This editorial is from this week’s edition of the newsletter Week in Review, sent to subscribers on Friday. Subscribe to the newsletter to get this weekly editorial the second it’s finished. The newsletter also includes the biggest stories of the week with a comment on each story.
Crypto
Bitcoin’s Stumble Looks Graceful Next to Zcash’s Faceplant — Week in Review
Bitcoin capitulated below its 200-week moving average with a big red candle, trading at $62,495 as of Friday morning. Ethereum saw similar blood, and the altcoin sector in general collapsed further, even the outliers that were shining in previous weeks.
Meanwhile, the stock market continued its parabolic ascent, with the S&P 500, Nasdaq, and Dow Jones all hitting new record levels yet again.
Traditional markets look unstoppable. The S&P 500 is on track for its longest weekly winning streak since 1985. But under the hood, folks like Jim Bianco worry that the entire rally is a one-trick pony. The concentration of money in AI is at historic highs. Space is hot too, led by the imminent SpaceX IPO, with fuel added to the fire by the likes of Fidelity. Even if the current software-focused AI trade cools off, the current trade could pivot heavily towards physical AI – robotics.
There are economic rumblings of discontent. Bernie Sanders has introduced the “American AI Sovereign Wealth Fund Act,” proposing to confiscate 50% of the equity in leading AI companies. The K-shaped economy is intensifying, with small businesses entirely left out of the recent uptick in hiring, marking the worst job outlook since May 2020. Pimco’s chief investment officer has warned that the first sustained credit default cycle in years has begun.
Against this backdrop, crypto is suffering a severe crisis of faith, tipped over the edge by the one-two punch of Saylor selling Bitcoin and the announcement that Zcash had a 4 year double-spend exploit. Here’s a good overview to understand the Zcash bug. In a bitter twist of fate, Taiki Maeda announced he had rotated heavily into Zcash (ZEC) because Saylor fumbled his thesis.
Sentiment was already low, but this bug and the subsequent ongoing price waterfalls is sending it lower, exacerbated by the divergence with equities. While the Nasdaq 100 hits fresh records fueled by AI, Bitcoin and crypto are cratering.
The on-chain data is ugly. Cycle-top buyers who held through the drawdown are finally capitulating, with Glassnode reporting that aggregated realized losses have spiked to $1.3B/day. Long-term bulls are openly stating they aren’t sure Bitcoin recovers this time, or lamenting the opportunity cost of holding Bitcoin while the AI trade minted millionaires. The problems aren’t just price action; fundamental concerns are mounting, as outlined in a viral thread detailing Bitcoin’s current structural issues. Crypto tourists like Brent Johnson are contemplating scenarios where MicroStrategy (MSTR) drops to single-digit support levels.
There are glimmers of hope. DonAlt, the legendary duck, says he will buy “properly” if the weekly candle closes above $71K. That seems all but impossible now, but not in the next couple of weeks. Saifedean Ammous argues that the ultimate backstop remains intact: the narrative that nation-states will buy Bitcoin precisely because it is an asset that cannot be seized by foreign adversaries. The ZEC failure, and a failure all privacy coins suffer currently, strengthens Bitcoin’s primacy as the de facto digital asset store of value.
The altcoin market is faring worse, of course. Delphi Digital declared what we already knew: airdrops don’t work and only create sellers. Builders are exhausted. Algod took to X to voice his frustration with the Bittensor ecosystem, citing unclear conviction and iteration fatigue, while noting that he still holds nearly an ATH amount of TAO but feels his conviction is being seriously tested by a lack of builder incentives.
The old guard of projects are soldiering on. Ryan Sean Adams continues to argue that Ethereum’s value capture mechanism is its use as money—a SoV, MoE, or unit of account. Justin Drake released a long post on the Google quantum computing breakthrough that made many feel Ethereum’s got a great game plan vis-à-vis Bitcoin. Meanwhile, Charles Hoskinson had to clarify that he is not leaving Cardano after ADA dropped 94% back to 2020 levels, prompting critics to beg him to just stop talking.
In a perfect summation of the market’s current feeling, Carl The Moon is officially pivoting to a music career.
Despite the gloom, Hunter Horsley is right: there is a quiet changing of the guard underway in crypto.
The brightest spot is Hyperliquid. HYPE broke all-time highs, proving that tokens can actually perform if they don’t have horrendous tokenomics. Its perpetual volume market share versus centralized exchanges hit 7%. The success even caught the attention of tradfi royalty, with ICE’s Jeff Sprecher noting that it’s bigger than NASDAQ with only 11 people.
But not everyone is convinced. Kyle Samani declared that Hyperliquid is just “Binance 2.0” and will fail due to its centralized technical decisions. This triggered Arthur Hayes to challenge Mr. Samani to a $100k charity wager that HYPE outperforms any top-ten crypto.
Despite this belief in HYPE, Mr. Hayes went from proclaiming “$HYPE to $150”, only to completely dump his HYPE position four days later. In other negative HYPE news, the UK’s FCA published a warning designating Hyperliquid as an unauthorized firm.
Meanwhile in CEX land, Binance announced stock trading on its platform, prompting jokes of being a little late to the party. Coinbase made waves by backing Ethena with open market purchases of ENA.
Perhaps the most fascinating infrastructure shift is the maturity of prediction markets. They’re no longer just for degenerate gambling; they are being actively used for hedging. Rob Hadick notes the sheer volume of teams building sophisticated institutional tooling to place hedging contracts. In a great real-world application, an NYC bar used Kalshi to hedge giving away free drinks if the Knicks win.
Let’s end on some hopium. Chris Perkins pondered whether we might be entering an “alt fundamentals szn” where real product-market fit actually matters. And the hosts of Forward Guidance argued that the massive, concentrated profits currently locked in AI and semis could eventually rotate back to the comparatively starved crypto markets.
-David Sencil
Crypto
FBI arrests man accused of using Steam games to drain victims’ crypto wallets | TechCrunch
U.S. prosecutors have accused a Florida man of uploading fake video games that contained malware to Steam, the popular PC games platform. Once victims downloaded and installed the games, the malware was designed to infect their computers, steal their passwords and other data, and drain their crypto wallets, according to a criminal complaint.
On Tuesday, the FBI arrested Zyaire Wilkins, a 21-year-old Florida resident and student. On Wednesday, prosecutors accused him and a number of unnamed co-conspirators of hacking crimes. Over the past two years, Wilkins and his partners allegedly published several malware-laden video games on Steam, including BlockBlasters, Dashverse, Lampy, Lunara, and PirateFi. Using that malware, says the FBI, Wilkins and his accomplices infected around 8,000 victims, and then hacked around 80 cryptocurrency wallets to steal at least $220,000 worth of crypto.
Wilkins and the others marketed their malicious video games on Discord, LinkedIn, and Telegram, according to the authorities.
Wilkins’ lawyer did not respond to a request for comment.
In March, the FBI announced that it was investigating a hacker suspected of using malware-embedded video games published on Steam to hack victims. In the announcement, the bureau called for people who downloaded the malicious games, which included those named in this week’s complaint, to come forward and provide evidence to aid the investigation.
In the last year, Steam’s maker Valve has removed several video games from its platform after they were found to contain malware, including PirateFi. All the games were designed to look legitimate, to the point that players could install them and play them, but they all contained malware.
After the FBI identified another person involved in the crimes, according to the complaint, federal agents interviewed them. The unnamed person said they worked with other people to raise money to launch and market the malicious games in return for sharing some of the stolen cryptocurrency. The FBI identified a specific crypto account involved in the scheme, and then traced cryptocurrency payments made with that account to buy several gift cards, including for Uber Eats. After subpoenaing Uber, the feds were able to see that the gift cards were linked to an account that made deliveries to Wilkins, who went by the nickname Sibel.eth online, according to the complaint.
The feds then got a search warrant for Wilkins’ residence, where they seized his MacBook laptop, cellphones, other devices, and digital wallets. According to the complaint, he refused to speak or answer any questions.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Crypto
DeFi’s Newest Threat: How Malicious Liquidity Pools Are Trick-Quoting Ethereum and Polygon Users
Key Takeaways
- Enso’s July 16 report exposed “toxic pools” that fake quotes, causing tens of thousands of dollars in losses on a Curve pool.
- The exploit threatens DeFi front-ends, with one malicious Uniswap v4 hook causing a 99.1% failure rate.
- Enso updated its Enso Shield product to detect fake quotes across 2 different blockchain environments.
A ‘Jekyll and Hyde’ Tactic
A newly uncovered class of malicious decentralized finance ( DeFi) liquidity pools is targeting the core infrastructure that cryptocurrency traders rely on to find the best prices, according to new research published July 16 by DeFi infrastructure firm Enso.
The company is calling the deceptive setups “toxic pools.” Unlike typical cryptocurrency hacks that drain funds directly from smart contracts, these pools are engineered to systematically trick transaction simulations. They return attractive, highly competitive price quotes when a crypto wallet or decentralized exchange ( DEX) aggregator runs a simulation, but they alter their behavior the moment the transaction is actually executed on the blockchain.
The result is a subtle, systemic drain: traders receive significantly worse execution prices than they were quoted, or their transactions fail, burning network fees in the process.
“Our investigation leads us to believe this is not simply another isolated smart contract exploit,” said Milos Costantini, co-founder and chief product officer at Enso. “The industry has spent years optimizing price discovery. Our findings suggest the next challenge is verifying execution integrity.”
According to Enso’s report, toxic pools exploit the off-chain “dry-run” simulations that wallets use to preview trades. The malicious contracts detect when they are running in a read-only simulation environment and return an artificially optimized price. Once the transaction is actually broadcast on-chain, the pool alters its mathematical logic to execute the trade at a degraded rate.
To remain hidden from security systems, these pools alternate between honest and malicious states, rendering static code scanners and historical reputation filters ineffective. This bait-and-switch design degrades the user experience and drains user funds through failed transactions. In one case study, a manipulated Curve pool triggered more than 37,000 reverted trades, forcing users to burn nearly $30,000 in gas fees.
Attackers are also exploiting next-generation, modular exchange architectures. On Polygon, a malicious “hook” — a smart contract plugin used in platforms like Uniswap v4 — lured routing systems with fake rates before triggering a 99.1% transaction failure rate.
Findings From On-Chain Forensic Analysis
The research, which spanned roughly two months of on-chain forensic analysis, combined historical archive- node data, transaction trace analysis and smart contract inspections. Enso engineers, with support from contacts at major DeFi protocols Curve Finance and Oku, identified active toxic pools operating across both the Ethereum and Polygon blockchains.
In one documented case study on Ethereum, a manipulated Curve pool processed more than 129,000 swaps. While the pool appeared to be the optimal route, it delivered worse execution than quoted, leading to approximately $225,000 in overstated quotes.
Furthermore, Enso’s team identified multiple blockchain oracle contracts deployed by the same operator to support additional pools, indicating the tactic is likely more widespread than the two documented cases and could represent an emerging template for on-chain extraction.
The findings present a direct challenge to the user-facing layer of the DeFi ecosystem. Popular wallets, consumer-facing interfaces and aggregators depend heavily on automated simulations to guarantee the “best path” for a user’s trade.
Enso’s report highlights that if routing infrastructure cannot distinguish between a legitimate quote and a manipulated one, front-ends will continue to steer users toward these traps. This creates potential legal and financial liability risks for wallet providers and interface operators who promise “best execution” but routinely deliver toxic routes.
In response to the threat, Enso announced it has updated its execution-protection product, Enso Shield, to include dedicated toxic-pool detection. The security tool is designed to bypass standard simulation methods by analyzing live on-chain context, monitoring quote history and using transaction traces to spot execution discrepancies.
Rather than blaming individual decentralized exchanges, Enso has called on the wider cryptocurrency industry to conduct further research into the manipulation of transaction simulations.
“If transaction simulations can be manipulated while real execution tells a different story,” Costantini said, “we need better ways to verify what users actually receive.”
Crypto
New law protects consumers from cryptocurrency kiosk/ATM fraud | Maui Now
July 16, 2026, 5:00 AM HST
Starting Oct. 1, cryptocurrency kiosk/ATMs that accept deposits will no longer be allowed in Hawai’i as a new consumer protection law takes effect.
Hawai’i is now the 35th state to enact a law to protect consumers from losing money in scams involving cryptocurrency kiosk/ATMs and is the first state to ban kiosks that accept deposits. Four other states have completely banned these machines. Other states have imposed transaction limits, mandated refunds for fraud, increased warning signs, required printed receipts and passed other consumer safeguards.
“The use of cryptocurrency kiosks in scams was increasing exponentially in Hawai’i and across the nation. Last year, the FBI said Hawai’i consumers reported losing $3.85 million through fraud involving cryptocurrency kioks. That’s nearly four times the amount reported lost in 2024,” said Keali’i Lopez, AARP Hawai‘i state director. “That’s why AARP fought hard to pass Act 224. We’re grateful to our advocacy volunteers and others who shared fraud stories, testified, called and sent letters and emails to help pass the law. We’re also thankful to lawmakers who acted decisively to protect consumers.”
The FBI said kupuna were especially vulnerable to cryptocurrency kiosk/ATM fraud and accounted for the majority of the losses. The machines look like bank ATMS and could be found in grocery stores, convenience stores, pharmacies, gas stations and other locations.
“Fraudsters use cryptocurrency kiosks like a getaway car in a bank robbery,” Lopez said. “They convince consumers through romance scams, by posing as an IRS agent or other official, or through a technology scam, to take money out of their banks and deposit it in the cryptocurrency kiosk and once the money is put into a scammer’s cryptocurrency wallet, it is gone.”
-
Alaska2 minutes agoEPA waives Clean Air Act restrictions on high-sulfur diesel for the North Slope
-
Arizona8 minutes agoArizona lacrosse leaders believe sport is poised to grow
-
Arkansas14 minutes agoTwo Narratives, One Ballot Box: Trump’s Concerns and Arkansas’ Response
-
California20 minutes agoForest Service workers held hostage at gunpoint by father, son in CA forest for hours: Authorities
-
Colorado26 minutes agoThe presiding judge of Colorado Springs Municipal Court will retire
-
Connecticut32 minutes agoWethersfield woman accused of sexually coercing minor from New York after meeting him online
-
Delaware38 minutes agoCanadian Wildfire Smoke Pushes Delaware Air Quality to Code Red | Delaware LIVE News
-
Florida44 minutes agoWill Florida see its next named storm this weekend?