📣 Peach Web is finally here!!! 🍑
The full peer-to-peer Bitcoin marketplace now in your browser!
No install. No app store. No KYC.
More features. More trading.
The best part: your phone still holds the keys. Safety first 🔐
🧵👇
The Coldcard hack proved @sesi_the_man was right.
Back in January 2026, he warned:
“What I worry more about is, let’s say I set up a hardware wallet and I use it. I set it up using a private key that wasn’t generated with sufficient entropy, that was somehow guessable or predictable by someone else. You think you’ve got X number of sats in your wallet and then one day you wake up and go to check your balance and, because someone else owns your key before you did or was able to guess it somehow, your Bitcoin’s gone. That is a nightmare scenario and something that some people have experienced.”
https://t.co/JrXxv4wKj3
Breath. Bitcoin will always be under attack. They didn't even start the real "then the fight us" phase (illegal status in most jurisdictions, arrests of people promoting it without collateral pretexts, appstore bans, attacks on mining farms to produce empty blocks, restriction on general use hardware, ban on main github repos, etc.). For now we just see an extreme focus of cybersec attacks on our sovereign stack. Bugs that were always there are being found and exploited. But they were there, so it was a matter of time. We have to fix them, full stop. Even if the Lightning Network will be marginally disrupted, the way it's built will allow us to always rebuilt it antifragile-style. In this specific case the Lightning Network is not (yet) under attack, it's currently only LND on BTCPay.
🚨🚨 URGENT: BTCPAYSERVER 🚨🚨
There is a critical vulnerability that is being actively exploited on BTCPay Server which can lead to loss of funds.
Update your BTCPayServer to to 2.4.2 or turn off your BTCPayServer now.
Hey @Trezor, just lost my life savings. Top sponsored Google result for 'Trezor wallet' is a phishing site!
The scam page (https://t.co/z5s9HaJIu2) is vacuuming up millions. Harvesting address is currently sitting at:
bc1qrz33mr7tx8wrpcs2pxrvv83hqwpm907s9shkz4 @zachxbt@CertiK
How does Peach generate seeds for the Peach hot Wallet?
Peach is a mobile app, therefore it has access to the mobile phone's secure pseudorandom source. To put it in simple terms: it relies on the mobile phone's randomness, which is also what is being used for many other security aspects of the phone.
👇
Because this is the current hot topic…
How does Peach generate seeds for the Peach hot Wallet?
Learn about seed phrases and entropy from an easy and peachy perspective
https://t.co/GO3xaRz487
Disclosure: this article was written without AI by @originalexbrou
How does Peach generate seeds for the Peach hot Wallet?
Peach is a mobile app, therefore it has access to the mobile phone's secure pseudorandom source. To put it in simple terms: it relies on the mobile phone's randomness, which is also what is being used for many other security aspects of the phone.
👇
Because this is the current hot topic…
How does Peach generate seeds for the Peach hot Wallet?
Learn about seed phrases and entropy from an easy and peachy perspective
https://t.co/GO3xaRz487
Disclosure: this article was written without AI by @originalexbrou
iOS: Get the stand alone Peach wallet in the App Store
Play Store/Zap Store/Apk:
Get the full Peach marketplace app including the peach wallet
Buy and sell BTC from other people.
https://t.co/hCJhNHvZQU
I haven't told the full story yet, but I came to the same conclusion back in May 2025 when I started doing an audit of `coldcard/firmware`.
I wanted to figure out conclusively where the CC RNG was getting sourced from, and found that it backed up to some shady library called libngu (https://t.co/wQu3wOB7cb) that had literally 6 stars on github and was maintained solely by a pseudoanon tranny.
I knew from past experience that linking to libsecp256k1 from Python was pretty easy, which seemed to be the stated purpose of the library use, and so I was confused about why it was there.
I sent a report to the CC team that I had doubts about whether the true RNG was actually in use, and pointed out that the hardcoded yasmarang constants in libngu were sloppy. I advised they rip the whole thing out and link against libsecp256k1 directly.
I was told that if something was wrong "we'd already know about it by now" and that everything was properly configured for the real boards.
I didn't follow up rigorously, which was a horrible mistake on my part.
Due to internal turbulence the week before the insane coldcard tragedy, we haven’t been present here since a few days.
What happened to Bitcoiners because of coldcard is sickening. Like everyone, we are devastated, upset and much more.
Peach is all good. Users are all good. P2P trades everyday.
Same for Peach Wallet.
Every time you use peach for receiving your sats from a P2P trade, the wallet gives you a new address.
Self custody.
Privacy.
Win.
Reusing a bitcoin address links your transactions and weakens your privacy.
The Blockstream app gives you a fresh receive address every time, and your funds stay in self-custody from the moment you buy.
@masunobom Payment data are E2E encrypted with the user pgp key derived from his peachID. Only the trade partner can decrypt it. Unless users open a dispute.