Home Blog Page 470

Clarity Act returns to U.S. Senate, Bank earnings: Crypto Week Ahead

0

The week ahead will see the U.S. Senate return from recess, with the Clarity Act on the agenda while the National Credit Union Administration’s window for comments on stablecoin issuer rules closes.

On top of that, April 15 brings the U.S. tax filing deadline, which could put pressure on cryptocurrency holders managing their finances and add volatility to the market.

The macro front will see markets digest critical data, including U.S. producer price inflation, to help assess the Federal Reserve’s interest-rate policy direction.

Earnings from Goldman Sachs, JPMorgan and BlackRock could provide additional hints on how their crypto-linked ventures are faring and how institutional appetite is evolving.

What to Watch

(All times ET)

  • Crypto
    • April 13: U.S. Senate returns from recess and negotiations on the Clarity Act will resume.
    • April 13: Comment period closes for the U.S. National Credit Union Administration’s proposed rule on permitted payment stablecoin issuer applications
    • April 15: U.S. tax filing deadline, including crypto, for individual income tax returns.
    • April 17: Mercado Libre shuts down Mercado Coin.
  • Macro
    • April 13: China M2 Money Supply YoY for March est. 8.9% (Prev. 9%)
    • April 14, 8:30 a.m.: U.S. Producer Price Index (PPI) MoM for March (Prev. +0.7%); Core PPI MoM (Prev. 0.5%)
    • April 15, 09:00 p.m.: China GDP Growth Rate YoY for Q1 est. 5% (Prev. 4.5%)
    • April 16, 04:00 a.m.: Euro Area Consumer Price Index (CPI) rate YoY for March est. 2.3% (Prev. 2.4%)
    • April 16, 7:30 a.m.: U.S. Initial Jobless Claims for week ending April 11 (Prev. 219K)
    • April 17, 2:00 p.m.: U.S. Fed Governor Christopher J. Wallet speech on Economic Outlook.
  • Earnings (Estimates based on FactSet data where available)
    • April 13: Goldman Sachs (GS), pre-market, $16.41
    • April 14: JPMorgan Chase (JPM), pre-market, $5.47
    • April 14: BlackRock (BLK), pre-market, $12.06
    • April 15: Morgan Stanley (MS), pre-market, $3.02
    • April 16: Bank of New York (BNY), pre-market, $1.93

Token Events

  • Governance Votes & Calls
    • Compound DAO is voting on several cross-chain market updates, including implementing CAPO price feeds on Unichain, deprecating stMATIC on Polygon, switching to API3 oracles on Ronin, and expanding collateral limits for Polygon markets. Voting ends April 13.
    • Lido DAO is voting on operational updates covering a 10,000 stETH LDO accumulation program, a node operator governance transition, incentive redirects, multisig policy updates, and increased Alliance BORG transfer limits. Voting ends April 13.
    • OlympusDAO is voting to determine the distribution timeline for its Cooler Drip acceleration, choosing between an accelerated 3-month, moderate 6-month, or conservative 12-month cadence for daily gOHM rewards. Voting ends April 13.
    • Decentraland DAO is voting to remove an inactive catalyst node from its network following its shutdown, a move that will also rebalance the network to maintain four foundation nodes and five community nodes. Voting ends April 14.
    • Cardano DAO is voting to authorize a treasury withdrawal of 50 million ADA to support the Cardano x Draper Dragon: Orion Fund. Voting ends April 14.
    • ENS DAO is voting to automate treasury operations by routing revenue directly to the endowment for immediate yield and allowing the treasury manager to maintain a six-month operational runway without routine votes. Voting ends April 14.
    • Squid DAO is voting to approve the category weightings for its April SQUID token drop, which rewards community members for March activities across various areas. Voting ends April 15.
    • SafeDAO is voting to allocate 5 million SAFE to fund a six-month staking rewards program and interface development for Safenet Beta. Voting ends April 20.
  • Unlocks
    • April 15: Connex (CONX) to unlock 1.52% of its circulating supply worth $18.39 million.
    • April 16: Arbitrum (ARB) to unlock 1.75% of its circulating supply worth $10.8 million.
    • April 17: DeBridge (DBR) to unlock 12.9% of its circulating supply worth $9.19 million.
  • Token Launches
    • April 15: HTX Global to complete its quarterly HTX token burn.
    • April 15: Tradoor airdrop expected to begin.

Conferences

Attacker mints $1 billion Polkadot tokens on Ethereum, steals just $250,000

0

Crypto hacks are nothing new, but cases where attackers take big risks and walk away with peanuts aren’t common. That rare scenario played out on Sunday.

An attacker exploited a vulnerability in Hyperbridge’s cross-chain gateway that connects different blockchains, minting 1 billion Polkadot tokens ($1.19 billion) on Ethereum and dumping them for approximately $237,000 worth of ether.

The exploit adds to a growing list of bridge vulnerabilities in 2026. Last month saw a $270 million Drift Protocol drain on Solana, while a social engineering attack, rather than a code exploit, similarly involved compromised infrastructure.

The Sunday exploit targeted the bridge contract, not Polkadot’s core network. Polkadot’s native token DOT was unaffected. The vulnerability sat in how Hyperbridge’s EthereumHost contract validates incoming cross-chain messages before passing them to the TokenGateway.

Bridges, which help move coins from one blockchain to another, remain the weakest link in cross-chain architecture because they hold admin-level control over token contracts on destination chains, meaning a single validation failure can grant an attacker the ability to mint unlimited supply.

Here’s how attack unfolded

On-chain traces show that the attacker submitted a forged message via dispatchIncoming, which was routed to TokenGateway.onAccept.

The request receipts check, which should have verified the message against a valid cross-chain state commitment from Polkadot, stored an all-zeros commitment value, suggesting the proof validation was either absent or circumventable for this specific call path. The gateway processed the message as legitimate.

The accepted message executed changeAdmin on the bridged Polkadot token contract, transferring admin rights to the attacker’s address. With admin control, the attacker minted 1 billion tokens in a single transaction and routed them through Odos Router V3 into a Uniswap V4 DOT-ETH pool, extracting roughly 108.2 ETH across what appears to be multiple swaps at slightly different prices.

Liquidity worked against the attacker

Weak liquidity/depth, or the market’s ability to absorb large orders at stable prices, is usually a major issue for whales. But, in this case, it worked against the attacker, capping its profit.

The bridged DOT pool on Ethereum held limited depth, meaning 1 billion tokens overwhelmed the available liquidity and the attacker received a fraction of a cent per token.

On a deeper pool or a higher-value bridged asset, the same vulnerability would have produced significantly larger losses. DOT trades just under $1.20 as of Asian morning hours on Monday.

CertiK flagged the exploit, confirming the attack vector was the Hyperbridge gateway contract and that the attacker profited approximately $237,000 from minting and selling the bridged tokens.

Hyperbridge has not publicly commented on the exploit or disclosed whether other bridged token contracts using the same gateway are vulnerable to the same forged-message attack vector.

Bitcoin Bearish Flag Is Still In Play, So Price Could Crash Again

0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

Crypto analyst Captain Faibik has announced that the Bitcoin price is still very much bearish despite the recovery. This comes after the market sentiment shifted as the Bitcoin price began to surge last week and then eventually claimed the $70,000 resistance, turning it into support again. Despite a lot of Bitcoin investors turning bullish off of this, the crypto analyst is still not convinced, believing that the current uptrend us actually only temporary.

Why The Bitcoin Price Is Still Bearish Despite Reaching $73,000

Last week, the Bitcoin price surged high, rising more than 5% and reaching $73,000 before meeting resistance. This has naturally led to more positive sentiment after weeks of negative sentiment, bringing a much-needed relief rally to investors who have suffered major losses.

Despite this, Captain Faibik does not believe that this calls for celebration and is instead choosing a very conservative stance. As for the current uptrend, the crypto analyst believes it could eventually continue, putting a possible peak right between $77,000 and $78,000 due to the liquidity there.

Other than this liquidity grab, there seems to be nothing else suggesting that the bitcoin price has turned bullish. Even after the push upward to get liquidity, the next direction is expected to be downward, triggering a possible 20% correction in this regard. This correction, as the analyst explains, could lead the price to push back into the $54,000-$56,000 area.

Bitcoin price
Source: X

If this trend does play out and the price does push this low, it could mean a new cycle low for the digital asset. This will erase the current cycle support, which still lies at $60,000. Nevertheless, the crypto analyst points this out as a possible play, saying that the bears are actually still in control of the Bitcoin price.

Despite being bearish on Bitcoin, the crypto analyst remains bullish on the altcoin market. He explains that while stabling most of his funds, a good chunk (30%) is currently sitting in the altcoin market, which the analyst expects to be be more bullish than Bitcoin from here. According to the analyst, investors need to be patient and wait for confirmation first before making a move.

Bitcoin price chart from Tradingview.com
BTC price still holding $70,000 support | Source: BTCUSD on Tradingview.com

Featured image from Dall.E, chart from TradingView.com

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

Morgan Stanley’s Bitcoin ETF on track to pull in $7bn in year one, says Ric Edelman

0

Morgan Stanley’s new Bitcoin exchange-traded fund looks set for a blockbuster debut year, said Ric Edelman, founder of the Digital Assets Council of Financial Professionals.

His forecast is based on the fund’s opening day performance on Wednesday that drew in $33 million in flows.

“That’s a pace of $7 billion in the first year,” Edelman told DL News. “The flywheel is just starting to spin.”

For those wondering, Edelman is no stranger to finance. He’s the founder of Edelman Financial Engines, which manages nearly $300 billion for around 1.3 million clients. He’s commonly found on Barron’s list of the planet’s most important financial advisers, along with hosting a nationally syndicated radio show with more than one million weekly listeners.

So when he makes a prediction, Wall Street pays attention.

Morgan Stanley is the first Wall Street bank to offer Bitcoin exposure to its clients. The firm’s 16,000 financial advisers manage around $6.2 trillion in assets.

Three-way win

To reach that $7 billion target, Edelman reckons Morgan Stanley will attack the market from three angles.

First, it will drain assets from already-existing crypto ETFs as investors switch to Morgan Stanley because of its lower fees.

Second, fresh capital will pour in from clients who’ve been waiting for their trusted bank to offer Bitcoin.

Third, Morgan Stanley’s new ETF legitimises Bitcoin by making it an in-house branded product rather than just listing competitors’ funds, argued Edelman.

Wednesday’s $33 million debut is already auspicious.

“Combined, these will lead to broader adoption of crypto by investors nationwide,” he told DL News. 

Pedro Solimano is a markets correspondent with DL News. Got a tip? Email him at psolimano@dlnews.com.

View source version on dlnews.com: https://www.dlnews.com/articles/markets/how-morgan-stanley-7bn-blockbuster-debut-ric-edelman/

View source version on dlnews.com: https://www.dlnews.com/articles/markets/how-morgan-stanley-7bn-blockbuster-debut-ric-edelman/

View source version on dlnews.com: https://www.dlnews.com/articles/markets/how-morgan-stanley-7bn-blockbuster-debut-ric-edelman/

View source version on dlnews.com: https://www.dlnews.com/articles/markets/how-morgan-stanley-7bn-blockbuster-debut-ric-edelman/

View source version on dlnews.com: https://www.dlnews.com/articles/markets/how-morgan-stanley-7bn-blockbuster-debut-ric-edelman/

View source version on dlnews.com: https://www.dlnews.com/articles/markets/how-morgan-stanley-7bn-blockbuster-debut-ric-edelman/

AI Routers Can Steal Credentials and Crypto

0

University of California researchers have discovered that some third-party AI large language model (LLM) routers can pose security vulnerabilities that can lead to crypto theft. 

A paper measuring malicious intermediary attacks on the LLM supply chain, published on Thursday by the researchers, revealed four attack vectors, including malicious code injection and extraction of credentials. 

“26 LLM routers are secretly injecting malicious tool calls and stealing creds,” said the paper’s co-author, Chaofan Shou, on X.

LLM agents increasingly route requests through third-party API intermediaries or routers that aggregate access to providers like OpenAI, Anthropic and Google. However, these routers terminate Internet TLS (Transport Layer Security) connections and have full plaintext access to every message. 

This means that developers using AI coding agents such as Claude Code to work on smart contracts or wallets could be passing private keys, seed phrases and sensitive data through router infrastructure that has not been screened or secured.

Multi-hop LLM router supply chain. Source: arXiv.org

ETH stolen from a decoy crypto wallet 

The researchers tested 28 paid routers and 400 free routers collected from public communities. 

Their findings were startling, with nine routers actively injecting malicious code, two deploying adaptive evasion triggers, 17 accessing researcher-owned Amazon Web Services credentials, and one draining Ether (ETH) from a researcher-owned private key.

Related: Anthropic limits access to AI model over cyberattack concerns

The researchers prefunded Ethereum wallet “decoy keys” with nominal balances and reported that the value lost in the experiment was below $50, but no further details such as the transaction hash were provided. 

The authors also ran two “poisoning studies” showing that even benign routers become dangerous once they reuse leaked credentials through weak relays.

Hard to tell whether routers are malicious

The researchers said it was not easy to detect when a router was malicious.  

“The boundary between ‘credential handling’ and ‘credential theft’ is invisible to the client because routers already read secrets in plaintext as part of normal forwarding.” 

Another unsettling find was what the researchers called “YOLO mode.” This is a setting in many AI agent frameworks where the agent executes commands automatically without asking the user to confirm each one.

Previously legitimate routers can be silently weaponized without the operator even knowing, while free routers may be stealing credentials while offering cheap API access as the lure, the researchers found.

“LLM API routers sit on a critical trust boundary that the ecosystem currently treats as transparent transport.” 

The researchers recommended that developers using AI agents to code should bolster client-side defenses, suggesting never letting private keys or seed phrases transit an AI agent session.

The long-term fix is for AI companies to cryptographically sign their responses so the instructions an agent executes can be mathematically verified as coming from the actual model. 

Magazine: Nobody knows if quantum secure cryptography will even work