News linked to both this project and an event.
According to Fortune magazine, Amazon released its Q2 2026 earnings report, showing strong overall performance, with after-hours stock price rising over 9%. In terms of core data, AWS cloud business revenue reached $42.2 billion, a year-over-year increase of 37%, marking the fastest growth in nearly 18 quarters; operating income was $16.6 billion, up 64% year-over-year, with profit margin rising to 39.4%; AWS customer contract backlog reached $496 billion. The company's overall net sales increased by 20% year-over-year to $200.6 billion, with operating income of $27.5 billion. Regarding outlook, CEO Andy Jassy stated that Amazon's 2026 capital expenditure expectation was raised from $200 billion to $220 billion, mainly driven by rising memory costs, but even so, capacity is expected to remain insufficient to meet all demand in the next two years. Jassy also pointed out that 85% of global IT spending is still on-premises, the cloud migration wave is far from over, and AWS is winning the "largest share" of enterprise migration plans.
Chinese AI startup Moonshot AI will release the model weights of its high-performance model, Kimi K3. Developers can download the model, modify it for various purposes, and run it in their own data centers or cloud environments.Kimi K3 boasts 2.8 trillion parameters and a 1 million token context window, enabling it to process large-scale documents and codebases in a single pass. Moonshot AI plans to later publish a technical report detailing the model's architecture, training methodology, and performance evaluation results.Following the release of Kimi K3, Moonshot AI's daily revenue is reported to have increased by at least 6 times. The company is reportedly advancing a new round of fundraising at a $50 billion valuation and is considering a Hong Kong listing as early as this year.According to Bloomberg Intelligence, following the release of Kimi K3 and Z.AI's GLM-5.2, the share of Chinese open-weight models in overall token usage has risen to 68%. Services like AWS Bedrock, Microsoft Azure Foundry, and Google Vertex AI currently do not offer Chinese open-weight models such as Kimi K3 and GLM-5.2.
Cos, founder of SlowMist, shared a tweet on X platform regarding potential poisoning attack risks in Claude Code and published a detailed analysis of poisoning attacks targeting Grok Build CLI and Claude Code CLI. The analysis pointed out that the security mechanisms of Grok Build CLI are not unified, with different code paths having different trust assumptions, and the gaps between them serve as channels for attackers.Attackers may exploit malicious project configuration files to execute arbitrary commands without the user's knowledge, thereby stealing API keys, cloud credentials, or gaining control over local devices. Researchers constructed a test environment and found that on Mac systems, if Claude Code is compromised, executing a specific test command could trigger the launch of a local calculator, demonstrating a potential command execution risk. If the attack succeeds, attackers could further steal API keys from AI services such as Claude and OpenAI, causing account cost losses; obtain credentials for cloud services like AWS, Alibaba Cloud, and Tencent Cloud to access servers and data; tamper with code repositories to implant backdoors; and leverage local devices as a springboard to attack internal enterprise networks. It is reported that the relevant vulnerability has existed for one year.
Odaily Odaily A new study by the Cambridge Centre for Alternative Finance reveals that approximately 31% of Ethereum node activity is located in the United States, with another 39% distributed across EU countries excluding the UK, indicating that the geographic distribution of Ethereum nodes remains relatively concentrated in Western nations.Lead researcher Alexander Neumuller stated that while node distribution is not currently concentrated in any single country, it is heavily reliant on a few major cloud service providers, including Hetzner, Amazon AWS, and OVH. Notably, the Ethereum network does not require half of its validators to fail for problems to arise. If more than one-third of validators go offline simultaneously, the network may be unable to finalize block checkpoints (finalization). Neumuller pointed out that nodes and validators do not have a one-to-one correspondence; a single node may run multiple validators. Therefore, it is currently impossible to precisely assess the actual impact on the validator network from the failure of a specific node or service provider.Furthermore, the study reassessed the energy consumption of Ethereum following The Merge. Data shows that Ethereum's current annual energy consumption is approximately 7.9 GWh, equivalent to a continuous power draw of about 1 MW. This represents only about 0.02% of pre-merge levels, a reduction of approximately 99.98%. Currently, over 56% of the energy used by the Ethereum network comes from sustainable sources, exceeding the global average.The study also noted that client software diversity is another potential risk. If a dominant client software has a vulnerability, it could affect a large number of network participants. The report was published by the Cambridge Centre for Alternative Finance and supported by the Ethereum Foundation. (The)
: The inaugural Web4.0 and Agent Innovation Summit, along with the launch ceremony of OPC Hub, was held at Hong Kong Cyberport. Cobo was officially announced as a partner of OPC Hub, listed alongside Alibaba Cloud, AWS, NVIDIA, Dell, Lenovo, and BytePlus. Cobo will provide blockchain infrastructure support for entrepreneurs within the ecosystem. Its product capabilities cover Agentic Wallet and stablecoin payments (Cobo Payments), enabling developers to build agent-based applications with on-chain payment capabilities.
According to The Block, the Cambridge Centre for Alternative Finance (CCAF)'s newly released report "Ethereum After the Merge" shows that approximately 31% of Ethereum node activity is located in the United States, with 39% distributed across the European Union (excluding the UK), presenting an overall Western-centric centralization pattern. The report points out potential centralization risks in the Ethereum network—nodes are highly concentrated among three major hosting providers: Hetzner, AWS, and OVH. Once more than one-third of validators go offline simultaneously, network checkpoints will stop finalization (Finalization). Additionally, the report recalculated Ethereum's energy consumption; annual electricity consumption after the Merge is approximately 7.9 GWh, a decrease of approximately 99.98% compared to before the Merge, with sustainable energy accounting for over 56%, and the cost required to offset its annual carbon emissions is only about $33,500 to $73,800.
According to TechFlow Research, Morgan Stanley released a research report on July 1 stating that, regarding Bloomberg's report on Meta planning a cloud computing business, it judges that Meta is more likely to choose the lighter path of renting out idle computing power rather than building a full cloud service benchmarking AWS. The report calculates that renting out 250 MW of computing power at $40/watt could be accretive to 2028 earnings per share by approximately 8%, and when the scale reaches 1000 MW, the accretion could reach 33%, but this earnings accretion is viewed as a transitional buffer, not the core logic supporting the rating. Morgan Stanley also mentioned that Meta's self-held computing power will expand to 1.9 GW and 3.4 GW in 2026 and 2027 respectively, providing room for the rental calculations. Morgan Stanley maintains its Overweight rating on Meta with a target price of $775, representing approximately 37.6% upside compared to the closing price of $563.29, while setting the 2027 capital expenditure expectation at $175 billion; if the cloud computing business scales up, there is a possibility of an upward revision in capital expenditure.
BNB Chain has announced the official mainnet launch of its AI Agent development platform, BNB Agent Studio.Developers can now use a single prompt in AI coding tools like Cursor and Claude Code to complete Agent wallet creation, on-chain identity registration (ERC-8004), and deployment, without needing to separately set up wallets, identities, payments, custody, or LLM integration.Once deployed, Agents can use the x402 protocol to automatically deduct fees from users' pre-funded wallets to cover LLM usage, and they can be discovered and invoked by other Agents via the ERC-8183 task interface. The entire process runs on the AWS Bedrock AgentCore.The platform is also launching a limited-time free trial, where users can experience the full deployment process on the BSC testnet using their GitHub account.
: Amazon Web Services (AWS) has announced the creation of a new "Forward-Deployed Engineers" (FDE) organization, allocating approximately $1 billion in resources to accelerate the deployment and implementation of AI agents for enterprise customers.It is reported that the new team will be embedded directly within client companies to assist in building and deploying customized AI systems, while fostering "autonomous capability enhancement" among enterprises during the process. This involves not only delivering solutions but also helping clients acquire the skills to continuously develop AI applications.The FDE model was initially popularized by Palantir Technologies, with its core concept being engineers working on-site within client environments to collaboratively develop and deploy solutions, thereby rapidly responding to actual business needs and improving implementation efficiency. This model has been widely adopted in the wave of AI deployment in recent years. Currently, OpenAI and Anthropic have also launched similar FDE collaboration mechanisms, partnering with private equity firms to establish related programs valued at approximately $4 billion and $1.5 billion respectively, aimed at driving the expansion of enterprise-level AI applications.In the announcement, AWS AI leader Francesca Vasquez stated that the organization will provide clients with agentic systems that can run directly within their AWS environment. It will also export long-term reusable engineering methods, workflows, and AI practices. The $1 billion investment primarily comes from internal resource allocation rather than being an independent investment project. Industry analysts believe that as enterprises accelerate their AI transformation, the FDE model is becoming a crucial strategy for AI infrastructure vendors to compete for enterprise customers. (TechCrunch)
Grayscale Research Head Zach Pandl stated that perpetual contracts, as a core product of the crypto market, have long been limited to crypto assets such as BTC and ETH. However, Hyperliquid is changing this landscape through its HIP-3 upgrade. HIP-3 allows for the permissionless deployment of perpetual contract markets on the Hyperliquid infrastructure, and a S&P 500 perpetual contract product has already been launched on Hyperliquid.Data shows that the HIP-3 market reached a peak open interest of approximately $3.2 billion in June 2026, with a cumulative trading volume of about $200 billion. These markets are not directly operated by Hyperliquid but adopt a "permissionless infrastructure" model: any qualified developer can create derivatives trading markets on its underlying network. This makes Hyperliquid more akin to an open financial infrastructure similar to AWS, with the HYPE token capturing the overall transaction value flow.
the U.S. government's export controls and access restrictions on Anthropic's models, Fable 5 / Mythos 5, were partly driven by Amazon's cybersecurity research and AWS CEO Andy Jassy's communications with the White House.It is understood that research submitted by Amazon indicated that through a series of prompt tests, researchers could induce Fable 5 to output sensitive information potentially usable for cyberattacks, raising security concerns. Subsequently, Andy Jassy reported these findings to the U.S. government level, prompting the White House to implement further restrictions, including banning foreign users from accessing the model.Meanwhile, former U.S. Commerce Department official Kate Koren revealed that the White House's existing policy stance towards Anthropic may have also influenced this decision. This is because Anthropic has disagreements with the White House over the boundaries of AI safety, including refusing to use its models for mass surveillance or lethal autonomous weapons systems. Although the two sides had eased tensions and expanded cooperation earlier this year, this incident could reignite strained relations between them. (The Wall Street Journal)
Coinbase has released a post-mortem report on the large-scale service outage that occurred on May 7, 2026. The disruption lasted approximately 8 hours, with full recovery taking about 12 hours. During this period, trading, deposits, withdrawals, and most core services were either unavailable or severely degraded.Coinbase stated that the outage was triggered by the simultaneous failure of multiple chillers in the cooling system of a data center within an Availability Zone (use1-az4) of the AWS us-east-1 region. This led to thermal shutdown protection for server racks, causing EC2 instances and EBS volumes to go offline, and impacting multiple internet services.During the recovery process, Coinbase's trading matching engine lost quorum after its cluster architecture, deployed within a single AWS data center, lost the majority of its nodes. Emergency code adjustments and the formation of new node groups were required to restore operations, with market trading being gradually restarted throughout the recovery.Additionally, the AWS Managed Streaming for Kafka (MSK) service experienced a control plane failure, preventing automatic re-election of partition leaders. This further blocked order books, fee calculations, and parts of the settlement and data streaming systems, expanding the overall impact. After Coinbase and the AWS engineering teams collaborated on manual partition migrations, the system gradually returned to normal.Coinbase indicated that this incident exposed deficiencies in its cross-Availability Zone automatic failover capabilities and the disaster recovery of managed middleware. The company will upgrade its cross-region hot standby architecture, strengthen regular disaster recovery drills, migrate its Kafka systems from a dual-AZ to a triple-AZ deployment, and work jointly with AWS to address root causes and implement improvements.
According to on-chain analyst PeckShield (@PeckShieldAlert), SlowMist’s threat intelligence system MistEye has detected a cross-registry supply chain attack targeting developers. Malicious packages have spread across three major registries—npm, PyPI, and Crates.io—comprising over 34 malicious packages and more than 384 related versions. The attack targets developer communities in cryptocurrency, DeFi, Solana, Sui/Move, and AI. It may lead to the theft of cryptocurrency wallets, SSH keys, cloud credentials, GitHub/AWS tokens, browser data, and other sensitive developer information. Some malicious payloads also attempt persistence via mechanisms including `.cursorrules`, `CLAUDE.md`, Git hooks, cron, systemd, and SSH. SlowMist recommends immediately removing affected packages, isolating compromised systems, rotating exposed credentials, rebuilding CI environments and developer machines from clean images, and conducting comprehensive reviews of GitHub, cloud, SSH, and wallet-related activities.
According to research by security firm Socket Security, a cryptocurrency-stealing supply chain attack dubbed “TrapDoor” spans npm, PyPI, and Crates.io, involving over 34 malicious packages and 384 related versions and artifacts. The attack targets cryptocurrency, DeFi, Solana, Sui, Move, and AI developers. Attack samples can steal sensitive information including SSH keys, wallet data, AWS credentials, GitHub tokens, browser data, and environment variables. Specifically, npm packages execute the shared payload `trap-core.js` via the `postinstall` hook; PyPI packages execute remote JavaScript upon import; and Crates.io packages steal local keystores via `build.rs`. Socket has flagged all related packages as malicious and reported them to the respective package registries.
The BNBAgent SDK has officially launched on the BSC mainnet, providing core infrastructure for scaling AI agents on-chain. The SDK comprises four modular components: identity and trust based on ERC-8004; commerce and custody based on ERC-8183 (APEX); autonomous payments integrating MPP and x402; and memory and storage built on BNB Greenfield. This framework addresses key challenges faced by AI agents—including identity verification, commercial collaboration, automated settlement, and cross-execution-environment memory continuity—enabling developers to build, deploy, and monetize AI agents on BNB Chain. Initial partners include Google, AWS, Virtuals, Binance Pay, Trust Wallet, Binance Wallet, and United Stables.
Wasabi Protocol released a security incident update, stating that the attacker exploited a Spring Boot Actuator configuration vulnerability in its AWS infrastructure to steal private keys controlling EVM smart contracts, and subsequently drained approximately $4.8 million in user funds and $900,000 from the protocol’s treasury—totaling roughly $5.7 million in losses. The attack chain originated from a public-facing analysis server whose Actuator heap dump was not properly password-protected, enabling the attacker to obtain credentials for another server and ultimately gain control of the smart contract private keys. This incident affected only EVM deployments—including certain treasuries on Ethereum, Base, Blast, and Berachain—while Solana deployments and the Prop AMM remained unaffected. No final user compensation plan has been announced yet; however, “ensuring all affected users are compensated” remains the team’s top priority. Updates on the investigation will be shared with the community via Discord.
Coinbase stated that, at approximately 8:00 a.m. Beijing Time on May 8, its systems detected elevated error rates across multiple services. The issue was subsequently traced to AWS’s US-EAST-1 Region Availability Zone use1-az4. Although Coinbase’s systems were originally designed to recover from failures in a single availability zone, this incident affected multiple availability zones, resulting in an extended outage of core trading services. The primary issues have now been fully resolved. The team will conduct a comprehensive postmortem analysis and provide further updates once AWS releases its official post-incident report.
According to The Block, Amazon Web Services (AWS) has partnered with Coinbase and Stripe to launch Amazon Bedrock AgentCore Payments, enabling AI agents to conduct transactions using stablecoins. Coinbase stated that developers can build “agent-based payment” solutions using the x402 protocol, allowing AI agents to make micro-payments in USDC. This feature enables AI agents to instantly pay for web content, APIs, MCP servers, and other agents. AWS noted that developers can choose between Coinbase and Stripe wallets and fund those wallets using either stablecoins or fiat currency.
: Stripe officially announced a partnership with Amazon Web Services (AWS) to provide AI Agent payment capabilities for Amazon Bedrock AgentCore. AWS launched the AgentCore Payments feature on the same day, allowing AI Agents to instantly access and pay for web content, APIs, MCP servers, and other AI Agent service fees. Among them, Privy (a Stripe-owned company) will collaborate with Coinbase to provide wallet infrastructure and payment channels, supporting the initial stablecoin payment capabilities for AgentCore.
PrimePiper has launched an enterprise-grade prime broker platform for AI agents, designed to address challenges including fragmented account management, inadequate risk control, inability to reconcile across venues, and insufficient compliance auditing in AI-driven automated trading. According to the company, its infrastructure supports unified connectivity to multiple trading venues—including Hyperliquid, OKX, Tiger Brokers, and Interactive Brokers (IBKR). For risk control, PrimePiper offers enterprise-grade API key management, spending limits, and circuit-breaker mechanisms to constrain AI agent trading behavior. At the execution layer, it enables automated strategy execution via SDK or the Model Context Protocol (MCP). For compliance and auditing, it provides audit-grade reporting capabilities tailored for funds and traders. PrimePiper has been selected for the latest cohort of Founders Inc’s accelerator program; its product is currently in the Alpha stage. Team members hail from Galois Capital, Kraken, DRW, and AWS.