
The AI-Pocalypse Continues
Discussed in this episode
Boost this Episode
Send sats directly to the creators. Value for Value.
Plus 1% to Podcast Index, 1% to Boost Bot.
Show Notes
A weekly news show informing you on the latest in Bitcoin, privacy and open source tech, hosted by Ungovernables, Max and Q.
AOB
- We are now a weekly show
- Topics
- Full screen video
- Admin tools
- Envoy 2.3.3
- KeyOS 1.4.0 beta3 (public release this week)
NEWS
- Core Lightning: A Critical Vulnerability, a Binary-Only Patch, and a Docker Pipeline That Broke Because of It – Stacker News / Blockstream Blog / GitHub Release
- Bitcoin’s First Quantum-Safe Mainnet Transaction (No Fork Required) – Bitcoin Magazine
- Stacker News Ships Embedded Spark Wallet and Receive Proxy Toggle – Stacker News
- SeedSigner Fork Adds Miniscript Support with Liana Bridge – X/@UnruggableGG
- Roman Storm Retrial Pushed to April 2027 – X/@rstormsf
- Coinbase and Better Mortgage Launch Bitcoin-Backed Mortgages – Bitcoin Magazine
- HRF Awards 500 Million Sats to 16 Freedom Tech Projects Worldwide – Bitcoin Magazine
- Kraken Users Locked Out After 12,000 Dust Transfers From Sanctioned HTX Wallets – Bitcoin Magazine
- Bitcoin Knots BLAKE2b Hardfork Goes Live as a “Mainnet Trial” – CryptoSlate / GitHub PR #359 / The Bitcoin Manual explainer
- Peach Bitcoin Pauses Escrow Model After Swiss Regulator Reversal – Peach Blog
RELEASES
Flint v1.0.3 – 2026-08-28
- Security audit follow-up for Seth’s BTCPay Server plugin. Strips macOS payloads from the build, pins the release path, and restores file permissions after dylib stripping. All artifacts are Sigstore-attested with no maintainer key required.
- Also in window: Flint v1.0.2 (2026-08-27) – 23% smaller package, shared reconciliation scans reducing SDK calls for idle stores, cached Spark network status reads. Follows the v1.0.0 milestone which fixed a payment-hash association security issue.
- Envoy 2.3.3 – 2026-08-27
- Point release improving Passport Prime pairing reliability with automatic retry and clock-drift tolerance. Also fixes a visual bug where seed verification puzzle words could overflow at high zoom, and removes a hardcoded Stripe test key.
- Sparrow Wallet 2.5.4 – 2026-08-27
- Significant hardware wallet security hardening: mandatory anti-klepto on BitBox02, Ledger wallet policy re-registration on rejection, and serialised USB device access to prevent enumeration interrupting operations. Also improves BIP129/descriptor import validation and SLIP39 passphrase handling.
- Eclair v0.14.2 – 2026-08-26
- ACINQ released Eclair v0.14.2 with fixes for bugs that “can be exploited by malicious nodes.” The release also documents that bitcoind should run on the same machine as eclair or use a secure tunnel. Upgrade is “highly recommended."
- BTCPay Server v2.4.3 – 2026-08-24
- Security release recommended for servers shared with many users. Release notes are minimal, stating only that updating is recommended. Published by NicolasDorier with a GPG-verified commit.
- BitBox02 Firmware 9.27.0 – 2026-08-24
- Displays long transaction and swap amounts in full instead of truncating. Adds message signing for keys in the m/45’ namespace and supports timestamp-based absolute locktimes. Stepped upgrade path required from older firmware versions.
- Blockstream Ships Jade 1.0.41 and Reflects on the Coldcard Fallout – Blockstream Blog
- Published: 2026-08-25
- Blockstream released Jade firmware 1.0.41 alongside a blog post responding to the Coldcard RNG vulnerability. Jade is not affected (no degraded RNG fallback path, mixes multiple entropy sources through SHA512). Release is security hardening: runtime bumped to latest stable, increased stack protection, updated dependencies, audited sensitive-memory clearing. Not urgent but recommended. 1.0.42 on an expedited timeline for less serious reports. The post reveals dozens of AI-automated scans landed on Jade within days of the Coldcard disclosure, plus multiple human reviews. Credit to Spiral’s Loupe tool and the Kvazar agentic harness.
- Arkade v0.9.16 – Aug 2026
- Major security hardening and admin web console for the Ark protocol server.
- BasicSwap DEX v0.18.5 – Aug 2026
- Bisq 1.10.7 – Aug 2026
- Hotfix for corrupted DAO datastores. Continues the rapid Bisq 1 patch cycle from last episode (1.10.5 security update, 1.10.6 hotfix).
- Cashu CDK 0.18.0-rc.1 – Aug 2026
- Release candidate with explicit payment confirmation, batch minting, and BOLT12 fix.
- Cashu TS v5.0.0-rc.8 – Aug 2026
- Release candidate with crash-safe swap previews.
- Fedimint v0.12.0 “Second Nature” – Aug 2026
- Named release of the federated ecash protocol.
- JoinMarket-NG 0.38.0 – Aug 2026
- Quantized fees, zero-fee makers, and security hardening. Continues the rapid development from last episode’s 0.37.0/0.37.1 releases.
- LND v0.21.3-beta.rc1 – Aug 2026
- Release candidate. Also ships v0.20.4 RC for the older branch.
- Nunchuk Android 2.8.4 – Aug 2026
- Bug fixes for the multisig wallet.
- Vexl 26.8.0 – Aug 2026
- Update to the P2P no-KYC trading app.
- Wasabi Wallet v2.8.2 – Aug 2026
- Coinjoin security patches and reorg sync fixes.
EDUCATION
- Deep Dive: Bitcoin’s Quantum-Resistant Transaction Explained – Sylvain Saurel / In Bitcoin We Trust
- Published: 2026-08-27
- Detailed technical explainer breaking down StarkWare’s first quantum-resistant Bitcoin mainnet transaction (block 964,199). Covers how hash-based cryptography replaces ECDSA exposure, explains Shor’s and Grover’s algorithms, the mempool attack surface (public keys are exposed between broadcast and confirmation), and why the broader network remains vulnerable despite this milestone.
TO DONATE TO ROMAN’S DEFENSE FUND: https://freeromanstorm.com/donate
HELP GET SAMOURAI A PARDON
- SIGN THE PETITION —-> https://www.change.org/p/stand-up-for-freedom-pardon-the-innocent-coders-jailed-for-building-privacy-tools
- DONATE TO THE FAMILIES w/ USD —-> https://www.givesendgo.com/billandkeonne
- DONATE TO THE FAMILIES w/ BTC —-> https://pay.zaprite.com/pl_JpxtkLv95T
- SUPPORT ON SOCIAL MEDIA —> https://billandkeonne.org/
VALUE FOR VALUE
Thanks for listening you Ungovernable Misfits, we appreciate your continued support and hope you enjoy the shows.
You can support this episode using your time, talent or treasure.
TIME:
- create fountain clips for the show
- create a meetup
- help boost the signal on social media
TALENT:
- create ungovernable misfit inspired art, animation or music
- design or implement some software that can make the podcast better
- use whatever talents you have to make a contribution to the show!
TREASURE:
- BOOST IT OR STREAM SATS on the Podcasting 2.0 apps @ https://podcastapps.com
- DONATE via Monero @ https://xmrchat.com/ungovernable
- BUY SOME STICKERS @ https://ungovernable.network/shop/
FOUNDATION
https://foundation.xyz/ungovernable
Foundation builds Bitcoin-centric tools that empower you to reclaim your digital sovereignty.
As a sovereign computing company, Foundation is the antithesis of today’s tech conglomerates. Returning to cypherpunk principles, they build open source technology that “can’t be evil”.
Thank you Foundation Devices for sponsoring the show!
Use code: Ungovernable for $10 off of your purchase
CAKE WALLET
https://cakewallet.com
Cake Wallet is an open-source, non-custodial wallet available on Android, iOS, macOS, and Linux.
Features:
- Built-in Exchange: Swap easily between Bitcoin and Monero.
- User-Friendly: Simple interface for all users.
Monero Users:
- Batch Transactions: Send multiple payments at once.
- Faster Syncing: Optimized syncing via specified restore heights
- Proxy Support: Enhance privacy with proxy node options.
Bitcoin Users:
- Coin Control: Manage your transactions effectively.
- Silent Payments: Static bitcoin addresses
- Batch Transactions: Streamline your payment process.
Thank you Cake Wallet for sponsoring the show!
MYNYMBOX
https://mynymbox.io
Your go-to for anonymous server hosting solutions, featuring: virtual private & dedicated servers, domain registration and DNS parking. We don’t require any of your personal information, and you can purchase using Bitcoin, Lightning, Monero and many other cryptos.
Explore benefits such as No KYC, complete privacy & security, and human support.
(00:00:00) INTRO
(00:00:58) THANK YOU FOUNDATION
(00:01:45) THANK YOU CAKE WALLET
(00:02:48) Going Weekly & Four Chainsaws
(00:05:13) The New Website & Topic Archive
(00:15:24) Envoy &…
Bitcoin is close to becoming worthless.
Now what's the Bitcoin? Bitcoin's like rat poison. Yeah. Oh. The greatest scam in history. Let's get it. Bitcoin will go to fucking zero.
Welcome
back to the Bitcoin Brief, the show where me and q and a catch up every two weeks to talk about Bitcoin, privacy, open source, keeping your Bitcoin secure, and the news and software updates that matter.
I just wanted to say a massive thank you to everyone who's been supporting Ungovernable Misfits, and a big thank you to Foundation Devices for supporting the show. If you haven't already checked them out, go to foundation.xyzed.
They make cypherpunk tools for fuckwits, and anyone can use this, even me. If you have any questions or you want to reach out, feel free, and I'll be happy to go through things with you. For anything super technical, I'll pass you on to queue. If you wanna buy one of these incredible passports, use the code ungovernable.
It will get you a discount, and it will let them know that I'm shilling. I'd also like to say a huge thank you to the Cake Wallet team. Not only are they supporting this show, but they're also bringing out some incredible features.
For those of you who actually use Bitcoin and actually care about their privacy and security, Cakewallet make it incredibly simple for you to live outside of the traditional financial system.
You can use Cake Pay within the app to buy gift cards for food, petrol, and whatever else you might need day to day. You can use silent payments, and, of course, you can use Monero. You can connect both Bitcoin and Monero nodes, use coin control, and this team are constantly innovating.
And I'm really excited to be working with them. If you have any questions, you can reach out to me, but check them out at cakewallet.com. Download the APK or start using this today on Mac, Windows, Linux, iPhone, or, of course, your Android device.
Enjoy the show. I just I just didn't do well. Oh, no. Well, we're here. Hello, mate. Hello, mate. We're seeing a lot of each other lately or hearing a lot of each other's voices. We are. It's
it's getting scary out there every week. Literally every week. We're we're now a weekly show. The people have spoken. The people have spoken. They've got what they wanted. More maps. More queue.
What fucked up lives they must have to think. Yeah. Do know what I could do more of? Yeah. You want something be happy. Yeah. It's not enough to hear them on a Friday show live. I want a Monday show every week as well. That's it's very kind. Thank you. It is. There are gonna be some nut jobs out there that listen to all 104
shows that the two of us will do together every week. Two of us. Yes. They will be. Well, they'll be well informed. They will be well informed. They will indeed. Yes. Yeah. Yeah. We've got quite a big list, so to focus for this week as well. Clank has been working hard, been fine tuning it for all my discovery stuff
along amongst many other things, which brings me to the first of my AOB. In fact, you go first. What's new in your world, mate? Anything notable to to tell the ungovernables?
I bought a new chainsaw. Oh. I think you might have mentioned that last time because I asked if it was electric, and you laughed at No. I've I've now got four chainsaws, so it's all what I've had. I've got, yeah, I've got four different chainsaws. Seth's out here buying
DGX sparks like they're going out of fashion. You're out there stacking chainsaws. They're just really fucking useful at this point in my life. I've got four of those. What else? Ripped out a kitchen.
Decided I didn't wanna invest any more time in building one out, so I bought a load of, like, tool station stuff, like, where you'd normally put, like, where you took, like it's like imagine, like, a snap on chest that you'd have in your, in your garage.
So my kitchen is now effectively carriage, which my missus is very happy about. She's like, oh, this this is a great look. I look forward to pictures of that. This is really in vogue. That's it really, mate. Just scratching around as usual.
Can't think of anything outside of that, to be honest. What about you? You won't be surprised to hear lots of vibe coding. I won't be surprised.
Yeah. A lot of it, especially over the weekend, did many, many hours on on the the Ungovernable website on the weekend. For those of you that have been living in a cave, check it out, ungovernable.network.
It's had a we've had a complete rebrand. Well, rebrand is is probably too sharp of a word because we still got the same awesome logo that Crown made. New website, new design language. And over the weekend, I've been adding come I to the realization, and I think Jordan might have had to
poke the idea into my head whether or not it was intentional or not, but we've got a massive archive. We've been we've been at this for for a long time. Right? Yep. We've got, like, 500 episode or over 500 episodes, I believe, because didn't we have the birthday not so long ago? Yeah. Let me have a look. We've got 500
apps. Let me have a look. Lots of proof of work anyway. While you're looking at I'll talk about what I've been up to. So, yeah, had the realization. I was like, there's there's fucking hundreds, if not thousands of hours
of value there. Don't get me wrong, some of it that we talked about five years ago about, I don't know, according to an implementation that now doesn't work or, you know, a wallet that is now defunct or something might be not of use to anybody.
But the overwhelming majority of it will be very useful to people, and we we are growing the listeners the listenership. The ungovernable network is growing. Thank you to everybody for your support. Quite a wealth actually.
That's good to hear. Good to hear. We've had a good month this month, and a lot of people
reaching out and joining and asking questions. They're like, oh, no. I bumped in and spoken to them at a conference, or I've listened to them as a speaker or, like, people who are I know from a long time ago, I've seen they're starting to to tune in and listen. So that's pretty cool.
Yeah. Absolutely. And I think it's slightly more difficult for us to grow because we tend to talk about the the less popular stuff. The less sexy. Court cases and privacy and, you know, we're not out here click baiting you talking about the the price and Is Bitcoin dead?
Which, as we know, gets gets clicks, doesn't it? Oh, yeah. So we we we don't lower ourselves to that sort of shit. So it is more difficult for us to to grow, but we are growing and we appreciate each and every one of you for sticking with us, joining us, sharing the show, subscribing, doing all that good stuff.
Like, it genuinely is we are starting to see the fruits of our labor, so thank you all for that. Back to what I was saying. Back catalog, it's huge. It's there's a load of value there. But up until now, we didn't have a great way outside of going to,
you know, Fountain or Apple Podcasts or something and just searching and hoping for the best. Mhmm. Well, now if you go to ungovernable.network/topics, as the name suggests, you can search all the topics that we talk about. We've got featured topics.
You won't be surprised to hear about, like, the top kind of most spoken about topics that we have at the moment is things like self custody, transaction privacy, and open source. So Mhmm.
If you're interested in one of those topics, you can go and just look up click on, like, open source, and then you'll see all of the recent transcripts for where any of our shows we've been talking about open source. Everything's time stamped.
So if you see something that picks your fancy, you can click on that and you'll be taken straight to that episode page on the website, and the player will start playing that. If it's a video show, like Free InTech Friday, the video will pop up and start playing right at that moment.
Same for audio, but obviously you won't be able to see it. And you can do that across the past 500 shows. You can search for anything like mini script. You can be more broad and just go for a topic like open source.
And we've got some cool visualizations in there as well, Max. I don't know whether you've actually had a chance to look at this over the weekend. So I only dropped it to the team yesterday.
But we've a lovely little pie chart there as well that kind of breaks up by percentage what we talk about most. Mhmm. And again, you will not be surprised to hear that self custody, security, freedom tech, and open source are, you know, the the standout winners.
And you also won't be surprised to hear that policy, geopolitics, and society is one of the lowest ones.
Wanky word salad stuff is is very low. Yeah. Indeed. And it's just a great way to to find new stuff. Or equally, where I see this being useful is, like, if you are an avid listener and you're like,
you're having a conversation in Normandy land and something like mini script pops up and you're like, fuck, Max and Q were talking about that like three weeks ago. Just come in here, pop in the term mini script in the topics page and it will it will bring it all up in chronological order.
And you'll be able to quickly find, you know, the exact timestamp where me or Max were talking about that specific topic. And you can just get the context there and then very, very, fast. And kind of brings all of that old content back to life.
I think am I right in saying because I haven't checked that. I've been in our admin panel pissing around all morning, checking out all the new features and stats and stuff, which is fucking amazing.
But I haven't been in that part. Can they, like, select a certain time stamp and make clips and videos and stuff like that, or is that in my head?
No. They so they can select the time stamp and go straight to that video or audio source on the website and start playing it. Clipping is already on my to do list. Okay. I just wanna be careful because currently the website is on a a VPS.
And obviously, don't want people to just be honest. You don't like DDoS us and kind of, you know, make loads of clips and we have this, mate. We solved this where they yeah. Well, you did. You did. You came up with a good idea. You said rather than downloading
clips, why don't we do it so that they can choose a certain time stamp, and then they can share that link that has that that takes the person to that time stamp. Oh, that already works. Yep. That's Oh, that already works? Yep. Fine. There we are. What what a beautiful you were talking about having an actual clipping tool I was.
Public facing like we have in the back end. Yeah. I was, and then I remembered our discussion. And Not impossible. That was the fix. Yeah. It's just
the my because my vision for it was like, you know, if someone says, oh, I'm, you know, I'm getting into Bitcoin. I've heard about this cold card hack. I don't think self custody is a good idea. I don't know what to do. Or if someone's, like, listen to the latest brief or listen to something that we're talking about, and it's like,
oh, I know a clip that would be useful. There's, like, a five minute section here where they're talking about how to do things properly and, like so that we don't steer people into the hands of
the exchanges and that everyone is just too scared to do things themselves. This is a good little section that I can send someone, and then they send it across. Like, it it takes them to that direct thing without having to make the clip. And I think that's a really valuable thing. And and like you say from the bank catalog,
just like sometimes it's random stuff like, oh, here's here's where they talk about how to make sourdough with John or, like, his you know I mean? Like, it's there's useful stuff
that can be shared. So, yeah, I'm loving it, mate. It's very good. Already in. So if you just click any of those timestamp links, you can just copy it, and it'll take whoever clicks that link will be taken straight to to that part of that specific episode. So that's pretty cool. We also had some good feedback from
a name called Arrow on Noster, who clearly likes watching Feed and Tech Friday on the website. Mhmm. But up until now, it was like a fixed size player, which is not great on mobile.
So I completely overlooked the fact that you should be able to maximize that and tilt your phone to the side and have like the proper kind of YouTube experience where it's full screen on your 6.1 inch iPhone or whatever you run. So that's now live as of today. Thank you very much, Arrow, for the the idea.
Can't believe I overlooked it, really. So that's live. Jordan also had another idea about making the website a progressive web app, so you get more of a native experience. So you can just go to ungovernable.network Yeah. Yeah. Leave it to your home screen. So if if the actual website is your
vehicle of choice to stay up to date with the shows, now it's more of a native experience that you get with a progressive web app. Know, it hides the the URL bar and all that sort of good stuff as well without needing to install an actual app. And then the last one is, you've already alluded to Mark, was the the admin tools.
Obviously, are gonna have to take our word for it here because the admin tools are for the admins, like me, you, Jordan, Seth, etcetera. But I've been bringing that up to speed so that we can streamline more of the the kind of end to end pipeline. And you'll notice some of the clips and Twitter
posting and Nosta posting and things like that. It's all manageable now. So basically, we've got our own kind of back end studio that is semi automated with some gates from actual humans that read shit and edit shit before anything goes live.
Yeah. So I'm very, very happy with where it's where it is at the moment. Like, it's come on a long, long way in the in the past, like, month or so. And we've still got lots to do. Yes. Well, thank you to you and your clankers for for building it, mate, and thank you to everyone who's giving
suggestions and things like that. It's really, really helpful. So keep them coming, and we'll continue building this out and making it more usable and helpful. So thanks for that. Yeah. We're this is this is like version one point o. Yeah. In the next couple of months, we're we're gonna, without sharing too much, have
the ungovernable AI lab up and running, and that will really allow us to take things to the next level. So I'm very, very excited to get there as well. So Yes. More details on that when it's when things come to fruition. For sure. Warren, AOB, just wanted to say I've now released Envoy two point three point three.
A lot of work has gone into this. Much needed updates. So if you are on the older version, I'd just suggest updating today.
Make sure you use dead hash to verify all that good stuff that we talked about on the last episode. But, yeah, I've done my testing, working really nicely. So thanks to the team who's helped me put that out and go and update if you need to. Very happy about that. Yeah. Thank you.
The improvements there, just more stable Passport Prime pairing. And we had a little issue where Passport Prime clock would drift very slightly, which could cause some Bluetooth connectivity issues. So those have now been rectified as well.
One KeyOS one point four point zero beta three is now available. Again, emphasis on the beta. If you don't wanna do some testing and be a little bit on the reckless side, then just wait for the public release, which should be out, I'm guessing, by the end of this week, all being well. Okay. If there's no show stoppers.
And that's a big big release, new UI, side loading of apps, so five coders, you can go and do whatever you want with your device now. Connections for CASA, unchained, better battery life, mass import for 2FA provide 2FA
exports from things like Google and Proton and stuff like that. So it's a big old release, hence the multiple beta testing phases. But public is is getting pretty close now. Very good. Alright. Let's let's get onto the news.
Unfortunately, we are starting with another software vulnerability. This time coming from the core Lightning team. There's been quite a lot happening over the past week or so. On the August 26, so maybe four or five days ago now, the maintainers
told every Core Lightning node's operator to basically either, you know, shut down the node entirely or restart it with an offline flag, which was a new concept to me. And they basically just said that, shut it down because you're at risk. There wasn't much else posted.
Details of the vulnerability are currently under a two week embargo. The original announcement happened a little bit strangely. It was on like a Discord channel, and there wasn't much of a immediate follow-up from anybody on any other channels like Blockstream or from any of the core
Lightning developers on Twitter or the Blockstream Twitter account or anything like that. That there was quite a significant lag. So a lot of people were were kind of a little bit taken aback as to what was going on because they lacked a bit of clarity.
Blockchain did clarify a bit more guidance over on Stacker News, further recommending that offline flag or or a full shutdown, although they're favoring the the offline flag. And then a couple of days later, the this so this is on the twenty eighth, they released Core Lightning version 26 o 6.7.
However, they released only signed binaries, not open source the code as has been the case for pretty much every release they've ever done ever. So they've just basically said, we fixed it. Here's a signed binary.
We're gonna release the the the source code in fourteen days or September 11. Their re their rationale for doing this, which on the surface seems logical, basically, know, if if they
release the source for the new one, then anybody with a clanker can look at the the difference between the new source code and the old source code, figure out what's going on, and then go and try and attack old nodes that haven't updated or gone offline.
But the problem is well, there's two problems there. Number one, this is a very dangerous precedent to set with, you know, just putting out closed source binaries and saying, trust us, bro. Mhmm. Especially for an open source project like Core Lightning.
Yeah. And then the other problem is that you can still reverse engineer closed source binaries to to work out what's happened anyway. So you might be slowing the clock down a little bit,
but you ain't stopping a a motivated attack er from pulling the closed source binary and trying to reverse engineer what the change was to then go and attack the old nodes anyway. So
Yeah. I don't like that. It's it's a difficult one. I know Orange Surf did a bit of poking around to core developers on Twitter to kind of get a bit more clarification and a bit more, you know, is this legit? Because it was a bit of a
a bit of a messy way that things came around, that things were announced, things got released. Like, they they said take it offline, and then two days later had the binary. Like, yeah, it was just it was a strange one.
But then the plot thing's a little bit further. On a day later, on the August 29, the release page picked up a critical warning. And basically, were some automated runs that made some docker images of a new release, which were tagged with a newer version than the closed source binary that they just released.
But apparently so if you upgraded to that one, you kind of did everything right, but you were not running the version with the fix in it, if that makes sense.
It does. So the only way to to, quote, unquote, protect yourself here is to trust them, run the closed source binary, and then see what happens in the next couple of weeks or to just take, you know, completely offline and just wait.
As the non techy one, don't fuck around with any of this shit. Just go and run this Flint thing that we're now running that Seth's built. If you're running a BTCPay and running a node and you wanna just,
like, not deal with this shit because, you know, it was only last episode we went, oh my god. There's a massive vulnerability in LND, and everyone's shut you know, either been hacked or their their channels have been closed. And I was like, oh, fuck. Yeah. All my channels have been closed now. Great. So then I said to you, oh, yeah.
I'm on, Sea Lightning, so at least I wasn't affected except that I was because my channels had all been closed because most other people run LND. I'm like, alright. Well, spin this all up again and open up a load more channels and and fuck around.
And then you said, no. Why don't you try this thing? So I try it. I put my trust in another team, like, granted every fucking episode, there seems to be a problem. Even technical people are getting hacked and having problems.
My suggestion, unless you really fucking know what you're doing and you're absolutely on the ball, is use that Flint thing because it fucking just works. You trust me anyway. Yeah, the I I have two comments on that. The first one is a quick reiteration
of what we we've said, like, every week since all these vulnerabilities started happening is that you better get used to this. It's gonna happen. If you run a software project or a hardware project or anything that handles Bitcoin, expect that people are attacking your shit right now. And you need to get ahead of them by,
unfortunately, spending money on powerful models to backtest and to attack your own shit, basically, before they do it. It is a bit of a race. Bitcoin is a feeling to pinch, all the pain first because if you're an attacker, like, is it more valuable to you to go and try and hack,
you know, somebody with some personal information, which you then have to go and sell to try and get some money for that vulnerability? Or do you just attack the money itself or the software that handles the money? Like, it's a no brainer.
So again, we are gonna come out stronger for this, but we are feeling the pain first and foremost. And I just think it's gonna continue for the next at least six months. I I just don't see any way around it, basically. And it just becomes a bit of a race as to,
you know, do do the the software maintainers and the hardware maintainers find it first? Or do the do the hackers find it first, basically? Yeah. I'm saying specifically, you know, it's a hot wallet. You know, we've always said anyway, try not to keep too many funds on there, you know, more than you would be prepared to lose in theory.
But now it's not in theory. It's like a reality. People are really out there getting hacked. Like, it's it's a real problem. So I'm just saying, like, if you're running a store or doing this stuff and, like, you don't wanna dedicate huge amounts of your time to it and be worried all the time, a,
maybe consider this other Flint thing, which works really well. And, b, just even when you have that, set the auto withdrawal
thing because you can set that so it will auto withdraw over a certain limit. It does it all for you. You don't have those funds hot. And then if there is another problem and there is even a problem with this Flint thing, then it's like, well, okay. I've lost what I'm comfortable losing,
and it's like, okay. That's fucked me up. It's a $100 or whatever, but it's not, like, everything that you've had on your store for that that, you know, last few months. And I know quite a few people who have been hit like that, a couple who have been hit like that immediately after being hit with the cold card stuff.
And so, you know, I'm just you hate to see it, and there's ways to protect. Yeah. Absolutely. It's about risk mitigation.
And, you know, clearly at the moment, hot wallets are the are the lowest hanging fruit, so act accordingly. But I also wanna be careful. I know Seth is part of the show, but, like, I don't wanna I don't want us to paint his solution as, like, the solution as as being, like, oh, this is secure and that one's not because No.
I'm not saying that. Flint is absolutely, you know, vulnerable to to the same threats as any other. But, yes, it does have some great tooling in there for, like, risk management, like auto swaps out to cold storage and stuff like that. To be clear, my point isn't that theirs is more secure.
That's it's definitely not that. It's Mhmm. Mhmm. Option is as secure at least for someone like me. I've got to put my trust either in myself and l and d or c lightning Yeah. Which all is there's problems with all of those, or I put my trust into this. Mhmm. And it's easier, and you can set those limits. So my point is simply, it's trust
wherever you go in a project, whichever option you go for here. And so for me, at least, I'd rather go for something that is simple, and it has a Seth looking at it rather than a me looking at it because I'm a fucking moron.
For me, I'm speaking about, and anyone who's a bit more, maybe less technical, I think it's a really good solution. That's all I'm saying. Yep. Agreed. Alright. Next on the list, Bitcoin's first quantum safe transaction has been mined on main net.
Starkware researchers, Avihu Levy and Tom Giladi, broadcast a quantum resistant Bitcoin transaction on mainnet in Block 964199 Using hash based one time signatures built from script op codes that already exist.
No consensus change, obviously, because it's already been mined on main net. No soft fork and didn't require anybody's permission from Bitcoin Core or anything like that.
It is a sizable transaction as you would expect from something that quotes or claims to be quantum resistant. 1,321 virtual bytes, which I believe is about four or five times bigger than the average transaction
currently, which, you know, a one input, two output transaction here according to my very quick search is around about 250 bytes. So you're looking at five times bigger, which means five times more expensive.
Not much So more to about 20 p. Yeah. So at one sap a byte, it's still insignificant. However, at 20 or 50 saps per byte, that becomes quite expensive. Yes. But if the alternative is, you know, bitcoin becomes quantum vulnerable, then I'd happily pay more.
I think that the the headline here isn't the fact that, oh, quantum resistant or, oh, it's expensive. It's the fact that they've done it already without requiring any existing any changes to the existing
consensus. Mhmm. That was announced, I believe, at the Bitcoin Asia conference that went down last week. So Were they Singapore or something, were they? I
I'm not sure where where it was. Oh, Hong Kong. Hong Kong. Okay. Link's in the show notes if you wanna go and watch the the announcement of this. Was some guy did it on on stage. It was Okay. The StarkNet guys.
Yeah. What else we got? Stacker News of shipped an embedded Spark wallet. There's a theme emerging here, isn't there? And they've also got a receive proxy toggle. So Stacker News, for those that live under a rock, is kind of like Bitcoiner, Reddit type thing with, you know, payments built in.
So they've now announced spark wallet to to power it, which as one option, to be clear, that you can enable during setup, which is obviously better than custodial. Not quite as good as running your own node, obviously. But there are many, many trade offs to all of those as we have waxed lyrical about over many, many Bitcoin briefs before.
And they also let you switch off the receive proxy on your Lightning address so that you can choose whether payments route through their infrastructure or come straight to you. And they've also cut their proxy free proxy fee from 10% to 3%.
Obviously, it goes without saying that an embedded browser wallet carries a lot of trust assumptions similar to custodial, but it seems like they're moving in the right direction. And this seems like a nice natural fit for for for the stack and use.
Very good.
Next on the list, more people building. GG of who goes by Unruggle GG on Twitter. He works for the Bull Bitcoin team, who are a great team, by the way. I've been working with them on some cool shit lately.
And they're just really a pleasure to work with. Ben Kaufman, great guy. GG's been vibe coding, and he has built a mini script fork of cTiner. He's been wait his quote here on his tweet said that I've wanted mini script on cTiner for years.
Rob Hamilton of Anchor Watch opened a git issue three years ago, and it's been sat there ever since. And GG just put his clankers to work and built it himself. Very similar to the way I've done with Passport Core and Passport Prime very recently. I've also done exactly the same thing.
He's got a cool demo with the in his tweet that's linked in the show notes. So good to see people, like, taking on you know, twelve months ago, this would have been an insurmountable challenge for most junior developers, let alone Gigi, who like myself is not a developer. And now there's guys like him and guys like me
making pull requests to major, you know, major tools in the Bitcoin ecosystem. Now obviously, I'm not gonna sit here and say, g g's fork is gonna be completely safe and you should go and put all your funds in. Same goes for for my proof of concepts with Passport Prime and Passport Corp. But the fact that we can get 95%
of the way there where some engineer can take over and, you know, do some proper code review is completely fucking wild to me. I'm I don't think I'm ever gonna get bored of it. So put this in the news because I just thought it was very cool. And he hasn't just updated the seed signer firmware.
He's also built his own Liana seed signer bridge to go with it. Because currently, for those of you that watched my demo, you will have seen that I mentioned that I had to fork Liana desktop because it doesn't support the QR code formats that Ctiner and Passport and Blockstream Jade and basically everybody apart from Coldcard supports.
So he took a different attack, and he built Liana Ctiner Bridge, which is a small standalone tool that bridges the Liana file based PSBT and cTina. Basically, just as like, as the name suggests, I guess,
a bridge between the two so that you have something that scans QR codes and then feeds it into Liana. So rather than him going the whole hog like me and and changing Liana quite significantly, he's kept the changes outside so that it can work. And it doesn't for those that want to use it, they can install, obviously,
the the new cTaner firmware and the the bridge, and it will work with the existing live Liana version. Right. Which is a novel approach. And again, just wanted to tip my hat to him because this is very cool. And if if I get a bit of time, I'd love to give this a test out. Yeah.
Well, this is the positive side. The hacks are the negative side of AI, and and you and him and others being able to build cool shit that you could never have built is the is the good side. Ying and yang. Yeah.
Absolutely. Talking of ying and yang, back to back to the yang. Roman Storm has had his retrial pushed back again to this time April 2027 04/26/2027, to be clear. So more uncertainty for him and it's quite a long pushback.
The acquittal motion is still undecided, and he's now got another eight more months of limbo, before, you know, he he find out what's going on, basically. So he's, you know, unfortunately to say that there's not gonna be any more progress on that until well into the next year. So this is shit.
And he's got he's got quite a lengthy tweet on going into the details of of it here. So, yeah, I haven't really got anything positive to say about that. I guess I could say that, he's said that he wants to come on to Freedom Debt Friday to talk about all this. Just need to, to nail down a date with him. We were actually waiting until
his most recent hearing, which clearly now is being pushed back. So maybe we can get him on and help continue to spread the word and raise awareness for his retrial. Yeah. For sure. Okay.
Next on the list, Coinbase. I know we don't normally talk about those. And mortgages, we also don't talk about those. But Coinbase have teamed up with Better Mortgage to make a bitcoin backed mortgage more generally available.
You can pledge bitcoin as collateral and borrow against it. Crucially, you can skip a taxable event that you would normally trigger by selling. Mhmm. And there's been some this seems to be well received because the wait list for this alone has come to a quarter sorry. 260,000,000
of people on the wait list. So there's a lot of people kind of wanting 260,000,000 people are on the wait $260,000,000 worth. Oh, I was gonna say. Okay. So, like, a couple of houses in LA.
Yeah. So the the I was gonna say that sounded like an unbelievable number because it was. I mean, Coinbase have a lot of users, but I don't know whether they've got that many users that would want to borrow against the Bitcoin for for a mortgage.
Yeah. Obviously, pros and cons to this, as with everything, you are able to dodge taxable events, but, obviously, you're handing over the keys to to Coinbase to hold onto your Bitcoin. But if you're already in the KYC world, all of your Bitcoin is KYC ed, and it's a vast proportion of your wealth and you wanna buy a house,
it could be a viable solution for you. Yeah. Yeah. I don't I don't really have anything too negative to say about it. Like, that would be quite useful for a lot of people. I I I guess I wonder how it works under the hood in terms of you put your Bitcoin up as collateral.
You get the loan. How much loan to value can you get? What what sort of, like, safety nets have you got in there to, like, deposit more collateral if you have a drop? And then is it separate in case there's a hack or something on Coinbase?
If that happens, then what? Who's liable? Are they liable? Are you liable? It'd be interesting to see the mechanics of it and, like, where the risk is because if it's if it's if they get hacked, there's an insurance policy that pays out and make sure that you don't, like, have your loan closed and your house taken,
which I I would assume they would have to be, then it's it's pretty pretty fucking useful. I mean, people need houses. And if you do sell, you're gonna get absolutely raped Mhmm. Paying your taxes on the capital gain.
If you live in America or The UK or whatever, there are other places that aren't gonna charge you cap gains. And then in that case, you'd be better off just selling. Yeah. Interesting. Yeah. Absolutely. I mean, the there's a couple of things that I
I I'm willing to take a bet on here that will be almost certain is that Coinbase will have themselves protected. The interest rates are probably gonna be high. And, obviously, you're you're giving up custody of your Bitcoin, so just bear in mind.
Yes. All of those things. Bear in mind. There there there's no public mention of the the interest rates or anything like that here. But, again, if you are Bitcoin wealthy and normie land poor, then could be a good option if you wanna buy a house.
Next on the list, Human Rights Foundation continuing to fund open source projects here. They've given away the the the most recent development fund gave away 500,000,000 sats across 16 different projects, all over the world, Africa, Asia, Latin America
for various different things here. I'm just looking through the list to see if there's any popular or well known projects. Two Five Six Foundation, good to see them getting some some funds here.
My First Bitcoin, I believe that's run by a guy that used to listen to our show. I cannot remember his name. What do you mean used to?
He's dead to us if he used to. Well, haven't if it's who I'm thinking of, I just haven't spoken to them or seen them and interacted with them for quite some time, so they might still listen. I fucking hope so. Don't use to us.
Two Five Six Foundation, My First Bitcoin Education, Xerox Chat if you're a Noster enjoyer, Flotilla Chat, more Noster stuff, Wallet Scrutiny, the guys that do the testing of reproducible builds.
What else have we got? Libbitcoin kernel. Lots lots of different stuff here, so good to see some worthwhile projects in there, getting some funding from HRF. Next on the list, something to do with Kraken.
Between the seventeenth and the August 24, wallets that were tied to a sanctioned exchange known as HTX, which I've never heard of before. Me neither. Sent roughly 12,000 dust transfers to Kraken user addresses.
The deposits tripped Kraken's AML controls and froze all of the accounts. Oh my god. Access has now been restored, but Kraken still holds 4,200,000 it considers tainted. And HTX denies all involvement.
Interesting. This is, yeah, a weird one because, like, sending dust, especially at current mempool rates from an address that you know is sanctioned if you control it, obviously, costs an attacker basically nothing.
Yeah. But as we've seen, can can cost a victim their their entire account. Yes. And worth mentioning here, like, restored access to your account doesn't necessarily mean that you've got your funds back. Like, there's there's there's a two tier here thing, and and that $4,200,000 that I mentioned,
I guess, drives that home and makes that clear Yeah. That Kraken is still going through the the processes here. Un unclear as to what the motive is here and who's actually behind it, because clearly HCX, whoever they are, are kind of staying away from it. Oh, HCX.
Oh, okay. HCX is the Chinese exchange that was formerly known as Huobi, which in my previous shitcoin years was was very familiar with. But, yeah, they're denying all knowledge and saying, not me, mister lawyer.
Lovely. Dusting is such an annoying problem. Yeah. Certainly is. Certainly is. More
news from the Bitcoin Knots camp.
Luke Dash junior, who, by the way, as of the last couple of days, has either stepped down or been removed from Ocean, as has Bitcoin Mechanic. I wonder what drove that decision. Anyway, they are doing a further hard fork known as Blake two b
Oh, which went live yesterday on the August 30 at Blockchain nine six one six four zero on the Bitcoin Knots breakaway chain. Luke Dasher is calling it a main net trial. And Knot's version twenty nine point four point one applied the change, and the final one is due today or tomorrow.
Keeps the chain if nothing breaks. So it looks like they do have some possible rollbacks from this. But basically, the headline is it swaps out Shar two five six because none of the Bitcoin miners supported them And changes it in for a new pro I say new, new to that chain protocol called Blake two b.
Mhmm. Which is basically ACID resistant hashing algorithm. Mhmm. The whole which is obviously intentional. Luke Dash's stated reason is killing the ASIC boost, which is the shortcut that gives large miners a bit of an efficiency edge.
No major exchange, wallet, lightning implementation, or anything that's committed to the chain, obviously. And this is the the kind of second fork attempt within a month after Bit one ten stalled at, like, two blocks.
And the ecosystem basically got completely ignored, rightly so. Nothing for anyone actually with a brain to worry about here. Main change is completely unaffected. If you are a not enjoyer, but you don't want to support this further fork, just don't install that twenty nine point four point one release candidate
Mhmm. Unless you wanna support a breakaway chain on a different hashing algorithm. Imagine having a a coin that has less blocks or blocks less often than we do shows. Like, that is It's a sound bite. It is so pathetic and laughable and expected.
It's just it's amazing. It's amazing. Indeed. Last one on the list, this has literally come out about an hour ago. I saw it just as I was prepping for the show, the final bit of the show notes.
Peach Bitcoin posted a blog post, again, as always linked in the show notes, where they are pausing their escrow model. Their founder, Steph, published an open letter via the the Peach blog.
Basically, for those that don't know, Peach is a licensed Swiss self regulatory organization. I believe they started in, like, '21 or 2022. Basically running a a KYC free peer to peer marketplace with certain trading limits to keep them within or under the Swiss threshold. That was how they were able to get around it.
But this year, the the regulator wrote seeking to to requalify the business and reconsider the compliance agreement that it had previously approved for Peach.
So with that assessed, Peach now runs without the escrow, basically taking themselves out of it. Sell offers are limited to KYC ed users. I didn't even know you could be KYC ed in No. I didn't know that.
Or white listed users or sellers with 60 plus trades and no lost disputes. Non KYC sellers get one trade at a time. Oh, okay. So you can still do it, you can only have one active trade at a time. And the fees are staying at 2%.
Which I guess, good that they're still operating, but the the escrow was what made Peach safe for buyers for obvious reasons. So, you know, stop you getting rugged after you sent the Bitcoin if you're a seller or or not receiving the Bitcoin after you've sent the fee out if you're a buyer.
So without the escrow, it's it's gonna be difficult. I mean, obviously, you've got reputation. But, yeah, just if you do use Peach, you need to be very, very careful now. Steph said in the blog post that she says they they're gonna continue to fight the the ruling, but they will comply if she loses.
And, the letter ends by allowing Peach, may have to stop the the entire marketplace or carry on without her. She said that she might step down, basically, which is sad. I've been fond of of Peach and and what they've been able to achieve.
They had a nice user interface and stuff. So just just be very careful if you're gonna use this moving forward because the escrow is is very important. If and if you're looking for alternatives,
check out things like HODL HODL or BISCO or something like that. Yeah. Or RoboSATs. Alright, mate. Let's let's hit some boost. I'll let you lead the way. Let me just scroll down one second. Lots of boost this week, which is very nice to see. Here we are.
Late stage huddle with 6,006 sets. Halfway through boosting to say live show. I won't listen live.
I won't listen live, but I think the banter is funnier, and the extra editing is not needed. That's my two sets. The banter is funny. I don't know why it would be funnier live. I guess because we have the all audience there. So yeah. Okay. I'll go along with that.
And, yeah, the editing is a big one. Although we have gotta sort out the audio on Restream because it's not as good. We'll get there. Yeah. Indeed. Just before you move on late stage, I'm pretty sure it was you that was on the the the boost board at ungovernable.network/v4v asking for
custom set amounts for when you wanna comment on the value for value board. Mhmm. And that is now live. You're welcome. Oh, that is nice. Good suggestion as well. Absolutely. Yeah. Keep them coming.
Anonymous with 2,100 sets just says, works, smiley face, Cruise. Cruise. Yes. So that's from Cruise. Big fan of the show. And works. As in he's testing ungovernable.network/v4v. He's he's, you know, it works. So thanks for testing it. Thanks for your support. Yeah. Thank you, mate. Yeah. Thank you. Nakamoto sixty one zero two
on Fountain boosted 2,100 sats with no comment. And ManBT streamed 1,420 sats on fountain. I think it's Mannbit. Mannbit. That would make a lot Yeah. More Anonymous again with a thousand sats.
When it says anonymous, is is their name called anonymous, or is it anonymous because the way that they've posted, they just haven't put a name through the site? I I think they must have typed anonymous in because I don't think there's an automatic placeholder, but I I could be wrong there. Okay.
And only 8 sats of fee. Pretty seamless payment with both Phoenix and cake. I always found annoying having to fill up fountain wallet to donate. Great work. I'm Rivan Stokes. Ah. Hello, Rivan Stokes. You go. Hello, mate. In case absolutely no one was wondering.
We were wondering literally wondering. We were. We were wondering live. Yeah. Thank you, mate. So maybe it is that. Maybe if you don't type anything in, it's anonymous. Must be. Yeah. Anonymous again with a thousand stats. It works nice. Podcast won't be able to see the live, but all in for the weekly. I don't see a place for acronym
here on the website. Maybe I'm doing something wrong. I don't see a place for acronym here. I think he means pseudonym. Yeah. Maybe. There definitely is a box to say name or name, which is optional.
Okay. Anonymous again with a thousand sats. Second try through the website. Note didn't go through. It did. Mhmm. Because we're reading it now. Yeah. Yeah. Maybe, like, they can't see it. But you know what? I bet it's that they did it, and then there was a lag on the board. Like, they didn't see their own tweet. Yeah. Not tweet.
Boost. But, anyway, it did go through, and thank you for the thousand stats. Appreciate you. Another anonymous with a thousand stats with no message. That was probably the one that he tried before. That was the first one.
So they both went through. Yeah. Thank you. Shadrach again with 939 sats. Thank you, gentlemen. And he said he also said forty hours per week. My fault, I normally notice fucked up, but that was Shadrach. Cast Peland streamed 938 sats on Fountain. Chad Farrow streamed 899
User two five four nine eight one zero four on Fountain, 690 stats. And they said, Luke Jim Jones aka Jonestown dude. Lol, perfect joke about cults within a cult of bitcoin. Ungovernable's one of the ways to fight that culty shit.
Do you get the Luke Jim Jones aka Jonestown dude? I don't get that bit. Who whoever you are, thank you for your support, and please explain. I think didn't we ask, like, who's linked Luke Jim Jones in the last episode? There was something like are you gonna search the website? It was like
and I was like, is it is it John Jones? The first thing that has come up for me is is mister Luke Jones, consultant knee surgeon.
Yeah. I've got the idea. I don't know. You have to explain to us, user two five four nine eight one zero four. Yeah. Rascal. Go on. Go on. What were you gonna say? No. I was gonna read the the next boost. Okay. Alright. I'll do the next two. Rascal at Fountain, 500 sats.
What was the dead hash firmware software signature verification app? It is dead hash. That is what it's called. I don't think it has any other name to it, is it? It's just dead hash. Yeah. I think so. I'm I'm gonna find a website URL for you now. Yeah.
I'm just oh, it's on my other it's on my other phone, actually. But, yeah, just dead hash. I used it today. It's again Yeah. I'll I'll, Jordan, when you listen to this, I've pasted the link into our telegram.
Yeah. And it should be in, like, most app stores and bits and pieces as well. Yep. But, yeah, it's it's fucking excellent, as we said last time. RevHoddle, 430¢. Weekly brief will be very welcome in my forty hours per week.
That's like was that 5% of his total listening is gonna be us? Yep. That is pretty, firstly, excellent maths. And and secondly, very nice to hear that we can take that much of your time and that you wanna tune in. So thank you.
Weekly briefs will be very welcome in my forty hours per week. Some of the highest signal around, check out the stats of the show on onlyboosts.com to see how much the v for v listeners love ungovernable.
Well, I've just tried, and it doesn't load. So I don't know whether that's a a now default five current project, or it's my connection that doesn't load. It's likely we've just got too many boosts that can't load.
It's so popular that we've broken it. So Maybe speak speaking of which, Thyme at Fountain streamed or boosted 250 sats with no comment. Silas Thornbrook, 121 sats, weekly Bitcoin brief for the win.
And, of course, Nos the Gang, 101 sats, ass over tit bullish on the weekly brief. Holy. I know. Nice. However, that wasn't the last boost because, you know, I mentioned somebody, you know, this is like a live circular feedback loop here. And I said somebody wanted full screen streaming.
Yep. Well, I respond obviously built it. It's now live. And I responded to them on Nosta earlier, and it was Arrow. And they've just boosted thirty two minutes ago while we whilst we've been recording saying shout out to Q for adding full screen to the video player after feedback. GOAT. Amazing.
Also, Obscura looks great, I'll be watching it as it develops and matures. And they sent 2,551 sats. Thank you, Arrow. Thank you, Arrow. Thank you very much. That's very cool. I like that that happens sort of live, but not live. And this one obviously isn't live. It sounds like definitely people want a weekly show. So Mhmm. Great.
And then it sounds like there's there's, like, a halfway some are saying live because it saves the time even if they won't be listening, like, let's say, I don't think there's anyone saying they don't want live.
It's not the best time to go live, but it's the only time that we can do. So what we're saying well, obviously, this one isn't live. Are we gonna try moving forward to do them? Can do it. We'll try and figure out the audio shit.
So yeah. Okay. And this is so this is potentially the last ever not live show. Yeah. Indeed. Wow. So so what are we are we committing to 9AM eastern, 2PM London? Yeah? Same as free tech Friday?
I think so. I think it makes sense. One on a Friday. I think so. It's I mean, it's it's a really specialist time, isn't it? Because, like, 9AM on a Monday, people are gonna be probably at work. But then most I guess, probably, most listeners who listen to this are probably, like, scoundrels or unemployed.
So I I assume they, they can still listen. So, yeah, let's keep it Well, yeah. Don't don't forget that a lot of people work at a desk either at home or in an office where they can easily just plug in headphones and just I don't know how people do it. I honestly, like signal.
I do not understand how a human being can listen to something while doing something. I have I can't like, I can I can listen to something while doing a physical task that takes very limited brain power? Driving is perfect.
Walking is perfect. Basic bit of, like, manual labor or gardening or, like, stuff that doesn't take that much. But as soon as I've got to think or type or read or do anything like that, I cannot listen. I can't even I could definitely can't listen to a podcast.
I can't even listen to music that has words in it. Anything I listen to has to have zero words. Otherwise, I cannot function. So to anyone who can do both at the same time,
I I agree. I think it depends what you're doing. Like, if I'm if I'm locked in doing, I don't know, deep into the support inbox at Foundation, then I'm not gonna be listening to fifty Cent or, you know, the latest.
But if I'm, you know, if I've cleared the support inbox and I'm just, like, flitting between ClawdCodes and Codex doing some VibeCo projects, then I could listen to something easily. It just it it depends on how deeply focused you need to be. Yeah. Not me. Not me. Well, you obviously have a different, more developed brain than I.
Right. Let's let's sign us off with releases, mate. As always, big long list in the in the show notes. I've just picked out some highlights that are worth quickly talking about before we sign us out and go about our merry day.
Flint from MrSethForPrivacy. Two releases in the last week. Quick reminder if you did miss the last show, this is Seth's BTC pay server plugin that enables you to take lightning payments without running a lightning node. It uses the Breeze Spark SDK.
So we've got version one point o two and one point o three, just some kind of maintenance stuff. He's cut the package size down. He has also done a security audit, stripped out some macOS payloads, and just general hardening basically, as he's very on trend with software projects at the moment.
Oh, yeah. Envoy, we already talked about at top of the show. Sparrow two point five point four. This one, the highlight here is mainly hardware wallet hardening. Anti Klepto is now mandatory with BitBox o two.
AntiClip though, for those of you that don't know, is is a kind of protocol or or implementation that USB based signers like the like the BitBox add as a as a compromise against sorry, as a protection against the compromised signing device that may leak your private key
slowly over time through the signatures that you broadcast within a transaction, Like bit to bit a few bits at a time, so to speak. Mhmm. Anti klepto is a protection against that. Very, very technical, but Sparrow is now mandating it with those USB based signers, specifically the BitBox o two.
Some other stuff, it's also reregistering ledger wallet policies if the device rejects one, and there's some other USB device hardenings as well.
Eclair version zero point fourteen point two. The reason I've included this one is they have basically strongly recommended that people update.
They said that in their words, they've shipped fixes for bugs that in their words can be exploited by malicious nodes. Pretty low on the details and it came out the exact same day as the core Lightning announcement, which tells me that maybe it could be related or across Lightning vulnerability potentially.
The other note here I've got is that the the release documents that Bitcoin d, the the Bitcoin daemon, should ideally be run on the same machine as the Eclair Lightning implementation, or reach through a secure tunnel.
Which points to me that it could be the, like, remote procedure call, the RPC connection between Eclair and Bitcoin as as the likely attack surface that's now been fixed. We don't know. I'm just surmising.
But, yeah, be aware that if you do run Eclair, which, let's be honest, not many people do outside of Phoenix on their phone, then make sure you you're updated. BTC Pay server two point four point three, security release on the August 24, recommended particularly for servers with that share many users.
Release notes say almost nothing beyond update. So, yeah, I've I've not really got much else to say there other than it's available. And this follows on from two point four point two incident from the last episode where actively exploited floor with the LND stuff and the macro incorrect credentials
was was talked about. So it sounds like they're still finding bugs and fixing them as quickly as they can with little to no release notes. BitBox o two nine point twenty seven point zero.
Up updates and fixes for long transaction show amounts and also message signing for m 45 derivation paths as well. And they also know about the the Sparrow anti klepto mandatory flag as well.
And then the last one is Blockchain Jade one point zero point four one was accompanied by a blog post. They have reiterated the fact that they're not affected by the cold card RNG vulnerability, which pretty much everybody was was well aware.
But they have released this and strongly recommended that people update because it fixes They've called it hardening fix. And I don't know whether they talk about the details here at all.
But yeah, the blog post is worth reading basically, because they draw some nice comparisons to the call card stuff, which will be linked in the show notes as well. Max, any comments or any feedback or stuff on those releases?
Not really, mate. Alright. Well, let's do it. Let's close this out. What about didn't we have some education stuff at the bottom? We did. Yeah. Yeah. There's one educational piece that right at the bottom of the show notes.
Bitcoin's quantum resistant transaction explained. Obviously, you will have heard us talk earlier about the the the first quantum resistance transaction that got mined on main net without needing any protocol changes
changes, excuse me. Well, there's a detailed blog post that goes dives into that. So if you are a turbo nerd and you you wanna go and see all the details, get your hands dirty and click that link in the show notes.
Yeah. Okay. And, also, just to remind everyone to join us this Friday for Freedom Tech Friday at 9AM eastern or 2PM London. You won't Who who put that on? It is either a special Canadian or it is a special Brit.
Well, I'm just gonna go straight to our admin panel and have a look at our fancy new calendar. I think it's a special needs Canadian. That's my feeling, but I'm not not a 100% sure. Where is it now?
I've put so many features in here. I can't find where It's so feature rich. There we go. Planner. Free Inset Friday planner. It is. It's Jordan talking about Ashikara desktop. Exciting. There we are. Yes. Very nice.
This guy. This guy. He never wants to come on and toot his horn about anything. Well, we can toot his horn for him. Yeah. Yeah. Make him that one of the listeners.
Yeah. Well, definitely don't miss that one. And next time you hear from us, we'll be live for the the Freedom Tech and then live for this one as well. So what a change Ungovernable has gone through.
Indeed. Indeed. We're we're here to take over, guys, and we appreciate your support. Keep liking, sharing, commenting, subscribing, all that good stuff. Yeah. Definitely do. Alright. Stay on Governable.
Have a good week, mate. Love you all. Before you go, mineinbox. Help keep your online presence hidden. They provide anonymous server hosting solutions, virtual, private, and dedicated servers, domain registration and DNS parking, they don't require any of your personal information, and you can purchase using Bitcoin,
Lightning or Monero. No personal information required. None. Zero. Minenbox.io. Stay ungovernable.
Machine transcript; expect the odd mishearing. Click a passage to play from there.




