@BitMaker_i
iAccount based inSpain
About this account
- Account based in
- Spain
- Connected via
- Spain Android App
Account-level information from X, not a live location or the device used for a specific post.
Bitcoiner | Hardware dev | NerdMiner | Bitronics 🛒https://nitter.cf/t.co/QfF3YMuaVz 🟪[email protected] ▶️https://nitter.cf/t.co/3ecbGoWDfE
Joined April 2022
- Tweets3K
- Following862
- Followers11.6K
- Likes5.4K
Nuevo vídeo en el canal 🎥
¿Bitcoin ya es resistente a la computación cuántica?
¿Es QSB la solución a esta amenaza?
Hablamos de ello aquí
youtu.be/tribW8d-uag
🤖 Made with AI
Esta cami la llevo en mi último video 😘
Día 15 mostrando catálogo camino a la @Wo_Bitcoin
Esta vez es turno de un crossover genial entre #Bitcoin y cierto fontanero bigotudo con nuestro querido Proof of Work.
Aún recuerdo la cara de @BitMaker_ cuando la vio el año pasado 🤩
La fuerza del POW, señoras y señores !
Nuevo vídeo en el canal 🎥
Os cuento cómo funciona ZeroKeyUSB: un gestor de contraseñas físico, del tamaño de un pendrive, que se desbloquea con un PIN en el propio aparato y os teclea las credenciales. Sin drivers, sin nube y sin internet.
youtu.be/owuKRyydYRQ
🤖 Made with AI
Nuevo vídeo en el canal 🎥
Os cuento cómo generar tu propia semilla de Bitcoin con unos dados o una moneda, completamente offline, con la nueva Seeder:
Open source y en la misma placa que el NerdMiner.
Tu semilla, tu azar 👇
youtu.be/432U6e3b6lw
🤖 Made with AI
🌱 Seeder is now available in the Bitronics Flasher.
Generate your Bitcoin seed 100% offline using your own entropy, on the same portable device you already use for NerdMiner, NerdAxe, NerdQaxe...
🔐 Your seed. Your entropy. Offline.
flasher.bitronics.store/
Aquí la explicación del caballero de capa roja👇
Liquid hack explained.
Liquid has confidential transactions that hide the amounts for improved privacy. A bug in how these transactions are validated caused inflation of Liquid BTC (L-BTC) and allowed hackers to empty the entire side chain.
Liquid nodes don't see the amounts of a confidential transaction, so to make sure that the transaction is still valid and doesn't cause inflation nodes check something called a balance proof and a range proof.
The balance proof establish that sum of the input amounts equal the output amounts, i.e., that "x L-BTC going in and x L-BTC going out". But there's a catch. Only relying on a balance proof isn't enough. You also need the range proof.
The range proof establishes that a hidden output amount falls within a positive range. That means a valid output must be at least 1 L-sat and at most 2^64 − 1 L-sats. Range proofs make sure that you can't mint "negative L-BTC".
Why is this even necessary? Remember, the amounts are hidden and a hidden negative amount would allow extra positive outputs to balance against it. Without a range proof, a transaction could say "I've put 1 L-BTC in, and I'm taking two outputs out: one with 4000 L-BTC and one with -3999 L-BTC)."
This is going to cause a disaster in a little bit.
Once the balance proof, the range proof, and other validations pass, a transaction is regarded as valid and can pass consensus. However, because especially the range proof is computationally expensive, Liquid nodes cache the result of a successful range proof in memory. Essentially, the node remembers "I saw this range proof before and it was valid, all good!".
In order to recognize the same range proof later on, you need to assign a label to it. This is called a cache key. This cache key is the actual cause of the bug.
The way this cache key was constructed allowed two different transactions to collide on their cache key. Essentially, one valid transaction (1 L-BTC in, 1 L-BTC out) had the same cache key as an invalid transaction (1 L-BTC in, 4000 L-BTC out).
Here's the hack: the attackers submitted the valid transaction (1 L-BTC in, 1 L-BTC out) first. Liquid nodes verified this transaction successfully, created a cache key called REKT and stored it in their cache. Then the attackers carefully crafted a second invalid transaction with (1 L-BTC in, 4000 L-BTC out) that created the same cache key REKT.
Instead of validating the second transaction and realizing that it printed money out of thin air, Liquid nodes found it in their cache and said "hey I saw this transaction before, everything is fine" and that caused the inflation.
The attackers then took their 4000 L-BTC and withdrew 4000 BTC onto the Bitcoin base chain.
Note: I might have gotten some details wrong, and I'm aware that I simplified quite a bit. I wrote this post to help people understand what happened. Please feel free to correct me in the comments or add more details below.
Ni el Red Team se adelantó a esto.. que más está por venir? No me quiero imaginar como estarán el resto de redes "crypto"
Nuevo vídeo en el canal !🎥
Si como yo te volviste loco con los anuncios de tantas vulnerabilidades este agosto... Aquí os cuento lo que pasó: robos, servicios cerrando por ataques con IA… y un grupo vestía de rojo capitaneando la defensa 👇
youtu.be/yNrVoEcOXBE
🤖 Made with AI
BitMaker ⚡ retweeted
Avui colabo de @BitronicsStore amb @TrobadesBTC fent taller de frases llavor amb daus. Ens ho hem passat molt bé, com tornar al col·le! 🤣
Si algú vol fer-lo, el dia 19 estarem a Guardiola de Font-rubí i el 26 a Tarragona, stay tuned!
Hoy Trobades Bitcoiners se vino a @BitronicsStore para hacer una formación en generación de semillas.
Utilizamos la seeder para validar todo el trabajo y aquí queda un buen ejercicio.
Hoy Trobades Bitcoiners se vino a @BitronicsStore para hacer una formación en generación de semillas.
Utilizamos la seeder para validar todo el trabajo y aquí queda un buen ejercicio.
BitMaker ⚡ retweeted
The NerdAxe Gaia 2.4 TH is here! 🚀
We’ve spent the last few days testing and fine-tuning it to achieve the best possible efficiency. Orders have already started shipping, and you’ll receive your tracking number soon!
Thank you so much for all your support! 🙌
Someone actually made a NerdMiner fork for BIP-110 BTC… This is karma for Luke 😂
Will those spammer miners help?
La história duró demasiado
OCEAN and Luke Dashjr announce today that, by mutual agreement, Luke Dashjr has separated from OCEAN, resigning as Chairman, Chief Technology Officer, and director.
Link to the joint statement press release here: prnewswire.com/news-releases…
Ver el grupo BBO es lagrimita, quiero uno para comunidad 😇@bcnbitcoinonly @Malaga2140 @Bitcoin_2140 @BitcoinTuesday_
Nuevo vídeo en el canal! 🎥
Os cuento cómo funciona y cómo podéis usar la nueva funcionalidad de SOLO groups en Bitronics Pool.
Mina solo, pero con tu comunidad. Si te toca el bloque, lo repartís entre vosotros
youtu.be/eMxS2kAaGIY
🤖 Made with AI
Nuevo vídeo en el canal!
Bitcoin se ha roto 🥲
¿Qué ha pasado y cómo hemos llegado hasta aquí?
Del anti-spam a un chain split y ahora un cambio de algoritmo en Proof of work...
youtu.be/THXbejeRn8Y
🤖 Made with AI
No se salva ni una 😞
Bueno, tansolo seedsigner
Confío en que todo esto es positivo
BITBOX DISCLOSES TWO SEVERE HARDWARE WALLET VULNERABILITIES
@BitBoxSwiss says there are no reports that any of the vulnerabilities were exploited or that user funds were stolen.
All disclosed issues are fixed in firmware v9.26.5, and BitBox is urging all users to update immediately.
Internal security audits uncovered two severe vulnerabilities, along with new details about a previously fixed bootloader flaw.
One vulnerability affecting BitBox Multi devices could allow a malicious host to execute arbitrary code and potentially install malicious firmware on devices that had not yet been set up.
Another flaw in Silent Payments could allow an attacker using a malicious host device to redirect funds to an unintended address, locking the Bitcoin and potentially enabling a ransom attack.
BitBox also disclosed that a previously patched bootloader vulnerability could have allowed an attacker to trick users into installing malicious firmware capable of stealing funds.
BitMaker ⚡ retweeted
UPDATE ON THE FUTURE OF BOLTZ 📢
Over the past couple of months, AI-assisted attackers have been targeting Boltz with increasing frequency, intensity and sophistication. Several of these attacks succeeded, but because Boltz is non-custodial, user funds were never at risk. The entirety of the risk was ours, and as a result of the losses incurred, on August 3rd we made the difficult decision to suspend the service to prevent further damage.
While working on a plan to bring Boltz back over the past days, we had to accept one painful insight: as a bootstrapped five-person startup, we simply don't have the resources to withstand the current level of attacks in the long run.
Today, we are happy to announce that a group of veteran Bitcoiners came forward to help, bringing the capital and engineering power the project needs. They have agreed to take over Boltz and continue the service. Work to find and fix the vulnerabilities is already under way, with the goal of bringing swaps back as soon as possible.
As we want to give them the freedom to introduce themselves in their own time, we are not attaching any names today.
All original founders of Boltz have stepped down from the company, effective immediately. None of us will have any formal or authoritative role with the Boltz project going forward, and any future open-source participation by us is strictly on a voluntary basis.
We are grateful for the community's support all these years, for the patience and understanding of our integrators affected by the disruption of our service, and to everyone who reached out offering support over the past week.
It was a hell of a ride, and we are proud of our contributions to the Bitcoin ecosystem.
Godspeed to the new Boltz team as they navigate these perilous times. We know Boltz is in good hands.
- Kilian, Michael & Karl