₿ BTC Loading... via Binance
Showing posts with label Bitcoin 101. Show all posts
Showing posts with label Bitcoin 101. Show all posts

Tuesday, August 11, 2026

The Inflation Hedge Argument for Bitcoin Has a 2022 Problem

BitBrainers - Is Bitcoin Actually an Inflation Hedge

BTC/USD vs US CPI YoY (USIRYY), monthly. BitBrainers via TradingView, Aug 2026.

By BitBrainers Editorial

Every Bitcoin pitch eventually arrives at the same line: it's a hedge against inflation. Fixed supply, no central bank, 21 million cap. The argument borrows gold's playbook and assumes the same rules apply. The chart above is worth staring at before accepting that framing.

The Part of the Argument That Is Actually True

The structural case for Bitcoin as a long-run store of value is real. The 21 million cap is not a marketing claim. It is enforced at the protocol level, and no government decision changes it. Every major fiat currency in history has been expanded by whoever controls the printing mechanism. Bitcoin cannot be..

Investors who bought in 2017 and held through 2021 saw returns that made CPI irrelevant as a comparison. The scarcity argument held up over that window. The problem comes when the word "hedge" gets attached to it. A hedge implies a specific mechanical relationship: when the thing you're hedging against rises, the hedge rises with it.

Bitcoin has not reliably done that. It did the opposite in the one period where the test actually mattered.


What Happened in 2022

US CPI peaked at 9.1% in June 2022, the highest reading since 1981. Bitcoin that month was trading below $20,000, down roughly 70% from its November 2021 high. The blue line in the chart above rises steadily through 2022. The candles collapse.

Gold fell too during 2022, though far less dramatically, and it recovered faster. The assets that genuinely performed as inflation hedges in that environment were energy, agricultural commodities, and real assets with direct pricing power tied to what was actually causing the inflation. Bitcoin was not in that category.

It fell because it had been trading as a risk asset. During the 2022 rate hiking cycle, Bitcoin's 90-day rolling correlation with the S&P 500 consistently ran above 0.65, peaking above 0.75 in mid-2022 per Bloomberg data. Gold's equity correlation over the same period stayed near zero. That single data point dismantles the "digital gold" comparison at the mechanism level, not just the surface level.

I have watched the same retail client make the inflation hedge argument in 2021, size up at $60,000, and get liquidated at $16,000 in 2022. The narrative did not change. The price did.

When the Fed started hiking and liquidity tightened, Bitcoin dropped alongside Nasdaq growth stocks. Not alongside gold. Not in the direction an inflation hedge should move.

The pattern has not shifted meaningfully since. In May 2026, CPI printed 4.2% year-on-year, the highest reading since April 2023. Bitcoin dipped roughly 2% on the release, from $62,800 to $61,500, then recovered to flat within hours. That is not a hedge behavior, thats a risk asset behavior.


Why Liquidity Drives It, Not Inflation

The 2020-2021 period is worth acknowledging here, because the narrative looked convincing then. The Fed expanded its balance sheet, rates went to zero, and Bitcoin went from $10,000 to $69,000. Inflation was rising through 2021. Bitcoin was rising. The two moved together and the "hedge" framing felt validated.

It was not inflation driving Bitcoin. It was liquidity. The Fed flooded the system with capital, that capital chased risk assets, and Bitcoin was at the top of that trade. CPI happened to be rising at the same time. The correlation was coincidental, not causal.

When the Fed reversed in 2022, the distinction became obvious. Inflation kept rising for months after the hikes started. Bitcoin stopped rising the moment liquidity conditions tightened. It was responding to the Feds balance sheet, not to CPI.

This is why global M2 money supply tracks Bitcoin's price far better than CPI does. M2 measures liquidity availability directly. Bitcoin historically lags global M2 expansion by roughly 10 to 12 weeks, which means the signal is readable in advance if you know where to look. The full breakdown of that lag and how to use it is in Bitcoin Follows M2 With a Lag Nobody Talks About.


Macro reads without the pitch

Weekly Bitcoin and macro analysis. Free. No price targets dressed up as research.

Subscribe

So What Does the Long-Run Case Actually Rest On?

Pull the short-term correlation out of the argument and a more defensible version survives. Bitcoin may be a hedge against currency debasement over decade-long horizons. That is not the same claim as hedging CPI.

Currency debasement is the structural erosion of purchasing power through sustained monetary expansion across multiple cycles. CPI is a quarterly snapshot of a basket of goods. The two are related but they diverge constantly over months and years. A fixed-supply asset plausibly protects against the first. It has not reliably protected against the second.

Most investors making the "inflation hedge" argument are thinking in one to two year windows. On that timeframe, Bitcoin has failed the test repeatedly, Gold has not. Gold does not need favorable liquidity conditions to function as a store of value. At this stage in its maturity, Bitcoin still does.


Two Things That Would Have to Change

For Bitcoin to function as a short-to-medium term inflation hedge, two conditions would need to shift.

Its equity correlation would need to break down structurally, which would require a holder base dominated by sovereign and institutional allocators treating it as a reserve asset rather than a speculative position. Spot ETF flows are moving in that direction, but the correlation data has not changed materially yet.

Its market depth would need to reach a scale where a central bank could buy meaningful quantities during an inflationary crisis without moving the price by double digits in a week. That depth does not exist at the size that matters for national reserve management.

Neither condition is impossible. Both are a long way off. Spot ETFs help, but $56 billions in cumulative inflows has not yet moved the correlation needle. Sovereign buyers are not showing up in the data.


Where That Leaves It

Bitcoin is a bet on global liquidity expansion, institutional adoption, and a fixed-supply design that may matter more in twenty years than it does today. That is a defensible position. It might even be a good one.

It is not a shortrun inflation hedge. The 2022 data makes that clear, and the chart at the top of this post shows it without requiring any argument at all.

The 21 million cap is a real property of the protocol. The inflation hedge label is a sales narrative built on top of it. Telling the difference is the first step toward writing something useful instead of something that sells. Most of the inflation hedge content online is the second kind.

Sources

Federal Reserve Bank of St. Louis: US Consumer Price Index, All Urban Consumers

Bureau of Labour Statistics via TradingView: USIRYY, United States Inflation Rate YoY

CoinGecko: Bitcoin historical price data

World Gold Council: Relevance of Gold as a Strategic Asset

This is market commentary, not financial advice. Nothing here is a recommendation to buy or sell any asset. Do your own research.

Sunday, August 9, 2026

BIP-110 Split From Bitcoin, Then Its Only Miner Quit

BitBrainers - BIP-110 chain split node comparison

The BIP-110 chain split off from Bitcoin at block 961,632 and stalled at 961,633 after its only miner stopped. The main chain kept building normally, reaching 961,721 by publish. Data: mempool.space.

By BitBrainers Editorial

Bitcoin split into two chains over the weekend. This one was not a surprise. BIP-110 hit its mandatory signaling deadline at block 961,632 on Saturday, and the numbers behind it had been telling the same story since March.

How The Split Actually Happened

BIP-110 is a one-year restriction on storing non-financial data, mainly Ordinals inscriptions, inside Bitcoin transactions. Supporters wanted it locked in through voluntary miner signaling. When that never reached the 55% threshold, the proposal's own rules forced a mandatory signaling period instead.

That period started August 7 at block 961,632. Nodes running BIP-110 software began rejecting any block that didn't signal support. Every other node kept validating normally, which is how you end up with two chains sharing one history up to a single block.

Support going into the deadline was thin: 2.53% of blocks signaled in the final two-week window, and the average since May sat closer to 0.42%. Ocean Pool provided most of what little signaling existed. We flagged this exact gap back in July, when support was still parked near zero.

The split didn't need majority support to trigger, only to lock in cleanly. Miners who reject non-signaling blocks simply start building their own chain the moment the deadline passes. Bitcoin Knots is the software behind that decision.

At block 961,632, AntPool mined the version the main network followed. Roughnecks, mining through Ocean, produced the signaling alternative that BIP-110 nodes accepted instead.

Ocean's own hashrate didn't move as one bloc, though. Its DATUM system lets individual miners set their own block templates, including whether to flip the BIP-110 signal. Simple Mining, which routes through Ocean, mined the very next block on the main chain instead. Even inside BIP-110's biggest backer, support was split.

The gap kept opening. By early Sunday afternoon the main chain had reached block 961,721 while the BIP-110 chain sat frozen at 961,633, the last block Roughnecks mined before it stopped. Eighty-eight blocks is several days of normal production on one side and nothing on the other.

Bitcoin has done this before without a split. Taproot activated at block 709,632 in November 2021 after building broad miner support first, and it never produced a persistent minority chain. BIP-110 entered its mandatory phase with a fraction of that support behind it, so the outcome here was closer to a default than a surprise.

Chain Splits Don't Wait For You To Catch Up

Get the mechanism explained before the headlines catch up. Free, straight to your inbox.

Subscribe

What This Means For Your Coins

Exchanges and ETF holders are not exposed to any of this. The people who need to pay attention are self-custody users running full nodes, especially anyone who updated to Bitcoin Knots to signal support. Replay protection is not automatic between the two chains, so moving coins carelessly during the split window can expose funds on both sides at once.

If you hold your own keys through a hardware wallet like Trezor, the fix is simple. Don't move anything until your node software and wallet firmware agree on which chain you're actually on.

Who's Saying What

Reaction split along predictable lines. Blockstream's Adam Back, who'd argued for months that a breakaway chain was the likely endgame, called the outcome settled and urged BIP-110 supporters back into the main ecosystem.

Strategy's Michael Saylor brought the clearest numbers: about 99.85% of Bitcoin's hashpower on the main chain, the minority branch stuck at two blocks and already more than 80 behind, figures that line up closely with what's above.

He followed with the math that matters. At roughly 0.15% of network hashpower, the minority chain needs 2,015 more blocks to reach its first difficulty adjustment, which at the current pace works out to about 25 years. His framing was blunt: "Consensus is earned, not declared."

There's a wrinkle if you mine through Ocean specifically. The pool switched its default endpoint to signal for BIP-110 on July 15, so anyone pointed at Ocean who never opted into the non-signaling endpoint has been mining the minority chain without realizing it. Developer Peter Todd flagged this over the weekend, estimating roughly $43,000 a day in hashpower value going to blocks the main network will never recognize.

The question of whether the minority chain would keep going got answered fast. Roughnecks, the pool behind both of its blocks, posted early Sunday that it was stopping mining under its own name after an internal team meeting around 3:40am UTC.

The post called it an escalation rather than a retreat and told anyone still mining BIP-110 blocks to stand down for now. Either way, the chain that split off at 961,632 no longer has an active miner behind it.


What Actually Got Resolved Here

Not much, honestly. The mandatory signaling period settled a governance mechanism, not the underlying argument. Whether non-financial data belongs in Bitcoin blocks is the same fight it was in March, and Ordinals volume has already been falling on its own for unrelated reasons.

The other side of this fight didn't need a fork at all. Ordinals advocate Leonidas proposed a client called DOG Mode in July that changes nothing about consensus rules. It just raises the transaction size Bitcoin Core will relay and drops the dust limit to one satoshi, making Ordinals and Runes cheaper to broadcast. DOG Mode needs one willing miner, not 55% of the network, which is the exact asymmetry BIP-110 just ran headfirst into.

With Roughnecks gone, the minority chain isn't fading out gradually so much as it just stopped. A chain with zero active miners doesn't creep toward its next difficulty adjustment. It sits frozen at whatever block it last reached, waiting for someone to pick the work back up.

The real story is what BIP-110 proved about changing Bitcoin's rules going forward. Getting 55% of hashrate to agree on anything in 2026 is a different bar than it was during Taproot, and the next controversial proposal will be measured against this exact outcome.


Sources

CoinDesk: Controversial Bitcoin fork BIP-110 mines two blocks, then stops

The Block: Bitcoin's BIP-110 supporters split onto minority chain as main network pulls ahead

KuCoin: Bitcoin BIP-110 Fork Fails as Mainnet Outpaces Minority Chain by 26 Blocks

ForkLog: Bitcoin network splits over BIP-110 soft fork

Binance Square (via Odaily): Roughnecks Stops Mining Operations Under BIP-110 Protocol

This is market commentary, not financial advice. Nothing here is a recommendation to buy or sell any asset. Do your own research.

Sunday, August 2, 2026

Nobody Has a Safe Place to Put It: What Coldcard Actually Proved

BitBrainers - Nobody Has a Safe Place to Put It: What Coldcard Actually Proved

By BitBrainers Editorial

Coinkite shipped the code that lost other people's money, and nothing in what follows takes that off them. But the same category of failure has already hit the other side of the argument, the exchanges, and it hit harder. Blaming one company is correct and it is not sufficient. There is no side of this that is actually safe. Only different ways to lose.

The Number That Should Have Been the Headline

In the first half of 2026 the crypto sector recorded a record number of hacks, 207 by TRM Labs' count, most of them smart contract exploits. But the money did not follow the count. Infrastructure and key-management failures were about 15 percent of incidents and roughly 76 percent of the money stolen.

Coldcard sits in the second group, and so does every exchange breach in that same data. The exposure begins at the exact place the industry keeps losing the most money, which is how a key gets made and who holds it. That is not an obscure corner of the product. For a device whose entire purpose is generating and protecting a key, it is the product. For a custodian, it is the whole job.

We do not sell a safe answer here.

We read the failures honestly and tell you what they actually mean. That is the whole newsletter.

Subscribe

Why This Keeps Happening to Regular People

The people who lost coins on Coldcard were not careless. Many followed the exact advice the most respected names in Bitcoin were giving. The device sat on recommended-wallet lists for years. Trusting the consensus pick is not negligence.


This Was Coinkite's Failure, Start to Finish

The firmware was theirs. The change that routed seed generation away from the hardware random number generator, the device's only source of real entropy, and into a predictable software fallback went out in March 2021 under their name, in a product sold on the single promise that it would generate a key no one could guess. CEO Rodolfo Novak has said the company takes full accountability and that its review process failed to catch it. That much is not in dispute.

The context deserves more attention than it is getting. Coldcard was GPL-licensed until a competitor, Foundation, built a device on that code. Novak said publicly that he regretted the license. Coinkite moved to MIT plus Commons Clause, blocking competing derivatives, and stripped out the crypto libraries inherited from Trezor. Foundation has published a timeline showing the entropy bug entered in the same 120-file commit that removed those GPL dependencies. Foundation is a competitor with an obvious interest in that framing, but the commits are public and the dates line up.

The licensing choice has a second cost that nobody priced at the time. Source-available is not open source. Under the Commons Clause, other developers could read the code but could not legally build on it, which quietly thins out the population of people with any reason to read it closely. Five years is a long time for a seed generation routine to go unexamined in a Bitcoin product, and the license is part of why.

Then there is the response. Coinkite's first advisory on July 30 told Mk4, Q and Mk5 owners they were not affected. That was wrong, and the advisory had to be expanded the next day. In the interval, an attack was actively running and people with newer devices were reading an official statement telling them to stand down. One prominent developer publicly told Novak he had spread misinformation and said someone he knew personally had been robbed from a Mk4 seed within hours of that advisory. Samson Mow ended up telling people to migrate off every Coldcard model regardless of version, because the vendor's own guidance could no longer be relied on.

One more detail worth noting, because the week's commentary got it backwards. Coinkite's minimal data retention was treated as the reason it could not warn its own customers. In fact the company has now said it emailed every address it could reach through its store and newsletter systems, and its own store notice explains that Canadian law requires eight years of business records, so names and addresses were blanked while the email field was kept. Reaching customers during an active theft is the right call. It also means the privacy posture that was part of the pitch was never quite what buyers understood it to be.

Novak's other public framing was that the bug was likely found using AI, calling it a sober reality of the new paradigm. Read plainly, that is a company whose code lost roughly $88 million pointing at the tool that found the flaw rather than at the five years in which it did not find it itself. We covered that response in detail in our breakdown of Coinkite's statement.

The deeper issue is that the security model was never built for a normal person. Entropy bits, firmware version tracking, BIP-39 passphrases, multisig quorums, dice rolls to seed your own randomness. That is a specialist's checklist wearing consumer packaging, and most people bought the packaging.


It Is Not Over, and That Is the Point

The first wave was a clean $70 million sweep in 41 minutes. By August 2, Galaxy Research was tracking three waves totalling 1,367 BTC, roughly $88.6 million, across 4,585 addresses. The number has moved every day since the story broke, and it will likely move again after this is published.

Watch the direction of travel. The first wave went after the largest balances, pulling $30 million in ten minutes. The third is emptying wallets worth a few thousand dollars each. That progression only makes sense if the operator holds a long list of compromised seeds and is working down it by value, monetising the tail after the whales are gone.

The third wave also broke the fingerprint. The first two shared a hardcoded fee and identical batching, which is how researchers linked them. The third uses more complex, harder-to-trace patterns, and Galaxy says it cannot confirm the same operator is behind all three. Either the attacker is adapting, or others have worked out the same flaw independently. Neither is reassuring.

The reason this keeps going is structural. Coinkite's emergency firmware cannot repair a seed that was already generated. Every vulnerable seed still holding funds stays vulnerable until its owner moves the coins, and Galaxy has warned that future sweeps need not resemble the ones already mapped. This is not an incident that concluded. It is an exposure that stays open until every affected person acts, and most of them do not know they are affected.


So What Does a Normal Person Actually Do

Watch what has happened on the timelines since. Within two days, people who had just seen a consensus recommendation fail were issuing new consensus recommendations. Name a replacement device, argue that the answer is firms large enough to employ cryptographers, move on. Almost none of it comes with more verification than the advice that put Coldcard on every recommended-wallet list to begin with.

That is the mechanism, and it is running again right now. The problem was never that people picked the wrong brand. It was that a brand recommendation was ever load-bearing for something this consequential.

So the honest answer is that there is no zero-risk option, and anyone selling you one is selling something. What exists is a set of trade-offs you get to choose between with open eyes.

Self-custody removes the counterparty who can freeze or lose your funds, and hands you the entire job of key security, firmware, and backups. An exchange removes the technical burden, and reintroduces the counterparty, the honeypot, and the interface you cannot see behind. Both are real risks. Neither is theoretical.

The most defensible posture is not picking a winner. It is refusing to concentrate. Do not put everything on one device, one vendor's firmware, one exchange, or one signing method. Spreading holdings across independent failure modes will not stop a loss. It stops a single loss from being total.

For anyone rebuilding after this, the concrete version is keys split across manufacturers, a Trezor hardware wallet beside a different vendor in a multisig quorum. Not because that vendor is trustworthy. Because no single vendor has to be.


Why This Does Not End With Everyone in Custodians

Follow the argument to its usual conclusion and you get: most people cannot do this safely, so most people should hand their coins to someone who can. A lot of this week's commentary lands exactly there, and the ETF and treasury-company flows suggest the market already agrees.

The objection is concentration. Enough Bitcoin in a few custodians rebuilds the seizure risk the thing was built to route around. What stops that from being terminal is a property gold never had. You can leave. Any holder can open a wallet, demand settlement, and have final possession in minutes, globally, for a few dollars. Most gold was never in its owner's hands, and you could not demand it be moved from London to Singapore this afternoon.

So custody concentrates only as long as the custodians stay worth using. The exit is what keeps them honest, and the exit only exists because self-custody remains possible for anyone who wants it. That is the case for keeping these skills alive even in a week that made them look dangerous.


The Part Nobody Wants Printed

Here is the sentence the industry avoids. In its current form, self-custody asks for a level of technical fluency that most people holding Bitcoin do not have and should not be expected to acquire overnight.

Read the failures, spread the risk, and distrust anyone who tells you one product ends the problem. That is not a satisfying conclusion. It is the accurate one, and the accurate one is the only kind worth publishing.


TRM LabsH1 2026 Crypto Hacks Reach Record High as Losses Fall Below $1 Billion

Crypto BriefingCrypto Records Most Hacked Half-Year Ever With 212 Exploits and $1.1 Billion Stolen

CoinDeskHow Bitcoin Cold Wallets Lost $70 Million in an Attack That Never Touched the Devices

CoinDeskBitcoin Cold-Wallet Attack Spreads to 4,500 Addresses as Losses Near $89 Million

The BlockCoinkite Issues Warning for Coldcard Mk3 Users Amid 594 BTC Theft Reports

ForbesUrgent Warning Issued After Sudden Spread Of Massive Bitcoin Attack

This is market commentary, not financial advice. Nothing here is a recommendation to buy or sell any asset. Do your own research.

Saturday, August 1, 2026

Your Hardware Wallet Might Already Be Broken

BitBrainers - Your Hardware Wallet Might Already Be Broken

By BitBrainers Editorial

It is tempting to read the Coldcard drain as a single company's mistake. That reading is too comfortable. In the space of about two months, three separate cryptographic flaws surfaced in crypto code that had all passed review, all of them years old, all found in a narrow window. Coldcard is the loudest one. It is not the only one, and the pattern is the actual story.

Three Failures, Three Layers

Start with the timeline, because the clustering is the point. In late May, security firm Coinspect disclosed a flaw it named Ill Bloom: a broken random number generator in certain mobile software wallets that made recovery phrases guessable. Affected wallets dated back to 2018. At least $5 million was drained, most of it Bitcoin.

Around the same window, Zcash disclosed a flaw of a different kind entirely. Not in a wallet, but inside the mathematical circuit that proves its private transactions are valid. A gap in the proving code that could, in theory, have allowed counterfeit ZEC. Zcash ran an emergency hard fork on July 28 to wall off the affected pool.

Then Coldcard, at the end of July. The same failure family as Ill Bloom, weak seed generation, but in the hardware wallets people had been told to trust precisely because software wallets kept failing. Roughly $70 million gone in 41 minutes.


The Detail That Ties Them Together

Here is the part worth sitting with. When Coinspect disclosed Ill Bloom, it said hardware wallet users appeared to be safe. That was true, for that flaw. It was also the advice that pushed exposed users toward hardware devices.

Weeks later, the hardware devices had their own entropy failure. The safe harbor from one bug was the epicenter of the next. Nobody was lying. The ground simply kept moving.

These were not the same bug or the same team. What they share is a category: old cryptographic code, sitting in production for years, doing something subtly wrong that nobody caught until someone went looking with the right tools.

Patterns matter more than incidents.

We connect the failures nobody else is connecting. Get the next one before it is obvious.

Subscribe

Why Old Code Is Suddenly Dangerous

For years, the industry treated survival as proof of safety. If a wallet or a library ran for five or ten years without incident, it was assumed sound. That assumption was always weaker than it looked.

A vulnerability that was never worth the enormous manual effort to find can become worth finding the moment that effort drops. Reading an unfamiliar codebase line by line, tracing dependencies, spotting one inverted check among thousands, used to take specialist time most attackers would not spend.

Coinkite said it plainly about its own bug: the code had been public since 2021, and the company has to assume someone used AI to review old versions of the firmware and found what human auditors, including a leading AI model Coinkite itself ran weeks earlier, had missed. We covered that admission in detail in our breakdown of Coinkite's response.

The uncomfortable implication is not about one vendor. It is that the cost of finding dormant bugs has fallen for everyone, defenders and attackers alike, and the attackers only need one.


What Is Actually Exposed

Bitcoin Core itself is not the worry here. It is probably the most reviewed open-source code in existence, with hundreds of people picking apart every proposed change. The danger lives in the sprawl around it.

Wallets, firmware, signing libraries, bridges, exchange infrastructure, swap tools. An enormous surface of code, most of it reviewed far less thoroughly than Core, much of it depending on the same handful of underlying libraries. Ill Bloom, Coldcard, and the Zcash circuit flaw all lived in that surrounding layer, not in a base protocol.

That is where the next one will come from too. Not a break in Bitcoin's core math, but a forgotten piece of the ecosystem that held enough money to make the search worthwhile.


What This Changes for You

The takeaway is not to panic or to abandon self-custody. It is to stop treating any single product's track record as a guarantee. Five clean years means the bug was expensive to find, not that it was never there.

The practical response is the same discipline that survives every one of these events: do not concentrate. Spreading holdings across independent devices, vendors, and methods will not prevent a flaw. It stops any one flaw from taking everything.

None of these three incidents touched a properly diversified setup for its full value. That is not luck. It is the one defense that works when the thing you trusted turns out to have been broken since the day you bought it.


The Hacker NewsAttackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets

TechTimesZcash Ironwood Launches Tuesday: Supply-Verification Checkpoint Closes Four-Year Flaw

CoinDeskHow Bitcoin Cold Wallets Lost $70 Million in an Attack That Never Touched the Devices

This is market commentary, not financial advice. Nothing here is a recommendation to buy or sell any asset. Do your own research.

Monday, July 6, 2026

Bitcoin Has a 21 Million Cap. The Claims Against It Don't.

BitBrainers - Bitcoin paper claims explainer

By BitBrainers Editorial

Bitcoin has a hard cap of 21 million coins. That number is enforced by consensus, secured by energy and cryptography, and cannot be changed without the agreement of the entire network. Satoshi built this constraint into the protocol in 2009 and it has held ever since.

What Satoshi did not build is a constraint on the number of claims that can be created against those 21 million coins. That problem belongs to the financial system, not the protocol. And the financial system is already working on it.

What FTX Actually Proved

In November 2022, FTX collapsed and roughly one million users discovered that the Bitcoin in their accounts did not exist. FTX had lent customer funds to its sister trading firm Alameda Research, which had lost them. The accounts showed balances. The coins were gone.

The popular read was "crypto is risky." The more precise read was: an exchange created claims against Bitcoin it did not hold, nobody audited those claims in real time, and users had no way to know the difference between an IOU and an actual coin.

That is the paper Bitcoin problem in its most extreme form. FTX was not an anomaly. It was a demonstration of what happens when the mechanism is left unchecked.

Every Exchange Balance Is an IOU

When you buy Bitcoin on an exchange and leave it in your account, you do not own Bitcoin. You own a contractual claim against the exchange for Bitcoin. The distinction matters enormously.

If the exchange is solvent and honest, the claim is worth exactly one Bitcoin. If the exchange is insolvent, over-leveraged, hacked, or operating fraudulently, the claim is worth whatever a bankruptcy court decides. That is not the same as holding a private key.

Most exchanges hold actual Bitcoin in reserve to back their customer balances. Most is not all. And reserve levels are not publicly verified on a real-time basis for most platforms. You are trusting an audit that may be months old, conducted by a firm with limited access.

ETFs Are Closer to Bitcoin. They Are Still Not Bitcoin.

The spot Bitcoin ETFs that launched in January 2024 are a genuine improvement over exchange IOUs. For several of the largest US funds, the custodian is Coinbase Custody, holding actual Bitcoin on-chain segregated from other assets.

But the custody chain introduces counterparty risk that does not exist with self-custody. The ETF share is a financial instrument, not a coin. The fund can be lent to authorized participants during the creation and redemption process. The holder has no ability to convert shares into actual Bitcoin or verify that the underlying coins are intact without trusting the custodian and the auditor.

For most institutional investors that tradeoff is acceptable. It is worth knowing it exists.

The protocol is sound. The system around it is not automatically.

We cover what the headlines skip. Every Monday, free.

Subscribe Free

Rehypothecation: The Same Bitcoin in Two Places

Bitcoin-backed lending is growing. Institutions borrow against Bitcoin collateral, just as they borrow against securities or real estate. The problem is rehypothecation: using the same collateral to secure multiple obligations simultaneously.

In traditional finance, securities rehypothecation is legal and common. A stock pledged as collateral at a prime broker can be lent out to a short seller, who delivers it to a buyer, who pledges it somewhere else. The original owner still "has" their shares. So does everyone in the chain. More claims than assets.

Bitcoin rehypothecation is less transparent than traditional finance because it is not subject to the same reporting requirements. There is no central registry of which Bitcoin has been pledged where. The protocol itself is sound, as we covered in our white paper breakdown, but that soundness does not prevent financial layer opacity.

Derivatives: Bitcoin Price Exposure With No Bitcoin

CME Bitcoin futures are cash-settled. When a contract expires, the counterparties exchange dollars based on the settlement price. No Bitcoin changes hands. The price is influenced by instruments that have zero connection to actual coin supply.

This is not unique to Bitcoin. Oil futures, gold futures, and stock index futures are all traded in volumes that dwarf the underlying physical market. But it means a significant portion of Bitcoin "demand" expressed in price discovery is demand for financial exposure, not demand for actual coins.

As derivatives markets deepen, this gap widens. Price can be set by participants who hold no Bitcoin and have no intention of ever holding any.

How Big Is Paper Bitcoin? Nobody Knows.

This is the honest answer. There is no public aggregate figure for total Bitcoin claims versus actual circulating coins. Glassnode estimates roughly 3 to 4 million BTC are permanently lost to forgotten keys. Circulating supply is approximately 19.8 million. Claims through exchanges, ETFs, lending desks, and derivatives are not audited in aggregate anywhere.

What we do know: exchange reserves have been falling for years and now sit at a seven-year low of 2.21 million BTC. That means less Bitcoin is sitting on exchanges than at any point since 2017. Whether that reflects genuine self-custody adoption or simply migration to different custodial structures is not clear from on-chain data alone.

What This Means in Practice

Bitcoin's protocol is not broken. The 21 million cap is real and mathematically enforced. Saylor is right on this. But the financial system building around Bitcoin is creating leverage, opacity, and periodic credit risk that the protocol was never designed to prevent.

Gold went through the same process. Banks created paper gold through fractional reserve systems for centuries before the gold standard was formally abandoned. The underlying commodity remained scarce. The claims against it did not.

Saylor's own view is more optimistic than this reads. He sees the financial layers forming around Bitcoin as ultimately strengthening it, the same way gold became more useful when banks and credit markets developed around it. The risk section of his manifesto is a warning about how those layers can go wrong, not an argument against them existing. This post is that warning in plain language.

The practical implication is straightforward. The closer your Bitcoin is to the base layer, meaning a private key you control with coins verified on-chain, the more actual Bitcoin exposure you have. The further you get from that, the more you are holding a financial instrument whose value depends on counterparty solvency, not protocol integrity.

Not every holder needs to self-custody. But every holder should understand what they actually own.


Sources

Michael Saylor / Strategy: Bitcoin Evolves by Not Changing — on paper Bitcoin risk
CoinDesk: FTX bankruptcy filing and customer fund misuse — November 2022
Glassnode: Exchange reserve data and on-chain supply metrics
CME Group: Bitcoin futures contract specifications — cash settlement

Disclosure: This article is for informational purposes only and is not financial advice. We may earn commissions from affiliate links. Always do your own research before making investment decisions.

Sunday, July 5, 2026

Most People Have Read the Bitcoin White Paper. Almost Nobody Understood Section 11.

BitBrainers - Bitcoin white paper Section 11 math explained

By BitBrainers Editorial

The Bitcoin white paper is nine pages. Most people who claim to have read it understood eight of them. Section 11 is where Nakamoto stops arguing and starts proving. It is also where most readers quietly stopped following the math and decided to trust the conclusion instead.

This is an honest walkthrough of what Section 11 actually says, what problem it solves, and why the answer to that problem is the reason you wait for six confirmations before treating a Bitcoin transaction as final.

What the First Ten Sections Actually Do

Sections one through ten build the argument. Nakamoto describes the problem with double-spending, introduces the concept of a chain of proof-of-work, explains how nodes reach consensus without a central authority, and walks through the incentive structure that keeps miners honest.

It is a compelling design document. Every piece fits logically. But by Section 10, Nakamoto has only argued that the system should work. Section 11 is where he proves it cannot be broken, mathematically, given a specific assumption about the attacker's share of hash power.

The Problem Section 11 Is Solving

Imagine you receive a Bitcoin payment. The sender broadcasts the transaction, it gets included in a block, and the block gets added to the chain. You ship the goods. Then the sender quietly mines an alternative version of the chain that does not include your transaction, catches up to the honest chain, and broadcasts it. Your payment disappears. The sender has their Bitcoin back.

This is the double-spend attack. It is the fundamental threat Nakamoto needed to make practically impossible for the system to work.

The question Section 11 answers is precise: if an attacker controls q percent of the network's total hash power and the honest chain is already z blocks ahead, what is the probability the attacker ever catches up?

The Gambler's Ruin Problem

Nakamoto frames this as a version of the gambler's ruin problem. A gambler with finite resources plays against a casino with infinite resources. Even if the gambler has a near-even chance of winning each hand, the casino will eventually bankrupt them because the casino can absorb losses and the gambler cannot.

In Bitcoin, the honest chain is the casino. It has more hash power than the attacker by assumption, so it mines blocks faster on average. The attacker is the gambler, trying to close the gap against a chain that keeps moving forward.

Nakamoto models the number of blocks the attacker mines using a Poisson distribution. The Poisson distribution is the right tool here because it models the number of times a random event occurs in a fixed interval when that event has a known average rate. Mining a block is exactly that kind of event.

The attacker mines blocks at rate q. The honest chain mines blocks at rate p, where p plus q equals 1 and p is greater than q. For each block the honest chain adds, Nakamoto calculates the probability the attacker closes the gap entirely and overtakes the chain.

What the Formula Produces

BitBrainers - Nakamoto Section 11 attack probability by confirmation

The result is this: the probability the attacker ever catches up from z blocks behind drops exponentially as z increases. Not linearly. Exponentially. Each additional confirmation multiplies the difficulty of a successful attack.

Nakamoto runs the numbers in Section 11 for a specific scenario. If the attacker controls 10 percent of hash power and the recipient waits for 0 confirmations, the attacker succeeds roughly 45 percent of the time. Wait for 1 confirmation and that drops to around 20 percent. At 6 confirmations with a 10 percent attacker, the probability of a successful double-spend is approximately 0.024 percent — two hundredths of one percent.

At 30 percent attacker hash power, the same 6 confirmations holds the probability in the low double digits, around 10 to 12 percent. It is only when the attacker approaches or exceeds 50 percent that the math breaks down fundamentally, because at that point the expected value of the attack becomes positive.

Six confirmations is not an arbitrary convention. It is the point at which the attack probability becomes economically irrational for any attacker controlling a realistic share of hash power.

This also explains why different participants use different thresholds. A merchant accepting a small payment might accept one or two confirmations — the potential loss is too low to justify waiting. An exchange receiving a large transfer might wait for 20 or 30. Six became the industry default because it represents the rational threshold for a realistic attacker, not because Nakamoto mandated it.

Bitcoin basics without the hand-waving.

Every Monday we break down what actually matters in markets and on-chain. No hopium, no noise.

Subscribe Free

Why This Was a Genuine Intellectual Achievement

Nakamoto did not invent the Poisson distribution or the gambler's ruin problem. Both are classical probability theory. What he did was recognize that these tools mapped precisely onto the double-spend problem and apply them correctly in nine pages.

The insight is that you do not need to prevent attacks from being attempted. You only need to make them unprofitable. The math in Section 11 proves that with honest majority hash power, the cost of a successful double-spend attack grows faster than the potential gain as confirmations increase.

That is the security model. Not cryptography alone. Not decentralization alone. A probability calculation that makes cheating economically self-defeating.

What It Means Today

The model holds as long as no single entity controls more than 50 percent of hash power. That assumption has been under pressure as mining has concentrated in large pools. Two or three major pools coordinating would theoretically cross the threshold.

In practice, the economics still work in Bitcoin's favor. A successful 51 percent attack would destroy the value of the asset the attacker spent resources to mine. The incentive to attack is undermined by the attack's own success. Nakamoto noted this too, in Section 6.

But the honest read is that the security guarantee in Section 11 is a probabilistic one, not an absolute one. Six confirmations makes attack economically irrational under normal conditions. It does not make attack physically impossible.

That distinction is what most white paper summaries quietly omit. Nakamoto did not omit it. He put the exact numbers in a table and let the math speak.

The One Line Worth Remembering

Section 11 closes with this: "We can see that the probability drops off exponentially with z."

That sentence is the entire security argument in eleven words. Every six-confirmation standard, every exchange policy, every custody procedure in the industry is downstream of that one observation. Most people who have "read" the white paper read around it.

Now you have not.


Sources

Satoshi Nakamoto: Bitcoin: A Peer-to-Peer Electronic Cash System (2008)
Bitcoin Wiki: Confirmation — security model and confirmation thresholds
Bitcoin Wiki: Double-spending — attack mechanics and historical context

Disclosure: This article is for informational purposes only and is not financial advice. We may earn commissions from affiliate links. Always do your own research before making investment decisions.

Wednesday, July 1, 2026

Why Your Exchange Wants You to Stay (And What Actually Fixes It)

BitBrainers - fractured Bitcoin coin with capital flowing toward AI infrastructure

By BitBrainers Editorial

Every exchange interface is built around one goal: keep your coins on their platform. Not because they're malicious by design, but because your balance sitting on their books is the entire business model. The friction to withdraw isn't an accident. It's revenue protection.

The Balance Sheet You Never See

When you deposit Bitcoin on an exchange, you don't hold Bitcoin anymore. You hold an IOU. The exchange holds the actual private keys, and your balance is just a number in their database. That number can be lent out, used as collateral, or in the worst case, gone before you ever try to withdraw it.

FTX proved this isn't theoretical. Sworn testimony and court filings later confirmed that Alameda Research, the trading firm founded by the same person who ran FTX, had been drawing on customer deposits for years before the collapse, using them as an open line of credit that reportedly ran into the tens of billions. The exchange marketed itself as the safest place to hold crypto while quietly reinvesting customer funds behind the scenes. When withdrawals spiked in November 2022, the gap between what customers thought they owned and what the exchange actually had on hand became impossible to hide. A U.S. court later ordered $12.7 billion in restitution and disgorgement, one of the largest judgments in the history of financial fraud enforcement. None of that money would have been at risk if it had never left customer wallets in the first place.

Three Ways They Profit While You Wait

Trading fees are the obvious one, but they're rarely the biggest. Spread markup on market orders quietly costs more than the stated fee on most retail trades. Interest on idle deposits is another: your uninvested cash or stablecoins often earn the exchange yield in the background while you earn nothing. And withdrawal friction, minimum amounts, network fee markups, occasional "verification delays," all nudge you toward leaving funds parked rather than moving them out.

None of this requires bad intent. It's just what happens when the platform's incentives and your incentives point in different directions. I watched this exact dynamic from the inside on a CFD brokerage desk. The house doesn't need you to lose. It just needs you to stay active and stay parked.

Worth saying plainly: not every exchange is FTX. Platforms like Kraken that publish proof-of-reserves and submit to third-party audits are a meaningfully different risk than one that hides its balance sheet entirely. Some withdrawal friction is also just regulation doing its job, KYC and AML checks exist to catch fraud and stolen funds, not only to slow you down. The incentive misalignment is still real. It's just not the whole story on every platform.

This is the kind of read you get weekly.

No hype. No "this coin will 100x." Just honest macro on Bitcoin, gold, and the market.

What Self-Custody Actually Fixes

Self-custody removes the middleman from the equation entirely. Your keys, your coins, no balance sheet risk, no lending desk, no "temporary" withdrawal freeze during a bank run. It doesn't eliminate risk, you take on the responsibility of not losing your own keys, but it converts counterparty risk into a risk you fully control.

A hardware wallet like a Trezor keeps your private keys offline, away from any exchange's balance sheet. Setup takes minutes. The habit of moving funds off-exchange after every trade takes longer to build, but it's the difference between owning Bitcoin and owning a promise.

Be honest with yourself about the tradeoff. More people lose crypto to their own mistakes, a lost seed phrase, a phishing link, a backup that was never written down, than to an exchange collapse. Self-custody removes one risk and hands you a different one. It's still the better trade for anything you're not actively using, but only if you take the seed phrase part seriously.

The Middle Ground

You don't need to self-custody every dollar you trade with. Keep active trading capital on the exchange, move everything else off. Treat the exchange like a checking account, not a savings account. That single mental shift changes how much risk you're actually carrying at any given time.

The Test That Actually Tells You Something

Forget reading the terms of service. There's a faster way to gauge how an exchange treats withdrawals: try one. Move a small, real amount off the platform and time it. A clean process, clear fees, and funds landing in your wallet within the stated window is a good sign. Repeated "verification required" prompts, minimums that conveniently sit above what you're trying to move, or support tickets that go nowhere are the same pattern that preceded past exchange failures, just earlier in the timeline. This costs you a few dollars in network fees. It's a cheap way to find out what a five-figure or six-figure withdrawal would actually look like before you need it to work.

Worth Watching Right Now

The EU's MiCA transitional licensing period expired today, July 1. Roughly 92 percent of the exchanges and crypto businesses that previously operated under older national licenses across Europe still lack full MiCA authorization, leaving them to either secure a license, wind down, or transfer clients to an already-licensed platform. Separately, Strategy authorized a new $2 billion buyback program alongside a mechanism that would let it sell bitcoin for liquidity if needed, a notable shift from its prior all-in accumulation stance. Bitcoin extended its slide below $58,500 this week, with roughly $320 million in leveraged positions liquidated in a single day.

Sources

CFTC, consent order and $12.7 billion judgment against FTX and Alameda Research, August 2024. Forbes, coverage of the FTX/Alameda restitution ruling, August 2024. Axios, FTX trial testimony on Alameda's use of customer funds, October 2023.

BitBrainers. We check the facts so you don't have to.

Disclosure: This post contains affiliate links. We may earn a commission at no extra cost to you.

Monday, May 18, 2026

The Tax Man Has Been Watching Your Wallet Since 2016. Most Crypto Holders Still Don't Know

The Tax Man Has Been Watching Your Wallet Since 2016. Most Crypto Holders Still Don't Know

Most people who buy Bitcoin think about price. Very few think about what happens when they sell it, swap it, or spend it. Tax authorities in the US, UK, Australia, and the EU have been building crypto-tracking infrastructure for years. The assumption that crypto is anonymous and untaxed is one of the most expensive mistakes new holders make.

This post covers how crypto tax works in most major countries, what actually triggers a taxable event, and what most guides conveniently leave out.


Crypto Is Treated as Property, Not Currency, in Most Countries

The IRS in the United States classified Bitcoin as property in 2014. HMRC in the UK took a similar position. The Australian Taxation Office followed. What this classification means is that every time you dispose of crypto, including selling, trading, or spending it, you potentially trigger a capital gains event.

This is not the same as how your bank account works. When you spend dollars, you do not owe capital gains tax. When you spend Bitcoin, in most jurisdictions, you do.

The European Union has been tightening its framework under DAC8, a directive that requires crypto exchanges operating in the EU to report user data to tax authorities. The reporting net is getting wider, not smaller.


A Taxable Event Is Not Just Selling to Fiat

This is where most new holders get caught. Swapping Bitcoin for Ethereum on an exchange is a taxable event in the US, UK, and Australia. You are disposing of one asset and acquiring another, and the capital gain or loss is calculated at the moment of the swap.

If you bought 1 BTC at $30,000 and swapped it for ETH when BTC was worth $76,325, you have a realized gain on that BTC. It does not matter that you never touched fiat. The gain is still taxable.

Spending crypto on goods or services triggers the same mechanism. In the US, this has been the IRS position since at least 2019.


Short-Term vs Long-Term Gains: The Holding Period Matters

Most countries distinguish between assets held for a short period versus a longer period. In the US, assets held for less than 12 months are taxed at ordinary income rates. Assets held longer than 12 months qualify for preferential long-term capital gains treatment.

The UK uses a different system under Section 104 pooling rules, where HMRC calculates your average cost basis across all purchases of the same asset. Australia has a similar long-term discount structure for assets held over 12 months.

The specific rates vary by income bracket and country. What stays consistent across jurisdictions is that the holding period affects how much you owe.


Receiving Crypto as Income Is Taxed Differently

If someone pays you in Bitcoin for work, or you earn crypto through staking, mining, or yield farming, most tax authorities classify that as income, not capital gain. You pay income tax on the fair market value of the crypto at the time you receive it.

Then, when you later sell or swap that crypto, you also potentially owe capital gains tax on any appreciation from the original income value. This means a single unit of crypto can be taxed twice in two separate categories before you ever see fiat.

Staking rewards in particular are a grey area that different countries handle differently. The UK's HMRC has issued guidance treating most staking rewards as income on receipt.


Most People Do Not Know This: Sending Crypto Between Your Own Wallets Is Not a Taxable Event

Moving Bitcoin from one wallet you own to another wallet you own does not trigger a capital gains event in the US, UK, or Australia. The IRS, HMRC, and ATO are consistent on this point.

Where people trip up is failing to document that both wallets belong to them. If your records are messy and you cannot prove wallet ownership, an auditor may treat a transfer as a sale or gift. Keep a clear record of every wallet address you control and when you created it.

This matters especially as more Bitcoin holders move to self-custody using hardware wallets. The act of moving from an exchange to a hardware wallet is not a taxable event. The paperwork you keep proving that is what protects you.


The Cost Basis Problem Is Where Things Get Complicated

Cost basis is what you originally paid for your crypto. Your taxable gain is the difference between what you paid and what you received when you disposed of it. Sounds simple. In practice, it is a mess.

If you bought Bitcoin 40 times over three years at different prices, your cost basis is not straightforward. Different accounting methods, FIFO (first in, first out), LIFO (last in, first out), and specific identification, produce different tax outcomes. The US allows specific identification if you can document it properly. The UK mandates its own pool calculation method.

With BTC currently at $76,325, any long-term holder sitting on gains is also sitting on a tax liability they will realize the moment they sell. That number is not hypothetical, it is baked into every wallet that has appreciated.


Tax Authorities Already Have More Data Than You Think

This is the contrarian point most crypto blogs miss. Many holders still operate as if self-reporting is optional or unlikely to get checked. That assumption is outdated. Coinbase has been reporting user data to the IRS since at least 2016 under legal order. Exchanges operating in the EU are mandated to report under DAC8. The OECD's Crypto-Asset Reporting Framework is being adopted by over 50 countries to enable automatic cross-border data sharing.

The era of crypto being invisible to tax authorities is effectively over for anyone using a regulated exchange. The only people this does not apply to are those who have never touched a KYC (Know Your Customer) exchange, and that group is a fraction of total holders.

The practical implication is that inaction is not the same as safety. Tax authorities are building backward-looking cases using exchange data, blockchain analytics companies, and international cooperation agreements.


Losses Are Not the End of the Story: Tax Loss Harvesting Is Real

Selling crypto at a loss lets you offset capital gains elsewhere in most jurisdictions. This is called tax loss harvesting and it is a legitimate strategy used by accountants worldwide.

If you made gains on BTC but took losses on an altcoin position, you may be able to net those against each other. In the US, capital losses first offset capital gains of the same type, then can offset up to $3,000 of ordinary income per year, with excess losses carried forward.

With BTC trading at $76,325 in mid-May 2026, anyone who entered at higher prices during previous cycle peaks may actually be sitting on unrealized losses worth documenting. A qualified crypto tax accountant, not a general accountant who has never touched crypto, is worth the cost in this situation.


The Software Tools That Exist Are Useful But Not Infallible

Crypto tax software like Koinly, CoinTracker, and TaxBit imports exchange history and wallet transactions to calculate your liability automatically. These tools save enormous time. They also make errors when exchanges format data inconsistently, when DeFi transactions are complex, or when chain data is incomplete.

Never submit a tax report generated by software without reviewing it. One miscategorized transaction can throw off your entire cost basis calculation.

For anyone buying or selling regularly, keeping a clean paper trail from the moment you start is the difference between a two-hour tax filing and a nightmare audit.


The Assumption Worth Challenging Before You Leave

You probably came here thinking that crypto taxes are a problem for people who made a lot of money. That assumption is wrong in two directions. First, even small gains are reportable in most countries. Second, even people who lost money have obligations, including documenting and reporting those losses, because losses have tax value.

The tax system does not care whether you feel like you made meaningful money. It cares about what you disposed of and what it was worth at the time. If you traded, swapped, spent, or earned crypto in any tax year, you have a filing obligation in most major jurisdictions regardless of whether the net result was profitable.


Disclosure: This post contains affiliate links to Trezor and Kraken. BitBrainers may earn a commission at no extra cost to you. This is not financial advice.

The one thing to remember: Every disposal of crypto, not just selling to fiat, is a taxable event in most countries. Know your cost basis, track every transaction, and do not confuse inaction with invisibility.

BitBrainers. Follow the data, not the noise.

Thursday, May 14, 2026

The Biggest Crypto Hacks in History and What They Taught Us

BitBrainers - The Biggest Crypto Hacks in History and What They Taught Us analysis and insights

Over $3 billion was stolen from crypto protocols and exchanges in a single year alone. Not from beginner mistakes. Not from phishing scams targeting grandmothers. From deep systemic failures that developers, executives, and regulators all saw coming and did nothing about. That number should make you angry, not scared.

This isn't a scare post. It's a forensic look at why some of the biggest crypto heists in history happened, what the industry learned, and honestly, what it still refuses to learn.

Mt. Gox Didn't Collapse Because Bitcoin Failed

Mt. Gox was once handling the majority of all global Bitcoin trades. When it imploded, approximately 850,000 BTC belonging to customers disappeared. The exchange had been bleeding funds through a bug in how it processed withdrawal transactions for years before anyone noticed. Bitcoin itself kept running. Every block confirmed. Every transaction settled. The protocol did exactly what it was built to do.

The failure was entirely human and organizational. Poor internal auditing, zero transparency, and a leadership structure that prioritised growth over security. This set the pattern for nearly every major exchange hack that followed.

Bitfinex Proved That Multi-Signature Security Can Still Be Exploited

Bitfinex used a multi-signature wallet setup with BitGo. Multi-signature means a transaction needs approval from multiple private keys before it can execute. It sounds bulletproof. It wasn't.

Attackers identified a flaw in how the system was configured rather than in the cryptography itself. Around 120,000 BTC were stolen. The interesting part? Bitfinex issued a token called BFX to creditors representing the debt, then bought those tokens back at face value over the following year. Most people write off exchange hacks as permanent losses. Bitfinex partially rewrote that narrative, though it took significant time and the approach was controversial.

The DAO Hack Was a Warning About Code as Law

Ethereum launched with an ambitious concept: smart contracts execute automatically based on code, with no human interference. A project called The DAO raised a massive amount of ETH to fund decentralised proposals. Then someone found a re-entrancy bug. This is where a smart contract can be tricked into sending funds multiple times before it updates its own internal balance. The attacker drained roughly a third of The DAO's funds.

The Ethereum community made a controversial decision to hard fork the blockchain and reverse the hack. Not everyone agreed. The group that rejected the fork kept the original chain running as Ethereum Classic. One hack literally split a blockchain into two separate assets that still trade today.

Ronin Network Showed That Bridges Are the Weakest Link in Crypto

The Ronin Network hack sits near the top of the all-time list by dollar value. Ronin was the blockchain underlying the Axie Infinity game. Attackers compromised validator nodes, the entities responsible for approving transactions on the network. They gained control of enough validators to approve fraudulent withdrawals of approximately 173,600 ETH and 25.5 million USDC.

Cross-chain bridges, the infrastructure that moves assets between different blockchains, have consistently been the most targeted attack surface in crypto. They hold large concentrations of funds. They involve complex code. They connect systems with different security assumptions. Every serious developer in the space knows bridges are dangerous. The market keeps building them anyway because users demand cross-chain functionality.

Most People Don't Know This About Private Key Management at Exchanges

Here's something that rarely makes it into mainstream coverage. Many exchanges historically stored private keys in hot wallets because cold storage creates operational friction. A hot wallet is connected to the internet. A cold wallet is not. Moving funds to a cold wallet means a human has to physically interact with the signing device. Exchanges optimised for withdrawal speed over withdrawal security.

The business logic made sense in the short term. The security logic was a disaster waiting to happen. The best exchanges today use a tiered system where only a small percentage of total funds sit in hot wallets at any given time. The rest stay in cold storage. But this only protects you if the exchange actually follows through on it, and you have no way to verify that from the outside.

Wormhole's $320 Million Loss Came From One Line of Buggy Code

Wormhole is a bridge connecting Solana to other blockchains. In early 2022, an attacker found a flaw in the signature verification logic. This means the code that checks whether a transaction has been properly authorised had a bug that allowed someone to bypass the check entirely. The attacker minted 120,000 wrapped ETH on Solana without actually depositing the real ETH on the Ethereum side. They then redeemed that synthetic ETH for real assets.

Jump Crypto, the firm behind Wormhole, replenished the funds within days. That response surprised the industry. It also confirmed that some serious institutional money now backs crypto infrastructure, and those institutions have reputational and financial reasons to make users whole when things break.

Self-Custody Isn't a Preference, It's a Risk Management Decision

Every hack covered here involved a third party holding assets on behalf of users. That's the common thread. When you leave Bitcoin on an exchange, you hold an IOU, not Bitcoin. The exchange holds the actual private keys. If the exchange gets hacked, mismanages funds, or goes insolvent, your Bitcoin is part of the mess.

Hardware wallets like Trezor put the private keys under your physical control. The keys never touch an internet-connected device. An attacker cannot remotely steal what they cannot remotely access. This isn't a marketing talking point. It's the direct lesson from every exchange hack ever documented.

Regulation Is Catching Up, But Don't Assume It Protects You

The Bank of England is currently reconsidering its approach to sterling stablecoin regulation following pushback from the industry, according to a report in the Financial Times covered by The Block this week. Regulators globally are tightening their grip on crypto infrastructure, and part of that pressure comes directly from the hack history we've been through.

Regulation will not prevent technical exploits in smart contracts. It will not stop a determined nation-state attacker. It adds accountability and oversight to centralised actors, which is better than nothing, but it doesn't solve the core problem of holding private keys securely.

The Contrarian Take Nobody Wants to Say Out Loud

Most crypto commentary treats hacks as anomalies. Rare events caused by unique circumstances that the industry is slowly closing off. That framing is wrong. Hacks are a structural feature of any high-value permissionless system. Bitcoin has survived for years without its base layer being compromised. But everything built on top of it, custodians, bridges, smart contracts, DeFi protocols, has a consistent track record of failure.

The lesson isn't that crypto is unsafe. The lesson is that the security guarantee Bitcoin offers at the base layer does not automatically extend to every product built around it. The protocol is not the product. Most people conflate the two.

Code Audits Exist, and Hackers Don't Care

Before major DeFi protocols launch, they typically commission smart contract audits from security firms. Firms like Certik, Trail of Bits, and OpenZeppelin have reviewed thousands of contracts. Audited contracts still get hacked regularly. An audit is not a security guarantee. It's a documentation of the security assumptions a firm reviewed at a single point in time. Code changes. New interactions between protocols create new attack surfaces. Auditors are not adversarial the way real attackers are.

This doesn't mean audits are useless. It means treating an audit as a final seal of safety is dangerously naive.

The Assumption Worth Challenging Before You Leave

You probably came into this post assuming the biggest lesson from crypto hacks is to use better passwords or avoid shady projects. That's surface-level thinking. The deeper lesson is about custody architecture. Who holds the keys, under what conditions, with what oversight, and what happens when that arrangement fails? Every hack in crypto history traces back to a bad answer to one of those four questions.

Bitcoin doesn't care who holds the keys. It will process whatever transaction is signed with the correct private key. The human systems wrapped around that cryptographic truth are where everything goes wrong.

If you're buying Bitcoin and holding it on an exchange, you're trusting that exchange's security decisions completely. If you want to actually hold Bitcoin, use a hardware wallet like Trezor and be responsible for your own keys. If you're still at the stage of buying and want a reliable exchange to get started, Kraken has a strong security track record compared to most competitors.

The one thing to remember: an exchange holding your Bitcoin isn't storing it for you, it's replacing it with a promise.


Disclosure: This post contains affiliate links to Trezor and Kraken. BitBrainers may earn a commission at no extra cost to you. This is not financial advice.


BitBrainers. No hype. No fluff. Just crypto that matters.

Wednesday, May 13, 2026

How Governance Tokens Actually Work and Why Most Are Worthless

BitBrainers - How Governance Tokens Actually Work and Why Most Are Worthless analysis and insights

Uniswap has processed hundreds of billions in trading volume. UNI token holders have collectively voted to keep the fee switch off for years. The people generating that revenue do not hold UNI. The people holding UNI do not benefit from that revenue. That is governance in crypto.

A Governance Token Is a Voting Ticket With No Ballot Box That Matters

When a protocol launches a governance token, it hands out voting rights over protocol parameters. Things like fee structures, treasury spending, adding new assets, or changing smart contract rules.

The token itself does not represent equity. It does not give you a cut of protocol revenue by default. It gives you the right to vote, and that is often where the usefulness ends.

Compound launched COMP in 2020 as one of the first major governance tokens. The concept spread fast. Every new DeFi protocol copied the model. Most of them had no serious thought put into what token holders would actually decide, or why anyone would care.

Voting Power Concentrates Exactly Like You Would Expect It To

Here is the structural problem. Governance tokens get distributed through liquidity mining, airdrops, and team allocations. Venture capital firms and early insiders consistently end up with the largest voting blocks.

On Compound, a handful of institutional addresses have historically controlled enough voting power to pass or block proposals unilaterally. Most retail holders own too few tokens to reach the minimum threshold required to even submit a proposal.

On Uniswap, you need 2.5 million UNI just to submit a governance proposal. At any price above a few dollars, that is a multi-million dollar barrier. That is not decentralized governance. That is a veto system designed to keep power where it already sits.

The Fee Switch Problem Exposes the Whole Lie

Uniswap has collected enormous fees since it launched. Those fees go entirely to liquidity providers. UNI holders get nothing.

There is a fee switch built into the protocol that could redirect a portion of fees to the governance treasury, which UNI holders control. The community has debated activating it for years. It has not happened, partly due to regulatory concerns around whether that would make UNI a security.

This is the core contradiction. Governance tokens promise holders influence over valuable protocols. But activating that value triggers regulatory scrutiny that developers want to avoid. So the token sits in limbo, powerful on paper, inert in practice.

Most People Do Not Know That Low Voter Turnout Is By Design, Not Accident

Here is the insider insight most posts skip. Low participation in governance votes is not a bug most teams want to fix. High voter turnout requires engaging retail holders. Retail holders are unpredictable. They can vote against protocol changes that VCs want pushed through.

Quorum thresholds are set high enough to fail without institutional participation, and low enough that institutions can pass things without retail. This architecture gives the appearance of community governance while keeping actual control concentrated.

Aave governance operates on this model. A proposal needs a specific token threshold to reach quorum. Retail holders are technically eligible to vote but structurally irrelevant unless they organize through delegation.

MakerDAO Is the Exception That Proves the Rule

MKR is one of the few governance tokens with real, embedded utility. MKR holders govern the Maker protocol, which controls the DAI stablecoin peg. Bad governance decisions directly reduce the value of MKR through a dilution mechanism.

This creates actual skin in the game. If MKR holders vote poorly and the protocol takes on bad debt, the system mints new MKR to cover losses, which dilutes existing holders. If they govern well, surplus revenue buys and burns MKR, which reduces supply and increases value.

That feedback loop is why MakerDAO governance has historically been more serious than most. The token has consequences attached to it. Most governance tokens carry no such weight.

Stablecoin Infrastructure Shows Where Real Crypto Value Is Flowing Right Now

While governance tokens shuffle voting power around, actual financial infrastructure is being built on top of stablecoins. This week, Stables announced it tapped the T-0 Network as stablecoin payment infrastructure, targeting Asia where stablecoins already account for a significant share of crypto payment volume.

That is the contrast that matters. Stablecoin payment rails are processing real economic activity. Governance tokens are processing votes that often change nothing. One has product-market fit. The other mostly has marketing.

The infrastructure being built around USDT and USDC in Asia represents the kind of utility that creates sustained demand for a token. A governance token for a protocol nobody uses has no equivalent demand driver.

Airdrop Dumping Destroys Token Value Faster Than Any Bear Market

When protocols airdrop governance tokens to early users, most recipients sell immediately. They earned the tokens through usage, not conviction. They have no reason to hold.

This dynamic hits every new governance token launch. The token spikes on day one, dumps over the following weeks as recipients sell, and stabilizes at a fraction of its launch price. The community left holding are the ones who bought into the narrative after the airdrop.

dYdX dropped its governance token to early traders. The price action followed the exact pattern described above. Most governance token launches follow the same arc. The protocol might be excellent. The token economics are structured to punish retail buyers.

Token Utility Gets Bolted On Later and It Shows

Projects that launch governance tokens often try to add utility retroactively. Staking rewards. Buyback programs. Revenue sharing proposals. These are patches on a flawed original design.

When a team needs to invent reasons for people to hold their token, that is not a good sign. The token was not designed with clear value capture from day one. It was designed to attract liquidity, distribute ownership on paper, and create a fundraising mechanism that avoided being called a fundraising mechanism.

Compare this to BTC. Bitcoin does not require governance theater to justify its value. The scarcity, the security model, and the network effect do that work. A governance token for a protocol with low usage and no fee capture has none of these fundamentals underneath it.

The Smart Contract Risk Nobody Mentions in Governance Discussions

Holding a governance token also means you are exposed to smart contract risk on that protocol. If the protocol gets exploited, the governance token often goes to near zero. You took the risk of a DeFi hack and received voting rights you probably never used as compensation.

Beanstalk, a stablecoin protocol, was drained through a governance attack. An attacker took out a flash loan, acquired enough governance tokens in a single transaction to pass a malicious proposal, drained the treasury, and repaid the loan. Governance itself became the attack vector.

This is not a hypothetical. Governance tokens can be used by adversaries to steal from the protocol they are supposed to protect. The same mechanism that lets holders vote lets a well-capitalized attacker weaponize voting rights in a single block.

The Contrarian Take: Governance Tokens Are Brilliant for Protocols, Terrible for Holders

Most analysis frames this as a problem to be solved. It is not. Governance token distribution is an elegant solution for protocols that want decentralized ownership narratives without giving up actual control.

The protocol captures liquidity, creates a distributed holder base that defends the protocol from criticism, and avoids securities classification by ensuring the token does not represent equity. Holders receive influence over parameters that rarely change and economic rights that rarely pay out.

The protocol wins. The early insiders win. The retail holder who bought on exchange after the hype cycle started is carrying all the risk with almost none of the upside. Understanding this reframes every new governance token launch you see.

Challenge One Assumption You Walked In With

You probably assumed that governance tokens exist primarily to give communities control over protocols. They do not. They exist primarily to distribute protocol risk to the public while keeping decision-making power concentrated among insiders. The community framing is real in some protocols, especially smaller ones. But at scale, it consistently breaks down along the lines described above. The assumption that voting rights equal real power is the mistake most token holders make before they learn it the expensive way.


Disclosure: This post contains affiliate links to Trezor and Kraken. BitBrainers may earn a commission at no extra cost to you. This is not financial advice.


The one thing you must remember: A governance token is only as valuable as the protocol's revenue, the credibility of its fee capture mechanism, and the seriousness of its voter participation. If any of those three are weak, the token is speculation, not ownership.


BitBrainers. No hype. No fluff. Just crypto that matters.


Sunday, May 10, 2026

Hard Forks Don't Break Bitcoin. They Reveal Who Actually Controls It.

BitBrainers - Hard Forks Don't Break Bitcoin. They Reveal Who Actually Controls It.

One developer disagreement split Bitcoin's network overnight and handed every holder a brand-new coin they didn't ask for. That's not a hypothetical. That happened in August 2017. If you weren't paying attention, you either claimed free money or left it rotting in an exchange wallet forever.

Hard forks are one of the most misunderstood events in crypto. Most beginner guides reduce them to "free coins!" and move on. That's lazy, and it misses the part that actually matters.


A Hard Fork Is a Protocol Divorce, Not an Update

A hard fork happens when a blockchain's code changes in a way that makes the new version permanently incompatible with the old one. It's not a software patch. It's a split.

Think of it like this: Bitcoin is a rulebook shared by thousands of computers worldwide. If a group of developers and miners decide to change a fundamental rule, say, the block size limit, and other nodes refuse to follow, you get two separate chains from that point forward. Both chains share all the history up to the split, then they go their own way.

This is different from a soft fork, which is a backward-compatible change. Soft forks tighten the rules. Hard forks change them in a way that older nodes will outright reject.


Bitcoin Cash Is the Textbook Case, and It Was Messy

In August 2017, a faction of the Bitcoin community hard forked the network to create Bitcoin Cash (BCH). The core disagreement was over block size. The original Bitcoin block size was capped at 1MB, which limited how many transactions could be processed per block. BCH boosted that limit to 8MB immediately.

Holders of Bitcoin at the time of the fork received an equal amount of BCH, one BCH for every one BTC. Sounds clean. In practice, claiming those coins required accessing your private keys, which created serious security risks if you did it wrong. More on that in a minute.

BCH then forked again in November 2018 into Bitcoin Cash ABC and Bitcoin SV (BSV). BSV later got delisted from multiple major exchanges. A coin born from ideological conflict can fracture again just as easily. This isn't stability. It's a chain of disagreements wearing a ticker symbol.


The Fork That Actually Changed Ethereum Forever

Ethereum Classic (ETC) exists because of a hard fork too, but the reason was different and messier. After the DAO hack drained roughly $60 million worth of ETH in 2016, the Ethereum core team proposed a fork to reverse the stolen transactions. Most of the community went along with it, creating what we now call Ethereum (ETH). The minority that refused to rewrite history kept running the original chain. That became Ethereum Classic.

This fork wasn't about scaling. It was about whether a blockchain should be truly immutable or whether the community gets to undo transactions it doesn't like. That philosophical split is still debated today. ETH took the pragmatic route. ETC held the ideological ground. Neither answer is obviously wrong, but the market has been fairly clear about which it prefers.


Here's What Most People Don't Know About Forks

Most people think the dangerous moment is during the fork. It's not. The dangerous moment is the weeks after, when people start trying to claim their forked coins.

To claim coins on a new fork chain, you typically need to use your private key on the new chain's software or a third-party claiming tool. If the fork coin has low developer security standards, and many do, you risk exposing your private key to malicious code. There have been documented cases of people losing their original Bitcoin while chasing forked coins worth far less.

The rule that serious holders follow is to move their original coins to a fresh wallet before interacting with anything fork-related. If you hold BTC in self-custody, hardware wallets handle fork claims with significantly better isolation than hot wallets or exchange accounts. A device like Trezor keeps your private keys offline and gives you far more control over how you interact with fork chains. You can check that out at affil.trezor.io.


Exchanges Decide Whether You Get Your Fork Coins at All

Here's something the free-coins narrative conveniently skips: if your BTC sits on an exchange during a fork, the exchange decides whether to credit you. Many exchanges have declined to support certain fork coins, meaning holders on those platforms got nothing.

In 2017 and 2018, some exchanges credited BCH to holders. Others did not. Coinbase initially said it wouldn't support BCH, then reversed course under user pressure. The point isn't which exchange did what. The point is that your fork eligibility was entirely in someone else's hands.

If you don't control your private keys, you don't control your fork coins. This is one of the strongest arguments for self-custody. Not your keys, not your coins applies before the fork and after it.


The Real Signal From a Fork Is Governance, Not the New Coin

Here's the contrarian take that most crypto content ignores: the new coin that emerges from a hard fork is almost never what matters. What matters is what the fork reveals about the original chain's governance structure.

The Bitcoin Cash fork exposed that Bitcoin had no clear mechanism to resolve major protocol disagreements. The community had argued about block sizes for years with no resolution. The fork was the blowout, not the argument itself. When you see a hard fork forming, the right question isn't whether the new coin has value. The right question is: what does this fight tell me about who actually controls this network?

Bitcoin has had over 70 attempted forks since its launch in 2009. The vast majority are abandoned or trade with negligible volume. The ones that survive reveal that a meaningful faction of the community held a different vision for long enough to maintain infrastructure.


Not Every Hard Fork Is a Fight. Some Are Planned Upgrades

It's worth separating contentious forks from planned ones. Some hard forks happen because the entire community agrees a change is necessary and coordinates around a specific block height. These go smoothly. There's no chain split because no faction refuses the upgrade.

Bitcoin's Taproot upgrade, which improved scripting flexibility and privacy, activated in November 2021. It was a soft fork, not a hard fork, but the point stands: upgrades can happen without drama when developers, miners, and node operators align. The fireworks happen when they don't.


What a Fork Means for BTC at $80,837 Today

With BTC sitting at $80,837 on May 10, 2026, fork discussions are always cycling through developer forums and social channels. The Bitcoin developer community has ongoing conversations about future upgrades. None of them involve the kind of ideological split that produced BCH. That's worth noting. The Bitcoin ecosystem today is significantly more institutionally mature than it was in 2017, which makes a chaotic contentious fork less likely, though never impossible.

If a credible fork proposal gains traction, it will show up in Bitcoin's GitHub repository discussions and mailing lists long before any media outlet covers it. Watching those sources is how you get ahead of the noise, not by waiting for a headline.


You Probably Think Forks Only Affect Old-School Holders

Here's the assumption worth challenging before you close this tab. If you're newer to Bitcoin and you think hard forks are a 2017-era problem that doesn't concern you, that thinking is wrong. Forks can happen to any chain at any time as long as people disagree about protocol direction. The bigger the community, the more potential vectors for conflict.

Right now the broader crypto ecosystem has hundreds of active chains, each with their own governance dynamics and developer factions. The probability of a fork touching something in your portfolio at some point is not small. Knowing how forks work before one hits a chain you hold is how you avoid making expensive decisions in the first 24 hours of chaos.


The One Thing You Must Remember

The new coin is bait. The fork itself is the signal. What a hard fork tells you about a network's governance, its community cohesion, and its ability to resolve disagreements is worth far more than whatever the forked token trades at on day one.

Keep your coins in self-custody before, during, and after a fork. Know which chain your wallet supports. Never interact with a fork chain using your original private keys until you've moved your original holdings to a clean address.


Disclosure: This post contains affiliate links to Trezor. BitBrainers may earn a commission at no extra cost to you. This is not financial advice.

BitBrainers. The crypto analysis you wish you had yesterday.


Jackson Hole Forces a Decision at $81,000

Warsh called his Jackson Hole speech a blank piece of paper. The market will fill it in for him. By BitBrainers Editorial Bitcoin is...

Jackson Hole Forces a Decision at $81,000