Welcome to Galaxy Research's Weekly Research Brief. Subscribe to get this newsletter delivered to your inbox every Friday morning.
This week, Thad Pinakiewicz breaks down the SEC’s proposal to modernize regulation of transfer agents; Lucas Tcheyan explains the ramifications of Nvidia’s deal to buy HuggingFace; and Marc Hochstein draws lessons from the data breach that leaked 153 million driver’s licenses.
Got feedback on this newsletter? Email [email protected]. We’d love to hear from you.
I Want to Trade Stocks in a Market That Doesn't Sleep: SEC Moves to Update Transfer Agent Rules
The Securities and Exchange Commission just took another big step toward modernizing the plumbing of the U.S. financial system from trading through settlement.
This week, the Commission proposed a sweeping update to the rules governing transfer agents—the firms responsible for maintaining issuers’ official ownership records, processing transfers and generally making sure that a share owned by Alice does not accidentally become two shares owned by Bob. Most of these rules have not been substantively updated since the late 1970s and early 1980s, when physical certificates and manual processing were still the default and “digital asset” had practically no meaning.
Meanwhile, the SEC is also preparing for its Sept. 17 roundtable on 24-hour trading. The agenda covers exchange and broker readiness, overnight surveillance, closing-price mechanics, clearing and settlement, expected liquidity, cybersecurity, staffing, market-data continuity and the eventual road from extended weekday trading toward a genuinely 24/7 market.
These sound like two separate projects (transfer-agent rules over here, trading hours over there), but they arrive at the same place. A market can only trade as continuously as its ownership records and its clearing, settlement, and compliance rails allow.
The pieces are already moving:
On June 26, the SEC approved expanded operating hours for the consolidated stock-market data feeds from 9:00 p.m. Sunday through 8:00 p.m. Friday, with a one-hour technical pause each weeknight.
On June 29, DTCC’s NSCC went live with 24x5 clearing, operating from Sunday evening through Friday evening.
On Aug. 5, the SEC approved temporary overnight price bands. Unlike daytime Limit Up–Limit Down rules, hitting the overnight band will not automatically trigger a trading pause.
On Dec. 6, FINRA’s Trade Reporting Facilities are scheduled to extend their hours to match the broader overnight-market rollout.
The market is already 24/7 in a way; you just have to know the right people or have a broker who will take overnight orders (for a fee of course). Investors can access alternative trading systems (ATSs) and broker platforms, but the consolidated national-market infrastructure that makes regular-session quotes and trades legible is not yet running overnight. The result is a patchwork rather than one cohesive market.
Our take
You might ask, “why are we not already there?” Talk to anyone at a bank or fund about what happens after the closing bell, and you’ll have your (likely frustrated) answer. Unless everything is happening inside one platform, or you have some of the best infrastructure money can buy, and sometimes even then, end-of-day processes still take time. Positions, cash, failed deliveries, and corporate actions all have to be reconciled across institutions. Someone’s ledger says one thing, someone else’s ledger says another, and several people spend the evening determining who owns what and where the human error occurred. Most of this is a vestige of decades of inefficiencies built up as the financial ecosystem evolved: different ledgers, different forms of securities, different custodians, different settlement systems, and an institutional structure in which everyone maintains a separate truth and then conducts a nightly séance to see whether the truths match.
Blockchains and common standards have spent more than a decade demonstrating how far shared state and programmable settlement can go toward solving that problem. Even the traditional incumbents are now proving the point. JPMorgan says its Kinexys currently processes roughly $7 billion per day and has processed more than $4 trillion since inception. It is largely private and permissioned, yes, but it is nevertheless a shared, programmable ledger operating at institutional scale. The important point is not the ideological purity of using a blockchain; it’s the overall efficiency increase of the entire financial system through common standards and platforms.
The proposed rule changes for TAs would recognize blockchain and distributed-ledger technology as expressly permitted recordkeeping media. To be fair, this was not necessarily prohibited before. The existing rules are explicitly technologically neutral, and that allowed transfer agents to argue with a straight face and some SEC staff guidance to back them up, that an onchain record satisfied their obligations.
Galaxy and our onchain transfer agent Superstate have done this with GLXY shares on Solana. Superstate, acting as the registered transfer agent, records legal ownership onchain in real time. Those shares are still restricted to verified investors and allowlisted wallets, so this is not yet permissionless stock composable throughout DeFi, but it demonstrates that the underlying model was already possible. The SEC’s proposal would close the distance between “our lawyers think this is permitted” and “the rulebook explicitly allows it.” Lawyers, after all, are very expensive consensus mechanisms. Consensus, rollback, and fork risks do not disappear; they become operational risks a TA has to control and document rather than reasons to not use blockchains at all.
The most interesting part comes from Commissioner Hester Peirce, who zeroed in on the proposal’s most heretical question (from a fed’s perspective):
This must have started the most passive-aggressive email chain ever CC’d to the AML/KYC maxis, but it is a fascinating question.
Proponents for personal privacy would welcome the change, but it raises some difficult questions given the pastiche of securities regulation we are currently saddled with.
Can tokenized stocks be bearer assets? The obvious analogy to bearer bonds is imperfect but useful here. With a true bearer instrument, possession is the be-all and end-all (just ask Hans Gruber what he was looking for in Nakatomi Plaza). Congress largely tax-nuked U.S. bearer issuance decades ago, rather than pretending that the concept was metaphysically impossible and declaring them illegal. Not all tokenized stocks are, or should be, bearer instruments. But for one that is designed to travel in a bearer-like manner, a public wallet address is strictly more information than an issuer would have in a true bearer model. It is persistent, observable, and auditable. It is not the same thing as knowing the human being behind it, but it is also not “no information.”
Then come the fun follow-on questions. What happens when one wallet, or 20 wallets controlled by the same person, crosses the 5% beneficial-ownership threshold? A wallet address does not file a Schedule 13D or 13G. The person controlling it does. Cross 10% and the Section 16 reporting regime enters the chat as well. Presumably identity could remain private at ordinary ownership levels and be revealed when a statutory threshold is crossed, but somebody still needs a defensible method for aggregating addresses under common control.
And what exactly constitutes control? A private key? A multisig signatory? A smart contract? An account held through a custodian? A DAO vote? A wallet managed by an adviser but economically owned by a client? These have been thorny questions for DAO designers and governance-token architects; how do you differentiate aligned voters from a cluster of wallets controlled by one entity without explicit lines of ownership? Taking these questions to their logical extremes outlines the points where there is an obvious break with other regulations.
Then there is a bigger issue. If a wallet address can be the registered holder, and an address is all that is required for the TA’s ownership record, could issuer-sponsored tokenized shares eventually move away from closed, whitelisted systems and circulate freely on public networks, the way xStocks and other SPV stock wrappers like Robinhood’s Euro stocks do?
The SEC has already made clear that putting a security onchain does not alter the application of the securities laws. Beneficial-ownership reporting, transfer restrictions, sanctions controls and the broader BSA/KYC stack surrounding brokers, custodians and regulated financial institutions will not evaporate because the certificate became a token. On the other hand, the proposal itself asks whether requiring full names and physical addresses creates unnecessary unauthorized-disclosure risk. There is an enormous policy gap between “a blockchain may maintain the ownership record” and “any anonymous wallet may freely receive the security.” Still, changing the transfer agent rule would matter. It could reduce the amount of personally identifiable information parked in centralized, breachable databases.
The benefits of automated, standardized settlement systems built on blockchains and open protocols are increasingly compelling. For people who don’t care about settlement and think around-the-clock markets are useful only for degenerate behavior, read the research on overnight returns varying statistically from market hours. Material information arrives while the primary exchanges are closed, and overnight price changes are meaningfully driven by that information (this was explicitly addressed in the SEC’s August release on overnight price bands). A closed exchange does not create informational silence; it creates a division between investors who can access OTC or alternative venues and investors who cannot.
This proposal lays the groundwork for the sober version of what DeFi has been trying to do for years. Letting more investors trade nearly around the clock, and eventually 24/7, should compress the rents charged by brokers "finding" overnight liquidity, commodifying more basic financial functions. It will not eliminate intermediation, but it can force middlemen to compete on service and cost rather than mere access.
Information flow does not stop when markets are closed. Right now, the only thing a closed market does is let privileged firms access the OTC markets. The regulations are now, finally, catching up. Onward and upward. –Thad Pinakiewicz
Nvidia Takes Hugging Face Into its Embrace with Acquisition Deal
On Thursday, Nvidia announced it had agreed to acquire Hugging Face, often described as the “GitHub for AI,” for $12.93 billion. CEO Jensen Huang said Nvidia would “scale Hugging Face’s platform, strengthen its infrastructure and expand access to AI,” and pledged that “Hugging Face will remain an open platform for the entire AI ecosystem.” The deal is expected to close in the first half of 2027 pending regulatory approval.
Nvidia participated in Hugging Face’s 2023 Series D at a $4.5 billion valuation. Last year, however, Hugging Face rejected a further $500 million Nvidia investment at a $7 billion valuation, saying it did not want to compromise the platform’s neutrality. That stance flipped this summer after Hugging Face entertained bids amid interest from other parties, reportedly including Salesforce and Microsoft.
Hugging Face CEO Clément Delangue said open-source AI has reached an inflection point and needs more compute, support, and visibility. The founders and the team would stay on after the acquisition and remain on the Hugging Face brand.
Our take
Nvidia is evolving from the world’s leading GPU producer into a company with offerings across nearly every layer of its self-described AI “5-Layer Cake” that includes energy, chips, infrastructure, models, and applications. Hugging Face sits at the model and application level, but Nvidia recently made forays into the infrastructure level with its push to make “AI factories” repeatable and financeable, including efforts to mobilize more than $500 billion capital for compute infrastructure.
The acquisition is both defensive and offensive. OpenAI, Anthropic, Google, Meta, and Microsoft are all building or buying custom accelerator chips to reduce reliance on Nvidia GPUs. Owning the default home where open models are published helps mitigate the fallout from accelerators’ adoption. Even if frontier training moves off Nvidia chips, a large share of fine-tunes, agents, forks, and apps will still route through Hugging Face.
The offensive case is about optimization rather than lock-in. Nvidia's position no longer rests on its CUDA platform being hard to leave, because models handle much of that porting work now and Nvidia does performance engineering directly alongside the frontier labs. Hugging Face adds distribution. Nvidia can optimize a popular open model for its own runtimes the week it's published and make that the default path a developer sees, without ever requiring its chips.
The acquisition lands at a sensitive moment for open-weight adoption as U.S. policy makers consider how to regulate them. Open models now account for a larger share of AI token use on leading routing platforms like OpenRouter, with Chinese labs dominating adoption. Nvidia has been a consistent contributor and advocate of open-source AI and stepped up its efforts significantly in the past year. It is already one of the largest publishers on Hugging Face, where it shipped Nemotron and other open model families, and in August acquired a non-exclusive license to Poolside’s Model Factory. On the policy front, in July Nvidia co-signed an open letter, “Open Weights and American AI Leadership,” urging policymakers not to restrict open-weight development and use. Buying Hugging Face lets Nvidia argue that American open infrastructure, not a ban, is the right answer to Chinese dominance. It also gives Nvidia a tighter loop for improving its own open-weight stack to better compete with today’s leaders.
The biggest criticism of the deal so far is the threat to neutrality. In its 8-K filing announcing the acquisition, Nvidia’s says it will keep the platform open, “consistent with existing practices,” continue to allow model makers and users to upload and download models and datasets of their choosing, and continue to support other hardware vendors. Nvidia compute will not be required to build on or deploy through Hugging Face. Delangue’s announcement of the acquisition reinforced this view, saying Nvidia committed to keeping the platform “open, independent and compute agnostic.” Still, bringing the hub in-house still improves Nvidia’s ability to shape search, evals, recommended runtimes, and enterprise defaults in ways that benefit Nvidia offerings. Even if the terms of service never change, the commercial logic is straightforward. More accessible open models mean more fine-tuning and inference, which in turn means more demand for Nvidia chips and the software stack that makes those chips usable. –Lucas Tcheyan
Driver’s License Dump Lays Bare Hazards of Data Hoarding
More than 153 million American and Canadian driver’s licenses were exposed in an apparent data breach of a widely used identity verification service, cybersecurity researcher Brian Krebs reported Tuesday.
Krebs learned about the incident because his license was compromised. A dark web vendor known as Nexus was offering it as a free sample of the 170 million stolen records it was selling on a Russian forum. Aside from scans of licenses (including U.S. Secretary of War Pete Hegseth’s), the trove included identification cards, medical cards, and travel documents.
The FBI (whose assistant director’s license was also exposed) has opened an investigation, Krebs and Reuters reported. Shortly after Krebs posted his article, Nexus' website disappeared.
Another victim was his mother. Both had shared their licenses with the Hertz car rental service, as did three other people whose data was compromised. Yet another scanned his license at a marijuana dispensary that had something in common with Hertz: IDScan.net, the verification service, listed both as clients.
IDScan told Krebs it was investigating the matter. As of writing, the company had not issued a detailed statement.
A third IDScan client, bank technology vendor Jack Henry & Associates, disclosed a cybersecurity incident Monday. “Based on our investigation to date, personally identifiable information (PII) data for fewer than 10 clients was impacted,” Jack Henry said. (Its clients are banks, not their customers.)
That incident, which involved voice phising and an extortion attempt, may be unrelated to the one Krebs reported. A Jack Henry spokesman told Galaxy Research: “While we use one IDScan.net product in our OpenAnywhere digital deposit account opening platform as an optional feature, we have been notified by IDScan.net that this specific product is not impacted. We are actively monitoring the situation and keeping our clients informed.”
Other IDScan clients include the U.S. Coast Guard, FedEx, Motorola Solutions, and Caesars Entertainment, according to a screengrab in Krebs' report.
The IDScan breach would rank among the top 20 in U.S. history by number of records leaked, according to data from cyber risk management firm UpGuard. It’s on par with the 2017 Equifax incident, which exposed sensitive data of 147 million U.S. and 15 million U.K. consumers.
Our take
This debacle underscores a message that cryptocurrency and cybersecurity community members have been shouting from the rooftops for years: data is a liability.
In a comment letter to the U.S. Treasury last year, we explained:
U.S. citizens are required to share copious amounts of personally identifiable information (PII) with strangers on a daily basis, simply to get by. Even to purchase cold medicine at the drugstore, Americans have to scan their driver’s licenses. Each time a consumer entrusts PII to a business, they widen the attack surface for would-be identity thieves. ... Promiscuous data collection turns businesses into “honeypots,” irresistible targets for hackers.
Many businesses need to learn something about their customers. A car rental service needs to know you are fit to drive. A dispensary or casino needs to know you’re of legal age. Financial institutions, famously, are required by law to “know your customer” (KYC).
PII should be handled with care, if at all. Businesses should collect only the data they absolutely need to operate and dispose of it as soon as they legally can. While that’s standard practice, many organizations cut corners.
Whenever data is retained, access should be locked down tight. Last year, Coinbase disclosed that nearly 70,000 of its customers’ sensitive details were leaked. Criminals obtained this information by bribing contractors and employees outside the U.S. with access to Coinbase’s systems, the company said.
Long term, we remain optimistic about zero-knowledge proofs’ potential to reduce data hoarding. “ZKP makes it possible for people to prove that something about them is true without exchanging any other data,” explained Alan Stapelberg, group product manager for Google Wallet, in a blog last year. “For example, a person visiting a website can verifiably prove he or she is over 18, without sharing anything else at all” – a feature Google added to its digital wallet.
Historically, ZKPs were slow and expensive to run, but they’re constantly improving. For example, the average cost of proving on the Ethereum blockchain steadily declined over the last 90 days, and latency generally held below a 10-second target:
Still, adoption is slow. Several apps (Zkpassport, Zpass, Rarimo) can scan a passport and spit out a proof attesting to an attribute (“at least 21 years old”; “not a North Korean national”) without doxxing the user. They face a chicken-and-egg problem: consumers have little incentive to download apps few businesses accept, and businesses have little incentive to accept forms of identification few consumers carry.
It's easy to despair. The Nexus hacker asked only $100 for Hegseth’s ID, suggesting stolen PII is so abundant it sells dirt cheap. But the worst thing to do would be to downplay this breach because “it's already out there.” Attackers can cause orders of magnitude more damage than the data costs.
We agree with Peter van Valkenburgh, executive director of crypto advocacy group Coin Center, who wrote in response to the driver’s license breach: “You should be mad. We are long, long, long overdue to reduce the amount of KYC we do as a society.” Don’t be complacent; demand better alternatives and support the developers building them. – Marc Hochstein
Other News
📅 House Republicans set to cut pre-election session short (bearish for CLARITY)
⚖️ N.J. AG asks Supreme Court to take up prediction market regulation case...
🛢️ ... as Kalshi seeks approval to list perpetual futures on oil prices....
🧑⚖️ ... and CFTC asks judge to dismiss CME lawsuit over crypto perps
🤖 ‘Welcome to the AGI era,’ OpenAI says as GPT-6 Astra model debuts
📈 Coinbase working to bring single-stock perps to the U.S.
☁️ Anthropic said to sign $35b, 350mw cloud deal with Nvidia-backed Lambda...
⚡... as Texas approves first ultra-high-voltage 765-k transmission lines
🐈 Hyperliquid said to be in talks with Kraken parent on U.S. market entry
🙄 Memecoin with unprintable name corners half tokenized Hims & Hers float
Chart of the Week: Terminal Takeover
Trading terminal volume has gone vertical since the start of the summer.
Back in June, weekly aggregate swap volume routed through onchain terminals (including FOMO, GMGN, Axiom, Pump.fun app, Terminal, Trojan, Photon, BullX, BonkBot, BasedBot, and Maestro) was ~$500m. It’s now pushing ~$4b. That’s roughly an 8x increase in less than three months. Robinhood Chain has seen massive success with tokenized equity-memecoin pairs and is driving user activity.
Terminals also just cleared $1b in a single day. That’s the first billion-dollar trading terminal volume day since January 2025. As a reminder, that earlier spike was driven by the president of the United States launching a memecoin on Solana. – Will Owens
Legal Disclosure:
This document, and the information contained herein, has been provided to you by Galaxy Digital Inc. and its affiliates (“Galaxy Digital”) solely for informational purposes. This document may not be reproduced or redistributed in whole or in part, in any format, without the express written approval of Galaxy Digital. Neither the information, nor any opinion contained in this document, constitutes an offer to buy or sell, or a solicitation of an offer to buy or sell, any advisory services, securities, futures, options or other financial instruments or to participate in any advisory services or trading strategy. Nothing contained in this document constitutes investment, legal or tax advice or is an endorsement of any of the stablecoins mentioned herein. You should make your own investigations and evaluations of the information herein. Any decisions based on information contained in this document are the sole responsibility of the reader. Readers should consult with their own advisors and rely on their independent judgement when making financial or investment decisions.
Participants, along with Galaxy Digital, may hold financial interests in certain assets referenced in this content. Galaxy Digital regularly engages in buying and selling financial instruments, including through hedging transactions, for its own proprietary accounts and on behalf of its counterparties. Galaxy Digital also provides services to vehicles that invest in various asset classes. If the value of such assets increases, those vehicles may benefit, and Galaxy Digital’s service fees may increase accordingly. The information and analysis in this communication are based on technical, fundamental, and market considerations and do not represent a formal valuation. For more information, please refer to Galaxy’s public filings and statements. Certain asset classes discussed, including digital assets, may be volatile and involve risk, and actual market outcomes may differ materially from perspectives expressed here.
For additional risks related to digital assets, please refer to the risk factors contained in filings Galaxy Digital Inc. makes with the Securities and Exchange Commission (the “SEC”) from time to time, including in its Quarterly Report on Form 10-Q for the quarter ended September 30, 2025, filed with the SEC on November 10, 2025, available at www.sec.gov.
Certain statements in this document reflect Galaxy Digital’s views, estimates, opinions or predictions (which may be based on proprietary models and assumptions, including, in particular, Galaxy Digital’s views on the current and future market for certain digital assets), and there is no guarantee that these views, estimates, opinions or predictions are currently accurate or that they will be ultimately realized. To the extent these assumptions or models are not correct or circumstances change, the actual performance may vary substantially from, and be less than, the estimates included herein. None of Galaxy Digital nor any of its affiliates, shareholders, partners, members, directors, officers, management, employees or representatives makes any representation or warranty, express or implied, as to the accuracy or completeness of any of the information or any other information (whether communicated in written or oral form) transmitted or made available to you. Each of the aforementioned parties expressly disclaims any and all liability relating to or resulting from the use of this information. Certain information contained herein (including financial information) has been obtained from published and non-published sources. Such information has not been independently verified by Galaxy Digital and, Galaxy Digital, does not assume responsibility for the accuracy of such information. Affiliates of Galaxy Digital may have owned, hedged and sold or may own, hedge and sell investments in some of the digital assets, protocols, equities, or other financial instruments discussed in this document. Affiliates of Galaxy Digital may also lend to some of the protocols discussed in this document, the underlying collateral of which could be the native token subject to liquidation in the event of a margin call or closeout. The economic result of closing out the protocol loan could directly conflict with other Galaxy affiliates that hold investments in, and support, such token. Except where otherwise indicated, the information in this document is based on matters as they exist as of the date of preparation and not as of any future date, and will not be updated or otherwise revised to reflect information that subsequently becomes available, or circumstances existing or changes occurring after the date hereof. This document provides links to other Websites that we think might be of interest to you. Please note that when you click on one of these links, you may be moving to a provider’s website that is not associated with Galaxy Digital. These linked sites and their providers are not controlled by us, and we are not responsible for the contents or the proper operation of any linked site. The inclusion of any link does not imply our endorsement or our adoption of the statements therein. We encourage you to read the terms of use and privacy statements of these linked sites as their policies may differ from ours. The foregoing does not constitute a “research report” as defined by FINRA Rule 2241 or a “debt research report” as defined by FINRA Rule 2242 and was not prepared by Galaxy Digital Partners LLC. Similarly, the foregoing does not constitute a “research report” as defined by CFTC Regulation 23.605(a)(9) and was not prepared by Galaxy Derivatives LLC. For all inquiries, please email [email protected].
©Copyright Galaxy Digital Inc. 2026. All rights reserved.