tl;dr
The Ethereum validator queue has flipped from 45 days wait for exit to 44 days wait for entry. SparkKitty is a piece of scary malware you need to know about.
Market Snap

Market Wrap
Tomorrow is the day when the Fed meets again to discuss its latest round of market manipulation of interest rates. Futures prices now imply roughly a one‑in‑three to two‑in‑five chance of a rate hike, up from just over 10% a couple of weeks ago after Brent briefly pushed through $100 per barrel. As The Milk Road pointed out, interest rates are a demand tool – higher rates depress economic activity. By contrast, elevated oil prices are a supply‑side problem. Demand-side tools are not the way to solve supply problems. Government policy – for example not bombing other countries which have a stranglehold on the Strait of Hormuz – is far more relevant.
Curious Cryptos’ Commentary – Ethereum
Just under a year ago, the Ethereum validator exit queue stretched as long as 45 days, with millions of coins waiting to be unlocked from staking.
As of today, more coins than ever have been staked, the exit queue comprises precisely zero coins. The validator entry queue is at 44 days – a complete flip of the previous situation.

I think the implications should be obvious to everyone.
Curious Cryptos’ Commentary – Seed phrase warning
Cyber-security firm Check Point has released a report warning of a major threat to crypto investors via their mobile phones. The full Check Point report can be read here.
SparkKitty malware is designed to analyse images stored on mobile devices for screenshots of wallet seed phrases, which underpin the private keys used by those who self‑custody crypto. It was first identified in early 2024, but recent developments have taken a more sinister turn.
Several apps on both the Apple App Store and Google Play were created as Trojan horses to deliver SparkKitty to unsuspecting users.
On the Apple App Store, the app “币coin” hid SparkKitty in two components I have never heard of before: AFNetworking and libswiftDarwin.dylib. By doing so, the malware avoided detection by the testers. On Google Play, it was delivered in “SOEX”, a purported “messaging and cryptocurrency exchange platform”. SparkKitty was also bundled in some sideloaded applications, especially gambling apps.
Once installed, SparkKitty requests access to the photo gallery. After exfiltrating details of anything that looks like a seed phrase or a QR code that might have a seed phrase embedded into it, that information would be sent to the feral fraudsters to allow the scumbags access to your crypto wallet.
If you have taken screenshots of your seed phrase, you must write it down on a piece of paper, then delete those screenshots. These feral scumbags will keep finding ever more ingenious ways of delivering malware to your devices. Your main line of defence is to be strict, consistent, and perpetually vigilant about your security arrangements.
…
Which brings us back, as always when discussing the security of your cryptos, to Ledger Nano.
In our opinion, Ledger Nano provides simply the best, most secure, and most elegant solution for storing your seed phrase and the signing of transactions. The Flex has a large screen, which is invaluable in identifying potentially malicious transactions prompted by fake apps or websites. For a monthly fee of £7.99, Ledger Recover stores your seed phrase in three encrypted tranches, greatly reducing the need for screenshots or even paper records of the seed.
If you have material holdings of cryptos and you don’t have a Ledger Nano Flex, you know what you must do right now.