dad bitcoiner @blockstream @opentimestamps 𝟶𝚡𝙵𝙱𝙰𝟶𝟺𝟼𝙴𝙰𝟽𝟺𝙱𝟶𝟶𝟷𝙲𝟷 gpg

CEXs are bleeding prediction in
[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026 At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately. What we have confirmed: -Estimated funds affected: approximately $351.6 million -Cold wallets remain fully secure. Bitget operates a three-tier wallet architecture — the breach contained only a portion of the hot wallet and warm wallet layers. -User funds are safe. The full amount of this loss falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million Actions we have taken: -Emergency response team activated within minutes of detection -Abnormal transfer addresses identified, flagged, and reported -Withdrawals temporarily suspended as a precautionary measure, pending security review -Law enforcement and on-chain security firms have been formally notified and are engaged What this means for you: -Your account balances are accurate and your assets are protected -Deposits and trading remain fully operational Withdrawals are temporarily paused and will be restored as soon as the security review is complete -What comes next: We will provide updates on an hourly basis across this channel and all official platforms. A full incident report — including root cause analysis and corrective actions — will be published within 24 hours. We will not speculate on the attack vector until the investigation is complete. Bitget has navigated multiple market cycles. We will not run from this. Every dollar and every decision will be accounted for, transparently and in full. Updates will be posted here and across all official Bitget channels as they become available. — Gracy Chen, CEO, Bitget
100
Luca Vaccaro retweeted
Your apocalypse phone doesn’t need a cell tower. meet the Doomsday Phone, a DIY communicator called Chatter, powered by an ESP32 and LoRa radio it sends text messages directly to another compatible device within range no SIM card no Wi-Fi no mobile operator a built-in screen and physical buttons mean you don’t need to pair it with your smartphone the video claims up to 10 km of range, depending on terrain, obstacles and antennas its strength is simple: two powered devices can communicate without relying on a working mobile network for a camping trip, a remote location or a network outage, that could mean getting an “i’m safe” to someone who needs to hear it
45
376
1,917
98,192
Bitcoin Blood team 🩸
Thoughts and prayers to @L0RINC who won't sleep for the next 2 weeks now that GPT 6.0 Daybreak & Opus 5.5 released today as he rescans the entire bitcoin codebase for the fifteenth time.
5
228
Luca Vaccaro retweeted
636606729769440499166579950236036751749912014371509557713570027508971809534551913252252094954941974952859310861988904737359709200557919 is a factor of RSA-896 saweis.net/posts/rsa-896.htm…
225
990
9,501
3,907,953
Luca Vaccaro retweeted
Strongly agree. When I verified Bitcoin Core 31.1 myself, I didn't stop at checking the SHA256 hash. I imported public PGP keys and verified signatures. More importantly, Bitcoin Core uses reproducible Guix builds: independent builders can build the same release on their own machines and attest that they arrived at the same binaries. Bitcoin Core 31.1 has Guix attestations from 16 independent builders: 0xb10c — github.com/0xb10c Emzy — github.com/Emzy Sjors — github.com/Sjors achow101 — github.com/achow101 benthecarman — github.com/benthecarman fanquake — github.com/fanquake guggero — github.com/guggero hebasto — github.com/hebasto m3dwards — github.com/m3dwards marcofleon — github.com/marcofleon pinheadmz — github.com/pinheadmz sedited — github.com/sedited sipsorcery — github.com/sipsorcery svanstaa — github.com/svanstaa theStack — github.com/theStack willcl-ark — github.com/willcl-ark That is a radically different trust model from simply checking a checksum published by the same party that gave you the binary. And frankly, it seems crazy to me that so much of the current discussion has shifted toward worrying about whether users need to generate their own randomness. We routinely trust general-purpose computers and modern operating systems to generate cryptographically strong passwords, passphrases and keys. Password managers do this every day. Anyone who has looked at how a modern OS seeds and maintains its CSPRNG knows that it continuously incorporates entropy from system and hardware events and exposes secure randomness once properly initialized. On a clean, freshly installed general-purpose OS, I am far more comfortable relying on a mature OS CSPRNG and well-reviewed cryptographic software than inventing my own entropy ceremony with dice. The bigger question for me is why we keep introducing specialized Bitcoin hardware in the first place. A device whose explicit purpose is securing Bitcoin creates targetedness. Manufacturers, payment processors, fulfillment companies, shipping providers and other third parties may now have economically valuable information about you: you probably own Bitcoin. If that data leaks, it can enable targeted phishing, social engineering, fake firmware or support messages, seed extraction attempts, SIM attacks, extortion or physical coercion — without anyone breaking the cryptography inside the device. The same trade-off exists with the current mantra of multi-vendor hardware-wallet multisig. Multisig can reduce key-compromise and correlated-device risk. But on the targetedness axis, every additional hardware-wallet vendor can add another manufacturer, customer database, supply chain, shipping provider, email system and specialized dependency to your threat model. If you wanted to create the biggest possible operational headache for yourself and your future heirs, one way would be to buy one device from every hardware-wallet vendor you can find. And there is certainly no shortage of them. You'd accumulate a huge specialized attack surface while repeatedly signaling to companies and their third-party providers that you are someone who takes Bitcoin custody seriously enough to buy dedicated signing devices. To me, that is completely backwards. Once you see the targetedness problem, you can't unsee it. My preference remains: Generic hardware. Linux. Bitcoin Core. Minimize specialized dependencies. Minimize targetedness. Minimize attack surface.
Very few people in Bitcoin seem to understand that a sophisticated attacker would not hide security flaws in an apps viewable source code. They would hide it in the prebuilt crypto binaries (AKA the thing that actually touches your private keys). These much more difficult to properly audit and its one of the many reasons why Bitcoin Core is the gold standard for the security critical functions of a Bitcoin Wallet (both generating secure keys AND signing). After "the incident" with coldcard, the overton window has shifted drastically towards entropy, but random enough entropy is only one small piece of what makes cryptography safe. Those of you that are overly focused on "entropy" and wanting to "roll the dice", are actually rolling dice on a single point of failure. Bitcoin Core is one of the very few projects that takes this seriously enough to actually pin its entire build toolchain with guix. This means that dozens of independent contributors can, on their own hardware, run the Guix build and publish their own signed hash attestation that the crypto libraries they ship are exactly what they claim to be. You simply aren't going to find this assurance in the rest of these projects, even the ones that look like they have a ton of github activity (i.e. open source review and contribution). They all rely on single points of trust, which is most often, trusting the one single party that built the crypto library isn't going to rug you with a backdoor. Bad actors will intentionally distract users from this by publishing attestations that prove nothing of substance. End users see a SHA256SUMS file and think verifying it gives them security... ...but the only thing it proves is that nobody messed with the app after it got strung together with some spooky crypto library compiled by some anonymous contributor in Ukraine.
11
17
147
34,071
Luca Vaccaro retweeted
Introducing HashFly...the first organic neuron bitcoin miner based on the fly brain. Fun fact if this could be scaled on real organic neurons, it would hash at ~ 1 watt per terahash...10x the efficiency of the best silicon 3nm ASICs!
69
137
859
843,152
Luca Vaccaro retweeted
A real OpenTimestamps use case is quietly taking shape around AI compliance. The EU AI Act requires general purpose AI providers to publish summaries of their training content. An independent archive, GPAI Ledger, is preserving these disclosures with SHA-256 + OpenTimestamps proofs anchored to Bitcoin. The archive has already timestamped OpenAI’s GPT Image 2 disclosure. It’s an independent implementation for now, but it shows exactly where OTS can fit as AI compliance records become more important. digital-strategy.ec.europa.e… gpailedger.com/ gpailedger.com/ledger/openai… gpailedger.com/ledger/meta/m… @peterktodd @opentimestamps $TIME
1
3
11
1,320
Luca Vaccaro retweeted
Replying to @sprecher14
You know how they say we only use 10% of our brain? Guess we are all mining bitcoin with 90% of it 😆
1
1
19
2,769
Luca Vaccaro retweeted
I did a full audit of Liquid's blockchain using elements-23.3.4 with "Range proof cache disabled via -norangeproofcache" from block 0 to 4054253 so I could independently verify that Liquid's blockchain contains no fraudulent LBTC or other assets and I got the correct chain tip 👍
Replying to @FarsideInsights
2026-09-06T13:52:11Z UpdateTip: new best=aad24e4fb64ca8adf4961667da87820cd48e553957ac64e75de7cdb298b5d66b height=4050335 version=0x20000000 log2_work=21.949610 tx=10343053 date='2026-09-06T13:52:10Z' progress=1.000000 cache=1.4MiB(3105txo) 2026-09-06T13:53:11Z ERROR: ConnectBlock: CheckQueue failed 2026-09-06T13:53:11Z InvalidChainFound: invalid block=e1d9a2aae69e0fc3ca18f7f7f84e0615e92a5e3b5000d66c10c34043346da0d5 height=4050336 date=2026-09-06T13:53:10Z 2026-09-06T13:53:11Z InvalidChainFound: current best=aad24e4fb64ca8adf4961667da87820cd48e553957ac64e75de7cdb298b5d66b height=4050335 date=2026-09-06T13:52:10Z 2026-09-06T13:53:11Z ERROR: ConnectTip: ConnectBlock e1d9a2aae69e0fc3ca18f7f7f84e0615e92a5e3b5000d66c10c34043346da0d5 failed, block-validation-failed 2026-09-06T13:53:11Z InvalidChainFound: invalid block=e1d9a2aae69e0fc3ca18f7f7f84e0615e92a5e3b5000d66c10c34043346da0d5 height=4050336 date=2026-09-06T13:53:10Z 2026-09-06T13:53:11Z InvalidChainFound: current best=aad24e4fb64ca8adf4961667da87820cd48e553957ac64e75de7cdb298b5d66b height=4050335 date=2026-09-06T13:52:10Z
9
21
181
18,788
Luca Vaccaro retweeted
To those responsible for the theft of bitcoin from the Liquid Network: Blockstream will not pay a ransom for the return of stolen funds. Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft. We have engaged in good faith in an effort to secure the return of stolen user funds and protect the broader Bitcoin community. That effort should not be mistaken for acceptance of the actions taken nor of the terms being demanded. We will not be a party to the precedent that open-source software developed for the good of the Bitcoin community should subject its developers to paying a ransom that far exceeds their economic participation. Bitcoin is hard money and can’t be minted without costs, Bitcoin doesn’t haircut users to pay a ransom. To the Bitcoin community: We are fighting for what we believe in, for the users whose funds were taken, and for the principles on which Bitcoin was built. The community has demonstrated incredible resolve with teams of people dedicating their time in support of each other to identify and patch vulnerabilities in each other's products and systems. We are all driven by the mission that Bitcoin is the single best asset, for every person, company, and institution on the planet to invest, use, and build on. The world is a different place with the advancements of AI, and the Bitcoin community has responded with force to combat that threat. Damage has been done, battles have been lost, but on the whole the Bitcoin community is gaining ground in the war with bad actors. We want to thank the community for those efforts, for your support in hardening the network, helping users recover funds, and for your support in our assertion that crime does not deserve rewards. To those holding the stolen bitcoin: There is still an opportunity to resolve this responsibly. The bitcoin can be returned and we can revert to the standard of white-hat principals. However, if the funds are not returned, we will pursue every lawful avenue available to us. We will work with law enforcement, exchanges, service providers, forensic specialists, and other relevant parties to trace and recover the assets and identify those responsible. More importantly, Bitcoin is transparent by design and the community is made up of the most sophisticated engineers, cryptographers, and white-hat hackers globally. Transactions do not disappear, and neither does the evidence they leave behind. We will not pay for the return of stolen property. We will not abandon our users. The Bitcoin community will not stop pursuing the funds. Return the bitcoin.
764
210
1,612
807,460
Luca Vaccaro retweeted
No, this is evil. Governments are definitely going to get special abilities to fake photos through mechanisms like this. Because they can get secret access to Apple's signing keys. Tools like @opentimestamps are the only democratic way to prove authenticity.
the apple reference photo is likely one of the most consequential things that apple is shipping watermarking AI gen content is a futile endeavor -- the smarter thing to do is to watermark real things instead
8
17
147
13,841
Scammers are thriving right now. Don't Trust, Verify.
Security Notice & Phishing Alert Following the recent Liquid Network incident, scammers are impersonating Liquid and Blockstream and urging users to "take action." Don't. Blockstream will never ask for your recovery phrase or PIN, ask you to send funds, or provide a link for updated software. Never - Send funds to a "recovery" address Never - Enter your seed on a "migration" site Never - Install firmware or software from an email link Never - Reply to unsolicited DMs Treat as scams: "mandatory security update" emails and portals, refund / re-peg / "claim L-BTC" sites, fake support DMs, lookalike domains, and unsolicited "white-hat" or bounty outreach. For verified updates, go only to blockstream.com or the official Blockstream app from the official app stores.
2
6
221
Luca Vaccaro retweeted
gpg --verify SHA256SUMS.asc is easily bypassable for detached signatures. The correct command requires the data file: gpg --verify SHA256SUMS.asc SHA256SUMS This appears to be a common mistake. Without the second argument, gpg succeeds even if the .asc file contains an arbitrary embedded message rather than signing the actual SHA256SUMS file. It prints a warning, but it's easily missed in gpg's output. The gpg manpage explicitly discourages the single-argument form, keeping it only for backward compatibility. I actually keep a list of gpg pitfalls. This is number 8. Mehdi Kerimov reported this in nix-bitcoin's self-updater via @nixbitcoinorg's bounty program. We had originally followed bitcoincore.org verification instructions, which had the same issue and have since been fixed. That this sat unnoticed on @bitcoincoreorg since 2018 shows just how little-known this footgun is. It's unlikely bad signatures were ever published at scale, as anyone noticing the warning or using the two-argument command would have caught it immediately.
12
29
132
16,292
Two kids.. I cook 7 days a week. I still write the code. No own a house. The job is open source. No box. Low money. Low time. Laptop. Omarchy. No robot. No car. BTC. Building a better future. That’s my fuel. 38 on paper. 83 in my head.
No kids. No girlfriend.. I cook 7 days a week. I manage teams of agents. I don’t code Sold the house. Sold the company. Tiny temp furnished box in Montréal. Not broke. Just bored. Laptop. Agents. A robot. A car. Money. French. English enough. Dopamine is my fuel. Dubai? Singapore? Shenzhen? Silicon Valley? Texas? Louisiana? 53 on paper. 35 in my head. If you were me, where do you go?
1
9
480
Privacy, as a human right, has to have many faces defending it and speaking out for it. In today’s world, nobody will give you your rights without your effort; you have to be ready to defend them every single day. Let’s do it together!
Europe has world-class privacy experts. But too often, their voices do not reach the people writing the rules. @LyudaKozlovska joins A Block with @mir_btc in @luganomycity to talk about building a bridge between privacy tech and policymakers. Watch the full block: rumble.com/v7dgycg-a-block-w… @LuganoLivingLab
1
8
36
2,576
the Simple the ₿etter
bitcoin-only hww, custody: complexity is the enemy of security. many alts don't have multisig or schnorr, one sizel lowest-common-denominator resulted in questionable custody architecture choices. bitcoin has cleanest architected, no alt marketing bullshit, hardcore security tech
1
19
2,725
Luca Vaccaro retweeted
This "problem" fucking stupid: wallets should have defined a standard where they backup the descriptor to the Bitcoin chain in encrypted form, e.g. in an OP_Return or taproot annex. For a wallet that is actually used, the descriptor backup would be a tiny % of chain space used.
For years people have said the wallet descriptor backup is one of the main reasons they don’t upgrade to multisig. But many modern hardware signers now store the descriptor themselves (so they can recognize multisig change addresses). And you keep your own copies anyway: cloud storage, encrypted SD card/email, engraved or QR if you’re extra paranoid. After years of using multisig, backing up the descriptor has never been a problem for me.
26
8
129
28,731
Luca Vaccaro retweeted
those who don't understand internet physics, are doomed to learn John Gilmore's quote the hard way. "The internet interprets censorship as damage and routes around it" -John Gilmore (cyherpunks list co-founder)
46
129
1,068
42,668
Luca Vaccaro retweeted
"Veni, vidi, forki" -Julius Dashjr
45
36
501
45,317