Kelp DAO Restores rsETH After $293 Million Exploit – Recovery Effort Highlights DeFi Interconnectedness

Key Takeaways

Kelp DAO Completes rsETH Recovery After April Exploit

Kelp DAO has announced the completion of its recovery process for its restaked Ether token, rsETH, following a $293 million exploit that took place on April 18. The attack was attributed to North Korea’s Lazarus Group.

According to Kelp DAO, the final tranche of 20,373.7 rsETH was transferred to the LayerZero smart contract responsible for locking, minting, burning and releasing rsETH during cross chain transfers. The protocol stated that this transfer closes the operational part of its rsETH recovery plan.

The exploit triggered a five week recovery effort. Earlier in the process, on May 13, Kelp DAO transferred an initial tranche of 25,000 rsETH. That move allowed bridging between the Ethereum mainnet and the network’s layer 2 blockchains to reopen. Withdrawals for rsETH resumed the following day.

Kelp DAO reported that since reopening withdrawals, rsETH mints, redemptions and reward operations have been running normally. Several crypto protocols contributed funds under the DeFi United initiative to help restore the token’s backing.

Ripple Effects Across the Crypto Lending Market

The April exploit did not remain isolated to Kelp DAO. It triggered a broader liquidity shock across decentralized finance markets and renewed concerns about the interconnected nature of DeFi protocols.

The attacker stole 116,500 rsETH and used a large portion of those tokens as collateral on the Aave lending platform. By borrowing wrapped Ether against this collateral, the attacker left Aave with $190 million in bad debt. The situation prompted a wave of withdrawals from the platform.

The incident illustrates how vulnerabilities in one protocol can cascade into others when tokens are widely used as collateral across lending markets. In this case, rsETH was integrated into Aave’s lending infrastructure, amplifying the financial impact beyond Kelp DAO itself.

The Kelp DAO exploit was one of 25 crypto hacks recorded in April. Combined losses across those incidents reached $630 million, making it the worst month for crypto related hacks since February 2025. In that earlier month, crypto exchange Bybit suffered a record $1.5 billion hack.

Aave’s Total Value Locked Remains Under Pressure

Aave was among the protocols most affected by the fallout. Before the exploit, Aave’s total value locked stood at $26.4 billion. Following the incident and the associated withdrawals, that figure fell to below $14 billion.

The decline also cost Aave its long held position as the largest DeFi protocol by total value locked. Data from DefiLlama shows that while net outflows from Aave’s lending markets have eased over the past month, the protocol’s total value locked has not recovered.

Since about one week after the exploit, Aave’s TVL has fluctuated within a narrow range between $13.9 billion and $15.1 billion. The stabilization suggests that the initial wave of withdrawals has slowed, but the platform has not regained the capital it held prior to the Kelp DAO incident.

For users who interact with DeFi lending markets, total value locked serves as a key indicator of available liquidity and market confidence. A sustained reduction in TVL can affect borrowing capacity, collateral requirements and overall market dynamics within decentralized lending ecosystems.

Operational Status of rsETH and Cross Chain Transfers

With the final tranche now transferred to the LayerZero smart contract, Kelp DAO states that the operational component of its recovery is complete. The smart contract plays a central role in managing rsETH across different blockchains by handling locking, minting, burning and releasing functions during cross chain transfers.

The reopening of bridging between Ethereum mainnet and layer 2 networks marked a significant milestone in the recovery process. Restoring cross chain functionality is critical for tokens like rsETH that are used across multiple decentralized applications and lending platforms.

Kelp DAO’s confirmation that minting, redemption and reward mechanisms are functioning normally signals a return to standard protocol operations, at least from an operational standpoint. The recovery was supported by contributions from several crypto protocols through the DeFi United initiative, aimed at restoring the token’s backing after the exploit.

Our Assessment

Kelp DAO has completed the operational phase of restoring rsETH five weeks after a $293 million exploit attributed to the Lazarus Group. The incident had significant spillover effects, particularly on Aave, where the use of stolen rsETH as collateral contributed to $190 million in bad debt and a sharp drop in total value locked.

While Kelp DAO reports that rsETH minting, redemptions and rewards are functioning normally again, Aave’s total value locked remains well below pre exploit levels. The episode underscores how security breaches in one DeFi protocol can affect liquidity and stability across interconnected platforms.

Aave Restores WETH Borrowing After Kelp DAO Exploit – Protocol Lifts Freeze as rsETH Recovery Advances

Key Takeaways

Aave Restores WETH Loan to Value Ratios Across Multiple Networks

Aave users can once again borrow against wrapped Ether on the decentralized finance protocol after the project lifted a precautionary freeze introduced in April. According to Aave founder Stani Kulechov, the protocol restored loan to value ratios for wrapped Ether to pre incident levels on Aave V3 Ethereum Core, Ethereum Prime, Arbitrum, Base, Mantle and Linea.

The freeze had been applied to wrapped Ether markets as well as to rsETH and wrsETH reserves following the exploit of Kelp DAO’s infrastructure. In a governance proposal that passed on Saturday, Aave stated that progress in the technical recovery process made it possible to lift the freeze without compromising user protection.

With the restoration of loan to value ratios, users can again borrow against wrapped Ether, including through collateral and debt swaps. The measure marks the completion of what Aave described as Phase II of the rsETH recovery plan.

Background: RsETH Exploit and Impact on Aave

The incident traces back to April 18, when attackers believed to be linked to North Korean state backed actors exploited Kelp DAO’s LayerZero powered bridge. The attackers stole 116,500 Kelp DAO Restaked Ether tokens and used them as collateral on Aave V3 to borrow wrapped Ether.

This sequence resulted in approximately 195 million dollars in bad debt on Aave. In response, Aave implemented temporary freezes on relevant reserves as a risk containment measure.

The financial impact was visible in Aave’s total value locked. According to data cited from DefiLlama, the protocol’s TVL dropped by more than 8 billion dollars following the exploit. As of Monday, Aave’s TVL stands at about 14.8 billion dollars, compared with 23.5 billion dollars in March.

The incident also affected deposit patterns. Tom Wan, head of data at Entropy Advisors, stated that since the hack, wrapped stETH and wrapped Ether deposits have declined. He quantified the decrease at 1.2 billion dollars for wstETH and 1.76 billion dollars for weETH.

Liquidity Conditions and Borrowing Rates After the Freeze

Following the disruption, liquidity dynamics on Aave changed. Ether utilization has fallen back below 90 percent, according to Tom Wan. At the same time, the annualized borrowing rate has decreased to 1.9 percent.

Lower utilization indicates that a larger share of supplied Ether is currently unused within the protocol. A reduced borrowing rate reflects this increased liquidity. Wan noted that leveraged Ether yield strategies involving wstETH or weETH relative to ETH have become profitable again under current conditions.

For users evaluating lending and borrowing conditions on Aave, the restored loan to value ratios and lower borrowing costs mark a return to more typical market parameters compared with the immediate aftermath of the exploit.

Kelp DAO Adjusts Network Support and Recovery Process

Parallel to Aave’s measures, Kelp DAO is implementing changes to its own infrastructure. On Sunday, the protocol announced that it will consolidate supported networks for rsETH based on usage and integrations.

As part of this process, Kelp DAO will sunset rsETH bridging on several networks after June 15. The affected networks include Optimism, HyperEVM, Unichain, Avalanche and MegaETH.

After the deadline, users seeking to recover funds on those networks will face a fee of 100 USDC per address, according to Kelp DAO.

Earlier in May, Kelp DAO migrated its restaking token rsETH to the Chainlink oracle platform. The protocol has continued to attribute the attack to LayerZero’s cross chain infrastructure, which previously served as its provider.

These steps form part of Kelp DAO’s broader recovery effort following the exploit and are designed to adjust the token’s technical setup and network footprint.

Governance and Risk Controls in Focus

The sequence of events highlights how decentralized protocols respond to security incidents through governance and parameter adjustments. In Aave’s case, the temporary freeze and subsequent restoration of loan to value ratios were executed through formal governance procedures.

The passed proposal emphasized that lifting the freeze would not compromise user protection, reflecting an assessment that recovery progress had reduced systemic risk linked to rsETH collateral.

For users active in decentralized lending markets, such governance decisions directly affect borrowing capacity, collateral eligibility and liquidity conditions across multiple networks.

Our Assessment

Aave has resumed normal wrapped Ether borrowing operations after completing Phase II of its rsETH recovery plan. The restoration of loan to value ratios follows a significant exploit that generated about 195 million dollars in bad debt and reduced the protocol’s total value locked by more than 8 billion dollars. At the same time, Kelp DAO is narrowing its network support and adjusting its technical infrastructure as part of its recovery process. Together, these measures indicate that both protocols are moving from emergency containment toward operational normalization under revised risk parameters.

Blockaid Launches Real-Time Compliance Suite – Institutions Expand Onchain Crypto Operations Under Regulatory Oversight

Key Takeaways

Blockaid Introduces Risk Exposure for Institutional Onchain Activity

Blockchain security firm Blockaid has launched Risk Exposure, a compliance infrastructure suite aimed at institutions that operate directly on public blockchains while remaining subject to regulatory requirements. The product expands the company’s focus beyond scam and exploit prevention into what it describes as programmable, real-time compliance for institutional onchain finance.

According to Blockaid, financial institutions such as banks, asset managers, custodians, and payment processors are no longer limited to occasional crypto exposure. Many now maintain continuous onchain positions, including liquidity pool allocations, stablecoin settlement across multiple chains, and treasury management through decentralized finance protocols. These activities create ongoing exposure that can change rapidly as funds move across wallets, bridges, mixers, and smart contracts.

Blockaid argues that traditional compliance models, which often rely on post-transaction address tagging and reporting, are not designed for an environment where risk profiles can shift within hours without direct action from the institution holding the assets.

Large-Scale Hacks and Exploits Highlight Monitoring Gaps

The company points to recent high-profile incidents to illustrate the scale and speed of risk propagation in crypto markets. Over the past 18 months, more than $1.5 billion linked to North Korean actors moved through the Bybit hack. Additional exploits at Cetus, Balancer, and KelpDAO resulted in combined losses exceeding $600 million.

In these cases, Blockaid states that tainted funds were distributed across multiple wallets, liquidity pools, and counterparties before legacy compliance systems flagged the activity. This pattern reflects how stolen or illicit funds can quickly become embedded in decentralized protocols, potentially affecting counterparties who did not initiate any suspicious transactions themselves.

For institutions that provide custody, settlement, or treasury services involving crypto assets, this dynamic creates regulatory and operational challenges. Exposure can arise not only from direct transfers but also from pooled liquidity or shared smart contract environments.

Three Core Components of the Risk Exposure Suite

Risk Exposure is structured around three main components intended to address these challenges in real time.

The first is a Risk Screening API. This tool evaluates incoming funds before they are accepted and returns structured assessments that include exposure categories, dollar amounts, and severity scores. The output is formatted for audit documentation and Suspicious Activity Report filings.

The second component is a Cosigner Policy Engine. It embeds anti-money laundering thresholds into multisignature workflows. Even if internal approvals have been granted, the system can reject transactions that exceed predefined risk limits.

The third element consists of DeFi Toxicity Monitors. These tools track exposure within protocols, liquidity pools, and counterparty positions throughout the day. Alerts are triggered when exposure to sanctioned entities, stolen crypto funds, scam infrastructure, or mixers surpasses set thresholds.

Blockaid states that its system uses transaction simulation, behavioral analysis, and artificial intelligence-driven threat identification to detect exposure before illicit proceeds enter institutional systems undetected.

Transaction Volume, Clients, and Technical Performance

Blockaid reports that it currently screens more than 500 million transactions per month for clients including Coinbase, MetaMask, Uniswap, Fireblocks, Polymarket, and OKX. According to the company, the infrastructure processes hundreds of transactions per second and delivers verdicts in under 300 milliseconds, with a stated accuracy rate of 99.99 percent.

Founded in 2022, Blockaid has raised $83 million in funding from investors such as Ribbit Capital, Sequoia, and Greylock.

In parallel, the firm highlights the growing impact of AI-driven fraud schemes, including so-called pig butchering scams. It cites findings from the FBI’s Operation Level Up, which reported that approximately 8 in 10 victims do not file complaints. This underreporting, according to Blockaid, limits the effectiveness of compliance systems that depend primarily on law enforcement records to tag suspicious addresses.

Implications for Bitcoin Custody and Institutional Exposure

Blockaid’s launch comes as Bitcoin custody, Bitcoin-backed lending, and Bitcoin treasury strategies become more integrated into institutional balance sheets. As regulated entities increase their direct exposure to digital assets, the compliance infrastructure supporting those positions becomes central to how they manage regulatory obligations.

Real-time monitoring tools may affect how institutions approach liquidity provision, cross-chain settlement, and counterparty risk in decentralized finance. For users of crypto platforms, including those assessing custodial services or onchain financial products, the presence of programmable compliance controls can influence how service providers manage inflows, withdrawals, and pooled exposure.

For platforms connected to betting, gaming, or other high-volume transaction environments, automated screening and policy enforcement can also shape how quickly transactions are processed and how risk thresholds are applied.

Our Assessment

Blockaid has introduced a compliance suite designed to address real-time exposure risks faced by institutions operating directly on public blockchains. The system combines transaction screening, automated policy enforcement, and continuous DeFi monitoring. The launch reflects the scale of recent crypto exploits and the operational shift of regulated financial institutions toward continuous onchain activity. As institutional participation in Bitcoin and decentralized finance expands, compliance infrastructure capable of monitoring exposure in real time becomes part of the broader market framework supporting that activity.

CoW Swap DAO Urges Users to Avoid Platform After Domain Hijacking – Frontend Exploit Prompts Security Warning

Key Takeaways

DAO Issues Public Warning After Domain Hijacking

The decentralized autonomous organization behind CoW Swap has urged users to stay off the platform following what has been described as a domain hijacking. According to reporting on April 14, 2026, the decentralized exchange aggregator advised users to refrain from visiting its website.

The warning was issued after a frontend exploit was identified. As a result, users were specifically told not to access the platform’s web interface. The communication indicates that the incident affects the website layer through which users typically interact with the service.

No additional operational details were disclosed in the source material. The core message from the DAO was clear: users should avoid visiting the CoW Swap website until further notice.

Frontend Exploit Affects Website Access

The reported incident centers on a frontend exploit. In this context, the frontend refers to the web interface that users access through a browser. The DAO’s warning suggests that the issue is linked to this interface rather than to a broader announcement about the protocol’s underlying structure.

By urging users to stay off the platform, the organization signaled that accessing the website could pose risks while the situation remains unresolved. The use of the term domain hijacking indicates that control over the website domain was affected, prompting immediate precautionary measures.

For users, the practical consequence is straightforward: avoid interacting with the CoW Swap website until the DAO communicates that it is safe to return. The advisory applies specifically to visiting the platform’s online interface.

Impact on Users of the Decentralized Exchange Aggregator

CoW Swap operates as a decentralized exchange aggregator. Users typically rely on such platforms to access liquidity and execute trades through a web interface. When that interface is compromised or potentially compromised, direct interaction becomes a risk factor.

The DAO’s public guidance focuses on prevention. By instructing users to stay away from the website, the organization aims to reduce the likelihood of further exposure during the period in which the frontend exploit remains unresolved.

For users who monitor decentralized trading platforms, the key takeaway is operational rather than technical. Access to the platform via its website has been explicitly discouraged. Anyone considering transactions through CoW Swap must take this warning into account and monitor official communications for updates.

Timing and Source of the Report

The development was reported on April 14, 2026. The information originates from coverage by Cointelegraph, which cited the DAO’s warning and referenced the domain hijacking and frontend exploit.

At the time of reporting, no additional technical breakdown or timeline of events was included in the source material. The available facts are limited to the existence of a domain hijacking, the identification of a frontend exploit, and the DAO’s instruction to users to avoid the website.

There were no further details regarding the duration of the advisory or specific remediation steps underway. The central message remains the same: users should not visit the platform’s web interface until the issue is addressed.

Operational Consequences for Platform Access

When a decentralized exchange aggregator advises users to refrain from accessing its website, the immediate operational effect is a pause in normal user activity through that channel. For individuals who rely on the web interface to initiate or manage trades, the warning effectively suspends direct engagement with the platform.

The incident underscores the importance of monitoring official updates when interacting with decentralized services. In this case, the DAO has taken a precautionary stance by issuing a public alert. The measure is framed as a protective step following the identification of a frontend exploit linked to a domain hijacking.

No further claims or assessments about the broader system were included in the reported information. The advisory is limited to website access.

Our Assessment

Based solely on the available information, the DAO behind CoW Swap has identified a domain hijacking and related frontend exploit and responded by urging users to stay off the platform’s website. The immediate significance lies in restricted access to the web interface of the decentralized exchange aggregator. Users are advised to avoid visiting the site until further notice, as communicated on April 14, 2026.

US Treasury Expands Cybersecurity Threat Intelligence to Crypto Firms – Digital Asset Platforms Gain Access to Federal Risk Data

Key Takeaways

Treasury Extends Cybersecurity Program to Digital Asset Companies

The US Department of the Treasury announced that its Office of Cybersecurity and Critical Infrastructure Protection is expanding a federal cybersecurity threat identification program to cover digital asset companies. Until now, the program primarily served traditional financial institutions.

Under the expansion, blockchain companies that choose to participate will receive the same cybersecurity threat intelligence as banks and other established financial entities. According to the Treasury, this information will be provided at no cost to participating firms.

Cory Wilson, deputy assistant secretary for cybersecurity at the Office of Cybersecurity and Critical Infrastructure Protection, stated that cyber threats targeting digital asset platforms are increasing in both frequency and sophistication. The expansion is designed to address those developments by integrating crypto firms more closely into existing federal threat sharing structures.

Policy Background: July 2025 Report on Digital Financial Technology

The initiative implements recommendations outlined in a July 2025 report titled “Strengthening American Leadership in Digital Financial Technology.” The report was issued under US President Donald Trump’s administration and focused on reinforcing the country’s position in digital finance.

By extending federal cybersecurity intelligence support to crypto businesses, the Treasury aligns digital asset infrastructure more closely with the regulatory and security frameworks applied to traditional finance. The announcement reflects a broader recognition that blockchain based platforms now form part of the financial system’s critical infrastructure.

Rising Financial Losses From DeFi Exploits

The decision comes amid continued financial losses from attacks on crypto platforms. According to data cited in the announcement, decentralized finance platform hacks resulted in nearly $169 million in losses during the first quarter of 2026 alone.

Between 2022 and 2025, the sector recorded significant cumulative losses from crypto related hacks. These figures highlight the persistent vulnerability of smart contract based protocols, centralized exchanges, and developer environments to cyber intrusion.

For users of crypto trading, staking, or betting platforms, such incidents can directly affect asset security, platform availability, and operational continuity. While the Treasury program does not mandate participation, it provides an additional source of threat intelligence to companies seeking to strengthen their defenses.

Drift Protocol Exploit Linked to Suspected State Affiliated Hackers

Recent events illustrate the type of threats the expanded program seeks to address. Drift Protocol, a decentralized cryptocurrency exchange, suffered a $280 million exploit in April 2026. According to a preliminary incident report from the company, the attack was carried out by suspected hackers affiliated with North Korea.

The Drift team reported that individuals who initially approached them at a major crypto industry conference were not North Korean nationals. However, the attackers allegedly maintained contact with the team for months following the event.

During that period, crypto stealing malware was deployed on developers’ machines. The malicious software was later activated in connection with the April exploit. The sequence of events demonstrates how social engineering and long term infiltration can precede large scale theft.

The Seals911 group, a team of blockchain cybersecurity specialists, assessed with medium high confidence that the attack was likely carried out by the same group responsible for the October 2024 hack of the Radiant Capital DeFi platform.

State Linked Cyber Threats and Industry Exposure

The Treasury’s announcement also reflects ongoing concerns about foreign intelligence operatives targeting crypto projects. State affiliated groups, including the North Korean linked Lazarus Group, have been associated with multiple high profile crypto attacks in recent years.

These operations often combine technical exploits with social engineering tactics. In the Drift case, direct in person contact at an industry event preceded the deployment of malware. Such methods expand the risk surface beyond code vulnerabilities to include human and operational factors.

For companies operating crypto exchanges, DeFi platforms, or crypto enabled betting services, this environment increases the importance of structured threat intelligence and coordinated response frameworks.

Implications for Digital Asset Platforms and Their Users

By granting crypto firms access to federal threat intelligence resources, the Treasury places digital asset businesses on a similar footing to banks in terms of information sharing. Participation remains voluntary, but the availability of no cost intelligence may lower barriers for smaller firms seeking institutional grade insights.

For users, including those active in crypto trading and online betting, the development signals closer integration of the crypto sector into national cybersecurity infrastructure. While it does not eliminate platform risk, it introduces an additional layer of coordination between public authorities and private operators.

The expansion also underscores the scale of recent losses and the operational sophistication of attackers targeting blockchain based services.

Our Assessment

The US Treasury has formally extended its cybersecurity threat identification program to digital asset companies, granting them access to the same intelligence provided to traditional financial institutions. The move follows policy recommendations from a July 2025 federal report and comes amid nearly $169 million in DeFi related losses in the first quarter of 2026. Recent incidents, including a $280 million exploit at Drift Protocol linked to suspected state affiliated hackers, illustrate the types of threats the initiative aims to address. The expansion integrates crypto platforms more directly into existing federal cybersecurity information sharing structures.

Bitcoin Depot ATM Operator Reports $3.6 Million in BTC Stolen – Corporate Hack Highlights Security Risks

Key Takeaways

Bitcoin Depot ATM Operator Confirms $3.6 Million Bitcoin Loss

A Bitcoin Depot ATM operator has reported that $3.6 million worth of Bitcoin was stolen in what the company described as a corporate hack. The incident was reported on April 8, 2026, and categorized as crypto-related news.

According to the report, the stolen assets were denominated in Bitcoin and amounted to $3.6 million. The company identified the event as a corporate hack, indicating that the breach affected internal systems rather than an isolated external transaction.

No additional operational details were included in the source material. The confirmed figure remains $3.6 million in Bitcoin.

Classification as a Corporate Hack

The company referred to the incident as a corporate hack. This classification distinguishes the event from other types of security issues, such as user-level account compromises or isolated wallet breaches. By labeling the event as corporate, the operator signaled that the breach occurred within its organizational infrastructure.

For readers who use crypto-related financial services, the distinction between individual account hacks and corporate-level breaches is relevant. A corporate hack suggests that internal systems were targeted, rather than a single end-user wallet or transaction.

The source material does not provide further technical details about the method of attack or the systems involved. The confirmed information remains that $3.6 million in Bitcoin was stolen and that the company described the incident as a corporate hack.

Implications for Crypto ATM Operators

The reported loss concerns a Bitcoin Depot ATM operator. Crypto ATM operators provide physical access points for buying or selling digital assets, including Bitcoin. In this case, the operator disclosed a loss linked to a corporate security breach.

For users who rely on crypto ATMs to convert cash into digital assets or vice versa, security practices at the corporate level are a central consideration. While the report does not describe customer impact or operational disruptions, the confirmed theft underscores that operators managing digital assets can be targets of cyber incidents.

The only quantified detail available is the amount reported stolen: $3.6 million in Bitcoin. No additional figures, timelines, or recovery information were included in the source material.

Why the Report Matters for Crypto Platform Users

For international users evaluating crypto-related services, including exchanges, betting platforms, or payment providers, reported security incidents form part of the broader risk landscape. A corporate hack involving millions of dollars in Bitcoin highlights that digital asset operators continue to face security threats.

The reported amount, $3.6 million, reflects a substantial sum in Bitcoin terms. The classification of the event as a corporate hack places the focus on internal infrastructure security rather than on individual user error.

The source material does not state whether law enforcement was involved, whether funds were recovered, or whether customer accounts were affected. The confirmed facts remain limited to the reported theft amount and the company’s description of the event.

Our Assessment

Based on the available information, a Bitcoin Depot ATM operator reported that $3.6 million in Bitcoin was stolen in a corporate hack. The case was reported on April 8, 2026, in the crypto category. The confirmed facts establish the scale of the reported loss and the classification of the breach as corporate in nature. No further operational or technical details were included in the source material.

Indonesian Courts Convict Three Terrorism Financiers Using Blockchain Evidence – Onchain Data Gains Legal Weight in Crypto Crime Cases

Key Takeaways

Indonesian Courts Accept Onchain Data as Core Evidence

Indonesian courts have relied on blockchain transaction data to secure the conviction of three individuals accused of financing terrorism, according to TRM Labs. The convictions were handed down in 2024 and 2025 and were based on detailed analysis of wallet addresses, transaction histories, and onchain fund flows.

TRM Labs stated that cryptocurrency evidence was not only admitted in court but formed the foundation of the prosecution in each case. The courts accepted blockchain records as credible and traceable financial documentation. This marks a development in how digital asset transactions are treated in criminal proceedings, particularly in cases involving national security.

According to TRM Labs, terrorism financing networks have increasingly used cryptocurrency to move funds. The firm noted that authorities and regulators were previously slower to scrutinize crypto transactions compared to traditional fiat channels. The Indonesian cases indicate that this gap is narrowing as investigative tools and technical expertise improve.

$49,000 in Stablecoins Traced to ISIS-Linked Fundraising Campaign

In one of the cases, Indonesian authorities traced more than $49,000 worth of USDt, also known as USDT, sent by a defendant across 15 transactions. The transfers moved from a local cryptocurrency exchange to a foreign platform. The funds were subsequently routed to a terrorism fundraising campaign in Syria that was linked to ISIS.

The tracing process was carried out by Indonesia’s financial intelligence team in cooperation with Densus 88, the country’s counterterrorism police unit. Investigators mapped the movement of funds across exchanges and blockchain addresses. The findings were presented in court as part of the prosecution’s case.

The courts accepted the blockchain analysis as key evidence. According to TRM Labs, this demonstrates that transaction records stored on public blockchains can be used to reconstruct financial flows in a manner that meets judicial standards.

For crypto users and service providers, the case highlights that stablecoin transfers between exchanges can be tracked and attributed when combined with exchange records and investigative tools. Even when funds move across borders and platforms, transaction histories remain accessible onchain.

Southeast Asia Expands Blockchain Intelligence Capabilities

TRM Labs reported that Indonesia is not alone in strengthening its approach to blockchain-based investigations. Similar patterns are emerging across Southeast Asia, where governments are investing in blockchain intelligence capabilities and increasing collaboration between public agencies and private analytics firms.

The firm specifically mentioned Singapore and Malaysia as jurisdictions where financial intelligence units and law enforcement agencies are building technical capacity to trace cryptocurrency flows. The objective is to address illicit finance risks that involve digital assets.

This regional focus comes amid broader enforcement actions. On April 1, Cambodian and Chinese officials captured Li Xiong, identified as a leader of the Huione Group. The organization served scam centers in Cambodia that carried out so-called pig butchering frauds and other investment schemes designed to steal cryptocurrency from victims worldwide. Li Xiong was extradited to China and is set to face fraud and money laundering charges.

His extradition followed the arrest three months earlier of Chen Zhi, head of Prince Group, which operates Huione Group. These actions underline coordinated cross-border enforcement efforts targeting crypto-related financial crime.

Stablecoins Feature Prominently in Illicit Activity Data

In a separate report published in February, TRM Labs stated that illicit entities received approximately $141 billion worth of stablecoins in 2025. The firm described this figure as a five-year high.

The Indonesian cases involved USDt, a stablecoin designed to maintain a value pegged to the US dollar. Stablecoins are frequently used in cross-border transactions because they combine price stability with blockchain-based transferability. According to TRM Labs, these characteristics have also made them attractive to illicit networks seeking to move funds outside traditional banking channels.

At the same time, the public nature of most blockchain networks allows investigators to analyze transaction paths in detail. When combined with exchange compliance data and law enforcement cooperation, onchain analytics can link wallet addresses to individuals and organizations.

For users of crypto platforms, including those active in online betting or digital asset transfers, the developments illustrate that transactions conducted on public blockchains can be subject to forensic review. Regulatory and enforcement agencies in multiple Southeast Asian jurisdictions are strengthening their ability to monitor and reconstruct digital asset flows.

Our Assessment

The convictions in Indonesia show that courts are prepared to accept blockchain transaction data as primary evidence in terrorism financing cases. Authorities traced more than $49,000 in stablecoin transfers across exchanges and linked the funds to an ISIS-connected campaign. TRM Labs reports that similar investigative capabilities are expanding across Southeast Asia, while stablecoins continue to feature prominently in illicit finance data. Together, these facts indicate a growing integration of blockchain analytics into formal legal and enforcement frameworks in the region.

Ripple Acquires Hidden Road for $1.25 Billion – Prime Brokerage Model Gains Ground in Institutional Crypto

Key Takeaways

Ripple’s $1.25 Billion Hidden Road Deal Highlights Infrastructure Focus

Ripple has agreed to acquire Hidden Road, a global multi-asset prime broker, in a transaction valued at $1.25 billion. The deal is described as the largest acquisition in the history of the crypto sector. Hidden Road operates as a prime brokerage, providing trading infrastructure across asset classes.

The transaction signals a shift in where established players see long-term value in digital assets. Rather than focusing solely on exchanges or token issuance, capital is moving toward institutional-grade trading infrastructure. Prime brokerage services sit between trading venues and institutional clients, handling onboarding, settlement, and in some cases leverage.

The acquisition takes place against a backdrop of increasing institutional involvement in crypto markets. According to Dominic Lohberger, chief product officer at Sygnum, institutional capital is now moving through structures that resemble those used in traditional finance.

Separation of Custody and Execution Becomes Institutional Baseline

For much of crypto’s history, exchanges combined multiple roles. They acted as trading venues, custodians, and clearing houses simultaneously. This structure was common in early Bitcoin markets, where infrastructure options were limited.

Recent market events have intensified scrutiny of this model. The collapse of FTX and a $1.4 billion hack affecting Bybit highlighted counterparty exposure at centralized platforms. These incidents reinforced concerns about holding client assets directly on exchanges.

In response, institutional participants are increasingly requiring a separation between custody and execution. Regulated off-exchange custody solutions now allow assets to remain with independent custodians while mirrored balances are made available on trading venues. Settlement processes can be automated without transferring full control of assets to exchanges.

This structure reflects long-standing principles in traditional finance, where custody and trading functions are typically separated. In the crypto market, this approach is becoming a standard requirement for market makers, hedge funds, and over-the-counter desks.

Two Models Compete: Off-Exchange Custody and Prime Brokerage

The market currently offers two primary approaches to reducing exchange counterparty risk.

The first is off-exchange custody, sometimes described as a tri-party arrangement. In this model, a third-party custodian holds assets on behalf of the client. The exchange receives a mirrored balance that enables trading. If the custodian keeps assets segregated and off its balance sheet, counterparty exposure to the exchange can be minimized. These arrangements are generally considered cost-efficient because the custodian does not need to commit its own balance sheet.

The second approach is the prime brokerage model. A prime broker intermediates between client and exchange, offering consolidated onboarding across venues, cross-venue net settlement, and access to leverage. This model is particularly relevant for market participants operating across multiple trading platforms simultaneously.

However, prime brokerage shifts counterparty exposure from the exchange to the prime broker itself. In traditional finance, large investment banks typically backstop this risk with substantial balance sheets. In crypto, prime brokers are expanding but operate with comparatively smaller balance sheets than globally systemically important banks.

Standard Chartered is among the traditional financial institutions building a crypto prime brokerage under its venture arm, reflecting broader interest from established banks in this segment.

Collateral Structures and the Role of US Treasurys

Collateral management is becoming a central component of these new frameworks. When custody is provided by a bank, clients can pledge traditional financial instruments as collateral. According to the source material, short-dated US Treasurys can be used and mirrored onto exchanges at full loan-to-value, while remaining with the custodian.

In these setups, custody fees represent only a fraction of the yield generated by the underlying instrument. As a result, collateral posted for trading purposes can generate a net positive return while also reducing exposure to exchange default.

The majority of collateral deployed in bank-grade off-exchange custody structures is currently held in US Treasury bills. Stablecoins are already accepted in several off-exchange frameworks. The range of eligible collateral is expected to expand to include tokenized money market funds that accrue yield in real time.

Certain strategies, such as basis trades, require pledging the underlying crypto asset itself. Even in these cases, holding assets with an independent custodian can reduce the overall risk surface compared to leaving funds directly on an exchange.

Expansion of Bank Participation in Off-Exchange Custody

The entry of additional global systemically important banks into off-exchange custody is anticipated in the coming months, according to the source material. Broader bank participation would widen the range of accepted collateral types and further align crypto market infrastructure with established financial standards.

As both off-exchange custody and prime brokerage models evolve, custodians may expand operational tools, while prime brokers may reinforce custody frameworks. The overall direction points toward institutional-grade risk management embedded within crypto trading workflows.

For market participants, including trading firms and liquidity providers active on multiple venues, these developments reshape how capital is allocated and protected. Instead of choosing between capital efficiency and asset security, new structures aim to combine both within regulated frameworks.

Our Assessment

Ripple’s $1.25 billion acquisition of Hidden Road underscores the growing importance of prime brokerage in crypto markets. The development reflects a broader structural shift toward separating custody from execution and adopting risk management standards common in traditional finance. Off-exchange custody arrangements, expanded collateral options, and increasing bank participation indicate that institutional trading infrastructure is becoming a central pillar of the digital asset ecosystem.