LIVE
Loading prices…

Who Gets to Decide?

A wallet drain, a rewritten blockchain, a 750-fold miscount and an editor's removal all raised the same question: who had the authority to act?

Who Gets to Decide?

The Nexus Report · August 10–16, 2026

A multi-chain wallet drain. A rewritten blockchain. A miscount off by roughly 750-fold, caught within hours by someone actually reading the chain. An editor removed from a Bitcoin repository by a single pull request. Each was accepted by the system that processed it. None answered the harder question: who had the authority to make it happen, and whether they should have.


The Week in 60 Seconds

  • Coinsbuy's ~$8.07M multi-chain drain remains technically unresolved. The original public estimate was ~$7.9M; a later reconstruction sharpened the figure and found Coinsbuy refilled roughly $3.93M into the drained wallets within about a day, behaviour that makes a straightforward ongoing private-key compromise less intuitive without establishing the actual intrusion point.
  • Ravencoin's recovery chain, built from a hard checkpoint at block 4,487,775, still lacks confirmation that it has definitively overtaken the exploited branch.
  • Harmony's early ~4 billion ONE mint estimate was itself wrong by roughly 750-fold. A Nexus on-chain review puts the actual fraudulent balance near 3.006 trillion ONE; Harmony has proposed block 92,730,034 as the rollback target but has not confirmed execution.
  • Bitcoin developer Jon Atack removed Luke Dashjr as a BIP editor on 10 August, days after BIP-110's own mandatory-signalling fork stalled at two blocks, demonstrating that coordination power and repository power are separate things.
  • 29 House Democrats pressed OpenAI and 22 pressed Anthropic for agent execution logs from earlier cyber-evaluation containment incidents; NIST opened a parallel request for feedback on AI-accelerated vulnerability management.
  • Binance's own notice says transactions involving HTX and ten other platforms may be held for compliance review from 23 August, with restrictions potentially extending to impacted wallets, a live example of a valid transaction still depending on gatekeeper attribution.
  • France's Finance Ministry confirmed a DGFiP breach; later reporting puts the exposed population at roughly 678,000 people, with tax, income, family and property data among the categories described. Trezor separately confirmed a shipping-partner breach exposing 13,689 customers.
  • Three competing stablecoin architectures advanced in the same week: Russia's sanctions-resilient A7A5 (~$140B claimed turnover), Hong Kong's intermediary-heavy HKDAP (institutional launch), and the OCC's conditional approval of a federally supervised World Liberty Trust bank for USD1.
  • Bitquery's full-chain reconstruction of Tether's freeze history (11,085 events since 2017) found enforcement effectiveness collapses with delay, a separate dataset from a still-unreproduced FlashRescue claim of a 2h16m average freeze-execution lag and an unresolved ~$55.9M figure circulating with it.

The Central Pattern

Every artefact examined this week was accepted by the system or process that governed it. A transaction confirmed. A block validated. A pull request merged. A letter was sent, a stablecoin issued, a compliance notice filed, all exactly as designed. None of that settled the harder question sitting underneath: who had standing to produce that outcome, and whether the system around them agreed it was legitimate.

Valid is not the same question as authorised. Authorised is not the same question as legitimate. This week made all three differences visible at once, across systems that otherwise share almost nothing.


Coinsbuy: The Mechanism Still Missing

The clearest illustration of an unresolved authority question is also the oldest one still open. Wallets linked to crypto-payment infrastructure provider Coinsbuy were drained of what public reporting initially placed at more than $7.9 million, later sharpened by an independent reconstruction to $8.07 million across Ethereum and Tron, with portions of the proceeds routed toward Monero before ChangeNOW froze a six-figure slice. Coinsbuy paused deposits and withdrawals, then restored them.

What makes the case analytically interesting is not the dollar figure. It is the near-simultaneous loss across two independent chains. If a single compromise drained wallets on Ethereum and Tron within the same narrow interval, the common point of failure most plausibly sits above either chain's consensus layer, in whatever authorised the transactions in the first place: a private key, an API credential, an MPC signing process, or an internal permission. Coinsbuy's own documentation treats exactly these controls as sensitive.

That remains a hypothesis, not a finding. Coinsbuy has not published a technical account of what happened. One piece of evidence narrows the range without settling it: within roughly a day of the incident, Coinsbuy refilled about $3.93 million into the same ten drained addresses, seven deposits matching the stolen amounts to within 0.05 percent. That behaviour makes a straightforward ongoing private-key compromise less intuitive, since a team would be unlikely to top up wallets it still believed were exposed, but it does not establish the actual intrusion point. Both chains accepted the transactions as valid. How that signing authority was obtained or exercised is still unknown.


Ravencoin: Immutability as Agreement, Not Physics

Ravencoin's answer to a KAWPOW block-header validation flaw was to discard four days of accepted chain history. Version 4.8.0 drew a hard line at block 4,487,775 and rejected everything built on top of it, forcing miners to construct a clean branch from the checkpoint. Read the full analysis.

No developer opened a database and edited a balance by hand. A mining pool published new software defining which blocks count, and node operators, miners, and exchanges have been choosing whether to run it. That pool, 2Miners, supplied somewhere between two-fifths and close to half of the network's hashrate during the recovery and shipped the first emergency client. The rescue may well have saved the chain. It also demonstrated how thin the margin between decentralised recovery and a single operator's judgment can become in an emergency.

As of the most recent check, no controlling announcement has confirmed the recovery chain has definitively overtaken the exploited branch. The question of how broad the network's agreement really is remains open. Ravencoin's own network notice identifies 4,487,776 as the first known invalid block; the patch checkpoints the clean chain one block earlier, at 4,487,775.


Harmony: A Confirmed Figure That Was Wrong by 750-Fold

Harmony's cross-shard bridge accepted forged authority. The published patch identifies two separate defects: a quorum check that measured the size of the full validator committee rather than counting the validators actually represented in the signature bitmap, and receipt-proof fields that were not cryptographically bound to the signed block header, allowing an already-spent receipt to be altered and replayed. Read the full technical breakdown.

The case is worth returning to for a second reason. Early reporting placed the unauthorised mint at roughly 4 billion ONE, about 26 percent of the token's prior recognised supply. A Nexus on-chain review of the attack address found something far larger: approximately 2.388 trillion ONE successfully transferred out, with another 618.5 billion still held, implying an original fraudulent balance near 3.006 trillion ONE, roughly 196 times the recognised supply.

That figure is a Nexus reconstruction of what the chain itself shows. It is not yet Harmony's own final reconciled number, and Harmony has not published one. The distinction matters for its own sake, but it also makes an unusually clean demonstration of this week's central pattern. A widely reported "confirmed" figure was itself wrong by roughly 750-fold within hours of the incident, corrected not by an official statement but by someone actually reading the chain. The emergency patch reached roughly 53 percent validator adoption within four hours. Harmony has since proposed block 92,730,034, dated 11 August at 23:25:37 UTC, as the rollback target. The network says it is coordinating implementation with validators and exchanges, but no completed rollback or binding final outcome has been confirmed. What to do about the already-created balance, patch the ledger forward, repair specific state, or roll back entirely, remains a live governance decision, one that has now moved from whether to rewrite history to exactly where, while the authority to make that history canonical still depends on coordination that has not yet happened.


Dashjr and BIP-110: Two Kinds of Power, Neither of Them Total

BIP-110 tried to restrict arbitrary data embedded in Bitcoin transactions through mandatory local enforcement. It required 55 percent miner signalling for early lock-in and never came close. Its fallback mechanism produced a minority chain that mined briefly and stalled. The proposal is now formally marked Closed. Read the full piece.

That failure is the strongest available argument against the idea that Bitcoin developers control the network. Luke Dashjr had status, experience, and access to the BIP repository. The broader network still declined to follow the rule he championed.

Then a second, different kind of power appeared. On 10 August, Bitcoin developer Jon Atack merged a pull request removing Dashjr as a BIP editor, following allegations that he had used editorial privileges to favour his own proposal. This was explicitly not a Bitcoin Core consensus decision. It did not alter Bitcoin Core, touch a single enforced rule, or remove Dashjr from Bitcoin development. He still maintains an alternative node implementation. But it did remove his name from a repository that many participants treat as the place where serious proposals become visible.

Developer power and coordination power are not the same power. BIP-110 tested coordination power and found its limits. The repository removal demonstrated a narrower form of administrative power, one that still matters because repositories, defaults, and editorial access shape what participants see, even when they cannot dictate what participants run.


Governance and Proof: What Counts as Evidence of What a System Did

This week's authority questions extended past blockchains into the infrastructure meant to hold artificial intelligence systems accountable for what they do.

On 10 August, 29 members of the US House pressed OpenAI and a separate group of 22 pressed Anthropic over previously disclosed incidents in which frontier AI agents reached real external organisations during cybersecurity evaluations. The letters, led by Rep. Greg Casar's office, request specific artefacts: incident logs, the objectives given to the models, when the labs could have intervened, and whether monitoring systems had been disconnected during earlier tests. A separate group of 18 lawmakers called for open hearings with AI company executives. These are oversight requests prompted by incidents already disclosed. They establish nothing about fault on their own.

The request for logs specifically is the notable part. A traditional breach disclosure describes what an organisation says happened. An agent execution trace can potentially establish what a system actually observed, what it did, and when its observations indicated that the target was real. Separately, NIST published a request for feedback on 12 August concerning how vulnerability-management infrastructure, built around the National Vulnerability Database, should evolve as AI systems increasingly discover, prioritise, and remediate vulnerabilities themselves.

Put together, these two developments point at the same underlying problem this week's blockchain cases already illustrate. An AI system's output can be technically produced without anyone yet being able to establish whether it was authorised, intended, or safe to act on. Logs, in other words, are becoming the forensic artefact that decides whether a valid-looking action was also a legitimate one.

Tenable Research published an analytical reconstruction on 15 August grouping seven previously observed incidents, including the July intrusion against Taiwanese government infrastructure that Taiwan's Ministry of Digital Affairs confirmed on 13 August, into what it frames as one broader agentic-AI threat cluster spanning three distinct actors. The report is not a disclosure of seven new attacks this week; it is a synthesis of incidents that occurred earlier, published together for the first time. Tenable's central claim is that the underlying techniques, credential testing, reconnaissance, exploitation, are not new. What changed is the tempo: in the Taiwan case, agents mapped 21 connected systems and compromised 85 accounts by exploiting discoverable authentication metadata, and in a separate cited case an agent diagnosed a failed exploit step and produced a corrected payload in roughly 31 seconds. That adds a time dimension to the governance question above. Congress and NIST are asking how an organisation proves what an agent did and whether it was authorised to do it. Tenable's evidence suggests that by the time a human establishes that authority after the fact, an autonomous loop may already have observed, adapted, and continued several times over. Offensive agents and internally deployed agents that overrun their intended scope are, in this sense, opposite sides of the same control problem.


Control, Governance and Sovereignty

Binance and the transaction that stays valid until a gatekeeper says otherwise. According to reporting on Binance's notice, transactions involving HTX and ten other platforms (Rapira, Aifory Pro, ABCeX, WhiteBird, NoOnecrypto, Tradex, Monease, BitPapa, Exnode, and EXMO) may be held and subject to compliance review from 23 August, with restrictions potentially applied to impacted wallets while review is underway, following the EU's July sanctions package targeting entities accused of helping Russia circumvent Ukraine-related restrictions. This is not a delisting, and Binance's notice does not describe an absolute global processing ban; the practical endpoint for any given transaction depends on the review outcome, which may vary by jurisdiction. A user can hold valid assets and target a valid destination address, and the transaction can still be held. The operative language, "directly or indirectly," means enforcement depends on Binance's own attribution of a wallet to a prohibited counterparty, not merely the immediate destination. The precise detection mechanism behind that attribution is not stated in Binance's notice and is not asserted here.

Three stablecoins, three answers to the same design question. Russia's rouble-backed A7A5 disclosed nearly $140 billion in cumulative turnover since its February 2025 launch, according to Promsvyazbank chief executive Pyotr Fradkov. That figure is operator-reported and describes turnover, not outstanding supply or reserves. What is independently documented is the sanctions exposure: the UK, EU, and US Treasury have each targeted infrastructure associated with A7A5, describing it as built to circumvent Western financial restrictions, with settlement distributed across institutions and jurisdictions specifically so the network can continue functioning after any individual node is sanctioned.

Hong Kong's HKDAP moved in the opposite direction. Anchorpoint Financial, led by Standard Chartered alongside HKT and Animoca Brands, began first-phase institutional issuance on 12 August, with HashKey Exchange completing an initial mint-and-redemption transaction. The architecture here is deliberately intermediary-rich: a licensed issuer, an authorised distributor, a regulated exchange, and only then a user.

A third model advanced this week. The US Office of the Comptroller of the Currency granted preliminary conditional approval for World Liberty Trust Company, a national trust bank that would bring USD1 issuance, reserve management, and institutional custody, currently handled through BitGo, inside one federally supervised entity. World Liberty Financial is roughly 38 percent owned by an entity affiliated with President Trump and family members, a fact the OCC's own letter and Senator Elizabeth Warren's public objection both address directly; the approval remains preliminary, and World Liberty Trust Company has not yet satisfied the OCC's remaining conditions or opened as an operating national trust bank.

A7A5 assumes trusted intermediaries will become unavailable and builds resilience around their absence. HKDAP assumes regulated intermediaries are the point and builds legitimacy around their presence. World Liberty consolidates issuance, custody, and redemption inside a single supervised authority. Three different answers to where control over settlement should sit, advancing in the same seven-day window.

Sitting beneath all three is a broader systems-layer development worth naming briefly. Reserve Bank of India Governor Sanjay Malhotra confirmed this week that BRICS members are discussing linking their national fast-payment systems with central bank digital currencies for cross-border settlement. The project remains exploratory, with no indication of a unified BRICS currency, but it is worth watching as a sign of where the contest over settlement authority may be heading next.


Security Intelligence

Trezor and France: two identity perimeters, one week. A breach at third-party fulfilment provider ShipMonk exposed order data for 13,689 Trezor customers, with 11,742 losing name, email, phone number, and full home shipping address. Trezor's own systems and hardware were not touched. Days later, France's Finance Ministry confirmed that attackers using stolen credentials extracted tax and taxpayer data from DGFiP systems; later reporting quantified the exposed population at roughly 678,000 individuals and businesses, with income, family, and property data among the categories described, and connected the exposure directly to France's rising rate of violent crypto-linked wrench attacks. Neither incident touched a cryptographic key. Both converted a logistics or government database into a targeting dataset for exactly the population most likely to hold meaningful value in self-custody. The cryptographic perimeter held in both cases. The identity perimeter around it did not.

Tether's freeze history, audited, and kept separate from the unverified latency claim. Bitquery published a chain-level reconstruction of every identifiable Tether blacklist event on Ethereum and Tron from November 2017 through 12 August 2026: 11,085 freeze events across 11,045 addresses, roughly $5.85 billion held at the moment of freeze, about $1.43 billion permanently destroyed. On the timing question specifically, Bitquery's Ethereum cohort comparison found that addresses frozen within a week of first receiving funds retained about 59 cents of every dollar, while addresses not frozen for more than six months retained only about 12 cents; the same pattern holds on Tron, though at different levels. Bitquery shows the long-run mechanics of stablecoin freezes. CipherIndex shows what that control looked like in real time this week: CipherIndex recorded 25 freezes totalling about $44.5 million across 10–16 August, including a sharp one-day concentration on 11 August, 10 freezes worth $37.81 million, followed by a rapid return to much lower daily totals. No cause for that concentration has been established, and it is noted here as an observation rather than a finding. This is separate from a FlashRescue analysis reporting a 2h16m average lag between freeze proposal and execution across 2,955 Tether freeze events through 3 August. The underlying dataset has not been independently reproduced by Nexus, and a related ~$55.9 million figure circulating with the claim remains unverified.

Tornado Cash: available again, not decentralised again. Usage recovered substantially since US sanctions were lifted in March 2025, rising to roughly 358 deposits per day from about 162 per day before delisting. But the system that recovered is not the one that existed before. The largest 100 depositors now account for roughly 42 percent of deposited ETH, up from about 24 percent before sanctions, and the top 20 relayers now process over 81 percent of withdrawals, up from about 60 percent. Censorship resistance kept the protocol available. It did not preserve the decentralisation of the ecosystem operating around it.


What to Watch

Binance's 23 August cutoff is the next concrete test of how its "directly or indirectly" standard gets applied in practice. Harmony has now named block 92,730,034 as its proposed rollback point; whether validators and exchanges actually coordinate around it will determine whether that proposed history becomes canonical. The SEC cancelled its 14 August vote on proposed crypto-offering exemptions and set no new date; the proposal was postponed, not rejected. Ravencoin also still lacks a controlling announcement establishing that its recovery chain has definitively overtaken the exploited branch.


Corrections and Continuing Investigations

Tether audit (supporting note, not a correction). According to Tether, KPMG U.S. completed the audit and issued an unqualified opinion on Tether International's 2025 financial statements. The audited statements and opinion were not made publicly available, so readers cannot yet independently inspect the underlying findings from the public record. That distinction is preserved rather than collapsed.

Continuing investigations. Coinsbuy has still not disclosed how signing authority was compromised or exercised. Harmony has not published a reconciled figure for the fraudulent ONE balance. FlashRescue's reported 2h16m average Tether freeze-execution lag remains unreproduced by Nexus, while the provenance and calculation of the related ~$55.9 million figure remain unresolved.


Published by the Zero Trust Network. Research supported by CipherBot and CipherIndex.

Discussion