
KYC: KILL YOUR CUSTOMER
Discussed in this episode
Boost this Episode
Send sats directly to the creators. Value for Value.
Plus 1% to Podcast Index, 1% to Boost Bot.
Show Notes
A weekly news show informing you on the latest in Bitcoin, privacy and open source tech, hosted by Ungovernables, Max and Q.
AOB
Max: spent a full day and roughly $100 in API credits on a marketing project using lower-end models rather than his normal Claude subscription -- couldn't use it due to privacy concerns around Ungovernable content; a warning that frontier model quality costs real money per token
Q: quiet weekend -- kids party Saturday, christening Sunday; off to Portugal on Friday
NEWS
Revolut hands passports and Bitcoin histories to a spoofed government request: attackers used a real government agency's email domain to extract passport scans, verification selfies, home addresses, and full transaction histories including Bitcoin activity; Revolut refuses to confirm the number of affected customers, the market, or the agency involved; attacker is now leaking customer files daily on Telegram and demanding 10,000 BTC -- CoinDesk, TechCrunch, Decrypt
Liquid exploit recovery: 3,400 BTC returned to block 965950 on September 7 via on-chain OP_RETURN negotiation; ~598.5 BTC (~$47M) remains with the exploiters; Blockstream refused the demanded 10% bounty, called it theft, and says it will work with law enforcement; block production resumed September 10 but peg operations remain suspended -- Bitcoin Magazine, news.bitcoin.com, CoinDesk, The Bitcoin Manual
Final CLARITY Act text drops: ethics deal done, developer protections narrowed; the Blockchain Regulatory Certainty Act now covers civil enforcement only with criminal protections removed -- including the charge brought against the Samourai developers; cloture vote is September 15 at 2:15pm ET, needs 60 votes; prediction markets put passage at ~25% -- The Crypto Times, The Block, The Hill, CoinDesk
Chinese quantum benchmark drops secp256k1 attack to 835 logical qubits, down 60% from the 2020 estimate of 2,124; current best hardware reaches 94 logical qubits; addresses with exposed public keys face the greatest future risk -- TFTC, CoinDesk
Alby Hub authentication bypass lets attackers drain Lightning wallets: critical flaw in v1.7.0 through v1.18.5 allows unauthenticated remote takeover when port 8080 is internet-accessible; at least one user confirmed compromised; update to v1.24.0 and block external access to port 8080 -- The Hacker News
Brevo breach lets attackers send phishing from Trezor, BitBox, and CoinTracking domains: attackers created API keys inside Brevo customer accounts allowing emails from real sending domains that passed SPF, DKIM, and DMARC; the lure was a fake STM32 Entropy Vulnerability alert targeting hardware wallet owners; Trezor and BitBox both confirmed the breach on September 9 -- CryptoTimes, Decrypt
RELEASES
Highlights
Electrs v0.12.0 -- 2026-09-13
- Switches to the bindex indexing library. Requires Bitcoin Core 31 or later and a full reindex -- upgrade Core first and plan for downtime, especially on lower-powered hardware.
Fedimint v0.12.1 -- 2026-09-12
- Security release fixing a vulnerability in the Lightning gateway's LNv1 payment handling. Gateway operators should upgrade immediately. The fix is consensus-neutral so federation participants and wallet users do not need to coordinate an upgrade.
Radar v1.0.7 -- 2026-09-12
- Adds BOLT11 invoice payments alongside lightning addresses, scan-to-pay from the send screen, on-chain receive via bitcoin: URI, full balance hiding across the app, and Signal backup migration on a single device.
Bitcoin Seed Tool v2.4.0 -- 2026-09-11
- Adds SeedQR scanning, Seed XOR splitting into 2-8 Coldcard-compatible shares, NIP-06 Nostr key derivation, BIP-44/49/84/86 descriptor export, and blank backup template printing. Also fixes seed leakage bugs -- existing users should update before use.
Phoenix v2.8.2 -- 2026-09-08 (Android), 2026-09-07 (iOS)
- Adds Italian, Japanese, Polish, Ukrainian, and Korean language support. Android users can now manually set feerates on outgoing on-chain transactions, matching iOS parity.
BTCPay Server v2.4.4 -- 2026-09-08
- Breaking-change release: NFC payments disabled by default at checkout, zero-amount invoices blocked by default, and Boltcard desktop setup removed in favour of the dedicated Boltcard app. Review the breaking changes before upgrading.
Ashigaru Desktop v1.4.5 -- 2026-09-07
- Major catch-up release. Fixes broken HTTPS connectivity in earlier builds (missing crypto modules broke all outbound connections). Adds in-app update checking with signature verification, a guided tour, dice-based passphrases, and stronger Dojo node verification. Existing users on older versions must download manually.
Flint v1.1.0 -- 2026-09-07
- Updates compatibility to BTCPay Server 2.4.4 and enforces Breez SDK Spark release gating. Upgrade alongside BTCPay 2.4.4. All artifacts signed with Sigstore build provenance.
Everything else
Amethyst v1.15.2 -- 2026-09-12
BasicSwap DEX v0.18.8 -- 2026-09-13
BasicSwap DEX v0.18.7 -- 2026-09-10
BDK FFI v3.1.0 -- 2026-09-12
Citrine v3.1.1 -- 2026-09-10
Core Lightning v26.06.7 -- 2026-09-11
Fedimint v0.11.3 -- 2026-09-12
JoinMarket-NG v0.39.2 -- 2026-09-12
LDK v0.2.6 -- 2026-09-10
LNbits v1.6.1 -- 2026-09-09
ngit-cli v3.0.0 -- 2026-09-08
Ride The Lightning v0.15.12 -- 2026-09-09
RoboSats v0.8.7-alpha -- 2026-09-10
Tor Browser 15.0.22 -- 2026-09-10
Trezor Suite 26.9.1 -- 2026-09-11
TO DONATE TO ROMAN'S DEFENSE FUND: https://freeromanstorm.com/donate
HELP GET SAMOURAI A PARDON
- SIGN THE PETITION ----> https://www.change.org/p/stand-up-for-freedom-pardon-the-innocent-coders-jailed-for-building-privacy-tools
- DONATE TO THE FAMILIES w/ USD ----> https://www.givesendgo.com/billandkeonne
- DONATE TO THE FAMILIES w/ BTC ----> https://pay.zaprite.com/pl_JpxtkLv95T
- SUPPORT ON SOCIAL MEDIA ---> https://billandkeonne.org/
VALUE FOR VALUE
Thanks for listening you Ungovernable Misfits, we appreciate your continued support and hope you enjoy the shows.
You can support this episode using your time, talent or treasure.
TIME:
- create fountain clips for the show
- create a meetup
- help boost the signal on social media
TALENT:
- create ungovernable misfit inspired art, animation or music
- design or implement some software that can make the podcast better
- use whatever talents you have to make a contribution to the show!
TREASURE:
- BOOST IT OR STREAM SATS on the Podcasting 2.0 apps @ https://podcastapps.com
- DONATE via Monero @ https://xmrchat.com/ungovernable
- BUY SOME STICKERS @ https://ungovernable.network/shop/
FOUNDATION
https://foundation.xyz/ungovernable
Foundation builds Bitcoin-centric tools that empower you to reclaim your digital sovereignty.
As a sovereign computing company, Foundation is the antithesis of today’s tech conglomerates. Returning to cypherpunk principles, they build open source technology that “can’t be evil”.
Thank you Foundation Devices for sponsoring the show!
Use code: Ungovernable for $10 off of your purchase
CAKE WALLET
Cake Wallet is an open-source, non-custodial wallet available on Android, iOS, macOS, and Linux.
Features:
- Built-in Exchange: Swap easily between Bitcoin and Monero.
- User-Friendly: Simple interface for all users.
Monero Users:
- Batch Transactions: Send multiple payments at once.
- Faster Syncing: Optimized syncing via specified restore heights
- Proxy Support: Enhance privacy with proxy node options.
Bitcoin Users:
- Coin Control: Manage your transactions effectively.
- Silent Payments: Static bitcoin addresses
- Batch Transactions: Streamline your payment process.
Thank you Cake Wallet for sponsoring the show!
MYNYMBOX
Your go-to for anonymous server hosting solutions, featuring: virtual private & dedicated servers, domain registration and DNS parking. We don't require any of your personal information, and you can purchase using Bitcoin, Lightning, Monero and many other cryptos.
Explore benefits such as No KYC, complete privacy & security, and human support.
(00:00:00) INTRO
(00:00:41) THANK YOU FOUNDATION
(00:01:29) THANK YOU CAKE WALLET
(00:03:50) The Privacy Tax
(00:12:08) Kids Parties and Christenings
(00:15:56) NEWS
(00:16:14) KYC: Kill Your Customer
(00:28:00) MORE NEWS
(00:52:42) BOOSTS
(01:02:36) UPDATES & RELEASES
Bitcoin is close to becoming worthless.
Now what's the Bitcoin? Bitcoin's like rat poison. Yeah. Oh. The greatest scam in history. Let's get it. Bitcoin will go to fucking zero.
Welcome back to the Bitcoin Brief, the show where me and q and a talk about Bitcoin, privacy, open source, keeping your Bitcoin secure, and the news and software updates that matter. I just wanted to say a mass thank you to everyone who's been supporting Ungovernable Misfits, and a big thank you to Foundation
for supporting the show. If you haven't already checked them out, go to foundation.xyzed. They make cypherpunk tools for fuckwits,
and anyone can use this, even me. If you have any questions or you want to reach out, feel free, and I'll be happy to go through things with you. For anything super technical, I'll pass you on to q. If you wanna buy one of these incredible passports, use the code ungovernable.
It will get you a discount, and it will let them know that I'm shilling. I'd also like to say a huge thank you to the Cake Wallet team. Not only are they supporting this show, but they're also bringing out some incredible features.
For those of you who actually use Bitcoin and actually care about their privacy and security, Cake Wallet make it incredibly simple for you to live outside of the traditional financial system.
You can use CakePay within the app to buy gift cards for food, petrol, and whatever else you might need day to day. You can use silent payments, and, of course, you can use Monero. You can connect both Bitcoin and Monero nodes, use coin control, and this team are constantly innovating.
And I'm really excited to be working with them. If you have any questions, you can reach out to me, but check them out at cakewallet.com. Download the APK or start using this today on Mac, Windows, Linux, iPhone, or, of course, your Android device.
Enjoy the show.
Hello. Happy Monday, and welcome back to The Bitcoin Brief, a live and interactive show taking place every Monday at 9AM eastern, 2PM UK time across the Ungovernable Network. Each week, we go through the news, the releases, and the developments that actually matter in Bitcoin.
This, of course, includes self custody, privacy, the tools you run yourself, and the people that are trying to make all of that harder. If it affects your ability to hold and spend your own money without see asking permission, then we wanna talk about it.
This show and the topics that we cover are powered by freedom.tech, a daily news desk news desk that allows, wow, that uses AI to monitor hundreds of sources so that we can continue to bring you the signal every single week. It's it's Monday. Go easy on me, Max. We'd love to have you I will never will never pull you up on your reading.
We would love to have you help stay the conversation by commenting live, asking questions, boosting the show, or just sharing it with your friends. My name's Q and A. I'm head of customer experience at Foundation. And as always, I am joined by my girlfriend Max, the head honcho of the ungovernable network.
Without further ado, I'm gonna have another sip of coffee. Welcome Max to the show. How the devil are you, sir? Very well, mate. Very well. I have two stories for you today. You always ask me what's Nice. What I've got for you. And and it's what is it called where you watch a show and it's like choose is it choose your adventure?
Or you know, they did it in that, like, sci fi show, Black Mirror, and it was like, there was a certain one what's it called? Choose your adventure. Yeah. Choose your journey. Choose your adventure. I know what you mean. Yeah. Choose your journey. So I'm gonna give you a choose your journey.
You can either have a story about FreedomTech over my weekend Okay. Or you can have a story about more manual labor, typical max. Well, obviously, I'm I'm gonna go for the FreedomTech one. You're gonna go for the Freedom Tech one? Yep.
So my my it's not really a story, but an insight into what it's like using AI without using the top models or expensive hardware. And just a warning to anyone or maybe how I was using it, but I spent a full day and about a $100 of credits
to do something that I could have done with Claude in, I would say, half an hour. I had to bribe my missus out of the door with clothes. I'll get you vouchers so you can go and buy some new clothes. I I Kids with ice cream,
pay them so I didn't have to go to this kid's birthday party I was supposed to, which actually was quite nice, house and peace, and sit for an entire day doing work on Nano GPT and just endlessly feeding it credits for quite a simple task. So not really a story. It's more just a warning to people where I bang on about
just use, you know, these systems. And I think I've said some very positive things about nano, especially with the image gen and stuff like that. I don't wanna take away from that, but if you are using the top models, if you are using, like, Fable five and that kind of stuff, Fuck me. It was, it was brutal.
I have questions, and I don't know how much you could share about any of this. So just, obviously, share what you're comfortable with. But, like Yeah. What were you doing? What models were you using? Why weren't you using Claude?
Or yeah. You may have been using Claude. I don't know. But but yeah. Can give us a bit of Didn't use my normal Claude subscription that I would use for Normie Life, Normie World, or GPT because it was sensitive information, and it was around ungovernable stuff. And I don't like to link my identity across two things.
So even though I have the subscription, even though I could very quickly do what I wanted to do in those, it would be feeding it sensitive information, and I don't trust them. And I think that's probably a reasonable assumption.
So that's the why. I was doing very simple, like, marketing style stuff, creating high end PDFs, working with, like, HTML and things that people can open and, like, marketing stuff mainly.
Bit of, like, creating charts here and there and that kind of stuff. And, yeah, like I say, if I'd have done it in Claude, probably half an hour. But I used I started with lower end models, just had a fucking nightmare. They just couldn't do what I wanted them to do. I'd give them a really good brief.
They'd spit out some absolute dog shit that I could have done off very easily. Then I'd I'd say, right. Can we make these changes? As I've said, I want a high quality PDF, his his images to replicate, blah blah blah. Then it kept doing, like, spazzy stuff. Like, there was a lot of text, but it was trying to generate images
rather than actually have the text separate. So that was just, like, again, fucking stupid. And then I just kept scaling up what models I was using, and they were getting smarter. So I went across GBT.
They got a bit smarter. Then I went across to a higher model on GBT. They got bit smarter. And then I was like, this is still not working and went across to Claude Fable five. And, eventually that was doing it. But it was, like, I think it was, like, $4.80 or $5 per prompt.
And so when you're doing yeah. So when you're do you know, you think, like, a subscription is, like, $90, whatever it is. Mhmm.
You know, I'd ask it to do a thing. It would come back, and then I'd be like, right. You know, here, you've got the charts going over the top of this text. You need to have more of a gap. Like, simple basic stuff where it's just not not fucking done its job properly.
And every time you do that, that's another $4.80. That's another $5. Oh, yeah. I can see there's a fucking class this error. That was supposed to be in this container. Oh, yes. Well done. And I'm like, yeah. Fucking well done. It's $5, mate. And then it would do it again.
And that, you know, like, often has a knock on effect. You change one thing, it fucks something else up. So Yep. You know, after, like, 20 little changes where I was like, ugh, I ended up just leaving it as, like, a document that was 98%
there. Like, not perfect, but I would normally have, like, perfected it. I just thought, I'm not throwing another fifty, sixty dollars at this. So not really a story. Just more of a warning. Like, if you are looking to do stuff with AI and you're used to a certain level of quality,
just understand that it can be extremely expensive if you are using these top models. Not saying it's not useful. It was very useful, but just either have deep pockets or find another way around.
Also, just to play devil's advocate here, and I don't know whether this is fact or not. I'm sure there's probably some truth in it. They're probably
I have no idea what you were actually asking the agent. But, like Yeah. Yeah. Yeah. Yeah. There there's probably some scope for improvement in how you articulate what what you wanted to get to elicit the results that you wanted sooner and and and for fewer less cost.
I'd be I'd be prepared to say that someone could have done it for at least half the cost if they were if they were very skilled and they were very clear about. But I like to iterate. It's just kind of how I do, you know, try this. Maybe just change that. It's just how I work. So,
yeah, it it probably could have been done for half the price, but you're still talking about $50. It's still, like, almost your whole month subscription on something that would probably take, I don't know, twenty minutes. Yeah. So, just yeah. That's the other side of the coin.
Freedom isn't free. Yeah. Absolutely. There's there's loads of things I could dive into there. Obviously, running stuff locally. Mhmm. You know, the the the the the subsidies of the the big two or big three, I guess.
You know, they they are currently worth their weight in goal to get especially if you don't know specifically what you want or you're less technical and you don't know how to articulate properly. Being able to lean on the intelligence of the of the frontier models can easily bridge that gap. Whereas if you go to the,
you know, the even the middle or or to the lower tiers, like, you've gotta be very clear and very concise and know exactly what you want. Otherwise, you just end up going around in loops. Like like, you sounds like you've Oh, yeah. Kinda gone through. So Oh, yes. Oh, yes. So, anyway, that's that's your choo choo journey there, mate.
What about you? What's what's happened over your weekend? There's no news, is there? I mean, I don't know why we've gone to weekly. There's no there's no Bitcoin news. Yeah. Nothing to talk about. Yeah.
Not a lot to talk about for my weekend, really. Very quiet. I very boring, to be honest with you. I had a kids party on Saturday and
which was absolutely fucking hell on earth. Just loads and loads of, like like, five to seven year olds just running around screaming, all females as well. Oh, god. Thank god I don't drink, and I wasn't hungover. Yeah.
And then on Sunday, I went to a christening, which is also makes me wanna gouge my own eyes out. Yeah. What would I I I would go christening over you lost?
Uh-oh. I think we lost him, ladies and gents.
Max, what did you I haven't I've done Oh, you're back. You're back. You're back. Okay. Sorry. I don't know what happened there. You you were saying I I think I choose christening. Yeah. I would choose christening. At least, like,
it's it's a little bit more civilized. It's probably slightly less screeching and that kind of stuff. And, like, when you're in the church, you could you could sort of close your eyes and have, like, a moment of peace while the hymns are going on and that kind of stuff. Yeah. No hymns, funny enough. Was quite surprised.
Okay. Alright. Fair enough. No hymns. Just just a a sermon or whatever you call it. Yeah. Sorry for those religious people. I'm I'm I'm absolutely not on that boat. But, yeah, it nice. I think it is a sermon. It's a sermon. There's something to be said. Like, I'm not religious either.
I've maybe got a little bit more religious or, like, open to the idea recently, but
I could something quite nice about a church. Like Oh, yeah. I like I like being inside and looking at the architecture, especially if get a nice one. Yeah. Like, the the, you know, the the to to tie it to Bitcoin, I guess, the proof of work that's gone in internally to make it look that good. Like, you just don't get that shit anymore, do
You don't. And and for the most part, people who go to the churches and stuff, like, tend to be kind of alright. Like, you can you're gonna normally meet a nicer person in a church than you are, like, on the streets in a major city kind of thing. Do you know what I mean? You just you so it's not a bad place to be. I
did have a little chuckle to myself, actually. The it was a female vicar. I don't know whether they have a name or whether it's just you're a vicar whether whether you've got a cock or not. A vicarette? A vicarious? No. It is a vicar.
Because remember the the show Vicar of Dibley, she was a Of course. She was a senior. Storm French classic. Yeah. Yeah. I had to laugh. She was obviously in all the get up. She had like the the white collar thing gone and she looked very prim and proper.
And she if you walk past her industry, you'd be like, yeah, you're you're in the god squad. Yeah. And she was up on stood up on the stand lectern thing. And then when she got down, like, obviously, a a long gown, like, lifted up a bit for her to step.
And she had a pair of Air Force ones on. I just
That's class. I like that. You know, you just expect somebody like that to have, like, I don't know, like, black, like Yeah. Pumps on or something. But nope. No. Massive, white, clean, crisp Air Force ones.
I like it. So, yeah, boring weekend. Just general family stuff. Nice four days of work this week, and then I'm off on Friday. I'm headed over to Portugal to see a friend for the weekend. Very
nice. I think I might know who that who that friend is. So say hi. I don't think you do, but okay. I think do. Okay. Okay. Nice. Say hi. Even if I don't know him, just to be creepy, just say, Max, who you don't know. Yeah. I've got this friend on the Internet, and, he says hi.
Yeah. Shall shall we dive into the show, mate? Yes. Let's do it. No surprise. We're starting with some doom. Revolut, they have had quite a big hack in the last couple of days. For those of you that don't know, Revolut is a UK based kind of neo bank fintech company that has
over, like, 80,000,000 customers now, and they also serve a large bit slash crypto user base as well. You can buy and sell and all that good stuff. On September 11, they Revolut started emailing customers to tell them that their data had gone to an unauthorized third party.
And no surprises, Zach xbt on Twitter was all over this. He made the email public, I believe, in one of his Telegram groups. Basically, somebody had used an email account tied to a real government agency domain to send information requests to Revolut.
Revolut treated them in genuine as genuine and sent over the files, basically, dot That's fine. A lot of their customers. Oh, yeah. By the way, for those of you that don't listen to Freedom Debt Friday, Max has a new toy. He's got a sound board, so you'll hear some audible interludes throughout the shows.
And hopefully, lots of them will make you laugh. That's more relevant than people might realize because a while ago, we talked about Peter McCormack and saying, like, every single sponsor he's ever had has rubbed his cut his listeners.
And I was thinking about it the other day, and I was like, it's not every single one. There was a couple that hadn't actually rubbed them. And one of them was Revolut. But Okay. Now So okay. That's fine.
Well, this isn't the first time Revolut have had a had a hack, but this is apparently quite quite a bit worse. So according to the email, the exposed data covers get wait. Get ready for this. A copy of your passport or driving license plus a verification selfie of you holding said document,
your full name, your date of birth, your occupation, your home address, your email, and your phone number, your iBan account details, your account statements, withdrawal records, full transaction history, including Bitcoin.
Yeah. Let that fucking sink in. That is absolutely just leave me lost for words. It is. On September 12, Revolut confirmed to Tech Crunch that, quote, a limited number of customers, systems, and funds are unaffected.
It will not say how many people, which country, or whose domain was used. On September 13, the attacker started publishing the data on Telegram beginning with well known customers. The first being a tennis player Alexander Shevchenko and Felix Romer, who is CEO of the crypto casino
Gamedom, which I've never heard of. And they say that they're gonna continue releasing more every day until Revolut pays, and I believe they're demanding something to the tune of, like, 10,000 Bitcoin.
Revolut won't pay. Revolut won't pay. I'm actually a Revolut customer, albeit I don't use them very much, and I've never used them for anything relating to Bitcoin. And Revolut are the the like, this super ironic thing about all of this, they are the most hyper compliant bank that I've ever had dealings with. They will send me,
like, at least once a year. I've been a customer of theirs for a number of years. At least once a year, they'll say, we need to reverify your documentation.
So it's not enough it's not enough that you do it once. It's the fact that if you wanna continue using their bank and being a customer of their bank, they kind of check-in every now and again and go, hey.
Send us a selfie or send us you know, is your driving license changed? Like, we need to save all of that. And, yeah, now they're just giving it away to people presenting to be the government.
Yeah. I can confirm they are hypervigilant the other way around. They closed me down after a big battle because I actually sold a property, and I contacted them because they're bit cunty anyway. And I was like, look.
Selling a property, there's gonna be some funds hitting my account just so that we don't have the issues that we always have. Here's the details of the solicitor. Here's the details of the sale.
Here's the amount that's gonna be coming through. You know, basically, like, don't fucking take my funds. Mhmm. So I did all of that, and then sale goes through after fucking months of cuntiness, and then the money gets frozen. And it took me
six weeks to get it back with all the documentation I'd already sent them and everything. I was like, I've fucking told you this is gonna happen. You've got all the information. They're like, nah. It's suspicious.
They're absolute twats. But that goes and and, you know, I don't wanna single out Revolut. They're all absolute twats. They all ask. They all they all have to ask you, especially in The UK.
Reverify what's your tax residency. Reverify what's your fucking occupation. Reverify where you live. Rever and they have to do all this bullshit. And, you know, every year, there's just more and more and more. Over back in the day, like, you could have a bank account, and you'd open it. You go into a, like, high street bank account.
Yep. You'd open it, and then you'd have it. And then, like, let's say a family member is like, oh, I'm gonna send you some birthday money. You know? You just turned 18 or whatever. You're like, oh, thanks. And then it would hit your account, and you'd have it. And there would be no I I would never be like, fuck.
This is gonna be a problem. But now, like, if anyone even suggests sending me money or I have to send them money or even that money has to, like, be in my account for any amount of time because it's gotta come out and pay something else, I get really fucking concerned.
Mhmm. It's and then you compare that to, like, Bitcoin. I mean, yeah, we've had Yeah. Have had some problems recently, but, like, I know if I send if if I, like, owe someone money and I'm like, oh, I'm gonna send it to you,
I know they're gonna get it, and I have no like, other than all, let's just check the end of the thing and the front thing and make sure I actually send it to right address. Other than that, it's like, oh, that's done.
So, yeah, there's a reason we're here. Yeah. Absolutely. It's drives home again. Just the age old reminders of why we Bitcoin and why we limit KYC wherever we can. Obviously, you know, this is slightly different. It's a bank. Like, you you would get a bank account without KYC in these days,
it's just about limiting, I guess, limiting the your exposure and your risk. I don't think they're gonna pay this, obviously, because I'm sure they probably haven't got 10,000 Bitcoin.
But, yeah, I I mean, this was the impetus for the the name of today's show, KYC kill your customer. Like, this is literally putting people in harm's way. Attackers have already got literally all of your personal information.
They'll see your Bitcoin withdrawals, and they'll go, he lives down the road from me. I'm gonna go and get a very big $10 wrench and cave his head in and ask him to or threaten to cave his head in and give him give me his Bitcoin.
Like, it's it's the the this these types of regulations do literally just fuck people's lives up. We we actually talked about this last week.
We had a bit because we we we always putting the clips together, and we had a bit where we're talking about as kill it kills your customer, and we were talking about this last week. And then the next week rolls around and another one. And this one's actually, for me, quite a bad one because I know a few friends and family who
listen to me about Bitcoin, but wouldn't listen to me about, like, self custody or any of that kind of stuff. And a few of them did buy on Revolut. Really? They're not poor individuals. Like, they're relatively well off. So I am a bit worried. I am a bit like, you know, the problem is
you can't I can't even call them and be like, because they won't see this. Mhmm. You know, Revolut is not gonna write to them. And even if they did, they'd be like, oh, yeah. A data breach. That'd be fine. Whatever. Like, I can't recall them and go, hey. Listen.
Just sleep with an axe under your pillow. Maybe get a guard dog. You know, think about your security, make sure you lock your doors. I can't I can't do that because, a, it's just gonna shit them up, and, b, I don't know because they're not gonna release, like, a list. They're not even gonna contact the individual and say, hey. Listen.
You know all that personal information that you have, like, saying that you own this amount of Bitcoin and all the rest of it, that would be really fucking dangerous for someone to know because they could knock on your door and come and steal it. Yeah. We we just gave it to, like, a bunch of criminals. They're not even gonna do that.
It's No. It it's fucked. People will I I guarantee you, people will die from this. Yeah. That and that sound really hyperbolic, but, like, you're you're not wrong. Fact. Fact. Yeah. And and and, yeah, people will die, and then many, many more people will have horrible experiences.
You're either gonna see on your security cameras, there's people outside with knives. Maybe you don't let them in, but, you know, they're they're out there. Or you get harassed on the phone every day or any number of other things that just make everyone's life more miserable, more scary, less assured, and all of this is for your safety.
And we bang on about KYC, and we bang on about all this stuff and have done for many, many years. But this is just like I feel like recent years are more and more highlighting that we're not wrong.
We're treated like criminals for trying to protect ourselves and our families, but we're not fucking wrong. No. Absolutely. It's it's not sexy to talk about. It's probably doesn't gain as much views, but, like No. It doesn't.
Yeah. It's one of those things. It's which we'll keep beating the drum, and I'm sure this will keep rolling over. They'll be a little fine. They'll be, like, 1% of their revenue, and everybody will memory hole it, and we'll be back again next week to talk about the same shit.
Unfortunately, yes. Saying that, though, it it's not sexy, and it's it's not what people, like, click. It's not like, oh, Bitcoin's going to a million. Well, analysts, da da da. We're not doing that kind of stuff. But our numbers recently Oh, yeah. The amount of you who are tuning in and listening and participating
it's not just listening. It's participating as well. Like, even on fountain, suddenly, we got, like, a 100 more people boosting, like, boosters, not just listeners, like, in the last, I don't know, few weeks.
Yeah. And and just, you know, people sharing and keep getting messages and recommendations and things like that. So thank you to everyone. I really, really appreciate it. It's it's the way we get found. It's just commenting and and, you know, you see you always see, like, the Bitcoin podcast
industry is just fucked. Like, it's just it's just a nonsense kind of thing. And then we quite often get, like, a little message underneath. Oh, we checked out Uncoverable. And then so I'll check that out. And that's I love seeing that and just new people joining. So welcome.
Definitely. Alright. Next news item, which is a follow on from last week's headline, the liquid hack where 4,000 Bitcoin were stolen from the Bitcoin network due to a vulnerability. Quick recap. That one.
Just in case you missed last week's show, Liquid is Blockstream's Bitcoin side chain. You send Bitcoin to a federation of 15 functionaries functionaries who lock it in reserve and issue you an equivalent Liquid Bitcoin on the Liquid network. It's a one to one peg.
On liquid, you have various benefits like fast transactions, confidential transactions, and getting back to real Bitcoin is a peg out where the members of the federation kind of authorize that on a kind of eleven and fifteen basis.
On the September 6 after a quick 2.5, I say quick dry run, the attackers used used the the vulnerability to which we went into detail on on the last show. I'm not gonna rehash it. To create 4,000 liquid Bitcoin, which is basically the whole volume on the entire network.
Backed by nothing, and they pushed it through sideswap's peg out. Sideswap processed it, and they got 4,000 Bitcoin on chain, basically draining the entire liquid network. The the functionaries functionaries on the network, they found this as a valid request and released the 3,996 Bitcoin,
leaving around a 197 Bitcoin left in reserve on the network. There was no keys compromised. The federation did exactly what it was built to do, and they they moved the coins that should bought. Excuse me. They moved the coins that should never have existed due to the vulnerability.
There was various messages being passed back and forth via op return, which I thought was quite cool. Maybe not given the circumstances, but basically, the hacker posted an opt return on on the Bitcoin network into a transaction saying, we are white hacks.
Contact us on chain. And then various messages were passed back and forth. They moved to encrypted messages so that people, you know, on lockers couldn't see. And I can't remember where we left it off last last week. But, anyway, eventually go on.
We left it with a bet, but not for any money because we're both skin. We left it that I said I think they won't give the money back. That's right. You said you thought that they would. And I think we're kind of both wrong and both right at the same time given the way that it's played out.
Yeah. So there's a clear winner. Yeah. Okay. Well, I'll let the listeners judge that. I'd say I'm more right than you for reasons
I'm about to state. So just as recap, 3,996 Bitcoin were stolen. Mhmm. On September 7, the attackers returned 3,400 of those Bitcoin back in Block Number 965950. They kept 598.5 Bitcoin, which is roughly $50,000,000.
And in a later on yeah. In a later on chain messages, they they call Blockstream, quote, delusional, greedy, and arrogant, demanded it pay a 10% bounty from its own money or, quote, cause all your holders a 15% loss. Basically, they're gonna keep the 600 bitcoin.
And then they threatened to publish their private negotiations. So basically, all of the encrypted messages that were going back and forth in these op returns. So that is the state of play. The the the attackers still have about 600 bitcoin.
They I I believe Blockstream have have publicly said yeah. They have said, quote, it will not pay a ransom. They're calling it theft, and they said they're gonna work with, excuse me, work with law enforcement to trace the coins.
Blockstream has since shipped elements version twenty three point three point four with the fix in. And on the September 10, four days ago, the liquid network restarted. And Adam Back, CEO of Blockstream, said that the liquid Bitcoin peg will be covered one to one.
I have a couple of follow-up comments, but I wanna let you come in first.
I sort of side with the theft with the criminals here, if I'm honest. Yeah. I sort of do because well, there's a few things that are going through my head. First of all, they've asked for a 10% ransom.
I don't think that's that uncommon. Like, 10% for not taking a 100% doesn't seem a completely unreasonable thing when anyone else could have taken it and taken the whole thing. I don't think that that's that unreasonable.
And then I think that the way that it's been handled by them saying, well, we're not gonna pay the 10%. If I was the attacker, I'd go, okay. Well, if you're treating me like a criminal not saying it's not criminal. It obviously is still theft and all that blah blah blah.
But if you're saying we're gonna we're gonna press charges, we're gonna try and find you, we're work with law enforcement, We're gonna come after you, and we weren't gonna pay you any sort of bounty for for doing what you've done and returning it. I wouldn't return fucking anything because you're looking over your shoulder anyway,
and, like, 50 million's lovely. It's like it's a lot of fucking money. But you could have just taken the whole lot because they're coming after you regardless, so you're better off having a a a more runway.
And I think if they were just all out, just bad actors, they would just fucking keep it all. I think Blockstream is being a bit cunty, if I'm honest. I just feel they're lucky that this lot gave back
anything at all because they didn't fix the bug. It was sat there for however long. It was they were told about it. It's not like they I'm pretty sure Blockstream have devs and, like, funds.
Like, they're not an an unfunded organization. They could have fixed it. They didn't, and someone could have taken all of it. And rather than sort of going, yeah. Cheers, love. You know? Or even negotiating, like, we're not gonna do 10%. We'll do eight or whatever. I don't know. I just feel I feel less like with them, if I'm honest.
Interesting. Okay. I I I tend to sit on the other side of this. Like, imagine you leave your front door unlocked. I walk in and see that you've got 10,000 in cash on your dining room table. I take it all, then I call you up, and then I say, got your money.
Mhmm. What are gonna do about it? Oh, alright. Do you know what? I'll give you $6 back, and I'm keeping the phone. Not $6 back, is it? Because they're taking they're asking for 10%. So you'd call me up and you go, look.
You're a silly cunt. You've left your front door unlocked and open even though someone said that a criminal could walk in. Right? Mhmm. So silly.
It's like leaving your your car open with the keys in there and parking that in any town center. How long do you think that's gonna stay there? Not very fucking long. Yeah. I've but that that doesn't give anybody the right to go and take it, though, just because It doesn't give them the right. But but it's stupid.
And so if you're gonna take personal responsibility for your life, it's something we talk about all the time in in Bitcoin land, like personal responsibility. Like, well, yeah, personal responsibility. If there's a massive code bug, whatever you call it, and it's not in a town center and it's not a car, it's 4,000 Bitcoin,
and it's other people's money, and it's your only job is to keep that safe and keep the network working. That's what you're doing. Then I would say that is your responsibility. And then if you fuck up if I did something really retarded, like, left my keys in my car and someone goes, right. I've nicked it. But listen.
Leave us a wheel and, or leave us the alloys and you have the car back. I'd be like, it's a bit fucking annoying, but Alright. I wouldn't be calling the police. I go, yeah. That's fucking stupid.
Why did I leave my front door unlocked and open? And it's not my cash. Why and then had everyone else's cash on the table and just left it unlocked. And someone said, we've nicked all of it, but, look, give us 10%.
I don't know. I don't know. Yeah. I mean, I get where you're coming from. I just don't see that that in any way makes it right. Like, yeah, Blockchain have have fucked up massively.
Yeah. Then trying to play, oh, yeah. We'll white hat hackers, and we'll give you most of it back. Like, there there are conventions and ways that things are done in in in software and responsible disclosure and stuff like that where I I strongly believe that if they did done the right thing and said, look, here's a demonstratable
way that we could drain the whole fucking network. Blockchain be like, oh, do you know what? Yeah. You know what? Here's here's a couple of Bitcoin or, I don't know, here's 10 Bitcoin. Like, you're set for life,
and you're also not gonna have the police chasing after you for the rest of your life. If they did it, though It's too late. If they did it If they did it. Because, you know, you once you disclose that you have found the bug,
you could send that to Blockstream. They could go, oh, yeah. Cheers, guys. Yeah. And I appreciate that. We could have lost 4,000 Bitcoin, but we haven't. So tell you what, here's $50. Mhmm.
Right? So this is the sort of thing that you might only find once in a lifetime as a white hat, gray hat Yep. Black hat, hacker. Right? If you take it and then you say, right, we'd like some money as a thank you for not stealing the whole lot. We're gonna give you most of it back.
I think 10% is, like, not unreasonable. 5% is even more reasonable. That's very different to, like Blockstream could have said, yeah. Cheers, guys. Like, pat on the back. There's no money.
Or cheers, guys. Here's $50. Whatever. So I think there's maybe a middle ground. I'm definitely not condoning theft. I think it's cunty. Like, we're seeing hacks all the time. At the end of the day, like, it is it is theft. It is wrong, and, you know, I'm not not saying it's not, but I'm just saying they got fucking lucky
that this lot, whoever they are,
returned most of it. Yep. Because Yeah. Well, not don't think I would in their situation. I'd go, fuck you. That's mine, mate. I'm looking over my shoulder anyway. I might as well have the whole lot. I've already it's theft. It's theft. It's theft. I'm gonna get up to the pearly gates, and god's gonna go, how shall I not steal?
You fucking stole. You're not coming in, mate. So I've messed that one up. I've got the police after me. Like, keep it all.
Yeah. I mean, we'll see. Even if they give it back now, I would imagine the the way that law enforcement typically typically looks at this sort of stuff is that they
will be Oh, they're still going. Even if even if Blockstream don't don't like, I'll just be like, oh, thank god we've got it all back. Even if Blockstream don't press charges or whatever the equivalent is in The US or wherever Blockstream's domiciled, it's already too late. Like, they are whoever did this is gonna be pursued.
A 100%. And and and so final point, I won't repeat it again. Blockstream, you're lucky you got most of it back because this lot could have kept it all. Yeah. Absolutely. Okay. More clarity act bullshit.
Reminder, this is The US market structure bill that splits crypto oversight between the SEC and the CFTC. On September the sorry. September 10, Senate Republicans revised released a revised version that closes the DINO loophole, decentralized in name only. So the DeFi projects that call themselves decentralized but are
clearly centrally run will have to register with the CFTC. And late last night on the September 13, sponsors of the bill, Senator Lummis, Bozeman, and Scott released what they call their, quote, last, best, and final text with a hunt with the 126 changes that the Democrats asked for.
The big ones are ethics, which had stalled democratic support all summer, and Trump agreed to rules making federal officials and their spouses divest significant crypto holdings or put them in a blind trust with the state attorney general being able to enforce them.
Unfortunately, the the part that most people, that listen to this show, matter, or that matters most to these people that listen to the show, should I say, the developer protection, which is the the blockchain regulatory certainty act, which stops the
noncustodial software developers being treated as money transmitters, which, you know, again, we've covered significantly over the past couple of years. That part now only covers civil enforcement.
The language protecting developers from criminal prosecution for unlicensed money transmission, one of the charges which, of course, was brought to the samurai developers was removed after pressure from prosecutors.
Writing noncustodial software should be shielded from regulators, but not from a criminal case, basically, is what they're saying. Yeah. The the vote which, ends debate and needs 60 votes is tomorrow, September 15 at 02:15 eastern.
Republicans hold 53 seats, so they need at least seven seven Democrats to get it to slide. Prediction markets are currently putting it around 25%. And if it fails, the most people are saying that the bill is almost certainly gonna slip past the midterms.
I need a I need a soundboard thing that's just like that says like Wah wah. Yeah. Just wah. Yeah. Exactly. That's a very good very good noise. I'll have to clip that up. Okay. Next on the list, quantum attack estimates have dropped to 835 logical cubits, whatever the hell that means. Well, let's dive in.
Every Bitcoin or UTXO that you hold is, of course, protected by a private key. From that private key, you can work out your public keys. But going the other way from your public key
back to your private key is impossible for a normal computer, crucially. That obviously, that's kind of a kind of important part so that nobody can steal your shit. That one way math is elliptic elliptic curve cryptography,
and the curve that Bitcoin uses is called sec p two fifty six k one. Been around for it for quite a while. It's well reviewed and is generally deemed pretty strong. However, a large enough quantum computer running Shaw's algorithm
could in theory reverse it. Give it a public key and it gives back the corresponding private key, which would obviously be not good.
Your addresses are slightly different here. Your addresses are like a hash of your public key depending on the address scheme that you use, of course. And hashes are not broken in the same way so that quantum computer cannot, in theory, work backwards from an address alone.
Well, the news item here is that on the September 10, Chinese researchers published an algorithm that would break sec p two fifty six k one, wow, that's a mouthful, with what they're quoting as 835 logical qubits.
The 2020 estimate was 200 2,124. So they claim to have reduced the requirements by roughly 60%. Now all of this is very technical and way above my head, but like I've had me my AI kind of help me do some distillation here. And these physical qubits are basically like the the kind of the the kind of raw hardware, I guess.
They're noisy and very error prone. The a logical qubit is many physical qubits working together with lots of error correction so that it can actually run consistent calculations. The best hardware today is 94 logical qubits.
So just to recap, the quoted number that they have is 835, so it's still ways off. Best hardware today, it that's a cumulative, like because you're saying logical qubits of these qubits working together on one problem.
Yeah. So it'd be like to put it in simple terms, it'd be like all of Seth's sparks with all the other sparks that could work Times a million. Is, yeah, are still less. They're, like, 90, but you need 835.
So we're still not at a situation that even with all the compute working together, we still are, like, 10 x off. Yes. Absolutely. Okay. But a lot a lot less off than we thought we were. Yes. The the gap is closing.
Okay. Now what can you do about this? There's no need for any blind panic. I'm not kind of trying to be a yeah. In short, yes. You're absolutely right. But there are a couple of things. Like, don't reuse addresses because when you Ah, yeah. The spend.
Yeah. When you spend from an address, the the public key goes on chain. So any coin's still sitting at that address, you know, the public key is exposed, and that makes it you know, if it's public, it's more vulnerable if in theory this continues to. That was what Sailor was banging on about. Do remember?
I I tend to not listen to Sailor, funny enough. No. But but there was, a no. Not do I. But you you can't help but see some of the interactions if you spend time on Bitcoin, Twitter. And there was something where he didn't want to
publish what address was holding coins or spend from it. And he was saying, well, it's technically more attackable. And people are like, oh, yeah. Well, it's theory and it's
and I I don't agree with much of what he says, but you can understand why if you're holding significant funds that I mean, it could make sense, especially if you're maybe closer to government than other people, and you might maybe know that they might have the ability to do things that they don't publish.
And then, therefore, you might think that actually it's not a good idea. Yeah. I'm not saying that he's linked to the government in any way, by the way.
Okay. Next on the list, l b Hub self hosted Lightning node and Wallet. On September 9, they disclosed the critical floor in version one point seven three two one point one eight point five.
Basically, if the which is very old, by way. It's over 12 old. So if you're running l b hub and you're up to date, there's no cause for panic here. Basically, if the management API, which was traditionally
on port eighty eighty, was reachable from the Internet, then anybody could take control of the hub running those versions without logging in. There's reports of only one user being compromised here.
Basically, this was an authentication bypass. Nothing was kind of cracked or, you know, there was no leakage of private keys or anything like that. It was just somebody was able to gain access to your Albihub. And, obviously, if you've got Godmode to an Albihub, you can drain the funds and send them wherever you like.
If you run AlbieHUB, obviously, make sure that you're up to date. I believe the latest is 1.24. Maybe take some back you know, be reassess as to whether your AlbieHUB actually needs to be publicly exposed or not. For most people, probably not.
And, obviously, rotate your credentials just to be on the safe side and just double check all of your payment history to check that you're not missing any funds.
Next on the list, we have more breaches.
We covered this a little bit, I believe. No. This is an extension of what we covered last week. Bravo, formerly known as Sendinblue, is a European email marketing service used by a number of Bitcoin companies.
Well, last week, it came to light that attackers gained access for to Bravo, created API keys inside some of their customer accounts, which let them send emails from those companies' real domains.
On the September 9, customers of Trezor, BitBox, and CoinTracking received fake s t m 32 entropy vulnerability alert emails designed to get hardware wallet owners to hand over wallet information.
Bitbox and Trezza both confirmed the breach around about the same time at 8PM that evening. Now because the attackers gained access to Bravo, which is like the the marketing tool that lives in the background, they were able to send legitimate emails that passed all of the typical email checks like SPF and DKIM
that your email provider normally runs to confirm that an email message came from the domain that it claims to be from. And they did indeed come from that domain because they had access to the to the back end where these companies were you know, they had all of the the email related credentials.
So the weak point was the company, Bravo, that the wallet makers trusted to send their email. It wasn't necessarily a compromise of anything to do directly with Trezor or Bitbox, but of us unfortunately, their customers were the ones that fell prey to it.
Obviously, they you know, this was targeted. Whoever did this attack and knew that, you know, that they've taken leaked lists from various different companies that of known hardware wallet users. Could be the ledger leak, could be the the previous Trez leak, could be And basically, they send
that emails and hope that somebody matches the fit that, oh, they have one of the devices that's covered in the email and they can get them to take the relevant action. They could have even got it from the Revolut leak, I suppose, because it you know, it's not
much of a stretch to be like, oh, he's bought Bitcoin. Maybe he's got a treasure. Let's send him this email and see if we can get even more of his funds. Fucking hell. So again, reminder, no wallet company is ever under any circumstances in any dimension going to email you to ask you for your seed words, tell you to take urgent action
to click a link and connect your device, to do anything to the shape of verify your wallet or apply an emergency upgrade. Anything like that is going to be a scam. Remain vigilant. This is going to accelerate.
Limit the amount of people that know that you own Bitcoin, and that's all I've got to say on a month. Yeah. And a weekly reminder, when you are buying your hardware, don't get it sent to your home address just in case because all the will in the world, these things can leak and and just be
be very careful. And what was the show that people were mentioning on,
you know, on our, nostrils, someone was like, do wanna do a new show? And just every week, you have, don't trust any kind as the as the entire show. So I'm just gonna leave that in now. That was someone's suggestion. It's just every week. So that that's your weekly reminder. Don't trust any cunt.
Yeah. Yeah. Absolutely. Alright, mate. Let's let's hit some boosts. Lots of boost flowing again as with last week. We'll go alternates, and I will kick us off with x patriotic who sent zero point zero two nine in XMR, ironically, on a Bitcoin show. Thank you very much, sir.
He said, it would be nice to have XMR or BTC denominated boosts, I think Yeah. She Currently, can tap SAT or XMR, and it highlights, but there's nothing else. Well, I've already been speaking to him in the background and and he has already assisted. This is fixed. Yeah. So thank you for your contributions,
your support. And, yeah, just for for a bit of extra context for listeners, if you go to on governorballup.network/v4v, you'll see our boost wall. You can now boost and denominate in anything from dollars to sats to bitcoin to x m r.
And the bit the BTP server in the back end will just do all the magic, and you'll get your name on the wall of fame to share your support for the show. Thank you, x patriotic. Thank you, mate. Anonymous sent 12,955 sats and said this is a shill. I'm gonna read it anyway.
Yeti cold is getting discussed a lot recently. Any chance of Yeti two point o deep dive? I to me, YETI cold sounds like a drinks container. You know, they make those, like, cold and and hot drinks containers, don't they, YETI? Yep. What the fuck is a YETI? I assume it's a hardware device.
I can't yeah. It's not really a device Yeah. I've done a bit of I am loosely aware of it. I didn't know there was a two point o. They have come back out of the woodwork after the call card stuff.
I think I have prepared a little bit of of a a high level that we'll get to straight after the brief after the the boost and before the releases. Fine. So let's finish off the the the boosts. Thank you, anonymous, whoever you are. We will circle back very shortly.
Next on the list is Lonely Pumpkins. You sent 10,000. Right now. And they said, tilting the scale away from Monero boosters. Keep up the good work, gents. Thank you. I am saluting you, lonely pumpkins.
Yeah. Thank you very much. Anonymous again. 6666 and says, continue the great work. Thank you. We will we we plan to. Yes. We're we're cranking hard at the ungovernable towers at the moment, and your your support is is very much welcomed.
Next on the list, we've got Reed BTC 2,143 stats, and they just said thank you, gentlemen. Thank you. User two five oh my god. I've got my eyes. 25498104 sent 2,000 stats and said q is already evidence of AGI.
I agree. I agree. I've said this for many years since even before AI was a thing.
Yeah. I think we might have said this before, but, like, do you remember when we first started recording and I was producing all my guides and it used to be, an ongoing in joke that, oh, Q's obviously a robot, and he's got an an army of robots working for him. Well, that is that is literally true now. You've spoken it into existence.
You've manifested it, as they say. Yeah. And the the best of the rest, just quickly, thank you to Rivan Stokes, RevHoddle, user 12931825, Nosdagang, and user 11694472. Thank you for your support as well. Yes. Thank you very much.
Okay. Yeti cold. So back to anonymous's question. I'm gonna try and keep this as high level as I can, and I want you to chime in when you when you in fact, cut me off as soon as you you you your brain ticks over. Well, that's fucking stupid. K? Just so I'm I'm I'm inviting you to talk
over me and tell me As soon as I think something is stupid, I'll just say that fucking okay. Yeah. Yeti two point o. That's fucking stupid. No. No. Come on. Play the game. Okay. Come on. Yeti so it's it's not an app. It's not a a specific piece of hardware.
It's a a a guide for building a three of seven multisig vault with nothing but Bitcoin Core and two ordinary Ubuntu laptops. No. No. It's already it's already there for me. Yeah. Well, that's where I was thinking. Who's that fucking what's his name?
The one who looks like an Ewok or something. Well, that's exactly who built this. CDs. That's exactly who Is it?
That's that fucking guy. What's his name again? It's j w weatherman. And I believe j w weatherman. Called heavily armed clown, which is also involved in this as well. Yes. Yes. Yes. Yes. So they they made the yeti cold version one Yep. But they now have a a two point o version.
So basically, one laptop runs a full node holding a watch only wallet. The other one is a signer booted from a live USB that runs only in memory. You create seven Bitcoin Core wallets on the signer, combine them into the multisig and burn each key to its own archival disk.
Yes, a CD disk. Along with the the wallet descriptor, of course, it's multisig. Before any real money goes in, you make three small test transactions between them all and use all seven keys.
Then the disks go to seven different locations. And to spend, you carry the transaction between the laptops on a USB stick and sign with any three of the disks. It it's just as it always has been, extremely complicated and seemingly unnecessary with a, like, a horrible user experience.
And then you need seven locations where you keep something physical. Like, I just don't see the benefit. Like, a, there are good there's good hardware out there anyway that does a very good job.
The systems that do a very good job as it is. And then if you really wanna go tinfoil hat or whatever, you've got, like, Liana and those kind of options to sort of go, like, an extra step further with spending conditions and stuff.
Or you take my approach, which is, like, just don't have all your eggs in one basket. This just seems like you could really, really fuck yourself really easily for everything thinking you're being smart. It's like it screams to me that someone's gonna have a sub story
a few years from now. I'd be like, oh, there's this fucking Yeti bloke on whatever his name, j w Weatherman. He said about getting all these discs, and I did that. And then I kept one at my nan's garage, and I kept one at my mate's fucking yard, and I kept one in the loft. And it's
like and then that we had a flood or the something fucking went wrong, and I've lost all my life savings. That's what I feel is gonna happen with that. That's my honest opinion. Yeah. I mean And also, fuck. Can I just say one final thing? I don't like anything where there's Bitcoin and laptops.
I don't like it, especially with all this AI shit. Yeah. Maybe you take out the ability for it to connect to this and that and use some clever shit.
I think if anyone's gonna do it, do it with, like, a graphene phone or something. Like, have have those as your signers. I'd feel more comfortable. If someone's just said, just run Ashigaru or run
Cupcake or run, like, a few things on phones, and you have one that's a signer and one that stores keys, and you don't connect them to the Internet. I I I feel that's safer than laptops. Yeah. I I mean, you won't find me recommending this.
It's 2026. Like, I'm not going out and buying CDs. I'm also not buying two Ubuntu laptops for this. I'm also not using Bitcoin Core as a wallet. It's a terrible, terrible wallet to use.
Like, there are so many better options here, and I I I'm not even gonna mention what I do for work. Like, that that that like Yeah. There's just so many better options that to do this. You can have all of the security that this claims to offer without needing to burn fucking CDs, use Bitcoin Core as a wallet, buy two separate Like,
I I get it. Like, the the idea here that that they don't want buy Bitcoin related hardware. Like, okay. Fine. Like, if that's if if that's what you wanna protect yourself against, build a Seed Signer. It'll be 10 times easier to use.
Yeah. Use a Seasigner, use a phone running graphene, whatever. You know, if you don't wanna have Bitcoin's hardware specifically, I get that. I can understand why someone would have that approach. But, yeah, this is no.
He does seem like a bit of a twat, to be honest with you. I don't like like, he just he does. Gotta be honest.
But he did it years ago. I listened to an episode with him, and he built this thing called, like, MathBot or something like that. And I remember playing around with it, and it was quite cool. It was like a a game for kids to learn maths,
and I thought it was quite cool. So bit of a twat. Wouldn't recommend this 21, but did something quite cool if you kids wanna learn maths from memory. So, yeah, shout out to you, mate. Cool. Right. Let's sign off with the releases.
As always, massive list of releases in the show notes. I've just picked out a a handful of ones that are worth a brief mention before we close out the show. Electrum Rust Server 0.12 has now been released.
Not very exciting project, but it is the backbone of many Bitcoin nodes. It's kind of like an unsung hero that people run on top of Bitcoin Core to help, you know, indexing their transactions and have faster wallet address lookups on their own node.
So as of the September 13, the latest version moves to a new indexing library called Bindex, which I thought was pretty funny. And it also needs Bitcoin Core 31 or later and a full reindex.
So be prepared for that. It needs a full reindex. So if you update your umbrella or your start nine or whatever you run, make sure that you upgrade Bitcoin Core first. I'm sure they'll have protections against this so that you get that you do it in the right order, and plan for the downtime.
Because if you're running a low powered hardware, that reindex could be a lengthy process.
Next on the list, we've got Ferrymint version zero point two one two point one. Ferrymint, for those of you living under a rock, is Bitcoin backed e cash held by any, you know, your own federation of guardians. It has lightning powered gateways to enable you to pay out to the rest of the network.
The reason I'm highlighting this one that came out on the September 12 is it's it's a security release. Fix is a vulnerability in how gateways handle lightning payments, and it's got extra hardening across the different l and d and LDK back ends as well.
The fix is consensus neutral. And by consensus, I don't mean Bitcoin. I mean, Fediment consensus. So guardians and wallet users don't need to kind of coordinate to upgrade as well. Gateway operators are the ones that need to act, and they should do it soon.
Back to the guys over at Cake slash Radar. They've released version one point o point seven. Radar, quick reminder, is a private messaging app. It's basically signal with Bitcoin self custody and payments built in.
On the September 12, they added paying to BOLT 11 lightning invoices, whereas previously, you could only pay to lightning addresses, the the email style addresses as well. Basically, you just scan to pay from the the send screen.
And you can also receive on chain Bitcoin through links so that you can hide and you can also hide your balance across the whole app as well. Oh, cool. They've also added signal backup migration on a single device. You can bring your signal message history across without a second phone. Nice.
Next on the list, shilling my own wares, Bitcoin seed tool version 2.4 o has been released. Did a bit of work over the weekend. Seed tool, for those that you don't know, is my free and open source seed tool, I guess. That that's why I called it seed tool.
The it runs in your browser. You know, there's there's one on my website, like a live version, but you should, if you're doing any sort of seed work, download it offline and run it on an offline machine. It's just a HTML file at the end of the day.
So the new release that came out on September 11 adds seed QR code scanning, the ability to split a seed into anywhere between two and eight seed x or shares that are compatible with other hardware wallets. You can derive Gnostic keys from your seed using the NIPO six standard,
and then various other slightly less boring stuff, including principal backup templates.
Was it you was it on this tool you also had, like, a a passphrase builder or something like that? Was it you, or is it someone else? I do have a passphrase builder. Yes. Let me bring Yeah. And it, like, shows the amount of protection you have and all that kind of stuff.
Yep. So you can roll you can roll dice and add words. And Yeah. I do need to do some word do do some work to improve the the communication of, like, how secure a pass phrase is, basically.
Right. Think I actually took out because the the old method was slightly flawed. So I'm gonna add add something more accurate back in that's kind of easier to to calculate or easy to understand, should I say. I have a question on passphrases.
It's always one of those controversial topics to some extent. Like, some people have, over the years, said definitely don't recommend using them. And some people have said, yeah, use them, but only use the the seed words that, you know, the what's the this bit?
What's the the seed word list? I forgot what it's called now. We have 39 seed word list. Where do you stand with it? Do you think that it should be completely random like a password? Like, you might see a few, you know, Proton pass and did, a a randomized one with letters and numbers and all that kind of stuff. Or
yeah. Where'd you stand with it? Either. Either is good enough as long as you're using enough entropy in either of them. So, like, minimum five to six words or a random password style gobbledygook.
Again, as long as either's got enough entropy, like, I'm indifferent. It doesn't really matter. The only I guess, if you're gonna lean one way or or the other is that if you do, like, a password style that's got special characters and things, I just think those
special characters, like, if you have spaces or or, like, exclamation marks or something, could be missing or easier to misinterpret than five English words with one space in between or with no spaces in between.
Like, it's just there's there's a reason that bit 39 exists, and that's because, like, plain words are easier for us humans to kind of understand and deal with and type and stuff. I guess what I'm this is my brain working here. So excuse excuse me if it doesn't make any sense. But if I was an attacker,
I'd be thinking, okay. The general recommendation is to use this bit 39 sequence. There's there's 2,048 words or whatever it is. My brain tells me that would be easier to work out what someone's passphrase is because it's gonna be a combination of a few of these words. I understand that there's 2,048
and the amount of combinations is massive and blah blah blah blah. Yeah. But my guess is that, like, you would know more that after this letter, there could be this letter on a word
rather than it would my my brain is telling me it'd be harder to know that there's oh, okay. There's gonna be letter, but then there's gonna be an exclamation mark. Or then there's there's gonna be a dash. Or there's gonna be now it's gonna be a capital. Or now it's gonna be a number.
I my guess is that that's just harder to fucking crack than just words, but maybe it's not. Like, is it or not? Well, ultimately, it depends. Like Well well, there there is some
kind of partial truth to what you're suggesting here. Like, if you can see what I've got on screen here, like, the this is obviously much fewer characters. Right? But there's a lot more, I guess I don't know what what you call it, but visual randomness. Like, like you say, there's characters and
there's, like, special characters, there's capital letters, there's there's noncapital letters. Yeah. But it's a lot shorter. So you've got fewer characters to guess Yeah. Versus,
like, five long words where, like you say, there's 2,000 a list of 2,004. Yeah. Like, I'd arguably, I'd say if there's enough entropy, it probably doesn't matter. It's probably the the the safest way that I can do it. But Mhmm. Me personally, would I rather type in five English words or
type in that that I've got on screen than it's the English words Yeah. Of course. Every day. Yeah. No. I I understand that. I'm just saying, like, 20 characters, let's say, which is x amount of words or 20 characters that are completely random, which is harder for it to crack.
In my brain, it's the 20 characters that are completely fucking random rather than 20 characters that are definitely in that word list, which would follow a certain pattern if you guess the first is that and.
Like, is that actually does that have is that harder to crack than the words if it's if it's limited to 20, let's say, or 10? You know who would be able to answer this? Super for Arrow. Well, I was gonna say fundamentals, but I'm sure SPA could answer this. Yeah. Funda well, fundamentals or SPA.
Yeah. Can you let us know, please? And anyone who's listening, just know that you can now actually watch this on our website. So where Q's talking through these types of tools and all this stuff, he's actually now got it that you can see his screen. So definitely check it out. You you be seeing it if you're watching.
We've got some Oh, yeah. Some stream inception. Yeah. Look at that. Yeah. Worth following along and and looking through. But, yeah, it's just it's an interesting question to me because that can be the difference between as it was with some of these cold card users,
is the difference between loss or not loss. And so it's an important thing to know. Yep. Absolutely. Alright. Back to the releases. Phoenix two point eight point two, my favorite normie friendly lightning wallet.
They released version two eight two on September 7 last week just after we recorded. And the iOS came out on September 8. They've added much more
lost my train of thought. Languages. They've added Italian, Japanese, Polish, Ukrainian, and Korean, and Android users can now set free rates by hand for on chain spends as well. Nice. If you haven't downloaded and tried Phoenix yet, you absolutely should.
Yeah. Excellent. It's been in my arsenal for many years, and it's never done me wrong. The the excellent wallet. Yeah. Yeah. Agreed. BTC pay server two point four point four came out on September 8.
They now have NFC payments at checkout turned off by default. Not sure why. Zero amount invoices are blocked by default, and bulk card setup from the desktop has been removed in favor of a traditional sorry, a custom bulk card app.
Next on the list, we've got Ashigaru version one point four point five. If you missed Freedom Tech Friday last Friday, go and check it out. Jordan was on giving us a show and tell. Basically, he's already covered all of this on free internet Friday.
But Ashigaru is the fork of Samurai Wallet, and Ashigaru desktop brings that into a desktop environment. And Jordan's been vibe coding his Canadian little fingers off and doing a sterling a sterling job.
Yeah. And, yeah, he's just been continuing to to improve. There's no big standout feature. Oh, sorry. There is standout features here. We've got guided tours, dice based passphrase tool, and stronger checks when verifying your own Dojo node. And he's added a login tool as well so that he can help with support.
Finally, last on the list, Flint version 1.1 o. Flint is Seth's lightning plug in for BTP pay server that he's built on top of the Breeze SDK. Version 1.1 o, which came out again September 7, last week just after we recorded the previous brief, has added compatibility with BT pay latest version
and release gating for the Breeze SDK Spark dependency. If you run Flint, upgrade it alongside your BT pay once you're on the latest version.
That's it, mate. Okay. That's us. Very good. Week. Very Mainly doom, as always. But
yeah. That's it. There's there's not a lot you can do about that. It's like being a war correspondent.
You're not gonna sort of, you know, get on and be like, hey. Having a right fucking laugh over here. It's always gonna be a little bit like this, but, hopefully, we have some fun along the way. We got some good stuff in there as well. We we're, I wouldn't say we're winning, but
It doesn't feel like it. Still be no. But but what there is is the option to protect yourself and to win, to take little wins if you do things right and listen. So I think that's that's what we strive for.
As long as we got the tools, like, we're just talking about there with Ashigarra desktop and Whirlpool and these sort of tools that are available, I think you have the chance to win. Take take something off the board, be less attackable, and that's that's a that's a version of winning.
Certainly is. Certainly is. As I said at the top of show, I will not be around for free and tech Friday this week. No guests. I believe we're just gonna have a bit of a new show. Maybe Seth's gonna give some insights from his recent trip to the West Coast to for the open source AI summit,
which was held at Presidio Bitcoin. Looking forward to watching some of the talks that are coming out of that actually. I am very much being nerd sniped by local AI as I'm sure all of the listeners have picked up on from my recent the recent shows that we've been doing. So I will
I won't be listening because I'll be on a plane, but I will be catching back up with with you guys afterwards. And other than that, we'll be back at the same time next week for more Bitcoin signal.
Yeah. Stay uncovernable.
Machine transcript; expect the odd mishearing. Click a passage to play from there.




