Blockchain is increasingly being embedded into financial and public infrastructure, but the industry’s persistent weaknesses remain impossible to ignore.
Circle has recruited BlackRock, Visa, Mastercard, DTCC and other financial institutions to validate its Arc network. Ondo Finance is strengthening its leadership as tokenised capital markets grow, while BitGo is moving billions of dollars in Wrapped Bitcoin to Chainlink’s interoperability infrastructure.
Kenya is applying blockchain to academic credential verification, and Indonesia’s PEKSINDO is making the case for digital assets aligned with Islamic-finance principles.
Against that institutional progress, Proof of Play is shutting down after failing to make its onchain-gaming model sustainable, while the Coldcard incident has exposed a devastating truth about self-custody: a hardware wallet is only as secure as the process used to generate its keys.
BlackRock, Visa and DTCC join Circle’s Arc validator network
Circle has named an unusually institutional group of founding validators for Arc, its blockchain network designed around stablecoin payments and tokenised finance.
The cohort includes BlackRock, Depository Trust & Clearing Corporation, Galaxy, Global Payments, Intercontinental Exchange, Mastercard, MoneyGram, SBI Group, Standard Chartered, Sumitomo Corporation and Visa, according to Ledger Insights.
Circle itself will also participate in validation.
Arc is currently operating through a private mainnet containing more than 100 institutional and ecosystem builders. Its public mainnet is scheduled to launch on 16 September 2026.
The validator list immediately distinguishes Arc from conventional public blockchains secured primarily by anonymous or crypto-native participants. Its founding organisations represent asset management, payments, banking, market infrastructure, custody and international commerce.
That structure could make Arc attractive to institutions that want blockchain settlement but require identifiable counterparties, established compliance processes and predictable governance.
USDC will serve as the network’s native gas asset, reducing the need for users to hold a separate volatile cryptocurrency merely to pay transaction fees. Circle is positioning Arc as infrastructure for stablecoin payments, foreign exchange, capital markets and tokenised real-world assets.
BlackRock is expected to bring BUIDL, its tokenised money-market fund, onto Arc. DTCC’s participation connects the project with the organisation responsible for core post-trade infrastructure across American securities markets, while Visa, Mastercard, Global Payments and MoneyGram bring extensive payment and distribution networks.
The combination signals a convergence between several previously separate parts of digital finance:
- Stablecoins as settlement assets
- Tokenised funds and securities
- Card and merchant-payment networks
- Institutional custody
- Clearing and market infrastructure
- Public blockchain programmability
However, the validator composition also creates questions about decentralisation.
A network secured by recognised global institutions may provide stronger accountability and easier regulatory engagement. It can also concentrate influence among a limited group of large companies capable of restricting transactions or enforcing policy decisions.
Arc may therefore become an important test of whether blockchain’s efficiency and programmability can be preserved within a network designed for institutional governance.
The goal is no longer simply to move traditional finance onto public blockchains. It is to build blockchain infrastructure that financial institutions are willing—and legally able—to operate themselves.
Ondo Finance appoints Adam Schlisman as chief financial officer
Ondo Finance has appointed former Blockchain.com executive Adam Schlisman as its new chief financial officer.
As Crypto.news reports, Schlisman joins as the tokenised-assets company expands its institutional capital-markets business.
He most recently served as CFO of global macro hedge fund Monashee Investment Management. Before that, he held the same position at Blockchain.com, overseeing finance, treasury and risk during a period of rapid expansion. He also spent almost a decade at Graham Capital Management in portfolio-management and risk roles.
The appointment gives Ondo an executive with experience spanning hedge funds, traditional markets and crypto-native financial services.
That combination matters as tokenisation companies move from product experimentation into businesses managing billions of dollars across multiple jurisdictions, networks and asset types.
Ondo offers blockchain-based access to US Treasuries, equities and other financial products. The company says more than $3.5 billion is held across its platforms, while Ondo Stocks has surpassed $1 billion in total value locked.
Its products are available through Ethereum, Solana and BNB Chain, with integrations covering exchanges, wallets and custody providers including Binance, Bitget, MetaMask, Ledger and Blockchain.com.
Scaling this model requires considerably more than creating tokens that track conventional assets.
The company must manage reserves, corporate finance, treasury exposure, reporting, risk, regulatory permissions and relationships with the institutions responsible for the underlying securities. Investors need confidence that a token represents an enforceable claim supported by appropriate custody and operational controls.
Schlisman’s appointment consequently reflects a wider change in the blockchain labour market. Tokenisation companies are recruiting leaders familiar with regulated finance because their long-term competition increasingly includes asset managers, banks and market-infrastructure providers.
HIPTHER previously examined this institutional direction in Blocks & Headlines covering Paxos, Ripple, tokenised settlement and blockchain trust infrastructure.
Proof of Play shuts down after its onchain-gaming model falls short
Proof of Play, the studio behind blockchain role-playing game Pirate Nation, is shutting down after failing to create a sustainable business at scale.
The company had raised approximately $33 million, including backing from Andreessen Horowitz, but was unable to convert its technology and early interest into lasting player engagement, according to BitcoinKE.
Proof of Play attempted to build a game in which assets and substantial elements of player activity existed onchain. Its broader thesis was that blockchain ownership and composability could create a new model for online games.
The closure demonstrates that technical ownership does not automatically create entertainment value or a durable economy.
Blockchain games must solve all the challenges faced by conventional studios—gameplay, retention, content development, community management and monetisation—while also handling wallets, transaction costs, smart contracts, token liquidity and regulatory uncertainty.
These additional systems can provide genuine benefits. Players may gain verifiable ownership of assets, developers can support external marketplaces, and game economies can become more transparent.
They can also produce friction. A player attracted by the game may not want to manage keys or understand token mechanics. An economy shaped heavily by financial incentives can attract users seeking rewards rather than entertainment, causing participation to collapse when token prices decline.
Proof of Play is releasing its code under an MIT licence and making its art and intellectual property available under Creative Commons Zero. The decision allows other developers and community members to continue using the assets without the original company.
The PIRATE token will be left to an independent foundation rather than maintained by Proof of Play.
Open-sourcing the project is consistent with blockchain’s community-driven ideals, but it does not ensure continuity. Code can survive without a company, while a living game still requires development, moderation, infrastructure and players.
The shutdown should not be interpreted as proof that blockchain gaming cannot work. It does show that ownership technology must support a compelling game rather than substitute for one.
Coldcard losses approach $120 million as transactions crowd Bitcoin’s mempool
The continuing theft of bitcoin associated with vulnerable Coldcard wallets has pushed estimated losses towards $120 million.
The attack began on 30 July and unfolded through several waves, generating a visible surge of transactions across Bitcoin’s mempool, according to CoinDesk.
Coldcard is a Bitcoin-focused hardware wallet manufactured by Coinkite and commonly used by holders who want to keep their private keys away from online exchanges.
The incident appears to involve a flaw affecting the generation of recovery phrases in certain firmware versions. Insufficient randomness may have made some seed phrases predictable enough for sophisticated attackers to reconstruct.
An initial wave reportedly removed more than 1,000 bitcoin from 1,196 addresses in approximately 41 minutes. Subsequent activity expanded the suspected losses and affected-address count.
The case is especially damaging because hardware wallets are promoted as a safer form of long-term self-custody.
Self-custody removes the danger that an exchange could collapse, freeze withdrawals or misuse customer assets. It creates a different concentration of risk: the owner depends on the wallet’s hardware, firmware, seed-generation process, backup method and their ability to respond correctly when a problem is discovered.
Installing updated firmware is not sufficient for a recovery phrase that was generated with vulnerable software. The weakness remains embedded in the seed, even if that phrase is imported into another device.
Potentially affected users must generate a completely new recovery phrase through corrected software and move their bitcoin to addresses controlled by the new seed.
The movement of funds created a disturbing contest inside Bitcoin’s mempool. Users identifying unauthorised transactions could attempt to replace them with higher-fee transfers directing funds to safe wallets, while attackers could increase their own fees to maintain priority.
This turns recovery into a race that rewards technical knowledge, monitoring and immediate action—advantages many ordinary hardware-wallet owners do not possess.
The incident reinforces several lessons:
- Hardware should be purchased from trusted sources.
- Firmware versions and security notices must be monitored.
- Seed generation deserves the same scrutiny as key storage.
- A firmware update cannot repair an already compromised seed.
- Recovery procedures should be tested before an emergency.
- Large holdings may require stronger multisignature arrangements.
Blockchain transparency allows investigators to observe the movement of stolen bitcoin. It does not allow them to reverse validly signed transactions.
That distinction remains central to self-custody: control is powerful precisely because the network cannot easily distinguish an owner from an attacker holding the correct keys.
BitGo replaces LayerZero with Chainlink CCIP for WBTC
BitGo has selected Chainlink’s Cross-Chain Interoperability Protocol as the exclusive cross-chain infrastructure for Wrapped Bitcoin.
The change replaces LayerZero’s Omnichain Fungible Token standard and affects approximately $7.3 billion in WBTC, according to CoinMarketCap Academy.
Wrapped Bitcoin allows bitcoin-backed value to operate on smart-contract networks where it can be used for lending, trading, liquidity provision and collateral.
Moving such a large asset between blockchains requires infrastructure that can coordinate token issuance and destruction without creating duplicate or unbacked supply. A failure in this layer could affect protocols and users across several networks simultaneously.
BitGo said the Chainlink arrangement allows it to retain direct control over WBTC token contracts, transfer limits and cross-chain settings. The company also intends to use CCIP for future tokenised assets.
The change forms part of a larger migration away from LayerZero following the $292 million Kelp DAO bridge exploit. Mantle, Lombard, Aave and Kraken have announced similar infrastructure decisions, taking the combined value of disclosed LayerZero-to-Chainlink migrations to approximately $14.5 billion.
Bridge security has become one of blockchain’s most consequential technical problems.
Individual networks may operate correctly while assets are lost through the mechanisms connecting them. Bridges can introduce smart-contract vulnerabilities, validator risk, compromised administrative keys and inconsistencies between token representations.
Selecting another provider does not eliminate those risks. It changes how they are managed.
Chainlink CCIP combines messaging infrastructure, programmable transfer controls and an additional risk-management network. BitGo’s direct control may help it respond to abnormal activity, but it also means users must understand which entities can pause, limit or modify transfers.
The migration demonstrates that interoperability is becoming an institutional infrastructure market. Security history, governance and operational control now matter as much as the number of networks a bridge supports.
This need for consistent security standards reflects the vulnerabilities examined in HIPTHER’s report on the OWASP Smart Contract Top 10 2026 and emerging blockchain security priorities.
Kenya uses Avalanche to protect academic credentials
Kenya is introducing a blockchain-based system to secure and verify millions of national academic records.
The Kenya National Examinations Council is anchoring examination credentials on Avalanche’s C-Chain, according to Digital Watch Observatory.
The system includes historical records dating back to 1989 and new certificates issued through Kenya’s electronic credential platform. Employers, schools and universities will be able to verify qualifications without relying entirely on slow manual requests or paper documentation.
Academic fraud has consequences beyond dishonest job applications.
Fake certificates can place unqualified individuals in positions involving public safety, healthcare, education or financial responsibility. Manual verification also creates delays for legitimate graduates applying for work or further study.
Blockchain can help by providing a durable timestamp and integrity record. A verifier can determine whether a credential matches the record issued by the responsible authority without requiring confidential educational information to be published openly.
The implementation must still protect personal data.
Placing complete student records on a public blockchain would create substantial privacy and correction problems. A more appropriate design stores the credential itself in a controlled system while recording a cryptographic proof onchain.
This allows verification without exposing grades, identity documents or other sensitive information.
Authorities also need procedures for legitimate changes. Names may be corrected, results can be appealed and records occasionally require amendment. Blockchain immutability should preserve an audit trail without preventing the authorised institution from issuing a replacement credential.
Kenya’s deployment is significant because it applies blockchain to a practical administrative problem rather than creating another speculative asset.
The long-term measure of success will be whether employers can verify credentials more quickly, fraudulent certificates become harder to use and graduates retain accessible proof of their qualifications.
PEKSINDO argues blockchain can support Sharia-compliant finance
Indonesia’s PT Indeks Kripto Syariah Indonesia is arguing that cryptocurrency should not automatically be treated as gambling and that blockchain can support financial products aligned with Sharia principles.
PEKSINDO commissioner Muslich Ramelan said blockchain’s transparency, accuracy and accountability can be consistent with the Islamic-finance principles of fairness and public benefit, according to IDNFinancials.
The position addresses one of the most complicated questions affecting digital-asset adoption in Muslim-majority markets.
Blockchain is a technology rather than a single financial product. It can be used to issue payment assets, document ownership, automate contracts or create highly speculative tokens. Whether a particular activity complies with Sharia therefore depends on its structure and purpose.
Islamic finance generally prohibits interest, excessive uncertainty and gambling. A transparent blockchain transaction may still be problematic when the underlying token has no credible utility, relies on leverage or is traded primarily through speculation.
Likewise, a digital asset does not become Sharia-compliant merely because its transactions can be audited.
A credible Islamic digital-finance ecosystem would need to examine:
- The economic purpose of the asset
- Whether ownership and reserves are genuine
- The presence of interest-bearing mechanisms
- Excessive uncertainty or speculation
- Leverage, derivatives and liquidation structures
- The rights assigned to token holders
- How returns are generated and distributed
- Governance and independent Sharia supervision
Blockchain may support compliance by creating traceable ownership, transparent reserves and programmable restrictions. Smart contracts could prevent certain prohibited transactions or automate profit-sharing arrangements.
However, code cannot settle every question of Islamic jurisprudence. Scholars, regulators, technologists and financial professionals must evaluate products individually rather than issuing a universal judgement on cryptocurrency.
PEKSINDO’s argument is therefore strongest when it separates blockchain infrastructure from speculative behaviour. The technology can support accountable financial activity, but compliance ultimately depends on how it is designed and used.
The bigger picture: blockchain is becoming infrastructure—and inheriting infrastructure-level responsibility
The seven developments show blockchain entering a more mature but demanding phase.
Circle is assembling established financial institutions to validate a stablecoin-native network. Ondo is hiring executives capable of managing tokenised markets at institutional scale, while BitGo is treating interoperability as critical infrastructure rather than a background technical feature.
Kenya demonstrates how blockchain can solve an administrative trust problem, and PEKSINDO is exploring how transparent digital systems might operate within established ethical and financial traditions.
Proof of Play and Coldcard reveal the other side of that transition.
Technical innovation cannot compensate for an unsustainable product, and self-custody cannot protect assets when the software responsible for generating keys is flawed. Decentralisation moves responsibility; it does not eliminate it.
The industry’s progress should consequently be measured less by the number of tokens or networks created and more by the reliability of the systems built around them.
Institutional blockchain infrastructure must provide clear governance, verifiable reserves, resilient interoperability, secure key generation, privacy protection and accountable methods for correcting mistakes.
Blockchain is no longer being tested only as an alternative to existing systems. It is increasingly being asked to become part of those systems.
That opportunity comes with a higher standard: when billions of dollars, public records or people’s professional futures depend on the technology, “code is law” is no longer an adequate governance model.









Got a Questions?
Find us on Socials or Contact us and we’ll get back to you as soon as possible.