Balanced · Trusted · Concise
CME Group's jurisdictional challenge froze the first SEC-approved Bitcoin index options product this week, the BIP-110 soft fork closed its activation window at 2.56% — less than one-twentieth of the 55% threshold required — and the Coldcard hardware wallet exploit more than tripled in scale to $116 million drained from more than 5,200 addresses.
CME Froze the First SEC-Approved Bitcoin Index Options — and Put the Bitcoin Commodity Question Back Before the Commission
The SEC granted CME Group's petition to review its conditional May 2026 approval of Nasdaq PHLX's cash-settled Bitcoin index options, publishing the order in the Federal Register on August 3 and setting August 24 as the deadline for public comment; the original approval is automatically stayed, freezing the product's launch indefinitely. CME argues Bitcoin is a non-security commodity under exclusive CFTC jurisdiction and that allowing a securities exchange to list direct Bitcoin index options would displace the CFTC-regulated Bitcoin derivatives market where CME holds dominant volume through its own Bitcoin futures and micro-futures contracts. Nasdaq's QBTC tracks the CME CF Bitcoin Real-Time Index — meaning CME's own index underlies the product CME moved to block. The review will test whether the SEC can clear Bitcoin-linked products at all when a CFTC-regulated exchange holds a jurisdictional counterclaim, a question the CLARITY Act would resolve by statute but that stalled in the Senate before its August recess.
The SEC's grant of CME's petition places the question of Bitcoin's commodity classification — and which federal regulator governs its derivatives market — formally back before the Commission at the moment when statutory resolution through the CLARITY Act is most uncertain.
BIP-110's Activation Window Closed at 2.56% — Bitcoin Governance Resisted Its Most Contested Soft Fork in Years
Block 961,632 arrived with only 48 of the preceding 1,831 blocks carrying the BIP-110 signal — 2.62% of the two-week window against a 55% threshold required for lock-in — ending the proposal's activation path under the current ruleset without the threshold ever approaching. OCEAN Pool was the only major mining operation to signal by default; Foundry USA, despite running a hashrate-weighted miner vote with non-responses counting as No through August 8, did not flip its signaling, and Antpool, ViaBTC, and F2Pool held out through the close. BIP-110, authored by developer Dathon Ohm, would have restricted most transaction outputs to 34 bytes, OP_RETURN to 83 bytes, and arbitrary data pushes to 256 bytes for one year, targeting Ordinal inscriptions, BRC-20 payloads, and similar non-payment data. Luke Dashjr said following the window's close that a proof-of-work algorithm change was the only remaining path if the proposal's goals were to be met outside the standard BIP activation process.
The failure establishes that even a hashrate-weighted vote backed by a pool controlling roughly a third of global hashrate cannot drive signaling to threshold without broad coalition support — delivering the clearest data point to date on how Bitcoin's governance process handles a contested soft fork when major pools decline to participate.
The Coldcard Exploit Grew to $116 Million — a Five-Year-Old Firmware Bug Is Still Draining Active Wallets
Four waves of theft followed the initial July 30 sweep: Galaxy Research's running tally reached 1,816 BTC — approximately $116 million at current prices — drained from more than 5,200 addresses, up from the 474 wallets and 594 BTC reported when the first sweep was detected. The vulnerability, introduced in firmware version 4.0.0 in March 2021, caused affected Coldcard devices to substitute MicroPython's software random number generator for the dedicated hardware entropy source during seed creation, collapsing key entropy from 128 bits to as little as 40 bits on older models; seeds derived partly from predictable parameters — device serial numbers and internal clock values — gave the attacker a precomputable keyspace scannable against the blockchain at scale. Affected models span Mk3 devices on firmware 4.0.0 through 5.0.3 and Mk4, Mk5, and Q devices on firmware below 5.6.0; wallets created using the dice-roll entropy option from initial setup appear unaffected. Coinkite released patched firmware and urged all potentially affected users to generate new seeds using a minimum of 50 dice rolls, then move funds to addresses derived from the new seed before the attacker scans the remaining vulnerable keyspace.
Patching the firmware does not recover an already-exposed seed — the only remediation is generating new keys and moving funds — meaning the active threat window remains open for every affected address until its holder acts.
Bitcoin Health Meter
48 Strained
Network 40
Demand 16
Holder 78
Market 62
Macro 69
View breakdown →
Editor's Choice
Bitkey Bitcoin Hardware Wallet

Self-custody made simple. Built by Block, Jack Dorsey's company, for real-world Bitcoin storage and everyday use.

View on Amazon
Bean of Fire Exotic Variety Box

Exotic single-origin coffees created by Nayib Bukele — the president who made El Salvador the first nation to adopt Bitcoin as legal tender.

View on Amazon
Amazon affiliate links. Purchases support BTC Weekly.
Follow via RSS
Your weekly roundup of Bitcoin's key developments. New issue every Saturday night.
btcweekly.org/feed.xml →