Listen on Spotify

Coldcard Hack Tests Crypto Security as Visa Moves Onchain

0 views
0%

Last updated: August 5, 2026, 4:00 a.m. EDT

A fast-moving theft linked to a flaw in Coldcard hardware-wallet software has become a sharp test of the cryptocurrency industry’s central promise: that digital assets can be held safely outside the banking system. Blockchain investigators and cybersecurity researchers estimated by August 4 that attackers had taken roughly $130 million in bitcoin from wallets whose recovery phrases were generated with insufficient randomness. The manufacturer, Coinkite, confirmed a serious seed-generation weakness, released corrected firmware and warned that installing an update does not repair an already-created vulnerable seed. Affected users must create a new seed on fixed software and move their funds.

The incident is not evidence that Bitcoin’s blockchain was broken, nor does it show that every hardware wallet or every form of cold storage is unsafe. It exposes a narrower but consequential failure: an offline device can protect a secret from internet theft while still creating a weak secret in the first place. If the recovery phrase is predictable enough to be searched by an attacker, keeping the device in a safe-deposit box does not solve the problem. The vault can remain closed while a duplicate key is reconstructed elsewhere.

That distinction matters far beyond one manufacturer. The Coldcard hack arrived while institutional participation was becoming more visible in crypto trading, while U.S. lawmakers were again struggling to advance the Digital Asset Market Clarity Act, and while Visa was offering banks a managed platform for stablecoin operations. It also came as traditional financial institutions expanded tokenized deposits, tokenized funds and other blockchain-based products. Together, those developments reveal a market moving in two directions at once: deeper integration with regulated finance and a renewed demonstration of the operational hazards that regulation, branding and offline storage cannot automatically remove.

The most useful way to understand the week’s news is therefore not as a collection of unrelated crypto headlines. It is a single market-structure story. Crypto is acquiring the plumbing of conventional finance—over-the-counter institutional desks, exchange-traded products, bank settlement tools, derivatives, compliance controls and branded payment networks—while continuing to rely on software, cryptographic key generation and custody practices that can fail in unfamiliar ways. The next stage of adoption will depend less on whether blockchains can transfer value and more on whether institutions can control the entire chain of responsibility around those transfers.

Key Takeaways

  • The central security failure: Coinkite said certain Coldcard firmware generated wallet seeds with materially less entropy than intended. Updating firmware fixes future seed creation but does not repair an existing affected seed.
  • The estimated loss: TechCrunch reported on August 4 that blockchain-monitoring firms estimated roughly $130 million had been stolen, with evidence suggesting multiple attackers. The figure remained provisional because onchain attribution was still developing.
  • What “cold” storage did and did not do: Offline storage reduced exposure to remote compromise of a device, but it could not compensate for weak randomness at wallet creation.
  • Institutionalization is real but concentrated: Wintermute reported that institutions generated 72% of spot flow on its over-the-counter desk in the first half of 2026. That is proprietary desk data, not a measure of the entire crypto market.
  • Regulatory uncertainty remains: The Senate version of the CLARITY Act would divide responsibilities between the SEC and CFTC and create new disclosure and intermediary rules, but ethics disputes, banking concerns and a compressed legislative calendar continued to threaten passage.
  • Visa is positioning itself as infrastructure, not merely a card network: Its new stablecoin platform is designed to give banks and fintechs a managed environment for wallets, minting, redemption, transfers, approvals and audit logs, initially using Open USD.
  • Tokenization is advancing in pilots before it reaches system-wide scale: Wells Fargo’s planned tokenized deposits and the expanding tokenized-Treasury market show meaningful progress, but today’s onchain asset values remain small beside conventional deposit, securities and payment markets.
  • The strategic question: Crypto’s future may be determined by which institutions can make digital-asset risk legible, insurable, auditable and recoverable—not by which platform offers the most radical version of self-custody.

Fact Box

What Coinkite Confirmed

  • Mk2 and Mk3 seeds generated on firmware 4.0.1 through 4.1.9 were identified as affected under the conditions described in the advisory.
  • Seeds generated on affected Mk4, Mk5 and Q firmware had about 72 bits of entropy rather than the expected 128 bits, according to Coinkite.
  • Fixed firmware corrects new seed generation, but an existing vulnerable seed must be replaced and the funds migrated.
  • Coinkite said sufficiently independent dice entropy or a strong, unique BIP-39 passphrase changes the risk analysis, while still advising migration where applicable.

Original source: Coinkite’s Coldcard Security Advisory

What Happened in the Coldcard Hack

The first obligation in reporting a cryptocurrency theft is to separate what the public blockchain can show from what investigators infer. Bitcoin transactions are visible, but the identity of the person controlling an address is not automatically visible. Analysts can identify unusual sweeps, common timing, consolidation patterns and links between clusters of addresses. They can estimate the amount moved. They cannot always prove, from the ledger alone, that every address used the same wallet software or that every movement was unauthorized.

That caveat is especially important here because the estimated loss grew quickly. Early reports focused on one July 30 sweep involving more than 1,000 addresses and roughly 1,083 bitcoin. Subsequent waves targeted additional addresses and smaller balances. By August 4, TechCrunch reported that Galaxy Research and Elliptic considered an estimate around $130 million reasonable. The outlet also reported that at least a dozen apparent attackers may have been involved. That made “the hacker” an imprecise description. The available evidence pointed to an exploitable weakness that more than one party could use once the vulnerable key space was understood.

Coinkite’s own advisory focused on the cause and the remediation rather than declaring a final theft total. The company said a weakness in random-number generation affected seed phrases created on specified firmware versions. A seed phrase is the human-readable backup from which a wallet derives its private keys. Those private keys authorize spending. The hardware device does not physically contain bitcoin; the bitcoin remains represented on the distributed ledger. The device protects the credentials that permit the owner to sign a valid transfer.

In a correctly designed wallet, the seed should come from a sufficiently large, unpredictable set of possibilities. “Entropy” is the technical term for that unpredictability. A 128-bit security target does not mean a user types 128 characters or that a thief must guess 128 words. It means the generation process should provide a search space so vast that brute-force reconstruction is economically and computationally infeasible. Reducing that effective randomness can transform an impossible search into a practical one, especially if attackers know how the faulty generator behaved and can prioritize wallets with visible balances.

Coinkite said the affected Mk4, Mk5 and Q seeds had about 72 bits of entropy rather than the expected 128 bits, while the older Mk2 and Mk3 issue was more severe. The exact practicality of attacking a given seed depends on the implementation, the information available to attackers, the hardware used for searching, and whether the owner added independent entropy or a strong BIP-39 passphrase. The critical point is that the attacker did not need to steal the physical wallet, penetrate a bank vault, infect the user’s computer or intercept a transaction. The weakness existed at the moment the secret was created.

That is why an ordinary firmware update is insufficient. Updating changes how the device creates future seeds. It does not retroactively add randomness to a seed that already controls funded addresses. The old addresses remain tied to the old private keys, and any attacker who can reconstruct those keys can still spend the bitcoin. Remediation requires a clean key-generation process, a verified new address and an onchain transfer from the vulnerable wallet to the new one.

The episode also illustrates why security disclosures can create a dangerous race. Once a vulnerability is public—or once attackers independently discover it—holders need enough information to act, but the same information can guide additional exploitation. Users may rush, make address-verification mistakes, download malicious “updates,” reveal seed words to fake support agents or send funds to phishing destinations. A responsible advisory therefore has to be technically specific without encouraging panic. Coinkite repeatedly told users to proceed carefully, verify firmware and addresses, and send a small test transaction before moving the remaining balance.

A Timeline of the Incident

The vulnerable software lineage dates to 2021, according to the manufacturer’s disclosure and technical reporting. The public crisis emerged in late July 2026 when researchers connected suspicious bitcoin sweeps with the seed-generation weakness. Coinkite published its advisory on July 30 and updated it on August 1. The company listed corrected versions for the affected product lines and emphasized that existing seeds required migration. Over the following days, investigators identified further sweeps and revised their loss estimates upward.

The video discussion published by Bloomberg Television on August 4 captured the story while it was still changing. At that point, the program described more than $100 million stolen. Later reporting that day placed the estimate around $130 million. This is precisely the kind of event in which a fixed number can become obsolete within hours. The defensible formulation is therefore an estimate with a timestamp, not a definitive final loss.

As of the research cutoff for this article, important questions remained unanswered. Investigators had not publicly identified all attackers. It was not clear how much of the stolen bitcoin could be linked conclusively to vulnerable Coldcard-generated seeds. The prospects for recovery were uncertain. Litigation, regulatory scrutiny and compensation claims were possible, but no final legal outcome had been established. Coinkite’s technical investigation was continuing.

Why Offline Storage Was Not Enough

“Cold wallet” is a useful category, but it can become a misleading promise when treated as a synonym for invulnerable. Cold storage generally means that private keys are created or kept away from internet-connected systems. That design reduces some of the most common attack paths: remote malware, browser compromise, malicious extensions, exchange-account takeover and theft from a cloud service. It does not eliminate every path to loss.

A cold wallet can fail through weak key generation, compromised firmware, a malicious supply chain, physical tampering, insecure backups, coercion, user error, poor inheritance planning, faulty transaction verification or a deceptive interface on the online computer used to prepare a payment. The absence of a network connection addresses one dimension of risk. It does not certify the quality of the device’s code, randomness, manufacturing process or operational instructions.

The Coldcard incident is best understood as a failure before storage. Consider a traditional safe. A strong safe can protect a well-made key. It cannot protect an owner if the locksmith produced keys from a predictable sequence and an outsider learned the pattern. The door remains physically secure, yet the access credential is no longer secret. In digital-asset custody, key generation is part of the security perimeter.

This is one reason hardware-wallet security depends on reproducibility and independent review. Open-source code can allow researchers to inspect implementation choices, but public code is not a guarantee that every user has verified the binary on a device or that reviewers will catch every defect promptly. Closed code can protect proprietary details but concentrates trust in the vendor. Secure elements can resist physical extraction but introduce vendor dependencies. General-purpose chips can be easier to audit but may have a larger attack surface. There is no architecture that removes the need for tradeoffs, testing and disciplined updates.

Randomness deserves particular attention because ordinary intuition performs badly here. A sequence can look random to a person and still be mathematically predictable. A device can collect multiple sources of entropy yet accidentally bypass one through a build configuration, fallback routine or library mismatch. A system can pass superficial tests while producing a much smaller key space than designers intended. Random-number generation is therefore not a decorative component; it is foundational cryptographic infrastructure.

For individual holders, the practical lesson is not that everyone should improvise advanced security. Complexity can increase risk. Multisignature arrangements, passphrases, dice-generated entropy and geographically separated backups can strengthen a setup when implemented correctly, but they also create more opportunities for lost credentials, mismatched derivation paths, incomplete instructions and inaccessible estates. A security design should be proportionate to the value held, the user’s technical ability and the likelihood that another trusted person will eventually need to recover the funds.

For institutions, the lesson is broader. A professional custody program cannot be reduced to buying a respected device. It requires vendor due diligence, code and firmware controls, separation of duties, address allowlists, transaction policies, audit trails, incident response, insurance analysis, key rotation, recovery testing and governance over who can authorize transfers. Institutional custody is a process, not a product.

Self-Custody, Qualified Custody and the ETF Alternative

The Coldcard failure sharpened an argument that had already been moving through the market: many investors want bitcoin exposure without wanting to manage bitcoin keys. A spot exchange-traded product answers that demand by placing operational custody behind a familiar brokerage interface. BlackRock describes its iShares Bitcoin Trust ETF as a product that simplifies the operational and custody complexities of holding bitcoin directly. That description is commercially self-interested, but it identifies a real division of labor. The investor owns shares in a trust rather than personally controlling the underlying coins.

That arrangement changes the risk; it does not abolish it. Direct self-custody exposes the holder to key-generation errors, backup failures, theft, coercion and irreversible transfers. An ETF introduces sponsor, custodian, market-structure, tracking, fee, brokerage and legal risks. The shareholder cannot independently move the trust’s bitcoin onchain, use it in a payment or verify ownership through a personal key. The product is designed for price exposure, not sovereign control over the asset.

The comparison therefore depends on the investor’s objective. Someone who values censorship resistance, direct settlement and control outside financial intermediaries may regard an ETF as an incomplete substitute. Someone whose objective is portfolio exposure inside a retirement, advisory or brokerage account may regard self-custody as unnecessary operational burden. Institutions often prefer the latter route because it fits established compliance, accounting, valuation and reporting systems.

The Coldcard hack does strengthen the ETF case in one specific sense: it shows that “I hold the keys” also means “I bear responsibility for the process that generated, stored and eventually transfers those keys.” That burden can be rational for a technically capable holder, but it is not free. The cost appears in time, expertise, testing, hardware, backup design, inheritance planning and the absence of conventional error correction.

At the same time, it would be too convenient for regulated intermediaries to present the incident as proof that centralized custody is inherently safer. Crypto history contains exchange failures, lender bankruptcies, insider thefts and custody breaches. Conventional finance has fraud, operational outages and resolution risk. The meaningful comparison is between specific systems with specific controls. A hardware wallet with independently verified entropy and careful backups can be robust. A poorly governed custodian can fail catastrophically. A regulated ETF can reduce individual key-management risk while concentrating assets with a small number of service providers.

This distinction also explains why institutional adoption can grow while retail interest in direct crypto ownership weakens. Institutional demand increasingly enters through products that abstract away the underlying blockchain mechanics: ETFs, separately managed accounts, qualified custodians, OTC derivatives, structured products and corporate treasury mandates. Those channels can support market liquidity without producing the cultural enthusiasm that characterized earlier retail cycles.

The Limits of Insurance and Legal Recourse

One of the most painful differences between a stolen self-custodied asset and an unauthorized bank transaction is the lack of a standard recovery framework. U.S. bank deposits can be protected by federal deposit insurance when an insured bank fails, subject to legal limits and account rules. Consumer-payment laws may allocate liability for certain unauthorized electronic transfers. Brokerage assets can receive different protections under securities and insolvency regimes. None of those frameworks automatically reimburses a person whose bitcoin was moved with a valid cryptographic signature derived from a compromised seed.

That does not mean victims have no legal claims. They may pursue the manufacturer, software contributors, sellers or other parties under contract, negligence, product-liability or consumer-protection theories, depending on jurisdiction and facts. Law enforcement can trace funds and sometimes seize assets when attackers use identifiable services. Blockchain-analysis firms can follow consolidation and laundering patterns. Exchanges can freeze deposits connected to known thefts when law and operational controls permit. But these are contingent paths, not guaranteed compensation.

Insurance is similarly uneven. A company may have cyber, crime, errors-and-omissions or specie coverage, but policy language, exclusions, custody definitions and loss causation matter. A retail hardware-wallet user should not assume that a vendor’s corporate insurance covers customer balances. A custodian may advertise insurance that applies only to certain storage arrangements, types of theft or aggregate limits shared across clients. The headline coverage amount is not the same as a promise to reimburse every loss.

The episode therefore creates a commercial opening for firms that can package custody with transparent liability, independent audits and credible incident response. The winner may not be the product with the most technically pure architecture. It may be the provider that gives clients a comprehensible answer to four questions: Who controls the keys? Who verifies the software? Who bears the loss if controls fail? What legal process applies when something goes wrong?

Bitcoin’s Price Response Was Muted, but the Market Message Was Not

Bitcoin traded around $64,000 near the August 5 research cutoff after spending the prior week in a relatively compressed range. The lack of a dramatic price collapse after the Coldcard disclosures should not be interpreted as proof that the incident was unimportant. Bitcoin’s market price reflects global supply and demand for the asset, not a direct estimate of liability for one hardware-wallet vendor. The affected amount, while devastating for victims, represented a small fraction of Bitcoin’s total market value and did not impair consensus, block production or settlement.

Market participants also distinguish protocol risk from application and custody risk. If the Bitcoin network had permitted invalid spending, created coins outside its rules or suffered a durable consensus failure, the valuation implications would be much broader. Here, valid signatures authorized transfers because attackers were believed to have reconstructed weakly generated credentials. The protocol processed those transactions as designed. That is cold comfort to victims, but it explains the limited systemic price reaction.

Several other forces were competing for attention. Geopolitical developments, Treasury yields, equity-market risk appetite, expected U.S. regulation, ETF flows and corporate bitcoin transactions all affected positioning. On August 4, U.S. equities rallied strongly while crypto lagged the broader risk-on move. Bitcoin’s relative stability was therefore ambiguous: it could be read as resilience after a security shock, or as evidence of weak participation while investors preferred other assets.

ETF data offered a similarly mixed picture. Farside Investors recorded positive U.S. spot-bitcoin ETF flow for August 3, while the smallest U.S. product, Hashdex’s DEFI, was preparing to close. BlackRock’s IBIT remained vastly larger. The combination suggests that regulated demand had not disappeared, but it was concentrating in a few dominant vehicles. That pattern closely resembles the institutional concentration described by Wintermute in OTC markets.

Price stability can also emerge from options and arbitrage activity rather than enthusiastic long-only buying. Institutions can sell volatility, run basis trades, hedge spot exposure, construct yield strategies or neutralize directional risk. Their participation may deepen liquidity while suppressing the explosive price behavior associated with retail leverage. A calmer market is not necessarily a more bullish market. It can mean that professional strategies are absorbing and redistributing risk.

The security incident matters to valuation over a longer horizon through adoption costs. If custody failures increase insurance premiums, legal exposure, compliance spending or consumer hesitation, they can slow the conversion of interested capital into funded positions. Conversely, they can redirect demand toward ETFs, banks and institutional custodians, strengthening the role of intermediaries without materially reducing demand for bitcoin exposure. The price effect may appear through market-share shifts inside the ecosystem rather than through an immediate selloff in bitcoin itself.

Market Snapshot

A More Institutional, More Concentrated Crypto Market

  • Wintermute said institutions accounted for 72% of spot flow on its OTC desk in the first half of 2026, up from 59% in the first half of 2025.
  • The firm said the number of tokens traded by institutional counterparties grew 24% over two years, versus 76% growth for retail clients.
  • Its data pointed to heavier use of options and a narrower investable universe for professional clients.
  • These figures describe Wintermute’s own business and should not be treated as a complete census of global crypto trading.

Original source: Wintermute’s H1 2026 OTC Flow Report

What Wintermute’s 72% Institutional Figure Really Means

Wintermute’s report supplied one of the clearest data points in Bloomberg’s discussion: institutions generated 72% of spot flow across tokens on the firm’s OTC desk in the first half of 2026. The share increased from 61% in the second half of 2025 and 59% in the first half of 2025. Hedge funds, asset managers, family offices and digital-asset treasury companies were among the institutional categories cited.

The figure is meaningful because OTC desks serve clients who want execution outside a public exchange order book, customized settlement, larger trade sizes, derivatives or reduced market impact. A growing institutional share suggests that professional counterparties are using crypto as a managed exposure rather than only as a speculative retail product. It also indicates that the market maker’s balance sheet, pricing and inventory decisions are increasingly shaped by institutions.

It does not mean institutions were responsible for 72% of all global crypto volume. Wintermute’s customer mix can differ materially from centralized exchanges, decentralized exchanges, retail brokerages and regional platforms. The denominator is the firm’s own spot OTC flow. An institutional desk naturally attracts institutions. The correct conclusion is narrower: within a significant market maker’s bilateral business, professional clients reached a record share and were large enough to influence the structure of liquidity.

The report’s token-coverage data may be more revealing than the headline percentage. Institutions expanded the number of tokens they traded by 24% over two years, while retail clients expanded their universe by 76%. That gap suggests that institutionalization does not spread capital evenly across thousands of assets. Professional investors generally require liquidity, custody support, legal analysis, reliable pricing, derivatives and counterparty approval. Each requirement narrows the list.

Bitcoin and Ether remain natural anchors because they have deeper markets, more established custody, listed futures, exchange-traded products and broader research coverage. Solana and a small group of other assets can attract institutional interest where liquidity and product support are sufficient. The long tail faces a different reality: a token can be technically tradable yet operationally uninvestable for a regulated or fiduciary institution.

This concentration has consequences for the popular idea of an “altseason,” a broad rally in smaller tokens. If institutions dominate incremental capital but buy a limited set of assets, rallies may become narrower. Liquidity can cluster around the approved names, while other tokens experience sharp but fragile retail-driven moves. Market capitalization alone may overstate investability where daily depth is limited and holders are concentrated.

Options activity adds another layer. Wintermute reported strong growth in altcoin options notional, consistent with institutions seeking yield, hedging downside or expressing relative-value views. Options can support more sophisticated risk transfer, but they can also make spot price action harder to interpret. A client buying a token may simultaneously sell calls, buy puts or hedge with futures. Gross flow does not reveal a simple bullish conviction.

Why Institutional Participation Can Reduce Realized Volatility

Bloomberg’s guest, Wintermute Chief Executive Evgeny Gaevoy, connected institutional strategies with lower realized volatility. The mechanism is plausible but not automatic. Dealers and option sellers can damp short-term moves by hedging against price changes. Arbitrageurs can close price gaps between venues. Larger pools of liquidity can absorb trades that would otherwise move the market. Portfolio managers may rebalance systematically rather than chase momentum.

Yet institutions can also increase volatility when leverage, crowded positioning or correlated risk limits force simultaneous exits. The failure of a large counterparty can transmit stress across venues. Basis trades that appear neutral can unwind violently if funding, margin or custody assumptions change. Professionalization alters volatility; it does not promise permanent calm.

Lower realized volatility also has an ambiguous effect on demand. Some investors welcome a more stable asset. Traders who depend on large price swings may move elsewhere. Options sellers can earn less premium when implied volatility falls. Miners and corporate holders may experience reduced mark-to-market stress, while leveraged speculators may increase position size because recent volatility appears lower. That behavior can rebuild fragility under the surface.

The key structural shift is that bitcoin is increasingly priced across connected institutional venues: spot ETFs, CME futures, options, OTC desks, prime brokers and collateral systems. The asset remains natively digital, but its marginal price can be influenced by the same balance-sheet constraints, funding costs and risk committees that shape traditional markets. This is the convergence Coinbase executives and other industry leaders describe, though convergence also means importing conventional financial fragilities.

The CLARITY Act Is the Institutional Catalyst—and the Political Bottleneck

Market participants often use “regulatory clarity” as a catch-all phrase, but the Digital Asset Market Clarity Act is a specific and extensive legislative proposal. The Senate substitute text for H.R. 3633 would establish a framework for digital commodities and ancillary assets, divide responsibilities between the Securities and Exchange Commission and the Commodity Futures Trading Commission, create registration and disclosure pathways, address intermediary conduct and preserve or modify several existing authorities.

The bill’s significance lies in reducing the legal uncertainty that surrounds a token’s lifecycle. A project can begin with a fundraising transaction that looks like an investment contract and later operate through a network whose token trades more like a commodity. Existing U.S. law has struggled to map that evolution consistently. Courts, agencies and market participants have argued over whether the security is the token itself, the transaction in which it was sold, or the continuing relationship between buyers and the promoter.

The Senate text attempts to build categories and procedures around that problem. It proposes a disclosure regime for “ancillary assets,” restrictions on dispositions by related persons, rules for intermediaries and coordination between the SEC and CFTC. A committee summary describes a “Regulation Crypto” exemption that would allow qualifying offerings under specified fundraising limits and continuing disclosure obligations. The full text is hundreds of pages, and its effects would depend heavily on agency rulemaking.

For institutions, the benefit is not simply a friendlier label. Legal classification affects which entity can custody an asset, where it can trade, how a broker reports it, what capital and compliance rules apply, which disclosures investors receive and what happens during insolvency. Uncertainty raises the cost of every internal approval. A clear but demanding rule can be easier to underwrite than a permissive environment governed by enforcement after the fact.

Wintermute’s Gaevoy described passage as a potentially powerful catalyst and argued that failure was already substantially reflected in market expectations. That is an opinion, not an observable fact. Legislative outcomes can be partially priced, but there is no objective meter showing how much of a bill’s failure is embedded in bitcoin or altcoin prices. The market’s reaction would also depend on the final text, implementation dates, amendments and whether the legislation resolves or creates new uncertainties.

The more defensible conclusion is that passage would expand the set of institutions willing to devote resources to U.S. crypto businesses. It could unlock product planning that is currently conditional on classification, exchange registration and custody rules. It would not guarantee rising token prices, successful projects or broad retail adoption. Regulation can increase compliance costs, eliminate business models and concentrate activity among firms large enough to satisfy the rules.

What the Bill Says About Investor Protection

Supporters emphasize disclosures, anti-fraud authority, resale restrictions, financial literacy and regulator coordination. The Senate Banking Committee’s fact sheet says the framework would preserve anti-fraud powers and require timely information for market participants. The bill text also addresses how brokers and dealers should disclose the treatment of digital commodities, payment stablecoins and related securities in insolvency, resolution or liquidation.

Those provisions respond to real failures exposed by the 2022 crypto bankruptcies. Customers often discovered that an account marketed like a deposit or wallet was legally an unsecured claim against a company. Asset segregation, books and records, rehypothecation, customer agreements and bankruptcy treatment determined recovery. A token’s market price mattered less than the customer’s place in the creditor hierarchy.

However, legislative fact sheets are advocacy documents. They summarize the sponsor’s case, not an independent assessment of every loophole or implementation risk. Investor protection depends on definitions, exemptions, enforcement budgets, state-federal coordination and the ability of agencies to write workable rules. A disclosure can be legally complete yet economically unhelpful. A registration category can create accountability while also encouraging activity to move offshore or into less transparent structures.

A central debate is whether the bill preserves enough securities-law protection when tokens are separated from the investment contracts through which they were distributed. Critics worry that issuers could use decentralization claims, certification procedures or exemptions to escape the full obligations applied to public securities. Supporters argue that applying conventional public-company rules indefinitely to network tokens is conceptually wrong and pushes legitimate activity abroad.

Both positions recognize the same underlying problem: digital assets combine elements of software, financing, commodities, payments and governance. The disagreement concerns which legal framework should dominate and when. The bill is not merely a contest between “regulation” and “innovation.” It is a contest between regulatory architectures.

Regulatory Status

What the Senate CLARITY Proposal Tries to Do

  • Create federal categories and procedures for digital commodities and ancillary assets.
  • Allocate responsibilities between the SEC and CFTC and require coordination.
  • Establish disclosure, resale and intermediary requirements under specified conditions.
  • Address investor education, anti-fraud authority and treatment of customer assets in insolvency.
  • Leave substantial implementation work to future agency rules.

Original source: Senate substitute text for H.R. 3633

Why Ethics Became More Than a Side Issue

The bill’s path narrowed because digital-asset policy collided with presidential financial interests. Democratic lawmakers argued that any market-structure legislation should include stronger restrictions on elected officials profiting from crypto ventures. The debate intensified around President Donald Trump’s family-linked projects, token activity and disclosed crypto income. The Wall Street Journal reported that opposition hardened after disclosures showing roughly $1.4 billion in crypto-related income.

That dispute is not peripheral. A law that increases the legitimacy, liquidity or economic value of an industry can create a conflict when officials involved in shaping the law have direct financial exposure to that industry. Traditional ethics rules address holdings, gifts, outside income and disclosure, but crypto ventures can involve tokens, governance rights, fees, licensing arrangements and decentralized entities that do not fit neatly into older categories.

Blockchain Association Chief Executive Summer Mersinger told Bloomberg that ethics terms should be worked out by elected officials and that the industry was encouraging negotiations rather than dictating the outcome. The position is understandable from a trade association seeking passage. It is also strategically risky. Neutrality on an issue that determines votes can look like indifference to the legitimacy of the law.

Critics led by Senator Elizabeth Warren argued that Republican language contained loopholes and did not adequately prevent future profits tied to office. Supporters countered that ethics provisions should apply consistently across officials and assets rather than become a vehicle for targeting one person. The substantive policy question became entangled with partisan trust: would the final restrictions meaningfully constrain conflicts, or merely create a headline that allowed the market bill to advance?

The legislative calendar magnified the disagreement. A bill of this scale requires floor time, procedural votes and enough bipartisan support to overcome a filibuster. If the Senate changes the House-passed text, the chambers must reconcile differences. Agency implementation follows enactment. An approaching recess and midterm campaign season made every unresolved issue more costly.

Prediction-market odds and analyst estimates moved lower as the window narrowed, but those indicators should be treated as sentiment measures, not constitutional facts. A last-minute agreement can change the calendar. A procedural vote can reveal support that was not public. Conversely, a public agreement can collapse over amendment language. The only definitive milestones are formal votes and enacted text.

The Banking Industry’s Stablecoin Objection

Ethics was not the only obstacle. Banks and crypto firms continued to dispute whether stablecoin issuers or affiliated platforms should be able to offer yield-like rewards. Banks argue that interest-bearing or reward-bearing stablecoins can pull deposits from the regulated banking system, reducing a funding base used for lending. Crypto firms respond that competition can improve payment products and that banks are protecting incumbency.

The distinction between an issuer paying interest and a separate platform paying rewards can become economically thin. If a customer holds a dollar token because an affiliated exchange pays a return, the product competes with a deposit even if the issuer itself does not promise interest. Legislators must decide whether to regulate form, economic substance or both.

This issue connects directly to Visa’s strategy and to tokenized deposits. Stablecoins can circulate across networks and platforms, potentially outside a single bank relationship. Tokenized deposits remain claims on a bank and preserve the deposit inside the banking system. Both can move value on blockchain infrastructure, but they distribute economics, legal claims and control differently. The policy outcome will influence which model wins institutional adoption.

For investors, the bill’s delay is less important than the eventual architecture. A rushed law that leaves ambiguous definitions could generate years of litigation. A durable compromise could lower legal costs while imposing meaningful controls. A complete failure would preserve the current patchwork of agency actions, court decisions, state licensing and product-specific exemptions. None of those outcomes maps cleanly to a single bitcoin price target.

Visa’s Stablecoin Platform Shows How Incumbents Plan to Stay in the Middle

Visa’s July 16 launch of the Visa Stablecoin Platform is a useful counterpoint to the self-custody crisis. Where the Coldcard model places control with the holder, Visa’s platform packages operational control for institutions. It offers a managed environment for wallet infrastructure, minting, redemption, transfers, user permissions, dual approvals, audit logging, passkeys and allowlists.

The platform is initially available in beta to selected clients and begins with Open USD, a stablecoin introduced by the Open Standard consortium. Visa says institutions can connect existing wallets or use a Visa-managed stack, link bank accounts, configure policies and integrate stablecoin operations with settlement and treasury workflows. The product sits alongside Visa’s stablecoin-linked cards, settlement and money-movement services.

This is not Visa abandoning its network for a public blockchain. It is Visa extending its role as an orchestration and acceptance layer. Stablecoins can transfer value quickly, but they do not automatically provide merchant acceptance, fraud management, dispute processes, compliance integration, foreign-exchange services or bank connectivity. Visa’s commercial thesis is that those surrounding services become more valuable as money becomes more programmable.

Cuy Sheffield, Visa’s head of crypto, made the argument directly: stablecoins have infrastructure but lack acceptance at scale. A user may hold a dollar token onchain, yet the local merchant expects an ordinary card payment and settlement in local currency. A stablecoin-linked card allows the token to fund a purchase while the merchant experiences the familiar Visa flow. The blockchain may sit behind the product rather than replacing the point-of-sale network.

This strategy resembles the way internet technology changed banking without eliminating banks. Open protocols reduced the cost of communication, but regulated institutions continued to own customer relationships, compliance and balance sheets. Stablecoins may reduce friction in settlement while increasing demand for companies that connect blockchains to merchants, banks and currencies.

Visa’s position is not unassailable. Stablecoin networks could develop native merchant acceptance, lower-cost QR payments or direct account-to-account transfers. Large platforms could bypass card economics. Central banks and instant-payment systems could improve cross-border functionality. Merchants may resist fees if onchain alternatives become easier. Visa must demonstrate that its controls and reach justify its place in the transaction.

There is also a strategic tension between neutrality and sponsorship. A network that supports many stablecoins can present itself as an interoperable bridge. Beginning the platform with Open USD, in which Visa is a consortium participant, gives it a direct stake in one ecosystem. Banks may welcome the governance model or hesitate until reserve, custody, redemption and legal details are more developed.

Why Stablecoins Still Need Conventional Payment Networks

The headline question raised in the Bloomberg discussion—why stablecoins need Visa when trillions of dollars already move on public blockchains—has two different answers depending on what “need” means. Stablecoins do not need Visa to exist, settle onchain or move between compatible wallets. The networks operate without a card company’s permission. But a stablecoin that is technically transferable is not automatically accepted at grocery stores, airlines, hotels, medical offices or millions of small businesses. Nor does a token by itself provide the full suite of identity checks, sanctions screening, fraud management, foreign-exchange conversion, merchant acquiring, chargeback rules, consumer interfaces and bank connectivity that commercial payments require.

Visa’s strongest argument is therefore not that it owns the new rail. It is that it can connect the new rail to the places where people already spend money. The company says its network reaches roughly 200 million merchant locations worldwide. A stablecoin-linked card can allow a customer to hold or receive digital dollars while the merchant continues to receive familiar local-currency settlement through an existing acquiring relationship. To the cardholder, the funding source may be a stablecoin balance. To the merchant, the transaction can still look like a conventional Visa payment.

That bridge is commercially valuable because adoption rarely occurs through a clean replacement of one system by another. Payment technology tends to layer new funding and settlement methods on top of old acceptance infrastructure. Contactless cards did not require every merchant to become a bank. Mobile wallets did not eliminate card networks; they tokenized card credentials and changed the interface. Stablecoin-linked cards follow a similar pattern: a blockchain can handle part of the value chain while the card network handles authorization, acceptance, conversion and merchant settlement.

The limitation is cost and dependency. One reason stablecoins attract businesses is the possibility of reducing the number of intermediaries in cross-border transfers. If the token is merely inserted beneath the same collection of network fees, acquiring fees, foreign-exchange spreads and compliance costs, the economic advantage can shrink. Visa must show that stablecoin settlement reduces friction rather than simply adding another layer to a mature fee stack.

The company also faces a strategic contradiction. Stablecoins can help Visa by expanding card programs and making international funding faster. They can also weaken the importance of card networks if merchants and consumers increasingly transact wallet to wallet. A business that receives regulated tokenized dollars directly, settles instantly and can convert them through liquid markets may not always need an authorization network designed around bank accounts and delayed settlement. Visa’s response is to become the infrastructure provider before direct onchain payments become large enough to bypass it.

That approach resembles the company’s history of adapting to new interfaces while preserving its place in the transaction. Visa does not generally lend the consumer the money and does not usually own the bank account. Its value comes from rules, routing, trust, acceptance and interoperability. A stablecoin platform extends that model upstream, giving banks and fintechs tools to create and manage tokenized money while keeping Visa connected to issuance and spending.

Acceptance Is Only One Part of the Problem

The institutional obstacles are broader than merchant reach. A bank considering a stablecoin product must decide who can mint and burn tokens, how reserves are held, how redemption works, which blockchains are supported, what happens when a chain stops finalizing transactions, how compromised addresses are treated, and how the institution reconciles blockchain records with its general ledger. It must also define controls for privileged administrators, transaction limits, key recovery, customer screening, audit trails and incident response.

Those are not glamorous features, but they determine whether a product survives a risk committee. Visa’s platform emphasizes dual controls, allowlists, passkey-based access and audit logs because institutional buyers are less interested in ideological purity than in operational accountability. A treasury department wants to know who approved a transfer, which policy allowed it, and how the transaction will appear in financial statements. It also wants a path for responding to fraud or legal orders.

Blockchain settlement can be final even when the business process behind it is not. A bank may still need to reverse an accounting entry, reimburse a customer, freeze a related account or pursue legal recovery after an onchain transfer has completed. The institution must therefore build procedures around a technology that does not necessarily provide the same reversibility as card or automated-clearing-house systems. That difference is manageable, but it cannot be ignored.

Liquidity creates another dependency. A stablecoin may trade near one dollar under normal conditions but still face redemption queues, market discounts or chain-specific liquidity gaps during stress. Banks need to understand the composition and duration of reserves, the rights of token holders, the location of cash and securities, and whether a redemption promise is legally enforceable. A polished issuance dashboard does not answer those questions by itself.

Open USD Gives Visa a Governance Experiment, Not Yet a Finished Standard

Visa began the beta version of its platform with Open USD, a stablecoin associated with the Open Standard consortium. The choice attracted attention because the market is dominated by established issuers, especially Tether’s USDT and Circle’s USDC. Open USD was comparatively new and had not yet accumulated the circulation, liquidity or track record of those larger tokens.

The consortium’s stated model is designed to distribute stablecoin economics more broadly. Participating companies can share in reserve income, after management costs, rather than leaving that revenue entirely with one issuer. The group also emphasizes open governance and free minting and redemption. In theory, those features can align wallets, exchanges, payment firms and fintech applications around a common dollar token.

The commercial logic is clear. Stablecoin issuers can earn substantial income by investing reserves in short-duration government securities and cash equivalents while paying little or no interest to token holders. As policy rates rose in the early 2020s, that reserve-income model became highly profitable. A consortium that shares part of the economics can recruit distribution partners more effectively than an issuer that keeps nearly all reserve yield.

Shared economics do not automatically produce shared trust. Institutional users still need definitive information about reserve assets, custodians, bankruptcy treatment, redemption rights, audit or attestation arrangements, supported networks and emergency governance. As of the research cutoff for this article, several of those details remained less developed publicly than the equivalent disclosures available for the largest incumbent stablecoins. Open USD should therefore be understood as an emerging network design rather than an established institutional standard.

Visa’s participation can improve credibility, but it does not substitute for reserve transparency. Nor does a consortium structure eliminate concentration. Governance can become fragmented if many partners have competing interests, or centralized if a small group retains practical control over upgrades, freezes and treasury decisions. The durability of Open USD will depend less on the number of logos in the consortium than on the legal and technical rules behind them.

Fact Box

What Visa’s Stablecoin Platform Is Designed to Do

  • Give banks, fintechs and crypto companies one environment for minting, burning, holding, redeeming and transferring stablecoins.
  • Connect token operations with bank accounts and institutional controls such as dual approval, allowlists and audit logs.
  • Support professional-services work that helps clients select use cases and move from a sandbox toward production.
  • Begin with Open USD while continuing to support other stablecoins through Visa’s broader settlement and card programs.

Original source: Visa’s July 16, 2026 platform announcement

Stablecoin Volume Is Large, but the Measurement Requires Care

The scale of stablecoin transfers helps explain why banks and payment companies are paying attention. Visa’s analytics framework estimated adjusted stablecoin volume of approximately $1.79 trillion in June 2026 and about $8.82 trillion during the first half of the year. The adjusted figure attempts to remove activity that can overstate genuine payment or trading demand, including automated transactions and transfers between addresses controlled by the same entity.

That adjustment is essential. Public blockchains record movements, not economic purpose. One dollar can be transferred repeatedly among exchanges, market makers, smart contracts and internal wallets, creating large gross volume without representing an equivalent amount of purchases or remittances. Raw blockchain volume therefore cannot be compared directly with card purchase volume or bank-payment statistics.

Even adjusted data has methodological limits. Address ownership is imperfectly known, automated activity can resemble human activity, and a transfer may support trading, collateral management, treasury movement or payments rather than one clear category. Different analytics firms use different filters. The result is not a single universally accepted measure of “stablecoin payments.”

The composition of activity matters as much as the total. USDC accounted for a large majority of adjusted volume in the first half of 2026 under Visa’s methodology, while USDT remained the larger token by circulation. That divergence shows how market capitalization and transaction usage can tell different stories. One token may dominate balances, another may dominate activity in regulated venues or decentralized-finance applications, and a third may gain traction in a specific region.

Visa’s opportunity depends on how much of that volume can become commercial flow rather than trading infrastructure. A token moved between two exchanges may generate little value for a card network. A payroll payment, supplier invoice, cross-border remittance or merchant purchase is more relevant. The company’s platform strategy is an attempt to influence the composition of stablecoin activity, not merely attach itself to an already-large number.

There is also a distinction between stablecoin settlement and stablecoin-linked spending. Visa has allowed selected issuers and acquirers to settle obligations using USDC, and it supports cards funded by stablecoin balances. Those are separate use cases. Settlement changes how financial institutions pay Visa or one another. A linked card changes how a consumer funds a purchase. The underlying token may be the same, but the economics, risks and regulatory treatment differ.

Tokenized Deposits and Stablecoins Are Competing Versions of Digital Money

The stablecoin debate becomes more complicated when commercial banks issue tokenized deposits. A tokenized deposit is generally a digital representation of a claim on a specific regulated bank. It can move on a blockchain or distributed ledger, but it remains tied to the bank’s balance sheet and deposit framework. A stablecoin is usually issued by a nonbank entity or special-purpose structure and backed by reserves held outside the ordinary deposit account relationship.

For a corporate treasurer, the distinction affects credit exposure, insurance, redemption, yield, interoperability and legal rights. A tokenized deposit at Wells Fargo may be useful inside a controlled network of approved clients. A widely circulating stablecoin may be easier to transfer across exchanges, wallets and decentralized applications. One offers a familiar banking relationship; the other may offer broader portability.

Wells Fargo said in August 2026 that it planned to introduce tokenized deposits for corporate and commercial clients, initially supporting U.S. dollar and British pound transfers. The bank’s project is intended to enable around-the-clock movement and faster cross-border activity on proprietary infrastructure. A separate group of large U.S. banks has been working through The Clearing House on a shared tokenized-deposit system, illustrating the industry’s preference for bank-issued money that can interoperate without ceding the customer relationship to a stablecoin company.

Feature Stablecoin Tokenized bank deposit Bitcoin
Economic claim Claim on an issuer or reserve structure, depending on legal design Deposit claim on a specific bank Native bearer-like digital asset with no issuer redemption promise
Price objective Usually targets one unit of fiat currency Denominated as a bank deposit in fiat currency Market-determined and volatile
Primary institutional appeal Portability across supported networks and platforms Existing bank relationship, compliance framework and balance-sheet integration Investment exposure, collateral use and censorship-resistant settlement characteristics
Key risk Reserve, redemption, issuer, legal and depegging risk Bank credit risk, network limits and restricted interoperability Price volatility, custody loss, network fees and regulatory uncertainty
Typical control model Issuer and smart-contract controls vary by token Bank-controlled permissions and identity requirements Control follows possession of valid private keys

Comparison reflects general structures; individual products can differ materially in legal rights, controls and technical design.

Why Banks Prefer Deposits They Control

Deposits are a core source of funding for banks. If customers move large balances into third-party stablecoins, banks can lose both funding and transaction data. Tokenized deposits allow them to offer faster, programmable movement without surrendering the liability relationship. The bank still knows the customer, controls access and can integrate the token with lending, cash management and foreign exchange.

That control can be an advantage for regulated institutions and a limitation for users. A proprietary bank token may work only among approved clients or within one network. Transferring it to a decentralized exchange, foreign wallet or competing bank may be impossible. A stablecoin with broad blockchain support can be more useful precisely because it is less tied to one institution.

The likely outcome is not one universal winner. Corporate treasury may use tokenized deposits for large, permissioned transfers and stablecoins for open-network payments or liquidity. Banks may issue their own tokens while holding or settling third-party stablecoins. Card networks may connect both forms to merchants. The result could be a layered system in which several digital-dollar claims coexist, each optimized for different legal and commercial needs.

Deposit Insurance Is Not Automatically Portable to a Token

Terms such as “deposit token” can create an impression that all familiar deposit protections automatically follow the asset. That should not be assumed. Coverage can depend on how the token is recorded, who owns the underlying account, whether the product is a direct deposit liability, and whether pass-through requirements are satisfied. Cross-border products add further jurisdictional differences.

Corporate balances also often exceed statutory insurance limits. For large businesses, the more important questions may be the issuing bank’s credit quality, legal segregation, settlement finality and operational continuity. The word “deposit” improves familiarity, but the contract and regulatory structure remain decisive.

Tokenization Is Advancing, but Most Projects Remain Small Beside Traditional Markets

Ophelia Snyder’s most useful contribution to the Bloomberg discussion was to separate technical proof from institutional scale. Financial firms have demonstrated that securities, funds, deposits and other claims can be represented on distributed ledgers. The harder question is whether those systems can handle a meaningful share of production activity while integrating with accounting, collateral, risk, compliance and settlement processes built over decades.

Public data from RWA.xyz showed approximately $37.38 billion of distributed tokenized real-world assets at the research cutoff, including about $16.17 billion of tokenized U.S. Treasury products. Those totals are substantial for a young market and small compared with the tens of trillions of dollars in global bonds, bank deposits and investment funds. The figures support both sides of the argument: tokenization is no longer a laboratory curiosity, yet it remains far from wholesale replacement of conventional infrastructure.

Tokenized Treasuries have been an effective early use case because the underlying asset is standardized, liquid and familiar. Investors can hold a blockchain-based interest in a fund or special-purpose vehicle that owns government securities. The token can serve as collateral in some applications and may offer faster transfer among approved participants. High short-term interest rates have also made the products commercially attractive.

But the token is not the Treasury security itself in every legal sense. Investors may own a share in a fund, a claim on an issuer or another contractual interest. Redemption can depend on administrators, transfer agents, custodians and banking hours even when the token moves around the clock. The blockchain layer can accelerate one part of the process while the legal asset and cash rails remain conventional.

This is why headline asset values can overstate the degree of transformation. A fund may issue tokenized shares while relying on traditional custody, portfolio accounting, cash settlement and identity checks. The token improves distribution or transferability, but the operating model is hybrid. That is still useful; it is simply different from replacing the financial system with autonomous smart contracts.

The Middleware Problem

Large financial institutions rarely run on one integrated technology stack. Trading systems, risk engines, general ledgers, customer databases, compliance tools, collateral platforms and reporting software may come from different vendors and update at different intervals. A tokenized transaction must be reflected consistently across those systems. If it settles at 2 a.m. on Sunday, the institution needs to know which risk limits apply, when valuation updates occur and how the transfer enters books that were designed around business days.

Margin is a clear example. A tokenized asset can move at any hour, but the institution’s credit team may not be staffed around the clock. Prices can change while conventional collateral systems are closed. If a smart contract automatically calls for more collateral on Saturday, the firm needs governance for meeting, disputing or liquidating the position. Twenty-four-hour settlement creates efficiency only when operational control becomes twenty-four-hour control.

Accounting presents a different challenge. The blockchain record proves that an address sent a token to another address. It may not prove the economic owner, purpose, tax treatment, valuation hierarchy or legal finality required by the institution’s books. Systems must map wallet addresses to customers and entities, classify transactions, calculate gains or losses, and preserve documentation for auditors and regulators.

Identity is similarly layered. Permissioned networks can restrict participation, but institutions still need to maintain customer files, screen counterparties and respond to changes in sanctions or risk status. A wallet approved yesterday may be compromised today. A smart contract may interact with hundreds of addresses indirectly. Compliance cannot be reduced to checking one address at onboarding.

Tokenization Does Not Guarantee Liquidity

One of the most persistent misconceptions is that putting an asset on a blockchain automatically makes it liquid. Liquidity requires buyers, sellers, market makers, price discovery, standardized rights, reliable custody and confidence that the asset can be redeemed or transferred. A token representing a private loan or a slice of real estate can still trade rarely and at a wide spread.

The problem can become more visible onchain because every inactive market is observable. Fractional ownership may lower the minimum investment, but it does not create demand. If legal restrictions limit who can buy, or if each platform uses a different token standard, the market can fragment into isolated pools.

Tokenized funds and securities can also introduce new forms of operational liquidity risk. Investors may expect instant redemption because the token transfers instantly, while the underlying portfolio settles on a slower schedule. In normal conditions the issuer can manage the mismatch. During stress, a rush for redemption may collide with banking hours, market closures or limited cash buffers.

The strongest tokenization projects acknowledge these dependencies rather than promising to erase them. They define settlement windows, redemption terms, eligible participants and fallback procedures. Institutional adoption will be measured by how well those systems behave during volatility, not by the speed of a demonstration transaction.

What Would Count as Genuine Scale?

Snyder suggested that the important threshold is not universal conversion but critical mass. A practical measure would be the share of a bank’s eligible deposits, a fund manager’s assets or a market’s daily settlement volume that routinely uses tokenized infrastructure. A few billion dollars can validate technology. A double-digit percentage of production flow would change operating priorities, vendor budgets and risk practices.

Scale would also be visible in behavior rather than announcements. Firms would report tokenized volume as an ordinary operating metric. Auditors would treat the systems as established control environments. Collateral could move between institutions without bespoke integration for every pair. Assets issued on one platform could be financed or traded on another under consistent legal rules.

Another sign would be resilience during failure. A mature system needs procedures for chain outages, software bugs, key compromise, erroneous transfers, forks and administrator misconduct. Traditional market infrastructure has its own failures, but decades of rules define how participants respond. Tokenized markets must build comparable operational memory.

CME’s Compute Futures Show How Crypto Infrastructure Is Converging With AI

The Bloomberg program also examined a less obvious convergence: the creation of futures tied to the price of computing power. CME Group and Silicon Data announced plans in May 2026 to launch contracts based on rental prices for high-performance graphics processing units, subject to regulatory review. The intended users include AI developers that buy compute, cloud providers that sell it and investors seeking exposure to an emerging economic input.

The idea is straightforward at a high level. An AI company may commit to products or customer contracts today while remaining uncertain about the cost of GPU capacity months later. A cloud provider may invest heavily in data centers and fear that rental prices will fall as supply expands or new chips become more efficient. Futures could allow each side to transfer part of that price risk.

CME Chairman and Chief Executive Terry Duffy described computing power as the “new oil” for the next decade. The comparison captures the economic importance of the resource but obscures a major technical difference. Oil can be stored. A barrel purchased today can, within physical and financial limits, be carried into the future. Unused computing capacity at 3 p.m. cannot be stored and delivered at 3 p.m. next month.

That non-storability changes the relationship between spot and futures prices. Commodity markets often rely on cash-and-carry arbitrage: traders buy the physical asset, store it and sell a futures contract when the price difference exceeds financing and storage costs. Compute lacks that mechanism. A futures curve must instead reflect expectations about future supply, demand, chip performance, energy costs, utilization and contract terms.

Standardization is another obstacle. “GPU compute” is not one uniform product. An Nvidia A100, H100 and B200 differ in performance, memory, energy use and suitability for specific workloads. Location matters because data-transfer latency and electricity costs matter. So do software configuration, networking, uptime guarantees and contract duration. A benchmark must normalize enough differences to create a tradable reference without becoming detached from the capacity businesses actually buy.

Silicon Data’s indices are intended to provide daily rental-price references for specific GPU classes. That can improve transparency in a market where prices are often negotiated privately. But a credible derivatives market requires more than an index. It needs robust data collection, resistance to manipulation, sufficient participants and a settlement methodology that remains meaningful when hardware generations change quickly.

Who Might Use Compute Futures?

AI model developers are the most intuitive buyers of price protection. Training and serving large models can require significant compute commitments. If rental rates rise unexpectedly, margins can deteriorate. A long futures position could offset part of that increase. The hedge would be imperfect if the developer uses different hardware or negotiates a bundled cloud contract, but it may still reduce broad price exposure.

Cloud providers and data-center operators could take the other side. They invest before demand is fully known and may want protection against falling rental rates. A short futures position could gain value when the benchmark declines, partially offsetting weaker revenue from physical capacity.

Chipmakers, lenders and project financiers may also use the curve. A bank financing a data center wants to assess future cash flow. A liquid benchmark could support loan covenants, valuation models or structured products. Investors may trade the contracts as a view on AI demand, semiconductor supply or power constraints.

Speculative participation is not inherently harmful; it can add liquidity and price discovery. The risk is that financial volume grows faster than the underlying benchmark’s depth. If a small number of observable rental quotes determine settlement for a large derivatives market, incentives to influence the index can become substantial.

Why This Matters to Bitcoin Miners

Bitcoin mining companies sit near the intersection because they already own or control land, grid connections, substations, cooling systems and power contracts. Those assets can be difficult and time-consuming to secure. As the economics of pure bitcoin mining became more volatile, several operators began converting or developing sites for AI and high-performance computing customers.

The pivot can improve revenue visibility. Bitcoin-mining income depends on the token’s price, network difficulty, transaction fees, equipment efficiency and the block subsidy. Hosting AI workloads can involve longer contracts and creditworthy corporate customers. That may produce steadier cash flow, although building an AI-ready data center often requires substantial additional capital.

The infrastructure is not perfectly interchangeable. Bitcoin mining uses specialized application-specific integrated circuit machines and can tolerate interruptions more readily than many AI workloads. AI data centers may require higher network reliability, different cooling, more complex buildings, redundant systems and service-level commitments. A site with cheap electricity is valuable, but conversion is not as simple as replacing one set of servers with another.

Power remains the shared constraint. Both activities consume large amounts of electricity, and both can be located where capacity is available. Mining operators that developed relationships with utilities and secured interconnections gained an option on future compute demand. In some cases, that option may now be worth more than the original mining business.

The market has begun to distinguish between companies that remain primarily exposed to bitcoin and those that have credible AI contracts or development pipelines. That distinction can be rational, but it also creates room for overstatement. Announcing an AI strategy is not the same as financing, building and operating a facility to hyperscale standards. Investors need to examine contract counterparties, capital requirements, completion guarantees, power availability and the share of revenue actually generated by AI customers.

Could Miners Switch Back if Bitcoin Rallies?

A large increase in bitcoin’s price would improve mining economics, but it would not necessarily cause an immediate reversal. Facilities converted for AI may be committed under multiyear contracts. Hardware, cooling and networking may no longer be optimized for mining. Corporate customers may impose uptime obligations that prevent opportunistic switching.

Operators can still retain a mixed portfolio. Some sites may continue mining because they are remote, interruptible or unsuitable for AI. Others may host high-performance computing. The ability to allocate capital across both businesses can reduce dependence on one market, provided management does not overextend the balance sheet.

The decision is ultimately based on risk-adjusted returns, not ideological loyalty. Mining can generate exceptional cash flow during a strong bitcoin market but exposes the operator to rapid reversals and increasing network competition. AI hosting may offer longer contracts but require more construction risk and customer concentration. A company that understands both may be more resilient; a company that chases whichever narrative currently commands the highest valuation may destroy capital.

Fact Box

CME’s Proposed Compute Futures

  • CME Group and Silicon Data announced the project on May 12, 2026.
  • The contracts are intended to reference daily GPU rental-price indices and launch later in 2026, pending regulatory review.
  • Potential users include AI developers, cloud providers, data-center operators and financial institutions.
  • The market-design challenge is that compute is heterogeneous and cannot be stored like oil, metals or agricultural commodities.

Original source: CME Group and Silicon Data announcement

The Common Thread Is Institutional Control

The Coldcard incident, the CLARITY Act, Visa’s platform, tokenized deposits and compute futures may appear to be separate stories. They are linked by one question: what controls are required when a technology developed outside traditional finance becomes part of institutional finance?

Coldcard shows that cryptographic self-custody is only as strong as the full process that creates and protects keys. Institutional buyers cannot rely on the slogan that offline equals safe. They need tested entropy, reproducible firmware, secure manufacturing, documented upgrades and incident procedures.

The CLARITY Act addresses a parallel governance problem at the market level. Institutions want to know which regulator oversees an asset, how intermediaries register, what disclosures issuers must make and how customer property is protected. The absence of those answers does not stop crypto trading, but it limits the number of institutions willing to build critical operations on the market.

Visa and the banks are solving the integration problem. They are packaging onchain functions inside familiar approval, identity and accounting systems. Their platforms may sacrifice some openness, but they are designed to satisfy the institutions that control deposits, merchant relationships and regulated balance sheets.

CME is performing a similar translation for compute. It is taking a privately negotiated, technically complex resource and attempting to turn it into a standardized financial risk. The exchange’s value is not the creation of GPUs. It is the contract, benchmark, clearing and market structure around their price.

In each case, institutionalization means adding layers that crypto’s earliest advocates often sought to avoid: administrators, intermediaries, rules, insurance, disclosures and dispute procedures. Those layers can reduce certain risks while creating new concentration and dependency. The result is neither pure decentralization nor a simple return to old finance. It is a hybrid system.

The Strongest Case for the Institutional Crypto Thesis

The optimistic interpretation is that crypto has moved beyond a speculative retail cycle and is becoming embedded in mainstream financial infrastructure. Wintermute’s client mix suggests more professional participation. Visa is investing in stablecoin issuance and settlement. Large banks are developing tokenized deposits. CME is building derivatives around a resource market partly supplied by former bitcoin miners. Congress is debating a detailed market-structure framework rather than whether digital assets should exist at all.

Institutional participation can improve liquidity and reduce some forms of volatility. Professional market makers quote continuously, arbitrage price differences and support larger trades. Custodians, auditors and regulated intermediaries can make access easier for pension funds, corporations and advisers that cannot safely manage private keys.

Stablecoins provide a practical use case independent of token-price appreciation. They can move dollar value internationally outside limited banking hours, serve as collateral in digital markets and simplify treasury operations for businesses working across jurisdictions. Tokenized deposits may bring similar benefits inside regulated bank networks.

Market-structure legislation could make those uses easier to scale by defining responsibilities. If intermediaries know whether the SEC or CFTC has authority, and customers receive enforceable protections for their property, firms can invest with greater confidence. A clear framework may also make enforcement more consistent by replacing jurisdictional disputes with explicit rules.

The security incident itself can support the maturity argument if the industry responds well. Public disclosure, firmware fixes, migration guidance and forensic investigation are how an ecosystem improves. No financial technology eliminates theft. The relevant test is whether vulnerabilities are identified, communicated and corrected, and whether users can obtain meaningful remedies.

The Strongest Skeptical Case

The skeptical interpretation begins with the same facts and reaches a different conclusion. Institutional share can rise because retail activity collapses, not because overall demand expands. A concentrated market dominated by a handful of tokens and professional firms may be more efficient but less broad-based. Lower volatility can reflect maturity or lack of interest.

Stablecoin volume may look impressive while remaining heavily tied to trading, collateral and internal transfers. Adjusted metrics improve the picture but depend on assumptions. The use of stablecoins for everyday commerce remains small compared with conventional payment systems. Banks and Visa may be experimenting defensively rather than committing their core businesses.

Tokenization announcements can outpace production. A pilot involving a few clients does not prove that the system can handle large volumes, stress, legal disputes or cross-platform settlement. Distributed-ledger projects have repeatedly demonstrated technical feasibility without overcoming institutional inertia and fragmented standards.

Regulatory clarity can also favor incumbents. Compliance costs may be manageable for large exchanges, banks and card networks but prohibitive for smaller developers. Rules intended to protect customers can consolidate the market around firms with the largest legal and lobbying budgets. That outcome may reduce fraud while weakening competition and open access.

The Coldcard losses challenge a core promise of self-custody. Users accepted the burden of holding keys in exchange for independence from exchanges and banks. A flaw in a trusted hardware device undermined that bargain. Without deposit insurance or a responsible intermediary able to reverse transfers, sophisticated technology can leave ordinary users with less recourse than conventional finance.

Finally, political conflict may prevent the legislation from delivering stable rules. Ethics concerns, banking disputes and partisan incentives are not peripheral. They determine whether a bill can pass and whether the public views it as legitimate. A market structure associated with political self-enrichment would struggle to command lasting confidence even if its technical provisions were sound.

What the Evidence Supports—and What It Does Not

The evidence supports the conclusion that institutional involvement in digital assets is expanding across trading, custody, payments and infrastructure. It does not support the stronger claim that crypto has already become a normal, fully integrated part of global finance. The projects are material, but most remain small relative to the systems they seek to complement or replace.

The evidence supports the conclusion that the Coldcard vulnerability exposed some users to catastrophic theft. It does not prove that every Coldcard, every hardware wallet or every offline custody method is unsafe. The flaw affected specific firmware and seed-generation conditions. Devices using properly generated seeds outside those conditions were not implicated by the advisory.

The evidence supports the conclusion that institutions accounted for 72% of Wintermute’s spot OTC flow in the first half of 2026. It does not prove that institutions accounted for 72% of all crypto trading. The figure is proprietary to one firm and one segment of the market.

The evidence supports the conclusion that the Senate has produced detailed CLARITY Act text and that negotiations were active in early August 2026. It does not establish that the bill will become law in its current form. Timing, amendments, ethics provisions and reconciliation with the House remain unresolved.

The evidence supports the conclusion that Visa sees stablecoins as strategically important. It does not prove that its platform will attract large production volume or that Open USD will challenge established tokens. The beta must convert interest into launched products and sustained transactions.

The evidence supports the conclusion that tokenized assets have reached tens of billions of dollars. It does not show that onchain markets have achieved the liquidity, interoperability or resilience of traditional securities infrastructure. Asset value is a useful indicator, not a complete measure of adoption.

What Happens Next

The immediate security question is whether investigators identify additional thefts, recover funds or establish clear attribution. Blockchain analytics can trace movements, but tracing does not guarantee recovery. Funds may be split, exchanged across networks or routed through services that complicate legal action. Users also face the practical task of determining whether their seeds were generated under affected firmware and moving assets safely.

Coinkite’s response will remain under scrutiny. Customers will evaluate the completeness and timing of disclosure, the quality of technical explanations, and any compensation or support offered. Hardware-wallet competitors will likely emphasize their own entropy designs, but they should be judged by evidence rather than marketing. Independent audits and transparent reproducible testing would be more useful than claims of absolute security.

For Congress, the key near-term events are procedural. Senators must resolve whether there are enough votes to advance the bill, what ethics restrictions are attached, and how bank-related stablecoin concerns are handled. Even Senate passage would not finish the process. Differences with House legislation would need to be reconciled before a final measure could reach the president.

Wintermute’s next flow reports will show whether the institutional share persists when market conditions change. A rebound in retail trading could reduce the percentage even if institutional volume continues rising. The more informative measure will be absolute flow, product breadth and whether institutions expand beyond Bitcoin, Ether and a narrow group of liquid tokens.

Visa’s year-end test is client conversion. Sandbox demand is not revenue or live volume. The company will need to show that banks have moved into production, that transactions occur reliably and that the platform offers an economic advantage over assembling other vendors. Open USD will need clearer reserve, custody and governance disclosure as circulation grows.

Tokenized deposits will be judged by interoperability. A Wells Fargo token that works only within a small proprietary environment can still improve internal client service, but the larger promise depends on movement across banks, currencies and platforms. The Clearing House initiative may provide common infrastructure, although shared bank control could limit openness.

CME’s compute futures will face a classic market-launch problem: users need liquidity before they are willing to participate, but liquidity requires users. Contract specifications, benchmark credibility and market-maker support will determine whether the product becomes a genuine hedging tool or a thinly traded experiment.

Risks Readers Should Keep in View

Custody and Key-Generation Risk

Hardware wallets reduce exposure to online theft but cannot protect against defective randomness, malicious firmware, insecure backups or user error. A secure plan requires understanding how the seed was created, keeping independent backups, verifying addresses on the device and testing recovery procedures. Large balances may warrant multisignature arrangements that avoid one device or seed becoming the sole point of failure.

Regulatory and Political Risk

Legislation can change quickly during negotiation, and a bill’s title does not guarantee a specific outcome. Market participants should distinguish committee text from enacted law. Ethical disputes and bank lobbying can alter provisions that affect custody, stablecoins, decentralized finance and regulatory jurisdiction.

Issuer and Reserve Risk

A stablecoin is only as dependable as its legal claim, reserves, redemption process and operational controls. Market capitalization does not prove solvency. Attestations provide useful information but are not always equivalent to a full financial-statement audit. New tokens deserve particular scrutiny because they have not been tested through prolonged stress.

Technology and Smart-Contract Risk

Tokenized assets can inherit vulnerabilities from blockchains, bridges, wallets and administrative keys. Permissioned controls can reduce some risks while creating privileged accounts that become attractive targets. Institutions need contingency plans for chain outages, forks and contract upgrades.

Liquidity and Valuation Risk

A token may represent a high-quality underlying asset and still trade at a discount if redemption is slow or buyers disappear. Futures tied to compute can also diverge from a company’s actual costs because hardware, location and service terms differ from the benchmark.

Execution and Capital Risk

Bitcoin miners converting sites for AI may face construction overruns, financing needs and customer concentration. Banks and payment firms can spend heavily on platforms that clients use only experimentally. Institutional interest should not be confused with profitable adoption.

Frequently Asked Questions

What was the Coldcard hack?

The incident involved attackers exploiting weak seed generation associated with certain Coldcard hardware-wallet firmware versions. The devices did not need to be online at the moment of theft. If an attacker could reconstruct a wallet’s private keys from insufficient randomness, the attacker could sign valid transactions remotely.

How much bitcoin was stolen?

Public estimates changed as investigators identified more addresses. By August 4, 2026, Galaxy Research and Elliptic estimated losses of roughly $130 million. That figure should be treated as provisional because attribution, duplicate counting and later fund movements can change the total.

Were all Coldcard wallets affected?

No. Coinkite identified specific affected firmware ranges and device families. The company said updated firmware corrected the random-number generation problem, but an update does not repair a seed created earlier under vulnerable conditions. Users must check the official advisory for their model and version.

Does a firmware update make an old seed safe?

No. The seed determines the private keys. If it was generated with inadequate entropy, updating the device does not change it. Coinkite advised affected users to generate a new seed under corrected conditions and move funds to addresses derived from that seed.

Are cold wallets still safer than exchanges?

They protect against many exchange and online-account risks, but they shift responsibility to the owner and device supply chain. Safety depends on firmware, seed generation, backups, physical security and operating practices. For some users, regulated custody or an exchange-traded product may reduce operational risk, while introducing intermediary and market risks.

What does Wintermute’s 72% figure mean?

It means institutional clients represented 72% of Wintermute’s spot over-the-counter flow in the first half of 2026. It is evidence about that firm’s desk, not a measure of the entire global crypto market.

What is the CLARITY Act?

It is proposed U.S. digital-asset market-structure legislation intended to define regulatory jurisdiction, establish registration pathways and add customer-protection and disclosure rules. Senate negotiations were still unresolved at the article’s August 5, 2026 research cutoff.

Why is the CLARITY Act stalled?

The obstacles include disputes over ethics restrictions, the treatment of political officials’ crypto interests, bank concerns about stablecoin rewards and the challenge of assembling enough bipartisan support. Procedural timing before the August recess added pressure.

What is Visa’s stablecoin platform?

Visa Stablecoin Platform is a beta infrastructure and services offering designed to help banks and fintechs mint, burn, hold, redeem and transfer stablecoins while applying institutional controls. Visa introduced it in July 2026 with Open USD as the initial token.

Why would a stablecoin use Visa?

A stablecoin can move without Visa, but Visa can connect it to merchant acceptance, banks, compliance systems, foreign exchange and card programs. The commercial question is whether that integration lowers costs or merely adds another intermediary.

How are tokenized deposits different from stablecoins?

A tokenized deposit is generally a digital claim on a particular bank, while a stablecoin is a claim on an issuer or reserve structure. Deposits may integrate more easily with banking controls; stablecoins may move more freely across networks. The exact legal rights depend on the product.

What are compute futures?

They are proposed derivatives tied to benchmark prices for renting high-performance computing capacity. AI developers could use them to hedge rising costs, while cloud providers or data-center operators could hedge falling rental rates. CME’s planned contracts were still subject to regulatory review.

Why are bitcoin miners moving into AI infrastructure?

Miners often control valuable power connections, land and cooling infrastructure. AI customers can offer longer contracts and more predictable revenue than bitcoin mining, although conversions require capital and the facilities are not fully interchangeable.

Has tokenization reached mainstream scale?

Not yet. Tokenized real-world assets have reached tens of billions of dollars and several institutional pilots are moving toward production. That is meaningful progress, but still small relative to global deposits, bonds and investment funds. Interoperability, liquidity and operational resilience remain constraints.

Final Assessment

The most important lesson from this cluster of developments is that institutional adoption does not eliminate crypto’s original risks; it reorganizes them. A user who leaves bitcoin on an exchange accepts intermediary risk. A user who moves it to a hardware wallet accepts key-generation and operational risk. A bank that issues a tokenized deposit reduces some reserve uncertainty but creates a closed-network dependency. A business that uses a stablecoin gains around-the-clock transferability but must assess the issuer, chain and redemption process.

The Coldcard incident provides the clearest warning because the losses were immediate and personal. An unplugged device created a sense of safety while vulnerable randomness undermined the keys at creation. The correct response is not to declare self-custody impossible. It is to reject security claims that stop at the word “offline.” Entropy, firmware, backups, signing policy and recovery all matter.

Wintermute’s data and the activity of Visa, major banks and CME show that institutions are not retreating from digital assets. They are selecting narrower products, demanding controls and integrating blockchain functions into existing financial structures. That can make the market more durable. It can also concentrate influence among the firms best able to satisfy regulation and absorb compliance costs.

The CLARITY Act is the political test of that transition. Its customer-protection provisions could reduce ambiguity and strengthen segregation, disclosure and oversight. Its legitimacy depends on whether Congress can address ethics and conflicts without turning market structure into a vehicle for protecting politically connected interests. Passage is not simply a technical question about jurisdiction; it is a trust question.

Visa’s stablecoin platform and the growth of tokenized deposits are the commercial test. The technology already works at pilot scale. The unresolved issue is whether it improves economics, interoperability and resilience at production scale. The same standard applies to tokenized securities and compute futures: announcements matter less than sustained volume, transparent rules and performance during stress.

Crypto’s next phase is therefore unlikely to look like the complete displacement of banks, exchanges or payment networks. It is more likely to be a negotiated integration in which blockchains handle selected parts of issuance, ownership and settlement while traditional institutions retain customer relationships, legal accountability and risk controls. The opportunity is real, but so is the danger of mistaking institutional branding for institutional-grade infrastructure.

This article is provided for general informational purposes and does not constitute financial, investment, tax, or legal advice.

Sources

Affiliate disclosure: Businessfinance.news may earn compensation from qualifying actions completed through selected links on this website, at no additional cost to the reader. Affiliate relationships do not influence our editorial reporting, analysis, or conclusions.

author avatar
Business Finance News
Date: August 5, 2026