More than ever, we desperately need a wallet that has a lot of eyes and contributors. As much as I like Liana and Sparrow, we cannot rely on a wallet developed by one company or developer.
There's an active effort to revamp the Core wallet. Try it and file feedback https://t.co/UDhIQ2d86j
When you download Bitcoin Core today, the binary doesn't contain everything your node runs. It still loads the C library (glibc and friends) from your operating system which means there are version requirements, behavior that can vary from machine to machine, and code that your node executes that isn’t covered by reproducible builds.
New static test builds pack it all into one deterministic Bitcoin Core binary.
@fanquake is asking node runners to test out these new static binaries and report results.
I said a thing or two about relaying stale tips.
Blocks may be stale, but the proposal is still fresh. Do review if you're interested - https://t.co/R8BSVDagSf
gained a ton of new insights working in bitcoin red team 🟥 that i wish i could share without vague posting. but this is what i got anon.
- we’re experiencing a massive collision between decades of human open source slop against 2 weeks of kimi k3 (not good)
- everything is broken, bitcoin is burning
- bitcoin is becoming stronger through this
- bitcoin is the obvious first target but the rest of the world will follow shortly
- sometimes old things need to burn so new things can grow on healthy soil
- humans should never code in c (just stop)
- lightning is complicated and is more broken than the average (sorry)
- verification is free. we used to complain about slop PRs. then about slop security audits. if you can’t handle the information overload, stop complaining and use AI to sort through it.
- those projects that started AI audits months ago are in a completely different position than those who didn’t
- projects need their own AI audit pipeline going into the future
- the burden for a developer to keep software safe and secure is pretty stressful and not for everyone. it has become a lot more stressful now.
- unmaintained projects are most probably broken, don’t rely on them. i’d rather one-shot it myself with a modern AI
- multiple concurrent, diverse human approaches have proven to be the best vulnerability search method
- external red teaming will probably have to continue forever
- we’ve basically completed a basic scan of virtually the entirety of bitcoin open source. the low hanging fruit is done.
- we’ve reported a ton of real critical and high vulnerabilities. project maintainers across the board have validated our findings.
- response speed is very different across projects and shows how healthy each project is. i recommend acting fast these days.
- red team etiquette matters. if you don’t disclose responsibly, boast on twitter about your findings on a particular project, or make indications about the nature of particular findings, you’ve disqualified yourself as a serious security researcher. trust is the most important factor in this game. if you lose it, it’s very hard to win it back.
- did i mention that humans should not code in c?
love you all.
We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days prior to August 8th, 2026.
The data exposed:
- Full names
- Shipping addresses
- Phone numbers
- Email addresses
The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email). The breach is limited due to Trezor’s strict 90-day data storage policy (we were also able to negotiate the same terms with fulfillment partners, who follow the same policy).
All affected customers have been contacted separately by email.
Our systems and devices remain secure, but affected customers could experience an increase in phishing attempts.
NEVER enter your wallet backup on a website or share it with anyone, and only check for updates on official Trezor channels.
We are deeply sorry to the community and those affected.
We are investigating this situation and will post updates on our blog:
https://t.co/JGrttMs4Ev
One more thing: the new QML based Bitcoin Core GUI is available for adventurous testers only as an early preview demo.
We've had some rounds of testing with a select group of devs and the great team over at @lclhostresearch giving good feedback and finding bugs.
It’s experimental, signet-only, and not an official Bitcoin Core release. Try it and tell us (@johnny9dev, @pseudoramdom) what works and what you don't like:
https://t.co/YUG3WANrwC
None of this would be possible without the @bitcoin_design community and their benevolent dictator @GBKS
Goal is to get this across the finish line for the following Bitcoin Core release. 🌎🌍🌏
Bitcoin Optech newsletter #417 is here:
- describes a draft BIP for relaying stale block tips between peers
- summarizes a draft BIP for cross-input signature aggregation
- examines a design for attaching post-quantum witness data
- links to a discussion of post-quantum output types
- summarizes discussions around transaction expiry
- points to a proposal for layered quantum recovery of hashed addresses
- describes a proposal to add a prunable block region for arbitrary data
- Optech Newsletter #417 Podcast
Sometimes, trust your guts. Even when you are told it's FUD. Turns out I was right, and that instinct saved so many fucking people. 5 days later, I think I'm not needed anymore, thank you everyone who trusted me and spread the word so quickly.
I'll write a "post mortem" as I lived it, as I think it's probably going to stay as my most valuable contribution to Bitcoin. Good night people, I hope you are safe.