@SuperTestneti
iAccount based inPuerto Rico
About this account
- Account based in
- Puerto Rico
- Connected via
- United States Android App
Account-level information from X, not a live location or the device used for a specific post.
Open source bitcoin dev | https://nitter.cf/t.co/4WgrYhM4QK #npub1yxp7j36cfqws7yj0hkfu2mx25308u4zua6ud22zglxp98ayhh96s8c399 bc1qefhunyf8rsq77f38k07hn2e5njp0acxhlheksn
Joined June 2020
- Tweets7.5K
- Following64
- Followers3.2K
- Likes5.2K
People who oppose taxation are like people who oppose rent
Oh, you want free stuff? Get in line, the real world costs money
Libertarianism is just crybaby communism
Proposed yesterday, implemented today.
An (emulated covenant) prototype of John Law's new Depot protocol in Sapio github.com/sapio-lang/sapio/…
Hey @BULLBITCOIN_ can y'all stop calling yourselves a self custodial exchange? For the exact same reasons as these guys, it's false marketing. Y'all can freeze user deposits just as well as Swiss Bitcoin Pay could.
An underappreciated thing about the new Wavelength software from Lightning Labs is its name. It doesn't have "Ark" in its name. It's probably the first new payment-focused bitcoin software in the past three years that has avoided that sound.
This is really cool. Transaction Cut Through for Bark and some Cashu mints
So, the bip110 drama is over now, and a bunch of hashrate lost its buyers, making it available at lower prices. And Ocean still works. It's possible to trade in your old coins for some fresh coinbase outputs. Is anyone building tools to automate this and make it more accessible?
Most pro110 miners are renting rigs from sites that don't accept bip110 coins. Those pro110 miners can only keep mining if they maintain a reserve of non110 coins, to pay with those. That means the most economically significant pro110ers will still be supporting the non110 chain!
Mostly this. But I think it's fine to play around with a small amount for fun. With a small amount, try to learn how to split your coins. If you succeed, you can then mix the split "small amount" with more coins to split more of them. But don't risk large amounts for this stuff.
Tonight Bitcoin might split, and the correct move is to do absolutely nothing. That's harder than it sounds, so here's what's actually happening:
At block 961,632, expected around 22:30 CET, nodes running BIP-110 start rejecting every block that doesn't signal for it. Miner signaling is at 2.6%. The threshold is 55%.
Those nodes are about to reject the chain carrying essentially all of the world's hashrate. What's left is a minority chain where blocks arrive whenever they feel like it.
Worth noting: BIP-110's real restrictions wouldn't kick in until around block 965,664, so early September. The split risk is tonight.
If it happens, three things are going to hurt people.
No replay protection.
That's the mechanism that makes a signed transaction valid on only one of the two chains. It doesn't exist here. Sign a transaction to dump your "free fork coins" and that same transaction can be rebroadcast on the main chain, taking your real bitcoin with it. Send 1 LukeCoin to a friend and your friend can walk off with the real bitcoin sitting on that same UTXO.
A shared UTXO set is a shared privacy leak.
Both chains inherit the same set. If you've got a non-KYC wallet with coinjoined funds and you consolidate all your fork coins into one transaction, you just linked those outputs on the real chain too. Same graph, same heuristics, two chains.
Claim scams.
Apps and sites offering to help you "claim" fork coins will show up within hours. Most of them want your seed phrase, and a seed phrase hands over the worthless coins and the real ones at the same time.
So the boring advice wins. Don't move anything. Coins that sit still cannot be replayed, because there is no signature to copy.
Anyone telling you to hurry up and claim something is working for the other side.
Super Testnet retweeted
It’s been a bumpy ride. If you’re trying to keep up to date or just need some comradery, come out to @SanJuanBitdevs Wed Aug 19th at Base Cowork this time.
RSVP below 👇
Super Testnet retweeted
Brief writeup on the replay protection mechanism I designed for @Truthcoin's Ecash fork. Might be useful for other forks as well as you can use different versions:
gist.github.com/RobinLinus/c…
Super Testnet retweeted
Like many, I've barely slept since the Coldcard incident. My mind has been racing on how to stop this from ever happening again.
I believe I've come up with a novel wallet design that solves Bitcoin's self-custody trilemma.
Live on mainnet.
Writeup: lu.ke/self-custody-trilemma
Super Testnet retweeted
There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds.
Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Server -> Maintenance -> Update & verify the 2.4.2 version string in the footer.
If you are unable to update right away, turn off your BTCPay Server to prevent unauthorized access until you can update.
Hey @leo_haf can you confirm that your electrum server (the one that backs mempool.guide) is backed by a node that follows the bip110 rules? (ie it will start rejecting non-signaling blocks soon?) I'm looking for one I can use for a coin splitting project involving RBF.
With ~48 hours left to go til bip110's so-called mandatory signaling period, less than 2.5% of blocks are signaling, and all are part of Ocean or tiny solo pools. A chain split looks very likely in the next two days. Sayonara, reckless bippers. I hope you learn from this mistake.
Here's something that interests me about the coldcard bug: it had 2 random number generators. The "bad" one was seeded with data including keypresses, the timestamp, and the device id. I can understand that, it's probably how I would seed it. What was the "good" one seeded with?
red teaming bitcoin:
- we’ve written multiple harnesses and we’re launching a huge wave of reviews against many core bitcoin projects: crypto libs, wallets, infra, …
- situation is extremely bad.
- we’re averaging on the order of 1 critical exploit per hour per person.
- we’ve reported critical vulnerabilities to several projects in the last 12 hrs.
- thankfully this is a very expensive exercise, we’re burning through 10k per day.
- you can donate tokens or accounts. send me a dm.
- thank you to @OpenSats for covering the bill.
- thank you to @Kimi_Moonshot and Kimi K3 for providing us with accounts and uncensored intelligence
Bitcoin Red Team Update:
We have been working around the clock, with ~$20,000 of spend up to this point across different services. Funding is secured, I appreciate all the gestures for donations but it is not necessary. The bill is taken care of.
We have done over a dozen disclosures up to this point, with 150 repos scanned. The hardest part is coordinating to get things to the right people (thank you @danielabrozzoni for the help)
I have a first pass on a bitcoin red team agent harness which only requires an @opencode zen api key, makes it easy for us to use K3 for the actual heavy lifting and then GPT Sol + Fable/Opus + GLM5.2 for supporting documentation.
While it is powerful, having found critical issues, I would view this as only version one. There is a lot of iteration I'm looking forward to improving on.
Our goal is to open source the harness so it can be pointed at internal repositories for insights so the hardening of defenses can go deeper than the code which is made public.
We also have been connected with OpenAi for some help so I could manage getting the @OpenAI Cyber Harness running as well (thank you @lylepratt ). Its a much more expensive scan, but well worth it for load bearing portions of the bitcoin ecosystem and has already yielded good results.
Goals for tomorrow are scale in processes and systems so we can do a better job and automating full end to end functionality to get humans out of the loop for the heavy lifting. The first mile (requests/staging) and last mile (handoff of reports) are the choke points right now.
Thank you @stutxo @callebtc @benthecarman @thesimplekid and so may more.
Super Testnet retweeted
Seeing a lot of people saying “self custody is over” thanks to the Coldcard hack.
Couldn’t disagree more. ~1,100 BTC has been stolen so far (est). And ~11,000 BTC went to exchanges yesterday. Potentially 10x more BTC was saved thanks to the fact that it was held in self custody! Why?
The distributed defense of self custody GAVE PEOPLE TIME to save their own money. If that RNG bug happened at a centralized custodian, all of the BTC is gone in one swoop. No time to react. But when it happens to a self custody wallet, each wallet has to be found and swept individually. People have time to act.
It makes the entire Bitcoin system more systemically resilient. And yes, it’s terrible that people are losing money. But in a scenario where this happens at a custodian, you eliminate any chance to react and save some people. If all bitcoin is held by a few centralized companies, you reduce that distributed defense and significantly increase the systemic risk of Bitcoin as a monetary network.
Last year the US government sent a bailout to Argentina. Now it is apparently sending a bailout to Japan: cnbc.com/2026/08/01/us-treas…
If you're into macrofinance, this is interesting: $1 of USD has been worth over 160 JPY for over 24 hours. Usually, the Japanese government treats the 160 mark as a "red line," and within a few hours, they intervene by selling loads of USD. This time maybe they aren't doing that?