The Philippine Securities and Exchange Commission (SEC) has issued a public investor alert warning Filipinos not to invest in dYdX and six other crypto trading platforms, saying they are not registered or authorized to solicit investments in the country.
In a Facebook post on Tuesday, the SEC named dYdX, Aevo, gTrade, Pacifica, Orderly, Deriv and Ostium, stating that based on its findings, the platforms appear to be offering investments to the public in exchange for promised returns, profits or interest.
The regulator said none of the listed entities are registered with the Commission or hold the required authorization under its crypto-asset service provider (CASP) framework, which requires firms offering crypto-related services in the Philippines to obtain licenses and meet capital and operational requirements.
The SEC also warned that individuals promoting any of the listed platforms in the Philippines may face criminal liability under the Securities Regulation Code. Under Sections 28 and 73 of the law, violators could be fined up to 5 million Philippine pesos (about $89,000) or imprisoned for up to 21 years, or both.
The advisory highlights a broader shift toward stricter enforcement in the Philippines, where regulators have increasingly moved from warnings to access restrictions. On Dec. 24, 2025, Philippine regulators blocked Coinbase and Gemini as part of their broader crackdown on unlicensed CASPs.
Philippine SEC advisory against dYdX. Source: Philippine SEC
Broader crackdown on unlicensed crypto operators
The latest advisory comes as Philippine regulators continue to step up enforcement against crypto platforms operating without local authorization.
In 2024, authorities moved to block access to Binance after a compliance deadline expired, with regulators also directing app stores to remove the trading platform’s app from users’ devices in the country.
Related: Cambodian lawmakers propose severe prison time for crypto scammers
The crackdown has since expanded to include other major platforms. In August 2025, the SEC issued an advisory naming 10 exchanges, including OKX, Bybit, KuCoin and Kraken, for offering crypto services without registration, warning that their activities exposed Filipino investors to risks.
While regulators have targeted unlicensed operators, compliant firms have continued rolling out crypto products. In 2025, PDAX partnered with Toku to enable stablecoin salary payouts, while digital bank GoTyme launched crypto services with Alpaca, allowing users to buy and hold digital assets within its app.
Magazine: Telegram avoids Philippines ban, yen carry trade going onchain: Asia Express
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently. Read our Editorial Policy https://cointelegraph.com/editorial-policy
The crypto market is showing signs of strength on Tuesday with bitcoin BTC$76,427.43 rising to $76,500, a gain of about 1% since midnight UTC.
The price spiked to around $77,000 at 9:45 a.m. before meeting a wave of spot sellers, who are probably protecting a potential breakout above Friday’s high of $78,300.
Ether (ETH) lagged behind bitcoin, rising just 0.3% to $2,320 as investors remained cautious around altcoins following the $290 million exploit on KelpDAO over the weekend.
Price action is still being dictated by the war in Iran, with the U.S. vice president due to travel to Pakistan for peace talks. A resolution is likely to lower oil prices, helping boost risk assets that have been inversely correlated since the war began.
U.S. stock index futures rose, demonstrating a return to risk-on sentiment.
Derivatives positioning
The long-short ratio for the crypto futures market is 50.68%, indicating a near-even split between bullish and bearish positions. In other words, traders are largely undecided on the direction of the market’s next move.
In the past 24 hours, major tokens such as BTC, SOL, HYPE and BNB have added 1%-3% in futures open interest (OI), a sign of capital inflows. ETH, DOGE and ZEC have seen slight declines in OI.
Open interest in AAVE futures has climbed to a record 3.59 million tokens. At the same time, the OI-adjusted cumulative volume delta has turned negative — indicating that sell orders are dominating and pushing into bids — while funding rates remain near zero. Taken together, the setup points to a slight bearish bias.
Bitcoin and ether funding rates remain negative, suggesting a bias toward short positions. This consistent bearish environment creates potential for a short squeeze. That’s a scenario in which price resilience prompts bears to mass-dump their bets, adding to the upward momentum in the spot price.
On the CME, activity in BTC futures continues to cool, even as the exchange-traded funds pull in millions. This combination indicates that inflows into the ETFs are mainly bullish directional plays rather than arbitrage bets involving a short BTC futures position against the ETF’s long position.
On Deribit, BTC and ETH puts continue to trade at a premium to calls, reflecting downside concerns.
Speaking of block flows (large trades executed over-the-counter), BTC straddles and strangles cumulatively account for over 50% of the activity over the past 24 hours.
Token talk
The altcoin market is still reacting to the weekend’s $290 million exploit on KelpDAO with decentralized finance (DeFi) tokens ethena (ENA), etherfi (ETHFI) and jupiter (JUP) all posting losses over the past 24 hours despite a marginal recovery since midnight UTC.
The CoinDesk Memecoin Index (CDMEME) is the worst-performing benchmark on Tuesday, losing 0.24% while the bitcoin-dominant CoinDesk 20 (CD20) is up by 0.65%.
The altcoin market is showing indecision, with the CoinDesk 80 (CD80) remaining flat during the Asia and European sessions.
AAVE is beginning to claw back some of its weekend losses after a 22% drop, adding 2.6% despite widespread negative sentiment across the DeFi sector.
CoinMarketCap’s “Altcoin Season” indicator is at 39/100, rising from the weekend’s low of 34/100, but still demonstrating investor preference for bitcoin over to altcoins.
The value of tokenized real-world assets on public blockchains is estimated at more than $29 billion, up more than 10% in the last 30 days.
OCBC, one of Singapore’s largest banking and financial services corporations, has launched a tokenized physical gold fund, with the underlying token, GOLDX, issued on both Ethereum and Solana.
The launch was made together with its asset management arm, Lion Global Investors and digital asset exchange DigiFT. The token is aimed at institutional investors, hedge funds and asset managers and can be bought and sold using both stablecoins and fiat currencies. After subscription, the token is delivered directly to investors’ blockchain wallets, OCBC said on Monday.
Kenneth Lai, head of global markets at OCBC, said the move is part of a new corporate strategy and a milestone in the corporation’s blockchain-focused approach.
“We believe digital assets will play an increasingly important role in financial services and our focus is on bridging traditional finance with the emerging world of decentralized finance,” he said.
The value of tokenized real-world assets on public blockchains has been on the rise in 2026, and is sitting at over $29 billion, up over 10% in the last 30 days, according to data from rwa.xyz.
The value of tokenized real-world assets on public blockchains is estimated at $29 billion. Source: rwa.xyz
GOLDX token tied to a physical gold fund
OCBC’s GOLDX token offers on-chain exposure to the LionGlobal Singapore Physical Gold Fund, which launched in December and had about $525 million (669 million Singapore dollars) in assets under management as of April 16, according to OCBC.
Related: Singapore Gulf Bank adds stablecoin mint and redeem for 24/7 settlement
The goal of the tokenized fund is to attract Web3 ecosystem participants and high-net-worth individuals who operate in blockchain and cryptocurrency ecosystems, according to OCBC.
OCBC has used blockchain technology before, starting with its first tokenized equity-linked note for accredited investors in 2023. Its total assets were estimated at about $526 billion as of December 2025.
Magazine: Will the CLARITY Act be good — or bad — for DeFi?
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently. Read our Editorial Policy https://cointelegraph.com/editorial-policy
Cab Payments has accused its largest shareholder, Helios, of blocking a takevover bid from StoneX in order to force through its own hostile takeover.
Editorial
This content has been selected, created and edited by the Finextra editorial team based upon its relevance and interest to our community.
The board of Cab Payments has already dismissed an earlier bid from Helios – which owns 45% of the firm’s equity – as “highly opportunistic”.
Last week US trading juggernaut Stone X tabled a sweetened l110p per share offer for the payments firm. CAB’s directors recommended its shareholders accept the bid, which valued the company at £241m, a 29 per cent premium to Helios’s largest offer.
However, as Cab Payments largest shareholder, Helios has the power to vote down the takeover approach.
Cab Payments has hit out at Helios over the decision, accusing it of depriving “minority shareholders of the opportunity to realize value at a significant premium to the Helios Consortium’s firm offer”.
The saga is the latest twist in the recent chequered history of Cab Payments. The B2B payments firm raised up to £335 million through a listing on the London Stock Exchange in July 2023 at a valuation of more than £800 million.
However, within three months, its share price had halved after the company revised revenue guidance sharply downwards, leading to the departure of its CEO. Shares currently trade at more than 70% below its initial listing price.
Bank of Korea Governor Shin Hyun-song used his first address in office to prioritize central bank digital currencies (CBDCs) and bank-issued deposit tokens, while leaving out any mention of stablecoins as South Korea weighs new crypto rules.
Shin, who began his four-year term Tuesday, pointed to the bank’s ongoing retail CBDC and deposit-token pilot, Project Hangang, and its role in Project Agorá, a cross-border tokenization effort led by the Bank for International Settlements, according to news outlet Chosun.
He framed digital currency as part of a broader shift in central banking during a period of economic strain and slower domestic growth.
The absence of stablecoins from his remarks stood out. The issue has dominated policy debate in Seoul, with lawmakers considering the Digital Asset Basic Act, which would set rules for stablecoin issuance.
Shin had told lawmakers at his confirmation hearing that stablecoins could coexist with CBDCs and deposit tokens in a “supplementary and competitive” manner.
His speech also outlined a bank-led model where the central bank would issue a CBDC, while commercial banks would provide deposit tokens fully convertible into it. Shin has argued that any stablecoin issuance should begin with regulated banks.
Beyond payments, Shin signaled closer scrutiny of crypto markets and non-bank finance. He said the central bank would expand monitoring of cryptocurrencies and other nontraditional assets, and seek broader access to data to track financial risks.
Shin also pledged steps to modernize currency markets, including 24-hour foreign exchange trading and an offshore won settlement system.
Horizon Quantum Computing Pte. Ltd. (“Horizon Quantum”), a pioneer of software infrastructure for quantum applications, today announced the debut of Beryllium, a hardware-agnostic, high-level language for programming quantum computers.
Beryllium is an object-oriented language, allowing developers to start with simple classical and quantum building blocks and progressively create richer, higher-level structures by reusing and extending what they have already defined. This layering of abstraction is designed to empower developers to think in terms of information structure rather than qubits and low-level processing details.
By shifting focus from how information is physically represented and processed in a quantum computer to how it can be structured and transformed, Beryllium is designed to raise the level of abstraction, reducing the need to manage quantum processing directly and making quantum software development more accessible to programmers without deep quantum expertise.
Beryllium is the third of four abstraction layers that Horizon Quantum has been pursuing as part of its ambitious plan to develop technology that bridges classical computer programming and quantum-accelerated implementation.
Developers will be able to access Beryllium through Triple Alpha, Horizon’s integrated development environment. Beryllium will sit alongside Triple Alpha’s other Turing-complete languages: Helium—a BASIC-like language that supports concurrent classical/quantum workflows—and Hydrogen—a portable, assembly-like language that allows for general control flow.
“At Horizon Quantum, we believe that enabling conventional software developers to harness quantum computers will be key to unlocking new applications,” said Dr. Joe Fitzsimons, founder and CEO of Horizon Quantum. “We believe Beryllium is an important milestone, as we introduce the abstraction needed to bridge the gap between classical and quantum programming.”
Horizon Quantum will preview Beryllium this week at Q2B Silicon Valley, a leading quantum technology conference. The company will also introduce additional technological progress across its software stack, including new pulse-level capabilities and the ability to execute its Hydrogen code directly on control systems hardware.
Bitcoin (BTC) rose 2.66% to around $75,800 on Monday after Strategy disclosed a $2.54 billion purchase, the company’s third biggest ever, and equivalent to about 2.5 months of new BTC supply.
However, several indicators suggest the rally may fizzle out.
BTC/USD daily chart. Source: TradingView
Key takeaways:
Poor macro conditions can spark BTC price pullback if Strategy’s buying slows.
Bitcoin’s technical setup hints at a potential dip toward $67,000–$69,000.
Strategy may halt BTC purchases this week
Strategy funded most of its latest 34,164 BTC purchase through its preferred stock, Stretch (STRC), which generated over $2.17 billion through at-the-market share sales between April 13 and April 19.
Source: Strategy’s SEC Filings
That accounted for roughly 86% of the total amount spent, while sales of its Class A common stock, MSTR, added another $366 million.
STRC lets Strategy raise cash for Bitcoin when it trades at or above $100. Stronger prices mean easier fundraising and more BTC buying. In 2026, STRC enabled the purchases of 77,000 BTC, ten times more than all the ETFs combined, per River data.
Bitcoin ownership YTD change. Source: River
But STRC has been trading below its $100 par value since April 15, which may limit Strategy’s ability to keep raising cash to purchase more Bitcoin this week.
STRC weekly estimates. Source: STRC.LIVE
In past episodes, pauses in Strategy’s Bitcoin purchases have coincided with BTC price slumps.
For instance, on average, BTC’s price has dipped by roughly 30% when STRC traded below its $100 par value.
BTC/USD vs. STRC daily performance chart. Source: TradingView
A 30% dip will take Bitcoin’s price to $53,000 when measured from current levels.
Source: X
The halt appears alongside weakening risk sentiment, with US stock indexes falling amid doubts over the US–Iran peace deal.
Nasdaq, S&P 500, and Dow Jones daily performance charts. Source: TradingView
US President Donald Trump said it was “highly unlikely” he would extend the two-week truce if no agreement is reached before it expires on Wednesday.
Any signs of an extended Middle East conflict may weigh on BTC’s prices.
BTC flag pullback hints at $67,000–$69,000
Bitcoin’s current chart structure shows classic flag consolidation, with price now drifting toward the pattern’s lower boundary. This setup raises the risk of a pullback toward the $67,000–$69,000 region in April, if support gives way.
BTC/USD daily chart. Source: TradingView
At the same time, downside may remain limited as the 20-day (green) and 50-day (red) EMAs continue to act as dynamic support levels. Holding above these averages would signal underlying demand, increasing the chances of a rebound.
Related: Adam Back says current demand is ‘almost’ enough to send Bitcoin to $1M
If that happens, BTC could attempt a breakout above the flag’s upper trend line, effectively invalidating the bearish setup.
Such a move would open the door for a recovery toward the 200-day EMA (blue), currently near $82,750.
As Cointelegraph reported, breaking the resistance near $78,000 is now a top priority for the bulls.
This article is produced in accordance with Cointelegraph’s Editorial Policy and is intended for informational purposes only. It does not constitute investment advice or recommendations. All investments and trades carry risk; readers are encouraged to conduct independent research before making any decisions. Cointelegraph makes no guarantees regarding the accuracy or completeness of the information presented, including forward-looking statements, and will not be liable for any loss or damage arising from reliance on this content.
In a detailed incident report, Aave service providers quantified the protocol’s exposure for the first time and outlined two scenarios depending on how Kelp DAO allocates the loss. LayerZero and Kelp continue to blame each other for the compromised bridge configuration.
Aave service providers on Monday published an incident report quantifying the protocol’s exposure to the April 18 Kelp DAO rsETH bridge exploit, outlining two bad-debt scenarios ranging from $123.7 million to $230.1 million, and recommending an immediate pause of the protocol’s Umbrella safety module.
According to the report, posted to the Aave governance forum, 89,567 of the 116,500 rsETH stolen from Kelp’s LayerZero bridge were deposited across seven attacker-controlled wallets on Aave. Those positions borrowed 82,650 WETH ($190.86 million) and 821 wstETH ($2.33 million).
The single largest position, on Aave’s Ethereum Core market, supplied 53,000 rsETH and borrowed 52,460 WETH, or $121 million, from one wallet. The remaining positions were distributed across Aave’s Arbitrum deployment. All attacker positions currently sit at health factors between 1.01 and 1.03.
Kelp subsequently recovered 40,373 rsETH by freezing a second attempted drain. That balance is the only confirmed backing for 152,577 rsETH of claims across every L2, a pro-rata backing ratio of 26.46%. Ethereum mainnet rsETH is backed separately by Kelp’s underlying ETH staking deposits.
Two bad debt scenarios
The report declined to commit to a single bad-debt figure, stating that the outcome depends on decisions outside Aave’s control — primarily how Kelp accounts for the loss and whether it updates its LRTOracle exchange rate.
Under Scenario 1, a uniform socialization across all rsETH holders on all chains, each token takes a 15.12% haircut. Total bad debt reaches $123.7 million, with the Ethereum Core WETH reserve absorbing $91.8 million, or a 1.54% shortfall. Mantle absorbs $10.4 million, or 9.54% of its WETH reserve, the most proportionally acute.
Under Scenario 2, losses are isolated to rsETH on L2s. Remote-chain rsETH is repriced to its 26.46% backing ratio, or a 73.54% haircut, while Ethereum mainnet rsETH is unaffected. Total bad debt rises to $230.1 million, all concentrated on L2s.
In this scenario, Mantle faces a 71.45% shortfall ($77.7 million), Arbitrum 26.67% ($88.4 million), Base 23.28% ($47.5 million), and Ink 18% ($13.9 million). Ethereum Core is untouched.
Umbrella covers only Ethereum Core reserves. Under Scenario 2, it would not activate.
Balance sheet disclosure
The report disclosed the Aave DAO’s financial position. As of April 20, the treasury holds $181 million — $62 million in Ethereum-correlated holdings, $54 million in AAVE tokens, and $52 million in stablecoins. The DAO generated $145 million in revenue in 2025 and $38 million year-to-date in 2026, with operating cash flow of $149 million in 2025 and $40 million year-to-date.
Aave DAO service providers are “leading an effort with ecosystem participants to address a potential bad-debt scenario,” the report said, and the effort has received “indicative commitments from various parties.” It did not identify the parties or quantify the commitments.
The report also recommended the DAO immediately pause the WETH Umbrella module. As of writing, 18,922 of the 23,507 aWETH staked in Umbrella — approximately 80% — have already entered the 20-day unstaking cooldown. A pause would block further deposits, withdrawals, transfers, and slashing. Coverage under a paused module would need to be handled manually through governance rather than automatically.
A second-order liquidation risk
The report also quantified the risk of further bad debt if ETH falls in price while Aave’s WETH reserves remain at 100% utilization. Because idle WETH balances are below $20 on every affected chain, liquidators cannot receive WETH as underlying and instead receive aWETH receipts, which keeps their capital inside the reserve and slows liquidation throughput.
At a 50% ETH price drop, Aave modeled $100.8 million of residual bad debt on Ethereum alone, with smaller amounts on Arbitrum, Base, Linea, and Mantle. Arbitrum and Base were flagged as particularly vulnerable because wstETH looping positions on those chains run at health factors around 1.03 — meaning first liquidations would trigger at ETH price drops of just 0.77% and 1.77%, respectively.
LayerZero and Kelp continue to trade blame
The Aave report did not assign blame for the underlying bridge exploit. LayerZero and Kelp DAO have continued to publicly attribute the incident to each other.
In a Sunday post-mortem, LayerZero Labs attributed the attack to the DPRK-linked Lazarus Group. The company said attackers compromised two downstream Remote Procedure Call (RPC) nodes used by its LayerZero-operated Decentralized Verifier Network (DVN), and introduced malicious software that returned forged data only to the DVN, then launched a DDoS attack to force failover to the poisoned RPC nodes.
LayerZero said the protocol itself was not exploited and attributed the attack’s success to Kelp’s use of a 1-of-1 DVN configuration.
In a rebuttal reported by CoinDesk on Monday, a source familiar with Kelp’s position said a communications channel between the two teams had been open since July 2024 and that LayerZero had not issued a specific recommendation to change the rsETH DVN configuration. The source said the compromised DVN was LayerZero’s own infrastructure and that Kelp’s core restaking contracts were not affected.
Yearn Finance core developer known on X as @banteg, published a technical review showing LayerZero’s public V2 OApp Quickstart uses a 1-of-1 DVN setup in its reference configuration across Ethereum, BSC, Polygon, Arbitrum, and Optimism. CoinDesk reported approximately 40% of applications on LayerZero currently run 1-of-1 configurations.
LayerZero has said it will no longer sign messages for any application using a 1-of-1 DVN configuration.
“DeFi has spent years auditing smart contracts. Kelp is the moment the industry realises the threat doesn’t end at the code. Most protocols are completely exposed at the infrastructure layer,” said Yair Cleper, Co-Founder and CEO of MagmaDevs and contributor to Lava Network, a decentralized marketplace for blockchain data providers.
Combined market up 30%, to record US $12.2 billion, fueled by strong AI-driven IaaS growth
Demand for technology services in Europe continued to accelerate in the first quarter, driven by strong demand for the cloud-based infrastructure services needed to power AI, the latest state-of-the-industry report from Information Services Group (ISG) (Nasdaq: III), a leading global technology research and advisory firm, shows.
Europe has turned the corner, as the region continues to embrace the power of AI to transform business. We’re seeing explosive growth in infrastructure services and steady growth in managed services, as companies take out cost to fund their AI ambitions.Share
The EMEA ISG Index™, which measures commercial outsourcing contracts with annual contract value (ACV) of US $5 million or more, shows ACV for the combined market (both managed services and cloud-based as-a-service) climbed 30 percent in the first quarter, to a record US $12.2 billion. Sequentially, the market was up 12 percent from its previous high in the fourth quarter. Over the last seven quarters, EMEA’s combined market has risen by double-digits in six of them, averaging 22 percent year-on-year growth in that span.
“Europe has clearly turned the corner, as the region continues to embrace the power of AI to transform business,” said Anthony Drake, president of ISG’s EMEA region. “We’re seeing explosive growth in infrastructure services and steady growth in managed services, as companies focus on cost optimization to fund their AI ambitions. In the first quarter, business process outsourcing was a bright spot, as AI begins to positively impact these services.
“Overall, the promise of AI is clearly outweighing the impact of geopolitical concerns,” Drake added.
First-Quarter Results by Segment
ACV in the as-a-service (XaaS) segment soared 52 percent year on year, to a record US $7.5 billion. It was the segment’s highest growth rate since the third quarter of 2021, and the eighth consecutive quarter of double-digit year-on-year growth, during which time growth averaged 36.5 percent a quarter. Sequentially, the XaaS market was up 17 percent versus the fourth quarter of 2025.
Within this segment, infrastructure-as-a-service (IaaS) climbed 72 percent, to US $6.1 billion—its fastest quarterly growth rate in more than seven years—while software-as-a-service (SaaS) advanced only 0.7 percent, to US $1.4 billion.
Managed services ACV in the first quarter rose nearly 6 percent, US $4.7 billion, its second-best quarter ever, and only the second time EMEA produced two US $4 billion-plus quarters in a row. There were 285 managed services contracts signed in the quarter, up 2 percent from the prior year, including three mega deals (ACV of US $100 million or more), the same as last year, but with the ACV of those deals up 22 percent year on year. New scope ACV was up 15 percent, to US $3.3 billion, only the second time the region has reached that figure.
Within managed services, IT outsourcing (ITO) slid 16 percent, to US $2.9 billion, with all areas down except for bundled infrastructure and application development and maintenance (ADM) services, up nearly 300 percent, and end user computing (EUC), up 60 percent. Business process outsourcing (BPO), meanwhile, soared 145 percent, to US $1.3 billion, versus a weak first quarter last year, but was up 25 percent sequentially. The biggest gainers were HR, facilities management and industry-specific services, all up triple digits, while call center services, the largest area of BPO, eked out a 0.7 percent increase. Engineering, research and development (ER&D) services, meanwhile, was up 4 percent, to US $399 million.
By industry, managed services ACV was sharply higher in telecommunications (up 192 percent) and retail (up 105 percent), while energy and transportation were both up about 30 percent. However, the region’s two largest sectors—banking, financial services and insurance (BFSI) and manufacturing—were a drag on growth, down 43 percent and 30 percent, respectively.
Geographic Performance
The region’s largest market, the U.K., posted its second consecutive US $1 billion-plus quarter, up 6 percent year on year, to US $1.2 billion. France rose 15 percent, to US $954 million, while Benelux and Southern Europe, two similar-sized markets at about US $400 million, were up 22 percent and 8 percent, respectively. DACH, however, declined 20 percent, to US $716 million, its slowest quarter in two years, and the Nordics was down 33 percent, to US $359 million, its worst quarter since the third quarter of 2024.
New ISG AI Index™ Launched
ISG last week announced the launch of its ISG AI Index™, a first-of-its-kind benchmark that measures how AI is impacting the global technology and business services sector. The initial findings were presented during the ISG Index call last Thursday. They show that infrastructure-as-a-service (IaaS) has seen the greatest impact from AI, up 160 percent. Software as-a-service (SaaS) has risen 53 percent while managed services is up only slightly, at 0.3 percent. On a market-weighted basis, the composite ISG AI Index was up 77 percent since inception, dating to December 2022, just after the launch of ChatGPT 3.0 and the start of the current AI era. Visit this webpage for more details.
2026 Global Forecast
ISG said it is raising its full-year forecast for XaaS revenue growth to 25 percent, up 400 basis points from its January forecast, and is holding its managed services growth forecast at 2.1 percent for the year. The forecasts reflect ISG’s view that XaaS growth will continue to accelerate on strong demand for AI, while managed services growth will remain “steady” as enterprises focus on cost takeout to fund their AI initiatives.
Crypto security is expanding beyond digital threats, with criminals increasingly targeting individuals directly through physical coercion rather than trying to exploit blockchain vulnerabilities or hack wallets.
The French case illustrates how attackers used a fake police raid and violence to force a Bitcoin transfer worth $1 million, bypassing encryption entirely by compelling the victim to authorize the transaction.
Wrench attacks are rising, with criminals using threats or force instead of technical exploits. This highlights how human vulnerability can override even the most secure cryptographic systems.
Impersonating authority figures such as police is highly effective because it combines fear, urgency and social conditioning, making victims more likely to comply without questioning the situation.
Digital defenses are no longer the only front line in crypto security. While phishing and exchange hacks have long been major threats, a growing number of thefts now bypass code entirely and target crypto holders directly.
A recent case in France highlights this shift. Attackers posing as police staged a “raid” and physically coerced a couple into transferring nearly $1 million in Bitcoin (BTC). This was not a failure of software, but a high-stakes robbery carried out through physical force.
When the victim, not the wallet, becomes the target
The incident occurred in Le Chesnay-Rocquencourt, a town near Paris, where a couple in their late 50s was allegedly assaulted inside their residence.
Here is the chronology of the incident:
Three individuals disguised as police officers gained entry to the home.
The couple was threatened at knifepoint.
The husband was forced to send Bitcoin to the attackers.
Both victims sustained injuries, and the husband was physically restrained and tied up.
The assailants fled the scene in a vehicle.
French authorities are currently investigating the matter, with charges including armed robbery and organized criminal conspiracy.
What distinguishes this case is not only the use of violence, but the specific strategy employed.
Rather than attempting to crack encryption, the perpetrators bypassed it entirely by coercing the owner into authorizing the transfer.
Why impersonating police officers is so effective
Posing as law enforcement officials is often effective because it taps into several psychological triggers:
Authority: People are socially conditioned to obey police directives.
Urgency: The appearance of an official raid creates the impression that immediate compliance is necessary.
Fear: Any resistance can seem as though it may lead to criminal consequences.
When criminals present themselves as police, victims often fail to question:
The reason for their presence.
The legitimacy of their demands.
The authenticity of the entire situation.
Under stress, the impulse to obey tends to overpower the instinct to verify or question what is happening.
In crypto, this risk is even greater because a single approved transaction can move significant funds in seconds.
Did you know? The term “wrench attack” became popular in the crypto space after an online comic joked that threatening someone physically is easier than breaking encryption. It reflects a real-world shift in which attackers bypass complex systems by targeting people rather than technology.
From simulated police raid to coerced Bitcoin transfer
Unlike conventional robberies that target cash, jewelry or other tangible items, this assault specifically targeted digital cryptocurrency holdings.
The attackers’ objective was straightforward: force the victim to carry out an immediate crypto transfer.
This form of theft can be difficult to contain for several reasons:
Stolen funds can be transferred anywhere in the world within minutes.
Blockchain transactions are generally irreversible.
Once transferred, funds can be moved quickly, which can make tracing and recovery more difficult.
When the victim retains direct control over their wallet, criminals do not need to steal hardware or break through security. They only need to force the victim to approve and send the transaction personally.
Understanding wrench attacks in the cryptocurrency space
It is often far easier to threaten a person with a wrench than to try to crack their encryption.
Rather than attempting to hack a wallet, perpetrators may use:
Threats
Physical violence
Other forms of coercion
These methods are used to force victims to reveal private keys or authorize the transfer of funds. Such attacks bypass even the strongest technical protections.
No matter how strong the encryption is, human vulnerability can make that security irrelevant.
Did you know? Some high-net-worth crypto holders now use “decoy wallets” with small balances. In a coercive situation, they can reveal these wallets instead of their main holdings, adding an extra layer of psychological and financial protection.
Why these attacks are becoming more frequent
Several underlying factors are driving this increase:
Growth in self-custody: A rising number of users now hold their own private keys and manage their assets directly, making them more immediate and accessible targets.
Visibility of high-value targets: Many cryptocurrency investors, company founders and executives maintain public profiles that make their wealth and identity relatively easy to identify.
Advances in cybersecurity: As digital wallet security improves and remote hacking becomes more difficult, criminals are increasingly turning to the softer target, the human user.
Instant global liquidity: Cryptocurrency enables near-instant transfers of value anywhere in the world without banks or intermediaries acting as gatekeepers.
In 2025 alone, documented cases of verified wrench attacks reportedly rose sharply, increasing 75% from 2024. Europe, and France in particular, stood out as a growing hotspot for such incidents. Financial losses reached $40.9 million in 2025, marking a 44% annual increase. While kidnapping remained the primary threat vector, physical assaults surged by 250%.
Why France has experienced a surge
France has recently recorded multiple high-profile violent crimes linked to cryptocurrency:
Kidnappings carried out to extort cryptocurrency ransoms.
Home invasions specifically targeting high-profile figures in the crypto industry.
Coordinated operations by organized criminal groups aimed at stealing digital assets.
These recurring incidents point to a shift in criminal behavior:
More deliberate efforts to identify individuals who hold cryptocurrency.
Increased surveillance of their physical locations and daily routines.
A growing preference for direct physical targeting over purely digital methods.
As cryptocurrency adoption continues to expand, public awareness of who owns it is also growing. Unfortunately, the physical risks associated with that visibility are rising as well.
Why criminals increasingly choose coercion over hacking
Crypto security has become increasingly strong. Hardware wallets, multisignature setups and cold storage solutions make remote hacking far more difficult.
Coercion, however, changes the equation.
Even the strongest technical protections may fail if a victim is coerced into unlocking their hardware device, revealing their credentials or authorizing a transaction.
Coercive attacks bypass cryptographic defenses entirely, target points of human access and exploit natural human reactions.
For perpetrators, this approach is often faster and more reliable than trying to break through technical defenses.
Why Bitcoin remains particularly exposed in duress situations
Bitcoin’s core architecture gives it considerable strength, but it also creates significant vulnerability when the owner is under coercion.
Its key features include:
The ability to transfer value immediately
The absence of any central entity capable of reversing transactions
Permissionless, worldwide accessibility
In a situation where the holder is forced to transfer funds, these traits can result in:
Assets being moved almost instantly
Virtually no realistic chance of recovery
Attackers rapidly moving funds across multiple addresses
The same qualities that give Bitcoin its independence and value also make stolen funds extremely difficult to recover once they are transferred under duress.
Did you know? Private security firms have started offering specialized protection services for crypto investors, including travel risk assessments, home security audits and digital footprint reduction strategies aimed at preventing targeted attacks.
How French authorities are responding
French law enforcement agencies are actively investigating the incident, with specialized organized crime units leading the effort.
Potential criminal charges under review include:
Although authorities are increasing enforcement in response to such incidents, these cases continue to present serious challenges because of:
The rapid cross-border movement of stolen assets
The pseudonymous and irreversible nature of cryptocurrency transactions
The involvement of organized and professional criminal groups
Key security takeaways for cryptocurrency owners
This incident underscores a major shift in the nature of cryptocurrency security threats.
Protecting technical systems alone is no longer enough. Safeguarding wallets, private keys and physical devices must now be paired with strong personal security measures.
Essential protective steps include:
Never publicly reveal or discuss the extent of your cryptocurrency holdings.
Keep your real-world identity separate from your wallet addresses and ownership.
Use multisignature wallets so that no single individual or compromised key can authorize transfers.
Distribute signing authority and key control across different geographic locations or trusted parties.
Cointelegraph maintains full editorial independence. Guides are produced without influence from advertisers, partners or commercial relationships. Content published in Guides does not constitute financial, legal or investment advice. Readers should conduct their own research and consult qualified professionals where appropriate.