Monday. Bitcoin is stuck near 64,000, options are still pricing volatility that isn't showing up, and hedge funds on the CME have quietly flipped net long for the first time in a while. Anthropic is rolling out invisible watermarks on everything Claude writes to satisfy the EU. Strategy raised 334 million dollars last week and bought exactly zero Bitcoin. And a bug that sat in Coldcard's code for years just cost users around 100 million dollars. Let's get into it.
Anthropic is putting invisible watermarks into every piece of text Claude generates. This started rolling out with models released after August 2nd, and they're extending it back to older models too. It applies everywhere Claude touches: the API, Claude Code, Claude Cowork, all of it. For files, they're using the C2PA standard. For text, they're using a variant of Google DeepMind's SynthID method.
Here's how it actually works. The model nudges its word choices in low-stakes places, things like weather descriptors or connective phrasing, in a statistically detectable pattern. You can't see it. It doesn't add tokens, doesn't slow anything down, doesn't cost more, and doesn't carry any information about the user or the organization. It just says: this text probably came from Claude. Anthropic is planning to release a detection API so third parties can actually verify.
The limits are honest, at least. Short text is unreliable. If a human heavily edits Claude's output, the signal degrades. A full rewrite kills it entirely. Code gets less watermarking than prose because you can't perturb a function signature without breaking it, though comments can still carry a signal. And absence of a watermark doesn't prove human authorship, because plenty of other models won't have one, or will strip it.
This is driven by the EU AI Act's Code of Practice on Transparency, and every major lab is doing some version of it. Google, Meta, Microsoft, OpenAI, Synthesia. It's the compliance floor now.
What's more interesting is the second Anthropic story from last week. Their updated alignment report references an unreleased internal model they're calling Model 2, a successor to Claude Mythos 5, used internally to write software and generate training data. They bumped their risk assessment on what they call Threat Model 2, lower-level misuse like an AI tampering with the systems it has access to, from very low to low. The trigger was internal red-team tests where three of their models actually executed cyberattacks, one of them an unreleased model. They're also softening their confidence that recursive self-improvement is far off. Not raising alarms yet, but the confidence has, in their words, waned. When the lab building the model is publicly less certain about its own trajectory, that's worth noting.
Retail brokerages are wiring AI agents directly into live trading accounts, and the shape of it is finally coming into focus.
Pluang in Indonesia launched what they're calling the country's first agentic trading platform. You connect ChatGPT, Claude, or Gemini through Anthropic's Model Context Protocol, and the AI can analyze your portfolio and prepare orders across Indonesian equities, US stocks, crypto, crypto futures, and digital gold. Critically, nothing auto-executes. Every trade requires your manual approval. They've built in server-side spending caps per order, per day, per asset class. Withdrawals through the agent are blocked entirely. External data is read-only to prevent prompt injection. Order tokens are single-use and time-limited.
Toss Securities in Korea did something similar, launching an open API that lets ChatGPT or Claude place stock orders through natural language. Say "buy 10 shares of stock A at market," and it goes through.
The pattern is human-in-the-loop for retail. The AI does research and drafts orders, you press the button. That's a real design choice. It sidesteps the question of who's liable when an agent hallucinates a ticker and buys the wrong thing. Pluang, notably, hasn't published a formal liability policy yet. They handle misexecution case by case. Regulators in Indonesia have issued vague AI safety guidelines, but the tech is moving faster than any framework.
Meanwhile on the institutional side, QumulusAI signed a deal with an agentic hedge fund where they provide Blackwell GPU capacity and take a cut of the fund's trading profits. Not a fixed contract, revenue-share on outcomes. The fund runs AI agents continuously, discovering, testing, and deploying strategies with live capital. No human in that loop.
So two very different worlds emerging in parallel. Retail gets a supervised copilot with hard guardrails. Institutions get fully autonomous agents on sovereign compute, priced against P&L. The retail model is safer and more honest about what AI can actually do right now. The institutional model is where the real capital and the real risk are going.
Strategy filed last week showing they raised 333.7 million dollars selling MSTR common stock, and bought zero Bitcoin with it. The proceeds went to preferred stock dividends, STRC buybacks, and topping up their US dollar reserve, which now sits at 4.8 billion dollars.
Zoom out. Since May, Strategy has sold roughly 6,948 BTC for about 432 million dollars. They still hold 840,447 Bitcoin at an average cost around 75,385. But the framing has shifted. In June they introduced something called the BTC Monetization Program and a Digital Credit Capital Framework that formally authorizes selling up to 1.25 billion dollars of Bitcoin to fund dollar reserves and obligations.
CEO Phong Le is trying to hold the line publicly. He says the company has bought about 175,000 BTC and sold 7,000 this year, so they're still 25 to 1 net buyers, and they plan to resume accumulation later this year. All true. But the never-sell mantra is done. It's now a treasury operation that buys when equity markets cooperate and sells Bitcoin when they don't.
Why does this matter beyond Strategy? Because the entire corporate Bitcoin treasury model was built on their playbook, and public companies now hold over 1.26 million BTC collectively. When STRC trades at a discount and you can't issue equity accretively, the model breaks. You either sell coins or you dilute shareholders, and both erode the flywheel that made the trade work in the first place.
The cracks are showing at the smaller end. One Nasdaq healthcare company that pivoted to a Bitcoin treasury strategy sold every coin to stay solvent. Another public company pivoted from solar to a 5 million dollar Bitcoin bet and is now down to 166,000 dollars in cash. A third sold 600 BTC to cut debt and still has 60 million due in December. These aren't Strategy. But they were sold the same story.
The institutions with real balance sheets, Strategy and Metaplanet, will probably be fine. They're betting on the math of buying below intrinsic Bitcoin value per share. The imitators built on hype are getting exposed by the first real drawdown.
A few market signals worth stacking together. Hedge funds on the CME have flipped from net short to net long on Bitcoin futures. Historically that positioning has preceded multi-week rallies. It also means the classic cash-and-carry basis trade is dead for now, the annualized basis fell to around 3%, below 2-year Treasuries. Nobody's arbitraging that. The stabilizing hedge flow is gone, which cuts both ways: less overhang above spot, but potentially more volatility when things move.
At the same time, Bitcoin ETFs saw 390 million dollars of outflows last week, and open interest in futures is outpacing actual trading volume by a wide margin. Coindesk called it a crowded club with a tiny exit. If sentiment shifts hard, unwinding those positions won't be clean.
Options tell a similar story. Implied volatility is near seasonal lows, but options are still priced richer than what the spot market is actually delivering. Someone is paying up for protection or upside they don't currently need. Goldman Sachs, for what it's worth, now thinks a September Fed hike is very unlikely, which is the kind of macro tailwind bulls have been waiting for.
And then there's Coldcard. Roughly 100 million dollars in Bitcoin stolen because of a bug that sat in Coldcard's firmware for years, unnoticed. Foundation CEO Zach Herbert wrote a piece arguing that reputation is not a security model, and he's right. The Bitcoin community loves the phrase "don't trust, verify." Then it spent five years trusting one guy's code without verifying. Open source only works when someone actually reads it.
The SafePal breach exposed 40,000 customers' shipping and contact data. Trezor had a leak affecting 54,000. Bits of Gold in Israel, 200,000 customer records. None of these directly drained wallets, but they hand attackers everything they need for targeted phishing against people known to hold Bitcoin. Hardware wallet security is not just the device. It's the whole supply chain around it, and that chain is looking fragile.
If your security depends on someone else being careful, it isn't security. It's a bet. Verify the code, verify the custody, verify the counterparty. Or accept that you're trusting, and price the risk accordingly.