Welcome to Galaxy Research's Weekly Research Brief. Subscribe to get this newsletter delivered to your inbox every Friday morning.
In this week's edition, Zack Pokorny looks at the CFTC’s advisory on mention markets; Lucas Tcheyan rounds up another dizzying week of AI developments; and Will Owens explains a proposal to bring Zcash-style privacy to Bitcoin.
Got feedback on this newsletter? Email [email protected]. We’d love to hear from you.
Altman and Amodei Urge AI Oversight. Their Agents Didn’t Wait
Sam Altman of OpenAI and Dario Amodei of Anthropic, the heads of two of the leading frontier AI labs, addressed the United Nations Security Council on Wednesday and urged world leaders to cooperate on AI safety.
Both executives called for international safety standards and a system for reporting AI incidents across borders. Amodei also proposed narrow global agreements, such as a ban on using AI to build biological weapons, along with systems that would let countries verify one another's AI commitments. Altman focused on who should be in charge, pointing to past cases where rival countries cooperated on a powerful new technology, and said major decisions should rest with governments accountable to the people they serve.
Both speeches followed recent policy pieces from the labs. On Sept. 12, Amodei published "We Must Pace the Frontier," which Galaxy covered last week. OpenAI published its own proposals on Monday, calling for international frontier standards based on the work of AI safety institutes with a focus on alignment research and recursive self-improvement. A day before the council session, President Trump rejected the push in his General Assembly address and pledged not to "stifle growth" of the technology.
Our take
The harder question for AI governance is what, exactly, should be governed. The technology is changing rapidly, its behavior is still poorly understood, and its development is increasingly intertwined with geopolitical and financial interests.
To add fuel to the fire, the technology is increasingly moving from controlled environments into the real world – sometimes, apparently, by accident. This week the Australian government said an OpenAI agent accessed public and non-public files on a Medicare statistics portal while researching public health spending. The incident occurred on June 18, and OpenAI notified Services Australia on Sept. 10, nearly three months later. OpenAI says it became aware of the activity in August during a review of misaligned model behavior and that its models "took actions we did not intend." The episode is also notable because it exposed a limitation of a mechanism Altman and Amodei explicitly endorsed at the UN: rapid incident reporting across borders.
The challenge is also changing in form. AI systems are increasingly being deployed as agents that can carry out multi-step tasks and interact with systems outside controlled research environments. On the same day Amodei briefed the UN, Anthropic announced that roughly 950 Claude agents spent 21 hours searching DNA databases using 210 million tokens before identifying a previously uncharacterized enzyme system. Human researchers performed the laboratory work, and Anthropic says the function of the enzyme system is still being investigated.
The Anthropic result was presented as a scientific success. The Australia incident, by contrast, was a security failure. But the two cases illustrate the same underlying shift: AI is moving from answering questions inside a sandbox to pursuing objectives across real-world systems, where the consequences of its actions can be useful ... or unintended.
The shift toward agent-dominated interactions is just starting to show up in the numbers. On OpenRouter, a leading model aggregator and routing layer, agents have consumed more tokens than humans since February. Agent token usage grew about 14x between February and August, versus 2.8x for humans. Cloudflare, which sits in front of roughly a fifth of the web, had expected automated traffic to overtake human traffic by the end of 2027, then revised that forecast to early 2027. In June, CEO Matthew Prince announced that the crossover had already happened.
Economics is reinforcing the shift. As agentic workloads’ share of usage grows, the cost of running those workloads is falling rapidly. On Vercel's AI Gateway, average price per token fell 23.2% in August and is now less than half its level five months earlier. Open-weight models accounted for 56% of token volume, up from 7% in December 2025. Vercel's data only covers traffic on its own gateway, so it isn't a measure of the entire market. But it shows how quickly inference is getting cheaper and how much usage is moving toward models outside the leading frontier labs.
That creates a harder problem for the kind of coordination proposed in New York. OpenAI and Anthropic can slow their own releases, expand evaluations, and improve incident reporting, but those measures address only the systems they control. As capable models become cheaper, agents move into real-world environments, and open-weight systems take a larger share of usage, the governance problem shifts from how frontier models are built to where AI systems can act, what they can access, and who is accountable when they do. - Lucas Tcheyan
‘Shielded Bitcoin' Paper Proposes Private BTC Transfers
On Thursday, Clara Shikhelman, Mikhail Komarov, and Aleksei Moskvin, researchers at cryptography R&D firm [[alloc] init], published Shielded Bitcoin. It is a protocol for private BTC transfers directly on the Bitcoin L1, with no soft fork or sidechain. In short, it takes Zcash’s shielded pool design (encrypted notes, public nullifiers, and zero-knowledge proofs) and runs it as a metaprotocol that uses Bitcoin only to publish data.
Value is held as “encrypted notes.” Transfers are data envelopes posted via OP_RETURN. The envelope carries encrypted notes for recipients and a proof that the sender owns the inputs and didn’t inflate the supply. Indexers watch Bitcoin for Shielded Bitcoin transfers to replay every envelope in block order and discard invalid ones.
Unlike Shielded CSV, the closest prior proposal, all data would live onchain, so a wallet could recover its funds from its seed alone. The abstract explicitly noted that peg-in and peg-out (the way BTC enters the system) are outside the paper’s scope.
The paper lands in the middle of perhaps the strongest privacy trade in the history of crypto. Zcash (ZEC) topped $1,600 this week and now ranks #9 by market cap among cryptocurrencies at ~$26 billion. It is up ~90% in 30 days and ~2,500% over the past year. The rally has several catalysts. Grayscale’s Zcash ETF (ZCSH) began trading on Aug. 25 and has since drawn more than $250 million in net inflows. On Sept. 16, Paradigm co-founder Matt Huang disclosed that the firm holds ZEC and called Zcash a private complement to Bitcoin. This is yet another crypto fund coming out to the market and validating ZEC as a clear expression of the privacy trade (Multicoin did this earlier this year). Shielded Bitcoin is an attempt to bring that privacy to Bitcoin itself. As it stands, users have to use other blockchains like Ethereum, Monero, Solana, or Zcash to achieve private digital transactions.
The day before the paper came out, Citrea, a Bitcoin L2 backed by Galaxy Ventures, acquired Crest, a private Bitcoin wallet. Citrea called this acquisition an attempt to “bring Zcash-style privacy to Bitcoin”.
This comes on the heels of NEAR pursuing the same demand for privacy. It recently announced confidential perps by default and confidential limit orders. NEAR is also +150% in the past month. The Zcash and NEAR narratives reinforce each other as well. The Zcash wallet ZODL is among the largest referral sources on NEAR Intents.
Our take
For most of this year and last year, Bitcoin maximalists scoffed at ZEC’s run. The common view among this group has been that it’s a “coordinated pump heading for a rug.” Maxis have been saying this since $200-$300, and the token has proceeded to 5x since then. Shielded Bitcoin gives that camp something to lean on. It’s a clever design and is a direct shot at the “private complement to Bitcoin” thesis now priced into ZEC, because it relies only on Bitcoin.
Likely the hardest part of the design isn’t in the paper, though. Peg-in and peg-out, the mechanisms that lock and release real BTC, are deferred to a future PIPEs v2 paper. (That’s PIPEs as in Polynomial Inner Product Encryption, not the mechanism DATs used to raise money.) The authors explicitly decline to claim that entry and exit are trustless or censorship-resistant, which really matters. Bridges have repeatedly been the most exploited component in crypto: Ronin, Wormhole, Nomad, KelpDAO, just to name a few. Novel ZK circuits also need to be battle tested; Zcash’s own Orchard Pool carried a soundness bug for four years through professional audits (which developers have since responded to with the Ironwood upgrade).
The design of Shielded Bitcoin also leans on Bitcoin Core v30’s looser OP_RETURN relay policy, the same change many maximalists fought hard against last year. Whichever architecture wins, the demand side of privacy in crypto looks more durable than in past cycles. This is partly due to the rapidly changing threat model.
Flock Safety is probably the clearest real-world example of privacy concerns. The company runs about 120,000 AI-enabled license-plate cameras across the U.S.
Critics argue the danger is in the network, since police can run algorithms across it to flag movement patterns as “suspicious”. After reports of officers abusing the system, the company cut its default data retention from 30 days to seven.
Transparent blockchains are global, permanent, and free for anyone to query. Clustering addresses onchain has been a mature capability for years. The bottleneck has always been linking an onchain public address to a real person’s identity, and AI advancements will likely remove this obstacle.
Earlier this year, researchers from ETH Zurich and Anthropic showed that LLM agents can re-identify pseudonymous Hacker News users with high precision from their profiles alone.
It’s not unreasonable to expect a future in which AI can use a tweeted transaction hash or one withdrawal from a KYC’d exchange to identify an individual's entire history of onchain activity. The blockchain never forgets.
Grayscale made this same argument when it launched ZCSH: as AI changes how financial activity can be monitored, demand for true financial privacy should only grow. The privacy trade is a response to surveillance getting more automated and permanent. We’ll be watching it closely. – Will Owens
CFTC ‘Mention Market’ Guidance Shows Challenge of Policing Novel Contracts
This week the Commodity Futures Trading Commission (CFTC) released guidance on mention markets, a subset of prediction markets that pertain to individuals’ speech, attendance at events, and interactions.
The advisory’s concern is that mention markets are fundamentally different from standard CFTC-approved event contracts, like “will the Fed hike rates in the next FOMC meeting?” These contracts settle on events that single individuals have little or no control over the outcome of the contract. Mention markets, on the other hand, are different in that they settle on “the discrete conduct of a named person,” such as “will Elon Musk say bitcoin on the next SpaceX earnings call?” As a result, the regulator’s Division of Market Oversight (DMO) notes, there is heightened risk in these markets under Core Principle 3, the statutory requirement that Designated Contract Markets (DCMs) list only contracts that are “not readily susceptible to manipulation.”
The DMO’s reasoning follows three risk vectors:
Ease of manipulation: the person controlling the outcome (or those close to them) can often trigger or avoid the triggering conduct at will.
Information asymmetry: insiders (event staff, scriptwriters, PR handlers) may have advance knowledge of what will happen, creating trading advantages.
Low detectability: when the triggering conduct happens in private, informal settings, or involves non-public figures, there's little independent verification or public scrutiny to catch manipulation.
In light of this, the DMO says Mention Markets should be treated as “presumptively readily susceptible to manipulation,” meaning DCMs face a higher bar to justify listing. The advisory details a four-factor scorecard DMO will use when a DCM files to list such contracts:
Independent obligations constraining the controlling individual
Susceptibility to manipulation through external pressure directed at controlling individuals
Independent verification and substantial public scrutiny.
Robustness of prophylactic trading rules, surveillance, and controls
The advisory says a DCM’s controls (factor 4) can’t be substituted with reliance on the market’s named individual’s own outside legal obligations (factor 1) and that exchanges still have to build their own safeguards.
Notably, the letter is purely informational and creates no binding rule, doesn’t reflect a formal Commission ruling, and does not prohibit DCMs from listing mention market contracts.
Our take
As, er, mentioned above, most CFTC-approved event contracts settle on outcomes single individuals cannot control (e.g. “will the Fed hike or cut?” or “who will win the 2028 presidential election?”). Mention markets are fundamentally different in this regard because they settle on the “discrete, voluntary conduct of a single named person” (e.g. “will Jensen Huang say 'data center' in Nvidia’s next earnings call?”). This creates a structural manipulation risk under Core Principle 3, which requires Designated Contract Markets (DCMs) to list only contracts that are not “readily susceptible to manipulation.”
The CFTC’s advisory addresses part of this risk as it relates to mention markets, but not all of it, without explicitly barring these markets. It’s not due to a lack of effort on the DMO staff’s part, but because the residual risk runs into constitutional protections and evidentiary standards which apply to these types of markets that a listing standard simply cannot resolve. Ther four-factor test functions largely as a transparency and market surveillance filter that can keep the least verifiable and low-scrutiny mention markets (e.g. a remark on a personal phone call or a comment at a closed-door dinner) off exchanges and monitor suspicious market activity. But for markets that do clear the bar (specifically ones around individual speech), verification and market oversight are solved without capturing the full “manipulability” picture. The market’s named individual can simply say the words for any reason, thereby “manipulating” the outcome. If they and those close to them don’t hold a position, they sit entirely outside the regulatory perimeter. The Commodity Exchange Act (CEA) manipulation liability attaches to conduct in connection with trading, and every control the advisory contemplates (i.e. restricted lists, position limits, surveillance, inducement rules) presumes the manipulator has an economic interest in the market or is coordinating with someone who does. A person with neither characteristic avoids all such controls.
Nor can that gap be closed prospectively, because the First Amendment prevents a DCM or the CFTC from writing a rule that would reach it; no one can require the named individual to avoid certain words, penalize them for saying them, or compel disclosure of what they intend to say. Someone who knows a mention market exists but has no economic exposure can still choose to say specific words that resolve the market one way or another. Someone who says the trigger phrase deliberately is indistinguishable from one who does so incidentally without proof of direct intent, which can be difficult to obtain in the case of speech.
As a whole, the controls outlined in the CFTC’s guidance can catch manipulation that runs through coordination and trading. But by nature of mention markets, they may struggle with cases where named individuals simply act on their own unprompted judgement. This point is one we made on Galaxy Brains in February. - Zack Pokorny
Other News
🚨 Bitget exchange’s hot wallet hacked for >$350m
🇺🇸💸 U.S. said to weigh plan to promote USD-backed stables abroad...
🪙 ... as Federal Reserve seeks comment on proposed GENIUS stablecoin rules
📄 CFTC sends crypto 'prerule’ to White House for review after Clarity Act fails...
❓ ... and updates FAQ on crypto and blockchain activities
🥊 Kalshi rebuts claims of wash trading on its ETH perpetuals market
🤝 Binance buys $100m CRCL stake (5% discount), will get monthly fee to promote USDC
🪖⚔️🗳️ Crypto super PAC Fairshake plans $30m ad campaign against Sherrod Brown
🏛️ NYSE and Blockchain.com to explore tokenized stocks
🙏 RIP former Hack VC partner Hsin-Ju Chuang, 37; “made industry feel inclusive”
Charts of the Week: BTC ETFs Get Back Into ‘Flow State’; 10Y Yield Soars
U.S. spot bitcoin ETPs took in $1b in net inflows Tuesday, the largest daily inflow of 2026. These inflows pushed the year-to-date net flows positive for the first time since April.
Meanwhile, the 10-year U.S. Treasury yield hit its highest level in nearly two decades, reflecting inflation fears and defying Secretary Scott Bessent's maneuvers to calm the market.
For more insights, follow @glxyresearch on X. – Alex Thorn and Thad Pinakiewicz
Legal Disclosure:
This document, and the information contained herein, has been provided to you by Galaxy Digital Inc. and its affiliates (“Galaxy Digital”) solely for informational purposes. This document may not be reproduced or redistributed in whole or in part, in any format, without the express written approval of Galaxy Digital. Neither the information, nor any opinion contained in this document, constitutes an offer to buy or sell, or a solicitation of an offer to buy or sell, any advisory services, securities, futures, options or other financial instruments or to participate in any advisory services or trading strategy. Nothing contained in this document constitutes investment, legal or tax advice or is an endorsement of any of the stablecoins mentioned herein. You should make your own investigations and evaluations of the information herein. Any decisions based on information contained in this document are the sole responsibility of the reader. Readers should consult with their own advisors and rely on their independent judgement when making financial or investment decisions.
Participants, along with Galaxy Digital, may hold financial interests in certain assets referenced in this content. Galaxy Digital regularly engages in buying and selling financial instruments, including through hedging transactions, for its own proprietary accounts and on behalf of its counterparties. Galaxy Digital also provides services to vehicles that invest in various asset classes. If the value of such assets increases, those vehicles may benefit, and Galaxy Digital’s service fees may increase accordingly. The information and analysis in this communication are based on technical, fundamental, and market considerations and do not represent a formal valuation. For more information, please refer to Galaxy’s public filings and statements. Certain asset classes discussed, including digital assets, may be volatile and involve risk, and actual market outcomes may differ materially from perspectives expressed here.
For additional risks related to digital assets, please refer to the risk factors contained in filings Galaxy Digital Inc. makes with the Securities and Exchange Commission (the “SEC”) from time to time, including in its Quarterly Report on Form 10-Q for the quarter ended September 30, 2025, filed with the SEC on November 10, 2025, available at www.sec.gov.
Certain statements in this document reflect Galaxy Digital’s views, estimates, opinions or predictions (which may be based on proprietary models and assumptions, including, in particular, Galaxy Digital’s views on the current and future market for certain digital assets), and there is no guarantee that these views, estimates, opinions or predictions are currently accurate or that they will be ultimately realized. To the extent these assumptions or models are not correct or circumstances change, the actual performance may vary substantially from, and be less than, the estimates included herein. None of Galaxy Digital nor any of its affiliates, shareholders, partners, members, directors, officers, management, employees or representatives makes any representation or warranty, express or implied, as to the accuracy or completeness of any of the information or any other information (whether communicated in written or oral form) transmitted or made available to you. Each of the aforementioned parties expressly disclaims any and all liability relating to or resulting from the use of this information. Certain information contained herein (including financial information) has been obtained from published and non-published sources. Such information has not been independently verified by Galaxy Digital and, Galaxy Digital, does not assume responsibility for the accuracy of such information. Affiliates of Galaxy Digital may have owned, hedged and sold or may own, hedge and sell investments in some of the digital assets, protocols, equities, or other financial instruments discussed in this document. Affiliates of Galaxy Digital may also lend to some of the protocols discussed in this document, the underlying collateral of which could be the native token subject to liquidation in the event of a margin call or closeout. The economic result of closing out the protocol loan could directly conflict with other Galaxy affiliates that hold investments in, and support, such token. Except where otherwise indicated, the information in this document is based on matters as they exist as of the date of preparation and not as of any future date, and will not be updated or otherwise revised to reflect information that subsequently becomes available, or circumstances existing or changes occurring after the date hereof. This document provides links to other Websites that we think might be of interest to you. Please note that when you click on one of these links, you may be moving to a provider’s website that is not associated with Galaxy Digital. These linked sites and their providers are not controlled by us, and we are not responsible for the contents or the proper operation of any linked site. The inclusion of any link does not imply our endorsement or our adoption of the statements therein. We encourage you to read the terms of use and privacy statements of these linked sites as their policies may differ from ours. The foregoing does not constitute a “research report” as defined by FINRA Rule 2241 or a “debt research report” as defined by FINRA Rule 2242 and was not prepared by Galaxy Digital Partners LLC. Similarly, the foregoing does not constitute a “research report” as defined by CFTC Regulation 23.605(a)(9) and was not prepared by Galaxy Derivatives LLC. For all inquiries, please email [email protected].
©Copyright Galaxy Digital Inc. 2026. All rights reserved.