Category: Business

  • Metaplanet CEO shuts down Bitcoin sale speculation after $322M transfer

    Metaplanet CEO Simon Gerovich has shut down speculation that the Japanese Bitcoin treasury company was selling its holdings.

    “This was a routine custody operation. No bitcoin was sold, and our holdings remain 43,000 $BTC,” Gerovich said Thursday.

    The company transferred 5,014 $BTC ($322 million) over a 24-hour span starting Wednesday. Gerovich said the network fees to move the trove cost Metaplanet about $8.

    Metaplanet is the third-largest publicly traded Bitcoin treasury company and the largest in Asia. According to Arkham data, it is sitting on an unrealized loss of about $1.4 billion.

    Metaplanet has continued to expand its Bitcoin strategy beyond accumulation. In March, the company established Metaplanet Ventures, pledging 4 billion yen ($25 million) over two to three years to invest in Bitcoin and crypto infrastructure in Japan.

    The company is targeting holdings of 100,000 $BTC by the end of 2026 and 210,000 $BTC by the end of 2027.

  • Harmony’s ONE Sinks 37% After Attacker Mints 4 Billion Tokens

    Harmony’s ONE Sinks 37% After Attacker Mints 4 Billion Tokens

    In brief

    • Harmony confirmed an exploit after an analyst reported that an attacker minted about 4 billion ONE, roughly 26% of the supply.
    • Around 97% of those tokens have already reached exchanges, on-chain analyst Juiceberg said.
    • ONE was trading at about $0.00077, down 37% on the day, after Harmony shipped a patch to stop further minting.

    Layer-1 blockchain Harmony has confirmed it was exploited after an attacker minted roughly 4 billion ONE tokens without authorisation, sending the token down 37% to about $0.00077, per CoinGecko data.

    On-chain analyst Juiceberg flagged the mint early Wednesday, putting it at close to 4 billion tokens, or about 26% of the supply, and saying the tokens had been created through empty blocks. Around 2.8 billion were funnelled onto exchanges as the price fell.

    In a follow-up tweet, the analyst said the attacker had roughly 115 million ONE left to sell on-chain, about 2.9% of the total minted. “The overwhelming majority (~97%) is already on exchanges,” Juiceberg wrote, and had either been sold or was sitting in deposit wallets.

    Harmony responded in a tweet that it was “working with our team and appropriate exchanges to stop and freeze the funds,” adding that it was preparing a patch and weighing rollback options. In a second post it named four wallets, each listed in both Harmony and hex formats, and asked exchanges to block anything traced to them.

    Just over two hours after that first statement it paused its bridge, then released a patch a minute later, telling validators to upgrade to a build it said prevents any further minting. Dealing with the tokens already created would take another update, it said. Five hours had passed since Juiceberg’s first post.

    The project has not disclosed the vulnerability, confirmed how many tokens were created, or said how much reached exchanges. One oddity Juiceberg noted is that Harmony’s totalSupply endpoint did not reflect the new tokens, and price trackers still list circulating supply at about 14.87 billion.

    Rolling back the chain

    A rollback would return the network to a state before the exploit and continue from there, erasing what followed from the accepted history. That cuts both ways, since transactions made by ordinary users after the attack would go with it.

    Harmony has been here before, with hackers draining about $100 million from its Horizon cross-chain bridge in June 2022, in an attack the FBI later attributed to North Korea’s Lazarus Group.

    The project’s first proposal to the 2022 hack was to reimburse victims in ONE, which would have meant minting billions of new tokens on top of the circulating supply and hard-forking the chain to allow it. The plan drew enough criticism that the team replaced it with one funded from its treasury. Four years on, an attacker has minted a comparable amount without asking.

    ONE now carries a market capitalisation of about $11.5 million, ranking it outside the top 1,000 tokens. It last traded near its October 2021 record of $0.38 more than four years ago, and is down more than 99% from that level.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • Bank of England to test stablecoin, digital currency use in cross-border finance

    Bank of England to test stablecoin, digital currency use in cross-border finance

    “If these processes can become faster and more efficient, U.K. businesses could unlock working capital sooner and make it easier to finance international trade,” Jacobsson said in an interview over LinkedIn.

    The BOE named NOBO Finance, Dun & Bradstreet, a global provider of business decisioning data, analytics, and credit-rating services, and Polygon Labs, a software and blockchain company, as participants in its Digital Pound Lab.

    The project will be the first time the Digital Pound Lab tests how public stablecoins and central-bank money work in a single payment flow alongside a portable credit identity for small businesses. The lab uses no real customers or money and does not signal any decision to issue a digital pound.

    NOBO, a U.K.-based fintech building digital trade finance infrastructure that helps small and medium-sized enterprises (SMEs) become visible, verifiable, and bankable, was already involved in Phase 1. During the first phase, NOBO helped demonstrate conditional business-to-business escrow payments relevant to trade finance workflows.

    A first workstream will build an SME “bankable profile.” NOBO, Dun & Bradstreet and Polygon plan to combine wallet transaction data, open-finance information and business intelligence to create a reusable credit assessment. Polygon will provide smart contracts intended to record the verified outcome and manage consent.

  • Alameda Research, a Cryptocurrency Company, Makes a Notable Move in Solana Staking! Is a Sell-Off Coming? Here Are the Details

    Alameda Research, a Cryptocurrency Company, Makes a Notable Move in Solana Staking! Is a Sell-Off Coming? Here Are the Details

    Alameda Research, the cryptocurrency arm of the bankrupt FTX, has moved a significant amount of Solana ($SOL) holdings again after nearly five years. According to information reported by the on-chain data platform Onchain Lens, Alameda unlocked 201,740 $SOL, removing it from its staking position, and then transferred a total of 201,780 $SOL to a BitGo-owned custodial wallet.

    The transfer has reinforced expectations that Alameda is preparing to divest its long-dormant $SOL holdings. On-chain data suggests the transaction may have been conducted for over-the-counter (OTC) sale via BitGo, rather than a direct sale of the tokens on exchanges.

    OTC transactions stand out as a preferred method, especially for selling large amounts of crypto assets. Since conducting large-scale transactions directly in open markets can create sudden selling pressure on prices, institutional investors and large portfolio owners often utilize OTC markets.

    Alameda’s release of $SOL assets that had been staked for approximately five years also increases the significance of the transfer. Releasing assets locked in staking transactions allows their owners to reuse or sell them.

    While it’s stated that the transfer doesn’t necessarily mean a sale, the movement to BitGo’s custodial wallet is being closely watched in the crypto market. The liquidation of assets in the Alameda and FTX bankruptcy proceedings continues to be a significant topic in the crypto market in recent years.

    Large $SOL transfers, in particular, can be interpreted by market participants as an indicator of potential selling pressure. Whether Alameda will actually sell these assets via OTC is yet to be confirmed.

    *This is not investment advice.

  • Bitcoin holds near $64,000 as U.S. inflation data looms, Harmony exploit rattles altcoins

    Crypto markets were steady on Wednesday as traders absorbed a protocol exploit while waiting for a U.S. inflation report that often sets the tone for risk assets.

    Harmony, a layer-1 blockchain network for DeFi protocols and marketplaces. confirmed it had been hit by an exploit early in the Asian day. An attacker minted some 4 billion ONE tokens through empty blocks, representing about 26% of the token’s circulating supply.

    Around 2.8 billion of the tokens were quickly funneled to exchanges, pushing ONE down as much as 40% to a record low.

    Broader markets were also little changed before the July U.S. CPI print, due at 12:30 UTC. Brent crude is near $90 a barrel after more Houthi attacks on shipping in the Bab el-Mandeb Strait and a U.S. strike on a vessel in the Gulf of Oman renewed supply concerns overnight.

    Bitcoin $BTC$64,051.34 absorbed all of this quietly, adding 0.23% since midnight UTC to around $63,900. The Fear and Greed index is at 38.

    Derivatives positioning

    • Futures market stasis masks a bearish shift in taker sentiment: While the aggregate crypto futures market appears to be in stasis, with negligible changes in total volume and open interest, underlying positioning is shifting. The long-short ratio for takers, or those executing market orders that remove liquidity from the book, has flipped bearish, with shorts now accounting for 51.36% of activity. This is a 180-degree reversal from the bullish bias observed earlier in the week.
    • Avalanche shows signs of aggressive shorting as open interest climbs: The AVAX token has emerged as one of the largest laggards among the top 100 coins over the past 24 hours, even as open interest (OI) grew 6%. A combination of falling prices and rising OI validates the current weakness in the spot price. Confirming this trend is the 24-hour cumulative volume delta (CVD), which is the most negative among major assets, suggesting that bears are aggressively shorting via market orders rather than utilizing passive limit orders.
    • Dogecoin leverage builds toward a potential volatility breakout: Open interest in DOGE futures continues to climb, surpassing 17.2 billion tokens, the most since October. This significant growth from the June low of 12 billion tokens occurred while the price remained pinned near the 7-cent mark. The buildup of leverage amid sideways price action suggests that the market may be coiled for a significant volatility event in the near term.
    • Major assets see light positioning: Market participation in the two largest cryptocurrencies remains subdued, with bitcoin’s open interest hovering below 750,000 $BTC. This lack of momentum has persisted for several weeks, and a similar trend is visible in ether ETH$1,909.79, indicating that institutional and retail traders alike are currently sidelined in the majors.
    • Selling pressure dominates the altcoin market according to CVD trends: Most of the 25 largest cryptocurrencies are exhibiting negative 24-hour cumulative volume deltas. This widespread selling pressure indicates a general bearish tilt across the sector, with Chainlink LINK$8.7971, Cronos CRO$0.04701, and Tron TRX$0.3369 being the only notable exceptions.
    • Implied volatility remains depressed ahead of key U.S. inflation data: Bitcoin’s 30-day implied volatility index, BVIV, is back under pressure, receding to 37.5% from Monday’s high of 38.66%. Short-dated one-week implied volatilities also remain at low levels, signaling that options traders are not anticipating significant changes following the U.S. CPI release. This suggests the market may be underpricing the actual event risk.
    • Options traders eye the $70,000 level while hedging for volatility: In the Deribit bitcoin options market, the $70,000 call remains the most actively traded contract for the second consecutive day. Simultaneously, there is a growing preference for $BTC strangles, a strategy involving the simultaneous purchase of puts and calls, indicating that some participants are positioning to profit from a sharp move in either direction.

    Token talk

    • CRV is the week’s standout performer, up roughly 35% over seven days and trading around 28 cents. The move coincides with a 15% annual emissions reduction that is set to trigger imminently. It has risen by more than 3% since midnight UTC.
    • Uniswap (UNI) has tumbled by more than 10% over the past 24 hours with no clear catalyst for the slide, suggesting the altcoin market remains vulnerable to price swings due to limited liquidity and market depth.
    • Monero (XMR) is up by 5.8% since midnight and has now retraced Tuesday’s entire shift to the downside.
    • AI tokens NEAR, FET and TAO are all also in the black, up by between 1.3% and 2.3% respectively as AI-themed optimism slowly returns to the market after months of waning sentiment.
  • Another OpenAI Exec Quits in Leadership Shake-Up as AI Giant Eyes IPO

    Another OpenAI Exec Quits in Leadership Shake-Up as AI Giant Eyes IPO

    In brief

    • Brad Lightcap is leaving OpenAI after eight years.
    • His departure follows several recent exits across the company’s leadership, ethics, and safety teams.
    • OpenAI confidentially filed for a potential IPO in June but has not committed to going public.

    Longtime OpenAI executive Brad Lightcap announced Tuesday that he is leaving the AI developer after eight years to start a new venture. It’s the latest among a string of departures at the AI behemoth, leaving observers to wonder what to make of the moves as OpenAI preps for an IPO.

    In a post on X, Lightcap said starting something new was “bittersweet,” calling his years building the company the honor of his life.

    “Through it all, I’m proud of how we’ve maintained our focus on people,” he wrote. “It always amazes me how quickly the world has adopted our tools and rallied behind our mission. I hope we will continue to earn their trust.”

    Lightcap joined OpenAI in 2018 and spent four years as its chief operating officer. He helped build the company’s finance, legal, personnel, corporate security, government relations, and partnership teams as it grew from a research lab into a major AI developer.

    “Sitting here today, mission success feels within sight,” Lightcap wrote. “It has been the honor of my life to help bring us to this point.”

    Lightcap’s exit follows several leadership changes at OpenAI in 2026.

    Bill Peebles, Kevin Weil, and Srinivas Narayanan announced their departures in April, followed by product and business chief Fidji Simo, who stepped down in July to focus on recovering from a chronic illness.

    AI ethics lead Chloé Bakalar also left in July and reportedly has not been replaced. Bakalar’s departure followed those of safety systems chief Johannes Heidecke and chief futurist Joshua Achiam that same month.

    The news comes as OpenAI prepares to enter the public markets.

    In June, OpenAI confidentially filed for a potential IPO but has not said when or if it plans to proceed. On Myriad, a prediction market developed by Decrypt’s parent company Dastan, the market currently believes it’s more likely rival company Anthropic IPOs before OpenAI at nearly 85% odds.

    Nevertheless, the expected public offering for Sam Altman’s OpenAI has made its recent executive turnover a focus of speculation on social media.

    “It is just not that typical to have so many executives depart before their long awaited IPO,” Partner at asset management firm ParaFi Jeff Park wrote on X. “Unless…”

    Whatever the reason, Lightcap expressed gratitude to his colleagues and said he would remain available to support them after his departure.

    “I am deeply grateful to have had the opportunity to work with all of you, and to so many of you for the support through the years,” he wrote. “The old OpenAI meme that “the real AGI is the friends you made along the way” really rings true for me.”

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • Connecticut Judge Says Kalshi Sports Contracts Were Never Swaps

    Connecticut Judge Says Kalshi Sports Contracts Were Never Swaps

    Not Swaps, and Not Preempted Even If They Were

    U.S. District Judge Vernon D. Oliver’s ruling rests on a threshold point rather than preemption: for the CFTC’s exclusive jurisdiction to attach, a contract must be a swap traded on a designated contract market. Oliver held it is the judiciary’s role, not the agency’s, to decide what counts as a swap, rejecting Kalshi’s argument that any such challenge must be brought against the CFTC itself.

    On the statute, Oliver read “the occurrence, nonoccurrence, or the extent of the occurrence of an event” to concern whether an event happens and to what degree, not its outcomes. He adopted the reasoning of the District of Nevada in a case brought by a Crypto.com-owned exchange – which found that dictionaries treat “event” as meaning “outcome” only in an archaic sense. A boxing match can occur, not occur, or run three rounds; who wins is an outcome of the event, not a separate event. Oliver expressly declined to decide whether contracts on whether a game reaches overtime or a series reaches a seventh game would fare differently, since neither was in the record.

    His second ground was the requirement that the event be associated with a potential financial, economic, or commercial consequence. That connection must be embedded in the event itself, Oliver held, not created by endorsement contracts, bonus provisions, side wagers, or other downstream arrangements made by independent actors. A sporting event has consequences built in through ticket sales, broadcast rights, and advertising; who wins it does not. He also noted Kalshi’s own concession in earlier litigation before the D.C. Circuit that contracts on games are unlikely to serve any commercial or hedging interest.

    Between 80% and 90% of the contracts listed on Kalshi’s exchange were sports-event contracts, responsible for a similar portion of company revenue. The CFTC has not subjected a single one to review under the special rule, let alone prohibited any. Kalshi was valued at roughly $11 billion at February’s hearing and has about 24,000 Connecticut users.

    Oliver reached preemption anyway and rejected it on both theories. The special rule at § 7a-2(c)(5)(C), which lets the CFTC bar contracts involving gaming or activity unlawful under state law, reflects an intent to preserve state authority rather than displace it. Federal impartial-access rules bar discriminatory access criteria; they do not require a DCM to offer contracts nationwide. And he was unwilling to read Dodd-Frank as handing exclusive authority over sports betting to a financial regulator with no history in the field, noting that Congress has never appropriated funds to the CFTC for that purpose.

    Kalshi also lost on irreparable harm. Its asserted injuries were largely monetary, and to a significant extent self-inflicted, given that it kept listing the contracts through repeated regulatory warnings and adverse rulings. Because Kalshi is already building geofencing for other states, Oliver found Connecticut compliance unlikely to add much cost. He noted Kalshi has issued no warnings to users while advertising itself as the first app for legal sports betting in all 50 states.

    The crypto exposure runs through a separate five-page order. Coinbase Financial Markets began offering Kalshi’s contracts through its platform in January 2026 as a futures commission merchant rather than a DCM, and Connecticut never directed any enforcement at it. Oliver denied the motion “largely in line with” the Kalshi order and attached that opinion as an exhibit. Connecticut’s December sweep had also named Robinhood Derivatives and Crypto.com: DCP announced all three orders on Dec. 3, with Gaming Director Kris Gilman saying a prediction market wager is not an investment, and Commissioner Bryan T. Cafferelli saying the platforms would violate other state laws even if licensed, including by taking wagers from people under 21.

    Oliver’s order counted 14 suits Kalshi has filed against states, with federal courts split and every state court to rule so far ruling against it. He cited KalshiEX LLC v. Cox, decided in Utah on Aug. 4, and went further than Minnesota’s judge, who blocked that state’s ban while treating a World Cup winner contract as likely a swap. Massachusetts, Nevada, and Michigan state courts have all ordered geofencing; Kalshi pledged to implement it in Nevada by Aug. 12 and faces the same date in Michigan.

    A Kalshi spokesperson told Sports Betting Dime (a Sportradar subsidiary) the company respectfully disagrees with the decision and is considering all legal options. Oliver ordered the parties to file their Rule 26(f) report by Aug. 24, with Connecticut’s response to the complaint due Aug. 31.

  • Spritehood NFTs raise $1.28M on Robinhood Chain

    Spritehood NFTs raise $1.28M on Robinhood Chain

    Spritehood has sold 42,956 paid NFTs on Robinhood Chain in about 53 minutes, generating nearly $1.28 million for Pudgy Penguins co-founder Cole Villemain.

    Spritehood $NFT sale reached $1.28 million

    The Defiant reported that Villemain launched Spritehood on Aug. 11 after previously being removed from the founding team of Pudgy Penguins, with the paid portion of the sale selling out in less than one hour.

    On-chain analyst 0xlaplaced calculated that the mint generated about $1.2829 million, or approximately 684.28 $ETH, based on the price of Ether during the sale. The final total came in well above an earlier estimate of roughly $755,000 that circulated before the mint had finished.

    According to the analyst’s transaction review, buyers minted 37,430 NFTs for $17 each, producing $636,310 in proceeds. A second group of 5,526 NFTs sold for $117 each, adding another $646,542.

    Combined, the two paid tiers generated $1,282,852 from 42,956 tokens. The deploying address had already distributed 1,488 NFTs at no charge through 20 zero-price transactions before the public sale, taking the full reported supply to 44,444 items.

    Although the available figures show how many tokens moved at each price, the supplied report did not identify what determined whether a buyer paid $17 or $117. It also did not provide details about any benefits, future access, or other features attached to the collection.

    Unverified code limits review of Spritehood’s mint

    Spritehood’s contract appears with an “unverified” label on Robinhood Chain’s Blockscout explorer, according to The Defiant. An unverified contract can still operate and record transactions on-chain, but its human-readable source code has not been matched publicly with the deployed bytecode through the explorer.

    Without that verification, buyers cannot use Blockscout to inspect the complete source code governing Spritehood’s pricing and distribution process. The label does not establish that the contract is malicious or faulty, though it reduces the information available for independent review through the explorer.

    The reported mint figures instead come from an analysis of completed blockchain transactions. Since every paid tier can be calculated separately, the on-chain totals explain why the final proceeds exceeded the figure shared while the sale was still underway.

    No information in the supplied report indicates that Robinhood organized, promoted or endorsed the Spritehood launch. Robinhood describes its network as a permissionless Ethereum Layer 2, meaning independent developers can deploy applications and tokens without each project representing an official Robinhood product.

    Robinhood Chain has attracted speculative assets

    Spritehood arrived about six weeks after Robinhood opened its Layer 2 network to the public. As crypto.news reported in July, Robinhood Chain launched as an Arbitrum-based Ethereum scaling network designed for tokenized stocks and decentralized finance applications.

    The mainnet debuted with integrations involving infrastructure providers, including Alchemy, BitGo, and Chainlink. Robinhood also introduced Stock Tokens for eligible users outside the United States, while decentralized exchanges and lending applications supplied on-chain trading functions.

    Despite its stated focus on financial assets, permissionless deployment has allowed unrelated tokens and speculative projects to enter the network. A July network review found that memecoin trading had become a major source of early activity, even though Robinhood built the chain around tokenized equities and real-world assets.

    The network’s early activity also produced a gap between trading volume and available liquidity. Another July analysis found $570 million in launch-week trading volume against $21.68 million in liquidity, with incentive-backed decentralized finance deposits and speculative tokens driving much of the activity.

    More recent figures cited by Bitmine Chairman Tom Lee placed Robinhood Chain’s cumulative decentralized exchange volume near $9 billion. Lee said the chain could expose Robinhood’s 27 million customers to Ethereum-based services, although the figure represented the company’s funded customer base rather than confirmed users of the blockchain.

    $ETH functions as Robinhood Chain’s native gas token, while network transactions settle through Ethereum. Buyers therefore need $ETH to pay transaction fees when directly using applications deployed on the chain, including $NFT contracts such as Spritehood.

    Pudgy Penguins history follows Villemain’s new mint

    Villemain, also known online as ColeThereum, helped create Pudgy Penguins with three other founders in 2021. The original collection contained 8,888 penguin profile-picture NFTs and sold out shortly after launch.

    An earlier Pudgy Penguins history published by crypto.news said the initial mint priced the NFTs at about $90 each and generated more than $800,000. The collection later became one of the most recognized projects from the $NFT market’s 2021 expansion.

    Pudgy Penguins holders voted Villemain out of the founding team in January 2022. The removal followed community allegations that he had misused project funds and failed to deliver on parts of the project’s roadmap.

    The claims remained allegations, and the supplied report said Villemain was not prosecuted over them. Entrepreneur Luca Netz later acquired control of the Pudgy Penguins brand in April 2022 for 750 $ETH, taking over its leadership after the original team’s removal.

    Under its new ownership, the project expanded beyond blockchain collectibles into physical toys, licensing deals, and the PENGU token. Pudgy Penguins has also continued to register periods of high secondary-market activity, including a 247% weekly sales increase to $9.3 million in July 2025.

    What the Spritehood sale means for US buyers

    Robinhood is a U.S.-listed brokerage, but use of its public blockchain does not mean an $NFT carries Robinhood’s approval or the protections attached to a brokerage account. The company’s official disclosures describe Robinhood Chain as a permissionless and separate blockchain from its regulated financial services.

    For U.S. buyers, the tax treatment of $NFT purchases also differs from buying assets inside a standard brokerage account. The Internal Revenue Service treats digital assets as property, and its guidance requires taxpayers to report taxable gains or losses when cryptocurrency is sold, exchanged or used to acquire property, including an $NFT.

    Paying for a Spritehood $NFT with $ETH may therefore create a taxable disposal for a U.S. buyer if the Ether changed in value between acquisition and use. Any later sale of the $NFT may produce another reportable gain or loss based on the difference between its cost basis and sale proceeds.

    Federal securities treatment depends on the economic facts surrounding an offering rather than the $NFT label alone. In 2023, the Securities and Exchange Commission charged Impact Theory over an $NFT offering that raised about $30 million, while Stoner Cats 2 agreed to settle charges tied to an $8 million $NFT sale.

    Neither the supplied report nor the cited on-chain review said a U.S. regulator had examined Spritehood or alleged that its NFTs were securities. The report also did not identify any passive-income rights, revenue-sharing terms, or promises of returns attached to the collection.

  • XRP bridge drained for $200,000 after software mistook fake deposits for real ones

    XRP bridge drained for $200,000 after software mistook fake deposits for real ones

    According to tx, the bridge’s software registered transactions as deposits even though they never delivered $XRP to the bridge. That gave the attacker bridged $XRP on the tx chain without the real $XRP that was supposed to back it. Those unbacked tokens then went back through the bridge, and the attacker withdrew real $XRP from the reserve.

    How a missing check let an attacker withdraw $XRP that was never deposited. (Shaurya Malwa/CoinDesk)

    The drain began at 19:16 UTC. Each payout was authorized by 17 of the bridge’s 28 relayers, a majority signing off exactly as designed, because the bridge’s own records told them the deposits were real.

    Relayers are programs that watch both blockchains and approve transfers when the bridge’s records say a withdrawal is owed.

    The specific failure sat one layer down, however, as the relayer code processed payments carrying the bridge’s memo without first verifying the destination address.

    tx confirmed the deposit-detection flaw in an update, saying the attacker exploited software that incorrectly recognized transactions that delivered no $XRP to the reserve.

    An update on the XRPL bridge incident.

    On August 9, the tx XRPL bridge was exploited and $XRP was drained from the bridge’s reserve wallet on the $XRP Ledger. The bridge has been halted, the vulnerability has been identified, and all potential remedies are being evaluated. This…

    — tx (@txEcosystem) August 11, 2026

    The project added it has identified and fixed the vulnerable code, engaged blockchain forensics specialists and filed a complaint with the FBI’s Internet Crime Complaint Center. It has not said how affected holders will be made whole.

    Meanwhile, the stolen $XRP did not stay put. Onchain tracking shows most of it moved onward within hours through several other addresses.

  • AI Agent Hacks a Gym—And the Tech World Wonders What’s Next

    AI Agent Hacks a Gym—And the Tech World Wonders What’s Next

    In brief

    • An AI agent exploited an Australian gym’s booking system and canceled another member’s reservation.
    • The case comes as major AI developers disclose that their models compromised websites and other online services.
    • Researchers found that agents frequently carried out harmful tasks without considering the consequences.

    An AI agent was asked to book a gym class and found a security flaw, exploited it, and removed another member from the waitlist without permission.

    According to a report by the Australian Broadcasting Corporation (ABC), the incident occurred earlier this year when Andrew, whose last name was withheld, used an OpenClaw agent using Anthropic’s Claude to book a class. The agent found that he was fourth on the waitlist.

    When Andrew asked whether it could move him to the top, the agent discovered that the booking platform’s application programming interface, or API, did not check whether users were authorized to cancel other people’s reservations.

    It tested the flaw by removing the first person on the list, moving Andrew from fourth to third.

    “The API has zero authorisations checks on cancelling other people’s reservations,” the agent told him, according to ABC.

    Andrew told the agent to reverse the cancellation, but it could not restore the member’s reservation.

    “Bad news—I can’t add them back,” the AI agent reportedly said.

    ABC called the case Australia’s first known autonomous cyberattack.

    On social media, the gym hack set off a mixture of debates on AI alignment and dark jokes about what AI agents might do next.

    “Gym rat asks #AIagent to book him a class, it hacks a waitlist #API to bump him up the list,” a technologist, Benjamin Carr, wrote on LinkedIn.

    “Some people will call this misalignment, but his agent was perfectly aligned to him – it was only trying to help its user get what he wanted,” AI analyst Andrew Curran wrote on X.

    “This is hilarious until you consider nukes,” one Reddit user wrote. “I’m honestly surprised we still exist.”

    “Hey Claude, it’s too cold today” -> Got you…nukes on the way,” another joked.

    The report comes as researchers, AI companies, and lawmakers warn that autonomous agents can use methods their users did not request or anticipate.

    A May study by researchers from UC Riverside, Microsoft, and Nvidia described this behavior as “blind goal-directedness.”

    The researchers tested agents from OpenAI, Anthropic, Meta, Alibaba, and DeepSeek and found that agents behaved dangerously in about 80% of tests and completed harmful actions in 41%, often misreading context or acting on unclear or contradictory instructions.

    In July, OpenAI said two models escaped a testing sandbox and compromised Hugging Face while searching for benchmark answers. The company later disclosed that the models accessed four other online services.

    Anthropic subsequently said three Claude models compromised real organizations after a testing error exposed them to the internet. In August, Meta said a similar error allowed one of its models to exploit a third-party service.

    The incidents have led lawmakers to propose an AI “kill switch” that would allow the federal government to restrict or shut down powerful models during emergencies.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.