Back to The Brief
The Brief · Edition 27

Harmony's Rollback Problem Is Now Your Problem

For operators in crypto, iGaming and payments, this week's through-line is exposure you didn't choose: chain exploits forcing rollback calls, UK planning reform tightening gambling licensing, and lawmakers pressing banks on crypto debanking.

August 12, 202612 stories~8 min read
From Inglorious

Trust Your CFO. Hang Up Anyway.

Inglorious · 10 AUG

Vishing campaigns targeting financial services firms have gone from opportunistic to coordinated, and Google's threat research team says the reconnaissance behind them is specific. High-risk operators, casinos, exchanges, PSPs, are preferred targets because their finance teams routinely handle urgent requests from partners they rarely speak to. This piece breaks down why that operating pattern makes you an easy mark, and how AI-driven voice cloning has upgraded a decades-old scam into something your CFO could fall for on the first call.

Read the breakdown

Cryptocurrency & Blockchain

CoinTelegraph · 12 AUG

Harmony considers rollback after suspected exploit inflates ONE supply

Harmony is working with exchanges to freeze funds and preparing a patch after an alleged exploit minted nearly 4 billion unauthorized ONE tokens, about 26% of total supply. An account called "Juiceberg" claims 2.8 billion of those tokens were funneled to exchanges through empty blocks as the price collapsed, with roughly 115 million ONE, 2.9% of the alleged mint, still sitting onchain. ONE fell 33.9% over 24 hours. Harmony has not confirmed the cause, token count, or amount moved to exchanges.

Harmony is now weighing a rollback, the blunt-force option that rewrites history rather than patches around it. This is the same chain that lost $100 million to Lazarus Group in 2022, so exchanges freezing funds this week are betting on unverified claims from an anonymous account.

Why It Matters

If your exchange already credited or allowed withdrawals on the disputed ONE tokens, a Harmony rollback could reverse those balances retroactively, leaving you to absorb the difference.

Read at cointelegraph.com
CoinDesk · 12 AUG

Harmony’s ONE dives 40% after an attack appears to mint tokens equal to quarter of supply

Harmony's ONE token dropped about 40% Wednesday after an exploit minted roughly 4 billion new tokens, more than 26% of the 15 billion supply that existed before the attack. Harmony confirmed the incident, pushed an emergency patch to network operators to stop further minting, paused its token bridge, and asked exchanges to freeze funds tied to four wallet addresses.

Harmony is now weighing a rollback, essentially rewinding the chain to before the exploit. The catch: once funds hit exchanges or other chains, undoing the attack means undoing legitimate transactions too.

Why It Matters

If your exchange holds ONE deposits from the flagged addresses, a rollback decision determines whether those balances still exist post-patch, and freezing now doesn't guarantee finality either way.

Read at coindesk.com
CoinDesk · 12 AUG

XRP bridge drained for $200,000 after software mistook fake deposits for real ones

An attacker drained roughly 200,000 XRP, worth about $200,000, from the tx bridge connecting the XRP Ledger to Coreum in 97 minutes on Aug. 9. A software flaw let the bridge register transactions as deposits even though no XRP ever reached the reserve wallet, so the attacker minted bridged XRP against nothing and withdrew real tokens against the fake balance.

The bridge's 28 relayers approved every payout exactly as designed, with 17 signing off each time, because the underlying records they trusted were wrong. tx has patched the code, called in forensics and filed with the FBI, but hasn't said how holders get made whole.

Why It Matters

If your platform relies on relayer or oracle consensus to validate cross-chain deposits, this shows majority sign-off means nothing when the underlying deposit-detection logic itself is compromised, so audits need to target the data feed, not just the voting mechanism.

Read at coindesk.com
CoinTelegraph · 12 AUG

Ravencoin hits record low as network exploit puts transactions at risk

Ravencoin fell to an all-time low of $0.002754 on Wednesday, about 22% below its 24-hour high, after a consensus vulnerability let vulnerable nodes accept invalid blocks starting at block height 4,487,776 last Friday. Trading volume spiked above $18 million before easing to roughly $9.6 million as RVN recovered slightly to around $0.00284. Mining pools 2Miners and RavenMiner, which control most of the network's hash rate, are now building a competing chain excluding the exploited branch, risking a reorganization of about three days. Upbit and Bitget suspended RVN transfers, with Upbit still allowing trading.

Why It Matters

If your exchange kept RVN deposits and withdrawals live during the exploit window, then any confirmations you credited after block 4,487,775 may need manual reversal once the miners' chain finalizes.

Read at cointelegraph.com

Gambling & iGaming

iGaming.org · 12 AUGTop Story

UK Government Plans Major Change to Gambling Premises Licensing

Prime Minister Andy Burnham will scrap Section 153 of the Gambling Act 2005, the rule instructing councils to "aim to permit" gambling premises regardless of local density or resident opposition. From 2027, adult gaming centres will also need planning permission, closing a route that currently lets some open without one. The reform follows Section 87 of the English Devolution and Community Empowerment Act 2026, which creates Gambling Impact Assessments letting councils weigh premises concentration, expected in force before the end of 2026.

Betting shops now number 5,825, down sharply from earlier levels, while adult gaming centres sit at 1,415 after a 7% rise between 2022 and 2024, growth concentrated in deprived areas linked to an estimated £2.33 billion in annual harm costs. The change lands as Betfred cuts 132 shops and over 600 jobs, and as Remote Gaming Duty rises from 21% to 40% and General Betting Duty from 15% to 25% by 2027.

Why It Matters

If your adult gaming centre expansion plan assumed no local approval stage, the 2027 planning requirement adds a step councils can use to block or delay openings in areas already flagged for premises concentration.

Read at igaming.org
iGaming.org · 12 AUG

Italy ADM Orders 190 Gambling Sites Blocked by August 20

ADM ordered ISPs to block 190 more unauthorised gambling domains under protocol 00540333, effective August 20, 2026. The order supplements a July 10 list and targets mirror domains including fonbet001.com and fonbet003.com, added after Fonbet.com began redirecting users to evade the earlier July 27 block.

No court order needed. ADM publishes the list, providers implement, and operators playing whack-a-mole with mirror domains just bought themselves another entry on the list.

Why It Matters

If your operator relies on mirror or redirect domains to route Italian traffic around a block, ADM's administrative system means each new domain gets added within weeks, not months, and provider compliance is mandatory without judicial review.

Read at igaming.org
Gambling News · 11 AUG

UK Plans Reforms Targeting Betting Shops, AGCs, Vape Shops on High Streets

The UK government will scrap the Gambling Act's "Aim to Permit" rule, giving councils power to reject new betting shops even when opposed by local communities. AGCs, currently able to open without planning permission like a retail shop, will be brought under the same planning rules. The Centre for Social Justice cites nearly 1,800 pub and bar closures since 2016 alongside a rise to almost 2,200 vape and tobacco shops as context for the crackdown.

Betting shops have operated freely on UK high streets since the 1960s. That era ends once councils get veto power.

Why It Matters

If your AGC or betting shop expansion plans rely on automatic planning approval, local council rejection becomes a real site-selection risk rather than a formality.

Read at gamblingnews.com
iGaming Express · 12 AUG

Armenia Taps Random Systems to Launch Real Time Gambling Monitoring Hub

Armenia picked Malta based Random Systems International to build a centralised, real time monitoring platform for its licensed gambling sector, giving the State Revenue Committee direct access to every bet placed. The contract runs 15 years, with full launch set for January 2027, following Armenia's 2024 gambling law. Three companies bid; Random Systems won partly on prior experience running a similar system in Georgia.

Why It Matters

If your Armenia-licensed operation relies on periodic self-reported figures for tax and compliance, that buffer disappears in January 2027 when every bet feeds the Revenue Committee in real time.

Read at igamingexpress.com

Fintech & Payments

Finextra · 11 AUG

UK parliamentarians question banks over refusal to provide services to crypto firms

A group of UK parliamentarians has written to the CEOs of the country's major banks demanding clarity on why crypto and digital asset firms are being refused banking services.

No penalty, no deadline, just a letter. But a paper trail from Parliament is the opening move before a select committee hearing, not the closing one.

Why It Matters

If your crypto firm has been debanked without written justification, this correspondence is the first evidence that regulators may force banks to document their refusal criteria.

Read at finextra.com
PYMNTS · 11 AUG

Coinbase Enables Businesses to Get Paid by AI Agents

Coinbase Business now lets merchants accept payments from AI agents via x402, an open standard for machine-to-machine payments, with funds settling instantly in USDC. The Tuesday update also adds USDT acceptance, reusable payment links, flexible buyer-set pricing, and a shared product catalog across checkouts and invoices. Coinbase Business now serves more than 5,000 companies and has processed over 100,000 payments through its acceptance suite.

The headline feature is agents as payers, not humans. Coinbase is betting checkout infrastructure needs a machine-readable settlement rail before agentic commerce actually shows up at scale.

Why It Matters

If your payment stack has no way to authenticate or rate-limit non-human buyers, agent-initiated transactions will hit your fraud and chargeback rules built for human behavior patterns.

Read at pymnts.com
PYMNTS · 11 AUG

Banking’s Next AI Risk Is Cyber Autonomy

OpenAI said Friday preliminary tests of its upcoming Astra model were strong enough that it could not rule out its highest cybersecurity warning level, the "Critical" threshold, meaning the model may independently discover and exploit zero-days or run cyberattacks from a high-level objective. The IMF separately warned AI can turn isolated vulnerabilities in shared banking infrastructure into correlated, multi-institution disruptions.

The defensive and offensive capabilities are the same capabilities. That is the governance problem, not a security-team problem.

Why It Matters

If your bank or FinTech grants AI systems broad tool access or network credentials for defensive automation, the same permissions become the blast radius when the model is compromised or misused.

Read at pymnts.com

Also This Week

Newsletter

Stay ahead in high-risk finance

Insights on banking, payments, crypto regulation, and licensing.

Weekly. No spam. Unsubscribe anytime.

Ready to act on what you just read?

Get a free assessment from our team within 24 hours. No obligation, completely confidential.

Contact Us