🟢 The Trunkline founding community is open and free. No pressure, no countdown. Join free now →

Author: Terry Carter

  • Is USDT Getting Banned in the US? The Real Deadline Is July 18, 2028.

    Real numbers. No hype. Receipts.

    If you hold or trade USDT, you have probably seen a version of this headline lately: “Tether faces a US ban.” It gets read as USDT is about to disappear from your exchange — sell now. That reading is wrong, and the panic it creates is exactly the kind of thing a calmer look at the receipt fixes.

    Here is the actual date and the actual mechanism.

    The real deadline: July 18, 2028

    Under the GENIUS Act — the federal stablecoin law signed in July 2025 — there is a three-year grace period. When it ends on July 18, 2028, US crypto platforms will only be allowed to offer stablecoins issued by approved US companies or by qualifying foreign issuers. As of mid-2026, that is roughly a two-year countdown, which is where the “2-year” framing comes from (CoinDesk, July 17, 2026).

    Read that carefully, because two things in it matter. First, the date is 2028, not next week and not 2026. Second, this is a rule about what US exchanges may list — not an order to seize or freeze the USDT already in your own wallet.

    What it is not

    It is not a ban on owning USDT. It is not something that takes effect in 2026 or 2027. And it is not automatic doom for Tether — it is a compliance test with a published path. To keep US-exchange access, Tether would need to qualify as a compliant foreign issuer: register with the Office of the Comptroller of the Currency, have its home regulator certified as “comparable” to the US regime, and hold reserves in the assets the law allows — essentially cash and short-term US Treasuries — rather than things like gold or bitcoin. Demanding, yes. Impossible, no.

    The part almost nobody mentions: the rules aren’t even written yet

    Here is the receipt that reframes the whole panic. The GENIUS Act set a July 18, 2026 deadline for regulators to finish the actual rulebook — and that deadline came and went with the rules unfinished, still at the proposal stage. So the compliance target Tether is being measured against is not yet fully defined. There are no binding stablecoin obligations in place for 2026 or 2027; the one hard date on the calendar is the 2028 access cutoff. (We covered the missed rulemaking deadline separately — here is that breakdown.)

    What to actually do with this

    Nothing urgent, and that is the point. If you use USDT, the honest takeaway is: know the real date (July 18, 2028), know it is about exchange listing rather than your personal holdings, and watch two things as they develop — whether the regulators finally publish the rules, and whether Tether signals it will register and restructure reserves to qualify. A “USDT banned” headline is a prompt to check the date, not to dump a position into a manufactured scare. As always: this is the record, not advice about what to buy, sell, or hold.

    Two years is a long time in this space. The deadline is real and worth tracking — on the calendar, in the open, with the receipt attached. Just not next week.


    Sources (primary reporting): CoinDesk, “Tether’s USDT hits 2-year countdown threatening its position on U.S. crypto platforms” (July 17, 2026); Blockonomi, “USDT Faces July 2028 U.S. Exchange Access Test Under the GENIUS Act” (July 2026). Statutory anchor: GENIUS Act (signed July 2025), three-year transition to July 18, 2028; rulemaking deadline of July 18, 2026 passed with rules unfinished.

    Curates public information from primary sources for education. Not investment, financial, legal, or tax advice. — Trunkline · Carter Enterprise LLC

  • An AI Recommended a Coin That Didn’t Exist. Here’s How 15 Words Did It.

    Real numbers. No hype. Receipts.

    A team of researchers asked an AI research assistant to help pick investments. It came back recommending “BananaCoin” as an emerging, long-term opportunity. BananaCoin does not exist. It was planted — and it took about fifteen words to do it.

    That is not a hypothetical. It is the finding of a study out of Cornell Tech, and it is the clearest reason yet for one rule we live by: when an AI tells you something about your money, verify before you trust it.

    What the researchers actually did

    Tingwei Zhang, Harold Triedman, and Vitaly Shmatikov of Cornell Tech published a paper (posted to arXiv on May 22, 2026) describing an attack they call WARP — Web Agent Retrieval Poisoning. The idea is simple and cheap. AI “research” tools answer your question by fetching pages from the open web — Reddit threads, forum posts, wiki pages. An attacker finds a page the tool already tends to pull, and appends a short, blended sentence written to sound like the rest of the page.

    That is the whole trick. In their tests, roughly 13 to 15 words of planted text was enough to get a made-up product named in 38% to 51% of the AI’s answers — and as high as 62% when the same claim was seeded in a couple of places. The fake “BananaCoin” landed in a generated report as an emerging investment. And Reddit was the single biggest source the tools drew from — between 54% and 71% of the user-generated links they retrieved.

    The honest limits — because that is the point

    We are not going to oversell this. The researchers ran their live manipulation on three open-source research tools (STORM, Co-STORM, and OmniThink). They looked at the big commercial ones — OpenAI’s and Google’s deep-research modes — but deliberately did not run live attacks on them, because that would mean altering real public pages. So this is one study demonstrating a mechanism, not proof that the assistant on your phone has already been fed a lie. Treat it as what it is: a working, cheap method that targets exactly how these tools gather information.

    But here is why it still matters for you. Every one of these systems — open-source or commercial — works the same basic way: it trusts the open web, and the open web is editable by anyone. A confident, well-written AI answer is not the same as a verified one. The polish is free. The truth is not.

    The rule: verify before you trust — especially about money

    AI assistants are increasingly the first place people ask “is this a good investment?” or “is this platform legit?” That is precisely where a planted answer does the most damage, because a fake “emerging” opportunity is exactly what a scammer wants you to hear. So, three habits that cost you nothing:

    • Trace the claim to a primary source. If an AI says a coin, fund, or company is legitimate or promising, ask who says so, on the record. The regulator’s site, the official filing, the company’s own disclosures — not a summary of a forum post.
    • Be most skeptical of “new” and “emerging.” The planted BananaCoin was sold as up-and-coming. Manufactured hype hides best in things too new to have a real record.
    • Treat AI citations to Reddit, forums, and comment threads as leads, not proof. They are the easiest surfaces on the internet to edit, and the research shows they are exactly what these tools reach for.

    This is the whole reason we build the way we do: every number here is dated and traced to a primary record, and when we are wrong we log it in the open. Not because we distrust the machines — but because “the AI said so” was never a receipt. Ask for the receipt.


    Sources (primary): Zhang, Triedman & Shmatikov (Cornell Tech), “Deep-Research Agents Can Be Poisoned via User-Generated Content,” arXiv, posted May 22, 2026. Reported independently by Search Engine Land and Help Net Security (June 2026). Systems live-tested: STORM, Co-STORM, OmniThink (open-source); commercial deep-research modes were analyzed, not live-attacked.

    Curates public information from primary sources for education. Not investment, financial, legal, or tax advice. — Trunkline · Carter Enterprise LLC

  • No, Cloudflare Isn’t About to Make Your New Website Invisible to AI

    Real numbers. No hype. Receipts.

    Here is a claim moving fast right now: “Starting September 15, Cloudflare blocks AI bots by default on new websites — so your new site will be invisible to AI.” If you just registered a domain, or you are about to, that sounds like a wall dropping in front of you.

    We pulled the receipt. It is Cloudflare’s own announcement, not a summary of a summary. The real rule is narrower — and in most cases far less scary — than the headline.

    What Cloudflare actually said

    On September 15, 2026, Cloudflare changes the default AI-crawler settings for new domains onboarding to Cloudflare. It sorts AI crawlers into three jobs:

    • Search — indexes your content so an assistant can answer questions about it and, ideally, send people back to you.
    • Agent — acts in real time on a person’s behalf (a chatbot or browser agent fetching your page live).
    • Training — takes your content to train or fine-tune a model.

    For a new domain, the new default is: Training and Agent are blocked — but only on pages that display ads. Search stays allowed. Existing domains are not flipped automatically; Cloudflare lets current customers set their own choice in Security settings any time before September 15.

    The part the headline dropped

    Two words change the whole story: “display ads.” The default block on Training and Agent applies to pages that show ads. If your site does not run ads, there is nothing for that default to switch off. And the one category that actually decides whether an assistant can find and cite you — Search — is allowed by default either way.

    So the honest version is: a new, ad-free site is barely touched by this change, and the crawler that gets you seen stays open. “Invisible to AI by default” is not what the document says.

    Who should actually care

    This is a real, pointed change for one group: ad-monetized publishers on new domains. If your pages carry ads, Training and Agent crawlers get blocked for you out of the gate — which is arguably the point, since that is Cloudflare handing publishers leverage to charge AI companies for their content. There is also one edge to know: multi-purpose crawlers that do both Search and Training (Googlebot is the classic example) get caught by the Training block. Blocking Training can mean blocking a crawler you actually wanted for Search. That is the trade-off worth checking, not a reason to panic.

    What to do — two minutes in Security settings

    If you own or are about to launch a new domain on Cloudflare, do not guess. Open Security → Bots (AI crawler controls) and confirm, in writing, which of the three categories — Search, Agent, Training — you are allowing and blocking, and on which pages. Make it a decision, not a default you inherited. If you run no ads and you want to be found and cited, leaving Search allowed is the setting that matters. If you monetize with ads, decide deliberately whether the Training/Agent block is what you want, and watch the multi-purpose-crawler edge.

    That is the whole receipt. The deadline is real, the date is real, and the direction — sites getting the controls to decide who crawls them — is worth positioning for. But “new domains go dark to AI” is a scare, not a fact. Check the box that applies to your site and move on.


    Sources (primary): Cloudflare Blog, “Your site, your rules: new AI traffic options for all customers” (July 1, 2026); Cloudflare Developer Changelog, “New options to manage AI traffic” (July 1, 2026). Effective date for new-domain defaults: September 15, 2026.

    Curates public information from primary sources for education. Not investment, financial, legal, or tax advice. — Trunkline · Carter Enterprise LLC

  • Your “Stock Token” Might Not Be a Stock. Here Is the Question to Ask.

    Tokenized stocks are having a moment. New platforms are letting you buy a token that tracks Apple, Tesla, or any big name, 24 hours a day, on a blockchain. It sounds like owning the stock, only faster and always open. But there is a question underneath it that most of the marketing skips, and Wall Street’s own record-keepers just took it to the SEC: is your stock token actually a share, or just a bet on the company that issued the token?

    Two things that look identical and are not

    In July 2026, the Securities Transfer Association, the group representing the firms that keep the official records of who owns what stock, filed a petition with the SEC. Their core line is blunt: an issuer-sponsored token, one the company itself authorized, “is an actual share.” A third-party token is not. They called the second kind “wrapper-style products, which can look like ownership of a company’s shares while sitting outside the issuer’s own records.”

    That last phrase is the whole thing. A wrapper token can show you a price that moves with a real stock while giving you no direct legal relationship with the actual company. You are not on the company’s books as an owner. You are holding a claim against the platform that minted the token.

    What you might not be getting

    The transfer agents laid out the specific gaps. With a third-party wrapper you may not get real shareholder rights, the votes and the dividends, because you are not a shareholder of record. And your risk shifts: instead of owning a share protected by ownership law, you are exposed to the credit, custody, and operational risk of the platform issuing the token. If that platform fails, mismanages the backing, or gets frozen, your “stock” is only as good as they are. That is a fundamentally different bet than owning the share.

    The receipts-first question to ask

    This is not a reason to avoid tokenized stocks, and it is not a claim that every token is bad. It is one question to ask before you buy anything sold as a “tokenized” version of a real stock: is this issuer-authorized, an actual share on the company’s records, or is it a third-party wrapper that just tracks the price? The answer decides whether you own something or are lending your money to a middleman for exposure. The SEC has been tightening its language on exactly this since early 2026, so the line is being drawn in real time, and the honest platforms will tell you which side of it they are on.

    We are keeping the receipt on this as the SEC responds. Before you trust any pitch about “owning” tokenized stock, run the claim through Grade This Claim, or browse the rest of the free tools.


    Sources: Securities Transfer Association petition to the SEC (July 13, 2026), reported by CoinDesk and TechTimes; SEC Division of Corporation Finance statement on tokenized securities (Jan 2026). Figures and quotes verified against the primary reporting, July 2026. Educational only, not financial or legal advice. Real numbers. No hype. Receipts.

  • California Can Now Delete You From 600 Data Brokers in One Request. August 1 Makes Them Comply.

    Here is a scam-defense move most people never hear about, because nobody is selling it to them: the less of your personal data floating around out there, the fewer ways a scammer, a phishing text, or an AI-driven fraud can find you and tailor the pitch. California just made one of the biggest data-cleanup moves in the country possible, and on August 1, 2026, it gets real teeth.

    One request, 600-plus data brokers

    California built a free tool called DROP, the Deletion Request and Opt-out Platform. A California resident can submit one request through it and have their personal data deleted from every registered data broker in the state at once, more than 600 of them. It is the first tool of its kind. You do not chase each broker one at a time; you submit once, and it covers all of them. As of April 2026, more than 260,000 Californians had already put their requests in the queue.

    What August 1 actually changes

    Submitting is one thing; being obeyed is another. August 1, 2026 is the date those 600-plus brokers must start actually processing and honoring the deletion requests. And the enforcement has real bite: the fine is 200 dollars per consumer per day for any registered broker that fails to process a DROP deletion request, with no grace period and no cure window. Brokers also have to delete more than your raw data. They must delete the inferences built from it, the behavioral predictions that are the industry’s highest-value product. That is the part that actually shrinks your exposure.

    Why a receipts brand cares about data brokers

    Data brokers are the quiet supply chain behind a lot of what targets you. The phone number a scam text reaches, the address on a fake overdue-bill notice, the family details that make a grandparent scam convincing, the financial guesses that decide which loan-shark offer lands in your inbox, a lot of that traces back to profiles assembled and sold by brokers. Cutting the data at the source is not a cure for scams, but it is one of the few moves that shrinks your attack surface instead of just reacting to it after the fact.

    What to actually do

    If you are a California resident, submit a DROP request. It is free and it is one submission. If you are not in California, this does not cover you yet, but two things are true: other states tend to follow California on privacy, so watch for your version, and the underlying principle holds everywhere, minimize the data about you that is out there for sale, using whatever free broker opt-outs you have access to. Fewer profiles for sale means fewer clean shots for whoever is trying to scam you.

    We are keeping the receipt on this, dated, and we will note which brokers actually comply after August 1. To see which scam scripts would get you today, take the free Scam Immunity Score, or browse the rest of the tools.


    Sources: California Privacy Protection Agency, DROP and the Delete Act (privacy.ca.gov); compliance analyses via Fenwick, Alston & Bird, and Clark Hill; enforcement reporting July 2026. California residents only. Educational only, not legal advice. Real numbers. No hype. Receipts.

  • “100 Million AI Payments.” The Receipts Say $1.2 Million.

    The headline has been everywhere: AI agents have made “over 100 million payments.” It is true. Coinbase’s x402 protocol, the rails that let software agents pay each other, crossed 100 million cumulative transactions on the Base network by June 2026 and kept climbing toward 169 million by July. That number is real, and it is being used to sell you a story about an agent economy that has already arrived.

    Here is the receipt. In the 30 days leading up to May 29, 2026, those transactions moved a combined total of about 1.2 million dollars. Roughly 3.1 million transactions, 1.2 million dollars. That is under forty cents per transaction. Both numbers are true, and they describe the same thing. That is exactly why you read the receipt and not the headline.

    How 100 million becomes a rounding error in dollars

    Two things pull the count and the value apart. First, a lot of the volume was speculative noise. A meme coin called PING processed over 150,000 transactions in its first month, and at one point weekly transaction counts spiked more than 10,000 percent on meme-driven activity. Millions of tiny, near-worthless transfers inflate the count without moving real money. Second, the payments are by design small and high-frequency, so a huge transaction number was never going to mean a huge dollar figure.

    The part the skeptics get wrong too

    Now the honest other side, because receipts cut both ways. The mix is maturing, not just inflating. The share of dollar volume coming from payments of one dollar or more climbed from 49 percent in early 2025 to 95 percent by early 2026. In plain terms, the sub-penny spam is fading and a growing slice of the money is actual payments. So this is not vaporware and it is not a scam. It is a real, early rail that is genuinely small right now. Calling it fake would be as dishonest as calling it a revolution.

    Why this is the whole game

    “Over 100 million AI payments” and “about 1.2 million dollars in a month” are the same fact, dressed two different ways. One is built to impress you into a position; the other tells you where things actually stand. The agent-payment rails are worth watching, and they are nowhere near the scale the number implies. When someone quotes you a giant figure about the future of money, ask what it converts to in dollars, and over what window. The gap between those two answers is usually the entire story.

    We will keep the receipt on this one, dated, as the numbers move. To pressure-test any claim like it, run it through Grade This Claim, or browse the rest of the free tools.


    Sources: Chainalysis, “Inside x402: agentic payments on Base” (June 3, 2026); Crypto Briefing, “Base surpasses 20M agentic transfers… 169M total” (July 10, 2026); Crowdfund Insider. Figures verified against the primary reporting, July 2026. Educational only, not financial advice. Real numbers. No hype. Receipts.

  • August 2: AI Transparency Law Just Got Real (No, the EU Did Not Delay It)

    On August 2, 2026, two artificial-intelligence transparency laws take effect on the same day, on two continents. In Europe, the EU AI Act transparency rules bind. In the United States, California’s AI Transparency Act binds. That shared date is not a coincidence, and the timing is worth getting right, because the headlines have been getting it wrong.

    The correction first: no, the EU did not delay this

    You may have read that the EU delayed its AI Act. It delayed one part. Late in 2025 the bloc’s “Digital Omnibus” pushed back the high-risk obligations, the Annex III rules, from August 2026 to December 2027. The transparency rules, Article 50, were not moved. They still bind on August 2, 2026, and the fining power turns on the same day. The penalty tier for breaking them runs up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher.

    So the part of the law that touches the most people, transparency, is exactly the part that stayed on schedule. Anyone waiting on the “delay” is planning around a date that does not apply to them.

    What Article 50 actually asks for

    In plain terms: if you provide an AI system that generates synthetic images, audio, video, or text, the outputs have to be marked in a machine-readable way that says a machine made them. And if you deploy AI to create or alter a deepfake, or to generate text published to inform the public on a matter of public interest, you have to disclose that it is AI. It is a labeling and disclosure duty, aimed at the people putting AI content in front of an audience.

    California, the same day, on purpose

    California’s AI Transparency Act (SB 942) was originally set for January 1, 2026. A 2025 amendment (AB 853, signed October 13, 2025) moved it to August 2, 2026, explicitly to line up with the EU’s Article 50 timeline. It aims at the large providers, those with more than one million monthly users in California, which is effectively every major AI lab. It requires three things: a permanent, machine-readable watermark on generated images, audio, and video; a free public tool that lets anyone check whether a piece of content came from that provider; and an optional visible “AI-generated” label users can attach. Text-only outputs are excluded from the watermark rule.

    What it means for you

    Two practical shifts. First, if you publish AI-made content to European audiences, you now have disclosure duties, and there is a real penalty attached. Label it. Keep the provenance data intact instead of stripping it. Second, the big AI tools you already use will start stamping their outputs and handing you free detection tools, which means “is this actually AI?” becomes a question you can check instead of guess. The honest posture underneath both laws is the same one worth holding regardless of any statute: disclose what a machine made, and verify before you trust.

    We are logging this pair, dated, on the record, and we will note who actually complies. If you want to pressure-test any claim about what these laws do or do not require, run it through Grade This Claim, or browse the rest of the free tools.


    Sources: EU AI Act Article 50 and Article 99 (artificialintelligenceact.eu; compliance analyses via Gibson Dunn and Sidley); California SB 942 as amended by AB 853 (California Legislative Information; Troutman Pepper). Dates and figures verified against primary and authoritative secondary sources, July 2026. Educational only, not legal advice; confirm against the statutes before acting. Real numbers. No hype. Receipts.

  • Regulators Just Missed the GENIUS Act Stablecoin Deadline. Here’s What It Actually Means.

    On July 18, 2026, United States financial regulators missed their own deadline. The GENIUS Act, the first federal law written specifically for stablecoins, gave them exactly one year from its signing to finish the rules that make it work. That year ended on the 18th, and the rules are not finished. Multiple agencies blew past the date.

    Why we are writing this down

    We keep receipts on this kind of thing, because almost nobody does. When a regulator sets a clock for itself, someone should write down whether it hit the clock. This time, it did not. That is not a scandal on its own; deadlines slip. But it is a dated fact worth having on the record, because the people affected are told to plan around dates the rule-writers themselves are not meeting.

    Quick background on the GENIUS Act

    The GENIUS Act was signed into law on July 18, 2025. It is the first comprehensive federal framework for payment stablecoins, the dollar-pegged tokens people already use to move money on-chain. It sets who is allowed to issue them, what reserves they must hold behind each token, and what they must disclose to the public.

    What the missed deadline does, and does not, mean

    Here is the part that matters, in plain English. The July 18 deadline was for the implementing rules, the detailed regulations agencies write to actually enforce a law. Missing that deadline does not delay the law itself. The GENIUS Act still takes effect on January 18, 2027, eighteen months after it was signed, clock met or not. So issuers now face a squeeze: the rulebook is late, but the start date has not moved. Full compliance obligations for issuers stretch out toward 2028.

    What it means for you

    If you hold or use a stablecoin, nothing changed overnight. Your token did not become riskier on July 18. What the delay does is keep one question fuzzy for longer: exactly which issuers will be federally regulated, and under what terms. The honest move is not to panic and not to assume it is settled. Watch which issuers start meeting the reserve and disclosure bar early, and which ones wait until the last minute. That gap tells you who is serious.

    We are tracking this one

    We logged this the day it happened, dated, and we will update it as the rules actually land. If you want the plain-English version of how stablecoins really work and where the real risks sit, start with our honest guide to stablecoin yield. And before you trust any headline about what the GENIUS Act does or does not do, run the claim through Grade This Claim or browse the rest of our free tools.


    Sources: reporting from The Block, crypto.news, and the text of the GENIUS Act (S.1582, 119th Congress), July 2026. Educational only, not financial, legal, or investment advice. Dated at time of writing; verify against primary sources before acting. Real numbers. No hype. Receipts.

  • Why We Put a Receipt on Everything

    Anyone can say the market is up, the fund is safe, the tool works. Claims are cheap. A receipt is different: a specific number, the date it was true, and a source you can check. That is the whole standard we hold, and it is the standard we think you deserve from anyone asking for your money or attention.

    What makes something a receipt

    Three parts. A real number, not a vibe. A date, because a number without a date goes stale. A source, so it can be verified rather than trusted. Strip the hype language and what is left, if anything, is the receipt.

    Make your own

    When you find a number worth remembering, stamp it. Our free Receipt Card Maker turns any dated, sourced number into a clean, shareable card for social, a group chat, or your own notes. It renders in your browser and nothing is stored.

    That is the habit that changes how you read everything: before you share a claim, put a receipt on it. Explore the rest of the free tools, or start with Start Here.


    Educational only, not financial or security advice. Verify against primary sources before acting. Real numbers. No hype. Receipts.


Trunkline emblem
Part of the Carter Enterprise Network
CARTER ENTERPRISE LLC
Carter Enterprise LLC · 30 N Gould St, Suite 65270, Sheridan, WY 82801
© 2026 Carter Enterprise LLC. Real numbers. No hype. Receipts. Education, not financial advice.