Bitcoin itself has never been hacked.
The ecosystem around it? 2026 is its worst year on record, more than $130M drained from “cold” hardware wallets in attacks linked to a firmware entropy flaw.
No malware. No phishing. Just weak entropy.
The protocol held. The periphery bled. The lesson is verification.
₿ btc-toolkit v1.3.1
A Bitcoin CLI built on one rule: verify everything on-chain, yourself.
7 commands. 110 tests. Zero dependencies. No Bitcoin Core required.
Powered by the @mempool public API and now, with --api-url, every query can go straight to YOUR own node instead.
Check any address, transaction, or block. In seconds. From your terminal.
pip install btc-toolkit
github.com/devdavidejesus/bt…
Don't Trust. Verify.
#Bitcoin #OpenSource
Sep 7, 2026 · 6:44 PM UTC
3
1
5
1,761
The $320M Liquid Network drain is being negotiated ON-CHAIN — via OP_RETURN messages on Bitcoin.
Don't trust the headlines. Read the purported attackers' opening message yourself:
btc-toolkit opreturn c103de95817b43f2df635ec6f35ff126ca26a7c6d20570c4b01866b2b3e69a19
That transaction moved ~3,998 BTC. The fee to carry the message: 269 sats.
This is why verification tools exist.
1
1
60
Full story published — every message of the $320M negotiation decoded, from "we are whitehats" to the 2-byte ":(" that ended it.
Including a detail nobody printed: the PGP signature checksum reads "=HAck".
dev.to/devdavidejesus/i-read…
1
1
30
btc-toolkit 1.4.0 — now built for pipelines.
→ stdin & --file batch mode: one JSON object per line, straight into jq
→ env vars for your own node, network and timeout
→ SECURITY.md with an honest threat model: what it protects, what it doesn't
→ every --json schema documented, with a stability policy
Still zero dependencies. pip install --upgrade btc-toolkit
1
1
22
@wiz @mempool — a thank-you, not a pitch: btc-toolkit is a zero-dependency Bitcoin CLI where every byte comes from your API, and --api-url points it at any self-hosted Mempool instance (Umbrel, Start9).
Last week it decoded the whole Liquid negotiation, live: dev.to/devdavidejesus/i-read…
there's a place you list community tools built on the API, I'd be glad to submit it — and if anything in how it uses the API could be lighter on your infra, I want to know.
github.com/devdavidejesus/bt…
1
25


