Fedimint. Decentralised #Bitcoin custody for the world. Read more at fedimint.org

Fedimint ๐Ÿ”† retweeted
Multiple Fedimint implementations were part of the original vision, now with the help of AI the dream is becoming reality ๐Ÿฅน Time to call the fedimint repo minimint again? Has my holding out finally paid off? ๐Ÿ˜
3
5
15
1,391
Another Fedimint implementation just dropped! ๐Ÿš€
3
15
1,776
We found a bug in our legacy Lightning integration and are contacting public gateway operators. User funds, federations, and ecash are not affected. Gateways using LDK Node or our newer LNv2 protocol are also not affected. We still recommend staying up to date. ๐Ÿงต
5
35
82
10,206
If we havenโ€™t reached out, please update to v0.12.1 ASAP, or shut down your Lightning gateway in the meantime if thatโ€™s not feasible. Users of federations without an active Lightning gateway will still be able to make ecash and on-chain transactions. github.com/fedimint/fedimintโ€ฆ
1
2
12
769
The bug results from an interaction between misunderstood HTLC interception behavior and our LN-ecash swap validation logic that evaded previous scans. We continue to do our own AI-accelerated security research and appreciate external research findings at security@fedimint.org
2
11
453
Fedimint ๐Ÿ”† retweeted
ecashmeshโšก๏ธ evidence-aware routing for Ecash across @CashuBTC , @fedimint and eventually @lightning beyond fees: liquidity, reliability, proof freshness and route risk which Ecash route should I use, and why? building for @bitshala boss battle 2026 ๐Ÿ”— github.com/bansalayush247/ecโ€ฆ
2
7
20
2,076
Fedimint ๐Ÿ”† retweeted
Why multiple implementations make sense for security beyond a certain point:
Calling on fellow cypherpunks to build alternative Fedimint implementations. The Liquid hack shows once again that single points of failure are what will break our systems and that includes the code we write. Security is an asymmetric game: an attacker has to find one weakness, while defenders have to find all. AI has permanently changed the attacker-defender balance for the worse. This is a fundamental problem for the entire freedom tech space and only mitigatable by aggressively reducing single points of failure. Federations are meant to do exactly that, but just like Liquid, Fedimint shares the โ€œsingle implementationโ€ problem. If we still want to bring privacy and freedom to the world we need to work together more than ever to reduce these single points of failure. For me that means seeking help to bootstrap independent Fedimint implementations. We are still early, but I've started extracting a specification that others could build off and would love to collaborate with any fellow cypherpunks who want to join us in that mission. In particular, Iโ€™d love to work with @callebtc and the @CashuBTC team, who have much more experience with a multi-implementation ecash protocol while the Fedimint team brings federation experience to the table. While AI exposes existing vulnerabilities and wreaks havoc in our ecosystem, it is also an opportunity for talented engineers to be far more productive than ever before. Iโ€™ve been talking with @fedibtc and there is funding for a small, crack team to pull this off. If this sounds interesting as a funder, please reach out! The idea is for the teams to be purposefully disconnected from the existing Fedimint implementation and to work autonomously, communicating mainly through the spec process. If you too believe that privacy and freedom are needed more than ever, please join us!
1
4
13
999
Fedimint ๐Ÿ”† retweeted
Using @fedibtc and a self-hosted @fedimint federation to make Bitcoin everyday money! This is Good Hope federation, running on 7 @start9labs devices, spread out across the Western Cape province of South Africa. We use it every day. But it's still mind blowing. Every single time.
1
13
40
3,330
Fedimint ๐Ÿ”† retweeted
Calling on fellow cypherpunks to build alternative Fedimint implementations. The Liquid hack shows once again that single points of failure are what will break our systems and that includes the code we write. Security is an asymmetric game: an attacker has to find one weakness, while defenders have to find all. AI has permanently changed the attacker-defender balance for the worse. This is a fundamental problem for the entire freedom tech space and only mitigatable by aggressively reducing single points of failure. Federations are meant to do exactly that, but just like Liquid, Fedimint shares the โ€œsingle implementationโ€ problem. If we still want to bring privacy and freedom to the world we need to work together more than ever to reduce these single points of failure. For me that means seeking help to bootstrap independent Fedimint implementations. We are still early, but I've started extracting a specification that others could build off and would love to collaborate with any fellow cypherpunks who want to join us in that mission. In particular, Iโ€™d love to work with @callebtc and the @CashuBTC team, who have much more experience with a multi-implementation ecash protocol while the Fedimint team brings federation experience to the table. While AI exposes existing vulnerabilities and wreaks havoc in our ecosystem, it is also an opportunity for talented engineers to be far more productive than ever before. Iโ€™ve been talking with @fedibtc and there is funding for a small, crack team to pull this off. If this sounds interesting as a funder, please reach out! The idea is for the teams to be purposefully disconnected from the existing Fedimint implementation and to work autonomously, communicating mainly through the spec process. If you too believe that privacy and freedom are needed more than ever, please join us!
A topic this critical deserves my first long-form post. The real question is not trusted vs trustless. It's how many independent things have to go wrong before you lose money. @TheBlueMatt said it in one sentence. Run the same software, suffer the same bugs. โฌ‡๏ธ Think about what actually happened. Liquid was an 11-of-15 multisig. Fifteen independent signers. No keys were compromised. Nevertheless, eleven honest signers approved a withdrawal that emptied 95% of the reserves, because every one of them was running the same code, and the code had the same bug. A few weeks before that, one firmware flaw swept thousands of Coldcard cold wallets. Different product, same lesson from the other side.โ€จ Before anything else, none of this is abstract. Coldcard victims lost savings they stacked over years. LBTC holders woke up to frozen funds through no fault of their own. And anyone who has ever shipped code that holds other people's money can and should empathise with the engineers at Blockstream. I do. But we have to be honest with ourselves here. The world has changed. AI tooling is surfacing bugs that sat dormant for years, a point Matt also made after Coldcard. Five year old vulnerabilities are getting weaponised. Supply chains are getting attacked. "Secure so far" doesn't mean much anymore. So let's also retire a comforting fiction. There is no such thing as โ€œtrustless.โ€ There never was. It was always shorthand for trust-minimised. Every system puts trust somewhere: in code, in firmware, in the people who write, ship, and run both. Liquid users trusted Elements. Coldcard users trusted a random number generator they never saw. Don't get me wrong. We should keep doing everything possible to make our code, our systems and the people behind them as trustworthy as we can. Audits, reviews, security culture, all of it. But trustworthiness is not the same thing as fault tolerance, and we need both. Fault tolerance only comes from having independent failure domains. In other words, no single point of failure. So what does this look like in practice: 1. Multiple implementations of every protocol that holds funds, with the power to reject and not just observe. 2. Multiple wallet implementations. We mostly have this already. 3. Keys generated on hardware from different vendors. 4. Multiple independent, trustworthy humans behind every system that holds money. 5. Geographic and jurisdictional distribution as one jurisdiction's rules can change overnight.ย  And to be clear, Matt's sentence currently applies to @Fedimint too. Fedimint was designed to remove single humans and single institutions as points of failure. That's the whole point of a constellation of federations. But today there is only one implementation of the protocol: every guardian runs the same software. Federated humans, monoculture code, and it's not good enough. So I'm calling on the Fedimint community to lead by example and fix this as quickly as we can. And to everyone else, tell me where I'm wrong. If I am, propose something better. If I'm not, then let's stop debating trusted vs trustless and start demanding independence at every layer. Software, hardware, humans, jurisdictions. All the way down. That's how Bitcoin stays worth the highest confidence as we enter this new age.
2
26
57
6,390
Fedimint ๐Ÿ”† retweeted
Congrats to the team for this huge milestone. Years of feedback and research to make this major upgrade to the protocol. Super excited to see the result and incorporate it into the Fedi app for a faster, smoother, and even more scalable offering. ๐Ÿ‘€โœ…๐Ÿš€
Fedimint v0.12.0 "Second Nature" is here! ๐Ÿš€ The highlights: * v2 modules (lnv2, mintv2, walletv2) now the default for new federations โœจ * Much lower Lightning payment latency โšก๏ธ * @iroh_n0 1.0 networking ๐ŸŒ * Wallet recovery without downtime ๐Ÿ”„ github.com/fedimint/fedimintโ€ฆ
3
9
1,620
Fedimint v0.12.0 "Second Nature" is here! ๐Ÿš€ The highlights: * v2 modules (lnv2, mintv2, walletv2) now the default for new federations โœจ * Much lower Lightning payment latency โšก๏ธ * @iroh_n0 1.0 networking ๐ŸŒ * Wallet recovery without downtime ๐Ÿ”„ github.com/fedimint/fedimintโ€ฆ
1
14
33
3,258
For app developers: UniFFI bindings bring the client to Kotlin & Swift ๐Ÿ“ฑ, new fee APIs show costs before you commit ๐Ÿค‘, and clients stay fully usable while recovering โ€” no more waiting for restore to finish. ๐Ÿ”„
1
2
189
Fedimint ๐Ÿ”† retweeted
Without Iroh we couldn't have made Fedimint as easy to run as it is today, so huge props to them! It's the future that IPv6 should have been ๐Ÿ˜
Iroh is what enables Fedimint to be as easy to run on a home networks or on an old phone as it is to run in the cloud!
1
3
14
1,282
Fedimint ๐Ÿ”† retweeted
We're live with @fedimint founder and @fedibtc co-founder, @EricSirion! Please drop your questions for Eric in the comments.
2
4
16
1,911
Iroh is what enables Fedimint to be as easy to run on a home networks or on an old phone as it is to run in the cloud!
This is interesting: iroh.computer Basically Tailscale but on application level, not network level. Uses QUIC so it is super fast and runs on embedded hardware too! @iroh_n0
2
13
2,742