Hey,
This week someone stole $387.5M without cracking a single key.
And the one regulator pushing ZK is leaving next week.
🫠
Lets’s get into it.
📊 The tape, quickly
$BTC ( ▲ 0.32% ) touched $86,355 on Monday, highest since January, then slipped back under the ~$86K average ETF cost basis by Wednesday.
Spot BTC ETFs still took in ~$2.4B net Sept 21-25.
🛡️ SEC: Stop building the haystack
Last Wednesday, SEC Commissioner Hester Peirce told SIFMA's digital assets conference that KYC has it backwards.
"We build ever bigger data haystacks on the theory that we will find a needle or two inside."
Every exchange, broker and app collects your passport, address and selfie, and keeps it.
⚠ She warned those databases become targets: hacks, phishing, even physical attacks.
Her alternative: zero-knowledge proofs. 🫡
You prove the one thing that matters:
not sanctioned
over 18
accredited investor
...without handing over the data behind it. 👌
This isn't just a speech. The SEC's Crypto Task Force already sat down with Aztec about ZKPassport in July.
And the physical part isn't hypothetical.
Chainalysis counted 46 wrench attacks in the first half of 2026. France leads, fed by leaked datasets, including a crypto tax app breach (~50,000 users) and a tax official selling files on crypto holders.

Here's what bugs me:
This industry spends fortunes protecting private keys. MPC, HSMs, multi-party approvals.
Then it keeps a tidy file with every customer's name, home address and balance.
That's a map to the keys. And the keys walk around on two legs.
KYC doesn't stop criminals. It hands them a shopping list.
👉 The safest data is the data you never collected.
The catch: the speech changes no rules, and Peirce leaves the SEC on Oct 2.
The idea needs a new owner. ⚠️
🏴☠️ Bitget lost $387.5M. Nobody cracked a key.
Thursday, Bitget's hot wallets sent ~$387.5M to attackers. Suspected North Korea, the TraderTraitor group.
How: the attacker got into a backend system, spoofed transaction data, and let Bitget's own approval process sign the withdrawals.
The biggest DPRK-linked theft of 2026. It pushes their year past $1B.
Bitget says its $464M protection fund covers users. Withdrawals restart in phases today.
It was one of five breaches this week. 🤦

The keys held.
The system that tells the keys what to sign didn't.
A hot wallet and a KYC database are the same thing: a big pile in one place, guarded by a process.
Processes get fooled.
North Korea doesn't need a new trick. It just needs one more pile.
🤖 The next attacker doesn't sleep
Research lab Transluce published 30,000+ logs of OpenAI agents hacking where nobody sent them.
Targets since at least March: Australia's Medicare portal, Hugging Face, Data USA.
Sept 19-20: agents probed Quidax, a Nigerian crypto exchange. Blocked.

Attackers used to have working hours.
Now they're swarms probing every API, all night.
Every database of passports gets scanned on a loop.
Less data isn't a privacy argument anymore. It's a security one.
⚡ Quick hits
🏦 The Fed wrote the rules for bank stablecoins.
"Bank stablecoins" = dollar tokens issued by a regulated bank's own subsidiary, instead of Circle or Tether. GENIUS allows it.
The proposal:
Full reserves at all times
Redemption within two business days
Capital starting at 2% of the first $20B
120-day approval clock.
No sneaking yield through affiliates or partners either. That's presumed to break GENIUS's interest ban.
Translation: banks can issue a stablecoin. They just can't let it compete with their own savings account. 🤌
The takeaway 🫡
Dissecting the week:
$387.5M left Bitget by fooling a process, not a key.
AI agents were probing a crypto exchange last week.
A regulator said: Stop hoarding the data. (But she will leave in October).
Every pile gets found.
🟥 So stop building piles.
See you next week. 🫶
— Juan