BTC $64,084, ETH $1,878.29, SOL $76.33, XRP $1.02, HYPE $55.49, DOGE $0.069858, AAVE $89.70, ZEC $498.20.
Tuesday morning is about balance sheets getting less romantic.
The August 8-10 digests already covered payment-server exploits, BNB malware storage, Kimi’s benchmark escape, OpenAI’s cyber disclosure, RWA collateral growth, BIP-110’s stalled fork, CLARITY timing, Brazil’s transfer delay, BitMEX reputation debt, Robinhood UK crypto, Kimsuky AI phishing, Dogechain withdrawal limbo, wallet-address rewriting, Hyperliquid fee capture, XRP weakness, and the recent agent-tooling repo loop.
This morning moves elsewhere.
Bitcoin is trying to prove it can be a diversifier while software stocks outperform it badly. Strategy sold another 1,690 BTC and raised common equity to rebuild a dollar reserve. Keel shut all U.S. mining operations and pointed the sites at AI and high-performance computing. Bitdeer produced far more bitcoin, grew revenue, and still sold off because the cost stack got heavier. Ethereum’s new roadmap puts privacy, censorship resistance, and quantum safety closer to the center. The U.K. FCA is preparing tokenized-gold rules to defend London’s bullion role. Mastercard’s $1.8 billion BVNK deal shows payment giants buying stablecoin infrastructure, not just testing it. Coinsbuy lost more than $8 million in a coordinated TRON and Ethereum wallet drain. Malicious Solidity Pro VS Code extensions targeted browser wallets, API keys, and credentials. GitHub’s fresh board tilted toward agent operations, independent browser infrastructure, and social-data ingestion.
Less “what pumped?” More “who has enough cash, compute, custody discipline, market plumbing, and security hygiene to survive a boring tape?”
Price snapshot via CoinGecko simple-price data around 04:55 HKT.
1. Bitcoin’s Decoupling Cut Both Ways
CoinDesk’s live market board pointed out that the iShares Expanded Tech-Software Sector ETF is making new highs relative to bitcoin.
The ratio reached 0.0016, while IGV is down only about 1% in 2026 compared with bitcoin’s 29% decline. CoinDesk also noted that the 20-day rolling correlation between bitcoin and IGV has turned negative for the first time since May 2024.
That sounds good if your bitcoin thesis is diversification.
It sounds worse if you expected bitcoin to ride the same risk-on wave as software and AI. Decoupling is only a virtue when capital wants the asset that detached. Right now, software is getting the cleaner bid.
The useful read is that bitcoin’s institutional story has split. ETF investors may still buy weakness, but public-market growth capital is rewarding compute and software first. Bitcoin has to prove it is more than a high-beta tech cousin when the cousin is outperforming.
2. Strategy Sold Bitcoin To Build A Cash Buffer
The Block reported that Strategy sold 1,690 BTC for about $108.6 million between Aug. 3 and Aug. 9.
That cut total holdings to 840,447 BTC, worth about $54.7 billion at current prices. The company also sold 6.59 million MSTR shares for $653.1 million, bought back 1.15 million STRC preferred shares, and lifted its dollar reserve to $4.65 billion.
This is the treasury-wrapper story entering a harder phase.
For years, Strategy’s signal was brutally simple: raise capital, buy bitcoin, repeat. Now the company is managing preferred-stock support, common-equity issuance, cash reserves, and bitcoin sales while sitting on roughly 4% of bitcoin’s fixed supply.
That doesn’t kill the thesis. It changes the dashboard.
Investors now have to watch BTC per share, cash coverage, preferred dividends, dilution, buybacks, and the market’s tolerance for a company that can sell bitcoin while still pitching itself as the cleanest corporate bitcoin vehicle.
3. Keel Turned Off U.S. Bitcoin Mining
The Block reported that Keel Infrastructure, formerly Bitfarms, decommissioned all of its U.S. bitcoin mining operations.
The company is preparing those sites for AI and high-performance-computing data centers. It also sold 1,085 BTC for $75 million between Apr. 1 and Aug. 7, leaving 1,861 BTC on the balance sheet.
This is a miner making a real physical asset switch, not an AI slide-deck garnish.
It is a physical asset reallocation. Power, land, interconnection, cooling, and permits are becoming more valuable to AI tenants than to hashprice exposure. Keel’s quarterly revenue fell 50% year over year to $30 million, and the company swung from almost $11 million of income to a $141 million loss.
The market punished the shares anyway.
Miners are learning that “we have power” is a better story than “we mine bitcoin,” but only if the conversion survives permitting, tenant demand, capex, and balance-sheet stress.
4. Bitdeer Proved Growth Is Not Enough
The Block reported that Bitdeer’s shares fell more than 15% after the miner reported second-quarter results.
The headline numbers looked strong. Revenue rose 47% year over year to about $229 million. Bitcoin production rose nearly 400% to 2,694 BTC. AI cloud revenue jumped tenfold to $14 million.
The cost side ruined the party.
Bitdeer posted a $92.3 million net loss as power, depreciation, research and development, administration, and interest expenses rose. It also ended the quarter with only 150 BTC, which signals it sold newly mined coins while bitcoin traded under pressure.
That is the miner pivot in one company.
AI revenue helps, but it doesn’t magically erase mining cyclicality, hardware depreciation, debt costs, and energy exposure. Public investors are no longer rewarding the pivot label by itself. They want proof that compute revenue can cover the old mining machine.
5. Ethereum Put Privacy And Quantum Safety On The Roadmap
The Block reported that Vitalik Buterin compared Ethereum’s 2023 roadmap with the newer Strawmap for upgrades through 2029.
The biggest additions are strong privacy, quantum security, native rollups, gas futures, and a broader “Lean Ethereum” effort that could eventually replace or revise core pieces of the protocol, including the EVM.
That is a meaningful shift.
Ethereum’s old public roadmap was mostly about scaling, MEV, state growth, and cleanup after the Merge. The new version treats privacy and future cryptographic risk as first-class protocol work.
The market angle is simple: Ethereum can’t sell institutional settlement, RWA collateral, and public-chain neutrality while leaving balances, flows, and censorship surfaces too exposed.
Privacy is becoming core infrastructure. Quantum readiness is becoming a credibility test. Ethereum is trying to get ahead of both before they turn into emergency upgrades.
6. London Wants Tokenized Gold Rules
CoinDesk reported that the U.K. Financial Conduct Authority is preparing rules for tokenized gold.
The regulator is consulting financial institutions on how tokenized claims on physical bullion could work as collateral in wholesale markets. London still handles about 70% of the world’s notional gold trading volume, but China is challenging that role.
This is tokenization with a real incumbent to protect.
The U.K. is not starting with another retail coin story. It is asking whether the global bullion market can move ownership, collateral, and settlement into digital rails without handing liquidity leadership to another jurisdiction.
That makes the regulatory design more interesting. If tokenized gold becomes acceptable wholesale collateral, the important questions become custody proof, settlement finality, redemption rights, and whether market participants trust the token when stress arrives.
Gold tokenization is not new. A serious London rulebook would be.
7. Mastercard Bought A Stablecoin Operating Layer
CoinDesk reported on Mastercard’s completed $1.8 billion acquisition of stablecoin infrastructure firm BVNK.
The detail that matters is who competed for it. CoinDesk says Coinbase and Visa were involved, with Coinbase potentially offering as much as $2.5 billion before BVNK chose Mastercard.
This is where the stablecoin race has moved.
Payments firms don’t only want experiments, pilots, or press releases. They want operators that can handle treasury movement, cross-border payroll, settlement, compliance, and integrations for real businesses. CoinDesk cited the stablecoin market at about $300 billion, but the better number may be the 24-hour treasury cycle BVNK is already supporting for a large payments company.
Stripe bought Bridge. Mastercard bought BVNK. Visa is partnering instead of owning.
The card networks know the threat now. Stablecoins are turning settlement from a card-network feature into software infrastructure.
8. Coinsbuy Lost $8 Million Across Two Chains
CoinDesk reported that crypto exchange Coinsbuy lost more than $8 million in a coordinated Aug. 9 attack across TRON and Ethereum.
The attacker reportedly started with a 5 USDT test transaction, then drained eight TRON wallets of 6.04 million USDT in about an hour. On Ethereum, three wallets were emptied of 1.89 million USDT and 77 ETH, with assets swapped through 1inch from a same-day wallet.
The lesson is not only “another exchange got hacked.”
The pattern shows how operational wallet controls fail across chains at once. If hot-wallet monitoring treats each chain as a separate incident, the attacker gets time. If treasury movement, withdrawal policy, and alerting don’t share one risk view, a small test transaction can become an $8 million drain.
Multi-chain support gives users reach. It also gives attackers more places to move before humans understand the shape of the breach.
9. Solidity Developers Got A VS Code Warning
The Hacker News reported that malicious VS Code extensions using the Solidity Pro name delivered browser-wallet and credential stealers.
The flagged extensions included helper-beeps.solidity-pro and web3devtoolsx.solidity-pro.
That should make every smart-contract team uncomfortable.
Developers are high-value wallets now. They hold deploy keys, API tokens, private RPC credentials, package credentials, browser sessions, and sometimes direct access to treasury tooling. A malicious editor extension doesn’t need to exploit the protocol if it can steal the keys around the protocol.
The practical fix is not glamorous: restrict extension sources, pin workspace recommendations, separate wallet browsers from dev browsers, rotate API keys, and treat editor plugins like production dependencies.
The attack surface has moved into the place builders stare at all day.
10. GitHub Trending - Agent Ops, Browsers, And Social Data
The featured-repo tracker ruled out recent repeats including PrimeIntellect-ai/prime-agent, semantica-agi/semantica, msitarzewski/agency-agents, google-deepmind/weathernext, vitali87/code-graph-rag, TauricResearch/TradingAgents, and ruvnet/RuView.
Fresh picks from GitHub Trending and repo metadata:
paperclipai/paperclip has about 76.4k stars and was pushed on Aug. 10. It pitches itself as an open-source app for managing agents at work. The signal is that agent adoption is moving from chat prompts to team-level operations: assignment, visibility, ownership, and repeatable work surfaces.
LadybirdBrowser/ladybird has about 65.2k stars and was pushed on Aug. 10. It is an independent browser project. That matters because browsers are becoming the execution surface for wallets, agents, passkeys, identity, and finance workflows. Independence at that layer is not nostalgia. It is leverage.
NanmiCoder/MediaCrawler has about 60.9k stars and collects notes, comments, posts, videos, questions, and replies from major Chinese platforms. The useful signal is demand for structured social data. Traders, researchers, and agents all want fresher public attention maps, but collection tools also raise sharper compliance, consent, and platform-risk questions.
Morning Read
Read Strategy’s BTC sale filing story, then read the FCA tokenized-gold piece, then read the Solidity Pro extension warning.
The number to remember is $4.65 billion.
That is Strategy’s dollar reserve after another week of BTC sales and common-stock issuance. The second number is 70%, because London still handles roughly that share of notional global gold trading, and the FCA is trying to keep that market relevant as tokenization grows up.
Tuesday’s read is that crypto is becoming less ideological and more operational. Bitcoin treasuries need cash buffers. Miners need higher-value compute customers. Ethereum needs privacy and post-quantum planning. Stablecoin firms need full-stack verification. Exchanges need cross-chain hot-wallet controls. Developers need cleaner extension hygiene.
The winners won’t just believe harder. They’ll manage the balance sheet, the browser, the chain, the keys, and the collateral.
Evening Update - 18:13 HKT
BTC $64,212, ETH $1,884.82, SOL $75.83, XRP $1.004, HYPE $55.21, DOGE $0.070496, AAVE $88.95, ZEC $484.87.
Tuesday evening is about regulated pipes becoming more specific.
The morning digest already covered bitcoin’s software-stock decoupling, Strategy’s cash reserve, Keel and Bitdeer’s AI-miner pivots, Ethereum privacy and quantum planning, U.K. tokenized-gold rulemaking, Mastercard’s BVNK acquisition, Coinsbuy’s wallet drain, malicious Solidity Pro extensions, and GitHub’s agent-ops/browser/social-data set. The August 8-10 mix also ruled out BTCPay, BIP-110, CLARITY calendar noise, Brazil’s transfer delay, Dogechain, Kimsuky, Hyperliquid fee capture, npm/Open VSX malware, ClickFix, and the recent repo loop.
Tonight moves into rulemaking, real collateral plumbing, prediction-market inputs, and agent-era security. The SEC set an Aug. 14 meeting for its first formal Reg Crypto proposal. Riot’s reported Anthropic deal turned the miner AI pivot from narrative into a 20-year contracted capacity story. ADI Chain and Shipfinex are trying to tokenize commercial ships, with no tokens live yet and only preliminary Dubai approval. Broadridge’s blockchain repo platform processed $8 trillion in July. Coinbase added derivatives for U.K. professional clients. Zama put a privacy token inside Revolut’s 70 million-user distribution surface. FlightAware sued Kalshi over flight-cancellation markets that rely on its data. BdThemes showed that a poisoned vendor JSON feed can become WordPress admin persistence. Atlassian Rovo showed how enterprise agents can turn normal documents and links into data-exfiltration paths. GitHub’s fresh board tilted toward local video inference, multimodal agent plugins, and governed event/MCP gateways.
That is a cleaner evening board. Less “which token got attention?” More “which issuer, exchange, data provider, dashboard, CMS, repo, or agent gateway becomes the control point when crypto and AI get institutional enough to be boring?”
Evening price snapshot via CoinGecko simple-price data around 18:13 HKT.
11. The SEC Put Reg Crypto On The Calendar
CoinDesk reported that the U.S. Securities and Exchange Commission scheduled an Aug. 14 meeting to propose “Regulation Crypto.”
That matters because this is formal rulemaking, not another staff statement.
The proposal is expected to create a tailored offering path for certain crypto investment contracts. It would give projects a capital-raising route and define an exit path when issuers are no longer actively managing a project. CoinDesk framed it as the SEC’s first major crypto rulemaking process under Chair Paul Atkins.
The timing is the story.
The Senate left for recess without even starting the CLARITY Act vote sequence. The SEC is now filling the gap with a process that can survive longer than informal guidance, but will still need comments, rewrites, and months of regulatory work.
That leaves builders in an awkward middle. Congress still matters for the market-structure map. The SEC is moving anyway. The practical play is to watch the proposal text, not the speeches around it.
12. Riot Turned AI Capacity Into A 20-Year Contract
CoinDesk reported that Riot Platforms shares jumped more than 20% pre-market after a $9.1 billion AI infrastructure agreement reportedly tied to Anthropic.
The base deal covers 191 megawatts at Riot’s Rockdale, Texas campus, with deployment starting in December 2027 and full buildout expected by June 2028. Two five-year extension options could lift total contract revenue to $16.1 billion.
This is the cleaner version of the miner pivot.
The morning digest covered Keel turning off U.S. mining and Bitdeer proving AI revenue doesn’t erase cost pressure. Riot adds the missing ingredient: contracted demand from a frontier AI customer over two decades.
That doesn’t make bitcoin mining irrelevant. It makes the power site the asset and mining one possible workload. Riot still reduced its BTC treasury during the quarter and mining revenue fell, so the capital market will judge whether AI leases can become steadier cash flow without swallowing the balance sheet first.
Mining companies used to sell hashpower leverage. Now the better ones are selling power access, cooling, land, and time.
13. Ship Tokenization Got A Reality Check
CoinDesk reported that ADI Chain and Shipfinex are partnering to tokenize commercial ships.
The numbers are large and the caveats are useful. Commercial vessels are estimated at about $2 trillion. Ship finance is about a $680 billion market. Shipfinex has identified around 35 vessels worth roughly $500 million as possible candidates.
But no maritime asset tokens have been issued yet.
Shipfinex also has only an in-principle approval from Dubai’s VARA, not a full operating license. CoinDesk notes that other maritime tokenization efforts already exist, including Galactica and Ethra Ship.
That makes this a good RWA story precisely because it is not clean.
Tokenizing a Treasury bill is paperwork plus custody. Tokenizing ships means vessel valuation, legal entities, insurance, operating economics, creditors, jurisdiction, and what exactly the token holder owns. CoinDesk says the token would represent a financial claim tied to a vessel, not legal ownership of the ship itself.
The RWA market is moving from simple collateral into real-world mess. That is where the real underwriting starts.
14. Broadridge’s Blockchain Repo Rail Hit $8 Trillion
The Block reported that Broadridge’s Distributed Ledger Repo platform processed more than $8 trillion in July volume.
The platform averaged $365 billion per day, up 28% year over year. It lets firms settle repo transactions on distributed-ledger technology while staying inside their existing trading and post-trade environments.
That is the institutional tokenization story people tend to miss.
It is not loud, retail, or ideological. It is collateral movement, repo financing, liquidity management, proxy voting, post-trade operations, wallets, and custody.
The scale matters because it makes the “blockchain for capital markets” argument less theoretical. If a DLT repo rail can handle hundreds of billions a day, the debate shifts from whether the technology can work to where it improves settlement, collateral reuse, governance, and operational risk.
Tokenization does not need every asset to be a public token. Some of the biggest rails will look like infrastructure upgrades inside institutions that already trust each other.
15. Coinbase Added U.K. Professional Derivatives
The Block reported that Coinbase is rolling out perpetuals, dated futures, and crypto options to eligible U.K. professional clients.
The launch follows Coinbase’s MiFID license and covers more than 170 contracts across crypto, commodities, equities, and foreign exchange. Perpetuals will be available around the clock with up to 50x leverage. Dated futures go up to 20x, while options are crypto-only.
This is Coinbase’s “Everything Exchange” strategy getting teeth outside the U.S.
The important part is product breadth. Coinbase is not only trying to be a spot exchange with a clean brand. It wants professional traders to use one regulated account for crypto, equities, stablecoins, savings, borrowing, and derivatives.
That pushes Coinbase closer to traditional prime-brokerage territory, but with crypto-native hours and leverage.
The risk is also obvious: once a venue offers 24/7 perps and 50x leverage in a broader investing account, suitability, margin controls, client classification, and disclosure become part of the product, not legal wallpaper.
16. Zama Took Privacy To Revolut Distribution
The Block reported that Zama listed its ZAMA token on Revolut across the European Economic Area.
That puts the fully homomorphic encryption privacy project in front of more than 70 million Revolut customers, including over 15 million who already trade crypto. Revolut users can buy and hold ZAMA in the main app and withdraw it to self-custody.
This is different from a privacy research launch.
Zama is trying to make encrypted balances, transactions, and positions usable on public blockchains without forcing users onto a separate privacy chain. The project already has confidential lending, RWA tokenization, and institutional token-operations work behind it.
The morning digest covered Ethereum putting privacy higher on the roadmap. Zama is the distribution-side version of the same theme.
Privacy stops being a niche topic when it appears inside normal fintech UX. The next test is whether users and institutions treat confidentiality as a default expectation, or whether regulators and exchanges keep treating it as a risk label first.
17. FlightAware Challenged Kalshi’s Data Rights
The Block reported that FlightAware sued Kalshi over flight-cancellation prediction markets.
FlightAware says Kalshi relied on its data and name without permission, creating the impression of a close partnership. The lawsuit seeks a temporary restraining order and injunctions blocking markets involving FlightAware.
The safety argument is sharper than the trademark argument.
FlightAware says markets on flight cancellations could create incentives around unsafe disruption, even though Kalshi excludes malicious and security-related events from payouts. The complaint also says Kalshi described outcomes as verified from FlightAware.
Prediction markets have spent the last year fighting over sports, elections, and regulator boundaries. This case adds a new layer: source data rights and oracle legitimacy.
If a market depends on a third-party data provider, the product is not only the contract. It is the permission, brand, integrity, and dispute path around the data feed.
That matters for crypto too. Onchain markets still need offchain facts. The legal fight may happen at the data-source layer before it ever reaches settlement.
18. BdThemes Showed Supply Chain Without Code Changes
The Hacker News reported that a BdThemes supply-chain compromise affected several WordPress plugins, prompting temporary download closures.
The weird part is that attackers did not need to modify official WordPress.org plugin source files. Wordfence said they poisoned a static remote JSON data stream fetched by an administrative promotional banner component.
That JSON path hit logged-in WordPress administrators.
The injected script could create rogue admin accounts, install a fake plugin ZIP, deploy a PHP web shell, and add persistence modules under mu-plugins. The affected list included Elementor-related plugins, with Element Pack Addons for Elementor showing more than 100,000 active installs.
This is the developer-tools lesson in miniature.
Teams audit package source and still miss remote data dependencies that execute inside admin surfaces. A plugin can be unchanged on disk and still become an exploit delivery path because the dashboard fetches content from a vendor-controlled bucket.
For crypto sites, exchanges, dashboards, and token landing pages, that is brutal. The marketing/admin layer can become production risk.
19. Rovo Made Enterprise Agents Look Too Trusted
The Hacker News reported that Atlassian’s Rovo assistant can be abused to collect Jira or Confluence data a signed-in user can access and send it to an external server.
Two firms found different paths. Varonis used a link parameter that preloaded attacker instructions into Rovo Chat, a flaw it says Atlassian fixed server-side on July 8. PromptArmor hid instructions in content Rovo read, then had the assistant gather internal data and exfiltrate it through a URL request.
That second route is the uncomfortable one.
The user still has to do something normal: upload content, ask the assistant to organize work, or click a crafted link. The agent then acts with the user’s permissions and turns internal tickets or pages into outbound data.
This is why enterprise AI security cannot stop at “the model is inside our tenant.”
The control point is tool use. Can the assistant open a URL it constructed itself? Can it render Markdown images? Can it reach public endpoints after reading private data? Can admins scope which groups get the agent at all?
Agents collapse search, permissions, and action into one surface. That surface now needs egress policy.
20. GitHub Trending - Local Video, Multimodal Plugins, And Agent Gateways
The featured-repo tracker ruled out the recent loop: paperclipai/paperclip, LadybirdBrowser/ladybird, NanmiCoder/MediaCrawler, msitarzewski/agency-agents, vectorize-io/hindsight, vitali87/code-graph-rag, google-deepmind/weathernext, PrimeIntellect-ai/prime-agent, semantica-agi/semantica, and the rest of the August 8-10 set.
Fresh picks from Trendshift’s daily GitHub repo board and repo metadata:
antirez/h3.c has about 484 stars and implements native MiniMax-H3 inference for Apple Silicon. The signal is local media generation getting closer to a developer-native loop: compile, run, iterate, profile, and keep the model phases from blowing through unified memory.
QwenLM/Qwen-MM-Plugins has about 1.7k stars and packages native multimodal plugins for Qwen models, including vision, OCR, grounding, segmentation, ASR, long-video memory, Blender, FreeCAD, and video-editing capabilities. The useful read is that agents are becoming tool bundles with eyes, ears, CAD hands, and video memory.
aklivity/zilla has about 1k stars and describes itself as a stateless multi-protocol gateway for event-driven applications and AI agents. It exposes Kafka, MQTT, HTTP, SSE, gRPC, WebSocket, OpenAPI services, and MCP through governed gateway routes. That matters because agent systems are about to need the same boring controls as distributed systems: routing, identity, authorization, schemas, telemetry, and one place to revoke access.
Evening Read
Read the SEC Reg Crypto piece, then read Broadridge’s $8 trillion DLR report, then read the Atlassian Rovo prompt-injection writeup.
The number to remember is $8 trillion.
That is Broadridge’s July repo volume on distributed-ledger rails. The second number is Aug. 14, because the SEC is moving from crypto guidance to a formal Reg Crypto proposal while Congress is still stuck on market structure.
Tuesday evening’s read is that crypto and AI are becoming normal enough to inherit normal institutional problems. Securities offerings need rules. Repo needs collateral plumbing. Derivatives need client classification. Privacy needs distribution. Prediction markets need data rights. Admin dashboards need supply-chain controls. Enterprise agents need egress policy.
The winners won’t be the loudest projects. They’ll be the ones that know exactly which pipe they own, which permission they need, which data they trust, and which action they can stop before it leaves the building.