Crypto Law Brief: The CLARITY Act's 72-Hour Window, Coldcard Losses Near $89M, and Santos Settles With the CFTC
A market-structure bill is out of floor calendar, a wallet flaw is still draining bitcoin on day five, a manipulation settlement has landed, and a mining hub is closing. What each changes legally:
The CLARITY Act Runs Out of Calendar
The Senate's only scheduled roll-call vote on Monday, August 3, was cloture on a continuing resolution funding the government (H.R. 6500). The CLARITY Act, H.R. 3633, appears nowhere on the agenda, and no cloture motion has been filed for it. With recess beginning after this week, roughly 72 hours remain.
Procedure matters more than politics here. Cloture is a multi-day sequence — file, wait a day, vote, then debate — so with none of it started, the calendar itself is the constraint. The holdup remains the ethics provision on conflicts tied to President Trump's crypto businesses. If the bill slips, oversight stays with agency guidance and enforcement discretion rather than statute, which a future administration can revise without Congress.
Coldcard's Fourth Wave Pushes Losses Toward $89 Million
Galaxy Research's Alex Thorn flagged a fourth attack wave on August 3 that swept roughly 449 BTC from about 709 addresses in two and a half hours. Cumulative losses now approach 1,815 BTC, near $89 million, across some 5,294 addresses. The cause traces to a firmware release after March 2021 that swapped the device's true random number generator for a weaker one, making seeds from affected units derivable. Coinkite has halted shipments and destroyed remaining vulnerable inventory.
The patch is where the legal problem lives: it protects newly generated seeds and does nothing for one already created on affected firmware. That turns a defect into open-ended exposure and frames the question a product liability claim starts with — what Coinkite knew about the 2021 change, and when. Causation is harder, since the loss itself came from a third-party thief.
The CFTC Fines George Santos Over a Bet on Himself
The CFTC settled with former Congressman George Santos over trades in a Kalshi contract on whether he would attend the 2026 State of the Union. He agreed to disgorge $17,569.98 and pay a $17,500 penalty, roughly $35,070, plus a three-year ban from CFTC-regulated markets. Per the order he traded both sides between February 12 and 25, accumulating over 23,800 "No" contracts while publicly signaling he would attend. He neither admitted nor denied it.
The classification is the notable part: the CFTC treated the event contract as a swap under the Commodity Exchange Act, applying anti-manipulation rules to an unregistered retail trader because he controlled the outcome. The same day, New York Attorney General Letitia James sued Kalshi under state gambling law seeking a shutdown and treble penalties — the same product is a regulated derivative in one forum and unlawful gambling in another.
Moscow Bans Mining Through 2032
Prime Minister Mikhail Mishustin signed Resolution 936 on July 25; Russia published it July 31. It bars mining and mining-pool participation in Moscow, the Moscow Region, and parts of Kursk from August 15, 2026, through December 31, 2032, on grid-capacity grounds, affecting roughly 65 data centers and 734 MW of capacity. The pressing issue is the two-week runway: relocating hashrate, unwinding hosting agreements, and testing whether force majeure clauses drafted for outages reach a government ban.
How to Protect Yourself
If you generated a seed phrase on a Coldcard after March 2021, treat those funds as compromised now. Patched firmware does not rescue an existing seed. Move the balance to a wallet whose seed came from unaffected hardware and never reuse the old one. Before migrating, record the device model, purchase date, firmware version, and transaction hashes — that record is the evidence any later claim rests on.
On recourse, report thefts promptly to the FBI's Internet Crime Complaint Center and to exchanges where the coins are likely to surface, since speed is what makes freezing possible. A defect like this can also support product liability or consumer protection claims, and limitations periods may run from discovery rather than purchase. Anyone facing an enforcement inquiry should involve counsel first.
At Coin Counsel, we work with individuals and businesses navigating the legal fallout of crypto fraud — whether you're a victim seeking recovery, a company facing regulatory scrutiny, or a project working to stay compliant in an increasingly complex legal landscape. The rules are evolving fast, and the cost of getting it wrong has never been higher. Contact us at coin-counsel.com to speak with a crypto-focused attorney today.
Disclaimer
This blog post is for informational purposes only and does not constitute legal advice. Reading this content does not create an attorney-client relationship between you and Coin Counsel or Franco Law PLLC. The legal landscape surrounding cryptocurrency is rapidly evolving and varies by jurisdiction. Do not act or refrain from acting based on information in this post without first consulting a qualified attorney. If you believe you have been the victim of crypto fraud, contact us at coin-counsel.com for a consultation.