Pinned Tweet
pinned tweet for threads
2
9
1,205
Congrats to Vladimir "astOwOlfo" Ivanov the eleventh Winner of the Hutter Prize
The Human Knowledge Compression Contest (widely known as the Hutter Prize) is alive and kicking. This year has seen the largest progress in its 20y-history. We received three winning submissions within one month with a remarkable total improvement of nearly 10% prize.hutter1.net/ (and ~1/3rd the size of the zip-file!). Congratulations to Ibrahim Marcouch & Kaido Orav & David Freelan & Vladimir Ivanov.
16
37
871
36,788
JK retweeted
I've resurrected the comonad.com/reader, interleaved a ton of contemporaneous content I had stored elsewhere, and made a couple of the articles interactive by moving their demo code into web assembly using modern GHC. Please let me know if you run into any issues. #Haskell
7
27
157
10,583
There's some confusion about what, exactly, was exploited here. I've seen claims that this was a long-standing bug, exploited after the "fix" was pushed to the open source repo but before that fix could be rolled out in production. That does not appear to be true. Instead, it seems that the fix *was* deployed, but inadvertently introduced a new bug which was subsequently exploited. Most of the network was still running official releases, none of which contain the new bug. Those nodes correctly rejected the block containing the exploit and stalled at height 4050335. The timeline is roughly as follows: • 2016-07-12: Range proof caching added • 2017-11-08: Range proofs extended to support assets • 2019-03-19: Range proof cache key "simplified", dropping asset & script fields. introduces Bug A. • 2026-09-01: Bug A "fixed" by extending cache key to include asset + script. introduces Bug B. • 2026-09-06: Bug B exploited, reserves drained, chain split. The original "Bug A" allows some limited cache poisoning because the cache key doesn't commit to the asset and script, allowing a cached result for a range proof for one asset to be applied to a different asset or context. Exploiting this in practice looks quite difficult, since the amount must match the primer and the proof must be genuine. The 2026 "fix" added those missing fields to the cache key, producing a format like: "proof | amount | asset | scriptpubkey" But this unfortunately made the key easier to manipulate and exploit: The four fields are concatenated without separators or length indicators. Since both the proof and the scriptpubkey are variable length, an attacker can stretch the proof and shrink the script to produce the exact same cache key from different proofs, amounts, assets and scripts. This lets an attacker smuggle arbitrary confidential output amounts and junk proofs past the range proof checker without proper validation, which breaks the guarantees that prevent hidden inflation. On-chain evidence suggests that this second bug is what was exploited: Two primer transactions each created an op_return with carefully constructed scriptpubkey and valid range proof for a (presumably) zero value output. blockstream.info/liquid/tx/2… blockstream.info/liquid/tx/7… This produced a cache key like: "<valid proof> | <valid amount> | <L-BTC> | OP_RETURN <negative amount> <L-BTC> OP_RETURN" The exploit transaction then created a large negative op_return output with an invalid range proof: blockstream.info/liquid/tx/f… The invalid proof is padded with bytes corresponding to the primer's valid amount and asset fields, aligning the actual amount and asset fields with the same bytes from the primer's opreturn payload: "<valid proof> <valid amount> <L-BTC> OP_RETURN | <negative amount> | <L-BTC> | OP_RETURN" The exploit transaction could then include a second output crediting the attacker with a large positive value, balanced out by the fake negative amount. Because the success was already cached, the invalid proof was never actually checked and the transaction was accepted as valid by nodes running versions of the software vulnerable to bug B. Although the amounts are blinded, this is the only output with an invalid range proof anywhere in the peg-out's recent ancestry, so this must be where the inflated coins were created. And since the padding only produces a cacheable key under the new format, it must have been the newer bug that was exploited.
Liquid Network's reserves just got drained for 4000 BTC due to an inflation bug in confidential transaction validation caching. each LBTC coin is now backed by only ~4.7% of a real Bitcoin.
18
57
268
65,514
JK retweeted
here are the transactions that caused the liquid consensus split and inflation bug, prior to the peg-out 1. two valid setup txs primed the rangeproof cache: blockstream.info/liquid/tx/2… blockstream.info/liquid/tx/7… 2. follow-up tx carried a garbage 4234-byte "proof" with an identical cache key that forked the network at block 4050336 and created 3,996.0183 L-BTC blockstream.info/liquid/tx/f… they later then pegged out va sideswap you are only allowed to peg out if ur on the whitelist but i think sideswap just let anyone add their key or something 🫠
8
36
155
21,436
Still the most under-appreciated American songwriting genius of the past four decades.
Moongazer
24
21
288
112,459
Bad year for Bitcoin treasury companies! Turns out buying Bitcoin and buying businesses that buy Bitcoin aren't the same trade.
4
10
49
1,936
What if gravity wasn’t exactly inverse square? Left: F ∝ 1/r² → Perfect, usual closed elliptical orbit Right: F ∝ 1/r^{2.01} → Just 0.5% different… and the orbit no longer closes. It slowly precesses, painting this hypnotic rosette pattern
Matt Henderson
31
79
439
38,879
Cheating and picking two
If you could require every college freshman in America to study one specific book, what would it be?
11
66
952
73,803
Replying to @effectfully
@effectfully can you solve Two Sum - LeetCode, in Haskell I just did without any monads (I used implicit params)
2
5
4,438
JK retweeted
My favorite movies? Flight, Jupiter Ascending, Tenet, Megalopolis
14
8
138
10,762
Replying to @davidbessis
let me unvaguepost this
5
115
3,177
Starting a thread cataloguing resources for learning Category Theory. To get all of the resources in this thread at one place, check out: patternatlas.com/v0/category…
8
54
180
thread for my math definitions
1
3
264
Category theory
If you've been struggling learning category theory, you might want to check out Paolo Perrone's 'Notes on Category theory: with examples from basic mathematics' available publicly on arXiv. These notes were produced during a class given to a diverse set of scientists (including chemists and physicists), with knowledge in linear algebra being the only subject assumed to be known! 🔗👇
1
1
77
Logic
Replying to @spikedoanz
I loved my course on logic in Uni! We used Dirk van Dalen's book Logic and Structure, and it was strangely pleasant to read.
1
55
I invented something
2
46
JK retweeted
MIT teaches operating systems by giving students a complete Unix like kernel and asking them to modify it it is called xv6 and is about 6000 lines of C a reimplementation inspired by Unix Version 6 from 1975 rewritten in modern C for x86 multiprocessor processes system calls virtual memory and filesystem are all there and small enough to read end to end in a weekend this is what you study to understand how operating systems actually work not just how they are described
64
552
4,823
345,108
The exponential function has two key properties: it sets up a homomorphism between multiplication and addition (eˣ⁺ʸ=eˣeʸ), and it is an eigenfunction of d/dx (d(eˣ)/dx=eˣ). As far as I know the easiest explanation is Lie groups.
13
51
548
36,410
JK retweeted
TIL that Pieter Wuille published a libsecp256k1 tutorial. wuille.net/posts/secp256k1-t…
4
49
203
10,855
JK retweeted
History of Mathematical Tables: From Sumer to Spreadsheets — amzn.to/4n93gs1 This one is pretty interesting as it tracks the way in which tabulation evolved with mathematics. The last paper is one the rise of spreadsheets.
2
4
39
1,387