Meta's Llama 4 lineup is reshaping the open-weight AI conversation, and the White House just decided that lineup doesn't belong inside its new frontier AI framework. The Coldcard exploit keeps grinding, with losses now topping 100 million dollars and possibly climbing toward 130. Bitcoin is quietly holding near 64,000 despite all of it. And the GENIUS Act's rulemaking deadline came and went with U.S. regulators nowhere close to done. Let's get into it.
Meta's Llama 4 has become the story that keeps generating aftershocks. Two models are public: Scout and Maverick. Scout is the fast one, 109 billion parameters with a 16-expert mixture-of-experts setup, and a context window of 10 million tokens. That's roughly 8 million English words in one shot. Multi-document summarization, reasoning over massive codebases, long-form user activity analysis — Scout is built for that.
Maverick is the flagship that's actually deployed. 400 billion parameters, 128 routed experts plus a shared expert, and this is the model powering Meta AI across Facebook, Instagram, and WhatsApp. The clever part: for every token, only about 17 billion parameters activate. The routing decision happens in microseconds. That's how Meta serves hundreds of millions of users without lighting the planet on fire. With FP8 quantization, Maverick fits on a single NVIDIA H100 DGX host. That's a big deal for anyone trying to self-host serious AI.
Then there's Behemoth, still in training. 1.6 trillion parameters, 16 experts, and Meta is claiming leadership on non-reasoning math, multilingual tasks, and image benchmarks. Independent benchmarks have been mixed so far, so temper the hype.
Here's the political layer. Last week the White House finalized its frontier AI framework, co-designed with OpenAI, Anthropic, Google, Microsoft, and xAI. Meta is not in it. The reason is structural: the framework is built around closed developer agreements. Open-weight models like Llama can be downloaded, forked, and run anywhere, which means voluntary safety commitments can't really bind them. So Llama gets excluded, and that exclusion quietly becomes a regulatory blind spot. Everything the framework claims to govern, Llama routes around by design.
Enterprises don't seem to mind. Hundreds of companies are pursuing Llama deployments. AWS Bedrock has said it will offer the enterprise-grade Llama as a managed service, and Microsoft's Azure AI Foundry is lining it up next to OpenAI's offerings. The hyperscalers that built their moats on proprietary APIs are now hosting the model that most threatens those APIs. That tension isn't going away.
The Coldcard situation is worse than it looked last week. Galaxy Research has now traced roughly 100 million dollars in stolen Bitcoin across three confirmed attack waves, with a suspected fourth wave that could push total losses to 130 million. Coldcard is telling affected users to move their coins now, because the exploit is still active on specific models and firmware versions.
Here's what makes this ugly. Block's Bitcoin Engineering team and independent Bitcoin Core developers traced the root cause to a firmware defect that quietly rerouted random-number generation away from the STM32 hardware source and into MicroPython's software randomness. That means the seed phrases those devices generated were never as random as users believed. The compromise happened before anyone touched a keypad.
The uncomfortable lesson: not your keys, not your coins is only half the sentence. If a single device generates your keys, and that device has a silent flaw, you never had the entropy you thought you had. Multi-vendor seed generation, dice rolls, or verifying entropy across independent tools stops being paranoid and starts being basic hygiene.
Interestingly, about 90 percent of the stolen Bitcoin still hasn't moved. And a bunch of very old wallets are suddenly waking up — including a 12-year-old wallet that shifted 31 million dollars on Monday. Some of that is probably affected holders sweeping funds to safety. Some might be something else. Investigators are watching.
Bitcoin itself is shrugging. Price is near 64,000, up on the day. Traders looked past the Coldcard news, past Strategy selling another 1,638 BTC to fund preferred-share buybacks, past a rare U.S.-Japan joint yen intervention that some feared would trigger carry-trade unwinds. Sentiment reads extreme fear on the index, but price action says otherwise. That gap between narrative and tape is usually where interesting things happen.
The GENIUS Act was supposed to give the U.S. its first federal framework for stablecoins. The rulemaking deadline was July 18. That deadline passed. The OCC, FDIC, NCUA, Federal Reserve, Treasury, FinCEN, and OFAC have collectively issued about ten proposals over the past year, but nothing final. There are no penalties for missing the deadline, so the whole thing just slides.
The backstop is January 18, 2027 — that's when the framework has to be effective, whether the rulebook is done or not. Which leaves issuers in an awkward spot: build compliance infrastructure against draft rules that might still change, or wait and risk being unready. Larger issuers with existing banking relationships and legal teams can absorb that uncertainty. Smaller fintechs cannot. The delay is quietly consolidating the market before the rules even land.
BlackRock is not waiting. It just launched two tokenized money market funds explicitly designed to qualify as stablecoin reserve assets under the GENIUS Act, and expanded its European tokenized cash platform to 311 billion dollars in money market fund access. When BlackRock builds infrastructure ahead of final rules, that tells you which direction the rules are actually going.
Meanwhile, the political scaffolding is cracking. Tyler Williams, Treasury Secretary Bessent's top crypto adviser and one of the main architects of the administration's digital asset agenda, left Treasury on July 31. He's the fourth senior crypto official to leave a federal role recently. Prediction markets now put the odds of the broader CLARITY Act passing this year at 27 percent, down sharply. The merged Senate draft surfaced on July 22 and lost Democratic support within days over a rewritten ethics provision. Majority Leader Thune conceded the pre-recess window.
So the picture: stablecoin rules half-written, market-structure legislation stalled, key personnel walking out the door, and private actors building faster than regulators can write. That's not a vacuum. That's a landscape where the biggest, best-capitalized players get to shape the defaults.
Two Lightning stories worth pairing this week, because they show both sides of Bitcoin's payments frontier.
On the bright side: Vida Global, an NYSE American-listed company, is now paying part of its global team in Bitcoin over Lightning, using Voltage Credit. The mechanics are elegant. Voltage extends a revolving line of credit, sends Bitcoin over Lightning to employees instantly, and Vida settles the total in U.S. dollars at month-end. No Bitcoin sits on Vida's balance sheet. No crypto accounting headaches. The books stay boring. It started because an employee in Argentina asked to be paid in Bitcoin instead of a currency that keeps eating itself. Vida says it's the first public company to use Voltage Credit this way. This is the model for global payroll that actually works — dollars in, Bitcoin out, no custody, no tax weirdness for the employer.
Merchant adoption is quietly compounding too. Steak 'n Shake added another 10 million dollars in Bitcoin to its reserve after seeing about 15 percent monthly sales growth in Q4 tied partly to Bitcoin acceptance. Las Vegas businesses are increasingly accepting Bitcoin, motivated by roughly 2.5 to 3.5 percent savings versus card processing fees. Square is waiving Bitcoin processing fees through 2026 for around 4 million U.S. merchants. When the math favors the merchant and the UX is a QR scan, adoption stops being ideological.
Now the dark side. Boltz, a non-custodial Bitcoin swap service and one of the more useful pieces of Lightning infrastructure, just shut down. Not because it got hacked — its non-custodial design actually protected user funds through months of attacks. It shut down because AI-assisted probing was finding and adapting exploits faster than a small dev team could patch them. Attackers now run automated agents that hunt bugs at machine speed. Defenders are still humans reading Slack.
That's the uncomfortable pattern. AI raises the floor for attackers dramatically. Small, principled, non-custodial teams get overwhelmed. And when they fold, users get pushed back toward large custodians who can afford full-time security operations. The AI hacking wave isn't just a security story — it's a centralization pressure. Every self-hosted, small-team piece of Bitcoin infrastructure now has to answer: can we survive being probed 24/7 by adversaries who never sleep and never get tired?
If a hardware wallet firmware bug can vaporize 130 million dollars in coins users thought were safe, and AI-assisted attackers can grind down a competent Lightning team until they close up shop, the honest question isn't whether self-custody is worth it. It's whether your self-custody setup would survive a single silent flaw. Check your entropy sources. Check your firmware. Assume the adversary is patient and automated.