Crypto trader and X personality Unihax0r lost +$200,000 on May 11 after someone drained two of his wallets across Ethereum, Base, and BSC. On-chain analysts think it was a private key leak linked to a Telegram trading bot.
βJust got drained or hacked for more than 200k. Sick to my stomach,β Unihax0r posted on X. He shared the attackerβs wallet address and asked people to help trace the funds.
Attacker swept three chains in under an hour
This wasnβt a smart contract exploit since thereβs no malicious token approval.
On-chain analyst @k0braca1 looked at the transactions right after it happened and said it looked like a private key leak. The attacker βhad full control over signing operations across multiple chains: Ethereum, Base and BSC.β
The drain took somewhere between 10 and 30 minutes. The biggest chunks were about $125,000 in $POD tokens on Base and $21,000 in $FHE on BSC, plus ETH and smaller positions. The attacker even sent a bit of ETH to the Ethereum wallet first to cover gas for sweeping the remaining token balances.
Hey bro, sorry this happened to you.
My quick assessment of what happened. The exploit looks like a private key leak rather than related to any malicious transactions, as the attacker has full control over signing operations across multiple chains: Ethereum, Base and BSC. Itβ¦
Both crypto wallets that got drained were created via a Telegram multichain trading bot called SIGMA. Unihax0r imported those wallets into GMGN, which is another Telegram trading tool, and Rabby Wallet.
Other wallets on Rabby and Jupiter were not drained since the SIGMA bot did not create them. This means that the SIGMA trading bot is the probable cause of this attack.
Investigators in the community have come up with a few ideas about what caused the theft of secret keys:
Telegram phishing through fake CAPTCHA bots that pop up when you use SIGMA.
Malware or infostealer infections.
Device compromise.
Malicious browser extensions.
Unihax0r said he checked his Telegram account and found no suspicious sessions, per Crypto Times.
The stolen crypto went to an externally owned account that the attacker controls.
The stolen crypto was transferred to an external wallet owned by the attacker. On-chain data shows the stolen tokens are already being mixed by the attacker.
Most of the assets are still sitting in the attackerβs wallets on Base. Community members and fraud tracking accounts have offered to help trace funds, but the odds of getting the money back are low.
Telegram bots are a structural weak point
Crypto losses connected to Telegram trading bots keep piling up. When a user generates wallets through Telegram bots, the private keys get created and stored within the botβs infrastructure.
Security researchers from ForkLog warned about using Telegram bots to trade crypto. They explained that Telegarm bots βcould potentially lead to asset losses and are not safeguarded against hacker attacks.β
Telegram bot scams have been ramping up. Web3 anti-scam platform ScamSniffer said Telegram group malware scams jumped by 2,000% between November 2024 and January 2025. Attackers use fake verification bots and phony group invitations to push malware that can access wallets and browser data.
Last September, Banana Gun, which is one of the most active Telegram trading bots, had 36 wallets exploited for 536 ETH. That was ~$1.9 million at the time. The bot went offline after that.
The rsETH crisis resulted in $200 million in bad debt on Aave’s books, despite not a single line of its contracts misbehaving.
On Apr. 18, attackers that Chainalysis preliminarily linked to Lazarus compromised RPC infrastructure, forced a failover to poisoned nodes via DDoS, and injected false data into a 1-of-1 DVN configuration on KelpDAO’s rsETH bridge.
The forged message released approximately 116,500 rsETH, and Aave’s incident report confirmed that Ethereum accepted nonce 308 while the Unichain source endpoint never advanced past 307.
The attacker supplied the compromised rsETH to Aave and borrowed against it, resulting in bad debt and serving as a frame for the current state of DeFi’s security.
Exploiters extracted over $635 million across 28 incidents in April, the worst monthly total in over a year. DefiLlama puts the cumulative historical cost of hacks at $16.5 billion, with $7.7 billion specifically targeting DeFi.
The high-profile exploits on Drift and the KelpDAO bridge resulted in DeFi losing nearly $11 bilion in total value locked last month.
That contractionΒ occurred as stablecoin rails, tokenized treasuries, and regulated settlement layersΒ gainedΒ institutional traction in the same capital markets.
DeFi exploiters extracted $635 million across 28 incidents in April, the sector’s worst monthly loss in over a year, while cumulative historical hacks reached $16.5 billion.
How did DeFi end up here?
Mitchell Amador, CEO of Immunefi, told CryptoSlate that DeFi has historically rewarded growth, integrations, liquidity, and speed over security maturity.
A protocol that adds a new asset, bridge, oracle, adapter, or external dependency gains immediate utility. The risk that integration carries produces no visible price signal until an exploit materializes, because the absence of an incident is invisible while it holds.
That asymmetry kept audit cycles and isolation practices secondary to shipping velocity for years, until April concentrated the consequences into a single month.
Amador said the most overlooked practices were multisig hygiene and management, supply chain hardening, real-time monitoring, and emergency response procedures.
Too many teams treated multisig as a security solution in itself, when its actual strength depends on signer count, the independence of those signers, their operational setup, and the processes around transaction review.
A low-threshold multisig, weak signer security, or a poorly monitored bridge or oracle can become a systemic exposure because DeFi protocols are composable by default. In this landscape, risk travels through integrations as efficiently as liquidity does.
While that culture was forming inside DeFi, a different model was being built in parallel.
βThe gap in output per person tells you what happens when you strip away everything that isn’t the core financial function. The teams that win this round will be the ones built on compliance and security from day one, ready to ship faster than a bank can call a meeting about it.β
DeFi built composable rails for over half a decade before Wall Street recognized them as the actual infrastructure layer of the next financial system.
The cost of that early market position was a security culture calibrated for speed over operational discipline.
Kasper Pawlowski, CTO of Euler Finance, names the governance dimension of the same failure in his post-incident analysis.
He said:
βDeFi treats risk assessment as a one-time onboarding decision, when in reality risk is dynamic.β
The 1-of-1 DVN configuration that enabled the KelpDAO exploit existed in production for years. Kelp says it was the default LayerZero shipped and reviewed across multiple integration meetings, while LayerZero says Kelp downgraded to it.
Whichever account is accurate, the configuration persisted unflagged through every integration with every downstream protocol. LayerZero has since banned the configuration on a protocol-wide basis, acknowledging that allowing its DVN to act as the sole verifier for high-value transactions was a mistake.
Stage
What happened
Why it mattered
RPC infrastructure compromised
Attackers compromised RPC infrastructure tied to the rsETH bridge setup
The attack began outside the core smart contracts, showing how off-chain infrastructure can become the entry point
DDoS forced failover
Traffic was pushed onto poisoned nodes through a forced failover
That let attackers control the data environment seen by the bridge verifier
False data injected into 1-of-1 DVN
Poisoned nodes fed false data into a single-verifier DVN configuration
A 1-of-1 verifier setup meant there was no independent check to stop the forged message
Forged bridge message accepted
The forged message released about 116,500 rsETH
Fake collateral was effectively minted into circulation
Fake rsETH supplied to Aave
The attacker deposited compromised rsETH into Aave as collateral
Aave treated the asset as valid and allowed borrowing against it
Borrowing created bad debt
The attacker borrowed other assets and left Aave with roughly $200 million in bad debt
Losses from a bridge failure migrated into a lending market and were socialized across the pool
The more consequential point is that a critical bridge-security parameter was normalized across the entire dependency chain until a $292 million exploit surfaced it.
Pawlowski argued:
βThe operational machinery DeFi has built β DAO governance, external risk service providers, and monthly review cycles β doesn’t move at the speed the underlying risk surface does. In many cases, the people doing the reviewing aren’t structurally independent of the assets they’re reviewing.β
That structural conflict produced the specific governance failure Pawlowski dissected. Aave’s 25,000 ETH treasury recovery proposal was authored by TokenLogic, a paid Aave service provider that publicly lists Kelp as a client and operates an Aave delegate platform.
For reference, TokenLogic is the same firm voting on its own proposals. On the same day Aave expanded rsETH to a 93% loan-to-value ratio in eMode, SparkLend deprecated the asset entirely, bundling the move with routine cleanup of underused positions.
Three months later, that routine pruning was the only separation between Spark’s depositors and the bad debt Aave now carries.
One protocol’s independent risk judgment outperformed another’s full-stack risk advisory apparatus. DeFi’s review machinery generated worse outcomes than a single asset manager doing portfolio hygiene.
What βhereβ means
Before the exploit, Aave was the largest DeFi protocol by total value locked, with over $26 billion in deposits.
Pawlowski noted:
βAave was the gold standard. If Aave can carry $200 million-plus in bad debt from a bridge exploit on a different protocol, the market has to recalibrate what βsafe’ actually means in DeFi lending.β
The pooled lending model is only as strong as its weakest accepted collateral, and when that collateral breaks, the entire shared pool absorbs the damage. The exposure reaches every depositor in the broader market, extending well past the vault that held the position.
Protocol
Decision on rsETH
Risk posture
Outcome
Aave
Expanded rsETH to a 93% loan-to-value ratio in eMode
More aggressive onboarding and collateral treatment
Ended up exposed to the compromised asset and now carries bad debt
SparkLend
Deprecated rsETH as part of routine cleanup of underused positions
More conservative portfolio and listing hygiene
Avoided the exposure that later hit Aave
Pawlowski pointed out that the structural reality had been βmuted by years of βbattle-tested’ and βblue-chip’ marketing.β
Amador broadened the exposure map beyond the mechanics of KelpDAO. The attack surface in DeFi now covers governance, signers, privileged roles, integrations, bridges, oracles, custody arrangements, and every external system a protocol depends on.
The most dangerous operational assumption a team can hold is that audited smart contracts equal a safe protocol. Immunefi’s own research shows that DeFi losses declined by as much as 80% over the last several years, because the sector hardened its code and attackers adapted.
Amador added that they now study the entire risk chain for the weakest points, and those points are now off-chain, governance-adjacent, or buried in dependency stacks that no single audit covers.
For institutions, April forced a specific reset. Amador described the checklist now: how admin keys are managed, who can pause markets, what dependencies exist, what the incident response process looks like, and how quickly a threat can be contained.
Pawlowski made the same point from the capital side, saying institutions will continue to enter on-chain credit because the demand for tokenized markets, transparent settlement, and programmable financial infrastructure is real.
However, the institutional investors will move toward isolated markets, permissioned or curated vaults, stricter asset onboarding, better insurance, continuous monitoring, and formalized emergency controls.
DeFi exploiters extracted $635 million across 28 incidents in April, the sector’s worst monthly loss in over a year, while cumulative historical hacks reached $16.5 billion.
Aave Horizon, a permissioned market for tokenized securities and RWAs launched in August 2025, has grown to more than $440 million in deposits.
Morpho’s vault ecosystem added ARCHITECT, the first FINMA-licensed investment manager to curate vaults at scale, and Flowdesk launched an institutional AUSD vault in March 2026, using tokenized equities as collateral.
EY-Parthenon and Coinbase’s 2026 survey found 73% of institutional respondents plan to increase digital asset allocations this year, but 81% prefer registered vehicles. Capital is moving on-chain through curated, governed, and compliance-aware structures.
The regulated alternative is accelerating on the other side of that same preference.
The GENIUS Act created the first federal framework for US stablecoins, with mandatory 100% reserve backing, no rehypothecation, and custody standards that Nadareski said βread like something a compliance desk could approve.β
A Goldman Sachs survey found 35% of institutional investors named regulatory uncertainty their biggest blocker, and 71% said they would increase exposure once clarity arrived.
Nadareski said, βThe floor is in place, the capital is waiting.β The CLARITY Act, which would define jurisdictional and custodian standards for digital assets, including tokenized securities, awaits consideration by the Senate Banking Committee as of May 14.
When that passes, Nadareski argued that βthe last item on most institutional checklists gets checked off. The waiting ends.β DeFi is competing for institutional capital against a nearly complete regulatory framework.
How DeFi resurges
Pawlowski named the full list of DeFi recovery tools: governance combined with proper market isolation, automated and AI-assisted risk monitoring, selective timelocks on parameters that warrant them, circuit breakers, KYC when required by regulation, application-specific sequencing, and policy-aware block builders.
He added:
βWhat’s been missing is the willingness to use them, because every one [of the tools] involves a tradeoff against the maximalist version of decentralization the industry has marketed itself on.β
Abandoning that marketing position is the starting point, but it’s not easy.
Pawlowski noted that βthe crypto industry has spent years pretending it can have everythingβ, such as full decentralization, censorship resistance, institutional-grade safety, and retail accessibility, without tradeoffs.
It was βthat fantasy that produced the conditions for these exploits.β A regulated institutional credit facility on-chain is a different product from a permissionless retail lending market, and governing both under the same orthodoxy created the conditions that let aggressive rsETH listings clear governance while structural bridge-security parameters sat unflagged for years.
Pawlowski believes the structural fix requires ending βthe conflicts that let aggressive listings get waved through low-turnout governance votes by service providers with commercial relationships on both sides of the trade.β
SparkLend’s independent pruning, versus Aave’s eMode expansion on the same day, is proof that different risk philosophies yield different outcomes.
DeFi needs to institutionalize that distinction, build governance structures around it, and make the tradeoffs explicit to every user and institution evaluating the protocol.
Amador’s operational prescription attacks the same problem from the execution layer.
DeFi must professionalize security in the same way it professionalized liquidity incentives via continuous audits, live bug bounty programs, formal verification where appropriate, independent security councils, stronger multisig thresholds, hardware-backed key management, real-time monitoring, public incident response playbooks, and mandatory risk reviews for every major integration.
Circuit breakers and isolation mechanisms should be built so that losses from a compromised asset, adapter, or dependency stay bounded within the affected market.
The benchmark for evaluating protocols should expand to cover security posture alongside yield and total value locked: who audited it, what the active bounty size is, how admin keys are managed, what dependencies exist, what the emergency procedure covers, and how quickly a threat can be contained.
Users and institutions should be able to compare protocols on those dimensions the way they compare APR.
Capability
Why it matters
What it looks like in practice
Market isolation
Prevents one compromised asset or dependency from contaminating a shared pool
Keeps risk assessment dynamic rather than one-time
Mandatory reviews for major integrations, recurring audits, formal verification where appropriate
Incident response readiness
Improves containment and recovery when something breaks
Public response playbooks, recovery guardians, predefined recovery procedures
Security transparency
Lets users and institutions compare protocols beyond yield
Clear disclosure of audits, bounty size, dependencies, admin controls, and response plans
A reform is already underway, as KelpDAO has begun migrating rsETH to Chainlink CCIP, LayerZero has banned 1-of-1 verifier configurations protocol-wide, and Aave Proposal 477 authorized liquidation of attacker positions, with recovered assets routed to a Recovery Guardian multisig.
Phase II of that proposal covers burning excess rsETH on Arbitrum, restoring bridge backing, reopening withdrawals, and compensating affected users.
Arbitrum’s Security Council separately froze 30,766 ETH tied to the attacker’s downstream funds.
That recovery required emergency councils, DAO votes, multisigs, and court proceedings, comprising a crisis-management stack drawn from the institutional finance playbook, deployed within a system that describes itself as permissionless.
DeFi reaches for those tools when losses get large enough, and protocols can embed them in advance or reconstruct them while a crisis unfolds.
DeFi’s case for composability
Nadareski identified the specific prize at stake for institutions choosing between DeFi and regulated alternatives.
Compliance officers want circuit breakers, time-locks, and custody standards that match their existing playbooks, and Wall Street has been building that wrapper for years.
Nadareski said:
βThe banks that move fastest will be the ones that stop trying to build everything in-house. Spinning up on-chain settlement with legacy teams puts you at 2028 if everything goes right. The play that ships this year is pairing established distribution and customer relationships with teams who already have the rails built.β
Composability is DeFi’s strongest argument for keeping the rails it built. A single protocol that executes a trade, manages collateral, routes liquidity, and automatically settles a transaction within seconds represents a capability that traditional finance can only replicate by rebuilding from the ground up.
Composability works as an institutional argument only if failures stay local. Once a bridge verifier, a governance vote, or a compromised oracle can transmit losses across shared liquidity pools at scale, composability operates as contagion infrastructure.
Amador noted:
βTrust the code is not enough when protocols depend on bridges, multisigs, governance processes, or external assets. The new standard has to be: assume every layer can fail, and design systems so one failure does not cascade into the entire market.β
Pawlowski framed the necessary changes as βgrowing up,β describing a sector that must accept and publish explicit tradeoffs, build genuinely independent governance structures, and make security a product feature that users and institutions can evaluate and compare.
DeFi built the composable infrastructure that tokenized markets are now adopting. Stablecoin rails, lending primitives, and liquidity mechanisms that originated inside permissionless DeFi are being packaged into products that Wall Street is shipping under regulatory cover.
If DeFi builds the operational maturity to match its technical architecture, composability remains the one capability beyond the reach of regulated wrappers. If DeFi fails to build that maturity, Wall Street captures the stablecoin and tokenization layer and, with it, the argument that open composable finance lacked the operational discipline serious capital requires.
Bitcoin, Rippleβs token, Solanaβs SOL, and several other altcoins made impressive moves over the past few hours, which was rather unexpected given the Sunday market sentiment and lack of major developments.
Interestingly, these recent gains coincided with Donald Trumpβs latest message on Iran.
The statement on Truth Social from the POTUS reads that Iran has been βplaying games with the United States, and the rest of the World, for 47 years.β He also placed significant blame on former President Barack Obama, saying the situation hit βpay dirtβ during his time in office.
βHe was not only good to them, he was great, actually going to their side, jettisoning Israel, and all other Allies, and giving Iran a major and very powerful new lease on life. Hundreds of Billions of Dollars, and 1.7 Billion Dollars in green cash, flown into Tehran, was handed to them on a silver platter. Every Bank in D.C., Virginia, and Maryland was emptied out β It was so much money that when it arrived, the Iranian Thugs had no idea what to do with it. They had never seen money like this, and never will again. It was taken off the plane in suitcases and satchels, and the Iranians couldnβt believe their luck.β
After also blaming Joe Biden, Trump said Iran will be laughing no longer at the USA. This statement comes after reports that Iran had sent their response to the USβs latest peace proposal. However, thereβs no further information as of press time regarding the actual decision.
As mentioned above, many crypto assets are in the green now. Bitcoinβs gains are among the most modest, but the asset still tapped $81,600. XRP has stolen the show from the larger-cap alts, surging by over 5% daily to a multi-week peak of just over $1.50.
SOL has risen to almost $100 after a 3.5% daily increase, ETH is well above $2,350, and ADA has gained over 5% to sit close to $0.29.
Attackers are posting fake macOS troubleshooting guides on Medium, Craft, and Squarespace. The goal is to make users run Terminal commands that install malware targeting iCloud data, saved passwords, and crypto wallets.
Microsoftβs Defender Security Research Team published the findings. The campaign has been running since late 2025. It preys on Mac users searching for help with common problems like freeing up disk space or fixing system errors.
Instead of offering a legit fix, the pages tell users to copy a command and paste it into Terminal. That command pulls down and runs malware.
The misleading blog posts tell readers to copy a malicious command and paste it into Terminal. This command downloads malware and runs it on the victimβs computer.
The technique is called ClickFix. Itβs social engineering that changes responsibility for launching the payload onto the victim. Because the user runs the command directly in Terminal, macOS Gatekeeper never inspects the payload.
Gatekeeper normally checks code signing and notarization on app bundles opened through Finder, but this method sidesteps it entirely.
Attackers launched three campaigns with the same goal
Microsoft spotted three campaign installers:
A loader.
A script.
A helper.
All three harvest sensitive data, establish persistence, and exfiltrate stolen information to the attackerβs servers.
The malware families include AMOS, Macsync, and SHub Stealer. If any one of the three malware was installed, it goes after iCloud and Telegram account data. Then it looks for private documents and photos under 2 MB. And it extracts crypto wallet keys from Exodus, Ledger, and Trezor, and steals saved usernames and passwords from Chrome and Firefox.
After installation, the malware throws up a fake dialog and asks for a system password to install a βhelper tool.β If the user enters the password, the attacker gets full access to files and system settings.
In some cases, researchers found that attackers deleted legitimate crypto wallet apps and replaced them with trojanized versions designed to monitor transactions and steal funds.
Trezor Suite, Ledger Wallet, and Exodus were some of the main apps targeted in this attack.
The loader campaign also includes a kill switch. The malware stops executing if it detects a Russian keyboard layout.
Security researchers observed attackers using curl, osascript, and other native macOS utilities to run payloads directly in memory. This is a fileless approach that makes detection harder for standard antivirus tools.
Attackers go after crypto developers
Security researchers from ANY[.]RUN discovered a Lazarus Group operation called βMach-O Man.β Hackers used the same ClickFix technique through fake meeting invitations. They went after fintech and crypto machines where macOS is common.
Cryptopolitan publishedΒ about the PromptMink campaign.
A malicious npm package was put into a crypto trading project by the North Korean group Famous Chollima through an AI-generated change. Using a two-layer package approach, the malware got access to wallet data and system secrets.
Both campaigns show that crypto wallet data is valuable. Attackers are adapting their delivery methods from fake blog posts to AI-assisted supply chain compromises to reach it.
Thereβs a middle ground between leaving money in the bank and rolling the dice in crypto. Start with this free video on decentralized finance.
Following the recent uptick in altcoin prices, conversations about the potential start of an altseason are gaining significant momentum. Interestingly, recent on-chain data about the rising altcoin trading volume has added some weight to the altseason discussions.
Altcoin Trading Volume Climbs Above Yearly Average
In a recent Quicktake post on the CryptoQuant platform, CryptoOnchain revealed a critical change in the altcoin market. Citing the βCEX Volume Ratio: Others vs Top 5β metric, the market analyst explained that the altcoin trading volume has been in an uptrend lately.Β
The βCEX Volume Ratio: Others vs Top 5β metric tracks how much trading volume is flowing into altcoins outside the top 5, relative to the combined volume of the top 5 assets. As such, it plays a key role in identifying the extent of capital rotation and whether altcoins have started to gain strength.Β
According to CryptoOnchain, the 30-day moving average of altcoin trading volume has now climbed past its 365-day moving average. This trend, explained the analyst, shows that the volume of this sub-asset class is steadily increasing.Β
Higher readings in the CEX Volume Ratio: Others vs. Top 5 are telltale signs that traders are leaning towards smaller altcoins rather than into major cryptocurrencies (Bitcoin, Ethereum, Solana, XRP, and BNB). This, in turn, is interpreted as growing risk appetite, which could positively influence an altcoin rally.
The market analyst cited historical data, noting that instances where the signals flashed mostly reflected short-term volume growth relative to the long-term baseline. These cases have also signaled βclear rotation of capital from major caps into mid and low-cap altcoins.β
For example, during the 2021 bull cycle, repeated clusters of these signals coincided with explosive rallies across the altcoinsβ sector, alongside a major price appreciation in Ethereum.
Notably, the chart shared by CryptoOnchain shows the purple βVolume Ratioβ line gradually strengthening again after a period of weakness. The analyst noted that a breakout in the ratio could precede high-volatility periods, potentially increasing the likelihood of an altcoin market rally.Β
Ethereum Stability Could Confirm Imminent Altcoin Rally
CryptoOnchain further explained that the reinvigoration of the altcoin trading volume could be a sign that βretail and institutional interest is expanding beyond the top 5 assets.β However, this does not necessarily translate to bullish news for the altcoin market.
According to the crypto pundit, confirmation from Ethereumβs price action might be necessary to determine the marketβs inner dynamics.
CryptoOnchain explained:
If this momentum is sustained and accompanied by a stable or rising ETH price, it could serve as a strong confirmation that a broader altcoin rally is underway.
As of press time, the Ethereum price stands at $2,329, up 1% over the past 24 hours, according to CoinGecko data.Β
The price of Bitcoin has been relatively stable since the start of April, showing strong efforts to reclaim former highs. In its latest recovery attempt, the premier cryptocurrency finally returned above $80,000 for the first time since early February.
Unsurprisingly, a relevant group of network participants, known as Bitcoin miners, appears to be taking advantage of the steady rise in BTCβs value over the past few weeks. Interestingly, a continuation of this profit-taking trend could pose an obstacle to the market leaderβs recovery.
Minersβ Profit-Taking Could Halt BTCβs Recovery
In a May 8th post on the X platform, crypto analyst Ali Martinez shared that Bitcoin minersβ behavior has shifted in recent weeks. The latest on-chain data shows that this group of network participants has been booking profits, as the price of BTC steadily climbed to a local high.
Highlighting changes in the Miner Reserves metric, which measures the total Bitcoin held in miner-affiliated addresses, Martinez revealed that about 3,400 BTC have been sent from addresses associated with network validators since April 7. Interestingly, this period has coincided with the coinβs price rising from $72,000 to around $82,790, further supporting the profit-taking hypothesis.
The analyst wrote on X:
Back then, Bitcoin was trading near $72,000. Through the recent climb toward yesterdayβs peak of $82,790, which represents a 15% price increase, miners have been steadily booking profits. On-chain data shows that miners have offloaded approximately 3,400 $BTC during this run, taking advantage of the recent price expansion to cover operational costs or lock in gains at multi-month highs.
Typically, falling Miner Reserves indicate that miners are distributing their coin to take profit, often to cover costs. As seen with several firms pivoting toward AI data centers, the profitability of the Bitcoin mining industry has been under significant pressure over the past few years.Β
More pertinently, the latest profit-taking and selling pressure can pose a threat to the ongoing recovery in Bitcoinβs price. The flagship cryptocurrency, which appears to have slowed down over the past day, would need uninterrupted bullish momentum to continue its current upside rally.
Bitcoin Price At A Glance
As of this writing, the price of BTC stands at around $80,287, reflecting a mere 0.8% leap in the past 24 hours. Meanwhile, the market leaderβs value has risen about 3% over the past seven days.
Chainlink (LINK) has been trading in a tight range between $9 and $9.50 over the past week, but one technical indicator suggests that the consolidation may be replaced by heightened volatility in the near future.
The recent whale accumulation and other bullish elements point to a higher probability of an upward move.
Prepare for Potential Turbulence
Several hours ago, the renowned analyst Ali Martinez disclosed that LINKβs Bollinger Bands have squeezed on the 3-day chart. The metric, developed by John Bollinger in the 1980s, uses a moving average flanked by two channels (upper and lower) that widen in volatile markets and narrow when things calm down. Squeezing the bands usually foreshadows a major move, but it offers no clarity on whether a rally or pullback is on the horizon.
The majority of analysts who have touched on the asset lately believe an upside is the more likely option. X user Celal Kucuker claimed that LINKβs graph looks βsolid and strong,β envisioning a pump to $100 during the next bull market.
For their part, CRYPTOWZRD suggested that the asset could be at a crossroads as its performance remains deeply correlated to Bitcoinβs price action.
βAbove $9.55, weβll see a further bullish move. Below, random movement will take place,β they predicted.
The Whales Step in
X user CryptoBusy revealed that whales (investors holding over 1 million LINK tokens each) have increased their exposure recently. As explained by the analyst, this move aligns with the latest real-world asset developments surrounding Chainlink and is a pattern historically linked to regime shifts.
Such accumulation is typically viewed as bullish for the price because it signals strong conviction from the big holders, which can encourage smaller players to follow their lead. It is important to note that whales are known as experienced, better-informed investors, suggesting they may be preparing for upcoming news that could positively impact LINKβs valuation.
The declining amount of tokens stored on exchanges is another factor that may favor the bulls. Earlier this week, LINK saw its largest daily net outflow since December of 2025. When investors move their holdings into self-custody, those tokens are less likely to be sold quickly. This, in turn, creates conditions that can support a possible price increase.
Visa said its settlement pilot for stablecoins now supports nine blockchains and has reached a run rate of $7 billion a year.
The company announced on April 29 that it added Arc, Base, Canton, Polygon and Tempo to a pilot that already used Avalanche, Ethereum, Solana and Stellar.
Visa said the annualized settlement run rate is up 50% from the prior quarter.
The pilot remains bounded by Visa’s own language, but the signal is in where the volume sits. Stablecoins are entering the part of payments consumers rarely see, the settlement layer that moves value between issuers, acquirers, banks, program managers and treasury systems after a transaction has already been authorized.
That makes the update a settlement-infrastructure signal as much as a blockchain support list. Visa is testing whether stablecoins can become a parallel settlement option inside payment infrastructure that already touches banks, card programs and merchants across markets.
The operational point is direct: crypto adoption is moving into the back office before it becomes visible at the checkout screen.
The conclusion has limits. The company described a pilot and support, gave a run rate for stablecoin settlement, and left the split by chain, stablecoin, partner, and geography undisclosed.
That keeps things bounded: the network is adding optional settlement rails, while traditional settlement remains part of the stack.
Visa has been building toward this point for several years. In 2023, the company said it had moved millions of USDC between partners over Solana and Ethereum to settle fiat-denominated VisaNet payments.
That announcement followed an earlier Crypto.com issuer pilot and expanded the settlement work to merchant acquirers Worldpay and Nuvei.
The operational issue is familiar in card payments. A consumer gets near-instant authorization at the point of sale, but funds still have to move between the issuing bank and the merchant’s bank.
Visa’s treasury and settlement systems sit inside that process, moving value across currencies and institutions.
In December 2025, U.S. issuer and acquirer partners gained the ability to settle with Visa in USDC, with Cross River Bank and Lead Bank initially settling over Solana.
The company cited faster funds movement, seven-day availability, and resilience across weekends and holidays.
The April release also connected the chain expansion to Visa’s stablecoin-linked card programs, which it said numbered more than 130 programs across more than 50 countries.
That makes the nine-chain footprint part of a broader payment operating model, beyond a ledger experiment.
The new run rate gives that timeline a sharper shape. The December 2025 U.S. launch put the prior annualized stablecoin settlement baseline above $3.5 billion.
The April update puts the run rate at $7 billion, with five more blockchains added to the pilot.
Before the April update
Added in April
Operational signal
Avalanche, Ethereum, Solana, Stellar
Arc, Base, Canton, Polygon, Tempo
Visa is widening the settlement pilot across public chains, payment-focused networks and institution-oriented infrastructure.
The table serves as a footprint rather than a volume map. The run rate applies to the pilot as a whole; the available disclosure leaves that volume undivided across the nine supported networks.
The sequence also shows a shift in who the product is for. The early work proved that USDC could move between card ecosystem participants.
The current phase asks whether the same settlement logic can be offered across a wider menu of rails while reducing the need for each partner to build separate crypto operations from scratch.
What the chain mix shows
The five additions suggest the types of environments Visa wants available to partners.
Arc is a stablecoin-native Layer 1 created by Circle. It brings USDC-denominated fees, optional privacy, sub-second deterministic finality and direct integration with Circle’s stack.
That makes Arc relevant to payment flows where predictable costs, stablecoin liquidity and transfer guarantees count more than token speculation.
Arc’s public materials also describe public testnet status, which keeps production claims bounded.
Base brings a different route into the same problem. Visa described Base as powered by Coinbase, while Base offers USDC payments that settle in seconds, use low gas costs and can be funded from a Base Account or Coinbase Account.
Base connects wallets, payment tooling, and exchange-linked liquidity into a consumer and developer surface.
Canton adds the institutional privacy layer. Visa had already said in March that it would become a Canton Super Validator, helping banks and financial institutions explore privacy-preserving payments, settlement and treasury use cases.
Canton centers stablecoin payments on need-to-know privacy, so counterparties, amounts and strategies can remain visible only to the parties that need them, unlike many open blockchains.
As an analytical reading of the chain mix, Polygon and Tempo fit the payment-infrastructure side of the roster. Polygon emphasizes global payments, stablecoin liquidity and lower-cost transactions.
Tempo emphasizes dedicated payment lanes, stablecoin-native gas, payment metadata for reconciliation and deterministic settlement.
Together, the additions create a wider operating menu across chain types. One partner may need low-cost stablecoin movement.
Another may need privacy controls for regulated finance. Another may value Coinbase-connected payment tooling.
Visa’s role is to make those differences usable through a common settlement layer.
The result is a portfolio of settlement options across chain types. That portfolio lets Visa present stablecoins as infrastructure that can adapt to partner constraints, from regulated privacy to low-cost throughput, while keeping the payment-network relationship in the center.
The adoption signal is operational
The broader market context supports the shift while keeping price moves out of the frame.Β As of April 30, the crypto market stood at aroundΒ $2.55 trillion, while DefiLlama put total stablecoin market capitalization at aroundΒ $319.802 billion.
USDC sits in that context as a core settlement asset used for payments, treasury management, collateral, and cross-chain liquidity.
Ethereum, Solana, and Polygon Ecosystem TokenΒ are large or payment-relevant networks and tokens that can carry settlement infrastructure while keeping price data in the background.
Stablecoins already have enough liquidity and operating history for large payment networks to treat them as infrastructure options.
The adoption test shifts from whether a consumer chooses a wallet over a card to whether payment firms can use stablecoins to move value after the customer-facing transaction is done.
The market-side thesis has been building. A January analysis of BlackRock’s stablecoin thesis argued that dollar tokens were shifting from trading utility to settlement infrastructure within and alongside traditional finance.
Visa’s update provides a current operating example for that thesis. The company is connecting stablecoin settlement to issuers, acquirers, U.S. banks, and stablecoin-linked card programs.
Its March expansion with Bridge said stablecoin-linked Visa cards were live in 18 countries, with planned expansion to more than 100 countries.
That release also said issuers and acquirers involved in those programs could settle with Visa using stablecoins over supported networks.
Regulation sits in the background. Treasury framed the U.S. GENIUS Act as providing regulatory clarity for a market it expects could become much larger.
Visa tied the expansion to pilots, banks, partners, and supported networks, while the policy debate helps explain why payment stablecoins are drawing more mainstream attention.
The $7 billion run rate shows real activity, while the lack of a chain-by-chain breakdown leaves the depth of each rail unclear.
The nine-chain footprint shows optionality, while the pilot label keeps the conclusion bounded.
The adoption signal is therefore specific. Stablecoins are taking on a role beyond trading-market distribution.
Within Visa’s settlement pilot, they are becoming a treasury and settlement option for institutions already within mainstream payments.
The next test is whether that option remains a specialist rail for selected partners or becomes a routine part of how global payment firms move value after the consumer never sees the transaction again.
Bitcoinβs recent rejection near key resistance has raised fresh concerns about the strength of its ongoing rally. After a steady climb, signs of selling pressure are beginning to emerge, hinting that bullish momentum may be weakening. With price now hovering around critical support zones, the next move could determine whether the uptrend regains traction or starts to lose steam.Β
2β618 Pattern Triggers: BTC Rejected At $78,000
In a market update, analyst Kamile Uray revealed that the long-anticipated 2-618 pattern for Bitcoin has officially activated. After the price approached the $78,037 mark, significant selling pressure stalled the upward momentum. This reaction at the local peak confirms that the market is currently responding to technical overhead, initiating a corrective phase.
The immediate outlook suggests the current decline could extend down to the $73,762 level, which serves as a critical decision point for the asset. If Bitcoin manages to hold this floor, the possibility of a renewed bullish push remains on the table.Β
Should the price slip below the $73,762 bottom, the next major target is $70,165, which aligns with the 0.618 Fibonacci support of the most recent upward wave. A successful defense of this area would likely spark another upward move. Conversely, if bulls want to reclaim full control, they must achieve a close above $79,555. Such a move would establish the first higher high on the 4-hour chart relative to the recent downturn, signaling a continuation of the macro uptrend toward the $98,000 and $107,000β$109,000 range.
In the event of a more severe retracement, secondary supports are identified at $65,666, $63,823, $62,433, and $60,000. The stakes are particularly high at this lower limit; a daily close below $60,000 would be a highly bearish signal, potentially marking the beginning of a more substantial market decline.
Key Levels In Focus: Mapping Bitcoinβs Critical Zones
Highlighting the key levels marked on the chart, Daan Crypto Trades emphasized that the low $80,000 region remains a pivotal zone for bulls in the short to mid-term. He also noted that the $72,000 level, which previously acted as resistance for over two months, has now flipped into a critical support zone.Β
Maintaining price above this level would reinforce bullish control and suggest that the market is building a solid base for further upside, providing the foundation needed for another leg higher. A breakdown below $72,000, however, would likely indicate that the momentum from the recent bounce is fading, opening the door for more sideways market structure. Although Bitcoin has posted a steady 20% gain throughout April, the price action may not last long, as volatility is expected to emerge at any point.
This month, Israel and Pakistan supplied a quieter test for crypto than the one playing out in US capital markets. What if the more important 2026 shift is happening where digital assets meet local money and bank accounts?
Israeli crypto firm Bits of Gold said Israel’s Capital Market Authority approved the issuance and distribution of BILS, a shekel-pegged stablecoin, after a two-year pilot. Days earlier, the State Bank of Pakistan issued BPRD Circular Letter No. 10 of 2026, replacing its 2018 virtual-currency prohibition.
The Pakistan circular allows regulated entities to open bank accounts for PVARA NOC or licensed VASPs and their customers under defined compliance conditions.
Those two moves sit far from the US spot ETF cycle. Yet they point to the operational layer that decides whether crypto becomes more than an investment wrapper. The US has supplied legitimacy, liquidity, and a powerful digital-dollar debate.
Other jurisdictions are testing a different operating layer: whether crypto can connect to local money, bank accounts, merchant checkout, and enforceable market rules.
That distinction changes how global adoption should be evaluated. A Bitcoin ETF lets investors buy exposure. A regulated shekel stablecoin lets users hold a domestic currency on-chain.
A central bank circular that lets licensed crypto firms open accounts gives the sector a bridge back into supervised banking. The first validates an asset class. The second and third test whether crypto can become usable financial infrastructure.
The test remains early. BILS still needs proof of issuance and usage. Pakistan still needs licensed VASPs with actual bank relationships. Hong Kong’s new licensees still need business launches.
The UAE still needs clearer public mapping between dirham-token announcements and Central Bank register entries. Still, the pattern is becoming harder to dismiss: in 2026, the practical crypto work is increasingly about where digital assets touch money, banks, merchants, and settlement systems.
Local money and bank access
Bits of Gold says the approved BILS project is a shekel-pegged stablecoin designed initially on Solana, with Fireblocks, QEDIT, EY, and the Solana Foundation involved in the pilot.
The policy signal is the local-currency component. BILS brings the shekel into an on-chain market still dominated by dollar stablecoins and asks whether a national currency can gain a programmable version without ceding the entire payments layer to USD tokens.
That is the monetary-sovereignty angle. Dollar stablecoins have become the working unit of much of crypto’s settlement activity.
A shekel token, if issuance and adoption follow approval, gives Israel a way to test domestic-currency rails inside that same infrastructure. The result would be measured less by market attention and more by whether wallets, exchanges, payment firms, and regulated counterparties find a reason to use it.
Pakistan supplies the banking half of the opening. The State Bank of Pakistan circular is concrete because it replaces FE Circular No. 3 of 2018 and permits SBP-regulated entities to open accounts for PVARA NOC or licensed VASPs and their customers.
The circular also ties access to bank controls, documentation, monitoring, customer-risk checks, and compliance with Pakistan’s virtual-asset framework.
That changes the operating surface for licensed crypto firms. Bank accounts are basic financial plumbing. They determine whether a regulated VASP can hold client money, reconcile flows, satisfy due diligence, and bring activity into monitored channels.
The HKMA register lists both with effective dates of April 10, 2026. That moves the jurisdiction from policy design to named licensed issuers, while leaving the business-launch and user-adoption tests ahead.
The early map is straightforward:
Jurisdiction
2026 signal
Rail being tested
Open test
Israel
Bits of Gold approval statement
Local-currency stablecoin
Issuance, redemption, and user uptake
Pakistan
SBP Circular Letter No. 10
Bank accounts for licensed VASPs
PVARA licensing and bank controls
Hong Kong
HKMA stablecoin issuer licenses
Named licensed issuers
Launches and market use
Japan, UK, EU
Rulemaking and implementation clocks
Market conduct and authorization
How rules behave under stress
UAE, South Korea
Payment-token and merchant-payment activity
Settlement and checkout rails
Scope, transaction flow, and adoption
Rulebooks are becoming operating layers
The same movement shows up in conduct rules. Japan’s Financial Services Agency has published materials pointing toward a shift from Payment Services Act treatment to Financial Instruments and Exchange Act-style oversight for crypto-assets.
The working-group report recommends information provision, crypto-asset service-provider controls, market-abuse rules, insider-trading rules, SESC powers, and stronger user protection. The FSA’s weekly review also notes draft Acts submitted to the Diet tied to FIEA and PSA amendments.
Japan’s signal is about classification and conduct. Crypto assets are being pulled toward a framework where disclosure, surveillance, and misconduct rules shape participation. That makes access conditional on behavior, supervision, and accountability.
It also shows why regulatory design can be a form of infrastructure. Markets use law as a routing layer when participants need to know who can list assets, who can custody them, who can market them, and which forms of trading behavior create liability.
The UK is building a similar operating layer with a longer runway. The FCA says firms that want to carry on new regulated cryptoasset activities can apply from Sept. 30, 2026 to Feb. 28, 2027.
The new regime is expected to come into force on Oct. 25, 2027. A related consultation notice shows the regulator moving through authorization, supervision, consumer-duty, custody, prudential, and market-abuse work.
Europe already has the broader framework in place. ESMA says MiCA establishes uniform rules for crypto-assets covering transparency, disclosure, authorization, supervision, consumer information, market integrity, and financial stability.
A broader global regulatory map has already shown regulation moving as a multi-market process. The 2026 layer adds a sharper point: rulebooks are starting to decide how crypto products enter ordinary financial channels.
The UAE adds a payment-token example, but scope remains the constraint. The Central Bank’s Payment Token Services Regulation provides the rulebook for payment-token activity, while a February CBUAE register provides a public check on licensed entities.
Separately, an ADX-hosted release says IHC, Sirius, and FAB received CBUAE approval to launch the dirham-backed DDSC on ADI Chain for institutional payments, settlement, treasury, and trade flows.
For now, the evidence points to a regulated payment-token framework and institutional settlement ambition; broad retail usage would need separate evidence.
South Korea adds a merchant layer. Crypto.com and KG Inicis said in March that they would integrate Crypto.com Pay across KG Inicis’s merchant network for foreign travelers and K-commerce users, with merchants able to receive fiat or digital assets.
South Korea’s K Bank partnership with Ripple points to another rail where bank and payments activity intersects with crypto. Both examples still need transaction data.
Their relevance is that they move the adoption debate toward checkout, settlement, remittance, and consumer-facing access.
The US-centered interpretation remains powerful because the numbers are large. On April 29, total crypto market capitalization stood near $2.59 trillion, with Bitcoin around $1.56 trillion.
Dollar stablecoins still dominate the working liquidity layer, with Tetherβs 24-hour volume near $111.50 billion and USDC near $47.84 billion.
Those figures explain why US policy and dollar rails keep pulling attention. The dollar stablecoin system is already large. US capital markets supply legitimacy at scale.
The CLARITY Act stablecoin fight shows that the US debate is also about who captures the economics of digital dollars. That benchmark remains essential, because global crypto infrastructure still depends heavily on dollar liquidity.
Usage data complicates that benchmark. Chainalysis said adjusted stablecoin economic volume reached $28 trillion in 2025, with a baseline projection of $719 trillion by 2035 and a catalyst scenario approaching $1.5 quadrillion.
As projections, those figures are scenario math rather than proof of future payment flows. Their direction changes the operating question: stablecoins are being evaluated as payments infrastructure, treasury infrastructure, and settlement infrastructure, alongside their role as trading collateral.
The Chainalysis adoption work shows why emerging markets sit near the center of that debate. It ranked India first, followed by the US, Pakistan, Vietnam, and Brazil, and described adoption as broad-based across income brackets.
It also tied durable adoption to on-ramps, regulatory clarity, and financial and digital infrastructure. Those are the variables being tested by Pakistan’s banking circular and by local-currency stablecoin efforts such as BILS.
The IMF adds the risk side. Its March paper on stablecoin inflows and FX spillovers finds that stablecoin flows can affect parity deviations, local currency depreciation, dollar premia, and financial stability.
Put simply, stablecoins become more consequential once they start behaving like a segment of the FX market.
That creates the live policy tension. Local-currency stablecoins can help keep domestic units relevant in on-chain finance. Banking access can pull VASPs into monitored channels.
Payment integrations can move crypto from portfolio exposure to checkout and settlement. Each rail also creates new supervisory demands around reserves, redemption, money laundering controls, market abuse, and currency pressure.
The evidence points to a specific split. US ETFs and Wall Street adoption have helped financialize crypto by improving access to exposure. The harder adoption test is happening where regulators decide whether crypto can touch local money, bank accounts, merchants, and FX markets.
That test is still early. BILS needs issuance and usage. Pakistan needs licensed VASPs operating through bank accounts. Hong Kong’s new licensees need launches. Japan, the UK, and the EU need rules that work under market stress.
The UAE needs clean issuer and register mapping. South Korea needs merchant activity beyond announcements.
If those signals appear, the global crypto map will look less like a US-led investment-product cycle and more like a set of regional financial systems absorbing crypto under local rules. If they fail to appear, the dollar and US capital markets will keep doing most of the work.
The next test is usage, measured against attention.