Pinned Tweet
pinned tweet for threads
2
9
1,205
Congrats to Vladimir "astOwOlfo" Ivanov the eleventh Winner of the Hutter Prize
The Human Knowledge Compression Contest (widely known as the Hutter Prize) is alive and kicking. This year has seen the largest progress in its 20y-history. We received three winning submissions within one month with a remarkable total improvement of nearly 10% prize.hutter1.net/ (and ~1/3rd the size of the zip-file!). Congratulations to Ibrahim Marcouch & Kaido Orav & David Freelan & Vladimir Ivanov.
16
37
870
36,801
JK retweeted
I've resurrected the comonad.com/reader, interleaved a ton of contemporaneous content I had stored elsewhere, and made a couple of the articles interactive by moving their demo code into web assembly using modern GHC. Please let me know if you run into any issues. #Haskell
7
27
157
10,586
There's some confusion about what, exactly, was exploited here. I've seen claims that this was a long-standing bug, exploited after the "fix" was pushed to the open source repo but before that fix could be rolled out in production. That does not appear to be true. Instead, it seems that the fix *was* deployed, but inadvertently introduced a new bug which was subsequently exploited. Most of the network was still running official releases, none of which contain the new bug. Those nodes correctly rejected the block containing the exploit and stalled at height 4050335. The timeline is roughly as follows: • 2016-07-12: Range proof caching added • 2017-11-08: Range proofs extended to support assets • 2019-03-19: Range proof cache key "simplified", dropping asset & script fields. introduces Bug A. • 2026-09-01: Bug A "fixed" by extending cache key to include asset + script. introduces Bug B. • 2026-09-06: Bug B exploited, reserves drained, chain split. The original "Bug A" allows some limited cache poisoning because the cache key doesn't commit to the asset and script, allowing a cached result for a range proof for one asset to be applied to a different asset or context. Exploiting this in practice looks quite difficult, since the amount must match the primer and the proof must be genuine. The 2026 "fix" added those missing fields to the cache key, producing a format like: "proof | amount | asset | scriptpubkey" But this unfortunately made the key easier to manipulate and exploit: The four fields are concatenated without separators or length indicators. Since both the proof and the scriptpubkey are variable length, an attacker can stretch the proof and shrink the script to produce the exact same cache key from different proofs, amounts, assets and scripts. This lets an attacker smuggle arbitrary confidential output amounts and junk proofs past the range proof checker without proper validation, which breaks the guarantees that prevent hidden inflation. On-chain evidence suggests that this second bug is what was exploited: Two primer transactions each created an op_return with carefully constructed scriptpubkey and valid range proof for a (presumably) zero value output. blockstream.info/liquid/tx/2… blockstream.info/liquid/tx/7… This produced a cache key like: "<valid proof> | <valid amount> | <L-BTC> | OP_RETURN <negative amount> <L-BTC> OP_RETURN" The exploit transaction then created a large negative op_return output with an invalid range proof: blockstream.info/liquid/tx/f… The invalid proof is padded with bytes corresponding to the primer's valid amount and asset fields, aligning the actual amount and asset fields with the same bytes from the primer's opreturn payload: "<valid proof> <valid amount> <L-BTC> OP_RETURN | <negative amount> | <L-BTC> | OP_RETURN" The exploit transaction could then include a second output crediting the attacker with a large positive value, balanced out by the fake negative amount. Because the success was already cached, the invalid proof was never actually checked and the transaction was accepted as valid by nodes running versions of the software vulnerable to bug B. Although the amounts are blinded, this is the only output with an invalid range proof anywhere in the peg-out's recent ancestry, so this must be where the inflated coins were created. And since the padding only produces a cacheable key under the new format, it must have been the newer bug that was exploited.
Liquid Network's reserves just got drained for 4000 BTC due to an inflation bug in confidential transaction validation caching. each LBTC coin is now backed by only ~4.7% of a real Bitcoin.
18
57
268
65,517
I’d advise the liquid white hats not to return the funds when a bug fix is implemented on Liquid. The basic incentive structure of the network appears to be flawed. Send victims bitcoin directly after they sign a bitcoin address while moving their liquid bitcoin Liquid is done
4
37
3,040
Yes, it’s lower level problems.
1
2
293
This has nothing to do with simplicity as a concept , maybe the bridge or confidential transactions
1
1
22
JK retweeted
here are the transactions that caused the liquid consensus split and inflation bug, prior to the peg-out 1. two valid setup txs primed the rangeproof cache: blockstream.info/liquid/tx/2… blockstream.info/liquid/tx/7… 2. follow-up tx carried a garbage 4234-byte "proof" with an identical cache key that forked the network at block 4050336 and created 3,996.0183 L-BTC blockstream.info/liquid/tx/f… they later then pegged out va sideswap you are only allowed to peg out if ur on the whitelist but i think sideswap just let anyone add their key or something 🫠
8
36
155
21,436
83
907
5,421
197,290
eh hem.... "PUNCTURE WOUND" how old are you?
1
8
Yes a liquid can enter a wound
1
5
Replying to @DavidWolfe
Granddaddy got tetenus walking in the chicken coop barefooted, and it's brutal but he did survive and lived to 101. I get mine every 7 years because my lifestyle is animals and outdoorsy. Puncture wounds don't bleed, so you step on a rusty nail, peroxide isn't going to kill it.
1
14
1,359
How is peroxide not going to kill it is a liquid that destroys all the bacteria
1
1
11
40 years of PhD labor patching Black-Scholes-Merton for overnight gaps, all about to be rendered obsolete in order to compete with sports gambling
JUST IN: 🇺🇸 SEC announces roundtable to prepare for 24-hour stock market trading. Panelists: • Citi • UBS • Cboe • NYSE • DTCC • Invesco • Nasdaq • Schwab • Samsung • Blackrock • Robinhood • Jane Street • State Street • BNP Paribas • BNY Pershing • Citadel Securities • Interactive Brokers
6
46
1,376
118,949
What’s better?
1
82
Unfortunate but multisig just creates a new single point of failure in that without the wallet descriptor, you’re kind of wrecked.
Two footguns most bitcoiners miss when setting up multisig according to @lopp. Not backing up your wallet descriptor, and treating multi-vendor multisig as "set it and forget it.”
43
5
85
38,438
please inform what other info that I need? Derivation path of each?
1
96
you need all of the public and private keys, which is probably apart of the HD wallet idk
23
Wrong, you create the wallet with 3 seeds of course you can recover it with them
1
3
141
No you can’t
3
105
Ok, #BIP110 is out of the way. Next, let's get @Truthcoin's (mislabelled) 'ecash' nonsense over and done with. Once these nothinburgers are over, maybe more bitcoiners will make time to focus on what's important: Building the institutional layer which can turn Bitcoin into a stable money for general adoption. The MVP of the needed M1 layer is now ready and working fine on mainchain. Next it takes a bit of work to kickstart a few supply chain corridors on Bitcoin.
5
17
2,057
Better math that again, for a typical day.
1
45
The block reward doesn’t count
14
Replying to @Truthcoin
Fair question. And I believe we share most goals, on scaling, privacy, decentralisation, scope. Here's the issue: Scarcity (supply with a relevant limit) is what makes a thing an economic good. Limited blockchain capacity therefore is a crucial feature of Bitcoin, not a bug. In other words, limited (technical) L1 is what makes a (economic) M0. Bitcoin is incredibly well dimensioned for this purpose. Removing is is like sawing off the branch of the tree on which one is sitting. No bad feelings, please..
4
1
256
Other coins have more fees than btc
1
37
Still the most under-appreciated American songwriting genius of the past four decades.
Moongazer
24
21
288
112,462
Bad year for Bitcoin treasury companies! Turns out buying Bitcoin and buying businesses that buy Bitcoin aren't the same trade.
4
10
49
1,936
By 2018, lack of accountability had *already* destroyed Core (The knotzies are *late* to the party, on that issue!)
New Study A primary selling point of adding Taproot to Bitcoin was its ability to hide spending paths and privately reveal only what is necessary to spend Yet of all 123M Taproot script-spends to date, 98.5% of them didn't have a single hidden path GitHub and ELI5 in 1st reply
6
1
20
4,063
1. So what? 2. They may have the option to use the script path, which is a key difference. That optionality can provide value even if it's not used
1
1
105
it was not meaningful enough of a change, it could have bundled anyprevout for example or ctv Now there is no path for further consensus changes because it’s confused what the process even is, and nobody will speak on it
1
10
Replying to @Truthcoin
It can be compared to the upgrade to P2SH and SegWit for example, and adoption by output value 5 years after P2SH, adoption was c12% on this metric 5 years after SegWit, native SegWit was c14% on this metric Taproot is now c13% So it's about the same, but I had expected Taproot adoption to be far slower. Because Taproot is much less compelling than say the huge fee discount in Segwit. Alsp, I just generally expect upgrades to take longer as time progresses
1
3
275
But that is not isolating the script path spends of taproot; it includes the key path spends which are not any different semantically from pre-taproot scripts
1
1
31
What if gravity wasn’t exactly inverse square? Left: F ∝ 1/r² → Perfect, usual closed elliptical orbit Right: F ∝ 1/r^{2.01} → Just 0.5% different… and the orbit no longer closes. It slowly precesses, painting this hypnotic rosette pattern
Matt Henderson
31
79
439
38,879
I recently found out that @Truthcoin doesn’t like Austrian economics & thinks Keynes makes more sense I still consider myself an Austrian & would love to see someone who can defeat Paul’s argument Who’s the best Austrian economist around? @saifedean? @BitcoinPierre? @scholarium_at?
11
1
18
3,004
Cheating and picking two
If you could require every college freshman in America to study one specific book, what would it be?
11
66
952
73,803