Home Blog Page 63

Did the U.S. Sell Bitcoin Despite Trump’s Strategic Reserve Order? What the Samourai Case Really Shows

TL;DR

  • Reports alleging a US Bitcoin sale tied to the Samourai Wallet case have triggered questions about whether federal agencies are acting in line with Trump’s Strategic Bitcoin Reserve order.
  • On-chain data confirms the Bitcoin was moved into Coinbase Prime custody, but does not prove that a sale actually occurred.
  • Whether the transfer violated the executive order depends on how the Bitcoin was legally classified at the time and remains unresolved.

Reports that U.S. authorities may have disposed of a small amount of Bitcoin have sparked controversy. Are federal agencies acting in line with the administration’s emerging crypto policy? The focus of the dispute is a reported sale of Bitcoin involving assets tied to the Samourai Wallet case and whether that action conflicts with President Donald Trump’s strategic reserve directive.

The issue gained political traction after Sen. Cynthia Lummis publicly joined in the criticism. Lummis argued that liquidating Bitcoin undercuts the credibility of treating it as a long-term strategic asset and risks sending mixed signals to markets.

What is confirmed on-chain

Blockchain records indicate that approximately 57.5 BTC, valued at around $6–$ 6.3 million at the time, were transferred into Coinbase Prime custody. The assets were linked to enforcement actions involving Bitcoin seized from the Samourai Wallet. That movement is verifiable on-chain and is not in dispute.

The data does not show whether the Bitcoin was ultimately sold. On-chain data can confirm transfers between wallets and custodians. What it cannot reveal is whether assets were liquidated, internally reallocated, or simply parked under institutional control. A move into Coinbase Prime is often associated with execution services. However, it is not, by itself, proof of a completed sale.

What is being alleged

Several reports have alleged the transfer was a sale, suggesting the DOJ liquidated the Bitcoin as part of routine forfeiture procedures. Other coverage has been more cautious, emphasizing that custody movements alone cannot confirm a sale without additional evidence.

The absence of an official statement confirming or denying liquidation has allowed both interpretations to circulate. As a result, the debate has been driven as much by inference as by verifiable documentation.

Trump’s strategic reserve order and the policy gap

The controversy intersects with President Donald Trump’s push to establish a Strategic Bitcoin Reserve. Under Trump’s Executive Order 14233, the administration signaled its intention to treat Bitcoin as a strategic asset rather than routinely sell it.

What remains unclear is how that directive applies to Bitcoin obtained through law enforcement actions. The order outlines the strategic intent but does not publicly specify how seized or forfeited assets should be classified, managed, or exempted from existing disposal procedures.

How Bitcoin forfeiture usually works

Historically, the Justice Department and U.S. Marshals Service have followed established processes when handling seized or forfeited Bitcoin. These assets were typically auctioned or liquidated, with proceeds directed according to statutory rules.

Those procedures predate any attempt to frame Bitcoin as a strategic reserve asset. As a result, agencies may still be operating under legacy enforcement frameworks that have not yet been updated to reflect new policy priorities. This creates a gray area where routine practice and political signaling may not fully align.

Timeline inconsistencies and reporting gaps

Adding to the uncertainty are discrepancies across reports regarding when the alleged sale occurred. Some outlets cite specific dates, while others refer only to general timeframes or focus exclusively on custody transfers.

These inconsistencies make it difficult to reconstruct a definitive sequence of events and weaken claims that a clear violation has already taken place. Without consistent timelines or transaction confirmation, assertions of noncompliance remain provisional.

Did this violate the executive order?

At this stage, three key questions remain unresolved:

  1. Was the Bitcoin actually sold, or merely transferred into institutional custody?
  2. Was the Samourai-linked Bitcoin classified as reserve-eligible under Executive Order 14233?
  3. Which agency has final authority to determine how such assets are handled?

Until these points are clarified, it is not possible to state conclusively whether any potential sale of Bitcoin by US enforcement agencies occurred in violation of the order or within existing enforcement authority.

Why this matters

Beyond the immediate dispute, the episode highlights the challenge of translating high-level policy directives into operational rules. If Bitcoin is to be treated as a strategic asset, agencies will need clear guidance on how to handle coins obtained through seizures and forfeitures.

For now, the question of whether the US sold Bitcoin remains open. What is clear is that transparency will determine how credible the strategic reserve narrative becomes. Confirmation from federal authorities about the status of the Samourai-linked Bitcoin would quickly settle the factual debate. Until then, the case stands as an early stress test for the United States’ evolving approach to Bitcoin policy.

Ledger Data Breach Linked to Third-Party Global-e Incident

TL;DR

  • Ledger confirmed a data breach linked to a security incident at third-party e-commerce provider Global-e.
  • Customer contact and order-related data may have been exposed. Ledger says no payment details, private keys, or recovery phrases were compromised.
  • The main risk for affected users is phishing and social engineering, as exposed contact data can be used to craft targeted scam messages.

Ledger has confirmed a data breach after a security incident at one of its third-party service providers, Global-e, exposed some customer information. The company said the incident did not affect its hardware wallets, private keys, or recovery phrases. However, it warned customers to remain alert for phishing attempts following the disclosure.

According to Ledger, the incident originated from unauthorized access within the infrastructure of Global-e, a commerce and checkout provider for Ledger’s online store. Ledger said it was notified after Global-e identified unusual activity and launched an internal investigation.

Third-party breach, not a wallet compromise

Ledger emphasized that this third-party breach involved only systems operated by Global-e. It did not extend to Ledger’s own wallet software or hardware products. The company said Global-e handles certain order-processing and e-commerce functions but has no access to wallet credentials or cryptographic secrets.

The issue became widely known after customers began sharing breach notifications online, prompting blockchain investigator ZachXBT to flag the incident publicly. Ledger later confirmed the reports and reiterated that the breach stemmed from a third-party environment rather than its self-custody infrastructure.

What data may have been exposed

Ledger said the Global-e data breach may have exposed customer contact and order-related information linked to purchases made through its online store. The company did not publish a definitive list of affected fields, but confirmed that it involved some customers’ personal data.

Based on notifications shared by users, the exposed details may include names, email addresses, phone numbers, shipping addresses, and order information. Ledger stated that the incident did not compromise payment card details.

The company has not disclosed how many customers were affected. Investigations into the scope of the exposure remain ongoing. As a result, Ledger customer data exposed through the incident may vary depending on individual order histories and regions.

What was not affected

Ledger stressed that the Ledger data breach did not compromise wallet security in any form. The company said that recovery phrases, private keys, wallet balances, and transaction capabilities remain fully secure.

Ledger also reiterated that Global-e does not store or process sensitive wallet-related information. As a result, the incident does not provide attackers with direct access to users’ crypto assets.

The company sought to clearly distinguish the event from a wallet hack. The breach involved only customer information handled within an external e-commerce system.

Phishing and social engineering risk

While no wallets were compromised, Ledger warned that the exposed data could increase Ledger phishing risk for affected users. Scammers can use contact and order information to craft convincing scam messages that impersonate customer support or reference real purchases, particularly when Ledger customer data exposed includes verified order details.

Ledger advised customers to remain cautious of unsolicited emails, messages, or calls claiming to be from Ledger. The company reiterated that it will never ask users to share recovery phrases or private keys. It urged customers to verify communications through official channels only.

Broader implications of vendor exposure

The incident highlights a broader issue facing the industry: even when core wallet technology remains secure, surrounding commercial infrastructure can introduce vulnerabilities. While this was not a hardware wallet data breach, it still illustrates how customer-facing systems such as payments, fulfillment, and support may present different risk profiles than protocol-level security.

From a structural perspective, the Ledger third-party breach reflects the growing complexity of crypto companies that operate hybrid models combining self-custody products with centralized retail and logistics stacks. In such setups, third-party vendor risk can emerge outside the core security perimeter users typically associate with hardware wallets.

Reputational impact and open questions

Although Ledger maintains that the data breach did not affect its products, repeated third-party incidents continue to raise questions about operational dependencies and oversight. The company said it is working with Global-e to assess the incident and monitor for any further developments.

Several questions remain unanswered. That includes the precise timeline of the unauthorized access, the total number of impacted customers, and whether it may require additional disclosures. Ledger said it will provide updates if new information becomes available.

For now, the company’s message remains consistent: the Ledger data breach did not compromise wallets or funds. Customers should stay vigilant, as exposed contact information can still be exploited through social engineering attacks.

Coinbase to pause peso-based services in Argentina from Jan. 31, keeping crypto trading live

TL;DR

  • Coinbase will pause peso-denominated services in Argentina from January 31, 2026, ending peso-to-USDC conversions and local bank withdrawals.
  • The move is framed as a temporary, operational pause, not a market exit, with Coinbase saying it plans to return with a revised local offering.

Coinbase will pause local peso-based services in Argentina starting January 31, 2026. The company will suspend features that let users convert Argentine pesos into USDC and withdraw funds to local bank accounts. The exchange says that the change follows a review of its local operations and is a temporary step back rather than a full exit.

What is changing for users

Past the end-of-January cutoff, Coinbase users in Argentina will no longer be able to use Argentine pesos (ARS) to buy or sell USDC. They will also lose the ability to withdraw funds through local bank rails. Coinbase communicated a transition window for customers to complete peso-based activity before the pause takes effect.

Coinbase emphasized that the change is focused on local fiat functionality. Core crypto features, such as holding assets and sending or receiving cryptocurrencies, will remain available even after the peso rails are switched off.

Coinbase calls it a “deliberate pause”

Coinbase framed the move as a “step back” to strengthen its approach and return with a more sustainable product in the market. The company also reiterated that Argentina remains strategically important for crypto innovation, even as it pauses local services tied to ARS rails.

That positioning matters because “Coinbase suspending Argentina peso services” reads like a retreat on the surface. However, the company is trying to draw a line between operating in-country and maintaining banking integrations that can be costly or fragile.

Why peso rails are the critical feature

For everyday users, the biggest difference between “crypto access” and “crypto utility” is often the on-ramp. In Argentina, demand for dollar-pegged stablecoins has been a recurring theme in coverage of local adoption. Stablecoins offer a straightforward hedge against inflation for users wanting dollar exposure in digital form.

That’s why the Coinbase peso-to-USDC pathway was operationally important. It connected local currency to a widely used stablecoin in one flow. Removing that link doesn’t kill crypto usage, of course. However, it adds friction, especially for users who relied on Coinbase as the simplest way to reach USDC from pesos.

What users can do before Jan. 31

Coinbase has signaled that users have a limited window to complete peso-based actions ahead of the cutoff date. Practically, that means customers who still need to move money off-platform via local rails should do it before the pause begins.

For users asking “when does Coinbase stop peso-to-USDC in Argentina,” the date to plan around is January 31, 2026.

What to watch next

The immediate question is whether Coinbase will provide a concrete timeline for restoring local rails. At least for now, Coinbase has not committed to a specific return date, even while saying it intends to come back with an improved customer experience.

The second watch item is whether the company maintains other footprints in the region while local fiat rails are paused. Coinbase has presented Latin America as a key region for its broader mission. That positioning suggests this is more about product structure than a strategic abandonment of the market.

Cardano Wallet Phishing Campaign Targets Users With Fake Eternl Desktop Installer

TL;DR

  • Cardano users are being targeted by a phishing campaign that impersonates a fake “Eternl Desktop” wallet installer distributed via unsolicited emails.
  • The installer uses legitimate remote access software, allowing attackers to gain persistent control of compromised devices rather than stealing credentials immediately.
  • Users should only download wallet software from official project channels and treat any email-based wallet update requests as hostile by default.

Cardano users are being targeted in an active wallet phishing campaign that impersonates a desktop version of the popular Eternl wallet. Security researchers warn that the attack uses professionally written emails and a convincing software installer. The goal is to trick users into compromising their own devices and exposing sensitive data.

Unlike earlier scams that relied on obvious malware or fake browser extensions, this campaign presents itself as a legitimate software update. That approach makes the threat harder to identify before damage is done.

How the Fake Eternl Desktop Campaign Works

The phishing operation begins with unsolicited emails claiming that a new “Eternl Desktop” application is available for download. The messages reference familiar Cardano ecosystem features, like the governance participation and staking tools.

Victims are then directed to a look-alike domain that closely mimics official branding. From there, it prompts users to download what appears to be a standard desktop installer. In reality, the file has no connection to the legitimate Eternl project.

This form of Eternl wallet phishing avoids requesting seed phrases or private keys directly. Instead, it relies on users voluntarily installing software as they assume the software to be an official wallet release.

Why This Attack Is Harder to Detect

What makes this Cardano wallet phishing campaign particularly dangerous is its use of legitimate remote access software. The installer does not rely on custom-built malware. It reportedly deploys a widely used enterprise remote management tool.

Once installed, the tool grants attackers persistent access to the victim’s device. Traditional antivirus and endpoint security tools may not immediately flag the activity because the software itself is not inherently malicious.

This technique allows attackers to monitor user behavior and access files. They can also wait for wallet activity before attempting to steal funds. The approach represents a shift toward device-level wallet compromise.

Potential Impact on Affected Users

Once they compromise a device, attackers can observe wallet interactions over time. They may intercept transactions or harvest credentials gradually. The campaign targets Cardano users specifically, but the risk extends beyond a single blockchain.

Any crypto wallets, browser sessions, or saved credentials on the same machine may be exposed. This broader risk profile makes the campaign more damaging than a typical phishing email. One-time losses are no longer the only concern.

Security researchers note that similar techniques have been used in other Cardano phishing attack cases. In those incidents, social engineering replaced technical exploits as the primary entry point.

Security Warnings and Research Findings

Multiple cybersecurity outlets have confirmed that the fake installer is not affiliated with any official Eternl release. There is currently no verified “Eternl Desktop” application matching the claims made in the phishing emails.

Researchers emphasize that legitimate wallet teams rarely distribute software through direct email campaigns. They also avoid third-party download links. In this case, the absence of public announcements is a key warning sign.

Signed releases and repository updates are also missing. Together, these factors strongly indicate a phishing operation. The campaign is still considered active.

How Users Can Protect Themselves Right Now

Users should avoid downloading wallet software from unsolicited emails. They should also avoid unknown or unfamiliar websites. Install wallet updates only from official project domains.

Additional precautions include verifying domain names before downloading software. Users should ignore urgent update requests delivered via email. Verify official announcements through trusted social channels.

Review installed applications regularly. Unknown remote access tools may indicate compromise. These steps remain the most effective defense against crypto wallet phishing.

Broader Context: Phishing as a Growing Crypto Threat

This incident reflects a broader trend across the crypto sector. Attackers increasingly favor social engineering over direct protocol attacks. Trusted software abuse has become a common tactic.

Recent reports of wallet drains across other ecosystems point to the same pattern. Phishing campaigns are becoming more targeted. They are also more patient.

By focusing on user-level compromise, attackers reduce detection risk. They also retain the ability to extract value over time.

This Cardano wallet phishing campaign highlights how subtle modern crypto scams have become. There was no protocol breach. There was also no obvious malware.

The attack relies entirely on user behavior and misplaced trust. Security awareness remains the first and most important line of defense. Any wallet update that bypasses official channels should be treated as hostile by default.

Pi Network Suspends Payment Requests After Scam Drains Millions in PI

PI network mainnet launch overshadowed by price volatility

Pi Network has temporarily disabled Pi Network payment requests after scammers used deceptive wallet requests to trick users into approving transfers, draining millions of PI tokens. The company said the pause is a precautionary measure while it reviews the incident.

How Payment Requests Were Abused

The payment request tool lets users request PI transfers from other accounts. According to reports, the attackers sent requests designed to look legitimate, leading some users to approve transfers to wallets controlled by the scammers.

Because the users approved these transactions, the network processed them as valid transfers. Hence, they are difficult to reverse. Several outlets described the incident as a coordinated payment request scam, rather than a technical exploit of the PI Network protocol.

Scale of the Losses

Estimates of the total losses vary across reports. Some sources cited roughly four million PI tokens drained through the scam, while others reported figures closer to 44 million tokens. The discrepancy reflects differing methodologies and the evolving nature of the investigation.

What remains consistent is that a significant volume of PI tokens was drained during the incident. This is one of the larger reported losses tied to user-initiated wallet interactions within the Pi ecosystem.

What Was Shut Down and What Wasn’t

Pi Network disabled Pi Network payment requests specifically, while leaving other wallet functions and the underlying blockchain operational. There has been no indication that private keys were compromised or that core network infrastructure was affected.

Official Response and User Guidance

In statements shared through official channels, Pi Network stated that it has suspended the function to limit further exposure while the incident is being assessed. They advised users to remain cautious when approving transactions and to rely only on verified communications from the project.

The company has not provided a timeline for when it plans to restore Pi Network payment requests. Additional safeguards may certainly be introduced before the feature is re-enabled.

Broader Context

The incident follows a wider pattern of scams targeting user-approval mechanisms across the crypto industry. As wallet interfaces emphasize convenience, features such as payment requests and approval prompts have increasingly become points of exploitation.

Similar tactics have been observed in other cases involving crypto payment request scams. Losses result from manipulated user actions rather than direct breaches of blockchain systems.

What Comes Next

Pi Network said it continues to monitor activity and investigate the scope of the scam. For now, the payment request feature remains disabled, with no confirmed timeline for reinstatement.

- Advertisement -

FEATURED