HOW USEFUL WAS THIS POST? RATE, LEAVE A COMMENT REQUESTING CHANGES, AND WE’LL AMEND ACCORDINGLY.
From a firmware flaw that helped attackers steal $112 million to AI privacy lawsuits that could impact state oversight, this week’s Risk Wrap explores key exposures across fintech, crypto, gambling, and AI.
53% of Financial Institutions See Cyber and Data Privacy Exposure Rising
The 2026 Annual Litigation Trends Survey by Norton Rose Fulbright examines key litigation risks in finance, energy, healthcare, and technology sectors. AI and cybersecurity risks were prominent across all industries. As for financial institutions:
- 53% reported increased federal exposure when it comes to cybersecurity and data privacy.
- 47% reported increased federal AI-related exposure.
- 44% reported increased state AI-related exposure.
Implications for brokers and their clients:
- Investigate specialist fintech insurance solutions from providers experienced in financial technology risks, including AI-enabled products, cyber threats, and regulatory exposures.
- Review whether existing cyber insurance addresses liabilities arising from the latest technological risks, including those related to AI and blockchain technology.
- Consider strengthening third-party liability to ensure it adequately covers risks introduced by vendors.
Norton Rose Fulbright (June 2026): 2026 Annual Litigation Trends Survey: A midyear industry pulse.
Emerging insurance industries mentioned: Fintech Insurance.
Lines of business mentioned: Cyber Liability Insurance.
CLARITY Act Provision Raises Questions Over State Oversight of AI
There’s growing concern that a provision in the CLARITY Act could give financial institutions broad exemptions from state securities and commodities laws while they test AI and other emerging technologies.
The provision would direct the SEC and CFTC to create a Micro-Innovation Sandbox within 360 days of enactment, allowing approved participants to test “innovative activities,” including AI applications.
Lawmakers had written that participation in the Sandbox could “supersede” state securities or commodities laws. They also stated that the bill should not prohibit enforcement actions related to fraud, deceit, or “any state law of general applicability.”
78 organizations, including the Consumer Federation of America and the Public Investors Arbitration Bar Association, have signed a letter to Senators John Thune and Chuck Schumer, urging lawmakers to reject the provision.
Even though the bill preserves state enforcement authority, critics say the language could still limit meaningful oversight. Corey Frayer, Director of Investor Protection at the Consumer Federation of America, warned that firms could, for example, deploy AI investment advice chatbots that would otherwise face federal or state investor protection requirements.
Opponents also question the provision amid what they view as a broader trend toward deregulation at the SEC. They highlight data security risks as another major concern, especially when AI systems are trained on sensitive customer applications and questionnaires. They argue that without strong safeguards, aggregating that information could create a valuable target for hackers.
Implications for brokers and their clients:
- Consider cyber liability insurance to address risks resulting from data breaches and other cyber threats.
- Consider D&O insurance to protect executives against claims alleging inadequate oversight, governance failures, or mismanagement of AI-related regulatory and compliance risks.
- Investigate specialist AI insurance from providers experienced in emerging risks and evolving regulations, especially where AI activity may face differing requirements across state and federal jurisdictions.
Source: Wealth Management (August 11, 2026). Consumer Groups Warn AI Provision In Crypto Bill Could Weaken State Regulators.
Emerging insurance industries mentioned: Artificial Intelligence Insurance.
Lines of business mentioned: Cyber Liability Insurance, Directors and Officers Liability Insurance.
A Five-year-old Firmware Flaw Just Cost Bitcoin Holders $112 Million
A long-standing firmware flaw in Coldcard wallets has resulted in one of the largest hardware wallet compromises to date. The vulnerability, present since March 2021, weakened the ability for the devices to generate truly random seed phrases. This allowed attackers to derive private keys and steal more than 1778 BTC (around $112.7 million) from over 8600 addresses.
The theft started on July 30, 2026, with more than 1000 BTC reportedly taken within the first 41 minutes. No significant attacker activity has been observed since August 6.
The vulnerability remained undetected until the incident and had been present since firmware version 4.0.1 was introduced. It caused Coldcard’s hardware-based random number generation to be unintentionally replaced with a software-based pseudorandom number generator.
Researchers suggested that attackers may have used AI models to identify and exploit the vulnerability. Coldcard’s parent company, Coinkite, issued a security advisory on July 30 and released a firmware fix the following day. No multi-sig wallets were affected.
Implications for brokers and their clients:
- Investigate specialized digital asset insurance to address theft and loss arising from compromised hot and cold storage, and many other crypto and blockchain-specific risks.
- Review whether tech E&O coverage responds to claims arising from defective software or firmware and resulting financial losses suffered by customers or third parties.
- Review cyber liability coverage for technology vulnerabilities, malicious exploitation, incident response, and resulting financial losses.
Source: The Cryptonomist (August 17, 2026). Coldcard Wallet Breach Drains $112M in Bitcoin After Five-Year-Old Firmware Flaw.
Emerging insurance industries mentioned: Digital Asset and Web3 Insurance.
Lines of business mentioned: Tech E&O and Cyber Liability Insurance.
Ireland Moves to Tighten AML Controls Across the Gambling Sector
Ireland’s gambling sector is set to face tighter AML measures as authorities respond to the increasing sophistication of laundering methods.
Reforms are expected to include greater scrutiny of licensing and closed-loop payment models where withdrawals would have to be returned to the same account used for deposits.
Prepaid cards may receive closer attention, especially when they make it difficult to verify a customer’s identity or source of funds, and greater cooperation between law enforcement, gambling sector stakeholders, and financial institutions is expected.
These changes come alongside the country’s transition to the Gambling Regulation Act 2024.
Implications for brokers and their clients:
- Investigate gambling insurance from providers with cross-jurisdictional expertise that can navigate evolving AML, licensing, and regulatory requirements.
- Consider crime insurance to protect against fraud, theft, and financial losses linked to increasingly sophisticated criminal activity.
- Consider professional indemnity insurance to cover claims arising from compliance, licensing, or other errors as regulatory obligations increase.
Source: iGaming Expert (August 13, 2026). Ireland seeks greater gambling oversight amid money laundering threat.
Emerging insurance industries mentioned: Gambling Insurance.
Lines of business mentioned: Crime Insurance, Errors and Omissions Insurance.
BTCPay Exploit Puts Lightning Network Operators on Alert
Open-source Bitcoin payment processor, BTCPay Server, restricted public remote access to LND-based Lightning Network nodes after attackers stole credentials and an undisclosed amount of funds. Specifically, attackers accessed LND “macaroon” files, which can authorize control over the nodes.
The issue affects BTCPay Server versions earlier than 2.4.2, including release candidates for 2.4.2. Users have been advised to upgrade to version 2.4.2 and it’s recommended that operators check for unauthorized payments, unplanned channel closures, unfamiliar peers, and unexpected changes to on-chain or Lightning balances.
Implications for brokers and their clients:
- Consider digital asset crime insurance to protect against theft of digital assets through compromised credentials, unauthorized transactions, and other sector-specific criminal activity.
- Consider business interruption insurance to cover losses arising when systems must be taken offline.
- Review third-party cyber coverage in case of claims alleging financial loss following a compromised vendor system.
Source: Coinpaper (August 10, 2026). BTCPay Server Restricts Lightning Access After Exploit Drains LND Nodes.
Lines of business mentioned: Digital Asset Crime Insurance, Business Interruption Insurance, Third Party Cyber Liability Insurance.
Gen AI Privacy Cases Test the Boundaries of Existing Laws
Privacy litigation involving gen AI is becoming more common. Early cases included wiretap claims against AI used in call centers and after some favorable rulings, new cases test how these laws apply in other settings.
In Chamberlain v Granola, Inc., the plaintiff claims that Granola’s AI notetaking tool intercepted her Microsoft Teams communications without her knowledge or consent. Similar tools make themselves known to meeting participants, but Granola is designed to be invisible, their website allegedly stating that “other people in the room won’t know it’s there.”
Meanwhile, in Thompson v SoundHound AI, Inc., the plaintiff claims that SoundHound’s smart ordering phone AI, which is used by a few restaurant chains, intercepted and transcribed her calls without consent.
These cases test the law in new ways. For example, in the Granola case, the federal Electronic Communications Privacy Act and the California Comprehensive Data Access and Fraud Act were invoked. Earlier claims only invoked California’s Invasion of Privacy Act.
Legal professionals have advised organizations deploying AI tools that handle communications data to review the potential risks as well as liability limiting provisions in vendor contracts.
Implications for brokers and their clients:
- Review tech E&O cover to confirm whether it responds to AI-related claims.
- Review whether existing professional indemnity cover responds to claims alleging that an AI provider’s advice, services, or implementation contributed to privacy violations.
- Review third-party liability coverage in case of claims brought by customers alleging privacy violations, financial loss, or other harm arising from the use of vendor systems.
Source: Holland & Knight (August 6, 2026). The Wave Continues to Build. GenAI Class Actions Expand into New Industries and Technologies.
Lines of business mentioned: Crime Insurance, Errors and Omissions Insurance.