The Mecca Defense Agreement's expansion could significantly alter regional power balances, fostering new alliances and shifting security paradigms.
The post Pakistan, Saudi Arabia, and Turkey discuss Mecca Defense Agreement expansion at Istanbul summit appeared first on Crypto Briefing.
The potential expansion of the Mecca Defense Agreement could reshape regional security dynamics and influence Gulf stability and oil markets.
The post Pakistan: 6-7 countries eye Mecca Defense Agreement amid Israel-Iran conflict appeared first on Crypto Briefing.
Partners Group's debt refinancing and redemption challenges could strain investor confidence, impacting future fundraising and market stability.
The post Partners Group faces €6B debt refinancing challenge as share price slides 24% appeared first on Crypto Briefing.
The exploit highlights vulnerabilities in DeFi protocols, emphasizing the need for stronger safeguards against price manipulation to protect assets.
The post Tectonic exploit drains $6M from Crypto.com-linked Cronos blockchain before validators pull the emergency brake appeared first on Crypto Briefing.
Aave's dominance in DeFi lending highlights the growing centralization within decentralized finance, impacting market dynamics and competition.
The post Aave accounts for 48% of active loans as DeFi lending surges 30% to $26.1B appeared first on Crypto Briefing.
Bitcoin Magazine

Bitcoin Cools Off After $3 Billion ETF-Driven Surge
Bitcoin slid Friday afternoon, cooling down after a phenomenal run following huge investment from U.S. ETF buyers.
The leading cryptocurrency was trading for $77,379 on Friday afternoon in New York after dropping more than 3% over a 24-hour period.
Bitcoin hit a high this week of $81,281 but slowed down after Federal Reserve Chair Kevin Warsh gave his first major speech as head of the central bank — saying on Friday that he had “more work to do” to fight inflation.
The Bitcoin price has in the past dropped when the Federal Reserve thinks inflation is too high because it means less chance of a rate cut; the leading cryptocurrency typically does better in a low-interest rate environment.
Bitcoin started surging last week after the U.S. Treasury would at least double the size of its liquidity-support buyback operations. The announcement last week hurt the dollar but non-yielding assets have benefited.
Exchange-traded funds, managed by the likes of BlackRock, Fidelity, and Grayscale have received net positive inflows for nine days in a row, according to Farside Investors data. Last week was their best week since October — when bitcoin hit a new all-time high — and that run has continued into this week.
Since August 17, investors have thrown over $3 billion at the funds. BlackRock’s iShares Bitcoin Trust received the lion’s share of the investment, but Morgan Stanley’s new Bitcoin Trust — which debuted this year — also experienced significant inflows.
Analysts have said that the so-called debasement trade — when investors buy an asset as a way to hedge against a currency losing value — was leading investors to eye-up bitcoin again.
Investors taking part in the trade think that bitcoin, gold and other precious metals are a good way to protect themselves from excessive government spending.
Total U.S. debt crossed $40 trillion for the first time this month.
This post Bitcoin Cools Off After $3 Billion ETF-Driven Surge first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Bitcoin Magazine

Debasement Trade Is Here Thanks to Government Debt — And Bitcoin Will Benefit: Grayscale
The debasement trade is back — and will benefit bitcoin.
That’s according to asset manager Grayscale’s crypto research team, who wrote in a note this week that the U.S. government debasing its currency would lead to cash hitting digital assets.
“Unchecked government debt growth undermines the credibility of fiat currencies and drives investors to seek out alternative stores of value like physical gold and certain cryptocurrencies,” the note by the firm’s head of research, Zach Pandl, read, adding that primarily bitcoin would benefit.
The so-called debasement trade is when investors buy an asset as a way to hedge against a currency losing value. The trade was hot last year, and helped bitcoin’s run, but the digital asset’s run lost steam after October as traders turned their attention to stocks related to artificial intelligence.
But since last week, bitcoin has benefited from news that the U.S. Treasury would at least double the size of its liquidity-support buyback operations. The announcement last week hurt the dollar but non-yielding assets have benefited.
“That buybacks are needed at all is the problem: heavy growth in government debt is driving up the cost of borrowing,” the note continued. “The Treasury is treating the symptoms (rising bond yields) because they cannot cure the disease (structural deficits).”
The note added that on the same day last week as the buyback announcement, the Treasury also said the U.S. public debt exceeded $40 trillion for the first time.
As debt and interest payments grow, the government needs to either raise taxes, cut spending, or issue more debt.
Bitcoiners see the more politically likely path as expanding the dollar supply — which is ultimately bad for the dollar, and good for scarce assets like bitcoin.
After bitcoin started surging last week, the dollar had its worst week of August and was trading at a three-month low.
Bitcoin was trading for $77,493 on Friday afternoon in New York after hitting a high this week of $81,281. Over a 24-hour period, the coin now sits unmoved, but over a 30-day period, it has jumped by more than 20%.
This post Debasement Trade Is Here Thanks to Government Debt — And Bitcoin Will Benefit: Grayscale first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Bitcoin Magazine

Bitcoin’s Moment Has Come for the Far East, Says Metaplanet CEO
Bitcoin’s time has come in Asia — especially with a changing regulatory landscape — and its people and companies should take advantage.
That was the message Metaplanet CEO Simon Gerovich gave at this year’s Bitcoin Asia conference, where on Friday he spoke of how his company went from failing to the third biggest bitcoin treasury in the world.
Bitcoin Asia kicked off on Thursday in Hong Kong, bringing the biggest names in the space to Hong Kong to talk about everything from treasury companies to building apps from scratch.
“The previous cycles belonged to the West, and the first Asian cycle has already started,” Gerovich said. “The only question left is who builds it. Will you?”
Often dubbed Asia’s answer to Nasdaq-listed Bitcoin treasury Strategy, Metaplanet pivoted from its core hotel and technology business to buying Bitcoin in 2024. The Tokyo Stock Exchange now holds 43,000 bitcoins worth about $3.3 billion at today’s prices.
Gerovich said in his speech that his company was small and going nowhere fast until it started putting bitcoin on its balance sheet, basically allowing investors to buy exposure to the biggest digital coin via its regulated shares.
He said that the strategy is a major opportunity for Asian companies, which can now capitalize on the changing regulatory landscape and the growing interest in Bitcoin.
Asian nations, including Japan, Hong Kong, and Singapore, are making regulatory changes to support digital assets.
Gerovich noted that Japan in particular is a country where its citizens have saved like no other part of the world — and that capital can now be put to good use.
“Hoarding cash has stopped making sense, and every household in Japan can now feel it,” he said.
“Japanese households hold roughly 14 trillion dollars in financial assets. About half of that sits in bank deposits, earning almost nothing, and that’s just Japan, add Korea, Southeast Asia, and the wealth managed out of this place, Hong Kong, and you’re looking at the deepest pools of patient savings on Earth.
“And for the first time in a generation, these savings are looking for somewhere to go.”
Gerovich added that Asian companies, institutions, and savers should take advantage of the current market conditions and build the Bitcoin infrastructure in their own regions.
“The end of the cash hoarding strategy and new rules are arriving at exactly the same time, and together, they set up what I think is the single biggest opportunity in Asian markets today,” he added.
This post Bitcoin’s Moment Has Come for the Far East, Says Metaplanet CEO first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Bitcoin Magazine

Capital B Raises €21M From Adam Back and TOBAM To Buy More BTC
Capital B, the Euronext Growth-listed company that bills itself as Europe’s first bitcoin treasury company, has raised €21 million ($24 million) in a private placement backed by Blockstream’s Adam Back and asset manager TOBAM — money it says could buy 270 more bitcoin and push its stack to roughly 3,415 BTC.
The company said Friday that a total of 36,219,070 shares were sold at €0.58 each as part of the deal, a 6.45% discount to Wednesday’s closing price.
Capital B said the net proceeds are expected to reach about €19.9 million after fees and transaction costs.
Capital B is the 27th biggest publicly traded bitcoin treasury in the world, according to Bitcoin Treasuries, with a total of 3,145 bitcoins in its stash — worth $245 million at today’s bitcoin price of $77,960.
Capital B, which describes itself as Europe’s first bitcoin treasury, built much of that position through fundraising rounds during the first half of 2026.
In May, it acquired 192 coins for €13 million after completing three capital raises.
Capital B’s announcement as other treasuries look to raise funds and accelerate their buys. Just this week, NYSE-listed AI-powered education company Genius Group said it was aiming to build parallel AI and bitcoin treasuries worth a combined $1.6 billion, after the company sold its entire bitcoin reserves to repay $8.5 million in debt.
Bitcoin treasuries have faced headwinds since 2025 when the price of the leading cryptocurrency took a hit. A number of companies in the space have had to liquidate their holdings, including the biggest corporate holder of bitcoin, Nasdaq-listed Strategy.
This post Capital B Raises €21M From Adam Back and TOBAM To Buy More BTC first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Bitcoin Magazine

Bitcoin Drops Before Shrugging Off Fed Chair’s Inflation Comments
Bitcoin dropped, then popped after Federal Reserve Chair Kevin Warsh gave his first major speech as head of the U.S. central bank and said he had “more work to do” to fight inflation.
The leading cryptocurrency was recently trading for $79,474 after dropping as low as $78,630 before quickly rising again.
Bitcoin has typically done well in a low interest rate environment but the Federal Reserve has been reluctant to lower borrowing costs due to sticky inflation in the world’s biggest economy.
“But on the price-stability side of our mandate, the numbers are more concerning,” Warsh said after talking about employment.
He added: “We must be confident that underlying inflation is moving to our objective, clearly and at sufficient speed. Otherwise, we have work to do.”
Bitcoin has in the past dropped on news that the Federal Reserve thinks inflation is too high because it means less chance of a rate cut. Following Warsh’s speech, traders priced in a 50% chance of rate hike in September.
But Bitcoin has appeared to — at least for now — shrug off the speech.
Bitcoin’s started surging last week after the U.S. Treasury Secretary Scott Bessent announced the department would double the size of its long-dated bond buybacks.
The news sent yields down lower, and the dollar slid while non-yielding assets like bitcoin and gold jumped.
Positive regulatory news also helped the coin: President Donald Trump last week said that the long-awaited crypto Clarity Act was a “very, very powerful” piece of legislation, and urged lawmakers to get it over the line.
The proposed law will establish a framework for distinguishing between digital assets that are securities, commodities or payment stablecoins — legislation that the crypto industry has long called for.
The Federal Reserve Bank of Kansas City is on Friday holding the annual event at Jackson Hole, Wyoming, where central bankers, Federal Reserve officials, policymakers and academics will gather to discuss “Financial Innovation: Implications for Payments and Policy.”
According to the Federal Reserve Bank of Kansas City website, this year’s event will touch on how “recent years have seen a dramatic increase in innovation in financial intermediation and payments,” including new technologies such as “cryptocurrencies and stablecoins.”
This post Bitcoin Drops Before Shrugging Off Fed Chair’s Inflation Comments first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
HTTP error 429 on https://cryptoslate.com/feed/
Failed to fetch feed.
If you run a crypto wallet as a browser extension, today is the day to open your extension list. In August 2026 the security firm Socket disclosed two separate campaigns in which extensions for Firefox, Chrome and Edge harvested recovery phrases, private keys and login credentials for crypto exchanges. The second of those reports was written up on August 30 and is therefore one day old. What is affected is precisely the place where many investors handle their wallet every day.
A browser extension is a small add-on program that runs inside the browser and holds permission to read and change the content of the pages you visit. That same permission is what makes it useful to wallet providers and valuable to attackers.
Socket is a security firm specialising in software supply chains that examines packages and extensions for malicious code. Its researchers published two findings within ten days that show the same pattern and yet do not belong together.
The first report is dated August 20, 2026 and concerns the Firefox marketplace: 77 extension identities are connected according to Socket's analysis, 40 of them confirmed malicious. The second report circulated between August 28 and 30 and concerns Chrome and Edge: 19 extensions, 18 of them for Chrome and one for Edge, carried a wallet drainer. A wallet drainer is malicious code that empties a balance to an outside address in a single operation instead of siphoning off individual amounts.
Both cases share one thing that matters more to you than any number: the extensions sat in the official marketplaces of the browser makers. Anyone who installed them did nothing wrong, downloaded no dubious file and clicked no link in an email.
Socket calls the Firefox campaign Offside Wallet Theft Factory and explicitly does not attribute it to any known actor. The researchers also do not write that the same operator stands behind every single extension; what links them is shared code and shared infrastructure.
The 40 confirmed extensions fall into four groups. Seven posed as crypto products and served as remotely controlled phishing loaders, among them an entry called 0KX WEB3, which used a zero in place of the letter O and so imitated the name of the exchange OKX. Fifteen carried the theft code directly inside them. Thirteen of those fifteen were altered rebuilds of the Rabby wallet software. Five more collected access credentials and the contents of the clipboard. The remaining 37 of the 77 identities appeared as VPN tools, password generators or sports apps and did in fact display match scores.
According to Socket, the interfaces of OKX, Rabby Wallet and TronLink were imitated. In this affair those three providers are the injured parties, not the cause: their name and their appearance were used as bait without any involvement on their part.
The technical basis was provided by projects on the database service Supabase, which acted as remote switches, together with Cloudflare Workers and Pages for the forged interfaces as well as control servers written directly into the code. Such control servers are known in the field as C2 servers, short for command and control; they receive the stolen data and send new instructions back. The signature data of the extensions covers the period from March 9 to August 3, 2026, with clusters in April and at the end of July. Mozilla removed the reported add-ons from the marketplace after the report.
An extension with permission to read and change data on all websites sits technically on the same level as the page itself. It sees what you type, it sees what the page shows you, and it can alter both before either reaches the other. For a wallet extension that is normal and unavoidable. For an extension that unlocks right-clicks or displays football scores, it is not.
The most instructive part of the Firefox finding has nothing to do with crypto at first. Nine of the confirmed malicious extensions began life as harmless sports applications and displayed results from football, basketball and American football. Only later updates replaced that function with wallet theft code, and did so under the same identifier. The malicious version thereby inherited the entire installed base and the accumulated positive reviews of its harmless predecessor. The campaign owes its name to that trick.
For your own practice this means that the check you carried out at installation does not hold indefinitely. Reviews, user numbers and the age of an extension describe its past. An update can replace the code completely, and by default extension updates run through automatically without your being asked.
With five of the 19 Chrome and Edge extensions it went much the same way, only one step earlier: according to Socket's analysis they were genuine, already published extensions by other developers that were taken over and then rebuilt. The remaining 14 the attackers had built themselves from scratch.
The thirteen altered Rabby rebuilds are the technically most delicate part of the Firefox finding. Rabby is open-source wallet software; its code may legally be copied and changed. The attackers rewrote exactly one function, namely the one that stores the keyring permanently. A keyring is the data record in which a wallet holds its private keys and the recovery phrase together.
In the original, this keyring is converted into text and then encrypted with your password before it lands on the hard drive. In the altered versions it is, as Socket describes it, sent off at precisely the moment when it exists in text form, that is, before encryption. Your wallet password protects nothing at this point, because it would only come into play afterwards. The same versions also intercept the recovery phrase when a wallet is created and when one is imported.

The second finding is the more recent one and concerns two further marketplaces in Chrome and Edge. According to Socket's analysis the 19 extensions contained a drainer that serves several chains at once: wallets on Ethereum and all networks compatible with it, wallets on Solana and wallets on Tron.
Added to this were rebuilt recovery and update pages that looked like the official interfaces of the hardware wallet makers Ledger and Trezor. Their sole purpose was to collect the recovery phrase. Here too, the two manufacturers are victims of imitation. Anyone who uses a hardware wallet and wonders which models exist at all and how they differ will find the overview in our comparison of crypto hardware wallets.
On reach there is one solid individual figure and one estimate. Solid is the extension named Enable Right Click & Copy, Smart Unlock + OCR: it had more than 70,000 users on Chrome and more than 10,000 on Edge when it turned malicious. For the campaign as a whole, one trade report cites around 80,000 affected users. The starting point is also disputed: BleepingComputer writes that the operation may have been running since the beginning of 2024, while another assessment of the same Socket analysis speaks of roughly six months of active operation and names February 2024 as the likely beginning. Both readings stand side by side, and neither of them is confirmed.
At the time of publication, according to BleepingComputer, none of the extensions was still available in the Chrome Web Store. The Edge version still was.
The sequence in the Chrome and Edge case is worth going through calmly, because it explains why a single bad extension reaches so far. After installation it opens an encrypted permanent connection to a control server, a so-called WebSocket connection. Over that line it loads individual JavaScript building blocks that were not contained in the marketplace package at all. A reviewer who looks only at the submitted package therefore finds little there.
It then removes the CSP header from every page you call up. The Content Security Policy is a protective instruction with which a website tells the browser which sources scripts may be executed from at all. If it falls away, the browser accepts outside code as well. That code is then injected into the page through hidden HTML elements.
The result is uncomfortably concrete. The bank, the exchange and the wallet interface you open in the same browser are, from that moment on, no longer the pages the provider delivers. They are what the extension makes of them. That is exactly why an approval that looks harmless on screen can mean something quite different in the background. How to read such an approval in detail is set out in our article on what you really approve when you confirm.
According to Socket, the drainer attacks not only wallets but also accounts at trading venues. Coinbase, Binance, Kraken, OKX, MEXC, KuCoin and Bybit are named, along with the MetaMask wallet. What it collects are access credentials, session tokens, browser history, account information from Facebook and LinkedIn, and form entries across a range of websites.
The term session token deserves an explanation of its own, because it is what sets this apart from ordinary password theft. A session token is the pass that a website issues to your browser after a successful login so that you do not have to enter your password and second factor again with every click. Whoever holds that token is already logged in as far as the website is concerned. Two-factor authentication has happened by then and is not requested a second time.
That is why changing your password is not enough when you suspect something. You have to end all active sessions as well. Most trading venues offer this function in their security settings under labels such as active devices, sessions or logged-in devices. Which providers come into question for customers in Germany at all, and which security features they bring with them, is shown in the overview of crypto exchanges.
The check takes a few minutes and costs nothing. In Firefox you open the address about:addons and select Extensions on the left. In Chrome it is chrome://extensions, in Edge edge://extensions. In all three browsers the detail view can be opened for each entry, showing permissions, publisher and installation source.
Go through the list from top to bottom and ask yourself two questions about every entry: do you still remember why you installed this extension? And have you actually used it in recent weeks? Anything that stumbles on either question goes. An extension you do not need is still an open door that nobody is guarding.
There is unfortunately no clean identifying mark for the update trick, and that belongs to the truth of the matter. There are, however, indications that are worth something taken together. It is striking when an extension with a banal function suddenly demands far-reaching permissions, or when the publisher name has changed. It is striking too when a review column shows older enthusiastic voices and more recent complaints about altered behaviour side by side. And any extension whose name matches a well-known product but for a single character is striking, as with the zero in the entry 0KX WEB3.

A genuine wallet extension needs far-reaching rights, otherwise it could not do its job. Access to data on all websites is therefore no alarm signal in its case. The real question is a different one: why does a screenshot tool, a translator or a right-click unlocker need the same permission?
In practice this means you sort your extensions by purpose and not by provider. Every extension that may read and change all pages although its function is needed only on a single page or at the push of a button is a candidate for deletion. Chrome and Edge additionally allow you to limit an extension's access to individual pages or to grant it only after a click. That setting costs you two days of getting used to it and takes most of its reach away from a hijacked extension.
The two Socket findings lead to a distinction that often blurs in everyday use. With a wallet as a browser extension the private key lies encrypted on the computer, and the software in the browser decrypts it in order to sign. With a hardware wallet the key never leaves the device; the computer sends the transaction over and gets the finished signature back.
This difference decides how an attack of the kind described turns out for you. Against harvested key material the hardware wallet helps, because there is simply nothing there to harvest. Against a manipulated interface that shows you a false recipient address it helps only if you read the details on the display of the device and not on the screen. And against a rebuilt recovery page that asks you to enter your recovery phrase, no technology helps at all. There, only one rule carries: never type that phrase anywhere. Which software wallets exist for everyday use and where their limits lie is set out in the comparison of software wallets.
For the Firefox case Socket makes a clear recommendation: anyone who has entered a recovery phrase or a private key into one of these extensions should treat the data as permanently compromised and move the balance to a newly created wallet. The reason is simple and readily overlooked. Deleting the extension takes back nothing that has already been transmitted. A recovery phrase cannot be revoked, only replaced.
The order matters when you suspect something. Create the new wallet on a device that is not affected, and only transfer afterwards. Anyone who sets up the new wallet in the same infected browser merely repeats the exercise with fresh keys. Then come the accounts at the trading venues: new password, end all sessions, set up the second factor again and check the withdrawal addresses on file.
A word on handling the agitation such reports set off. In precisely the days after an incident becomes public, messages multiply that promise help to those affected and ask for the recovery phrase in the process. That scam now runs on paper as well, as the case of wallet phishing by letter shows. No reputable provider and no authority ever asks for that phrase.
If something has in fact flowed out, secure the evidence before you tidy up. That includes the time of the outflow, the addresses affected, the transaction identifiers from the relevant block explorer, the name and identifier of the extension together with a screenshot of the marketplace page if the entry is still reachable, and the file number of a police report.
How such a loss works out for tax purposes depends on the individual case and belongs in the hands of a tax adviser. Without complete evidence that question cannot be settled at all, and the evidence is considerably harder to obtain weeks later than on the day after. A portfolio tool that records your movements anyway spares you the reconstruction by hand when it counts.
The month's two findings arose independently of each other and affect all three major browsers. They say the same thing: a browser maker's marketplace is a pre-selection and not a guarantee, and the check made at installation ages faster than the extension itself.
The original reports are available at Socket on the Firefox campaign and in the write-up by BleepingComputer on the Chrome and Edge case.
(As of August 31, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
The most uncomfortable deadline of this week is one that officially does not exist. At Plume, the Season 2 claim has been open since the end of May 2026 – and the project has never published an end date, neither as a day nor as a period. Secondary reporting, meanwhile, circulates a window of roughly three months, which would run out with August, that is, today. That figure cannot be substantiated at the project source. Which is exactly why there is only one sensible way to handle it: if you are registered and have not claimed yet, check the portal now instead of waiting for an announcement that may never come.
This overview lists the airdrops that either have a claim window open this week or a date fixed within the next 14 days. Every detail comes from the source linked alongside it. Where a project has published no end date, that is stated explicitly – there are no estimated deadlines here. For last week's status, see our piece on the airdrops of week 35.
| Project | Status | Date / deadline |
|---|---|---|
| Plume (Season 2) | Claim open | no end date published; registration closed May 27, 2026 |
| Grass (Stage 2) | Claim open | until January 22, 2027 |
| GRVT | First tranche expired, more to follow | 30 days per tranche; date of the second unlock not published |
| Midnight (NIGHT) | Thawing running | until December 4, 2026, then a 90-day grace period |
| dappOS (DOS) | Claim phase 2 open | since August 11, 2026, end not published |
Plume is a layer-1 chain for tokenised real-world assets. Season 2 of its points programme ended on March 31, 2026; registration for the distribution then ran from April 29 to May 27, 2026. Anyone who missed that step is, by the project's own account, excluded from the distribution – there is no way to fix it after the fact. Eligible wallets needed at least 10,000 Plume Points, in some cases plus verification via Human Passport.
The claim itself has been running since the end of May 2026 through the official portal. And here is the gap that puts this entry at the top of the list this week: Plume has never named an end date. The announcement gives a start and the registration deadline, nothing more; when we retrieved it on August 31, 2026, the project blog carried no newer post supplying a claim deadline either.
A number is circulating regardless: secondary reports and aggregator pages mention a window of about three months, which by arithmetic would expire at the end of August. That figure does not come from Plume. We list it here only because it circulates, and expressly not as a deadline. In practice it changes nothing about the advice – on the contrary: a claim with no published end date can be closed at any time, without prior notice. If you are eligible and registered, claim today, not at some point.
Source: Plume – "Plume Points Season 2 Airdrop Registration Is Now Open" (project blog, retrieved again on August 31, 2026; the blog index contains no newer airdrop post)
The Solana project Grass has been paying out its Stage 2 rewards since July 22, 2026, covering epochs 1 to 19, that is, the period from October 14, 2024 to June 8, 2026. Claiming runs through the project's official dashboard.
Grass is one of the few projects that names a clean, published deadline: the claim is open until January 22, 2027, a full six months. Whatever is not claimed by then is retained by Grass. It is the most comfortable entry on this list – and, experience suggests, the one where most is left on the table, because half a year of time feels like unlimited time. Put the date in your calendar if you are eligible.
Source: Grass – "How Your Stage 2 Rewards Allocation Works" (retrieved again on August 31, 2026)
The derivatives exchange GRVT held its token generation event on July 30, 2026 and is distributing 280 million GRVT in total. What makes this airdrop distinctive is its mechanics, and they are stricter than in any other entry here: the distribution runs in tranches over twelve months, and every unlocked tranche has a claim window of 30 days. Once it closes, the tranche is gone for good; the project explicitly rules out exceptions.
The first tranche was unlocked at the TGE, and its window ran out by arithmetic at the end of August. Important detail: GRVT never published a calendar date for it – the 30 days follow from the published rule. What counts is solely the expiry date the Reward Portal shows for your specific tranche.
For this week, what matters most is what is still to come: after the first, further unlocks follow over twelve months, each with its own 30-day clock. GRVT publishes no unlock schedule, and when we checked the help centre on August 31, 2026, there was no date for the second tranche. We deliberately do not calculate one here. Anyone who registered before July 17, 2026 and stored a destination chain is credited each due tranche automatically; everyone else has to claim manually at every unlock. That is exactly where forfeited claims come from – set a reminder, as the project itself recommends.
Source: GRVT Help Center – "How to Receive and Manage Your $GRVT Airdrop" (retrieved again on August 31, 2026)
At Midnight, the privacy network from the Cardano ecosystem, NIGHT tokens are redeemed through a thawing procedure. According to the project, the frame for it runs until December 4, 2026, followed by a grace period of 90 days. If you are eligible, this gives you the longest lead time on this list – and you still should not push it, because redemption involves several steps.
One caveat, in our own cause, that belongs in this format: the project source was not reachable when we tried on August 31, 2026 – from our environment the server answers with a bot-protection interstitial (HTTP 429) instead of the article. The dates given here therefore come from the last successful check of that same page. There is no indication that anything has changed, but we cannot re-verify it today. If you are relying on the deadline, open the page yourself.
Source: Midnight – "Guide to the NIGHT Token Launch and Redemption" (retrieval on August 31, 2026 blocked by bot protection; details from the last successful check)
The DOS token launched with its TGE on August 10, 2026, and phase 2 has been running since August 11, 2026, letting eligible wallets claim transferable DOS. dappOS has announced a phase 3, but without a date, and no end date has been published for any of the phases so far. The only official route is the claim portal on the project's own domain.
What comes after that is the real decision: a freshly distributed token with a small market capitalisation swings violently in its first weeks, and the selling pressure from an ongoing claim hits it on top. Anyone who wants to trade such a position at all needs access that actually covers the small pairs – pure charting tools like Dexscreener or TradingView only display, they do not trade. One alternative for that is the mobile app FOMO Family, which lets you discover, swipe through and trade meme and low-cap tokens directly in the app, with fast deposits; download the app through this link and you get ten percent off trading fees. The sober part belongs with it: trading meme and low-cap tokens is highly risky, volatility is extreme and a total loss is possible at any time. Where else DOS trades, see our crypto exchange comparison.
Six much-discussed candidates did not make the list. The reason differs in each case, and each one is worth as much as an entry:
Plus this format's standing rule: projects listed as "live" on aggregator pages that name neither a snapshot nor a claim window at the project source do not get in. "Airdrop confirmed, date open" is not a deadline.
Airdrops are the preferred hunting ground for wallet drainers, and the patterns repeat:
An airdrop is not by definition a tax-free gift. Whether an allocation counts as taxable income depends above all on whether you provided something in return. With this week's campaigns that is not a marginal question: anyone who collected points through trading volume or by running a network node stands differently from someone who received an allocation without doing anything.
So secure the timestamp, quantity, market value, price source, transaction hash and the terms of participation right at the moment of claiming – the terms in particular tend to disappear first once a campaign page is taken down. An overview of further campaigns is available in our section on crypto airdrops.
Week 36 is the week of unspoken deadlines. Two entries on this list – Plume and dappOS – have an open claim window with no published end, and at GRVT the clock on every future tranche runs 30 days without any unlock schedule existing. In all three cases the same applies: a missing date is not a reprieve, it is a risk. Only Grass and Midnight name hard dates with January 22, 2027 and December 4, 2026 – and even there a large share of allocations is routinely left unclaimed.
And the sobering part: most allocations sit in the two- to three-figure range, the fee for claiming eats a noticeable share of that, and a substantial proportion of all allocated tokens is never claimed at all. The effort pays off mainly where you are already eligible.
Disclosure: some of the providers mentioned in this article work with us through partner programmes. This has no influence on our editorial assessment.
(As of August 31, 2026. This article is not investment advice. Deadlines and terms of participation change; check them with the provider before taking part.)
If you are holding VANRY on KuCoin, a different deadline applies to you than the one the exchange gives you. What counts is September 10, 2026 at 13:00 UTC. By then your VANRY has to be sitting in your own wallet and swapped through the project's portal. KuCoin itself allows withdrawals until September 14, 2026 at 08:00 UTC, roughly four days longer. Anyone who goes by that later date will collect tokens for which no swap route exists any more by that point.
The reason is an announcement KuCoin published on August 13, 2026, which German-language coverage has so far passed over. The exchange has delisted the token and stated explicitly that it will not handle the swap for its customers. That puts the entire action on you. This piece explains what to do, in which order, and where the established facts end and the uncertainty begins.
In the delisting notice of August 13, 2026, KuCoin first describes the starting position: according to the Vanar Chain team the VANRY token is being migrated to the Base network, and KuCoin had worked with the project team on the terms of the token swap. Then comes the sentence that makes the difference. After several discussions, the project team had been unable to meet the conditions KuCoin requires in order to process a swap on behalf of users. The exchange draws the conclusion from this that it will not support the swap.
What matters is how you read that paragraph. It is the account of one of the two parties involved. KuCoin attributes the failed agreement to the project team; a public rebuttal from Vanar addressing this passage specifically is not available. For your decision the question of blame is secondary in any case. What is decisive is the practical consequence, and it is stated unambiguously in the same notice: VANRY deposits remain closed, withdrawals are possible via the Ethereum network as an ERC20 token, and users are strongly advised to withdraw their holdings as soon as possible.
That recommendation is right, but it is incomplete. Nowhere does the notice name a date by which the withdrawal has to be done for the swap to still work. That date sits with the project.
In the interplay between exchange and project there are three points in time. These three belong to different senders and mean different things.
August 14, 2026, 08:00 UTC. KuCoin removed VANRY from spot trading. Since then you can neither buy nor sell the token there. Deposits had already been closed beforehand and stay closed. This date has passed and matters only as context.
September 10, 2026, 13:00 UTC. The project's swap window closes. It was opened on August 11, 2026 at 13:00 UTC and runs for 30 days. The portal states unmistakably that there is only a single window and that no subsequent migration via the portal will be offered once the 30 days have elapsed. This is the deadline you have to orient yourself by.
September 14, 2026, 08:00 UTC. KuCoin closes the withdrawal service for VANRY. Up to that point you can get at your balance. After that, no longer by the normal route.
The last two dates lie roughly 91 hours apart, that is three days and 19 hours. During that period the withdrawal still works, but the swap does not.
Pairs of deadlines of this kind turn up regularly in delistings, and most of the time they are harmless. Here they are not, because the order is the wrong way round. The exit from the exchange stays open longer than the entrance to the swap. A customer who reads their exchange's announcement attentively and sticks to the date named there can do everything correctly and still end up with tokens that can no longer be migrated.
It is worth looking at Binance for comparison. There, five weeks lie between the end of the swap window and the end of the withdrawal deadline. A gap like that stands out; you can see that two different clocks are running. We have written up what that case looks like in detail in our piece on the VANRY migration to Base and the Binance withdrawal deadline. At KuCoin it is four days instead of five weeks, and the exchange urges customers in the same notice to withdraw. The gap is small enough to feel like a buffer, and large enough to become expensive.
In practice that means: count backwards from September 10, not forwards from today. And count with a buffer, because between clicking "withdraw" and the moment the tokens are available in your wallet, an exchange has verification steps, security checks and, if in doubt, a manual approval.

A token swap is the move of a token from one smart contract to another, as a rule because the project is changing blockchain. The old units are locked, and the same number of new units are created on the target network. With VANRY this happens at a ratio of one to one: for every old token locked you receive one new token on Base.
A centralized exchange can carry out this process for its customers because it holds the tokens in its own pooled wallets anyway. The trading venue locks the total holding, receives the new units and credits them back to the accounts. From your side it looks like nothing at all: the balance stays the same, trading carries on. It is precisely this convenience that falls away when an exchange declines the swap. Then you are the custodian yourself, and the action that would otherwise run in the background is one you have to trigger.
Self-custody is the technical term for holding your tokens in a wallet whose private key only you know. The project's swap portal can work exclusively with wallets of that kind, because it requires a signature from the address the tokens are sitting on. An exchange address cannot provide that signature for you.
The procedure consists of two operations that have to run one after the other. First the withdrawal from the exchange, then the swap in the portal. Both together have to be completed before September 10, 2026 at 13:00 UTC.
You need a wallet that supports the Ethereum network, because KuCoin pays VANRY out as an ERC20 token on Ethereum. Whether that is a software wallet on your phone or a hardware device makes no difference to the swap; what matters is that you control the private key and that the wallet can connect to a web application. If you are setting things up afresh at this point anyway, our hardware wallet comparison sets out the criteria that count here. Have the receiving address ready and check it twice.
For the withdrawal you select Ethereum, or ERC20, as the network. That is the only option KuCoin names for VANRY. Reckon with a network fee that the exchange deducts from the amount paid out, and with a processing time that, depending on load, can range from a few minutes to several hours. Small holdings can become uneconomic at this point if the fee eats up the value of the position. You should do that calculation beforehand.
As soon as the tokens have arrived in your wallet, you connect it to the swap portal, select Ethereum as the source chain, enter the amount, grant the approval and confirm the lock transaction. The new tokens are then sent automatically to the same address on Base. The portal gives around four hours after confirmation of the lock transaction as the figure from experience. There is no manual collection step.
One warning is stated so plainly in the portal that it belongs here again: never send tokens directly from an exchange into the swap. The detour via your own wallet is not a recommendation but a precondition, because the new tokens go to the sending address and you have no access to an exchange address.
On its portal page the project keeps a list of the trading venues that, by their own announcement, will process the swap. Six names are on it: Paribu, Bitvavo, LBank, Indodax, BingX and WEEX. For German investors Bitvavo is the one that matters most among them, because this provider serves the German-speaking market directly.
KuCoin is not on this list, and the exchange has since explained why itself. That answers a question that was still open in August: English-language reporting on August 10 had said that KuCoin would handle the migration automatically. That statement had no counterpart in the project's own list, and we flagged it at the time for what it was. The announcement of August 13 resolves the contradiction in the other direction.
A rule follows from this that holds beyond this case. What counts is always the announcement of your own trading venue, not a project's collected list, and certainly not a media report. If you spread your holdings across several venues anyway, a look at our overview of crypto exchanges compared helps you see which provider communicates how on delistings and migrations. VANRY was, incidentally, also one of six tokens that were dropped from spot trading at Binance in August; the list is in our piece on the Binance delisting of six tokens.
If your VANRY is in the project's staking rather than on an exchange, a second timetable applies. Staking means that you deposit tokens in a contract and receive a reward for it; the contract only releases them again after a lock-up period. This lock-up period, the so-called cooldown, is 21 days at Vanar.
According to the project, staking was closed on August 19, 2026; that was also the last day for which rewards accrue. Anyone who initiates unstaking by September 10, 2026 at the latest remains eligible for the swap, even if the 21 days have not elapsed by then. For these wallets an airdrop on Base is planned for September 11, 2026. Anyone who does not initiate unstaking by September 10 will, on the project's account, not be included in that airdrop.
In practice that means: the click on "unstake" is the actual cut-off, not the withdrawal itself. If you have not done anything here yet, that is the most urgent point on the whole list.

At this point precision matters more than drama, because a lot of half-knowledge is circulating here. The old tokens do not disappear on September 10, and nobody declares them worthless by decree. The project writes explicitly that it can neither block nor freeze, claw back or alter individual holders' balances. What ends is the swap route via the portal.
What the project goes on to write: after the migration the old contracts on Ethereum, Polygon and VanarChain are no longer to represent the active VANRY economy; the new token on Base becomes the definitive token for the coming phase. Full contract details and any final measures for the old contracts are to be published through the official channels. The project has not yet named a date for that.
That also leaves open whether there will be a case-by-case solution for latecomers after the deadline. The portal says neither yes nor no on this. Anyone who misses the swap should neither rely on goodwill nor assume it is ruled out. All that is established is that the route via the portal is closed at that point. More important than any speculation about it is the plain observation that liquidity follows the active token: the DEX liquidity on Ethereum was, according to the project, already removed on August 10, 2026.
Migrations attract imitators. As soon as a project announces a new contract, tokens with the same name and the same ticker appear that have nothing to do with the original. The only reliable test is the contract address, meaning the unique identifier of the smart contract on the chain in question.
For the old token on Ethereum and on Polygon the project names the same address, beginning with 0x8de5b80a. The new token on Base carries an address that begins with 0x07848a7b. On VanarChain itself there was no token contract, because VANRY was the native currency of that chain. Check the full address against the entry on the official portal page before every operation, and never take it from a message, a screenshot or a comment.
The portal itself warns with unusual clarity against using links from comments, direct messages, Telegram messages or unofficial websites. That warning is not there without reason: a deadline is the moment when attempted fraud works best, because time pressure crowds out checking.
The swap itself costs no fee according to the project; the ratio stays one to one. You still have to pay, in three places. First, the exchange's withdrawal fee. Second, the network fee for the approval and the lock transaction on Ethereum, which you bear yourself and which fluctuates with load. Third, if you want to move the new tokens on Base later, the network costs there, which are however markedly lower.
Keep a small amount of the relevant fee currency ready on the Base side, otherwise you will see your new tokens in the wallet but will not be able to move them. And build the four hours the portal gives as its experience figure for delivery into your schedule. Anyone starting around midday on September 10 no longer has that buffer.
How a one-to-one swap in the course of a network migration is to be treated for tax purposes depends on the individual case and is not something that can be answered across the board. What you can do in any event is make sure your records are complete. Note down when you originally acquired the tokens, when they left the exchange, when the lock transaction was confirmed and when the new units arrived on Base. Save the transaction identifiers for both chains.
The reason is pragmatic: a change of chain tears apart the automatic matching in many analysis tools. The old holding disappears, a new one turns up, and without your note that looks like a sale followed by a purchase. Our overview of tax tools and portfolio trackers shows how to represent operations like this cleanly. Classifying your specific case belongs in the hands of a tax adviser.
Honesty requires marking the edges. The dates, addresses and procedural details in this text come from two primary sources: KuCoin's delisting announcement and the project's swap portal. Both were retrievable on August 31, 2026. The two sides have opposing interests in how the failed swap agreement is presented, and neither of the two deadlines appears at the respective other party.
What we cannot establish is whether KuCoin will still change its position before September 14, whether the project will grant a grace period, and when the old contracts will be switched off. Nor do we make any statement about the token's price development; this text is a matter of deadlines and custody. And we do not judge who is in the right in the dispute between exchange and project team. Before every step, check the current announcement at KuCoin and the details in the official Vanar Chain swap portal.
(As of August 31, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
The Cronos blockchain has stopped. On Sunday, August 30, 2026, the chain's validators halted block production after an attacker had emptied the lending market Tectonic. Estimates of the damage range from roughly $66 million to $75 million, and a second on-chain analysis arrives at a considerably larger outflow from the lending pools. For you, a single distinction comes first: if your balance sits on the chain itself, it is not moving right now, whether or not you ever had anything to do with Tectonic. If it sits in the Crypto.com app or on the company's exchange, it is untouched, according to the company.
Tectonic is the largest lending protocol on Cronos. A lending protocol is an application into which users deposit funds so that other users can borrow them against posted collateral; the depositors earn interest in return. Before the attack it held roughly $121.7 million, according to Blockonomi, which amounted to about 46 percent of all capital deposited in Cronos DeFi. Outstanding loans at that point stood at roughly $82.7 million.
The attacker drove up the price of TONIC, the protocol's own governance token, posted the revalued holding as collateral and borrowed the hard assets out of the pools against it. He then began to move the proceeds out across a bridge. A bridge is a service that transfers value from one blockchain to another; it is the only way to get proceeds off a chain.
That is exactly where the validators stepped in. The Cronos account wrote on X the same day: "We identified an exploit in Tectonic. The Cronos Network has been halted and we'll provide updates here." Tectonic itself reported shortly afterwards that it was dealing with an incident, and asked users to leave the protocol alone for the time being: "As a precaution, please do not interact with the protocol until we confirm it is safe to do so."
The price of CRO, the chain's base asset, incidentally did not give way that day. Blockonomi reports a gain of around five percent over the course of the day. That is an indication of how little a chain halt can be read off the market price in the first moment.
The numbers that explain the attack are not in the damage report but in the market data of the manipulated token. TONIC had trading liquidity of roughly $1.34 million and a daily volume of about $11,000, according to Blockonomi. A token with that volume can be pushed in any direction with comparatively little capital.
According to the analysis by on-chain analyst Weilin Li, which several trade publications rely on, the TONIC price rose roughly a hundredfold in about 20 minutes. The attacker then posted that holding as collateral and withdrew from the pools the assets that were actually worth something. Blockonomi puts the window between the start of the manipulation and the end of the withdrawals at around 65 minutes.
The procedure has a name, and it is an old one. An attacker inflates the price of a thinly traded piece of collateral, borrows real assets against it and leaves the worthless position standing. Anyone who knows the Moonwell case on Base will recognize the pattern immediately: there too, barely traded collateral was the way in, as our analysis of the Moonwell exploit of August 27 shows.
No key was stolen and no security flaw in the program code was exploited. The contracts did what they were supposed to do. What was wrong was the assumption they operated on: that the reported price of a piece of collateral matches what it actually sells for. That is a valuation question, not a key question, and that is why no hardware wallet protects you here.
Every lending protocol sets a loan-to-value ratio for each piece of approved collateral. The loan-to-value ratio states what share of the deposited value you are actually allowed to borrow; at 20 percent, $1,000 of collateral gives you $200 of credit. For TONIC that value stood at 20 percent, according to Blockonomi.
A low ratio sounds cautious, and it is, as long as the underlying price holds. Against a manipulated price, however, the ratio no longer helps at all. Twenty percent of a value inflated a hundredfold is still a multiple of what the collateral really yields. The ratio caps the leverage, not the error.
Anyone who wants to see how differently providers handle exactly this question will find the range of approved collateral and terms in our comparison of crypto lending providers. The gap between a protocol that admits only a few deeply traded assets and one that accepts its own governance token as collateral is considerable.

Several amounts are in circulation, and they contradict each other only in appearance. Weilin Li's first estimate came to roughly $66 million and was raised to about $75 million after a further attacker address holding roughly $8 million could be attributed. That figure appears in most of the day's reports, among them The Block.
A second analysis, which Cryptobriefing attributes to on-chain analyst Awoo, arrives at an outflow of roughly $120 million from the pools in a single transaction, plus around $2 million through copycats and a stake of about $5.6 million from the attacker. Other houses name $119.5 million as the amount that was at risk.
The two figures measure different things. One describes what was left as proceeds at the end, the other what was moved out of the pools in total. Tectonic itself had confirmed neither a sum nor a cause by press time. As long as that is the case, the range belongs in every account, and not a smoothed average.
That a blockchain can be halted within minutes is not a matter of course but a property of how it is built. Cronos runs on Tendermint Core, a consensus mechanism in which a fixed, permissioned group of validators produces the blocks. The number of these validators is capped at 100.
A validator is a machine that proposes and confirms new blocks. With a hundred known operators, an agreement can be organized within a few minutes. With a chain of hundreds of thousands of independent participants it cannot be, and that is precisely why Bitcoin cannot be halted and Cronos can. That is neither a flaw nor a merit but a trade-off: speed and the ability to act, in exchange for unstoppability.
The case of August 30 is not the first of its kind this month. Only the day before, three chains from the Cosmos ecosystem pulled the emergency brake for a different reason, as set out in our analysis of the Cosmos EVM vulnerability. The chain halt has thus been used as a tool twice within two days.
The arithmetic of the day is unusually clear. Before block production ended, the attacker had moved roughly $6 million across a bridge to Ethereum, according to consistent reports. Around $60 million stayed behind on the stalled chain and is as unreachable there for the attacker as it is for everyone else.
The halt has thereby held on to the greater part of the proceeds. But it has also frozen every other position on Cronos along with it: every open loan, every trading position, every scheduled payout, every automated process. A user who wanted to sell on Sunday afternoon and had nothing to do with the incident could not.
Neither Cronos nor Tectonic had published a restart date or a final post-mortem by press time. A post-mortem is a project's retrospective report on the course, cause and consequences of an incident. Nor had any party committed by then to compensating Tectonic's depositors.
Cronos is often mentioned in the same breath as Crypto.com, and for placing your own situation it is precisely that closeness that produces the most common mix-up. Crypto.com chief executive Kris Marszalek stated on X on August 30 that the company's app and exchange had not been compromised, that customer funds there were safe, and that its own security team was supporting the investigation. He promised a full post-mortem once the investigation is complete.
In practice that means: anyone holding CRO through the app or the exchange holds an entry in a company's database and is not affected by the state of the chain for now. Anyone running their own wallet on Cronos, by contrast, holds their assets on exactly the chain that has stopped. The same coin, two entirely different situations.
That distinction is the core of the case for you, and it has a flip side. A balance held with a provider is insensitive to a chain halt, but dependent on the provider. A balance in your own wallet is independent of the provider, but tied to the fate of the chain. You do not get both at once.

A halted network behaves differently from what most people expect. Your assets have not disappeared, the last valid balance is fixed, and it stands. What is missing is the ability to change it. There is no transfer, no sale, no repayment and no margin top-up as long as no block is being produced.
Three things follow from this that can affect you directly. A loan that stood just short of the liquidation threshold cannot be rescued by a top-up during the standstill. A price you saw on an external market can no longer be realized on the chain. And an application that depends on data from this chain carries on working with a frozen state, even if it runs on a different network itself.
At the restart a further question arises that is still open in the Cronos case: what happens to the attacker's balances that sit on the chain? A chain that can be halted can also alter states at the restart. Whether that happens here has not been announced so far.
What counts for you in this case is above all a question that goes beyond Cronos: how much of your own holdings sits on networks that can be halted by agreement? That is not a matter of guesswork but a property you can look up, and you need no technical knowledge for it.
The block explorer of the chain in question, meaning the public search interface for blocks and transactions, usually carries a validator list. Four data points are enough for an assessment: the number of active validators, whether access is open or permissioned, how much share the largest operators hold between them, and whether the chain has ever been halted before. A double-digit or barely triple-digit validator count with permissioned access means, in practice: this chain can be halted.
No instruction to sell follows from that. What follows is that you know which part of your holdings can become immobile in an emergency, and that you choose that part deliberately rather than by accident.
When you put funds into a lending protocol, you are on the hook for the quality of the collateral that protocol admits, even if you hold none of it yourself. If the proceeds from a piece of collateral are not enough after a collapse to cover the loan, an uncollectible residual claim stays in the system, and that comes at the depositors' expense.
Three data points appear in almost every protocol's documentation and largely answer the question. First, the list of approved collateral together with the loan-to-value ratio: if the protocol's own governance token is on it, that is a warning sign, because its price moves with the protocol's fortunes. Second, the price source: a price that comes from a single thin trading venue is easier to move than a value averaged over time from several sources. Third, the separation of markets: some protocols isolate risky collateral in pots of their own, so that a failure there does not feed through to the remaining depositors.
The case is part of a run that has been going on for weeks. On August 23 it hit Term Finance through voting rights, on August 27 Moonwell through the price source of a thinly traded piece of collateral, on August 30 Tectonic by the same route. The attacks differ in detail but always hit the same spot: the valuation of what is posted as collateral.
A chain halt creates a gap in your records, and that gap catches up with you later, not today. As long as no blocks are being produced, the chain supplies no new data, and portfolio and tax programs that draw their values from there show a frozen state or none at all.
So write down now what cannot be reconstructed later: the time of the halt as you observed it, your positions and open loans as of the last valid block, all project announcements with their dates, and every operation you could not carry out because of the standstill. If compensation follows later, or something is changed at the restart, you will need this starting state to explain the difference.
A note for context, not tax advice: whether a loss from an incident of this kind is recognized for tax purposes, and under which type of income, has to be assessed case by case and belongs in the hands of a tax adviser. What you can contribute is a complete set of records.
Further reading: the write-up by TFTC on the chain halt and Tectonic's share of Cronos DeFi liquidity and the compilation by Blockonomi on the loan-to-value ratio, trading volume and time window of the attack.
(As of August 30, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
When you pay with a crypto card, the money backing that card frequently does not sit in your own wallet. It sits in a separate container operated by the card platform and filled by you when you top up. On August 28, 2026 an attack on exactly such a container showed what that means when things go wrong: users' self-custodied wallets were left untouched, and the loaded card balance was gone.
The provider concerned is not available in Germany. The construction behind it, however, is. This piece places the incident in context, explains the terms and shows you how to tell which custody model your own card uses and who would be responsible in the event of a loss.
Avici is a so-called neobank on the Solana blockchain: an app that attaches a Visa card to an on-chain account of its own. On August 28, 2026 the provider disclosed that there was a problem with card payouts. According to the reconstruction by crypto.news, the first malicious transaction occurred at 16:49:48 UTC, and reporting began in the early evening.
On the provider's account, what was affected was neither the Solana network nor the users' app wallet, but a single smart contract in which the backing for the cards is held. Anyone who left their funds in the app without loading them onto the card stood outside the attack. Anyone who had topped up stood inside it.
On the account given by Cryptopolitan, the attacker exploited the payout logic of the program written in Rust by calling the functions SubmitSignatures, AddCollateralAdmin and WithdrawCollateralAsset one after another. The middle step is the decisive one: with it the attacker entered himself as an authorised administrator of the collateral and could then withdraw what had been deposited through the regular route.
The episode was not a single grab. According to the breakdown Avici published later, the attack series comprised 14,672 transactions, of which 2,344 failed. That points to an automated script working through the contract systematically over hours rather than to a one-off strike.
A card balance contract is a standalone program on a blockchain into which you transfer funds so that a payment card can draw on them. As soon as you top up, the money leaves your wallet and sits in that contract until a card payment is settled or you pull it back.
The difference from a wallet is practical rather than theoretical. Your wallet is protected by a key only you hold. The card contract has an access logic of its own, usually with roles for the operator so that settlement works at all. Whoever defeats that role management reaches the balances of every user without knowing a single private key.
That is exactly what happened at Avici. The app's self-custodied Solana and EVM wallets were left untouched according to the provider. What was attacked was solely the separate contract into which users had transferred funds for the card. The widespread notion that a self-custodial product is automatically self-custodial as a whole does not hold at this point.
Two orders of magnitude are circulating about the scale, and both rest on a traceable basis. On the day of the incident crypto.news counted an outflow of 10,005.03 SOL plus around $11,600 in USDC and USDT, together roughly $1.07 million at the price of the time. Avici itself named 1,685 affected users and $500,859.22 in card balances after its internal reconciliation.
The range of roughly $0.5 million to $1.07 million resolves once you look at the reference quantity. The higher figure measures what flowed out of the contract in assets. The lower one measures how much of that could be assigned to individual customer accounts as card balance. Both figures come from different ways of counting, and neither is the "correct" one in the sense of the other.
For you as a reader the lesson matters more than the exact sum: in the first hours of an incident like this, on-chain estimates and the provider's later reconciliation stand side by side, and they rarely coincide. Anyone making decisions in that phase should know which of the two figures they are looking at.

The name on the card is the app's. Issuing and technical operation are as a rule handled by a specialised card issuer in the background. At Avici that is the firm Rain, which supplies card programmes for companies and maintains contracts of its own on several blockchains for the purpose.
According to the companies involved, Rain located the fault itself and traced it to an outdated version of its Solana contracts, used besides Avici by a small number of other programmes. The company says all deployments still running on that version were subsequently updated and external forensic specialists brought in. Which other programmes were affected, and whether damage arose there, has not been named publicly.
Avici has undertaken to reimburse all affected card balances in full and says it has filed a report with the FBI's Internet Crime Complaint Center. Whether and when reimbursements have actually been made cannot be verified from outside; the undertaking is an announcement by the company rather than an accomplished fact.
On the same day the card programme of the Solana trading platform Jupiter also briefly paused payouts of card balances. The platform explained this as a precautionary measure while its card partner completed security checks of its own, and stated that its own users' accounts and funds had at no point been affected. Payouts then resumed as normal.
This episode is more instructive than it first appears. The brief halt shows that a fault in a shared contract version reaches several card programmes at once, including ones from which nothing ultimately flows out. The card in your hand can come from a provider whose software you never chose.
Such a halt amounts in effect to a temporary block on your card balance. The money is not lost, but it is unavailable for the duration of the check. Anyone parking a whole month's spending on a crypto card notices the difference from a current account in exactly this situation.
For German readers the availability question is the first filter, and it comes out clearly for the two programmes named. Avici's documentation lists 47 territories in which the card can be used, among them countries in Latin America, Africa and Asia and individual US states. Europe, the European Economic Area and Germany appear in neither the permitted nor the prohibited list. The Jupiter card, issued by Rain or by DCS depending on country of residence, likewise does not list the EEA among its supported regions.
The model itself is nevertheless available in Germany. The card from ether.fi, for instance, is also issued through Rain, holds the balance in a smart contract vault controlled by the user, and settles on the Ethereum layer 2 Scroll. The provider's help page lists twenty unsupported countries, among them Estonia, Finland, the Netherlands and Hungary; Germany is not on it. Because this programme does not settle on Solana, it falls outside the contract version at issue in the Avici case.
Anyone looking around this product group finds cards with quite different mechanics side by side. Which models exist and how fees and cashback differ is set out in the overview of crypto credit cards. The custody question is only one of several there, but it is the one that decides responsibility when something goes wrong.
In the EU a payment card with a loaded balance is normally an e-money product. The issuer needs authorisation as an e-money institution for it, must separate customer funds from its own assets and hold them at a bank or in safe investments. Where crypto enters the picture, authorisation as a crypto-asset service provider has been added since the MiCA transition period ended on July 1, 2026.
The difference from deposit protection matters: segregated custody means that customer funds do not fall into the estate if the provider becomes insolvent. It does not mean that a state guarantee scheme steps in for losses, as it does for bank deposits up to 100,000 euros. Advertising for payment cards regularly conflates the two.
If your card balance sits in an on-chain contract instead, this framework does not apply in that form. There is then no custodied customer money at an institution, but assets in a program whose security depends on the code and on its role management. Reimbursement in that case is a matter of goodwill and of the provider's contractual undertaking, as the Avici case shows, and not a matter of supervisory law.

Under the first model you top up a card, your crypto is sold either at top-up or at payment, and what sits on the card is electronic money at a licensed issuer. The provider keeps an account for you, the supervisor watches over the separation of customer funds, and in a dispute you have a named contractual partner holding authorisation.
Under the second model you transfer crypto into a contract that serves as collateral or as the balance for the card. The appeal lies in keeping control for longer and not having to sell assets in order to be able to pay. The price lies in the security of that contract becoming your risk, regardless of how well you look after your own keys.
Hybrid forms exist. Some providers hold the balance in fiat at an institution and additionally let you post crypto as collateral. Others convert only at the moment of payment. Which variant applies is stated in the terms, and reading those repays the effort more than the product description on the home page.
Regardless of the custody model, paying with crypto in Germany has a tax dimension that many discover only at the tax return. If crypto is exchanged into euros at the card payment or at top-up, that is a disposal in the sense of private assets. Whether a taxable gain results depends on the holding period, the acquisition costs and the exemption threshold.
In practice that means a card converting a small amount at every purchase generates many individual events that want documenting. Anyone not recording them continuously faces a reconstruction from bank statements and blockchain data at the end of the year. Models in which you pay against posted collateral instead of selling behave differently for tax purposes; here an assessment of the individual case repays the effort, because it turns on the specific contractual arrangement.
You answer the following questions for your own card from the provider's documents rather than from memory.
First: who issues the card? The terms name an institution with a registered office and an authorisation. If an EEA e-money institution is named there, that points to the first model. If an infrastructure provider without any stated authorisation is named, read on.
Second: what happens when you top up? If your crypto is converted into euros or dollars and carried as a balance, e-money is involved. If it stays as crypto and is described as collateral, you are working with an on-chain contract.
Third: do the terms name a contract with an address? Providers of the second model give the contract address or a vault. That is a reliable identifying mark.
Fourth: how is reimbursement handled when things go wrong? Search the terms for the words liability, reimbursement and exclusion. A provider expressly excluding losses from faults in smart contracts is telling you where your risk lies.
Fifth: how much is on the card at all? A card balance is cash in your jacket pocket and not a portfolio. Loading only the next few weeks' needs limits the possible damage to an amount you can absorb.
If this check brings you up against approvals and signatures you are asked to confirm, read carefully first what you are approving. How to recognise an abusive approval is set out at length in our guide to wallet drainers and signature approvals.
The August 28 incident does not concern you directly as a German card user, because the two programmes named are not available here. The construction that made the damage possible in the first place, however, is also found in cards you can obtain in this country. Three steps take you further:
(As of August 30, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Gabriel Perez used his access to Trump's speeches before delivery to bet on "presidential mention market" contracts, profiting more than $107,500 before the CFTC caught up with him.
The Austin and Kyoto hard forks, deployed quietly on the Bor and Heimdall clients before public disclosure, closed denial-of-service and consensus-hardening flaws that Polygon says were never exploited.
Spot Bitcoin ETFs shed $201.9 million on Aug. 28, ending a nine-day inflow run, even as Ethereum funds extended a 10-day streak with fresh cash.
A Bitcoin rally to around $79,000 lifted the company's 840,447 BTC roughly $2.8 billion above its cost basis, as Saylor's "We're Back" post fueled speculation that Strategy may resume buying.
More than 100 AI, security, finance, and technology organizations want governments and industry to prepare for attacks powered by increasingly capable models.
Shiba Inu isn't ready to give up one of the most important price threshold on the chart.
Ripple is accelerating the expansion of its RLUSD stablecoin, with millions of tokens minted across the XRP Ledger and Ethereum in recent days as the dollar-pegged asset’s total supply climbs above $2 billion.
Market feels stronger than any point in 2026, however, the clear picture is yet to be painted out there.
Ripple Chief Legal Officer Stuart Alderoty has argued that passing the CLARITY Act could boost job creation and economic growth in the United States.
Gold investor and longtime Bitcoin critic Peter Schiff has renewed his criticism of the cryptocurrency.
Space Exploration Technologies Corporation is preparing to deploy its inaugural constellation of artificial intelligence satellites equipped with Nvidia processors in late 2027. CEO Elon Musk revealed the initiative this week, suggesting that processing AI computations in orbital environments may ultimately prove more economical than conventional ground-based infrastructure.
Space Exploration Technologies Corp., SPCX
According to Musk, the space-based computing strategy may also reduce environmental impact compared to traditional data center operations. The executive anticipates the orbital infrastructure will achieve operational scale by 2028.
On Nvidia’s August 26 quarterly earnings conference call, Chief Financial Officer Colette Kress announced that the company’s Vera Rubin computing platform has entered full-scale production. Current shipments are being distributed to Oracle, Amazon, and SpaceX.
The semiconductor manufacturer also revealed its ownership position of 122.8 million shares in SpaceX. This dual arrangement establishes Nvidia as simultaneously a critical hardware provider and significant equity stakeholder in the aerospace company.
Research analysts at Evercore ISI highlighted the reciprocal nature of this partnership. Their analysis identifies SpaceX among the initial adopters of the Vera Rubin computing architecture.
Musk stated that SpaceX facilities will utilize Nvidia hardware exclusively. Separately, SpaceX finalized its $60 billion all-equity purchase of Cursor in August. The artificial intelligence coding platform generates over $1 billion in annualized revenue.
Evercore ISI analyst Kutgun Maral views the orbital computing segment as an emerging growth avenue. However, the investment firm doesn’t anticipate substantial revenue contributions to SpaceX before fiscal 2029 at the earliest.
Evercore’s financial models project the initial 1 gigawatt of space-based computing capacity becoming operational in 2029. The firm forecasts expansion to 8 gigawatts of orbital infrastructure by year-end 2029, alongside 10 gigawatts of ground-based capability.
According to the research note, any acceleration of the 2029 deployment timeline into 2028 would represent significant additional capacity. Musk has referenced cost structures ranging from $30 to $50 per watt for the orbital platforms.
Evercore maintains its Outperform recommendation on SpaceX equity with a $230 valuation target. The consensus analyst target price stands at $228.59, suggesting approximately 61% appreciation potential from present trading levels. Wall Street’s aggregate rating reflects a Moderate Buy, comprising 24 buy recommendations, six hold ratings, and three sell opinions.
The ambitious program confronts substantial technical barriers. Thermal management systems present significantly greater complexity in space environments due to the absence of atmospheric convection for heat dissipation.
Research published by the Brookings Institute calculated that adequate heat rejection from a single orbital data facility could necessitate radiator arrays spanning 2.15 million square feet. This represents a formidable engineering obstacle without established solutions.
Orbital assets also contend with solar radiation exposure and escalating collision risks from space debris. Regulatory clearances may introduce delays as the constellation expands.
The fundamental uncertainty centers on whether SpaceX can transition from an initial demonstration launch in 2027 to a fully functional commercial network in subsequent years.
The post SpaceX and Nvidia Partner on AI-Powered Satellite Network Set for Late 2027 Launch appeared first on Blockonomi.
On August 28, Cathie Wood’s ARK Invest executed a significant rebalancing of its semiconductor holdings, divesting $74.5 million in Advanced Micro Devices shares while simultaneously establishing positions in both Nvidia and Broadcom.
The investment firm liquidated 156,286 AMD shares distributed across its various exchange-traded funds. This transaction represented ARK’s second consecutive day of AMD reduction, having previously sold approximately 37,977 shares valued at $18.26 million on August 27. Despite these sales, AMD stock has climbed 117.4% since the beginning of the year.
Advanced Micro Devices, Inc., AMD
ARK purchased 243,707 Nvidia shares, representing approximately $53 million in value calculated at the August 28 closing price of $217.55. This acquisition occurred one trading session after Nvidia experienced an 8.9% surge on robust quarterly results, subsequently retreating 4.5%.
The chipmaker disclosed fiscal second-quarter revenue reaching $96.2 billion, marking a 106% increase compared to the prior-year period. Adjusted earnings per share totaled $2.22, surpassing analyst expectations of $2.10.
Management provided third-quarter revenue guidance of approximately $108 billion, exceeding the consensus estimate of $104.19 billion from Wall Street analysts. Nvidia’s chief financial officer indicated the company anticipates roughly 70% revenue expansion through fiscal 2028.
Following the earnings release, multiple Wall Street analysts elevated their price objectives. JPMorgan increased its target from $280 to $320. Bank of America maintained its buy recommendation with a $350 price target, designating Nvidia as a preferred selection. Melius Research established the Street’s highest target at $420.
Nvidia shares have appreciated approximately 16.6% year to date.
ARK simultaneously acquired 55,131 Broadcom shares totaling $20.5 million in value. This transaction followed an earlier Broadcom purchase executed during the same week.
Broadcom is scheduled to announce its fiscal third-quarter financial performance after trading concludes on September 3. Analyst consensus projects revenue of $29.24 billion, reflecting 83.3% year-over-year expansion, alongside adjusted earnings per share of $3.21.
Benchmark analyst Cody Acree maintained his buy rating and $545 price objective on Broadcom shares. He observed that the stock currently trades at the lower end of its artificial intelligence peer group based on valuation metrics and characterized it as an improved opportunity following a 13% decline after its second-quarter announcement.
Broadcom stock has gained 6.6% year to date.
Wood continues to express conviction regarding artificial intelligence’s contribution to enhanced corporate profitability and operational efficiency. She has articulated that organizations embracing AI technology will distinguish themselves from competitors who remain hesitant.
Notwithstanding this bullish outlook, the Ark Innovation ETF has generated a five-year annualized return of -6.91% through August 28, substantially underperforming the S&P 500’s 11.33% gain. The fund experienced approximately $2.09 billion in net outflows throughout the preceding 12-month period.
The flagship Ark Innovation ETF has advanced 9.97% year to date, lagging the S&P 500’s 12.65% appreciation during the identical timeframe.
The post ARK Invest Exits AMD Position, Doubles Down on Nvidia (NVDA) and Broadcom (AVGO) appeared first on Blockonomi.
Shares of Meta (META) gained 1.21% as new revelations emerged about the company’s controversial workforce transformation initiative, pending litigation, and mounting concerns over return on massive AI investments.
Meta Platforms, Inc., META
On August 26, Reuters released an extensive investigation drawing from confidential company documents and interviews with over 20 sources, exposing the complete picture of Meta’s behind-the-scenes workforce strategy.
The initiative bore the code name Project OT, representing Organization Transformation. Conceived during Meta’s January leadership summit at Zuckerberg’s Hawaiian estate, the program aimed to transform Meta into an “AI native” organization where artificial intelligence agents would assume responsibilities currently handled by human staff.
During strategic planning sessions, leadership contemplated workforce reductions reaching 60% in select departments. The overhaul was designed to unfold across two phases, with phase one launching May 20 and a subsequent phase scheduled for November targeting additional positions.
At that juncture, Meta employed approximately 79,000 people. A 20% reduction would have meant eliminating close to 16,000 positions.
Just hours before the initial round of terminations on May 19, Zuckerberg reversed his decision. Meta proceeded with the 10% workforce reduction the following morning, affecting roughly 8,000 employees, but completely abandoned the planned November phase.
Zuckerberg subsequently assured staff members he did “not expect other company-wide layoffs this year.”
The abrupt change of direction occurred as internal metrics cast doubt on the effectiveness of the AI implementation. While code generation utilizing AI platforms increased 220% year-over-year, modifications producing new or enhanced features visible to end users grew merely 36%.
Security breaches and technical malfunctions, encompassing service outages and potential data compromises, escalated 40% compared to the previous year. Employee hours dedicated to resolving these issues climbed 70%.
Staff resistance was also mounting. Meta had deployed monitoring software on U.S. employees’ computers to record keystrokes and cursor movements, with the goal of training AI agents to mimic human work patterns. Numerous workers concluded they were essentially training their own replacements.
Employee satisfaction plummeted from 74% positive to 55% positive in Meta’s biannual Pulse survey.
A distinct lawsuit initiated in July alleges Meta utilized AI-driven systems to pinpoint and terminate employees who were on medical absence or taking leave to care for family members.
Meta rejected the allegations, declaring that “workforce management and organizational decisions were and are made by people, not AI.”
Employment attorneys cited in Forbes indicated the case may depend on whether Meta’s selection methodology disproportionately impacted employees on leave, and observed that California and New York, where affected employees work, both maintain robust employment protections.
Meta acknowledged Project OT’s existence, characterizing it as a cost-reduction and reorganization initiative. The company clarified it never planned to eliminate 60% of its total workforce, and that multiple major divisions were excluded from the program.
During an internal all-hands meeting in early July, Zuckerberg admitted that AI agent technology had not “accelerated” at the pace he anticipated, though he projected significant advancements within the following three to six months.
Meta intends to commit at least $130 billion to AI processors and infrastructure throughout 2026. Financial analysts predict this expenditure will absorb the company’s complete operating cash for that fiscal year.
META stock was up 1.21% when this report was published.
The post Meta (META) Stock: How Internal AI Rebellion Stopped Zuckerberg’s Mass Layoff Plan appeared first on Blockonomi.
Two major music publishing powerhouses, Sony Music Publishing and Warner Chappell Music, have initiated legal proceedings against Anthropic, the artificial intelligence firm responsible for the Claude chatbot, claiming the company utilized thousands of protected musical works without authorization during AI model development.
The legal complaint was submitted Friday to a federal court in Northern California. Anthropic co-founders Dario Amodei and Benjamin Mann were identified as defendants along with the corporation.
According to the publishers, Anthropic conducted a “brazen campaign of illegally torrenting, scraping, and downloading copyrighted works on a massive scale.” The legal filing identifies popular compositions such as “Eye of the Tiger,” Marvin Gaye’s “Ain’t No Mountain High Enough,” Mariah Carey’s holiday classic “All I Want for Christmas is You,” and Taylor Swift’s “Paper Rings.”
Additional works mentioned in the complaint include “Livin’ On a Prayer,” “September,” “Great Balls of Fire,” “Ramblin’ Man,” and “Hallelujah.”
The legal action alleges that Anthropic obtained portions of this content via two unauthorized digital repositories: Library Genesis and Pirate Library Mirror. These platforms housed literary works containing song lyrics and musical notations.
This allegation builds on a June 2025 judicial determination that established Anthropic had acquired over 7 million unlicensed books from these identical sources. While a judge subsequently determined that utilizing copyrighted literature for AI training constituted fair use, Anthropic ultimately paid more than $1.5 billion to resolve a separate class-action claim brought by authors regarding pirated materials.
Sony and Warner Chappell contend that Claude possesses the capability to generate copyrighted lyrics when responding to user queries. They assert this functionality could enable the AI system to substitute for authorized lyric platforms and damage the commercial market for human-generated musical content.
The publishing houses are requesting a jury trial along with statutory damages totaling up to $150,000 for every composition Anthropic purportedly misappropriated.
Anthropic has disputed the accusations. “We disagree with the publishers’ claims and we intend to defend ourselves robustly in court,” a company representative stated.
This legal challenge represents not Anthropic’s initial encounter with music copyright disputes. A 2023 legal action from Universal Music Group, Concord Music Group, and ABKCO led to court-sanctioned restrictions mandating that Anthropic prevent Claude from generating copyrighted lyrics in user interactions.
Sony Music Publishing operates as a division of Sony Group Corp. Warner Chappell functions as a subsidiary of Warner Music Group.
Anthropic recently disclosed preliminary second-quarter revenue exceeding $11.5 billion, representing a more than 14-fold increase compared to the corresponding period in the previous year. The organization also achieved its initial positive adjusted operating income as it considers a potential public offering.
The post Major Music Publishers Target Anthropic in Copyright Infringement Lawsuit Over Claude AI Training appeared first on Blockonomi.
South Korean memory chip manufacturer SK Hynix is evaluating a possible collaborative venture to establish a semiconductor production facility in Japan, signaling the company’s commitment to expanding manufacturing capabilities in response to increasing artificial intelligence demands.
SK hynix Inc., SKHY
Chairman Chey Tae-won of SK Group acknowledged the ongoing discussions during meetings between business organizations from South Korea and Japan held in Sendai. The company has not finalized decisions regarding the specific location, investment amount, or potential partnership arrangements.
“We are looking all over Japan,” Chey said. “Anywhere with good power and good water.”
This Japanese expansion consideration represents one component of SK Hynix’s comprehensive strategy to enhance worldwide manufacturing capacity. The chipmaker recently commenced construction of a chip packaging operation in West Lafayette, Indiana, while simultaneously planning a substantial 54 trillion won ($39 billion) investment to expand its South Korean manufacturing infrastructure.
Miyagi Prefecture officials in Japan are mounting an intensive campaign to secure the manufacturing facility, proposing a 300,000-square-meter location complemented by enhanced water and electrical infrastructure specifically designed for semiconductor manufacturing operations.
Tokyo has demonstrated strong commitment to providing substantial financial incentives for international semiconductor manufacturers. Taiwan Semiconductor Manufacturing Co. has previously received such support, positioning SK Hynix as a potential candidate for similar benefits.
Competing memory chip producer Micron Technology currently maintains production facilities in Hiroshima. Additionally, Japan hosts numerous SK Hynix supply chain partners, including Tokyo Electron, along with major customers such as Sony and Nintendo.
SK Hynix maintains an indirect ownership position in Kioxia Holdings, the Japanese flash memory manufacturer based in Tokyo. CEO Kwak Noh-jung recently indicated that SK Hynix is “carefully looking at how we can co-develop the NAND flash market with our customers and suppliers.”
Demand for both high-bandwidth memory products and NAND flash storage has experienced substantial growth as technology giants including Meta and Amazon expand data storage capabilities to support artificial intelligence computing requirements.
SK Hynix manufactures critical components utilized in Nvidia’s artificial intelligence processors, establishing the company as a crucial supplier in the ongoing AI infrastructure expansion.
Company executives anticipate that worldwide memory chip supply limitations will extend through 2030, making production capacity enhancement a strategic imperative for the foreseeable future.
Chey also used the Sendai meetings to make a broader point about regional economic cooperation. “Now is the time for Korea and Japan to form an economic bloc,” he said at an event focused on the two countries’ shrinking workforces.
The company has not announced a specific timeframe for reaching a final determination on the Japanese manufacturing venture.
The post SK Hynix (SKHY) Explores Japanese Manufacturing Partnership to Boost Memory Chip Production appeared first on Blockonomi.
HTTP error 429 on https://cryptopotato.com/feed/
Failed to fetch feed.