Bitcoin, Bitcoin Mining and Sustainability, Economist Lead researcher at Melanion Greentech Newsletter: Bits of Bitcoin Research ⚡bitcoinishope@getalby.com ⚡

I am excited to finally be able to announce it. 💥 My Bitcoin Market Structure Dashboard is now live! 📈
4
3
20
2,897
Dr. Jan Wüstenfeld retweeted
I built a tracker that notifies me anytime there is a wrench attack reported in the media. For France alone, there is one every. single. week. People are going to get killed over this.
‼️ BREAKING: Our investigations team at Duel is in contact with the Revolut hacker, and we've found out a lot more about how he did what he did. - The hacker got access to government employee accounts using an infostealer. After gaining access to an employee's email, they would log in, add their own recovery email, start to log everything, and silently listen in. - To not get caught, they would instantly delete any email sent that was not intended for the original employee. The inbox was checked 24/7 for any new response to the hacker's sent emails. Upon receiving one, the hacker would instantly download it as a .eml and delete it before the original employee noticed - The hacker says that at first he used to forge court orders (presumably when targeting other companies), but quickly realised that this wouldn't work for Revolut. After some research, they decided the best entity to target was Revolut's Lithuania-based Revolut Bank UAB, which would respond to a European Investigation Order (as shown in the images). - With this stolen email, the hacker sent one request, originally 5 months ago, attached below. Revolut believed it, thinking it was the Italian government, and complied with the order. - From the hacked email, the hacker was able to control and end emails that looked like they genuinely came from multiple Italian government email addresses. - The hacker continuously sent out requests over the course of 5 months. Not once did Revolut ask questions or not send over the information. In one incident, the hacker accidentally sent the wrong document. Instead of realising what was going on, Revolut's support guided them on what to change (shown in an image below) We remain in contact with the hacker and we've requested exclusivity of information related to the story to be kept with Duel. We believe it is in the public's best interest for EVERY piece of information related to this to be released, so that the extent of Revolut's failure can be brought to light, as well as the sheer stupidity of the manner in which the KYC paradigm is currently conducted. The Duel team hopes that Revolut will be held accountable for their lack of due diligence and betraying their customers in such a severe manner, especially given the breadth and depth of the breach. Lives are now at risk. I'm personal friends with one of the victims, and he'll probably have to move houses due to the continued (credible) kidnap threats. We hope to soon release a much more detailed article with more information, emails, screenshots and more.
7
33
187
10,955
Dr. Jan Wüstenfeld retweeted
Happy Release Day to myself! 📙 Digital Real Estate is finally out, and now also available on Amazon for international shipping. What a journey, and at times a struggle, it has been to bring this book to life. After more than three years of researching, writing, rewriting, and refining, it feels somewhat surreal to finally see it released. Thank you to everyone who supported me along the way. I’m looking forward to bringing the book and its thesis out into the world, and to seeing where the coming cycle takes these ideas. This is only the beginning. ⚡
55
46
399
33,648
Dr. Jan Wüstenfeld retweeted
This is awesome! Our @bitcoinpolicy interns out in the wild and proudly representing our little REU program. Great job, Connor (@CJABTC)! We need more of this. Support our little program so we can send more interns to conferences.
Connor Aherne (@CJABTC) is a @AlabamaBTClub student and @bitcoinpolicy summer intern. He did field research for his policy paper (with @jyn_urso) at Bitcoin++ consensus edition this summer, to discover the policy implications of soft forks such as the BIP110 debate.
8
29
4,582
Dr. Jan Wüstenfeld retweeted
5× MONEY WARS (DAS ORIGINAL 😉) ZU GEWINNEN! 👉🏻 Markiert einfach jemanden, der Money Wars unbedingt gebrauchen könnte. Unter allen Kommentaren verlosen wir 5 Exemplare. ⏰ Teilnahmeschluss: 23.08. um 21:21 Uhr Danach entscheidet der Zufall. 🍀 Danke @Hodlcat21 für dieses wundervolle Postdesign 🥰
29
17
59
4,759
Dr. Jan Wüstenfeld retweeted
What a mess. Unfortunately this Trezor address leak will directly lead to an increase in targeted social engineering and potentially wrench attacks. Here are my recommendations for what to do if you were in this breach (or just want to protect yourself against the result of these breaches in the future). Social engineering protection Scammers will use the combination of having your personal information to both target you (phone, email) and convince you that they are legit (using your name and potentially home address as proof that they know you and are here to help). They will contact you via phone or email with targeted lies meant to scare you into talking to them and taking the actions they want you to, in the name of protecting your bitcoin. Ignore any communication from "Trezor" that doesn't come from their official domains (the @Trezor handle, trezor.io are the main ones I know of). You should also ignore communication from "Google" or "Apple" pretending like your email is compromised. They trick you into giving them your email credentials, and then once inside your inbox they can do all manner of things to trick you without Google's typical filters stopping them. Generally a company's support team will never call you on the phone without you contacting them. If they reach out proactively and are trying to get you to take any action to "remain safe" - refuse. Social engineers steal much more money on a regular basis than physical attackers. Most people worry about physical attack more because it sounds scarier, but the bigger risk of actual funds loss is social engineering. Get your suspicion antennae up. Phishing Phishing has a lot of overlap with social engineering. The main difference in my mind is that phishers put in less effort than social engineers. Social engineers may use phishing tools to help them. Phishers are just putting their nets out and trying to get you to make a mistake. Be very suspicious of emails directing you to go to Trezor's website or download a new Trezor app. Triple check the URL for Trezor or any hardware wallet website that you visit. Even if you Google Trezor, there are fake Trezor phishing apps running Google ads that will tell you to type in your seed phrase and then steal your money. Be very careful when downloading or using new wallet apps that you are getting the right one. Wrench attacks The one everyone worries about the most, even though it's the least common. Unfortunately since this breach includes physical addresses, it's possible we will see some wrench attack attempts come from it. Unless you are going to move, the best you can do is try to deter attackers and make sure that if it happens, they can't steal all your money. Distribute your keys and use a multisig to ensure that you don't have enough keys to spend bitcoin at your house. Then consider keeping a small-ish amount of BTC in a single sig wallet that you are willing to give up to make someone go away. We don't recommend the type of duress wallet that uses the same device/software as your main wallet, but when you type in a different PIN it brings up the fake wallet. It's too hard to remember the duress PIN when someone is beating you up, and too easy to give in when they ask you for more after you pay them from the duress wallet. You need to make it so you truly can't send them all your money. Casa recently built Guardian Mode to help protect against social engineering and wrench attacks. It requires the Casa key to sign for all transactions you send. We do a video verification call to make sure you are not being tricked or under duress before signing with our key. Available to Premium+ Casa members. You can also check out an old post we did about physical home security, which unfortunately we have to reshare every year or two: blog.casa.io/a-home-defense-… Very sorry to all the people who were caught up in this. Rough few weeks for bitcoin security. Reach out to us if you need assistance on any of these points.
We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days prior to August 8th, 2026. The data exposed: - Full names - Shipping addresses - Phone numbers - Email addresses The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email). The breach is limited due to Trezor’s strict 90-day data storage policy (we were also able to negotiate the same terms with fulfillment partners, who follow the same policy). All affected customers have been contacted separately by email. Our systems and devices remain secure, but affected customers could experience an increase in phishing attempts. NEVER enter your wallet backup on a website or share it with anyone, and only check for updates on official Trezor channels. We are deeply sorry to the community and those affected. We are investigating this situation and will post updates on our blog: trezor.io/blog/news/recent-c…
24
31
197
36,190
Dr. Jan Wüstenfeld retweeted
🚨 Unpopuläre Meinung: Die Sparkasse wird in den nächsten Jahren mehr Menschen zu Bitcoin bringen als die meisten Bitcoin-Influencer. Warum? Weil Millionen Menschen ihrer Bank mehr vertrauen als jedem Experten auf X.
Ab Oktober sollen Millionen Sparkassen-Kunden Bitcoin direkt in ihrer Banking-App kaufen können. 🚀 Bitcoin wird nicht gewinnen, weil jeder ihn versteht. Bitcoin wird gewinnen, weil er immer einfacher zu kaufen wird. ₿
38
22
342
22,428
Denn das ist alles nur geklaut (eo eo)... Wenn ihr das Originalspiel sucht und nicht die Kopie, dann schaut doch lieber bei @Satoshiskidzz vorbei.
7
10
145
7,604
Dr. Jan Wüstenfeld retweeted
Lieber @marcfriedrich , ich habe AUCH ein Spiel entwickelt, das dich finanziell schlauer macht. Sogar mit denselben vier Eigenschaften. In derselben Reihenfolge. Und demselben Namen. Meins ist von 2023. Deins hab ich bestellt. Bin gespannt. 😅🤡 Leider blockiert von M.F. ;(
Alternativ: Ich habe ein Spiel von @Satoshiskidzz „kopiert“, welches ich vor einigen Wochen bei @NikoJilch im Podcast gesehen habe.
48
37
241
55,428
Dr. Jan Wüstenfeld retweeted
COLDCARD HACK FALLOUT WORSENS AS BITCOIN RED TEAM FINDS CRITICAL BUGS ACROSS ECOSYSTEM @glxyresearch estimates at least 15 different attackers are now exploiting the COLDCARD vulnerability, with new theft clusters still being identified. If your funds were stolen, report it to Galaxy’s @intangiblecoins. Even small victim reports help identify new attackers. One report involving less than 1 BTC led researchers to uncover a previously unknown attack that siphoned 12 BTC from 126 addresses. Meanwhile, Bitcoin developer @callebtc says an emergency Bitcoin Red Team is reviewing wallets, crypto libraries, and infrastructure, finding roughly one critical vulnerability per person per hour. The effort is burning through ~$10,000/day in AI tokens and compute, with funding provided by @OpenSats
58
196
1,410
128,723
Dr. Jan Wüstenfeld retweeted
Knowledge is a privilege. The countries with the highest Bitcoin adoption are not the wealthy, tech-savvy ones. They are some of the most economically destroyed places on earth. Nigeria — 33 million people with no bank account. Venezuela — about 30% of the population uses it because currency lost 99% of its value. People were converting their salaries to Bitcoin within minutes of getting paid not because of blockchain but because their money was worthless the second they touched it Pakistan — #3 globally. Millions of workers sending money home, Western Union takes 5-10% and Bitcoin takes almost nothing. Ethiopia — One of the poorest countries on the planet. War, inflation, no banking infrastructure… Yemen — A country under active bombardment with a collapsed banking system. People receiving money from family abroad when no bank will operate. Should i continue? Cuba, Argentina… but i think you get the point. Understanding Bitcoin is a privilege but needing Bitcoin is not. The people debating this from their laptops already have a stable currency, a bank account, a credit card, and the luxury of time to learn. The people in these countries didn't have the privilege of not needing to figure it out. So yeah it would be the perfect world for everybody to understand the “lingo”, but that doesnt mean its the reality. There are people out there that NEED bitcoin, its not a choice or an option. So i disagree with everyone needing to understand every single term
> Since when was bitcoin “only for developers” or coders or engineers? Life requires you to have a basic understanding of a lot of things. You can't drive a car safely without understanding a bit of physics. You can't navigate personal finances without understanding some math and economics. Indeed, you can't securely use a computer without understanding what a secret is: passwords. If you want to have control of your money, you need to have a basic idea of what a seed is. Yes, that probably means knowing what a random number is. Sorry, but there's a limit to how simple things can be if we want to give people control of their money. And yes, that means that a non-trivial part of the world will always be too stupid to actually take full advantage of cryptocurrencies.
36
13
192
16,940
Doing the important work. 🎉 🧡
Bitcoin Red Team Update: We have been working around the clock, with ~$20,000 of spend up to this point across different services. Funding is secured, I appreciate all the gestures for donations but it is not necessary. The bill is taken care of. We have done over a dozen disclosures up to this point, with 150 repos scanned. The hardest part is coordinating to get things to the right people (thank you @danielabrozzoni for the help) I have a first pass on a bitcoin red team agent harness which only requires an @opencode zen api key, makes it easy for us to use K3 for the actual heavy lifting and then GPT Sol + Fable/Opus + GLM5.2 for supporting documentation. While it is powerful, having found critical issues, I would view this as only version one. There is a lot of iteration I'm looking forward to improving on. Our goal is to open source the harness so it can be pointed at internal repositories for insights so the hardening of defenses can go deeper than the code which is made public. We also have been connected with OpenAi for some help so I could manage getting the @OpenAI Cyber Harness running as well (thank you @lylepratt ). Its a much more expensive scan, but well worth it for load bearing portions of the bitcoin ecosystem and has already yielded good results. Goals for tomorrow are scale in processes and systems so we can do a better job and automating full end to end functionality to get humans out of the loop for the heavy lifting. The first mile (requests/staging) and last mile (handoff of reports) are the choke points right now. Thank you @stutxo @callebtc @benthecarman @thesimplekid and so may more.
1
6
1,822
Dr. Jan Wüstenfeld retweeted
Replying to @OpenAI
@OpenAI help, need to change my org id for cyber program
7
8
64
8,698
Dr. Jan Wüstenfeld retweeted
Who died and made @Rob1Ham Bitcoin CEO?
16
1
132
4,783
Dr. Jan Wüstenfeld retweeted
I have spent over $10,000 scanning 100+ bitcoin ecosystem related libraries looking for vulnerabilities with Kimi K3 running as quarterback. Myself and a small "Red Team" have found multiple serious vulnerabilities impacting the ecosystem. They vary in scope severity, but this is a call to action. For any critical tier vulnerability that was identified if I was able to immediately demonstrate a POC (proof of concept), I have already responsibly disclosed to the maintainers. HERE IS HOW YOU CAN HELP ME IF YOU ARE NOT TECHNICAL: - please share with me any repository that is on github that I can scan, we want to cast a wide net. It takes a few moments for you to link github accounts, we'll take it from there - if that project does not have a SECURITY.md make an issue asking the dev to list one IF YOU ARE TECHNICAL: - If you are a maintainer or contributor to a project, I may have already scanned your repo, hit me up I'll share the results, if not I'll add your project to the list. - If I can trust you to do larger review to start looking through this stuff to give me more eyes let me know. AI Has forever changed software development. Tomorrow marks 1 week of Kimi k3 being live in open weights. We are going to accelerate.
289
429
2,522
226,694
Dr. Jan Wüstenfeld retweeted
The commits (code changes) that introduced Coldcard's low entropy bug, changed around 2500 lines of code. These were changes to the most important parts of their codebase, ensuring that the seeds have enough entropy so that.... your coins don't get stolen. The code comments for all these changes? "runs" and "x" Hard to believe, but true.
JUST IN: Dustin Dettmer (@dusty_daemon) digs into the COLDCARD firmware commit history to uncover what actually happened in the code to introduce one of the worst bugs for self-custody in recent bitcoin history open.substack.com/pub/btcpp/…
26
57
482
49,835
Dr. Jan Wüstenfeld retweeted
in 2019, i locked myself out of a hardware wallet by using a silly long passphrase I lost 0.3 BTC and seriously considered giving up on bitcoin i was in my mid 20s, I'd just got out of debt and put my savings into bitcoin please know that things can and will get better
72
38
767
82,077
Dr. Jan Wüstenfeld retweeted
The only Coldcards that are not affected by the fiasco are the ones that are still running the original Trezor code on them
73
220
2,634
177,575
Dr. Jan Wüstenfeld retweeted
This is worse than any previous Bitcoin exchange hack. It is arguably one of the worst things that could happen. The popular hardware wallet COLDCARD has a faulty random number generator (RNG). Funds are being drained from ordinary users’ hardware wallets as you read this. Users first reported to Block less than 24 hours ago that funds were moving out of their wallets. The exploit was most likely discovered with the help of AI. Block has confirmed that the RNG is broken. You know what that means. There are likely already multiple attackers competing for the affected BTC. Many more will join very soon. Nobody knows how much BTC is affected. Nobody knows how many users are affected. This attack has only just begun, and it will continue until all affected BTC has been drained unless users secure their funds first. Inevitably, many Bitcoiners will not hear about the incident early enough to respond in time. I am truly saddened for everyone affected, especially those who may have just lost their life savings. The worst part is that they did everything right.
202
466
3,422
290,870
Dr. Jan Wüstenfeld retweeted
My new favorite Bitcoin book.
13
6
111
3,027