Anchorage Digital opens institutional access to Frgmnt’s fUSD and sfUSD
The SEC is rewriting the custody rulebook right now. The answer decides more than where your stablecoins sit — it decides who keeps the yield they generate.

On 25 August 2026, the SEC sent a crypto custody proposal to the White House Office of Management and Budget. The text is sealed. No public comment yet.
One phrase inside it matters more than the rest: qualified custodian.
How the agency defines those two words will decide who is legally allowed to hold digital assets in the United States, and under what conditions. Congress has stalled. The regulator is filling the vacuum.
Meanwhile most people still can’t answer a simpler question. When your stablecoins sit somewhere and quietly accrue a return — who actually holds the keys?
That is not a technicality. It decides what happens in a bankruptcy. It decides whether a balance can be frozen. And since July 2025, it decides something almost nobody talks about: who keeps the yield.
Custody stopped being a storage question. It became a market-structure question — and then a yield question.
“Not your keys, not your coins” started as a slogan. It is now written into law on two continents.
The direction of travel is clear enough. Custodians are being professionalised. Self-custody is being protected. Both are being defined — and definitions have consequences.
Strip the vocabulary away and one thing separates the two models. The private key.
Self-custody (non-custodial):
Custodial:
Chainalysis logged $3.4 billion stolen in 2025. Centralised services took the largest single hits — the Bybit breach alone was roughly $1.5 billion.
Private key compromise, not exotic smart-contract bugs, remains the dominant attack vector.
A “qualified custodian” is a legal designation, not a security guarantee.
Under Rule 206(4)-2, US registered investment advisers must generally hold client funds with one: a bank, a broker-dealer, a futures commission merchant, or certain trust companies.
In September 2025, SEC staff issued no-action relief letting advisers treat state-chartered trust companies as banks for crypto custody purposes.
What qualified custody buys you:
What it does not buy you:
That distinction is the whole article. Regulated custody manages how counterparty risk is handled. Non-custodial architecture removes that specific risk entirely.

Here is the uncomfortable data. A survey of more than 3,000 US crypto users found:
Globally, roughly 59% of wallet users say they prefer self-custodial wallets. Behaviour disagrees with belief by a wide margin.
The gap is not ignorance. It is friction. Self-custody has historically meant a seed phrase you guard forever, no support line, and no way to put idle dollars to work without becoming a part-time DeFi analyst.
Remove the friction and the gap closes. That is why MetaMask shipped a self-custodial Money Account in June 2026 bundling stablecoin yield, payments and trading. The market is chasing the same insight.

Now the part that should change how you think about all of this.
The GENIUS Act, signed 18 July 2025, prohibits permitted payment stablecoin issuers from paying holders any interest or yield simply for holding the token. The reserves still earn. The issuer keeps it.
That is the original stablecoin bargain, now written into statute. You hand over dollars. They hand you a token. They put the reserves in Treasuries. The return stays on their balance sheet.
The fight over the edges is loud:
Strip the politics and one fact survives. In a custodial model, the return your dollars produce belongs to whoever holds them. Custody and yield are the same decision wearing two hats.
Sky Protocol runs the opposite premise.
USDS is the fully backed unit of account of Sky Ecosystem — the stablecoin independent capital allocators draw against governance-approved collateral. It converts 1:1 with major stablecoins through the Peg Stability Module, with no fees and no slippage.
Convert USDS to sUSDS and you hold the world’s largest yield-generating stablecoin. sUSDS accrues the Sky Savings Rate programmatically, inside your own wallet.
Four mechanics matter here:
The demand is measurable. In Q1 2026, sUSDS attracted more than $2.5 billion in new capital — more than the next four yield-generating stablecoins combined.

Non-custodial does not mean risk-free. It means the risks are visible.
At the time of writing, Sky Protocol shows $14.15B in Total Protocol Collateral against $11.48B in stablecoin supply.
Overcollateralised, and auditable line by line at financial.skyeco.com — not attested quarterly by a firm you have never met.
Losses absorb in a fixed, published order:
sUSDS holders access the rate. They are not claimants on any single Agent, borrower or strategy. That distinction is structural — and most people get it backwards.

The record is checkable too. Seven years of operations with zero exploits at the core protocol. Solvent through Black Thursday.
Zero exposure to UST or FTX, because governance never approved either as eligible collateral.
S&P Global assigned a B- rating in 2024, the first structured finance credit rating given to an onchain protocol.
And the Sky Frontier Foundation reported Gross Protocol Revenue of $123.79M in Q1 2026, the highest in protocol history.
If you want the full architecture, start here.

Self-custody has a bill too, and it is worth naming honestly.
Chainalysis recorded $58 million stolen in violent “wrench attacks” in 2025 — the highest annual total on record — with more than $30 million already taken in the first half of 2026.
Home invasions rose to 37% of incidents. A lost seed phrase has no support line and no appeals process.
So the honest answer depends on you, not on a universal ranking:
But treat this as two questions, not one. Who holds the keys and who keeps the return used to be separate concerns. Since the GENIUS Act, they are the same concern.
Self-custody used to mean choosing control over yield. The non-custodial savings model exists so you don’t have to choose.
If you can’t name who holds the key, you already know the answer.
Over to you. Where do your stablecoins actually live right now — an exchange, a self-custody wallet, or split between both? And if the SEC’s definition of qualified custodian lands narrow, does that change your answer?
Drop it in the comments. Curious how many people are in the 88%.
Self-Custody vs Qualified Custody: Who Actually Holds Your Keys? was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.
The SEC’s Division of Corporation Finance has issued updated staff guidance on public reporting expectations for digital asset depositories and crypto custody arrangements.
The guidance centers on how public companies disclose balance sheet treatment and risk factors when they hold crypto assets on behalf of third-party customers. That makes it important for custodians, exchanges, digital asset platforms, and any public company handling customer crypto.
This is staff guidance, not formal Commission rulemaking.
That distinction matters. The SEC is not creating a new law through the document. But staff guidance can still influence how companies prepare filings, describe risk, and answer regulator comments.
For more details, visit the official Sec platform.
Crypto custody is not just a technical issue.
It is also an accounting, disclosure, and investor-protection issue. When a public company holds digital assets for customers, investors need to understand what is on the balance sheet, what is off the balance sheet, what risks exist, and how those assets are protected.
That is not always simple.
Digital assets can involve private keys, third-party custodians, insurance limits, wallet architecture, legal title questions, bankruptcy risk, cybersecurity controls, and changing regulatory expectations.
SEC staff guidance helps companies understand what information may need to be disclosed.
The industry learned the hard way that custody structure matters.
After major exchange failures and platform collapses, investors became more alert to questions around customer asset segregation, corporate control, rehypothecation, wallet access, and bankruptcy treatment.
Public companies cannot simply say they hold crypto safely and leave it there.
They need to explain the risks clearly. They may need to describe how assets are held, who controls private keys, whether customer assets are commingled, what happens if a custodian fails, and whether legal protections are clear.
That is why reporting guidance in this area carries weight.
The SEC’s document should not be overstated.
Staff guidance does not have the same legal force as a formal rule adopted by the Commission. It also does not replace statutes, court decisions, or accounting standards. Companies still need legal and accounting advice for their specific facts.
But guidance can still matter in practice.
It tells issuers what SEC staff may ask about during filing reviews. It can shape disclosure norms. It can also signal which risks regulators believe investors need to see more clearly.
The guidance points toward more precise disclosure around crypto custody.
That may include the nature of assets held, customer rights, custody controls, risk exposure, insurance arrangements, third-party service providers, cybersecurity risks, and balance sheet presentation.
For companies in the digital asset depository business, vague language is becoming harder to defend.
Investors want to know what the company actually controls and what obligations it has to customers.
This is not a market-moving crypto rule by itself.
But it is part of a wider tightening around disclosure. As more companies hold, custody, or service digital assets, regulators are pushing for clearer reporting. That can make the sector more transparent, but it may also increase compliance costs.
For investors, that is probably healthy.
Crypto custody risk is not going away. Better disclosure makes it easier to compare companies and understand where the real exposure sits.
The SEC’s latest staff guidance adds another layer to that process.
This article draws on SEC Division of Corporation Finance staff guidance relating to digital asset reporting and custody disclosures.
This article was written by the News Desk and edited by Samuel Rae.
This report is based on information released by Sec. at Sec

Bitcoin Magazine
![]()
SEC Sends Proposal to White House To Modernize Crypto Custody
The Securities and Exchange Commission has sent a proposal to the White House aiming to “clarify the framework for the custody of crypto assets” for investment advisers and companies.
In a rule change sent Tuesday, the regulator said it wanted to “improve and modernize the regulations” surrounding custody for the crypto space.
The proposal comes after a vote was delayed on the long-awaited Clarity Act. Despite the delay, regulators like the SEC and Commodity Futures Trading Commission have said they will still proceed with trying to shape crypto policy.
JUST IN:
— Bitcoin Magazine (@BitcoinMagazine) August 26, 2026SEC has sent a new proposal to the White House concerning "amendments to the custody rules" to "clarify the framework for the custody of crypto assets"
pic.twitter.com/c45BK1tlok
“This rulemaking would clarify the framework for the custody of crypto assets for investment adviser and investment companies, as well as make other modernizations needed to remove burdens from certain outdated provisions that are no longer needed to provide investor protection given the evolution in the markets and security trading and holding practices,” the proposal read.
Pro-crypto lawmakers had hoped to pass the Clarity Act before Congress broke for August recess, but the vote slipped to September after Democrats balked at the latest draft.
Some Republican senators — like Senator Cynthia Lummis — accused some of deliberately holding it back.
Still, pro-crypto regulators want to press ahead. CFTC Chairman Michael Selig has said he will proceed with rulemaking whether or not the Clarity Act is enacted, aiming to finalise rules before the administration’s term is out.
And earlier this month, the SEC proposed its own framework to allow token issuers to raise money in the U.S. without falling foul of securities laws.
President Donald Trump campaigned on a ticket to help the crypto industry and received major backing from Silicon Valley entrepreneurs. Since taking office, regulators have taken a remarkably different approach to watchdogging the digital asset space.
The president last week urged lawmakers to get the Clarity Act over the line. SEC Chair Paul Atkins has said he is “committed to supporting Congress in advancing” the bill.
This post SEC Sends Proposal to White House To Modernize Crypto Custody first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Bitcoin is not broken by quantum headlines, but disciplined holders should stop address reuse, protect cold storage, and prepare for the…
With CBBI at 39, Fear & Greed at 73, M2 near $23.16 trillion, and Bitcoin reclaiming major technical ground, the rebound is real — but…
Bitcoin Magazine
![]()
Citi to Debut Bitcoin Custody for Institutional Investors
Citi will debut a bitcoin custody service later this year. The top bank said Tuesday that its Custody+ product will allow institutional investors to custody both traditional assets and bitcoin within one framework, rather than needing separate systems.
The bank first announced plans to debut a digital asset custody service last year. It said at the time that it had been developing the service for several years.
Citi is the latest American bank to move deeper into the digital asset space following friendlier legislation and pro-crypto approach from U.S. regulators.
JUST IN: $2.8 trillion bank Citi announces they will go live with Bitcoin custody services later this year
— Bitcoin Magazine (@BitcoinMagazine) August 18, 2026pic.twitter.com/hfIZIJIh7o
“Custody+ is a clear example of this investment as we build infrastructure to eliminate latency and drag for institutional investor clients,” Head of Investor Services at Citi, Chris Cox, said in a statement.
The service, according to Citi, will let clients process every asset servicing transaction through a “single seamless flow.”
Clients will get continuous, near-instant visibility and execution across servicing, settlement, FX, cash, and data — plus the flexibility to plug in digital assets or build their own offerings on top of Citi’s rails — instead of being locked into a single standardized custody workflow.
Citi’s new custody service runs parallel to its broader blockchain offerings, including Citi Token Services, which enables real-time cross-border payments using tokenized deposits.
The firm since last year has also been working with other top banks — including Deutsche Bank, Goldman Sachs, and Bank of America — to explore issuing a stablecoin product.
Speaking about the long-awaited crypto Clarity Act last week, Citigroup CEO Jane Fraser said that the bank was a “leader in digital assets.” She added that while the legislation needed some improvements, the bank wanted a “good bill to go through.”
The Clarity Act, which aims to define which tokens qualify as securities versus commodities, is the latest pro-crypto legislation. Lawmakers will vote on the bill in September.
This post Citi to Debut Bitcoin Custody for Institutional Investors first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Bitcoin Magazine
![]()
Casa CEO Nick Neuman: 233k BTC Moved To Safety After Coldcard Exploit Proves Self-Custody Resilience
Casa CEO Nick Neuman pointed to onchain data from the recent Coldcard firmware exploit as evidence that self-custody strengthens Bitcoin’s resilience as an asset class.
In an X post on Aug. 9, Neuman cited figures showing that in the days after the Coldcard hack, where approximately 2.1k BTC was stolen, 22k BTC moved to exchanges and 233k BTC left long-term holder wallets in on-chain transactions, according to data by Checkonchain. “The onchain metrics around the Coldcard incident reinforce how important self-custody is to the resilience of Bitcoin as an asset class,” Neuman wrote.

Galaxy Research has tracked confirmed losses from the Coldcard entropy flaw as low as 1.7k, ranging to more than 2k BTC. The stolen coins are tracked across multiple attack waves beginning July 30, with higher estimates approaching $130 million. The vulnerability stemmed from a March 2021 firmware issue that weakened seed generation on certain Coldcard models.
Neuman said Casa’s own customer conversations indicated that some of the 233k BTC movement reflected holders shifting from non-Coldcard single-key setups (such as Ledger or Trezor) into multisig wallets after reassessing single-key risk. Other flows involved multisig users removing Coldcard devices from their keysets.
“So somewhere between ~10x-100x the amount of bitcoin stolen was moved to safety as people sounded the alarm,” he wrote. “This is a giant flashing neon sign showcasing the resilience that self-custody adds to the network.”
Neuman contrasted the outcome with a hypothetical centralized custodian breach. In that scenario, he argued, the numbers would likely reverse: limited funds might escape while the majority would be lost in a single event. With self-custody, attackers had to target individual wallets, limiting the scale of any single success and giving holders time to react.
“If all that BTC was held at a custodian and the custodian was hacked instead, those numbers would have been flipped,” Neuman stated. “As it was, the thieves had to crack one wallet at a time (and are still going), earning a little BTC each wallet, instead of cracking one wallet and getting a massive payday.”
He concluded that self-custody benefits not only individual holders but the Bitcoin network itself by distributing risk and preserving confidence.
Casa, founded in 2018, provides multi-signature vault solutions aimed at higher-value holders and institutions seeking practical self-custody. Bitcoin Magazine has previously covered the company’s multisig products and Neuman’s views on sovereignty and institutional adoption.
The Coldcard incident has prompted renewed discussion across the industry about single-signature hardware wallets, key generation practices, and the relative merits of multisig and emerging covenant-based vault designs. Onchain data cited by Neuman suggests that, whatever the technical shortcomings of specific devices, the ability of holders to move funds independently limited the systemic impact.
This post Casa CEO Nick Neuman: 233k BTC Moved To Safety After Coldcard Exploit Proves Self-Custody Resilience first appeared on Bitcoin Magazine and is written by Juan Galt.
Bitcoin Magazine
![]()
Self Custody Is Dead. Long Live Self Custody
The Coldcard hack last week dealt a low blow to certain elements of the Bitcoin industry. A somber introspection has begun to question many of the practices and assumptions involved in securing bitcoin at a retail level. The consequences of this process might not be visible for many months.
Some are saying that self-custody is dead. Some reports estimate that over 11,000 bitcoins were moved to custodial exchanges last week as users fled one of the most popular hardware wallets in the Bitcoin industry. The hack, which is ongoing and users can still save themselves from, has seen north of 1,300 bitcoins stolen, with some estimates as high as 2,000 coins.
Coinkite in particular and its most vocal founder, NVK, had very strong opinions about what it took to secure bitcoin private keys from hackers. Its hardware wallets were airgapped to make sure malware could not exfiltrate data through USB cables. It used low-resolution, LED screens to avoid the complexity of touch screens. It developed protocols like BBQR and integrated NFC so that information could be transferred between the device and a computer without them touching or sharing SD cards. The list of paranoid design choices that made Coldcards iconic is long.
Yet the hackers involved in the theft of bitcoins held in Coldcards last week did not use any methods you might see in a modern spy movie. They exploited the one feature Coldcard should have had absolutely locked down. The generation of keys with high enough randomness, also known as entropy. In other words, secrets securing that are actually, mathematically hard to guess. While the devices were intended to use high-quality sources of entropy, the firmware had a bug which did not, resulting in Bitcoin private keys that were, in turn, easy to guess. The bug went undiscovered for years, and the product only grew in popularity in the meantime, until last week.
Despite this loss, which wounded a cohort of Bitcoiners who were among the most committed. Bitcoin can not give up on self-custody and expect to retain its integrity. At least that is what many in the industry believe, and the case for that is clear.
Satoshi Nakamoto’s white paper clearly intended Bitcoin to be a solution to trusted third parties and intermediaries. It eloquently made the case against trusted hierarchies of finance, as the 2008 financial crisis revealed the deep systemic risks and flaws legacy finance has led to. Many believe the 2008 crisis was never escaped, its consequences haunting us to this day.
This may be unpopular, but we never escaped the 2008 financial crisis. We just shifted the pain.
— Nayib Bukele (@nayibbukele) July 29, 2026
Going further back to the birth and proliferation of the modern banking system and its fiat currency. The 6102 executive order signed by President Franklin D. Roosevelt in 1933 saw the persecution and confiscation of gold from centralized trusted third parties and citizens alike. $300,000,000 in gold was returned after the executive order threatened gold owners with heavy fines and jail time if they did not sell their bullion to the banks at $20,67 per ounce. Over 14 million troy ounces worth of gold were turned in as a result. Another 200 million troy ounces are estimated to have been held in the American banking system at the time. The banking system, not just in the U.S. but worldwide at the time, was built atop the gold standard.
The U.S. was the largest economy of the world at the time, with the biggest concentration of gold inside its borders. Its abandonment of the gold standard was a death blow to gold as a free market pricing mechanism for goods and services as a whole. Governments throughout the world, now free from the chains of sound money, quickly fed and fattened from the hidden tax of inflation. At the time of the EO, the price of gold was artificially fixed to $20.67 an ounce; not a year later, it was repriced to $35 with the passing of the Gold Reserve Act in 1934, a 69% devaluation in the dollar.
The fiat standard was thus delivered to governments throughout the world on a silver platter, by an unholy alliance between the banking system and politicians. It granted central banks the legal right to counterfeit money, to print it at will. It was soon followed by World War Two, which was of course funded by fiat currency. Tens of millions of people sacrificed in this war at the altar of state power.
Fast forward a hundred years and U.S. government debt demands almost a trillion per year be paid in interest alone, with total owed close to 40 trillion and debt to GDP at 123%. These are arguably the inevitable yet predictable consequences of the death of the gold standard. The purchasing power of the dollar has collapsed in the century that followed, at the same time as technology has gone parabolic in its efficiency gains. That is only possible with money that has continually become worthless for decades. And the dollar is the best of the fiat lot.
Confiscation of gold in a rising power like the United States murdered the gold standard. It, however, could not have been possible if civilian custody of gold had been wider and more distributed. Many of the civilians who returned millions in gold after the 6102 EO had just taken it out of their accounts in a bank run. Their names were known, the amount of gold they held, tallied.
If gold was easier to move in large quantities. If private gold ownership totals had been more ambiguous. If removing the free flow of gold had not been so easy for the state to do, by knocking on the doors of bankers and pointing a gun, then perhaps the economies of the world would not have been able to withstand such a vast and destructive war, as was WWII for so long, in the following decade.
Bitcoin poses an alternative to gold, designed to learn from its inadequacies. Bitcoin has better properties to resist and survive such a confiscation. Bitcoiners envision and aspire to unlock a world that adopts Bitcoin as a global monetary standard. Where a large minority or even a small majority of the global economy uses Bitcoin as their primary store of value. In such a future, Bitcoin would take the place of gold and return sound money to the so-called capitalist order.
To reach global reserve currency and defend this position, Bitcoin will need to be better than gold, and it can be better precisely because of its digital nature. The control of private keys, as difficult as it seems now in the shadow of the Coldcard hack, nevertheless can be far more powerful than any physical vault. Multi-signature scripts alone unlock distributed storage of Bitcoin private keys, such that a threshold of them must approve to move coins. This means that multi-jurisdictional, multinational vaults can exist and escape or resist the greedy hands of a large state that might attempt a new kind of 6102 takeover.
The digital nature of Bitcoin means large amounts of value can be moved easily as well, without having to send the navy on a mission to pick up the gold. Without having to build a trusted hierarchy of banking custodians to transfer it. Civilians, with tools available today and better tools that are yet to come, might be able to hide their Bitcoin ownership as has been done in war-torn countries like Ukraine already, escaping a fearsome state’s grip over the public’s wealth.
Ultimately, a major hardware wallet manufacturer has failed the Bitcoin industry. The fundamental qualities of money remain the same, and among them all, as identified by Aristotle and others beyond him, Bitcoin remains king.

“Bitcoin vs gold vs fiat One is not like the others” – @BITCOINARCHIVE
This post Self Custody Is Dead. Long Live Self Custody first appeared on Bitcoin Magazine and is written by Juan Galt.
Bitcoin Magazine
![]()
Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach
Over a thousand bitcoins are believed to have been stolen so far in a hack that started to be discussed on social media in the afternoon of July 30th. Coinkite, one of the most reputable hardware wallet manufacturers, was revealed to have a critical bug in the way it generated secure private keys for its Bitcoin hardware wallets. Industry experts believe AI was used in the breach.
Coldcard MK3 devices with firmware version 4.0.1 (March 2021) through 4.1.9 are the worst affected. 12- or 24-word seeds generated by the device that did not include user-generated dice rolls or a BIP 39 extra passphrase are vulnerable.
Users who fit this category, who have bitcoins in an MK3 Coldcard and did not use the dice roll feature for extra entropy or the extra passphrase, should consider themselves at risk and move their coins as soon as possible from the wallets. Bitcoin Magazine technical writer Shinobi has published a guide on the topic, and Coinkite has also published a guide and advisory.
The vulnerability was a specific line of code in the firmware, a low-level software codebase that controls the hardware. This firmware appears to be upgradable. The Coinkite advisory was updated this morning, advising users to upgrade device firmware for all three chips, MK3, MK4 and MK5 devices, including the Coldcard Q:
“Updated July 31, 2026 at 9:33 a.m. EDT: Fixed firmware is now available. Mk4 and Mk5 users must update to version 5.6.0 or later. Q users must update to version 1.5.0Q or later. For Mk3, update to version 4.2.0 or later.”
Coinkite also explained in their advisory that updating the firmware does not mean that the private and public keys generated by the vulnerable firmware before it are now secure; those keys remain vulnerable as they were effectively created with a weak password. After the firmware is updated, a new wallet needs to be created, and the funds need to be sent onchain to the new addresses to secure the funds. Coinkite wrote:
“Updating the firmware does not change or repair an existing seed. If your seed was generated before the fixed firmware version for your model, follow the migration guidance below unless the independent dice-entropy exception applies to you.”
Peter Todd, Core contributor and cybersecurity engineer, today addressed specific edge cases for multi-signature wallets that use a threshold of Coldcards to secure funds. “Example case: you have a 2-of-3, with 2 Cold Cards, and a 3rd uncompromised device. If you move your funds, the moment your script is revealed for the first time – previously hidden behind the address hash – the attacker now knows enough to use the compromised 2 cold card keys to steal your funds.”
The transaction that reveals the multisig script might be unconfirmed, giving hackers enough time to create a competing transaction with a higher fee. Fortunately, such cases have a solution: the MARA mining pool can help in this case with their private mempool mining service, Slipstream; “because they promise to keep your transaction – and thus pubkeys – secret until they’re already in a block. Dramatically reducing the ability of the attacker to steal the funds,” said Todd. He added that “If you’ve already reused addresses, this isn’t relevant, and you should just try to move your funds ASAP. But if you haven’t, MARA may be able to help.”
NVK, one of the co-founders of Coldcard, published a long post on X with an initial analysis beyond the basic security steps needed to secure funds. In it, he wrote that the company is “committed to working with affected users who want to pursue a police report, insurance claim, or their own investigation”, including “a written incident summary specific to your loss and any transaction data we can share”.
Beyond the immediate crisis, NVK pointed to a broader tech shift as the hacking capabilities of AI begin to change previous cybersecurity dynamics and expectations. In the blog post he wrote:
“To every other developer: we believe this is a sober reality of the new AI paradigm. AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts. If your firmware is open-source or has ever been public, assume it’s already being read by attackers and defenders alike.”
The hack and over 70 million dollars in estimated stolen funds in the past 24 hours are an effective bounty paid to hackers who are now likely auditing every wallet codebase available for vulnerabilities. While the Bitcoin and broader crypto industry has generally operated under the assumption that hackers will test their code, the development of AI models optimized for cybersecurity accelerates these processes.
Industry experts gathered in a long X Spaces public call last night, discussing the topic for many hours. Beyond the immediate recommendations and answering questions to Bitcoin users throughout the long Spaces, analysis of what is likely to follow in the coming weeks was also discussed. Other wallet providers are likely to get probed, and especially open source projects which generate private key material will be tested.
The X Spaces was not recorded, likely to preserve the privacy of everyone in the call; however, initial sentiment suggests companies will need to be auditing their code with the latest frontier models, as a matter of survival. The latest cybersecurity-oriented AI models by Anthropic, OpenAI, Moonshot’s Kimi K3 and others are already available to the public. Many companies in the Bitcoin industry already use these to test the integrity of the code, but some might not be, and the race to find vulnerabilities in wallet-facing code will certainly continue, especially in the following weeks.
Ultimately, today we grieve lost coins, and a state of introspection and careful review occurs. Beyond this now historic hack will be an open source self-custody industry and infrastructure that is likely to be orders of magnitude more secure, with very hard lessons learned. After all, every hacker with an AI agent is likely testing defenses now.
Future high sovereignty wallets, be it at the retail or corporate level, are likely to not depend on any single vendor. Multisignature wallets, when well done, can distribute vulnerability risks across different code bases, teams and hardware.
User-generated entropy was also a major theme in the X Spaces discussed earlier, with dice roll-generated entropy brought up regularly as a solution. Coldcards, as well as other hardware wallets like Foundation Devices, guide users on how to add their own entropy properly; many dice need to be rolled, ideally north of a hundred individual rolls. Once done, however, dice rolls represent a non-software source of randomness for wallets that also separates users from the edge-case risks in software- or hardware-generated entropy.
Covenants a popular soft fork among a certain niche in the Bitcoin industry have also started to be brought up as further step to strengthen the self-custody industry. This upgrade to the Bitcoin consensus which might be hard fought if achieved at all, could give users important smart contract capabilities, such a wallet that can only send to a white list of addresses, something not possible in Bitcoin script today.
This post Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach first appeared on Bitcoin Magazine and is written by Juan Galt.
A Swiss cantonal bank has moved crypto trading directly into its normal banking experience, and that is the part of the story that matters most.
BancaStato, the state bank of the Canton of Ticino, has partnered with Sygnum and Avaloq to let clients buy, hold, and sell Bitcoin, Ethereum, Litecoin, and Solana through its mobile and web banking channels.
This is not a crypto exchange launching another app. It is a traditional regional bank adding digital assets inside the banking platform its clients already use.
Sygnum is providing the digital asset banking and custody infrastructure, while Avaloq’s core banking environment is being used for the integration. The assets are held off-balance sheet in Sygnum’s institutional custody setup.
That is a very Swiss version of crypto adoption: regulated, integrated, custody-led, and built into the existing banking stack rather than presented as a retail trading spectacle.
Most crypto access stories still have a similar shape.
An exchange adds a product. A fintech app adds a token. A wallet adds a new chain. Those launches can matter, but they usually sit outside the traditional banking relationship.
BancaStato’s move is different because it brings crypto into the bank interface itself.
For ordinary clients, that reduces friction. They do not need to open a separate exchange account or move money to a platform they may not know. They can access supported digital assets through a banking environment that already handles their financial relationship.
For institutions and conservative users, that matters even more.
The biggest barrier to crypto adoption is often not interest. It is trust, custody, compliance, and operational comfort. A cantonal bank working with Sygnum and Avaloq gives the service a more familiar structure.
That does not make crypto risk-free. Bitcoin, Ethereum, Solana, and Litecoin remain volatile assets. Clients can still lose money if prices move against them. But the access model is more bank-native than the typical retail exchange route.
Sygnum has built its position around regulated digital asset banking, and this kind of partnership is exactly where that model becomes useful.
Banks that want to offer crypto do not always want to build custody, trading infrastructure, blockchain connectivity, compliance processes, and asset operations from scratch. That is expensive, slow, and risky.
A B2B provider gives them a shortcut.
Sygnum’s infrastructure lets BancaStato offer crypto access while leaning on a specialist digital asset bank for the custody and trading stack. Avaloq’s involvement then connects that service into the bank’s existing core system.
That is the real adoption signal.
Crypto becomes another product layer inside regulated banking infrastructure, not a separate universe.
If more banks choose that path, the industry may not grow through flashy retail apps alone. It may grow quietly through integrations that make digital assets feel like part of normal financial services.
Switzerland has been one of the more serious crypto jurisdictions for years.
That does not mean every Swiss financial institution is rushing into digital assets. But the country has built a clearer lane for regulated custody, tokenization, banking integrations, and institutional services than many other markets.
BancaStato’s launch fits that pattern.
It is not a claim that all Swiss banks are now adopting crypto. It is not even a national rollout. It is one cantonal bank serving Swiss residents through a specific partnership.
But that is still meaningful.
Traditional finance adoption rarely happens all at once. It usually arrives through controlled launches, limited asset lists, custody partnerships, and client-demand testing. Banks start with major assets, watch how clients use the product, and then decide whether to expand.
Here, the supported list is conservative but notable: Bitcoin, Ethereum, Solana, and Litecoin. That gives clients exposure to the two largest crypto networks, one high-activity smart contract ecosystem, and one older payment-focused asset.
The next question is whether this kind of integration becomes repeatable.
If Sygnum and Avaloq can help one cantonal bank bring crypto into its banking channels, the model may appeal to other banks that want to offer digital assets without becoming crypto-native operators themselves.
That would be more important than the launch size alone.
The market often gets excited about exchange volumes and ETF inflows, but bank distribution is another adoption route. It can bring crypto to clients who are interested but do not want to leave the regulated banking environment.
There are still limits. The rollout is local. The asset list is narrow. The risk remains with clients. And this should not be exaggerated into a national Swiss banking shift.
Still, BancaStato’s move shows how crypto access is becoming more embedded in traditional finance.
Not through a slogan. Through custody, APIs, core banking software, and a regulated bank willing to put the service in front of clients.
That is a quieter story than a bull-market exchange launch, but it may be more durable.
This article is based on announcements from Sygnum and BancaStato.
This article was written by the News Desk and edited by Samuel Rae.
This report is based on information released in disclosures at primary source documentation.
