In two days' time Julian and I will be doing an open Jitsi meeting to discuss the work on Script Restoration. Come and ask questions!
1pm Berlin time:
https://t.co/I6BrA4riVE
Today is a sad day for the Lightning Network community as one of our very respected developers is moving on to new ventures.
At the same time, I am delighted that I had the opportunity to collaborate with @rusty_twit and learn so much from him. In any case, I wish him well!
This is so fucking embarrassing.
Bitcoin is a 1.6T USD asset.
While the entire world is sending their best experts in cryptography and quantum physicists to debate the dangers of quantum computers, we're forced to listen to a purified influencer pleb slop gobbledygook.
These people sound like they're at the verge of psychosis. I'd rather listen to a new age hippie high on DMT and it would make more sense than this.
Gm. just a reminder that most people your age are also just figuring it out. the ones who seem certain online are performing certainty. you're not behind you're just honest.
Core Lightning 26.04 "Negative Routing Fees" has shipped.
Splicing is out of experimental, the node runs leaner, and peer messages are now padded to resist traffic analysis. ⚡
A security researcher just documented a large-scale counterfeit Ledger Nano S Plus operation selling compromised devices across multiple online marketplaces.
The fake units look identical to the real thing but contain completely different hardware. Instead of Ledger's secure element chip, the counterfeits run an ESP32 microcontroller with modified firmware labeled "Nano S+ V2.1." Seeds and PINs are stored in plain text and transmitted to attacker-controlled servers. Any wallet initialized on the device is drained.
The operation goes beyond the hardware. The sellers also distribute a fake version of Ledger Live built with React Native and signed with a debug certificate. It intercepts transactions and exfiltrates sensitive data to multiple command-and-control servers. The campaign spans five attack vectors: compromised hardware, Android APKs, Windows executables, macOS installers, and iOS apps distributed through TestFlight to bypass App Store review.
This comes days after ZachXBT documented a separate fake Ledger Live app that made it through Apple's Mac App Store review process. That operation drained over $9.5 million from more than 50 victims, including musician G. Love, who lost 5.92 BTC after entering his recovery phrase into what he believed was the legitimate app.
The pattern is clear: the attack surface for hardware wallet users has shifted from firmware exploits to supply chain and distribution fraud. The devices themselves remain secure. The problem is that users are being intercepted before they ever touch a real one.
Ledger's own "genuine check" feature can be bypassed when the hardware itself is compromised at the source, which makes where you buy the device as important as how you use it.
The rules haven't changed, but they've never been more important: buy hardware wallets only from the manufacturer. Never enter your recovery phrase into any software. If a companion app asks for your 24 words on a screen, it's a scam. Every time.
@niftynei@MITBitcoinClub@achow101 It's been at least 20 years since I said (of Linux kernel development scaling, with git, maintainer hierarchy and all) "reviewing doesn't scale, so we stopped doing that".
always_was.gif
@JeremyRubin I don't follow. I think the types are /opcode/ dependent, i.e. OP_ADD and similar arithmetic operations treate operands differently from OP_LEFT, etc.
I love me a good type system though! Are you thinking something more like simplicity?
Rusty Russell (@rusty_twit) wrote on the Bitcoin-Dev mailing list that the first two BIPs of the Great Script Restoration (or Grand Script Renaissance) have been submitted for BIP numbering...
https://t.co/PbWeDBq0nz
New number assignment:
The “Grand Script Renaissance” BIPs, “Varops Budget for Script Runtime Constraint” and “Restoration of disabled script (Tapleaf 0xC2)” shall be referred to as BIP 440 and 441:
someone reminded me that i should spell out for people that the reason there are a gazillion @btcplusplus events around the globe is because the vision is that almost every dev has access to a top-tier bitcoin developer conference in their backyard ✨
running the @BitcoinWildlife Circle Plonk verifier in bitcoin script with full GSR (OP_MUL and OP_CAT) uses at least 6x less block space compared to using OP_CAT alone
both implementations have negligible validation cost, the full verifier executes in less than 10ms
@AbdelStark