Home Blog Page 73

Off-Chain Manager, On-Chain Fallout: Stream Finance Probes $93 Million Loss After XUSD Depeg

Stream Finance $93M loss visual. Open digital vault with dissolving crypto symbols and blurred office in background, symbolizing off-chain risk in DeFi.

TL;DR

  • Stream Finance froze deposits and withdrawals after a $93M loss tied to an external fund manager.
  • Perkins Coie is leading a legal probe while the XUSD stablecoin trades below $1.
  • The case highlights how off-chain management can undermine DeFi transparency.

Stream Finance has become the latest DeFi platform to face scrutiny after reporting a $93 million loss linked to an external fund manager. The Stream team said the manager had overseen part of its treasury and disclosed the shortfall on November 4, 2025. In response, the protocol halted deposits and withdrawals, said pending deposits would not be processed, and began withdrawing liquid assets held elsewhere.

The company retained Perkins Coie LLP, naming partners Keith Miller and Joseph Cutler to lead a legal investigation into how the losses occurred and whether recovery is possible. Stream Finance said it is cooperating with legal counsel and prioritizing the protection of remaining assets, but has not provided further details on the investigation’s scope or timeline.

A Stablecoin Breaks Its Peg

The market reaction was immediate. XUSD, Stream’s native stablecoin, depegged sharply. Reports placed intraday lows between $0.30 and $0.53 before stabilizing around the $0.60–$0.70 range. On-chain data from DeFiLlama show Stream’s total value locked plunging from about $204 million to under $100 million within hours of the disclosure.

Trading venues scrambled to contain contagion. Liquidity pools linked to Stream saw redemptions spike. The depeg echoed the mechanics of previous algorithmic-stablecoin shocks. However, this time the trigger wasn’t code failure but off-chain fund management gone wrong.

When Off-Chain Managers Undermine On-Chain Assumptions

The loss at Stream Finance highlights a paradox at the heart of decentralized finance. Smart contracts promise transparency and automated control. Yet, many protocols entrust capital to external managers for yield generation or liquidity provisioning. These off-chain arrangements can outstrip the visibility offered by blockchain data.

If a manager takes leveraged positions, misreports PnL, or faces counter-party exposure, users see none of it until losses are crystallized. For protocols that market “audited smart contracts” and real-time dashboards, that blind spot can be existential.

Risk professionals note that traditional finance mitigates such risk through segregation of duties, daily reconciliations, and independent oversight. Those controls rarely exist in yield-seeking DeFi ventures.

What the Perkins Coie Investigation Will Probe

Hiring Perkins Coie, one of the most established U.S. crypto law firms, signals that legal accountability may extend beyond internal reviews. The investigation will trace fund flows and examine whether the external manager acted within mandate. It will also evaluate disclosure obligations to users. Potential outcomes range from civil recovery actions and clawback efforts to referrals for regulatory or criminal inquiry if misappropriation surfaces.

Stream’s statement that it is “withdrawing liquid assets” implies triage. The company may consolidate what remains in custody before counterparties or courts freeze balances. Such steps suggest the team anticipates a prolonged claims process, echoing the post-mortems that followed Celsius, Voyager, and BlockFi in previous cycles.

Contagion Watch: Collateral Across Lending Markets

Beyond direct losses, analysts are eyeing collateral exposures. Estimates shared by pseudonymous on-chain researchers suggest that as much as $280 million in loans across Euler, Morpho, and Silo may involve Stream-linked assets. These figures remain third-party estimates as the protocol didn’t confirm or deny any of them. Additionally, the possibility of impaired collateral has prompted lending markets to tighten collateral-factor parameters and add extra oracle checks.

If those loans are forcibly unwound or discounted, ripple effects could extend to unrelated liquidity pools. That risk is a reminder that composability cuts both ways.

Lessons for Protocols and Users

The $93 million loss at Stream Finance underscores how off-chain dependencies can negate on-chain transparency. For DeFi protocols that employ external fund managers, experts advocate several safeguards:

  • Independent risk committees and daily NAV attestations.
  • Hard limits on position size, leverage, and value-at-risk.
  • Real-time dashboards showing mandate-level data.
  • Periodic auditor access to brokerage and custody statements.

Users can also self-audit by reading whitepapers for terms like “external yield strategy” or “managed fund allocation.” If a protocol can’t explain how it redeems user assets when such partners default, the risk premium may outweigh the yield.

What Happens Next

Stream Finance has not published a timeline for unfreezing withdrawals. The protocol’s community forum and social feeds now serve as real-time triage boards where users share wallet screenshots and speculate on recovery ratios. Perkins Coie’s investigation will determine whether restitution is feasible or whether Stream joins the list of DeFi projects undone by governance blind spots.

For investors, the losses at Stream Finance have become a cautionary example of what can happen when decentralized systems rely too heavily on centralized fund-management structures.

Readers’ frequently asked questions

What happens to funds when a DeFi platform pauses withdrawals?

When a DeFi protocol halts withdrawals, user assets are typically frozen within its smart contracts or managed wallets. Funds aren’t necessarily lost, but users can’t move them until the protocol re-enables access or concludes an internal or legal review.

Why did the XUSD stablecoin lose its peg?

After Stream Finance reported its losses, investors rushed to redeem XUSD for safer assets. That sudden demand drained liquidity reserves and caused the price to drop below $1. That’s a common reaction when confidence in a stablecoin’s collateral weakens.

How can users check whether other DeFi projects use off-chain fund managers?

Most protocols describe their asset-management structure in whitepapers or audits. Users can look for terms like “external manager,” “off-chain yield strategy,” or “custodial partner.” If those terms appear, it’s a sign that part of the project’s funds are handled outside the blockchain which adds traditional financial risk to DeFi operations.

What Is In It For You? Action items you might want to consider

Track official updates from Stream Finance

Follow the project’s verified X (Twitter) account and official blog for announcements from Perkins Coie or the Stream team regarding the progress of the investigation and withdrawal status.

Monitor the XUSD stablecoin’s market recovery

Keep an eye on XUSD trading volumes and price stability on major DeFi dashboards such as DeFiLlama or CoinGecko to assess whether liquidity and confidence are returning.

Review exposure to protocols using external fund managers

If you use other DeFi platforms, check their documentation and audits to identify whether any assets are managed off-chain. Adjust allocations accordingly to reduce counterparty and governance risk.

Zerohash MiCA License Clears EU Regulatory Path as Mastercard Eyes $2 Billion Acquisition

Photo-realistic image of an open EU passport with digital circuit patterns and crypto symbols, reflecting Mastercard and MiCA’s EU-wide passporting framework.

TL;DR

  • Zerohash earns Dutch MiCA authorization, allowing crypto and stablecoin services across 30 EEA markets.
  • The license strengthens its role as a regulated infrastructure partner for banks and fintechs.
  • Talks with Mastercard continue, with reports valuing the potential deal at $1.5–$2 billion.

Zerohash has received a MiCA license from the Netherlands Authority for the Financial Markets (AFM). It is among the first firms authorized to operate as a Crypto-Asset Service Provider (CASP) in Europe. The approval grants an EU CASP passport, which allows Zerohash to offer regulated crypto and stablecoin services across all 30 EEA markets.

This authorization turns Zerohash into a compliance-ready stablecoin infrastructure provider. It also arrives as Mastercard is reportedly exploring a $1.5–$2 billion acquisition, signaling that regulated crypto infrastructure is becoming a valuable strategic asset.

What the MiCA License Enables

The MiCA authorization in the Netherlands allows Zerohash to provide custody, exchange, and settlement of crypto assets. It also permits the company to issue or support fiat-backed stablecoins within the EU.

An AFM crypto license lets the firm serve clients across borders without applying for separate permits in each country. Under MiCA’s “passporting” model, a single license unlocks access to the entire bloc. That is a major simplification for fintechs and institutions that want to integrate digital-asset functions.

For readers wondering what a MiCA license allows in the EU, it covers most activities related to trading, custody, and transfer of crypto assets. All providers must still meet strict capital and compliance standards.

Inside Zerohash — The Infrastructure Behind the License

Founded in Chicago in 2017, Zerohash builds API-based infrastructure for digital assets. It lets banks, brokers, and fintech apps offer crypto products without handling tokens directly. Its platform handles on-chain settlement, liquidity routing, and regulatory reporting through a single interface.

Clients include Interactive Brokers, Stripe, Franklin Templeton, and Worldpay. These firms use Zerohash’s embedded rails for crypto and stablecoin transactions. The company has raised roughly $104 million, reaching a valuation near $1 billion in its last round.

Its system relies on segregated custody, automated KYC/AML checks, and real-time risk controls. These features align well with the new MiCA stablecoin rules and help Zerohash scale as a licensed service provider.

Why It Matters for Banks and Fintechs

Working with a licensed infrastructure partner removes the need to build an internal compliance stack. Through Zerohash’s API, banks can launch on-chain payment options or tokenized deposit products while staying within MiCA rules.

This move toward embedded crypto for banks reflects broader trends in tokenization in EU finance. Corporate treasuries are testing blockchain-based settlements for FX and cross-border payouts. Fintech wallets want stablecoins for faster transfers. With its MiCA license and plug-and-play technology, Zerohash becomes part of the core plumbing of Europe’s regulated digital-asset market.

The Mastercard–Zerohash Deal Talks

Industry outlets reported that Mastercard and Zerohash are in advanced talks. The deal has not been finalized, and neither company has confirmed the negotiations. Most reports cite Fortune, which estimated the potential valuation at $1.5–$2 billion.

If completed, the acquisition would expand Mastercard’s blockchain strategy. It would build on earlier pilots with Paxos and other tokenized settlement projects. The addition of a MiCA-authorized partner would strengthen Mastercard’s reach in stablecoin acceptance and regulated crypto infrastructure.

For now, the talks remain unconfirmed and subject to change. Still, the reported valuation range highlights the growing importance of licensed infrastructure providers in Europe’s new regulatory era.

Market and Policy Implications

The Zerohash case shows how MiCA is reshaping Europe’s crypto sector. Firms with strong funding and legal compliance now have a clear path to scale. Smaller startups may face rising costs and may need to partner with licensed entities.

More companies are expected to register with the AFM as CASPs, seeking EU-wide access under MiCA’s licensing framework. The rollout of MiCA effectively opened a new regulatory chapter, allowing licensed firms to scale across borders under a unified European passport. These early movers are set to anchor the institutional layer of Europe’s crypto ecosystem.

Compared to the fragmented US approach under FinCEN and NYDFS, Europe’s single license could offer faster growth and more consistent oversight.

What to Watch Next

  • Updates from the AFM and ESMA as new MiCA standards take effect.
  • Any confirmation, update, or denial regarding the Mastercard–Zerohash talks.
  • Bank and payment-service pilots using MiCA-approved stablecoins for settlement.
  • Rising demand for licensed stablecoin services in Europe as institutions seek regulated partners.

By securing its Zerohash MiCA license, the company has positioned itself as an EU-wide crypto passport provider ready to bridge traditional finance and the regulated digital-asset economy.

Balancer Exploit Spreads Across Forks as Shared v2 Code Fuels $128 Million Drain

Metallic crypto dominos engraved with Balancer, Beets.fi, and Berachain logos toppling in a chain reaction, symbolizing the $128M Balancer hack 2025 and cascading DeFi exploit across shared smart-contract code.

The Balancer hack has become one of the largest Ethereum DeFi protocol breaches in 2025. Around $128 million vanished in a multi-chain attack that rippled through projects built on Balancer’s open-source vault architecture. Assets, including osETH, WETH, and wstETH, were siphoned from Balancer v2 Vaults. The exploit triggered emergency pauses across several networks and exposed how tightly interlinked today’s DeFi infrastructure has become.

What Went Wrong

Early forensics link the Balancer exploit to a flaw in the manageUserBalance function. The Balancer v2 vulnerability let attackers move internal balances without authorization. In simple terms, one faulty permission check opened a backdoor across every protocol using the same module.

Investigators are still examining whether the bug came from a recent code update or an old oversight. Balancer Labs has urged liquidity providers to exit affected pools while it prepares a fix.

The Fork Domino Effect

The Balancer forks affected included Beets.fi (Beethoven X) and Berachain’s BEX exchange. Each relied on Balancer’s vault contracts with almost no changes. The Beets.fi hack forced developers to halt swaps and launch an emergency DAO vote. The Berachain exploit led to a full pause of its exchange while engineers drafted patches.

The episode shows a clear problem in DeFi. Code reuse speeds innovation but also synchronizes failure. When one shared contract breaks, its clones follow. As one auditor said, open-source code “compounds both efficiency and exposure.” The Balancer security breach turned a single-protocol issue into a network-wide crisis within hours.

How the Attack Unfolded

The first warnings appeared late Sunday UTC. Tracking firms noticed sudden withdrawals from Balancer Vaults on Ethereum. Soon after, similar drains hit Polygon, Base, and Sonic. Initial estimates showed $70 million in losses. Hours later, totals rose to $128 million as analysts linked cross-chain addresses.

The Balancer hack now ranks as the largest DeFi exploit of the year. Most of the Balancer hack losses involved wrapped-asset liquidity tokens. The attacker consolidated funds into new Ethereum wallets and moved portions through bridges to hide the trail. No recovery or freeze has been confirmed.

Market and Ecosystem Reaction

After the Balancer exploit, the BAL token fell about seven percent. Liquidity on major pools thinned as users withdrew funds. Trading volume briefly shifted to Uniswap and Curve. Fork developers coordinated with auditors to push urgent patches.

Analysts say the case proves DeFi needs modular audits and shared bug-bounty pools. Separate audits for identical codebases are not enough. Industry groups are already discussing version tracking and collective vulnerability registries for forked contracts.

Outlook: Cooperation as Defense

The Balancer hack remains a defining moment for DeFi security. Balancer Labs, Beets.fi, and Berachain are preparing post-mortems and tracking stolen wallets. The attack highlights DeFi’s paradox: open code brings progress; and contagion.

Balancer v3 is expected to emphasize stronger code isolation and stricter upgrade controls. Yet the deeper lesson goes beyond Balancer. In a world of composable finance, one DeFi exploit can cascade through every fork that shares its code.

Readers’ frequently asked questions

What exactly does it mean when a DeFi protocol like Balancer is “exploited”?

An exploit happens when attackers find a flaw in a smart contract and use it to move or withdraw funds they shouldn’t be able to access. In Balancer’s case, the bug allowed unauthorized internal transfers within its vault system. Once executed, these on-chain actions can’t be reversed, so losses become permanent unless funds are voluntarily returned or recovered through law enforcement.

Why did other projects like Beets.fi and Berachain lose money if they’re separate platforms?

Both platforms used the same Balancer v2 code as the foundation for their own exchanges. When Balancer’s core vault contract turned out to have a bug, that same flaw existed in its forks. This is common in open-source DeFi, where projects copy audited code to save development time—but it also means one error can affect multiple protocols at once.

Can users who lost funds in the Balancer hack 2025 get their money back?

It’s unlikely in the short term. Because the assets were drained directly from on-chain contracts, there’s no central authority that can reverse the transactions. Recovery depends on whether the hacker returns funds, is identified, or exchanges agree to freeze stolen tokens. Balancer Labs and affected projects are still investigating and monitoring the stolen wallets.

What Is In It For You? Action items you might want to consider

Withdraw funds from affected Balancer pools

Liquidity providers should remove assets from any Balancer v2 Vaults or forked pools that have not yet been patched to prevent further exposure to the exploit.

Review exposure in Beets.fi and Berachain integrations

Users and projects that use Balancer-based liquidity or routing through Beets.fi or Berachain should verify whether their pools were affected and follow the official mitigation steps from each platform.

Monitor Balancer Labs’ post-mortem and recovery updates

Stay alert for official Balancer Labs statements and updates from audit partners. These communications will confirm when contracts are safe and whether partial fund recovery becomes possible.

X Chat Promises Privacy — But Can Musk Build a Messenger Without Selling User Data?

Elon Musk says his rebuilt messaging system, X Chat, won’t read your messages, track your behavior, or sell your data to advertisers. That’s a bold claim in 2025 when WhatsApp and Instagram still thrive on ad targeting and user profiling. His message is clear: if you’re not the product, you can finally just be the user.

But as with all disruptive visions, privacy comes with paradoxes, and complexities.

Musk’s Pitch: Privacy Over Profit

X Chat isn’t just an incremental redesign within the X app. It’s a full reconstruction of the platform’s messaging architecture. The old, centralized DM format is being replaced by a peer-to-peer encrypted system modeled after “Bitcoin-style” encryption, where keys supposedly reside on user devices.

Musk asserts that no chat data will be collected, analyzed, or monetized. Ads won’t appear, which is a direct rejection of Meta’s data-fueled advertising model.

He has also outlined a roadmap extending to voice, video, peer-to-peer payments, and a standalone X Chat app for messaging independent of social feeds. At launch, Premium users enjoy ad-free encrypted messaging. Over time, X aims to expand these capabilities to all users.

Privacy Reality: Scrutiny and Skepticism

Every promise of privacy invites scrutiny. Although Musk touts a privacy revolution, independent experts have flagged important caveats.

Some analyses suggest X Chat’s encryption isn’t fully peer-to-peer. Private keys and metadata may still pass through or be stored on X servers. There’s no open technical documentation or external verification. For now, users can’t confirm the robustness of the “Bitcoin-style” claims.

Musk acknowledges ongoing development and plans to release a technical whitepaper. True trust, however, will require transparency and third-party review.

Meta’s WhatsApp, Telegram, and Signal also claim strong privacy. Yet each employs different trade-offs in encryption, data handling, and backup architecture. X Chat will need to demonstrate, not merely promise, superior privacy.

The Business Dilemma: Beyond Ads and Subscriptions

X’s privacy-first stance resonates with crypto users, privacy advocates, and technologists. But with ads sidelined and basic access free, a fundamental question looms: how will X Chat fund itself?

Unlike Meta’s ad-based empire or Signal’s donation model, X is exploring multiple monetization channels:

  • Premium subscriptions and paid verification offering tiered benefits such as access to Grok AI and enhanced privacy options.
  • Revenue-sharing partnerships that allow X and its AI division, xAI, to earn through licensing and enterprise services.
  • Creator monetization, including live-stream ad splits, subscriptions, tips, and sponsorships.
  • Future transaction fees on crypto-based payments or business messaging once those features go live.

This diversification helps X reduce dependency on ads. This shift was accelerated by declining advertiser interest and Musk’s polarizing public stances.

The Adoption Hurdle: Network Effects and Integration

Even if users trust X Chat’s privacy promises, winning mass adoption is another battle. WhatsApp’s and Telegram’s enormous user bases rely on network effects—everyone’s already there. For most people, privacy is secondary to convenience and reach.

However, X Chat could gain traction if it integrates real advantages:

  • Verified identity messaging to reduce scams and impersonation.
  • Native crypto payments, once the X Payments infrastructure matures.
  • AI-powered moderation that filters abuse without scanning message content.
  • Deep integration with the X platform, blending public and private communication.

Early features like multi-device sync and the option to chat without linking a phone number address long-standing pain points. They could ease onboarding for new users.

Still, success will depend on more than technology. It requires cross-app interoperability, global rollout, and trust earned through transparent security practices.

Setting a Precedent: The Long Game

For now, X Chat is more a foundational rebuild than a finished product. Musk’s goal is to lay the groundwork for an “Everything App” where posting, messaging, shopping, and payments coexist, protected by data autonomy.

If X can combine genuine privacy compliance, robust features, and a self-sustaining revenue model, it could redefine how social platforms monetize.

X Chat isn’t poised to dethrone WhatsApp or Telegram overnight. Instead, it’s a test case for an ecosystem that enables payments, verification, and identity without turning user data into currency. Whether this paradigm can scale will depend on technical transparency, institutional trust, and continuous innovation.

X Chat is a bold experiment in rewriting the social contract between users and platforms. By anchoring privacy and diversifying monetization, Musk is challenging the logic of monetized surveillance that made social media profitable.

The hard truth is that privacy doesn’t scale easily when “free” is the default expectation. Technical trust also takes time to earn.

Yet if X Chat’s vision holds; if it truly delivers encrypted communication and sustainable monetization without exploiting user data, it could set a precedent for a digital economy where the user is both private and empowered, not just the product.

Readers’ frequently asked questions

Can I use X Chat without an X account?

Not yet. The current version of X Chat is integrated into the X app. A standalone X Chat app is on the roadmap and is expected to let users message without using the main X social feed.

Does X Chat share metadata or usage information?

Messages are encrypted, but some metadata (for example, timestamps, delivery status, or device identifiers) may still be processed for routing and sync. X has not published a detailed metadata policy yet, so users should assume limited data handling until official documentation is released.

When will wallet or payment features arrive?

Peer-to-peer payments are part of X’s roadmap under X Payments but are not available in X Chat today. Rollout is expected after compliance and licensing steps are completed in major markets.

What Is In It For You? Action items you might want to consider

Evaluate the credibility of privacy claims before adopting new messengers

Before switching to X Chat or any encrypted platform, look for technical whitepapers, independent audits, or third-party reviews. Real privacy depends on verifiable transparency, not marketing promises.

Review how your current messaging app handles data

Most users underestimate how much metadata is collected by mainstream apps. Checking your current messenger’s privacy policy helps you understand what’s changing, and what isn’t, if you move to X Chat.

Track how X expands its ecosystem around payments and identity

Wallet integration and verified identity features could transform X from a messaging tool into a broader platform. Monitoring these developments will show whether X can sustain its privacy model without relying on ads.

From Silence to Sorry: MEXC’s $3 Million Freeze and the Cost of Accountability

A crypto trader stands before a locked digital vault glowing with the MEXC logo, symbolizing blocked account access and user frustration amid solvency rumors and transparency concerns.

When the MEXC account freeze hit the headlines in late October, few expected it to turn into one of the year’s most damaging episodes for a major exchange. What began as a routine compliance check escalated into a four-month standoff, ending only when public outrage forced MEXC to apologize and unfreeze a $3 million trader account. The affair has become a case study in how centralized platforms manage (or mismanage) user disputes.

The freeze that sparked the fire

In July 2025, MEXC froze roughly $3 million belonging to a high-volume trader known in the community as White Whale. The exchange cited vague “risk-control concerns” and requested additional verification. The trader complied, but nothing happened for months. Support tickets went unanswered, and private escalation channels produced no results. By autumn, what MEXC called a temporary hold looked more like a permanent lock. The incident sparked new fears about MEXC withdrawal problems and user protection on centralized platforms.

When silence breaks

After exhausting all internal options, the trader finally went public in late October, posting transaction proofs and screenshots to social media. The post went viral, prompting major crypto outlets to pick up the story. Suddenly, a quiet dispute became an industry flashpoint. Commentators asked the obvious question: why did MEXC freeze a trader’s $3 million? Within days, rumors of liquidity stress and hidden liabilities began circulating. These MEXC solvency rumors fueled withdrawals across the platform and sent the exchange’s reputation into free fall.

The apology under pressure

Only after the uproar reached mainstream coverage did MEXC act. Executives issued an official statement admitting that an “internal crypto exchange risk management error” had wrongly flagged the trader’s account. MEXC restored the trader’s funds in full and promised to review its procedures. MEXC’s apology spread quickly across crypto media, but its timing made it clear that accountability arrived only after social-media outrage. For many observers, this wasn’t customer service; it was crisis containment.

Solvency doubts that won’t die

MEXC tried to calm the storm by releasing an updated snapshot of its proof of reserves, claiming more than 100 percent asset backing for USDT, BTC, and ETH. Yet even this did little to restore confidence. Proof-of-reserves confirms wallet balances, but it doesn’t reveal off-balance-sheet liabilities or internal borrowing. As some analysts noted, a MEXC proof of reserves explained only part of the story. In absence of independent audits, the community remains unconvinced. Traders interpreted the gesture as damage control designed to slow withdrawals rather than genuine transparency.

The bigger question of accountability

The incident highlights a systemic flaw in centralized exchanges: they can freeze, delay, or deny access to funds with minimal oversight. In the MEXC account freeze saga, there was no arbitration process, no regulator to appeal to, and no communication until the issue went viral. That gap between control and accountability is what keeps centralized exchange trust issues at the center of the industry’s transparency debate.

While MEXC insists that user assets are safe and its reserves remain intact, reputation once lost is hard to rebuild. Users may forgive technical mistakes, but months of silence undermine confidence more than any balance-sheet figure ever could.

The White Whale episode shows that in crypto, public pressure often substitutes for consumer protection. MEXC’s quick reversal after four months of inaction might have ended one trader’s ordeal, but it left the wider market wondering, is MEXC exchange safe for traders 2025? Until exchanges adopt independent audits and transparent dispute mechanisms, even a single frozen account can snowball into a solvency scare — and another reminder that trust, once frozen, is not easily thawed.

- Advertisement -

FEATURED