Building nodes for Security, Privacy and Freedom | github.com/openoms | PGP 5BFB77609B081B65 | ⚡openoms@diynodes.com | @blinkbtc #RaspiBlitz

Running Bitcoin Core.
30
15
210
21,794
openoms retweeted
Blink team members will never ask you for a code, PIN, password or seed phrase. Protect your account now: add email login and two-factor authentication in the app. Full post-mortem coming soon. Questions: support@blink.sv
1
2
35
871
openoms retweeted
Every account affected by the September 19 incident has been made whole. We restored each account to its exact pre-incident balance. Affected users were notified directly before this post. Thank you to our mission-aligned shareholders who stepped in.
25
65
333
21,367
Keep iOS up-to-date and have Lockdown mode switched on all the time.
Urgent security advisory for iOS users! Install the latest iOS update immediately. Security researchers report that financially motivated attackers are now using a complete, in-the-wild exploit chain that can quietly steal cryptocurrency private keys and mnemonic seed phrases from iPhones. The reported attack begins when a target is socially engineered into opening a malicious page in Safari. That page is said to abuse a memory-corruption flaw in WebKit / JavaScriptCore to gain arbitrary read/write access from JavaScript, then bypass Pointer Authentication Codes (PAC) to run native code, break out of the WebContent sandbox, and escalate to kernel/root privileges. With that access, attackers can pull data from the device Keychain and from local crypto wallet apps. The claimed impact range is iOS 13 through iOS 26.5; that range has not been independently confirmed in full. Until more is known, treat any unpatched device as potentially exposed and update as soon as a newer build is available. Also avoid untrusted links in Safari, especially if you keep wallet keys or seed phrases on the phone.
1
1
4
1,185
Security Advisory: We are investigating reports of a potential issue affecting experimental features in Core Lightning that may impact user funds. We urge all Core Lightning users running experimental features to disable them immediately while we investigate.
43
108
305
59,627
openoms retweeted
1/ Bitcoin Map is in Blink. Finally! As we roll out BTC Map in Blink, we want Bitcoin communities everywhere to help us make the map better. If you've added Bitcoin merchants before, now is the time to check, update and verify your old listings. Add new, remove inactive. Your local knowledge makes the map stronger. 🧡
10
44
139
14,661
Core Lightning 26.06.7 is out and recommended for every node runner. It fixes vulnerabilities reported over the past three weeks, during a sharp rise in AI-generated reports across open source Bitcoin. Details stay under embargo for two weeks, then all published. github.com/ElementsProject/l…
17
110
275
145,157
Software is burning around us with new vulnerabilities every day then Apple comes with 8 new emojis. WTF is this even? @Apple please make Linux a first class citizen on your hardware.
1
1
13
692
Core Lightning is under a security embargo. How to keep selling while you wait, if you have btcpayserver (I use btcpay-docker). If you run BTCPay with Core Lightning, the advice right now is to upgrade or take your node offline, and there's no fixed build to upgrade to yet. You don't have to stop taking Lightning payments to do it. You can tell the following to your AI agent if you don't want to do it yourself: 1. Put the node in offline mode rather than stopping it A stopped node also stops watching the chain, so it can't respond if a peer force-closes or publishes an old state. Core Lightning's offline flag refuses all peer traffic while lightningd keeps running and following blocks. Create docker-compose-generator/docker-fragments/opt-cln-offline.custom.yml: services: clightning_bitcoin: environment: LIGHTNINGD_OPT: | offline Register and apply it: export BTCPAYGEN_ADDITIONAL_FRAGMENTS="$BTCPAYGEN_ADDITIONAL_FRAGMENTS;opt-cln-offline.custom" . ./btcpay-setup.sh -i Check it took. You want "Started in offline mode!" in the log, and no binding field at all in getinfo: docker logs btcpayserver_clightning_bitcoin 2>&1 | grep -i "offline mode" docker exec btcpayserver_clightning_bitcoin lightning-cli getinfo | jq .binding 2. Block the REST port offline closes port 9735 and nothing else. If your compose publishes clnrest, that's unpatched Core Lightning code answering HTTP from the internet. Find the published mapping onto container port 3010 with docker ps, then probe it from off the box. Anything other than 000 means it's open. ufw won't help here, because Docker's publish path skips the INPUT chain. The rule goes in DOCKER-USER and matches the container port, since packets are already DNAT'd by then: iptables -I DOCKER-USER -i eth0 -p tcp --dport 3010 -j DROP Use your real public interface. Docker rebuilds DOCKER-USER empty on boot, so wrap it in a systemd unit if you want it to survive a reboot. 3. Install Blink (blink.sv) on your phone, create a non-custodial (Spark) account, and set a username. That gives you a Lightning address of the form yourname@blink.sv. 4. Point your stores at it Install the Blink plugin in BTCPay and restart. Get 1.1.2 or newer: earlier builds fail on BTCPay-served Lightning addresses with a description hash error. The plugin needs BTCPay 2.4.2 or newer. For each store, go to Settings, then Lightning, then Use custom node, and enter: type=blink;ln-address=yourname@blink.sv Anything left on the internal node needs either a new backend or its Lightning payment method switched off. Store settings are cached, so restart BTCPay afterwards with docker restart generated_btcpayserver_1. Then buy something from your own store. "Test connection" isn't enough. Stay safe. Keep receiving sats.
5
6
26
3,325
If you run Core Lightning: when the release is published: upgrade with signed binaries, or start your node with `--offline`. Details stay under embargo for two weeks. Previous releases, including 26.04, are unsupported. Full details when the embargo lifts. The 26.09 release is still planned for late September.
Like many open source Bitcoin projects, CLN has received a number of AI-generated CVE reports from multiple sources over the past 10 days. Our small team, together with several invaluable open source contributors, has been working intensively to validate and triage these reports and develop fixes where needed. We’re now working through a broader remediation strategy. The first step is a point release containing many of these fixes, and we will strongly recommend upgrading. We’re aiming to have an initial version of the point release available within the next few days.
13
60
124
28,261
openoms retweeted
Looks like a severe Core Lightning (CLN) issue was discovered. It sounds like you should consider restarting your CLN node with `--offline` and be on the lookout for the point release coming in the next few days. (Messages from CLN discord via stacker.news/items/1555439).
14
84
216
42,203
openoms retweeted
Who wants to help me with maintaining and testing the fork? Are there any users out there willing to start actively participating?
0.0.139 is the final version of nix-bitcoin. Really enjoyed these 8 years developing Bitcoin infrastructure on NixOS, very grateful for your support. The code is there, so fork it.
4
19
39
4,587
openoms retweeted
🎲Rolling dice to create a new bitcoin seed is EASY. People WAY OVERCOMPLICATE it, stressing everyone out by insisting on absurd levels of perfection and unnecessary rituals. I told AI to do the research. Then I organized it all to be human-friendly. kdmukai-bot.github.io/seedsi…
50
110
503
52,858
openoms retweeted
0.0.139 is the final version of nix-bitcoin. Really enjoyed these 8 years developing Bitcoin infrastructure on NixOS, very grateful for your support. The code is there, so fork it.
5
15
69
16,988
openoms retweeted
gained a ton of new insights working in bitcoin red team 🟥 that i wish i could share without vague posting. but this is what i got anon. - we’re experiencing a massive collision between decades of human open source slop against 2 weeks of kimi k3 (not good) - everything is broken, bitcoin is burning - bitcoin is becoming stronger through this - bitcoin is the obvious first target but the rest of the world will follow shortly - sometimes old things need to burn so new things can grow on healthy soil - humans should never code in c (just stop) - lightning is complicated and is more broken than the average (sorry) - verification is free. we used to complain about slop PRs. then about slop security audits. if you can’t handle the information overload, stop complaining and use AI to sort through it. - those projects that started AI audits months ago are in a completely different position than those who didn’t - projects need their own AI audit pipeline going into the future - the burden for a developer to keep software safe and secure is pretty stressful and not for everyone. it has become a lot more stressful now. - unmaintained projects are most probably broken, don’t rely on them. i’d rather one-shot it myself with a modern AI - multiple concurrent, diverse human approaches have proven to be the best vulnerability search method - external red teaming will probably have to continue forever - we’ve basically completed a basic scan of virtually the entirety of bitcoin open source. the low hanging fruit is done. - we’ve reported a ton of real critical and high vulnerabilities. project maintainers across the board have validated our findings. - response speed is very different across projects and shows how healthy each project is. i recommend acting fast these days. - red team etiquette matters. if you don’t disclose responsibly, boast on twitter about your findings on a particular project, or make indications about the nature of particular findings, you’ve disqualified yourself as a serious security researcher. trust is the most important factor in this game. if you lose it, it’s very hard to win it back. - did i mention that humans should not code in c? love you all.
212
565
3,476
375,323
Comunicado Lamentamos comunicarles que el día que no queríamos que llegara ha llegado: @lnp2pBot llega a su fin. Como comunicamos hace pocos días, @lnp2pBot ha sido atacado desde el primer día, las pérdidas que hemos sufrido las hemos asumido por el simple hecho de seguir dándole el servicio que se merecen nuestros fieles usuarios. Sin embargo los hechos se han precipitado y aunque llevamos meses trabajando para mejorar la seguridad del bot no contamos con los recursos para enfrentar un ejercito de script kiddies armados con modelos de IA. Por todo esto hemos tomado la dura y penosa decisión de detener indefinidamente todo tipo de actividad de @lnp2pBot, con efecto inmediato. Una vez más las pérdidas son nuestras. Nos comunicaremos con los pocos usuarios que tienen pagos pendientes para resolver esos casos particulares. No habrá ni un solo usuario afectado económicamente. El bot nació como nuestra legítima defensa ante gobiernos autoritarios que pretenden obligar a los usuarios en entregar todo tipo de información personal con la excusa de que es por su propio bien. Muchas veces pensamos que eran ellos quienes iban a lograr cerrar al bot. Irónicamente no fue ningún gobierno autoritario quien lo logró sino probablemente algunos de nuestros propios usuarios. A todos nuestros usuarios. ¡Gracias totales!
193
172
835
166,570
openoms retweeted
Replying to @BtcpayServer
go to your btcpayserver-docker dir: --- ./btcpay-down.sh rm /var/lib/docker/volumes/generated_lnd_bitcoin_datadir/_data/data/chain/bitcoin/mainnet/*.macaroon rm /var/lib/docker/volumes/generated_lnd_bitcoin_datadir/_data/data/chain/bitcoin/mainnet/macaroons.db ./btcpay-up.sh ---
3
4
15
5,170
openoms retweeted
🚨PSA for LND + BTCPay Server users🚨 Don’t assume you’re safe after upgrading. You’re going to want to explicitly destroy your macaroons and macaroons.db and recreate them fresh. This also applies to auth mechanisms for other LN backends. Also, if you generated a hot on-chain wallet in BTCPay you want to move those funds.
There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds. Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Server -> Maintenance -> Update & verify the 2.4.2 version string in the footer. If you are unable to update right away, turn off your BTCPay Server to prevent unauthorized access until you can update.
18
130
251
58,376