Fake reviews are 👎. So I built the opposite. AudienceScore: an open protocol where every review is proven by a cryptographic receipt, and every score is recomputable by anyone. Scores no one can buy. Open source, built for the AI era. https://t.co/vtrLnObyP7
Three operating-surface changes in the last 48 hours: a payment infrastructure compromise that exposed the key management risk beneath multichain custody, a new EU enforcement authority that can now ban crypto services at the country level, and a protocol change that ties on-chain execution capacity directly to stake size.
Triple-A: On July 24-25, on-chain analyst Specter detected outflows from hot wallets controlled by Triple-A, a Singapore-based stablecoin payment gateway used by businesses to send and receive cross-border crypto payments. Funds were removed from wallets on TRON, Ethereum, Polygon, Arbitrum, TON, and Solana simultaneously. PeckShield confirmed the estimated loss above $9.7 million, with the attacker swapping assets and consolidating approximately 5,227 ETH into a single address at 0x01F83B5d4fb30E8AA3daC1681B4048D9135253b1. The multichain spread indicates the attacker gained access to wallet infrastructure controlling keys on multiple networks at once rather than exploiting any single smart contract. Triple-A had published no official statement or confirmed root cause as of July 25. Deposits reportedly remained active and continued receiving new customer funds during the incident window.
EU 21st Russia Sanctions Package: The Council of the EU adopted the package on July 23, 2026, naming 218 entities and individuals, the largest batch in four years. For crypto operators, the material change is structural: the package introduces a country-level ban authority for the first time, giving Brussels the power to cut off all crypto-asset service providers in an entire third-country jurisdiction if that jurisdiction hosts platforms facilitating Russian sanctions evasion. The immediate application places transaction bans on 14 crypto-related service platforms across six jurisdictions: Georgia, Panama, the UAE, the Marshall Islands, Kyrgyzstan, and Belarus. Named platforms include HTX. Transaction bans on HTX, EXMO, and nine other listed entities take effect August 23, 2026; bans on A7 Nigeria, A7 Africa, and PilotFinance take effect August 13. The A7 cross-border payment network, which issued the A7A5 stablecoin used to route funds around earlier restrictions, is a central target; one report placed A7 volume at approximately $120 billion. EU persons and entities are prohibited from transacting with any listed platform after their respective effective dates. The new country-level tool shifts compliance pressure from individual platform designation toward host jurisdictions, changing the calculus for exchanges and custodians operating in those six countries or routing through counterparties there.
Aptos AIP-146: Aptos Labs confirmed AIP-146 enabled on mainnet on July 24. The proposal, authored by George Mitenkov of Aptos Labs, introduces staking-based transaction limits: transactions can request execution capacity above the network's standard ceiling, scaled in tiers up to a hard cap of 100 times the normal limit. Access is gated by committed stake. A 2x multiplier requires roughly 1 million APT in committed stake; 4x requires approximately 5 million APT; 8x requires approximately 10 million APT. The feature targets workloads that exceed standard per-transaction limits, including on-chain liquidations, large-scale data migrations, and multi-step risk management operations. Before AIP-146, every transaction on Aptos ran under the same processing ceiling regardless of complexity or the operator's stake position. The change creates a two-tier execution environment where stake size determines access to heavy compute, with practical implications for any application building fully on-chain financial infrastructure on Aptos.
Four changes to crypto's operating surface in the last 48 hours: two bridge exploits, a new institutional funding structure for Bitcoin security, and an SEC commissioner statement that directly names on-chain vault and lending operators.
Verus-Ethereum Bridge: On July 23, the Verus-Ethereum bridge was drained for the second time in roughly two months, losing approximately $7.54 million in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD. Blockaid confirmed the July attack used the same bridge contract, same entry path, and same bug class as the May breach that cost $11.58 million. The root cause, documented by multiple security researchers, is missing Solidity validation: the Ethereum-side contract accepted valid signatures and Merkle proofs but did not confirm that the amount released matched value committed on the Verus source chain. The May incident closed with a bounty arrangement returning roughly 75% of stolen funds. The bridge apparently re-opened with the underlying flaw intact. A different attacker used a new wallet to execute the same technique, spending 0.01 VRSC to trigger payouts of approximately 1,137 ETH and 71.5 tBTC in a single transaction at 03:45 UTC. The attacker converted most stolen assets into approximately 3,916 ETH and began routing funds through Tornado Cash. Verus had issued no public response or confirmed repair timeline at time of reporting.
AFX Trade: Blockaid flagged an exploit targeting AFX Trade, a decentralized perpetual exchange on Arbitrum, at 21:30 UTC on July 22. The attacker drained approximately $24.15 million USDC from a third-party bridge AFX operates and converted the funds to 12,467.5 ETH before moving them from Arbitrum to Ethereum. The Arbitrum native bridge was not involved. Arbitrum contributor Steven Goldfeder confirmed the compromised bridge was independently operated by AFX. The investigation remains open with no confirmed root cause published. AFX subsequently extended a white-hat settlement offering the attacker a 30% keep on approximately $24 million in exchange for returning the remainder.
Bitcoin Security Consortium: On July 23, nine firms announced the Bitcoin Security Consortium: Anchorage Digital, ARK Invest, BlackRock, Block, Blockstream, Coinbase, Fidelity Digital Assets, Galaxy, and Strategy. The group pledged an aggregate $15 million over three years to fund open-source Bitcoin security research and development, with initial focus on post-quantum cryptography including work related to BIP-360. The $15 million is not held in a pooled fund. Each member directs its own capital independently to developers, researchers, or organizations of its choosing. Day-to-day coordination goes to Mike Schmidt, executive director of developer nonprofit Brink, in a volunteer capacity. The consortium stated it will not direct Bitcoin protocol changes or take positions on specific proposals. Separately, Galaxy had announced a $5 million developer grant program for quantum-resistant Bitcoin solutions two days earlier. BlackRock simultaneously published a report characterizing the quantum threat as technically manageable and noting that upgrading Bitcoin's cryptography is less burdensome than building a quantum computer capable of attacking it.
SEC Commissioner Peirce: On July 22, Commissioner Hester Peirce published a formal statement on the SEC website titled "Headstands and Summervaults" warning that on-chain vaults and lending strategies may fall under federal securities laws depending on their structure. The statement names specific operating categories: vaults where managers or curators select yield strategies, rebalance assets, or appoint others to make those decisions could qualify as investment companies under existing law. On-chain lending arrangements where operators set interest rates, define collateral requirements, or manage liquidation thresholds may also trigger securities classification. Peirce stated the assessment will be fact-specific for each product. She is not issuing a rule and this is a personal statement, not a Commission position. The practical effect is a direct compliance signal to vault operators, curators, and on-chain lending protocol teams, particularly those with active management layers above smart contracts. As of July 2026, approximately $8.6 billion sat across 788 curated vaults serving roughly 1.4 million users. Protocols including Morpho operate the vault infrastructure integrated by Coinbase and Robinhood for stablecoin yield products. Peirce invited vault and lending operators to engage with the SEC rather than assume blockchain deployment places their products outside federal jurisdiction.
Three items in the last 48 hours: a cross-chain bridge exploited through message-encoding reuse, a DeFi front-end announcing permanent shutdown after a vault exploit forced it out of operation, and two Uniswap governance votes live now that would extend the protocol's fee-burn mechanism to new chains and versions.
Wanchain / Midnight: On July 20-21, 2026, BlockSec's Phalcon monitor identified an exploit against Wanchain's Cardano-to-BNB Chain bridge, draining approximately 515.2 million NIGHT tokens from the bridge treasury, worth roughly $10 million at prevailing prices. The attack completed in four transactions over an eight-minute window. BlockSec identified the root cause as a non-injective signed-message encoding flaw in the bridge's TreasuryCheck validator: the Plutus V2 contract hashes 14 variable-length redemption fields through raw concatenation without delimiters, which allows different field combinations to produce the same byte string and reuse the same signature. The attacker replayed a legitimate BSC transaction authorizing roughly 3,110 NIGHT to extract approximately 203 million NIGHT in a single redemption on the Cardano side, a roughly 65,000x inflation via field-boundary ambiguity. The stolen tokens were funneled into Cardano wallets before roughly 90% was liquidated through Cardano DEX swaps. Wanchain took the bridge offline. The Midnight Foundation confirmed the Midnight blockchain and its core protocol were not compromised. NIGHT is Midnight's governance token and the source of DUST, the network resource for transactions and smart contract execution. Midnight launched its mainnet in March 2026, and NIGHT remains publicly transferable, making the token held in bridge custody a live attack surface independent of Midnight's own security posture.
SummerFi: On July 20, 2026, https://t.co/SVnV4cvqcc and its development company https://t.co/SVnV4cvqcc Labs formally announced wind-down of the platform after seven years, citing a July 6 exploit on the Lazy Summer Protocol as the direct cause. The exploit manipulated two USDC vaults on Ethereum mainnet in a single atomic transaction, extracting roughly $6.04 million by inflating reported assets and initiating an oversized withdrawal against a $65.4 million flash loan. The attack hit user deposits, protocol-owned capital, and the team's own reserves simultaneously, eliminating the operational runway needed to rebuild. The https://t.co/SVnV4cvqcc interface and customer support channels remain live until August 31, 2026. After that date, responsibility for withdrawals, remediation, and continued protocol operation transfers entirely to the Lazy Summer DAO. No shutdown date for the underlying protocol has been set because it operates under separate decentralized governance. The Lazy Summer vaults route deposits across lending strategies including Aave and Morpho; the specific attack vector was a valuation flaw in one of those strategy adapters that held outdated NAV figures. CertiK attributed the exploit to a flash loan attack, while SummerFi characterized it as NAV manipulation, and no independent reconciliation of the two accounts has been published. The pre-exploit TVL was between $22 million and $25 million.
Uniswap: Two on-chain governance proposals opened July 19, 2026, with voting open through July 26. Proposal 100 would activate protocol fees on select Uniswap v4 pools across seven chains: Ethereum, Arbitrum, Base, BNB Chain, Polygon, Optimism, and Robinhood Chain. The targeted pool categories are static-fee pools without hooks, continuous clearing auction pools, and aggregator hook pools. Proposal 99 would extend v2 and v3 protocol fees to Robinhood Chain, where all three Uniswap versions deployed on July 1, 2026. Both proposals route collected fees into the TokenJar and Firepit burn system established under December 2025's UNIfication vote, where fees accumulate and can only be withdrawn when equivalent UNI is burned. That link between fee flow and supply reduction is immutable once deployed and cannot be altered by subsequent governance. As of July 19, each proposal held roughly 2.94 million UNI in favor against a 40 million UNI quorum threshold, approximately 7.4% of the requirement. A temperature check run July 7-12 drew 93% support with 13.9 million UNI voting in favor. The quorum gap means turnout, not sentiment, is the open variable through July 26. Robinhood Chain is an Arbitrum Orbit chain, so governance execution on that chain runs through retryable tickets via its Inbox and the L2 alias of the Uniswap Timelock, a routing dependency that must succeed for the fee switch to land on-chain for that deployment.
Two infrastructure updates in the last 48 hours: a cross-chain bridge halted under a flash loan attack, and a privacy network eight days from a hard fork that will determine whether its shielded supply is clean.
Allbridge Core: On July 19, the Allbridge Core cross-chain stablecoin bridge was exploited for approximately $1.65 million from its Solana liquidity pools. The attacker borrowed $1.12 million USDC in a flash loan from Kamino, executed rapid USDC/USDT swaps to distort the pool's exchange ratio, withdrew liquidity at the manipulated rate within the same transaction, and bridged the proceeds from Solana to Ethereum before routing funds into privacy pools. The exploit did not require a leaked key or a direct contract flaw in Allbridge's bridge logic. The attack surface was the pricing mechanism that determines the withdrawal rate from Allbridge Core's native stablecoin pools. Allbridge paused the protocol, advised all liquidity providers to withdraw from affected pools immediately, and asked traders who profited from the resulting arbitrage window to return funds to a published recovery address. No post-mortem or reopening date has been published. Allbridge Core prices liquidity withdrawals off real-time pool ratios rather than external oracles, which is the design property that made the manipulation effective. The protocol was hit by a structurally similar flash loan price manipulation on BNB Chain in April 2023, recovered most of those funds through a white-hat arrangement, and relaunched with modified withdrawal logic. The same class of attack succeeded again three years later on a different chain. Allbridge had roughly $21.6 million in pool liquidity before the incident.
Zcash: On July 19, co-founder Zooko Wilcox published the operational details of the Ironwood hard fork response to the Orchard circuit vulnerability disclosed in late May. Ironwood, formally NU6.3, activates at block 3,428,143 around 8 a.m. EST on July 28, 2026. The fork seals the legacy Orchard shielded pool and opens a new pool built on a corrected circuit with formal verification underway by Project Tachyon. Funds leaving the old pool must pass through a turnstile mechanism that enforces a strict accounting rule: outflows cannot exceed the total amount ever legitimately deposited. If counterfeit ZEC was created through the earlier soundness flaw, the surplus coins will remain frozen inside the old pool rather than entering circulation. No evidence of exploitation has been found, but the privacy properties of the Orchard pool mean undetected issuance cannot be ruled out until the turnstile closes. Node operators must upgrade software before block 3,428,143. Exchanges, wallets, and swap services that have not completed testing are expected to temporarily suspend ZEC deposits and withdrawals around the activation date. Separately, Zakura 1.0.0, a new Zcash node client forked from the Zcash Foundation's Zebra codebase, launched on July 15 and synced mainnet in approximately four hours and twenty minutes, adding a second production-ready implementation alongside Zebra ahead of the upgrade deadline.
Three updates from the last 48 hours across bridge security and protocol engineering custody.
Across Protocol: At approximately 05:30 UTC on July 17, Across Protocol's Solana deployment was attacked, marking the first disclosed security incident in the protocol's history across more than $34 billion in lifetime bridged volume. The loss landed on Risk Labs, the protocol's own relayer operator, not on depositors. All in-flight bridge transactions settled normally, and Across re-enabled Solana deposits by July 18 after a containment period. The root cause has not been publicly confirmed. Across is coordinating the trace with SEAL 911 and published three attacker addresses, one on Solana and two on EVM chains, consistent with cross-chain fund movement. A full post-mortem is pending. The Solana leg of Across went live in July 2025 through the V4 upgrade, and in April 2026 Asymmetric Research had disclosed a prior event-spoofing vulnerability in the same SVM spoke pool, which was patched without loss at the time. Whether July 17's attack exploited a related class of issue in Solana's off-chain event handling or a separate relayer infrastructure flaw will only be confirmed by the post-mortem.
Cardano: On July 17, Input Output announced the formal transfer of Cardano's core engineering infrastructure to independent specialist teams, beginning in August 2026 and continuing through 2027. The components being handed over are the Haskell node, the Plutus smart contract platform, the Daedalus wallet, Hydra scaling technology, and developer relations. Se7en Labs and Teragone are the named recipients. Intersect and Pragma will provide oversight. The target is at least three parallel node implementations in Haskell, Rust, and Go. Input Output will pivot to research and venture creation through IO Labs and IO Ventures from January 2027. This is a structural change to who controls Cardano's reference software and delivery cadence. IO has been the sole engineering authority since the network's inception. The handover runs concurrent with the July 18 Protocol Version 11 enactment, which is the first hard fork Cardano has executed entirely through on-chain Voltaire governance. IO halved its 2026 treasury request to roughly $46.8 million as part of the same transition.
Three changes from the last 48 hours across oracle security, DeFi lending infrastructure, and institutional stablecoin rails.
Ostium: On July 15, an attacker compromised a private key belonging to one of Ostium's oracle signers on Arbitrum and used that access to submit fraudulent future-dated price reports through the protocol's registered PriceUpKeep forwarder. The attacker executed approximately 20 looped delegated trades, opening positions at market prices and closing them against manipulated oracle prices in a single atomic batch, extracting between $11.86 million and $18 million in USDC from Ostium's main liquidity vault. Ostium paused all trading immediately. The root cause is a private key compromise, not a flaw in audited contract logic. The exploit hit the oracle signer layer sitting outside the audited smart contracts and did not require any on-chain governance or direct contract interaction to execute. Ostium had raised $27.8 million and processed over $50 billion in cumulative trading volume before the incident.
Cascade: On July 16, PeckShield reported that the Cascade Liquidity Strategy vault, operated by Polychain and Variant-backed perpetuals platform Cascade, was exploited for 1.34 million USDC. The attacker bridged the stolen funds from Arbitrum to Solana and then to Ethereum via Relay Protocol in DAI. User deposits in the CLS vault were locked pending trading launch, meaning affected depositors had no ability to withdraw before the exploit. A second Solana lending protocol, DeFiTuna, disclosed on July 16 that an attacker exploited its lending pools roughly seven hours earlier, extracting $580,000 and leaving the USDC lending pool at a matching deficit. DeFiTuna identified and patched the attack vector and said it is investigating and attempting fund recovery. In both cases the confirmed loss came out of user-supplied pool liquidity rather than protocol treasuries.
Aave V4 / Avalanche: On July 15, Aave Labs deployed Aave V4 on Avalanche, the first V4 deployment outside Ethereum mainnet. The deployment introduces the Hub and Spoke architecture, replacing the monolithic pool model with a single Liquidity Hub that distributes credit to modular Spokes operating under separate risk parameters. Initial assets at launch include wAVAX, sAVAX, BTC.b, USDC, USDT, WETH.e, and EURC across three Spokes: a Main market, an AVAX Correlated market, and a Forex market. A dedicated RWA hub supporting borrowing against tokenized US Treasuries, money market funds, private credit, and corporate bonds is planned as a subsequent Spoke. Chainlink provides oracle infrastructure. The Avalanche Foundation committed up to $15 million in milestone-based incentives tied to hub launches and market growth. Future V4 deployments on Arbitrum, Optimism, and Base are contingent on stability metrics from this Avalanche deployment.
Visa Stablecoin Platform: On July 16, Visa launched the Visa Stablecoin Platform in beta with select institutional clients. VSP packages stablecoin minting, redemption, wallet custody, and treasury settlement into a single Visa-managed environment for financial institutions, fintechs, and crypto-native firms. The platform launches with Open USD, the consortium-backed stablecoin introduced by Open Standard, a group that includes Visa, Mastercard, Coinbase, and Stripe. Clients can use Visa's new Wallet-as-a-Service stack or connect existing wallets, then configure dual-control approval workflows, audit logs, passkeys, and transfer allow lists for treasury and settlement operations. The platform integrates stablecoin flows into Visa's existing network, risk, and fraud systems rather than requiring institutions to build separate blockchain infrastructure. Visa's parallel stablecoin settlement pilot was running at a $7 billion annualized rate as of April 2026 across nine blockchains. VSP extends that from settlement-only into full-stack issuance and custody operations.
Two DeFi operating surfaces failed in the last 48 hours: an oracle signer compromise on a real-world asset perpetuals exchange, and a vault accounting exploit that forced a seven-year-old yield protocol to wind down entirely.
Ostium / Arbitrum: On July 15, 2026, an attacker holding a compromised oracle signer private key used Ostium's registered PriceUpKeep forwarder to submit future-dated authorized oracle reports against the protocol's RWA perpetuals vault. The forwarder, a legitimate automation component, accepted the reports as valid because the signer key had not been revoked. The attacker opened and closed approximately 20 looped trades in a single executeBatch call, each round compounding the margin from roughly $1,000 to an eventual position that triggered an approximately $18 million USDC payout from the OLP liquidity vault. Blockaid and CertiK flagged the drain with loss estimates ranging from $18 million to $22 million, representing approximately 28% of the vault's pre-exploit TVL. Ostium halted all trading immediately and has recommended users revoke approvals for all protocol contracts pending investigation. No post-mortem has been published and no timeline for resuming trading has been given. The attack vector was not smart contract code. It was the external signing key that authorized price data delivery, the same infrastructure class that failed at Bonzo Lend on Hedera and at https://t.co/SVnV4cvqcc's Lazy Summer Protocol earlier this month.
https://t.co/SVnV4cvqcc Labs: On July 16, https://t.co/SVnV4cvqcc Labs published a shutdown announcement confirming the company has no viable path forward following the July 6 flash-loan exploit of the Lazy Summer Protocol. The attacker manipulated the net asset value of two Ethereum USDC vaults in a single atomic transaction by donating overvalued Silo Varlamore vault tokens into strategy adapters that had been capped for offboarding but remained inside active share-price calculations. A deposit at the genuine price and a redemption against liquid assets at the inflated price extracted approximately $6.04 million: $5.64 million from the lower-risk USDC vault and roughly $400,000 from the higher-risk vault. The team stated that a meaningful portion of its own capital was held in the affected vaults, removing the runway needed to fund recovery work and continued operations. The https://t.co/SVnV4cvqcc interface and support channels will remain live until August 31, 2026. The Lazy Summer DAO, a separate governance body, retains control over the underlying protocol and is working to restore vault withdrawals and redemptions independently of the Labs company closure. https://t.co/SVnV4cvqcc operated for approximately seven years, spinning out from the Maker Foundation in June 2021, and the Lazy Summer Protocol had accumulated nearly $200 million in TVL during its first nine months before the exploit ended its commercial operation.
Taken together, both failures trace to the same operating-layer gap: privileged off-chain infrastructure, an oracle signer key and a vault valuation calculation, that sat outside the audited smart contract code but sat directly in the path of user funds. Neither protocol was breached through its own contract logic. Both ended with full trading or operational shutdowns.
Three protocol-layer changes from the last 48 hours: a cross-chain executor compromise active today, a Cardano hard fork entering final countdown, and Aave V3 going live on a ZK rollup with restricted initial caps.
LayerZero: On July 15, PeckShield reported that LayerZero Executor wallets were compromised across eight networks including Ethereum, BNB Chain, Base, Arbitrum, Avalanche, Optimism, Mantle, and Plasma, with approximately $2.4 million drained. The attacker bridged the proceeds to Ethereum and converted most of the assets into 956 ETH and roughly $322,000 in USDC. The executor role in LayerZero handles gas abstraction and on-chain message delivery; a compromise at this layer affects message execution across every chain where the executor was active. LayerZero has not yet published a formal incident report, and the root cause of the wallet access has not been confirmed. Protocols using the LayerZero Labs executor as their default should treat execution delivery on affected chains as an open risk variable until the post-mortem is published.
Cardano: The Van Rossem hard fork initiation was ratified at the epoch 642 boundary on July 13 at 21:45 UTC, completing the DRep, stake pool operator, and Constitutional Committee voting thresholds required under Cardano's Voltaire governance framework. Hard fork enactment is set for July 18 at 21:45 UTC. The upgrade activates Protocol Version 11, an intra-era hard fork that updates the Plutus cost model to reduce smart contract execution fees, introduces new cryptographic primitives, enforces VRF key uniqueness, and revises reference input rules. As of ratification, 93% of current block production was already running node version 11 and exchange readiness by tracked liquidity had cleared 84%. Any stake pool operator, exchange, or infrastructure service still running a legacy node will fall out of sync at the July 18 enactment block. This is the first Cardano hard fork executed entirely through on-chain Voltaire governance without unilateral IOG control.
Aave / zkSync Era: On or around July 10, the Aave DAO executed the activation proposal for Aave V3 on zkSync Era, listing five initial assets: USDC, USDT, WETH, wstETH, and ZK. The pool launched with deliberately low supply and borrow caps, roughly $10,000 per asset, to allow internal testing before the Aave Guardian raises them to governance-approved levels. The deployment uses Aave v3.1 and was re-deployed with zksolc compiler version 1.5.3 after a prior compiler dependency issue was identified and fixed. Pool admin authority sits with the Aave Guardian during the bootstrap period. The activation follows BGD Labs completing a full technical evaluation of the zkSync network infrastructure and risk providers approving asset parameters. Builders and protocols on zkSync Era now have access to Aave's borrowing and collateral infrastructure, with caps expected to scale once the guardian confirms stable operation.
Four protocol-level changes from the last 48 hours: two mainnet upgrades shipped, one Bitcoin governance test approaching a hard deadline, and one oracle security failure on an L1.
NEAR Protocol: On July 10, the NEAR mainnet activated v2.13.0, shipping three distinct infrastructure changes simultaneously. The upgrade added post-quantum signature support using the NIST-finalized ML-DSA-65 algorithm at the validator layer. It also enabled automatic shard splitting, letting the network dynamically redistribute load across shards as congestion builds rather than requiring manual parameter changes through governance. The third change deploys NEP-611, a new gas key system that lets applications sponsor user transaction fees, which removes the requirement for end users to hold NEAR to transact.
Stellar: On July 10, Stellar mainnet shipped Protocol 27, named Zipper. The upgrade introduces smart contract credentials and developer identity verification delegation. Credentials allow smart contracts to hold and verify attestations about accounts or addresses directly onchain, making Stellar's contract layer usable for compliance-sensitive workflows without relying on off-chain identity infrastructure. The timing is notable: DTCC selected Stellar as the public-chain layer for its tokenized securities pilot, which is scheduled to begin limited production trades this month.
Bitcoin BIP-110: As of July 12, miner signaling for BIP-110 remains below 1% with an early August deadline approaching. BIP-110 would impose a one-year restriction on OP_RETURN outputs and other non-financial data-carrying transaction methods. The proposal uses a user-activated soft fork mechanism requiring 55% miner signaling, significantly below the traditional 95% threshold. Michael Saylor and Adam Back have both publicly opposed the measure. With sub-1% support across the mining pool at the deadline horizon, BIP-110 is tracking toward a small minority fork rather than a network-wide rule change, but the UASF path keeps the outcome formally open until the block-height trigger.
Bonzo Lend / Hedera: On or around July 12, Bonzo Lend lost approximately $9.05 million after an attacker exploited a verification flaw in a third-party Supra oracle contract deployed on the Hedera network. The protocol lost 77% of its total value locked. The attack vector was the oracle contract itself, not the lending protocol logic, placing the failure at the price-feed and verification layer rather than in Bonzo's core contract. Hedera is an account-model DLT used primarily for enterprise settlement use cases, and Supra is a third-party oracle provider. The failure adds another data point to the pattern SlowMist identified in its H1 2026 mid-year report: infrastructure and cross-chain systems are absorbing a disproportionate share of losses relative to smart contract code vulnerabilities.
Three changes in the last 48 hours reshaped operating conditions across custody, settlement rails, and developer tooling security.
Circle / OCC: On July 10, the U.S. Office of the Comptroller of the Currency granted Circle Internet Group final approval to establish First National Digital Currency Bank, N.A., which will operate under the name Circle National Trust. The bank opens by providing fiduciary digital asset custody for Circle and its affiliates, with a path under the approved business plan to extend custody services to a limited number of institutional clients, specifically banks and regulated derivatives organizations. The charter also creates a framework for moving USDC reserve management under direct OCC supervision as a future capability, replacing the current reliance on third-party banks and custodians to hold the cash and Treasury assets backing USDC. Circle had received conditional OCC approval in December 2025 after submitting its application in June 2025.
Swift / tokenized deposits: On July 9, Swift declared its blockchain-based ledger ready for initial use, with 17 banks across six continents preparing to run live transactions. The full roster includes ANZ, BNP Paribas, BNY, Citi, DBS, First Abu Dhabi Bank, FirstRand, HSBC, Itaú Unibanco, Lloyds, Mashreq, MUFG, OCBC, Standard Chartered, UBS, UOB, and Wells Fargo. The ledger functions as an orchestration layer for bank-issued tokenized deposits on each institution's own ledger, letting banks move customer funds overnight and on weekends before final settlement completes through existing correspondent rails. Swift built the system in approximately nine months. The architecture runs on Hyperledger Besu with Chainlink CCIP providing cross-chain connectivity on a permissioned network. Tokenized deposit payments is the first use case; Swift has cited programmable money and AI-agent-initiated commerce as planned subsequent applications.
Injective Labs / npm supply chain: On July 8, attackers used access to a trusted maintainer's GitHub account to push a backdoor into @injectivelabs/sdk-ts, the official TypeScript SDK for building on the Injective blockchain, which carries approximately 50,000 weekly downloads. The malicious version, 1.20.21, was published through the repository's own OIDC trusted-publishing pipeline via GitHub Actions, so no stolen npm credentials were required. The payload hooked the two primary key-derivation entry points, PrivateKey.fromMnemonic() and PrivateKey.fromHex(), capturing raw BIP-39 mnemonic seed phrases and private keys at the moment a wallet was loaded or created, then exfiltrated the data via an HTTPS POST request to an endpoint designed to mimic legitimate Injective infrastructure. The compromise spread transitively to 17 additional @injectivelabs scoped packages that pinned the malicious SDK version. The malicious code was live for approximately 49 minutes before a revert commit removed the payload. Clean version 1.20.23 was published across all 18 affected packages and 1.20.21 was deprecated on npm. Developers who installed any affected package during the exposure window should treat all wallet credentials in that environment as compromised and migrate funds to new wallets with freshly generated keys.
Two security disclosures this week expose different layers of blockchain infrastructure: a VM-level execution flaw in a Move-based L1 and a governance-layer treasury drain on Solana.
Aptos / Hexens: Security firm Hexens publicly disclosed on July 4-5 a critical stale-cache bug in the Aptos Move virtual machine, reported privately through SEAL911 channels on February 25 and patched by Aptos Labs within hours, with a public pull request on February 27. The flaw was a type-confusion vulnerability in the Move VM execution environment, the layer that processes every smart contract on the network, where stale cached data could cause the runtime to misclassify on-chain resource types. Hexens simulated the attack on a cluster approximating one-third of the validator set using a server setup costing roughly $3,000, achieving a near-90% success rate with no insider access or special permissions required. Hexens estimated first-order systemic exposure at $70 billion, accounting for stablecoins, cross-chain messaging systems including LayerZero and Wormhole, USDC's CCTP, and DeFi protocols connected to Aptos. Aptos Labs disputed the practical exploitability under real mainnet conditions. Polygon CTO Mudit Gupta independently reviewed the proof-of-concept and validated it ran as claimed. No user funds were lost; the fix was applied at the network level before any confirmed exploitation. The disclosure is now public, meaning protocols that depend on Aptos for settlement or bridge connectivity should treat it as a prompt to audit their dependencies against the patched runtime.
BonkDAO / Solana Realms: On July 6, an attacker drained approximately $20 million in BONK tokens from the BonkDAO treasury using the protocol's own token-weighted governance system on Solana's Realms platform. The sequence began June 30 with the submission of proposal BIP-76, which embedded a treasury transfer instruction inside governance language. Over July 4 and 5, a separate wallet spent roughly $4.4 million buying BONK on Bybit and Binance, acquiring just over 1% of supply, the exact quorum threshold. The proposal passed with 99.9% yes votes, only seven addresses voted in total, and roughly $20 million in BONK moved automatically to attacker-controlled wallets. No smart contract was exploited; the voting system executed as designed. BonkDAO had no execution-time timelock, no multisig override, and no emergency pause mechanism on the treasury. The attacker identified the exchange wallets used to accumulate voting power, and BonkDAO is coordinating with the Solana Foundation, law enforcement, and centralized exchanges including Upbit and Kraken, both of which paused BONK deposits and withdrawals. Recovery is uncertain given the transactions ran through the DAO's own legitimate machinery.
AI just made fact-memory free and infinite.
So the penalty for forgetting details dropped to zero. The premium on what you DO retain - structure, judgment, the right question -went way up.
If you remember how problems get solved but not who wrote the book: you’re built for this era.
I recently heard the CEOs of DeepMind and Anthropic discussing this thought experiment: Imagine a new country appearing overnight with a population of 10 million people, all smarter than Albert Einstein. What would happen?
In another podcast, Microsoft’s CEO described a future where a company might have 2 million or even 20 million AI agents.
What many people don’t realize is that an “AI agent” is really just a coordinated series of steps. For example, managing household trash could involve:
1. One agent tracking the garbage can’s location at all times.
2. Another monitoring the city of Cary’s website for schedule changes.
3. A third setting alerts if anything updates.
4. A fourth sending a reminder text to a human or robot on trash day.
These can be stacked endlessly into complex systems. When people say “AI,” they often mean this full harness—the agents, sub-agents, and rules that tie them together.
Once we have truly capable agents, they will design and optimize these systems themselves: creating the plans, fallback procedures, and actions (using local/personal LLMs or SLMs). The next phase—recursive self-improvement—is already close. After that, progress becomes unstoppable and life gets very strange.
Two regulated-access boundaries moved this week: the EU's MiCA hard cutoff went live and the US legislative path for codifying a Fed digital dollar ban is stalled one signature away.
Binance: On June 26, Binance notified users in France, Italy, Poland, and Spain to begin withdrawing funds, confirming it will not have a MiCA Crypto-Asset Service Provider license in place by the July 1 deadline. The exchange withdrew its application filed with Greece's Hellenic Capital Market Commission on June 24 after months of review and no formal decision. It is now pursuing authorization through France, but has no timeline for approval. Without a license from at least one EU member state, Binance cannot legally serve clients across all 27 member states from July 1. Kraken, Coinbase, OKX, and https://t.co/DrgrTytAIl hold valid MiCA licenses and gain direct structural advantage as Binance winds down unlicensed EU activity. Of roughly 3,000 crypto firms operating in the EU, approximately 210 hold full CASP authorization as of the deadline.
US CBDC ban: Congress passed the 21st Century ROAD to Housing Act in a 85-5 Senate vote on June 22 and a 358-32 House vote shortly after. The bill contains a provision in Title XI, Section 1101 prohibiting the Federal Reserve from issuing a retail central bank digital currency or any substantially similar digital asset through December 31, 2030. Private dollar-denominated stablecoins that are open, permissionless, and private are explicitly carved out from the prohibition. Trump cancelled the June 24 signing ceremony and conditioned his signature on passage of the SAVE America Act, a voter-ID bill the Senate rejected 48-50 on June 4. The bill sits on the president's desk unsigned. Under the Constitution's 10-day presentment window, it can become law without a signature if Trump does not act. The delay also compresses the Senate calendar for the Digital Asset Market Clarity Act, which analysts say must clear the Senate floor before the August recess to have realistic 2026 passage odds.
Two stablecoin infrastructure changes landed on June 25 and 26: a new protocol-native token standard shipped on Base alongside two sequencer failures, and Spark seeded shared stablecoin swap liquidity onto Uniswap v4.
Base: The Beryl hard fork activated on June 26 at 18:00 UTC, introducing B20, a protocol-native token standard for stablecoin and real-world asset issuers. B20 tokens run as Rust precompiles inside Base's node software rather than as deployed smart contracts, and ship with role-based permissions, mint and burn controls, transfer restrictions, and freeze and seizure tools for regulated issuers. The upgrade also cuts the standard single-proof withdrawal window from Base to Ethereum from seven days to five, and integrates Reth V2, which Base says reduces node storage by up to 50 percent. On June 25, hours before Beryl was originally scheduled, block production halted for approximately two hours after block 47,806,542 when a consensus fault caused an invalid block to enter the sequencing pipeline. The chain halted a second time on June 26 with the same signature, nodes stuck at the same block. Both halts required manual node restarts to restore syncing across the ecosystem. The root cause has been identified but no post-mortem has been published. As a consequence, the B20 Activation Registry mainnet enablement was postponed with no revised date. Developers cannot deploy B20 tokens until the registry comes online.
Spark / Uniswap: On June 25, Spark deployed approximately $150 million in stablecoin liquidity across two Uniswap v4 pools on Ethereum mainnet. The pools pair Sky's USDS against Tether's USDT and PayPal's PYUSD. The structure is designed as shared settlement infrastructure so that banks, fintechs, and payment firms entering stablecoin issuance can access a single pooled system rather than each bootstrapping isolated liquidity and inventory management. Spark functions as the orchestration layer controlling allocation governance; Uniswap v4 supplies the programmable AMM architecture. A DualPool hook allowing idle capital to move into yield strategies between trades is planned for a later phase pending a separate security review.
Two infrastructure prerequisites for institutional crypto use advanced in the last 48 hours: a protocol scaling testnet launched and a European payment compliance rail was cleared.
Cardano: Input Output Group launched the Musashi Dojo testnet for Ouroboros Leios on June 23. The testnet runs five structured phases, Earth through Void, for developer stress-testing and adversarial load simulation before any mainnet governance vote. Leios introduces endorser blocks that exploit idle time between standard Praos blocks, with early targets putting throughput at up to 200 KB/s against the current 4.5 KB/s ceiling. Mainnet deployment requires both successful test completion and a separate on-chain governance approval cycle, with a late 2026 target.
Ripple: Luxembourg's Commission de Surveillance du Secteur Financier issued a preliminary Green Light Letter for Ripple's Crypto Asset Service Provider license under MiCA on June 23. The approval is conditional and not yet final. Once finalized, it activates passporting rights across all 30 European Economic Area countries through a single authorization. Combined with Ripple's existing EU Electronic Money Institution license, the paired structure lets European banks, fintechs, and corporates access both Ripple Payments and RLUSD stablecoin infrastructure through one regulated integration, replacing prior per-jurisdiction compliance requirements. Around 83% of EU crypto firms remained unlicensed as of mid-June, making the July 1 MiCA deadline a hard sorting event for market access.