₿ BTC Loading... via Binance

Wednesday, August 5, 2026

BlackRock Bought the Dip. Italy's Largest Bank Sold 94% of IBIT. Someone Is Wrong

Source: The Block. Dark blue bars are IBIT. The chart updates daily.

By BitBrainers Editorial

Intesa Sanpaolo cut its BlackRock IBIT position by 93.7% in the second quarter, dropping from roughly ~646,809 shares to 40,723 shares. The filing also disclosed a new put position against the same fund and a tripling of the bank's staked Ethereum ETF stake. This is not retail panic. This is Italy's largest bank, with €1.5 trillion in customer assets, deciding that a quarter of a billion dollars in Bitcoin ETF exposure was too much to keep.

In the same quarter, BlackRock's IBIT took in $869 million in a single week. The fund now holds 3.70% of every Bitcoin in existence and has absorbed $60.81 billion since launch. One institution is running for the exit. Another is still vacuuming up the floor. Both cannot be right about the same asset at the same price.


The Filing That Got Buried

Intesa Sanpaolo's Q2 13F landed without the fanfare of a MicroStrategy purchase or a Tesla headline, which is exactly why it matters. The bank had been one of the more visible European institutional adopters, more than doubling its crypto ETF holdings to $235 million in Q1 2026. Sixty days later, the Bitcoin allocation was effectively gone.

The details are more interesting than the headline. The bank did not just sell. It bought puts. That is a directional bet, not a rebalancing. And the same filing shows the bank tripled its position in a staked Ethereum ETF, suggesting the capital did not leave crypto entirely. It rotated. Whether that rotation is a vote against Bitcoin specifically, or against the ETF wrapper, or simply a mandate level decision to favour assets that generate yield over assets that produce none, the filing does not say. What it says is that one of Europe's most conservative systemically important banks no longer wants to own Bitcoin through BlackRock's product.


BlackRock's Vacuum

IBIT has now led daily inflows for so many consecutive sessions that the pattern is almost boring. The fund took in $319 million of a $499 million weekly total in late July, then added another $183 million in the final days of the month. When the broader complex was bleeding $4.5 billion in June, IBIT still found buyers. When Fidelity's FBTC, a fund with zero fees, was shedding $85 million in a week, IBIT was taking in $869 million.

The explanation is not price. It is plumbing. BlackRock's products sit on the platforms that pension managers, endowments, and financial advisers already use. Buying IBIT means clicking a button they have clicked a thousand times before. For most institutional allocators, IBIT is not a crypto bet. It is an asset allocation decision made inside infrastructure they trust. That distribution advantage explains why a fund charging 0.25% is beating a free competitor four to one.

But distribution is not conviction. It is convenience. And convenience flows reverse faster than conviction flows when the narrative turns.


The Divergence

Here is the tension. Intesa Sanpaolo sold 94% of its IBIT stake in a quarter when Bitcoin traded between roughly $60,000 and $67,000. BlackRock's own clients added billions through the same product in the same price range. Either Italy's largest bank is front running a correction that BlackRock's allocators do not see, or BlackRock's allocators are averaging into a range that Intesa decided was a ceiling.

The third option is that they are different animals entirely. Intesa's $235 million position was a trading book allocation, nimble enough to rotate into staked ETH in sixty days. BlackRock's inflows are coming from model portfolios and target maturity funds that rebalance quarterly, if that. One is a speedboat. The other is an oil tanker. They can move in opposite directions without either being wrong about the destination.

What breaks that symmetry is scale. IBIT now holds roughly $48.86 billion in net assets. If Intesa's rotation is the first of many European banks trimming Bitcoin ETF exposure ahead of regulatory uncertainty, the EU's MiCA deadlines, the stalled CLARITY Act, the ethics deadlock in Washington, then BlackRock's inflows are absorbing exits that have not yet shown up in the daily flow data. The daily prints show BlackRock winning. The quarterly filings show someone large leaving. Both are true. One is just slower.


What the Flows Actually Say

Zoom out and the picture is less bullish than the IBIT headlines suggest. U.S. spot Bitcoin ETFs recorded $5.4 billion in net outflows in the first half of 2026, their first negative half year since launching in January 2024. June alone produced $4.5 billion in outflows, the largest single month exit on record. July's recovery covered roughly 15% of that damage before the final week flipped back to red.

The cumulative net inflow total since launch, roughly $53.94 billion, is still below the October 2025 peak. The funds have not made back what they lost between November 2025 and February 2026, a four month stretch that saw $6.38 billion leave alongside Bitcoin's slide from over $100,000 to nearly $60,000.

IBIT's dominance is real, but it is also a concentration risk. When a single fund is the only buyer in a market of sellers, the fund becomes the market. Large inflow days now have follow on effects on spot price that did not exist eighteen months ago. That feedback loop cuts both ways. If BlackRock's allocators ever stop buying, a bad quarter, a risk averse macro shock, a regulatory headline, there is no second buyer large enough to absorb the flow.


We read the filings so you can skip the timeline.

Weekly Bitcoin and macro analysis, built from primary sources.

Subscribe

What This Sets Up

Watch the next wave of 13F filings. Intesa was not the only European bank in these products. If Deutsche Bank, BNP Paribas, or Santander show similar reductions in Q3, the institutional adoption narrative needs a rewrite. One bank rotating is a trade. Three banks rotating is a trend.

Watch Ethereum ETF flows. Intesa did not leave crypto. It left Bitcoin for staked ETH. If that rotation repeats across other institutional filings, the Bitcoin is the only institutional crypto thesis takes a hit. Ethereum's ETF complex is smaller and younger, but it is yield bearing in a way Bitcoin's is not, and that matters for bank treasury desks.

Watch IBIT's daily prints for deceleration. The fund has led inflows for so long that the streak itself has become the story. The day that streak breaks, not because of a single red day, but because the weekly total turns negative while Bitcoin is still above $60,000, is the day the oil tanker starts turning.

And watch Friday's NFP. A print below 100,000 prices in a September cut and gives risk assets a macro tailwind. Above 150,000 and the Fed's three dissents start looking like a majority. Intesa and BlackRock are arguing about Bitcoin's institutional future. The jobs number might decide who is right.

For the wider macro setup this week and the dates that matter: this week's Weekly Brief


Sources

CryptoTimes Intesa Sanpaolo Slashes IBIT Holdings 94%, Boosts ETH Stake 3x in Q2

Yahoo Finance BlackRock's IBIT Leads Nearly $1B Bitcoin ETF Recovery as Inflows Hit 7 Straight Days

CryptoBriefing BTC ETF Flows Turn Negative for Over Half of 2026

CoinDesk The Bitcoin ETF Recovery in Flows Is Real. It Is Just Not Complete Yet

Investing.com BlackRock IBIT Sees $214M Outflow as Redemption Streak Hits $4.4B

Tools We Use

Kraken — Spot and futures on BTC, ETH, and 200+ assets.

Trezor — Cold storage. No internet connection required.

This is market commentary, not financial advice. Nothing here is a recommendation to buy or sell any asset. Do your own research.

Monday, August 3, 2026

The Market Priced Everything This Week Except the $110 Million Theft

BitBrainers - Coldcard drained vs Bitcoin price

By BitBrainers Editorial

On July 30 an attacker emptied 1,196 Bitcoin addresses in 41 minutes. Four waves later the running total stands at 1,815.75 BTC across 5,294 addresses, with a fourth wave actively running on August 3. The devices holding those coins were Coldcards, the hardware wallet the most security-conscious corner of Bitcoin has recommended for a decade. Bitcoin closed July 30 around $62,800, down less than 1% from the prior session, and was back at $63,781 by August 3. A theft at that scale bought a brief dip inside an existing range.

Forty Bits Instead of One Hundred Twenty Eight

A hardware wallet generates a seed phrase from a dedicated chip built to produce true randomness. The target is 128 bits of entropy, a number large enough that guessing it is computationally impossible for anything humans can build.

A single code change on March 1, 2021 caused Coldcard firmware to silently fall back to a software pseudorandom generator instead of the STM32 hardware chip. On Mk3 devices the effective search space collapsed to roughly 40 bits. Coinkite has confirmed that figure. Every coin taken came from a wallet created after that March 2021 firmware release, which is the strongest on-chain evidence linking the thefts to the bug.

The gap between 128 bits and 40 bits is not a matter of degree. An attacker who could constrain the device UID, timer state and prior RNG-call history could reproduce candidate seeds offline, derive their addresses, and check them against public blockchain data. No physical access to any device was required at any point.

Coinkite CEO Rodolfo Novak apologised publicly and took full accountability, saying the company's review process had failed to catch it. Emergency firmware shipped on July 31. That firmware does not repair an existing seed. A seed created with weak entropy stays weak permanently, on any device, in any wallet software. Coinkite has since halted shipments and destroyed all remaining vulnerable inventory, an acknowledgment that the problem cannot be patched on existing hardware, only replaced.


The Coins Have Not Moved

Here is the detail that explains the muted reaction. Galaxy Research reported that the first three waves of stolen Bitcoin remain unspent in attacker-controlled addresses. Not mixed, not bridged, not sent to an exchange. A fourth wave is moving coins right now as this post publishes.

Galaxy called that unusual for a theft of this size and offered two readings: the operator is waiting for scrutiny to fade, or has no viable path to launder a sum this visible on a public ledger. A decade ago $75 million in stolen Bitcoin would have been through a mixer within hours. Today, with exchange compliance tightened and firms like Galaxy and Chainalysis watching in real time, moving it is the hard part.

What happened here was a change of ownership rather than supply hitting the market, and for price purposes those are entirely different events. Only one of them registers as flow.

That covers the mechanics. It does not explain why the drift since has been sideways rather than sharply lower, which is where the rest of the week comes in.


We read the filings so you can skip the timeline.

Weekly Bitcoin and macro analysis, built from primary sources.

Subscribe

What Was Actually Setting Price

The $116 million was competing for attention with a calendar that had far more direct claims on flows.

The FOMC voted 9-3 to hold rates at 3.50% to 3.75% on July 29, with three officials dissenting toward a hike. Fed Chair Kevin Warsh again declined to give forward guidance. The PCE print on July 31 showed continued cooling, which softened hike expectations at the margin without changing the committee's split.

Spot Bitcoin ETFs posted net outflows of $61.53 million for the week ending July 31, breaking a three-week inflow streak worth roughly $306 million. Fidelity's FBTC led redemptions at $85.19 million. BlackRock's IBIT ran the other way with $869.02 million in weekly inflows.

Senate Majority Leader John Thune confirmed the CLARITY Act would not get a floor vote before the August recess. Polymarket odds on 2026 passage sit near 28%, down from 82% in February.

Three catalysts with direct, measurable links to institutional flows. Against those, a firmware bug affecting a device with a niche installed base competes for headlines, not for order books.

Strategy's Michael Saylor flagged that Bitcoin is sitting almost exactly on its 200-week moving average, a level it has traded above 92% of the time by Strategy's own calculation. That is the company's number rather than an independent study, but the level is real and the market is respecting it.


The Part Nobody Is Pricing

Price gave this one candle. Bitcoin's security assumptions deserve considerably more than that.

The bug lived in open-source code for five years. Public review is supposed to be the defence, and the code was public the entire time. Coinkite says it suspects an attacker used an automated tool to comb old code versions, something Coinkite itself had attempted weeks earlier without finding it.

That is the uncomfortable part. Machine-assisted auditing found a five-year-old flaw before the vendor running the same class of tool did. Every open-source wallet firmware repository is now sitting in the same searchable pile, and the search cost has collapsed.

Victims are organising class-action claims over losses now exceeding $116 million. Legal opinion is split on whether a hardware manufacturer carries product liability for a firmware defect of this kind. Whatever the outcome, it sets the first real precedent for the category.

None of that is in the price. Some of it will be, eventually, in the form of slower self-custody adoption or a repricing of what a hardware wallet warranty is actually worth.


The Argument Happening Underneath

The louder claim circulating is that this marks a turning point for self custody, an assault on the be-your-own-bank position that has anchored Bitcoin culture since the beginning.

The counterargument is more persuasive. People who already cared about self custody will now care more and tighten their setup. People who never cared are still leaving coins on exchanges and were never going to be moved by a firmware advisory. The net behavioural change is probably close to zero, which is a duller conclusion than a revolution but fits how the last several custody scares actually played out.

The concrete prediction worth holding onto is narrower. Passphrases move from optional to standard practice, because a BIP-39 passphrase is the specific thing that protected people here. Dice-roll entropy sits in the same category. Both were treated as advanced-user extras for years, and both just became the difference between a working wallet and an empty one.

A paid hardware device is a convenience layer that a lot of holders quietly reclassified as a security guarantee. The device did the job it was sold to do, right up until one line of firmware meant it had never been doing it at all. Convenience and guarantee are not the same product, and the price difference between them is not what the market has been paying.


What This Sets Up

Watch whether the first three waves move. A transfer toward an exchange or mixer turns a custody story into a supply story, and that is the version that would show up on a chart. An OP_RETURN message has already appeared in one attacker address advertising laundering services and KYC bypass for a 10% fee. That is not the attacker moving coins. It is the wider illicit economy signalling it is ready when they are.

Watch the class-action filings. A ruling on manufacturer liability for a firmware defect would reprice risk across every hardware wallet vendor, not just Coinkite.

Watch the audit wave. If machine-assisted review of old firmware is now cheap enough for an attacker to run at scale, the next disclosure of this type is a question of scheduling, not probability. The vendors with the shortest patch-to-disclosure gap will be the ones that survive the next one with their reputations intact.

For the wider macro setup this week and the dates that matter: this week's Weekly Brief


Sources

Bloomberg Coldcard Bitcoin Wallets Compromised as Hackers Exploit Software Flaw

Fortune Bitcoin Owners Rocked by $116 Million Hack: What We Know About the Coldcard Exploit

The Hacker News Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

TheStreet Crypto Coldcard Hack Just Grew to $89M

CryptoTimes Coldcard Hack Enters Wave 4: 449 BTC Swept Live

Blockhead A Five-Year-Old Coldcard Bug Let Hackers Guess Bitcoin Wallet Keys

Bitcoin Magazine Coinkite Releases Fixed Firmware After Coldcard Bug

Bitcoin.com News Coinkite Faces Class Action Threat as Bitcoin Wallet Bug Costs Users Over 1,300 BTC

CaptainAltcoin Bitcoin Spot ETFs End Inflow Streak

Tools We Use

Kraken — Spot and futures on BTC, ETH, and 200+ assets.

Trezor — Cold storage. No internet connection required.

This is market commentary, not financial advice. Nothing here is a recommendation to buy or sell any asset. Do your own research.

Weekly Brief: July Closed Green. August Has a Record to Defend

By BitBrainers Editorial

Bitcoin closed July at roughly $63,000, up about 7% for the month. That makes three consecutive green Julys, a streak no other month can match. August arrives with the worst seasonal record on the board, a CLARITY Act that just lost its Senate floor window, and an ETF flow picture that flipped back to red in the final week of the month. The range from early July is still intact. Whether it holds is the only question that matters this week.

July Ended Green. August Has Never Been Kind.

Bitcoin held the $60,965 floor through July and closed near $63,000. The month printed green for the third consecutive year, which is genuinely rare. Seasonal data going back to 2013 shows August closing red more often than any other month, with a median loss around 8%.

That context does not make a down August inevitable. It does put the burden of proof on the bulls. A three-day close above $66,885 invalidates the bearish seasonal framing and opens a path toward $76,000. Losing $60,965 on a three-day close starts a different conversation, with the $54,000 zone as the next technical reference.

The range has held since early July with no break in either direction on real volume. Until that changes, the range is the trade.


ETF Flows: Three Weeks Up, Then a Friday Flush

Spot Bitcoin ETFs ran three consecutive weeks of net inflows through late July, roughly $306 million across the streak. That reversed June's $4.5 billion outflow month, the worst since the funds launched in early 2024.

The final week broke it. Net outflows hit $61.53 million for the week ending July 31, driven by a sharp move on the last trading day. Fidelity's FBTC led redemptions at $85.19 million. Grayscale's GBTC shed another $52.63 million.

BlackRock's IBIT was the outlier, posting $869.02 million in weekly inflows against the broader red tape. IBIT keeps functioning as the institutional anchor, but even that inflow could not offset redemptions across the rest of the product set.

Three weeks of inflows followed by one red week is not a trend reversal. It is a data point worth watching as August opens.


Flows over noise, every week.

The macro and Bitcoin read that skips the hopium and shows the data.

Subscribe

CLARITY Act: The Window Closed Without a Vote

Senate Majority Leader John Thune confirmed last week that the CLARITY Act will not get a floor vote before the recess. The bill is not dead, but the calendar now works against it in ways it did not in February.

The updated merged text dropped on July 22 at 616 pages, combining the Senate Banking and Agriculture drafts and adding ethics provisions barring covered federal officials from issuing or sponsoring digital assets while in office. Democrats had demanded those provisions for months. The compromise arrived too late for a floor calendar already consumed by a Russia sanctions package and a backlog of nominations.

Polymarket odds on the CLARITY Act becoming law in 2026 have fallen to roughly 28%, down from 82% in February. The bill passed the House in July 2025 with 294 votes and cleared the Senate Banking Committee in May. It has not received a full Senate floor vote. Missing August does not kill it, but it pushes the next realistic window into a fall calendar crowded by election-year politics and must-pass appropriations.

The market impact runs through what stays in place without it. The SEC and CFTC's March 17 joint guidance, classifying 16 digital assets under a five-category taxonomy, remains the operating framework. That guidance can be rescinded by any future administration without a congressional vote. A statute cannot. The longer the bill waits, the longer that reversibility sits under every institutional allocation decision.


The Fed Held. Jackson Hole Is the Next Real Signal.

The FOMC voted 9-3 to hold rates at 3.50% to 3.75% on July 29. Three officials dissented in favor of a hike. Fed Chair Kevin Warsh again withheld forward guidance in the post-meeting statement, consistent with his strategic-ambiguity approach.

The PCE price index released July 31 showed continued cooling, which softened rate-hike expectations at the margin. But three dissents on a hold is not a committee drifting toward cuts. The next FOMC is September 15 to 16. Warsh speaks at Jackson Hole on August 27 to 29, and that speech is the next real read on direction.

Bitcoin barely reacted to the hold. That tracks with how the market has treated Fed decisions all year. The live sensitivity sits in ETF flows and the legislative calendar, not the rate line itself.


Key Levels This Week

Bitcoin near $63,000 entering August 3. Support at $61,400 and $59,070. Resistance at $64,567, with $67,172 as the next target if reclaimed on volume. The $60,965 weekly floor is the structural line.

Price sits below the 20-day moving average inside a descending channel. ETH trades near $1,865 with supports at $1,807 and $1,717. XRP at $1.06, near its own channel support around $1.05.

None of the three have confirmed a breakout. All three are watching the same variables: the jobs print, ETF flows, and whatever the Senate does before it leaves town.


The Week Ahead: Dates That Matter

This is a calendar-heavy week where the macro prints and the Senate clock overlap. The dates below are the ones capable of moving price.

Date Event Why It Matters
Mon Aug 3 Senate floor opens Published schedule lists only a spending-bill vote. No CLARITY Act action.
Wed Aug 5 Cloture filing deadline Last day to file ordinary cloture for a Friday procedural vote on CLARITY.
Fri Aug 7 July NFP, 8:30am ET Consensus around 87,500 vs June's 57,000. Below 100K prices in a September cut. Above 150K pushes yields up.
Fri Aug 7 CLARITY recess cutoff Practical last chance for a 2026 Senate vote before the break.
Mon Aug 10 Senate recess begins State work period starts. Legislative window for crypto closes until fall.
Wed Aug 12 July CPI First inflation read after the July hold. Feeds directly into September rate positioning.
This week Palantir, AMD earnings Read as AI-demand signals. Palantir consensus is $1.81B revenue, up 81% YoY.

Beyond this week, Warsh speaks at Jackson Hole on August 27 to 29, and the next FOMC lands September 15 to 16. Both sit outside the immediate window but frame the back half of the quarter.

For last week's setup and what we were watching heading in: Weekly Brief: The Week the Market Celebrated Too Early


Sources

CaptainAltcoin Bitcoin Spot ETFs End Inflow Streak, Week of July 27-31

US Bureau of Labor Statistics Employment Situation Release Schedule, July 2026

CryptoNews CLARITY Act Senate Delay Drops 2026 Odds to 35%

CryptoSlate CLARITY Act Vanishes From Monday's Senate Schedule

CryptoRank Bitcoin, Ethereum and XRP Price Prediction for August 2026

CNBC Stock Market Next Week: Outlook for Aug. 3-7, 2026

BeInCrypto Bitcoin Price Prediction for August 2026: Whales Bet Against a 4-Year Losing Streak

Tools We Use

Kraken — Spot and futures on BTC, ETH, and 200+ assets.

Trezor — Cold storage. No internet connection required.

This is market commentary, not financial advice. Nothing here is a recommendation to buy or sell any asset. Do your own research.

Sunday, August 2, 2026

The CLARITY Act Is Not Stalling Over Crypto

BitBrainers - The CLARITY Act Is Not Stalling Over Crypto

By BitBrainers Editorial

The Senate leaves for its August recess in under a week and the most consequential crypto bill in US history still has no floor vote scheduled. It is not stalling over how to regulate digital assets. Every serious version of that fight was settled months ago. It is stalling over whether the sitting President should be allowed to keep earning from the industry the bill would legitimise.

Where It Actually Stands

The Digital Asset Market Clarity Act passed the House on 17 July 2025 by 294 to 134. The Senate Banking Committee advanced its portion on 14 May 2026 by 15 to 9. Since then: no floor vote, no cloture filed, no scheduled date.

The bill has been sitting on the Senate Legislative Calendar since 1 June, at number 423. Eligible for floor action for two months, never scheduled.

Industry and congressional negotiators marked 7 August as the practical deadline. Majority Leader John Thune told reporters he did not think they would get it done, adding that he would like to at least get CLARITY started.

The arithmetic is the whole problem. Republicans hold 53 seats. Cloture needs 60. That means at least seven Democrats, and under Senate Rule XXII the bill needs two separate cloture sequences, each of which typically eats most of a legislative week. Floor time that might have covered it went to a Russia sanctions package and a backlog of nominations.


What Is Actually in It

The merged text released on 22 July runs to roughly 616 pages. The core of it is a jurisdiction split. Spot markets in digital commodities go to the CFTC, investment contracts and ancillary assets stay with the SEC, and payment stablecoins fall under banking-style rules built on the already-enacted GENIUS Act. Exchanges, brokers and dealers would register with the CFTC.

Around that sit the provisions people actually argue about. A fundraising exemption lets projects raise up to $50 million a year and $200 million lifetime without full SEC registration. Intermediaries become financial institutions under the Bank Secrecy Act. Non-custodial developers get explicit protection from registration purely for writing code. Interest-like yields on idle stablecoin balances get banned while rewards tied to actual transaction activity survive. Most of it takes effect 360 days after enactment.

Worth noting what it is not. It does not touch tax treatment. Crypto remains property in the eyes of the IRS either way.


The Fight Is Not About Crypto

President Trump's 2025 financial disclosure showed roughly $1.4 billion in crypto-related income. About $636 million came from the $TRUMP meme coin and nearly $800 million from World Liberty Financial, the DeFi platform his family co-founded. A separate July disclosure tied more than $1 billion in income to his crypto ventures over the past year.

Democrats' position is structural rather than symbolic: they argue you cannot build a federal framework for an industry that produced the sitting President's single largest income stream without enforceable rules on his continued participation in it.

The White House agreed to ethics language that bars the President, Vice President, certain members of Congress, covered officials and their spouses from issuing or sponsoring a digital asset for consideration while in office, with a divestiture or blind trust requirement kicking in a year after enactment. Officials could still own crypto and would have to disclose sales.

Two details explain why that has not closed the deal. The ban sunsets on 20 January 2029, which is the end of the current presidential term, something we covered when the clause first appeared. And enforcement sits solely with the Attorney General, not state attorneys general and not private parties. So the restriction on the President expires when he leaves office and is enforceable in the meantime only by his own appointee.

Seven crypto-friendly Democrats rejected it. Angela Alsobrooks, Cory Booker, Catherine Cortez Masto, Ruben Gallego, John Hickenlooper, Mark Warner and Raphael Warnock said in a joint statement that the Republican text falls short, citing ethics alongside consumer protection, illicit finance, market integrity and DeFi regulation. Elizabeth Warren put it more directly, saying that whatever it is called, a provision that does not stop the President profiting from crypto is not an ethics provision.

Gallego, one of only two Democrats who backed the bill in committee, described the returned draft to Politico in language we will not reprint and said it was not a serious effort. He is now working on a counteroffer with Republican Thom Tillis.

Deadlines like this move fast.

We track what actually happens on the calendar, not what gets promised on it.

Subscribe

The Vote Might Happen Anyway, and Not to Pass

On 30 July, Treasury Secretary Scott Bessent publicly demanded an immediate floor vote, calling the bill floor-ready and accusing Senate Democrats of choosing politics over American leadership. Lummis amplified it, pointing to more than a hundred compromises already made and to the Fraternal Order of Police reversing its earlier opposition after the DeFi provisions were revised.

Thune has signalled he may bring the bill to the floor without the votes secured. That reads more as an election-year manoeuvre than a legislative one. Forcing senators to take a public position on crypto regulation months before November has value to Republicans whether or not the bill clears.

The risk is that it burns the negotiation. Cynthia Lummis, one of the Republican negotiators, posted that after nearly eleven months of giving almost everything asked of them, she does not know what else her Democratic colleagues need. Reporting on the talks suggests a forced vote on a text Democrats have already rejected could cause a rift that does not heal.


What the Market Thinks

Prediction markets have been brutal about this all year. Polymarket odds on CLARITY becoming law in 2026 peaked above 80 percent in February, hit a record low near 24 percent in mid-July, briefly recovered to around 45 percent when the updated text was expected, and have settled in the low-to-mid 30s as the ethics deadlock hardened. Galaxy Research cut its own estimate to 50 percent.

Worth noting what did not move those numbers. A direct public appeal from the President in mid-July produced no upward move at all, which tells you traders read the binding constraint as Democratic votes rather than presidential enthusiasm.


What Happens If It Slips

Failure before recess does not kill the bill. It pushes it into a September calendar with less momentum and then into an election year, where controversial votes get harder. Estimates of the delay range from 2027 to considerably longer. Lummis has warned that failure this year could push comprehensive federal rules out to 2030, after a Congress nobody has met yet is seated.

In the meantime the rules come from agencies rather than statute. The SEC and CFTC issued joint interpretive guidance on 17 March 2026 classifying sixteen digital assets under a five-category taxonomy, and the SEC has said it is prepared to write crypto rules if Congress does not. That is the part the industry actually fears, because interpretive guidance is not law. Any future administration can rescind it, and the whole framework reverts to enforcement discretion overnight.

Which is the real stake here, and it has little to do with this month. A statute is durable. Guidance lasts exactly as long as the people who issued it.


What to Watch This Week

One thing decides it: whether Thune files cloture on a motion to proceed before the chamber leaves. A filing typically sets up a vote two session days later, and without one there is no summer vote at all.

After that, watch whether the Gallego and Tillis counteroffer produces text the White House will accept, and whether any of the seven Democrats move publicly. If the window closes, the thing to track through autumn is whether leadership tries to attach CLARITY to must-pass year-end legislation. Lobbyists have floated that route in trade press. No senator has confirmed it.


Sen. Lummis (primary source)Merged CLARITY Act text, released 22 July 2026

CoinDeskSenators Ready to Send Stricter Ethics Rules on Trump's Crypto Ventures to White House

The HillCrypto Bill Faces Democratic Backlash Over New Ethics Rules

CoinDeskUS Senate Puts Off Crypto Clarity Act as It Focuses Limited Bandwidth Elsewhere

Bitcoin MagazineSenate Democrats Reject Clarity Act Ethics Rewrite

Crypto NewsCLARITY Act Senate Delay Drops 2026 Odds

Tools We Use

Kraken — Spot and futures on BTC, ETH, and 200+ assets.

Trezor — Cold storage. No internet connection required.

This is market commentary, not financial advice. Nothing here is a recommendation to buy or sell any asset. Do your own research.

Nobody Has a Safe Place to Put It: What Coldcard Actually Proved

BitBrainers - Nobody Has a Safe Place to Put It: What Coldcard Actually Proved

By BitBrainers Editorial

Coinkite shipped the code that lost other people's money, and nothing in what follows takes that off them. But the same category of failure has already hit the other side of the argument, the exchanges, and it hit harder. Blaming one company is correct and it is not sufficient. There is no side of this that is actually safe. Only different ways to lose.

The Number That Should Have Been the Headline

In the first half of 2026 the crypto sector recorded a record number of hacks, 207 by TRM Labs' count, most of them smart contract exploits. But the money did not follow the count. Infrastructure and key-management failures were about 15 percent of incidents and roughly 76 percent of the money stolen.

Coldcard sits in the second group, and so does every exchange breach in that same data. The exposure begins at the exact place the industry keeps losing the most money, which is how a key gets made and who holds it. That is not an obscure corner of the product. For a device whose entire purpose is generating and protecting a key, it is the product. For a custodian, it is the whole job.

We do not sell a safe answer here.

We read the failures honestly and tell you what they actually mean. That is the whole newsletter.

Subscribe

Why This Keeps Happening to Regular People

The people who lost coins on Coldcard were not careless. Many followed the exact advice the most respected names in Bitcoin were giving. The device sat on recommended-wallet lists for years. Trusting the consensus pick is not negligence.


This Was Coinkite's Failure, Start to Finish

The firmware was theirs. The change that routed seed generation away from the hardware random number generator, the device's only source of real entropy, and into a predictable software fallback went out in March 2021 under their name, in a product sold on the single promise that it would generate a key no one could guess. CEO Rodolfo Novak has said the company takes full accountability and that its review process failed to catch it. That much is not in dispute.

The context deserves more attention than it is getting. Coldcard was GPL-licensed until a competitor, Foundation, built a device on that code. Novak said publicly that he regretted the license. Coinkite moved to MIT plus Commons Clause, blocking competing derivatives, and stripped out the crypto libraries inherited from Trezor. Foundation has published a timeline showing the entropy bug entered in the same 120-file commit that removed those GPL dependencies. Foundation is a competitor with an obvious interest in that framing, but the commits are public and the dates line up.

The licensing choice has a second cost that nobody priced at the time. Source-available is not open source. Under the Commons Clause, other developers could read the code but could not legally build on it, which quietly thins out the population of people with any reason to read it closely. Five years is a long time for a seed generation routine to go unexamined in a Bitcoin product, and the license is part of why.

Then there is the response. Coinkite's first advisory on July 30 told Mk4, Q and Mk5 owners they were not affected. That was wrong, and the advisory had to be expanded the next day. In the interval, an attack was actively running and people with newer devices were reading an official statement telling them to stand down. One prominent developer publicly told Novak he had spread misinformation and said someone he knew personally had been robbed from a Mk4 seed within hours of that advisory. Samson Mow ended up telling people to migrate off every Coldcard model regardless of version, because the vendor's own guidance could no longer be relied on.

One more detail worth noting, because the week's commentary got it backwards. Coinkite's minimal data retention was treated as the reason it could not warn its own customers. In fact the company has now said it emailed every address it could reach through its store and newsletter systems, and its own store notice explains that Canadian law requires eight years of business records, so names and addresses were blanked while the email field was kept. Reaching customers during an active theft is the right call. It also means the privacy posture that was part of the pitch was never quite what buyers understood it to be.

Novak's other public framing was that the bug was likely found using AI, calling it a sober reality of the new paradigm. Read plainly, that is a company whose code lost roughly $88 million pointing at the tool that found the flaw rather than at the five years in which it did not find it itself. We covered that response in detail in our breakdown of Coinkite's statement.

The deeper issue is that the security model was never built for a normal person. Entropy bits, firmware version tracking, BIP-39 passphrases, multisig quorums, dice rolls to seed your own randomness. That is a specialist's checklist wearing consumer packaging, and most people bought the packaging.


It Is Not Over, and That Is the Point

The first wave was a clean $70 million sweep in 41 minutes. By August 2, Galaxy Research was tracking three waves totalling 1,367 BTC, roughly $88.6 million, across 4,585 addresses. The number has moved every day since the story broke, and it will likely move again after this is published.

Watch the direction of travel. The first wave went after the largest balances, pulling $30 million in ten minutes. The third is emptying wallets worth a few thousand dollars each. That progression only makes sense if the operator holds a long list of compromised seeds and is working down it by value, monetising the tail after the whales are gone.

The third wave also broke the fingerprint. The first two shared a hardcoded fee and identical batching, which is how researchers linked them. The third uses more complex, harder-to-trace patterns, and Galaxy says it cannot confirm the same operator is behind all three. Either the attacker is adapting, or others have worked out the same flaw independently. Neither is reassuring.

The reason this keeps going is structural. Coinkite's emergency firmware cannot repair a seed that was already generated. Every vulnerable seed still holding funds stays vulnerable until its owner moves the coins, and Galaxy has warned that future sweeps need not resemble the ones already mapped. This is not an incident that concluded. It is an exposure that stays open until every affected person acts, and most of them do not know they are affected.


So What Does a Normal Person Actually Do

Watch what has happened on the timelines since. Within two days, people who had just seen a consensus recommendation fail were issuing new consensus recommendations. Name a replacement device, argue that the answer is firms large enough to employ cryptographers, move on. Almost none of it comes with more verification than the advice that put Coldcard on every recommended-wallet list to begin with.

That is the mechanism, and it is running again right now. The problem was never that people picked the wrong brand. It was that a brand recommendation was ever load-bearing for something this consequential.

So the honest answer is that there is no zero-risk option, and anyone selling you one is selling something. What exists is a set of trade-offs you get to choose between with open eyes.

Self-custody removes the counterparty who can freeze or lose your funds, and hands you the entire job of key security, firmware, and backups. An exchange removes the technical burden, and reintroduces the counterparty, the honeypot, and the interface you cannot see behind. Both are real risks. Neither is theoretical.

The most defensible posture is not picking a winner. It is refusing to concentrate. Do not put everything on one device, one vendor's firmware, one exchange, or one signing method. Spreading holdings across independent failure modes will not stop a loss. It stops a single loss from being total.

For anyone rebuilding after this, the concrete version is keys split across manufacturers, a Trezor hardware wallet beside a different vendor in a multisig quorum. Not because that vendor is trustworthy. Because no single vendor has to be.


Why This Does Not End With Everyone in Custodians

Follow the argument to its usual conclusion and you get: most people cannot do this safely, so most people should hand their coins to someone who can. A lot of this week's commentary lands exactly there, and the ETF and treasury-company flows suggest the market already agrees.

The objection is concentration. Enough Bitcoin in a few custodians rebuilds the seizure risk the thing was built to route around. What stops that from being terminal is a property gold never had. You can leave. Any holder can open a wallet, demand settlement, and have final possession in minutes, globally, for a few dollars. Most gold was never in its owner's hands, and you could not demand it be moved from London to Singapore this afternoon.

So custody concentrates only as long as the custodians stay worth using. The exit is what keeps them honest, and the exit only exists because self-custody remains possible for anyone who wants it. That is the case for keeping these skills alive even in a week that made them look dangerous.


The Part Nobody Wants Printed

Here is the sentence the industry avoids. In its current form, self-custody asks for a level of technical fluency that most people holding Bitcoin do not have and should not be expected to acquire overnight.

Read the failures, spread the risk, and distrust anyone who tells you one product ends the problem. That is not a satisfying conclusion. It is the accurate one, and the accurate one is the only kind worth publishing.


TRM LabsH1 2026 Crypto Hacks Reach Record High as Losses Fall Below $1 Billion

Crypto BriefingCrypto Records Most Hacked Half-Year Ever With 212 Exploits and $1.1 Billion Stolen

CoinDeskHow Bitcoin Cold Wallets Lost $70 Million in an Attack That Never Touched the Devices

CoinDeskBitcoin Cold-Wallet Attack Spreads to 4,500 Addresses as Losses Near $89 Million

The BlockCoinkite Issues Warning for Coldcard Mk3 Users Amid 594 BTC Theft Reports

ForbesUrgent Warning Issued After Sudden Spread Of Massive Bitcoin Attack

This is market commentary, not financial advice. Nothing here is a recommendation to buy or sell any asset. Do your own research.

Saturday, August 1, 2026

Your Hardware Wallet Might Already Be Broken

BitBrainers - Your Hardware Wallet Might Already Be Broken

By BitBrainers Editorial

It is tempting to read the Coldcard drain as a single company's mistake. That reading is too comfortable. In the space of about two months, three separate cryptographic flaws surfaced in crypto code that had all passed review, all of them years old, all found in a narrow window. Coldcard is the loudest one. It is not the only one, and the pattern is the actual story.

Three Failures, Three Layers

Start with the timeline, because the clustering is the point. In late May, security firm Coinspect disclosed a flaw it named Ill Bloom: a broken random number generator in certain mobile software wallets that made recovery phrases guessable. Affected wallets dated back to 2018. At least $5 million was drained, most of it Bitcoin.

Around the same window, Zcash disclosed a flaw of a different kind entirely. Not in a wallet, but inside the mathematical circuit that proves its private transactions are valid. A gap in the proving code that could, in theory, have allowed counterfeit ZEC. Zcash ran an emergency hard fork on July 28 to wall off the affected pool.

Then Coldcard, at the end of July. The same failure family as Ill Bloom, weak seed generation, but in the hardware wallets people had been told to trust precisely because software wallets kept failing. Roughly $70 million gone in 41 minutes.


The Detail That Ties Them Together

Here is the part worth sitting with. When Coinspect disclosed Ill Bloom, it said hardware wallet users appeared to be safe. That was true, for that flaw. It was also the advice that pushed exposed users toward hardware devices.

Weeks later, the hardware devices had their own entropy failure. The safe harbor from one bug was the epicenter of the next. Nobody was lying. The ground simply kept moving.

These were not the same bug or the same team. What they share is a category: old cryptographic code, sitting in production for years, doing something subtly wrong that nobody caught until someone went looking with the right tools.

Patterns matter more than incidents.

We connect the failures nobody else is connecting. Get the next one before it is obvious.

Subscribe

Why Old Code Is Suddenly Dangerous

For years, the industry treated survival as proof of safety. If a wallet or a library ran for five or ten years without incident, it was assumed sound. That assumption was always weaker than it looked.

A vulnerability that was never worth the enormous manual effort to find can become worth finding the moment that effort drops. Reading an unfamiliar codebase line by line, tracing dependencies, spotting one inverted check among thousands, used to take specialist time most attackers would not spend.

Coinkite said it plainly about its own bug: the code had been public since 2021, and the company has to assume someone used AI to review old versions of the firmware and found what human auditors, including a leading AI model Coinkite itself ran weeks earlier, had missed. We covered that admission in detail in our breakdown of Coinkite's response.

The uncomfortable implication is not about one vendor. It is that the cost of finding dormant bugs has fallen for everyone, defenders and attackers alike, and the attackers only need one.


What Is Actually Exposed

Bitcoin Core itself is not the worry here. It is probably the most reviewed open-source code in existence, with hundreds of people picking apart every proposed change. The danger lives in the sprawl around it.

Wallets, firmware, signing libraries, bridges, exchange infrastructure, swap tools. An enormous surface of code, most of it reviewed far less thoroughly than Core, much of it depending on the same handful of underlying libraries. Ill Bloom, Coldcard, and the Zcash circuit flaw all lived in that surrounding layer, not in a base protocol.

That is where the next one will come from too. Not a break in Bitcoin's core math, but a forgotten piece of the ecosystem that held enough money to make the search worthwhile.


What This Changes for You

The takeaway is not to panic or to abandon self-custody. It is to stop treating any single product's track record as a guarantee. Five clean years means the bug was expensive to find, not that it was never there.

The practical response is the same discipline that survives every one of these events: do not concentrate. Spreading holdings across independent devices, vendors, and methods will not prevent a flaw. It stops any one flaw from taking everything.

None of these three incidents touched a properly diversified setup for its full value. That is not luck. It is the one defense that works when the thing you trusted turns out to have been broken since the day you bought it.


The Hacker NewsAttackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets

TechTimesZcash Ironwood Launches Tuesday: Supply-Verification Checkpoint Closes Four-Year Flaw

CoinDeskHow Bitcoin Cold Wallets Lost $70 Million in an Attack That Never Touched the Devices

This is market commentary, not financial advice. Nothing here is a recommendation to buy or sell any asset. Do your own research.

Saylor's Company Lost 8.3 Billion on Paper

BitBrainers - Saylor's Company Lost 8.3 Billion on Paper

By BitBrainers Editorial

Strategy reported one of the largest quarterly losses in its history on Thursday. Michael Saylor's company also added more Bitcoin than almost any quarter before it. Both of those sentences are true, and reading only the first one is how most of the coverage got this wrong.

The Loss Everyone Is Reading Wrong

Strategy's operating loss for Q2 came in around $8.3 billion, and roughly $8.32 billion of that was a single line item: a non-cash, unrealized write-down on its Bitcoin holdings under fair-value accounting.

That accounting rule, formally ASC 350-60, took effect for public companies last year. It requires Bitcoin holdings to be marked to market every quarter, meaning the balance sheet now moves with the price whether or not a single coin gets sold.

Nothing left the company because of this loss. It is a valuation entry, not a wire transfer. The reported net loss figure varied slightly across outlets, some cited $8.6 billion, others closer to $8.2 billion, but the underlying driver was the same $8.32 billion mark-to-market swing every time.


What Strategy Actually Did With the Quarter

While the accounting line went negative, the company added 83,901 BTC during the quarter at an average price near $75,500, bringing total holdings to 843,775 BTC. That is roughly 4 percent of every Bitcoin that will ever exist, by the company's own count.

Holdings are up 25 percent since the start of 2026. More telling is the metric Strategy wants shareholders watching instead of GAAP earnings: Bitcoin per share, which rose from 201,170 to 210,824 satoshis, a 5 percent gain in a single quarter, despite meaningful share dilution from ongoing capital raises.

The stock moved higher in the after-hours session following the print. Investors appear to have looked past the headline loss to the accumulation number underneath it, which is exactly the read Strategy has spent two years training the market to make.


Q2 2026 at a Glance

The headline loss and the accumulation number, side by side.

METRIC Q2 2026
Total Bitcoin holdings 843,775 BTC
Bitcoin added this quarter 83,901 BTC
Average purchase price ~$75,500
Share of total Bitcoin supply ~4%
Holdings growth since Jan 1, 2026 +25%
Bitcoin per share (BTC yield metric) 210,824 sats (+5% QoQ)
Software revenue $122.4M (+6.9% YoY)
Operating loss ~$8.3B
Unrealized Bitcoin write-down (non-cash) $8.32B
Convertible debt outstanding $8.21B → $6.71B
STRC preferred stock (target $99-100) ~$89.50

Reported net loss varied slightly by outlet, roughly $8.2B to $8.6B, depending on which line items were included. The operating loss and the $8.32B Bitcoin write-down were consistent across every source.

The headline number is rarely the real one.

We read past it every time. Get the actual story in your inbox.

Subscribe

Saylor's Framing, and Why It Isn't Wrong

On the call, Executive Chairman Michael Saylor described Bitcoin as the winner of the "digital capital network race" and said the company's real opportunity now sits in building credit infrastructure on top of it, not in the software business that once defined MicroStrategy.

That is not new bravado. It is the same thesis the company has run since it went all-in on Bitcoin years ago. What changed is that fair-value accounting now forces that volatility onto the income statement every single quarter instead of leaving it in a footnote.

The framing held while the accumulation was real. What changed this quarter is that the company stopped treating accumulation as automatic, which makes the credit-infrastructure language less a vision statement than a description of where the balance sheet is actually headed.


The Part of the Story That's Actually Risky

Strategy's preferred stock, STRC, was trading near $89.50 against a $99 to $100 target range. The company is running a $1 billion buyback, with roughly $975 million still unused, aimed at getting STRC back to par by a September 8 target date.

And the buying has stopped. Strategy has now gone five consecutive weeks without a Bitcoin purchase, its longest confirmed pause in nearly two years, with holdings flat at 843,775 BTC while the ATM programs kept running. Dollar reserves stood at $3.75 billion as of 26 July.

On the debt side, the company repurchased $1.5 billion of convertible notes at an 8 percent discount, cutting convertible debt outstanding from $8.21 billion to $6.71 billion. That is a genuine deleveraging move sitting inside the same quarter as the headline loss.

One more fact worth stating plainly: Rosen Law Firm opened a securities investigation in June into whether Strategy and its executives made materially misleading statements about the Bitcoin strategy and the risks in its preferred securities. No complaint has been filed as of this writing, and an investigation is not a finding of wrongdoing. It is, however, a fact of the current situation and belongs in any honest account of it.


The Part That Actually Changed

The accounting loss led every headline. The more consequential disclosure came from the call itself, and it got far less attention.

President and CEO Phong Le said Strategy will sell Bitcoin whenever management considers it advantageous, and that investors should expect it may do so going forward. That is not hypothetical. The company already completed its largest-ever Bitcoin sale earlier this year, roughly 3,588 BTC, under what it calls its BTC Monetization Program, with proceeds going toward preferred dividend obligations.

Management also said future capital raises will no longer flow entirely into Bitcoin. Proceeds will be allocated dynamically between Bitcoin and US dollar reserves depending on market conditions, liquidity needs, and corporate obligations. Bitcoin-backed borrowing was explicitly ruled out, citing counterparty and margin risk.

For a company whose entire identity was built on never selling, that is the story. The automatic link between raising capital and buying Bitcoin is gone. Investors can no longer read a share sale as a coming purchase, and the company has told them in plain terms to expect sales.


What This Sets Up

Strategy's structure now leans on Bitcoin's price to service two separate obligations on two separate timelines: defending STRC's par value by September, and meeting convertible note put dates further out in 2027. Both make the company more exposed to a sustained drawdown than "they just bought more Bitcoin" suggests on its own.

STRC pays a 10 percent annual dividend, distributed monthly. That obligation keeps running regardless of Bitcoin's price. The September 8 target is not a soft goal. If STRC stays below par through that date, it signals to the market that the preferred dividends are not comfortably covered by the Bitcoin treasury model, which feeds directly into the 2027 convertible note put dates where holders can demand repayment. The dividend is not the risk. The sequence is.

This quarter is effectively the template other Bitcoin treasury companies will either follow or avoid. Anyone who wants Bitcoin exposure without taking on that layered corporate debt and preferred-equity structure has a simpler option: holding it directly through a platform like Kraken rather than through MSTR's equity.

The real test is not this quarter's accounting print. It is whether Bitcoin's price stabilizes enough for STRC to reach par by September 8. That date matters more to Strategy's near-term stability than anything in Thursday's headline number.


CoinpediaStrategy Ends Its Buy Every Dip Bitcoin Strategy, Here's What's Replacing It

FinanceFeedsStrategy Says It Will Continue Selling Bitcoin and No Longer Allocate All New Capital to BTC Purchases

Yahoo FinanceMicroStrategy Q2 2026: Bitcoin Accumulation Accelerates Despite Accounting Loss

Investing.comEarnings Call Transcript: MicroStrategy Q2 2026 Loss Deepens as Bitcoin Bets Weigh

CoinSpeakerStrategy Q2 2026: $8.6B Loss Driven by Bitcoin Accounting

TheStreetStrategy Misses Q2 Earnings Estimates by a Wide Margin

TechTimesStrategy Q2 Earnings Due Tonight: $8.3B Bitcoin Loss and Capital Model Under Test

This is market commentary, not financial advice. BitBrainers holds Bitcoin and other digital assets. Nothing here is a recommendation to buy or sell any asset. Do your own research.

Coinkite Blames AI for the Bug, and the Attacker Left a Paid Account Behind

BitBrainers - Coinkite Blames AI for the Bug, and the Attacker Left a Paid Account Behind

By BitBrainers Editorial

Three days ago, Coldcard's entropy bug was one bad number. It has since split into two disputed totals, a vendor admission about AI, and a paper trail that ends at a blockchain data provider's billing account. Here is what actually changed since the last update, and why the total will likely keep moving.

Two Firms, Two Totals, Same Bug

Chainalysis put the damage at roughly $38 million as of Friday, tracing about 500 wallets swept in a tight 25-minute window. Galaxy Research and Block's own engineering team came in far higher: 1,196 addresses, 1,082.65 BTC, worth close to $70 million, across a wider 41-minute span.

The gap is not a disagreement about the bug itself. It is a disagreement about which transactions belong to the same attacker, since the two firms drew the boundary of "this event" differently and neither has finished counting.

Independent trackers were already citing a higher total by Saturday morning, unconfirmed by either firm. If you want the original entropy breakdown and the first 594 BTC sweep, our July 31 breakdown covers that from the start.


What We Know So Far

Four consolidation addresses account for most of the confirmed total. None have moved since the sweep.

CONSOLIDATION ADDRESS BTC STATUS
bc1qq85v2c9...cu9r 562.02 ● unmoved
bc1qx76cae2...fhe3 398.48 ● unmoved
bc1q8jy96fe...tp3q 89.62 ● unmoved
bc1qnk4zh9q...fecp0 32.45 ● unmoved

That's roughly 1,082.5 of the 1,082.65 BTC Galaxy Research attributes to the full sweep, accounted for across four wallets. Figures per Galaxy Research's on-chain mapping, corroborated by Block. Verify any balance directly on a block explorer rather than a third-party dashboard.

The Attacker Went for the Largest Wallets First

Chainalysis's timeline adds the most interesting new detail. In the first 10 minutes, the attacker had already pulled roughly $30 million, hitting the largest wallets before working down the list.

Three of the ten biggest affected wallets held at least 10 BTC each. That is not opportunistic scanning. The list was sorted by value before the first transaction was broadcast.

Sorting by balance ahead of time means the attacker had visibility into wallet holdings before touching a single signing key, which points to a reconnaissance phase that likely ran for weeks.

Numbers like this change fast.

Get the reconciled totals and the next disclosure the moment they land.

Subscribe

Coinkite's Own Explanation Is the Uncomfortable Part

Coinkite has now said it has to assume "someone used AI to review previous versions of our firmware" to find the bug, since the code has been sitting in public view since 2021.

The company also disclosed it ran a leading AI model over its own codebase a few weeks before the attack happened. That review did not flag the issue either.

Set that next to the forum's own technical read: a #define versus #ifdef mismatch, invisible unless someone traced the macro logic line by line. Five years of public code, and the people paid to audit it were not the ones who found it.


A Billing Account May Be the Attacker's Only Mistake

Block's Bitkey engineering lead, Clay Garrett, said investigators confirmed "the operator used a paid account at a well-known blockchain-services provider" to query source addresses during the sweep.

The provider's internal logs reportedly matched the timing and sequence of the attack closely enough that Block is calling the finding confirmed rather than suspected. Authorities have been notified.

None of this means an arrest is close. The cryptographic work here was close to flawless, and the target list was sorted by balance before a single key was touched. What the operator did not avoid was one ordinary point of contact with a company that keeps records.


What Actually Changes If You Own One

Coinkite shipped mandatory patches: firmware 5.6.0 for Mk4 and Mk5, 1.5.0Q for the Q model. There is no patch for Mk3 or Mk2, because the fix is a new seed, not a firmware update.

Updating firmware does not make an old seed safe by itself. The actual fix is generating a brand new seed on updated hardware, verifying the receive address on-device, and testing with a small transaction before moving the rest.

If you are rebuilding anyway, this is also the moment to consider spreading the risk across manufacturers instead of trusting one vendor's firmware for everything, which is the whole case for something like a Trezor hardware wallet as a second device in a multisig setup.


The Bigger Argument This Reopens

Bitcoin Core developer instagibbs independently reproduced the vulnerability, which closes any remaining doubt that this is real. The technical story is essentially finished. The institutional one is not.

Analysts are already using the incident to argue that self-custody has quietly built up its own operational risk, the kind that nudges undecided holders toward regulated custodians and spot ETFs instead of a hardware wallet in a drawer.

Price barely moved through any of this. BTC held its key support level the whole time, which says more about how numb the market has gotten to security headlines than about how serious this particular one actually is.


CoinDeskHow Bitcoin Cold Wallets Lost $70 Million in an Attack That Never Touched the Devices

Bitcoin MagazineColdcard Bitcoin Thief Likely Used Top Blockchain Services Provider

CybernewsAI Might Have Helped Hackers Steal $38M in Bitcoin

AMBCryptoColdcard Seed Flaw Linked to $38M Bitcoin Theft as Loss Estimates Continue to Rise

CoinDeskColdcard's $38 Million (So Far) Exploit Shakes Faith in Self-Custody, May Push Investors to ETFs

This is market commentary, not financial advice. Nothing here is a recommendation to buy or sell any asset. Do your own research.

Friday, July 31, 2026

Tether reserve buffer Q1 vs Q2 2026

BitBrainers - Tether reserve buffer Q1 vs Q2 2026

Tether reserve buffer — assets minus liabilities, Q1 vs Q2 2026. Source: Tether Q2 2026 attestation, BDO Italy.

By BitBrainers Editorial

Tether published its Q2 attestation on Friday. Net operating profit of $1.5 billion, up almost 50% from Q1. Fourteen more tons of gold. USDT circulation at $184.6 billion and over 60% of the stablecoin market. Every outlet led with those numbers. The one that needed explaining was the reserve buffer, which fell from $8.23 billion to $4.11 billion in three months.

What the Buffer Is and Why Halving Matters

The reserve buffer is the gap between what Tether owns and what it owes. As of June 30 the company reported $187.75 billion in assets against $183.64 billion in liabilities, leaving $4.11 billion of surplus.

Three months earlier that surplus was $8.23 billion. The liabilities barely moved, up roughly $110 million. The entire change came from the asset side, which fell about $4 billion.

That is the part worth sitting with. A company that earned $1.5 billion in the quarter still ended it with $4 billion fewer assets than it started with.


Where the Four Billion Went

Roughly $1.8 billion of it is explainable directly from the report. Tether marks its gold and Bitcoin holdings to market, and both fell in Q2.

Gold holdings went from $19.84 billion to $18.84 billion, a loss of $1 billion, and that is after buying 14 additional tons. The tonnage rose from 132.2 to 146.2 while the dollar value dropped, because the gold price fell around 15% during the quarter to just over $4,000 an ounce.

Bitcoin holdings went from $6.62 billion to $5.80 billion, a loss of $820 million. Same story: Tether added roughly 1,796 coins to reach 98,933 BTC, while the price used in the reports fell from $68,200 to $58,600.

So two of Tether's hard-asset positions grew in size and shrank in value at the same time. Add the $1.5 billion of profit that should have pushed assets up, and there is still a gap of several billion the attestation does not account for.

Capital movements out of the company are the obvious candidate. Tether's Q1 report disclosed $854 million in net capital movements alongside profit. The Q2 announcement gives no equivalent breakdown, and BDO's attestation confirms balances rather than explaining them.

Most coverage stopped at the headline number.

We read the attestation. Weekly, free, no filler.

Subscribe

The Case That This Is Fine

A fair reading says none of this is alarming. The buffer is still positive. Assets still exceed liabilities. The profit engine, interest income from short-duration Treasuries and repurchase agreements, is intact and producing more than it did last quarter.

Tether also cut secured lending by $2.38 billion, about 15%. Secured loans have been the least transparent line on that balance sheet for years, and shrinking them genuinely reduces risk. That is a decision in the right direction.

USDT grew by $446 million in circulation while the total stablecoin market contracted. Tether took share in a shrinking market and added more than 30 million users. A stablecoin losing float is a far harder problem than one gaining it, and Tether is not losing float.


The Case That It Is Worth Watching

A $4.11 billion buffer against $184.6 billion of liabilities is a cushion of about 2.2%. Three months ago it was 4.5%. Neither number is insolvency. The direction of travel is what changed.

The mechanism is also uncomfortable. Part of the buffer's decline came from gold and Bitcoin falling in price, which means the cushion partly depends on two volatile assets holding their value. Hard assets are a reasonable long-term bet. They are a strange choice for the layer that absorbs short-term shocks.

Then there is the audit. Tether reports through attestations from BDO Italy, which verify that reported balances match what BDO observed at a point in time. That is not the same as a full audit, and Tether has been describing a Big Four audit as in progress for several years without one appearing.


Why This Is Not Only Tether's Problem

USDT sits at over 60% of the stablecoin market. It is the base pair for a large share of crypto trading volume, a standard collateral asset across DeFi, and the settlement rail for cross-border flows in markets where dollar access is difficult.

That concentration means Tether's balance sheet is load-bearing for the whole asset class. A stablecoin at 60% market share does not have private problems.

None of which is a prediction. Tether is profitable, liquid, growing share, and holding an enormous pile of Treasuries, gold, and Bitcoin. The point is narrower: a buffer that halves in one quarter is the kind of number that deserves an explanation, and the report did not give one.


The Backdrop

Tether is among the largest private holders of U.S. government debt in the world. Its year-end 2025 report put direct and indirect Treasury exposure near $141 billion, and the Q2 profit came from exactly that exposure.

Meanwhile the U.S. national debt sat at $39.68 trillion on July 23 and has been rising roughly $41 billion a day, which puts the $40 trillion line right about now. Net interest costs are projected above $1 trillion for fiscal 2026.

Tether earns its money from that debt and converts part of the proceeds into physical gold in Switzerland. Whether you read that as a hedge or as an opinion about where this is going, the company has been doing it consistently for two years.

We looked at how to weigh conflicting signals in a soft market in Fear and Greed Says Buy. MVRV Says Not Yet. The Tether numbers belong in the same file: useful, incomplete, and worth revisiting next quarter.


What to Check in October

Three things in the Q3 attestation will say more than anything in this one. Whether the buffer recovers toward $8 billion or keeps sliding. Whether Tether discloses capital movements alongside the profit figure. And whether the Big Four audit moves from "in progress" to published.

If gold and Bitcoin recover in Q3, part of the buffer comes back on its own without Tether doing anything. That would tell you the halving was mostly mark to market. If the buffer keeps falling while those assets recover, that is a different story entirely.


Sources
CoinDesk: Tether posts $1.5 billion operating profit in Q2 as reserve buffer falls by half
Yahoo Finance: Tether reports $1.5B Q2 profit as USDT supply grows, gold holdings rise
Bloomingbit: Tether posts $1.5 billion in Q2 operating profit, gold holdings top 146 tons
IndexBox: U.S. national debt reaches $39.676 trillion, latest Treasury data shows record high

This is market commentary, not financial advice. Nothing here is a recommendation to buy or sell any asset. Do your own research.

Weekly Brief: Bitcoin Just Broke a Two-Month Range. Here Is What Matters This Week.

By BitBrainers Editorial Bitcoin broke a two-month range with a 24% weekly candle. The Treasury buyback was the match. The squeeze di...

Weekly Brief: Bitcoin Just Broke a Two-Month Range. Here Is What Matters This Week.