96 stories published across 7 days, including 12 continuing threads.
The Week’s Throughline
The defining event was the Bybit hack — approximately $1.46 billion stolen, the largest exchange breach in crypto history — with Bybit claiming it blocked a further $700 million in withdrawals without disclosing how. The security picture darkened further as Galaxy Research tied years-old Coldcard firmware weakness to Bitcoin thefts now exceeding $115 million, and Maya Protocol suffered a six-bug exploit that drained cross-chain liquidity pools. Against this backdrop of trust erosion, U.S. regulators moved with unusual speed: the SEC unanimously proposed its first comprehensive crypto-assets framework (Regulation Crypto Assets, plus token offering exemptions including a $75 million safe harbor), the Treasury proposed GENIUS Act licensing rules for stablecoin issuers, and the OCC granted preliminary approval for Trump-linked World Liberty Trust to become a national trust bank and issue the USD1 stablecoin. The week’s throughline: custodial and self-custody security failures reached record scale at the exact moment the federal regulatory architecture to govern the industry finally began to take concrete shape.
Continuing Threads
- Bybit’s record breach and partial containment: After the $1.46 billion theft, Bybit said its controls prevented over $700 million in additional withdrawals from other wallets during the same attack. The mechanism remains undisclosed, and the stolen amount is still the largest ever taken from an exchange.
- Coldcard’s firmware bug, five years in the making: Galaxy Research tied the July 30 sweep of 1,082.65 BTC to weak randomness in seed generation present since firmware v4.0.1 (March 2021). Total losses now exceed $115 million across three confirmed attack waves and 5,200+ drained addresses, with roughly 1,531 BTC still sitting in attacker-controlled wallets and Coinkite’s CEO initially denying a wallet-wide vulnerability.
- Tether’s first Big Four audit: KPMG issued an unqualified opinion on Tether International’s 2025 financial statements, with reserves exceeding liabilities by $6.814 billion and gold physically counted bar-by-bar. The full report has not been released, and the milestone lands just as the GENIUS Act and FDIC proposals impose stricter reserve and disclosure rules.
- The SEC’s regulatory package takes shape: All three sitting commissioners voted for Regulation Crypto Assets, paired with two registration exemptions, a conditional safe harbor that would strip the “investment contract” label from tokens, and state securities law preemption. All of it is proposed, not final, and public comments are now open.
Worth Remembering
- Maya Protocol’s exploit was more than a $1.7 million theft: Post-mortems found the attacker exploited six bugs to inflate a liquidity pool by 49.45 million CACAO, gained 99.93% control of it, and triggered a global halt — with total pool value dropping $11 million, per CoinDesk.
- Gnosis Chain voted to stop being a Layer 1: GnosisDAO approved transitioning from a standalone chain to an Ethereum-settled rollup, unlocking roughly 350,000 GNO and ending treasury-funded staking rewards — a structural retreat from validator-set security.
- Binance handed Russian authorities data used to prosecute a Ukraine donor: Documents show client data Binance provided led to charges against a user for donating to Ukraine’s military, raising hard questions about exchange compliance with authoritarian governments despite Binance’s 2023 exit from Russia.
- The OCC’s World Liberty decision sets a stablecoin precedent: Preliminary conditional approval for World Liberty Trust to operate as a national trust bank and take over USD1 issuance from BitGo places stablecoin issuance under direct federal banking oversight for the first time — tangled, inevitably, with President Trump’s ownership stake.