
4000 BITCOIN HACKED
Discussed in this episode
Boost this Episode
Send sats directly to the creators. Value for Value.
Plus 1% to Podcast Index, 1% to Boost Bot.
Show Notes
A weekly news show informing you on the latest in Bitcoin, privacy and open source tech, hosted by Ungovernables, Max and Q.
AOB
First live show!
Ungovernable.network updates
KeyOS 1.4 is out
NEWS
Liquid exploit: roughly 4,000 BTC withdrawn; return discussions ongoing– TFTC, CoinDesk, Stacker News | Updates: OrangeSurf, Samson Mow
Orionx Exchange Collapses in Chile: $7M Missing, 100K Users Affected – TFTC
Coinbase/Better Bitcoin-Backed Mortgages Can Reuse Borrowers’ Collateral – CoinDesk
House Cancels Late-September Votes, Squeezing CLARITY Act Window – Roll Call, CoinDesk
Trezor Breach Worse Than Reported: 67,000 More US Customers Exposed – Bitcoin Magazine
Pocket Bitcoin Breach Links 291 Users’ Identities to Bitcoin Addresses – Pocket Bitcoin Blog
Coldcard Wave 3 Attacker Moves Stolen BTC Through THORChain – TFTC
Tether Froze $42.4M USDT on a Verbal Homeland Security Request, No Warrant – CoinDesk
RELEASES
Highlights
KeyOS v1.4.0 – 2026-09-04
- Major release for Passport Prime with a redesigned launcher, app sideloading with granular permissions, multisig exports for Unchained and Casa, new wallet connections (Bitcoin Safe, Coconut Wallet), authenticator imports from Aegis and Proton, and PIN-before-seed-reveal. Includes security fixes: P2WSH/P2SH-P2WSH change output validation, enhanced ATECC608 entropy, and a PSBT trust_witness_utxo toggle addressing CVE-2020-14199.
- Adds native Trezor hardware wallet support for Bitcoin cold storage and offline signing. Fixes a security vulnerability (GHSA-695v-fhpj-fv8x) where a malicious deep-link could cause EVM assets to be sent on an incorrect network. Also includes improved Monero sync visibility.
- Adds BitBox02 connectivity over Bluetooth and USB, integrates Krux hardware wallet support, and introduces emergency push notifications with home-screen alerts.
- Major update adding three new coordinators (Eleuteria, Freeport, Ammanaya), a federation consensus mechanism, and end-to-end encrypted image uploads in order chat via Blossom. Coordinators are now ranked live by DevFund donation value. Multiple security fixes including PGP verification.
Aqua Wallet v0.5.3 – 2026-09-01
BasicSwap DEX v0.18.6 – 2026-09-06
BitBox02 Firmware v9.27.1 – 2026-09-04
Bitcoin Knots v29.4.1 – 2026-09-02
Blockstream Green Desktop 3.5.4 – 2026-09-04
Bull Bitcoin Mobile 6.13.4 – 2026-09-04
Cashu CDK v0.18.0 – 2026-09-02
Cashu TS v5.0.0-rc.9 – 2026-09-04
Coldcard Firmware v5.6.2 and v1.5.2Q – 2026-09-03
Flint v1.0.4 – 2026-09-02
JoinMarket-NG v0.39.1 – 2026-09-06
LDK v0.3-rc1 – 2026-09-04
Lightning Terminal v0.17.4-alpha – 2026-09-03
LND v0.21.3-beta – 2026-09-02
Mostro v0.18.7 – 2026-09-05
Specter-DIY v1.10.5 – 2026-09-06
Tails 7.12 – 2026-09-05
Zeus v13.2.1 – 2026-09-02
EDUCATION
Liquid explainer: cached validation versus key compromise
- Use OrangeSurf’s technical notes alongside the DeFi Prime explainer. Treat early reporting as provisional, not a completed postmortem.
- The reported flaw lets an invalid proof receive a cached pass; confidential amounts do not make validity unknowable. OrangeSurf reports one explorer rejected the transaction, with the cause of divergence unresolved.
- Do not describe this as cryptographically bypassing federation signatures, or assert that Confidential Transactions hid issuance from every observer.
- The SpendNode discussion can frame key compromise versus invalid issuance, but its incident details need the qualifications above.
- Holding an L-BTC wallet key still leaves the underlying BTC dependent on the federation and the system’s validation rules. Mainchain self-custody avoids that particular peg exposure; it does not eliminate all software or consensus risk.
- Pair with Mow’s on-chain message chronology: an offer to return most funds is not completed recovery, and an acknowledgement is not proof of a complete patch.
- Published: 2026-09-04
- Explains how mining pools could use BIP352 silent payment addresses to pay miners directly in coinbase transactions, replacing xpub-based payouts and improving miner privacy. The newsletter also covers the full CLN ping-flood DoS disclosure and post-quantum signature proposals.
- A concrete, actionable application of silent payments moving from theory to real infrastructure. Shows how the protocol can improve miner privacy without new consensus changes. The CLN disclosure detail is also worth mentioning as follow-up to last episode’s CLN coverage.
TO DONATE TO ROMAN’S DEFENSE FUND: https://freeromanstorm.com/donate
HELP GET SAMOURAI A PARDON
- SIGN THE PETITION —-> https://www.change.org/p/stand-up-for-freedom-pardon-the-innocent-coders-jailed-for-building-privacy-tools
- DONATE TO THE FAMILIES w/ USD —-> https://www.givesendgo.com/billandkeonne
- DONATE TO THE FAMILIES w/ BTC —-> https://pay.zaprite.com/pl_JpxtkLv95T
- SUPPORT ON SOCIAL MEDIA —> https://billandkeonne.org/
VALUE FOR VALUE
Thanks for listening you Ungovernable Misfits, we appreciate your continued support and hope you enjoy the shows.
You can support this episode using your time, talent or treasure.
TIME:
- create fountain clips for the show
- create a meetup
- help boost the signal on social media
TALENT:
- create ungovernable misfit inspired art, animation or music
- design or implement some software that can make the podcast better
- use whatever talents you have to make a contribution to the show!
TREASURE:
- BOOST IT OR STREAM SATS on the Podcasting 2.0 apps @ https://podcastapps.com
- DONATE via Monero @ https://xmrchat.com/ungovernable
- BUY SOME STICKERS @ https://ungovernable.network/shop/
FOUNDATION
https://foundation.xyz/ungovernable
Foundation builds Bitcoin-centric tools that empower you to reclaim your digital sovereignty.
As a sovereign computing company, Foundation is the antithesis of today’s tech conglomerates. Returning to cypherpunk principles, they build open source technology that “can’t be evil”.
Thank you Foundation Devices for sponsoring the show!
Use code: Ungovernable for $10 off of your purchase
CAKE WALLET
https://cakewallet.com
Cake Wallet is an open-source, non-custodial wallet available on Android, iOS, macOS, and Linux.
Features:
- Built-in Exchange: Swap easily between Bitcoin and Monero.
- User-Friendly: Simple interface for all users.
Monero Users:
- Batch Transactions: Send multiple payments at once.
- Faster Syncing: Optimized syncing via specified restore heights
- Proxy Support: Enhance privacy with proxy node options.
Bitcoin Users:
- Coin Control: Manage your transactions effectively.
- Silent Payments: Static bitcoin addresses
- Batch Transactions: Streamline your payment process.
Thank you Cake Wallet for sponsoring the show!
MYNYMBOX
https://mynymbox.io
Your go-to for anonymous server hosting solutions, featuring: virtual private & dedicated servers, domain registration and DNS parking. We don’t require any of your personal information, and you can purchase using Bitcoin, Lightning, Monero and many other cryptos.
Explore benefits such as No KYC, complete privacy & security, and human support.
(00:00:00) INTRO
(00:00:58) THANK YOU FOUNDATION
(00:01:45) THANK YOU CAKE WALLET
(00:02:48) Not Just Weekly, Live Weekly!
(00:07:44) KeyOS 1.4.0
(00:14:51) NEWS
(00:15:07) The Liquid Exploit
(00:40:02) MORE NEWS
(00:55:05) BOOSTS
(01:04:40) UPDATES & RELEASES
(01:06:50) EDUCATION
(01:09:10) THANK YOU MYNYMBOX
Bitcoin is close to becoming worthless.
Now what's the Bitcoin? Bitcoin's like rat poison. Yeah. Oh. The greatest scam in history. Let's get it. Bitcoin will go to fucking zero.
Welcome
back to the Bitcoin Brief, the show where me and q and a catch up every two weeks to talk about Bitcoin, privacy, open source, keeping your Bitcoin secure, and the news and software updates that matter.
I just wanted to say a massive thank you to everyone who's been supporting Ungovernable Misfits, and a big thank you to Foundation Devices for supporting the show. If you haven't already checked them out, go to foundation.xyzed.
They make cypherpunk tools for fuckwits, and anyone can use this, even me. If you have any questions or you want to reach out, feel free, and I'll be happy to go through things with you. For anything super technical, I'll pass you on to queue. If you wanna buy one of these incredible passports, use the code ungovernable.
It will get you a discount, and it will let them know that I'm shilling. I'd also like to say a huge thank you to the Cake Wallet team. Not only are they supporting this show, but they're also bringing out some incredible features.
For those of you who actually use Bitcoin and actually care about their privacy and security, Cakewallet make it incredibly simple for you to live outside of the traditional financial system.
You can use Cake Pay within the app to buy gift cards for food, petrol, and whatever else you might need day to day. You can use silent payments, and, of course, you can use Monero. You can connect both Bitcoin and Monero nodes, use coin control, and this team are constantly innovating.
And I'm really excited to be working with them. If you have any questions, you can reach out to me, but check them out at cakewallet.com. Download the APK or start using this today on Mac, Windows, Linux, iPhone, or, of course, your Android device.
Enjoy the show.
Hello, and welcome to The Bitcoin Brief, a live and interactive show taking place every Monday at 9AM eastern and 2PM UK time across the ungovernable network. Each week, we go through the news, the releases, and the developments that actually matter in Bitcoin.
This, of course, includes self custody, privacy, the tools that you run you that you run yourself, and the people that are unfortunately trying to make all of that harder. If it affects your ability to hold and spend your own money without asking permission, then we wanna talk about it.
This show and the topics that we cover are powered by freedom.tech, a daily news desk that uses AI to monitor hundreds of sources so that we can continue to bring you the signal every single week.
We'd love to have you help steer the conversation by commenting live, asking questions, boosting the show, or just sharing it with your friends. My name is q and a, and I'm head of customer experience at Foundation. And as always, I'm joined by my friend Max, the head honcho of the Ungovernable Network.
Without further ado, let's dive into the very first live Bitcoin brief. Max, how the devil are you? Wow. What a change from a year and a half ago. We're never gonna do a live show. So almost all our shows are now live. And Here we are. The monthly going to the brief and the brief going to a weekly. And,
yeah, it's exciting, mate. And it seems that it's good timing as well because there is never a dull moment in Bitcoin and Fruit and Tech land at the moment. It is Yes. Fucking Yeah. I keep saying, like, I'll just, you know, sit in the evening and once the kids are quiet for half of a second, I'll say to my missus, like,
oh, there was another hack today, or there was this, or there was you know? And she's like, what the fuck is going on? And I'm like, I good question. Tune in on Monday to find out. Yeah. Indeed. We are ungovernable
or the ungovernable network is now the perfect way to start your weekend with Freedom Tech Friday Yes. And also to start your week with the Bitcoin brief. Like, we've got you covered now. We do.
But, yeah, it's what what a week to pick to go for our first live show was a lot to talk about. For those of you that knew here, we obviously cover the the the the kind of last week or seven days worth of Bitcoin news.
We read out boosts from the ungovernable network, and we also talk about the the releases that actually matter.
Before we do that, Max and I normally have a little bit of an answer just to catch up and see if we've got any AOB. So, Max, did you have a busy weekend? Did you have you had any kitchens fall on your head this weekend? No. Fitted a dishwasher. I hadn't had a dishwasher for a long time, so that was that was really nice.
And that was it, mate, really. Just sort of, like, fixed stuff around the house with the help of children, which is extremely helpful when they wanna help you.
Trying to do plumbing and they're, like, throwing things in the way and all that kind of stuff, which is good. But, yeah, it was nice, mate. What about you? Pretty restful one, thankfully. Did a bit of work on on the website as always. Yeah. Yeah. Grinding.
We we now have all of the cool clips that that you produce in the background and post onto socials,
we now have the option to publish those to the site so that we start to build up a little bit of a clip archive. But rather than just sitting there like, you know, YouTube shorts and just scrolling through sixty second clips of of our shows.
They're actually a lot more useful. You can obviously get a feel for what we're talking about, but then you'll see the transcript from the clip, and you'll also see a link to take you straight to that episode so that you can view that episode, watch it, and also go straight to the timestamp of that clip because
the clip might cut short if it's, you know, we're talking about a specific topic and we just give you a quick sixty second snippet and to to entice you. If you wanna click click that link and then go straight and hear the full conversation, you now can. And they've all got their own unique URL
also on the website. So keep an eye out at ungovernable.network. Did you get a chance to look at these over the weekend, Matt? I haven't had a proper look through it. I saw the spec and what you'd built and yeah. Plan to have a proper look through today. But just as a general nod, the site and functionality is
epic. Like, it's it's so fucking useless. Everything I wish I had eight, nine years ago, whenever it was when I started trying to learn about Bitcoin. It's fucking brilliant. Good. Good. Glad to hear it. Like I say, we're only just getting started. So on Governables, keep your ideas coming forward.
We've already had quite a few of you help shape some features on the the website and love being able to respond to feedback like that, so keep it coming. The only other bit of AOB for me is we've been talking for the past couple of weeks around the KeyOS 1.4 beta.
That is now public release, available as of Friday last week, and it is literally our biggest release in company history and certainly in Passport Prime. The the headline amongst many others is new user interface, new app icons, but most importantly, app sideloading.
So you can now go and install any app you want, whether it whether or not it's built by foundation or whether you built it yourself or whether you've got some cool developer friends who like to build apps for Passport Prime and KeyOS.
The world is literally your oyster now. All you need to do is install the relevant developer certificate. So let's say if Max was the one making the application, he would sign the application and give you know, he publishes developer certificate so that when Passport Prime installs the app,
you can or the the device will verify that the installed app or the app being installed, excuse me, is actually signed by Mac so that you know it's you know, you're not installing something from somebody else.
So yeah, the the the the flood gates are open now. I've been installing every single app possible just to see as the limits and stuff like that. There's lots of proof of concepts on the foundation website. If you just go to app dash showcase,
you'll be able to see all of the ones I've been vibe coding, and there's loads of third party contributors that have already been building even before this side loading became a true reality as of Friday. So super super happy to to see this live, and
I think we're gonna see a bit of a of a kind of app renaissance, and you're really gonna be able to customize KeyOS to suit whatever you want. You know, that that ranges from everything from
a Bitcoin only signer where you've just got one, two, three, or four apps, the basic ones, and you just use it with Sparrow. Cool. Go for it. Or you can have 50 apps for all of your different personal security needs. Like, the world is literally your oyster. Use the device how you want based on your threat models and your
what you need out of the device, basically. So very, very exciting and we'll be providing lots more updates as the the week go by. I'm gonna be short selecting some of the the the cool apps that I see people building, and we'll do little showcases on across the the ungoverable shows as well. Yeah. That's awesome.
Is there gonna be, like, a central point that they can find these apps? Like, you know, like, we had Dojo Bay on Friday where people can, like, go on and have a look and see what they wanna connect to via Nims, etcetera. Like, is there gonna be a similar kind of almost app store or, like, you know, like a
rating system of the people who build the apps or some way that people who aren't as sort of plugged in to the groups as maybe you or I would be know roughly who should trust or not. You do what I mean? Like, yeah, Jordan builds an app or go yeah. You build an app or go yeah. Yeah. And there's others that'd be like, maybe not.
I'll answer that in two two phases. What's ready now and what the end state looks like. So what's ready now? App are sideloading only. So you have to go out and find the app that you wanna install.
There are no additional foundation sign apps yet. So it's a case of if you build your own, sign your own app and install it on your own device, or you know somebody who's building apps and you do the same but with the applications that they're building. It's true sideloading.
It's just like an APK on Android basically where it's up to you what you install, but you've gotta go and find it. Yep. Now, obviously, that's great. It gives users freedom, but it's also we're we're not kind of best serving more newcomers that need that kind of app discovery or that app store experience.
So, yeah, end state, there will be more of a a white listed kind of foundation app store. That will be slower moving for two reasons. Number one, we plan to add our own apps in there as well, which obviously takes developer hours to do that properly.
And number two is that if we move to feature third party applications, which we do plan to do so, we obviously need to to vet those. Because if, you know, if we're given those the kind of whitelist treatment, we wanna be confident that if they're in our app store that we know that they are not doing anything nefarious.
Now with all of that said, KeyOS is built such that if even if you do install a nefarious application, it only has access to the specific things that you give it access to anyway. Right? So you you have very granular permissions
on what every app can do as you install, and you can change them at any time in the future. But if we're gonna put our name to it and say, hey, look, here is a KQuala app that you can download directly from our app store so that you can secure your Monero
offline, then we obviously wanna check that code. Right? So obviously, that's the end state, and that's how we would like things to be because it is much easier, and it would allows us to kind of
curate the user experience and highlight specific applications that we know and we're confident in. But, obviously, that's gonna take a little bit more time. And then the third part of it, I guess, is
there's absolutely nothing stopping somebody spinning up something like an f droid but for Yeah. Possible prime apps where they do their own curation, they have their own kind of signing schemes and stuff. Like it's completely open.
And if somebody wants to to build that or vibe code that, it'd be pretty easy to do so, really. And then people could submit their own to, you know, I don't know, Primedroid or whatever they wanna call it and have like a a third party app store that offers the same sort of or a similar user experience,
but it just hasn't gone through the curation that we would do if we were to put our name to it, our foundation. Yeah. That'd it'd just be cool to see, wouldn't it? Like, a bit of a most downloaded or highest rated or Yeah. Absolutely.
You know, somewhat trusted developers and and all that kind of stuff. So, yeah, it'd be cool to see how that builds out. I also still want what what are Kate doing with this development of this app? Because I really would like one. I'd like, an offline Monero device,
and, I know there's cupcake and all of that, but that should be really useful. Yeah. I mean, I can't share too much details other than they have a developer working on it. I I don't wanna give any time to girls. I mean, obviously, it's it's
not available yet, and it's slower than we would like. But, obviously, the Kate team have their own priorities as well. So Yeah. Yeah. They are working on it. It's all I can kind of share, basically. Okay. Alright. They've got I think they've got eight new workers that just joined K. K.
Gold boxes. Yeah. They never ask for a toilet break is all I know. Yeah. And they work twenty four seven for free. Just feed them with some power and some electricity and away they go. Well, mate, it's let's dive into the news. It's been one hell of a whirlwind week yet again. Oh, yeah.
So the headline news article for the week, and you'll see that scrolling across the bottom. Roughly 4,000 yes, you heard that right. 4,000 Bitcoin was withdrawn from the liquid network after a software bug allowed LBTC that shouldn't exist to be accepted as valid.
The initial reporting valued the withdrawal at somewhere like $320,000,000. And I must stress before I go into the details here, this is still unfolding as we speak. It it hit Twitter last night.
So it's a little under twelve hours old and it's still unfolding. So there may be some
items that come out of this or some truths that come out of this after we record. So bear in mind when we're recording this or when we are live that I'm I'm dealing with what I have in front of me. But anyway, so the attacker exploited the liquid validation software that redeems the resulting liquid Bitcoin
for real Bitcoin that was previously held in the liquid federation reserves. And to be clear, this 4,000 BTC is pretty much everything on liquid. I think there was somehow like a 150 or 200 bitcoin left. So it's like the entire network's worth of bitcoin, essentially.
So how a quick recap on how liquid works because it's not something that we talk about often on the brief. But liquid is a separate network that's kinda connected to Bitcoin. Some people call it a side chain.
Users deposit Bitcoin into its kind of backing arrangement, and they receive liquid Bitcoin or LBTC, which they can then move around on the liquid network that's faster, cheaper, and more private thanks to or can be more private thanks to confidential transactions.
Mhmm. You can kind of think of LBTC as like an IOU or a claim ticket. Each of those IOU's or tickets is supposed to represent 1 bitcoin, the equivalent amount of bitcoin held by a group of organization called the Liquid Federation. And I believe there's 15 people oh, sorry, 15 Companies.
Organizations that that take part in that. So you can hold LBTC in your own liquid wallet using your own keys. And the Bitcoin back in it remains under the federation's control until it doesn't, unfortunately, as we've seen in the last twenty four hours. To withdraw your your LBTC, you kind of go through a a redemption process
where those coins are removed from circulation on the liquid network. And then the the a quorum of the federation, believe again, it's 11 out of the 15, pays that Bitcoin from their reserves back to your actual on chain Bitcoin address.
That process is called a a peg out. So basically, an LBTC liquid Bitcoin holder depends on the federation to keep the equivalent reserve secure whilst they have the the liquid IOU.
And obviously, they rely on the the federation to keep the software secure and act and make sure that all of the accounting is accurate so that, you know, you don't have a run on the bank, so to speak.
So moving forward, the liquid network has a pretty cool privacy feature called confidential transactions, quite analogous to to Monero, which hides transaction amounts. The the network still needs to check that users aren't artificially creating money when they transact. And it does that through,
what do you call them, like mathematical proofs, which let let it verify certain properties of the amounts without seeing the amounts itself. Cali had a a pretty cool explanation on this, which is useful here because it separates two checks.
First off, when you send a liquid transaction, the transaction needs to balance. The amount going in must match the amount going out apart from fees. And the second one is each hidden amount must fall within a permitted range.
And so you might be thinking, well, why the hell does that matter? Well, imagine I put 1 coin into a transaction and I created two outputs. One worth 100 coins and one worth minus 99 coins.
The the math balances, a 100 minus 99 is one. But that would give me a 100 coin output to spend, balance against a negative amount that should never have been allowed. And these range proofs that they have built into the system are supposed to help prevent that. Mhmm. Those numbers are obviously just illustrative
of just why the the checks are necessary, but it does lead me into what went wrong. So a friend of the show, Orange Surf, as as always is on the ball with this sort of stuff. You can see I've got his one of his many tweets on the subject. Thanks, Orange Surf. Yeah.
According to his analysis, the problem was in a a shortcut designed to save processing time. Checking these range proofs that I just spoke about takes work. It's computationally intensive.
Once the software and the this is the element software here, by the way, that that kind of powers the liquid network. Once that's successfully checked one, it remembers the result so it can avoid repeating the same calculation. Makes sense.
That memory is what the system calls a cache, which you'll hear used quite often in anything to do with computing. To look up a result in that cache, the software needs a label identifying what it checked.
The label has to include all of the details that could affect whether or not the proof is valid. So another analogy would be, you know, imagine a ticket inspector checking a ticket and recording its barcode.
The next time that they see that barcode, the inspector waves it through. But that becomes a problem if the inspector's record leaves out which event the ticket belong to. An approval for one event could be reused on another.
And so what Orange Surf said in his analysis basically is that Liquids cache identified and checked the proof using the proof itself and a mathematical representation of the amount. It omitted any other relevant information, including the asset type and the condition to control and how the output could be spent.
So that allowed the software to reuse a successful result in a situation where a fresh check would ordinarily fail. So the cache operates on an output and its proof, and the mistake was in how the software identified whether or not something had already been checked.
So I appreciate that all this is pretty complex, but, like, it's worth double clicking on this because once you understand how it works, you can kind of then look at how the attacker, and we'll come on to who the attackers are later, how they turn that into Bitcoin.
So the the reported mechanism starts with a valid proof that I've just been talking about being checked, and a successful result stored in memory in the cache. A carefully constructed invalid output then matches the incomplete description of that cache.
The software finds the earlier check that it did and is like, yep, that's fine. Go ahead. So that's the reported route by which the invalid liquid Bitcoin passed the validation of the element software and became spendable.
Obviously, we're waiting for a complete and full technical post mortem on all of this, And I'm just going off all the people's research here that are far cleverer than me because we do still need to establish the the full kind of construction and sequence.
Side swap has also given a direct account of the withdrawal, and it said basically that a customer submitted a 4,000 liquid Bitcoin to its peg out service, which is like to basically
saying, here's some liquid, give me some real Bitcoin. Yeah. They're not just some, all. Give me all. Not the entire network. Yeah. And I'm not pegging all users.
Yeah. Side swap says those coins are being created through a bargain elements and the soft that which is, as I said, the software that kind of powers liquid. Its service accepted them as ordinary liquid Bitcoin.
They were removed from circulation through the withdrawal process, and the federation paid approximately 3,996 Bitcoin to the customer's well, I say customer, the attacker's Bitcoin address.
So basically, we flick back to that ticket analogy, bogus tickets have been accepted in exchange for real money from the till. Oh, boy. What else have we got here? Because I've got some lengthy notes on this.
So some people might think, well, why didn't multiple signing keys prevent this? Because as I mentioned, we have 11 of 15 signatories in the in the federation. Well, as as I said earlier, liquid reserves, they're protected by these these multiple keys.
Cytop says it's authorizes authorization key wasn't compromised. The withdrawal had valid authorization because it went through the normal service. The failure happened earlier when the network accepted the liquid Bitcoin that should never have existed.
The signers across the federation relied on the software's view of the liquid chain. And once that software treated the coins, the liquid coins as valid, the withdrawal could proceed. Several organizations running the same faulty validation code can reach the same incorrect conclusion.
The number of signing keys doesn't resolve that because it's a shared software failure essentially. So the attacker therefore didn't even need to steal any of the federation keys to get the Bitcoin paid out, which I think is is one of the headlines here. It's like, on the surface of it, an 11 of 15
multi sig to to peg out some Bitcoin sounds super secure. Like, how are you gonna compromise 11 geographically distributed companies? Right? It's but they didn't even need to. Yeah. Moving on, Orange Surf again, he's pointed to a fix that had a commit dates in August and sorry. August 3
and a pull request with that kind of fix open on September 1.
So basically, what was what I think he's saying here is that they knew about the problem, but they didn't fix it fast enough. And somebody else found the problem and exploited it immediately.
But the problem is the the fix that's where this public pull request is open is public. So somebody has clearly seen the fix that hasn't been merged into the software and distributed and thought, uh-huh. That's that bug that they are looking to fix is still live on the network. I'm gonna go and exploit it.
Again, all of this is a moving target here. So there's still a lot to to uncover. But what else have we got? I I think that's it, basically. It's just a complete a complete mess.
There has been no blocks. You know, they they obviously because it's a centralized service, they stopped all the blocks. There haven't been any blocks for, like, twenty four hours now. If you wanna transact on liquid, you can't.
So hopefully, you didn't have much funds or any funds on liquid. I'll have been here, I reckon. I I had some on liquid. Oh, really? Yeah. Have you be interesting to see, like, what what experience you have when you load the wallet.
Yeah. Well, I I I'm pretty sure I had a little bit because I had to swap I had to swap into liquid to use a service a while back. And then I couldn't I couldn't use liquid on that service anymore, and then I couldn't swap out from liquid to lightning on the wallet that I was using because bolts went down.
And I was I I'm pretty sure I was just like, well, what the fuck do I do with this now? And just sort of was like, ugh. I can't swap it. Can't use it. I can't do a swap.
Fuck it. I'll just I'll come back to this later. So that probably is gone. It wasn't it wasn't a lot. Like, I'm not gonna cry about it. It's probably like a a mail out or something. But, like Yeah. Yeah. I mean, at least at least Just mitigation as always.
Yeah. But fuck. I mean, like, I don't know who, but I assume some people would have kept a lot on there. And Yep. It will have affected. So I'm not sort of joking around and fucking around about something like this because it's another one where I don't think anyone that we really spend time with probably is keeping all their
total amount of coins or vast amounts of coins on liquid. They might use it for a swap here or for something or part of a machine of privacy on Bitcoin, but it's fucking I mean, 4,000 Bitcoin is so much Bitcoin. And it's like Oh, yeah. It's just this weird sense.
And we keep talking about it every week, but it's like, now that people have these clankers and they're becoming so fucking good at this kind of stuff, and they work twenty four hours a day, like we said, and they don't have toilet breaks, you cannot you cannot have a company that has 4,000 Bitcoin plus of users'
Bitcoin and then find an issue with it and go, yeah. We'll do that later, mate. Like, you can't I mean, like, The the only thing I can think is maybe whoever's found the bug internally has not understood fully the
the potential ramifications and then that it could allow for a complete and utter drain of the entire network, essentially. That's I imagine can think of. Yeah. No. I'm what I'm saying is I imagine not because that would be mental, but I wouldn't put anything past anyone at this stage. But, like, I imagine not. But still, if
you're a company of that size, you know, you would think that you have a decent amount of compute that you can throw at securing everything that you have all the time. And if you have any bug, it should automatically in this weird day and age that we're in now that we weren't in six months ago, if you're holding funds
and you're doing anything on Bitcoin or any other chain, you I don't think you can afford at this point not to have your own team of AI bots just working around the clock. And Yeah. People then controlling those bots around the clock and that they are constantly reviewing
all code and everything all the time and cross checking each other and, like, it's war. It's fucking like, it's so above my, like, understanding the actual code side and how people are actually doing this. But all I know is if you leave anything, someone else has the compute, and they have a massive incentive
to throw their compute at all these Bitcoin businesses. They're they're gonna be the targets before anything else because,
you know, what else are you gonna do? It's like, oh, you don't need to worry about Bitcoin. You need to worry about nuclear launch codes. No. I don't because most people don't wanna fucking fire nukes. What they want is 4,000 Bitcoin.
That's what they want. So people are gonna attack that first, and we're seeing it. Yep. Absolutely. Cosign that. And I think the the only other thing, like, I agree with everything you just said, but, like, it's especially true if somebody is well funded as Blockstream, arguably the most well funded company in Bitcoin. Right?
A couple of the details that I missed out that are very interesting as part of this. Samsung now has a good timeline, which I've got up on screen now. Basically, the attacker when they did the withdrawal or the peg out for the almost 4,000 Bitcoin,
they put an op return in the transaction. Basically, supposed a message to say, we are white hats. Contact us on chain, which is interesting. And then Blockstream responded about an hour later with another transaction in another op return. I love that they're like speaking to each other through the chain.
Basically said, please contact security@blockstream.com. What security? And yeah. Another six hours later, Blockstream then sent an encrypted message via OpReturn to the hacker's PGP key. And obviously, it was encrypted, so we don't know what they said.
And then an hour late after that, the hatters the hatters the hackers The hatters. Said sending most back to and then a Bitcoin address. Is that okay?
Then Oh. No response from Blockstream I don't. That. And then an hour later, the hackers again said, bug first. The chain is under risk at latest commit right now. Make sure every node is patched, then we will transfer the money back safely after confirming the fix.
And then three minutes later, Blockstream said, yes, thank you. Although I think that final message from Blockstream is to the earlier message saying, you know, is it okay if I send them back to this address?
Not to fix your shit, essentially. And then the status as of right now, the the 4,000 Bitcoin still hasn't moved. So I presume they're basically waiting for Blockstream to merge in for all the the federation nodes to to be fixed.
And I'm I'm gonna call this one and say, I find it highly unlikely that that Bitcoin gets returned. Really? Yeah. Well, I I think it's someone's Why would the why would the attacker even enter negotiations?
For a laugh. Really? Like, you should you should come away with, like, £300,000,000 or dollars, and and you think that that they're not running for the hills. Don't under don't underestimate the value of a good laugh. And I think that you'll you'll see it. And, you know, like, is it Zach XBT who
Yeah. Does all of this incredible work to find these scammers who will call up innocent people and get them to part with their Bitcoin. And these these kids are making we've talked about it on the show before, but millions, tens of millions, hundreds of millions, they're they're fucking retarded.
They they'll they'll go and get, like, 10,000,000, a $100,000,000 worth of Bitcoin. And rather than shutting the fuck up and going and living a really blessed life, they flex about it. They'll call the people that they've scammed and rub it in their face.
They'll they'll go on to other chat rooms and laugh about what they're doing and give little clues and, like, oh, here's a picture of my arm. We just got very fucking specific tattoo, and they're idiots.
So you can be good at stealing money and be a fucking idiot. And my guess is that these people are really good at stealing money. They just stole 4,000 Bitcoin, but they're also fucking idiots. And for the sake of a laugh, they're doing all this. I can't believe that's that's so much money.
How how tempting when no one currently knows who you are and you've got all that money, you can you can live you can live however you want for the rest of your life and so can your family and everyone you love and everyone you care about
for the rest of your life and then your children and their children and their children can all live a really fucking great life as well. Why would you go, do know what? I'll give it back to Blockstream because they're a bit skinned.
So we've gotta make sure that we don't fuck Blockstream over. And, yeah, let me give it back and just go back to my fucking office. I don't see it, mate. I don't think it's gonna happen.
I'm gonna take the opposite side of that bet. Okay. And I genuinely think they're gonna come back. Because I again, well, if assuming that they do give the money back to Blockstream. Blockstream
well, let's be clear. It's not all Blockstream funds, is it? It's people that deposit into into the liquid liquid network. But Blockstream are well funded. I mean and if it was me, I'd be like, okay. Do I wanna spend the rest of my life looking over my shoulder?
Or do I take a little gamble to be like, hey, you can have all this back. You send me 10 and I'll, you know, as a thank you for for being, know, responsible. 10 bitcoin's gonna change your life. Yeah. And then you don't have to look over your shoulder.
Ultimately, we don't know. I'm sure there'll be a lot more details out as of by the time we record next week. The only other thing I wanna say on this, look on screen now. I'm just looking at the hacker's address and everybody well, I say everybody. There's a lot of people dusting the address and posting messages into opt return.
It says hacker is not a white hat. This is an inside job. The next one says Francis Puglio knew about this vulnerability. The next one says, this is an inside job to cover up Blockstream.
Another one says, white hats, 50 k for fireworks, they say out they say out white hats in front of Capitol Hill tonight and protest. There's just loads of messages being sent through without return. It's quite funny.
I think you're on mute, Max. But, well, it'd be interesting to see who wins this bet. I'm not gonna put any actual money on it because I keep losing I keep I keep having little mini hacks of my own, which I won't go into too much. But but the this this Blockstream one was one of them and keep I just keep getting fucked at the moment. So
damn, but let's see who wins. I hope it gets returned because I'm sure that there are good people who have got money on there and will will desperately need it back. And I think the whole Bitcoin scene has had enough pain in the last few weeks Oh, yeah. As it stands. And and the final thing I was gonna say is as you were
laying out your case, my probability of me being right did go lower slightly because it reminded me of was it Mahood or something like that? There was a there was a a young guy who on Lightning maybe four or five years ago,
did he did he ex what did he do? Did he I think he, like, attacks the network and shut shut a lot of the network down. And
do do you remember what I'm talking about? I have no idea what you're talking about. It was, like, four or five years ago, maybe, quite a young guy, Mahood or oh, fuck. What was his name? Can't remember. Anyway, he he he found a way to, like, attack lightning.
And I don't think he stole funds, but I think he, like, shut it down and Oh, Burak. That oh, maybe it's that. Yeah. Was it b u r a k or something? Yeah. Burak. Yeah. Burak. Burak. Yeah. It was him. Yeah. It just reminded me of that because I remember people getting all up in arms about him doing what he did.
But then it got people talking, and it it sort of, like, delivered a message differently to just like, oh, by the way, fix your shit. So it could be that there's value
for this hacker in a, like you said, not looking over your shoulder because you don't know what's gonna happen to you if you fucking steal 4,000 Bitcoin. Like, someone could really be quite upset with you.
And and, also, maybe you want a bit of exposure and be like, hey. Like, look at me. Give me some stats and look at me. So I I would say my confidence in my initial assessment is lower after you said it, but I still think I'm right.
Well, on Governables, let us know in these comments what you think. What would you do? Alright. We need to rattle through now to keep the time. Yes. Next, on the list, we have a report from from TFTC.
There's $7,000,000 reportedly missing from a Chilean exchange, OrionX, after they halted withdrawals due to a the outputs of a forensic audit found roughly roughly $7,000,000 in customer cryptocurrency had been moved to external wallets between 2018 and 2021.
The criminal complaint accuses founding partners of cuss of using customer funds for unauthorized speculative trading, a tale as old as time. The report puts a number of affected users at around 100,000, says Chili's financial regulator, and confirmed that the exchange operated without a license.
The accusations still need to obviously go through all of the legal process. Customers are already dealing with the effect of the, you know, the immediate consequence. They obviously cannot withdraw their money. Mhmm. And whether were not they're gonna get anything back is still completely uncertain.
Obviously, this is another reminder, your weekly reminder to get your funds off in exchange and take them into self custody. Get your funds it gets a little bit more complicated now than it used to be. Get your funds off exchange.
Get them on chain. Don't probably use Lightning because you might get hacked. I would not use liquid. It's probably not safe. So don't use a side chain. Don't use a second layer. Bring them into self custody, but make sure that your entry is good and think very, very carefully about who you trust as your hardware provider.
Consider multisig, but if you are using multi it's just like it's not a very simple thing to say anymore, I'm afraid. My my thing I'm gonna say, I think, going forward is have self custody.
Don't have all your eggs in one basket. Tune in every week. Ask the questions, and and just don't trust any cunt. Yes. Or seek the advice of a reputable professional if you're not confident doing it yourself. Yeah. And Never under any circumstances share your seed words with anybody. That's a good one. Yeah. Never do that. And don't
go so balls deep in on Bitcoin or crypto that it could ruin your life. Because, yes, you might be thinking to the upside, it could change my life, but we are seeing that it can really fucking change your life the other way. So just have some food in the freezer, like, own some shit, like, be able to, like, look after your family, please.
Cosign that. Alright. Circling back on something we started to talk about last week or the week before. CoinDesk is reporting that better bitcoin backed mortgage product with Coinbase. Oh, yeah.
It allows better the company better to reuse bitcoin borrowers pledge as collateral. Oh. Shock horror. Rehypothecation. Who could have seen this coming? Not me. Collateral is an asset a lender can claim if you fail to be repaid a loan, and takes that a step further. The lender can use your pledge asset
in additional finance agreements, I. More risk. Yeah. Yeah. Yeah. This which obviously creates another layer and if I could potentially affect your ability to recover the Bitcoin. But, you know, in the event that something goes wrong and you, you know, you don't keep up your mortgage payments or whatever,
basically, they're lending your Bitcoin out for other purposes that may or may not be a worthwhile investment, essentially. Yeah. Yeah. Be careful. As we as we said first time around, like, tread very, very carefully with this shit like this.
Okay. Quick update on the Clarity Act for US enjoyers, although I don't think there'll be many on today because it's Labor Day. They're probably all still in bed. The US House has canceled its final two weeks of September voting sessions leaving a narrow window before the midterm recess.
Meanwhile, the Clarity Act procedural vote is scheduled for September 15, a week tomorrow. This is about on whether the legislation can move forward with 60 votes needed to overcome the procedural hurdle.
It doesn't by itself make the bill law. Quick reminder that the legislation aims to clarify how digital assets and Bitcoin are regulated, including the division of responsibility between the SEC, the CFTC, and all the three letter or seven letter agencies over there as well.
The the downstream of this, because, ordinarily, this isn't something that we would traditionally cover, but, like, this could have big ramifications as to how the whole industry is regulated and how,
you know, that can have downstream effects on the tools that we use day to day, basically. So it is something I'm keeping a quiet eye on, but as we say each and every week, it's been pushed back yet again.
Alright. Next on the list, another quick recap. Unfortunately, this time on the the Trezor leak. Bitcoin Magazine have reported that Trezor shipping partner, ShipMonk, they were saying customer records that shouldn't have been that should have been deleted, allegedly exposing an additional 67,000 US customers.
So combined with the earlier disclosure of roughly, I think it was like 13 or 14,000, that brings the total to around 80,000 people. The exposed information includes a mix of names, postal addresses, phone numbers, and email addresses.
Not great. I wish we had more positive stuff to talk about. Trezor has come out saying, you know, its devices remain secure. This is more of a of a leak in the third party customer sorry, shipping service having not handled their shit correctly.
So again, like we said last when we first talked about this, it's difficult. I feel for treasure a little bit because, like, if you ship physical products, you have to have a relationship with somebody who handles shipping information.
And as soon as you give that information away, it's outside of your control, and you can have the most secure procedure possible. But if they they don't, then your customers is leaking anyway. So Well, like you like you said as well, you can't really have your own in house logistics.
It's just it's not something that you can do. So you kind of have to be in the hands of other people. I I think there needs to be a push, though. We've always said it, but I think there needs to be a push. It's like, just do not get this stuff sent to your personal address.
Just don't do it. Like, just don't send it to a company, a PO box, a a friend who's in a military base, like we said before, just somewhere where someone can't come and knock on your door because having your funds swept because of some Canadian cunt is one thing.
But having it having having people turn up at your door where your family sleep, that is a totally different kettle of fish. It's it's real. It's fucking scary. We see it in France and all over the world, and, you know, this is this is why this is so scary.
Phone numbers, okay. You can change it. It's it's a pain in the ass. You can change it. Email, okay. You can change it. Moving house, that's a little bit harder. And Yeah. This is a real fucking problem. And so, yeah, I I'm not here to slag Tresor off, but I think any listener who's thinking about
ordering any hardware. And if you do, obviously, it should be foundation. Obviously, you should use code uncoverable. But if you do, do not get it sent to your house, please. Yeah. And on that, a lot of these manufacturers, foundation included, now have the option to either send to a PO box
or to send to things like UPS access points as well. We added that in the last week or so for for US residents, and we're working on adding that globally as soon as possible. So always look for that sort of option first.
Add one thing. When you do go to these boxes what what do you call them? Not community boxes. Access points. That's what UPS calls them anyway. UPS. Do you have to sign for it? Is one of those, like, at, like, a corner shop or whatever?
I do you know what? I don't know because I was a US only. I've not had a chance to to try it, but I believe you just have I think it might be a QR code that you get on your phone. And it's like in the lockable boxes or something like that, probably. Yeah. Well, I I don't even know if it's that. I think
the short the top and bottom of it, I'm pretty sure you can use somebody else's, you know, not your real name. Okay. Fine. So don't use your real name. And when you do go there, be COVID safe. Make sure you're masked up. You don't wanna be spreading those germy germs when you go and collect because CCTV
is everywhere and these flock cameras and all the other bullshit. So top tips. Yes, sir. Right. Next on the list, another breach, unfortunately. Pocket Bitcoin has said that it a breach of its support system exposed the compliance record for 291 customers connecting identity information and documents to Bitcoin addresses.
A separate group of 5,120 customers had bank transfer details exposed including names, iBan, and payment amounts. No private keys were compromised crucially. Obviously, the the address linkage is especially significant because of Bitcoin transaction history being completely public.
An address obviously on its own doesn't necessarily identify a person, but this one literally does. Leak customer record can supply that missing connection. Yeah. Not great. I don't actually know where pocket Bitcoin I think they're just solely in the EU.
But, yeah, my my heart goes out to for those 291 customers. Yes. And again, hark back to interact with Bitcoin with as little information as you possibly can. That includes buying Bitcoin or buying Bitcoin related hardware as well.
Isn't it crazy to find a point on all this kind of kind of negative stuff, but isn't it crazy that the safest way to possibly use Bitcoin is the way that causes you the most trouble and buying peer to peer
and holding your own funds and jumping through hoops not to link it to your identity or other addresses and managing UTXOs and blah blah blah blah blah. And all the stuff that we do and try to do is the safest thing for you and your family, yet you can't then use that Bitcoin in normie world because you can't prove its provenance.
And because you can't prove its provenance, you can't use it. So by using it safely, you outcast yourself from the rest of the financial system. And that is Mhmm. That is the cost of KYC. That is the cost of all of these stupid cunts making these stupid decisions for your safety.
They are putting people at risk. These these bits of information are leaked because they have to be collected, and it's it's fucking disgusting. It's literally killing people. Like, that's not a overstretch or me being bombastic. That is these regulations
and these people who don't even know how Bitcoin works or anything about it who are making these decisions for your safety are literally putting your life at risk. Yep. Certainly is. Cosign that. No KYC only if you can. If you can.
If you can indeed. Alright. Back to the cold card attack. TFTC reporting that the attacker associated with the wave three exploit has moved roughly 20.5 Bitcoin into Ethereum through 34 Wallchain transactions on September the second and third. What the fuck are they doing?
That's a little over 1% of the reported 1,789 Bitcoin that was stolen in total. Most of the funds remain untouched after the reporting cut off. For those of you that don't know, Thorchain kinda lets users exchange assets across different blockchains.
You know, in practical terms, somebody can send Bitcoin into the swap and receive an asset on the other side like Ethereum or whatever. For the investigators, obviously, that adds another kind of system to follow and can make tracing a little bit more complicated, although it's not foolproof.
It does obviously, it doesn't, you know, automatically erase the connection or the amounts. You know, you can have timing analysis, amount analysis, and stuff like that. And swap protocols, you know, may also keep records as well. But I just thought that was an interesting little tip that some of it's gone over to Ethereum.
Odd. Odd move. Yep. Indeed. Right. Last Yep. This last one? Yeah. Last one on the news. Tether getting sued over a $42,400,000 freeze. Two Thai businessmen are suing Tether over free the freezing of $42,400,000 in USDT across 10 Ethereum addresses.
According to CoinDesk reporting on this lawsuit, the plaintiffs alleged that Tether acted on a informal request from Homeland Security investigations more than three months before a seizure warrant was issued.
They also say that the acquired they acquired the tokens through legitimate secondary market transactions, and their allegations include the timing and the legal basis of the freeze remaining, you know, obviously, this remains for the court to to imagine sorry, to examine, should I say.
The technical point here that I wanted to to kind of double click on is that Tether basically just blacklisted an address and froze the account on a verbal from the homeland from homeland security. So just another highlight that it's a centralized tool and your balance can be taken away from you instantaneously through
a phone call, essentially. So once again, I I mentioned the term risk mitigation. If you do wanna use stable coins, all of the ones that I know about are centralized and can be switched off quite literally at will, as we've just seen here. $42,400,000.
Yeah. Well Okay. That brings us to the end of the news. We should probably do some boosts now, my Now, two things. Number one, we've got loads of boosts. So thank you all so much Thank you. The thing.
I think now that we're live and that we're getting so many boosts, which is a very, very good problem to have, we appreciate each and every one of you even if you just send one stat like the the message is very important to us. But we're at the point now where sitting and reading them all is probably gonna bore everybody to tears.
So my suggestion to you, Mac, is that after this week, we'll read them all this week because we haven't notified everybody. Yep. And as of next week, we'll pick, like, the top five or six Mhmm. To be read for each week.
I think so. I think so. Because, you know, we're trying to keep these to an hour. We're already at fifty five minutes. We are getting more boost, and we're very grateful for that. We do now have a place that they will be there for eternity on the website.
So everyone can still read through. We can still see them. It's just with the amount of boost, I think it'll end up being a a fifteen minute section that we then miss out on the other bits. But, yeah, thank you to everyone, and we'll we're gonna read them all today anyway.
Yep. There's the the wall of fame. I say wall of fame. This is in chronological order. But, yeah, before we get into into the the boost from the last show, I do have two apologies to make because I missed some on previous shows prior to that. So I'm gonna start with those.
First one's from anonymous. You said $25.92
25 $26, let me round it up, worth of XMR. And they boosted the Bitcumbreaf 80 7. And they said, wild and fast developing times that we're living in and it will accelerate. Yep. We've seen that already. Oh, yeah. So I think you're feeling right about a weekly show is needed. Well Yeah. Here we are. Thank very much.
No preference about a live show or not, because I normally work at the time and can't tune it anyways. That's no problem. As you say, we record it and you can catch up afterwards. But thank you for your support. And the other one comes from a friend of the show, xPatriotic, who said $64,
thank you, sir, in exabyte. And he said, please make the Bitcoin Brief weekly. The best show in Bitcoin's based by a league, especially the robot. Max is a see you next Tuesday though. By the way, what shells weigh hundreds of kilos? Holy shit, mate. Unreal. What shells? I promise you because they were like solid hardwood,
and then backing was all like swollen and everything. It was and it was all one run, like, all screwed in together. So listen, mate. You wouldn't have survived it. Let me just tell you that.
Alright. Onto the top boosters for for the last show. Top of the shop, Ape Myth Van Dea sent $50 in XMR. By the way, Bitcoin boosters, what you do in the the Monero boys are out shining you on a Bitcoin show. Are you gonna let that happen? That has that has always been the case.
Like, not even not even close. They are big, big boosters. Well, we appreciate you nonetheless. Yeah. Eight Myth Rondea, $50 in XMR. Weekly is the way. How much XMR do I have to boost to get you guys to read XMR boost on every show?
I promise I'll use the show tags to make it easy for your clankers. Well, Ape, mission accomplished. You're top of the shop, and we truly appreciate that. That's a lot of a lot of dough, so thank you, mate. We do. Yeah. Thank you very much, Ape. I think Ape, just this year, has paid for our hosting and
the bits and pieces that we need to record, etcetera. So, yeah, thank you, mate. We really, really appreciate it. Jordan up. Go on. Should we do what? One and one and one and one? Yep. Yep. Alright. So Jordan sent 6,172 sats, and he said, I don't really like the dollar amount, if I'm honest with you. I like I like sats and picos.
I can well, we've got all of the above, you can just read the sats amounts. Okay. Alright. And Jordan said it's $4.32 AM, and Q has me doing node testing, the things I do for him. Teamwork makes the dream work. Thank you, mate. Appreciate your help as always. Late stage hovel, 6,006 sats. Please go back to the ad reads that say x y z.
I love those. Also, yes, your listeners do need a weekly discussion between my two favorite English gentlemen. However, seven chainsaws is entirely too many chainsaws. Also, I boosted on the website last week asking for custom boost amount in sets.
Unless I just missed it last week, then I see it now. Good work queue updating that as well. Can you also make the message box more than one single line? See, I love this. This is like a proper feedback loop. Yeah, absolutely. I think I might have already done that. Probably.
If I haven't, I will. I'm pretty sure it, if I if I just keep typing it out, I'm pretty sure it wraps. No. It doesn't. Okay. Yeah. I'll fix that. Thank you for your support and your your feedback. Look at this. This is so good.
Your BTC story sent 5,000 stats. Was nicely surprised to hear my seat sign my BTC story. That's Gigi. Yeah. I was gonna say. Yep. Was nicely surprised to hear my seat sign and miniscript fork mentioned on the last episode of Uncoverable.
Thanks, q, for the shout out. I appreciate it, mate. I've been tweaked I've been tweaking my clanker away to get that sounded okay, mate. Listen. What you do in private is is between you and your clanker. I've been tweaking my clanker away to get the PR one step closer to the finish line.
You can just build things. No permission to ask. What a time to be alive. He's got his hands up at the end, like, they're up. Nice. Chad Farrow, 3333
sats. Thanks for shouting out my podcast, gents. It's simply called Chad and Reed's podcast. Oh, nice. I teamed up with Reid from local Bitcoiners podcast to see what kind of cool shit we can build. Well, keep up the good work, mate. I know you do a lot for podcasting.
Oh, he's he's the the god of podcasting. I still haven't tuned in. I keep thinking about it, and I'm like, oh, next time I'm driving or next time I'm doing something, I'm gonna have a listen. So I will do it. I will have a listen and and give some thoughts on it. But, yeah, excited that he's got one. That's very cool.
Anonymous.
See, this is the dyslexia you're getting me. Where's the sats? 2,553 sats. Thank you, mate. That's too fucking funny that you guys were recording during my last boost. I really appreciate that the ungovernable crew puts in or what the ungovernable crew puts in, and the new website
has been a huge level up. Keep up the great work, gentlemen. This must be nasty gang, and just forgot to put their name in. Because you remember, when I showed you, and popped up. Beautiful timing. Yeah. That was amazing. Alright. Thank you, mate. Right.
I'm just gonna quickly rattle through all of the rest of them because there's so many. Yeah. Read BTC 2,143 sats. Listen to Ungovernable if you're not already. It'll be one of the most valuable additions to your podcast feed. Absolutely agree. You've got great great taste. Welder Ian, 2,222 sats. Anonymous, 2,100 sats. Banana man, 1,289
sats. And they said, weekly show would be great. In my opinion, don't do it live. Well, about that. FreeTech Friday is great, but a more polished show is nice too. Okay. INPC 1,111 sats. Yabba dabba doo, etcetera.
Appreciate the lack of macro phony cheese. You are welcome. Link in part rules. Who's that guy? One thousand and twenty two sats. I wish the descriptions on fountain didn't look so weird when they are compressed. Yeah, me too.
User 254981041000 Sats. They said, yes. Luke Jim Jones is something you guys said two episodes ago from a boost and you guys didn't know who or in what reference it was to stay ungovernable. My guess is that's not the gang as well. Yeah.
Ravians Ravians Ravians Ravians I was getting that one wrong. Stokes. Ravians Stokes 500. Let's fucking go. Arrow, stay ungovernable. Forgot my name on the last boost. Lol, well, you've just been read out as anonymous. Thank you for your support.
Code 27500Sats. Rev Huddle, 431
They said very cool that HRF is recognizing NOSTA as a worthwhile avenue for freedom. NOSTA is the killer Bitcoin app. NOSTA keys are Bitcoin keys after all hashtag forty hours per week. On that, can any Primal users that are also ungovernables tell me if Primal has been hot garbage for you in the last week or so.
It just doesn't load anything for me these days. What has changed? That's never I've never had any I've never had anything but a subpar experience on any fucking nostril thing.
Local Bitcoiners, 420 sats. Local Bitcoiners, listen to the breeze to keep up with all the updates as velocity continues to increase. Yeah. You can say that again. Shadrack, 323 sats. I may be boosted on XMR pod, but doing it again here for the social capital.
Hashtag forty hours per week. Anonymous 210 sats. Testing as the text didn't add to the last boost. This oh, that was from from Cruz. Thank you, sir. So last four months, 121. Loving the weekly show, gentlemen. Cheers to you both and the ungovernable crew. Always ungovernable, stay free.
Noster Gang, 101 sats. Jim Jones is literally where the term drinking the Kool Aid is derived from. It was laced with cyanide and almost a thousand people died. Oh. Thank you. See, I love talking to the young governors through the booths. This is amazing. We learn so much.
We do. And then the last one, user 19 12931825100Sats, and they just gave us a thumbs up and a salute. Thank you. Thank you all very, very much. It's so good to see all the love. But again, as of next week, we're just gonna have to read out the top five or six, because otherwise, these shows will be never ending. Keep them coming.
We love all the feedback. Truly appreciate all of it.
Okay. Right. We're nearly done. We are gonna talk about some releases. KeyOS version 1.4, I've already talked about at the top of the show. Oh, by the way, when this comes out on the the podcast feed, the
release notes or well, the show notes are incredibly long. There's some loads of useful shit in there. Why don't you put your show notes up? You don't put any show notes up. Yeah. Somebody called me out on Nosta for that, and then I sent them the screen recording saying,
have you seen all of this? Like, did did you wanna try and click around?
Anyway, as I was saying, the show notes are very, very in-depth. There's loads of releases in there. And again, if we talked about all of them, we'll be here until Friday. So I just pick out the highlights, but like this isn't everything that's in the list. Mhmm. So KeyOS 1.4, I've talked about that at the top of the show.
Next one, Cakewallet six point four point four, I've added native Trezor hardware wallet support for Bitcoin call storage and offline signing. Very cool. Nunchuck Android two point eight point five has added BitBox o two connectivity over Bluetooth and over USB.
They've also added support for the Crooked hardware wallet. And they've also introduced emergency push notifications with home screen alerts. And finally RoboSATs Alpha version 0.87. This is a major release adding three new coordinators, Elluteria, Freeport and Amanana.
I butchered that last one but it's close enough. A federation consensus mechanism, enter an encrypted image uploads in the in the order chat via Noster Blossom servers. Coordinators are now ranked live by dev fund donation value and multiple security fixes including PGP verification.
And then just to wrap us up, we have some educational pieces that you may find useful if you wanna sit down and take a read. We've got orange surf technical notes which I referenced at the start about the liquid vulnerability or attack that is ongoing.
And there's also some deep dive research by somebody called Yuval Kogman who works at Spiral, doing a deep dive on certain CoinJoin's structural privacy failures. I haven't checked that one out yet, but it sounds very much on my street.
And the last one is Bitcoin OpTech episode or issue number 421 covering silent payments and mining pool Coinbase payouts. Max, we're at the end of the very first live Bitcoin brief. How do you think that went? I I think it went very well, mate. I'm very happy we've gone live. It means I don't have to sit and edit at the end of this. Very,
very happy to see all the changes on the website. Very happy to see us constantly in the charts and all the new listeners. So, yeah, I'm a happy boy, mate.
Yeah. I checked fountain a few times this week and we we had multiple shows in the the top trending bit. And and that's all down to you guys listening for for showing you support. So again, I know we say it all the time, but we genuinely really appreciate it. It it really helps us get discovered.
And the the kind of growing listener base is is proof of that. So thank you all for your help. Very good. Well, we'll catch you well, we'll catch you on Friday and then next week, and keep it ungovernable.
We will indeed. Yeah. See you all Friday for Freedom Tech Friday, folks. And if not, we'll catch you next Monday for more Bitcoin signal. Before you go, mininbox.help keep your online presence hidden.
They provide anonymous server hosting solutions, virtual, private, and dedicated servers, domain registration, and DNS parking. They don't require any of your personal information, and you can purchase using Bitcoin, Lightning, or Monero.
No personal information required. None. Zero. Minenbox.io. Stay ungovernable.
Machine transcript; expect the odd mishearing. Click a passage to play from there.




