skip to content

Research • September 04, 2026 • 20 mins

Weekly Research Brief: Get Ready for 24/7 Stock Markets

Plus: Nvidia embraces HuggingFace; the driver’s license debacle.

Welcome to Galaxy Research's Weekly Research Brief. Subscribe to get this newsletter delivered to your inbox every Friday morning.

This week, Thad Pinakiewicz breaks down the SEC’s proposal to modernize regulation of transfer agents; Lucas Tcheyan explains the ramifications of Nvidia’s deal to buy HuggingFace; and Marc Hochstein draws lessons from the data breach that leaked 153 million driver’s licenses.

Got feedback on this newsletter? Email [email protected]. We’d love to hear from you.

I Want to Trade Stocks in a Market That Doesn't Sleep: SEC Moves to Update Transfer Agent Rules

The Securities and Exchange Commission just took another big step toward modernizing the plumbing of the U.S. financial system from trading through settlement.

This week, the Commission proposed a sweeping update to the rules governing transfer agents—the firms responsible for maintaining issuers’ official ownership records, processing transfers and generally making sure that a share owned by Alice does not accidentally become two shares owned by Bob. Most of these rules have not been substantively updated since the late 1970s and early 1980s, when physical certificates and manual processing were still the default and “digital asset” had practically no meaning.

Meanwhile, the SEC is also preparing for its Sept. 17 roundtable on 24-hour trading. The agenda covers exchange and broker readiness, overnight surveillance, closing-price mechanics, clearing and settlement, expected liquidity, cybersecurity, staffing, market-data continuity and the eventual road from extended weekday trading toward a genuinely 24/7 market.

These sound like two separate projects (transfer-agent rules over here, trading hours over there), but they arrive at the same place. A market can only trade as continuously as its ownership records and its clearing, settlement, and compliance rails allow.

The pieces are already moving:

The market is already 24/7 in a way; you just have to know the right people or have a broker who will take overnight orders (for a fee of course). Investors can access alternative trading systems (ATSs) and broker platforms, but the consolidated national-market infrastructure that makes regular-session quotes and trades legible is not yet running overnight. The result is a patchwork rather than one cohesive market.

Our take

You might ask, “why are we not already there?” Talk to anyone at a bank or fund about what happens after the closing bell, and you’ll have your (likely frustrated) answer. Unless everything is happening inside one platform, or you have some of the best infrastructure money can buy, and sometimes even then, end-of-day processes still take time. Positions, cash, failed deliveries, and corporate actions all have to be reconciled across institutions. Someone’s ledger says one thing, someone else’s ledger says another, and several people spend the evening determining who owns what and where the human error occurred. Most of this is a vestige of decades of inefficiencies built up as the financial ecosystem evolved: different ledgers, different forms of securities, different custodians, different settlement systems, and an institutional structure in which everyone maintains a separate truth and then conducts a nightly séance to see whether the truths match.

Blockchains and common standards have spent more than a decade demonstrating how far shared state and programmable settlement can go toward solving that problem. Even the traditional incumbents are now proving the point. JPMorgan says its Kinexys currently processes roughly $7 billion per day and has processed more than $4 trillion since inception. It is largely private and permissioned, yes, but it is nevertheless a shared, programmable ledger operating at institutional scale. The important point is not the ideological purity of using a blockchain; it’s the overall efficiency increase of the entire financial system through common standards and platforms.

The proposed rule changes for TAs would recognize blockchain and distributed-ledger technology as expressly permitted recordkeeping media. To be fair, this was not necessarily prohibited before. The existing rules are explicitly technologically neutral, and that allowed transfer agents to argue with a straight face and some SEC staff guidance to back them up, that an onchain record satisfied their obligations.

Galaxy and our onchain transfer agent Superstate have done this with GLXY shares on Solana. Superstate, acting as the registered transfer agent, records legal ownership onchain in real time. Those shares are still restricted to verified investors and allowlisted wallets, so this is not yet permissionless stock composable throughout DeFi, but it demonstrates that the underlying model was already possible. The SEC’s proposal would close the distance between “our lawyers think this is permitted” and “the rulebook explicitly allows it.” Lawyers, after all, are very expensive consensus mechanisms. Consensus, rollback, and fork risks do not disappear; they become operational risks a TA has to control and document rather than reasons to not use blockchains at all.

The most interesting part comes from Commissioner Hester Peirce, who zeroed in on the proposal’s most heretical question (from a fed’s perspective):

Should transfer agents continue to be required to collect names and physical addresses of securityholders or should the rule allow other identifiers, such as email and digital wallet addresses, to be collected instead?

This must have started the most passive-aggressive email chain ever CC’d to the AML/KYC maxis, but it is a fascinating question.

Proponents for personal privacy would welcome the change, but it raises some difficult questions given the pastiche of securities regulation we are currently saddled with.

Can tokenized stocks be bearer assets? The obvious analogy to bearer bonds is imperfect but useful here. With a true bearer instrument, possession is the be-all and end-all (just ask Hans Gruber what he was looking for in Nakatomi Plaza). Congress largely tax-nuked U.S. bearer issuance decades ago, rather than pretending that the concept was metaphysically impossible and declaring them illegal. Not all tokenized stocks are, or should be, bearer instruments. But for one that is designed to travel in a bearer-like manner, a public wallet address is strictly more information than an issuer would have in a true bearer model. It is persistent, observable, and auditable. It is not the same thing as knowing the human being behind it, but it is also not “no information.”

Then come the fun follow-on questions. What happens when one wallet, or 20 wallets controlled by the same person, crosses the 5% beneficial-ownership threshold? A wallet address does not file a Schedule 13D or 13G. The person controlling it does. Cross 10% and the Section 16 reporting regime enters the chat as well. Presumably identity could remain private at ordinary ownership levels and be revealed when a statutory threshold is crossed, but somebody still needs a defensible method for aggregating addresses under common control.

And what exactly constitutes control? A private key? A multisig signatory? A smart contract? An account held through a custodian? A DAO vote? A wallet managed by an adviser but economically owned by a client? These have been thorny questions for DAO designers and governance-token architects; how do you differentiate aligned voters from a cluster of wallets controlled by one entity without explicit lines of ownership? Taking these questions to their logical extremes outlines the points where there is an obvious break with other regulations.

Then there is a bigger issue. If a wallet address can be the registered holder, and an address is all that is required for the TA’s ownership record, could issuer-sponsored tokenized shares eventually move away from closed, whitelisted systems and circulate freely on public networks, the way xStocks and other SPV stock wrappers like Robinhood’s Euro stocks do?

The SEC has already made clear that putting a security onchain does not alter the application of the securities laws. Beneficial-ownership reporting, transfer restrictions, sanctions controls and the broader BSA/KYC stack surrounding brokers, custodians and regulated financial institutions will not evaporate because the certificate became a token. On the other hand, the proposal itself asks whether requiring full names and physical addresses creates unnecessary unauthorized-disclosure risk. There is an enormous policy gap between “a blockchain may maintain the ownership record” and “any anonymous wallet may freely receive the security.” Still, changing the transfer agent rule would matter. It could reduce the amount of personally identifiable information parked in centralized, breachable databases.

The benefits of automated, standardized settlement systems built on blockchains and open protocols are increasingly compelling. For people who don’t care about settlement and think around-the-clock markets are useful only for degenerate behavior, read the research on overnight returns varying statistically from market hours. Material information arrives while the primary exchanges are closed, and overnight price changes are meaningfully driven by that information (this was explicitly addressed in the SEC’s August release on overnight price bands). A closed exchange does not create informational silence; it creates a division between investors who can access OTC or alternative venues and investors who cannot.

This proposal lays the groundwork for the sober version of what DeFi has been trying to do for years. Letting more investors trade nearly around the clock, and eventually 24/7, should compress the rents charged by brokers "finding" overnight liquidity, commodifying more basic financial functions. It will not eliminate intermediation, but it can force middlemen to compete on service and cost rather than mere access.

Information flow does not stop when markets are closed. Right now, the only thing a closed market does is let privileged firms access the OTC markets. The regulations are now, finally, catching up. Onward and upward. –Thad Pinakiewicz

Nvidia Takes Hugging Face Into its Embrace with Acquisition Deal

On Thursday, Nvidia announced it had agreed to acquire Hugging Face, often described as the “GitHub for AI,” for $12.93 billion. CEO Jensen Huang said Nvidia would “scale Hugging Face’s platform, strengthen its infrastructure and expand access to AI,” and pledged that “Hugging Face will remain an open platform for the entire AI ecosystem.” The deal is expected to close in the first half of 2027 pending regulatory approval.

Nvidia participated in Hugging Face’s 2023 Series D at a $4.5 billion valuation. Last year, however, Hugging Face rejected a further $500 million Nvidia investment at a $7 billion valuation, saying it did not want to compromise the platform’s neutrality. That stance flipped this summer after Hugging Face entertained bids amid interest from other parties, reportedly including Salesforce and Microsoft.

Hugging Face CEO Clément Delangue said open-source AI has reached an inflection point and needs more compute, support, and visibility. The founders and the team would stay on after the acquisition and remain on the Hugging Face brand.

Our take

Nvidia is evolving from the world’s leading GPU producer into a company with offerings across nearly every layer of its self-described AI “5-Layer Cake” that includes energy, chips, infrastructure, models, and applications. Hugging Face sits at the model and application level, but Nvidia recently made forays into the infrastructure level with its push to make “AI factories” repeatable and financeable, including efforts to mobilize more than $500 billion capital for compute infrastructure.

The acquisition is both defensive and offensive. OpenAI, Anthropic, Google, Meta, and Microsoft are all building or buying custom accelerator chips to reduce reliance on Nvidia GPUs. Owning the default home where open models are published helps mitigate the fallout from accelerators’ adoption. Even if frontier training moves off Nvidia chips, a large share of fine-tunes, agents, forks, and apps will still route through Hugging Face.

The offensive case is about optimization rather than lock-in. Nvidia's position no longer rests on its CUDA platform being hard to leave, because models handle much of that porting work now and Nvidia does performance engineering directly alongside the frontier labs. Hugging Face adds distribution. Nvidia can optimize a popular open model for its own runtimes the week it's published and make that the default path a developer sees, without ever requiring its chips.

The acquisition lands at a sensitive moment for open-weight adoption as U.S. policy makers consider how to regulate them. Open models now account for a larger share of AI token use on leading routing platforms like OpenRouter, with Chinese labs dominating adoption. Nvidia has been a consistent contributor and advocate of open-source AI and stepped up its efforts significantly in the past year. It is already one of the largest publishers on Hugging Face, where it shipped Nemotron and other open model families, and in August acquired a non-exclusive license to Poolside’s Model Factory. On the policy front, in July Nvidia co-signed an open letter, “Open Weights and American AI Leadership,” urging policymakers not to restrict open-weight development and use. Buying Hugging Face lets Nvidia argue that American open infrastructure, not a ban, is the right answer to Chinese dominance. It also gives Nvidia a tighter loop for improving its own open-weight stack to better compete with today’s leaders.

The biggest criticism of the deal so far is the threat to neutrality. In its 8-K filing announcing the acquisition, Nvidia’s says it will keep the platform open, “consistent with existing practices,” continue to allow model makers and users to upload and download models and datasets of their choosing, and continue to support other hardware vendors. Nvidia compute will not be required to build on or deploy through Hugging Face. Delangue’s announcement of the acquisition reinforced this view, saying Nvidia committed to keeping the platform “open, independent and compute agnostic.” Still, bringing the hub in-house still improves Nvidia’s ability to shape search, evals, recommended runtimes, and enterprise defaults in ways that benefit Nvidia offerings. Even if the terms of service never change, the commercial logic is straightforward. More accessible open models mean more fine-tuning and inference, which in turn means more demand for Nvidia chips and the software stack that makes those chips usable. –Lucas Tcheyan

Driver’s License Dump Lays Bare Hazards of Data Hoarding

More than 153 million American and Canadian driver’s licenses were exposed in an apparent data breach of a widely used identity verification service, cybersecurity researcher Brian Krebs reported Tuesday.

Krebs learned about the incident because his license was compromised. A dark web vendor known as Nexus was offering it as a free sample of the 170 million stolen records it was selling on a Russian forum. Aside from scans of licenses (including U.S. Secretary of War Pete Hegseth’s), the trove included identification cards, medical cards, and travel documents.

The FBI (whose assistant director’s license was also exposed) has opened an investigation, Krebs and Reuters reported. Shortly after Krebs posted his article, Nexus' website disappeared.

Another victim was his mother. Both had shared their licenses with the Hertz car rental service, as did three other people whose data was compromised. Yet another scanned his license at a marijuana dispensary that had something in common with Hertz: IDScan.net, the verification service, listed both as clients.

IDScan told Krebs it was investigating the matter. As of writing, the company had not issued a detailed statement.

A third IDScan client, bank technology vendor Jack Henry & Associates, disclosed a cybersecurity incident Monday. “Based on our investigation to date, personally identifiable information (PII) data for fewer than 10 clients was impacted,” Jack Henry said. (Its clients are banks, not their customers.)

That incident, which involved voice phising and an extortion attempt, may be unrelated to the one Krebs reported. A Jack Henry spokesman told Galaxy Research: “While we use one IDScan.net product in our OpenAnywhere digital deposit account opening platform as an optional feature, we have been notified by IDScan.net that this specific product is not impacted. We are actively monitoring the situation and keeping our clients informed.”

Other IDScan clients include the U.S. Coast Guard, FedEx, Motorola Solutions, and Caesars Entertainment, according to a screengrab in Krebs' report.

The IDScan breach would rank among the top 20 in U.S. history by number of records leaked, according to data from cyber risk management firm UpGuard. It’s on par with the 2017 Equifax incident, which exposed sensitive data of 147 million U.S. and 15 million U.K. consumers.

Our take

This debacle underscores a message that cryptocurrency and cybersecurity community members have been shouting from the rooftops for years: data is a liability.

In a comment letter to the U.S. Treasury last year, we explained:

U.S. citizens are required to share copious amounts of personally identifiable information (PII) with strangers on a daily basis, simply to get by. Even to purchase cold medicine at the drugstore, Americans have to scan their driver’s licenses. Each time a consumer entrusts PII to a business, they widen the attack surface for would-be identity thieves. ... Promiscuous data collection turns businesses into “honeypots,” irresistible targets for hackers.

Many businesses need to learn something about their customers. A car rental service needs to know you are fit to drive. A dispensary or casino needs to know you’re of legal age. Financial institutions, famously, are required by law to “know your customer” (KYC).

PII should be handled with care, if at all. Businesses should collect only the data they absolutely need to operate and dispose of it as soon as they legally can. While that’s standard practice, many organizations cut corners.

Whenever data is retained, access should be locked down tight. Last year, Coinbase disclosed that nearly 70,000 of its customers’ sensitive details were leaked. Criminals obtained this information by bribing contractors and employees outside the U.S. with access to Coinbase’s systems, the company said.

Long term, we remain optimistic about zero-knowledge proofs’ potential to reduce data hoarding. “ZKP makes it possible for people to prove that something about them is true without exchanging any other data,” explained Alan Stapelberg, group product manager for Google Wallet, in a blog last year. “For example, a person visiting a website can verifiably prove he or she is over 18, without sharing anything else at all” – a feature Google added to its digital wallet.

Historically, ZKPs were slow and expensive to run, but they’re constantly improving. For example, the average cost of proving on the Ethereum blockchain steadily declined over the last 90 days, and latency generally held below a 10-second target:

ethproofs image
Source: Ethproofs.org

Still, adoption is slow. Several apps (Zkpassport, Zpass, Rarimo) can scan a passport and spit out a proof attesting to an attribute (“at least 21 years old”; “not a North Korean national”) without doxxing the user. They face a chicken-and-egg problem: consumers have little incentive to download apps few businesses accept, and businesses have little incentive to accept forms of identification few consumers carry.

It's easy to despair. The Nexus hacker asked only $100 for Hegseth’s ID, suggesting stolen PII is so abundant it sells dirt cheap. But the worst thing to do would be to downplay this breach because “it's already out there.” Attackers can cause orders of magnitude more damage than the data costs.

We agree with Peter van Valkenburgh, executive director of crypto advocacy group Coin Center, who wrote in response to the driver’s license breach: “You should be mad. We are long, long, long overdue to reduce the amount of KYC we do as a society.” Don’t be complacent; demand better alternatives and support the developers building them. – Marc Hochstein

Other News

Chart of the Week: Terminal Takeover

Trading terminal volume has gone vertical since the start of the summer.

Back in June, weekly aggregate swap volume routed through onchain terminals (including FOMO, GMGN, Axiom, Pump.fun app, Terminal, Trojan, Photon, BullX, BonkBot, BasedBot, and Maestro) was ~$500m. It’s now pushing ~$4b. That’s roughly an 8x increase in less than three months. Robinhood Chain has seen massive success with tokenized equity-memecoin pairs and is driving user activity.

Trading terminal weekly volume by chain

Terminals also just cleared $1b in a single day. That’s the first billion-dollar trading terminal volume day since January 2025. As a reminder, that earlier spike was driven by the president of the United States launching a memecoin on Solana. – Will Owens

Trading Terminal daily volume

You are leaving Galaxy.com

You are leaving the Galaxy website and being directed to an external third-party website that we think might be of interest to you. Third-party websites are not under the control of Galaxy, and Galaxy is not responsible for the accuracy or completeness of the contents or the proper operation of any linked site. Please note the security and privacy policies on third-party websites differ from Galaxy policies, please read third-party privacy and security policies closely. If you do not wish to continue to the third-party site, click “Cancel”. The inclusion of any linked website does not imply Galaxy’s endorsement or adoption of the statements therein and is only provided for your convenience.