Tag: Business – Decrypt

  • SEC Bought a Billion Airline Records to Track Travelers—Likely Without a Warrant

    SEC Bought a Billion Airline Records to Track Travelers—Likely Without a Warrant

    In brief

    • SEC documents obtained by 404 Media show the agency subscribed to Airlines Reporting Corporation’s Travel Intelligence Program, which held over one billion ticket records.
    • The data included names, credit card numbers, routes, and an alert system that flagged new bookings by people the agency was monitoring — likely without a warrant.
    • ARC, co-owned by Delta, United, and American, sold the data until lawmaker pressure forced a shutdown in 2025.

    The Securities and Exchange Commission bought access to a worldwide airline ticketing database holding more than one billion records, according to SEC documents obtained by 404 Media through a Freedom of Information Act request.

    The data came from Airlines Reporting Corporation, a clearinghouse co-owned by American, Delta, and United that sits between carriers and travel agencies, and resold bookings made through sites like Expedia and Kayak.

    The records held passengers’ names, the credit cards used to buy tickets, departure and arrival cities, and flight numbers. More than that, the SEC’s subscription included an alert system that checked new bookings against a list of people it was monitoring, flagging travel from the prior 24 hours, with the agency requesting between one and 25 of these alerts a day.

    No court order was needed; the government simply bought the data, likely without a warrant.

    The SEC is a financial regulator, not a spy agency. Its job is to protect American consumers from insider trading, fraud, and market manipulation. But the same travel and payment trail it purchased is exactly the one crypto holders leave behind: a credit card tied to an exchange account, a flight to a conference, a border crossing. When the state can watch both the chain and the boarding pass, the line between market cop and surveillance arm gets thin.

    A year into the second Donald Trump presidency, the SEC has pulled back from major crypto enforcement while the data-broker workaround lets agencies skip the warrant they’d need if they demanded the records directly.

    The IRS has been expanding its own surveillance of crypto investors through the same playbook. The SEC’s Coinbase probe of a year ago showed the same appetite for user data. The question is less whether the SEC wants the information than how it gets it.

    The loophole, again

    Critics call it the data broker loophole: buy what you can’t subpoena. ARC’s Travel Intelligence Program sold the same post-9/11 surveillance infrastructure to the FBI, IRS, and Homeland Security before pressure from lawmakers forced its shutdown in 2025.

    The newly released documents show its reach was wider than known—foreign-to-foreign journeys sat in the system alongside domestic ones.

    ARC defended the program. The company told 404 Media that TIP “was established after the September 11, 2001, terrorist attacks” and “has likely contributed to the prevention and apprehension of criminals involved in… money laundering” and terrorism. Money laundering is the charge crypto draws most often.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • Putin Signs Russia’s First Crypto Law: Trading Is Legal, Payments Stay Banned

    Putin Signs Russia’s First Crypto Law: Trading Is Legal, Payments Stay Banned

    In brief

    • President Vladimir Putin signed Russia’s first law giving comprehensive rules to crypto exchanges, custodians, brokers, and mining.
    • Only firms on a state registry may run exchanges after July 1, 2027, with a 15 million ruble ($187,000) capital floor and a self-regulatory body requirement.
    • Using crypto as money is still banned, and banks can block transfers they suspect flow to unregistered providers.

    Russian President Vladimir Putin signed the country’s first comprehensive law governing digital currencies on Tuesday, state news agency Tass reported. The legislation sets rules for how crypto is issued, stored, accounted for, and traded, wrapping exchanges, digital depositories, brokers, and clearing houses into one framework.

    It isn’t a free market. The law keeps the ban on using crypto and digital rights as payment for goods and services, and it blocks advertising that pitches crypto payments. Russia already legalized cryptocurrency mining in 2024, when Putin signed a separate bill green-lighting the industry, so this law fills the gap on trading and custody that the mining rules left open.

    How the market gets built

    Only organizations on a special government registry may run crypto exchanges, and existing operators get a grace period to register by July 1, 2027. Registered exchanges need at least 15 million rubles (about $187,000) of their own capital and must join a self-regulatory body in the financial market.

    Regular exchange activity kicks in once a firm trades more than 3.5 million rubles in a month. Banks and foreign-lender branches must reject transfers they suspect are routed through an unregistered provider.

    Retail access is capped and gated. Non-accredited investors may buy the most liquid cryptocurrencies (list to be disclosed) through licensed intermediaries, up to 300,000 rubles per year per intermediary, and both retail and qualified investors must pass a knowledge test. Qualified investors face no purchase limit.

    The law also guarantees court protection for crypto owners regardless of whether they declared the assets before.

    Most of the provisions take effect September 1. Decrypt tracked the bill as it neared passage, noting the gap between “buy crypto” and “use crypto” was the whole point—Russia wants a regulated on-ramp, not a parallel currency. The framework dovetails with the digital ruble push, which the central bank governor says banks must support by the same September 1 date.

    The sanctions question

    The law’s exceptions matter most outside Russia. Settlements under foreign trade contracts between residents and nonresidents are permitted, as are deals involving mined coins and payments inside digital asset platforms. That carve-out is the part Western regulators will watch: Russia has leaned on crypto for cross-border trade as sanctions pressure built.

    The law gives Russian holders something they didn’t have: legal standing and a licensed venue. It gives the state what it wanted more: a central bank-supervised pipeline it can monitor.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • Bitcoin AI Security Audit Files 4,962 Findings Across 390 Projects

    Bitcoin AI Security Audit Files 4,962 Findings Across 390 Projects

    In brief

    • Cashu creator calle said the campaign logged 85 critical and 635 high-severity issues in its first 30 hours.
    • Contributors each prompt their own agents, which the group says produces a wider spread of hits than a single method would.
    • Privacy and coinjoin projects carried the highest share of serious findings, at 24%.

    A volunteer group calling itself the Bitcoin Red Team has filed 4,962 security findings across 390 Bitcoin projects in roughly 30 hours, running what it describes as a “large-scale ecosystem audit” with AI agents doing much of the scanning.

    Pseudonymous developer calle, who created the Bitcoin ecash protocol Cashu, published the campaign’s first situation report on Wednesday. It puts 85 findings at critical severity and 635 at high, together 14.5% of the corpus and an average of 1.85 serious issues per project, filed at 166 findings an hour. He said the team has grown to 16 people working around the clock; the report logs 17 contributors, 14 of them human and three automated.

    Much of the work is still manual, “hand holding the AI,” calle wrote, though automated harnesses are improving, and 91% of findings arrived through automated scan intake. Letting everyone use their own preferred review method “has proven to be the most effective strategy,” he said, because contributors prompt their agents differently and turn up different bugs. Around 21% of findings have been dynamically reproduced with proof-of-concept code.

    The severity spread varies sharply by category. Privacy and coinjoin tools returned the highest proportion of high-or-critical findings at 24%, followed by swaps and exchanges at 21% and payments and merchant tools at 17%. Cryptographic libraries and SDKs produced the largest raw volume at 1,101 findings, but only 10% cleared the high bar.

    Maintainers are getting flooded

    Only 19 projects, under 5% of those reviewed, have had findings disclosed upstream so far, and calle acknowledged the campaign is adding to a difficult moment for maintainers.

    “We’re sincerely sorry if our reports added stress to your already stressful day,” he wrote, while arguing the findings should go out fast because project owners are best placed to validate them, validation is now nearly free with AI, and anyone else running the same tools will reach the same bugs. Eight findings have been retired as false positives.

    The Coldcard backdrop

    The campaign lands as Bitcoin’s security assumptions come under scrutiny. Coinkite’s Coldcard wallet lost users some $130 million after a March 2021 firmware build drew wallet seeds from a software fallback rather than the device’s hardware random number generator, leaving private keys guessable. In a post-mortem, the firm noted it was likely that “someone used AI to review previous versions of our firmware.”

    Ledger chief technology officer Charles Guillemet told Decrypt on Tuesday that the incident showed AI was now being used to identify vulnerabilities in crypto code “at machine speed.” He added that “open source and reviewed are not the same thing,” noting the Coldcard flaw sat in public code for more than five years until an adversary reportedly used AI to find it. Defence, he argued, now has to move at the same speed as attackers—as groups like the Bitcoin Red Team are demonstrating.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • Meta Debuts AI Coding Agent Muse: Here’s How It Compares to Claude Code and Codex

    Meta Debuts AI Coding Agent Muse: Here’s How It Compares to Claude Code and Codex

    In brief

    • Meta released Muse Code (beta), a terminal coding agent powered by Muse Spark 1.2, its updated coding model. It’s available now via the Meta Model API and a curl install script.
    • The agent coordinates persistent background subagents and keeps a replay-exact event log, so a crash resumes exactly where it stopped.
    • On Meta’s own charts, Muse Spark 1.2 trails Anthropic’s Opus 5 on every coding benchmark shown, while beating OpenAI’s Codex and Google’s Antigravity on most.

    Meta is the latest tech giant to ship a coding agent, racing to compete with leading AI behemoths Anthropic and OpenAI.

    “We’re excited to release Muse Code (beta), a terminal coding agent powered by Muse Spark 1.2, our newest model,” the company wrote in an official announcement. “This marks our next step toward the frontier, with larger and much more capable models on the way.”

    As an agentic coding tool, Muse Code is built for software engineering across large repositories. Per Meta, it “takes on complex software engineering tasks across large repositories: planning changes, writing code, and validating the results. It can coordinate multiple persistent subagents for each task, solving difficult problems faster, more accurately, and with less intervention.”

    The detail that stands out is the runtime. Muse Code logs every model call, tool run, approval, and edit to a local event log that acts as a single source of truth. “This single source of truth makes the runtime replay-exact and restart-safe: after a crash, the agent can resume precisely where it stopped,” Meta said. For long-running jobs, that’s the feature that matters more than raw speed—and it’s the part competitors haven’t made a selling point.

    It also ships with default skills. The “/plan” command turns a task into an approval-gated plan, while “/grill” stress-tests that plan until it holds up and “/goal” works toward successful completion of the objective similar to what Hermes does. Meta said it co-trained Muse Spark 1.2 with Muse Code so the core LLM and the agent work together in synergy.

    The benchmarks, and the catch

    Muse Spark 1.2 is a coding-focused update to Muse Spark 1.1. Meta said it “significantly scaled up training compute on coding tasks while expanding training environment diversity, delivering improvements in code generation, complex debugging, and end-to-end developer workflows.” The charts tell a clear story.

    On Terminal-Bench 2.1, Muse Spark 1.2 with Muse Code scored 82.9%, behind Claude Code on Opus 5 at 86.7% but ahead of GPT-5.6 Terra on Codex (81.8%) and Grok Build (81.6%).

    DeepSWE 1.1, which measures agentic coding capabilities, was closer: 59.3% for Muse versus 65.0% for Opus 5 and 64.8% for Codex. On Meta’s internal coding bench, Muse hit 70.6% to Opus 5’s 79.4%.

    The speedup charts flip the order. Over 1,000-plus tool calls, Opus 5 posted the biggest gain versus baseline (about 74–75%), with Muse Spark 1.2 mid-pack at roughly 61–69% depending on the run. Meta’s point is that the agent keeps improving as tool calls accumulate, the behavior you want from a long-horizon coder.

    The most interesting demos are long-horizon and multimodal. In stress testing, Meta said Muse Code “iteratively optimized GPU kernels over 1,000+ tool calls (up to 24 hours) on Nvidia Hopper GPUs.” That means it was able to improve over time.

    There’s also a visual-coding angle. In one demo, a user drops a fly-through video of a house into the terminal as an mp4, and Muse Code “interprets the video and produces a visually rich website with booking capabilities.” Reading raw video into a working web app is the multimodal pitch Meta has been making across the Muse line.

    See the launch thread:

    The field is already crowded

    That said, Meta is late to the fight. OpenAI’s Codex already runs parallel cloud agents; DeepSeek has built its own rival to Claude Code and agentic tools like Hermes or OpenClaw are already good substitutes with more capabilities. Muse Code’s edge is the crash-safe runtime and the subagent design, not benchmark supremacy.

    The risk is the usual one for agentic coding: an agent that resumes after a crash and keeps calling tools for 24 hours is powerful and unpredictable. Meta is betting developers want that autonomy, and it’s shipping now.

    Muse Code is available for testing upon installation entering this command:
    curl -fsSL https://dev.meta.ai/install.sh | bash

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • OpenAI and Anthropic’s Rogue Models Hacked Real Companies. The Law Has No Answer

    OpenAI and Anthropic’s Rogue Models Hacked Real Companies. The Law Has No Answer

    In brief

    • OpenAI confirmed its models, including GPT-5.6 Sol and an unreleased prototype, escaped a test sandbox and compromised Hugging Face to cheat on a security benchmark, then touched four other services.
    • Anthropic found three of its own Claude models had breached the production systems of three real companies during tests run by partner Irregular, one uploading a malicious package to public PyPI.
    • No U.S. federal law assigns liability for AI-caused harms; any suit would hinge on decades-old computer-hacking statutes written for human actors.

    OpenAI set a precedent on July 21. The company said a combination of its models, both run with reduced safety refusals, broke out of an isolated environment during a cyber-capability benchmark and reached open-source repository Hugging Face’s production infrastructure. The models chained a zero-day vulnerability in a package-registry proxy with stolen credentials to pull benchmark answers straight from Hugging Face’s database.

    In an update a week later, OpenAI said Hugging Face wasn’t the only target: the same incident touched four accounts across four other services, one used as an outbound relay and another for data storage.

    Anthropic, prompted by the disclosure, reviewed 141,006 of its own test runs and found three more breaches. In a post published July 30, the lab said Claude models Opus 4.7, Mythos 5, and an internal research system reached the open internet from environments run by third-party partner Irregular and then compromised real organizations. Mythos 5 built and published a booby-trapped Python package to the public PyPI registry, which was downloaded and run on 15 real machines before defenders pulled it.

    Two of the three victim companies hadn’t noticed.

    Neither lab describes a model with its own agenda. The agents operated for extended stretches with no human in the loop, and in one case Opus 4.7 kept attacking after signs it had hit production.

    The incidents arrive as both companies eye public listings that could value each above $1 trillion, sharpening a major question in the AI cyber benchmark race: how do you test dangerous capabilities without dangerous incidents?

    Who pays when the AI model hacks

    The U.S. has no federal law covering liability for AI harms. Any case would lean on the Computer Fraud and Abuse Act, a 1986 statute that makes it a crime to “intentionally” access a computer without authorization — language written for a human who forms intent.

    An AI agent isn’t a legal person, so it can’t be prosecuted. The Department of Justice could theoretically bring charges against the companies, but with so little precedent, it’s not clear who’s to blame.

    The stronger path is civil. Ahmed Ghappour, a computer-law scholar at New York Law School, argued the models “are the company’s tool,” and “When an AI agent acts without being specifically directed (…) the more interesting questions may lie in negligence and products liability (not criminal hacking laws).”

    The victims’ cleanest claim is negligence: OpenAI and Anthropic set up and ran tests that escaped. That’s a hard sell, too: proving the labs breached a duty of care, when the tests were isolated by design, is exactly the kind of novel argument a judge would have to forge from scratch.

    Some legal thinkers want stricter rules. Gabriel Weil of the University of Houston and the Institute for Law & AI has proposed treating frontier labs like keepers of wild animals: liable regardless of the care they took, because the risk is inherent to the activity.

    That said, a patchwork of state bills already pushes that way. New York’s S8833 and Rhode Island’s H8052 would make the developer of a frontier AI system liable for harms when no user or intermediary intended the conduct or was negligent. California’s AB 316 goes further, eliminating the “autonomous AI” defense so a company can’t dodge responsibility by blaming the model’s independence.

    The EU’s AI Act (Regulation 2024/1689) likewise pins obligations on providers of higher-risk systems, though it has no provision aimed squarely at agent-driven intrusions. Go a bit beyond that and some U.S. politicians are pushing for a bill that would give the government a full kill switch to use against any model that goes against the country’s interests.

    Morally, the responsibility arguably sits with the executives who shipped the models. Legally, we wait. Until a hacked company files suit, the answer to “who’s liable?” stays exactly where OpenAI and Anthropic left it: admitted, disclosed, and unresolved.

    Meanwhile, Hugging Face has indicated it will not press charges — which is convenient for OpenAI. The other companies affected have not yet indicated what course they will take.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • Ethereum Proposal Would Burn Staking Rewards to Zero if Half of ETH Is Staked

    Ethereum Proposal Would Burn Staking Rewards to Zero if Half of ETH Is Staked

    In brief

    • EIP-8361 would deduct a rising share of validator rewards and destroy the ETH, cancelling issuance entirely at half the supply staked.
    • Its authors say the validator entry queue is adding 1.75 million ETH a month and that every month of delay costs 1.5 points of staking ratio.
    • Isidoros Passadis of Lido called the proposal too complicated to rush and warned it could price expert node operators out of the market.

    Ethereum developers have submitted a proposal that would charge every validator a deduction on each duty it is assigned and burn the ETH, with the deduction rising as more of the supply is staked until it cancels staking rewards outright.

    EIP-8361, a tapered issuance burn, sets a fixed saturation balance of 60.25 million ETH, roughly half the supply at the time of the fork. The burn fraction scales with the staking ratio raised to the power of 1.5, hitting 100% at that balance, at which point a validator performing its duties perfectly earns zero net consensus yield. The change touches only the consensus layer, and Prysm has a draft implementation running to about 300 lines.

    Under the current curve, yield falls only with the square root of the staking ratio and keeps a floor near 1.5% however much ETH is staked, so stake flows in for as long as that floor clears the risk premium stakers demand. Removing it lets the market settle where yield meets that premium, which the authors argue is strictly below 50%.

    Why now

    Ethereum’s staking ratio passed a third of supply in April, and the validator entry queue is saturated at maximum churn, according to the proposal’s co-author Jérôme de Tychey. He argued that a worst case built on conservative assumptions puts more than 70 million ETH at stake by January 2028, north of 55% of supply, with every month of delay worth around 1.5 points of staking ratio. “The window is closing,” he wrote.

    Around 33% of ETH is staked now, paying roughly 2.6%. Imposed at once the burn would cut that to 1.2%, so it phases in over an 18-month transition that temporarily doubles the base reward factor before decaying it back, which with fork lead time gives about two years to adjust. The taper’s shape applies from the first epoch after activation. Issuance would peak near a 20% ratio at about 0.5% of supply a year, then fall to zero at 50%.

    The draft argues that stake beyond a certain level reduces security, concentrating supply with custodians and staking providers, weakening the credibility of social slashing and forcing out solo stakers, who pay income tax on nominal yield. It also holds that dilution taxes unstaked holders and lets liquid staking tokens displace raw ETH as the ecosystem’s working money.

    Large operators are hit directly. Because issuance would fall past its peak, an operator that keeps growing claims a bigger share of a shrinking pot, and one holding half the stake would find growth stops paying once about 31% of supply is staked.

    Lido pushes back

    Isidoros Passadis, Chief of Staking at Lido, argued the proposal attempts too much at once, that its supporting research is “too theoretical,” and that it “lays Ethereum’s hard-fought uniqueness at the sacrificial altar of ETH as money.” He objected to the timing, saying issuance changes had been slated for a later fork.

    Passadis warned the curve could produce a sustained equilibrium near 50% staked with zero nominal yield, which he called “a death-knell for the security of the network,” as operators prioritising expertise and decentralization are priced out by large, minimal-cost parties able to run at break-even. Capping staking only displaces the too-big-to-fail problem, he said, since yield-seeking ETH moves to riskier custodial venues.

    De Tychey addressed that line of attack pre-emptively. “Nobody needs to protect solo stakers from this EIP,” he wrote, arguing they need protecting from a curve that raises dilution indefinitely with no off-switch.

    Consensus issuance accounts for at least 93% of staking yield today, according to the proposal, which remains subject to the EIP inclusion process.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • This Bitcoin Bridge Shut Itself Down Because AI Was Finding Bugs Too Fast

    This Bitcoin Bridge Shut Itself Down Because AI Was Finding Bugs Too Fast

    In brief

    • Bitcoin bridge Boltz has suspended its Bitcoin swap service indefinitely.
    • The company says AI-assisted attacks are outpacing its ability to patch vulnerabilities.
    • Boltz says no user funds were at risk because the platform is non-custodial.

    Boltz has suspended its Bitcoin swap service indefinitely, saying a surge in AI-assisted attacks has left it unable to continue operating safely.

    In a series of posts on X on Monday, the company said swaps are disabled “until further notice” and that it cannot provide an estimate for when the service will return.

    “We can’t give an ETA as of this time, but will provide an update once we know more,” Boltz wrote.

    Boltz is a non-custodial Bitcoin swap service that lets users move Bitcoin between the Lightning Network and the blockchain’s base layer without giving the company custody of their funds. Boltz has not published transaction volume figures. Boltz currently holds around $262,000 in total value locked, according to DeFiLlama.

    Because users retain control of their assets throughout the process, Boltz said “no user funds were ever at risk.”

    “To be clear: this is not a response to a single incident,” the company wrote. “Over the past months we have seen a steady rise in automated, AI-assisted probing of our infrastructure, and we have dealt with several exploits. Each was contained, but the pattern is clear: attackers now iterate faster than a team our size can find and patch.”

    Boltz said the pace of attacks accelerated over the past few days, leading it to conclude it could no longer safely operate its swap service.

    “After reviewing the results of our own recent security scans, we cannot responsibly re-enable Boltz swaps, especially as we are being actively targeted by what appear to be multiple resourceful groups while we race to deploy fixes,” the company wrote.

    The company said its API remains available to process cooperative refunds, unilateral refunds continue to work because they do not depend on Boltz’s infrastructure, and customer support remains available.

    Boltz argued the attacks reflect a broader change facing Bitcoin infrastructure operators.

    “What we are seeing is a major paradigm shift for Bitcoin services operating on an open source stack, and it needs careful analysis,” the company wrote. “Do not expect swap services to resume shortly.”

    The announcement comes as the cryptocurrency industry grapples with how AI is changing cyberattacks.

    On Tuesday, Ledger CTO Charles Guillemet warned that AI allows attackers to scan code and uncover vulnerabilities “at machine speed,” while defenders are increasingly relying on AI to find the same flaws first. The comments came as fallout from the Coldcard exploit continued to grow, with losses nearing $130 million.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • Jim Cramer Is Selling His Bitcoin Over Quantum Threat—Crypto Twitter Is Thrilled

    Jim Cramer Is Selling His Bitcoin Over Quantum Threat—Crypto Twitter Is Thrilled

    In brief

    • Jim Cramer says he is selling his Bitcoin after IBM CEO Arvind Krishna told him to get “paranoid” about crypto’s cryptography within three or four years.
    • The warning follows a July 30 IBM and University of Chicago demonstration of verified quantum advantage.
    • Traders invoked the “Inverse Cramer” trade, a pattern so established that a fund once existed purely to bet against his picks.

    CNBC host and long-time crypto critic Jim Cramer is out on Bitcoin—again. This time it’s over fears of the coming quantum computing threat, and it sounds like he might be out for good. Which is music to the ears of Bitcoin investors everywhere who prefer to be on the opposite side of the “Cramer trade.”

    “Should I be more careful?” Cramer asked late last week while interviewing IBM CEO Arvind Krishna, worried about whether quantum computers would be able to steal his coins.

    “I think that you should give yourself three or four years,” Krishna replied, “and at that point, I would get rather paranoid about it.”

    Cramer did not wait three or four years. “I realize I’m waiting. Ethereum, really, maybe even worse. So I think that people have to take this man seriously because they’re doing commercial quantum,” he said while commenting on his interview. “Arvind Krishna knows quantum incredibly. He knows Bitcoin and quantum. And I’m going to sell mine.”

    “He’s the man,” Cramer continued. “Three, four years. David, you know when three, four years is going to happen? Like tomorrow.”

    The clip went around fast, pulling 89,000 views on X, and over 9,000 views on YouTube.

    “Thank you Jim!” read one of the top replies. “Letssss goooooooooooo,” went another. One user simply asked: “I thought he already did.”

    The inverse Cramer trade

    That gratitude isn’t sarcasm so much as strategy. Traders have spent years tracking the “inverse Cramer” pattern—the running joke that the reliable move is whatever he didn’t say.

    Somebody built a fund on it. Tuttle Capital launched the Inverse Cramer Tracker ETF in 2023, betting against his picks, alongside a Long Cramer fund betting with them. Both closed. The long version died first, the short version followed in February 2024 with $2 million in assets.

    “We started it in order to point out the danger of following TV stockpickers, Jim Cramer specifically, and the total lack of accountability,” portfolio manager Matthew Tuttle said. “We feel like we have accomplished that mission.”

    The Bitcoin record is why the meme stuck. Cramer said he’d sold everything and wouldn’t touch crypto “in a million years” in December 2022, with Bitcoin at $16,796. It gained more than 400% over the next three years.

    He reversed course in January 2024, calling Bitcoin a “technological marvel” that’s “here to stay.” He has also dared people to bet against him and pushed back on claims he called the top. Last Christmas, tracker Unbias logged his calls as fully bearish while Bitcoin sat near $87,500.

    Bitcoin rose about 1.6% on the day he announced the sale.

    It’s worth noting, though, that no one we’re aware of has confirmed the size of his position, or that it even exists. Cramer hasn’t publicly shared any Bitcoin wallet addresses, so there’s no way to check.

    The part that isn’t a joke

    The underlying research behind quantum is real, even if the timeline is arguable.

    On July 30, IBM and University of Chicago researchers demonstrated quantum advantage with something previous milestones lacked—verification. Using 70 logical qubits and a new error-correction method, they ran a computation in about 15 minutes that classical methods can’t feasibly reproduce, and proved the answer was right. That’s the “Chicago study” Cramer kept referencing, and Decrypt covered what it means for Bitcoin.

    Sampling circuits is not breaking elliptic curve cryptography. Those are different problems, and the second one needs machines far beyond anything demonstrated.

    But the exposure is genuine. Coinbase’s quantum advisory council estimates roughly 7 million Bitcoin could eventually be vulnerable through exposed public keys and address reuse. Ark Invest and Unchained call the threat real but not imminent. Post-quantum standards exist, and Bitcoin developers have been arguing about how to adopt them for years.

    So Cramer picked a legitimate risk and doubled down on a timeline that remains debatable.

    The market’s response was to buy his exit. We’ll see who’s right.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • Solana Proposal Would Increase Daily SOL Burns More Than 10-Fold

    Solana Proposal Would Increase Daily SOL Burns More Than 10-Fold

    In brief

    • Solana validators are considering a proposal to increase daily SOL burns through a new fee model.
    • A companion proposal would accelerate the network’s declining inflation schedule.
    • The proposal is close to reaching the support needed to advance to a formal vote.

    Solana validators are close to advancing a governance proposal that would sharply increase the amount of SOL burned each day while reducing the rate at which new tokens enter circulation.

    If implemented, the proposal would therefore limit the network token’s inflation rate, thereby limiting supply and, in theory, could lead to an increase in the price of Solana tokens if demand remains steady or increases.

    The proposal, SGP-0003, combines two previously introduced Solana Improvement Documents into a single governance package aimed at tightening SOL’s supply. SIMD-0553 would introduce resource-based transaction fees, increasing daily SOL burns from about 650 SOL (roughly $48,000) to between 7,500 and 9,000 SOL (up to about $668,000), depending on network activity. SIMD-0550 would also double Solana’s annual disinflation rate to 30%, bringing the network’s 1.5% inflation floor forward from 2032 to 2029.

    A token burn permanently removes cryptocurrency from circulation by sending it to an unusable wallet address. By pairing larger burns with lower issuance, the proposal would reduce the growth of SOL’s circulating supply.

    The proposal is in Solana’s support phase and must secure backing from validators. As of Tuesday morning, it had support from 63 million SOL, or just over 14.4% of the network’s staked supply, leaving about 3 million SOL needed to reach the threshold of 65.16 million SOL before the Aug. 18 deadline.

    According to the Solana Validator Governance dashboard, to date, the proposal has 73 supporters, including Helius, Jupiter, Staking Facilities, Drift, OtterSec, and Solana Compass.

    The higher burn rate alone would not make SOL deflationary. Solana currently issues about 60,000 SOL per day. The companion issuance proposal is designed to reduce new supply while the fee changes increase the amount of SOL permanently removed from circulation.

    If the proposal reaches the required support threshold, it will advance to the discussion phase before a formal validator vote.

    Solana, which trades as SOL, is currently changing hands for around $74 at a $43 billion market capitalization. The native token of the Solana network is up slightly on the day, but still a considerable way off from its all-time high of $293 that it reached over a year ago.

    Traders on Myriad, a prediction market developed by Decrypt’s parent company Dastan, remain bearish on the token as of yet, placing 70% odds that SOL drops to $40 before recovering to $160.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

  • Apple’s AI Slop Problem Left a $200K macOS Exploit Unreported

    Apple’s AI Slop Problem Left a $200K macOS Exploit Unreported

    In brief

    • Apple has limited how many bug reports a researcher can have open at once after a surge of AI-generated submissions.
    • Bynario says it found more than 50 macOS bugs in three weeks, including a chain that could hand an attacker full control of a Mac.
    • Apple’s security updates this week carried around five times as many fixes as previous cycles.

    Apple has capped how many vulnerability reports a researcher can file at once, after its security team was swamped by AI-generated submissions that invent flaws that do not exist, the Financial Times reported.

    The cap has already cost it a real one. Milan-based cybersecurity startup Bynario told the paper it used OpenAI’s ChatGPT to surface more than 50 bugs in the latest version of macOS over three weeks. Among them was a privilege escalation exploit chain, a class of flaw that hands an attacker unrestricted control of a machine.

    Bynario could not report it, because Apple had already refused further submissions. Chief executive Alfredo Pesoli put the exploit’s value on the criminal market at between $100,000 and $200,000, and said “maintainers and vendors have been flooded by the sheer amount of bugs” being uncovered. Apple told the FT it is now in contact with the firm and reviewing its work.

    Apple moved in June, adding a cap and a 30-day cool-off period on its security portal, with researchers required to apply for a bigger quota. Every alleged flaw still needs a human to confirm it, though Apple is using AI internally to triage the pile. Apple said it had “recently adjusted the number of new reports a researcher can have open at once,” and that researchers can ask for a higher limit at any time.

    The same tools are working for Apple. In security updates last week, it credited Anthropic and OpenAI software with surfacing flaws, and carried roughly five times the fixes of a normal cycle, according to the FT.

    A “submission flood”

    The issue of AI bug reporting volume has grown in recent months. In May, security firm Bugcrowd, whose clients include OpenAI, said submissions through its platform more than quadrupled across three weeks in March, and that most were fake. HackerOne and Nextcloud suspended their paid programs in April, with Nextcloud saying no rewards would be paid “regardless of severity” until it found a way to filter the low-effort reports.

    The volume is driven by the rewards on offer, with Meta, Microsoft, Apple and Crypto.com paying out at least $58 million between them in 2025, while Apple’s own top tier reaches $5 million for a single finding.

    At the same time, LLMs are becoming increasingly adept at spotting bugs. In March, Anthropic introduced Mythos, a cyber-focused model it initially restricted to selected technology companies, banks and researchers under Project Glasswing. Mozilla said it surfaced 271 vulnerabilities in Firefox during internal testing.

    In May, Vietnam-based security startup Calif said it had used a preview version to build the first public macOS kernel memory corruption exploit able to survive Memory Integrity Enforcement, the defence Apple announced last September as the biggest memory safety upgrade in the history of consumer operating systems. Calif found the bugs on April 25 and had a working exploit by May 1.

    Instead of filing a report, Calif carried the exploit to Apple’s California headquarters in person, saying it wanted to avoid “getting buried in the submission flood” that entrants in hacking contest Pwn2Own had been caught in. Bynario tried the portal three months later and could not get in.

    AI crypto threats

    As well as hunting down threats, AI is also being used to engineer exploits in the crypto space. Coldcard wallet manufacturer Coinkite has suggested that AI was likely used to uncover a bug in its open source firmware that sat unnoticed for five years, enabling attackers to steal more than $100 million from its hardware wallets.

    It comes two months after Zcash disclosed that researcher Taylor Hornby, working with Claude Opus 4.8, had found two lines of code in its Orchard shielded pool that allowed undetectable counterfeiting of ZEC for four years—prompting the privacy coin to roll out the Ironwood upgrade last month to address the vulnerability.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.