skip to content

Weekly Research Brief: SEC Scrambles to Act as CLARITY Fizzles

Weekly Top Stories

Welcome to Galaxy Research's Weekly Top Stories. Subscribe to get this newsletter delivered to your inbox every Friday morning.

In this week's edition, Alex Thorn updates readers on the $130m+ Coldcard hack; Alex analyzes steps taken by the SEC and CFTC to set clear rules with the Clarity Act’s fate uncertain; and Will Owens gives a postmortem on the failed Bitcoin proposal BIP-110.

Got feedback on this newsletter? Email [email protected]. We’d love to hear from you.

📄 Fizzling CLARITY Act Odds Leave Agencies Scrambling to Act

With odds fading for CLARITY Act passage in 2026, the Securities and Exchange Commission was poised to unveil major exemptions to safely promote crypto innovation, but later backtracked.

The SEC was set to unveil two long-awaited regulatory exemptions this week: Reg Crypto, which will create a new pathway for the primary issuance of cryptoassets to the public; and the Innovation Exemption, which will allow for secondary trading of tokenized securities in decentralized finance. Bloomberg had reported in May that the SEC was on the verge of publishing these exemptions, but the agency then backtracked after significant pushback from the traditional securities industry. New reporting suggested Tuesday that those exemptions were now imminent, but again the SEC appears to be backtracking after Eleanor Terret reported that the innovation exemption was again delayed. And late Thursday, the SEC published a notice about their planned Friday open meeting, which was believed to be about Reg Crypto.

The Commodity Futures Trading Commission is aggressively moving to cement its jurisdiction over prediction market contracts, which it argues are swaps under the Commodities and Exchange Act. This week the CFTC issued an emergency order seeking to countermand New York Attorney General Letitia James' effort to secure a nationwide temporary restraining order blocking Kalshi from offering event contracts (not just sports, bets: James sought to stop the firm from offering trades on “culture, elections, and other events,” emphasis added). The latest salvo follows months of lawsuits between prediction markets venues, U.S. states, and the CFTC, some involving events contracts generally, others focused on sports-related contracts, but all involving questions state vs. federal authority over these markets.

After the successful, bipartisan markup of CLARITY Act by the Senate Banking Committee in May, odds had climbed that the bill could pass the Senate before the August recess (which began on Aug. 7). But as the weeks wore on, several factors obstructed the bill's progress. First, the issue of increased ethics controls for government officials' involvement in crypto, which had been tabled throughout the committee’s processes, reared its head and could not be resolved despite substantial bipartisan efforts. Second, increased pressure from banks – community banks in particular – resulted in some backsliding of support for the bill even from Republicans. Third, calls for further weakening of the developer protections in the Blockchain Regulatory Certainty Act (BRCA) from illicit finance hawks swirled as a specter over the negotiations, though late-stage moderation on the issue by some law enforcement groups seemed to temper fears this issue could derail the bill. All of these factors made it difficult for Senate Majority Leader John Thune (R-SD) to corral the 60 votes needed to overcome a filibuster, and as the calendar waned into the August recess, he declined to call a vote. At the very end of the work period, Sen. Thune did finally "notice" the first vote on the bill, meaning the Senate now plans to vote on CLARITY when it returns from recess in mid-September.

OUR TAKE

The reality is that CLARITY is now much more about politics than policy. The bill is extremely comprehensive and includes registration and licensing requirements, new compliance responsibilities for service providers and new surveillance and sanctions authorities for government, substantial clarifications of law and regulation to protect consumers, and myriad other provisions that promote American leadership, investor protection, and regulatory clarity. None of that matters right now.

Without even considering the banks' lobbying on stablecoin yield or the low-grade simmer of the "illicit activity" issue, without a clear deal on the ethics issue – which a bipartisan group of Senators sent to the White House on Thursday, July 30, but to which the White House never publicly responded – there is likely no pathway to 60 votes in the Senate. Expecting a vote on the bill when the Senate returns in September would be optimistic if not quixotic, not just because these issues remain unresolved but because the September "session" is just 2-3 weeks long: the Senate reconvenes Sept. 14 and adjourns for midterm election activity around Oct. 2. The reality is that unless an initial "motion to proceed" vote happens almost immediately upon the lawmakers’ return to D.C., there will only be enough time for the CLARITY Act to pass the Senate if it dominates basically the entire working session. For these reasons, we are lowering our odds of CLARITY Act passage in 2026 to 10%.

Meanwhile, the SEC's closeness to producing both Reg Crypto and the “Innovation Exemption” (characterized by repeated starts and stops) are instructive both for CLARITY and for crypto policy during the rest of Trump's presidency. First, it's likely that the SEC previously delayed action on Reg Crypto and the Innovation Exemption at least in part to avoid interfering with the politics of the CLARITY Act. That the Commission is clearly close to acting on them now that CLARITY has stalled perhaps reflects an acknowledgement that the bill's odds are severely diminished. Note that Reg Crypto is substantially related to Title I of the CLARITY Act, and the Innovation Exemption directly overlaps with Sec. 10505.

If Senate negotiations may have been stalling the Commission’s announcements of Reg Crypto and the Innovation Exemption, other factors had been pressuring the agency from the other end to act. First, Commissioner Hester Peirce plans to vacate her seat in November (she is required by statute to vacate by the end of the 119th Congress), and it's not hard to imagine that the Commission wants to release these landmark actions before she leaves, given the depth and length of her work on these issues. Second, and more importantly, the Commission needs time for these initiatives. The specific initiatives, in particular the Innovation Exemption, are likely to be structured to offer a time-limited sandbox for issuers to try onchain trading of tokenized securities, the results of which will likely inform rulemaking on the topic. The authorization and occurrence of market activity in the sandbox, as well as the resulting rulemaking, are extremely likely to result in substantial litigation between market participants (particularly traditional finance stakeholders) and the Commission. Advancing these concepts from policy idea to formalized rule is likely to be a multiyear effort, and the Commission needs to start the clock as soon as possible. The urgency here from the Commission makes sense, and we commend it, but the competing pressures of both 1) a desire to advance crypto rulemaking while during this presidential term while 2) facing headwinds from CLARITY and backlash from the traditional securities industry account for the spasmodic nature of the rollout.

CLARITY Act passage remains a possibility, but we are firmly in "circus trick" territory – if it is to pass in 2026, we need magic. Regardless of the CLARITY Act's momentum or outcome, though, we now expect the Commission to publish the texts of Reg Crypto, the Innovation Exemption, or both over the next several weeks or couple months, another reminder that the crypto industry is poised for exciting times and a positive regulatory environment ahead even without CLARITY. – Alex Thorn

🫆 Coldcard Exploit Abates as Total Losses Climb to (at Least) 1,700 BTC

New incidents of hackers exploiting vulnerabilities in the Coldcard hardware wallet have abated, though the tally of losses continues to climb as new victims come forward.

Galaxy Research has now been in direct contact with 190 victims, whose reports have helped confirm with high confidence that 1778.84 BTC ($112.7m) has been stolen from more than 8,600 addresses. Notably, this number does not include several medium-confidence sets of possible thefts, such as the still unconfirmed “Wave 4.” If these candidate footprints and the suspected but unconfirmed Wave 4 were included, the loss would climb to 2,417.35 BTC ($153m).

Coldcard 1

For background, a Coldcard was a hardware wallet used mostly by ideological retail Bitcoiners for cold storage (storage of BTC without a centralized intermediary or custodian). On March 17, 2021, Coinkite (Coldcard’s manufacturer) upgraded the devices’ firmware to use a new random number generator for entropy insertion into the cryptographic key generation process. Due to a software bug, the implementation of the new RNG was faulty and the devices instead silently failed during key generation and fell back to a separate, catastrophically insufficient form of entropy. The resulting private keys created on the devices lacked sufficient entropy to defend against attackers who could use compute to regenerate the private keys. Attackers have been executing this attack since at least early morning July 30, 2026, systematically recreating Coldcard-generated seeds and sweeping the funds onchain.

Coldcard 2

Among the confirmed, high-confidence waves and footprints of attacker activity, none occurred after Aug. 6. Additional victims continue to report to Galaxy Research, helping us directly attribute losses and confirm additional footprints, but none have revealed confirmed attacker activity after Aug. 6. NOTE: the reason for the abatement in attack waves is likely because vulnerable users have migrated or most funds have already been drained. If you still hold funds on a single-signature Coldcard wallet, you are advised to move your funds to new addresses.

In addition to Waves 1, 2, and 3, with help from victim reports, Galaxy Research has identified at least 33 additional attacker footprints. We cannot confirm whether any of the waves or footprints are attributable to the same or different attackers, but we can say with high confidence that multiple attackers were active in the threat environment exploiting the Coldcard vulnerability.

Coldcard 3

The bulk of funds have remained largely unmoved since they were stolen from victims. Of the at least 1,778 BTC that has been stolen, 1,531 BTC remains in attacker-controlled addresses unmoved. ~246 BTC has been moved by attackers after the theft, with 65% flowing into Coinjoin mixing transactions and 35% continuing to move onwards onchain, sometimes through carefully constructed peelchains. A tiny amount can be traced, at least in part, to deposits into exchanges or interchain bridges.

Coldcard 4

Galaxy Research has provided lists of attacker addresses to crypto exchanges, compliance and investigative firms, and law enforcement agencies in hopes that they can be frozen if they appear at centralized intermediaries.

<strong>OUR TAKE</strong>

This event has left the Bitcoin community reeling for a number of reasons. First, the nature of the attack is such that the victim cohort is comprised of some of the most philosophically aligned bitcoiners: long-term savers in BTC who believed in self-custody cold storage without an intermediary. These users did not lose their funds because they sent them to shady offshore exchanges, or bridged them to DeFi to chase a long tail of yield, or gambled their BTC for riskier assets. Second, while the loss just barely cracks the top 20 crypto thefts of all time (at $112m, it’s #20 just below Multichain’s July 2023 $130m heist and just above Harmony Horizon Bridge’s June 2022 $100m theft), the magnitude of the theft is unheard of for self-custody hardware wallets. Finally, Coldcard’s were widely promoted by Bitcoin maximalists as the most security-conscious hardware wallet, so its failure strikes at the core of the Bitcoin influencer intelligentsia’s multi-year educational and promotional efforts.

There is some evidence that the exploit has increased fear of and damaged the narrative about self-custody, at least for the near and medium terms. The count of small transfers (<1 BTC) flowing into exchanges reached a local high following the incident; inflows to exchanges exceeded 22k BTC in just the first four days after the attacks began; and as of Aug. 8, exchange balances stood at 3.683m BTC, an all-time high. Some traditional financial firms seemed to jump on the moment, with BlackRock announcing that the minimum to in-kind create IBIT ETF shares from native BTC had been lowered to $1m (from $25m).

But the event also highlighted the safer ways to do self-custody, with multisig emerging as a clear victor. Not one theft transaction stole funds from a multisig. One form of multisig that has found itself in the spotlight for self-custody, partly due to its redundancy but also its accessibility to less-technical users, is collaborative multi-sig self-custody, such as those services offered by Casa, Unchained, Nunchuk, Anchorwatch, Liana, and others.

“We’ve seen massive inbound in the two weeks since the Coldcard exploit was discovered,” said Casa CEO Nick Neuman. “New customer signups have surged and customers have moved substantial amounts of BTC into their Casa multisig vaults.”

Anchorwatch COO Becca Rubenfeld has seen similar growth in demand. “Anchorwatch saw an immediate uptick in new customer signups, as well as inflows from existing customers,” Rubenfeld told Galaxy Research. She noted that her company saw “its biggest single week of inflows since the company’s inception.”

“Framing this as a win for custodians and a loss for self-custody misses the point. The real risk is a single point of failure—whether that's a custodian, a hardware wallet manufacturer, or you,” Dhruv Bansal, co-founder of Unchained, told Galaxy Research. Unchained has seen “a meaningful surge in interested from longtime self-custody bitcoiners who want to distribute that risk without given control,” Bansal said.

In the wake of the attacks, Rob Hamilton (CEO of Anchorwatch), Calle (of the Cashu open source project), James O’Beirne, and ~25 others have been operating the Bitcoin Red Team, systematically sweeping crucial code repositories across the ecosystem for vulnerabilities and recommending patches. The renewed focus on code security is welcome but obviously more urgent in the age of AI. Our own research into the attackers suggests with high confidence that, even if they didn’t need to use it to discover the vulnerability (though they probably did), at least some of the attackers almost certainly utilized AI models without cyber safeguards (like the recently released, open-source Kimi K3 model) to carry out the attack. Hamilton told me on Galaxy Brains this week that “safety” policies from U.S. frontier labs have largely prevented the Red Team from utilizing frontier models to defend against the attacks, leaving him and his fellow security researchers to rely on the same Chinese open-source models as the attackers. It seems that, until now, the Bitcoin mantra of “don’t trust, verify” fell short – not nearly enough verification was being done. The Red Team is leading the charge to change that.

Bitcoin culture will evolve due to the Coldcard incident. The era of Bitcoin maximalist purity – one that included admonishment of those who do not self-custody, or who utilize hardware wallets that are not “Bitcoin only” (as Coldcard was), or that venerated non-technical influencer personalities above open-source developers with cypherpunk determinations – is very likely to come to an end in mainstream Bitcoin culture. To be clear, no one is to blame for this incident other than Coinkite, whose shoddy code introduced the bug and whose ostracization of the open source community contributed to its lack of discovery for five years – certainly not the victims, who did nothing wrong, and not the podcasters and influencers who promoted Coinkite hardware without having conducted deep security audits of the firmware themselves (an unreasonable standard, in my opinion).

But the Bitcoin social movement over the last six years, really starting during the Covid lockdowns, has reached a notable milestone, if not a pivot point or even bookend, as a result of the Coldcard exploit. The era of “contributing” to Bitcoin and converting people into bitcoiners solely through philosophical explanations, memetic platitudes, and, frankly, s**tposting, is over. Bitcoiners need to do more: audit more code, educate more clearly and effectively, and be less judgmental of newcomers who may not feel technologically capable of securing their own coins. The early evidence says this is already happening and that Bitcoin, and its community, will ultimately be stronger because of the incident. If the core tenets of self-custody, self-sovereignty, and transacting without intermediaries are to live on, this must happen. Because the centralized intermediaries are only growing bigger, stronger, and better at marketing their own versions of BTC exposure. – Alex Thorn

🪊 The Bitcoin Fork That Lasted Two Blocks

The soft fork that was supposed to save Bitcoin from “spam" lasted two blocks.

BIP-110, formally the Reduced Data Temporary Softfork, was the brainchild of pseudonymous developer Dathon Ohm with input from Luke Dashjr, creator of the Bitcoin Knots node software, former chairman and CTO of the Ocean mining pool, and a polarizing figure in the Bitcoin community. It called for a one-year consensus-level restriction on arbitrary data in Bitcoin transactions. This includes Ordinals inscriptions (Bitcoin’s answer to NFTs), BRC-20 and Runes (both fungible token standards), and oversized OP_RETURN. The proposal contained seven rules capping most outputs at 34 bytes, OP_RETURN at 83, data pushes at 256, plus restrictions on Taproot annexes and control blocks.

The activation design targeted 55% miner signaling (1,109 of 2,016 blocks). By comparison, Bitcoin’s SegWit upgrade in 2017 wanted 95% and Taproot in 2021 wanted 90%. If 55% wasn’t reached, a mandatory signaling window opened at block 961,632, where enforcing nodes would reject any block that didn’t signal, regardless of hashrate.

Miners never came close. In the last difficulty period before the window opened, 51 of 2,016 blocks signaled. That is 2.53% against a threshold its own authors had already cut nearly in half from the standard. According to block data, every one of those 51 blocks came from Ocean.

Block 961,632 landed on Aug. 8 at 19:35:55 UTC. AntPool mined a non-signaling block that the network accepted, and BIP-110 nodes rejected it. Roughnecks, mining through Ocean’s DATUM system, produced the competing block.

The minority chain reached 961,633 and stopped. Roughnecks quit the next day and told other miners to do the same, then reversed on Aug. 10 and resumed, saying it would keep going until a “sensible POW change” arrived. The main Bitcoin chain is now several hundred blocks ahead. Strategy Executive Chairman Michael Saylor commented on the pitiful fork attempt, saying “Bitcoin worked exactly as designed” (by remaining unaffected in the face of the ill-fated fork attempt).

Ocean was the only pool signaling in favor of BIP-110. Days after the split, it disclosed that a Stratum configuration error had routed some of its miners onto the BIP-110 chain (rather than the real Bitcoin chain) for roughly 18 hours. The pool restored its default endpoint and committed to roughly 0.3 BTC in direct rebates within 72 hours. Cryptographer and Bitcoin OG Adam Back suggested the losses come out of Dashjr’s salary. Ocean’s reported hashrate has since fallen 96%, and miners have publicly called for leadership changes.

On Aug. 9, Bitcoin Improvement Proposal editor Mark “Murch” Erhardt filed a motion to the Bitcoin development mailing list recommending that fellow editor Luke Dashjr be removed as an editor. Erhardt cited Dashjr’s conflict of interest, minimal contribution, championing a contentious fork, and a coordination breakdown with the other editors.

The next day, it was done. Jon Atack merged the pull request (a one-line deletion) and longtime Bitcoin Core contributor Bryan Bishop confirmed the repository permissions were revoked. Bishop, Atack, Erhardt, Olaoluwa Osuntokun, and Ruben Somsen remain as BIP editors. Dashjr also announced a sabbatical from Ocean. He continues to refer to the majority chain as “Bpedo.” (One of his arguments for limiting arbitrary data was the alleged risk of child sexual abuse material being published onchain.)

Dathon Ohm’s response to the 2.53% tally was to accuse the large pools of collusion and announce work on a proof-of-work change to “fire the miners.” Dashjr backed it, citing ASICBoost when pressed on what was wrong with SHA-256d, the hash function at the core of Bitcoin. (ASICBoost is a technique for speeding up mining.)

OUR TAKE

Ocean’s entire pitch was miner sovereignty. DATUM exists so operators build their own block templates locally instead of trusting pool operators’ block construction. That is a useful product solving a real centralization problem. Then a config error pointed unassigned hashrate at the chairman's fork for 18 hours without operator consent, and the pool ended up writing rebate checks. A movement that spent two years arguing pools are dangerous intermediaries proved its thesis at its own expense.

The soft fork itself was never a “neutral anti-spam patch” as its proponents claimed. It was a consensus-level attempt to invalidate fee-paying transactions a minority of the Bitcoin community disliked. On top of that, the threshold for acceptance was cut from 95% to 55% and a mandatory window was designed to split the network if even that low bar wasn’t cleared. Lowering the threshold manufactured a quixotic attempt at a chain that needs (by Saylor’s math) 25 years to reach its first difficulty adjustment.

BIP 148 (whose activation in 2017 is celebrated as Bitcoin Independence Day) worked because exchanges, wallets, businesses, and holders were already behind it. Miners capitulated to an economic majority that had moved without them. A UASF (user-activated soft fork) is a mechanism for the economic majority to route around miners. It is not a mechanism for ~2.5% to route around everyone.

The PoW pivot makes this all worse for Ocean. Miners rejected BIP-110, and the response was to try to change the electorate. And ASIC resistance may not even be the point. Per one of the Knots strategy channels, the stated logic was to adopt an altcoin’s algorithm so ASICs would exist for the new chain on day one. Basically, cannibalize the hardware of an asset Bitcoiners would call valueless (they use an indelicate term for these; it rhymes with “bitcoin”). Bitcoin Gold ran this experiment in 2017 and nobody bothers citing it as a cautionary tale anymore.

LukeJr Discord screenshot

Luke Dashjr laying out proof-of-work design criteria in the Bitcoin Knots Discord channel. Source: Bitcoin.com News

What to watch is whether Ocean’s 96% drawdown proves permanent. The pool building the most credible answer to Bitcoin mining centralization bet itself on a fork its chairman championed, and lost. - Will Owens

Other News

  • 🔍 Tether completes audit with KPMG U.S., a Big Four firm; USDT issuer has come a long way

  • 🤦‍♂️ Trezor hardware wallet customer data exposed in shipping provider breach

  • 🏴‍☠️ Trump authorizes hiring of privateers to hack crime rings (with $1m bond)

  • 😓 Solana narrowly avoids outage as routing fault knocks 29% of stake offline

  • 🏭 Nvidia taps Wall Street firms to raise $500b+ for ‘AI factory’ buildout

  • 🔮 Kalshi said to top $4b in annualized revenue and seek $40b valuation...

  • 🛜 ...as it streams order books via DoubleZero’s high-speed data network

  • ◀️ Crypto infra provider Zerohash’s U.S. bank application “returned” without decision

  • 🔌 Anthropic said to be $9.1b tenant leasing 191 MW from Riot Platforms...

  • 💰 ...which sold 4,300 BTC in 2Q to fund pivot from mining to AI data centers

Charts of the Week: Crypto Lending’s Orderly, Measured Decline

Q2 was the first quarter since Q4 2022 in which onchain lending declined across every category tracked by Galaxy Research (CeFi, DeFi, and the crypto-collateralized portion of collateral debt position stablecoins), as the market’s deleveraging trend continued. The notable difference between current conditions and those of the previous bear cycle is that outstanding loans are falling in a steady, stepwise decline rather than in outright collapse.

All told, crypto-collateralized lending contracted by $11.33 billion (16.78%) in Q2 2026 to $56.16 billion. This is 40.13% lower than the Q3 2025 high of $78.69 billion.

COTW 1

Outstanding borrows on DeFi lending applications have significantly shrunk since reaching an all-time high of $47.13 billion on Sept. 19. Sitting at $21.94 billion as of July 31, onchain lending has declined by $25.19 billion, or 53.45%. That decline is still shallower than the 80%+ DeFi drawdown seen in the 2022 bear cycle, despite the widespread crypto-market drawdown and the $200 million rsETH exploit that roiled Aave.

COTW 2

For more insights, stay tuned for Galaxy Research’s quarterly leverage report, coming soon. – Zack Pokorny

You are leaving Galaxy.com

You are leaving the Galaxy website and being directed to an external third-party website that we think might be of interest to you. Third-party websites are not under the control of Galaxy, and Galaxy is not responsible for the accuracy or completeness of the contents or the proper operation of any linked site. Please note the security and privacy policies on third-party websites differ from Galaxy policies, please read third-party privacy and security policies closely. If you do not wish to continue to the third-party site, click “Cancel”. The inclusion of any linked website does not imply Galaxy’s endorsement or adoption of the statements therein and is only provided for your convenience.