Bitcoin. Fedimint. Lightning.
#Bitcoin has made me more: - careful with my time - patient - stoic - minimalist - healthy - honest - analytical - grateful - anti-consumerist - thoughtful - holistic - detail-oriented - globally-minded - long-termist Bitcoin evolves our minds as much as our money.
104
473
2,664
Obi Nwosu πŸ”… retweeted
Another Fedimint implementation just dropped! πŸš€
3
15
1,776
Obi Nwosu πŸ”… retweeted
Multiple Fedimint implementations were part of the original vision, now with the help of AI the dream is becoming reality πŸ₯Ή Time to call the fedimint repo minimint again? Has my holding out finally paid off? 😝
3
5
15
1,391
Obi Nwosu πŸ”… retweeted
ecashmesh⚑️ evidence-aware routing for Ecash across @CashuBTC , @fedimint and eventually @lightning beyond fees: liquidity, reliability, proof freshness and route risk which Ecash route should I use, and why? building for @bitshala boss battle 2026 πŸ”— github.com/bansalayush247/ec…
2
7
20
2,076
Without privacy, you are simply holding your would-be attackers’ Bitcoin or crypto for them. They just haven’t gotten around to taking it from you yet.
Since 2022 @ODFoundation has campaigned before EU regulators for the privacy of payments and asked the bitcoin industry to join. We were grateful for the support of @jack , @obi and a few other bitcoiners. Most others laughed and said it was not their business. In 2023 we won a majority in the European Parliament for our safeguards. The closed-door trilogue then removed majority of them from the AML Regulation. We did not have enough loud voices from the industry to defend payment privacy, and now we face the hunting of our data at scale. There is still a chance. OSCE PA parliamentarians have adopted remedies against the weaponisation of AML/CFT laws and recognised transnational financial repression as a threat to the security of the OSCE area, which covers the US, Canada, Europe and Central Asia. This would have been impossible without the support of @AtlasNetwork, @cypher_tank and the Reynolds Foundation @AlvaroSalas , who understood the problem at first sight. Will you keep observing and complaining, or join and make this space safe to use, invest and build in? There is nowhere else to run. Privacy has to be protected and normalised as a human right. Now, before it is too late.
3
5
24
2,280
Thanks to the Fedimint team for their transparency and quick response. It’s a reminder that beyond accelerating AI threat detection, we need multi-provider multisig to prevent single points of failure.
We found a bug in our legacy Lightning integration and are contacting public gateway operators. User funds, federations, and ecash are not affected. Gateways using LDK Node or our newer LNv2 protocol are also not affected. We still recommend staying up to date. 🧡
1
1
18
2,705
Context:
A topic this critical deserves my first long-form post. The real question is not trusted vs trustless. It's how many independent things have to go wrong before you lose money. @TheBlueMatt said it in one sentence. Run the same software, suffer the same bugs. ⬇️ Think about what actually happened. Liquid was an 11-of-15 multisig. Fifteen independent signers. No keys were compromised. Nevertheless, eleven honest signers approved a withdrawal that emptied 95% of the reserves, because every one of them was running the same code, and the code had the same bug. A few weeks before that, one firmware flaw swept thousands of Coldcard cold wallets. Different product, same lesson from the other side.
 Before anything else, none of this is abstract. Coldcard victims lost savings they stacked over years. LBTC holders woke up to frozen funds through no fault of their own. And anyone who has ever shipped code that holds other people's money can and should empathise with the engineers at Blockstream. I do. But we have to be honest with ourselves here. The world has changed. AI tooling is surfacing bugs that sat dormant for years, a point Matt also made after Coldcard. Five year old vulnerabilities are getting weaponised. Supply chains are getting attacked. "Secure so far" doesn't mean much anymore. So let's also retire a comforting fiction. There is no such thing as β€œtrustless.” There never was. It was always shorthand for trust-minimised. Every system puts trust somewhere: in code, in firmware, in the people who write, ship, and run both. Liquid users trusted Elements. Coldcard users trusted a random number generator they never saw. Don't get me wrong. We should keep doing everything possible to make our code, our systems and the people behind them as trustworthy as we can. Audits, reviews, security culture, all of it. But trustworthiness is not the same thing as fault tolerance, and we need both. Fault tolerance only comes from having independent failure domains. In other words, no single point of failure. So what does this look like in practice: 1. Multiple implementations of every protocol that holds funds, with the power to reject and not just observe. 2. Multiple wallet implementations. We mostly have this already. 3. Keys generated on hardware from different vendors. 4. Multiple independent, trustworthy humans behind every system that holds money. 5. Geographic and jurisdictional distribution as one jurisdiction's rules can change overnight.Β  And to be clear, Matt's sentence currently applies to @Fedimint too. Fedimint was designed to remove single humans and single institutions as points of failure. That's the whole point of a constellation of federations. But today there is only one implementation of the protocol: every guardian runs the same software. Federated humans, monoculture code, and it's not good enough. So I'm calling on the Fedimint community to lead by example and fix this as quickly as we can. And to everyone else, tell me where I'm wrong. If I am, propose something better. If I'm not, then let's stop debating trusted vs trustless and start demanding independence at every layer. Software, hardware, humans, jurisdictions. All the way down. That's how Bitcoin stays worth the highest confidence as we enter this new age.
1
408
Obi Nwosu πŸ”… retweeted
Calling on fellow cypherpunks to build alternative Fedimint implementations. The Liquid hack shows once again that single points of failure are what will break our systems and that includes the code we write. Security is an asymmetric game: an attacker has to find one weakness, while defenders have to find all. AI has permanently changed the attacker-defender balance for the worse. This is a fundamental problem for the entire freedom tech space and only mitigatable by aggressively reducing single points of failure. Federations are meant to do exactly that, but just like Liquid, Fedimint shares the β€œsingle implementation” problem. If we still want to bring privacy and freedom to the world we need to work together more than ever to reduce these single points of failure. For me that means seeking help to bootstrap independent Fedimint implementations. We are still early, but I've started extracting a specification that others could build off and would love to collaborate with any fellow cypherpunks who want to join us in that mission. In particular, I’d love to work with @callebtc and the @CashuBTC team, who have much more experience with a multi-implementation ecash protocol while the Fedimint team brings federation experience to the table. While AI exposes existing vulnerabilities and wreaks havoc in our ecosystem, it is also an opportunity for talented engineers to be far more productive than ever before. I’ve been talking with @fedibtc and there is funding for a small, crack team to pull this off. If this sounds interesting as a funder, please reach out! The idea is for the teams to be purposefully disconnected from the existing Fedimint implementation and to work autonomously, communicating mainly through the spec process. If you too believe that privacy and freedom are needed more than ever, please join us!
A topic this critical deserves my first long-form post. The real question is not trusted vs trustless. It's how many independent things have to go wrong before you lose money. @TheBlueMatt said it in one sentence. Run the same software, suffer the same bugs. ⬇️ Think about what actually happened. Liquid was an 11-of-15 multisig. Fifteen independent signers. No keys were compromised. Nevertheless, eleven honest signers approved a withdrawal that emptied 95% of the reserves, because every one of them was running the same code, and the code had the same bug. A few weeks before that, one firmware flaw swept thousands of Coldcard cold wallets. Different product, same lesson from the other side.
 Before anything else, none of this is abstract. Coldcard victims lost savings they stacked over years. LBTC holders woke up to frozen funds through no fault of their own. And anyone who has ever shipped code that holds other people's money can and should empathise with the engineers at Blockstream. I do. But we have to be honest with ourselves here. The world has changed. AI tooling is surfacing bugs that sat dormant for years, a point Matt also made after Coldcard. Five year old vulnerabilities are getting weaponised. Supply chains are getting attacked. "Secure so far" doesn't mean much anymore. So let's also retire a comforting fiction. There is no such thing as β€œtrustless.” There never was. It was always shorthand for trust-minimised. Every system puts trust somewhere: in code, in firmware, in the people who write, ship, and run both. Liquid users trusted Elements. Coldcard users trusted a random number generator they never saw. Don't get me wrong. We should keep doing everything possible to make our code, our systems and the people behind them as trustworthy as we can. Audits, reviews, security culture, all of it. But trustworthiness is not the same thing as fault tolerance, and we need both. Fault tolerance only comes from having independent failure domains. In other words, no single point of failure. So what does this look like in practice: 1. Multiple implementations of every protocol that holds funds, with the power to reject and not just observe. 2. Multiple wallet implementations. We mostly have this already. 3. Keys generated on hardware from different vendors. 4. Multiple independent, trustworthy humans behind every system that holds money. 5. Geographic and jurisdictional distribution as one jurisdiction's rules can change overnight.Β  And to be clear, Matt's sentence currently applies to @Fedimint too. Fedimint was designed to remove single humans and single institutions as points of failure. That's the whole point of a constellation of federations. But today there is only one implementation of the protocol: every guardian runs the same software. Federated humans, monoculture code, and it's not good enough. So I'm calling on the Fedimint community to lead by example and fix this as quickly as we can. And to everyone else, tell me where I'm wrong. If I am, propose something better. If I'm not, then let's stop debating trusted vs trustless and start demanding independence at every layer. Software, hardware, humans, jurisdictions. All the way down. That's how Bitcoin stays worth the highest confidence as we enter this new age.
2
26
57
6,390
A topic this critical deserves my first long-form post. The real question is not trusted vs trustless. It's how many independent things have to go wrong before you lose money. @TheBlueMatt said it in one sentence. Run the same software, suffer the same bugs. ⬇️ Think about what actually happened. Liquid was an 11-of-15 multisig. Fifteen independent signers. No keys were compromised. Nevertheless, eleven honest signers approved a withdrawal that emptied 95% of the reserves, because every one of them was running the same code, and the code had the same bug. A few weeks before that, one firmware flaw swept thousands of Coldcard cold wallets. Different product, same lesson from the other side.
 Before anything else, none of this is abstract. Coldcard victims lost savings they stacked over years. LBTC holders woke up to frozen funds through no fault of their own. And anyone who has ever shipped code that holds other people's money can and should empathise with the engineers at Blockstream. I do. But we have to be honest with ourselves here. The world has changed. AI tooling is surfacing bugs that sat dormant for years, a point Matt also made after Coldcard. Five year old vulnerabilities are getting weaponised. Supply chains are getting attacked. "Secure so far" doesn't mean much anymore. So let's also retire a comforting fiction. There is no such thing as β€œtrustless.” There never was. It was always shorthand for trust-minimised. Every system puts trust somewhere: in code, in firmware, in the people who write, ship, and run both. Liquid users trusted Elements. Coldcard users trusted a random number generator they never saw. Don't get me wrong. We should keep doing everything possible to make our code, our systems and the people behind them as trustworthy as we can. Audits, reviews, security culture, all of it. But trustworthiness is not the same thing as fault tolerance, and we need both. Fault tolerance only comes from having independent failure domains. In other words, no single point of failure. So what does this look like in practice: 1. Multiple implementations of every protocol that holds funds, with the power to reject and not just observe. 2. Multiple wallet implementations. We mostly have this already. 3. Keys generated on hardware from different vendors. 4. Multiple independent, trustworthy humans behind every system that holds money. 5. Geographic and jurisdictional distribution as one jurisdiction's rules can change overnight.Β  And to be clear, Matt's sentence currently applies to @Fedimint too. Fedimint was designed to remove single humans and single institutions as points of failure. That's the whole point of a constellation of federations. But today there is only one implementation of the protocol: every guardian runs the same software. Federated humans, monoculture code, and it's not good enough. So I'm calling on the Fedimint community to lead by example and fix this as quickly as we can. And to everyone else, tell me where I'm wrong. If I am, propose something better. If I'm not, then let's stop debating trusted vs trustless and start demanding independence at every layer. Software, hardware, humans, jurisdictions. All the way down. That's how Bitcoin stays worth the highest confidence as we enter this new age.
All the signers were running the same software, so all had the same bug.
12
28
84
21,051
Obi Nwosu πŸ”… retweeted
Please join @Modibe_, @frankcorva , and @vryfokkenou on Thursday, 10 September, at 9am ET. They’ll be discussing how @fedimint is used within the @BitcoinEkasi community and beyond in South Africa. Be sure to tune in!
1
16
24
1,244
Obi Nwosu πŸ”… retweeted
From an upgrade to @fedimint to an inspirational conversation with a Kenyan community leader and entrepreneur, we had a lot to be excited about this week. A thread 🧡:
2
5
26
2,229
Congrats to the team for this huge milestone. Years of feedback and research to make this major upgrade to the protocol. Super excited to see the result and incorporate it into the Fedi app for a faster, smoother, and even more scalable offering. πŸ‘€βœ…πŸš€
Fedimint v0.12.0 "Second Nature" is here! πŸš€ The highlights: * v2 modules (lnv2, mintv2, walletv2) now the default for new federations ✨ * Much lower Lightning payment latency ⚑️ * @iroh_n0 1.0 networking 🌐 * Wallet recovery without downtime πŸ”„ github.com/fedimint/fedimint…
3
9
1,620
Obi Nwosu πŸ”… retweeted
Fedimint v0.12.0 "Second Nature" is here! πŸš€ The highlights: * v2 modules (lnv2, mintv2, walletv2) now the default for new federations ✨ * Much lower Lightning payment latency ⚑️ * @iroh_n0 1.0 networking 🌐 * Wallet recovery without downtime πŸ”„ github.com/fedimint/fedimint…
1
14
33
3,258
Obi Nwosu πŸ”… retweeted
Community Chat with Kelvin Makini of EcoBitz nitter.net/i/broadcasts/1kKzDPpyz…
1
5
23
1,369
Obi Nwosu πŸ”… retweeted
Received my pay fully in ecash for the first time this month, feels magical πŸ₯°
3
30
961
Obi Nwosu πŸ”… retweeted
Please join @Modibe_, @frankcorva, and Kelvin Makini on Thursday, 3 September, at 10am ET. They'll discuss Kelvin's work and @EcoBitz_21m, his waste-to-bitcoin initiative that pays recyclers in bitcoin. We will go live on X and Instagram. Be sure to tune in!
1
13
26
1,180
Obi Nwosu πŸ”… retweeted
Without Iroh we couldn't have made Fedimint as easy to run as it is today, so huge props to them! It's the future that IPv6 should have been 😁
Iroh is what enables Fedimint to be as easy to run on a home networks or on an old phone as it is to run in the cloud!
1
3
14
1,282
Obi Nwosu πŸ”… retweeted
ICYMI: our special episode with @EricSirion, creator of @fedimint and co-founder of Fedi, is now live on YouTube. The episode covers community custody, ecash, privacy and more! Eric also hints at an upcoming update to make federation setup easier. πŸ˜‰ Click the link in the thread to watch the full episode.
2
7
25
1,652
I really hope this phase of Bitcoin community retrospection continues indefinitely. We're questioning our priors again.
1
6
42
2,572
Obi Nwosu πŸ”… retweeted
Shopping local and paying with Bitcoin has never been easier! βš‘πŸ›’ From fresh finds to family essentials, our Thrift Store & WiFi Zone is powered by circular Bitcoin micro-payments. Check out the community shopping for clothes, shoes, and kids' gearβ€”all paid seamlessly using sats. Want to support our mission?Scan the QR code at the end of the video to donate on-chain or via Lightning, or visit: support.bitcoinekasi.com
1
14
23
898