The negative premium period on the US-based cryptocurrency exchange Coinbase, caused by the Bitcoin price falling below Binance’s, has reached its longest period to date.
According to CoinGlass data, the Coinbase Bitcoin Premium Index remained in negative territory for 75 consecutive days between May 19 and August 1. The index’s final value was recorded at -0.0959%, marking the longest period of negative premium seen since the indicator’s inception.
The previous record was a 40-day streak of negative premium recorded between January 16 and February 24. The current period also significantly surpassed the approximately 30-day period of negative premium seen during the “October 10 crash” last year.
Related NewsFive Major New Features Are Coming to XRP—Ripple Official Reveals
The Coinbase Bitcoin Premium Index measures the difference between Bitcoin prices on Coinbase Pro and Binance. An index that remains in negative territory for an extended period indicates that the Bitcoin price on Coinbase is lower than on Binance. This typically signals weakening buying pressure or increasing selling pressure in the US market.
However, concluding that US institutional investors are exiting Bitcoin or that there is capital outflow from the country based solely on this indicator is not considered accurate. The index can also be affected by market liquidity, trading hours, investor profiles, and regional demand differences between exchanges.
More than 1,000 bitcoin, worth about $70 million, was drained from 1,196 wallets in a 41-minute window on July 30, nearly double the amount reported when the theft first surfaced.
Galaxy Research mapped the full event on Friday, finding 1,082.65 BTC swept between 01:10 and 01:51 UTC across six blocks, with three intervening blocks containing nothing, which suggests the transactions were broadcast in batches rather than continuously.
The proceeds sit in four addresses and have not moved. Early reporting captured only one of those addresses, which is why the figure has grown.
The size of the attack is much smaller than some of the bigger attacks this year, but the mechanism is what makes this unusually — and why the attack is such a big deal.
Why the Coldcard wallet exploit is a bigger deal than most exploits
Most crypto theft involves getting to something. An exchange is breached, a contract is tricked, a key is phished off a laptop. The defence has always been distance, which is precisely what a hardware wallet sells. Keep the key on a device that never connects to the internet and, theoretically, there is nothing for an attacker to touch.
Most crypto thefts require reaching the key. This one rebuilt it. (Shaurya Malwa/CoinDesk)
When a wallet is created, the device is supposed to pick a number so large and so unpredictable that guessing it is impossible.
Validators (entities that supply their resources to run and maintain a network) were advised to reject it, and an emergency server release marked it unsupported to prevent activation. No funds were lost, because it never reached the main network.
Permission Delegation, which lets an institution grant another account narrowly scoped authority without handing over full signing power, was disclosed as vulnerable in September 2025 and disabled.
The bug allowed one account to charge transaction fees to another and potentially drain its balance. The ledger’s documentation has listed both amendments as obsolete since, to be replaced by revised versions.
(Shaurya Malwa/CoinDesk)
The other three are new. Confidential MPT combines zero-knowledge proofs, which let someone prove a statement is true without revealing the underlying data, with elliptic-curve encryption, so that balances and transfer amounts on Multi-Purpose
Tokens stay private while auditors or regulators can still verify them when required.
Sponsored Fees and Reserves lets a bank or platform cover another account’s $XRP fees and reserve requirement, removing the need for every user to acquire $XRP before transacting.
Lastly, Dynamic MPT lets an issuer specify at creation which token properties can be changed later, avoiding a full migration to a new token when fees or metadata need updating.
Ripple’s Head of Product, Jazzi Cooper, announced five new updates that could significantly expand the use of the $XRP Ledger in institutional finance and tokenized asset markets. These features are planned for release in xrpld 3.3.0, expected next week.
Cooper stated that XRPL has already proven its ability to support tokenized assets on a large scale, and the next step is to utilize these assets more effectively in global transfers, trading, collateralization, and settlement transactions.
The first modification to be included in the new version, “Confidential MPT,” will provide native privacy features to Multi-Purpose Tokens on XRPL through zero-knowledge proofs and elliptic curve cryptography. This system will allow token balances and transaction amounts to be kept private on the public ledger. However, authorized parties, such as auditors or regulators, will be able to verify transaction details when necessary.
The “Batch” feature will allow up to eight transactions between different accounts to be executed atomically in a single ledger entry. All transactions will either be successful or none will occur. This structure is expected to facilitate corporate finance applications, particularly those involving payment-for-delivery and atomic reconciliation.
Related NewsHas Bitcoin Hit Bottom, or Is a Shakeout on the Way? What About $XRP?
The “Delegation of Authority” arrangement will allow institutions to define limited transaction permissions without transferring full control over private keys. This means that treasury teams will continue to control asset issuance keys, while trading desks or operations teams will be able to perform specific transactions within defined limits.
With the “Sponsored Fees and Reserves” feature, banks, token issuers, or platforms will be able to cover other users’ $XRP transaction fees and account reserves. Users will retain ownership of their accounts and private keys, eliminating the need to purchase and manage $XRP before joining the network. Ripple believes this feature will improve the user experience in both enterprise and consumer-focused applications.
Finally, the “Dynamic MPT” regulation will allow token issuers to update transaction fees, metadata, and other specific features after the token is created. Under the current system, such changes may require the issuance of a new token and the migration of users to the new asset. With the new feature, issuers will be able to predetermine which features can be changed in the future during the token creation phase.
Cooper added that version 3.3.0 of xrpld is expected to be released next week, but these changes will not be automatically activated. The updates will need to be verified by validators before they can be activated on the $XRP Ledger.
After several days of high activity, on-chain data indicates that Shiba Inu’s exchange flow dynamics have changed once more, with netflows returning to almost neutral territory. After last week’s dramatic fluctuations, the most recent metrics show a net exchange flow of roughly -2.31 billion $SHIB over the previous 24 hours, indicating that inflows and outflows are now mostly balanced. A negative netflow indicates that slightly more tokens are leaving exchanges than are entering.
Shiba Inu moving between exchanges
In comparison to the trillions of $SHIB that frequently shift between exchanges during times of increased volatility, a figure of -2.3 billion $SHIB may seem insignificant. The most recent reading indicates that the market is entering a phase of consolidation rather than aggressive accumulation or heavy distribution.
Additional on-chain indicators corroborate that interpretation. At about 86.99 trillion $SHIB, exchange reserves are essentially unchanged, suggesting that the total quantity of tokens held on centralized exchanges has stabilized. The seven-day average of exchange outflows decreased by 16.6 percent, while exchange inflows increased slightly by 0.65%, indicating that the withdrawal wave that was observed earlier this week has begun to subside.
$SHIB/USDT Chart by TradingView
Despite the slowdown in exchange movements, network activity is still comparatively strong. Active receiving addresses increased by 0.86% over the previous day, while active addresses increased by 0.81%. Additionally, there was a slight increase in the number of transactions, indicating that users are still using the network despite the decline in speculative trading. Technically speaking, $SHIB is trying to stabilize following its dramatic rally and the decline last week.
At $0.00000465, the token is currently trading well above the 50-day and 100-day moving averages. After months of consistent weakness, those indicators have now started to function as close support. The 200-day moving average around $0.00000598 remains the main barrier, however.
Shiba Inu’s comfort zone
During its recent breakout, $SHIB came close to the larger resistance zone around $0.00000500, but it was unable to sustain momentum, which led to profit-taking and a return to moving-average support.
After momentarily going into overbought territory during the rally, the Relative Strength Index has also returned to normal. The RSI, which is currently in the mid-50s, indicates that momentum has cooled without turning bearish, opening the door for another attempt to rise if buying pressure resumes. As of right now, neutral exchange netflows show that neither buyers nor sellers have established a clear advantage.
The argument for fresh accumulation would be strengthened if exchange reserves started to fall while net outflows started to rise once more. On the other hand, increasing inflows combined with declining price action may indicate that more holders are getting ready to sell.
Both on-chain metrics and the technical picture point to consolidation rather than a clear directional shift, suggesting that $SHIB is currently consolidating its recent gains rather than starting a new trend.
Pi Network [PI] has been in a relentless downtrend since April 2025. The altcoin has made successive lower highs and lower lows on the longer-term price charts. Any bounces the bulls were able to enforce, such as the one in March 2026 that nearly reached $0.30, were unable to establish a bullish structure.
On July 19, the token saw yet another short-term bounce that reached a high of $0.104. It turned out to be a sweep of the liquidity clustered around the $0.10 round-number resistance.
PI crypto value has slid by nearly 21% in the two weeks since then. The Pi Network’s protocol v25 upgrade would improve stability and also bring BN254 cryptography and Poseidon hashing.
A liquidity pool containing SLICE and Test-Pi was launched recently. This test launch uses an automated market maker alongside the Pi DEX order book.
Over the past three days, from the 28th to the 30th, the token rallied by 7.1%.
Will this bounce result in further PI crypto value drawdown?
Source: PI/$USDT on TradingView
The $0.13 low from February was breached, and a new swing low at $0.07 has been established. The technical indicators on the 1-day chart were firmly in favor of the sellers.
The OBV has been trending lower throughout 2026. The CMF fell below -0.05 earlier in July to signal increased selling pressure on the token. Only recently did the indicator climb back into neutral territory.
The RSI was at 37 and has been below neutral 50 since May. Once again, it indicated dominant bearish momentum.
Traders’ call to action- There is potential for a bounce
Source: PI/$USDT on TradingView
The 4-hour swing structure was also bearish. The golden pocket, according to the Fibonacci retracement levels, was at $0.113-$0.124. Unfortunately for the buyers, an attempt to climb above the psychological $0.10 barrier was firmly refuted earlier this month.
In the short-term, the $0.083-$0.085 area must be flipped to support to give bulls hope of a resurgence.
Unless there is renewed demand for PI, further downside would be likely. A bounce toward $0.10-$0.125 would offer a selling opportunity to swing traders.
Final Summary
The PI crypto value saw a 7% bounce from the week’s low at $0.073.
The technical indicators showed sellers were dominant, and a sizeable PI bounce does not appear likely in the coming days.
The SEC has delivered an unusually blunt ultimatum to lawmakers: if the CLARITY Act stalls, the agency will write its own crypto market rules. The statement, flagged in the latest weekly roundup, injects fresh unpredictability into a regulatory process that already faces heavy bank lobbying. The warning came during a week that also saw Morgan Stanley launch spot Ethereum and Solana exchange-traded products and BNY Mellon move fund recordkeeping on-chain.
The SEC’s posture effectively raises the stakes on a bill that has been teetering in the Senate. With less than four days before a scheduled vote, major banking interests have been pushing to weaken or stall the legislation, as detailed in reports on the bank lobbying effort. The agency’s willingness to act unilaterally signals that senior officials do not intend to leave the market in a regulatory vacuum, even if Congress fails.
Morgan Stanley Opens Spot ETPs on Two Chains
On the product side, Morgan Stanley’s decision to list spot ETH and Solana ETPs marks a notable expansion beyond Bitcoin. While Bitcoin spot ETPs have been available in the US since early 2024, Ethereum and Solana products represent a deeper push into programmable blockchain exposure. The launch comes as traditional asset managers continue to test institutional appetite for multi-asset crypto baskets.
Solana’s inclusion is particularly striking. The network has drawn attention for its high throughput and growing developer base, but it has also faced outage concerns and regulatory ambiguity. Morgan Stanley’s move suggests that the bank’s wealth management clients are interested in exposure that goes beyond the largest market cap assets.
BNY Mellon Goes On-Chain for Fund Recordkeeping
BNY Mellon’s decision to shift part of its fund recordkeeping infrastructure on-chain reflects a different kind of institutional conviction. Rather than creating a new product for clients, the custody giant is integrating blockchain into its own back-office operations. The move mirrors a broader tokenization trend that accelerated this week, with total real-world assets on-chain crossing $20 billion, as covered in a recent tokenization roundup.
When a 240-year-old bank begins migrating internal processes to distributed ledgers, the signal is harder to dismiss than a press release. It suggests that cost savings and settlement efficiency are being tested inside regulated workflows, not just in startup sandboxes.
Strategy Posts a Heavy Loss While Holding Nearly 844,000 $BTC
Not every piece of institutional news pointed upward. Strategy—formerly MicroStrategy—reported an $8.22 billion second-quarter loss. The company continues to hold approximately 844,000 $BTC, making it the largest corporate bitcoin holder. The loss stems from an impairment charge driven by bitcoin’s price decline during the quarter.
The result underscores how deeply Strategy’s balance sheet is tied to spot bitcoin movements. While its conviction thesis remains unchanged, the volatility creates a unique risk profile for equity holders. The episode may also influence how other publicly traded firms approach bitcoin treasury strategies going forward.
Digital Asset Treasuries Pivot Toward AI Infrastructure
Separately, a cluster of digital asset treasury firms is quietly shifting capital from pure crypto holdings into AI data centers. The pivot reflects a search for yield-generating physical infrastructure at a time when holding digital assets on balance sheets carries significant mark-to-market risk. Several firms are repurposing mining facilities or building new capacity tailored for AI compute workloads, a trend that intersects with growing demand for decentralized storage solutions like those examined in a Filecoin price prediction analysis.
What unites these developments is a market moving on two tracks simultaneously. On one track, regulators are signaling they will tighten oversight with or without Congress. On the other, established financial institutions are embedding blockchain infrastructure deeper into their operations, while corporate treasuries adapt to the realities of holding volatile digital assets. The coming weeks will test whether that dual pressure reshapes market structure faster than Washington can legislate.
According to a deep analysis from Galaxy Research, the core theft unfolded in a tightly coordinated burst lasting about 25 minutes, while broader analysis later connected roughly 1,196 addresses and as much as 1,083 bitcoin, valued at nearly $70 million, to activity spanning approximately 41 minutes. The final figures could change as investigators continue tracing transactions on the public Bitcoin blockchain.
A 5-Year-Old Bug Reaches Bitcoin Wallets Worldwide
The affected wallets belonged largely to long-term holders who generated their recovery seeds using Coldcard devices running vulnerable firmware released from March 2021 onward. Coldcard is an air-gapped hardware wallet made by Canadian manufacturer Coinkite and designed to keep bitcoin (BTC) keys isolated from internet-connected devices.
Many of the emptied addresses had remained dormant for years. The attacker moved rapidly, paid elevated fixed transaction fees, and left no change outputs, meaning each address was emptied completely. That pattern suggested an automated operation using a prepared list of private keys rather than customers independently moving their funds.
The theft was not caused by phishing, malware on a user’s computer, physical device theft or a conventional remote breach. Instead, a firmware error weakened the randomness used when some Coldcard devices created wallet seeds. Those seeds looked normal but came from a far smaller range of possible combinations than users had been promised.
Coldcard’s Random Number Generator Quietly Failed
A Bitcoin wallet seed is a secret, commonly displayed as 12 or 24 words, from which the wallet generates its addresses and private keys. A properly generated 12-word seed contains 128 bits of entropy, a technical measure describing an enormous number of possible combinations that makes guessing the seed effectively impossible.
Coldcard devices were supposed to obtain that randomness from a hardware random number generator inside the device’s microcontroller. The component draws from physical electrical noise that an outside observer should not be able to predict.
During a software-library migration in 2021, however, Coinkite disclosed that two random-number functions with matching interfaces became confused. One accessed the device’s proper hardware generator. The other was a weak software fallback intended for boards without suitable hardware.
A configuration setting disabled the default MicroPython hardware path because Coinkite supplied its own hardware wrapper. The software checked only whether that setting existed, not whether it was enabled. Because the setting was present but assigned a value of zero, the build completed successfully, while seed generation silently shifted to the weaker software generator.
Factory Data and Timing Replaced True Randomness
That fallback relied heavily on predictable device information, including a chip identifier similar to a serial number and internal clock values associated with startup timing. An attacker who could narrow those inputs would face a much smaller search than the 128-bit range expected from a securely generated seed.
Coinkite estimated the effective search space for vulnerable Mk3 seeds at about 40 bits under current assumptions. That is still a large number of possibilities, but it can be searched with specialized computing equipment, especially when an attacker can compare candidate seeds against bitcoin addresses visible on the blockchain.
Snapshot of the Coldcard Mk3 model.
Later Coldcard models, including the Mk4, Q and Mk5, added some randomness from a secure element. However, only a limited portion reached the affected generator, leaving an estimated 72 bits of effective entropy on seeds created before corrected firmware was installed. That was stronger than the Mk3 path but still below the intended 128-bit standard.
The difference is similar to replacing a truly random lock combination with one derived from a lock’s serial number and the time it was first switched on. The resulting combination may look random, but someone who knows the formula and can estimate the starting information can reproduce it. Many users are migrating, not only from Mk3 devices, but from Mk4, Q, and Mk5 as well.
Coinkite Tells Users to Create Entirely New Seeds
Coinkite released security advisories and corrected firmware after becoming aware of the active threat. The company said users who generated seeds on affected firmware should create a completely new seed using a fixed version and transfer their bitcoin to addresses controlled by that seed.
Installing the update alone is not enough. A seed created under the flawed system remains weak permanently because the firmware update cannot add randomness to words that already exist.
Coinkite advised users to update their device, create a new seed, verify the backup and wallet fingerprint, confirm the receiving address, send a small test transaction, and then move the remaining balance. Users should retain the old backup until the transfer is confirmed, but should no longer treat the old seed as secure.
The company identified fixed releases including Mk3 version 4.2.0 or later, Mk4 and Mk5 version 5.6.0 or later, and Q version 1.5.0Q or later, along with corresponding Edge versions. Tapsigner, Opendime, and Satscard products use different code and were reportedly not affected.
Added Security Protected Some Coldcard Owners
Users who added enough independent dice rolls when generating a seed were substantially protected because their own randomness overwhelmed the defective software input. Coinkite said at least 50 private rolls of a fair die provided adequate protection from this issue, though additional rolls can provide a wider safety margin.
A strong BIP-39 passphrase also creates a separate wallet that cannot be reconstructed from the seed words alone. Multi-signature wallets, which require keys from multiple devices or locations before bitcoin can move, were largely or fully protected when the vulnerable Coldcard seed represented only one part of the signing arrangement.
Those safeguards were optional, however. Many victims appear to have followed the standard security advice available at the time: Buy a respected hardware wallet, generate the seed offline, protect the backup, and never enter it into an internet-connected device.
Coinkite Accepts Blame as Debate Turns to AI
Coinkite CEO Rodolfo Novak, widely known as NVK, apologized publicly on July 31 and said the company accepted full responsibility for the firmware failure. “I’m sorry and I’m devastated. Our team is heartbroken about yesterday’s news,” Novak wrote. He acknowledged that the hotfix secures newly created seeds but cannot repair seeds generated under vulnerable software.
Coinkite CEO Rodolfo Novak’s apology article. Image source: X.
Novak explained that Coinkite would publish a full technical account after verifying the details and assist affected users seeking police reports, insurance claims or independent investigations. He also warned developers that artificial intelligence (AI) tools can now scan old public code for hidden weaknesses faster than traditional review processes may detect them.
Coinkite stressed it must assume an attacker used AI to inspect its open-source firmware, though no evidence has established how the flaw was discovered. The company also acknowledged that a recent review performed with a leading AI model failed to identify the problem. Several competitor hardware wallet manufacturers have taken to social media to note that their products are not affected.
“Ledger is not affected by the recently published Coldcard Mk3 advisory,” the company told X users after the Coldcard incident. “Ledger devices use a certified True Random Number Generator (TRNG) built directly into our Secure Element chip, generating full 256 bits of entropy for every 24-word Secret Recovery Phrase.”
“Trezor users: your funds are safe,” the hardware wallet maker Trezor explained on Friday. “The recent Coldcard issue is limited to their own custom firmware and how some of their devices generated randomness. Trezor does not share that code.”
The Trezor X account added:
“We have always mixed multiple independent sources of randomness together (device hardware + host + secure elements on newer models). We are truly sorry for everyone who has lost bitcoin.”
What Coldcard Users Should Watch Next
The attacker’s identity remains unknown, and the stolen bitcoin could move from its consolidation addresses at any time. Investigators are still working to determine how many vulnerable seeds were actually generated, how much bitcoin remains exposed, and whether additional high-value wallets have already been identified by the attacker. However, Coinkite may not have much info on owners from long ago.
“Fun double-edged sword: Coinkite purges all their customer records after 120 days to protect against data breaches,” the co-founder of Casa, Jameson Lopp, reported on X. “Which means they are unable to reach out to customers who bought vulnerable coldcards over the past 5 years to warn them of this vulnerability.”
The pseudonymous open-source bitcoin developer dubbed calle shared thoughts on the matter. “I am truly saddened for everyone affected, especially those who may have just lost their life savings. The worst part is that they did everything right,” calle said on X.
The incident will also test whether Coinkite can restore confidence in Coldcard and whether hardware-wallet makers adopt stronger independent reviews of seed generation. For users, the immediate priority is simpler: Anyone who created a seed on affected firmware without strong independent dice entropy, a passphrase, or multisignature protection should treat it as compromised and move funds carefully to a newly generated wallet.
Beyond the devastating theft, bitcoiners across the community are sounding the alarm and pushing others to spread the word before more vulnerable wallets are emptied.