10th known contributor to Bitcoin Core. Full-Time Open-Source Bitcoin+Lightning Projects @spiral_xyz. Open-Source Bitcoin for 15 years. Mostly reposting @soona.

NY/SF, usually
It’s time for bitcoiners to step up and build. You don’t need to know anything about software development anymore, you just need to know how to write words! We have a golden opportunity to build out agentic payments based on open money, rather than letting agentic payments be captured by megacorps yet again. But we’re squandering it arguing about useless crap instead of building. Play with openclaw, give it a bitcoin wallet (moneydevkit makes this super easy! Also Lexe and phoenixd!), make it do things. If it fails to do what you want, go fix it! Have your agent build that bitcoin domain reseller, that bitcoin airline ticket reseller, or whatever it is you want! Bitcoin doesn’t just happen, it’s built. Join in.
USDC on base seems far more common for 402 payments now than Bitcoin. Recently, even Stripe joined the bandwagon. That’s a centralized stablecoin on a permissioned chain. Agents are starting to use fiat. It’s a huge loss, and in a race, many aren’t even aware that it exists. The scam coins are marching on, and even fiat is evolving. Where are the Bitcoin solutions that attract real users? Which other concept other than buying and selling Bitcoin has actually broken out of the bubble and made it to the mainstream? Bitcoin doesn’t just happen. These missing solutions need to be built by someone. Reject the “Bitcoin wins by hodling” narrative. The devs and entrepreneurs are what keep this project alive and keep marching forward. It’s not the scammy influencers, not the psychotic drama queens, the child-like infighting, or incompetent idiots dancing on the graves of word-class devs leaving Bitcoin. I hope the bear market flushes all that crap away, and we can get back to building stuff instead of tearing it down.
79
145
780
134,895
Yes there are actually many who think like this.
>be me >discover effective altruism >apparently normal charity is inefficient >why donate to random sad thing when spreadsheet can tell you optimal sad thing >fair enough >buy mosquito nets >save lives >numbers look good >feel powerful >couple years later >someone asks an innocent question >why only count people alive today >huh >future people matter too >obviously >my grandchildren shouldn't matter less just because they haven't spawned yet >reasonable.jpg >keep following logic >what about their grandchildren >also yes >what about people in 500 years >sure >5000 years >why not >500 million years >starting to get weird but morality is morality >open calculator >humanity could survive for an astronomically long time >could colonize galaxy >could have trillions upon trillions of descendants >maybe digital people too >maybe simulated civilizations >maybe dyson spheres full of happy uploaded minds >calculator starts smoking >realize currently living humans are rounding error >8 billion people suddenly looking extremely beta >future contains potentially 10^something people >can't even fit beneficiaries in google sheets >new moral priority unlocked >protect the long-term future >stop thinking in units of "people helped" >start thinking in "fraction of cosmic endowment preserved" >malaria? >terrible >but only kills existing humans >AI extinction could delete the entire light cone >nuclear war could permanently derail civilization >bad institutions could lock in terrible values for ten million years >someone invents wrong constitution in 2140 >quadrillions suffer >better fund governance workshop now >friend says maybe we should improve hospitals >explain opportunity cost >friend says hospitals are full of actual sick people >explain scope sensitivity >friend stops inviting me to dinner >need to decide what to fund >easy >expected value >suppose project has one in a million chance of preventing extinction >sounds tiny >but extinction destroys 10^50 future lives >multiply >mother of god >$10 million project has expected value of several galaxies >charity evaluation complete >someone asks where the one-in-a-million number came from >expert judgement >which expert >us >how calibrated >extremely thoughtfully >reduce estimate to one in ten million to be conservative >still beats curing cancer by 38 orders of magnitude >epistemic robustness achieved >someone says maybe project doesn't work >assign 20% chance >still astronomical >maybe project makes problem worse >assign 5% chance >still astronomical >why 5 >because 30 felt pessimistic >publish 46-page report >contains seventeen sensitivity analyses >every sensitivity analysis begins after assuming intervention has positive sign >critic says you're multiplying enormous hypothetical stakes by extremely uncertain probabilities >yes >that's literally why it's important >critic says the uncertainty might be structural rather than numerical >make probability smaller >critic says no, I mean maybe your model is wrong >make probability smaller again >critic begins rubbing temples >discover AI safety >perfect longtermist cause >AI might kill everyone >or create utopia >or seize galaxy >or tile universe with paperclips >or create billions of conscious software minds >finally a problem with numbers big enough for me >start AI safety nonprofit >mission: prevent dangerous AI >hire smartest people available >smartest people immediately start building better AI to understand dangerous AI >interesting >we must understand capabilities to understand safety >we must scale models to study alignment >we must race ahead so less responsible actors don't get there first >we must deploy systems to learn how deployment can go wrong >we must build the thing quickly because building the thing quickly is dangerous >outsider asks why the people most worried about AI apocalypse all work at AI companies >complicated field >company releases stronger model >very concerned >company begins training even stronger model >extremely concerned >company raises $14 billion >concern reaches unprecedented levels >need to influence government >future is at stake >normal democratic process too slow >politicians don't understand exponential curves >public doesn't understand x-risk >experts must guide them >who counts as expert >people who understand x-risk >who understands x-risk >our friends >someone objects that this seems politically convenient >explain we're representing future generations >future generations unavailable for comment >develop concept of value lock-in >terrifying possibility that one ideology controls civilization forever >therefore extremely important that civilization adopts correct values before lock-in >whose values >let's circle back >begin with impartial morality >end with small group of people deciding what quadrillions of hypothetical beings would want >beautiful arc >meanwhile actual humans keep doing annoying things >voting wrong >having parochial attachments >loving family more than strangers >caring about local community >getting upset when told their suffering is cosmically negligible >evolutionary biases everywhere >explain that moral intuition cannot be trusted >except intuition that future digital people count >and intuition that extinction is uniquely bad >and intuition that our probability estimates are sane >and intuition that our institutional choices improve the future >those intuitions survived peer review >someone donates $5k to local homeless shelter >inefficient >could have funded 0.0000000000003% of an AI governance researcher >think of all the simulated people you just killed >okay maybe don't phrase it that way publicly >PR team says "future generations deserve a voice" >much better >journalist asks what longtermism means >say "future people matter" >everyone agrees >great >journalist asks what follows from that >well technically we should redirect enormous resources toward low-probability interventions affecting astronomical futures >journalist raises eyebrow >return to "future people matter" >motte has entered the chat >critic: of course future people matter >me: glad we agree >critic: I don't agree that your institute knows how to help them >me: why do you hate our grandchildren >eventually notice uncomfortable implication >if future value dominates everything >then helping people today mostly matters through effects on future >education matters because future institutions >health matters because future productivity >democracy matters because future trajectory >human beings slowly become instrumental variables in their own moral philosophy >see starving child >feel compassion >check spreadsheet >child's direct welfare contribution negligible >but perhaps childhood nutrition improves national institutional quality >compassion restored >tell myself this is impartial altruism >one day assistant asks obvious question >"how do you know your intervention actually improves the far future?" >silence >open spreadsheet >increase column width >add confidence interval >assistant asks again >"no, I mean how do you know the sign is positive?" >stare into cosmic light cone >10^50 people staring back >none of them exist >none of them can tell me >none of them can falsify my assumptions >realize I have invented the perfect constituency >infinitely important >completely silent >and always represented by me
3
12
4,720
Matt Corallo 🟠 retweeted
Many have reached out, many wanting us to keep going. We didn’t realize to what extent. Due to this vibe shift, we are actively exploring sustainable funding to reconsider and massively scale up. If you’d like to be a part/donate email hello@progressivebitcoiner.org
10
11
103
16,454
Everyone talking about how hard alignment is, Google just left wondering what everyone is talking about.
This sounds pretty well behaved to me.
2
1
8
4,146
Matt Corallo 🟠 retweeted
The team at @lclhostresearch is firing on all cylinders: - Mining Unit: developing FIBRE & P2Poolv2 lclhost.org/blog/mining-unit… -Post Quantum Cryptography Group: exploring threshold signatures (PRAWNS) lclhost.org/blog/prawns/ -Bitcoin Core Unit: doing great work across Core, including some much needed wallet love lclhost.org/programs/ Give them a follow to stay in the loop on important Bitcoin research and applications!
One PR in this tracking issue, the "addHDkey interface," was merged yesterday! Congrats to the author and the newest member of our Bitcoin Core Unit, @pseudoramdom.
4
6
44
5,053
Matt Corallo 🟠 retweeted
I want to give a huge public thanks to @SenLummis and her staff for all their work. There were multiple, repeated attempts at “compromise” throughout this process that would have thrown Bitcoin and open source developers under the bus. At every turn she stood strong for what she believed was the right policy. We are very lucky to have her voice in Congress and she will be sorely missed next year.
10
37
267
11,063
Matt Corallo 🟠 retweeted
Whatever happens to CLARITY, I’m grateful for the extraordinary amount of work that went into protecting software developers along the way. Developer liability was never the biggest-dollar issue in this bill. Market structure, securities law, commodities law—those questions understandably consumed most of the oxygen. But developer protections implicated something more fundamental: whether the law can distinguish between the person who builds a tool and the person who uses it to commit a crime. I’m especially grateful to @SenLummis and her staff. They stood up for that principle under enormous pressure and kept fighting for it through every iteration of the bill. Senator Lummis will be sorely missed when she leaves the Senate. And I’m grateful to my colleagues at @bitcoinpolicy, @fund_defi, @coincenter, and especially @valkenburgh, who kept this issue from becoming an afterthought and consistently defended the rights of people who write and publish open-source software. The legislative fight may be ending for now. The legal one is not. That matters well beyond crypto. As software becomes more autonomous, and agentic commerce increasingly blurs the line between tools and traditional intermediaries, one of the defining legal questions of this century will be whether peer-to-peer systems can exist without making the people who build the software responsible for every bad act committed through it. The answer has to be yes. The work continues.
2
13
59
3,472
Matt Corallo 🟠 retweeted
🚨CLARITY vote on track to FAIL in the US Senate "NO" votes so far from key YES voters on GENIUS: Angela Alsobrooks Mark Warner Ralph Warnock Lisa Blunt Rochester Catherine Cortez Masto John Fetterman Susan Collins
dear senators: we are watching to see how you vote today. do the right thing and GET ON THE BILL!
21
19
147
74,046
1/ Today at 2:15pm, the Senate votes on whether to advance Clarity. CCI is urging all Senators to vote YES. Ahead of this critical vote, we are sharing CCI’s library of documents on the bill: what it does, who it protects, and why it is needed. 🧵
1
10
27
3,230
Matt Corallo 🟠 retweeted
dear senators: we are watching to see how you vote today. do the right thing and GET ON THE BILL!
9
48
357
41,201
Matt Corallo 🟠 retweeted
EA AI safetyism increasingly looks like Marxism-Leninism for the algorithmic age. The old vanguard claimed privileged knowledge of the inevitable course of History. The new one claims privileged knowledge of the probabilistic course of Humanity. Both use an elaborate intellectual framework to reach the same political conclusion: a small group of enlightened people must constrain everyone else for their own good. That has never lead to anything except monumental human suffering.
275
1,582
9,154
1,164,124
Matt Corallo 🟠 retweeted
i’m sorry to inform you that zero knowledge proofs are not the solution to the KYC data leak nightmare we find ourselves in. the solution is less KYC. advanced cryptography for governments is a slippery slope that will only lead to a more controlled society over time.
53
91
776
17,383
Matt Corallo 🟠 retweeted
A harness using a proprietary model with an API key cannot "just copy itself” indiscriminately…because you can block API access…an llm doesn’t have access to its weights
Jacob Coxon's next interview on CBS News (ex Anthropic+Open AI researcher who resigned) "We can't just unplug it because it could be copying itself over to other computers. Like it's not that difficult to find yourself because an AI is just code. It could transfer itself over the internet to a different place and then you unplug it here, but it's actually still over there and maybe it makes 10,000 copies of itself and they're all cooperating." ---- From "CBS News" YouTube channel, (full video link in comment)
2
4
21
5,255
Matt Corallo 🟠 retweeted
Breaking into my local jewelry store tonight and taking 15% of inventory as a community service. You see, someone else could break in tonight and take 100%, so that makes me a good guy.
43
14
393
18,992
Matt Corallo 🟠 retweeted
Every message the attackers send makes it clearer their claim of being whitehats is absurd. Whitehats don't steal funds without a reasonable disclosure attempt, don't hold funds hostage with extortionary struggle sessions, and don't unilaterally take a made-up % of stolen funds. These charlatans should be hunted down by private sector mercs and forced to hand over the stolen funds by any physical means necessary.
Anyway we are going to publish the privatekey to decrypt our conversations afterwards.
23
4
81
10,364
Matt Corallo 🟠 retweeted
Reminder that this guy probably spent 30$ and two hours his this time exploiting this, and he is asking a multimillion dollar ransom.
negotiations for the remaining 598.5 BTC are going well
17
3
45
7,657
Matt Corallo 🟠 retweeted
There's some confusion about what, exactly, was exploited here. I've seen claims that this was a long-standing bug, exploited after the "fix" was pushed to the open source repo but before that fix could be rolled out in production. That does not appear to be true. Instead, it seems that the fix *was* deployed, but inadvertently introduced a new bug which was subsequently exploited. Most of the network was still running official releases, none of which contain the new bug. Those nodes correctly rejected the block containing the exploit and stalled at height 4050335. The timeline is roughly as follows: • 2016-07-12: Range proof caching added • 2017-11-08: Range proofs extended to support assets • 2019-03-19: Range proof cache key "simplified", dropping asset & script fields. introduces Bug A. • 2026-09-01: Bug A "fixed" by extending cache key to include asset + script. introduces Bug B. • 2026-09-06: Bug B exploited, reserves drained, chain split. The original "Bug A" allows some limited cache poisoning because the cache key doesn't commit to the asset and script, allowing a cached result for a range proof for one asset to be applied to a different asset or context. Exploiting this in practice looks quite difficult, since the amount must match the primer and the proof must be genuine. The 2026 "fix" added those missing fields to the cache key, producing a format like: "proof | amount | asset | scriptpubkey" But this unfortunately made the key easier to manipulate and exploit: The four fields are concatenated without separators or length indicators. Since both the proof and the scriptpubkey are variable length, an attacker can stretch the proof and shrink the script to produce the exact same cache key from different proofs, amounts, assets and scripts. This lets an attacker smuggle arbitrary confidential output amounts and junk proofs past the range proof checker without proper validation, which breaks the guarantees that prevent hidden inflation. On-chain evidence suggests that this second bug is what was exploited: Two primer transactions each created an op_return with carefully constructed scriptpubkey and valid range proof for a (presumably) zero value output. blockstream.info/liquid/tx/2… blockstream.info/liquid/tx/7… This produced a cache key like: "<valid proof> | <valid amount> | <L-BTC> | OP_RETURN <negative amount> <L-BTC> OP_RETURN" The exploit transaction then created a large negative op_return output with an invalid range proof: blockstream.info/liquid/tx/f… The invalid proof is padded with bytes corresponding to the primer's valid amount and asset fields, aligning the actual amount and asset fields with the same bytes from the primer's opreturn payload: "<valid proof> <valid amount> <L-BTC> OP_RETURN | <negative amount> | <L-BTC> | OP_RETURN" The exploit transaction could then include a second output crediting the attacker with a large positive value, balanced out by the fake negative amount. Because the success was already cached, the invalid proof was never actually checked and the transaction was accepted as valid by nodes running versions of the software vulnerable to bug B. Although the amounts are blinded, this is the only output with an invalid range proof anywhere in the peg-out's recent ancestry, so this must be where the inflated coins were created. And since the padding only produces a cacheable key under the new format, it must have been the newer bug that was exploited.
Liquid Network's reserves just got drained for 4000 BTC due to an inflation bug in confidential transaction validation caching. each LBTC coin is now backed by only ~4.7% of a real Bitcoin.
18
57
268
64,637
The liquid bug is a great example of why formal verification isn't magic and won't stop everything - when you have a bug in the integration logic, rather than in the verified crypto logic, its just as bad.
13
13
160
17,172