skip to content

Weekly Top Stories - 07/24/26

Top Stories O3

Welcome to Galaxy Research's Weekly Top Stories. Subscribe to get this newsletter delivered to your inbox every Friday morning.

In this week's edition, Alex Thorn discusses the final push to pass the Clarity Act; Will Owens digs into the Bitcoin industry's quantum preparation efforts; and Thad Pinakiewicz explains the latest episode of AI models behaving badly.

Got feedback on this newsletter? Email [email protected]. We’d love to hear from you.

CLARITY’s Combined Text Is Here. Now It Needs Votes

The Senate’s combined CLARITY Act text was released Wednesday, bringing together the market-structure legislation advanced by the Senate Agriculture Committee in January and the Senate Banking Committee in May. The Agriculture Committee advanced its Digital Commodity Intermediaries Act on January 29, while Banking approved its portion of CLARITY by a 15–9 vote on May 14. The new text uses those bills as its two core divisions while adding ethics restrictions, law-enforcement provisions, changes to the GENIUS Act and several other negotiated additions.

The combined bill is 616 pages long and contains 104 numbered sections: Section 1 plus 103 sections across four divisions. Division A contains the Banking Committee product, Division B contains the Agriculture Committee product, Division C contains the new ethics package and Division D establishes the bill’s effective date.

Here is where several of the biggest outstanding issues landed:

Issue

What the combined text does

Change from prior drafts

Government ethics

A new six-section division prohibits covered senior officials and their spouses from issuing or sponsoring digital assets for consideration while in office. It also restricts intermediaries from listing those assets, creates disclosure and blind-trust provisions, places enforcement exclusively with the Justice Department and sunsets at noon on January 20, 2029.

New. Neither committee-approved draft contained this ethics division. The DOJ-only enforcement mechanism and 2029 sunset are already major Democratic objections. Read the combined text.

Developer protections and BRCA

The bill retains both the general software-developer protections and the Blockchain Regulatory Certainty Act. BRCA protects non-controlling developers and infrastructure providers from being treated as money transmitters solely because they publish software or provide non-custodial services.

Largely unchanged. Current §10604 closely tracks Banking §604, while additional developer protections appear in §§10601 and 20209. Some exclusions were removed from the DeFi-specific section, but the broader standalone protections remain. See the bill text.

Former Banking §301 (now §10301)

The standard for identifying a controlled, non-decentralized protocol now reaches persons acting through an “agreement, arrangement, or understanding” to act in concert.

Tightened. The May draft referred only to an “agreement to act in concert” and expressly excluded activities such as transaction validation, operating nodes or oracles, and supplying bandwidth. Those named exclusions are no longer in §10301, although many remain protected elsewhere in the bill. A narrower security-council exception survives. See current §10301.

Self-custody

The Keep Your Coins Act remains in the bill, protecting individuals’ ability to hold and transact with their own assets. New §20216 also provides that inactivity or dormancy alone cannot cause lawfully self-custodied assets to be treated as abandoned, unclaimed, forfeitable or subject to state escheat.

Expanded. Keep Your Coins is substantially retained from the Banking text, while the dormancy and abandoned-property protection is new. See §§10602 and 20216.

Stablecoin yield and rewards

Digital-asset service providers may not pay interest or yield solely for holding a payment stablecoin or based on a customer’s balance. Bona fide activity- and transaction-based rewards remain permitted when they are not economically equivalent to deposit interest.

Substantially unchanged. The compromise contained in Banking §404 carries into current §10404. See current §10404.

Tokenization—formerly §505

Current §10505 directs the SEC to study tokenized securities and generally provides that a tokenized security receives the same regulatory treatment as the underlying security it represents. The SEC may adapt compliance mechanics for distributed-ledger systems.

Retained and renumbered. The provision closely tracks Banking §505. See current §10505.

GENIUS Act modifications

New §11004 makes 22 lettered changes to the GENIUS Act, including credit-union parity, state-regime deadlines, federal enforcement and emergency authorities, AML and sanctions provisions, foreign-issuer supervision, reserve and rehypothecation corrections, territorial treatment and a federal custody floor. New §10906 separately addresses compliance with lawful orders involving stablecoin freezing, burning, seizure or reissuance.

New and more than merely technical. Although titled “technical corrections,” several provisions make meaningful policy and enforcement changes. See §§10906 and 11004.

CFTC registration and custody

The Agriculture bill’s expedited-registration provision has been replaced by a more detailed notice-of-intent regime covering disclosures, financial resources, cybersecurity, examinations, customer-asset segregation and regulatory supervision. The bill also creates a dedicated qualified digital-asset custodian framework.

Substantially revised and expanded. The transition pathway is more prescriptive than the January Agriculture text, and qualified-custodian registration is new. See §§20104 and 20205.

Enforcement and investor protection

A new law-enforcement title addresses elder and “pig-butchering” scams, state and local enforcement grants, investigator training, cyber capabilities and coordinated scam enforcement. New §10111 also preserves existing anti-fraud actions, private rights and federal and state enforcement authorities, subject to the bill’s asset-classification rules.

New. These provisions materially expand the government’s investigative, enforcement and victim-protection toolkit. See §§10111 and 10901–10906.

The immediate Democratic reaction was negative. Sen. Elizabeth Warren, the bill’s most consistent Democratic critic, said in a video Thursday that the latest draft “would make it easier for criminals, cartels and terrorists to move money and finance their operations.” Her formal statement also attacked the ethics package’s DOJ-only enforcement mechanism and declared that the bill “should be dead on arrival.”

More consequentially for the vote count, seven Democrats who have been negotiating with Republicans (Sens. Mark Warner, Angela Alsobrooks, Cory Booker, Catherine Cortez Masto, Ruben Gallego, John Hickenlooper and Raphael Warnock) issued a joint statement saying the current text “falls short,” but specifically demanded stronger provisions on ethics, consumer protection, illicit finance, conflicts of interest and market integrity, while saying they would continue negotiating. Sen. Kirsten Gillibrand was notably not among the seven signatories.

No floor vote has been scheduled. Asked whether CLARITY and other pending legislation could be completed before the summer break, Majority Leader John Thune told Punchbowl: “I don’t think we’ll be able to get them done. I would like to at least get Clarity started. We’ll see where the votes are.” Subsequent reporting indicated that leadership may try to begin the floor process without completing it before senators leave Washington. (It’s not clear how directly Thune was casting doubt on CLARITY timing, or whether he was just generally commenting on calendar constraints and Punchbowl played up his CLARITY angle).

The Senate calendar is now the central constraint. The chamber is scheduled to remain in session through Friday, August 7, with its formal state work period beginning Monday, August 10.

OUR TAKE

Treasury Secretary Scott Bessent said this week that CLARITY was on the “1-yard line”. Maybe it is. But one yard can be the longest yard on the field. And like football, politics is a game of inches.

We are in the eleventh hour, the 91st minute of stoppage time and, increasingly, Hail Mary territory. The combined text is finally public, but the coalition required to pass it is not visibly in place.

Republicans officially hold 53 seats, but Sens. Josh Hawley and Rand Paul have been reported as likely no votes, while Sen. Mitch McConnell has not voted since his June hospitalization. That leaves a dependable Republican starting point of roughly 50 before considering any additional defections. In other words, the bill may not even have a clear majority-party majority in hand, much less the 60 votes required to overcome a filibuster.

Democrats who were supposed to provide the pathway to 60 votes have instead locked arms against the current draft. This despite the fact that Democrats have truly won many concessions from Republicans throughout the process.That’s our estimate from reporting and members’ public statements, not a confirmed whip count, but the arithmetic is looking brutal at this moment in time.

It increasingly appears that passing CLARITY will require a true grand bargain: a legislative circus trick that pulls a rabbit out of a hat. Taking the negotiating Democrats’ statement at face value, a Republican such as Thom Tillis, Cynthia Lummis, or Bill Hagerty may need to secure additional movement from the administration on ethics and then persuade Democrats that the resulting package is sufficient. But that bargain probably needs to emerge within the next 4 days, not the next 4 weeks.

Although the Senate is formally scheduled to remain in Washington through August 7, we believe the practical deadline to start the voting process is next Thursday night, July 30. Leadership needs time to file cloture, begin debate, process amendments, pass the bill, and resolve any remaining issues. Every day spent negotiating the terms is one fewer day available to execute the floor strategy.

As we have repeatedly written, if CLARITY does not pass the Senate before members leave Washington for August, its prospects of becoming law in 2026 diminish substantially. September offers only a narrow window before appropriations fights and election politics consume the calendar. The calendar is no longer merely an obstacle. It is now the enemy.

Are we Tom Brady and the Patriots, down 28–3 and about to complete one of the greatest comeback victories in history? Or are we Drake Maye and the Patriots, a great team with a real opportunity, but who ultimately didn’t really have a chance against the Seahawks? Is the deficit simply too large and the clock too short? We will probably know within the next seven days.

When we last published odds in late June, we had already reduced our post-Banking-markup optimism to a 50–50 coin flip. With the calendar running out, the negotiating Republicans and Democrats publicly opposing the current ethics language and passage increasingly dependent on a grand bargain that does not yet exist, it is difficult to credibly remain at 50%.

We are lowering our estimate of the probability that CLARITY becomes law in 2026 to 30%. We hope we are wrong. This is a strong bill that would substantially improve the United States’ regulatory posture toward crypto, protect investors and customers, provide powerful new tools to combat illicit activity, promote innovation and reinforce American capital-markets leadership. The time for incremental negotiations is over. The bill needs a last-ditch effort, and it needs leadership. Pass the bill! –Alex Thorn

Bitcoin’s Largest Institutions Launch $15m Security Initiative

Nine of the largest institutional participants in Bitcoin have put a number on what it costs to keep the network secure. BlackRock, Fidelity Digital Assets, Coinbase, Strategy, Block, Galaxy, Anchorage, ARK Invest, and Blockstream announced the formation of the Bitcoin Security Consortium this week, pledging $15 million over the next three years for Bitcoin security research and open-source development.

This is not a development organization, nor is it a governance body. The consortium doesn’t write code, and it doesn’t vote on what Bitcoin becomes next. As per the announcement, members “don’t direct its development, and don’t speak for Bitcoin.” Robert Mitchnick, BlackRock’s global head of digital assets, framed the commitment as making “significant additional funding available to support Bitcoin’s long-term security needs.” Mike Schmidt, executive director of Brink (the nonprofit that’s funded Bitcoin Core contributors since 2020) is coordinating the day-to-day effort as a volunteer, independent of any member organization.

The timing tracks with where institutional BTC ownership sits. Spot exchange-traded funds (ETFs), publicly traded treasury companies, custodians, and exchanges now collectively secure hundreds of billions of dollars of BTC. This is a scale of institutional exposure that didn’t exist three years ago. And quantum computing has become one of the most discussed long-term risks to that pile of capital. This consortium is landing the week Galaxy Digital launched our own Bitcoin Quantum Readiness Initiative, committing up to $5 million toward developer grants and a Quantum Advisory Council focused on post-quantum migration (note that Galaxy also joined the Bitcoin Security Consortium). Meanwhile, custody giant BitGo has rolled out quantum risk scoring for institutional wallets, Blockstream has named post-quantum cryptography a top engineering priority for 2026, and Strategy has initiated a Bitcoin security program. The consortium reads as the coordination layer sitting on top of individual company-level activity.

Its mandate is broader than quantum risk. Funding is intended to support protocol security research generally.

OUR TAKE

Bitcoin security funding has historically come from a small group of nonprofits, often operating on budgets that wouldn’t register on any of these nine companies’ balance sheets. That model worked fine when BTC was mostly held by people who’d opted into the risk themselves. It doesn’t hold up as well with hundreds of billions of institutional dollars now sitting on top of the protocol.

Strategy CEO Phong Le put the incentive plainly: long-term holders have every reason to want Bitcoin secure for generations, and funding the people doing that unglamorous maintenance work is a natural extension of holding it. Unlike many other blockchains, Bitcoin has no foundation. (It used to, but that organization ran out of money more than a decade ago, when cryptocurrency was still a fringe interest.) It was never built to have one, but it’s accumulated enough economic value that its security has effectively become a public good with a funding problem. Someone still has to pay the people maintaining the code on which trillions of dollars depend. The consortium is best understood as an attempt to solve that coordination problem in a way akin to how Linux and other critical open-source infrastructure get funded, without introducing centralized governance.

It also invites an obvious knee-jerk reaction: these big companies funding Bitcoin security sounds, to some ears, like “institutions taking over Bitcoin.” The announcement goes out of its way to head that off. Funding developers is not the same thing as directing them. Consensus on Bitcoin still lives exactly where it always has, with users, node operators, miners, and developers in that same slow, occasionally frustrating rough-consensus process that’s kept the protocol credibly neutral for 17 years. The fact that Schmidt is running this as a volunteer keeps nine of the most powerful companies in the industry from having a hand on the wheel. Whether this earns trust in Bitcoin-native circles or gets read as a Trojan horse comes down entirely to whether that line holds.

A year ago, quantum risk to Bitcoin was conference-panel material. It was interesting, distant, and mostly theoretical. No more. None of these announcements mean that a cryptographically relevant quantum computer is imminent, but it signals that the ecosystem has started treating quantum readiness as an engineering problem worth solving on its own timeline.

The most notable part of this consortium is what committing that capital says about where Bitcoin now sits. The standing commitment to collectively fund developer work without asking for control in return is a milestone. Bitcoin’s governance hasn’t changed. The balance sheet of who’s willing to pay for its upkeep just did. - Will Owens

The Call Came From Inside the Lab

OpenAI, the frontier lab that spent the past year warning the world about its models' cyber capabilities, this week confirmed that one of those models had proved the point without being asked to.

Last week Hugging Face (“the GitHub of machine learning”) disclosed it had been hit by what looked like a AI-enabled intrusion. This week OpenAI acknowledged the call came from inside the house: during an internal evaluation, a model under test broke out of its sandbox (a controlled, isolated environment) and, with no human in the loop, exploited Hugging Face on its own accord.

This is not the first time a frontier lab’s large language model (LLM) has escaped containment. OpenAI reported that previously, during an internal evaluation of a benchmark, a model broke out of its sandbox to post its results to GitHub. An exploit, yes, but a relatively harmless one. Anthropic has seen Claude “helpfully” escape a sandbox to complete a task. But the Hugging Face incident might be the first time the escapee conducted a live exploit of an external service. Notably, this wasn’t a malicious exploit; the LLM just wanted to solve the question it was given. But that might just be luck this time around.

So, what actually happened? OpenAI was measuring the cyber capabilities of GPT-5.6 ("Sol") and a second, undisclosed frontier model (presumably GPT-6) on an exploit benchmark, and instructed the system to maximize its score. Rather than grind through the benchmark's tasks from first principles, the model did what a genuinely good security engineer does when handed a test: it looked at whether the test itself could be cracked. It broke out of the sandbox through an undisclosed third-party vendor integration, moved laterally through OpenAI’s systems onto the open internet, and generated several zero-day exploits to crack Hugging Face to find the answers to the benchmark it was tasked with solving. OpenAI itself called it an “unprecedented cyber incident.”

The alarming part for businesses everywhere, and particularly crypto projects, is what happened during Hugging Face’s response. Hugging Face saw the attack as it was occurring; the cadence and volume of the requests made clear this was automated and fast, far faster than a human hacking crew was capable of acting. Untangling a machine-speed intrusion by hand takes dozens of hours to days, so the defenders did the sensible thing and reached for AI to fight AI. But the most capable model available to them (unnamed but presumably Anthropic's Fable) would not help, because the model’s cyber guardrails were unable to tell apart a defender under attack from an attacker spinning a story to extract working exploits. With the cyber-capable frontier model refusing to help, the Hugging Face team ultimately fell back to a locally run open-weight model, the Chinese GLM 5.2, to mount its defense. The U.S. frontier labs’ stance on access to LLMs with advanced cyber capabilities pushed a U.S. company to a Chinese model.

The attacker was a frontier model with no restraint in the moment of the breakout; the defenders were denied frontier help precisely because they were asking frontier questions. Only after the fact was Hugging Face fast-tracked into OpenAI's trusted-access program, and that call came because it is a large, visible player whose attacker traced straight back to OpenAI. Would a smaller, independently run site have gotten the phone call, or would we simply never have heard about it?

OUR TAKE

This is the scenario the AI doomers have been sketching for years, from the “AI 2027” forecast, to Eliezer Yudkowsky and Nate Soares' If Anyone Builds It, Everyone Dies. It is also, rather conveniently, the best marketing a lab could script.

Anthropic has spent months banging the drum that its top-tier Mythos models are so capable that the U.S. government restricted their distribution under export controls, even as the lab kept using them internally. That is arguably the single best advertisement a technology company can run: “our product is so powerful the state had to step in to keep it out of incapable hands. Releasing it publicly would be tantamount to handing a crate of guns to a band of chimpanzees.” OpenAI, for all its own warnings, had no comparable marketing home run until now. A clean, self-contained story in which its model is dangerous enough to escape a sandbox and breach a marquee name, with OpenAI riding to the rescue days later, supplies exactly the missing beat Sam Altman’s company needed to return to the limelight.

So, was this a genuine uncontrolled breakout or a well-contrived one? The whole story hinges on the model escaping through an undisclosed third-party integration. A few obvious questions: Why would a lab sophisticated enough to build frontier cyber models stand up a sandbox around a dangerously capable model without first auditing the very integrations that formed its walls? Would any competent security team put a live, cyber-tuned model in a box wired to untested third-party code? We will leave the conclusions to the reader, but a modicum of skepticism would be forgivable. Either reading points to the same reality that should concern anyone with money onchain: the next generation of unreleased LLM models are as capable, if not more so, than any flesh-and-blood hacker. The modern software stack, with its nested dependencies, constant updates, and myriad integrations, has grown past the point where any human team can reasonably check all the blind spots.

An alternative (not mutually exclusive) read of the breakout was that it wasn’t a marketing stunt akin to Red Bull dropping a man from space (or at least not just that) but a more calculated play to target U.S. lawmakers’ escalating concerns around AI regulation and U.S. primacy. A dramatic, well-timed breakout is also the strongest argument frontier labs can make for why frontier cyber capability should be licensed, gated, and kept in a small circle of approved hands, namely their own. If the lesson regulators draw from this week is that these models are too dangerous to distribute freely, the labs that already hold them don't lose; they get a permanent seat at the table, and a state-sanctioned reason to keep everyone else out. It also conveniently reframes the case against open weights: a model dangerous enough to break containment is a model too dangerous to expose to distillation. Anthropic's export-control saga already secured its protected status. An OpenAI incident that "proves" the danger firsthand gives Washington the narrative and digs Altman his moat.

Crypto is uniquely exposed here, and uniquely underprepared. Tens of billions of dollars in contracts sit potentially exposed. Let’s start with some uncomfortable facts. Nearly every major exploit in this industry has hit a protocol, or blockchain that was audited by a smart contract review firm. Attempts to quantify smart contract risk, such as the defunct Mars Protocol framework, have all been searching for elements that correlate with safety, without a truly reliable measure. The majority of the analysis usually boils down to some combination of how long the contract has been deployed and how much money is at stake to be lost; the more of each, the more secure the protocol is assumed to be. Galaxy’s own smart contract risk framework primarily focuses on a firm’s ability to manage the operational risk around interacting with smart contracts, not the risk of the smart contracts themselves. In the cryptoverse where code must be perfect to prevent catastrophic exploits, human error becomes the primary weakness. If a room full of code auditors and professional risk managers can't reliably stay ahead of one talented attacker, the industry stands no chance against thousands of untiring attackers at once.

The crypto industry needs to be on the frontier (no pun intended) of code security, not a year behind it. Crypto needs to come together to secure itself and prevent the next great retail exodus, not from a surplus of fraud and a lack of foresight, but from a lack of access to the cool kids’ club at the leading AI labs. (The Bitcoin Security Consortium may be one such effort to join that club). In a world where OpenAI and Anthropic gate access to the dangerous cyber-capable frontier models, they can decide who wins and loses based on whom they give access to. The past week’s events suggest we may already live in that world. Thad Pinakiewicz

Other News

Chart of the Week: Robinhood Chain Nips at Solana’s Heels

Robinhood Chain’s first two weeks have been gangbusters. Total value locked (TVL) has crossed $300m, according to DefiLlama. DEX trading volume has been more striking: multiple days have posted above $500m. That’s been enough to put Robinhood Chain among the top five blockchains globally by daily DEX volume on several occasions, which is remarkable for a chain that wasn’t live on mainnet a month ago.

Other News - inline 1

For more insights on Robinhood Chain, stay tuned for a Galaxy Research deep dive, coming soon. - Will Owens

You are leaving Galaxy.com

You are leaving the Galaxy website and being directed to an external third-party website that we think might be of interest to you. Third-party websites are not under the control of Galaxy, and Galaxy is not responsible for the accuracy or completeness of the contents or the proper operation of any linked site. Please note the security and privacy policies on third-party websites differ from Galaxy policies, please read third-party privacy and security policies closely. If you do not wish to continue to the third-party site, click “Cancel”. The inclusion of any linked website does not imply Galaxy’s endorsement or adoption of the statements therein and is only provided for your convenience.