CEO @AnchorWatch, Bitcoin Custody & Insurance You can't stop Math, molon labe.

PGP
I should scan more codebases
❗️ A security researcher was paid a 115k bounty for reporting a vulnerability to Facebook. It's one of many "HEIF Heist" remote attack paths reported, targeting services that decode attacker-controlled HEIF, HEIC, or AVIF images.
4
54
3,507
Filed a critical vulnerability today, under exposed to Bitcoin
3
4
133
7,312
Summary of the Pod: @AnchorWatch 🤝 @hellmoneypod
AI IS BREAKING BITCOIN Rob Hamilton spent the last six weeks on the front line of the AI War, this is his story. Casey @Rodarmor and Erin Redwing @realizingerin sit down with @Rob1Ham (CEO of @AnchorWatch and Bitcoin) to talk about AI tearing through the Bitcoin ecosystem - from the COLDCARD bug and Red Team to Chinese vs. American models and what comes next for software security. Rob’s conclusion: Bitcoin is getting hit first, but AI is coming for everyone. TIMESTAMPS 0:00 Intro & Bitcoin DEFCON Level 3:24 How Rob was recruited to the AI War 5:53 Kimi K3 changed everything 7:50 @COLDCARDwallet Hack 12:00 Red Teaming the Bitcoin Ecosystem with AI 21:13 AI Security as Spiritual War: Demons in Bitcoin's Code 24:07 The AI Great Oxygenation Event 26:30 The Gell-Mann Amnesia Effect 33:06 Collapse of the Internet Ad Revenue Model 35:06 Transhumanism 37:30 Red Teaming 42:00 Rob's Conscription to the AI War 46:52 AI Attack vs Defense 51:22 Rob is now a Bitcoin Core Contributor 54:56 Don't Trust, Verify 57:36 Pleb vs Dev: Who dominates Bitcoin culture now? 1:01:11 Covenants & Reactive Security 1:19:47 US vs China AI Models 1:27:35 Open Weight Models vs Frontier Labs 1:30:29 Math is Illegal 1:32:25 Raising Kids in the AI Era & Outro
5
5
33
4,436
No better crew than @rodarmor and @realizingerin to sit down with for my first live in person podcast since the Red Team efforts kicked off! @hellmoneypod continues its reign as the bitcoin podcast which has its finger on the pulse of both technology and cultural vibes.
1
4
37
3,704
It’s time boys
You could say @callebtc & I are entering a very Chinese time of our life.
23
167
13,361
I’m on a plane heading to the north east
Telecommunications issues affecting “some frequencies” are causing ground stops across the northeastern U.S., NBC reports. Airports affected by the equipment outage include JFK, LaGuardia, Newark and Philadelphia.
1
20
3,085
Come out Canada, we have you surrounded.
382
319
3,535
93,878
Secret from my old production days at MLG is to make sure you bribe the production team
2
5
926
Honored to join @watchbmtv live in studio with @GraceRemiTV and @realseanhagan as their first outside guest (sorry @isaiahdaustin). We covered @AnchorWatch, Bitcoin Security using AI with the Red Team, and the quantum threat.
7
8
36
3,055
Was listening to @bitcoinoptech and heard my PR get a shoutout! Contrary to the giggling of @bitschmidty and @bitschmidty, I found this bug as a human!!!
I went to create a wallet on Bitcoin Core this morning and my client crashed. I took the verbose error logs, and dumped it into GPT 5.6 Daybreak, which isolated it to a one line of code change. I then had GPT Astra write a draft PR, and when @L0RINC confirmed it was a real issue, I pushed the PR! +1 -1 for the fix, 68 lines of code added for tests, making it a +69 -1 PR
1
23
3,488
I see @typesafeai is going for the make your eyes bleed if you try to read the T&Cs approach 😂
16
1,762
bro theyre gonna do mccarthyism to effective altruists
1
16
2,182
My father was a truck driver. I'm a TRUC driver.
3
1
29
2,237
Blessed X Timeline
1
13
363
Replying to @lopp
2
54
1,925
Day 2 of the @PresidioBitcoin Open Source AI summit is underway! This has been an amazing conference with great talks and fascinating conversations. Lots of learnings and opportunities ahead!
3
1
22
1,703
me irl
10
56
2,440
Im in SF for the @PresidioBitcoin Open Source AI summit! Excited to do a panel later today on Securing Open Source Software with @moneyball @jordanmecom and @_tnull!
4
3
80
2,710
Good security model
1
1
70
2 Days from observing a crash locally to writing the patch, submitting a PR, going through some rounds of reiview and getting merged! Such a privilege to get multiple commits supporting the bitcoin core wallet in the past month! 🥳
I went to create a wallet on Bitcoin Core this morning and my client crashed. I took the verbose error logs, and dumped it into GPT 5.6 Daybreak, which isolated it to a one line of code change. I then had GPT Astra write a draft PR, and when @L0RINC confirmed it was a real issue, I pushed the PR! +1 -1 for the fix, 68 lines of code added for tests, making it a +69 -1 PR
5
2
67
5,693
Me working with @OpenAI Astra for cybersecurity
7
81
4,087
Blockstream "white hat" just sent an unencrypted OP Return " :( "
3,400 BTC just returned to the liquid federation. Looks like ~600 BTC stayed behind.
17
8
240
68,698
Replying to @awayslice
I’m more of a pink hat myself
2
11
584
3,400 BTC just returned to the liquid federation. Looks like ~600 BTC stayed behind.
It looks like ~4,000 BTC just moved from the Liquid Network bridge all at once with an OP Return saying, "we are whitehats. contact us on chain". TXID: c103de95817b43f2df635ec6f35ff126ca26a7c6d20570c4b01866b2b3e69a19
94
78
632
544,638
Entering Day 39
12
6
217
17,873
It looks like ~4,000 BTC just moved from the Liquid Network bridge all at once with an OP Return saying, "we are whitehats. contact us on chain". TXID: c103de95817b43f2df635ec6f35ff126ca26a7c6d20570c4b01866b2b3e69a19
Liquid got got? Liquid Pegout tx 4000/4200 BTC 8db751a650ae2f12006b7e8c69a75e4df360e8afd6b9e05ae0b9fa6458a7b140 Hacker message: "we are whitehats. contact us on chain" c103de95817b43f2df635ec6f35ff126ca26a7c6d20570c4b01866b2b3e69a19
144
238
1,488
1,083,476
I went to create a wallet on Bitcoin Core this morning and my client crashed. I took the verbose error logs, and dumped it into GPT 5.6 Daybreak, which isolated it to a one line of code change. I then had GPT Astra write a draft PR, and when @L0RINC confirmed it was a real issue, I pushed the PR! +1 -1 for the fix, 68 lines of code added for tests, making it a +69 -1 PR
14
6
242
40,021
The year is 2050, I’m in my basement using my analog libsecp256k1 computer to sign a HTLC to buy a cup of coffee
12
15
183
19,485
its so over
nvm we're so back
3
36
4,666
nvm we're so back
3
27
9,640
Maybe not?
Are we so back?
3
17
8,776
Across any sizable volume it'd fall to under 1/9000th the price

ALT Rain GIF

2
3
258
#NewProfilePic Thanks for the still @WalkerAmerica! May have dropped the suit, but still on team Big Bitcoin.
4
4
52
2,932
This is how your email finds me
6
4
146
4,313
Heavy is the head that wears the crown
i accept your challenge
3
1
23
4,895
A message for @stutxo and his @lxdev_ project
a message to the ceo of bitcoin
7
6
82
11,196
I already have one! I upgraded to an orange cummerbund and pocket square for my evening wear
1
1
91
On the latest @hellmoneypod we learn that @realizingerin agrees with @Truthcoin because he CHARMMOGGS @rodarmor
Bitcoin’s Next Civil War Is Already Here Casey @Rodarmor and Erin Redwing @realizingerin dive deep into Paul Sztorc’s eCash Bitcoin fork and the return of the Bitcoin fork wars. The fork implements Drivechain through BIP 300 and BIP 301, allowing Bitcoin to support side chains for privacy, prediction markets, decentralized exchanges, assets, DNS, post-quantum cryptography, and more — without adding those features directly to Bitcoin Core. We break down how hashrate escrow and blind merge mining actually work, the seven proposed Drivechain side chains, the controversial redistribution of 500,000 of Satoshi’s coins, and the central question hanging over the entire proposal: can Bitcoin miners actually be trusted to make this work? TIMESTAMPS: 0:00 Intro 8:18 Fork Wars: @Truthcoin's eCash Bitcoin Fork 11:17 What is Drivechain? BIP 300 & BIP 301 12:56 Satoshi Coin Redistribution & Drivechain Timeline 14:17 Side Chains: Bitcoin's White Whale 18:04 Blockstream's Liquid & Why Side Chains Fail 21:22 Lightning vs Side Chains 23:07 Hashrate Escrow Deep Dive: How BIP 300 Works 28:00 Blind Merge Mining & Core Untouched Soft Fork 32:28 The Seven Proposed Drivechain Side Chains 36:30 Who Validates the Side Chains? 40:40 Are Miners Stupid or is Drivechain Stupid? 44:00 Paul Sztorc's Integrity & Pathological Honesty 51:00 The Fork Wars: Luke vs Paul vs Michael 59:00 What Makes Bitcoin Bitcoin? 1:04:00 Should You Spend Your Bitcoin? Deflationary Psychology 1:13:00 The Future of Bitcoin & Sovereign Individuals
2
1
25
6,234
4 years! Was right when I found out about miniscript, seedsigner of all signers was best positioned to adopt it because it used the embit library which is the first to add miniscript signing support
4
141

ALT GIF by Giphy QA

2
2
107
Red teaming the @WalkerAmerica podcast by eating a rack of ribs on camera
Today on @titcoinpodcast it is my distinct honor and privilege to welcome Bitcoin CEO @Rob1Ham to the show. Let me know if you have any questions for Rob. When he’s not controlling the narrative for Big Bitcoin ™️ , Rob enjoys giggling in the face of adversity and saving open-source Bitcoin projects from clanker attacks through his charitable work with Red Team. Rob also runs @AnchorWatch as a hobby. Live stream on N o s t r o n l y at 2PM EST. Episode available everywhere else in a few days.
8
2
69
7,293
Everything is good for BIG BTC®🟥 Trust the plan
9
3
169
7,137
Replying to @terminaldotshop
WR Cozy% Took 5 minutes in @opencode
1
5
431
Replying to @terminaldotshop
New WR Fable%
1
48
3,626
Cron member btw
3
650
Replying to @terminaldotshop
😂
7
63
7,385
Replying to @terminaldotshop
Fable Cooked
2
51
4,472
Replying to @terminaldotshop
I'm on it
2
120
40,903
As I bury myself out of backlogged emails and notes to myself, I wanted to give a special shoutout to @awayslice and the entire Nostr community who sent me a 5 pound pastrami. I followed Josh’s advice of, “the key ingredient for a pastrami sandwich, is too much pastrami”
14
4
293
10,513
Thank you very much @Otis_Bitmeyer for the fresh beans! Enjoying a nice pour over right now.
3
2
44
2,500
On Friday Anthropic came out with their Claude Code plugin which will do a sweep of codebases. I did some scans across different codebases both internal and of FOSS libraries and wanted to share my thoughts. The pros: 1. If you have not done any codebase scans up to this point, this is the most straight forward experience I've found up to this point. 2. It does find issues! There was 1 or 2 things that were not picked up from other scans that I've done up to this point. 3. It does a very thorough job to screen out false positives. 4. You are able to pick different levels of effort that were clearly explained (picture below) The Cons: 1. It is comically expensive, I ran a max scan that was ~$1,000, easily would have been a third to run this scan with open models. This was in line with the estimates I asked the plugin to provide prior to kicking off the analysis, so if you're curious yourself, just ask for a cost estimate before starting the scan at the level of effort you're interested in. 2. While the precision (true positive) rate was high, the recall (identifying of total confirmed issues) was quite low. The plugin is definitely steered to only showing confirmed true positives, but in a security landscape I'd rather see the larger universe of possible issues than be blinded from seeing the reality. 3. Even as a member of the Trusted Cyber Access program in Anthropic - I WAS STILL DOWNGRADED FOR CYBER CONCERNS USING THEIR PLUGIN SPECIFICALLY MADE FOR CYBER SCANS! 72% of tokens were used by Opus 4.8 after getting numerous downgrades. Opus 4.8 came out in May, using FOSS models that came out in the past month is clearly a better ROI when you consider they are cheaper and better performing. This last one gives me pause, since Anthropic has now granted the ability for enterprises to enable Mythos for scans. As much as I'd love the chance to pony up for the scan, do I have to use their harness for the mythos scans? The model is for sure a critical part of analysis, but the harness I'm finding can be just as important for being able to focus the model to find critical issues. If it is an on rails tool just like this plugin, I'm skeptical that it'd be worth it. Between this plugin and OpenAI's Codex Security SDK, I'd go for OpenAI's. It is also a lengthy and costly scanner you can't control, but the level of insights I got between the two repos was a meaningful difference. For multiple large codebases, I've had the Codex Security Harness fail on occasion and never finish, but its findings were thorough and more additive to my findings when compared to Anthropic's plugin.
7
5
75
8,569
"Have You Said Thank You Once @stutxo?"
1
2
12
2,139
Uh guys, why is my @OpenAI Chat GPT Daybreak Blue speaking mandarin to me?
9
3
56
7,323
This bitcoin core commit is a nice security improvement! Before checking out new code, this script verifies that each commit in the chain is signed by a trusted key, stopping once it reaches, or is proven to predate, a trusted root. The issue was that a divergent history, or even a Git error, could be mistaken for a commit that predated the trusted root, causing the script to fail open and return success without completing the intended verification. Bitcoin Core has a robust human review process, so there wasn't much real risk, but this fix closes an important gap in the code verification workflow. Belt and suspenders! Thank you again @L0RINC for shepherding this, all of the reviewers for testing it, and Kimi K3 for finding it!
I got my first commit merged into bitcoin core today! Last week I started poking scans into bitcoins codebase looking for straight forward wins. Thank you @L0RINC for doing the heavy lifting after my clankers sifted for bugs. Just the start!
8
9
148
9,773
I got my first commit merged into bitcoin core today! Last week I started poking scans into bitcoins codebase looking for straight forward wins. Thank you @L0RINC for doing the heavy lifting after my clankers sifted for bugs. Just the start!
54
17
629
39,993
😂
Libre-relay proves I’m not lying. It requires consensus change to fire the miners to stop this.
1
2
38
5,515
pinging the group chat

ALT Lets Go Boys GIF by Pixel Bandits

2
159
indeed
1
1
3
220
This is proper bitcoin security. Either you do it yourself, or you pay someone to do it for you, but there is no escaping it.
2
3
49
2,779
Mood
27
1
274
10,293
Has anyone noticed that GPT Daybreak (Sol, more cyber access) constantly calls out to claude? Below this is a full tool call doing a re-prompt of the inital subagent process, but to sonnet 5.
4
19
4,312
People said self custody was dead and they'd just leave it on an exchange because it was safer.
"Self custody isn't safe I'll just leave it on an exchange"

ALT Surprised World Cup GIF

1
4
119
5,777
Thank you @BeccaAmilee for the very kind gift! She and the rest of the team at @AnchorWatch have absolutely crushed it these past 2 weeks while I've been, "off at war". I've never been one for nice clothing/accessories, but its my namesake and I'll take good care of it!
26
3
307
22,928

ALT Jerry Seinfeld Reaction GIF

1
3
66
"oh this is could be bad"
7
57
5,062
I have now set up my 2 councils. Monitoring the situation. Red Team: 🇨🇳 Deepseekv4 Pro Kimi K3, GLM5.2 Blue Team: 🇺🇸 GPT 5.6 Daybreak Blue Grok 4.6 Fable/Opus All made possible by @opencode
16
17
273
7,591
"says security researcher @rob1ham"

ALT Apple Tv Hi Its Me GIF

"This has been the wildest 2 weeks of my life" says security researcher @Rob1Ham While Western AI models from Anthropic & OpenAI prevent users from in-depth code auditing, open Chinese models have been an unexpected life raft for developers.
4
3
81
6,804
19 minutes later I have ben blocked from using Daybreak Blue for Red Teaming bitcoin infrastructure. I ALREADY AM PART OF TRUSTED ACCESS????
Just got access to OpenAi's latest cyber model "Daybreak Blue" Ready to have my heart broken again 🥺
30
23
285
29,922
Just got access to OpenAi's latest cyber model "Daybreak Blue" Ready to have my heart broken again 🥺
14
3
117
28,059
Happy Eclipse Season! The vibe checks out for me @realizingerin Thank yoy for being my Bitcoin Bene Gesserit in this crazy past 2 weeks 🙏🙏
🚨 Eclipse season starts TOMORROW 🚨 FTX collapsed on an eclipse. Charlie Kirk was assassinated during eclipse season. Not every eclipse is a major crisis, but they tend to coincide with events that feel unexpected in the moment, but strangely fitting in retrospect.
2
1
30
5,666
Thank you @cbspears & @AsILayHodling for having me on @blockspace today to discuss the Bitcoin Red Team efforts that have been ongoing for the last 2 weeks. We're at an inflection point with AI & policy in the United States. You can not ban math in a free country. Molon Labe.
10
14
75
6,627
DONT YOU DARE TAKE MY MATH AWAY
4
52
2,463
Another morning, another vulnerability found by Kimi K3, with the issue confirmed by the maintainer. While attempting to triage the issue, @PortlandHODL was using @AnchorWatch's Cyber Verification Program seat by @AnthropicAI and was downgraded off of fable. What is the point?
15
28
262
33,326

ALT sesame street glitch GIF

I guess I'm a security researcher now
40
2,869