
Did Bitcoin Just Go Dark?
Discussed in this episode
Boost this Episode
Send sats directly to the creators. Value for Value.
Plus 1% to Podcast Index, 1% to Boost Bot.
Show Notes
A weekly news show informing you on the latest in Bitcoin, privacy and open source tech, hosted by Ungovernables, Max and Q.
AOB
- Max: flooded the downstairs after leaving a sink running over the weekend, spent Saturday ripping out old timber and clutter he'd been meaning to clear out anyway, then a full kids' day that left them sick afterwards
- Q: spent the weekend building his own local, voice-controlled AI assistant after watching the new Spider-Man film
- Q: read this week's letter #7 from Keone, "Notes from the Inside", posted on The Rage -- a tough one on conditions moving between facilities; audio version out later this week, timed with Rick's Free Samurai prize draw
- Q: enjoyed last week's Freedom Tech Friday listener questions episode, ranging from Bitcoin to Monero to privacy, multisig and local AI
NEWS
- Research lab [alloc] init, founded by Misha Komarov with Clara Shikhelman as Head of Protocol Research, published Shielded Bitcoin, a proposal for Zcash-style private transfers needing no soft fork; shielded transactions are encrypted data blobs carried in OP_RETURN or witness data that Bitcoin only orders and timestamps, while separate indexer software checks zero-knowledge proofs and stops double-spends; value sits in encrypted "notes" spent by publishing a one-time nullifier that proves the spend without revealing which note it is; the peg moving real BTC in and out isn't designed yet and rests on an unproven witness-encryption scheme called PIPEs v2; CoinDesk reports fees around 4x normal, a trusted setup and no launch date -- Bitcoin Magazine, CoinDesk, allocinit
- Blockstream published its own post-mortem of the 6 September Liquid exploit: a rangeproof-cache flaw dating to April 2018 ("Bug A"), responsibly disclosed 2 August and patched by 11 August, introduced a second flaw ("Bug B") where unprefixed cache keys let two different proofs collide; the attacker used it to mint about 4,000 unbacked LBTC and peg out 3,996 BTC through SideSwap, draining the reserve from about 4,205 BTC to 197 BTC; 3,400 BTC was returned and the network resumed 9-10 September, but about 602 BTC remains with the attacker and peg-outs stay paused with no date; the 11-of-15 federation multisig worked exactly as designed, the failure was in the software deciding what counted as a valid transaction -- Blockstream
- Bitget detected unauthorised transfers from its hot and warm wallets at 18:31 UTC on 24 September and froze withdrawals platform-wide; CEO Gracy Chen says the attacker compromised a backend system, spoofed transaction data and triggered Bitget's own approval process, with private key compromise ruled out; the loss was revised from $351.6M to about $387.5M once Zcash and TRON assets were counted, mostly ETH, TRX and USDT with no bitcoin taken; Circle and Tether froze about $318K, while roughly $83M in native XRP moved beyond Ripple's power to freeze; North Korea attribution comes from Bitget, Elliptic and MetaMask's Taylor Monahan, not yet from any government; Bitget says its User Protection Fund covers the loss and is reopening withdrawals in phases from 28 September -- CoinDesk, TFTC, Bitcoin Magazine, CoinDesk (freezes), CoinDesk (XRP), Bitget
- AMLBot traced part of the Bitget haul from TRX to USDT, bridged to Ethereum, swapped to about 145 ETH, then through THORChain into about 4.59 BTC, with roughly 4 BTC of that linked to an unnamed Wasabi coinjoin round and the addresses "blacklisted"; most of the stolen funds have not moved -- AMLBot on X, crypto.news
- Matt Morehouse disclosed two denial-of-service bugs in Eclair v0.13.1 and earlier, fixed in v0.14.0: oversized feature-bit init messages could allocate about 300MB per message and crash a node, and zlib-compressed channel queries could inflate 64KB into 64MB; his smite fuzzer found the first, an LLM-assisted search for similar code patterns found the second -- Delving Bitcoin
- Lightning Labs published four security advisories: a High-rated bug let an invoice be marked settled after an interceptor had already cancelled the HTLC, affecting tapd 0.5.0 and earlier and lnd 0.18.4 to 0.18.5; three Low-rated DoS bugs covered a gossip stall, a panic on a malformed DNS seed response, and memory exhaustion from Brontide write allocations; nodes on current lnd (0.21.3 or 0.20.4) are unaffected -- Lightning Labs security
- Galaxy's Alex Thorn disclosed that 52.37 BTC from weak-entropy Coldcard addresses, about 2.8% of the total taken and roughly $4.5M, had been moved into an address belonging to a Wyoming "Crypto Recovery Trust" carrying an OP_RETURN reading "claim:cryptorecoverytrust.com"; the trust says owners can reclaim coins by proving control, but the white-hats are unnamed and its legal documents are unverified -- CoinDesk
- SEC Commissioner Hester Peirce announced she resigns effective 2 October after nearly nine years to join Regent University School of Law, leaving the SEC with two Republican commissioners and no replacement nominee named; two days earlier, at SIFMA's Digital Assets Conference, she argued for replacing KYC document collection with zero-knowledge proofs and attribute-based credentials, telling regulators "we build ever bigger data haystacks on the theory that we will find a needle or two inside" -- CoinDesk, TFTC, TFTC (speech)
- New York Attorney General Letitia James and Governor Kathy Hochul sued Polymarket US in state court on 24 September alleging unlicensed gambling and underage betting, seeking at least $4.6B in fines; Polymarket moved the case to federal court and countersued, arguing the Commodity Exchange Act gives the CFTC exclusive authority; the next day a unanimous Sixth Circuit panel ruled Kalshi's sports contracts are subject to state gambling law, splitting with the Third Circuit and making a Supreme Court case more likely -- CoinDesk, CNBC, CoinDesk (Kalshi)
- BitMEX stopped trading, deposits and new positions at 04:00 UTC on 23 September after 11 years, with API withdrawals ending 28 September and website withdrawals staying open; from 1 October verified accounts with a balance pay the greater of 1% a year or $50 a month; owner HDR Global Trading cites a strategic review, with no legal or regulatory issues behind the closure -- CoinDesk
- The x402 protocol, reviving HTTP 402 "Payment Required" for machine payments, merged Ben Carman's spec for paying with Lightning: the server issues a BOLT11 invoice whose description hash commits to the exact request, the client pays and returns the preimage, and the facilitator checks it against the payment hash and invoice signer without querying the receiver's node -- GitHub PR #2861
RELEASES
Am I Exposed v0.36.0 -- 2026-09-26
- Detects Whirlpool tx0 premix outputs and Wasabi 1.x coinjoins it previously missed or misgraded, and flags input-side address reuse as a leak instead of scoring it as good.
Jam v2.0.0-beta.4 -- 2026-09-24
- Fourth beta of the JoinMarket web UI: adds Sign Message, pins the exact UTXOs shown when sweeping, and lets you freeze or unfreeze several UTXOs at once.
Shhark v0.8.1-shhark-preview.5 -- 2026-09-12
- A self-hosted, privacy-focused Ark wallet preview adding optional Payjoin v2 on Signet, Tor-only networking that fails closed, Silent Payments and experimental post-quantum messaging.
ZEUS v13.2.2 -- 2026-09-23
- Stable release embedding LND v0.21.3 with SATS Routing and Coinos as swap providers, plus a critical fix moving iOS wallet data out of iCloud-synced Keychain.
Blockstream Green Android 5.7.0 -- 2026-09-24
- Adds manual coin selection filters, transaction notes and a price chart, and restores 2-of-2 and 2-of-3 multisig account creation.
umbrelOS 2.0.0 -- 2026-09-22
- Stable release of Umbrel's home-server OS adding a Photos app, multiple user accounts, virtual machines, FailSafe RAID storage and a redesigned App Store.
SignerOS v1.3.0 -- 2026-09-23
- Fixes a bug where one valid input in a multi-input transaction could make a fake change output look legitimate; every input is now checked against the actual cosigner keys.
Blockstream Green Desktop 3.6.0 -- 2026-09-21
- Adds paying to Lightning addresses and LNURL-pay from the send flow, redesigns manual coin selection, and restores 2-of-2 and 2-of-3 multisig account creation.
Everything Else
- Amber v6.6.5 -- 2026-09-21
- Nostr signer: relay backups are now encrypted with a separate derived key, previously readable by any app with a remembered decrypt permission.
- Arkade TS SDK 0.4.76 -- 2026-09-25
- Developer SDK patch release for the Arkade (Ark) protocol, following 0.4.75 earlier in the week.
- Bisq Easy (Android) 0.14.1 -- 2026-09-26
- Security release: embedded Tor updated to 0.4.9.13, closing high-severity Tor issues, now built from Bisq's own Tor fork.
- Sister app: Bisq Connect 0.10.0 (2026-09-26), same Tor upgrade.
- Breez Spark SDK 0.26.0 -- 2026-09-23
- Adds receiving USDT and USDC, and instant or expedited claims for on-chain deposits.
- Cashu TS v4.11.0 -- 2026-09-22
- Backported fixes: melt preimages checked against the invoice hash, requests default to a 5-minute timeout, and closed subscriptions report an error.
- cln-nip47 v0.2.1 -- 2026-09-26
- Nostr Wallet Connect plugin for Core Lightning. Dependency updates.
- Core Lightning v26.06.8 -- 2026-09-22
- Security release fixing responsibly reported vulnerabilities, confirmed to include the dual-fund drain reported in issue #9498. Upgrade.
- Ditto v2.42.2 -- 2026-09-27
- Nostr social server: verified-link badges, muted users blocked from push notifications.
- Also in window: 2.39.2 to 2.42.0 (posting streaks, emoji packs, push).
- JoinMarket-NG 0.40.0 -- 2026-09-27
- BIP-329 labels now distinguish coinjoin output, coinjoin change and deposits; adds PSBT v2 signing and warns when the wallet daemon listens in plaintext off localhost.
- <a…
Bitcoin is close to becoming worthless.
Now what's the Bitcoin? Bitcoin's like rat poison. Yeah. Oh. The greatest scam in history. Let's get it. Bitcoin will go to fucking zero.
Welcome back to the Bitcoin Brief, the show where me and q and a talk about Bitcoin, privacy, open source, keeping your Bitcoin secure, and the news and software updates that matter. I just wanted to say a mass thank you to everyone who's been supporting Ungovernable Misfits, and a big thank you to Foundation
for supporting the show. If you haven't already checked them out, go to foundation.xyzed. They make cypherpunk tools for fuckwits,
and anyone can use this, even me. If you have any questions or you want to reach out, feel free, and I'll be happy to go through things with you. For anything super technical, I'll pass you on to q. If you wanna buy one of these incredible passports, use the code ungovernable.
It will get you a discount, and it will let them know that I'm shilling. I'd also like to say a huge thank you to the Cake Wallet team. Not only are they supporting this show, but they're also bringing out some incredible features.
For those of you who actually use Bitcoin and actually care about their privacy and security, Cake Wallet make it incredibly simple for you to live outside of the traditional financial system.
You can use CakePay within the app to buy gift cards for food, petrol, and whatever else you might need day to day. You can use silent payments, and, of course, you can use Monero. You can connect both Bitcoin and Monero nodes, use coin control, and this team are constantly innovating.
And I'm really excited to be working with them. If you have any questions, you can reach out to me, but check them out at cakewallet.com. Download the APK or start using this today on Mac, Windows, Linux, iPhone, or, of course, your Android device.
Enjoy the show.
Hello, and welcome back to the Bitcoin Brief, a live and interactive show taking place every Monday at 9AM eastern or 2PM UK time across the ungovernable network. Each week, we go through the news, the releases, and the developments that actually matter in Bitcoin.
This, of course, includes self custody, privacy, the tools you run yourself, and the people that are trying to make all of that harder. If it affects your ability to spend your own money without asking permission, then we wanna talk about it.
This show and the topics we cover are powered by freedom.tech, a daily news desk that uses AI to monitor hundreds of sources so we can continue to bring you the signal each and every week.
We'd love to have you help steer the conversation by commenting live, asking questions, boosting the show, or just sharing it with your friends. My name's Q and A. I'm head of customer experience at Foundation. And as always, I am joined by my good friend Max, the head honcho of the Ungovernable Network.
Without further ado, let's dive into the show, kick off the week strong. Max, how are you doing? And also, before I let Max come in, far more important people are in the chat. Good morning, John.
Good morning, John. Good morning, Q. Good morning, anyone else who's lurking in the livestream. Yeah. I'm good, mate. I'm good. I was running a bit late, so not as prepared as I usually am, and I don't have any show notes. I don't know if we have show notes or not, but I haven't got them in front of me. They're in Telegram.
They're in Telegram. You doubt me. But yeah. Unprepared. Mate, I never doubt you. I just constantly doubt myself for good reason. Where are they? In the brief in the brief section? They should be. Let me just
yeah. They're all there. They come brief. You got the show notes. You got the restream link, and you got the show up. I see the image. I see ah, are they is the image for it the the breach continues,
I think. That might have Yeah. That's just the cached image from last show. Oh, but it still says breach season continues. Don't worry about it. We we have the right title. It's just restream doing restream things.
Is it weekend in Portugal for queue unless you went to work again? Oh, are you talking about the show notes now or what? Show notes. Sure.
The only show notes I have access to are are those ones. Well, that really matters. I can't fucking read anything. Show notes. I posted them today, twenty five minutes ago. It's definitely the right ones. I've just clicked the link to check. I can't see them. They didn't come to me. They're not like I'm looking at Telegram,
the Bitcoin brief in our Telegram group, and all there is today is an image, and they're there. They've just come through now. I just sent them again. Weird. Okay. Telegram doing Telegram things. Anyway, did you have a good weekend?
I had a very nice weekend. Thank you. Yeah. I did a bit of stuff around the house because I flooded downstairs, and then I had to rip out a load of bits of pieces that I wanted to rip out anyway. Of course, did. Tell tell me more about the flooding.
It's not that interesting. I left a sink running with a plug in it, and then one of my children asked me if he could take the bin out with me. And my plan was fill the sink while I go and do the bin because you try and, you know, multitask
and do things efficiently. So I thought that's about the right time in that fill with the hot water, and then I can do the dishes when I come back. And then he distracted me with a thousand questions and swings and just, like, all sorts of stuff happened. And then I came back, and I was like, oh, why is everywhere wet? And then I went,
you absolute moron. And, basically, the whole of downstairs was completely flooded. And, yeah, there was a load of stuff that I wanted to take out, like, old timber and bits and pieces anyway, which all got behind, and it was just all fucking disgusting. So I spent most of the
Saturday sorting that, which was not so fun. But then we did a, like, full kids day the next day, and they had lots of fun. They had so much fun that they're now sick. That sounds like a pretty a mixed weekend. Yeah. Pretty quiet for me.
Bit of it like dad weekend, just doing a little job around the house really, just throwing all taking all of the shit to the recycling center. Oh, that's good. That's a good job. Moving the dryer
inside now that we've cleared some more space. I've got more room in the gym slash garage Nice. Which is, you know, which is nice. Really good. Maybe room for for some more equipment in there.
Bit of bit of personal vibe coding. I I went to watch Spider Man on Friday night. I'm a bit of a closet Marvel nerd.
Spider like, the the new Spider Man, he well, I say new. It's the same actor, but the new film, I mean. He he's in his flat in in New York or his apartment. I think it is. He's got like a Iron Man style setup.
Excellent. He likes talking to Jarvis and shit like that. Obviously, Spider Man's Jarvis. He's not called Jarvis. I can't remember what it's called. But I was like, I now have all of the power to make my own, so I'm trying to do that.
Like a a voice like a a voice version. Voice to control all my all my shit. But I'm but I'm trying to do it in a way that, like, uses local voice models and stuff. And, yeah, it's not quite as slick as Spider Man, so I'm I'm not gonna be joining the Avengers anytime soon.
There's there's slightly more funding in the Stark Empire than there is in the Ungovernable empire. So I think we can all be forgiven for being a bit behind the times.
Yeah. Yeah. But it's getting there. It's getting there. I think I think, you know, a few more a few more evenings poking around on it. I think it'll be somewhere close to usable. I'll I'll share it with you once once it's ready so you can call me a note.
Very cool. On a a not so light note, we now have letter number seven from Keone, his note from the inside posted to to the rage. That came out four days ago on the September 24. And I've done the read for this one that because obviously, for those of you listeners that don't know, Max
has been having relevant ungovernables reading these out so that people can listen to them as well and kind of immortalize the the madness in audio form. Yeah. So I I recorded this one just after Free Intentive Friday last Friday.
And it was tough, mate. Like it it was it's this one's probably the the the hardest one I've had to had to read. And I don't mean that in the sense of like, I had to read it and record my voice, although that was pretty challenging because it's it's a lengthy article. There's a few fuck sakes. Yes. Yeah.
But what I mean is like, it's just a difficult read. I I think to to paraphrase one of the the quotes from in there is, like it's not even paraphrase. I can actually quote it. It's up on the top of article. Quote the absolute worst thirty days of my life. Mhmm. It was, yeah, basically, it documents his journey in transit between
facilities just basically turning into a complete clusterfuck and him being shacked up with rapists and murderers and child molesters and things like that in what sound like absolutely squalor conditions.
Yeah. So not a nice read at all. It's important that we do read it to to keep this current and continue to beat the drum because it's obviously an important topic. But,
yeah, found that one one really tough. Obviously, it's it's linked on the rage if you wanna read it and will be on the feed. Well, you tell us when it'll be on the feed, mate. I think I spent some time over the weekend editing it.
I'll do a little intro and outro. I think I'll probably another few hours and I'll have it cracked. So maybe maybe tomorrow maybe tomorrow or Wednesday release. I wanna get it released at the same time that Rick is running this prize draw.
Yes. For anyone who hasn't seen it yeah. So if you haven't seen it already, Rick, who's r mess it at r mess it on Twitter, has been running this prize draw. It's actually gained a lot of steam. It's doing really well at the moment. I think let's just have a look now. It's
what's the actual website for it? I'm just bringing it up on the on the screen. Oh, of course. Yeah. You can do that. Yeah. 3,000,000 sat jackpot and 3,000,000 sat charity pot. So whoever wins, you can you can buy tickets.
Whoever wins gets half the pot, and then the other the other half goes to support the cause, obviously. But, you know, 6,000,000 sats in the part is pretty fucking impressive. I would like to see this get to 10 by the end of the week if we can.
Well, yeah, more more if possible, but I wanted to release, the notes from the inside audio version, just to jolt everyone and get everyone over there as well. So, yeah, probably Tuesday or Wednesday.
But, yeah, what a what a great initiative and really cool to see people actually doing something here. And raising that, like, that amount of stats is, as I say, very impressive. Like,
it's very hard to get people to part with their stats for these type of things. And most people, there are some extremely generous people who have been there from the very beginning supporting.
So I don't wanna dilute what they're doing. But just as a general rule, it's hard. And he's gamified this and, yeah, done an amazing website and an amazing, yeah, price draw here. Yeah. I believe this is not the first time he's done this. I wanna say last around about last year when I was in Manchester for Maybe.
Nathan Days Bitfest UK. I'm sure Rick ran a similar thing as well using the same format where it's like a provably fair kind of lottery that's tied into I believe it's tied into like the block hash of when they do the drone stuff. You can go in and approve that it's fair sort of thing. So
I wanna say that this is this is the second time he's done it. If you wanna get involved, the website on screen, the URL for that is freesamurai. Now. And don't forget to spell samurai the way that Samurai spells it, which is s a m o u r a I.
Yeah. And you can you can buy tickets with Lightning or on chain and use an op return. You can each entry is 5,000 sats. So you can do one entry, five entries, 10 entries, or 21 entries. 21 entries, 65,000 sats.
But, yeah, if there's anything out there worth supporting and getting involved with, it's this. And then, obviously, you can win the prize money, and then you can decide to do what you want with it. You might wanna give all of that to to help free Samurai, or you might have your eye on something else. But
definitely go and check it out. And even even if it's just one ticket, it all makes a difference. So definitely definitely go and do that. And, yeah, respect to Rick. I've never actually spoken to him. We've we've back and forth a few times over the years. Yeah.
He's a cool guy. On on Twitter and things like that. But, yeah, you you have my respect for doing this. Maybe I have to do a little call with him. Yeah. Yeah. And get him on. Yeah. Let's do that. Let's do that.
Anyway website as well. Well, exactly. Like, it's it's not like a half assed job that he's done. It's it's really fucking great.
So, yeah, we'll we'll definitely get them on. Definitely go and get involved. And what was I just about to say?
Oh, if you're listening and you wanna add this to the prize, might tempt people a little bit. You can add a free samurai T shirt and a free samurai hoodie and a free samurai hat to the to the prize pot, and I'll cover all of those just if that tempts people. So if you're listening and you wanna add that, I don't know what that is, a $150
or something worth of stuff, a bit more. Add that in. Awesome.
Well, that's very kind of you. Yeah. That's that's it for my AOB, mate. I I don't know whether you've got anything else before we dive into the news. Oh, what? The only other one I had actually, just quickly while you're thinking, is Awesome Freedom Set Friday last week. Really enjoyed that We
did a if you haven't caught it yet, know it's only been live for a couple of days. We did a listening questions episode, which we haven't known for ages. So we had loads of decent questions. We actually got through a fair chunk, like 90% of them, which I was quite surprised at.
Very wide ranging from Bitcoin to Monero to privacy tips, multisig, AI, local AI. Yeah. It was a really fun one. So I think we we should maybe drop one of those in per month or something like that because it seemed to be a a good appetite for them. So
yeah. I really just wanna say thank you to everybody that got involved with that one. It was it was a lot of fun. Yeah. Because it sort of just meanders all over the place because different interests and different types of listeners. And, yeah, I enjoy them. I think it will naturally happen anyway because we
obviously could get a guest on every single week, but we're quite picky and choosy about the projects and people that we have on. And so there's always gonna be the odd time where we're like, actually, let's just do let's do one of these. I think it will naturally happen.
For sure. Yep. One thing I wanted to before we move on, from obviously, I'm I'm editing what you've sent over in voice form for the notes from the inside. I haven't finished it yet. I'm sort of, like, two thirds the way through or something like that.
But one thing that really one thing it, like, really, really stuck with me and made me feel really physically uncomfortable was and this might tempt people in. It's like a random thing, but they're talking about, like, spraying, like, getting high. They put them all into this, like, underground room.
And Mhmm. Keanu's in there with, as you said, like, rapists, murderers, like, fucking like, not the best people. Sure. There's some good people in there as well, but not the best people. And this is a bit where he's talking about, like, as soon as the guards leave,
they're using this I think they call it juice. And I was like, what the fuck is juice? And he explains they spray either cockroach spray or rat poison onto paper and then light the paper and then inhale the fumes.
And then just, like, go, like, that fentanyl stance and just, like, hunch over for a few minutes and just sort of have no control over their body.
It made me feel, like, really fucking a bit I don't know. Like, you ever get this where you, like, can't sit still and you feel, like, really uncomfortable in your own skin? Because I was like, at what stage in life are you there sucking in rat poison or cockroach spray in a dark room to escape?
Like, that's that's the good that's what you wanna escape to. You've you've gone through all the security and been searched three times and somehow managed to get this fucking rat poison or cockroach spray and a lighter in, and that's what you're doing. It just made me feel like if that's the human experience,
there's something seriously wrong. It's it just really fucking stood out to me. Yeah. I mean, same for me. One of the many things throughout the whole the whole letter that just made me feel very uncomfortable.
Just makes you realize how lucky you are to, you know, have your day to day privileges and just live a relatively normal life, doesn't it? It it certainly does. And and like I said, we'll have this live. So anyone who wants to listen can do. And may I say actually, on a lighter note, you made my job way easier than it usually is.
Your reading skills, although you have the odd stumble and a fumble, well done. It must be doing all these intros that you're doing on the, FrimTech Fridays and things you sort of learn to read again. But, normally, it would take me two or three times as long as it's taken me.
Yeah. I mean, I think my recording was, like, twenty eight minutes or something like that. So, hopefully, you can chop it down a fair bit. But Yeah. It will be about twenty minutes by the time I'm done, probably. Too bad.
But, yeah, it was well done. Well done. Thank you. Thank you. You can read. Congratulations.
Right. Let's let's move on to the news. We got a lot to cover. Some of them, obviously, we will dive a little bit deeper into. Some of them are more political, and naturally, we'll kind of mention them and skip across them. The headline for this week, we actually took briefly on this on Theme Tech Friday. But I thought it pays,
you know, obviously this is specifically for Bitcoin and it make make sense to go into a little bit deeper given that the rest of the news was kind of benign, especially when you compare it to recent weeks.
Shielded Bitcoin, a proposal for Zcash style private transfers has been released And the the crux here is proposal. This is this is very much early stage alpha software, test software at the moment. So don't expect it to be in your favorite wallet next week.
But very I thought it's pretty cool, especially as I read into it a little bit more. So to set the scene a little bit, every normal Bitcoin transaction is public. The amount, the addresses, and the link to every coin that came before it. It's Bitcoin's open ledger. That's how it works.
Zcash allegedly solved this years ago with what they call shielded transactions, where they use zero knowledge proofs to hide the sender, the receiver, and the amount. Kinda similar to Monero as well.
Well, on the September 24, just four days ago, a research lab with a really weird name called Allocint. I'm probably butchering the name, but Alloc in it. Alloc something like that anyway.
Founded by people I've never heard of, Misha Kamarov and Clara Schakelman as head of protocol research. They published a design for doing the same thing on top of Bitcoin. And here's the cool part, without changing Bitcoin at all.
So this is what some people might refer to as kind of like a meta protocol. It's a set of rules that live inside ordinary valid Bitcoin transactions today or can do. Each shielded transaction is a blob of encrypted data with a prefix carried in. Yes. You guessed it. Our old friend, OPRETURN or witness data.
Bitcoin generally sees meaningless data. It orders it and timestamps it and that's generally it basically. It's kind of like there's not much fanfare here. The rules are enforced by separate software called indexes kind of similar to the way in which
ordinals might approach this sort of thing where they have kind of arbitrary additional data that only makes sense to them, which anybody can run next to your own Bitcoin full node.
This in the exact same way that your node kind of enforces the Bitcoin rules, this additional piece of indexer software would kind of speak the additional shielded Bitcoin transaction meta protocol.
Inside this new system, value is held in encrypted records that they call notes, which is like the shielded version of a UTXO. So when you were to pay somebody, your wallet creates a new note for them and encrypts its contents, encrypts the amount and the details needed to spend it using a secret key
oh, sorry, a secret that only you and the receiver are able to work out. From one master key, your wallet can generate as many receiving addresses you like, just like a traditional kind of bitcoin wallet.
And separate viewing keys let you show your incoming or outgoing payments to somebody. For example, an accountant. Sounds very similar to Monero actually in that in that respect. Crucially, without giving them power to spend.
When you spend a normal coin, Bitcoin removes it from a list of unspent coins, the UTXO set, which tells everybody exactly which coin moved. Shielded Bitcoin never removes anything. Every note ever created goes into an ever growing tree structure.
And to spend one, you publish what they call a nullifier, which is a one time tag calculated from that note and your key along with a specific zero knowledge proof. So that's where that kind of ZK stuff starts to come in.
The proof shows four things without actually revealing any of them. This is where it gets pretty cool. It proves that the note really exists in the tree. It proves that you're authorized to spend it.
It prove it confirms the nullifier was calculated correctly. I'm not sure the technicalities of that one. And that no new money was created. Nobody can tell which note the nullifier belongs to, and indexes only check that the same nullifier has been used before and that alone is designed to stop the double spend problem.
The cool part is that because Bitcoin doesn't check any of this or or standard Bitcoin or Bitcoin as we know it today, an invalid shielded transaction can still be mined into a block. So indexes throw it out and never change anyone's balance.
The the hard part in all of this and I believe is kind of not solved yet is the peg. Getting real Bitcoin in and out of the system and I believe it's not even been designed just yet. The the plan that they have is a scheme that they call PIPES v two and PIPES is is capitalized here, so it's gonna be an analogy.
Not sure not sure what the exact analogy, not analogy, what's the word I'm looking for there, Max? A acronym. Acronym. Yeah. Yeah. Based on witness encryption. So a key is locked, so it can only be unlocked by somebody who presents a proof that a condition has been met.
For example, that a deposit has confirmed. The idea is the is a peg in with no federation, no operator holding the coins, but witness encryption is to my knowledge an unproven practice, and the paper is all, as I said, very very still alpha.
And the whole kind of trust question sits in that missing piece really of like how do you get this peg in and out. Yeah. So this is pretty cool. There's there's probably gonna be some Zcash or Monero enthusiasts listening to this going, well, that's all sounds very similar.
But where I think this is interesting or potentially interesting is the fact that in theory, I know there's a lot of there's still some holes in this. It could be live and opt in
with Bitcoin today. We know how difficult it is to change Bitcoin at the protocol level, nigh on impossible these days. And I don't necessarily think that that is always a bad thing. But we also know that Bitcoin has a very, very bad privacy problem. Like, yes, there are ways around it with swapping and lightning and things like that.
But if we could have the traditional Bitcoin wallet experience, but also with all of this extra anonymity built in or or opt in, then I would love to see this kind of progress. Definitely.
It'd be incredible. I guess we just wait and see. I I think it's the unproven part, the peg in, peg out, like Mhmm. And how secure all of that is. And
especially with how the last couple of months has been. You know what I mean? It makes you sort of feel like, oh, okay. You're gonna sort of, like, try and do it, and then suddenly, poof, it's gone.
Like, yeah, untested cryptography with with funds. It's kind of concerns me a little bit. But if it was possible, fucking excellent. It would be great. Yeah. The the other thing that's that's not mentioned here that is worth bearing in mind is that, like,
I presume it's gonna be blatantly obvious if you own a coin that moves into the shielded system and then back out or in and then stays in, which so so you're kind of not losing the the ability to for example, today, if if I was to send some Bitcoin to Coinbase that's been through Whirlpool or similar,
then they Oh, yeah. Good luck. Could see that. And and and I don't think that this is gonna fix that, but it does give on chain privacy to the level that you we tend to see with the likes of Monero or Shielded Zcash
where, you know, you've got blinded amounts or liquid. You got blinded amounts, you got blinded recipients, and all that sort of stuff. So it's a step in the right direction, but it doesn't fix all of the problems.
It doesn't. But, like, with everything in Bitcoin, it doesn't fix it doesn't fix it by itself, but there are other things that could be done prior to that. Like, for example, you know, opening up a Lightning channel and then doing a spend out and then,
like, doing it so that there's a there's a break there. And then when you come back out through Lightning again or something like that to change it. Also, I've I've heard people talking about
sending Postmix coins to Taproot addresses
to break links, and there's a few other little tips and tricks and stuff like that. I mean, I yeah. You don't solve that problem, but that's that's something you never solve with Bitcoin unless there's a major change to Bitcoin because it is open and, like, that's good for some things and and very, very bad for privacy.
I agree. Yeah. Absolutely. Alright. Let's move on. Update on the liquid stuff. They've posted their own post mortem. If you've missed the last couple of shows, quick up quick reminder. On the September 6, the liquid network network was drained of almost its entire reserve, almost 4,000 bitcoin by somebody or
an entity that called themselves white hat hackers.
It clearly it's become clear since then that they are probably not white hat hackers because of all of the stuff we covered in the recent shows. If you're not sure, go back and check them out. But, yeah. A couple of days ago on the September 23, Blockstream published its own assessment of what happened.
So there were two bugs. The first which Blockstream calls bug a, very descriptive, was a flaw in the cache element use sorry, the cache, the elements, the liquid software uses to remember which rain proof range proofs.
You just say you've jinxed me, I'm actually said I was really good at reading and now my note, I can't read my own notes. Which range proofs it had already checked and it dated back to but get this, April 2018.
A reach a researcher called Stu Txo, great name, reported it responsibly on the August 2 and it was patched on the thirteenth sorry. Yeah. It was patched by the August 11 by all of the function functionaries.
However, this patch introduced bug b. Again, very descriptive. The fields that make up each cache entry were joined together without saying how long each one was. So two different proofs could produce the same entry.
Think of think about writing a 12 next to a three and a one next to a 23, both read one, two, three. The attacker used Bugbee to mint about 4,000 liquid Bitcoin backed by absolutely nothing and proceeded to peg out 3,996 of those through SideSwap, which is a as the name suggests, is a swap service where you can get from
liquid paper Bitcoin to Just real stop there for a second. I I thought I wondered this last when we were covering it before, and I think I just didn't wanna upset your flow.
They just have that much side swap just sat there just, like, on the cash, and they're just like, yeah.
Alright. How does that work? Well, side swap the the the the Bitcoin, the real Bitcoin comes from the liquid federations reserves, right, which is controlled by that 11 of fifteen. So the 11 of fifteen signed off on this transaction, but sides what was the kind of service that processed the withdrawal,
basically. But it would have had to have been signed by 11 of the 15 functionaries. So it wasn't the size what it wasn't the size what was sat on 4,000 Bitcoin. That was controlled by the 11 of 15 multisig.
So what's their task? What like, because there's already if if Blockstream already hold all those funds, then what does SideSwap do? Blockstream hold That's my point. Blockstream don't hold them. They are held by the collective 11 of 15 from I see. I see. SideSwap is just the interface or the service that is able to
speak liquid and also speak Bitcoin and Yeah. Okay. Yeah. Kind of provides that facility. Okay. The real question is why don't they have kind of limits on flows? Like, you you would have thought,
let's maybe set a limit that you can't withdraw 50% of the network at once or something like that. Like, that would be Yeah. It's not a bad sensible. Bad idea. Restraint is is was the term I'm looking for. Yeah. Obviously, that wasn't in place and 4,000 Bitcoin basically got stolen.
The network was halted the same day. A few days later, 3,400 Bitcoin came back with the negotiations still ongoing about the remaining 602 bitcoin between the attacker and Blockstream. No update on that side of things.
Peg outs are still paused. Although I believe you can do some very small swaps with things like Aqua and whatnot.
They they they're gonna resume once the federation confirms the full one to one backing and the security reviews are finished.
So Oh, it's just final quote on my notes here, which kinda summarizes this quite nicely. The 11 to 15 multisig worked exactly as designed, like I said earlier. The failure was in the software that decides whether a transaction is valid.
And that is where the trust in the Federation side chain actually sits. It I guess when you're designing these systems, there's probably an element of, like, you're focusing on the main thing that shields people. Like, you're thinking about, oh, well, there has to be 11 signers.
It's like, you know, it's gonna be very unlikely that they're gonna collude, and therefore, it's gonna be should be safe. And so you're sort of focusing on that main bit of shielding and not thinking like, oh, there's, like, a a minor kink in the armor somewhere else where
that doesn't matter at all. You know what I mean? It's like Yeah. It was a very sneaky weigh in. But nonetheless, like, I still stand by all my comments that I I have made on the last few shows, and I've someone agreed with me actually in the in the comments the other day. Was like, ah, there's one other. There's one other who agrees
with me. But anyway, it's fucked. It's it what whatever stance you take is fucked. Yeah. Absolutely. Well, sticking with hacks. This is a new one. On 06:30 UTC on the September 24, just a couple of days ago, Bitget, which I've never heard of until now.
Well, until this news dropped at least. No. I mean They detected an unauthorized transfer from its hot and warm wallets and froze withdrawals for everybody. CEO, Gracie Chen, says the attacker got into a back end system in the wallet infrastructure, fed it fake transaction data, and triggered Bitget's own approval process.
Private key theft has been completely ruled out. The losses were first put at $351,000,000, then revised on the September 25 to about 387,000,000 once Zcash and Tron assets were also counted.
It was most mostly ETH, TRX. Is that Tron? Yeah. TRX, Tron. And USDT that was stolen. No Bitcoin, which is interesting. Maybe they keep that in a separate system. Okay. Now, obviously, the stable coins in and amongst those assets I've just mentioned. And Circle and Tether froze about $318,000 off the 387,000,000.
The attacker moved about 83,000,000 of native XRP, which Ripple allegedly has no power to freeze. What the fuck are you gonna do with 83,000,000 in XRP? You just I'll tell you what you do with 83,000,000 in XRP is you wait because that is going to 1,000 a coin.
Yeah. Of course. Yes. Yes. It's pretty fucking up. Come on, mate. You do you know what's funny? Just a quick XRP story here, which, I don't wanna take us too far off track. I met since moving a few people since, like, you know, making a few friends and parents at school and that kind of stuff.
One of the wealthiest and well, actually, of the smartest, like, as a general rule, we can all be smart and retards at the same time. I think that's fair to say. Very smart, very successful person I've made friends with who I talked a little bit about Bitcoin with, and he is a massive XRP shill. Like, fucking
and it's just so funny to see, like, someone who's so capable and so competent in, like, most other walks of life and then just, like, has this blind spot with this thing. And it did make me realize, like, we are
we are so in our bubble of being able to see these kind of things because we've been here for a certain amount of time, and we've just spent so much time on this that it's not just like, there are just mongs who just, like, are in these chat groups, and they get sent in. They're like, oh, I'm gonna be a fucking millionaire.
And, like, they are proper stupid, but it catches smart people out too. It's weird. It's really weird to observe. And and also when you do observe it and it's with someone who is smart because if it's just like a moron, I go, yeah. Good luck with that, mate.
But when someone's smart, like, they've got a family and, like, you like them, it's really hard because you don't wanna be like, listen. You're a fucking itch. Shut shut the fuck up, you idiot. You don't wanna be too mean, but also you don't wanna see them lose all their money because it's like, oh, yeah.
I've got, like, most of my net worth in this now. You're like, oh god. It's weird. Yeah. I mean, it just goes to show you can be rich and a retard. Yeah. Well, you you but you can be rich and smart, but also just have one blind spot where you are a retard in one aspect of life, and it could ruin you.
Yeah. Yeah. Yeah. We're a little bit more fragile than we like to believe, I think. Oh, yes. Back to BitGap. Yes. The as always, the attribution points at North Korea, which BitGap has set itself relating to IP evidence tied to VPNs that a known North Korean hacker group has used before.
Elliptic are saying it's highly likely based on on chain links to the by bit laundering addresses and from MetaMask's Taylor Monaghan, who also kind of backed up as well. No government has attributed it to it yet.
Now here's an interesting point. Bitget says that it's user protection fund has covered the loss entirely and that it's reopening withdrawals in stages at eight from 08:00 today. On yesterday, on the September 28 with ETH following tomorrow and USDT the day after, and everything else on the October 2.
So, yeah, they've they've got insurance here and that they reckon that it's all good, which is obviously good for the users. Imagine being an insurer for, like, default. I mean, Bitcoin Bitcoin's one thing, isn't it? And, like, we covered that. She last
last Friday, we're talking about this and just, like, it's so normal for these hacks to be all over ETH and there to be these vulnerabilities and, like, money's flying all over the place and scams everywhere.
It's relatively new in Bitcoin land. I can't imagine being an insurer and going, do you know what I wanna insure? I wanna insure fucking defy. Like, what are you thinking, and and how much do you have to charge to make it worth your while? Because it seems to be a complete fucking clusterfuck.
Like, it did like, I can't think of anything worse to be the insurer on. No. I agree. I'd imagine their rates are colossal. Extremely high. Yeah. Extremely high. Well, just just around this bit get bit get portion of the story out.
On the September 26, just two days ago, AML bots traced part of the bit get haul from, get this, TRX Tron to USDT Tether across to Ethereum u using USDTO, whatever the fuck that is, into about a 145 ETH, then through Thorchain into about 4.59 BTC.
It linked about 4 BTC of that to a Wasabi CoinJoin round, and it says it has blacklisted the addresses. Most of the stolen funds outside of what I've just mentioned have not moved at all.
Okay. Just thought that was interesting that they've managed to trace it across multiple networks. And through Wasabi? It's Bitcoin. Yeah. Well, I I don't know whether they've kind of traced it on the the kind of output side of I'm not sure.
Okay.
Right. Okay. Moving on. We have been recording for a long time and we still got a lot to go. So let's speed up a bit. Two Eclair Lightning bugs have been or denial of services have been disclosed.
Unsurprisingly, one of them is communicated as being found by an LLM. On the September 24, Matt Morehouse disclosed two denials of servicing bugs in Eclair zero point one three point one, and earlier fixed in 0.14, which was back in May.
The first used oversized feature bit messages appear could make the node allocate around 300 megabytes for every initial message as in the denial of service attack and the first message to which is sorry. The in it message is the first message that two nodes exchange.
And what this could do is crash the node and knock your peer offline. The second one used compressed channel queries. No idea what they are. Where 64 kilobytes of data could inflate to 64 megabytes once unpacked.
Once again, this is all fixed, but is yeah. Oh, sorry. Yeah. This is this was found by AI assisted bug hunting, I believe, by Project Loop, which is the one that we mentioned on the last show, I believe, which is powered by Block where they're doing actual
white hat hacking on on Bitcoin projects. So good to see that, you know, true open source projects are getting hardened and before they can be exploited. On that note, we also have Lightning Labs disclosing four l and d advisories all long since fixed.
On the September 25, Lightning Labs published four security advisories. The one rated high let an invoice be marked as settled after an interceptor had already canceled the payment. Free shit. Nice.
An interceptor is software that decides whether or not a node accept an incoming payment. It affected tap d 0.5 and early versions of l and d as well. The three orders were all rated at low or denial of service bugs as well.
If you run l and d, check that you are on zero point two one point three or newer.
More hacks. Back to the cold card fiasco, for lack of a better term. On the twenty first of first of September, Galaxy's Alex Thorn disclosed that 52.37 Bitcoin from those weak entropy addresses had been moved into an address belonging to a Wyoming, quote, Crypto Recovery Trust.
The transaction carried an OPRETURN message reading, quote, claim coloncryptorecoverytrust.com. This equates to about 2.8% of all of the the total that were taken, which is about $4,500,000 in today's today's money.
Owners of the affected addresses may be able to reclaim their coins and the trust says releases require proof that you control the address. Not sure how you're gonna do that given that the private keys would have already been leaked to everybody with a Kimmy k three subscription.
But the white hats have not been named and the trust's legal documents have not been independently verified. Interesting one. I don't know what to make of this. Bit bit weird. I
if I had to bet on it, I would say that
actually, I don't know. I don't know. I was gonna say, like, if I had to bet on it, would say it's not really a white hat, and they're just covering their ass while they move some thumbs so that if they get stopped or caught, they're like, oh, well, I was doing the right thing. That would be my guess, but, like, some sort of, like, cover.
But you never know. It could be. But like you say, how do you prove it? It's like, if everyone has the ability to make it look like it's theirs, how do you actually do that? Mhmm. What would you I suppose, like, you could maybe prove that you bought a device and then prove that you have the ability to sign something,
and maybe you could prove provenance of coins if, you know, it could be traced back to, like, purchasing on an exchange or something like that. Maybe.
I don't know. I saw a lot of people saying, like, keep hold of your cold cards. Don't actually, like, shoot them or burn them or whatever Definitely. Which I think is probably good advice because you never know. Like, the the this kind of thing could actually be a real white hat.
I don't know. I guess we find out. Yeah. Definitely. Okay. Next on the list. Hester Peeks. Running over time. Sorry. Yeah. You can Can I just say one more thing? Yeah.
Fuck you, MBK. Yeah. Agreed. That's just just really, really fuck you, and don't start slithering out of your hole and doing all these things you are on Twitter. And don't start feeling bad for him and and letting his snakish ways back in. Just seriously fuck you, and we can move on.
I agree. Okay. Let's whisk through these. Yeah. Hester Pierce is leaving the SEC. She has been one of the SEC's most consistent defenders of self custody and Bitcoin and crypto privacy. She led the the SEC's crypto task force.
On the September 25, she announced that she res resigned effective October 2 after nearly nine years, and she's gonna be rejoining Regent University School of Law.
This leaves the SEC with two commissioners, both republicans, chairman Paul Atkins and commissioner Mark u Ueda. Fuck knows how you say that. With no replacement nominee named. And that two member commission could run well into next year.
Two days before the announcements at a conference, she gave a speech called looking for change in haystacks, where she argued for replacing KYC document collection with zero knowledge proofs and attribute based credentials.
Prove the fact, the file. You approve your age, citizen, or sanction status without handing over the documents themselves, which I think we can all get behind and it's kind of a breath of fresh air to hear somebody in the government actually talking what seems like common sense.
To quote her, she said, we build ever bigger data haystacks on the theory that we will find a needle or two inside. The bigger the haystack, however, makes it harder to find the needles, which I thought was pretty cool.
Obviously, is her personal view, not SEC policy, and she's not gonna be able to change any rules. But this is at least now on federal record, which is worth note because we're we're quick to point fault with these three letter agencies.
And it's, you know, she was the one of the few people that was more aligned with us than anybody else in the government. So it's kind of sad to to see her go and kind of not really positive from a a policy perspective.
Okay. Next one I'm gonna skip because of time and move straight to New York is suing Polymarket as the cause splits on split prediction markets.
On the September 24, the New York attorney general Letitia James and governor Kathy Hochul sued Polymarket US in state court. They are alleged, you guessed it, you haven't got a license, mate, on licensed gambling, And that it let 18 year olds bet where the New York law requires 21.
They want an injunction, forfeiture, restitution, and fines of three times the gains, reportedly at least, hope you're sitting down for this, $4,600,000,000 according to one named source.
Within hours, Polymarket moved the case to federal court and filed its own lawsuit arguing that the Commodity Exchange Act gives the CFTC exclusive authority and not them. The next day, a unanimous sixth circuit panel ruled that Calci sports contracts
are subject to Ohio and Tennessee gambling law. New York had already sued Calci two months earlier.
So states are now treating the CFTC registered prediction markets as unlicensed casinos. The sixth circuit ruling puts it at odds with the third circuit. God knows what that means. Americans, hopefully it means something to you.
Which which sided with Kelshi and makes a a supreme court case more most likely in in this scenario. Basically, it comes down to whether federal commodities law overrides state gambling law and who gets to regulate a market or that market.
Oh, like always crawling over who gets to regulate. Yes. Absolutely. Oh, come off. Next on the list, BitMEX is the exchange that's pioneered perpetual futures. Been around for a long time. Eleven years to be precise is closing its doors.
Oh. It stopped trading deposits and new positions at 4AM, UTC on the September 23 after announcing the closure back in July. Withdrawals through the API ended at 4AM on this today on the September 28, while withdrawal through the website stay open.
From the October 1, verified accounts that still hold a balance pay the greater of 1% a year or $50 charged monthly, presumably to keep the assets there, so obviously get them off. And yeah, bit of an institution this one in the kind of Bitcoin and crypto world and closing its doors.
Did they say why or?
I do not know. I'd imagine they probably stated that back in July, but I don't have that in my notes. Okay. Last one on the news list, x four zero two has added lightning for paper request payments over HTTP.
So HTTP has many different status codes. One of which is four zero two quote payment required. That was set aside years ago in the early days of the internet and has never been used. The x four zero two protocol revives it so that machines can pay for things autonomously or not autonomously over HTTP, the the kind of internet protocol.
On September 23, x four zero two merged Ben Carmen of
fuck. Where did Ben Carmen used to work? Put a few places. I think he's at Spiral now, which is cool. But Oh, the Bitcoin company or something like that. Bitcoin company, Mutiny. Yeah. He's done a lot of cool shit.
So they merged his specification for paying with lightning. The bay basically, the way it works is the server issues a fresh lightning invoice whose description commits to the exact request being paid. Think of something like, you know, access this article.
The client pays and returns the pre image, which is like a 32 byte secret revealed when an invoice is paid. The facilitator or the person who owns the website that's asking for the payment checks the pre image and well, checks it against the payment hash and basically allows them access to to whatever is behind the paywall.
This is pretty cool. I know we've kind of had this in a kind of rudimentary way with various different protocols built on top of of Lightning, but this kind of makes it more internet native now. So this is pretty cool. Obviously,
this is just the fact that it's merged into the protocol. If websites choose not to adopt this, then it means nothing at all, but it's a step in the right direction.
I we need to do some boosts, but I need you to update the notes, Max, because I just realized that the boost that I got initially this morning in the notes that you got in front of you are from the wrong place, and they don't include a lot of them. So Okay.
Let me just quickly Have you already I've completely thought You want me to refresh it? Okay. In a second. I was gonna say And you're while you're saying that, I'll I'll reiterate Hit refresh. My my points. Go on.
You can hit refresh. It's done. Ah, there we are. Yeah. I was gonna say it didn't change before. Yeah. Let's what should we do? The top three?
Let's do top four just just to change it up a little bit. I'll kick I'll kick us off. Lonely Pumpkins, 10,000 sats. Oh. Keep on keeping it real, gents. Keep stacking sats. Keep stacking skills. Thank you for your support.
Yeah. Thank you, Lonely Pumpkins. He's been he or she has been top booster for, I think, the last, like, four episodes or something like that. Yep. We see you, and we appreciate you. Thank you. We do appreciate you. Thank you very much.
Expatriotic. One part 0 point 01 XMR. 0 point 003. He he was upset about that, so I'll make sure I put that in. Yeah. Yeah. 01003 XMR, expatriotic. One pineapple bacon jalapeno ham pizza is amazing.
Two. Not get fucked. No. You're absolutely right. It's terrible. One day, expatriotic, we'll have a pizza together. That sounds delicious. You can have what would you even you just don't have pineapple or any sort of fruit anywhere near a Visa. Maniac.
Robot vacuums are the best. We had one in China. Yeah. I bet it was good in China as well. Three, the gunshot may be unsettling for headphone wearers. Made me jump a bit. Eater.
Good. Next on the list, Welder Ian, 2,222 sats. No comment. And Cruz with 2,100 sats. Ham and pineapple pizza is goated. Go fuck yourself. Yes. Yes. I'm so pleased to hear that people in the chat have taste. It's delicious.
Cruz, I'm a fan of yours. You've you support the show, and you are one of the you're in the ungovernable hall of fame, but you're wrong. You know which head you are getting.
Right. Let's let's do the release highlights. Oh oh, sorry. Quickly, shout out. We won't read them all, RevHoddle, Chad Farrow, Chad Chad Farrow, Nosdagang, we'll we see you. We appreciate your support as well. Thank you. We do. Yeah.
Thank you very I I wasn't broken then, just that Chad Farrow boosted three times. Yeah. While we're talking about Chad Farrow, I wanted to also just say thanks to bowl after bowl for having me on episode four listening to that last night. Four five nine.
Great. That's a great podcast. They really like, if you wanna talk about value for value, I think probably they're the best I've seen. The the the way they set up their value for value is pretty incredible.
And, yeah, I appreciate them having me on. Yeah. Absolutely. Alright. Let's quickly hit the release highlights. Am I Exposed? Which is that really cool tool from the Spaniards. It's had a new update. 0.36 is now available.
It's basically a tool that scans your Bitcoin transactions. You run it all locally and it grades them basically on their privacy scores and what information can be gleaned from any given transaction.
Mhmm. This version out on the September 26 now recognizes Whirlpool t x zero transactions with fee padded premix outputs, which it previously missed or graded incorrectly. It also detects Wasabi version 1.0 coin joins.
It also flags input side address reuse, spending several received from one reuse address as a leak, whereas before it would have called that good. And yeah. So just some general improvements there, especially with the Whirlpool stuff, which is cool as well.
Yeah. Next up on the list, a project I didn't know was still being maintained. Oh, wow. Yeah. Yeah. Is the web interface that is built on top of join market. It's got version two point o, It's now out in beta.
On the September 24, it adds sign message, lets you freeze or unfreeze several coins at once. Sweeps now pin the exact coin shown, and they list them in a confirmed dialogue so that sweeps spend exactly the coins you saw,
which obviously matters when you're keeping your coins apart on purpose. It's particularly important after you coin join. Fidelity coins stay pinned when creating, renewing or unlocking bonds and payment links with unsupported parameters are now rejected instead of half followed.
New release to a new wallet that I've not heard of before. I'm gonna let you try and pronounce this one, Mark. You should be able to see it on screen. Here we go. Shark Theo 8.1. Why why are people why are Bitcoin is so bad at name and stuff? Like like, shark wallet would sound pretty cool, but why call it shark with two h's? Like,
did you slip on the keyboard or what like, what's the It's a bit like I don't know. Shart. Like shart. You'd have a Yeah. Not a shart but it's actually my wallet. Sharted. Yes. Yeah. Yeah. Yeah. Well, shark is a self custody wallet for the ARC protocol.
Maybe that's where they want to. Is it like s h, like some sort of s s h cool Oh, no. I get it now. Now I feel like a fucking idiot. Okay. Good. Now I feel like an idiot. Okay. You got me, whoever it is that made this wallet. So it's for the it's a privacy and self custody wallet for the ARC protocol. So it's Ah.
Okay. ARC. Okay. We'll let them know this is really good. I don't wanna walk it back too far. Like, if you have to explain your name, then it's probably not a good name. Yeah. But it's so niche.
It's like people who are gonna use I haven't even read the spec, but it's like, this is gonna be fucking niche, isn't it? So I think when you're using it, you'd go, oh, yeah. That's that's clever. I like that. Yeah. So this is a new wallet. It's it's a preview version 0.81 preview point five. Again, what a catchy name. Which came out
a couple of weeks ago. Dropped on my radar this week. Adds optional pay join v two. Arc and bar. You can oh, that's on Signet to be clear. Told you it was a preview. It also includes boarding straight into Arc from a pay join. It runs over TOR only, fails close so that if TOR breaks, the wallet stops loading instead of leaking your IP.
It also supports silent payments and experimental post quantum message signing. So basically this is a web interface wallet that lives on top of the ARC network, specifically the bark protocol.
Fucking hell. Some confusing shit in there but it seems pretty cool and pretty promising. Well, also, I like the fact that let me bring it up. They are hosting their own GitLab, which I thought was pretty based. They're not on GitHub, so just chat out to you whoever you are. P I hiker.
Thank you.
Right. That's the list. Zeus thirteen point two point two is now available as of the twenty third third of September. It embeds new LND versions. It adds SAT routing, which is now the default. It adds coinOS or coinOS as a swap provider and also includes critical fixes for iOS and which is related to how the wallet stores
data in the iCloud key chain. So an important update if you are a Zeus runner. All the fixes include revealing your seed words requires you to authenticate again. The duress pin, I didn't even know it had, now wipes everything.
Pretty cool. And the payment string swapped after you review it can no longer be paid. Pretty cool. Blockstream Green version or Blockstream Green Android version 5.7, they've now added manual coin selection filters, transaction notes, and a price chart. Who doesn't love a price chart?
And it brings back creating two of two and two of three multisig accounts. Pretty big big release. Seems to be Android only though. I'm not sure on the iOS update. Next on the list, big fan of this one. We we talked about the the beta release a couple of shows ago. Umbrella OS version two is now out as a main release.
And they also have a new mobile application to go with as well, which is exquisite. I tweeted about that this morning. You can have auto photo sync from your iPhone or from your Mac, which is very useful. I turned it on last night.
And there's a whole host of other features that come along as part of two point o, including virtual machines, GPU acceleration, faster loading, automatic https, redesigned app store, NCP service for your AI agents, and much, much more. Very, very big fan of that project
or company. Yeah. Yeah. They do well. Very well. At least we talked about it last week, didn't we? Were we were looking at their design. Yeah. Yeah. Did a great job. And the the iOS app, I can't sing enough praise about it. Very simple, but it just gets the job done. Great layout. You can tell they've got some good designers there.
Next on the list, Sina OS version 1.3 has been released. This is a new one on my radar. Version 1.3 sorry, let me take a step back. Sina OS is a minimal live Linux system, think Tails. You can boot any PC from a USB stick with it and the machine basically becomes a
I don't wanna use the term air gap to which is what my AI generated notes say, but I guess it could be if your laptop is offline. But you can plug it in a la Tails and do bitcoin shit with it.
Version 1.3 which came out on the September 23 has some bug fixes where transactions with several inputs could break or make fake change outputs look legitimate. Multisig change address verification improvements and much much more.
This is a young project from, I believe, a single developer which only started a couple of months or one month ago in August. It's had very little independent review so far. So please treat it as a playground not to be used with your real funds, but pretty cool nonetheless. So like to see people building.
It's meant to be a signing device of sorts, basically. Indeed. But I absolutely would not use it with any real funds just yet. Yeah. Yeah. But so it's it's not like a a replacement for tails and like a or an ephemeral sort of thing. It's it's really is being built as like a signing device, and that's it.
Yes. I mean, it's similar to Tails in the sense that I I believe it is ephemeral, and it runs on a USB stick, so you can plug it into any laptop and boot from it. But is this a replacement for, a Passport Prime or a BitBox? Absolutely not, in my opinion. Not until it's had much more time in the market and independent review.
Yep. Okay. Last on the list, Blockstream Green desktop version 3.6 came out on the September 21, which adds paying to lightning addresses. It adds LNURL pay from the send screen, redesigned coin selection, configurable Electrum gap limit, and brings back as with the mobile app creation of two of two and two of three multi sig accounts.
There we go. That's the end of our list. Just in time because my bladder is about to pop. Just wanna Getting old. Yeah. Certainly am. Just wanna bookend the show by reminding you to head to freesamurai.
Now Yep. To get involved with the draw and support the samurai crew. Oh, look. 20,000 more stats. Yeah. That just ticked up as I loaded the page. You've got three days to do it. This show will be coming out in just a few hours, so no excuses that you heard the podcast late.
If you're getting your forty hours per week, you should be hearing this in time, so go and get involved. Yeah. Definitely do.
Alright. Thanks everyone. I've just I've I've just seen a comment from John, and I'll let you sign this off. Because I'm just gonna quickly run to the bathroom while you talk about what John wants us to talk about, which is the new show on the feed.
Yeah. Okay. I will. Please mention our new show, what do you reckon? Hi, John. Me and John have a new show called what do you reckon? And we had episode one, MK Ungovernable go out, maybe it was a week ago now. Was it last Wednesday?
And it is a show where me and John have our discussions that we'd normally have off air on air, we talk about all the weird and wonderful things, whether it is as our first one is mind control and the history of mind control and MK Ultra and the Manson family and all those sort of crazy but real life other than
other than you could even make up. And we're also gonna be covering some other topics that I actually I won't disclose yet, but some conspiracy stuff, some survival stuff, some anti medical establishment stuff, and
all the sorts of things that we talk about in the and behind closed doors. So it's it's not a freedom tech show specifically, but I think a lot of the topics that we're gonna be covering will help you and your family be more free.
So go and check us out. It's in my podcast queue for my next long dog walk because it is a longer show, but very excited to to hear John's dulcet tones once again. Yeah.
Right. Let's wrap this baby up. Thank you all for joining us. Thank you for your boost. And, yeah, we will catch you on Friday for Freedom Tech Friday. Have a good week everybody. Yeah. Stay ungovernable.
Machine transcript; expect the odd mishearing. Click a passage to play from there.




