Home Blog Page 14

Tether Lost $4B in Reserve Cushion While Still Profitable

TL;DR

  • Tether’s reserve buffer fell from $8.23 billion to $4.11 billion in Q2 2026 despite reporting $1.5 billion in operating profit.
  • Most of the decline came from falling gold and Bitcoin prices and a $2.38 billion reduction in secured loans.
  • USDT remained fully backed, but the smaller buffer raises questions about how excess reserves are managed.

Tether, the company behind USDT, the world’s largest stablecoin, said its reserves exceeded its liabilities by $4.11 billion as of June 30, 2026. Three months earlier, Tether’s reserve buffer stood at $8.23 billion. The company earned about $1.5 billion in operating profit over the same quarter, as attested by the accounting firm BDO.

A stablecoin like USDT is supposed to trade at $1 because it is backed by reserves, cash, government bonds, gold, and other assets worth at least as much as the tokens in circulation. On that count Tether’s $187.75 billion in total assets still comfortably clears its $183.64 billion in liabilities, most of which is simply the value of USDT tokens people hold. What shrank is the cushion above that baseline. Those excess reserves would absorb losses if reserve assets fell in value or a large number of holders tried to redeem USDT at once. So, the size of that padding is what determines how much stress the system can take before the peg itself comes under pressure.

While Tether’s press release did not explain what drove the buffer down from $8.23 billion, lining up this quarter’s reserve report against last quarter’s fills in most of the gap.

Where the $4 billion went

CategoryQ1 (Mar 31)Q2 (Jun 30)Change
U.S. Treasury bills$117.04B$114.96B-$2.08B
Reverse repos$24.08B$25.62B+$1.54B
Gold$19.84B (132.2 tons)$18.84B (146.2 tons)-$1.00B
Bitcoin$6.62B (~97,137 BTC)$5.80B (98,933 BTC)-$0.82B
Secured loans$15.83B$13.45B-$2.38B
Total assets$191.77B$187.75B-$4.02B

The Treasury and repo book, the core of the reserve, barely moved on net. Two things account for nearly all the rest.

Gold and Bitcoin lost value on paper even as Tether bought more of both. The company added 14 tons of gold and about 1,796 Bitcoin during the quarter, but gold fell around 15% and Bitcoin dropped from roughly $68,200 to $58,600. Buying into a falling market meant the new purchases only partly offset the markdown on everything already held, leaving a combined $1.82 billion paper loss on assets Tether still owns in full.

Secured loans dropped by $2.38 billion, exactly the reduction Tether disclosed. This is the one line where money actually left the reserve, not just lost value on paper. Add the $1.82 billion in mark-to-market losses to the $2.38 billion loan reduction and the total, $4.2 billion, comes close to accounting for the entire $4.02 billion decline in Tether’s reserve buffer. The residual difference likely sits in smaller categories, public equities and other investments. Tether’s Q2 release does not break out those individually.

Source: newhedge.io

The murkiest line item

Secured loans are the part of Tether’s reserve that draws the most scrutiny, because nothing else in the report works this way. Tether values gold, Bitcoin, and public equities at current market prices every quarter. Movements in that section reflect the market. Secured loans are measured differently, at the loan’s face value under standard accounting rules. They are adjusted only if Tether books a credit loss. That means this quarter’s $2.38 billion decline is not Tether marking down the loans because borrowers’ collateral lost value. It reflects an actual change in principal outstanding, loans being repaid, called in, or not renewed.

Who borrows

Tether has never disclosed who receives these loans. Borrowers post collateral, historically crypto assets like Bitcoin, worth more than what they owe. Tether can seize that collateral if a loan isn’t repaid or the coverage ratio slips. Outside reporting has linked some past borrowers to now-defunct firms including Celsius Network and Three Arrows Capital, based on blockchain analysis, not anything Tether confirmed. In 2022 Tether pledged to wind this category down to zero by the end of 2023. It never happened; the balance dipped, grew again, and has sat in the multiple billions ever since.

There is a plausible link between this quarter’s loan reduction and the same price declines that hit gold and Bitcoin. If a borrower posted crypto as collateral and its value fell, Tether could have issued a margin call requiring the borrower to repay part of the loan to keep the required coverage intact. That would show up exactly as a drop in the secured loans balance, just triggered by the borrower’s collateral, not a markdown on Tether’s own books. Nothing in the disclosure distinguishes that scenario from Tether simply choosing to lend less this quarter, and the company has never said which it was.

An attestation, not an audit

BDO’s report is an attestation, a check of Tether’s figures against a defined set of criteria on a single date. A full audit digs into a company’s complete financial records and internal controls over an extended stretch of time, not one snapshot. Tether has said a “Big Four” audit is underway but has not said when it will conclude.

That audit is the only mechanism that could settle whether this quarter’s $2.38 billion loan reduction was Tether pulling back from risk or Tether forcing borrowers to repay as their collateral lost value. Tether has not said which it was, and until the audit finishes, no one outside the company can check.

Bitcoin Theft Linked to Coldcard Devices Reaches Fourth Wave

TL;DR

  • A fourth wave tied to Coldcard devices pushed Bitcoin losses higher as the theft expanded across more than 5,200 addresses.
  • Researchers identified the activity in real time via mempool transactions and Replace-by-Fee signals.
  • The attacker’s behavior is evolving, with reduced clustering and early second-hop fund movement.

A fourth wave of Bitcoin theft from Coldcard wallets is underway. And, for the first time in this incident, researchers spotted it while transactions were still sitting unconfirmed in the mempool.

Galaxy Research’s Alex Thorn flagged the activity Monday. He warned that a pattern matching the first three waves was moving through blocks in real time. Early estimates showed hundreds of Bitcoin already moving across hundreds of addresses. The counts were revised multiple times as the sweep progressed. The confirmed portion later settled near 448.7 BTC from 709 suspected victim addresses after removing roughly 89 multisig addresses that did not match earlier patterns. The sweep ran at about 13.8 transactions per block, far above the baseline rate Galaxy measured before the incident began.

Some of the flagged transactions carried Replace-by-Fee signaling. This feature allows a pending transaction to be replaced with a higher-fee version. The transactions had not yet confirmed when Thorn posted, but a subset of affected users had a brief window to broadcast a competing transaction and move their funds before the attacker’s transaction confirmed. It is the first point in the four-wave incident where researchers surfaced a theft while in progress and not just after the fact.

The combined figure now approaches 1,816 BTC swept from more than 5,200 addresses. The estimates build from on-chain clustering based on address activity. It is not a confirmed victim count or a final loss figure.

https://twitter.com/intangiblecoins/status/2084079706320646300

Three earlier waves set the pattern

According to Coinkite, the Canadian company behind Coldcard, the vulnerability traces to a March 2021 firmware error. It routed wallet seed generation through a predictable software random-number generator instead of the device’s hardware generator. A wallet seed produces the private keys controlling its addresses. A predictable seed leaves a far smaller set of possible keys for an attacker to test offline.

The first theft wave hit on July 30, draining about 1,083 BTC from 1,196 Coldcard addresses in a 41-minute window, close to a full Bitcoin per address. A second wave followed roughly 27 hours later. It added about 76 BTC and brought the running total to 1,158.66 BTC from 2,673 addresses. Galaxy said the two waves shared enough transaction characteristics, common collector addresses, matching output types, and similar timing, to suggest a single operator. However, the company stopped short of calling that confirmed.

A third wave, identified Saturday, added 207.7 BTC from 1,912 addresses and lifted the total to 1,367.05 BTC across 4,585 addresses. It averaged just over a tenth of a Bitcoin per address. Well below the first wave’s average, this suggests the higher-value addresses in the vulnerable pool had already been cleared.

Each wave changed its footprint

The first two waves funneled stolen funds into a small number of shared collector addresses, a pattern that was relatively easy to trace. The third wave broke from that structure. It grouped an average of about six victim addresses per sweep transaction and held the proceeds in more complex script-based addresses, a departure from the earlier simpler format. It then sent each transaction’s proceeds to its own destination instead of a shared collector. Funds spread across roughly 293 separate addresses. The attacker also scanned only the default derivation path, the standard address branch most wallets use first. The two earlier waves had tested several paths.

Wave four extended that anti-clustering approach. Most of its 216 destination addresses were newly created with no prior transaction history. Galaxy also noted that some funds had already moved to second-hop addresses by the time it posted, so one further step was added compared to the earlier waves.

Galaxy is confident each wave is internally the work of one operator, but not that the same operator carried out all four. Waves one and two likely share an operator, based on matching structure and a 27-hour gap between them, though Galaxy stopped short of confirming it. Wave three broke that pattern enough that the company would not assume the same actor was behind it. Wave four looks different again. Thorn’s read is that the wave four topology suggests multiple actors now racing the same key space in parallel, not one operator simply scaling up.

Fixed firmware does not undo existing exposure

Coinkite has released corrected firmware for every affected Coldcard model and release track, including Mk3, Mk4, Mk5, and the Coldcard Q. The fix addresses future seed generation. It does not strengthen a seed that was already created on the affected software. The underlying private keys do not change when the firmware is updated.

Coinkite’s advisory tells affected owners to generate a new seed on corrected firmware and migrate their funds. It identifies a narrow exception for seeds created with at least 50 independent, private dice rolls entered through the device’s added-entropy feature. It also notes that a strong, unique BIP-39 passphrase adds an independent barrier. Even so, the company continues to recommend migration for passphrase users, since a weak or reused passphrase can still be guessed.

Coinkite has published a technical explanation of the root-cause bug but has not yet released the fuller formal technical review it said would follow its initial advisory. The company has not confirmed the roughly $88.6 million figure tied to the first three waves as a final loss total. Neither has it confirmed the wave four numbers Galaxy published.

https://twitter.com/COLDCARDwallet/status/2083155034762621425

What happens next

If any of the parked Bitcoin moves, it stops being a static number on a blockchain explorer and becomes something investigators can follow. Galaxy has already shared roughly 600 suspected attacker addresses with federal investigators, compliance firms, and cross-industry security researchers. Any exchange, mixer, or swap service can already check fund sources against those addresses. That may be exactly why the proceeds from the first three waves have sat untouched for days: moving them costs the attacker(s) the one advantage still working in their favor.

Wave four offers an early look at what that risk looks like in practice. Some of its funds already moved to second-hop addresses within hours of the sweep. It sits closer to needing an eventual exit than anything from the earlier waves. On-chain data alone cannot settle whether the attacker is preparing to cash out or simply adding another layer of obfuscation between the theft and future movements. Where those second-hop funds go next, toward an exchange or a swap service, or into further unlinked addresses, is likely to be the first real signal either way. It is not the only one to watch: Coinkite has yet to publish the fuller technical review it promised after its initial advisory, and the company has not confirmed Galaxy’s wave four figures on its own. Either would sharpen a picture that, for now, still rests on on-chain inference alone.

Strategy Turns to Bitcoin Sales to Support Preferred Dividends

TL;DR

  • Strategy sold about $218.4 million of Bitcoin in 2026 to help fund preferred-stock dividends.
  • The reported $8.22 billion quarterly loss was mostly an unrealized accounting markdown, not a cash loss or large-scale Bitcoin sale.
  • The company continues to grow its BTC holdings while using selective sales and a dollar reserve to manage rising dividend and financing obligations.

Strategy disclosed on July 30 that its Bitcoin sales during 2026 totaled about $218.4 million and helped fund preferred-stock dividends. The sales put a dent in a strategy built on the premise that Strategy would never sell.

The disclosure came alongside an $8.22 billion second-quarter net loss. Most of the loss was an unrealized markdown from a lower quarter-end Bitcoin price. It did not involve cash outflows or equivalent BTC sales.

Strategy is now using Bitcoin from its reserve to support a growing financing structure. The company still holds more than 843,000 BTC, but accumulation is no longer the only permitted use of its holdings.

The $8.22 billion loss was mostly unrealized

Strategy recorded an $8.32 billion unrealized loss on its Bitcoin during the quarter. Under fair-value accounting, the company updates the balance-sheet value of its holdings as Bitcoin’s market price changes. Gains or losses flow into reported earnings even when Strategy does not sell the coins.

Strategy earned $10.02 billion in the second quarter of 2025, when rising Bitcoin prices generated a large unrealized gain.

Strategy held approximately 843,775 BTC as of July 26. The company reported an original acquisition cost of $63.69 billion and a market value of $54.77 billion, using a July 27 price of $64,915.

Its average purchase price was about $75,476 per Bitcoin. The gap between cost and market value can change and does not represent a realized loss on the full reserve.

Source: CoinGecko

Bitcoin can now fund several obligations

Strategy’s board-authorized BTC Monetization Program allows the company to sell Bitcoin for several purposes. These include building its dollar reserve, paying preferred dividends and interest, and funding securities repurchases.

Strategy’s shift toward selling Bitcoin began earlier than the July 30 disclosure. The $218.4 million figure covers the year through July 26, not just the second quarter. On June 1, 2026, the company disclosed in an SEC filing that it had sold 32 BTC between May 26 and May 31 for about $2.5 million, its first Bitcoin sale since December 2022. The move drew renewed public scrutiny of Michael Saylor’s long-standing “never sell” position, including past remarks that holders should part with a kidney before their Bitcoin. Saylor addressed the criticism at the BTC Prague conference on June 11, 2026, describing the sale as routine treasury management tied to a defined financial obligation, not a reversal of Strategy’s Bitcoin thesis.

Preferred-stock dividends had a growing effect on the quarter’s results. Strategy reported $400.7 million of preferred dividends, up from $49.1 million one year earlier. Those payments increased the loss attributable to common shareholders above the company’s overall net loss.

Strategy has not abandoned its Bitcoin treasury: holdings grew 25% during 2026 through July 26. Selling Bitcoin gives the company another source of cash when dividends and interest come due.

A dollar reserve provides a cash buffer

Strategy said its dollar reserve had reached $3.75 billion by the results announcement. Management estimated that the reserve could cover more than 2.1 years of its existing preferred dividends and interest obligations.

That figure is larger than the company’s June 30 cash position of $1.71 billion in cash and cash equivalents plus $736.1 million in short-term investments, reflecting subsequent financing activity.

Strategy raised $17.06 billion through at-the-market securities offerings during 2026 through July 26. It also reduced its convertible debt from $8.21 billion to $6.71 billion by repurchasing notes at a discount.

Separately, the company authorized a $1 billion repurchase program for MSTR common shares. However, no common-stock repurchases had occurred by July 26. Strategy did spend about $25 million repurchasing STRC preferred shares below their stated value.

Future Bitcoin sales remain uncertain

Strategy has not provided a schedule or target for further Bitcoin sales. Bitcoin prices, financing conditions, and the size of future preferred-stock obligations will likely shape how much it sells and when.

Those obligations are growing. Further preferred-stock issuance would add to the recurring cost already driving the dividend increase. Raising capital through common shares avoids that cost but dilutes existing shareholders, so each financing option carries a different tradeoff for the company and for investors.

The dollar reserve is the clearest gauge of how much pressure that creates. Whether its current coverage window holds, shrinks, or grows in future disclosures will show how tightly Bitcoin sales stay tied to the cost of servicing Strategy’s preferred securities.

Scam Uses Fake IRS Letters and QR Codes to Target Crypto Wallets

TL;DR

  • Fake IRS crypto letters use QR codes to direct recipients to a fraudulent compliance portal that collects wallet and account details.
  • The site gathers information such as exchange, estimated holdings, and phone number, which may support later social engineering attempts.
  • IRS correspondence about crypto has become more common, making convincing fake notices harder to distinguish, while the scale and impact of this campaign remain unknown.

The IRS Criminal Investigation division warned on July 30 that fraudsters are mailing official-looking letters to cryptocurrency holders. The notices use a QR code to direct recipients to a fake “Digital Asset Compliance Portal.”

The fake IRS crypto letters mirror common phishing campaigns but use physical mail to add credibility. A convincing envelope and tax-notice format can make the request feel more legitimate than an unexpected email. The IRS says it is not an official portal and taxpayers do not need to register wallets or exchanges through it.

Coinbase Security and threat-intelligence firm DarkTower traced the mechanics of the campaign which gathers information that may support later social engineering attempts, like basic account details and phone numbers. The number of letters sent, and whether there are confirmed victims or losses, remains unknown.

The letter sends recipients to a look-alike site

The mailed notice copies elements of genuine government correspondence. These include Treasury and IRS references, a notice number and an urgent deadline. Its QR code points away from IRS.gov to a domain that resembles an official compliance service.

After a recipient scans the code, the site asks which exchange or wallet holds the person’s cryptocurrency. It lists both hardware wallets and major trading platforms. Next, it asks for an estimated account value which allows the operator to identify higher-value targets.

The site then signals a “platform approval” hand-off before requesting a phone number under a verification step. According to Coinbase and DarkTower, this prepares a possible follow-up call. The caller may pretend to represent the IRS, an exchange or a compliance service.

The potential phone call is where theft could occur

According to Coinbase and DarkTower, the phone-based step remains unconfirmed, as testing the flow caused the site to go dark after entering a number, leaving open whether a call follows or the number is stored for later use. If a call does occur, it would likely mirror common social engineering patterns. During such contact, a fraudster may seek an account password or a two-factor authentication code, or request a wallet recovery phrase, each of which can provide a route to an exchange account or self-custodied funds.

A caller may also instruct the recipient to transfer cryptocurrency to a “safe” wallet, which would send assets to an address controlled by the scammer. Even if the timing and trigger of any call remain unclear, these requests are key warning signs. A legitimate agency or exchange will not ask for credentials, recovery phrases, or transfers during an unsolicited call.

Coinbase said DarkTower traced the campaign domain to a Hong Kong registrar. Someone registered it shortly before the letters went out. The site used Romanian hosting infrastructure associated with other phishing pages. However, those technical locations do not establish the operators’ identities or nationality.

A paper notice can be real, but this portal is not

The IRS does send legitimate notices by mail, so a paper envelope alone is not proof of fraud.

Crypto tax reporting and disclosure requirements have expanded in recent years, making IRS correspondence about digital assets more common for many holders. This means that a convincing notice may appear routine at first glance and recipients may be less likely to scrutinize a letter from the IRS, which can increase the effectiveness of a well-crafted fake.

The decisive warning signs are the invented portal and the wallet-registration request. Before scanning any code or visiting the printed site or calling any number on the notice, recipients should check their official IRS online account or use contact details obtained directly from IRS.gov.

At this time, public sources have not explained how the senders obtained names and home addresses associated with crypto ownership. Neither Coinbase nor any other exchange or the IRS itself reported on a related database breach. 

Exposed information requires quick account checks

Anyone who entered information into the unverified compliance portal should treat it as compromised. Coinbase recommends changing the affected exchange password and checking the two-factor authentication method. Users should also contact the provider through its official app or website.

Never share a wallet recovery phrase with a caller or enter it into a tax-compliance site. If someone disclosed a phrase, the owner may need to move any remaining assets. They should use independently verified wallet guidance and act before a scammer can.

The IRS accepts reports about suspicious tax-related letters, websites and calls. In addition, victims can report fraud to the Federal Trade Commission. Exchange-specific incidents should go through the provider’s official support channel.

Zcash restricts old pool after flaw raised hidden supply risk

TL;DR

  • Zcash activated its Ironwood upgrade July 28 and closed the Orchard shielded pool to new value.
  • Orchard’s roughly 3.66 million ZEC was not stolen or confirmed as counterfeit and can still leave through a supply-accounting checkpoint.
  • Migration is voluntary, while wallet readiness, its completion date and any historical exploitation remain unresolved.

Zcash activated its Ironwood network upgrade on July 28, closing the older Orchard shielded pool, a part of the network that stores private transactions, to new funds. The network simultaneously opened a separately tracked private pool for future shielded transactions.

Orchard contained a critical flaw that could have allowed someone to create counterfeit ZEC without leaving an obvious public record. Developers fixed the immediate vulnerability in early June. However, that repair could not prove whether anyone had exploited the flaw during the previous four years.

Ironwood creates a clean starting point for shielded funds. Orchard users can still withdraw or migrate their ZEC, but the transfer will happen gradually through compatible wallets.

The vulnerability behind the upgrade

Zcash uses shielded pools to keep transaction details private while still checking that transactions follow network rules. The Orchard flaw affected the circuit responsible for that control process.

Researcher Taylor Hornby discovered the vulnerability on May 29 using Anthropic’s Claude Opus 4.8 as part of an AI-assisted security audit commissioned by Shielded Labs, shortly after the model’s public release. According to a Shielded Labs disclosure, developers deployed an emergency fix within days of the disclosure. Public analysis has not established that anyone created counterfeit ZEC.

A public checkpoint protects the migration

Still, Zcash’s private design means the blockchain cannot provide a complete historical answer. Therefore, the migration uses an accounting boundary described as a turnstile.

The network publicly recorded how much legitimate value entered Orchard. Its rules now prevent more value from leaving than that recorded amount. Any counterfeit ZEC that might exist beyond the verified balance could not cross the boundary.

This supply check is the main security purpose behind Zcash’s upgrade to Ironwood. It does not expose individual transactions or remove the privacy features of the new pool.

Orchard can release funds but cannot receive more

Zcash activated Ironwood at mainnet block 3,428,143. From that block onward, network rules prevent new value from entering Orchard. They also stop ordinary transfers between users from remaining inside the older pool.

Value already held in Orchard is fully available to owners. They can move it into Ironwood or withdraw it to another supported Zcash address. The new pool started with a separate transaction history and a zero balance.

CoinDesk reported that Orchard held about 3.66 million ZEC when Ironwood activated. That amount was worth roughly $1.7 billion at the reported market price. Around 1,500 ZEC had already moved into Ironwood by the publication cutoff. That leaves the bulk of Orchard’s 3.66 million ZEC still waiting to migrate.

Wallet support will shape the migration

Moving Orchard funds is voluntary and user-driven. In fact, not every ZEC holder needs to act immediately, since a lot of coins sit outside Orchard entirely.

However, Orchard users need wallet software that supports Ironwood and handles the migration safely. Wallet readiness matters because a poorly designed transfer can reveal more transaction information than the user intended.

The Zcash community has published several dashboards tracking how much value crosses into Ironwood. These tools can measure total movement between pools without identifying the people involved.

The final migration timeline remains unknown. Some funds may stay in Orchard for an extended period because their owners are inactive, waiting for wallet updates or choosing not to move.

Ironwood adds a future recovery feature

Ironwood also changes how the network records shielded notes. The new format is designed to support recovery if future quantum computers break the cryptography that protects today’s private balances.

This feature does not quantum-proof Zcash now, but it preserves information that could support a later recovery process after the network adopts new cryptography.

The new pool also has its own balance records, note tree and list of previously spent notes. So nodes can track Ironwood independently from Orchard while maintaining private transaction details.

Formal verification of the new circuit is still in progress, and wallet and exchange support will differ by provider. Migration speed now depends less on Zcash’s code than on how quickly individual wallets adopt it.

- Advertisement -

FEATURED