITY. CFTC Chairman Michael S. Selig announced the work Thursday, saying his staff are now looking at rules that could bring both registered companies and currently unregistered crypto exchanges under a purpose-built CFTC framework. He is also working with SEC Chairman Paul Atkins through Project Crypto on an asset classification system. But the CFTC is not planning to leave the market in limbo if CLARITY dies on Capitol Hill. CFTC prepares its own crypto rules while Congress decides CLARITY’s fate Selig noted that the CFTC already has authority to designate a new type of designated contract market (DCM) centered on crypto. The current registered CFTC entities could be able to join, but unregistered cryptocurrency exchanges could apply for such designation. This framework would be applicable for margined and leveraged cryptocurrency trades with regulation specifically designed for these products. “To achieve this, I’ve directed the CFTC staff to begin exploring rules to codify a CFTC market structure for crypto assets using the agency’s existing authorities. This could enable current registrants as well as non-registrant crypto exchanges to be designated by the CFTC as a type of DCM known as a crypto asset market and offer crypto asset trading on a leveraged or margined basis subject to purpose-fit rules under the CFTC’s regulatory oversight.” Furthermore, Selig wants his employees to talk with protocol developers on how their products can be sold in the United States without these developers having to wonder where the boundary of legality is. “I’ve also directed staff to engage with developers of onchain finance protocols to establish ways in which developers can offer their protocols in a legal and compliant manner in the United States. Future-proofing developer protections once and for all.” Selig said CLARITY will still be given time for a congressional vote. If lawmakers cannot agree, however, he plans to tell staff to begin the CFTC rulemaking process. “We’re going to give CLARITY its breathing room for a vote, but if the Democrats cannot support a bipartisan work product, which reflects compromises from both sides of the aisle, and ultimately send a fair version of the bill to the President’s desk, then rest assured, I will direct CFTC staff to move swiftly to propose these new rules for the industry.” The chairman tied that approach to the CFTC’s history. Congress created the agency in 1974 after derivatives markets had moved well beyond the agricultural contracts covered by older federal laws. Currency contracts, petroleum allocations and Ginnie Mae certificates were among the newer instruments emerging at the time. The roots went back much further. Merchants formed the Chicago Board of Trade in 1848 above a flour store. By 1859, traders had developed arrangements that allowed contracts to settle based on changes in commodity prices instead of always requiring physical delivery. Futures were born, and politicians quickly started calling the activity gambling. Congress eventually created one federal framework instead of dividing derivatives regulation according to whatever commodity sat underneath a contract. The CFTC received “exclusive jurisdiction” over commodity derivatives and a legal mandate to “promote responsible innovation.” The definition of a commodity was intentionally wide. It could cover physical goods, services, rights, interests, events, and other underlying subjects used in derivatives. Federally regulated DCMs then became the main venues for these contracts, while also acting as self-regulatory organizations responsible for enforcing market rules. Selig expands the CFTC roadmap into AI compute and prediction markets The CFTC is also preparing for financial markets built around AI compute and expanding its rulebook for prediction markets. “We’ve crossed the Rubicon and are standing at a new frontier of finance. It’s not a question of whether innovations like blockchain, artificial intelligence, and prediction markets will transform our markets. It’s a question of where this innovation will take place and who will write the rules.” For AI, the agency is treating computing capacity as an increasingly important economic resource. Advanced GPU clusters are expensive and scarce, while demand keeps rising. Selig said spot, forward, and derivative markets could develop around compute to provide pricing and hedging tools. The CFTC issued a request for comment on compute markets earlier this week and is working with the Department of Commerce. The administration’s AI plan also calls for better access to large-scale compute for startups and researchers. “Access to advanced GPU clusters and compute capacity increasingly determines who can compete, who can innovate, and ultimately, who can lead. As demand for compute grows, so too does the need for markets capable of efficiently allocating scarce resources and managing risk.” Proposals have been made by the agency regarding modifications in CFTC Rule 40.11. It is not possible for the event contracts to fail to meet core principles or to be easily manipulated. War and terrorism, assassination, gaming, and criminal acts are given additional consideration, as per federal law, and the contracts may be prohibited by the CFTC. The problem is that terms including “gaming” and “involve” are not defined in the statute, while the law also lacks a fixed test for determining the public interest. The smartest crypto minds already read our newsletter. Want in? Join them.
A Bitcoin short squeeze carried XRP to $1.29 while its funds sat out
XRP surged around 30% last week to trade at about $1.29, its best run in months. The token jumped as the exchange-traded fund inflows that had supported earlier gains dried up. Wednesday did the heavy lifting XRP surged 10.40% on Wednesday, its biggest one-day gain since February 6, before adding a second leg Thursday that pushed the weekly candle toward $1.32. The level is just under the token’s 200-day average price, the closest XRP has traded to that line since the beginning of the year. The rally lifted XRP off a floor of $0.9862, which it touched the week before. This is the same zone the token hovered in just before its post-election surge in November 2024, which took it to an all-time high close to $3.65. The Relative Strength Index on the daily chart hit 79.2. The RSI has a scale of 0 to 100, with readings near 80 indicating an asset is heavily overbought. Bitcoin, which surged above $72,000 on Thursday, its highest level since May, was the catalyst. On Wednesday, shorts on Bitcoin were liquidated for $2.75 billion in crypto’s biggest-ever short-liquidation event, CoinGlass data shows. The 24-hour figure ran to $3 billion across the market. The U.S. Treasury said it would raise the size of its long-end buybacks to at least $4 billion per operation starting September 9. Traders interpreted the plan as a sign of looser financial conditions, and the move came hours before President Donald Trump met with crypto executives from Coinbase, Ripple, and Robinhood at the White House. ETF demand cooled while the price ran XRP beat its usual correlation with Bitcoin, but its ETF inflows dipped off in the surge. The United States spot XRP ETFs saw 30 straight days of net inflows after the launch of Canary Capital’s XRPC on November 13, amassing $1.18 billion in combined assets by mid-December, according to a report from Cryptopolitan at the time. That steady flow became one of the reasons for the token’s bullish case. CNBC correspondent MacKenzie Sigalos called XRP the standout crypto trade of 2026 in a January segment, pointing to inflows that held up during a fourth-quarter dip even as Bitcoin ETF flows fell, as Cryptopolitan reported. This week was a reversal for XRP. The price jumped, and the fund demand that had pushed XRP higher before took a breather. XRP open interest is already down over 11% from its rally-day high, suggesting some of the leverage behind the rally is unwinding. According to CoinGecko, XRP is currently trading at $1.26, up 11.3% on the day and 23.1% over the week. Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
Crypto, AI, and online betting firms are driving a record $517 million in corporate election spen...
Crypto firms, artificial intelligence companies, and online gambling businesses are behind a $517 million of corporate election spending focused on the 2026 U.S. races. Public Citizen’s data claims that U.S. companies put that sum into House and Senate contests during the 15 months through the first quarter, surpassing the $461 million corporations spent across the full two-year 2024 election cycle. Even more cash is expected before voting on November 3, when Democrats will try to control both chambers. The businesses sending the largest checks are not the traditional powers that dominated political money in Washington for decades. Crypto, tech, and betting firms route huge sums through expanding political networks Companies and billionaire founders can send funds into super PACs, affiliated PACs supported by those groups, and nonprofit organizations that need not reveal donors. Some donors fund several parts of those networks while also giving separately to individual politicians. Super PACs can raise unlimited sums of money, but they cannot hand those funds directly to candidates or coordinate what they do with campaigns. Instead, they can buy political ads, finance voter turnout efforts, and fund campaign events and rallies. CEOs have even spent millions of their personal money above corporate donations. This is seen by way of SpaceX (NASDAQ: SPCX) CEO Elon Musk, who has spent over $90 million in federal races for the 2026 cycle and will end up spending much more before November arrives. Co-founder of Alphabet (NASDAQ: GOOGL, GOOG) Sergey Brin has spent over $106 million in California alone, including money he spent trying to stop the wealth tax in his state. Meta Platforms (NASDAQ: META) has given $65 million to four separate super PACs supporting Democratic and Republican candidates in state races. Their activity includes elections in California, Texas, Illinois, and other states. Corporate spending is only part of the money flowing into the midterms. AdImpact estimates political advertising will hit a record $11.6 billion, including money from billionaires, unions, social causes, and other groups. That would move past the earlier advertising record of $11.2 billion set during the 2023-2024 election cycle. Fairshake goes after crypto critics as major donors stockpile cash for 2026 The crypto industry already used this political model aggressively during the 2024 elections. Coinbase (NASDAQ: COIN), Ripple, and venture capital company Andreessen Horowitz supplied major money to Fairshake, the sector’s main super PAC. One of the group’s biggest battles happened in Ohio, where its spending helped remove longtime Democratic Senator Sherrod Brown from office. Public Citizen later compared Fairshake to a corporate “Death Star” that could “annihilate individual candidates.” Its method moved away from the older habit of tying an industry closely to only one political party. Crypto groups instead supported politicians who favored their policy positions, regardless of whether those candidates were Democrats or Republicans. Politicians seen as hostile to the sector could then become targets of multimillion-dollar outside campaigns designed to push them out of office. Sherrod used to be one of the biggest voices against cryptocurrencies when he sat as the chairman of the Senate Banking Committee. Now, his approach has softened due to his political aspirations. Experts say that his aggressive stance has been toned down as he is seeking re-election in the Senate. According to Sherrod’s campaign director, Patrick Eisenhauer, he understands that “cryptocurrency is part of America’s economy.” Fairshake began 2026 with a $193 million pool of campaign money. Election records now show that about $130 million is still available for upcoming races. Coinbase, Ripple, and California venture capital firm Andreessen Horowitz supplied nearly all of that funding. Andreessen Horowitz has also contributed more than $81 million to PACs centered mostly on crypto and AI, based on federal campaign records reviewed by Reuters. At least $23.8 million from that amount was sent to Fairshake. The company’s founders are also using their personal wealth. Ben Horowitz and Marc Andreessen have each donated around $4 million during this election cycle. Most of their personal contributions went to MAGA Inc., the super PAC supporting President Donald Trump. Fairshake still has $130 million available for political spending before November. Elon has also indicated that he expects to spend more than the $90 million he has already committed. Large amounts from both sources are therefore still waiting to be used, while total corporate political spending has already climbed to $517 million several months before voters go to the polls. If you're reading this, you’re already ahead. Stay there with our newsletter.
Encrypted web page payload turns Grok into a chat history leak
Grok is still handing users’ private chat data to hackers, according to a report from Adversa AI published on Thursday. Hackers get ahold of this data through injecting commands in encrypted text that sits in regular-looking web pages. The cybersecurity firm alerted xAI more than two months ago; however, there’s no fix available yet. Ciphertext flows through Grok’s filter Adversa researcher Rony Utevsky named the attack “cryptographic context injection.” It passes the chatbot’s own safety filter easily. Most LLMs filter incoming and outgoing text for suspicious commands. However, this attack hides malicious text from Grok’s filter. The malicious instruction is encrypted, leaving only the ciphertext, the key, and a note on how to decrypt it on the page. The filter reads text but never runs it, so ciphertext passes through. Grok then decrypts it inside its code sandbox. It treats the plaintext that pops out as a trusted tool output. “The runtime execution launders attacker-controlled data into trusted instructions the agent will act upon,” Adversa wrote in its disclosure. When a user asks Grok to summarize or analyze a webpage, the assistant fetches it, decrypts the hidden payload, and follows it. The decrypted instructions tell Grok to make something that looks like a decryption key. It’s derived from the user’s name, coarse location, subscription tier, and the complete set of prompts from that conversation. It is then attached to a URL that directs to the attacker’s server. Once Grok opens the URL, the data lands in the attacker’s logs. xAI has been sitting on the report since June 3 xAI has been aware of this attack since June 3, 2026, when Utevsky reported the bug directly and through the company’s HackerOne program for bug bounties. xAI has noted the report but has not given a timeline for a patch. Utevsky says he raised it again on August 4 and August 10. As of August 19, the exploit was still working on Grok.com. Adversa is only publishing the attack mechanism, and the recommended fix is in the agent’s harness. Days ago, Google’s Gemini 3.7 Flash model generated material normally blocked by its filters. This includes instructions for building an incendiary weapon and a copy of the model’s own system prompt. That version is a direct jailbreak. Utevsky said this is because Gemini’s Python environment can’t reach outside websites. Google considers jailbreaks to be outside of the scope of its disclosure program. Gemini’s success rate dropped sharply by August. Adversa could not point to a filter update, a model change, or both as the cause. In May, Cryptopolitan reported that a user on X wrote a message in Morse code that bypassed the bot’s safeguards and got Grok to tell the linked agent Bankrbot to send around $200,000 in DRB tokens on Base. If you're reading this, you’re already ahead. Stay there with our newsletter.
Encrypted web page payload turns Grok into a chat history leak
Grok is still handing users’ private chat data to hackers, according to a report from Adversa AI published on Thursday. Hackers get ahold of this data through injecting commands in encrypted text that sits in regular-looking web pages. The cybersecurity firm alerted xAI more than two months ago; however, there’s no fix available yet. Ciphertext flows through Grok’s filter Adversa researcher Rony Utevsky named the attack “cryptographic context injection.” It passes the chatbot’s own safety filter easily. Most LLMs filter incoming and outgoing text for suspicious commands. However, this attack hides malicious text from Grok’s filter. The malicious instruction is encrypted, leaving only the ciphertext, the key, and a note on how to decrypt it on the page. The filter reads text but never runs it, so ciphertext passes through. Grok then decrypts it inside its code sandbox. It treats the plaintext that pops out as a trusted tool output. “The runtime execution launders attacker-controlled data into trusted instructions the agent will act upon,” Adversa wrote in its disclosure. When a user asks Grok to summarize or analyze a webpage, the assistant fetches it, decrypts the hidden payload, and follows it. The decrypted instructions tell Grok to make something that looks like a decryption key. It’s derived from the user’s name, coarse location, subscription tier, and the complete set of prompts from that conversation. It is then attached to a URL that directs to the attacker’s server. Once Grok opens the URL, the data lands in the attacker’s logs. xAI has been sitting on the report since June 3 xAI has been aware of this attack since June 3, 2026, when Utevsky reported the bug directly and through the company’s HackerOne program for bug bounties. xAI has noted the report but has not given a timeline for a patch. Utevsky says he raised it again on August 4 and August 10. As of August 19, the exploit was still working on Grok.com. Adversa is only publishing the attack mechanism, and the recommended fix is in the agent’s harness. Days ago, Google’s Gemini 3.7 Flash model generated material normally blocked by its filters. This includes instructions for building an incendiary weapon and a copy of the model’s own system prompt. That version is a direct jailbreak. Utevsky said this is because Gemini’s Python environment can’t reach outside websites. Google considers jailbreaks to be outside of the scope of its disclosure program. Gemini’s success rate dropped sharply by August. Adversa could not point to a filter update, a model change, or both as the cause. In May, Cryptopolitan reported that a user on X wrote a message in Morse code that bypassed the bot’s safeguards and got Grok to tell the linked agent Bankrbot to send around $200,000 in DRB tokens on Base. If you're reading this, you’re already ahead. Stay there with our newsletter.
Researchers tie the arrayref Rust crate hijack to North Korean hackers
Wiz says the supply chain attack that poisoned arrayref, a Rust package present in roughly three-quarters of environments running Rust, has drawn comparisons with recent North Korean operations. The harmful update hid a backdoor that steals login information inside a code designed to run automatically when users compile projects. So, anyone who compiled a project on Thursday may now have exposed their computer and secrets. Why is North Korea being blamed for the hack on arrayref? Wiz researchers Rami McCarthy and Benjamin Read have published a report in which they noted that the arrayref payload beacons to a command-and-control path, /49890878, that also appears in the Mastra campaign. Microsoft links the Mastra campaign to a North Korean hacking group it calls Sapphire Sleet. The internet address (IP) used in the arrayref attack shares the same security certificate as another address used in Mastra. Also, a victim who reported suspicious activity flagged an IP that Google Cloud saw in the axios npm attack. Mandiant says that the attack was done by a North Korean group called UNC1069. Both attacks used the same hosting company, Hostwinds. The attack was hard to notice because it changed very little. Ilyas Makari, a security researcher from Aikido, found that the actual code inside the three Rust packages, arrayref, internment, and append-only-vec, was not altered. The only change was one new dependency added to each package’s list called proc-macro1. This name is a misspelling of the popular proc-macro2 crate, which has over 154 million downloads. The fake crate even includes the real proc-macro2 code, so the software still builds and passes all tests. The harmful part was hidden in the build script. Cargo runs build scripts automatically at compile time, so, as the Rust Security Response Team spelled out in its advisory, merely compiling a project that pulled the bad version was enough to trigger the attack. Once running, the second stage of the attack stole saved passwords from Chrome, Brave, and Edge browsers and installed itself so it would survive computer restarts on Windows, Mac, and Linux. The largest Rust compromise by download count Aikido stated that this attack is the biggest Rust crate compromise it has seen, measured by downloads, with arrayref, which is used in tools for Solana and Ethereum, sitting at about 244 million total downloads. The exposure was reportedly live for 86 minutes before deletion. The team said Nextron Systems made the initial report. And once the attack was discovered, the team unyanked the clean versions and locked the maintainer’s account. The Rust team said it does not believe the author acted maliciously, assessing instead that their machine or credentials were compromised. Notably, Amazon disclosed on July 29 that it had linked a string of npm library compromises to a single DPRK-linked actor. TRM Labs also reported that North Korean groups accounted for about 76% of all crypto hack value in 2026 through April (roughly $577 million). Black Hat researcher Vangelis Stykas has said he tracked North Korean hackers into 1,640 companies across 57 countries. He found that they often bait developers with fake job offers that install malware, similar to the poisoned build dependency in this case. Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
Chamath Palihapitiya warns data center revolt could dent US GDP
Investor Chamath Palihapitiya issued a warning in an X post on Thursday. He argued that the political finger-pointing surrounding the construction of AI data centers could lead to the loss of 200 to 300 basis points of annual US GDP if the fighting continues. Chamath pointed to backlash from states like Texas, Ohio, and Pennsylvania as early signs of a situation that could spread across the United States. What did Chamath call a powder keg? Palihapitiya is a Silicon Valley venture capitalist and has painted the state-level fights over AI data centers as a national economic risk. In an August 20 post on X, he wrote, “This is a powder keg,” and the matter could derail the American economy if it metastasizes. He blamed the AI industry for “doing the basics” and went on to list a few things the sector has got wrong when it came to AI data centers. His comments come amid a slew of posts about the issue of an increase in electricity rates due to the emergence of AI data centers. In a back-and-forth on August 19, he stated that building expensive reactors and moving large users off the grid will spike everyone else’s electricity rates. “This is now how electricity prices work,” he wrote. In a previous post, Chamath has asked what nuclear plants would run if not data centers. From supporters to skeptics in Ohio, Texas and Pennsylvania The warning comes as governors are withdrawing support for data centers. Politicians across the aisle are currently revolting against such projects despite courting the AI data centers for years For example, Josh Shapiro, the Governor of Pennsylvania, previously supported the building of data centers. But just this week, he moved to remove the tax breaks and priority permitting he once offered data centers, if they do not meet newer and stricter standards. He tagged them the “strictest guardrails in the nation.” Governor Shapiro also berated what he called “predatory developers” looking to force local officials to do their bidding. The Governors of Texas and New York have taken similar steps, with Texas pausing projects and promising to rescind tax breaks worth over a billion dollars, and New York placing a one-year moratorium on large facilities In Ohio, however, the fight seems to be tougher. As Cryptopolitan reported, Senate Republicans are warning that a loss in the midterms by Sen. Jon Husted would spell disaster for AI projects in the state. Meanwhile, Ohio’s gubernatorial nominees, Republican Vivek Ramaswamy and Democrat Amy Acton, have mapped out plans to toughen the rules if sworn into office. Rising electricity costs are driving the outrage The outrage can be traced to the rise in household costs. Approximately one in six households in America is struggling to pay their utility bills. According to the Department of Energy, the construction of data centers would consume up to 15.3% of the country’s power supply by the year 2030. The Energy Information Administration counted up to 250 data centers in the state of Ohio and saw that residential power has climbed by 175% since 2005, way above inflation. 7 in 10 Americans are against the construction of AI data centers close to their homes; this is based on a March 2026 Gallup survey. Money is flowing from both sides Political groups from both sides of the divide are spending big. This election cycle, AI-focused super PACs have received $107 million and spent $55.5 million on federal races. Leading the Future has raised ~ $140 million with backing from Andreessen Horowitz and OpenAI President Greg Brockman, while Public First Action, a pro- AI regulation group, has raised $80 million, with half of that coming from Anthropic. The larger AI industry and the White House are trying to get up to speed. President Trump admitted Wednesday that data centers “could use a little public relations help,” even though he generally expressed support for them, stating, “If I were a governor or a mayor, I would want that plant in my community.” His ratepayer-protection pledge, which asks companies to cover their own power and grid costs, has been signed by Google, Microsoft, Meta, Oracle, xAI, OpenAI, and Amazon. Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
Meta's new Mac assistant reads business dashboards and feeds ad targeting
On Wednesday, August 19, 2026, Meta launched a dedicated Mac app for its Meta AI assistant. Version 1.0 beta transcribes speech in any app, reads a window on command, and hooks into a business owner’s Instagram, Facebook, ad accounts, and Google Workspace. The app is built for Meta ads buyers, such as creators and small businesses. Dictation lands anywhere, screen reading answers on request The app is built atop two Mac-native features. First, dictation. Hold a key, say something, and the text appears in whatever app’s open, email window, or code editor. Transcription runs across every app, putting Meta alongside Wispr Flow, Superwhisper, and Monologue. A month ago, Google brought the same system-wide dictation to its Gemini Mac app. The app also looks at the current screen and answers questions about it using Meta’s Muse Spark model. For the next question, the window sharing tool uses the visible text and a screenshot. That’s context gathering. The Option-Space shortcut brings up a small assistant box over the desktop. Meta swapped out its Llama models for the Muse family, the first output from Alexandr Wang’s Meta Superintelligence Labs, and shipped a terminal coding agent, Muse Code, two weeks ago. The Facebook creator still lags behind on desktop control. Gemini can share a window, while OpenAI’s ChatGPT and Anthropic’s Claude go further and let their assistants operate the machine. The real product is a business’s own data The release is all about advertising, the business that keeps Meta’s lights on. It’s an app mostly for businesses and content creators. It wires into Facebook, Instagram, and Google Workspace for document access. The Workspace hookup is gated behind a professional Facebook or Instagram account. Once connected, the assistant reads how a post performed, from reach to likes, shares, and saves, and recommends what to publish afterward. It also assembles decks, documents, and spreadsheets, and runs recurring jobs like a weekly performance report. Additionally, it surfaces public insights on how rival brands present themselves. “You can ask Meta AI questions about your business and get answers drawn from the context only Meta has, like your account engagement and ad performance.” Meta wrote in its own blog post. Meta’s privacy policy says that interactions with AI features are used to train its models. The training reach includes material from a connected business Google account and can inform ad targeting as well. Meta offers an Incognito Mode that processes chats in a space the company cannot access. It has not explained how such protection would extend to autonomous agents. The app is free, with paid Meta One plans that raise rate limits on heavier features. Early response from Mac users on the web was dull, with several saying they would not install it. In the Q2 2026 earnings call, CEO Mark Zuckerberg described a big opportunity to sell agents to businesses and automate work for them. Cryptopolitan reported in July that Meta expects to spend up to $145 billion this year on chips, data centers, and other artificial intelligence infrastructure. If you're reading this, you’re already ahead. Stay there with our newsletter.
Australia passes new law to fine tech giants that don't pay for local news
Australia’s parliament has passed the “News Bargaining Incentive” on Thursday, a law focused on top tech platforms like Meta, Google, TikTok and Microsoft, handing them a choice between signing paid deals with Australian news publishers or giving up 2.5% of their local advertising revenue to the government. The levy is set to affect only firms with a “significant” search or social media service in the country alongside local advertising revenue worth over A$250 million ($178 million), according to The News and SBS. According to current figures, these requirements cover Meta, Alphabet’s Google, TikTok and Microsoft’s LinkedIn. Terms set for the tech giants To ensure the companies do not escape the 2.5% charge entirely via loopholes, however, the law has terms built-in so the funds are well distributed. These platforms are now required to sign agreements with at least eight separate Australian publishers before their financial reporting period ends, and none of the deals can be credited for more than 25% of what they would otherwise owe. The 25% cap is the Australian government’s method to plug an obvious potential loophole. Without this cap, a platform could simply give one large media group a huge check, completing the workaround, and leaving smaller newsrooms with nothing. Funds spent with large publishers count towards 150% of a platform’s bill, while spending with small and medium-sized news outlets counts towards 200%. The law also stated the deals must fund news production or the online distribution of publisher content. Legislation funds Australian news organizations The Australian government believes publisher content drives the ad sales and all forms of engagement these tech platforms benefit from, so a share of the money belongs with the newsrooms. The legislattion extends the News Media Bargaining Code introduced in 2021, which Australia intended to use in pushing platforms toward direct negotiations with publishers. Parliament passed the new measure a day after clearing separate laws that restrict gambling advertising. “This is an important day for Australian news businesses and Australian journalism,” the government said in a statement. AI angle important to publishers Some platforms have already started paying for journalism to feed AI systems. Google has said it would work with the Associated Press to source quality information through its Gemini service, and OpenAI struck a deal with Axios to fund 13 new local newsletters, staff and technology included. AI answer engines are now summarising the news readers used to click through to read in entirety, and publishers now also want the value of their reporting recognised in cash, not just in citations. If you're reading this, you’re already ahead. Stay there with our newsletter.
Peter Schiff calls Bitcoin's climb above $72K a fakeout as bulls dig in
Peter Schiff, a longtime Bitcoin critic, said on Thursday that BTC’s rise to above $72,000 is a false breakout built on a one-off Treasury move. Bullish analysts, on the other hand, regard the same week’s data as the start of a fresh cycle for Bitcoin. Will Bitcoin continue rising? Bitcoin traded around $71,447 on Thursday, up about 9% over 24 hours. The price reached a high of around $72,397 during the day, according to CoinMarketCap, its highest since May 31. Peter Schiff, who has long been critical of BTC, told his followers to “Sell Bitcoin” and instead buy gold, arguing that the recent rally is due to a surprise announcement from the U.S. Treasury. The U.S. Treasury announced that it would double its long-term bond buybacks. The limit for each operation was raised from $2 billion to at least $4 billion, causing the 30-year bond yield to drop from over 5.34%, which was its highest in 19 years, to about 5.196%. In a follow-up post, Schiff said Treasury yields have already started climbing again and that the buyback announced so far is too small to change that. Stopping the trend, he argued, would take a much larger buyback plus an official quantitative easing program from the Federal Reserve. “Got gold?” he added, reinforcing his view that any weakening of the dollar helps gold more durably than it helps Bitcoin. In early October 2025, Schiff declared that Bitcoin was in a bear market. Are the bulls right about BTC? Ki Young Ju of CryptoQuant pointed out that Bitcoin demand has turned positive across both spot and perpetual futures for the first time since the October 2025 all-time high. He said that if the pattern holds for another month, it would be fair to conclude a new bull cycle has begun. Adam Back is even more optimistic, saying he believes BTC can hit $1 million. He sees that price as the point where Bitcoin’s total value would match gold’s. Back plans to explain his reasoning in person at the Bitcoin Treasuries Conference on September 28. Institutional flows also support the bulls for now. U.S.-listed spot Bitcoin ETFs pulled in more than $1 billion between Monday and Wednesday, a complete reversal from $389.7 million in outflows the prior week. BTC whales have added roughly $2.75 billion worth of the token over 60 days. BTC ETFs have posted three consecutive inflow days. Source: SoSoValue. Investor confidence also got a boost after President Donald Trump met with executives from Coinbase (NASDAQ: COIN), Payward, and Blockchain.com. The meeting raised hopes that the stalled Clarity Act might move forward again. The Senate is expected to discuss it again in mid-September. Data from Deribit showed that traders had $1.5 billion worth of BTC call options at the $70,000 price level. They also had $1.4 billion in put options at the $60,000 level. Bitcoin’s highest price was above $126,000 last October. After that, it dropped sharply, which started the current bear market. Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
Alibaba reports 9% rise in quarterly revenue, shares fall 6%
Alibaba grew its revenue 9% last quarter but shares still fell 6% after profit dropped 76% due to a surge in AI spending, the company reported Thursday. Revenue for the quarter ending June 30 reached 268.95 billion yuan ($39.64 billion), up 9% from a year earlier. Net income fell to 10.54 billion yuan ($1.55 billion), equaling a 76% decline. Non-GAAP net income after removal of share-based pay, investment swings and one-off items still dropped 38% to 20.72 billion yuan ($3.05 billion), while adjusted EBITA fell 30% to 27.33 billion yuan ($4.03 billion). Capital spending jumped 75% to feed AI interests Alibaba’s capital expenditures for Q2 hit 67.68 billion yuan ($9.98 billion), a 75% jump from the same period a year earlier, money the company tied to AI infrastructure. The expenditure drained cash, as free cash flow swung to an outflow of 44.67 billion yuan ($6.58 billion), more than double the 18.82 billion yuan outflow a year earlier. The unit housing Alibaba’s model work, its Qwen consumer app and the QwenWork enterprise agent, its AI Labs and Applications segment, ran an adjusted EBITA loss of 13.86 billion yuan ($2.04 billion). This loss was only 3.22 billion yuan one year ago. Alibaba blamed the higher numbers on higher inference costs from the Qwen app and deeper investment in its AI stack. Cloud carried the quarter The AI Cloud and Compute Services segment lifted revenue by 45% to 48.44 billion yuan ($7.14 billion). Alibaba credited this to an increased adoption of its AI products. Revenue from AI-related products specifically came in at 12.38 billion yuan ($1.82 billion), a 12th straight quarter of triple digit growth over a one year span. Unlike the AI applications unit, cloud brought in significant revenue. Its adjusted EBITA rose 133% to 5.63 billion yuan ($830 million). “We delivered a strong quarter, driven by the improving commercialization of our full-stack AI capabilities,” Chief Executive Officer Eddie Wu said in a statement. E-commerce divergence amid $100 billion target Alibaba’s retail engine split in two different directions, with the China Quick Commerce revenue climbing 45% to 53.30 billion yuan, while the larger China E-commerce business slipped 8% to 110.90 billion yuan. Its 88VIP membership tier grew by double digits to about 64 million members as of June 30. Three months earlier Alibaba posted adjusted net income of just 86 million yuan and its first operating loss since 2021, all caused by the same AI and quick-commerce bills. The company has told investors it aims to reach $100 billion in combined annual revenue from cloud and AI within five years. The scale of the spending in the just completed quarter shows what this target will cost before it is achieved. If you're reading this, you’re already ahead. Stay there with our newsletter.
Japan exports soar 23% as China shipments surge and AI demand fuels growth
Japan’s exports climbed 23.2% in July compared with the same month last year, with stronger semiconductor equipment sales and much heavier trade with China doing most of the lifting. That was the quickest annual export gain since October 2022. It also meant export growth sped up for a fifth straight month. Economists had been looking for a smaller 19.9% rise. Chipmaking equipment was a major reason the total came in so high. Japan shipped 49.1% more semiconductor machinery by value than a year earlier as companies continued pouring money into hardware for artificial intelligence. China was also buying much more from Japan in July compared to last year. Imports from Japan into China grew by 25.8% whereas exports to America were up 22%. China remains Japan’s top trading partner. Still, the growth in income derived from exports was significantly higher than growth in volume of shipments. The volume of exports grew by only 5.2%. Price increases and weak currency helped increase the export value. A weak currency also makes it easier for Japanese producers to offer lower prices to their clients in foreign countries. However, there is a trade-off. The country now requires more of its national currency to buy imports. AI demand lifts Japan’s chip exports while the weak yen makes imported goods more expensive Markets responded once the July trade numbers came out during the session. The Nikkei 225 rose 0.64%, while the yen slipped 0.11% against the dollar and traded at 158.35. Japan’s currency has weakened sharply over the last year. At roughly the same point a year ago, one dollar was worth around 145 yen. Lately, the dollar has been close to 160 yen. After Monday’s economic data was published, it was changing hands at about 159 yen. Japan also paid much more for goods coming into the country. Imports increased 27.8% in July from the previous year, the biggest annual rise since November 2022. Analysts had predicted a 26.5% increase, leaving the actual figure above expectations. Oil played a big part in the higher import total. Japan’s petroleum import bill jumped 87.8% as crude became more expensive during the Iran war. Businesses and households have had to deal with higher energy costs as a result. The second quarter was the first full three-month stretch to capture the economic impact of the Iran war. Energy remained costly through that period, adding to household and business expenses while domestic spending was already losing steam. Exports keep Japan’s economy growing while weak domestic spending limits second-quarter GDP The economy of Japan recorded an annualized growth rate of 1.1% in the second quarter. This is below economists’ estimate of 2%. The economy of Japan also grew at a 2.1% annualized rate in the quarter preceding the second quarter. This growth rate was below economists’ expectations. The growth rate between the quarter under review and the previous quarter was just 0.3%. This is below economists’ estimate of 0.5%. The strongest contribution to GDP came from exports. Foreign trade contributed by 0.5 percentage points to GDP in the second quarter. Domestic demand on the other hand reduced growth by 0.2 percentage points. A year ago, Japan’s economy grew 0.7%, up from the 0.5% annual growth recorded during the first quarter. The Bank of Japan also revised its forecast earlier this month when it released its latest outlook for economic activity. The central bank now sees growth of 0.6% for the 2026 fiscal year ending in March 2027, compared with its previous estimate of 0.5%. Japanese Prime Minister Sanae Takaichi has expressed her intention to return growth to the right track. Nevertheless, at present, approval ratings for Sanae are higher than for some other prime ministers in Japan, although those ratings have been gradually decreasing. If you're reading this, you’re already ahead. Stay there with our newsletter.
Robots set for ChatGPT moment in 10 years, says Unitree CEO
Humanoid robots could hit a “ChatGPT moment” within two to three years under ideal conditions, and five to ten if progress stalls, Unitree founder Wang Xingxing stated at the World Robot Conference in Beijing on Thursday. His statements come just one day after his company’s Shanghai listing saw the stock surge more than 460% before it dipped. Unitree CEO describes tipping point Wang mentioned his targets for the industry’s ambitions, stating he wants a robot that can walk into a home or workplace it has never seen and finish about 80% of tasks using only spoken or typed instructions. He described the same benchmark as about 80% of tasks across 80% of unfamiliar settings, and called it “an important tipping point for the robot industry to usher in explosive growth.” When OpenAI’s chatbot launched in late 2022, it moved LLMs from being just a lab novelty to a product that was marketed en-masse in a matter of weeks. Models that let machines read and navigate physical space have had nothing of such, and the Unitree CEO believes the robot industry is still waiting for its own version of that leap. Wang also candidly noted the reasons why robots break, explaining that robots trained for a while in a fixed room can get close to a perfect success rate, but they fail the moment an object is swapped or the space they are in change. He claimed the drawback remained the gap between digital models and physical hardware. Wang said that residual error was the biggest bottleneck facing AI embodied in physical robots anywhere, and claimed decision-making models were the industry’s central weakness. He also conceded that Unitree was still quite behind at putting physical AI to real-world use, even though world models take the company’s largest share of capital and staff. Cautious message after Shanghai stock surge Unitree became the first humanoid maker to list on China’s A-share market on Wednesday, and its shares closed the day at 460.34% above the 150.80 yuan offer price, valuing the Hangzhou company at 340 billion yuan, or about $50.42 billion. The stock then fell sharply on Thursday. “Relative to the mood around World Robot Conference and Unitree’s spectacular IPO, Wang Xingxing was notably sober about current capabilities,” Georg Stieler, who heads automation at consultancy Stieler, told Technology.org. However, everyone in the field is not as measured on timing as the Unitree CEO. Wang He, founder of the startup Galbot, expects the sector to reach its ChatGPT moment by 2028, defining it as robots handling 70% to 80% of everyday tasks without special training. Unitree’s prospectus shows that most of its buyers are still universities and research institutions and not factories, with the company shipping more than 5,500 humanoid robots in 2025. China continues to fund humanoid robots China delivered over 40,000 units in the first half of this year and accounted for 97% of global shipments, according to a Chinese industry body report cited by Technology.org. A shrinking workforce makes machines appealing for repetitive and dangerous jobs even if they are not as efficient as human workers. A State Council research center has projected the physical AI market at 400 billion yuan by 2030 and above one trillion yuan by 2035. Beijing’s economic planners have, however, told manufacturers to stop flooding the market with near-identical designs, while the U.S. Federal Communications Commission banned future imports of foreign-made humanoid and quadruped robots on national security grounds last month. Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
Canadian rocket startups race to close the country's G7 launch gap
Canada has seen a growing contingent of homegrown startups step up after the government in Ottawa smartened up to its untenable position as one of the only G7 nations that cannot send a satellite into orbit without extensive help from beyond its shores. With deteriorating United States relations escalating the urgency of the situation, the Canadian government has funneled cash into incentivizing the growth of its local space industry. SpaceX’s (NASDAQ: SPCX) decision not to take any Falcon 9 bookings past 2028 has now sweetened the pot. Canada is pouring cash into space push Canada Rocket Company, NordSpace and Reaction Dynamics are three of the standout beneficiaries of the CAD $305 million the Canadian government committed under its federal Launch the North program. Each of them has received a first installment of CAD $8.3 million in May 2026. Other than funding for startups, infrastructure is also going up, with $200 million in federal investment going to a Canada-owned spaceport announced in March. The results are already showing up too. NordSpace framed the orbital-class engine it unveiled on August 19 as Canada’s largest steps yet toward sovereign launch. Down the coast, Maritime Launch ran a successful hypersonic suborbital test from Canso, Nova Scotia, on June 10, according to the Centre for International Governance Innovation, which reported that both Maritime Launch and NordSpace expect to reach orbital flight within roughly a year. Which G7 nations can’t send rockets into space? Canada is the only G7 nation that still cannot launch rockets into space without outside help from the United States on most occasions, even though the country has actually reached the Moon. However, on April 21, 2026, Transport Minister Steven MacKinnon introduced the Canadian Space Launch Act, a bill that sets the parameters for rockets to launch and re-enter the Canadian airspace. The plan, if it works, will lay the blocks for a commercial launch industry that Canada believes could be worth as much as $40 billion. Reaching those estimates could be helped by the trickle-down effects of decisions at Elon Musk’s SpaceX that could have customers competing for rides to orbit with booming satellite launch demand. Canada Rocket Company co-founder and CEO Hugh Kolias is bracing for a “space super cycle” that could see around 100,000 satellites orbiting Earth by 2030, up from the current 18,000. Kolias’ Toronto-based firm is building its R-2, a reusable medium-lift rocket, to get ahead of the SpaceX 2028 Falcon 9 cutoff date. Available specifications confirm the seven methane-and-oxygen engines on the rocket have enough thrust to carry about 12,500 kilograms. Canada Rocket Company has raised $22.5 million, mostly from Canadian investors, including the Business Development Bank of Canada. The firm has also brought back nine Canadians from SpaceX, Blue Origin and Europe’s ArianeGroup, growing to 25 staff in July from two in January. The early signals are bullish, but the enormity of the task cannot be overemphasized. As Kolias mentioned, a medium-lift rocket could routinely take between eight and ten years, with 300 to 500 engineers and technicians working on a budget of at least US$500 million. The smartest crypto minds already read our newsletter. Want in? Join them.
Privacy blockchain Beldex raises $8M to build encryption tools for AI agents
Beldex, a privacy-focused blockchain infrastructure company, has raised $8 million in a new funding round, bringing its total capital raised to $36 million. The company is working on encryption tools aimed at artificial intelligence agents alongside its existing suite of privacy products. The round was led by Sigma Capital, with participation from NTC, Nxgen, Digital Consensus Fund and EAK Ventures. It follows two earlier rounds from DWF Labs and Block Alpha that brought in a combined $28 million in 2023. Vineet Budki, managing director and CEO at Sigma Capital, said the firm was drawn to Beldex’s history in the space. “What stood out to me about Beldex is its long-term conviction,” he said. Budki said that they believe that Beldex is well positioned for the next era of Web3, which, according to him, demands privacy, an area that the company spent years building into its infrastructure. What will the new funding build? Beldex is working on an infrastructure layer that will allow developers to build shielded smart contracts and encrypted identities for AI agents without sacrificing performance and usability. It said that the raised capital will be deployed in that direction. The company also said the funds will help fast-track its research into fully homomorphic encryption, which is a method of processing encrypted data without ever decrypting it. This also includes achieving the roadmap that it set for quantum-resistant consensus mechanisms and an EVM-compatible sidechain built to handle sensitive data. Beldex also stated that it will deploy a browser extension wallet and a set of software development kits that is designed to lower the technical barrier for developers who want to add encryption to their applications. In a company statement, Alex Mok Kong Ming, Beldex’s chief operating officer, said, “Over the past three years, Beldex has evolved from building a functional privacy ecosystem to developing a privacy infrastructure for consumers, developers and AI agents where transactions, communications, and operations are required to be autonomous and private.” Kong Ming said that the $8 million raise gives them the resources to accelerate their vision. According to him, data exposure will become a fundamental risk as AI becomes more autonomous, stating that they are “building Beldex to address that challenge at the infrastructure level.” Why are investors betting on privacy now? Privacy-oriented digital assets outperformed every other sector in the crypto market in the final quarter of 2025, according to a Grayscale report. Grayscale has also made significant investments in the privacy-focused blockchain Zcash’s ZEC token. It is behind the Grayscale Zcash Trust, which is an investment vehicle that gives investors exposure to the ZEC token. Grayscale is working on making it an approved spot ETF that would trade on NYSE Arca. Venture investors, including a16z Crypto, have described privacy infrastructure as central to crypto’s next stage of growth. At the same time, security researchers have documented a rise in incidents tied to autonomous AI agents. Research published by the Cloud Security Alliance and Token Security in April found that 65% of organizations experienced at least one security incident that was linked to an AI agent in the past year, with sensitive data exposure the most common cause. Encryption methods like zero-knowledge proofs and fully homomorphic encryption are moving from research into production, given the threats that are about to become mainstream in the market. How does this round fit into Beldex’s track record? Beldex already runs a set of privacy products, including BChat, an encrypted messaging app; BelNet, a decentralized routing network; and the Beldex Browser, built for private web access. The network also operates BNS, a naming system for blockchain-based addresses, and secures its ledger through a masternode network using a proof of stake consensus model. Afanddy Bin Hushni, the company’s chairman, said the new capital would let Beldex build privacy into products from the outset. Husni said, “With this new $8 million capital raise, we’re finally able to start creating, building the vessel from the ground up to ensure that every byte of data, whether that’s an AI agent’s entire decision tree or a simple message, is encrypted by default before it ever hits the network.” The company also plans to build bridges connecting its network to Ethereum, Solana, and Base as part of an effort to keep data private as it moves across different blockchains.