A quick scan of what's moving right now. Meta is rolling out Llama 5 alongside an aggressive custom silicon push, with the MTIA 450 chip doubling memory bandwidth and targeting early 2027 deployment. The US Treasury says it grabbed roughly 1 billion dollars in Iranian crypto under Operation Economic Fury, and Scott Bessent is hinting some of it could land in the federal Bitcoin reserve. The American Reserve Modernization Act would lock any government Bitcoin away for at least 20 years. Salesforce claims its AI agents collapsed a 231-day migration into 13 days. And Coldcard's Mk5 ships with a tougher case and a Gorilla Glass display while keeping the dual secure element design that made the Mk4 popular. Let's dig in.
Meta is having a strange month. On one hand, the Llama ecosystem keeps growing. Over 1.2 billion downloads, 85,000 derivatives on Hugging Face, and the open weights story remains the most credible counterweight to closed frontier models. Meta also shipped Llama Guard 4, LlamaFirewall, and CyberSec Eval 4, which together give developers an actual security stack for agent deployments. That matters because enterprise procurement teams are starting to demand auditable safety controls, and open-weight models have been weak there.
The infrastructure story is also serious. Meta disclosed four generations of its MTIA custom chip in roughly two years. The MTIA 450 doubles HBM bandwidth over the 400, the MTIA 500 adds another 50% on top, and hundreds of thousands of units are already in production. The point is to cut Llama inference costs below what general-purpose cloud providers charge, and to stop being a hostage to NVIDIA's supply schedule.
But then there's Avocado. Meta ran something called the Model Capability Initiative, where U.S. employees had their keystrokes, mouse movements, and screen activity logged to train a next-generation internal model. Six weeks after that program, 8,000 employees were laid off while 6,000 roles stayed open. The payroll savings were positioned as funding for AI infrastructure. And Avocado missed multiple deadlines and underperformed Google's Gemini 3.0 on reasoning, coding, and writing. Meta reportedly considered licensing Gemini to fill the gap inside its own products.
So here's the contradiction. Meta is genuinely winning on open-source distribution and on custom silicon economics. And Meta is genuinely losing on frontier model quality, badly enough that workers trained their replacement and the replacement isn't good enough yet. If you're building on Llama, the cost story is real. If you're betting on Meta to catch Google or Anthropic at the frontier, the internal numbers say otherwise.
Two interesting signals this week on whether agentic AI actually works inside large organizations.
Salesforce moved its entire software development pipeline onto Claude Code with unlimited token access for developers. April 2026 numbers: 50.8% more work items completed per developer, 79% more merged pull requests per developer, and incidents actually dropped 5%. The headline example is a migration of 33 API endpoints to a new cloud-native architecture, estimated at 231 person-days, finished in 13 days. That's roughly 18 times faster with full test coverage. They're also experimenting with one-person and three-person teams instead of traditional Scrum squads.
Salesforce also dropped the Data 360 MCP Server in developer preview, which lets any MCP-compliant agent talk directly to enterprise data with zero-copy integration into Snowflake, Databricks, and BigQuery. And CVS Health is rolling out Agentforce Health across Aetna and CVS Caremark call centers, with AI handling routine context-gathering so human agents focus on the harder conversations.
Meanwhile, ServiceNow used its Knowledge 2026 event to reposition itself entirely. Instead of a workflow platform with AI features bolted on, it's now pitching itself as the governance and action layer for enterprise AI. The AI Control Tower moved from monitoring to real-time enforcement, meaning it can detect an agent doing something outside its permissions and shut it down mid-action. The new Action Fabric lets external agents like Claude or Copilot execute governed work inside ServiceNow, with full audit trails. There's a new product called Otto that acts as a single conversational front-end across all of it, and something called Project Arc, an autonomous desktop agent that runs multi-step work in a sandbox.
The pattern is clear. Salesforce is betting on agents doing the work. ServiceNow is betting on being the layer that watches the agents. Both bets can be right. The interesting question is which one captures more enterprise budget in 2027 when CFOs start asking what they actually got for all this AI spending.
If you care about holding your own keys, this was a notable week. Coinkite shipped the Coldcard Mk5, the first hardware revision to the line since 2022. The improvements are deliberately boring: a 1.54-inch Gorilla Glass display, redesigned tactile buttons, better NFC, a tougher case, and a transparent shell variant so you can physically inspect for tampering. What didn't change matters more. Dual secure elements from two different chip vendors, air-gapped private keys, open-source firmware, Bitcoin-only. No touchscreen, no Bluetooth, no wireless anything. The Mk4 still gets the same firmware updates, so existing owners aren't being pushed to upgrade.
Compare that to the Trezor Safe 7, which went the other direction. Encrypted Bluetooth, magnetic wireless charging, a LiFePO4 battery rated for about 100 transactions per charge, IP67 dust and water resistance, and the new TROPIC01 secure element which Trezor is pitching as auditable and NDA-free. The standout claim is a quantum-enabled bootloader, designed to switch to quantum-resistant signatures when the standards mature.
These are two genuinely different philosophies. Coldcard says the attack surface is the enemy, so minimize it. Trezor says convenience drives adoption, so add wireless and a battery but make every layer auditable. Both are defensible. Neither is wrong.
The reminder of why this matters came from a different corner of the market. A third-party module called SquidRouterModule, installed on some Gnosis Safe wallets, drained 3.2 million dollars from 86 wallets in two hours on May 25. The root cause was inadequate caller authentication. The attacker injected strings to impersonate authorized users and execute transactions without multi-sig approval. The module wasn't built by Safe or by Squid. It was an optional add-on that users opted into.
That's the lesson. The base layer can be solid and you can still get drained by something you bolted onto it. Audit your enabled modules. Revoke what you don't actively use. And if you're using a hardware wallet, the value isn't the screen or the Bluetooth, it's the discipline of keeping the signing environment narrow.
The sovereign Bitcoin story took a real step forward. Patrick Witt from the White House Council on Digital Assets said at Consensus Miami that a formal announcement on the U.S. strategic Bitcoin reserve is coming within weeks. The current federal holding is around 328,372 BTC, worth roughly 24 billion dollars, which already makes the U.S. the largest known state holder.
The mechanism matters more than the number. The American Reserve Modernization Act would lock any Bitcoin in the reserve for a minimum of 20 years unless liquidated to reduce the national debt, require quarterly proof-of-reserve reports, third-party audits, and congressional oversight. Acquisition would be budget-neutral, funded through asset reallocations and criminal forfeitures, with a longer-term path toward asset swaps. Some proponents are floating an eventual target of 1 million BTC, roughly 5% of total supply, accumulated at up to 200,000 per year.
And then there's the 1 billion dollars in Iranian crypto the Treasury says it just seized under Operation Economic Fury. Bessent's language was blunt. They quote, just outright grabbed the wallets. That seizure is now an early test of whether the reserve framework absorbs forfeited assets directly.
Meanwhile, smaller sovereigns are quietly testing the waters. Luxembourg's Intergenerational Sovereign Fund made its first crypto move in Q4 2025, about 7.9 million euros into three U.S.-listed spot Bitcoin ETFs from BlackRock, Bitwise, and ARK 21Shares. The strategic cap is 1% of assets, current exposure 0.75%. By year-end they were sitting on an unrealized loss of about 25.6% on cost, which is awkward for a prudence-driven fund but also the reason the position is small. Abu Dhabi hosted the inaugural Digital Assets Forum in May, anchored by ADGM's regulatory framework, and is positioning itself as a hub for institutional digital finance connecting Europe, Asia, and Africa.
The shape of 2026 is clearer now. State actors are no longer debating whether Bitcoin exists. They're debating how much to hold, how long to lock it, and who signs the custody contract. A 20-year statutory lockup on government Bitcoin is structurally different from an ETF position that can be unwound in a quarter. If the U.S. announcement lands the way Witt described it, the floating supply gets smaller in a way that's very hard to reverse.
One prediction. If the U.S. reserve announcement actually includes a 20-year statutory lockup and seized-asset funding, every other G20 treasury runs the same internal memo within 90 days. Not because they want to, but because they can't afford not to.