@oz_21mi
iAccount based inEurope
About this account
- Account based in
- Europe
- Connected via
- Web
Account-level information from X, not a live location or the device used for a specific post.
#bitcoin #lightning ⚡ Software Solutions Engineer. Information Theorist. Thermoeconomic Hacker. Building @fedibtc LN URL ⚡ : [email protected]
Earth
Joined July 2011
- Tweets11.3K
- Following861
- Followers880
- Likes24.9K
Pinned Tweet
Idk who needs to hear this but the sooner you defeat your ego, the happier and more fulfilled you will be
#stayhumble #stacksats #bitcoin
The nuance to this take is that vanilla harnesses target a one size fits all on the proverbial hat that is interface between your human meat brain and the LLM
If your human brain isn't much different than everyone else's then you're probably fine on vanilla
But LLM devs may not be optimizing for how your meat brain thinks
Also customizing your setup and evaluating whether or not it's better than vanilla might be one of the few ways you can still exercise your brain and not outsource all of your thinking
It's still really intensive work to maintain your own skills, hooks, style guides, memories, etc and you need to be auditing, pruning, and refining them regularly
everything was security by obscurity.
the veil has been lifted.
The end of software secrecy is almost upon us. The death of closed source, and the final triumph of open source.
I should have realized this a few months ago when I successfully decompiled the game of Firefighter from an ancient DOS shareware binary. My robot friend was able to tell it had been written in Borland Pascal from looking at the data layout; it gave me back very readable Pascal code with sensibly chosen function and variable names. I transpiled it to Rust and now ship it as part of my heritage games collection.
The thing is, I thought of this as a fun stunt but didn't have any confidence that the technique would scale up to large, real programs. I have since learned that people are now doing this sort of thing with entire AAA games, which are among the most complex software artifacts ever to be shipped as a binary. If they can be decompiled, anything can be.
This has implications. Massive implications. We need to think about what the world is like when, in general, there is no longer a secrecy moat around almost any software at all.
1/2
oz retweeted
Full post-mortem of the September 19 attack, and a 50% bounty — up to 3.3 BTC — on the stolen funds:
blink.sv/blog/sept-19-attack…
Bounty terms:
blink.sv/bounty-terms
On Saturday September 19 an attacker used a flaw in our admin tools to take over 35 Blink accounts and withdraw about 6.61 BTC from 24 of them. A customer called one of our engineers at 11:39 UTC. Fifteen minutes later the whole custodial service was off. By that evening the hole was closed and the service was back. By Thursday September 24 every affected customer had their exact balance back, in bitcoin and in dollars, paid for by Blink's shareholders. No customer bears any loss.
This was our fault. Not Bitcoin's, not our users'. To the 22 customers whose bitcoin was taken, and to the 3,817 people whose account details were looked up: we are sorry.
How it happened:
From October 2023 until that Saturday, anyone with a free Blink account and a web browser could give themselves the powers of our support staff: change the email or phone on any account, log in as that customer, raise their limits. Three unremarkable mistakes in how our admin tools checked permissions, stacked on top of each other, in code we inherited.
The whole team was busy moving tens of thousands of users to self-custody under new regulation. Monitoring built to catch outages didn't catch an administrator doing things no administrator should.
What it didn't touch:
The money came out of our hot wallet. Most customer funds sit in multi-signature cold storage that nothing in our admin tools can reach. Non-custodial accounts were never in play: we don't hold those keys.
What the attacker saw:
They also read the details of 3,817 other accounts, in some cases a phone number or email address. Not names, not IDs, not addresses, not passwords, not seed phrases. We wrote to every holder we could reach, saying exactly what was seen.
What stopped them:
Two-factor authentication. The attacker logged in to nine accounts that had it on and tried eighteen times to move money. Zero loss.
None of the 24 drained accounts had it on. If you take one thing from this post: Settings → Security and Privacy → Two-factor authentication. Then turn it on for your email too.
What we changed:
The flaw was fixed the same day and a third layer added two days later. The admin tools are off the public internet. The functions that change a customer's email or phone are switched off for everyone while we redesign them. All customer API keys were revoked.
The hot wallet now holds a fraction of what it did. Security fixes are developed privately and published once deployed; the code stays open source. A standing security reporting channel is live, with rewards of up to 0.1 BTC for critical findings.
Where the money is:
Some still sits where it was withdrawn to. About 5 BTC has gone through a cross-chain swap service; a small amount reached an exchange that is cooperating.
Criminal complaints are filed in El Salvador and Próspera, the regulators are notified, and we have traced the funds continuously. We are not expecting the money back.
So we are putting a 50% bounty on it.
Whoever provides the information that leads to a recovery gets 25% of what is recovered. Another 25% of anything recovered goes to Bitcoin Beach, Bitcoin Ekasi, Afribit Kibera and the circular economies they choose. No cap, no end date, paid only out of funds that actually come back. Write to [email protected].
We would far rather have spent this money on grassroots Bitcoin adoption than lost it to a thief. Shame on the attacker.
One more thing:
Ignore any email or SMS about this incident that contains a link: we contacted affected users only through messages in the Blink app. We will never ask for your PIN, password, seed phrase or a login code.
The full post-mortem has the timeline, the technical detail for anyone running code derived from ours, and the bounty terms (links at the top).
oz retweeted
In less than 24 months there will be a clip of a high profile CRO explaining this reality to a (much smaller) room of sales reps.
🚨BREAKING: Jensen Huang just EXPOSED Dario and Altman’s "Rogue AI" grift to avoid getting sued into oblivion under EXISTING law
“Don't let this doomsday narrative cause somebody to relieve them of the laws that currently exist.
Go and read between the lines. They're actually not asking for more laws; they're asking to be relieved of the laws we do have.”
ABSOLUTE TRUTH NUKE
oz retweeted
Big news! Ecash App is now available for iOS!
Ecash App is a feature-rich, transparent Fedimint wallet, now available on iOS, Android, Linux, and macOS.
Confidential transactions in Liquid had an inflation bug before the wrong fix was applied, though it would have been very hard to exploit: independent analysis by Steven Roose
JUST IN: Steven Roose (@stevenroose3), CEO of Second and ex-Liquid maintainer, dives deep in this latest Insider Edition exclusive.
Here's happened exactly last Sunday, Sept 7th leading to the 4k bitcoin exfiltration from the @Liquid_BTC
insider.btcpp.dev/p/how-cach…
oz retweeted
The bug results from an interaction between misunderstood HTLC interception behavior and our LN-ecash swap validation logic that evaded previous scans.
We continue to do our own AI-accelerated security research and appreciate external research findings at [email protected]
oz retweeted
We found a bug in our legacy Lightning integration and are contacting public gateway operators.
User funds, federations, and ecash are not affected.
Gateways using LDK Node or our newer LNv2 protocol are also not affected. We still recommend staying up to date.
🧵
oz retweeted
Why multiple implementations make sense for security beyond a certain point:
Calling on fellow cypherpunks to build alternative Fedimint implementations.
The Liquid hack shows once again that single points of failure are what will break our systems and that includes the code we write.
Security is an asymmetric game: an attacker has to find one weakness, while defenders have to find all. AI has permanently changed the attacker-defender balance for the worse. This is a fundamental problem for the entire freedom tech space and only mitigatable by aggressively reducing single points of failure. Federations are meant to do exactly that, but just like Liquid, Fedimint shares the “single implementation” problem.
If we still want to bring privacy and freedom to the world we need to work together more than ever to reduce these single points of failure. For me that means seeking help to bootstrap independent Fedimint implementations. We are still early, but I've started extracting a specification that others could build off and would love to collaborate with any fellow cypherpunks who want to join us in that mission. In particular, I’d love to work with @callebtc and the @CashuBTC team, who have much more experience with a multi-implementation ecash protocol while the Fedimint team brings federation experience to the table.
While AI exposes existing vulnerabilities and wreaks havoc in our ecosystem, it is also an opportunity for talented engineers to be far more productive than ever before. I’ve been talking with @fedibtc and there is funding for a small, crack team to pull this off. If this sounds interesting as a funder, please reach out! The idea is for the teams to be purposefully disconnected from the existing Fedimint implementation and to work autonomously, communicating mainly through the spec process.
If you too believe that privacy and freedom are needed more than ever, please join us!
153,000,000 American driver licenses leaked in KYC hack
This is 63% of all American driver licenses
In US driver licenses function as valid government-issues photo IDs
krebsonsecurity.com/2026/09/…
I'm not sending anyone my passport anymore
My Portuguese lawyer wanted me to email her a copy of my passport for KYC
I rejected and she was confused
"I've never been hacked"
99% of people are not aware any account probably can and will be hacked on a long enough timespan
The best security is NOT storing sensitive data ever
🚨 If you run Core Lightning, upgrade to v26.06.7 NOW
In the last few hours my node has logged what appear to be automated attempts to exploit the vulnerability behind this release: rapid-fire retries over a 90 minute window from a node that never announced itself.
oz retweeted
This is interesting: iroh.computer
Basically Tailscale but on application level, not network level. Uses QUIC so it is super fast and runs on embedded hardware too!
@iroh_n0
oz retweeted
Running LND in production means knowing when to upgrade. The new published policy gives you that clarity.
Lightning Labs maintains the two most recent release lines, and both get security fixes. A line reaches end of life when the second major release after it ships, so support tracks releases, not a calendar date. Once a line reaches end of life, it gets no further fixes.
Run the latest minor of a maintained line to keep getting LND security fixes. As of today, the latest minors of maintained lines are v0.21.2 and v0.20.3.
For more details: security.lightning.engineeri…
oz retweeted
This is so funny
Readers added context they thought people might want to know
GitHub launched a new status page in December 2018 that introduced granular reporting of individual component uptimes instead of overall service uptime, making pre- and post-2018 data not directly comparable. github.blog/engineering/in… statusgator.com/blog/has-githu…
oz retweeted
Replying to @mouser58907 @Tesla
Yep. The driver literally told me: "I just completely trusted FSD, I knew it would do the right thing."