Scalable, Trust-Minimized, Distributed Timestamping with Bitcoin. (This account is controlled by @peterktodd) 97DDKmdqUcdU5EViLYuWydBE72W9inSbJVmN62GyBAGS

OpenTimestamps retweeted
we still won't fly there
🚨🇪🇺 BREAKING: The EU has offered Canada the opportunity to become its first ever “associate member”
1,504
883
26,986
2,593,557
OpenTimestamps retweeted
Today is the 10 year anniversary of the production release of @opentimestamps I created OpenTimestamps in a few weekends because I was frustrated that no-one else had created such an obvious and necessary tool. Since then it has become the global standard for secure timestamps: if you ask an LLM how to create a timestamp, it'll almost certainly suggest using OpenTimestamps. OpenTimestamps has grown to the point where everything from art, to forum posts, to software releases, to war crimes evidence is getting timestamped with OpenTimestamps. Along with some applications I won't be able to talk about for at least a few years... fortunately that data is timestamped! While I have no way of knowing for sure how many documents in total are getting timestamped per second – merkle trees – I can say that as of the past two weeks (beyond that I automatically delete logs) the public calendars I run have averaged about 5 timestamp requests per second from about 60,000 distinct IP addresses. I have no idea what all these people are using OpenTimestamps for. But clearly it's getting fairly popular! Thanks goes out to @realSimpleProof, $TIME, and all the people who have donated directly to the public calendars for their support. OpenTimestamps costs a few hundred a month to run now, along with my time. Without your help keeping OpenTimestamps running would be a lot more painful. If you want to donate, you can do so right here: alice.btc.calendar.opentimes… Thanks also goes to @RCasatta and @BULLBITCOIN_ for running two of the four public calendars. They're one of the reasons why OpenTimestamps doesn't have a single point of failure. Finally, thanks goes to the many people who have contributed code to OpenTimestamps over the years, including entire libraries in languages like java and JavaScript that I have no experience with. In fact, the majority of OpenTimestamps clients are quite possibly using code I didn't write at all! petertodd.org/2016/opentimes…
28
68
410
23,592
OpenTimestamps retweeted
A real OpenTimestamps use case is quietly taking shape around AI compliance. The EU AI Act requires general purpose AI providers to publish summaries of their training content. An independent archive, GPAI Ledger, is preserving these disclosures with SHA-256 + OpenTimestamps proofs anchored to Bitcoin. The archive has already timestamped OpenAI’s GPT Image 2 disclosure. It’s an independent implementation for now, but it shows exactly where OTS can fit as AI compliance records become more important. digital-strategy.ec.europa.e… gpailedger.com/ gpailedger.com/ledger/openai… gpailedger.com/ledger/meta/m… @peterktodd @opentimestamps $TIME
1
3
11
1,314
OpenTimestamps retweeted
Note that censoring the OpenTimestamps calendars is impossible without miner-enforced coin whitelists, at which point Bitcoin isn't even Bitcoin anymore: petertodd.org/2025/opentimes…
1
2
2
347
OpenTimestamps retweeted
🏆 Immutable History: 3rd place in the Cypher Tank Non-Profit category. To preserve history, you first need to protect it. That's why we brought Peter Todd and the Immutable History team to the Lugano City Archives, where OpenTimestamps, Peter's own protocol, is already used to timestamp records and strengthen transparency. It's a powerful example of how Bitcoin technology can protect public institutions, historical records, and ultimately, human rights. This is why non-profit Bitcoin projects deserve funding ⚡🦡
5
16
2,616
OpenTimestamps retweeted
😂😂😂 For my personal data like my photos collection I use a combination of git-annex, PGP signatures, and @opentimestamps The data gets backed up fully offline media. Including Blu-Ray disks – impossible to hack. Sounds like my setup is better than Romania's...
Romania's national land registry is gone. Not encrypted, not exfiltrated. Deleted. That distinction matters more than most coverage has acknowledged. Ransomware groups encrypt your data and sell you the key back. That's a criminal business model with its own internal logic. Wiping a database and walking away doesn't generate revenue. It generates chaos. And when the motive isn't money, you have to ask what it is instead. The land registry isn't a glamorous target. It doesn't make headlines the way a power grid does. But think about what it actually holds: the authoritative legal record of who owns what across an entire country. Every mortgage. Every property title. Every piece of collateral backing a bank loan. Every disputed boundary that's ever wound through a court. Tax assessment rolls. Government planning records. This is the connective tissue of a functioning property economy, and Romania's is now gone. If backups are intact and recoverable, this is a severe incident with a measured recovery timeline. If backups are partial, corrupted, or absent, Romania is looking at something genuinely without modern precedent at national scale: the potential need to reconstruct a country's property ownership record from physical deeds, historical documents, notary archives, and third-party bank records. That process would take years and generate litigation for a decade. Millions of property owners, lenders, and government agencies disrupted simultaneously, all at once, from a single operation. The wiper attack as a technique has a fairly specific genealogy. Sandworm, the GRU-linked group that has been the most active and destructive state-sponsored actor in documented cyberattack history, pioneered the mass deployment of destructive malware against civilian infrastructure. NotPetya in 2017 is the canonical case: disguised as ransomware but actually a wiper, deployed initially against Ukrainian targets and then spreading globally to cause roughly $10 billion in damages. WhisperGate hit Ukrainian government systems in January 2022, weeks before the full-scale invasion. HermeticWiper followed within days of the invasion beginning. The pattern is consistent. Wiper attacks on civilian administrative systems in Eastern Europe, preceding or accompanying escalation in Russian military or political aggression, attributed to Russian state or state-directed actors. Romania is not Ukraine, but it is not a neutral party either. It is a NATO member hosting alliance assets on its territory. It serves as a significant logistics corridor for Western military assistance flowing to Ukraine. Romanian ports on the Black Sea have been part of the grain corridor discussions. Western intelligence assessments have consistently placed Romania among the targets of Russian hybrid warfare operations, which include not just cyberattacks but also disinformation campaigns and physical sabotage activities that have been documented across Central and Eastern Europe over the past several years. No attribution has been formally confirmed for this specific attack, and it would be premature to state one with certainty. But the profile fits a category of operation that intelligence services and private threat researchers have associated with state-level actors, specifically because the operational objective appears to be disruption rather than profit. Criminal groups have no particular incentive to wipe a land registry. There's no ransom leverage in destroyed data you can't restore, no market for exfiltrated property records, no monetization pathway that explains the choice. The choice of target and the choice of technique together point toward someone trying to make a country hurt in slow, grinding, difficult-to-attribute ways. The resilience question is the one that should be generating the most immediate attention. Government administrative databases across Europe exist in a complicated tier below the systems that receive serious security investment. Energy infrastructure, financial clearing systems, military networks: these have formal protection regimes, regulatory requirements, incident response planning, and significant resources behind them. Administrative registries, court databases, social services systems, property records: these frequently run on older infrastructure, with inconsistent backup practices, minimal security staffing, and no particular regulatory mandate driving investment. They are critical in practice but not classified as critical in policy, and the gap between those two things is where attacks like this land. Romania's situation is an extreme version of a vulnerability that is broadly distributed across European government systems. If the Romanian land registry had robust, air-gapped, regularly tested backups, this attack is recoverable, painful and expensive but recoverable. If it didn't, and that is a serious if, then this becomes a case study that every government IT administrator in Europe should be required to review in detail. The recovery window itself has costs regardless of how complete the backups turn out to be. Property transactions that can't close. Mortgages that can't be verified. Court cases that can't proceed. Bank collateral assessments that are in legal limbo. Every day the registry is offline or unreliable, the economic damage compounds. For a country of Romania's size, that's not trivial. One more thing worth sitting with: this attack didn't require physical access, didn't require killing anyone, didn't trigger a treaty response, and may not even result in clear public attribution. The attacker, whoever it is, achieved what a campaign of sabotage might take months and significant operational exposure to accomplish. And they did it in a way that is difficult to respond to under existing legal and treaty frameworks, because a cyberattack on a civilian database in peacetime occupies a genuinely ambiguous space in international law. That ambiguity is a feature, not a bug, for actors operating in the hybrid space. The whole point is that it's not quite war, not quite crime, and not quite nothing. foreigninterference.org/post… #foreigninterference #WiperAttacks #InfrastructureAttacks #CriticalInfrastructureMapping #MunicipalServiceDisruption
4
2
13
6,216
OpenTimestamps retweeted
Canada’s proposed Bill C-22 is so broad that my @opentimestamps calendar service could be a Electronic Service regulated by it. One calendar is hosted in Toronto. C-22 requires metadata retention up to one year; my calendars delete IP logs after two weeks. I will not comply.
🚨 Canada’s Bill C-22 is here & it’s the same surveillance bill from last year's failed C-2. 🚨 What does this mean? ❌ Your metadata would be stored by electronic service providers - for example messaging and email providers - for up to 12 months. ❌ The government would force these companies to build surveillance capabilities directly into their platforms. The government calls it “lawful access” but we know that forcing providers to enable access to encrypted data puts EVERYONE'S privacy & security at risk. 😡 Because we know that there is no backdoor for the good guys only! Help us fight for Canadian's privacy & say no to this surveillance bill. Send a letter to reject Bill C-22 here 👉 internetsociety.org/our-work… #Canada #CanadaBill #Surveillance
3
26
145
12,867
OpenTimestamps retweeted
Replying to @Jeremybtc
It would be great if @x used @opentimestamps on all their posts. It would cryptographically prove beyond a shadow of a doubt that posts were posted when it says they were posted. Probably futile, but cc @nikitabier.
3
2
17
4,703
Good reason to use OpenTimestamps to timestamp your git commits: if GitHub, etc. does something insane to old commits, you can easily spot it because the timestamps will be wiped out. Also, PGP sign your git commits locally! petertodd.org/2016/opentimes…
This GitHub incident is insane. Merge queue commits have been reverting previously merged commits at random. This not only breaks the mental contract teams have with Git in general, but is subtle enough to be really hard to unravel after the fact. githubstatus.com/incidents/z…
3
1
26
15,896
OpenTimestamps retweeted
Maybe you should read the paper, because yeah, exactly one mitigation I mentioned ;)
1
1
9
2,484
The Bob calendar is down right now because it's out of funds to pay tx fees: bob.btc.calendar.opentimesta… If people can send funds to bc1q83zmvtfks2dnvqfgcmxme24kah602cxr59h5v7 to get it back up that'd be much appreciated.
1
5
14
4,522
bellingcat.gitbook.io/toolki… @bellingcat's archival tool for social media posts, videos, and images uses OpenTimestamps. YouTube, Twitter, Telegram, etc. won't provide a signature on their data. So the best verifiable evidence that an archive is authentic is an OTS timestamp.
1
3
16
4,335
Historical reunion of the "Merkle Brothers" tonight at the @SatoshiLugano!!! The @opentimestamps OGs: @RCasatta and @peterktodd!
21
9
89
9,126
OpenTimestamps retweeted
.@internetarchive why are you not using @opentimestamps? We are now in an era of seemless fabrication of content. Thermodynamic impossible to forge proofs of when data was first recorded is literally the most important thing on the internet now.
6
8
86
4,466
OpenTimestamps retweeted
Awesome! Someone finally collected this bounty: github.com/opentimestamps/op…
Replying to @peterktodd
You can construct an @opentimestamps proof for the file @CommerceGov timestamped and the transaction fcf172401ca9d89013f13f5bbf0fc7577cb8a3588bf5cbc3b458ff36635fec00 Bounty: first person who replies with a valid OpenTimestamps proof for this gets 100k sats!
5
4
29
7,392
Triggering some Solana degens for science. 😂 97DDKmdqUcdU5EViLYuWydBE72W9inSbJVmN62GyBAGS
88
59
224
57,397
Interesting project! projecttimestamper.org/
Replying to @projtimestamper
So our independent work at Project Timestamper has been to digitally timestamp these 86 million individual recorded tracks to anchor their authenticity. We embedded these timestamps on the Bitcoin blockchain using the OpenTimestamps service. 6/
4
5
38
18,946
OpenTimestamps retweeted
We just contributed to The OpenTimestamps Calendars on Geyser! Creators using Web3 COAs with OTS should consider this: geyser.fund/project/opentime…
3
9
8,879