⚠️ Security notice
We recently discovered a security incident affecting customer support data at Pocket Bitcoin. Your bitcoin and private keys were not affected by this incident, as Pocket is non-custodial and never holds your keys.
Full details and what to be aware of:
https://t.co/JYvpPRUSDX
Customer: I lost 3 BTC. Five years of DCA. What are you doing for the people this happened to?
Coldcard: A new firmware release is available. 5.6.1 for Mk4 and Mk5.
Customer: I’m asking about the victims.
Coldcard: This release follows three weeks of sustained review.
Customer: Are you sorry?
Coldcard: We continue to acknowledge the customers who suffered severe financial losses.
Customer: Is acknowledging the same as sorry?
Coldcard: It is an acknowledgement.
Customer: Who wrote the code that emptied me?
Coldcard: It was the seed-generation attack.
Customer: Who wrote the code?
Coldcard: The attack.
Customer: Is anyone being compensated?
Coldcard: Updating does not repair an existing seed.
Customer: Is that a no?
Coldcard: Users should generate a new seed and move their funds.
Customer: There are no funds. That’s why I’m here.
Coldcard: We strongly recommend verifying the signed firmware download.
Customer: Have you spoken to a single one of us?
Coldcard: The release includes many additional security and correctness improvements.
Customer: Have you spoken to a single one of us?
Coldcard: Thank you for helping make this release stronger.
Customer: Do you understand what you’ve done to us?
Coldcard: The firmware is available now.
Introducing https://t.co/GVgJI9w7Ec a Boltz fork now running for the community.
Thanks to the effort of our team, the project is now live. Thanks to the great software work by Boltz team.
Wake up babe, new onchain vault design just dropped.
Connector Vaults: Delegated Execution and Stateless Revocation
Cuts the presigned txs required for the Anzen signing ceremony in half!
https://t.co/NsV22YamxD
How fast can you go from zero to integrating Bitcoin and Lightning payments into your app? In just minutes with Wavelength.
Clone the repo, install, and you're sending and receiving — done. No liquidity to manage. Works for humans and AI agents alike.
Watch the demo. 〰️⚡
Since August 1st, we have seen an elevated number of attempts on our platform, and many partners reported AI-assisted attacks.
We quickly partnered with Prem AI for quick, confidential access to uncensored Kimi K3.
We then helped tune audit patterns for the Bitcoin codebase into a custom harness that found more issues requiring attention.
Today that harness became available as Cyberscan. Give it a try!
Bisq v1.10.5 is released.
This important security update fixes vulnerabilities identified during our recent security audit.
Updating to this version is required to continue trading and using the Bisq DAO.
https://t.co/e4PhQ1ap8Y
Djuri is an *awesome* bitcoiner and his FOSS/H github repo was taken down a couple of years ago b/c of Coinkite legal action. Consider supporting his work and ordering a BTClock. The software is actively developed and has tons of awesome features.
https://t.co/8GGSgPmqzz
We've compressed the full chain address index (i.e. Electrum) down from 160GB to 16GB without sacrificing our blazing IBD (22 mins over 5Gbps internet) or query response (24ms to get a 27,656 output address history) times. How can this be??
There's a lot of people rn in the process of moving funds & creating new #bitcoin setups.
Yet, the #1 reason people lose bitcoin?
POOR BACKUPS.
So today I'm launching https://t.co/gP26SvAWnt.
A dedicated document for MAXIMALLY secure paper backups.
100% free & open source.
We just released the Dixence security update.
During our internal audits, we were able to discover and fix multiple security issues in the BitBox firmware.
We recommend our users to update their BitBoxApp and device firmware through the BitBoxApp settings.
https://t.co/bcHaeVU641
RBITCOIN LAUNCHES NEW BITCOIN NODE IMPLEMENTATION
After more than eight years of thinking about the project, @reardencode prompted @grok to help build rbitcoin, a new Bitcoin node implementation written in Rust.
https://t.co/5F38E2KIVs
It supports Electrum, Esplora and Bitcoin Core RPC interfaces.
The fully synced node takes up roughly 850GB, including transaction and Electrum indexes, and synced to mainnet in under 30 hours on a laptop.
The project uses minimal dependencies, modest RAM and a compact storage architecture, with no UTXO set.
reardencode says it is ready for use as a wallet backend.
With @KeithMukai’s help I got to take some of the experimental microcontroller UX for a spin (sorry for the poor video quality, was just playing around). The experience is super compelling, DIY just continues to get better and better.
WASABI WALLET HAD HIGH-SEVERITY OS COMMAND INJECTION VULNERABILITY FOR TWO YEARS
A vulnerability introduced in February 2024 could allow an attacker to craft a malicious coordinator link that, if copied into a user’s clipboard and followed by clicking “Read More” in Wasabi, could execute commands directly on the user’s Mac or Linux computer.
The commands could run with the user’s permissions, potentially accessing wallet data, stealing keys, installing malware, or tampering with transactions.
The flaw was introduced two months before the Samourai Wallet arrests and server seizures in April 2024 and remained in Wasabi until it was patched in March 2026.
The code was reportedly introduced by an anonymous developer who later scrubbed their Git history.
H/t @LaurentMT@noosphere888x2
Critical vulnerability in the bip322 Rust crate: BIP-322 proofs for P2WPKH and
P2SH-P2WPKH addresses could be forged with any attacker key. Full
address-ownership bypass. Fixed in 0.0.11, affected versions yanked. If you
verify Bitcoin address ownership, please upgrade now.
Mostro v0.18.3 is out 🧌⚡️
This release brings several important bug fixes and reliability improvements, including:
🧹 Fixes for ghost orders and public order book synchronization
🔄 Re-subscription of held invoices in fiat-sent and dispute states
🔐 Restricted trade public key rotation to the order creator
⏱️ Enforced CLTV expiration for trade escrow
🛡 Improved handling of pre-trade orders and order release
A special thanks to the Red Team 🟥 for their great work identifying and reporting high-priority bugs. Their efforts have helped us uncover and fix several important issues in this release.
Update your node 👇
https://t.co/AVjacFTOkd
#Bitcoin #Lightning #Nostr #P2P #Mostro