Saudi Arabia · · 14 min read

Beyond the Coldcard exploit, Saudi & Tether, plus what DeFi can learn from TradFi and vice versa: The Intersection (#27)

Beyond the Coldcard exploit, Saudi & Tether, plus what DeFi can learn from TradFi and vice versa: The Intersection (#27)
Photo by Akhilesh Sharma / Unsplash

Welcome to another summer double issue (#27) from TheIntersection team - our next issue will be out in two weeks' time! Enjoy the holidays!!

In this issue:

  1. News: Tether takes tokenisation to Saudi real estate
  2. Analysis: What can TradFi learn from DeFi? What can DeFi learn from TradFi?
  3. Opinion: Beyond the Coldcard exploit
  4. Our weekly events round-up

 And it's all free! Before we dive in, one request: please forward this weekly letter to anyone you think might be interested. We also very much welcome feedback (and contributors). If you want to email us, just drop an email to us at teams@theintersection.news.

News in Brief

Tether completes its first full financial audit: Tether said KPMG U.S. has completed its first full independent audit of the company’s 2025 financial statements. The audit is a notable step for the USDT issuer, which has faced years of scrutiny over its reserves and transparency. KPMG issued an unqualified opinion on the accounts.

DTCC moves tokenisation into live markets: The Depository Trust & Clearing Corporation has successfully processed live trades using DTC-tokenised securities, covering equities, ETFs, Treasuries and collateral transactions. Around 40 firms took part, with DTCC now preparing for the full launch of its tokenisation service in October.
DTCC announcement

Tokenisation market grows — but liquidity remains a problem: The market continues to expand, but new research suggests much of the headline value is sitting still. BeInCrypto found that 910 of 1,289 tokenised assets, worth around $32.9 billion, recorded no transfers during the week studied. The numbers highlight a key challenge for the sector: putting assets on-chain is one thing; creating active, liquid markets around them is another.

Deep Dive — Tether takes tokenisation to Saudi real estate

The top line: Tether is moving beyond stablecoins and into the infrastructure behind real-world assets, starting with institutional real estate in Saudi Arabia. On August 6, Tether announced a partnership with Saudi firm First Data and fintech BKN301 to use its Hadron platform to issue and manage tokenised property assets. First Data will handle issuance and the market, while BKN301 connects the system to banking and compliance infrastructure.

Why Saudi Arabia?

The choice of Saudi Arabia is important. The country is investing heavily in financial technology as part of its Vision 2030 program, which aims to diversify the economy and modernize its financial system. For Tether, it also gives Hadron a market where tokenisation can be tied to large, real-world assets rather than just crypto products. The initial focus is institutional real estate, but the partners said the model could later be used for energy, infrastructure, and other assets. Tether is still best known for USDT, but Hadron shows where the company wants to go next.

Launched in 2024, Hadron is designed to provide the infrastructure needed to put traditional assets on-chain, including issuance, management and compliance. Tether is also already behind XAUT, one of the largest tokenised gold products, with roughly $2.6 billion in assets. The Saudi deal, therefore, looks less like a one-off property project and more like an attempt to turn Tether into a behind-the-scenes infrastructure provider for tokenized assets. Tokenisation has spent years being sold on the promise of putting everything from bonds to property on a blockchain. But the harder question is what happens after an asset is tokenised — who issues it, who can buy it, where it trades and how it connects to the existing financial system.

Recent activity in tokenised equities shows the same issue. Binance's bStocks accounted for about 85% of tokenised-equity DEX trading in July, with monthly volume jumping to around $8.8 billion. That sounds like explosive growth, but the numbers need some context. CoinDesk reported that July's $11.3 billion in tokenised-stock trading was heavily concentrated in QQQB, a token tracking the Invesco QQQ ETF. QQQB alone generated about $9.27 billion, or roughly 82% of total volume.

What can TradFi learn from DeFi? What can DeFi learn from TradFi?

 by John Gray

As traditional financial institutions rush to integrate DeFi-native ideas, we unpack the symbiotic relationship between the two systems.

 Mainstream finance has started lifting ideas straight from the DeFi playbook. This is most visible in the spread of tokenisation: as a Forbes headline framed it earlier this week, ‘Every Major Bank Is Racing To Put Wall Street On The Blockchain’.

 Wells Fargo, for instance, recently said it will offer tokenised deposits to corporate and commercial clients. BlackRock’s BUIDL has become a multi-billion-dollar tokenized Treasury product, and earlier this month, the asset manager expanded the strategy with two tokenized money products. Also this month, JPMorgan said it is providing the blockchain infrastructure for a tokenised US-dollar money market fund launched by Schroders, making Schroders the first global asset manager approved to issue a tokenised share class on the bank’s Kinexys platform.

 Alongside the blockchainification of everything, TradFi is also borrowing a set of market-structure ideas from DeFi: composability, in which assets can plug into multiple financial applications; collateral efficiency, in which an asset can continue earning yield while supporting other transactions; continuous, atomic settlement; and interoperability between previously separate systems.

 A good example of this is JPMorgan’s Kinexys, which has been demonstrating near-real-time settlement and redemption of tokenised Treasury assets across multiple blockchain networks. The important point is not simply that these assets sit on a blockchain, but that they can settle continuously and be used as programmable collateral. Elsewhere, institutional trading venues are already beginning to accept tokenised Treasury products such as BUIDL as collateral for derivatives and digital asset trading, echoing one of DeFi’s defining mechanisms: posting a yield-bearing asset while continuing to earn on it.

 In light of these cascading changes, it feels like a good time to ask: what, exactly, is the relationship between DeFi and TradFi? If DeFi was once dismissed as an esoteric corner of crypto, why are some of the world’s largest financial institutions now adopting its core mechanisms? By a similar token, if DeFi is meant to be an entirely decentralised, permissionless system, what does it mean that fiat-backed stablecoins have become its foundational monetary layer?

 The truth is, of course, that the two systems enjoy a symbiotic relationship. One way to think about it is to see DeFi “as both a laboratory and a stress test for the future of finance”, as Jaime Castillo León and Alfred Lehar write in ‘What data have told us about decentralized finance’ (2025), a paper that is simultaneously a primer and a masterclass on the mechanics of DeFi. To explore what that symbiosis looks like in practice, InterSection News recently spoke to Alfred Lehar, Professor at the Haskayne School of Business at the University of Calgary.

Alfred Lenar

 Why Wall Street is paying attention

 “I think most people still see crypto in general as a speculative asset,” Lehar says, “but that is totally missing the point.” Rather, DeFi should be understood as a new form of trading and settlement infrastructure. Its core advantage is not that it creates new assets, but that it makes moving and settling assets faster and simpler than traditional systems built around layers of intermediaries and back-office processes.

 Take equity markets. In conventional finance, cash and securities are recorded on separate ledgers and transferred through a network of brokers, custodians and clearing institutions. DeFi brings both money and financial assets into the same programmable environment, allowing transactions to settle more directly and with less operational friction.  This advantage is what the major financial institutions have woken up to. It is not a question of ideology. It’s simply a smoother system. Money, like water, always looks for the path of least resistance.

 For Lehar, this is key to understanding the relationship between DeFi and TradFi. More than a parallel, competing system, DeFi serves as a sandbox, rapidly generating new ways of working and thinking that the mainstream system can then scale up. This is why, going forward, we will likely see more DeFi-native processes migrating into mainstream finance.

 Beyond blockchain: what DeFi teaches about market design

 But there is much more that TradFi can learn from DeFi than just blockchain technology. A core characteristic of DeFi, Lehar argues, is that many problems traditionally addressed through regulation or centralized institutions are instead tackled through private sector innovation. Creativity is essential in a system with no central authority.

 A nice example of this was how the issue of front-running was addressed. In the early days of decentralised exchanges such as Uniswap, automated bots would detect a pending trade before it was settled on the blockchain, buy the asset first, and push the price slightly higher. When the original trade was executed, the bot would then sell at a profit. For the trader, the result was simply worse execution; for the bot, it was a virtually risk-free gain extracted from the transaction itself.

 Rather than relying on regulation, DeFi developed market-based solutions to the problem. Private mempools, for example, hide pending trades from bots until they are settled on the blockchain, preventing them from jumping the queue. Trading protocols such as 1inch have also introduced mechanisms that make front-running far less profitable by preventing bots from immediately selling back into the price increase they helped create. The take-home, for Lehar, is that governments should not assume regulation is always the best response to a market failure. Before introducing new rules, policymakers should ask whether a private-sector solution could address the problem more efficiently and with fewer unintended distortions.

 TradFi can learn from the market structures and technologies that have emerged on-chain, while policymakers can use DeFi as a testing ground to discover which problems genuinely require regulation and which can be addressed through better market design. The result, he argues, could be a financial system that is more effective, more cost-effective, and subject to fewer unnecessary frictions.

 What DeFi can learn about money

 The flow goes both ways. If TradFi is borrowing DeFi’s infrastructure, DeFi is increasingly relying on TradFi’s money, in the sense that fiat-backed stablecoins are becoming the default monetary layer for on-chain finance. This raises a key question: do they strengthen the crypto ecosystem by giving it a stable unit of account, or do they reintroduce the centralised dependencies crypto was originally designed to avoid? An academic perspective is useful here, not least because it strives to avoid the ideologies that often distort these debates.

 In Lehar’s opinion, fiat’s increasing uptake in DeFi is more likely to strengthen fiat than undermine it. “We still have crypto-native assets that will be some sort of competition for traditional finance and prevent countries from overissuing or totally devaluing their own fiat currencies, which is probably healthy to keep governments in line.” Variations in national fiat currencies also reflect the differences in economic activity across different countries.   That leads to the broader issue of monetary policy, which is often left out of conversations that focus on the payment side of crypto. One of the lessons DeFi can learn from TradFi, Lehar argues, is that a fixed issuance schedule is not necessarily a virtue. Bitcoin’s predetermined supply may be attractive as a store of value, but it would be a poor tool for managing inflation or responding to economic shocks. “For many people,” he observes, “issuing less is always better, but I think that’s not necessarily true because it creates deflation, and, as we know, deflation is very harmful for the economy.”

 This is precisely the kind of question central banks wrestle with constantly: how much money should be in circulation, and what trade-offs exist between inflation, deflation and economic activity? Crypto protocols are increasingly having to confront similar questions, yet the debate remains relatively underdeveloped. There is still considerable room, Lehar argues, “to discuss what kind of objective we want to achieve with our monetary policy”.  In short, he wryly notes, “I’m not sure that we are ready for one world currency yet.”

Convergence?

 Lehar’s hopeful vision is that one day TradFi and DeFi will merge, giving rise, simply, to “a better system than we have today”. It is not a question of which system will prevail. TradFi is already borrowing DeFi’s infrastructure and market design, while DeFi is rediscovering the importance of monetary policy, stable units of account and institutional trust. The future may look less like a replacement and more like a convergence — a financial system that combines the speed and programmability of DeFi with the stability and robust governance of TradFi.

Beyond the Coldcard exploit

By James Butterfill, Head of Research, Coinshares

James Butterfill, Coinshares

Two seemingly unrelated security incidents have recently captured the financial industry’s attention. A serious vulnerability affecting Coldcard hardware wallets led to the compromise of user funds, while several of the world’s largest hedge funds, including Point72, Citadel, Millennium, and Two Sigma2, were reportedly targeted by audio-based phishing attacks designed to compromise employee credentials. One concerns Bitcoin self-custody, the other traditional finance, but both point towards the same underlying trend: artificial intelligence is beginning to reshape the economics of cybersecurity.

A vulnerability introduced into Coldcard firmware in March 2021 remained undiscovered for more than five years before being exploited against real users. Coinkite1 confirmed that affected devices generated substantially less entropy than intended, weakening the security of seeds created by vulnerable firmware. Estimates from blockchain analytics researchers suggest approximately $116M to $130M of Bitcoin may have been compromised across thousands of addresses.

There is no public evidence that AI was responsible for finding the vulnerability. Coinkite has suggested AI-assisted code review may have played a role, but its own retrospective testing with multiple frontier models failed to identify the flaw. More importantly, what happens if AI continues reducing the time, expertise, and cost required to find subtle software flaws across all of finance?

The IMF has warned that AI could accelerate vulnerability discovery and exploitation, while the UK National Cyber Security Centre has identified AI-assisted exploit development as a significant near-term risk. AI does not need to break cryptography to materially change financial security. It simply needs to make everything around it easier to attack.

Cryptographic authorisation versus institutional trust

Bitcoin and traditional finance have different security architectures. Bitcoin’s base layer validates spending conditions cryptographically, generally without needing to establish the real-world identity of the person initiating a transaction. Traditional financial institutions also rely extensively on cryptography, including encryption, hardware security modules, and digital signatures, but cryptography is only one layer. Banks and asset managers must also determine whether customers are genuine, employees are authorized, counterparties are legitimate, and payment instructions should be trusted. These are identity and institutional trust problems, and AI is becoming increasingly effective at attacking them. Large language models can personalize phishing, reproduce voices and video, automate reconnaissance and search for vulnerabilities with less human involvement.

The recent attacks on hedge funds provide a useful example: Point72, Citadel, Millennium, and other major investment firms were targeted by audio-based phishing schemes in which attackers impersonated trusted personnel to obtain sensitive credentials. Reports described the wider campaign as involving AI-enabled voice cloning. Public information about the precise role played by AI remains limited, but attackers were clearly seeking to exploit human trust rather than defeat the underlying cryptography.

Several attempts appear to have been detected before material damage occurred. Yet these firms have substantial cybersecurity budgets, specialist teams and mature controls. The fact that attackers still consider employees and identity processes viable points of entry is significant in itself.

AI is changing the economics of cyberattacks

Some of the clearest evidence comes from the UK AI Security Institute. AISI tested frontier AI models against a simulated 32-stage corporate network attack involving reconnaissance, credential theft, exploitation, reverse engineering, and data exfiltration. With a fixed 10-million-token inference budget, GPT-4o completed an average of 1.7 stages in August 2024. By February 2026, Claude Opus 4.6 averaged 9.8 stages, almost a six-fold increase in 18 months. The best individual run completed 22 of 32 stages, roughly six hours of the estimated 14 hours of work AISI believes a human expert would require. The test contained no active defenders, but the direction is clear: capabilities that once required significant expertise are becoming cheaper and easier to access. 

Figure 1: Average stages completed by frontier AI agents in AISI’s 32-stage corporate cyberattack benchmark at a fixed 10 million-token inference budget. Source: UK AI Security Institute.

Vulnerability exploitation is already becoming a more important route into corporate systems. Verizon's 2026 Data Breach Investigations Report found that it had become the leading initial access method, accounting for 31% of breaches, while third-party involvement was present in 48%.

That matters for finance, which depends on cloud providers, payment processors, identity providers, custodians, and thousands of other third parties. The Financial Stability Board estimates that non-bank financial institutions alone held $256.8tr of assets in 2024. AI does not need to create a new category of cyberattack to change the risk profile of this infrastructure; it only needs to reduce the marginal cost of attacking existing weak points.

The same logic applies to fraud. The ECB and EBA found that payment fraud across the EU increased from €3.5B in 2023 to €4.2BColdcard Security Advisory in 2024. Strong customer authentication continued to perform well, but institutions highlighted the growing number of cases in which legitimate users are manipulated into authenticating fraudulent transactions themselves.

AI potentially makes that attack surface larger. Voice generation, personalised phishing, synthetic identities and automated reconnaissance increase the sophistication and scale of social engineering. If an attacker cannot defeat authentication technically, the next option is to persuade the authenticated person to defeat it on their behalf. The machine does not need to steal the key if it can persuade the person holding it to open the door.

What Coldcard actually tells us

The Coldcard exploit was not a failure of Bitcoin's consensus mechanism or underlying cryptography, but an implementation failure in the process used to generate cryptographic entropy. Secure protocols still require secure implementations. Bitcoin can provide strong cryptographic assurances at the protocol level while the hardware, software, and users around it remain vulnerable.

Bitcoin itself continued functioning as designed; the attacker did not break its signature algorithm or consensus mechanism. Instead, weaknesses in the implementation meant some users' keys were not as unpredictable as they should have been. This complicates the traditional framing of self-custody. Removing a third-party custodian removes one form of counterparty risk, but it transfers responsibility for hardware, software, backups and operational security to the holder. For some investors, incidents like this may strengthen the case for institutional custody or ETP structures where key management is handled professionally and combined with segregated storage, cold-storage policies, multi-party authorization, whitelisted wallets and monitoring. Institutional custody is not immune to cyber risk, but the trade-off is less about which model is “secure” and more about which risks investors are willing and equipped to manage themselves.

One reason Bitcoin security failures receive disproportionate attention is that losses are immediately visible. When a self-custody wallet is compromised, the owner generally bears the loss directly, and the movement of assets is observable. Within traditional finance, losses can instead be distributed between institutions, insurers, payment providers, and customers.

There is also a more important asymmetry. Bitcoin's base security architecture is designed to minimize the need for discretionary trust. Traditional finance cannot remove identity from its operating model. Banks must know who their customers are, determine what employees are authorized to do, maintain recovery mechanisms, and allow human intervention when exceptional circumstances occur. As machines become better at imitating humans, identifying vulnerabilities and automating attacks, maintaining identity-based trust will likely become more expensive.

That does not mean Bitcoin or decentralised networks are inherently secure while traditional finance is insecure. Coldcard is evidence of why that claim would be too simplistic. But it does suggest that AI could dramatically alter the relative economics of different security architectures. The Coldcard exploit showed that implementation quality matters just as much as cryptographic design. At the same time, attacks against some of Wall Street's most sophisticated investment firms illustrate the challenge facing identity-dependent financial systems as convincing human impersonation becomes increasingly cheap to produce.

These incidents are not evidence that one financial system is secure while the other is not, but there is huge asymmetry at the moment, with traditional finance having far more attack vectors and far larger sums of money at stake. We also believe that further news of AI-related attacks is likely to drive people towards decentralized blockchain solutions, which are far less vulnerable relative to the centralized public ledger systems in finance or government.

 Sources:

1 Coinkite Security Advisory, 30 July 2026, blog.coinkite.com

2 Bloomberg.com, 5 August 2026

  Events on our radar

 

 

Read next