The attacker associated with the third wave of Coldcard wallet thefts has begun moving more bitcoin, routing earlier transfers through THORChain to Ethereum and sending newer movements into CoinJoin rounds. Galaxy Research described the activity in a Sept. 7 on-chain update and said the exploiter had created 293 two-of-two multisignature vaults for victims’ coins.
The update documents wallet behavior, not the attacker’s identity or intent. Moving funds through cross-chain infrastructure and collaborative Bitcoin transactions can complicate tracing, but it does not by itself prove that the proceeds have been successfully laundered.
Wave 3 funds start leaving their vaults Galaxy said the first movements in this wave occurred on Sept. 2, when coins were sent through THORChain and arrived on Ethereum. The research firm then observed subsequent transfers entering CoinJoin rounds. Its public post did not provide a final amount moved or say that every vault had been emptied.
A CoinJoin combines inputs and outputs from multiple participants in one Bitcoin transaction. That construction makes straightforward transaction-graph analysis more difficult because an observer cannot simply assume that each input maps to a specific output. Investigators can still use timing, amounts and later spending behavior, but confidence in attribution can fall.
The latest movement follows the larger Coldcard incident Galaxy previously connected the third wave to hundreds of attacker-created vaults. Earlier reporting on the Coldcard exploit and affected bitcoin described a broader theft involving compromised wallet generation. The newest transfers change the case from largely stationary holdings to an active tracing problem.
THORChain and CoinJoin play different roles in that path. THORChain enables swaps across native assets, while CoinJoin operates within Bitcoin by combining transactions. Neither tool is inherently malicious; the relevance here comes from their observed use by addresses Galaxy associates with the exploiter.
Wallet remediation remains separate from fund tracing Following stolen funds does not repair a compromised seed. Users affected by weak wallet generation must create a fresh seed with corrected software or trusted hardware and transfer remaining assets. Simply installing new firmware cannot make an already exposed recovery phrase secret again.
Galaxy’s update gives investigators a new sequence to monitor, but recovery is not guaranteed. Any definitive claim about attribution, the amount mixed or the destination of swapped assets will require additional on-chain evidence and, potentially, information from services that receive the funds.
AUTHOR
Blockchain analyst specializing in the regulatory impact of government policies on the crypto industry. Known for his thorough research and clear, engaging writing, Emmanuel provides insightful analysis on the latest trends, market shifts, and emerging crypto innovations. His work aims to educate and inform both novice and experienced readers, offering expert perspectives on the fast-evolving world of digital assets. With a passion for staying ahead of the curve, Ogwu is a trusted voice in the cryptocurrency and blockchain space.
The operator behind the so-called Wave 3 cluster of Coldcard hardware-wallet thefts has begun systematically cashing out stolen bitcoin after weeks of inactivity, according to a Monday update from Galaxy Research.
Galaxy’s on-chain team says the actor created 293 separate 2-of-2 multisignature vaults, one for each victim grouping, rather than funneling coins into a shared collector as earlier waves did.
Those vaults held about 208 bitcoin after the late-July and early-August sweeps.
Starting September 2, the operator began spending the largest holdings first.
By September 7 it had emptied ranks 1 through 11, moving 97.09 bitcoin from 12 vaults.
The next ten unspent vaults still contain 30.81 bitcoin; vaults ranked 61 through 293 hold another 33.77 bitcoin combined.
Two hundred eighty-two vaults remain untouched with 116.98 bitcoin.
The first large exit, on September 2, sent 20.50 bitcoin across THORChain into two Ethereum addresses that were later emptied.
Subsequent spends on September 5 and 6 routed coins into CoinJoin mixing rounds after brief hops through Taproot addresses.
Galaxy calculates that the Wave 3 operator has now moved roughly 45 percent of the coins taken in that cluster, sending them either to Ethereum via THORChain or into CoinJoin denominations.
The Coldcard Wave 3 operator has been methodically moving the largest thefts in order by size rank. They have spent ranks 1–11 in order; the next ten unmoved vaults hold 30.81 BTC. Ranks 61–293 hold 33.77 BTC between them. pic.twitter.com/iV09c1JwaL
— Galaxy Research (@glxyresearch) September 7, 2026
The same spending also revealed a previously unlisted 58-address cluster that used an identical 2-of-2 script and was co-spent into a hop that funded a CoinJoin.
Galaxy currently labels the cluster “cause = open” but considers it likely another Coldcard victim set.
If confirmed, Wave 3 would expand to 294 vaults and Galaxy’s published high-confidence total for the entire exploit would rise to about 1,806 bitcoin.
Across the wider investigation, Galaxy estimates that about 82 percent of coins it attributes to the Coldcard vulnerability still sit in original attacker-controlled addresses, while about 18 percent have been moved in patterns consistent with laundering.
The 45 percent figure applies only to the Wave 3 vaults now being spent.
The thefts stem from a firmware defect introduced in March 2021 that weakened seed generation on certain Coldcard models, allowing offline reconstruction of private keys for single-signature addresses created after that date.
Coinkite published an advisory and fixed firmware; existing weak seeds cannot be repaired and must be replaced.
Galaxy has documented multiple distinct waves and footprints and has said it cannot confirm whether they belong to one actor or several.
Researchers continue to work with victims so they can file reports with authorities and have shared suspected attacker addresses with investigators and industry partners. Additional victims are still coming forward, but Galaxy has not identified confirmed new attacker activity after August 6 except for these later movements of already-stolen coins.
The hacker behind the third wave of Coldcard hardware wallet exploits has started cashing out, routing approximately 97.09 BTC, worth about $7.8 million, through cross-chain swaps and mixing services over a five-day window. Galaxy Research flagged the movement on September 7, noting it represents roughly 45% of the Wave 3 stolen funds.
The funds first hit THORChain on September 2, where they were swapped into Ether. By September 5 and 6, additional portions had been run through CoinJoin transactions, a Bitcoin privacy technique that bundles multiple users’ transactions together to obscure the trail. The attacker appears to be working through the largest vaults first, a prioritization strategy that suggests deliberate planning rather than panicked liquidation.
A firmware flaw five years in the making A firmware update shipped by Coinkite in March 2021 (version 4.0.1 onward) introduced a bug that caused Coldcard devices, primarily the Mk3 and later models, to default to a software-based pseudo-random number generator when creating wallet seeds. The hardware random number generator was effectively bypassed.
Advertisement
The result: seeds generated with only 40 to 72 bits of effective entropy. For context, modern cryptographic standards typically call for 128 to 256 bits. Skilled attackers could reconstruct private keys entirely offline through brute-force computation.
Coinkite eventually patched the firmware, but any wallet seed generated during the vulnerable window remains compromised regardless of whether the device itself has been updated. The company has urged affected users to generate entirely new seeds and migrate their funds.
The full scope: 1,789 BTC across 8,865 addresses Galaxy Research, led by analyst Alex Thorn, has been tracking the Coldcard exploit chain since the attacks began on July 30, 2026. Total confirmed losses stand at approximately 1,789 BTC, valued at around $114.7 million at the time of theft. More than 8,865 addresses have been affected, with the median victim losing more than 1 BTC. An additional cluster of 58 addresses has been identified that could push total losses to roughly 1,806 BTC.
The attacks came in waves. The first wave alone extracted 1,082.65 BTC in just 41 minutes, a staggering pace that points to automated scripts scanning the blockchain for weak keys. Galaxy’s research suggests at least 15 different attackers were involved across the waves, which ran from July 30 through August 6. Activity dropped sharply after that.
Of the total haul, 82% of stolen Bitcoin remains sitting in attacker-controlled wallets. Only 18% has shown movement consistent with laundering. Galaxy’s team has engaged directly with over 190 victims and shared identified attacker addresses with law enforcement agencies and industry partners.
THORChain’s uncomfortable spotlight The attacker’s choice of THORChain as a laundering vehicle is notable but not surprising. The decentralized cross-chain liquidity protocol enables swaps between native assets on different blockchains without requiring a centralized intermediary. THORChain’s permissionless architecture means it can’t freeze or reverse transactions the way a centralized exchange can.
The subsequent use of CoinJoin adds another layer of obfuscation. By mixing the converted funds with legitimate Bitcoin transactions, the attacker makes chain analysis significantly harder, though not impossible. Firms like Chainalysis and Elliptic have developed increasingly sophisticated tools for de-mixing CoinJoin outputs, and law enforcement has successfully traced CoinJoin-laundered funds in prior cases.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
The individual responsible for the third wave of the Coldcard wallet hack has transferred around 45% of the stolen Bitcoin, according to Galaxy Research. The funds have been routed through THORChain as well as CoinJoin transactions in an effort to obfuscate their origins.
Large-scale movements tracedOn September 2, Galaxy Research reported that the hacker began moving Bitcoin through THORChain to swap into Ethereum, marking a significant step in laundering the stolen assets. The most recent activity involved sending funds into CoinJoin rounds, which aggregate payments from multiple users within a single transaction to mask individual sources.
The research team found that the exploiter established 293 two-of-two multisignature vaults to store the illicitly acquired Bitcoin. The hacker has been systematically draining the funds, starting from the largest vaults and proceeding in descending order by size. So far, withdrawals from the 11 biggest vaults have been completed.
These transfers enabled Galaxy Research to spot a previously unidentified vault that appeared to contain assets from another Coldcard wallet victim. However, the circumstances leading to this loss have not yet been verified.
Ongoing laundering effortsGalaxy Research calculated that 82% of all Bitcoin stolen across the Coldcard wallet exploit waves is still parked in addresses believed to be under attacker control. The remaining 18% has been moved, likely as part of ongoing attempts to launder the proceeds and further complicate tracking efforts.
Galaxy identified systematic fund movements from sizable multisignature vaults, and noted the use of protocols like CoinJoin and THORChain to layer transactions and increase privacy while dispersing the stolen Bitcoin.
The Coldcard exploit now stands as the third-largest crypto attack so far in 2026, as indicated by data from DefiLlama. Only the $293 million Kelp DAO breach and the $280 million Drift protocol incident eclipsed the Coldcard case in scale this year.
Security landscape and investor toolsIncidents like the Coldcard breach highlight the need for vigilant monitoring of digital asset flows and market events. Sudden protocol exploits and high-profile listings can trigger market shifts within seconds, impacting users and liquidity. In this fast-moving environment, investors can be at a disadvantage if forced to switch between multiple apps for charts, news, or portfolio updates.
Seeking to address these challenges, many traders are turning to privacy-oriented platforms such as CryptoAppsy, which streamline all essential features. With instant access to real-time charts, price notifications, token-specific news, and macroeconomic data—all without requiring account creation—traders can respond faster to developments that may affect their holdings or risk exposure.
Sandwich attacks are a form of maximal extractable value (MEV) and a persistent cost for DEX traders. Between November 2024 and October 2025, they extracted an estimated $60 million from Ethereum users across 60,000 to 90,000 attacks per month.
THORChain addresses this through an alternative execution model designed to make these attacks unprofitable. Let’s explore how MEV works and how THORChain prevents it.
What Is a Sandwich Attack?A sandwich attack is a strategy where a bot pays to place one trade immediately before a user's swap and another immediately after it, capturing the price movement the user's own trade creates.
When a trader submits a transaction on a chain like Ethereum, it enters a public waiting area called a mempool. Block builders then select which transactions to include and determine their order within the block.
Because pending transactions can be seen before they're executed, bots can identify large swaps that are likely to move an asset's price. This lets them pay block builders to position their own transactions before (front-running) or after (back-running) the trader's swap, and profit from the resulting price movement.
Front-running occurs when an attacker identifies a pending transaction and submits another one with a higher gas fee, ensuring it's processed first. The attacker aims to benefit from the price movement the original transaction is expected to create.
Back-running occurs when an attacker places a transaction immediately after a large trade. By anticipating how the first transaction will affect the market price, the attacker can trade on the resulting movement.
A sandwich attack combines both strategies. The bot first buys the asset ahead of the user’s transaction, pushing the price higher before the user’s swap executes. The user then trades at a worse price and receives fewer tokens than expected (the loss), while the swap itself creates additional buying pressure and pushes the price up further. The bot immediately sells at the higher price, capturing the difference between its entry and exit prices and extracting value from the user’s trade.
The user doesn't usually see this extraction as a separate fee: tt shows up as worse execution and greater slippage instead while the bot's profit comes directly from the additional price impact imposed on the user.
Example: A pool holds 100 ETH and 350,000 USDC, pricing ETH at 3,500 USDC. A bot spots a pending 10,000 USDC buy and purchases 0.5 ETH for about 1,759 USDC, pushing the price to roughly 3,535 USDC. The user’s swap then returns about 2.75 ETH instead of 2.78 ETH without the attack. After the user’s trade pushes the price higher, the bot sells its 0.5 ETH back for about 1,860 USDC, earning roughly 101 USDC.
Why THORChain Prevents Sandwich AttacksOn THORChain, swaps do not execute based on who pays the most to go first. Every trade goes through the Advanced Swap Queue, which orders swaps by price impact. In simple terms, the trade that moves the pool the most gets priority. That completely changes the economics of a sandwich attack.
When executing a swap on THORChain, fees depend on three parameters: the size of the swap (x), the size of the source pool (X), and the size of the destination pool (Y). While the formula may look complex to non-technical users, the principle is simple: the larger the swap relative to the available liquidity, the higher the fee.
This creates a built-in cost for an attacker. To gain priority over a user, the attacker must submit a trade with greater price impact, which generally means committing more capital and paying a higher fee. For large trades, the capital required can become significant (several millions). For smaller trades, the cost of the attack can quickly exceed the value available to extract. And a simple mathematical simulation can demonstrate the effect.
The example below compares a sandwich attack under a fixed 0.3% fee model with THORChain's slip fee model. The attacker swaps 1,001 RUNE for 8,271.22 ASSET. After the user's transaction executes, the attacker swaps the 8,271.22 ASSET back and receives only 972.48 RUNE, closing the sandwich with a 28.52 RUNE loss. The result is independent of pool size: under the slip fee model, the combined cost of the attacker's entry and exit trades exceeds the value made available by the transaction in between.
Importantly, THORChain's introduction of a minimum fees (L1SlipMinBps) doesn't change this. It only adjusts the minimum fee collected, while swap priority still depends on the trade's size relative to the pool and the (theoretical) slip-based fee generated.
https://x.com/THORChain/status/1504255731444649985ConclusionSandwich attacks rely on the ability to pay for transaction priority. THORChain removes that advantage by tying execution priority to price impact and fees to trade size relative to available liquidity.
That changes the economics entirely: getting ahead of a user requires a larger, more expensive trade, while the attacker's entry and exit both incur slip-based costs, making sandwich attacks economically unviable.
In the end, this design benefits swappers by protecting them from the value extraction that can occur on other DEXs and chains.
People's Bank of China increases its gold holdings for the 22nd consecutive month.
China's gold reserves stood at 76.73 million ounces (about 2,386.57 tons) at the end of August, up 650,000 ounces (around 20.22 tons) month-on-month. The People's Bank of China has been increasing its gold holdings for 22 consecutive months. (Jin10)
1 seconds ago
Unrealized profit from a smart money address’s ZEC holdings has exceeded $10 million, pushing its cumulative returns to $11.37 million.
According to monitoring by ai_9684xtpa, the smart money address yixie10, which deployed roughly $20 million into long ZEC positions, has expanded its cumulative ZEC trading profits to approximately $11.37 million. On September 4, when ZEC traded at around $985, this address held an unrealized profit of about $8.465 million. ZEC’s price has since risen by roughly 22%; if its position size remains unchanged, the unrealized profit is expected to further expand to around $10.34 million. Adding the previously realized profit of approximately $1.038 million, the address’s total gains from this single ZEC trade are likely to once again exceed $10 million.
1 seconds ago
Hong Kong stocks closed, with the Hang Seng Index down 0.93% and Zhipu dropping 5.3%.
Hong Kong stocks closed lower, with the Hang Seng Index down 0.93% and the Technology Index falling 0.92%; Zhipu (02513.HK) dropped 5.3%.
1 seconds ago
Administrative Measures for the Online Marketing of Financial Products will take effect on September 30: KOLs must hold valid certificates to work.
According to Caixin News, the "Administrative Measures for Online Marketing of Financial Products" jointly issued by the People's Bank of China and seven other government ministries will officially take effect on September 30, 2026. The regulation aims to clarify the boundaries between finance and technology, and does not impose a full ban on online live-stream sales of financial products; instead, it lays out specific guidelines and norms for marketing activities. It specifies that financial products promoted via official accounts, live streams, or short videos must be conducted on either the financial institution’s self-operated platform or accounts legally registered by the institution on third-party internet platforms. Additionally, marketers must be employees of financial institutions, hold relevant business qualifications, and obtain authorization from the financial institution. This means KOLs (Key Opinion Leaders, i.e., influencers and internet celebrities) who wish to promote financial products will need to "hold valid certificates to work".
1 seconds ago
BonkGuy praised MEME in a post, leading to its price surging over 50% in a short period.
Prominent trader BonkGuy lauded the MEME token in a social media post, revealing he had missed the opportunity to buy it when its market capitalization was below $10 million, before it surged to $150 million in just a few hours. He opined that MEME could emerge as one of the most representative meme coins of this cycle, noting the emerging "crypto-stock meme" narrative remains in its early stages, with MEME at the heart of this new narrative. Following his remarks, GMGN market data shows MEME rallied over 50% in a short period, with its current market cap standing at approximately $133 million.
1 seconds ago
Bitcoin drops below $79,000, logging a 0.99% loss in the 24-hour period.
According to HTX market data, Bitcoin has fallen below $79,000, currently trading at $78,999.99, with a 0.99% decline in the past 24 hours.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
THORChain x RAVN Podcast #232 ft. 0xMuninn, KentonC137 & patriotsounds | September 5, 2026 | Watch the full episode on YouTube
By Raynalytics
TL;DRRAVN is live in public beta with an aggregator that compares native-asset routes across THORChain and other execution venues, then ranks results by expected net output after applicable costs.0xMuninn says RAVN does not custody funds or deploy contracts that hold them. Its retail app is intended to remain zero-fee, while its API is designed for wallets and other integrators.RAVN’s MCP interface aims to let AI agents quote and execute the same native-asset routes, including a path from a $BTC treasury to $USDC settlement for x402 payments.$RUNE support, more EVM destination routes through Router v6, and possible $XMR support remain future work. None was presented as live or dated.IntroductionRAVN is an execution aggregator built around a simple question: if someone holds native $BTC and wants an asset on another network, why should the route require wrapped assets, a bridge, or several disconnected interfaces?
0xMuninn said the product grew out of that friction. After working in Web3 infrastructure, he wanted an interface that could compare execution venues while leaving the user with the canonical destination asset. The result is a consumer-facing app in public beta, plus an API for wallets and other products that want to offer cross-chain execution without building the underlying routing themselves.
The podcast focused on where THORChain Swap fits in that model, why RAVN is building for both people and agents, and which parts of the integration are still not ready.
1. One Request, Competing Native RoutesRAVN is not itself a liquidity venue. It sends a requested swap to multiple execution sources, then compares what comes back. During the show, 0xMuninn named THORChain, Chainflip, NEAR Intents and Relay among the integrations, and said the product had more than 13 execution venues in its routing set.
The relevant comparison is not only the displayed exchange rate. RAVN says it ranks routes on the amount expected to reach the user after applicable transaction costs, and can favor speed, gasless RFQ routes or zero-slippage RFQs when they genuinely provide the better result.
"We never touch any fund." (0xMuninn)That model gives a wallet or user one request instead of a separate search through every venue. It does not mean every route is identical. Each provider has its own asset coverage, execution model and operational status, so the selected route remains dependent on the live quotes available at that moment.
0xMuninn repeatedly drew a line around custody. He said RAVN does not hold user funds, route funds through its own contracts or write contracts that receive them. It is building the routing and execution layer around independent venues, not a new bridge or a synthetic-asset system.
2. The Consumer App Is Only One SurfaceRAVN’s public app is the visible entry point, but 0xMuninn described the API as the larger business path. An integrator can check venue health, request a quote and then execute when it chooses. The API accommodates three transaction patterns: an on-chain transaction, a deposit flow and a signature transaction for RFQ or gasless routes.
"We are baking all of these 13 venues into one single API and providing it to other integrators." (0xMuninn)For a wallet, the proposed value is implementation scope. Instead of building Bitcoin transaction handling and maintaining a separate relationship with each execution venue, it could call RAVN’s API and expose a native $BTC route. 0xMuninn estimated that a basic integration could take 20 to 30 minutes, but that is his estimate, not a guarantee for every wallet.
The consumer app currently supports EVM and Solana wallet connections. For a $BTC-originating swap, RAVN intentionally uses a deposit-address flow rather than asking someone to connect a Bitcoin wallet to the site. 0xMuninn framed that as a trust and simplicity choice, especially for holders with meaningful balances in one wallet.
RAVN is live in public beta, not a finished launch. The team is inviting feedback while it fixes issues and refines the product. Its stated retail policy is a zero RAVN fee, with monetization intended to come from B2B and agent-facing products.
3. Agentic Finance Needs Execution and Key BoundariesThe most forward-looking part of the conversation was RAVN’s MCP server. The idea is not to create a separate, worse route for bots. An agent should be able to ask for a quote, execute a selected route and check its status through the same routing engine that serves a person.
"Hold the keys yourself." (0xMuninn)0xMuninn’s example was an agent with $BTC, $ETH or $SOL in treasury that needs to settle an x402 payment in $USDC on Base or Solana. RAVN could provide the conversion path to the settlement asset, while x402 handles the machine-to-machine payment. The protocol does not change the agent’s permission model: RAVN says it never controls the keys.
That distinction matters. An agent can be permitted to execute, advised to prepare a transaction, or kept entirely away from signing authority. 0xMuninn’s recommendation was to keep keys with the user and let an agent advise or act only within the authority the user deliberately grants.
The product thesis is that permissionless native-asset execution reduces friction for agents that otherwise need to navigate exchange accounts, KYC and several different APIs. It is still early infrastructure, not evidence that autonomous trading is safe by default. Denny pointed to a recent case where a user’s own cloud agent mishandled a $30,000 swap, underscoring why route selection and key control need to remain separate decisions.
4. THORChain Integration Is Live, but the Next Routes Are ConditionalRAVN already uses THORChain for the native $BTC routes it can support today. The next requests are broader than that. 0xMuninn said $RUNE was not yet available in RAVN, and that current THORChain capabilities and temporarily unavailable memoless flows limited some of the paths he had expected to offer.
The recent memoless recap explains why those flows were paused while the protocol reviews their defenses. RAVN’s experience also surfaced an implementation detail: a memoless $BTC swap can require a unique inbound amount so the protocol can match the transaction without a memo. 0xMuninn initially found that unexpected, then said the documented design made sense once he understood it.
"I’m waiting for Router v6." (0xMuninn)Router v6 could make more EVM destination addresses available, which is the immediate expansion 0xMuninn emphasized. Kenton and Denny described the work as close or largely complete, but gave no reliable activation date. The honest status is work in progress, not a launch promise.
$XMR is another potential addition, not a committed route. 0xMuninn wants to study the technical dependencies and user demand after THORChain’s Monero integration is established. He also declined to add custody-based privacy hops to RAVN simply to offer a privacy feature, arguing that a route can obscure activity without providing the same properties as an on-chain privacy asset.
What to WatchRAVN beta feedback: whether public testing changes the app’s available routes, wallet support or execution experience.B2B integrations: whether a wallet or application adopts the API for native $BTC execution, beyond RAVN’s own interface.Agent permissions: how RAVN’s MCP users set signing authority and transaction constraints as agentic flows mature.Router v6: whether THORChain activates the expanded destination capability RAVN wants, and which routes it enables in practice.$RUNE and $XMR: whether RAVN adds these assets after its technical and product reviews. Neither was live at the time of the podcast.More THORChain data, check out raynalytics.net
Follow Raynalytics for more Weekly Analytics and Podcast recaps.
THORSday Community Podcast #231 ft. codehans1, Devel484, CBarraford, KentonC137 & patriotsounds | September 3, 2026 | Watch the full episode on YouTube
By Raynalytics
TL;DRTHORChain completed a long-awaited churn, but the stability focus continues for another week before reassessment. Monero remains built and working on stagenet, with its mainnet launch still waiting. A Gaia pause interrupted the next churn during the show.Protocol-owned liquidity is active, with 20% of system income being routed toward POL. Denny showed almost $22,000 on day three, with deposits going into the TRON $USDT pool.Rujira's app layer has resumed with two contracts still disabled. Hans wants emergency halts followed by prompt contact with the affected team and a clear route to resolution.Devel argues base-layer limit orders could improve quotes and execution for all swappers. Chad and Hans question the complexity and priority; Rujira's oracle-based DCL offers another approach to keeping trading value inside the ecosystem.Chad is building better metrics and log access for AI-assisted maintenance. Kenton reported stronger AI discovery, while ADR30's delegated node permissions still needed more votes.1. Churn Returns, but Stability Still Sets the PaceTHORChain finally churned again, bringing relief after the extended disruption. Devel said the change in the active node set immediately improved average block times by about 300 milliseconds as troubled nodes left and healthy ones entered.
That progress does not end the stability-first period discussed last week. Chad's Thursday engineering call favored another week of focused fixes, followed by reassessment. Outstanding Solana issues were one reason to continue.
"I'm hesitant to say that we've completed our stability without achieving stability." (Chad)For Monero followers, the message was explicit: the integration is built, functioning and working on stagenet. The team has not abandoned it. Monero and Zcash remain behind the decision to resume adding chains, with no new launch date given.
During the show, a Gaia pause complicated the next churn. Chad said a security concern was being investigated; details were still emerging. It illustrated a dependency he wants to revisit: adding a chain currently requires a churn. As more chains and signing schemes make that process more complex, he wants to remove avoidable dependencies on it. That is a proposed direction, not a completed redesign.
2. POL Starts Building Pool Depth Every BlockProtocol-owned liquidity, or POL, supplied the week's other concrete milestone. The setting was 20% of system income, and Denny showed almost $22,000 accumulated on day three. Allocations happen every block; the current destination was the TRON $USDT pool.
The discussion described pool selection as being recalculated each churn cycle, directing new liquidity toward an eligible pool based on its activity. The purpose is to build depth that stays under protocol ownership. Raynalytics' POL Income dashboard tracks the allocations, deposits and pool priorities.
"Its only interest is to just supply more liquidity and more depth to the pools." (Chad)Denny explored whether this made THORChain resemble an ETF or an index fund. Chad drew a boundary around that analogy: holding $RUNE does not give someone a direct redeemable share of the POL portfolio. The intended benefit is indirect, through deeper pools, more useful trading capacity and the fees that activity can generate.
Kenton floated a possible future distribution to $TCY holders if POL became sufficiently large. Chad treated that as an option, not a commitment. Treasury rebalancing was also raised, including Oleg's suggested $500,000 move toward TRON stablecoin liquidity. No allocation decision was announced.
3. Rujira Resumes With Two Contracts Still PausedThere is a material update to Saturday's discussion of the app-layer pause: Rujira is running again. Hans said the bond contract and its trading pair remained disabled while the team double-checked the relevant query paths.
He said the non-determinism issue had been fixed in v3.20, with further checks intended to establish that nothing remained. The broader lesson concerns separation: complex financial logic can sit on the app layer, but the base-layer queries it calls must still behave deterministically and contract execution must be bounded.
Hans accepted that emergency controls need to be usable immediately. His proposed follow-through was to pull the lever when necessary, contact the relevant team, and establish a clear path to resolution.
"We weren't really sure what the correct process to get things reenabled was." (Hans)The group also discussed malicious use of pause powers. Chad described counter-votes and possible governance action against offending nodes; these were responses to a hypothetical attack, not an announced automatic penalty.
Hans explained one safeguard in Rujira's credit-account design: collateral can still be sent to a position's address when app-layer execution is paused, including supported secured assets. That can help protect a position during market moves, but it does not restore every action. App-layer-only positions cannot necessarily be sold while their contracts are halted.
4. BLO's Promise Meets the Cost of More ComplexityDevel's base-layer limit-order proposal, or BLO, produced the episode's longest debate. The disagreement centered on whether the execution benefits justify adding another trading mechanism alongside THORChain's AMM pools.
Chad evaluates a feature by implementation effort, risk and expected return. BLO would add code, maintenance obligations and operational questions about how two liquidity mechanisms interact. He remains open to it, but gives it a lower priority while stability work continues. Hans shared those concerns, drawing on years of building on-chain order books and the pitfalls of rounding, iteration limits and execution time.
Devel's case is that the initial users may be a small group of arbitrageurs, while the beneficiaries are everyone whose swaps reach the base layer.
"It improves the quote, it improves the result, it improves the speeds, it reduces refunding." (Devel)He said existing limit swaps have details that make them unattractive for arbitrageurs. BLO is designed around that workflow, with the aim of winning more quotes for ordinary users. Devel and the Maya Protocol team would likely provide much of the implementation, although core review and testing would still be necessary.
Oleg Petrov from SwapKit supplied a concrete example through chat: a user wanted a fast $20 million swap involving shallow pools. BLO could let market makers post liquidity and serve it in smaller chunks. Chad challenged the assumption that enough capital would be waiting there. Devel agreed that makers would need time to reallocate funds. The example shows the opportunity and the unresolved liquidity problem; it is not a claim that BLO already solves large swaps.
Hans also explained Dynamic Concentrated Liquidity, or DCL, which Rujira is developing. Instead of quoting only along a fixed curve, it uses the strategy's average entry price and THORChain's enshrined oracle price to adjust bids and asks. Its aim is to retain more trading profit and liquidity within the ecosystem.
Devel questioned whether external arbitrageurs would capture opportunities before the oracle-driven strategy reacts. Hans welcomed the resulting price competition. Neither DCL's profitability nor BLO's adoption was presented as proven. The designs could also interact: Hans said the app layer could use base-layer order functionality if it becomes available.
5. AI Maintenance Needs Better VisibilityHans and Chad agreed that agents can already use open blockchain interfaces. An agent can generate keys and broadcast transactions; a special agent-branded chain is not a prerequisite. A convenient cross-chain command-line wallet could help, but Hans noted that agents can also work with multiple existing tools.
Chad's immediate work is more operational. He wants protocol metrics pushed into Midgard, where statistical analysis can flag unusual values. An agent could then connect those anomalies to code and logs, investigate causes and potentially open a proposed fix.
The second piece is a THORNode API for querying logs over a block range. Together, these would give developers and agents more context without requiring every investigator to run a node. Devel said he already uses a restricted MCP server to give an agent log access, and had built monitoring that notified him when a churn succeeded.
There are limits. Data from one node may not explain why another node has a different app hash. Bifrost logs also remain a separate operator-controlled source. Chad discussed possible private, opt-in sharing later, while stressing that sensitive log contents require care. Broader visibility is work underway, not a deployed autonomous maintenance system.
6. Better AI Discovery, but a Weak August Fee-Test SampleKenton showed the swap site's score on Ora, reporting an improvement from 18/100 two months earlier to 89/100. He credited SEO work and the Unstoppable Wallet developers, and said he and Randy were now seeing daily API-key requests, including projects finding THORChain through AI search. Some requests were spam or individual inquiries, so this is evidence of visibility, not a count of signed integrations.
He is also replacing older “liquidity protocol” descriptions with “decentralized exchange” where possible, so search systems associate THORChain with a term people actually use.
"We have to stop inventing words that nobody uses." (Kenton)Distribution work continues through DeFi Llama: the first paid article has launched, with roughly monthly articles planned over the next year. Blockworks also announced its dashboard. Referral tracking links were still being finished.
On execution, Kenton reported fixes for THORChain Swap, including $USDT allowance handling and THORName address entry. He asked users to retest Bitcoin Taproot flows, including a reported Ledger issue, rather than treating every route as independently verified.
The dynamic-fee experiment had a less encouraging month. Chad reported roughly $187,000 of ShapeShift volume for THORChain in August, about 6.1% of the total. He considered the sample too small for a strong conclusion and wants to add higher-volume affiliates after the stability period, with Edge Wallet mentioned as a possibility. Better discovery and better routing economics still need to turn into sustained flow.
7. ADR30 and the Next Wave of Node OperatorsADR30 remained around 37% support during the recording. The Liquify proposal would let a node owner delegate selected tasks to other addresses without handing over the key controlling the bond. A team could separate routine operation from custody, making the setup more practical for professional infrastructure providers. The vote was still open; follow it on the governance tracker.
The standby queue was another sign of activity. Denny highlighted Runetard for helping bond providers become independent node operators and encouraged other multi-node operators to consider doing the same.
The group was cautious about accelerating churn merely to clear the backlog. Chad and Devel preferred gradual changes while reliability improves. Devel also highlighted the rule that the lowest-bonded node no longer has to leave unless the active set is at capacity, allowing smaller operators to remain when they perform well.
What to WatchNext Thursday's stability review: whether remaining issues are resolved enough to resume new-chain launches, including Monero and Zcash.POL deployment: how much income accumulates, where deposits land and how pool priorities change across churn cycles.Rujira's remaining pauses: completion of the contract checks and clearer communication around future emergency halts.BLO and DCL evidence: implementation review, testing, execution benefits and how much liquidity each design can attract.AI maintenance tooling: delivery of metrics and log access, with clear boundaries around operator-specific data.Conversion into flow: whether AI discovery, paid distribution and a broader dynamic-fee sample produce sustained activity.ADR30 and node growth: further votes, successful churns and independent operators entering the active set.More THORChain data, check out raynalytics.net
Follow Raynalytics for more Weekly Analytics and Podcast recaps.
TLDR A 20.5 BTC stash linked to the 2026 Coldcard hardware wallet theft moved through 34 THORChain swaps into Ethereum on September 2 and 3. Bitquery traced the funds from a “reported” attacker address tied to what it calls Wave 3 of the theft. Most of the traced value, 20.15 BTC, landed at one Ethereum address that later showed an outgoing drop of about 5 ETH. Most of the stolen Bitcoin, over 1,400 BTC, remains parked and untouched in identified addresses. Researchers including Galaxy Research say they still cannot confirm whether all theft waves trace back to one person or group. A stash of Bitcoin linked to the 2026 Coldcard hardware wallet theft began moving this week. Blockchain data provider Bitquery tracked the funds as they crossed into Ethereum.
The move shifted the case from a mostly parked stash of stolen coins into an active cross chain trail. Investigators had watched much of the stolen Bitcoin sit untouched for months.
The activity started on September 2 when 20.49703196 BTC left an address linked to the theft. Bitquery’s classification file lists the address as reported and tied to what it calls Wave 3.
The coins passed through two fresh Bitcoin addresses. Both were later emptied, according to Bitquery’s tracking data.
Bitquery places the origin address in its reported tier, one step below its confirmed list. The person or group controlling the funds has not been identified.
THORChain is a tool that lets users swap coins across different blockchains. Bitquery’s live tracker recorded 34 swaps on September 2 and 3 that sent 20.45 BTC of traced value into Ethereum.
The tracker’s broader total reached 20.69 BTC across 36 swaps. That figure includes two earlier swaps worth 0.24 BTC that happened back on August 2.
Most of the funds, 20.15 BTC across 26 swaps, ended up at one Ethereum address. A smaller amount, 0.30 BTC, moved through eight swaps to a second address.
The two August swaps sent funds to a third address. Bitquery’s records show THORChain swap memos naming the main destination for the September transactions.
That main Ethereum address held about 649.5 ETH with no outgoing transactions when Bitquery checked at 16:15 UTC on September 3. About an hour later, at 17:25 UTC, a balance check showed 644.4974 ETH.
The drop of roughly 5 ETH marked the first outgoing activity from that address since the funds arrived.
Most Stolen Bitcoin Remains Untouched Not all of the stolen Bitcoin has moved. At block 965,339, Bitquery counted 1,402.59 BTC still sitting in identified addresses linked to the theft.
Of that total, 1,396.33 BTC has never moved since it was stolen. Bitquery tracks the 20.69 BTC that went through THORChain as a separate category, now watched on Ethereum.
A separate dataset built from Bitcoin block data breaks the theft into waves. It counts Waves 1 through 3 apart from a fourth wave of 64.90373764 BTC, and says the blockchain alone cannot confirm whether one group is behind all of them.
Galaxy Research has also said it cannot fully link every wave of the theft to a single source. The firm has estimated total losses from the Coldcard theft at 1,700 BTC or more.
As of the latest check, the main Ethereum address tied to the September swaps still held about 644.5 ETH. The rest of the traced Bitcoin has yet to move beyond the two Bitcoin addresses used in the swap.
Stolen Bitcoin from the third wave of the Coldcard wallet attacks has begun leaving the hacker’s original addresses, with part of the holdings being swapped into Ethereum through THORChain.
The movement is the first recorded departure of funds from the original attacker addresses across any of the three waves, according to Alex Thorn, Galaxy’s head of research. Thorn said Wednesday that the third-wave attacker had moved about 10% of the stolen holdings, leaving roughly 90% untouched.
Several attempts to convert the assets have not gone through as intended. Thorn said the attacker’s swap attempts through THORChain had repeatedly resulted in refunds, prompting further attempts.
Researchers following the activity on-chain were able to trace the transfers beyond THORChain to a fresh Ethereum address. Thorn said the address had been passed to relevant authorities and crypto companies. He also said the attacker’s next step remained uncertain, including whether the assets would be moved again to make them harder to follow or transferred to an exchange.
Coldcard Attackers Remain Active The latest transfers follow a broader Coldcard exploit that Galaxy Research has linked to the loss of at least 1,789 Bitcoin across 8,865 addresses. Those assets were valued at approximately $114.7 million when they were stolen.
Blockchain security company CertiK had also reported activity involving funds associated with the exploit in August, when 64 Bitcoin and 200 Ether were sent to cryptocurrency mixers, including Tornado Cash.
The latest movement comes days after Thorn reported further evidence that the Coldcard attackers remained active. A deliberately weakened wallet set up by a researcher was swept on Aug. 28. The wallet was designed to determine whether the attackers could locate vulnerable keys.
DisClamier: This content is informational and should not be considered financial advice. The views expressed in this article may include the author's personal opinions and do not reflect The Crypto Basic opinion. Readers are encouraged to do thorough research before making any investment decisions. The Crypto Basic is not responsible for any financial losses.
A hacker linked to the third wave of Coldcard wallet thefts has started swapping stolen Bitcoin for Ether through THORChain.
Galaxy head of research Alex Thorn took to X on Wednesday to report that the third-wave exploiter moved about 10% of the stolen funds, with 90% remaining untouched. Thorn said it marked the first time funds from any of the three waves had moved onchain from the original hacker addresses.
“The hacker appears to be having some issues swapping all the funds through THORChain — they keep getting refunded and he keeps retrying,” he said.
Thorn said onchain analysts traced the funds through THORChain to a new Ethereum address, adding that he shared it with relevant authorities and crypto companies. It remains unclear whether the attacker will attempt to further obscure or move the assets through an exchange, he added.
The transfers follow a Coldcard exploit that Galaxy Research linked to the theft of at least 1,789 Bitcoin from 8,865 addresses, worth about $114.7 million at the time they were stolen. Blockchain security company CertiK reported in August that hackers linked to the exploit had sent 64 Bitcoin and 200 Ether to cryptocurrency mixers such as Tornado Cash.
The latest movement comes days after Thorn said the Coldcard attackers remained active, citing the Aug. 28 sweep of a deliberately weakened researcher wallet designed to test the attackers’ ability to find vulnerable keys.
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.
A hacker linked to the third wave of Coldcard wallet thefts has started swapping stolen Bitcoin for Ether through THORChain.
Galaxy head of research Alex Thorn took to X on Wednesday to report that the third-wave exploiter moved about 10% of the stolen funds, with 90% remaining untouched. Thorn said it marked the first time funds from any of the three waves had moved onchain from the original hacker addresses.
“The hacker appears to be having some issues swapping all the funds through THORChain — they keep getting refunded and he keeps retrying,” he said.
Thorn said onchain analysts traced the funds through THORChain to a new Ethereum address, adding that he shared it with relevant authorities and crypto companies. It remains unclear whether the attacker will attempt to further obscure or move the assets through an exchange, he added.
The transfers follow a Coldcard exploit that Galaxy Research linked to the theft of at least 1,789 Bitcoin from 8,865 addresses, worth about $114.7 million at the time they were stolen. Blockchain security company CertiK reported in August that hackers linked to the exploit had sent 64 Bitcoin and 200 Ether to cryptocurrency mixers such as Tornado Cash.
The latest movement comes days after Thorn said the Coldcard attackers remained active, citing the Aug. 28 sweep of a deliberately weakened researcher wallet designed to test the attackers’ ability to find vulnerable keys.
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.
A hacker associated with the third wave of Coldcard wallet thefts began converting stolen Bitcoin into Ether through THORChain on Sept. 3, according to Galaxy Research’s Alex Thorn.
Summary
Third-wave Coldcard attacker moved roughly 10% of stolen Bitcoin through THORChain into Ether this week. Researchers traced the swaps to a new Ethereum address and shared details with relevant authorities. Around 90% of the third-wave funds remained unmoved when Galaxy researcher Alex Thorn reported transfers. THORChain repeatedly refunded some swap attempts, prompting the attacker to resubmit transactions, Thorn reported Wednesday. Coinkite says affected seeds require migration because installing corrected firmware cannot repair existing wallet credentials. The transactions moved approximately 10% of the Bitcoin controlled by that attacker, Thorn said. Roughly 90% remained at its original addresses when he published the update.
Researchers traced the swaps through THORChain to a newly identified Ethereum address. Thorn said he shared the address with law enforcement, crypto companies and other organizations monitoring the stolen assets.
Coldcard hacker encounters failed THORChain swaps THORChain allows users to exchange native assets across blockchains without depositing funds into a centralized exchange. The protocol can therefore convert native Bitcoin into Ether without relying on a conventional custodial platform.
COLDCARD WAVE 3 HACKER SWAPS FUNDS TO ETH VIA THORCHAIN
the wave 3 exploiter has moved stolen funds for the first time, swapping to ETH them through the THORChain cross-chain DEX
these are the first funds from wave 1, 2, or 3 to move onchain from the original hacker addresses pic.twitter.com/jjOrX5wBR9
— Alex Thorn (@intangiblecoins) September 2, 2026 However, not every transaction succeeded. Thorn said the hacker appeared to be experiencing technical problems while attempting to process the swaps.
“The hacker appears to be having some issues swapping all the funds through THORChain — they keep getting refunded and he keeps retrying,” Thorn said.
The cause of the refunds was not immediately confirmed. Possible explanations include liquidity limitations, transaction settings or protocol safeguards, but no verified technical assessment had established the reason.
The movement represented the first detected onchain transfer from the original addresses associated with the first three attack waves, according to Thorn. Analysts will now monitor whether the resulting ETH moves to centralized exchanges, bridges or privacy services.
Galaxy traced 1,789 Bitcoin to the thefts Galaxy Research previously attributed the loss of 1,789.28 BTC across 8,865 addresses to the Coldcard vulnerability. The Bitcoin was worth approximately $114.7 million when stolen.
As crypto.news previously reported, approximately 87% of the identified Bitcoin remained unmoved as of Aug. 25. The estimate included funds linked to multiple attackers and attack waves, not only the wallet now using THORChain.
Galaxy’s figures partly relied on 221 victim reports covering 790.72 BTC. Onchain analysis identified additional affected addresses beyond those reported directly by customers.
The total remains an estimate because researchers have identified several attacker patterns with different levels of confidence. Galaxy has distinguished its high-confidence attribution from other addresses that may also relate to the vulnerability.
Earlier attackers used cryptocurrency mixers The latest THORChain swaps are separate from earlier laundering activity attributed to other attackers. CertiK reported in August that wallets linked to the broader incident sent 64 BTC and 200 ETH toward cryptocurrency mixers.
In related coverage, crypto.news found that one attacker retained 1,159 BTC while another began mixing smaller amounts. The different movements suggest that several parties may have exploited the same weakness.
Mixers and cross-chain swaps can complicate tracking, but they do not automatically make funds untraceable. Investigators can continue following transfers when assets enter and leave public protocols.
Centralized exchanges remain potential intervention points because they conduct identity and sanctions checks. Thorn said the new Ethereum destination had been distributed to relevant companies so they could identify subsequent deposits.
Coldcard users still need new wallet seeds The theft was linked to weak seed generation in Coldcard firmware released from 2021. The vulnerability reduced the randomness protecting some wallet credentials, allowing attackers to calculate private keys without physically accessing the devices.
Coinkite, Coldcard’s manufacturer, says corrected firmware is available across affected models. Its current security guidance states that previously generated vulnerable seeds still require migration.
Installing updated firmware does not repair a seed created under the affected software. Users must generate a new seed with corrected firmware and transfer their Bitcoin to addresses controlled by that new wallet.
Meanwhile, the attacker also remained active after the largest theft waves had ended. On Aug. 29, an address linked to the operation swept Bitcoin from a deliberately weakened researcher wallet, according to Thorn. Researchers created the wallet to test whether the attacker continued searching for predictable private keys. Its rapid compromise indicated that automated scanning remained active nearly one month after the first large thefts.
The incident has also prompted closer examination of how hardware wallets generate recovery phrases. Unlike phishing attacks, the Coldcard thefts did not require victims to approve transactions or reveal credentials. The exposed seeds contained insufficient randomness, allowing attackers to derive keys remotely and identify funded addresses on Bitcoin’s public ledger. As crypto.news previously explained, the firmware flaw weakened seeds generated on affected devices, meaning secure storage practices could not protect funds tied to those credentials.
Galaxy and other investigators are expected to continue watching the new Ethereum address. No public recovery, arrest or official identification of the attacker had been announced when the transfers were reported.
A cybercriminal associated with the third wave of thefts from Coldcard wallets has started converting stolen Bitcoin into Ether using THORChain, a decentralized cross-chain liquidity protocol.
Onchain transfers and THORChain activityAlex Thorn, head of research at Galaxy, reported on X that the exploiter moved about 10% of the illicit funds to a new Ethereum address. Thorn stated that 90% of the Bitcoin taken during this attack remains unmoved in the original hacker-controlled wallets.
This recent transaction signals the first notable movement from the hacker’s addresses since the initial Coldcard attacks, according to Thorn. He noted that the hacker encountered technical difficulties during the process, as multiple attempted swaps through THORChain were refunded before succeeding.
The hacker appears to be encountering issues swapping all the funds through THORChain, with repeated attempts resulting in refunds, Alex Thorn said.
Expert onchain analysts have traced the transferred funds to a new Ethereum address, which has since been shared with relevant law enforcement and major crypto firms. There is uncertainty around whether the attacker will attempt further laundering steps, such as transferring assets through an exchange to obscure their origins.
Mini dictionary: THORChain, a cross-chain decentralized liquidity network that allows users to swap cryptocurrencies between different blockchains without relying on centralized exchanges.
Background on the Coldcard theftGalaxy Research previously attributed a Coldcard exploit to the theft of at least 1,789 Bitcoin from 8,865 different wallet addresses. The stolen Bitcoin was valued at $114.7 million at the time of theft. Coldcard is a hardware wallet developed by Canadian company Coinkite, used by cryptocurrency holders to store Bitcoin securely offline.
The initial theft was discovered after blockchain security firm CertiK observed hackers linked to the exploit sending 64 Bitcoin and 200 Ether through cryptocurrency mixers, specifically Tornado Cash. Cryptocurrency mixers are services designed to obscure the transaction history of coins to improve privacy, but they are often used by cybercriminals to launder stolen assets.
DetailsValueTotal Bitcoin stolen1,789 BTCNumber of affected addresses8,865Initial value of stolen assets$114.7 millionBitcoin mixed via Tornado Cash (August)64 BTCEther mixed via Tornado Cash (August)200 ETHPercentage of funds moved (THORChain swap)10%Percentage of funds remaining90%Continued activity and security concernsThe transfer activity follows ongoing monitoring by blockchain researchers, who found that the hacker remained active as recently as late August. At that time, the attacker swept a deliberately weakened wallet set up by a researcher to test if the thief continued to scan for vulnerable keys.
The Coldcard security breach has heightened concerns in the cryptocurrency community, with observers watching to see if the stolen assets will undergo further laundering or ultimately enter mainstream exchanges.
Galaxy Digital Head of Research Alex Thorn stated that attackers behind the Coldcard Wave 3 recently transferred stolen funds for the first time, converting a portion of the assets to ETH via cross-chain decentralized exchange THORChain. This marks the first instance of funds from the Wave 1, Wave 2, or Wave 3 attacks being moved from the attackers’ initial wallet addresses to other on-chain addresses. Currently, approximately 90% of the stolen funds from Wave 3 remain untransferred. On-chain activity indicates the attackers encountered apparent issues when conducting conversions via THORChain, with some transactions being repeatedly refunded, though they continue to attempt converting the remaining funds.
Relevant content
The Crypto Fear & Greed Index has risen to 65, with the market remaining in "greed" territory.
According to data from Alternative, today’s Crypto Fear & Greed Index dropped to 65, up from 63 yesterday, with market sentiment remaining in the "Greed" territory. Note: The index ranges from 0 to 100, and its components include: volatility (25%), trading volume (25%), social media buzz (15%), market surveys (15%), Bitcoin’s market dominance (10%), and Google Trends analysis (10%).
10 minutes ago
Chasing the rally of the 'NiuLai' token, crypto KOL XXAntiWar transfers 17.57 million tokens to seven addresses.
According to on-chain analyst Ai Yi (@ai_9684xtpa), crypto KOL XXAntiWar, who chased the rally during the bull market, has transferred 17.57 million tokens to 7 addresses via multiple intermediaries in recent days, and is currently still in unrealized loss. Thus, while Fomo shows XXAntiWar has liquidated all positions, this is actually because new holding addresses have not been recorded.
10 minutes ago
An institution transferred 39,500 ETH worth approximately $95 million to a CEX.
According to Yuqing Monitoring, an institutional entity transferred 39,500 ETH (valued at approximately $95 million) to multiple CEXs over the past day. Over the past four days, its total transfers to CEXs have reached 142,800 ETH (worth around $345 million), while it still holds 29,735 ETH (approximately $70.9 million).
10 minutes ago
South Korea’s foreign exchange reserves posted a record increase of $14.33 billion in August.
South Korea’s foreign exchange reserves rose by $14.33 billion in August, marking the largest single-month increase in history, driven mainly by a sharp rise in commercial banks’ foreign currency deposits at the Bank of Korea (BOK). The BOK said in a Thursday statement that as of the end of August, the country’s foreign exchange reserves climbed to $442.28 billion from $427.95 billion at the end of July. The central bank added that August’s reserve growth stemmed primarily from a surge in foreign currency deposits held by financial institutions, while a weaker U.S. dollar against other currencies also boosted investment income and valuation gains on overseas assets denominated in foreign currencies. The improved reserves have strengthened South Korea’s financial buffer, as the won weakened several times in the first half of the year, drawing market attention to the country’s external financing conditions. Earlier this year, the won fell to its lowest level since 2009, prompting South Korean authorities to repeatedly warn against excessive exchange rate volatility and seek to curb capital outflows driven by massive retail investor investments in overseas assets.
10 minutes ago
Berkshire Hathaway plans to hold stakes in Japan's five major trading houses for the long term, with related stocks rising collectively.
Japanese trading house stocks rose on Thursday after Greg Abel, CEO of Berkshire Hathaway, said the firm plans to keep its stakes in these trading houses for decades to come. The trading house sector was among the top gainers in the Topix index on Thursday. Mitsubishi Corp. jumped as much as 4.5%, hitting its highest level since May; Sumitomo Corp., Mitsui & Co., Itochu Corp., and Marubeni all rose more than 2.5%. Berkshire currently holds roughly a 10% stake in each of the five trading houses. Abel, who took over as CEO from Warren Buffett in January this year, told CNBC in an interview on Wednesday that Berkshire’s holdings in the Japanese trading houses are "long-term investments" and the company intends to hold them for decades. Since Berkshire disclosed its stakes in 2020, the share prices of these Japanese trading houses have benefited from their association with Buffett. A market analyst at Tokai Tokyo Research Institute noted that Abel’s renewed show of confidence "may rekindle investors’ interest in buying trading house stocks."
10 minutes ago
Ansem: Robinhood’s Stock Price Bottoming Out and Consolidating, Expected to Hit New High in Q4
Crypto KOL Ansem wrote in a post that traditional finance (TradFi) firms consistently lag behind when integrating new crypto operations, as their suited executives often take too long to access relevant data. He believes Robinhood (HOOD) is a strong investment pick, noting its stock has been consolidating from the bottom, while the company is adding a key new revenue stream through its Layer 2 blockchain business. Robinhood’s stock is projected to hit a new all-time high in the fourth quarter, rising 50% from its current level.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
Privacy-focused cryptos widely outperformed the market in August. Zcash (ZEC) climbed 82%, driven by the launch of Grayscale’s spot ZCSH ETF on NYSE Arca. Monero (XMR), on the other hand, rose 40%, thanks to the arrival of native swaps on THORChain v3.20. And the momentum does not stop there: several more discreet privacy coins are also benefiting, even though regulatory pressure remains strong.
In brief ZEC surged 82% in August, raising its market cap from about 8 to over 14 billion dollars after the launch of Grayscale’s ZCSH fund on NYSE Arca. XMR gained nearly 40% over the month and approached a market cap of 10 billion dollars, notably after the arrival of native XMR swaps on THORChain. Other privacy coins also benefited from the movement, even though regulatory pressure remains a significant obstacle for the sector Zcash, Grayscale’s accelerator boost ZEC’s surge peaked during the last week of August, but the movement had started well before the ETF listing. The token’s return to its 2018 levels had laid the foundations.
Then, on August 25, Grayscale finalized the conversion: ZCSH thus becomes the very first listed product to offer direct exposure to ZEC. The fund is backed by about 304 million dollars worth of ZEC held at Coinbase Custody, for an annual fee of 2.5%.
Grayscale presents ZCSH as a “satellite” position. The fund justifies the conversion by the network’s maturity and its zero-knowledge proofs (cryptographic proofs that validate a transaction without revealing amounts or addresses).
Buying a share of ZCSH rather than holding ZEC offers the benefits of the creation and redemption mechanism typical of ETFs, which reduces the gaps with the fund’s net asset value, whereas the trust was still trading at a 17% discount at the end of June. The effective launch of ZCSH on NYSE Arca remains a world first for spot exposure to a privacy coin.
Monero and THORChain, the native swaps bet Monero followed a different trajectory. XMR started the month more calmly before accelerating towards the end of August. In the last week, the crypto gained nearly 20%, bringing its monthly gain to around 40% and its market cap to nearly 10 billion dollars.
This time, it was not an ETF that served as catalyst. The main new element concerns THORChain, which integrated native XMR swaps in its version 3.20. This development allows users to swap Monero against other assets like bitcoin or ether directly via the protocol’s cross-chain infrastructure.
For Monero, this integration comes in a particular context. Several exchanges have already removed XMR from their offerings, notably due to compliance difficulties linked to the confidential nature of transactions.
Decentralized liquidity solutions therefore take on additional importance. With native swaps, users can move their XMR without necessarily going through a centralized platform or a tokenized version of the asset.
The rollout remains gradual and liquidity still has to prove itself. The XMR surge observed in August therefore does not guarantee that this momentum will continue at the same pace.
Liquidity vs regulation, the sector’s double challenge Between institutional access for Zcash and new decentralized gateways for Monero, the market shows renewed interest in financial tools preserving anonymity.
However, the regulatory environment continues to toughen: about ten jurisdictions already ban trading of privacy coins on regulated exchanges, and the implementation in 2026 of the OECD’s CARF (Crypto-Asset Reporting Framework) will strengthen tax transparency obligations.
For this summer rally to be sustainable, three factors will be decisive: actual flows to the ZCSH ETF, liquidity depth on THORChain, and the projects’ ability to reconcile privacy and compliance. As Zcash’s progress before the Ironwood upgrade already showed, privacy is becoming a promising investment theme again; it remains to be seen if volumes will follow in the long term.
Maximize your Cointribune experience with our "Read to Earn" program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.
Join the program
A
A
Lien copié
Fenelon L.
Passionné par le Bitcoin, j'aime explorer les méandres de la blockchain et des cryptos et je partage mes découvertes avec la communauté. Mon rêve est de vivre dans un monde où la vie privée et la liberté financière sont garanties pour tous, et je crois fermement que Bitcoin est l'outil qui peut rendre cela possible.
DISCLAIMER
The views, thoughts, and opinions expressed in this article belong solely to the author, and should not be taken as investment advice. Do your own research before taking any investment decisions.
THORChain now has a public-facing dashboard that puts its revenue, trading volume, staking data, and network distribution metrics on full display. The move is part of a broader transparency push that includes a collaboration with DeFiLlama and independent analytics from data analyst Raynalytics.
The numbers behind the comeback In July 2026, its first full month after restarting trading, the protocol generated $950K in fees, placing it 12th among all decentralized exchanges. Trading volumes during that same month hit approximately $797M.
As of mid-August 2026, THORChain’s cumulative fees have reached $173M, while total swap volume has crossed $124B.
Advertisement
The protocol’s core value proposition has always been enabling native asset swaps without wrapped tokens or bridges. You send real BTC and receive real ETH, with liquidity providers and node operators earning fees from every transaction.
DeFiLlama enters the picture THORChain began collaborating with DeFiLlama back in April 2026, working on data integration and dashboard improvements. That collaboration culminated in DeFiLlama launching its own THORChain Ecosystem Dashboard in August 2026, covering key financial metrics and analytics.
Part of the joint effort has also been directed toward building an institutional investment dashboard, giving compliance teams access to clean data and verifiable metrics.
Context: why transparency matters now Earlier in 2026, the protocol suspended trading after a security exploit forced the team to pause operations. The $950K in July fees and $797M in trading volume suggest the rebuilding is working, with liquidity providers returning and fee distribution flowing to node operators and liquidity providers.
What this means for the broader DEX landscape Unlike Uniswap or Curve, which operate within single ecosystems, THORChain facilitates swaps across entirely separate blockchains, enabling users to move between Bitcoin and Ethereum without relying on centralized exchanges or wrapped assets. Landing at 12th among DEXs by fees in its first month back demonstrates that demand for native cross-chain swaps persisted despite the trading pause.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
THORChain x Rujira Podcast #230 ft. PragmaticMonkey, KentonC137 & patriotsounds | August 29, 2026 | Watch the full episode on YouTube
By Raynalytics
TL;DRRujira's app layer was globally paused while THORChain's base-layer team investigates non-determinism concerns. Pragmatic Monkey argued that the known risky contract could have remained paused while other app-layer activity resumed, but Kenton stressed that the full technical picture was still emerging.The dispute was not only about uptime. A global pause leaves users unable to manage positions and removes the app layer from price dislocations that can generate revenue for Rujira and THORChain.Pragmatic Monkey said a prior restart produced more than $500,000 in volume and about $18,000 of revenue in a few blocks. Those are his internal figures from a prior event, not a forecast for the next restart.The episode's shared conclusion was straightforward: stability takes priority, but emergency decisions need a clearer communication and coordination process.Custom Concentrated Liquidity is live. Dynamic Concentrated Liquidity is being tested, while Sonar remains a possible future mobile product rather than a committed launch.IntroductionTwo days after THORChain's stability-first update, a separate problem came into view: Rujira's app layer was not merely slowing new work, it was globally paused.
Pragmatic Monkey joined Kenton and Denny to explain why Rujira contributors were frustrated. The immediate question was technical, but the bigger question was operational: when a decentralized network needs an emergency control, who communicates the scope, the rationale and the path back online?
1. The App Layer Is Paused While the Base Layer StabilizesPragmatic Monkey said the chain had encountered several non-determinism issues, the kind that can cause nodes to disagree about the state of the network. One app-layer yield contract was the observed trigger when it was enabled. The base layer had returned after the contract was paused, he said, but the wider app layer remained halted.
His position was not that stability should be sacrificed for activity. Rujira's team supports the broader decision to slow releases and focus on making the base layer robust. The disagreement was over scope. Pragmatic Monkey said the affected contract had already been isolated successfully, so a contract-level pause could let other app-layer positions and strategies operate while the investigation continued.
"We own this system together." (Pragmatic Monkey)Kenton did not present the case as settled. He said he did not have all the technical information and pointed to the possibility of further concerns that justified testing before a restart. That distinction matters. The episode records Rujira's argument for a narrower pause, not a confirmed finding that a global pause was unnecessary.
For users, however, the difference is tangible. A global halt can leave collateralized positions inaccessible while markets move. Current positions were described as standard CDPs rather than perps, which lowers but does not remove liquidation risk. The same control model would be much harder to defend once high-leverage products exist.
2. Decentralization Needs an Emergency ProcessThe episode became a live governance discussion. Pragmatic Monkey said Rujira had no warning that the full app layer would remain paused when the base layer restarted. Kenton agreed that communication needed to improve, while also resisting a judgment before the contributing developers had explained their reasoning.
"Real decentralization should not mean no coordination." (Pragmatic Monkey)The network's ability to halt a contract or the app layer is a strength in a genuine emergency. The problem is making that power predictable for users, builders and node operators. Rujira's proposed minimum is not centralized control. It is an agreed process: identify the risk, use the narrowest safe scope, tell affected teams and users what happened, and state the conditions for reopening.
Kenton framed the tension with an emergency-brake analogy. A brake belongs on the train, but it should be pulled for an emergency, not as an ordinary operating decision. The practical follow-up is to determine whether the available evidence required a global halt and to make the next decision easier to understand in real time.
"We have to find some chain of command or some procedure or something like that that we can all agree to." (Kenton)This is also a reminder of how THORChain governance works. Node operators can coordinate a different outcome when the necessary threshold is reached. That is decentralized control, but it does not eliminate the need for shared norms around safety-critical actions.
3. A Restart Can Be an Economic EventThe cost of the pause is not limited to unavailable positions. Rujira's architecture can capture price differences between its app-layer markets and THORChain's base-layer pools. When those markets restart out of sync, the resulting dislocations can create arbitrage opportunities that flow through the protocol instead of entirely to external traders.
Pragmatic Monkey showed a prior restart in which, he said, Rujira processed more than $500,000 of volume and generated roughly $18,000 in revenue in a few blocks. He said nearly all of that revenue came from arbitrage, despite total app-layer TVL remaining below $2 million at the time. Under Rujira's 50/50 revenue split, he estimated about $9,000 went to THORChain from that event.
"We made $18,000 of revenue in just a few blocks." (Pragmatic Monkey)Those figures describe a prior event with its own market conditions, not an estimate for a future restart. But they explain Rujira's urgency. A wide price gap can be an opportunity to internalize value for liquidity providers and the protocol. Keeping the app layer closed means that opportunity is instead left to whatever external arbitrage can access the base-layer markets.
The same argument has limits. A restart must not be rushed merely to capture revenue. The point is that an app-layer pause changes market access and economic outcomes, so its scope and duration deserve the same transparent treatment as its security rationale.
4. CCL Is Live. DCL and Sonar Remain Work in ProgressThe original plan for the show was a demonstration of Custom Concentrated Liquidity, or CCL. That product is live and lets users provide liquidity within a chosen range. A broader walkthrough is being rescheduled.
The next product, Dynamic Concentrated Liquidity, or DCL, is earlier. As covered in the Podcast #223 recap, DCL is designed to move beyond a fixed range. Pragmatic Monkey said the new strategy would use an oracle price and a user's average entry price, buying only when it lowers that average and selling above it at a target spread.
That does not make DCL live. The first contract version was only days into testing, and Pragmatic Monkey was still examining how it behaves in a sustained one-way market. A strategy that protects an average entry price can also go long periods without trading, which is good for capital preservation but less useful for steady market making and protocol volume.
"More stability, more robustness, and then we can move on to actually try to continue building the cool apps." (Pragmatic Monkey)The group also discussed Sonar, a future Rujira mobile product. It is not an active release. Rujira's immediate priority is improving its web and mobile-web experience, while a rebuilt mobile app remains a possibility when capacity permits.
What to WatchThe app-layer restart: what the base-layer and Maya teams conclude about broader non-determinism risk, and whether the app layer can return with the affected contract still paused.Emergency coordination: whether contributors establish a clearer process for scoped halts, communication and restart conditions.User-position safeguards: how the pause model evolves before higher-risk products such as perps are introduced.Restart economics: whether a future synchronized restart again creates internalized arbitrage revenue, and how that value is distributed.DCL testing: whether the strategy can balance average-entry protection with enough activity to be useful for market making.Sonar: whether mobile-web improvements lead to a formal plan for a Rujira mobile app.More THORChain data, check out raynalytics.net
Follow Raynalytics for more Weekly Analytics and Podcast recaps.
Monero ($XMR) has posted its strongest monthly performance in more than four years, gaining over 45% in August 2026 and rising roughly 10% in a single 24-hour window. The last time the privacy-focused cryptocurrency delivered a comparable monthly gain was April 2021.
THORChain 3.20 Brings Native XMR Swaps The rally coincides with a significant protocol upgrade from THORChain. The timing matters:
That is a notable shift for Monero holders in particular.
Derivatives Market Signals Strong Demand The price action has been accompanied by a sharp move in derivatives markets. during the move, a dynamic that can amplify upward price momentum as bearish bets are forcibly closed.
The THORChain upgrade offers a structural reason for renewed interest beyond short-term speculation. A decentralized, non-custodial alternative for XMR swaps could help sustain demand if that trend continues.
31 August 2026 | 13:26 Monero led major cryptocurrencies as volume jumped 255%, but one trading pair carried most activity and THORChain’s anticipated native-XMR route remains delayed, leaving traders to judge whether momentum can last.
Key Takeaways XMR gained 10% as volume tripled. One KuCoin pair carried most volume. THORChain’s Monero rollout remains on hold. Daily RSI climbed above 84, raising risk. XMR outpaces every top-20 At 10:02 UTC on August 31, CoinGecko placed Monero near $532.29, up 10% over 24 hours and 22% over seven days. No other altcoin among the 20 largest cryptocurrencies by market value matched its daily gain.
Rolling 24-hour volume reached approximately $240.7 million, a 255% increase from the previous day. That implies an earlier comparison base of roughly $67.7 million and helps explain why the percentage change looks so dramatic. XMR’s market capitalization stood near $10 billion, making the latest turnover equivalent to about 2.4% of its market value.
The higher volume shows that more trading accompanied the price advance, but it does not represent $240.7 million of new investment. Every completed trade adds to the figure, and the same coins can change hands repeatedly.
Five days earlier, Coindoo’s review of a cooling altcoin market found XMR down 1.2% for the day and up 7.8% over seven days. By August 31, the reported weekly return had expanded by 14.4 percentage points.
Monero’s move also fits an older sector theme. In July, our team found that nine of the ten largest privacy coins finished the week higher. That history provides context for renewed interest in privacy assets, but it cannot identify the trigger for this particular 10% move.
One KuCoin pair carried 56% of the volume CoinGecko tracked XMR across 18 exchanges and 48 markets, but the activity was heavily concentrated. KuCoin’s XMR/USDT pair generated approximately $134.2 million, accounting for 56.2% of all tracked volume.
The concentration does not erase the increase, but it narrows what the headline figure proves. Participation was not equally strong across the market, and more than half of the recorded turnover depended on one exchange and one pair.
Broader demand would look different: total volume would remain elevated while KuCoin’s share declined as other exchanges and trading pairs became more active. If overall volume falls as activity on that pair cools, the surge will look more like a brief concentration of momentum than a market-wide change in XMR demand.
THORChain has not launched native XMR swaps yet The trading data show that activity increased; they do not reveal why. Major development surrounding Monero is THORChain’s planned native integration, although the official timeline does not support treating it as a completed catalyst.
Monero applies privacy by default, concealing transaction amounts and making senders and recipients difficult to link. That design distinguishes it from networks where confidential transfers are optional, but it has also contributed to XMR’s removal or restriction on several centralized platforms.
THORChain’s proposed integration would offer another route. Users could exchange native XMR for assets on other supported networks without wrapping the coin or depositing it with a centralized custodian.
In its July soft-launch plan, THORChain described the Monero code as close to ready and planned to begin with a clearly labeled beta. The cautious rollout reflects work that its existing integrations do not require: Monero’s transaction outputs and signing process must be handled through a separate technical setup.
The schedule changed before launch. On August 27, THORChain placed XMR and Zcash on an initial one-to-two-week hold while it reviewed network stability following version 3.20 and a pending hotfix. Monero also remained absent from THORChain’s supported-asset list at the time of writing.
Monero’s protocol plans are separate Monero’s own roadmap should not be confused with THORChain’s integration. The official roadmap places Full-Chain Membership Proofs, the Cuprate Rust node, Bulletproofs++ and the Seraphis/Jamtis codebase in its “Coming Soon” section. None was announced on August 31 as a fresh reason for the price move.
There is therefore no verified same-day fundamental announcement that explains the rally. The prospect of easier decentralized access may be attracting interest, but the available data cannot separate that expectation from momentum trading or a broader rotation into privacy assets.
Monero’s daily chart is strong but extended Prices moved quickly during the session.
Monero (XMR/USD) price chart showing a sharp surge and RSI indicator.
On the daily chart, XMR stood well above its major moving averages. The 50-day simple moving average was near $386, while the 100- and 200-day averages were clustered around $360 and $359. At approximately 39% above the 50-day average, price had no nearby moving-average support if profit-taking accelerated.
Daily RSI reading reached 84 which reflects strong momentum rather than an automatic reversal signal, but it also shows that the advance has had little time to reset. A routine pullback can become sharp when buyers enter after such an extended move.
The first level to watch is $500, both a round number and the area needed to preserve most of the latest breakout. The measured advance began near $486.32, making a daily close below that level a clearer sign that the latest leg had failed. The previous consolidation around $470 would then become relevant.
On the upside, $540 marks the immediate overhead area around the latest price readings. A daily close above it would leave $560 as the next visible round-number zone, although that level is a reference point rather than a guaranteed target.
What would make the rally more convincing Usable native swaps: THORChain launches XMR support, and its pool develops enough depth to process swaps without excessive slippage. Broader participation: Total volume stays elevated while KuCoin’s 56.2% share declines as activity spreads to other venues. A calmer chart: RSI retreats toward the 60-70 area while XMR continues closing above $500. The 255% volume increase shows that traders noticed Monero. It does not yet show whether they arrived for native-swap access, the wider privacy trade or short-term momentum. Actual THORChain usage, broader exchange participation and XMR’s behavior after RSI cools will provide a clearer answer than the size of one day’s price candle.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency prices are volatile, and market data can change rapidly.
Author
Kosta has reported on cryptocurrency markets and blockchain infrastructure since 2020, bringing over six years of hands-on experience in the crypto industry built through daily tracking of markets, trends, and emerging blockchain developments. Specializing in Bitcoin on-chain analysis, institutional ETF flows, and digital asset price action, his work at Coindoo has been cited by other news agencies and consistently covers market developments with a focus on data-driven reporting across Bitcoin, Ethereum, Solana, and XRP. Over the years, Kosta has contributed to multiple crypto media outlets in different regions, authoring over 6,000 articles across the sector. His reporting spans cryptocurrency markets and the broader fintech industry, tracking not only price action but also the technological and regulatory forces shaping the ecosystem. To support his analysis, Kosta actively leverages on-chain data and metrics from leading platforms such as Santiment, Glassnode, and CryptoQuant, enabling deeper, evidence-based market insights. He believes in the power of transparency and the data that underpins the blockchain ecosystem. His academic background in Marketing Management from Denmark further complements his analytical approach, adding a strong understanding of communication strategy and content positioning to his work.
Five altcoins broke out during mid-August, and four of them now carry dated September catalysts that could extend or end the move.
The turn rolled through the market in stages. Uniswap bottomed on August 14, and Solana volume spiked on August 19. Zcash, Monero, and Hyperliquid then broke out together on August 22.
Zcash (ZEC) Broke Out 3 Days Before Its ETF LaunchedRank: 10
Price: $838.78
Market Cap: $14.18 billion
Grayscale listed the first US spot Zcash product on NYSE Arca on August 25 under the ticker ZCSH. The debut was quiet, drawing roughly $14.8 million in first-session volume. Notably, the breakout preceded the listing by three days.
ZEC cleared its November 2025 cycle high near $750 on August 22. It then reached $888, just under the 1.272 Fibonacci extension at $903. The next extension sits at $1,099. This is an eight-year high rather than a record, since ZEC peaked above $3,190 in October 2016.
ZEC daily chart / Source: TradingviewMeanwhile, a coinholder poll on the NU7 upgrade closes September 14. One question asks whether to replace the halving schedule with a smooth issuance curve. Rejection at $903 could return the price to the $750 breakout level, which held on August 25.
Monero (XMR) Closes In on a Record Above $800Rank: 13
Price: $536.77
Market Cap: $10.13 billion
THORChain enabled native Monero swaps on August 25, allowing direct trades against Bitcoin and stablecoins without wrapping. That partly routes around the exchange delistings that hit the asset through 2025. However, XMR carries no dated September catalyst.
The chart broke above the May swing high on August 22 and added 26.5% in seven days. XMR now tests the 0.5 Fibonacci retracement at $538. Above it sits the 0.618 golden pocket at $600, then the record high of $799.89 set on January 14.
XMR daily chart / Source: TradingviewIn contrast to Zcash, this move looks derivatives-led. Open interest roughly doubled in two weeks to about $278 million, and futures volume runs far above spot. A squeeze that builds this fast can unwind just as fast. Earlier privacy coin positioning showed the same pattern.
The immediate support for XMR sits at $476.53.
Hyperliquid (HYPE) Faces a $1.2 Billion Unlock on September 29Rank: 9
Price: $81.78
Market Cap: $18.18 billion
Hyperliquid routes 99% of order-book fees into buybacks, currently worth roughly $58 million to $80 million a month. A release of about 14.2 million HYPE, near $1.2 billion, lands on September 29. Roughly 47% goes to insiders.
HYPE cleared its prior record at $77 on August 22 and reached $86.71 five days later. The first target is the 1.272 extension at $92.37, followed by $111.93.
HYPE daily chart / Source: TradingviewHistorically, monthly releases moved price 14.1% lower in May, 1% higher in June, and 7% lower in July. From $81.78, that range maps to roughly $70 to $76, which brackets the $77 breakout level. Below that, support sits at $64.91, then $55.41, where the 0.618 retracement meets the trendline from January.
Uniswap (UNI) Burn Doubled to a Record in AugustRank: 29
Price: $5.12
Market Cap: $3.19 billion
Uniswap activated v4 protocol fees and Robinhood Chain fees in late July. August was the first full month with both running, and burn funding hit a record $8.9 million. That is roughly double the pace held since January.
UNI set a higher low on August 14, then cleared swing highs at $3.99 and $4.43. It now tests the 0.618 retracement near $4.94. Above that sit $5.66 and the January high at $6.57.
UNI daily chart / Source: TradingviewThe Senate cloture vote on the CLARITY Act falls in mid-September and needs 60 votes. Failure could stall the breakout. Therefore, the burn story needs a caveat, since a 20 million UNI annual growth budget keeps supply closer to neutral than deflationary.
Validators approved SIMD-0550 on August 28, doubling annual disinflation from 15% to 30%. Bitwise crossed $1 billion in Solana ETF assets the same day. Transaction V1 then activates on September 9, raising the maximum transaction size more than threefold.
SOL broke the 0.382 retracement at $93.98 and is now confirming the 0.5 level at $104.44 as support. Volume expanded from August 19. The next target is the 0.618 retracement at $114.89.
SOL daily chart / Source: TradingviewHowever, the fundamentals disagree with the chart. Network fees fell 44% quarter over quarter, and Solana’s share of global fees dropped to 17.3% from 26.6%. That divergence makes $104 the level that matters most.
What to Watch NextThe September calendar is tight. Transaction V1 lands on the 9th, the Zcash poll closes on the 14th, the CLARITY vote follows in mid-month, and Hyperliquid’s unlock arrives on the 29th.
Four of these five carry a dated event, and the leaders are extended after an eight-day breakout. Monero is the exception, so its path depends on flow rather than a catalyst.
George Town, Cayman Islands, August 25th, 2026, Chainwire
THORChain, a decentralized exchange, announced the launch of THORChain 3.20, an upgrade introducing native support for Monero (XMR) and Zcash (ZEC) swaps.
Until now, moving between privacy coins such as XMR or ZEC and the crypto market has required users to rely on centralized exchanges, custodial services, or additional intermediary steps. With THORChain 3.20, users can natively swap XMR and ZEC against assets including Bitcoin (BTC), Ethereum (ETH), and stablecoins directly through THORChain.
No wrapped versions of XMR or ZEC are required. Users do not need to create an account or hand custody of their assets to a centralized entity. This is a significantly more direct route between privacy-focused cryptocurrencies and the most widely used assets in crypto.
For Monero holders, access to the broader crypto market has become an increasingly important issue as XMR continues to be removed or restricted by centralized exchanges. THORChain’s integration provides an alternative based on native assets and self-custody rather than requiring users to deposit their coins with an exchange.
The release is one of THORChain’s most significant upgrades to date. In addition to Monero and Zcash integration, version 3.20 introduces several broader changes to the protocol, including Protocol-Owned Liquidity (POL) and the new Stable Reserve, alongside renewed support for Solana, Base, and BNB. The Stable Reserve introduces stablecoin-to-stablecoin swaps with no liquidity fees, and Protocol-Owned Liquidity gives THORChain additional mechanisms for deploying protocol capital across the network.
The move builds on THORChain’s core proposition of allowing users to exchange native cryptocurrencies across otherwise disconnected blockchain networks without handing control of their assets to an intermediary.
THORChain already enables native cross-chain swaps across assets including Bitcoin and Ethereum. The addition of privacy-focused networks expands that model into an area of the crypto market where decentralized access has been far more limited until today.
About THORChain THORChain is a decentralized exchange that enables users to swap native digital assets across different blockchain networks without relying on wrapped assets or centralized custodians. It allows users to exchange assets including Bitcoin, Ethereum, and other supported cryptocurrencies while maintaining a self-custodial experience.
George Town, Cayman Islands, 25th August 2026, ChainwireBy Chainwire
2 min read
Create an account to save your articles.
Add on Google
Add Decrypt as your preferred source to see more of our stories on Google.
George Town, Cayman Islands, August 25th, 2026, Chainwire
THORChain, a decentralized exchange, announced the launch of THORChain 3.20, an upgrade introducing native support for Monero (XMR) and Zcash (ZEC) swaps.
Until now, moving between privacy coins such as XMR or ZEC and the crypto market has required users to rely on centralized exchanges, custodial services, or additional intermediary steps. With THORChain 3.20, users can natively swap XMR and ZEC against assets including Bitcoin (BTC), Ethereum (ETH), and stablecoins directly through THORChain.
No wrapped versions of XMR or ZEC are required. Users do not need to create an account or hand custody of their assets to a centralized entity. This is a significantly more direct route between privacy-focused cryptocurrencies and the most widely used assets in crypto.
For Monero holders, access to the broader crypto market has become an increasingly important issue as XMR continues to be removed or restricted by centralized exchanges. THORChain’s integration provides an alternative based on native assets and self-custody rather than requiring users to deposit their coins with an exchange.
The release is one of THORChain’s most significant upgrades to date. In addition to Monero and Zcash integration, version 3.20 introduces several broader changes to the protocol, including Protocol-Owned Liquidity (POL) and the new Stable Reserve, alongside renewed support for Solana, Base, and BNB. The Stable Reserve introduces stablecoin-to-stablecoin swaps with no liquidity fees, and Protocol-Owned Liquidity gives THORChain additional mechanisms for deploying protocol capital across the network.
The move builds on THORChain’s core proposition of allowing users to exchange native cryptocurrencies across otherwise disconnected blockchain networks without handing control of their assets to an intermediary.
THORChain already enables native cross-chain swaps across assets including Bitcoin and Ethereum. The addition of privacy-focused networks expands that model into an area of the crypto market where decentralized access has been far more limited until today.
About THORChain
THORChain is a decentralized exchange that enables users to swap native digital assets across different blockchain networks without relying on wrapped assets or centralized custodians. It allows users to exchange assets including Bitcoin, Ethereum, and other supported cryptocurrencies while maintaining a self-custodial experience.
THORChain [RUNE] surged by more than 26% in the past 24 hours, ranking first among all gainers in the top 200 cryptos by market cap.
The hype around a network upgrade alongside a broader, stronger crypto market drove the token’s price. As a result, RUNE’s daily trading volume matched the uptick in price, recording a 3x increase, but remained fairly low, in excess of $20 million.
Here is how the THORChain v3.20 upgrade fueled the sudden surge:
THORChain v3.20 upgrade goes live as short liquidations spike The network announced that the THORChain v3.20 upgrade went live on the 26th of August. This upgrade allows swapping Monero [XMR] and Zcash [ZEC] for Bitcoin [BTC], Ethereum [ETH], and stablecoins.
The upgrade has expanded THORChain’s addressable market as it brings privacy users to a direct connection to crypto. The upgrade comes three months after an attacker exploited THORChain for over $10 million across BTC, ETH, and BSC.
That could increase the chain’s swap volume, with Ethereum and Bitcoin consistently dominating as per data from DefiLlama. The chain averaged $7 million in daily BTC swaps and $10 million in daily ETH swaps.
Source: DeFiLlama Thus, it is safe to say the rally was driven by a surge in sentiment following the upgrade and increased user base.
The surge in daily buying volume triggered liquidation of perpetual short orders. As per CoinGlass data, RUNE short positions worth 10x those of longs were wiped out.
Source: CoinGlass With a stronger crypto market and altcoins gaining ground, RUNE could truly shift its market structure. Let’s find…
Can RUNE bulls flip $0.65 into support? The 200-day EMA shows that RUNE price action has turned bullish on a long-term daily scale. The altcoin was still bearish looking at the horizontal structural levels.
RUNE was still trading below the $0.65 zone, which was the last lower high of the bearish trend. The market structure has shifted from the EMA perspective, but it is yet to confirm by flipping the $0.65 resistance into support.
Bulls tested the $0.65 supply zone but met instant rejection. It is still unclear if they got the zeal to breach the resistance.
Source: RUNE/USDT on TradingView However, the CVD showed bulls were positioning with 1.78 million RUNE bought on Binance as of the time of press. Moreover, the Sentiment was at 80, indicating the crowd was convinced the altcoin rally may be sustainable.
Still, it is worth noting that the rally may be short-lived since it is sentiment-driven. Otherwise, if the market structure is shifting, then RUNE may be positioning for more gains.
Final Summary RUNE rallies by more than 26% in 24 hours after the THORChain v3.20 upgrade, leading all of the top 200 cryptos by market cap. RUNE bulls tested the $0.65 resistance level, which, if flipped into support, would shift the market structure to bullish.
THORSday Community Podcast #229 ft. CBarraford, KentonC137 & patriotsounds | August 27, 2026 | Watch the full episode on YouTube
By Raynalytics
TL;DRTHORChain has put new launches on an initial one-to-two-week pause to prioritize stability after v3.20 and the pending v3.20.1 hotfix. Zcash, $XMR, protocol-owned liquidity deployment and the SwapKit rev-share test are all delayed, not cancelled.The team traced the immediate instability to app-layer calls through non-deterministic API endpoints. A temporary app-layer pause remains technically possible, but no decision to use it was made during the episode.ADR30 was at 38% approval when recorded. It would let node operators delegate selected administrative commands without handing over control of funds.THORChain is considering what an AI-native protocol interface should look like. An unpublicized MCP server already exists in GitLab, while a command-line wallet for agents is only a possible direction.Memoless registrations were paused after a spam attempt. The team is weighing pricing, rate limits and registration-design changes, while stressing that a user must still follow the correct inbound flow.1. Stability Comes Before the Next LaunchTHORChain had just shipped v3.20, but the episode opened with the harder follow-up: the network needed a v3.20.1 hotfix and a period of focused stability work before the roadmap could advance again.
Chad Barraford said the immediate issue came from the Rujira app layer sometimes querying API endpoints whose results could vary between requests. That variation can change gas consumption. In a consensus system, even a tiny difference in execution is unacceptable, so the team chose to pause new work while it fixed the current failure mode and watched the chain closely.
"We've had too much instability recently to just kind of keep on slogging forward." (Chad)The current patch was expected within roughly 24 hours, contingent on testing and node adoption. But the broader pause is not merely a hotfix window. The team wants at least one or two weeks to assess stability, then decide whether it can resume the roadmap or needs more time.
That means Zcash and Monero are waiting, alongside new feature rollouts, protocol-owned liquidity deployment and rev-share. The message is deliberately cautious: $XMR and Zcash are delayed, not abandoned. Churns should still resume during the stability period, but new chain launches are not the near-term priority.
The community also asked whether the app layer itself could be paused temporarily. Chad confirmed that it is technically possible, but said the team did not yet think it was necessary. The identified patch may be enough, though that judgment could change as more information arrives.
2. AI Strategy Is Still Taking ShapeBefore the technical updates, Denny highlighted a self-funded AI video from French Chad that had reached nearly 9,000 impressions. The anecdote led into a broader question: if agents increasingly initiate crypto activity, what should THORChain build for them?
Kenton said work on AI-engine optimization was beginning to show results in AI search. Chad took the longer view. He expects agents to account for a growing share of transactions, but he does not think the correct protocol strategy is obvious yet.
"The hard thing is figuring out what our strategy should be in that context." (Chad)Some ingredients already exist. Chad said a developer has been working on an open-source MCP server in THORChain's GitLab, though it had not been publicized. Agents can already broadcast a transaction with the necessary memo, so basic agent use does not require a new protocol feature.
The more ambitious possibility is an AI-friendly, command-line wallet with structured JSON output. Instead of asking an agent to operate a graphical wallet, it could hold assets, inspect transaction history and submit transactions through an interface designed for software. That idea is not a product commitment, and it may not be THORChain-specific. It is a direction the team is evaluating as the capabilities and economics of AI change.
Chad also clarified the role of Huginn. It is designed to operate independently, not as a chat assistant that a developer prompts directly. A GitLab issue can be assigned to Huginn, which then works through that task on its own schedule.
https://raynalytics.net/network-status/governance3. ADR30 Separates Operations From Fund ControlADR30 was at 38% approval during the show. The proposal would let a node operator delegate selected operational commands to another address without giving that address control of the node's funds or private keys.
That makes it a quality-of-life change rather than an economic redesign. An operator could split routine duties among people or systems while retaining the key material that matters for custody. The proposal was associated with Liquify, and Chad said he saw no material protocol-design risk beyond the normal need to implement and review the code correctly.
"The security, all that remains the same." (Chad)The vote was not presented as complete. Operators and bond providers still need time to review proposals, coordinate internally and vote. The conversation also returned to a possible future ADR that would require validators to participate in ADR votes, including an abstain option, so governance does not remain idle by default.
Other proposals remain in the queue, including free stablecoin swaps, per-asset minimum fee settings and Devel's limit-order idea. They can wait. The team was clear that stability outranks adding more work to the release path.
4. SwapKit Rev-Share Is Close, but Not ActiveThe planned rev-share arrangement with SwapKit is technically close on both sides. Chad said THORChain's work is ready for additional staging tests, while SwapKit's implementation was nearing completion. Under the proposed test, a portion of fees would go to a SwapKit-controlled bucket, where the partner could use it to compete for more external wallet flow.
"We'll start with 20%, we'll see how that goes." (Chad)That 20% figure is a starting point for a test, not a live setting. The team intends to judge the arrangement by the resulting data, then increase, decrease or stop it if the outcome does not justify the share.
Rev-share can be enabled through an operational Mimir vote, which ordinarily needs three agreeing nodes. But no activation should be read into that mechanism. The same stability pause affecting $XMR and Zcash also pushes the rev-share test back by at least one or two weeks.
The episode also touched on protocol-owned liquidity. v3.20 was meant to help direct system income into selected pools, but that work is now subject to the same pause. The team may later prioritize stablecoins, $XMR, Zcash or other pools, but no new allocation is expected while stability work takes precedence.
5. Memoless Swaps Are Paused While the Team Reworks DefensesThe memo registration feature used for memoless swaps was turned off after someone began repeatedly registering short memo identifiers in an attempt to capture an incorrectly sent inbound transaction. Each pool has roughly 100,000 possible identifiers, and the attacker tried to flood that space with registrations.
Chad's key distinction was important: the attempt can only succeed when someone sends funds to THORChain without including a memo and without registering the intended memo first. It is not a conventional compromise of a correctly formed THORChain Swap.
"The protocol gained money in this particular attack as of now." (Chad)The attacker pays to keep registrations active and, at the time of the episode, was operating at a loss. That does not make the design question irrelevant. The team is deciding whether to restart the feature as it is, make registrations more expensive as space fills, cap registrations per block, bind a registration more closely to the sending address, or include the expected amount in the registration. Each option creates different wallet and user-experience edge cases.
For now, the status is a pause and an active design discussion, not a finalized fix. The practical guidance remains the same: use an interface that constructs the transaction correctly, read its warnings and send a small test transaction before committing a meaningful amount. Self-custody gives users control, but it also makes transaction discipline non-optional.
What to Watchv3.20.1 and uptime: whether the hotfix is adopted cleanly and the team sees the stable operation it wants before reopening the roadmap.New-chain timing: when Zcash and $XMR return to the launch queue after the initial one-to-two-week stability review.ADR30: whether the delegation proposal clears its node vote and how quickly the remaining governance queue moves afterward.AI interfaces: whether the MCP server is publicized, and whether the agent-friendly command-line wallet concept becomes a concrete build.Memoless redesign: which registration defense the team chooses and when THORChain Swap can safely re-enable the flow.More THORChain data, check out raynalytics.net
Follow Raynalytics for more Weekly Analytics and Podcast recaps.
THORChain just gave privacy coin holders something they’ve been waiting years for: a way to trade Monero and Zcash directly for Bitcoin, Ethereum, and stablecoins without touching a centralized exchange or dealing with wrapped token workarounds. XMR responded by jumping roughly 8.9%.
The cross-chain decentralized exchange protocol rolled out version 3.20 on August 25, introducing native swap support for both XMR and ZEC. In a crypto landscape where privacy tokens keep getting booted from centralized platforms, that’s not just a technical upgrade. It’s a lifeline.
What v3.20 actually does Traders can now swap XMR or ZEC directly against BTC, ETH, and stablecoins through THORChain’s liquidity pools. The transactions remain self-custodial throughout, meaning users never hand over control of their assets to a third party during the swap process.
Beyond the privacy coin integrations, the upgrade packs two other notable features. Protocol-Owned Liquidity, or POL, gives the protocol itself a stake in its own liquidity pools. The second addition is a Stable Reserve mechanism that enables fee-free stablecoin swaps.
Months in the making This wasn’t a surprise announcement. THORChain’s development team showed off a live demo of Monero swaps back in May 2026, and preliminary code had been quietly folded into earlier releases. The project has described Monero integration as one of its most technically complex efforts to date.
The team opted for a phased launch strategy, acknowledging that liquidity for XMR and ZEC pools will likely be thin at the outset. Shallow pools mean higher slippage on larger trades, so the early days will probably work best for smaller swaps while liquidity depth builds organically.
Why this matters beyond the price pump The 8.9% XMR price surge is the attention-grabbing number, but the structural implications run deeper. Over the past several years, centralized exchanges have been steadily delisting privacy coins under regulatory pressure. Binance dropped Monero in multiple jurisdictions. OKX followed. Kraken trimmed its privacy coin offerings in certain markets.
The Protocol-Owned Liquidity feature could accelerate that process. By deploying protocol-controlled capital into its own XMR and ZEC pools, THORChain can bootstrap the liquidity depth that outside providers might be slow to commit.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
A set of critical vulnerabilities discovered in Zoom’s annotation feature could have enabled malicious participants to remotely execute code on another attendee’s device, without any interaction from the victim.
Critical flaws allow silent device takeoverIsraeli cybersecurity company A Security identified the flaws, naming the exploit method “Zoomsday.” Their researcher managed to construct a working exploit in less than a day by leveraging fewer than 20 prompts with commonly available AI models.
The vulnerabilities targeted Zoom’s annotation system, which is used for drawing, adding text, and sharing collaborative elements during meetings. Manipulating the annotation data allowed attackers to trigger dangerous memory-corruption issues on another participant’s computer.
Zoom classified two of the vulnerabilities, CVE-2026-53413 and CVE-2026-53415, as high severity with CVSS scores of 8.3. Both theoretically enabled one user to run malicious code on another participant’s system. A third vulnerability, CVE-2026-53414, received a medium severity rating.
For cryptocurrency holders, such an attack could provide unauthorized access to sensitive resources, including exchange sessions, wallet applications, and confidential data, significantly increasing the risk to digital assets if a device is compromised.
Mini dictionary: CVSS (Common Vulnerability Scoring System) is a standardized method for rating the severity of cybersecurity vulnerabilities, with scores ranging from 0 (low) to 10 (critical).
Zoom’s annotation flaws could let an attacker in the same meeting execute code on another participant’s device with no user action and no link-click required.
Zoom responds, but E2EE poses ongoing riskA Security first alerted Zoom to the vulnerabilities in June. In response, Zoom issued client-side security updates and implemented a server-side filter to block malicious annotation traffic from reaching vulnerable devices.
However, the researchers cautioned that the server-side defense does not work in end-to-end encrypted meetings because Zoom lacks the ability to inspect encrypted content. As a result, users with outdated clients in encrypted meetings may still be at risk.
Zoom recommended that affected Workplace customers update to at least version 7.1.5 or 7.0.6, according to their update channel. Earlier versions of Zoom Rooms and Meeting SDK are also vulnerable to attack.
VulnerabilitySeverityAffected FeatureCVE-2026-53413High (8.3)Annotation systemCVE-2026-53415High (8.3)Annotation systemCVE-2026-53414MediumAnnotation systemCompromising a computer through Zoom may expose access to cryptocurrency wallets, private keys, or other sensitive digital-asset data stored locally.
Recent crypto sector attack highlights threatIn September 2025, JP Thor, co-founder of decentralized exchange protocol THORChain, reportedly lost approximately $1.3 million after his computer was compromised during a seemingly legitimate Zoom meeting.
With the recently uncovered Zoomsday vulnerabilities, attackers no longer need to convince users to download malicious files or install fake updates. A vulnerable client is enough for unauthorized code execution as soon as an attacker joins the meeting.
Zoom advised all users, especially those handling digital assets or operating in sensitive environments, to update their software to the recommended versions without delay.
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.
The stolen XRP was converted to ETH, routed through THORChain and ultimately sent to Tornado Cash after the bridge was drained.
On August 9, a bridge connecting the XRP Ledger and Coreum (now rebranded as tx) lost close to 200,000 XRP after an attacker tricked its deposit-checking system into treating a wallet-to-wallet transfer as a real deposit.
The bridge has since halted, and both the operator and outside researchers have traced the failure to Coreum-side software rather than anything on the XRP Ledger itself.
What Happened, and How the Alarm Went Out The first public warning came from a trader posting as playa, who flagged that the bridge’s XRPL account rxXXXeMX8Gy5YvibvGLnQJ1XKKD7UswM1, was bleeding funds and pointed to the account’s DefaultRipple setting as the cause.
Playa said the balance had gone from 93,700 XRP to 77,200 XRP within minutes, a reading taken from an eleven-minute slice of what turned out to be a ninety-seven-minute drain.
Another user, Vet, pushed back in the same thread, writing that “the reason is the coreum bridge was being actively exploited.” Playa later agreed, posting, “I was rushing when I posted and didn’t dig in properly.”
The tx team confirmed the exploit in a statement, saying its software “incorrectly registered transactions that never actually delivered any XRP to the bridge.”
A technical breakdown from Reza Bashash filled in the mechanism: the attacker sent the bridge’s own wrapped token between two of their own wallets, attached a bridge-deposit memo, and because the token is issued by the bridge, the transfer showed up in its history and was read as a genuine deposit.
You may also like: ONE Dumps to ATL as Harmony Exploited in Unauthorized Mint of 4B Tokens Important Ripple News and XRP Price Update: August 11 Major XRP Ledger Upgrade Targets Institutional Adoption But There’s a Catch Relayers approved it, unbacked assets were minted on the Coreum side, and the attacker withdrew real XRP against them. Bashash put the total at 198,715.88 XRP, converted to ETH, routed through THORChain, and ultimately sent to Tornado Cash.
The tx says the vulnerability has been identified, the bridge remains halted, and it has filed a report with the FBI’s Internet Crime Complaint Center. No other bridged assets were affected, and the operator says a plan for compensating users is still being worked out.
A Deeper Look, and a Market Already Under Pressure A later on-chain review found the same root cause from a different angle: 21 separate Coreum relayers each attested to the same phantom deposit, letting the attacker mint bridge assets with nothing backing them, then repeated the trick with escalating amounts before cashing out.
Every payout that followed on the XRPL Ledger carried a valid multisignature from the bridge’s own relayer quorum, which is why the DefaultRipple explanation didn’t hold up once the transaction data was checked. Native XRP has no trust line to ripple along in the first place, and the flag governs only the bridge’s issued tokens.
The exploit landed while XRP was already sliding. The token sits near $1.02, close to a 21-month low, down roughly 4.4% this week as Bitcoin fell to about $64,000 and the broader crypto market shed some $40 billion in a day.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
According to CertiK’s monitoring, two transactions of 200 ETH each linked to the Coldcard attack incident were sent to Tornado Cash. The funds were first cross-bridged from BTC to an ETH address starting with 0x41B7 via THORChain, before being transferred to Tornado Cash.
Relevant content
US Treasury Department's removal of some Iran-related sanctions measures does not represent a policy shift.
According to Fox News, the U.S. Department of the Treasury has removed some Iran-related sanctions from its website. A Treasury official stated: "This does not represent any shift in U.S. policy toward the Iranian government, the Islamic Revolutionary Guard Corps-Quds Force, any designated terrorist organization, or their supporters or proxies. Today’s removal is part of normal administrative procedures, carried out after a review of specific circumstances related to Baghdad Aviation." Earlier, the Office of Foreign Assets Control (OFAC) under the U.S. Treasury Department released an "Update on Revoking Counterterrorism Designations," lifting some Iran-related sanctions, including removing Fly Baghdad (Baghdad Aviation) from the sanctions list. The airline had previously been added to the counterterrorism sanctions list due to its ties to the Islamic Revolutionary Guard Corps-Quds Force.
3 minutes ago
Circle secures USDC’s core position in the Coinbase ecosystem, as the three-year revenue-sharing agreement has been renewed.
Jeremy Allaire, founder and CEO of Circle, the issuer of USDC, stated during tonight’s earnings call: “We have renewed our agreement with Coinbase under existing terms, ensuring USDC remains central to all of Coinbase’s product offerings. We also look forward to expanding our USDC network via distribution deals with strategically aligned partners.” The collaboration agreement between Circle and Coinbase, signed on August 18, 2023, stipulates that Circle—USDC’s sole issuer—shares interest revenue generated from USDC reserve assets with Coinbase: Coinbase will receive 100% of reserve interest from USDC held on its platform, plus 50% of the remaining reserve interest from USDC held off its platform. The agreement has an initial three-year term and an automatic renewal mechanism.
3 minutes ago
Trade.xyz made its first purchase of HYPE using revenue from its HIP-3, acquiring 2,000 HYPE tokens valued at approximately $108,000.
Perpetual decentralized exchange (Perp DEX) Trade.xyz on the Hyperliquid chain has purchased HYPE for the first time using its HIP-3 revenue, acquiring 2,000 HYPE tokens worth approximately $108,000.
3 minutes ago
Trade.xyz has launched pre-IPO perpetual contracts for Unitree Robotics, with the current price standing at $69.
HIP-3 decentralized trading platform Trade.xyz has launched Unitree’s pre-IPO perpetual contract, currently quoted at $69, corresponding to a post-listing market cap of approximately $27.9 billion. Separately, HIP-3 decentralized trading platform Paragon also launched Unitree’s pre-IPO perpetual contract yesterday, with a current quote of $68.8. The UNITREE pre-market perpetual contract price represents the USD value of one ordinary Unitree share. Unitree’s STAR Market IPO plans to issue at least around 40.45 million shares, accounting for 10% of its total post-issuance share capital, with post-issuance total shares standing at approximately 404.5 million. The current contract price implies a market cap of $27.9 billion, equivalent to around 190.6 billion RMB. Unitree’s IPO prospectus targets an issuance valuation of approximately 42 billion RMB (around $5.8–6.2 billion), which is expected to deliver a 4.5x gain for new share subscribers after listing. Unitree is set to hold its initial public offering on the Shanghai Stock Exchange’s STAR Market, with its net subscription date scheduled for August 10, 2026.
3 minutes ago
The optical communication sector in the US stock market extended its gains from yesterday, with AAOI and COHR surging over 5%.
According to BIT (bit.com) market data, the U.S. optical communications sector extended its gains from yesterday, with the following performances: Pure Photonics ETF (FOTO) rose 2.2%; Corning (GLW) gained 0.52%; Marvell Technology (MRVL) increased 0.5%; AAOI (Applied Optoelectronics) climbed 5.1% — a manufacturer of 800G/1.6T high-speed optical modules focused on AI data center transceivers; LITE (Lumentum Holdings) rose 2.56%, a core supplier of optical communications lasers and modules and a key player in AI data centers; COHR (Coherent Corp) gained 5.86%, a leader in lasers, optical components and photonics solutions covering data center and industrial sectors; CIEN (Ciena Corporation) climbed 2.49%, which produces high-speed SerDes and connectivity chips and focuses on low-power interconnections for AI data centers. Yesterday’s development: The Trump administration is drafting a ban on imports of new Chinese data center components, and the U.S. Federal Communications Commission (FCC) plans to impose import restrictions on Chinese optical transceivers (used for high-speed fiber data transmission in data centers), aiming to announce and take effect within this year. A U.S. ban on new Chinese data center equipment imports could raise costs for U.S. cloud computing firms including Amazon Web Services (AWS, AMZN.O), forcing them to switch to alternative suppliers such as U.S.-based Coherent (COHR.N) and Lumentum (LITE.O).
3 minutes ago
The United States lifts sanctions related to Iran.
The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) has posted an update on its official website, lifting sanctions related to Iran.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
Changxin's pre-IPO price drops to $6, corresponding to an RMB share price of 40.62 yuan on its first day of listing.
According to Hyperinsight’s monitoring, the Pre-IPO contract price of CXMT (Changxin Memory Technologies, whose listed entity is Changxin Technology) on Hyperliquid has fallen to $6, with a more than 5.7% drop in 24 hours. The corresponding RMB share price stands at 40.62 yuan. Calculated based on the post-issue total share count of 66.881 billion shares, the on-chain implied market capitalization is approximately $400 billion, equivalent to around 2.7 trillion yuan. At this valuation, the subscription cost per lot of 500 shares for retail investors who win the online application is 4,330 yuan. The estimated market value of 500 shares on the first day of listing is 20,310 yuan, translating to a profit of roughly 16,000 yuan per lot.
16 minutes ago
The latest draft of the CLARITY Act includes an incentive clause for white hat hackers, proposing to offer rewards to individuals who identify security vulnerabilities.
The latest draft of the U.S. Senate’s Cryptocurrency Market Structure Act (the CLARITY Act) includes provisions encouraging white hat hackers to responsibly disclose cybersecurity vulnerabilities, proposing to authorize rewards for individuals who identify and report such flaws to bolster protection for digital asset infrastructure before they are maliciously exploited. The provision incorporates the views of former CFTC Chairman J. Christopher Giancarlo, a long-time advocate for digital asset innovation.
16 minutes ago
US tech giants have cut nearly 140,000 jobs this year, with the four leading players' AI capital expenditure totaling $725 billion.
According to statistics from the Financial Times in partnership with Challenger, Gray & Christmas, U.S. tech industry layoffs since 2026 have accounted for more than one-third of all announced layoffs nationwide. Amazon, Oracle, Meta and Microsoft alone have cut nearly 50,000 jobs, roughly 6% of their total workforce. In sharp contrast, Amazon, Alphabet, Meta and Microsoft are projected to invest a combined $725 billion in AI infrastructure such as data centers this year. After laying off staff in March, Oracle’s total headcount dropped by 21,000 for the full year; this month, S&P downgraded its credit rating, citing weak cash flow and uncertain AI returns. Microsoft cut 4,800 jobs this month, mainly in its Xbox gaming division, essentially a full reset of its $75 billion acquisition of Activision Blizzard three years ago. The narrative that "AI causes layoffs" is met with skepticism in academic circles. Enrico Moretti, an economics professor at the University of California, Berkeley, notes that AI-related layoffs are more of an excuse for management to correct over-hiring during the pandemic. "Claiming AI-driven efficiency gains is easier than admitting to over-hiring back then," he said. Market pricing also contradicts this narrative: within 30 trading days of announcing layoffs, companies that attributed cuts to AI saw their stock prices underperform the Nasdaq by nearly 10%, while companies laying off for other reasons lagged by only around 4%. Amazon and Microsoft have explicitly stated that AI adoption is not a decisive factor in their layoffs. In contrast to the tech giants’ non-core business contractions, AI-native startups like Anthropic and OpenAI are still rapidly expanding their workforce, driving fast growth in AI sector employment. "What is being cut is merely all other non-core business segments."
16 minutes ago
Layer1 project Vanar will begin migrating its infrastructure to Base next Tuesday.
Layer 1 blockchain project Vanar announced that its infrastructure migration to Base will kick off next Tuesday. Users currently staking VANRY must first unstake, wait for the cooldown period to elapse before claiming their tokens. Earlier, Vanar stated that existing VANRY token holders can complete the migration at a 1:1 ratio, with their holding amounts remaining unchanged. Additionally, VANRY’s total supply will rise from 2.4 billion to 10 billion tokens, approximately 62% of which will stay locked during the migration. Once the migration is complete, staking for Vanarchain validators will be halted.
16 minutes ago
2035年数据中心将占美国电力消耗的约20%,成为下一个AI瓶颈
U.S. data center power demand is projected to surge by 253% from 2026 levels, reaching a record 194 gigawatts by 2035 — with 1 gigawatt roughly matching the capacity of a traditional nuclear reactor. Currently, data centers consume 6% of the U.S.’s annual electricity; that share is estimated to climb to around 12% by 2030, and will account for roughly 20% of total U.S. electricity consumption by 2035. Most of the growth in U.S. power demand is concentrated in a handful of grid regions, such as the PJM Interconnection, which serves Washington, D.C. and 13 states including Virginia, Pennsylvania and Ohio. Power will be the next AI bottleneck.
16 minutes ago
Robinhood Chain's 24-hour network fee revenue reached $350,000, ranking fourth among all blockchains.
According to DeFiLlama data, Robinhood EVM Chain generated $350,000 in 24-hour network fee revenue, ranking fourth among all blockchains, trailing only Canton, Tron, and Solana. Launched on July 1, the Robinhood EVM Chain has seen its total value locked (TVL) quickly rise to $315 million. Though originally designed for on-chain stocks and ETFs, it has emerged as a major hub for meme coin activity.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
@THORChain x @Dashpay Podcast #197 ft. @TheDesertLynx, @KentonC137 & @patriotsounds | May 9, 2026
By @Raynalytics
TL;DRDash is coming to THORChain, bringing one of the most battle-tested cypherpunk chains in crypto onto the apex permissionless DEX.Dash's next release ships Zcash Orchard-level shielded privacy on its Evolution chain in the coming weeks, putting it alongside Zcash and Monero on the top tier of privacy tech.Dash has had deterministic 1-second instant finality since 2014, a feature uniquely suited to cross-chain swaps where speed and irreversibility actually matter.DashCon (Sept 3) and Common S3nse (Sept 4-5) are co-located in Amsterdam for Cypherpunk Week. Joel wants to use the moment to assemble THORChain, Maya, Dash, Zcash, Monero, Quai, and other freedom-aligned projects under one banner.Kenton called for a culture shift at THORChain: stop gating integrations on market cap. Smaller engaged communities bring marketing, network effects, and integrations that outweigh the dev cost.1. IntroductionJoel Valenzuela hasn't had a fiat bank account in ten years. He's spent a decade living almost entirely on crypto, currently runs business development and marketing for Dash, and in his own words "cyber-bullies Saylor on X for sport." He came on Podcast #197 to talk about Dash finally landing on THORChain, the Orchard-level privacy upgrade shipping in weeks, and a bigger pitch: it's time for the freedom-aligned corner of crypto to assemble at the same conferences, behind the same banner.
2. Meet Joel ValenzuelaFor those who don't know Joel (@TheDesertLynx): about 13 years in crypto, came in via sound money advocacy and his Mexican family's experience with the 1990s peso crash. He moved to New Hampshire for the Free State Project, then at the end of 2015 decided to go all-in: only get paid in crypto, eventually close the fiat bank account.
The bank actually closed it for him. After a fraud incident drained his account, the bank wanted to set him up with a replacement. He thought about it and never went back.
"The bank actually closed me out, but they wanted me back. And I just was like, let me think about it. And I just never went back."He's now spent about a decade living almost entirely on crypto. He runs business development and marketing for Dash, and is, in his own words, "the worst maxi shill in the world." He uses Dash because it works, but his framing is sovereignty first, ticker second.
3. Living on Crypto: Instant Finality and the Sovereign StackThe technical case for Dash that matters most for THORChain is 1-second deterministic finality. Dash transactions get locked by the master node network within about a second, and if a block ever shows up trying to conflict with that lock, the network rejects the block. There are no probabilistic confirmations, no waiting for reorgs to become statistically unlikely.
"As soon as you see a Dash transaction, it's permanent and you don't have to worry about that."This is the foundation of Dash's payments stack. The @Dashpay wallet has usernames, encrypted on-chain metadata (so transaction history isn't an Excel spreadsheet of addresses), and a contact list. The Dash Spend feature uses that instant finality to do something most chains can't: buy a gift card for the exact amount of your purchase, in real time, at checkout. Walk up to Home Depot, scan your items, see $68.49, open Dash Spend, get a barcode, scan it, done. No padding the gift card with dust, no waiting 10 minutes for confirmations.
Joel says Dash Spend reaches roughly 150,000 US merchants, plus a recent Eon Pay integration extending coverage across Southeast Asia.
His broader sovereignty stack: self-custody, no KYC, not denominated in dollars or stablecoins. He uses a private reloadable card for the edge cases where Visa/Mastercard rails are unavoidable. The goal, in his words, is to not need cards within three years.
4. The Privacy Catch-Up: Dash's Next ReleaseDash's history in privacy is unusual. It was the first crypto with explicitly built-in privacy features (the original 2014 "Darkcoin"), predating @monero by a few months. But Dash's integrated CoinJoin model hides the transaction graph while leaving amounts visible. Monero and @Zcash pulled ahead on amount-hiding with confidential transactions (2017) and zero-knowledge proofs respectively.
That gap is about to close. Dash's lead developer Quantum Explorer has been porting Zcash's Orchard shielded-pool technology to the Dash Evolution chain. The code is in the next release, expected in the coming weeks. When it lands, Dash will have Zcash-level shielded transactions with 1-second finality.
There's a second angle: Zcash has long promised shielded assets (ZSAs, fully private tokens), but that roadmap has effectively paused at Zcash.
"Dash is getting Zcash shielded assets before Zcash. Dash might act as a test net for, is there demand for a fully private stable coin."5. Why Dash on THORChain MattersTHORChain already has @Maya_Protocol deeply integrated with Dash, and Maya has shipped instant-transaction support in the past few months. The case for THORChain catching up is straightforward: with the privacy market clearly back in force, and with recent centralized-DEX incidents making the cost of cutting corners on decentralization visible again, this is the moment for THORChain to be the natural home for sovereign assets.
Once Dash lands, the list of coins available across all three major cross-chain DEXes (THORChain, Maya, Near Intents) becomes very short: $BTC, $ETH, Zcash, and Dash. That's the rock-solid tier where centralized exchange delisting risk no longer matters because the on-chain volume can carry it. Joel noted Dash has been affected by delistings more than any other coin in crypto, so a permanent home on a permissionless DEX is more than a nice-to-have for the project.
The Free State Project lifer who closed his bank account in 2016 is now spending political capital making sure his coin's volume can survive any centralized delisting on the planet. That's the alignment, and that's why this integration matters.
@KentonC137 used the segment to make a broader call: stop gating THORChain integrations on market cap. A 20-million-dollar project with an engaged community brings free marketing, network effects, and access to audiences THORChain doesn't otherwise reach. The cost is dev work and the node operator overhead of running another daemon. The upside is months of unpaid pitching from a passionate team.
"Market cap should not be a barrier entry when it comes to THORChain."Kenton flagged projects worth watching as integration candidates: @QuaiNetwork (PoW Layer 1 with hybrid privacy and strong recent momentum), Nym (decentralized VPN with Edward Snowden's endorsement), and Firo on the smaller end. He also raised decentralized storage like Filecoin and Arweave as future integration targets so cross-chain rails can settle storage payments without centralized fiat onramps.
6. Quick PSA: Free SamouraiKenton is using free Twitter ad credits on the THORChain account to amplify the Free Samourai movement, supporting @SamouraiWallet co-founder @KeonneRodriguez and his co-defendant Bill, both currently serving federal sentences after pleading guilty in July 2025. Twitter doesn't allow promoting exchange interfaces, but it does allow awareness campaigns. Kenton has framed this as the new Free Ross movement and Keonne's wife will be coming on the podcast soon. Every dollar counts, and the THORChain community can move the needle here.
7. Cypherpunk Week in AmsterdamBlock your calendar. Amsterdam, September 3-5, three back-to-back events at the same venue (De Hallen Studios):
DashCon, September 3. The first major Dash conference since the 2019 Zurich event, organized by Joel. THORChain is invited and there will be a cross-chain DEX panel.Common S3nse, September 4-5. Organized by @CryptoCanal; formerly known as ETHDam. Last year's keynote was Alexey Pertsev of @TornadoCash, delivered while wearing an ankle monitor.Hackathon runs alongside. Builders welcome.Sponsorship and ticket packages are bundled across all three. Confirmed freedom-aligned sponsors include @EdgeWallet, @Zcash, and @zano_project. Conference URLs: commons3nse.cryptocanal.org and dash-con.com.
8. Assemble the Avengers: The Cypherpunk CornerThe bigger pitch from Joel: at the major industry conferences (Consensus, Bitcoin Vegas, Token2049), there is no home for hardcore decentralized projects. The booths are dominated by stablecoin slop, custodial wallets, and Hoskinson-grade marketing budgets. Meanwhile the cypherpunk contingent has nowhere to congregate.
Joel's proposal: club together. THORChain, Maya, Dash, Zcash, Monero, Quai, Edge, Bitcoin Cash, and any other freedom-aligned project pitches in to share one "Cypherpunk Corner" at the big conferences. Color-coded shirts. Real product demos. Live swaps on-stage. Branding spicy enough to actually stand out against the corpo-AI booths.
"We can have this anchor, this shining beacon on a hill of all the actual hardcore people."The economics work: a single booth at one of these conferences can run $35K-$100K, but typically comes with 10-20 unused tickets per sponsor. Pool the sponsorship, pool the tickets, and you have a 50-100 person on-site presence showing up to one conference together, with one coordinated narrative.
@patriotsounds called this the most exciting idea of the episode. Kenton's in. The plan is to start with Common S3nse and DashCon in September, then scale to Consensus 2027.
9. Takeaways / What to WatchDash integration on THORChain. The roadmap is now official. Watch for development pace and pool launch.Dash's next release. Shielded transactions with Orchard tech at 1-second finality, shipping in weeks. This closes the privacy gap with Zcash and Monero.Cypherpunk Week, Sept 3-5 Amsterdam. DashCon and Common S3nse back-to-back at the same venue. Speaker slots and sponsorship are open.The open door policy. Kenton's call to lower the integration bar is worth tracking. If THORChain culture shifts here, the next 12 months could see a wave of smaller but engaged communities onboarded.Free Samourai movement. Twitter ad credits supporting the defense fund. Keonne's wife on the podcast soon.The Avengers thesis. Watch for a coordinated cypherpunk presence at the next round of major conferences."Taxation is theft. Your phone is spying on you. Fiat is a scam. Live on crypto before it's too late."More @THORChain data, check out Raynalytics
Follow @Raynalytics for more Weekly Analytics and Podcast recaps.
Morgan Stanley raises Micron's price target to $1,200, maintains 'Overweight' rating.
Morgan Stanley released a report raising Micron Technology (MU.O)’s price target from $1,050 to $1,200, while maintaining an "Overweight" rating. The investment bank lifted its fiscal 2027 earnings per share (EPS) forecast for the chipmaker by roughly 40% to $168, and upgraded its free cash flow (FCF) projection from $104 billion to $140 billion. Aligning with Micron’s management, the bank holds that AI will push DRAM demand to consistently outpace supply significantly after 2027. Micron’s last fiscal quarter results matched this trend, with both its quarterly performance and outlook showing notable upside potential.
5 minutes ago
US officials: Israel has withdrawn troops from parts of the buffer zone in southern Lebanon.
A U.S. State Department official said Israel has withdrawn from parts of the buffer zone in southern Lebanon, describing the move as a "goodwill gesture" toward the Lebanese government.
5 minutes ago
CBRS trades below IPO price post-earnings: Erases all gains six weeks after listing, two smart money firms net $5.8 million from first-day IPO shorts.
According to Hyperinsight monitoring, Cerebras (CBRS), the AI chip firm previously dubbed "Nvidia’s strongest challenger", saw its stock price fall in stages after reporting its first quarterly results since going public, as negative guidance overshadowed better-than-expected performance. The stock has dropped roughly 22% since the earnings release and officially broke below its IPO price today. On-chain whales are overall bearish. CBRS trades at $184 on the Hyperliquid platform, down 7.7% in 24 hours. Large-scale short positions (million-dollar level) total around $11.62 million, 2.39 times the long positions ($4.87 million). Two major short positions were placed precisely at high levels as early as the IPO day or even before the IPO: - Whale 0xe0ff: Shorted at $284.51 on May 14 with a 3x leveraged position of $6.13 million, generating an unrealized profit of $3.24 million (+104%); - Whale 0x9996: Shorted at $275.92 on May 11 with a 5x leveraged position of $5.48 million, generating an unrealized profit of $2.64 million (+162%). It is learned that both addresses currently hold short positions in both CBRS and SPCX, and have recorded substantial unrealized profits, preferring to place short positions at high levels before or on the day of major stock listings. With the realization of negative earnings news in this round, the combined unrealized profit of the two positions is around $5.88 million. Currently, the average entry price of CBRS short whales is around $275, and the current price is over 30% lower than that. The nearest short liquidation line is at $200.13, about 7% away from the current price.
5 minutes ago
Multiple high-performing domestic public mutual fund products have tightened their purchase restrictions.
E Fund Management announced in its latest filing that the E Fund Information Industry Select Fund, managed by Zheng Xi, has cut its purchase limit to 10,000 yuan. The same purchase limit reduction to 10,000 yuan applies to another fund under his management, E Fund Information Industry Fund, while E Fund Global Growth Select Hybrid Fund (QDII) has lowered its purchase limit to 10 yuan. In addition, Guolianan Preferred Industry Fund, Harvest Tech Innovation Fund, and Principal Performance-Driven Fund have also announced purchase limits or adjustments to their limits recently. Jin Zicai, a fund manager closely watched by the market, imposed additional purchase limits on multiple public offering funds under his management, with the four funds involved cutting their purchase limits to 500 yuan starting June 23. Purchase limits on high-performing funds likely stem from multiple considerations: they can avoid return dilution caused by short-term concentrated subscriptions, and proactive limits during overheated market conditions also send risk warning signals to the market. As the first half of the year draws to a close, such moves have become increasingly frequent. Overall, Wind data shows that since June alone, 19 funds with year-to-date net asset value returns exceeding 90% have suspended large subscriptions or adjusted their purchase caps. (Source: Cailian Press)
5 minutes ago
The US stock market's optical communication sector rises across the board in pre-market trading, with Corning up 9.28%.
According to Bitget market data, the U.S. stock market's optical communication sector saw broad pre-market gains, with MRVL rising 4.99%, LITE up 3.24%, Nokia up 3.11%, Corning up 9.28%, and AXTI up 6.69%.
5 minutes ago
US-listed AI chip stocks saw mixed pre-market performance, with Qualcomm surging 13%.
According to Bitget market data, U.S. AI chip stocks posted mixed pre-market performance: Qualcomm (QCOM.O) surged 13%, Intel (INTC.O) rose nearly 6%, AMD (AMD.O) gained nearly 4%, and Google (GOOG.O) declined 1.4%.
US-listed AI chip stocks saw mixed pre-market performance, with Qualcomm surging 13%.
According to Bitget market data, U.S. AI chip stocks posted mixed pre-market performance: Qualcomm (QCOM.O) surged 13%, Intel (INTC.O) rose nearly 6%, AMD (AMD.O) gained nearly 4%, and Google (GOOG.O) declined 1.4%.
4 minutes ago
Micron Technology surges 18% in pre-market trading on US stocks
According to Bitget market data, the US stock storage sector is seeing broad pre-market gains. Micron Technology (MU.O) jumps 18% in pre-market trading, as its strong earnings significantly exceeded expectations, with multiple major banks raising the stock’s target price. SanDisk (SNDK) rises 12.25%, Western Digital (WDC) gains 12.05%, and Seagate Technology (STX) climbs 8.63%.
4 minutes ago
SBI announced it will acquire cryptocurrency trading platform Bitbank for 46.7 billion yen.
According to Nikkei News, Japanese financial group SBI Holdings announced on the 25th that it will acquire cryptocurrency exchange platform bitbank for 46.7 billion yen (approximately $288 million). Upon completion of the transaction, SBI Group’s crypto asset custody scale is expected to exceed 1 trillion yen, making it one of the largest operators in Japan’s crypto industry. Per the plan, a subsidiary under SBI Holdings will acquire Bitbank shares from individual shareholders including its founders as early as August this year. Bitbank will then repurchase shares held by existing shareholders MIXI and Ceres by the end of October. If combining data from SBI’s own crypto exchange SBI VC Trade and Bitbank, as of April this year, the two firms had a total of around 2.92 million accounts and total custody assets of approximately 1.1 trillion yen. While different crypto exchanges disclose custody assets at varying time points, among Japan’s major industry competitors, bitFlyer held about 960 billion yen in custody assets as of the end of December 2025, and Coincheck had around 800 billion yen as of the end of March 2025.
4 minutes ago
Bithumb was fined for sharing user data overseas without consent.
South Korean regulatory authorities have ordered cryptocurrency exchange Bithumb to pay a 210 million won (approximately $136,000) fine for sharing user personal information with overseas platforms without user consent. According to an announcement released Thursday by South Korea’s Personal Information Protection Commission (PIPC), the relevant user data exposure occurred between September and November 2025. At that time, Bithumb transferred user information to overseas platforms while sharing its USDT market order book data. The PIPC also noted that when assisting users with asset transfers to 13 overseas exchanges, Bithumb failed to obtain full and sufficient user consent before sharing personal details including names, wallet addresses, and dates of birth. For the two violations, the PIPC not only imposed the fine but also ordered Bithumb to rectify its processes and management systems related to cross-border transmission of user information.
US-listed AI chip stocks saw mixed pre-market performance, with Qualcomm surging 13%.
According to Bitget market data, U.S. AI chip stocks posted mixed pre-market performance: Qualcomm (QCOM.O) surged 13%, Intel (INTC.O) rose nearly 6%, AMD (AMD.O) gained nearly 4%, and Google (GOOG.O) declined 1.4%.
4 minutes ago
Micron Technology surges 18% in pre-market trading on US stocks
According to Bitget market data, the US stock storage sector is seeing broad pre-market gains. Micron Technology (MU.O) jumps 18% in pre-market trading, as its strong earnings significantly exceeded expectations, with multiple major banks raising the stock’s target price. SanDisk (SNDK) rises 12.25%, Western Digital (WDC) gains 12.05%, and Seagate Technology (STX) climbs 8.63%.
4 minutes ago
SBI announced it will acquire cryptocurrency trading platform Bitbank for 46.7 billion yen.
According to Nikkei News, Japanese financial group SBI Holdings announced on the 25th that it will acquire cryptocurrency exchange platform bitbank for 46.7 billion yen (approximately $288 million). Upon completion of the transaction, SBI Group’s crypto asset custody scale is expected to exceed 1 trillion yen, making it one of the largest operators in Japan’s crypto industry. Per the plan, a subsidiary under SBI Holdings will acquire Bitbank shares from individual shareholders including its founders as early as August this year. Bitbank will then repurchase shares held by existing shareholders MIXI and Ceres by the end of October. If combining data from SBI’s own crypto exchange SBI VC Trade and Bitbank, as of April this year, the two firms had a total of around 2.92 million accounts and total custody assets of approximately 1.1 trillion yen. While different crypto exchanges disclose custody assets at varying time points, among Japan’s major industry competitors, bitFlyer held about 960 billion yen in custody assets as of the end of December 2025, and Coincheck had around 800 billion yen as of the end of March 2025.
4 minutes ago
Bithumb was fined for sharing user data overseas without consent.
South Korean regulatory authorities have ordered cryptocurrency exchange Bithumb to pay a 210 million won (approximately $136,000) fine for sharing user personal information with overseas platforms without user consent. According to an announcement released Thursday by South Korea’s Personal Information Protection Commission (PIPC), the relevant user data exposure occurred between September and November 2025. At that time, Bithumb transferred user information to overseas platforms while sharing its USDT market order book data. The PIPC also noted that when assisting users with asset transfers to 13 overseas exchanges, Bithumb failed to obtain full and sufficient user consent before sharing personal details including names, wallet addresses, and dates of birth. For the two violations, the PIPC not only imposed the fine but also ordered Bithumb to rectify its processes and management systems related to cross-border transmission of user information.
PANews reported on April 24 that, according to Ember, the hacker who stole approximately $98 million from Balancer last November has recently begun exchanging some of his ETH for BTC via the cross-chain protocol THORChain. Today, the hacker exchanged 7,000 ETH for 204.7 BTC (approximately $15.88 million), and the transaction is still ongoing. Currently, the hacker still holds 15,000 ETH (approximately $34.65 million) on the Ethereum blockchain and 204.7 BTC (approximately $15.88 million) on the Bitcoin blockchain.
US-listed AI chip stocks saw mixed pre-market performance, with Qualcomm surging 13%.
According to Bitget market data, U.S. AI chip stocks posted mixed pre-market performance: Qualcomm (QCOM.O) surged 13%, Intel (INTC.O) rose nearly 6%, AMD (AMD.O) gained nearly 4%, and Google (GOOG.O) declined 1.4%.
4 minutes ago
Micron Technology surges 18% in pre-market trading on US stocks
According to Bitget market data, the US stock storage sector is seeing broad pre-market gains. Micron Technology (MU.O) jumps 18% in pre-market trading, as its strong earnings significantly exceeded expectations, with multiple major banks raising the stock’s target price. SanDisk (SNDK) rises 12.25%, Western Digital (WDC) gains 12.05%, and Seagate Technology (STX) climbs 8.63%.
4 minutes ago
SBI announced it will acquire cryptocurrency trading platform Bitbank for 46.7 billion yen.
According to Nikkei News, Japanese financial group SBI Holdings announced on the 25th that it will acquire cryptocurrency exchange platform bitbank for 46.7 billion yen (approximately $288 million). Upon completion of the transaction, SBI Group’s crypto asset custody scale is expected to exceed 1 trillion yen, making it one of the largest operators in Japan’s crypto industry. Per the plan, a subsidiary under SBI Holdings will acquire Bitbank shares from individual shareholders including its founders as early as August this year. Bitbank will then repurchase shares held by existing shareholders MIXI and Ceres by the end of October. If combining data from SBI’s own crypto exchange SBI VC Trade and Bitbank, as of April this year, the two firms had a total of around 2.92 million accounts and total custody assets of approximately 1.1 trillion yen. While different crypto exchanges disclose custody assets at varying time points, among Japan’s major industry competitors, bitFlyer held about 960 billion yen in custody assets as of the end of December 2025, and Coincheck had around 800 billion yen as of the end of March 2025.
4 minutes ago
Bithumb was fined for sharing user data overseas without consent.
South Korean regulatory authorities have ordered cryptocurrency exchange Bithumb to pay a 210 million won (approximately $136,000) fine for sharing user personal information with overseas platforms without user consent. According to an announcement released Thursday by South Korea’s Personal Information Protection Commission (PIPC), the relevant user data exposure occurred between September and November 2025. At that time, Bithumb transferred user information to overseas platforms while sharing its USDT market order book data. The PIPC also noted that when assisting users with asset transfers to 13 overseas exchanges, Bithumb failed to obtain full and sufficient user consent before sharing personal details including names, wallet addresses, and dates of birth. For the two violations, the PIPC not only imposed the fine but also ordered Bithumb to rectify its processes and management systems related to cross-border transmission of user information.
PANews reported on April 25 that, according to on-chain analyst Ai Yi, the address associated with the Balancer theft incident in November 2025 (loss of over $116 million) transferred 5,609 ETH, equivalent to approximately $13 million, to the cross-chain protocol THORChain in the past 9 hours for further money laundering and cross-chain swaps.
As of April 25, the Balancer hackers had exchanged 14,300 ETH for 419.3 BTC (approximately $32.51 million) through THORChain, and are still dismantling and transferring the remaining stolen funds.
SBI announced it will acquire cryptocurrency trading platform Bitbank for 46.7 billion yen.
According to Nikkei News, Japanese financial group SBI Holdings announced on the 25th that it will acquire cryptocurrency exchange platform bitbank for 46.7 billion yen (approximately $288 million). Upon completion of the transaction, SBI Group’s crypto asset custody scale is expected to exceed 1 trillion yen, making it one of the largest operators in Japan’s crypto industry. Per the plan, a subsidiary under SBI Holdings will acquire Bitbank shares from individual shareholders including its founders as early as August this year. Bitbank will then repurchase shares held by existing shareholders MIXI and Ceres by the end of October. If combining data from SBI’s own crypto exchange SBI VC Trade and Bitbank, as of April this year, the two firms had a total of around 2.92 million accounts and total custody assets of approximately 1.1 trillion yen. While different crypto exchanges disclose custody assets at varying time points, among Japan’s major industry competitors, bitFlyer held about 960 billion yen in custody assets as of the end of December 2025, and Coincheck had around 800 billion yen as of the end of March 2025.
4 minutes ago
Bithumb was fined for sharing user data overseas without consent.
South Korean regulatory authorities have ordered cryptocurrency exchange Bithumb to pay a 210 million won (approximately $136,000) fine for sharing user personal information with overseas platforms without user consent. According to an announcement released Thursday by South Korea’s Personal Information Protection Commission (PIPC), the relevant user data exposure occurred between September and November 2025. At that time, Bithumb transferred user information to overseas platforms while sharing its USDT market order book data. The PIPC also noted that when assisting users with asset transfers to 13 overseas exchanges, Bithumb failed to obtain full and sufficient user consent before sharing personal details including names, wallet addresses, and dates of birth. For the two violations, the PIPC not only imposed the fine but also ordered Bithumb to rectify its processes and management systems related to cross-border transmission of user information.
4 minutes ago
Analyst: SK Hynix’s US listing and fund-raising could trigger a valuation re-rating.
According to Bloomberg, SK Hynix is set to issue American Depositary Receipts (ADRs) on the Nasdaq on July 10. The listing aims to raise nearly $30 billion, making it one of the largest ADR issuances in history. Market participants widely believe the move will significantly expand its global investor base and may drive a valuation re-rating. Multiple asset management firms project that if its valuation converges with Micron Technology’s, its share price could rise by 30% over the next year. One fund manager noted that SK Hynix should trade at a valuation at least on par with Micron, as demand for memory chips is likely to outpace supply for years to come. The listing comes amid an unusually strong boom in the memory chip sector. Shares of Micron, SK Hynix, and Samsung Electronics have all surged over 200% this year, marking their best annual performance in decades. Demand for High Bandwidth Memory (HBM) from AI servers is widely seen as the driver of a structural "memory supercycle".
4 minutes ago
Jefferies: Samsung is likely to follow SK Hynix’s example to list in the US via ADRs.
Jeff Kim, Head of Research at Jefferies, said Samsung is likely to follow SK Hynix in listing on the U.S. market via American Depositary Receipts (ADRs), which will boost the share price of the South Korean chipmaker whose valuation lags behind Micron. "Chip stocks are at a turning point. ADRs will serve as an important catalyst to drive their valuations," he added.
The hacker behind the Kelp DAO bridge exploit has moved nearly all unfrozen funds through privacy channels, leaving only a small balance in the original wallets.
Summary
Kelp DAO exploiter has laundered nearly all $220 million, leaving about $1.7M in original wallets. The funds moved through THORChain, Wasabi, Tornado Cash and Umbra, reducing direct tracing options now. Arbitrum’s $71M freeze remains the largest recoverable slice, with court claims now pending against it. The Kelp DAO hacker has laundered about $220 million in unfrozen funds, according to on-chain data cited by Arkham Intelligence. The funds moved through THORChain, Wasabi, Tornado Cash and Umbra, making direct tracking harder for investigators.
Source: Arkham Intelligence The report described the amount moved as “nearly all” of the unfrozen funds. It also said “roughly $1.7 million” remains in the original attacker wallets. That leaves a narrow path for direct recovery of the funds that were not frozen earlier.
Kelp DAO Hacker Has Laundered Nearly All $220M in Unfrozen Funds, Closing the Recovery Window
According to The Defiant, on-chain tracking data shows that the hackers behind the Kelp DAO bridge exploit, identified as North Korean threat group TraderTraitor, have laundered… pic.twitter.com/UlCj44BTa4
— Wu Blockchain (@WuBlockchain) June 2, 2026 Exploit traced to North Korea-linked actors The April attack drained about $292 million from Kelp DAO’s bridge. Chainalysis said the attackers released about 116,500 rsETH against a fake burn event after targeting off-chain bridge infrastructure, not Kelp DAO’s core smart contracts.
LayerZero’s incident report linked the attack to TraderTraitor, a North Korea-linked group also tracked as UNC4899 and part of the wider Lazarus ecosystem. The same wider threat network has been tied to other large crypto attacks this year.
Frozen funds remain the main recovery path A large part of the stolen assets did not move freely after the attack. Arbitrum’s Security Council froze more than 30,000 ETH soon after the exploit, creating the main pool still within reach of a recovery process.
The Defiant reported that the frozen portion is about $71 million. That sum is now tied to legal claims in the U.S., after families with unpaid judgments against North Korea sought control of the funds. The remaining unfrozen funds have largely moved through privacy tools.
Broader hack pattern As previously reported by crypto.news, North Korea-linked Lazarus attacks drained $577 million from Drift Protocol and KelpDAO in April. The same report said those two attacks made up 76% of all crypto theft tracked in 2026 through April.
Moreover, Radiant Capital will wind down operations after failing to recover from a $50 million exploit linked to North Korea-aligned actors, as crypto.news reported. The Radiant case showed how slow recovery, lost funding and laundering through Tornado Cash can leave a protocol with limited options.
For Kelp DAO, the latest laundering update does not close every legal or recovery route. The frozen ETH remains important. However, the unfrozen portion now appears much harder to recover through normal address-by-address tracing. The case adds pressure on bridge operators, DeFi teams and investigators to act before stolen funds enter privacy routes.
The window for tracing and recovering more than $220 million stolen from Kelp DAO’s bridge has all but closed. On-chain tracking data laid out in the original report shows that the North Korean threat group TraderTraitor has now laundered nearly every dollar of previously unfrozen funds, using a chain of privacy-focused platforms. Only around $1.7 million remains in the hackers’ original wallets, effectively ending any realistic prospect of direct, transaction-by-transaction asset recovery.
The speed and scale of the operation underscore a growing structural problem for DeFi bridges. Kelp DAO, an Ethereum-based restaking protocol, was hit by an exploit that exposed users to losses on par with some of the largest cross-chain breaches. The cleaning process moved assets through THORChain, Wasabi, Tornado Cash, and Umbra—a stack of mixing tools and cross-chain liquidity networks that make on-chain tracing extremely difficult. It also raises urgent questions about what, if anything, can still be done to disrupt the flow of funds into the hands of a state-sponsored unit already sanctioned by the U.S. for funding weapons programs.
How the $220 million disappeared The laundering did not rely on a single method. THORChain, a decentralized cross-chain liquidity protocol, let the attackers move assets between blockchains without requiring wrapped tokens or custodial bridges. Wasabi and Umbra added coinjoin-style privacy layers for Bitcoin and Ethereum, while Tornado Cash—already designated by OFAC—was used to break on-chain links further. Such a combination is not new, but the fact that it was executed by a group tied to the Lazarus umbrella shows the operational sophistication that regulated industry participants are up against.
Ethereum remains the most active chain by developer count, as recent activity data confirms, but its open composability is a double-edged sword. The same infrastructure that powers liquid staking and restaking can be exploited when bridge contracts are not airtight. For Kelp DAO users, the near-total movement of unfrozen funds marks a point of finality that few in the community wanted to accept this early.
The North Korea factor and regulatory friction TraderTraitor is one of several aliases linked to North Korean cyber teams that the U.S. Department of the Treasury and the FBI have identified as instrumental in stealing billions in crypto over the past few years. These operations are not ordinary hacks; they are viewed by intelligence agencies as a direct source of hard currency for Pyongyang’s sanctions-evasion apparatus. Every dollar that disappears into these laundering pipelines ends up beyond the reach of civilian recovery efforts and, often, beyond swift law enforcement intervention.
The laundering closes a chapter on traceability just as Washington lawmakers wrestle with the shape of future crypto oversight. A landmark bill that would set new rules for digital asset markets is now under fresh attack from the banking lobby, as reported in the legislative drama unfolding in the Senate. While legislative fights play out over market structure, hacks like the one at Kelp DAO continue to expose the gap between enforcement ambition and on-the-ground capability.
What remains uncertain Despite the closure of the direct tracing window, law enforcement and blockchain intelligence firms retain options, though they are limited. Funds that eventually hit centralized exchanges can be frozen if they are flagged in time, but the combination of THORChain swaps and mixing layers makes that a high-effort, low-probability endeavor. Some portion of the stolen value may already be outside any cooperative jurisdiction.
For DeFi protocols building bridges and restaking layers, the episode is a harsh reminder that recovery design must be baked into the earliest stages of smart contract architecture. Post-exploit freezes and negotiation, as seen in other incidents, did not produce a meaningful outcome here. The industry will be watching whether the remaining $1.7 million can yield any final intelligence—or whether it, too, will slip into the same opaque channels that swallowed the other 99.2 percent of the haul.
AUTHOR
Max delves deep into the cryptocurrency realm, with a passion for altcoins and NFTs. Convinced of crypto's transformative potential, he envisions a decentralized financial future. Max's background in the financial sector grants him unique insights into global monetary systems. In his leisure, Max embraces the thrill of adventures and is an avid sports enthusiast, finding balance and rejuvenation away from work.
THORChain has moved into the next phase of its recovery from the May 15 vault exploit.
Summary
Validators must approve v3.19.0 before THORChain begins its staged restart and fully restores network services. The upgrade adds compromised-vault quarantine and temporary keyshare checks before signing resumes across the network. ADR-028 applies the recovery plan without minting new RUNE or diluting existing token holders further. Validators are now reviewing version 3.19.0, which combines security patches with the ADR-028 loss-recovery plan.
The release also introduces a mechanism that can quarantine a compromised vault. THORChain said this would stop an affected vault from processing transactions while keeping its activity visible to the network.
Validators review THORChain v3.19.0 “The next major step in the recovery process is now underway,” THORChain said in its sixth incident update. Validators must vote to approve v3.19.0 before the network can begin the staged upgrade.
THORChain Incident Update #6
The next major step in the recovery process is now underway. Validators are being asked to review, approve, and prepare for the v3.19.0 upgrade, which contains the TSS security patches and ADR028 implementation designed to address the economic impact…
— THORChain (@THORChain) June 8, 2026 The release contains patches for the threshold signature system used to control THORChain vaults. It also implements ADR-028, the governance plan approved after the exploit. The protocol said the upgrade would move the network closer to restoring normal operations.
Version 3.19.0 includes a new Compromised Vault Mimir setting. Once enabled, the setting will isolate the drained vault from transaction processing without removing it from network monitoring.
Keyshare checks come before signing resumes THORChain plans to validate the ADR-028 data migration after validators complete the upgrade. Every node must then verify the integrity of its keyshares through a temporary protocol called keyverify.
Keyshares allow validators to sign vault transactions together without one operator holding the full private key. The added check aims to confirm that the remaining shares are intact before signing restarts.
After those checks, validators will unhalt signing and start a churn. Churning replaces the active validator set and transfers assets into newly generated vaults. The network will wait for that process to finish before restoring other services.
Secured and Trade assets will return first. Liquidity-provider actions will follow, while trading will resume at the end of the 11-step process. Each stage depends on the previous checks completing successfully.
ADR-028 covers losses without new RUNE As previously reported by crypto.news, THORChain validators approved ADR-028 in May. The plan uses protocol-owned liquidity to absorb losses before allocating any remaining shortfall across synthetic asset holders.
The framework does not mint or sell new RUNE. It also avoids direct dilution for existing holders. Future system income will help rebuild protocol-owned liquidity after the restart.
THORChain also activated a bounty window for the attacker and approved the full slashing of the linked node. The protocol said innocent nodes that shared the affected vault would remain protected.
Full restart still depends on validators The May 15 exploit drained about $10.7 million from one of THORChain’s five vaults. THORChain’s report said a newly added node exploited a weakness in the GG20 threshold signature implementation. Four other vaults remained unaffected.
Automatic solvency checks detected the imbalance and halted signing within minutes. Node operators later paused trading, chain observation and churning while developers investigated the attack.
Validator approval of v3.19.0 would begin the final technical sequence, but it would not restore every service at once. THORChain will reopen signing, asset functions, liquidity actions and trading in stages after completing the vault, migration, keyshare and churn checks.