Home Blog Page 77

Millions of European crypto users face a sudden hunt for new digital asset platforms

0

The immediate impact will fall on customers whose exchanges are withdrawing services, Fazel told CoinDesk

Several exchanges, including Binance, have announced changes to their European services ahead of the July 1 deadline, while others continue seeking MiCA authorization or adjusting their products.

“When a platform pulls back, users unfortunately absorb the shock, like a tenant being evicted by its landlord with no notice,” Fazel said. “People shouldn’t keep hunting for a new home. They should pick one built to stay.”

“When you’re choosing a new home, the price is one thing.”But we need to look at the identity match, the platform, its culture, its security, the features you’ll actually use, and the community you’re joining.”

“Incentives fade,” he added. “A home you trust doesn’t.”

Coinbase and OKX last week offered deposit and transfer incentives to attract new users amid some exchanges scaling back services in Europe.

Fazel said those offers may persuade some customers to switch, but argued they should not be the deciding factor.

“Every exchange is piling into the same rat race of bigger bonuses, louder cheques,” he said. “But money does not earn trust. A local track record does.”

Crypto analytics firm Chainalysis proposes standards for blockchain tracing

0

The ontology lays out how Chainalysis views the role of attribution to these clusters, presenting a two-tier structure; the first tier “defines the structural graph,” while the second assesses how confident the analysis is in that graph.

“What does it mean that these addresses belong together, right? It’s clearly because somebody believes that they are under the control of the same entity, right?” Illum said. “Maybe it’s an exchange, or maybe it’s a darknet market, or maybe it’s a mixer, or whatever. But what are the grounds to establish that these things actually belong together?”

Investigators likely won’t have private keys, which would be the easiest way to tell if a cluster of addresses is all being controlled by the same entity, so they would then have to look at onchain data.

Illum was also clear about the limitations of this type of analysis: While Chainalysis could conduct research into transactions and clusters, it cannot, on its own, identify the actual end user without additional information.

Chainalysis could track funds to a crypto exchange, for example, or another entity managing wallets on behalf of customers, but investigators might need to issue a subpoena to identify who the customer is.

In other words, who controls a wallet or what entity is associated with the wallet are separate questions from the actual tracing aspect.

J.P. Morgan broadens Kinexys blockchain settlement network as banks modernize cross-border payments

0

J.P. Morgan has expanded the number of currencies supported by its Kinexys blockchain payments platform, a move that could make it easier for multinational companies to move money between countries at any hour of the day.

The bank added the Australian dollar, Hong Kong dollar, Japanese yen, Chinese renminbi and Singapore dollar to Kinexys’ Blockchain Deposit Account network, a feature that lets clients move tokenized bank deposits over the platform. The new additions join the U.S. dollar, euro and British pound, giving institutional clients access to eight currencies for blockchain-based settlement and foreign exchange.

The announcement comes as banks look for ways to solve a longstanding problem in global finance: moving money faster across borders without transactions having to go through multiple banks limited by local banking hours.

Kinexys is designed to remove some of those delays. Instead of relying solely on traditional payment rails, it uses a permissioned blockchain network operated by J.P. Morgan to record and settle transfers between participating clients. Because the platform runs continuously, businesses can move funds, exchange currencies and manage liquidity 24 hours a day, seven days a week.

Strategy (MSTR) Surges 12% As Bitcoin Regains $60,000

0

Shares of Strategy Inc. climbed 14% at times on Monday to roughly $94, their best single-day gain in weeks, after the bitcoin treasury company unveiled a sweeping capital overhaul.

The move marks a significant shift for the company once synonymous with an unrelenting bitcoin accumulation strategy. Strategy’s board approved a new Digital Credit Capital Framework that authorizes up to $1.25 billion in bitcoin sales to fund a newly created U.S. dollar reserve, cover preferred dividend obligations, and service debt. 

The company also authorized $1 billion in common stock buybacks and $1 billion in repurchases of its preferred securities.

The company raised the dividend rate on its Variable Rate Series A Perpetual Stretch Preferred Stock, known as STRC, to 12% annually — a 50 basis point increase effective July 1.

Strategy held 847,363 BTC as of June 28, purchased for an aggregate $64.10 billion at an average price of $75,651 per coin. With bitcoin trading near $60,000 Monday afternoon, the company sits on an unrealized loss on its entire stack — context that makes the new monetization framework more than just financial engineering. 

The company said it has approximately $2.55 billion in U.S. dollar reserves, covering roughly 17 months of annual preferred dividend and interest obligations of about $1.76 billion.

The stock had been grinding lower since hitting a high near $200 earlier this year in May, pulled down by bitcoin weakness and broader risk-off pressure. Monday’s bounce, driven largely by the capital plan announcement, brought shares back above $92 intraday, with a session peak near $94.

Other crypto and bitcoin-linked stocks also started the week out strong. 

Nakamoto (NAKA) shares surged more than 10% at points during Monday’s session, among the day’s strongest movers in the crypto equity space. Strive (ASST) climbed over 3.5% at its intraday peak. Coinbase (COIN), by contrast, saw a more muted session — shares up around 2% at their high.

Strategy and bitcoin price action

Bitcoin price shed roughly 6% over the past week, pulling back from a high near $64,400 earlier in the period to trade around lows of $58,800 today — a grind lower that has tracked weakness across broader risk assets.

Bitcoin price has now dropped more than 18% on the month, with the June candle opening near $76,690 and finding no sustained bid on the way down. 

Six straight weeks of ETF outflows, totaling tens of millions in institutional selling, have weighed on the price throughout the stretch. Bitcoin remains below its key 50-month exponential moving average near $65,600, a level that technicians watch as a line between short-term recovery and deeper correction territory.

Bitcoin Magazine is published by BTC Inc, a subsidiary of Nakamoto Inc. (NASDAQ: NAKA)

Golden Dolphin Plans $300M China New-Energy Asset Tokenization With RWA Global

0

  • RWA Global Inc. will advise Golden Dolphin Trading on a plan to tokenize about $300 million in China new-energy mobility assets.
  • The initiative aims to create a compliant route for qualified global investors to access China’s clean-mobility infrastructure through regulated RWA tokens.

RWA Global Inc. has signed an advisory agreement with Golden Dolphin Trading L.L.C. to support the planned tokenization of about $300 million in Chinese new-energy mobility assets, according to the company’s announcement.

Golden Dolphin is a UAE-domiciled company focused on new-energy mobility infrastructure and services in China. RWA Global, an international real-world asset tokenization consultancy, will act as strategic adviser as the companies explore a compliant route for qualified global investors.

The deal comes shortly after China moved to formalize oversight of offshore tokenized asset-backed securities tied to onshore assets. In February 2026, the China Securities Regulatory Commission issued rules requiring domestic entities controlling the underlying assets to make regulatory filings before offshore issuance.

That makes the Golden Dolphin mandate more than a routine tokenization project.

For years, global investors have had limited direct access to China’s domestic infrastructure growth. The new framework does not open the market broadly, but it creates a supervised route for offshore issuance backed by Chinese assets, while China keeps its wider restrictions on cryptocurrencies in place.

RWA Global said its work with Golden Dolphin will focus on building a legal and regulatory pathway for foreign investment into tokenized Chinese real-world assets. Further milestones are expected as the partnership develops.

“This engagement is about far more than a single transaction,” said Kevin Yunai, founder and chief executive officer of RWA Global Inc. “China’s new-energy economy is among the most dynamic in the world, yet global investors have had few compliant ways to participate in it directly. Tokenization changes that.”

Yunai said the Golden Dolphin work is “a first step toward building a transparent, regulated bridge between international capital and Chinese real-world assets,” adding that the opportunity could eventually be “measured not in millions, but in billions.”

The target asset class is large.

China is the world’s biggest new-energy vehicle market. Sales of new-energy vehicles reached 16.49 million units in 2025, up 28.2% from a year earlier, according to CAAM data reported by CnEVPost.

That fleet requires a growing charging network.

China aims to build a national network of 28 million charging facilities by the end of 2027, with public charging capacity sufficient to meet demand from more than 80 million electric vehicles, according to a 2025 action plan.

These are capital-intensive assets.

Charging stations, battery services and mobility infrastructure require large upfront investment, but can generate recurring cash flows over time. That profile is one reason infrastructure has become an attractive test case for real-world asset tokenization.

The global tokenization market is growing, but it remains uneven.

RWA.xyz currently tracks about $441.38 billion in represented real-world asset value, including about $299.41 billion in stablecoin value and $27.65 billion in distributed asset value. That gap shows why headline asset value and live, circulating tokenized value are not the same thing.

Longer-term forecasts are larger.

Standard Chartered and Synpulse have projected that demand for tokenized real-world assets could reach $30.1 trillion by 2034. BCG and ADDX previously estimated asset tokenization could become a $16.1 trillion opportunity by 2030.

Large financial institutions have already moved into tokenized financial assets.

BlackRock’s BUIDL fund overtook Franklin Templeton’s OnChain U.S. Government Money Fund in 2024. This shows how quickly tokenized Treasury products can scale when institutional distribution and compliance are in place.

JPMorgan has also entered the market.

In December 2025, J.P. Morgan Asset Management launched its first tokenized money-market fund, My OnChain Net Yield Fund, on the public Ethereum blockchain. The fund is aimed at qualified investors and is powered by Kinexys Digital Assets.

But physical infrastructure is harder to tokenize than Treasury bills.

Treasuries and money-market funds have standardized pricing, liquid reference markets and well-understood custody arrangements. EV charging networks involve local permits, utilization rates, operating costs, power-grid access, asset verification and cash-flow monitoring.

That is where the Golden Dolphin project will be tested.

The key questions are whether the underlying assets are clearly identified, whether cash flows can be audited, whether foreign investors have enforceable economic rights, and whether the tokenized instrument qualifies under both offshore securities rules and China’s new filing regime.

China has already seen early RWA experiments.

Chinese companies have explored tokenizing assets ranging from prized trees to tea and liquor, often through Hong Kong-linked structures. The same report noted market concerns that supply of tokenized assets could grow faster than actual investor demand.

The regulatory backdrop has been uneven.

In September 2025, China’s securities regulator reportedly asked some mainland brokerages to pause real-world asset tokenization activity in Hong Kong, signaling concern over the rapid expansion of offshore digital-asset initiatives.

That is why the RWA Global-Golden Dolphin agreement is notable.

It is not simply another tokenization announcement. It is an attempt to apply the model to Chinese clean-mobility infrastructure after regulators moved to define the rules for offshore tokenized securities backed by onshore assets.

Donna Tang, partner at Esquare Legal, said the engagement is “more than the tokenization of a single asset,” calling it an early step toward “building a compliant offshore bridge between China’s real industrial value and global capital.”

Tang said RWA tokenization could give international investors “a more transparent, regulated, and sustainable way to participate in China’s clean-energy opportunities,” while supporting cross-border investment and the energy transition.

Why does this matter?

The success of the project could help create a repeatable model for financing Chinese clean-mobility infrastructure with offshore capital. That would be significant because China’s EV ecosystem is already operating at global scale, while foreign participation in domestic infrastructure remains constrained.

The risk is that tokenization may not solve the hardest part.

Putting an asset on-chain can improve settlement, transferability and transparency. But it does not automatically create liquidity, investor protection or enforceable claims. Those still depend on legal structure, disclosure, asset verification, custody, compliance and secondary-market demand.

That is why the RWA Global-Golden Dolphin agreement will be judged less by the $300 million headline figure than by execution.

Right now, it’s an advisory mandate, not a completed token issuance. The next meaningful milestones will be regulatory filings, asset-level disclosures, investor eligibility details and proof that the structure can attract qualified capital beyond the announcement stage.

The above article “Golden Dolphin Plans $300M China New-Energy Asset Tokenization With RWA Global” was first published on AlexaBlockchain. Read the complete article here: https://alexablockchain.com/golden-dolphin-plans-300m-china-new-energy-asset-tokenization-with-rwa-global/

Read Also: Polygon’s 5,000 TPS Upgrade Could Make Stablecoin Payments Viable for Payroll, Remittances and B2B Settlement

Disclaimer: The information provided on AlexaBlockchain is for informational purposes only and does not constitute financial advice. Read complete disclaimer here.

Bitcoin-backed lending is making a comeback, according to Silicon Valley Bank

0

The growth case rests on a simple dynamic: as bitcoin ownership broadens and prices rise, holders increasingly want to borrow against appreciated collateral for tax efficiency, working capital or lifestyle needs, while lenders gain comfort underwriting overcollateralized loans secured by a highly liquid asset.

The bitcoin lending industry was reshaped by the failures of Celsius, BlockFi, and Genesis during the 2022–2023 crypto credit crisis. While each firm had different business models, they shared common vulnerabilities: maturity mismatches, excessive leverage, concentrated counterparty exposure and the rehypothecation of customer assets.

Their collapses underscored the importance of conservative underwriting, transparent risk management, and fully collateralized lending-principles that have become the foundation of the next generation of BTC-backed lenders, the SVB report said.

Landmark transactions, including Ledn’s $188 million asset-backed security, the first bitcoin-collateralized deal to receive an investment-grade rating from a Nationally Recognized Statistical Ratings Organization, underscore growing confidence in BTC-backed credit structures, according to SVB.

While bitcoin-backed loan rates still generally range from 7.5% to 16% annual percentage rate (APR), well above comparable traditional financing, SVB expects increased participation from banks and private credit funds to narrow spreads over time. Early signs are already emerging, including Strike’s recently announced 7.5% rate on term loans larger than $5 million, backed by a $2.1 billion credit facility from Tether.

Pump.fun’s PUMP Buybacks Top $400M as Token Stays Flat

0

The Solana launchpad’s repurchases since July now exceed $400M, yet PUMP trades roughly 83% below its record and is little changed on the day

Pump.fun, the Solana-based memecoin launchpad that has generated more than $1.1 billion in lifetime fees, has repurchased over $400 million of its PUMP token, with the running total crossing that mark in recent days, according to the company’s onchain dashboard.

The tracker showed cumulative buybacks of about $400.9 million as of Monday afternoon, covering roughly 145.5 billion PUMP acquired over 346 days. Pump.fun burns every repurchased token immediately under the policy it adopted in April, so the running buyback total now closely tracks the amount of PUMP permanently removed from circulation.

The milestone tests the central premise of Pump.fun’s tokenomics: that steady, revenue-funded buying and burning will tie PUMP’s value to the platform’s cash flows. So far, the supply cuts have not lifted the price.

PUMP edged up about 1% in the 24 hours through Monday, matching Bitcoin’s gain, according to CoinGecko. The token has fallen about 16% over the past 30 days and trades roughly 83% below its record of about $0.0088, set in September.

Revenue Directed at Repurchases

Pump.fun started buying back PUMP in July 2025 and initially directed all revenue toward repurchases. In late April, the company burned about $370 million of accumulated tokens, roughly 36% of the circulating supply at the time, and switched to a programmatic model.

The platform now routes 50% of net revenue from its bonding curve, PumpSwap and Terminal products into an irreversible smart contract that buys PUMP on the open market and burns it. The Defiant reported the change at the time. The remaining revenue funds operations, hiring and acquisitions.

The platform has produced about $1.13 billion in fees and $1.05 billion in revenue since launching in January 2024, according to DefiLlama. Fee generation has cooled alongside the broader memecoin market, totaling about $23.5 million over the past 30 days.

JPMorgan backs U.S. crypto bill but warns of risks in digital asset framework

0

The blog comes as the Senate races to advance the Digital Asset Market Clarity Act before lawmakers break for their August recess. While the bill cleared the Senate Banking Committee, negotiators are still trying to resolve several contentious issues, including ethics rules for senior government officials with crypto ties, liability protections for decentralized finance developers, stablecoin yield provisions and concerns from Senate Agriculture Committee Democrats.

Industry groups remain optimistic that the legislation can reach the Senate floor in July, but analysts have warned that failing to pass it before the August recess would sharply reduce its chances of becoming law this year.

In JPMorgan’s view, assets that function like securities should continue to follow securities laws regardless of whether they are issued on a blockchain. Likewise, decentralized trading platforms that serve as exchanges or brokers should be held to the same standards for market integrity, disclosure and customer protection.

JPMorgan also devoted considerable attention to stablecoins, an area where many banks see both commercial opportunity and competitive pressure. While stablecoins and tokenized deposits could improve payment efficiency, the executives warned against allowing products that resemble bank deposits to operate outside the capital, liquidity and consumer protection rules that apply to banks. Features such as rewards or cashback for holding balances, they wrote, could lead consumers to assume they have protections that may not exist, increasing the risk of rapid withdrawals during times of market stress.

Can AI drain DeFi? Separating Claude Mythos hype from reality

0

  1. Claude Mythos and DeFi: Real threat or overblown fear?

When Anthropic introduced Claude Mythos-class models as its most advanced AI system for cybersecurity, it drew the usual mix of reactions from crypto communities. The lineup included Claude Fable 5, a Mythos-class model intended for broad use, although access was later suspended after a US government directive.

The concern around decentralized finance (DeFi) was easy to understand. If AI systems can find software flaws faster and with less human input, attackers may also use them to spot weak points in protocols before security teams can fix them. 

Those concerns may seem overstated, but they come from a real shift in technology. AI tools have become better at reviewing code, spotting flaws and supporting security teams. At the same time, DeFi remains a major target for attackers because its code is often public, its protocols hold large amounts of money and many systems are new or not fully battle-tested.

The key question is whether Claude Mythos and similar tools pose a serious threat to DeFi, or whether the industry is overstating what today’s AI can actually do.

The answer sits somewhere between the hype and the alarm.

  1. What is Claude Mythos?

Claude Mythos is Anthropic’s most advanced AI system for cybersecurity. Unlike general-purpose AI assistants that can write code or explain technical concepts, Mythos is designed to handle complex security tasks.

Anthropic initially limited access to the model instead of releasing it widely. According to the company, Mythos showed clear improvements in vulnerability research, exploit analysis and layered cybersecurity reasoning compared with earlier versions.

That capability drew attention quickly because vulnerability detection is valuable in both cybersecurity and crypto.

A security expert might spend weeks reviewing code for small flaws. If AI can shorten that timeline to hours, or even less, it could change the balance in defensive security.

That possibility explains much of the unease in crypto circles.

  1. Why Claude Mythos matters to DeFi

DeFi has lost billions of dollars to hacks, exploits and protocol failures in recent years. The concern is not new.

Flash-loan attacks, cross-chain bridge exploits, governance attacks and smart contract bugs have shown that even audited protocols can still have gaps.

Unlike traditional software systems, DeFi protocols often control large amounts of money through smart contracts. A vulnerability may not just expose information. It could allow attackers to move funds quickly and without permission.

That makes DeFi especially attractive to malicious actors.

The open-source nature of many blockchain projects adds another risk. Their code is available for security teams to review, but it is also available to attackers.

In the past, finding advanced vulnerabilities required deep technical skill. Security researchers needed strong knowledge of coding languages, blockchain architecture, cryptography and attack methods.

AI changes that.

Instead of manually reviewing large codebases, analysts can now use AI assistants to flag suspicious patterns, summarize complex systems and point out possible attack paths.

This is where concerns around Claude Mythos begin.

Did you know? In some controlled security competitions, AI systems have identified software vulnerabilities in minutes that would normally take human researchers several hours, or even days, to find.

  1. Can AI really find vulnerabilities in DeFi protocols?

The short answer is yes. AI systems have already shown that they can find certain types of software vulnerabilities.

Studies from Anthropic and other research groups show that advanced models can review code repositories, test security assumptions and sometimes find issues that human analysts miss.

Smart contracts are well suited to this kind of analysis because they are often public and written in structured languages such as Solidity.

An AI system can quickly review thousands of contracts, spot repeated patterns and look for known types of vulnerabilities.

Areas where AI is likely to provide growing support include:

  • Reviewing audit reports
  • Identifying unsafe coding practices
  • Comparing protocol upgrades
  • Detecting permission errors
  • Modeling possible exploit paths
  • Analyzing interactions between smart contracts

AI is becoming a force multiplier for security researchers. A task that once required a full team of experts could increasingly be handled by a smaller group of security professionals using advanced AI tools.

That is a meaningful change, not just marketing hype.

The table below shows how Claude Mythos compares with other models:

Claude Mythos 5 tops major tests

  1. Why AI threats to DeFi may be exaggerated

Even with these advances, there is a clear difference between finding a vulnerability and stealing funds. Many crypto attacks involve much more than spotting a flaw.

Attackers often need to:

  • Understand complex protocol mechanics
  • Bring in significant capital
  • Coordinate multiple transactions
  • Exploit market conditions
  • Manipulate liquidity
  • Navigate governance systems
  • Avoid detection

Even when a vulnerability exists, turning it into a successful attack often requires detailed planning and careful execution.

The real-world environment is far more complex than isolated coding tests.

Current AI systems also have limits. They can reach wrong conclusions, miss key details or follow weak lines of analysis. Security experts often find that AI tools produce useful insights alongside many false alarms.

An AI tool might flag 10 possible vulnerabilities, but only one may turn out to be valid. That matters because skilled human oversight is still essential.

Claude Mythos could speed up vulnerability detection, but it does not remove the need for experienced security experts.

Did you know? Many DeFi protocols publish their code online. This gives both security teams and AI tools more real-world financial software to review than in traditional banking systems.

  1. The defensive side of AI in DeFi

A major flaw in the claim that AI will weaken DeFi is the idea that only attackers will benefit from these tools. Security teams have access to them too.

Security firms are already adding AI to their review processes. Developers are using AI-assisted code checks more often. Bug hunters can also use AI to spot issues before attackers find them.

Over time, AI may become a normal part of protocol security.

That could mean:

  • Every code update goes through AI-assisted review
  • AI agents continuously monitor deployed contracts
  • Automated systems look for unusual on-chain activity
  • Possible vulnerabilities are flagged before deployment

In that case, AI could strengthen DeFi security instead of weakening it.

The technology is neutral on its own. Its impact depends on how well attackers and defenders use it.

  1. When AI attacks meet AI defenses

A more realistic outlook points to a future where AI systems challenge each other directly. This would make security faster on both sides.

Attackers will use more advanced models to find vulnerabilities and plan attacks. Security teams will use similar tools to monitor threats, improve code quality and respond faster.

This already happens in traditional cybersecurity, where offensive and defensive tools improve side by side.

DeFi could become the next major battleground for this contest. The likely result is not a sudden collapse of the sector. Instead, DeFi may enter a period of faster security upgrades and adaptation.

Projects that are slow to find vulnerabilities and update their code could face greater risk. Those that adopt AI-supported safeguards may become stronger than before.

Did you know? Several major crypto losses have come from compromised private keys, social engineering attacks or governance manipulation rather than flaws in smart contract code itself.

  1. Assessing protocol vulnerabilities

Risk is not spread evenly across DeFi. Smaller projects with limited security resources often face the highest exposure.

Several categories are especially vulnerable:

  • Fast deployment schedules: Projects that prioritize quick launches over careful testing may leave structural flaws in place.
  • Copied codebases: Many protocols reuse or slightly modify existing code. Advanced AI tools can compare these systems quickly and expose inherited flaws.
  • Weak audit coverage: Projects with little or no third-party review are less prepared for advanced attacks.
  • Legacy smart contracts: Older contract designs may rely on assumptions that no longer hold up against modern exploit methods.

Automated analysis tools could sharply reduce the time needed to find these weaknesses.

  1. What DeFi builders should do now

Claude Mythos offers an important lesson for the industry. DeFi builders should assume that attackers may already be using automated research tools. Security strategies need to improve accordingly.

Core priorities should include:

  • Expanding automated security testing
  • Running continuous, real-time audits
  • Adding AI-assisted code analysis to development pipelines
  • Increasing bug bounty rewards
  • Using formal verification for critical code
  • Improving threat monitoring and real-time incident response

Engineering teams must reduce the time between finding a vulnerability and deploying a fix. In an AI-accelerated environment, response time becomes just as important as prevention.

  1. A major shift, not DeFi’s breaking point

Claude Mythos has shown that automated systems can handle complex security tasks that once required specialized experts. That marks a major shift for DeFi, where a code flaw can lead to the immediate loss of user funds.

Still, predictions of total systemic failure ignore several practical realities. Finding a vulnerability does not guarantee a successful exploit. Current AI tools still produce uneven results, human oversight remains essential and defensive teams have access to the same technology.

The more likely outcome is a change in security standards, not a collapse of DeFi. Automated tools could reduce the time and cost needed to find vulnerabilities. That will put more pressure on development teams to improve code quality, respond faster and build stronger security systems.

Ultimately, these developments are a warning, not a guaranteed outcome. The future of decentralized infrastructure will not be decided only by what AI can find. It will also depend on whether attackers or defenders use the technology more effectively.

Private keys, not smart contracts, caused 40% of crypto’s $16 billion hack losses. Here’s whats being done.

0

“Most blockchain infrastructure was originally built for a single-user, single-key model, one private key controls everything, and if that key is lost or stolen, all the assets are gone instantly. This goes against the basic security principles that traditional finance has relied on for decades: more than one person approving, separation of duties, and several layers of defense,” Wu told CoinDesk.

In a way, the system built to revolutionize global finance has weaker security than a typical email account.

Wu added that the number of routes through which an attack can be launched has increased significantly. “Cloud systems, third-party tools, social media accounts, and the people operating them, all of these can become a way in.”

Both Wu and Fan pointed to the Bybit hack of February 2025 as an example of a widening attack surface. Attackers compromised the software supply chain of a third-party developer tool, allowing them to inject malicious code into the wallet’s web interface and trick executives into unknowingly signing away $1.5 billion in Ethereum.

The fix

The industry is now moving to address the private key vulnerability issue, though not evenly, according to Wu.

“There’s progress on many fronts: MPC [multi-party computation] wallets, account abstraction with social recovery, passkey-based login, hardware wallet enforcement, and proper key management SOPs,” he said. “The problem is that these are often added as optional extras, instead of being built in from the start at the protocol level. Most chains still treat security as a feature to bolt on, not as a core design principle.”